Tag Archives: Security

You Are a Target

Last week, I wrote in Nothing to Hide that although the “I Have Nothing to Hide” folks believe they are too unimportant to be targeted by governments and hackers, that is almost certainly wrong. Serendipitously, the current issue the SANS … Continue reading

Posted in General | Tagged | Leave a comment

Government and Cybersecurity

This is almost too easy. Remember how governments everywhere are whining about not being able to read our encrypted communications and are demanding a backdoor? “Don’t worry,” they tell us, “we’re the government and we’re experts in this stuff. We … Continue reading

Posted in General | Tagged | Leave a comment

Troy Hunt on Why Passwords Aren’t Going Away

I was trying to create a Web account with my credit card company so I could update some information. The process was painful beyond endurance and their password policy revealed that they weren’t using the best practices method of hashing … Continue reading

Posted in General | Tagged | Leave a comment

Emacs Security

If you follow the Emacs-Devel list, even in a desultory way, you probably noticed the long thread going back to June concerning Emacs’ insecure usage of TLS and what it means for Emacs users. LWN.net has a nice article that … Continue reading

Posted in General | Tagged , | Leave a comment

Karl Voit on Security

Karl Voit has an useful post on good password security practices. There’s not really anything new in the post but it brings together most of the best practices in a single place. The main problem is that you no longer … Continue reading

Posted in General | Tagged | Leave a comment

Diceware Video

The idea of choosing a list of common words as a password is fairly common and can lead to very secure passwords if the selection process is done randomly. The idea entered popular culture with the famous XKCD correct horse … Continue reading

Posted in General | Tagged | Leave a comment

HTTPS Is Easy

Troy Hunt, whom I’ve written about many times, has performed a public service by putting together 4 simple videos that show how easy it is to implement HTTPS on your site. The link takes you to a blog post that … Continue reading

Posted in General | Tagged | Leave a comment

A Reasonably Safe Windows Email Reading Environment

If you are unfortunate enough to work in a Windows/Outlook/Exchange/MS Office/Adobe/Flash environment, you know that you are constantly at risk of being infected with email viruses. Needless to say, no system is completely secure but there are safer alternatives. Of … Continue reading

Posted in General | Tagged | Leave a comment

Lava Lamps

If you’re a geek with an interest in cryptography, you know that one of the hardest problems in practical cryptography is random number generation. A weak PRG (pseudorandom number generator) is one of the surest ways to get a cryptographic … Continue reading

Posted in General | Tagged | Leave a comment

You Can’t Make This Stuff Up

I can’t decide if this is a joke or if someone is actually that clueless. It’s not April 1st so I’m reluctantly concluding that it’s for real1. I’m sure Miessler was surprised to learn that he’s maintaining the master password … Continue reading

Posted in General | Tagged | 1 Comment