Category: security

openPGP usage

Over at the the cypherpunks mail list, one Tony Arcieri posted a graphic showing an interesting rise in the number of OpenPGP keys registered on the SKS keyserver in the last month or so. The graphic comes from the SKS statistics page. The overall trend is clearly upwards, and has been for some time, but …

Continue reading

Permanent link to this article: https://baldric.net/2013/08/25/openpgp-usage/

thank you citizen

Imagine Dave’s censorship (^W) surveillance program outsourced to G4S.

Permanent link to this article: https://baldric.net/2013/08/23/thank-you-citizen/

untrusted dod certificate

Chris Williams over at El Reg posted a nice article about the kind of crypto best practice you need to follow if you care about privacy. The article questions the wisdom of using David Miranda as what Williams calls a “data mule” to carry physical electronic media (possibly) containing sensitive data through Heathrow and goes …

Continue reading

Permanent link to this article: https://baldric.net/2013/08/23/untrusted-dod-certificate/

tor usage on the rise

A couple of weeks ago I noted that the release of tails 0.20 seemed to be popular – at least if the traffic on my mirrors was anything to go by. The statistics published by the Tor project itself show an interesting rise in (probable) Tor usage since June. The graphic shows that the number …

Continue reading

Permanent link to this article: https://baldric.net/2013/08/22/tor-usage-on-the-rise/

aunty doesn’t get it

The BBC has today commented on the Guardian story about David Miranda’s detention for nearly nine hours at Heathrow under Schedule 7 of the UK Terrorism Act 2000. The BBC’s on-line report ends with a web feedback form asking: Have you been detained under schedule 7 of the Terrorism Act 2000 at a British airport, …

Continue reading

Permanent link to this article: https://baldric.net/2013/08/20/aunty-doesnt-get-it/

tor users under attack

The Tor network does not just provide anonymous internet access, it also provides for so-called hidden services. These services are not visible outside the Tor network and are only reachable over Tor. The servers are given Tor specific addresses of the form “xyz123.onion” (actually, the addresses are a little more complicated than that because the …

Continue reading

Permanent link to this article: https://baldric.net/2013/08/10/tor-users-under-attack/

lavabit dead

I run my own mail server for a number of reasons. And I rarely regret that decision. However, there have been occasions in the past when relying on a single mail provider (even when that provider is myself) has proven problematic. The first problem arose several years ago when the ISP which I use for …

Continue reading

Permanent link to this article: https://baldric.net/2013/08/09/lavabit-dead/

security failure at digital ocean

This morning I received an email from Digital Ocean titled “Avoid Duplicate SSH Host Keys”. The email said: “If you have created an Ubuntu Droplet or snapshot prior to July 2nd, DigitalOcean recommends regenerating the SSH host keys. Droplets based on standard images now create unique SSH host keys.” (This, of course, implies that they …

Continue reading

Permanent link to this article: https://baldric.net/2013/08/03/security-failure-at-digital-ocean/

repeat after me – snowden is not the story

John Naughton has an interesting column in his “networker” series in today’s Observer. In it he laments the fact that the majority of the world’s mainstream media seem more intent on reporting on Snowden the man than on what Snowden has revealed. He starts: “Repeat after me: Edward Snowden is not the story. The story …

Continue reading

Permanent link to this article: https://baldric.net/2013/07/28/repeat-after-me-snowden-is-not-the-story/

soldier available cross magnet

I am in the process of changing passwords on a bunch of different systems/applications and have been pondering my algorithms, so to speak. Like my friend David, I have an internal model of varying password schemes which I can use in different places. This means that I can happily pick a password for a low …

Continue reading

Permanent link to this article: https://baldric.net/2013/07/26/soldier-available-cross-magnet/

ubuntu forums compromised

Right now (21.00 today), the ubuntu forums site says it is “down for maintenance”. It appears to have been down since yesterday. The site reports: There has been a security breach on the Ubuntu Forums. The Canonical IS team is working hard as we speak to restore normal operations. This page will be updated regularly …

Continue reading

Permanent link to this article: https://baldric.net/2013/07/21/ubuntu-forums-compromised/

save your money – just use tails

I suppose it was inevitable that the Snowden revelations would lead to greater interest in privacy and anonymity. I applaud that. I suppose it was also inevitable that there would be a rash of commercial products emerging from both “entrepreneurs” and the more established “security” companies to take advantage of that increased interest. That, I …

Continue reading

Permanent link to this article: https://baldric.net/2013/07/17/save-your-money-just-use-tails/

tor and https at eff

For those of you unsure of what might leak where and when using tor and/or https to protect your browsing, there is a useful interactive graphic on the EFF site. As EFF point out, the potentially visible data includes: the site you are visiting, your username and password, the data you are transmitting, your IP …

Continue reading

Permanent link to this article: https://baldric.net/2013/07/15/tor-and-https-at-eff/

more irony

This is lovely. On a whim I have just checked the DNS for the Guardian. I got the following results: MX records: guardian.co.uk mail exchanger = 30 guardian.co.uk.s200b1.psmtp.com. guardian.co.uk mail exchanger = 40 guardian.co.uk.s200b2.psmtp.com. guardian.co.uk mail exchanger = 10 guardian.co.uk.s200a1.psmtp.com. guardian.co.uk mail exchanger = 20 guardian.co.uk.s200a2.psmtp.com. So – all four MX records point to SMTP …

Continue reading

Permanent link to this article: https://baldric.net/2013/06/24/more-irony/

trivial traffic bump

I normally get around 1000 to 1300 hits a day (or 32,000 to 40,000 per month) on trivia. Not a huge hit rate, but consistent and on a slight upward trend over the past year. Today I have seen over double that – most of it this morning. Between 05.30 and 07.00 local time my …

Continue reading

Permanent link to this article: https://baldric.net/2013/06/17/trivial-traffic-bump/

prism opt-out

In all the noise on the ‘net about the alleged NSA PRISM program, this new site offers an amusing, but nonetheless useful, list of free alternatives to proprietary software. In part the site sort of misses the point about PRISM, but it is still good to see someone taking the time to point out that …

Continue reading

Permanent link to this article: https://baldric.net/2013/06/16/prism-opt-out/

Edward Snowden

The revelations of the past week or so have been interesting to me more for what they haven’t said, than what they have. There are a few points arising from Snowden’s story which puzzle me and which don’t seem to have been addressed by the mainstream media – at least not the ones I read. …

Continue reading

Permanent link to this article: https://baldric.net/2013/06/15/edward-snowden/

PRISM – we had it first

I can exclusively reveal that the UK government had a PRISM database long before those upstarts in the USA. In the late 1970s I worked in the Statistics Division of what was then the UK Civil Service Department. We used a database of Civil Service personnel called PRISM (Personnel Record Information System for Management). I …

Continue reading

Permanent link to this article: https://baldric.net/2013/06/10/prism-we-had-it-first/

another good reason not to buy one

Back in November 2011 I wrote about the TP-Link TL-SC3130G IP camera. I had some trouble getting that device to work properly over wifi so I returned it and got my money back. Today, Core Security released an advisory about this device (and several others from TP-Link) about a remotely exploitable vulnerability arising from “hard-coded …

Continue reading

Permanent link to this article: https://baldric.net/2013/05/29/another-good-reason-not-to-buy-one/

gchq recruitment site stores plaintext passwords

I can’t resist this. El Reg today points to a blog post by a guy called Dan Farrall who has commented on his experience of receiving a plain text reminder of his GCHQ recruitment site password by email after filling out its forgotten password form. Farrall’s blog post is worth reading. Whilst he acknowledges that …

Continue reading

Permanent link to this article: https://baldric.net/2013/03/27/gchq-recruitment-site-stores-plaintext-passwords/

using an ssh reverse tunnel to bypass NAT firewalls

There is usually more than one way to solve a problem. Back in October last year I wrote about using OpenVPN to bypass NAT firewalls when access to the firewall configuration was not available. I have also written about using ssh to tunnel out to a tor proxy. What I haven’t previously commented on is …

Continue reading

Permanent link to this article: https://baldric.net/2013/03/26/using-an-ssh-reverse-tunnel-to-bypass-nat-firewalls/

no sites are broken

Or so the wordpress post at wordpress.org would have us believe. However, I think there is flaw in both their logic, and their decision making here. I spotted the problem following an upgrade to wordpress 3.5 on a site I use. One of the plugins on that site objected to the upgrade with the following …

Continue reading

Permanent link to this article: https://baldric.net/2012/12/19/no-sites-are-broken/

password theft

I have mentioned odd postings to bugtraq before. Today, one “gsuberland” added to the canon with a gem about the Netgear WGR614 wireless router. He says in his post that he has been “reverse engineering” this router. Now for most bugtraq posters (and readers) this would mean that he has been disassembling the firmware. But …

Continue reading

Permanent link to this article: https://baldric.net/2012/12/14/password-theft/

tor and the UK data communications bill

As a Tor node operator, I have an interest in how the draft UK Data Communications Bill would affect me should it be passed into law. In particular, I would be worried if Tor ended up being treated as a “telecommunications operator” within the terms of the Act (should it become an Act). Fortunately, Steven …

Continue reading

Permanent link to this article: https://baldric.net/2012/12/10/tor-and-the-uk-data-communications-bill/