Google+
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, 12 December 2016

Cool simple little privacy tool for your webcam.

Neat little privacy slider for laptop webcams and phones:

Yep, sticking a bit of tape over the lens it waaaaay cheaper but its also messier and hassle..


UK Amazon link: http://amzn.to/2gt87RP

Sunday, 3 August 2014

UK's GCHQ certifies Master's Degrees in Cyber Security

This marks another significant step in the development of the UK’s knowledge, skills and capability in all fields of Cyber Security as part of the National Cyber Security Programme.
 
The National Cyber Security Strategy recognises education as key to the development of Cyber Security skills and, earlier in the year, UK universities were invited to submit their Cyber Security Master’s degrees for certification against GCHQ’s stringent criteria for a broad foundation in Cyber Security.

Full certified status:
  • Edinburgh Napier University - Degree - MSc in Advanced Security and Digital Forensics
  • Lancaster University - Degree - MSc in Cyber Security
  • University of Oxford - Degree - MSc in Software and Systems Security
  • Royal Holloway, University of London - Degree - MSc in Information Security
Provisional certified status:
  • Cranfield University - Degree - MSc in Cyber Defence and Information Assurance
  • University of Surrey - Degree - MSc in Information Security



http://www.engadget.com/2014/08/03/gchq-certifies-security-degrees/

http://www.gchq.gov.uk/press_and_media/press_releases/Pages/GCHQ-certifies-Masters-Degrees-in-Cyber-Security.aspx

Sunday, 13 July 2014

LibreSSL crypto library leaps from OpenBSD to Linux, OS X

Snipped the good bits fro The Reg. Link at the bottom:

The OpenBSD project has released the first portable version of LibreSSL, the team's OpenSSL fork – meaning it can be built for operating systems other than OpenBSD.

The LibreSSL project, which aims to clean up the buggy and inscrutable OpenSSL code, was founded about two months ago by a group of OpenBSD developers, so it only makes sense that getting it running on that OS would be their priority.

...

The LibreSSL developers have also worked to get OpenSSL's unorthodox and inconsistent source code into "kernel normal form" (KNF), a standard C coding style used by the OpenBSD project.

In addition, although the goal of the LibreSSL project is to create a secure, drop-in replacement for OpenSSL, the developers have also tried to undo some of the OpenSSL developers' more ill-advised design decisions.

For example, the OpenSSL library relies on a quirky custom memory-management layer that behaves in strange ways, which makes it impossible to audit the code with tools designed to flag memory management problems. The LibreSSL team has been replacing this code with new routines that use memory allocation routines from the standard C library, making it far easier to spot bugs.

http://www.theregister.co.uk/2014/07/12/libressl_portable/

Wednesday, 12 March 2014

Vodafone Germany starts rolling out SIM card based encryption

The interesting bits:

A report from The Hacker News has detailed Vodafone's plans for securing customers' data communication using a SIM card based solution which previously was possible using separate smart cards or tokens. The company has developed this solution in collaboration with its security partner Giesecke & Devrient (G&D).

The solution which will utilize a PIN and a digital signature will be used to encrypt the data at sender's end and decrypt at the receiver's ends using the SIM. Data such as emails, documents, VPN connections and other forms of data communication will be secured using it. Currently, the Secure SIM solution uses S/MIME encryption but the company expects to use PGP in the future as the system becomes mature.

Vodafone expects to launch similar encryption solution for voice calls using a Secure Call app, which the company hopes to launch on all major smartphone platforms such as Android, iOS and Windows Phone.



http://www.neowin.net/news/vodafone-germany-starts-rolling-out-sim-card-based-encryption

Saturday, 22 February 2014

Why you need to start using a password manager.

I bought against using one for ages...but my brain has failed me... I can only re-hash, re-formulate, completely re-define passwords so many times before things become impossible...

In the end people either start doing a few simple things... Using repeat passwords or worst of all, writing them down! More commonly they also use really simple passwords... That ones always been a mystery to me as to why as it's easy to come up with at least one good complex password.

So in steps some password managers:
KeePass & LastPass

There are a lot more out there. These are the best known to me.

LastPass uses the cloud and personally, I find it the easiest to use as a switch devices a lot.

For those not as happy with the cloud being used there is also KeePass.

So why use them?

Cracking passwords is becoming easier with more computational power and large lists of breaches becoming more increasingly available. The tools for cracking them are also getting a lot better. Examples being; RockYou.txt coming in around 60MB (Yes that's a .txt file).

Also think about this expert from a Ars Technica article:

"A PC running a single AMD Radeon HD 7970 GPU, for instance, can try on average an astounding 8.2 billion password combinations each second, depending on the algorithm used to scramble them. Only a decade ago, such speeds were possible only when using pricey supercomputers.


So whats the key to a half decent password these days? Length combine with complexity.Don't just pick a really long word. 

i.e. Defenestration (A favourite word of mine for some random reason)

Now the character length is good but it's bound to get found on a dictionary brute force attack.. 

Next found would be passwords like Defenestration13 or Defenestration231127

Then D3f3n3str4t10n

Now we're getting into the area of a more solid password: 

45%D3fe[3str4t^on#!1731 (Not so heavy with the l33t speak, miss some characters on purpose)

So you're happy with your genius password that you think is uncrackable. 6 months down the line its in some dictionary because Tescos, Sony, Twitter or whom ever had a breach that month was not taking enough care to hash, salt their data. 

So this is why those password managers are becoming important and I've moved over. I;ve never had a breach of security (that I know of) but with unique complex random and long passwords on my logins I will certainly minimise any damage that could be done. I would make the password to your email account particularly complex! 

A lot of services are now starting to also use 2 step authentication where your mobile / email gets sent a verification code to input at login... it costs you a little more time but it's well worth it. Get used to using them as they can also be invaluable if your password is compromised. Facebook and Google have been using these for a while and they work pretty smoothly.  MMO games such as World of Warcraft and Guild Wars 2 also make extensive use of this tech as well so it's becoming increasingly popular.

Some good links worth a read:
Wikipedia -Password cracking
ArsTechnica - The secret to online safety: Lies, random characters, and a password manager

Tuesday, 22 October 2013

CDN / security reading list.

CDN URLs:

http://www.level3.com/en/products-and-services/data-and-internet/cdn-content-delivery-network/

http://www.akamai.com/html/solutions/aura_multiscreen_del.html

http://www.akamai.com/html/solutions/aura-solutions.html

http://aws.amazon.com/cloudfront/

https://www.cloudflare.com/features-cdn

http://www.highwinds.com/ Also talks about GDN's Game delivery networks: http://www.highwinds.com/gdn/

http://www.skytide.com/

http://www.bbc.co.uk/rd/projects/adaptive-bitrate-technology


Related / content:
http://en.wikipedia.org/wiki/HTTP_Live_Streaming

http://www.cisco.com/web/about/ac49/ac0/ac1/ac259/nds.html

http://www.f5.com/products/big-ip/


Security based:

https://www.cloudflare.com/

http://www.level3.com/en/products-and-services/cyber-security/ddos-attack-protection-mitigation/

http://googleblog.blogspot.co.uk/2013/10/new-free-expression-tools-from-google.html

http://www.arbornetworks.com/solutions/service-providers

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5879/ps6264/ps5888/prod_white_paper0900aecd8011e927.html

Google - Project Shield

Project Shield is an initiative to use Google's infrastructure to protect free expression online. The service currently combines Google's DDoS mitigation technologies and Page Speed Service (PSS), which allow websites to serve their content through Google to be better protected from DDoS attacks.
http://projectshield.withgoogle.com/

Thursday, 10 October 2013

Critical WhatsApp crypto flaw threatens user privacy, researchers warn

Not good for one of the worlds most popular instant messengers if its as true as the researchers say. WhatApp didn't seem too concerned in their response to Ars.

http://arstechnica.com/security/2013/10/critical-whatsapp-crypto-flaw-threatens-user-privacy-researchers-warn/

Friday, 30 August 2013

INFINITE LOOP / THE APPLE ECOSYSTEM Rendering bug crashes OS X, iOS apps with string of Arabic characters.

http://arstechnica.com/apple/2013/08/rendering-bug-crashes-os-x-and-ios-apps-with-string-of-arabic-characters/

And for another recent OSX sudo issue see:
http://arstechnica.com/security/2013/08/unpatched-mac-bug-gives-attackers-super-user-status-by-going-back-in-time/

Not a good time for Apple devices! Although this won't help I always recommend Mac users use a anit-virus package. There is no excuse really as there are free ones out there such as Avast's: http://www.avast.com/en-gb/free-antivirus-mac . I also recommend their Android security software which is awesome and much better than Apples built in 'find my phone' feature set.

Saturday, 26 January 2013

Dodgy ads recently appearing on this site ?

Sorry to anyone who recently had some rather dodgy re-directs. I think I had some sort of code injection security issue. I've removed the majority affiliate and ads from the site and it appears to have cleared the problem. They were likely what was used to insert the malware. Please let me know if you are still seeing any unusual activity.


Tuesday, 15 January 2013