<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>binaryfactory.ca &#187; Security</title>
	<atom:link href="http://blog.binaryfactory.ca/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.binaryfactory.ca</link>
	<description>..by Guillaume Ross</description>
	<lastBuildDate>Thu, 11 Aug 2011 21:47:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Cyber-Ark Enterprise Vault &#8211; Password management</title>
		<link>http://blog.binaryfactory.ca/2010/11/cyber-ark-enterprise-vault-password-management/</link>
		<comments>http://blog.binaryfactory.ca/2010/11/cyber-ark-enterprise-vault-password-management/#comments</comments>
		<pubDate>Tue, 30 Nov 2010 01:11:21 +0000</pubDate>
		<dc:creator>Guillaume</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.binaryfactory.ca/?p=458</guid>
		<description><![CDATA[I&#8217;ve spent some time in the last weeks testing Cyber-Ark&#8217;s Enterprise Password Vault. First of all, let me say that I am in no way associated with them, and that this post reflects only my opinion of the software, and not that of any of my clients. This is not a review of the tool, [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Cyber-Ark Logo" src="http://www.cyber-ark.com/img/interface/logo.gif" alt="Cyber-Ark Logo" width="190" height="44" /></p>
<p>I&#8217;ve spent some time in the last weeks testing Cyber-Ark&#8217;s Enterprise Password Vault. First of all, let me say that I am in no way associated with them, and that this post reflects only my opinion of the software, and not that of any of my clients. This is not a review of the tool, but a bit of information on it and on why everyone should think about using such a solution to secure credentials and become compliant with various laws, guidelines, best practices and policies.</p>
<p><strong>What&#8217;s Cyber-Ark Enterprise Password Vault?</strong></p>
<p>Cyber-Ark&#8217;s password management environment is made out of multiple separate, secure pieces. At the core of the solution is the Cyber-Ark Vault itself. This server runs on a secured Windows server OS, with no standard services running, and with multiple security layers added. This machine can be considered as an &#8220;appliance&#8221;, as it is very different from a stock Windows environment. This is what will store files, which in the case of the Enterprise password vault, represent passwords. The vault can be highly available, in a cluster, and replicated as well.</p>
<p>In order to use those files, an interface is needed. The best way to do this is using the Password Vault Web Access, which resides on a web server and communicates with the Vault using proprietary protocols. This allows all systems administrators, operators, developers, etc, to access the vault without needing particular client software.</p>
<p>The third important block is the CPM (Central Password Manager), which will act as the enforcer of policies and as a bridge between the vault containing the accounts and the machines where they are used, when necessary.</p>
<p><strong>Why should it be used?</strong></p>
<p>A solution such as this one should be used at least to store &#8220;generic&#8221; accounts, while providing separation of duty, auditing, and ease of management. A good example would be the built-in Administrator account of an Active Directory domain. In many cases, the enterprise will want to keep this password somewhere, in case it is ever needed. However, if anyone knows it, there can be no traceability proof if something is done using it.</p>
<p>Companies often design complex pen and paper based systems to store these accounts, often in separate parts, in different safes, in different locations. This is all well until there are just too many generic accounts to keep track of. By using a good password vault product, you should be able to separate duties between password owners and users. Allow management to approve requests for viewing the passwords, allow sysadmins to reset some passwords but not others, and most importantly, log every access to those passwords.</p>
<p>Once someone has seen the password, it is important that it be changed. This is where the CPM comes handy. It is able to change passwords for multiple platforms. Coupled with the ability to delegate only &#8220;connect&#8221; access (basically, establishing a direct RDP or SSH session with the credentials without showing the password), it can be used to manage a list of passwords that should never be known by anyone until they need to be used. This can also be used to share accounts on systems that do not support multiple users. By changing the password every time it is used, and logging everything, even an appliance that only has a &#8220;root&#8221; user now has some traceability.</p>
<p>Another great improvement to security that can be made is proper management of service accounts. Many service accounts in environments are set to not expire, as they are to be managed manually.. this means that a lot of manual labor will be done managing them, or in many cases, that they will simply not be managed. Now, with a product such as this one, you can discover what service accounts are being used for what service on what server, as well as enable central management. Yes, this means that it can connect back to Windows servers (among others) and change the passwords used to start up services so that they match. This effectively means that service accounts could be set up with a temporary password during installation, and once managed by the tool, never seen or known again.</p>
<p>Do yourself a favor, and start studying those solutions. Start by storing &#8220;generic&#8221; and built-in administrative credentials, and work your way up to shared accounts and service accounts. Once they are all in the vault, you can start experimenting with automated management features. It is better to start now and have something ready to use than to wait until something bad happens and then do it in a hurry..</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.binaryfactory.ca/2010/11/cyber-ark-enterprise-vault-password-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>QoS For Facetime (And Firewall config)</title>
		<link>http://blog.binaryfactory.ca/2010/09/qos-for-facetime-and-firewall-config/</link>
		<comments>http://blog.binaryfactory.ca/2010/09/qos-for-facetime-and-firewall-config/#comments</comments>
		<pubDate>Fri, 03 Sep 2010 00:36:21 +0000</pubDate>
		<dc:creator>Guillaume</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Gadgets]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.binaryfactory.ca/?p=450</guid>
		<description><![CDATA[To get facetime working on your firewall you need to be sure some ports can be used. For most home users this won&#8217;t be a problem but it may be different at work. Here is the Apple KB Article on it : http://support.apple.com/kb/HT4245 If the Wi-Fi network router that you are connected to uses a [...]]]></description>
			<content:encoded><![CDATA[<p>To get facetime working on your firewall you need to be sure some ports can be used. For most home users this won&#8217;t be a problem but it may be different at work. Here is the Apple KB Article on it :</p>
<p>http://support.apple.com/kb/HT4245</p>
<blockquote><p>If the Wi-Fi network router that you are connected to uses a firewall or security software to restrict Internet access, contact the network administrator and reference this technical article. To use FaceTime on a restricted Wi-Fi network, port forwarding must be enabled for ports 443 (TCP), 3478–3497 (UDP), 16384–16386 (UDP), and 16393–16402 (UDP).</p></blockquote>
<p>Make sure those UDP port ranges have a good priority in your QoS configuration and you should be good to go. It is worth noting that DNS and HTTP must be open to the outside as well, but they are probably used only to establish the call (same for HTTPS/443) so the QoS config should not matter.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.binaryfactory.ca/2010/09/qos-for-facetime-and-firewall-config/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to apply a temporary GPO to a machine being imaged</title>
		<link>http://blog.binaryfactory.ca/2010/03/how-to-apply-a-temporary-gpo-to-a-machine-being-imaged/</link>
		<comments>http://blog.binaryfactory.ca/2010/03/how-to-apply-a-temporary-gpo-to-a-machine-being-imaged/#comments</comments>
		<pubDate>Sat, 27 Mar 2010 00:20:50 +0000</pubDate>
		<dc:creator>Guillaume</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[Imaging]]></category>
		<category><![CDATA[Tip]]></category>

		<guid isPermaLink="false">http://blog.binaryfactory.ca/?p=413</guid>
		<description><![CDATA[Depending on how you use Active Directory in your organization, you may be setting a lot of security policies on workstations, and some of these settings can be problematic during the automated build of computers. A few workarounds exist to avoid applying those to the workstations being imaged: * Create a temporary OU for the [...]]]></description>
			<content:encoded><![CDATA[<p>Depending on how you use Active Directory in your organization, you may be setting a lot of security policies on workstations, and some of these settings can be problematic during the automated build of computers.</p>
<p>A few workarounds exist to avoid applying those to the workstations being imaged:</p>
<p>* Create a temporary OU for the computer account, and move it to the proper location once the build is done<br />
* Change the order of the steps in your build to avoid issues caused by security settings<br />
* Configure a GPO to override the settings that need to be set only during deployment, and filter that only to machines being used.</p>
<p>For multiple different reasons, I had to use the last option. It is a rather clean option, as it doesn&#8217;t involve moving computer accounts after the build or any chances on the domain during the imaging process, other than joining the machine, which is great.</p>
<p>One word of notice: Make sure whatever you are overriding is not a must for security and is simply an &#8220;annoyance&#8221;, because eventually (within a few minutes probably), a user WILL figure out how you&#8217;re doing the filtering and WILL apply it to his own machine, in order to bypass some security settings.</p>
<p>Only a few steps are involved :</p>
<p>1) Create a GPO that will set the values to what they need to be during the build (don&#8217;t link it yet)</p>
<p>2) Create a WMI filter called &#8220;BoxBeingBuilt&#8221; or something similar. Have it do a query on something you know is true only during imaging. If you can&#8217;t find anything reliable, do something like this:</p>
<p>Select * from Win32_Environment Where Name = &#8220;BuildinDaBox&#8221;</p>
<p>3) Ensure your built process sets a system variable with that name at the beginning, and removes it at the end.</p>
<p>Tada!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.binaryfactory.ca/2010/03/how-to-apply-a-temporary-gpo-to-a-machine-being-imaged/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpsMgr &#8211; Problems deploying through Windows Firewall</title>
		<link>http://blog.binaryfactory.ca/2010/02/opsmgr-problems-deploying-through-windows-firewall/</link>
		<comments>http://blog.binaryfactory.ca/2010/02/opsmgr-problems-deploying-through-windows-firewall/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 23:06:03 +0000</pubDate>
		<dc:creator>Guillaume</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[MOM]]></category>
		<category><![CDATA[SCOM]]></category>
		<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://blog.binaryfactory.ca/?p=401</guid>
		<description><![CDATA[Having issues pushing SCOM through the Windows firewall? You opened the Remote Administration exception, you can ping it, you can browse shares, file and print sharing is enabled, yet it still fails? There is one thing I have not seen documented in the SCOM installation/deployment guides: The agent actually adds an exception for itself when [...]]]></description>
			<content:encoded><![CDATA[<p>Having issues pushing SCOM through the Windows firewall?</p>
<p>You opened the Remote Administration exception, you can ping it, you can browse shares, file and print sharing is enabled, yet it still fails?</p>
<p>There is one thing I have not seen documented in the SCOM installation/deployment guides: The agent actually adds an exception for itself when it runs, so if you block local exceptions (What&#8217;s the point of having a GPO for the firewall config on your serves if you don&#8217;t?) , it will fail.</p>
<p>Add this to your Firewall policy, as a program exception:<br />
<span style="font-family: Verdana; font-size: x-small;">%SystemRoot%\422C3AB1-32E0-4411-BF66-A84FEEFCC8E2\MOMAgentInstaller.exe</span></p>
<p><span style="font-family: Verdana; font-size: x-small;">Be sure to open it for the proper IPs only for added security. Then try to push it again..</span></p>
<p><span style="font-family: Verdana; font-size: x-small;">Good luck!</span></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.binaryfactory.ca/2010/02/opsmgr-problems-deploying-through-windows-firewall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EFS Recovery &#8211; Problems with Ntbackup</title>
		<link>http://blog.binaryfactory.ca/2009/11/efs-recovery-problems-with-ntbackup/</link>
		<comments>http://blog.binaryfactory.ca/2009/11/efs-recovery-problems-with-ntbackup/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 23:49:32 +0000</pubDate>
		<dc:creator>Guillaume</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Backup]]></category>
		<category><![CDATA[EFS]]></category>
		<category><![CDATA[Encryption]]></category>

		<guid isPermaLink="false">http://blog.binaryfactory.ca/?p=373</guid>
		<description><![CDATA[If you are trying to perform EFS recovery by backing up encrypted files on a client machine and sending the backup file to a dedicated recovery workstation, remember this: 1) You need to be a local admin while performing the backup, and the restore, in order to back up the data stream even though you [...]]]></description>
			<content:encoded><![CDATA[<p>If you are trying to perform EFS recovery by backing up encrypted files on a client machine and sending the backup file to a dedicated recovery workstation, remember this:</p>
<p>1) You need to be a local admin while performing the backup, and the restore, in order to back up the data stream even though you don&#8217;t have access to the encrypted files.</p>
<p>2) If a policy is disabling EFS on the recovery workstation, ntbackup won&#8217;t tell you that it can&#8217;t create the encrypted files because EFS is disabled. No. It will simply SKIP the files. So if you have files that get skipped, try to manually create a folder and encrypt it. It has to work else you will not be able to restore the backup properly..</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.binaryfactory.ca/2009/11/efs-recovery-problems-with-ntbackup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New PGP Key !</title>
		<link>http://blog.binaryfactory.ca/2009/08/new-pgp-key/</link>
		<comments>http://blog.binaryfactory.ca/2009/08/new-pgp-key/#comments</comments>
		<pubDate>Sun, 02 Aug 2009 02:50:42 +0000</pubDate>
		<dc:creator>Guillaume</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.binaryfactory.ca/?p=316</guid>
		<description><![CDATA[Here&#8217;s my new PGP key, valid until August 1st, 2014. Yeah, I&#8217;m kind of sick of generating new ones yearly. &#8212;&#8211;BEGIN PGP PUBLIC KEY BLOCK&#8212;&#8211; Version: GnuPG v1.4.9 (Darwin) mQGiBEpzqR8RBADk2w/POIp9FYMdCUOcbRuP5fHEWGyxrAdb19KjTHoHH+L4fk2c zy5IuvUhYZdC97mBr6S2Pg2bdXcxnSCtCIjeW78q6d6gmjoup0A5dvqNaK4xvWFo m8LvBochSIl/LjMsyvL7Jbm4rwfKNJVm5aTe5ZcoT97QdI8IxAW10XaLuwCg53R8 F/Ty6yeY2pwxnE7HZGcggCsEAIUbFiGcapUJI1IraYqBQbtjXL8/sX5hqcIdJ3K8 k+LJclIswiR7YYvJPjtiHCe9pe/SnUrOCjN8eygjlQIgWpNYHcMbhobECBR4Q4MU 4CF20tndFmyZU5BkLeUzItn9WE4W4Ib/6Ny5dQYQ7cSipKV4HsOWNXM+onng6N82 /KvxA/9B+5L0e6y7paFbaWkuq9XvcP3UfW3HewAi3WlvChMQ5zWuDSfsgCfEmxIo 1zz9hai6lBcbZinD4pdcWtDI9lHztRoqiSmMMvcZr+TX76ykCERvF1uo++19uH2H B3pXjTs4wdPZ2XyXfcDWJzl7IrciXLK3J91I+IfLrlYnqRZx3rRcR3VpbGxhdW1l IFJvc3MgKFRoaXMga2V5IHdpbGwgYmUgdmFsaWQgdW50aWwgQXVndXN0IDFzdCwg MjAxNC4pIDxndWlsbGF1bWVAYmluYXJ5ZmFjdG9yeS5jYT6IZgQTEQIAJgUCSnOp HwIbIwUJCWdnoQYLCQgHAwIEFQIIAwQWAgMBAh4BAheAAAoJECFth7cSBE0ry3kA oMt+O/tKLwELxFE6pct9Sl/bE17yAKCnJml9k4Gj8DyaBlYFnfMzRPkrWbkCDQRK c6kfEAgAjuBEe96GS3/umwzbdxNBlnh0Fodshq30+aGcxyPOij5muUCeNkw2ieSF xDefMjfjt2wLqhIms2cPPN0cH3Wg4ZvF1wI51UBfeIj1ivDk7K5EbMbyWsfADNP8 fqAMOpKlWKsSx3C03i0G6Dt+4QyqfT5b5k7SIaFdBRfAbqqdsJtPhn0Q/DbDWt2x 69AapRba7+xROB8I8O1jSH2kM7MiW4bpBIKmkKE4P5gBTk2aWPjhHLap9U4XKdQa nS6ztLBDyMaH5a4xXKi5xCkWR77Qav9y8uXR8Rr9y7Yw0KTmy8WLRiCKtfNIMTTx l5mH+vz8dkZhkxw6FstUBfjoVTXtSwADBQf+NLOh1U49bZnyNsRuzrfnoUehgnvk SgAlWOQhJwEfV5Tv+ysT2+uoEXYrtJo95KPyNkyuzxqP62IFJCI00oHyk6nJZsGb 3Ge5xg8NRoPLfH4Q//wIcZ4sl3rlnZoU8LxmnpvitPAOdLwf5NZ47EIECIdUxt91 Nc7xTJGMhsZPIUmKaMomg/Sq3HS9Z+KQ1q/cp8zpHmV8Oq1EdQjNR/pzRCilz19g oi8PaWiUkTzOm3bHrvcxf8ijY2RJsSzBdKCu3235Tc5ldXahmR+OPrEUEgiCjJxM +xoxtkeD5AeOGYlqLD4pfSG/w+IkEaRLYRrV2o967L12eg7I3AZhMmDgOohPBBgR AgAPBQJKc6kfAhsMBQkJZ2ehAAoJECFth7cSBE0rLQQAn0EzHFSISci9+FSf3psH 7ffGN/K7AJ93zwmaWzjTk0ZOgHXf7llzkZzRVA== [...]]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s my new PGP key, valid until August 1st, 2014. Yeah, I&#8217;m kind of sick of generating new ones yearly.</p>
<p>&#8212;&#8211;BEGIN PGP PUBLIC KEY BLOCK&#8212;&#8211;<br />
Version: GnuPG v1.4.9 (Darwin)</p>
<p>mQGiBEpzqR8RBADk2w/POIp9FYMdCUOcbRuP5fHEWGyxrAdb19KjTHoHH+L4fk2c<br />
zy5IuvUhYZdC97mBr6S2Pg2bdXcxnSCtCIjeW78q6d6gmjoup0A5dvqNaK4xvWFo<br />
m8LvBochSIl/LjMsyvL7Jbm4rwfKNJVm5aTe5ZcoT97QdI8IxAW10XaLuwCg53R8<br />
F/Ty6yeY2pwxnE7HZGcggCsEAIUbFiGcapUJI1IraYqBQbtjXL8/sX5hqcIdJ3K8<br />
k+LJclIswiR7YYvJPjtiHCe9pe/SnUrOCjN8eygjlQIgWpNYHcMbhobECBR4Q4MU<br />
4CF20tndFmyZU5BkLeUzItn9WE4W4Ib/6Ny5dQYQ7cSipKV4HsOWNXM+onng6N82<br />
/KvxA/9B+5L0e6y7paFbaWkuq9XvcP3UfW3HewAi3WlvChMQ5zWuDSfsgCfEmxIo<br />
1zz9hai6lBcbZinD4pdcWtDI9lHztRoqiSmMMvcZr+TX76ykCERvF1uo++19uH2H<br />
B3pXjTs4wdPZ2XyXfcDWJzl7IrciXLK3J91I+IfLrlYnqRZx3rRcR3VpbGxhdW1l<br />
IFJvc3MgKFRoaXMga2V5IHdpbGwgYmUgdmFsaWQgdW50aWwgQXVndXN0IDFzdCwg<br />
MjAxNC4pIDxndWlsbGF1bWVAYmluYXJ5ZmFjdG9yeS5jYT6IZgQTEQIAJgUCSnOp<br />
HwIbIwUJCWdnoQYLCQgHAwIEFQIIAwQWAgMBAh4BAheAAAoJECFth7cSBE0ry3kA<br />
oMt+O/tKLwELxFE6pct9Sl/bE17yAKCnJml9k4Gj8DyaBlYFnfMzRPkrWbkCDQRK<br />
c6kfEAgAjuBEe96GS3/umwzbdxNBlnh0Fodshq30+aGcxyPOij5muUCeNkw2ieSF<br />
xDefMjfjt2wLqhIms2cPPN0cH3Wg4ZvF1wI51UBfeIj1ivDk7K5EbMbyWsfADNP8<br />
fqAMOpKlWKsSx3C03i0G6Dt+4QyqfT5b5k7SIaFdBRfAbqqdsJtPhn0Q/DbDWt2x<br />
69AapRba7+xROB8I8O1jSH2kM7MiW4bpBIKmkKE4P5gBTk2aWPjhHLap9U4XKdQa<br />
nS6ztLBDyMaH5a4xXKi5xCkWR77Qav9y8uXR8Rr9y7Yw0KTmy8WLRiCKtfNIMTTx<br />
l5mH+vz8dkZhkxw6FstUBfjoVTXtSwADBQf+NLOh1U49bZnyNsRuzrfnoUehgnvk<br />
SgAlWOQhJwEfV5Tv+ysT2+uoEXYrtJo95KPyNkyuzxqP62IFJCI00oHyk6nJZsGb<br />
3Ge5xg8NRoPLfH4Q//wIcZ4sl3rlnZoU8LxmnpvitPAOdLwf5NZ47EIECIdUxt91<br />
Nc7xTJGMhsZPIUmKaMomg/Sq3HS9Z+KQ1q/cp8zpHmV8Oq1EdQjNR/pzRCilz19g<br />
oi8PaWiUkTzOm3bHrvcxf8ijY2RJsSzBdKCu3235Tc5ldXahmR+OPrEUEgiCjJxM<br />
+xoxtkeD5AeOGYlqLD4pfSG/w+IkEaRLYRrV2o967L12eg7I3AZhMmDgOohPBBgR<br />
AgAPBQJKc6kfAhsMBQkJZ2ehAAoJECFth7cSBE0rLQQAn0EzHFSISci9+FSf3psH<br />
7ffGN/K7AJ93zwmaWzjTk0ZOgHXf7llzkZzRVA==<br />
=9tWC<br />
&#8212;&#8211;END PGP PUBLIC KEY BLOCK&#8212;&#8211;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.binaryfactory.ca/2009/08/new-pgp-key/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Performance impact of clearing your swap file at shutdown</title>
		<link>http://blog.binaryfactory.ca/2009/07/performance-impact-of-clearing-your-swap-file-at-shutdown/</link>
		<comments>http://blog.binaryfactory.ca/2009/07/performance-impact-of-clearing-your-swap-file-at-shutdown/#comments</comments>
		<pubDate>Mon, 06 Jul 2009 23:13:54 +0000</pubDate>
		<dc:creator>Guillaume</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Performance]]></category>

		<guid isPermaLink="false">http://blog.binaryfactory.ca/?p=295</guid>
		<description><![CDATA[For security reasons, it might be advisable to clear your swap file at shutdown. It doesn&#8217;t provide great security, and you really should be using full drive encryption anways. But in case anyone is wondering, for a 1.5gig swap file, this option (ClearPageFileAtShutdown) seems to add about 30 to 40 seconds of time to the [...]]]></description>
			<content:encoded><![CDATA[<p>For security reasons, it might be advisable to clear your swap file at shutdown.</p>
<p>It doesn&#8217;t provide great security, and you really should be using full drive encryption anways.</p>
<p>But in case anyone is wondering, for a 1.5gig swap file, this option (ClearPageFileAtShutdown) seems to add about 30 to 40 seconds of time to the shutdown procedure as it overwrites the file with zeroes.</p>
<p>Now turn it back off and install Truecrypt!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.binaryfactory.ca/2009/07/performance-impact-of-clearing-your-swap-file-at-shutdown/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interesting discussions about PIFTS.EXE</title>
		<link>http://blog.binaryfactory.ca/2009/03/interesting-discussions-about-piftsexe/</link>
		<comments>http://blog.binaryfactory.ca/2009/03/interesting-discussions-about-piftsexe/#comments</comments>
		<pubDate>Tue, 10 Mar 2009 17:10:32 +0000</pubDate>
		<dc:creator>Guillaume</dc:creator>
				<category><![CDATA[Gadgets]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Conspiracy]]></category>

		<guid isPermaLink="false">http://blog.binaryfactory.ca/?p=250</guid>
		<description><![CDATA[** Update ** Official word from Symantec &#160; My favorite quote from that paragraph is: “ Releasing a patch unsigned is an extremely rare occurrence that does not pose any security issues to our users”. Wow, I guess Norton’s too good, they don’t even need to sign patches. Then why do they ever sign them, [...]]]></description>
			<content:encoded><![CDATA[<p>** Update ** <a href="http://community.norton.com/norton/board/message?board.id=nis_feedback&amp;thread.id=39119">Official word from Symantec</a></p>
<p>&#160;</p>
<p>My favorite quote from that paragraph is:<em> “ Releasing a patch unsigned is an extremely rare occurrence that does not pose any security issues to our users”.</em></p>
<p><em></em></p>
<p><strong>Wow</strong>, I guess Norton’s too good, they don’t even need to sign patches. Then why do they ever sign them, if they can push unsigned ones?</p>
<p>Why was that patch hidden, and why did they delete true messages concerning PIFTS before the &quot;spam” appeared?</p>
<p>&#160;</p>
<p>&#160;</p>
<p>PIFTS.exe is generating quite a buzz as nobody seems to really know what it does, and Symantec seems to be putting more effort at moderating posts than explaining what it does.&quot;</p>
<p>&#160;</p>
<p><a href="http://isc.sans.org/diary.html?storyid=5992">SANS page about PIFTS</a></p>
<p><a href="http://chrysler5thavenue.blogspot.com/">Blog post by a guy who thinks that Slashdot is a web 2.0 social networking site for techies:</a> </p>
<p><a href=" http://digg.com/software/What_is_PIFTS_and_why_is_Symantec_covering_it_up ">Digg discussion about that page</a></p>
<p><a href="http://anubis.iseclab.org/?action=result&amp;task_id=19d7659347c3ebcd4a5ba7e9faa60fa14&amp;format=html">Anubis report</a> (who knows if that was done using the real file though): </p>
<p><a href="http://it.slashdot.org/article.pl?sid=09/03/10/139229">Slashdot Discussion</a></p>
<p><a href="http://voices.washingtonpost.com/securityfix/2009/03/symantec_users_complain_of_mys.html">Washington Post &quot;Voices&quot;</a></p>
<p>&#160;</p>
<p>Great screenshot from the Symantec boards, the thread should be gone in a few minutes..</p>
<p>&#160;</p>
<p><a href="http://blog.binaryfactory.ca/wp-content/uploads/2009/03/image.png"><img title="image" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="341" alt="image" src="http://blog.binaryfactory.ca/wp-content/uploads/2009/03/image-thumb.png" width="644" border="0" /></a> </p>
<p>&#160;</p>
<p>And another one..</p>
<p>&#160;</p>
<p><a href="http://blog.binaryfactory.ca/wp-content/uploads/2009/03/image1.png"><img title="image" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="812" alt="image" src="http://blog.binaryfactory.ca/wp-content/uploads/2009/03/image-thumb1.png" width="758" border="0" /></a> </p>
<p>Possibly a great 4chan prank? Who knows, you’d think Symantec would release an official statement if that was the case..</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.binaryfactory.ca/2009/03/interesting-discussions-about-piftsexe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

