<?xml version='1.0' encoding='utf-8' ?>
<!--  If you are running a bot please visit this policy page outlining rules you must respect. http://www.livejournal.com/bots/  -->
<rss version='2.0' xmlns:lj='http://www.livejournal.org/rss/lj/1.0/' xmlns:media='http://search.yahoo.com/mrss/' xmlns:atom10='http://www.w3.org/2005/Atom'>
<channel>
  <title>Vitty</title>
  <link>http://tant.livejournal.com/</link>
  <description>Vitty - LiveJournal.com</description>
  <lastBuildDate>Sat, 26 Dec 2009 00:16:54 GMT</lastBuildDate>
  <generator>LiveJournal / LiveJournal.com</generator>
  <lj:journal>tant</lj:journal>
  <lj:journalid>1544490</lj:journalid>
  <lj:journaltype>personal</lj:journaltype>
  <atom10:link rel='hub' href='http://pubsubhubbub.appspot.com/' />
  <image>
    <url>http://l-userpic.livejournal.com/95813137/1544490</url>
    <title>Vitty</title>
    <link>http://tant.livejournal.com/</link>
    <width>100</width>
    <height>99</height>
  </image>

<item>
  <guid isPermaLink='true'>http://tant.livejournal.com/38093.html</guid>
  <pubDate>Sat, 26 Dec 2009 00:16:54 GMT</pubDate>
  <title>Sometimes mediocre encryption is better than strong encryption and sometimes no encryption is better</title>
  <link>http://tant.livejournal.com/38093.html</link>
  <description>Совершенно неожиданную для меня позицию &lt;a href=&quot;http://www.schneier.com/blog/archives/2009/12/intercepting_pr.html&quot;&gt; занял &lt;/a&gt; Брюс Шнайер в &lt;a href=&quot;http://online.wsj.com/article/SB126102247889095011.html&quot;&gt; нашумевшей &lt;/a&gt; истории. Нет, я даже во многом с ним согласен. Но от Шнайера... не ожидал. Видимо, надо прочесть &lt;a href=&quot;http://www.schneier.com/book-sandl.html&quot;&gt; вторую &lt;/a&gt; книгу.</description>
  <comments>http://tant.livejournal.com/38093.html</comments>
  <lj:security>public</lj:security>
  <lj:reply-count>1</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://tant.livejournal.com/37707.html</guid>
  <pubDate>Fri, 18 Dec 2009 14:48:28 GMT</pubDate>
  <title>Сегодняшнее</title>
  <link>http://tant.livejournal.com/37707.html</link>
  <description>&lt;a href=&quot;http://picasaweb.google.com/lh/photo/03tC51j-yHRyM1Ld7qZwTw?feat=embedwebsite&quot;&gt;&lt;img src=&quot;http://lh5.ggpht.com/_6Eeon9biidk/SyuV8M1RIxI/AAAAAAAAD94/MpblHCaCIfo/s288/18122009150.jpg&quot; /&gt;&lt;/a&gt;</description>
  <comments>http://tant.livejournal.com/37707.html</comments>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://tant.livejournal.com/37437.html</guid>
  <pubDate>Sat, 12 Dec 2009 22:46:32 GMT</pubDate>
  <title>К вопросу о security</title>
  <link>http://tant.livejournal.com/37437.html</link>
  <description>(via &lt;span class=&apos;ljuser ljuser-name_avva&apos; lj:user=&apos;avva&apos; style=&apos;white-space: nowrap;&apos;&gt;&lt;a href=&apos;http://avva.livejournal.com/profile&apos;&gt;&lt;img src=&apos;http://l-stat.livejournal.com/img/userinfo.gif&apos; alt=&apos;[info]&apos; width=&apos;17&apos; height=&apos;17&apos; style=&apos;vertical-align: bottom; border: 0; padding-right: 1px;&apos; /&gt;&lt;/a&gt;&lt;a href=&apos;http://avva.livejournal.com/&apos;&gt;&lt;b&gt;avva&lt;/b&gt;&lt;/a&gt;&lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;Cormac Herley, Microsoft Research:&lt;br /&gt;&lt;br /&gt;It is often suggested that users are hopelessly lazy and unmotivated on security questions. They chose weak&lt;br /&gt;passwords, ignore security warnings, and are oblivious to certificates errors. We argue that users’ rejection&lt;br /&gt;of the security advice they receive is entirely rational from an economic perspective. The advice offers to&lt;br /&gt;shield them from the direct costs of attacks, but burdens them with far greater indirect costs in the form of effort.&lt;br /&gt;Looking at various examples of security advice we find that the advice is complex and growing, but the benefit&lt;br /&gt;is largely speculative or moot. For example, much of the advice concerning passwords is outdated and does little&lt;br /&gt;to address actual treats, and fully 100% of certificate error warnings appear to be false positives. Further, if&lt;br /&gt;users spent even a minute a day reading URLs to avoid phishing, the cost (in terms of user time) would be two&lt;br /&gt;orders of magnitude greater than all phishing losses. Thus we find that most security advice simply offers a&lt;br /&gt;poor cost-benefit tradeoff to users and is rejected. Security advice is a daily burden, applied to the whole&lt;br /&gt;population, while an upper bound on the benefit is the harm suffered by the fraction that become victims an-&lt;br /&gt;nually. When that fraction is small, designing security advice that is beneficial is very hard. For example, it&lt;br /&gt;makes little sense to burden all users with a daily task to spare 0.01% of them a modest annual pain.&lt;br /&gt;&lt;br /&gt;(&lt;a href=&quot;http://research.microsoft.com/en-us/um/people/cormac/papers/2009/solongandnothanks.pdf&quot;&gt; статья целиком &lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;Вообще, скорее соглашусь.</description>
  <comments>http://tant.livejournal.com/37437.html</comments>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://tant.livejournal.com/37240.html</guid>
  <pubDate>Tue, 08 Dec 2009 23:57:14 GMT</pubDate>
  <title>Школьный проект</title>
  <link>http://tant.livejournal.com/37240.html</link>
  <description>Хотел было удалить пост про &lt;a href=&quot;http://tant.livejournal.com/36599.html&quot;&gt;школьный проект&lt;/a&gt;, но передумал. Пусть висит для истории, мы хорошо тогда поработали.</description>
  <comments>http://tant.livejournal.com/37240.html</comments>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://tant.livejournal.com/36599.html</guid>
  <pubDate>Mon, 20 Oct 2008 20:56:21 GMT</pubDate>
  <title>Запоздало-рабочее</title>
  <link>http://tant.livejournal.com/36599.html</link>
  <description>&lt;div&gt;&lt;p&gt;&lt;a href=&quot;http://freeschool.altlinux.ru/?p=573&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://freeschool.altlinux.ru/maps/map_big.png&quot; border=&quot;1&quot; alt=&quot;Карта внедрения СПО в школы РФ&quot;&gt;&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</description>
  <comments>http://tant.livejournal.com/36599.html</comments>
  <lj:security>public</lj:security>
  <lj:reply-count>2</lj:reply-count>
</item>
</channel>
</rss>
