<?xml version="1.0" encoding="UTF-8"?><!-- generator="WordPress/abc" -->
<rss version="0.92">
<channel>
	<title>Playhouse of privacy, security, hacking, encryption, intelligence and some business stuff</title>
	<link>http://infosecurity.ch</link>
	<description>My interest in espionage/counterespionage, hacking, privacy, security, technology and sometime business and marketing stuff related to security world. BLOG IS IN ENGLISH. TRANSLATIONS ARE AUTOMATIC.</description>
	<lastBuildDate>Fri, 23 Jul 2010 07:16:30 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>GSM cracking in penetration test methodologies (OSSTMM) ?</title>
		<description><![CDATA[As most of this blog reader already know, in past years there was a lot of activities related to public research for GSM auditing and cracking.

However when there was huge media coverage to GSM cracking research results, the tools to make the cracking was really early stage and still very inefficient.

Now Frank Stevenson , norwegian [...]]]></description>
		<link>http://infosecurity.ch/20100723/gsm-cracking-in-penetration-test-methodologies-osstmm/</link>
			</item>
	<item>
		<title>Snake-oil security claims on crypto security product</title>
		<description><![CDATA[Security market grow, more companies goes to the market, but how many of them are taking seriously what they do?

You know, doing security technology mean that you are personally responsible for the protection of the user&#8217;s information. You must make them aware of what they need, exactly what your are doing and which kind of [...]]]></description>
		<link>http://infosecurity.ch/20100719/snake-oil-security-claims-on-crypto-security-product/</link>
			</item>
	<item>
		<title>Web2.0 privacy leak in Mobile apps</title>
		<description><![CDATA[You know that web2.0 world it&#8217;s plenty of leak of any kind (profiling, profiling, profiling) related to Privacy and users starts being concerned about it.

Users continuously download applications without knowing the details of what they do, for example iFart just because are cool, are fun and sometime are useful.




  


On mobile phones users install [...]]]></description>
		<link>http://infosecurity.ch/20100717/web2-0-privacy-leak-in-mobile-apps/</link>
			</item>
	<item>
		<title>AES algorithm selected for use in space</title>
		<description><![CDATA[I encountered a nice paper regarding analysis and consideration on which encryption algorithm it&#8217;s best suited for use in the space by space ship and equipments.

The paper has been done by the Consultative Committee for Space Data Systems that&#8217;s a consortium of all space agency around that cumulatively handled more than 400 mission to space.




 [...]]]></description>
		<link>http://infosecurity.ch/20100708/aes-algorithm-selected-for-use-in-space/</link>
			</item>
	<item>
		<title>Blackberry Security and Encryption: Devil or Angel?</title>
		<description><![CDATA[Blackberry have good and bad reputation regarding his security capability, depending from which angle you look at it.

This post it&#8217;s a summarized set of information to let the reader the get picture, without taking much a position as RIM and Blackberry can be considered, depending on the point of view, an extremely secure platform or [...]]]></description>
		<link>http://infosecurity.ch/20100707/blackberry-security-and-encryption-devil-or-angel/</link>
			</item>
	<item>
		<title>Celebrating &#8220;Hackers&#8221; after 25 years</title>
		<description><![CDATA[A cult book, ever green since 25 years.


  


It&#8217;s been 25 years since &#8220;Hackers&#8221; was published. Author Steven Levy reflects on the book and the movement.


http://radar.oreilly.com/2010/06/hackers-at-25.htmlSteven Levy wrote a book in the mid-1980s that introduced the term "hacker" -- the positive connotation -- to a wide audience. In the ensuing 25 years, that word [...]]]></description>
		<link>http://infosecurity.ch/20100701/celebrating-hackers-after-25-years/</link>
			</item>
	<item>
		<title>Botnet for RSA cracking?</title>
		<description><![CDATA[I read an interesting article about putting 1.000.000 computers, given the chance for a serious botnet owner to get it, to crack RSA.

The result is that in such context attacking an RSA 1024bit key would take only 28 years, compared to theoretical 19 billion of years.

Reading of this article, is extremely interesting because it gives [...]]]></description>
		<link>http://infosecurity.ch/20100630/botnet-for-rsa-cracking/</link>
			</item>
	<item>
		<title>Patent rights and opensource: can they co-exist?</title>
		<description><![CDATA[How many of you had to deal with patented technologies?

How many of the patented technologies you dealed with was also &#8220;secrets&#8221; in their implementation?

Well, there&#8217;s a set of technologies whose implementation is open source (copyright) but that are patented (intellectual property right).

A very nice paper about the topic opensource &#38; patents that i suggest to [...]]]></description>
		<link>http://infosecurity.ch/20100627/patent-rights-and-opensource-can-they-co-exist/</link>
			</item>
	<item>
		<title>China Encryption Regulations</title>
		<description><![CDATA[Hi all,

i found this very interesting paper on China Encryption Import/Export/Domestic Regulations done by Baker&#38;Mckenzie in the US.

It&#8217;s strongly business and regulatory oriented giving a very well done view on how china regulations works and how it may behave in future.

Read here Decrypting China Encryption&#8217;s Regulations (form Bakernet website) .]]></description>
		<link>http://infosecurity.ch/20100616/china-encryption-regulations/</link>
			</item>
	<item>
		<title>IOScat &#8211; a Port of Netcat to Cisco IOS</title>
		<description><![CDATA[A porting of famous netcat to Cisco IOS router operating system: IOSCat

The only main limit is that it does not support UDP, but that&#8217;s a very cool tool!

A very good txt to read is Netcat hacker Manual.]]></description>
		<link>http://infosecurity.ch/20100613/ioscat-a-port-of-netcat-to-cisco-ios/</link>
			</item>
	<item>
		<title>The (old) Crypto AG case and some thinking about it</title>
		<description><![CDATA[In the &#8216;90, closed source and proprietary cryptography was ruling the world.

That&#8217;s before open source and scientifically approved encrypted technologies went out as a best practice to do crypto stuff.

I would like to remind when, in 1992, USA along with Israel was, together with switzerland, providing backdoored (proprietary and secret) technologies to Iranian government to [...]]]></description>
		<link>http://infosecurity.ch/20100607/the-old-crypto-ag-case-and-some-thinking-about-it/</link>
			</item>
	<item>
		<title>Missiles against cyber attacks?</title>
		<description><![CDATA[The cyber conflicts are really reaching a point where war and cyberwar merge together.

NATO countries have the right to use the force against attacks on computer networks.]]></description>
		<link>http://infosecurity.ch/20100607/missiles-against-cyber-attacks/</link>
			</item>
	<item>
		<title>Mobile Security talk at WHYMCA conference</title>
		<description><![CDATA[I want to share some slides i used to talk about mobile security at whymca mobile conference in Milan.Read here my slides on mobile security .

The slides provide a wide an in-depth overview of mobile security related matters, i should be doing some slidecast about it putting also audio. Maybe will do, maybe not, it [...]]]></description>
		<link>http://infosecurity.ch/20100602/mobile-security-talk-at-whymca-conference/</link>
			</item>
	<item>
		<title>iPhone PIN: useless encryption</title>
		<description><![CDATA[I recently switched one of my multiple mobile phones with which i go around to iPhone.

I am particularly concerned about data protection in case of theft and so started having a look around about the iPhone provided protection system.

There is an interesting set of iPhone Business Security Features that make me think that iPhone is [...]]]></description>
		<link>http://infosecurity.ch/20100601/iphone-pin-useless-encryption/</link>
			</item>
	<item>
		<title>Who extract Oil in Iran? Business and UN sanction together</title>
		<description><![CDATA[I like geopolitic and i am following carefully iran issues.

I went to National Iranian Oil Company website and have seen &#8220;Exploration &#38; Production&#8221; section where are listed all the companies and their country of origin that are allowed to make Exploration of oil in Iran.

On that list we find the list of countries along with [...]]]></description>
		<link>http://infosecurity.ch/20100601/who-extract-oil-in-iran-business-and-un-sanction-together/</link>
			</item>
	<item>
		<title>Exploit code against SecurStar DriveCrypt published</title>
		<description><![CDATA[It seems that the hacking community somehow like to target securstar products, maybe because hacking community doesn&#8217;t like the often revealed unethical approach already previously described in this blog by articles and user&#8217;s comments.

In 2004 a lot of accusation against Hafner of SecurStar went out because of alleged intellectual property theft regarding opensource codes such [...]]]></description>
		<link>http://infosecurity.ch/20100525/hackers-doesnt-like-securstar-products-exploit-code-against-drivecrypt-published/</link>
			</item>
	<item>
		<title>Quantum cryptography broken</title>
		<description><![CDATA[Quantum cryptography it&#8217;s something very challenging, encryption methods that leverage the law of phisycs to secure communications over fiber lines.

To oversimplify the system is based on the fact that if someone cut the fiber, put a tap in the middle, and joint together the other side of the fiber, the amount of &#8220;errors&#8221; that will [...]]]></description>
		<link>http://infosecurity.ch/20100520/quantum-cryptography-broken/</link>
			</item>
	<item>
		<title>FUN! Infosecurity consideration on some well known films</title>
		<description><![CDATA[Please read it carefully Film that needed better infosec.

One the the review, imho the most fun one on film Star Wars:

The scene

Death star getting blown up

Infosec Analysis

Darth Vader must be heralded as the prime example of a chief executive who really didn&#8217;t care about information security. The entire board was unapproachable and clearly no system [...]]]></description>
		<link>http://infosecurity.ch/20100518/fun-infosecurity-consideration-on-some-well-known-films/</link>
			</item>
	<item>
		<title>great point of view</title>
		<description><![CDATA[Because security of a cryptographic system it&#8217;s not a matter of &#8220;how many bits do i use&#8221; but using the right approach to do the right thing to mitigate the defined security risk in the most balanced way.

]]></description>
		<link>http://infosecurity.ch/20100420/great-point-of-view/</link>
			</item>
	<item>
		<title>Encryption is not scrambling: be aware of scrambler!</title>
		<description><![CDATA[Most of us know about voice scrambler that can be used across almost any kind of voice based communication technology.

Extremely flexible approach: works everything

Extreme performance: very low latency

but unfortunately&#8230;

Extremely weak: Scrambling cannot be considered secure.

Only encryption can be considered secure under the Kerckoff&#8217;s principle .

So please don&#8217;t even consider any kind of analog scrambler if [...]]]></description>
		<link>http://infosecurity.ch/20100420/encryption-is-not-scrambling-be-aware-of-scrambler/</link>
			</item>
	<item>
		<title>SecurStar GmbH Phonecrypt answers on the Infosecurityguard/Notrax case: absolutely unreasonable!  :-)</title>
		<description><![CDATA[UPDATE 20.04.2010: http://infosecurityguard.com has been disabled. Notrax identity became known to several guys in the voice security environments (cannot tell, but you can imagine, i was right!) and so our friends decided to trow away the website because of legal responsibility under UK and USA laws.

UPDATE: Nice summary of the whole story (i know, it&#8217;s [...]]]></description>
		<link>http://infosecurity.ch/20100201/answer-of-securstar-gmbh-on-the-infosecurityguardnotrax-case-absolutely-unreasonable/</link>
			</item>
	<item>
		<title>Evidence that infosecurityguard.com/notrax is SecurStar GmbH Phonecrypt &#8211; A fake independent research on voice crypto</title>
		<description><![CDATA[Below evidence that the security review made by an anonymous hacker on http://infosecurityguard.com is in facts a dishonest marketing plan by the SecurStar GmbH to promote their voice crypto product.

I already wrote about that voice crypto analysis that appeared to me very suspicious.

Now it&#8217;s confirmed, it&#8217;s a fake independent hacker security research by SecurStar GmbH, [...]]]></description>
		<link>http://infosecurity.ch/20100201/evidence-that-infosecurityguard-comnotrax-is-securstar-gmbh-a-fake-independent-research-on-voice-crypto/</link>
			</item>
	<item>
		<title>Dishonest security: The SecurStart GmbH Phonecrypt case</title>
		<description><![CDATA[I would like to provide considerations on the concept of ethics that a security company should have respect to the users, the media and the security environment.

SecurStar GmbH made very bad things making that infosecuriguard.com fake independent research.

It&#8217;s unfair approach respect to hacking community.



It&#8217;s unfair marketing to end user. They should not be tricking by [...]]]></description>
		<link>http://infosecurity.ch/20100201/dishonest-security-the-securstart-gmbh-case/</link>
			</item>
	<item>
		<title>About the SecurStar GmbH Phonecrypt voice encryption analysis (criteria, errors and different results)</title>
		<description><![CDATA[This article want to clarify and better explain the finding at infosecurityguard.com regaring voice encryption product evaluation.
This article want to tell you a different point of view other than infosecurityguard.com and explaining which are the rational with extensive explaination from security point of view.
Today i read news saying: &#8220;PhoneCrypt: Basic Vulnerability Found in 12 out [...]]]></description>
		<link>http://infosecurity.ch/20100130/about-the-voice-encryption-analysis-phonecrypt-can-be-intercepted-serious-security-evaluation-criteria/</link>
			</item>
	<item>
		<title>Licensed by Israel Ministry of Defense? How things really works!</title>
		<description><![CDATA[You should know that Israel is a country where if a company need to develop encryption product they must be authorized by the government.

The government don&#8217;t want that companies doing cryptography can do anything bad to them and what they can do of good for the government, so they have to first be authorized.

Companies providing [...]]]></description>
		<link>http://infosecurity.ch/20100129/licensed-by-israel-ministry-of-defense-how-things-really-works/</link>
			</item>
	<item>
		<title>O3B Networks: a new satellite broadband approach</title>
		<description><![CDATA[That&#8217;s something amazing, &#8220;other 3 billion&#8221; broadband coverage not trough fiber but trough satellite.

A project where also google is one of the shareholder, covering 3 billion persons trough low orbit, low latency broadband (10GBit) satellite network.

Check here technical infrastructure details on ITU website.]]></description>
		<link>http://infosecurity.ch/20100126/o3b-networks-a-new-satellite-broadband-approach/</link>
			</item>
	<item>
		<title>Index of economic freedom</title>
		<description><![CDATA[When looking at facts and figures about globalized world, the index of economic freedom is a nice tool to make proper considerations.]]></description>
		<link>http://infosecurity.ch/20091221/index-of-economic-freedom/</link>
			</item>
	<item>
		<title>Location Based Services: the big brother thanks you ;-)</title>
		<description><![CDATA[Do you use your iphone, google phone, blackberry or nokia smartphone with cool built-in GPS?

Well law enforcement can now know even better where you are, at any time, even with historical data and much better than BTS based location systems.

Sprint has given 8 million times customer&#8217;s GPS information to law enforcement (sound something like a [...]]]></description>
		<link>http://infosecurity.ch/20091201/location-based-services-the-big-brother-thanks-you/</link>
			</item>
	<item>
		<title>Gold-Lock Security Encryption Contest: be careful!</title>
		<description><![CDATA[This post is to talk about the “unfair” marketing approach of Gold-Lock, an israeli company doing mobile voice encryption authorized by Israeli Ministry of Defence .

Following an announcement seen on Linkedin “Information Security Community” group:


  GoldLock is offering US$ 100.000 and a job for an unencryption

  GoldLock, an israeli encryption and security company [...]]]></description>
		<link>http://infosecurity.ch/20091125/gold-lock-security-encryption-contest-be-careful/</link>
			</item>
	<item>
		<title>Recuva: Nice windows data recovery tool</title>
		<description><![CDATA[Not a professional tool but an easy, quick and free one.

If you just accidently deleted some files on windows or your employee leave the company deleting all his data, well that you get out from trouble quickly.

It also came out in a &#8216;portable&#8217; version to be loaded from an USB stick drive.

Check Recuva recovery tool]]></description>
		<link>http://infosecurity.ch/20091112/recuva-nice-windows-data-recovery-tool/</link>
			</item>
	<item>
		<title>Military contractors going commercial</title>
		<description><![CDATA[Most military contractors are suffering from the restriction of government&#8217;s budgets for military expenses and are moving into commercial markets, still they have to adjust a lot of things.

Read here a nice analysis from rochtel on how military contractors should adapt their strategy.


]]></description>
		<link>http://infosecurity.ch/20091110/military-contractors-going-commercial/</link>
			</item>
	<item>
		<title>Disk encryption sometimes &#8216;works&#8217;</title>
		<description><![CDATA[I am one of the person convinced that a computer disk encryption system will not protect you from public authorities if they are convinced enough and the case is very important.

There are a lot of way to convince a person to release a password.

However there&#8217;s a case in Australia where not revealing the disk password [...]]]></description>
		<link>http://infosecurity.ch/20091109/disk-encryption-sometimes-works/</link>
			</item>
	<item>
		<title>Brazilian Electrical Blackout: preview of cyberwar</title>
		<description><![CDATA[In 2005 and 2007 in Brazil million of people was targetted by a blackout.

Initially it appeared like an accident.

Now it&#8217;s known that was caused by a cyber attack against electricity control systems.

That was just a preview of what a cyber attack in a cyberwar means.

In near future we&#8217;ll probably see something like &#8216;virtual custom offices&#8217; [...]]]></description>
		<link>http://infosecurity.ch/20091107/brazilian-electrical-blackout-preview-of-cyberwar/</link>
			</item>
	<item>
		<title>Political conflict in Turkey between Prosecutors and Wiretappers</title>
		<description><![CDATA[It seems that in Turkey the Telecommunication Directorate (TIB), in charge of managing the wiretapping, intercepted the president of the Judge and Prosecutors Associations.

Prosecutors and Judge usually does not like being tapped, and so the 1st High Criminal Court ordered an audit of all the recording done by the TIB since 2006.

Read more here.]]></description>
		<link>http://infosecurity.ch/20091107/political-conflict-in-turkey-between-prosecutors-and-wiretappers/</link>
			</item>
	<item>
		<title>Come back to blogging</title>
		<description><![CDATA[I come back to blogging. Why i stopped my blogging trial period?

1st because being busy @work

2nd because my blogging software expired and i hate wordpress editor (i really need a blogging client for my own way of making information).

I use this software called Ecto that cost about 17 EUR and it&#8217;s pretty useful to keep [...]]]></description>
		<link>http://infosecurity.ch/20091107/come-back-to-blogging/</link>
			</item>
	<item>
		<title>Conventionality is not morality.</title>
		<description><![CDATA[During my daily RSS OCD reading I had to deal with this article: it has been written by a &#8220;senior anti-virus researcher at Kaspersky Lab&#8217;s&#8220;. Talk about personal interest.

I wont comment on the practical implications of useless signature based AV&#8217;s and how cyber criminals will never need amateur-ish projects to carry on their malicious tactics.

But what [...]]]></description>
		<link>http://infosecurity.ch/20090806/conventionality-is-not-morality/</link>
			</item>
	<item>
		<title>Hackers Hacking Hackers</title>
		<description><![CDATA[Hackers hacking hackers are always pretty fun.

And I am not talking about ZF05 (which was cool reading, even if not as cool as ~El8 was), I am talking about this.]]></description>
		<link>http://infosecurity.ch/20090803/hacking-hackers/</link>
			</item>
	<item>
		<title>This is big business, this is the American way</title>
		<description><![CDATA[43 years old &#8220;UFO eccentric&#8221; hacker Gary McKinnon just loses appeal against his extradition to the States for computer crimes he committed 7 years ago.

If you&#8217;ve lived under a rock during the last few years what this dude did was basically break into .gov computers looking for UFO related material.

Probably the last case of recreational [...]]]></description>
		<link>http://infosecurity.ch/20090731/this-is-big-business-this-is-the-american-way/</link>
			</item>
	<item>
		<title>Russia: the best worldwide place for cybercrime business</title>
		<description><![CDATA[Russia is a very beautiful place for any committed cybercrime business owner.

FBI and Mcafee are trying to do something, do they will ever succeed?

I don&#8217;t think so, it&#8217;s a political issue as russia is not going to extradite any cybercriminal and is not going to provide strong international cooperations.

Always remember that in Russia Business Network [...]]]></description>
		<link>http://infosecurity.ch/20090730/russia-the-best-worldwide-place-for-cybercrime-business/</link>
			</item>
	<item>
		<title>Iphone jailbreaking crashing towers? FUD!</title>
		<description><![CDATA[It&#8217;s interesting to read a news about an anti-jailbreaking statement by apple that say that with jailbreaked phones it may be possible to crash mobile operator&#8217;s towers:

By tinkering with this code, “a local or international hacker could potentially initiate commands (such as a denial of service attack) that could crash the tower software, rendering the [...]]]></description>
		<link>http://infosecurity.ch/20090730/iphone-jailbreaking-crashing-towers-fud/</link>
			</item>
</channel>
</rss>
