<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>grounded</title>
    <link>http://www.olafkock.de/ok/</link>
    <description>Olaf Kock</description>
    <language>de</language>
    <copyright>Olaf Kock</copyright>
    <pubDate>Sun, 11 Sep 2011 19:14:23 GMT</pubDate>
    <dc:creator>Olaf Kock</dc:creator>
    <dc:date>2011-09-11T19:14:23Z</dc:date>
    <dc:language>de</dc:language>
    <dc:rights>Olaf Kock</dc:rights>
    <image>
      <title>grounded</title>
      <url>http://www.olafkock.de/ok/</url>
    </image>
    <item>
      <title>TNO - Trust No One.</title>
      <link>http://www.olafkock.de/ok/2011/09/11/tno_trust_no_one.html</link>
      <content:encoded>&lt;p&gt;First of all:&amp;nbsp;This is not a security analysis, and no statement about the actual security of firefox sync. It's merely an analysis &lt;em&gt;of the description given in the FAQ&lt;/em&gt; and my conclusion from that. And a brief one as well. I do &lt;em&gt;not&lt;/em&gt; want to downplay the security of Firefox Sync. It's merely an example of how to read and judge claims of security features - documentation! &lt;em&gt;I did not even look at the technical background of sync, I didn't try to use it - and I don't want to&lt;/em&gt;. Read on to know why.&lt;/p&gt;
&lt;p&gt;[Update:&amp;nbsp;From the comments below it seems that technically everything is well designed:&amp;nbsp;Keys get generated on the client. Still, as this is about reading security information literally, the comment holds. I hope the FAQ will be updated to state this sooner or later]&lt;/p&gt;
&lt;h1&gt;Handling passwords&lt;/h1&gt;
&lt;p&gt;I know that I can save my passwords in firefox. In fact, I use this feature for certain sites. I implicitly trust the algorithm that's used for encrypting the password vault with the passphrase that I have to enter (the so called master password). Of course, this is the first thing I do after installing Firefox to a new machine. And I trust my passphrase to provide enough security for the purpose of the passwords that I save in there. And I trust that my passphrase never leaves my computer.&lt;/p&gt;
&lt;p&gt;However, now, on a new system with the latest and greatest Firefox, Firefox not only offers to store my password, but also to sync it to Mozilla's servers. This is from a component called Sync, has been a plugin previously, but is now in the core. I guess many people might use it due to this fact.&lt;/p&gt;
&lt;p&gt;Being the security conscious wisenheimer (why do I want my &lt;em&gt;passwords&lt;/em&gt; to be stored on a third party computer?), I looked up &amp;quot;firefox sync&amp;quot;, and got directed to &lt;a href="http://support.mozilla.com/en-US/kb/what-firefox-sync"&gt;Mozilla's FAQ&lt;/a&gt;. There it states, among other information&lt;/p&gt;
&lt;div style="margin-left: 40px; font-style: italic;"&gt;
&lt;h2&gt;What is a Sync Key and why do I need one?&lt;/h2&gt;
&lt;p&gt;When you set up a Sync account we generate a long string of numbers  and letters that we call a Sync Key. The Sync Key is used to encrypt  your data before it's sent to the Mozilla servers. Think of it as a key  that locks your information in a vault that only you can open. This  means that neither Mozilla nor anyone else can read your information  without having your Sync Key to unlock it.&lt;/p&gt;
&lt;h2&gt;Where's all my data?&lt;/h2&gt;
&lt;p&gt;It's encrypted with your Sync Key and safely stored on the Mozilla  servers. Because Sync uses advanced security measures your information  is never vulnerable to online bad guys or companies that will sell your  information.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;Sounds good? Well, very convenient at least. Let me emphasize the parts that caught my attention:&lt;/p&gt;
&lt;div style="margin-left: 40px; font-style: italic;"&gt;
&lt;h2&gt;What is a Sync Key and why do I need one?&lt;/h2&gt;
&lt;p&gt;When you set up a Sync account &lt;u&gt;&lt;strong&gt;we&lt;/strong&gt;&lt;/u&gt; generate a long string of numbers  and letters that we call a Sync Key. The Sync Key is used to encrypt  your data before it's sent to the Mozilla servers. Think of it as a key  that locks your information in a vault that only you can open. This  means that &lt;u&gt;&lt;strong&gt;neither Mozilla nor anyone else can read&lt;/strong&gt;&lt;/u&gt; your information  &lt;u&gt;&lt;strong&gt;without having your Sync Key&lt;/strong&gt;&lt;/u&gt; to unlock it.&lt;/p&gt;
&lt;h2&gt;Where's all my data?&lt;/h2&gt;
&lt;p&gt;It's encrypted with your Sync Key and safely stored on the Mozilla  servers. Because Sync uses advanced security measures your information  is &lt;u&gt;&lt;strong&gt;never&lt;/strong&gt;&lt;/u&gt; vulnerable to online bad guys or companies that will sell your  information.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;As I said, I never analyzed sync! I only read the linked FAQ article. And these two paragraphs make me want to uninstall it immediately. But I can't - it's in the core now. Well, at least I can &amp;quot;not use&amp;quot; it.&lt;/p&gt;
&lt;p&gt;Just in case there is someone who didn't get my point from the emphasis above, here's some reasoning:&lt;/p&gt;
&lt;p&gt;&lt;u&gt;&lt;em&gt;Mozilla&lt;/em&gt;&lt;/u&gt; generates a key, and nobody &lt;u&gt;&lt;em&gt;who does not have it&lt;/em&gt;&lt;/u&gt; can access my data. This &lt;em&gt;should&lt;/em&gt; imply that &lt;u&gt;&lt;em&gt;nobody but me&lt;/em&gt;&lt;/u&gt; can access my data. But what keeps the party that generates such a key to keep a copy? I have been somewhat wary even before I started to listen to the &lt;a href="http://twit.tv/sn"&gt;Security Now netcast&lt;/a&gt;, but from Steve Gibson I learnt the term &amp;quot;Trust No One&amp;quot; (TNO), which give a name to my suspicions.&lt;/p&gt;
&lt;p&gt;Well, and being &lt;u&gt;&lt;em&gt;never&lt;/em&gt;&lt;/u&gt;&lt;em&gt; vulnerable&lt;/em&gt; is probably a bit too far fetched and would need a few disclaimers. But this is merely a small detail, not the core of my problem.&lt;/p&gt;
&lt;p&gt;It's not that I don't trust Mozilla (I'm running their software loyally since the Netscape age, and you know that software running locally can do), but this description is hiding the underlying problems from the ingenuous reader. I know that the FAQ is a wiki - I could edit it or the discussion - but the underlying problem is not so much in this documentation, it's rather the principle that's broken (if the documentation is correct). Yes, it's a convenient solution, but no, there's no way I accept the described mode of operation as a security feature for knowingly storing data like my passwords on any third party server. I know that other's might accept this, but it really turns me down and away from this.&lt;/p&gt;
&lt;p&gt;Even if the FAQ is incorrect ant the Sync Key is generated locally and never leaves my computer (unless I install it on another computer myself), this article shall still ask for reading such documentations accurately.&lt;/p&gt;
&lt;p&gt;And, to finish this with another disclaimer:&amp;nbsp;For the foreseeable future Firefox will stay to be my preferred browser. I'm a geek of habit, and it's easy to work around this issue by not using sync. After all, it takes some work to activate it. And I love Firefox (and the plugin zoo that I have assembled and that I'm trusting implicitly). Oh, and did I mention that I love &lt;a href="http://twit.tv/sn"&gt;Security Now&lt;/a&gt;?&lt;/p&gt;</content:encoded>
      <category domain="http://www.olafkock.de/ok/categories/en/">english</category>
      <category domain="http://www.olafkock.de/ok/tags/encryption/">encryption</category>
      <category domain="http://www.olafkock.de/ok/tags/security/">security</category>
      <category domain="http://www.olafkock.de/ok/tags/software/">software</category>
      <pubDate>Sun, 11 Sep 2011 19:14:23 GMT</pubDate>
      <guid isPermaLink="false">tag:www.olafkock.de,2011-09-11:default/1315768463934</guid>
      <dc:date>2011-09-11T19:14:23Z</dc:date>
    </item>
    <item>
      <title>Radio Liferay</title>
      <link>http://www.olafkock.de/ok/2011/08/19/radio_liferay.html</link>
      <content:encoded>&lt;p&gt;I've started podcasting again. It's all on &lt;a href="https://www.liferay.com/web/olaf.kock/blog"&gt;liferay.com&lt;/a&gt; and &lt;a href="http://feeds.feedburner.com/RadioLiferay"&gt;feedburner&lt;/a&gt;. The current working title is &amp;quot;Radio Liferay&amp;quot; and it covers all things noteworthy about Liferay.&lt;/p&gt;</content:encoded>
      <enclosure url="http://feedproxy.google.com/~r/RadioLiferay/~3/XNRR2-UrGdw/radio-liferay-episode-1%3A-james-falkner" length="33736704" type="audio/x-mpeg" />
      <category domain="http://www.olafkock.de/ok/tags/liferay/">liferay</category>
      <category domain="http://www.olafkock.de/ok/tags/podcast/">podcast</category>
      <pubDate>Fri, 19 Aug 2011 18:46:00 GMT</pubDate>
      <guid isPermaLink="false">tag:www.olafkock.de,2011-08-19:default/1313779560000</guid>
      <dc:date>2011-08-19T18:46:00Z</dc:date>
    </item>
    <item>
      <title>It's been a while</title>
      <link>http://www.olafkock.de/ok/2011/05/23/its_been_a_while.html</link>
      <content:encoded>&lt;p&gt;It's been a while since I updated this blog. During this time &lt;a href="http://jazzy.id.au/"&gt;James Roper&lt;/a&gt; has been busy with a few more &lt;a href="http://pebble.sf.net"&gt;pebble&lt;/a&gt; releases. At the time of this writing, we're at 2.6.2, see the &lt;a href="http://open.jira.com/browse/PEBBLE"&gt;change log&lt;/a&gt; on open.jira.com for a summary on what's new and noteworthy.&lt;/p&gt;
&lt;p&gt;Also, James has taken over the lead developer role for pebble. It was obvious for a while - I didn't find enough time to quickly answer to issues that he typically jumped on immediately. A big thanks for this, now I'll just need to set aside the time to upgrade this installation here. Luckily all versions of pebble have shown to be quite more stable than some (php-based) blog engines, so there's no immediate need to upgrade - one of the reasons I chose pebble in the beginning.&lt;/p&gt;
&lt;p&gt;Finding time is a nice reminder: Being on the road quite often now (for Liferay), I've started to do Liferay community meetings where I'm travelling to. They are announced on my &lt;a href="https://www.liferay.com/de/web/olaf.kock/blog"&gt;Liferay Blog&lt;/a&gt;, feel free to subscribe there to get a chance to meet, typically somewhere in europe. Even if you're not (yet?) working with Liferay, feel free to show up.&lt;/p&gt;&lt;div class="tags"&gt;&lt;span&gt;Social Bookmarks : &lt;/span&gt;&amp;nbsp;&lt;a href="http://slashdot.org/bookmark.pl?url=http://www.olafkock.de/ok/2011/05/23/its_been_a_while.html&amp;amp;title=It%27s+been+a+while" target="_blank" title="Add this post to Slash Dot"&gt;&lt;img src="common/images/slashdot.png" alt="Add this post to Slashdot" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://digg.com/submit?url=http://www.olafkock.de/ok/2011/05/23/its_been_a_while.html&amp;amp;title=It%27s+been+a+while" target="_blank" title="Digg this post"&gt;&lt;img src="common/images/digg.png" alt="Add this post to Digg" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://reddit.com/submit?url=http://www.olafkock.de/ok/2011/05/23/its_been_a_while.html&amp;amp;title=It%27s+been+a+while" target="_blank" title="Add this post to Reddit"&gt;&lt;img src="common/images/reddit.png" alt="Add this post to Reddit" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://del.icio.us/post?url=http://www.olafkock.de/ok/2011/05/23/its_been_a_while.html&amp;amp;title=It%27s+been+a+while" target="_blank" title="Save this post to Del.icio.us"&gt;&lt;img src="common/images/delicious.png" alt="Add this post to Delicious" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://www.stumbleupon.com/submit?url=http://www.olafkock.de/ok/2011/05/23/its_been_a_while.html&amp;amp;title=It%27s+been+a+while" target="_blank" title="Stumble this post"&gt;&lt;img src="common/images/stumbleupon.png" alt="Add this post to Stumble it" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://www.google.com/bookmarks/mark?op=edit&amp;amp;bkmk=http://www.olafkock.de/ok/2011/05/23/its_been_a_while.html&amp;amp;title=It%27s+been+a+while" target="_blank" title="Add this post to Google"&gt;&lt;img src="common/images/google.png" alt="Add this post to Google" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://technorati.com/faves?add=http://www.olafkock.de/ok/2011/05/23/its_been_a_while.html" target="_blank" title="Add this post to Technorati"&gt;&lt;img src="common/images/technorati.png" alt="Add this post to Technorati" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://www.bloglines.com/sub/http://www.olafkock.de/ok/2011/05/23/its_been_a_while.html" target="_blank" title="Add this post to Bloglines"&gt;&lt;img src="common/images/bloglines.png" alt="Add this post to Bloglines" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://www.facebook.com/share.php?u=http://www.olafkock.de/ok/2011/05/23/its_been_a_while.html" target="_blank" title="Add this post to Facebook"&gt;&lt;img src="common/images/facebook.png" alt="Add this post to Facebook" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://www.furl.net/storeIt.jsp?u=http://www.olafkock.de/ok/2011/05/23/its_been_a_while.html&amp;amp;t=It%27s+been+a+while" target="_blank" title="Add this post to Furl"&gt;&lt;img src="common/images/furl.png" alt="Add this post to Furl" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;amp;url=http://www.olafkock.de/ok/2011/05/23/its_been_a_while.html&amp;amp;title=It%27s+been+a+while" target="_blank" title="Add this post to Windows Live"&gt;&lt;img src="common/images/windowslive.png" alt="Add this post to Windows Live" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;amp;u=http://www.olafkock.de/ok/2011/05/23/its_been_a_while.html&amp;amp;t=It%27s+been+a+while" target="_blank" title="Add this post to Yahoo!"&gt;&lt;img src="common/images/yahoo.png" alt="Add this post to Yahoo!" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;</content:encoded>
      <category domain="http://www.olafkock.de/ok/categories/en/">english</category>
      <category domain="http://www.olafkock.de/ok/tags/liferay/">liferay</category>
      <category domain="http://www.olafkock.de/ok/tags/pebble/">pebble</category>
      <pubDate>Mon, 23 May 2011 04:25:00 GMT</pubDate>
      <guid isPermaLink="false">tag:www.olafkock.de,2011-05-23:default/1306124700000</guid>
      <dc:date>2011-05-23T04:25:00Z</dc:date>
    </item>
    <item>
      <title>Pebble 2.5 RC 1 released</title>
      <link>http://www.olafkock.de/ok/2010/09/08/pebble_2_5_rc_1_released.html</link>
      <content:encoded>&lt;p&gt;A big Thank You goes to &lt;a href="http://jazzy.id.au/"&gt;James Roper&lt;/a&gt; for continuing to bring pebble forward. Last week he released &lt;a href="http://prdownloads.sourceforge.net/pebble/pebble-2.5-RC1.zip?download"&gt;pebble 2.5 RC 1&lt;/a&gt; - go ahead, download and test.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Major new features to test in this release include:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;New plugin manager - the old entering class names and property names manually is gone, and is replaced by a new interface with inline documentation for each plugin.  See &lt;a class="moz-txt-link-freetext" href="http://open.jira.com/wiki/display/PEBBLE/Plugin+Development"&gt;http://open.jira.com/wiki/display/PEBBLE/Plugin+Development&lt;/a&gt; for more information.&lt;/li&gt;
    &lt;li&gt;XSRF protection - Pebble should now be safe from XSRF attacks.  If while using Pebble normally, you reach an error page saying &amp;quot;No Security Token&amp;quot;, then you have probably encountered a bug.  Read &lt;a class="moz-txt-link-freetext" href="http://open.jira.com/wiki/display/PEBBLE/XSRF+Prevention"&gt;http://open.jira.com/wiki/display/PEBBLE/XSRF+Prevention&lt;/a&gt; for more information.&lt;/li&gt;
    &lt;li&gt;Facebook OpenID comment authors.  This plugin can be enabled in the plugin administration (make sure you read the docs carefully, you need to setup a Facebook application for your blog and enter the ID for it into Pebble for this to work).&lt;/li&gt;
    &lt;li&gt;Twitter integration&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;Read his &lt;a href="http://sourceforge.net/mailarchive/forum.php?thread_name=AANLkTi%3DOt_%2B7-vXoGaF_GZiyQxWwFm2gmTGnGqfe6mTp%40mail.gmail.com&amp;amp;forum_name=pebble-user"&gt;original announcement&lt;/a&gt; on the pebble mailing list.&lt;/p&gt;</content:encoded>
      <category domain="http://www.olafkock.de/ok/categories/en/">english</category>
      <category domain="http://www.olafkock.de/ok/tags/pebble/">pebble</category>
      <category domain="http://www.olafkock.de/ok/tags/software/">software</category>
      <pubDate>Wed, 08 Sep 2010 18:42:00 GMT</pubDate>
      <guid isPermaLink="false">tag:www.olafkock.de,2010-09-08:default/1283971320000</guid>
      <dc:date>2010-09-08T18:42:00Z</dc:date>
    </item>
    <item>
      <title>Verpackungsweisheiten</title>
      <link>http://www.olafkock.de/ok/2010/08/14/verpackungsweisheiten.html</link>
      <content:encoded>&lt;p&gt;Verpackungen begeistern mich immer wieder.&amp;nbsp;Diese pr&amp;auml;zise Sprache:&amp;nbsp;&amp;quot;komplett mit feinem Butter&lt;em&gt;geschmack&lt;/em&gt;&amp;quot;, &amp;quot;ohne &lt;em&gt;k&amp;uuml;nstliche&lt;/em&gt; Aromastoffe&amp;quot;, &amp;quot;dermatologisch getestet&amp;quot;, &amp;quot;&lt;a href="https://twitter.com/olafk/status/19802562638"&gt;kann Spuren von N&amp;uuml;ssen enthalten&lt;/a&gt;&amp;quot;.&lt;/p&gt;
&lt;p&gt;&lt;img align="right" alt="" src="/ok/images/buttergeschmack.png" /&gt;In diesem Kartoffelp&amp;uuml;ree &amp;quot;&lt;em&gt;komplett mit feinem Buttergeschmack&lt;/em&gt;&amp;quot; ist jedenfalls laut Zutatenliste kein bisschen Butter enthalten. Steht ja auch nicht drauf. Ausschnitt aus der Zutatenliste, die vielleicht mehr oder weniger zum &amp;quot;feinen Buttergeschmack&amp;quot; beitragen (in umgekehrter Reihenfolge): Aroma, Milcheiwei&amp;szlig;,   Milchzucker.&lt;/p&gt;
&lt;p&gt;Ich liebe sowas ja. Oder es frustriert mich. Kann ich nicht so genau sagen. Gleich noch ein Beispiel, dieses Mal keine Lebensmittel:&lt;/p&gt;
&lt;p&gt;&lt;img align="left" alt="" src="/ok/images/dermatologischbestaetigt.png" /&gt;&amp;quot;&lt;em&gt;Dermatologisch best&amp;auml;tigt:&amp;nbsp;ph-Wert 5.5&lt;/em&gt;&amp;quot;. Nun ja - das h&amp;auml;tte nicht unbedingt ein Dermatologe best&amp;auml;tigen m&amp;uuml;ssen. Ein durchschnittlicher Chemielaborant, vielleicht auch ein Sch&amp;uuml;ler mit Zugang zu den Chemier&amp;auml;umen seiner Schule h&amp;auml;tte das wohl auch gekonnt. H&amp;auml;tte aber nicht so gut geklungen...&lt;/p&gt;
&lt;p&gt;Oder kann mich jemand aufkl&amp;auml;ren und da steckt tats&amp;auml;chlich was bemerkenswertes dahinter, das ich bisher &amp;uuml;bersehen habe? Ich will ja nicht sagen, dass es keine&amp;nbsp;Hautvertr&amp;auml;glichkeitspr&amp;uuml;fungen gegeben hat, aber die Verpackung sagt zumindest dar&amp;uuml;ber nichts aus.&lt;/p&gt;
&lt;p&gt;Was mich am meisten fasziniert: Viele Menschen scheinen aus solchen Etiketten nicht das gleiche zu lesen wie ich - sonst w&amp;uuml;rde z.B. bei Lebensmitteln der unverhohlene Hinweis auf den Ersatz von hochpreisigen Inhaltsstoffen durch billige Aromastoffe ja nicht wirken. Oder ist die Grundeinstellung da drau&amp;szlig;en tats&amp;auml;chlich&amp;nbsp;&amp;quot;Hauptsache es schmeckt - egal wodurch&amp;quot;? Dann wundern mich pl&amp;ouml;tzlich auch die ganzen vergangenen Gammelfleischskandale nicht mehr. Apropos:&amp;nbsp;War lange keiner mehr, oder?&lt;/p&gt;</content:encoded>
      <category domain="http://www.olafkock.de/ok/categories/de/">deutsch</category>
      <category domain="http://www.olafkock.de/ok/tags/etikett/">etikett</category>
      <category domain="http://www.olafkock.de/ok/tags/sprachpanscherei/">sprachpanscherei</category>
      <pubDate>Sat, 14 Aug 2010 12:51:49 GMT</pubDate>
      <guid isPermaLink="false">tag:www.olafkock.de,2010-08-14:default/1281790309977</guid>
      <dc:date>2010-08-14T12:51:49Z</dc:date>
    </item>
  </channel>
</rss>

