<?xml version="1.0" encoding="UTF-8"?><!-- generator="WordPress/2.9.1" -->
<rss version="0.92">
<channel>
	<title>Analytical Engine</title>
	<link>http://www.analyticalengine.net</link>
	<description>Application Security, General Technology, and Geek Ramblings</description>
	<lastBuildDate>Sat, 06 Mar 2010 02:04:03 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Threat Modeling Game</title>
		<description><![CDATA[Microsoft has made a little game of threat modeling, with details here.  The idea is that by printing particular scenarios on cards and creating a competition to figure out how each scenario can be applied to an application model a development team will be reasonably effective at finding threats (I would add that if [...]]]></description>
		<link>http://www.analyticalengine.net/archives/214</link>
			</item>
	<item>
		<title>Miscellenia</title>
		<description><![CDATA[Couple random thoughts, observations, stuff:
Last night my wife wanted to pay her Sprint bill &#8211; she didn&#8217;t want to get up and go down stairs to grab her purse and credit card so she asked me for mine and I just tossed her my wallet without thinking.  Rather than grabbing my dedicated credit card [...]]]></description>
		<link>http://www.analyticalengine.net/archives/212</link>
			</item>
	<item>
		<title>On Google and Privacy Policies</title>
		<description><![CDATA[Google is currently getting reamed for their poorly handled roll out of Buzz to Gmail users.  It is pretty clear that they made the choice to automatically enroll as many people as possible into Buzz in order to grow its initial market share, at the expense of user choice and privacy.   This [...]]]></description>
		<link>http://www.analyticalengine.net/archives/209</link>
			</item>
	<item>
		<title>Do as I Say&#8230;</title>
		<description><![CDATA[An old and well worn addage is &#8220;Do as I say, not as I do&#8221;, generally in a fit of hypocracy when the listener is asked to ignore the example being set by the speaker. The fallacy of that statement was addressed by the series of &#8220;I learned it by watching you&#8221; advertisements trying to [...]]]></description>
		<link>http://www.analyticalengine.net/archives/205</link>
			</item>
	<item>
		<title>Reddit silliness</title>
		<description><![CDATA[There is an interesting writeup on the Reddit blog about the particular vulnerability that lead to their exploitation.  In general it is a reasonably informative writeup that delves into their mistake and I wish all security flaws recieved such an informative writeup (You occassionally see Michael Howard delve into details on a Microsoft vulnerability, [...]]]></description>
		<link>http://www.analyticalengine.net/archives/202</link>
			</item>
	<item>
		<title>Security can be its own worst enemy</title>
		<description><![CDATA[This is a great article on some of the pitfalls of the security mindset &#8211; the post is essentially based around the quote &#8220;The more secure you make something, the less secure it becomes&#8221;. A quick snippet:
I recently attended two conferences on Usability, Security, and Privacy. The first, SOUPS (Symposium on Usable Privacy and Security), [...]]]></description>
		<link>http://www.analyticalengine.net/archives/198</link>
			</item>
	<item>
		<title>Forget Virus Scanners</title>
		<description><![CDATA[Does anyone know of a decent program that allows you to whitelist which executables may be loaded (even better would be executables, dlls, and assemblies but that would be a bit of a headache to manage)?  Conceptually it shouldn&#8217;t be that hard to write &#8211; just poll the running processes and kill any not [...]]]></description>
		<link>http://www.analyticalengine.net/archives/196</link>
			</item>
	<item>
		<title>Opera Unite</title>
		<description><![CDATA[How do you make a web browser, already one of the most common attack vectors against a client, even less secure?  I know, add a web server and have it serve up the whole damn client file system!  What a great idea!  
Is Opera insane?  What does the Threat Model look [...]]]></description>
		<link>http://www.analyticalengine.net/archives/194</link>
			</item>
	<item>
		<title>China&#8217;s mandatory filter software</title>
		<description><![CDATA[It turns out that Green Dam, the censorware that China want&#8217;s installed on all machines sold within its borders, is crap.  The security researchers who wrote the article in that link found many major vulnerabilities within twelve hours of examining the software.  First, it has buffer overlows, which can be exploited just by [...]]]></description>
		<link>http://www.analyticalengine.net/archives/191</link>
			</item>
	<item>
		<title>Question on Disclosure</title>
		<description><![CDATA[So here is a hypothetical -
Say a small real-estate agency is using a simple PostNuke website (which is out of date) to gather rental applications &#8211; applications with all of the information necessary to both verify (and apply for) credit as well as history of passed residences.  In other words, say they were collecting [...]]]></description>
		<link>http://www.analyticalengine.net/archives/189</link>
			</item>
</channel>
</rss>
