<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msinfluentials.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Revisiting the Immutable Laws</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/09/22/revisiting-the-immutable-laws.aspx</link><description>For many years I, and many others, have been referring to the immutable laws of security when trying to explain why something works, or does not work, a particular way. However, I&amp;#39;ve always wondered how immutable the laws really are? I finally sat</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: Revisiting the Immutable Laws</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/09/22/revisiting-the-immutable-laws.aspx#9782</link><pubDate>Thu, 30 Oct 2008 06:40:38 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:9782</guid><dc:creator>Vincenzo Di Russo [MVP]</dc:creator><description>&lt;p&gt;PingBack from&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.dotnethell.it/vincent/Security-Watch-le-10-leggi-immutabili-della-sicurezza.__14446.aspx"&gt;blogs.dotnethell.it/.../Security-Watch-le-10-leggi-immutabili-della-sicurezza.__14446.aspx&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=9782" width="1" height="1"&gt;</description></item><item><title>re: Revisiting the Immutable Laws</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/09/22/revisiting-the-immutable-laws.aspx#9735</link><pubDate>Wed, 22 Oct 2008 05:33:21 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:9735</guid><dc:creator>jesper</dc:creator><description>&lt;p&gt;Marta, I am sorry to hear that. Could it possibly be that they re-activated old hotmail accounts you let lapse? Either way, it is not something I can help with. I recommend you contact the Security Support Center at Microsoft. The various options for doing that are listed at &lt;a rel="nofollow" target="_new" href="http://technet.microsoft.com/en-us/security/cc165610.aspx"&gt;technet.microsoft.com/.../cc165610.aspx&lt;/a&gt;. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=9735" width="1" height="1"&gt;</description></item><item><title>re: Revisiting the Immutable Laws</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/09/22/revisiting-the-immutable-laws.aspx#9734</link><pubDate>Wed, 22 Oct 2008 04:56:15 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:9734</guid><dc:creator>Marta Guillen</dc:creator><description>&lt;p&gt;Mr. Jesper,&lt;/p&gt;
&lt;p&gt;I have to appologize for using this way of communication with You, but after hours and hours of searching the Web for technical support in order to get help and solutions to my problem, I bumped into Your blog which I found very interesting.&lt;/p&gt;
&lt;p&gt;I am facing a security problem, where somebody has stolen passwords for old hotmail accounts of mine and is using them to harass me and harm me in many ways.&lt;/p&gt;
&lt;p&gt;I don&amp;#39;t seem to be able to find answers anywhere and don&amp;#39;t know how to stop it. Would You be so kind to help me with this problem if you could?&lt;/p&gt;
&lt;p&gt;Thank you very much and Best Regards.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=9734" width="1" height="1"&gt;</description></item><item><title>USB devices do not support DMA</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/09/22/revisiting-the-immutable-laws.aspx#9546</link><pubDate>Mon, 06 Oct 2008 18:49:18 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:9546</guid><dc:creator>Rob</dc:creator><description>&lt;p&gt;I read your article this morning, and wanted to point out that USB devices do not support DMA. &amp;nbsp;The USB host controller (a PCI-type device) does, but USB devices themselves only return data when polled by the host controller. &amp;nbsp;One cannot build a USB flash drive or other peripheral that can write to arbitrary memory addresses. &amp;nbsp;A PCI device, however, could do this; think ExpressCard (which supports both USB and PCI Express) or even 32-bit CardBus devices (perhaps).&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=9546" width="1" height="1"&gt;</description></item><item><title>re: Revisiting the Immutable Laws</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/09/22/revisiting-the-immutable-laws.aspx#9489</link><pubDate>Tue, 30 Sep 2008 15:49:44 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:9489</guid><dc:creator>YADmitry</dc:creator><description>&lt;p&gt;I liked the paragraph about edlin. Honestly I didn&amp;#39;t know it was still there (checking it on win2K3). Looking inside this exe: MS DOS Version 5.00 (C)Copyright 1981-1991&lt;/p&gt;
&lt;p&gt;Wow! Unchanged since MS DOS 5!&lt;/p&gt;
&lt;p&gt;The same applies to exe2bin. All my old DOS friends are still there - even my favourite debug.exe.&lt;/p&gt;
&lt;p&gt;Another surprising thing - the presence of upg351db. WINS DB upgrade when you jump from NT3.5 to 2000. I reckon this program can compete with edlin in terms of frequency of use.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=9489" width="1" height="1"&gt;</description></item><item><title>re: Revisiting the Immutable Laws</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/09/22/revisiting-the-immutable-laws.aspx#9456</link><pubDate>Tue, 23 Sep 2008 23:08:51 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:9456</guid><dc:creator>Harry Johnston</dc:creator><description>&lt;p&gt;Chris: there&amp;#39;s no reason a voting machine can&amp;#39;t be made reasonably resistant to physical tampering. &amp;nbsp;If the electronics are inside a suitable container - strong, locked, and alarmed - and provided the unit is stored appropriately when not in use, there&amp;#39;s no problem. &amp;nbsp;Think automatic teller machine.&lt;/p&gt;
&lt;p&gt;Physical audit trail is also a key idea here. &amp;nbsp;The machine needs to print out a copy of the vote for the user to check. &amp;nbsp;This copy can be put in a traditional ballot box in the event the machine&amp;#39;s results are challenged (or selected at random for auditing).&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=9456" width="1" height="1"&gt;</description></item><item><title>re: Revisiting the Immutable Laws</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/09/22/revisiting-the-immutable-laws.aspx#9455</link><pubDate>Tue, 23 Sep 2008 22:48:22 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:9455</guid><dc:creator>Chris</dc:creator><description>&lt;p&gt;Thank you for re-energizing the immutable laws of security. &amp;nbsp;Seems most people don&amp;#39;t want to heed the third tenant of the laws: &amp;nbsp;If someone has physical access to your computer, then it isn&amp;#39;t your computer anymore.&lt;/p&gt;
&lt;p&gt;This fact was extremely evident when the various news outlets published harsh articles talking about how vulnerable the DieBold Voting machines are to physical tampering. &amp;nbsp;It would seem that we will have an electronic voting machine only when it becomes possible to allow someone to vote electronically without making physical contact with the voting machine. &amp;nbsp;Not likely anytime soon.&lt;/p&gt;
&lt;p&gt;And on a side note... why is it that our current non-electronic voting methods aren&amp;#39;t held up to the same rigorous security requirements as what is being held against the electronic voting machines?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=9455" width="1" height="1"&gt;</description></item><item><title>re: Revisiting the Immutable Laws</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/09/22/revisiting-the-immutable-laws.aspx#9454</link><pubDate>Tue, 23 Sep 2008 22:41:14 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:9454</guid><dc:creator>Harry Johnston</dc:creator><description>&lt;p&gt;I note that you haven&amp;#39;t defined &amp;quot;immutable&amp;quot;. &amp;nbsp;I don&amp;#39;t think it is a good word, because it implies that they apply not only for existing hardware designs and operating systems, but for any possible hardware design and operating system.&lt;/p&gt;
&lt;p&gt;I don&amp;#39;t know whether this is what you mean by it, but if so, I&amp;#39;d dispute law 1. &amp;nbsp;It&amp;#39;s entirely possible for an operating system to be designed so that malicious or faulty code can&amp;#39;t do you any harm simply by virtue of being run. &amp;nbsp;(Of course this can&amp;#39;t eliminate all possible social engineering attacks, but it can make it much more difficult to confuse a user into doing something bad, particularly in a corporate setting.)&lt;/p&gt;
&lt;p&gt;Law 3 is also marginal in this respect - a better hardware design would go a long way towards mitigating this, at least in the context where either the attacker is under observation or the computer is connected to an alarm system.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=9454" width="1" height="1"&gt;</description></item></channel></rss>