<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Byung Kyu Park&#039;s Personal Website &#187; security</title>
	<atom:link href="http://bkpark.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://bkpark.com</link>
	<description>Everything about Byung Kyu Park</description>
	<lastBuildDate>Fri, 03 Feb 2012 19:31:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Yet another CalMail phishing attempt</title>
		<link>http://bkpark.com/2010/02/20/yet-another-calmail-phishing-attempt/</link>
		<comments>http://bkpark.com/2010/02/20/yet-another-calmail-phishing-attempt/#comments</comments>
		<pubDate>Sun, 21 Feb 2010 06:23:18 +0000</pubDate>
		<dc:creator>bkpark</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[calmail]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://bkpark.com/?p=515</guid>
		<description><![CDATA[Still fairly obvious, but it looks like phishers are getting better. Below is the email with full-headers (headers revealing my secret email server setup redacted): Return-path: <span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=fX7_gdcqtST-0KpRghBpSr9XI4Y_Tuoo3LwMIlfJmO4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=fX7_gdcqtST-0KpRghBpSr9XI4Y_Tuoo3LwMIlfJmO4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span> Envelope-to: <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Wm5m0_v9EqnOMa3R--MEQJHXh0VdMVkcAeIBAzSL0UY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Wm5m0_v9EqnOMa3R--MEQJHXh0VdMVkcAeIBAzSL0UY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span> Delivery-date: Sat, 20 Feb 2010 21:19:26 -0800 Received: from xxxxxxxx.berkeley.edu ([128.32.xxx.xxx]) by xxxxx.xxxxxxxxxxxx.xxx with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.69) (envelope-from &#60;<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=fX7_gdcqtST-0KpRghBpSr9XI4Y_Tuoo3LwMIlfJmO4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=fX7_gdcqtST-0KpRghBpSr9XI4Y_Tuoo3LwMIlfJmO4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&#62;) id 1Nj4E2-0003HR-Mg for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Wm5m0_v9EqnOMa3R--MEQJHXh0VdMVkcAeIBAzSL0UY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Wm5m0_v9EqnOMa3R--MEQJHXh0VdMVkcAeIBAzSL0UY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sat, 20 [...]]]></description>
			<content:encoded><![CDATA[<p>Still fairly obvious, but it looks like phishers are getting better. Below is the email with full-headers (headers revealing my secret email server setup redacted):</p>
<pre>
Return-path: <span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>
Envelope-to: <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>
Delivery-date: Sat, 20 Feb 2010 21:19:26 -0800
Received: from xxxxxxxx.berkeley.edu ([128.32.xxx.xxx])
        by xxxxx.xxxxxxxxxxxx.xxx with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32)
        (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E2-0003HR-Mg
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:26 -0800
Received: from xxxxxxx by xxxxxxxx.Berkeley.EDU with local (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E2-0004s1-Bl
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=Cmh-O_mcqcU-BOPxOIMc_UUzu6IhYUQPm6Ud-UFchuY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:26 -0800
Received: from cm03fe.ist.berkeley.edu ([169.229.218.144])
        by xxxxxxxxx.Berkeley.EDU with esmtp (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E2-0004rv-9i
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxxxxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:26 -0800
Received: from cm09be.ist.berkeley.edu ([169.229.218.182])
        by cm03fe.ist.berkeley.edu with esmtps (TLSv1:AES256-SHA:256)
        (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E1-0005NQ-Cn
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxxxxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:25 -0800
Received: from cyrus by cm09be.ist.berkeley.edu with local (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4E1-0002WX-Ra
        for <span class="mh-email">xxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=9hInstEEzMyl6a3FvLVaLt5DZGhvMr4XzJr8zlOSaho=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxxxxxxxx.xxx</span>; Sat, 20 Feb 2010 21:19:25 -0800
Received: from cm01fe.ist.berkeley.edu (cm01fe.IST.Berkeley.EDU [169.229.218.142])
        by cm09ms.ist.berkeley.edu (Cyrus v2.3.13-CalMail-v2.3) with LMTPA;
        Sat, 20 Feb 2010 21:19:25 -0800
X-Sieve: CMU Sieve 2.3
Received: from persius.rz.uni-potsdam.de ([141.89.68.1])
        by cm01fe.ist.berkeley.edu with esmtp (Exim 4.69)
        (envelope-from &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;)
        id 1Nj4Dy-0007hK-52; Sat, 20 Feb 2010 21:19:24 -0800
Received: from arnim.rz.uni-potsdam.de (arnim.rz.uni-potsdam.de [141.89.68.11])
        by persius.rz.uni-potsdam.de (8.12.11/8.12.11) with ESMTP id o1L50smS001879;
        Sun, 21 Feb 2010 06:00:54 +0100 (CET)
Received: from uni-potsdam.de (localhost.localdomain [127.0.0.1])
        by arnim.rz.uni-potsdam.de (8.13.8/8.13.8) with ESMTP id o1L50qp1025812;
        Sun, 21 Feb 2010 06:00:52 +0100
Received: from 41.138.182.176 ([41.138.182.176]) by webmail.uni-potsdam.de
        (Horde MIME library) with HTTP; Sun, 21 Feb 2010 06:00:52 +0100
Message-ID: &lt;<span class="mh-email">2010<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=qyIqDwBc7N65vKMVQMscN_ksEGgbJ2_FbgM99tnQG7gHV8AypQ9sBhRBzh6IY_aPQmaKmqZHRr3sys56-Ixgsw==' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=qyIqDwBc7N65vKMVQMscN_ksEGgbJ2_FbgM99tnQG7gHV8AypQ9sBhRBzh6IY_aPQmaKmqZHRr3sys56-Ixgsw==', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@webmail.uni-potsdam.de</span>&gt;
Date: Sun, 21 Feb 2010 06:00:52 +0100
From: "Berkeley.edu Web-Administration" &lt;<span class="mh-email">webm<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=8kVOM8ua-pvpy26zNXEOj4o9qBHX2f2ts1Nre6AkEQQ=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>&gt;
Reply-to: <span class="mh-email">supp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=g0UERoJSVzHhkMRrmqix4mqOgswGuS8E5WHPgfJFLo4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=g0UERoJSVzHhkMRrmqix4mqOgswGuS8E5WHPgfJFLo4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@live.com</span>
To: undisclosed-recipients: ;
Subject: Alert: Update your CalMail  account
MIME-Version: 1.0
Content-Type: text/plain;
        charset=ISO-8859-1;
        DelSp="Yes";
        format="flowed"
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
User-Agent: Internet Messaging Program (IMP) H3 (4.1.6)
X-Virus-Scanned: clamav-milter 0.95.3 at arnim.rz.uni-potsdam.de
X-Virus-Status: Clean
X-j-chkmail-Score: MSGID : 4B80BE06.000 on persius : j-chkmail score : X : 5/50 0
X-Miltered: at persius with ID 4B80BE06.000 by Joe's j-chkmail (http://j-chkmail.ensmp.fr)!
X-Ucb-Scan-Signature: 606d01dea56a423fb13a5c3f55ff5ffa3eae29a5
X-Ucb-Spam: Gauge=IIIIIII, Probability=7%, Report=''
X-Ucb-Notice: This message has been processed by a spam tagging system.
        See http://mailinfo.berkeley.edu/ for more information.

--

Dear CalMail User,

Your email account needs to be upgraded with our new F-Secure® HTK4S
anti-virus/anti-spam 2010 version.
Fill the columns below and click reply to send back or your account will be
suspended temporary from our services.

CalNet ID:
Passphrase:
Phone Number:

Berkeley.edu Web-Administration
Greg Silva

https://calmail.berkeley.edu/

----©2010, University Of California.
</pre>
<p>Note the fairly convincing From: address. A lot of the suspicious routing information will be hidden by most email clients, <em>however</em>, the Reply-to: header (which would route the email to <span class="mh-email">supp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=g0UERoJSVzHhkMRrmqix4mqOgswGuS8E5WHPgfJFLo4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=g0UERoJSVzHhkMRrmqix4mqOgswGuS8E5WHPgfJFLo4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@live.com</span> and which the phishing relies on) <em>should</em> be set to visible by most email clients, which means, yet again, people who pay attention to details shouldn&#8217;t be taken in by this rather amateurish phishing attempt.</p>
<p>Not to mention one should never send passphrases over email&mdash;even if you know the recipient; email is transmitted in clear text between servers and is <em>inherently insecure</em>. </p>
]]></content:encoded>
			<wfw:commentRss>http://bkpark.com/2010/02/20/yet-another-calmail-phishing-attempt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conspiracy theory: Obama to declare martial law or something?</title>
		<link>http://bkpark.com/2009/12/07/conspiracy-theory-obama-to-declare-martial-law-or-something/</link>
		<comments>http://bkpark.com/2009/12/07/conspiracy-theory-obama-to-declare-martial-law-or-something/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 07:01:53 +0000</pubDate>
		<dc:creator>bkpark</dc:creator>
				<category><![CDATA[politics]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[conspiracy theories]]></category>
		<category><![CDATA[lew rockwell]]></category>
		<category><![CDATA[obama]]></category>
		<category><![CDATA[us military]]></category>

		<guid isPermaLink="false">http://byungkyupark.com/?p=386</guid>
		<description><![CDATA[A post at LewRockwell.com is worrying whether U.S. army will have a new enemy: American citizens: Members of all branches of the United States Military will soon be facing a most critical decision. The European Union Times is reporting here that Obama is using the deployment of additional troops to Afghanistan to cover for the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.lewrockwell.com/gaddy/gaddy75.1.html">A post at LewRockwell.com is worrying whether U.S. army will have a new enemy: American citizens</a>:</p>
<blockquote><p>
Members of all branches of the United States Military will soon be facing a most critical decision. The European Union Times is reporting here that Obama is using the deployment of additional troops to Afghanistan to cover for the movement of some 200,000 troops, presently on duty in countries other than Iraq and Afghanistan, to USNORTHCOM to prepare for the &#8220;expected outbreak of Civil War within the United States before the end of winter.&#8221;
</p></blockquote>
<p>The claim is just so out there, I don&#8217;t know how to take it. Is this one of those truther or birther type conspiracy theories (or, say, DHS report on right-wing domestic terrorism) that have no legs to stand on? Or does this have some basis on facts?</p>
<p>In the end, even if the worst fears (about the ruling elite&#8217;s intentions) of Mr. Gaddy come true, I wouldn&#8217;t worry about it. Men and women of American military have been one of the most fiercest defenders of individual freedom&mdash;including the individual right to own and carry firearm&mdash;I have ever known. If orders were to come down for these patriotic men and women to trample on the constitutionally protected individual rights of Americans, I have every confidence that they will mutiny before following those orders&mdash;after all, Nuremberg tribunals proved that &#8220;just following orders&#8221; wasn&#8217;t an excuse for ignoring one&#8217;s conscience, and if I had to put my trust in anyone else&#8217;s conscience, I would put it in the conscience of American volunteer army.</p>
<p>If I am betrayed by this trust, well, the world as I know has come to an end and my most deeply held beliefs might as well break.</p>
]]></content:encoded>
			<wfw:commentRss>http://bkpark.com/2009/12/07/conspiracy-theory-obama-to-declare-martial-law-or-something/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tempting: Google offers DNS service</title>
		<link>http://bkpark.com/2009/12/03/tempting-google-offers-dns-service/</link>
		<comments>http://bkpark.com/2009/12/03/tempting-google-offers-dns-service/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 19:39:53 +0000</pubDate>
		<dc:creator>bkpark</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[google]]></category>

		<guid isPermaLink="false">http://www.novakyu.net/?p=285</guid>
		<description><![CDATA[Google offers DNS service: &#8220;Google has announced the launch of their free DNS resolution service, called Google Public DNS. According to their blog post, Google Public DNS uses continuous record prefetching to avoid cache misses — hopefully making the service faster — and implements a variety of techniques to block spoofing attempts. They also say [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://tech.slashdot.org/story/09/12/03/1814238/Google-Launches-Public-DNS-Resolver">Google offers DNS service</a>:</p>
<blockquote><p>
&#8220;Google has announced the launch of their free DNS resolution service, called Google Public DNS. According to their blog post, Google Public DNS uses continuous record prefetching to avoid cache misses — hopefully making the service faster — and implements a variety of techniques to block spoofing attempts. They also say that (unlike an increasing number of ISPs), Google Public DNS behaves exactly according to the DNS standard, and will not redirect you to advertising in the event of a failed lookup. Very cool, but of course there are questions about Google&#8217;s true motivations behind knowing every site you visit.&#8221;
</p></blockquote>
<p>Oh, this is tempting. I have some routers configured to use OpenDNS (mainly for their supposed fast response, not for the redirect to search), and I am rather tempted to re-configure them to use Google&#8217;s DNS servers.</p>
<p><em>But</em>, frankly, I think Google already has enough of my private information. I don&#8217;t need them to know every site I visit (and no, I don&#8217;t put much stock in ToS; as much as I trust Google more than other companies, once they have the information, it&#8217;s safer to assume that they&#8217;ll have it for-ever).</p>
<p>Well, I guess for now, Google&#8217;s DNS servers do not offer anything beyond what OpenDNS or my local DNS servers do &#8230; so at least the decision is a no-brainer for the time being.</p>
]]></content:encoded>
			<wfw:commentRss>http://bkpark.com/2009/12/03/tempting-google-offers-dns-service/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Calmail leaks IP addresses!</title>
		<link>http://bkpark.com/2009/11/29/calmail-leaks-ip-addresses/</link>
		<comments>http://bkpark.com/2009/11/29/calmail-leaks-ip-addresses/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 09:43:47 +0000</pubDate>
		<dc:creator>bkpark</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[tech]]></category>
		<category><![CDATA[calmail]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[ip address]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://byungkyupark.com/?p=347</guid>
		<description><![CDATA[For regular visitors of my blog from UCB, here&#8217;s an early holiday Christmas present to you: Calmail leaks IP addresses! Here&#8217;s a quick demonstration (I&#8217;ve seen similar headers on emails from friends and colleagues, but I didn&#8217;t want to expose their info; I&#8217;ve redacted some info here as I didn&#8217;t want to expose my &#8230; [...]]]></description>
			<content:encoded><![CDATA[<p>For regular visitors of my blog from UCB, here&#8217;s an early <strike>holiday</strike> Christmas present to you: Calmail leaks IP addresses! Here&#8217;s a quick demonstration (I&#8217;ve seen similar headers on emails from friends and colleagues, but I didn&#8217;t want to expose their info; I&#8217;ve redacted some info here as I didn&#8217;t want to expose my &#8230; secret email server scheme, or my real username for Calmail):</p>
<pre>
Return-path: <span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@visitor3.berkeley.edu</span>
Envelope-to: <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>
Delivery-date: Sun, 29 Nov 2009 01:32:12 -0800
Received: from visitor3.berkeley.edu ([128.32.124.159])
        by helen.byungkyupark.com with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32)
        (Exim 4.69)
        (envelope-from <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@visitor3.berkeley.edu</span>>)
        id 1NEg8a-0000jX-J7
        for <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sun, 29 Nov 2009 01:32:12 -0800
Received: from xxxxxxx by visitor3.Berkeley.EDU with local (Exim 4.69)
        (envelope-from <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@visitor3.berkeley.edu</span>>)
        id 1NEg8a-0001rk-4v
        for <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sun, 29 Nov 2009 01:32:12 -0800
Received: from smtp-out1.berkeley.edu ([128.32.61.106])
        by visitor3.Berkeley.EDU with esmtp (Exim 4.69)
        (envelope-from <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>>)
        id 1NEg8a-0001rW-2q
        for <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@byungkyupark.com</span>; Sun, 29 Nov 2009 01:32:12 -0800
Received: from arsenic.calmail ([192.168.1.2] helo=calmail.berkeley.edu)
        by fe2.calmail with esmtpsa (TLSv1:AES256-SHA:256)
        (Exim 4.69)
        (auth plain:<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>)
        (envelope-from <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>>)
        id 1NEg8T-0000qs-8R
        for <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@byungkyupark.com</span>; Sun, 29 Nov 2009 01:32:06 -0800
MIME-Version: 1.0
Received: from visitor3.Berkeley.EDU [128.32.124.159]
        with HTTP/1.1 (POST); Sun, 29 Nov 2009 01:32:05 -0800
Date: Sun, 29 Nov 2009 01:32:05 -0800
From: "Byung Kyu Park, BA" <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>>
To: <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@byungkyupark.com</span>
Subject: This will demonstrate how Calmail leaks IP addresses
Message-ID: <<span class="mh-email">7272<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=PIZb3BZ65wtedD-LBrEO1s6_ddlpl4eURLiWRU9gu9bksB0BbGqHyEQoJjzd3s48' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=PIZb3BZ65wtedD-LBrEO1s6_ddlpl4eURLiWRU9gu9bksB0BbGqHyEQoJjzd3s48', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>>
X-Sender: <span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>
User-Agent: RoundCube Webmail/0.3-RC1.UCB3
Content-Type: multipart/alternative;
        boundary="=_ad4b95d1d25a334cada12ae4c3335783"

Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset="UTF-8"

And this email was composed on the RoundCube webmail client.

Andrew
</pre>
<p>You will see that the detailed email header (which most email clients hide, but there is always an option to show full headers) reveals the IP from which I was accessing Calmail&#8217;s webmail interface (no, I&#8217;m not in the lab right now; but I am proxying through one of my servers, because I consider my current IP address a confidential, personal, private information). Similar headers show if you use SMTP protocol or if you use the other webmail.</p>
<p>I am not entirely sure if this is a feature or bug&mdash;embedding IP information in headers will help with legitimate activities of law enforcement authorities, as well as illegitimate (is there any other kind?) squelching of dissenting voices&mdash;so I haven&#8217;t reported it to <span class="mh-email">abu<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=WdX4nZ0t6okDHer_vsLt9SbNbqXWq2EEI392bvkc4iY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=WdX4nZ0t6okDHer_vsLt9SbNbqXWq2EEI392bvkc4iY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span> or, I don&#8217;t know, <span class="mh-email">h<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=JzlZGyzrhl1f-vxngDtmvDxa-12AwpOtYWLW3LGae3g=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=JzlZGyzrhl1f-vxngDtmvDxa-12AwpOtYWLW3LGae3g=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>? <span class="mh-email">secu<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=F_ZV3im-1FOCU20DjclP1b88u6z2m8jp5vIEDGzZM3A=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=F_ZV3im-1FOCU20DjclP1b88u6z2m8jp5vIEDGzZM3A=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>?</p>
<p>In any case, now that you know, now you can avoid using Calmail&mdash;if you value your privacy.</p>
<p>Ironically, GMail may be one of the most secure email system to use, as far as privacy goes, because headers from GMail is fairly clean from any private information. Or, I guess if you are like me, you run a computer server at work, on which you run a bunch of things like websites and email servers so whose IP address isn&#8217;t exactly a state secret. You can proxy everything through that server (like I did here) or run your mail clients and what-not on that server.</p>
<p>No matter what you do, just remember: when you send an email through Calmail, you announce to your recipient what your IP address is at that moment. Don&#8217;t send that email if you are not comfortable with that.</p>
]]></content:encoded>
			<wfw:commentRss>http://bkpark.com/2009/11/29/calmail-leaks-ip-addresses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scary: SSL not quite secure any more</title>
		<link>http://bkpark.com/2009/11/17/scary-ssl-not-quite-secure-any-more/</link>
		<comments>http://bkpark.com/2009/11/17/scary-ssl-not-quite-secure-any-more/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 02:15:41 +0000</pubDate>
		<dc:creator>bkpark</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://www.novakyu.net/?p=282</guid>
		<description><![CDATA[This is scary: &#8220;A Turkish grad student has devised a serious, real-world attack on Twitter that targeted a recently discovered vulnerability in the SSL protocol. The exploit by Anil Kurmus is significant because it successfully targeted the so-called SSL renegotiation bug to steal Twitter login credentials that passed through encrypted data streams. All in all, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://it.slashdot.org/story/09/11/16/2327230/SSL-Renegotiation-Attack-Becomes-Real">This is scary</a>:</p>
<blockquote><p>
&#8220;A Turkish grad student has devised a serious, real-world attack on Twitter that targeted a recently discovered vulnerability in the SSL protocol. The exploit by Anil Kurmus is significant because it successfully targeted the so-called SSL renegotiation bug to steal Twitter login credentials that passed through encrypted data streams. All in all, a man in the middle is able to steal the credentials of a user authenticating himself through HTTPS to a trusted website.&#8221;
</p></blockquote>
<p>What&#8217;s next? PGP? Can we trust anything other than OTPs any more?</p>
]]></content:encoded>
			<wfw:commentRss>http://bkpark.com/2009/11/17/scary-ssl-not-quite-secure-any-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why I want to learn to use a gun (and carry it too)</title>
		<link>http://bkpark.com/2009/11/06/why-i-want-to-learn-to-use-a-gun-and-carry-it-too/</link>
		<comments>http://bkpark.com/2009/11/06/why-i-want-to-learn-to-use-a-gun-and-carry-it-too/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 18:06:46 +0000</pubDate>
		<dc:creator>bkpark</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[fort hood]]></category>
		<category><![CDATA[gun rights]]></category>
		<category><![CDATA[self reliance]]></category>
		<category><![CDATA[terrorism]]></category>

		<guid isPermaLink="false">http://byungkyupark.com/?p=293</guid>
		<description><![CDATA[This is why I am determined and resolved to learn how to use a gun (and get a carry permit): That is a good lesson to remember. The attacker in this case gave little consideration to his personal security, by all accounts, and was not going to stop until someone stopped him. Munley understood this [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hotair.com/archives/2009/11/06/the-woman-who-stopped-a-mass-murderer/">This</a> is why I am determined and resolved to learn how to use a gun (and get a carry permit):</p>
<blockquote><p>
That is a good lesson to remember.  The attacker in this case gave little consideration to his personal security, by all accounts, and was not going to stop until someone stopped him.  Munley understood this and went against every human survival instinct to pursue a confrontation with a murderous lunatic — and nearly got killed for her efforts.  Her heroism saved lives at Fort Hood.
</p></blockquote>
<p>I refuse to be a victim. Because we do not live in an ideal world, there will always be those who want to victimize us, be it a madman or the government (but I repeat myself), and I need to make sure that I can win&mdash;if it ever comes down to the contest of brute force.</p>
<p><em>Update (12/26, h/t: Elliott)</em>: <a href="http://volokh.com/2009/12/26/the-unorganized-militia-once-again-is-needed/">my point exactly</a>. Americans are not born victims&mdash;that&#8217;s why Founders enshrined the right to defend oneself in the Second Amendment. Absent statist drive for power, I don&#8217;t see why anyone would strive to make any place (airports, airplane, etc.) constitution-free zone and designate everyone in that area victim. Regulations&mdash;after all, for something as potentially dangerous as guns and cars, we do want to make sure that people using them are properly trained and do not intend to harm others&mdash;I can understand. Blanket bans, I cannot.</p>
]]></content:encoded>
			<wfw:commentRss>http://bkpark.com/2009/11/06/why-i-want-to-learn-to-use-a-gun-and-carry-it-too/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>TSA improvement: I&#8217;ll take what I can get</title>
		<link>http://bkpark.com/2009/08/28/tsa-improvement-ill-take-what-i-can-get/</link>
		<comments>http://bkpark.com/2009/08/28/tsa-improvement-ill-take-what-i-can-get/#comments</comments>
		<pubDate>Sat, 29 Aug 2009 01:38:12 +0000</pubDate>
		<dc:creator>bkpark</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[obama]]></category>
		<category><![CDATA[tsa]]></category>

		<guid isPermaLink="false">http://byungkyupark.com/?p=127</guid>
		<description><![CDATA[There is a slight improvement to TSA&#8217;s search and seizure of electronic devices: &#8220;The US Government has updated its policy on the search and seizure of laptops at border crossing. &#8216;The long-criticized practice of searching travelers&#8217; electronic devices will continue, but a supervisor now would need to approve holding a device for more than five [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://yro.slashdot.org/story/09/08/28/1216200/Homeland-Security-Changes-Laptop-Search-Policy">There is a slight improvement to TSA&#8217;s search and seizure of electronic devices</a>:</p>
<blockquote><p>
&#8220;The US Government has updated its policy on the search and seizure of laptops at border crossing. &#8216;The long-criticized practice of searching travelers&#8217; electronic devices will continue, but a supervisor now would need to approve holding a device for more than five days. Any copies of information taken from travelers&#8217; machines would be destroyed within days if there were no legal reason to hold the information.&#8217;&#8221;
</p></blockquote>
<p>If I take this at the face value (so many things promised by this administration didn&#8217;t come to be, so I don&#8217;t know if I can), then it means if they search and seize my laptop (after finding the encrypted data, if they do), they will have to return the laptop to me in less than one week. I don&#8217;t really care if they destroy their copy of my encrypted data (because, barring breakthroughs in attacks against encryption algorithms in use today, they won&#8217;t be able to do anything with it; and it&#8217;s at least 5 years or so that I can sleep soundly).</p>
<p>This is a small &#8220;improvement&#8221;, if that at all, but I will take what I can get. Ideally, I want TSA and its &#8230; ineffectual, draconian security theater gone, but some among us do like the pretension of security better than actual security, which I don&#8217;t think the government (or maybe even private enterprises) can achieve at all.</p>
]]></content:encoded>
			<wfw:commentRss>http://bkpark.com/2009/08/28/tsa-improvement-ill-take-what-i-can-get/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Coming revolution in steganography?</title>
		<link>http://bkpark.com/2009/08/14/coming-revolution-in-steganography/</link>
		<comments>http://bkpark.com/2009/08/14/coming-revolution-in-steganography/#comments</comments>
		<pubDate>Fri, 14 Aug 2009 21:05:09 +0000</pubDate>
		<dc:creator>bkpark</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[steganography]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.novakyu.net/?p=253</guid>
		<description><![CDATA[There are now a group of people with huge incentive to hide secret in plain sight: the hackers who control botnets with Twitter. I, for one, am excited. Here are a group of people with a profit motive (it&#8217;s the illegal kind, but, oh well) who can make a real contribution to steganography. Imagine the [...]]]></description>
			<content:encoded><![CDATA[<p>There are now a group of people with huge incentive to hide secret in plain sight: <a href="http://it.slashdot.org/story/09/08/14/1828248/Twitter-Used-To-Control-Botnet-Machines">the hackers who control botnets with Twitter</a>.</p>
<p>I, for one, am excited. Here are a group of people with a profit motive (it&#8217;s the illegal kind, but, oh well) who can make a real contribution to steganography. Imagine the coming advances in the next year or so!</p>
]]></content:encoded>
			<wfw:commentRss>http://bkpark.com/2009/08/14/coming-revolution-in-steganography/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux local privilege escalation bug; clock&#8217;s ticking</title>
		<link>http://bkpark.com/2009/08/13/linux-local-privilege-escalation-bug-clocks-ticking/</link>
		<comments>http://bkpark.com/2009/08/13/linux-local-privilege-escalation-bug-clocks-ticking/#comments</comments>
		<pubDate>Thu, 13 Aug 2009 23:09:48 +0000</pubDate>
		<dc:creator>bkpark</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[kernel bug]]></category>
		<category><![CDATA[privilege escalation]]></category>

		<guid isPermaLink="false">http://www.novakyu.net/?p=251</guid>
		<description><![CDATA[Slashdot has a story on newly discovered (but ever-present) Linux bug which could allow local users to gain root privileges. I guess it&#8217;s re-install time for many of my servers, or at least one of them. I am currently keeping &#8230; a vigilant log to check that nothing out of ordinary is happening, but I [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://linux.slashdot.org/story/09/08/13/2022212/Local-Privilege-Escalation-On-All-Linux-Kernels">Slashdot has a story</a> on newly discovered (but ever-present) Linux bug which could allow local users to gain root privileges.</p>
<p>I guess it&#8217;s <a href="http://linux.slashdot.org/comments.pl?sid=1335689&#038;cid=29057607">re-install time</a> for many of my servers, or at least one of them. I am currently keeping &#8230; a vigilant log to check that nothing out of ordinary is happening, but I am considering the machine compromised and in line for re-install as soon as I can find the time.</p>
]]></content:encoded>
			<wfw:commentRss>http://bkpark.com/2009/08/13/linux-local-privilege-escalation-bug-clocks-ticking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When I&#039;m dead, how will my loved ones break my password? (and not the government)</title>
		<link>http://bkpark.com/2009/07/02/when-im-dead-how-will-my-loved-ones-break-my-password-and-not-the-government/</link>
		<comments>http://bkpark.com/2009/07/02/when-im-dead-how-will-my-loved-ones-break-my-password-and-not-the-government/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 13:06:11 +0000</pubDate>
		<dc:creator>bkpark</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[trust]]></category>

		<guid isPermaLink="false">http://byungkyupark.com/?p=104</guid>
		<description><![CDATA[Cory Doctorow writes for Guardian, More specifically, what about the secrets that protect our data? Like an increasing number of people who care about the security and integrity of their data, I have encrypted all my hard-drives – the ones in my laptops and the backup drives, using 128-bit AES – the Advanced Encryption Standard. [...]]]></description>
			<content:encoded><![CDATA[<p>Cory Doctorow <a href="http://www.guardian.co.uk/technology/2009/jun/30/data-protection-internet">writes for Guardian</a>,</p>
<blockquote><p>
More specifically, what about the secrets that protect our data? Like an increasing number of people who care about the security and integrity of their data, I have encrypted all my hard-drives – the ones in my laptops and the backup drives, using 128-bit AES – the Advanced Encryption Standard. Without the passphrase that unlocks my key, the data on those drives is unrecoverable, barring major, seismic advances in quantum computing, or a fundamental revolution in computing.
</p></blockquote>
<p>After considering a few options that most people who think about this particular problem would, including an option I might have considered adequate, a safebox containing the passphrase (or an unencrypted private key which can be used to similar effect), and rejecting them, he concludes,</p>
<blockquote><p>
Finally, I hit on a simple solution: I&#8217;d split the passphrase in two, and give half of it to my wife, and the other half to my parents&#8217; lawyer in Toronto. The lawyer is out of reach of a British court order, and my wife&#8217;s half of the passphrase is useless without the lawyer&#8217;s half (and she&#8217;s out of reach of a Canadian court order).
</p></blockquote>
<p>Obviously this makes the attack on the passphrase slightly easier: if it was originally 10-characters long, then now the attacker needs to consider only 5-character passphrase, once he gets the control of one. But it&#8217;s probably easy enough to make your passphrase long enough to minimize this problem, i.e. make your passphrases 40-chars long instead of the recommended 20-chars (for my full hard drive encryption, I use a 26-char password and it&#8217;s probably not too difficult for me to memorize one that&#8217;s twice as long).</p>
<p>And if you don&#8217;t mind a little bit of technical complexity, you can split the key mathematically rather than as a string: i.e. for each character, take its ASCII code, and split it, randomly, into two numbers (running both positively and negatively, say from -255 to 255; it wouldn&#8217;t be possible to split them into another sets of printable ASCII codes, as lowest 32 numbers aren&#8217;t printable, so may as well just turn each character into numbers) so that when they are added together, you get the correct character back, and store information about these two sets of numbers separately&mdash;and either of these two sets by itself is literally nothing but a random set of numbers, betraying no information about the actual passphrase.</p>
<p>Overall, I think this is a good scheme, except, well, it only works for people with connections in two countries (and if the liberals have their way, we will have the One World Government pretty soon, so splitting jurisdiction may not be an option soon).</p>
<p>It seems like, at least in any scenarios I can think of, if you want to share a secret with someone else and wants to keep it secret (between the two of you), then the only way to do it is under some subterfuge&mdash;either regarding the fact that you have a secret, or that the other person shares it (so that you can prevent the person from getting subpoenaed).</p>
]]></content:encoded>
			<wfw:commentRss>http://bkpark.com/2009/07/02/when-im-dead-how-will-my-loved-ones-break-my-password-and-not-the-government/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

