<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>schmichael&#039;s blog &#187; security</title>
	<atom:link href="http://blog.schmichael.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.schmichael.com</link>
	<description>good good study, day day up</description>
	<lastBuildDate>Sat, 05 Nov 2011 23:13:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Fedora&#8217;s Crypto Consolidation</title>
		<link>http://blog.schmichael.com/2008/10/20/fedoras-crypto-consolidation/</link>
		<comments>http://blog.schmichael.com/2008/10/20/fedoras-crypto-consolidation/#comments</comments>
		<pubDate>Mon, 20 Oct 2008 19:50:50 +0000</pubDate>
		<dc:creator>Michael Schurter</dc:creator>
				<category><![CDATA[GNU/Linux]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[crypto]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[fedora]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ubuntu]]></category>

		<guid isPermaLink="false">http://michael.susens-schurter.com/blog/?p=422</guid>
		<description><![CDATA[I just found out Fedora is attempting to consolidate on Mozilla&#8217;s NSS for system-wide cryptography. I love the idea and hope it succeeds as it will make using crypto so much easier for system administrators and users. Since humans are &#8230; <a href="http://blog.schmichael.com/2008/10/20/fedoras-crypto-consolidation/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I just found out Fedora is attempting to consolidate on <a href="http://developer.mozilla.org/en/NSS">Mozilla&#8217;s NSS</a> for <a href="http://fedoraproject.org/wiki/FedoraCryptoConsolidation">system-wide cryptography</a>.  I love the idea and hope it succeeds as it will make using crypto so much easier for system administrators and users.</p>
<p>Since humans are the weakest link in the security chain, improving the human interaction with crypto is a much bigger security win than the latest impossible-to-crack-by-the-NSA-in-a-bajillion-years algorithm.  While switching libraries isn&#8217;t exactly a huge UI win, having a single application to manage all of your certificates, keys, passwords, etc. would be.</p>
<p>I&#8217;d love to see Debian, Ubuntu, Suse, et al, get on board as well because this is the sort of initiative that simply won&#8217;t happen upstream.  Upstream developers have already chosen a crypto library and probably like it.  The burden of tight integration is definitely the job of system engineers and packagers.</p>
<p>I submitted an Ubuntu Brainstorm Idea, so please feel free to vote on it if you&#8217;re so inclined:<br />
<a href="http://brainstorm.ubuntu.com/idea/14632/"><img src="http://brainstorm.ubuntu.com/idea/14632/image/1/" /></a></p>
<p>I would love to submit this idea to Debian as well, but I have no idea where to even start.  Probably a mailing list, but I don&#8217;t exactly have the skills to defend this proposition.  Eventually bugs would need to be filed against every package that needs to be converted to NSS, but I&#8217;m afraid doing that as just-another-end-user might just anger a bunch of maintainers&#8230;</p>
<p><strong>Update:</strong> Looks like the <a href="http://ldn.linuxfoundation.org/article/lsb-beta-reveals-new-tools-features-developers">LSB is standardizing on NSS</a> as well.</p>
<p><small>I <em>really</em> need to learn deb packaging&#8230;</small></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.schmichael.com/2008/10/20/fedoras-crypto-consolidation/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

