<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7069852322886703926</id><updated>2012-01-08T04:30:25.184-08:00</updated><title type='text'>Domdingelom on security, fun and life</title><subtitle type='html'>coming at you live and uncensored.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>24</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-6004059545996480078</id><published>2009-02-10T13:39:00.000-08:00</published><updated>2009-02-10T13:41:20.374-08:00</updated><title type='text'>We are moving</title><content type='html'>as of now, please refer to &lt;a href="http://blog.remes-it.be"&gt;http://blog.remes-it.be&lt;/a&gt; aka 'The Security Kitchen'.&lt;br /&gt;This blog is officially closed.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-6004059545996480078?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/6004059545996480078/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=6004059545996480078' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/6004059545996480078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/6004059545996480078'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2009/02/we-are-moving.html' title='We are moving'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-4150479842911101708</id><published>2009-01-26T13:58:00.000-08:00</published><updated>2009-01-26T14:04:52.720-08:00</updated><title type='text'>because not everybody will use transparent proxies.</title><content type='html'>As I travel around and attach my laptop to different networks, I'm left to disable/enable the proxy server settings ever so often. I grew tired of it and that's why I messed around with a small vbscript that :&lt;br /&gt;a) detects whether the proxy settings are enabled or disabled&lt;br /&gt;b) asks you to reverse that state&lt;br /&gt;&lt;br /&gt;you may want to add additional code to enable disable different proxies.&lt;br /&gt;&lt;br /&gt;Here's the code :&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;const HKEY_CURRENT_USER = &amp;amp;H80000001&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;const HKEY_LOCAL_MACHINE = &amp;amp;H80000002&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;strComputer = "."&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Set oReg=GetObject("winmgmts:{impersonationLevel=impersonate}!\\"&amp;amp;_ &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; strComputer &amp;amp;"\root\default:StdRegProv")&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;strKeyPath = "Software\Microsoft\Windows\CurrentVersion\Internet Settings"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;strValueName = "ProxYEnable"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;oReg.GetDWORDValue HKEY_CURRENT_USER,strKeyPath,strValueName,dwValue&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;If dwValue = 1 Then&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; answer=Msgbox("Proxy is currently enabled. Disable it?",36)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; ProxyOn = True&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Elseif dwValue = 0 Then&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; answer=Msgbox("Proxy is currently disabled, Enable it?",36)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; ProxyOn = False&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;End if&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;If ProxyOn=False Then&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; If answer = 6 Then &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  dwValue = 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  oReg.SetDWORDValue HKEY_CURRENT_USER,strKeyPath,strValueName,dwValue&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; Elseif answer = 7 Then&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  dwValue = 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  oReg.SetDWORDValue HKEY_CURRENT_USER,strKeyPath,strValueName,dwValue&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; End if&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Elseif ProxyOn=True Then&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;If answer = 6 Then &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  dwValue = 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  oReg.SetDWORDValue HKEY_CURRENT_USER,strKeyPath,strValueName,dwValue&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Elseif answer = 7 Then&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  dwValue = 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  oReg.SetDWORDValue HKEY_CURRENT_USER,strKeyPath,strValueName,dwValue&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;End if&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;End If&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Have fun!&lt;br /&gt;Stay Secure!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-4150479842911101708?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/4150479842911101708/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=4150479842911101708' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/4150479842911101708'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/4150479842911101708'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2009/01/because-not-everybody-will-use.html' title='because not everybody will use transparent proxies.'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-8258141697601980160</id><published>2009-01-07T17:05:00.000-08:00</published><updated>2009-01-07T17:14:29.950-08:00</updated><title type='text'>why procedures are important.</title><content type='html'>&lt;span style="font-family: arial;"&gt;It's 2am as I write this blogpost and first let me give you a little history :-)&lt;br /&gt;&lt;br /&gt;The past 2 days I spent at the hospital because I went through some excrutiating pain because of a 2mm big kidney stone.  It was detected on a scan and I was instructed to drink as much fluids as possible while on painkillers and some other alleviating drugs. I also had to pee through a sift, so I would be able to find the stone if it so chose to make its exit. &lt;br /&gt;(TMI ? Maybe, but bear with me ;-) )&lt;br /&gt;&lt;br /&gt;This evening I was painfree and I was discharged from hospital (thank God, I'm back with the family again. I also chose to take my little sift home.  No stone was found yet and I wanted to see that little bugger.&lt;br /&gt;&lt;br /&gt;So, here I was, just after a shower, and I needed to pee, badly. Our bathroom is upstairs and my little sift was in the toilet room downstairs.  I was juggling with the thought of peeing upstairs, without my sift, because I was really feeling tired but I told myself 'no, you HAVE to use the sift'.&lt;br /&gt;&lt;br /&gt;I don't have to add that the stone has chosen to make its exit now.  I caught it and I'm happy.&lt;br /&gt;&lt;br /&gt;All this to tell you that, however tired or stressed you are, whatever deadline you are up against, procedures are massively important in our job.  If you decide to cut corners because you know better and/or because you think that 'one time doesn't hurt', you might as well be wrong this one time. Think about it, be flexible, but don't sacrifice procedure just for the sake of it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-8258141697601980160?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/8258141697601980160/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=8258141697601980160' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/8258141697601980160'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/8258141697601980160'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2009/01/why-procedures-are-important.html' title='why procedures are important.'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-4671842526104160535</id><published>2008-12-30T11:41:00.000-08:00</published><updated>2008-12-30T13:45:43.508-08:00</updated><title type='text'>Dear Internet, I love you</title><content type='html'>&lt;span style="color: rgb(0, 0, 0);font-family:arial;" &gt;but I don't trust you anymore.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-style: italic;font-family:courier new;font-size:85%;"  &gt;&lt;span style="color: rgb(153, 153, 153);"&gt;I remember meeting U here in the good ol' days&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:courier new;font-size:85%;"  &gt;&lt;span style="color: rgb(153, 153, 153);"&gt;I would never pick the flower of my favourite protegé&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:courier new;font-size:85%;"  &gt;&lt;span style="color: rgb(153, 153, 153);"&gt;Maybe if I would have&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:courier new;font-size:85%;"  &gt;&lt;span style="color: rgb(153, 153, 153);"&gt;Then U would not treat me this way&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:courier new;font-size:85%;"  &gt;&lt;span style="color: rgb(153, 153, 153);"&gt;U tricked me - but U will not anymore&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:courier new;font-size:85%;"  &gt;&lt;span style="color: rgb(153, 153, 153);"&gt;No, no&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:courier new;font-size:85%;"  &gt;&lt;span style="color: rgb(153, 153, 153);"&gt;I love you, but I don't trust &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 170); color: rgb(153, 153, 153);"&gt;&lt;/span&gt;&lt;span style="color: rgb(153, 153, 153);"&gt;U anymore&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;It doesn't happen very often that I can quote an appropriate Prince lyric when blogging about Information Security :-)&lt;br /&gt;&lt;br /&gt;For the third time this year this year the internet has been broken, this time it's the fact that some Certificate Authorities failed to phase out MD5 signatures from their PKI back when MD5 collisions were proven (2004). Kudos to Mr. Appelbaum and Mr. Sotirov.&lt;br /&gt;You can read all the juicy details here : &lt;a href="http://www.phreedom.org/research/rogue-ca/"&gt;http://www.phreedom.org/research/rogue-ca/&lt;/a&gt;&lt;br /&gt;Great work.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now where are we ? What can we do ?&lt;br /&gt;&lt;br /&gt;Let's list the CA's that are identified as issuing MD5-based certs in 2008 and by default trusted in our browsers :&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;         RapidSSL&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;         FreeSSL&lt;br /&gt;         TrustCenter&lt;br /&gt;         RSA Data Security&lt;br /&gt;         Thawte&lt;br /&gt;         Verisign.co.jp&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="mediumtext"  style="font-family:arial;"&gt;&lt;br /&gt;These CA's have promised to move to SHA1 as soon as possible, In the mean while it might&lt;br /&gt;be better not to trust them. That means removing them from the certificate store in your favorite&lt;br /&gt;browser. I did just that on my machines.&lt;br /&gt;&lt;br /&gt;In a business environment it's a little bit more complex.  Take your time to assess your risk, the game stores in China and Russia probably don't have sufficient stocks of PS3's, so we can assume it will take a while for the first real attack to take place ;-)&lt;br /&gt;&lt;br /&gt;An interesting feature in an Active Directory environment might be to control CA certs through Group Policy. You can export root certificates from a trusted machine, or you can download them from the different CA vendors (more cumbersome, yet more secure). The following policy allows you to push out your set of trusted CA's to your install base.&lt;br /&gt;Open Group Policy Management Console&lt;br /&gt;Open a Policy of choice or create a new one&lt;br /&gt;Goto the following policy setting :&lt;br /&gt;     Computer Configuration &gt; Windows Settings &gt; Security Settings &gt; Public Key Policies.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:arial;"&gt;And configure as needed.&lt;br /&gt;&lt;br /&gt;Ah, but by default, Windows will update the list of trusted CA's itself ... damn that :( Luckily Microsoft has thought about that :-) They're not all bad, you know.  &lt;a href="http://technet.microsoft.com/en-us/library/bb457160.aspx#EAAA"&gt;This article&lt;/a&gt; shows how&lt;br /&gt;to disable this function. The same article lays out how to disable this update feature on stand alone computers. You see, if you want to, you can be in control.&lt;br /&gt;&lt;br /&gt;Please note that Firefox keeps it's own certificate store, seperate from Windows/IE. I'm not aware of a possibility to centrally control root certificates in FF. If I stumble upon something I'll post it here in an update.&lt;br /&gt;&lt;br /&gt;Now I'm off to go break the internet using a bench of 500 Wii consoles all controled with a Wii Fit board and my Guitar hero guitar.  because after all, that is how we roll.&lt;br /&gt;&lt;br /&gt;As some wise man said : trust, but verify.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-4671842526104160535?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/4671842526104160535/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=4671842526104160535' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/4671842526104160535'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/4671842526104160535'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/12/dear-internet-i-love-you.html' title='Dear Internet, I love you'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-2816198336919540107</id><published>2008-12-29T15:16:00.000-08:00</published><updated>2008-12-29T15:26:06.037-08:00</updated><title type='text'>as it stands now this will be my last blog post</title><content type='html'>&lt;span style="font-family: arial;"&gt;Since we have been notified that the internet will break at 3.15pm CET tomorrow.  It's nice when the buzz gets at full speed and nobody knows what will happen.&lt;br /&gt;&lt;br /&gt;Anyway, Jacob Appelbaum and Alexander Sotirov are presenting &lt;a href="http://events.ccc.de/congress/2008/Fahrplan/events/3023.en.html"&gt;'Making the theoretical possible' &lt;/a&gt;&lt;br /&gt;tomorrow at 3.15pm at 25C3.&lt;br /&gt;&lt;br /&gt;With a quick count, the internet will be broken 3 times this year. First we had DNS, then Sockstress and tomorrow ... a wild guess would be DNS (again) with a wild bend to abuse SSL weaknesses ... we'll see. BGP ?&lt;br /&gt;&lt;br /&gt;If this is goodbye, it's been fun. I love you all, see you on Web 3.0 ;-)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-2816198336919540107?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/2816198336919540107/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=2816198336919540107' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/2816198336919540107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/2816198336919540107'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/12/as-it-stands-now-this-will-be-my-last.html' title='as it stands now this will be my last blog post'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-179611155365702342</id><published>2008-12-29T04:04:00.001-08:00</published><updated>2008-12-29T04:37:18.164-08:00</updated><title type='text'>on the risk of inaccurate 'assessments'</title><content type='html'>&lt;span style="font-family:arial;"&gt;I've pondered on a '$security_topic is dead' title for this blogpost, but I managed to steer clear of that one. I personally don't believe that anything (except for Antivirus ;-)) is really dead and my buddhist little toe tells me that if anything is dead, it will most probably live on in another shape or form.&lt;br /&gt;&lt;br /&gt;I've been involved in penetration tests, security assessments and audits of different kinds (both regulatory and not) and from both perspectives (as the tester and as the testee). When sitting on the tester chair, I've experienced how hard it is to translate ones findings to a proper report that, without resorting to FUD, accurately assesses the risks the customer is exposed to. On the other hand, I've been frustrated with numerous reports I received that qualified risks as High, Medium, Low and/or Red, Yellow, Green. From a customer perspective, what am I to do with these 'values' ?&lt;br /&gt;&lt;br /&gt;While a qualitative assessment is the easiest way to qualify risks, it also completely disconnects us from the business and/or the customer. When making a qualitative assessment we are not taking in account the nature of the business and the processes that our customer actually practices to run his business.&lt;br /&gt;Some practicioners refer to 'best practices' or 'good practices' (marketeers, please take a one-way ticket to a deserted island ?) but still I don't feel that this positively impacts the result of the analysis.&lt;br /&gt;&lt;br /&gt;Within the limits of a penetration test, quantitative risk assessment is nearly impossible. First and foremost because you will never* receive accurate numbers within the limited timeframe but again also, and more importantly, because as a technical tester you are completely and utterly disconnected from the business.&lt;br /&gt;Running meaningless numbers through complicated formulas and creating scatter plot&lt;br /&gt;graphs representing risks are probably comparable to trying to kill a deer by&lt;br /&gt;throwing a bullet at it. It does not work.&lt;br /&gt;&lt;br /&gt;In short :&lt;br /&gt;a) penetration tests and security assessments are, today, mostly technology oriented.&lt;br /&gt;Yes, we do assessment on the process level too, but not as much and not as thorough.&lt;br /&gt;b) results are often poorly communicated due to lack of connection with the business and/or lack of feedback from the business.&lt;br /&gt;c) customers are not up to par considering risk assessment as a vital part of doing business. Security is still the responsibility of IT.&lt;br /&gt;&lt;br /&gt;Conclusion :&lt;br /&gt;If we want to create value by providing penetration testing and security assessment services, we should stop selling 5 days, fixed prices 'solutions' providing a detailed report. We should engage with our customer on a very high level so we can first understand the business and then tailor security solutions to their needs by going through shorter iterative cycles solving problems one at a time, raising awareness throughout the business and in the end providing a company with the necessary processes to tackle security processes on their own.&lt;br /&gt;&lt;br /&gt;I'm looking forward to be a part of this in 2009.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-179611155365702342?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/179611155365702342/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=179611155365702342' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/179611155365702342'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/179611155365702342'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/12/on-risk-of-inaccurate-assessments.html' title='on the risk of inaccurate &apos;assessments&apos;'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-8432515541677784290</id><published>2008-12-21T04:23:00.000-08:00</published><updated>2008-12-21T04:32:06.064-08:00</updated><title type='text'>I have nothing more to add</title><content type='html'>&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/ZrDxe9gK8Gk&amp;hl=en&amp;fs=1"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/ZrDxe9gK8Gk&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;As I am sitting here, watching this video, I really can't say much more.  At the moments when you are not tied up in projects, deadlines, working for the boss every night and day, please think about the fact that it is all about love, life and people. &lt;br /&gt;&lt;br /&gt;From here I extend to all of you a virtual hug and the sincere wish that whatever you do, whatever you plan allows you and yours to grow.&lt;br /&gt;&lt;br /&gt;Love.&lt;br /&gt;Peace out.&lt;br /&gt;&lt;br /&gt;Wim&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-8432515541677784290?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/8432515541677784290/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=8432515541677784290' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/8432515541677784290'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/8432515541677784290'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/12/i-have-nothing-more-to-add.html' title='I have nothing more to add'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-3661396904706653566</id><published>2008-12-19T03:27:00.000-08:00</published><updated>2008-12-19T03:29:00.759-08:00</updated><title type='text'>Mankind is not an island</title><content type='html'>&lt;p&gt;&lt;span style="font-family:arial;"&gt;&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/ZrDxe9gK8Gk&amp;amp;hl=en&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/ZrDxe9gK8Gk&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;"&gt;Brilliant&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;"&gt;Emotional&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;"&gt;Genius&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-3661396904706653566?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/3661396904706653566/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=3661396904706653566' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/3661396904706653566'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/3661396904706653566'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/12/mankind-is-not-island.html' title='Mankind is not an island'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-6654090916414001192</id><published>2008-12-18T14:36:00.000-08:00</published><updated>2008-12-18T15:00:13.869-08:00</updated><title type='text'>how 800,000 people can still be wrong</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://do69.files.wordpress.com/2008/04/yves-leterme.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 197px;" src="http://do69.files.wordpress.com/2008/04/yves-leterme.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;This is not a security related post !!!&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: arial;"&gt;May I introduce to you, Mr. Yves Leterme, prime minister of our little country. In June 2007 he was elected prime minister with a whopping 800,000 votes behind his name. I'm not going to lay out the history of Belgium in this blogpost, but some of you may know we have a Dutch-speaking part (Flanders) and a French-speaking part (Wallonie). It has been a troubled marriage for the past decades and it came to no surpise Yves won so many votes by touting a far-going federal reform of the country (on the verge of seperatism). That was medio 2007. We are now at the end of 2008 and the following has happened :&lt;br /&gt;1) Mr. Leterme has not been able to form a functioning government in 18 months.&lt;br /&gt;2) Mr. Leterme was not able to deliver on his promise of a federal reform, which he promised would 'benefit' the whole country. Instead his demeanor drove a wedge between the two parts of Belgium and mutual understanding has been far gone since his appearance on the main stage.&lt;br /&gt;3) In 09/2008, 10/2008, the financial crisis hit. Big Belgian banks (Fortis, Dexia) got into trouble and were bailed out by the Belgian government. This was the moment Yves proved himself to be quite the leader, or so he thought. He messed up countless times, lied about the European authorities not being reachable while decisions were being made. Mrs. Kroes proved him wrong on national television. Talking about humiliation.&lt;br /&gt;4) Shareholders took the Belgian government to court over the Fortis deal, because Yves decided to move fast and sell off the left-overs to BNP Paribas without consulting the shareholders. And this is where his amateurism culminates. While the higher courts were deliberating the case. Mr. Letermes minions decided it was time to 'intervene', putting pressure on judges to rule in favor of the government. This was brought out in parliament yesterday and today and in more than 24 hours, the Belgian government has not been able to formulate an answer to its defense or say something sensible about the shit we're in. &lt;br /&gt;&lt;br /&gt;All this while the global financial crisis is developing at rapid speed, corporations are struggling to stay afloat and workers are scared senseless about their future.  While some say worse than having a disfunctional government is having no government at all, I am not so sure. When we wake up tomorrow morning, Mr. Leterme is no longer a leader, he is an incompetent person grasping to power, while knowing he does not have the ability to make right what he did wrong, nor does he have the power to control the crisis at hand. Mr. Yves Leterme will be a lame duck. Sure we will suffer with no government but at least he won't be able to do further damage.&lt;br /&gt;&lt;br /&gt;Mr. Leterme,&lt;br /&gt;While you were cheering when you 'won' the elections, you knew you didn't have it in you, didn't you ? You knew that it all was a big fat lie just to be part of history. Did you think about 'the people' at that time ? Did you think about the fact that your power-hunger would have an impact on 10,000,000 people ? You fucked up, realize it, step down and let us move forward.&lt;br /&gt;Thanks.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-6654090916414001192?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/6654090916414001192/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=6654090916414001192' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/6654090916414001192'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/6654090916414001192'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/12/how-800000-people-can-still-be-wrong.html' title='how 800,000 people can still be wrong'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-6011454703276405357</id><published>2008-12-13T06:15:00.001-08:00</published><updated>2008-12-13T06:18:28.611-08:00</updated><title type='text'>the internet police is here</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_jSNQUBsBtUE/SUPD9CgJ0YI/AAAAAAAAAeU/OKnkyuaihr8/s1600-h/airshoot.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 240px; height: 320px;" src="http://3.bp.blogspot.com/_jSNQUBsBtUE/SUPD9CgJ0YI/AAAAAAAAAeU/OKnkyuaihr8/s320/airshoot.JPG" alt="" id="BLOGGER_PHOTO_ID_5279278641619521922" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: center; font-weight: bold; font-family: verdana;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Out to take on all the internet crooks :-)&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-6011454703276405357?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/6011454703276405357/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=6011454703276405357' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/6011454703276405357'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/6011454703276405357'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/12/internet-police-is-here.html' title='the internet police is here'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_jSNQUBsBtUE/SUPD9CgJ0YI/AAAAAAAAAeU/OKnkyuaihr8/s72-c/airshoot.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-8326579159624068422</id><published>2008-12-13T05:21:00.000-08:00</published><updated>2008-12-13T06:05:15.756-08:00</updated><title type='text'>Belgian bank accounts compromised</title><content type='html'>&lt;span style="font-family: arial;"&gt;As I'm reading through the Belgian news, there's a report about hackers compromising about a dozen Belgian bank accounts.  The bank involved is not named, but it would be one of the bigger banks in Belgium, either Fortis, Dexia or KBC. Belgian law enforcement has started an investigation, no doubt this will die a silent death.  What's even more worrysome is that all banks I know, in Belgium, use two-factor authentication. Not unbreakable, but still pretty rigidly implemented. &lt;br /&gt;&lt;br /&gt;However, what struck me most is the comment by Febelfin, an organisation grouping Belgian financial institutions.  Here's what they said :&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; color: rgb(255, 0, 0);"&gt;"You are safe if you are running a regularly updated antivirus application."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Allow me to disagree, and I don't even want to bring this down to a "AV is dead" post, cuz we all&lt;br /&gt;know we had too much of that lately ;-) However, what amazes me the most is that a professional organisation that (especially in these times, cuz they f'd up mucho lately) dares to come with as lame an advice as this.  If you truly care about your customers and their money, I'd expect a little more than this. If you truly care about your customers, come out and tell us how this happened and what your customers can really do to protect themselves (which, in the current situation is close to nothing).  If you truly care about your customers, take up your responsibility and disclose. &lt;br /&gt;&lt;br /&gt;I'm not accepting "protecting the investigation" or "protecting the customers", you and I know the culprits are long gone and/or hiding behind networks and servers hosted in far away lands.&lt;br /&gt;&lt;br /&gt;I don't expect to be answered though ... but at least I got to rant ;-)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-8326579159624068422?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/8326579159624068422/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=8326579159624068422' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/8326579159624068422'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/8326579159624068422'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/12/belgian-bank-accounts-compromised.html' title='Belgian bank accounts compromised'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-1889899797432784558</id><published>2008-12-10T15:53:00.000-08:00</published><updated>2008-12-10T16:03:18.900-08:00</updated><title type='text'>All the praying in the world won't save you.</title><content type='html'>&lt;span style="font-family: arial;"&gt;While watching the news on our local news station tonight, I saw an item on a Belgian&lt;br /&gt;priest that had his Outlook (looked like 2000 to me) crash on him. The result of this event was&lt;br /&gt;the loss of all weddings, baptisms and other church events for the coming weeks and months.&lt;br /&gt;I'm pretty convinced that most parish members won't move to another parish because of this&lt;br /&gt;event, but if this were the hard-working plumber (by brother is one and no his name is not Joe), carpenter this would have hit hard.&lt;br /&gt;&lt;br /&gt;Imagine that you have planned your wedding on January 22nd, it is now just another free date. Someone else might book the spot and knowing how bridezillas can behave (let alone groomillas) it ain't gonna be a pretty sight.  It might even cost a dime (or two). &lt;br /&gt;&lt;br /&gt;God might be everywhere, but he isn't on your harddrive, saving your bytes.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-1889899797432784558?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/1889899797432784558/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=1889899797432784558' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/1889899797432784558'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/1889899797432784558'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/12/all-praying-in-world-wont-save-you.html' title='All the praying in the world won&apos;t save you.'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-3178405045738305546</id><published>2008-12-10T15:38:00.001-08:00</published><updated>2008-12-10T15:53:13.349-08:00</updated><title type='text'>IM spam is not dead yet</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_jSNQUBsBtUE/SUBTHkdh57I/AAAAAAAAAeM/E8gknu_X5eo/s1600-h/MSNspam.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 123px;" src="http://2.bp.blogspot.com/_jSNQUBsBtUE/SUBTHkdh57I/AAAAAAAAAeM/E8gknu_X5eo/s200/MSNspam.JPG" alt="" id="BLOGGER_PHOTO_ID_5278310152789944242" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;it doesn't happen very often. For me about once a month and mostly from the same people :( I guess some just never learn.  Todays domain was just.realcoolss.com, a name that resolved to 208.116.34.163, which is an IP address in the block 208.116.0.0/18 owned by FortressITX in New Jersey and the domain name is owned by Jeff Fisher of TST Management Inc in ... Panama.&lt;br /&gt;Based on my originating IP address I'm redirected a Dutch webpage for a subscription service.&lt;br /&gt;No malware involved on first sight.&lt;br /&gt;&lt;br /&gt;Spam is international, spam is global and apparently, spam is still ota lucrative. I guess we should consider spam a cloud service.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-3178405045738305546?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/3178405045738305546/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=3178405045738305546' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/3178405045738305546'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/3178405045738305546'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/12/im-spam-is-not-dead-yet.html' title='IM spam is not dead yet'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_jSNQUBsBtUE/SUBTHkdh57I/AAAAAAAAAeM/E8gknu_X5eo/s72-c/MSNspam.JPG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-2633580556356371893</id><published>2008-12-03T04:13:00.000-08:00</published><updated>2008-12-03T04:21:09.389-08:00</updated><title type='text'>When I read blogs I don't want to be annoyed ...</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_jSNQUBsBtUE/STZ4Y2tXb1I/AAAAAAAAAc8/ygrjN5JdgZs/s1600-h/noscript.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 168px; height: 320px;" src="http://3.bp.blogspot.com/_jSNQUBsBtUE/STZ4Y2tXb1I/AAAAAAAAAc8/ygrjN5JdgZs/s320/noscript.JPG" alt="" id="BLOGGER_PHOTO_ID_5275536381909102418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;with so many dependencies !&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;If you are a blogger and force me (as a reader) to&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;allow (or temporary allow, or forbid) some or all of these sites to make&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;visiting your site at least enjoyable, you're wrong.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;I love my Noscript, some might argue that it's Noscript that&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;makes my life difficult. I beg to differ.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;I love lean blogs, if you expect people to read your blog, try to keep it lean as well.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;kthxbai&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;PS : if you recognize your blog, go do your job :-)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-2633580556356371893?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/2633580556356371893/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=2633580556356371893' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/2633580556356371893'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/2633580556356371893'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/12/when-i-read-blogs-i-dont-want-to-be.html' title='When I read blogs I don&apos;t want to be annoyed ...'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_jSNQUBsBtUE/STZ4Y2tXb1I/AAAAAAAAAc8/ygrjN5JdgZs/s72-c/noscript.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-2052271032524235447</id><published>2008-12-01T06:03:00.000-08:00</published><updated>2008-12-01T13:48:50.287-08:00</updated><title type='text'>all your twitter are belong to us</title><content type='html'>&lt;span style="font-family:arial;"&gt;This is a follow up to my post of earlier today, where I noticed that authentication on twitter.com worked no matter what the password safed in FF3 was. I delved a little deeper and came to this&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;conclusion:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;A propietary cookie named auth_token is send with any GET to twitter.com (both http and https).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;This cookie contains a hashed value that never changes, not over time, not when you change your password and not when you change machines. Your auth_token will always be the same. I first&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;checked in IE and FF3 on my Windows XP laptop, then I verified on my Macbook. It's all the same&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;as a test, I created a auth_token cookie (using the Add n Edit FF3 plugin) on a Fresh Ubuntu linux clone and lo and behold, I was not requested to login, it took me directly to my personal Twitter homepage. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;As twitter gains more and more traction in the enterprise, I can only imagine the possibilities ... &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;Using the https twitter site would be good to mitigate this problem but your company might still use a transparent https proxy, exposing your twitter credential. Twhirl (a twitter client) uses the https variant by default. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;What twitter could do is obvious, make the auth_token an expiring cookie (preferably at end of session) and make it unique, by salting it. When somebody much smarter than me finds on which parameters the auth_token is based, twitter is gone.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family:Arial;"&gt;Update !!&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;Thanks to &lt;a href="https://www.twitter.com/DidierStevens"&gt;@DidierStevens&lt;/a&gt; : the auth_token cookie is not created when you do not select the Remember me option.  &lt;a href="https://www.twitter.com/security4all"&gt;@Security4All&lt;/a&gt; also has some interesting tips in the comments.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;Update 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;DidierStevens (in the comments) did some follow-up research and if it is a hash (which it seems to be, based on the length either SHA-1 or RIPEMD-160) it is not based on username, name, id or e-mail address. Changing either of these parameters doesn't change the value of the cookie (or invalidate it). Didier, thanks for following up. I will look into this further soon as I am still waiting for feedback from Twitter after reporting this. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-2052271032524235447?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/2052271032524235447/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=2052271032524235447' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/2052271032524235447'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/2052271032524235447'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/12/all-your-twitter-are-belong-to-us.html' title='all your twitter are belong to us'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-8863746559959665949</id><published>2008-12-01T00:54:00.000-08:00</published><updated>2008-12-01T01:09:20.897-08:00</updated><title type='text'>Is firefox+twitter+https messing with me ?</title><content type='html'>&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;first thing in the morning? Coffee, then check on twitter, that is if I can. So I start FF3 and browse to &lt;a href="https://www.twitter.com/"&gt;https://www.twitter.com/&lt;/a&gt;. Https, because that is how I roll. &lt;/div&gt;&lt;br /&gt;&lt;div&gt;Now, for one reason or the other I decide to click on the little lock on the bottom right and check out security on the website and this is what it says to me :&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://1.bp.blogspot.com/_jSNQUBsBtUE/STOnJ4oAMXI/AAAAAAAAAcM/7Kp28WjfaZ4/s1600-h/pagesecinfo.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5274743376841814386" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 320px; CURSOR: hand; HEIGHT: 266px" alt="" src="http://1.bp.blogspot.com/_jSNQUBsBtUE/STOnJ4oAMXI/AAAAAAAAAcM/7Kp28WjfaZ4/s320/pagesecinfo.JPG" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Apparently I've visited this website 64 times today. I'm sorry, but I'm not THAT addicted :)&lt;/p&gt;&lt;a href="http://4.bp.blogspot.com/_jSNQUBsBtUE/STOnqgkcRXI/AAAAAAAAAcU/73K94PPQ9Iw/s1600-h/savedpw.bmp"&gt;&lt;img id="BLOGGER_PHOTO_ID_5274743937320109426" style="FLOAT: right; MARGIN: 0px 0px 10px 10px; WIDTH: 247px; CURSOR: hand; HEIGHT: 320px" alt="" src="http://4.bp.blogspot.com/_jSNQUBsBtUE/STOnqgkcRXI/AAAAAAAAAcU/73K94PPQ9Iw/s320/savedpw.bmp" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;Moreover, it says I have no passwords saved yet it logged me in automagically, so lets click through on the View Saved Passwords button. I would expect it to be grayed out since there are no passwords saved. Damn, it even has the correct username, how would it otherwise be able to log me in? Indeed. So I click the Show passwords button and it reveals my password. Sorry, let me rephrase that, Firefox reveals A password but not my current password.&lt;/p&gt;&lt;p&gt;WTF ?&lt;/p&gt;&lt;p&gt;I tried this again and again, same behaviour. How can it log me in with a wrong password. At this moment it looks like the culprit is the auth token, which is a cookie saved and set to expire 20 years from now. &lt;/p&gt;&lt;p&gt;I'll have to get back to this since duty calls but FF3+Twitter right now doesn't feel like the right combination. If anybody can and/or wants to shine a light on this behaviour, I'm open to suggestions.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-8863746559959665949?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/8863746559959665949/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=8863746559959665949' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/8863746559959665949'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/8863746559959665949'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/12/is-firefoxtwitterhttps-messing-with-me.html' title='Is firefox+twitter+https messing with me ?'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_jSNQUBsBtUE/STOnJ4oAMXI/AAAAAAAAAcM/7Kp28WjfaZ4/s72-c/pagesecinfo.JPG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-7793597754268534842</id><published>2008-11-18T14:33:00.000-08:00</published><updated>2008-11-18T14:58:59.139-08:00</updated><title type='text'>Ten not-so-good practices for avoiding data loss during layoffs</title><content type='html'>&lt;span style="font-family:arial;"&gt;Richard Stiennon &lt;a href="http://www.networkworld.com/community/node/35375"&gt;blogged&lt;/a&gt; about 'best' practices for data protection during these difficult economic times.  I can see where they come from and I can comprehend the business logic behind them, I do have a problem with most of the suggested 'best' practices ... lemme explain&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;1. Restate and re-publish your organization policy on confidential information. Require everyone in the company to sign it.&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;if you have a policy and it is not signed off on, you're a dork.  Assume you have some disgruntled employees, after requiring everybody to sign off on the policy you will have a shitload of disgruntled employees. These people will know what you are up to. People are not stupid cows, you're just covering your bases. How are you gonna pick up the pieces when recovery starts ? You're throwing all your HR management principles out of the window.  Good luck&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;4.    Identify and restrict access to key data such as employee records, resumes, customer lists, and financial statements.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;well yeah ... if it's touch or go, this is a project worth spending your valuable money on. For one it's gonna f* up your business processes if handled in haste and you'll spend money that you could better use in places where they actually benefit the business at this moment.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;5. Log, monitor and audit employee online actions&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I'm not even going into privacy isses here. but logging and monitoring would assume you have a baseline to compare anomalies against.  Again, starting 'now' because times are precarious is too late and it's also wasting precious resources which (when laying off people) are only gonna get scarcer.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;7. Use extra caution with system admins and privileged users.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;if you have over-privileged users, and that's what you're talking about here, you haven't been really on-par with your security efforts.  Extra caution is not gonna help you much, it is also not a very measurable security control.&lt;br /&gt;&lt;br /&gt;All in all, I'm mostly appalled by the disrespect these 'best' practices show for the people that worked their ass off for you in the past years. Yes, the people that pulled all nighters for meeting deadlines and those people that in your (the average managers) eyes represent costs (-$$).&lt;br /&gt;If this is the time to justify security controls, you're one bad-ass CISO, CSO or whatever title you carry.&lt;br /&gt;&lt;br /&gt;I'm not saying security controls (including those in the above-mentioned article) are not worth it, but NOW ? I'm sorry, it's too little, too late.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-7793597754268534842?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/7793597754268534842/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=7793597754268534842' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/7793597754268534842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/7793597754268534842'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/11/ten-not-so-good-practices-for-avoiding.html' title='Ten not-so-good practices for avoiding data loss during layoffs'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-5261094641164849081</id><published>2008-11-14T04:25:00.000-08:00</published><updated>2008-11-14T04:37:14.824-08:00</updated><title type='text'>Belgian wardriver not punished</title><content type='html'>&lt;span style="font-family:arial;"&gt;When earlier this year a wardriver was arrested for using an unprotected network, everybody thought a precedent would be set. About 6 months later (yes, the Belgian justice system is fast like that), he was convicted but he does not have to serve time (about 1 year).  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;How did he get caught ? A passer-by found it suspicious that someone was using his laptop from a car and called the cops.  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;The whole case leaves me with some questions :&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;How did the cops make sure he wasn't using a 3G card for internet connectivity ?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;How did they confiscate and forensically investigated his laptop to prove that he had been using that specific network? Did they actually do that ?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;How did they forensically investigate the router/WAP to prove that he had been connected to that specific network? Did they actually do that ?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;If not, I don't think they can have a legal case. If the case wasn't build with forensic evidence and just on testimony by 'the neighbour', the network owner (residential network) and/or the wardriver, I do get a little concerned.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;Unfortunately I don't have access to legal cases ... I would love to go through those details ...&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-5261094641164849081?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/5261094641164849081/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=5261094641164849081' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/5261094641164849081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/5261094641164849081'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/11/belgian-wardriver-not-punished.html' title='Belgian wardriver not punished'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-1071060608282770788</id><published>2008-11-10T13:17:00.000-08:00</published><updated>2008-11-10T13:41:34.557-08:00</updated><title type='text'>Selling Vodka or selling security solutions ... an analogy.</title><content type='html'>&lt;span style="font-family:arial;"&gt;As I was waiting in line @ the nightshop I was pondering and it hit me hard.  In front of me was a man, drunk as a skunk, completely wasted.  He needed 10 minutes to collect his change from the counter after buying a bottle of Vodka.  This was one of those moments ... Why did this shop clerk sell 75cl of Vodka to a person that was clearly completely unaware of himself ? I know there are laws here in Belgium that should prevent this from happening but Belgian law is a little like a corporate security policy, there's a vast amount of paper covering Belgian law, but there's not a lot of it that's actually enforced.&lt;br /&gt;&lt;br /&gt;The analogy is clear. As a reseller or an integrator, we try to deliver quality service to our customer. That's our added value, it's basically who we are, what makes us different from the shop next door. Or does it ?&lt;br /&gt;&lt;br /&gt;I feel, more often than not, that the quality that sets us apart is sacrificed for the sell.  While we realize that a certain product (within our portfolio) is not as good a match as another product we don't master, and it may fit the requirements today but maybe not 1,5 years from now, it will get sold. And the customer will have to live with the consequences. This doesn't hurt the relationship because the project definition doesn't mention those future requirements and 1,5 years from now ... Mr X will probably not think about that past project, so everything is a-ok.&lt;br /&gt;&lt;br /&gt;To me it isn't. While we tout that "IT should align with the bizniz" and "We, as integrator Y, think of YOUR business first", we don't very often put our money where our mouth is. The sell counts, it adds to todays bottom line of OUR business, the fact that the customer will have to overhaul that specific part of his infrastructure/solution in 24 months or something, buying new gadgets, training his people, aligning the new stuff once again with his business (or worst, aligning his business with his new stuff) ... might be the least of our worries.&lt;br /&gt;&lt;br /&gt;Is ethic important to you while doing business? Especially security business ? What's your thoughts ?&lt;br /&gt;&lt;br /&gt;My thoughts : ethics in doing security business is #1 , making money is one thing, making money and jeopardizing businesses is something completely different.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-1071060608282770788?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/1071060608282770788/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=1071060608282770788' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/1071060608282770788'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/1071060608282770788'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/11/as-i-was-waiting-in-line-nightshop-i.html' title='Selling Vodka or selling security solutions ... an analogy.'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-3059641099960567601</id><published>2008-11-07T16:09:00.000-08:00</published><updated>2008-11-07T16:11:14.798-08:00</updated><title type='text'>countering spam with a vengeance.</title><content type='html'>&lt;span style="font-family: arial;"&gt;You know them, heartwarming stories that try to tear you up about kids, sick people, adoptions gone awry ... whatever. It never seems to stop, until I received this one.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;In 1986, Peter Davies was on holiday in Kenya after graduating from Northwestern University . &lt;br /&gt;&lt;br /&gt;On a hike through the bush, he came across a young bull elephant standing with one leg raised in the air. The elephant seemed distressed, so Peter approached it very carefully.&lt;br /&gt;&lt;br /&gt;He got down on one knee, inspected the elephants foot, and found a large piece of wood deeply embedded in it. As carefully and as gently as he could, Peter worked the wood out with his knife, after which the elephant gingerly put down its foot. The elephant turned to face the man, and with a rather curious look on its face, stared at him for several tense moments. Peter stood frozen, thinking of nothing else but being trampled. Eventually the elephant trumpeted loudly, turned, and walked away. Peter never forgot that elephant or the events of that day.&lt;br /&gt;&lt;br /&gt;Twenty years later, Peter was walking through the Chicago Zoo with his teenaged son. As they approached the elephant enclosure, one of the creatures turned and walked over to near where Peter and his son Cameron were standing. The large bull elephant stared at Peter, lifted its front foot off the ground, then put it down. The elephant did that several times then trumpeted loudly, all the while staring at the man.&lt;br /&gt;&lt;br /&gt;Remembering the encounter in 1986, Peter could not help wondering if this was the same elephant. Peter summoned up his courage, climbed over the railing, and made his way into the enclosure. He walked right up to the elephant and stared back in wonder. The elephant trumpeted again, wrapped its trunk around one of Peter legs and slammed him against the railing, killing him instantly.&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;br /&gt;&lt;strong&gt;Probably wasn't the same fucking elephant. &lt;/strong&gt;&lt;strong&gt;This is for everyone who sends me those heart-warming bullshit stories.&lt;/strong&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-3059641099960567601?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/3059641099960567601/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=3059641099960567601' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/3059641099960567601'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/3059641099960567601'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/11/countering-spam-with-vengeance.html' title='countering spam with a vengeance.'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-2456385608743395258</id><published>2008-11-05T14:02:00.000-08:00</published><updated>2008-11-05T15:10:41.670-08:00</updated><title type='text'>can we escape from password hell ?</title><content type='html'>&lt;span style="font-family: arial;"&gt;You know the drill, ever so often (30 days ? 45 days ? 3 months ?) you are required to change your password in each and every business application. Sometimes you're lucky and some applications share a common directory, good for you but most often this is not the case.  If this drill is accompanied with a requirement for complex Pa$$w0rd5 , sticky notes are your saviour whether your CISO likes it or not.  And we're back to square one, welcome to password hell.&lt;br /&gt;&lt;br /&gt;In comes the holy grail : (enterprise) SSO. Finally there's an application that takes over the management of all your passwords, leaving you with one (preferably complex) password to logon to your computer and no headaches afterwards.  But is this really true ? What are the caveats ? What should you look for in an eSSO solution and what are the problems you might face during rollout ?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What is eSSO ?&lt;br /&gt;&lt;/span&gt;enterprise Single Sign-On solutions allow you to reduce the # of times your users have to provide a username and password to an application (any application ?). Most of the solutions work through technology that 'recognizes' logon screens which is matched to a specific userid+password combination in a password safe.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Who are the competitors &lt;/span&gt;(I only list the top 4 in the &lt;a href="http://mediaproducts.gartner.com/reprints/ca/160413.html"&gt;Gartner magic quadrant&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Imprivata&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Citrix &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Passlogix&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: arial;"&gt;Evidian&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-family: arial;"&gt;* disclaimer : I do not comment on the specific vendors solutions.  It is up to the reader to&lt;br /&gt;select the solution that best fits his/her needs.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: arial;"&gt;&lt;span style="font-weight: bold;"&gt;What does it offer ?&lt;/span&gt;&lt;br /&gt;a) your users don't have to worry about changing several passwords anymore. They keep one single password that allows them access to their workstation, then the eSSO software takes over. Simple, easy peasy (or maybe not). &lt;br /&gt;b) Obviously this will reduce the time your helpdesk people spend on password resets, how much that is greatly depends on your organisation. Quantifying this cost is often difficult.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;And now ?&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;We don't really care about users do we ? Why would we want a solution that makes their life easier? Well there's a number of reasons. &lt;br /&gt;&lt;br /&gt;A. You might be driven by compliance regulations. While your applications might not support detailed user access logging, your eSSO solution can do that for you, uniformely over all your applications.&lt;br /&gt;B. Your users' drawers (desks !!) look like craigslist.com for passwords.  Passwords are traded, especially during holiday seasons, when specific responsibilities are informally delegated. Some solutions allow formal delegation among users without disclosing the password. This is a powerful tool and worth considering. &lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;C. You have decided to implement an Identity and/or Access Management solution, while eSSO certainly isn't IAM, it may prove an important part of the puzzle.  A properly deployed eSSO solution will get you buy-in from the workfloor and allow you to embark on the long and hard journey that your IAM roll-out will be. &lt;br /&gt;D. You actually care about your users, productivity and the protection of your information resources.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Ok, so tell me now, where is the bad stuff you refuse to tell me ?&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;Different vendors, different solutions.  Almost all of them will offer you a replacement for the microsoft GINA (msgina.dll), which means they come and mess in the basic login process of your windows environment.  Call it a corporate wide Man in the Middle attack if you will, it is what it is. Take a good look at this GINA during PoC, because some might not have all functionality implemented (I've seen GINA replacements that didn't include a password expiration/rotation function !!!). Additionally, take a careful look at what your needs are. If you take this project on, define your goals and don't submit to scope creep (your worst enemy), nifty features might be tempting, but featurism can get you (and your project) killed. It's better to work in short cycles, adding functionality in every cycle than ending up in a high-speed vortex that leaves you and your users with a broken solution.&lt;br /&gt;&lt;br /&gt;Appliances, appliances, they look shiny and tempting. Yet, that box represents a single point of failure.  Yes you can have 2 boxes and make them redundant, how redundant depends on the solution, do they support Active/Active failover ?  Some of the solutions work with middleware installed on a server while all properties are stored in the LDAP directory of your choice. Cool, your corporate directory is already redundant and there's no black box to be worried about. Transparency FTW !!! Consider it.  &lt;br /&gt;&lt;br /&gt;Make an application inventory and start of with a PoC for your most critical applications. Most vendors will tout to support any application. They don't.&lt;br /&gt;Java applications are the most work-intensive.  There's some very special magic to be performed to make them work with SSO. Sometimes simply installing the SSO client can already break all your Java-based apps (don't get me started over Oracle Forms, Oracle Frommels for the Dutch speaking).&lt;br /&gt;&lt;br /&gt;To conclude this installment, there's the possibility of adding 2-factor authentication (2FA) to the solution.  Yes, I'm talking the "something you have/know/are" combination, but not in the RSA, Vasco, (add OTP vendor here), sense of the word. Most of the companies I know use RFID badges for Access Control, it is fairly easy to also use them in any eSSO solution so users need their card and their password (or a pincode) to logon.  I know RFID is broken beyond repair, I know it has been haXored, don't worry ... I'm aware.&lt;br /&gt;Make sure you only use them for identification and let the authentication of the user depend on either the "something you know" (password/pin) or "something you are" (biometry) factor.&lt;br /&gt; &lt;br /&gt;I will elaborate on the possibilities of 2FA in eSSO solutions later this week, talking about smart cards, active and passive RFID, eID and PKI.  For now, I hope you enjoyed the read. Stay safe !&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-2456385608743395258?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/2456385608743395258/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=2456385608743395258' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/2456385608743395258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/2456385608743395258'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/11/can-we-escape-from-password-hell.html' title='can we escape from password hell ?'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-1965475961832822375</id><published>2008-11-02T14:01:00.000-08:00</published><updated>2008-11-02T14:14:48.449-08:00</updated><title type='text'>The French crack down on illegal downloads</title><content type='html'>&lt;span style="font-family:arial;"&gt;On Friday, the EUObserver came with an interesting article on a new French law (http://euobserver.com/9/27026) that will introduce a cut-off from internet access for people that are caught 3 times illegally downloading copyrighted content.&lt;br /&gt;&lt;br /&gt;To me, it's mind-boggling how the recording industry lobby has been able to push the French in accepting such a law. There was an amendment requesting to replace the cut-off by a fine but that was not accepted because "&lt;/span&gt;The principle of a financial penalty changes the philosophy [of the bill], from instructive to repressive". &lt;span style="font-family:arial;"&gt;And that in times where e-government is becoming more and more of a reality. Would we really allow a citizen or a family to be cut off from the intertubez for a year (yes, 365 jours !!) ? Is making them pay XXX euros less repressive ? &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;That's what you get when your prez marries a recording artist (* I'll leave the interpretation of the word artist to the readers discretion).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-1965475961832822375?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/1965475961832822375/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=1965475961832822375' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/1965475961832822375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/1965475961832822375'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/11/on-friday-euobserver-came-with.html' title='The French crack down on illegal downloads'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-8113329595331089570</id><published>2008-10-31T02:37:00.000-07:00</published><updated>2008-10-31T02:50:53.727-07:00</updated><title type='text'>does Twitter suck ?</title><content type='html'>&lt;span style="font-family: arial;"&gt;Social media is what it is, you either love it or you hate it.  Mark Horstman from &lt;/span&gt;&lt;a style="font-family: arial;" href="http://www.blogger.com/www.managertools.com"&gt;Manager tools&lt;/a&gt; ranted on twitter in his most recent audio blog "Twitter, I hate it". I love the Manager Tools podcast (I am a regular listener) and I obviously am nowhere near a C-suit position (nor do I aspire to be), it provides me with some interesting tidbits I can use in my daily busi-business. If for nothing else but to understand my bosses better :-). On this I have to disagree however. Twitter in and of itself is not the problem Mark, it is how you use it. If used wisely, it is a tool that a C-suit can use to be closer to the workfloor and/or the customer. the EULA of Twitter doesn't say you have to be constantly connected nor do your 'friends' have to expect you are. &lt;a style="font-family: arial;" href="http://www.blogger.com/search.twitter.com"&gt;twitter search&lt;/a&gt;&lt;span style="font-family: arial;"&gt; provides you a tool that you can use to find users' comments on your company, brand, product name. You can just review private messages once in a while. For instance, Guy Kawasaki uses it, do you think he reads all messages from his 20k+ followers ? I don't think so. Lance Armstrong is on Twitter, he has 2k+ followers and is following 2 profiles himself. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;let's say it like this, Twitter is the nail, you choose how you hold the hammer.   &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-8113329595331089570?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/8113329595331089570/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=8113329595331089570' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/8113329595331089570'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/8113329595331089570'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/10/does-twitter-suck.html' title='does Twitter suck ?'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7069852322886703926.post-3240105178729566058</id><published>2008-10-28T03:12:00.000-07:00</published><updated>2008-10-28T03:17:10.768-07:00</updated><title type='text'>A new beginning</title><content type='html'>&lt;span style="font-family:arial;"&gt;I've been blogging for a while now, back at &lt;a href=http://www.remes-it.be&gt;www.remes-it.be&lt;/a&gt;. While it's fun to own and maintain my own site, it's also quite labor-intensive and it uses time that I'd rather spend on other things.&lt;br /&gt;&lt;br /&gt;From here on of, I'll use this blogspace for my weekly musings on information security, what keeps me buzzing and life in general.&lt;br /&gt;&lt;br /&gt;Be Secure,&lt;br /&gt;&lt;br /&gt;Wim&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7069852322886703926-3240105178729566058?l=domdingelom.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://domdingelom.blogspot.com/feeds/3240105178729566058/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7069852322886703926&amp;postID=3240105178729566058' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/3240105178729566058'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7069852322886703926/posts/default/3240105178729566058'/><link rel='alternate' type='text/html' href='http://domdingelom.blogspot.com/2008/10/new-beginning.html' title='A new beginning'/><author><name>Wim Remes</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh5.googleusercontent.com/-XA-KgwdKQcE/AAAAAAAAAAI/AAAAAAAAAo0/Yl_qRJIeocs/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry></feed>
