Tag Archives: Security

Some Good News From PHP

Here’s some encouraging news on the security front. As regular readers know, I’ve written several times about how to safely hash passwords and complained about sites that don’t do it correctly. Now PHP 5.5 has a function that does the … Continue reading

Posted in Programming | Tagged | Leave a comment

Password Cracking

There’s a great article over at Ars Technica about password cracking and how easy it’s become. The ease with which passwords can be cracked are the result of two things: Improved hardware using GPU processors, and Huge lists of real … Continue reading

Posted in General | Tagged | 2 Comments

Cracking WiFi Passwords

Dan Goodin over at Ars Technica has an interesting and scary article about cracking his neighbors’ WiFi network passwords. Sadly, this turns out to be a lot easier than it should be. The general process is Capture the authentication handshake … Continue reading

Posted in General | Tagged | Leave a comment

PPTP and MS-CHAP

Just in case there’s anyone left out there who’s still using PPTP as a VPN solution, H-Online has an article warning about serious security problems with PPTP when used with MS-CHAP. Even Microsoft is warning users about the issue. It’s … Continue reading

Posted in General | Tagged | Leave a comment

A Malware Debugging Tool From Google

After Irreal’s recent malware incident I’ve been keeping an eye out for ways to avoid any further exploits and for taking remedial action in case Irreal is reinfected. The particular piece of malware that attacked Irreal was only interested in … Continue reading

Posted in General | Tagged , | Leave a comment

Two Factor Authentication for Gmail

Mat Honan’s terrifying tale of being hacked should make all of us examine our digital security closely. If, like me and many others, a significant part of your life is lived or stored on-line, Honan’s story makes clear how vulnerable … Continue reading

Posted in General | Tagged | 2 Comments

When SSL Is Not SSL

Troy Hunt has a nice post on SSL and how many sites misuse it. As Hunt says, SSL is not about encryption. The problem that Hunt is writing about is sites that deliver a login page, say, in http and … Continue reading

Posted in General | Tagged | 1 Comment

The Dropbox Breakin

Much is being made of the supposed Dropbox break in. Several users reported that they started receiving spam at email addresses that were only used with their Dropbox accounts. Dropbox, to their credit, immediately launched an investigation and brought in … Continue reading

Posted in General | Tagged | Leave a comment

Malware Prophylaxis

After last week’s malware outbreak at Irreal I’ve been thinking about ways to prevent another episode. For those who haven’t been following along, someone managed to add a line of obfuscated PHP to the index.php file that gets things going … Continue reading

Posted in General | Tagged , | 5 Comments

Password Reuse

I’ve mentioned Troy Hunt’s writings here before. Hunt writes regularly on security and always has something interesting to say. Last year I wrote about Hunt’s analysis of passwords from the Sony compromise and—sorry but it’s true—the stupid choices people make … Continue reading

Posted in General | Tagged | Leave a comment