-
Archives
- January 2023
- December 2022
- January 2021
- June 2020
- June 2019
- May 2018
- February 2018
- November 2017
- April 2017
- March 2017
- October 2016
- September 2016
- November 2015
- March 2015
- January 2015
- December 2014
- June 2014
- May 2014
- April 2014
- October 2013
- August 2013
- July 2013
- March 2013
- February 2013
- January 2013
- December 2012
- September 2012
- August 2012
- July 2012
- April 2012
- March 2012
- November 2011
- October 2011
- April 2011
- March 2011
- September 2010
- August 2010
- December 2009
- September 2009
- June 2009
- May 2009
- March 2009
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- September 2006
- August 2006
- July 2006
-
Meta
Category Archives: Commentary
Cyber UL – Reloaded
So about nine years ago Tan at the L0pht first wrote about the creation of a Cyber Underwriters Laboratory. Like the real UL the Cyber UL would be tasked with independently testing and evaluating software, specifically security related software without … Continue reading
Posted in Commentary, L0pht
Comments Off on Cyber UL – Reloaded
Security Ethics? Are there any?
I have a list of websites that I read as part of my morning ritual just like everybody else. It helps fritter away the first few minutes of the day as I wait for my tea to cool to a … Continue reading
Posted in Commentary
Comments Off on Security Ethics? Are there any?
Defacement Archive May Close
One of the more popular features of HNN (The Hacker News Network) was the daily list of web page defacements that was maintained at the time by Attrition.org. Maintaining such an archive soon overwhelmed Attrition and the task was taken … Continue reading
Posted in Commentary, Current Events
Comments Off on Defacement Archive May Close
More USB Snake Oil
I’m still busy recovering from the excellent Source Boston conference and I will post a recap soon but I wanted to get this out there. Last week I wrote about RFID enabled external hard drives that supposedly offered secure encryption … Continue reading
Posted in Commentary, Snake Oil
Comments Off on More USB Snake Oil
More secure products that aren’t
Think that cool USB thumb drive you just bought with the word of ‘encryption’ written in big letters all over the package is really secure? Think again. ComputerWorld recently reviewed seven ‘secure’ USB drives and basically found that they are … Continue reading
Posted in Commentary, Snake Oil
Comments Off on More secure products that aren’t
Tamper Resistant Point of Sale Machine Isn’t
When I see something labeled tamper-resistant or even tamper-proof I don’t assume it is secure I just think that it is a little more difficult to break into than something that isn’t tamper-resistant. Three researchers at the University of Cambridge … Continue reading
Posted in Commentary, Current Events, Snake Oil
Comments Off on Tamper Resistant Point of Sale Machine Isn’t
Less Than Two Weeks to Source2008
So I was having lunch with one of the organizers of the Source Boston 2008 conference yesterday (Spicy Beef Bowl, mmmmm) and realized that this is going to be one really great conference. Not only are there big name speakers … Continue reading
Posted in Commentary, Current Events
Comments Off on Less Than Two Weeks to Source2008
AES = XOR = Secure? WTF!?!
I don’t have time for all of the stupidity out there but this is just to stupid to let pass by. Easy Nova a German company that makes a variety of computer storage accessories, recently released a hard drive case … Continue reading
Posted in Commentary, Current Events, Snake Oil
Comments Off on AES = XOR = Secure? WTF!?!
Responsible disclosure for vendors?
If a vendor finds a vulnerability in a competitors code are they obligated to tell them? What exactly is ethical and or responsible disclosure when it comes to competing vendors? Among security researchers the general consensus these days is to … Continue reading
Posted in Commentary, Current Events
Comments Off on Responsible disclosure for vendors?
More POS Hacks Grab CC Numbers
Everyone gets a kick out of TV shows and news reports that feature stupid criminals. People who get themselves locked inside the store they are trying to rob or stuck in the air vent attempting to break in. For some … Continue reading →