Tag Archives: Security

The Past Comes Due for Equifax

For those who have forgotten, 2 years ago Equifax—one of the top three credit reporting services in the world—suffered a catastrophic breach that resulted in the loss of data on 150 million people. The details are drearily familiar: Equifax had … Continue reading

Posted in General | Tagged | Leave a comment

Some Pithy Advice to Engineers About Crypto

Via Karl Voit we have this Tweet from Tim Dierks offering some pithy but good advice to engineers about crypto: I’ve been working on Google’s cryptography policy (for engineers). It fits in a tweet: Don’t invent your own algorithms, don’t … Continue reading

Posted in General | Tagged | Leave a comment

Privacy.io

From John Cook’s Data Privacy Twitter feed we have this recommendation: How to protect your privacyhttps://t.co/4Os4OH1p7D — Data Privacy (@data_tip) March 14, 2019 If you’re at all interested in privacy, you should take a look at the PrivacyTools.io site. It … Continue reading

Posted in General | Tagged , | Leave a comment

An Analysis of Some Password Managers

Over at the Independent Security Evaluators site they have an interesting article on the security of of several password managers. It’s virtually universal advice from security experts that you should use a password manager and the authors of the article … Continue reading

Posted in General | Tagged | Leave a comment

An Afterword on Being Almost There

In a comment to my recent post on achieving a digital life, Zarniwoop asks about the risks of putting all my eggs in one basket if everything I need for everyday carry is on my iPhone. That’s a question I … Continue reading

Posted in General | Tagged , , , | Leave a comment

You Are a Target

Last week, I wrote in Nothing to Hide that although the “I Have Nothing to Hide” folks believe they are too unimportant to be targeted by governments and hackers, that is almost certainly wrong. Serendipitously, the current issue the SANS … Continue reading

Posted in General | Tagged | Leave a comment

Government and Cybersecurity

This is almost too easy. Remember how governments everywhere are whining about not being able to read our encrypted communications and are demanding a backdoor? “Don’t worry,” they tell us, “we’re the government and we’re experts in this stuff. We … Continue reading

Posted in General | Tagged | Leave a comment

Troy Hunt on Why Passwords Aren’t Going Away

I was trying to create a Web account with my credit card company so I could update some information. The process was painful beyond endurance and their password policy revealed that they weren’t using the best practices method of hashing … Continue reading

Posted in General | Tagged | Leave a comment

Emacs Security

If you follow the Emacs-Devel list, even in a desultory way, you probably noticed the long thread going back to June concerning Emacs’ insecure usage of TLS and what it means for Emacs users. LWN.net has a nice article that … Continue reading

Posted in General | Tagged , | Leave a comment

Karl Voit on Security

Karl Voit has an useful post on good password security practices. There’s not really anything new in the post but it brings together most of the best practices in a single place. The main problem is that you no longer … Continue reading

Posted in General | Tagged | Leave a comment