Feeds:
Posts
Comments

Posts Tagged ‘security’

When an event occurs that raises the awareness of the general population to a risk from a particular threat, the mitigation strategy of many individuals seems to entail taking actions that do not in fact address the threat. Instead they purchase equipment and take actions that only make them feel better with out in fact [...]

Read Full Post »

The Internet Crime Complain Center (IC3) released a statement today about a new twist on the old online vehicle sale scam.
This scam works by advertising “competitively” priced vehicles at online classified sites like CraigsList. The seller will have a third-party involved as a kind of escrow to ensure you get your vehicle and they get [...]

Read Full Post »

X-Rays

I have a box. It is a box with a known purpose and a clear function. However, this box also purportedly contains countermeasures that prevent it from functioning should the case ever be opened. This is a problem as it is my job to open the case.
So you see my conundrum. I have to [...]

Read Full Post »

The use, breaking and securing of locks is an interest of mine that sometimes finds relevance in my daily life. I have no particular depth of knowledge nor skill in the subject, only enough to understand that basic workings of locks and on occasion pick one for the fun of it. On the topic of [...]

Read Full Post »

Any sufficiently advanced technology is indistinguishable from magic – Arthur C. Clarke
This weekend was the first Defcon I attended, and if I had to summarize what I learned, it would be two-fold.  One, any sense of security we feel in life is a lie.  Second, for some of the things the speakers were doing, I [...]

Read Full Post »

Two days ago this vulnerability was released: http://www.debian.org/security/2008/dsa-1571
Luciano Bello discovered that the random number generator in Debian’s openssl package is predictable. This is caused by an incorrect Debian-specific change to the openssl package (CVE-2008-0166). As a result, cryptographic key material may be guessable.
This is a Debian-specific vulnerability which does not affect other operating systems which [...]

Read Full Post »

From time to time we are asked to take actions that in some contexts would be considered illegal activity. At times we are asked by companies to perform actual illegal endeavors. Discerning the difference between a legal illegal activity and an illegal illegal activity can be hard to one such as myself, uninformed with the [...]

Read Full Post »

While there are many great web browsers out there, Firefox is unparalleled for web development.  I wanted to devote a post to some of my favorite extensions that I use during development….  
 

Firebug: My top choice for extensions.  Great for viewing and fixing errors that appear in the console.  I also use it to inspect [...]

Read Full Post »

cDc: Goolag

The Cult of the Dead Cow, which bills itself as “the internet’s #1 white slavery and cockfighting site” recently released Goolag an open-source, surprisingly written in C#, tool that allows one to search a site using “dorks”.
From Goolag’s specifications document:
* Dork = A detailed search pattern – [...]

Read Full Post »