<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>martinmurphy.com - Martin Murphy &#187; Security</title>
	<atom:link href="http://martinmurphy.com/blog/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://martinmurphy.com/blog</link>
	<description>Martin Murphy's Weblog</description>
	<lastBuildDate>Thu, 25 Feb 2010 20:48:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Can you crack a code?</title>
		<link>http://martinmurphy.com/blog/2009/01/05/76-can-you-crack-a-code/</link>
		<comments>http://martinmurphy.com/blog/2009/01/05/76-can-you-crack-a-code/#comments</comments>
		<pubDate>Mon, 05 Jan 2009 23:50:00 +0000</pubDate>
		<dc:creator>Martin Murphy</dc:creator>
				<category><![CDATA[Blogs]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://martinmurphy.com/blog/?p=76</guid>
		<description><![CDATA[Saw this on Bruce Schneier&#8217;s blog, it&#8217;s the FBI&#8217;s Dec 2008 cryptanalysis problem. Can you crack a code? Good fun.]]></description>
			<content:encoded><![CDATA[<p>Saw this on <a href="http://www.schneier.com/blog/archives/2009/01/fbis_new_crypta.html">Bruce Schneier&#8217;s blog</a>, it&#8217;s the FBI&#8217;s Dec 2008 cryptanalysis problem. <a href='http://www.fbi.gov/page2/dec08/code_122908.html'>Can you crack a code?</a></p>
<p>Good fun.</p>
]]></content:encoded>
			<wfw:commentRss>http://martinmurphy.com/blog/2009/01/05/76-can-you-crack-a-code/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSH updates</title>
		<link>http://martinmurphy.com/blog/2007/08/03/62-ssh-updates/</link>
		<comments>http://martinmurphy.com/blog/2007/08/03/62-ssh-updates/#comments</comments>
		<pubDate>Fri, 03 Aug 2007 12:33:22 +0000</pubDate>
		<dc:creator>Martin Murphy</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://martinmurphy.com/blog/2007/08/03/62-ssh-updates/</guid>
		<description><![CDATA[The Past: I&#8217;m a long-time user of SSH. I presume that I was typical in my initial use of it for secure access to remote servers. But I quickly became familiar with its port-forwarding capabilities, and have often set up intricate webs of connected and nested tunnels, in order to negotiate the problems of multiple [...]]]></description>
			<content:encoded><![CDATA[<p><strong>The Past:</strong><br />
I&#8217;m a long-time user of SSH.  I presume that I was typical in my initial use of it for secure access to remote servers.  But I quickly became familiar with its port-forwarding capabilities, and have often set up intricate webs of connected and nested tunnels, in order to negotiate the problems of multiple NAT servers and firewalls.  I even considered myself a power-user.</p>
<p><strong>The Present:</strong><br />
Today, while checking out <a href="http://www.theregister.com/2007/08/01/defcon_survival_guide/">A Defcon survival guide on The Register</a>, I noticed that they had mentioned the <code>-D</code> parameter to SSH.  It was that kind of &#8220;in-passing&#8221; reference, where you know they think they&#8217;re stating the obvious.  You&#8217;ve probably guessed though, that it was not obvious to me.<br />
Enter the <a href="https://help.ubuntu.com/community/SSHHowto">Ubuntu SSH Howto</a>, and in particular the &#8220;SSH as a Proxy&#8221; section.  How could I not know that a SSH could run as a SOCKS proxy, tunnelled to a remote server?  Now I&#8217;ll be able to run SOCKS capable client applications (including web browsers) across lots of network configurations, without having to identify and forward individual ports.  Brilliant!</p>
<p><strong>The Future:</strong><br />
Wait, what&#8217;s that I see? At the bottom of the page there&#8217;s a link to <a href="https://help.ubuntu.com/community/SSH_VPN">SSH VPN</a>. It can&#8217;t be.  Not full networking access (routing,UDP,etc) over an SSH tunnel using the &#8220;tun&#8221; driver.  Yes it is, it&#8217;s amazing.  I can&#8217;t try this one out at the moment, but it will be a definite must-have for me (very soon).<br />
Anywhere, on any network, once I have SSH access, I can get full access to my home network. (Or, if I wanted, an <a href="http://www.amazon.com/gp/browse.html?node=201590011">Amazon EC2</a> node that I could start when I needed full Internet access)</p>
<p>What lessons I&#8217;ve learned today, and not just about SSH.  It&#8217;s important to check out the features and updates of software and networking tools that you use.  Especially, if you already consider them important and useful.  Don&#8217;t fall into the trap of thinking you already know how to use them, even if, like me, you&#8217;ve been using the tools for too many years to remember.</p>
<p>Now, I&#8217;ve also been using Ethereal for a long time, but a colleague has recommended <a href="http://www.wireshark.org/">WireShark</a>, I must find out which one is better <img src='http://martinmurphy.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://martinmurphy.com/blog/2007/08/03/62-ssh-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RFID being tapped to stifle exam cheaters</title>
		<link>http://martinmurphy.com/blog/2007/05/14/50-rfid-being-tapped-to-stifle-exam-cheaters/</link>
		<comments>http://martinmurphy.com/blog/2007/05/14/50-rfid-being-tapped-to-stifle-exam-cheaters/#comments</comments>
		<pubDate>Mon, 14 May 2007 09:45:05 +0000</pubDate>
		<dc:creator>Martin Murphy</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://martinmurphy.com/blog/2007/05/14/50-rfid-being-tapped-to-stifle-exam-cheaters/</guid>
		<description><![CDATA[Not convinced about the usefulness of this RFID application, reported on Ars Technica: RFID being tapped to stifle exam cheaters Given that this only seems to be used to check if all the exam papers are still in the package. Surely, someone could count them? Also, it doesn&#8217;t seem to account for the fact that [...]]]></description>
			<content:encoded><![CDATA[<p>Not convinced about the usefulness of this RFID application, reported on Ars Technica: <a href="http://arstechnica.com/news.ars/post/20070513-rfid-being-tapped-to-stifle-exam-cheaters.html">RFID being tapped to stifle exam cheaters</a></p>
<p>Given that this only seems to be used to check if all the exam papers are still in the package. Surely, someone could count them?  Also, it doesn&#8217;t seem to account for the fact that whoever might steal the papers, may now just photograph/photocopy them instead.</p>
<p>On the other hand using statistical analysis to flag particular answer papers for further investigation seems reasonable but it doesn&#8217;t prove that someone has cheated.</p>
]]></content:encoded>
			<wfw:commentRss>http://martinmurphy.com/blog/2007/05/14/50-rfid-being-tapped-to-stifle-exam-cheaters/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My voice is my passport</title>
		<link>http://martinmurphy.com/blog/2007/05/14/49-my-voice-is-my-passport/</link>
		<comments>http://martinmurphy.com/blog/2007/05/14/49-my-voice-is-my-passport/#comments</comments>
		<pubDate>Mon, 14 May 2007 09:37:00 +0000</pubDate>
		<dc:creator>Martin Murphy</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[Positioning]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://martinmurphy.com/blog/2007/05/14/49-my-voice-is-my-passport/</guid>
		<description><![CDATA[Wow, this is the second movie reference in 2 posts. You may have guessed that I&#8217;m interested in security and alternative computer input/output systems. This morning, I saw this post &#8220;Voice biometrics: coming to a security system near you.&#8221; about banks using voice print technology. Interesting discussion about using voice to combine 2 id methods, [...]]]></description>
			<content:encoded><![CDATA[<p>Wow, this is the second <a href="http://imdb.com/title/tt0105435/">movie reference</a> in 2 posts.</p>
<p>You may have guessed that I&#8217;m interested in security and alternative computer input/output systems.  This morning, I saw this post &#8220;<a href="http://arstechnica.com/articles/culture/voice-biometrics-come-of-age.ars">Voice biometrics: coming to a security system near you.</a>&#8221; about banks using voice print technology.<br />
Interesting discussion about using voice to combine 2 id methods, something you have: voiceprint, and something your know: security question.  The usual concerns about &#8220;Big Brother&#8221; are also mentioned.</p>
<p>Humorous, even if not politically correct, referring to some users as &#8220;goats&#8221; <img src='http://martinmurphy.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://martinmurphy.com/blog/2007/05/14/49-my-voice-is-my-passport/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Eyeball-tracking camera could change real-world ads</title>
		<link>http://martinmurphy.com/blog/2007/05/11/48-eyeball-tracking-camera-could-change-real-world-ads/</link>
		<comments>http://martinmurphy.com/blog/2007/05/11/48-eyeball-tracking-camera-could-change-real-world-ads/#comments</comments>
		<pubDate>Fri, 11 May 2007 10:12:46 +0000</pubDate>
		<dc:creator>Martin Murphy</dc:creator>
				<category><![CDATA[Positioning]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://martinmurphy.com/blog/2007/05/11/48-eyeball-tracking-camera-could-change-real-world-ads/</guid>
		<description><![CDATA[Interesting story about a camera that can count eyes. They suggest that it might be used by advertising companies to count the numbers of eyes that have looked at particular ads. Eyeball-tracking camera could change real-world ads Getting closer to the ads in &#8220;Minority Report&#8221; This might be interesting for anyone researching computer vision or [...]]]></description>
			<content:encoded><![CDATA[<p>Interesting story about a camera that can count eyes.  They suggest that it might be used by advertising companies to count the numbers of eyes that have looked at particular ads. <a href="http://arstechnica.com/news.ars/post/20070510-eyeball-tracking-camera-could-change-real-world-ads.html">Eyeball-tracking camera could change real-world ads</a><br />
Getting closer to the ads in <a href="http://imdb.com/title/tt0181689/">&#8220;Minority Report&#8221;</a><br />
This might be interesting for anyone researching computer vision or pervasive and ubiquitous computing.</p>
]]></content:encoded>
			<wfw:commentRss>http://martinmurphy.com/blog/2007/05/11/48-eyeball-tracking-camera-could-change-real-world-ads/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;lsof&#8221; command</title>
		<link>http://martinmurphy.com/blog/2007/04/18/43-lsof-command/</link>
		<comments>http://martinmurphy.com/blog/2007/04/18/43-lsof-command/#comments</comments>
		<pubDate>Wed, 18 Apr 2007 15:31:58 +0000</pubDate>
		<dc:creator>Martin Murphy</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://martinmurphy.com/blog/2007/04/18/43-lsof-command/</guid>
		<description><![CDATA[Just found out about this command today. &#8220;lsof&#8221; displays information about open files by processes on *nix systems (including network &#8220;files&#8221; &#8211; TCP/UDP). I don&#8217;t know how I managed to miss such a useful command over the years. As an example, listing network ports (which I would previously have done with netstat): # lsof +c0 [...]]]></description>
			<content:encoded><![CDATA[<p>Just found out about this command today.</p>
<p>&#8220;lsof&#8221; displays  information about open files by processes on *nix systems (including network &#8220;files&#8221; &#8211; TCP/UDP). I don&#8217;t know how I managed to miss such a useful command over the years.</p>
<p>As an example, listing network ports (which I would previously have done with netstat):</p>
<pre>
# lsof +c0 -n | grep IP 

java             1022    martinm   28u     IPv6
          467902                 TCP 192.168.2.104:51769->192.168.10.1:xmpp-client (ESTABLISHED)
java             2961    martinm    6u     IPv6
          322274                 TCP *:8083 (LISTEN)
evolution        6408    martinm   59u     IPv6
          472527                 TCP [fffe:111:11:2:111:72ff:fe10:2bd]:51943->[fffe:111:11:1::11]:imaps (ESTABLISHED)
mysql           18407    martinm    3u     IPv4
          489375                 TCP 192.168.2.104:49021->192.168.2.146:mysql (ESTABLISHED)
firefox-bin     24396    martinm   52u     IPv4
          490170                 TCP 192.168.2.104:52906->192.168.0.1:webcache (ESTABLISHED)
</pre>
<p><em>I added linebreaks to make it more readable</em><br />
As usual, further information is available with <code>man lsof</code>.<br />
Now I&#8217;ll just need to find out a way of setting the command to be the Java Start Class to identify which java program has the port open.</p>
<p><strong>Update:</strong> the number after the command is the PID so a <code>ps -fp<em>XXXX</em></code> will show the comamnd line.</p>
]]></content:encoded>
			<wfw:commentRss>http://martinmurphy.com/blog/2007/04/18/43-lsof-command/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>With desktop camera, your face can be your password &#124; CNET News.com</title>
		<link>http://martinmurphy.com/blog/2007/03/29/39-with-desktop-camera-your-face-can-be-your-password-cnet-newscom/</link>
		<comments>http://martinmurphy.com/blog/2007/03/29/39-with-desktop-camera-your-face-can-be-your-password-cnet-newscom/#comments</comments>
		<pubDate>Thu, 29 Mar 2007 13:55:37 +0000</pubDate>
		<dc:creator>Martin Murphy</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[Positioning]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://martinmurphy.com/blog/2007/03/29/39-with-desktop-camera-your-face-can-be-your-password-cnet-newscom/</guid>
		<description><![CDATA[Just noticed this story (via a link from LifeHacker) With desktop camera, your face can be your password &#124; CNET News.com The company produces a 3D desktop camera that can be used for authentication. So instead of entering a password, smartcard or fingerprint, your face can log you into a computer (or open a door). [...]]]></description>
			<content:encoded><![CDATA[<p>Just noticed this story (via a link from <a title="LifeHacker" target="_blank" href="http://www.lifehacker.com/software/news/daily-news-roundup-248021.php">LifeHacker</a>)</p>
<p><a href="http://news.com.com/2100-1029_3-6171383.html?part=rss&#038;tag=2547-1_3-0-20&#038;subj=news">With desktop camera, your face can be your password | CNET News.com</a></p>
<p>The company produces a 3D desktop camera that can be used for authentication.  So instead of entering a password, smartcard or fingerprint, your face can log you into a computer (or open a door).  Interesting for anyone working in the field of computer vision.</p>
]]></content:encoded>
			<wfw:commentRss>http://martinmurphy.com/blog/2007/03/29/39-with-desktop-camera-your-face-can-be-your-password-cnet-newscom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Lockdown: Locked, but not secure &#8211; Engadget</title>
		<link>http://martinmurphy.com/blog/2006/12/01/19-the-lockdown-locked-but-not-secure-engadget/</link>
		<comments>http://martinmurphy.com/blog/2006/12/01/19-the-lockdown-locked-but-not-secure-engadget/#comments</comments>
		<pubDate>Fri, 01 Dec 2006 12:54:59 +0000</pubDate>
		<dc:creator>Martin Murphy</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://martinmurphy.com/blog/2006/12/01/19-the-lockdown-locked-but-not-secure-engadget/</guid>
		<description><![CDATA[Just noticed this on Engadget. It&#8217;s a discussion about the security of doorlocks, it will need further investigation on my part. The Lockdown: Locked, but maybe secure (part 1) refers to the previous articles: The Lockdown: Locked, but not secure (Part I) &#8211; Engadget The Lockdown: Locked, but not secure (Part II) &#8211; Engadget]]></description>
			<content:encoded><![CDATA[<p>Just noticed this on Engadget. It&#8217;s a discussion about the security of doorlocks, it will need further investigation on my part.<br />
<a href="http://www.engadget.com/2006/11/30/the-lockdown-locked-but-maybe-secure-part-1/">The Lockdown: Locked, but maybe secure (part 1)</a></p>
<p>refers to the previous articles:</p>
<p><a href="http://www.engadget.com/2006/08/24/the-lockdown-locked-but-not-secure-part-i/">The Lockdown: Locked, but not secure (Part I) &#8211; Engadget</a></p>
<p><a href="http://www.engadget.com/2006/08/24/the-lockdown-locked-but-not-secure-part-2/">The Lockdown: Locked, but not secure (Part II) &#8211; Engadget</a></p>
]]></content:encoded>
			<wfw:commentRss>http://martinmurphy.com/blog/2006/12/01/19-the-lockdown-locked-but-not-secure-engadget/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
