Showing posts with label security dinosaur. Show all posts
Showing posts with label security dinosaur. Show all posts

Friday, February 28, 2020

Blockchain is not the answer

from here and here (image source)

It's something that comes up again and again in all sorts of areas. People who are trying to solve a problem think "I know, I'll use the blockchain" and then they have a bunch of problems. It seems even Ron Rivest agrees (at least in the context of voting) that blockchain is not the answer.

Thursday, November 30, 2017

How is "too long" still a thing in 2017?

from here and here

Thanks to Paul Gilzow for pointing out how foolish it is to have a password length limit in this day and age, and, incredibly, getting a representative of the company in question to consider the possibility that Paul is right.

Tuesday, March 14, 2017

No one is that unimportant

from here

It doesn't matter who you are or how unimportant you think you are, everyone has something an attacker wants, even if it's just another bot for their botnet or another ransomware payout.

Monday, May 9, 2016

The Only Way To Pass This Test Is Not To Take It

from here

Whether it's a program that could be a password stealer for all you know, or a website that shares your password in the clear with dozens of advertisers, there's really no good way to implement a password strength test without expecting users to do something unwise with their passwords. Password strength testers really need to go extinct because they do not help improve people's security, they promote insecure behaviour.

(Just a reminder: as cool as dinosaurs may be, you don't want to be a security dinosaur).

Thursday, April 28, 2016

My Privacy & Security Get Along Just Fine, Thanks

from here

Some people will tell you that privacy and security are at odds with one another, but that's not the case. Whenever privacy vs. security comes up it's actually your interests vs. the interests of the state or some other authority. It's just framed as privacy vs. security to make you more likely to accept a bad compromise.

Friday, April 1, 2016

More Like Just "Forget Protection"

from here
Set and forget means that it involves the user as little as possible, and you might think that's a good thing, but that means it's up to your computer alone to outwit intelligent opponents, and guess what, your computer just isn't that smart.

Wednesday, February 17, 2016

Best According To Whom?

from here

Over and over again I hear about password best practices, but invariably they turn out to be practices from the last century and as such are no longer anywhere near best anymore. What's worse is that everyone's idea of what constitutes best practices for passwords is a slightly different variation of the decades old advice. There is no agreement on what constitutes best practices so the term "best practices" doesn't even refer to a definite, well defined thing.

What we now know about passwords is this: 1) generated passwords are stronger than chosen passwords, and 2) recording passwords scales better than remembering passwords. Password managers cover both of these facts.

Tuesday, October 20, 2015

How We Lose Freedom In The Name Of Security

from here

We've grown accustomed as of late to the use of "terrorism" as way to scare people into accepting fewer freedoms in exchange for questionable advances in security, but before 9/11 this ploy was used a fair bit and it's still just as capable today (if we ever wise up to the terrorism ploy).

Monday, October 12, 2015

TLS Is The New Hotness Now

from here

If you're still talking about SSL now that all versions of SSL are essentially deprecated, you should stop.

Monday, October 5, 2015

This Is The Way To Never Improve

from here

This is the way to never improve,
Never improve,
Never improve,
This is the way to never improve,
Your security posture.

Monday, September 28, 2015

Maybe Forcing People To Go Back To Post-It Notes Is Even More Insecure

from here

On Twitter, @munin is trying to figure out where the bullshit idea to block pasting passwords into password fields (thus making the use of password managers much more difficult) came from (so he can kill it with fire, one hopes). If you think you know the origin, drop him a line.

Monday, September 21, 2015

For When You Want To Pretend You Know What You're Talking About

from here

Keeping track of how many products can detect a sample while hobbled by VirusTotal's configuration is just about the most meaningless thing you can do.

Monday, June 1, 2015

If By "Things" You Mean The NSA Then Yes

from here

Hard to believe in this day and age, with all the advances that have been made in computer power, people still think performance is a reasonable excuse for not encrypting things.

Wednesday, February 25, 2015

Because That's What It Takes To Get People To Click

from here

Attackers are only as sophisticated as they need to be, and considering the sorry state of most organizations' security that means most are not very sophisticated at all.

Thursday, July 31, 2014

That's Some Prehistoric Snake-Oil, Right There

from here

I'll never understand what the allure is supposed to be considering how awful the military's infosec track record is.

Wednesday, July 16, 2014

Don't Write Cheques That Your Ass Can't Cash

from here

Silly Trustwave. Snake oil is for snakes.

Wednesday, April 30, 2014

You Can Pick Your Nose But Don't Pick Those

from here

Seriously, a good password manager will not only store and enter passwords for you, it'll generate them too. Choosing them yourself is so obsolete.

Wednesday, April 23, 2014

Maybe You Should Stop Playing Games

from here

Here's a sentiment that really needs to go die in a fire. Security isn't something you win or lose at, don't treat it like it's a game. Cybercrime is CRIME. Nobody talks about regular criminals "winning", and it's not because criminals aren't getting away with stuff (they certainly are), but rather because that's a ridiculously simplistic way of looking at the world.

Defenses will always have weaknesses. There will always be victims. Stop putting all your eggs in the prevention basket and start learning how to recover from failure. Being able to recover from failure is the only way anyone succeeds.

Monday, April 14, 2014

Security Burnout And Other Whining

from here

People are part of the system. That means they are sometimes part of the problem. Quit your belly aching and start working on solutions that acknowledge that fact.

(Inspiration)

Friday, April 11, 2014

Hard To Believe The Security Of So Many Rests On The Shoulders Of So Few

from here

Perhaps if OpenSSL had enough financial resources to support more than a measly 4 core developers (only 1 of whom is full time) problems like the Heartbleed bug could be avoided.