<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec">
    <title>gmane.comp.security.funsec</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17969"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17968"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17967"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17966"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17965"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17964"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17963"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17962"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17961"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17960"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17959"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17958"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17957"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17956"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17955"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17953"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17951"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17950"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17949"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.funsec/17948"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17969">
    <title>Re: malicious binaries</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17969</link>
    <description>&lt;pre&gt;i get mine from


VirusWatch mailing list
VirusWatch&amp;lt; at &amp;gt;lists.clean-mx.com
http://lists.clean-mx.com/cgi-bin/mailman/listinfo/viruswatch

great feed for research


On May 22, 2012, at 2:40 PM, Daniel Otis &amp;lt;dso&amp;lt; at &amp;gt;moosoft.com&amp;gt; wrote:

&lt;/pre&gt;</description>
    <dc:creator>_</dc:creator>
    <dc:date>2012-05-24T12:14:43</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17968">
    <title>Re: Rotten AV proves "free market" false?</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17968</link>
    <description>&lt;pre&gt;malware/badware makers are better than AV writters. 

On May 22, 2012, at 5:24 AM, Drsolly &amp;lt;drsollyp&amp;lt; at &amp;gt;drsolly.com&amp;gt; wrote:

&lt;/pre&gt;</description>
    <dc:creator>_</dc:creator>
    <dc:date>2012-05-22T21:54:46</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17967">
    <title>Re: funsec Digest, Vol 81, Issue 9</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17967</link>
    <description>&lt;pre&gt;I will be out at the office with extremely limited access to email from
April 28th until May 12th.  If you need urgent assistance, please email
pcsupport&amp;lt; at &amp;gt;dcemail.harvard.edu. or call 617-998-8558.  Thank you!

&lt;/pre&gt;</description>
    <dc:creator>Erin Boyle</dc:creator>
    <dc:date>2012-05-13T17:00:16</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17966">
    <title>Re: .secure TLD</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17966</link>
    <description>&lt;pre&gt;Haha, yeah.

In all seriousness though, I would be all for it if the technical
requirements were a moving target that follows industry best practice and
competent security recommendations

Update the requirements yearly to be as strict as possible and give at most
1 year to be up to par.

Won't be perfect, but if we .secure can force everyone to cut down their
low hanging fruit once in a while, we'd have some step forward rather than
the feel-good joke of a marketing gimmick it's likely to become.




On Fri, May 11, 2012 at 9:23 PM, Ben April &amp;lt;bapril&amp;lt; at &amp;gt;gmail.com&amp;gt; wrote:

&lt;/pre&gt;</description>
    <dc:creator>Stephanie Daugherty</dc:creator>
    <dc:date>2012-05-13T05:41:33</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17965">
    <title>Re: funsec Digest, Vol 81, Issue 8</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17965</link>
    <description>&lt;pre&gt;I will be out at the office with extremely limited access to email from
April 28th until May 12th.  If you need urgent assistance, please email
pcsupport&amp;lt; at &amp;gt;dcemail.harvard.edu. or call 617-998-8558.  Thank you!

&lt;/pre&gt;</description>
    <dc:creator>Erin Boyle</dc:creator>
    <dc:date>2012-05-12T17:00:21</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17964">
    <title>Re: funsec Digest, Vol 81, Issue 7</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17964</link>
    <description>&lt;pre&gt;I will be out at the office with extremely limited access to email from
April 28th until May 12th.  If you need urgent assistance, please email
pcsupport&amp;lt; at &amp;gt;dcemail.harvard.edu. or call 617-998-8558.  Thank you!

&lt;/pre&gt;</description>
    <dc:creator>Erin Boyle</dc:creator>
    <dc:date>2012-05-11T17:00:21</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17963">
    <title>Breakpoint 2012 Call For Papers</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17963</link>
    <description>&lt;pre&gt;                 . ______________________________________
                 ._\\.         Breakpoint 2012           (___.
                 :          Intercontinental Rialto          :
                 :           Melbourne,  Australia           :
                 :             October 17th-18th             :
                 :__                                    . ___:
                    )____________________________________\\
                                                            .
                          www.ruxconbreakpoint.com
                          www.twitter.com/ruxconbpx



Introduction
------------

 Breakpoint is a new security conference to be held on the 17th and 18th of
 October, in Melbourne Australia. The event will show case the work of expert
 security researchers from around the world on a wide range of topics.
 Breakpoint is organised by the Ruxcon conference team and will offer a
 specialised and more professional security conference to complement and lead
 into the larger and&lt;/pre&gt;</description>
    <dc:creator>cfp&lt; at &gt;ruxcon.org.au</dc:creator>
    <dc:date>2012-05-10T11:49:38</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17962">
    <title>Re: funsec Digest, Vol 81, Issue 6</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17962</link>
    <description>&lt;pre&gt;I will be out at the office with extremely limited access to email from
April 28th until May 12th.  If you need urgent assistance, please email
pcsupport&amp;lt; at &amp;gt;dcemail.harvard.edu. or call 617-998-8558.  Thank you!

&lt;/pre&gt;</description>
    <dc:creator>Erin Boyle</dc:creator>
    <dc:date>2012-05-10T17:00:44</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17961">
    <title>Re: funsec Digest, Vol 81, Issue 5</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17961</link>
    <description>&lt;pre&gt;I will be out at the office with extremely limited access to email from
April 28th until May 12th.  If you need urgent assistance, please email
pcsupport&amp;lt; at &amp;gt;dcemail.harvard.edu. or call 617-998-8558.  Thank you!

&lt;/pre&gt;</description>
    <dc:creator>Erin Boyle</dc:creator>
    <dc:date>2012-05-06T17:00:28</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17960">
    <title>Re: funsec Digest, Vol 81, Issue 2</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17960</link>
    <description>&lt;pre&gt;I will be out at the office with extremely limited access to email from
April 28th until May 12th.  If you need urgent assistance, please email
pcsupport&amp;lt; at &amp;gt;dcemail.harvard.edu. or call 617-998-8558.  Thank you!

&lt;/pre&gt;</description>
    <dc:creator>Erin Boyle</dc:creator>
    <dc:date>2012-05-05T17:00:17</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17959">
    <title>Re: Stolen iPhone posts thief's pics on victim's Facebookaccount</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17959</link>
    <description>&lt;pre&gt;Too bad Facebook strips out GPS information.
This is pretty damning evidence implying theft by a cruise employee.

-Neal
--
Neal Krawetz, Ph.D.
Hacker Factor Solutions
http://www.hackerfactor.com/


On Thu, May 24, 2012 at 10:00:50AM -0700, Rob, grandpa of Ryan, Trevor, Devon &amp;amp; Hannah wrote:
&lt;/pre&gt;</description>
    <dc:creator>Dr. Neal Krawetz</dc:creator>
    <dc:date>2012-05-25T17:34:18</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17958">
    <title>Stolen iPhone posts thief's pics on victim's Facebookaccount</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17958</link>
    <description>&lt;pre&gt;K goes on a Disney cruise.

Somebody on staff on the cruise line steals K's phone.

And takes pictures.

The iPhone automatically posts pictures on K's Facebook account.

https://www.facebook.com/media/set/?set=a.4102695045342.2181863.122194859
7&amp;amp;type=3&amp;amp;l=45551c466f

or

http://is.gd/xxkPob

(There is a rather heavy irony in the fact that, in order to get these somewhat 
delicious "turn the tables on the thief" situations, you have to join Facebook or 
some other similarly dangerous soc med site, and set a smartphone app to 
automatically post your pictures there ... which carries privacy dangers ...)

It's also amusing that one of the pics probably identifies one of the ship's officers 
...)

======================  (quote inserted randomly by Pegasus Mailer)
rslade&amp;lt; at &amp;gt;vcn.bc.ca     slade&amp;lt; at &amp;gt;victoria.tc.ca     rslade&amp;lt; at &amp;gt;computercrime.org
The object-oriented model makes it easy to build up programs by
accretion.  What this often means, in practise, is that it
provides a structured way to write spaghetti code.     - P&lt;/pre&gt;</description>
    <dc:creator>Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah</dc:creator>
    <dc:date>2012-05-24T17:00:50</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17957">
    <title>malicious binaries</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17957</link>
    <description>&lt;pre&gt;Many moons ago I ran a site to share malware binaries amongst the people 
on this list.  I'm always looking for a new source of data so I am 
wondering if there is a current free source for sharing malicious 
binaries for analysis.  Thanks!  Also, I wouldn't mind running such a 
service again, the only problem was I was the only one sharing ;)

Daniel

&lt;/pre&gt;</description>
    <dc:creator>Daniel Otis</dc:creator>
    <dc:date>2012-05-22T20:40:27</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17956">
    <title>Re: Rotten AV proves "free market" false?</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17956</link>
    <description>&lt;pre&gt;"So why are the outcomes of this market so poor? "

Because the job that they're trying to do, can't actually be done.

On Mon, 21 May 2012, Rob, grandpa of Ryan, Trevor, Devon &amp;amp; Hannah wrote:


&lt;/pre&gt;</description>
    <dc:creator>Drsolly</dc:creator>
    <dc:date>2012-05-22T11:24:55</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17955">
    <title>Rotten AV proves "free market" false?</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17955</link>
    <description>&lt;pre&gt;(Or lousy OS situation, or pitiful software security in general ...)

http://www.businessinsider.com/when-competition-easy-entry-and-no-government-
produces-lousy-results-a-quick-look-at-the-anti-virus-and-anti-malware-market-
2012-5

or

http://is.gd/yfQXMG

(I do recall some research that indicates "low cost of entry" actually promotes 
monoculture ...)

======================  (quote inserted randomly by Pegasus Mailer)
rslade&amp;lt; at &amp;gt;vcn.bc.ca     slade&amp;lt; at &amp;gt;victoria.tc.ca     rslade&amp;lt; at &amp;gt;computercrime.org
Harold Crick: I'm glad I caught you. I wanted to give you these
Ana Pascal (the baker): What are they?
Harold Crick: Flours.
Ana Pascal: What?
Harold Crick: I brought you flours.
- `Stranger Than Fiction' http://www.imdb.com/title/tt0420223/quotes
victoria.tc.ca/techrev/rms.htm http://www.infosecbc.org/links
http://blogs.securiteam.com/index.php/archives/author/p1/
http://twitter.com/rslade
&lt;/pre&gt;</description>
    <dc:creator>Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah</dc:creator>
    <dc:date>2012-05-21T18:47:38</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17953">
    <title>(Redundant) Backup is good</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17953</link>
    <description>&lt;pre&gt;An example:
http://www.youtube.com/watch?v=EL_g0tyaIeE

======================  (quote inserted randomly by Pegasus Mailer)
rslade&amp;lt; at &amp;gt;vcn.bc.ca     slade&amp;lt; at &amp;gt;victoria.tc.ca     rslade&amp;lt; at &amp;gt;computercrime.org
         The client interface is the boundary of trustworthiness.
                                             - Tony Buckland, UBC
victoria.tc.ca/techrev/rms.htm http://www.infosecbc.org/links
http://blogs.securiteam.com/index.php/archives/author/p1/
http://twitter.com/rslade
&lt;/pre&gt;</description>
    <dc:creator>Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah</dc:creator>
    <dc:date>2012-05-15T22:50:54</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17951">
    <title>Error in Finnish e-prescription software randomly added characters when Return was used</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17951</link>
    <description>&lt;pre&gt;Finnish Medical Journal (in Finnish):
http://www.laakarilehti.fi/uutinen.html?opcode=show/news_id=12029/type=1

Google translation:
http://translate.google.com/translate?hl=en?sl=fi&amp;amp;tl=en&amp;amp;u=http%3A//www.laakarilehti.fi/uutinen.html%3Fopcode%3Dshow/news_id%3D12029/type%3D1

It is reported that using Return key in Effica e-prescription software randomly caused the program to add or destroy characters typed by the doctor.
According to the article The National Institute for Health and Welfare ("THL") denied the use of Return key when writing dosage instructions.
Technically the error in the software developed by Tieto company was associated to the message transmission.

Juha-Matti
&lt;/pre&gt;</description>
    <dc:creator>Juha-Matti Laurio</dc:creator>
    <dc:date>2012-05-13T09:43:56</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17950">
    <title>Re: .secure TLD</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17950</link>
    <description>&lt;pre&gt;On Fri, 11 May 2012 21:23:01 -0400, Ben April said:

Read between the lines.  The guy scored $9M in startup funding, and
only has to pay ICANN $185K for the .secure TLD. And then he gets to
collect *more* money from anybody silly enough to buy into the TLD.

Step 3: Profit!
&lt;/pre&gt;</description>
    <dc:creator>valdis.kletnieks&lt; at &gt;vt.edu</dc:creator>
    <dc:date>2012-05-13T04:24:27</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17949">
    <title>PCI DSS and BEAST</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17949</link>
    <description>&lt;pre&gt;I just spent two effortful days getting my Secure Server to pass the PCI
DSS. The big problem is the BEAST vulnerability. And it's a corker. What
you have to do to get your certification, is disable most of the strong
crypto that you accept, and only accept some of the weaker ones (a bit of
research on the web will give you that info).

Having done that, and gotten my certification renewed, my QA told me that
some of the big banks haven't passed the PCI DSS tests.

So, naturally, I did my own test. The site I tested (and it's a biggie) 
seems to be vulnerable to MITM attacks.

So here's a freebie to any journos reading this list. Choose a few banks, 
give their Secure Server domain name to a PCI DSS testing facility, and 
see if they pass the standard test.

But only do that if it's legal to do so in the place where you live.


&lt;/pre&gt;</description>
    <dc:creator>Drsolly</dc:creator>
    <dc:date>2012-05-12T18:28:35</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17948">
    <title>Re: .secure TLD</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17948</link>
    <description>&lt;pre&gt;

What happened to "The map is not the territory"?

After that, I want to know what happened to "The tap is not
meritorious".
&lt;/pre&gt;</description>
    <dc:creator>Bruce Ediger</dc:creator>
    <dc:date>2012-05-12T16:35:49</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.funsec/17947">
    <title>Re: .secure TLD</title>
    <link>http://permalink.gmane.org/gmane.comp.security.funsec/17947</link>
    <description>&lt;pre&gt;

Well, the whole idea is somewhere between hilarious and blatantly 
ignorant on its face, so that's funny (as in "funny sad" -- these folk 
do seem to think they're doing something useful that will make a 
difference) right off the bat...

If they really want to "assure security" they won't let any of their 
registered domains install any currently-popular web-apps, PHP or, 
realistically, even a web server.

The statement fom the "What is the DPWG?" section of their homepage:

   The introduction of new global Top Level Domains (gTLDs) both poses
   new challenges and offers new opportunities to the information
   security and great Internet communities.  The likely introduction
   of hundreds of new gTLDs has the potential to confuse consumers and
   create new opportunities for malware hosting, phishing and the
   creation of DNS-based control channel networks.  At the same time,
   the new gTLDs give us a chance to start fresh and create portions
   of the Internet where end-users can confidently transa&lt;/pre&gt;</description>
    <dc:creator>Nick FitzGerald</dc:creator>
    <dc:date>2012-05-12T04:06:54</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.comp.security.funsec">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.comp.security.funsec</link>
  </textinput>
</rdf:RDF>

