<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://blog.gmane.org/gmane.comp.security.funsec">
    <title>gmane.comp.security.funsec</title>
    <link>http://blog.gmane.org/gmane.comp.security.funsec</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17963"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17958"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17957"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17955"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17953"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17951"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17949"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17946"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17945"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17943"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17942"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17922"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17921"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17920"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17918"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17916"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17914"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17913"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17912"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.funsec/17911"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17963">
    <title>Breakpoint 2012 Call For Papers</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17963</link>
    <description>&lt;pre&gt;                 . ______________________________________
                 ._\\.         Breakpoint 2012           (___.
                 :          Intercontinental Rialto          :
                 :           Melbourne,  Australia           :
                 :             October 17th-18th             :
                 :__                                    . ___:
                    )____________________________________\\
                                                            .
                          www.ruxconbreakpoint.com
                          www.twitter.com/ruxconbpx



Introduction
------------

 Breakpoint is a new security conference to be held on the 17th and 18th of
 October, in Melbourne Australia. The event will show case the work of expert
 security researchers from around the world on a wide range of topics.
 Breakpoint is organised by the Ruxcon conference team and will offer a
 specialised and more professional security conference to complement and lead
 into the larger and more casual Ruxcon weekend conference. Breakpoint will
 cater towards security researchers and industry professionals alike, with a
 focus on cutting edge security research.

 With just one day separating both conferences, Breakpoint presents a great
 opportunity for our selected speakers to receive a complimentary trip to
 Australia and experience both the Breakpoint and Ruxcon conferences, not to
 mention the great weather, awesome parties, and friendly people.

 Melbourne is Australia's cultural capital, with Victorian-era architecture,
 extensive shopping, museums, galleries, theatres, and large parks and gardens.
 It is a city of many subcultures, personalities and styles, and it is these
 layers that make it so interesting. Melbourne has a vibrant arts and music
 scene, eccentric cafes, cobbled lane-ways, quirky shops, intimate bars and
 restaurants, and is known as one of the world's great streetart capitals.


Important Dates
---------------

 * May     10        Call For Presentations Open
 * July    30        Call For Presentations Close
 * October 15-16     BreakPoint Training
 * October 17-18     BreakPoint Conference
 * October 20-21     Ruxcon Conference


Topic Scope
-----------

Topics of interest include, but are not limited to:


 o Mobile Device Security
 o Exploitation Techniques
 o Reverse Engineering
 o Vulnerability Discovery
 o Rootkit Development
 o Malware Analysis
 o Code Analysis
 o Virtualization, Hypervisor Security
 o Cloud Security
 o Embedded Device Security
 o Hardware Security
 o Telecommunications Security
 o Wireless Network Security
 o Web Application Security
 o Law Enforcement Activities
 o Forensics
 o Threat Intelligence
 o You get the idea


Submission Guidelines
---------------------

 In order for us to process your submission we will require the following
 information:


 1. Presentation title
 2. Detailed summary of your presentation material
 3. Name/Nickname
 4. Mobile phone number
 5. Brief personal biography
 6. Description of any demonstrations involved in the presentation
 7. Information on where the presentation material has or will be presented
    before Breakpoint

 * Preference will be given to presentations that contain original research
   that will be first presented at Breakpoint.
 * As a general guideline, BreakPoint presentations are between
   45 and 60 minutes, including question time.


 If you have any enquiries about submissions, or would like to make a
 submission, please send an email to bpx&amp;lt; at &amp;gt;ruxconbreakpoint.com


Speaker Benefits
----------------

 Speakers at BreakPoint will be entitled to the following benefits:                                                    

 - A round trip economy airfare to Melbourne (total cost limit applies)
 - Three nights accommodation at the Intercontinental Rialto
 - Complementary registration for Breakpoint and Ruxcon conferences
 - Invitation to all BreakPoint and Ruxcon parties
 - Unlock 'Presented on world's smallest continent' achievement

 * All speaker benefits apply to a single speaker per submission.


Contact
-------

 If you have any questions or queries, contact us at:

 * Email:            bpx&amp;lt; at &amp;gt;ruxconbreakpoint.com
 * Twitter           &amp;lt; at &amp;gt;ruxconbpx
&lt;/pre&gt;</description>
    <dc:creator>cfp&lt; at &gt;ruxcon.org.au</dc:creator>
    <dc:date>2012-05-10T11:49:38</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17958">
    <title>Stolen iPhone posts thief's pics on victim's Facebookaccount</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17958</link>
    <description>&lt;pre&gt;K goes on a Disney cruise.

Somebody on staff on the cruise line steals K's phone.

And takes pictures.

The iPhone automatically posts pictures on K's Facebook account.

https://www.facebook.com/media/set/?set=a.4102695045342.2181863.122194859
7&amp;amp;type=3&amp;amp;l=45551c466f

or

http://is.gd/xxkPob

(There is a rather heavy irony in the fact that, in order to get these somewhat 
delicious "turn the tables on the thief" situations, you have to join Facebook or 
some other similarly dangerous soc med site, and set a smartphone app to 
automatically post your pictures there ... which carries privacy dangers ...)

It's also amusing that one of the pics probably identifies one of the ship's officers 
...)

======================  (quote inserted randomly by Pegasus Mailer)
rslade&amp;lt; at &amp;gt;vcn.bc.ca     slade&amp;lt; at &amp;gt;victoria.tc.ca     rslade&amp;lt; at &amp;gt;computercrime.org
The object-oriented model makes it easy to build up programs by
accretion.  What this often means, in practise, is that it
provides a structured way to write spaghetti code.     - Paul Graham
victoria.tc.ca/techrev/rms.htm http://www.infosecbc.org/links
http://blogs.securiteam.com/index.php/archives/author/p1/
http://twitter.com/rslade
&lt;/pre&gt;</description>
    <dc:creator>Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah</dc:creator>
    <dc:date>2012-05-24T17:00:50</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17957">
    <title>malicious binaries</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17957</link>
    <description>&lt;pre&gt;Many moons ago I ran a site to share malware binaries amongst the people 
on this list.  I'm always looking for a new source of data so I am 
wondering if there is a current free source for sharing malicious 
binaries for analysis.  Thanks!  Also, I wouldn't mind running such a 
service again, the only problem was I was the only one sharing ;)

Daniel

&lt;/pre&gt;</description>
    <dc:creator>Daniel Otis</dc:creator>
    <dc:date>2012-05-22T20:40:27</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17955">
    <title>Rotten AV proves "free market" false?</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17955</link>
    <description>&lt;pre&gt;(Or lousy OS situation, or pitiful software security in general ...)

http://www.businessinsider.com/when-competition-easy-entry-and-no-government-
produces-lousy-results-a-quick-look-at-the-anti-virus-and-anti-malware-market-
2012-5

or

http://is.gd/yfQXMG

(I do recall some research that indicates "low cost of entry" actually promotes 
monoculture ...)

======================  (quote inserted randomly by Pegasus Mailer)
rslade&amp;lt; at &amp;gt;vcn.bc.ca     slade&amp;lt; at &amp;gt;victoria.tc.ca     rslade&amp;lt; at &amp;gt;computercrime.org
Harold Crick: I'm glad I caught you. I wanted to give you these
Ana Pascal (the baker): What are they?
Harold Crick: Flours.
Ana Pascal: What?
Harold Crick: I brought you flours.
- `Stranger Than Fiction' http://www.imdb.com/title/tt0420223/quotes
victoria.tc.ca/techrev/rms.htm http://www.infosecbc.org/links
http://blogs.securiteam.com/index.php/archives/author/p1/
http://twitter.com/rslade
&lt;/pre&gt;</description>
    <dc:creator>Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah</dc:creator>
    <dc:date>2012-05-21T18:47:38</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17953">
    <title>(Redundant) Backup is good</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17953</link>
    <description>&lt;pre&gt;An example:
http://www.youtube.com/watch?v=EL_g0tyaIeE

======================  (quote inserted randomly by Pegasus Mailer)
rslade&amp;lt; at &amp;gt;vcn.bc.ca     slade&amp;lt; at &amp;gt;victoria.tc.ca     rslade&amp;lt; at &amp;gt;computercrime.org
         The client interface is the boundary of trustworthiness.
                                             - Tony Buckland, UBC
victoria.tc.ca/techrev/rms.htm http://www.infosecbc.org/links
http://blogs.securiteam.com/index.php/archives/author/p1/
http://twitter.com/rslade
&lt;/pre&gt;</description>
    <dc:creator>Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah</dc:creator>
    <dc:date>2012-05-15T22:50:54</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17951">
    <title>Error in Finnish e-prescription software randomly added characters when Return was used</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17951</link>
    <description>&lt;pre&gt;Finnish Medical Journal (in Finnish):
http://www.laakarilehti.fi/uutinen.html?opcode=show/news_id=12029/type=1

Google translation:
http://translate.google.com/translate?hl=en?sl=fi&amp;amp;tl=en&amp;amp;u=http%3A//www.laakarilehti.fi/uutinen.html%3Fopcode%3Dshow/news_id%3D12029/type%3D1

It is reported that using Return key in Effica e-prescription software randomly caused the program to add or destroy characters typed by the doctor.
According to the article The National Institute for Health and Welfare ("THL") denied the use of Return key when writing dosage instructions.
Technically the error in the software developed by Tieto company was associated to the message transmission.

Juha-Matti
&lt;/pre&gt;</description>
    <dc:creator>Juha-Matti Laurio</dc:creator>
    <dc:date>2012-05-13T09:43:56</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17949">
    <title>PCI DSS and BEAST</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17949</link>
    <description>&lt;pre&gt;I just spent two effortful days getting my Secure Server to pass the PCI
DSS. The big problem is the BEAST vulnerability. And it's a corker. What
you have to do to get your certification, is disable most of the strong
crypto that you accept, and only accept some of the weaker ones (a bit of
research on the web will give you that info).

Having done that, and gotten my certification renewed, my QA told me that
some of the big banks haven't passed the PCI DSS tests.

So, naturally, I did my own test. The site I tested (and it's a biggie) 
seems to be vulnerable to MITM attacks.

So here's a freebie to any journos reading this list. Choose a few banks, 
give their Secure Server domain name to a PCI DSS testing facility, and 
see if they pass the standard test.

But only do that if it's legal to do so in the place where you live.


&lt;/pre&gt;</description>
    <dc:creator>Drsolly</dc:creator>
    <dc:date>2012-05-12T18:28:35</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17946">
    <title>.secure TLD</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17946</link>
    <description>&lt;pre&gt;http://www.darkreading.com/authentication/167901072/security/security-management/240000187/new-i-secure-i-internet-domain-on-tap.html

If they really wanted to be secure they would require the
implementation of RFC 3514

&lt;/pre&gt;</description>
    <dc:creator>Ben April</dc:creator>
    <dc:date>2012-05-12T01:23:01</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17945">
    <title>Terrorist toddlers (Toddler terrorists?)</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17945</link>
    <description>&lt;pre&gt;http://www.vancouversun.com/travel/toddler+JetBlue+employees+pull+month+from+flight+over+list/6606185/story.html
&lt;/pre&gt;</description>
    <dc:creator>Robert Slade</dc:creator>
    <dc:date>2012-05-11T17:49:07</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17943">
    <title>As you were ...</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17943</link>
    <description>&lt;pre&gt;Apparently the Mayan's were as bad as anyone else changing their minds on the 
date of the end of the world ...

http://www.sciencedaily.com/releases/2012/05/120510141905.htm

======================  (quote inserted randomly by Pegasus Mailer)
rslade&amp;lt; at &amp;gt;vcn.bc.ca     slade&amp;lt; at &amp;gt;victoria.tc.ca     rslade&amp;lt; at &amp;gt;computercrime.org
The evening news is where they begin with 'Good evening,' and
then proceed to tell you why it isn't.
            - http://twitter.com/judybishop/status/25012495785664512
victoria.tc.ca/techrev/rms.htm http://www.infosecbc.org/links
http://blogs.securiteam.com/index.php/archives/author/p1/
http://twitter.com/rslade
&lt;/pre&gt;</description>
    <dc:creator>Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah</dc:creator>
    <dc:date>2012-05-10T22:03:41</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17942">
    <title>7 Ways Oracle Puts Database Customers At Risk</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17942</link>
    <description>&lt;pre&gt;A very good coverage:

http://www.darkreading.com/database-security/167901020/security/news/232901381/7-ways-oracle-puts-database-customers-at-risk.html

Juha-Matti
&lt;/pre&gt;</description>
    <dc:creator>Juha-Matti Laurio</dc:creator>
    <dc:date>2012-05-10T15:19:56</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17922">
    <title>Cost/benefit?</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17922</link>
    <description>&lt;pre&gt;http://www.cbc.ca/news/world/story/2012/05/05/japan-nuclear-power-shut-off.html

Boy, this came as a bit of a shocker.  Yeah, I know people are afraid of nukes (and 
power companies are often more careless than they should be.  Even so, you would 
think that some people would realize the huge risks and (invisible) costs of coal 
and oil.

======================  (quote inserted randomly by Pegasus Mailer)
rslade&amp;lt; at &amp;gt;vcn.bc.ca     slade&amp;lt; at &amp;gt;victoria.tc.ca     rslade&amp;lt; at &amp;gt;computercrime.org
A lot of good arguments are spoiled by some fool who knows what
he is talking about.                             - Miguel de Unamuno
victoria.tc.ca/techrev/rms.htm http://www.infosecbc.org/links
http://blogs.securiteam.com/index.php/archives/author/p1/
http://twitter.com/rslade
&lt;/pre&gt;</description>
    <dc:creator>Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah</dc:creator>
    <dc:date>2012-05-05T19:36:43</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17921">
    <title>Seriously?</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17921</link>
    <description>&lt;pre&gt;Seriously? The "new threat of user-initiated drive by downloads"?

===============================================

Don’t Install Android Security Updates While Browsing the Web,
http://www.gottabemobile.com/2012/05/04/dont-install-android-security-updates-while-browsing-the-web/

Surfing the web on Android is relatively safe, but a new threat tricks
users into installing a trojan that calls itself a security update.

Symantec discovered the Android.Notcompatible threat this week,
calling attention to the new threat of user-initiated drive by
downloads.

Malware is a problem on Android smartphones, but it is typically
reserved for infected fake games and apps found on third-party
marketplaces. This new attack can happen on any infected webpage, and
relies on tricking the user into installing the malware.
...
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.&lt;/pre&gt;</description>
    <dc:creator>Jeffrey Walton</dc:creator>
    <dc:date>2012-05-05T19:18:39</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17920">
    <title>Phecal photo forensics</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17920</link>
    <description>&lt;pre&gt;I suppose I really can't let this one ... pass ...

Last weekend a young woman fell to her death while on a tandem hang glider ride with an experienced pilot.  The pilot, owner of a company that takes people on hang gliding rides for kicks, promises video of the event: the hang glider is equipped with some kind of boom-mounted camera pointed at the riders.

Somehow the police investigating the incident suspected that the pilot had swallowed the memory card from the video camera.  (Presumably the video was running, and presumably the pilot knew it would show something unfortunate.)  This was later confirmed by x-rays.

So, this week we have all been on "memory card movement" watch.

And it has cr... I mean, come out all right.

http://www.cbc.ca/news/canada/british-columbia/story/2012/05/04/bc-hang-glider.html

====================== rslade&amp;lt; at &amp;gt;computercrime.org  slade&amp;lt; at &amp;gt;victoria.tc.ca  rslade&amp;lt; at &amp;gt;vcn.bc.ca "If you do buy a computer, don't turn it on."     - Richards' 2nd Law ============= for back issues: [Base URL] site http://victoria.tc.ca/techrev/ CISSP refs:     [Base URL]mnbksccd.htm Security Dict.: [Base URL]secgloss.htm Book reviews:   [Base URL]mnbk.htm                 [Base URL]review.htm Partial/recent: http://groups.yahoo.com/group/techbooks/ Review mailing list: send mail to techbooks-subscribe&amp;lt; at &amp;gt;egroups.com http://blogs.securiteam.com/index.php/archives/author/p1/ http://blog.isc2.org/isc2_blog/slade/index.html http://twitter.com/rslade 


&lt;/pre&gt;</description>
    <dc:creator>Robert Slade</dc:creator>
    <dc:date>2012-05-04T21:32:22</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17918">
    <title>The Facebook Commandments</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17918</link>
    <description>&lt;pre&gt;I've always been interested in "netiquette."  (Almost 25 years ago I created a set of 
"rules of Internet Order" which can still be found, although mostly on mailing list 
archives.)  Recent research has found a number of "commandments" common to 
Facebook users, and quantified them:
http://www.vancouversun.com/technology/Facebook+Commandments/6552868/sto
ry.html

The result?

The REAL 10 Commandments of Facebook

Of the 36 friendship rules identified by researchers, these were the most followed. 
Listed in order of endorsement.

1. Thou shalt expect a response after posting on someone's profile.

2. Thou shalt refrain from being disrespectful.

3. Thou shalt consider how a post might negatively affect someone's relationships.

4. If a post is deleted by someone, thou shalt not repost it.

5. Thou shalt communicate with Facebook friends outside of Facebook.

6. Thou shalt present oneself positively but honestly.

7. Thou shalt not let Facebooking with someone interfere with work.

8. Thou shalt not post information on Facebook that could later backfire.

9. Thou shalt use common sense when interacting with someone.

10. Thou shalt consider how a post might negatively affect someone's career.


Disappointingly banal.

======================  (quote inserted randomly by Pegasus Mailer)
rslade&amp;lt; at &amp;gt;vcn.bc.ca     slade&amp;lt; at &amp;gt;victoria.tc.ca     rslade&amp;lt; at &amp;gt;computercrime.org
We learn from experience that men never learn anything from
experience.                                    - George Bernard Shaw
victoria.tc.ca/techrev/rms.htm http://www.infosecbc.org/links
http://blogs.securiteam.com/index.php/archives/author/p1/
http://twitter.com/rslade
&lt;/pre&gt;</description>
    <dc:creator>Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah</dc:creator>
    <dc:date>2012-05-02T19:03:44</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17916">
    <title>Buy it!  You need it!</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17916</link>
    <description>&lt;pre&gt;http://www.icanbarelydraw.com/comic/1810

Not to jump on the current "AV is useless" bandwagon, but I've definitely heard 
this type of thing often enough from vendors ...

======================  (quote inserted randomly by Pegasus Mailer)
rslade&amp;lt; at &amp;gt;vcn.bc.ca     slade&amp;lt; at &amp;gt;victoria.tc.ca     rslade&amp;lt; at &amp;gt;computercrime.org
Security is difficult, President.  Anyone who says differently is
selling something.                              - The Paranoid Guide
victoria.tc.ca/techrev/rms.htm http://www.infosecbc.org/links
http://blogs.securiteam.com/index.php/archives/author/p1/
http://twitter.com/rslade
&lt;/pre&gt;</description>
    <dc:creator>Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah</dc:creator>
    <dc:date>2012-04-27T18:43:29</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17914">
    <title>Flash! TSA bans bread!</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17914</link>
    <description>&lt;pre&gt;Following the explosions in two BC sawmills, which experts are speculating may 
have been caused by fine sawdust caused by excessively dry wood, the TSA has 
banned any particulate materials, such as sawdust, flour, and icing sugar, to be 
banned from all flights.

http://www.cbc.ca/news/technology/story/2012/04/25/bob-mcdonald-science-
sawmill-fires.html

Also included in the ban are any objects made from particulate materials, such as 
particleboard, bread, and icing sugar dusted donuts.  (The union representing TSA 
workers had argued, unsuccessfully, against this last item.)  The TSA's Director Of 
Really Dangerous Stuff also noted that materials with larger particle sizes, such as 
table salt and sand, were also being included in the ban.

At press time, we were still awaiting word on whether computer equipment was to 
be included in the ban, since silicon chips are commonly said to be made of sand.

(Yeah, yeah, I know, don't give the TSA ideas ...)

(Dust explosions used to be common, and still happen, in coal mines, sawmills, and 
granaries.  The idea that beetle-killed wood might be at fault is interesting, since 
sawing dry wood creates smaller particles and more of them, and the existing 
safety measures may no longer be sufficient.  One report quoted a witness to the 
recent fire who couldn't believe that dust could create such an explosion.  I 
understand that, absent nuclear weapons, the most powerful explosives in the 
military arsenal are fuel-air explosives [FAE], which are essentially the same 
thing.)

======================  (quote inserted randomly by Pegasus Mailer)
rslade&amp;lt; at &amp;gt;vcn.bc.ca     slade&amp;lt; at &amp;gt;victoria.tc.ca     rslade&amp;lt; at &amp;gt;computercrime.org
  Inside some of us is a thin person struggling to get out,
  but he can usually be sedated with a few pieces of chocolate cake.
victoria.tc.ca/techrev/rms.htm http://www.infosecbc.org/links
http://blogs.securiteam.com/index.php/archives/author/p1/
http://twitter.com/rslade
&lt;/pre&gt;</description>
    <dc:creator>Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah</dc:creator>
    <dc:date>2012-04-26T17:28:36</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17913">
    <title>That oozing you hear is the sound of world domination byathersclerosis ...</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17913</link>
    <description>&lt;pre&gt;Apparently, Al Queda and the Islamists were right.  America *is* the Great Satan.  
They were just wrong about which particular "weapon of mass destruction" would 
be involved ...

http://npr.tumblr.com/post/21788479559/gifhound-pizza-hut-introduces-the-
crown-crust

======================  (quote inserted randomly by Pegasus Mailer)
rslade&amp;lt; at &amp;gt;vcn.bc.ca     slade&amp;lt; at &amp;gt;victoria.tc.ca     rslade&amp;lt; at &amp;gt;computercrime.org
To make no mistake is not in the power of man; but from their
errors and mistakes the wise and good learn wisdom for the future
                                                          - Plutarch
victoria.tc.ca/techrev/rms.htm http://www.infosecbc.org/links
http://blogs.securiteam.com/index.php/archives/author/p1/
http://twitter.com/rslade
&lt;/pre&gt;</description>
    <dc:creator>Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah</dc:creator>
    <dc:date>2012-04-25T23:43:10</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17912">
    <title>Public presentation of complex issues</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17912</link>
    <description>&lt;pre&gt;http://www.bbc.co.uk/news/technology-17838798#

I came across this by accident, and was disappointed that I'd hit the video clip 
rather than an actual story.  (The fact that this clip is nominally about porn is not 
really the point.)

What I found increasingly disturbing as the clip went on was how the deck was 
loaded against reality.  The "criminologist" with the better jacket, better shirt, and 
better haircut, who was in the studio, shot in part profile, and in front of a colour 
background, was the guy blowing smoke.  (If you are going to say that the ISPs 
should be responsible, they aren't the ones controlling your "rooter" [sorry].  Or, 
if they did set it once, they don't do anything to it on an ongoing basis.)  The guy 
who actually knows what he is talking about has made poor fashion choices (and 
that's *his* fault), but he's also shot in full-face mugshot format, in front of a dull 
grey background (and gets cut off at one point).  If they had deliberately set out to 
relieve parents of responsibility they couldn't have done a better job.

======================  (quote inserted randomly by Pegasus Mailer)
rslade&amp;lt; at &amp;gt;vcn.bc.ca     slade&amp;lt; at &amp;gt;victoria.tc.ca     rslade&amp;lt; at &amp;gt;computercrime.org
You see, wire telegraph is a kind of a very, very long cat.  You
pull his tail in New York and his head is meowing in Los Angeles.
Do you understand this?  And radio operates exactly the same way:
you send signals here, they receive them there.  The only
difference is that there is no cat.                - Albert Einstein
victoria.tc.ca/techrev/rms.htm http://www.infosecbc.org/links
http://blogs.securiteam.com/index.php/archives/author/p1/
http://twitter.com/rslade
&lt;/pre&gt;</description>
    <dc:creator>Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah</dc:creator>
    <dc:date>2012-04-25T22:52:31</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17911">
    <title>[HITB-Announce] HITB Magazine Issue 008 (now with printedition!)</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17911</link>
    <description>&lt;pre&gt;The 8th issue of the HITB Quarterly Magazine is now available for download!

http://magazine.hitb.org/

This edition is a little bit 'lighter' than previous issues as the
editorial team is busy working on an extra special release for our 10th
year anniversary conference in October, HITBSecConf2012 - Malaysia.

http://conference.hitb.org/hitbsecconf2012kul/

For the first time ever though, we're making print editions of the
magazine available (courtesy of HP MagCloud) - A print edition of the
HITB Quarterly is a perfect addition for your coffee table or office
reception area and we'll be making past issues also available for print
over the next couple of weeks.

We're hoping that print sales will allow us to pay our authors and
contributors for their articles, so ordering a print copy is a way for
you to help support them! Putting together content for the magazine is
practically a full time job and it would be nice to offer authors some
form of compensation for the time and energy taken to produce the high
quality articles that you all enjoy.

Enjoy the issue and hopefully see you at #HITB2012AMS in May:
http://conference.hitb.org/hitbsecconf2012ams/

---
Hafez Kamal
HITB Crew
Hack in The Box (M) Sdn. Bhd.
Suite 26.3, Level 26, Menara IMC,
No. 8 Jalan Sultan Ismail,
50250 Kuala Lumpur,
Malaysia

Tel: +603-20394724
Fax: +603-20318359

&lt;/pre&gt;</description>
    <dc:creator>Hafez Kamal</dc:creator>
    <dc:date>2012-04-23T14:19:11</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.funsec/17910">
    <title>Preventing Widespread Automated Attacks in iOS</title>
    <link>http://comments.gmane.org/gmane.comp.security.funsec/17910</link>
    <description>&lt;pre&gt;A real nice three part article by Jonathan Zdziarski on abusing
programs in memory using Objective C.

Preventing Widespread Automated Attacks in iOS,
https://viaforensics.com/iphone-forensics/preventing-widespread-ios-application-infection.html

With a hundred million end users, the notion of a widespread attack on
Apple iOS devices is tempting to any criminal. The dream (or
nightmare) of an attacker somehow targeting potentially millions of
always-on, always-connected iOS devices using a large-scale automated
attack is quite disconcerting.
...

While I’ve discussed a number of ways to circumvent these technologies
in my book, this article is going to dig a bit deeper and address
automated techniques to steal data from a common place in iOS: memory.
What if I told you that I could steal personal information that you
don’t even store on your phone, from your phone, while you were using
your phone, and be a thousand miles away? The reality is much worse
than this, in fact. Should an attacker craft such an automated attack,
they could quite possibly modify data as it’s sent TO your financial
institution, or other online account, to redirect payments to their
own account, or to wreak other forms of havoc, using your own
application to do it.
...
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.&lt;/pre&gt;</description>
    <dc:creator>Jeffrey Walton</dc:creator>
    <dc:date>2012-04-21T22:29:07</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.comp.security.funsec">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.comp.security.funsec</link>
  </textinput>
</rdf:RDF>

