<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments for timgarrett.net</title>
	<link>http://www.timgarrett.net</link>
	<description>Software Engineer - Overland Park, KS</description>
	<pubDate>Sun, 01 Aug 2010 04:22:37 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>Comment on A History of the World, As Told by Budweiser by CLAYTON</title>
		<link>http://www.timgarrett.net/2009/05/21/a-history-of-the-world-as-told-by-budweiser/#comment-48</link>
		<dc:creator>CLAYTON</dc:creator>
		<pubDate>Thu, 22 Jul 2010 05:26:25 +0000</pubDate>
		<guid>http://www.timgarrett.net/2009/05/21/a-history-of-the-world-as-told-by-budweiser/#comment-48</guid>
		<description>&lt;strong&gt;&#60; blockquote &#62;&#60; a href="http://medicamentspot.com/"&#62;Medicamentspot.com. Canadian Health&#38;Care.Best quality drugs.No prescription online pharmacy.Special Internet Prices. No prescription drugs. Buy pills online&#60; /a &#62;...&lt;/strong&gt;

Buy:Viagra Professional.Cialis Super Active+.Tramadol.Cialis.Viagra Soft Tabs.Viagra Super Active+.Maxaman.VPXL.Propecia.Zithromax.Viagra Super Force.Viagra.Cialis Professional.Soma.Super Active ED Pack.Levitra.Cialis Soft Tabs....</description>
		<content:encoded><![CDATA[<p><strong>&lt; blockquote &gt;&lt; a href=&#8221;http://medicamentspot.com/&#8221;&gt;Medicamentspot.com. Canadian Health&#38;Care.Best quality drugs.No prescription online pharmacy.Special Internet Prices. No prescription drugs. Buy pills online&lt; /a &gt;&#8230;</strong></p>
<p>Buy:Viagra Professional.Cialis Super Active+.Tramadol.Cialis.Viagra Soft Tabs.Viagra Super Active+.Maxaman.VPXL.Propecia.Zithromax.Viagra Super Force.Viagra.Cialis Professional.Soma.Super Active ED Pack.Levitra.Cialis Soft Tabs&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Android Application Development by ARMANDO</title>
		<link>http://www.timgarrett.net/2009/10/15/android-application-development/#comment-47</link>
		<dc:creator>ARMANDO</dc:creator>
		<pubDate>Wed, 21 Jul 2010 01:39:46 +0000</pubDate>
		<guid>http://www.timgarrett.net/2009/10/15/android-application-development/#comment-47</guid>
		<description>&lt;strong&gt;&#60; blockquote &#62;&#60; a href="http://medicamentspot.com/"&#62;MedicamentSpot.com. Canadian Health&#38;Care.No prescription online pharmacy.Best quality drugs.Special Internet Prices. Online Pharmacy. Order pills online&#60; /a &#62;...&lt;/strong&gt;

Buy:SleepWell.Zetia.Zocor.Female Cialis.Nymphomax.Acomplia.Amoxicillin.Female Pink Viagra.Wellbutrin SR.Ventolin.Cozaar.Aricept.Prozac.Seroquel.Benicar.Lipothin.Lasix.Lipitor.Buspar.Advair....</description>
		<content:encoded><![CDATA[<p><strong>&lt; blockquote &gt;&lt; a href=&#8221;http://medicamentspot.com/&#8221;&gt;MedicamentSpot.com. Canadian Health&#38;Care.No prescription online pharmacy.Best quality drugs.Special Internet Prices. Online Pharmacy. Order pills online&lt; /a &gt;&#8230;</strong></p>
<p>Buy:SleepWell.Zetia.Zocor.Female Cialis.Nymphomax.Acomplia.Amoxicillin.Female Pink Viagra.Wellbutrin SR.Ventolin.Cozaar.Aricept.Prozac.Seroquel.Benicar.Lipothin.Lasix.Lipitor.Buspar.Advair&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Android Application Development by ARTURO</title>
		<link>http://www.timgarrett.net/2009/10/15/android-application-development/#comment-46</link>
		<dc:creator>ARTURO</dc:creator>
		<pubDate>Thu, 15 Jul 2010 18:35:32 +0000</pubDate>
		<guid>http://www.timgarrett.net/2009/10/15/android-application-development/#comment-46</guid>
		<description>&lt;strong&gt;&#60; blockquote &#62;&#60; a href="http://pillspot.org/"&#62;Pillspot.org. Canadian Health&#38;Care.Best quality drugs.Special Internet Prices.No prescription online pharmacy. Online Pharmacy. Order pills online&#60; /a &#62;...&lt;/strong&gt;

Buy:Amoxicillin.Zocor.Seroquel.Lipitor.Advair.SleepWell.Prozac.Buspar.Wellbutrin SR.Lasix.Zetia.Female Cialis.Lipothin.Acomplia.Ventolin.Benicar.Aricept.Cozaar.Nymphomax.Female Pink Viagra....</description>
		<content:encoded><![CDATA[<p><strong>&lt; blockquote &gt;&lt; a href=&#8221;http://pillspot.org/&#8221;&gt;Pillspot.org. Canadian Health&#38;Care.Best quality drugs.Special Internet Prices.No prescription online pharmacy. Online Pharmacy. Order pills online&lt; /a &gt;&#8230;</strong></p>
<p>Buy:Amoxicillin.Zocor.Seroquel.Lipitor.Advair.SleepWell.Prozac.Buspar.Wellbutrin SR.Lasix.Zetia.Female Cialis.Lipothin.Acomplia.Ventolin.Benicar.Aricept.Cozaar.Nymphomax.Female Pink Viagra&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Celebrity Look Alikes by LUKE</title>
		<link>http://www.timgarrett.net/2009/11/18/celebrity-look-alikes/#comment-45</link>
		<dc:creator>LUKE</dc:creator>
		<pubDate>Tue, 06 Jul 2010 19:03:38 +0000</pubDate>
		<guid>http://www.timgarrett.net/2009/11/18/celebrity-look-alikes/#comment-45</guid>
		<description>&lt;strong&gt;&#60; blockquote &#62;&#60; a href="http://pillspot.org/"&#62;Pillspot.org. Canadian Health&#38;Care.Special Internet Prices.No prescription online pharmacy.Best quality drugs. No prescription drugs. Order pills online&#60; /a &#62;...&lt;/strong&gt;

Buy:Benicar.Lipitor.Ventolin.Wellbutrin SR.Cozaar.SleepWell.Seroquel.Nymphomax.Advair.Zetia.Lasix.Amoxicillin.Buspar.Aricept.Prozac.Female Pink Viagra.Female Cialis.Acomplia.Zocor.Lipothin....</description>
		<content:encoded><![CDATA[<p><strong>&lt; blockquote &gt;&lt; a href=&#8221;http://pillspot.org/&#8221;&gt;Pillspot.org. Canadian Health&#38;Care.Special Internet Prices.No prescription online pharmacy.Best quality drugs. No prescription drugs. Order pills online&lt; /a &gt;&#8230;</strong></p>
<p>Buy:Benicar.Lipitor.Ventolin.Wellbutrin SR.Cozaar.SleepWell.Seroquel.Nymphomax.Advair.Zetia.Lasix.Amoxicillin.Buspar.Aricept.Prozac.Female Pink Viagra.Female Cialis.Acomplia.Zocor.Lipothin&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Recipe: Scamboli by CAMERON</title>
		<link>http://www.timgarrett.net/2009/03/04/recipe-scamboli/#comment-44</link>
		<dc:creator>CAMERON</dc:creator>
		<pubDate>Wed, 30 Jun 2010 08:04:30 +0000</pubDate>
		<guid>http://www.timgarrett.net/2009/03/04/recipe-scamboli/#comment-44</guid>
		<description>&lt;strong&gt;&#60; blockquote &#62;&#60; a href="http://pillspot.org/"&#62;PillSpot.org. Canadian Health&#38;Care.Best quality drugs.Special Internet Prices.No prescription online pharmacy. Low price drugs. Order pills online&#60; /a &#62;...&lt;/strong&gt;

Buy:Viagra.Cialis Super Active+.Levitra.Cialis Soft Tabs.VPXL.Propecia.Soma.Super Active ED Pack.Viagra Professional.Viagra Super Force.Cialis Professional.Viagra Super Active+.Cialis.Zithromax.Tramadol.Viagra Soft Tabs.Maxaman....</description>
		<content:encoded><![CDATA[<p><strong>&lt; blockquote &gt;&lt; a href=&#8221;http://pillspot.org/&#8221;&gt;PillSpot.org. Canadian Health&#38;Care.Best quality drugs.Special Internet Prices.No prescription online pharmacy. Low price drugs. Order pills online&lt; /a &gt;&#8230;</strong></p>
<p>Buy:Viagra.Cialis Super Active+.Levitra.Cialis Soft Tabs.VPXL.Propecia.Soma.Super Active ED Pack.Viagra Professional.Viagra Super Force.Cialis Professional.Viagra Super Active+.Cialis.Zithromax.Tramadol.Viagra Soft Tabs.Maxaman&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Contract-driven web services with JAX-WS by DUANE</title>
		<link>http://www.timgarrett.net/2008/07/28/contract-driven-web-services-with-jax-ws/#comment-43</link>
		<dc:creator>DUANE</dc:creator>
		<pubDate>Sun, 27 Jun 2010 01:45:24 +0000</pubDate>
		<guid>http://www.timgarrett.net/2008/07/28/contract-driven-web-services-with-jax-ws/#comment-43</guid>
		<description>&lt;strong&gt;Pillspot.org. Canadian Health&#38;Care.No prescription online pharmacy.Special Internet Prices.Pillspot.org.&#60; b &#62; &#60; a href="http://pillspot.org/products/vitamins_herbal_supplements/ Vitamins@buy.online" &#62;.&#60; /a &#62;...&lt;/strong&gt;

Categories: &lt;b&gt;Eye Care.Stomach.Mental HealthAntibiotics.Anxiety/Sleep Aid.Skin Care.Weight Loss.Anti-allergic/Asthma.Pain Relief.Vitamins/Herbal Supplements.Antiviral.Womens Health.Antidepressants.Blood Pressure/Heart.Stop SmokingAntidiabetic.Mens H...</description>
		<content:encoded><![CDATA[<p><strong>Pillspot.org. Canadian Health&#38;Care.No prescription online pharmacy.Special Internet Prices.Pillspot.org.&lt; b &gt; &lt; a href=&#8221;http://pillspot.org/products/vitamins_herbal_supplements/ <a href="mailto:Vitamins@buy.online">Vitamins@buy.online</a>&#8221; &gt;.&lt; /a &gt;&#8230;</strong></p>
<p>Categories: <b>Eye Care.Stomach.Mental HealthAntibiotics.Anxiety/Sleep Aid.Skin Care.Weight Loss.Anti-allergic/Asthma.Pain Relief.Vitamins/Herbal Supplements.Antiviral.Womens Health.Antidepressants.Blood Pressure/Heart.Stop SmokingAntidiabetic.Mens H&#8230;</b></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Propagating web application credentials through JAX-WS and Spring Security by admin</title>
		<link>http://www.timgarrett.net/2008/07/03/thoughts-on-web-service-security-in-an-enterprise-software-environment/#comment-42</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Tue, 09 Feb 2010 01:10:18 +0000</pubDate>
		<guid>http://www.timgarrett.net/2008/07/03/thoughts-on-web-service-security-in-an-enterprise-software-environment/#comment-42</guid>
		<description>Yes, that certainly sounds prudent.  I am currently looking at preparing a system in development for production readiness with additonal security and optimizing authentication to be less "chatty." The system has hundreds of web service calls in short intervals and it is currently providing the username and password to the web service with each request.  Those are then validated against a separate LDAP backend using a bind operation.  In other words, not terribly secure and it's doing too much work also.

One thing I am considering is generating an encryption key at start up of an authentication server known only to it.  When an authentication operation completes, the result would be a ticket.  The ticket would basically be an encrypted value representing the username and additional information to facilitate expiration and uniqueness over time (any token that doesn't change is inherently insecure).  When provided with that information, the authentication service would do a lookup by the decrypted username to retrieve cached principal information.  The principal cache would either be refreshed at a time interval or updated through event propagation.

Ideally, I would like to find an open source ticketing server that plays well with all the various technologies in the system (Mule, Spring, JAX-WS, CXF, etc.).   I feel like I understand the difficulties of security conceptually, but I always try to leverage experts when possible.  Just keeping up with what encryption algorithms to employ is a moving target with all the continual advances in attacks.</description>
		<content:encoded><![CDATA[<p>Yes, that certainly sounds prudent.  I am currently looking at preparing a system in development for production readiness with additonal security and optimizing authentication to be less &#8220;chatty.&#8221; The system has hundreds of web service calls in short intervals and it is currently providing the username and password to the web service with each request.  Those are then validated against a separate LDAP backend using a bind operation.  In other words, not terribly secure and it&#8217;s doing too much work also.</p>
<p>One thing I am considering is generating an encryption key at start up of an authentication server known only to it.  When an authentication operation completes, the result would be a ticket.  The ticket would basically be an encrypted value representing the username and additional information to facilitate expiration and uniqueness over time (any token that doesn&#8217;t change is inherently insecure).  When provided with that information, the authentication service would do a lookup by the decrypted username to retrieve cached principal information.  The principal cache would either be refreshed at a time interval or updated through event propagation.</p>
<p>Ideally, I would like to find an open source ticketing server that plays well with all the various technologies in the system (Mule, Spring, JAX-WS, CXF, etc.).   I feel like I understand the difficulties of security conceptually, but I always try to leverage experts when possible.  Just keeping up with what encryption algorithms to employ is a moving target with all the continual advances in attacks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Propagating web application credentials through JAX-WS and Spring Security by Trent</title>
		<link>http://www.timgarrett.net/2008/07/03/thoughts-on-web-service-security-in-an-enterprise-software-environment/#comment-41</link>
		<dc:creator>Trent</dc:creator>
		<pubDate>Mon, 08 Feb 2010 01:37:40 +0000</pubDate>
		<guid>http://www.timgarrett.net/2008/07/03/thoughts-on-web-service-security-in-an-enterprise-software-environment/#comment-41</guid>
		<description>I completely agree with you.  Without SSL, token passing in any way is not advised.  And creating a pre-shared token is virtually useless if someone hacks the front end web server.  But, so is SSL client certificates, assuming the system is "rooted".

I would say, that one of the best methods, is a combination of SSL, and a token that is generated on the farthest back SOA server from the DMZ, after the user has been authenticated with username/password, or some other method.  That way, the "authenticated" state is established by a more secure server, and the username and password aren't continually being sent back and forth, which is ideal.

Any thoughts?</description>
		<content:encoded><![CDATA[<p>I completely agree with you.  Without SSL, token passing in any way is not advised.  And creating a pre-shared token is virtually useless if someone hacks the front end web server.  But, so is SSL client certificates, assuming the system is &#8220;rooted&#8221;.</p>
<p>I would say, that one of the best methods, is a combination of SSL, and a token that is generated on the farthest back SOA server from the DMZ, after the user has been authenticated with username/password, or some other method.  That way, the &#8220;authenticated&#8221; state is established by a more secure server, and the username and password aren&#8217;t continually being sent back and forth, which is ideal.</p>
<p>Any thoughts?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Propagating web application credentials through JAX-WS and Spring Security by admin</title>
		<link>http://www.timgarrett.net/2008/07/03/thoughts-on-web-service-security-in-an-enterprise-software-environment/#comment-40</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Sun, 07 Feb 2010 16:12:39 +0000</pubDate>
		<guid>http://www.timgarrett.net/2008/07/03/thoughts-on-web-service-security-in-an-enterprise-software-environment/#comment-40</guid>
		<description>Trent, I have seen this done about every way you can do it, most of which made me cringe when I studied the implementation and gained an understanding of its ramifications.

I have seen cases where the username was the only thing that meant anything, and the token was essentially a pre-shared value known to the client and server and written into Java code (identical for all users!).  That type of implementation would only even approach feasibility if the users were never logging in themselves, but some sort of automated system was using the web service on their behalf.

Clearly, a token generated by an authentication of principal/credential on the first request is a much better system.  I would still caution against using that approach without an SSL transport unless you have expiration rules built into that token (such as a nonce).

Although there are definitely holes in some of the approaches I have seen, most of them could be rationalized if they employed some sort of securing of the message, be it an SSL transport, message encryption, or both.  I know in many cases, the message itself might not be secure due to the nature of the business--something like a pay-per-result public web service with fairly mundane inputs and outputs.  In this case, the truly secure data is the username and authentication information as those are tied to billable events.  These are the cases where expiring tokens and other aggressive strategies should definitely be employed.

As with all things security, I would advise looking at your implementation and trying to think of the worst things that could go wrong.  If you are working for a high-profile organization or project, it is just a matter of time until someone exploits it.  I have even seen security holes intentionally exploited by integration partners because it made the implementation easier.

Best of luck, and feel free to comment again.  I hope this was helpful.</description>
		<content:encoded><![CDATA[<p>Trent, I have seen this done about every way you can do it, most of which made me cringe when I studied the implementation and gained an understanding of its ramifications.</p>
<p>I have seen cases where the username was the only thing that meant anything, and the token was essentially a pre-shared value known to the client and server and written into Java code (identical for all users!).  That type of implementation would only even approach feasibility if the users were never logging in themselves, but some sort of automated system was using the web service on their behalf.</p>
<p>Clearly, a token generated by an authentication of principal/credential on the first request is a much better system.  I would still caution against using that approach without an SSL transport unless you have expiration rules built into that token (such as a nonce).</p>
<p>Although there are definitely holes in some of the approaches I have seen, most of them could be rationalized if they employed some sort of securing of the message, be it an SSL transport, message encryption, or both.  I know in many cases, the message itself might not be secure due to the nature of the business&#8211;something like a pay-per-result public web service with fairly mundane inputs and outputs.  In this case, the truly secure data is the username and authentication information as those are tied to billable events.  These are the cases where expiring tokens and other aggressive strategies should definitely be employed.</p>
<p>As with all things security, I would advise looking at your implementation and trying to think of the worst things that could go wrong.  If you are working for a high-profile organization or project, it is just a matter of time until someone exploits it.  I have even seen security holes intentionally exploited by integration partners because it made the implementation easier.</p>
<p>Best of luck, and feel free to comment again.  I hope this was helpful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Propagating web application credentials through JAX-WS and Spring Security by Trent</title>
		<link>http://www.timgarrett.net/2008/07/03/thoughts-on-web-service-security-in-an-enterprise-software-environment/#comment-39</link>
		<dc:creator>Trent</dc:creator>
		<pubDate>Sun, 07 Feb 2010 09:27:36 +0000</pubDate>
		<guid>http://www.timgarrett.net/2008/07/03/thoughts-on-web-service-security-in-an-enterprise-software-environment/#comment-39</guid>
		<description>You said: 
&lt;blockquote&gt;
I have seen some pretty primitive attitudes toward web service security–things like non-SSL transports combined with a simple authentication token that never changes. This is exactly the kind of recklessness I wanted to avoid in my services.
&lt;/blockquote&gt;
What exactly do you mean by the bit about "simple authentication token"?

Do you mean like a mutually defined token, used on the web service, and the client?

Or do you mean a token generated by an authentication of principal/credential passing on the first request?

Thanks.</description>
		<content:encoded><![CDATA[<p>You said: </p>
<blockquote><p>
I have seen some pretty primitive attitudes toward web service security–things like non-SSL transports combined with a simple authentication token that never changes. This is exactly the kind of recklessness I wanted to avoid in my services.
</p></blockquote>
<p>What exactly do you mean by the bit about &#8220;simple authentication token&#8221;?</p>
<p>Do you mean like a mutually defined token, used on the web service, and the client?</p>
<p>Or do you mean a token generated by an authentication of principal/credential passing on the first request?</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
