<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MattJay Security &#187; fundamentals</title>
	<atom:link href="http://www.mattjaysecurity.com/category/fundamentals/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mattjaysecurity.com</link>
	<description>The musings of a young information security professional on current security events.</description>
	<lastBuildDate>Wed, 02 Feb 2011 17:09:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Reveal Passwords Bookmarklet &#8211; What Could Go Wrong?</title>
		<link>http://www.mattjaysecurity.com/2011/02/reveal-passwords-bookmarklet-what-could-go-wrong/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://www.mattjaysecurity.com/2011/02/reveal-passwords-bookmarklet-what-could-go-wrong/#comments</comments>
		<pubDate>Wed, 02 Feb 2011 17:09:14 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[fundamentals]]></category>
		<category><![CDATA[Password]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=131</guid>
		<description><![CDATA[Lifehacker posted an article this AM about a Bookmarklet that would reveal passwords on your screen that are normally bulleted out. It is advertised as a way to help remember passwords that are saved in some sort of autofill application such as LastPass or just in your browser. Sounds terrific so you don&#8217;t forget them [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="whatcouldgowrong" src="http://www.liquidmatrix.org/blog/wp-content/uploads/2011/02/whatcouldgowrong.jpg" alt="" width="350" height="230" />Lifehacker posted an article this AM about a Bookmarklet that would reveal passwords on your screen that are normally bulleted out.</p>
<p>It is advertised as a way to help remember passwords that are saved in some sort of autofill application such as LastPass or just in your browser. Sounds terrific so you don&#8217;t forget them by heart.</p>
<p>I liken this to the fact that 10 years ago I had to dial everybody&#8217;s phone number on my home phone manually, and now I just pull up their contact in my cell and hit send. The funny thing is those friends and family I still call from the pre-cell phone era are the only people&#8217;s numbers I know by heart.</p>
<p>But even though this bookmarklet sounds like a good idea in theory, I have a problem with it. How many times have you been typing your login information in and started typing your password accidentally in the username field? For me it has happened a decent number of times and a handful of those were while people were behind me watching, which of course was followed by me changing my password. So now you are telling me there is a javascript bookmarklet being advertised to do such a thing *on purpose*?</p>
<p>What could go wrong here?</p>

<div class="sociable">
<div class="sociable_tagline">
<strong>Share and Enjoy:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;bodytext=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;notes=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;t=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;annotation=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;t=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;s=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  href="http://twitter.com/home?status=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2011/02/reveal-passwords-bookmarklet-what-could-go-wrong/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Computer Security Week 1</title>
		<link>http://www.mattjaysecurity.com/2009/01/computer-security-week-1/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://www.mattjaysecurity.com/2009/01/computer-security-week-1/#comments</comments>
		<pubDate>Fri, 02 Jan 2009 00:22:00 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[computer]]></category>
		<category><![CDATA[fundamentals]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=4</guid>
		<description><![CDATA[In the the very first week of my Computer Security class we were presented with a broad overview of the upcoming semester. We touched everything from the CIA triad (Confidentiality, Integrity, and Availability) to discussing the more public view of security (i.e. the cyber section of the FBI and Secret Service, identity theft, etc.). We [...]]]></description>
			<content:encoded><![CDATA[<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_gq8ASTy40oI/SV1ezvjTfjI/AAAAAAAAACM/UhTFwElRC7E/s1600-h/CIA+triad.png"><img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 247px; height: 320px;" src="http://1.bp.blogspot.com/_gq8ASTy40oI/SV1ezvjTfjI/AAAAAAAAACM/UhTFwElRC7E/s320/CIA+triad.png" alt="" id="BLOGGER_PHOTO_ID_5286485780633714226" border="0" /></a><br /><span style="font-size:100%;">                  In the the very first week of my Computer Security class we were presented with a broad overview of the upcoming semester.  We touched everything from the CIA triad (Confidentiality, Integrity, and Availability) to discussing the more public view of security (i.e. the cyber section of the FBI and Secret Service, identity theft, etc.).</p>
<p>We were also presented with the following video of Richard Clarke who is the Chairman of Good Harbor Consulting, senior White House Advisor to the last three presidents and an expert in security including cyber security and counterterrorism.  If you would like to watch it you can skip the first 7:30 minutes which is just PR stuff and an introduction.</p>
<p><embed src="http://blip.tv/play/Aa+zFYreFg" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="320" height="270"></embed></p>
<p>&#8220;Richard A. Clarke is an internationally recognized expert on security, including homeland security, national security, cyber security, and counterterrorism. He is currently Chairman of Good Harbor Consulting and an on-air consultant for ABC News. Clarke served the last three Presidents as a senior White House Advisor. Over the course of an unprecedented 11 consecutive years of White House service, he held the titles of Special Assistant to the President for Global Affairs, National Coordinator for Security and Counterterrorism, and Special Advisor to the President for Cyber Security. His published works include the New York Times #1 bestseller Against All Enemies, Scorpion&#8217;s Gate, and Breakpoint. Mr. Clarke will be discussing the current state of the war on terrorism and what it means for homeland security and technology.&#8221;</p>
<p>The class was presented with the following.</p>
<p>&#8220;Week 1</p>
<p>The objectives for this week are to outline what expectations the students may have from the teacher, and what expectation the teacher has from the students. A brief preview for the semester will be provided. At the end of the week, the following topics will have been covered.<br /></span>
<ul>
<li><span style="font-size:100%;">Fundamental concepts of information security</span></li>
<li><span style="font-size:100%;">Common forms of malware</span></li>
<li><span style="font-size:100%;">Information Security Life Cycle</span></li>
</ul>
<p> <span style="font-size:100%;"><br />Assignment 1<br />Watch this movie and comment on it in your course blog. You can skip over the first 7:30 minutes, as they are just public relations.</p>
<p>Can you relate to this clip? Do you see any effects of computer security controls in your daily life? What kind of controls do you see? How do they affect you?&#8221;</p>
<p><span style="font-weight: bold;">If you&#8217;d like, I&#8217;d be interested to see a few responses from other people who wish to leave comments.</p>
<p></span>In the next few weeks of our meetings we covered respectively Laws and Ethics, Authentication, and Access Control.  My next post or two will cover these topics and then we move on to the Defender and Attacker life cycle and break down each step along the way of each.<br /></span></p>

<div class="sociable">
<div class="sociable_tagline">
<strong>Share and Enjoy:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F01%2Fcomputer-security-week-1%2F&amp;title=Computer%20Security%20Week%201&amp;bodytext=%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20In%20the%20the%20very%20first%20week%20of%20my%20Computer%20Security%20class%20we%20were%20presented%20with%20a%20broad%20overview%20of%20the%20upcoming%20semester.%20%20We%20touched%20everything%20from%20the%20CIA%20triad%20%28Confidentiality%2C%20Integrity%2C%20and%20Availability%29%20to%20discussing%20the%20mo" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F01%2Fcomputer-security-week-1%2F&amp;title=Computer%20Security%20Week%201&amp;notes=%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20In%20the%20the%20very%20first%20week%20of%20my%20Computer%20Security%20class%20we%20were%20presented%20with%20a%20broad%20overview%20of%20the%20upcoming%20semester.%20%20We%20touched%20everything%20from%20the%20CIA%20triad%20%28Confidentiality%2C%20Integrity%2C%20and%20Availability%29%20to%20discussing%20the%20mo" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F01%2Fcomputer-security-week-1%2F&amp;t=Computer%20Security%20Week%201" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F01%2Fcomputer-security-week-1%2F&amp;title=Computer%20Security%20Week%201&amp;annotation=%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20In%20the%20the%20very%20first%20week%20of%20my%20Computer%20Security%20class%20we%20were%20presented%20with%20a%20broad%20overview%20of%20the%20upcoming%20semester.%20%20We%20touched%20everything%20from%20the%20CIA%20triad%20%28Confidentiality%2C%20Integrity%2C%20and%20Availability%29%20to%20discussing%20the%20mo" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F01%2Fcomputer-security-week-1%2F&amp;title=Computer%20Security%20Week%201&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20In%20the%20the%20very%20first%20week%20of%20my%20Computer%20Security%20class%20we%20were%20presented%20with%20a%20broad%20overview%20of%20the%20upcoming%20semester.%20%20We%20touched%20everything%20from%20the%20CIA%20triad%20%28Confidentiality%2C%20Integrity%2C%20and%20Availability%29%20to%20discussing%20the%20mo" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Computer%20Security%20Week%201&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F01%2Fcomputer-security-week-1%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F01%2Fcomputer-security-week-1%2F&amp;title=Computer%20Security%20Week%201" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F01%2Fcomputer-security-week-1%2F&amp;title=Computer%20Security%20Week%201" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F01%2Fcomputer-security-week-1%2F&amp;t=Computer%20Security%20Week%201&amp;s=%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20In%20the%20the%20very%20first%20week%20of%20my%20Computer%20Security%20class%20we%20were%20presented%20with%20a%20broad%20overview%20of%20the%20upcoming%20semester.%20%20We%20touched%20everything%20from%20the%20CIA%20triad%20%28Confidentiality%2C%20Integrity%2C%20and%20Availability%29%20to%20discussing%20the%20mo" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  href="http://twitter.com/home?status=Computer%20Security%20Week%201%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F01%2Fcomputer-security-week-1%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2009/01/computer-security-week-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

