Tag Archives: Security

Pins And Their Distribution

If you’re a reasonably connected person—not geek, person—your smartphone is the gateway to your life. It provides access to your bank accounts and other financial information, your on-line shopping accounts, your contacts, your email and chat history, and all other … Continue reading

Posted in General | Tagged | Leave a comment

CISA Best Practices for Mobile Communications

Recently, The Cybersecurity and Infrastructure Security Agency (CISA) released some best practices for mobile communications. These are the result of the recent exploits attributed to The People’s Republic of China. While the recommendations were targeted at senior government officials, they … Continue reading

Posted in General | Tagged | Leave a comment

Law Enforcement Discovers Irony

For years, anyone with a reasonable knowledge of the situation and no ax to grind has been preaching the gospel that today’s on-line society needs strong, end-to-end encryption for the safe conduct of our electronic activities. At the same time, … Continue reading

Posted in General | Tagged | Leave a comment

Passwords And Their Problems

In response to my recent post on How Passwords Are Stolen, Smitty remarked that the bar for brute forcing your credentials is lowering. I agreed and remarked that passwords are well past their sell-by date. Unfortunately, although some reasonable alternatives … Continue reading

Posted in General | Tagged | Leave a comment

How Passwords Are Stolen

As most you know by now, I live a digital life as much as possible. I pay my bills, do my banking, order my food and other shopping, communicate with friends and family, and get my news electronically. For someone … Continue reading

Posted in General | Tagged | Leave a comment

More Hard Coded Credentials

Remember a month ago when I ranted wrote about Solar Winds making what can only be described as professional malfeasance by hard coding credentials into one of their applications? It seemed worth writing about because, after all, that was surely … Continue reading

Posted in General | Tagged | Leave a comment

Using .authinfo With Org Code Blocks

As most of you know, I’m a big fan of using literate programming techniques in the context of what might be described as “devops”. The technique boils down to writing an Org file with code blocks that document how you … Continue reading

Posted in General | Tagged , | Leave a comment

Partying Like It’s The Last Century

It’s hard to be too cynical about the security practices of software vendors: even those selling “security” solutions. Although most Irreal readers probably know a lot more about good security practices than the average user, security is a difficult discipline … Continue reading

Posted in General | Tagged | Leave a comment

Schneier On Staying Safe On The Internet

There may be more knowledgeable people on security than Bruce Schneier but hardly any of them are talking to us. They mostly work for the NSA or its brethren or they’re cybercriminals. Happily, Schneier does talk to us and he … Continue reading

Posted in General | Tagged | Leave a comment

An Analysis Of The XZ Malware Injection Process

If you’re in tech and not in a coma, you will have at least heard of the recent attempt to inject malware through the xz (de)compression utility. The technical press, as is its wont, has been blasting the story all … Continue reading

Posted in General | Tagged , | Leave a comment