Friday, April 5, 2013

digital 9/11

from here (inspired by @gattaca's tweet)

listening to fearmongering can get so tedious sometimes. i share dave's sentiment.

george carlin on airport security



don't hold back, george, tell us how you really feel.

Thursday, April 4, 2013

mobile security

from here (source image)

for all the bells and whistles in modern mobile security suites, none are this effective at preventing theft, and hopefully none are this user-unfriendly.

camouflage win

found on failblog

this was, at one point, labeled a camouflage win on failblog - and i would have to agree because i still have difficulty figuring out what i'm looking at.

Wednesday, April 3, 2013

flip flop security

from here (source image)

i dunno. maybe there's more going on here than meets the eye, but unless those are some really smelly sandals, this isn't going to stop anyone from stealing that bike.

advanced persistent threat to candy bars



some threats are more advanced and persistent than others. you're probably not going to be able to keep this guy out of your vending machines.

Tuesday, April 2, 2013

mcafee Y U NO hash passwords?

from here (source image)

thanks to dave lewis for tweeting this insanity. the password has a maximum length and can't contain special characters? yeah, that's because they're storing the passwords in plaintext - the database field has a space limit and special characters could lead to a SQL injection.

if they hashed the passwords like they're supposed to, neither of those problems would be an issue. and this from a supposed security company? more like an insecurity company. holy crap.

selecting the form of our downfall

found on memebase

normally i just go for the really funny memes, but this one actually got me thinking. a lot of time and energy and money has been invested in going after the easy online threats, the "low hanging fruit" if you will. how much have the sophisticated attackers benefited from that lack of attention? from a strategic point of view, would it not make sense to put the majority of our effort into the hard battles rather than the easy ones?

Monday, April 1, 2013

all fails are final

from here (source article)

thanks to steve werby for bringing this little lolthreat to my attention.

benign drive-by SQL injection

found on alfredo reino's blog

there was a drive-by SQL injection image featured here 2 years ago. gunter ollman recently ran across the picture and tweeted it and one of the responses he got pointed to this much more elegant example

EDIT 2013-04-02: i don't always add stuff after the fact, but when i do, it's usually funnier than what was there before

from here