<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Ed Bellis - ClearText</title>
	<atom:link href="http://edbellis.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://edbellis.com</link>
	<description>converting black signals to red</description>
	<lastBuildDate>Mon, 03 Jan 2011 23:09:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on BlackHat Without The Drama by Talking InfoSec with the Experienced &#8211; RSA Edition &#8212; HoneyApps - The Blog</title>
		<link>http://edbellis.com/2009/08/04/blackhat-without-the-drama/#comment-1165</link>
		<dc:creator><![CDATA[Talking InfoSec with the Experienced &#8211; RSA Edition &#8212; HoneyApps - The Blog]]></dc:creator>
		<pubDate>Mon, 03 Jan 2011 23:09:53 +0000</pubDate>
		<guid isPermaLink="false">http://edbellis.com/?p=148#comment-1165</guid>
		<description><![CDATA[[...] attacks, cloud security and compliance among other things with David Mortman who had one of the most under appreciated talks at BlackHat I have ever had the pleasure to hear along with Richard Bejtlich who I spoke with on a [...]]]></description>
		<content:encoded><![CDATA[<p>[...] attacks, cloud security and compliance among other things with David Mortman who had one of the most under appreciated talks at BlackHat I have ever had the pleasure to hear along with Richard Bejtlich who I spoke with on a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Crowdsourcing Payment Security by David Marsh</title>
		<link>http://edbellis.com/2009/06/30/crowdsourcing-payment-security/#comment-1158</link>
		<dc:creator><![CDATA[David Marsh]]></dc:creator>
		<pubDate>Tue, 17 Aug 2010 20:12:24 +0000</pubDate>
		<guid isPermaLink="false">http://edbellis.com/?p=137#comment-1158</guid>
		<description><![CDATA[Hi Ed!

I just read your section in Beautiful Security, and I was amazed at how clearly you saw some of the challenges and potential solutions in the payment security space. 

I wish I would have read this a year ago, before I started working on the TransArmor project I am on. It would have spurred some interesting thoughts and helped frame some of the discussions that I had to learn hard lessons in. 

TransArmor is a tokenization solution - we are (as you suggested) removing those crown jewel PANs out of the merchant environments so that the temptation and opportunity for breach no longer exists for would-be attackers. 

I will also take a look at the wiki and see if I can add anything useful.

I would really like to hear some of your thoughts on the current proposed solutions - end-to-end encryption and tokenization. 

Kind Regards,

David Marsh]]></description>
		<content:encoded><![CDATA[<p>Hi Ed!</p>
<p>I just read your section in Beautiful Security, and I was amazed at how clearly you saw some of the challenges and potential solutions in the payment security space. </p>
<p>I wish I would have read this a year ago, before I started working on the TransArmor project I am on. It would have spurred some interesting thoughts and helped frame some of the discussions that I had to learn hard lessons in. </p>
<p>TransArmor is a tokenization solution &#8211; we are (as you suggested) removing those crown jewel PANs out of the merchant environments so that the temptation and opportunity for breach no longer exists for would-be attackers. </p>
<p>I will also take a look at the wiki and see if I can add anything useful.</p>
<p>I would really like to hear some of your thoughts on the current proposed solutions &#8211; end-to-end encryption and tokenization. </p>
<p>Kind Regards,</p>
<p>David Marsh</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The Vulnerability Arms Race by Tweets that mention The Vulnerability Arms Race « Ed Bellis – ClearText -- Topsy.com</title>
		<link>http://edbellis.com/2010/05/11/the-vulnerability-arms-race/#comment-1146</link>
		<dc:creator><![CDATA[Tweets that mention The Vulnerability Arms Race « Ed Bellis – ClearText -- Topsy.com]]></dc:creator>
		<pubDate>Tue, 11 May 2010 20:09:28 +0000</pubDate>
		<guid isPermaLink="false">http://edbellis.com/?p=161#comment-1146</guid>
		<description><![CDATA[[...] This post was mentioned on Twitter by Dan Cornell and Ed Bellis, Lucas Zaichkowsky. Lucas Zaichkowsky said: RT @ebellis: New Blog Post: The Vulnerability Arms Race - on CSOonline http://bit.ly/brXtg1 and backup here: http://bit.ly/d6JnhU [...]]]></description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Dan Cornell and Ed Bellis, Lucas Zaichkowsky. Lucas Zaichkowsky said: RT @ebellis: New Blog Post: The Vulnerability Arms Race &#8211; on CSOonline <a href="http://bit.ly/brXtg1" rel="nofollow">http://bit.ly/brXtg1</a> and backup here: <a href="http://bit.ly/d6JnhU" rel="nofollow">http://bit.ly/d6JnhU</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 5 Things You Might Not Know About Ed Bellis by Laz</title>
		<link>http://edbellis.com/2009/09/08/5-things-you-might-not-know-about-ed-bellis/#comment-1133</link>
		<dc:creator><![CDATA[Laz]]></dc:creator>
		<pubDate>Wed, 10 Feb 2010 15:38:57 +0000</pubDate>
		<guid isPermaLink="false">http://edbellis.com/?p=151#comment-1133</guid>
		<description><![CDATA[Ed, when are you going to swim the Chicago River?]]></description>
		<content:encoded><![CDATA[<p>Ed, when are you going to swim the Chicago River?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 5 Things You Might Not Know About Ed Bellis by cleartext</title>
		<link>http://edbellis.com/2009/09/08/5-things-you-might-not-know-about-ed-bellis/#comment-1120</link>
		<dc:creator><![CDATA[cleartext]]></dc:creator>
		<pubDate>Sun, 15 Nov 2009 04:12:30 +0000</pubDate>
		<guid isPermaLink="false">http://edbellis.com/?p=151#comment-1120</guid>
		<description><![CDATA[@andres thanks for the very kind words regarding the book. The chapter has actually been turned into a wiki on the O&#039;Reilly commons site. I&#039;d love it if you would look it over and perhaps edit and create additional content that you think would make this model apply to card present transactions as well. 

you can find the wiki here: http://commons.oreilly.com/wiki/index.php/Beautiful_Trade:_Rethinking_Ecommerce_Security]]></description>
		<content:encoded><![CDATA[<p>@andres thanks for the very kind words regarding the book. The chapter has actually been turned into a wiki on the O&#8217;Reilly commons site. I&#8217;d love it if you would look it over and perhaps edit and create additional content that you think would make this model apply to card present transactions as well. </p>
<p>you can find the wiki here: <a href="http://commons.oreilly.com/wiki/index.php/Beautiful_Trade:_Rethinking_Ecommerce_Security" rel="nofollow">http://commons.oreilly.com/wiki/index.php/Beautiful_Trade:_Rethinking_Ecommerce_Security</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 5 Things You Might Not Know About Ed Bellis by jack crouch</title>
		<link>http://edbellis.com/2009/09/08/5-things-you-might-not-know-about-ed-bellis/#comment-1118</link>
		<dc:creator><![CDATA[jack crouch]]></dc:creator>
		<pubDate>Fri, 13 Nov 2009 13:23:56 +0000</pubDate>
		<guid isPermaLink="false">http://edbellis.com/?p=151#comment-1118</guid>
		<description><![CDATA[eddie....
i finished my research on blackie, it turned out 26 pages which includes his career at u of ala.......i sent him one at tampa and i also spoke with him on phone asking if he minded me offering you a copy......i will keep the original but if you want the other copy just let me know what address to send.......i received your previous email with tampa phone.........that was blackies first question, &#039;&#039; how did you find me ?....................jack 352-787-2436]]></description>
		<content:encoded><![CDATA[<p>eddie&#8230;.<br />
i finished my research on blackie, it turned out 26 pages which includes his career at u of ala&#8230;&#8230;.i sent him one at tampa and i also spoke with him on phone asking if he minded me offering you a copy&#8230;&#8230;i will keep the original but if you want the other copy just let me know what address to send&#8230;&#8230;.i received your previous email with tampa phone&#8230;&#8230;&#8230;that was blackies first question, &#8221; how did you find me ?&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;..jack 352-787-2436</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 5 Things You Might Not Know About Ed Bellis by Andres Velandia</title>
		<link>http://edbellis.com/2009/09/08/5-things-you-might-not-know-about-ed-bellis/#comment-1117</link>
		<dc:creator><![CDATA[Andres Velandia]]></dc:creator>
		<pubDate>Tue, 10 Nov 2009 21:00:42 +0000</pubDate>
		<guid isPermaLink="false">http://edbellis.com/?p=151#comment-1117</guid>
		<description><![CDATA[Hello: since I could not find any e-mail address to write to you, I have chosen this box to do so. I have been reading the book &quot;Beautiful Security&quot;, and have just finished chapter 5. I have found &quot;beautiful&quot; the proposed model; in fact, it made me think: how come nobody ever thought of this before?
Anyway, my only observation is that you have deemed your model as suitable only for card-not-present transactions. After thinking about it a little longer, the model fits perfectly card-present transactions, because the parties involved are just the same. From what I have read, I think consumers should use their credit cards (even debit cards) only with merchants that comply with all requirements proposed by you.
All in all, congratulations for your fresh interesting ideas about security.]]></description>
		<content:encoded><![CDATA[<p>Hello: since I could not find any e-mail address to write to you, I have chosen this box to do so. I have been reading the book &#8220;Beautiful Security&#8221;, and have just finished chapter 5. I have found &#8220;beautiful&#8221; the proposed model; in fact, it made me think: how come nobody ever thought of this before?<br />
Anyway, my only observation is that you have deemed your model as suitable only for card-not-present transactions. After thinking about it a little longer, the model fits perfectly card-present transactions, because the parties involved are just the same. From what I have read, I think consumers should use their credit cards (even debit cards) only with merchants that comply with all requirements proposed by you.<br />
All in all, congratulations for your fresh interesting ideas about security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 5 Things You Might Not Know About Ed Bellis by jack crouch</title>
		<link>http://edbellis.com/2009/09/08/5-things-you-might-not-know-about-ed-bellis/#comment-1112</link>
		<dc:creator><![CDATA[jack crouch]]></dc:creator>
		<pubDate>Sun, 01 Nov 2009 20:41:13 +0000</pubDate>
		<guid isPermaLink="false">http://edbellis.com/?p=151#comment-1112</guid>
		<description><![CDATA[made friendship three years ago with edward thayer &#039;&#039;blackie&#039;&#039; bellis about 85 yrs old, former baseball pitcher at U of Ala &#039;46,&#039;47 residing in The Villages, FL. also played pro minor league baseball in Lynn MA &#039;47. i recently received copies from Lynn newspaper during baseball season of &#039;47 naming ed bellis several times as player on that team...had lunch with blackie  about once a month up entill two mo ago....his answer maching on phone does not return my calls...would like to found out his current wherebouts.......auburn jack]]></description>
		<content:encoded><![CDATA[<p>made friendship three years ago with edward thayer &#8221;blackie&#8221; bellis about 85 yrs old, former baseball pitcher at U of Ala &#8217;46,&#8217;47 residing in The Villages, FL. also played pro minor league baseball in Lynn MA &#8217;47. i recently received copies from Lynn newspaper during baseball season of &#8217;47 naming ed bellis several times as player on that team&#8230;had lunch with blackie  about once a month up entill two mo ago&#8230;.his answer maching on phone does not return my calls&#8230;would like to found out his current wherebouts&#8230;&#8230;.auburn jack</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 5 Things You Might Not Know About Ed Bellis by Sarah</title>
		<link>http://edbellis.com/2009/09/08/5-things-you-might-not-know-about-ed-bellis/#comment-1101</link>
		<dc:creator><![CDATA[Sarah]]></dc:creator>
		<pubDate>Wed, 09 Sep 2009 20:18:42 +0000</pubDate>
		<guid isPermaLink="false">http://edbellis.com/?p=151#comment-1101</guid>
		<description><![CDATA[Too bad. *Rolling eyes even more*]]></description>
		<content:encoded><![CDATA[<p>Too bad. *Rolling eyes even more*</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on OpenID SSO Everywhere! by OpenID Publishes Security Best Practices &#171; Ed Bellis &#8211; ClearText</title>
		<link>http://edbellis.com/2008/06/24/openid-sso-everywhere/#comment-1047</link>
		<dc:creator><![CDATA[OpenID Publishes Security Best Practices &#171; Ed Bellis &#8211; ClearText]]></dc:creator>
		<pubDate>Wed, 17 Jun 2009 20:11:03 +0000</pubDate>
		<guid isPermaLink="false">http://cleartext.wordpress.com/?p=40#comment-1047</guid>
		<description><![CDATA[[...] to my friend for getting a bit side-tracked off of his original question, but having written about OpenID about a year and a half ago, I felt the need to go through this and find out if any of the original concerns I had expressed [...]]]></description>
		<content:encoded><![CDATA[<p>[...] to my friend for getting a bit side-tracked off of his original question, but having written about OpenID about a year and a half ago, I felt the need to go through this and find out if any of the original concerns I had expressed [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

