<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2987896066309092616</id><updated>2011-07-07T21:26:19.399-07:00</updated><title type='text'>Café de Fallo</title><subtitle type='html'>a technical blog on information security</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>22</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-3525038859912955168</id><published>2010-04-16T22:42:00.000-07:00</published><updated>2010-04-16T23:04:13.416-07:00</updated><title type='text'>Rejection of security advice is entirely rational ! (not my words)</title><content type='html'>OK, so here I am trying to educate students (and Internet) users of the need for better security practices, and then I see a paper that argues that "rejection of security advice is entirely rational". Humm, this should be an interesting read.   The paper is available on Cormac Herley's site:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://research.microsoft.com/users/cormac/papers/2009/SoLongAndNoThanks.pdf"&gt;So Long, and No Thanks for the Externalities: the Rational Rejection of Security Advice by Users&lt;/a&gt;&lt;br /&gt;published at NSPW 2009.&lt;br /&gt;&lt;br /&gt;I haven't read the paper carefully, as yet -- but in general I do agree (with some reservations) with the author, unless you are the victim, of course!. IT security these days is hard, especially since the number of users and the usage patterns are growing everyday...probably a reason (among several others) that the cost-benefit is poor when it comes to security advice. Until I read this article, I used to think security advice and awareness is a 2-wall problem.&lt;br /&gt;&lt;br /&gt;wall 1:  I don't know &lt;span style="color: rgb(153, 0, 0);"&gt;why &lt;/span&gt;this is a security problem&lt;br /&gt;wall 2: ah, I know what the security problem is -- but I don't know &lt;span style="color: rgb(153, 0, 0);"&gt;how &lt;/span&gt;to solve it&lt;br /&gt;&lt;br /&gt;Are we breaking these walls down now?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-3525038859912955168?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/3525038859912955168/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=3525038859912955168' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/3525038859912955168'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/3525038859912955168'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2010/04/rejection-of-security-advice-is.html' title='Rejection of security advice is entirely rational ! (not my words)'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-754690234321278345</id><published>2010-03-05T11:17:00.001-08:00</published><updated>2010-03-05T11:26:09.657-08:00</updated><title type='text'>Cyber crime -- will it ever stop?</title><content type='html'>An interesting article in today's news ..after the arrest of a ring of hackers who created "Mariposa" ..a botnet network to steal personal information. There seems to be a debate on whether it is better to go after the bad-guys? ..or protect ourselves in the long run by education/awareness? You decide :)&lt;br /&gt;&lt;br /&gt;Click &lt;a href="http://www.cnn.com/2010/TECH/03/05/cyberattack.prosecute/index.html?hpt=C2"&gt;here&lt;/a&gt; for the complete article on CNN Tech&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-754690234321278345?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/754690234321278345/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=754690234321278345' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/754690234321278345'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/754690234321278345'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2010/03/cyber-crime-will-it-ever-stop.html' title='Cyber crime -- will it ever stop?'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-8788356748121614694</id><published>2009-12-08T08:45:00.000-08:00</published><updated>2009-12-08T09:18:06.078-08:00</updated><title type='text'>Advance-fee (a.k.a 419) Fraud</title><content type='html'>Ever got those emails about a Nigerian businessman or merchant wanting to deposit money with you? or ..something on the lines of "I don't know where to keep all this money/treasure..I have so so much!", well..it is a bull****. and popularly known as 419 fraud, or called it the "Advance Fee Fraud". There some other forms of the same fraud too, and here is why it is a "fraud". Below incident prompted me to write this blog.&lt;br /&gt;&lt;br /&gt;So my wife wanted to sell an iPod (we had an extra one, don't ask how), so we put it up on craigslist. Out of the 10 replies she got, 7 of them were strangely saying that they will pay MORE than what we have asked for. We were selling it for $70, ..the buyer (call him Charlie) was willing to pay $200. Strange? Yes. So here was the catch. Apparently, Charlie wanted us to pay him back the difference (why!) ..and then it would be all balanced. He messed with the wrong person though, since I was reading about this fraud that week (for a class that I teach). Here is how the fraud works.&lt;br /&gt;&lt;br /&gt;1. Charlie requests that he will buy your item for $200 (even though you are selling for $70). Sometimes he may ask to keep a few dollars as reward for yourself (well..)&lt;br /&gt;&lt;br /&gt;2. You agree, and ask Charlie for the money.&lt;br /&gt;&lt;br /&gt;3. Charlie sends you a fake email that the money has been deposited.&lt;br /&gt;&lt;br /&gt;4. Fake email says that you need to type in the mailing conformation number, or the bank confirmation number (for $200-$70=$130 difference you owe Charlie) for the deposit you made into Charlie's account.&lt;br /&gt;&lt;br /&gt;5. You hit the bank submit button and pay $130 to Charlie (and record the confirmation #). You might have already shipped the item too!&lt;br /&gt;&lt;br /&gt;6. Guess what! you've lost your money and also the item you shipped -- there is no Charlie, and neither has he deposited $200 into your account earlier. You check your account, and call your bank multiple times -- only to hear an angry voice that there has been no such deposit from Mr. Charlie!! "No deposits, no Charlie".&lt;br /&gt;&lt;br /&gt;7. Now your item is enroute to some address (possibly someone waiting to picked up at a side walk) ..and your $130 is also gone. Heck!&lt;br /&gt;&lt;br /&gt;WOW. genius! But these guys have been chased before -- some have been caught, and some are still at large. So if you get an email claiming to pay more (or ship item before confirming payment) ..please beware. I was lucky!&lt;br /&gt;&lt;br /&gt;One last note. Most such email have someone named to be in Nigeria, or East Africa -- but I doubt all are true. Someone next door could writing these email, and claiming domicile in Nigeria..though this form of fraud apparently started here. Read more here:&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Advance-fee_fraud"&gt;http://en.wikipedia.org/wiki/Advance-fee_fraud&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-8788356748121614694?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/8788356748121614694/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=8788356748121614694' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/8788356748121614694'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/8788356748121614694'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/12/advance-fee-aka-419-fraud.html' title='Advance-fee (a.k.a 419) Fraud'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-4895835878634020637</id><published>2009-11-01T17:28:00.001-08:00</published><updated>2009-11-01T17:32:29.280-08:00</updated><title type='text'>National Cyber Security Awareness Month 2009</title><content type='html'>Yes, apparently there is one -- October is the National Cyber Security Awareness Month, and there has been a a lot of buzz about security this month.&lt;br /&gt;&lt;br /&gt;Check: &lt;a href="http://googleblog.blogspot.com/2009/10/celebrating-national-cyber-security.html"&gt;http://googleblog.blogspot.com/2009/10/celebrating-national-cyber-security.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Oktoberfest is another kind of awareness month :)  ..nothing to do with cyber security, but still fun!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-4895835878634020637?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/4895835878634020637/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=4895835878634020637' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/4895835878634020637'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/4895835878634020637'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/11/national-cyber-security-awareness-month.html' title='National Cyber Security Awareness Month 2009'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-2555352669832219477</id><published>2009-09-16T20:18:00.001-07:00</published><updated>2009-09-16T20:57:22.577-07:00</updated><title type='text'>Top 10 Reasons Why Mac OS X has No viruses, ..at least so far!</title><content type='html'>So, I asked this question in the class I teach "Why Mac OS X has no viruses" -- it is a good question, since the Mac user-base is gradually increasing and most laptops and PCs (with Microsoft Windows-based OS) are so easily infected by malware, virus, adware, spyware, etc..unless you take proper security measures, of course.&lt;br /&gt;&lt;br /&gt;One student answered:  &lt;span style="font-style: italic;"&gt;"..because Mac has a very small number of users, so hackers are not interested"&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;While this is a possible reason, but not the only reason -- so I decided to do my "homework". So below are my reasons why it is so. Oh..but I am still with a Dell running Windows XP...meanwhile, wifey has recently got a Mac Book Pro -- and flaunting it around the house right now. :-)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Top 10 Reasons Why Mac OS X has No viruses&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;1. OS X is built on UNIX (actually, FreeBSD) – which is a multi user system with a security architecture built into it at the beginning of design itself. WINDOWS came from single-user architecture with security and multi user capability as an “after thought”. Patching does not help much!&lt;br /&gt;&lt;br /&gt;2. UNIX had networking built into it from the beginning; again in Windows this was included at a later date. Also, most of Mac OS X was developed after the Internet, so the vulnerabilities were addressed during the design of OS X. Most viruses exploit the Internet connections, email and file transfer.&lt;br /&gt;&lt;br /&gt;3. Windows built Internet Explorer into the O/S at a very deep level, and allowed code execution within the browser. In OS X the browser is a completely separate application -- not an integral part of the OS. Most virus or hackers exploit this vulnerability, since some malicious code can be run in the browser itself.&lt;br /&gt;&lt;br /&gt;4. In earlier Windows everything ran as the system user (what!), so the capability to compromise an entire system was easier. Simply during a breach, hacker=system user! Close your eyes.&lt;br /&gt;&lt;br /&gt;5. Microsoft’s backward compatibility mantra does not do them any favors  -- all Microsoft OS need to run old software, so they need so many old APIs, all of which can have holes in them. The patches help “patch” the holes, but the patches may have holes too! Like the chicken-and-egg problem?&lt;br /&gt;&lt;br /&gt;6. OS X has no registry. Ah ha…this is one of the biggest mistakes Microsoft made though it helps in organizing the applications well – how about organizing the security?&lt;br /&gt;&lt;br /&gt;7. OS X asks for your password before allowing you to run new software or install something. Not fool proof, but at least fool resistant. Well.&lt;br /&gt;&lt;br /&gt;8. Where do viruses usually hang out in Windows:&lt;br /&gt;a. At the root.&lt;br /&gt;b. In the user’s local settings temp folder.&lt;br /&gt;c. In these folders: \windows, \system, \system32 — the most common places where viruses hide.&lt;br /&gt;d. As registry entries.&lt;br /&gt;&lt;br /&gt;None of those areas are exposed to the environment (or users) in OS X. You can’t see those folders. Virus writers can’t access them. Thus, viruses can’t exploit those areas. A recent Mac virus may have tried to exploit this – not much success.&lt;br /&gt;&lt;br /&gt;9. Earlier, Mac’s ran on PowerPC (by IBM and Motorola), so not many weaknesses were not exploited by viruses. Many PCs. Laptops run on Intel’s microprocessors. Note however that Mac has started to use Intel’s processors now – welcoming some possible viruses? You can say that Mac maintains a “clean and secure” gene-pool, but how long will it last?&lt;br /&gt;&lt;br /&gt;10. Mac has a smaller user-base, so there is more incentive for hackers or virus coders to attack the “big-fish” Microsoft XP or Windows Vista ..but not a tasty one :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-2555352669832219477?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/2555352669832219477/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=2555352669832219477' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/2555352669832219477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/2555352669832219477'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/09/top-10-reasons-why-mac-os-x-has-no.html' title='Top 10 Reasons Why Mac OS X has No viruses, ..at least so far!'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-7426217240751974768</id><published>2009-09-15T19:28:00.001-07:00</published><updated>2009-09-15T19:30:53.081-07:00</updated><title type='text'>Survey about Using Good Passwords (asking for your 2 minutes)</title><content type='html'>This is a small survey which I plan to use as part of a research paper. It will less take less than 2 minutes. Please answer the following questions and hit submit.&lt;br /&gt;Thanks for your participation and your time! Take care.&lt;br /&gt;&lt;br /&gt;Link to the survey:&lt;br /&gt;&lt;a href="http://spreadsheets.google.com/viewform?hl=en&amp;amp;formkey=dEVhR3BkcUFobWM2VUZyUWV0Tmp2WEE6MA.." target="_blank"&gt;http://spreadsheets.google.&lt;wbr&gt;com/viewform?hl=en&amp;amp;formkey=&lt;wbr&gt;dEVhR3BkcUFobWM2VUZyUWV0Tmp2WE&lt;wbr&gt;E6MA..&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;Microsoft Tool&lt;br /&gt;&lt;a href="http://www.microsoft.com/protect/fraud/passwords/checker.aspx" target="_blank"&gt;http://www.microsoft.com/&lt;wbr&gt;protect/fraud/passwords/&lt;wbr&gt;checker.aspx&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;iPass Tool (best password will be highlighted in green)&lt;br /&gt;&lt;a href="http://sunrise.webfactional.com/ipass" target="_blank"&gt;http://sunrise.webfactional.&lt;wbr&gt;com/ipass&lt;/a&gt;&lt;a href="http://sunrise.webfactional.com/ipass" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-7426217240751974768?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/7426217240751974768/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=7426217240751974768' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/7426217240751974768'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/7426217240751974768'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/09/survey-about-using-good-passwords.html' title='Survey about Using Good Passwords (asking for your 2 minutes)'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-7127396454023684976</id><published>2009-09-15T18:31:00.000-07:00</published><updated>2009-09-15T18:36:34.683-07:00</updated><title type='text'>...and another PHISHING attempt</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_V2r5qe9ns7M/SrBASr1oBiI/AAAAAAAABMc/5H9qgA6skvs/s1600-h/bsnl.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 194px;" src="http://1.bp.blogspot.com/_V2r5qe9ns7M/SrBASr1oBiI/AAAAAAAABMc/5H9qgA6skvs/s320/bsnl.JPG" alt="" id="BLOGGER_PHOTO_ID_5381872244457211426" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;"bsnl" is an internet service provider in India. These crawlers are getting smarter..but phishing is still phishing!&lt;br /&gt;&lt;br /&gt;I like the warning message:&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"...&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;you are required to do this before the next 48hrs of receipt of this e-mail, or your Web mail Account will be de-activated and erased from our database." &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Thank you very much -- I would be happy if you delete me from the "phishing database" :)&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-7127396454023684976?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/7127396454023684976/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=7127396454023684976' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/7127396454023684976'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/7127396454023684976'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/09/and-another-phishing-attempt.html' title='...and another PHISHING attempt'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_V2r5qe9ns7M/SrBASr1oBiI/AAAAAAAABMc/5H9qgA6skvs/s72-c/bsnl.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-9030644751154682341</id><published>2009-09-10T11:53:00.000-07:00</published><updated>2009-09-10T12:09:33.016-07:00</updated><title type='text'>DGTFX Virus Alert  (yeah sure, ..it is an email phishing scam!)</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_V2r5qe9ns7M/SqlLkNCg9cI/AAAAAAAABMU/oULMHiKKLW8/s1600-h/scam.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 194px;" src="http://4.bp.blogspot.com/_V2r5qe9ns7M/SqlLkNCg9cI/AAAAAAAABMU/oULMHiKKLW8/s320/scam.JPG" alt="" id="BLOGGER_PHOTO_ID_5379914315218351554" border="0" /&gt;&lt;/a&gt;Received this in my INBOX today. It is a phishing scam obviously..actually -- it not that "obvious" since the email looks pretty legitimate at first examination. But the scammers forgot that I teach IT security courses here ..oops, so it is no use messing with the wrong guy :) Anyway -- be careful guys.&lt;br /&gt;&lt;br /&gt;Good idea to alert your IT department, or consult a security alert focus group if you have any doubts. As the good man says "better safe, than sorry". Peace.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-9030644751154682341?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/9030644751154682341/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=9030644751154682341' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/9030644751154682341'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/9030644751154682341'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/09/dftfx-virus-alert-yeah-sure-it-is-email.html' title='DGTFX Virus Alert  (yeah sure, ..it is an email phishing scam!)'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_V2r5qe9ns7M/SqlLkNCg9cI/AAAAAAAABMU/oULMHiKKLW8/s72-c/scam.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-780631385386110957</id><published>2009-09-07T11:12:00.001-07:00</published><updated>2009-09-07T11:35:25.882-07:00</updated><title type='text'>"Digital Life" after Death?</title><content type='html'>&lt;span&gt;Seems like an irrelevant discussion at first thought, ha? No, I thought the same..while I was browsing through the &lt;a href="http://www.time.com/time/business/article/0,8599,1916317,00.html"&gt;September 14, 2009 issue of the TIME magazine&lt;/a&gt;. But the article "Managing your Online Afterlife" caught my attention after reading a few paragraphs.&lt;br /&gt;&lt;br /&gt;So, what happens all the digital data floating around the WWW after you die? Apparently, major companies do have some security policies now to give access to information or emails exchanged by loved ones. Facebook, MySpace, Google, Yahoo! all have a policy of their own.&lt;br /&gt;&lt;br /&gt;I found this article particularly interesting because it shows how important we (or relatives of loved one)  consider any kind of digital information. If it was of no value -- no one would fight for it. In my opinion, yes, there is a lot of "precious" - social, personal, emotional, and intellectual information out there ..stored on data servers quietly clocking away in a dark server room.&lt;br /&gt;&lt;br /&gt;As the author points out ..soon we might see a clause in someone's Will that tells -- how and who can access, and share information in my "after life".&lt;br /&gt;&lt;br /&gt;Humm. Do I need to start using my dairy again?&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-780631385386110957?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/780631385386110957/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=780631385386110957' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/780631385386110957'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/780631385386110957'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/09/digital-life-after-death.html' title='&quot;Digital Life&quot; after Death?'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-8609895918129174525</id><published>2009-08-31T21:59:00.001-07:00</published><updated>2009-08-31T22:11:43.970-07:00</updated><title type='text'>LOOKUP</title><content type='html'>We can't imagine our lives without the Internet these days -- but hey, as they say..every story has 2 sides! Consider for example how easy it is for someone who wants to look you up (and possibly stock you, for whatever the reason) :)  Gone are the days when you wanted to elope..and be in hiding for a few years.&lt;br /&gt;&lt;br /&gt;There might be more services out there, but here is one that I ran into &lt;a href="http://www.lookupanyone.com/"&gt;LookupAnyone.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Oh come on..why do state/federal offices or other collecting agencies even sell their data to such websites! Why? What happened to privacy of citizens? I agree criminal and background checks are need when necessary -- but these can be done by offices specially delegated to do this. Why make the data 'public'? There is cost of course...seems like it is all about the money, at someone else's mercy.&lt;br /&gt;&lt;br /&gt;Anyway -- if I ever move, or when I move..you know how to find me. :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-8609895918129174525?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/8609895918129174525/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=8609895918129174525' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/8609895918129174525'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/8609895918129174525'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/08/lookup.html' title='LOOKUP'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-6163920192840590147</id><published>2009-08-27T07:33:00.001-07:00</published><updated>2009-08-27T15:50:31.924-07:00</updated><title type='text'>Fake faces ..real Identity?</title><content type='html'>..and you thought that ID theft due to "dumpster diving" was a problem. Check out the look-alikes that resemble some famous people. I ran into this website:&lt;br /&gt;&lt;a href="http://www.fakefaces.co.uk/"&gt;http://www.fakefaces.co.uk/&lt;/a&gt; recently that claims to have celebrity look-alikes. &lt;br /&gt;&lt;br /&gt;Assuming that the images are not-morphed (which also is a possibility), the resemblance is pretty striking. Think what would happen if Mr. Beckham, or Mr. Austin Powers would walk into a Thailand resort for a vacation. VIP service?&lt;br /&gt;&lt;br /&gt;Well..I wonder if there is a look-alike that exists for every one of us -- not just celebrities. Oh yes, I learned a new word too. Apparently, a person who is a look-alike, but not related to you is called a &lt;b&gt;"Doppelgänger"&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;Need a friend -- a bio or genetics scientists to tell me how close a match can ever get? Spooky.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-6163920192840590147?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/6163920192840590147/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=6163920192840590147' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/6163920192840590147'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/6163920192840590147'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/08/fake-faces-realy-identity.html' title='Fake faces ..real Identity?'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-3629354734628526270</id><published>2009-08-11T18:31:00.000-07:00</published><updated>2009-08-11T18:51:33.000-07:00</updated><title type='text'>Tweet Tweet</title><content type='html'>You think &lt;a href="http://www.blogger.com/www.faceboook.com"&gt;Facebook&lt;/a&gt; is intrusive? ..Checkout &lt;a href="http://www.blogger.com/post-create.g?blogID=2987896066309092616" com=""&gt;Twitter&lt;/a&gt;. I know Twitter started in 2006, but has been big only since the recent 1-2 years. There are pros and cons to such information (or status) broadcasts of course. Plus side -- you can be a social animal (only connected to the virtual world). The down side -- what about privacy? and what happened to the good old fashion in-person talk -- or even healthy gossip? :)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.myfoxboston.com/dpp/news/local/042409_Twitter_Time"&gt;Here&lt;/a&gt; is a newscast where BU professor Azer Bestavros was recently interviewed. Nice discussion. By the way, President Obama also tweets.&lt;br /&gt;&lt;br /&gt;My question is: How much should we tweet, but still enjoy the in-person experiences that usually become lasting memories?&lt;br /&gt;&lt;br /&gt;P.S: I am not on Twitter. Will tweet for __ (not sure yet)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-3629354734628526270?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/3629354734628526270/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=3629354734628526270' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/3629354734628526270'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/3629354734628526270'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/08/tweet-tweet.html' title='Tweet Tweet'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-510618288789673524</id><published>2009-08-07T12:26:00.000-07:00</published><updated>2009-08-07T12:33:24.596-07:00</updated><title type='text'>Data loss incidents -- Web portal</title><content type='html'>&lt;a href="http://datalossdb.org/"&gt;DataLossDB&lt;/a&gt; -- a comprehensive website that documents data loss incidents that happen world-wide. The implications of data loss are severe of course, but knowing about such incidents is good too. TJX case with 94,000,000 records compromised holds the record so far.&lt;br /&gt;&lt;br /&gt;From the website:&lt;br /&gt;&lt;span style="font-style: italic; color: rgb(153, 51, 0);font-size:85%;" &gt;"DataLossDB is a research project aimed at documenting known and reported  data loss incidents world-wide. The effort is now a community one, and  with the move to Open Security Foundation's DataLossDB.org, asks for  contributions of new incidents and new data for existing incidents.  For  any questions about this site or the data contained within the site,  please contact &lt;a href="mailto:curators@datalossdb.org"&gt;curators@datalossdb.org&lt;/a&gt;"                     &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-510618288789673524?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/510618288789673524/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=510618288789673524' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/510618288789673524'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/510618288789673524'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/08/data-loss-incidents-web-portal.html' title='Data loss incidents -- Web portal'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-1140084231681172768</id><published>2009-08-05T08:50:00.000-07:00</published><updated>2009-08-05T09:05:53.108-07:00</updated><title type='text'>Da Vinci and Fibonacci</title><content type='html'>I just finished reading the novel &lt;a href="http://www.amazon.com/Da-Vinci-Code-Dan-Brown/dp/0385504209"&gt;"The Da Vinci Code"&lt;/a&gt; by Dan Brown. Leaving the controversies surrounding the books aside, I was intrigued by the use of Fibonacci numbers as a password, or crypt.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Fibonacci_number"&gt;Fibonacci numbers&lt;/a&gt; as you are from the sequence: 0, 1, 1, 2, 3, 5, 8, 13, 21, 34, ...&lt;br /&gt;&lt;br /&gt;One could start with one of the numbers in the sequence, and use the rest of sequence (with minor modifications that are easy to remember) as a password. Brilliant -  Jacques Saunière!  Well, actually brilliant Leonardo of Pisa. I just learned that the Fibonacci sequence is named after Leonardo of Pisa, who was known as Fibonacci (a contraction of filius Bonaccio, "son of Bonaccio".)&lt;br /&gt;&lt;br /&gt;If my password or PIN were: 131722  ...can you guess how I derived it?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-1140084231681172768?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/1140084231681172768/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=1140084231681172768' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/1140084231681172768'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/1140084231681172768'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/08/da-vinci-and-fibonacci.html' title='Da Vinci and Fibonacci'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-4051250962388317984</id><published>2009-08-05T07:21:00.000-07:00</published><updated>2009-08-05T07:29:36.393-07:00</updated><title type='text'>Authentication (I am who I am)</title><content type='html'>There are a plenty of ways to authenticating (proving that you are YOU) in this world. In everyday life we are asked to authenticate ourselves by showing an ID, typing a password, finger print, etc.&lt;br /&gt;&lt;br /&gt;Someone recently recently asked me:&lt;br /&gt;&lt;span style="color: rgb(0, 0, 153);"&gt;What is most secure form of authentication or to establish one's identity?&lt;/span&gt; &lt;br&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 153);"&gt;a)  one based on what you are&lt;/span&gt; &lt;br&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 153);"&gt;b)  one based on what you can do&lt;/span&gt; &lt;br&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 153);"&gt;c)  one based on what you know&lt;/span&gt; &lt;br&gt;&lt;br /&gt;&lt;br /&gt;Tricky!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-4051250962388317984?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/4051250962388317984/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=4051250962388317984' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/4051250962388317984'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/4051250962388317984'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/08/authentication-i-am-who-i-am.html' title='Authentication (I am who I am)'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-5771719464647585158</id><published>2009-08-02T13:13:00.000-07:00</published><updated>2009-08-17T09:05:14.166-07:00</updated><title type='text'>Paper published at SEKE 2009</title><content type='html'>&lt;span style="font-size:100%;"&gt;My paper titled "&lt;/span&gt;&lt;span style="font-family:Arial,Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://people.bu.edu/kulkarni/pub.htm"&gt;iPass: An Integrated Framework for Educating, Monitoring and Enforcing Password Policies for Online Services&lt;/a&gt;" was accepted at the 21st International Conference on Software Engineering and Knowledge Engineering (SEKE 2009), Boston, USA, July 2009.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-5771719464647585158?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/5771719464647585158/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=5771719464647585158' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/5771719464647585158'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/5771719464647585158'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/08/paper-published-at-seke-2009.html' title='Paper published at SEKE 2009'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-5053711803365257379</id><published>2009-08-02T13:00:00.000-07:00</published><updated>2009-08-02T13:07:40.661-07:00</updated><title type='text'>Creating your own security lab</title><content type='html'>Here is book on how you can create, set-up and practice + develop solutions.&lt;br /&gt;&lt;a href="http://www.amazon.com/Build-Your-Own-Security-Lab/dp/0470179864/ref=sr_1_1?ie=UTF8&amp;amp;qid=1249243438&amp;amp;sr=8-1"&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.amazon.com/Build-Your-Own-Security-Lab/dp/0470179864/ref=sr_1_1?ie=UTF8&amp;amp;qid=1249243438&amp;amp;sr=8-1"&gt;Build Your Own Security Lab: A Field Guide for Network Testing (Paperback)&lt;/a&gt;&lt;br /&gt;By Michael Gregg&lt;br /&gt;&lt;br /&gt;I am in the process of develop some exercises, labs for my students -- let me know if you have any experiences :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-5053711803365257379?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/5053711803365257379/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=5053711803365257379' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/5053711803365257379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/5053711803365257379'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/08/creating-your-own-security-lab.html' title='Creating your own security lab'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-8446079357339479045</id><published>2009-05-05T09:08:00.000-07:00</published><updated>2009-05-05T09:12:26.746-07:00</updated><title type='text'>CS conference rankings</title><content type='html'>..ran into this site that maintains the rankings of the top computer science conferences. Check here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cs-conference-ranking.org/conferencerankings.html"&gt;CS Conference rankings&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;the website claims that they update the ranking every 3 months, so use your discretion if you are really worried about which conference to submit your paper -- obviously every paper counts! :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-8446079357339479045?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/8446079357339479045/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=8446079357339479045' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/8446079357339479045'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/8446079357339479045'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/05/cs-conference-rankings.html' title='CS conference rankings'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-8070168429423869269</id><published>2009-04-13T09:46:00.000-07:00</published><updated>2009-04-13T09:50:13.548-07:00</updated><title type='text'>Strong passwords - what? ...Take a survey</title><content type='html'>I am requesting you to participate in small survey for a project I am doing on -- understanding user perception, usage, and techniques for "strong passwords". Thanks. Click link below.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://spreadsheets.google.com/viewform?formkey=cGV2eURVSnRsVjNGa20xc2RNcU9qSEE6MA.."&gt;Password Policy Survey&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It would take less than 1 minute, and hey -- this will not be used to hack into your system -- don't worry :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-8070168429423869269?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/8070168429423869269/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=8070168429423869269' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/8070168429423869269'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/8070168429423869269'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/04/strong-passwords-what-take-survey.html' title='Strong passwords - what? ...Take a survey'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-5925975259406579471</id><published>2009-03-05T19:41:00.000-08:00</published><updated>2009-03-05T19:54:26.100-08:00</updated><title type='text'>Privacy in a Public world...of facebook</title><content type='html'>Just ask around in your class or your office who is not on facebook or orkut or myspace or whatever your favorite WWW "space"...doubt if many will raise their hands. Well, with information floating around in the public world of FB, and the web in general -- there is not much you can do to hide, but there is some help...some help that will help keep your information more private to the circle of friends, and less public to the 'public'.&lt;br /&gt;&lt;br /&gt;I ran into this neat article on how to use the security settings in Facebook -- worth reading, and surely worth configuring your profile accordingly: More here:&lt;br /&gt;&lt;a href="http://www.allfacebook.com/2009/02/facebook-privacy/"&gt;http://www.allfacebook.com/2009/02/facebook-privacy/&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;Rule of thumb: "Don't post anything that might embarrass/hurt/annoy/tick-off  yourself or someone you may know" :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-5925975259406579471?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/5925975259406579471/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=5925975259406579471' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/5925975259406579471'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/5925975259406579471'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/03/privacy-in-public-worldof-facebook.html' title='Privacy in a Public world...of facebook'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-7816464121072935662</id><published>2009-03-03T20:51:00.000-08:00</published><updated>2009-03-03T20:58:45.584-08:00</updated><title type='text'>security vs. usability</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_V2r5qe9ns7M/Sa4JpOkL9SI/AAAAAAAABG8/DHhLptLWip8/s1600-h/Picture1.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 320px; height: 111px;" src="http://4.bp.blogspot.com/_V2r5qe9ns7M/Sa4JpOkL9SI/AAAAAAAABG8/DHhLptLWip8/s320/Picture1.png" alt="" id="BLOGGER_PHOTO_ID_5309191614605554978" border="0" /&gt;&lt;/a&gt;Information assurance or security is always a balance between:&lt;br /&gt;"Usability" and "the level of Security", Scott Adams sums it up pretty well in this cartoon. Enjoy!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-7816464121072935662?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/7816464121072935662/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=7816464121072935662' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/7816464121072935662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/7816464121072935662'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/03/security-vs-usability.html' title='security vs. usability'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_V2r5qe9ns7M/Sa4JpOkL9SI/AAAAAAAABG8/DHhLptLWip8/s72-c/Picture1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2987896066309092616.post-1448353442255901807</id><published>2009-03-03T18:30:00.000-08:00</published><updated>2009-03-03T18:41:25.086-08:00</updated><title type='text'>Mirror mirror on the wall...which is the strongest password of them all</title><content type='html'>Passwords are the one of the simplest and most easy-to-use forms of providing security. Everyone uses at least 5-6 passwords, some simple, some strong -- have you ever wondered how strong your password is? I can came across this really cool utility (Password Checker)  that checks the strength of your passwords.  Check here:&lt;br /&gt;&lt;a href="http://www.microsoft.com/protect/yourself/password/checker.mspx"&gt;http://www.microsoft.com/protect/yourself/password/checker.mspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Not a bad idea to check the strength here, before you create a new login/password when you enroll for any online service :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2987896066309092616-1448353442255901807?l=cafedefallo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cafedefallo.blogspot.com/feeds/1448353442255901807/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2987896066309092616&amp;postID=1448353442255901807' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/1448353442255901807'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2987896066309092616/posts/default/1448353442255901807'/><link rel='alternate' type='text/html' href='http://cafedefallo.blogspot.com/2009/03/mirror-mirror-on-wallwhich-is-strongest.html' title='Mirror mirror on the wall...which is the strongest password of them all'/><author><name>Dhananjay</name><uri>http://www.blogger.com/profile/01339464714179459102</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://3.bp.blogspot.com/_V2r5qe9ns7M/Sa3su56Y9aI/AAAAAAAABGQ/V1XgwfeDUE4/S220/kulkarni.jpg'/></author><thr:total>0</thr:total></entry></feed>
