<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SpaziDigitali &#187; Security</title>
	<atom:link href="http://spazidigitali.com/cat/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://spazidigitali.com</link>
	<description>Luca Mearelli's Blog</description>
	<lastBuildDate>Fri, 12 Mar 2010 16:52:39 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>When people ask for security holes as features</title>
		<link>http://spazidigitali.com/2005/08/22/when-people-ask-for-security-holes-as-features/</link>
		<comments>http://spazidigitali.com/2005/08/22/when-people-ask-for-security-holes-as-features/#comments</comments>
		<pubDate>Mon, 22 Aug 2005 12:25:34 +0000</pubDate>
		<dc:creator>lm</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.spazidigitali.com/log/2005/08/22/when-people-ask-for-security-holes-as-features/</guid>
		<description><![CDATA[Thinking about security:
&#8230; I went to install   the driver, the instructions actually said something to the tune of &#8220;Ignore   this warning box, it doesn&#8217;t mean anything important. Continue clicking OK  on every screen until the driver finishes installing.&#8221;

Read more about the ways companies try to walk around the Windows Certified [...]]]></description>
			<content:encoded><![CDATA[<p>Thinking about <em>security</em>:</p>
<blockquote><p>&#8230; I went to install   the driver, the instructions actually said something to the tune of &#8220;Ignore   this warning box, it doesn&#8217;t mean anything important. Continue clicking OK  on every screen until the driver finishes installing.&#8221;
</p></blockquote>
<p>Read more about the ways companies try to walk around the Windows Certified Drivers warnings <a href="http://article.gmane.org/gmane.comp.encryption.general/7176">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://spazidigitali.com/2005/08/22/when-people-ask-for-security-holes-as-features/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing and Usable Security</title>
		<link>http://spazidigitali.com/2005/07/25/phishing-and-usable-security/</link>
		<comments>http://spazidigitali.com/2005/07/25/phishing-and-usable-security/#comments</comments>
		<pubDate>Mon, 25 Jul 2005 12:23:10 +0000</pubDate>
		<dc:creator>lm</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.spazidigitali.com/log/?p=10</guid>
		<description><![CDATA[From Cryptogram: a paper from Rachna Dhamija and Doug Tygar researchers at the University of California Berkeley outlines a scheme to improve the tools in the hands of the users to fight the problem of  phishing.
They describe a couple of protocols, to be implemented by the browser and the server which can augment the [...]]]></description>
			<content:encoded><![CDATA[<p>From <a href="http://www.schneier.com/crypto-gram.html">Cryptogram</a>: a <a href="http://www.tygar.net/papers/Battle_against_phishing.pdf">paper</a> from Rachna Dhamija and Doug Tygar researchers at the University of California Berkeley outlines a scheme to improve the tools in the hands of the users to fight the problem of  phishing.</p>
<p>They describe a couple of protocols, to be implemented by the browser and the server which can augment the   trust a user might pose in the interaction with a web application. </p>
<p>The main point made by the article is that the challenges posed by phishing can and should be solved taking into account the usability of the solution for the user, therefore they start by posing the accent on some security properties which sould be addressed by any solution to this problem (and therefore suggest  a metodology to test anti-phishing approaches).<br />
I find that these properties might have a more general application to secure software/service development.</p>
<p>Taking into account usability of a security protocol makes it more effective by easing the burden for the human user (which is often the weakest link in the protocol).</p>
<p>A <a href="http://www.google.it/search?hl=it&#038;q=%22security+usability%22&#038;btnG=Cerca+con+Google&#038;meta=">search</a> on google show a good deal of infos on security and usability (some interesting articles i found are <a href="http://del.icio.us/mearelli/security%2Busability">here</a>, among these the <a href="http://usablesecurity.com/">Usable Security</a> blog).</p>
]]></content:encoded>
			<wfw:commentRss>http://spazidigitali.com/2005/07/25/phishing-and-usable-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
