<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:pingback="http://madskills.com/public/xml/rss/module/pingback/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>The Wit and Ramblings of David Giard - Security</title>
    <link>http://www.davidgiard.com/</link>
    <description>Demanding rigidly defined areas of doubt and uncertainty</description>
    <language>en-us</language>
    <copyright>David Giard</copyright>
    <lastBuildDate>Mon, 24 Dec 2012 15:50:00 GMT</lastBuildDate>
    <generator>newtelligence dasBlog 2.0.7226.0</generator>
    <managingEditor>davidgiard@davidgiard.com</managingEditor>
    <webMaster>davidgiard@davidgiard.com</webMaster>
    <item>
      <trackback:ping>http://www.davidgiard.com/Trackback.aspx?guid=43b45121-f9a5-4001-ad93-5ec7e15ab8ce</trackback:ping>
      <pingback:server>http://www.davidgiard.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.davidgiard.com/PermaLink,guid,43b45121-f9a5-4001-ad93-5ec7e15ab8ce.aspx</pingback:target>
      <dc:creator>David Giard</dc:creator>
      <wfw:comment>http://www.davidgiard.com/CommentView,guid,43b45121-f9a5-4001-ad93-5ec7e15ab8ce.aspx</wfw:comment>
      <wfw:commentRss>http://www.davidgiard.com/SyndicationService.asmx/GetEntryCommentsRss?guid=43b45121-f9a5-4001-ad93-5ec7e15ab8ce</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <img border="0" src="http://www.davidgiard.com/content/binary/TechnologyAndFriends.gif" />
        </p>
        <p>
          <strong>Episode 245</strong>
        </p>
        <p>
          <a href="http://technologyandfriends.com/SubText/archive/2012/12/24/tf245.aspx" target="_blank"> Joe
Kuemerle on Reverse Engineering Applications </a>
        </p>
        <img width="0" height="0" src="http://www.davidgiard.com/aggbug.ashx?id=43b45121-f9a5-4001-ad93-5ec7e15ab8ce" />
      </body>
      <title>Joe Kuemerle on Reverse Engineering Applications</title>
      <guid isPermaLink="false">http://www.davidgiard.com/PermaLink,guid,43b45121-f9a5-4001-ad93-5ec7e15ab8ce.aspx</guid>
      <link>http://www.davidgiard.com/2012/12/24/JoeKuemerleOnReverseEngineeringApplications.aspx</link>
      <pubDate>Mon, 24 Dec 2012 15:50:00 GMT</pubDate>
      <description>&lt;p&gt;
&lt;img border="0" src="http://www.davidgiard.com/content/binary/TechnologyAndFriends.gif" /&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Episode 245&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://technologyandfriends.com/SubText/archive/2012/12/24/tf245.aspx" target="_blank"&gt; Joe
Kuemerle on Reverse Engineering Applications &lt;/a&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.davidgiard.com/aggbug.ashx?id=43b45121-f9a5-4001-ad93-5ec7e15ab8ce" /&gt;</description>
      <comments>http://www.davidgiard.com/CommentView,guid,43b45121-f9a5-4001-ad93-5ec7e15ab8ce.aspx</comments>
      <category>Security</category>
      <category>Technology and Friends</category>
      <category>Video</category>
    </item>
    <item>
      <trackback:ping>http://www.davidgiard.com/Trackback.aspx?guid=e7ee5dfe-8a5a-43ea-8ac0-0b65df7cde82</trackback:ping>
      <pingback:server>http://www.davidgiard.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.davidgiard.com/PermaLink,guid,e7ee5dfe-8a5a-43ea-8ac0-0b65df7cde82.aspx</pingback:target>
      <dc:creator>David Giard</dc:creator>
      <wfw:comment>http://www.davidgiard.com/CommentView,guid,e7ee5dfe-8a5a-43ea-8ac0-0b65df7cde82.aspx</wfw:comment>
      <wfw:commentRss>http://www.davidgiard.com/SyndicationService.asmx/GetEntryCommentsRss?guid=e7ee5dfe-8a5a-43ea-8ac0-0b65df7cde82</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <img border="0" src="http://www.davidgiard.com/content/binary/TechnologyAndFriends.gif" />
        </p>
        <p>
          <strong>Episode 244</strong>
        </p>
        <p>
          <a href="http://technologyandfriends.com/SubText/archive/2012/12/17/tf244.aspx" target="_blank"> Josh
Harrison on Azure Access Control service </a>
        </p>
        <img width="0" height="0" src="http://www.davidgiard.com/aggbug.ashx?id=e7ee5dfe-8a5a-43ea-8ac0-0b65df7cde82" />
      </body>
      <title>Josh Harrison on Azure Access Control service</title>
      <guid isPermaLink="false">http://www.davidgiard.com/PermaLink,guid,e7ee5dfe-8a5a-43ea-8ac0-0b65df7cde82.aspx</guid>
      <link>http://www.davidgiard.com/2012/12/17/JoshHarrisonOnAzureAccessControlService.aspx</link>
      <pubDate>Mon, 17 Dec 2012 15:13:00 GMT</pubDate>
      <description>&lt;p&gt;
&lt;img border="0" src="http://www.davidgiard.com/content/binary/TechnologyAndFriends.gif" /&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Episode 244&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://technologyandfriends.com/SubText/archive/2012/12/17/tf244.aspx" target="_blank"&gt; Josh
Harrison on Azure Access Control service &lt;/a&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.davidgiard.com/aggbug.ashx?id=e7ee5dfe-8a5a-43ea-8ac0-0b65df7cde82" /&gt;</description>
      <comments>http://www.davidgiard.com/CommentView,guid,e7ee5dfe-8a5a-43ea-8ac0-0b65df7cde82.aspx</comments>
      <category>Azure</category>
      <category>Security</category>
      <category>Technology and Friends</category>
      <category>Video</category>
    </item>
    <item>
      <trackback:ping>http://www.davidgiard.com/Trackback.aspx?guid=dcf5c057-0432-4ee4-9e60-b75d16eb2731</trackback:ping>
      <pingback:server>http://www.davidgiard.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.davidgiard.com/PermaLink,guid,dcf5c057-0432-4ee4-9e60-b75d16eb2731.aspx</pingback:target>
      <dc:creator>David Giard</dc:creator>
      <wfw:comment>http://www.davidgiard.com/CommentView,guid,dcf5c057-0432-4ee4-9e60-b75d16eb2731.aspx</wfw:comment>
      <wfw:commentRss>http://www.davidgiard.com/SyndicationService.asmx/GetEntryCommentsRss?guid=dcf5c057-0432-4ee4-9e60-b75d16eb2731</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
So last night I go to the bar to get all liquored up and I says to the bartender:
“Gimme my favourite getting-liquored-up drink – a dirty vodka martini with extra olives
and Grey Goose vodka.
</p>
        <p>
The bartender looks at me and he sees my cherubic countenance and he notices my boyish
charm and he says “Son, we have laws in this state. We are unable to serve anyone
who is under the age of 21. Can you prove to me that you are at least 21 years old?”
</p>
        <p>
“You bet I can!” I says to him. “Follow me!”
</p>
        <p>
And we go out back where my private jet is parked and we fly down to Tampa where he
meets my parents and they tell him how I was born during the Kennedy administration
and they explain how I was such a rotten kid that my dad went to the War in Vietnam
just to get a break from me.
</p>
        <p>
Then we get back in my private jet and we fly to Jacksonville, NC to the hospital
where I was born and they show us my birth certificate and the bartender asks me “Can
you prove that you are the David Giard listed on this birth certificate?” and I proceed
to provide him with blood samples and fingerprints and utility bills and all sorts
of evidence that I am in fact the David Giard listed on the Birth Certificate.
</p>
        <p>
So we fly back to the bar and the bartender says “OK, you’ve convinced me that you
are David Giard and that you were born more than 21 years ago” and he mixes up my
favourite getting-liquored-up drink and I drink it like the grown man that I am.
</p>
        <p>
Now…
</p>
        <p>
…Some of the above story is untrue.
</p>
        <p>
First, I don’t drink Grey Goose. I’m a Ketel One man.
</p>
        <p>
Second, I don’t own a private jet.
</p>
        <p>
And finally, the bartender does not have time to personally verify the identity and
age of every young whippersnapper who orders a drink. If he did so, he wouldn’t have
time to serve other whippersnappers and they would go away thirsty and cranky and
he wouldn’t make enough money to keep the bar open.
</p>
        <p>
Instead, the bartender has to trust someone else. But who can he trust? Probably not
me. As we’ve already seen, I am capable of telling a convincing story that is not
100% true.
</p>
        <p>
Of course, he will trust the government (because, if you can’t trust the government,
who can you trust?)
</p>
        <p>
In my case, he will trust the state government because months ago, I went to an office
run by the state of Michigan and I proved to them (by supplying a birth certificate,
a photo ID, a utility bill, and other documents) that I am David Giard and on what
date I was born. It turns out that the state government has been verifying such information
for a long time, so they are pretty good at it. When I had satisfied the government
office, they issued me a “token” verifying my identity and certain claims about me,
such as my date of birth. This token took the form of a Driver’s License. This Driver’s
License claims that my name is David Giard and that I was born on a specific date
and that I look like the photo in the corner of the license and that I reside at a
specific address.
</p>
        <p>
Claims-based authentication works exactly like this.
</p>
        <p>
In claims-based authentication, an application does not authenticate a user directly.
Instead, the application directs the user to a trusted authority (known as a “Secure
Token Service” or “STS”) and asks the STS to authenticate the user. In some cases,
this STS may even decide to ask some other STS that it trusts to authenticate the
user. When the user has been authenticated, the STS will create a token to return
to the application. This token contains proof of authentication, but it may also contain
a number of “Claims”. Claims are attributes about the user that are asserted by the
STS. Because the application trusts the STS, it will believe these claims about the
user.
</p>
        <p>
Much like the bartender believes the birth date on a valid driver’s license, the application
believes the claims contained in the token. And just like the bartender applies his
own rules based on the driver’s license claims (you must be 21 or over to drink),
the application can apply whatever rules it sees fit to authorize the user based on
claims contained in the token provided by the STS. For example, the application may
decide that only users in a given role may view certain pages in an application. Or
that certain links are disabled, unless a user has been with the company a certain
length of time. 
</p>
        <p>
Thus, the authentication (who is this user?) is outsourced to another application,
but the authentication (what can this user do?) is not.
</p>
        <img width="0" height="0" src="http://www.davidgiard.com/aggbug.ashx?id=dcf5c057-0432-4ee4-9e60-b75d16eb2731" />
      </body>
      <title>A Parable About Claims</title>
      <guid isPermaLink="false">http://www.davidgiard.com/PermaLink,guid,dcf5c057-0432-4ee4-9e60-b75d16eb2731.aspx</guid>
      <link>http://www.davidgiard.com/2012/11/09/AParableAboutClaims.aspx</link>
      <pubDate>Fri, 09 Nov 2012 13:22:00 GMT</pubDate>
      <description>&lt;p&gt;
So last night I go to the bar to get all liquored up and I says to the bartender:
“Gimme my favourite getting-liquored-up drink – a dirty vodka martini with extra olives
and Grey Goose vodka.
&lt;/p&gt;
&lt;p&gt;
The bartender looks at me and he sees my cherubic countenance and he notices my boyish
charm and he says “Son, we have laws in this state. We are unable to serve anyone
who is under the age of 21. Can you prove to me that you are at least 21 years old?”
&lt;/p&gt;
&lt;p&gt;
“You bet I can!” I says to him. “Follow me!”
&lt;/p&gt;
&lt;p&gt;
And we go out back where my private jet is parked and we fly down to Tampa where he
meets my parents and they tell him how I was born during the Kennedy administration
and they explain how I was such a rotten kid that my dad went to the War in Vietnam
just to get a break from me.
&lt;/p&gt;
&lt;p&gt;
Then we get back in my private jet and we fly to Jacksonville, NC to the hospital
where I was born and they show us my birth certificate and the bartender asks me “Can
you prove that you are the David Giard listed on this birth certificate?” and I proceed
to provide him with blood samples and fingerprints and utility bills and all sorts
of evidence that I am in fact the David Giard listed on the Birth Certificate.
&lt;/p&gt;
&lt;p&gt;
So we fly back to the bar and the bartender says “OK, you’ve convinced me that you
are David Giard and that you were born more than 21 years ago” and he mixes up my
favourite getting-liquored-up drink and I drink it like the grown man that I am.
&lt;/p&gt;
&lt;p&gt;
Now…
&lt;/p&gt;
&lt;p&gt;
…Some of the above story is untrue.
&lt;/p&gt;
&lt;p&gt;
First, I don’t drink Grey Goose. I’m a Ketel One man.
&lt;/p&gt;
&lt;p&gt;
Second, I don’t own a private jet.
&lt;/p&gt;
&lt;p&gt;
And finally, the bartender does not have time to personally verify the identity and
age of every young whippersnapper who orders a drink. If he did so, he wouldn’t have
time to serve other whippersnappers and they would go away thirsty and cranky and
he wouldn’t make enough money to keep the bar open.
&lt;/p&gt;
&lt;p&gt;
Instead, the bartender has to trust someone else. But who can he trust? Probably not
me. As we’ve already seen, I am capable of telling a convincing story that is not
100% true.
&lt;/p&gt;
&lt;p&gt;
Of course, he will trust the government (because, if you can’t trust the government,
who can you trust?)
&lt;/p&gt;
&lt;p&gt;
In my case, he will trust the state government because months ago, I went to an office
run by the state of Michigan and I proved to them (by supplying a birth certificate,
a photo ID, a utility bill, and other documents) that I am David Giard and on what
date I was born. It turns out that the state government has been verifying such information
for a long time, so they are pretty good at it. When I had satisfied the government
office, they issued me a “token” verifying my identity and certain claims about me,
such as my date of birth. This token took the form of a Driver’s License. This Driver’s
License claims that my name is David Giard and that I was born on a specific date
and that I look like the photo in the corner of the license and that I reside at a
specific address.
&lt;/p&gt;
&lt;p&gt;
Claims-based authentication works exactly like this.
&lt;/p&gt;
&lt;p&gt;
In claims-based authentication, an application does not authenticate a user directly.
Instead, the application directs the user to a trusted authority (known as a “Secure
Token Service” or “STS”) and asks the STS to authenticate the user. In some cases,
this STS may even decide to ask some other STS that it trusts to authenticate the
user. When the user has been authenticated, the STS will create a token to return
to the application. This token contains proof of authentication, but it may also contain
a number of “Claims”. Claims are attributes about the user that are asserted by the
STS. Because the application trusts the STS, it will believe these claims about the
user.
&lt;/p&gt;
&lt;p&gt;
Much like the bartender believes the birth date on a valid driver’s license, the application
believes the claims contained in the token. And just like the bartender applies his
own rules based on the driver’s license claims (you must be 21 or over to drink),
the application can apply whatever rules it sees fit to authorize the user based on
claims contained in the token provided by the STS. For example, the application may
decide that only users in a given role may view certain pages in an application. Or
that certain links are disabled, unless a user has been with the company a certain
length of time. 
&lt;/p&gt;
&lt;p&gt;
Thus, the authentication (who is this user?) is outsourced to another application,
but the authentication (what can this user do?) is not.
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.davidgiard.com/aggbug.ashx?id=dcf5c057-0432-4ee4-9e60-b75d16eb2731" /&gt;</description>
      <comments>http://www.davidgiard.com/CommentView,guid,dcf5c057-0432-4ee4-9e60-b75d16eb2731.aspx</comments>
      <category>Security</category>
    </item>
    <item>
      <trackback:ping>http://www.davidgiard.com/Trackback.aspx?guid=836508ba-6774-4ee8-bd83-646d40d24763</trackback:ping>
      <pingback:server>http://www.davidgiard.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.davidgiard.com/PermaLink,guid,836508ba-6774-4ee8-bd83-646d40d24763.aspx</pingback:target>
      <dc:creator>David Giard</dc:creator>
      <wfw:comment>http://www.davidgiard.com/CommentView,guid,836508ba-6774-4ee8-bd83-646d40d24763.aspx</wfw:comment>
      <wfw:commentRss>http://www.davidgiard.com/SyndicationService.asmx/GetEntryCommentsRss?guid=836508ba-6774-4ee8-bd83-646d40d24763</wfw:commentRss>
      <slash:comments>2</slash:comments>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <img border="0" src="http://www.davidgiard.com/content/binary/TechnologyAndFriends.gif" />
        </p>
        <p>
          <strong>Episode 219</strong>
        </p>
        <p>
          <a href="http://technologyandfriends.com/SubText/archive/2012/07/02/tf219.aspx" target="_blank">Vittorio
Bertocci on WIF</a>
        </p>
        <img width="0" height="0" src="http://www.davidgiard.com/aggbug.ashx?id=836508ba-6774-4ee8-bd83-646d40d24763" />
      </body>
      <title>Vittorio Bertocci on WIF</title>
      <guid isPermaLink="false">http://www.davidgiard.com/PermaLink,guid,836508ba-6774-4ee8-bd83-646d40d24763.aspx</guid>
      <link>http://www.davidgiard.com/2012/07/02/VittorioBertocciOnWIF.aspx</link>
      <pubDate>Mon, 02 Jul 2012 14:47:00 GMT</pubDate>
      <description>&lt;p&gt;
&lt;img border="0" src="http://www.davidgiard.com/content/binary/TechnologyAndFriends.gif" /&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Episode 219&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://technologyandfriends.com/SubText/archive/2012/07/02/tf219.aspx" target="_blank"&gt;Vittorio
Bertocci on WIF&lt;/a&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.davidgiard.com/aggbug.ashx?id=836508ba-6774-4ee8-bd83-646d40d24763" /&gt;</description>
      <comments>http://www.davidgiard.com/CommentView,guid,836508ba-6774-4ee8-bd83-646d40d24763.aspx</comments>
      <category>Security</category>
      <category>Technology and Friends</category>
      <category>Video</category>
    </item>
    <item>
      <trackback:ping>http://www.davidgiard.com/Trackback.aspx?guid=626cd51b-7ac2-49f3-bc5b-6e32f0e7b9de</trackback:ping>
      <pingback:server>http://www.davidgiard.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.davidgiard.com/PermaLink,guid,626cd51b-7ac2-49f3-bc5b-6e32f0e7b9de.aspx</pingback:target>
      <dc:creator>David Giard</dc:creator>
      <wfw:comment>http://www.davidgiard.com/CommentView,guid,626cd51b-7ac2-49f3-bc5b-6e32f0e7b9de.aspx</wfw:comment>
      <wfw:commentRss>http://www.davidgiard.com/SyndicationService.asmx/GetEntryCommentsRss?guid=626cd51b-7ac2-49f3-bc5b-6e32f0e7b9de</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <img border="0" src="http://www.davidgiard.com/content/binary/TechnologyAndFriends.gif" />
        </p>
        <p>
          <strong>Episode 207</strong>
        </p>
        <p>
          <a href="http://technologyandfriends.com/SubText/archive/2012/04/23/tf207.aspx" target="_blank">Troy
Hunt on ASP.NET Security </a>
        </p>
        <img width="0" height="0" src="http://www.davidgiard.com/aggbug.ashx?id=626cd51b-7ac2-49f3-bc5b-6e32f0e7b9de" />
      </body>
      <title>Troy Hunt on ASP.NET Security</title>
      <guid isPermaLink="false">http://www.davidgiard.com/PermaLink,guid,626cd51b-7ac2-49f3-bc5b-6e32f0e7b9de.aspx</guid>
      <link>http://www.davidgiard.com/2012/04/23/TroyHuntOnASPNETSecurity.aspx</link>
      <pubDate>Mon, 23 Apr 2012 20:37:00 GMT</pubDate>
      <description>&lt;p&gt;
&lt;img border="0" src="http://www.davidgiard.com/content/binary/TechnologyAndFriends.gif" /&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Episode 207&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://technologyandfriends.com/SubText/archive/2012/04/23/tf207.aspx" target="_blank"&gt;Troy
Hunt on ASP.NET Security &lt;/a&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.davidgiard.com/aggbug.ashx?id=626cd51b-7ac2-49f3-bc5b-6e32f0e7b9de" /&gt;</description>
      <comments>http://www.davidgiard.com/CommentView,guid,626cd51b-7ac2-49f3-bc5b-6e32f0e7b9de.aspx</comments>
      <category>ASP.NET</category>
      <category>Security</category>
      <category>Technology and Friends</category>
      <category>Video</category>
    </item>
    <item>
      <trackback:ping>http://www.davidgiard.com/Trackback.aspx?guid=5c62098e-761a-4ac2-8cf2-4d52659eb5d2</trackback:ping>
      <pingback:server>http://www.davidgiard.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.davidgiard.com/PermaLink,guid,5c62098e-761a-4ac2-8cf2-4d52659eb5d2.aspx</pingback:target>
      <dc:creator>David Giard</dc:creator>
      <wfw:comment>http://www.davidgiard.com/CommentView,guid,5c62098e-761a-4ac2-8cf2-4d52659eb5d2.aspx</wfw:comment>
      <wfw:commentRss>http://www.davidgiard.com/SyndicationService.asmx/GetEntryCommentsRss?guid=5c62098e-761a-4ac2-8cf2-4d52659eb5d2</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <img border="0" src="http://www.davidgiard.com/content/binary/TechnologyAndFriends.gif" />
        </p>
        <p>
          <strong>Episode 198 </strong>
        </p>
        <p>
          <a href="http://technologyandfriends.com/SubText/archive/2012/02/27/tf198.aspx" target="_blank">Bill
Sempf on Security</a>
        </p>
        <img width="0" height="0" src="http://www.davidgiard.com/aggbug.ashx?id=5c62098e-761a-4ac2-8cf2-4d52659eb5d2" />
      </body>
      <title>Bill Sempf on Security</title>
      <guid isPermaLink="false">http://www.davidgiard.com/PermaLink,guid,5c62098e-761a-4ac2-8cf2-4d52659eb5d2.aspx</guid>
      <link>http://www.davidgiard.com/2012/02/27/BillSempfOnSecurity.aspx</link>
      <pubDate>Mon, 27 Feb 2012 20:33:00 GMT</pubDate>
      <description>&lt;p&gt;
&lt;img border="0" src="http://www.davidgiard.com/content/binary/TechnologyAndFriends.gif" /&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Episode 198 &lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://technologyandfriends.com/SubText/archive/2012/02/27/tf198.aspx" target="_blank"&gt;Bill
Sempf on Security&lt;/a&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.davidgiard.com/aggbug.ashx?id=5c62098e-761a-4ac2-8cf2-4d52659eb5d2" /&gt;</description>
      <comments>http://www.davidgiard.com/CommentView,guid,5c62098e-761a-4ac2-8cf2-4d52659eb5d2.aspx</comments>
      <category>Security</category>
      <category>Technology and Friends</category>
      <category>Video</category>
    </item>
  </channel>
</rss>