<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-8709972</id><updated>2009-02-21T21:12:35.196+11:00</updated><title type='text'>michael silk</title><subtitle type='html'>security</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://michaelsilk.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8709972/posts/default'/><link rel='alternate' type='text/html' href='http://michaelsilk.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>michael silk</name><uri>http://www.blogger.com/profile/17452837115340269487</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8709972.post-110127008096203709</id><published>2004-11-24T15:10:00.000+11:00</published><updated>2004-11-25T10:19:50.276+11:00</updated><title type='text'>Followup on "Solution to Phishing"</title><summary type='text'>Just a quick note..I left a few disadvantages out :)a) Username/email disclosure.It would be appropriate, from a user's point of view, for them to get a message confirming whether the email address or username that they typed in was correct or not. If they were to receive no such message they may sit back and wait for the email to come and never receive it hence getting quite annoyed :)b</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8709972/posts/default/110127008096203709'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8709972/posts/default/110127008096203709'/><link rel='alternate' type='text/html' href='http://michaelsilk.blogspot.com/2004/11/followup-on-solution-to-phishing.html' title='Followup on &quot;Solution to Phishing&quot;'/><author><name>michael silk</name><uri>http://www.blogger.com/profile/17452837115340269487</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01481849892363671010'/></author></entry><entry><id>tag:blogger.com,1999:blog-8709972.post-110117926403507378</id><published>2004-11-23T13:41:00.000+11:00</published><updated>2004-12-01T10:34:16.470+11:00</updated><title type='text'>Article - A Solution to Phishing</title><summary type='text'>Michael Silk ( version: 1.0.0, released on: 23rd of November, 2004 ) Introduction For those who don't know what Phishing is, read this (it isn't very long) ... Solution Now that you are up to speed, we can discuss a proposed solution. The idea is to use a "one-time password-based" system. As we know, Phishing works by receiving your username and password. However, what if your password is only</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8709972/posts/default/110117926403507378'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8709972/posts/default/110117926403507378'/><link rel='alternate' type='text/html' href='http://michaelsilk.blogspot.com/2004/11/article-solution-to-phishing.html' title='Article - A Solution to Phishing'/><author><name>michael silk</name><uri>http://www.blogger.com/profile/17452837115340269487</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01481849892363671010'/></author></entry><entry><id>tag:blogger.com,1999:blog-8709972.post-109770724390459460</id><published>2004-10-14T08:37:00.000+10:00</published><updated>2004-11-23T14:24:04.606+11:00</updated><title type='text'>Article - Really random numbers</title><summary type='text'>Michael Silk ( version: 1.0.2, released on: 16th of August, 2004 ) Random numbers are used in almost all encryption algorithms to generate encryption keys and random pad data. Unfortunately, the random number generators (RNG's) provided by most programming SDK's do not provide adequate security. GoalTo provide a system to obtain "real" random numbers and use them for our security purposes. </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8709972/posts/default/109770724390459460'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8709972/posts/default/109770724390459460'/><link rel='alternate' type='text/html' href='http://michaelsilk.blogspot.com/2004/10/article-really-random-numbers.html' title='Article - Really random numbers'/><author><name>michael silk</name><uri>http://www.blogger.com/profile/17452837115340269487</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01481849892363671010'/></author></entry><entry><id>tag:blogger.com,1999:blog-8709972.post-109770642921789586</id><published>2004-10-14T08:25:00.000+10:00</published><updated>2004-11-23T14:28:42.773+11:00</updated><title type='text'>Welcome Message</title><summary type='text'>Hello, and welcome. This site is intended as a publishing spot for security-based articles written by me: Michael Silk.  This is a temporary site and you should not come back and check it ... if there is anything interesting here you will be notified via a mailing list :)</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8709972/posts/default/109770642921789586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8709972/posts/default/109770642921789586'/><link rel='alternate' type='text/html' href='http://michaelsilk.blogspot.com/2004/10/welcome-message.html' title='Welcome Message'/><author><name>michael silk</name><uri>http://www.blogger.com/profile/17452837115340269487</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='01481849892363671010'/></author></entry></feed>