Tag: security
-
I got kicked off LinkedIn this week. Apparently there was "suspicious behaviour" on my account. To get back in, I needed to go through Persona's digital ID check (this, despite the fact that I've got a Persona-powered verification on my LinkedIn, less than six months old).
After looping around many times identifying which way up a picture of a dog was and repeatedly photographing myself, my passport, and my driving license, I eventually got back in. Personally, I suspect they just rolled out some Online Safety Act functionality and it immediately tripped over my unusual name.
But let this be a reminder to anybody who (unlike me) depends upon their account in a social network: it can be taken away in a moment and be laborious (or impossible) to get back. If you care about your online presence, you should own your own domain name; simple as that!
-
Lock All The Computers
I wanted a button on my desk that, when I pressed it, would simultaneously lock every computer connected to my KVM system. Here's what I came up with.
-
Google Shared My Phone Number!
When people started calling my personal mobile number with questions about a voluntary organisation I'm involved with, I was confused: we weren't sharing that number. It turns out that Google had decided to take the number I used to verify my identity for Google Business some years prior and start putting it in Google Search results. WTF, Google?
-
Halifax Shared My Credit Agreement!
Today, my partner's husband received a letter, addressed to him, about a change to his credit card agreement. Except the letter wasn't about his credit card... it was about mine! Halifax dun goofed.
-
Generative AI use and human agency
Joanna Bryson's put together an absolutely fantastic list of considerations about the use of AI, and two of her points do a better job than I did at saying what I was trying to, last week.
-
Reply to Vika, re: Content-Security-Policy
Vika shared her frustrations with Content-Security-Policy nonces when delivering pre-generated/cached content. I've had a similar fight, so I've written-up a few of the things I tried and what I learned as a result.
-
UKโs secret Apple iCloud backdoor order is a global emergency, say critics
The UK seems to be strongarming Apple to weaken the security of its consumer products, which is fucking stupid. Weakened and backdoored encryption in mainstream products doesn't help catch smart criminals. But it does help smart criminals to catch regular folks.
-
Endless SSH Tarpit on Debian
Given that I already routinely run my SSH servers on unusual ports, I'm surprised it took me until today before I discovered Endlessh, an SSH tarpit you can install on the conventional port to waste the time of anybody attempting a brute-force attack. Here's how I set it up on a Debian 12 server.
-
As well as the programming tasks I'm working on for Three Rings this International Volunteer Day, I'm also doing a little devops. We've got a new server architecture rolling out next week, and I'm tasked with ensuring that the logging on them meets our security standards.
Alt
Terminal screenshot showing a directory listing of a logs directory with several gzipped logfiles with different date-stamped suffixes, and the contents of the logrotate configuration file that produced them.
Each server's on-device logs are retained in date-stamped files for 14 days, but they're also backed-up offsite daily.
Those bits all seem to be working, so next I need to work out a way to add a notification to our monitoring platform if any server doesn't successfully push a log to the offsite backup in a timely manner.
-
Good Food, Bad Authorisation
(BBC) Good Food has started adding "premium" content for which you have to install their app and pay for a subscription. Except the paywall they've put in place is so weak that I fell through it without even meaning to. It's a great - and relatively harmless - example of how front-end-first development is undermining the development of secure Web systems.
-
Brainfart
Brainfart moment this morning when my password safe prompted me to unlock it with a password, and for a moment I thought to myself "Why am I having to manually type in a password? Don't I have a password safe to do this for me?" ๐คฆ
-
Length Extension Attack Demonstration (Video)
This is a video version of my blog post, Length Extension Attack. In it, I talk through the theory of length extension attacks and demonstrate an SHA-1 length extension attack against an (imaginary) website.
The video can also be found on:
YouTube
-
Length Extension Attack Demonstration
Hash length extension attacks aren't necessarily intuitive without a little understanding of how vulnerable hashing algorithms work. Using SHA1 as an example, I've put together a step-by-step demonstration with a focus on teaching the underlying principles behind the vulnerability.
-
WCEU23 - Day 1
My first "full" day at WordCamp Europe 2023 was busy and intense, but I loved networking and learning about WordPress history and security and what's worth knowing about design and typography.
-
Keeping 2FA Secrets in a Password Safe?
I use my password manager to generate TOTP second factor codes. I know this is controversial, with some folks claiming it reduces multifactor authentication down to a single factor and is therefore no better than just a username/password, but I disagree, and I can explain why.








