<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ilium Software Blog &#187; Security</title>
	<atom:link href="http://blog.iliumsoft.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.iliumsoft.com</link>
	<description>Behind the Scenes at Ilium Software</description>
	<lastBuildDate>Mon, 23 Jan 2012 20:24:19 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<copyright>Copyright 2004-2012, Ilium Software, Inc.</copyright>
	<ttl>480</ttl>
<image>
	<url>http://blog.iliumsoft.com/wp-content/iliumsoft_feed.png</url>
	<width>81</width>
	<height>31</height>
	<title>Ilium Software</title>
	<link>http://blog.iliumsoft.com</link>
</image>
		<item>
		<title>Dropbox exposed? Not a problem for eWallet GO!</title>
		<link>http://blog.iliumsoft.com/2011/06/21/dropbox-exposed-not-a-problem-for-ewallet-go/</link>
		<comments>http://blog.iliumsoft.com/2011/06/21/dropbox-exposed-not-a-problem-for-ewallet-go/#comments</comments>
		<pubDate>Tue, 21 Jun 2011 18:33:58 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[eWallet GO!]]></category>

		<guid isPermaLink="false">http://blog.iliumsoft.com/?p=2394</guid>
		<description><![CDATA[As you may have heard, Dropbox accidentally left the barn door open over the weekend. Thanks to a glitch in their system, Dropbox made it possible to access some of their secure user vaults without a password. The good news is that if you are an eWallet GO!™ customer that syncs to Dropbox, your eWallet [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.iliumsoft.com/wp-content/uploads/2011/04/114.png"><img class="alignleft size-full wp-image-2309" title="eWallet GO!" src="http://blog.iliumsoft.com/wp-content/uploads/2011/04/114.png" alt="eWallet GO!" width="114" height="114" /></a>As you may have heard, Dropbox accidentally <a href="http://blog.dropbox.com/?p=821">left the barn door open</a> over the weekend. Thanks to a glitch in their system, Dropbox made it possible to access some of their secure user vaults without a password. The good news is that if you are an eWallet GO!™ customer that syncs to Dropbox, your eWallet GO! data is safe.</p>
<p>The file eWallet GO! saves on Dropbox is fully encrypted using 256-bit AES encryption. This means that an eWallet GO! data file using a strong password would <a href="http://blog.iliumsoft.com/2011/05/06/ewallet-go-makes-cloud-storage-safer/">take thousands of years</a> to hack! Even if someone did get into your Dropbox account over the weekend, your data is safe if you stored your important information in eWallet GO!</p>
<p>And if you aren&#8217;t using eWallet GO! you should <a href="http://www.ewalletgo.com">get it today</a>! That way, if the other guy drops the ball, you can relax and know that your most important information will remain secure!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.iliumsoft.com/2011/06/21/dropbox-exposed-not-a-problem-for-ewallet-go/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>eWallet GO! LastPass Converter Available</title>
		<link>http://blog.iliumsoft.com/2011/05/10/ewallet-go-lastpass-converter-available/</link>
		<comments>http://blog.iliumsoft.com/2011/05/10/ewallet-go-lastpass-converter-available/#comments</comments>
		<pubDate>Tue, 10 May 2011 15:28:20 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
				<category><![CDATA[Our Products]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software in General]]></category>
		<category><![CDATA[eWallet GO!]]></category>

		<guid isPermaLink="false">http://blog.iliumsoft.com/?p=2357</guid>
		<description><![CDATA[
By popular request, we just released an update to the eWallet GO!™ Conversion Utility* that lets you easily move data exported from LastPass into eWallet GO!
It&#8217;s easy to do! Just export the LastPass data and save it into a text file, then run through the Conversion Utility wizard. That&#8217;s it! The utility does all the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.iliumsoft.com/wp-content/uploads/2011/04/114.png"><img class="alignleft size-full wp-image-2309" title="eWallet GO!" src="http://blog.iliumsoft.com/wp-content/uploads/2011/04/114.png" alt="eWallet GO!" width="114" height="114" /></a></p>
<div id="_mcePaste">By popular request, we just released an update to the <a href=" http://www.iliumsoft.com/wtu">eWallet GO!™ Conversion Utility</a>* that lets you easily move data exported from LastPass into eWallet GO!</div>
<p>It&#8217;s easy to do! Just export the LastPass data and save it into a text file, then run through the Conversion Utility wizard. That&#8217;s it! The utility does all the rest!</p>
<div id="_mcePaste">We hope this helps those of you who were looking for a solution like this!</div>
<p>For more information about eWallet GO! <a href="http://www.ewalletgo.com">click here</a>.<br />
To access the eWallet GO! Conversion Utility <a href="http://www.iliumsoft.com/wtu">click here</a>.<br />
To learn more about converting to eWallet GO! from LastPass, <a href="http://www.iliumsoft.com/site/support/kb/article.php?id=522">click here</a>.</p>
<h6>* Previously known as the Wallet Transfer Utility</h6>
]]></content:encoded>
			<wfw:commentRss>http://blog.iliumsoft.com/2011/05/10/ewallet-go-lastpass-converter-available/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>eWallet GO! Makes Cloud Storage Safer</title>
		<link>http://blog.iliumsoft.com/2011/05/06/ewallet-go-makes-cloud-storage-safer/</link>
		<comments>http://blog.iliumsoft.com/2011/05/06/ewallet-go-makes-cloud-storage-safer/#comments</comments>
		<pubDate>Fri, 06 May 2011 20:45:16 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[BlackBerry]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Our Products]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software in General]]></category>
		<category><![CDATA[eWallet GO!]]></category>
		<category><![CDATA[iPhone, iPad and iPod touch]]></category>

		<guid isPermaLink="false">http://blog.iliumsoft.com/?p=2345</guid>
		<description><![CDATA[With recent news about a possible security breach for a cloud-based secure information manager and discussions like this one at various sites around the web, we wanted to say a few things about eWallet GO!TM With eWallet GO! we&#8217;ve developed a solution that gives you the convenience of cloud based storage and sharing while significantly [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.iliumsoft.com/wp-content/uploads/2011/04/114.png"><img class="alignleft size-full wp-image-2309" title="eWallet GO!" src="http://blog.iliumsoft.com/wp-content/uploads/2011/04/114.png" alt="eWallet GO!" width="114" height="114" /></a>With recent news about a possible security breach for a cloud-based secure information manager and discussions <a href="http://www.gottabemobile.com/2011/05/05/do-lastpass-issues-point-to-concerns-storing-passwords-in-the-cloud/">like this one</a> at various sites around the web, we wanted to say a few things about eWallet GO!<sup>TM</sup> With eWallet GO! we&#8217;ve developed a solution that gives you the convenience of cloud based storage and sharing while significantly reducing the risk!</p>
<p>When you backup your information to Dropbox or Google Docs from eWallet GO! you&#8217;re backing up a fully encrypted file. This file features the power of 256-bit AES encryption. Even if someone managed to get this backup file, as long as you&#8217;ve chosen a strong password, <strong>it is effectively impossible for them to access your personal information stored in eWallet GO!</strong> And when we decrypt your data so you can view it, it all happens locally – we never, EVER send your password over the internet.</p>
<p><strong>But how safe is safe?</strong></p>
<p>But what does this “256-bit” stuff mean? In <a href="http://en.wikipedia.org/wiki/Brute-force_attack">a great article on Wikipedia</a> about what it would take to hack a file using 256-bit AES encryption, they offer the following:</p>
<blockquote><p><em>A device that could check a billion billion (1018) AES keys per second (if such a device could ever be made) would in theory require about 3×10<sup>51</sup> years to exhaust the 256-bit key space.</em></p></blockquote>
<p>In other words, a really good password using 256-bit AES encryption is effectively unhackable by anything outside of science fiction. Humans will have constructed a <a href="http://en.wikipedia.org/wiki/Dyson_sphere">Dyson Sphere</a> around the sun and shed our mortal forms by the time someone can get to your data.</p>
<p><strong>Good Passwords Required!</strong></p>
<p>There is a caveat – <strong>the security is only as good as the password</strong>. First, we all know choosing a password another person could guess is a bad idea. We also know that we should never leave the password where someone else could find it, and we know that we should never pick a word that appears in the dictionary. We hear this advice time and again from security experts, and it’s true!</p>
<p>But what about a “brute force” attack, where a hacker uses a computer to guess the password by trying different combinations of letters, numbers, and symbols? In this case, the longer the password, the harder it becomes to crack. How hard? Let me give you a couple of examples:</p>
<blockquote><p><em>An 8-digit password using all lowercase letters would take, in theory, around 3-6 years to hack with brute force.</em></p>
<p><em>An 8-digit password using a combination of lowercase, uppercase, numbers, and symbols would take, in theory, around 4000-8000 years to hack with brute force.</em></p></blockquote>
<p>That’s right – if your password is f8#$mGQ! it could take 4-8 THOUSAND years to figure it out using an off-the shelf computer and the appropriate software.</p>
<p>And here’s the best part – length benefits are exponential! Add one more character – and now it might take 250-500 THOUSAND YEARS to hack your password.</p>
<p>At the end of the day, you don’t have to sacrifice convenience for security. <strong>With eWallet GO! you get all the benefits of cloud based storage and sharing while significantly reducing the risk</strong>.</p>
<p><em>Need help building a strong password? Visit <a href="http://www.passbuilder.com">www.passbuilder.com</a> to generate super-strong passwords!</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.iliumsoft.com/2011/05/06/ewallet-go-makes-cloud-storage-safer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>eWallet 7.0 &#8211; Updates and Answers</title>
		<link>http://blog.iliumsoft.com/2009/11/30/ewallet-7-0-updates-and-answers/</link>
		<comments>http://blog.iliumsoft.com/2009/11/30/ewallet-7-0-updates-and-answers/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 16:11:47 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
				<category><![CDATA[BlackBerry]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Our Products]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech Support and Customer Service]]></category>
		<category><![CDATA[iPhone, iPad and iPod touch]]></category>

		<guid isPermaLink="false">http://blog.iliumsoft.com/?p=1762</guid>
		<description><![CDATA[I&#8217;m in the middle of a major software release right now so I&#8217;ll make this quick. I apologize that I can&#8217;t respond to all your comments individually, but considering how many of them there are, that simply isn&#8217;t possible. So &#8211; let&#8217;s get started&#8230;
Thanks!
First let me say thanks to everyone who posted their support. We [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-medium wp-image-1773" title="eWallet2" src="http://blog.iliumsoft.com/wp-content/uploads/2009/11/eWallet2-300x272.jpg" alt="eWallet2" width="180" height="163" />I&#8217;m in the middle of a major software release right now so I&#8217;ll make this quick. I apologize that I can&#8217;t respond to all your comments individually, but considering how many of them there are, that simply isn&#8217;t possible. So &#8211; let&#8217;s get started&#8230;</p>
<p><strong>Thanks!</strong><br />
First let me say thanks to everyone who posted their support. We really appreciate it and we are working very hard to live up to your expectations. The new release is a pretty big deal and I think you&#8217;ll all like it. In fact I think you&#8217;ll REALLY like it. So thanks for your kind words and we hope you like eWallet 7.0!</p>
<p><strong>eWallet 7.0 Will Be Out Tuesday</strong><br />
eWallet 7.0 will be out tomorrow morning. This was the planned release date all along and we&#8217;re sticking to it.</p>
<p>More after the jump!</p>
<p><span id="more-1762"></span></p>
<p><strong>Why Did iPhone Come Out First?</strong><br />
Ask Apple! Our last update took 4 weeks to get approved. This one? 4 days. Seriously. We wanted them to come out pretty close (or at least have the desktop version out first) and we thought our timing was pretty good but once again Apple proved us wrong. What can I tell you &#8211; we&#8217;re at their mercy on this and we have absolutely zero control over when they release our software. It sucks. They should let us choose a date to go live once they approve it.</p>
<p><strong>I Have to Pay to Upgrade?</strong><br />
As it says in the update notes for iPhone version, the upgrade to eWallet 7.0 on desktop may be a paid upgrade if you purchased more than 90 days ago. The price is going to be our usual $10.00 upgrade price, but with this release you’re getting something extra as well. More on that tomorrow.</p>
<p><strong>I Don’t Want to Pay to Upgrade!</strong><br />
If you don’t want to upgrade, then you don’t have to. We’ll continue to support our previous versions just like we always have. Heck – we’ve got a couple of eWallet 2.0 users we still take calls from now and then. So if you fall outside the 90 days and you don’t want to pay to upgrade, feel free to keep using the previous version.</p>
<p><strong>I Already Upgraded My iPhone and Don’t Want to Pay to Upgrade!</strong><br />
<span style="text-decoration: line-through;">I’m sorry. We made it extremely clear in the upgrade information that you may be required to purchase an upgrade to the desktop version. I’m very sorry if you didn’t read that before you upgraded. Update information really is very important and worth reading.</span></p>
<p><span style="text-decoration: line-through;">Although Apple doesn’t provide you with any way to backup to an older version (although they should) there are some work-arounds out there in google searches. Here is one that Pierre posted in the blog comments here:</span></p>
<blockquote><p><span style="text-decoration: line-through;">You can revert back to your iPhone e-wallet version 6. You need to look at your Recycle bin and check for ewallet.ipa. It should be 2.8meg. Delete your version 7 in iphone and itune. Double click ewallet.ipa and reconfigure sync. Back to normal.</span></p></blockquote>
<p><span style="text-decoration: line-through;">Keep in mind that this is a non-supported function. I can make no promises about how well this will work.</span></p>
<p><strong>UPDATE</strong>:<em> OK, so in talking to folks we discovered that our perfectly clear message was anything but. In fact it was a bit misleading. Please check out the NEXT blog post for an update on that &#8211; we&#8217;re working very hard on a solution to help out folks who are having trouble now or who don&#8217;t want to upgrade. Again, sorry about that!</em></p>
<p><strong>Just Send Me the Old Version<br />
</strong>If I send you the old version today, we&#8217;ll be kicked off the AppStore tomorrow and there won&#8217;t be an eWallet for iPhone. Apple won&#8217;t let us do that. Period. In fact they don&#8217;t even give us a way to get software onto your device outside of iTunes.</p>
<p><strong>You Shouldn’t Charge For Upgrades!</strong><br />
Not charging is not a sustainable business model for a product like eWallet. New sales alone don’t cover the costs for development of major changes in functionality. We have to charge for upgrades.</p>
<p><strong>You Should Have &lt;Insert Comment&gt;</strong><br />
There was lots of advice in the blog comments. Some constructive &#8211; some not. I can’t answer all of them here but we thought &#8211; carefully &#8211; through pretty much every idea you posted. For any number of reasons they wouldn’t work, with reasons ranging from the limits of the AppStore to economic suicide. We truly did choose what we believed was the best possible path for this process in an environment where we have less and less control over that very same process.</p>
<p><strong>Mac? Mac? MAC!!??</strong><br />
I&#8217;ve got something for you &#8211; not <em>exactly</em> what you&#8217;re expecting but I think you&#8217;ll like it! Check back tomorrow!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.iliumsoft.com/2009/11/30/ewallet-7-0-updates-and-answers/feed/</wfw:commentRss>
		<slash:comments>43</slash:comments>
		</item>
		<item>
		<title>No, Bob. &#8220;Password&#8221; Isn&#8217;t a Good One.</title>
		<link>http://blog.iliumsoft.com/2009/07/16/no-bob-password-isnt-a-good-one/</link>
		<comments>http://blog.iliumsoft.com/2009/07/16/no-bob-password-isnt-a-good-one/#comments</comments>
		<pubDate>Thu, 16 Jul 2009 14:04:30 +0000</pubDate>
		<dc:creator>Ellen</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.iliumsoft.com/?p=1435</guid>
		<description><![CDATA[Hi Twitter Management,
Correction: This post was originally meant to be tongue-in-cheek, where we would offer Twitter employees a free copy of eWallet to keep track of their passwords. It&#8217;s not an offer for the general public. 
It looks like you&#8217;re having a little problem with your passwords. I know you know that using &#8220;password&#8221; isn&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p><img class="postimage" title="oops" src="http://blog.iliumsoft.com/wp-content/uploads/2009/07/oops.jpg" alt="oops" hspace="12" vspace="6" width="191" height="131" align="left" />Hi Twitter Management,</p>
<p><strong>Correction: This post was originally meant to be tongue-in-cheek, where we would offer Twitter employees a free copy of eWallet to keep track of their passwords. It&#8217;s not an offer for the general public. </strong></p>
<p><a href="http://www.techcrunch.com/2009/07/15/another-security-tip-for-twitter-dont-use-password-as-your-password/">It looks like you&#8217;re having a little problem with your passwords.</a> I know <em>you know </em>that using &#8220;password&#8221; isn&#8217;t a good idea, but I imagine you&#8217;ve all probably been pretty busy lately.</p>
<p>We&#8217;ve got this program called <a href="http://www.iliumsoft.com/site/ew/ewallet.php">eWallet</a> &#8211; you may have heard of it. It not only lets you store passwords safely so that you don&#8217;t have to pick the ones anyone can remember &#8211; and hack &#8211; but it also has a built-in password generator so you don&#8217;t even have to think of one. It&#8217;s network compatible, so your trusted employees (though you might want to rethink them as well, from what I&#8217;ve been reading) can all use it, and it&#8217;s compatible with iPhone, iPod Touch, Blackberry and Windows Mobile phones.</p>
<p>I&#8217;d be happy to give you a copy! No charge &#8211; consider it thanks for giving us all yet another way to feed our internet addictions. Just <a href="http://www.iliumsoft.com/site/support/kb/contact.php">get in touch with our Customer Service</a> guys, and we&#8217;ll get you your copy.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.iliumsoft.com/2009/07/16/no-bob-password-isnt-a-good-one/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Most People Wouldn&#8217;t Call These Mothers&#8217; Day Videos</title>
		<link>http://blog.iliumsoft.com/2008/05/09/most-people-wouldnt-call-these-mothers-day-videos/</link>
		<comments>http://blog.iliumsoft.com/2008/05/09/most-people-wouldnt-call-these-mothers-day-videos/#comments</comments>
		<pubDate>Fri, 09 May 2008 15:18:46 +0000</pubDate>
		<dc:creator>Ellen</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.iliumsoft.com/?p=342</guid>
		<description><![CDATA[Even the FTC is getting into the video act. They&#8217;ve released videos about phishing, identity theft, and protecting personal information on YouTube. I&#8217;ll admit I only watched the short ones, but they were pretty good. 
I&#8217;m guessing that everyone who reads this blog knows all this already, but I&#8217;m also guessing that everyone who reads [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://blog.iliumsoft.com/wp-content/uploads/2008/05/phish.gif" alt="" title="phish" width="105" height="88" class="postimage" align="left" />Even the FTC is getting into the video act. They&#8217;ve released <a href="http://youtube.com/ftcvideos">videos about phishing, identity theft, and protecting personal information</a> on YouTube. I&#8217;ll admit I only watched the short ones, but they were pretty good. </p>
<p>I&#8217;m guessing that everyone who reads this blog knows all this already, but I&#8217;m also guessing that everyone who reads this blog knows someone who could use a reminder. I&#8217;m very careful what I click on, but I know too many people who forget, or just don&#8217;t realize, that what looks like a very, very legitimate email might not be. </p>
<p>Most people wouldn&#8217;t call these Mothers&#8217; Day videos, but if watching and remembering one of these videos makes someone&#8217;s mother stop and think before she clicks a link in an email, it will be worth a lot more than flowers.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.iliumsoft.com/2008/05/09/most-people-wouldnt-call-these-mothers-day-videos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Monday* Morning Mobile Miscellany</title>
		<link>http://blog.iliumsoft.com/2008/02/05/monday-morning-mobile-miscellany/</link>
		<comments>http://blog.iliumsoft.com/2008/02/05/monday-morning-mobile-miscellany/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 14:00:58 +0000</pubDate>
		<dc:creator>Ellen</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Handheld and Mobile World]]></category>
		<category><![CDATA[Our Company & Staff]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software in General]]></category>

		<guid isPermaLink="false">http://blog.iliumsoft.com/?p=287</guid>
		<description><![CDATA[*(I wrote this Monday. I&#8217;m publishing it Tuesday because we updated our blog software yesterday, and couldn&#8217;t publish new articles.)
A few related posts and articles I found interesting this morning:

Users&#8217; Bad Habits Invite Malware, Forum Says. I have very mixed feelings about this. I&#8217;m a huge fan of being careful. I drown boxes of old [...]]]></description>
			<content:encoded><![CDATA[<p><img class="postimage" align="left" src='http://blog.iliumsoft.com/wp-content/uploads/2008/02/cal.gif' alt='cal.gif' />*(I wrote this Monday. I&#8217;m publishing it Tuesday because we <a href="http://blog.iliumsoft.com/?p=286">updated our blog software yesterday</a>, and couldn&#8217;t publish new articles.)</p>
<p>A few related posts and articles I found interesting this morning:</p>
<p><span id="more-287"></span><br />
<a href="http://news.yahoo.com/s/pcworld/20080203/tc_pcworld/142125">Users&#8217; Bad Habits Invite Malware, Forum Says</a>. I have very mixed feelings about this. I&#8217;m a huge fan of being careful. I drown boxes of old business cards rather than just throwing them out, shred <em>everything</em> with anyone&#8217;s info on it, even things like holiday cards, and have told my favorite aunt she&#8217;s not allowed to send me email until she learns the difference between CC: and BCC:. But I&#8217;m not a fan at all of the &#8220;blame the users&#8221; approach to problems, which I think is much too prevalent among technical people. Yes, people are afraid of change, as the article says, but with good reason. Who hasn&#8217;t installed or upgraded some software, only to find their PC not working as well, or not working at all? And who believes that even the most conscientious use of security software and techniques is going to stop all the malware? Not me.</p>
<p>People should practice good security &#8211; absolutely. But that alone isn&#8217;t going to be enough. The internet infrastructure, particularly email, has to change. And I&#8217;d love to see installed software behaving a lot better as well.</p>
<p>But speaking of practicing good security, Marc sent me a fun page describing why <a href="http://ww2.umflint.edu/its/helpdesk/security/passwords/">Passwords are like Underwear</a>. I particularly liked the illustrations. Maybe I&#8217;ll send it to my aunt.</p>
<p>And, finally, getting back to mobile, Tariq at <a href="http://www.etenblog.com/2008/02/02/developer-series-part-i/">Eten Blog dot Com</a> is publishing a very in-depth interview he did with representatives of a few of the major mobile developers. The interview will be published in 4 parts (it&#8217;s long) &#8211; the first one is online  <a href="http://www.etenblog.com/2008/02/02/developer-series-part-i/">here</a>. Check it out if you&#8217;re interested! </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.iliumsoft.com/2008/02/05/monday-morning-mobile-miscellany/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Aplogies to Our Loyal Readers</title>
		<link>http://blog.iliumsoft.com/2008/02/05/aplogies-to-our-loyal-readers/</link>
		<comments>http://blog.iliumsoft.com/2008/02/05/aplogies-to-our-loyal-readers/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 13:56:25 +0000</pubDate>
		<dc:creator>Ellen</dc:creator>
				<category><![CDATA[Our Company & Staff]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.iliumsoft.com/?p=286</guid>
		<description><![CDATA[If you subscribe to the comments feed on this blog, or read them online, and have been seeing a lot of spam among them recently, we apologize! Somehow, our filter plug-in got disabled. We&#8217;ve fixed it now, and are in the process of upgrading our WordPress installation to get the very latest in security. Thanks [...]]]></description>
			<content:encoded><![CDATA[<p>If you subscribe to the comments feed on this blog, or read them online, and have been seeing a lot of spam among them recently, we apologize! Somehow, our filter plug-in got disabled. We&#8217;ve fixed it now, and are in the process of upgrading our WordPress installation to get the very latest in security. Thanks to everyone who wrote us about the problem, and I hope it won&#8217;t happen again.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.iliumsoft.com/2008/02/05/aplogies-to-our-loyal-readers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>You Can&#8217;t Be Too Rich, Too Thin, or Too Careful</title>
		<link>http://blog.iliumsoft.com/2007/12/03/you-cant-be-too-rich-too-thin-or-too-careful/</link>
		<comments>http://blog.iliumsoft.com/2007/12/03/you-cant-be-too-rich-too-thin-or-too-careful/#comments</comments>
		<pubDate>Mon, 03 Dec 2007 14:49:16 +0000</pubDate>
		<dc:creator>Ellen</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.iliumsoft.com/?p=263</guid>
		<description><![CDATA[More and more, I realize you really can&#8217;t be too careful.
I got an email this morning, looking like it was from PayPal, telling me to login to my account and update my information. I have enough experience to know what to look for before hitting any link, and also to know what kinds of emails [...]]]></description>
			<content:encoded><![CDATA[<p>More and more, I realize you really can&#8217;t be too careful.</p>
<p>I got an email this morning, looking like it was from PayPal, telling me to login to my account and update my information. I have enough experience to know what to look for before hitting any link, and also to know what kinds of emails to be suspicious of in general, but I also know that a lot of people don&#8217;t. I used to think things like the personal images and extra security questions were overkill, but I&#8217;ve changed my mind. I&#8217;m taking security a lot more seriously now, because some of the tricks the bad guys are pulling are pretty impressive.</p>
<p>I&#8217;d bet that people who read this blog (and thanks for reading it; I really like being able to just &#8220;think out loud&#8221; on my PC and call it working) are pretty careful and knowledgeable too, but I&#8217;d also bet that everyone has at least one friend or relative who&#8217;d read an email like the one I got today and click that link that looks legitimate. So if you know someone like that, this would be a great time to remind them that emails aren&#8217;t necessarily from who they say they&#8217;re from. And that links don&#8217;t necessarily go to the site in their text.</p>
<p>And now back to figuring out how to get rich and thin.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.iliumsoft.com/2007/12/03/you-cant-be-too-rich-too-thin-or-too-careful/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Information Security</title>
		<link>http://blog.iliumsoft.com/2007/11/07/information-security/</link>
		<comments>http://blog.iliumsoft.com/2007/11/07/information-security/#comments</comments>
		<pubDate>Wed, 07 Nov 2007 14:20:58 +0000</pubDate>
		<dc:creator>Ellen</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.iliumsoft.com/?p=255</guid>
		<description><![CDATA[I&#8217;m thinking a lot about information security lately. Not because we develop and sell eWallet, but because of two things that have happened recently:
Our office was broken into. Nothing but one laptop was taken (and it was just used for testing, so had no valuable info on it, plus was password-protected). We think that our [...]]]></description>
			<content:encoded><![CDATA[<p><img align='left' class="postimage" src='http://blog.iliumsoft.com/wp-content/uploads/2007/11/police.jpg' alt='police.jpg' />I&#8217;m thinking a lot about information security lately. Not because we develop and sell eWallet, but because of two things that have happened recently:</p>
<p>Our office was broken into. Nothing but one laptop was taken (and it was just used for testing, so had no valuable info on it, plus was password-protected). We think that our alarm scared the person or people away, and they just took the nearest good-looking piece of equipment. While we&#8217;re all feeling a little rattled by the thought that someone was in our office, we&#8217;re also very aware it could have been much worse. </p>
<p>We stopped keeping the credit card numbers we get for sales several years ago, and are very careful to protect any confidential info &#8211; whether users&#8217; email addresses or our own credit card numbers and passwords &#8211; on any of our PCs, so I know that anyone getting any of our equipment wouldn&#8217;t be able to get any useful information. And I know we&#8217;re good about keeping offsite backups of all the corporate and customer info. I hope we&#8217;re also good about keeping offsite backups of our own PCs, but I know at least I don&#8217;t do that every day. But we&#8217;d lose weeks of work if we all had to get new PCs and set them up. I&#8217;m not sure that 5-year-old PCs (mine&#8217;s at least that old) are even worth taking, but I hope I never find out.</p>
<p>The other thing that&#8217;s happened is that as part of two banks I use being acquired, I&#8217;m kicking off a long-postponed personal financial reorganization. Wow &#8211; there&#8217;s a <strong>lot</strong> of info to enter and keep with new bank accounts. Online security is a lot better than it used to be, which I&#8217;m very glad about. But it&#8217;s clear that no matter how excellent my memory is, there&#8217;s no way I could be without a good wallet program. And being able to enter free-form info &#8211; like my third boyfriend&#8217;s pet&#8217;s name, or the street my high school was on &#8211; is a lot more critical than it was when we first added the Notes fields to eWallet cards. </p>
<p>Anyway, I&#8217;m glad the banks are looking out for me, and I&#8217;m glad there&#8217;s good enough software that I can manage everything I need to. And I&#8217;m really glad we got an alarm when we moved into this office (we&#8217;d always planned to with the previous one, but never got around to it). It&#8217;s too bad we need all that, but since we do, it&#8217;s good that it&#8217;s there.</p>
<p>And, yes, I&#8217;m thinking a lot about mobile technology too, especially with all the new announcements lately. I just don&#8217;t have anything to say about it &#8211; yet &#8211; that hasn&#8217;t been said by many other people.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.iliumsoft.com/2007/11/07/information-security/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

