it seems to me that if printers are going to be susceptible to malware now then eventually everything we put technology into will be - including the crapper.
Friday, December 30, 2011
malware's progression
it seems to me that if printers are going to be susceptible to malware now then eventually everything we put technology into will be - including the crapper.
bouncer (of junk mail)
just a simple shirt design i thought might be fitting for those in infosec who fancy themselves tough guys/gals.
Thursday, December 29, 2011
yoda's password
some more merch from the secmeme store. this one was intended to look like a post-it note with a username and password on it. you know, the kind that gets stuck to monitors and other places. as such i didn't do any clothes with this one (though i suppose i could if people want me to) because people generally don't stick post-it notes to their clothes.
now there are at least 3 ways of looking at this. first, we generally do really judge passwords by their size, and that combined with the fact that there is upper and lower case letters with a number (S1ze has a 1 in it) and a symbol might make one believe that this is a pretty strong password (the password force is strong with yoda). password strength meters would certainly say that this is a good, strong password. however, because the password is composed of dictionary words, there's actually a lot less entropy here than you might realize. but the biggest and most obvious problem, of course, is that writing it down on a post-it that you stick to your monitor invalidates any security it might have.
now there are at least 3 ways of looking at this. first, we generally do really judge passwords by their size, and that combined with the fact that there is upper and lower case letters with a number (S1ze has a 1 in it) and a symbol might make one believe that this is a pretty strong password (the password force is strong with yoda). password strength meters would certainly say that this is a good, strong password. however, because the password is composed of dictionary words, there's actually a lot less entropy here than you might realize. but the biggest and most obvious problem, of course, is that writing it down on a post-it that you stick to your monitor invalidates any security it might have.
authenticity
from here (thanks to @mikko for bringing the incident to my attention)
you might question the authenticity of the image, you may argue it looks faked, that no one would be so foolish, but i grabbed this screenshot from the following video that i found on this swedish news site
according to the news site there are humourous acronyms beyond what you can easily make out in the picture(s)/video.
OMG
WTF
STFU
PWN3D (the 3 looks more like a backwards E to my eye)
URANOOB (the first i can't make out, even in the picture @mikko tweeted)
LMAOROTF
KTHXBYE: P
*update: thanks to @Rob_OEM for pointing me towards the following image of an equivalent eyechart
*update: just to clear up any confusion, as @mikko rightly points out, the original gaffe was made by a norwegian news channel. the site i linked to above is a swedish site that was simply reporting on the gaffe. and thus ends (i hope) one of the longest secmeme posts ever.
you might question the authenticity of the image, you may argue it looks faked, that no one would be so foolish, but i grabbed this screenshot from the following video that i found on this swedish news site
according to the news site there are humourous acronyms beyond what you can easily make out in the picture(s)/video.
OMG
WTF
STFU
PWN3D (the 3 looks more like a backwards E to my eye)
URANOOB (the first i can't make out, even in the picture @mikko tweeted)
LMAOROTF
KTHXBYE: P
*update: thanks to @Rob_OEM for pointing me towards the following image of an equivalent eyechart
*update: just to clear up any confusion, as @mikko rightly points out, the original gaffe was made by a norwegian news channel. the site i linked to above is a swedish site that was simply reporting on the gaffe. and thus ends (i hope) one of the longest secmeme posts ever.
Wednesday, December 28, 2011
yes i can hear you
inspired by a loud talker on a bus, i figure there are a number of ways of getting the message across that "you shouldn't be doing that here!" - from apparel for you or your dog, to accessories, to even some stationary. whipping out a journal with this on the cover and starting to write things down would probably freak some people out. the items can be found here.
secmeme's got merch
never let it be said that i'm afraid to try new things. some time ago i started fiddling around with cafepress and i started to make some designs. first for shirts but then some other things too. what you see above is my first attempt. i put it on a bunch of clothes that you can check out and even buy here.
it occurs to me that shirts and other merchandise is actually a pretty good medium for catchphrase-type memes since it just takes one person to wear it and lots of people s/he encounter will be exposed to the phrase/meme.
there's no logo or anything pointing back to secmeme.com, mind you. i suppose i could have done something like that but i'm not trying to advertise the site.
furthermore, i've tried to make sure the mark-up is $0.00. that means i get no money from the sale of these items unless i missed something somewhere, and i might because $0 is not a default cafepress seems to endorse. i'm not looking to turn a profit (or even pay for the secmeme domain registration). what i want is for the items to be seen, and every extra penny someone has to pay is an extra reason not to buy and use the item and that's contrary to the whole exercise. no point in letting greed erect barriers to success.
it occurs to me that shirts and other merchandise is actually a pretty good medium for catchphrase-type memes since it just takes one person to wear it and lots of people s/he encounter will be exposed to the phrase/meme.
there's no logo or anything pointing back to secmeme.com, mind you. i suppose i could have done something like that but i'm not trying to advertise the site.
furthermore, i've tried to make sure the mark-up is $0.00. that means i get no money from the sale of these items unless i missed something somewhere, and i might because $0 is not a default cafepress seems to endorse. i'm not looking to turn a profit (or even pay for the secmeme domain registration). what i want is for the items to be seen, and every extra penny someone has to pay is an extra reason not to buy and use the item and that's contrary to the whole exercise. no point in letting greed erect barriers to success.
Tuesday, December 27, 2011
anonymous denial
from here
the very idea that anonymous could know that someone claiming to be anonymous wasn't in fact anonymous implies a centralized structure to anonymous. someone somewhere would have to know who is part of the group in order to make claims about who isn't. since anonymous has claimed that's not the case for some years now, the person making this denial doesn't actually understand anonymous' structure as defined by anonymous.
then again, i suppose agnosis (no knowledge) and anonymous (no name) have a tendency to go hand in hand..
the very idea that anonymous could know that someone claiming to be anonymous wasn't in fact anonymous implies a centralized structure to anonymous. someone somewhere would have to know who is part of the group in order to make claims about who isn't. since anonymous has claimed that's not the case for some years now, the person making this denial doesn't actually understand anonymous' structure as defined by anonymous.
then again, i suppose agnosis (no knowledge) and anonymous (no name) have a tendency to go hand in hand..
anonymous causality?
from here
better late than never. today i've been inspired by a rather bizarre claim by anonymous that they didn't crack stratfor
better late than never. today i've been inspired by a rather bizarre claim by anonymous that they didn't crack stratfor
Monday, December 26, 2011
facebook membership award
from here
just in case you couldn't tell that the idea of facebook giving away 1.5 million dollars was a scam, they threw in a country that is, shall we say, renowned for a lack authenticity.
just in case you couldn't tell that the idea of facebook giving away 1.5 million dollars was a scam, they threw in a country that is, shall we say, renowned for a lack authenticity.
leave virustotal alone
from here (image source)
i couldn't make up my mind whether to plead virustotal's case using Y U NO guy or chris crocker, so i did both.
i couldn't make up my mind whether to plead virustotal's case using Y U NO guy or chris crocker, so i did both.
Subscribe to:
Posts (Atom)










