<?xml version="1.0" encoding="iso-8859-1"?><!-- generator="b2evolution/1.10.2" -->
<rss version="0.92">
	<channel>
		<title>Cognitive and Scientific Brainology</title>
					  <link>http://andreicostin.com/index.php/brain</link>
			  <description>andrei costin andreicostin costinandrei zveriu</description>
			  <language>en-US</language>
			  <docs>http://backend.userland.com/rss092</docs>
			  			  <item>
			    <title>EuSecWest 2010 - 'Hacking printers for fun and profit'</title>
			    <description>&lt;h3&gt;EuSecWest 2010 - &amp;#8216;Hacking printers for fun and profit&amp;#8217;&lt;/h3&gt;

&lt;p&gt;Most probably you have come to the right place if you were looking for:&lt;br /&gt;
 - &amp;#8220;Hacking printers for fun and profit&amp;#8221; paper from &lt;a href=&quot;http://eusecwest.com/&quot;&gt;EuSecWest 2010&lt;/a&gt;&lt;br /&gt;
 - Andrei Constin or Andrei Constantin presentation from EuSecWest 2010&lt;/p&gt;

&lt;p&gt;Actually, by a mis-fortunate spelling mistake on the initial publication of the &lt;a href=&quot;http://eusecwest.com/agenda.html&quot;&gt;speakers list for EuSecWest 2010&lt;/a&gt;, which (given the copy-paste and propagation effect of the blogs and mailing-lists) transformed &lt;b&gt;my correct name Andrei Costin&lt;/b&gt; to become Andrei Constin which then by Google&amp;#8217;s &amp;#8220;wisdom&amp;#8221; became Andrei Constantin.&lt;/p&gt;

&lt;p&gt;Download here: &lt;a href=&quot;http://andreicostin.com/media/blogs/brain/EuSecWest2010_AndreiCostin_HackingPrintersForFunAndProfit.pdf&quot; title=&quot;EuSecWest 2010 &amp;quot;Hacking Printers for fun and profit&amp;quot; Andrei Costin&quot;&gt;EuSecWest 2010 &amp;#8220;Hacking Printers for fun and profit&amp;#8221; Andrei Costin&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Download here: Remote-initiated PPE (printer payload exploit) using Java applets.&lt;/p&gt;

&lt;h4&gt;ESW10 Feedback&lt;/h4&gt;
&lt;p&gt;Seems some people really liked the talk, paper and the ideas, while others took their most hilarious laughs ever &lt;img src=&quot;http://andreicostin.com/rsc/smilies/icon_smile.gif&quot; alt=&quot;&amp;#58;&amp;#41;&quot; class=&quot;middle&quot; /&gt; (not sure if it was because of my talk or because of Amsterdam treats =)) ).&lt;/p&gt;

&lt;p&gt;Tweetfeeds of the conference can be found &lt;a href=&quot;http://twitter.com/search?q=%23EUSecWest&quot;&gt;here&lt;/a&gt; and &lt;a href=&quot;http://twitter.com/search?q=%23esw10&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;All in all, the event was very nice. Special thanks to &lt;a href=&quot;http://twitter.com/dragosr&quot;&gt;Dragos&lt;/a&gt; and all the crew for organizing a great event.&lt;/p&gt;

&lt;p&gt;After hearing about hackers on the plane and hackers on the train, we were doing hackers on the boat on Amsterdam&amp;#8217;s canals. Also, it was nice to see that a cool crowd from ESW10 DoS-ed the tram literally on their way to the boats &lt;img src=&quot;http://andreicostin.com/rsc/smilies/icon_smile.gif&quot; alt=&quot;&amp;#58;&amp;#41;&quot; class=&quot;middle&quot; /&gt;.&lt;br /&gt;
PS: we almost got owned by the boat captain like a group of kindergarten kids =))&amp;#8230; shhhhh and quiet, otherwise get kicked in the ass &lt;img src=&quot;http://andreicostin.com/rsc/smilies/graybigrazz.gif&quot; alt=&quot;&amp;#58;&amp;#80;&quot; class=&quot;middle&quot; /&gt;&lt;/p&gt;

&lt;p&gt;And yeah, props to Dragos for the &lt;a href=&quot;http://www.discountdivers.com/pix/6.pelican.case.black.jpg&quot;&gt;pelican case&lt;/a&gt; full of beer and to the guys caring the heavy devil of ice and beer &lt;img src=&quot;http://andreicostin.com/rsc/smilies/graylaugh.gif&quot; alt=&quot;&amp;#58;&amp;#41;&amp;#41;&quot; class=&quot;middle&quot; /&gt;.&lt;/p&gt;</description>
			    <link>http://andreicostin.com/index.php/brain/2010/06/20/eusecwest_2010_hacking_printers_for_fun_</link>
			  </item>
			  			  <item>
			    <title>EUSecWest 2010 is near</title>
			    <description>&lt;h3&gt;EUSecWest 2010 is near&lt;/h3&gt;

&lt;p&gt;I invite you to take a look at EUSecWest 2010 &lt;a href=&quot;http://eusecwest.com/agenda.html&quot;&gt;agenda&lt;/a&gt; and &lt;a href=&quot;https://www.eusecwest.com/register&quot;&gt;register&lt;/a&gt;. Perhaps we could meet there, who knows&amp;#8230;&lt;/p&gt;</description>
			    <link>http://andreicostin.com/index.php/brain/2010/05/16/eusecwest_2010_is_near</link>
			  </item>
			  			  <item>
			    <title>"Programmers should be able to program!" program</title>
			    <description>&lt;h3&gt;&amp;#8220;Programmers should be able to program!&amp;#8221; program&lt;/h3&gt;

&lt;p&gt;Well, sad and true in the same time&amp;#8230; It is an entertaining reading and one full of insights&amp;#8230;&lt;/p&gt;

&lt;p&gt;Maybe it&amp;#8217;s just one of those reasons why software is getting more crappy, unreliable, insecure, etc.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.codinghorror.com/blog/2010/02/the-nonprogramming-programmer.html&quot;&gt;The non-programming programmers&lt;/a&gt;&lt;/p&gt;

&lt;a href=&quot;http://andreicostin.com/index.php/brain/2010/04/16/p176#more176&quot;&gt;[...] Read more!&lt;/a&gt;</description>
			    <link>http://andreicostin.com/index.php/brain/2010/04/16/programmers_should_be_able_to_program_pr</link>
			  </item>
			  			  <item>
			    <title>Comprehensive list of security and hackers conferences and conventions 2010</title>
			    <description>&lt;h3&gt;Comprehensive list of security and hackers conferences 2010&lt;/h3&gt;

&lt;p&gt;Recently, there is a high span of various security and hackers conferences and conventions going on.&lt;/p&gt;

&lt;p&gt;Keeping track of them is not as easy as it seems, since there is no central point where to look up their schedules, locations, call for papers, etc.&lt;/p&gt;

&lt;p&gt;So I decided to compile a list for my own (well it doesn&amp;#8217;t cover 100% of security related conferences out there, but it tries to cover most of the publicly known/accessible ones).&lt;/p&gt;

&lt;a href=&quot;http://andreicostin.com/index.php/brain/2010/04/11/p174#more174&quot;&gt;[...] Read more!&lt;/a&gt;</description>
			    <link>http://andreicostin.com/index.php/brain/2010/04/11/comprehensive_list_of_security_and_hacke_2010</link>
			  </item>
			  			  <item>
			    <title>Learning Wireless Power: Part 1 - Security</title>
			    <description>&lt;h4&gt;Prolog&lt;/h4&gt;
&lt;p&gt;&lt;a href=&quot;http://en.wikipedia.org/wiki/Wireless_energy_transfer&quot;&gt;Wireless Power&lt;/a&gt; is not something new. It&amp;#8217;s an old idea, an old dream, an old demo. However, it now revived with new forces in form of new technology products.&lt;/p&gt;

&lt;p&gt;Mainly, there are two camps trying to use magnetic induction to charge things:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;one offering a charging pad&lt;/li&gt;
  &lt;li&gt;other trying for over-the-air power&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;However, the post is not about going over this technology itself - if you want to explore, check the links provided at the end.&lt;/p&gt;

&lt;h4&gt;To the point&lt;/h4&gt;
&lt;p&gt;The point of this post is to discuss the &lt;b&gt;security perspective of wireless power transfer, especially for over-the-air type&lt;/b&gt;. Several couple of years proved consistently that &lt;a href=&quot;http://en.wikipedia.org/wiki/Wireless&quot;&gt;wireless technologies (WiFi, RFID, remote controls, GSM, etc.)&lt;/a&gt; are very prone to security vulnerabilities (sadly, most often by design, rather by implementation).&lt;/p&gt;

&lt;p&gt;The types of attack one can envision are:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;p&gt;&lt;b&gt;wireless power theft&lt;/b&gt;&lt;/p&gt;&lt;a href=&quot;http://andreicostin.com/index.php/brain/2010/02/10/p169#more169&quot;&gt;[...] Read more!&lt;/a&gt;</description>
			    <link>http://andreicostin.com/index.php/brain/2010/02/10/learning_wireless_power_part_1_security</link>
			  </item>
			  	</channel>
</rss>
