Archive for the 'Security' Category
Is code-signing the solution against malware?
0 Comments Published by Felipe Alfaro Solana November 10th, 2009 in SecurityI was reading the comments for Schneier’s is antivirus dead? article. As usual, Bruce Schneier is sharp and gets the whole picture.
One of the comments from that article said to stop using Windows. Not using Windows is, unfortunately, the wrong solution. Other platforms like Mac OS X have serious security bugs. Linux had have also [...]
Distributed virus analysis
0 Comments Published by Felipe Alfaro Solana March 19th, 2009 in SecurityWhile reading a post on how current anti-virus solutions are starting to become complete inefficient and even reporting false positives, a few thoughts came to my mind.
The first one is that I’ve been running with no anti-virus on my computers for more than 8 years now. The use of low-risk platforms, like UNIX-based systems, and [...]
Safari/MacBook security
0 Comments Published by Felipe Alfaro Solana March 19th, 2009 in Mac OS X, SecurityIt is probably not very well-known for many, and probably ignored by most, but it seems that Mac OS X and specifically Safari leaves much to be desired when talking about security.
During the Pwn2Own contest, Safari was the first browser to fall, in the order of seconds, when put under attack by Charlie Miller. This [...]
Seguridad y punto de conexión a la red.
2 Comments Published by Felipe Alfaro Solana February 9th, 2008 in Personal, SecurityLeyendo un artículo de Kriptópolis, me encuentro con una referencia a Peter Tippett en la que éste hace un símil entre la seguridad en la industria automovilística y la industria de la seguridad informática. Aunque puedo coincidir con este señor, creo que no es una comparación del todo justa. En primer lugar, un coche es [...]
Kerberizing Leopard’s Remote Login (built-in SSH) service
1 Comment Published by Felipe Alfaro Solana December 7th, 2007 in Kerberos, Mac OS X, Security0. Introduction
Enabling Kerberos/GSSAPI support in Leopard’s Remote Login (SSH) service is straightforward. As Leopard’s Remote Login is built using OpenSSH, most of what is described here applies perfectly to other flavors of UNIX.
Kerberos/GSSAPI authentication allows for Single Sign-On capabilities in OpenSSH in such a way that it makes very convenient to work with or manage [...]
Sistema simple de voto electrónico
2 Comments Published by Felipe Alfaro Solana November 11th, 2007 in Personal, SecurityIntroducción
En los sistemas convencionales, el votante se dirige a un colegio electoral, introduce su voto, en forma de papeleta, en un sobre, se identifica ante un agente e introduce su voto en una urna. Los sistemas tradicionales separan el proceso de autentificación del votante del proceso recuento de votos, de forma que éstos se realizan [...]
Mac OS X 10.5 Leopard built-in firewall
9 Comments Published by Felipe Alfaro Solana November 10th, 2007 in Firewall, Mac OS X, SecurityThe firewall in Mac OS X 10.5 Leopard is confusing, to say the least. It is not enabled by default, which is a huge mistake, in my humble opinion. Also, the graphical user interface offers less flexibility than in previous version while trying to configure it. Besides allowing you to independently control the blocking of [...]
SOAP, user credentials and plain-text
1 Comment Published by Felipe Alfaro Solana August 21st, 2007 in SecurityOnce again, it’s good to know that some Web sites are treating sensitive information, like user credentials, the way they deserve: in plain-text.
I saw the following error message from the VMware site while trying to log in:
Fatal error: Uncaught exception ‘Exception’ with message ‘SimpleXMLElement::__construct() expects parameter 1 to be string, object given’ in /www/html/beta_programs/methods.class.php:154 Stack [...]
OpenSSH public-keys, ssh-agent and Keychain
0 Comments Published by Felipe Alfaro Solana February 3rd, 2007 in OpenSSH, SecurityI have always though that ssh-agent has some limitations. One of those limitations is that when invoked from .bashrc or .zshrc in the following way:
`eval ssh-agent`
will cause one ssh-agent instance to be spawned for every shell, which is a waste of resources. An easy solution is to use Keychain, which is also described here.
Basically, Keychain [...]
Recently, I read a nice post (Spanish only) published by Sergio Hernando on anti-virus software. After reading it, I decided to go on and write my own personal opinions on security and anti-virus software. In this particular case, although unusual, I disagree — most of the time, I can’t agree more with Sergio — with [...]
AboutYou are currently browsing the Felipe Alfaro Solana weblog archives for the 'Security' category. Longer entries are truncated. Click the headline of an entry to read it in its entirety. |
||||