<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel>
	<title>MetaFilter posts tagged with security</title>
	<link>http://www.metafilter.com/tags/security/rss</link>
	<description>tag posts with security</description>
		  <pubDate>Sat, 12 Jul 2008 10:35:45 -0800</pubDate>
      <lastBuildDate>Sat, 12 Jul 2008 10:35:45 -0800</lastBuildDate>

	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>
	<item>
		<title>Freedom Flies</title>
		<link>http://www.metafilter.com/73252/Freedom-Flies</link>
		<description>
		The Department of Homeland Security has &lt;a href=&quot;http://www.lamperdlesslethal.com/news/upload/pg1HomelandSecurity7_06.pdf&quot;&gt;expressed&lt;/a&gt; &lt;a href=&quot;http://www.lamperdlesslethal.com/news/upload/pg2HomelandSecurity7_06.pdf&quot;&gt;interest &lt;/a&gt; [PDFs] in forcing all commercial airline passengers to wear a taser bracelet that can be used to incapacitate anyone on an airline.  This &lt;a href=&quot;http://www.lamperdlesslethal.com/video_gallery.asp?video=http://www.lamperdlesslethal.com/video/EMDsafetybracelet.flv&amp;title=&quot;&gt;video&lt;/a&gt;, from the company that will produce the bracelets, explains how the bracelet would be put on the passenger at the point that they clear security, and would not be removed until they leave secure areas. It would take the place of boarding passes, carry personal and biometric information about the passengers, track and monitor every passenger via GPS and shock the wearer on command, immobilizing him or her for several minutes.  DHS official, Paul S. Ruwaldt of the Science and Technology Directorate, office of Research and Development is also excited about the possiblility of using it as an interrogation tool at airports. Ah freedom, who knew it smelled like burning flesh?  </description>
		<guid isPermaLink="false">tag:metafilter.com,2008:site.73252</guid>
		<pubDate>Sat, 12 Jul 2008 10:35:45 -0800</pubDate>

<category>security</category>

<category>terrorism</category>

<category>homelanddefense</category>

<category>tasers</category>

<category>biometrics</category>

<category>airlines</category>

<category>freedom</category>

<dc:creator>dejah420</dc:creator>
	</item>
      <item>
		<title>TSA gets Xray goggles. No, seriously.</title>
		<link>http://www.metafilter.com/72510/TSA-gets-Xray-goggles-No-seriously</link>
		<description>
		&lt;a href="http://news.yahoo.com/s/afp/20080610/ts_alt_afp/ustransportaviationsecurity;_ylt=AtcCc4COnO77owc76ktKboWs0NUE"&gt;Scanners that see through clothing installed in US airports.&lt;/a&gt; Good news! No more testing. Time to roll these puppies out. It&apos;s OK though, seriously guys. See we&apos;re gonna &lt;a href=&quot;http://www.tsa.gov/blog/2008/05/which-is-it-millimeter-wave-or.html&quot;&gt;blur the faces&lt;/a&gt; when we look at their sexual organs, so everything&apos;s cool. K?

&lt;a href=&quot;http://www.metafilter.com/56681/Oh-I-wish-we-had-the-image-tag-again&quot;&gt;Prev&lt;/a&gt;.  </description>
		<guid isPermaLink="false">tag:metafilter.com,2008:site.72510</guid>
		<pubDate>Fri, 13 Jun 2008 13:27:54 -0800</pubDate>

<category>TSA</category>

<category>backscatter</category>

<category>xray</category>

<category>airport</category>

<category>security</category>

<category>airportsecurity</category>

<category>obliterationofprivacy</category>

<dc:creator>allkindsoftime</dc:creator>
	</item>
      <item>
		<title>How to steal priceless jewelry: prank call</title>
		<link>http://www.metafilter.com/72265/How-to-steal-priceless-jewelry-prank-call</link>
		<description>
		&lt;a href="http://www.cbc.ca/canada/british-columbia/story/2008/06/04/bc-ubc-security-ruse.html?ref=rss"&gt;Theives bypassed all security systems by simply posing as the security company on the phone&lt;/a&gt; These days as a robber dealing with high-tech security systems it seems that it&apos;s not about being a hacker or having loads of money to pull off a heist, its about making a phone call, having bear spray, and waiting for a guard to go on smoke break. How UBC jewelry was stolen from the &lt;a href=&quot;http://www.moa.ubc.ca/&quot;&gt;Museum of Anthropology&lt;/a&gt; :

Thieves make one call essentially saying &quot;Oh ya, we are the company in charge of your security systems, tonight we are doing some tests, so when alarms go off, its just tests, so don&apos;t worry about it&quot;. Security&apos;s reply &quot;OK.&quot;

The UBC gold jewelry: still missing... Simplicity pays off. </description>
		<guid isPermaLink="false">tag:metafilter.com,2008:site.72265</guid>
		<pubDate>Wed, 04 Jun 2008 13:30:20 -0800</pubDate>

<category>heist</category>

<category>security</category>

<category>missing</category>

<category>jewelry</category>

<dc:creator>figTree</dc:creator>
	</item>
      <item>
		<title>It doesn&apos;t matter how much security you put on the box.  Humans are not secure.</title>
		<link>http://www.metafilter.com/71858/It-doesnt-matter-how-much-security-you-put-on-the-box-Humans-are-not-secure</link>
		<description>
		&lt;a href="http://sysopmind.com/essays/aibox.html"&gt;The AI-Box Experiments.&lt;/a&gt; The hypothesis: &quot;A transhuman can take over a human mind through a text-only terminal.&quot; Does Artifical Intelligence create &lt;a href=&quot;http://www.swinburne.edu.au/sbs/ajets/journal/V1N1/pdf/V1N1-2-Thiel.pdf&quot;&gt;moral monsters&lt;/a&gt; (PDF) ? Can we create &lt;a href=&quot;http://www.singinst.org/upload/CFAI//index.html&quot;&gt;friendly AI&lt;/a&gt;?  </description>
		<guid isPermaLink="false">tag:metafilter.com,2008:site.71858</guid>
		<pubDate>Wed, 21 May 2008 15:12:47 -0800</pubDate>

<category>ai</category>

<category>artificialintelligence</category>

<category>transhuman</category>

<category>security</category>

<category>experiment</category>

<dc:creator>desjardins</dc:creator>
	</item>
      <item>
		<title>15 bits of crypto should be enough for anybody</title>
		<link>http://www.metafilter.com/71730/15-bits-of-crypto-should-be-enough-for-anybody</link>
		<description>
		On May 13, security advisories published by &lt;a href=&quot;http://lists.debian.org/debian-security-announce/2008/msg00152.html&quot;&gt;Debian&lt;/a&gt; and &lt;a href=&quot;http://www.ubuntu.com/usn/usn-612-1&quot;&gt;Ubuntu&lt;/a&gt; revealed that, for over a year, their OpenSSL libraries have had a major flaw in their &lt;a href=&quot;http://en.wikipedia.org/wiki/Cryptographically_secure_pseudorandom_number_generator&quot; title=&quot;Wikipedia: Cryptographically secure pseudorandom number generator&quot;&gt;CSPRNG&lt;/a&gt;, which is used by &lt;a href=&quot;http://en.wikipedia.org/wiki/Key_generation&quot; title=&quot;Wikipedia: Key generation&quot;&gt;key generation&lt;/a&gt; functions in many widely-used applications, which caused the &quot;random&quot; numbers produced to be extremely predictable. &lt;small&gt;[&lt;a href=&quot;http://blog.rominet.net/2008/05/debianopenssl-debacle.html&quot;&gt;lolcat summary&lt;/a&gt;]&lt;/small&gt; How bad is it? It&apos;s &lt;a href=&quot;http://www.debian.org/security/key-rollover/&quot;&gt;pretty&lt;/a&gt; &lt;a href=&quot;http://wiki.debian.org/SSLkeys&quot;&gt;bad&lt;/a&gt;. Understand that these keys are used not only for encryption, but also for authentication. The keyspace has been reduced to a mere 32,768 possibilities, and you can already &lt;a href=&quot;http://metasploit.com/users/hdm/tools/debian-openssl/&quot;&gt;download them all&lt;/a&gt;, along with tools to use them. Worse still, in the days &lt;em&gt;before&lt;/em&gt; the issue became publicly known, there was a &lt;a href=&quot;http://www.informationweek.com/news/security/attacks/showArticle.jhtml?articleID=207603339&quot;&gt;noticeable&lt;/a&gt; &lt;a href=&quot;http://stats.denyhosts.net/stats.html&quot;&gt;spike&lt;/a&gt; in the number of brute-force attacks on SSH servers, indicating that there has already been significant exploitation of this vulnerability.

Partial timeline of events: In May 2006, &lt;a href=&quot;http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=363516&quot;&gt;a bug&lt;/a&gt; led to &lt;a href=&quot;http://thread.gmane.org/gmane.comp.encryption.openssl.devel/10917&quot;&gt;a question&lt;/a&gt; which led to &lt;a href=&quot;http://svn.debian.org/viewsvn/pkg-openssl/openssl/trunk/rand/md_rand.c?rev=141&amp;r1=140&amp;r2=141&quot;&gt;the fateful patch&lt;/a&gt; being applied to &lt;a href=&quot;http://svn.debian.org/viewsvn/pkg-openssl/openssl/trunk/rand/md_rand.c?rev=141&amp;view=markup&quot;&gt;md_rand.c&lt;/a&gt; (in Debian&apos;s &quot;unstable&quot; development branch). In April 2007, Debian 4.0 &quot;etch&quot; and Ubuntu 7.04 were both released, which was the beginning of the inclusion of the buggy version of OpenSSL in officially-released distributions. The bug remained unfixed through the releases of Ubuntu 7.10 and 8.04. On May 7, 2008, the &lt;a href=&quot;http://svn.debian.org/viewsvn/pkg-openssl/openssl/trunk/crypto/rand/md_rand.c?rev=300&amp;view=diff&amp;r1=300&amp;r2=299&quot;&gt;patch to fix the problem&lt;/a&gt; was committed to Debian&apos;s source repository, and on May 13 the issue was officially disclosed and updated packages were made available to users. (The patch&apos;s availability days before public disclosure of the bug appears to be a violation of &lt;a href=&quot;http://www.debian.org/doc/developers-reference/ch-pkgs.en.html#s-bug-security-confidentiality&quot;&gt;Debian&apos;s policy&lt;/a&gt;.)

&lt;a href=&quot;http://blog.drinsama.de/erich/en/linux/2008051401-debian-openssl-desaster.html&quot;&gt;Here&lt;/a&gt; &lt;a href=&quot;http://blog.drinsama.de/erich/en/linux/2008051401-consequences-of-sslssh-weakness.html&quot;&gt;are&lt;/a&gt; &lt;a href=&quot;http://changelog.complete.org/posts/714-Thoughtfulness-on-the-OpenSSL-bug.html&quot;&gt;some&lt;/a&gt; &lt;a href=&quot;http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/&quot;&gt;responses&lt;/a&gt; &lt;a href=&quot;http://algebraicthunk.net/~dburrows/blog/entry/worst-ever/&quot;&gt;from&lt;/a&gt; &lt;a href=&quot;http://www.advogato.org/person/branden/diary/5.html&quot;&gt;Debian&lt;/a&gt; &lt;a href=&quot;http://blog.steve.org.uk/i_still_don_t_know_why_i_m_here.html&quot;&gt;blogs&lt;/a&gt;, and &lt;a href=&quot;http://www.links.org/?p=327&quot;&gt;two&lt;/a&gt; &lt;a href=&quot;http://www.links.org/?p=328&quot;&gt;from&lt;/a&gt; an OpenSSL developer. </description>
		<guid isPermaLink="false">tag:metafilter.com,2008:site.71730</guid>
		<pubDate>Fri, 16 May 2008 22:01:42 -0800</pubDate>

<category>internet</category>

<category>security</category>

<category>crypto</category>

<category>cryptography</category>

<category>prng</category>

<category>ssl</category>

<category>ssh</category>

<category>debian</category>

<category>ubuntu</category>

<category>linux</category>

<category>random</category>

<category>numbers</category>

<category>math</category>

<category>owie</category>

<category>probability</category>

<dc:creator>finite</dc:creator>
	</item>
      <item>
		<title>Bin Laden Determined To Strike In U.S. Part 2</title>
		<link>http://www.metafilter.com/71286/Bin-Laden-Determined-To-Strike-In-US-Part-2</link>
		<description>
		&lt;a href="http://www.gao.gov/new.items/d08622.pdf"&gt;"The United States Lacks a Comprehensive Plan to Destroy the Terrorist Threat and Close the Safe Haven in Pakistan's Federally Administered Tribal Areas"&lt;/a&gt; (PDF).  A recent &lt;a href=&quot;http://www.gao.gov/&quot;&gt;GAO&lt;/a&gt; report claims that the Bush administration has &lt;a href=&quot;http://www.washingtonindependent.com/view/report-u-s-lacks&quot;&gt;failed to prevent Al Qaeda&apos;s reemergence in Pakistan&lt;/a&gt;, and that we&apos;re basically &lt;a href=&quot;http://www.thewashingtonnote.com/archives/2008/04/daily_show_on_g/&quot;&gt;right back where we started&lt;/a&gt; in 2001.  </description>
		<guid isPermaLink="false">tag:metafilter.com,2008:site.71286</guid>
		<pubDate>Wed, 30 Apr 2008 18:45:43 -0800</pubDate>

<category>AlQaeda</category>

<category>Bush</category>

<category>DailyShow</category>

<category>GAO</category>

<category>Pakistan</category>

<category>Security</category>

<category>Terrorism</category>

<category>War</category>

<dc:creator>homunculus</dc:creator>
	</item>
      <item>
		<title>Bovine terrorism is a bomb in a bull.</title>
		<link>http://www.metafilter.com/70332/Bovine-terrorism-is-a-bomb-in-a-bull</link>
		<description>
		Slate asks, &lt;a href=&quot;http://www.slate.com/id/2187648/pagenum/all/#page_start&quot;&gt;&quot;What&apos;s behind the boom in homeland-security and emergency-management majors?&quot;&lt;/a&gt;  </description>
		<guid isPermaLink="false">tag:metafilter.com,2008:site.70332</guid>
		<pubDate>Sat, 29 Mar 2008 12:02:29 -0800</pubDate>

<category>terrorism</category>

<category>homelandsecurity</category>

<category>security</category>

<category>professionalparanoids</category>

<category>education</category>

<category>college</category>

<category>university</category>

<dc:creator>Afroblanco</dc:creator>
	</item>
      <item>
		<title>outsourcing the country</title>
		<link>http://www.metafilter.com/70265/outsourcing-the-country</link>
		<description>
		The &lt;a href=&quot;http://www.gpo.gov/&quot;&gt;Governmental Printing Office&lt;/a&gt; prints all United States passports but they decided that it was time to &lt;a href=&quot;http://www.washingtontimes.com/apps/pbcs.dll/article?AID=/20080326/NATION/840186493/1001&quot;&gt;outsource&lt;/a&gt; part of the work. They claim it is &lt;a href=&quot;http://www.gpo.gov/news/2008/08news11.pdf&quot;&gt;secure&lt;/a&gt; [pdf].  </description>
		<guid isPermaLink="false">tag:metafilter.com,2008:site.70265</guid>
		<pubDate>Thu, 27 Mar 2008 06:47:05 -0800</pubDate>

<category>passport</category>

<category>passports</category>

<category>outsourcing</category>

<category>gpo</category>

<category>government</category>

<category>security</category>

<dc:creator>mustcatchmooseandsquirrel</dc:creator>
	</item>
      <item>
		<title>NECs new biometric security cam will guess your age, gender, (and it would be nice if it could size you up according to how you dress).</title>
		<link>http://www.metafilter.com/70151/NECs-new-biometric-security-cam-will-guess-your-age-gender-and-it-would-be-nice-if-it-could-size-you-up-according-to-how-you-dress</link>
		<description>
		&lt;a href="http://www.ubergizmo.com/15/archives/2007/10/nec_fieldanalyst_camera.html"&gt;NEC plans to market a system later this year that can derive someone's gender and age from images captured with a camera&lt;/a&gt; &quot;The system compares the photo against a database of several thousand faces to figure gender and age based on such factors as facial shape and wrinkles. &quot;  According to Nikkei Weekly 01/28/2008 Edition.  Link goes to Ubergizmo.

&quot;It&apos;s called FieldAnalyst and it&apos;s from NEC. The system homes in on faces of people who pass by the video camera. It then rapidly compares the image against samples in a database. It then spits out what it believes is your approximate age is and your gender.&quot; ..&quot;NEC scientists may next try to add clothing as a characteristic and classify people by whether they wear a suit or a T-shirt.&quot; more &lt;a href=&quot;http://www.news.com/8301-10784_3-9790253-7.html&quot;&gt;here&lt;/a&gt;  </description>
		<guid isPermaLink="false">tag:metafilter.com,2008:site.70151</guid>
		<pubDate>Sun, 23 Mar 2008 22:46:52 -0800</pubDate>

<category>biometrics</category>

<category>security</category>

<category>big</category>

<category>brother</category>

<dc:creator>celerystick</dc:creator>
	</item>
      <item>
		<title>what did we tell you</title>
		<link>http://www.metafilter.com/70033/what-did-we-tell-you</link>
		<description>
		The owners of the domain donotreply.com &lt;a href=&quot;http://www.donotreply.com/&quot;&gt;get a lot of mail&lt;/a&gt;. &lt;small&gt;&lt;small&gt;[&lt;a href=&quot;http://www.43folders.com/2008/03/19/links-march-19th&quot;&gt;via&lt;/a&gt;]&lt;/small&gt;&lt;/small&gt;  </description>
		<guid isPermaLink="false">tag:metafilter.com,2008:site.70033</guid>
		<pubDate>Wed, 19 Mar 2008 13:46:38 -0800</pubDate>

<category>email</category>

<category>security</category>

<category>donotreply</category>

<dc:creator>Armitage Shanks</dc:creator>
	</item>
      
	</channel>
</rss>


