Feb

6

In-dash Car PC For a Modest Price

Posted February 6, 2008 by Keith McMillan | Comments Off on In-dash Car PC For a Modest Price

Gizmodo had this interesting link to techabob‘s site, where he gives a quick pitch on an in-dash car PC called NaviSurfer II. This little unit comes without an OS, but has an adjustable built-in touchscreen LCD display, and costs less than $1,000 (without USB accessories).

They’ve got a nice list of accessory modules too:

  • Bluetooth USB Dongle
  • DVB-T TV Tuner
  • GPRS/GSM/CDMA USB modem
  • Wi-Fi USB modem
  • External CD/DVD drive
  • USB GPS Receiver
  • OBDII Vehicle Diagnostics
  • Digital Media Remote
  • Wireless Keyboard with touchpad
  • 4 Port USB Hub
  • SD/CF USB card reader

I’ve thought for a long time that I’d like to put a PC into my little BMW 328iS, but one of the problems has been where to put the display. It’s not what you’d call “roomy” in there, and I didn’t really want to drill holes in the dash.

This unit would solve the problem nicely. I’d have to get some sort of stereo receiver so I could still listen to broadcast, but this looks like it’d do the trick otherwise.

Feb

6

New Section on the Site

Posted February 6, 2008 by Keith McMillan | Comments Off on New Section on the Site

Since posting a quick hit on the publication of the new O’Reilly’s security book earlier this week, I thought it might be nice to have a “bookstore” on the site, with convenient links to good books.

So, now there’s a “bookstore”. Share and enjoy! I’ve set it up with a selection of the books I’ve got on my bookshelf that I’ve referred to it more than once, and some others that I have reason to suspect aren’t a waste of the paper they’re printed on.

Feb

6

ActiveX Takes Another Beating

Posted February 6, 2008 by Keith McMillan | Comments Off on ActiveX Takes Another Beating

Earlier in the week, Symantec reported that there were new flaws found in a number of Microsoft’s ActiveX controls, and the recommendation from SANS was to disable these controls due to these problems.

Today, Symantec is reporting today (via CSO Online) that they’re already seeing exploits in the wild using the Yahoo Jukebox control:

The attack, which was first observed in the last few hours, is not widespread at present. Symantec Security Response Director Oliver Friedrichs said Tuesday that the company had identified just three Web sites that were hosting the attack code, all of which seem to be linked to the same criminals. But he believes that more attacks are inevitable as the bad guys work the code into their malicious toolkits of software.

So it’s past the academic, “yes we should do that” stage, folks: either stop using IE, or get those controls disabled. You’ve been warned.

It’s easy to pick on IE: it’s a very common platform, and it’s wealth of features and tight integration with the operating system make it an attractive target. It’s also frequently a corporate standard, so there’s that built-in base of targets as well. I’ll only point out in passing that MS hasn’t made this problem any easier by disentangling the browser from the OS.

It’s unfortunate that many web application developers take the easier road, and make their web apps such that they’re only compatible with Internet Explorer. This just forces people who might want to use a different browser to use IE as well. With this approach, you then get all the vulnerabilities of each browser.

It’s seductive to get all that power, however, so we’re back to the old continuum, secure on one end, usable on the other. You want it to do whiz-bang things, that may mean that it’s less secure as a result, or takes us an inordinate amount of work to get it going.

Of course, if you need a web application because it’s critical to your business, and that web app relies on one of those insecure controls, then you’re in trouble.

Feb

5

Security as a Chore

Posted February 5, 2008 by Keith McMillan | 1 Comment

This article from CompuWorld is on it’s surface about how the French bank Société Générale lost $7.3 Billion due to unauthorized and fradulent trades by a junior trader. It’s more than that, however, as the article does a good job talking about the conflicting interests inside a large organization.

There are those people in large businesses that, either because of temperament,  lack of understanding, or lack of time, simply don’t want to deal with computer security.  It’s easier to grant all access rather than figure out the right permissions for the job, to not remember to revoke the right permissions when someone moves from one area to another, and this results in a gradual, and inappropriate, accretion of permissions. Making sure people have the right permissions, that those permissions are kept up to date, and that they’re appropriately terminated is difficult, but the consequences of not doing so are , however, clear in this case.

I can understand, and even sympathize with these overwhelmed folks. They have lots to do, and worrying about security shouldn’t keep them from getting their “day job” done. It’s the reason we need to have a strong centralized authentication and authorization mechanism in place for enterprises like this, and to have policies and procedures in place to make it as easy as possible to get these things updated on a timely basis. Without them, your business stands to lose plenty.

Feb

5

WordPress Update

Posted February 5, 2008 by Keith McMillan | Comments Off on WordPress Update

Last night, our friends at wordpress.org released version 2.3.3, which fixes a security problem in their XML-RPC implementation, so this morning I updated the site to use the new version. If you were trying to access the site at that time, you may have noticed some squirrelyness, but it should now be resolved. Please let me know if you see something amiss (my contact information is under “contact”).

Incidentally, I wanted to say that I’m really appreciating the capabilities and flexibility of WordPress. If you’re looking for blogging software, I highly recommend it, and you can’t beat the price, since it’s free.

Feb

4

The FBI Wants to Catalog You

Posted February 4, 2008 by Keith McMillan | Comments Off on The FBI Wants to Catalog You

Found over on CNN, an alarming article on the latest plans the FBI has to catalog everything about you, more or less.

The FBI is gearing up to create a massive computer database of people’s physical characteristics, all part of an effort the bureau says to better identify criminals and terrorists.

It’s really there to track criminals and terrorists, the usual boogeymen. But wait, then we read later in the article:

You don’t have to be a criminal or a terrorist to be checked against the database. More than 55 percent of the checks the FBI runs involve criminal background checks for people applying for sensitive jobs in government or jobs working with vulnerable people such as children and the elderly, according to the FBI.

The FBI says it hasn’t been saving the fingerprints for those checks, but that may change.[…]

This sort of thing makes me really uncomfortable, and that’s coming from someone who’s fingerprints are already on file. Maybe I better explain that, I used to work for a defense contractor, so my fingerprints are on file for the background check. And I’m sure that rants like this won’t help.

I’m not 100% clear on exactly how this helps with terrorists. I mean, weren’t the 9/11 hijackers here legally? Didn’t they do everything possible to stay under the radar (except asking to learn how to land, I suppose)?

Do we then want to start compiling large files on people’s points of view, monitoring their conversations, reading their email, and associating it with their biometric information, such as iris scans and palm prints, even when they haven’t done anything illegal? I’m probably just being paranoid. [1][2][3][4] It’s not like we would maintain information on people even if they’re innocent. Unless they’re applying for sensitive jobs. Or just because we say so.

Somebody hand my my tinfoil hat.

Feb

4

Second Edition of O’Reilly’s Computer Security Basics

Posted February 4, 2008 by Keith McMillan | Comments Off on Second Edition of O’Reilly’s Computer Security Basics

I’ve been a fan of O’Reilly’s computer books for years. Very seldom do I find that one of theirs is a dud. I don’t know how they do it.

A second edition of their Computer Security Basics has been released. It provides a good overview of the field, without getting into too much arcana. It’s a good starting point for those new to the field, and a good jumping off point to look to look for more in depth info.

Feb

4

How is this Heading off Botnets, Exactly?

Posted February 4, 2008 by Keith McMillan | Comments Off on How is this Heading off Botnets, Exactly?

The CSO feed today had a link to an article about a local (at least to me!) company that is producing a device that automates the detection of network based attacks. The article was headlined “Startup Looks to Head Off Botnets.”

I  chased the link because I think botnets  are a tremendous threat. They put a huge amount of computing power, scattered across the globe, into the hands of a single nefarious individual. These things are responsible for most of the spam you’ re receiving, for internet extortion, for infecting other machines, and probably for tooth decay as well (I’m not 100% about that last point). Seriously, tho, these things are nasty.

So my curiosity was piqued when I read “heading off botnets”. But we’re talking here about the automated detection of attacks. I fail to see how this qualifies as addressing head-on the problem of botnets, and in fact it’s probably a while before we see if anything interesting comes of this.

The article does raise a good point, however, the days of manually generating signatures for attacks are probably near an end, and we do need a new approach for the problems.

Feb

4

Fundamentals of UML: The Requirements Diagrams

Posted February 4, 2008 by Keith McMillan | 1 Comment

I’ve been intending to write an entry (perhaps more than one, don’t know yet) about the various Unified Modeling Language tools out there. At one point, I’d worked with more of these tools than anyone else I knew, and this gave me a bit of perspective on which tool was good for what particular use. Before I did that, I thought that it would be a good idea to do a few posts on the UML itself: what it is, why you care, and how you use it. This post covers the requirements model and diagrams, one of three broad categories of diagrams in the UML, the others being static and dynamic diagrams.

Read more

Feb

1

Navy Railgun Firing Successful

Posted February 1, 2008 by Keith McMillan | Comments Off on Navy Railgun Firing Successful

Gizmodo has an article up with video and text on the successful firing of the Navy’s new railgun. For those unfamiliar with the idea, it’s basically a really big eletromagnetic projectile accelerator. You pump a bunch of current through a series of really big electromagnets, aligned along a barrel, and it accelerates your projectile.

The US Navy has just completed a 10-megajoule test fire of their huge rail gun. For the first time ever, they fired a projectile with a velocity of 8,270 feet per second. That’s an amazing 5,640 mph, and the gun is only firing at a third of its potential power.

If you’ve got the time, a bit of skill with a soldering iron, and are bored, you can build your own. Please remember to wear safety glasses while firing.

I have to wonder a couple of things about this article. The first is, where do you get all the electricity to power one of these things on a ship? Would a nuclear reactor be sufficient (I’d think so)? How long would it take you to charge up the capacitors to fire it (what’s the rate of fire)? And finally, what kind of shielding are you going to have to put on all the electronics if you’ve got an electromagnet emitting an EMP this freaking big?


Blogroll