sunpig + security   141

London 2012's stupendous insanity leaves sport as an also-ran | John Harris | Comment is free | guardian.co.uk
At which point, it is surely worth reflecting on the stupendous insanity boiling around the Olympics, and the fact that sport has become only a detail. Small wonder, of course – the founding idea of the modern games was an expression of the rise of the nation state, and ever since, the resulting spectacle has always crystallised two things: first, the unrivalled power of governments to lay on such gigantic and ludicrously wasteful spectacles; and second, whatever madness is swirling around the host country. Running, jumping and swimming, by comparison, will always be an added extra.
guardian  sport  olympic  games  2012  london  uk  britain  consumerism  society  culture  commercialism  security  theatre 
4 weeks ago by sunpig
encryption is (mostly) not magic | Benlog
For the most part, encryption isn’t magic. Encryption lets you manage secrets more securely, but if users are involved in the key management, that almost certainly comes at the expense of usability and features. Web services should strongly consider encryption where possible to more strictly manage their internal access controls. But think carefully before embarking on a design that forces users to manage their keys. In many cases, users simply don’t understand that losing the key means losing the data. As my colleague Umesh Shankar says, if you design a car lock so secure that locking yourself out means crushing the car and buying a new one, you’re probably doing it wrong.
encryption  security  mozilla  firefox  privacy  users  usability  hashing  hash  password  key  voting 
4 weeks ago by sunpig
encryption is not gravy | Benlog
That last point bears repeating: if you design a system with encryption where users manage keys, you’re going to lose features. You want gravy on that turkey? Sorry, no stuffing for you. “What?” you say. But I want my stuffing and my gravy! I want to believe I can have it all!
mozilla  firefox  sync  crypto  encryption  data  user  password  security  loss  device 
4 weeks ago by sunpig
PHP: a fractal of bad design - fuzzy notepad
Virtually every feature in PHP is broken somehow. The language, the framework, the ecosystem, are all just bad. And I can’t even point out any single damning thing, because the damage is so systemic. Every time I try to compile a list of PHP gripes, I get stuck in this depth-first search discovering more and more appalling trivia. (Hence, fractal.)

PHP is an embarrassment, a blight upon my craft. It’s so broken, but so lauded by every empowered amateur who’s yet to learn anything else, as to be maddening. It has paltry few redeeming qualities and I would prefer to forget it exists at all.
php  language  design  feature  broken  software  code  programming  rant  reference  security  fault  bug  error  array 
5 weeks ago by sunpig
Princeton S* Network Systems» Blog Archive » JavaScript in JavaScript (js.js): Sandboxing Third-Party Scripts
js.js is a JavaScript interpreter (which runs in JavaScript) that allows an application to execute a third-party script inside a completely isolated, sandboxed environment. An application can, at runtime, create and interact with the objects, properties, and methods available from within the sandboxed environment, giving it complete control over the third-party script. js.js supports the full range of the JavaScript language, is compatible with major browsers, and is resilient to attacks from malicious scripts.
js  javascript  sandbox  environment  emscripten  native  code  programming  interpreter  security 
5 weeks ago by sunpig
Troy Hunt: Breaking CAPTCHA with automated humans
RT @karlgroves: Holy Cow! Must read article on how useless your CAPTCHA is: HT @ppatel
captcha  break  human  bot  automated  security  fail 
january 2012 by sunpig
Troy Hunt: The only secure password is the one you can’t remember
"The only secure password is the one you can’t remember" /by @troyhunt
troyhunt  password  security  infosec  manager 
june 2011 by sunpig
Why loading JavaScript over SSL from a third-party CDN is a bad idea
RT @yaypie: Why loading JavaScript over SSL from a third-party CDN is a bad idea:
ryangrove  ssl  security  trust  load  cdn  js  javascript  resource  external  site  certificate  web  webdev 
may 2011 by sunpig
evercookie - virtually irrevocable persistent cookies
RT @jeremiahg: RT @samykamkar: evercookie - JS API for extremely persistent browser cookies < uh oh, someone is ma ...
ever  cookie  cookies  browser  persistent  security  privacy  tracking  persistence  forever  long  history  data  storage  html  html5  web  webdev  samy  js  javascript  api 
september 2010 by sunpig
Doth I protest too much? | Mark Thomas | Comment is free | The Guardian
"Protest is part of the democratic process. It wasn't the goodwill of politicians that led them to cancel developing countries' debt, but the protests and campaigning of millions of ordinary people around the world. The political leaders were merely the rubber stamp in the democratic process. Thus any targeting and treatment of demonstrators (at the G20 for example) that creates a "chilling effect" – deterring those who may wish to exercise their right to protest – is profoundly undemocratic."
markthomas  guardian  politics  protest  democracy  freedom  privacy  security  surveillance  police  uk  activism  lh 
october 2009 by sunpig
It’s Me, and Here’s My Proof: Why Identity and Authentication Must Remain Distinct
Essay about security, specifically looking at the potential danger of biometrics being misunderstood and therefore misued. (via <a href="http://www.schneier.com/blog/archives/2009/01/identity_authen.html">Bruce Schneier</a>)
security  microsoft  identity  authentication  password  geeknotes  authorization  auth  factor  biometrics 
january 2009 by sunpig
« earlier      

related tags

4thamendment  5.5  abc  absurd  access  account  accounts  activism  addon  admin  administration  adultswim  advice  aim  airline  ajax  amazon  analysis  animation  anonymity  anonymous  anthrax  antwerp  apache  api  app  apple  application  apppool  array  asp  asp.net  aspnet  aspnet2.0  assignment  athf  atlantic  atm  atom  attack  attr_accessible  audio  auth  authentication  authnauthz  authorization  automated  awareness  bac  backup  bank  banking  bcrypt  behaviour  ben  benadida  bigbrother  biometics  biometrics  blog  blogging  blowfish  bodyguard  border  boston  bot  break  breakin  breaking  britain  broken  browser  bruceschneier  brucesterling  bruteforce  bug  bundle  burglary  business  caja  camera  capabilities  captcha  card  cbp  cdn  censorship  certificate  chain  change  charliestross  cheek  cherylmorgan  chrisheilmann  circuit  circumvention  clickjacking  clockwork  cloud  cnet  code  color  colour  comint  command  commercialism  communication  compare  compatibility  composition  compromise]  computer  computers  computing  configuration  connect  connectionstring  constitution  consumerism  content  control  cookie  cookies  correspondent  corydoctorow  crack  cracking  credentials  crime  crisp  cross  crossdomain  crossing  crt  crypto  cryptography  csrf  css  css3  culture  customs  cwe  cya  danger  data  database  dba  debug  deception  defeat  defectiveyeti  democracy  design  desktop  detect  development  device  diamond  diamonds  digg  disguise  disney  distortion  dns  domain  dotnet  drm  dropbox  eavesdropping  edwardhasbrouck  effectiveness  electrical  email  emergency  empire  emscripten  encryption  engineering  environment  ericsink  error  essay  estate  eu  europe  ever  evercookie  exaggeration  execute  expectation  experience  exploit  external  eyes  f-secure  face  facebook  facial  factor  factoring  factory  facts  fail  failure  fastcgi  fault  fear  feature  fence  finance  findability  finder  fingerprint  firefox  firesheep  firewall  fivethirtyeight  fix  flash  flying  folder  forever  forgery  form  frame  fraud  freedom  french  fsecure  fullscreen  funny  games  geeknotes  get  glasses  google  gps  gpu  greasemonkey  groundhog  group  groups  guard  guardian  guns  hack  hacking  hardware  hash  hashes  hashing  hdcp  hdd  hdmi  heist  history  hmac  hoax  homeland  html  html5  http  https  human  icann  iceland  id  idcards  identification  identify  identity  idiot  ie  ie7  iframe  iis  iis7  iis7.5  iis_iusrs  imperial  implementation  incident  inclusiveness  inference  infosec  infrared  infrastructure  inhertitance  injection  inspect  inspiration  install  installer  internet  internetexplorere  interpreter  intrusion  ipfw  iphone  ipod  iraq  itunes  iusr  jamesfallows  java  javascript  jira  johnresig  journalism  js  json  jsonp  kaspersky  kentbrewster  key  kiphawley  landing  language  laptop  law  lcd  led  legal  leonardonotarbartolo  leopard  lh  liberty  lifehacks  link  lion  littlebrother  live  load  local  locate  lock  locks  log4net  login  logout  london  long  los  loss  mac  machine  make-up  makeup  malware  manager  maninthemiddle  marblecake  markpilgrim  markthomas  markuskuhn  mastermind  math  mattblaze  matthewbaldwin  medium  memory  message  michaelmahemoff  microsoft  mindset  mistake  mitm  mitre  mobileme  mode  money  monitoring  monument  mooreslaw  moot  mostlyevil  motiondetector  movabletype  movies  mozilla  mssqlserver  mt  music  myspace  mysql  name  natesilver  native  network  networking  networkservice  news  nginx  nmap  noise  nsa  oauth  object  objectives  obscure  olympic  opacity  openid  operations  orange  osx  overreaction  pants  params  paranoia  pararazzi  passphrase  passport  password  pasword  paullamere  performance  permissions  persist  persistence  persistent  personal  philosophy  phishing  phone  photo  photography  php  phreaking  physical  picking  picture  planning  plastic  plot  police  policy  politics  poll  pool  power  precision  president  prevent  prevention  primarykey  privacy  problem  programming  protect  protection  protest  protocol  proxy  psychology  publishing  python  quantum  qubit  question  rails  rainbow  ramonrozas  random  rant  reaction  recognition  recovery  red  reference  remote  repression  reset  resolve  resource  response  RFID  righttosilence  risk  robots.txt  root  rss  ruby  ryangrove  sa  safes  safety  salt  samharris  samy  sandbox  sanitize  sans  save  sb  scan  schneier  scinning  screening  scroll  search  secrecy  secret  security  securityquestion  securitytheatre  seek  self-signed  sense  sercret  server  sha-1  sha1  siemens  signal  signature  simpletalk  sisistar  site  sixapart  skimmer  slicehostattack  snowleopard  social  society  software  sony  sound  spam  speech  speed  sport  sql  sqlserver  sqltalk  ssh  ssl  startup  state  statement  statistics  status  steal  stevejobs  storage  store  storm  story  stoyanstefanov  strategy  stuxnet  submit  sunglasses  surveillance  swift  sync  syndication  system  table  tactics  target  technology  tempest  temporarily  terror  terrorism  testing  theatlantic  theatre  theft  theory  thinking  thirdparty  threat  tie  time  timing  tips  tls  token  tomengelhardt  tracking  tradeoff  transport  travel  trojan  troyhunt  truecrypt  trust  tsa  tweakers  twitter  ui  uk  underwear  update_attributes  url  us  usa  usability  usb  user  username  users  ux  vaneck  video  violence  virus  visa  vista  voice  voting  vpn  vulnerability  war  waronterror  washington  watch  watchclock  waterroof  web  web.config  webdev  webserver  whatwg  white  wifi  will  win7  windows  windows7  wired  wireless  wishlist  wordpress  worm  wpa  wrap  xml  xsrf  xss  yellow  yql  zoompf 

Copy this bookmark:



description:


tags: