Tuesday, September 13, 2011
Sheikh Zayed bin Sultan Al Nahyan, Founder of the UAE

His Highness Sheikh Zayed bin Sultan Al Nahyan served as President of the United Arab Emirates since the formation of the Federation on 2 December 1971 and as Ruler of the Emirate of Abu Dhabi since 1966.
Understanding the UAE is impossible without understanding the life of Sheikh Zayed and his deep religious faith, his vision, his determination and hard work, his generosity at home and abroad, and the way in which he devoted his life to the service of his people and the creation of a better worldBorn around 1918 in Abu Dhabi, Sheikh Zayed was the youngest of the four sons of Sheikh Sultan bin Zayed Al Nahyan, Ruler of Abu Dhabi from 1922 to 1926. At the time Sheikh Zayed was born, the emirate was poor and undeveloped, with an economy based primarily on fishing and pearl diving and on simple agriculture in scattered oases inland.
Life, even for members of the ruling family, was simple. Education was generally confined to lessons in reading and writing, along with instruction in Islam from the local preacher. Transport was by camel or boat, and the harshness of the arid climate meant that survival itself was often a major concern.
Through the late 1920s and 1930s, Sheikh Zayed’s thirst for knowledge took him into the desert with Bedouin tribesmen to learn all he could about the way of life of the people and the environment. He later recalled with pleasure his experience of desert life and his initiation into the sport of falconry, which became a lifelong passion.
In 1946, Sheikh Zayed became Ruler’s Representative in the Eastern Region of Abu Dhabi, centered on the oasis of Al Ain. The job involved administering six villages and an adjacent desert region. In the late 1940s and early 1950s, Sheikh Zayed established his clear vision of what he wished to achieve for the people of Al Ain, and as someone who led by example.
Despite few government revenues, Sheikh Zayed succeeded in bringing progress to Al Ain, establishing basic administration, personally funding the first modern school in the emirate and coaxing relatives and friends to contribute towards small-scale development.
He revised local water ownership rights to ensure a more equitable distribution, which led to agricultural development and re-establishment of the oasis as the predominant market center. His city planning in Al Ain helped ensure that today, the city is one of the greenest in Arabia.
In August 1966, Sheikh Zayed became Ruler of Abu Dhabi, with a mandate to develop the emirate as quickly as possible. His years in Al Ain had given him valuable experience in government and time to develop a vision of progress. With the export of the first cargo of Abu Dhabi crude in 1962, he could rely on oil revenues in the service of the people, and a massive construction program for schools, housing, hospitals and roads was underway.
In 1968 the British announced their intention of withdrawing from the Arabian Gulf by the end of 1971. Sheikh Zayed, with the late Ruler of Dubai, Sheikh Rashid bin Saeed Al Maktoum, took the lead in calling for a federation that would include not only the seven emirates that made up the Trucial States, but also Qatar and Bahrain.
Eventually seven states followed Sheikh Zayed in establishing the UAE, which formally emerged on the international stage on December 2, 1971. While his enthusiasm for federation was a key factor in the formation of the UAE, Sheikh Zayed also won support for the way in which he sought consensus and agreement among his fellow rulers.
Sheikh Zayed was elected by his fellow rulers as the first President of the UAE, a post to which he was successively re-elected at five-year intervals.
One foundation of his philosophy as a leader and statesman was that the resources of the country should be fully used to the benefit of the people, including the women of the UAE who benefited of his vision of education, employment and equality.
n governing the nation, Sheikh Zayed drew from Arabian Bedouin traditions of consensus and consultation. At an informal level, that principle has long been practiced through the institution of the majlis (council) where a leading member of society holds an “open-house” discussion forum, at which any individual may put forward views for discussion and consideration.
In 1970, recognizing that Abu Dhabi was embarking on a process of rapid development, Sheikh Zayed formalized the consultation process and established the National Consultative Council, bringing together the leaders of each of the main tribes. A similar body was created in 1971 for the entire UAE: the Federal National Council, the state’s parliament.
The conservation of natural environment and wildlife was critical to Sheikh Zayed. He believed that the character of the Emirati people derives, in part, from the struggle to survive in the harsh and arid local environment and worked throughout his life on preserving such species as the Arabian Oryx and the sand gazelle. The World Wildlife Fund recognized his contribution with the prestigious Gold Panda award.
Sheikh Zayed was a firm opponent of harsh dogmas and intolerance. In an interview in 2002, he said, “Muslims stand against any person of Muslim faith who will try to commit any terror act against a fellow human being. A terrorist is an enemy of Islam and of humanity, while the true Muslim is friendly to all human beings and a brother to other Muslims and non-Muslims alike. This is because Islam is a religion of mercy and tolerance.”
Sheikh Zayed applied his ideals of consensus and tolerance more broadly. Within the Arabian Gulf region, and in the broader Arab world, the UAE has sought to enhance cooperation and to resolve disagreement through a calm pursuit of dialogue and consensus.
In the 1990s he also recognized that the UAE could play a more active role in international peacekeeping operations. The UAE Armed Forces participated in the Arab Deterrent Force that sought to bring to an end the civil strife in Lebanon, and in UNISOM TWO, the United Nations peacekeeping and reconstruction force in Somalia.
In early 1999, Sheikh Zayed was among the first world leaders to express support for the decision by the North Atlantic Treaty Organization (NATO) to launch its aerial campaign to force Serbia to halt its genocidal activities against the people of Kosovo. From late 1999 to 2001, the UAE contingent serving with the UN’s KFOR peacekeeping force was the largest from any of the non-NATO states, and the only one from an Arab or Muslim country.
While ensuring that the UAE should increasingly shoulder international responsibilities, however, Sheikh Zayed also made it clear that the UAE’s role is one that is focused on relief and rehabilitation.
In the Balkans, Iraq, Afghanistan and other countries, the policy adopted by the UAE clearly reflects the desire of Sheikh Zayed to apply the good fortune of his country to those less fortunate. Through bodies like the Zayed Charitable and Humanitarian Foundation and the Abu Dhabi Fund for Development, established by Sheikh Zayed before the foundation of the UAE, as well as through institutions like the Red Crescent Society, the country now plays a major role in the provision of relief and development assistance worldwide.
Sheikh Zayed died in 2004, in his late eighties.
Sunday, June 26, 2011
Bruce Schneier

Bruce Schneier ( /ˈʃnaɪər/; born January 15, 1963[1]) is an American cryptographer, computer security specialist, and writer. He is the author of several books on computer security and cryptography, and is the founder and chief technology officer of BT Counterpane, formerly Counterpane Internet Security, Inc. He received his master's degree in computer science from the American University in Washington, DC in 1988.[2]
Schneier writes a freely available monthly Internet newsletter on computer and other security issues, Crypto-Gram, as well as a security weblog, Schneier on Security. The weblog started out as a way to publish essays before they appeared in Crypto-Gram, making it possible for others to comment on them while the stories were still current, but over time the newsletter became a monthly email version of the blog, re-edited and re-organized.[3][citation needed] Schneier is frequently quoted in the press on computer and other security issues, pointing out flaws in security and cryptographic implementations ranging from biometrics to airline security after the September 11 attacks. He also writes "Security Matters", a regular column for Wired Magazine.[4
Schneier revealed on his blog that in the December 2004 issue of the SIGCSE Bulletin, three Pakistani academics, Khawaja Amer Hayat, Umar Waqar Anis, and S. Tauseef-ur-Rehman, from the International Islamic University in Islamabad, Pakistan, plagiarized an article written by Schneier and got it published.[5] The same academics subsequently plagiarized another article by Ville Hallivuori on "Real-time Transport Protocol (RTP) security" as well.[5] Schneier complained to the editors of the periodical, which generated a minor controversy.[6] The editor of the SIGCSE Bulletin removed the paper from their website and demanded official letters of admission and apology. Schneier noted on his blog that International Islamic University personnel had requested him "to close comments in this blog entry"; Schneier refused to close comments on the blog, but he did delete posts which he deemed "incoherent or hostile".[5]
http://en.wikipedia.org/wiki/Bruce_Schneier
About Bruce Schneier

Bruce Schneier is an internationally renowned security technologist and author. Described by The Economist as a "security guru," he is best known as a refreshingly candid and lucid security critic and commentator. When people want to know how security really works, they turn to Schneier.
His first bestseller, Applied Cryptography, explained how the arcane science of secret codes actually works, and was described by Wired as "the book the National Security Agency wanted never to be published." His book on computer and network security, Secrets and Lies, was called by Fortune "[a] jewel box of little surprises you can actually use." Beyond Fear tackles the problems of security from the small to the large: personal safety, crime, corporate security, national security. His current book, Schneier on Security, offers insight into everything from the risk of identity theft (vastly overrated) to the long-range security threat of unchecked presidential power and the surprisingly simple way to tamper-proof elections.
Regularly quoted in the media -- and subject of an Internet meme -- he has testified on security before the United States Congress on several occasions and has written articles and op eds for many major publications, including The New York Times, The Guardian, Forbes, Wired, Nature, The Bulletin of the Atomic Scientists, The Sydney Morning Herald, The Boston Globe, The San Francisco Chronicle, and The Washington Post.
Schneier also publishes a free monthly newsletter, Crypto-Gram, with over 150,000 readers. In its ten years of regular publication, Crypto-Gram has become one of the most widely read forums for free-wheeling discussions, pointed critiques, and serious debate about security. As head curmudgeon at the table, Schneier explains, debunks, and draws lessons from security stories that make the news.
http://www.schneier.com/about.html
Two-Factor Authentication: Too Little, Too Late
By Bruce Schneier
Inside Risks 178
Communications of the ACM vol 48, n 4
April 2005
The problem with passwords is that it is too easy to lose control of them. People give their passwords to other people. People write them down, and other people read them. People send them in email, and that email is intercepted. People use them to log into remote servers, and their communications are eavesdropped on. Passwords are also easy to guess. And once any of that happens, the password no longer works as an authentication token because you can never be sure who is typing in that password.
Two-factor authentication mitigates this problem. If your password includes a number that changes every minute, or a unique reply to a random challenge, then it's difficult for someone else to intercept. You can't write down the ever-changing part. An intercepted password won't be usable the next time it's needed. And a two-factor password is more difficult to guess. Sure, someone can always give his password and token to his secretary, but no solution is foolproof.
These tokens have been around for at least two decades, but it's only recently that they have received mass-market attention. AOL is rolling them out. Some banks are issuing them to customers, and even more are talking about doing it. It seems that corporations are finally recognizing the fact that passwords don't provide adequate security, and are hoping that two-factor authentication will fix their problems.
Unfortunately, the nature of attacks has changed over those two decades. Back then, the threats were all passive: eavesdropping and offline password guessing. Today, the threats are more active: phishing and Trojan horses. Two new active attacks we're starting to see include:
Man-in-the-Middle Attack. An attacker puts up a fake bank Web site and entices a user to that Web site. The user types in his password, and the attacker in turn uses it to access the bank's real Web site. Done correctly, the user will never realize that he isn't at the bank's Web site. Then the attacker either disconnects the user and makes any fraudulent transactions he wants, or passes along the user's banking transactions while making his own transactions at the same time.
Trojan Attack. An attacker gets the Trojan installed on a user's computer. When the user logs into his bank's Web site, the attacker piggybacks on that session via the Trojan to make any fraudulent transaction he wants.
See how two-factor authentication doesn't solve anything? In the first case, the attacker can pass the ever-changing part of the password to the bank along with the never-changing part. And in the second case, the attacker is relying on the user to log in.
The real threat is fraud due to impersonation, and the tactics of impersonation will change in response to the defenses. Two-factor authentication will force criminals to modify their tactics, that's all.
Recently, I've seen examples of two-factor authentication using two different communications paths: call it "two-channel authentication." One bank sends a challenge to the user's cell phone via SMS and expects a reply via SMS. If you assume that all the bank's customers have cell phones, then this results in a two-factor authentication process without extra hardware. And even better, the second authentication piece goes over a different communications channel than the first; eavesdropping is much more difficult.
But in this new world of active attacks, no one cares. An attacker using a man-in-the-middle attack is happy to have the user deal with the SMS portion of the login, since he can't do it himself. And a Trojan attacker doesn't care, because he's relying on the user to log in anyway.
Two-factor authentication is not useless. It works for local login, and it works within some corporate networks. But it won't work for remote authentication over the Internet. I predict that banks and other financial institutions will spend millions of dollars outfitting their users with two-factor authentication tokens. Early adopters of this technology may very well experience a significant drop in fraud for a while as attackers move to easier targets, but in the end there will be a negligible drop in the amount of fraud and identity theft.
Two-factor authentication
http://en.wikipedia.org/wiki/Two-factor_authentication
two-factor authentication
According to proponents, two-factor authentication could drastically reduce the incidence of online identity theft, phishing expeditions, and other online fraud, because the victim's password would no longer be enough to give a thief access to their information. Opponents argue (among other things) that, should a thief have access to your computer, he can boot up in safe mode, bypass the physical authentication processes, scan your system for all passwords and enter the data manually, thus -- at least in this situation -- making two-factor authentication no more secure than the use of a password alone.
Some security procedures now require three-factor authentication, which involves possession of a physical token and a password, used in conjunction with biometric data, such as fingerscanning or a voiceprint.
