<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Chakraborty Software</title>
	<atom:link href="http://www.chakraborty.ch/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.chakraborty.ch</link>
	<description>Information Security Consulting Services</description>
	<lastBuildDate>Mon, 24 Oct 2011 14:26:46 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on French Researchers &#8220;Hack&#8221; TOR by Ralph</title>
		<link>http://www.chakraborty.ch/exploits/french-researchers-hack-tor/comment-page-1/#comment-4762</link>
		<dc:creator>Ralph</dc:creator>
		<pubDate>Mon, 24 Oct 2011 14:26:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.chakraborty.ch/?p=471#comment-4762</guid>
		<description>So, a french engineering school can do something the FBI and DOJ can&#039;t, with their resources? by DDOSing FBI nodes (presumably clean)? Wonder if they got &quot;Anonymous&quot;, who&#039;ve been attacking some of the sites too.
We&#039;ll see.</description>
		<content:encoded><![CDATA[<p>So, a french engineering school can do something the FBI and DOJ can&#8217;t, with their resources? by DDOSing FBI nodes (presumably clean)? Wonder if they got &#8220;Anonymous&#8221;, who&#8217;ve been attacking some of the sites too.<br />
We&#8217;ll see.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on French Researchers &#8220;Hack&#8221; TOR by Rob_OEM</title>
		<link>http://www.chakraborty.ch/exploits/french-researchers-hack-tor/comment-page-1/#comment-4761</link>
		<dc:creator>Rob_OEM</dc:creator>
		<pubDate>Mon, 24 Oct 2011 13:50:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.chakraborty.ch/?p=471#comment-4761</guid>
		<description>I agree with you on the poor details-to-buzzwords ratio. We&#039;ll see what it&#039;s all about after they show it. However, concerning the inventory phase, I might be able to clarify a thing.
In the article they say &lt;cite&gt;most nodes&#039; IP addresses are accessible publicly or using the system&#039;s source code&lt;/cite&gt; from which I infer &lt;em&gt;all TOR exit nodes are public, some other nodes are hardcoded in the source, most nodes can be discovered using public APIs.&lt;/em&gt;
The rest of the attack, you got that part, involves the compromise of existing nodes or adding rogue nodes, and DoSing all the others (lame, but they mention a way of essentially making messages loop through fixed nodes in TOR, which sounds great-if-real)</description>
		<content:encoded><![CDATA[<p>I agree with you on the poor details-to-buzzwords ratio. We&#8217;ll see what it&#8217;s all about after they show it. However, concerning the inventory phase, I might be able to clarify a thing.<br />
In the article they say <cite>most nodes&#8217; IP addresses are accessible publicly or using the system&#8217;s source code</cite> from which I infer <em>all TOR exit nodes are public, some other nodes are hardcoded in the source, most nodes can be discovered using public APIs.</em><br />
The rest of the attack, you got that part, involves the compromise of existing nodes or adding rogue nodes, and DoSing all the others (lame, but they mention a way of essentially making messages loop through fixed nodes in TOR, which sounds great-if-real)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Windows Vista Security Guide, Medical Computers by Medical PC</title>
		<link>http://www.chakraborty.ch/best-practices/windows-vista-security-guide-medical-computers/comment-page-1/#comment-4759</link>
		<dc:creator>Medical PC</dc:creator>
		<pubDate>Mon, 10 Oct 2011 20:59:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.chakraborty.ch/blog/?p=22#comment-4759</guid>
		<description>excellent article! security is always an issue when your talking about medical computers and the equipment used to store patient information inside hospital and doctors offices.</description>
		<content:encoded><![CDATA[<p>excellent article! security is always an issue when your talking about medical computers and the equipment used to store patient information inside hospital and doctors offices.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on iPad Security &#8212; My Overview by Arjo</title>
		<link>http://www.chakraborty.ch/architecture-design/ipad-security-my-overview/comment-page-1/#comment-4752</link>
		<dc:creator>Arjo</dc:creator>
		<pubDate>Thu, 07 Jul 2011 20:57:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.chakraborty.ch/?p=209#comment-4752</guid>
		<description>Wait till Max publishes his findings on the iPad....you may not want one...then again, just make sure you don&#039;t leave it lying around and let someone like Max gets his hands on it for about 2 minutes. (yep, i saw some of his findings in a demo he did for me)...yikes</description>
		<content:encoded><![CDATA[<p>Wait till Max publishes his findings on the iPad&#8230;.you may not want one&#8230;then again, just make sure you don&#8217;t leave it lying around and let someone like Max gets his hands on it for about 2 minutes. (yep, i saw some of his findings in a demo he did for me)&#8230;yikes</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on iPad Security &#8212; My Overview by Laptops and Border Controls &#187; Chakraborty Software</title>
		<link>http://www.chakraborty.ch/architecture-design/ipad-security-my-overview/comment-page-1/#comment-4114</link>
		<dc:creator>Laptops and Border Controls &#187; Chakraborty Software</dc:creator>
		<pubDate>Tue, 23 Nov 2010 07:25:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.chakraborty.ch/?p=209#comment-4114</guid>
		<description>[...] iPad Security &#8212; My Overview  Recent CommentsMr Lakofski on Firesheep and Credentials Sniffing &#8212; First ImpressionsAdi on Getting Started in Securityjohn on SSL / SSH and MTU Problemspenglx on SSL / SSH and MTU ProblemsPeter on Securitrons and the Thunk Test [...]</description>
		<content:encoded><![CDATA[<p>[...] iPad Security &#8212; My Overview  Recent CommentsMr Lakofski on Firesheep and Credentials Sniffing &#8212; First ImpressionsAdi on Getting Started in Securityjohn on SSL / SSH and MTU Problemspenglx on SSL / SSH and MTU ProblemsPeter on Securitrons and the Thunk Test [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Firesheep and Credentials Sniffing &#8212; First Impressions by Mr Lakofski</title>
		<link>http://www.chakraborty.ch/exploits/firesheep-and-credentials-sniffing/comment-page-1/#comment-3988</link>
		<dc:creator>Mr Lakofski</dc:creator>
		<pubDate>Wed, 27 Oct 2010 13:32:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.chakraborty.ch/?p=298#comment-3988</guid>
		<description>You know who this will annoy the most? Our friends in domestic intelligence.</description>
		<content:encoded><![CDATA[<p>You know who this will annoy the most? Our friends in domestic intelligence.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Getting Started in Security by Adi</title>
		<link>http://www.chakraborty.ch/organization/getting-started-in-security/comment-page-1/#comment-3925</link>
		<dc:creator>Adi</dc:creator>
		<pubDate>Tue, 24 Aug 2010 07:33:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.chakraborty.ch/?p=199#comment-3925</guid>
		<description>I am a recent entry in to this field working as an analyst since about a year, having previously worked on grid computing. I can vouch for everything you have listed as being right on the mark, especially about people who end up in this field not starting in it.

Your blog has a lighter vein to it making it an extremely enjoyable read, which is a rare thing in this field full of MIB. Keep it coming.</description>
		<content:encoded><![CDATA[<p>I am a recent entry in to this field working as an analyst since about a year, having previously worked on grid computing. I can vouch for everything you have listed as being right on the mark, especially about people who end up in this field not starting in it.</p>
<p>Your blog has a lighter vein to it making it an extremely enjoyable read, which is a rare thing in this field full of MIB. Keep it coming.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SSL / SSH and MTU Problems by john</title>
		<link>http://www.chakraborty.ch/standards/ssl-ssh-and-mtu-problems/comment-page-1/#comment-3465</link>
		<dc:creator>john</dc:creator>
		<pubDate>Wed, 05 May 2010 20:53:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.chakraborty.ch/blog/?p=61#comment-3465</guid>
		<description>Hiya,

sorry, what is &quot;B/S&quot;?  

What kind of SSL gateway are you referring to (product)?  Is this the same for everyone?  Can you post a link to the customer&#039;s page?</description>
		<content:encoded><![CDATA[<p>Hiya,</p>
<p>sorry, what is &#8220;B/S&#8221;?  </p>
<p>What kind of SSL gateway are you referring to (product)?  Is this the same for everyone?  Can you post a link to the customer&#8217;s page?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SSL / SSH and MTU Problems by penglx</title>
		<link>http://www.chakraborty.ch/standards/ssl-ssh-and-mtu-problems/comment-page-1/#comment-3464</link>
		<dc:creator>penglx</dc:creator>
		<pubDate>Wed, 05 May 2010 09:27:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.chakraborty.ch/blog/?p=61#comment-3464</guid>
		<description>we accerd a problem while our customer use the pppoe through ssl Gateway proxy the B/S Application System.

the problem show as 
while the MTU of SSL Gateway set as 1200 we can visit the App(through SSL GATEWAY) but the net action is very slow as open a page need 30 seconds;
while the MTU of SSL GATEWAY set higher than 1200(such as 1300 1400) we can&#039;t visit the App

can you give me some suggestions

thank u 
Best wishes</description>
		<content:encoded><![CDATA[<p>we accerd a problem while our customer use the pppoe through ssl Gateway proxy the B/S Application System.</p>
<p>the problem show as<br />
while the MTU of SSL Gateway set as 1200 we can visit the App(through SSL GATEWAY) but the net action is very slow as open a page need 30 seconds;<br />
while the MTU of SSL GATEWAY set higher than 1200(such as 1300 1400) we can&#8217;t visit the App</p>
<p>can you give me some suggestions</p>
<p>thank u<br />
Best wishes</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Securitrons and the Thunk Test by Peter</title>
		<link>http://www.chakraborty.ch/best-practices/securitrons-and-the-thunk-test/comment-page-1/#comment-3453</link>
		<dc:creator>Peter</dc:creator>
		<pubDate>Sun, 31 Jan 2010 17:52:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.chakraborty.ch/?p=163#comment-3453</guid>
		<description>As someone that has worked in several bank security management functions with high &quot;thunk&quot; factors, I think there is a solution.  However, that solution will require acceptance that a large part of the &quot;thunk&quot; has zero contribution to security, but is there for political and legal reasons, and that demands courage.

As yet, I&#039;m not convinced the courage, the will and especially the vision is there to reduce the amount of trees that go into security management.  A &quot;thunk&quot; says &quot;we&#039;ve put some work into this&quot;, which translates into &quot;we did everything we could&quot; if things go wrong.  It takes a brave person to state that the single sheet of A4 is equivalent..</description>
		<content:encoded><![CDATA[<p>As someone that has worked in several bank security management functions with high &#8220;thunk&#8221; factors, I think there is a solution.  However, that solution will require acceptance that a large part of the &#8220;thunk&#8221; has zero contribution to security, but is there for political and legal reasons, and that demands courage.</p>
<p>As yet, I&#8217;m not convinced the courage, the will and especially the vision is there to reduce the amount of trees that go into security management.  A &#8220;thunk&#8221; says &#8220;we&#8217;ve put some work into this&#8221;, which translates into &#8220;we did everything we could&#8221; if things go wrong.  It takes a brave person to state that the single sheet of A4 is equivalent..</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: basic

Served from: www.chakraborty.ch @ 2012-02-06 03:24:25 -->
