Security

Qubes OS: Not just for …

Security often seems like a joke: there seem to be more, and better-funded, bad actors than security practitioners. What can the average person do? One thing would be to just stop using computers and smartphones. But 99.783281% of the two people I polled on that question wouldn’t go near that …

Don't Tell Me Apple iOS …

Apple has long held itself up as a paragon of mobile security, but the wrap is unpeeling this year. The biggest news is that it never revealed the extent of a hack that infected 128,000,000 (yes, 128 million) iOS devices - iPhones and iPads - back in 2015. In fact, it’s not even clear that they …

Yet who would have …

According to a 2015-05-07 article in SANS @RISK: The Consensus Security Vulnerability Alert, Vol. 15, Number 18 (which you can get for free by signing up at https://www.sans.org/account):


"The Hospira LifeCare PCA3 Drug Infusion Pump has been found 
to contain multiple remotely …

Security Theatre, Part n

According to a BBC report on the latest security theatre, airline customers are now to be subject to the following indignities for in-flight entertainment:

  • Customers to remain seated during final hour of flight;
  • No access to hand luggage and a ban on leaving possessions or blankets on laps during …

Protecting Your Castle

SANS.org has a nice white paper showing how to protect your home network using OpenBSD and other free software. According to the abstract:


"It is possible to clean up the back yard with Free Open Source Software and a little design. Using off the shelf components and Open Source software the …

Bell Canada supporting …

The illegal spying by the U.S. Government, aided and abetted by lawbreaking telecom companies, is fairly well known. But what you might not have known is that Bell Canada quite often routes packets via the USA.  I can think of no good technological reason for this, since we have very good …

Linus Just Doesn't Get It

Linux founder Linus Torvalds makes an amazing claim about Linux security (or not) on gmane.kernel.org (I'm not even gonna help pagerank that article by linking to it; search the newsgroup name and the date 2008-07-08). Speaking about security fixes, he says:

... It makes "heroes" out of …

On Strike for a better …

When I mentioned on a mailing list that I don't use Skype because it's closed source both at the protocol level and at the code level, and further they don't even provide binaries for OpenBSD, a colleague on that list wrote back:

This is pretty strange... Are you on strike or something? Do you
use …

Sensible by Default

One of OpenBSD's mottos is "Secure by Default", but a more general form might be "Sensible by Default." I was astonished to find out the other day that some of the Linux distributions apparently produce CD-ROMs that will wipe out your hard disk if you just boot them and press …

Apple Mac OS 10.4 minor …

When you move the mouse into the "hot corner" to activate Screen Lock, there is a brief interval (maybe only a second) during which if you move the mouse out of the hot corner, the screen is unlocked!!!
This is idiotic. As I have said many times, Apple should abolish the use of "hot …