<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://weblogs.asp.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Tobler.SoftwareArchitecture() : [Security]</title><link>http://weblogs.asp.net/jtobler/archive/tags/_5B00_Security_5D00_/default.aspx</link><description>Tags: [Security]</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>[Security] Major Cryptographic Algorithms Broken by Quantum Bogodynamics</title><link>http://weblogs.asp.net/jtobler/archive/2004/08/18/216869.aspx</link><pubDate>Thu, 19 Aug 2004 01:09:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:216869</guid><dc:creator>CSharpener</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/jtobler/rsscomments.aspx?PostID=216869</wfw:commentRss><comments>http://weblogs.asp.net/jtobler/archive/2004/08/18/216869.aspx#comments</comments><description>It is definitely not April Fools' Day, but the article &lt;a href="http://news.com.com/2100-1002_3-5313655.html"&gt;Crypto researchers abuzz over flaws&lt;/a&gt; will probably make you think it is.&amp;nbsp; As if all of the nasty viruses and worms and buffer overruns of late aren't enough, now MD4, MD5, HAVAL-128, RIPEMD, SHA-1, and other basic cryptographic algorithms currently in heavy production usage are under severe mathematical attack.&amp;nbsp; &lt;br /&gt; &lt;br /&gt; I think the only reasonable non-Occamian (Null-O) theory is that we must have recently experienced a serious rise in bogon flux density.&amp;nbsp; It's obvious (TM) that &lt;a href="http://catb.org/%7Eesr/jargon/html/B/bogon.html"&gt;bogons&lt;/a&gt; and &lt;a href="http://catb.org/%7Eesr/jargon/html/P/psyton.html"&gt;psytons&lt;/a&gt; have started poking their holes not only through electronic equipment but also even through basic theories and abstractions of all types.&amp;nbsp; &lt;a href="http://info.astrian.net/jargon/terms/q/quantum_bogodynamics.html"&gt;Quantum bogodynamics&lt;/a&gt; has evolved into the abstract realm!&amp;nbsp; Start boning up on your &lt;a href="http://www.nada.kth.se/%7Easa/madsci/qcd.html"&gt;quantum compudynamics&lt;/a&gt; or we are surely lost. Hmmmmmm?&amp;nbsp; Perhaps we're lost, anyway.&lt;br /&gt; &lt;br /&gt; "Caveat everybody!&amp;nbsp; She's gonna' blow!"&amp;nbsp; &lt;br /&gt; &lt;br /&gt; &lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=216869" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/jtobler/archive/tags/_5B00_General_5D00_/default.aspx">[General]</category><category domain="http://weblogs.asp.net/jtobler/archive/tags/_5B00_Security_5D00_/default.aspx">[Security]</category></item><item><title>[Security] Defensive Security Programming Resource</title><link>http://weblogs.asp.net/jtobler/archive/2004/08/14/214738.aspx</link><pubDate>Sun, 15 Aug 2004 06:07:00 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:214738</guid><dc:creator>CSharpener</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://weblogs.asp.net/jtobler/rsscomments.aspx?PostID=214738</wfw:commentRss><comments>http://weblogs.asp.net/jtobler/archive/2004/08/14/214738.aspx#comments</comments><description>Security conscious software developers, certainly including .NET developers, should take particular note of the &lt;a href="http://www.metasploit.com/projects/Framework/"&gt;Metasploit Framework&lt;/a&gt; released into the wild by &lt;a href="http://www.metasploit.com/index.html"&gt;Metasploit&lt;/a&gt;.&amp;nbsp; I have to stretch a bit to have faith that this information and toolkit will be used more for good than harm.&amp;nbsp; Still, with all sorts of very nasty new viruses appearing, ones that can even hop from Bluetooth to your Symbian-enabled cellphone (see &lt;a href="http://securityresponse.symantec.com/avcenter/venc/data/epoc.cabir.html"&gt;SymbOS.Cabir&lt;/a&gt;), all of us serious software professionals had better educate ourselves on the tools and techniques being used against us by the denizens of the Dark Side.&amp;nbsp; Frankly, I think the virus wars have escalated beyond the coping ability of the normal anti-virus vendors and their products.&amp;nbsp; From what I see, most organizations are absolutely clueless as to the new hazards we face today!&amp;nbsp; If you care about your users, you will need to work very hard to protect them and your applications from the kinds of tactics demonstrated publicly by &lt;a href="http://www.metasploit.com/index.html"&gt;Metasploit&lt;/a&gt; and similar exploit information sources.&amp;nbsp; May the Force be with you!&lt;br /&gt; &lt;br /&gt; &lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=214738" width="1" height="1"&gt;</description><category domain="http://weblogs.asp.net/jtobler/archive/tags/_5B00_Tools_5D00_/default.aspx">[Tools]</category><category domain="http://weblogs.asp.net/jtobler/archive/tags/_5B00_Security_5D00_/default.aspx">[Security]</category></item></channel></rss>