<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FewBar.com - Make it good &#187; Security</title>
	<atom:link href="http://fewbar.com/category/tech/security-tech/feed/" rel="self" type="application/rss+xml" />
	<link>http://fewbar.com</link>
	<description>Technology, life, and mischief, not in that order</description>
	<lastBuildDate>Wed, 18 Apr 2012 00:55:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>Cloud Computing Security</title>
		<link>http://fewbar.com/2010/07/cloud-computing-security-2/</link>
		<comments>http://fewbar.com/2010/07/cloud-computing-security-2/#comments</comments>
		<pubDate>Wed, 07 Jul 2010 15:52:13 +0000</pubDate>
		<dc:creator>clint</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[crypto]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://fewbar.com/?p=238</guid>
		<description><![CDATA[<a href="http://fewbar.com/2010/07/cloud-computing-security-2/" title="Cloud Computing Security"></a>Cloud Computing Security. The linked presentation above came up in a discussion the other day on IRC about what to do with certificates and SSH host keys. I hadn&#8217;t really thought about this. Sometimes it feels like once you put &#8230;<p class="read-more"><a href="http://fewbar.com/2010/07/cloud-computing-security-2/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<a href="http://fewbar.com/2010/07/cloud-computing-security-2/" title="Cloud Computing Security"></a><p style="text-align: center;"><a href="http://www.slideshare.net/astamos/cloud-computing-security"><img src="http://cdn.slidesharecdn.com/stamosetech2009cybercrime-090310165030-phpapp01-thumbnail-2?1236774594" alt="" /></a></p>
<p><a href="http://www.slideshare.net/astamos/cloud-computing-security">Cloud Computing Security</a>.</p>
<p>The linked presentation above came up in a discussion the other day on IRC about what to do with certificates and SSH host keys.</p>
<p>I hadn&#8217;t really thought about this. Sometimes it feels like once you put on your &#8220;somebody else is thinking about security&#8221; blinders, the world just starts moving faster and the ideas get more interesting. Unfortunately, at this high speed, I have to wonder if the impact may not be fatal for some heavy cloud (ab)users.<span id="more-238"></span></p>
<p>To &#8220;see what I&#8217;m on about&#8221;,  skip ahead to slide #66 to see the bits about random numbers.</p>
<p>I keep thinking back to the days where I would open up &#8220;pSSH&#8221; on my Palm Treo 650 and it would warn me &#8220;This device has no real random number capabilities, so the crypto is probably pretty sketchy, be careful.&#8221; Unfortunately, our ssh clients on cloud instances aren&#8217;t telling us that. Somebody needs to put &#8220;fix random seeding in the cloud&#8221; on their todo list. Oh wait, I just did.</p>
]]></content:encoded>
			<wfw:commentRss>http://fewbar.com/2010/07/cloud-computing-security-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Personal schedule for Clint Byrum: Velocity 2010, Web Performance &amp; Operations Conference &#8211; O&#8217;Reilly Conferences, June 22 &#8211; 24, 2010, Santa Clara, CA</title>
		<link>http://fewbar.com/2010/06/personal-schedule-for-clint-byrum-velocity-2010-web-performance-operations-conference-oreilly-conferences-june-22-24-2010-santa-clara-ca/</link>
		<comments>http://fewbar.com/2010/06/personal-schedule-for-clint-byrum-velocity-2010-web-performance-operations-conference-oreilly-conferences-june-22-24-2010-santa-clara-ca/#comments</comments>
		<pubDate>Thu, 17 Jun 2010 05:29:22 +0000</pubDate>
		<dc:creator>clint</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[velocity]]></category>

		<guid isPermaLink="false">http://fewbar.com/?p=212</guid>
		<description><![CDATA[<a href="http://fewbar.com/2010/06/personal-schedule-for-clint-byrum-velocity-2010-web-performance-operations-conference-oreilly-conferences-june-22-24-2010-santa-clara-ca/" title="Personal schedule for Clint Byrum: Velocity 2010, Web Performance &amp; Operations Conference - O&#039;Reilly Conferences, June 22 - 24, 2010, Santa Clara, CA"></a>Attention Stalkers: You&#8217;ll need to forge a badge to follow me around in these sessions, as I believe the conference is sold out. That is, unless you already registered. Personal schedule for Clint Byrum: Velocity 2010, Web Performance &#38; Operations &#8230;<p class="read-more"><a href="http://fewbar.com/2010/06/personal-schedule-for-clint-byrum-velocity-2010-web-performance-operations-conference-oreilly-conferences-june-22-24-2010-santa-clara-ca/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<a href="http://fewbar.com/2010/06/personal-schedule-for-clint-byrum-velocity-2010-web-performance-operations-conference-oreilly-conferences-june-22-24-2010-santa-clara-ca/" title="Personal schedule for Clint Byrum: Velocity 2010, Web Performance &amp; Operations Conference - O&#039;Reilly Conferences, June 22 - 24, 2010, Santa Clara, CA"></a><p>Attention Stalkers: You&#8217;ll need to forge a badge to follow me around in these sessions, as I believe the conference is sold out. That is, unless you already registered.</p>
<p><a href="http://en.oreilly.com/velocity2010/public/schedule/share/f655d0eeddfe5e60722bc2127699bb09">Personal schedule for Clint Byrum: Velocity 2010, Web Performance &amp; Operations Conference &#8211; O&#8217;Reilly Conferences, June 22 &#8211; 24, 2010, Santa Clara, CA</a>.</p>
<p><i>ooops.. fixed the link to actually work if you&#8217;re not logged in to oreilly.com as ME</i></p>
]]></content:encoded>
			<wfw:commentRss>http://fewbar.com/2010/06/personal-schedule-for-clint-byrum-velocity-2010-web-performance-operations-conference-oreilly-conferences-june-22-24-2010-santa-clara-ca/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Protecting “Cloud” Secrets with Grendel&#8221;</title>
		<link>http://fewbar.com/2010/05/protecting-%e2%80%9ccloud%e2%80%9d-secrets-with-grendel/</link>
		<comments>http://fewbar.com/2010/05/protecting-%e2%80%9ccloud%e2%80%9d-secrets-with-grendel/#comments</comments>
		<pubDate>Fri, 28 May 2010 08:03:28 +0000</pubDate>
		<dc:creator>clint</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[grendel]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[secret]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://fewbar.com/?p=198</guid>
		<description><![CDATA[<a href="http://fewbar.com/2010/05/protecting-%e2%80%9ccloud%e2%80%9d-secrets-with-grendel/" title="&quot;Protecting “Cloud” Secrets with Grendel&quot;"></a>&#8220;because we believe that all web applications should take security seriously. Today we’re open sourcing a piece of software, Grendel, that we think can help many sites (not just financial applications) protect users’ data from a RockYou-style mass disclosure in &#8230;<p class="read-more"><a href="http://fewbar.com/2010/05/protecting-%e2%80%9ccloud%e2%80%9d-secrets-with-grendel/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<a href="http://fewbar.com/2010/05/protecting-%e2%80%9ccloud%e2%80%9d-secrets-with-grendel/" title="&quot;Protecting “Cloud” Secrets with Grendel&quot;"></a><blockquote><p><a href="http://blog.wesabe.com/2010/01/04/protecting-cloud-secrets-with-grendel/">&#8220;because we believe that all web applications should take security seriously. Today we’re open sourcing a piece of software, Grendel, that we think can help many sites (not just financial applications) protect users’ data from a RockYou-style mass disclosure in a simple way.&#8221;</a></p></blockquote>
<p>Pretty interesting stuff.. and makes perfect sense for those websites out there playing russian roulette with their users&#8217; data&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://fewbar.com/2010/05/protecting-%e2%80%9ccloud%e2%80%9d-secrets-with-grendel/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.163 seconds -->

