<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>webjedi.net</title>
	<atom:link href="http://www.webjedi.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.webjedi.net</link>
	<description>SYN, SYN-ACK, ACK, BLOG, FIN, RST</description>
	<lastBuildDate>Mon, 02 Jan 2012 02:01:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<copyright>Copyright &#38;#xA9; webjedi.net 2011 </copyright>
	<managingEditor>webjedi@mac.com (webjedi.net)</managingEditor>
	<webMaster>webjedi@mac.com (webjedi.net)</webMaster>
	<image>
		<url>http://www.webjedi.net/wp-content/plugins/podpress/images/powered_by_podpress.jpg</url>
		<title>webjedi.net</title>
		<link>http://www.webjedi.net</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle></itunes:subtitle>
	<itunes:summary>SYN, SYN-ACK, ACK, BLOG, FIN, RST</itunes:summary>
	<itunes:keywords></itunes:keywords>
	<itunes:category text="Society &#38; Culture" />
	<itunes:author>webjedi.net</itunes:author>
	<itunes:owner>
		<itunes:name>webjedi.net</itunes:name>
		<itunes:email>webjedi@mac.com</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.webjedi.net/wp-content/plugins/podpress/images/powered_by_podpress_large.jpg" />
		<item>
		<title>Bleeding Edge Is Nice&#8230; Your Personal Privacy Is Better&#8230;</title>
		<link>http://www.webjedi.net/2012/01/01/bleeding-edge-is-nice-your-personal-privacy-is-better/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=bleeding-edge-is-nice-your-personal-privacy-is-better</link>
		<comments>http://www.webjedi.net/2012/01/01/bleeding-edge-is-nice-your-personal-privacy-is-better/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 02:01:15 +0000</pubDate>
		<dc:creator>netadmin</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.webjedi.net/?p=50</guid>
		<description><![CDATA[So, if you have  (or are &#8220;stuck&#8221;) with an iDevice other than an iPad 2 or iphone 4S, you most undoubtedly heard about the Spire port to these older, albeit iOS 5.x compatible devices in order to enable that lovely feature called Siri. I&#8217;m sure the developer has vetted that their work is all well [...]]]></description>
			<content:encoded><![CDATA[<div class="al2fb_like_button"><div id="fb-root"></div><script src="http://connect.facebook.net/en_US/all.js#appId=251732994847088&amp;xfbml=1" type="text/javascript"></script>
<fb:like href="http://www.webjedi.net/2012/01/01/bleeding-edge-is-nice-your-personal-privacy-is-better/" send="true" layout="button_count" show_faces="true" width="450" action="like" font="arial" colorscheme="light" ref="AL2FB"></fb:like></div><p>So, if you have  (or are &#8220;stuck&#8221;) with an iDevice other than an iPad 2 or iphone 4S, you most undoubtedly heard about the Spire port to these older, albeit iOS 5.x compatible devices in order to enable that lovely feature called Siri.</p>
<p><span id="more-50"></span></p>
<p>I&#8217;m sure the developer has vetted that their work is all well and legal, and in itself is a great exercise of stretching the boundary of what could be construed as acceptable use of technology licenses. THe cool thing is, it&#8217;s a great hack, and their caveat was&#8230; you still need one of the newer devices to proxy, or utilize a few other methods in order to authenticate these devices to Apple&#8217;s Siri servers.</p>
<p>So, immediately, the lemmings came to sites where &#8220;how to&#8217;s&#8221; were posted and started asking about open proxies for utilizing this Cydia package (I&#8217;ll go more into Jailbreaking and issues there in another blog post) effectively. So, slowly, over the last week proxies have been piling up on websites.</p>
<p>The smart thing the developer put up, noting that a lot of their work was reverse engineering, that potentially PII (personally identifiable information) may be getting sent over these authentication sessions to Apple. In the case of Spire, the RE&#8217;ed Siri activator, that information would pass through the proxy in a &#8220;man in the middle&#8221; format (which essentially a proxy is). In this case it also occurs over SSL.</p>
<p>What I&#8217;ve noted here, reversing the IP addresses of the proxies out there (list here &#8211; http://www.ijailbreak.com/spire-proxy-host-list/) is that the latest pile originate in Bahrain (not one to treat privacy with any level of respect) and require  you to install a self-signed SL certificate on your device. in order for it to work, you have to &#8220;trust&#8221; that certificate. Unfortunately, Apple doesn&#8217;t allow you to control certificates at such a low level from the &#8220;average user&#8221; side of things on iDevices like they do on their desktops, so in essence, this SSL certificate can be used to sign and trust other applications and encrypt other channels. In short, it&#8217;s a good way to get malicious code that you &#8220;trusted&#8221; in order to get this proxy feature to work.</p>
<p>Now, being the paranoid person I am, I regularly back up, and of course, you already takek the risk of 1) using an Apple device and trusting Apple, and 2) opening up your device by jailbreaking it (legal as of Summer 2010 in the US of A) and bypassing a major security feature to install code you, well, trust a 3rd party developer has written and not so maliciously.</p>
<p>This is the catch-22 in both Apple&#8217;s model (their trust of developers, who all they need to do is join ADC, pay their fee, and write an app that doesn&#8217;t raise eyebrows during their &#8220;examination&#8221;) and those 3rd Party developers who list their stuff on easily expandable repository lists on Cydia.</p>
<p>&nbsp;</p>
<p>So, in short, beware, be careful, and think about who you trust to get the newest whiz-bang hack on your phone&#8230; you don&#8217;t know who is listening.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webjedi.net/2012/01/01/bleeding-edge-is-nice-your-personal-privacy-is-better/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>So, it&#8217;s 2012 &#8211; what&#8217;s next&#8230;</title>
		<link>http://www.webjedi.net/2012/01/01/so-its-2012-whats-next/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=so-its-2012-whats-next</link>
		<comments>http://www.webjedi.net/2012/01/01/so-its-2012-whats-next/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 00:00:01 +0000</pubDate>
		<dc:creator>netadmin</dc:creator>
				<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.webjedi.net/?p=40</guid>
		<description><![CDATA[Well, in my career, and just what I like to do, I do a LOT of writing. My job now has me writing on the taxpayers dime, so, for items I feel do not constitute information embargoed or specific to any agency I will be releasing papers, drafts, presenations, and other stuff I&#8217;ve plopped out of my [...]]]></description>
			<content:encoded><![CDATA[<div class="al2fb_like_button"><div id="fb-root"></div><script src="http://connect.facebook.net/en_US/all.js#appId=251732994847088&amp;xfbml=1" type="text/javascript"></script>
<fb:like href="http://www.webjedi.net/2012/01/01/so-its-2012-whats-next/" send="true" layout="button_count" show_faces="true" width="450" action="like" font="arial" colorscheme="light" ref="AL2FB"></fb:like></div><p>Well, in my career, and just what I like to do, I do a LOT of writing. My job now has me writing on the taxpayers dime, so, for items I feel do not constitute information embargoed or specific to any agency I will be releasing papers, drafts, presenations, and other stuff I&#8217;ve plopped out of my head here on the dite. I</p>
<p>ll do my best to put them in digestible formats. I think I&#8217;ll also get back to doing some idea generating and some security research stuff again&#8230; mainly because I miss it&#8230; so hopefully over the next few days, I&#8217;ll redact what I can and edit others and get some things up here for you allt o enjoy&#8230;</p>
<p>&nbsp;</p>
<p>If the stuff is wrong, off base, or otherwise, feel free to note it int he comments&#8230; I&#8217;d hope that this provides a discussion forum for these topics. All of these are my own ideas and research, and usually are sole authorship&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webjedi.net/2012/01/01/so-its-2012-whats-next/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FIRST POST!!!</title>
		<link>http://www.webjedi.net/2011/08/18/first-post/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=first-post</link>
		<comments>http://www.webjedi.net/2011/08/18/first-post/#comments</comments>
		<pubDate>Fri, 19 Aug 2011 03:36:04 +0000</pubDate>
		<dc:creator>netadmin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[first]]></category>
		<category><![CDATA[lame]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[personal]]></category>
		<category><![CDATA[post]]></category>
		<category><![CDATA[start]]></category>

		<guid isPermaLink="false">http://www.webjedi.net/?p=14</guid>
		<description><![CDATA[That is so lame&#8230; however, if you have talked to me in the past year&#8230; things have changed significantly in my life&#8230; so I figure I&#8217;d restart this blog and start getting my life in order and share with folks who care to read, what&#8217;s been going on in my life. I&#8217;m deciding what to [...]]]></description>
			<content:encoded><![CDATA[<div class="al2fb_like_button"><div id="fb-root"></div><script src="http://connect.facebook.net/en_US/all.js#appId=251732994847088&amp;xfbml=1" type="text/javascript"></script>
<fb:like href="http://www.webjedi.net/2011/08/18/first-post/" send="true" layout="button_count" show_faces="true" width="450" action="like" font="arial" colorscheme="light" ref="AL2FB"></fb:like></div><p>That is <em>so</em> lame&#8230; however, if you have talked to me in the past year&#8230; things have changed significantly in my life&#8230; so I figure I&#8217;d restart this blog and start getting my life in order and share with folks who care to read, what&#8217;s been going on in my life. I&#8217;m deciding what to possibly transfer from the old site, as well as from some other places where I was posting&#8230; some stuff is incredibly personal, other content maybe not so much. So, we&#8217;ll see. Stay Tuned.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webjedi.net/2011/08/18/first-post/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

