<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>BPuhl's Blog</title>
	<atom:link href="http://imav8n.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://imav8n.wordpress.com</link>
	<description>A little bit of everything without actually being much of anything</description>
	<lastBuildDate>Thu, 11 Jun 2009 07:05:27 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<image>
		<url>http://www.gravatar.com/blavatar/8c7edbfbe927a98561dc6df56a55588a?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>BPuhl's Blog</title>
		<link>http://imav8n.wordpress.com</link>
	</image>
			<item>
		<title>Facebook is going to allow user names on June 12th</title>
		<link>http://imav8n.wordpress.com/2009/06/10/facebook-is-going-to-allow-user-names-on-june-12th/</link>
		<comments>http://imav8n.wordpress.com/2009/06/10/facebook-is-going-to-allow-user-names-on-june-12th/#comments</comments>
		<pubDate>Thu, 11 Jun 2009 07:05:27 +0000</pubDate>
		<dc:creator>BPuhl</dc:creator>
				<category><![CDATA[Babbling and Blabbering]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Friends and family]]></category>
		<category><![CDATA[Identity and Access]]></category>
		<category><![CDATA[Random Tecnical Stuff]]></category>
		<category><![CDATA[Randomness]]></category>

		<guid isPermaLink="false">http://imav8n.wordpress.com/2009/06/10/facebook-is-going-to-allow-user-names-on-june-12th/</guid>
		<description><![CDATA[If you use Facebook, you might notice a box when you log in that says beginning June 12th, Facebook will allow registration of user names.&#160; If you “click here” to have them send more info, you’ll receive this in your registered email inbox:
Starting on Friday, June 12th, at 9:01pm, you&#8217;ll be able to choose a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=286&subd=imav8n&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>If you use Facebook, you might notice a box when you log in that says beginning June 12th, Facebook will allow registration of user names.&#160; If you “click here” to have them send more info, you’ll receive this in your registered email inbox:</p>
<blockquote><p>Starting on Friday, June 12th, at 9:01pm, you&#8217;ll be able to choose a username for your Facebook account to easily direct friends, family, and coworkers to your profile.</p>
<p>To select your username, visit the link below after 9:01pm on June 12th:</p>
<p><a href="http://www.facebook.com/username/">http://www.facebook.com/username/</a></p>
<p>To learn more about usernames, visit the Help Center:</p>
<p><a href="http://www.facebook.com/help.php?page=896">http://www.facebook.com/help.php?page=896</a></p>
<p>Thanks,</p>
<p>The Facebook Team</p>
<p>&#160;</p>
</blockquote>
<p>So what does this mean?&#160; Well, for one thing, it means that if you’ve got a common name – or – if your like me, and you KNOW that there’s someone else on Facebook with the same name (since he and I are actually friends on Facebook), then it means that you want to “claim” your user name as soon as the application opens.</p>
<p>I did seen an interesting article here <a title="http://www.huffingtonpost.com/jonathan-handel/trademark-protection-and_b_213756.html" href="http://www.huffingtonpost.com/jonathan-handel/trademark-protection-and_b_213756.html">http://www.huffingtonpost.com/jonathan-handel/trademark-protection-and_b_213756.html</a> about trademark registrations and how Facebook intends to handle squatters.&#160; So don’t bother trying to register facebook.com/McDonalds, you won’t have it for long if you do.&#160; </p>
<p>I like the very last part of that article though.&#160; There is already a recommendation for what to do, if somebody maliciously claims not only your trademark, but also fills out the forms sufficiently such that you (the legitimate owner of the trademark) actually can’t use the automation to claim it back. </p>
<p>Oh how much fun Identity Management can be <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/imav8n.wordpress.com/286/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/imav8n.wordpress.com/286/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/imav8n.wordpress.com/286/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/imav8n.wordpress.com/286/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/imav8n.wordpress.com/286/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/imav8n.wordpress.com/286/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/imav8n.wordpress.com/286/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/imav8n.wordpress.com/286/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/imav8n.wordpress.com/286/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/imav8n.wordpress.com/286/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=286&subd=imav8n&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://imav8n.wordpress.com/2009/06/10/facebook-is-going-to-allow-user-names-on-june-12th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1b9d49e2bbef72e8001ec6e9888296ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">BPuhl</media:title>
		</media:content>
	</item>
		<item>
		<title>Congratulations!</title>
		<link>http://imav8n.wordpress.com/2009/06/09/congratulations/</link>
		<comments>http://imav8n.wordpress.com/2009/06/09/congratulations/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 22:09:44 +0000</pubDate>
		<dc:creator>BPuhl</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Random Tecnical Stuff]]></category>

		<guid isPermaLink="false">http://imav8n.wordpress.com/?p=284</guid>
		<description><![CDATA[Congratulations to all of the MSIT and Product Group members who got us this far (and let’s not forget the users!)

       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=284&subd=imav8n&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Congratulations to all of the MSIT and Product Group members who got us this far (and let’s not forget the users!)</p>
<p><a href="http://imav8n.files.wordpress.com/2009/06/red_dfl.jpg"><img style="border-bottom:0;border-left:0;display:inline;border-top:0;border-right:0;" title="red_dfl" border="0" alt="red_dfl" src="http://imav8n.files.wordpress.com/2009/06/red_dfl_thumb.jpg?w=781&#038;h=547" width="781" height="547" /></a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/imav8n.wordpress.com/284/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/imav8n.wordpress.com/284/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/imav8n.wordpress.com/284/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/imav8n.wordpress.com/284/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/imav8n.wordpress.com/284/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/imav8n.wordpress.com/284/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/imav8n.wordpress.com/284/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/imav8n.wordpress.com/284/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/imav8n.wordpress.com/284/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/imav8n.wordpress.com/284/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=284&subd=imav8n&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://imav8n.wordpress.com/2009/06/09/congratulations/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1b9d49e2bbef72e8001ec6e9888296ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">BPuhl</media:title>
		</media:content>

		<media:content url="http://imav8n.files.wordpress.com/2009/06/red_dfl_thumb.jpg" medium="image">
			<media:title type="html">red_dfl</media:title>
		</media:content>
	</item>
		<item>
		<title>Random port? I think not&#8230;</title>
		<link>http://imav8n.wordpress.com/2009/06/08/random-port-i-think-not/</link>
		<comments>http://imav8n.wordpress.com/2009/06/08/random-port-i-think-not/#comments</comments>
		<pubDate>Mon, 08 Jun 2009 18:58:21 +0000</pubDate>
		<dc:creator>BPuhl</dc:creator>
				<category><![CDATA[ADFS]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Random Tecnical Stuff]]></category>

		<guid isPermaLink="false">http://imav8n.wordpress.com/2009/06/08/random-port-i-think-not/</guid>
		<description><![CDATA[6 months ago – We’re in the process of federating with a new partner, and the link they send us to their federation server looked something like this:&#160; https://federation.foo.com:9031/blah – notice the port 9031? 
This seemed a little random, but not completely unusual since people tend to grab an available port when they want to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=281&subd=imav8n&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><blockquote><p><strong>6 months ago</strong> – We’re in the process of federating with a new partner, and the link they send us to their federation server looked something like this:&#160; <a href="https://federation.foo.com:9031/blah">https://federation.foo.com:9031/blah</a> – notice the port 9031? </p>
<p>This seemed a little random, but not completely unusual since people tend to grab an available port when they want to host a test/beta site.</p>
</blockquote>
<p>With a bit of troubleshooting, working with our proxy server team, etc… figured out that our proxy servers only allow SSL connectivity out to port 443, so the federation was broken.&#160; A bit of back and forth with the partner, they moved to the standard SSL port, and everything worked great.</p>
<blockquote><p><strong>4 months ago</strong> – We’re in the process of federating with a new partner, and the link they send us to their federation server looked something like this:&#160; <a href="https://federation.contoso.com:9031/blah">https://federation.contoso.com:9031/blah</a></p>
<p><strong>Us:&#160; </strong>Hey, we’ve seen this before – we can only connect to port 443 for SSL sites, can you move your federation server to the standard port?      <br /><strong>Reply:</strong>&#160; Sure, done – check it now</p>
<p>And there was much rejoicing. yeah.</p>
</blockquote>
<p>Rinse and repeat this a half a dozen times over the past few months, and we’re getting pretty good at recognizing the issue.&#160; And since about 60% of our federation partners are using STS’s which are not ADFS/Geneva, this scenario is even more common.</p>
<p>The other day, while dancing this dance yet again, we did notice one thing though – It’s not a random port – it’s ALWAYS port 9031.&#160; Not only that, but looking back, it’s always with partners who are using Ping Federate server.</p>
<p>A <a href="http://www.pingidentity.com/search.cfm?cx=003773791578361302287%3Aquvv1-cgy40&amp;cof=FORID%3A11&amp;q=9031#1406">quick search for “9031” on the Ping website</a>, finds that a lot of their sample code uses port 9031.&#160; </p>
<p>Ah ha!&#160; Now I get it.&#160; It wasn’t random after all, but rather re-using the sample code to set up services.&#160; Which is a great, so now we know that when we’re federating with a partner that’s using Ping Federate – be on the lookout for port 9031.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/imav8n.wordpress.com/281/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/imav8n.wordpress.com/281/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/imav8n.wordpress.com/281/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/imav8n.wordpress.com/281/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/imav8n.wordpress.com/281/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/imav8n.wordpress.com/281/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/imav8n.wordpress.com/281/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/imav8n.wordpress.com/281/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/imav8n.wordpress.com/281/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/imav8n.wordpress.com/281/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=281&subd=imav8n&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://imav8n.wordpress.com/2009/06/08/random-port-i-think-not/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1b9d49e2bbef72e8001ec6e9888296ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">BPuhl</media:title>
		</media:content>
	</item>
		<item>
		<title>SYSVOL Replication Migration Guide: FRS to DFS Replication</title>
		<link>http://imav8n.wordpress.com/2009/05/01/sysvol-replication-migration-guide-frs-to-dfs-replication/</link>
		<comments>http://imav8n.wordpress.com/2009/05/01/sysvol-replication-migration-guide-frs-to-dfs-replication/#comments</comments>
		<pubDate>Sat, 02 May 2009 06:00:56 +0000</pubDate>
		<dc:creator>BPuhl</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Random Tecnical Stuff]]></category>

		<guid isPermaLink="false">http://imav8n.wordpress.com/2009/05/01/sysvol-replication-migration-guide-frs-to-dfs-replication/</guid>
		<description><![CDATA[Web pages on Microsoft TechNet: http://go.microsoft.com/fwlink/?LinkId=139749
A Microsoft Word (.doc) document on the Microsoft Download Center: http://go.microsoft.com/fwlink/?LinkId=150375
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=280&subd=imav8n&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Web pages on Microsoft TechNet: <a href="http://go.microsoft.com/fwlink/?LinkId=139749">http://go.microsoft.com/fwlink/?LinkId=139749</a></p>
<p>A Microsoft Word (.doc) document on the Microsoft Download Center: <a href="http://go.microsoft.com/fwlink/?LinkId=150375">http://go.microsoft.com/fwlink/?LinkId=150375</a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/imav8n.wordpress.com/280/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/imav8n.wordpress.com/280/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/imav8n.wordpress.com/280/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/imav8n.wordpress.com/280/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/imav8n.wordpress.com/280/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/imav8n.wordpress.com/280/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/imav8n.wordpress.com/280/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/imav8n.wordpress.com/280/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/imav8n.wordpress.com/280/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/imav8n.wordpress.com/280/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=280&subd=imav8n&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://imav8n.wordpress.com/2009/05/01/sysvol-replication-migration-guide-frs-to-dfs-replication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1b9d49e2bbef72e8001ec6e9888296ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">BPuhl</media:title>
		</media:content>
	</item>
		<item>
		<title>AD in the Perimeter Network</title>
		<link>http://imav8n.wordpress.com/2009/04/27/ad-in-the-perimeter-network/</link>
		<comments>http://imav8n.wordpress.com/2009/04/27/ad-in-the-perimeter-network/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 11:52:18 +0000</pubDate>
		<dc:creator>BPuhl</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Identity and Access]]></category>
		<category><![CDATA[Random Tecnical Stuff]]></category>

		<guid isPermaLink="false">http://imav8n.wordpress.com/2009/04/27/ad-in-the-perimeter-network/</guid>
		<description><![CDATA[A new whitepaper has been published providing the guidance you need to deploy Active Directory, and specifically RODC’s, in a “Perimeter Network” (the network segment formerly known as DMZ).
I know that a lot of folks have come to me, asking for help/guidance on putting RODC’s into the DMZ rather than putting full DC’s or having [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=278&subd=imav8n&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>A new whitepaper has been published providing the guidance you need to deploy Active Directory, and specifically RODC’s, in a “Perimeter Network” (the network segment formerly known as DMZ).</p>
<p>I know that a lot of folks have come to me, asking for help/guidance on putting RODC’s into the DMZ rather than putting full DC’s or having a separate forest.&#160; This should provide the information you need to keep safe, secure, and most of all…functional.</p>
<p>Some of the topics include:    <br />•&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Security considerations and configurations for RODCs in the DMZ&#160; <br />•&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Network configurations for RODCs     <br />•&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Application compatibility with RODCs in the DMZ     <br />•&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Step by step instructions and a sample script to help perform domain join using RODCs </p>
<p><a title="http://technet.microsoft.com/en-us/library/dd728034.aspx" href="http://technet.microsoft.com/en-us/library/dd728034.aspx">http://technet.microsoft.com/en-us/library/dd728034.aspx</a></p>
<p>&#160;</p>
<p><em><a href="http://bsonposh.com/">Brandon</a> pointed out to me, that the doc is nice, but having a downloadable version would be much nicer.&#160; We fired off a quick mail, and there will be a downloadable version of the document in the download center in the near future.</em></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/imav8n.wordpress.com/278/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/imav8n.wordpress.com/278/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/imav8n.wordpress.com/278/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/imav8n.wordpress.com/278/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/imav8n.wordpress.com/278/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/imav8n.wordpress.com/278/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/imav8n.wordpress.com/278/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/imav8n.wordpress.com/278/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/imav8n.wordpress.com/278/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/imav8n.wordpress.com/278/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=278&subd=imav8n&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://imav8n.wordpress.com/2009/04/27/ad-in-the-perimeter-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1b9d49e2bbef72e8001ec6e9888296ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">BPuhl</media:title>
		</media:content>
	</item>
		<item>
		<title>Collection agencies&#8230;.</title>
		<link>http://imav8n.wordpress.com/2009/04/10/collection-agencies/</link>
		<comments>http://imav8n.wordpress.com/2009/04/10/collection-agencies/#comments</comments>
		<pubDate>Sat, 11 Apr 2009 06:02:36 +0000</pubDate>
		<dc:creator>BPuhl</dc:creator>
				<category><![CDATA[ADFS]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Friends and family]]></category>
		<category><![CDATA[Identity and Access]]></category>
		<category><![CDATA[Randomness]]></category>
		<category><![CDATA[Rants]]></category>

		<guid isPermaLink="false">http://imav8n.wordpress.com/2009/04/10/collection-agencies/</guid>
		<description><![CDATA[I have had a few discussions recently at work about ways to make things more convenient.&#160; Either convenient for our users (cloud services), convenient for our customers (single sign on), etc…&#160; 
But a one-two punch hit me, when I just had 2 close friends &#8211; both of whom have been impacted by the financial mess [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=277&subd=imav8n&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I have had a few discussions recently at work about ways to make things more convenient.&#160; Either convenient for our users (cloud services), convenient for our customers (single sign on), etc…&#160; </p>
<p>But a one-two punch hit me, when I just had 2 close friends &#8211; both of whom have been impacted by the financial mess – have their identity attacked because something that had built in security controls (checks) was made to be more convenient (by phone), and in the process all of the controls were removed so my friends were vulnerable.</p>
<p>Really, I call it fraud, or identity theft, or just plain robbery…&#160; But in both cases, the banks say that there are no laws against this:</p>
<blockquote><p>My friend lost her job, and fell behind on payments.&#160; She owed $1100 for this months rent, $4400 to a creditor that by this point had gone to a collection agency, and some other bills (credit cards, gas, electricity, etc…).&#160; Through creative budgeting and working with parents, friends, and anyone else, she scraped together $5000 that she could use.&#160; </p>
<p>With the new money available, she came up with the following plan:</p>
<p>&#160;&#160; $1100 for rent     <br />&#160;&#160;&#160;&#160;&#160; 900 for the other bills      <br />&#160;&#160;&#160;&#160;&#160; 500 to the collection agency      <br />&#160;&#160;&#160;&#160;&#160; The rest to be used for the following months rent, payments, etc…</p>
<p>She called the collection agency, and agreed to pay them $500 now, and then set up a payment plan for the rest of the money.&#160; That’s where the first mistake happened:&#160; They wanted the payment as a “check by phone”.&#160; So she voided a check, gave them the info, etc…</p>
<p>The collection agency first attempted to clear the check for the full $4400.&#160; Because the money was in the account, the check cleared – of course, this meant that she couldn’t pay any of the other bills, or her rent, etc…&#160; And she had already tapped out her friends, parents, etc…</p>
<p>You can imagine that the calls to the collection agency were like:&#160; “Sorry, sucks to be you – we’ve got our money now”</p>
<p>The bank was equally useless:&#160; “You gave them a check by phone, the money was in the account, they cleared it…Sucks to be you”</p>
</blockquote>
<p>This was just completely ridiculous, but it shows that in the absence of standards or protocols, there is no shortage of people that will offer things for the sake of “convenience” which blow the hell out of “security”.&#160; If you have to write a check and sign it, then you fill in the amount, etc…&#160; modification of that is check fraud.&#160; But those security controls went out the window when banks allowed people to do “checks by phone”, and there is absolutely nothing to prevent unscrupulous people from raping your bank account if you give them the information.</p>
<p>The second case is similar, but with a slight twist</p>
<blockquote><p>My friend has slowly but surely been paying off debts that were racked up over a period of time, and has been working through one of those debt consolidation management companies.&#160; Since she wasn’t getting the resolution that she needed from the company, she took back the money that was in their escrow account and started working with the collection agency independently.</p>
<p>On the first phone call, she had an $7,000 debt and worked with the agency to negotiate down to where they would accept $4300.&#160; Seems like a good deal, so again, check by phone for $4300.</p>
<p>A couple of days later, she received a notice from the collection agency, indicating that they “Had an agreement for an <em>initial payment</em> of $4300”.&#160; In other words, the deal they made on the phone was a lie, instead of negotiating the total, they just wanted an initial payment and were going to keep going after her for the remaining balance.</p>
<p>Ahhh…but the check by phone hadn’t cleared yet.</p>
<p>So a quick call to the bank, a $28.00 stop payment charge, and there was a stop-payment for that check before it cleared.</p>
<p>Good right?</p>
<p>Not so much.&#160; 2 days later, $4300 was withdrawn from the account anyway, by check #1001 (not the check number she gave them).&#160; A long, convoluted, multi-transfer call back with the bank this time, and they could see where the initial check number had attempted to clear, been rejected (the stop payment), and then the company had re-submitted another check by phone with the different check number and got the money.</p>
<p>After several days of arguing, it’s still unclear whether the bank is going to say “Sorry, sux to be you” or if they are actually going to help.&#160; I’m not holding my breath.</p>
</blockquote>
<p>So again, the safety features around checks – being numbered, signed, amounts written (twice) – are all placed into the trusting hands of the least trustworthy person (the merchant that wants your money), and there is remarkably little recourse.&#160; I suppose you could go get a lawyer, etc…&#160; But during that time the money is gone, life still needs to be lived, and a lawyer is going to take 30% of whatever you get back anyway (or some amount of payment)…</p>
<p>All for the sake of convenience (to whom?)</p>
<p>There are better ways, one of which I really like.&#160; I’ve had a credit card with CitiBank since college.&#160; And many years ago, they came up with this idea of virtual account numbers for your credit card.&#160; You can go to their website (or they have a downloadable application), and if you want to make a purchase, you can get a one-time use credit card number (with expiration and CVC) for that one purchase.&#160; I haven’t used it in a while, but IIRC you can even specify the amount of the purchase you’re going to make (which is really the protection).&#160; This is great, because the security of a credit card is handing the piece of plastic with the signature on the back to the person behind the register.&#160; With online purchases, you can’t do that, so instead lets take the things which you can control (amount of purchase, usefulness of the number after it’s been used properly) and control those instead.&#160; Reasonable mitigations.</p>
<p>This is the type of control that we’re going to need if we want to protect our resources in a more “convenient” (read: Online) world. </p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/imav8n.wordpress.com/277/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/imav8n.wordpress.com/277/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/imav8n.wordpress.com/277/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/imav8n.wordpress.com/277/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/imav8n.wordpress.com/277/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/imav8n.wordpress.com/277/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/imav8n.wordpress.com/277/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/imav8n.wordpress.com/277/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/imav8n.wordpress.com/277/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/imav8n.wordpress.com/277/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=277&subd=imav8n&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://imav8n.wordpress.com/2009/04/10/collection-agencies/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1b9d49e2bbef72e8001ec6e9888296ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">BPuhl</media:title>
		</media:content>
	</item>
		<item>
		<title>Happy Birthday Redmond.Corp.Microsoft.Com</title>
		<link>http://imav8n.wordpress.com/2009/04/09/happy-birthday-redmondcorpmicrosoftcom/</link>
		<comments>http://imav8n.wordpress.com/2009/04/09/happy-birthday-redmondcorpmicrosoftcom/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 02:50:00 +0000</pubDate>
		<dc:creator>BPuhl</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Random Tecnical Stuff]]></category>

		<guid isPermaLink="false">http://imav8n.wordpress.com/2009/04/09/happy-birthday-redmondcorpmicrosoftcom/</guid>
		<description><![CDATA[10 years ago, Microsoft’s largest internal domain was upgraded to Windows 2000 becoming the first production Active Directory, and it’s still going strong…
Dn: DC=redmond,DC=corp,DC=microsoft,DC=com    &#160;&#160; whenCreated: 4/9/1999 7:49:12 PM Pacific Daylight Time; 
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=276&subd=imav8n&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>10 years ago, Microsoft’s largest internal domain was upgraded to Windows 2000 becoming the first production Active Directory, and it’s still going strong…</p>
<p><strong>Dn: DC=redmond,DC=corp,DC=microsoft,DC=com</strong>    <br />&#160;&#160; whenCreated: 4/9/1999 7:49:12 PM Pacific Daylight Time; </p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/imav8n.wordpress.com/276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/imav8n.wordpress.com/276/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/imav8n.wordpress.com/276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/imav8n.wordpress.com/276/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/imav8n.wordpress.com/276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/imav8n.wordpress.com/276/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/imav8n.wordpress.com/276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/imav8n.wordpress.com/276/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/imav8n.wordpress.com/276/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/imav8n.wordpress.com/276/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=276&subd=imav8n&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://imav8n.wordpress.com/2009/04/09/happy-birthday-redmondcorpmicrosoftcom/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1b9d49e2bbef72e8001ec6e9888296ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">BPuhl</media:title>
		</media:content>
	</item>
		<item>
		<title>TEC 2009 Wook Lee Memorial Challenge</title>
		<link>http://imav8n.wordpress.com/2009/04/09/tec-2009-wook-lee-memorial-challenge/</link>
		<comments>http://imav8n.wordpress.com/2009/04/09/tec-2009-wook-lee-memorial-challenge/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 22:18:59 +0000</pubDate>
		<dc:creator>BPuhl</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Identity and Access]]></category>
		<category><![CDATA[Random Tecnical Stuff]]></category>
		<category><![CDATA[Randomness]]></category>

		<guid isPermaLink="false">http://imav8n.wordpress.com/2009/04/09/tec-2009-wook-lee-memorial-challenge/</guid>
		<description><![CDATA[At The Experts Conference in Las Vegas this year, Stuart threw out the challenge to the DS MVP’s to come up with their list of changes they would like to see in Active Directory, but put it to the tune of an Elvis song.&#160; After a midnight (mildly inebriated) recording session, and some fancy editing [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=275&subd=imav8n&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>At The Experts Conference in Las Vegas this year, Stuart threw out the challenge to the DS MVP’s to come up with their list of changes they would like to see in Active Directory, but put it to the tune of an Elvis song.&#160; After a midnight (mildly inebriated) recording session, and some fancy editing by the Quest Software production staff, here’s the result!</p>
<p>&#160;</p>
<div style="width:425px;display:block;float:none;margin:0 auto;padding:0;" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:7ea9d977-00bf-422a-afe1-182f3ec94867" class="wlWriterEditableSmartContent">
<div><span style="text-align:center; display: block;"><a href="http://imav8n.wordpress.com/2009/04/09/tec-2009-wook-lee-memorial-challenge/"><img src="http://img.youtube.com/vi/Qdq4wC062-U/2.jpg" alt="" /></a></span></div>
</div>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/imav8n.wordpress.com/275/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/imav8n.wordpress.com/275/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/imav8n.wordpress.com/275/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/imav8n.wordpress.com/275/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/imav8n.wordpress.com/275/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/imav8n.wordpress.com/275/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/imav8n.wordpress.com/275/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/imav8n.wordpress.com/275/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/imav8n.wordpress.com/275/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/imav8n.wordpress.com/275/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=275&subd=imav8n&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://imav8n.wordpress.com/2009/04/09/tec-2009-wook-lee-memorial-challenge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1b9d49e2bbef72e8001ec6e9888296ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">BPuhl</media:title>
		</media:content>

		<media:content url="http://img.youtube.com/vi/Qdq4wC062-U/2.jpg" medium="image" />
	</item>
		<item>
		<title>Being Hacked is ok (if you&#8217;re paying for it)</title>
		<link>http://imav8n.wordpress.com/2009/03/27/being-hacked-is-ok-if-youre-paying-for-it/</link>
		<comments>http://imav8n.wordpress.com/2009/03/27/being-hacked-is-ok-if-youre-paying-for-it/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 11:02:00 +0000</pubDate>
		<dc:creator>BPuhl</dc:creator>
				<category><![CDATA[ADFS]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Identity and Access]]></category>
		<category><![CDATA[InfoCards]]></category>
		<category><![CDATA[Random Tecnical Stuff]]></category>
		<category><![CDATA[Rants]]></category>

		<guid isPermaLink="false">http://imav8n.wordpress.com/2009/03/27/being-hacked-is-ok-if-youre-paying-for-it/</guid>
		<description><![CDATA[There were many great speakers at TEC 2009 this year (and I was there too!), especially in the Federated Identity track.&#160; One of the things that I was interesting, was during one of the sessions the speaker described many of the current non-federated authentication schemes that SaaS providers can use.&#160; The implementations may have varied [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=270&subd=imav8n&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>There were many great speakers at TEC 2009 this year (and I was there too!), especially in the Federated Identity track.&#160; One of the things that I was interesting, was during one of the sessions the speaker described many of the current non-federated authentication schemes that SaaS providers can use.&#160; The implementations may have varied slightly, but they often amounted to “Give us your user name and password, and we’ll authenticate you across some out-of-band channel.”&#160; The deployment of this service requires that extra channel for auth, sometimes being a VPN connection, or an LDAP service that the provider can authenticate against…things like that.</p>
<p>A comment was made, something about the security risk that this poses; after all, it IS by definition a “man in the middle attack.”&#160; The next couple of minutes were spent blasting this type of ridiculous design (after all, this was the federation track) and how horrible this was and people would never let this type of set up occur at their company.</p>
<p>Of course, that’s probably not true at all, is it?&#160; After all, every application outsourcing project I’ve worked on includes the “user SSO” line item, but nobody says what that has to be.&#160; And the corporate security risk analysis has to outweigh the hard dollar cost savings that were driving the project to begin with, which is why I suspect that the typical CorpSec risk analysis always ends up somewhere in the Billions of dollars with a picture of the company going down in flames.&#160; Yet even that’s not enough even enough to stop the project from moving forward, because at the end of the day, IT departments are often not empowered to say “No, you can’t do that”…rather…we end up saying, “This sucks, but here’s the best that we can do to make it work.”</p>
<p>And that is why, a man in the middle attack, even one with credential harvesting, is OK if the company is paying someone to do it (and saving real money in the process)</p>
<p>And it’s why now more than ever we need comprehensive federated authentication solutions, so we don’t have to get run over by these hacks.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/imav8n.wordpress.com/270/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/imav8n.wordpress.com/270/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/imav8n.wordpress.com/270/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/imav8n.wordpress.com/270/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/imav8n.wordpress.com/270/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/imav8n.wordpress.com/270/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/imav8n.wordpress.com/270/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/imav8n.wordpress.com/270/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/imav8n.wordpress.com/270/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/imav8n.wordpress.com/270/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=270&subd=imav8n&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://imav8n.wordpress.com/2009/03/27/being-hacked-is-ok-if-youre-paying-for-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1b9d49e2bbef72e8001ec6e9888296ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">BPuhl</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft Tag</title>
		<link>http://imav8n.wordpress.com/2009/03/27/microsoft-tag/</link>
		<comments>http://imav8n.wordpress.com/2009/03/27/microsoft-tag/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 08:49:02 +0000</pubDate>
		<dc:creator>BPuhl</dc:creator>
				<category><![CDATA[21st Century]]></category>
		<category><![CDATA[Random Tecnical Stuff]]></category>
		<category><![CDATA[Randomness]]></category>

		<guid isPermaLink="false">http://imav8n.wordpress.com/2009/03/27/microsoft-tag/</guid>
		<description><![CDATA[This looks pretty cool!
http://www.microsoft.com/tag/
&#160;
Here’s the tag I created, which would bring you back to my blog if you scanned it with a tag reader app on your phone… 

       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=271&subd=imav8n&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>This looks pretty cool!</p>
<p><a title="http://www.microsoft.com/tag/" href="http://www.microsoft.com/tag/">http://www.microsoft.com/tag/</a></p>
<p>&#160;</p>
<p>Here’s the tag I created, which would bring you back to my blog if you scanned it with a tag reader app on your phone… </p>
<p><a href="http://imav8n.files.wordpress.com/2009/03/blog-tag.jpg"><img style="border-bottom:0;border-left:0;display:inline;border-top:0;border-right:0;" title="blog_tag" border="0" alt="blog_tag" src="http://imav8n.files.wordpress.com/2009/03/blog-tag-thumb.jpg?w=381&#038;h=321" width="381" height="321" /></a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/imav8n.wordpress.com/271/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/imav8n.wordpress.com/271/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/imav8n.wordpress.com/271/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/imav8n.wordpress.com/271/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/imav8n.wordpress.com/271/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/imav8n.wordpress.com/271/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/imav8n.wordpress.com/271/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/imav8n.wordpress.com/271/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/imav8n.wordpress.com/271/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/imav8n.wordpress.com/271/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=imav8n.wordpress.com&blog=1856342&post=271&subd=imav8n&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://imav8n.wordpress.com/2009/03/27/microsoft-tag/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1b9d49e2bbef72e8001ec6e9888296ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">BPuhl</media:title>
		</media:content>

		<media:content url="http://imav8n.files.wordpress.com/2009/03/blog-tag-thumb.jpg" medium="image">
			<media:title type="html">blog_tag</media:title>
		</media:content>
	</item>
	</channel>
</rss>