<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Blog of Trust &#187; General</title>
	<atom:link href="http://blogoftrust.com/category/general/feed" rel="self" type="application/rss+xml" />
	<link>http://blogoftrust.com</link>
	<description>Watching the trusted computing world</description>
	<lastBuildDate>Thu, 17 Feb 2011 14:40:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>How to get thrown out of an NSA party</title>
		<link>http://blogoftrust.com/how-to-get-thrown-out-of-an-nsa-party/563</link>
		<comments>http://blogoftrust.com/how-to-get-thrown-out-of-an-nsa-party/563#comments</comments>
		<pubDate>Mon, 27 Sep 2010 15:55:59 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[network world]]></category>
		<category><![CDATA[nsa]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/how-to-get-thrown-out-of-an-nsa-party/563</guid>
		<description><![CDATA[There was a quite amusing article from Ellen Messmer of Network World, who attended the NSA Trusted Computing Conference and Exposition at Florida as a member of the press, and although she was only allowed to attend basically one of the three days, she managed to get a ticket to an evening party, only to [...]]]></description>
			<content:encoded><![CDATA[<p>There was <a href="http://www.networkworld.com/news/2010/091610-nsa-party.html?page=2">a quite amusing article from Ellen Messmer of Network World</a>, who attended the NSA Trusted Computing Conference and Exposition at Florida as a member of the press, and although she was only allowed to attend basically one of the three days, she managed to get a ticket to an evening party, only to get ejected soon after it got going due to the NSA employees getting uneasy, it seems, at the presence of the press.</p>
<p>It&#8217;s an interesting report and well worth a read.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/how-to-get-thrown-out-of-an-nsa-party/563/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trusted Computing Group at the NSA Trusted Computing Conference</title>
		<link>http://blogoftrust.com/trusted-computing-group-at-the-nsa-trusted-computing-conference/562</link>
		<comments>http://blogoftrust.com/trusted-computing-group-at-the-nsa-trusted-computing-conference/562#comments</comments>
		<pubDate>Mon, 27 Sep 2010 15:49:09 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[nsa]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/trusted-computing-group-at-the-nsa-trusted-computing-conference/562</guid>
		<description><![CDATA[There was a bunch of posts to the TCG official blog regarding the recent NSA Trusted Computing Conference held in Orlando, Florida. Here is a recap: In the Exhibit Area TCG In Action part 1 and part 2 Day 2 of TCG in Action Finally, a panel discussion recap I wish I could have found [...]]]></description>
			<content:encoded><![CDATA[<p>There was a bunch of posts to the TCG official blog regarding the recent NSA Trusted Computing Conference held in Orlando, Florida. Here is a recap:</p>
<ul>
<li><a href="http://www.trustedcomputinggroup.org/community/2010/09/in_the_exhibit_area_tcg_in_action_at_the_nsa_trusted_computing_conference_and_exposition_orlando_fl">In the Exhibit Area</a></li>
<li><a href="http://www.trustedcomputinggroup.org/community/2010/09/tcg_in_action_at_the_nsa_trusted_computing_conference_and_exposition_orlando_fl">TCG In Action part 1</a> and <a href="http://www.trustedcomputinggroup.org/community/2010/09/tcg_in_action_at_the_nsa_trusted_computing_conference_and_exposition_orlando_fl_continued">part 2</a></li>
<li><a href="http://www.trustedcomputinggroup.org/community/2010/09/day_2_tcg_in_action_at_the_nsa_trusted_computing_conference_and_exposition_orlando_fl">Day 2 of TCG in Action</a></li>
<li>Finally, a <a href="http://www.trustedcomputinggroup.org/community/2010/09/panel_recaps_nsa_trusted_computing_conference">panel discussion recap</a></li>
</ul>
<p>I wish I could have found a good excuse to get to go there!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/trusted-computing-group-at-the-nsa-trusted-computing-conference/562/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Intertrust announces a security SDK</title>
		<link>http://blogoftrust.com/intertrust-announces-a-security-sdk/560</link>
		<comments>http://blogoftrust.com/intertrust-announces-a-security-sdk/560#comments</comments>
		<pubDate>Wed, 15 Sep 2010 15:48:59 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[actvila]]></category>
		<category><![CDATA[drm]]></category>
		<category><![CDATA[intertrust]]></category>
		<category><![CDATA[marlin]]></category>
		<category><![CDATA[sockeye]]></category>
		<category><![CDATA[stmicroelectronics]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/intertrust-announces-a-security-sdk/560</guid>
		<description><![CDATA[Here&#8217;s an interesting press release announcement from Intertrust entitled Intertrust Introduces New Technology for Protecting Secrets, which describes an implementation of their Sushi Marlin client SDK. STMicroelectronics are supplying the hardware side of secure decoder chips, to realise the following: Marlin protects both operator and content provider content during delivery and this protection is ensured [...]]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s an interesting press release announcement from Intertrust entitled <a href="http://www.businesswire.com/news/home/20100913005720/en">Intertrust Introduces New Technology for Protecting Secrets</a>, which describes an implementation of their Sushi Marlin client SDK. STMicroelectronics are supplying the hardware side of secure decoder chips, to realise the following:</p>
<blockquote><p>Marlin protects both operator and content provider content during delivery and this protection is ensured within the end consumer product through the combination of the Sockeye Hardened Cryptography solution and the secure, powerful and flexible multi-core architecture of the STi7105.</p>
</blockquote>
<p><a href="http://www.marlin-community.com/">Marlin</a> seems rather popular in the broadcast world, and is the DRM behind, for instance, the <a href="http://whatjapanthinks.com/tag/actvila/">acTVila</a> system for streaming and download of video over the internet and direct to televisions in Japan.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/intertrust-announces-a-security-sdk/560/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Should Intel have bought Wave instead?</title>
		<link>http://blogoftrust.com/should-intel-have-bought-wave-instead/558</link>
		<comments>http://blogoftrust.com/should-intel-have-bought-wave-instead/558#comments</comments>
		<pubDate>Tue, 31 Aug 2010 16:42:14 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[intel]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[wave]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/should-intel-have-bought-wave-instead/558</guid>
		<description><![CDATA[David Lacey&#8217;s IT Security Blog examined the Intel buy-out of McAfee in detail, but he doesn&#8217;t see the sense in it. He paraphrases Intel&#8217;s statements on the buy-out with this: In fact the real motivation behind the deal is an initiative to embed more security in hardware. Intel confidently believes that McAfee&#8217;s security technology will [...]]]></description>
			<content:encoded><![CDATA[<p>David Lacey&#8217;s IT Security Blog <a title="Hardware security hits the road" href="http://www.computerweekly.com/blogs/david_lacey/2010/08/hardware_security_hits_the_roa.html">examined the Intel buy-out of McAfee</a> in detail, but he doesn&#8217;t see the sense in it. He paraphrases Intel&#8217;s statements on the buy-out with this:</p>
<blockquote><p>In fact the real motivation behind the deal is an initiative to embed more security in hardware. Intel confidently believes that McAfee&#8217;s security technology will help create &quot;hardware-enhanced security.&quot;</p>
</blockquote>
<p>Given that Intel already have <a title="Still Can’t Win the Core Wars: A Report from Black Hat" href="http://srmsblog.burtongroup.com/host_security/">their TXT technology and implement DRTM</a>, I cannot see this one myself. However, thinking a bit more, Intel are trying to get into the mobile and embedded world, and there not just a hardware root of trust is needed, but also runtime protection – I wonder if that&#8217;s what Intel see, McAfee providing software and firmware to make jailbreaking difficult or impossible?</p>
<p>Finally, David Lacey makes this suggestion:</p>
<blockquote><p>So hardware security is certainly coming our way, though it might not take the form initially suggested by an Intel/McAfee merger. In fact, a smarter and cheaper option for a chip manufacturer might be to buy Wave Systems, a security vendor specializing in hardware based trusted computing solutions.</p>
</blockquote>
<p>I&#8217;d describe Wave as &quot;<em>specialising in software for managing hardware-based trusted computing</em>&quot;, but it&#8217;s a good point that Wave Systems would make a sensible investment for a chip manufacturer.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/should-intel-have-bought-wave-instead/558/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Trusted Computing even more dangerous than Cameron Diaz!</title>
		<link>http://blogoftrust.com/trusted-computing-even-more-dangerous-than-cameron-diaz/557</link>
		<comments>http://blogoftrust.com/trusted-computing-even-more-dangerous-than-cameron-diaz/557#comments</comments>
		<pubDate>Tue, 31 Aug 2010 16:28:47 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[cameron diaz]]></category>
		<category><![CDATA[intel]]></category>
		<category><![CDATA[mcafee]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/trusted-computing-even-more-dangerous-than-cameron-diaz/557</guid>
		<description><![CDATA[Kevin Townsend had a bit of a rant on his blog about McAfee being bought by Intel, a matter which has been covered both here and elsewhere, but I did enjoy the tie in with Cameron Diaz, so it was too good a headline to miss out on. He makes this point: Trusted computing is [...]]]></description>
			<content:encoded><![CDATA[<p>Kevin Townsend had a bit of a rant on his blog about <a title="Cameron Diaz is the most dangerous thing on the Internet; apart from Intel buying McAfee…" href="http://kevtownsend.wordpress.com/2010/08/19/cameron-diaz-is-the-most-dangerous-thing-on-the-internet-apart-from-intel-buying-mcafee/">McAfee being bought by Intel</a>, a matter which has been covered both here and elsewhere, but I did enjoy the tie in with Cameron Diaz, so it was too good a headline to miss out on.</p>
<p>He makes this point:</p>
<blockquote><p>Trusted computing is a seductive idea. You protect the hardware so that nothing bad can run on it. But think about this. If you stop bad things, you have to allow good things. Problem is, it’s not you (the user) but them (the trusted computing supplier) that defines what is good and what is bad.</p>
</blockquote>
<p>That is almost correct, covering an area I&#8217;ve been looking at recently about who trusts who, and what does trust in fact mean, but it is also rather wrong in that it is (usually) the TPM Owner that defines what is good or bad; in a typical home situation the owner will be you the user, although in a corporate environment it is probably the IT department, but since the company owns your hardware that&#8217;s to be expected.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/trusted-computing-even-more-dangerous-than-cameron-diaz/557/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Intel buying McAfee</title>
		<link>http://blogoftrust.com/intel-buying-mcafee/556</link>
		<comments>http://blogoftrust.com/intel-buying-mcafee/556#comments</comments>
		<pubDate>Tue, 24 Aug 2010 16:16:20 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[intel]]></category>
		<category><![CDATA[mcafee]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/intel-buying-mcafee/556</guid>
		<description><![CDATA[The big news in the Trusted Computing and security world last week was Intel buying McAfee for 7.68 billion dollars. Both companies are members of the Trusted Computing Group, with Intel being a promoter, and from the press release, one of the claimed benefits to Intel of the acquisition is this: Acquisition enables a combination [...]]]></description>
			<content:encoded><![CDATA[<p>The big news in the Trusted Computing and security world last week was <a href="http://www.businesswire.com/portal/site/home/permalink/?ndmViewId=news_view&amp;newsId=20100819005699&amp;newsLang=en">Intel buying McAfee for 7.68 billion dollars</a>. Both companies are <a href="http://www.trustedcomputinggroup.org/about_tcg/tcg_members">members of the Trusted Computing Group</a>, with Intel being a promoter, and from the press release, one of the claimed benefits to Intel of the acquisition is this:</p>
<blockquote><p>Acquisition enables a combination of security software and hardware from one company to ultimately better protect consumers, corporations and governments as billions of devices &#8211; and the server and cloud networks that manage them &#8211; go online.</p>
</blockquote>
<p>Cloud security is getting more and more important these days, so it will be interesting to see what the merger can bring to the Trusted Computing world.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/intel-buying-mcafee/556/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Symbio&#8217;s Trusted Endpoint on a stick</title>
		<link>http://blogoftrust.com/symbios-trusted-endpoint-on-a-stick/554</link>
		<comments>http://blogoftrust.com/symbios-trusted-endpoint-on-a-stick/554#comments</comments>
		<pubDate>Fri, 20 Aug 2010 15:07:00 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[symbio]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/symbios-trusted-endpoint-on-a-stick/554</guid>
		<description><![CDATA[I&#8217;m sure I&#8217;ve mentioned this company before, but I can&#8217;t find the story again! Regardless, it&#8217;s an interesting development that deserves not just a first but also a second mention. Symbio Technologies have released a new version of their Symbiont Boot Stick, a USB memory stick containing a protected trusted environment that can access a [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m sure I&#8217;ve mentioned this company before, but I can&#8217;t find the story again! Regardless, it&#8217;s an interesting development that deserves not just a first but also a second mention. Symbio Technologies have released a <a title="Symbio Technologies Readies Next Generation Symbiont Boot Stick" href="http://www.clickpress.com/releases/Detailed/257350005cp.shtml">new version of their Symbiont Boot Stick</a>, a USB memory stick containing a protected trusted environment that can access a remote desktop, for instance, creating a secure thin client endpoint that can log into a corporate network without ever touching the RAM or hard disk on the client, thus once the session is finished, no trace of the data access is left for hackers to attack.</p>
<p>I&#8217;d love one of them for my corporate network so when I go on business trips I don&#8217;t need to carry two notebook computers, instead I can just plug the memory stick into my personal netbook.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/symbios-trusted-endpoint-on-a-stick/554/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HP Labs looking for a security researcher</title>
		<link>http://blogoftrust.com/hp-labs-looking-for-a-security-researcher/534</link>
		<comments>http://blogoftrust.com/hp-labs-looking-for-a-security-researcher/534#comments</comments>
		<pubDate>Tue, 08 Jun 2010 15:47:01 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[hp]]></category>
		<category><![CDATA[job]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/hp-labs-looking-for-a-security-researcher/534</guid>
		<description><![CDATA[I see a posting from Marco Casassa Mont, an HP employee, on a vacancy at HP Labs Bristol (or Princeton). The desirable qualifications are: A PhD in a discipline relevant to information security. Experience of security management in large organisations. Deep knowledge of at least one area of significance to security management, e.g. network security, [...]]]></description>
			<content:encoded><![CDATA[<p>I see a posting from Marco Casassa Mont, an HP employee, on <a href="http://www.communities.hp.com/online/blogs/mcm/archive/2010/06/08/141593.aspx">a vacancy at HP Labs Bristol (or Princeton)</a>. The desirable qualifications are:</p>
<ul>
<li>A PhD in a discipline relevant to information security.</li>
<li>Experience of security management in large organisations.</li>
<li>Deep knowledge of at least one area of significance to security management, e.g. network security, economics of security, systems architecture, trusted computing, operating system security, security policy, privacy, security of distributed systems, security modelling, information security, threats.</li>
<li>Strong communication skills.</li>
</ul>
<p>I know a couple of the guys at HP Bristol and I&#8217;ve read papers by a few others of them, so I think it would be a pretty awesome place to work; if I was in the UK I&#8217;d be sorely tempted to apply.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/hp-labs-looking-for-a-security-researcher/534/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Intertrust partners with China broadcaster for DRM</title>
		<link>http://blogoftrust.com/intertrust-partners-with-china-broadcaster-for-drm/532</link>
		<comments>http://blogoftrust.com/intertrust-partners-with-china-broadcaster-for-drm/532#comments</comments>
		<pubDate>Mon, 07 Jun 2010 14:36:34 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[cctv]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[drm]]></category>
		<category><![CDATA[intertrust]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/intertrust-partners-with-china-broadcaster-for-drm/532</guid>
		<description><![CDATA[This recent press release is not directly TPM-related (although who knows what the future holds), but Intertrust is always a company I&#8217;m interested in. They have teamed up with the all too appropriately-initialled CCTV to develop a DRM protection system for high-definition video. The China DRM (Digital Rights Management) Forum is also in on the [...]]]></description>
			<content:encoded><![CDATA[<p>This recent press release is not directly TPM-related (although who knows what the future holds), but Intertrust is always a company I&#8217;m interested in. They have teamed up with the all too appropriately-initialled CCTV to <a href="http://www.pr-inside.com/cctv-high-tech-development-company-and-r1926672.htm">develop a DRM protection system for high-definition video</a>. The China DRM (Digital Rights Management) Forum is also in on the deal, as the standards body for the DRM to be used. This is not a China-only standard; a number of multinationals are involved too, as it says in the final paragraph:</p>
<blockquote><p>Currently there are 78 participants in China DRM Forum, including major Chinese content providers such as CCTV, SMG, and BTV, as well as leading technology companies such as TCL, Changhong, Panasonic, Philips, Sony, Nokia, and Intel.</p>
</blockquote>
<p>I&#8217;ll have to check this out further&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/intertrust-partners-with-china-broadcaster-for-drm/532/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>State of the art in Secure Operating Systems</title>
		<link>http://blogoftrust.com/state-of-the-art-in-secure-operating-systems/526</link>
		<comments>http://blogoftrust.com/state-of-the-art-in-secure-operating-systems/526#comments</comments>
		<pubDate>Tue, 11 May 2010 14:44:46 +0000</pubDate>
		<dc:creator>Ken Y-N</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[defensetech]]></category>
		<category><![CDATA[sel4]]></category>

		<guid isPermaLink="false">http://blogoftrust.com/state-of-the-art-in-secure-operating-systems/526</guid>
		<description><![CDATA[The website DefenseTech had an article summarising the latest attempts to build a Secure (and by implication Trusted) Operating System. China, Australia, the European Union and the USA&#8217;s best are described in outline; to me the one of most interest is selL4, Secure L4, as it is a real product and is closely related to [...]]]></description>
			<content:encoded><![CDATA[<p>The website DefenseTech had an article summarising the <a title="The Race to Build a Secure Operating System" href="http://defensetech.org/2010/05/11/the-race-to-build-a-secure-operating-system/">latest attempts to build a Secure (and by implication Trusted) Operating System</a>. China, Australia, the European Union and the USA&#8217;s best are described in outline; to me the one of most interest is <a href="http://blogoftrust.com/open-kernel-labs-kernel-proved-correct/465">selL4, Secure L4</a>, as it is a real product and is closely related to the OKL4 kernel that appears in such places as all Android phones.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogoftrust.com/state-of-the-art-in-secure-operating-systems/526/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

