Entries Categorized as 'Security'

Debian’s poor OpenSSL Randomness

Date May 16, 2008

This is worth reading.

Update: The Debian people created a website with instructions to rollover keys. And there’s also a Perl script for testing SSH servers an other packages for vulnerabilities.
Update 2: Bruce Schneier jumped in. And here is a xkcd cartoon and some source.
Update 3: Here are some useful tips (in German).

I don’t use “personal firewalls”

Date May 9, 2008

I have never used personal firewalls on my computers. And I really tend to refuse such piece of software. Maybe it’s related to my habit not to work on Windows over the last years, but I generally think you don’t get any advantages from personal firewalls. Why?

They add complexity, which is bad for security,
they have [...]

Quotes from Schneier’s “Beyond Fear”

Date May 9, 2008

Just found some interesting quotes from Bruce Schneier’s book “Beyond Fear: Thinking Sensibly about Security in an Uncertain World”. I really like this one:
“Anyone can understand security. The people who think they know best, and the people who think they ought to, would have you believe that security is like quantum mechanics or brain surgery, [...]

Security Engineering

Date May 6, 2008

One of the best books in the security engineering field is now available in its second edition. The first edition ist entirely free for download and you can even download some chapters from the latest edition.

Feeling Secure, being secure?

Date April 25, 2008

Bruce Schneier had a good article the other day: The Feeling and Reality of Security. I also recommend this one (from the comments) and an older article which is quite informative. We are all much to sensible regarding the security of our children and get the risks wrong. E.g. in former times kids had much [...]

Read then write …

Date April 19, 2008

After reading this article on The Daily WTF I found Mike Andrews’ blog post that said it all.

The 10.000 web sites infection mystery solved

Date April 18, 2008

SANS has a report about an attack that for example caused the latest outage of the Austrian WKÖ website. The WKÖ website was carrying Chinese malware at least for one hour and they are titling “Hackerangriff erfolgreich abgewehrt”?
Do they know what the German word “abwehren” means? I don’t think so.

Asterisk PBX behind NAT

Date March 17, 2008

I had a lot of problems with an Asterisk BPX behind NAT. Asterisk dropped all incoming calls after 20 seconds because of an unanswered packet. This is a well known problem when NATing Asterisk, but even Google does not provide any solution. This single problem drove me nuts last friday when I tried all possible [...]

Hacking radio controlled pacemakers

Date March 13, 2008

This is no fun and it shows the importance of building security into almost everything digital today.

Open access switch

Date March 13, 2008

Hybrid buses in San Francisco have a power switch that can be accessed easily through an unlocked panel on the outside of the bus. Tsss …