<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>&#60;em&#62;{}&#60;/em&#62; &#187; Security</title>
	<atom:link href="http://www.cbvenkat.net/topics/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cbvenkat.net</link>
	<description>Embrace, an Indic Tech Blog</description>
	<lastBuildDate>Thu, 26 Aug 2010 07:24:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Adding TRUST to mobile platforms</title>
		<link>http://www.cbvenkat.net/2009/10/29/adding-trust-to-mobile-platforms/</link>
		<comments>http://www.cbvenkat.net/2009/10/29/adding-trust-to-mobile-platforms/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 14:48:24 +0000</pubDate>
		<dc:creator>Venkatraman Balasubramanian</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.cbvenkat.net/2009/10/29/adding-trust-to-mobile-platforms/</guid>
		<description><![CDATA[I have been thinking after noticing the Common Criteria EAL4 certification awarded to Microsoft Mobile 6.1. This certification makes me think that Microsoft Mobile 6.1 based devices are secured better than the other Mobile OS implementations. In the market, we see more operating systems showing-up in the Mobile devices which are used for personal, enterprise [...]]]></description>
			<content:encoded><![CDATA[<p>I have been thinking after noticing the <a href="http://www.microsoft.com/industry/government/press/Common_Criteria_0809.mspx">Common Criteria EAL4 certification awarded to Microsoft Mobile 6.1</a>. This certification makes me think that Microsoft Mobile 6.1 based devices are secured better than the other Mobile OS implementations. In the market, we see more operating systems showing-up in the Mobile devices which are used for personal, enterprise and sensitive (gov) needs.</p>
<p>Its a given fact that some vendors have a very strong hold on what can be be deployed or even run (Apple&#8217;s ability to, preemptively, remote administer my phone and uninstall an application is a scary thought) on these devices. Most of OS vendors want our applications to be digitally signed by them, some force their own software delivery platform on us.<br />
<span id="more-116"></span><br />
We have Snapdragon like hardware platforms available in the market. General purpose OS implementations for Mobile devices is a good way to progress. My wish is to have some more hardware innovation from the industry and leap to the next horizon in the mobility segment. May be we would have a choice to buy a brand new phone and have a option to install a OS of our choice (Android, Windows Mobile, Symbian, Maemo, etc.,)</p>
<p>Is there a need to look at how we trust the OS vendors and their implementations that run most of our mobile devices?.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cbvenkat.net/2009/10/29/adding-trust-to-mobile-platforms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure OS &#124; EAL 6+</title>
		<link>http://www.cbvenkat.net/2008/11/27/secure-os-eal-6/</link>
		<comments>http://www.cbvenkat.net/2008/11/27/secure-os-eal-6/#comments</comments>
		<pubDate>Thu, 27 Nov 2008 08:20:06 +0000</pubDate>
		<dc:creator>Venkatraman Balasubramanian</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.cbvenkat.net/?p=45</guid>
		<description><![CDATA[Green Hills Software Inc has raised the bar for the Operating System Software Vendors. It is very nice to see their Commercial Operating System certified by the National Information Assurance Partnership (NIAP), a U.S. government initiative operated by the National Security Agency (NSA), to Common Criteria Evaluation Assurance Level (EAL) 6+, High Robustness.
http://www.marketwire.com/press-release/Green-Hills-Software-Inc-921108.html

The mainstream Operating [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.ghs.com/">Green Hills Software Inc</a> has raised the bar for the Operating System Software Vendors. It is very nice to see their Commercial Operating System certified by the National Information Assurance Partnership (NIAP), a U.S. government initiative operated by the National Security Agency (NSA), to Common Criteria Evaluation Assurance Level (EAL) 6+, High Robustness.</p>
<div id="attachment_113" class="wp-caption aligncenter" style="width: 310px"><img src="http://www.cbvenkat.net/wp-content/uploads/2009/09/greenhillssoftwareincintegritycc-eal6-300x205.png" alt="Green Hills Software Inc. Integrity RTOS EAL 6+ Certificate" title="Green Hills Software Inc. Integrity RTOS EAL 6+ Certificate" width="300" height="205" class="size-medium wp-image-113" /><p class="wp-caption-text">Green Hills Software Inc. Integrity RTOS EAL 6+ Certificate</p></div>
<p><a href="http://www.marketwire.com/press-release/Green-Hills-Software-Inc-921108.html">http://www.marketwire.com/press-release/Green-Hills-Software-Inc-921108.html<br />
</a></p>
<p>The mainstream Operating System Software Vendors have been able to get only up to EAL 4+. This is pushes STOP 7 (EAL 5+) from BAE Systems as the Second Most Secured Operating System. It is interesting to note that WindRiver is also working in getting their VxWorks RTOS certified at EAL 6+.<br />
<span id="more-45"></span><br />
The above Common Criteria Evaluation information is primarily for the Operating System and not for the applications running inside the Operating System. This means that a Python/PHP application deployed under this EAL6+ environment can still be vulnerable and allow a SQL Injection Attack. Everybody can be benefited with the usage of Secure environment, provided the entire development community is conscious about the intricacies involved in securing the environment and develop secure applications. </p>
<p><a href="http://www.commoncriteriaportal.org/">Common Criteria Evaluation</a> and <a href="https://www.trustedcomputinggroup.org/home">Trusted Computing</a> help us organize the very foundation (the OS and where it runs) of creating a secure environment. Now it is still within the reach of the best minds in the Open Source world to come-up with a Open Source Implementation covering both Software and Hardware parts of a EAL 6+/7 Solution. It would help even SMEs to work in a secure environment. Wouldn&#8217;t that be worth the cause?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cbvenkat.net/2008/11/27/secure-os-eal-6/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
