<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0" xml:base="http://www.computersecurityworld.com">
<channel>
 <title>Jasmeet Chhabra's blog</title>
 <link>http://www.computersecurityworld.com/blog/jasmeet-chhabra</link>
 <description />
 <language>en</language>
<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/JasmeetChhabrasBlog" type="application/rss+xml" /><item>
 <title>Movie and TV security myth busted: Voice-Print does not exist</title>
 <link>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2009/jan/movie-and-tv-security-myth-busted-voice-print-does-not-exist</link>
 <description>&lt;p&gt;Despite what movies and TV will have you think, there is no such thing as a voiceprint. &lt;a href="http://dsc.discovery.com/news/2008/12/04/voice-print-tech.html"&gt;As per this article on Discovery:&lt;/a&gt; &lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;i&gt;"It's a very very dangerous term. There is no single feature of a voice that is indelible that works like a fingerprint does."&lt;/i&gt;&lt;/p&gt;
&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Despite what some &lt;a href="http://news.zdnet.com/2100-1009_22-144373.html"&gt;companies will have you believe about voice authentication&lt;/a&gt;, it has been shown &lt;a href="http://www.phonelosers.com/pla-radio-episode-17-voice-authentication/"&gt;not to work very well in practice. &lt;/a&gt;&lt;br /&gt;
Also, in case you haven't seen it before, this mythbusters video shows how &lt;a href="http://www.metacafe.com/watch/252534/myth_busters_finger_print_lock/"&gt;fingerprint locks can be easily fooled too.&lt;/a&gt; Not to mention that if you use it for something valuable, &lt;a href="http://news.bbc.co.uk/2/hi/asia-pacific/4396831.stm"&gt;you can lose your finger too.&lt;/a&gt;&lt;br /&gt;
Do you use fingerprint authentication on your laptop? Guess what... you are leaving your fingerprints all over the laptop, making it very easy for a smart thief to reconstruct a fake fingerprint as shown in the Mythbuster's video and get access to all you data and more.&lt;br /&gt;
Biometrics still have a way to go before I start using them.&lt;/p&gt;
</description>
 <comments>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2009/jan/movie-and-tv-security-myth-busted-voice-print-does-not-exist#comments</comments>
 <category domain="http://www.computersecurityworld.com/category/computer-security/biometrics">Biometrics</category>
 <pubDate>Sat, 03 Jan 2009 19:55:00 +0000</pubDate>
 <dc:creator>Jasmeet Chhabra</dc:creator>
 <guid isPermaLink="false">32 at http://www.computersecurityworld.com</guid>
</item>
<item>
 <title>Las Vegas Slot Machines Vs Electronic Voting Machines Security</title>
 <link>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2009/jan/las-vegas-slot-machines-vs-electronic-voting-machines-security</link>
 <description>&lt;p&gt;&lt;a href="http://media3.washingtonpost.com/wp-dyn/content/graphic/2006/03/16/GR2006031600213.gif"&gt;From Washington Post&lt;/a&gt;&lt;br /&gt;
&lt;img src="/csecwfiles/Las-Vegas-Slot-Machines-Vs-Electronic-Voting-Machines-Security.gif" alt="Las Vegas Slot Machines Vs Electronic Voting Machines Security" \&gt;&lt;/p&gt;
</description>
 <comments>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2009/jan/las-vegas-slot-machines-vs-electronic-voting-machines-security#comments</comments>
 <category domain="http://www.computersecurityworld.com/category/computer-security/funny">Funny</category>
 <category domain="http://www.computersecurityworld.com/category/computer-security/ironic">Ironic</category>
 <pubDate>Fri, 02 Jan 2009 20:02:42 +0000</pubDate>
 <dc:creator>Jasmeet Chhabra</dc:creator>
 <guid isPermaLink="false">31 at http://www.computersecurityworld.com</guid>
</item>
<item>
 <title>Your accounts may be in danger if you use same passwords across different websites.  Read on for a solution</title>
 <link>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2008/feb/your-accounts-may-be-danger-if-you-use-same-passwords-across-different</link>
 <description>&lt;p&gt;Do you use the same password across different websites?  Do you know if you do so your passwords may be stolen by the website you signed up with.  So, is there a solution?  The best solution of course is to use a different password at at each website you signed up with.  But for most mere mortals that is not a practical option.  I will tell you what I do.  I use a password generator that generates a unique password for me at each website I sign up with.  The password generator takes a secret pass phrase that I enter and the website's unique URL and cryptographically mixes it to generate a unique password for the website.  It basically uses a cryptographic hash function  to make sure that even if somebody gets access to one of your passwords, your secret passphrase cannot be guessed.  To learn more about why that works, &lt;a href="http://en.wikipedia.org/wiki/Cryptographic_hash_function"&gt; see here&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;To be even more secure I actually have two pass phrases.  I use one pass phrase to generate passwords for all the websites that are related to banking or finance and other for normal websites like Google etc this password generator is actually just a bookmark and is compatible with all browsers.  Here is a link to the &lt;a href="http://supergenpass.com/"&gt;password generator.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Note that when you visit the link you will find that there is also a mobile version of the password generator which is useful when you are working on a machine that is not your own.  This mobile version can be used to generate passwords from a web page form. You can  copy and run this mobile password generator on your own website.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.computersecurityworld.com/blog/jasmeet-chhabra/2008/feb/your-accounts-may-be-danger-if-you-use-same-passwords-across-different"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2008/feb/your-accounts-may-be-danger-if-you-use-same-passwords-across-different#comments</comments>
 <category domain="http://www.computersecurityworld.com/category/computer-security/password-management">password management</category>
 <pubDate>Thu, 21 Feb 2008 04:49:30 +0000</pubDate>
 <dc:creator>Jasmeet Chhabra</dc:creator>
 <guid isPermaLink="false">30 at http://www.computersecurityworld.com</guid>
</item>
<item>
 <title>Are you sure you sanitized the data enough to remove all private information and made it anonymous?</title>
 <link>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2008/jan/are-you-sure-you-sanitized-data-enough-remove-all-private-information-</link>
 <description>&lt;p&gt;In our work as security professionals a lot of time we encounter decisions about what data to reveal or hide due to privacy concerns. I am sure when &lt;a href="http://www.netflixprize.com/"&gt;Netflix decided to release its data as a part of the challenge&lt;/a&gt; to come up with a better recommendation algorithm, it thought that it had sanitized the data enough. But, it seems that &lt;a href="http://www.cs.utexas.edu/~shmat/shmat_netflix-prelim.pdf"&gt;Arvind Narayanan and Vitaly Shmatikov, researchers at the University of Texas at Austin, were &lt;a href="http://www.securityfocus.com/news/11497"&gt;able to extract enough info out of the data&lt;/a&gt; to be able to identify a few sampled users.&lt;/a&gt; More at this &lt;a href="http://www.cs.utexas.edu/~shmat/netflix-faq.html"&gt;faq&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;They used some data mining techniques and &lt;a href="http://www.securityfocus.com/news/11497"&gt;associated the Netflix data with that stored by the user in IMDB. &lt;/a&gt;Since the IMDB data is available publicly and is associated with usernames, they were able to associate the two sets of data and identify which Netlix data belonged to a particular used on IMDB. In effect they removed the anonymity of the Netflix data for that user.&lt;br /&gt;
It makes perfect sense if you realize that with so many choices in this world, our habits are very individual and unique whether they are  movie watching habits, eating habits, buying habits etc.&lt;br /&gt;
So, how do we anonymize the data? By inserting errors, removing random pieces etc. It seems none of that works as very little data is needed to uniquely identify you.&lt;br /&gt;
This quote from &lt;a href="http://www.wired.com/politics/security/commentary/securitymatters/2007/12/securitymatters_1213"&gt;this article&lt;/a&gt; explains it very clearly&lt;br /&gt;
"Other research reaches the same conclusion. Using public anonymous data from the 1990 census, Latanya Sweeney found that 87 percent of the population in the United States, 216 million of 248 million, could likely be uniquely identified by their five-digit ZIP code, combined with their gender and date of birth. About half of the U.S. population is likely identifiable by gender, date of birth and the city, town or municipality in which the person resides. Expanding the geographic scope to an entire county reduces that to a still-significant 18 percent. "In general," the researchers wrote, "few characteristics are needed to uniquely identify a person."&lt;/p&gt;
&lt;p&gt;So in effect as the power of computers and the amount of public data increases, Can we pretty much say goodbye to anonymity? Only the future will tell, but the signs don't look good.  Attacking anonymous data is exactly how we will learn how to defend anonymity. Narayanan and Shmatikov are currently working on developing algorithms and techniques that enable the secure release of anonymous datasets like Netflix's. We need a lot more researchers like them to learn how to do anonymity right.&lt;/p&gt;
</description>
 <comments>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2008/jan/are-you-sure-you-sanitized-data-enough-remove-all-private-information-#comments</comments>
 <category domain="http://www.computersecurityworld.com/category/computer-security/anonymity">anonymity</category>
 <category domain="http://www.computersecurityworld.com/category/computer-security/data-mining">data mining</category>
 <category domain="http://www.computersecurityworld.com/category/computer-security/privacy">privacy</category>
 <pubDate>Wed, 09 Jan 2008 14:45:25 +0000</pubDate>
 <dc:creator>Jasmeet Chhabra</dc:creator>
 <guid isPermaLink="false">28 at http://www.computersecurityworld.com</guid>
</item>
<item>
 <title>When a computer/agent executes a contract who is responsible?</title>
 <link>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2008/jan/when-computeragent-executes-contract-who-responsible</link>
 <description>&lt;p&gt;I just found this article on securityfocus which talks about what are the &lt;a href="http://www.securityfocus.com/columnists/458/2"&gt;legal implications of computers executing operations on your behalf.&lt;/a&gt; Who is responsible if an automated agent buys something on your behalf , or logs on to a website on your behalf by automatically accepting the TOS? As usual technology seems to be moving much faster than the law here. Maybe that is why the book &lt;a href="http://www.amazon.com/gp/redirect.html?ie=UTF8&amp;amp;location=http%3A%2F%2Fwww.amazon.com%2FSovereign-Individual-Mastering-Transition-Information%2Fdp%2F0684832720&amp;amp;tag=compsecuworl-20&amp;amp;linkCode=ur2&amp;amp;camp=1789&amp;amp;creative=9325"&gt;The Sovereign Individual: Mastering the Transition to the Information Age&lt;/a&gt;&lt;img src="http://www.assoc-amazon.com/e/ir?t=compsecuworl-20&amp;amp;l=ur2&amp;amp;o=1" width="1" height="1" border="0" alt="" style="border:none !important; margin:0px !important;" /&gt; says that technology is gong to end the nation state as government's powers are eroded by technology moving too fast for them to control. &lt;/p&gt;
</description>
 <comments>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2008/jan/when-computeragent-executes-contract-who-responsible#comments</comments>
 <category domain="http://www.computersecurityworld.com/category/computer-security/agent">agent</category>
 <category domain="http://www.computersecurityworld.com/category/computer-security/contract">contract</category>
 <category domain="http://www.computersecurityworld.com/category/computer-security/legal">legal</category>
 <category domain="http://www.computersecurityworld.com/category/computer-security/miscellaneous">Miscellaneous</category>
 <pubDate>Wed, 09 Jan 2008 05:31:28 +0000</pubDate>
 <dc:creator>Jasmeet Chhabra</dc:creator>
 <guid isPermaLink="false">27 at http://www.computersecurityworld.com</guid>
</item>
<item>
 <title>Why I like Firefox</title>
 <link>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2008/jan/why-i-firefox</link>
 <description>&lt;p&gt;I love &lt;A href="www.mozilla.com/firefox/"&gt; Firefox&lt;/a&gt; and besides the standard reasons of it being faster, better interface etc., the main reason I love firefox is because of their addons. As an example some of the security related addons that I have on my firefox browser are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/573"&gt;Add N Edit cookies: &lt;/a&gt;&lt;/b&gt;  Allows me to edit any cookie. A great took for hacking the cookies that are stored by a website.
&lt;li&gt;&lt;b&gt; &lt;a href="http://noscript.net/"&gt;No Script: &lt;/a&gt;&lt;/b&gt; This is the greatest Firefox extension in terms of improving the security. It gives awesome amount of control over which websites are allowed to run scripts in a browser and even prevents some XSS attacks.
&lt;li&gt;&lt;b&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/966"&gt;Tamper Data:&lt;/a&gt; &lt;/b&gt;Allows you to view and modify HTTP/HTTPS headers and post parameters. Great hacking tool!
&lt;/ul&gt;
</description>
 <comments>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2008/jan/why-i-firefox#comments</comments>
 <category domain="http://www.computersecurityworld.com/category/computer-security/firefox">firefox</category>
 <category domain="http://www.computersecurityworld.com/category/computer-security/miscellaneous">Miscellaneous</category>
 <pubDate>Tue, 08 Jan 2008 05:14:19 +0000</pubDate>
 <dc:creator>Jasmeet Chhabra</dc:creator>
 <guid isPermaLink="false">26 at http://www.computersecurityworld.com</guid>
</item>
<item>
 <title>How good is iViz Tech's technology?</title>
 <link>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2008/jan/how-good-iviz-techs-technology</link>
 <description>&lt;p&gt;Found this &lt;a href="http://www.redherring.com/Home/23401"&gt; this  Red Herring article &lt;/a&gt; from &lt;a href="http://blogs.inspions.net/2008/01/05/iviz-tech-solutions-ai-based-hacking-on-demand/"&gt; this blog&lt;/a&gt;. The article claims that technology by the startup &lt;a href="http://www.ivizindia.com/iviz/"&gt; iViz Tech&lt;/a&gt; in India "Aims to Put Hackers Out of Work".  The Red Herring article is a little light on details, so I looked through there website. They claim to use "Emulation of Human Intelligence" to simulate attack the way a real hacker would. It probably is more like expert systems because simulating a real human hacker at any reasonable level is currently not possible. This implies that although it would be possible for it to find new attacks, it would probably be impossible for it to find a totally new class of attacks. Also, there are other penetration testing companies which use AI techniques for penetration testing like &lt;a href="http://www.rapid7.com/nexpose/architecture.jsp"&gt;Rapid7&lt;/a&gt;. So, what is new? Not very clear from the description on there website. If you know let me know. Also, I think that the "Putting Hackers out of work" is just a headline grabbing bait as current state of AI does not allow us to do that. It may make penetration tester's job much easier though.&lt;br /&gt;
&lt;b&gt; Update:&lt;/b&gt; Found another company which offers Artificial Intelligence based penetration testing tools: &lt;a href="http://www.procheckup.com/"&gt;Procheckup&lt;/a&gt;&lt;br /&gt;
P.S.&lt;br /&gt;
Artificial Intelligence" for security attacks has also been previous employed in the  technique of fuzzing used by some security researchers to find an &lt;a href="http://www.itbusinessedge.com/item/?ci=18762"&gt;exploit a day for a month&lt;/a&gt; in different browsers. &lt;a href="http://blog.itproportal.com/?p=208"&gt;Hackers are beginning to employ fuzzing/AI too&lt;/a&gt;&lt;/p&gt;
</description>
 <comments>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2008/jan/how-good-iviz-techs-technology#comments</comments>
 <category domain="http://www.computersecurityworld.com/category/computer-security/artificial-intelligence">Artificial Intelligence</category>
 <category domain="http://www.computersecurityworld.com/category/computer-security/penetration-testing">Penetration testing</category>
 <category domain="http://www.computersecurityworld.com/category/computer-security/startup">Startup</category>
 <category domain="http://www.computersecurityworld.com/category/computer-security/startup-watch">Startup Watch</category>
 <pubDate>Mon, 07 Jan 2008 03:38:31 +0000</pubDate>
 <dc:creator>Jasmeet Chhabra</dc:creator>
 <guid isPermaLink="false">21 at http://www.computersecurityworld.com</guid>
</item>
<item>
 <title>Created Web Application Security resource list</title>
 <link>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2007/dec/created-web-application-security-resource-list</link>
 <description>&lt;p&gt;&lt;a href="http://www.computersecurityworld.com/content/computer-security/tutorials/web-application-security-meta-resource-list-tutorials-cheat-shee"&gt; I just Created this Web Application Security resource list. &lt;/a&gt;I hope to maintain this and make it more useful as I find more links.&lt;/p&gt;
</description>
 <comments>http://www.computersecurityworld.com/blog/jasmeet-chhabra/2007/dec/created-web-application-security-resource-list#comments</comments>
 <category domain="http://www.computersecurityworld.com/category/computer-security/web-application">Web Application</category>
 <pubDate>Tue, 01 Jan 2008 03:44:23 +0000</pubDate>
 <dc:creator>Jasmeet Chhabra</dc:creator>
 <guid isPermaLink="false">12 at http://www.computersecurityworld.com</guid>
</item>
<item>
 <title>Computer Security World First Post</title>
 <link>http://www.computersecurityworld.com/blog/jasmeet-chhabra/miscellaneous/2007/mar/computer-security-world-first-post</link>
 <description>&lt;p&gt;This is my first post. I will try to put information, news and comments on different security and cryptography aspects including Tutorials, Howtos, reviews etc. Basically, anything that catches my fancy in the area of security and cryptography. &lt;/p&gt;
</description>
 <comments>http://www.computersecurityworld.com/blog/jasmeet-chhabra/miscellaneous/2007/mar/computer-security-world-first-post#comments</comments>
 <category domain="http://www.computersecurityworld.com/category/computer-security/miscellaneous">Miscellaneous</category>
 <pubDate>Sun, 04 Mar 2007 02:54:32 +0000</pubDate>
 <dc:creator>Jasmeet Chhabra</dc:creator>
 <guid isPermaLink="false">1 at http://www.computersecurityworld.com</guid>
</item>
</channel>
</rss>
