<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">
<channel>
    <title>The Quiet Earth - Experiences</title>
    <link>http://blog.balrog.de/</link>
    <description>rants and musings about information security</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.4.1 - http://www.s9y.org/</generator>
    <pubDate>Wed, 05 Dec 2007 10:21:58 GMT</pubDate>

    <image>
        <url>http://blog.balrog.de/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: The Quiet Earth - Experiences - rants and musings about information security</title>
        <link>http://blog.balrog.de/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Spam as Spam can: JobLeads.DE</title>
    <link>http://blog.balrog.de/archives/486-Spam-as-Spam-can-JobLeads.DE.html</link>
            <category>Experiences</category>
    
    <comments>http://blog.balrog.de/archives/486-Spam-as-Spam-can-JobLeads.DE.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=486</wfw:comment>

    <slash:comments>5</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=486</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    Und immer wenn du denkst, es geht nicht mehr (schlimmer), kommt irgendjemand, der dir das Gegenteil beweist. Na super. Heute morgen finde ich in meiner geschÃ¤ftlichen Inbox diesen Spam:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Sehr geehrter Herr Eble, &lt;br /&gt;
&lt;br /&gt;
vor Kurzem haben wir mit einem jungen Team JobLeads gelauncht. JobLeads ist eine &quot;By Invitation only&quot;-Karriereplattform, die sich speziell an hoch qualifizierte Fach- und FÃ¼hrungskrÃ¤fte richtet. Top-Unternehmen schreiben bei JobLeads ihre Stellenangebote aus und versehen diese mit PrÃ¤mien zwischen â‚¬ 2.000 und â‚¬ 20.000 fÃ¼r die erfolgreiche Empfehlung von Kandidaten. &lt;br /&gt;
&lt;br /&gt;
Um den Anforderungen an eine exklusive Karriereplattform gerecht zu werden, gehen wir bei der Auswahl unserer Mitglieder sehr selektiv vor. JobLeads-Mitglieder haben an fÃ¼hrenden UniversitÃ¤ten im In- und Ausland studiert und sind nun in verantwortungsvollen Positionen tÃ¤tig. Als Absolvent der Universitaet Freiburg gehÃ¶ren auch Sie zu diesem Personenkreis und wir mÃ¶chten Ihnen anbieten, die Vorteile von JobLeads zu nutzen (die Mitgliedschaft ist und bleibt natÃ¼rlich kostenlos). &lt;br /&gt;
&lt;br /&gt;
Als Mitglied hat man exklusiven Zugang zu Top-Stellenangeboten und die MÃ¶glichkeit, die ausgeschriebenen Positionen an Freunde zu empfehlen. Kommt es aufgrund einer Empfehlung zu einer Einstellung, erhÃ¤lt man die PrÃ¤mie. SelbstverstÃ¤ndlich kann man sich auch auf interessante Positionen bewerben. JobLeads macht es so mÃ¶glich, immer Ã¼ber spannende Stellenangebote von attraktiven Unternehmen informiert zu bleiben, Freunden interessante Jobs zu empfehlen und nebenbei noch Geld zu verdienen. &lt;br /&gt;
&lt;br /&gt;
Falls Sie Interesse haben, JobLeads-Mitglied zu werden, kÃ¶nnen Sie sich Ã¼ber den unten stehenden Link registrieren. Falls nicht, wÃ¼nschen wir Ihnen auf Ihrem Karriereweg weiterhin viel Erfolg. &lt;br /&gt;
&lt;br /&gt;
https://www.jobleads.de/user_introduction_invitation.php?aid=XXXX &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Viele GrÃ¼ÃŸe aus Hamburg &lt;br /&gt;
&lt;br /&gt;
Ihr JobLeads-Team &lt;br /&gt;
&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Das zeugt ja schon mal aus mehreren GrÃ¼nden von Ã¤h... fehlender Ãœberlegung. Erstens: woher haben die meine GeschÃ¤ftsadresse? Mit der gehe ich nicht gerade hausieren. Zweitens: es ist Spam. Ich habe keine GeschÃ¤ftsbeziehungen mit diesem ominÃ¶sen Unternehmen noch habe ich Interesse daran, von denen meine Inbox gefÃ¼llt zu bekommen. Drittens: schlechte Datenquelle - ich bin kein Alumnus der &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.uni-freiburg.de/&#039;);&quot;  href=&quot;http://www.uni-freiburg.de/&quot;  title=&quot;Albert-Ludwigs-UniversitÃ¤t Freiburg&quot;&gt;ALU&lt;/a&gt;. Ich war da zwar mal eine Weile eingeschrieben, aber ich habe nicht abgeschlossen dort. Viertens (und damit kommen wir zu den technischen Seiten des ganzen Braindeaths): es gibt keine funktionierende Abuse-Adresse fÃ¼r jobleads.de. FÃ¼nftens: dÃ¼nnes Gefasel auf der Webseite, irgendwo ist &quot;Recruiting 2.0&quot; erwÃ¤hnt (meine GÃ¼te, dieser 2.0-Hype ist doch schon wieder vorbei!).&lt;br /&gt;
&lt;br /&gt;
Ich spare mir jetzt irgendwelche offensichtlichen Auslassungen Ã¼ber Investmentbanker. Man soll ja nicht eine ganze Berufsgruppe Ã¼ber einen Kamm scheren.&lt;br /&gt;
&lt;br /&gt;
Nichtsdestotrotz muss man derartigen Machenschaften gleich entsprechend einen Riegel vorschieben:&lt;br /&gt;
&lt;blockquote&gt;&lt;br /&gt;
Hallo,&lt;/br&gt;&lt;br /&gt;
&lt;/br&gt;&lt;br /&gt;
&lt;p&gt;Ich habe diesen Spam von Euch in meiner geschÃ¤ftlichen Inbox gefunden. Nicht genug damit, daÃŸ Ihr damit eindeutig gegen existierende Gesetze verstÃ¶ÃŸt, zeigt ihr dazu noch&lt;/p&gt;&lt;br /&gt;
&lt;ol&gt;&lt;br /&gt;
&lt;li&gt;eine erstaunliche InsensibilitÃ¤t (hallo? Jobmarkt-Angebote an geschÃ¤ftliche Adressen? Geht&#039;s noch?)&lt;/li&gt;&lt;br /&gt;
&lt;li&gt;eine erstaunliche Inkompetenz was Marketing in Zeiten des Internet bedeutet (Spam ist die beste Antiwerbung, die ihr hÃ¤ttet machen kÃ¶nnen)&lt;/li&gt;&lt;br /&gt;
&lt;/ol&gt;&lt;br /&gt;
&lt;p&gt;Eine rechtliche Aufarbeitung dieser Email spare ich mir - diesmal. Nichtsdestotrotz beanspruche ich nach Â§19 Bundesdatenschutzgesetz Auskunft darÃ¼ber:&lt;/p&gt;&lt;br /&gt;
&lt;ol&gt;&lt;br /&gt;
&lt;li&gt;welche Daten Ihr Ã¼ber mich gespeichert habt&lt;/li&gt;&lt;br /&gt;
&lt;li&gt;wo ihr diese Daten her habt&lt;/li&gt;&lt;br /&gt;
&lt;li&gt;an wen Ihr diese Daten weitegegeben habt bzw. weiterzugeben gedenkt&lt;/li&gt;&lt;br /&gt;
&lt;/ol&gt;&lt;br /&gt;
&lt;p&gt;Ich gebe Euch bis Freitag, den 7.12.2007, 17:00 Zeit, dieses Auskunftersuchen zu beantworten. Verstreicht diese Frist ohne Antwort, werde ich rechtliche Schritte einleiten.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;DarÃ¼ber hinaus untersage ich jedwede Weitergabe oder Verarbeitung der gespeicherten Daten, soweit sie mich betreffen.&lt;/p&gt;&lt;br /&gt;
 &lt;/br&gt;&lt;br /&gt;
&lt;/br&gt;    Axel Eble&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/karrierebibel.de/vitamin-b-jobleads-versucht-sich-in-recruiting-20/&#039;);&quot;  href=&quot;http://karrierebibel.de/vitamin-b-jobleads-versucht-sich-in-recruiting-20/&quot;  title=&quot;Die Karriere-Bibel&quot;&gt;Die Karriere-Bibel&lt;/a&gt; sieht das JobLeads-Angebot Ã¼brigens etwas neutraler. 
    </content:encoded>

    <pubDate>Wed, 05 Dec 2007 11:02:05 +0100</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/486-guid.html</guid>
    <geo:long>7.85943</geo:long><geo:lat>48.02558</geo:lat><category>anti-recruiting</category>
<category>jobleads</category>
<category>recruiting</category>
<category>spam</category>
<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Verbietet Killerspiele! Lockt die Jugend ins Kino!!!(eins elf)</title>
    <link>http://blog.balrog.de/archives/480-Verbietet-Killerspiele!-Lockt-die-Jugend-ins-Kino!!!eins-elf.html</link>
            <category>Experiences</category>
    
    <comments>http://blog.balrog.de/archives/480-Verbietet-Killerspiele!-Lockt-die-Jugend-ins-Kino!!!eins-elf.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=480</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=480</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    Nach dem Besuch von Â«James Bond: Casino RoyaleÂ» stellt sich mir ernsthaft die Frage, was die Diskussion Ã¼ber das Verbot von Egoshootern (vulgo: Killerspiele) soll, wenn derartige Filme ab 12 Jahren freigegeben sind. Mal ganz abgesehen von der sinnfreien Darstellung der Gewalt (den Sex hatten sie ja mal wieder ausgeblendet und bitte was soll das denn?!) finde ich auch die Thematik fÃ¼r einen 12jÃ¤hrigen nicht unbedingt nachvollziehbar.&lt;br /&gt;
&lt;br /&gt;
Was wieder einmal zeigt, daÃŸ das reflexartige Geschrei nach dem Â«Verbot von KillerspielenÂ» eben nicht mehr ist als genau das: reflexartiges Geschrei. 
    </content:encoded>

    <pubDate>Sat, 06 Jan 2007 18:28:36 +0100</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/480-guid.html</guid>
    <geo:long>10.33537</geo:long><geo:lat>47.7192</geo:lat><category>egoshooter</category>
<category>filme</category>
<category>killerspiele</category>
<category>media</category>
<category>medien</category>
<category>medienkompetenz</category>
<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Language Log: Translating leadership, creating verbiage</title>
    <link>http://blog.balrog.de/archives/474-Language-Log-Translating-leadership,-creating-verbiage.html</link>
            <category>Experiences</category>
            <category>Meta</category>
            <category>Off-Topic</category>
    
    <comments>http://blog.balrog.de/archives/474-Language-Log-Translating-leadership,-creating-verbiage.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=474</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=474</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/itre.cis.upenn.edu/~myl/languagelog/archives/003483.html&#039;);&quot;  href=&quot;http://itre.cis.upenn.edu/~myl/languagelog/archives/003483.html&quot;&gt;Language Log: Translating leadership, creating verbiage&lt;/a&gt;&lt;br /&gt;
&quot;Translating thought leadership...creating business results&quot;&lt;br /&gt;
&lt;br /&gt;
Wonderful, just wonderful! I&#039;ve nothing to add to it, actually. 
    </content:encoded>

    <pubDate>Tue, 22 Aug 2006 12:37:08 +0200</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/474-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>The Quest to Shutdown A Credit Card Fraud Site</title>
    <link>http://blog.balrog.de/archives/473-The-Quest-to-Shutdown-A-Credit-Card-Fraud-Site.html</link>
            <category>Experiences</category>
            <category>local</category>
    
    <comments>http://blog.balrog.de/archives/473-The-Quest-to-Shutdown-A-Credit-Card-Fraud-Site.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=473</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=473</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    In &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.viruslist.com/de/weblog?weblogid=192362303&#039;);&quot;  href=&quot;http://www.viruslist.com/de/weblog?weblogid=192362303&quot;&gt;Viruslist.com - Analytiker-Tagebuch&lt;/a&gt; (German only) a Kaspersky Labs technician describes how they found a Russian web site hosting data of about 300 credit cards, some with only basic information, some with deluxe information like ATM PIN, email address and phone number of the owner.&lt;br /&gt;
&lt;br /&gt;
Kaspersky labs then called the &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.bka.de/&#039;);&quot;  href=&quot;http://www.bka.de/&quot;&gt;Bundeskriminalamt &lt;/a&gt;, the German Federal police - to no avail. All three people they were named as responsible for this sort of information were already gone for the weekend. The same at the State police authorities. What is really scary is the fact that they didn&#039;t reach anybody from MasterCard or VISA, both. The hotline for lost cards wanted to know the credit card number of the calling party. Ouch.&lt;br /&gt;
&lt;br /&gt;
Well, Kaspersky is not without resources. They finally contacted their US branch office which in turn got in contact with the FBI - and the Russian headquarters took care of shutting the site down.&lt;br /&gt;
&lt;br /&gt;
I&#039;m curious if this experience will change something at the German police institutions. However, I really doubt it. 
    </content:encoded>

    <pubDate>Mon, 07 Aug 2006 12:54:27 +0200</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/473-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Don't Bark Too Loud</title>
    <link>http://blog.balrog.de/archives/429-Dont-Bark-Too-Loud.html</link>
            <category>Experiences</category>
            <category>Technology</category>
    
    <comments>http://blog.balrog.de/archives/429-Dont-Bark-Too-Loud.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=429</wfw:comment>

    <slash:comments>4</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=429</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/blogs.23.nu/disLEXia/stories/9511/&#039;);&quot;  href=&quot;http://blogs.23.nu/disLEXia/stories/9511/&quot;&gt;Maximillian Dornseif writes in &lt;em&gt;Barking at Banks&lt;/em&gt;&lt;/a&gt; that German banks sell indexed transaction numbers (iTANs, authorization codes for individual transactions) as the best thing since sliced bread and that all security woes would be magically cured by their use. He goes on to say that the banks spread misinformation and points to an advisory by his students about how iTANs are of no use against Man-In-The-Middle-Attacks. Which, of course, is right.&lt;br /&gt;
However, iTANs are a good tool against phishing - a phisher won&#039;t have any idea which TAN will be the next and even if they phish two or three TANs chances are they are of little use to him. And that&#039;s not even mentioning that users should get some funny feeling upon a) reading phishing emails as they are translated so extremely bad that it should be obvious they&#039;re not from the bank and b) the form asking for the TANs doesn&#039;t ask for TANs with specific indexes. So, while iTANs don&#039;t help against trojans they are pretty useful against phishers.&lt;br /&gt;
&lt;br /&gt;
Dornseif&#039;s and his students&#039; underlying premises are true, however: if the banks would use a sufficiently good mix of low-level and high-level security things would be much harder for phishers. What do I mean by low-level security? Things like &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.emergentchaos.com/archives/001590.html&#039;);&quot;  href=&quot;http://www.emergentchaos.com/archives/001590.html&quot;&gt;&lt;strong&gt;not&lt;/strong&gt; sending out HTML emails&lt;/a&gt; but simple &lt;code&gt;text/plain&lt;/code&gt; messages, sent from the email servers and domains of the bank itself. And what do I mean by high-level security? Well, a time based one-time password (OTP) would be a better idea than a list of pre-generated TANs. However, the cost/benefit ratio probably won&#039;t see us going there. Even better would be &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/en.wikipedia.org/wiki/HBCI&#039;);&quot;  href=&quot;http://en.wikipedia.org/wiki/HBCI&quot;&gt;HBCI&lt;/a&gt; with a Class 3 chipcard reader. In that case, however, the user interface is clumsy (as is often the case with security: it&#039;s not exactly user-friendly). So I don&#039;t see much happening on that front, either.&lt;br /&gt;
&lt;br /&gt;
As a final note, it&#039;s quite interesting how diverse different countries&#039; banks can be. In some countries banks hand out time-based OTP tokens, in the USA on the other hand banks don&#039;t seem to get a grasp of the concept of transaction authorization. Quite interesting, actually, as I&#039;m sure it ties down to the mentality and society of the corresponding people. 
    </content:encoded>

    <pubDate>Thu, 25 Aug 2005 15:07:49 +0200</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/429-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Congratulations, Risks!</title>
    <link>http://blog.balrog.de/archives/417-Congratulations,-Risks!.html</link>
            <category>Experiences</category>
            <category>General</category>
            <category>Technology</category>
    
    <comments>http://blog.balrog.de/archives/417-Congratulations,-Risks!.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=417</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=417</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    The &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.f-secure.com/weblog/&#039;);&quot;  href=&quot;http://www.f-secure.com/weblog/&quot;&gt;F-Secure&lt;/a&gt; weblog reminds of the &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.risks.org/&#039;);&quot;  href=&quot;http://www.risks.org/&quot;&gt;RISKS Digest&lt;/a&gt;&#039;s 20&lt;sup&gt;th&lt;/sup&gt; anniversary today. Thanks to &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.csl.sri.com/neumann/neumann.html&#039;);&quot;  href=&quot;http://www.csl.sri.com/neumann/neumann.html&quot;&gt;Dr. Peter G. Neumann&lt;/a&gt; for handling the digest!&lt;br /&gt;
&lt;br /&gt;
What was new to me was the fact that the Digest is also available as an &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/catless.ncl.ac.uk/rdigest.rdf&#039;);&quot;  href=&quot;http://catless.ncl.ac.uk/rdigest.rdf&quot;&gt;RSS feed&lt;/a&gt; nowadays. 
    </content:encoded>

    <pubDate>Wed, 03 Aug 2005 12:43:32 +0200</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/417-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Nostalgia: Good Bye, My Friend</title>
    <link>http://blog.balrog.de/archives/405-Nostalgia-Good-Bye,-My-Friend.html</link>
            <category>Experiences</category>
            <category>General</category>
            <category>Meta</category>
    
    <comments>http://blog.balrog.de/archives/405-Nostalgia-Good-Bye,-My-Friend.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=405</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=405</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    I just revoked a PGP key I had created 1995. It&#039;s really sweet to remember all the stories to all the email addresses that the key was tagged with.&lt;br /&gt;
&lt;br /&gt;
Good bye, my friend. 
    </content:encoded>

    <pubDate>Fri, 24 Jun 2005 22:43:36 +0200</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/405-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Technological Complexity Bites Back</title>
    <link>http://blog.balrog.de/archives/365-Technological-Complexity-Bites-Back.html</link>
            <category>Experiences</category>
            <category>General</category>
            <category>Meta</category>
            <category>Technology</category>
    
    <comments>http://blog.balrog.de/archives/365-Technological-Complexity-Bites-Back.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=365</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=365</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/silverstr.ufies.org/blog/&#039;);&quot;  href=&quot;http://silverstr.ufies.org/blog/&quot; title=&quot;Dana Epp&#039;s Blog&quot;&gt;Dana Epp&lt;/a&gt; talks about &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/silverstr.ufies.org/blog/archives/000773.html&#039;);&quot;  href=&quot;http://silverstr.ufies.org/blog/archives/000773.html&quot;&gt;the Top 10 Threats in 2004 (According to McAfee)&lt;/a&gt;. While he&#039;s right in that most of these exploited long-known vulnerabilities that could have been patched, I see this only as an effect, a symptom, not the root cause. Why? Because even the notorious Microsoft vulnerabilities are not the root cause. It&#039;s the people and the complexity of the technology they use but refuse to learn enough about.&lt;br /&gt;
Our current computer and network technology is sufficiently easy to use for most people to jump aboard and do it. It is, however, at the same time sufficiently complex that most people will make errors in their configuration which in turn lead to vulnerabilities in their installed base.&lt;br /&gt;
Even people who should know it better (read: paid administrators in small to large companies) often enough have no clue whatsoever why something needs to be done in a certain way. Example? Take Wireless LAN - there&#039;s an abundance of people (and companies) setting up their access points without any security settings turned on. Take DNS: one of the most used and most abused protocols and applications on the Internet.&lt;br /&gt;
&lt;br /&gt;
I believe that we need to work on the complexity: if things were less complex or at least well enough hidden behind a decent, intuitive GUI, I think we might better off. This would include safe and sensible default settings that work. And yes, we would possibly have to revamp some of the core protocols. The Internet has emerged from a small and safe place into an anarchic labyrinth where the old technologies simply don&#039;t scale any more. They were sufficient for the old times when there was trust abundant Out There. Today we need a complex design phase that caters to the complex problems and tries to find easy solutions to complexity.&lt;br /&gt;
&lt;br /&gt;
And in the meantime it would help a lot if our dear vendors would start shipping their gear with security options turned on by default.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 04 Jan 2005 02:01:13 +0100</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/365-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Im Westen nichts Neues</title>
    <link>http://blog.balrog.de/archives/328-Im-Westen-nichts-Neues.html</link>
            <category>Experiences</category>
    
    <comments>http://blog.balrog.de/archives/328-Im-Westen-nichts-Neues.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=328</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=328</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.avolio.com/&#039;);&quot;  href=&quot;http://www.avolio.com/&quot;&gt;Fred Avolio&lt;/a&gt; &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.avolio.com/weblog/security/SecurityRedux.html&#039;);&quot;  href=&quot;http://www.avolio.com/weblog/security/SecurityRedux.html&quot;&gt;talks&lt;/a&gt; about how the same old, same old discussions seem to pop up in information security.&lt;br /&gt;
&lt;br /&gt;
He&#039;s right, of course. I heard &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.ranum.com/&#039;);&quot;  href=&quot;http://www.ranum.com/&quot;&gt;Marcus Ranum&lt;/a&gt; a few days ago and he said basically the same thing: Information Security isn&#039;t rocket science and the most effective techniques have been around since at least 20 years.&lt;br /&gt;
&lt;br /&gt;
So, what does it mean? To be cynical, it means that the information security industry is a big part of the problem. They don&#039;t seem to want to come up with solutions to our problems, they don&#039;t seem to want to do research. Of course, if they make us secure, they won&#039;t sell anything anymore. And if they want to keep on selling us their stuff that more or less works, they&#039;ll have to re-label it. So that&#039;s why we have &lt;em&gt;Intrusion Prevention&lt;/em&gt; now.&lt;br /&gt;
&lt;br /&gt;
The real hard problems haven&#039;t been solved, like log file correlation; like insecure default settings; like… you name it. 
    </content:encoded>

    <pubDate>Sun, 04 Apr 2004 20:20:05 +0200</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/328-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Anfänger</title>
    <link>http://blog.balrog.de/archives/323-Anfer.html</link>
            <category>Experiences</category>
    
    <comments>http://blog.balrog.de/archives/323-Anfer.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=323</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=323</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    How to tell a human from an automatic probe? Easy:&lt;br /&gt;
&lt;br /&gt;
&lt;pre&gt;&lt;br /&gt;
 Out: 220 Heimdal.Balrog.DE ESMTP Postfix&lt;br /&gt;
 In:  HELO&lt;br /&gt;
 Out: 501 Syntax: HELO hostname&lt;br /&gt;
 In:  QUIT&lt;br /&gt;
 Out: 221 Bye&lt;br /&gt;
&lt;/pre&gt; 
    </content:encoded>

    <pubDate>Sat, 24 Jan 2004 22:39:05 +0100</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/323-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>

</channel>
</rss>