<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>/dev/otmar</title>
	<atom:link href="http://lendl.priv.at/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://lendl.priv.at/blog</link>
	<description>... as if the Internet needed another blog.</description>
	<pubDate>Mon, 30 Jan 2012 11:58:59 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>Links</title>
		<link>http://lendl.priv.at/blog/2012/01/30/links/</link>
		<comments>http://lendl.priv.at/blog/2012/01/30/links/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 11:58:59 +0000</pubDate>
		<dc:creator>otmar</dc:creator>
		
		<category><![CDATA[Internet]]></category>

		<guid isPermaLink="false">http://lendl.priv.at/blog/?p=309</guid>
		<description><![CDATA[I&#8217;ve too many Tabs open in Firefox. But instead of bookmarking them (where they will rot forever) I&#8217;ll post them here to compost in the blogsphere so that they might provide nutrition to others.
Top Five Regrets of the Dying
Rogue Sites
Attack Patterns
Project Wombat
APT Mitigation
APT Domains
Wütende Nerds
ACTA Rapporteur
JavaScriptMVC Getting Started
Origin ASN for Anycasting
SSL DOS Attacks (also here)
Google [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve too many Tabs open in Firefox. But instead of bookmarking them (where they will rot forever) I&#8217;ll post them here to compost in the blogsphere so that they might provide nutrition to others.</p>
<p><a href="http://beyondtheopposites.com/2011/11/22/top-five-regrets-of-the-dying/">Top Five Regrets of the Dying</a></p>
<p><a href="http://www.techdirt.com/articles/20111130/02093116930/step-step-debunking-us-chamber-commerces-dishonest-stats-about-rogue-sites.shtml">Rogue Sites</a></p>
<p><a href="http://www.esecurityplanet.com/network-security/finding-attack-patterns-in-the-digital-crime-scene.html">Attack Patterns</a></p>
<p><a href="http://wombat-project.eu/">Project Wombat</a></p>
<p><a href="http://www.publicsafety.gc.ca/prg/em/ccirc/2011/tr11-002-eng.aspx">APT Mitigation</a></p>
<p><a href="http://r00tsec.blogspot.com/2011/08/leak-of-apt-domains.html">APT Domains</a></p>
<p><a href="http://www.heise.de/tr/artikel/Wir-brauchen-wuetende-Nerds-1397391.html">Wütende Nerds</a></p>
<p><a href="http://www.laquadrature.net/wiki/ACTA_rapporteur_denounces_ACTA_mascarade">ACTA Rapporteur</a></p>
<p><a href="http://javascriptmvc.com/docs.html#!getstarted">JavaScriptMVC Getting Started</a></p>
<p><a href="https://www.isc.org/community/blog/201109/origin-asn-anycasted-services">Origin ASN for Anycasting</a></p>
<p><a href="http://www.thc.org/thc-ssl-dos/">SSL DOS Attacks</a> (also <a href="http://permalink.gmane.org/gmane.comp.security.full-disclosure/82533">here</a>)</p>
<p><a href="http://googleonlinesecurity.blogspot.com/2011/04/improving-ssl-certificate-security.html">Google SSL Improvements</a></p>
<p><a href="http://books.slashdot.org/story/11/04/04/1336254/Book-Review-15-Minutes-Including-QampA">Presentation hints</a></p>
<p><a href="http://www.dmarc.org/draft-dmarc-base-00-01.html"><br />
DMARC.</a> Not that much different than my Domain Policy proposal from years ago.</p>
<p><a href="http://www.abusehelper.be/demo">Abusehelper Demo</a></p>
<p><a href="http://www.isecom.org/osstmm/">OSTMM</a></p>
<p><a href="http://www.wanderingmist.com/arts-and-crafts/how-to-make-a-sheep-costume-for-children/">Shaun costumes</a></p>
<p><a href="https://tools.ietf.org/html/rfc6296">IPv6 NAT</a></p>
]]></content:encoded>
			<wfw:commentRss>http://lendl.priv.at/blog/2012/01/30/links/feed/</wfw:commentRss>
		</item>
		<item>
		<title>DNSSEC Troubles</title>
		<link>http://lendl.priv.at/blog/2012/01/26/dnssec-troubles/</link>
		<comments>http://lendl.priv.at/blog/2012/01/26/dnssec-troubles/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 10:14:40 +0000</pubDate>
		<dc:creator>otmar</dc:creator>
		
		<category><![CDATA[CERT]]></category>

		<category><![CDATA[Internet]]></category>

		<guid isPermaLink="false">http://lendl.priv.at/blog/?p=308</guid>
		<description><![CDATA[I&#8217;ve given my share of DNSSEC talks over the last three years. I usually explain what exactly DNSSEC provides and what it does not.  One of the downsides I tell ISPs about is that other people&#8217;s DNSSEC errors will hit your call-center if you&#8217;re doing DNSSEC-validation.
This just happened to Comcast.
I really recommend that anyone [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve given my share of DNSSEC talks over the last three years. I usually explain what exactly DNSSEC provides and what it does not.  One of the downsides I tell ISPs about is that other people&#8217;s DNSSEC errors will hit your call-center if you&#8217;re doing DNSSEC-validation.</p>
<p>This just <a href="http://www.darkreading.com/authentication/167901072/security/application-security/232500483/dnssec-error-caused-nasa-website-to-be-blocked.html?nomobile=1">happened to Comcast</a>.</p>
<p>I really recommend that anyone enabling DNSSEC validation on their resolvers should be prepared for this case. The <a href="http://www.dnssec.comcast.net/DNSSEC_Validation_Failure_NASAGOV_20120118_FINAL.pdf">report from Comcast</a> is instructive, especially the media fallout they had to cope with.</p>
]]></content:encoded>
			<wfw:commentRss>http://lendl.priv.at/blog/2012/01/26/dnssec-troubles/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Textbooks on the iPad</title>
		<link>http://lendl.priv.at/blog/2012/01/22/textbooks-on-the-ipad/</link>
		<comments>http://lendl.priv.at/blog/2012/01/22/textbooks-on-the-ipad/#comments</comments>
		<pubDate>Sun, 22 Jan 2012 22:13:11 +0000</pubDate>
		<dc:creator>otmar</dc:creator>
		
		<category><![CDATA[Internet]]></category>

		<guid isPermaLink="false">http://lendl.priv.at/blog/?p=307</guid>
		<description><![CDATA[Apple announced last week that it wants to change the way textbooks work for US schools: Instead of schools buying books that are given to a succession of pupils, each kid should receive its own copy of the textbook as an ebook on his iPad.
So far, so interesting. I have two observations on this:
a) Richard [...]]]></description>
			<content:encoded><![CDATA[<p>Apple announced last week that it wants to <a href="http://arstechnica.com/apple/news/2012/01/apple-announces-ibooks-2-to-reinvent-textbooks.ars">change the way textbooks work for US schools</a>: Instead of schools buying books that are given to a succession of pupils, each kid should receive its own copy of the textbook as an ebook on his iPad.</p>
<p>So far, so interesting. I have two observations on this:</p>
<p>a) Richard Stallman wrote once a short story called &#8220;<a href="http://souravroy.com/foss/essays-by-richard-stallman/the-right-to-read/">The right to read</a>&#8220;. Having textbooks solely on DRM-infected ebook readers is yet another step in that direction.</p>
<p>b) This is a huge opportunities for crowd-sourced textbooks. The material that basic textbooks cover have been summarized, prepared for lectures, lessons, books, &#8230; by successions of teachers, home-schoolers, students and other people over and over again. This is a market that is pitch-perfect for some sort of Wikipedia-style cooperative editing. </p>
<p>There will be no single common edition for all topics, some are just too controversial. In other cases, there will be different approaches on how to teach a certain subject. Nevertheless, if it is easy enough to share enhancements to copylefted textbooks, we might see that many teachers will enhance the ebook for their class (add some multimedia content, add exercises, provide additional information) and feed all these back into the public pool of ebooks.</p>
<p>Optimally, this would work as a plugin into <a href="https://www.apple.com/ipad/built-in-apps/ibooks.html">Apple&#8217;s ebook writing software</a> to make it a seamless experience. The economic incentive for Apple is not there, so I doubt that will happen soon. But if someone writes a decent conversion tool that takes a set of pages from Wikipedia (perhaps enhanced with some special tags for this purpose) and builds a textbook from them, this could take off very quickly.</p>
<p>This could do to textbooks what Wikipedia already did to lexica.</p>
<p>(And of course, Amazon will also <a href="http://www.zdnet.com/blog/perlow/amazon-primed-to-disrupt-apples-textbook-plans/19662">try to ruin Apple&#8217;s plans</a>.)</p>
]]></content:encoded>
			<wfw:commentRss>http://lendl.priv.at/blog/2012/01/22/textbooks-on-the-ipad/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Merry Christmas 2011</title>
		<link>http://lendl.priv.at/blog/2011/12/24/merry-christmas-2011/</link>
		<comments>http://lendl.priv.at/blog/2011/12/24/merry-christmas-2011/#comments</comments>
		<pubDate>Sat, 24 Dec 2011 15:15:21 +0000</pubDate>
		<dc:creator>otmar</dc:creator>
		
		<category><![CDATA[Life]]></category>

		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://lendl.priv.at/blog/?p=304</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p><img src="http://lendl.priv.at/blog/wp-content/uploads/2011/12/xmas2011.jpg" alt="" title="xmas2011" width="500" height="333" class="alignnone size-full wp-image-305" /></p>
]]></content:encoded>
			<wfw:commentRss>http://lendl.priv.at/blog/2011/12/24/merry-christmas-2011/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The WOW-Effect</title>
		<link>http://lendl.priv.at/blog/2011/12/02/the-wow-effect/</link>
		<comments>http://lendl.priv.at/blog/2011/12/02/the-wow-effect/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 09:06:15 +0000</pubDate>
		<dc:creator>otmar</dc:creator>
		
		<category><![CDATA[CERT]]></category>

		<guid isPermaLink="false">http://lendl.priv.at/blog/?p=303</guid>
		<description><![CDATA[This week I had some fun helping a co-working with a paper regarding the effect of WOW64 (the 32-bit environment of 64-bit Windows) on various tools and procedures that security analysts use.
The result is here: The WOW-Effect.
]]></description>
			<content:encoded><![CDATA[<p>This week I had some fun helping a co-working with a paper regarding the effect of WOW64 (the 32-bit environment of 64-bit Windows) on various tools and procedures that security analysts use.</p>
<p>The result is here: <a href="http://www.cert.at/downloads/papers/wow_effect_en.html">The WOW-Effect</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://lendl.priv.at/blog/2011/12/02/the-wow-effect/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Tracks</title>
		<link>http://lendl.priv.at/blog/2011/11/26/tracks-34/</link>
		<comments>http://lendl.priv.at/blog/2011/11/26/tracks-34/#comments</comments>
		<pubDate>Sat, 26 Nov 2011 11:56:54 +0000</pubDate>
		<dc:creator>otmar</dc:creator>
		
		<category><![CDATA[Tracks]]></category>

		<guid isPermaLink="false">http://lendl.priv.at/blog/?p=301</guid>
		<description><![CDATA[Another lazy Saturday track:

]]></description>
			<content:encoded><![CDATA[<p>Another lazy Saturday track:</p>
<p><a href='http://lendl.priv.at/blog/wp-content/uploads/2011/12/wien-20111126-00108.jpg'><img src="http://lendl.priv.at/blog/wp-content/uploads/2011/12/wien-20111126-00108.jpg" alt="" title="wien-20111126-00108" width="480" height="421" class="alignnone size-full wp-image-302" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://lendl.priv.at/blog/2011/11/26/tracks-34/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Tracks</title>
		<link>http://lendl.priv.at/blog/2011/11/01/tracks-33/</link>
		<comments>http://lendl.priv.at/blog/2011/11/01/tracks-33/#comments</comments>
		<pubDate>Tue, 01 Nov 2011 10:42:36 +0000</pubDate>
		<dc:creator>otmar</dc:creator>
		
		<category><![CDATA[Tracks]]></category>

		<guid isPermaLink="false">http://lendl.priv.at/blog/?p=299</guid>
		<description><![CDATA[We did away with the old children&#8217;s corner in the living room and the new setup gives us more space. See e.g. these tracks:

(My regular digicams are not available, thus I had to resort to the camera on my old Nokia phone.)
]]></description>
			<content:encoded><![CDATA[<p>We did away with the old children&#8217;s corner in the living room and the new setup gives us more space. See e.g. these tracks:</p>
<p><img src="http://lendl.priv.at/blog/wp-content/uploads/2011/11/tracks-2011-11-01.jpg" alt="" title="tracks-2011-11-01" width="500" height="666" class="alignnone size-full wp-image-300" /></p>
<p>(My regular digicams are not available, thus I had to resort to the camera on my old Nokia phone.)</p>
]]></content:encoded>
			<wfw:commentRss>http://lendl.priv.at/blog/2011/11/01/tracks-33/feed/</wfw:commentRss>
		</item>
		<item>
		<title>#DigiNotar and paying for an audit</title>
		<link>http://lendl.priv.at/blog/2011/09/07/diginotar-and-paying-for-an-audit/</link>
		<comments>http://lendl.priv.at/blog/2011/09/07/diginotar-and-paying-for-an-audit/#comments</comments>
		<pubDate>Wed, 07 Sep 2011 20:25:48 +0000</pubDate>
		<dc:creator>otmar</dc:creator>
		
		<category><![CDATA[CERT]]></category>

		<category><![CDATA[Internet]]></category>

		<guid isPermaLink="false">http://lendl.priv.at/blog/?p=298</guid>
		<description><![CDATA[The question Mozilla, Microsoft and Apple should be asking themselves now is:
Which other CA do they trust based on an audit by PwC? Their green light on DigiNotar was so flawed that I have serious doubts about anyone else they certified as a trustworthy CA.
This is a bit like the financial rating agencies at the [...]]]></description>
			<content:encoded><![CDATA[<p>The question Mozilla, Microsoft and Apple should be asking themselves now is:</p>
<p>Which other CA do they trust based on an audit by PwC? Their green light on DigiNotar was so flawed that I have serious doubts about anyone else they certified as a trustworthy CA.</p>
<p>This is a bit like the financial rating agencies at the height of the 2008 banking crisis: why the hell should I trust the audit/rating of someone who is paid by the people they are auditing/rating and who need an &#8220;all fine&#8221;/AAA result?</p>
]]></content:encoded>
			<wfw:commentRss>http://lendl.priv.at/blog/2011/09/07/diginotar-and-paying-for-an-audit/feed/</wfw:commentRss>
		</item>
		<item>
		<title>RIP Semantic Web</title>
		<link>http://lendl.priv.at/blog/2011/06/07/rip-semantic-web/</link>
		<comments>http://lendl.priv.at/blog/2011/06/07/rip-semantic-web/#comments</comments>
		<pubDate>Tue, 07 Jun 2011 19:45:31 +0000</pubDate>
		<dc:creator>otmar</dc:creator>
		
		<category><![CDATA[Internet]]></category>

		<guid isPermaLink="false">http://lendl.priv.at/blog/?p=293</guid>
		<description><![CDATA[How many research grants have been awarded to &#8220;Semantic Web&#8221; research proposals over the last few years? I always maintained that this is a typical academic solution to a problem that will be solved by very simple additions to the existing web like microformats.
Now the search heavyweights have joined the semantic web for real. But [...]]]></description>
			<content:encoded><![CDATA[<p>How many research grants have been awarded to &#8220;Semantic Web&#8221; research proposals over the last few years? I always maintained that this is a typical academic solution to a problem that will be solved by very simple additions to the existing web like <a href="http://microformats.org/">microformats</a>.</p>
<p>Now the search heavyweights have joined the semantic web for real. But not by doing RDF or any of those full blown perfect solutions developed over the last years by burning research money.</p>
<p>As I see it, most of the research projects are now completely obsolete given the launch of <a href="http://schema.org/">schema.org</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://lendl.priv.at/blog/2011/06/07/rip-semantic-web/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Nokia 2680s and iSync</title>
		<link>http://lendl.priv.at/blog/2011/05/16/nokia-2680s-and-isync/</link>
		<comments>http://lendl.priv.at/blog/2011/05/16/nokia-2680s-and-isync/#comments</comments>
		<pubDate>Mon, 16 May 2011 20:26:49 +0000</pubDate>
		<dc:creator>otmar</dc:creator>
		
		<category><![CDATA[System Administration]]></category>

		<guid isPermaLink="false">http://lendl.priv.at/blog/?p=291</guid>
		<description><![CDATA[Now that Andrea owns a Mac again it was overdue to get iSync up and running with her Phone.
iSync is nice, but her Nokia 2680 is neither supported by the 10.7 iSync, nor does Nokia provide a suitable plugin. Luckily, there are alternatives. Paul Bain has published a few plugins on his blog, including one [...]]]></description>
			<content:encoded><![CDATA[<p>Now that Andrea owns a Mac again it was overdue to get iSync up and running with her Phone.</p>
<p>iSync is nice, but her Nokia 2680 is neither supported by the 10.7 iSync, nor does Nokia provide a suitable plugin. Luckily, there are alternatives. Paul Bain has published a <a href="http://www.paulbain.com/2008/11/05/nokia-6600-slide-isync-plugin/">few plugins on his blog</a>, including one for the 3600 Slide. According to one of the comments, that should be pretty easy to adapt for the 2680s.</p>
<p>Installing the plugin and replacing all occurrences of &#8220;3600 Slide&#8221; with &#8220;2680s&#8221; was simple, but it didn&#8217;t work: iSync still complained about an &#8220;unsupported phone&#8221;. </p>
<p>The solution became apparent when looking at the log in /var/log: the phone is actually a &#8220;2680s-2&#8243;, and once I got the strings right, iSync was happy.</p>
<p>To make things easier for others trying to replicate this, here is a <a href="http://lendl.priv.at/blog/wp-content/uploads/2011/05/nokia-2680s-2phoneplugin.zip'">zip of the my resulting plugin</a>. (And I hope plain zip did the job, and I&#8217;m not running into some macos resource fork &#038; co weirdness.)</p>
<p>HTH.</p>
]]></content:encoded>
			<wfw:commentRss>http://lendl.priv.at/blog/2011/05/16/nokia-2680s-and-isync/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>

