<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>netsekure rng</title>
	<atom:link href="http://netsekure.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://netsekure.org</link>
	<description>random noise generator</description>
	<lastBuildDate>Wed, 17 Feb 2010 21:09:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>TLS Renegotiation MITM fix is now official</title>
		<link>http://netsekure.org/2010/02/tls-renegotiation-mitm-fix-is-now-official/</link>
		<comments>http://netsekure.org/2010/02/tls-renegotiation-mitm-fix-is-now-official/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 21:09:33 +0000</pubDate>
		<dc:creator>Nasko</dc:creator>
				<category><![CDATA[Completely Random]]></category>
		<category><![CDATA[MiTM]]></category>
		<category><![CDATA[renegotiation]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[TLS]]></category>
		<category><![CDATA[TLS1.1]]></category>
		<category><![CDATA[TLS1.2]]></category>

		<guid isPermaLink="false">http://netsekure.org/?p=197</guid>
		<description><![CDATA[As of Feb 12th, the solution for the TLS renegotiation man-in-the-middle attack is an official IETF standard:
http://tools.ietf.org/html/rfc5746
I&#8217;m super happy and excited as this is the first RFC I am a co-author of and it fixes a major problem with one of the most widely used security protocols. Now let&#8217;s hope it will get quickly implemented, [...]]]></description>
		<wfw:commentRss>http://netsekure.org/2010/02/tls-renegotiation-mitm-fix-is-now-official/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TLS renegotiation status update</title>
		<link>http://netsekure.org/2010/02/tls-renegotiation-status-update/</link>
		<comments>http://netsekure.org/2010/02/tls-renegotiation-status-update/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 23:15:17 +0000</pubDate>
		<dc:creator>Nasko</dc:creator>
				<category><![CDATA[Completely Random]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[TLS]]></category>
		<category><![CDATA[TLS1.1]]></category>
		<category><![CDATA[TLS1.2]]></category>

		<guid isPermaLink="false">http://netsekure.org/?p=194</guid>
		<description><![CDATA[It&#8217;s been a while since I last checked any news or used a computer. I was away for more than a month spending time with our new baby daughter and almost completely disconnected from the tubes of the net.
Now that I&#8217;m back, I wanted to point to a patch from Microsoft that allows admins to [...]]]></description>
		<wfw:commentRss>http://netsekure.org/2010/02/tls-renegotiation-status-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TLS Renegotiation Test</title>
		<link>http://netsekure.org/2009/11/tls-renegotiation-test/</link>
		<comments>http://netsekure.org/2009/11/tls-renegotiation-test/#comments</comments>
		<pubDate>Sat, 28 Nov 2009 17:33:59 +0000</pubDate>
		<dc:creator>Nasko</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[man-in-the-middle]]></category>
		<category><![CDATA[MiTM]]></category>
		<category><![CDATA[renegotiation]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[TLS]]></category>
		<category><![CDATA[TLS1.1]]></category>
		<category><![CDATA[TLS1.2]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://netsekure.org/?p=156</guid>
		<description><![CDATA[
 

The new TLS/SSL man-in-the-middle (MiTM) attack targets the renegotiation part of the protocol. There are two variations of the renegotiation &#8211; client initiated and server initiated. This tool allows you to test any web server (input as server:port) for client initiated renegotiation support, as server initiated renegotiation depends on specific server configuration. As currently [...]]]></description>
		<wfw:commentRss>http://netsekure.org/2009/11/tls-renegotiation-test/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>A tale of commercial security product</title>
		<link>http://netsekure.org/2009/11/a-tale-of-commercial-security-product/</link>
		<comments>http://netsekure.org/2009/11/a-tale-of-commercial-security-product/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 16:45:01 +0000</pubDate>
		<dc:creator>Nasko</dc:creator>
				<category><![CDATA[Dossiers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[PGP Desktop]]></category>
		<category><![CDATA[Unsigned installer]]></category>

		<guid isPermaLink="false">http://netsekure.org/?p=124</guid>
		<description><![CDATA[I want to share a story that had me completely puzzled and frustrated. I had to install PGP Desktop for something I’m playing with. I was amazed by PGP (the company) because I thought those guys understand security, the concept of digital signatures, and the crypto area in general. Well, believe it or not I [...]]]></description>
		<wfw:commentRss>http://netsekure.org/2009/11/a-tale-of-commercial-security-product/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TLS 1.2 in Windiows 7</title>
		<link>http://netsekure.org/2009/10/tls-1-2-in-windiows-7/</link>
		<comments>http://netsekure.org/2009/10/tls-1-2-in-windiows-7/#comments</comments>
		<pubDate>Fri, 09 Oct 2009 05:52:34 +0000</pubDate>
		<dc:creator>Nasko</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[TLS]]></category>
		<category><![CDATA[TLS1.1]]></category>
		<category><![CDATA[TLS1.2]]></category>
		<category><![CDATA[Win7]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://netsekure.org/?p=115</guid>
		<description><![CDATA[Windows 7 includes support for TLS 1.1 and TLS 1.2. I&#8217;ve been running with enabled 1.2 support for a while now and no problems at all, so I figured I&#8217;d share how to enable it. You need to import these 4 reg keys:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Client]
"DisabledByDefault"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Server]
"DisabledByDefault"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client]
"DisabledByDefault"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server]
"DisabledByDefault"=dword:00000000
This will allow Win7 to [...]]]></description>
		<wfw:commentRss>http://netsekure.org/2009/10/tls-1-2-in-windiows-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mixed mode content settings for IE and Firefox</title>
		<link>http://netsekure.org/2009/08/mixed-mode-content-settings-for-ie-and-firefox/</link>
		<comments>http://netsekure.org/2009/08/mixed-mode-content-settings-for-ie-and-firefox/#comments</comments>
		<pubDate>Thu, 13 Aug 2009 23:31:09 +0000</pubDate>
		<dc:creator>Nasko</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[CookieMonster]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[ForceHTTPS]]></category>
		<category><![CDATA[http]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[mixed mode content]]></category>

		<guid isPermaLink="false">http://netsekure.org/?p=98</guid>
		<description><![CDATA[I recently installed a plugin for my blog to help with one of the daily tasks I do, only to find out that it is improperly coded, such that it requests resources using HTTP, even though I access my admin section through HTTPS. With all the latest findings on how insecure the web is and [...]]]></description>
		<wfw:commentRss>http://netsekure.org/2009/08/mixed-mode-content-settings-for-ie-and-firefox/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>State of computer security</title>
		<link>http://netsekure.org/2009/07/state-of-computer-security/</link>
		<comments>http://netsekure.org/2009/07/state-of-computer-security/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 22:54:52 +0000</pubDate>
		<dc:creator>Nasko</dc:creator>
				<category><![CDATA[Completely Random]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[weakest link]]></category>

		<guid isPermaLink="false">http://netsekure.org/?p=92</guid>
		<description><![CDATA[In case you haven&#8217;t seen it yet, zf0 summer of hax was released in the last few days. While scanning through the content, I read a paragraph in the &#8220;Industry Check&#8221; section that perfectly sums up the state of computer security these days:
Are you professional types really this out of touch? I see all these [...]]]></description>
		<wfw:commentRss>http://netsekure.org/2009/07/state-of-computer-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>It is important to identify attack vectors</title>
		<link>http://netsekure.org/2009/07/it-is-important-to-identify-attack-vectors/</link>
		<comments>http://netsekure.org/2009/07/it-is-important-to-identify-attack-vectors/#comments</comments>
		<pubDate>Thu, 23 Jul 2009 22:49:09 +0000</pubDate>
		<dc:creator>Nasko</dc:creator>
				<category><![CDATA[Completely Random]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[attack vector]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[passwords]]></category>

		<guid isPermaLink="false">http://netsekure.org/?p=81</guid>
		<description><![CDATA[I recently read a paper on the topic of strong passwords. While going through it, it hit me that very often people will discuss a way of solving some problem (phishing for example), but they fail to enumerate what the attack vectors are and subsequently how the solution addresses these attack vectors. I like how [...]]]></description>
		<wfw:commentRss>http://netsekure.org/2009/07/it-is-important-to-identify-attack-vectors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secret questions?</title>
		<link>http://netsekure.org/2009/07/secret-questions/</link>
		<comments>http://netsekure.org/2009/07/secret-questions/#comments</comments>
		<pubDate>Thu, 16 Jul 2009 17:09:59 +0000</pubDate>
		<dc:creator>Nasko</dc:creator>
				<category><![CDATA[Completely Random]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[secret questions]]></category>

		<guid isPermaLink="false">http://netsekure.org/?p=84</guid>
		<description><![CDATA[The recent story on the twitter breach of company information reminded me of an interesting research I recently saw. A few researchers have worked with real people to gather data how well security questions used by online apps work. Their paper has all the glory details,but there are two things that stood out to me:

secret [...]]]></description>
		<wfw:commentRss>http://netsekure.org/2009/07/secret-questions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Slow TLS performance with ISA</title>
		<link>http://netsekure.org/2009/06/tls-and-isa/</link>
		<comments>http://netsekure.org/2009/06/tls-and-isa/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 16:19:54 +0000</pubDate>
		<dc:creator>Nasko</dc:creator>
				<category><![CDATA[Dossiers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Client Authentication]]></category>
		<category><![CDATA[ISA]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[TLS]]></category>
		<category><![CDATA[Windows Authentication]]></category>

		<guid isPermaLink="false">http://netsekure.org/?p=72</guid>
		<description><![CDATA[A case of troubleshooting slow page loading over SSL/TLS through an ISA server.]]></description>
		<wfw:commentRss>http://netsekure.org/2009/06/tls-and-isa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
