Showing posts with label one does not simply x. Show all posts
Showing posts with label one does not simply x. Show all posts

Friday, March 3, 2023

They are humour impaired

from here and here

I'm surprised people still make this mistake, but you should absolutely not joke with the airport security about bombs or hijacking. You aren't going to like it when they put you in jail. I don't care how funny you think you are, or even how funny you actually are, they won't be laughing.

Monday, June 14, 2021

How "smart" is that exercise bike now?

from here

>It's hard to get over the idea of entrusting the privacy of your data to a company with the same name as ECHELON, even if there wasn't a specific security incident calling their capabilities into question

Tuesday, January 7, 2020

Always have a backup plan

from here

It's a shame that people lost their jobs because their company couldn't recover from ransomware, but it could have just as easily been a fire or hardware failure or some other disaster and there's no one you can pay to undo that kind of thing. If all you're planning to do is pay someone when disaster strikes it's not going to end well. You need to be prepared long before disaster strikes.

Tuesday, June 25, 2019

Fingered by a thumb drive

from here

You'd think members of Anonymous would have good enough OpSec sense to know that you leave your personal belongings at home when you're out committing crimes. Apparently not everyone got the memo.

Thursday, March 14, 2019

There's an app for that

found on Quick Meme

This right here is one of the reasons some people call antivirus apps viruses. I remember a time when there were dedicated removal tools for certain viruses (and some other malware). When antivirus software becomes just as difficult to remove from your system as malware, it does not inspire confidence.

Tuesday, November 6, 2018

Except in Kentucky

from here

Gosh, I sure home nothing bad happens as a consequence of intentionally leaving an election-related server wide open like that.

Is there something about Kentucky that Americans know but the rest of us don't?

Friday, October 19, 2018

If at first you don't succeed...

from here

Recidivism is exactly why cyber-criminals are a bad fit for security companies. Crackers may not be as dumb as this guy, but they might just be confident enough in their own intelligence to think they've worked out all the bugs in their criminal enterprise.

Thursday, October 4, 2018

Everyone is the AV guy/gal there

from here

You know who you are and you know what you've done. I'm not going to shame you any more than you've already shamed yourself.

Thursday, May 3, 2018

I hope they didn't fall off the back of a truck

from here

Thanks to Asher Wolf for raising awareness of this apparent data breach. It's an interesting state of affairs. On the one hand they have no evidence the data was retrieved by anyone so they assume it wasn't, while on the other hand they have no evidence the data was destroyed so they assume it was. It's amazing what people can do with no evidence.

Wednesday, April 25, 2018

Privacy - Let me google that for you

from here

Hard to believe in 2018 a company the size of Google could release a chat service with no end-to-end encryption. How out of touch do you have to be to do that now? These days a messaging application without encryption is a toy, not a product.

Wednesday, April 18, 2018

Always bet on a hack

from here

Why am I not surprised that an IoT thermometer was used to steal data from a casino? Even though casinos are notoriously scrupulous about security (even computer security), it's not hard to imagine people failing to realize the risk posed by a thermometer.

But it's not really a thermometer, it's a computer that also happens to measure temperature. Computers replacing ordinary things is a trend that seem destined to end badly.

Wednesday, March 28, 2018

Maybe it'll be end-to-end-to-end encrypted (Microsoft-in-the-middle)

from here

In January everyone was singing Microsoft's praises for their promise to incorporate the Signal protocol into Skype. I'm pretty sure that praise is about to come to an abrupt end if they're banning bad words. Microsoft can't do both. They can't have their cake and eat it too.

Thursday, December 28, 2017

Someone drank too many Long Island Iced Teas

from here

An iced tea company reinventing itself as a blockchain company reminds me an awful lot of a restaurant company reinventing itself as a biometrics company, and that didn't end well for anyone except the scammers at the heart of the plan.

Wednesday, November 29, 2017

Would you trust a social network with your life savings?

found on Imgflip

If you use the same password for both then Twitter is essentially in possession of the key that unlocks all your finances, and I don't think that's something they planned to protect when they were devising their defenses. Even if it was something they planned for, that doesn't mean they'd be any good at it. Certainly I wouldn't expect them to be better at protecting that than they were at protecting President Trump's Twitter account.

Friday, September 1, 2017

What could possibly go wrong?

from here

If this is the kind of fore-thought we can expect from the new FCC, I think we're going to need to find an alternative interpretation for those 3 letters.

Monday, July 31, 2017

When best practices should be the only practices

found on Stack Exchange

I know this best practice. I follow it as best I can, but after spending a week trying to figure out a way to use PBKDF2 securely with just ordinary .Net (no  extensions or additional 3rd party libraries) and failing, I'm starting to see why people continue to violate this best practice.

Friday, July 15, 2016

Doesn't Seem To Make It More Secure

from here (source image)

Adding security after the fact (bolting it on) ranges from just partially effective to not effective at all and purely just for show.

Friday, January 9, 2015

One Clue To Fool Them All

tweeted by George V. Hulme

Thanks to George V. Hulme for tweeting this meme expressing doubt that we can ever figure out who committed an online attack with any accuracy. As @thegrugq has said, the attackers control too much of the forensic information we'd have access too in the online world, they can easily deceive us.

Now, if there's offline evidence about who did what, that could be a lot more compelling than pointing at a map and saying "we saw their IP address(es) in traffic related to the attack".