<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: First SINP draft</title>
	<atom:link href="http://blog.affien.com/archives/2006/05/16/first-sinp-draft/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.affien.com/archives/2006/05/16/first-sinp-draft/</link>
	<description>A few thoughts</description>
	<lastBuildDate>Sun, 31 May 2009 12:07:29 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bas Westerbaan</title>
		<link>http://blog.affien.com/archives/2006/05/16/first-sinp-draft/comment-page-1/#comment-42402</link>
		<dc:creator>Bas Westerbaan</dc:creator>
		<pubDate>Tue, 16 May 2006 18:13:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.w-nz.com/archives/2006/05/16/first-sinp-draft/#comment-42402</guid>
		<description>I&#039;ve send the specification to the research group security of systems of the Radboud University in Nijmegen. I&#039;m waiting for a response.

The only weak point of which I know is that it uses HTTPS, which isn&#039;t very strong — strong enough though to be used for other online services which take a creditcard number.

For the presentation I&#039;ve made a proof of concept implementation, which supported the negotiation. At the moment I&#039;m making an implementation that complies fully to the specification in Python and PHP.

I&#039;ll indeed have to write plugins for existing software, but first I need to finish the initial implementation first :-). When I&#039;ve got a client library in several languages, then the plugins won&#039;t be that difficult anymore. I just need people to support it :-).

The event where we&#039;ve presented it was a presentation for a project called Codeyard, which tries to involve high school students more with open source. The event was pretty cool --- you don&#039;t talk everyday with several professors security of systems and representatives of a 2 biljon profit/year company (capgemini).</description>
		<content:encoded><![CDATA[<p>I&#8217;ve send the specification to the research group security of systems of the Radboud University in Nijmegen. I&#8217;m waiting for a response.</p>
<p>The only weak point of which I know is that it uses HTTPS, which isn&#8217;t very strong — strong enough though to be used for other online services which take a creditcard number.</p>
<p>For the presentation I&#8217;ve made a proof of concept implementation, which supported the negotiation. At the moment I&#8217;m making an implementation that complies fully to the specification in Python and PHP.</p>
<p>I&#8217;ll indeed have to write plugins for existing software, but first I need to finish the initial implementation first <img src='http://blog.affien.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> . When I&#8217;ve got a client library in several languages, then the plugins won&#8217;t be that difficult anymore. I just need people to support it <img src='http://blog.affien.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> .</p>
<p>The event where we&#8217;ve presented it was a presentation for a project called Codeyard, which tries to involve high school students more with open source. The event was pretty cool &#8212; you don&#8217;t talk everyday with several professors security of systems and representatives of a 2 biljon profit/year company (capgemini).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zef</title>
		<link>http://blog.affien.com/archives/2006/05/16/first-sinp-draft/comment-page-1/#comment-42400</link>
		<dc:creator>Zef</dc:creator>
		<pubDate>Tue, 16 May 2006 18:02:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.w-nz.com/archives/2006/05/16/first-sinp-draft/#comment-42400</guid>
		<description>I had a quick read of the document and it looks quite nice. However the question is how sure are you that this is completely secure. You take credit card information as an example in your white paper, that&#039;s quite something. You better be 100% sure this system is bulletproof. Did you have anybody who knows a lot about security have a look at it?

But it looks promising. Once you&#039;re sure it&#039;s secure the next challenge will be adoption. Do you have an implementation of it yourself yet? If you want it adopted you&#039;d probably have to write some plug-ins or extensions to current web applications (like forum software) yourself to show that it works and people can easily start using it. You can&#039;t really expect people to just grab your spec and start implementing at the start. It has to prove itself first.

And what kind of event was this you presented it at, something from your school or something?</description>
		<content:encoded><![CDATA[<p>I had a quick read of the document and it looks quite nice. However the question is how sure are you that this is completely secure. You take credit card information as an example in your white paper, that&#8217;s quite something. You better be 100% sure this system is bulletproof. Did you have anybody who knows a lot about security have a look at it?</p>
<p>But it looks promising. Once you&#8217;re sure it&#8217;s secure the next challenge will be adoption. Do you have an implementation of it yourself yet? If you want it adopted you&#8217;d probably have to write some plug-ins or extensions to current web applications (like forum software) yourself to show that it works and people can easily start using it. You can&#8217;t really expect people to just grab your spec and start implementing at the start. It has to prove itself first.</p>
<p>And what kind of event was this you presented it at, something from your school or something?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
