<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>USENIX Update &#187; security</title>
	<atom:link href="http://blogs.usenix.org/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.usenix.org</link>
	<description>News and info from USENIX: The Advanced Computing Systems Association</description>
	<lastBuildDate>Fri, 10 Feb 2012 04:52:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>Network Security in the Medium Term: 2061&#8211;2561 AD</title>
		<link>http://www.youtube.com/watch?v=ihm3jKTXPXI&#038;feature=youtube_gdata</link>
		<comments>http://www.youtube.com/watch?v=ihm3jKTXPXI&#038;feature=youtube_gdata#comments</comments>
		<pubDate>Tue, 16 Aug 2011 23:24:13 +0000</pubDate>
		<dc:creator>USENIXAssociation</dc:creator>
				<category><![CDATA[Charles Stross]]></category>
		<category><![CDATA[http://gdata.youtube.com/schemas/2007#video]]></category>
		<category><![CDATA[information processing]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[science fiction]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[USENIX]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://gdata.youtube.com/feeds/api/videos/ihm3jKTXPXI</guid>
		<description><![CDATA[Keynote Address given by Charles Stross, Author of award-winning science fiction, at the 20th USENIX Security Symposium (USENIX Security '11), held August 8--12, 2011, in San Francisco, CA.

A science fiction writer takes a look at the medium-term impl...]]></description>
		<wfw:commentRss>http://blogs.usenix.org/2011/08/16/network-security-in-the-medium-term-2061-2561-ad-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="rtsp://v2.cache4.c.youtube.com/CigLENy73wIaHwlyPdekjLcZihMYESARFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="rtsp://v5.cache5.c.youtube.com/CigLENy73wIaHwlyPdekjLcZihMYDSANFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="http://www.youtube.com/v/ihm3jKTXPXI?version=3&amp;amp;f=user_uploads&amp;amp;app=youtube_gdata" length="" type="application/x-shockwave-flash" />
		</item>
		<item>
		<title>Comprehensive Experimental Analyses of Automotive Attack Surfaces</title>
		<link>http://www.youtube.com/watch?v=bHfOziIwXic&#038;feature=youtube_gdata</link>
		<comments>http://www.youtube.com/watch?v=bHfOziIwXic&#038;feature=youtube_gdata#comments</comments>
		<pubDate>Mon, 15 Aug 2011 16:33:50 +0000</pubDate>
		<dc:creator>USENIXAssociation</dc:creator>
				<category><![CDATA[Automotive Attack Surfaces]]></category>
		<category><![CDATA[car theft]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[http://gdata.youtube.com/schemas/2007#video]]></category>
		<category><![CDATA[in-cabin audio exfiltration]]></category>
		<category><![CDATA[location tracking]]></category>
		<category><![CDATA[long distance vehicle control]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[USENIX]]></category>
		<category><![CDATA[wireless communication]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://gdata.youtube.com/feeds/api/videos/bHfOziIwXic</guid>
		<description><![CDATA[Refereed Paper presented by Stephen Checkoway (University of California, San Diego) at the 20th USENIX Security Symposium (USENIX Security '11), held August 8--12, 2011, in San Francisco, CA.

Authors: Stephen Checkoway, Damon McCoy, Brian Kantor, Dann...]]></description>
		<wfw:commentRss>http://blogs.usenix.org/2011/08/15/comprehensive-experimental-analyses-of-automotive-attack-surfaces/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="rtsp://v7.cache5.c.youtube.com/CigLENy73wIaHwknXjAizs53bBMYESARFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="rtsp://v4.cache7.c.youtube.com/CigLENy73wIaHwknXjAizs53bBMYDSANFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="http://www.youtube.com/v/bHfOziIwXic?version=3&amp;amp;f=user_uploads&amp;amp;app=youtube_gdata" length="" type="application/x-shockwave-flash" />
		</item>
		<item>
		<title>A Security Analysis of the APCO Project 25 Two-Way Radio System</title>
		<link>http://www.youtube.com/watch?v=NW-jRRTPCuw&#038;feature=youtube_gdata</link>
		<comments>http://www.youtube.com/watch?v=NW-jRRTPCuw&#038;feature=youtube_gdata#comments</comments>
		<pubDate>Thu, 11 Aug 2011 17:14:14 +0000</pubDate>
		<dc:creator>USENIXAssociation</dc:creator>
				<category><![CDATA[APCO Project 25]]></category>
		<category><![CDATA[data traffic]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[http://gdata.youtube.com/schemas/2007#video]]></category>
		<category><![CDATA[P25]]></category>
		<category><![CDATA[Security Analysis]]></category>
		<category><![CDATA[selective subframe jamming]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[Two-Way Radio System]]></category>
		<category><![CDATA[USENIX]]></category>
		<category><![CDATA[voice traffic]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://gdata.youtube.com/feeds/api/videos/NW-jRRTPCuw</guid>
		<description><![CDATA[Why (Special Agent) Johnny (Still) Can't Encrypt: A Security Analysis of the APCO Project 25 Two-Way Radio System

Refereed Paper presented by Matt Blaze (University of Pennsylvania) at the 20th USENIX Security Symposium (USENIX Security '11), held August 8--12, 2011, in San Francisco, CA.

Awarded Outstanding Paper

Authors: Sandy Clark, Travis Goodspeed, Perry Metzger, Zachary Wasserman, Kevin Xu, and Matt Blaze, University of Pennsylvania

Abstract: APCO Project 25 (&#34;P25&#34;) is a suite of wireless communications protocols used in the US and elsewhere for public safety two-way (voice) radio systems. The protocols include security options in which voice and data traffic can be cryptographically protected from eavesdropping. This paper analyzes the security of P25 systems against both passive and active adversaries. We found a number of protocol, implementation, and user interface weaknesses that routinely leak information to a passive eavesdropper or that permit highly efficient and difficult to detect active attacks. We introduce new selective subframe jamming attacks against P25, in which an active attacker with very modest resources can prevent specific kinds of traffic (such as encrypted messages) from being received, while emitting only a small fraction of the aggregate power of the legitimate transmitter. We also found that even the passive attacks represent a serious practical threat. In a study we conducted over a two year period in several US metropolitan areas, we found that a significant fraction of the &#34;encrypted&#34; P25 tactical radio traffic sent by federal law enforcement surveillance operatives is actually sent in the clear, in spite of their users' belief that they are encrypted, and often reveals such sensitive data as the names of informants in criminal investigations.]]></description>
		<wfw:commentRss>http://blogs.usenix.org/2011/08/11/a-security-analysis-of-the-apco-project-25-two-way-radio-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="rtsp://v2.cache1.c.youtube.com/CigLENy73wIaHwnsCs8URaNvNRMYESARFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="rtsp://v8.cache7.c.youtube.com/CigLENy73wIaHwnsCs8URaNvNRMYDSANFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="http://www.youtube.com/v/NW-jRRTPCuw?version=3&amp;amp;f=user_uploads&amp;amp;app=youtube_gdata" length="" type="application/x-shockwave-flash" />
		</item>
		<item>
		<title>Network Security in the Medium Term: 2061&#8211;2561 AD</title>
		<link>http://www.youtube.com/watch?v=06iQVwVBWI0&#038;feature=youtube_gdata</link>
		<comments>http://www.youtube.com/watch?v=06iQVwVBWI0&#038;feature=youtube_gdata#comments</comments>
		<pubDate>Thu, 11 Aug 2011 16:56:02 +0000</pubDate>
		<dc:creator>USENIXAssociation</dc:creator>
				<category><![CDATA[Charles Stross]]></category>
		<category><![CDATA[http://gdata.youtube.com/schemas/2007#video]]></category>
		<category><![CDATA[information processing]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[science fiction]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[USENIX]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://gdata.youtube.com/feeds/api/videos/06iQVwVBWI0</guid>
		<description><![CDATA[Keynote Address given by Charles Stross, Author of award-winning science fiction, at the 20th USENIX Security Symposium (USENIX Security '11), held August 8--12, 2011, in San Francisco, CA.

A science fiction writer takes a look at the medium-term impl...]]></description>
		<wfw:commentRss>http://blogs.usenix.org/2011/08/11/network-security-in-the-medium-term-2061-2561-ad/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="rtsp://v4.cache3.c.youtube.com/CigLENy73wIaHwmNWEEFV5Co0xMYESARFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="rtsp://v7.cache8.c.youtube.com/CigLENy73wIaHwmNWEEFV5Co0xMYDSANFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="http://www.youtube.com/v/06iQVwVBWI0?f=user_uploads&amp;amp;app=youtube_gdata" length="" type="application/x-shockwave-flash" />
		</item>
		<item>
		<title>Rethinking passwords</title>
		<link>http://blogs.usenix.org/2010/11/12/rethinking-passwords/</link>
		<comments>http://blogs.usenix.org/2010/11/12/rethinking-passwords/#comments</comments>
		<pubDate>Fri, 12 Nov 2010 19:34:28 +0000</pubDate>
		<dc:creator>Ben Cotton</dc:creator>
				<category><![CDATA[LISA Conference]]></category>
		<category><![CDATA[LISA10]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[technical conference]]></category>

		<guid isPermaLink="false">http://blogs.usenix.org/?p=691</guid>
		<description><![CDATA[&#8220;We have to do better &#8230; The bad guys are pros, they&#8217;re just as good as you are and maybe better.&#8221;  That&#8217;s Bill Cheswick&#8217;s message to the audience in his talk &#8220;Rethinking Passwords.&#8221;  Comparing the password policies of various companies and educational institutions yields a confusing and sometimes contradictory set of requirements.  This makes managing [...]]]></description>
		<wfw:commentRss>http://blogs.usenix.org/2010/11/12/rethinking-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Working with SELinux</title>
		<link>http://blogs.usenix.org/2010/11/08/working-with-selinux/</link>
		<comments>http://blogs.usenix.org/2010/11/08/working-with-selinux/#comments</comments>
		<pubDate>Mon, 08 Nov 2010 15:16:14 +0000</pubDate>
		<dc:creator>Ben Cotton</dc:creator>
				<category><![CDATA[Update]]></category>
		<category><![CDATA[LISA Conference]]></category>
		<category><![CDATA[LISA10]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SELinux]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://blogs.usenix.org/?p=601</guid>
		<description><![CDATA[SELinux is not the most popular of Linux components.  For many admins, myself included, disabling SELinux is a critical part of the system installation process.  The extra security that SELinux provides is generally seen as not worth the ease-of-use impacts.  Fortunately, the tools used to manage SELinux have matured in recent releases and many in [...]]]></description>
		<wfw:commentRss>http://blogs.usenix.org/2010/11/08/working-with-selinux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Advanced Persistent Threat</title>
		<link>http://www.youtube.com/watch?v=Tiwnx6r-VnE&#038;feature=youtube_gdata</link>
		<comments>http://www.youtube.com/watch?v=Tiwnx6r-VnE&#038;feature=youtube_gdata#comments</comments>
		<pubDate>Fri, 20 Aug 2010 18:07:00 +0000</pubDate>
		<dc:creator>USENIXAssociation</dc:creator>
				<category><![CDATA[cyber defense]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[http://gdata.youtube.com/schemas/2007#video]]></category>
		<category><![CDATA[LISA]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[USENIX]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[System Administration]]></category>

		<guid isPermaLink="false">http://gdata.youtube.com/feeds/api/videos/Tiwnx6r-VnE</guid>
		<description><![CDATA[Talk given by Michael K. Daly, Director of Enterprise Security Services for Raytheon Company, at the 23rd Large Installation System Administration Conference (LISA '09).

Critical infrastructures and the governments, corporations, and individuals suppo...]]></description>
		<wfw:commentRss>http://blogs.usenix.org/2010/08/20/the-advanced-persistent-threat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="rtsp://v1.cache6.c.youtube.com/CigLENy73wIaHwlxVv6qxycsThMYESARFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="rtsp://v6.cache1.c.youtube.com/CigLENy73wIaHwlxVv6qxycsThMYDSANFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="http://www.youtube.com/v/Tiwnx6r-VnE?version=3&amp;amp;f=user_uploads&amp;amp;app=youtube_gdata" length="" type="application/x-shockwave-flash" />
		</item>
		<item>
		<title>Searching for Truth, or at Least Data: How to Be an Empiricist Skeptic</title>
		<link>http://www.youtube.com/watch?v=C4rrhbs-eA0&#038;feature=youtube_gdata</link>
		<comments>http://www.youtube.com/watch?v=C4rrhbs-eA0&#038;feature=youtube_gdata#comments</comments>
		<pubDate>Thu, 19 Aug 2010 21:19:07 +0000</pubDate>
		<dc:creator>USENIXAssociation</dc:creator>
				<category><![CDATA[http://gdata.youtube.com/schemas/2007#video]]></category>
		<category><![CDATA[LISA]]></category>
		<category><![CDATA[software testing]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[USENIX]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[System Administration]]></category>

		<guid isPermaLink="false">http://gdata.youtube.com/feeds/api/videos/C4rrhbs-eA0</guid>
		<description><![CDATA[Talk given by Elizabeth D. Zwicky at the 23rd Large Installation System Administration Conference (LISA '09).

What do software testing, security, and successful project planning have in common? They all require the same outlook. Call it &#34;skeptical empiricist,&#34; call it &#34;man from Missouri&#34; (the Show Me state), call it data-driven, but whatever you call it, it involves looking beyond claims and guesses and trying to figure out what the facts are. This talk will provide you with tools and advice on how to find data and make sense of it, plus of course inspiring tales of triumph, disaster, and comedy revolving around the search for facts.]]></description>
		<wfw:commentRss>http://blogs.usenix.org/2010/08/19/searching-for-truth-or-at-least-data-how-to-be-an-empiricist-skeptic/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="rtsp://v1.cache6.c.youtube.com/CigLENy73wIaHwkNeD67heuKCxMYESARFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="rtsp://v6.cache7.c.youtube.com/CigLENy73wIaHwkNeD67heuKCxMYDSANFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="http://www.youtube.com/v/C4rrhbs-eA0?version=3&amp;amp;f=user_uploads&amp;amp;app=youtube_gdata" length="" type="application/x-shockwave-flash" />
		</item>
		<item>
		<title>Capsicum: Practical Capabilities for UNIX</title>
		<link>http://www.youtube.com/watch?v=raNx9L4VH2k&#038;feature=youtube_gdata</link>
		<comments>http://www.youtube.com/watch?v=raNx9L4VH2k&#038;feature=youtube_gdata#comments</comments>
		<pubDate>Wed, 18 Aug 2010 21:11:25 +0000</pubDate>
		<dc:creator>USENIXAssociation</dc:creator>
				<category><![CDATA[http://gdata.youtube.com/schemas/2007#video]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[UNIX]]></category>
		<category><![CDATA[USENIX]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://gdata.youtube.com/feeds/api/videos/raNx9L4VH2k</guid>
		<description><![CDATA[Awarded Best Student Paper!

Paper presented by Robert N.M. Watson, University of Cambridge, at the 19th USENIX Security Symposium (USENIX Security '10).

Paper authors: Robert N.M. Watson and Jonathan Anderson, University of Cambridge; Ben Laurie and ...]]></description>
		<wfw:commentRss>http://blogs.usenix.org/2010/08/18/capsicum-practical-capabilities-for-unix/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="rtsp://v5.cache4.c.youtube.com/CigLENy73wIaHwlpHxW-9HGjrRMYESARFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="rtsp://v5.cache1.c.youtube.com/CigLENy73wIaHwlpHxW-9HGjrRMYDSANFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="http://www.youtube.com/v/raNx9L4VH2k?version=3&amp;amp;f=user_uploads&amp;amp;app=youtube_gdata" length="" type="application/x-shockwave-flash" />
		</item>
		<item>
		<title>VEX: Vetting Browser Extensions for Security Vulnerabilities</title>
		<link>http://www.youtube.com/watch?v=0Z4ClRuWlDE&#038;feature=youtube_gdata</link>
		<comments>http://www.youtube.com/watch?v=0Z4ClRuWlDE&#038;feature=youtube_gdata#comments</comments>
		<pubDate>Wed, 18 Aug 2010 21:04:08 +0000</pubDate>
		<dc:creator>USENIXAssociation</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[http://gdata.youtube.com/schemas/2007#video]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[USENIX]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://gdata.youtube.com/feeds/api/videos/0Z4ClRuWlDE</guid>
		<description><![CDATA[Awarded Best Paper!

Paper presented by Sruthi Bandhakavi, University of Illinois at Urbana-Champaign, at the 19th USENIX Security Symposium (USENIX Security '10).

Paper authors: Sruthi Bandhakavi, Samuel T. King, P. Madhusudan, and Marianne Winslett,...]]></description>
		<wfw:commentRss>http://blogs.usenix.org/2010/08/18/vex-vetting-browser-extensions-for-security-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="rtsp://v7.cache6.c.youtube.com/CigLENy73wIaHwkxlJYblQKe0RMYESARFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="rtsp://v1.cache2.c.youtube.com/CigLENy73wIaHwkxlJYblQKe0RMYDSANFEgGUgx1c2VyX3VwbG9hZHMM/0/0/0/video.3gp" length="" type="video/3gpp" />
<enclosure url="http://www.youtube.com/v/0Z4ClRuWlDE?version=3&amp;amp;f=user_uploads&amp;amp;app=youtube_gdata" length="" type="application/x-shockwave-flash" />
		</item>
	</channel>
</rss>

