<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Holy Hash!</title>
		<link>https://holyhash.com/en/</link>
		<description>Recent content on Holy Hash!</description>
		<generator>Hugo</generator>
		<language>en-US</language>
		
		
		
		
			<lastBuildDate>Sun, 29 Mar 2026 05:10:43 +0000</lastBuildDate>
		
			<atom:link href="https://holyhash.com/en/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>On the use of LLM (“AI”) in security decisions</title>
				<link>https://holyhash.com/2026/03/29/on-the-use-of-llm-ai-in-security-decisions/</link>
				<pubDate>Sun, 29 Mar 2026 05:10:42 +0000</pubDate>
				<guid>https://holyhash.com/2026/03/29/on-the-use-of-llm-ai-in-security-decisions/</guid>
				<description>&lt;p&gt;What will happen if we keep using Large Language Models as the basis of decisions, especially in a field like security? Would taking the statistically average decision from this moment on, at every step, lead to a decay of decision correctness over time, or would it stay stable?&lt;/p&gt;&#xA;&lt;p&gt;The question sits at the intersection of decision theory, statistics, and ergodicity. The short answer is: decay, almost inevitably, and for several reinforcing reasons.&lt;/p&gt;</description>
			</item>
			<item>
				<title>AI Software Design Security and Language Choice</title>
				<link>https://holyhash.com/2025/11/30/ai-software-design-security-and-language-choice/</link>
				<pubDate>Sun, 30 Nov 2025 14:28:18 +0000</pubDate>
				<guid>https://holyhash.com/2025/11/30/ai-software-design-security-and-language-choice/</guid>
				<description>&lt;p&gt;Or, rather, the quality of the Artificial Intelligence (AI) generated software in general but it goes for security as well, naturally, since security and quality are but the two sides of the same coin. Software engineers happily embraced the wonderful possibility of being able to program in a natural language &amp;#8211; describing the task to an agent that uses a Large Language Model (LLM) to produce the actual code. The question I want to look into today is the choice of the programming language for such endeavours.&lt;/p&gt;</description>
			</item>
			<item>
				<title>CAST workshop on development security</title>
				<link>https://holyhash.com/2018/03/13/cast-workshop-on-development-security/</link>
				<pubDate>Tue, 13 Mar 2018 08:00:45 +0000</pubDate>
				<guid>https://holyhash.com/2018/03/13/cast-workshop-on-development-security/</guid>
				<description>&lt;p&gt;&lt;a href=&#34;https://holyhash.com/media/2018/03/cloud_security.png&#34;&gt;&lt;img fetchpriority=&#34;high&#34; decoding=&#34;async&#34; class=&#34;alignright size-medium wp-image-1064&#34; src=&#34;https://holyhash.com/media/2018/03/cloud_security-300x200.png&#34; alt=&#34;&#34; width=&#34;300&#34; height=&#34;200&#34; srcset=&#34;https://holyhash.com/media/2018/03/cloud_security-300x200.png 300w, https://holyhash.com/media/2018/03/cloud_security-400x267.png 400w, https://holyhash.com/media/2018/03/cloud_security.png 600w&#34; sizes=&#34;(max-width: 300px) 100vw, 300px&#34; /&gt;&lt;/a&gt;We are holding our yearly security conference in Darmstadt on the 22nd of March &amp;#8211; that&amp;#8217;s next week &amp;#8211; together with our partners from Fraunhofer SIT and CAST. This time, the focus subject will be DevOps and cloud technologies, including both operations and development preparation for the security in the cloud. The speakers are prepared to talk about a range of things from threat modeling and management down to massive tests, so I expect it will be rather interesting. We will also have a couple of presentations from companies talking about how they do things in their own cloud software in practice, so it will not be all theory either.&lt;/p&gt;</description>
			</item>
			<item>
				<title>A company with an SQL injection name</title>
				<link>https://holyhash.com/2017/01/19/a-company-with-an-sql-injection-name/</link>
				<pubDate>Thu, 19 Jan 2017 15:00:28 +0000</pubDate>
				<guid>https://holyhash.com/2017/01/19/a-company-with-an-sql-injection-name/</guid>
				<description>&lt;p&gt;Finally, someone registered a company that is an SQL injection attack. We saw the license plates on cars doctored to execute SQL injection attacks but this is the first time, I think, that an attempt to crash all business SQL databases in a country is made.&lt;/p&gt;&#xA;&lt;p&gt;The company name is: ; &lt;strong&gt;DROP TABLE &amp;#8220;COMPANIES&amp;#8221;;&amp;#8211; LTD&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The registration record: &lt;a href=&#34;https://beta.companieshouse.gov.uk/company/10542519&#34;&gt;https://beta.companieshouse.gov.uk/company/10542519&lt;/a&gt;&lt;/p&gt;&#xA;&lt;div id=&#34;attachment_1059&#34; style=&#34;width: 676px&#34; class=&#34;wp-caption alignnone&#34;&gt;&lt;a href=&#34;https://www.explainxkcd.com/wiki/index.php/Little_Bobby_Tables&#34;&gt;&lt;img fetchpriority=&#34;high&#34; decoding=&#34;async&#34; aria-describedby=&#34;caption-attachment-1059&#34; class=&#34;size-full wp-image-1059&#34; src=&#34;https://holyhash.com/media/2017/01/exploits_of_a_mom.png&#34; alt=&#34;&#34; width=&#34;666&#34; height=&#34;205&#34; srcset=&#34;https://holyhash.com/media/2017/01/exploits_of_a_mom.png 666w, https://holyhash.com/media/2017/01/exploits_of_a_mom-300x92.png 300w, https://holyhash.com/media/2017/01/exploits_of_a_mom-400x123.png 400w, https://holyhash.com/media/2017/01/exploits_of_a_mom-650x200.png 650w&#34; sizes=&#34;(max-width: 666px) 100vw, 666px&#34; /&gt;&lt;/a&gt;&lt;p id=&#34;caption-attachment-1059&#34; class=&#34;wp-caption-text&#34;&gt;XKCD cartoon &amp;#8220;Exploits of a mom&amp;#8221;&lt;/p&gt;</description>
			</item>
			<item>
				<title>Don’t patch it, it’s fine?</title>
				<link>https://holyhash.com/2016/11/17/dont-patch-it-its-fine/</link>
				<pubDate>Thu, 17 Nov 2016 15:00:45 +0000</pubDate>
				<guid>https://holyhash.com/2016/11/17/dont-patch-it-its-fine/</guid>
				<description>&lt;p&gt;I wrote back in 2013 about my shock at discovering that the companies are now publicly calling to stop the investment in security and avoid fixing security bugs in my article &lt;a href=&#34;https://holyhash.com/455/brainwashing-in-security/&#34;&gt;Brainwashing in security&lt;/a&gt;. There, we witnessed the head of Adobe security, Brad Arkin, tell us that the companies should not be wasting their precious resources on &amp;#8220;fixing every little bug&amp;#8221;, agreeing to the comment made by another participant, John Viega from SilverSky, that:&lt;/p&gt;</description>
			</item>
			<item>
				<title>Data breach at LinkedIn</title>
				<link>https://holyhash.com/2016/05/26/data-breach-at-linkedin/</link>
				<pubDate>Thu, 26 May 2016 09:30:28 +0000</pubDate>
				<guid>https://holyhash.com/2016/05/26/data-breach-at-linkedin/</guid>
				<description>&lt;p&gt;&lt;a href=&#34;https://holyhash.com/media/2016/05/linkedin-default-share.png&#34;&gt;&lt;img fetchpriority=&#34;high&#34; decoding=&#34;async&#34; class=&#34;alignright size-medium wp-image-1048&#34; src=&#34;https://holyhash.com/media/2016/05/linkedin-default-share-300x183.png&#34; alt=&#34;linkedin-default-share&#34; width=&#34;300&#34; height=&#34;183&#34; srcset=&#34;https://holyhash.com/media/2016/05/linkedin-default-share-300x183.png 300w, https://holyhash.com/media/2016/05/linkedin-default-share.png 360w&#34; sizes=&#34;(max-width: 300px) 100vw, 300px&#34; /&gt;&lt;/a&gt;Apparently, there was a serious data breach at LinkedIn and many customer records were stolen including &amp;#8220;member email addresses, hashed passwords, and LinkedIn member IDs&amp;#8221;. LinkedIn sent out a notification informing that the passwords were invalidated. What is interesting in the note is that they included a cryptic note that the break-in was &amp;#8220;not new&amp;#8221;. What could they mean by that?&lt;/p&gt;</description>
			</item>
			<item>
				<title>Position yourself on Security Maturity Grid</title>
				<link>https://holyhash.com/2016/02/09/position-yourself-on-security-maturity-grid/</link>
				<pubDate>Tue, 09 Feb 2016 17:00:57 +0000</pubDate>
				<guid>https://holyhash.com/2016/02/09/position-yourself-on-security-maturity-grid/</guid>
				<description>&lt;p&gt;I wrote up the &lt;a href=&#34;https://holyhash.com/security-maturity-grid/&#34;&gt;Security Maturity Grid&lt;/a&gt; the way quality management is usually presented. The grid is a simple 5 x 6 matrix that shows different stages of maturity of the company’s security management against six different security management categories (management understanding of security, problem handling, cost of security, etc). The lowest stage of maturity is called ‘Uncertainty’ – the organisation is inexperienced, security management is a low priority and reactive, etc – then as security management matures it goes through the stages of ‘Awakening’, ‘Enlightenment’, ‘Wisdom’, then the highest level, ‘Certainty’. Each point – maturity versus category – on the grid has a brief description of how that combination appears in the company.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Security Maturity Grid</title>
				<link>https://holyhash.com/security-maturity-grid/</link>
				<pubDate>Tue, 09 Feb 2016 13:00:13 +0000</pubDate>
				<guid>https://holyhash.com/security-maturity-grid/</guid>
				<description>&lt;p&gt;The grid is a simple 5 x 6 matrix that shows different stages of maturity of the company’s security management against six different security management categories (management understanding of security, problem handling, cost of security, etc). The lowest stage of maturity is called ‘Uncertainty’ – the organisation is inexperienced, security management is a low priority and reactive, etc – then as security management matures it goes through the stages of ‘Awakening’, ‘Enlightenment’, ‘Wisdom’, then the highest level, ‘Certainty’. Each point – maturity versus category – on the grid has a brief description of how that combination appears in the company.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Worst languages for software security</title>
				<link>https://holyhash.com/2016/01/19/worst-languages-for-software-security/</link>
				<pubDate>Tue, 19 Jan 2016 15:00:48 +0000</pubDate>
				<guid>https://holyhash.com/2016/01/19/worst-languages-for-software-security/</guid>
				<description>&lt;p&gt;I was sent an article about program languages that generate most security bugs in software today. The article seemed to refer to a report by Veracode, a company I know well, to discuss what software security problems are out there in applications written in different languages. That is an excellent question and a very interesting subject for a discussion. Except that the article really failed to discuss anything, making instead misleading and incoherent statements about both old-school lnguages like C/C++ and the PHP scripting. I fear we will have to look into this problem ourselves then instead.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Backdoors in encryption products</title>
				<link>https://holyhash.com/2015/12/15/backdoors-in-encryption-products/</link>
				<pubDate>Tue, 15 Dec 2015 17:00:37 +0000</pubDate>
				<guid>https://holyhash.com/2015/12/15/backdoors-in-encryption-products/</guid>
				<description>&lt;p&gt;&lt;a href=&#34;https://holyhash.com/media/2015/12/padlock-security-protection-hacking-540x334.jpg&#34; rel=&#34;attachment wp-att-1009&#34;&gt;&lt;img decoding=&#34;async&#34; class=&#34;alignleft size-thumbnail wp-image-1009&#34; src=&#34;https://holyhash.com/media/2015/12/padlock-security-protection-hacking-540x334-150x150.jpg&#34; alt=&#34;padlock-security-protection-hacking-540x334&#34; width=&#34;150&#34; height=&#34;150&#34; srcset=&#34;https://holyhash.com/media/2015/12/padlock-security-protection-hacking-540x334-300x186.jpg 300w, https://holyhash.com/media/2015/12/padlock-security-protection-hacking-540x334-400x247.jpg 400w, https://holyhash.com/media/2015/12/padlock-security-protection-hacking-540x334.jpg 540w&#34; sizes=&#34;(max-width: 150px) 100vw, 150px&#34; /&gt;&lt;/a&gt;After the recent terrorist attacks the governments are again pushing for more surveillance and the old debate on the necessity of the backdoors in encryption software &lt;a href=&#34;http://time.com/4115010/paris-attacks-encryption-surveillance-snowden/&#34;&gt;raises its ugly head again&lt;/a&gt;. Leaving the surveillance question aside, let&amp;#8217;s see, what does it mean to introduce backdoors to programs and how they can be harmful, especially when we are talking security and encryption?&lt;/p&gt;</description>
			</item>
			<item>
				<title>CAST Workshop “Secure Software Development”</title>
				<link>https://holyhash.com/2015/09/21/cast-workshop-secure-software-development/</link>
				<pubDate>Mon, 21 Sep 2015 08:00:02 +0000</pubDate>
				<guid>https://holyhash.com/2015/09/21/cast-workshop-secure-software-development/</guid>
				<description>&lt;p&gt;&lt;a href=&#34;https://holyhash.com/media/2013/10/7033818-3d-abbild-monster-mit-investigate-linse.jpg&#34;&gt;&lt;img decoding=&#34;async&#34; class=&#34;size-full wp-image-555 alignleft&#34; src=&#34;https://holyhash.com/media/2013/10/7033818-3d-abbild-monster-mit-investigate-linse.jpg&#34; alt=&#34;7033818-3d-abbild-monster-mit-investigate-linse&#34; width=&#34;168&#34; height=&#34;168&#34; srcset=&#34;https://holyhash.com/media/2013/10/7033818-3d-abbild-monster-mit-investigate-linse.jpg 168w, https://holyhash.com/media/2013/10/7033818-3d-abbild-monster-mit-investigate-linse-150x150.jpg 150w&#34; sizes=&#34;(max-width: 168px) 100vw, 168px&#34; /&gt;&lt;/a&gt;We are organizing the workshop on &amp;#8220;&lt;a href=&#34;http://www.cast-forum.de/workshops/infos/209&#34;&gt;Secure Software Development&lt;/a&gt;&amp;#8221; now for the third year in a row. As usual, the workshop is in Darmstadt and the logistics is cared for by the CAST e.V. The date for the workshop is 12 November.&lt;/p&gt;&#xA;&lt;p&gt;This year most presentations seem to be in German, so probably it does not make much sense for non-German speaking people. But if you speak German, we have some rather interesting subjects like our experiences with vulnerability management, research into sociotechnical basis of development security and problems with developing the mobile payment infrastructure security.&lt;/p&gt;</description>
			</item>
			<item>
				<title>TrueCrypt Disk Encryption</title>
				<link>https://holyhash.com/truecrypt-disk-encryption/</link>
				<pubDate>Sun, 20 Sep 2015 04:55:05 +0000</pubDate>
				<guid>https://holyhash.com/truecrypt-disk-encryption/</guid>
				<description>&lt;p&gt;&lt;a href=&#34;https://holyhash.com/media/2014/06/truecrypt.jpeg&#34;&gt;&lt;img decoding=&#34;async&#34; class=&#34;alignright size-full wp-image-714&#34; src=&#34;https://holyhash.com/media/2014/06/truecrypt.jpeg&#34; alt=&#34;truecrypt&#34; width=&#34;128&#34; height=&#34;173&#34; /&gt;&lt;/a&gt;The only disk encryption tool that was widely available to the public in source code and &lt;a href=&#34;https://holyhash.com/truecrypt/iSec_Final_Open_Crypto_Audit_Project_TrueCrypt_Security_Assessment.pdf&#34;&gt;was audited&lt;/a&gt; by an independent third-party security laboratory is TrueCrypt. Unfortunately, the authors of TrueCrypt &lt;a href=&#34;http://truecrypt.org&#34;&gt;stopped&lt;/a&gt; the development in May 2015 and proposed an outrageous in its insecurity move to built-in encryption on Windows. Knowing that we do not trust closed source systems, knowing that all large companies collaborate with governments to insert backdoors to their software, knowing that there is a large interest in corporation to subvert user privacy, I suggest you keep to the TrueCrypt. Hopefully someone will step up and continue the development but the good old versions still work and are available here at: &lt;a href=&#34;https://holyhash.com/truecrypt/&#34;&gt;/truecrypt/&lt;/a&gt;. The version audited by iSec Partners is 7.1a and that is the recommended one for the moment.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Windows 10: catching up to Google?</title>
				<link>https://holyhash.com/2015/09/01/windows-10-catching-up-to-google/</link>
				<pubDate>Tue, 01 Sep 2015 23:00:54 +0000</pubDate>
				<guid>https://holyhash.com/2015/09/01/windows-10-catching-up-to-google/</guid>
				<description>&lt;p&gt;&lt;a href=&#34;https://holyhash.com/media/2015/08/windows-10-is-spying-on-every-user-but-theres-a-way-out.jpg&#34;&gt;&lt;img fetchpriority=&#34;high&#34; decoding=&#34;async&#34; class=&#34;alignright size-medium wp-image-962&#34; src=&#34;https://holyhash.com/media/2015/08/windows-10-is-spying-on-every-user-but-theres-a-way-out-300x183.jpg&#34; alt=&#34;windows-10-is-spying-on-every-user-but-theres-a-way-out&#34; width=&#34;300&#34; height=&#34;183&#34; srcset=&#34;https://holyhash.com/media/2015/08/windows-10-is-spying-on-every-user-but-theres-a-way-out-300x183.jpg 300w, https://holyhash.com/media/2015/08/windows-10-is-spying-on-every-user-but-theres-a-way-out-400x244.jpg 400w, https://holyhash.com/media/2015/08/windows-10-is-spying-on-every-user-but-theres-a-way-out.jpg 640w&#34; sizes=&#34;(max-width: 300px) 100vw, 300px&#34; /&gt;&lt;/a&gt;Windows 10 has turned out to be a very interesting update to the popular desktop operating system. Apparently, Microsoft envies Google for their success in spying on everyone and their dog through the Internet. Accordingly, Microsoft could not resist turning Windows into a mean spying machine. People were mightily surprised when all of the new spying features of Windows started to get uncovered.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Continue the TrueCrypt discussion: Windows 10</title>
				<link>https://holyhash.com/2015/08/21/continue-the-truecrypt-discussion-windows-10/</link>
				<pubDate>Fri, 21 Aug 2015 06:30:56 +0000</pubDate>
				<guid>https://holyhash.com/2015/08/21/continue-the-truecrypt-discussion-windows-10/</guid>
				<description>&lt;p&gt;I already pointed out previously that I do not see any alternative to the TrueCrypt for encrypting data on disk. TrueCrypt is the only tool that we can more or less trust so far. You will probably remember that Bruce Schneier recommended to use Windows encryption, the BitLocker, instead of TrueCrypt and I called that idea &lt;a href=&#34;https://holyhash.com/955/truecrypt/&#34;&gt;nonsense&lt;/a&gt;. To prove me right, here comes the Windows 10 End User License Agreement (EULA) that states explicitly Microsoft will retain the keys to the encryption.&lt;/p&gt;</description>
			</item>
			<item>
				<title>TrueCrypt</title>
				<link>https://holyhash.com/2015/06/16/truecrypt/</link>
				<pubDate>Tue, 16 Jun 2015 17:00:56 +0000</pubDate>
				<guid>https://holyhash.com/2015/06/16/truecrypt/</guid>
				<description>&lt;p&gt;&lt;a href=&#34;https://holyhash.com/media/2015/06/truecrypt.jpeg&#34;&gt;&lt;img decoding=&#34;async&#34; class=&#34;alignright size-full wp-image-956&#34; src=&#34;https://holyhash.com/media/2015/06/truecrypt.jpeg&#34; alt=&#34;truecrypt&#34; width=&#34;128&#34; height=&#34;173&#34; /&gt;&lt;/a&gt;Since the anonymous team behind TrueCrypt has &lt;a href=&#34;https://holyhash.com/711/truecrypt-disappears/&#34;&gt;left the building&lt;/a&gt;, security aware people were left wondering what&amp;#8217;s next. I personally keep using TrueCrypt and as long as it works I will keep recommending it.&lt;/p&gt;&#xA;&lt;p&gt;Recently, Bruce Schneier has raised a few red flags by his strange advice that seems to indicate that he is being paid now for his &amp;#8220;services to the community&amp;#8221; by parties not so interested in keeping the community secure. One more thing is his advice to switch from TrueCrypt to BitLocker.&lt;/p&gt;</description>
			</item>
			<item>
				<title>The human factor: philosophy and engineering</title>
				<link>https://holyhash.com/2015/04/22/the-human-factor-philosophy-and-engineering/</link>
				<pubDate>Wed, 22 Apr 2015 15:00:59 +0000</pubDate>
				<guid>https://holyhash.com/2015/04/22/the-human-factor-philosophy-and-engineering/</guid>
				<description>&lt;p class=&#34;western&#34;&gt;&lt;span lang=&#34;en-US&#34;&gt;The ancient Greeks had a concept of “&lt;/span&gt;&lt;em&gt;&lt;span lang=&#34;en-US&#34;&gt;aretê&lt;/span&gt;&lt;/em&gt;&lt;span lang=&#34;en-US&#34;&gt;” (/ˈærətiː/) that is usually loosely translated to English as “quality”, “excellence”, or “virtue”. It was all that and more: the term meant the ultimate and harmonious fulfillment of task, purpose, function, or even the whole life. Living up to this concept was the highest achievement one could attain in life. Unfortunately, it does not translate well into English where the necessary concept is absent.&lt;/span&gt;&lt;/p&gt;</description>
			</item>
			<item>
				<title>GAO report on cybersecurity in Air Traffic Control is outright scary</title>
				<link>https://holyhash.com/2015/04/17/gao-report-on-cybersecurity-in-air-traffic-control-is-outright-scary/</link>
				<pubDate>Fri, 17 Apr 2015 20:00:50 +0000</pubDate>
				<guid>https://holyhash.com/2015/04/17/gao-report-on-cybersecurity-in-air-traffic-control-is-outright-scary/</guid>
				<description>&lt;p&gt;&lt;a href=&#34;https://holyhash.com/media/2015/04/aircraft-networks.jpg&#34;&gt;&lt;img fetchpriority=&#34;high&#34; decoding=&#34;async&#34; class=&#34;alignright size-medium wp-image-933&#34; src=&#34;https://holyhash.com/media/2015/04/aircraft-networks-300x268.jpg&#34; alt=&#34;aircraft-networks&#34; width=&#34;300&#34; height=&#34;268&#34; srcset=&#34;https://holyhash.com/media/2015/04/aircraft-networks-300x268.jpg 300w, https://holyhash.com/media/2015/04/aircraft-networks-768x687.jpg 768w, https://holyhash.com/media/2015/04/aircraft-networks-1024x916.jpg 1024w, https://holyhash.com/media/2015/04/aircraft-networks-400x358.jpg 400w, https://holyhash.com/media/2015/04/aircraft-networks-650x581.jpg 650w, https://holyhash.com/media/2015/04/aircraft-networks.jpg 1503w&#34; sizes=&#34;(max-width: 300px) 100vw, 300px&#34; /&gt;&lt;/a&gt;The fact that the modern aircraft can be controlled from the ground is not widely publicized but known. There was though a lot of controversy, including among specialists, about how much of control could be intercepted by unauthorized 3rd parties. Well, now the extent of the problem is confirmed officially.&lt;/p&gt;&#xA;&lt;p&gt;The U.S. Government Accountability Office (GAO), which is also called &amp;#8220;watchdog of Congress&amp;#8221;, usually oversees the federal government for the expenditure of public funds. However, the 56-page report &amp;#8220;&lt;a href=&#34;http://www.gao.gov/assets/670/669627.pdf&#34;&gt;Air Traffic Control: FAA Needs a More Comprehensive Approach to Address Cybersecurity As Agency Transitions to&lt;/a&gt; &lt;a href=&#34;http://www.gao.gov/assets/670/669627.pdf&#34;&gt;NextGen&lt;/a&gt;» (&lt;a href=&#34;https://tigr.net/xlink/2015/2015-04-14-gao-669627.pdf&#34;&gt;copy&lt;/a&gt;) published on April 14  tells a very interesting but scary story. For a document that is not classified as &amp;#8220;secret&amp;#8221;, in any case.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Passwords and other secrets in source code</title>
				<link>https://holyhash.com/2015/03/30/passwords-and-other-secrets-in-source-code/</link>
				<pubDate>Mon, 30 Mar 2015 12:00:57 +0000</pubDate>
				<guid>https://holyhash.com/2015/03/30/passwords-and-other-secrets-in-source-code/</guid>
				<description>&lt;p&gt;&lt;a href=&#34;https://holyhash.com/media/2015/03/key-under-mat.jpg&#34;&gt;&lt;img fetchpriority=&#34;high&#34; decoding=&#34;async&#34; class=&#34;alignright size-medium wp-image-922&#34; src=&#34;https://holyhash.com/media/2015/03/key-under-mat-300x225.jpg&#34; alt=&#34;key-under-mat&#34; width=&#34;300&#34; height=&#34;225&#34; srcset=&#34;https://holyhash.com/media/2015/03/key-under-mat-300x225.jpg 300w, https://holyhash.com/media/2015/03/key-under-mat-768x576.jpg 768w, https://holyhash.com/media/2015/03/key-under-mat-400x300.jpg 400w, https://holyhash.com/media/2015/03/key-under-mat-650x488.jpg 650w, https://holyhash.com/media/2015/03/key-under-mat.jpg 1000w&#34; sizes=&#34;(max-width: 300px) 100vw, 300px&#34; /&gt;&lt;/a&gt;Secrets are bad. Secrets in source code are an order of magnitude worse.&lt;/p&gt;&#xA;&lt;p&gt;Secrets are difficult to protect. Every attacker goes after the secrets and we must protect our secrets against all of them. The secrets are the valuable part of our software and that&amp;#8217;s why they are bad &amp;#8211; they represent an area of heightened risk.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Security Forum Hagenberg 2015</title>
				<link>https://holyhash.com/2015/03/29/security-forum-hagenberg-2015/</link>
				<pubDate>Sun, 29 Mar 2015 11:00:26 +0000</pubDate>
				<guid>https://holyhash.com/2015/03/29/security-forum-hagenberg-2015/</guid>
				<description>&lt;p&gt;&lt;a href=&#34;https://holyhash.com/media/2015/01/sf_logo.png&#34;&gt;&lt;img fetchpriority=&#34;high&#34; decoding=&#34;async&#34; class=&#34;alignright size-full wp-image-898&#34; src=&#34;https://holyhash.com/media/2015/01/sf_logo.png&#34; alt=&#34;sf_logo&#34; width=&#34;190&#34; height=&#34;266&#34; /&gt;&lt;/a&gt;I will be talking about the philosophy in engineering or the human factor in the development of secure software at the Security Forum in Hagenberg im Mühlkreis, Austria on 22nd of April.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.securityforum.at/en/&#34;&gt;https://www.securityforum.at/en/&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;My talk will concentrate on the absence of a holistic, systemic approach in the current software development as a result of taking the scientific approach of &amp;#8220;divide and conquer&amp;#8221; a bit too far and applying it where it should not be.&lt;/p&gt;</description>
			</item>
			<item>
				<title>House key versus user authentication</title>
				<link>https://holyhash.com/2015/03/05/house-key-versus-user-authentication/</link>
				<pubDate>Thu, 05 Mar 2015 12:00:32 +0000</pubDate>
				<guid>https://holyhash.com/2015/03/05/house-key-versus-user-authentication/</guid>
				<description>&lt;p&gt;&lt;a href=&#34;https://holyhash.com/media/2015/03/key_gold.jpg&#34;&gt;&lt;img decoding=&#34;async&#34; class=&#34;alignright size-medium wp-image-914&#34; src=&#34;https://holyhash.com/media/2015/03/key_gold-161x300.jpg&#34; alt=&#34;key_gold&#34; width=&#34;161&#34; height=&#34;300&#34; srcset=&#34;https://holyhash.com/media/2015/03/key_gold-161x300.jpg 161w, https://holyhash.com/media/2015/03/key_gold-214x400.jpg 214w, https://holyhash.com/media/2015/03/key_gold.jpg 300w&#34; sizes=&#34;(max-width: 161px) 100vw, 161px&#34; /&gt;&lt;/a&gt;I got an interesting question regarding the technologies we use for authentication that I will discuss here. The gist of the question is that we try to go all out on the technologies we use for the authentication, even trying unsuitable technologies like biometrics, while, on the other hand, we still use fairly simple keys to open our house doors. Why is that? Why is the house secured with a simple key that could be photographed and copied and it seems sufficient nevertheless? Why then, for example, the biometrics is not enough as an authentication mechanism by comparison?&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
