<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>IOStream TechNotes &#187; Security</title>
	<atom:link href="http://iostreamcto.wordpress.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://iostreamcto.wordpress.com</link>
	<description>Musings From The CTO</description>
	<lastBuildDate>Wed, 12 Sep 2007 15:23:53 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='iostreamcto.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/577764dae23ad186025257eec9d30701?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>IOStream TechNotes &#187; Security</title>
		<link>http://iostreamcto.wordpress.com</link>
	</image>
			<item>
		<title>Bulletproof Website Logins With Verisign PIP</title>
		<link>http://iostreamcto.wordpress.com/2007/09/07/bulletproof-website-logins-with-verisign-pip/</link>
		<comments>http://iostreamcto.wordpress.com/2007/09/07/bulletproof-website-logins-with-verisign-pip/#comments</comments>
		<pubDate>Fri, 07 Sep 2007 15:28:52 +0000</pubDate>
		<dc:creator>iostreamcto</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://iostreamcto.wordpress.com/2007/09/07/bulletproof-website-logins-with-verisign-pip/</guid>
		<description><![CDATA[The Safer, Faster Surfing With OpenDNS post sparked discussion about phishing as well as other techniques utilized for the purposes of identity theft. Therefore, I thought I might post about a new, free OpenID service offered by VeriSign Labs that can be combined with a special Identity Protection Keychain Token or SanDisk Cruzer U3 flash [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=iostreamcto.wordpress.com&blog=828431&post=17&subd=iostreamcto&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="https://pip.verisignlabs.com/" target="_blank"><img src="https://pip.verisignlabs.com/web/brand/images/brandheaderLogo.jpg" alt="Verisign Labs Logo" align="right" border="0" height="60" hspace="5" vspace="5" width="206" /></a>The <a href="http://iostreamcto.wordpress.com/2007/09/05/safer-faster-surfing-with-opendns/">Safer, Faster Surfing With OpenDNS</a> post sparked discussion about phishing as well as other techniques utilized for the purposes of identity theft. Therefore, I thought I might post about a new, free OpenID service offered by <a href="https://pip.verisignlabs.com/" target="_blank">VeriSign Labs</a> that can be combined with a special <a href="https://idprotect.verisign.com/learnmoretoken.v" target="_blank">Identity Protection Keychain Token</a> or <a href="https://idprotect.verisign.com/learnmoresandisk.v" target="_blank">SanDisk Cruzer U3 flash drive</a> in order to achieve two-factor authentication when logging into OpenID enabled websites.</p>
<h3>What is PIP?</h3>
<p><a href="https://pip.verisignlabs.com/" target="_blank">Personal Identity Provider</a> allows you to manage your personal information online by providing a single sign on to multiple websites. PIP also provides the flexibility to share only the information you choose with each website. When you create a PIP account, you will receive a personal identifier in the form of a URL that you can use to sign in or register at any site that supports OpenID.</p>
<h3>Manage your online identities with PIP</h3>
<p><img src="https://seal.verisign.com/images/logo2.gif" alt="Versign Secured Site Logo" align="right" border="0" height="61" hspace="5" vspace="5" width="134" />Use PIP to protect your information and share it with sites you trust. You can set PIP to track what sites you have shared your information with and for how long. You can choose to stop sharing information with a site you no longer trust. I use my VeriSign PIP identity with <a href="http://www.plaxo.com/" target="_blank">Plaxo</a> to maintain continuous contacts and calendar synchronization across my personal Google Gmail, Yahoo! and Windows LiveMail accounts.</p>
<h3>How to use PIP</h3>
<p><a href="https://pip.verisignlabs.com/register.do" target="_blank" title="Create a PIP account"><img src="https://pip.verisignlabs.com/web/brand/images/openid_logo.jpg" alt="OpenID Logo" align="right" border="0" height="47" hspace="5" vspace="5" width="122" /></a>Click the <a href="https://pip.verisignlabs.com/register.do" target="_blank">OpenID button</a> to the right to sign up for and create a PIP Account. You will receive a personal URL that you can use on sites that show the OpenID logo. From the same browser you used to sign into PIP, <a href="http://openiddirectory.com/" target="_blank" title="Link to OpenID Directory">visit one of the many sites that support OpenID</a> and type or paste your URL into the Sign in area. Using your PIP URL makes it easy to register for a new account, or sign in to your existing accounts. If the site you are registering for requests information, you can choose which information you would like to share or keep private.</p>
<p style="text-align:center;"><img src="https://pip.verisignlabs.com/web/brand/images/sample_signin.jpg" alt="OpenID Sign-in Screenshot" border="0" height="217" hspace="5" vspace="5" width="300" /></p>
<h3>Integrate VerSign&#8217;s PIP into Firefox with The SeatBelt Extension</h3>
<p><a href="https://pip.verisignlabs.com/seatbelt.do" target="_blank" title="Download the Seatbelt Extension for Firefox"><img src="https://pip.verisignlabs.com/web/brand/images/login_here.jpg" alt="Seatbelt Button" align="right" border="0" height="26" hspace="5" vspace="5" width="98" />SeatBelt </a>is a Firefox plug-in that assists you when signing in to OpenID sites with your PIP URL. Typically, if you are not signed into your PIP account when you access a sign in page using OpenID, you need to access your PIP account and sign in. Since you must do this within the same browser window, you have to navigate away from the page you wish to sign in to. SeatBelt detects that you have clicked on an OpenID sign in field while not signed into your PIP account and prompts you to sign in. Once you have signed in, SeatBelt automatically returns you to the OpenID sign in page with your PIP URL filled in. The sign in session continues as normal.<br />
<strong><font color="#ff6600">NOTE:</font></strong> <em><font color="#ff6600">I have discovered issues between the Seatbelt Extension and scripts on certain websites, this WordPress blog being a prime example. I have reported the issue to VerSign and recommend waiting on installing this extension until it is out of beta.</font></em></p>
<h3>Adding two-factor authentication to OpenID</h3>
<p><a href="https://idprotect.verisign.com/learnmoretoken.v" title="Verisign Identity Protection Keychain Token" target="_blank"><img src="https://idprotect.verisign.com/brand-verisign/images/catalog-token1.gif" alt="Versign Identity Keychain Token" align="right" border="0" height="108" hspace="5" vspace="5" width="180" /></a>A <a href="https://idprotect.verisign.com/learnmoretoken.v" target="_blank">VIP keychain token</a> is an online security credential that you can use to identify yourself securely to participating online banks and merchant sites. A VIP credential protects your accounts and your identity by requiring a higher level of security when you conduct transactions online. To use a VIP credential, press the button on the keychain token to generate a security code that is unique to your credential. Then, sign in to participating online bank and merchant sites with your username, password, and the unique security code.</p>
<p>To obtain a <strong>VeriSign Identity Protection Keychain Token</strong> <font color="#ff6600"><em>after obtaining your PIP credentials</em></font>, click <a href="https://idprotect.verisign.com/learnmoretoken.v" target="_blank">HERE</a>. The token is currently $30 US plus a $6 S&amp;H fee.</p>
<p><a href="https://www.paypal.com/securitykey" target="_blank"><img src="http://cache.gizmodo.com/assets/resources/2007/01/paypalsecurity.jpg" alt="PayPal Security Key" align="right" border="0" height="102" hspace="5" vspace="5" width="181" /></a>An alternative to the $36 VeriSign token is the $5 <a href="http://www.paypal.com/securitykey" target="_blank">PayPal Security Key</a>. This key can function with both your PayPal and eBay accounts as well as your VeriSign Personal Identity Provider ID. This is the device I use and recommend for anyone interested in adding two-factor authentication to their security practices..</p>
<p>A third option is to use a U3 flash drive. VeriSign has teamed up with <a href="http://www.sandisk.com/Products/Catalog(1167)-SanDisk_Cruzer_Titanium_USB_Flash_Drive.aspx" target="_blank">SanDisk</a> to <a href="https://idprotect.verisign.com/learnmoresandisk.v" target="_blank">enable your SanDisk U3 smart drive to work as an online security credential</a>. You can use the VIP credential embedded on your SanDisk U3 smart drive to identify yourself securely to participating online bank and merchant sites. <a href="http://www.sandisk.com/Products/Catalog(1167)-SanDisk_Cruzer_Titanium_USB_Flash_Drive.aspx" target="_blank"><img src="http://www.sandisk.com/Assets/Products/130/T2-2GB_closed_130.jpg" alt="SanDisk Cruzer Titanium" align="right" border="0" height="114" hspace="5" vspace="5" width="130" /></a>See the <span class="pageTitle"></span><span class="pageTitle">‘<a href="https://idprotect.verisign.com/learnmoresandisk.v" target="_blank">VeriSign Identity Protection for SanDisk U3 Smart Drives</a>’ page for complete information and usage instructions.</span></p>
<p><font color="#ff6600"><strong>UPDATE:</strong></font> <em>I have been playing catch-up with my podcast listening of late due to a more hectic than normal schedule.  I just finished listening to <a href="http://www.grc.com">Steve Gibson&#8217;s</a> <a href="http://www.grc.com/SecurityNow.htm#107">Security Now Podcast #107</a> where he reviews <a href="https://pip.verisignlabs.com/" target="_blank">Verisign Labs’ Personal Identity Provider</a> in detail. Please download and listen to his podcast as a supplement to this post. Also, the Solo Technology blog posted two articles relating their personal experiences with both OpenID and the security tokens. These articles are <a href="http://www.solo-technology.com/blog/2007/07/31/the-key-to-paypal-security/" target="_blank">HERE</a> and <a href="http://www.solo-technology.com/blog/2007/08/04/paypal-security-and-openid-integration/" target="_blank">HERE</a>.</em></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/iostreamcto.wordpress.com/17/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/iostreamcto.wordpress.com/17/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/iostreamcto.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/iostreamcto.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/iostreamcto.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/iostreamcto.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/iostreamcto.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/iostreamcto.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/iostreamcto.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/iostreamcto.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/iostreamcto.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/iostreamcto.wordpress.com/17/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=iostreamcto.wordpress.com&blog=828431&post=17&subd=iostreamcto&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://iostreamcto.wordpress.com/2007/09/07/bulletproof-website-logins-with-verisign-pip/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/49e38c35dd50350e197920427fb74855?s=96&#38;d=identicon" medium="image">
			<media:title type="html">IOStreamCTO</media:title>
		</media:content>

		<media:content url="//pip.verisignlabs.com/web/brand/images/brandheaderLogo.jpg" medium="image">
			<media:title type="html">Verisign Labs Logo</media:title>
		</media:content>

		<media:content url="//seal.verisign.com/images/logo2.gif" medium="image">
			<media:title type="html">Versign Secured Site Logo</media:title>
		</media:content>

		<media:content url="//pip.verisignlabs.com/web/brand/images/openid_logo.jpg" medium="image">
			<media:title type="html">OpenID Logo</media:title>
		</media:content>

		<media:content url="//pip.verisignlabs.com/web/brand/images/sample_signin.jpg" medium="image">
			<media:title type="html">OpenID Sign-in Screenshot</media:title>
		</media:content>

		<media:content url="//pip.verisignlabs.com/web/brand/images/login_here.jpg" medium="image">
			<media:title type="html">Seatbelt Button</media:title>
		</media:content>

		<media:content url="//idprotect.verisign.com/brand-verisign/images/catalog-token1.gif" medium="image">
			<media:title type="html">Versign Identity Keychain Token</media:title>
		</media:content>

		<media:content url="http://cache.gizmodo.com/assets/resources/2007/01/paypalsecurity.jpg" medium="image">
			<media:title type="html">PayPal Security Key</media:title>
		</media:content>

		<media:content url="http://www.sandisk.com/Assets/Products/130/T2-2GB_closed_130.jpg" medium="image">
			<media:title type="html">SanDisk Cruzer Titanium</media:title>
		</media:content>
	</item>
		<item>
		<title>Firewall Leak Tester</title>
		<link>http://iostreamcto.wordpress.com/2007/08/19/firewall-leak-tester/</link>
		<comments>http://iostreamcto.wordpress.com/2007/08/19/firewall-leak-tester/#comments</comments>
		<pubDate>Sun, 19 Aug 2007 17:45:49 +0000</pubDate>
		<dc:creator>iostreamcto</dc:creator>
				<category><![CDATA[On-Line Tools]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://iostreamcto.wordpress.com/2007/08/19/firewall-leak-tester/</guid>
		<description><![CDATA[I was made aware of an excellent on-line service for testing the effectiveness of  your  firewall courtesy of  Steve Gibson&#8217;s very informative Security Now! podcast (Episode 105). The  name of the site is  Firewall Leak Tester. The site&#8217;s developers describe the service thusly:
“This website, on one hand, enables you to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=iostreamcto.wordpress.com&blog=828431&post=8&subd=iostreamcto&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I was made aware of an excellent on-line service for testing the effectiveness of  your  firewall courtesy of  <a href="http://en.wikipedia.org/wiki/Steve_Gibson" title="OPen Steve Gibson's entry in Wikipedia in a new window">Steve Gibson&#8217;s</a> very informative <a href="http://www.grc.com/securitynow.htm" title="Open the Security Now! podcast listing in a new window">Security Now!</a> podcast (<a href="http://www.grc.com/sn/SN-105.htm" title="Security Now! ep.#105 Show Notes" target="_blank">Episode 105</a>). The  name of the site is  <a href="http://www.firewallleaktester.com/" title="Open Firewall Leak Tester in a new window" target="_blank">Firewall Leak Tester</a>. The site&#8217;s developers describe the service thusly:</p>
<p>“<em>This website, on one hand, enables you to test your software personal firewall thanks to different test programs (&#8216;leaktests&#8217;), and on the other hand, shows a global vulnerabilities view of the most common personal firewalls in a summary page. Firewall Leak Tester provides also documentation and advice to improve your security dramatically.</em>”</p>
<p>Nineteen (19!) tests are linked from this master resource. This is definitely a recommended service for the IT professional double checking their corporate firewall setup, computer enthusiast learning about how easily computer systems can be penetrated, or home PC users concerned about their privacy and security.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/iostreamcto.wordpress.com/8/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/iostreamcto.wordpress.com/8/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/iostreamcto.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/iostreamcto.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/iostreamcto.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/iostreamcto.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/iostreamcto.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/iostreamcto.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/iostreamcto.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/iostreamcto.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/iostreamcto.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/iostreamcto.wordpress.com/8/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=iostreamcto.wordpress.com&blog=828431&post=8&subd=iostreamcto&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://iostreamcto.wordpress.com/2007/08/19/firewall-leak-tester/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/49e38c35dd50350e197920427fb74855?s=96&#38;d=identicon" medium="image">
			<media:title type="html">IOStreamCTO</media:title>
		</media:content>
	</item>
	</channel>
</rss>