<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ERNW White Paper on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/ernw-white-paper/</link>
    <description>Recent content in ERNW White Paper on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 12 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/ernw-white-paper/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>ERNW White Paper 79: Integrating Incident Analysis and Digital Forensics Tooling for Automated Compromise Detection</title>
      <link>https://insinuator.net/2026/08/ernw-white-paper-79-integrating-incident-analysis-and-digital-forensics-tooling-for-automated-compromise-detection/</link>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/08/ernw-white-paper-79-integrating-incident-analysis-and-digital-forensics-tooling-for-automated-compromise-detection/</guid>
      <description>&lt;p&gt;With this blog post I am pleased to announce the publication of a new ERNW White Paper about our incident analysis and digital forensics framework. It is available on our &lt;a href=&#34;https://ernw.de/en/whitepapers/issue-79.html&#34;&gt;website&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Due to the increasing number and impact of computer security incidents, it has become essential to develop and implement efficient measures for their investigation. However, comprehensive forensic analyses are time-consuming, and this time is often not available to security analysts during computer security incidents. As a result, automated tools are increasingly being used. These tools, however, often cover only a limited scope of the necessary analyses and typically require deep technical expertise to be used effectively.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW White Paper 77: Unified Security Hardening with Cross-Platform Native Binaries</title>
      <link>https://insinuator.net/2026/05/ernw-white-paper-77-unified-security-hardening-with-cross-platform-native-binaries/</link>
      <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/05/ernw-white-paper-77-unified-security-hardening-with-cross-platform-native-binaries/</guid>
      <description>&lt;p&gt;When configuring a new device, achieving an acceptable Lynis hardening score is&#xA;a challenge most practitioners are familiar with.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Whitepaper 76: Linux Client Hardening Guide</title>
      <link>https://insinuator.net/2026/05/ernw-whitepaper-76-linux-client-hardening-guide/</link>
      <pubDate>Tue, 19 May 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/05/ernw-whitepaper-76-linux-client-hardening-guide/</guid>
      <description>&lt;p&gt;Hardening a Linux client system to an acceptable degree is a time-consuming&#xA;process, one that demands familiarity with a broad set of configuration&#xA;parameters, framework recommendations, and the reasoning behind each control.&lt;/p&gt;&#xA;&lt;p&gt;This post introduces our new Linux client hardening guide&#xA;(&lt;a href=&#34;https://github.com/ernw/hardening/blob/master/operating_system/linux/ERNW_Hardening_Linux.md&#34;&gt;MD&lt;/a&gt;,&#xA;&lt;a href=&#34;https://ernw.de/en/whitepapers/issue-76.html&#34;&gt;PDF&lt;/a&gt;), a comprehensive, publicly&#xA;available hardening reference for Linux systems.&lt;/p&gt;&#xA;&lt;h2 id=&#34;motivation-and-scope&#34;&gt;Motivation and Scope&lt;/h2&gt;&#xA;&lt;p&gt;The guide covers the full breadth of controls needed to significantly raise the&#xA;security posture of a modern Linux installation while preserving operational&#xA;usability (this will be very subjective, the guide reflects my opinion of&#xA;“usable”). It has been developed and validated against Ubuntu 24.04 LTS as the&#xA;primary reference platform, and cross-tested on Fedora, Debian 12, and Arch&#xA;Linux as well as on traditionally server-oriented distributions like openSUSE&#xA;Leap 15.6, Debian 12, Rocky Linux 9, and Red Hat Enterprise Linux 9 while not&#xA;focussing on those as the guide is created for Linux clients.&lt;/p&gt;</description>
    </item>
    <item>
      <title>One More Thing: Introducing the New macOS 26 Tahoe Hardening Guide</title>
      <link>https://insinuator.net/2026/02/one-more-thing-introducing-the-new-macos-26-tahoe-hardening-guide/</link>
      <pubDate>Wed, 11 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/02/one-more-thing-introducing-the-new-macos-26-tahoe-hardening-guide/</guid>
      <description>&lt;p&gt;After seven years, we’re publishing a new macOS hardening guide. Fully updated,&#xA;modernized, and now publicly available on&#xA;&lt;a href=&#34;https://github.com/ernw/hardening/blob/master/operating_system/osx/26/Hardening_Guide-macOS_26_Tahoe_1.0.md&#34;&gt;GitHub&lt;/a&gt;&#xA;as&#xA;&lt;a href=&#34;https://github.com/ernw/hardening/blob/master/operating_system/osx/26/Hardening_Guide-macOS_26_Tahoe_1.0.md&#34;&gt;Markdown&lt;/a&gt;&#xA;and on our &lt;a href=&#34;https://ernw.de/en/whitepapers/issue-75.html&#34;&gt;website&lt;/a&gt; as&#xA;&lt;a href=&#34;https://ernw.de/en/whitepapers/issue-75.html&#34;&gt;PDF&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The previous guide, written for macOS Mojave (10.14), reflected a very different&#xA;macOS security model. At the time, hardening often meant working around the&#xA;operating system, manually enforcing controls, and compensating for missing&#xA;platform guarantees. That guide served its purpose, but the platform has&#xA;fundamentally changed since then.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Release of ERNW White Paper 73: Analyzing WinpMem Driver Vulnerabilities</title>
      <link>https://insinuator.net/2025/10/release-of-ernw-white-paper-73-analyzing-winpmem-driver-vulnerabilities/</link>
      <pubDate>Thu, 02 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/10/release-of-ernw-white-paper-73-analyzing-winpmem-driver-vulnerabilities/</guid>
      <description>&lt;p&gt;Today we are releasing a new white paper that delivers a technical analysis of&#xA;security weaknesses discovered in WinpMem, an open-source Windows memory&#xA;acquisition driver widely used in digital forensics.&lt;/p&gt;&#xA;&lt;p&gt;After a concise primer on relevant Windows internals (virtual vs. physical&#xA;memory, page tables and PTEs, CR3 context switching, and kernel and user memory&#xA;separation), the report examines how both the fundamental design of WinpMem and&#xA;specific implementation choices create severe risk.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Whitepaper 71: Analysis of Anti-Virus Software Quarantine Files</title>
      <link>https://insinuator.net/2021/01/ernw-whitepaper-71-analysis-of-anti-virus-software-quarantine-files/</link>
      <pubDate>Wed, 27 Jan 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/01/ernw-whitepaper-71-analysis-of-anti-virus-software-quarantine-files/</guid>
      <description>&lt;p&gt;I am glad to announce the release of the ERNW whitepaper 71 containing&#xA;information about quarantine file formats of different AV software vendors. It&#xA;is available&#xA;&lt;a href=&#34;https://static.ernw.de/whitepaper/ERNW-Whitepaper-71_AV_Quarantine_signed.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;anti-virus-software&#34;&gt;Anti-Virus Software&lt;/h2&gt;&#xA;&lt;p&gt;I took quarantine files from real-life incidents and created some in a lab&#xA;environment. Afterwards I tried to identify metadata, like timestamps, path&#xA;names, malware names, and the actual malicious file in the quarantine files. One&#xA;goal was to use this information to support our incident analyses: Using the&#xA;results, we can now easily create timelines showing information about&#xA;quarantined files, extract the detected malware, and sometimes even find&#xA;information about processes that created the malicious files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW White Paper 70 – HL7 FHIR: Preserving Distributed Resource Integrity</title>
      <link>https://insinuator.net/2020/12/ernw-white-paper-70-hl7-fhir-preserving-distributed-resource-integrity/</link>
      <pubDate>Fri, 18 Dec 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/12/ernw-white-paper-70-hl7-fhir-preserving-distributed-resource-integrity/</guid>
      <description>&lt;p&gt;With this blog post I am pleased to announce the publication of a new ERNW White Paper about the HL7 FHIR communication standard.&lt;/p&gt;&#xA;&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;Digital networking is already widespread in many areas of life. More and more medical devices are also being networked in the healthcare industry. This growth makes the development and use of new medical communication standards necessary since existing solutions can only meet the changing requirements with great effort. The HL7 FHIR standard is an example of such a medical communication standard. FHIR is said to have increased the interoperability between different medical contexts,e.g., administration, billing, and clinical care, to enable data exchange of various systems. The FHIR standard addresses the security risks associated with strongly networked communication from a large number of systems across the trust and organizational boundaries only indirectly because FHIR does not define mandatory security controls or requirements.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW White Paper 69 – Safety Impact of Vulnerabilities in Insulin Pumps</title>
      <link>https://insinuator.net/2020/09/ernw-white-paper-69-safety-impact-of-vulnerabilities-in-insulin-pumps/</link>
      <pubDate>Fri, 11 Sep 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/09/ernw-white-paper-69-safety-impact-of-vulnerabilities-in-insulin-pumps/</guid>
      <description>&lt;p&gt;With this blog post I am pleased to announce the publication of a new ERNW White Paper &lt;a href=&#34;https://ernw-research.de/en/whitepapers/issue-69.html&#34;&gt;[1]&lt;/a&gt;. The paper is about severe vulnerabilities in an insulin pump we assessed during project ManiMed and we are proud to publish this subset of the results today.&lt;/p&gt;&#xA;&lt;h2 id=&#34;manipulating-medical-devices&#34;&gt;Manipulating Medical Devices&lt;/h2&gt;&#xA;&lt;p&gt;The German Federal Office for Information Security (BSI), in its role as the Federal Cyber Security Authority in Germany, aims to sensitize manufacturers and the public regarding security risks of networked medical devices. In response to the often fatal security reports and press releases of networked medical devices, the BSI initiated the project Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security analysis of selected products is carried out through security assessments. In the context of this project, severe vulnerabilities were identified during the assessment of the DANA Diabecare RS system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Whitepaper 67: Active Directory Trust Considerations</title>
      <link>https://insinuator.net/2018/12/ernw-whitepaper-67-active-directory-trust-considerations/</link>
      <pubDate>Tue, 11 Dec 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/12/ernw-whitepaper-67-active-directory-trust-considerations/</guid>
      <description>&lt;p&gt;Last week &lt;a href=&#34;https://twitter.com/HarmJ0y&#34;&gt;Will “harmj0y” Schroeder&lt;/a&gt; published an excellent technical article titled &lt;a href=&#34;https://www.harmj0y.net/blog/redteaming/not-a-security-boundary-breaking-forest-trusts/&#34;&gt;“Not A Security Boundary: Breaking Forest Trusts”&lt;/a&gt; in which he lays out how a highly critical security compromise can be achieved across a forest boundary, resulting from a combination of default AD (security) settings and a novel attack method. His post is a follow-up to the DerbyCon talk “The Unintended Risks of Trusting Active Directory” which he had given together with &lt;a href=&#34;https://twitter.com/tifkin_&#34;&gt;Lee Christensen&lt;/a&gt; and &lt;a href=&#34;https://twitter.com/enigma0x3&#34;&gt;Matt Nelson&lt;/a&gt; at DerbyCon (video &lt;a href=&#34;http://www.irongeek.com/i.php?page=videos/derbycon8/track-2-03-the-unintended-risks-of-trusting-active-directory-lee-christensen-will-schroeder-matt-nelson&#34;&gt;here&lt;/a&gt;). They will also discuss this at the upcoming &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt; Active Directory Security Track (details on some more talks, including &lt;a href=&#34;https://twitter.com/PyroTek3&#34;&gt;Sean Metcalf’s&lt;/a&gt; one, can be found in &lt;a href=&#34;https://insinuator.net/2018/11/first-talks-of-troopers19-accepted/&#34;&gt;this post&lt;/a&gt; or &lt;a href=&#34;https://insinuator.net/2018/12/and-five-talks-more-were-accepted-at-troopers19/&#34;&gt;this one&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>White Paper on Incident Analysis and Forensics in Docker Environments</title>
      <link>https://insinuator.net/2018/02/white-paper-on-incident-analysis-and-forensics-in-docker-environments/</link>
      <pubDate>Wed, 14 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/white-paper-on-incident-analysis-and-forensics-in-docker-environments/</guid>
      <description>&lt;p&gt;In this article, we describe the impact of the increased use of &lt;em&gt;Docker&lt;/em&gt; in corporate environments on forensic investigations and incident analysis. Even though Docker is being used more and more (Portworx, Inc., 2017), the implications of the changed runtime environment for forensic processes and tools have barely been considered. We describe the technological basics of Docker and, based on them, outline the differences that occur with respect to digital evidence and previously used methods for evidence acquisition. Specifically, we look at digital evidence within a Docker container which are lost or need to be acquired in different ways compared to a classical virtual machine, and what new traces and opportunities arise from Docker itself.&lt;/p&gt;</description>
    </item>
    <item>
      <title>White Paper on Multi-Factor Authentication in Microsoft Windows Environments</title>
      <link>https://insinuator.net/2018/01/white-paper-on-multi-factor-authentication-in-microsoft-windows-environments/</link>
      <pubDate>Mon, 29 Jan 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/01/white-paper-on-multi-factor-authentication-in-microsoft-windows-environments/</guid>
      <description>&lt;p&gt;A new ERNW whitepaper was just published. I wrote this whitepaper in the course of my bachelor thesis and it examines multi-factor authentication in Microsoft Windows environments:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Credential theft and the subsequent reuse of stolen credentials are a significant problem in today’s information security. To counter the associated risks, a planned approach is required as part of a comprehensive security architecture program. This includes the implementation of multi-factor authentication as an important building block. This whitepaper covers the relevant steps of implementing a multi-factor authentication system in an enterprise environment and closes with a security evaluation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>White Paper on Incident Handling First Steps, Preparation Plans, and Process Models</title>
      <link>https://insinuator.net/2017/02/white-paper-on-incident-handling-first-steps-preparation-plans-and-process-models/</link>
      <pubDate>Wed, 01 Feb 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/02/white-paper-on-incident-handling-first-steps-preparation-plans-and-process-models/</guid>
      <description>&lt;p&gt;We just published my &lt;a href=&#34;https://www.ernw.de/download/newsletter/ERNW_Whitepaper58_IncidentHandlingFirstSteps_signed.pdf&#34;&gt;Whitepaper about First Steps, Preparation Plans, and Process Models for Incident Handling&lt;/a&gt;, that I wrote to pass the time between Christmas and New Year. The whitepaper sums up information that I consider to be useful to prepare for IT security incidents as a conclusion from the incidents in which we supported over the past year.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/newsletter/ERNW_Whitepaper58_IncidentHandlingFirstSteps_signed.pdf&#34;&gt;&lt;img src=&#34;teaser.jpg&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Have you for example thought about classes of incidents that are most likely to affect you and formulated Incident Handling Preparation Plans for those incidents?&lt;/p&gt;</description>
    </item>
    <item>
      <title>An MLD Testing Methodology</title>
      <link>https://insinuator.net/2015/03/an-mld-testing-methodology/</link>
      <pubDate>Fri, 06 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/an-mld-testing-methodology/</guid>
      <description>&lt;p&gt;Based on recent research in the ERNW IPv6 lab and with &lt;a href=&#34;https://www.troopers.de/events/troopers15/467_mld_considered_harmful__breaking_another_ipv6_subprotocol/&#34;&gt;our MLD talk&lt;/a&gt; looming we’ve put together a (as we think) comprehensive document discussing how to thoroughly test MLD implementations in various components (network devices or servers/clients). We hope it can contribute to a better understanding of the protocol and that it can serve as either a checklist for your own environment or as a source of inspiration for researchers looking at MLD themselves.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Evaluation of IPv6 Capabilities of Commercial IPAM Solutions</title>
      <link>https://insinuator.net/2015/01/evaluation-of-ipv6-capabilities-of-commercial-ipam-solutions/</link>
      <pubDate>Wed, 28 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/evaluation-of-ipv6-capabilities-of-commercial-ipam-solutions/</guid>
      <description>&lt;p&gt;Originating from a customer IPv6 deployment project, in early 2014 we defined a number of requirements as for the IPv6 capabilities of IPAM solutions, with a certain focus on security-related requirements (due to the specific environment of the project). We subsequently performed a practical evaluation of several commercial solutions, based on documentation, lab implementation and vendor communication.&lt;/p&gt;&#xA;&lt;p&gt;We just released &lt;a href=&#34;https://www.ernw.de/download/newsletter/ERNW_Newsletter_46_Evaluation_of_Commercial_IPAM_Solutions_IPv6_Capabilities.pdf&#34;&gt;a newsletter describing the requirements and the results of the evaluation&lt;/a&gt;.&lt;br&gt;&#xA;It should be noted that in the interim newer versions of the evaluated products might be available which might have enhanced features. Hence, from our perspective, understanding the requirements of an individual environment might even be more important than the actual results described in that document (as those only reflect a certain point of time). We hope to contribute here to a well-informed requirements definition and decision taking process on your side.&lt;br&gt;&#xA;Feel free to get back to us on any of the points laid out or, even better, join us at the Troopers &lt;a href=&#34;https://www.troopers.de/events/troopers15/322_ipv6_security_summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt; in Heidelberg on Mar 16th/17th in order to discuss any related points.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamics of IPv6 Prefixes within the LIR Scope in the RIPE NCC Region</title>
      <link>https://insinuator.net/2014/11/dynamics-of-ipv6-prefixes-within-the-lir-scope-in-the-ripe-ncc-region/</link>
      <pubDate>Thu, 06 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/dynamics-of-ipv6-prefixes-within-the-lir-scope-in-the-ripe-ncc-region/</guid>
      <description>&lt;p&gt;To contribute to the &lt;a href=&#34;http://www.insinuator.net/2014/10/deaggregation-by-large-organizations/&#34;&gt;current debate&lt;/a&gt; on IPv6 route deaggregation &amp;amp; “strict-filtering” performed by certain ISPs we just released a white paper on “&lt;a href=&#34;https://www.ernw.de/newsletter/newsletter-44-november-2014-dynamics-of-ipv6-prefixes-within-the-lir-scope-in-the-ripe-ncc-region/index.html&#34;&gt;Dynamics of IPv6 Prefixes within the LIR Scope in the RIPE NCC Region&lt;/a&gt;“. I will give a &lt;a href=&#34;https://ripe69.ripe.net/wp-content/uploads/presentations/137-RIPE69_Langner_Rey_Schaetzle_Slash48_Considered_Harmful.pdf&#34;&gt;talk&lt;/a&gt; on the overall topic later today at the &lt;em&gt;Routing Working Group&lt;/em&gt;. We sincerely hope that the IPv6 community becomes aware of the inherent issues, and that practical solutions can be found which consider &amp;amp; meet the needs of the different parties involved.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Newsletter 42: Dangers of Disabled Pre-Boot Authentication in  Corporate Environments</title>
      <link>https://insinuator.net/2013/12/ernw-newsletter-42-dangers-of-disabled-pre-boot-authentication-in-corporate-environments/</link>
      <pubDate>Mon, 16 Dec 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/12/ernw-newsletter-42-dangers-of-disabled-pre-boot-authentication-in-corporate-environments/</guid>
      <description>&lt;p&gt;It’s been a long time… we just published an &lt;a href=&#34;https://www.ernw.de/category/newsletter/index.html&#34;&gt;ERNW Newsletter&lt;/a&gt;. Here’s the abstract:&lt;/p&gt;&#xA;&lt;p&gt;In order to protect sensitive data on corporate laptops, most companies are using full disk encryption solutions. While native encryption products like Microsoft Bitlocker, Apple FileVault and open source solutions like TrueCrypt were already heavily scrutinized by security researchers, many popular commercial third party products are to some point still black boxes.&lt;/p&gt;&#xA;&lt;p&gt;In this paper, we discuss Check Point Full Disk Encryption (FDE) with active “Windows Integrated Logon”. Checkpoint FDE is a software package that is part of Check Point Endpoint Security and offers full disk encryption on Microsoft  Windows and Mac OS X systems. The “Windows Integrated Logon” feature reduces total cost of ownership by disabling pre-boot authentication. Check Point themselves warn about security risk associated with using this feature.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — Newsletter</title>
      <link>https://insinuator.net/2013/02/vmdk-has-left-the-building-newsletter/</link>
      <pubDate>Sat, 23 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/vmdk-has-left-the-building-newsletter/</guid>
      <description>&lt;p&gt;We are pleased to announce that we summarized the results from our &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;VMDK research&lt;/a&gt; in our latest newsletter.&lt;/p&gt;&#xA;&lt;p&gt;We hope you enjoy the reading and will get some “food for thought”!&lt;/p&gt;&#xA;&lt;p&gt;The newsletter can be found at:&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/ERNW_Newsletter_41_ExploitingVirtualFileFormats.pdf&#34;&gt;ERNW_Newsletter_41_ExploitingVirtualFileFormats.pd&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;A digitally signed version can be found at:&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/ERNW_Newsletter_41_ExploitingVirtualFileFormats_signed.pdf&#34;&gt;ERNW_Newsletter_41_ExploitingVirtualFileFormats_signed.pdf&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Enjoy your weekend,&lt;br&gt;&#xA;Matthias&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Server 2008 R2 BSI-compliance</title>
      <link>https://insinuator.net/2012/07/windows-server-2008-r2-bsi-compliance/</link>
      <pubDate>Thu, 26 Jul 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/07/windows-server-2008-r2-bsi-compliance/</guid>
      <description>&lt;p&gt;Recommendations by the &lt;a href=&#34;https://www.bsi.bund.de/EN/Home/home_node.html&#34;&gt;German Federal Office for Information Security&lt;/a&gt; (&lt;em&gt;BSI – Bundesamt für Sicherheit in der Informationstechnik&lt;/em&gt;) are obligatory for German government agencies, civil services and authorities (like recommendations of the NIST are relevant to American government agencies and authorities). They are often used as references and security best practices in other countries as well. Hence it is hard to understand why the recommendations on how to harden Windows Server &lt;strong&gt;2008&lt;/strong&gt; based systems were published only some weeks ago and only on a preliminary draft basis (which is, obviously, better than nothing ;-)).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sell Your Own Device – A Field Study on Decommissioning of Mobile Devices</title>
      <link>https://insinuator.net/2012/02/sell-your-own-device-a-field-study-on-decommissioning-of-mobile-devices/</link>
      <pubDate>Tue, 28 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/sell-your-own-device-a-field-study-on-decommissioning-of-mobile-devices/</guid>
      <description>&lt;p&gt;On Friday we released our latest technical newsletter with the fancy title &lt;em&gt;“Sell Your Own Device – A Field Study on Decommissioning of Mobile Devices”&lt;/em&gt;. It is the result of a field study on decommissioned mobile business devices bought on eBay and about how stored data may be extracted in different ways.&lt;/p&gt;&#xA;&lt;p&gt;As always we love to share plenty of practical advise: At the end of the newsletter you will find the mitigating controls to securely handle mobile devices at the end of their life cycle process.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Wrap-up on MFD Security</title>
      <link>https://insinuator.net/2011/11/a-wrap-up-on-mfd-security/</link>
      <pubDate>Wed, 16 Nov 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/11/a-wrap-up-on-mfd-security/</guid>
      <description>&lt;p&gt;On last year’s &lt;a href=&#34;http://www.troopers.de/archives/troopers11/&#34;&gt;TROOPERS11&lt;/a&gt;, Matthias (mluft) and I gave a &lt;a href=&#34;http://www.troopers.de/wp-content/uploads/2011/04/TR11_Schaefer_Luft_Multifunction_devices.pdf&#34;&gt;talk&lt;/a&gt; on Multifunction Devices. Hardly surprising: It was related to the state of &lt;em&gt;secure&lt;/em&gt; operation of MFDs. It was heavily motivated by experiences we collected out in the wild. We faced a frightening low level of awareness concerning the role of MFDs for the overall security picture – in particular regarding the processing of sensitive data…&lt;/p&gt;&#xA;&lt;p&gt;However, instead of only showing and proving well-known weaknesses and vulnerabilities, we decided to adapt ERNW’s *&lt;a href=&#34;http://www.ernw.de/content/e7/e181/e1612/download1614/ERNW_LANline_VirtCloudSec_Keynote_ger.pdf&#34;&gt;Seven Sisters&lt;/a&gt; *model in order to match the needs of secure MFD operation and to develop some kind of guideline. As Matthias already lost some &lt;a href=&#34;http://www.insinuator.net/2011/04/sisters-act-of-mfd-security/&#34;&gt;words&lt;/a&gt; on this, I’m not gonna waste your valuable time by repeating, what has already been said. However I described our approach and our thoughts on that topic in a recently published &lt;a href=&#34;http://ernw.de/content/e15/e28/index_ger.html&#34;&gt;ERNW Newsletter&lt;/a&gt;. If for what ever reason you didn’t see our talk or even didn’t attend &lt;a href=&#34;http://www.troopers.de/archives/troopers11/&#34;&gt;TROOPERS11&lt;/a&gt; at all, have a look on Newsletter 37 and give us feedback on what you think about the whole topic…&lt;/p&gt;</description>
    </item>
    <item>
      <title>Certificate Based Device Authentication with iOS Devices</title>
      <link>https://insinuator.net/2011/10/certificate-based-device-authentication-with-ios-devices/</link>
      <pubDate>Wed, 05 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/certificate-based-device-authentication-with-ios-devices/</guid>
      <description>&lt;p&gt;We recently performed a Proof-of-Concept (PoC) implementation of certificate based auth with iPads in some large environment. So far the focus has been mainly on WLAN access; VPN and EAS authentication are going to follow in the next step.&lt;/p&gt;&#xA;&lt;p&gt;As we figure that the topic might be of interest for some of you, we’ve extracted a certain, not-too-customer-specific part of the deliverable and converted it into an &lt;a href=&#34;http://www.ernw.de/content/e15/e26/e1662/download1664/ERNW_Newsletter_36_Cert_for_iOS_en_ger.pdf&#34;&gt;ERNW newsletter&lt;/a&gt;. Special thanks go to Rene Graf for leading the project! 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Research on “Application Virtualization” – Results online now</title>
      <link>https://insinuator.net/2010/08/research-on-application-virtualization-results-online-now/</link>
      <pubDate>Mon, 16 Aug 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/08/research-on-application-virtualization-results-online-now/</guid>
      <description>&lt;p&gt;Just wanted to let you know that we sent out &lt;a href=&#34;http://ernw.de/content/e15/e28/e1575/download1577/ERNW_Newsletter_32_ThinApp_signed_en_ger.pdf&#34;&gt;ERNW Newsletter 32&lt;/a&gt; end of last week. As we &lt;a href=&#34;http://www.insinuator.net/2010/08/application-virtualization-as-browser-security-control/&#34;&gt;promised&lt;/a&gt; it includes the results of  research regarding the question “Is browser virtualization a valid security control in order to mitigate browser based security risks?”.&lt;/p&gt;&#xA;&lt;p&gt;Simon did a great job with writing the latest newsletter. It’s a 30-page document which should help you to have a basis for well-informed decisions when it comes to the deployment of an application virtualization technology.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
