<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Who is Hahleq?</title>
	<atom:link href="http://www.timrenshaw.com/blog/feed" rel="self" type="application/rss+xml" />
	<link>http://www.timrenshaw.com/blog</link>
	<description>Tim Renshaw, that's who!</description>
	<lastBuildDate>Wed, 28 Jul 2010 07:06:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>The Two Faces of the Ground Zero Mosque</title>
		<link>http://www.timrenshaw.com/blog/archives/357</link>
		<comments>http://www.timrenshaw.com/blog/archives/357#comments</comments>
		<pubDate>Wed, 28 Jul 2010 07:06:23 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Tim's Opinion]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=357</guid>
		<description><![CDATA[VDHs Private Papers:: The Two Faces of the Ground Zero Mosque. Though any given muslim may not be your enemy, don&#8217;t be deceived America, Islam is our enemy and the enemy of all freedom and liberty loving people.  The building of this mosque must be stopped!]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.victorhanson.com/articles/ibrahim072710.html">VDHs Private Papers:: The Two Faces of the Ground Zero Mosque</a>.</p>
<p>Though any given muslim may not be your enemy, don&#8217;t be deceived America, Islam is our enemy and the enemy of all freedom and liberty loving people.  The building of this mosque must be stopped!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/357/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is this man Obamas worst nightmare?</title>
		<link>http://www.timrenshaw.com/blog/archives/355</link>
		<comments>http://www.timrenshaw.com/blog/archives/355#comments</comments>
		<pubDate>Thu, 22 Jul 2010 21:25:37 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=355</guid>
		<description><![CDATA[I hope Herman Cain does run.   I&#8217;d vote for him with no qualms whatsoever. via Is this man Obamas worst nightmare?.]]></description>
			<content:encoded><![CDATA[<p>I hope Herman Cain does run.   I&#8217;d vote for him with no qualms whatsoever.</p>
<p>via <a href="http://www.wnd.com/index.php?fa=PAGE.view&amp;pageId=181961">Is this man Obamas worst nightmare?</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/355/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fabulous interview of Victor Davis Hanson</title>
		<link>http://www.timrenshaw.com/blog/archives/347</link>
		<comments>http://www.timrenshaw.com/blog/archives/347#comments</comments>
		<pubDate>Tue, 20 Jul 2010 16:13:19 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Politics]]></category>
		<category><![CDATA[Tim's Opinion]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=347</guid>
		<description><![CDATA[As usual, not much to quibble with as far as I&#8217;m concerned.  If only we&#8217;d not let the union-backing, liberals polute our education system over the last 50 years, we&#8217;d have more citizens of reason than emotion and America wouldn&#8217;t be in the increasingly sad shape it is. via VDHs Private Papers:: Interview with Blog4History.]]></description>
			<content:encoded><![CDATA[<p>As usual, not much to quibble with as far as I&#8217;m concerned.  If only we&#8217;d not let the union-backing, liberals polute our education system over the last 50 years, we&#8217;d have more citizens of reason than emotion and America wouldn&#8217;t be in the increasingly sad shape it is.</p>
<p>via <a href="http://www.victorhanson.com/articles/hanson070410B.html">VDHs Private Papers:: Interview with Blog4History</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/347/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Product Watch: New Microsoft Identity Technology Aims To Protect Online Privacy &#8211; DarkReading</title>
		<link>http://www.timrenshaw.com/blog/archives/345</link>
		<comments>http://www.timrenshaw.com/blog/archives/345#comments</comments>
		<pubDate>Tue, 13 Jul 2010 21:54:30 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Digital Life]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=345</guid>
		<description><![CDATA[Product Watch: New Microsoft Identity Technology Aims To Protect Online Privacy &#8211; DarkReading. All the way back from March.  Can&#8217;t believe I missed this for so long.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.darkreading.com/security/privacy/showArticle.jhtml?articleID=223101456">Product Watch: New Microsoft Identity Technology Aims To Protect Online Privacy &#8211; DarkReading</a>.</p>
<p>All the way back from March.  Can&#8217;t believe I missed this for so long.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/345/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sales Engineer Wanted in Silicon Valley</title>
		<link>http://www.timrenshaw.com/blog/archives/344</link>
		<comments>http://www.timrenshaw.com/blog/archives/344#comments</comments>
		<pubDate>Mon, 12 Jul 2010 19:50:56 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/archives/344</guid>
		<description><![CDATA[Looking for a Sales Engineer based out of Silicon Valley area. Please contact me at tim.renshaw@arcot.com with resume or referral information for immediate consideration.]]></description>
			<content:encoded><![CDATA[<p>Looking for a Sales Engineer based out of Silicon Valley area. Please contact me at tim.renshaw@arcot.com with resume or referral information for immediate consideration. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/344/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Chrome Extension Powers Android-Based Payments &#8212; InformationWeek</title>
		<link>http://www.timrenshaw.com/blog/archives/342</link>
		<comments>http://www.timrenshaw.com/blog/archives/342#comments</comments>
		<pubDate>Sun, 11 Jul 2010 05:22:17 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Digital Life]]></category>
		<category><![CDATA[Gear]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=342</guid>
		<description><![CDATA[Google Chrome Extension Powers Android-Based Payments &#8212; InformationWeek. Interesting.  I&#8217;m going to try and see an implementation of this and see how it works with my new Android-based phone.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.informationweek.com/news/infrastructure/management/showArticle.jhtml?articleID=225702442&amp;cid=nl_tw_security_2010-07-07_t">Google Chrome Extension Powers Android-Based Payments &#8212; InformationWeek</a>.</p>
<p>Interesting.  I&#8217;m going to try and see an implementation of this and see how it works with my new Android-based phone.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/342/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Obamanation continues&#8230;</title>
		<link>http://www.timrenshaw.com/blog/archives/340</link>
		<comments>http://www.timrenshaw.com/blog/archives/340#comments</comments>
		<pubDate>Mon, 21 Jun 2010 03:41:07 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=340</guid>
		<description><![CDATA[World Sees Obama as Incompetent and Amateur The World from Berlin: Will Obama Be the &#8216;Jimmy Carter of the 21st Century&#8217;? Two choices:  The Obamanation is either: 1)  A complete idealistic moron on the scale of and beyond Jimmy Carter. 2)  A true Marxist believer who is actively working towards the damage of the United [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.usnews.com/articles/opinion/2010/06/18/mort-zuckerman-world-sees-obama-as-incompetent-and-amateur.html" target="_blank">World Sees Obama as Incompetent and Amateur</a></p>
<p><a href="http://www.spiegel.de/international/germany/0,1518,701279,00.html" target="_blank">The World from Berlin:  Will Obama Be the &#8216;Jimmy Carter of the 21st Century&#8217;?</a></p>
<p>Two choices:  The Obamanation is either:</p>
<p>1)  A complete idealistic moron on the scale of and beyond Jimmy Carter.</p>
<p>2)  A true Marxist believer who is actively working towards the damage of the United States.</p>
<p>Another way of thinking of it:</p>
<p>1) bumbling fool</p>
<p>2) evil genius</p>
<p>There are really no alternatives.  He either is accidentally or on purpose destroying America and her leadership role for overall good in the world.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/340/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Arthur Laffer WSJ Article &#8211; miss this at your own risk!</title>
		<link>http://www.timrenshaw.com/blog/archives/336</link>
		<comments>http://www.timrenshaw.com/blog/archives/336#comments</comments>
		<pubDate>Thu, 17 Jun 2010 20:53:12 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Economics]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Politics]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=336</guid>
		<description><![CDATA[Arthur Laffer June 6, 2010 in WSJ:  Tax Hikes and the 2011 Economic Collapse]]></description>
			<content:encoded><![CDATA[<p>Arthur Laffer June 6, 2010 in WSJ:  <a href="http://online.wsj.com/article/SB10001424052748704113504575264513748386610.html#articleTabs%3Darticle" target="_blank">Tax Hikes and the 2011 Economic Collapse</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/336/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another man in the middle attack verified</title>
		<link>http://www.timrenshaw.com/blog/archives/330</link>
		<comments>http://www.timrenshaw.com/blog/archives/330#comments</comments>
		<pubDate>Tue, 02 Mar 2010 17:44:15 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Digital Life]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=330</guid>
		<description><![CDATA[Blizzard has admitted that there is an active and successful attack against their Blizzard Authenticators. Man in the middle attacks circumventing authenticators This makes perfect sense as: OTP tokens such as the Authenticator are obviously susceptible to a live man-in-the-middle (MITM) attack as has been demonstrated as something well beyond &#8220;theoritical&#8221; a decade ago.  The [...]]]></description>
			<content:encoded><![CDATA[<p>Blizzard has admitted that there is an active and successful attack against their Blizzard Authenticators.</p>
<p><a href="http://www.wow.com/2010/02/28/man-in-the-middle-attacks-circumventing-authenticators/">Man in the middle attacks circumventing authenticators</a></p>
<p>This makes perfect sense as:</p>
<ol>
<li>OTP tokens such as the Authenticator are obviously susceptible to a live man-in-the-middle (MITM) attack as has been demonstrated as something well beyond &#8220;theoritical&#8221; a decade ago.  The issue isn&#8217;t with the token vendor or type, it is with the entire scheme of a short-lived, shared secret in an increasingly real-time, share-it-and-lose-it networked world.</li>
<li>Blizzard is likely the largest OTP deployment on the planet.  They haven&#8217;t released any numbers, but if even 10% of users use it, that&#8217;s roughly 1.2 million users.  i.e. Big ROI.</li>
<li>There&#8217;s money in &#8220;them thar accounts&#8221;.</li>
</ol>
<p><strong>What can you do?</strong></p>
<ul>
<li>All the normal things, run anti-virus, anti-spyware, etc.</li>
<li>Log into WoW from as few PCs as possible and only those you absolutely control.</li>
<li>Try to log into any web page that requires authenticator authentication as little as possible, as a man-in-the-middle attack in a browser doesn&#8217;t require a local keylogger file as is being used in this current attack</li>
</ul>
<p><strong>What can Blizzard do?</strong></p>
<ul>
<li>The obvious:
<ul>
<li>I believe their thick client already scans for a large number of known attack libraries, files, etc. at the time of launch.  This will be added to the list.</li>
<li>I also suspect they are looking for suspicious behavior to the extent that they can with the client.  This type of behavior should be added to the list for that.  Also, they may want to consider increasing the terms and conditions of what we allow them to do in the client with regard to looking for vulnerabilities and suspicious behavior.</li>
</ul>
</li>
<li>Less Obvious:  Blizzard should seriously consider having a separate authentication mechanism for getting into the game client than for logging into the various portions of Battle.Net / WorldofWarcraft.com / etc.  Why?
<ul>
<li>The more times you use the Authenticator, the more opportunities you have to be compromised.</li>
<li>Blizzard has more controls and capabilities to protect the login through their seriously &#8220;thick&#8221; client to provide additional protections to the authenticator login.</li>
<li>Blizzard has much less control over the login environment and ability to monitor what is happening in a web-based authentication with an authenticator.  This current attack is heavy-weight in regards to payload necessary to pull it off.  A successful MITM attack in a web login requires much less work and no payload (client software installed) to execute.</li>
<li>What does the attacker want access to, my WoW account details or the stuff on my various characters, in my banks or my guild&#8217;s banks?  Go look at what is on file in your &#8220;My Account&#8221; section. Ask yourself:
<ul>
<li>What is there that an attacker couldn&#8217;t get more readily and simply somewhere else given Blizzard is following good practices with regard to what details are shown, masked, etc.?</li>
<li>What can the attacker do to you there?  Change your password?  Why bother when I can steal both your static password and dynamic password in a simple web-based MITM attack?  As you now realize, an attacker only need to compromise you one time.  They don&#8217;t need to have a reusable password.</li>
<li>How about turn off your authenticator?  Hopefully you would stop and think seriously about providing the serial number of your Authenticator if asked outside of your specifically intending to turn it off.</li>
</ul>
</li>
</ul>
</li>
<li>My suggestion to Blizzard is to consequently move authenticator management and use completely into the WoW client and only ever ask for the Authenticator code from within the client for game session login.  Enable the ability and strongly suggest to users that they use a separate password for Battle.Net web page logins (sans Authenticator) and another separate password to use in the game client with your Authenticator).</li>
<li>Lastly, and I know from first-hand experience in discussing this with Blizzard devs that this probably won&#8217;t fly, but seriously consider offering additional forms of authentication that aren&#8217;t susceptible to MITM attacks.  I know the alternatives aren&#8217;t as globally friendly for all our WoW brethren that login from shared network cafe PCs, but that&#8217;s not the whole market and those of us not constrained in that fashion would like something better if you offered it.  More work for you, yes.  Better security for us and retention of us as customers, yes.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/330/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Majority says government a threat to citizens rights</title>
		<link>http://www.timrenshaw.com/blog/archives/326</link>
		<comments>http://www.timrenshaw.com/blog/archives/326#comments</comments>
		<pubDate>Fri, 26 Feb 2010 17:22:40 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Tim's Opinion]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=326</guid>
		<description><![CDATA[CNN Poll: Majority says government a threat to citizens rights via CNN Poll: Majority says government a threat to citizens’ rights. Maybe there is hope given that this apparently &#8220;astonishing poll&#8221; reflects the firmly held belief of the crafters of the U.S. Constitution.  Government is an evil.  A necessary evil, but evil all the same [...]]]></description>
			<content:encoded><![CDATA[<p>CNN Poll: Majority says government a threat to citizens rights</p>
<p>via <a href="http://politicalticker.blogs.cnn.com/2010/02/26/cnn-poll-majority-says-government-a-threat-to-citizens-rights/?fbid=ooBQYHNqtcq">CNN Poll: Majority says government a threat to citizens’ rights</a>.</p>
<p>Maybe there is hope given that this apparently &#8220;astonishing poll&#8221; reflects the firmly held belief of the crafters of the U.S. Constitution.  Government is an evil.  A necessary evil, but evil all the same and is to be kept small and easy to stomp on when it starts to do what it must by its nature&#8230; restrict freedom of the individual.</p>
<p>Want to fix the economy?  Want to fix healthcare?</p>
<ul>
<li>Reduce the number of regulations everywhere.</li>
<li>Reduce taxes across the board.</li>
<li>Reduce all levels of government employment.</li>
<li>Break the unions in all government hiring so the weak and the lazy can actually be fired.  (Throw in the completely evil NEA while you&#8217;re at it).</li>
<li>Introduce &#8220;loser pays&#8221; tort reform.</li>
</ul>
<p>That would do for a start as there would be such a boom as hasn&#8217;t been seen since at least the post-WW2 or 1980s boom and would likely be even bigger than that.  Then the problem just becomes keeping those that feel guilty for living in the greatest country ever on earth to keep from gaining power and undoing what makes it great.  Once we leave this obamanation behind, let&#8217;s vow to never return.  Let our rally cry be, &#8220;Remember Carter and the obamanation!&#8221;.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/326/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
