<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2000411277939142534</id><updated>2012-01-09T15:07:15.120-05:00</updated><category term='DHS'/><category term='tools'/><category term='OAuth'/><category term='security'/><category term='bcb4'/><category term='hash'/><category term='policy'/><category term='ssh'/><category term='privacy'/><category term='cloud'/><category term='django'/><category term='OpenID'/><category term='AWS'/><category term='HTTP'/><category term='NIST'/><category term='#googleio'/><category term='copyright'/><category term='PKI'/><category term='appengine'/><category term='opensource'/><category term='anonymity'/><category term='python'/><category term='drm'/><category term='study'/><category term='browser'/><category term='identity'/><category term='infosec'/><category term='ssl'/><category term='EFF'/><category term='dev'/><category term='standards'/><category term='code'/><category term='devexp'/><category term='blogging'/><category term='crypto'/><title type='text'>Identity Associates Blog</title><subtitle type='html'>App Engine development, information security, clouds, and related topics.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>97</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-4464554957398411916</id><published>2012-01-07T17:54:00.000-05:00</published><updated>2012-01-07T18:02:20.521-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><title type='text'>Sovereign Keys</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif;"&gt;I'm starting to look into &lt;a href="https://www.eff.org/deeplinks/2011/11/sovereign-keys-proposal-make-https-and-email-more-secure"&gt;Sovereign Keys&lt;/a&gt;, covered in more detail in [1] and [2].&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;That the current PKI system is brittle is accepted by many people. &amp;nbsp;Brainstorming and prototyping new internet service authentication approaches is first-order important, and Sovereign Keys is worthy of further investigation and support.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Seems like&amp;nbsp;Sovereign Keys does introduce a few new concepts that need security analysis; the timeline servers offer an interesting capability, I wonder about vulnerabilities. &amp;nbsp;For that matter, I wonder about patents in this space. &amp;nbsp; There is a minefield of granted timestamping patents and while the timeline servers may not specifically address timestamping, I wonder of some of those patents were written generally enough to impact&amp;nbsp;Sovereign Keys. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Note that a proposal from&amp;nbsp;&lt;/span&gt;&lt;span style="color: #333333; line-height: 15px;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Adam Langley and Ben Laurie of Google [3] also introduces the notion of a public append-only log, in some ways similar to timeline servers, but not domain-specific.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;[1]&amp;nbsp;&lt;span style="font-size: x-small;"&gt;&lt;a href="https://www.eff.org/deeplinks/2011/11/sovereign-keys-proposal-make-https-and-email-more-secure"&gt;https://www.eff.org/deeplinks/2011/11/sovereign-keys-proposal-make-https-and-email-more-secure&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;[2]&amp;nbsp;&lt;span style="font-size: x-small;"&gt;&lt;a href="https://git.eff.org/?p=sovereign-keys.git;a=blob;f=sovereign-key-design.txt;hb=HEAD"&gt;https://git.eff.org/?p=sovereign-keys.git;a=blob;f=sovereign-key-design.txt;hb=HEAD&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;[3]&amp;nbsp;&lt;a href="https://threatpost.com/en_us/blogs/google-researchers-propose-new-plan-shore-ca-system-112911"&gt;&lt;span style="font-size: x-small;"&gt;https://threatpost.com/en_us/blogs/google-researchers-propose-new-plan-shore-ca-system-112911&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-4464554957398411916?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/4464554957398411916/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=4464554957398411916' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4464554957398411916'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4464554957398411916'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2012/01/sovereign-keys.html' title='Sovereign Keys'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-7497181917236592705</id><published>2011-11-18T09:38:00.001-05:00</published><updated>2011-11-18T09:42:14.500-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='python'/><category scheme='http://www.blogger.com/atom/ns#' term='code'/><title type='text'>Python Decorators</title><content type='html'>Thanks to Stack Overflow (pretty much always awesome!) &amp;nbsp;here is the best explanation of Python Decorators I have found.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://stackoverflow.com/questions/739654/understanding-python-decorators/1594484#1594484"&gt;http://stackoverflow.com/questions/739654/understanding-python-decorators/1594484#1594484&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-7497181917236592705?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/7497181917236592705/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=7497181917236592705' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7497181917236592705'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7497181917236592705'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/11/python-decorators.html' title='Python Decorators'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-4049850672938394219</id><published>2011-11-17T09:11:00.001-05:00</published><updated>2011-11-17T09:18:57.457-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='infosec'/><category scheme='http://www.blogger.com/atom/ns#' term='standards'/><category scheme='http://www.blogger.com/atom/ns#' term='ssl'/><title type='text'>CA/Browser Forum - Certificate Baseline Requirements</title><content type='html'>Here:&amp;nbsp;&lt;a href="http://www.gerv.net/temp/Baseline_Requirements_Draft_50.pdf"&gt;http://www.gerv.net/temp/Baseline_Requirements_Draft_50.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Focused for now on certificate policies for issuing certificates used to trust publicly-available servers, this document (draft 50) represents lots of hard work and expertise and provides a good stake post for practioners.&lt;br /&gt;&lt;br /&gt;We need equally comprehensive work on application and service design, deployment, and management for relying parties so that the trust inherent in the certificate issuance process is not squandered in error-prone implementation "in the wild."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-4049850672938394219?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/4049850672938394219/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=4049850672938394219' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4049850672938394219'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4049850672938394219'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/11/cabrowser-forum-certificate-baseline.html' title='CA/Browser Forum - Certificate Baseline Requirements'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-1767395864185279619</id><published>2011-09-09T16:00:00.000-04:00</published><updated>2011-09-09T16:00:15.857-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='standards'/><category scheme='http://www.blogger.com/atom/ns#' term='NIST'/><title type='text'>NIST Cloud Computing Reference Architecture updated</title><content type='html'>Source document here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://collaborate.nist.gov/twiki-cloud-computing/pub/CloudComputing/ReferenceArchitectureTaxonomy/NIST_SP_500-292_-_090611.pdf"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;http://collaborate.nist.gov/twiki-cloud-computing/pub/CloudComputing/ReferenceArchitectureTaxonomy/NIST_SP_500-292_-_090611.pdf&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-1767395864185279619?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/1767395864185279619/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=1767395864185279619' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1767395864185279619'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1767395864185279619'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/09/nist-cloud-computing-reference.html' title='NIST Cloud Computing Reference Architecture updated'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-5219715944004805063</id><published>2011-09-08T08:29:00.000-04:00</published><updated>2011-09-09T07:09:34.120-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='appengine'/><title type='text'>app engine pricing</title><content type='html'>So, App Engine announced new pricing. &amp;nbsp;It looks to be more expensive, and many would say this is an understatement. &amp;nbsp; &amp;nbsp;It is more expensive, and/but you can probably take some steps to manage and design for the pricing model. &amp;nbsp;What you need to keep in mind is that "instances" are now a&amp;nbsp;fundamental&amp;nbsp;pricing component, where they weren't before. &amp;nbsp;Managing instances thru latency and caching to reduce instance use are directions you need to consider. &amp;nbsp;Here are two useful articles:&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;&lt;a href="http://code.google.com/appengine/articles/managing-resources.html"&gt;http://code.google.com/appengine/articles/managing-resources.html&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;and&lt;br /&gt;&lt;a href="http://highscalability.com/blog/2011/9/7/what-google-app-engine-price-changes-say-about-the-future-of.html"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;http://highscalability.com/blog/2011/9/7/what-google-app-engine-price-changes-say-about-the-future-of.html&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Look at using caching and datastore more efficiently, and use the Admin console to experiment with the scheduler. &amp;nbsp;In particular, the "Lower Max Idle Instances" is a good place to start. &amp;nbsp; Check the managing-resources article above for more details. &amp;nbsp;I expect that more information will be forthcoming as well.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;UPDATE&lt;/i&gt;: &amp;nbsp;I expected more, but who knew this soon. From Peter Magnusson who is director of the AppEngine team, read his Google+ post for more context.&lt;br /&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;&lt;a href="https://plus.google.com/110401818717224273095/posts/AA3sBWG92gu"&gt;https://plus.google.com/110401818717224273095/posts/AA3sBWG92gu&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Minor note: glad to see Python 2.7 about to be rolled out.&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-5219715944004805063?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/5219715944004805063/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=5219715944004805063' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5219715944004805063'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5219715944004805063'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/09/app-engine-pricing.html' title='app engine pricing'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-7140830172077216625</id><published>2011-08-30T08:55:00.000-04:00</published><updated>2011-09-13T14:34:21.729-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='policy'/><category scheme='http://www.blogger.com/atom/ns#' term='ssl'/><category scheme='http://www.blogger.com/atom/ns#' term='EFF'/><title type='text'>global CA Infrastructure reminds us again its broken</title><content type='html'>via an attack using a fraudulent SSL certificate apparently targeted at users in Iran.&lt;br /&gt;&lt;br /&gt;Google statement here:&amp;nbsp;&lt;a href="http://googleonlinesecurity.blogspot.com/2011/08/update-on-attempted-man-in-middle.html"&gt;http://googleonlinesecurity.blogspot.com/2011/08/update-on-attempted-man-in-middle.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;EFF here:&amp;nbsp;&lt;a href="https://www.eff.org/deeplinks/2011/08/iranian-man-middle-attack-against-google"&gt;https://www.eff.org/deeplinks/2011/08/iranian-man-middle-attack-against-google&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Apparently Google Chrome browser detected the bad certificate out of the box, and Mozilla Firefox and Microsoft IE moved rapidly to revoke the root cert of the issuing CA. Thanks are due an&amp;nbsp;observant&amp;nbsp;Google Chrome user who first noticed and reported the certificate warning. &amp;nbsp;The browser community moved rapidly to address this problem, which is good. &amp;nbsp;Reporting and action channels for problems are clearly improving and indicate a focus on this issue at the major vendors.&lt;br /&gt;&lt;br /&gt;Some points I draw from this:&lt;br /&gt;&lt;br /&gt;Good reaction is required, but&amp;nbsp;pro-activity &amp;nbsp;(as seen with Google Chrome) is critically important in making the global CA infrastructure stronger and more&amp;nbsp;resilient. &lt;br /&gt;&lt;br /&gt;Google's pinning worked in this case, but I agree with this Hacker News &lt;a href="http://news.ycombinator.com/item?id=2514660"&gt;discussion &lt;/a&gt;- that pinning is needed, and works, only emphasizes that the CA infrastructure is broken. &amp;nbsp; I'm not sure we can find a "golden band-aid" to address how broken it is. &amp;nbsp; &amp;nbsp;Its ironic or not I suppose that browser technology is needed to identify weaknesses in the security infrastructure used to protect browser activities. Browsers as the early-wanting systems for CA compromise. &amp;nbsp;Browser updates as the new revocation system.&lt;br /&gt;&lt;br /&gt;I think the goals the EFF has with its &lt;a href="https://www.eff.org/observatory/"&gt;SSL Observatory&lt;/a&gt; are important and I think the work they are doing in general in this area is really valuable. &lt;br /&gt;&lt;br /&gt;I guess I better start learning more about Convergence&amp;nbsp;&lt;a href="http://convergence.io/"&gt;http://convergence.io/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;* UPDATE:&amp;nbsp;&lt;/i&gt;For the reader interested in an advanced analysis, this from Dan&amp;nbsp;Kaminsky:&amp;nbsp;&lt;a href="http://dankaminsky.com/2011/08/31/notnotar/"&gt;http://dankaminsky.com/2011/08/31/notnotar/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here is a related risk analysis:&amp;nbsp;&lt;a href="http://security.blogoverflow.com/2011/08/31/a-risk-based-look-at-fixing-the-certificate-authority-problem/"&gt;http://security.blogoverflow.com/2011/08/31/a-risk-based-look-at-fixing-the-certificate-authority-problem/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Further Update: two informative posts from TOR:&lt;br /&gt;&lt;a href="https://blog.torproject.org/blog/diginotar-debacle-and-what-you-should-do-about-it"&gt;https://blog.torproject.org/blog/diginotar-debacle-and-what-you-should-do-about-it&lt;/a&gt;&lt;br /&gt;and:&amp;nbsp;&lt;a href="https://blog.torproject.org/blog/diginotar-damage-disclosure"&gt;https://blog.torproject.org/blog/diginotar-damage-disclosure&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You know you have a broken system when well-meaning people provide their own best-effort solutions:&lt;br /&gt;&lt;a href="https://kuix.de/blog/index.php?entry=Firefox-Add-On:-CA-Knockout"&gt;https://kuix.de/blog/index.php?entry=Firefox-Add-On:-CA-Knockout&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-7140830172077216625?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/7140830172077216625/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=7140830172077216625' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7140830172077216625'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7140830172077216625'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/08/global-ca-infrastructure-reminds-us.html' title='global CA Infrastructure reminds us again its broken'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-2752979806265213226</id><published>2011-08-18T07:39:00.002-04:00</published><updated>2011-08-18T07:39:51.183-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crypto'/><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>an attack on AES-128</title><content type='html'>A recent paper explains an attack on &lt;a href="http://en.wikipedia.org/wiki/Advanced_Encryption_Standard"&gt;AES-128&lt;/a&gt;. &amp;nbsp;Best to think of it now as AES-126, more or less.&lt;br /&gt;&lt;br /&gt;paper here:&amp;nbsp;&lt;a href="http://research.microsoft.com/en-us/projects/cryptanalysis/aes.aspx"&gt;http://research.microsoft.com/en-us/projects/cryptanalysis/aes.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;presentation here:&amp;nbsp;&lt;a href="http://rump2011.cr.yp.to/d41bd80f6680cfd2323e53fbb9a62a81.pdf"&gt;http://rump2011.cr.yp.to/d41bd80f6680cfd2323e53fbb9a62a81.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Conventional wisdom says attacks get better over time; once a chink in the armor is found it can lead to more effective attacks. &amp;nbsp; The Wikipedia article on SHA-1 shows a slow but steady improvement in attacks since the 2005 work by Wang etc.... &amp;nbsp;It seems to me that it is possible that any single attack strategy probably approaches some upper limit for effectiveness. &amp;nbsp; The real-world problems arise when the upper limit effectiveness of that attack is sufficient to break an algorithm easily with ordinary computing power. &amp;nbsp;(of course, the "cloud" &lt;a href="http://www.darkreading.com/authentication/167901072/security/encryption/229000423/cloud-based-crypto-cracking-tool-to-be-unleashed-at-black-hat-dc.html"&gt;redefines &lt;/a&gt;the amount of computes available to the ordinary user)&lt;br /&gt;&lt;br /&gt;It'll be very interesting to see if the techniques used to attack AES-128 now allow for significant improvement over time.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-2752979806265213226?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/2752979806265213226/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=2752979806265213226' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2752979806265213226'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2752979806265213226'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/08/attack-on-aes-128.html' title='an attack on AES-128'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-1283611609389292239</id><published>2011-08-17T10:20:00.002-04:00</published><updated>2011-08-18T07:44:43.697-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='dev'/><category scheme='http://www.blogger.com/atom/ns#' term='devexp'/><title type='text'>developer attention</title><content type='html'>I can testify to this, from Life and Code:&amp;nbsp;&lt;a href="http://lifeandcode.tumblr.com/post/8993770468/why-you-shouldnt-interrupt-developers"&gt;http://lifeandcode.tumblr.com/post/8993770468/why-you-shouldnt-interrupt-developers&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Specifically:&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #323b41; font-family: 'Lucida Grande', 'Lucida Sans Unicode', Verdana, sans-serif; font-size: 11px; line-height: 18px;"&gt;Much research has shown that software development is particularly demanding of cognitive resources: you have to keep a lot of stuff in your brain at the same time while programming. Even a one-minute interruption erases this info, and it can take 10-15 minutes to re-establish the programmer’s mental state.&lt;/span&gt;— Jakob Nielsen, August 2011&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-1283611609389292239?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/1283611609389292239/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=1283611609389292239' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1283611609389292239'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1283611609389292239'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/08/i-can-testify-to-this-from-life-and.html' title='developer attention'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-5717177716847313785</id><published>2011-07-08T13:02:00.001-04:00</published><updated>2011-07-08T13:02:52.255-04:00</updated><title type='text'>transferring domain name</title><content type='html'>identityassociates.com will be offline for a bit as I transfer the domain name, and switch hosting providers. &amp;nbsp;IA will move to Google Apps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-5717177716847313785?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/5717177716847313785/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=5717177716847313785' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5717177716847313785'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5717177716847313785'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/07/transferring-domain-name.html' title='transferring domain name'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-259546323661885869</id><published>2011-07-01T16:43:00.000-04:00</published><updated>2011-07-01T16:43:16.822-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='NIST'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><title type='text'>NSTIC Privacy Workshop</title><content type='html'>I had the opportunity to attend much of the two day &lt;a href="http://www.nist.gov/nstic/"&gt;NSTIC &lt;/a&gt;Privacy Workshop held in Cambridge Massachusetts this week. &amp;nbsp; I haven't been following this NIST-backed effort as closely as I probably should have, so the workshop in Cambridge was a perfect opportunity to catch up with NSTIC, at least through the lens of privacy.&lt;br /&gt;&lt;br /&gt;A few observations:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The people involved are experienced and sharp. &amp;nbsp; The process seems inclusive, which bodes well. &amp;nbsp;The meeting was well run.&lt;/li&gt;&lt;li&gt;There was some deja-vu for me based on some PKI experiences in working groups I participated in over 10 years ago in the financial sector. &amp;nbsp;Identity, authentication, authorization, attributes, etc... &amp;nbsp;all being discussed in similar ways. &amp;nbsp; Its dangerous to look too closely at that past experience, though, because use cases, technology, and the environment are so substantially evolved from that time frame.&lt;/li&gt;&lt;li&gt;More than one speaker noted the compelling issues on the horizon regarding mobility, location based services, "big data" mining and related advances, noting this may rapidly outstrip the worries we have about current ad-network dominated problems.&lt;/li&gt;&lt;li&gt;Once again, Identity Woman, aka Kaliya Hamlin, seems to be two steps ahead. &amp;nbsp;Will the Personal Data Ecosystem Consortium trump traditional standards processes by leveraging the&amp;nbsp;entrepreneurial&amp;nbsp;energy of competing startups? &amp;nbsp;Running code FTW?&amp;nbsp;&lt;/li&gt;&lt;li&gt;So what do I worry about? &amp;nbsp;I'd love for the vision and zeal of the privacy advocates to win the day, but I'm not sure that is feasible. &amp;nbsp;Maybe we need to &amp;nbsp;ensure that NSTIC allows privacy-enhancing approaches to be first-class citizens in any adopted standard, and a true market will emerge whereby citizens and consumers have the right and ability to chose to use privacy-enhancing solution. &amp;nbsp;And let the NSTIC infrastructure itself not leak privacy. &amp;nbsp;A bad scenario, in my opinion, would be for the NSTIC process to be co-opted by the biggest firms, and NSTIC results in a legal, regulatory, and operational framework that in practice serves to meet the widest dreams of the greediest internet &amp;nbsp;marketers at the expense of meaningful citizen privacy.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;National Strategy for Trusted Identities in Cyberspace (NSTIC):&amp;nbsp;&lt;a href="http://www.nist.gov/nstic/"&gt;http://www.nist.gov/nstic/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;epic.org has a great overview paper on NSTIC here:&amp;nbsp;&lt;a href="http://epic.org/privacy/nstic.html"&gt;http://epic.org/privacy/nstic.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;personal data ecosystem consortium:&amp;nbsp;&lt;a href="http://personaldataecosystem.org/"&gt;http://personaldataecosystem.org/&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-259546323661885869?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/259546323661885869/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=259546323661885869' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/259546323661885869'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/259546323661885869'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/07/nstic-privacy-workshop.html' title='NSTIC Privacy Workshop'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-2490743989591242396</id><published>2011-06-25T12:22:00.000-04:00</published><updated>2011-06-25T12:22:22.247-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='infosec'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>each day better than the next</title><content type='html'>So it continues to be an interesting time in the infosec world. &amp;nbsp;Just off the top of my head, the last several months have seen Stuxnet, RSA SecureID being breached, account credentials compromised at Citibank and Google/Gmail, a CA compromised, and lots of activity from Anonymous and Lulzsec. &amp;nbsp; Dropbox security was broken for a time, and there is all too plentiful evidence that people deploying solutions on Amazon Web Services are leaving gaping security holes.&lt;br /&gt;&lt;br /&gt;Some attacks show alarming sophistication and are extremely targeted. &amp;nbsp; Others exploit well-known attack vectors that could have been closed had reasonable security practices been followed.&lt;br /&gt;&lt;br /&gt;In any event, lots of work remains. &amp;nbsp; Where to start....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-2490743989591242396?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/2490743989591242396/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=2490743989591242396' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2490743989591242396'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2490743989591242396'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/06/each-day-better-than-next.html' title='each day better than the next'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-1230988798254981902</id><published>2011-05-19T10:12:00.002-04:00</published><updated>2011-05-19T10:24:42.847-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='AWS'/><title type='text'>new AWS security whitepapers</title><content type='html'>Amazon Web Services continues to be a preferred destination for many people moving apps to the cloud. &amp;nbsp; Security and related concerns continue to be important for enterprise-grade applications, and the AWS team has released more content helping users understand security models on AWS.&lt;br /&gt;&lt;br /&gt;Overview of Security Processes:&amp;nbsp;&lt;a href="http://d36cz9buwru1tt.cloudfront.net/pdf/AWS_Security_Whitepaper.pdf"&gt;http://d36cz9buwru1tt.cloudfront.net/pdf/AWS_Security_Whitepaper.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;and&lt;br /&gt;&lt;br /&gt;Risk and Compliance:&lt;a href="http://d36cz9buwru1tt.cloudfront.net/pdf/aws-risk-and-compliance-whitepaper.pdf"&gt;&amp;nbsp;http://d36cz9buwru1tt.cloudfront.net/pdf/aws-risk-and-compliance-whitepaper.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;(Not sure I'm loving these URLs, but... &amp;nbsp;you can always find the latest here:&amp;nbsp;&lt;span class="Apple-style-span" style="color: #212121; font-family: Helvetica; font-size: 10px;"&gt;&lt;a href="http://aws.amazon.com/security"&gt;http://aws.amazon.com/security&lt;/a&gt;&lt;/span&gt;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-1230988798254981902?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/1230988798254981902/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=1230988798254981902' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1230988798254981902'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1230988798254981902'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/05/new-aws-security-whitepapers.html' title='new AWS security whitepapers'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-3347272705646441358</id><published>2011-05-18T15:41:00.001-04:00</published><updated>2011-05-18T15:41:31.251-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='#googleio'/><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='appengine'/><title type='text'>App Engine evolves - Google IO 2011</title><content type='html'>Google's App Engine continues to evolve, and lots of steps were taken or announced at Google IO 2011 last week. &amp;nbsp;I'll use this post to collect thoughts and evaluations as I think thought all that I learned.&lt;br /&gt;&lt;br /&gt;This post on App Engine blog is a good place to start: &amp;nbsp;&lt;a href="http://googleappengine.blogspot.com/2011/05/year-ahead-for-google-app-engine.html"&gt;http://googleappengine.blogspot.com/2011/05/year-ahead-for-google-app-engine.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So, App Engine won't be as "free". &amp;nbsp; &amp;nbsp; App Engine pricing will increase, and the previously-discussed App Engine for Business has been folded into App Engine pricing tiers. &amp;nbsp; Here is a current FAQ on App Engine pricing:&lt;br /&gt;&lt;a href="https://groups.google.com/group/google-appengine/msg/739169f799d8e69a?"&gt;https://groups.google.com/group/google-appengine/msg/739169f799d8e69a?&lt;/a&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; It makes some sense to me that Google has had a chance to learn how much its costs to run this service, and it seems fair to reflect that knowledge into the business model. &lt;br /&gt;&lt;br /&gt;App Engine is no longer in preview mode. &amp;nbsp;Also a good thing, this includes providing SLA terms, corporate support, and other features that will make App Engine easier to explain to enterprises.&lt;br /&gt;&lt;br /&gt;More soon...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-3347272705646441358?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/3347272705646441358/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=3347272705646441358' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3347272705646441358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3347272705646441358'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/05/app-engine-evolves-google-io-2011.html' title='App Engine evolves - Google IO 2011'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-3065632809800848028</id><published>2011-04-18T09:48:00.002-04:00</published><updated>2011-04-18T10:00:13.822-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>another cloud security document - security considerations</title><content type='html'>From Australia, recorded here for posterity, etc... &amp;nbsp;Thanks to @Beaker for tweeting about this.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.dsd.gov.au/publications/Cloud_Computing_Security_Considerations.pdf"&gt;http://www.dsd.gov.au/publications/Cloud_Computing_Security_Considerations.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In my opinion, this document is particularly valuable because its list of detailed security considerations is more comprehensive than most; &amp;nbsp;it provides a very good starting point for developing your own checklist.&lt;br /&gt;&lt;br /&gt;Australian DSD home site:&amp;nbsp;&lt;a href="http://www.dsd.gov.au/infosec/cloudsecurity.htm"&gt;http://www.dsd.gov.au/infosec/cloudsecurity.htm&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-3065632809800848028?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/3065632809800848028/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=3065632809800848028' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3065632809800848028'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3065632809800848028'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/04/another-cloud-security-document.html' title='another cloud security document - security considerations'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-45226519539178880</id><published>2011-04-08T11:55:00.001-04:00</published><updated>2011-04-10T07:57:05.920-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='policy'/><title type='text'>more on global CA infrastructure from Dan Wallach</title><content type='html'>I decided not to update my previous &lt;a href="http://identityassociates.blogspot.com/2011/03/trusted-certificate-compromise.html"&gt;post&lt;/a&gt;, it was getting a little straggly with so many updates. &amp;nbsp;Anyway, Dan Wallach's content-dense post is worth of its own entry here on this humble blog.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-7Ci_TZpRB5s/TZ8voV1YofI/AAAAAAAAAh8/DikR1lSyuqw/s1600/picture-72.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-7Ci_TZpRB5s/TZ8voV1YofI/AAAAAAAAAh8/DikR1lSyuqw/s1600/picture-72.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Dan Wallach writing on Freedom to Tinker makes several good points in following up on the recent CA compromise, here:&lt;br /&gt;&lt;a href="http://www.freedom-to-tinker.com/blog/dwallach/building-better-ca-infrastructure"&gt;http://www.freedom-to-tinker.com/blog/dwallach/building-better-ca-infrastructure&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Dan includes a bunch of useful links and discusses a couple of short-term promising approaches, for example:&lt;br /&gt;&lt;blockquote&gt;A straightforward idea is to track the certs you see over time and generate a prominent warning if you see something anomalous. This is available as a fully-functioning Firefox extension,&amp;nbsp;&lt;a href="https://addons.mozilla.org/en-us/firefox/addon/certificate-patrol/"&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;Certificate Patrol&lt;/span&gt;&lt;/a&gt;. This should be built into every browser.&lt;/blockquote&gt;and,&lt;br /&gt;&lt;blockquote&gt;In addition to your first-hand personal observations, why not leverage other resources on the network to make their own observations? For example, while Google is crawling the web, it can easily save SSL/TLS certificates when it sees them, and browsers could use a real-time API much like&amp;nbsp;&lt;a href="http://code.google.com/apis/safebrowsing/"&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;Google SafeBrowsing&lt;/span&gt;&lt;/a&gt;. A research group at CMU has already built something like this, which they call a&amp;nbsp;&lt;a href="http://www.networknotary.org/"&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;network notary&lt;/span&gt;&lt;/a&gt;. In essence, you can have multiple network services, running from different vantage points in the network, all telling you whether the cryptographic credentials you got match what others are seeing. Of course, if you're stuck behind an attacker's firewall, the attacker will similarly filter out all these sites.&lt;/blockquote&gt;&lt;blockquote&gt;UPDATE:&amp;nbsp;&lt;a href="http://googleonlinesecurity.blogspot.com/2011/04/improving-ssl-certificate-security.html"&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;Google is now doing almost exactly what I suggested&lt;/span&gt;&lt;/a&gt;.&amp;nbsp;&lt;/blockquote&gt;&lt;br /&gt;The joke has always been - every year starts fresh with: "This is the Year of PKI". &amp;nbsp;PKI will never have a "year" - it will continue to develop organically, being improved locally and globally through the efforts of lots of security technologists working collaboratively, &amp;nbsp;unfortunately sometimes in response to the efforts of bad actors.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-45226519539178880?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/45226519539178880/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=45226519539178880' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/45226519539178880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/45226519539178880'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/04/more-on-global-ca-infrastructure-from.html' title='more on global CA infrastructure from Dan Wallach'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-7Ci_TZpRB5s/TZ8voV1YofI/AAAAAAAAAh8/DikR1lSyuqw/s72-c/picture-72.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-8440092097338204935</id><published>2011-04-02T08:59:00.000-04:00</published><updated>2011-04-02T08:59:01.317-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>useful paper: Assessing Cloud Security</title><content type='html'>thanks to Context Information Security. &amp;nbsp;See:&amp;nbsp;&lt;a href="http://contextis.co.uk/resources/white-papers/assessing-cloud-node-security/"&gt;http://contextis.co.uk/resources/white-papers/assessing-cloud-node-security/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The attack vectors discussion is concise and helpful, and the sample assessment report was interesting; although one assumes the white paper is also designed to drum up business....&lt;br /&gt;&lt;br /&gt;Overall, a useful addition to the cloud security library.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-8440092097338204935?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/8440092097338204935/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=8440092097338204935' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8440092097338204935'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8440092097338204935'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/04/useful-paper-assessing-cloud-security.html' title='useful paper: Assessing Cloud Security'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-1919395189317075290</id><published>2011-04-01T09:20:00.000-04:00</published><updated>2011-04-01T09:20:13.884-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='standards'/><category scheme='http://www.blogger.com/atom/ns#' term='NIST'/><title type='text'>NIST Cloud Computing Reference Architecture</title><content type='html'>I'll have to dig into these 26 pages. &amp;nbsp;NIST continues with their useful work addressing cloud definition, categorization, and architecture.&lt;br /&gt;&lt;br /&gt;Collaboration site here:&amp;nbsp;&lt;a href="http://collaborate.nist.gov/twiki-cloud-computing/bin/view/CloudComputing/WebHome"&gt;http://collaborate.nist.gov/twiki-cloud-computing/bin/view/CloudComputing/WebHome&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Reference Architecture (PDF) here:&lt;br /&gt;&lt;a href="http://collaborate.nist.gov/twiki-cloud-computing/pub/CloudComputing/Meeting12AReferenceArchitectureMarch282011/NIST_CCRATWG_029.pdf"&gt;http://collaborate.nist.gov/twiki-cloud-computing/pub/CloudComputing/Meeting12AReferenceArchitectureMarch282011/NIST_CCRATWG_029.pdf&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-1919395189317075290?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/1919395189317075290/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=1919395189317075290' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1919395189317075290'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1919395189317075290'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/04/nist-cloud-computing-reference.html' title='NIST Cloud Computing Reference Architecture'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-863397009706478172</id><published>2011-03-23T07:33:00.006-04:00</published><updated>2011-03-30T06:39:08.103-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='browser'/><title type='text'>trusted Certificate compromise - a sophisticated attack</title><content type='html'>thanks to ioerror at Tor Project for in-depth discovery and analysis of this situation, described here: &amp;nbsp;&lt;a href="https://blog.torproject.org/blog/detecting-certificate-authority-compromises-and-web-browser-collusion"&gt;https://blog.torproject.org/blog/detecting-certificate-authority-compromises-and-web-browser-collusion&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;summarizing snippet:&lt;br /&gt;&lt;blockquote&gt;Last week, a smoking gun came into sight: A Certification Authority appeared to be compromised in some capacity, and the attacker issued themselves valid HTTPS certificates for high-value web sites. With these certificates, the attacker could impersonate the identities of the victim web sites or other related systems, probably undetectably for the majority of users on the internet.&lt;/blockquote&gt;If you are interested in PKI and its security in a global sense, I recommend you read the article. &amp;nbsp;A couple of observations. &amp;nbsp;First, the right thing seemed to happen, emphasis on 'seemed' so far, &amp;nbsp;in that the affected CAs identified an issue and notified relevant parties rapidly. &amp;nbsp;And 'fixes' were rolled out by the browser manufacturers. &amp;nbsp; Even more interesting to me is the glimpse into the people and systems that are collaborating to monitor this global PKI infrastructure and report on its robustness, bringing light to a murky, complicated area. &amp;nbsp; Having visibility into the operations of the global PKI is a good thing for all of us.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;UPDATE&lt;/i&gt;: &amp;nbsp;More on this topic from Peter Eckersley of EFF. &amp;nbsp;I didn't know that IP addresses associated with the attack were Iranian. &amp;nbsp; Also, Peter links to a statement by Comodo. &amp;nbsp;Here are Peter's remarks:&amp;nbsp;&lt;a href="https://www.eff.org/deeplinks/2011/03/iranian-hackers-obtain-fraudulent-https"&gt;https://www.eff.org/deeplinks/2011/03/iranian-hackers-obtain-fraudulent-https&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Another UPDATE: &lt;/i&gt;Paul Roberts at ThreatPost offers some common-sense wisdom, via Paul Turner, for&amp;nbsp;managing&amp;nbsp;your&amp;nbsp;certificates, and your certificate exposure I suppose. See:&amp;nbsp;&lt;a href="http://threatpost.com/en_us/blogs/forged-certificates-five-steps-secure-your-enterprise-032411"&gt;http://threatpost.com/en_us/blogs/forged-certificates-five-steps-secure-your-enterprise-032411&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Yet Another UPDATE&lt;/i&gt;: &amp;nbsp;Comodo hacker statement released, discussed in detail by Errata Security:&amp;nbsp;&lt;a href="http://erratasec.blogspot.com/2011/03/comodo-hacker-releases-his-manifesto.html"&gt;http://erratasec.blogspot.com/2011/03/comodo-hacker-releases-his-manifesto.html&lt;/a&gt;&amp;nbsp;&amp;nbsp; Yes, Iranian. &amp;nbsp;Yes, not that hard to do, apparently.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Perhaps Final UPDATE:&lt;/i&gt;&amp;nbsp;&amp;nbsp;Ben Adida offers a useful analogy about evolution in discussing how the global PKI became brittle enough to permit this kind of compromise. &amp;nbsp;In my opinion Ben is always thoughtful and his insights and analysis help me to see issues from new perspectives. &amp;nbsp; His discussion is here:&amp;nbsp;&lt;a href="http://benlog.com/articles/2011/03/30/intelligently-designing-trust/"&gt;http://benlog.com/articles/2011/03/30/intelligently-designing-trust/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-863397009706478172?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/863397009706478172/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=863397009706478172' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/863397009706478172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/863397009706478172'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/03/trusted-certificate-compromise.html' title='trusted Certificate compromise - a sophisticated attack'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-707552525702636639</id><published>2011-03-22T09:45:00.000-04:00</published><updated>2011-03-22T09:45:57.046-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AWS'/><title type='text'>on understanding AWS EBS</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh3.googleusercontent.com/-DkC0q227Kro/TYinuymT1sI/AAAAAAAAAhE/hL6WUTUiQTM/s1600/logo_aws.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://lh3.googleusercontent.com/-DkC0q227Kro/TYinuymT1sI/AAAAAAAAAhE/hL6WUTUiQTM/s1600/logo_aws.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Great post by Adrian Cockcroft about EBS. &amp;nbsp; See:&amp;nbsp;&lt;a href="http://perfcap.blogspot.com/2011/03/understanding-and-using-amazon-ebs.html"&gt;http://perfcap.blogspot.com/2011/03/understanding-and-using-amazon-ebs.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is one of the best overviews I've seen and it succinctly explains architectural attributes you should be well aware of. &amp;nbsp; The diagrams are very helpful. &amp;nbsp; Thanks Adrian. &amp;nbsp;I'll be referring to this often.&lt;br /&gt;&lt;br /&gt;AWS here:&amp;nbsp;&lt;a href="http://aws.amazon.com/"&gt;http://aws.amazon.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-707552525702636639?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/707552525702636639/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=707552525702636639' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/707552525702636639'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/707552525702636639'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/03/on-understanding-aws-ebs.html' title='on understanding AWS EBS'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='https://lh3.googleusercontent.com/-DkC0q227Kro/TYinuymT1sI/AAAAAAAAAhE/hL6WUTUiQTM/s72-c/logo_aws.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-1134939857265279090</id><published>2011-03-02T12:03:00.000-05:00</published><updated>2011-03-02T12:03:56.794-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><title type='text'>Federal Cloud Computing Strategy</title><content type='html'>Thanks to CIO.gov here:&amp;nbsp;&lt;a href="http://www.cio.gov/pages.cfm/page/IT-Reform-Series-Federal-Cloud-Computing-Strategy-Published"&gt;http://www.cio.gov/pages.cfm/page/IT-Reform-Series-Federal-Cloud-Computing-Strategy-Published&lt;/a&gt;&amp;nbsp;&amp;nbsp;for publishing this strategy document.&lt;br /&gt;&lt;br /&gt;This provides as good an overview and introduction to the benefits of Cloud Computing as I've seen, albeit from a federal&amp;nbsp;agency adoption&amp;nbsp;perspective. &amp;nbsp;Here is the&amp;nbsp;direct&amp;nbsp;link to the PDF:&amp;nbsp;&lt;a href="http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf"&gt;http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh4.googleusercontent.com/-DRP_Czih6UU/TW50mEtVezI/AAAAAAAAAfc/EBJbdazZA8A/s1600/vivek.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://lh4.googleusercontent.com/-DRP_Czih6UU/TW50mEtVezI/AAAAAAAAAfc/EBJbdazZA8A/s1600/vivek.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&amp;nbsp;&amp;nbsp;Vivek Kundra, USA's CIO is driving this effort. &amp;nbsp; Follow Vivek on Twitter:&amp;nbsp;&lt;span class="Apple-style-span" style="color: #444444; font-family: 'Helvetica Neue', Arial, Helvetica, 'Liberation Sans', FreeSans, sans-serif; line-height: 21px;"&gt;&lt;a href="http://twitter.com/#!/VivekKundra"&gt;@VivekKundra&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-1134939857265279090?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/1134939857265279090/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=1134939857265279090' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1134939857265279090'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1134939857265279090'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/03/federal-cloud-computing-strategy.html' title='Federal Cloud Computing Strategy'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='https://lh4.googleusercontent.com/-DRP_Czih6UU/TW50mEtVezI/AAAAAAAAAfc/EBJbdazZA8A/s72-c/vivek.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-7452492207680876502</id><published>2011-02-23T16:42:00.000-05:00</published><updated>2011-02-23T16:42:55.837-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='NIST'/><title type='text'>NIST addresses Cloud Security and Privacy</title><content type='html'>&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;NIST recently issued a draft document on cloud security and privacy -&amp;nbsp;&lt;a href="http://csrc.nist.gov/publications/drafts/800-145/Draft-SP-800-145_cloud-definition.pdf,"&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; line-height: 10px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; line-height: 10px;"&gt;&lt;span class="Apple-style-span" style="color: steelblue;"&gt;http://csrc.nist.gov/publications/drafts/800-145/Draft-SP-800-145_cloud-defin&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; color: steelblue; line-height: 10px;"&gt;&lt;a href="http://csrc.nist.gov/publications/drafts/800-145/Draft-SP-800-145_cloud-definition.pdf,"&gt;ition.pdf&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Additionally they've republished their cloud&amp;nbsp;definition&amp;nbsp;as a draft&amp;nbsp;document, and&amp;nbsp;started a wiki to&amp;nbsp;facilitate&amp;nbsp;communication about cloud standards, research etc...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;More here:&amp;nbsp;&lt;a href="http://www.nist.gov/itl/csd/cloud-020111.cfm"&gt;http://www.nist.gov/itl/csd/cloud-020111.cfm&lt;/a&gt;,&amp;nbsp;and the wiki is here:&amp;nbsp;&lt;a href="http://collaborate.nist.gov/twiki-cloud-computing/bin/view/CloudComputing/"&gt;http://collaborate.nist.gov/twiki-cloud-computing/bin/view/CloudComputing/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Security has been a reason, and probably a good one, for enterprises to delay moving applications to the cloud. &amp;nbsp; As a result, cloud security has had plenty of attention, not just from NIST, as noted here previously. &amp;nbsp; It continues to be my opinion that security will be a reason to adopt cloud-based solutions, and not a reason to delay. &amp;nbsp;As transparency, agreed standards, business models and service agreements, and technical improvements continue - small, mid-sized, and even larger companies will rely on cloud providers for security. &amp;nbsp; Security talent, solution architecture and infrastructure as well as management attention will be another shared resource provided by the cloud. It is in the cloud providers business interests to solve this problem.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-7452492207680876502?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/7452492207680876502/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=7452492207680876502' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7452492207680876502'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7452492207680876502'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/02/nist-addresses-cloud-security-and.html' title='NIST addresses Cloud Security and Privacy'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-3110114161647961263</id><published>2011-02-16T06:55:00.000-05:00</published><updated>2011-02-16T06:55:11.232-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>further research available on Stuxnet</title><content type='html'>Symantec updates its report, available here: &lt;a href="http://www.symantec.com/connect/blogs/updated-w32stuxnet-dossier-available"&gt;http://www.symantec.com/connect/blogs/updated-w32stuxnet-dossier-available&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Stuxnet is very interesting as it almost assuredly represents the first case of significant cyber-warfare seen in the wild. &amp;nbsp; Its cautionary and we'll see how cyber-warfare evolves from this template.&amp;nbsp; I'd be cautious with those USB disks....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-3110114161647961263?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/3110114161647961263/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=3110114161647961263' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3110114161647961263'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3110114161647961263'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/02/further-research-available-on-stuxnet.html' title='further research available on Stuxnet'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-7632613135467654634</id><published>2011-02-13T21:23:00.000-05:00</published><updated>2011-02-13T21:23:05.044-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ssl'/><category scheme='http://www.blogger.com/atom/ns#' term='python'/><category scheme='http://www.blogger.com/atom/ns#' term='appengine'/><title type='text'>App Engine SDK requires SSL</title><content type='html'>As a Python user I had to teach my environment to use SSL to upload code.&amp;nbsp; This requirement was introduced in a recent SDK release.&amp;nbsp;&amp;nbsp; It was a little complicated, but the best guidelines I found to make it work were here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.developerzen.com/2010/09/23/the-complete-guide-to-setting-up-python-development-environment-on-windows/"&gt;http://www.developerzen.com/2010/09/23/the-complete-guide-to-setting-up-python-development-environment-on-windows/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You need to follow all the steps right through "Install Support for SSL".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-7632613135467654634?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/7632613135467654634/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=7632613135467654634' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7632613135467654634'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7632613135467654634'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/02/app-engine-sdk-requires-ssl.html' title='App Engine SDK requires SSL'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-5616870720334015507</id><published>2011-02-12T09:08:00.001-05:00</published><updated>2011-02-12T09:18:50.312-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='django'/><category scheme='http://www.blogger.com/atom/ns#' term='python'/><category scheme='http://www.blogger.com/atom/ns#' term='appengine'/><title type='text'>new App Engine SDK - 1.4.2</title><content type='html'>see: &lt;a href="http://googlecode.blogspot.com/2011/02/app-engine-142-sdk-api-updates-and.html"&gt;http://googlecode.blogspot.com/2011/02/app-engine-142-sdk-api-updates-and.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;and since I'm a Python guy, the Python SDK notes detail a few specific goodies:&amp;nbsp; &lt;a href="http://code.google.com/p/googleappengine/wiki/SdkReleaseNotes"&gt;http://code.google.com/p/googleappengine/wiki/SdkReleaseNotes&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I'm excited about support for Django 1.2 and the improve presence capability in XMPP&lt;br /&gt;&lt;br /&gt;And, not strictly related to the SDK, from Guido's Tweet stream, something I've wanted for a while:&lt;br /&gt;&lt;blockquote&gt;Check out the Permissions tab on your &lt;a class="  twitter-hashtag" href="http://twitter.com/#%21/search?q=%23appengine" rel="nofollow" title="#appengine"&gt;#&lt;strong&gt;appengine&lt;/strong&gt;&lt;/a&gt; Admin Console. New feature: Role dropdown! Owner, Developer, Viewer. &lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-5616870720334015507?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/5616870720334015507/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=5616870720334015507' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5616870720334015507'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5616870720334015507'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/02/new-app-engine-sdk-142.html' title='new App Engine SDK - 1.4.2'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-2465092958561287126</id><published>2011-02-11T10:26:00.000-05:00</published><updated>2011-02-11T10:26:06.766-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Google offers two factor authentication</title><content type='html'>This doesn't solve everything, but it'll be a good capability to add to a site or two I have developed.&amp;nbsp; See:&lt;br /&gt;&lt;a href="http://googleblog.blogspot.com/2011/02/advanced-sign-in-security-for-your.html"&gt;http://googleblog.blogspot.com/2011/02/advanced-sign-in-security-for-your.html &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-2465092958561287126?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/2465092958561287126/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=2465092958561287126' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2465092958561287126'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2465092958561287126'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/02/google-offers-two-factor-authentication.html' title='Google offers two factor authentication'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-356399599648692289</id><published>2011-02-01T14:38:00.000-05:00</published><updated>2011-02-01T14:38:15.363-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AWS'/><title type='text'>getting started with AWS</title><content type='html'>I've been doing a lot recently with App Engine.&amp;nbsp; For several reasons I need to do a few things with Amazon AWS.&amp;nbsp; In particular, I need to play with Elastic Beanstalk, but that is not for today.&amp;nbsp; For today, I've collected three links to getting started. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://ec2.scripting.com/"&gt;EC2 for Poets&lt;/a&gt; from Dave Winer&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.starstryder.com/2011/01/23/set-up-an-aws-lamp-server-connected-to-a-rds-database/"&gt;Set up an AWS LAMP server connected to a RDS database&lt;/a&gt;, from Pamela Gay via Star Stryder&lt;br /&gt;&lt;h1 style="font-weight: normal;"&gt;&lt;span style="font-size: small;"&gt;And, of course, from the AWS documentation: &lt;a href="http://docs.amazonwebservices.com/AWSEC2/latest/GettingStartedGuide/"&gt;Get Started with EC2&lt;/a&gt;&lt;/span&gt;&lt;/h1&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-356399599648692289?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/356399599648692289/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=356399599648692289' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/356399599648692289'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/356399599648692289'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/02/getting-started-with-aws.html' title='getting started with AWS'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-2217123386516920999</id><published>2011-01-19T07:26:00.001-05:00</published><updated>2011-01-19T07:34:13.775-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='code'/><category scheme='http://www.blogger.com/atom/ns#' term='AWS'/><category scheme='http://www.blogger.com/atom/ns#' term='appengine'/><title type='text'>Elastic Beanstalk</title><content type='html'>Elastic Beanstalk minimizes one of the objections I have about AWS - its lack of a simple deployment capability. This, as other commentators have spelled out, brings AWS even closer to being able to offer a pure PAAS in its portfolio, and bridges a gap with Google's AppEngine.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_KOyrssBxwjc/TTbYRbhOvEI/AAAAAAAAAeo/dT6MTidJ1XI/s1600/aws.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_KOyrssBxwjc/TTbYRbhOvEI/AAAAAAAAAeo/dT6MTidJ1XI/s1600/aws.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;More information here: &lt;a href="http://www.allthingsdistributed.com/2011/01/aws_elastic_beanstalk.html"&gt;http://www.allthingsdistributed.com/2011/01/aws_elastic_beanstalk.html&lt;/a&gt;&lt;br /&gt;and here: &lt;a href="http://aws.typepad.com/aws/2011/01/introducing-elastic-beanstalk.html"&gt;http://aws.typepad.com/aws/2011/01/introducing-elastic-beanstalk.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I believe that PAAS solutions that support Java will offer the best early path for enterprises to bring their apps to the cloud.&amp;nbsp;&amp;nbsp; Elastic Beanstalk is starting with a Java container but promises more.&amp;nbsp; I'd like to see a Python/Django environment - Django might well be able to evolve into a cross-cloud platform approach and help address the 'lock-in" issue.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-2217123386516920999?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/2217123386516920999/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=2217123386516920999' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2217123386516920999'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2217123386516920999'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2011/01/elastic-beanstalk.html' title='Elastic Beanstalk'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_KOyrssBxwjc/TTbYRbhOvEI/AAAAAAAAAeo/dT6MTidJ1XI/s72-c/aws.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-7725045993162708744</id><published>2010-12-17T17:23:00.000-05:00</published><updated>2010-12-17T17:23:50.308-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>AWS Achieves PCI DSS 2.0</title><content type='html'>Congratulations to Amazon AWS on achieving validated service provider status.&amp;nbsp; Details here:&lt;br /&gt;&lt;a href="http://aws.typepad.com/aws/2010/12/aws-achieves-pci-dss-20-validated-service-provider-status.html"&gt;http://aws.typepad.com/aws/2010/12/aws-achieves-pci-dss-20-validated-service-provider-status.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;From the Amazon Web Services blog, a relevant snippet:&lt;br /&gt;&lt;blockquote&gt;"Until recently, it was unthinkable to even consider the possibility of  attaining PCI compliance within a virtualized, multi-tenant environment.  PCI DSS version 2.0, the newest version of DSS published in late  October 2010, did provide guidance for dealing with virtualization but  did not provide any guidance around multi-tenant environments. However,  even without multi-tenancy guidance, we were able to work with our PCI  assessor to document our security management processes, PCI controls,  and compensating controls to show how our core services effectively and  securely segregate each AWS customer within their own protected  environment. Our PCI assessor found our security and architecture  conformed with the new PCI standard and verified our compliance."&lt;/blockquote&gt;&lt;br /&gt;Security  is always one of the first objections raised when discussing moving  important apps with regulated data to a cloud provider.&amp;nbsp; Its been my  opinion for a while that cloud providers will be in position to offer  best-in-class security solutions sooner or later.&amp;nbsp; First, the business  model cries out for it - cloud providers can attract more applications,  and more significant applications, if they can address security  requirements.&amp;nbsp; Second - cloud providers will be in good position to  address security by leveraging scarce security expertise across all  their hosted applications.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I expect providers like Google, Amazon,  Rackspace, etc... can attract and retain excellent security professionals  to make sure thior infrastructure is buttoned up tight.&amp;nbsp; Or as tight as  is feasible.&amp;nbsp; Not to say there won't be breaches, there will be, but  they should be able to do the job right.&amp;nbsp; We might have to pay a few  extra dollars of course.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-7725045993162708744?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/7725045993162708744/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=7725045993162708744' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7725045993162708744'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7725045993162708744'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2010/12/aws-achieves-pci-dss-20.html' title='AWS Achieves PCI DSS 2.0'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-6974394811872847401</id><published>2010-08-08T16:02:00.000-04:00</published><updated>2010-08-08T16:02:01.394-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Cloud Security - 2010 Google Faculty Summit</title><content type='html'>Here is a set of videos from a Google Faculty Summit recently; the focus is on security and privacy, particularly from a research point of view.&amp;nbsp;&amp;nbsp; I'm working my way thru them, and I can vouch that these are worthwhile and mind-opening.&lt;br /&gt;&lt;br /&gt;See: &lt;a href="http://research.google.com/university/relations/facultysummit2010/"&gt;http://research.google.com/university/relations/facultysummit2010/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-6974394811872847401?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/6974394811872847401/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=6974394811872847401' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6974394811872847401'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6974394811872847401'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2010/08/cloud-security-2010-google-faculty.html' title='Cloud Security - 2010 Google Faculty Summit'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-6172914286284287859</id><published>2010-08-03T14:14:00.000-04:00</published><updated>2010-08-03T14:14:08.228-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='appengine'/><title type='text'>App Engine SDK</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_KOyrssBxwjc/TFhb7AbYhxI/AAAAAAAAAcY/tLMn_VHII6U/s1600/google-app-engine-logo.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_KOyrssBxwjc/TFhb7AbYhxI/AAAAAAAAAcY/tLMn_VHII6U/s1600/google-app-engine-logo.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&amp;nbsp;A new pre-release SDK has been announced for App Engine.&amp;nbsp;&amp;nbsp; Of particular interest to me, and I expect useful in a current project, are:&lt;br /&gt;&lt;blockquote&gt;&lt;ul&gt;&lt;li&gt;Multitenancy is now supported in the datastore, allowing better compartmentalization of user data.&amp;nbsp;&lt;/li&gt;&lt;li&gt;Automatic image thumbnailing is now available in the Images API using get_url_base().&amp;nbsp;&lt;/li&gt;&lt;li&gt;Users can now serve custom static error pages for over_quota, dos_api_denial, and default cases. &lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;For more details, &lt;a href="http://groups.google.com/group/google-appengine/browse_thread/thread/6b02929cb6832c3a#"&gt;see: http://groups.google.com/group/google-appengine/browse_thread/thread/6b02929cb6832c3a#&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-6172914286284287859?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/6172914286284287859/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=6172914286284287859' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6172914286284287859'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6172914286284287859'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2010/08/app-engine-sdk.html' title='App Engine SDK'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_KOyrssBxwjc/TFhb7AbYhxI/AAAAAAAAAcY/tLMn_VHII6U/s72-c/google-app-engine-logo.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-4328388940937390186</id><published>2010-07-20T09:33:00.002-04:00</published><updated>2010-07-26T11:06:16.901-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='standards'/><category scheme='http://www.blogger.com/atom/ns#' term='opensource'/><title type='text'>OpenStack</title><content type='html'>The interwebs are abuzz with news of OpenStack - an open source cloud stack initiative incorporating NASA's Nebula, Rackspace code, and the work of many others.&lt;br /&gt;&lt;br /&gt;Here are three helpful links if you want to learn more:&lt;br /&gt;&lt;br /&gt;GigaOM: &lt;a href="http://gigaom.com/2010/07/19/why-openstack-matters-cloud-insiders-weigh-in/"&gt;http://gigaom.com/2010/07/19/why-openstack-matters-cloud-insiders-weigh-in/ &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;TechCrunch:&lt;a href="http://techcrunch.com/2010/07/18/openstack-org-rackspace-open-sources-their-cloud-services-platform-and-gets-nasa-on-board/"&gt; http://techcrunch.com/2010/07/18/openstack-org-rackspace-open-sources-their-cloud-services-platform-and-gets-nasa-on-board/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;ZDNet: &lt;a href="http://www.zdnet.com/blog/open-source/nasa-gives-openstack-instant-credibility/6878"&gt;http://www.zdnet.com/blog/open-source/nasa-gives-openstack-instant-credibility/6878&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;My take:&amp;nbsp;&amp;nbsp; The "Cloud" continues as an area of rapid, relentless innovation.&amp;nbsp; The cloud market is exploding with new approaches, technologies, architectures, etc...&amp;nbsp;&amp;nbsp; A credible open source effort to develop open technologies for enterprise and government cloud deployments will help foster competition and fight vendor lock-in for this market.&amp;nbsp;&amp;nbsp; Innovation is occurring too rapidly for standards efforts to make sense yet, but open work will lead to good results in interoperability as well.&lt;br /&gt;&lt;br /&gt;update: this article discusses NASA's decision to drop Eucalyptus from Nebula.&amp;nbsp; it provides an interesting insight about commercializing open source.&amp;nbsp; (and, en passant, a discussion of Eucalyptus&amp;nbsp; scalability). see: &lt;a href="http://www.theregister.co.uk/2010/07/20/why_nasa_is_dropping_eucalyptus_from_its_nebula_cloud/"&gt;http://www.theregister.co.uk/2010/07/20/why_nasa_is_dropping_eucalyptus_from_its_nebula_cloud/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;update 2: more from Andy&amp;nbsp; Oram at O'Reilly Community: &lt;a href="http://broadcast.oreilly.com/2010/07/openstack-offered-as-rackspace.html"&gt;http://broadcast.oreilly.com/2010/07/openstack-offered-as-rackspace.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;update 3: Fred Trotter note the applicability of Open Stack to HealthCare IT:&lt;br /&gt;&lt;a href="http://www.fredtrotter.com/2010/07/26/openstack-and-software-freedom-in-healthcare-it/"&gt;http://www.fredtrotter.com/2010/07/26/openstack-and-software-freedom-in-healthcare-it/ &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-4328388940937390186?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/4328388940937390186/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=4328388940937390186' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4328388940937390186'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4328388940937390186'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2010/07/openstack.html' title='OpenStack'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-873968454084221970</id><published>2010-07-19T14:51:00.001-04:00</published><updated>2010-07-19T14:52:52.593-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>PKI in the news - revoking certificate associated with malware</title><content type='html'>VeriSign (working with Microsoft) is revoking the public key certificate associated with the signing key used (subsequently?) to sign some drivers that were part of a malware distribution.&amp;nbsp; Here is a summary article: &lt;a href="http://threatpost.com/en_us/blogs/verisign-revokes-certificate-used-sign-stuxnet-malware-071710"&gt;http://threatpost.com/en_us/blogs/verisign-revokes-certificate-used-sign-stuxnet-malware-071710&lt;/a&gt;, thanks to the high-quality site Threatpost.&lt;br /&gt;&lt;br /&gt;The article also describes innovations in the malware loading mechanism, which are of less interest to me. &amp;nbsp; I look forward to an article with more technical details that can address PKI-related question like:&lt;br /&gt;&lt;br /&gt;If the certificate expired in June, why is it still necessary to revoke it?&amp;nbsp; (Kind of an academic question - many applications don't check revocation status, much less expiry dates.)&amp;nbsp; but, for the record.&lt;br /&gt;&lt;br /&gt;How did the malware distributor access the private signing key used to sign the driver?&amp;nbsp; It would be very interesting to know how the driver-signing trust chin was broken.&lt;br /&gt;&lt;br /&gt;I've worked with PKI in the past, with several companies and in a few consulting engagements.&amp;nbsp;&amp;nbsp; PKI is always interesting, technically challenging, and prone, unfortunately, to failures of differing types due to its underlying complexity.&amp;nbsp;&amp;nbsp; Can't live with it, and can't live without it.&amp;nbsp;&amp;nbsp; (And can't shoot it.)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-873968454084221970?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/873968454084221970/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=873968454084221970' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/873968454084221970'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/873968454084221970'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2010/07/pki-in-news-revoking-certs-used-to-sign.html' title='PKI in the news - revoking certificate associated with malware'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-3078760988551531505</id><published>2010-07-07T06:47:00.001-04:00</published><updated>2010-07-07T06:53:34.153-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><title type='text'>more cloud taxonomy</title><content type='html'>A post from Stefan Reid teases a full report from Forrester laying out a more comprehensive cloud taxonomy.&amp;nbsp; I continue to believe that you can't successfully make decisions about a cloud strategy unless you have a good grasp of what is meant by cloud, and what types of cloud might influence your decision strategy.&lt;br /&gt;&lt;br /&gt;This graphic suggests you should consider private clouds to be primarily a visualization story.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_KOyrssBxwjc/TDRaDv5CoNI/AAAAAAAAAcI/bEWe6vIoYkI/s1600/cloud.f.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="205" src="http://4.bp.blogspot.com/_KOyrssBxwjc/TDRaDv5CoNI/AAAAAAAAAcI/bEWe6vIoYkI/s320/cloud.f.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I have no relationship to Forrester but if understanding cloud taxonomy is important to you, this may be a useful report.&amp;nbsp; Link: &lt;a href="http://blogs.forrester.com/stefan_ried/10-07-06-forresters_cloud_computing_taxonomy"&gt;http://blogs.forrester.com/stefan_ried/10-07-06-forresters_cloud_computing_taxonomy&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-3078760988551531505?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/3078760988551531505/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=3078760988551531505' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3078760988551531505'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3078760988551531505'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2010/07/more-cloud-taxonomy.html' title='more cloud taxonomy'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_KOyrssBxwjc/TDRaDv5CoNI/AAAAAAAAAcI/bEWe6vIoYkI/s72-c/cloud.f.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-3670757886835456470</id><published>2010-06-22T08:51:00.000-04:00</published><updated>2010-06-22T08:51:22.286-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><title type='text'>cloud performance</title><content type='html'>From&lt;a href="http://twitter.com/acroll"&gt; @acroll&lt;/a&gt; at &lt;a href="http://radar.oreilly.com/2010/06/on-the-performance-of-clouds.htm"&gt;O'Reilly Radar&lt;/a&gt;, this post offers a snapshot of a cloud performance study by &lt;a href="http://www.bitcurrent.com/new-report-on-cloud-performance/"&gt;bitcurrent&lt;/a&gt;.&amp;nbsp;&amp;nbsp; I continue to like Google App Engine.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.bitcurrent.com/wp-content/uploads/2010/06/BCtest-postchart.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="216" src="http://www.bitcurrent.com/wp-content/uploads/2010/06/BCtest-postchart.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanks to bitcurrent and WebMetrics for doing the study and making it available.&amp;nbsp; All details are available at the webmetrics site:&lt;a href="http://www.webmetrics.com/landingpage/bitcurrentcloud/"&gt; http://www.webmetrics.com/landingpage/bitcurrentcloud/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;(image: http://www.bitcurrent.com/wp-content/uploads/2010/06/BCtest-postchart.png)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-3670757886835456470?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/3670757886835456470/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=3670757886835456470' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3670757886835456470'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3670757886835456470'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2010/06/cloud-performance.html' title='cloud performance'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-8038223192494061460</id><published>2010-05-27T14:20:00.000-04:00</published><updated>2010-05-27T14:20:16.290-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='#googleio'/><title type='text'>some snapshots from Google I/O 2010</title><content type='html'>&lt;div style="text-align: left;"&gt;Some real content in a post to come real soon now.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://1.bp.blogspot.com/_KOyrssBxwjc/S_63lCMl0jI/AAAAAAAAAbw/BVhm0uRpc_M/s1600/arrive.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://1.bp.blogspot.com/_KOyrssBxwjc/S_63lCMl0jI/AAAAAAAAAbw/BVhm0uRpc_M/s320/arrive.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://2.bp.blogspot.com/_KOyrssBxwjc/S_63nnL4ysI/AAAAAAAAAb0/ew53rGmSEyI/s1600/waiting.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="239" src="http://2.bp.blogspot.com/_KOyrssBxwjc/S_63nnL4ysI/AAAAAAAAAb0/ew53rGmSEyI/s320/waiting.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://4.bp.blogspot.com/_KOyrssBxwjc/S_63pfREU1I/AAAAAAAAAb4/1H6mlKSXJa8/s1600/more.waiting.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="239" src="http://4.bp.blogspot.com/_KOyrssBxwjc/S_63pfREU1I/AAAAAAAAAb4/1H6mlKSXJa8/s320/more.waiting.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-8038223192494061460?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/8038223192494061460/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=8038223192494061460' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8038223192494061460'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8038223192494061460'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2010/05/some-snapshots-from-google-io-2010.html' title='some snapshots from Google I/O 2010'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_KOyrssBxwjc/S_63lCMl0jI/AAAAAAAAAbw/BVhm0uRpc_M/s72-c/arrive.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-9106615503916811501</id><published>2010-04-27T10:11:00.001-04:00</published><updated>2010-07-07T07:07:35.595-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><title type='text'>another Cloud Computing article with definitions (among other things)</title><content type='html'>from ACM: &lt;a href="http://cacm.acm.org/magazines/2010/5/87259-why-cloud-computing-will-never-be-free/fulltext"&gt;http://cacm.acm.org/magazines/2010/5/87259-why-cloud-computing-will-never-be-free/fulltext&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The author includes the first reference that penetrated my awareness of "Cloud 2.0" - what he calls value-based Clouds.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-9106615503916811501?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/9106615503916811501/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=9106615503916811501' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/9106615503916811501'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/9106615503916811501'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2010/04/another-cloud-computing-article-with.html' title='another Cloud Computing article with definitions (among other things)'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-7296567723815194468</id><published>2010-04-09T16:09:00.000-04:00</published><updated>2010-04-09T16:09:16.567-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><title type='text'>two more good Cloud presentations</title><content type='html'>&lt;a href="http://www.davidchappell.com/blog/index.php"&gt;&lt;/a&gt;&lt;a href="http://www.davidchappell.com/blog/index.php"&gt;David Chappell&lt;/a&gt; has an excellent presentation on cloud platforms, PDF here:&lt;a href="http://www.esri.com/events/devsummit/pdf/chappell-slides.pdf"&gt; http://www.esri.com/events/devsummit/pdf/chappell-slides.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here is an overview of Microsoft's Azure: &lt;a href="http://www.slideshare.net/lynnlangit/windows-azure-platform-2626957"&gt;http://www.slideshare.net/lynnlangit/windows-azure-platform-2626957&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-7296567723815194468?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/7296567723815194468/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=7296567723815194468' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7296567723815194468'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7296567723815194468'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2010/04/two-more-good-cloud-presentations.html' title='two more good Cloud presentations'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-1982438133267799721</id><published>2010-04-07T16:46:00.000-04:00</published><updated>2010-04-07T16:46:30.934-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>secure development in the cloud - force.com</title><content type='html'>The guys at force.com have added a section in their developer area focused solely on secure development.&amp;nbsp; Some of this is force.com specific, but there is a lot of generally useful information condensed well on the site.&lt;br /&gt;&lt;br /&gt;See:&amp;nbsp;&lt;a href="http://blog.sforce.com/sforce/2010/04/introducing-forcecom-secure-cloud-development.html"&gt; http://blog.sforce.com/sforce/2010/04/introducing-forcecom-secure-cloud-development.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-1982438133267799721?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/1982438133267799721/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=1982438133267799721' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1982438133267799721'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1982438133267799721'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2010/04/secure-development-in-cloud-forcecom.html' title='secure development in the cloud - force.com'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-8751972616652961359</id><published>2010-04-02T16:25:00.002-04:00</published><updated>2010-04-02T16:34:29.438-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><title type='text'>cloud computing overview</title><content type='html'>due to Communications of the ACM:&lt;a href="http://cacm.acm.org/magazines/2010/4/81493-a-view-of-cloud-computing/fulltext"&gt; http://cacm.acm.org/magazines/2010/4/81493-a-view-of-cloud-computing/fulltext&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is a good overview that makes several key points that help with the definition of cloud computing, and related nomenclature and classification.&amp;nbsp;&amp;nbsp; I believe that the hype around cloud is so high that many vendors and solution providers bend over backwards to define cloud computing so that whatever they are pitching is a key cloud component you can't live without.&amp;nbsp; Articles like this help provide a framework to sort out the clutter.&lt;br /&gt;&lt;br /&gt;Their list of 10 obstacles and opportunities is particularly well-done and insightful.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-8751972616652961359?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/8751972616652961359/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=8751972616652961359' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8751972616652961359'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8751972616652961359'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2010/04/cloud-computing-overview.html' title='cloud computing overview'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-3087925532840388888</id><published>2010-01-05T16:25:00.005-05:00</published><updated>2010-04-07T16:42:56.111-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>getting started with cloud security</title><content type='html'>Think of this post as a trailhead for learning more about the various issues, opinions, and resources relevant for cloud security.  I don't claim this is complete, or the best way to start, but it might be helpful if you're interested in cloud security and you are just beginning.&lt;br /&gt;&lt;br /&gt;First, a couple of useful resources on cloud computing in general:&lt;br /&gt;&lt;br /&gt;The Economist has a briefing on cloud computing, focusing on how companies like Microsoft, Google, and others (not to forget Rackspace) will compete in this new space:&lt;br /&gt;&lt;a href="http://www.economist.com/displaystory.cfm?story_id=14637206"&gt;http://www.economist.com/displaystory.cfm?story_id=14637206&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;NIST is looking closely at cloud frameworks, taxonomy, and security:&lt;br /&gt;&lt;a href="http://csrc.nist.gov/groups/SNS/cloud-computing/"&gt;http://csrc.nist.gov/groups/SNS/cloud-computing/&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;There are many very good technical resources that address cloud security.  I can suggest the following:&lt;br /&gt;&lt;br /&gt;Technology Review, published by MIT, has a 5 page article on cloud security:&lt;br /&gt;&lt;a href="http://www.technologyreview.com/web/24166/"&gt;http://www.technologyreview.com/web/24166/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://www.cloudsecurityalliance.org/"&gt;Cloud Security Alliance&lt;/a&gt; is the go-to resource for cloud security, in my opinion, and in particular you should read the latest rev of their Cloud Security Guidance.&lt;br /&gt;&lt;br /&gt;enisa published a Cloud Computing Risk Assessment:&lt;br /&gt;&lt;a href="http://www.enisa.europa.eu/act/rm/files/deliverables/cloud-computing-risk-assessment"&gt;http://www.enisa.europa.eu/act/rm/files/deliverables/cloud-computing-risk-assessment&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Several more focused and technical resources are also helpful, and include Craig Balding's European RSA 2009 presentation:&lt;br /&gt;&lt;a href="http://www.slideshare.net/craigbalding/what-everyone-ought-to-know-about-cloud-security"&gt;http://www.slideshare.net/craigbalding/what-everyone-ought-to-know-about-cloud-security&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here is a very illuminating presentation given at BlackHat USA 2009: &lt;br /&gt;&lt;a href="http://www.slideshare.net/astamos/cloud-computing-security"&gt;http://www.slideshare.net/astamos/cloud-computing-security&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The site for the ACM's 2009 Cloud Computing Security Workshop has a number of presentations and papers you can download if you are interested in more technical topics:&lt;br /&gt;&lt;a href="http://crypto.cs.stonybrook.edu/ccsw09/"&gt;http://crypto.cs.stonybrook.edu/ccsw09/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There are very many blogs that address or mention cloud security.  Rather than try (and fail) to provide a comprehensive list, I'll suggest you look at Chris Hoff's blog &lt;a href="http://www.rationalsurvivability.com/blog/"&gt;Rational Survivability&lt;/a&gt;.   For the record - Chris led a discussion of security at Cloud Camp Boston and that discussion introduced me to some of these resources (thanks Chris, my head hurts now...).  Chris also is a leader in the &lt;a href="http://groups.google.com/group/A6WG"&gt;A6 working group&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Maybe in another post I should try to list the various experts that, on Twitter, are helping to drive this forward.  Maybe.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;UPDATE:&amp;nbsp; &lt;/i&gt;Check out&lt;a href="http://cloudpaas.org/"&gt; http://cloudpaas.org/&lt;/a&gt; for an interesting matrix laying out features and capabilities of various clouds.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-3087925532840388888?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/3087925532840388888/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=3087925532840388888' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3087925532840388888'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3087925532840388888'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2010/01/getting-started-with-cloud-security.html' title='getting started with cloud security'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-3807827913860256612</id><published>2009-12-25T11:40:00.003-05:00</published><updated>2009-12-28T08:10:19.606-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crypto'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>its all about key management</title><content type='html'>Bruce Schneier has it right with respect to the recent kerfuffle about unmanned drone video encryption.   See: &lt;a href="http://www.schneier.com/blog/archives/2009/12/intercepting_pr.html"&gt;http://www.schneier.com/blog/archives/2009/12/intercepting_pr.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;UPDATE&lt;/b&gt;&lt;/i&gt;: there is always room for debate.  Ben Adida agrees that key management is difficult, but suggests that syndicating the video stream may offer an alternative approach.  See: &lt;a href="http://benlog.com/articles/2009/12/27/sometimes-its-not-counter-intuitive/"&gt;http://benlog.com/articles/2009/12/27/sometimes-its-not-counter-intuitive/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;My opinion: Designing real-world security solutions is hard - to further the debate we would need to dive deeply into the use cases and understand the detailed requirements and flows - then analyze the existing solution in light of current technology and practices.   I'll bet there are some details about requirements and use cases that haven't been shared publicly.  Just saying.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-3807827913860256612?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/3807827913860256612/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=3807827913860256612' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3807827913860256612'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3807827913860256612'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2009/12/its-all-about-key-management.html' title='its all about key management'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-6811737052683556725</id><published>2009-11-18T10:58:00.000-05:00</published><updated>2009-11-18T10:58:08.400-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>EC2 Vulnerability?</title><content type='html'>Academic research suggests attack vectors for cloud computing applications.&lt;br /&gt;&lt;br /&gt;see: &lt;a href="http://www.technologyreview.com/computing/23792/"&gt;http://www.technologyreview.com/computing/23792/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Seems like a cloud should not leak, even implicitly, structural information about configuration, etc...   Also seems like there are reasonable approaches to plug these types of leaks, but the larger point is that there are surely many ways to attack cloud-based services, and creative security researchers (and hackers) will find them.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-6811737052683556725?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/6811737052683556725/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=6811737052683556725' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6811737052683556725'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6811737052683556725'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2009/11/ec2-vulnerability.html' title='EC2 Vulnerability?'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-7450715509974950012</id><published>2009-10-23T11:41:00.000-04:00</published><updated>2009-10-23T11:41:22.202-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='identity'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>medical records online, or in the cloud?</title><content type='html'>Caution should prevail; see: &lt;a href="http://www.wired.com/threatlevel/2009/10/medicalrecords/"&gt;Medical Records: Stored in the Cloud, Sold on the Open Market&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Never underestimate the power of birthday, ZIP code and gender for identification.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-7450715509974950012?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/7450715509974950012/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=7450715509974950012' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7450715509974950012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7450715509974950012'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2009/10/medical-records-online-or-in-cloud.html' title='medical records online, or in the cloud?'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-3026092385425216473</id><published>2009-10-04T15:11:00.000-04:00</published><updated>2009-10-04T15:11:38.221-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>a cautionary tale about cloud security</title><content type='html'>Well described by the BitBucket team - a problem with an attack on their AWS-based infrastructure.  See: &lt;a href="http://blog.bitbucket.org/2009/10/04/on-our-extended-downtime-amazon-and-whats-coming/"&gt;http://blog.bitbucket.org/2009/10/04/on-our-extended-downtime-amazon-and-whats-coming/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In the end it looks like the right thing happened, but certainly there were a few travails along the way.  This episode suggests you need your own sophisticated technical resources to work the problem with the cloud provider team.&lt;br /&gt;&lt;br /&gt;For those who worry that finger-pointing or delay in problem identification can occur with your cloud provider, this episode confirms some of your fears.  Its early yet, and over time providers will be able to distinguish themselves by their tools and techniques for rapid identification and resolution of problems, including security-related attacks like this one.  Its a learning curve for all involved.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-3026092385425216473?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/3026092385425216473/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=3026092385425216473' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3026092385425216473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3026092385425216473'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2009/10/cautionary-tale-about-cloud-security.html' title='a cautionary tale about cloud security'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-8991109024036241888</id><published>2009-09-14T14:09:00.001-04:00</published><updated>2009-09-14T14:10:00.975-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crypto'/><title type='text'>crypto agility</title><content type='html'>MSDN offers a good overview and rationale for crypto agility here: &lt;a href="http://msdn.microsoft.com/en-us/magazine/ee321570.aspx"&gt;http://msdn.microsoft.com/en-us/magazine/ee321570.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In my opinion, if you're programming crypto, you should be an expert developing library code that application programmers use.  If you're developing a library, then there is no excuse for ignoring crypto agility.  IMO.&lt;br /&gt;&lt;br /&gt;If you're an application developer - don't develop your own crypto.  Evaluate and choose developed code with a good reputation that meets your requirements.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-8991109024036241888?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/8991109024036241888/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=8991109024036241888' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8991109024036241888'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8991109024036241888'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2009/09/crypto-agility.html' title='crypto agility'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-8044647823542487058</id><published>2009-07-31T10:00:00.000-04:00</published><updated>2009-07-31T10:00:44.254-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='code'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>security considerations in coding</title><content type='html'>There is a lot of value in considering security in our software development lifecyle.&lt;br /&gt;Here is a good resource to identify coding issues during development or review.&lt;br /&gt;&lt;br /&gt;See the top 25 most dangerous programming errors: &lt;a href="http://cwe.mitre.org/top25/index.html"&gt;http://cwe.mitre.org/top25/index.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-8044647823542487058?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/8044647823542487058/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=8044647823542487058' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8044647823542487058'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8044647823542487058'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2009/07/security-considerations-in-coding.html' title='security considerations in coding'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-6211708177041610856</id><published>2009-07-23T06:35:00.001-04:00</published><updated>2009-07-23T06:37:24.127-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crypto'/><category scheme='http://www.blogger.com/atom/ns#' term='python'/><title type='text'>New Crypto Library</title><content type='html'>with Python bindings!&lt;br /&gt;&lt;br /&gt;NaCl: Networking and Cryptography library:&lt;a href="http://nacl.cace-project.eu/"&gt; http://nacl.cace-project.eu/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Thanks to &lt;a href="http://cace-project.eu/"&gt;http://cace-project.eu/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-6211708177041610856?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/6211708177041610856/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=6211708177041610856' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6211708177041610856'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6211708177041610856'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2009/07/new-crypto-library.html' title='New Crypto Library'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-1453745404311209977</id><published>2009-04-27T11:36:00.000-04:00</published><updated>2009-04-27T11:36:55.395-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='study'/><category scheme='http://www.blogger.com/atom/ns#' term='bcb4'/><title type='text'>bar camp boston 4</title><content type='html'>Spent Saturday at BCB4 - &lt;a href="http://www.barcampboston.org/"&gt;http://www.barcampboston.org/&lt;/a&gt;&amp;nbsp;&amp;nbsp; twitter #bcb4&lt;br /&gt;&lt;br /&gt;It was well worth my investment of time, and I regret not being able to attend Sunday as well.&amp;nbsp; The un-conference concept worked well, the organizers did a great job, and several of the sessions I attended were really useful and interesting.&lt;br /&gt;&lt;br /&gt;In particular: &lt;i&gt;Raw Data: Facilitating Data Reuse on the Web&lt;/i&gt;, and&amp;nbsp; &lt;i&gt;How to Go from PHP to Django&amp;nbsp;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;There were other sessions I missed that I would have liked to attend but for the restriction on being in two places at once.&lt;br /&gt;&lt;br /&gt;Here is a quick random snap of some of the crowd&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_KOyrssBxwjc/SfXQdsCYBYI/AAAAAAAAAVA/nu94uRBW9h4/s1600-h/bcb4.crowd.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_KOyrssBxwjc/SfXQdsCYBYI/AAAAAAAAAVA/nu94uRBW9h4/s320/bcb4.crowd.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-1453745404311209977?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/1453745404311209977/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=1453745404311209977' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1453745404311209977'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1453745404311209977'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2009/04/bar-camp-boston-4.html' title='bar camp boston 4'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_KOyrssBxwjc/SfXQdsCYBYI/AAAAAAAAAVA/nu94uRBW9h4/s72-c/bcb4.crowd.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-1845902056224971210</id><published>2009-03-03T10:31:00.003-05:00</published><updated>2009-03-03T10:32:04.038-05:00</updated><title type='text'>twitter</title><content type='html'>well, i'm starting to play around with Twitter.&amp;nbsp; can't say I see all the uses yet, but I've found some that are helpful, especially using Search to follow topics I have an interest in.&lt;br /&gt;&lt;br /&gt;more soon.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-1845902056224971210?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/1845902056224971210/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=1845902056224971210' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1845902056224971210'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1845902056224971210'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2009/03/twitter.html' title='twitter'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-4797442917296696096</id><published>2009-02-22T09:31:00.000-05:00</published><updated>2009-02-22T09:31:21.157-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DHS'/><title type='text'>2009 National Infrastructure Protection Plan</title><content type='html'>The 2009 National Infrastructure Protection Plan is available for download from DHS here:&lt;a href="http://www.dhs.gov/xprevprot/programs/editorial_0827.shtm"&gt; http://www.dhs.gov/xprevprot/programs/editorial_0827.shtm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;An inital scan suggests this will be a helpful report to read if one is suffering from a late-night bout of insomnia.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-4797442917296696096?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/4797442917296696096/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=4797442917296696096' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4797442917296696096'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4797442917296696096'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2009/02/2009-national-infrastructure-protection.html' title='2009 National Infrastructure Protection Plan'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-8426095009199240905</id><published>2009-02-20T08:36:00.000-05:00</published><updated>2009-02-20T08:36:58.452-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='crypto'/><category scheme='http://www.blogger.com/atom/ns#' term='browser'/><title type='text'>breaking SSL?</title><content type='html'>A presentation at Black Hat demonstrated some techniques for breaking SSL.&amp;nbsp; Thoughtful analysis provided by Dan Kminsky in this &lt;a href="http://www.doxpara.com/?p=1269"&gt;post&lt;/a&gt;, including a reference to a PDF of the original presentation.&lt;br /&gt;&lt;br /&gt;As frequently happens, you can find securiy holes in how the crypto algorithms are integrated into an application that humans use.&lt;br /&gt;&lt;br /&gt;Reading thru Dans analysis provdies some good insight in how to understand the problems and attacks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-8426095009199240905?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/8426095009199240905/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=8426095009199240905' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8426095009199240905'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8426095009199240905'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2009/02/breaking-ssl.html' title='breaking SSL?'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-7802410225885903731</id><published>2009-02-04T06:49:00.007-05:00</published><updated>2009-02-04T06:57:01.996-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='study'/><category scheme='http://www.blogger.com/atom/ns#' term='python'/><title type='text'>Python's beginnings</title><content type='html'>&lt;a href="http://python.org/"&gt;Python &lt;/a&gt;is my implementation language of choice - I find it approachable, intuitive and powerful.&amp;nbsp;&amp;nbsp; I still have much to learn about it but feel productive using it for small tools or larger tasks (for example, with &lt;a href="http://www.djangoproject.com/"&gt;Django&lt;/a&gt;.)&lt;br /&gt;&lt;br /&gt;Python's creator, &lt;a href="http://en.wikipedia.org/wiki/Guido_van_Rossum"&gt;Guido van Rossum&lt;/a&gt;, is writing a series of blog entries describing &lt;a href="http://python-history.blogspot.com/"&gt;The History of Python&lt;/a&gt;&amp;nbsp; - reading these provides fun insight into the early development of a great language.&amp;nbsp; Thanks Guido.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-7802410225885903731?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/7802410225885903731/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=7802410225885903731' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7802410225885903731'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7802410225885903731'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2009/02/history-of-python.html' title='Python&apos;s beginnings'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-4437487225504977150</id><published>2009-01-09T09:52:00.001-05:00</published><updated>2009-01-09T10:05:51.561-05:00</updated><title type='text'>Jam Cell Phones During Terror Attack?</title><content type='html'>Surely this idea needs rethinking/recasting.&amp;nbsp;&amp;nbsp; &lt;a href="http://blog.wired.com/defense/2009/01/nypd-eyes-disru.html"&gt;http://blog.wired.com/defense/2009/01/nypd-eyes-disru.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I would imagine attack planners would have backup plans in case they lost communication in any scenario.&amp;nbsp;&amp;nbsp; On the other hand, ordinary citizens wouldn't - no warnings to family members, no reports to authorities.&amp;nbsp;&amp;nbsp; Ordinary people enabled by communcation technology brought that 9/11 hijacked plane done in Pennsylvania - avoiding greater catastrophe in Washington.&amp;nbsp;&amp;nbsp;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-4437487225504977150?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/4437487225504977150/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=4437487225504977150' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4437487225504977150'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4437487225504977150'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2009/01/jam-cell-phones-during-terror-attack.html' title='Jam Cell Phones During Terror Attack?'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-6644599847258046155</id><published>2008-12-30T15:16:00.002-05:00</published><updated>2008-12-31T06:54:52.907-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='crypto'/><category scheme='http://www.blogger.com/atom/ns#' term='hash'/><title type='text'>why were you using MD5 anyway?</title><content type='html'>Just published at the &lt;a href="http://events.ccc.de/congress/2008/"&gt;CCC&lt;/a&gt; is a documented attack on PKIs with CAs that use the MD5 hash algorithm.&amp;nbsp;&amp;nbsp; Its been known for some time that using MD5 is a mistake - perhaps soon someone will build a browser plug-in to generically warn if any of your certs base trust on MD5.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Here are the details in a well-written paper - &lt;a href="http://www.win.tue.nl/hashclash/rogue-ca/"&gt;creating a rogue CA certificate.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Update&lt;/b&gt;: the estimable Ed Felten explains this issue in real world terms: &lt;a href="http://www.freedom-to-tinker.com/blog/felten/researchers-show-how-forge-site-certificates"&gt;http://www.freedom-to-tinker.com/blog/felten/researchers-show-how-forge-site-certificates&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-6644599847258046155?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/6644599847258046155/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=6644599847258046155' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6644599847258046155'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6644599847258046155'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/12/dont-use-md5.html' title='why were you using MD5 anyway?'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-3422539369617591272</id><published>2008-12-30T08:55:00.000-05:00</published><updated>2008-12-30T09:01:17.225-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='study'/><category scheme='http://www.blogger.com/atom/ns#' term='browser'/><title type='text'>browser security resource</title><content type='html'>Very useful document available from Google: &lt;a href="http://code.google.com/p/browsersec/wiki/Main"&gt;Browser Security Handbook&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I expect Google security guys will keep this Wiki up to date.&amp;nbsp;&amp;nbsp; If you're interested in understanding browser security issues then this is a good resource to work through.&amp;nbsp; With so many apps moving to the cloud, and the browser as the default client, every programmer should understand browser security.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-3422539369617591272?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/3422539369617591272/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=3422539369617591272' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3422539369617591272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3422539369617591272'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/12/browser-security-resource.html' title='browser security resource'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-893001884869845103</id><published>2008-12-10T17:07:00.000-05:00</published><updated>2008-12-10T17:21:46.259-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='infosec'/><category scheme='http://www.blogger.com/atom/ns#' term='policy'/><title type='text'>securing cyberspace</title><content type='html'>&lt;h2 style="font-weight: normal;"&gt;&lt;a href="http://www.csis.org/component/option,com_csis_pubs/task,view/id,5157/"&gt;&lt;span style="font-size: small;"&gt;Securing Cyberspace for the 44th Presidency&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h2 style="font-weight: normal;"&gt;&lt;span style="font-size: small;"&gt;from &lt;a href="http://www.csis.org/index.php"&gt;CSIS&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style="font-weight: normal;"&gt;&lt;span style="font-size: small;"&gt;Read through this for a useful perspective on probable emerging policy changes that will shape the infosec landscape for&amp;nbsp; some time to come.&amp;nbsp;&amp;nbsp; I looked through it quickly&amp;nbsp; hoping to find contributors combining great technical and policy background, and hoped that someone like Dan Geer would be involved.&amp;nbsp; Rest easy - he was.&lt;/span&gt;&lt;/h2&gt;&lt;h2 style="font-weight: normal;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style="font-weight: normal;"&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;/h2&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-893001884869845103?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/893001884869845103/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=893001884869845103' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/893001884869845103'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/893001884869845103'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/12/securing-cyberspace.html' title='securing cyberspace'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-4173933808211371454</id><published>2008-11-22T09:40:00.001-05:00</published><updated>2008-11-22T09:51:13.983-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crypto'/><category scheme='http://www.blogger.com/atom/ns#' term='hash'/><category scheme='http://www.blogger.com/atom/ns#' term='NIST'/><title type='text'>NIST hash function update</title><content type='html'>Watching from afar, particularly via the mailing list discussions, I've been following the progress on the NIST hash function competition.&amp;nbsp; Bruce Schneier offers an update in Wired:&amp;nbsp; &lt;a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/11/securitymatters_1120"&gt;&lt;span style="font-size: small;"&gt;America's Next Top Hash Function Begins&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The process issues and questions are almost as interesting as the math - in my opinion the NIST competition model provides a good, and improving, model for&amp;nbsp; harnessing the talents of interested experts to develop new tools we can all benefit from.&amp;nbsp;&amp;nbsp; I imagine there are many other domains where this approachis or could be valuable.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-4173933808211371454?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/4173933808211371454/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=4173933808211371454' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4173933808211371454'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4173933808211371454'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/11/nist-hash-function-update.html' title='NIST hash function update'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-4773890525817022917</id><published>2008-11-22T09:30:00.001-05:00</published><updated>2008-11-22T09:35:25.800-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crypto'/><title type='text'>the Basic Idea of Public Key Cryptosystems</title><content type='html'>&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;for the permanent record, here is a good (and colorful) very basic &lt;a href="http://scienceblogs.com/goodmath/2008/11/asymmetric_cryptography_the_ba.php"&gt;introduction &lt;/a&gt;to &lt;/span&gt;&lt;span style="font-size: small;"&gt;asymmetric cryptography, from the ever valuable &lt;a href="http://scienceblogs.com/goodmath/2008/11/asymmetric_cryptography_the_ba.php"&gt;Good Math, Bad Math&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-4773890525817022917?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/4773890525817022917/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=4773890525817022917' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4773890525817022917'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4773890525817022917'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/11/basic-idea-of-public-key-cryptosystems.html' title='the Basic Idea of Public Key Cryptosystems'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-2813664229407503026</id><published>2008-08-15T17:33:00.000-04:00</published><updated>2008-08-15T17:36:07.795-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tools'/><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='ssh'/><title type='text'>perspectives</title><content type='html'>&lt;a href="http://www.cs.cmu.edu/%7Eperspectives/"&gt;Perspectives &lt;/a&gt;- more innovation arising from attempts to provide simpler solutions to real problems than PKI is perceived to offer.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-2813664229407503026?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/2813664229407503026/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=2813664229407503026' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2813664229407503026'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2813664229407503026'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/08/perspectives.html' title='perspectives'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-5458990530816802864</id><published>2008-08-06T07:56:00.000-04:00</published><updated>2008-08-06T07:58:47.340-04:00</updated><title type='text'>coming soon - new Identity Associates service</title><content type='html'>Soon I will refocus the Identity Associates service portfolio and add a new service. Watch this space for more details...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-5458990530816802864?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/5458990530816802864/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=5458990530816802864' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5458990530816802864'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5458990530816802864'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/08/coming-soon-new-identity-associates.html' title='coming soon - new Identity Associates service'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-7201856358607238788</id><published>2008-08-06T07:51:00.000-04:00</published><updated>2008-08-06T07:52:51.584-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tools'/><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><title type='text'>GMail and https</title><content type='html'>If you're a gmail user, you should start using gmail over https.&amp;nbsp; See this &lt;a href="http://googlesystem.blogspot.com/2008/07/force-gmail-to-use-secure-connection.html"&gt;article &lt;/a&gt;for more details.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-7201856358607238788?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/7201856358607238788/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=7201856358607238788' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7201856358607238788'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7201856358607238788'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/08/gmail-and-https.html' title='GMail and https'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-9169722860870311290</id><published>2008-08-06T07:45:00.000-04:00</published><updated>2008-08-06T07:49:07.682-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tools'/><title type='text'>eraser</title><content type='html'>Started using &lt;a href="http://www.heidi.ie/node/6"&gt;eraser &lt;/a&gt;recently. Easy to use solution for scrubbing data off disk.&amp;nbsp; I use it to eliminate confidential client data from my laptop.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-9169722860870311290?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/9169722860870311290/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=9169722860870311290' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/9169722860870311290'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/9169722860870311290'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/08/eraser.html' title='eraser'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-4563773706126121836</id><published>2008-06-10T08:40:00.002-04:00</published><updated>2008-06-10T08:42:01.974-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='code'/><title type='text'>Google IO</title><content type='html'>Attended the Google IO developers conference in SF a couple of weeks ago.  Focused on App Engine but also tried to learn more about Open Social.&lt;br /&gt;&lt;br /&gt;App Engine looks almost ready for prime time (SLAs anyone?) and I'll build a trial app on it shortly.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-4563773706126121836?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/4563773706126121836/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=4563773706126121836' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4563773706126121836'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4563773706126121836'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/06/google-io.html' title='Google IO'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-8515032334930934946</id><published>2008-04-07T16:17:00.003-04:00</published><updated>2008-04-07T16:26:18.333-04:00</updated><title type='text'>worrisome?</title><content type='html'>This &lt;a href="http://www.freedom-to-tinker.com/?p=1275"&gt;post &lt;/a&gt;in Freedom to Tinker by Harlan Yu describes worries associated with Phorm's approach to the market.  Phorm works to assure people that they preserve privacy, and I can't look under the covers sufficiently to validate that claim.   Harlan raises serious and appropriate questions about their  violation of the &lt;a href="http://en.wikipedia.org/wiki/End-to-end_principle"&gt;end-to-end&lt;/a&gt; principle of the Internet if it is true that Phorm is rewriting and redirecting HTTP traffic,&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-8515032334930934946?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/8515032334930934946/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=8515032334930934946' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8515032334930934946'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8515032334930934946'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/04/worrisome.html' title='worrisome?'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-3104361446273483631</id><published>2008-04-04T11:15:00.001-04:00</published><updated>2008-04-04T11:16:36.144-04:00</updated><title type='text'>not making it to RSA conference this year</title><content type='html'>Unfortunately.  Immersion in an unrelated project is dominating my schedule.  Maybe next year.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-3104361446273483631?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/3104361446273483631/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=3104361446273483631' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3104361446273483631'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3104361446273483631'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/04/not-making-it-to-rsa-conference-this.html' title='not making it to RSA conference this year'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-2394323773154937372</id><published>2008-04-04T11:12:00.002-04:00</published><updated>2008-04-04T11:15:00.309-04:00</updated><title type='text'>more voting machine mayhem</title><content type='html'>Ed Felten &lt;a href="http://www.freedom-to-tinker.com/?p=1274"&gt;describes&lt;/a&gt; woes with voting machines in New Jersey.&lt;br /&gt;&lt;br /&gt;I still think voting is too important to trust to commercial enterprises.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-2394323773154937372?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/2394323773154937372/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=2394323773154937372' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2394323773154937372'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2394323773154937372'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/04/more-voting-machine-mayhem.html' title='more voting machine mayhem'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-1591927774075421189</id><published>2008-03-16T11:19:00.001-04:00</published><updated>2008-03-16T11:21:30.116-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='identity'/><title type='text'>Windows Cardspace</title><content type='html'>It'll make sense to pick up this book, &lt;a href="http://www.identityblog.com/?p=927"&gt;Understanding Windows Cardspace&lt;/a&gt;, soon.  Here is an &lt;a href="http://www.identityblog.com/?p=927"&gt;overview &lt;/a&gt;from IdentityBlog&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-1591927774075421189?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/1591927774075421189/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=1591927774075421189' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1591927774075421189'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1591927774075421189'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/03/windows-cardspace.html' title='Windows Cardspace'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-6807859724792610329</id><published>2008-02-25T11:21:00.001-05:00</published><updated>2008-02-25T11:23:39.333-05:00</updated><title type='text'>Security vs. Privacy</title><content type='html'>No one says it better than Bruce Schneier in this &lt;a href="http://www.schneier.com/blog/archives/2008/01/security_vs_pri.html"&gt;post&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Particularly relevant point:&lt;blockquote&gt;The debate isn't security versus privacy. It's liberty versus control.&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-6807859724792610329?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/6807859724792610329/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=6807859724792610329' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6807859724792610329'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6807859724792610329'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2008/02/security-vs-privacy.html' title='Security vs. Privacy'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-6143718420621585734</id><published>2007-11-02T13:41:00.000-04:00</published><updated>2007-11-02T13:45:49.453-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='standards'/><category scheme='http://www.blogger.com/atom/ns#' term='hash'/><category scheme='http://www.blogger.com/atom/ns#' term='NIST'/><title type='text'>NIST announces competition for SHA-3</title><content type='html'>this just in:  &lt;a href="http://www.csrc.nist.gov/groups/ST/hash/sha-3/index.html"&gt;Cryptographic Hash Algorithm Competition&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As a software guy, it'll be interesting to watch the planning and work involved to integrate the result of this competition into widely deployed security protocols.&lt;a href="http://www.schneier.com/blog/archives/2005/10/nist_hash_works_3.html"&gt;algorithm agility&lt;/a&gt; anyone?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-6143718420621585734?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/6143718420621585734/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=6143718420621585734' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6143718420621585734'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6143718420621585734'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/11/nist-announces-competition-for-sha-3.html' title='NIST announces competition for SHA-3'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-5999987003879635699</id><published>2007-11-02T13:27:00.000-04:00</published><updated>2007-11-02T13:33:51.567-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OpenID'/><title type='text'>burton group on OpenID</title><content type='html'>In the &lt;a href="http://srmsblog.burtongroup.com/"&gt;Security and Risk Management Strategies Blog&lt;/a&gt;, Bob Blakely asks appropriate questions in his post &lt;a href="http://srmsblog.burtongroup.com/2007/09/what-is-openid-.html"&gt;WHAT IS OPENID FOR?&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Having some PKI background (I'm recovering....) I know these are the questions upon which identity systems can founder.&lt;br /&gt;&lt;br /&gt;In particular: &lt;blockquote&gt;4. What is the threat model?&lt;br /&gt;&lt;br /&gt;What threats is OpenID designed to protect against? Accidental failures at a participating party? Malicious behavior by users? Malicious behavior by relying parties? Malicious behavior by OpenID providers? Wiretappers? Hackers attempting to penetrate a relying party? Hackers attempting to penetrate a provider? Hackers attempting to penetrate a client system? Cryptanalysts?&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-5999987003879635699?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/5999987003879635699/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=5999987003879635699' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5999987003879635699'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5999987003879635699'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/11/burton-group-on-openid.html' title='burton group on OpenID'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-7007772352099590139</id><published>2007-10-30T09:29:00.001-04:00</published><updated>2007-10-30T09:33:15.942-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='study'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTP'/><title type='text'>HTTP signatures</title><content type='html'>James Clark has a thoughtful sequence of posts on &lt;a href="http://blog.jclark.com/2007/10/signing-http-requests.html"&gt;signing HTTP responses&lt;/a&gt;, where, in Jim's words: &lt;blockquote&gt;"The purpose of the proposal that I've been developing in this series of posts is to allow somebody that receives a representation of a resource to verify the integrity and origin of that representation; the mechanism for achieving this is signing HTTP responses."&lt;/blockquote&gt;  Besides the utility of the approach, reading these posts provides a good lesson in how to think about solving a technical problem.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-7007772352099590139?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/7007772352099590139/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=7007772352099590139' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7007772352099590139'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7007772352099590139'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/10/http-signatures.html' title='HTTP signatures'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-2036430421688044115</id><published>2007-10-30T09:19:00.000-04:00</published><updated>2007-10-30T09:27:00.099-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='study'/><category scheme='http://www.blogger.com/atom/ns#' term='OpenID'/><title type='text'>FOAF and OpenID use case</title><content type='html'>See &lt;a href="http://dig.csail.mit.edu/breadcrumbs/node/206"&gt;http://dig.csail.mit.edu/breadcrumbs/node/206&lt;/a&gt; for a good explanation of a use case that combines OpenID and FOAF.&lt;br /&gt;&lt;br /&gt;Its an interesting confluence of technologies where a powerful anti-spam commenting capability emerges out of some new-ish building blocks.  Be authenticated to comment if you are a friend of a friend......   &lt;br /&gt;&lt;br /&gt;As the post points out, there is a relationship conceptually to Six Apart's work on "&lt;a href="http://www.sixapart.com/about/news/2007/09/were_opening_th.html"&gt;Opening the Social Graph&lt;/a&gt;" - an effort and direction I find compelling.    I'd rather own my own identify particulars instead of outsourcing them to some of a multitude of service providers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-2036430421688044115?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/2036430421688044115/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=2036430421688044115' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2036430421688044115'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2036430421688044115'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/10/foaf-and-openid-use-case.html' title='FOAF and OpenID use case'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-5125148923357218760</id><published>2007-10-30T09:14:00.000-04:00</published><updated>2007-10-30T09:18:58.749-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ssh'/><title type='text'>tunneling SSH</title><content type='html'>From &lt;a href="http://nateaune.com/"&gt;NateSpace&lt;/a&gt;, &lt;a href="http://nateaune.com/2007/06/03/ssh-tunneling-for-dummies/"&gt;SSH tunneling for dummies&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I've used SSH from time to time, but not for a few years.   This well-written post explains how to use SSH in the context of IRC.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-5125148923357218760?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/5125148923357218760/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=5125148923357218760' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5125148923357218760'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5125148923357218760'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/10/tunneling-ssh.html' title='tunneling SSH'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-2974485590179271250</id><published>2007-09-29T15:42:00.000-04:00</published><updated>2007-09-29T15:47:15.786-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='code'/><title type='text'>password  security lore</title><content type='html'>Coding Horror shares some wisdom on &lt;a href="http://www.codinghorror.com/blog/archives/000953.html"&gt;password storage&lt;/a&gt; and using &lt;a href="http://www.codinghorror.com/blog/archives/000949.html"&gt;rainbow tables to crack passwords&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-2974485590179271250?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/2974485590179271250/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=2974485590179271250' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2974485590179271250'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2974485590179271250'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/09/password-storage.html' title='password  security lore'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-5598418654369511087</id><published>2007-09-29T15:26:00.000-04:00</published><updated>2007-09-29T15:50:35.004-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OAuth'/><category scheme='http://www.blogger.com/atom/ns#' term='OpenID'/><title type='text'>OpenID, OAuth</title><content type='html'>So, trying to sort out Open ID and what I can really use it for.  Seems like its a lite-weight, low-security model for web single-sign on.    And now OAuth is here to help with API and protocol support.&lt;br /&gt;&lt;br /&gt;Simon Willison and David Recordon's OpenID &lt;a href="http://www.slideshare.net/daveman692/openid-bootcamp-tutorial/"&gt;tutorial&lt;/a&gt; from O'Reilly OSCON 07, via SlideShare.&lt;br /&gt;&lt;br /&gt;Here is "&lt;a href="http://"&gt;A Recipe for OpenID-Enabling Your Site&lt;/a&gt;", from Plaxo.&lt;br /&gt;&lt;br /&gt;O'Reilly Radar claims&lt;a href="http://radar.oreilly.com/archives/2007/09/oauth_open_auth.html"&gt; Open Authentication Comes Closer to Reality with OAuth&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Here is the &lt;a href="http://oauth.net/blog"&gt;OAuth blog&lt;/a&gt;, with links to the latest &lt;a href="http://oauth.googlecode.com/svn/spec/branches/1.0/drafts/3/spec.html"&gt;spec&lt;/a&gt;.   How does OAuth fit in?  From OAuth:&lt;blockquote&gt;"The OAuth protocol enables websites or applications (Consumers) to access Protected Resources from a web service (Service Provider) via an API, without requiring Users to disclose their Service Provider credentials to the Consumers. More generally, OAuth creates a freely-implementable and generic methodology for API authentication."&lt;/blockquote&gt;&lt;br /&gt;I'm working on a project right now where OAuth may come in handy.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-5598418654369511087?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/5598418654369511087/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=5598418654369511087' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5598418654369511087'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5598418654369511087'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/09/openid-oauth.html' title='OpenID, OAuth'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-6985952730694255993</id><published>2007-08-03T11:21:00.000-04:00</published><updated>2007-08-03T11:27:49.528-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='copyright'/><title type='text'>Pamela Samuelson on copyright reform</title><content type='html'>&lt;a href="http://www.ischool.berkeley.edu/~pam/"&gt;Pamela Samuelson&lt;/a&gt; wrote this article (&lt;a href="http://www.ischool.berkeley.edu/~pam/papers/Preliminary%20Thoughts%20utah.pdf"&gt;pdf&lt;/a&gt;) outlining thoughts about copyright reform and  a potential model copyright law.&lt;br /&gt;&lt;br /&gt;A process for copyright reform is necessary, in my opinion, for no other reason than to raise the issues broadly and make societal decisions about the best approach.  Perhaps I'm naive.  One also hopes for an approach that is easy to comprehend for non-lawyers.&lt;br /&gt;&lt;br /&gt;At any rate, Pamela's article is a great place to look to understand where we are and how we could move forward.&lt;br /&gt;&lt;br /&gt;(thanks to various sites in the blogosphere for raising this paper to my attention.)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-6985952730694255993?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/6985952730694255993/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=6985952730694255993' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6985952730694255993'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6985952730694255993'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/08/pamela-samuelson-on-copyright-reform.html' title='Pamela Samuelson on copyright reform'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-7641859306214550307</id><published>2007-06-28T15:31:00.000-04:00</published><updated>2007-06-28T15:42:55.975-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OpenID'/><title type='text'>Simon Willison on Open ID</title><content type='html'>&lt;small&gt;For a while I've been looking for a good introduction to Open ID, and for now I think this &lt;a href="http://video.google.com/videoplay?docid=2288395847791059857"&gt;video &lt;/a&gt;of Simon's Google talk is the best I've found.&lt;br /&gt;&lt;br /&gt;Simon provides a great overview of how Open ID fits into the Internet ecosystem; the talk is focused more on the capabilities Open ID offers to consumers and providers than underlying technical details of the protocol, etc...&lt;br /&gt;&lt;br /&gt;Simon mentions a few useful links, recorded here for completeness:&lt;br /&gt;&lt;a href="http://openid.net/"&gt;OpenID.net&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.openidenabled.com/"&gt;OpenID Enabled&lt;/a&gt;&lt;br /&gt;&lt;a href="http://simonwillison.net/"&gt;Simon Willison’s Weblog&lt;/a&gt;&lt;br /&gt;and, &lt;a href="http://idproxy.net/"&gt;idproxy.net&lt;/a&gt;&lt;/small&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-7641859306214550307?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/7641859306214550307/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=7641859306214550307' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7641859306214550307'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7641859306214550307'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/06/simon-willison-on-open-id.html' title='Simon Willison on Open ID'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-4637935581265442025</id><published>2007-06-21T11:36:00.001-04:00</published><updated>2007-06-21T11:39:12.110-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='standards'/><title type='text'>Next Steps for XML Signature and XML Encryption</title><content type='html'>&lt;small&gt;A &lt;a href="http://www.w3.org/2007/xmlsec/ws/cfp"&gt;call for participation&lt;/a&gt; for an upcoming W3C Workshop on Next Steps for XML Signature and XML Encryption.   I'm glad to see work in this area continuing - improving the utility of these standards in applications and legal use cases is near and dear to my heart.&lt;/small&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-4637935581265442025?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/4637935581265442025/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=4637935581265442025' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4637935581265442025'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4637935581265442025'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/06/next-steps-for-xml-signature-and-xml.html' title='Next Steps for XML Signature and XML Encryption'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-5490933450431099217</id><published>2007-06-08T13:28:00.000-04:00</published><updated>2007-06-08T13:29:34.870-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='standards'/><title type='text'>WebDAV for Certificate Publishing and Revocation</title><content type='html'>&lt;small&gt;Interesting idea, and one worth tracking: &lt;blockquote&gt;&lt;a href="http://xml.coverpages.org/draft-chadwick-webdav-00.txt"&gt;Use of WebDAV for Certificate Publishing and Revocation&lt;/a&gt;&lt;/blockquote&gt;&lt;/small&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-5490933450431099217?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/5490933450431099217/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=5490933450431099217' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5490933450431099217'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5490933450431099217'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/06/webdav-for-certificate-publishing-and.html' title='WebDAV for Certificate Publishing and Revocation'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-2580083404849255250</id><published>2007-05-16T15:51:00.000-04:00</published><updated>2007-06-08T13:31:27.070-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='standards'/><category scheme='http://www.blogger.com/atom/ns#' term='identity'/><title type='text'>SAML, Liberty, etc... presentation at iiw2007</title><content type='html'>&lt;small&gt;&lt;br /&gt;Altho I am not able to attend iiw2007 in person, its good to see great information from the conference being shared on the web.&lt;br /&gt;&lt;br /&gt;In particular, this &lt;a href="http://www.xmlgrrl.com/blog/archives/2007/05/15/the-saml-and-liberty-spiel-in-12-minutes-flat/"&gt;material &lt;/a&gt;from Eve Maler, posted on her &lt;a href="http://www.xmlgrrl.com/blog/"&gt;blog&lt;/a&gt;, is a very useful and succinct overview of SAML, Liberty, Concordia, and some related concepts.&lt;br /&gt;&lt;/small&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-2580083404849255250?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/2580083404849255250/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=2580083404849255250' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2580083404849255250'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/2580083404849255250'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/05/saml-liberty-etc-presentation-at.html' title='SAML, Liberty, etc... presentation at iiw2007'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-4745683413932791541</id><published>2007-05-03T17:43:00.000-04:00</published><updated>2007-05-03T17:49:01.276-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><title type='text'>Adobe Acrobat and Reader security</title><content type='html'>&lt;small&gt;&lt;br /&gt;&lt;br /&gt;For some time I've believed that Adobe has not taken full advantage of their widespread platform in terms of providing security for documents, etc...   Adobe is making considerable headway in improving its stance with respect to document security and related matters.&lt;br /&gt;&lt;br /&gt;In this &lt;a href="http://blogs.adobe.com/security/2007/04/acrobat_and_reader_security_do.html"&gt;post&lt;/a&gt;, John Landwehr provides a set of links to updated information from Adobe on Acrobat and Reader security.&lt;br /&gt;&lt;br /&gt;&lt;/small&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-4745683413932791541?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/4745683413932791541/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=4745683413932791541' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4745683413932791541'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/4745683413932791541'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/05/adobe-acrobat-and-reader-security.html' title='Adobe Acrobat and Reader security'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-3326134236342505630</id><published>2007-03-18T12:33:00.000-04:00</published><updated>2007-03-18T12:37:05.576-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><title type='text'>.Net framework 2.0 and certificates</title><content type='html'>&lt;small&gt;&lt;br /&gt;MSDN magazine recently published a very useful article on &lt;a href="http://msdn.microsoft.com/msdnmag/issues/07/03/NETSecurity/default.aspx"&gt;supporting certificates in applications with the .net framework 2.0&lt;/a&gt;.   This will come in handy in a project I'm looking at now.&lt;br /&gt;&lt;br /&gt;&lt;/small&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-3326134236342505630?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/3326134236342505630/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=3326134236342505630' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3326134236342505630'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3326134236342505630'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/03/net-framework-20-and-certificates.html' title='.Net framework 2.0 and certificates'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-5595268697326737087</id><published>2007-03-18T12:27:00.000-04:00</published><updated>2007-03-18T12:32:14.748-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OpenID'/><title type='text'>Wordpress and OpenID</title><content type='html'>&lt;small&gt;&lt;br /&gt;Wordpress &lt;a href="http://wordpress.com/blog/2007/03/06/openid/"&gt;announced &lt;/a&gt;that &lt;blockquote&gt;You can now use your WordPress.com blog as an OpenID.&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Couple this with the fact that Earthlink now provides Wordpress for use with its business accounts, and this gives me an opportunity to try out two new things at once.&lt;br /&gt;&lt;/small&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-5595268697326737087?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/5595268697326737087/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=5595268697326737087' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5595268697326737087'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5595268697326737087'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/03/wordpress-and-openid.html' title='Wordpress and OpenID'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-5200775824481272687</id><published>2007-02-13T07:01:00.000-05:00</published><updated>2007-01-26T10:18:07.389-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='drm'/><title type='text'>Schneier on Vista content protection</title><content type='html'>&lt;small&gt;&lt;br /&gt;See &lt;a href="http://www.schneier.com/blog/archives/2007/02/drm_in_windows.html"&gt;DRM in Windows Vista&lt;/a&gt;, by Bruce Schneier.  Perhaps a good way to summarize this view is that Hollywood should be very careful about what they wish for.  Relying on Microsoft to provide the players and controls for your premium content may cause you to be &lt;a href="http://en.wikipedia.org/wiki/Pwn"&gt;pwned&lt;/a&gt;.&lt;br /&gt;&lt;/small&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-5200775824481272687?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/5200775824481272687/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=5200775824481272687' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5200775824481272687'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5200775824481272687'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/02/schneier-on-vista-content-protection.html' title='Schneier on Vista content protection'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-1585422330551609593</id><published>2007-01-26T10:09:00.000-05:00</published><updated>2007-01-26T10:18:07.461-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='standards'/><category scheme='http://www.blogger.com/atom/ns#' term='code'/><title type='text'>NIST's Plan for New Cryptographic Hash Functions</title><content type='html'>&lt;blockquote&gt;"Due to recent attacks on the SHA-1 hash function specified in FIPS 180-2, Secure Hash Standard, NIST is initiating an effort to develop one or more additional hash algorithms through a public competition, similar to the development process for the Advanced Encryption Standard (AES)."&lt;/blockquote&gt;&lt;br /&gt;&lt;small&gt;For all the details, see the NIST &lt;a href="http://www.csrc.nist.gov/pki/HashWorkshop/index.html"&gt;site&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I think this will be a very interesting thread to follow.   In particular, because hash algorithms are implemented so widely, the choices of standards groups and coders around &lt;a href="http://www.schneier.com/blog/archives/2005/10/nist_hash_works_3.html"&gt;algorithm agility&lt;/a&gt;, as Bruce Schneier points out, may be significant.&lt;br /&gt;&lt;/small&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-1585422330551609593?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/1585422330551609593/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=1585422330551609593' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1585422330551609593'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1585422330551609593'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/01/nists-plan-for-new-cryptographic-hash.html' title='NIST&apos;s Plan for New Cryptographic Hash Functions'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-7919865475028421936</id><published>2007-01-26T10:04:00.000-05:00</published><updated>2007-01-26T10:08:41.284-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='drm'/><title type='text'>response to Vista content protection FAQ</title><content type='html'>published by Peter Gutmann &lt;a href="http://www.cs.auckland.ac.nz/%7Epgut001/pubs/vista_cost.html#response"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-7919865475028421936?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/7919865475028421936/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=7919865475028421936' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7919865475028421936'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7919865475028421936'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/01/response-to-microsoft-response-to.html' title='response to Vista content protection FAQ'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-6410469234508966551</id><published>2007-01-21T08:47:00.000-05:00</published><updated>2007-01-21T09:01:20.150-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='drm'/><title type='text'>Vista content protection FAQ from Microsoft</title><content type='html'>&lt;span style="font-size:85%;"&gt;In response to &lt;a href="http://www.cs.auckland.ac.nz/%7Epgut001/"&gt;Peter Gutmann&lt;/a&gt;'s  paper (referenced here a couple of posts ago) Microsoft has issued a &lt;a href="http://windowsvistablog.com/blogs/windowsvista/archive/2007/01/20/windows-vista-content-protection-twenty-questions-and-answers.aspx"&gt;faq &lt;/a&gt;on the &lt;a href="http://windowsvistablog.com/"&gt;Windows Vista Team Blog&lt;/a&gt;.    My reading of the faq suggests that some of the more inflammatory concerns may not be worries.    However there is enough spin and fine print to suggest that there remains plenty to worry about.   The faq is a fine exercise in implicitly and explicitly suggesting that Vista content protection is a natural evolution of the feature set, with lots of collateral improvements as side benefits.    Not sure I'm buying that line....&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-6410469234508966551?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/6410469234508966551/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=6410469234508966551' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6410469234508966551'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6410469234508966551'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/01/vista-content-protection-faq-from.html' title='Vista content protection FAQ from Microsoft'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-3506154992482161482</id><published>2007-01-19T11:39:00.000-05:00</published><updated>2007-01-19T11:45:39.904-05:00</updated><title type='text'>NIST FAQ  on Evaluation  of  Laboratories that Test Voting Systems</title><content type='html'>&lt;span style="font-size:85%;"&gt;As we mentioned previously, the trustworthiness of electronic voting systems is at the basis of confidence in our election processes, and our democracy.&lt;br /&gt;&lt;br /&gt;NIST recently posted a &lt;a href="http://www.nist.gov/public_affairs/factsheet/voting_qa.html"&gt;FAQ  &lt;/a&gt;on Evaluation  of  Laboratories that Test Voting Systems.   NIST's ongoing involvement in this issue is a requirement from our perspective.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-3506154992482161482?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/3506154992482161482/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=3506154992482161482' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3506154992482161482'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/3506154992482161482'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2007/01/nist-faq-on-evaluation-of-laboratories.html' title='NIST FAQ  on Evaluation  of  Laboratories that Test Voting Systems'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-1962853585989190267</id><published>2006-12-27T16:03:00.000-05:00</published><updated>2006-12-27T16:19:57.292-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='drm'/><title type='text'>a great paper on Vista Content Protection</title><content type='html'>&lt;span style="font-size:85%;"&gt;by Peter Gutmann,  see:  "&lt;a href="http://www.cs.auckland.ac.nz/%7Epgut001/pubs/vista_cost.txt"&gt;A Cost Analysis of  Windows Vista Content Protection&lt;/a&gt;."   Peter's substantial contributions to the PKI literature have helped me learn about many of the thorny issues that arise when you actually try to do something with PKI.   His writing style is approachable, clear, and sometimes leavened with a little humor.&lt;br /&gt;&lt;br /&gt;In this paper, Peter turns his eye towards Vista's content protection technologies, and the costs imposed as a result on hardware developers, driver writers, and of course, eventually, end-users.&lt;br /&gt;&lt;br /&gt;Seems to me Vista may be a major step in a downward path taking the PC from general-purpose computing device to set-top box.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-1962853585989190267?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/1962853585989190267/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=1962853585989190267' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1962853585989190267'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1962853585989190267'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2006/12/great-paper-on-vista-content-protection.html' title='a great paper on Vista Content Protection'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-1949359010219040978</id><published>2006-12-26T17:22:00.000-05:00</published><updated>2006-12-27T16:20:24.790-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='standards'/><category scheme='http://www.blogger.com/atom/ns#' term='code'/><title type='text'>XMLSIG For Dynamic Languages</title><content type='html'>&lt;a href="http://xmlsig.sourceforge.net/"&gt;&lt;span style="font-size:85%;"&gt;XMLSIG For Dynamic Languages&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; is a sourceforge hosted project sponsored by Verisign developing code providing xml digital signature libraries for scripting languages, including in particular &lt;a href="http://www.python.org/"&gt;Python&lt;/a&gt;.   Wish we had this a few years ago for an XML product we were building.&lt;br /&gt;&lt;br /&gt;I've started looking through the code and its pretty solid.   I suppose the next step is to install it and build a Python app or two to see how easy it is to work with.   I can think of a couple of fun things to do.&lt;br /&gt;&lt;br /&gt;This will make it easier to develop SAML-based  apps in Python.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-1949359010219040978?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/1949359010219040978/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=1949359010219040978' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1949359010219040978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1949359010219040978'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2006/12/xmlsig-for-dynamic-languages.html' title='XMLSIG For Dynamic Languages'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-1895427707016361090</id><published>2006-12-15T14:24:00.000-05:00</published><updated>2006-12-15T14:50:49.841-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='standards'/><title type='text'>OpenSSO - Open Federation</title><content type='html'>&lt;span style="font-size:85%;"&gt;Last month  Sun's &lt;a href="https://opensso.dev.java.net/"&gt;OpenSSO&lt;/a&gt; project announced &lt;a href="https://opensso.dev.java.net/servlets/NewsItemView?newsItemID=4377"&gt;Open Federation&lt;/a&gt;.   The architecture and use case documents are particularly helpful.   Now I'll have to dig in deeper to understand how best to use this code.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-1895427707016361090?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/1895427707016361090/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=1895427707016361090' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1895427707016361090'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/1895427707016361090'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2006/12/opensso-open-federation.html' title='OpenSSO - Open Federation'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-8479487773985684001</id><published>2006-12-06T08:24:00.000-05:00</published><updated>2006-12-06T08:36:13.704-05:00</updated><title type='text'>more on: NIST draft report on electronic voting systems</title><content type='html'>&lt;span style="font-size:85%;"&gt;So, the TGDC's meeting received coverage from mainstream media, and very reputable bloggers.  Here are some relevant links:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/12/05/AR2006120501355.html"&gt;article&lt;/a&gt; in the Washington Post.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://benlog.com/articles/2006/12/06/i-spoke-too-quickly/"&gt;blogpost &lt;/a&gt;by Ben Adida - who I believe is a most reputable commentator on this topic, and his blog &lt;a href="http://benlog.com/"&gt;benlog &lt;/a&gt;is always illuminating.&lt;br /&gt;&lt;br /&gt;its hard to imagine a more important topic -- fair, accurate, and trustworthy voting is at the foundation of democracy.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-8479487773985684001?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/8479487773985684001/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=8479487773985684001' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8479487773985684001'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/8479487773985684001'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2006/12/more-on-nist-draft-report-on-electronic.html' title='more on: NIST draft report on electronic voting systems'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-7916987906966592065</id><published>2006-12-02T09:09:00.000-05:00</published><updated>2006-12-02T09:18:18.520-05:00</updated><title type='text'>NIST draft report on electronic voting systems</title><content type='html'>&lt;span style="font-size:85%;"&gt;a link to the paper and Q&amp;A is available via  &lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://vote.nist.gov/"&gt;vote.nist.gov&lt;/a&gt;&lt;span style="font-size:85%;"&gt;, in particular &lt;a href="http://www.nist.gov/public_affairs/factsheet/draftvotingreport.htm"&gt;Draft Report on Voting System Vulnerability.&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.nist.gov/public_affairs/factsheet/draftvotingreport.htm"&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-7916987906966592065?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/7916987906966592065/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=7916987906966592065' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7916987906966592065'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7916987906966592065'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2006/12/nist-draft-report-on-electronic-voting.html' title='NIST draft report on electronic voting systems'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-409452982621940853</id><published>2006-10-27T08:47:00.000-04:00</published><updated>2006-10-27T08:55:09.203-04:00</updated><title type='text'>Federated Identity Management article</title><content type='html'>&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;Written by Sarah Scalet,&lt;b&gt; &lt;/b&gt;this &lt;a href="http://www.csoonline.com/read/100106/fea_federated_idm.html"&gt;article &lt;/a&gt;discusses clearly some of the issues with rolling out federated identity solutions in the real world.  &lt;br /&gt;&lt;br /&gt;As always, business relationships and legal factors need to be addressed when rolling out a security-related solution that crosses organization boundaries.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-409452982621940853?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/409452982621940853/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=409452982621940853' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/409452982621940853'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/409452982621940853'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2006/10/federated-identity-management-article.html' title='Federated Identity Management article'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-5944120289011415117</id><published>2006-10-15T20:23:00.000-04:00</published><updated>2006-10-15T20:31:16.074-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='standards'/><title type='text'>OASIS Digital Signature Services v1.0  public review</title><content type='html'>More information here:  &lt;a href="http://www.oasis-open.org/archives/tc-announce/200610/msg00003.html"&gt; http://www.oasis-open.org/archives/tc-announce/200610/msg00003.html  &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Having built, in an earlier life, an XML digital signature server (and encryption service), this is worth looking at closely.  Maybe its time to dust off that old code....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-5944120289011415117?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/5944120289011415117/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=5944120289011415117' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5944120289011415117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/5944120289011415117'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2006/10/oasis-digital-signature-services-v10.html' title='OASIS Digital Signature Services v1.0  public review'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-7199091365031040688</id><published>2006-10-12T07:48:00.000-04:00</published><updated>2006-10-27T09:04:39.504-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='anonymity'/><category scheme='http://www.blogger.com/atom/ns#' term='blogging'/><title type='text'>Anonymous Blogging</title><content type='html'>Ethan  Zuckerman of  &lt;a href="http://cyber.law.harvard.edu/home/"&gt;Berkman Center for Internet and Society&lt;/a&gt; and &lt;a href="http://www.globalvoicesonline.org/"&gt;Global Voices&lt;/a&gt; recently published a post on&lt;span style="text-decoration: underline;"&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.ethanzuckerman.com/blog/?p=1015"&gt;Anonymous Blogging with Wordpress and Tor.&lt;/a&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;&lt;/span&gt; I haven't tried this recipe yet, but I plan to.&lt;br /&gt;&lt;br /&gt;This is interesting because the goal of protecting one's identity is very significant in some situations, and it also shows how capabilities can be knit together to solve a complicated problem.&lt;br /&gt;&lt;br /&gt;I assume it won't be too long before some blogging solution makes this easier out of the box.&lt;br /&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-7199091365031040688?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/7199091365031040688/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=7199091365031040688' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7199091365031040688'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/7199091365031040688'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2006/10/anonymous-blogging.html' title='Anonymous Blogging'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2000411277939142534.post-6532544062339320338</id><published>2006-10-12T07:37:00.000-04:00</published><updated>2006-10-12T07:42:37.908-04:00</updated><title type='text'>Welcome!</title><content type='html'>Welcome to the Identity Associates blog. &lt;br /&gt;&lt;br /&gt;There is a lot going on in identity, privacy, anonymity, and security.   Its impossible to monitor, analyze and assess all the activity in the field.    When I spot something I think is notable or important, or want to draw your attention to something I've been thinking about or working on, I'll post here.&lt;br /&gt;&lt;br /&gt;I hope readers will find this blog useful and enjoyable.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2000411277939142534-6532544062339320338?l=identityassociates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://identityassociates.blogspot.com/feeds/6532544062339320338/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2000411277939142534&amp;postID=6532544062339320338' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6532544062339320338'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2000411277939142534/posts/default/6532544062339320338'/><link rel='alternate' type='text/html' href='http://identityassociates.blogspot.com/2006/10/welcome.html' title='Welcome!'/><author><name>Peter Lieberwirth</name><uri>https://profiles.google.com/102132656888312135858</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-w7CDu1aLpnw/AAAAAAAAAAI/AAAAAAAAAAA/o6uStskSPoc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry></feed>
