<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Playhouse of privacy, security, hacking, encryption, intelligence and some business stuff</title>
	<atom:link href="http://infosecurity.ch/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecurity.ch</link>
	<description></description>
	<lastBuildDate>Mon, 27 Jun 2011 17:44:37 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2</generator>
	<item>
		<title>Comment on TETRA hacking is coming: OsmocomTETRA by Henrik</title>
		<link>http://infosecurity.ch/20110123/tetra-hacking-is-coming-osmocomtetra/comment-page-1/#comment-318</link>
		<dc:creator>Henrik</dc:creator>
		<pubDate>Mon, 27 Jun 2011 17:44:37 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20110123/tetra-hacking-is-coming-osmocomtetra/#comment-318</guid>
		<description>I hope i can listen to Swedish Police soooon :)</description>
		<content:encoded><![CDATA[<p>I hope i can listen to Swedish Police soooon :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Not every elliptic curve is the same: trough on ECC security by Mathias Brossard</title>
		<link>http://infosecurity.ch/20100926/not-every-elliptic-curve-is-the-same-trough-on-ecc-security/comment-page-1/#comment-316</link>
		<dc:creator>Mathias Brossard</dc:creator>
		<pubDate>Thu, 26 May 2011 09:46:04 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100926/not-every-elliptic-curve-is-the-same-trough-on-ecc-security/#comment-316</guid>
		<description>After looking at RFC5639 and the Brainpool site, I&#039;m quite sure the Brainpool P-curves are not the same than SECG, X9.62, NIST. They&#039;re using a very similar methodology, but chose to generate new curves using the same sizes (except for 512 bits instead of 521 bits). They cite improved security, using a value for &#039;p&#039; that has no special form (to avoid patented fast arithmetic) and a general distrust of NIST curves (not explicitly said) that have no explanation for the different seeds used.</description>
		<content:encoded><![CDATA[<p>After looking at RFC5639 and the Brainpool site, I&#8217;m quite sure the Brainpool P-curves are not the same than SECG, X9.62, NIST. They&#8217;re using a very similar methodology, but chose to generate new curves using the same sizes (except for 512 bits instead of 521 bits). They cite improved security, using a value for &#8216;p&#8217; that has no special form (to avoid patented fast arithmetic) and a general distrust of NIST curves (not explicitly said) that have no explanation for the different seeds used.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on RFC 6189: ZRTP is finally a standard! by test</title>
		<link>http://infosecurity.ch/20110411/rfc-6189-zrtp-is-finally-a-standard/comment-page-1/#comment-314</link>
		<dc:creator>test</dc:creator>
		<pubDate>Sun, 15 May 2011 16:00:07 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20110411/rfc-6189-zrtp-is-finally-a-standard/#comment-314</guid>
		<description>test comment</description>
		<content:encoded><![CDATA[<p>test comment</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PrivateGSM: Blackberry/iPhone/Nokia mobile voice encryption with ZRTP or SRTP/SDES by Interested user</title>
		<link>http://infosecurity.ch/20101019/privategsm-blackberryiphonenokia-mobile-voice-encryption-with-zrtp-or-srtpsdes/comment-page-1/#comment-262</link>
		<dc:creator>Interested user</dc:creator>
		<pubDate>Thu, 20 Jan 2011 09:00:56 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20101019/privategsm-blackberryiphonenokia-mobile-voice-encryption-with-zrtp-or-srtpsdes/#comment-262</guid>
		<description>You should add your client to the list at
http://en.wikipedia.org/wiki/Comparison_of_VoIP_software#Mobile_phones

Unfortunately, 800 EUR per year is too expensive for private use...</description>
		<content:encoded><![CDATA[<p>You should add your client to the list at<br />
<a href="http://en.wikipedia.org/wiki/Comparison_of_VoIP_software#Mobile_phones" rel="nofollow">http://en.wikipedia.org/wiki/Comparison_of_VoIP_software#Mobile_phones</a></p>
<p>Unfortunately, 800 EUR per year is too expensive for private use&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Not every elliptic curve is the same: trough on ECC security by Ian Simmons</title>
		<link>http://infosecurity.ch/20100926/not-every-elliptic-curve-is-the-same-trough-on-ecc-security/comment-page-1/#comment-241</link>
		<dc:creator>Ian Simmons</dc:creator>
		<pubDate>Tue, 26 Oct 2010 23:57:14 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100926/not-every-elliptic-curve-is-the-same-trough-on-ecc-security/#comment-241</guid>
		<description>I believe there is a flaw in this article. ECC Brainpool specifies an ECC FP 512-bit key not 521-bit. See RFC5639 section 2.2. Technical Requirements bullet 1.</description>
		<content:encoded><![CDATA[<p>I believe there is a flaw in this article. ECC Brainpool specifies an ECC FP 512-bit key not 521-bit. See RFC5639 section 2.2. Technical Requirements bullet 1.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Not every elliptic curve is the same: trough on ECC security by badmash</title>
		<link>http://infosecurity.ch/20100926/not-every-elliptic-curve-is-the-same-trough-on-ecc-security/comment-page-1/#comment-235</link>
		<dc:creator>badmash</dc:creator>
		<pubDate>Sat, 23 Oct 2010 11:32:53 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100926/not-every-elliptic-curve-is-the-same-trough-on-ecc-security/#comment-235</guid>
		<description>&lt;p&gt;I just signed up to your blogs rss feed. Will you post more on this subject?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I just signed up to your blogs rss feed. Will you post more on this subject?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Blackberry Security and Encryption: Devil or Angel? by naif</title>
		<link>http://infosecurity.ch/20100707/blackberry-security-and-encryption-devil-or-angel/comment-page-1/#comment-196</link>
		<dc:creator>naif</dc:creator>
		<pubDate>Thu, 12 Aug 2010 15:47:15 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100707/blackberry-security-and-encryption-devil-or-angel/#comment-196</guid>
		<description>&lt;p&gt;Nice article from Forbes about RIM and Government Monitoring.&lt;/p&gt;

&lt;p&gt;A Deductive Proof about RIM and Government Monitoring (Forbes): http://bit.ly/cWnNPw&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Nice article from Forbes about RIM and Government Monitoring.</p>
<p>A Deductive Proof about RIM and Government Monitoring (Forbes): <a href="http://bit.ly/cWnNPw" rel="nofollow">http://bit.ly/cWnNPw</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Blackberry Security and Encryption: Devil or Angel? by naif</title>
		<link>http://infosecurity.ch/20100707/blackberry-security-and-encryption-devil-or-angel/comment-page-1/#comment-195</link>
		<dc:creator>naif</dc:creator>
		<pubDate>Wed, 11 Aug 2010 21:09:07 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100707/blackberry-security-and-encryption-devil-or-angel/#comment-195</guid>
		<description>&lt;p&gt;There&#039;s an article on recent blackberry security issues.&lt;/p&gt;

&lt;p&gt;Different point of view between governments that:
- who can&#039;t wiretap Blackberry services and force RIM to do so (India, UAE,Saudi)
- who don&#039;t allow selling Blackberry until secret services (FSB) made an agreement for tapping (Russia)
- who don&#039;t trust RIM for government use because of potential spying risk on RIM networks (France and Germany)&lt;/p&gt;

&lt;p&gt;That&#039;s because RIM is not only a phone manufacturer but also a Service Provider with a world-wide internet overlay that&#039;s the RIM network.&lt;/p&gt;

&lt;p&gt;Read VoIP SA blog post on US tapping of RIM messaging:
http://voipsa.org/blog/2010/08/04/blackberries-and-lawful-intercept/&lt;/p&gt;

&lt;p&gt;That&#039;s because it&#039;s a service provider and not only a manufacturer.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>There&#8217;s an article on recent blackberry security issues.</p>
<p>Different point of view between governments that:<br />
- who can&#8217;t wiretap Blackberry services and force RIM to do so (India, UAE,Saudi)<br />
- who don&#8217;t allow selling Blackberry until secret services (FSB) made an agreement for tapping (Russia)<br />
- who don&#8217;t trust RIM for government use because of potential spying risk on RIM networks (France and Germany)</p>
<p>That&#8217;s because RIM is not only a phone manufacturer but also a Service Provider with a world-wide internet overlay that&#8217;s the RIM network.</p>
<p>Read VoIP SA blog post on US tapping of RIM messaging:<br />
<a href="http://voipsa.org/blog/2010/08/04/blackberries-and-lawful-intercept/" rel="nofollow">http://voipsa.org/blog/2010/08/04/blackberries-and-lawful-intercept/</a></p>
<p>That&#8217;s because it&#8217;s a service provider and not only a manufacturer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on GSM cracking in penetration test methodologies (OSSTMM) ? by naif</title>
		<link>http://infosecurity.ch/20100723/gsm-cracking-in-penetration-test-methodologies-osstmm/comment-page-1/#comment-181</link>
		<dc:creator>naif</dc:creator>
		<pubDate>Fri, 23 Jul 2010 12:36:40 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100723/gsm-cracking-in-penetration-test-methodologies-osstmm/#comment-181</guid>
		<description>&lt;p&gt;WOW!
It would be very useful also to prepare a webpage on backtrack 4 homepage on the Hardware / Software setup requirements to make GSM interception testing and to update it following the Blackhat Conference talk from Karsten Nohl next week.&lt;/p&gt;

&lt;p&gt;Consider me available to collect and invest time and (some) money to test the hardware setup, test and documentation, also collecting the rainbow tables required.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>WOW!<br />
It would be very useful also to prepare a webpage on backtrack 4 homepage on the Hardware / Software setup requirements to make GSM interception testing and to update it following the Blackhat Conference talk from Karsten Nohl next week.</p>
<p>Consider me available to collect and invest time and (some) money to test the hardware setup, test and documentation, also collecting the rainbow tables required.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on GSM cracking in penetration test methodologies (OSSTMM) ? by Emanuele Gentili</title>
		<link>http://infosecurity.ch/20100723/gsm-cracking-in-penetration-test-methodologies-osstmm/comment-page-1/#comment-180</link>
		<dc:creator>Emanuele Gentili</dc:creator>
		<pubDate>Fri, 23 Jul 2010 10:19:30 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100723/gsm-cracking-in-penetration-test-methodologies-osstmm/#comment-180</guid>
		<description>&lt;p&gt;This tool will be avail in BackTrack 4 repository in a few days.&lt;/p&gt;

&lt;p&gt;emgent
BackTrack Linux Coordinator&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>This tool will be avail in BackTrack 4 repository in a few days.</p>
<p>emgent<br />
BackTrack Linux Coordinator</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Snake-oil security claims on crypto security product by Marc Ruef</title>
		<link>http://infosecurity.ch/20100719/snake-oil-security-claims-on-crypto-security-product/comment-page-1/#comment-178</link>
		<dc:creator>Marc Ruef</dc:creator>
		<pubDate>Tue, 20 Jul 2010 08:09:53 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100719/snake-oil-security-claims-on-crypto-security-product/#comment-178</guid>
		<description>&lt;p&gt;Hello,&lt;/p&gt;

&lt;p&gt;I am thinking about a site collecting snake-oil products/advertisements. Something like http://datalossdb.org/ - One may do a checklist out of Matt Curtin&#039;s paper ;) In the meanwhile I send suspicious vendors/products to Bruce Schneier and hope he is going to rant about them in his blog ;)&lt;/p&gt;

&lt;p&gt;Regards,&lt;/p&gt;

&lt;p&gt;Marc&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>I am thinking about a site collecting snake-oil products/advertisements. Something like <a href="http://datalossdb.org/" rel="nofollow">http://datalossdb.org/</a> &#8211; One may do a checklist out of Matt Curtin&#8217;s paper ;) In the meanwhile I send suspicious vendors/products to Bruce Schneier and hope he is going to rant about them in his blog ;)</p>
<p>Regards,</p>
<p>Marc</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Snake-oil security claims on crypto security product by naif</title>
		<link>http://infosecurity.ch/20100719/snake-oil-security-claims-on-crypto-security-product/comment-page-1/#comment-177</link>
		<dc:creator>naif</dc:creator>
		<pubDate>Mon, 19 Jul 2010 21:05:05 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100719/snake-oil-security-claims-on-crypto-security-product/#comment-177</guid>
		<description>&lt;p&gt;Nice topic.&lt;/p&gt;

&lt;p&gt;IMHO it would really be required to use a strong full disclosure oriented approach with a website collecting analysis and evidence with objective evaluation points related to snake-oil spotting.&lt;/p&gt;

&lt;p&gt;Something that have to be objective along with attached proof (screenshots, documents, etc) about a specific analysis.&lt;/p&gt;

&lt;p&gt;Also because a single persons doing this would not be really effective, probably a little community based platform with objective criteria to handle snake oil spotting would be very fun :-)&lt;/p&gt;

&lt;p&gt;Fabio&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Nice topic.</p>
<p>IMHO it would really be required to use a strong full disclosure oriented approach with a website collecting analysis and evidence with objective evaluation points related to snake-oil spotting.</p>
<p>Something that have to be objective along with attached proof (screenshots, documents, etc) about a specific analysis.</p>
<p>Also because a single persons doing this would not be really effective, probably a little community based platform with objective criteria to handle snake oil spotting would be very fun :-)</p>
<p>Fabio</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Snake-oil security claims on crypto security product by Marc Ruef</title>
		<link>http://infosecurity.ch/20100719/snake-oil-security-claims-on-crypto-security-product/comment-page-1/#comment-176</link>
		<dc:creator>Marc Ruef</dc:creator>
		<pubDate>Mon, 19 Jul 2010 20:54:59 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100719/snake-oil-security-claims-on-crypto-security-product/#comment-176</guid>
		<description>&lt;p&gt;Hello,&lt;/p&gt;

&lt;p&gt;Nice article that summarizes the problem very good.&lt;/p&gt;

&lt;p&gt;But how would you expect to proceed with a vendor that is selling snake oil? Would you expect to make an analysis public to warn others from the false promises?&lt;/p&gt;

&lt;p&gt;Regards,&lt;/p&gt;

&lt;p&gt;Marc&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>Nice article that summarizes the problem very good.</p>
<p>But how would you expect to proceed with a vendor that is selling snake oil? Would you expect to make an analysis public to warn others from the false promises?</p>
<p>Regards,</p>
<p>Marc</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Blackberry Security and Encryption: Devil or Angel? by Kyle</title>
		<link>http://infosecurity.ch/20100707/blackberry-security-and-encryption-devil-or-angel/comment-page-1/#comment-173</link>
		<dc:creator>Kyle</dc:creator>
		<pubDate>Wed, 07 Jul 2010 22:18:23 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100707/blackberry-security-and-encryption-devil-or-angel/#comment-173</guid>
		<description>&lt;p&gt;I enjoyed reading this post, in particular the summary of conflicts RIM has had with government institutions while trying to sell devices to foreign markets. The fact that RIM is selling highly secure devices to markets that aren&#039;t comfortable with the technology really brings to light some of the global trade issues that aren&#039;t usually in the consumer&#039;s eye. These are the types of problems normally reserved for defense industry contracts and yet RIM, which is now considered largely a consumer product, has to deal with this.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I enjoyed reading this post, in particular the summary of conflicts RIM has had with government institutions while trying to sell devices to foreign markets. The fact that RIM is selling highly secure devices to markets that aren&#8217;t comfortable with the technology really brings to light some of the global trade issues that aren&#8217;t usually in the consumer&#8217;s eye. These are the types of problems normally reserved for defense industry contracts and yet RIM, which is now considered largely a consumer product, has to deal with this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About the SecurStar GmbH Phonecrypt voice encryption analysis (criteria, errors and different results) by Bilal Ahmed</title>
		<link>http://infosecurity.ch/20100130/about-the-voice-encryption-analysis-phonecrypt-can-be-intercepted-serious-security-evaluation-criteria/comment-page-1/#comment-165</link>
		<dc:creator>Bilal Ahmed</dc:creator>
		<pubDate>Tue, 29 Jun 2010 11:13:48 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100130/about-the-voice-encryption-analysis-phonecrypt-can-be-intercepted-serious-security-evaluation-criteria/#comment-165</guid>
		<description>&lt;p&gt;Nice to read this article and it will be great if you can include more cell phone spy software like Mobistealth and other cell phone and sms spy software&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Nice to read this article and it will be great if you can include more cell phone spy software like Mobistealth and other cell phone and sms spy software</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Evidence that infosecurityguard.com/notrax is SecurStar GmbH Phonecrypt &#8211; A fake independent research on voice crypto by Ronny</title>
		<link>http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/comment-page-1/#comment-102</link>
		<dc:creator>Ronny</dc:creator>
		<pubDate>Fri, 19 Mar 2010 18:19:05 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/#comment-102</guid>
		<description>&lt;p&gt;Read this:&lt;/p&gt;

&lt;p&gt;http://groups.google.com/group/alt.security.scramdisk/browse_thread/thread/67db4bf8c34a06d3/c724e69a44eb94b0%3F&lt;/p&gt;

&lt;p&gt;http://groups.google.com/group/alt.security.scramdisk/browse_thread/thread/1d86bc59bff869cb/cbf562f2f1b04c18%3Fq=hafner%26amp;lnk=ol%26amp;&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Read this:</p>
<p><a href="http://groups.google.com/group/alt.security.scramdisk/browse_thread/thread/67db4bf8c34a06d3/c724e69a44eb94b0%3F" rel="nofollow">http://groups.google.com/group/alt.security.scramdisk/browse_thread/thread/67db4bf8c34a06d3/c724e69a44eb94b0%3F</a></p>
<p><a href="http://groups.google.com/group/alt.security.scramdisk/browse_thread/thread/1d86bc59bff869cb/cbf562f2f1b04c18%3Fq=hafner%26amp;lnk=ol%26amp;" rel="nofollow">http://groups.google.com/group/alt.security.scramdisk/browse_thread/thread/1d86bc59bff869cb/cbf562f2f1b04c18%3Fq=hafner%26amp;lnk=ol%26amp;</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Evidence that infosecurityguard.com/notrax is SecurStar GmbH Phonecrypt &#8211; A fake independent research on voice crypto by wow</title>
		<link>http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/comment-page-1/#comment-97</link>
		<dc:creator>wow</dc:creator>
		<pubDate>Sun, 28 Feb 2010 16:50:42 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/#comment-97</guid>
		<description>&lt;p&gt;Nice work!!!!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Nice work!!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Evidence that infosecurityguard.com/notrax is SecurStar GmbH Phonecrypt &#8211; A fake independent research on voice crypto by Dohei</title>
		<link>http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/comment-page-1/#comment-66</link>
		<dc:creator>Dohei</dc:creator>
		<pubDate>Tue, 02 Feb 2010 01:42:31 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/#comment-66</guid>
		<description>&lt;p&gt;Hafner known as &#039;unethical&#039; person&lt;/p&gt;

&lt;p&gt;.. to say the least.&lt;/p&gt;

&lt;p&gt;It is little known that his anonymising service &#039;surfsolo&#039; was actually provided by another outfit at www.privacy.li . According to there website they dumped Wilfried Hafner last year around August/September for &#039;unethical behaviour&#039;, check it out here:&lt;/p&gt;

&lt;p&gt;http://privacy.li/news.html&lt;/p&gt;

&lt;p&gt;I wonder why...&lt;/p&gt;

&lt;p&gt;Don&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hafner known as &#8216;unethical&#8217; person</p>
<p>.. to say the least.</p>
<p>It is little known that his anonymising service &#8216;surfsolo&#8217; was actually provided by another outfit at <a href="http://www.privacy.li" rel="nofollow">http://www.privacy.li</a> . According to there website they dumped Wilfried Hafner last year around August/September for &#8216;unethical behaviour&#8217;, check it out here:</p>
<p><a href="http://privacy.li/news.html" rel="nofollow">http://privacy.li/news.html</a></p>
<p>I wonder why&#8230;</p>
<p>Don</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About the SecurStar GmbH Phonecrypt voice encryption analysis (criteria, errors and different results) by danno</title>
		<link>http://infosecurity.ch/20100130/about-the-voice-encryption-analysis-phonecrypt-can-be-intercepted-serious-security-evaluation-criteria/comment-page-1/#comment-65</link>
		<dc:creator>danno</dc:creator>
		<pubDate>Mon, 01 Feb 2010 23:23:12 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100130/about-the-voice-encryption-analysis-phonecrypt-can-be-intercepted-serious-security-evaluation-criteria/#comment-65</guid>
		<description>&lt;p&gt;Nice work, quite thorough. If you&#039;re going to bust someone, it&#039;s good to be thorough.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Nice work, quite thorough. If you&#8217;re going to bust someone, it&#8217;s good to be thorough.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Evidence that infosecurityguard.com/notrax is SecurStar GmbH Phonecrypt &#8211; A fake independent research on voice crypto by noneman</title>
		<link>http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/comment-page-1/#comment-64</link>
		<dc:creator>noneman</dc:creator>
		<pubDate>Mon, 01 Feb 2010 19:01:52 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/#comment-64</guid>
		<description>&lt;p&gt;MicroChick:&lt;/p&gt;

&lt;p&gt;http://news.techworld.com/mobile-wireless/7425/devastating-mobile-attack-under-spotlight/
it´s another Fake from Hafner:
German Security Specialist write http://www.marko-rogge.de/rexspyartikel.pdf&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>MicroChick:</p>
<p><a href="http://news.techworld.com/mobile-wireless/7425/devastating-mobile-attack-under-spotlight/" rel="nofollow">http://news.techworld.com/mobile-wireless/7425/devastating-mobile-attack-under-spotlight/</a><br />
it´s another Fake from Hafner:<br />
German Security Specialist write <a href="http://www.marko-rogge.de/rexspyartikel.pdf" rel="nofollow">http://www.marko-rogge.de/rexspyartikel.pdf</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About the SecurStar GmbH Phonecrypt voice encryption analysis (criteria, errors and different results) by Surreptitious Evil</title>
		<link>http://infosecurity.ch/20100130/about-the-voice-encryption-analysis-phonecrypt-can-be-intercepted-serious-security-evaluation-criteria/comment-page-1/#comment-62</link>
		<dc:creator>Surreptitious Evil</dc:creator>
		<pubDate>Mon, 01 Feb 2010 16:49:31 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100130/about-the-voice-encryption-analysis-phonecrypt-can-be-intercepted-serious-security-evaluation-criteria/#comment-62</guid>
		<description>&lt;p&gt;Having followed this from el Reg, I am also quite interested in the two identical laudatory comments (14 &amp; 15 on http://infosecurityguard.com/?p=26#comments) have recently first-registered domains 1st Dec and 28 Dec 09) and have also commented favourable on other posts.&lt;/p&gt;

&lt;p&gt;A quick google for &quot;Carroll B Merriman&quot; was instructive - an entirely context-free commentor with weird interjects on everything from California &#039;go-go &amp; sushi&#039; bars (where he posts about Zune?) to Lancashire computer repair &amp; web design (well, Blackpool ain&#039;t too far) and, most tellingly, about internet affiliate marketing.  The Blackpool PC site hurt in the karma (poor goldfish, crap site) and, interestingly, appears to be strangely registered - to a non-UK resident individual (rather than a UK company).  &#039;David Pennington&#039; may well be connected to &#039;Steve Pennington&#039; who has aaafleetwoodpcrepair.co.uk, who is connected to &quot;tickets4u Ltd&quot; - a UK registered company.&lt;/p&gt;

&lt;p&gt;V dodgy, in my professional opinion - this grass is clearly plastic.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Having followed this from el Reg, I am also quite interested in the two identical laudatory comments (14 &amp; 15 on <a href="http://infosecurityguard.com/?p=26#comments" rel="nofollow">http://infosecurityguard.com/?p=26#comments</a>) have recently first-registered domains 1st Dec and 28 Dec 09) and have also commented favourable on other posts.</p>
<p>A quick google for &#8220;Carroll B Merriman&#8221; was instructive &#8211; an entirely context-free commentor with weird interjects on everything from California &#8216;go-go &amp; sushi&#8217; bars (where he posts about Zune?) to Lancashire computer repair &amp; web design (well, Blackpool ain&#8217;t too far) and, most tellingly, about internet affiliate marketing.  The Blackpool PC site hurt in the karma (poor goldfish, crap site) and, interestingly, appears to be strangely registered &#8211; to a non-UK resident individual (rather than a UK company).  &#8216;David Pennington&#8217; may well be connected to &#8216;Steve Pennington&#8217; who has aaafleetwoodpcrepair.co.uk, who is connected to &#8220;tickets4u Ltd&#8221; &#8211; a UK registered company.</p>
<p>V dodgy, in my professional opinion &#8211; this grass is clearly plastic.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Evidence that infosecurityguard.com/notrax is SecurStar GmbH Phonecrypt &#8211; A fake independent research on voice crypto by MicroChick</title>
		<link>http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/comment-page-1/#comment-61</link>
		<dc:creator>MicroChick</dc:creator>
		<pubDate>Mon, 01 Feb 2010 16:07:56 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/#comment-61</guid>
		<description>&lt;p&gt;Thanks for the heads up. We have done an update on this story here and linked back to your blog. http://news.techworld.com/security/3211618/accusations-fly-over-voice-encyption-hack/&lt;/p&gt;

&lt;p&gt;Please link back to us in your coverage!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Thanks for the heads up. We have done an update on this story here and linked back to your blog. <a href="http://news.techworld.com/security/3211618/accusations-fly-over-voice-encyption-hack/" rel="nofollow">http://news.techworld.com/security/3211618/accusations-fly-over-voice-encyption-hack/</a></p>
<p>Please link back to us in your coverage!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Evidence that infosecurityguard.com/notrax is SecurStar GmbH Phonecrypt &#8211; A fake independent research on voice crypto by Logan</title>
		<link>http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/comment-page-1/#comment-60</link>
		<dc:creator>Logan</dc:creator>
		<pubDate>Mon, 01 Feb 2010 12:36:44 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/#comment-60</guid>
		<description>&lt;p&gt;Hi together,&lt;/p&gt;

&lt;p&gt;if securstar is doing that kind of stuff, it will be really bad for them. But, do you know that securstar has a product that allow anonymous surfing over the web. So, thier Server for that anonymous product are located also at that Ip adress !&lt;/p&gt;

&lt;p&gt;If i will be the hacker, i will upload the content of www.infosecurityguard.com not over my public IP adress ! I will redirect every up oder download over a lots of proxy&#039;s.&lt;/p&gt;

&lt;p&gt;So, when somebody gets a IP adress, with a link to a company, that is not the evidence, that the company is the &quot;badboy&quot;.&lt;/p&gt;

&lt;p&gt;Even, the hacking of Mobile Phones is a very old issue, so what Notrax is telling us, is: &quot;there is still dangerous things out there, even when you feel secure, you are not  !&lt;/p&gt;

&lt;p&gt;So, i think the content of that page are true, so when i pay 500 Euro&#039;s or more for a Security Product and it can be hacked with a oldschool bypass trick....shame on that company !&lt;/p&gt;

&lt;p&gt;Anyway, i trust no one ! Not Securstar, not that page, not other places.&lt;/p&gt;

&lt;p&gt;Think, before you publish !&lt;/p&gt;

&lt;p&gt;Greetz&lt;/p&gt;

&lt;p&gt;Logan&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hi together,</p>
<p>if securstar is doing that kind of stuff, it will be really bad for them. But, do you know that securstar has a product that allow anonymous surfing over the web. So, thier Server for that anonymous product are located also at that Ip adress !</p>
<p>If i will be the hacker, i will upload the content of <a href="http://www.infosecurityguard.com" rel="nofollow">http://www.infosecurityguard.com</a> not over my public IP adress ! I will redirect every up oder download over a lots of proxy&#8217;s.</p>
<p>So, when somebody gets a IP adress, with a link to a company, that is not the evidence, that the company is the &#8220;badboy&#8221;.</p>
<p>Even, the hacking of Mobile Phones is a very old issue, so what Notrax is telling us, is: &#8220;there is still dangerous things out there, even when you feel secure, you are not  !</p>
<p>So, i think the content of that page are true, so when i pay 500 Euro&#8217;s or more for a Security Product and it can be hacked with a oldschool bypass trick&#8230;.shame on that company !</p>
<p>Anyway, i trust no one ! Not Securstar, not that page, not other places.</p>
<p>Think, before you publish !</p>
<p>Greetz</p>
<p>Logan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Evidence that infosecurityguard.com/notrax is SecurStar GmbH Phonecrypt &#8211; A fake independent research on voice crypto by Les</title>
		<link>http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/comment-page-1/#comment-59</link>
		<dc:creator>Les</dc:creator>
		<pubDate>Mon, 01 Feb 2010 11:36:53 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/#comment-59</guid>
		<description>&lt;p&gt;How does the saying go? bad things.. bad people..&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>How does the saying go? bad things.. bad people..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About the SecurStar GmbH Phonecrypt voice encryption analysis (criteria, errors and different results) by John</title>
		<link>http://infosecurity.ch/20100130/about-the-voice-encryption-analysis-phonecrypt-can-be-intercepted-serious-security-evaluation-criteria/comment-page-1/#comment-57</link>
		<dc:creator>John</dc:creator>
		<pubDate>Sun, 31 Jan 2010 06:59:54 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20100130/about-the-voice-encryption-analysis-phonecrypt-can-be-intercepted-serious-security-evaluation-criteria/#comment-57</guid>
		<description>&lt;p&gt;Absolutely correct, I knew that hacker is nothing but a marketing dummy, seems like I was right&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Absolutely correct, I knew that hacker is nothing but a marketing dummy, seems like I was right</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Chinese Spying NSA/USA buying Cryptographic Equipment on Ebay by Vladimir</title>
		<link>http://infosecurity.ch/20090712/chinese-spying-nsausa-buying-cryptographic-equipment-on-ebay/comment-page-1/#comment-7</link>
		<dc:creator>Vladimir</dc:creator>
		<pubDate>Mon, 20 Jul 2009 13:18:40 +0000</pubDate>
		<guid isPermaLink="false">http://infosecurity.ch/20090712/chinese-spying-nsausa-buying-cryptographic-equipment-on-ebay/#comment-7</guid>
		<description>&lt;p&gt;I think there is nothing surprising. Every day such devices are stolen, bought and sold. The only new thing is that he managed to buy these at eBay (if he really did).&lt;/p&gt;

&lt;p&gt;Id doesn&#039;t matter if you obtain just a device - can you read and disassemble the algorithms, code etc? I don&#039;t know. Or it&#039;s damn hard.&lt;/p&gt;

&lt;p&gt;Besides, Russians are experiencing the same issues. E.g. when it was Soviet Union, it was ok. But then it split into several countries (CIS countries). And many military RND enterprises are located in Ukraine.&lt;/p&gt;

&lt;p&gt;Now the Ukraine is friends with USA. So they just sold them a couple of Soviet-made military aircrafts with all documentation (e.g. drawings, schematics etc). So USA can make a full study of the technologies. That&#039;s the real leakage! 
And they also sell such technologies to China (spare parts, documents etc). Russia stopped selling military aircrafts to China recently - because chinese are buying 2 aircrafts and make 50 copies instead of buying 50 more, that&#039;s what really amazing!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I think there is nothing surprising. Every day such devices are stolen, bought and sold. The only new thing is that he managed to buy these at eBay (if he really did).</p>
<p>Id doesn&#8217;t matter if you obtain just a device &#8211; can you read and disassemble the algorithms, code etc? I don&#8217;t know. Or it&#8217;s damn hard.</p>
<p>Besides, Russians are experiencing the same issues. E.g. when it was Soviet Union, it was ok. But then it split into several countries (CIS countries). And many military RND enterprises are located in Ukraine.</p>
<p>Now the Ukraine is friends with USA. So they just sold them a couple of Soviet-made military aircrafts with all documentation (e.g. drawings, schematics etc). So USA can make a full study of the technologies. That&#8217;s the real leakage!<br />
And they also sell such technologies to China (spare parts, documents etc). Russia stopped selling military aircrafts to China recently &#8211; because chinese are buying 2 aircrafts and make 50 copies instead of buying 50 more, that&#8217;s what really amazing!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

