<?xml version="1.0"?>
<!-- RSS generated by Radio UserLand v8.0.7 on Tue, 16 Apr 2002 17:52:40 GMT -->
<rss version="0.92">
	<channel>
		<title>Financial Applications Security Weblog</title>
		<link>http://radio.weblogs.com/0103213/</link>
		<description>Secure Applications for Open Markets</description>
		<copyright>Copyright 2002 Pelle Braendgaard</copyright>
		<lastBuildDate>Tue, 16 Apr 2002 17:52:40 GMT</lastBuildDate>
		<docs>http://backend.userland.com/rss092</docs>
		<managingEditor>pelle@neubia.com</managingEditor>
		<webMaster>pelle@neubia.com</webMaster>
		<item>
			<description>&lt;H4&gt;&lt;A href=&quot;http://www.computerworld.com/itresources/rcstory/0,4167,STO70112_KEY73,00.html&quot;&gt;Experts: Insider threat may be harder to detect&lt;/A&gt;&lt;/H4&gt;
&lt;P&gt;This article from &lt;A href=&quot;http://www.computerworld.com&quot;&gt;Computer World&lt;/A&gt;&amp;nbsp;is quite interesting, if initially slightly confusing. The headline seems to mirror the content but it sems to be challenged by the summary:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&lt;EM&gt;Recent findings that insiders constitute the primary threat to enterprise security are being challenged by experts who insist the greater threat to security remains external.&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The article&amp;nbsp;cites the &lt;A href=&quot;http://radio.weblogs.com/0103213/2002/04/10.html#a34&quot;&gt;CSI study&lt;/A&gt;&amp;nbsp;and quotes&amp;nbsp;NASA and US Dept. of Labour CIO&apos;s as saying that their main threats are external. However as a few security experts later in the article state the problem is probably that the internal threat isn&apos;t detected.&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&lt;EM&gt;&quot;I don&apos;t believe that many corporations know that the majority of attacks occur behind the firewall,&quot; said Mike Hager, vice president of network security and disaster recovery at OppenheimerFunds Distributor Inc. in New York. &quot;And most still believe the firewall will stop them.&quot; &lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I think this rings particularly true with Financial companies. There might not be many such incidents yet, but when they happen they happen big and hurt alot more than an external attack through the firewall.&lt;/P&gt;
&lt;P&gt;In addition I think we will start seeing much smarter hacker groups around, who will build up much greater inside knowledge of financial institutions. Just look at the hackgroups of the 80&apos;s who often had greater knowledge of the phone companies internal computer systems, than most people within.&lt;/P&gt;</description>
			<category>Investment Banking Technology</category>
			</item>
		<item>
			<description>&lt;H4 class=headerxlarge&gt;&lt;A href=&quot;http://www.eweek.com/article/0,3658,s=1884&amp;amp;a=25494,00.asp&quot;&gt;Contracts Getting Tough on Security&lt;/A&gt;&lt;/H4&gt;&lt;!-- BEGIN BODY OF ARTICLE --&gt;
&lt;TABLE cellSpacing=0 cellPadding=1 width=&quot;100%&quot; border=0&gt;
&lt;TBODY&gt;
&lt;TR vAlign=top&gt;
&lt;TD class=BodyCopyMedium align=left&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&lt;EM&gt;Enterprise IT managers and CIOs, growing impatient with security vulnerabilities, are fighting back with language in contracts that holds software companies liable for breaches and attacks that exploit their products.&amp;nbsp; ...&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&lt;EM&gt;... For example, a Fortune 50 company recently wrote a clause into a contract with a major software company that holds the vendor responsible for any security breach connected to its software, according to sources familiar with the deal. [&lt;A href=&quot;http://www.eweek.com&quot;&gt;eWeek&lt;/A&gt;]&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This is definitely a trend we will see continue. Not just for commercial software but also in internal and external agreements for software development or service providing.&lt;/P&gt;
&lt;P&gt;For service providers, I would imagine that this would&amp;nbsp; become addendums as part of their existing Quality of Service agreements. Some of these current agreements might already be good enough as they are to cover such events. But ofcourse as the service providers get hit by more and more of these issues, they will naturally want to pass the buck onto the software providers.&lt;/P&gt;</description>
			<category>Investment Banking Technology</category>
			</item>
		<item>
			<description>&lt;H4&gt;&lt;A href=&quot;http://www.nytimes.com/2002/04/11/technology/11NET.html&quot;&gt;MS to drop Hailstorm&lt;/A&gt;&lt;/H4&gt;
&lt;P&gt;Microsoft is slowly killing of Hailstorm according to an article by John Markoff of the New York Times. He claims that MS has been slowly devesting their My Services (formerly Hailstorm) Consumer Web Services platform over the past few months, with a goal of eventually releasing &quot;My Services&quot; as a package for Corporates to use.&lt;/P&gt;
&lt;P&gt;I don&apos;t know how this will affect Passport yet, but I can&apos;t imagine them halting that service for the time being, regardless of its problems. I wonder if the &lt;A href=&quot;http://radio.weblogs.com/0103213/2002/03/20.html#a5&quot;&gt;Citibank announcement&lt;/A&gt; last month will be affected by it as they were to be the prefered financial services provider for My Services.&lt;/P&gt;</description>
			<category>Identification</category>
			<category>Retail Banking</category>
			<category>Web Services</category>
			</item>
		<item>
			<description>&lt;H4&gt;&lt;A href=&quot;http://msdn.microsoft.com/ws-security/&quot;&gt;IBM, MS and Verisign announce new Web Service Security Architecture&lt;/A&gt;&lt;/H4&gt;
&lt;P&gt;I haven&apos;t had time to read the full whitepaper yet. This Whitepaper describes their new &lt;A href=&quot;http://www-106.ibm.com/developerworks/library/ws-secure/&quot;&gt;WS-Security&lt;/A&gt; proposal.&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&lt;EM&gt;This document describes a proposed strategy for addressing security within a Web service environment. It defines a comprehensive Web service security model that supports, integrates and unifies several popular security models, mechanisms, and technologies (including both symmetric and public key technologies) in a way that enables a variety of systems to securely interoperate in a platform- and language-neutral manner. It also describes a set of specifications and scenarios that show how these specifications might be used together.&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P dir=ltr&gt;I&apos;ll have a quick read and come back with any comments.&lt;/P&gt;</description>
			<category>Identification</category>
			<category>Web Services</category>
			<category>XML</category>
			</item>
		<item>
			<description>&lt;H4&gt;&lt;A href=&quot;http://www.microsoft.com/technet/security/bulletin/ms02-018.asp&quot;&gt;New IIS Patches from Microsoft&lt;/A&gt;&lt;/H4&gt;
&lt;P&gt;Microsoft yesterday released a new set of Patches for IIS. The patch and the security holes it fixes are described &lt;A href=&quot;http://www.microsoft.com/technet/security/bulletin/ms02-018.asp&quot;&gt;here&lt;/A&gt;. While you&apos;re at it you might want to run the &lt;A href=&quot;http://www.microsoft.com/technet/security/tools/tools/locktool.asp&quot;&gt;IIS Lockdown tool&lt;/A&gt;, which checks for common (read default) insecure configurations. I do hope they make this part of the standard setup procedure in future versions.&lt;/P&gt;</description>
			<source url="http://www.securityfocus.com/topnews?type=rss">SecurityFocus</source>
			<category>Advisories</category>
			<category>Web Servers</category>
			</item>
		<item>
			<description>&lt;H4&gt;&lt;A href=&quot;http://radio.weblogs.com/0100887/2002/04/09.html#a184&quot;&gt;SOAP security and external underwear&lt;/A&gt;. &lt;/H4&gt;
&lt;P&gt;&lt;FONT face=Verdana,Geneva,Arial,Helvetica,Sans-Serif size=2&gt;Jon Udell discusses the &lt;A href=&quot;http://www.w3.org/TR/SOAP/#_Toc478383528&quot;&gt;SOAPAction header&lt;/A&gt; and its uses for filtering SOAP requests through a firewall. The concept of the header is that the client making the SOAP Request, places a SOAPAction header in the HTTP request describing what it is they are going to be doing. For example what method they will be invoking. When I first read this a few years back it did send question marks buzzing up through my head, as you cant really on an external description of what is going to happen. Jon put&apos;s it great with his analogy of External Underwear:&lt;/FONT&gt;&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&lt;FONT face=Verdana,Geneva,Arial,Helvetica,Sans-Serif size=2&gt;&lt;EM&gt;Did the notion advanced in DevelopMentor&apos;s FAQ -- that SOAP packets would declare intent by publishing interface and method names in the HTTP header -- make sense? At the time it seemed reasonable to me. But now, I wonder if a SOAPaction policy isn&apos;t rather like the scene in &lt;/EM&gt;&lt;/FONT&gt;&lt;A href=&quot;http://us.imdb.com/Title?0066808&quot;&gt;&lt;FONT face=Verdana,Geneva,Arial,Helvetica,Sans-Serif size=2&gt;&lt;EM&gt;Bananas&lt;/EM&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;EM&gt;&lt;FONT face=Verdana,Geneva,Arial,Helvetica,Sans-Serif size=2&gt; where the newly-installed dictator declares that &quot;everybody must wear their underwear on the outside, so we can check.&quot; The interfaces that a company chooses to expose to the world are, in the end, a policy that will or won&apos;t be enforced, regardless of the SOAP toolkits in use or the translations performed in a request pipeline. Enforcement will always require more than checking for underwear on the outside. &lt;/FONT&gt;[&lt;/EM&gt;&lt;A href=&quot;http://radio.weblogs.com/0100887/&quot;&gt;&lt;EM&gt;Jon&apos;s Radio&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt;]&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Those of us who were writing perl CGI apps way back in the early days of the Web learnt that you can&apos;t rely on the format of a request. You really do need to verify all data before you make any assumptions about it, so a http SOAPAction header specifying a Stock ticker lookup interface, can just as easily have a Stock trading message within.&lt;/P&gt;
&lt;P&gt;All of this discussion though assumes that you only have one single SOAP gateway/router on your web server. This strikes me as a bit naive from a security standpoint. I think that only interfaces with the EXACT same security properties should be exposed&amp;nbsp;in the same router. This way you can use the underlying web servers security as well as external firewall&apos;s to provide access control and authentication. Lets not reinvent the wheel here.&lt;/P&gt;</description>
			<source url="http://radio.weblogs.com/0100887/rss.xml">Jon&apos;s Radio</source>
			<category>Middle Tier Technlogies</category>
			<category>Web Servers</category>
			<category>Web Services</category>
			<category>XML</category>
			</item>
		<item>
			<description>&lt;H4&gt;&lt;A href=&quot;http://zdnet.com.com/2100-1107-879619.html&quot;&gt;A quick intro to Buffer Overflows Attacks&lt;/A&gt;&lt;/H4&gt;
&lt;P&gt;Robert Vamosi over at &lt;A href=&quot;http://zdnet.com&quot;&gt;ZDNet&lt;/A&gt; provides a great little not too technical introduction to buffer overflow attacks. You might use this to explain buffer overflow attacks to nontech personell etc.&lt;/P&gt;</description>
			<source url="http://www.securityfocus.com/topnews?type=rss">SecurityFocus</source>
			<category>Advisories</category>
			</item>
		<item>
			<description>&lt;H4&gt;Issues with CSI Cybercrime Survey &lt;/H4&gt;
&lt;P&gt;Jiri (?) from the brand new &lt;A href=&quot;http://radio.weblogs.com/0100367/&quot;&gt;Security Weblog&lt;/A&gt; commented on my issues with the CSI survey and pointed out two great papers by Mich Kabay about the inherent flaws in computer security studies.&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&lt;EM&gt;Agree. There is an old saying that goes something like statistics is just a sientific way of fooling people. Pelle points out that the interpretataion of CSI survey is dubious. What&apos;s more, sampling on which the survey was based is funny as well. Survey is responded to by security professionals from large organisations. This inevitably affects the results (that are then interpreted in the way outlined by Pelle). And BTW, there are two &lt;/EM&gt;&lt;A href=&quot;http://www2.norwich.edu/mkabay/methodology/crime_studies.htm&quot;&gt;&lt;EM&gt;relevant&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; &lt;/EM&gt;&lt;A href=&quot;http://www2.norwich.edu/mkabay/methodology/crime_stats_methods.htm&quot;&gt;&lt;EM&gt;papers&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; on cyber crime surveys from Mich Kabay who happens to be a security professional and at the same time holds PhD in statistics.&lt;/EM&gt;[&lt;A href=&quot;http://radio.weblogs.com/0100367/&quot;&gt;Security weblog&lt;/A&gt;]&lt;/P&gt;&lt;/BLOCKQUOTE&gt;</description>
			<source url="http://radio.weblogs.com/0100367/rss.xml">Security weblog</source>
			</item>
		<item>
			<description>&lt;H4&gt;&lt;A href=&quot;http://weblog.digital-identity.info/archives/000066.html&quot;&gt;Open for Business (Identity management &amp;amp; open networks)&lt;/A&gt;. &lt;/H4&gt;
&lt;P&gt;Nikolaj at Digital Identity mentions &lt;A href=&quot;http://www.hyperion.co.uk&quot;&gt;Consult Hyperion&lt;/A&gt;&apos;s&amp;nbsp; &lt;A href=&quot;http://www.hyperion.co.uk/PubWebFiles/openforbusiness.pdf&quot;&gt;whitepaper on identity management&lt;/A&gt;. Big points to him for also posting a link in the same article to Carl Ellison and Bruce Schneiers classic: &lt;A href=&quot;http://www.counterpane.com/pki-risks-ft.txt&quot;&gt;What You&apos;re not Being Told about Public Key Infrastructure&lt;/A&gt;. Nice one.&lt;/P&gt;[&lt;A href=&quot;http://weblog.digital-identity.info/&quot;&gt;Digital Identity&lt;/A&gt;]</description>
			<source url="http://weblog.digital-identity.info/index.xml">Digital Identity</source>
			<category>Identification</category>
			<category>Investment Banking Technology</category>
			<category>Middle Tier Technlogies</category>
			</item>
		<item>
			<description>&lt;H4&gt;&lt;A href=&quot;http://www.gocsi.com/press/20020407.html&quot;&gt;Cyber crime bleeds U.S. corporations, survey shows&lt;/A&gt;&lt;/H4&gt;
&lt;P&gt;Many sources have commented on the latest &lt;A href=&quot;http://www.gocsi.com&quot;&gt;Computer Security Institue&lt;/A&gt; (CSI) &lt;A href=&quot;http://www.gocsi.com/press/20020407.html&quot;&gt;survey&lt;/A&gt;, which was done in cooperation with the FBI. These surveys are quite interesting but I question the methodology used by the various respondents to the survey to get their answers. &lt;/P&gt;
&lt;P&gt;For example the survey counts non work related web surfing as&amp;nbsp; a Cyber Crime. It specifies that in the past year the average cost per respondent has gone from $357,160 to $536,000 a year. The survey claims the two main issues here being productivity and liability. While I can definitely see liability as being a potential issue, I&apos;m quite unsure of the methods they use to quantify their loss of productivity. Howabout the increase of productivity of employees who are happy because their employer doesn&apos;t chose to treat them like children.&lt;/P&gt;
&lt;P&gt;Another area that might raise a few eyebrows is the losses based on theft of proprietary information. The report says that respondents reported a total loss of $170,827,000 last year. Yet only 20% of respondents reported such infractions. Granted these can be serious issues, however the Tech industry has a history of overreporting the value of such crimes. Just remember the Kevin Mitnick case where companies such as Sun, Nokia etc. made &lt;A href=&quot;http://www.kevinmitnick.com/letters.html&quot;&gt;outrageous claims&lt;/A&gt; on losses caused by him.&lt;/P&gt;
&lt;P&gt;Much more serious in my view is Financial Fraud. The survey states that 12% of respondents had a loss on average&amp;nbsp; of $957,384. Most of this from what I can acertain is basically traditional credit card fraud.&amp;nbsp; However I do believe we will see a growth over the next year or two in losses based on investment banking systems. Just imagine how much money could be made if someone managed to create large false trades or spread disinformation on trade/news feeds. Not covered under Financial Fraud but equally an issue would be the cost of DOS attacks targeted at realtime trade feeds.&lt;/P&gt;</description>
			<source url="http://www.securityfocus.com/topnews?type=rss">SecurityFocus</source>
			<category>Investment Banking Technology</category>
			<category>Retail Banking</category>
			</item>
		<item>
			<description>&lt;H4&gt;Quick 5 minute intro to JCE for Developers&lt;/H4&gt;
&lt;P&gt;All enterprise java&amp;nbsp;developers should have at least a passing knowledge of JCE. If you&apos;ve never tried it before try this quick little intro to sample it: &lt;A href=&quot;http://builder.com.com/article.jhtml?id=u00220020408gcn01.htm&amp;amp;page=1&amp;amp;vf=tt&quot;&gt;Master the basics of Java Cryptography Extension (JCE)&lt;/A&gt;.&amp;nbsp; [&lt;A href=&quot;http://builder.com&quot;&gt;builder.com&lt;/A&gt;]&lt;/P&gt;</description>
			<source url="http://p.moreover.com/cgi-local/page?index_computersecurity+rss">Moreover - moreover...</source>
			<category>Middle Tier Technlogies</category>
			</item>
		<item>
			<description>&lt;H4&gt;&lt;A href=&quot;http://weblog.digital-identity.info/archives/000064.html&quot;&gt;DigitalIdWorld, an industry &apos;portal&apos;&lt;/A&gt;.&lt;/H4&gt;
&lt;P&gt;&lt;I&gt;Phil Becker has started &lt;A href=&quot;http://www.digitalidworld.com&quot;&gt;DigitalIdWorld&lt;/A&gt;, &lt;I&gt;&quot;the hub of the digital identity industry&quot;&lt;/I&gt;, in the model of &lt;A href=&quot;http://www.google.com/search?q=cache:mEBAkA9tqikC:www.ispcon.com/+ISPCON&amp;amp;hl=en&quot;&gt;ISPCON&lt;/A&gt; the independant ISP industry resource he founded in 1992.&lt;BR&gt;&lt;A href=&quot;http://www.digitalidworld.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=26&amp;amp;mode=flat&amp;amp;order=0&quot;&gt;Several&lt;/A&gt; &lt;A href=&quot;http://www.digitalidworld.com/modules.php?op=modload&amp;amp;name=News&amp;amp;file=article&amp;amp;sid=15&amp;amp;mode=flat&amp;amp;order=0&quot;&gt;interesting&lt;/A&gt; &lt;A href=&quot;http://www.digitalidworld.com/modules.php?op=modload&amp;amp;name=Search&amp;amp;file=index&amp;amp;action=search&amp;amp;overview=1&amp;amp;active_stories=1&amp;amp;stories_topics[0]=&amp;amp;stories_cat[0]=&quot;&gt;articles&lt;/A&gt; have already started appearing, and rumours are of an industry conference in the fall. Bahamas, anyone? ;)&lt;/I&gt; [&lt;A href=&quot;http://weblog.digital-identity.info/&quot;&gt;Digital Identity&lt;/A&gt;]&lt;/P&gt;</description>
			<source url="http://weblog.digital-identity.info/index.xml">Digital Identity</source>
			<category>Identification</category>
			<category>Web Services</category>
			</item>
		<item>
			<description>&lt;H4&gt;While we&apos;re on the subject of MS holes...&lt;/H4&gt;
&lt;P&gt;&lt;FONT size=2&gt;I&apos;m not going to be covering these IE holes regularly as they are already heavily published elsewhere and MS are doing a pretty good job now a days at getting them out to users. But a couple of &lt;A href=&quot;http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-015.asp&quot;&gt;new problems&lt;/A&gt; are now covered by their latest &lt;A href=&quot;http://www.microsoft.com/windows/ie/downloads/critical/Q319182/default.asp&quot;&gt;IE Cumilative Patch&lt;/A&gt;. If you are using any IE5 or up on your machine or as part of the standard windows build in your company, you probably should install the patch.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;I&apos;m not blaming MS for these holes, as I&apos;ve said they&apos;ve started to do a pretty good job. They did have some stupid ones in the past, but we can work with them now. In a complex piece of software like IE6, which consists of many different subcomponents its hard to find all of the problems up front.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;That said, these problems together with last years email panics, should help to underline why we need to protect our systems more than ever. The default approach I see many places is that companies panic and shut down net traffic all together. Thats not good for the business, the employees or the customers of the company. We are all part of the net now, and we should embrace that fact as an opportunity rather than a threat. What that does call for though is well thought out business applications and procedures.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;</description>
			<category>Advisories</category>
			</item>
		<item>
			<description>&lt;H4&gt;&lt;A href=&quot;http://online.securityfocus.com/cgi-bin/archive.pl?id=1&amp;amp;start=2002-03-29&amp;amp;end=2002-04-04&amp;amp;threads=1&amp;amp;tid=264927&quot;&gt;Local Security Vulnerability in Windows NT and Windows 2000&lt;/A&gt;&lt;/H4&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&lt;EM&gt;DebPloit uses a hole in the NT/2000 debugging subsystem and allows ANY user&lt;BR&gt;with ANY privileges (even Guest and Restricted user) to execute processes in&lt;BR&gt;the security context of an administrator or a local system (SYSTEM) account.&lt;BR&gt;In other words, any person who have an access to the local computer can&lt;BR&gt;became an administrator and do everything he/she wants. &lt;A href=&quot;http://online.securityfocus.com/archive/1&quot;&gt;[Bugtraq]&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P dir=ltr&gt;This could obviously&amp;nbsp; be an issue anywhere where NT Servers are used. I&apos;ve verified it and it appears to work. The Authors of the exploit have an &lt;A href=&quot;http://www.ntutility.com/freeware.html&quot;&gt;intermediate fix&lt;/A&gt; as well untill MS comes out with a bugfix. The source is available for the fix, so you might want to check it and compile it yourself. The risk of installing a third party fix like this might be even greater than the hole itself. You call the punches.&lt;/P&gt;
&lt;P dir=ltr&gt;&amp;nbsp;&lt;/P&gt;</description>
			<category>Advisories</category>
			</item>
		<item>
			<description>&lt;H4&gt;&lt;A href=&quot;http://www.forbes.com/home/2002/03/27/0327linux.html&quot;&gt;Wall Street Embraces Linux&lt;/A&gt; &lt;/H4&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&lt;SPAN class=mainarttxt&gt;&lt;EM&gt;Merrill &lt;B&gt;&lt;/B&gt;(nyse: &lt;/EM&gt;&lt;A class=maintkrlink href=&quot;http://www.forbes.com/finance/mktguideapps/compinfo/CompanyTearsheet.jhtml?tkr=MER&quot;&gt;&lt;EM&gt;MER&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; - &lt;/EM&gt;&lt;A href=&quot;http://www.forbes.com/markets/company_news.jhtml?ticker=MER&quot;&gt;&lt;EM&gt;news&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; - &lt;/EM&gt;&lt;A href=&quot;http://www.forbes.com/peopletracker/results.jhtml?startRow=0&amp;amp;name=&amp;amp;ticker=MER&quot;&gt;&lt;EM&gt;people&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt;) is one of many Wall Street brokerages doing a large-scale Linux deployment in an effort to cut their costs and boost revenue...&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=mainarttxt&gt;&lt;EM&gt;&lt;SPAN class=mainarttxt&gt;... Merrill&apos;s plans, and others like it, are very significant because they are the first companywide--rather than departmental--Linux implementations. While not without risk, this lends an enormous amount of credence to the argument that Linux can be used in place of more established technologies like Unix. &lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;[&lt;A href=&quot;http://www.forbes.com&quot;&gt;Forbes&lt;/A&gt;]&lt;/P&gt;&lt;/BLOCKQUOTE&gt;</description>
			<source url="http://slashdot.org/slashdot.rdf">Slashdot: News for nerds, stuff that matters</source>
			<category>Investment Banking Technology</category>
			</item>
		<item>
			<description>&lt;H4&gt;&lt;A href=&quot;http://www-106.ibm.com/developerworks/xml/library/x-encrypt/index.html&quot;&gt;Exploring XML Encryption&lt;/A&gt;&lt;/H4&gt;
&lt;P&gt;&lt;A href=&quot;http://www-106.ibm.com/developerworks/&quot;&gt;IBM Developer Works&lt;/A&gt; are running a good article on &lt;A href=&quot;http://www.w3.org/TR/xml-encryption-req&quot;&gt;XML Encryption&lt;/A&gt;. Over the last year or so almost all the new feeds and systems I&apos;ve linked in with on projects have used XML for interop. XML Security is going to be extremely important over the next year or two. It is particularly useful, because you can encrypt and sign individual elements rather than only full messages. The signatures will ofcourse verify the integrity of a message or element and the element by element encryption is useful for only allowing access to the part of the message you need in your subsystem.&lt;/P&gt;</description>
			<source url="http://www.theregister.co.uk/tonys/slashdot.rdf">The Register</source>
			<category>Investment Banking Technology</category>
			<category>Mobile Technology</category>
			<category>Payment Systems</category>
			<category>Web Services</category>
			<category>XML</category>
			</item>
		<item>
			<description>&lt;H4&gt;&lt;A href=&quot;http://www.internetnews.com/ent-news/article/0,,7_999111,00.html&quot;&gt;Increased Security Spending Includes Personnel&lt;/A&gt; &lt;/H4&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&lt;EM&gt;During the past year, Giga found that organizations appeared to appropriate larger portions of the budget for senior security managers, including chief security officers (CSOs) than before. Spurred by Sept. 11 and a heightened awareness of the need for security, the time of &quot;jungle rules&quot; for security management is at an end. &lt;/EM&gt;[&lt;A href=&quot;http://www.internetnews.com&quot;&gt;Internet News&lt;/A&gt; ]&lt;/P&gt;&lt;/BLOCKQUOTE&gt;</description>
			<source url="http://www.securityfocus.com/topnews?type=rss">Security Focus</source>
			</item>
		</channel>
	</rss>
