Tag Archives: Security

Security and Unicode

I’ve written before about the wonders of Unicode but this post is an example of its dark side. Over at the Microsoft Malware Protection Center there is an interesting post about the use of Unicode by malware. It seems that … Continue reading

Posted in General | Tagged | Leave a comment

SSH Tricks

Smylers over at the Smylers Blog has an outstanding post on little known things you can do with SSH. Even after years of using SSH daily, there were still a couple of tricks new to me in the post. Smylers … Continue reading

Posted in General | Tagged | Leave a comment

How Passwords Get Stolen

I just stumbled across a nice post on How Attackers Steal Passwords by Joe Golton over at FilterJoe. It’s an interesting look at the common attacks on user passwords. There’s not a lot new or surprising in the post but … Continue reading

Posted in General | Tagged | Leave a comment

Diceware Implementation (Part 2)

Last time I presented an implementation of the Diceware method for generating a secure password. Today I’d like to finish up with a few details. First, the careful reader might wonder why I generated 4 random bytes with RAND_bytes instead … Continue reading

Posted in Programming | Tagged | 1 Comment

An Implementation of Diceware

A few of my recent posts (1, 2, 3) discussed the Diceware method of choosing a password. The idea is that you roll a die 5 times to get a 5 digit number and use that number to look up … Continue reading

Posted in Programming | Tagged | Leave a comment

Troy Hunt On XKCD Password Security

Troy Hunt, whose work I admire and have mentioned before (1, 2, 3) has posted about the XKCD password security cartoon that I wrote about in Password Advice From XKCD. It’s easy to misconstrue his post as being critical of … Continue reading

Posted in General | Tagged | Leave a comment

How People Select Their Passwords

The invaluable Troy Hunt has run another analysis of recent dumps of password data from Anonymous, LulzSec, and others. This time he looks at how people select their passwords. As with his previous analyses, the results are depressing. His idea … Continue reading

Posted in General | Tagged | Leave a comment

Password Advice From XKCD

In view of today’s XKCD: I thought it would be useful to again mention the post by Jeff over at the Agile Bits Blog. That post discusses making a password by choosing 5 or 6 random words for your passwords. … Continue reading

Posted in General | Tagged | 1 Comment

Common iPhone Pins

I’ve written several (1, 2, 3) posts about the analysis of passwords divulged by groups like LulzSec. The results were terrifyingly consistent: 123456 and password were almost always the most frequently used passwords. Now Daniel Amitay author of the Big … Continue reading

Posted in General | Tagged | Leave a comment

The 25 Most Dangerous Software Errors

Each year the SANS Institute and the MITRE Corporation team up to survey the year’s most dangerous programming errors. This year’s list, the 2011 Common Weakness Enumeration, was published at the end of June. This is a great resource and … Continue reading

Posted in Programming | Tagged | Leave a comment