I used to pretty much only use my laptop, which was nice, because all my data was stored in one place. However, I now use a desktop computer at work. For the most part, it's OK, because I don't need to access much work stuff from home, and vice versa. However, occasionally it does happen, and so I'm thinking more about online services.
Clipperz is an online password (or other textual data) manager. Now for most security-conscious people, “online” and “password manager” do not go together. However, Clipperz uses JavaScript to encrypt all your data before sending it to their servers. That means that none of your data can be accessed by Clipperz (or anyone else) unless they know your password.
Even better, Clipperz is free/open-source software, which means that if you really don't trust them, you can audit their source code. Or run your own service.
I had thought about implementing something similar, but Clipperz does more-or-less what I want it to, plus some things that I hadn't thought of. The only downside is that I wish it would have better organizational features (in particular, a hierarchical organization).
No, not that kind of hash. The NIST is holding a contest for a new cryptographic hash function. Vulnerabilities have been found in the most commonly used hash functions, MD5 and SHA-1, and the contest is for the new SHA-3 standard. The deadline for submissions was last Friday, so if you missed it, too bad.
Schneier et al. have submitted their algorithm, called skein, and Rivest et al. have submitted MD6.
The NIST held a similar contest several years back for encryption algorithms, which resulted in Rijndael being officially named as the Advanced Encryption Standard. That contest took 5 years. We'll see how long this one takes. Hashing is generally less well-understood, and harder to do, than encryption.
(see also: /.)
The National Research Council has released a 352-page report that tells us what most of us knew already: trying to use data mining to find bad guys doesn't work very well. The problem being that there are too many false positives.
Whether or not this will actually stop anyone from trying to do it anyways remains to be seen.
At least, Elvis’ passport was sighted. And despite being dead, Elvis managed to get a new “un-forgeable” RFID passport.
Security researchers managed to modify an RFID-based passport so that it seems to belong to “Elvis Aaron Presley,” complete with photo.
The problem is not so much with the ability to forge passports, but rather with the claims that they are un-forgeable, and the false sense of security. If security personnel believe that the passports are un-forgeable, then we actually become less secure because of it.
(see also: /.)
As we all know, the only way to make sure that terrorists don't sneak weapons onto planes is to require that all airline passengers fly naked, without any carry-on luggage. Well, it looks like we're one step closer to that. Several American airports have installed new scanners that can see under peoples’ clothing.
And, like most recent airport security measures, the security scanners are not only completely unnecessary and useless, they also seem to be completely ineffective too.
The scanners do a good job seeing under clothing but cannot see through plastic or rubber materials that resemble skin, said Peter Siegel, a senior scientist at the California Institute of Technology. "You probably could find very common materials that you could wrap around you that would effectively obscure things," Siegel said.
Yes, apparently you can find some certain materials, wrap them around your body, and hide weapons there.
I blogged about a year an a half ago about spam killing statistics on my server. I thought I'd post an update since then. These are the spam rejections from the past 10 days.
Obviously, these numbers don't show the whole picture — they're only based on 10 days of activity. For example, the backscatter that I get seems to happen in waves, so it's low now, but some times, it's huge.
So in all, in the past 10 days, my mail server rejected 5,370 messages (compared to 3,281 from my last blog) and accepted 873 (compared to 564 from my last blog) messages. I also have another layer of spam filtering when I fetch the mail from my server.
So, spam volumes are up by about 1.6 times. General mail volume is also up — I'm subscribed to a few more mailing lists.
Changes to my filtering setup since last time include:
I've also started reporting some spam via spamcop.
Jes complained that I haven't blogged recently, so here it goes. I'm back in Waterloo, after a nice break in Edmonton. I got back on the 8th. Southern Ontario has had a lack of snow this winter ... until I got back. It started snowing the night I got back, and since then, we had one or two days without snow on the ground. We even had a snowstorm that shut down the school last Monday.
On my flight back, I was randomly selected at security for a patdown, I guess to make sure that I wasn't hiding a plastic gun in my pants that would evade detection by the metal detectors. The guard who searched me was professional an courteous. Random searches are a good thing for security, as long as they are truly random, and not based on things like racial profiling. Because once you start trying to profile, the terrorists will recruit people who don't fit the profile.
Thumbs up to cashiers in Alberta (at least the ones that I met at Best Buy and MEC). The signature on my credit card is worn off. The cashiers in Alberta actually checked that it was me by asking for my driver's license. Nobody in Ontario ever checked my license.
Thumbs down to the Vancouver airport. They had to shut down the international terminal and re-screen everyone because of a security mess-up. I don't know the exact details, but it seems like somebody failed to do their job.
As usual, my news pile is backing up (but not bad as my photo pile — I still have my summer photos to put up). So here's a dump of some of the articles.
First of all, don't take pictures of the police, or you might get arrested. (/., /. followup) (Even if you are fully within your rights to do so.)
Also, don't play in trees if you are a 12-year old child. You'll get arrested, and put your DNA on record. (/.)
If you're in an American airport, don't say that the TSA Director Kip Hawley is an idiot, even if he really is an idiot. (KHIAI, /.) If you do that, you may get detained. Because apparently freedom of speech doesn't apply inside an airport.
OK, enough sarcasm. (What? Hubert being sarcastic? Never...)
Electronic voting machines are becoming more commonly used in the US. But it seems like every month, there's a new problem that's found with them. The Open Voting Foundation took apart a Diebold machine, and found that it just takes flipping a single switch, and you can make the machine load your own software, instead of the (supposedly) certified software. (/.) The electronic voting machines also wreaked havoc in Maryland elections. Ed Felten et al. have shown how to infect a Diebold voting machine with a virus and change election results. (Dr. Dobbs, /.)
As Canada considers implementing their own version of the DMCA legislation, Professor Michael Geist, ran a series called 30 Days of DRM, which outlined 30 issues that need to be considered in anti-circumvention legislation. (A brief background: DRM, or “Digital Rights Management”, also called “Digital Restrictions Management”, is a term that refers to technologies used to limit access to digital media, such as music and movies. Anti-circumvention legislation makes it illegal to bypass DRM, aimed at preventing unauthorized duplication, but which also prevents legitimate use of the media.)
Despite claims of security, the new e-passports have been cloned. (/.) While this is not the same as creating a new, fake passport, it is still a significant hole. Some security is gained by embedding a chip inside a passport, but the new passports are generally viewed as unforgeable, giving people a false sense of security.
And the Senate Judiciary Committee has voted to extend the US's warrantless wiretapping. (/.) Because who needs judicial oversight? (Whoops. There I go with the sarcasm again.)
Remember the big scare back in August, that caused airline passengers to not be allowed to bring liquids (with a few exceptions) on board an airplane? Well, a Pakistani judge has ruled that there is not enough evidence against one of the key suspects to link him to any terrorist activities. (BBC, Al Jazeera, /.) Can we please have our water bottles back, now?
This page was made from only the finest electrons.
© Hubert Chathi <><