Showing posts with label Security Now. Show all posts
Showing posts with label Security Now. Show all posts

Wednesday, October 2, 2013

Steve Gibson's Secure Login (SQRL) Concept

Documentation https://www.grc.com/sqrl/sqrl.htm

Security Now Episode 424:  Steve Gibson introduces the idea (Video & Audio Podcast, or streaming) http://twit.tv/show/security-now/424

This looks very very interesting, I am looking forward to seeing how this works out.

SQRL is pronounced "Squirrel" ^_^

I lack the expertise to vet this idea, but it sounds very good to me, would solve a lot of problems for average users, while providing very strong security that would be difficult to compromise.

Looking forward to the development of SQRL, and hats off to Steve for making it public domain!!

From Practical Considerations section of first page of documentation:
"Did I invent anything? I don't care. Even if some aspects of this system are novel, and might be subject to intellectual property protection, this is too important and much bigger than me. It should be made free for the world to use without encumbrance. With this publication of every detail, I hereby release and disclaim any and all proprietary rights to any new ideas developed and presented herein. This work is thereby added to the public domain."

Thursday, January 31, 2013

PSA Security & Hacking: UPnP (Universal Plug and Play ) Vulnerability



Security Now 389 "Unplug UPnP" links for audio downloads & etc http://twit.tv/show/security-now/389

[Edited to Add:  Steve Gibson has UPnP exposure test in Shields up now!  Thanks Steve!! https://twitter.com/SGgrc/status/297165652257554432]

CERT Note http://www.kb.cert.org/vuls/id/922681

US CERT "Multiple vulnerabilities have been announced in libupnp, the open source portable SDK for UPnP devices. Libupnp is employed by hundreds of vendors for UPnP-enabled devices. Information is also available in CERT Vulnerability Note VU#922681.

US-CERT recommends that affected UPnP device vendors and developers obtain and employ libupnp version 1.6.18, which addresses these vulnerabilities.

US-CERT recommends that users and administrators review CERT Vulnerability Note VU#922681, disable UPnP (if possible), and restrict access to SSDP (1900/udp) and Simple Object Access Protocol (SOAP) services from untrusted networks such as the Internet." ~http://www.us-cert.gov/current/

Steve Gibson provides details on this issue, he also notes in the VOD above that he is going to add the capability to test for this Vulnerability to his ShieldsUP service/software.

ShieldsUP http://www.grc.com/x/ne.dll?rh1dkyd2

Problem with this, is even if you disable UPnP on your Router, it may still be enabled on the WAN (Internet) side.

Till Gibson gets this functionality added to ShieldsUP, not sure how most people could scan for it to be sure it was disabled on their routers.

Hard Core Nerds with correct tools could Pen Test individual Routers, but not aware of any practical way to test for people that don't have the skillset and tools for Pen Testing.

AFAIK the Rapid7 tool isn't stable/reliable, least it wasn't yeasterday for many people, it may have been patched since then, but not comfortable recommending it at this time.

I wouldn't trust vulnerability list from any Manufacturer on this, because it is a very bad case of stupid to have in the first place.

I haven't had enough time to find out if Tomato http://en.wikibooks.org/wiki/Tomato_Firmware#Supported_devices or DD WRT http://www.dd-wrt.com/site/index provide a guaranteed fix for this yet.



Wednesday, July 25, 2012

Security Now Streaming

http://www.justin.tv/twit#/w/3488649232/6

"discuss important issues of personal computer security. Sometimes we'll discuss something that just happened. Sometimes we'll talk about long-standing problems, concerns, or solutions. Either way, every week we endeavor to produce something interesting and important for every personal computer user"
~http://www.grc.com/securitynow.htm

Monday, July 23, 2012

PSA: Gamigo 11 Million Passwords Hacked

See Ars article, also Forbes, the Forbes article links http://pwnedlist.com/ for checking if your email has been leaked.

I haven't heard about http://pwnedlist.com/ before, but shows as green with McAfee.

For more on Password Cracking, or Hacking, and what you should do see "Lessons Learned from Cracking 2 Million LinkedIn Passwords" and/or Steve Gibson's Haystacks & Needles (Understanding Passwords).

But if you have a Gamigo account, you should change your password, the Steve Gibson link above provides good advice on passwords.

Wednesday, June 20, 2012

Security Now streaming

http://live.twit.tv/

Been listening to podcasts of Security now for a while, but happened to be free to catch stream live today.

They have multiple stream feed levels available as well as audio only if your trying to keep data usage down on a mobile device.

Well worth listening to for Computer Nerds and/or people wanting to learn more about computer security.

Steve Gibson is very good at explaining complex computer stuff so non Computer Nerds like me can understand it, without dumbing the content down.

Sunday, June 17, 2012

Interesting Software

http://portableapps.com/

Heard this mentioned on recent Security Now podcast, a listener emailed them that he runs "portable Firefox from PortableApps.com in my Dropbox" so all his Tabs are synced, said he has being doing that for years.

Just thought that was such a neat idea, that I had to blog it, figured people might build on it and think of some more creative solutions to problems.

Tuesday, May 29, 2012

Computer Security: "The Rules Of Computing"

An excellent article, titled "The Rules of Computing" from a Computer Security blog I follow, it is Mac focused, but the information, aside from Mac specific software, applies to all computers, including Smart Phones!

A lot of people don't realize that smart phones are computers, with additional vulnerabilities added, and that it takes a certainly baseline skillset to operate them without undue security risks.

Especially with the Android platform, since it is less tied down, and far more open, much like computers. 

I wonder if there may be a real job opportunity for Nerds to get into Android Security?

Stay Safe,

Cliff

Monday, May 21, 2012

Computer, Electronic, HAM Geeks gather round, great story of a 16 yr old building his own Sonic Gun

This story is simply to good not to share with everyone, and there is a small Blizzard tie in at the end of the story.

Steve Gibson is a complete Nerd, I would say he is a super Nerd, this story describes a month or so in his life at age 16, when he build a real Sonic Stunner, and what happened when he used it.

This is also a story that might help older nerds get their kids into building hardware or doing coding, instead of just using technology.

Enjoy:

 Security Now #281

Podcast link: http://www.podtrac.com/pts/redirect.mp3/aolradio.podcast.aol.com/sn/sn0281.mp3
Mobile/low def Video:  http://dts.podtrac.com/redirect.mp4/twit.cachefly.net/video/sn/sn0281/sn0281_h264b_640x368_256.mp4






Tuesday, April 24, 2012

Security Now Podcast

I really like the Security Now Podcast with Steve Gibson, alternate podcast link on TwitTV, Steve is a total Nerd Baller, he has had Nerd jobs since he was 13 years old!

For more on Steve Gibson see Wiki on him or his webpage http://www.grc.com/intro.htm

He also provides some useful computer software, including freeware.

Computer Nerds may want to look at SpinRite (Note: SpinRite is NOT free) his HDD recovery tool, it works on pretty much any HDD, even things like Tivo and console games. 

I find this podcast useful for Computer news and tidbits, and sometimes neat Hacker tidbits.

Not saying it is for everyone, I am not a true hard core computer geek myself, but I usually understand enough from this show to know if I want to google or look up links mentioned to learn more.

I also like the fact that they provide several resources for each podcasts, including transript, below is a list from Gibson's website:

Each episode has SIX resources:


High quality 64 kbps mp3 audio file
Quarter size, bandwidth-conserving,
16 kbps (lower quality) mp3 audio file
A web page with any supplementary notes
A web page text transcript of the episode
A simple text transcript of the episode
Ready-to-print PDF (Acrobat) transcript  
If you have any other tech or computer security podcasts that you recommend, please suggest them in the comments section below. No need to log in to post. GL HF, Cliff