<?xml version="1.0"?>
<rss version="2.0">
<channel>
  <title>IT Risk Space - Risk Management category</title>
  <link>http://itriskspace.com/categories/riskmanagement/</link>
  <description>From Reverse Engineer to CIO, we want to enlighten you all!</description>
  <language>en</language>
  <copyright>Daria, Igor and Andreas</copyright>
  <lastBuildDate>Sat, 09 Jan 2010 11:39:00 GMT</lastBuildDate>
  <generator>Pebble (http://pebble.sourceforge.net)</generator>
  <docs>http://backend.userland.com/rss</docs>
  
  
  <item>
    <title>Is Mobile Telephony via GSM still Secure enough? </title>
    <link>http://itriskspace.com/2010/01/09/1263037140000.html</link>
    
      
      
        <description>
          &lt;link rel=&#034;File-List&#034; href=&#034;file://localhost/Users/andreaswuchner/Library/Caches/TemporaryItems/msoclip/0/clip_filelist.xml&#034; /&gt; &lt;!--[if gte mso 9]&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 
  0
  false
  
  
  18 pt
  18 pt
  0
  0
  
  false
  false
  false
  
   
   
   
   
  
 
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;![endif]--&gt; &lt;style type=&#034;text/css&#034;&gt;
&lt;!--
 /* Font Definitions */
@font-face
	{
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{
	panose-1:2 4 5 3 5 4 6 3 2 4;}
 /* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-parent:&#034;&#034;;
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:12.0pt;&#034;Times New Roman&#034;;
	mso-bidi-&#034;Times New Roman&#034;;}
@page Section1
	{size:612.0pt 792.0pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.Section1
	{page:Section1;}
--&gt;
&lt;/style&gt; &lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
table.MsoNormalTable
	{mso-style-name:&#034;Table Normal&#034;;
	mso-style-parent:&#034;&#034;;
	font-size:12.0pt;&#034;Times New Roman&#034;;
	mso-fareast-&#034;Times New Roman&#034;;}
&lt;/style&gt;
&lt;![endif]--&gt;  &lt;!--StartFragment--&gt;
&lt;p&gt;&lt;span style=&#034;color: black;&#034;&gt;As all of you most probably have heard of, on 28th of December 2009 a German computer engineer announced at the CCC in Berlin that he had cracked the A5/1 cipher used in GSM communication. This would mean that someone could eavesdrop on confidential information exchanged via a cell phone. &lt;br /&gt;
&lt;br /&gt;
I have asked my Cryptography Competence Center around Prof. B. Esslinger to analyzed the risk and to provide a security report with further details and recommendations, which you can find below.&amp;nbsp; More information about the work of Prof. Esslinger and the open source crypto community can be found on the project page at &lt;a href=&#034;http://www.cryptool.org/index.php/en.html&#034;&gt;http://www.cryptool.org/index.php/en.html&lt;/a&gt;&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
Currently, we see the risk still as acceptable and from a technical point of view, the situation is under control. However, this might change very soon and therefore this risk area must be continuously monitored.&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
NOTE: In general, phones, especially cell phones and cordless phones, shall not be considered as secure communication devices. For business areas with high confidentiality requirements, the usage of encrypted mobile phones is strongly recommended. &lt;br /&gt;
&lt;br /&gt;
I really like the report and therefore I wanted to share with all of you as you may have the same questions or requirements in your area of responsibility.&lt;br /&gt;
&lt;br /&gt;
Cheers&lt;br /&gt;
-Andreas&lt;/span&gt;&lt;/p&gt;
&lt;!--EndFragment--&gt;&lt;p&gt;&lt;a href=&#034;http://itriskspace.com/2010/01/09/1263037140000.html&#034;&gt;Read full article&lt;/a&gt;&lt;/p&gt;
        </description>
      
    
    
    
    <category>Risk Management</category>
    
    <category>Newsflash</category>
    
    <comments>http://itriskspace.com/2010/01/09/1263037140000.html#comments</comments>
    <guid isPermaLink="true">http://itriskspace.com/2010/01/09/1263037140000.html</guid>
    <pubDate>Sat, 09 Jan 2010 11:39:00 GMT</pubDate>
  </item>
  
  <item>
    <title>Open-Source project jeopardizes banking with mobile devices</title>
    <link>http://itriskspace.com/2009/09/25/1253891160000.html</link>
    
      
      
        <description>
          In August 2009 Karsten Nohl introduced his GSM Open-Source project @ HAR 2009 (Hacking at Random http://har2009.org) in the Netherlands. In his speech &amp;ldquo;Subverting the security base of GSM&amp;rdquo; he and Sascha Krissler explained the weaknesses of the standard encryption method A5/1 used globally around the world within the GSM networks. More details can be found within the full story.&lt;br /&gt;
&lt;br /&gt;
Enjoy&lt;br /&gt;
-Andreas&lt;p&gt;&lt;a href=&#034;http://itriskspace.com/2009/09/25/1253891160000.html&#034;&gt;Read full article&lt;/a&gt;&lt;/p&gt;
        </description>
      
    
    
    
    <category>Risk Management</category>
    
    <category>Software</category>
    
    <category>Malware</category>
    
    <comments>http://itriskspace.com/2009/09/25/1253891160000.html#comments</comments>
    <guid isPermaLink="true">http://itriskspace.com/2009/09/25/1253891160000.html</guid>
    <pubDate>Fri, 25 Sep 2009 15:06:00 GMT</pubDate>
  </item>
  
  <item>
    <title>Information Operations</title>
    <link>http://itriskspace.com/2009/08/17/1250538120000.html</link>
    
      
      
        <description>
          During economic crisis we would like to provide you with some awareness information around information operations.&lt;br /&gt;
&lt;br /&gt;
The following article has been written by Martin Rutishauser, MAS Information Security and Security Engineer at Ispin AG.&lt;br /&gt;
&lt;br /&gt;
Martin and I have studied together at the University of Applied Sciences in Lucerne and are good friends since, both being IT-Security enthusiastics.&lt;br /&gt;
&lt;br /&gt;
Martin is mainly working around the subjects penetration testing, forensics and information operations.&lt;br /&gt;
&lt;br /&gt;
At this point I would like to thank Martin for taking time to write this article, which might be an eye opener to some.&lt;p&gt;&lt;a href=&#034;http://itriskspace.com/2009/08/17/1250538120000.html&#034;&gt;Read full article&lt;/a&gt;&lt;/p&gt;
        </description>
      
    
    
    
    <category>Risk Management</category>
    
    <category>Privacy</category>
    
    <comments>http://itriskspace.com/2009/08/17/1250538120000.html#comments</comments>
    <guid isPermaLink="true">http://itriskspace.com/2009/08/17/1250538120000.html</guid>
    <pubDate>Mon, 17 Aug 2009 19:42:00 GMT</pubDate>
  </item>
  
  </channel>
</rss>
