So tell me again why we’re such a threat if we’re included!

Recently yet another debacle has unfolded with Citigroup sending out letters to customers and former customers informing them that their data was lost in transit, all up an estimated 3.9 million records. This is about the 4th such incident in as many weeks to come to light, and the worst to date.

Surely the US banking industry should be loosing money over this as karmic retribution for such poor standards in handling private and confidential information, yet this just doesn’t seem to be the case.

So why are we being punished (by not being included) because we might cause harm, when these banks are doing everything they can to look like a fly by night operation?

CNN has the full story.

Gemplus Kit

I had a few more PKI cards turn up today, so far no luck with those either, even though they have been pre-loaded with a GemSAFE image. I plan to contact the local distribtor in the morning to see if we can nut something out. I did take a stanley knife to the GemSAFE card I have to fit it in the GemPC Key reader, and it works quite nicely.

Below are some photos I took earlier on tonight.
Continue reading

Group Meeting – Assurance Party for Hawaii

McKinley Community School for Adults
634 Pensacola Street, Room 208
Honolulu, HI 96814
on June 4 @ 10am.

The contact at the Linux Group is: Michael Bishop

2005 Annual General Meeting

This is the official 30 days notice for the next AGM.

The next AGM will be held on the 3rd of July 2005 at 1PM GMT, it will be held via IRC again this year.

Conversions for local time:

11pm Sydney
9pm Perth
2pm London
9am New York
6am San Francisco

As of the other day invoices for membership payments were sent out to all current members, everyone wishing to vote and/or be nominated for a board position must be a financial member at the time of the AGM and we must receive payment on or before the 1st of July (local time) so that we can have time to prepare for the AGM.

So far the agenda only consists of a few items.

1) Financial Summary
2) Any pending membership forms to be voted on
3) Call for nominations of board positions and votes if needed

Please contact me ASAP if there should be any alterations to the agenda ASAP.

Industrial Espionage using Trojan horses

Interesting run down on the trojan horse doing the rounds in Israel and how the whole kit and caboodle was brought down by simply targeting the wrong person, and then that person finding their information leaked on the internet.

Read on for more details

6th International Free Software Forum

The 6th International Free Software Forum will happen in June, 1st to 4th, in Porto Alegre, RS, Brasil.
CAcert assurers will be present with a stand, doing mass-assurances, up to 150 points in a row.
If you plan to be assured, please register with CAcert.org before being assured, and bring two original identification documents with photo, recognized by Brailian government as valid (ID cards from Mercosul countries and Passports are also valid)

Solving the certificate distribution problem

For a long time now I’ve realised one of the biggest problems with PKI, especially in organisations, is distribution and management of the keys/certificates. So now that I actually have some hardware to play with it’s enabled me to start working on some solutions to this problem.

My first solution to this problem was also my first attempt at coding a PHP-GTK application as well, one of the benefits of PHP-GTK is it’s ability to be run across many platforms similar to java and .net, the down side was a major lack of decent examples and documentation. I came across numerous applications in the “Hello World”, and some very very advanced applications such as the novap2p app, but there was very little in the way of what I was attempting, so hopefully it will serve as a good demo for others as well as a useful tool for people with hardware crypto devices. The other down side is poor GUI design tools, I ended up using glade, but it is by far the worst GUI design tool I’ve ever used, although I don’t know that the full blame lies with glade, but it could have been made so much better, all the elements are there just some of the defaults are brain dead.

In any case, and a number of other non-php/gtk related issue later, I’ve posted the app online as well as some screen shots to the wiki, it’s a very basic app to make things easier in getting certificates signed and onto PKI cards, but it does work pretty well even if I do say so myself.

Is it finally time to sound the death knell to passwords?

Security mechanisms can be defined in the following ways “something you know”, “something you have” and “something you are”.

Passwords are something you know
PKI cards/tokens are something you have
Biometrics is something you are

The problem I have with biometrics is you can’t change the tokens, and this can be bad for a number of reasons. For example, some new cars come with a biometric reader so they can claim they are harder to steal, but as one proud new owner found out it just makes criminals hurt you more, so now he doesn’t have a car and he has one less finger, that’s right, they stole his car and cut off his finger as well!

My preference lies with something you have, that is PKI hardware, which in most cases also requires a PIN, which is something you know, which adds up to 2 factor authentication. The beauty of this system is that the PIN and the card by themselves are useless, having the card by itself is useless because if you get the PIN wrong 3 times the cards will lock themselves to prevent brute force attacks, and of course the PIN by itself is pointless.

And so begins my epic tale of getting PKI hardware to work with Linux, and the difficulty I encountered highlighting one of the many reasons PKI hasn’t taken off in a big way.

This week I met up with a nice gentlemen, who happened to be the distributor for Gemplus products in Australia/New Zealand, and was kind enough to give me a few of their products for evaluation purposes. I believe others have also managed to get evaluation kit from Aladdin as well, check the main mailing list archive for details on that.

In any case this was my first look at any kind of PKI based hardware, and as per usual for Linux driver support and integration between applications leave a lot to be desired, but the lack of coherent documentation was an even bigger headache.

Read on for more Continue reading

2005 Annual General Meeting

Some of you may be unaware, however we’ve pencilled the 3rd of July (for most time zones) in as the date of the next AGM. By law we are required to hold an AGM every 12 months.

If you would like to vote on, or be nominated for any of the board positions you must either become a member, or renew your membership by the 1st of July (so we can process things in time for the meeting).

If you would like to become a member it’s encouraged that you read our rules, as this has information covering most/all questions about memberships and board roles, it also has the membership form on the 2nd last page that needs to be filled out and signed.

Adobe’s PDF editor can digitally sign documents, or you can print it out and scan it. Once you have a signed document (either digital or written signatures) you need to email this to secretary at CAcert org. Once received all new membership requests will be dealt with as the first order of business at the next AGM.

It’s encouraged that everyone that wants to vote or be nominated for a role also get their membership paid for before the AGM as this will ensure your vote is valid and able to be counted.

Membership is only US$10/year, and if you don’t want to become a member, but just want to donate some money to CAcert that is also welcome.

Conference – Prologic Prologue 2005

http://www.tostitilburg.nl/culture2/index.php/prologic/ May 27-29, TOSti, Tilburg, Holland. There will be a CAcert Assurers session on Friday 27th of May after 3 pm.