<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>I Am Security &#187; web2.0</title>
	<atom:link href="http://www.iamit.org/blog/tag/web2-0/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.iamit.org/blog</link>
	<description>Security news and research</description>
	<lastBuildDate>Mon, 26 Jul 2010 09:20:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
<cloud domain='www.iamit.org' port='80' path='/blog/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>AHA! A blast from the past&#8230;</title>
		<link>http://www.iamit.org/blog/2009/12/aha-a-blast-from-the-past/</link>
		<comments>http://www.iamit.org/blog/2009/12/aha-a-blast-from-the-past/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 06:33:19 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[predictions]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[web2.0]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=389</guid>
		<description><![CDATA[I just ran across this great blog post from Lori MacVittie at Web2.0 Journal. Can&#8217;t say exactly why it sparked my interest, but after reading it I realized this may be Freudian&#8230; The proposed Anonymous Human Authentication (AHA &#8211; great acronym Lori!) proposed in it closely resembles a technology we worked on back in the days [...]


Related posts:<ol><li><a href='http://www.iamit.org/blog/2009/09/two-steps-forward-one-step-back-controling-botnets/' rel='bookmark' title='Permanent Link: Two steps forward, one step back &#8211; controling botnets&#8230;'>Two steps forward, one step back &#8211; controling botnets&#8230;</a></li>
<li><a href='http://www.iamit.org/blog/2010/06/identity-crisis/' rel='bookmark' title='Permanent Link: Identity crisis'>Identity crisis</a></li>
<li><a href='http://www.iamit.org/blog/2009/10/clouds-and-the-winds-that-blows-them-away/' rel='bookmark' title='Permanent Link: Clouds, and the winds that blows them away&#8230;'>Clouds, and the winds that blows them away&#8230;</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>I just ran across this great <a href="http://web2.sys-con.com/node/1204447">blog post</a> from Lori MacVittie at Web2.0 Journal. Can&#8217;t say exactly why it sparked my interest, but after reading it I realized this may be Freudian&#8230; The proposed Anonymous Human Authentication (AHA &#8211; great acronym Lori!) proposed in it closely resembles a technology we worked on back in the days of BeeFence.</p>
<p>I&#8217;m not putting any links to BeeFence since it was a startup I had the honor to be one of the founders of (which obviously went down the road of many other startups&#8230;), but the neat thing about it was the technology (did I mention I was the CTO <img src='http://www.iamit.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  ). Basically &#8211; we had what we called &#8220;Active Validation&#8221; (or sometimes &#8220;Interrogation&#8221;) of sessions. We generalized it a bit more to cover additional protocols rather than just focus on Web2.0 (think what it can do to the NIDS/IPS world&#8230;).</p>
<p>Makes me think of getting back on the startup bandwagon, although I&#8217;d have to make some sense out of the drawer-full of ideas I&#8217;ve been filling over the past few years having been engaged in web security and cloud security recently&#8230; you never know <img src='http://www.iamit.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2009/09/two-steps-forward-one-step-back-controling-botnets/' rel='bookmark' title='Permanent Link: Two steps forward, one step back &#8211; controling botnets&#8230;'>Two steps forward, one step back &#8211; controling botnets&#8230;</a></li>
<li><a href='http://www.iamit.org/blog/2010/06/identity-crisis/' rel='bookmark' title='Permanent Link: Identity crisis'>Identity crisis</a></li>
<li><a href='http://www.iamit.org/blog/2009/10/clouds-and-the-winds-that-blows-them-away/' rel='bookmark' title='Permanent Link: Clouds, and the winds that blows them away&#8230;'>Clouds, and the winds that blows them away&#8230;</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2009/12/aha-a-blast-from-the-past/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Two steps forward, one step back &#8211; controling botnets&#8230;</title>
		<link>http://www.iamit.org/blog/2009/09/two-steps-forward-one-step-back-controling-botnets/</link>
		<comments>http://www.iamit.org/blog/2009/09/two-steps-forward-one-step-back-controling-botnets/#comments</comments>
		<pubDate>Sun, 13 Sep 2009 15:12:48 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[eCrime]]></category>
		<category><![CDATA[predictions]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[web2.0]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=364</guid>
		<description><![CDATA[Botnet communication using newsgroups is old news as web2.0 twitter and blog channels have been used for a long time.


Related posts:<ol><li><a href='http://www.iamit.org/blog/2009/12/aha-a-blast-from-the-past/' rel='bookmark' title='Permanent Link: AHA! A blast from the past&#8230;'>AHA! A blast from the past&#8230;</a></li>
<li><a href='http://www.iamit.org/blog/2009/06/getting-a-business-degree-as-part-of-security-research/' rel='bookmark' title='Permanent Link: Getting a business degree as part of Security Research?'>Getting a business degree as part of Security Research?</a></li>
<li><a href='http://www.iamit.org/blog/2010/06/identity-crisis/' rel='bookmark' title='Permanent Link: Identity crisis'>Identity crisis</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Just stumbled across this: <a href="http://www.symantec.com/connect/blogs/google-groups-trojan">http://www.symantec.com/connect/blogs/google-groups-trojan</a> &#8211; basically, botnets are utilizing Google groups (could have been any other mailing list system for the sake of argument) to communicate between the bots (trojans) and their command and control centers.</p>
<p>Funny how technology sometimes is way simpler than you imagine it would be. As per the new twitter based botnet channels, and the fancy web2.0 communications that are available for usage (see older post at <a href="http://www.iamit.org/blog/2009/08/botnet-communications-moving-to-web2-0/">here</a>), utilizing the age-old mechanism of anonymously posing messages on a newsgroup is humbling.</p>
<p>Nevertheless, it&#8217;s the same new story (Google groups were chosen because of the web interface and the uptime reputation), just dressed up in old clothes (pun intended&#8230;). The same advice that I gave 2 years ago, which I gave last year, and again 3 months ago, is still valid &#8211; forget about putting out fires (that&#8217;s your off-the-shelf AV). Focus on proper mitigation, a solution that shows you how the technology is an extension of the company&#8217;s research, and forward thinking attitude. Look for solutions that are more behavioral in nature in order to identify mal-intent communications, and act proactively based on the predictions and research done.</p>
<p>Basically &#8211; don&#8217;t settle for mediocracy!</p>
<p>Stay safe.</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2009/12/aha-a-blast-from-the-past/' rel='bookmark' title='Permanent Link: AHA! A blast from the past&#8230;'>AHA! A blast from the past&#8230;</a></li>
<li><a href='http://www.iamit.org/blog/2009/06/getting-a-business-degree-as-part-of-security-research/' rel='bookmark' title='Permanent Link: Getting a business degree as part of Security Research?'>Getting a business degree as part of Security Research?</a></li>
<li><a href='http://www.iamit.org/blog/2010/06/identity-crisis/' rel='bookmark' title='Permanent Link: Identity crisis'>Identity crisis</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2009/09/two-steps-forward-one-step-back-controling-botnets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Drawing the line &#8211; securing an organization while thinking of users&#8230;</title>
		<link>http://www.iamit.org/blog/2009/09/drawing-the-line-securing-an-organization-while-thinking-of-users/</link>
		<comments>http://www.iamit.org/blog/2009/09/drawing-the-line-securing-an-organization-while-thinking-of-users/#comments</comments>
		<pubDate>Mon, 07 Sep 2009 16:36:28 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[online banking]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security policy]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[web2.0]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=362</guid>
		<description><![CDATA[Securing sensitive organizational information where end-users that are not part of the organization need access to such said data and may even modify it.


Related posts:<ol><li><a href='http://www.iamit.org/blog/2009/07/practical-vs-regulatory-the-votes-are-in/' rel='bookmark' title='Permanent Link: Practical vs. Regulatory &#8211; the votes are in!'>Practical vs. Regulatory &#8211; the votes are in!</a></li>
<li><a href='http://www.iamit.org/blog/2010/06/identity-crisis/' rel='bookmark' title='Permanent Link: Identity crisis'>Identity crisis</a></li>
<li><a href='http://www.iamit.org/blog/2009/10/clouds-and-the-winds-that-blows-them-away/' rel='bookmark' title='Permanent Link: Clouds, and the winds that blows them away&#8230;'>Clouds, and the winds that blows them away&#8230;</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>My latest post on the Israeli Insurance Association (<a href="http://www.igudbit.org.il/Index.asp?ArticleID=1235&amp;CategoryID=98">http://www.igudbit.org.il/Index.asp?ArticleID=1235&amp;CategoryID=98</a> [HEBREW]) discusses the challanges of managing risk in a complex organizational environment where you have to take into account end-users meddling with data.</p>
<p>In Israel, insurance agencies are not yet at the stage where they provide full access to insured parties online to their insurance and policy information, but should be getting ready to do so. Some of the considerations and implications of creating the infrastructure for such access is discussed in the article in light of the risk management requirements set forth by regulation for such organizations. Financial institutions have been facing the same issues for years now since online banking have become a standard so it&#8217;s a great opportunity to reexamine what policies are applicable and what technologies can be used to enforce them in a very similar environment.</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2009/07/practical-vs-regulatory-the-votes-are-in/' rel='bookmark' title='Permanent Link: Practical vs. Regulatory &#8211; the votes are in!'>Practical vs. Regulatory &#8211; the votes are in!</a></li>
<li><a href='http://www.iamit.org/blog/2010/06/identity-crisis/' rel='bookmark' title='Permanent Link: Identity crisis'>Identity crisis</a></li>
<li><a href='http://www.iamit.org/blog/2009/10/clouds-and-the-winds-that-blows-them-away/' rel='bookmark' title='Permanent Link: Clouds, and the winds that blows them away&#8230;'>Clouds, and the winds that blows them away&#8230;</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2009/09/drawing-the-line-securing-an-organization-while-thinking-of-users/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
