<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IronWil Blog &#187; Certificates</title>
	<atom:link href="http://ironwil.net/blog/tag/certificates/feed/" rel="self" type="application/rss+xml" />
	<link>http://ironwil.net/blog</link>
	<description>&#34; &#039;Tis better to be silent and be thought a fool, than to speak and remove all doubt.&#34; - Abraham Lincoln</description>
	<lastBuildDate>Tue, 27 Jul 2010 19:24:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>New TWiT NetCasts &#8211; 2009.06.13</title>
		<link>http://ironwil.net/blog/2009/06/13/new-twit-netcasts-2009-06-13/</link>
		<comments>http://ironwil.net/blog/2009/06/13/new-twit-netcasts-2009-06-13/#comments</comments>
		<pubDate>Sat, 13 Jun 2009 14:39:03 +0000</pubDate>
		<dc:creator>Iron Wil</dc:creator>
				<category><![CDATA[Reminder]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[AT&T]]></category>
		<category><![CDATA[Calacanis]]></category>
		<category><![CDATA[Certificates]]></category>
		<category><![CDATA[E3]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Gibson]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[Ihnatko]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[IPV6]]></category>
		<category><![CDATA[Laporte]]></category>
		<category><![CDATA[Lindsay]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[MacBreak]]></category>
		<category><![CDATA[MailBag]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[NetCasts]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Palm]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Thurrott]]></category>
		<category><![CDATA[TWiT]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[WWDC]]></category>
		<category><![CDATA[XP]]></category>

		<guid isPermaLink="false">http://ironwil.net/blog/?p=930</guid>
		<description><![CDATA[TWiT 198: Emission Accomplished Hosts: Leo Laporte, Jeff Cannata, Tom Merritt, Jason Calacanis, and Denise Howell. The Palm Pre, Apple&#8217;s WWDC 2009, voting on advertisements, Bing, E3, Google gets cozy with the White House, and more. Show Notes MacBreak Weekly 144: WWDC Wrap Up Hosts: Leo Laporte, Alex Lindsay, and Andy Ihnatko WWDC report, a [...]]]></description>
			<content:encoded><![CDATA[<p class="title podcast" style="text-align: right;"><strong><a title="TWiT #198" href="http://twit.tv/198" target="_blank">TWiT 198: Emission Accomplished</a></strong></p>
<p style="text-align: right;">Hosts: <a rel="nofollow" href="http://leoville.com/">Leo Laporte</a>, <a rel="nofollow" href="http://jeffcannata.com/">Jeff Cannata</a>, <a rel="nofollow" href="http://www.tommerritt.com/">Tom Merritt</a>, <a rel="nofollow" href="http://mahalo.com/">Jason Calacanis</a>, and <a rel="nofollow" href="http://www.bagandbaggage.com/">Denise Howell</a>.</p>
<p style="text-align: right;">The Palm Pre, Apple&#8217;s WWDC 2009, voting on advertisements, Bing, E3, Google gets cozy with the White House, and more.</p>
<p style="text-align: right;"><a title="TWiT Show Notes" rel="nofollow" href="http://wiki.twit.tv/wiki/TWiT_198" target="_blank">Show Notes</a></p>
<p class="title podcast"><strong><a title="MacBreak Weekly #144" href="http://twit.tv/mbw144" target="_blank">MacBreak Weekly 144: WWDC Wrap Up</a></strong></p>
<p>Hosts: <a rel="nofollow" href="http://leoville.com/">Leo Laporte</a>, <a rel="nofollow" href="http://pixelcorps.tv/">Alex Lindsay</a>, and <a rel="nofollow" href="http://www.cwob.com/">Andy Ihnatko</a></p>
<p>WWDC report, a new iPhone, AT&amp;T, Palm Pre, App Store power, video, voice dialing, compass, and more.</p>
<p><a rel="nofollow" href="http://wiki.twit.tv/wiki/MacBreak_Weekly_144">Show Notes</a></p>
<p style="text-align: right;"><strong><a title="Security Now! #200" href="http://twit.tv/sn200" target="_blank">Security Now 200: Your Questions, Steve&#8217;s Answers 68</a></strong></p>
<p style="text-align: right;">Hosts: <a rel="nofollow" href="http://grc.com/">Steve Gibson</a> with <a rel="nofollow" href="http://leoville.com/">Leo Laporte</a></p>
<p style="text-align: right;">In this mailbag episode we discuss IPv6, Non-VPNs, Microsoft ClickOnce, expired SSL certificates, and more.</p>
<p style="text-align: right;"><a title="Security Now! Show Notes" rel="nofollow" href="http://wiki.twit.tv/wiki/Security_Now_200" target="_blank">Show Notes</a></p>
<h2><a title="Windows Weekly #111" href="http://twit.tv/ww111" target="_blank">Windows Weekly 111: An F.U. To The E.U.</a></h2>
<p>Hosts: <a rel="nofollow" href="http://winsupersite.com/">Paul Thurrott</a> and <a rel="nofollow" href="http://leoville.com/">Leo Laporte</a></p>
<p>Europe getting 7 without IE, Bing is taking off, Morro, Google goes after Exchange, and more.</p>
<p><a title="Windows Weekly Show Notes" href="http://wiki.twit.tv/wiki/Windows_Weekly_111" target="_blank">Show Notes</a></p>
<p style="text-align: right;">iron wil</p>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fironwil.net%2Fblog%2F2009%2F06%2F13%2Fnew-twit-netcasts-2009-06-13%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fironwil.net%2Fblog%2F2009%2F06%2F13%2Fnew-twit-netcasts-2009-06-13%2F" height="61" width="51" /></a></div><p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://ironwil.net/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://ironwil.net/blog/2009/06/13/new-twit-netcasts-2009-06-13/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Now [#181] NetCast</title>
		<link>http://ironwil.net/blog/2009/01/30/security-now-181-netcast/</link>
		<comments>http://ironwil.net/blog/2009/01/30/security-now-181-netcast/#comments</comments>
		<pubDate>Fri, 30 Jan 2009 10:13:21 +0000</pubDate>
		<dc:creator>Iron Wil</dc:creator>
				<category><![CDATA[Article]]></category>
		<category><![CDATA[Certificates]]></category>
		<category><![CDATA[Errata]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[NetCasts]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[QuickTime]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[XP]]></category>
		<category><![CDATA[Yubikey]]></category>

		<guid isPermaLink="false">http://ironwil.net/blog/?p=824</guid>
		<description><![CDATA[Crypto Recap Topics future topic: keyed message authentication code News and Errata Quicktime 7.6 Update for both Mac and Windows, critical, 7 exploits patched illegal iWork &#8217;09 with a trojan that will deeply infect your Mac with a bot net you have options for your windows automatic update, choose the one right for you, make [...]]]></description>
			<content:encoded><![CDATA[<p class="title podcast"><strong>Crypto Recap</strong></p>
<p><span class="mw-headline">Topics </span></p>
<ul>
<li> future topic: keyed message authentication code</li>
</ul>
<p><a name="News_and_Errata"></a></p>
<p><span class="mw-headline"> News and Errata </span></p>
<ul>
<li> Quicktime 7.6 Update for both Mac and Windows, critical, 7 exploits patched</li>
<li> illegal iWork &#8217;09 with a trojan that will deeply infect your Mac with a bot net</li>
<li> you have options for your windows automatic update, choose the one right for you, make sure you are patched</li>
<li> <a class="mw-redirect" title="Yubikey" href="http://wiki.twit.tv/wiki/Yubikey">Yubikey</a>, limited size of password discussed last show, someone wrote in to say longer password is possible</li>
<li> <a class="external free" title="http://cryptolink.com" rel="nofollow" href="http://cryptolink.com/">http://cryptolink.com</a> trademark is in place now</li>
<li> <a class="external free" title="http://My.BarackObama.com" rel="nofollow" href="http://my.barackobama.com/">http://My.BarackObama.com</a> forum, people were putting up trojans</li>
</ul>
<p><a name="Crypto_Recap"></a></p>
<p><span class="mw-headline"> Crypto Recap </span></p>
<p>3.5 year review of all the security pieces that have been talked about</p>
<p>threat model &#8211; what is it we can do?  what are we trying to do?</p>
<p>for example, we assume the endpoints are secure while we try to secure the communication between the two endpoints &#8211; keystroke logger, for example, we can&#8217;t secure against &#8211; if someone gets physical access, we&#8217;re insecure</p>
<p>we assume non-infinite computational power because all of the crypto is subject to brute force attack, no matter how long the key is</p>
<p>&#8220;perfect&#8221; security?  yes, one-time pad &#8211; still isn&#8217;t secure if someone has physical access</p>
<p>much crypto depends on this fact: it is very easy to multiply two big prime numbers together, not easy to factor the result into those two original primes</p>
<p>taking something to a power is easy, taking the log is hard &#8211; also a fundamental assumption of security at present</p>
<p>you want there not to be a single point of failure, even if single communications is cracked, all the rest of the communications should still be secure &#8211; a single shared key is a bad idea for this reason</p>
<p>assume endpoints secure, path inbetween (the internet) totally insecure</p>
<p>what do we mean by security?  in this context where we&#8217;re protecting traffic between two endpoints, we want 3 things:</p>
<ol>
<li> confidentiality, interceptor in the middle cannot read the messages</li>
<li> integrity of message, guard against message being modified</li>
<li> authenticate the endpoints, are we really talking who we think we are?</li>
</ol>
<p>encryption gives confidentiality, symmetric (same key at both ends used to encrypt and decrypt), asymmetric (two different keys used, one to encrypt a random symmetric key that&#8217;s used to encrypt the message, the other to decrypt that symmetric key), key agreement</p>
<p>message integrity, using hashes to create a signature (md5, sha1, etc), a hash is a digest of a much-larger communication, a fingerprint &#8211; any change to the original message will change that fingerprint &#8211; not computationally feasible to make a change to the original message and deliberately produce the same signature &#8211; md5 has been broken in this respect</p>
<dl>
<dd> in a couple of weeks we&#8217;ll talk about keyed digest, giving an authenticated signature, which we don&#8217;t have now </dd>
</dl>
<p>endpoint authentication, certificates and chain of trust anchored to a root authority</p>
<p>get yours <a title="Security Now! #181" href="http://twit.tv/sn181" target="_blank">here</a>.</p>
<p>iron wil</p>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fironwil.net%2Fblog%2F2009%2F01%2F30%2Fsecurity-now-181-netcast%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fironwil.net%2Fblog%2F2009%2F01%2F30%2Fsecurity-now-181-netcast%2F" height="61" width="51" /></a></div><p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://ironwil.net/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://ironwil.net/blog/2009/01/30/security-now-181-netcast/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple Security Update 2008-007</title>
		<link>http://ironwil.net/blog/2008/10/10/apple-security-update-2008-007/</link>
		<comments>http://ironwil.net/blog/2008/10/10/apple-security-update-2008-007/#comments</comments>
		<pubDate>Fri, 10 Oct 2008 18:02:03 +0000</pubDate>
		<dc:creator>Iron Wil</dc:creator>
				<category><![CDATA[Article]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Certificates]]></category>
		<category><![CDATA[ClamAV]]></category>
		<category><![CDATA[Finder]]></category>
		<category><![CDATA[Fix]]></category>
		<category><![CDATA[MySQL Server]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tomcat]]></category>

		<guid isPermaLink="false">http://ironwil.net/blog/?p=632</guid>
		<description><![CDATA[Things that were updated in this patch: Security Update 2008-007 Apache Certificates ClamAV ColorSync CUPS Finder launchd libxslt MySQL Server Networking PHP Postfix PSNormalizer QuickLook rlogin Script Editor Single Sign-On Tomcat vim Weblog Read the details here. iron wil]]></description>
			<content:encoded><![CDATA[<p>Things that were updated in this patch:</p>
<p><span style="text-decoration: underline;">Security Update 2008-007</span></p>
<ul>
<li>Apache</li>
<li>Certificates</li>
<li>ClamAV</li>
<li>ColorSync</li>
<li>CUPS</li>
<li>Finder</li>
<li>launchd</li>
<li>libxslt</li>
<li>MySQL Server</li>
<li>Networking</li>
<li>PHP</li>
<li>Postfix</li>
<li>PSNormalizer</li>
<li>QuickLook</li>
<li>rlogin</li>
<li>Script Editor</li>
<li>Single Sign-On</li>
<li>Tomcat</li>
<li>vim</li>
<li>Weblog</li>
</ul>
<p>Read the details <a title="Security Update 2008-007" href="http://support.apple.com/kb/HT3216" target="_blank">here</a>.</p>
<p>iron wil</p>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fironwil.net%2Fblog%2F2008%2F10%2F10%2Fapple-security-update-2008-007%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fironwil.net%2Fblog%2F2008%2F10%2F10%2Fapple-security-update-2008-007%2F" height="61" width="51" /></a></div><p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://ironwil.net/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://ironwil.net/blog/2008/10/10/apple-security-update-2008-007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.507 seconds -->
