<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Jan Rochat's Weblog</title>
	<atom:link href="http://janrochat.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://janrochat.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Tue, 08 Jan 2008 19:00:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='janrochat.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Jan Rochat's Weblog</title>
		<link>http://janrochat.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://janrochat.wordpress.com/osd.xml" title="Jan Rochat&#039;s Weblog" />
	<atom:link rel='hub' href='http://janrochat.wordpress.com/?pushpress=hub'/>
		<item>
		<title>PKI Smart Cards only a security tool ?</title>
		<link>http://janrochat.wordpress.com/2008/01/05/pki-smart-cards-only-a-security-tool/</link>
		<comments>http://janrochat.wordpress.com/2008/01/05/pki-smart-cards-only-a-security-tool/#comments</comments>
		<pubDate>Sat, 05 Jan 2008 11:11:50 +0000</pubDate>
		<dc:creator>janrochat</dc:creator>
				<category><![CDATA[Digital Idenity]]></category>
		<category><![CDATA[pki]]></category>
		<category><![CDATA[Public Key Infrastructuur]]></category>
		<category><![CDATA[Public Key Technology]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[safesign]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Smart Card]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[pki Security]]></category>
		<category><![CDATA[RSA Digital Identity]]></category>

		<guid isPermaLink="false">http://janrochat.wordpress.com/2008/01/05/pki-smart-cards-only-a-security-tool/</guid>
		<description><![CDATA[Most of the time when I explain to people that I sell middleware for PKI Smart Cards They assume that I am strictly in the security business. The big question; is this a fact or are there other usages for PKI Smart Cards or to generalize the concept PKI tokens. &#160; PK(I) Tokens First of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janrochat.wordpress.com&amp;blog=2163116&amp;post=11&amp;subd=janrochat&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal">Most of the time when I explain to people that I sell middleware for PKI Smart Cards They assume that I am strictly in the security business. The big question; is this a fact or are there other usages for PKI Smart Cards or to generalize the concept PKI tokens.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"><b>PK(I) Tokens</b></p>
<p class="MsoNormal">First of all we most of the time address those (mostly) RSA based tokens as PKI Tokens. Better would be to address them  as Public Key Technology Tokens or RSA Tokens. Calling it PKI Tokens gives the impression that they only can be used in combination with a Public Key Infrastructure, all though those tokens are most of the time used in combination with a Public Key Infrastructure there may also be applications that use the PKI Token  strictly for holding a RSA Key Pair without the certificate.<span> </span></p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"><b>So what about the security bit ?</b></p>
<p class="MsoNormal">Back to the main question. When addressing the tokens as Public Key Technology token it becomes clear that we talk about a technology. As I believe that technology should always support he business we have to look at the business side of things to find an answer on the big question.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"><b>The business side of things</b></p>
<p class="MsoNormal">When looking to the business side we don’t talk about issues like: “I want that all my users have Strong Digital Identity”. We talk about: “I want to increase my turn over” or “I want to cut down my cost”. If we start looking to it from the business angle it is not that difficult to discover a business case for PKI Tokens.<span> </span>An example might be giving all your customers a token to give them access to your website to cut down cost.  Another example; you can give all your employees a token which is protected by a fingerprint so that you cut down cost on resetting passwords.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"><b>So…</b></p>
<p class="MsoNormal">Security is only one of the driving forces behind the use of PKI Tokens like smart cards. We are talking about a technology that has to serve the business and can be used in many different business applications as a technology providing you with a complete set of standards, protocols and implementations laying around to be used to solve your business problem.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"><b>And….</b></p>
<p class="MsoNormal">Well now it is up to you to come up with the business problems and the opportunities that can be solved by using this technology.</p>
<p class="MsoNormal">&nbsp;</p>
<div style="text-align:center;"><img src="http://www.janrochat.com/images/smartcard1.gif" alt="SafeSign" height="323" width="216" /></div>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"><span></span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/janrochat.wordpress.com/11/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/janrochat.wordpress.com/11/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/janrochat.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/janrochat.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/janrochat.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/janrochat.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/janrochat.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/janrochat.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/janrochat.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/janrochat.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/janrochat.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/janrochat.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/janrochat.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/janrochat.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/janrochat.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/janrochat.wordpress.com/11/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janrochat.wordpress.com&amp;blog=2163116&amp;post=11&amp;subd=janrochat&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://janrochat.wordpress.com/2008/01/05/pki-smart-cards-only-a-security-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a35d0d4a378b44efe4878e2c62f97e1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">janrochat</media:title>
		</media:content>

		<media:content url="http://www.janrochat.com/images/smartcard1.gif" medium="image">
			<media:title type="html">SafeSign</media:title>
		</media:content>
	</item>
		<item>
		<title>iGoogle Web Gadgets</title>
		<link>http://janrochat.wordpress.com/2008/01/02/igoogle-web-gadgets/</link>
		<comments>http://janrochat.wordpress.com/2008/01/02/igoogle-web-gadgets/#comments</comments>
		<pubDate>Wed, 02 Jan 2008 19:36:38 +0000</pubDate>
		<dc:creator>janrochat</dc:creator>
				<category><![CDATA[gadget]]></category>
		<category><![CDATA[game]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[igoogle]]></category>
		<category><![CDATA[live]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[webgadget]]></category>

		<guid isPermaLink="false">http://janrochat.wordpress.com/2008/01/02/igoogle-web-gadgets/</guid>
		<description><![CDATA[The last few days I discovered Gadgets. I started playing around with the new system from Microsoft Live. It took a couple of hours before I found out that this nice feature also exist on other web sites. Implementing Gadgets gives you the possibility to add &#8220;little&#8221; apps to a web page. An example of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janrochat.wordpress.com&amp;blog=2163116&amp;post=10&amp;subd=janrochat&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The last few days I discovered Gadgets. I started playing around with the new system from Microsoft Live. It took a couple of hours before I found out that this nice feature also exist on other web sites. Implementing Gadgets gives you the possibility to add &#8220;little&#8221; apps to a web page. An example of this is customizing the normal Google search page by using <a href="http://www.igoogle.com" title="iGoogle" target="_blank">igoogle </a>. I started with building a Gadget wrapping a flash implementation of the classic PacMan game. If you want to add this Gadget on you web page <a href="http://gmodules.com/ig/creator?url=http://www.janrochat.com/pacman/pacman.xml&amp;synd=open&amp;w=400&amp;h=460&amp;title=PacMan&amp;border=%23ffffff%7C3px%2C1px+solid+%23999999" title="PacMan Gadget" target="_blank">look at this page</a>.</p>
<div style="text-align:center;"><img src="http://www.janrochat.com/pacman/pacman.png" alt="The PacMan game" height="325" width="274" /></div>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/janrochat.wordpress.com/10/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/janrochat.wordpress.com/10/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/janrochat.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/janrochat.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/janrochat.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/janrochat.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/janrochat.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/janrochat.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/janrochat.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/janrochat.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/janrochat.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/janrochat.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/janrochat.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/janrochat.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/janrochat.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/janrochat.wordpress.com/10/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janrochat.wordpress.com&amp;blog=2163116&amp;post=10&amp;subd=janrochat&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://janrochat.wordpress.com/2008/01/02/igoogle-web-gadgets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a35d0d4a378b44efe4878e2c62f97e1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">janrochat</media:title>
		</media:content>

		<media:content url="http://www.janrochat.com/pacman/pacman.png" medium="image">
			<media:title type="html">The PacMan game</media:title>
		</media:content>
	</item>
		<item>
		<title>Firefox Susceptible To QuickTime Security Flaw, what about Second Life Client ?</title>
		<link>http://janrochat.wordpress.com/2007/11/28/firefox-susceptible-to-quicktime-security-flaw-what-about-second-life-client/</link>
		<comments>http://janrochat.wordpress.com/2007/11/28/firefox-susceptible-to-quicktime-security-flaw-what-about-second-life-client/#comments</comments>
		<pubDate>Wed, 28 Nov 2007 09:24:24 +0000</pubDate>
		<dc:creator>janrochat</dc:creator>
				<category><![CDATA[Second Life]]></category>
		<category><![CDATA[secondlife]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://janrochat.wordpress.com/2007/11/28/firefox-susceptible-to-quicktime-security-flaw-what-about-second-life-client/</guid>
		<description><![CDATA[Yesterday I saw the following on Slashdot.org : Apple&#8217;s QuickTime media player software contains a previously undocumented security weakness in the way QuickTime handles the RTSP media-streaming protocol. The vulnerability is present in QuickTime versions 4.0 through 7.3 (the latest version) on both Windows and Mac systems. Symantec has tested the publicly available exploit code [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janrochat.wordpress.com&amp;blog=2163116&amp;post=7&amp;subd=janrochat&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Yesterday I saw the following on <a href="http://it.slashdot.org/it/07/11/27/1851212.shtml" title="Slashdot.org">Slashdot.org</a> :</p>
<blockquote><p> <em>Apple&#8217;s QuickTime media player software contains a <a href="http://blog.washingtonpost.com/securityfix/2007/11/exploit_released_for_unpatched_3.html">previously undocumented security weakness</a> in the way QuickTime handles the RTSP media-streaming protocol. The vulnerability is present in QuickTime versions 4.0 through 7.3 (the latest version) on both Windows and Mac systems. Symantec has tested the publicly available exploit code and found that it failed to work properly against Internet Explorer 6/7 or Safari 3 Beta but the exploit works against Firefox if users have chosen QuickTime as the default player for multimedia formats. Firefox users are more susceptible to this attack because <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/11/0day_exploit_for_apple_quickti.html">Firefox farms off the request directly to the QuickTime Player</a> as a separate process outside of its control, while IE loads the QuickTime Player as an internal plugin and when the overflow occurs, standard buffer-overflow protection is triggered, shutting down the affected processes before any damage can occur.&#8221;</em></p></blockquote>
<p>And I realized that the Second Life Client is also using QuickTime. A simple test produced the following picture when applied on the windows version of the Second Life Client. So it seems that Second Life Client is also suffering from the same problem as Firefox does.</p>
<p><a href="http://janrochat.files.wordpress.com/2007/11/slcrash.jpg" title="slcrash.jpg"></a></p>
<p style="text-align:center;"><a href="http://janrochat.files.wordpress.com/2007/11/slcrash.jpg" title="slcrash.jpg"><img src="http://janrochat.files.wordpress.com/2007/11/slcrash.jpg?w=468" alt="slcrash.jpg" /></a></p>
<p>At the moment I only had time to try it on Windows and I have no idea if the same problem exists on the Mac.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/janrochat.wordpress.com/7/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/janrochat.wordpress.com/7/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/janrochat.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/janrochat.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/janrochat.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/janrochat.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/janrochat.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/janrochat.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/janrochat.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/janrochat.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/janrochat.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/janrochat.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/janrochat.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/janrochat.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/janrochat.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/janrochat.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=janrochat.wordpress.com&amp;blog=2163116&amp;post=7&amp;subd=janrochat&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://janrochat.wordpress.com/2007/11/28/firefox-susceptible-to-quicktime-security-flaw-what-about-second-life-client/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a35d0d4a378b44efe4878e2c62f97e1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">janrochat</media:title>
		</media:content>

		<media:content url="http://janrochat.files.wordpress.com/2007/11/slcrash.jpg" medium="image">
			<media:title type="html">slcrash.jpg</media:title>
		</media:content>
	</item>
	</channel>
</rss>
