<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The PhoneBoy Blog &#187; security</title>
	<atom:link href="http://phoneboy.com/category/security/feed" rel="self" type="application/rss+xml" />
	<link>http://phoneboy.com</link>
	<description>Simplifying Network Security, Telecom, Gadgets, and More!</description>
	<lastBuildDate>Sun, 05 Feb 2012 00:13:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Securing Mobile Devices May Be Impossible</title>
		<link>http://phoneboy.com/4182/securing-mobile-devices-may-be-impossible</link>
		<comments>http://phoneboy.com/4182/securing-mobile-devices-may-be-impossible#comments</comments>
		<pubDate>Sun, 07 Aug 2011 06:20:21 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[mobile network operators]]></category>
		<category><![CDATA[mobile phones]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://phoneboy.com/?p=4182</guid>
		<description><![CDATA[From via Securing Mobile Devices May Be an Impossible Task: Attacks against smartphones such as BlackBerrys, iPhones and Android phones have become quite prevalent in recent years and many of them have focused on getting malicious apps on users phones. Thats a quick and easy way to get access to user data and sensitive information. But there [...]]]></description>
			<content:encoded><![CDATA[<p>From via <a href="http://threatpost.com/en_us/blogs/securing-mobile-devices-may-be-impossible-task-080411">Securing Mobile Devices May Be an Impossible Task</a>:</p>
<blockquote><p>Attacks against smartphones such as BlackBerrys, iPhones and Android phones have become quite prevalent in recent years and many of them have focused on getting malicious apps on users phones. Thats a quick and easy way to get access to user data and sensitive information. But there are a slew of other real and potential vectors that attackers have at their disposal no, as well. Going after the device firmware is one potential method, as is attacking the mobile infrastructure itself.&#8221;</p>
<p>If I can update your phone remotely, I own the phone at every level and I own you. Its game over,&#8221; said Don Bailey, a senior security consultant at iSEC Partners, said during the panel discussion.</p></blockquote>
<p><a href="http://phoneboy.com/4161/thinking-about-mobile-security">While I myself have been thinking about mobile security</a>, this is an angle I didn&#8217;t even consider. If hackers can pwn the mobile phone network itself, well, everyone&#8217;s mobile device is in danger. There&#8217;s not much you can do about it, either.</p>
<hr /><h2>Comments</h2><ul><li><a href="http://phoneboy.com/4182/securing-mobile-devices-may-be-impossible">6 August 2011</a>, Robmitch writes: How is this any different to the current paradigm with PC's and the Internet? I don't see that the issues are much different, just that the form factors and the areas of attack change slightly. There's an interesting commentary at http://www.theregister.co.uk/2011/08/04/secret_iphone_hacking_tool/ on iphone hacking vectors, if you combine firmware update capabilities and this then there's some very evil stuff going on. But it's no different to the sort of MITM or Phishing-style attacks that we've seen on the Internet for years. Surely the same defence model can/should be used?</li><li><a href="http://phoneboy.com/4182/securing-mobile-devices-may-be-impossible">6 August 2011</a>, <a href='http://www.phoneboy.com' rel='external nofollow' class='url'>PhoneBoy</a> writes: Surely it can, but the mobile operating systems are so locked down third parties can't provide security services like they can on a PC. You also can't easily "firewall" your mobile phone with a hardware device like you can with your PCs at home. :)</li><li><a href="http://phoneboy.com/4182/securing-mobile-devices-may-be-impossible">7 August 2011</a>, Robmitch writes: Fair point - that just means that the Mobile OS providers either have the obligation to secure their OS (Guess Apple kinda missed the boat on that one!) and the mobile network providers need to start incorporating that external "firewall" capability into their mobile networks. I think that corrupting endpoint devices is a relatively minor concern if the whole network is up for grabs - I guess the telcos have relied upon the technology to hijack or emulate a base station to be too expnsive and/or obscure up until now. Again, these are lessons that have been well learnt in the PC/Internet world, and another point where IP convergence into telephony/SCADA/infrastructure catches out historically poor security practice.</li><li><a href="http://phoneboy.com/4182/securing-mobile-devices-may-be-impossible">29 August 2011</a>, <a href='http://www.communication-agency.de/' rel='external nofollow' class='url'>Tomas</a> writes: I bought my first Smartphone some weeks ago and I was thinking about security issues, too. I was looking for some good methods to secure my phone, but my search wasn´t as successfull as I was hoping. So it is and will be hard to really securing your phone.</li></ul><hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/4161/thinking-about-mobile-security" rel="bookmark" title="Permanent Link: Thinking About Mobile Security">Thinking About Mobile Security</a></li><li><a href="http://phoneboy.com/1357/end-users-arent-the-customers" rel="bookmark" title="Permanent Link: End Users Aren&#8217;t The Customers">End Users Aren&#8217;t The Customers</a></li><li><a href="http://phoneboy.com/1532/mobile-phones-applications-and-subsidies" rel="bookmark" title="Permanent Link: Mobile Phones, Applications, and Subsidies">Mobile Phones, Applications, and Subsidies</a></li><li><a href="http://phoneboy.com/2173/why-we-need-to-go-to-ipv6-now" rel="bookmark" title="Permanent Link: Why We Need To Go To IPv6. Now.">Why We Need To Go To IPv6. Now.</a></li><li><a href="http://phoneboy.com/1202/who-controls-the-branding" rel="bookmark" title="Permanent Link: Who Controls The Branding?">Who Controls The Branding?</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/4182/securing-mobile-devices-may-be-impossible">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/4182/securing-mobile-devices-may-be-impossible/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Check Point: R75.20, SecurityPower, and New Appliances</title>
		<link>http://phoneboy.com/4175/check-point-r75-20-securitypower-and-new-appliances</link>
		<comments>http://phoneboy.com/4175/check-point-r75-20-securitypower-and-new-appliances#comments</comments>
		<pubDate>Tue, 02 Aug 2011 17:11:28 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[business]]></category>
		<category><![CDATA[check point]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://phoneboy.com/?p=4175</guid>
		<description><![CDATA[By now I&#8217;m sure you&#8217;ve seen, heard, or read Check Point&#8217;s official announcements made at NASDAQ this morning. This is by no means a regurgitation of the official press releases, but it is my own personal take on what was announced. If you want to see the announcement for yourself, check out the recording! (Just to [...]]]></description>
			<content:encoded><![CDATA[<p>By now I&#8217;m sure you&#8217;ve seen, heard, or read Check Point&#8217;s official announcements made at NASDAQ this morning. This is by no means a regurgitation of the official press releases, but it is my own personal take on what was announced. <a href="http://investor.shareholder.com/media/eventdetail.cfm?eventid=100577&amp;CompanyID=CHKP&amp;e=1&amp;mediaKey=65CD319864BBDF2E65FF709AFEEBDC8D">If you want to see the announcement for yourself, check out the recording</a>!</p>
<p>(Just to be clear, I work for Check Point and these are my own thoughts.)</p>
<p><strong>Check Point R75.20</strong></p>
<p>This release (<a href="http://www.checkpoint.com/press/2011/080211-check-point-enhances-3d-security.html">press release</a>, <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk64361">download</a>) brings a number of new features. One of the most anticipated ones is the ability to inspect outgoing SSL traffic. Not just for Application Control, where it is most needed given the proliferation of sites requiring SSL, but in all the various software blades we support. And its included as part of the relevant software blades license (i.e. it&#8217;s not a separate charge).</p>
<p>SSL inspection is done by essentially doing a &#8220;man in the middle&#8221; on the traffic. The gateway dynamically generates a certificate for the destination website, which is presented to the client when they connect. This allows the Security Gateway to see the traffic &#8220;in the clear&#8221; and make the relevant security decisions. The connection is encrypted as it leaves the gateway with SSL. Since SSL inspection is more intensive than inspecting HTTP traffic, and potentially creates potential regulatory issues by its use, you will have granular controls as to when this feature is invoked.</p>
<p>Another new feature in R75.20 is a completely revamped URL Filtering blade. While Check Point is still selling this as a separate product, it is actually integrated with Application Control. Applications and URL Filtering categories are given equal billing in the now combined Application Control and URL Filtering rulebase. You can do user-level URL filtering (with Identity Awareness) and can take advantage of our UserCheck technology to inform users of the policies. We can also handle HTTPS websites and custom categories. The categories themselves have also been substantially updated.</p>
<p>Unlike with previous versions of URL Filtering, where the entire URL filtering database was stored locally on the Security Gateway, the new engine makes use of the cloud. Commonly accessed URLs and their categories are stored in a local cache on the gateway. Over 99% of your web traffic should be met by the local cache on your gateway. When someone accesses a URL not in the local cache, the URL Filtering database in the cloud is consulted, with the result being stored in the local cache for future use.</p>
<p>The Data Loss Prevention (DLP) blade also gets a substantial update in R75.20. HTTP performance is substantially improved in this release and you also gain the ability to examine HTTPS traffic as well. A large number of additional &#8220;out of the box&#8221; datatypes are now included. We also integrate with an internal Microsoft Exchange server so DLP can be performed on internal email as well as email leaving the organization.</p>
<p><strong>SecurityPower</strong></p>
<p>A common complaint I&#8217;ve heard from Check Point customers over the years is that the performance numbers we quote for our appliances don&#8217;t reflect what performance you&#8217;ll get in the real world with real world traffic patterns. This is because performance numbers have been historically quoted for a single firewall rule (any any any accept) with the most optimal traffic pattern (1500 byte UDP packets). To be fair, this has been the standard industry practice for some time now. Every vendor of network equipment performs tests like this.</p>
<p>Unfortunately, this isn&#8217;t a good indicator of how an appliance will perform under real world conditions. With that in mind, Check Point has developed a new testing methodology for its appliances using a real rulebase (100 rules) with real-world traffic patterns (both based on industry standards and actual patterns seen at Check Point customer installations). This rulebase and traffic pattern exercises all of the various features and functionalities available in our Security Gateway. Based on those tests, Check Point has rated each appliance with a <a href="http://www.checkpoint.com/products/securitypower/">SecurityPower</a> Unit rating (SPU).</p>
<p>One could call the SPU an arbitrary metric. What it gives you is a relatively simple way to compare appliances and the relative security load they can handle. More importantly, an SPU can be generated for a given set of requirements (required blades, throughput, number of connections, and so on). You can then compare that against the available appliances to ensure you choose the right security appliance for the right security task.</p>
<p>Check Point has developed a tool that does exactly this. It will be available shortly. Personally, I think this is a big deal.</p>
<p><strong>New Appliances</strong></p>
<p>Two new appliances are being launched today for the data center: the 21400 (<a href="http://www.checkpoint.com/press/2011/080211-21400-raises-the-bar-in-data-center-security.html">press release</a>, <a href="http://www.checkpoint.com/products/21400-appliances/index.html">product page</a>) and the 61000 (<a href="http://www.checkpoint.com/press/2011/080211-61000-system-fastest-security-gateway.html">press release</a>, <a href="http://www.checkpoint.com/products/61000-appliances/index.html">product page</a>). These appliances are aimed squarely at the data center, where tens or even hundreds of <del>megabits</del> gigabits per second of throughput are needed!</p>
<p>The 21400 is a powerful 2U platform that features massive port density (up to 37 1000-base-T ports, 36 1000-base-F SFP ports, or 12 10GBase-F SFP+ ports), 50 GB of firewall throughput, 21GB of IPS throughput, hot-swappable redundant power supplies and disk drives, and an optional Lights-out Management card. Everything you&#8217;d expect from a carrier-grade chassis. The appliance runs both R71 and R75 with SecurePlatform.</p>
<p>The 61000 series, on the other hand, is a monster appliance! It&#8217;s a 14U (DC) or 15U (AC) bladed chassis that, when fully loaded, will support 200GB of firewall throughput today and, with future hardware and software enhancements, will support over 1TB of throughput in the future! Aside from all of the various connectivity and redundancy options, the appliance acts as a single platform that, when new hardware blades are added, automatically configures itself to distribute the load between the blades! The platform currently runs a 64bit version of SecurePlatform based on R75.</p>
<p>Both appliances, which are referred to as Data Center Appliances, are available now on the <a href="https://pricelist.checkpoint.com/pricelist/US/PLUSswblades/GeneralPL.jsp#2012Appliances">Check Point pricelist</a>.</p>
<hr /><h2>Comments</h2><ul><li><a href="http://phoneboy.com/4175/check-point-r75-20-securitypower-and-new-appliances">2 August 2011</a>, <a href='http://www.cpshared.com/forums/showthread.php?p=4097#post4097' rel='external nofollow' class='url'>Most Important Announcement of the Year [2011] - Page 6 - CPShared Forums</a> writes: <!--%kramer-ref-pre%-->[...] y&#039;all are interested in my personal take on our announcement:   http://phoneboy.com/4175/check-point...new-appliances     __________________ http://phoneboy.com Email: my CPShared username @ gmail.com Unless otherwise [...]<!--%kramer-ref-post%--></li><li><a href="http://phoneboy.com/4175/check-point-r75-20-securitypower-and-new-appliances">2 August 2011</a>, RStewart writes: Towards the end, I think you mean tens to hundreds of *gigabits*. Hundreds of megabits of throughput is easy. ;-)</li><li><a href="http://phoneboy.com/4175/check-point-r75-20-securitypower-and-new-appliances">2 August 2011</a>, EF writes: Did you notice that they changed --AGAIN-- the price for software blades? The URL Filtering blade is now $1,500/$3,000/$4,500 depending on the appliance or container size, instead of a plain $1,500 per gateway.</li></ul><hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/3917/check-point-r75-now-available" rel="bookmark" title="Permanent Link: Check Point R75 Now Available">Check Point R75 Now Available</a></li><li><a href="http://phoneboy.com/2961/job-change-dead-ahead" rel="bookmark" title="Permanent Link: Job Change Dead Ahead">Job Change Dead Ahead</a></li><li><a href="http://phoneboy.com/3944/gil-shwed-says-check-point-isnt-for-sale" rel="bookmark" title="Permanent Link: Gil Shwed says Check Point isn&#8217;t for sale">Gil Shwed says Check Point isn&#8217;t for sale</a></li><li><a href="http://phoneboy.com/4050/announcing-cpshared-the-open-technical-forum-for-all-things-check-point" rel="bookmark" title="Permanent Link: Announcing CPshared: The Open Technical Forum for all things Check Point">Announcing CPshared: The Open Technical Forum for all things Check Point</a></li><li><a href="http://phoneboy.com/383/the_long-term_plan_for_phoneboy_com" rel="bookmark" title="Permanent Link: The long-term plan for phoneboy.com">The long-term plan for phoneboy.com</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/4175/check-point-r75-20-securitypower-and-new-appliances">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/4175/check-point-r75-20-securitypower-and-new-appliances/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Thinking About Mobile Security</title>
		<link>http://phoneboy.com/4161/thinking-about-mobile-security</link>
		<comments>http://phoneboy.com/4161/thinking-about-mobile-security#comments</comments>
		<pubDate>Mon, 25 Jul 2011 04:00:17 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[mobile phones]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://phoneboy.com/?p=4161</guid>
		<description><![CDATA[Mobile devices are, like any powerful tool, a double edged sword. They enable unprecedented ability to access and create information from anywhere! They are also a huge problem for information security. Unlike a traditional PC, where there are a number of solutions to address various information security needs, mobile devices (those running iOS, Android, Symbian, [...]]]></description>
			<content:encoded><![CDATA[<p>Mobile devices are, like any powerful tool, a double edged sword. They enable unprecedented ability to access and create information from anywhere! They are also a huge problem for information security.</p>
<p>Unlike a traditional PC, where there are a number of solutions to address various information security needs, mobile devices (those running iOS, Android, Symbian, Blackberry and others) provide little if any mechanisms for third parties to provide security solutions. Beyond ActiveSync integration, which itself is potentially untrustworthy (remember how iOS used to lie to Exchange servers that their mail store was encrypted?), other options for securing the device or data on the device are limited.</p>
<p>That said, mobile operating systems have had the benefit of experience of other operating systems. They are designed to be more resistant to intrusion by requiring signed code, employing sandboxing, limiting the available APIs, and more. It doesn&#8217;t eliminate the risk of security vulnerabilities, but it does minimize the risk known ones will occur.</p>
<p>Unfortunately, the &#8220;baked in&#8221; security only addresses a small segment of potential security issues. It does nothing to address future security issues that might crop up. Due to the limited APIs, it is not possible for third parties to address these issues without cooperation from the OS vendor (e.g. Apple, Google, Nokia). Unfortunately, security threats evolve far faster than an OS vendor&#8217;s ability to mitigate these threats on their own. Just look at how long it took Microsoft to enable the firewall in Microsoft Windows by default, implement driver signing, or any number of other security mechanisms that are just the default on mobile operating systems.</p>
<p>Even so, the most important feature of a mobile device&#8211;the ability to access and share information from anywhere&#8211;is also a threat to an enterprise. The potential for data leakage is substantial! All I have to do is take a picture of a whiteboard in an office with confidential data on it using an Android phone with Google+ automatically uploading my photos &#8220;in the cloud&#8221; to have a potential data leak! Not to mention using your personal device to access mobile email and working with attachments. </p>
<p>Even if adequate tools existed to address all the issues on mobile devices, one should not blindly rely on these tools. It comes down to people understanding the security implications of their actions and adjusting their actions accordingly.</p>
<hr /><h2>Comments</h2><ul><li><a href="http://phoneboy.com/4161/thinking-about-mobile-security">3 August 2011</a>, <a href='http://www.think7.co.uk' rel='external nofollow' class='url'>jason @ Voip</a> writes: It took years to get users to even consider security on their PCs. How long do you think it'll take them to consider it on their mobile phones? Till they are hacked? Oops! They have been and they've still not learned!</li><li><a href="http://phoneboy.com/4161/thinking-about-mobile-security">6 August 2011</a>, <a href='http://phoneboy.com/4182/securing-mobile-devices-may-be-impossible' rel='external nofollow' class='url'>Securing Mobile Devices May Be Impossible &laquo; The PhoneBoy Blog</a> writes: [...] While I myself have been thinking about mobile security, this is an angle I didn&#8217;t even consider. If hackers can pwn the mobile phone network itself, well, everyone&#8217;s mobile device is in danger. There&#8217;s not much you can do about it, either. [...]</li><li><a href="http://phoneboy.com/4161/thinking-about-mobile-security">19 August 2011</a>, <a href='http://www.hotelmontgomerysj.com/' rel='external nofollow' class='url'>Peter</a> writes: Thanks a lot for this nice article. I think there are too many security breaches in mobile devices to use it with peace of consience. Just for example the untrostworthyness like you told the fact that iOS used to lie to exchange servers that their mail store was encrypted. I don´t know if i want to use a smartphone as long as i can´t get a clear overview over the security possibilities that are trustworthy.</li></ul><hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/4182/securing-mobile-devices-may-be-impossible" rel="bookmark" title="Permanent Link: Securing Mobile Devices May Be Impossible">Securing Mobile Devices May Be Impossible</a></li><li><a href="http://phoneboy.com/3948/mobile-security-aint-the-same-on-all-platforms" rel="bookmark" title="Permanent Link: Mobile Security Isn&#8217;t The Same on All Platforms">Mobile Security Isn&#8217;t The Same on All Platforms</a></li><li><a href="http://phoneboy.com/942/why_purple?_and_why_minutes?" rel="bookmark" title="Permanent Link: Why Purple? And Why Minutes?">Why Purple? And Why Minutes?</a></li><li><a href="http://phoneboy.com/2088/phoneboys-week-that-was-3-february-2008" rel="bookmark" title="Permanent Link: PhoneBoy&#8217;s Week That Was 3 February 2008">PhoneBoy&#8217;s Week That Was 3 February 2008</a></li><li><a href="http://phoneboy.com/2961/job-change-dead-ahead" rel="bookmark" title="Permanent Link: Job Change Dead Ahead">Job Change Dead Ahead</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/4161/thinking-about-mobile-security">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/4161/thinking-about-mobile-security/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>ZoneAlarm’s Newest Security Solution: SocialGuard</title>
		<link>http://phoneboy.com/4096/zonealarm%e2%80%99s-newest-security-solution-socialguard</link>
		<comments>http://phoneboy.com/4096/zonealarm%e2%80%99s-newest-security-solution-socialguard#comments</comments>
		<pubDate>Tue, 26 Apr 2011 19:57:37 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[check point]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://phoneboy.com/?p=4096</guid>
		<description><![CDATA[From ZoneAlarm’s Newest Security Solution: SocialGuard: SocialGuard, ZoneAlarm’s newest security solution, promises a groundbreaking new method of monitoring and preventing safety breaches on Facebook the most popular social networking site by a mile, with over 500 million users without “friending” your child and intruding on his/her social space. SocialGuard sends real-time alerts to parents via email–or [...]]]></description>
			<content:encoded><![CDATA[<p>From <a href="http://blog.zonealarm.com/2011/04/zonealarms-newest-security-solution-socialguard.html">ZoneAlarm’s Newest Security Solution: SocialGuard</a>:</p>
<blockquote><p><a href="http://www.zonealarm.com/security/en-us/zonealarm-socialguard-facebook-parental-control.htm">SocialGuard</a>, ZoneAlarm’s newest security solution, promises a groundbreaking new method of monitoring and preventing safety breaches on Facebook the most popular social networking site by a mile, with over 500 million users without “friending” your child and intruding on his/her social space. SocialGuard sends real-time alerts to parents via email–or the SocialGuard interface–whenever suspicious activity is detected on your child’s profile; parents can customize security settings and keywords to trigger such messages if the child is exposed to illicit or inappropriate content. SocialGuard monitors children’s Facebook accounts for threats including cyberbullying, age fraud ensures children are not befriended by adults outside of their network; friend requests, hacked accounts, and link safety flags dangerous/offensive links contained in messages.</p>
<p>The product, available now, can be purchased <a href="http://www.zonealarm.com/security/en-us/zonealarm-socialguard-facebook-parental-control.htm">here</a>.</p></blockquote>
<p>Check Point, my employer, is behind this. I&#8217;ve used the betas of this product and they do precisely what they say without being a huge burden on you or your computer. The price: $1.99 a month or $19.99 a year, makes this a no-brainer if you have kids using Facebook!</p>
<p><a href="http://www.youtube.com/watch?v=qLndSCI49FM">See what Check Point&#8217;s Head of Consumer Business has to say about SocialGuard</a>.</p>
<hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/1279/sightspeed-60-coming-in-early-february" rel="bookmark" title="Permanent Link: SightSpeed 6.0 Coming in Early February">SightSpeed 6.0 Coming in Early February</a></li><li><a href="http://phoneboy.com/3020/phoneboy-goes-corporate-twitter-style" rel="bookmark" title="Permanent Link: PhoneBoy Goes Corporate, Twitter Style">PhoneBoy Goes Corporate, Twitter Style</a></li><li><a href="http://phoneboy.com/2751/a-new-hope" rel="bookmark" title="Permanent Link: A New Hope">A New Hope</a></li><li><a href="http://phoneboy.com/2838/security-folks-lets-not-forget-the-dialup-users" rel="bookmark" title="Permanent Link: Security Folks: Let&#8217;s Not Forget The Dialup Users">Security Folks: Let&#8217;s Not Forget The Dialup Users</a></li><li><a href="http://phoneboy.com/1307/gizmocall-cant-penetrate-firewalls" rel="bookmark" title="Permanent Link: GizmoCall? Can&#8217;t Penetrate Firewalls.">GizmoCall? Can&#8217;t Penetrate Firewalls.</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/4096/zonealarm%e2%80%99s-newest-security-solution-socialguard">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/4096/zonealarm%e2%80%99s-newest-security-solution-socialguard/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gil Shwed: &#8220;The [security] industry needs to change a little bit&#8221;</title>
		<link>http://phoneboy.com/4086/gil-shwed-the-security-industry-needs-to-change-a-little-bit</link>
		<comments>http://phoneboy.com/4086/gil-shwed-the-security-industry-needs-to-change-a-little-bit#comments</comments>
		<pubDate>Wed, 13 Apr 2011 19:24:41 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[check point]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://phoneboy.com/?p=4086</guid>
		<description><![CDATA[From Reality Check &#8211; Features &#8211; Malware &#8211; Computer Business Review: &#160; &#8220;The industry needs to change a little bit,&#8221; [Check Point Software Technologies CEO Gil Shwed] says. &#8220;Our software blade architecture is the right direction but it&#8217;s not enough. I think the real change is actually understanding that security is not a bunch of technologies [...]]]></description>
			<content:encoded><![CDATA[<p>From <a href="http://malware.cbronline.com/features/reality-check-check-point-firewall-gil-schwed">Reality Check &#8211; Features &#8211; Malware &#8211; Computer Business Review</a>:</p>
<p>&nbsp;</p>
<blockquote><p>&#8220;The industry needs to change a little bit,&#8221; [Check Point Software Technologies CEO Gil Shwed] says. &#8220;Our software blade architecture is the right direction but it&#8217;s not enough. I think the real change is actually understanding that security is not a bunch of technologies that people need to deploy but understanding that it needs to be treated like a business process. It starts with the well-defined policy of what a company wants to achieve and what is allowed or not allowed, continues with educating &#8211; or not educating but involving the users &#8211; and the enforcement side is only the last part of it.</p>
<p>&#8220;Most of our customers have a lot of check lists but not one clear policy. Everybody is trying to keep the users aside from that, but if users are not aware of their expected behaviour they become the weakest link in security. Then it goes to enforcement, which needs to apply these principles. We&#8217;ve just launched 3D Security that has three elements &#8211; policy, people and enforcement &#8211; and I think that would be a major change in people&#8217;s mindset when they think about security.</p></blockquote>
<p>While Check Point certainly has some great security technology&#8211;I should know, I work there&#8211;if it&#8217;s not applied according to a process and policy with defined business goals, the result will be less than satisfying. I&#8217;ve seen it again and again in my work over the years.</p>
<hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/3944/gil-shwed-says-check-point-isnt-for-sale" rel="bookmark" title="Permanent Link: Gil Shwed says Check Point isn&#8217;t for sale">Gil Shwed says Check Point isn&#8217;t for sale</a></li><li><a href="http://phoneboy.com/2830/check-point-softwares-earnings-call-and-nokias-security-appliance-business" rel="bookmark" title="Permanent Link: Check Point Software&#8217;s Earnings Call and Nokia&#8217;s Security Appliance Business">Check Point Software&#8217;s Earnings Call and Nokia&#8217;s Security Appliance Business</a></li><li><a href="http://phoneboy.com/3168/gil-shwed-opens-nasdaq" rel="bookmark" title="Permanent Link: Gil Shwed Opens NASDAQ">Gil Shwed Opens NASDAQ</a></li><li><a href="http://phoneboy.com/3017/check-point-software-posting-record-financial-results-for-q1-2009" rel="bookmark" title="Permanent Link: Check Point Software Posting Record Financial Results For Q1 2009">Check Point Software Posting Record Financial Results For Q1 2009</a></li><li><a href="http://phoneboy.com/2159/the-academy-video-how-tos-on-network-security-products" rel="bookmark" title="Permanent Link: The Academy: Video How-Tos On Network Security Products">The Academy: Video How-Tos On Network Security Products</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/4086/gil-shwed-the-security-industry-needs-to-change-a-little-bit">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/4086/gil-shwed-the-security-industry-needs-to-change-a-little-bit/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CPshared and CPUG: A Couple of Observations</title>
		<link>http://phoneboy.com/4071/cpshared-and-cpug-a-couple-of-observations</link>
		<comments>http://phoneboy.com/4071/cpshared-and-cpug-a-couple-of-observations#comments</comments>
		<pubDate>Tue, 15 Mar 2011 06:40:13 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[check point]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://phoneboy.com/?p=4071</guid>
		<description><![CDATA[On the two Check Point user community sites CPUG and CPshared, I made a couple of interesting observations today: CPshared already had more active threads today than CPUG. This includes all the public boards, which I verified by loading up both sites in Google Chrome&#8217;s &#8220;Incognito Mode&#8221; to ensure I wasn&#8217;t logged in. The number [...]]]></description>
			<content:encoded><![CDATA[<p>On the two Check Point user community sites <a href="http://cpug.org/forums">CPUG</a> and <a href="http://www.cpshared.com/forums">CPshared</a>, I made a couple of interesting observations today:</p>
<ul>
<li>CPshared already had more active threads today than CPUG. This includes all the public boards, which I verified by loading up both sites in Google Chrome&#8217;s &#8220;Incognito Mode&#8221; to ensure I wasn&#8217;t logged in.</li>
<li>The number of Check Point employees already participating on CPshared is far more than I&#8217;ve ever noticed on CPUG in the past two years.</li>
</ul>
<p>Keep in mind that the CPUG forums have been around since August 2005. CPshared was only &#8220;officially&#8221; announced last week&#8211;it had been privately tested for about 4 weeks before that.</p>
<p>Again, these are just observations. They may be completely meaningless. You can come to your own conclusions here.</p>
<hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/4050/announcing-cpshared-the-open-technical-forum-for-all-things-check-point" rel="bookmark" title="Permanent Link: Announcing CPshared: The Open Technical Forum for all things Check Point">Announcing CPshared: The Open Technical Forum for all things Check Point</a></li><li><a href="http://phoneboy.com/fw1" rel="bookmark" title="Permanent Link: Where Did the FireWall-1 FAQ Go?">Where Did the FireWall-1 FAQ Go?</a></li><li><a href="http://phoneboy.com/189/reconnecting_with_phoneboy_of_old" rel="bookmark" title="Permanent Link: Reconnecting with PhoneBoy of old">Reconnecting with PhoneBoy of old</a></li><li><a href="http://phoneboy.com/227/pictures_from_my_check_point_user_group_apperance" rel="bookmark" title="Permanent Link: Pictures from my Check Point User Group apperance">Pictures from my Check Point User Group apperance</a></li><li><a href="http://phoneboy.com/405/usb_powered_fish_tank" rel="bookmark" title="Permanent Link: USB Powered Fish Tank">USB Powered Fish Tank</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/4071/cpshared-and-cpug-a-couple-of-observations">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/4071/cpshared-and-cpug-a-couple-of-observations/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Announcing CPshared: The Open Technical Forum for all things Check Point</title>
		<link>http://phoneboy.com/4050/announcing-cpshared-the-open-technical-forum-for-all-things-check-point</link>
		<comments>http://phoneboy.com/4050/announcing-cpshared-the-open-technical-forum-for-all-things-check-point#comments</comments>
		<pubDate>Fri, 11 Mar 2011 07:33:39 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[check point]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://phoneboy.com/?p=4050</guid>
		<description><![CDATA[I&#8217;ve been a participating in the Check Point user community in various places for a long time now. Heck, I ran a Check Point community of my own for a while. It&#8217;s not often the community gets a new place to congregate, so it&#8217;s worthy of an announcement. Presenting CPshared:  The Open Technical Forum for [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been a participating in the Check Point user community in various places for a long time now. Heck, <a href="http://fw1-gurus.phoneboy.com">I ran a Check Point community of my own for a while</a>. It&#8217;s not often the community gets a new place to congregate, so it&#8217;s worthy of an announcement.</p>
<p><a href="http://www.cpshared.com">Presenting CPshared:  The Open Technical Forum for All Things Check Point</a>. In the NG days, this was a base &#8220;package&#8221; in the Check Point suite that handled communication between management and modules. It was also called the SVN Foundation. This is where the name comes from, and I think it&#8217;s an appropriate name.</p>
<p><a href="http://www.cpshared.com/">CPshared</a> was started by an ex-Check Point employee and a long-time member of the Check Point community. It is designed to be an alternate approach to information dissemination to more established forums like <a href="http://cpug.org/">CPUG</a>&#8211;a forum I kickstarted by donating my own content to in 2005. CPshared includes a blog (with contributions by others), a web-based forum, a Twitter account <a href="http://twitter.com/cpshared">@cpshared</a>, and a web-based chat system.</p>
<p>CPshared has been under private beta for the last few weeks with a number of other long-time members of the Check Point community, including a few Check Point employees. It was formally announced today. If you use Check Point products, give it a look and join the small, but growing community!</p>
<hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/4071/cpshared-and-cpug-a-couple-of-observations" rel="bookmark" title="Permanent Link: CPshared and CPUG: A Couple of Observations">CPshared and CPUG: A Couple of Observations</a></li><li><a href="http://phoneboy.com/fw1" rel="bookmark" title="Permanent Link: Where Did the FireWall-1 FAQ Go?">Where Did the FireWall-1 FAQ Go?</a></li><li><a href="http://phoneboy.com/167/check_point_is_watching_me" rel="bookmark" title="Permanent Link: Check Point is watching me">Check Point is watching me</a></li><li><a href="http://phoneboy.com/477/am_i_doing_a_book_on_ngx?" rel="bookmark" title="Permanent Link: Am I doing a book on NGX?">Am I doing a book on NGX?</a></li><li><a href="http://phoneboy.com/484/skype_is_not_like_open_source" rel="bookmark" title="Permanent Link: Skype is NOT like Open Source">Skype is NOT like Open Source</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/4050/announcing-cpshared-the-open-technical-forum-for-all-things-check-point">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/4050/announcing-cpshared-the-open-technical-forum-for-all-things-check-point/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Cisco Valet: Easy Setup, but is it Secure?</title>
		<link>http://phoneboy.com/4020/the-cisco-valet-easy-setup-but-is-it-secure</link>
		<comments>http://phoneboy.com/4020/the-cisco-valet-easy-setup-but-is-it-secure#comments</comments>
		<pubDate>Sat, 29 Jan 2011 19:46:08 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[computers]]></category>
		<category><![CDATA[gadgets]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://phoneboy.com/?p=4020</guid>
		<description><![CDATA[A PR firm representing Cisco asked me if I wanted to review the Cisco Valet, which is a line of &#8220;surprisingly simply home wireless&#8221; devices that, I have to say, does what it says on the tin. It is by far the easiest setup process I&#8217;ve seen. The first thing I noticed was the packaging. [...]]]></description>
			<content:encoded><![CDATA[<p>A PR firm representing Cisco asked me if I wanted to review the <a href="http://home.cisco.com/en-us/wireless/valet">Cisco Valet</a>, which is a line of &#8220;surprisingly simply home wireless&#8221; devices that, I have to say, does what it says on the tin. It is by far the easiest setup process I&#8217;ve seen.</p>
<p>The first thing I noticed was the packaging. A complete lack of technical jargon or marketing about how this router compares to the others they sell. There most technical things on the box are in small print and are just basically a list of system requirements and a warning that, due to a number of factors, your wireless speeds and range may vary.</p>
<p>When I did the initial setup, I used my Mac&#8211;usually a stumbling block for these so-called &#8220;easy setup&#8221; programs. The Easy Set Up key is little more than a Flash drive that contains some documentation and the Cisco Connect application. Launching the Cisco Connect gives you a screen that tells you to do do three things:</p>
<ul>
<li>Plug the router into your Internet connection</li>
<li>Plug the router into your power</li>
<li>Click next</li>
</ul>
<p>In less than the five minutes it tells you it could take, I had a screen that told me my router was set up and I was connected to it. Sweet! You could, of course, do some additional configuration of the router. A very simple interface is presented for doing this (click image for larger view):</p>
<p><img class="aligncenter size-medium wp-image-4022" title="Screen shot 2011-01-28 at 2.26.05 PM" src="http://phoneboy.com/wp-content/uploads/2011/01/Screen-shot-2011-01-28-at-2.26.05-PM-300x207.png" alt="" width="300" height="207" /></p>
<p>The add device option gives you the settings you need to configure a device. Obviously, it&#8217;s going to vary by device manufacturer. Once it has detected the device has connected, you can then &#8220;name&#8221; the device for later. Handy!</p>
<p>I didn&#8217;t mess with the parental controls&#8211;I almost never find them granular enough for my tastes. However, it appears they do some category-based URL filtering and allow you to blacklist sites. The problem is the restrictions are per-host, meaning you have to select the individual hosts that you wish to restrict. You also can&#8217;t whitelist sites or create a default URL filtering policy that applies to all connected hosts. That said, it&#8217;s more functionality than I&#8217;ve seen in a typical consumer router.</p>
<p>The guest access feature is quite handy as well. Cisco Valet creates a second (open) SSID that your guests can use to access the Internet. It is segmented off from your regular wireless network and presents a captive portal to your guests, whom must enter a password before they are allowed access to the Internet:</p>
<p>Of course, you can disable this feature as well.</p>
<p>When the router is first configured, the SSID is set to a random adjective-noun word combination and the password is set to a 10 character random string. In the Valet Settings, you can change these things to something. You can also save this to the Easy Setup Key (or create a new one using any standard USB thumb drive) that will allow you easily configure other Mac or Windows computers in your house with the correct wireless settings.</p>
<p><img class="aligncenter size-medium wp-image-4023" title="Screen shot 2011-01-28 at 2.26.25 PM" src="http://phoneboy.com/wp-content/uploads/2011/01/Screen-shot-2011-01-28-at-2.26.25-PM-300x209.png" alt="" width="300" height="209" /></p>
<p>And, of course, there&#8217;s the Advanced Settings, which fires up a web browser with a typical Linksys-style web interface for configuring the router (though it is entirely Cisco-branded now). This is where the geek settings are, of course, and are, &#8220;advanced.&#8221; I&#8217;m sure given the relatively ease through which computers can be added and the basic settings can be configured, there will rarely be a reason for most people to ever visit the advanced settings.</p>
<p><strong>But Is It Secure?</strong></p>
<p>Most reviews stop here. They are quite happy that someone has finally come up with a wireless router that almost anyone with even rudimentary computer knowledge could configure and use. That is a feat worthy of praise, no doubt.</p>
<p>I am not most people. I wonder, in the back of my mind, does Cisco make this device easy to use, yet actually make it secure? The answer is not surprising&#8211;to me at least.</p>
<p>First, it&#8217;s probably worth pointing out that I work for a competitor to Cisco: <a href="http://www.checkpoint.com">Check Point Software Technologies</a>. We don&#8217;t compete in the consumer market, really, but we certainly in the enterprise network security market. That doesn&#8217;t affect my opinions here, but I figure I should disclose that since some might consider it a conflict of interest.</p>
<p>Prior to proceeding with the setup wizard, I saw what the router was broadcasting by default&#8211;a WPA-protected access point named CiscoXXXXX (where XXXXX corresponded to the last 5 digits of the device serial number). My guess is the router is preconfigured with some default WPA password that the Cisco Connect software then changes to something else, which it then tells you after the setup is complete.</p>
<p>Cisco gets props on a number of things security related:</p>
<ul>
<li>Choosing a random network name (SSID)&#8211;most manufacturers use a known default</li>
<li>Configuring WPA as a default</li>
<li>Choosing a random password that contains numbers, upper and lower case letters, and special symbols</li>
</ul>
<p>All three of these things are good. By choosing a random SSID and a random password, it makes it harder for someone to brute-force (i.e. guess every possible password) access to the wireless access point.</p>
<p>While these are far better than what I&#8217;ve seen from others, it&#8217;s, unfortunately, not enough. To be relatively safe from a brute-force attempt, the passphrase needs to be at least <em><strong>20</strong></em> characters&#8211;random ones at that. Also, it defaults to WPA/WPA2 mixed mode, which allows you to use the TKIP, which may be needed for some legacy hardware, is not the most secure. You can change to WPA2, which only supports AES. It would be nice if you could change the rekey interval, but I don&#8217;t see a way to do that from the advanced settings.</p>
<p>There are a couple of other dangerous settings enabled by default:</p>
<ul>
<li>Universal Plug and Play is enabled by default (which, when paired with malware, could easily make your computers more vulnerable to attacks)</li>
<li>WMM Support (in the QoS section) which, when enabled, makes your network a little more susceptible to hacking when WPA (not WPA2) is enabled.</li>
</ul>
<p><strong>The Nintendo DS Factor</strong></p>
<p>One rather common WiFi-enabled device in any household with children is the Nintendo DS. This device does not support WPA at all. Even the newer DSi, which does support WPA, doesn&#8217;t support it for DS games. This means, if you want your kids to be able to use the WiFi features of their DS games, they won&#8217;t be able to use them unless you use WEP for your wireless security, which is not recommended.</p>
<p>This is, in my opinion, one big disappointment with the Cisco Valet. There is no way to allow a Nintendo DS to use the Guest wireless without using WEP. They could very easily allow the whitelisting of certain MAC addresses to be allowed to access the Guest wireless (which is open, unencrypted, and will work with the DS) without requiring web-based captive portal authentication.</p>
<p><strong>Other Minor Gripes</strong></p>
<p>The Cisco Connect software allows you to configure items that cannot be configured with the Advanced Settings interface, namely the Guest wireless access. I would like to be able to change the default IP range used for the Guest wireless and, possibly, whitelist certain machines as I described above.</p>
<p>By default, the router administration password the same as the WPA password. This does make it easier for end users, but I think you should be able to set them independently in the Cisco Connect software.</p>
<p>I also do not see a way through the Cisco Connect software to upgrade the firmware for my router. This is a necessary, sometimes daunting task, especially given the number of hardware variations that can exist even with the same model. There&#8217;s no reason Cisco couldn&#8217;t have made this process as simple as they&#8217;ve made everything else&#8211;push a button and it takes care of the rest.</p>
<p>And, of, course, my security gripes above. While they went a lot farther than I&#8217;ve seen other manufacturers go, they could have gone just a little farther in choosing more secure defaults, possibly with an optional &#8220;security settings&#8221; page so you don&#8217;t have to hunt in the Advanced Settings interface to make the wireless connectivity more secure.</p>
<p>All in all, though, I am very impressed with the product. I could easily see myself recommending this product to my non-technical friends and family as a dirt simple way to share their Internet connection and create their own personal wireless hotspot.</p>
<p>The only people I cannot recommend this product to are Linux users who lack a Windows or Mac machine on which to run the Cisco Connect software. Since the initial setup of this router cannot happen without the Cisco Connect software, which does not run on Linux, your &#8220;out of the box&#8221; experience will be less than fulfilling. You only need the software the first time, of course, but you might be better off with a <a href="http://homesupport.cisco.com/en-us/wireless/linksys">Linksys-branded router</a>.</p>
<p>So yes, Cisco did it. They made WiFi easy for normal people to set up. Using the Easy Setup Key, I set up four different Windows computers with my Cisco Valet settings in a matter of minutes. It was drop-dead simple. I wish they spent a little more time on the security side of things, but this is a tough one to do without making things more inconvenient for users. Given what Cisco was aiming for here, I think they nailed it.</p>
<hr /><h2>Comments</h2><ul><li><a href="http://phoneboy.com/4020/the-cisco-valet-easy-setup-but-is-it-secure">13 February 2011</a>, <a href='http://www.technifi.com/news/The-Cisco-Valet-Easy-Setup-but-is-it-Secure-6375798.html' rel='external nofollow' class='url'>The Cisco Valet: Easy Setup, but is it Secure? - Wireless Network News</a> writes: <!--%kramer-ref-pre%-->[...] Cisco Valet: Easy Setup, but is it Secure?  The PhoneBoy Blog / 29th Jan 2011           Nintendo [...]<!--%kramer-ref-post%--></li></ul><hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/1253/wait-doesnt-cisco-have-the-iphone-trademark" rel="bookmark" title="Permanent Link: Wait, Doesn&#8217;t Cisco Have the iPhone Trademark?">Wait, Doesn&#8217;t Cisco Have the iPhone Trademark?</a></li><li><a href="http://phoneboy.com/1261/ciscos-trademark-case-against-apple-silly" rel="bookmark" title="Permanent Link: Cisco&#8217;s Trademark Case Against Apple &#8220;Silly&#8221;">Cisco&#8217;s Trademark Case Against Apple &#8220;Silly&#8221;</a></li><li><a href="http://phoneboy.com/403/sipura_gets_acquired_by_linksys__er_cisco" rel="bookmark" title="Permanent Link: Sipura gets acquired by Linksys, er Cisco">Sipura gets acquired by Linksys, er Cisco</a></li><li><a href="http://phoneboy.com/1258/cisco-sues-apple-over-iphone-trademark" rel="bookmark" title="Permanent Link: Cisco Sues Apple over iPhone Trademark!">Cisco Sues Apple over iPhone Trademark!</a></li><li><a href="http://phoneboy.com/102/is_security_holding_voip_back?" rel="bookmark" title="Permanent Link: Is Security Holding VoIP Back?">Is Security Holding VoIP Back?</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/4020/the-cisco-valet-easy-setup-but-is-it-secure">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/4020/the-cisco-valet-easy-setup-but-is-it-secure/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Speaking IPv6</title>
		<link>http://phoneboy.com/4015/speaking-ipv6</link>
		<comments>http://phoneboy.com/4015/speaking-ipv6#comments</comments>
		<pubDate>Sat, 29 Jan 2011 06:03:52 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[computers]]></category>
		<category><![CDATA[connectivity]]></category>
		<category><![CDATA[ipv6]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://phoneboy.com/?p=4015</guid>
		<description><![CDATA[IPv6 is the next generation of IP&#8211;the protocol by which most of our computers, phones, and other related devices talk to each other and to the Internet. Today, everything generally talks using IPv4, which has a 32-bit address space, or roughly 4 billion possible addresses. Both because of the sheer number of devices and the [...]]]></description>
			<content:encoded><![CDATA[<p>IPv6 is the next generation of IP&#8211;the protocol by which most of our computers, phones, and other related devices talk to each other and to the Internet. Today, everything generally talks using IPv4, which has a 32-bit address space, or roughly 4 billion possible addresses. Both because of the sheer number of devices and the number of &#8220;reserved&#8221; addresses within the IPv4 space, the number of globally available IP addresses is running out.</p>
<p>To put it in perspective, as I write this, there is still a few /8 addresses unallocated by the <a href="http://www.iana.org">IANA</a>, which are distributed to regional registries, which are then responsible for distributing the IPs to ISPs, whom in turn distribute them to you. A /8, in IPv4, is 16,777,216 IP addresses. That seems like a lot of addresses, until you realize that, depending on how those IPs are allocated, the number of usable IPs ends up being a bit less.</p>
<p>Even so, once IANA runs out of /8s, the individual registries and ISPs still likely have caches of IPv4 addresses. The problem of address space exhaustion probably won&#8217;t show any acute symptoms immediately, but the lack of IPv4 addresses (and the lack of wide deployment of IPv6) will start causing problems soon, creating pockets of servers that can only be accessed by one protocol or another.</p>
<p>We&#8217;ve actually been working around the problem of address exhaustion in the IPv4 space for some time now using network address translation. That router you get from your local consumer electronics store has been masquerading all of your computers behind a single, public IP address, providing you both a level of protection and connectivity.</p>
<p>Enterprises do much the same thing, except their boxes are significantly larger and they also might provide services accessible on the Internet, which means: they need more than one public IP. Also, some enterprises have so many connected systems that they have, quite literally, run out of available private IP addresses (some IPs in the IPv4 space are set aside explicitly for private, non-Internet connected use).</p>
<p>In any case, the pressure is mounting to switch to IPv6. Given that some of my customers are asking about IPv6, I figured I&#8217;d get myself educated. I happen to have access to one of the people who helped define the IPv6 standards in the IETF (he works at Check Point), but there&#8217;s really no better way to learn about it than to just get it set up.</p>
<p>Of course, part of the problem right now is that my ISPs at home (Comcast, CenturyLink) are still serving me IPv4 addresses. Fortunately, there are ways of tunneling over IPv4 to the IPv6 networks. One such service is <a href="http://tunnelbroker.net/">TunnelBroker</a>, run by the folks at <a href="http://www.he.net">Hurricane Electric</a>. They tunnel IPv6 packets inside of IPv4 packets (more specifically using IP Protocol 41, designed for this purpose).</p>
<p>I had it working on an old Linksys router I had flashed with TomatoUSB and hacked a bit. I had IPv6 flowing through my network and was able to reach a few sites over IPv6. Then I had the realization that I was no longer protected by my router. I was now directly reachable&#8211;without a firewall! While I could fix that, I think that&#8217;s enough experimentation for now.</p>
<p>I guess the point is: I can make it work today. However, few people are going to want to do what I had to go through to make it work. Every hop in the network has to be IPv6 friendly and IPv6 enabled. For the home user, it&#8217;s going to have to be as simple as plugging in a router. We&#8217;ll get there, but it&#8217;s going to be a bumpy ride for the next few years.</p>
<hr /><h2>Comments</h2><ul><li><a href="http://phoneboy.com/4015/speaking-ipv6">20 February 2011</a>, <a href='http://silpol.blogspot.com/' rel='external nofollow' class='url'>A. T.</a> writes: when I noticed Hurricane Electric mentioned, immediately I recalled "Running IPv6 in practice" http://www.debian-administration.org/article/Running_IPv6_in_practice ... could be great if you tag all your IPv6 posts with particular tag ;)</li><li><a href="http://phoneboy.com/4015/speaking-ipv6">20 February 2011</a>, <a href='http://www.phoneboy.com' rel='external nofollow' class='url'>PhoneBoy</a> writes: I was thinking about doing that anyway, thanks for reminding me!</li></ul><hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/2101/getting-closer-to-ipv6" rel="bookmark" title="Permanent Link: Getting Closer To IPv6?">Getting Closer To IPv6?</a></li><li><a href="http://phoneboy.com/4033/speaking-ipv6-privately" rel="bookmark" title="Permanent Link: Speaking IPv6&#8211;Privately">Speaking IPv6&#8211;Privately</a></li><li><a href="http://phoneboy.com/2173/why-we-need-to-go-to-ipv6-now" rel="bookmark" title="Permanent Link: Why We Need To Go To IPv6. Now.">Why We Need To Go To IPv6. Now.</a></li><li><a href="http://phoneboy.com/4032/your-isp-may-be-trialing-ipv6-already" rel="bookmark" title="Permanent Link: Your ISP May be Trialing IPv6 Already!">Your ISP May be Trialing IPv6 Already!</a></li><li><a href="http://phoneboy.com/2122/innovate-or-get-out-of-the-way" rel="bookmark" title="Permanent Link: Innovate Or Get Out Of The Way">Innovate Or Get Out Of The Way</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/4015/speaking-ipv6">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/4015/speaking-ipv6/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Check Point R75 Now Available</title>
		<link>http://phoneboy.com/3917/check-point-r75-now-available</link>
		<comments>http://phoneboy.com/3917/check-point-r75-now-available#comments</comments>
		<pubDate>Tue, 28 Dec 2010 02:08:26 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[check point]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://phoneboy.com/?p=3917</guid>
		<description><![CDATA[Anyone who&#8217;s following the Check Point Twitter, Facebook page, or has been peeking around in User Center has probably seen the release of R75&#8211;Check Point&#8217;s next major release. DLP, Mobile Access, Identity Awareness, and Application Control are all now available as Software Blades&#8211;modules that can be enabled as needed. Over the past several months, as part [...]]]></description>
			<content:encoded><![CDATA[<p>Anyone who&#8217;s following the <a href="http://twitter.com/checkpointsw">Check Point Twitter</a>, <a href="http://facebook.com/checkpointsoftware">Facebook page</a>, or has been peeking around in User Center has probably seen the release of <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk58362">R75</a>&#8211;Check Point&#8217;s next major release. DLP, Mobile Access, Identity Awareness, and Application Control are all now available as Software Blades&#8211;modules that can be enabled as needed.</p>
<p>Over the past several months, as part of my normal duties at Check Point, I have talked with a number of the people involved in this release. I&#8217;ve learned about some of the technologies that went into this release, and I have to say, it&#8217;s quite amazing how it all comes together!</p>
<p><a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk58362">Take R75 out for a test drive</a>. Even if you don&#8217;t immediately use the new features, there are some usability enhancements in the SmartConsole applications, an improved IPS engine, and, of course, <a href="http://appwiki.checkpoint.com/">AppWiki</a>, which is a great resource to find out about applications&#8211;even if you&#8217;re not using our Application Control Software Blade!</p>
<hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/3944/gil-shwed-says-check-point-isnt-for-sale" rel="bookmark" title="Permanent Link: Gil Shwed says Check Point isn&#8217;t for sale">Gil Shwed says Check Point isn&#8217;t for sale</a></li><li><a href="http://phoneboy.com/4050/announcing-cpshared-the-open-technical-forum-for-all-things-check-point" rel="bookmark" title="Permanent Link: Announcing CPshared: The Open Technical Forum for all things Check Point">Announcing CPshared: The Open Technical Forum for all things Check Point</a></li><li><a href="http://phoneboy.com/383/the_long-term_plan_for_phoneboy_com" rel="bookmark" title="Permanent Link: The long-term plan for phoneboy.com">The long-term plan for phoneboy.com</a></li><li><a href="http://phoneboy.com/4175/check-point-r75-20-securitypower-and-new-appliances" rel="bookmark" title="Permanent Link: Check Point: R75.20, SecurityPower, and New Appliances">Check Point: R75.20, SecurityPower, and New Appliances</a></li><li><a href="http://phoneboy.com/fw1" rel="bookmark" title="Permanent Link: Where Did the FireWall-1 FAQ Go?">Where Did the FireWall-1 FAQ Go?</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/3917/check-point-r75-now-available">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/3917/check-point-r75-now-available/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Should I Use This Computer?</title>
		<link>http://phoneboy.com/4028/should-i-use-this-computer</link>
		<comments>http://phoneboy.com/4028/should-i-use-this-computer#comments</comments>
		<pubDate>Wed, 03 Nov 2010 22:57:36 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[computers]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://phoneboy.com/4028/should-i-use-this-computer</guid>
		<description><![CDATA[Found at a hotel &#8220;business center&#8221; computer. Related PostsMy wife&#8217;s parents are now Broadband-enabledBlogging AnywhereMy Dad&#8217;s Internet Safety TipsInternet Channel on WiiReorganizing my office This work originally came from The PhoneBoy Blog and is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License. Fingerprint: e37ac627f3d973694c212ff9430d215a]]></description>
			<content:encoded><![CDATA[<p>Found at a hotel &#8220;business center&#8221; computer.</p>
<hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/320/my_wife's_parents_are_now_broadband-enabled" rel="bookmark" title="Permanent Link: My wife&#8217;s parents are now Broadband-enabled">My wife&#8217;s parents are now Broadband-enabled</a></li><li><a href="http://phoneboy.com/1866/blogging-anywhere" rel="bookmark" title="Permanent Link: Blogging Anywhere">Blogging Anywhere</a></li><li><a href="http://phoneboy.com/1148/my-dads-internet-safety-tips" rel="bookmark" title="Permanent Link: My Dad&#8217;s Internet Safety Tips">My Dad&#8217;s Internet Safety Tips</a></li><li><a href="http://phoneboy.com/2374/internet-channel-on-wii" rel="bookmark" title="Permanent Link: Internet Channel on Wii">Internet Channel on Wii</a></li><li><a href="http://phoneboy.com/58/reorganizing_my_office" rel="bookmark" title="Permanent Link: Reorganizing my office">Reorganizing my office</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/4028/should-i-use-this-computer">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/4028/should-i-use-this-computer/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using Firesheep is Illegal. So What?</title>
		<link>http://phoneboy.com/3962/using-firesheep-is-illegal-so-what</link>
		<comments>http://phoneboy.com/3962/using-firesheep-is-illegal-so-what#comments</comments>
		<pubDate>Fri, 29 Oct 2010 14:12:38 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://phoneboy.com/?p=3962</guid>
		<description><![CDATA[From Using Firesheep is illegal in the US, UK, and most of the world: One thing that many sites have glossed over is the inherent illegality of using Firesheep. &#8220;Go on! Try it! It&#8217;s cool!&#8221; &#8212; yes, it is shockingly cool, but if you use it on a public network you are breaking the law. In [...]]]></description>
			<content:encoded><![CDATA[<p>From <a href="http://www.downloadsquad.com/2010/10/29/using-firesheep-is-illegal-in-the-us-uk-and-most-of-the-world/">Using Firesheep is illegal in the US, UK, and most of the world</a>:</p>
<blockquote><p>One thing that many sites have glossed over is the inherent illegality of using Firesheep. &#8220;Go on! Try it! It&#8217;s cool!&#8221; &#8212; yes, it is shockingly cool, but if you use it on a public network you are breaking the law.</p>
<p>In general, the interception of any communication &#8212; digital or otherwise &#8212; is prohibited by law. Government agencies are the only exception and even then a warrant is usually required. Firesheep, by intercepting digital communication and re-routing it to your Web browser is a wiretap. Unless you&#8217;re trying to crack the local organized crime racket and you have a warrant in your pocket, you are breaking the law.</p></blockquote>
<p>Making something illegal doesn&#8217;t mean people&#8211;especially criminals&#8211;won&#8217;t do it. Besides, one could argue that this communication is being broadcast unencrypted and can easily be sniffed passively, thus one should not have had a reasonable expectation of privacy.</p>
<p>The goal of this program isn&#8217;t to let people hijack each other&#8217;s web sessions anyway, it&#8217;s to clearly demonstrate the threat of using unencrypted WiFi using unencrypted protocols, which has existed since WiFi was first conceived. Unfortunately, easy-to-use programs like this are what&#8217;s needed to apply the appropriate pressure to change our protocols and practices.</p>
<hr /><h2>Comments</h2><ul><li><a href="http://phoneboy.com/3962/using-firesheep-is-illegal-so-what">8 November 2010</a>, <a href='http://www.swordshield.com/2010/11/08/no-script-kiddie-left-behind-firesheep-makes-stealing-logins-over-wifi-easy/' rel='external nofollow' class='url'>No Script Kiddie Left Behind &#8211; Firesheep Makes Stealing Logins Over WiFi Easy | Sword &amp; Shield Enterprise Security, Inc.</a> writes: [...] you&#8217;re interested in experimenting with Firesheep, Phoneboy cautions that using it may be illegal, so the  usual legal precautions [...]</li><li><a href="http://phoneboy.com/3962/using-firesheep-is-illegal-so-what">14 November 2010</a>, Myka writes: Blah blah blah tell it the crows, if you leave your car wide open with the keys in the ignition dont complain that it was stolen</li></ul><hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/3956/unencrypted-access-needs-to-die" rel="bookmark" title="Permanent Link: Unencrypted Access Needs To Die">Unencrypted Access Needs To Die</a></li><li><a href="http://phoneboy.com/4184/verizon-following-att-yet-again-this-time-on-illegal-tethering" rel="bookmark" title="Permanent Link: Verizon Following AT&#038;T Yet Again, This Time on &#8220;Illegal&#8221; Tethering">Verizon Following AT&#038;T Yet Again, This Time on &#8220;Illegal&#8221; Tethering</a></li><li><a href="http://phoneboy.com/2294/why-the-us-has-more-minutes-of-use-than-others" rel="bookmark" title="Permanent Link: Why The U.S. Has More Minutes Of Use Than Others">Why The U.S. Has More Minutes Of Use Than Others</a></li><li><a href="http://phoneboy.com/3122/there-oughta-be-a-law-against-this" rel="bookmark" title="Permanent Link: There Oughta Be A Law Against This">There Oughta Be A Law Against This</a></li><li><a href="http://phoneboy.com/292/does_a_mobile_phone_to_voip_bridge_break_any_laws?" rel="bookmark" title="Permanent Link: Does a Mobile Phone to VoIP bridge break any laws?">Does a Mobile Phone to VoIP bridge break any laws?</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/3962/using-firesheep-is-illegal-so-what">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/3962/using-firesheep-is-illegal-so-what/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Unencrypted Access Needs To Die</title>
		<link>http://phoneboy.com/3956/unencrypted-access-needs-to-die</link>
		<comments>http://phoneboy.com/3956/unencrypted-access-needs-to-die#comments</comments>
		<pubDate>Thu, 28 Oct 2010 22:29:51 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://phoneboy.com/?p=3956</guid>
		<description><![CDATA[From Why Firesheep’s Time Has Come &#124; Steve (GRC) Gibson&#8217;s Blog: In case you’ve been somewhere off the grid, and have somehow missed the news, Firesheep is an incredibly easy to use add-on for the Firefox web browser that, when invoked while connected to any open and unencrypted WiFi hotspot, lists every active web session being conducted [...]]]></description>
			<content:encoded><![CDATA[<p>From <a href="http://steve.grc.com/2010/10/28/why-firesheeps-time-has-come/">Why Firesheep’s Time Has Come | Steve (GRC) Gibson&#8217;s Blog</a>:</p>
<blockquote><p><a href="http://steve.grc.com/2010/10/28/why-firesheeps-time-has-come/"></a>In case you’ve been somewhere off the grid, and have somehow missed the news, Firesheep is an incredibly easy to use add-on for the Firefox web browser that, when invoked while connected to any open and unencrypted WiFi hotspot, lists every active web session being conducted by anyone sharing the hotspot, and allows a snooping user to hijack any other user’s online web session logon with a simple double-click of the mouse. The snooper, then logged on and impersonating the victim, can do anything the original logged on user/victim might do.</p></blockquote>
<p>I&#8217;ve experimented with Firesheep on my own system. Normally, I use Google Chrome, but I installed a fresh copy of Firefox just for the occasion to try Firesheep.</p>
<p><a title="Firesheep-example by PhoneBoy, on Flickr" href="http://www.flickr.com/photos/phoneboy/5124526752/"><img src="http://farm2.static.flickr.com/1159/5124526752_e47cc84760.jpg" alt="Firesheep-example" width="500" height="142" /></a></p>
<p>Within a few moments, I was able to pick up web sessions happening from my Google Chrome browser. I was able to use both my Facebook and Twitter from Firefox without having to log into them! It did pick up my Google login, but before I hit Gmail, I had to provide authentication. Remember, this was a fresh installation of Firefox on a machine that did not previously have Firefox installed at all!</p>
<p>This is scary stuff. As Steve Gibson says, though, this has always been possible with unencrypted WiFi by anyone with enough 1337 5killz to pull it off. Now, it&#8217;s as simple as installing a web browser plugin.</p>
<hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/3962/using-firesheep-is-illegal-so-what" rel="bookmark" title="Permanent Link: Using Firesheep is Illegal. So What?">Using Firesheep is Illegal. So What?</a></li><li><a href="http://phoneboy.com/337/mci__qwest__and_verizon" rel="bookmark" title="Permanent Link: MCI, Qwest, and Verizon">MCI, Qwest, and Verizon</a></li><li><a href="http://phoneboy.com/1144/nokia-n93-and-access-points-on-odd-channels" rel="bookmark" title="Permanent Link: Nokia N93 and Access Points on Odd Channels">Nokia N93 and Access Points on Odd Channels</a></li><li><a href="http://phoneboy.com/930/macbook_didn't_make_it" rel="bookmark" title="Permanent Link: MacBook Didn&#8217;t Make It">MacBook Didn&#8217;t Make It</a></li><li><a href="http://phoneboy.com/920/crack_wep_with_a_single_packet" rel="bookmark" title="Permanent Link: Crack WEP With a Single Packet">Crack WEP With a Single Packet</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/3956/unencrypted-access-needs-to-die">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/3956/unencrypted-access-needs-to-die/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mobile Security Isn&#8217;t The Same on All Platforms</title>
		<link>http://phoneboy.com/3948/mobile-security-aint-the-same-on-all-platforms</link>
		<comments>http://phoneboy.com/3948/mobile-security-aint-the-same-on-all-platforms#comments</comments>
		<pubDate>Thu, 28 Oct 2010 01:52:42 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[mobile phones]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://phoneboy.com/?p=3948</guid>
		<description><![CDATA[From an article on Cnet announcing a mobile security product: The [product] runs on all mobile operating systems and devices. It includes antivirus, personal firewall, antispam, and remote monitoring and control services. It remotely backs up and restores data and can locate devices that are lost and stolen, as well as wipe data from stolen [...]]]></description>
			<content:encoded><![CDATA[<p>From <a href="http://news.cnet.com/8301-27080_3-20020758-245.html?part=rss&#038;subj=news&#038;tag=2547-1_3-0-20">an article on Cnet announcing a mobile security product</a>:</p>
<blockquote><p>The [product] runs on all mobile operating systems and devices. It includes antivirus, personal firewall, antispam, and remote monitoring and control services. It remotely backs up and restores data and can locate devices that are lost and stolen, as well as wipe data from stolen devices. It also can send an alert when a SIM card has been removed or replaced. For enterprise users, it protects devices accessing networks with SSL-based virtual private network.</p></blockquote>
<p>And it makes great toast, too!</p>
<p>Reality check. The functionality of the above mentioned product is highly dependent on the mobile platform we&#8217;re talking about. A quick trip to the vendor&#8217;s website shows you what options are available on which platform, and it&#8217;s clearly not the same.</p>
<p>Mobile operating systems are designed more secure from the get-go. That doesn&#8217;t completely reduce the need for security, but it does reduce or eliminate certain classes of threats. Also, each mobile OS has their own unique restrictions on the kinds of apps that can be written. Each mobile OS has different security services that can be utilized in different ways.</p>
<p>In short, what you can do on iPhone and what you can do on Android are very different. Even if a vendor provides the same application on multiple platforms, it is not going to provide the same level of functionality. It simply cannot.</p>
<p>The author of the above-linked piece did not even attempt to articulate this critical point. If you&#8217;re looking at a mobile security solution for your enterprise, you simply have to be aware of this reality so as you don&#8217;t expect something that cannot be delivered.</p>
<p><strong>Disclaimer</strong>: My employer offers a competing product: <a href="http://www.checkpoint.com/products/mobile-access-software-blade/">Mobile Access Software Blade</a>. However, the above thoughts are my own.</p>
<hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/587/why_is_skype_so_popular?" rel="bookmark" title="Permanent Link: Why is Skype So Popular?">Why is Skype So Popular?</a></li><li><a href="http://phoneboy.com/1198/fccs-mcdowell-has-cohones" rel="bookmark" title="Permanent Link: FCC&#8217;s MCDowell Has Cohones">FCC&#8217;s MCDowell Has Cohones</a></li><li><a href="http://phoneboy.com/4182/securing-mobile-devices-may-be-impossible" rel="bookmark" title="Permanent Link: Securing Mobile Devices May Be Impossible">Securing Mobile Devices May Be Impossible</a></li><li><a href="http://phoneboy.com/4161/thinking-about-mobile-security" rel="bookmark" title="Permanent Link: Thinking About Mobile Security">Thinking About Mobile Security</a></li><li><a href="http://phoneboy.com/1488/re-blogging-aint-so-great" rel="bookmark" title="Permanent Link: Re-Blogging Ain&#8217;t So Great">Re-Blogging Ain&#8217;t So Great</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/3948/mobile-security-aint-the-same-on-all-platforms">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/3948/mobile-security-aint-the-same-on-all-platforms/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gil Shwed says Check Point isn&#8217;t for sale</title>
		<link>http://phoneboy.com/3944/gil-shwed-says-check-point-isnt-for-sale</link>
		<comments>http://phoneboy.com/3944/gil-shwed-says-check-point-isnt-for-sale#comments</comments>
		<pubDate>Tue, 26 Oct 2010 22:58:08 +0000</pubDate>
		<dc:creator>PhoneBoy</dc:creator>
				<category><![CDATA[check point]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://phoneboy.com/?p=3944</guid>
		<description><![CDATA[From Check Point isn&#8217;t for sale, says Shwed &#8211; Haaretz Daily Newspaper &#124; Israel News: Two months ago, antivirus systems giant McAfee was sold to Intel for $7.7 billion. At the time, a number of analysts suggested that Check Point Software Technologies would also be an attractive target for takeover. Gil Shwed, the company&#8217;s founder and [...]]]></description>
			<content:encoded><![CDATA[<p>From <a href="http://www.haaretz.com/print-edition/business/check-point-isn-t-for-sale-says-shwed-1.320350?localLinksEnabled=false">Check Point isn&#8217;t for sale, says Shwed &#8211; Haaretz Daily Newspaper | Israel News</a>:</p>
<blockquote><p>Two months ago, antivirus systems giant McAfee was sold to Intel for $7.7 billion. At the time, a number of analysts suggested that Check Point Software Technologies would also be an attractive target for takeover. Gil Shwed, the company&#8217;s founder and leader, yesterday shrugged at the idea in conversation with reporters, after the company filed its third-quarter financials.</p>
<p>Anything&#8217;s possible, Shwed said: but he&#8217;s been very consistent in his position for the last 17 years, which is that Check Point isn&#8217;t for sale. &#8220;We are very proud of the fact that we are an Israeli company, an independent one,&#8221; he said.</p></blockquote>
<p>Why would Check Point put themselves up for sale when the financials continue to be strong and only getting better? I think it&#8217;s just &#8220;wishful thinking&#8221; by the analysis.</p>
<p><strong>Disclaimer</strong>: I work for Check Point.</p>
<hr /><h2>Related Posts</h2><ul><li><a href="http://phoneboy.com/4086/gil-shwed-the-security-industry-needs-to-change-a-little-bit" rel="bookmark" title="Permanent Link: Gil Shwed: &#8220;The [security] industry needs to change a little bit&#8221;">Gil Shwed: &#8220;The [security] industry needs to change a little bit&#8221;</a></li><li><a href="http://phoneboy.com/3168/gil-shwed-opens-nasdaq" rel="bookmark" title="Permanent Link: Gil Shwed Opens NASDAQ">Gil Shwed Opens NASDAQ</a></li><li><a href="http://phoneboy.com/2830/check-point-softwares-earnings-call-and-nokias-security-appliance-business" rel="bookmark" title="Permanent Link: Check Point Software&#8217;s Earnings Call and Nokia&#8217;s Security Appliance Business">Check Point Software&#8217;s Earnings Call and Nokia&#8217;s Security Appliance Business</a></li><li><a href="http://phoneboy.com/3017/check-point-software-posting-record-financial-results-for-q1-2009" rel="bookmark" title="Permanent Link: Check Point Software Posting Record Financial Results For Q1 2009">Check Point Software Posting Record Financial Results For Q1 2009</a></li><li><a href="http://phoneboy.com/3981/more-obsolete-voip-gear-for-sale" rel="bookmark" title="Permanent Link: More Obsolete VoIP Gear for Sale">More Obsolete VoIP Gear for Sale</a></li></ul><hr /><small><a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">
<img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-nc-nd/3.0/us/80x15.png" />
</a>
<br />This work originally came from <a href="http://phoneboy.com/3944/gil-shwed-says-check-point-isnt-for-sale">The PhoneBoy Blog</a> and is licensed under a 
<a rel="license" href="http://creativecommons.org/licenses/by-nc-nd/3.0/us/">Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License</a>.
<br />Fingerprint: e37ac627f3d973694c212ff9430d215a</small>]]></content:encoded>
			<wfw:commentRss>http://phoneboy.com/3944/gil-shwed-says-check-point-isnt-for-sale/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

