<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Marcus Povey &#187; Security</title>
	<atom:link href="http://www.marcus-povey.co.uk/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.marcus-povey.co.uk</link>
	<description>Making the world a better place, one byte at a time...</description>
	<lastBuildDate>Mon, 06 Feb 2012 19:13:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.1</generator>
	<atom:link rel='hub' href='http://www.marcus-povey.co.uk/?pushpress=hub'/>
		<item>
		<title>Reporting online terrorists</title>
		<link>http://www.marcus-povey.co.uk/2010/02/04/reporting-online-terrorists/</link>
		<comments>http://www.marcus-povey.co.uk/2010/02/04/reporting-online-terrorists/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 18:43:32 +0000</pubDate>
		<dc:creator>Marcus Povey</dc:creator>
				<category><![CDATA[bct]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[barcamp transparency]]></category>
		<category><![CDATA[innovate]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[surveillance]]></category>
		<category><![CDATA[terrorists]]></category>

		<guid isPermaLink="false">http://www.marcus-povey.co.uk/?p=426</guid>
		<description><![CDATA[There was a small ripple around the internet this morning caused by the Home office opening up the Beta terrorist reporting tool. To what extent the reports from this tool are monitored is unclear, but I suspect this will cause more problems that it solves. Even before we consider the rather broad definition the government [...]]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter" title="Direct government terrorist reporting tool" src="http://farm5.static.flickr.com/4054/4329838363_c744d463e9.jpg" alt="" width="500" height="421" /></p>
<p>There was a small ripple around the internet this morning caused by the Home office opening up the Beta <a href="https://reporting.direct.gov.uk/">terrorist reporting tool</a>.</p>
<p>To what extent the reports from this tool are monitored is unclear, but I suspect this will cause more problems that it solves.</p>
<p>Even before we consider the <a href="http://www.direct.gov.uk/en/CrimeJusticeAndTheLaw/Counterterrorism/DG_183993">rather broad definition the government has for illegal material</a> (which on the face of it could cover a number of science and religious texts), I can see the tool quickly becoming buried under false positives &#8211; whether through over sensitive citizens or through plain vindictiveness &#8211; which would need to be investigated.</p>
<p>Even if no further action is taken after the investigation, the cost in both time and resources must surely represent a significant risk that things that are actually a threat will be missed.</p>
<div class="wsbuttons">
	<div class="shareblob facebook">
		<div class="fb-like" data-href="http://www.marcus-povey.co.uk/2010/02/04/reporting-online-terrorists/" data-send="false" data-layout="box_count" data-width="60" data-show-faces="false" data-colorscheme="light"></div>
	</div>

	<div class="shareblob google">
		<div class="g-plusone" data-size="tall" data-href="http://www.marcus-povey.co.uk/2010/02/04/reporting-online-terrorists/"></div>
	</div>

	<div class="shareblob twitter">
		<div class="twitter">
			<a href="https://twitter.com/share?url=http%3A%2F%2Fwww.marcus-povey.co.uk%2F2010%2F02%2F04%2Freporting-online-terrorists%2F&count=vertical" class="twitter-share-button" data-lang="en">Tweet</a>
			<script>!function(d,s,id){var js,fjs=d.getElementsByTagName(s)[0];if(!d.getElementById(id)){js=d.createElement(s);js.id=id;js.src="//platform.twitter.com/widgets.js";fjs.parentNode.insertBefore(js,fjs);}}(document,"script","twitter-wjs");</script>
		</div>
	</div>

</div>
	]]></content:encoded>
			<wfw:commentRss>http://www.marcus-povey.co.uk/2010/02/04/reporting-online-terrorists/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Fake police at Canary Wharf</title>
		<link>http://www.marcus-povey.co.uk/2009/10/19/fake-police-at-canary-wharf/</link>
		<comments>http://www.marcus-povey.co.uk/2009/10/19/fake-police-at-canary-wharf/#comments</comments>
		<pubDate>Mon, 19 Oct 2009 12:42:30 +0000</pubDate>
		<dc:creator>Marcus Povey</dc:creator>
				<category><![CDATA[bct09]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[canary wharf]]></category>
		<category><![CDATA[love]]></category>
		<category><![CDATA[police]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.marcus-povey.co.uk/?p=347</guid>
		<description><![CDATA[A few days ago my father &#8211; a passionate amateur photographer &#8211; fell foul of Canary Wharf&#8217;s pretend police. His crime? Taking a photo of a shadow of a tree on a building. Initially it was two fake police which challenged him, demanding that he show them what photos he took on his camera. This [...]]]></description>
			<content:encoded><![CDATA[<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://www.youtube.com/v/4cvay_r2FK8&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;feature=player_embedded&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/4cvay_r2FK8&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;feature=player_embedded&amp;fs=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>A few days ago my father &#8211; a passionate amateur photographer &#8211; fell foul of Canary Wharf&#8217;s pretend police. His crime? Taking a photo of a shadow of a tree on a building.</p>
<p>Initially it was two fake police which challenged him, demanding that he show them what photos he took on his camera. This <a href="http://www.flickr.com/photos/garrettc/2454203221/">not even the real police are entitled to do</a>, and fake police certainly can not (since they have no more rights than you or I).</p>
<p>He quite rightly refused, at which point the fake coppers prevented him from leaving, and so committed the <a href="http://en.wikipedia.org/wiki/False_imprisonment">first actual crime</a>.</p>
<p>More fake police arrived and the situation became increasingly tense, the fake police demanded that he show them the photos citing &#8220;terrorism&#8221; and &#8220;9/11&#8243; and &#8220;The current climate&#8221; and said that taking a photo of a shadow was &#8220;not what normal people did&#8221;.</p>
<p>They threatened him by their physical presence, <a href="http://en.wikipedia.org/wiki/False_imprisonment">preventing him from leaving</a>, and threatened to call the police. To which my father requested that they do so since it was the private security agents who were breaking the law (they of course didn&#8217;t call them).</p>
<p>The intimidation continued for about 40 minutes becoming increasingly farcical until the supervisor turned up, who was much less confrontational and admitted that they had no right to demand to see his photos or to detain him. My father, who was not feeling very well and was getting tired, showed the photo and was finally permitted to leave.</p>
<p>To his credit, my father kept his cool throughout although he now wishes that he hadn&#8217;t capitulated. We are now investigating possible legal action against the private security firm responsible and their agents.</p>
<p>This sort of scenario appears to be happening more often, and it is happening thanks to the passive co-operation of the public. It is understandable that people do give in at times &#8211; especially in situations like this where 20 odd 6ft something men were sent to intimidate one gentlemen in his 60s carrying a camera, however it is the general climate of passive acceptance that lets governments and corporations think we can get away with it.</p>
<p>Fundamentally, you have the right to film, take photos, say, do or be anything and you don&#8217;t need permission to do so. This is the essence of freedom, and to let this right &#8211; which (if you excuse the hyperbole) was paid for with the blood of your ancestors &#8211; be lost is the only crime that really matters.</p>
<div class="wsbuttons">
	<div class="shareblob facebook">
		<div class="fb-like" data-href="http://www.marcus-povey.co.uk/2009/10/19/fake-police-at-canary-wharf/" data-send="false" data-layout="box_count" data-width="60" data-show-faces="false" data-colorscheme="light"></div>
	</div>

	<div class="shareblob google">
		<div class="g-plusone" data-size="tall" data-href="http://www.marcus-povey.co.uk/2009/10/19/fake-police-at-canary-wharf/"></div>
	</div>

	<div class="shareblob twitter">
		<div class="twitter">
			<a href="https://twitter.com/share?url=http%3A%2F%2Fwww.marcus-povey.co.uk%2F2009%2F10%2F19%2Ffake-police-at-canary-wharf%2F&count=vertical" class="twitter-share-button" data-lang="en">Tweet</a>
			<script>!function(d,s,id){var js,fjs=d.getElementsByTagName(s)[0];if(!d.getElementById(id)){js=d.createElement(s);js.id=id;js.src="//platform.twitter.com/widgets.js";fjs.parentNode.insertBefore(js,fjs);}}(document,"script","twitter-wjs");</script>
		</div>
	</div>

</div>
	]]></content:encoded>
			<wfw:commentRss>http://www.marcus-povey.co.uk/2009/10/19/fake-police-at-canary-wharf/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Elgg 1.0 gatekeeper functions</title>
		<link>http://www.marcus-povey.co.uk/2008/05/29/elgg-10-gatekeeper-functions/</link>
		<comments>http://www.marcus-povey.co.uk/2008/05/29/elgg-10-gatekeeper-functions/#comments</comments>
		<pubDate>Thu, 29 May 2008 15:45:27 +0000</pubDate>
		<dc:creator>Marcus Povey</dc:creator>
				<category><![CDATA[elgg]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.marcus-povey.co.uk/?p=39</guid>
		<description><![CDATA[This is just a quick post to introduce a pair of functions I wrote today while working on some of the Elgg 1.0 access control code. Namely, call_gatekeeper($function, $file = "") and callpath_gatekeeper($path, $include_subdirs = true), both of which return a boolean value. call_gatekeeper() This function tests to see whether it has the given method/function [...]]]></description>
			<content:encoded><![CDATA[<p>This is just a quick post to introduce a pair of functions I wrote today while working on some of the Elgg 1.0 access control code.</p>
<p>Namely, <code>call_gatekeeper($function, $file = "")</code> and <code>callpath_gatekeeper($path, $include_subdirs = true)</code>, both of which return a boolean value.</p>
<p><strong>call_gatekeeper()</strong></p>
<p>This function tests to see whether it has the given method/function (optionally also test that it is defined in a specified file) exists on the call stack.</p>
<p>The function will return <code>true</code> if the called by the named function (or its parent was called by the named function).</p>
<p>Here is an example of its usage:</p>
<blockquote><p><code>function my_secure_function()<br />
{<br />
if (!call_gatekeeper("my_call_function"))<br />
return false;<br />
... do secure stuff ...<br />
}</code></p>
<p><code>function my_call_function()<br />
{<br />
// will work<br />
my_secure_function();<br />
}</code></p>
<p><code>function bad_function()<br />
{<br />
// Will not work<br />
my_secure_function();<br />
}</code></p></blockquote>
<p>To specify a method instead of a function, pass an array to <code>$function</code> containing the classname and method name.</p>
<p><strong>callpath_gatekeeper()</strong></p>
<p>This function is similar to <code>call_gatekeeper()</code> but returns <code>true</code> if it is being called by a method or function which has been defined on a given path or by a specified file.</p>
<p>The function accepts two parameters:</p>
<p><code>$path</code>, which is either the full path of the desired file or a partial path. If a partial path is given and <code>$include_subdirs</code> is <code>true</code>, then the function will return <code>true</code> if called by any function in or below the specified path.</p>
<div class="wsbuttons">
	<div class="shareblob facebook">
		<div class="fb-like" data-href="http://www.marcus-povey.co.uk/2008/05/29/elgg-10-gatekeeper-functions/" data-send="false" data-layout="box_count" data-width="60" data-show-faces="false" data-colorscheme="light"></div>
	</div>

	<div class="shareblob google">
		<div class="g-plusone" data-size="tall" data-href="http://www.marcus-povey.co.uk/2008/05/29/elgg-10-gatekeeper-functions/"></div>
	</div>

	<div class="shareblob twitter">
		<div class="twitter">
			<a href="https://twitter.com/share?url=http%3A%2F%2Fwww.marcus-povey.co.uk%2F2008%2F05%2F29%2Felgg-10-gatekeeper-functions%2F&count=vertical" class="twitter-share-button" data-lang="en">Tweet</a>
			<script>!function(d,s,id){var js,fjs=d.getElementsByTagName(s)[0];if(!d.getElementById(id)){js=d.createElement(s);js.id=id;js.src="//platform.twitter.com/widgets.js";fjs.parentNode.insertBefore(js,fjs);}}(document,"script","twitter-wjs");</script>
		</div>
	</div>

</div>
	]]></content:encoded>
			<wfw:commentRss>http://www.marcus-povey.co.uk/2008/05/29/elgg-10-gatekeeper-functions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Most current IT security practices are a waste of time</title>
		<link>http://www.marcus-povey.co.uk/2008/02/07/most-current-it-security-practices-are-a-waste-of-time/</link>
		<comments>http://www.marcus-povey.co.uk/2008/02/07/most-current-it-security-practices-are-a-waste-of-time/#comments</comments>
		<pubDate>Thu, 07 Feb 2008 23:38:28 +0000</pubDate>
		<dc:creator>Marcus Povey</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[it]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[strength in depth]]></category>

		<guid isPermaLink="false">http://www.marcus-povey.co.uk/2008/02/07/most-current-it-security-practices-are-a-waste-of-time/</guid>
		<description><![CDATA[While I do believe some of the analogies to be somewhat erroneous, I find myself broadly agreeing with the points raised in this article about current security practices. We in the industry often find ourselves focusing on the more technical issues &#8211; patches, penetration testing etc. These fall well within the IT department&#8217;s sphere of [...]]]></description>
			<content:encoded><![CDATA[<p>While I do believe some of the analogies to be somewhat <span class="ital-inline">erroneous, I find myself broadly agreeing with the points raised in <a href="http://www.darkreading.com/document.asp?doc_id=145224&amp;WT.svl=news1_1">this article about current security practices</a>.</span></p>
<p>We in the industry often find ourselves focusing on the more technical issues &#8211; patches, penetration testing etc. These fall well within the IT department&#8217;s sphere of understanding. They are sexy issues.</p>
<p>Certainly more interesting than matters of staff training, but as the article points out this is likely to be a much bigger win than ensuring everyone is using 28 character passwords or that company computers get patches the second they are available.</p>
<blockquote><p>&#8220;Employee training sometimes gets a bad rap because it doesn&#8217;t alter the behavior of every employee who takes it,&#8221; he said. &#8220;But if I can reduce the number of security incidents by 30 percent through a $10,000 security awareness program, doesn&#8217;t that make more sense than spending $1 million on an antivirus upgrade that only reduces incidents by 2 percent?&#8221;</p></blockquote>
<p>I am a big fan of the &#8220;strength in depth&#8221; approach to IT security and I believe that one should never rely too much on one technique. It doesn&#8217;t hurt to lock things down &#8211; decent passwords are certainly not going to do any harm &#8211; but I agree the big hits are probably going to be elsewhere.</p>
<p>However all the fancy security software in the world is not going to stop untrained staff doing something &#8216;unfortunate&#8217; like sending the bank details of 25 million people through the post on two unencrypted CDs.</p>
<p>Crucially, for real security I think one should plan for failure and make sure that it is not the end of the world if something <em>does</em> happen. Backups, encrypting confidential data, as well as ensuring you have a firewall set up and configure correctly are all parts of a consolidated defence.</p>
<p>In short. Make sure your doors and windows are locked, but keep valuables out of sight and make sure you&#8217;ve taken out an insurance policy&#8230; and tell your flatmate not to let dodgy masked men with &#8220;swag&#8221; written on a sack wander around your apartment.</p>
<div class="wsbuttons">
	<div class="shareblob facebook">
		<div class="fb-like" data-href="http://www.marcus-povey.co.uk/2008/02/07/most-current-it-security-practices-are-a-waste-of-time/" data-send="false" data-layout="box_count" data-width="60" data-show-faces="false" data-colorscheme="light"></div>
	</div>

	<div class="shareblob google">
		<div class="g-plusone" data-size="tall" data-href="http://www.marcus-povey.co.uk/2008/02/07/most-current-it-security-practices-are-a-waste-of-time/"></div>
	</div>

	<div class="shareblob twitter">
		<div class="twitter">
			<a href="https://twitter.com/share?url=http%3A%2F%2Fwww.marcus-povey.co.uk%2F2008%2F02%2F07%2Fmost-current-it-security-practices-are-a-waste-of-time%2F&count=vertical" class="twitter-share-button" data-lang="en">Tweet</a>
			<script>!function(d,s,id){var js,fjs=d.getElementsByTagName(s)[0];if(!d.getElementById(id)){js=d.createElement(s);js.id=id;js.src="//platform.twitter.com/widgets.js";fjs.parentNode.insertBefore(js,fjs);}}(document,"script","twitter-wjs");</script>
		</div>
	</div>

</div>
	]]></content:encoded>
			<wfw:commentRss>http://www.marcus-povey.co.uk/2008/02/07/most-current-it-security-practices-are-a-waste-of-time/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

