Showing posts with label Steve Gibson. Show all posts
Showing posts with label Steve Gibson. Show all posts

Wednesday, October 2, 2013

Steve Gibson's Secure Login (SQRL) Concept

Documentation https://www.grc.com/sqrl/sqrl.htm

Security Now Episode 424:  Steve Gibson introduces the idea (Video & Audio Podcast, or streaming) http://twit.tv/show/security-now/424

This looks very very interesting, I am looking forward to seeing how this works out.

SQRL is pronounced "Squirrel" ^_^

I lack the expertise to vet this idea, but it sounds very good to me, would solve a lot of problems for average users, while providing very strong security that would be difficult to compromise.

Looking forward to the development of SQRL, and hats off to Steve for making it public domain!!

From Practical Considerations section of first page of documentation:
"Did I invent anything? I don't care. Even if some aspects of this system are novel, and might be subject to intellectual property protection, this is too important and much bigger than me. It should be made free for the world to use without encumbrance. With this publication of every detail, I hereby release and disclaim any and all proprietary rights to any new ideas developed and presented herein. This work is thereby added to the public domain."

Thursday, August 8, 2013

VPN Guide by Steve Gibson

https://www.grc.com/vpn/overview.htm is link to Steve Gibson's guide to VPN, if your learning how to set up your own VPN like me, or if your just curious about VPN and want to learn, it is a great resource.

It also ties in with setting up your own server, I am looking at this neat ARM based machine, called Utilite, for low power server http://utilite-computer.com/web/home

Blurb about it on Ars http://arstechnica.com/information-technology/2013/07/99-arm-based-pc-runs-either-ubuntu-or-android/

Monday, February 4, 2013

Security & Hacking: UPnP update

First, Steve Gibson's ShieldsUP now has UPnP scan in it!  Big thanks to Steve for getting this out so fast!!

Steve Tweeted https://twitter.com/SGgrc/status/297165652257554432:
GRC'S new UPnP Exposure Test is NOW ONLINE. Goto Choose "ShieldsUP!"... and you can't miss it.

http://grc.com is direct link, above is twitter shortened link to same url, ShieldsUP is large image with link on that page.

Easy & simple to do, not complicated to use, if you can click a mouse you can use it.

According to this Tweet from Steve, OpenWRT is vulnerable as well, https://twitter.com/SGgrc/status/297173997743902720:
UPnP: I'm checking returned data, but NO IP addresses. I've seen that a Roku is exposed, and so is OpenWRT (and lots of other stuff!)

Friday, October 26, 2012

Security & Hacking: How to Crack WPA & WPA2

Good, though somewhat technical, article on cracking WiFi http://www.smallnetbuilder.com/wireless/wireless-howto/31914-how-to-crack-wpa-wpa2-2012

Though not mentioned in that article, related to strong passwords, I really think everyone should be using a good password keeper.

So the only password you need to remember is the one needed to unlock your password keeper, I would use Steve Gibson's advice for that password, blogged about here http://cliffsesportcorner.blogspot.com/2012/05/steve-gibsons-haystacks-needles.html

Then use random passwords, generated by the password keeper, for everything else.

There are many good password keepers out there, I like and recommend mSecure https://msevensoftware.com/

For free I believe Strip Lite is good, their website http://getstrip.com/ or iTunes.

Another free one I might suggest is KeePass, I have heard good things about it, and have a friend that uses it.


See Also:

Thursday, August 9, 2012

PSA: Blizzard NA Bnet change your passwords

http://us.blizzard.com/en-us/securityupdate.html

See link for full details, short version, Blizzard has found determined some information was hacked, and are suggesting NA accounts to change passwords.

Secret Questions may have been compromised as well.


For more on good passwords see Steve Gibson's Haystacks & Needles (Understanding Passwords)

I would also strongly suggest Two Factor Authentication.

Wednesday, July 25, 2012

Security Now Streaming

http://www.justin.tv/twit#/w/3488649232/6

"discuss important issues of personal computer security. Sometimes we'll discuss something that just happened. Sometimes we'll talk about long-standing problems, concerns, or solutions. Either way, every week we endeavor to produce something interesting and important for every personal computer user"
~http://www.grc.com/securitynow.htm

Monday, July 23, 2012

PSA: Gamigo 11 Million Passwords Hacked

See Ars article, also Forbes, the Forbes article links http://pwnedlist.com/ for checking if your email has been leaked.

I haven't heard about http://pwnedlist.com/ before, but shows as green with McAfee.

For more on Password Cracking, or Hacking, and what you should do see "Lessons Learned from Cracking 2 Million LinkedIn Passwords" and/or Steve Gibson's Haystacks & Needles (Understanding Passwords).

But if you have a Gamigo account, you should change your password, the Steve Gibson link above provides good advice on passwords.

Friday, July 13, 2012

PSA: NVIDIA Devloper Zone Hacked

http://nakedsecurity.sophos.com/2012/07/13/nvidia-android-forums-hackers/

I saw this first on Sophos blog linked above.

Cut and paste from NVIDIA's warning post below, see their link for complete message, http://www.nvidia.com/content/devzone/index.html,
NVIDIA suspended operations today of the NVIDIA Developer Zone (developer.nvidia.com). We did this in response to attacks on the site by unauthorized third parties who may have gained access to hashed passwords.
We are investigating this matter and working around the clock to ensure that secure operations can be restored.
As a precautionary measure, we strongly recommend that you change any identical passwords that you may be using elsewhere.
NVIDIA does not request sensitive information by email. Do not provide personal, financial or sensitive information (including new passwords) in response to any email purporting to be sent by an NVIDIA employee or representative.

For more on Passwords see More D3 Account Security or Computer & Password Security: Salting & Hashing explained clearly or Steve Gibson's Haystacks & Needles (Understanding Passwords).

Wednesday, June 20, 2012

Security Now streaming

http://live.twit.tv/

Been listening to podcasts of Security now for a while, but happened to be free to catch stream live today.

They have multiple stream feed levels available as well as audio only if your trying to keep data usage down on a mobile device.

Well worth listening to for Computer Nerds and/or people wanting to learn more about computer security.

Steve Gibson is very good at explaining complex computer stuff so non Computer Nerds like me can understand it, without dumbing the content down.

Tuesday, May 29, 2012

Steve Gibson's Haystacks & Needles (Understanding Passwords)

I am a big fan of Steve Gibson, if your a computer Nerd you probably know who he is, if not let's just say he knows Computers & Computer Security better than anyone your likely to meet.

He is also an excellent communicator, he is one of the best people I know, for taking a complex & arcane topic and explaining it so anyone can understand it.

I strongly recommend reading his article on Passwords at https://www.grc.com/haystack.htm

There are many important components to good passwords, and I suggest reading his article, but if your not going to, I would say the 2 key points to a strong enough password for most of us are the following.

First, Password Length, size matters!

[Thinking of it that way will ensure you remember that important fact.]

Longer is better!!

Second, use a specific minimum complexity, in Steve Gibson's own words [types of characters:  Lower case letters, upper case letters, numbers, and symbols ie "@<>$&*"]:
"The use of every type of character forces the attacker to search through the largest possible space. We must always assume that an attacker is as smart as possible (and most are). So, knowing that 41.69% of all passwords consist of only lowercase alphabetic characters, a smart attacker who is forced to resort to a brute force search won't initially bother spending time guessing passwords that contain uppercase, digits and symbols. Only after an all lowercase search out to some length has failed will an attacker decide that the unknown target password must contain additional types of characters.

So, in essence, by deliberately using at least one of each type of character, we are forcing the attacker to search the largest possible password space, because our password won't ever be found in any of the smaller spaces
."

Links & Info
Steve Gibson's Password Podcast:
Wikipedia on Steve Gibson http://en.wikipedia.org/wiki/Steve_Gibson_%28computer_programmer%29

Steve's Little Corner http://www.grc.com/stevegibson.htm
Steve's Twitter http://twitter.com/SGgrc
Steve's Blog https://www.grc.com/news.htm

Monday, May 21, 2012

Computer, Electronic, HAM Geeks gather round, great story of a 16 yr old building his own Sonic Gun

This story is simply to good not to share with everyone, and there is a small Blizzard tie in at the end of the story.

Steve Gibson is a complete Nerd, I would say he is a super Nerd, this story describes a month or so in his life at age 16, when he build a real Sonic Stunner, and what happened when he used it.

This is also a story that might help older nerds get their kids into building hardware or doing coding, instead of just using technology.

Enjoy:

 Security Now #281

Podcast link: http://www.podtrac.com/pts/redirect.mp3/aolradio.podcast.aol.com/sn/sn0281.mp3
Mobile/low def Video:  http://dts.podtrac.com/redirect.mp4/twit.cachefly.net/video/sn/sn0281/sn0281_h264b_640x368_256.mp4






Tuesday, April 24, 2012

Security Now Podcast

I really like the Security Now Podcast with Steve Gibson, alternate podcast link on TwitTV, Steve is a total Nerd Baller, he has had Nerd jobs since he was 13 years old!

For more on Steve Gibson see Wiki on him or his webpage http://www.grc.com/intro.htm

He also provides some useful computer software, including freeware.

Computer Nerds may want to look at SpinRite (Note: SpinRite is NOT free) his HDD recovery tool, it works on pretty much any HDD, even things like Tivo and console games. 

I find this podcast useful for Computer news and tidbits, and sometimes neat Hacker tidbits.

Not saying it is for everyone, I am not a true hard core computer geek myself, but I usually understand enough from this show to know if I want to google or look up links mentioned to learn more.

I also like the fact that they provide several resources for each podcasts, including transript, below is a list from Gibson's website:

Each episode has SIX resources:


High quality 64 kbps mp3 audio file
Quarter size, bandwidth-conserving,
16 kbps (lower quality) mp3 audio file
A web page with any supplementary notes
A web page text transcript of the episode
A simple text transcript of the episode
Ready-to-print PDF (Acrobat) transcript  
If you have any other tech or computer security podcasts that you recommend, please suggest them in the comments section below. No need to log in to post. GL HF, Cliff