<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Paper Jammed &#187; Security</title>
	<atom:link href="http://paperjammed.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://paperjammed.com</link>
	<description>Has paper taken over your life?</description>
	<lastBuildDate>Wed, 04 Apr 2012 00:42:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Get it while it lasts—Microsoft&#8217;s easy way to lock down a shared computer</title>
		<link>http://paperjammed.com/2010/11/01/get-it-while-it-lasts%e2%80%94microsofts-easy-way-to-lock-down-a-shared-computer/</link>
		<comments>http://paperjammed.com/2010/11/01/get-it-while-it-lasts%e2%80%94microsofts-easy-way-to-lock-down-a-shared-computer/#comments</comments>
		<pubDate>Tue, 02 Nov 2010 01:56:26 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Tools of the Trade]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=1045</guid>
		<description><![CDATA[Do you have a shared computer somewhere in your life? A computer that anyone and everyone uses in order to hop online to do a quick web search or to print a document? I have been dealing with situations like this for years, working with computers in a small school and at a nonprofit volunteer [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1057" title="Computer Hard Drive" src="http://paperjammed.com/wp-content/uploads/2010/11/iStock_000002116383XSmall-201x300.jpg" alt="" width="201" height="300" />Do you have a shared computer somewhere in your life? A computer that anyone and everyone uses in order to hop online to do a quick web search or to print a document?</p>
<p>I have been dealing with situations like this for years, working with computers in a small school and at a nonprofit volunteer organization, shared by many. It seems that whenever I turn on any of these machines, the background is set to something ugly, the screen resolution is weird, there is some cute animated mouse cursor, and someone has <a href="http://paperjammed.com/2010/01/28/is-there-anything-interesting-lingering-on-your-clipboard/">left their most intimate secrets</a> in a document on the desktop.</p>
<p><a href="http://www.microsoft.com/downloads/en/details.aspx?familyid=d077a52d-93e9-4b02-bd95-9d770ccdb431&amp;displaylang=en">Microsoft Steady State</a> solves all of these issues by providing a means of creating a golden configuration that is restored to absolute perfection the next time the machine is rebooted. But download it before the end of the year, when it will be pulled by Microsoft!<span id="more-1045"></span></p>
<p><strong>Steady State Magic</strong></p>
<p>This free product gives you the ability to configure accounts on your XP or Vista machine with several fine-level access controls. For example, you can prevent users from changing screen settings or prevent them from writing to anywhere other than their personal &#8220;Documents and Settings&#8221; directory.</p>
<p>But by far the coolest feature is the ability to turn off hard drive writes altogether. When you do this, Windows slips a layer between the OS and the physical hard drive that intercepts and tracks all hard drive activity during a session. During the session, the user can browse the web, create documents, install programs, whatever&#8230;but when the machine reboots, the cached list of hard drive changes is discarded completely: the hard drive is restored to the way it looked before the user booted the machine.</p>
<p><strong>What can you use this for?</strong></p>
<p>There are many places where a completely protected machine would be of great use&#8230;</p>
<ul>
<li>A shared computer in a public area, like a hotel lobby</li>
<li>A home computer that is used by the kids and the cat and the dog</li>
<li>Computers in a school or library setting</li>
<li>Shared computers in a setting where many different workers use the same computer</li>
</ul>
<p><strong>Anything to worry about?</strong></p>
<ul>
<li>All of your users must remember that everything must be saved to a USB stick before reboot. Steady State warns you of this every time you reboot the machine.</li>
<li>There are some annoyances that might happen, such as that silly &#8220;Desktop Cleanup Wizard&#8221; popping up every single day because it thinks it hasn&#8217;t been run in five months, or &#8220;New Programs Installed&#8221; balloons that come up every single day because, again, the machine is restored totally to day-one upon reboot.</li>
<li>Microsoft is killing the product at the end of the year. Now it will likely remain functional for XP and Vista, but they are not upgrading it for Windows 7. But this is too cool a product not to try out. In theory, you could create a steady state machine today and keep booting today&#8217;s version of Windows XP for the next five years.</li>
</ul>
<p><strong>Additional Features</strong></p>
<p>With the hard drive protection enabled, you can add programs at any time from an administrator account. When you shut down, Steady State will ask you if you want to commit your changed hard drive data to the Steady State disk image.</p>
<p>Even without the hard drive protection enabled, you have plenty of security constraints you can enable for other users to keep them from installing their favorite annoying toolbar and blinking mouse cursor. Think of this as a poor-man&#8217;s version of the domain policy tool used in enterprise environments.</p>
<p><strong>More Information</strong></p>
<ul>
<li><a href="http://www.oakdome.com/lab/?page_id=100">Microsoft Steady State. How to remotely remove and retain changes on lab computers</a>.</li>
<li><a href="http://news.cnet.com/8301-13554_3-9886306-33.html">Defending the C disk with SteadyState from Microsoft</a></li>
<li>Alternatives to Steady State for Windows 7: <a href="http://technet.microsoft.com/en-us/library/gg176676(WS.10).aspx">Creating a Steady State by Using Microsoft Technologies</a></li>
<li>See Episode #129 of Steve Gibson&#8217;s Security Now podcast: <a href="http://www.grc.com/securitynow.htm">Security Now! Episode Archive</a></li>
</ul>
<p><strong>Conclusion</strong></p>
<p>I did not understand just how slick a tool this is until I installed it on a spare machine. It took about fifteen minutes to configure things right, but that machine has been running for the past few weeks with the locked-down golden configuration. Whenever it reboots, it looks exactly as it did when I installed Steady State.</p>
<p>Give it a try before it&#8217;s too late!</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2010/11/01/get-it-while-it-lasts%e2%80%94microsofts-easy-way-to-lock-down-a-shared-computer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Password angst and the modern Graphics Processing Unit</title>
		<link>http://paperjammed.com/2010/08/16/password-angst-and-the-modern-graphics-processing-unit/</link>
		<comments>http://paperjammed.com/2010/08/16/password-angst-and-the-modern-graphics-processing-unit/#comments</comments>
		<pubDate>Tue, 17 Aug 2010 00:01:05 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=1035</guid>
		<description><![CDATA[It seemed like all we needed to do was mix in some numbers and funny characters and that would make our passwords extra super secret enough to protect our Lego ID from the dark force. This belief was based on the understanding that only those with supercomputers at their disposal would have the computational ability [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1040" title="iStock_000001759879XSmall" src="http://paperjammed.com/wp-content/uploads/2010/08/iStock_000001759879XSmall-201x300.jpg" alt="" width="201" height="300" />It seemed like all we needed to do was mix in some numbers and funny characters and that would make our passwords extra super secret enough to protect our <a href="http://www.lego.com">Lego</a> ID from the dark force.</p>
<p>This belief was based on the understanding that only those with supercomputers at their disposal would have the computational ability to trundle through all of the permutations needed for a brute force attack against our jumble of weird symbols.</p>
<blockquote><p>Richard Boyd, of the Georgia Tech Research Institute, <a href="http://www.bbc.co.uk/news/technology-10963967" target="_blank">told</a> the BBC that the number-crunching capacity of graphics cards compares to those of supercomputers built only 10 years ago.</p>
<p>— The Register</p></blockquote>
<p>Huh?!</p>
<p>The modern bleeding-edge graphics card, normally the purview of hardcore gamers, packs sufficient mathematical muscle to compete with not-so-old super computers?<span id="more-1035"></span></p>
<p>In other words, not only do we have to worry about black-hats who can command arrays of hijacked home computers to take down sites like Twitter and Facebook at will, but they now have mathematical might at their disposal that we normally associate with scientists and three-letter government agencies.</p>
<p>Read all about the demise of the short password here:</p>
<p><a href="http://www.theregister.co.uk/2010/08/16/password_security_analysis/">Short passwords &#8216;hopelessly inadequate&#8217;, say boffins</a> (The Register)</p>
<p><strong>Doom and gloom?</strong></p>
<p>Fortunately, from a password security point of view, this kind of computing power is most useful to hackers who have access to the encrypted password file from the server—a file that is hopefully treated with extra special care to prevent others from seeing it.</p>
<p>The hacker simply runs every possible combination of umpteen funny characters through well known hash algorithms until one particular choice hashes perfectly into the stolen encrypted version. Then he logs into your Lego account and orders more Star Wars Lego kits.</p>
<p>If the hacker does not have the list of encrypted user passwords, he cannot run this process on his über cruncher machine in isolation: He must make a login attempt with each password. And most systems start inserting longer delays, and eventually blocking logins altogether, after three or four failed attempts.</p>
<p><strong>An ominous sign</strong></p>
<p>Password hacking aside, there is a more sinister problem facing us&#8230;</p>
<p>Large powerful government agencies do not spend all of their computing horsepower trying every possible ten-character password to crack a Unix login, do they? They are more concerned with modern hard encryption technologies, the cornerstone of e-commerce and our trust in the Internet.</p>
<p>The time is near when these fancy 128-bit <a href="http://en.wikipedia.org/wiki/Advanced_Encryption_Standard">AES </a>keys will fall prey to ne&#8217;er-do-wells with nothing more than a tricked-out gaming machine.</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2010/08/16/password-angst-and-the-modern-graphics-processing-unit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I wish the hackers would leave PDF alone!</title>
		<link>http://paperjammed.com/2010/08/03/i-wish-the-hackers-would-leave-pdf-alone/</link>
		<comments>http://paperjammed.com/2010/08/03/i-wish-the-hackers-would-leave-pdf-alone/#comments</comments>
		<pubDate>Wed, 04 Aug 2010 03:15:59 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Paperless Life]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[Rants]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=1028</guid>
		<description><![CDATA[In case I haven&#8217;t made myself clear in other posts, I like PDF documents. I mean I Really Like PDF documents. And I want to be able to treat a PDF file exactly as I would a sheaf of printed pages. Then along comes someone who exploits yet another bug in someone&#8217;s PDF renderer. A [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1029" title="20100804-50568_3739" src="http://paperjammed.com/wp-content/uploads/2010/08/20100804-50568_3739.png" alt="" width="300" height="133" />In case I haven&#8217;t made myself clear in other posts, I like PDF documents. I mean I Really Like PDF documents.</p>
<p>And I want to be able to treat a PDF file exactly as I would a sheaf of printed pages.</p>
<p>Then along comes someone who exploits yet another bug in someone&#8217;s PDF renderer. A few months ago Acrobat Reader was all over the news. Today I saw that all of the cool kids are <a href="http://www.engadget.com/2010/08/03/jailbreakme-using-pdf-exploit-to-hack-your-iphone-so-could-the/">jailbreaking their iPhones using a simple web site</a> that exploits a PDF defect in mobile Safari in iOS4.</p>
<p>And if the slick website can inject code that does something as profound as jailbreaking your iPhone, it should be child&#8217;s play for a black hat to use the same thing to take over your iPhone and ring up millions of dollars of charges to some telephone extortion outfit in a remote part of Africa.</p>
<p>I guess all of the fancy PDF features are a double edged sword—recall that Active-X controls and DDT were both amazing and powerful when they were introduced, but the improper use of both have sullied their good names. I just hope that the goal of a pure paper replacement standard is not lost and that these events do not cause PDF to become a marginalized technology.</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2010/08/03/i-wish-the-hackers-would-leave-pdf-alone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Don&#8217;t let weak passwords take you down!</title>
		<link>http://paperjammed.com/2010/06/29/dont-let-weak-passwords-take-you-down/</link>
		<comments>http://paperjammed.com/2010/06/29/dont-let-weak-passwords-take-you-down/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 02:14:53 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Good Sites]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=1020</guid>
		<description><![CDATA[I was recently searching for some material related to password generation and stumbled on a blog post from a few years ago that contains some very candid and eye-opening discussion on password security. How I&#8217;d Hack Your Weak Passwords (onemansblog.com) The author starts off with a list of the top ten passwords, and how he [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1025" title="safe lock" src="http://paperjammed.com/wp-content/uploads/2010/06/iStock_000007608737XSmall-200x300.jpg" alt="iStockphoto" width="200" height="300" />I was recently searching for some material related to password generation and stumbled on a blog post from a few years ago that contains some very candid and eye-opening discussion on password security.</p>
<p><a href="http://onemansblog.com/2007/03/26/how-id-hack-your-weak-passwords/">How I&#8217;d Hack Your Weak Passwords</a> (onemansblog.com)</p>
<p>The author starts off with a list of the top ten passwords, and how he would go about finding the personal information needed. For example, number 1 is &#8220;Your partner, child, or pet’s name, possibly followed by a 0 or 1 (because they’re always making you use a number, aren’t they?)&#8221; and number 2 is &#8220;The last 4 digits of your social security number.&#8221;</p>
<p>The really interesting bits are when the author explains exactly how he would approach hacking your accounts, and how likely he would be to succeed. Unfortunately, the tools needed to engage in this kind of mischief are readily available and do not require great skill to employ.</p>
<p>Some key protection points include&#8230;</p>
<ul>
<li>Don&#8217;t use the same password for all of your online activities. Use different passwords for each site. That way, if your Facebook password is compromised, your Wachovia password is safe.</li>
<li>Never use dictionary words, names, or other common passwords.</li>
<li>Look for a trusted password management utility to help ease the pain of having a hundred different passwords.</li>
<li>Your email is one of the most important and critical passwords—a criminal can use the &#8220;reset my password&#8221; feature on many shopping sites once they have access to your email account.</li>
</ul>
<p>Take a look at the article and see if you can make some changes in the way you handle password security so that you don&#8217;t get hacked!</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2010/06/29/dont-let-weak-passwords-take-you-down/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is there anything interesting lingering on your clipboard?</title>
		<link>http://paperjammed.com/2010/01/28/is-there-anything-interesting-lingering-on-your-clipboard/</link>
		<comments>http://paperjammed.com/2010/01/28/is-there-anything-interesting-lingering-on-your-clipboard/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 04:40:19 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=867</guid>
		<description><![CDATA[A few weeks ago I pulled up a chair in front of an aging computer that is shared by many volunteers in order to log their work and do occasional web searches. After an hour or so of doing paperwork, I wanted to look something up on Google, so I selected the word and hit [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-868" title="www Search" src="http://paperjammed.com/wp-content/uploads/2010/01/iStock_000010018988XSmall-300x198.jpg" alt="" width="300" height="198" />A few weeks ago I pulled up a chair in front of an aging computer that is shared by many volunteers in order to log their work and do occasional web searches. After an hour or so of doing paperwork, I wanted to look something up on Google, so I selected the word and hit <strong>Control-C</strong> to copy it and quickly pasted it into the Google search bar, only to be greeted with an unusual error from Google saying that my search text was too long.</p>
<p>And the bits of the search string I saw had nothing to do with what I had copied. Clearly my <strong>Control-C</strong> did not “take” and I had pasted whatever stuff had been hanging around from the prior user.<br />
My curiosity got the better of me and I opened Notepad and did a quick <strong>Control-V</strong> and watched in amazement as a young girl’s secrets were exposed before my eyes.</p>
<p>She is clearly struggling in her relationship with her boyfriend, because she had listed about fifty bad points about him in detail—and some were pretty bad. She then listed a dozen or so good points at the bottom. And I must admit that I read the whole story…and felt a voyeuristic guilt with each word.</p>
<p>I then closed Notepad and purged the clipboard and felt much better.<br />
Of course, that doesn’t change the fact that I will feel uncomfortable the next time I see her. I feel like I snuck into her room and read her diary.</p>
<p>This is what she had done: She had written her personal note in Word or some other tool and then likely decided to email it to herself, so she copied and pasted the sordid details of her love life into Gmail, forgetting to purge the clipboard before going home.</p>
<p>And I, with no malice or intent, bumbled into her secrets.</p>
<p><strong>Learn from the mistakes of others!</strong></p>
<p>When was the last time you used a public computer at the library or worked on a common computer at school or work? Did you leave anything behind?</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2010/01/28/is-there-anything-interesting-lingering-on-your-clipboard/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Could your family access your secrets in an emergency?</title>
		<link>http://paperjammed.com/2010/01/10/could-your-family-access-your-secrets-in-an-emergency/</link>
		<comments>http://paperjammed.com/2010/01/10/could-your-family-access-your-secrets-in-an-emergency/#comments</comments>
		<pubDate>Sun, 10 Jan 2010 18:59:10 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Green Living]]></category>
		<category><![CDATA[Paperless Life]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Knowledge Management]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=851</guid>
		<description><![CDATA[Several weeks ago I was sitting at the dining room table with a family friend going through a stack of documents and letters. Her husband had passed away suddenly some weeks before, and I was doing the best I could to help her untangle the paperwork and understand what was what. This unfortunate scene made [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-853" title="Keys on a keyboard" src="http://paperjammed.com/wp-content/uploads/2010/01/iStock_000008796911XSmall-225x300.jpg" alt="" width="225" height="300" />Several weeks ago I was sitting at the dining room table with a family friend going through a stack of documents and letters. Her husband had passed away suddenly some weeks before, and I was doing the best I could to help her untangle the paperwork and understand what was what. This unfortunate scene made it clear to me that sudden illness or death of a family member may require us to access files that they have, for many reasons.</p>
<p>Imagine that you were to become temporarily incapacitated for whatever reason&#8230;</p>
<ul>
<li>Can a family member log in to your computer, as yourself, in order to access your files?</li>
<li>Can your spouse access your online banking details so the bills can be paid?</li>
<li>Can your family find your insurance information that you scanned and filed away?</li>
<li>Is there someone who can log in to any online accounts that need care and feeding?</li>
</ul>
<p>Not a pleasant subject, indeed, but one that worries me from time to time.</p>
<p>One way to address these needs is to keep all of your passwords and so forth in one special place, using a password safe application, and make sure someone else has the access code. For example, you can use a tool such as <a href="http://agilewebsolutions.com/products/1Password">1Password</a> or <a href="http://www.splashdata.com/splashid/index.asp">SplashId</a> to store hundreds of secret bits that you use all the time, and your family might need.</p>
<p>You might consider writing down the master passwords that control your life and sealing them in an envelope that you provide to a trusted family member. Since this is such a great security risk if found by the enemy, you might want to omit any identifying information from the note. Impress upon them the need to secure the document very well.</p>
<p>Perhaps you can choose the same master password with your spouse, with one relatively short password locking your computer and a long secure password locking your password safe application.</p>
<p>Regardless of how you address these issues, sit down with your better half (or trusted family member) and review where documents are and how to access them.</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2010/01/10/could-your-family-access-your-secrets-in-an-emergency/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Don&#8217;t worry if you didn&#8217;t sanitize your documents—even the TSA forgets occasionally</title>
		<link>http://paperjammed.com/2009/12/08/dont-worry-if-you-didnt-sanitize-your-documents%e2%80%94even-the-tsa-forgets-occasionally/</link>
		<comments>http://paperjammed.com/2009/12/08/dont-worry-if-you-didnt-sanitize-your-documents%e2%80%94even-the-tsa-forgets-occasionally/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 22:29:29 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Paperless Life]]></category>
		<category><![CDATA[Searching and Indexing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[Shredding]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=796</guid>
		<description><![CDATA[It&#8217;s too comical to be true. A few months back, when I wrote an article warning about inadequate attempts at sanitizing PDF documents, I thought that any organization serious about censoring documents would not make such a basic error. Especially not a government agency, after the military had been caught by this pitfall. Apparently this [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-797" title="20091208-redaction1" src="http://paperjammed.com/wp-content/uploads/2009/12/20091208-redaction1.gif" alt="20091208-redaction1" width="361" height="280" />It&#8217;s too comical to be true. A few months back, when I wrote an article <a href="http://paperjammed.com/2009/04/21/keeping-your-secrets-to-yourself—what-can-your-shared-documents-tell-others/">warning about inadequate attempts at sanitizing PDF documents</a>, I thought that any organization serious about censoring documents would not make such a basic error. Especially not a government agency, after the military <a href="http://www.schneier.com/blog/archives/2005/05/pdf_radacting_f.html">had been caught</a> by this pitfall.</p>
<p><a href="http://www.wanderingaramean.com/2009/12/tsa-makes-another-stupid-move.html">Apparently this is not the case</a></p>
<p>It seems that the TSA has leaked their official document of airport security guidelines. ABC News says <a href="http://abcnews.go.com/Blotter/massive-tsa-security-breach-agency-secrets/story?id=9280503">Online Posting Reveals a &#8220;How To&#8221; for Terrorists to Get Through Airport Security</a></p>
<p><a href="http://abcnews.go.com/Blotter/massive-tsa-security-breach-agency-secrets/story?id=9280503"></a><span id="more-796"></span></p>
<p><strong>A Rookie Mistake</strong></p>
<p>Look at the screenshot of the document at the top of this post. Even though a certain part of the document has been blacked out, it is possible to select the text and copy/paste to find out what is hidden behind the black text.</p>
<p>What kinds of things are listed in this document?</p>
<ul>
<li>Photographs of all kinds of official ID cards. Ever wondered what a U.S. Senator&#8217;s ID card looks like?</li>
<li>Procedures for calibrating equipment, such as where guns should be hidden for the testing and such.</li>
<li>Guidelines for who gets searched and who doesn&#8217;t.</li>
<li>Guidelines for what objects get searched and which don&#8217;t.</li>
<li>And much much more!</li>
</ul>
<p>In other words, this was a most unfortunate event.</p>
<p>See for yourself—ABC News (and others) have <a href="http://a.abcnews.go.com/images/Blotter/ht_tsa_screening_2_091208.pdf">posted the document with redactions removed</a>.</p>
<p><strong>Easy as Pie</strong></p>
<p>Here&#8217;s a screenshot of the original document, opened in Adobe Acrobat Professional.</p>
<p><img class="alignnone size-full wp-image-801" title="20091208-redaction2" src="http://paperjammed.com/wp-content/uploads/2009/12/20091208-redaction2.gif" alt="20091208-redaction2" width="500" height="197" /></p>
<p>As you can see, it was a trivial matter to use the <strong>TouchUp Object</strong> tool to gently slide the black rectangle off of the secret stuff (I have blurred the text here, though you can read it from ABC News if you wish).</p>
<p>If you are working with confidential documents that could potentially cause disaster if leaked, <em>please</em> learn how to redact your documents correctly!</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2009/12/08/dont-worry-if-you-didnt-sanitize-your-documents%e2%80%94even-the-tsa-forgets-occasionally/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Keeping your secrets to yourself—old changes lingering in your PDF files</title>
		<link>http://paperjammed.com/2009/11/23/keeping-your-secrets-to-yourself-old-changes-lingering-in-your-pdf-files/</link>
		<comments>http://paperjammed.com/2009/11/23/keeping-your-secrets-to-yourself-old-changes-lingering-in-your-pdf-files/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 04:46:58 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Geeky]]></category>
		<category><![CDATA[PDF]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=781</guid>
		<description><![CDATA[A few months ago I wrote an article that touched upon the problems inherent in attempts to sanitize documents before sending them to the enemy—perhaps to remove competitor&#8217;s names or trade secrets. I was reading a post on a board I frequent where a person was describing exactly this kind of activity—removing sensitive information from [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-791" title="Rusty trap" src="http://paperjammed.com/wp-content/uploads/2009/11/iStock_000011076402XSmall-300x225.jpg" alt="Rusty trap" width="300" height="225" />A few months ago I wrote an article that touched upon <a href="http://paperjammed.com/2009/04/21/keeping-your-secrets-to-yourself—what-can-your-shared-documents-tell-others/">the problems inherent in attempts to sanitize documents</a> before sending them to the enemy—perhaps to remove competitor&#8217;s names or trade secrets.</p>
<p>I was reading a post on a board I frequent where a person was describing exactly this kind of activity—removing sensitive information from PDF documents. Several suggestions were made, but one individual suggested opening the file in Acrobat Pro and replacing the sensitive text with good old <a href="http://www.lipsum.com/">Lorem Ipsum</a>.</p>
<p>It was at that moment that I recalled a peculiar feature of the PDF file format: it is designed to support nondestructive updates, allowing people to make vast changes to a PDF document while still retaining the original document, fully intact. I did a few experiments and was surprised with the results.<span id="more-781"></span></p>
<p><strong>A Brief Note on the PDF File Format</strong></p>
<p>For the geeky types among us, one place to begin is this article:</p>
<p><a href="http://www.mactech.com/articles/mactech/Vol.15/15.09/PDFIntro/">Portable Document Format: An Introduction for Programmers</a></p>
<p>The key points to get out of the article is this: A PDF document is comprised of several distinct sections, a <strong>Header</strong>, a <strong>Body</strong>, an <strong>&#8220;xref&#8221; Table</strong>, and a <strong>Trailer</strong>. At the very end of the file you will find the character sequence <strong>%%EOF</strong></p>
<p>The PDF standard was designed to allow multiple updates to a document, while retaining the original version. This is accomplished by appending anything new to the end of the document, after the original <strong>EOF</strong> tag. The document will now have two <strong>EOF</strong> tags: one indicating where the original document ended, and a new <strong>EOF</strong> tag indicating where the new changes end.</p>
<p>If we wish to revert PDF changes, it should be a simple matter of opening the PDF file in a binary editor, searching for the first <strong>EOF</strong> tag, and deleting everything following.</p>
<p><strong>A Simple Experiment</strong></p>
<p>Let&#8217;s start with a proper secret document containing missile plans&#8230;</p>
<p><img class="alignnone size-full wp-image-785" title="20091123-missile-plans-1" src="http://paperjammed.com/wp-content/uploads/2009/11/20091123-missile-plans-1.gif" alt="20091123-missile-plans-1" width="439" height="418" /></p>
<p>Suppose we want to obscure some special information in paragraph 37. We can open the file in Acrobat Professional and use its text editing features to swap in the venerable <em>Lorem Ipsum</em> text.</p>
<p>Here&#8217;s what it looks like after the switch:</p>
<p><img class="alignnone size-full wp-image-786" title="20091123-lorem-ipsum" src="http://paperjammed.com/wp-content/uploads/2009/11/20091123-lorem-ipsum.gif" alt="20091123-lorem-ipsum" width="598" height="243" /></p>
<p>You can see here that the first seven lines of text starting on paragraph 37 have been replaced with appropriate unreadable text.</p>
<p>Now, open the new PDF file in a binary editor (since PDF files contain a mix of text and binary, the editor must be a binary editor).</p>
<p><img class="alignnone size-full wp-image-787" title="20091123-binary-editor" src="http://paperjammed.com/wp-content/uploads/2009/11/20091123-binary-editor.gif" alt="20091123-binary-editor" width="693" height="633" /></p>
<p>Note the <strong>%%EOF</strong> character sequence embedded in the text. This is the first <strong>EOF</strong> tag, indicating where the original file ended. All we need to do is place the cursor to the right of the <strong>EOF</strong> and delete everything to the end of the file.</p>
<p>Once we have done so, it&#8217;s like magic:</p>
<p><img class="alignnone size-full wp-image-788" title="20091123-after-binary-editing" src="http://paperjammed.com/wp-content/uploads/2009/11/20091123-after-binary-editing.gif" alt="20091123-after-binary-editing" width="794" height="323" /></p>
<p>The edits that replaced lines of paragraph 37 with gibberish have neatly been undone!</p>
<p><strong>More Details</strong></p>
<p>From the <a href="http://www.mactech.com/articles/mactech/Vol.15/15.09/PDFIntro/">PDF Intro document</a> linked earlier:</p>
<p>&#8220;The trailer, it turns out, plays an important role in the way PDF implements incremental updating. The key concept to understand here is that a PDF file is never overwritten, only added to. That goes for all portions of the PDF file &#8211; even the trailer itself, and the end-of-file marker. In other words, a multiply-updated PDF document may contain multiple trailers &#8211; and multiple end-of-file markers! (There may be numerous occurrences of %%EOF.) Each time the file is edited, an addendum is written to the tail of the file, consisting of the content objects that have changed, a new xref section, and a new trailer containing all the information that was in the previous trailer, as well as a /Prev key specifying the byte offset (from the beginning of the file) of the previous xref section. The cross-reference info will then be distributed across more than one xref section. To access all of the cross-references, the reader must walk the list of /Prev keys in all the trailers, in reverse order.</p>
<p>Space doesn&#8217;t permit a detailed exploration of updates here, but you can find several examples in Appendix A of the PDF 1.3 specification (available at <a href="http://partners.adobe.com/asn/developer">http://partners.adobe.com/asn/developer</a>).&#8221;</p>
<p><strong>Summary</strong></p>
<p>It is important to understand that the PDF standard allows for appended updates to files that leave the original document intact, regardless of how drastic the changes are. If you are intent on redacting text from PDF documents, do not depend on simply deleting the secrets using a PDF editor—you must use a proper redaction tool that addresses these issues correctly.</p>
<p>That said, I did some experimenting with a few utilities (Apple Preview, PDFpen, and Adobe Acrobat Pro) and found that some write the file from scratch each time, with no lingering cruft from former versions, while others respect the original intent of the PDF standard. This means that you can&#8217;t trust that older revisions are being retained in your file and you can&#8217;t trust that they aren&#8217;t.</p>
<p>Be conservative: use a redaction tool for secrecy and proper backups for versioning.</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2009/11/23/keeping-your-secrets-to-yourself-old-changes-lingering-in-your-pdf-files/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>HowStuffWorks — How Paperless Offices Work</title>
		<link>http://paperjammed.com/2009/07/03/howstuffworks-%e2%80%94-how-paperless-offices-work/</link>
		<comments>http://paperjammed.com/2009/07/03/howstuffworks-%e2%80%94-how-paperless-offices-work/#comments</comments>
		<pubDate>Sat, 04 Jul 2009 00:30:42 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Green Living]]></category>
		<category><![CDATA[Paperless Life]]></category>
		<category><![CDATA[Workflow]]></category>
		<category><![CDATA[Good Sites]]></category>
		<category><![CDATA[Indexing]]></category>
		<category><![CDATA[Online Services]]></category>
		<category><![CDATA[Organization]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=594</guid>
		<description><![CDATA[I have always been a big fan of HowStuffWorks, with their detailed in-depth articles describing such disparate topics as manual transmissions and money laundering. Anyway, author Diane Dannenfeldt has written a lengthy article on How Paperless Offices Work, giving ample coverage to myriad aspects of the topic: Introduction to How Paperless Offices Work Benefits of [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-full wp-image-595 alignnone" src="http://paperjammed.com/wp-content/uploads/2009/07/20090703-howstuffworks.jpg" alt="20090703-howstuffworks" width="492" height="352" /></p>
<p>I have always been a big fan of HowStuffWorks, with their detailed in-depth articles describing such disparate topics as <a href="http://auto.howstuffworks.com/transmission.htm">manual transmissions</a> and <a href="http://money.howstuffworks.com/money-laundering.htm">money laundering</a>.</p>
<p>Anyway, author Diane Dannenfeldt has written a lengthy article on How Paperless Offices Work, giving ample coverage to myriad aspects of the topic:</p>
<ul>
<li>Introduction to How Paperless Offices Work</li>
<li>Benefits of a Paperless Office</li>
<li>Transitioning to a Paperless Office</li>
<li>Managing Digital Documents</li>
<li>Going Paperless at Home</li>
<li>Paperless Office Solutions</li>
</ul>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Introduction to HoPaperless Offices Work</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Benefits of a Paperless Office</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Transitioning to a Paperless Office</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Managing Digital Documents</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Going Paperless at Home</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Paperless Office Solutions</div>
<p>Take a look at the full article here: <a href="http://communication.howstuffworks.com/how-paperless-offices-work.htm">How Paperless Offices Work</a> (howstuffworks.com)</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2009/07/03/howstuffworks-%e2%80%94-how-paperless-offices-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Banish the kids to their own network!</title>
		<link>http://paperjammed.com/2009/06/02/banish-the-kids-to-their-own-network/</link>
		<comments>http://paperjammed.com/2009/06/02/banish-the-kids-to-their-own-network/#comments</comments>
		<pubDate>Wed, 03 Jun 2009 00:16:43 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Geeky]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Portable Devices]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=557</guid>
		<description><![CDATA[A nastygram from my ISP let me know that I needed to take action to lock down my home network. In this article I discuss using a spare router in a somewhat unusual daisy chain configuration in order to banish the teenagers and all of their wifi devices to their own network.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-560" src="http://paperjammed.com/wp-content/uploads/2009/06/istock_000006562749xsmall-300x210.jpg" alt="" width="300" height="210" />A few weeks ago I received an unpleasant bit of email from my Internet provider. At first, I thought it was yet another lame spammer or phisher sending me some official-looking notice, but after a moment&#8217;s inspection I realized that this was a real <em>bona-fide </em>official notice.</p>
<p>Their network security department very kindly (and politely) informed me that they had received a &#8220;cease and desist&#8221; order from a particular game publisher. They had included the game publisher&#8217;s email, complete with the incriminating evidence.</p>
<p>There it was: logs showing the MAC address of my cable modem being involved in suspicious <a href="http://en.wikipedia.org/wiki/BitTorrent_(protocol)">BitTorrent</a> activities.</p>
<p>Considering that at any time during the week there can be from two to six or seven different teenagers hanging out in my humble abode, carrying virus-ridden machines, the message was clear: I had to get serious about locking down network access<span id="more-557"></span></p>
<p><strong>The Problem</strong></p>
<p>I would have liked to have bought some net filtering software to slap on the offending machine and been done with it, however I knew that this was insufficient.</p>
<p>Even if this one event could be traced to a youthful source, a more ominous danger comes from the inevitable malware and viruses that teenagers collect on their machines as they swap cool stuff with their friends.</p>
<p>Complicating things, there are many devices on our home network: Besides their school laptops, the kids have video game consoles and one has an iPod touch, all with wifi access. Think about how many different gadgets are on <em>your</em> home network.</p>
<p>And shutting off access altogether was not an option—there is still schoolwork to be done!</p>
<p><strong>The answer: A Private Network for the Kids</strong></p>
<p>My solution was to put together an unusual network configuration using a second wireless router; I wanted the ability to manage every single kid-owned device at the flip of a switch, while leaving the grownups untouched.</p>
<p><img class="aligncenter size-full wp-image-568" src="http://paperjammed.com/wp-content/uploads/2009/06/20090602-network-devices.gif" alt="" width="600" height="550" /></p>
<p>I hooked the cable modem (<strong>red</strong>) to the main router, shown in <strong>green</strong>. I then plugged a second wireless router, shown in <strong>blue</strong>, into the first.</p>
<p>By doing this, you can see that there is <em>one single wire</em> connecting the entire <strong>blue</strong> network (the kids) to the <strong>green</strong> network. It was trivial to then configure the green<em> </em>router with appropriate access control and filtering for that one single device: the blue router.</p>
<p><strong>Some quirky details</strong></p>
<p>Home routers like these are, by default, configured with a <a href="http://en.wikipedia.org/wiki/Network_address_translation">NAT</a> firewall. They work sort of like one-way mirrors: someone on the network can see out, but nobody can see in. As a result of this, the kids (<strong>blue</strong> devices) can see any device on the main router (<strong>green</strong> devices), such as our print server and the NAS device, but no one can see <em>into</em> the kids&#8217; network.</p>
<p>As paradoxical as it seems, this is exactly what I wanted. By making the kids&#8217; network a private network, it appears to the green router as a single device. When I am configuring access restrictions, I only need to control access for the blue router&#8217;s IP address or MAC address.</p>
<p>Many consumer-grade routers have flakey firmware that just doesn&#8217;t really behave well when you start doing things like turning on filtering for multiple machines. I simplified things by bringing down the number of controlled devices to <em>one</em>. In addition, if one were to try filtering on the IP addresses or MAC addresses of individual machines, this can be easily defeated by manually changing the IP address or MAC address. With my configuration, the MAC address being filtered is the blue router, locked away safely.</p>
<p><strong>The Finer Points</strong></p>
<p>If you want to set up a network like this, do the following:</p>
<ul>
<li>(Recommended) Reset the kids&#8217; router. Hold the hard reset button on the router in while you turn on power; hold the button for 15 seconds or so.</li>
<li>Hook the kids&#8217; router up to a spare laptop using an Ethernet cable. (Turn off the wireless of the laptop for the time being).</li>
<li>Use the laptop to navigate to the configuration web page (usually 192.168.1.1).</li>
<li>Set the router&#8217;s own address to a <em>different</em> network from the main network, such as 192.168.<strong>2</strong>.1. <em>This is critical</em>.</li>
<li>Configure the router&#8217;s gateway and DHCP server entries to all point to the <em>main</em> router (192.168.1.1). This tells the kids&#8217; router to use the main router as a source for its DHCP lookups and such, rather than going to cable modem.</li>
<li>Navigate to the configuration web page at the new address (192.168.2.1). You may need to close the browser and replug the Ethernet cable.</li>
<li>Set up your wireless security for the kids however you like. Make sure to choose a different channel and SSID from your main router.</li>
<li>Remove the laptop and plug the WAN port of the kids&#8217; router into one of the LAN ports of the main router. Restart everything.</li>
<li>Test both networks to make sure things work the way you think they should.</li>
<li>(Optional) You might want to connect to the kids&#8217; router and set it&#8217;s external IP address statically. Make sure that this is set to a number on the home network (e.g. 192.168.1.2).</li>
</ul>
<p>Some notes:</p>
<ul>
<li>You can only maintain the kids&#8217; router from a machine connected to the kids&#8217; network; the home network cannot see the management screens. If you wish, you could enable remote management for the kids&#8217; network only, since the main home router is still protecting the whole network from intruders.</li>
<li>Computers on the kids&#8217; network can see all devices, but they aren&#8217;t on the same network. This means that network printers and NAS devices are accessible, but you will have to attach to them using IP addresses. I was able to easily set up the machines on the 192.168.2.1 network to use a print server on 192.168.1.100.</li>
<li>For machines that should have full access (a.k.a. <em>yours</em>), make sure that you either set the <strong>green</strong> network to be a higher priority or remove the <strong>blue</strong> network SSID entry altogether. I found out the hard way that my iMac would randomly pick the green or the blue depending on which one it saw first when it woke up.</li>
<li>This does <em>not</em> wall off your main network; it simply provides a single point of control to the entire kids&#8217; network. In other words, don&#8217;t depend on this setup to prevent malware on the kids machines from seeing your machine. You can, however, set up your PC to not trust the kids&#8217; network.</li>
</ul>
<p><strong>Wireless Network Security</strong></p>
<p>Regardless of how you set up your network, make sure you use at least WPA encryption (Never use WEP!). Make sure your passwords are solid.</p>
<p><strong>Using DD-WRT on my new wireless router</strong></p>
<p>In addition to the new network configuration, I went one step further and chose a main router that lends itself well to installation of open-source firmware. I ordered a <a href="http://www.amazon.com/Linksys-Cisco-WRT54GL-Wireless-G-Broadband-Compatible/dp/B000BTL0OA/ref=sr_1_1?ie=UTF8&amp;s=electronics&amp;qid=1243905597&amp;sr=8-1">Linksys WRT54GL</a> from Amazon for a little over fifty bucks. I chose this one because, as a direct descendent of the venerable <a href="http://en.wikipedia.org/wiki/WRT54G">WRT54G</a>, this router is very well suited for running alternative firmware such as <a href="http://en.wikipedia.org/wiki/Dd-wrt">DD-WRT</a>, giving substantial control over things like, say, access control&#8230;</p>
<p>Within a half hour after my new router arrived, I had gone to the <a href="http://www.dd-wrt.com/dd-wrtv3/dd-wrt/hardware.html">Supported Hardware</a> page, obtained the latest build of DD-WRT, and replaced the Linksys firmware with the far-better open source code.</p>
<p>I won&#8217;t go into the specifics of installation here, but it isn&#8217;t very challenging. Check out the <a href="http://www.dd-wrt.com/dd-wrtv3/index.php">DD-WRT site</a> for details.</p>
<p><strong>Closing Thoughts</strong></p>
<p>Make no mistake: we are responsible for whatever goes on our home networks. Just like your home telephone; if someone dials up some 900 number and rings up a thousand-dollar phone bill, the phone company won&#8217;t care a whit who did it, you will still pay. Likewise, regardless of who did the BitTorrent download, there is a certain degree of responsibility of the homeowner to lock down the network.</p>
<p>Another point: Without some degree of personal responsibility on the part of the kids in the house, this sort of activity would simply be an arms race of filtering and blocking versus hacking. My goal is to help keep the honest people honest and to make life more difficult for the viruses and malware.</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2009/06/02/banish-the-kids-to-their-own-network/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

