Tag Archives: Security

Yet Another Reason to Encrypt Files in Dropbox

As I’ve written many many times, if you’re storing anything in Dropbox that you wouldn’t want to see published in the New York Times then you better encrypt it. Here’s yet another reason to do so.

Posted in General | Tagged | Leave a comment

Hashing Passwords: An Object Lesson

Irreal regulars know that I periodically go off an a rant about the proper hashing of passwords and the dire consequences of failing to do it correctly. Not even I, however, could have imagined that Cisco would get it wrong. … Continue reading

Posted in General | Tagged | Leave a comment

Analysis of the Gauss Malware

Over at Ars Technica Dan Goodin has a nice article analyzing the Gauss malware. Gauss appears to be related to Stuxnet and internal code signatures suggest that its provenance is the same1. Although Gauss was discovered last year, very little … Continue reading

Posted in General | Tagged | Leave a comment

Secure Communications Apps

Over at A Few Thoughts on Cryptographic Engineering, Matthew Green has a useful review of some secure communications apps. He looks at Cryptocat Silent Circle RedPhone Wickr from the standpoint of code quality, encryption protocols, and ease of use. Interestingly, … Continue reading

Posted in General | Tagged | Leave a comment

Reflections on Trusting Trust Redux

Way back in 1984, Ken Thompson wrote what I consider one of the greatest papers on computer security. I wrote about this in my The Greatest Hack of all Time post. If you haven’t read this paper your education is … Continue reading

Posted in General | Tagged | Leave a comment

Password Horror

This isn’t the usual post about some nincompoop making yet another foolish security mistake. It’s about a guy who does (almost) everything right and almost loses it all. Over at the White Hat Security Blog, Jeremiah Grossman tells a chilling … Continue reading

Posted in General | Tagged | Leave a comment

Sony: The Bill So Far

Back in 2011 I wrote about the Sony break in and subsequent disclosure of 100 million log on credentials. At the time I remarked that it would be years before the final cost of the exploit would be known. Now … Continue reading

Posted in General | Tagged | Leave a comment

Plain Text Offenders

A year ago, I wrote about Plain Text Offenders a website dedicated to naming and shaming Web sites that store their user’s passwords in plain text. Sadly, the Website has recently celebrated their 1000th post. Think about that for a … Continue reading

Posted in General | Tagged | Leave a comment

Cheswick on Passwords

Over at acmqueue William Cheswich has an interesting article on Rethinking Passwords. After listing the usual litany of problems with passwords as a security measure, Cheswick traces the historical roots of the problem. He says that we are stilling using … Continue reading

Posted in General | Tagged | Leave a comment

Is The TSA Finished?

I know, I know: I’m courting a comeuppance from Betteridge’s Law but this is too good to ignore. Christopher Elliot at Linked in has an interesting post in which he posits that the TSA, as we know it today, can’t … Continue reading

Posted in General | Tagged | Leave a comment