<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>UMW IT Security</title>
	<atom:link href="http://umwitsec.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://umwitsec.wordpress.com</link>
	<description>IT Security Awareness.  Keying on issues that students, faculty and staff of the University of Mary Washington may encounter.</description>
	<lastBuildDate>Fri, 22 Feb 2008 18:57:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='umwitsec.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>UMW IT Security</title>
		<link>http://umwitsec.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://umwitsec.wordpress.com/osd.xml" title="UMW IT Security" />
	<atom:link rel='hub' href='http://umwitsec.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Blog is moving.</title>
		<link>http://umwitsec.wordpress.com/2008/02/22/blog-is-moving/</link>
		<comments>http://umwitsec.wordpress.com/2008/02/22/blog-is-moving/#comments</comments>
		<pubDate>Fri, 22 Feb 2008 18:57:53 +0000</pubDate>
		<dc:creator>ccalvert</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://umwitsec.wordpress.com/?p=23</guid>
		<description><![CDATA[Update your bookmarks, RSS feeds, etc. The new location for this blog will be http://ccalvert.umwblogs.org Thanks<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=23&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Update your bookmarks, RSS feeds, etc.</p>
<p>The new location for this blog will be http://ccalvert.umwblogs.org</p>
<p>Thanks</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/umwitsec.wordpress.com/23/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/umwitsec.wordpress.com/23/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/umwitsec.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/umwitsec.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/umwitsec.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/umwitsec.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/umwitsec.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/umwitsec.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/umwitsec.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/umwitsec.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/umwitsec.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/umwitsec.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/umwitsec.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/umwitsec.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/umwitsec.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/umwitsec.wordpress.com/23/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=23&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://umwitsec.wordpress.com/2008/02/22/blog-is-moving/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4723f32a399e6ac33d75571c410fe065?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ccalvert</media:title>
		</media:content>
	</item>
		<item>
		<title>Disk Encryption Bad News!</title>
		<link>http://umwitsec.wordpress.com/2008/02/22/disk-encryption-bad-news/</link>
		<comments>http://umwitsec.wordpress.com/2008/02/22/disk-encryption-bad-news/#comments</comments>
		<pubDate>Fri, 22 Feb 2008 18:27:33 +0000</pubDate>
		<dc:creator>ccalvert</dc:creator>
				<category><![CDATA[Drive Encryption]]></category>

		<guid isPermaLink="false">http://umwitsec.wordpress.com/?p=22</guid>
		<description><![CDATA[After being excited about the new version of Truecrypt and learning of FREE Compusec, this study really yanked the rug out from under full disk encryption. Researchers at Princeton discovered fairly easy ways to get a disks encryption key if a computer is on and even recently turned off. What is really bad news for [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=22&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>After being excited about the new version of Truecrypt and learning of FREE Compusec, this <a href="http://citp.princeton.edu/memory/" title="Defeating Full Disk Encryption Study at Princeton">study</a> really yanked the rug out from under full disk encryption.  Researchers at Princeton discovered fairly easy ways to get a disks encryption key if a computer is on and even recently turned off.  What is really bad news for some implementations of Bitlocker, and possibly other disk encryption techniques that store the key in a TPM chip, is that the computer can be turned off for months and this attack is still effective.</p>
<p>Other then making sure one&#8217;s computer is turned off completely &#8212; no sleep mode, even hibernation in some cases &#8212; there isn&#8217;t a good defense for software based full disk encryption.   <a href="http://www.seagate.com/ww/v/index.jsp?locale=en-US&amp;name=dn_sec_intro_fde&amp;vgnextoid=1831bb5f5ed93110VgnVCM100000f5ee0a0aRCRD" title="Seagate Momentus Full Disk Encryption drive">Segate&#8217;s Momentus FDE</a> isn&#8217;t <i>currently</i> subject to this attack because the drive stores the key in it&#8217;s own memory chip independent of the system RAM.</p>
<p>This research from Princeton is certainly going to cause manufacturers to make new hardware technology to protect against RAM dump attacks.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/umwitsec.wordpress.com/22/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/umwitsec.wordpress.com/22/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/umwitsec.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/umwitsec.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/umwitsec.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/umwitsec.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/umwitsec.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/umwitsec.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/umwitsec.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/umwitsec.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/umwitsec.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/umwitsec.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/umwitsec.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/umwitsec.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/umwitsec.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/umwitsec.wordpress.com/22/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=22&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://umwitsec.wordpress.com/2008/02/22/disk-encryption-bad-news/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4723f32a399e6ac33d75571c410fe065?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ccalvert</media:title>
		</media:content>
	</item>
		<item>
		<title>Disk Encryption Good News!</title>
		<link>http://umwitsec.wordpress.com/2008/02/22/disk-encryption-good-news/</link>
		<comments>http://umwitsec.wordpress.com/2008/02/22/disk-encryption-good-news/#comments</comments>
		<pubDate>Fri, 22 Feb 2008 18:27:21 +0000</pubDate>
		<dc:creator>ccalvert</dc:creator>
				<category><![CDATA[Drive Encryption]]></category>

		<guid isPermaLink="false">http://umwitsec.wordpress.com/?p=21</guid>
		<description><![CDATA[Good news in the full disk encryption arena. Truecrypt 5.0, and now 5.0a, has been released. The most important new feature in the Windows version is that can encrypt the entire Windows system partition. Finally, an open source full disk encryption product for Windows. I&#8217;ve been using the full encryption on my home machine since [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=21&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Good news in the full disk encryption arena.  <a href="http://truecrypt.org" title="Truecrypt - Encryption for Mac, Linux and Windows">Truecrypt</a> 5.0, and now 5.0a, has been released.  The most important new feature in the Windows version is that can encrypt the entire Windows system partition.  Finally, an open source full disk encryption product for Windows.  I&#8217;ve been using the full encryption on my home machine since Feb. 17th and there doesn&#8217;t seem to be any conflicts or performance issues.  Steve Gibson, of GRC.com, ran a test (defragging copies of a hard drive) that showed performance to be increased under Truecrypt compared to an unencrypted drive.  One limitation of TC&#8217;s full disk encryption is that it doesn&#8217;t support hibernation so it may not be suitable for most laptops.</p>
<p>Truecrypt also released versions for Mac OS X, though not full disk encryption.  Along with Windows and Linux support Truecrypt volumes can be very portable between systems.</p>
<p>In addition to Truecrypt, <a href="http://www.ce-infosys.com/english/downloads/free_compusec/index.html" title="FREE Compusec">FREE Compusec</a> is a free, though not open source, product for full disk encryption for Windows.  This product does support hibernation and it has some other features not currently in Truecrypt.  I will do an evaluation of this product as well.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/umwitsec.wordpress.com/21/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/umwitsec.wordpress.com/21/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/umwitsec.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/umwitsec.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/umwitsec.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/umwitsec.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/umwitsec.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/umwitsec.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/umwitsec.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/umwitsec.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/umwitsec.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/umwitsec.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/umwitsec.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/umwitsec.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/umwitsec.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/umwitsec.wordpress.com/21/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=21&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://umwitsec.wordpress.com/2008/02/22/disk-encryption-good-news/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4723f32a399e6ac33d75571c410fe065?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ccalvert</media:title>
		</media:content>
	</item>
		<item>
		<title>Accessing the Internet with lower privileges.  (Subtitled:  Surfing Safer)</title>
		<link>http://umwitsec.wordpress.com/2007/07/05/accessing-the-internet-with-lower-privileges-subtitled-surfing-safer/</link>
		<comments>http://umwitsec.wordpress.com/2007/07/05/accessing-the-internet-with-lower-privileges-subtitled-surfing-safer/#comments</comments>
		<pubDate>Thu, 05 Jul 2007 20:31:53 +0000</pubDate>
		<dc:creator>ccalvert</dc:creator>
				<category><![CDATA[e-mail security]]></category>
		<category><![CDATA[Web browsers]]></category>

		<guid isPermaLink="false">http://umwitsec.com/2007/07/05/accessing-the-internet-with-lower-privileges-subtitled-surfing-safer/</guid>
		<description><![CDATA[By default XP creates all users as full administrators on the PC. Now I know that everyone creates another account for day-to-day use that has fewer privileges, right? No? After patching and having a firewall, including a home router, the main ways that machines are compromised are through malicious web sites or e-mail. Using one&#8217;s [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=20&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>By default XP creates all users as full administrators on the PC.  Now I know that everyone creates another account for day-to-day use that has fewer privileges, right?  No?</p>
<p>After patching and having a firewall, including a home router, the main ways that machines are compromised are through malicious web sites or e-mail.  Using one&#8217;s web browser as a full administrator makes it much easier for a computer to get &#8216;owned&#8217;.   Where I used to work the vast majority of the users were not local administrators.  Scans would be done to look for malware and occasionally there would be machines that had lots of spyware installed.  In every case the user&#8217;s account would have elevated privileges.</p>
<p>That being said, it can definitely be a pain to have two different accounts (though there are techniques that help quite a bit.  RunAs.exe, for example).  Since most attacks come through web browsers or e-mail, there is a way to run them in a safer way.</p>
<p>One way to surf safer is to use Firefox, Opera or some other web browser besides Internet Explorer.  I&#8217;m not saying IE is poorly coded but it has three things working against it:</p>
<ol>
<li>It is the most commonly used browser so it is the biggest target</li>
<li>It is closed source which prevents thousands of security experts looking over the code</li>
<li>It uses Active-X which is not officially supported, and not &#8216;allowed&#8217; because of Microsoft patents.</li>
</ol>
<p>Many pages don&#8217;t work properly in non-IE browsers.  There is great <a href="https://addons.mozilla.org/en-US/firefox/addons/previews/1419">plugin</a> that allows pages to opened inside of Firefox  being rendered by IE.  This plugin is set to always open Microsoft or MSN sites in IE.  Other pages can be opened in IE with a right-click.</p>
<p>Instead of Outlook or Outlook Express for e-mail use <a href="http://www.mozilla.com/thunderbird/">Thunderbird</a> or <a href="http://www.eudora.com/">Eudora</a> (which will be open source soon).  Regardless of the e-mail client, attachments should be considered unsafe by default.  Gmail is a great way to protect one&#8217;s computer from malware via e-mail as they have quite a few layers of protection.</p>
<p>Another option, which may not be for everyone, is to launch programs with fewer privileges.  There is a tool that was recently purchased by Microsoft called <a href="http://www.microsoft.com/technet/sysinternals/utilities/psexec.mspx">PsExec</a> which can, among other things, launch processes but it &#8220;strips the Administrators group and allows only privileges assigned to the Users group.&#8221;  What is handy about this method is that all bookmarks (excuse me, Favorites) are still the same and it is possible to run the program as an admin if necessary.  Here is sample syntax for launching IE with PsExec.</p>
<p><strong>psexec -l -d &#8220;c:\program files\internet explorer\iexplore.exe&#8221;</strong></p>
<p>I&#8217;ve changed most of my IE shorcuts to  use the above syntax.  I&#8217;ve been using it for about a year now and most sites work just fine.  Ironically, the Windows Update site does not work unless it is running as an admin.   No problem, I just launch IE from an unmodified shortcut.</p>
<p>Once again, none of the above techniques help with saving attachment or downloading malware and then launching it separately.   <strong>Don&#8217;t trust attachments</strong>.  Gmail won&#8217;t even let you download a .EXE file.</p>
<p>Oh yeah, some of you are wondering about Vista.  Well Vista, by default, runs account with reduced privileges and then asks &#8220;Are you sure&#8221;, if the program wants to do something normally requiring admin rights.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/umwitsec.wordpress.com/20/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/umwitsec.wordpress.com/20/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/umwitsec.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/umwitsec.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/umwitsec.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/umwitsec.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/umwitsec.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/umwitsec.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/umwitsec.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/umwitsec.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/umwitsec.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/umwitsec.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/umwitsec.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/umwitsec.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/umwitsec.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/umwitsec.wordpress.com/20/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=20&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://umwitsec.wordpress.com/2007/07/05/accessing-the-internet-with-lower-privileges-subtitled-surfing-safer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4723f32a399e6ac33d75571c410fe065?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ccalvert</media:title>
		</media:content>
	</item>
		<item>
		<title>PayPal Security Key</title>
		<link>http://umwitsec.wordpress.com/2007/07/05/paypal-security-key/</link>
		<comments>http://umwitsec.wordpress.com/2007/07/05/paypal-security-key/#comments</comments>
		<pubDate>Thu, 05 Jul 2007 19:32:18 +0000</pubDate>
		<dc:creator>ccalvert</dc:creator>
				<category><![CDATA[e-commerce]]></category>
		<category><![CDATA[Web browsers]]></category>

		<guid isPermaLink="false">http://umwitsec.com/2007/07/05/paypal-security-key/</guid>
		<description><![CDATA[Multi-factor authentication (biometrics, security token, etc.) is better than using a password alone. For $5 one can get a security key for PayPal. I&#8217;ve always been a fan of PayPal because it is safer than credit cards in that money is transferred in exact amounts to vendors. Only PayPal has to have the credit card [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=19&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Multi-factor authentication (biometrics, security token, etc.) is better than using a password alone.  For $5 one can get a security key for PayPal.  I&#8217;ve always been a fan of <a href="http://PayPal.com">PayPal</a> because it is safer than credit cards in that money is transferred <strong>in exact amounts</strong> to vendors.  Only PayPal has to have the credit card information.</p>
<p>PayPal, though great, is still susceptible to attacks in that a password can be guessed or keystroke loggers can capture login credentials.  The new security key takes care of those two attacks.  Read more, or order your own, <a href="https://www.paypal.com/securitykey">here</a>.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/umwitsec.wordpress.com/19/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/umwitsec.wordpress.com/19/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/umwitsec.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/umwitsec.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/umwitsec.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/umwitsec.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/umwitsec.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/umwitsec.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/umwitsec.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/umwitsec.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/umwitsec.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/umwitsec.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/umwitsec.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/umwitsec.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/umwitsec.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/umwitsec.wordpress.com/19/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=19&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://umwitsec.wordpress.com/2007/07/05/paypal-security-key/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4723f32a399e6ac33d75571c410fe065?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ccalvert</media:title>
		</media:content>
	</item>
		<item>
		<title>Using &#8220;PGP&#8221; in Gmail</title>
		<link>http://umwitsec.wordpress.com/2007/05/18/using-pgp-in-gmail/</link>
		<comments>http://umwitsec.wordpress.com/2007/05/18/using-pgp-in-gmail/#comments</comments>
		<pubDate>Fri, 18 May 2007 14:10:34 +0000</pubDate>
		<dc:creator>ccalvert</dc:creator>
				<category><![CDATA[e-mail security]]></category>

		<guid isPermaLink="false">http://umwitsec.com/2007/05/18/using-pgp-in-gmail/</guid>
		<description><![CDATA[Yesterday, someone asked me if I use PGP, and at the time I wasn&#8217;t, but I am using it now. The methods I used are likely to be applicable to UMW students, because I set this up in Gmail. Next year, hopefully, Gmail will be the standard e-mail for students. I initially set this up [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=16&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Yesterday, someone asked me if I use PGP, and at the time I wasn&#8217;t, but I am using it now.   The methods I used are likely to be applicable to UMW students, because I set this up in Gmail.   Next year, hopefully, Gmail will be the standard e-mail for students.</p>
<p align="left">I initially set this up on a Mac and used <a href="http://fiatlux.zeitform.info/en/instructions/pgp_macosx.html" title="PGP MacOSX">these instructions</a> to get started.   Things didn&#8217;t seem to be working at first, but after opening a new terminal all was well.   <a href="http://www.faqs.org/docs/securing/chap19sec155.html" title="GnuPGP Syntax">This link</a> helped with some of the syntax, and finally, here is the link to <a href="http://firegpg.tuxfamily.org/?page=install&amp;lang=en" title="FireGPG">FireGPG</a> to install the extension that hooks into Gmail running in Firefox.</p>
<p> <img src="http://umwitsec.files.wordpress.com/2007/05/firegpgexample.jpg?w=600&#038;h=411" alt="FireGPG example" height="411" width="600" /></p>
<p>The above is a screenshot showing the new buttons, context menu, and an example of encryption in Gmail.</p>
<p>At home on my Windows machine I installed the <a href="http://www.gnupg.org/(en)/download/index.html" title="GnuPGP">GnuPGP</a> for that OS and imported the keys I had created on the Mac.  I&#8217;ll probably use <a href="http://www.gpg4win.org/" title="Gpg4Win">this</a> software for key management on Windows.</p>
<p>Also for a Mac you may want to use <em><a href="http://macgpg.sourceforge.net/" title="MacPGP">GPG Keychain Access</a> </em>for managing keys.   <a href="http://www.gnome.org/projects/seahorse/" title="SeaHorse">Here</a> is an option for Gnome users.</p>
<p>Happy Crypting!</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/umwitsec.wordpress.com/16/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/umwitsec.wordpress.com/16/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/umwitsec.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/umwitsec.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/umwitsec.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/umwitsec.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/umwitsec.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/umwitsec.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/umwitsec.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/umwitsec.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/umwitsec.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/umwitsec.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/umwitsec.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/umwitsec.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/umwitsec.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/umwitsec.wordpress.com/16/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=16&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://umwitsec.wordpress.com/2007/05/18/using-pgp-in-gmail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4723f32a399e6ac33d75571c410fe065?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ccalvert</media:title>
		</media:content>

		<media:content url="http://umwitsec.files.wordpress.com/2007/05/firegpgexample.jpg" medium="image">
			<media:title type="html">FireGPG example</media:title>
		</media:content>
	</item>
		<item>
		<title>Giving Blink a try.</title>
		<link>http://umwitsec.wordpress.com/2007/05/17/giving-blink-a-try/</link>
		<comments>http://umwitsec.wordpress.com/2007/05/17/giving-blink-a-try/#comments</comments>
		<pubDate>Thu, 17 May 2007 16:51:19 +0000</pubDate>
		<dc:creator>ccalvert</dc:creator>
				<category><![CDATA[PC Security]]></category>

		<guid isPermaLink="false">http://umwitsec.com/2007/05/17/giving-blink-a-try/</guid>
		<description><![CDATA[Blink Personal, might be the only security software to add to a PC. Here is a list of features from eEye.com. Blocks and removes viruses, spyware, worms, trojans, and other malicious programs Protection from unknown ‘zero-day’ attacks Protects against Identity Theft and Phishing attempts System and Application firewalls protect against hackers and unauthorized system changes [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=14&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://umwitsec.files.wordpress.com/2007/05/eeye.jpg" title="Eeye"></a></p>
<p style="text-align:center;"><a href="http://umwitsec.files.wordpress.com/2007/05/eeye.jpg" title="Eeye"><img src="http://umwitsec.files.wordpress.com/2007/05/eeye.jpg" alt="Eeye" /></a></p>
<p><a href="http://www.eeye.com/html/products/blink/personal/index.html"></a></p>
<p><a href="http://www.eeye.com/html/products/blink/personal/index.html">Blink Personal</a>, might be the only security software to add to a PC.  Here is a list of features from eEye.com.</p>
<ul>
<li>Blocks and removes <strong>viruses</strong>, <strong>spyware</strong>, <strong>worms</strong>, <strong>trojans</strong>, and other malicious programs</li>
<li>Protection from unknown <strong>‘<a href="http://research.eeye.com/html/alerts/zeroday">zero-day</a>’</strong> attacks</li>
<li>Protects against <strong>Identity Theft</strong> and <strong>Phishing</strong> attempts</li>
<li>System and Application <strong>firewalls</strong> protect against hackers and unauthorized system changes</li>
<li><strong>Intrusion prevention</strong> and system protection prevent remote attacks and unauthorized program execution</li>
<li>Detection of missing operating system and application <strong>patches</strong></li>
<li>Detection of weak <strong>configurations</strong> that leave personal information at risk of being compromised</li>
</ul>
<p>Another awesome feature is that a another version of eEye&#8217;s flagship software is with this product.  A personal version of Retina scanner allows for doing vulnerability scans on your own computer, and it only takes a few minutes.  Not only does it check for typical Micrsoft vulnerabilities, but other software as well.  I was reminded to update my Quick Time and iTunes because they contained critical vulnerabilities.</p>
<p>I was also surprised that it stated there were some critical problems with Word.  It said there are no fixes for these particular problems yet, just to be careful what documents you open.  At my former job some of the overseas posts where compromised to zero day exploits in Word.  So reading this brought back memories of having to change every single password on a network of over 50,000 users.</p>
<p>Anyway, here are some of the negatives to Blink.</p>
<ol>
<li>It is only free for the first year, but I think I&#8217;ll be paying the $29.00 for it next year.</li>
<li>It will report incidents back to the mother ship.  This is to allow eEye to make a better product, prevent false positives, etc.</li>
<li>It wants you to uninstall previous security type programs such as anti-virus, personal firewalls, etc.  I was already going to uninstall my anti-virus but was looking for a good substitute.  Some of the legitimate security tools I use Symantec wants to eat, and I can&#8217;t find a good way to stop the program from doing that.</li>
<li>Like many outbound firewalls, it can annoying to get them trained properly.  It already understands common Internet software such as Firefox and IE, but it did not like my news reader or Groupwise client, but all seems to be calm now.</li>
</ol>
<p>I&#8217;m going to give Blink a try to see how it behaves.  It looks very promising as a different,  yet thorough, way of protecting one&#8217;s PC.</p>
<p>Update, 18May2007:  Blink can be a pain for those that use not-that-popular Internet software.  It will take a while to train, and it did eat some of my legitimate-software-that-can-be-used-for-nefarious-purposes, but at least it was easy to tell it to spit it back out and don&#8217;t eat it again.</p>
<p>Update, 15June2007:   Blink is now off most of the time.  If eEye would streamline some usability options then this would be a great product.  I rebooted my laptop where I didn&#8217;t have any Internet connectivity, and it took over 5 minutes just to shut down Blink.  Skype and LogMeIn couldn&#8217;t connect to servers, obviously, so they kept trying multiple servers and multiple ports.  Blink was extremely offended by this behavior and kept asking &#8220;Are you sure?&#8221; every time Skype or LogMeIn tried something else.</p>
<p>When the &#8220;Are you sure?&#8221; prompt was up I couldn&#8217;t disable Blink via the icon in the tray because this is how the software was designed.  I tried stopping the service but kept getting &#8220;access denied&#8221;.  So, I had to set up rules in Blink to allow Skype and LogMeIn to be able to talk to any IP on any port before I could stop Blink.  There should be another way to quench a security product&#8217;s desire to do good without making one&#8217;s computer wide open to external servers.  And it wasn&#8217;t just Skype and LogMeIn, there were other things running such as Quicktime, Groupwise and ClamWin that were trying in vain to phone home.</p>
<p>Then again, without Blink, or similar, running then those applications could talk to whomever they&#8217;d like.  I do basically trust Groupwise, etc., but I&#8217;d like to know when some unknown program tries to open a connection.  Sooo, if there was a better way to simply state that Program X can be trusted (like the behavior of older ZoneAlarm), then Blink would be a more pleasant program.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/umwitsec.wordpress.com/14/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/umwitsec.wordpress.com/14/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/umwitsec.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/umwitsec.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/umwitsec.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/umwitsec.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/umwitsec.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/umwitsec.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/umwitsec.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/umwitsec.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/umwitsec.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/umwitsec.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/umwitsec.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/umwitsec.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/umwitsec.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/umwitsec.wordpress.com/14/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=14&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://umwitsec.wordpress.com/2007/05/17/giving-blink-a-try/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4723f32a399e6ac33d75571c410fe065?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ccalvert</media:title>
		</media:content>

		<media:content url="http://umwitsec.files.wordpress.com/2007/05/eeye.jpg" medium="image">
			<media:title type="html">Eeye</media:title>
		</media:content>
	</item>
		<item>
		<title>FTP alternatives</title>
		<link>http://umwitsec.wordpress.com/2007/05/09/ftp-alternatives/</link>
		<comments>http://umwitsec.wordpress.com/2007/05/09/ftp-alternatives/#comments</comments>
		<pubDate>Wed, 09 May 2007 13:15:25 +0000</pubDate>
		<dc:creator>ccalvert</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://umwitsec.com/2007/05/09/ftp-alternatives/</guid>
		<description><![CDATA[As of July 1st, FTP access to the main shares will be disabled from the Internet except for faculty and staff using a VPN. As of the Fall, FTP access will be disabled altogether. This link lists other options for getting to a share. Unfortunately, none of the alternatives work with Vista out of the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=13&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As of July 1st, FTP access to the main shares will be disabled from the Internet except for faculty and staff using a VPN.  As of the Fall, FTP access will be disabled altogether.  This <a href="http://download.umw.edu/public/fileaccess/">link</a> lists other options for getting to a share.</p>
<p>Unfortunately, none of the alternatives work with Vista out of the box, however, NetStorage does work if one installs and uses Firefox.  NetStorage only allows one file to be uploaded/downloaded at at time, but at least it is a viable option until, hopefully, one of the other options will be updated to work with Vista by the Fall.</p>
<p>Update:  Another workaround for Vista that does work without installing additional software is to disable TLS 1.0 in Internet Explorer, but make sure SSL 3.0 is still set.    This will allow NetStorage to work with IE.  Use this option only as a last resort because it does lower the security posture.</p>
<p>Using Firefox has security advantages, mainly that it doesn&#8217;t allow ActiveX applets to run.  It is also open source which means that hundreds, if not thousands, of security experts have gone through the source code looking for exploits.  Mozilla offers a $500 reward for any security flaws found in Firefox (as long as the flaw isn&#8217;t exploited by the discoverer).</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/umwitsec.wordpress.com/13/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/umwitsec.wordpress.com/13/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/umwitsec.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/umwitsec.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/umwitsec.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/umwitsec.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/umwitsec.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/umwitsec.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/umwitsec.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/umwitsec.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/umwitsec.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/umwitsec.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/umwitsec.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/umwitsec.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/umwitsec.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/umwitsec.wordpress.com/13/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=13&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://umwitsec.wordpress.com/2007/05/09/ftp-alternatives/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4723f32a399e6ac33d75571c410fe065?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ccalvert</media:title>
		</media:content>
	</item>
		<item>
		<title>Windows users, There&#8217;s a new exploit in town!</title>
		<link>http://umwitsec.wordpress.com/2007/04/03/windows-users-theres-a-new-exploit-in-town/</link>
		<comments>http://umwitsec.wordpress.com/2007/04/03/windows-users-theres-a-new-exploit-in-town/#comments</comments>
		<pubDate>Tue, 03 Apr 2007 17:16:39 +0000</pubDate>
		<dc:creator>ccalvert</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://umwitsec.com/2007/04/03/windows-users-theres-a-new-exploit-in-town/</guid>
		<description><![CDATA[There is a newly found vulnerability that effects Internet Explorer, Outlook, Outlook Express and even the Windows&#8217; OS itself. Actually, the discovery isn&#8217;t that new, the flaw was reported on 20 Dec. 2006 to Microsoft. The short answer is to make sure antivirus definitions are up to date. All major AV vendors had an update [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=12&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>There is a newly found <a href="http://www.microsoft.com/technet/security/advisory/935423.mspx">vulnerability</a> that effects Internet Explorer, Outlook, Outlook Express and even the Windows&#8217; OS itself.  Actually, the discovery isn&#8217;t that new, the flaw was reported on 20 Dec. 2006 to Microsoft.</p>
<p>The short answer is to make sure antivirus definitions are up to date.  All major AV vendors had an update over the weekend for this new attack vector.  Avoid using Outlook Express if at all possible because the exploit will fire even if viewing in text mode.  Use Outlook in text mode, and only use IE for going to known safe sites.</p>
<p>Microsoft says there will be a patch today.  This must be a big threat for MS to release a patch out of cycle, which is normally the 2nd Tuesday of each month.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/umwitsec.wordpress.com/12/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/umwitsec.wordpress.com/12/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/umwitsec.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/umwitsec.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/umwitsec.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/umwitsec.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/umwitsec.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/umwitsec.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/umwitsec.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/umwitsec.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/umwitsec.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/umwitsec.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/umwitsec.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/umwitsec.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/umwitsec.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/umwitsec.wordpress.com/12/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=12&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://umwitsec.wordpress.com/2007/04/03/windows-users-theres-a-new-exploit-in-town/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4723f32a399e6ac33d75571c410fe065?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ccalvert</media:title>
		</media:content>
	</item>
		<item>
		<title>Disk Image Encryption for Macs</title>
		<link>http://umwitsec.wordpress.com/2007/03/30/disk-image-encryption-for-macs/</link>
		<comments>http://umwitsec.wordpress.com/2007/03/30/disk-image-encryption-for-macs/#comments</comments>
		<pubDate>Fri, 30 Mar 2007 12:33:54 +0000</pubDate>
		<dc:creator>ccalvert</dc:creator>
				<category><![CDATA[Drive Encryption]]></category>

		<guid isPermaLink="false">http://umwitsec.com/2007/03/30/disk-image-encryption-for-macs/</guid>
		<description><![CDATA[TrueCrypt was mentioned in an earlier blog entry as a way to encrypt part of a drive. This great utility is only available for Linux and Windows. Well, Mac OS X has a built in way of encrypting disk images. As with TrueCrypt this method can be used for encrypting portions of a drive, and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=10&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>TrueCrypt was mentioned in an earlier blog entry as a way to encrypt part of a drive.  This great utility is only available for Linux and Windows.  Well, Mac OS X has a <a href="http://www.hackszine.com/blog/archive/2007/03/how_to_create_an_encrypted_dis.html?CMP=OTC-7G2N43923558">built in</a> way of encrypting disk images.</p>
<p><a href="http://umwitsec.files.wordpress.com/2007/03/macdiskencryption.jpg" title="Mac Disk Encryption"><img src="http://umwitsec.files.wordpress.com/2007/03/macdiskencryption.jpg" alt="Mac Disk Encryption" /> </a></p>
<p>As with TrueCrypt this method can be used for encrypting portions of a drive, and sections of a thumb drive as well.  I&#8217;m liking Macs more and more as time goes on.  ; )</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/umwitsec.wordpress.com/10/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/umwitsec.wordpress.com/10/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/umwitsec.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/umwitsec.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/umwitsec.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/umwitsec.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/umwitsec.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/umwitsec.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/umwitsec.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/umwitsec.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/umwitsec.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/umwitsec.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/umwitsec.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/umwitsec.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/umwitsec.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/umwitsec.wordpress.com/10/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=umwitsec.wordpress.com&amp;blog=883079&amp;post=10&amp;subd=umwitsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://umwitsec.wordpress.com/2007/03/30/disk-image-encryption-for-macs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4723f32a399e6ac33d75571c410fe065?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ccalvert</media:title>
		</media:content>

		<media:content url="http://umwitsec.files.wordpress.com/2007/03/macdiskencryption.jpg" medium="image">
			<media:title type="html">Mac Disk Encryption</media:title>
		</media:content>
	</item>
	</channel>
</rss>
