blech + security   24

Hacking Scarlett Johansson using Google and gumption | Ars Technica
"Reaching from a Florida computer into the most private documents of Hollywood celebrities took no organized blackmail ring, no special tools, and no special software. It required merely a search engine, an Internet connection, and the willingness to be deeply creepy."
arstechnica  hacking  socialengineering  google  email  security  from instapaper
7 weeks ago by blech
Use historical imagery to see nuclear site | Google Earth Blog
"So what's the purpose of blurring the imagery if it's that easy to obtain clear shots?" On Google Earth, imagery and historic data.
google/earth  satellite  surveillance  nuclear  security  securitytheathre?  via:straup  from delicious
september 2011 by blech
How to hack Amazon with a book | Dr. Wetter
"Whereas the standard example for a stored XSS vulnerability over an out-of-band channel is a web mailer like OWA using SMTP here this channel for the attack is kind of — err, let's put it this way — unusual: One has to write a book!"
security  amazon  xss  books  development  web  from delicious
december 2010 by blech
People happy to use airport full-body scanners | BBC News
"Nine out of 10 British people are happy to use full-body scanners being rolled out at UK airports." "The poll of 10,000 people, including 977 Britons... found acceptance of the scanners was highest in the UK." "One in three surveyed in Germany and Belgium objected, and only 45% in Hong Kong and 24% in Mexico were in favour."
news  bbc  politics  security  securitytheathre?  privacy  scanner  from delicious
april 2010 by blech
Security Update might break Perl | bulknews.typepad.com
The Security Update released by Apple yesterday, 2009-001, clobbers part of the core IO module. If you've ever upgraded it, you'll need to fetch it manually and reinstall.
perl  macosx  security  cpan  via:obra 
february 2009 by blech
Bringing OpenID and OAuth Together | Google Data APIs
'Google now supports the "Hybrid Protocol", combining OpenID federated login together with OAuth access authorization.' Looks like this might end up with a usable, open competitor to Facebook Connect.
google  oauth  openid  authentication  identity  authorisation  data  api  security 
january 2009 by blech
Flickr API security weakness | Yes/No/Cancel
Martin Kleppmann on what, to me, smells more like a theoretical than a practical weakness in the Flickr API. There's at least one mistake - if an app is authenticated, it doesn't need to be approved again - and more generally, even if you do have an app's key and secret, you can still only get the level of auth the app originally asked for. The fixes all seems horribly overcomplex (for example, my EXIF machine tagger has just four users, total, because keys/secrets are such a barrier to entry). Anyway, can't say I'm that worried personally.
flickr  security  oauth  authentication  api  via:billyabbott 
january 2009 by blech
Homeland "Security" | Nick Taylor
"So I have to give up significant amounts of personal data, and have no ‘expectation of privacy’. Makes me think twice about whether going to the US is even worth it."
us  travel  visa  security  via:thegareth 
january 2009 by blech
Rate limiting with memcached | Simon Willison
How to stop someone doing a dictionary attack on your Django/Python website, by using memcache.
python  django  security  memcached  simonwillison 
january 2009 by blech
US Army warns of Twitter dangers | Yahoo News
'"Twitter has also become a social activism tool for socialists, human rights groups, communists, vegetarians, anarchists, religious communities, atheists, political enthusiasts, hacktivists and others to communicate with each other and to send messages to broader audiences," the report said.'
twitter  security  report  paranoia  terrorism  nonsense  ap  via:deusx  via:tomc 
october 2008 by blech
Lift the download quarantine | The Pug Automatic
A nice little AppleScript folder action which calls xattr to remove that annoying "You've downloaded this, is it safe?" dialog. Trades security for convenience, of course, but if you want it, here it is. (I do.)
macosx  security  securitytheathre?  download  applescript  script  hack  xattr  metadata  via:straup 
august 2008 by blech
Changing the download safety settings | My Macinations
I should have a good look at this and see if the safe files are related at all to the xattr settings discussed earlier.
apple  macosx  security  safari  via:ssp 
march 2008 by blech
“Disabling” Launch Services File Quarantine | The Apple Blog
That annoying "this is downloaded from the Internet" dialog? Here's how to get rid of it.
apple  macosx  security  software  finder  metadata  applescript  via:daringfireball 
march 2008 by blech
Downloaded From the Internet? | pudge hates software
Chris Nandor on the hates-software blogmailinglisthing about the rather stupid notifications you get that an application is from the Internet.
apple  macosx  software  security 
march 2008 by blech
Counter-terrorism advertising campaign | Met Police
I couldn't believe it when I saw the "Photos" ad on the back page of one of the evening freesheets on Tuesday. "Terrorists ... take photos of CCTV cameras" So do ordinary (well, only slightly abnormal) people...
uk  police  advertising  advert  security  terrorism  photography  stupid 
march 2008 by blech
Leopard finally supporting ssh-agent at login
When I finally upgrade, I should be able to junk SSHKeychain. Which is good, because it often takes a gig of VM for no apparent reason.
macosx  ssh  unix  security 
october 2007 by blech
Cordon blue | Guardian Unlimited
"In the past few weeks an 11-mile blue fence has sprung up around the 2012 Olympics site in east London. Is it a necessary security measure - or a reminder of how divisive the games are? Andy Beckett walks along it." Looks like a good read. Or cycle.
london  olympics  development  sport  security  2012  guardian  via:rodcorp 
september 2007 by blech
Security Watch: Gone in 60 seconds--the high-tech version - CNET reviews
On remote keyless entry systems: "The authors also suggest that car owners wrap their keyless ignition fobs in tin foil when not in use" to prevent scanning.
security  motoring  transport  authentication  tinfoilhat  via:nkrishna 
may 2006 by blech
URL authentication in IE
Including how to revert to the previous, insecure user:pass@host method
work  ie  security  authentication 
may 2006 by blech
How Mac OS X Implements Password Authentication, Part 2
I'm surprised that the LANMAN passwords get generated automatically, given you have to futz in Accounts to get Windows sharing working. Interesting post.
macosx  authentication  security  via:rentzsch 
april 2006 by blech
TextMate Blog ‽ Keychain Access from Shell
Could be useful in various places. Actually, maybe in Blue Coconut, although there "proper" Cocoa access would be better.
apple  security  keychain  via:daringfireball 
april 2006 by blech
Network Security, Vulnerability Assessment, Intrusion Prevention
Despite the CNet report from boingboing mentioning eEye, their page doesn't mention iTunes
apple  itunes  windows  security  eeye 
november 2005 by blech
Search Results
I notice the eEye vulnerability hasn't made CVE status
apple  itunes  security  cve 
november 2005 by blech

Copy this bookmark:



description:


tags: