Friday, April 11, 2014

Pretty Cool.


The Internet Bug Bounty rewarded @neelmehta with a $15,000 bounty for the TSL heartbeat read oversrun, aka HeartBleed.

And then @neelmehta donated the reward to the Freedom of the Press Foundation.

Very Cool!

-------------------------------------------------

#6626 CVE-2014-0160

TLS heartbeat read overrun

Someone reported a bug to OpenSSL.
A missing bounds check in the handling of the TLS heartbeat extension can be used to reveal up to 64k of memory to a connected client or server.

Only 1.0.1 and 1.0.2-beta releases of OpenSSL are affected including 1.0.1f and 1.0.2-beta1.

Thanks for Neel Mehta of Google Security for discovering this bug and to Adam Langley agl@chromium.org and Bodo Moeller bmoeller@acm.org for preparing the fix.

Affected users should upgrade to OpenSSL 1.0.1g. Users unable to immediately upgrade can alternatively recompile OpenSSL with -DOPENSSL_NO_HEARTBEATS.

1.0.2 will be fixed in 1.0.2-beta2.

http://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=96db9023b881d7cd9f379b0c154650d6c108e9a3

Thursday, April 10, 2014

BrickFair LEGO Convention, August 2 - 3, 2014


BrickFair VA 2014 is 4 months away!
Join us Aug 2nd & Aug 3rd2014 at the Dulles Expo Center in Chantilly, VA.
Doors open 11:00am to 4:00pm.
Over 900 LEGO artists from across the country will exhibit LEGO models and games spread over 100,000 square feet.
$12 at the door. Visit www.BrickFair.com/VA.


Wednesday, April 9, 2014

Emergency SSL/TLS Patching Under Way



Emergency SSL/TLS Patching Under Way

A "Heartbleed" flaw revealed in the OpenSSL library leaks the contents of memory, including passwords, source code, and keys.

The race is on to fix SSL-based websites and software in the wake of a newly revealed and dangerous flaw in the popular OpenSSL library for encrypting HTTP traffic, with nearly one-third of major websites potentially at risk.

OpenSSL released a patch yesterday for a read-overrun bug in its implementation of the Transport Layer Security protocol's "heartbeat" extension, an extension to the protocol that checks on the site to which it is connecting to ensure it's connected and can respond. If exploited, the bug leaks the contents of the memory from the server to the client and vice versa, potentially exposing passwords and other sensitive data and, most alarmingly, the SSL server's private key. OpenSSL Versions 1.0.1 and 1.0.2 beta are affected by the vulnerability, which was discovered by security researchersat Google and Codenomicon.

http://www.darkreading.com/vulnerabilities---threats/emergency-ssl-tls-patching-under-way/d/d-id/1204282

Saturday, March 29, 2014

Removing Glued LEGO Magnet Minifigures


I decided to spend a bit of time myself trying to find a solution that is both safe for the minifig and the person using the method. (Please read our Tutorials Disclaimer for your safety here.) I will start with the process that I found working, and below that I will list my failed attempts for your further amusement (and horror!). ;)

Sunday, March 23, 2014

In defense of UDP


Heard through @StrongwaterSec

the_skys_kid comments on Freenode under DDOS again


[–]the_skys_kidRHODESIA WAS SUPER! 2284 points  agox7

I'll defend UDP.

UDP is the honey badger of the internet protocol suite.

UDP is all about the transaction. UDP is standing on a cliff yelling, "Come at me, bro", whether you're there or not.

UDP is a man's protocol doing real shit like bootstrapping your ass and slapping an IP on you. Get up, motha fucka!

UDP will talk shit to one of you or all of you. UDP ain't scared. UDP brought the fear.

UDP understands that you may be slow sometimes. So UDP will wait for your sorry ass. UDP grew up without a father, too.

UDP sends a message and couldn't give a fuck if you got it or not.

UDP got a message from you saying that you got his messages and guess what? UDP didn't even open it! Not one fuck given.

Don't try to shake UDP's hand! You crazy?

And, when UDP dies because you weren't available, UDP doesn't shed a tear. UDP is hardcore. He's going out even if he knows you ain't there. UDP is a goddam one-man slaughter house.

Why?

Because UDP doesn't give a fuck.



http://www.reddit.com/r/sysadmin/comments/1yn4lh/freenode_under_ddos_again/cfmaxrh?context=3

Sunday, March 16, 2014

Hate Small Talk? One Approach Anyone Can Use - by Jeff Haden


"Look around the room. Pick someone who looks uncomfortable. Pick someone who seems to feel out of place. Pick someone just like you."

"Then go talk to them. Make it your goal to make that one person feel more comfortable. Then you'll feel more comfortable too."

Try it. If it's painful to mingle, if it's awkward to make small talk, use those feelings in a positive way. Turn sympathy for yourself into empathy for another. Go rescue someone.

Just introduce yourself to people and ask a basic question: what they do, where they're from, why they're attending. You don't need to be a conversational genius. The people you rescue won't notice. They'll be too busy feeling less like wallflowers and more like people who belong--and they will always remember that it was you who made them feel that way.

More:
http://www.inc.com/jeff-haden/hate-small-talk-one-approach-anyone-can-use.html

Thursday, February 13, 2014

Applied DNA Sciences Teams with LMI, a Leading Government Consulting Firm to Tackle Supply Chain Counterfeiting |



This collaborative relationship seeks to educate the public and private sectors on the increasing risk posed by counterfeits, and encourage the development and fielding of preventive measures.

LMI has deep supply chain consulting and inventory management experience for the military and across the federal government. APDN invests in industry-leading research and provides a variety of authentication solutions to both commercial and government clients.

"Supply chains critical for commerce and security are under attack. In the electronics arena, remarking, cloning, and manufacture from salvaged die are creating increasingly sophisticated counterfeits. Industry and public sector users alike are struggling to ensure authentic components in this flood of fakes," said Joe Doyle, senior consultant for LMI. A cutting edge technology company in this space working with a leading supply chain consultancy is just the sort of collaboration that can make a difference, Doyle added.

More:

Tuesday, February 11, 2014

Arizona Sheriff Arpaio puts 38 prisoners on bread and water while prepping for deposition in Justice Dept lawsuit for racially profiling Latinos | Government Security News


This man is not a servant of the people...

Although Arpaio calls himself "America's toughest sheriff" and has a number of diehard supporters, the County of Maricopa recently announced that his racial profiling policies have in fact cost Maricopa County taxpayers $22 million. In May of 2013, U.S. District Judge Murray Snow ruled that Arpaio's office routinely profiled Latinos in traffic and immigration patrols.


Monday, February 10, 2014

Army units give thumbs-down to battlefield intelligence system |


Ouch!

Software complexity, unreliability and user training that extends no further than "buttonology" continue to plague the Army's multibillion Distributed Common Ground System (DCGS-A), prompting soldiers to turn to commercial software, according to feedback from several units in Afghanistan.

That feedback was included in a memo from November, obtained by Military.com and reported by DOD Buzz. The memo resulted from an October meeting five units had with Brig. Gen. Christopher Ballard, at the time deputy chief of staff for intelligence at the International Security Assistance Force Joint Command.

Among the complaints are that DCGS-A is "unstable, slow, not friendly and a major hindrance to operations," with upgrades that wipe out users' data, according to comments from the 130thEngineer Brigade, which reported losing three to five calendar days a month because of system issues.

More:

Sunday, February 9, 2014

Predicting for 2103? Really?



I think this is a typo. Either that or somebody is doing some loooooong range forecasting.

Wednesday, January 22, 2014

A secure phone, designed with user privacy and security as the primary objective



Will government call on the Blackphone for secure comm?

The latest tool for secure communication in government might be the Blackphone. The sleek, black smartphone uses encryption so users can make secure phone calls, use video chat features and store files securely. And while the Blackphone name may not be well known yet, its creators, Geeksphone and Silent Circle, are at the heart of many efforts to improve secure communications. 

Geeksphone is a Madrid-based company specializing in the development, promotion and commercialization of open-source mobile telephony. The company launched an Android smartphone in 2009 and the world's first Firefox OS-powered smartphone in 2013. Silent Circle provides a peer-to-peer platform for encrypted voice, video, text and file transfer on mobile devices via a secure, proprietary network, software and mobile apps.

More:
http://gcn.com/articles/2014/01/21/blackphone.aspx

Wednesday, January 15, 2014

Costco pricing codes - the real deals

 Price ending in .99 – the product is full price

Price ending in .97 – a deal decided by the manager

Price ending in .49 or .79 – manufacturer's special -
The manufacturer is testing out at Costco, usually at a lower price than Costco would sell the item

Price ending in .00 – It means the manager wants the item out.

A price tag with an asterisk – it's discounted and discontinued

More:
http://slightlyviral.com/getting-the-best-deals-at-costco/