<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.pluralsight.com/community/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security Briefs - All Comments</title><link>http://www.pluralsight.com/community/blogs/keith/default.aspx</link><description>by Keith Brown</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>re: CardSpace v2 moving into a new role?</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2009/05/20/cardspace-v2-moving-into-a-new-role.aspx#68554</link><pubDate>Mon, 29 Jun 2009 13:40:52 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:68554</guid><dc:creator>keith-brown</dc:creator><description>&lt;p&gt;For the latest drops, I&amp;#39;d follow the download link from the main Geneva page: &lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/geneva"&gt;www.microsoft.com/geneva&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The client is called CardSpaceGeneva.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=68554" width="1" height="1"&gt;</description></item><item><title>re: CardSpace v2 moving into a new role?</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2009/05/20/cardspace-v2-moving-into-a-new-role.aspx#68346</link><pubDate>Sun, 28 Jun 2009 13:13:54 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:68346</guid><dc:creator>Matthew</dc:creator><description>&lt;p&gt;Very interesting. I have been &amp;nbsp;wondering where this was going for a while. Where is the new &amp;#39;client&amp;#39; to be found? &amp;nbsp;Windows 7 sport the same selector as far as I can see&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=68346" width="1" height="1"&gt;</description></item><item><title>re: Is the Identity Metasystem user centric or not?</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2009/05/07/is-the-identity-metasystem-user-centric-or-not.aspx#63034</link><pubDate>Wed, 20 May 2009 14:17:45 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:63034</guid><dc:creator>Mike Pettit</dc:creator><description>&lt;p&gt;My assumption about the user-at-the-center bit that KC&amp;#39;s original post talked about requiring the user to be aware of what identities (and attributes) were being exposed to what relying parties and applications. &amp;nbsp;On the Internet, only application specific identity services (Live services themselves, Facebook, LinkedIn, etc) provide granular, user-decided sharing choices. &amp;nbsp;Even then, those are subject to the whim of changing corporate use policies over time. &amp;nbsp;3rd party identity systems are just too new in practice to provide for this in a way that application vendors are willing or able to incorporate into their technology and use policies.&lt;/p&gt;
&lt;p&gt;So, going back to KC and CardSpace, a user might be expected to create multiple Windows Live ID&amp;#39;s, one for each &amp;#39;persona&amp;#39; the user might express on the Internet. &amp;nbsp;The same could be said of creating multiple identities on each social networking site. &amp;nbsp;Whether the browser-based login state mechanisms will get to the point of allowing different logins per-tab using the same identity provider or same application is another matter.&lt;/p&gt;
&lt;p&gt;I have a feeling that just as any secure communications protocol beyond 1-way SSL has proven too complex for almost all Internet transactions, any use of &amp;#39;claims&amp;#39; beyond login ID will take a long time to conceptually and practically take hold. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Today, the only interoperable, widely deployed option available to the user is PKI certificates. &amp;nbsp;I simply acquire certificates representing my various &amp;#39;personas&amp;#39;, and each certificate carries only the attributes I&amp;#39;m willing to share under that persona. &amp;nbsp;If I purchase them from a big enough vendor, they are even recognized by most potential services out there. &amp;nbsp;Unfortunately, since PKI deployment/use on the Windows platform is only understood by a relative few, and securely getting my certificates sync&amp;#39;ed across my various devices is even less understood, nearly all application vendors looking to scale shy away from using client-certificate based identity solutions.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=63034" width="1" height="1"&gt;</description></item><item><title>Are complex federation scenarios driving us away from user-centric identity?</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2009/05/07/is-the-identity-metasystem-user-centric-or-not.aspx#62751</link><pubDate>Tue, 19 May 2009 15:00:36 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:62751</guid><dc:creator>Security Briefs</dc:creator><description>&lt;p&gt;As I pointed out in my last post , in corporate federation scenarios, we don’t need to put the user at&lt;/p&gt;
&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=62751" width="1" height="1"&gt;</description></item><item><title>Addressing data recovery in detail</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2009/02/26/excellent-paper-on-password-recovery.aspx#62351</link><pubDate>Mon, 11 May 2009 13:07:07 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:62351</guid><dc:creator>Addressing data recovery in detail</dc:creator><description>&lt;p&gt;Data recovery means you still have a chance to reclaim a lost or damaged file. Most data recovery products are easy to use and inexpensive. A data recovery agent can be contacted for in-lab service.&lt;/p&gt;
&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=62351" width="1" height="1"&gt;</description></item><item><title>re: Is the Identity Metasystem user centric or not?</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2009/05/07/is-the-identity-metasystem-user-centric-or-not.aspx#62212</link><pubDate>Fri, 08 May 2009 06:09:00 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:62212</guid><dc:creator>dominick</dc:creator><description>&lt;p&gt;Well - when you look here:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://docs.oasis-open.org/imi/identity/v1.0/identity.html"&gt;docs.oasis-open.org/.../identity.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The laws are not mentioned.&lt;/p&gt;
&lt;p&gt;In my eyes the IMS is a guideline how to use existing technologies like WS-Trust and SAML to create interoperable environments (and btw WS-Fed is not part of that guideline).&lt;/p&gt;
&lt;p&gt;The laws are something to keep in mind when implementing your&amp;quot; version&amp;quot; of your identity management system.&lt;/p&gt;
&lt;p&gt;dom&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=62212" width="1" height="1"&gt;</description></item><item><title>Lost data file recovery</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2009/02/26/excellent-paper-on-password-recovery.aspx#62100</link><pubDate>Wed, 06 May 2009 11:03:14 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:62100</guid><dc:creator>Lost data file recovery</dc:creator><description>&lt;p&gt;If you don&amp;#39;t know file recovery is divided into categories: deleted lost and damaged. Understand which one you face is the first step. Deciding which one to use is next. I&amp;#39;ll show the different file recovery choices and method in recovering data.&lt;/p&gt;
&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=62100" width="1" height="1"&gt;</description></item><item><title>File hard drive recovery software</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2009/02/26/excellent-paper-on-password-recovery.aspx#62084</link><pubDate>Tue, 05 May 2009 13:28:00 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:62084</guid><dc:creator>File hard drive recovery software</dc:creator><description>&lt;p&gt;It&amp;#39;s often difficult to differentiate the capabilities of hard drive recovery specialists. Ask them to show you in their contract that they will not ship it to another company. That will delete ninety-five percent of all companies. Another quick test&lt;/p&gt;
&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=62084" width="1" height="1"&gt;</description></item><item><title>Hard disk recovery information</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2009/02/26/excellent-paper-on-password-recovery.aspx#62060</link><pubDate>Sat, 02 May 2009 22:09:26 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:62060</guid><dc:creator>Hard disk recovery information</dc:creator><description>&lt;p&gt;Computer investigations and disk recovery is all that professional do. If you&amp;#39;re looking for a reliable solution to get data salvaged then look for a company that does just those disciplines. They will also offer disk recovery software. Just this information&lt;/p&gt;
&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=62060" width="1" height="1"&gt;</description></item><item><title>Data recovery service of a hard drive</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2009/02/26/excellent-paper-on-password-recovery.aspx#61637</link><pubDate>Sat, 25 Apr 2009 20:06:22 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:61637</guid><dc:creator>Data recovery service of a hard drive</dc:creator><description>&lt;p&gt;Who will you be hiring for your data recovery service? It&amp;#39;s either the tech shop in the area or specialist. What&amp;#39;s the difference? Well the data recovery service company specializes in just getting people files recovered and putting cyber-criminals in&lt;/p&gt;
&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=61637" width="1" height="1"&gt;</description></item><item><title>Data recovery software tools</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2009/02/26/excellent-paper-on-password-recovery.aspx#61626</link><pubDate>Sat, 25 Apr 2009 19:07:31 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:61626</guid><dc:creator>Data recovery software tools</dc:creator><description>&lt;p&gt;While all the data recovery software are programmed to get files recovered there is a difference between many of them. This is a little technical but it state my point: data recovery software can reconstruct a file system that has been altered or that&lt;/p&gt;
&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=61626" width="1" height="1"&gt;</description></item><item><title>re: Create self-signed X.509 certificates in a flash with Self-Cert</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2009/01/22/create-self-signed-x-509-certificates-in-a-flash-with-self-cert.aspx#59332</link><pubDate>Mon, 06 Apr 2009 09:42:04 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:59332</guid><dc:creator>Rickard</dc:creator><description>&lt;p&gt;Thank you&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=59332" width="1" height="1"&gt;</description></item><item><title>re: Using Remote Assistance behind a router</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2008/01/14/49913.aspx#59290</link><pubDate>Fri, 03 Apr 2009 21:22:55 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:59290</guid><dc:creator>WORKASDATAENTRYATHOME</dc:creator><description>&lt;p&gt;nice tips.! it worked for me.! &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=59290" width="1" height="1"&gt;</description></item><item><title>re: Is Intellisense for XAML broken for you in VS 2008?</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2009/01/28/is-intellisense-for-xaml-broken-for-you-in-vs-2008.aspx#59284</link><pubDate>Fri, 03 Apr 2009 17:28:34 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:59284</guid><dc:creator>Silencer</dc:creator><description>&lt;p&gt;Great tip. I have the same problem. Other people suggested re-registering a dll, re-installing VS2008 :-( &amp;nbsp;&lt;/p&gt;
&lt;p&gt;But this simple trick just worked .&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=59284" width="1" height="1"&gt;</description></item><item><title>re: Welcome to the Identity and Access Management Developer Center!</title><link>http://www.pluralsight.com/community/blogs/keith/archive/2006/06/06/26869.aspx#59155</link><pubDate>Fri, 27 Mar 2009 22:10:23 GMT</pubDate><guid isPermaLink="false">d057c89c-07b5-4bfb-b52f-d79d1e3ece89:59155</guid><dc:creator>starbros</dc:creator><description>&lt;p&gt;msdn link is now broken&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=59155" width="1" height="1"&gt;</description></item></channel></rss>