<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">
<channel>
    <title>The Quiet Earth - local</title>
    <link>http://blog.balrog.de/</link>
    <description>rants and musings about information security</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.4.1 - http://www.s9y.org/</generator>
    <pubDate>Thu, 11 Dec 2008 12:39:15 GMT</pubDate>

    <image>
        <url>http://blog.balrog.de/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: The Quiet Earth - local - rants and musings about information security</title>
        <link>http://blog.balrog.de/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>PCs mit Dreien, Vieren oder eventuell FÃ¼nfen?</title>
    <link>http://blog.balrog.de/archives/493-PCs-mit-Dreien,-Vieren-oder-eventuell-Fuenfen.html</link>
            <category>local</category>
    
    <comments>http://blog.balrog.de/archives/493-PCs-mit-Dreien,-Vieren-oder-eventuell-Fuenfen.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=493</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=493</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    &lt;!-- s9ymdb:7 --&gt;&lt;img width=&quot;600&quot; height=&quot;800&quot; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://blog.balrog.de/uploads/images/11122008028.jpg&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;
&lt;br /&gt;
Ohne Worte. 
    </content:encoded>

    <pubDate>Thu, 11 Dec 2008 13:24:41 +0100</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/493-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>ReisebÃ¼ro</title>
    <link>http://blog.balrog.de/archives/492-Reisebuero.html</link>
            <category>local</category>
    
    <comments>http://blog.balrog.de/archives/492-Reisebuero.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=492</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=492</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    &lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://blog.balrog.de/uploads/images/10122008027.jpg&#039; onclick=&quot;F1 = window.open(&#039;/uploads/images/10122008027.jpg&#039;,&#039;Zoom&#039;,&#039;height=615,width=815,top=225,left=440,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes&#039;); return false;&quot;&gt;&lt;!-- s9ymdb:5 --&gt;&lt;img width=&quot;110&quot; height=&quot;83&quot; style=&quot;float: left; border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://blog.balrog.de/uploads/images/10122008027.serendipityThumb.jpg&quot; alt=&quot;&quot; /&gt;&lt;/a&gt; Abends in Freiburg kommt man gelegentlich an ReisebÃ¼ros vorbei. Diese haben hÃ¤ufiger auch groÃŸe Flatscreens als WerbetrÃ¤ger im Schaufenster. &lt;br /&gt;&lt;a href=&quot;http://blog.balrog.de/archives/492-Reisebuero.html#extended&quot;&gt;Continue reading &quot;ReisebÃ¼ro&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Thu, 11 Dec 2008 11:43:56 +0100</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/492-guid.html</guid>
    <geo:long>7.859717</geo:long><geo:lat>48.025081</geo:lat><category>zeitlÃ¤ufte</category>
<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>BarCamp Freiburg: Security Metrics</title>
    <link>http://blog.balrog.de/archives/485-BarCamp-Freiburg-Security-Metrics.html</link>
            <category>local</category>
            <category>Meetings</category>
    
    <comments>http://blog.balrog.de/archives/485-BarCamp-Freiburg-Security-Metrics.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=485</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=485</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    &lt;p&gt;Well, it&#039;s been on my mind for quite a while to set up some sort of security meeting in the area.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;It should have something to do with security and I want to learn something through it as well.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;Over at &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.orkpiraten.de/blog/plugin/tag/barcamp+hamburg&#039;);&quot;  href=&quot;http://www.orkpiraten.de/blog/plugin/tag/barcamp+hamburg&quot; title=&quot;JollyOrc&quot;&gt;JollyOrc&lt;/a&gt; I got intrigued by the idea of a barcamp and, what can I say: the three items seem to match up nicely.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;We&#039;ve been over the issue of security metrics time and time again in many different places and in many different company - without any meaningful result so far. I think it&#039;s time for a get-together and a discussion about what metrics make sense in what context.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;The format of a &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/barcamp.org/&#039;);&quot;  href=&quot;http://barcamp.org/&quot; title=&quot;BarCamp&quot;&gt;BarCamp&lt;/a&gt; seems to be ideally suited for exactly that: a get-together of like-minded people with different backgrounds working on the same topic.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;I&#039;m sure the location could be provided, maybe even by my company.&lt;/p&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 04 Dec 2007 21:54:27 +0100</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/485-guid.html</guid>
    <category>barcamp security metrics</category>
<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>Democracy, Freedom and the Internet.</title>
    <link>http://blog.balrog.de/archives/483-Democracy,-Freedom-and-the-Internet..html</link>
            <category>local</category>
    
    <comments>http://blog.balrog.de/archives/483-Democracy,-Freedom-and-the-Internet..html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=483</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=483</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    The German District Attorney of Halle has &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.heise.de/newsticker/meldung/83376&#039;);&quot;  href=&quot;http://www.heise.de/newsticker/meldung/83376&quot;  title=&quot;Heise Article (German only)&quot;&gt;urged the Credit Card Industry to screen all 20-22 million German credit cards&lt;/a&gt; for transactions along some criteria - without having an initial suspicion of any criminal behaviour. Any such screening and searching is only legal through a warrant. Now there are two immediate scandals obvious: &lt;br /&gt;
&lt;ol&gt;&lt;br /&gt;
&lt;li&gt;the District Attorney had no warrant whatsoever, but they threatened the credit card companies that non-compliance would be illegal and punishable&lt;/li&gt;&lt;br /&gt;
&lt;li&gt;the credit card companies&#039; lawyers obviously didn&#039;t care to think this would be illegal and complied.&lt;/li&gt;&lt;br /&gt;
&lt;/ol&gt;&lt;br /&gt;
&lt;br /&gt;
It almost comes as no surprise that the &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.heise.de/newsticker/meldung/83611&#039;);&quot;  href=&quot;http://www.heise.de/newsticker/meldung/83611&quot;  title=&quot;Heise Article about the Gewerkschaft der Polizei&#039;s statement (German only)&quot;&gt;Police Union says that illegal means in investigations are fine to get results&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
What it was all about? Child pornography. Which, according to German Law, is about &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.lawblog.de/index.php/archives/2007/01/12/kinderpornografie-ein-blick-ins-gesetz/&#039;);&quot;  href=&quot;http://www.lawblog.de/index.php/archives/2007/01/12/kinderpornografie-ein-blick-ins-gesetz/&quot;  title=&quot;Udo Vetter, a prominent German Lawyer, shines a light on the severity of Child Pornography in German law (German only)&quot;&gt;in the same category as Wilful Damage to Property&lt;/a&gt; (which would almost be a joke in itself if it wasn&#039;t so sad). The screening of the 20 million German credit cards yielded 322 suspects.&lt;br /&gt;
&lt;br /&gt;
&lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.heise.de/newsticker/meldung/83516&#039;);&quot;  href=&quot;http://www.heise.de/newsticker/meldung/83516&quot;  title=&quot;Heise Article about Udo Vetter suing the District Attorney of Halle (German only)&quot;&gt;Udo Vetter&lt;/a&gt; wants to have a court state if the District Attorney&#039;s action was legal or not. &lt;br /&gt;
&lt;br /&gt;
I&#039;m wondering what our current government will try next. 
    </content:encoded>

    <pubDate>Fri, 12 Jan 2007 12:59:04 +0100</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/483-guid.html</guid>
    <category>bÃ¼rgerrechte</category>
<category>investigations</category>
<category>law enforcement</category>
<category>strafverfolgung</category>
<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>German Government plans a Federal Trojan</title>
    <link>http://blog.balrog.de/archives/482-German-Government-plans-a-Federal-Trojan.html</link>
            <category>local</category>
    
    <comments>http://blog.balrog.de/archives/482-German-Government-plans-a-Federal-Trojan.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=482</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=482</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    The German Federal Government plans to have a Trojan created to &lt;strike&gt;spy on its citizens&lt;/strike&gt; help the law enforcement agencies in their investigations.&lt;br /&gt;
&lt;br /&gt;
Currently the legality of this plan is under scrutiny (the first try to get an &quot;online search&quot; done was stopped as illegal by a judge), but the government is not afraid to tout that they will create the legal grounds for it if necessary.&lt;br /&gt;
&lt;br /&gt;
&lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.heise.de/newsticker/meldung/83538&#039;);&quot;  href=&quot;http://www.heise.de/newsticker/meldung/83538&quot;  title=&quot;Heise article about the trojan (German)&quot;&gt;Heise&lt;/a&gt; has published more information, among them the factoid that two programmers will be hired to write the trojan and that the development should not cost more than 200,000 â‚¬ in total.&lt;br /&gt;
&lt;br /&gt;
The brazenness of this idea is astounding (not to mention dumbfounding) - not to mention that they will have a hard time against people with at least some security skill.&lt;br /&gt;
&lt;br /&gt;
Oh well, it&#039;s always good to see perfectly good tax money go down the drain. 
    </content:encoded>

    <pubDate>Fri, 12 Jan 2007 10:16:43 +0100</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/482-guid.html</guid>
    <category>bundestrojaner</category>
<category>federal trojan</category>
<category>investigations</category>
<category>law enforcement</category>
<category>malware</category>
<category>strafverfolgung</category>
<category>trojan</category>
<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>The Quest to Shutdown A Credit Card Fraud Site</title>
    <link>http://blog.balrog.de/archives/473-The-Quest-to-Shutdown-A-Credit-Card-Fraud-Site.html</link>
            <category>Experiences</category>
            <category>local</category>
    
    <comments>http://blog.balrog.de/archives/473-The-Quest-to-Shutdown-A-Credit-Card-Fraud-Site.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=473</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=473</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    In &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.viruslist.com/de/weblog?weblogid=192362303&#039;);&quot;  href=&quot;http://www.viruslist.com/de/weblog?weblogid=192362303&quot;&gt;Viruslist.com - Analytiker-Tagebuch&lt;/a&gt; (German only) a Kaspersky Labs technician describes how they found a Russian web site hosting data of about 300 credit cards, some with only basic information, some with deluxe information like ATM PIN, email address and phone number of the owner.&lt;br /&gt;
&lt;br /&gt;
Kaspersky labs then called the &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.bka.de/&#039;);&quot;  href=&quot;http://www.bka.de/&quot;&gt;Bundeskriminalamt &lt;/a&gt;, the German Federal police - to no avail. All three people they were named as responsible for this sort of information were already gone for the weekend. The same at the State police authorities. What is really scary is the fact that they didn&#039;t reach anybody from MasterCard or VISA, both. The hotline for lost cards wanted to know the credit card number of the calling party. Ouch.&lt;br /&gt;
&lt;br /&gt;
Well, Kaspersky is not without resources. They finally contacted their US branch office which in turn got in contact with the FBI - and the Russian headquarters took care of shutting the site down.&lt;br /&gt;
&lt;br /&gt;
I&#039;m curious if this experience will change something at the German police institutions. However, I really doubt it. 
    </content:encoded>

    <pubDate>Mon, 07 Aug 2006 12:54:27 +0200</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/473-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>
<item>
    <title>SLAs are news items nowadays</title>
    <link>http://blog.balrog.de/archives/335-SLAs-are-news-items-nowadays.html</link>
            <category>local</category>
    
    <comments>http://blog.balrog.de/archives/335-SLAs-are-news-items-nowadays.html#comments</comments>
    <wfw:comment>http://blog.balrog.de/wfwcomment.php?cid=335</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.balrog.de/rss.php?version=2.0&amp;type=comments&amp;cid=335</wfw:commentRss>
    

    <author>nospam@example.com (Axel Eble)</author>
    <content:encoded>
    &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.heise.de/newsticker/meldung/47079&#039;);&quot;  title=&quot;heise online - Microsoft unterstützt Bundesinnenministerium bei IT-Sicherheit&quot; href=&quot;http://www.heise.de/newsticker/meldung/47079&quot;&gt;Microsoft unterstützt Bundesinnenministerium bei IT-Sicherheit&lt;/a&gt; is a news item stating that Microsoft will support the &lt;a onclick=&quot;javascript: pageTracker._trackPageview(&#039;/extlink/www.bsi.bund.de/&#039;);&quot;  title=&quot;Bundesamt für Sicherheit in der Informationstechnik&quot; href=&quot;http://www.bsi.bund.de/&quot;&gt;&lt;em&gt;Bundesamt für Sicherheit in der Informationstechnik&lt;/em&gt;&lt;/a&gt; (BSI) in securing the operation of critical infrastructure (like TelCo or Electrical Power). The BSI is supposed to help operators of critical infrastructure in securing their information technology equipment.&lt;br /&gt;
&lt;br /&gt;
It does sound like nothing more than a simple SLA about vulnerability information, even more so since they don&#039;t want to publish the nature of the information that Microsoft will share.&lt;br /&gt;
&lt;br /&gt;
Anyone willing to bet that it&#039;s nothing more than a simple information service about vulnerabilities? 
    </content:encoded>

    <pubDate>Mon, 03 May 2004 15:17:19 +0200</pubDate>
    <guid isPermaLink="false">http://blog.balrog.de/archives/335-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license>
</item>

</channel>
</rss>