<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ChrisAshworth.org &#187; Security</title>
	<atom:link href="http://chrisashworth.org/blog/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://chrisashworth.org/blog</link>
	<description></description>
	<lastBuildDate>Sun, 27 Nov 2011 02:54:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Ten Hopes</title>
		<link>http://chrisashworth.org/blog/2010/06/21/ten-hopes/</link>
		<comments>http://chrisashworth.org/blog/2010/06/21/ten-hopes/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 13:34:16 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Art]]></category>
		<category><![CDATA[Baltimore]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://chrisashworth.org/blog/?p=522</guid>
		<description><![CDATA[Wendell Berry speaking at a college commencement in 1989. Submitted without comment. Beware the justice of Nature. Understand that there can be no successful human economy apart from Nature or in defiance of Nature. Understand that no amount of education can overcome the innate limits of human intelligence and responsibility. We are not smart enough [...]]]></description>
			<content:encoded><![CDATA[<p>
Wendell Berry speaking at a college commencement in 1989. Submitted without comment.
</p>
<blockquote>
<ol>
<li>Beware the justice of Nature.</li>
<li>Understand that there can be no successful human economy apart from Nature or in defiance of Nature.</li>
<li>Understand that no amount of education can overcome the innate limits of human intelligence and responsibility. We are not smart enough or conscious enough or alert enough to work responsibly on a gigantic scale.</li>
<li>In making things always bigger and more centralized, we make them both more vulnerable in themselves and more dangerous to everything else. Learn, therefore, to prefer small-scale elegance and generosity to large-scale greed, crudity, and glamour.</li>
<li>Make a home. Help to make a community. Be loyal to what you have made.</li>
<li>Put the interest of the community first.</li>
<li>Love your neighbors–not the neighbors you pick out, but the ones you have.</li>
<li>Love this miraculous world that we did not make, that is a gift to us.</li>
<li>As far as you are able make your lives dependent upon your local place, neighborhood, and household–which thrive by care and generosity–and independent of the industrial economy, which thrives by damage.</li>
<li>Find work, if you can, that does no damage. Enjoy your work. Work well.</li>
</ol>
</blockquote>
<p>
<small>Discovered via <a href="http://theatretact.org/?p=250">Scott Walters</a>.</small>
</p>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fchrisashworth.org%2Fblog%2F2010%2F06%2F21%2Ften-hopes%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fchrisashworth.org%2Fblog%2F2010%2F06%2F21%2Ften-hopes%2F&amp;source=Chris_Ashworth&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://chrisashworth.org/blog/2010/06/21/ten-hopes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Uphill Battle</title>
		<link>http://chrisashworth.org/blog/2009/02/10/uphill-battle/</link>
		<comments>http://chrisashworth.org/blog/2009/02/10/uphill-battle/#comments</comments>
		<pubDate>Tue, 10 Feb 2009 14:40:07 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Design]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://chrisashworth.org/blog/?p=197</guid>
		<description><![CDATA[What happens when you don&#8217;t start a software project looking at it from the user&#8217;s perspective? This happens: I tried once or twice to press this point when I was serving my brief stint in the security world. Unfortunately I didn&#8217;t have much clout with the big names of SELinux, because I&#8217;ve never been a [...]]]></description>
			<content:encoded><![CDATA[<p>
What happens when you don&#8217;t start a software project looking at it from the user&#8217;s perspective?
</p>
<p>
This happens:
</p>
<p class="center">
<img src="http://chrisashworth.org/blog/wp-content/uploads/2009/02/disable-selinux.png" alt="disable-selinux.png" border="0" width="364" height="323" />
</p>
<p>
I tried once or twice to press this point when I was serving my brief stint in the security world.  Unfortunately I didn&#8217;t have much clout with the big names of SELinux, because I&#8217;ve never been a &#8220;real&#8221; security guy.  I was more of a product &amp; usability guy, living as a guest in their world.  It&#8217;s a smart world, too.  Hell, I&#8217;m lucky enough to count many good friends there, and these are not low-watt bulbs, let me tell you.
</p>
<p>
But it always made me sad that the community never felt willing to really, <i>really</i> internalize a respect for the user, or to entertain the crazy concept that maybe, <i>maybe</i> security doesn&#8217;t have to be quite <i>this</i> hard.  Yes, real security exposes the thorny complexity of operating systems, and yes, it&#8217;s reasonable to say you need to know something about security to do it right.  But with the right tools&mdash;and perhaps more importantly the right attitude&mdash;I think we could make some real usability improvements in the world of security.
</p>
<p>
&nbsp;<br />
<small>P.S.: For the record, I was trying to figure out how to disable the audio on a Wiimote.</small>
</p>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fchrisashworth.org%2Fblog%2F2009%2F02%2F10%2Fuphill-battle%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fchrisashworth.org%2Fblog%2F2009%2F02%2F10%2Fuphill-battle%2F&amp;source=Chris_Ashworth&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://chrisashworth.org/blog/2009/02/10/uphill-battle/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The War on the Unexpected</title>
		<link>http://chrisashworth.org/blog/2007/11/27/the-war-on-the-unexpected/</link>
		<comments>http://chrisashworth.org/blog/2007/11/27/the-war-on-the-unexpected/#comments</comments>
		<pubDate>Tue, 27 Nov 2007 12:45:00 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Politics]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://chrisashworth.org/blog/2007/11/27/the-war-on-the-unexpected/</guid>
		<description><![CDATA[On November 1st, Bruce Schneier published his essay &#8220;The War on the Unexpected&#8220;. It made the rounds online, and it well deserved the attention. I won&#8217;t start copying in bits and pieces of that text, because you really owe it to yourself to read the whole thing.  I didn&#8217;t link to the essay at the [...]]]></description>
			<content:encoded><![CDATA[<p>On November 1st, Bruce Schneier published his essay &#8220;<a href="http://www.schneier.com/blog/archives/2007/11/the_war_on_the.html">The War on the Unexpected</a>&#8220;.  It made the rounds online, and it well deserved the attention.  I won&#8217;t start copying in bits and pieces of that text, because you really owe it to yourself to <a href="http://www.schneier.com/blog/archives/2007/11/the_war_on_the.html">read the whole thing</a>. </p>
<p>I didn&#8217;t link to the essay at the time, but I sure as hell am now.  Why now?  Maybe it was all those idiotic &#8220;Terror Tips?  Report Suspicious Activity&#8221; highway signs I saw this Thanksgiving.  Or maybe it was Schneier&#8217;s <a href="http://www.schneier.com/blog/archives/2007/11/more_war_on_the.html">followup post</a> where he describes <a href="http://news.bbc.co.uk/1/hi/england/west_yorkshire/7096456.stm">a man in the UK</a> who &#8220;had gone into a diabetic coma on a bus&#8221; and therefore &#8220;was shot twice with a Taser gun by police who feared he may have been a security threat.&#8221;  I have a loved one with type 1 diabetes, and that just makes my blood boil. </p>
<p>This is just f&amp;!king unacceptable, people.   Schneier is right: fear is winning.  <a href="http://www.schneier.com/blog/archives/2006/08/what_the_terror.html">Refuse to be terrorized.</a></p>
<p>I&#8217;ll end this on a positive note.  My sister recently sent me a link to <a href="http://www.youtube.com/watch?v=1nnj7r1wCD4">the interview with Barack Obama at Google</a>.  After watching it, I went and sent the guy some money.   I love this guy.  He gets it.  He gets that a culture of fear is not acceptable.  And he gets a lot of other things too.  He&#8217;s genuine, he&#8217;s wicked smart, and he gets my vote.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fchrisashworth.org%2Fblog%2F2007%2F11%2F27%2Fthe-war-on-the-unexpected%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fchrisashworth.org%2Fblog%2F2007%2F11%2F27%2Fthe-war-on-the-unexpected%2F&amp;source=Chris_Ashworth&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://chrisashworth.org/blog/2007/11/27/the-war-on-the-unexpected/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Even scumbags can have a sense of humor</title>
		<link>http://chrisashworth.org/blog/2007/09/01/even-scumbags-can-have-a-sense-of-humor/</link>
		<comments>http://chrisashworth.org/blog/2007/09/01/even-scumbags-can-have-a-sense-of-humor/#comments</comments>
		<pubDate>Sat, 01 Sep 2007 16:11:26 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://chrisashworth.org/blog/2007/09/01/even-scumbags-can-have-a-sense-of-humor/</guid>
		<description><![CDATA[The following phone conversation just occurred: Elizabeth: Hello? Phone Scamming Scumbag: [Spoken smoothly and officially.] Hello, we are conducting market research today. Are you over the age of 18? E: Yes. PSS: What is your income level: over 15,000 a year, over&#8212; E: &#8212;I&#8217;m sorry, I don&#8217;t feel comfortable telling you my income level. What [...]]]></description>
			<content:encoded><![CDATA[<p>The following phone conversation just occurred: </p>
<p><b>Elizabeth:</b> Hello?</p>
<p><b>Phone Scamming Scumbag:</b> [<i>Spoken smoothly and officially.</i>] Hello, we are conducting market research today.  Are you over the age of 18?</p>
<p><b>E:</b> Yes.</p>
<p><b>PSS:</b> What is your income level: over 15,000 a year, over&mdash;</p>
<p><b>E:</b> &mdash;I&#8217;m sorry, I don&#8217;t feel comfortable telling you my income level.  What is the survey for?</p>
<p><b>PSS:</b> I&#8217;m sorry, I don&#8217;t feel comfortable telling you what the survey is for.  </p>
<p>[click]
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fchrisashworth.org%2Fblog%2F2007%2F09%2F01%2Feven-scumbags-can-have-a-sense-of-humor%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fchrisashworth.org%2Fblog%2F2007%2F09%2F01%2Feven-scumbags-can-have-a-sense-of-humor%2F&amp;source=Chris_Ashworth&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://chrisashworth.org/blog/2007/09/01/even-scumbags-can-have-a-sense-of-humor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>- &#8211; - &#8211; -BEGIN PGP SIGNED MADNESS- &#8211; - &#8211; -</title>
		<link>http://chrisashworth.org/blog/2006/07/30/begin-pgp-signed-madness/</link>
		<comments>http://chrisashworth.org/blog/2006/07/30/begin-pgp-signed-madness/#comments</comments>
		<pubDate>Mon, 31 Jul 2006 03:30:45 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Rants]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.chrisashworth.org/blog/2006/07/30/begin-pgp-signed-madness/</guid>
		<description><![CDATA[Dear Guy That Signs All His Email With a PGP Key, Before sending any more email, please consult the following brief checklist: Do the recipients of your email have access to your public PGP key? Do the recipients of your email give a damn about who wrote your email? Hint: if you cannot answer yes [...]]]></description>
			<content:encoded><![CDATA[<p>Dear Guy That Signs All His Email With a PGP Key,</p>
<p>Before sending any more email, please consult the following brief checklist:</p>
<ul>
<li>Do the recipients of your email have access to your public PGP key?</li>
<li>Do the recipients of your email give a damn about who wrote your email?</li>
</ul>
<p>Hint: if you cannot answer yes to at least one of these questions, you should not be signing your email.  The degree to which you should not be signing your email is directly proportional to the number of recipients.</p>
<p>Thus, in the following equation,</p>
<p>Large public discussion list + PGP key unavailable even on your website + generic query for which the author is irrelevant anyway = <i>why are you polluting the signal with a PGP hash?</i></p>
<p>Technology, indiscriminately applied, is unhelpful at best.  So stop with the hashes already.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fchrisashworth.org%2Fblog%2F2006%2F07%2F30%2Fbegin-pgp-signed-madness%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fchrisashworth.org%2Fblog%2F2006%2F07%2F30%2Fbegin-pgp-signed-madness%2F&amp;source=Chris_Ashworth&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://chrisashworth.org/blog/2006/07/30/begin-pgp-signed-madness/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

