<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>BruceTonge.Info &#187; Security</title>
	<atom:link href="http://www.brucetonge.info/category/computing/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.brucetonge.info</link>
	<description>It&#039;s not difficult really...</description>
	<lastBuildDate>Thu, 25 Aug 2011 14:18:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>PSN Email</title>
		<link>http://www.brucetonge.info/psn-email/</link>
		<comments>http://www.brucetonge.info/psn-email/#comments</comments>
		<pubDate>Wed, 27 Apr 2011 23:06:33 +0000</pubDate>
		<dc:creator>OKButton</dc:creator>
				<category><![CDATA[Games]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.brucetonge.info/?p=127</guid>
		<description><![CDATA[I have just tonight received the email I have been waiting for from Sony in regard to there PSN &#8220;Outage&#8221;. As you are all probably aware the PSN has been down for a week now and looks like it will be down for at least another week. It would appear that Sony have managed to [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>I have just tonight received the email I have been waiting for from Sony in regard to there PSN &#8220;Outage&#8221;. As you are all probably aware the PSN has been down for a week now and looks like it will be down for at least another week. It would appear that Sony have managed to loose there entire user database to an intruder. the only think they seem to have protected is the security code for credit cards though they are not finished investigating the breach so there is time yet&#8230;</p>
<p>The one thing that has struck me is that they have lost all the users passwords&#8230; Now this is quite alarming in a number of ways. Firstly let me note the two options I see there being for the loss of passwords as described by Sony (which is vague at best):</p>
<p>1. The passwords were stored in the clear (not protected by a hash) and were in the same databases that have been taken. Or.</p>
<p>2.The passwords were stored in a database that was compromised but they were hashed password.</p>
<p>Now if option 2 is the case I can only guess that there is some worry that the hashing method used is not very strong I.E. a known algorithm with no salt. This would be bad but excusable.</p>
<p>I fear however that Sony have kept the passwords in the clear. This is inexcusable. IF this turns out to be the case I dare say the protection of the credit card security codes will be as equally poor.</p>
<p>I will await the full disclosure of this incident before I decide weather to leave the PlayStation platform for good.</p>
<div class="shr-publisher-127"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.brucetonge.info/psn-email/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Getting worried</title>
		<link>http://www.brucetonge.info/getting-worried/</link>
		<comments>http://www.brucetonge.info/getting-worried/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 23:26:20 +0000</pubDate>
		<dc:creator>OKButton</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.brucetonge.info/2010/04/26/getting-worried/</guid>
		<description><![CDATA[I have had a number of new regisers to my wp site in the last few days all with .pl domains the latest had the word spam in ther email address. I am a little worried a wp hack might be coming down the pipe. I think I am going to start dropping a few [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>I have had a number of new regisers to my wp site in the last few days all with .pl domains the latest had the word spam in ther email address. I am a little worried a wp hack might be coming down the pipe. I think I am going to start dropping a few inactive and dubois users this week. If you want to stay post a comment.</p>
<div class="shr-publisher-117"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.brucetonge.info/getting-worried/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security KTN Dead Allready?</title>
		<link>http://www.brucetonge.info/security-ktn-dead-allready/</link>
		<comments>http://www.brucetonge.info/security-ktn-dead-allready/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 22:23:17 +0000</pubDate>
		<dc:creator>OKButton</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.brucetonge.info/2010/01/05/security-ktn-dead-allready/</guid>
		<description><![CDATA[Last year I joined the security knoladge transfer network (KTN). I attended there meeting in Manchester where they set out ther plans to help raise IT security knolage to uk companies and government. It would spear from looking at there site that there grand design has been raines in a lot. Bad news for everyone [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>Last year I joined the security knoladge transfer network (KTN). I attended there meeting in Manchester where they set out ther plans to help raise IT security knolage to uk companies and government. It would spear from looking at there site that there grand design has been raines in a lot. Bad news for everyone and no substitute in sight.</p>
<div class="shr-publisher-104"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.brucetonge.info/security-ktn-dead-allready/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>MacRumours Hacked</title>
		<link>http://www.brucetonge.info/macrumours-hacked/</link>
		<comments>http://www.brucetonge.info/macrumours-hacked/#comments</comments>
		<pubDate>Tue, 06 Jan 2009 17:51:41 +0000</pubDate>
		<dc:creator>OKButton</dc:creator>
				<category><![CDATA[Computing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.brucetonge.info/?p=62</guid>
		<description><![CDATA[The live feed for the MacWorld keynote from MacRumours was hacked today. This hack also took down there regular site. From the text that was in replacement to the keynote info (provided by thoes that had hacked the site) it seems that access to the server controle pannel was hacked allowing access to the hole [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>The live feed for the MacWorld keynote from MacRumours was hacked today. This hack also took down there regular site. From the text that was in replacement to the keynote info (provided by thoes that had hacked the site) it seems that access to the server controle pannel was hacked allowing access to the hole system. It also apeared that more than one hacker had had ago at the system as conversations emerged in the streem. At one point it seemed that other users of the site were also able to contribute as requests to stop were also included in the streem as well as info from other streem providers. Not a good day for MacRumours.</p>
<div class="shr-publisher-62"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.brucetonge.info/macrumours-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yubikey Issues</title>
		<link>http://www.brucetonge.info/yubikey-issues/</link>
		<comments>http://www.brucetonge.info/yubikey-issues/#comments</comments>
		<pubDate>Wed, 14 May 2008 23:10:19 +0000</pubDate>
		<dc:creator>OKButton</dc:creator>
				<category><![CDATA[Computing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.brucetonge.info/?p=41</guid>
		<description><![CDATA[I have ordered my key now will be with me in two weeks so I can have a proper play then. But I have been thinking. This device doesn&#8217;t work if you can just buy one anonymously and create an identity with it and use it for authentication. All it is really good for a [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>I have ordered my key now will be with me in two weeks so I can have a proper play then. But I have been thinking. This device doesn&#8217;t work if you can just buy one anonymously and create an identity with it and use it for authentication. All it is really good for a single user is for adding to existing accounts on systems and using the key as a single authentication device through the central auth system (openID). Other than that the key needs to be issued by a party and tied to there system and issued in a way so that it is securely placed into the hands of the correct owner for multi factor authentication. in this method for each system you need authentication to you would need a separate key ie for access to a bank account with one firm and access to a credit card held by another firm. One key will not do all. What this system needs is a central authentication system that can be trusted to some level. A bit like <span class="a">Thawte did with ssl certs all those years ago.<br />
</span></p>
<div class="shr-publisher-41"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.brucetonge.info/yubikey-issues/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Yubico has got me exited</title>
		<link>http://www.brucetonge.info/yubico-has-got-me-exited/</link>
		<comments>http://www.brucetonge.info/yubico-has-got-me-exited/#comments</comments>
		<pubDate>Sat, 10 May 2008 20:36:30 +0000</pubDate>
		<dc:creator>OKButton</dc:creator>
				<category><![CDATA[Computing]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.brucetonge.info/?p=40</guid>
		<description><![CDATA[Ok I have just herd about the new authentication device from Yubico it is called the Yubikey and it is verry simple it is a usb keyboard in a pen drive that sends a single instance key for authentication anyway I am pressed for time at the mo and this Portugees keyboard is all wrong. [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>Ok I have just herd about the new authentication device from <a href="http://www.yubico.com" title="http://www.yubico.com">Yubico</a> it is called the Yubikey and it is verry simple it is a usb keyboard in a pen drive that sends a single instance key for authentication anyway I am pressed for time at the mo and this Portugees keyboard is all wrong. But the top and the bottom is havea look it is all opensource they just sell the hardware I have bought mine to play with. you should too. I will postmore when I have had a play but read theresite is is verry cool in the way that it works.</p>
<div class="shr-publisher-40"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://www.brucetonge.info/yubico-has-got-me-exited/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

