Skip to content

Dan Q

    • Articles
    • Everything
    • Notes
    • Reposts (shares)
    • Checkins (geo*)
    • Videos
    • Reviews
    • Comics
    • Tags
    • Stats
    • Subscribe
    • Blogroll
  • About
    • Semi-standard "slash pages" you might like to explore:
    • /about
    • /blank
    • /blogroll
    • /colophon
    • /contact
    • /cv
    • /events
    • /license
    • /pfp
    • /postcards
    • /privacy
    • /salary
    • /shh
    • /slashes
    • /stats
    • /subscribe
    • /where
    • Hide posts of type:
    • Choose how Dan's dressed:
    • Hair
    • T-Shirt
  • Contact
  • Podcast

Tag: security

  • I got kicked off LinkedIn this week. Apparently there was "suspicious behaviour" on my account. To get back in, I needed to go through Persona's digital ID check (this, despite the fact that I've got a Persona-powered verification on my LinkedIn, less than six months old).

    After looping around many times identifying which way up a picture of a dog was and repeatedly photographing myself, my passport, and my driving license, I eventually got back in. Personally, I suspect they just rolled out some Online Safety Act functionality and it immediately tripped over my unusual name.

    But let this be a reminder to anybody who (unlike me) depends upon their account in a social network: it can be taken away in a moment and be laborious (or impossible) to get back. If you care about your online presence, you should own your own domain name; simple as that!

    • Note
    • posted 25 July, 2025
  • A small white 10-key keyboard with hand-drawn icons on stickers on the keys. A finger reaches in to press one key, which flashes a purple LED from beneath.

    Lock All The Computers

    I wanted a button on my desk that, when I pressed it, would simultaneously lock every computer connected to my KVM system. Here's what I came up with.

    Read more (374 words)

    • Article
    • 6 comments
    • posted 23 July, 2025
  • Image representing post: Google Shared My Phone Number!

    Google Shared My Phone Number!

    When people started calling my personal mobile number with questions about a voluntary organisation I'm involved with, I was confused: we weren't sharing that number. It turns out that Google had decided to take the number I used to verify my identity for Google Business some years prior and start putting it in Google Search results. WTF, Google?

    Read more - about 3 minutes (688 words)

    • Article
    • with an accompanying podcast
    • 16 comments
    • posted 21 May, 2025
  • Carefully-censored letter from Halifax, highlighting the parts that show my correct address, last four digits of my card, and my credit limit... and where it shows a pair of names that are not mine.

    Halifax Shared My Credit Agreement!

    Today, my partner's husband received a letter, addressed to him, about a change to his credit card agreement. Except the letter wasn't about his credit card... it was about mine! Halifax dun goofed.

    Read more (268 words)

    • Article
    • 3 comments
    • posted 24 April, 2025
  • Generative AI use and human agency

    Joanna Bryson's put together an absolutely fantastic list of considerations about the use of AI, and two of her points do a better job than I did at saying what I was trying to, last week.

    Read more - about 5 minutes (1020 words)

    • Repost
    • of this original
    • 1 comment
    • posted 24 February, 2025
  • Reply to Vika, re: Content-Security-Policy

    Vika shared her frustrations with Content-Security-Policy nonces when delivering pre-generated/cached content. I've had a similar fight, so I've written-up a few of the things I tried and what I learned as a result.

    Read more - about 4 minutes (736 words)

    • Reply
    • 2 comments
    • posted 20 February, 2025
  • UKโ€™s secret Apple iCloud backdoor order is a global emergency, say critics

    The UK seems to be strongarming Apple to weaken the security of its consumer products, which is fucking stupid. Weakened and backdoored encryption in mainstream products doesn't help catch smart criminals. But it does help smart criminals to catch regular folks.

    Read more (395 words)

    • Repost
    • of this original
    • 1 comment
    • posted 10 February, 2025
  • Screenshot showing SSH connection being established to an Endlessh server, which is returning line after line of randomly-generated text as a banner.

    Endless SSH Tarpit on Debian

    Given that I already routinely run my SSH servers on unusual ports, I'm surprised it took me until today before I discovered Endlessh, an SSH tarpit you can install on the conventional port to waste the time of anybody attempting a brute-force attack. Here's how I set it up on a Debian 12 server.

    Read more (466 words)

    • Article
    • posted 6 January, 2025
  • As well as the programming tasks I'm working on for Three Rings this International Volunteer Day, I'm also doing a little devops. We've got a new server architecture rolling out next week, and I'm tasked with ensuring that the logging on them meets our security standards.

    Full image of Terminal screenshot showing a directory listing of a logs directory with several gzipped logfiles with different date-stamped suffixes, and the contents of the logrotate configuration file that produced them.
    Alt

    Terminal screenshot showing a directory listing of a logs directory with several gzipped logfiles with different date-stamped suffixes, and the contents of the logrotate configuration file that produced them.

    Each server's on-device logs are retained in date-stamped files for 14 days, but they're also backed-up offsite daily.

    Those bits all seem to be working, so next I need to work out a way to add a notification to our monitoring platform if any server doesn't successfully push a log to the offsite backup in a timely manner.

    • Note
    • posted 5 December, 2024
  • Overlay attempting to block content to the page beneath, saying "Try 1 year for just ยฃ9.99 and save 81%".

    Good Food, Bad Authorisation

    (BBC) Good Food has started adding "premium" content for which you have to install their app and pay for a subscription. Except the paywall they've put in place is so weak that I fell through it without even meaning to. It's a great - and relatively harmless - example of how front-end-first development is undermining the development of secure Web systems.

    Read more - about 3 minutes (507 words)

    • Article
    • 1 comment
    • posted 19 July, 2024
  • KeePassXC authentication screen on Windows; no password has been entered.

    Brainfart

    Brainfart moment this morning when my password safe prompted me to unlock it with a password, and for a moment I thought to myself "Why am I having to manually type in a password? Don't I have a password safe to do this for me?" ๐Ÿคฆ

    Read more (45 words)

    • Note
    • posted 11 January, 2024
  • Image representing post: Length Extension Attack Demonstration (Video)

    Length Extension Attack Demonstration (Video)

    This is a video version of my blog post, Length Extension Attack. In it, I talk through the theory of length extension attacks and demonstrate an SHA-1 length extension attack against an (imaginary) website.

    The video can also be found on:

    YouTube

    Read more (42 words)

    • Video
    • 1 comment
    • posted 30 November, 2023
  • A browser viewing a photo of a box full of money, overlaid with the caption "This image is valuable!". The URL is full of strangely-encoded characters.

    Length Extension Attack Demonstration

    Hash length extension attacks aren't necessarily intuitive without a little understanding of how vulnerable hashing algorithms work. Using SHA1 as an example, I've put together a step-by-step demonstration with a focus on teaching the underlying principles behind the vulnerability.

    Read more - about 9 minutes (2081 words)

    • Article
    • 6 comments
    • posted 30 November, 2023
  • Dan, smiling, wearing a purple t-shirt with a WordPress logo and a Pride flag, hugs a cut-out of a Wappu (itself hugging a "WP 20" balloon and wearing a party hat).

    WCEU23 - Day 1

    My first "full" day at WordCamp Europe 2023 was busy and intense, but I loved networking and learning about WordPress history and security and what's worth knowing about design and typography.

    Read more - about 13 minutes (2959 words)

    • Article
    • 5 comments
    • posted 9 June, 2023
  • Diagram showing a password safe on a desktop computer being used to fill the username and password parts of a login form, and a mobile phone providing the information for the second factor.

    Keeping 2FA Secrets in a Password Safe?

    I use my password manager to generate TOTP second factor codes. I know this is controversial, with some folks claiming it reduces multifactor authentication down to a single factor and is therefore no better than just a username/password, but I disagree, and I can explain why.

    Read more - about 5 minutes (978 words)

    • Article
    • 2 comments
    • posted 26 January, 2023

Posts navigation

Older posts
Newer posts

Get in Touch

I'd love to hear from you! Why not...

  • email me on blog@danq.me?
    (my spam filter is aggressive, so use a good subject line, i.e. not just "hello"; encrypt your email if you like)
  • say hi on Mastodon, where I'm @dan@danq.me?
  • send a letter or postcard to
    Dan Q, Unit 159610, PO Box 7169, Poole, BH15 9EL, UK
  • reach out some other way?
  • ยฉ Dan Q 1998-2026
  • Creative CommonsAttributionNon-Commercial except where stated (how to use)
  • powered by BloqClassicPressHTML5CSS3
  • privacy
  • Read articles, checkins, notes, reposts, and more...
  • @dan@danq.me
  • contact
  • subscribe
  • Dan Q
  • Creative Commons Attribution Non-Commercial license
  • ClassicPress
  • CSS is awesome
  • Created by a human, not by AI
  • LGBTQ+ pride flag (2018 progress variant)
  • Polyamory flag
  • Say no to Web3
  • Mastodon (it's like email... no, come back!)
  • Tested on Firefox
  • Best viewed on the Internet
  • PHP
  • Ruby
  • Debian
  • Caddy (webserver)
  • Find me on Melonland
  • Check out my GitHub
  • Three Rings - by volunteers, for volunteers, since 2002
  • I'm a fucking webmaster
  • Looks best at: any resolution!