Tag Archives: Security

Cracking Passwords

Last May, Ars Technica published a chilling article on password cracking that I’ve been meaning to write about for a while. I urge you to take a look at it even if you’re just a user but especially if you … Continue reading

Posted in General | Tagged | Leave a comment

Dropbox and the NSA

I’ve written many, many, many, many times that if you are using Dropbox for private information that you don’t want others to have access to you better be encrypting it. And if you’re not, you have only yourself to blame … Continue reading

Posted in General | Tagged | 1 Comment

Responsible Disclosure

Most Irreal readers are familiar with the concept of responsible disclosure: the idea that if you discover an exploitable flaw in a site or piece of software, you should contact and inform the folks responsible for the site or software … Continue reading

Posted in General | Tagged | Leave a comment

Password Myths

As you all know too well, I am very interested in password technology. Certainly, passwords aren’t, by themselves, the answer to security but they can help if people pick them sensibly and Web sites handle them is a secure manner. … Continue reading

Posted in General | Tagged | Leave a comment

StrongBox

Two years ago I wrote about WSJ SafeHouse, an effort on the part of the Wall Street Journal to start their own version of Wikileaks. The idea was that prospective whistle blowers would have a safe way to send documents … Continue reading

Posted in General | Tagged | Leave a comment

What’s in a Logo?

Troy Hunt is the world’s greatest lover and he’s got the t-shirt to prove it. That’s his way of making a serious point about those badges you see on many sites certifying that the site is safe and not infected … Continue reading

Posted in General | Tagged | Leave a comment

Why Sites Have Bad Password Policies

Ars Technica has an excellent article on why many sites have security limiting password policies. I’ve written about this before on my old blog, but the Ars Technica article is particularly infuriating. So much so that this is my second … Continue reading

Posted in General | Tagged | Leave a comment

Tips on Securing a WordPress Site

After the recent WordPress Administration Page attack, my hosting provider sent its customers a link to the WordPress page on securing WordPress sites. It’s an excellent resource if you’re running WordPress and some of the ideas are general enough that … Continue reading

Posted in General | Tagged | Leave a comment

The Worst Password Tips

Mark Burnnet has an interesting post on The Worst Password Tips. His main thesis is that much—or even most—of the advice you hear about choosing passwords is no longer good advice. It used to be that passwords like p@r013 gave … Continue reading

Posted in General | Tagged | 3 Comments

A Simple Explanation of One-Way Functions and Their Application to Passwords

John Graham-Cumming has a very nice 4-part series on one-way functions and their application to passwords. The explanation is completely non-mathematical and should be understandable by anyone. By the end of the third post, Graham-Cumming has explained how a simple … Continue reading

Posted in General | Tagged | Leave a comment