Knuth, G_D, and Crypto

[ via R. A. Hettinga ] Comp Sci godfather Donald Knuth isn’t worried about the security of his keys, he’s already been rooted by G_D. However, the cypherpunk community isn’t keen on letting The Allmighty sign their keys just yet. The browser asks if you want to trust the Aleph-One length key signed by the [...]

Denton’s Privacy Problem

Nick Denton’s all bent out of shape that Slashdot obscures their logs. Too bad Mr. Denton, I’m sorry that you don’t seem to understand that terrorism does not magicaly make the right of people to peacefuly assemble, even in cyberspace, go away. Tossing the Constitution in the dustbin so you can show those Conservabloggers just [...]

Springtime, Taxes, and the Attack on Iraq

When I first saw the title of this article in MIT’s Technology Review, I first thought of a song from “The Producers“. Richard Muller, of Cal Berkeley’s Physics department, says that an attack on Iraq will happen because Iraq’s been working on an ‘gun style’ bomb, like the one the US used on Hiroshima, and [...]

Secure Programming in PHP

[ via mac.scripting.com ] Ah, so many ways to be mauled by an 31337 H4X0R. Time for a PHP code security review.

Spammers exploiting GET hole in formmail.pl

Spammers are using a hole in the popular formmail.pl CGI-bin script to send spam. The script’s authors list several changes you can make to secure your installation. They may be completely devoid of morals, but they are clever. At least this clears up the mystery of the format of the spam I’ve gotten lately.

Suggestions for Wireless LAN Security

A list of things to do to help secure your wireless LAN.

No Foam Cheeseheads at the Superbowl, the Bastards.

[ via Oliver Willis ] Instead of worrying about Green Bay fans’ choice of headgear, Superdome officials should keep a sharp eye open for Bruce Dern. Come on, no daughter or son of America’s Dairyland is going to lower themselves to be in the employ of Islamic Facsists.

Return of the Trojan Authenticator

Will MS Passport bring back the old fake-a-legit-looking-login-screen attack?

Snort: Network Intrusion Detection that runs on OS X

What’s wonderful about OS X is taking a Unix tool and being able to run it on your Mac. For instance, Snort is a network intrusion detection tool which will compile under Darwin.

Mc Veigh Voyuer Virus

Crackers were able to exploit Americans’ homicidal mania in order to gain access to their machines. A trojan, described as a ‘pirated’ video of the McVeigh execution, was circulated in chat rooms. Upon execution of the ‘video’ (not McVeigh,) the trojan installed the usual suite of tools for someone to take control of the system.

Firewalls for OS X

How to enable and use the FreeBSD firewall in OS X.

Alcatel comments on their own security flaw

[ via Cryptogram ] Some models of Alcatel DSL modems had a major security hole (perhaps the same one that allowed script kiddies to delete all the people in that “I Have a Dream” ad?) Alcatel posted an explanatory document on the website. Unfortunately, that document was in MS Word, thus it contained all the [...]