<?xml version="1.0" encoding="UTF-8"?>




<rss version="2.0"> <channel> <title>Evernote Openbook: General InfoSec Stuff</title>
<link>http://www.evernote.com/pub/ssulistyo/InfoSecStuff</link>
<description>Notes from ssulistyo&#039;s  Evernote Openbook: General InfoSec Stuff</description> 

  
  <lastBuildDate>Tue, 17 Mar 2009 08:33:51 GMT</lastBuildDate>
 
  
  <item> <title>Clip:http://www.lockdown.co.uk/?pg=combi&amp;s=articles</title> <link>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#6a05796f-b689-4b09-87da-e0876fd82c82</link>
  <description><![CDATA[
    
    
    
        
        <div class="ennote"></div>
    
    ]]></description> <pubDate>Tue, 17 Mar 2009 08:33:51 GMT</pubDate> <guid>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#6a05796f-b689-4b09-87da-e0876fd82c82</guid> 
  
  </item>

  
  <item> <title>25c3 check out</title> <link>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#c8028a3f-0fff-4f2e-9b6d-ebf74e148b7d</link>
  <description><![CDATA[
    
    
    
        
        <div class="ennote">
<div>25c3 check out</div>
<div> </div>
<div>itx wifi cracking box</div>
<div><a shape="rect" href="http://www.awgh.org/" target="_blank">http://www.awgh.org/</a><br clear="none"/><br clear="none"/>http://www.foodhacking.com/<br clear="none"/><br clear="none"/>http://www.stainlessapp.com/<br clear="none"/></div>
</div>
    
    ]]></description> <pubDate>Mon, 29 Dec 2008 15:13:46 GMT</pubDate> <guid>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#c8028a3f-0fff-4f2e-9b6d-ebf74e148b7d</guid> 
  
  </item>

  
  <item> <title>Secure USB Sticks</title> <link>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#4c105ab0-9d89-4828-bc27-69689036a12b</link>
  <description><![CDATA[
    
    
    
        
        <div class="ennote"><div> Links:</div><div> 
</div><div><a href="http://www.kingston.com/flash/DataTravelers_enterprise.asp" shape="rect">http://www.kingston.com/flash/DataTravelers_enterprise.asp</a></div><div><a href="https://www.ironkey.com/" shape="rect">https://www.ironkey.com/</a></div><div><a href="http://www.corsairmemory.com/products/padlock.aspx" shape="rect">http://www.corsairmemory.com/products/padlock.aspx</a></div><div> 
</div><div> 
</div><div>Offensichtlich wird in diesem Bereich aber auch viel Schund verkauft:</div><div><a href="http://www.heise.de/security/USB-Stick-mit-Hardware-AES-Verschluesselung-geknackt--/artikel/113014" shape="rect">http://www.heise.de/security/USB-Stick-mit-Hardware-AES-Verschluesselung-geknackt--/artikel/113014</a></div><div><a href="http://www.heise.de/security/USB-Stick-mit-PIN-Abfrage--/artikel/110798" shape="rect">http://www.heise.de/security/USB-Stick-mit-PIN-Abfrage--/artikel/110798</a> &lt;--- Corsair Padlock</div><div><a href="http://www.heise.de/security/Sichere-USB-Sticks-geknackt--/artikel/103942" shape="rect">http://www.heise.de/security/Sichere-USB-Sticks-geknackt--/artikel/103942</a></div></div>
    
    ]]></description> <pubDate>Tue, 28 Oct 2008 19:01:13 GMT</pubDate> <guid>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#4c105ab0-9d89-4828-bc27-69689036a12b</guid> 
  
  </item>

  
  <item> <title>Untitled Note</title> <link>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#ddf52fc7-7602-43ce-ae32-a62045cd58a1</link>
  <description><![CDATA[
    
    
    
        
        <div class="ennote"></div>
    
    ]]></description> <pubDate>Tue, 28 Oct 2008 18:59:57 GMT</pubDate> <guid>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#ddf52fc7-7602-43ce-ae32-a62045cd58a1</guid> 
  
  </item>

  
  <item> <title>D-A-CH Security 2009</title> <link>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#494d9d84-83cc-4d4c-8a9d-4c15f7741a40</link>
  <description><![CDATA[
    
    
    
        
        <div class="ennote">
Call for Papers
<p> </p>
<p align="center"><a href="http://www.syssec.at/fileadmin/files/DACHSecurity2009/DACH_Security_2009-CFP.pdf" target="CfP" shape="rect">CALL FOR PAPERS ZUM DOWNLOADEN!</a></p>
<p> </p>
<p> </p>
<p align="justify">Ziel der Veranstaltung ist es, eine interdisziplinäre Übersicht zum aktuellen Stand der IT-Sicherheit in Industrie, Dienstleistung, Verwaltung und Wissenschaft in Deutschland, Österreich und der Schweiz zu geben. Insbesondere sollen Aspekte aus den Bereichen Forschung und Entwicklung, Lehre, Aus- und Weiterbildung vorgestellt, relevante Anwendungen aufgezeigt sowie neue Technologien und daraus resultierende Produktentwicklungen konzeptionell dargestellt werden. Da IT-Sicherheit integrierter Bestandteil nahezu aller informationstechnischer Anwendungen und Prozesse ist, sind auch Beiträge zu rechtlichen Rahmenbedingungen und wirtschaftlichen Faktoren gewünscht.</p>
<p> </p>
Themen dieser Arbeitskonferenz

<ul><li>Risiko- und Sicherheitsmanagement</li><li>Incident Handling und Business Continuity</li><li>Sichere elektronische Geschäftsprozesse</li><li>Multimedia und On-Demand-Dienste</li><li>Identitäts- und Rechtemanagement</li><li>Digitale Signaturen und Archivierung</li><li>Biometrische Verfahren und Anwendungen</li><li>Computerkriminalität und Gegenmaßnahmen</li><li>Botnetze, Spam und Phishing</li><li>Trusted Computing und DRM</li><li>Security Awareness</li><li>Secure Embedded Systems</li><li>Sicherheitsrelevante Anwendungen</li><li>WLAN, Mobilfunk und mobile Endgeräte</li></ul>

<ul><li>eGovernment, eHealth und eCommerce</li><li>Kritische Infrastrukturen</li><li>Sichere Webservices</li><li>Intrusion Detection und Computer-Forensik</li><li>Verfügbarkeit und Notfallsplanung</li><li>Sicherheitsinfrastrukturen und PKI</li><li>Authentifikation und Single-Sign-On</li><li>Protokollierung und Überwachung</li><li>Sicherheitstoken, Smartcards und RFID</li><li>Pervasive und Ubiquitous Computing</li><li>Netzwerklösungen, VPN und Remote Access</li><li>Privacy, Datenschutz und Rechtsfragen</li><li>Best Practice und Fallstudien</li><li>Folgen, Akzeptanz, Perspektiven</li></ul>

</div>
    
    ]]></description> <pubDate>Tue, 28 Oct 2008 11:19:17 GMT</pubDate> <guid>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#494d9d84-83cc-4d4c-8a9d-4c15f7741a40</guid> 
  
  </item>

  
  <item> <title>infosec ideas</title> <link>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#1d12be16-c2e3-454d-aeb9-42f60d11b8af</link>
  <description><![CDATA[
    
    
    
        
        <div class="ennote">Bot net grid &amp; cloud computing</div>
    
    ]]></description> <pubDate>Sat, 18 Oct 2008 14:50:27 GMT</pubDate> <guid>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#1d12be16-c2e3-454d-aeb9-42f60d11b8af</guid> 
  
  </item>

  
  <item> <title>Sources Shortlist</title> <link>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#9dfb3d17-5189-4c94-b21a-e1e404002307</link>
  <description><![CDATA[
    
    
    
        
        <div style="background-color:#ffffff;" class="ennote">
<div>Sources Shortlist</div>
<div> </div>
<div>[Sc03] Schoemaker, Michiel: Identity in Flexible Organizations: Experiences in Dutch Organizations. In: Creativity and Innovation Management, Vol. 12, No. 4, 2003; 191 - 201.</div>
<div> </div>
<div>[HG92] Hirschhorn, L.; Gilmore, T.: The new boundaries of the &quot;boundaryless&quot; company. In: Harvard Business Review, Vol. 70 No. 3, 1992; 104-15.</div>
<div> </div>
<div>[RS99] Robbins, Stephanie S.; Stylianou, Antonis C.: Post-merger systems integration: the impact on IS capabilities. In: Information &amp; Management, Vol. 36, No. 4, October 1999; 205-212</div>
<div> </div>
<div>[BS06] Bhargav-Spantzel, A.; Squicciarini, A. C.; Bertino, E.: Establishing and protecting digital identity in federation systems. In: Journal of Computer Security, Vol. 14, No. 3, 2006; 269-300  </div>
<div> </div>
<div>[HR05] Hommel, Wolfgang; Reiser, Helmut: Federated Identity Management: Die Notwendigkeit zentraler Koordinationsdienste. KiVS Kurzbeiträge und Workshop, 2005; 65-72</div>
<div> </div>
<div>[PW03] Pfitzmann, Birgit; Waidner, Michael: Federated Identity-Management Protocols — Where User Authentication Protocols May Go. 11th Cambridge International Workshop on Security Protocols, 2003; 174</div>
</div>
    
    ]]></description> <pubDate>Fri, 10 Oct 2008 09:15:04 GMT</pubDate> <guid>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#9dfb3d17-5189-4c94-b21a-e1e404002307</guid> 
  
  </item>

  
  <item> <title>Identity Federation Quellen</title> <link>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#8380671f-1309-4147-9db8-1ea3f45190bd</link>
  <description><![CDATA[
    
    
    
        
        <div class="ennote"><p>Version:1.0 StartHTML:0000000149 EndHTML:0000010889 StartFragment:0000000199 EndFragment:0000010855 StartSelection:0000000199 EndSelection:0000010855 Building flexible organizations for fast-moving markets
</p><p><a href="http://www.sciencedirect.com/science?_ob=ArticleURL&amp;#38;_udi=B6V6K-3SWVHX5-2&amp;#38;_user=10&amp;#38;_rdoc=1&amp;#38;_fmt=&amp;#38;_orig=search&amp;#38;_sort=d&amp;#38;view=c&amp;#38;_acct=C000050221&amp;#38;_version=1&amp;#38;_urlVersion=0&amp;#38;_userid=10&amp;#38;md5=dc64e2b8ecf6726fc853b226bf106413" shape="rect">http://www.sciencedirect.com/science?_ob=ArticleURL&amp;_udi=B6V6K-3SWVHX5-2&amp;_user=10&amp;_rdoc=1&amp;_fmt=&amp;_orig=search&amp;_sort=d&amp;view=c&amp;_acct=C000050221&amp;_version=1&amp;_urlVersion=0&amp;_userid=10&amp;md5=dc64e2b8ecf6726fc853b226bf106413</a></p><p><br clear="none"/></p><p>Betwixt and between: Temporary Employees as Liminal Subjects in Flexible Organizations
</p><p><a href="http://oss.sagepub.com/cgi/content/abstract/20/4/601" shape="rect">http://oss.sagepub.com/cgi/content/abstract/20/4/601</a></p><p><br clear="none"/></p><p>Flexible Organizations Through Object-oriented
</p><p>and Transaction-oriented Information Systems
</p><p><a href="http://pbfb5www.uni-paderborn.de/www/WI/WI2/wi2_lit.nsf/663247270b635985c1256bc900519bef/24a84acfefd09784412564e3003b5f74/$FILE/BB37.pdf" shape="rect">http://pbfb5www.uni-paderborn.de/www/WI/WI2/wi2_lit.nsf/663247270b635985c1256bc900519bef/24a84acfefd09784412564e3003b5f74/$FILE/BB37.pdf</a></p><p><br clear="none"/></p><p>Identity in Flexible Organizations: Experiences in Dutch Organizations
</p><p><a href="http://www3.interscience.wiley.com/journal/118890767/abstract?CRETRY=1" shape="rect">http://www3.interscience.wiley.com/journal/118890767/abstract?CRETRY=1&amp;SRETRY=0</a></p><p><br clear="none"/></p><p>The flexible firm and the flexible coworker
</p><p><a href="http://www.ingentaconnect.com/content/mcb/086/2000/00000012/00000004/art00004" shape="rect">http://www.ingentaconnect.com/content/mcb/086/2000/00000012/00000004/art00004</a></p><p><br clear="none"/></p><p>The new boundaries of the &quot;boundaryless&quot; company.
</p><p><a href="http://www.ncbi.nlm.nih.gov/pubmed/10117998" shape="rect">http://www.ncbi.nlm.nih.gov/pubmed/10117998</a></p><p><br clear="none"/></p><p><b>On Adaptive Identity Management: The Next Generation of Identity Management Technologies</b></p><p><a href="http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.4.4957" shape="rect">http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.4.4957</a></p><p><br clear="none"/></p><p>Planning for post-merger integration—eight lessons for merger success
</p><p><a href="http://www.sciencedirect.com/science?_ob=ArticleURL" shape="rect">http://www.sciencedirect.com/science?_ob=ArticleURL&amp;_udi=B6V6K-45K071G-4M&amp;_user=10&amp;_rdoc=1&amp;_fmt=&amp;_orig=search&amp;_sort=d&amp;view=c&amp;_acct=C000050221&amp;_version=1&amp;_urlVersion=0&amp;_userid=10&amp;md5=57407f7a7b69ebb137e8d92b2473ed09</a></p><p><br clear="none"/></p><p>The Drivers of Success in Post-Merger Integration
</p><p><a href="http://www.sciencedirect.com/science?_ob=ArticleURL" shape="rect">http://www.sciencedirect.com/science?_ob=ArticleURL&amp;_udi=B6W6S-4C0V36H-6&amp;_user=10&amp;_rdoc=1&amp;_fmt=&amp;_orig=search&amp;_sort=d&amp;view=c&amp;_acct=C000050221&amp;_version=1&amp;_urlVersion=0&amp;_userid=10&amp;md5=3525cb639fc3b69702f50ba957993f8b</a></p><p><br clear="none"/></p><p>Post-merger systems integration: the impact on IS capabilities
</p><p><a href="http://www.sciencedirect.com/science?_ob=ArticleURL" shape="rect">http://www.sciencedirect.com/science?_ob=ArticleURL&amp;_udi=B6VD0-3X8327D-2&amp;_user=10&amp;_rdoc=1&amp;_fmt=&amp;_orig=search&amp;_sort=d&amp;view=c&amp;_acct=C0000502...</a></p></div>
    
    ]]></description> <pubDate>Thu, 09 Oct 2008 17:51:18 GMT</pubDate> <guid>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#8380671f-1309-4147-9db8-1ea3f45190bd</guid> 
  
  </item>

  
  <item> <title>subway hack comment</title> <link>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#79d45ab7-2bf3-445f-b735-5778757ab142</link>
  <description><![CDATA[
    
    
    
        
        <div class="ennote">Here is the presentation: <div>http://www-tech.mit.edu/V128/N30/subway/Defcon_Presentation.pdf </div><div><br clear="none"/></div><div>Mirrors: </div><div>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#07ff6ce9-1aa9-45e9-8bd2-10ce0805e534 </div><div>https://dl.getdropbox.com/u/77164/anatomy%20of%20a%20subway%20hack.pdf </div><div><br clear="none"/></div><div>Also, a vulnerability assessment report: </div><div>http://blog.wired.com/27bstroke6/files/vulnerability_assessment_of_the_mtba_system.pdf</div></div>
    
    ]]></description> <pubDate>Sun, 10 Aug 2008 03:46:57 GMT</pubDate> <guid>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#79d45ab7-2bf3-445f-b735-5778757ab142</guid> 
  
  </item>

  
  <item> <title>anatomy of a subway hack</title> <link>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#07ff6ce9-1aa9-45e9-8bd2-10ce0805e534</link>
  <description><![CDATA[
    
    
      <center>
         <a href="http://www.evernote.com/pub/ssulistyo/InfoSecStuff#07ff6ce9-1aa9-45e9-8bd2-10ce0805e534"><img src="http://www.evernote.com/shard/s1/thumb/07ff6ce9-1aa9-45e9-8bd2-10ce0805e534"/></a>
      </center>
    
    
    ]]></description> <pubDate>Sun, 10 Aug 2008 03:16:23 GMT</pubDate> <guid>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#07ff6ce9-1aa9-45e9-8bd2-10ce0805e534</guid> 
  
    <enclosure url="http://www.evernote.com/shard/s1/thumb/07ff6ce9-1aa9-45e9-8bd2-10ce0805e534"
               length="0" type="image/jpeg"/>
  
  </item>

  
  <item> <title>Press Release</title> <link>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#a116bdc6-5808-4cef-8812-0a4cc530baec</link>
  <description><![CDATA[
    
    
    
        <a href="http://www.evernote.com/pub/ssulistyo/InfoSecStuff#a116bdc6-5808-4cef-8812-0a4cc530baec"><img align="right" src="http://www.evernote.com/shard/s1/thumb/a116bdc6-5808-4cef-8812-0a4cc530baec"/></a>
        <div style="background-color:#ffffff;" class="ennote">

<p>Press Release<br clear="none"/>
3 June 2008<br clear="none"/>
<a href="http://www.enisa.europa.eu/" shape="rect">http://www.enisa.europa.eu</a></p>

Printing – the ‘forgotten’ security link to safeguard business assets. EU Agency ENISA launches report on ‘Secure Printing’
ENISA, the EU Agency for European Network and Information Security, launches its report on “Secure Printing’ with recommendations to business on secure printing and copying of confidential data. Printing/copying devices can be penetrated and hijacked for fraud so that sensitive data or identity is easily stolen. But 350 surveyed European organisations have little awareness of the costs and risks of uncontrolled printing, the Agency report shows.
<p align="left">New printing techniques provide ways for companies to improve customer relations, cutspending and streamline business processes but, at the sametime, expose <a href="http://www.enisa.europa.eu/garnish/hotel_bill.jpg" target="_blank" shape="rect"></a>organisations to security threats. For example, in December 2007, a UK government body reported missing a data cartridge containing the pension details of 6,500 persons. When a draft of this press release was printed in a hotel, the <a href="http://www.enisa.europa.eu/garnish/hotel_bill.JPG" shape="rect">reverse side</a> showed the hotel bill of a guest, with minibar and other private expenses listed, proving the point in case.<br clear="none"/>
<br clear="none"/>
Only 53% of companies use authentication for printing, such as smart cards, biometric identification, or PIN codes. ENISA therefore recommends business to adopt secure printing strategies to protect business assets and confidential customer data.</p>
<p>Printers produce key business documents, such as invoices, forms, tickets, statements, employee and customer data. But how is data treated in the printing process? Sensitive data is most vulnerable when in transit, where printing is a weak, ‘forgotten link’ in the security chain. Protecting confidential data in printing devices has both security and financial benefits, as top management recognise that office print expenditure can be reduced by 10-30% through the implementation of secure printing practices (Source: Gartner, 2008). And yet, awareness of secure printing strategies is lowamong more than 350 French, German and UK organisations, according ...</p></div>
    
    ]]></description> <pubDate>Mon, 09 Jun 2008 11:29:33 GMT</pubDate> <guid>http://www.evernote.com/pub/ssulistyo/InfoSecStuff#a116bdc6-5808-4cef-8812-0a4cc530baec</guid> 
  
    <enclosure url="http://www.evernote.com/shard/s1/thumb/a116bdc6-5808-4cef-8812-0a4cc530baec"
               length="0" type="image/jpeg"/>
  
  </item>
 </channel> </rss>