N3rvp4in’s Kludge

You know, this is really what this is, a KLUDGE!

Posts Tagged ‘security’

Update on Yubikey

Posted by n3rvp4in on May 10, 2008

Steve Gibson has an episode of Security Now (SN143) that is dedicated to the Yubikey. This thing sounds better all the time.  The fact is that I think they we a little caught off guard when they met Steve Gibson.  They were unaware of his reach.  It sounds like the people running Yubico were not fully committed to the direction their company would go in, but they are making those choices now.  The stated intent of the company is to sell the device.  The amount paid for the device depends on how many you buy.  You get 1 for $35 or 1,000,000 for about $5 a piece.  So if you want to play around with 1 or 2 you can or if you want to develop a hugh system around them you could also do that.  The nice part is the software to get these things working is open source now.  So people like me who don’t have a clue about implementing a huge authentication system can play around with it and make it work on a small scale.  Of course, making things work on a small scale is the precursor to making things work on a large scale.  I really like open source software for this reason.  So much software is too costly to even attempt to make work on small projects and this really impairs the ability to learn how it works.  At least for honest people.

Posted in Computers | Tagged: , , , , | Leave a Comment »

Keeping Up With Computer Security

Posted by n3rvp4in on February 9, 2008

I like to work with computers and the vast majority of what I see is security related.  For example, a customer brings in a box that is running “slow”.  So the first thing I do is look for some type of malware.  99% of the time the system is infected with multiple items of malware.  This is usually the time that I recommend a format and reinstall of the OS.  As a side note, I have yet to have a customer bring is a box with Linux running on it.  Maybe its because few customers know what it is until I tell them.

Keeping up with the massive amount of information about computer security has become impossible.  I think this is true for all security gurus / enthusiasts, not just myself.  My strategy has become, listen to a select group of pod-casts and wade through the info contained in the pod-casts.  I also have several RSS feeds that I subscribe to and I look through these several times a day.  The problem is just the amount of info.  If I didn’t have other things to do, maybe I could get through more of it.  Oh well, I will attempt to keep up with the info that I deem the most valuable.

Posted in Computers | Tagged: , , , , | Leave a Comment »

Interesting Story on Security Now #130

Posted by n3rvp4in on February 9, 2008

I finally listened to the Security Now episode this week and there is a great story about a security tester. Steve Gibson relates a story about this person pen-testing a company. If you are into that kind of thing check it out. Note: If you have wireless devices of any kind in your home or office check it out.

http://www.grc.com/SecurityNow.htm

Posted in General Advice | Tagged: , | Leave a Comment »