<?xml version="1.0" encoding="UTF-8"?><!-- generator="WordPress/2.5" -->
<rss version="0.92">
<channel>
	<title>Useful Security</title>
	<link>http://www.usefulsecurity.com</link>
	<description>Solving real security problems that matter to real users</description>
	<lastBuildDate>Fri, 09 Nov 2007 01:16:17 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Apple Sandboxes Part 2</title>
		<description>Here are a couple of examples of using sandboxes in Leopard. Both examples involve confining a test application that needs to read a file, but should not be able to write that file. I realize that this could be easily implemented with standard Discretionary Access Control (DAC) mechanisms, but this ...</description>
		<link>http://www.usefulsecurity.com/2007/11/apple-sandboxes-part-2/</link>
			</item>
	<item>
		<title>Apple Sandboxes Part 1</title>
		<description>Linux isn't the only operating system with activity in the enhanced access control department. Apple recently released Mac OS X 10.5 Leopard, which includes a new feature called a sandbox (or seatbelt, depending on where you're looking) as well. I delved into the sandbox mechanisms a bit and wanted to ...</description>
		<link>http://www.usefulsecurity.com/2007/11/apple-sandboxes-part-1/</link>
			</item>
	<item>
		<title>Montavista Vision 2007</title>
		<description>I had the distinct opportunity to speak at the Montavista Vision conference about SELinux in embedded devices. I'd like to say thanks to all who attended my talk. A copy of the slides is available here. Thanks for all the questions. I hope I answered them to your satisfaction.

Some of ...</description>
		<link>http://www.usefulsecurity.com/2007/10/montavista-vision-2007/</link>
			</item>
	<item>
		<title>LinuxWorld 07</title>
		<description>I'd like to say thanks to all who attended my talk at LinuxWorld. A copy of the slides is available here. I hope you enjoyed it and got a lot out of it. I just posted the second demo in full here, and I'll try to get the last one ...</description>
		<link>http://www.usefulsecurity.com/2007/08/linuxworld-07/</link>
			</item>
	<item>
		<title>Preventing Disclosure</title>
		<description>Problem
While it is always preferable to keep confidential information such as customer records away from a website, that is often not feasible. This is especially true in ecommerce, but is true in other areas as well. In order to protect this information, most people will employ some sort of authentication ...</description>
		<link>http://www.usefulsecurity.com/2007/08/preventing-disclosure/</link>
			</item>
	<item>
		<title>Vulnerable web applications</title>
		<description>Problem
Web applications can be a source of very frequent vulnerabilities. These vulnerabilities can stem from bugs in the program itself as well as the libraries and frameworks upon which it depends. These vulnerabilities are often used as the entry-point for an attacker to upload malicious software onto a system. This ...</description>
		<link>http://www.usefulsecurity.com/2007/08/vulnerable-web-applications/</link>
			</item>
	<item>
		<title>Useful Security</title>
		<description>Welcome to usefulsecurity.com. This blog is dedicated to providing tips, pointers, howtos, and other information on solving real security problems. Too often today security professionals come up with "solutions" that don't really help users solve their security problems. This stems from many reasons, including not understanding the problem correctly, not ...</description>
		<link>http://www.usefulsecurity.com/2007/08/useful-security/</link>
			</item>
</channel>
</rss>
