Tag Archives: Security

A Lawsuit Waiting To Happen

There’s an interesting, if depressing, post over at hover.com about how feedback had fueled new features. One of these new features seems particularly ill-advised. Apparently some of their users weren’t able to remember their passwords so Hover Would send them … Continue reading

Posted in General | Tagged | Leave a comment

Better Passwords

Over at the AgileBits Blog (the makers of 1Password) Jeff has a nice discussion of picking secure passwords. His discussion is in the context of picking a master password for 1Password but it applies more generally. Much of the really … Continue reading

Posted in General | Tagged | Leave a comment

The Security Hall of Shame

Two more inductees into the Security Hall of Shame. Honestly, I could devote a whole blog to this sort of thing. Perhaps we should start a Security Hall of Shame blog similar to Steve Friedl’s No Dashes or Spaces Hall … Continue reading

Posted in General | Tagged | Leave a comment

Lessons From Dropbox

I’ve written before about Dropbox and their supposed scandal regarding the perfectly obvious fact that they could, in fact, read users’ files stored on the site. Despite the lamentations of the aggrieved and even the filing of a complaint with … Continue reading

Posted in General | Tagged | Leave a comment

Still More Password Analysis

Three more bloggers have weighed in with an analysis of the 62,000 passwords that LulzSec released recently. These three analyses take a look at the structure of the passwords and have some interesting details that I hadn’t seen before. Aviv … Continue reading

Posted in General | Tagged | Leave a comment

The Greatest Hack of All Time

I just saw a reference to one of my favorite papers on computer security. It’s Ken Thompson’s Turing Award Lecture, Reflections on Trusting Trust. In it he describes what the Jargon File calls a truly moby hack: the insertion of … Continue reading

Posted in General | Tagged | Leave a comment

Encrypting (Some) Dropbox Files

A while ago I wrote about the developing ‘scandal’ involving Dropbox’s supposed admission that they could read your data. As I remarked at the time, no one with an ounce of sense ever thought otherwise but the question did remain … Continue reading

Posted in General | Tagged | Leave a comment

More Password Analysis

A week ago I wrote about the analysis of the Gawker passwords. Now Troy Hunt has provided a similar analysis based on the SonyPictures.com compromise. He looked at 37,608 accounts from the LulzSec torrent and analyzed the passwords for Length … Continue reading

Posted in General | Tagged | Leave a comment

As I Was Saying

No sooner had I pushed my Bad Passwords post than I stumbled on this post by Marc Bevand over at Zorinaq. Bevand reports that VISA’s Verified by VISA authentication system forces users to select weak passwords (this may not be … Continue reading

Posted in General | Tagged | Leave a comment

Bad Passwords

Alternative title: Good Grief. It’s absolutely incredible how clueless people still are about password security. You would think that anyone using the Web today would be aware of the numerous compromises that involve weak passwords. Apparently not. Over at Naked … Continue reading

Posted in General | Tagged | Leave a comment