Skip to content

Dan Q

    • Articles
    • Everything
    • Notes
    • Reposts (shares)
    • Checkins (geo*)
    • Videos
    • Reviews
    • Comics
    • Tags
    • Stats
    • Subscribe
    • Blogroll
  • About
    • Semi-standard "slash pages" you might like to explore:
    • /about
    • /blank
    • /blogroll
    • /colophon
    • /contact
    • /cv
    • /events
    • /license
    • /pfp
    • /postcards
    • /privacy
    • /salary
    • /shh
    • /slashes
    • /stats
    • /subscribe
    • /where
    • Hide posts of type:
    • Choose how Dan's dressed:
    • Hair
    • T-Shirt
  • Contact
  • Podcast

Tag: security

  • A hacker 'steals his own slides back'

    Breaking https' AES-GCM (or a part of it)

    The coolest talk of this year's Blackhat must have been the one of Sean Devlin and Hanno Böck. The talk summarized this early year's paper, in a very cool way: Sean walked on stage and announced that he didn't have his slides. He then said that it didn't matter because he had a good idea …

    Read more (64 words)

    • Repost
    • posted 16 August, 2016
  • Image representing post: Anatomy of Cookie XSS

    Anatomy of Cookie XSS

    Using a real-life vulnerability he discovered on the University of Oxford's IT Services website as an example, Dan reminds you of the importance of sanitising even cookie data to prevent XSS vulnerabilities.

    Read more - about 3 minutes (580 words)

    • Article
    • 6 comments
    • posted 16 June, 2016
  • Payment Redirection Fraud

    Here is an example scenario… You receive an email requesting a payment. It could be for rent, it could be fees for a course or any other legitimate reason. Typically, the payment is a significant sum. The email contains the banking details you need to make the payment. Then shortly after the 1st email arrives…

    …

    Read more (58 words)

    • Repost
    • posted 9 June, 2016
  • "Iceland", one of my Raspberry Pi VPN hotspots

    Raspberry Pi VPN Hotspot (or How To Infuriate Theresa May For Under £40)

    For a small sum of money and a little time, you too can have a little box that encrypts everything on your WiFi network until it leaves the UK.

    Read more - about 7 minutes (1437 words)

    • Article
    • 4 comments
    • posted 25 November, 2015
  • Greg, Marc, Blair and Dom, as depicted in Greg's 2007 blog post.

    Squiz CMS Easter Eggs (or: why do I keep seeing Greg's name in my CAPTCHA?)

    When using the Squiz CMS, Dan noticed that his CAPTCHA kept containing the same patterns of letters. These turned out to be the names of early developers on the system, which in turn lead Dan to uncover Easter Eggs in the software that have been deliberately concealed by their authors.

    Read more - about 5 minutes (1030 words)

    • Article
    • 6 comments
    • posted 27 March, 2015
  • Social Engineering of the Day

    Dan goes to deliver a lecture on security and, before he's even identified himself, manages to find out from the receptionist the best way to circumvent their door locks.

    Read more (207 words)

    • Article
    • 1 comment
    • posted 15 May, 2014
  • Something like HTTPS Everywhere for new Opera?




    I'm looking for an extension that will automatically redirect-to-HTTPS for particular domains, e.g. to ensure that I'm using the secure version of Wikipedia, etc., whenever I go there. The HTTPS Everywhere plugin from the EFF does this for Firefox and Chrome; what can I do to make this work in Opera?


    Read more (52 words)

    • Repost
    • posted 9 October, 2013
  • Pattern lock configuration on an Android mobile phone.

    Phone Security == Computer Security

    Dan gets paranoid and despairs about the ease with which mobile devices can be stolen, the wealth of personal information stored on them, and the under-use of readily-available encryption tools.

    Read more - about 4 minutes (755 words)

    • Article
    • 2 comments
    • posted 20 December, 2012
  • You are a target. Your password is weak. Attacks are on the rise. You can protect yourself.

    Rave Reviews for Your Password Sucks

    After running a breakout session entitled "Your password: how bad guys will steal your identity" at the 2012 UAS Conference, Dan gets rave reviews. Nice.

    Read more - about 3 minutes (643 words)

    • Article
    • 1 comment
    • posted 26 October, 2012
  • Image representing post: KeePass for Opera

    KeePass for Opera

    Dan develops a browser plugin for Opera to allow the KeePass Password Safe to work with Opera 12+, after the Opera team remove the feature upon which many KeePass users depended.

    Read more (260 words)

    • Article
    • posted 17 June, 2012
  • My mobile banking app, showing me a special six digit code.

    Cardless Cashpoints

    RBS Group banks now offer the ability to withdraw cash from ATMs without using a bank card, by making the withdrawal request from their mobile app. Dan gives it a go, and shares his thoughts on the process.

    Read more - about 4 minutes (949 words)

    • Article
    • 2 comments
    • posted 14 June, 2012
  • CCTV camera.

    Internetland

    In Internetland, everybody has prosopagnosia. That's why it's so important that the people who live there treat their passwords with care. Dan tells a story about Alice, Bob, Eve, and an antiques store.

    Read more - about 9 minutes (2078 words)

    • Article
    • 2 comments
    • posted 13 June, 2012
  • Image representing post: Instead Of Blogging...

    Instead Of Blogging...

    In a declaration of 'blog bankruptcy', Dan lists all of the topics that he'd hoped to have blogged about during the last (very busy!) month, and gets on with writing about other things. He's been busy!

    Read more - about 3 minutes (542 words)

    • Article
    • 3 comments
    • posted 1 August, 2011
  • Image representing post: Deliciously Silly Password Restrictions

    Deliciously Silly Password Restrictions

    After being reminded that social bookmarking service del.icio.us exists, Dan logs in and gives it a go. His first experience with its new version... isn't terribly promising.

    Read more (322 words)

    • Article
    • 8 comments
    • posted 28 April, 2011
  • Bank Security

    Dan tries to tell a bank that their website is insecure. You'd think it'd be easier than this.

    Read more (307 words)

    • Article
    • 3 comments
    • posted 26 April, 2011

Posts navigation

Older posts
Newer posts

Get in Touch

I'd love to hear from you! Why not...

  • email me on blog@danq.me?
    (my spam filter is aggressive, so use a good subject line, i.e. not just "hello"; encrypt your email if you like)
  • say hi on Mastodon, where I'm @dan@danq.me?
  • send a letter or postcard to
    Dan Q, Unit 159610, PO Box 7169, Poole, BH15 9EL, UK
  • reach out some other way?
  • © Dan Q 1998-2026
  • Creative CommonsAttributionNon-Commercial except where stated (how to use)
  • powered by BloqClassicPressHTML5CSS3
  • privacy
  • Read articles, checkins, notes, reposts, and more...
  • @dan@danq.me
  • contact
  • subscribe
  • Dan Q
  • Creative Commons Attribution Non-Commercial license
  • ClassicPress
  • CSS is awesome
  • Created by a human, not by AI
  • LGBTQ+ pride flag (2018 progress variant)
  • Polyamory flag
  • Say no to Web3
  • Mastodon (it's like email... no, come back!)
  • Tested on Firefox
  • Best viewed on the Internet
  • PHP
  • Ruby
  • Debian
  • Caddy (webserver)
  • Find me on Melonland
  • Check out my GitHub
  • Three Rings - by volunteers, for volunteers, since 2002
  • I'm a fucking webmaster
  • Looks best at: any resolution!