<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Blog Security: The Girl With the Dragon Tattoo Scares Me Into Taking It Seriously.</title>
	<atom:link href="http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/</link>
	<description>Blog Tips to Help You Make Money Blogging - ProBlogger</description>
	<lastBuildDate>Fri, 10 Feb 2012 17:04:37 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Bloxom Cheap</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-2/#comment-4839956</link>
		<dc:creator>Bloxom Cheap</dc:creator>
		<pubDate>Sat, 05 Jun 2010 08:37:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4839956</guid>
		<description>Learned as much as I would if I had written this.. nice post thanks!</description>
		<content:encoded><![CDATA[<p>Learned as much as I would if I had written this.. nice post thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sherise Mccoo</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-2/#comment-4835158</link>
		<dc:creator>Sherise Mccoo</dc:creator>
		<pubDate>Sat, 15 May 2010 00:35:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4835158</guid>
		<description>Hi there may I quote some of the material found in this blog if I reference you with a link back to your site?</description>
		<content:encoded><![CDATA[<p>Hi there may I quote some of the material found in this blog if I reference you with a link back to your site?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Demarcus Puzio</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-2/#comment-4830555</link>
		<dc:creator>Demarcus Puzio</dc:creator>
		<pubDate>Sat, 24 Apr 2010 13:38:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4830555</guid>
		<description>Genuinely wonderful !! I’ve just ordered a cellular app progress at codingate, they rapidly determined real critical and more than inexpensive developpers who created the thing in couple of times!!mobile - telecom and voip - web - desktop applications .</description>
		<content:encoded><![CDATA[<p>Genuinely wonderful !! I’ve just ordered a cellular app progress at codingate, they rapidly determined real critical and more than inexpensive developpers who created the thing in couple of times!!mobile &#8211; telecom and voip &#8211; web &#8211; desktop applications .</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pacific</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-2/#comment-4828411</link>
		<dc:creator>pacific</dc:creator>
		<pubDate>Tue, 13 Apr 2010 01:52:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4828411</guid>
		<description>I&#039;m so happy using blogger you could forget all about security only you have to do is write and write</description>
		<content:encoded><![CDATA[<p>I&#8217;m so happy using blogger you could forget all about security only you have to do is write and write</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Raymond</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-2/#comment-4826770</link>
		<dc:creator>Raymond</dc:creator>
		<pubDate>Mon, 05 Apr 2010 04:02:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4826770</guid>
		<description>You got numerous positive points there. I made a search on the issue and found nearly all peoples will agree with your blog.</description>
		<content:encoded><![CDATA[<p>You got numerous positive points there. I made a search on the issue and found nearly all peoples will agree with your blog.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Emo girls</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-2/#comment-4824893</link>
		<dc:creator>Emo girls</dc:creator>
		<pubDate>Thu, 25 Mar 2010 06:50:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4824893</guid>
		<description>I also liked this one =)) =^_^=</description>
		<content:encoded><![CDATA[<p>I also liked this one =)) =^_^=</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Emo girls</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-2/#comment-4824892</link>
		<dc:creator>Emo girls</dc:creator>
		<pubDate>Thu, 25 Mar 2010 06:47:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4824892</guid>
		<description>That was awe-awe-awe-some=)</description>
		<content:encoded><![CDATA[<p>That was awe-awe-awe-some=)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anne</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-2/#comment-4823409</link>
		<dc:creator>Anne</dc:creator>
		<pubDate>Wed, 17 Mar 2010 08:22:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4823409</guid>
		<description>Thanks for this post .I&#039;ve recently had the experience of one of my Wordpress blogs being hacked. Fortunately it was one which I had not done much work yet and I&#039;ve ended up completely deleting it and the wordpress installation. The first thing I know about it was when I went into the admin panel and it was all messed up. I then tried to access the blog and got a big red warning from Microsoft about it being a dangerous site. I decided to completely delete the entire blog and make a fresh start .

I will certainly be implementing your security tips on my main wordpress blog</description>
		<content:encoded><![CDATA[<p>Thanks for this post .I&#8217;ve recently had the experience of one of my WordPress blogs being hacked. Fortunately it was one which I had not done much work yet and I&#8217;ve ended up completely deleting it and the wordpress installation. The first thing I know about it was when I went into the admin panel and it was all messed up. I then tried to access the blog and got a big red warning from Microsoft about it being a dangerous site. I decided to completely delete the entire blog and make a fresh start .</p>
<p>I will certainly be implementing your security tips on my main wordpress blog</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Living with Balls</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-2/#comment-4823033</link>
		<dc:creator>Living with Balls</dc:creator>
		<pubDate>Mon, 15 Mar 2010 19:42:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4823033</guid>
		<description>Thanks for the tips! This is defintely a concern of mine as my blog continues to grow.  From now on I&#039;m making sure I backup once a week.</description>
		<content:encoded><![CDATA[<p>Thanks for the tips! This is defintely a concern of mine as my blog continues to grow.  From now on I&#8217;m making sure I backup once a week.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Russell Coker</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-2/#comment-4822964</link>
		<dc:creator>Russell Coker</dc:creator>
		<pubDate>Mon, 15 Mar 2010 12:54:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4822964</guid>
		<description>http://www.yubico.com/home/index/
http://henrik.schack.dk/yubikey-plugin/

I should have mentioned it before, generally it&#039;s regarded that for good computer security your access control should be based on &quot;something you have and something you know&quot;.  There are a variety of hardware devices you can use for authenticating yourself.  One of the cheapest and easiest is the Yubikey which emulates a USB keyboard and requires no special device driver support and no transcribing long numbers.

http://etbe.coker.com.au/2010/03/15/yubikey/

I&#039;ve written about some of the technical aspects of the Yubikey at the above URL.</description>
		<content:encoded><![CDATA[<p><a href="http://www.yubico.com/home/index/" rel="nofollow">http://www.yubico.com/home/index/</a><br />
<a href="http://henrik.schack.dk/yubikey-plugin/" rel="nofollow">http://henrik.schack.dk/yubikey-plugin/</a></p>
<p>I should have mentioned it before, generally it&#8217;s regarded that for good computer security your access control should be based on &#8220;something you have and something you know&#8221;.  There are a variety of hardware devices you can use for authenticating yourself.  One of the cheapest and easiest is the Yubikey which emulates a USB keyboard and requires no special device driver support and no transcribing long numbers.</p>
<p><a href="http://etbe.coker.com.au/2010/03/15/yubikey/" rel="nofollow">http://etbe.coker.com.au/2010/03/15/yubikey/</a></p>
<p>I&#8217;ve written about some of the technical aspects of the Yubikey at the above URL.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Russell Coker</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-2/#comment-4822512</link>
		<dc:creator>Russell Coker</dc:creator>
		<pubDate>Sat, 13 Mar 2010 10:40:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4822512</guid>
		<description>scheng1: If your site is of low value then an onscreen keyboard will avoid the simpler keyloggers.

But if someone was trying to attack a high value blog like Scoblizer then they wouldn&#039;t be stopped by such things.  Among other things an attacker who has a trojan installed (a pre-requisite for running a software keylogger) can hijack the session.  One thing they could do is hijack the logout button to simulate closing the session but allow the attacker to continue using the session.  If the session in question had administrative rights then the attacker could add new accounts.

One protection against trojans is to have multiple backups stored on removable media - and to hope that the attacker doesn&#039;t encrypt all files and hide the key (as some viruses have done in the past).

But really anything you do on a compromised platform is going to result in you losing if it&#039;s worth enough to an attacker.  It&#039;s best to just use a reliable system.

You could consider having one computer dedicated to doing nothing but blog administration (computers are cheap).  When viewing links from blog comments and reading other people&#039;s blogs use a different computer.  A Windows box that does nothing but talk to your blog server should be safe enough.

http://etbe.coker.com.au/2010/03/08/designing-secure-linux/

Or you could use an OS that doesn&#039;t tend to be prone to keylogger attacks, such as Linux.  The above URL has a post I recently wrote with some design ideas for a particularly secure Linux system.  Linux security is reasonably good but we can improve it.</description>
		<content:encoded><![CDATA[<p>scheng1: If your site is of low value then an onscreen keyboard will avoid the simpler keyloggers.</p>
<p>But if someone was trying to attack a high value blog like Scoblizer then they wouldn&#8217;t be stopped by such things.  Among other things an attacker who has a trojan installed (a pre-requisite for running a software keylogger) can hijack the session.  One thing they could do is hijack the logout button to simulate closing the session but allow the attacker to continue using the session.  If the session in question had administrative rights then the attacker could add new accounts.</p>
<p>One protection against trojans is to have multiple backups stored on removable media &#8211; and to hope that the attacker doesn&#8217;t encrypt all files and hide the key (as some viruses have done in the past).</p>
<p>But really anything you do on a compromised platform is going to result in you losing if it&#8217;s worth enough to an attacker.  It&#8217;s best to just use a reliable system.</p>
<p>You could consider having one computer dedicated to doing nothing but blog administration (computers are cheap).  When viewing links from blog comments and reading other people&#8217;s blogs use a different computer.  A Windows box that does nothing but talk to your blog server should be safe enough.</p>
<p><a href="http://etbe.coker.com.au/2010/03/08/designing-secure-linux/" rel="nofollow">http://etbe.coker.com.au/2010/03/08/designing-secure-linux/</a></p>
<p>Or you could use an OS that doesn&#8217;t tend to be prone to keylogger attacks, such as Linux.  The above URL has a post I recently wrote with some design ideas for a particularly secure Linux system.  Linux security is reasonably good but we can improve it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: scheng1</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-2/#comment-4822476</link>
		<dc:creator>scheng1</dc:creator>
		<pubDate>Sat, 13 Mar 2010 06:15:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4822476</guid>
		<description>haha, you sound like my mummy!  I like to add a bit about password.  It is better to use onscreen keyboard just in case a trojan horse program is installed in our computer.</description>
		<content:encoded><![CDATA[<p>haha, you sound like my mummy!  I like to add a bit about password.  It is better to use onscreen keyboard just in case a trojan horse program is installed in our computer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zach</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-1/#comment-4822317</link>
		<dc:creator>Zach</dc:creator>
		<pubDate>Fri, 12 Mar 2010 09:02:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4822317</guid>
		<description>Very good article.  There is a security plugin as well that will help patch up your Wordpress install:

http://wordpress.org/extend/plugins/secure-wordpress/

I have this installed on my blog along with a highly customized .htaccess and mod_security installed and configured.

@Ami, take out the Deny from all in .htaccess, and replace it with this:

# BEGIN WordPress

RewriteEngine On
RewriteBase /
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]


# END WordPress

That should get you started again.</description>
		<content:encoded><![CDATA[<p>Very good article.  There is a security plugin as well that will help patch up your WordPress install:</p>
<p><a href="http://wordpress.org/extend/plugins/secure-wordpress/" rel="nofollow">http://wordpress.org/extend/plugins/secure-wordpress/</a></p>
<p>I have this installed on my blog along with a highly customized .htaccess and mod_security installed and configured.</p>
<p>@Ami, take out the Deny from all in .htaccess, and replace it with this:</p>
<p># BEGIN WordPress</p>
<p>RewriteEngine On<br />
RewriteBase /<br />
RewriteCond %{REQUEST_FILENAME} !-f<br />
RewriteCond %{REQUEST_FILENAME} !-d<br />
RewriteRule . /index.php [L]</p>
<p># END WordPress</p>
<p>That should get you started again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: abercrombie london</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-1/#comment-4822311</link>
		<dc:creator>abercrombie london</dc:creator>
		<pubDate>Fri, 12 Mar 2010 08:29:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4822311</guid>
		<description>i love the girl with the dragon tatoo, it&#039;s fascinating. won’t hurt. But if you have a small number of people with Author-or-higher privs on your blog, just use better passwords. A good, long, unique, unguessable, non-dictionary password will make brute-forcing moot. I’ve never seen actual brute-force attacks — only “common passwords” attacks.</description>
		<content:encoded><![CDATA[<p>i love the girl with the dragon tatoo, it&#8217;s fascinating. won’t hurt. But if you have a small number of people with Author-or-higher privs on your blog, just use better passwords. A good, long, unique, unguessable, non-dictionary password will make brute-forcing moot. I’ve never seen actual brute-force attacks — only “common passwords” attacks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Russell Coker</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-1/#comment-4822286</link>
		<dc:creator>Russell Coker</dc:creator>
		<pubDate>Fri, 12 Mar 2010 06:45:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4822286</guid>
		<description>Remember to check your backups periodically, sometimes something goes wrong with the backup process and there&#039;s nothing that can be restored.

I recommend doing backups at the database level if possible.  I run a mysqldump on the database server and then scp the files to another system.  So even if something was going wrong with my blog it wouldn&#039;t affect the backups unless it had changed the database.

Make sure that your backups are under your control.  Emailing them to a gmail account etc is not good enough!  The data must end up on physical media that you personally own, preferably multiple pieces of media.  My blog backups are transferred daily to a RAID-1 array on my home server and I periodically back them up to removable drives.</description>
		<content:encoded><![CDATA[<p>Remember to check your backups periodically, sometimes something goes wrong with the backup process and there&#8217;s nothing that can be restored.</p>
<p>I recommend doing backups at the database level if possible.  I run a mysqldump on the database server and then scp the files to another system.  So even if something was going wrong with my blog it wouldn&#8217;t affect the backups unless it had changed the database.</p>
<p>Make sure that your backups are under your control.  Emailing them to a gmail account etc is not good enough!  The data must end up on physical media that you personally own, preferably multiple pieces of media.  My blog backups are transferred daily to a RAID-1 array on my home server and I periodically back them up to removable drives.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nimit Kashyap</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-1/#comment-4822280</link>
		<dc:creator>Nimit Kashyap</dc:creator>
		<pubDate>Fri, 12 Mar 2010 05:45:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4822280</guid>
		<description>wordpress security is  really a big issue, i had lost my previous blog because i didn&#039;t had the backup.</description>
		<content:encoded><![CDATA[<p>wordpress security is  really a big issue, i had lost my previous blog because i didn&#8217;t had the backup.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Samantha Milner</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-1/#comment-4822176</link>
		<dc:creator>Samantha Milner</dc:creator>
		<pubDate>Thu, 11 Mar 2010 19:27:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4822176</guid>
		<description>This was a very good blog.  It was fill with lots of advice.  I never heard of people hacking blogs.  I guess people will hacked anything these days.

Kind Regards,
Sam
   X</description>
		<content:encoded><![CDATA[<p>This was a very good blog.  It was fill with lots of advice.  I never heard of people hacking blogs.  I guess people will hacked anything these days.</p>
<p>Kind Regards,<br />
Sam<br />
   X</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Matthews</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-1/#comment-4822166</link>
		<dc:creator>Justin Matthews</dc:creator>
		<pubDate>Thu, 11 Mar 2010 18:40:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4822166</guid>
		<description>Very well written Kelly.  I too am in love with the internet.  My wife calls my laptop my mistress,but she is glad it is technology and not a real woman.  Something about fondling keys being better than other things.
Great Security heads up too, That book makes it seem way to easy to hack into anywhere.  And it can be!</description>
		<content:encoded><![CDATA[<p>Very well written Kelly.  I too am in love with the internet.  My wife calls my laptop my mistress,but she is glad it is technology and not a real woman.  Something about fondling keys being better than other things.<br />
Great Security heads up too, That book makes it seem way to easy to hack into anywhere.  And it can be!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Soares</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-1/#comment-4822136</link>
		<dc:creator>John Soares</dc:creator>
		<pubDate>Thu, 11 Mar 2010 15:58:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4822136</guid>
		<description>It&#039;s very important to have a good Wordpress theme that  will still work when you do updates. Before I switched to Thesis I had two blogs running on free themes. 

When I updated to a newer version of Wordpress, one theme crashed completely.</description>
		<content:encoded><![CDATA[<p>It&#8217;s very important to have a good WordPress theme that  will still work when you do updates. Before I switched to Thesis I had two blogs running on free themes. </p>
<p>When I updated to a newer version of WordPress, one theme crashed completely.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Deanna V</title>
		<link>http://www.problogger.net/archives/2010/03/11/blog-security-girl-with-dragon-tattoo-movie/comment-page-1/#comment-4822134</link>
		<dc:creator>Deanna V</dc:creator>
		<pubDate>Thu, 11 Mar 2010 15:54:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.problogger.net/?p=10646#comment-4822134</guid>
		<description>I don&#039;t even have my blog set up yet, and I&#039;m already loving reading all of these articles.  Your writing style is so entertaining and yes, I did learn something I won&#039;t forget.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t even have my blog set up yet, and I&#8217;m already loving reading all of these articles.  Your writing style is so entertaining and yes, I did learn something I won&#8217;t forget.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 1/26 queries in 0.093 seconds using memcached

Served from: www.problogger.net @ 2012-02-11 04:49:16 -->
