Tag Archives: Security

Storing Passwords Securely 2

A few days ago, I wrote about the Stormpath Video on how to secure passwords. Now Stormpath has published a blog post that covers the same material. This is good stuff and if you’re working on a site that handles … Continue reading

Posted in General | Tagged | Leave a comment

Storing Passwords Securely

I’ve written several posts about securely storing passwords (this one for instance). Here’s a video from Stormpath featuring their CTO Les Hazlewood that covers the same material for those who prefer a visual presentation. Hazlewood covers various levels of password … Continue reading

Posted in General | Tagged | Leave a comment

Computer Attacks in Real Time

BetaBeat has a fascinating article (via The Atlantic Wire) on a Honey Pot project that allows you to watch attacks as they happen. Every time there’s an attack, a red dot explodes on a world map at the source of … Continue reading

Posted in General | Tagged | Leave a comment

NIST Announces SHA-3

NIST just announced the winner of the SHA-3 competition: it’s Keccak. The Keccak hash uses a completely different strategy from the SHA-2 family, something that most analysts view as an advantage. It’s not clear how quickly Keccak will be integrated … Continue reading

Posted in General | Tagged | Leave a comment

An Analysis of PIN Numbers

Over at Data Genetics there’s a great analysis of PIN numbers. By aggregating data from several breaches Nick Berry gathered 3.4 million PIN numbers and performed extensive analysis on them. Every possible value was represented in the sample but they … Continue reading

Posted in General | Tagged | Leave a comment

Security Roundup

It’s been a busy week on the security front. Of course, that’s true of most weeks but here’s some interesting stories from the past few days: CloudCracker is offering a special this week on their MS-CHAPv2 service. They will break … Continue reading

Posted in General | Tagged | Leave a comment

Some Good News From PHP

Here’s some encouraging news on the security front. As regular readers know, I’ve written several times about how to safely hash passwords and complained about sites that don’t do it correctly. Now PHP 5.5 has a function that does the … Continue reading

Posted in Programming | Tagged | Leave a comment

Password Cracking

There’s a great article over at Ars Technica about password cracking and how easy it’s become. The ease with which passwords can be cracked are the result of two things: Improved hardware using GPU processors, and Huge lists of real … Continue reading

Posted in General | Tagged | 2 Comments

Cracking WiFi Passwords

Dan Goodin over at Ars Technica has an interesting and scary article about cracking his neighbors’ WiFi network passwords. Sadly, this turns out to be a lot easier than it should be. The general process is Capture the authentication handshake … Continue reading

Posted in General | Tagged | Leave a comment

PPTP and MS-CHAP

Just in case there’s anyone left out there who’s still using PPTP as a VPN solution, H-Online has an article warning about serious security problems with PPTP when used with MS-CHAP. Even Microsoft is warning users about the issue. It’s … Continue reading

Posted in General | Tagged | Leave a comment