<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Shaheen N Abdul Jabbar</title>
	<atom:link href="http://snajsoft.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://snajsoft.com</link>
	<description>Software Engineer &#62; Security Officer &#62; Security Architect</description>
	<lastBuildDate>Wed, 25 Aug 2010 22:19:38 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Risk Based Authentication</title>
		<link>http://snajsoft.com/2010/08/25/risk-based-authentication/</link>
		<comments>http://snajsoft.com/2010/08/25/risk-based-authentication/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 16:39:46 +0000</pubDate>
		<dc:creator>Shaheen Abdul Jabbar</dc:creator>
				<category><![CDATA[Access Control]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Architecture]]></category>
		<category><![CDATA[Architecture]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Fraud Prevention]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Risk Based Authentication]]></category>

		<guid isPermaLink="false">http://snajsoft.com/?p=386</guid>
		<description><![CDATA[The technique that uses both contextual and historical user information along with data supplied during an internet transaction to assess the probability of whether a user interaction is authentic or not is called risk based authentication.
Traditional username and password along with information such as who the user is, from where the user is logging in [...]]]></description>
		<wfw:commentRss>http://snajsoft.com/2010/08/25/risk-based-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Biometrics Authentication</title>
		<link>http://snajsoft.com/2010/07/20/biometrics-authentication/</link>
		<comments>http://snajsoft.com/2010/07/20/biometrics-authentication/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 17:37:27 +0000</pubDate>
		<dc:creator>Shaheen Abdul Jabbar</dc:creator>
				<category><![CDATA[Access Control]]></category>
		<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Security Architecture]]></category>
		<category><![CDATA[Architecture]]></category>
		<category><![CDATA[Biometrics]]></category>
		<category><![CDATA[Fraud Prevention]]></category>
		<category><![CDATA[Identity Theft]]></category>

		<guid isPermaLink="false">http://snajsoft.com/?p=391</guid>
		<description><![CDATA[Passwords and personal identification numbers (PIN) are information that we need to remember since the day we started interacting with digital systems. Do we know the count of passwords we need to remember? Do we know if we forgot a password already? Some of these passwords also known as passphrase are long to remember that [...]]]></description>
		<wfw:commentRss>http://snajsoft.com/2010/07/20/biometrics-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disk Overwrite or Wipeout Best Practice</title>
		<link>http://snajsoft.com/2010/06/10/disk-overwrite-or-wipeout-best-practice/</link>
		<comments>http://snajsoft.com/2010/06/10/disk-overwrite-or-wipeout-best-practice/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 03:21:27 +0000</pubDate>
		<dc:creator>Shaheen Abdul Jabbar</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Canada RCMP]]></category>
		<category><![CDATA[Disk Overwrite]]></category>
		<category><![CDATA[Disk Wipeout]]></category>
		<category><![CDATA[Gutmann method]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[NIST 800-88]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[US DoD 5220.22-M]]></category>

		<guid isPermaLink="false">http://snajsoft.com/?p=357</guid>
		<description><![CDATA[An online search shows majority of tools available for wiping out data on a disk points to a practice of 7 wipes. They believe that it is a US DoD requirement. Some of them support the Gutmann method of 35 wipes.
However, I could not find any documentation on US government website that indicates seven wipes. [...]]]></description>
		<wfw:commentRss>http://snajsoft.com/2010/06/10/disk-overwrite-or-wipeout-best-practice/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Authentication &#8211; Level of Assurance</title>
		<link>http://snajsoft.com/2010/06/07/authentication-level-of-assurance/</link>
		<comments>http://snajsoft.com/2010/06/07/authentication-level-of-assurance/#comments</comments>
		<pubDate>Tue, 08 Jun 2010 03:34:53 +0000</pubDate>
		<dc:creator>Shaheen Abdul Jabbar</dc:creator>
				<category><![CDATA[Access Control]]></category>
		<category><![CDATA[Australia]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Canada]]></category>
		<category><![CDATA[IAEG]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[Liberty Alliance]]></category>
		<category><![CDATA[New Zealand]]></category>
		<category><![CDATA[NIST 800-63]]></category>
		<category><![CDATA[OMB M-04-04]]></category>
		<category><![CDATA[United States]]></category>

		<guid isPermaLink="false">http://snajsoft.com/2010/06/07/authentication-level-of-assurance/</guid>
		<description><![CDATA[Authentication is the process of confirming an entity&#8217;s identity based on reliable credentials. The process and the technology involved in authentication varies with various level of assurance required from the entity.
Authentication Level of Assurance can be defined as the authentication strength required for a relying party to be assured that an entity is indeed who [...]]]></description>
		<wfw:commentRss>http://snajsoft.com/2010/06/07/authentication-level-of-assurance/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How Virtual Private Networks Work</title>
		<link>http://snajsoft.com/2010/04/09/how-virtual-private-networks-work/</link>
		<comments>http://snajsoft.com/2010/04/09/how-virtual-private-networks-work/#comments</comments>
		<pubDate>Fri, 09 Apr 2010 11:35:03 +0000</pubDate>
		<dc:creator>Shaheen Abdul Jabbar</dc:creator>
				<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[Architecture]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Connect With Me]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Remote Access]]></category>
		<category><![CDATA[VPN]]></category>

		<guid isPermaLink="false">http://snajsoft.com/?p=250</guid>
		<description><![CDATA[How Stuff Works.com has put up a great tutorial in layman&#8217;s language on how VPN work &#8211; http://computer.howstuffworks.com/vpn.htm
]]></description>
		<wfw:commentRss>http://snajsoft.com/2010/04/09/how-virtual-private-networks-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Must Haves in a SaaS Provider</title>
		<link>http://snajsoft.com/2009/12/29/security-must-haves-in-a-saas-provider/</link>
		<comments>http://snajsoft.com/2009/12/29/security-must-haves-in-a-saas-provider/#comments</comments>
		<pubDate>Tue, 29 Dec 2009 14:11:22 +0000</pubDate>
		<dc:creator>Shaheen Abdul Jabbar</dc:creator>
				<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Outsourcing]]></category>
		<category><![CDATA[SaaS]]></category>

		<guid isPermaLink="false">http://snajsoft.com/?p=238</guid>
		<description><![CDATA[The past year was a learning curve on Cloud Computing, especially on SaaS providers. More and more ASPs are coming back rebranded as SaaS provider. As a security practitioner, it would be good to have a must have check list that we need to use to assess them.
I prepared the following must have check list [...]]]></description>
		<wfw:commentRss>http://snajsoft.com/2009/12/29/security-must-haves-in-a-saas-provider/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Happy Holidays &amp; New Year</title>
		<link>http://snajsoft.com/2009/12/24/happy-holidays-new-year-2010/</link>
		<comments>http://snajsoft.com/2009/12/24/happy-holidays-new-year-2010/#comments</comments>
		<pubDate>Thu, 24 Dec 2009 19:30:33 +0000</pubDate>
		<dc:creator>Shaheen Abdul Jabbar</dc:creator>
				<category><![CDATA[Miscellaneous]]></category>

		<guid isPermaLink="false">http://snajsoft.com/?p=230</guid>
		<description><![CDATA[]]></description>
		<wfw:commentRss>http://snajsoft.com/2009/12/24/happy-holidays-new-year-2010/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>ASP to SaaS</title>
		<link>http://snajsoft.com/2009/11/18/asp-to-saas/</link>
		<comments>http://snajsoft.com/2009/11/18/asp-to-saas/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 16:28:44 +0000</pubDate>
		<dc:creator>Shaheen Abdul Jabbar</dc:creator>
				<category><![CDATA[Security Architecture]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[IaaS]]></category>
		<category><![CDATA[PaaS]]></category>
		<category><![CDATA[SaaS]]></category>

		<guid isPermaLink="false">http://snajsoft.com/?p=223</guid>
		<description><![CDATA[A discussion on business model transition from ASP to SaaS]]></description>
		<wfw:commentRss>http://snajsoft.com/2009/11/18/asp-to-saas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Placing a Vulnerability Assessment Scanner</title>
		<link>http://snajsoft.com/2009/10/24/placing-a-vulnerability-assessment-scanner/</link>
		<comments>http://snajsoft.com/2009/10/24/placing-a-vulnerability-assessment-scanner/#comments</comments>
		<pubDate>Sat, 24 Oct 2009 04:51:21 +0000</pubDate>
		<dc:creator>Shaheen Abdul Jabbar</dc:creator>
				<category><![CDATA[Security Architecture]]></category>
		<category><![CDATA[Vulnerability Assessment]]></category>

		<guid isPermaLink="false">http://snajsoft.com/?p=208</guid>
		<description><![CDATA[Where do you put vulnerability assessment (VA) scanners in a very distributed network? Consider a scenario where a company has presence in North America, Europe and South Asia. As part of its annual penetration testing environment, the company wants to conduct vulnerability assessment at all its demilitarized zones (DMZ). North America may have DMZs in [...]]]></description>
		<wfw:commentRss>http://snajsoft.com/2009/10/24/placing-a-vulnerability-assessment-scanner/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Unauthentication</title>
		<link>http://snajsoft.com/2009/10/15/unauthentication/</link>
		<comments>http://snajsoft.com/2009/10/15/unauthentication/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 10:30:47 +0000</pubDate>
		<dc:creator>Shaheen Abdul Jabbar</dc:creator>
				<category><![CDATA[Access Control]]></category>
		<category><![CDATA[Bruce Schneier]]></category>

		<guid isPermaLink="false">http://snajsoft.com/?p=202</guid>
		<description><![CDATA[by Bruce Schneier
In computer security, a lot of effort is spent on the authentication problem.  Whether it’s passwords, secure tokens, secret questions, image mnemonics, or something else, engineers are continually coming up with more complicated &#8212; and hopefully more secure &#8212; ways for you to prove you are who you say you are over the [...]]]></description>
		<wfw:commentRss>http://snajsoft.com/2009/10/15/unauthentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
