<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>How in the TECH &#187; Security</title>
	<atom:link href="http://www.howinthetech.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.howinthetech.com</link>
	<description>Daily Tech Tips and News</description>
	<lastBuildDate>Tue, 16 Mar 2010 21:19:19 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<atom:link rel='hub' href='http://www.howinthetech.com/?pushpress=hub'/>
		<item>
		<title>Windows Without Admin Rights</title>
		<link>http://www.howinthetech.com/windows-without-admin-rights/</link>
		<comments>http://www.howinthetech.com/windows-without-admin-rights/#comments</comments>
		<pubDate>Tue, 23 May 2006 20:28:26 +0000</pubDate>
		<dc:creator>Adam Myers</dc:creator>
				<category><![CDATA[Techlines Today]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.evileyez.org/windows-without-admin-rights/</guid>
		<description><![CDATA[


It&#8217;s normal for Microsoft to transition their corporate environment to the latest and greatest software, especially as they transition towards RTM (release to manufacturing). However, it was quite interesting to hear that Microsoft is considering revoking local admin-rights during the Vista company-wide rollout.
We haven&#8217;t made that final determination yet. We would like to absolutely look [...]]]></description>
			<content:encoded><![CDATA[<p><div style="float: right; margin-top:0px;margin-left:5px;"><script type="text/javascript"><!--
google_ad_client = "pub-7614676277221702";
google_ad_slot = "8180382492";
google_ad_width = 336;
google_ad_height = 280;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</div></p>
<p>It&#8217;s normal for Microsoft to transition their corporate environment to the latest and greatest software, especially as they transition towards RTM (release to manufacturing). However, it was quite interesting to hear that <a href="http://www.zdnet.com.au/news/security/soa/Microsoft_considers_taking_admin_rights_from_employees/0,2000061744,39257228,00.htm" target="_blank">Microsoft is considering revoking local admin-rights</a> during the Vista company-wide rollout.</p>
<blockquote><p>We haven&#8217;t made that final determination yet. We would like to absolutely look at scenarios where we can look at elements of User Access Control &#8212; that is the feature in Vista &#8212; so that we can start moving in that direction &#8230; It is a tough balance and every company has to decide what is right for them,&#8217; said Estberg. However, Estberg said that for the moment, the company will continue to leave the responsibility of installing software with its employees.</p></blockquote>
<p>Live by the sword, die by the sword. I find it shocking that in a large corporate environment the policy allows for most everyone to run Windows as a local admin. Though this easily explains why it is such a pain to work as a regular user; Microsoft hasn&#8217;t had to struggle through the process yet.</p>
<p>Take installing software in the typical corporate environment.</p>
<p>In UNIX:</p>
<ol>
<li>User needs a particular application. Depending on company policy, the user may be able to install in their own home folder. If not, they could submit a request to support.</li>
<li>Support authorizes request, does a remote SSH connection to the users machine, installs the software (while the user is still working) and notifies user that the software was installed.</li>
<li>Software ties into centralized package management system so IT can keep tabs on security notifications, updates, etc and roll it (easily) into the centralized update mechanism.</li>
</ol>
<p>In Windows:</p>
<ol>
<li>The user needs software and does not have admin rights. The chances the user can install in their home folder is close to 0%. User requires IT to install.</li>
<li>IT receives the request and approves it. Perhaps IT gets lucky and the software is packaged as an MSI that can be installed via group policy. IT adds the install files to a network share and adjusts group policy. Tells user to restart or wait until next boot to get the update. Most likely the software cannot be installed via MSI (no auto-install MSI exists) and manual installation will happen.</li>
<li>IT contacts the user to tell them they will access their system remotely and to log out (no concurrent users in XP). User logs out and IT logs in remotely via RDP rendering the computer inaccessible for the user.</li>
<li>IT installs the software as administrator. IT logs out and notifies the user the software was installed.</li>
<li>A little while later, user contacts IT saying that the software does not run properly. Apparently the software needs to be run as admin first time to initiate some files in the program files folder. Admin repeats step 2 and 3 to finalize the software install. Unfortunately, the software refuses to run via RDP. IT has to either have local user login as a temporary admin to run the software or admin has to physically access the machine.</li>
<li>Admin decides to go to the machine to step through the install. Runs the software, logs in as the user account and it still is not operational. Admin then has to pull out regmon/filemon to determine the issues (as the regular user). Once done, admin has to re-acquire admin level rights (ie runas or admin shares) to make file permission changes/registry security changes.</li>
<li>After a debugging session, the software finally works as expected for the user (hopefully). Admin then writes down all the steps required in the event of a software upgrade, future install, etc.</li>
<li>Admin decides to notify software company so hopefully next version is fixed.. software company&#8217;s support is not interested and state &#8220;admin access required&#8221;.</li>
<li>There is no central management of the software, so admin has to manually check for updates (along with the myraid of other software). Perhaps in the spare time, the admin writes a script to assist in the installation.</li>
</ol>
<p>I&#8217;m not jaded though &#8211; honest. Gah!!!</p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-delicious">
			<a href="http://del.icio.us/post?url=http://www.howinthetech.com/windows-without-admin-rights/&amp;title=Windows+Without+Admin+Rights" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.howinthetech.com/windows-without-admin-rights/&amp;title=Windows+Without+Admin+Rights" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="sexy-diigo">
			<a href="http://www.diigo.com/post?url=http://www.howinthetech.com/windows-without-admin-rights/&amp;title=Windows+Without+Admin+Rights&amp;desc=%0D%0A%0D%0AIt%27s%20normal%20for%20Microsoft%20to%20transition%20their%20corporate%20environment%20to%20the%20latest%20and%20greatest%20software%2C%20especially%20as%20they%20transition%20towards%20RTM%20%28release%20to%20manufacturing%29.%20However%2C%20it%20was%20quite%20interesting%20to%20hear%20that%20Microsoft%20is%20considering%20revoking%20local%20admin-rights%20during%20the%20Vista%20comp" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.howinthetech.com/windows-without-admin-rights/&amp;title=Windows+Without+Admin+Rights" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.howinthetech.com/windows-without-admin-rights/&amp;title=Windows+Without+Admin+Rights" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.howinthetech.com/windows-without-admin-rights/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="sexy-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.howinthetech.com/windows-without-admin-rights/&amp;title=Windows+Without+Admin+Rights" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=Windows+Without+Admin+Rights+-+http://b2l.me/gpz6w+" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.howinthetech.com/windows-without-admin-rights/&amp;submitHeadline=Windows+Without+Admin+Rights&amp;submitSummary=%0D%0A%0D%0AIt%27s%20normal%20for%20Microsoft%20to%20transition%20their%20corporate%20environment%20to%20the%20latest%20and%20greatest%20software%2C%20especially%20as%20they%20transition%20towards%20RTM%20%28release%20to%20manufacturing%29.%20However%2C%20it%20was%20quite%20interesting%20to%20hear%20that%20Microsoft%20is%20considering%20revoking%20local%20admin-rights%20during%20the%20Vista%20comp&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="sexy-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.howinthetech.com/windows-without-admin-rights/&amp;t=Windows+Without+Admin+Rights" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="sexy-friendfeed">
			<a href="http://www.friendfeed.com/share?title=Windows+Without+Admin+Rights&amp;link=http://www.howinthetech.com/windows-without-admin-rights/" rel="nofollow" class="external" title="Share this on FriendFeed">Share this on FriendFeed</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.howinthetech.com/windows-without-admin-rights/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>DD-WRT v23 SP1 Released Today</title>
		<link>http://www.howinthetech.com/dd-wrt-v23-sp1-released-today/</link>
		<comments>http://www.howinthetech.com/dd-wrt-v23-sp1-released-today/#comments</comments>
		<pubDate>Tue, 16 May 2006 22:19:25 +0000</pubDate>
		<dc:creator>Adam Myers</dc:creator>
				<category><![CDATA[Techlines Today]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[System Administration]]></category>

		<guid isPermaLink="false">http://www.evileyez.org/dd-wrt-v23-sp1-released-today/</guid>
		<description><![CDATA[DD-WRT is a free firmware for several wireless routers, most notably the Linksys WRT54G.
DD-WRT is maintained by BrainSlayer at dd-wrt.com. DD-WRT up to v22  was based on the Alchemy firmware from Sveasoft, which was based on the original Linksys firmware. Among other features not found in the original Linksys firmware, DD-WRT adds the Kai [...]]]></description>
			<content:encoded><![CDATA[<p>DD-WRT is a free firmware for several wireless routers, most notably the <a title="Linksys" href="http://www.linksys.com">Linksys WRT54G</a>.</p>
<p>DD-WRT is maintained by BrainSlayer at <a href="http://www.dd-wrt.com/">dd-wrt.com</a>. DD-WRT up to v22  was based on the Alchemy firmware from <a href="http://www.sveasoft.com">Sveasoft</a>, which was based on the original Linksys firmware. Among other features not found in the original Linksys firmware, DD-WRT adds the Kai Console Gaming network daemon, Wireless Distribution System (WDS), RADIUS, Quality of Service (QoS) controls for bandwidth allocation, radio output power control (up to 251mW), and software support for a Secure Digital card hardware modification.</p>
<p><a href="http://www.dd-wrt.com/dd-wrtv2/downloads/index.php?path=dd-wrt.v23+SP1/" target="_blank">Check out the newest version</a>.</p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-delicious">
			<a href="http://del.icio.us/post?url=http://www.howinthetech.com/dd-wrt-v23-sp1-released-today/&amp;title=DD-WRT+v23+SP1+Released+Today" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.howinthetech.com/dd-wrt-v23-sp1-released-today/&amp;title=DD-WRT+v23+SP1+Released+Today" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="sexy-diigo">
			<a href="http://www.diigo.com/post?url=http://www.howinthetech.com/dd-wrt-v23-sp1-released-today/&amp;title=DD-WRT+v23+SP1+Released+Today&amp;desc=DD-WRT%20is%20a%20free%20firmware%20for%20several%20wireless%20routers%2C%20most%20notably%20the%20Linksys%20WRT54G.%0D%0A%0D%0ADD-WRT%20is%20maintained%20by%20BrainSlayer%20at%20dd-wrt.com.%20DD-WRT%20up%20to%20v22%20%20was%20based%20on%20the%20Alchemy%20firmware%20from%20Sveasoft%2C%20which%20was%20based%20on%20the%20original%20Linksys%20firmware.%20Among%20other%20features%20not%20found%20in%20the%20or" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.howinthetech.com/dd-wrt-v23-sp1-released-today/&amp;title=DD-WRT+v23+SP1+Released+Today" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.howinthetech.com/dd-wrt-v23-sp1-released-today/&amp;title=DD-WRT+v23+SP1+Released+Today" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.howinthetech.com/dd-wrt-v23-sp1-released-today/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="sexy-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.howinthetech.com/dd-wrt-v23-sp1-released-today/&amp;title=DD-WRT+v23+SP1+Released+Today" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=DD-WRT+v23+SP1+Released+Today+-+http://b2l.me/gsqkz+" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.howinthetech.com/dd-wrt-v23-sp1-released-today/&amp;submitHeadline=DD-WRT+v23+SP1+Released+Today&amp;submitSummary=DD-WRT%20is%20a%20free%20firmware%20for%20several%20wireless%20routers%2C%20most%20notably%20the%20Linksys%20WRT54G.%0D%0A%0D%0ADD-WRT%20is%20maintained%20by%20BrainSlayer%20at%20dd-wrt.com.%20DD-WRT%20up%20to%20v22%20%20was%20based%20on%20the%20Alchemy%20firmware%20from%20Sveasoft%2C%20which%20was%20based%20on%20the%20original%20Linksys%20firmware.%20Among%20other%20features%20not%20found%20in%20the%20or&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="sexy-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.howinthetech.com/dd-wrt-v23-sp1-released-today/&amp;t=DD-WRT+v23+SP1+Released+Today" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="sexy-friendfeed">
			<a href="http://www.friendfeed.com/share?title=DD-WRT+v23+SP1+Released+Today&amp;link=http://www.howinthetech.com/dd-wrt-v23-sp1-released-today/" rel="nofollow" class="external" title="Share this on FriendFeed">Share this on FriendFeed</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.howinthetech.com/dd-wrt-v23-sp1-released-today/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure your Passwords Easily with Password Safe</title>
		<link>http://www.howinthetech.com/secure-your-passwords-easily/</link>
		<comments>http://www.howinthetech.com/secure-your-passwords-easily/#comments</comments>
		<pubDate>Fri, 12 May 2006 17:53:54 +0000</pubDate>
		<dc:creator>Adam Myers</dc:creator>
				<category><![CDATA[How in the Tech]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.evileyez.org/secure-your-passwords-easily/</guid>
		<description><![CDATA[


Password Safe is a free and open source program that allows you to use a unique password for all your accounts, without actually having to remember all those username and password combinations. The program is a single binary/exe that requires no installation, which makes it highly portable and conveinent, and runs on all various flavors [...]]]></description>
			<content:encoded><![CDATA[<p><div style="float: right; margin-top:0px;margin-left:5px;"><script type="text/javascript"><!--
google_ad_client = "pub-7614676277221702";
google_ad_slot = "8180382492";
google_ad_width = 336;
google_ad_height = 280;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</div></p>
<p><a href="http://passwordsafe.sourceforge.net/" target="_blank"><img class="alignnone" style="float: left;" src="/images/password_safe.gif" alt="" align="left" />Password Safe</a> is a free and open source program that allows you to use a unique password for all your accounts, without actually having to <strong>remember</strong> all those username and password combinations. The program is a single binary/exe that requires no installation, which makes it highly portable and conveinent, and runs on all various flavors of Windows.</p>
<p>Starting Password Safe the first time results in a window prompting for the location of the password database you wish to open. As you have yet to create the database, simply clicking <em>Create new database</em> will allow you to, surprisingly, create your database file as well as assigning a Master Password that is necessary for authentication during day to day usage. Pick a strong and secure password, but do not forget it, as there will be no way to recover your password file without it. Hey, you wanted security right?</p>
<div style="text-align: center;"><img src="/images/password_safe_entry.PNG" alt="" /></div>
<p>Adding a new username/password is simple and straightforward, even allowing for the creation of random ultra-secure passwords. You may wish to take advantage of this feature because Password Safe is able to fill in the login form inside your browser with a simple keyboard shortcut (CTRL+T). Not only will Password Safe remember your passwords, it also facilitates the ability to create strong passwords.</p>
<div style="text-align: center;"><img src="/images/password_safe_collapsed.PNG" alt="" /></div>
<p>As our Internet lifetime continues to age, we are constantly challenged in remembering and maintaining all of our account information. Password Safe is an excellent tool whose value is only truly realized the more you use it.</p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-delicious">
			<a href="http://del.icio.us/post?url=http://www.howinthetech.com/secure-your-passwords-easily/&amp;title=Secure+your+Passwords+Easily+with+Password+Safe" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.howinthetech.com/secure-your-passwords-easily/&amp;title=Secure+your+Passwords+Easily+with+Password+Safe" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="sexy-diigo">
			<a href="http://www.diigo.com/post?url=http://www.howinthetech.com/secure-your-passwords-easily/&amp;title=Secure+your+Passwords+Easily+with+Password+Safe&amp;desc=%0D%0A%0D%0APassword%20Safe%20is%20a%20free%20and%20open%20source%20program%20that%20allows%20you%20to%20use%20a%20unique%20password%20for%20all%20your%20accounts%2C%20without%20actually%20having%20to%20remember%20all%20those%20username%20and%20password%20combinations.%20The%20program%20is%20a%20single%20binary%2Fexe%20that%20requires%20no%20installation%2C%20which%20makes%20it%20highly%20portable%20and%20c" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.howinthetech.com/secure-your-passwords-easily/&amp;title=Secure+your+Passwords+Easily+with+Password+Safe" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.howinthetech.com/secure-your-passwords-easily/&amp;title=Secure+your+Passwords+Easily+with+Password+Safe" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.howinthetech.com/secure-your-passwords-easily/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="sexy-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.howinthetech.com/secure-your-passwords-easily/&amp;title=Secure+your+Passwords+Easily+with+Password+Safe" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=Secure+your+Passwords+Easily+with+Password+Safe+-+http://b2l.me/gpeqc+" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.howinthetech.com/secure-your-passwords-easily/&amp;submitHeadline=Secure+your+Passwords+Easily+with+Password+Safe&amp;submitSummary=%0D%0A%0D%0APassword%20Safe%20is%20a%20free%20and%20open%20source%20program%20that%20allows%20you%20to%20use%20a%20unique%20password%20for%20all%20your%20accounts%2C%20without%20actually%20having%20to%20remember%20all%20those%20username%20and%20password%20combinations.%20The%20program%20is%20a%20single%20binary%2Fexe%20that%20requires%20no%20installation%2C%20which%20makes%20it%20highly%20portable%20and%20c&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="sexy-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.howinthetech.com/secure-your-passwords-easily/&amp;t=Secure+your+Passwords+Easily+with+Password+Safe" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="sexy-friendfeed">
			<a href="http://www.friendfeed.com/share?title=Secure+your+Passwords+Easily+with+Password+Safe&amp;link=http://www.howinthetech.com/secure-your-passwords-easily/" rel="nofollow" class="external" title="Share this on FriendFeed">Share this on FriendFeed</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.howinthetech.com/secure-your-passwords-easily/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Looking at Vista&#8217;s User Account Control</title>
		<link>http://www.howinthetech.com/looking-at-vistas-user-account-control/</link>
		<comments>http://www.howinthetech.com/looking-at-vistas-user-account-control/#comments</comments>
		<pubDate>Thu, 04 May 2006 22:33:26 +0000</pubDate>
		<dc:creator>Adam Myers</dc:creator>
				<category><![CDATA[Bits & Bytes]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vista]]></category>

		<guid isPermaLink="false">http://www.evileyez.org/looking-at-vistas-user-account-control/</guid>
		<description><![CDATA[I blogged ever so briefly about Vista&#8217;s new User Account Control before and what it will mean to users in its current form so I&#8217;m quite happy to find that ZDNet is experiencing the same type of mind-numbing annoyances with UAC as I.
It&#8217;s clear that Microsoft is attempting to instill safe practices to it&#8217;s userbase; [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://static.flickr.com/54/132032882_f3c263b68f_o.jpg" alt="" align="left" />I blogged ever so briefly about <a href="http://www.evileyez.org/windows-apologist-upset-about-vista/" target="_blank">Vista&#8217;s new User Account Control</a> before and what it will mean to users in its current form so I&#8217;m quite happy to find that ZDNet is experiencing the same type of <a href="http://blogs.zdnet.com/Bott/?p=44" target="_blank">mind-numbing annoyances with UAC</a> as I.</p>
<p>It&#8217;s clear that Microsoft is attempting to instill safe practices to it&#8217;s userbase; you should not run Windows under the Administrator account. Fabulous idea, no one can argue that. However its current implementation is just a nightmare to work with and those of us that are already the &#8220;family tech guy&#8221; are in for a real treat in a year as Vista becomes more prevelant. The user/permission paradigm is just not a part of the average Windows user&#8217;s technology-trained mind. That&#8217;s probably the first hurdle in the security marathon. Secondly, many <a href="http://www.pluralsight.com/wiki/default.aspx/Keith.HallOfShame" target="_blank">many applications in their current iterations fail miserably under UAP</a>. One of Windows strengths is in its ability to run software from 10 years back &#8211; this just isn&#8217;t going to fly any longer.</p>
<p>I still have what may be misguided faith that Microsoft will polish this up, because, whether we all want to admit it, this is desperately needed.</p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-delicious">
			<a href="http://del.icio.us/post?url=http://www.howinthetech.com/looking-at-vistas-user-account-control/&amp;title=Looking+at+Vista%27s+User+Account+Control" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.howinthetech.com/looking-at-vistas-user-account-control/&amp;title=Looking+at+Vista%27s+User+Account+Control" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="sexy-diigo">
			<a href="http://www.diigo.com/post?url=http://www.howinthetech.com/looking-at-vistas-user-account-control/&amp;title=Looking+at+Vista%27s+User+Account+Control&amp;desc=I%20blogged%20ever%20so%20briefly%20about%20Vista%27s%20new%20User%20Account%20Control%20before%20and%20what%20it%20will%20mean%20to%20users%20in%20its%20current%20form%20so%20I%27m%20quite%20happy%20to%20find%20that%20ZDNet%20is%20experiencing%20the%20same%20type%20of%20mind-numbing%20annoyances%20with%20UAC%20as%20I.%0D%0A%0D%0AIt%27s%20clear%20that%20Microsoft%20is%20attempting%20to%20instill%20safe%20practice" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.howinthetech.com/looking-at-vistas-user-account-control/&amp;title=Looking+at+Vista%27s+User+Account+Control" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.howinthetech.com/looking-at-vistas-user-account-control/&amp;title=Looking+at+Vista%27s+User+Account+Control" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.howinthetech.com/looking-at-vistas-user-account-control/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="sexy-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.howinthetech.com/looking-at-vistas-user-account-control/&amp;title=Looking+at+Vista%27s+User+Account+Control" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=Looking+at+Vista%27s+User+Account+Control+-+http://b2l.me/gpfvc+" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.howinthetech.com/looking-at-vistas-user-account-control/&amp;submitHeadline=Looking+at+Vista%27s+User+Account+Control&amp;submitSummary=I%20blogged%20ever%20so%20briefly%20about%20Vista%27s%20new%20User%20Account%20Control%20before%20and%20what%20it%20will%20mean%20to%20users%20in%20its%20current%20form%20so%20I%27m%20quite%20happy%20to%20find%20that%20ZDNet%20is%20experiencing%20the%20same%20type%20of%20mind-numbing%20annoyances%20with%20UAC%20as%20I.%0D%0A%0D%0AIt%27s%20clear%20that%20Microsoft%20is%20attempting%20to%20instill%20safe%20practice&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="sexy-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.howinthetech.com/looking-at-vistas-user-account-control/&amp;t=Looking+at+Vista%27s+User+Account+Control" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="sexy-friendfeed">
			<a href="http://www.friendfeed.com/share?title=Looking+at+Vista%27s+User+Account+Control&amp;link=http://www.howinthetech.com/looking-at-vistas-user-account-control/" rel="nofollow" class="external" title="Share this on FriendFeed">Share this on FriendFeed</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.howinthetech.com/looking-at-vistas-user-account-control/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Configure your own free VPN with Hamachi</title>
		<link>http://www.howinthetech.com/configure-your-own-free-vpn/</link>
		<comments>http://www.howinthetech.com/configure-your-own-free-vpn/#comments</comments>
		<pubDate>Tue, 02 May 2006 20:36:34 +0000</pubDate>
		<dc:creator>Adam Myers</dc:creator>
				<category><![CDATA[How in the Tech]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.evileyez.org/configure-your-own-free-vpn/</guid>
		<description><![CDATA[


Hamachi is a program that enables you to quickly configure a secure private network between computers over the traditionally insecure Internet. At it&#8217;s core, this slick solution allows you to access your computers remotely (over VNC or RDP), safe Windows File Sharing, play LAN games, or deploy inherently private Web or FTP servers. Essentially it [...]]]></description>
			<content:encoded><![CDATA[<p><div style="float: right; margin-top:0px;margin-left:5px;"><script type="text/javascript"><!--
google_ad_client = "pub-7614676277221702";
google_ad_slot = "8180382492";
google_ad_width = 336;
google_ad_height = 280;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</div></p>
<p><a href="http://www.hamachi.cc/">Hamachi</a> is a program that enables you to quickly configure a secure private network between computers over the traditionally insecure Internet. At it&#8217;s core, this slick solution allows you to access your computers remotely (over VNC or RDP), safe Windows File Sharing, play LAN games, or deploy inherently private Web or FTP servers. Essentially it allows people to build ad hoc local area networks, easily.</p>
<p>Installation of Hamachi is of standard fare.</p>
<ol>
<li><a href="http://www.hamachi.cc/download">Download</a> the most recent version of the software (<a href="http://files.hamachi.cc/priv/HamachiSetup-1.0.0.53-en.exe">version 1.0.0.56</a> as of this writing).</li>
<li>Step through the installation process; accepting the default options is recommended. A reboot may be necessary afterwards, to finish off the installation process.
<div>
<div style="text-align: center;"><img src="/images/hamachi_0.png" alt="" /></div>
</div>
</li>
<li>Once installed, launch Hamachi from the newly created shortcut. Here Hamachi will step you through the account creation process by requesting a nickname and creating the account on the Hamachi server. You will be presented with your own unique 5.X.X.X IP address upon completition.
<div>
<div style="text-align: center;"><img src="/images/hamachi_1.png" alt="" /></div>
</div>
<div>
<div style="text-align: center;"><img src="/images/hamachi_2.png" alt="" /></div>
</div>
</li>
<li>After account creation and login, it is time to create your private network. Click &#8220;Create new network&#8221; and provide the requested information. The password chosen here should be highly secure as it is critical to Hamachi&#8217;s security model.
<div>
<div style="text-align: center;"><img src="/images/hamachi_3.png" alt="" /></div>
</div>
</li>
<li>On a second computer, follow the installation process from above but instead of creating a new network, you want to &#8220;Join existing network&#8221; using the password created as authentication.</li>
</ol>
<p><img src="/images/hamachi_5.png" alt="" align="left" />So how does this all work? From Hamachi&#8217;s website, the &#8220;peers utilize the help of a 3rd node called <em>mediation  		server</em> to locate each other and to boot strap the connection between 		themselves. The connection itself is direct and once it&#8217;s 		established <strong>no traffic flows through our servers</strong>.&#8221; Basically, the mediation server is what allows Hamachi to be a zero-configuration VPN by handling all the complications of NAT and Firewall traversal for you, behind the scenes. It is important to note that the Hamachi does not forward any traffic &#8211; it&#8217;s only purpose is to assist in establishing the direct point-to-point connection between the computers.</p>
<p>Is it the total panacea that every wifi user is looking for &#8211; that is, an easy to install/configure/maintain and most importantly secure VPN solution? Surprisingly for a free product, it is! There is one caveat, in order to truly emulate standard VPN functionality, Hamachi requires a computer to connect to; you must leave your home computer running in order for your hotspot laptop to bounce off of it, via Remote Desktop.</p>
<p>Give it a go, I highly recommend it.</p>
<p>Running Hamachi as a service in Linux:<br />
<a href="http://forums.hamachi.cc/viewtopic.php?t=3421">http://forums.hamachi.cc/viewtopic.php?t=3421</a></p>
<p>Hamachi on Mac OSX Beta info:<br />
<a href="http://forums.hamachi.cc/viewtopic.php?t=4260">http://forums.hamachi.cc/viewtopic.php?t=4260</a></p>
<p>[tags]VPN, Hamachi, Secure WiFi[/tags]</p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-delicious">
			<a href="http://del.icio.us/post?url=http://www.howinthetech.com/configure-your-own-free-vpn/&amp;title=Configure+your+own+free+VPN+with+Hamachi" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.howinthetech.com/configure-your-own-free-vpn/&amp;title=Configure+your+own+free+VPN+with+Hamachi" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="sexy-diigo">
			<a href="http://www.diigo.com/post?url=http://www.howinthetech.com/configure-your-own-free-vpn/&amp;title=Configure+your+own+free+VPN+with+Hamachi&amp;desc=%0D%0A%0D%0AHamachi%20is%20a%20program%20that%20enables%20you%20to%20quickly%20configure%20a%20secure%20private%20network%20between%20computers%20over%20the%20traditionally%20insecure%20Internet.%20At%20it%27s%20core%2C%20this%20slick%20solution%20allows%20you%20to%20access%20your%20computers%20remotely%20%28over%20VNC%20or%20RDP%29%2C%20safe%20Windows%20File%20Sharing%2C%20play%20LAN%20games%2C%20or%20deploy%20i" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.howinthetech.com/configure-your-own-free-vpn/&amp;title=Configure+your+own+free+VPN+with+Hamachi" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.howinthetech.com/configure-your-own-free-vpn/&amp;title=Configure+your+own+free+VPN+with+Hamachi" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.howinthetech.com/configure-your-own-free-vpn/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="sexy-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.howinthetech.com/configure-your-own-free-vpn/&amp;title=Configure+your+own+free+VPN+with+Hamachi" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=Configure+your+own+free+VPN+with+Hamachi+-+http://b2l.me/gr795+" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.howinthetech.com/configure-your-own-free-vpn/&amp;submitHeadline=Configure+your+own+free+VPN+with+Hamachi&amp;submitSummary=%0D%0A%0D%0AHamachi%20is%20a%20program%20that%20enables%20you%20to%20quickly%20configure%20a%20secure%20private%20network%20between%20computers%20over%20the%20traditionally%20insecure%20Internet.%20At%20it%27s%20core%2C%20this%20slick%20solution%20allows%20you%20to%20access%20your%20computers%20remotely%20%28over%20VNC%20or%20RDP%29%2C%20safe%20Windows%20File%20Sharing%2C%20play%20LAN%20games%2C%20or%20deploy%20i&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="sexy-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.howinthetech.com/configure-your-own-free-vpn/&amp;t=Configure+your+own+free+VPN+with+Hamachi" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="sexy-friendfeed">
			<a href="http://www.friendfeed.com/share?title=Configure+your+own+free+VPN+with+Hamachi&amp;link=http://www.howinthetech.com/configure-your-own-free-vpn/" rel="nofollow" class="external" title="Share this on FriendFeed">Share this on FriendFeed</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.howinthetech.com/configure-your-own-free-vpn/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>McAfee update exterminates Excel</title>
		<link>http://www.howinthetech.com/mcafee-update-exterminates-excel/</link>
		<comments>http://www.howinthetech.com/mcafee-update-exterminates-excel/#comments</comments>
		<pubDate>Tue, 14 Mar 2006 03:59:39 +0000</pubDate>
		<dc:creator>Adam Myers</dc:creator>
				<category><![CDATA[Techlines Today]]></category>
		<category><![CDATA[Microsoft Excel]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.evileyez.org/mcafee-update-exterminates-excel/</guid>
		<description><![CDATA[&#8220;An error in McAfee&#8217;s virus definition file released Friday morning caused the company&#8217;s consumer and enterprise antivirus products to flag Microsoft&#8217;s Excel, as well as other applications on users&#8217; PCs, as a virus called W95/CTX, Joe Telafici, director of operations at McAfee&#8217;s Avert labs, told CNET News.com.&#8221;
The files they are gone.
It seems McAfee ate them.
Go [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;An error in McAfee&#8217;s virus definition file released Friday morning caused the company&#8217;s consumer and enterprise antivirus products to flag Microsoft&#8217;s Excel, as well as other applications on users&#8217; PCs, as a virus called W95/CTX, Joe Telafici, director of operations at McAfee&#8217;s Avert labs, told CNET News.com.&#8221;</p>
<p>The files they are gone.<br />
It seems McAfee ate them.<br />
Go home from work now.</p>
<p><a href="http://news.com.com/McAfee update exterminates Excel/2100-1002_3-6048709.html?tag=newsmap">read more</a> | <a href="http://digg.com/technology/McAfee_update_exterminates_Excel">digg story</a></p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-delicious">
			<a href="http://del.icio.us/post?url=http://www.howinthetech.com/mcafee-update-exterminates-excel/&amp;title=McAfee+update+exterminates+Excel" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.howinthetech.com/mcafee-update-exterminates-excel/&amp;title=McAfee+update+exterminates+Excel" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="sexy-diigo">
			<a href="http://www.diigo.com/post?url=http://www.howinthetech.com/mcafee-update-exterminates-excel/&amp;title=McAfee+update+exterminates+Excel&amp;desc=%22An%20error%20in%20McAfee%27s%20virus%20definition%20file%20released%20Friday%20morning%20caused%20the%20company%27s%20consumer%20and%20enterprise%20antivirus%20products%20to%20flag%20Microsoft%27s%20Excel%2C%20as%20well%20as%20other%20applications%20on%20users%27%20PCs%2C%20as%20a%20virus%20called%20W95%2FCTX%2C%20Joe%20Telafici%2C%20director%20of%20operations%20at%20McAfee%27s%20Avert%20labs%2C%20told%20CNE" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.howinthetech.com/mcafee-update-exterminates-excel/&amp;title=McAfee+update+exterminates+Excel" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.howinthetech.com/mcafee-update-exterminates-excel/&amp;title=McAfee+update+exterminates+Excel" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.howinthetech.com/mcafee-update-exterminates-excel/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="sexy-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.howinthetech.com/mcafee-update-exterminates-excel/&amp;title=McAfee+update+exterminates+Excel" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=McAfee+update+exterminates+Excel+-+http://b2l.me/gxsv5+" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.howinthetech.com/mcafee-update-exterminates-excel/&amp;submitHeadline=McAfee+update+exterminates+Excel&amp;submitSummary=%22An%20error%20in%20McAfee%27s%20virus%20definition%20file%20released%20Friday%20morning%20caused%20the%20company%27s%20consumer%20and%20enterprise%20antivirus%20products%20to%20flag%20Microsoft%27s%20Excel%2C%20as%20well%20as%20other%20applications%20on%20users%27%20PCs%2C%20as%20a%20virus%20called%20W95%2FCTX%2C%20Joe%20Telafici%2C%20director%20of%20operations%20at%20McAfee%27s%20Avert%20labs%2C%20told%20CNE&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="sexy-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.howinthetech.com/mcafee-update-exterminates-excel/&amp;t=McAfee+update+exterminates+Excel" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="sexy-friendfeed">
			<a href="http://www.friendfeed.com/share?title=McAfee+update+exterminates+Excel&amp;link=http://www.howinthetech.com/mcafee-update-exterminates-excel/" rel="nofollow" class="external" title="Share this on FriendFeed">Share this on FriendFeed</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.howinthetech.com/mcafee-update-exterminates-excel/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mac OS X hacked in less than 30 minutes</title>
		<link>http://www.howinthetech.com/mac-os-x-hacked-in-less-than-30-minutes/</link>
		<comments>http://www.howinthetech.com/mac-os-x-hacked-in-less-than-30-minutes/#comments</comments>
		<pubDate>Mon, 06 Mar 2006 23:03:03 +0000</pubDate>
		<dc:creator>Adam Myers</dc:creator>
				<category><![CDATA[Techlines Today]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.evileyez.org/mac-os-x-hacked-in-less-than-30-minutes/</guid>
		<description><![CDATA[&#8220;Gaining root access to a Mac is &#8216;easy pickings,&#8217; according to an individual who in less than 30 minutes won an OS X hacking challenge last month by gaining root control of a machine using an unpublished security vulnerability.&#8221;
I&#8217;m sure this is going to spread like wildfire across the Internets today, but let me take [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;Gaining root access to a Mac is &#8216;easy pickings,&#8217; according to an individual who in less than 30 minutes won an OS X hacking challenge last month by gaining root control of a machine using an unpublished security vulnerability.&#8221;</p>
<p>I&#8217;m sure this is going to spread like wildfire across the Internets today, but let me take a minute to debunk this. As best I see, the website in question allows users to create their own UNIX-style accounts through a LDAP interface. From this remote access shell, the said hacker was able to use a vulnerability to escalate his privileges to root-level. Sure, its a succesful hack, but I&#8217;m not aware of any &#8220;secure&#8221; machines configured to allow users to create their own shell access. Furthermore, I do not believe SSH is even enabled by default on OS X (though to be fair, most admins will turn this on).</p>
<p>What&#8217;s the significance? It&#8217;s not that OS X isn&#8217;t hackable, or that this sysadmin gave far more remote access than is normal; no, it&#8217;s that no one operating system is more or less secure than another. Security is an ongoing project, completed one day, only to begin the next.</p>
<p><a href="http://www.zdnet.com.au/news/security/soa/Mac_OS_X_hacked_in_less_than_30_minutes/0,2000061744,39241748,00.htm">read more</a> | <a href="http://digg.com/apple/Mac_OS_X_hacked_in_less_than_30_minutes">digg story</a></p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-delicious">
			<a href="http://del.icio.us/post?url=http://www.howinthetech.com/mac-os-x-hacked-in-less-than-30-minutes/&amp;title=Mac+OS+X+hacked+in+less+than+30+minutes" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.howinthetech.com/mac-os-x-hacked-in-less-than-30-minutes/&amp;title=Mac+OS+X+hacked+in+less+than+30+minutes" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="sexy-diigo">
			<a href="http://www.diigo.com/post?url=http://www.howinthetech.com/mac-os-x-hacked-in-less-than-30-minutes/&amp;title=Mac+OS+X+hacked+in+less+than+30+minutes&amp;desc=%22Gaining%20root%20access%20to%20a%20Mac%20is%20%27easy%20pickings%2C%27%20according%20to%20an%20individual%20who%20in%20less%20than%2030%20minutes%20won%20an%20OS%20X%20hacking%20challenge%20last%20month%20by%20gaining%20root%20control%20of%20a%20machine%20using%20an%20unpublished%20security%20vulnerability.%22%0D%0A%0D%0AI%27m%20sure%20this%20is%20going%20to%20spread%20like%20wildfire%20across%20the%20Internets%20" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.howinthetech.com/mac-os-x-hacked-in-less-than-30-minutes/&amp;title=Mac+OS+X+hacked+in+less+than+30+minutes" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.howinthetech.com/mac-os-x-hacked-in-less-than-30-minutes/&amp;title=Mac+OS+X+hacked+in+less+than+30+minutes" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.howinthetech.com/mac-os-x-hacked-in-less-than-30-minutes/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="sexy-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.howinthetech.com/mac-os-x-hacked-in-less-than-30-minutes/&amp;title=Mac+OS+X+hacked+in+less+than+30+minutes" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=Mac+OS+X+hacked+in+less+than+30+minutes+-+http://b2l.me/gpeqd+" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.howinthetech.com/mac-os-x-hacked-in-less-than-30-minutes/&amp;submitHeadline=Mac+OS+X+hacked+in+less+than+30+minutes&amp;submitSummary=%22Gaining%20root%20access%20to%20a%20Mac%20is%20%27easy%20pickings%2C%27%20according%20to%20an%20individual%20who%20in%20less%20than%2030%20minutes%20won%20an%20OS%20X%20hacking%20challenge%20last%20month%20by%20gaining%20root%20control%20of%20a%20machine%20using%20an%20unpublished%20security%20vulnerability.%22%0D%0A%0D%0AI%27m%20sure%20this%20is%20going%20to%20spread%20like%20wildfire%20across%20the%20Internets%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="sexy-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.howinthetech.com/mac-os-x-hacked-in-less-than-30-minutes/&amp;t=Mac+OS+X+hacked+in+less+than+30+minutes" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="sexy-friendfeed">
			<a href="http://www.friendfeed.com/share?title=Mac+OS+X+hacked+in+less+than+30+minutes&amp;link=http://www.howinthetech.com/mac-os-x-hacked-in-less-than-30-minutes/" rel="nofollow" class="external" title="Share this on FriendFeed">Share this on FriendFeed</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.howinthetech.com/mac-os-x-hacked-in-less-than-30-minutes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OSx86 10.4.4 Security Broken</title>
		<link>http://www.howinthetech.com/osx86-1044-security-broken/</link>
		<comments>http://www.howinthetech.com/osx86-1044-security-broken/#comments</comments>
		<pubDate>Tue, 14 Feb 2006 16:40:01 +0000</pubDate>
		<dc:creator>Adam Myers</dc:creator>
				<category><![CDATA[Techlines Today]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.evileyez.org/?p=82</guid>
		<description><![CDATA[Apple&#8217;s hardware based platform-protection for Mac OS X has been broken. What has it been, a month or less since the hardware was released? Artificially restricting people from something they want (enough to actually buy it, even!) combined with an interesting challenge for hackers by using new protection methods is a good way to get [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.osx86project.org/index.php?option=com_content&amp;task=view&amp;id=116&amp;Itemid=2">Apple&#8217;s hardware based platform-protection for Mac OS X</a> has been broken. What has it been, a month or less since the hardware was released? Artificially restricting people from something they want (enough to actually buy it, even!) combined with an interesting challenge for hackers by using new protection methods is a good way to get your software cracked quickly.</p>
<p>What a waste of engineering. This is why all the effort behind HD movie disc protection is stupid. Not only are you going to have hackers salivating over the idea of dismantling the system just because its something new and interesting (and the fame that comes with it), but you&#8217;re also creating a huge inconvenience for people that actually want to buy your product!</p>
<p>Spending a little money to make some trivial protection to stop the most casual copying is the only thing worthwhile. These companies should put a fair price on their product and sell to the people that want it. Putting a premium price on BD-ROMs and slapping ridiculous protection on them is pointless. They should cost the same as DVDs and have only trivial protection. DVD protection is easy enough for grandma to bypass yet they still fly off the shelves.</p>
<p>I hope Sony/Toshiba/Movie studios wake up when the public decides they don&#8217;t want to pay for this crap.</p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-delicious">
			<a href="http://del.icio.us/post?url=http://www.howinthetech.com/osx86-1044-security-broken/&amp;title=OSx86+10.4.4+Security+Broken" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.howinthetech.com/osx86-1044-security-broken/&amp;title=OSx86+10.4.4+Security+Broken" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="sexy-diigo">
			<a href="http://www.diigo.com/post?url=http://www.howinthetech.com/osx86-1044-security-broken/&amp;title=OSx86+10.4.4+Security+Broken&amp;desc=Apple%27s%20hardware%20based%20platform-protection%20for%20Mac%20OS%20X%20has%20been%20broken.%20What%20has%20it%20been%2C%20a%20month%20or%20less%20since%20the%20hardware%20was%20released%3F%20Artificially%20restricting%20people%20from%20something%20they%20want%20%28enough%20to%20actually%20buy%20it%2C%20even%21%29%20combined%20with%20an%20interesting%20challenge%20for%20hackers%20by%20using%20new%20prot" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.howinthetech.com/osx86-1044-security-broken/&amp;title=OSx86+10.4.4+Security+Broken" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.howinthetech.com/osx86-1044-security-broken/&amp;title=OSx86+10.4.4+Security+Broken" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.howinthetech.com/osx86-1044-security-broken/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="sexy-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.howinthetech.com/osx86-1044-security-broken/&amp;title=OSx86+10.4.4+Security+Broken" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=OSx86+10.4.4+Security+Broken+-+http://b2l.me/gu3c9+" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.howinthetech.com/osx86-1044-security-broken/&amp;submitHeadline=OSx86+10.4.4+Security+Broken&amp;submitSummary=Apple%27s%20hardware%20based%20platform-protection%20for%20Mac%20OS%20X%20has%20been%20broken.%20What%20has%20it%20been%2C%20a%20month%20or%20less%20since%20the%20hardware%20was%20released%3F%20Artificially%20restricting%20people%20from%20something%20they%20want%20%28enough%20to%20actually%20buy%20it%2C%20even%21%29%20combined%20with%20an%20interesting%20challenge%20for%20hackers%20by%20using%20new%20prot&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="sexy-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.howinthetech.com/osx86-1044-security-broken/&amp;t=OSx86+10.4.4+Security+Broken" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="sexy-friendfeed">
			<a href="http://www.friendfeed.com/share?title=OSx86+10.4.4+Security+Broken&amp;link=http://www.howinthetech.com/osx86-1044-security-broken/" rel="nofollow" class="external" title="Share this on FriendFeed">Share this on FriendFeed</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.howinthetech.com/osx86-1044-security-broken/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Wee Bit Anal Over Strong Passwords?</title>
		<link>http://www.howinthetech.com/strong_password/</link>
		<comments>http://www.howinthetech.com/strong_password/#comments</comments>
		<pubDate>Wed, 10 Aug 2005 22:25:47 +0000</pubDate>
		<dc:creator>Adam Myers</dc:creator>
				<category><![CDATA[Off the Topic]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I'd just like to say that as a sysadmin, I'm all for strong passwords and enforcement thereof, but this is a guaranteed way to have your users use sticky notes cheat-sheets:

* The password must contain at least one (1) UPPER CASE letter.
* The password must contain at least one (1) LOWER CASE letter.
* The password must contain at least one (1) numeric digit: (0,1,2,3,4,5,6,7,8,9).
* The password cannot contain any four (4) consecutive characters of your username
* The password must be at least eight (8) characters long.
* The password cannot be changed to any of your three (3) previous passwords.
* The minimum user-defined password life is one (1) day.
* The password cannot contain any dictionary word greater than or equal to four (4) characters.
* The password will expire annually.
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;d just like to say that as a sysadmin, I&#8217;m all for strong passwords and enforcement thereof, but this is a guaranteed way to have your users use sticky notes cheat-sheets:</p>
<p>* The password must contain at least one (1) UPPER CASE letter.<br />
* The password must contain at least one (1) LOWER CASE letter.<br />
* The password must contain at least one (1) numeric digit: (0,1,2,3,4,5,6,7,8,9).<br />
* The password cannot contain any four (4) consecutive characters of your username<br />
* The password must be at least eight (8) characters long.<br />
* The password cannot be changed to any of your three (3) previous passwords.<br />
* The minimum user-defined password life is one (1) day.<br />
* The password cannot contain any dictionary word greater than or equal to four (4) characters.<br />
* The password will expire annually.</p>
<p>&#8230;the requirements for a registration system I came across today. Yoi!</p>


<!-- Begin SexyBookmarks Menu Code -->
<div class="sexy-bookmarks sexy-bookmarks-expand">
<ul class="socials">
		<li class="sexy-delicious">
			<a href="http://del.icio.us/post?url=http://www.howinthetech.com/strong_password/&amp;title=A+Wee+Bit+Anal+Over+Strong+Passwords%3F" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="sexy-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.howinthetech.com/strong_password/&amp;title=A+Wee+Bit+Anal+Over+Strong+Passwords%3F" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="sexy-diigo">
			<a href="http://www.diigo.com/post?url=http://www.howinthetech.com/strong_password/&amp;title=A+Wee+Bit+Anal+Over+Strong+Passwords%3F&amp;desc=I%27d%20just%20like%20to%20say%20that%20as%20a%20sysadmin%2C%20I%27m%20all%20for%20strong%20passwords%20and%20enforcement%20thereof%2C%20but%20this%20is%20a%20guaranteed%20way%20to%20have%20your%20users%20use%20sticky%20notes%20cheat-sheets%3A%0D%0A%0D%0A%2A%20The%20password%20must%20contain%20at%20least%20one%20%281%29%20UPPER%20CASE%20letter.%0D%0A%2A%20The%20password%20must%20contain%20at%20least%20one%20%281%29%20LOWER%20CASE%20le" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="sexy-reddit">
			<a href="http://reddit.com/submit?url=http://www.howinthetech.com/strong_password/&amp;title=A+Wee+Bit+Anal+Over+Strong+Passwords%3F" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="sexy-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.howinthetech.com/strong_password/&amp;title=A+Wee+Bit+Anal+Over+Strong+Passwords%3F" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="sexy-technorati">
			<a href="http://technorati.com/faves?add=http://www.howinthetech.com/strong_password/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="sexy-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://www.howinthetech.com/strong_password/&amp;title=A+Wee+Bit+Anal+Over+Strong+Passwords%3F" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="sexy-twitter">
			<a href="http://twitter.com/home?status=A+Wee+Bit+Anal+Over+Strong+Passwords%3F+-+http://b2l.me/gsgd3+" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="sexy-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.howinthetech.com/strong_password/&amp;submitHeadline=A+Wee+Bit+Anal+Over+Strong+Passwords%3F&amp;submitSummary=I%27d%20just%20like%20to%20say%20that%20as%20a%20sysadmin%2C%20I%27m%20all%20for%20strong%20passwords%20and%20enforcement%20thereof%2C%20but%20this%20is%20a%20guaranteed%20way%20to%20have%20your%20users%20use%20sticky%20notes%20cheat-sheets%3A%0D%0A%0D%0A%2A%20The%20password%20must%20contain%20at%20least%20one%20%281%29%20UPPER%20CASE%20letter.%0D%0A%2A%20The%20password%20must%20contain%20at%20least%20one%20%281%29%20LOWER%20CASE%20le&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="sexy-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.howinthetech.com/strong_password/&amp;t=A+Wee+Bit+Anal+Over+Strong+Passwords%3F" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="sexy-friendfeed">
			<a href="http://www.friendfeed.com/share?title=A+Wee+Bit+Anal+Over+Strong+Passwords%3F&amp;link=http://www.howinthetech.com/strong_password/" rel="nofollow" class="external" title="Share this on FriendFeed">Share this on FriendFeed</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>
<!-- End SexyBookmarks Menu Code -->

]]></content:encoded>
			<wfw:commentRss>http://www.howinthetech.com/strong_password/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
