<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" version="2.0">

<channel>
	<title>Dan Griffin's Blog</title>
	
	<link>http://www.jwsecure.com</link>
	<description>Security, information technology, business</description>
	<lastBuildDate>Mon, 14 May 2012 23:36:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/jwsecure-dan" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="jwsecure-dan" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>See you @ ToorCamp 2012</title>
		<link>http://www.jwsecure.com/2012/05/14/see-you-toorcamp-2012/</link>
		<comments>http://www.jwsecure.com/2012/05/14/see-you-toorcamp-2012/#comments</comments>
		<pubDate>Mon, 14 May 2012 23:36:42 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[ToorCon]]></category>
		<category><![CDATA[TPM]]></category>

		<guid isPermaLink="false">http://www.jwsecure.com/2012/05/14/see-you-toorcamp-2012/</guid>
		<description><![CDATA[I’ll be presenting a talk entitled Hacking Measured Boot and EFI.]]></description>
			<content:encoded><![CDATA[<p>I’ll be presenting a talk entitled <a href="http://toorcamp.org/content12/2">Hacking Measured Boot and EFI</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jwsecure.com/2012/05/14/see-you-toorcamp-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Many Flavors of Authorization Claims</title>
		<link>http://www.jwsecure.com/2012/05/09/the-many-flavors-of-authorization-claims/</link>
		<comments>http://www.jwsecure.com/2012/05/09/the-many-flavors-of-authorization-claims/#comments</comments>
		<pubDate>Wed, 09 May 2012 15:04:41 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[JW Secure]]></category>
		<category><![CDATA[Newsletter]]></category>

		<guid isPermaLink="false">http://www.jwsecure.com/2012/05/09/the-many-flavors-of-authorization-claims/</guid>
		<description><![CDATA[The May 2012 edition of the JW Secure Informer newsletter is now out. Learn more about authorization claims here.]]></description>
			<content:encoded><![CDATA[<p>The May 2012 edition of the JW Secure Informer newsletter is now out. Learn more about authorization claims <a href="http://archive.constantcontact.com/fs007/1103180583929/archive/1109953876554.html">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jwsecure.com/2012/05/09/the-many-flavors-of-authorization-claims/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Great new AWS support for .NET &amp; SQL</title>
		<link>http://www.jwsecure.com/2012/05/09/great-new-aws-support-for-net-sql/</link>
		<comments>http://www.jwsecure.com/2012/05/09/great-new-aws-support-for-net-sql/#comments</comments>
		<pubDate>Wed, 09 May 2012 14:58:19 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[Amazon]]></category>
		<category><![CDATA[Cloud Computing]]></category>

		<guid isPermaLink="false">http://www.jwsecure.com/2012/05/09/great-new-aws-support-for-net-sql/</guid>
		<description><![CDATA[Amazon Web Services has announced built-in support for .NET developers in their easy scale-up fabric, Elastic Beanstalk, as well as support for SQL Server in their hosted relational data store, RDS. Pretty cool stuff for developers using the Microsoft/Windows tool chain. Full announcement is here.]]></description>
			<content:encoded><![CDATA[<p>Amazon Web Services has announced built-in support for .NET developers in their easy scale-up fabric, Elastic Beanstalk, as well as support for SQL Server in their hosted relational data store, RDS. Pretty cool stuff for developers using the Microsoft/Windows tool chain. Full announcement is <a href="http://aws.amazon.com/about-aws/whats-new/2012/05/08/new-managed-services-for-windows-developers/">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jwsecure.com/2012/05/09/great-new-aws-support-for-net-sql/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Real security is different from compliance</title>
		<link>http://www.jwsecure.com/2012/05/07/real-security-is-different-from-compliance/</link>
		<comments>http://www.jwsecure.com/2012/05/07/real-security-is-different-from-compliance/#comments</comments>
		<pubDate>Mon, 07 May 2012 14:44:32 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[Security Strategy]]></category>

		<guid isPermaLink="false">http://www.jwsecure.com/2012/05/07/real-security-is-different-from-compliance/</guid>
		<description><![CDATA[Couldn’t resist doing a post on this table, which makes some excellent points: However, the axis that’s missing here is customer demand. After all, how “real” can security be if nobody’s buying? Not that customers aren’t buying from both columns – they are. But why should there be this dichotomy, perceived or otherwise, between Compliance [...]]]></description>
			<content:encoded><![CDATA[<p>Couldn’t resist doing a post on this table, which makes some excellent points:</p>
<p><a href="http://www.jwsecure.com/wp-content/uploads/2012/05/clip_image002.jpg"><img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="clip_image002" border="0" alt="clip_image002" src="http://www.jwsecure.com/wp-content/uploads/2012/05/clip_image002_thumb.jpg" width="404" height="254"></a></p>
<p>However, the axis that’s missing here is customer demand. After all, how “real” can security be if nobody’s buying? Not that customers aren’t buying from both columns – they are. But why should there be this dichotomy, perceived or otherwise, between Compliance versus Real Security? Customers as well as technology vendors (not to mention government) share responsibility for that perception. The industry is better served by products that blur those lines.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jwsecure.com/2012/05/07/real-security-is-different-from-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Check out our Android integration capabilities</title>
		<link>http://www.jwsecure.com/2012/04/03/check-out-our-android-integration-capabilities/</link>
		<comments>http://www.jwsecure.com/2012/04/03/check-out-our-android-integration-capabilities/#comments</comments>
		<pubDate>Tue, 03 Apr 2012 23:10:14 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[JW Secure]]></category>
		<category><![CDATA[RSA]]></category>

		<guid isPermaLink="false">http://www.jwsecure.com/2012/04/03/check-out-our-android-integration-capabilities/</guid>
		<description><![CDATA[Captured by our new Android technology website page, and exemplified by the mobile health claims solution we demonstrated at the RSA conference this year – and which also included a Windows Phone “Mango” version – JW Secure are experts in device identity. Need a custom security solution on Android and don’t want to confuse your [...]]]></description>
			<content:encoded><![CDATA[<p>Captured by our new <a href="http://www.jwsecure.com/technologies/android/">Android technology website page</a>, and exemplified by the mobile health claims solution we demonstrated at the RSA conference this year – and which also included a Windows Phone “Mango” version – JW Secure are experts in device identity. Need a custom security solution on Android and don’t want to confuse your users? We’ve got that covered.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jwsecure.com/2012/04/03/check-out-our-android-integration-capabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Informer v13: Endpoint Security</title>
		<link>http://www.jwsecure.com/2012/03/26/informer-v13-endpoint-security/</link>
		<comments>http://www.jwsecure.com/2012/03/26/informer-v13-endpoint-security/#comments</comments>
		<pubDate>Mon, 26 Mar 2012 20:28:49 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[JW Secure]]></category>
		<category><![CDATA[Newsletter]]></category>

		<guid isPermaLink="false">http://www.jwsecure.com/2012/03/26/informer-v13-endpoint-security/</guid>
		<description><![CDATA[What is it about networked computers that allow them to be so easily hacked? Find out in the JW Secure Informer newsletter.]]></description>
			<content:encoded><![CDATA[<p>What is it about networked computers that allow them to be so easily hacked? Find out in the <a href="http://archive.constantcontact.com/fs007/1103180583929/archive/1109530502146.html">JW Secure Informer newsletter</a>. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.jwsecure.com/2012/03/26/informer-v13-endpoint-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Informer v12: Business Agility, Structured Storage</title>
		<link>http://www.jwsecure.com/2012/03/26/informer-v12-business-agility-structured-storage/</link>
		<comments>http://www.jwsecure.com/2012/03/26/informer-v12-business-agility-structured-storage/#comments</comments>
		<pubDate>Mon, 26 Mar 2012 20:25:11 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[JW Secure]]></category>
		<category><![CDATA[Newsletter]]></category>

		<guid isPermaLink="false">http://www.jwsecure.com/2012/03/26/informer-v12-business-agility-structured-storage/</guid>
		<description><![CDATA[High-growth businesses have advanced IT needs that can only be met by a combination of services and resources that are internal and external, off-premise and on-premise. The best line of business storage solutions are those that offer the interoperability of SQL, the rapid provisioning benefits of the cloud, and the security benefits of on-premise storage. [...]]]></description>
			<content:encoded><![CDATA[<p>High-growth businesses have advanced IT needs that can only be met by a combination of services and resources that are internal and external, off-premise and on-premise. The best line of business storage solutions are those that offer the interoperability of SQL, the rapid provisioning benefits of the cloud, and the security benefits of on-premise storage.</p>
<p>Learn more in the <a href="http://archive.constantcontact.com/fs007/1103180583929/archive/1109062061021.html">JW Secure Informer newsletter</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jwsecure.com/2012/03/26/informer-v12-business-agility-structured-storage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New SmartUtil available for Windows 8</title>
		<link>http://www.jwsecure.com/2012/03/14/new-smartutil-available-for-windows-8/</link>
		<comments>http://www.jwsecure.com/2012/03/14/new-smartutil-available-for-windows-8/#comments</comments>
		<pubDate>Wed, 14 Mar 2012 22:38:59 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[SmartUtil]]></category>
		<category><![CDATA[Windows 8]]></category>

		<guid isPermaLink="false">http://www.jwsecure.com/2012/03/14/new-smartutil-available-for-windows-8/</guid>
		<description><![CDATA[SmartUtil version 1.0.3.1 is now available for download here. It supports Windows versions Vista through 8, including the new virtual smart card device.]]></description>
			<content:encoded><![CDATA[<p>SmartUtil version 1.0.3.1 is now available for download <a href="http://www.jwsecure.com/wp-content/uploads/2012/03/SmartUtil-1.0.3.1.zip">here</a>. It supports Windows versions Vista through 8, including the new virtual smart card device.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jwsecure.com/2012/03/14/new-smartutil-available-for-windows-8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mobile Computing Revealed – Tonight!</title>
		<link>http://www.jwsecure.com/2012/03/14/mobile-computing-revealed-tonight/</link>
		<comments>http://www.jwsecure.com/2012/03/14/mobile-computing-revealed-tonight/#comments</comments>
		<pubDate>Wed, 14 Mar 2012 16:38:32 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[JW Secure]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Mobile Computing]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Seattle]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows 8]]></category>

		<guid isPermaLink="false">http://www.jwsecure.com/2012/03/14/mobile-computing-revealed-tonight/</guid>
		<description><![CDATA[Come check out Mobile Computing Revealed, hosted tonight in Bellevue by Seattle Technical Forum. Event details and registration are here. I’ll be presenting Mobile Health Claims, including two of the demos that we did this year for RSA.]]></description>
			<content:encoded><![CDATA[<p>Come check out Mobile Computing Revealed, hosted tonight in Bellevue by Seattle Technical Forum. Event details and registration are <a href="http://www.meetup.com/Sea-Tech-Forum/events/36852322/">here</a>. I’ll be presenting Mobile Health Claims, including two of the demos that we did this year for RSA.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jwsecure.com/2012/03/14/mobile-computing-revealed-tonight/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud is RAD on steroids</title>
		<link>http://www.jwsecure.com/2012/03/05/cloud-is-rad-on-steroids/</link>
		<comments>http://www.jwsecure.com/2012/03/05/cloud-is-rad-on-steroids/#comments</comments>
		<pubDate>Mon, 05 Mar 2012 21:59:21 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[Amazon]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Azure]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[JW Secure]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[TPM]]></category>
		<category><![CDATA[Windows 8]]></category>

		<guid isPermaLink="false">http://www.jwsecure.com/2012/03/05/cloud-is-rad-on-steroids/</guid>
		<description><![CDATA[We (JW Secure) used cloud computing as the foundation for all four of the “live” security demos we showed at our booth at RSA last week: Mobile Health Claims: the backend consists of a consumer banking web service and a custom security token service (STS), both of which are running on Windows Azure. The frontend [...]]]></description>
			<content:encoded><![CDATA[<p>We (JW Secure) used cloud computing as the foundation for all four of the “live” security demos we showed at our booth at RSA last week:</p>
<ul>
<li><strong>Mobile Health Claims</strong>: the backend consists of a consumer banking web service and a custom security token service (STS), both of which are running on Windows Azure. The frontend consists of a mobile checking app for Android and Windows Phone. Device identity is tightly bound to user identity, and only devices with up to date firmware and operating system versions are allowed to perform high-value transactions such as fund transfer. </li>
<li><strong>TPM Health Claims</strong>: the backend consists of a Windows web server running in Amazon EC2. The frontend is a web page with an ActiveX control. The control allows the user to sign into online checking only from a host that meets a certain security bar (anti-malware signatures are up to date, firewall is on, etc.). Health data is submitted in the form of SAML claims, signed by a private key protected by the client Trusted Platform Module (TPM).</li>
<li><strong>Secure Boot and Remote Attestation</strong>: the backend consists of a line of business (LOB) web service and an STS, both in Azure. The web service implements a purchase order submission and approval workflow and interfaces with a front-end Metro-style GUI. Purchase orders can only be approved if the host TPM is trusted and the boot log is clean.</li>
</ul>
<p>See a recurring theme? LOB services deployed to the cloud. This is the new state of the art when it comes to Rapid Application Development (RAD). If you’re an LOB development shop and you’re not taking advantage of the latest toolkits (Ruby on Rails, ASP.NET MVC) and cloud application fabrics (Heroku, Azure), then you’re probably not deploying new business capabilities as quickly as you could be. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.jwsecure.com/2012/03/05/cloud-is-rad-on-steroids/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

