<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2582112902847616917</id><updated>2012-02-01T11:40:23.614-08:00</updated><category term='computer security'/><category term='anonymity'/><title type='text'>Universal Security</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>32</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-7362447165083170486</id><published>2008-01-26T23:22:00.000-08:00</published><updated>2008-01-26T23:28:33.736-08:00</updated><title type='text'>usb key evil tools</title><content type='html'>In the movies "hackers" plug in devices to computers and progress bars appear showing "downloading".  This is not reality.  Below are two tools that are reality.  Usb keys can be used to silently install and retrieve and email keyloggers. &lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;&lt;a href="http://wiki.hak5.org/wiki/USB_Switchblade"&gt;USB Switchblade&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;"The goal of the USB Switchblade is to silently recover information from a target Windows 2000 or higher computer, including password hashes, LSA secrets, IP information, etc... "&lt;br /&gt;&lt;br /&gt;&lt;a href="http://wiki.hak5.org/wiki/USB_Hacksaw"&gt;USB hacksaw&lt;/a&gt;&lt;br /&gt;"The USB Hacksaw is an evolution of the popular USB Switchblade that uses a modified version of USBDumper, Blat, Stunnel, and Gmail to automatically infect Windows PCs with a payload that will retrieve documents from USB drives plugged into the target machine and securely transmit them to an email account.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-7362447165083170486?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/7362447165083170486/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=7362447165083170486' title='12 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/7362447165083170486'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/7362447165083170486'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2008/01/usb-key-evil-tools.html' title='usb key evil tools'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>12</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-9152452147278180353</id><published>2007-12-10T18:01:00.000-08:00</published><updated>2007-12-10T18:03:54.586-08:00</updated><title type='text'>Airpwn</title><content type='html'>If you don't know about&lt;a href="http://www.evilscheme.org/defcon/"&gt; airpwn,&lt;/a&gt; then you're missing out on some funny.  Remember kids, the "man in the middle" attack is sometimes very very disturbing!&lt;br /&gt;&lt;blockquote&gt;Over the course of defcon, we fielded 7 different airpwn configurations to see how well it worked, and of course to watch as 31337 h4x0rz got goatse up in their mug. The configurations were:&lt;br /&gt;&lt;br /&gt;HTTP goatse, 100% of the screen&lt;br /&gt;HTTP goatse replacing all images&lt;br /&gt;HTTP goatse as the page background via CSS&lt;br /&gt;HTTP tubgirl replacing all images&lt;br /&gt;HTTP "owned" graphic, replacing all images (eventually I felt bad about all the ass pictures)&lt;br /&gt;HTTP javascript alert boxes, letting people know just how pwned they were&lt;br /&gt;FTP banners (while this worked, nobody pays attention to FTP banners so we abandoned this quickly)&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-9152452147278180353?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/9152452147278180353/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=9152452147278180353' title='301 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/9152452147278180353'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/9152452147278180353'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/12/airpwn.html' title='Airpwn'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>301</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-8537231988203021740</id><published>2007-12-09T16:42:00.000-08:00</published><updated>2007-12-09T16:55:18.635-08:00</updated><title type='text'>Off the record messaging (forward security)</title><content type='html'>Interesting concepts, especially forward security&lt;br /&gt;&lt;a href="http://www.cypherpunks.ca/otr/#faqs"&gt;http://www.cypherpunks.ca/otr/#faqs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The idea here is to have secure messaging with a few more benefits than have been available by encrypted chat (offered by gaim and many others for several years).  It's supported by everyone's favorite client, Adium X.  One of the problems with other methods of encrypted conversations is that they were all authenticated with the same key, so that if your machine is &lt;span style="font-style: italic;"&gt;ever&lt;/span&gt; compromised the attacker can now read all your &lt;span style="font-style: italic;"&gt;past conversations&lt;/span&gt;.  Also, if your machine is compromised, you cannot deny having said what you said since it was signed with your key.&lt;br /&gt;&lt;br /&gt;OTR messaging uses crazy math to ensure that each conversation is encrypted with a different key derived from the same original secret key.  Therefore you cannot use a captured private key to unencrypt previous messages but you know the current conversation is authenticated because all the subkeys must have been made with the original key.  (This is part of the gpg specification.)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://chris.milbert.com/AIM_Encryption/#MacAdium"&gt;AdiumX is available as a download&lt;/a&gt; beta with OTR built in.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://chris.milbert.com/AIM_Encryption/adium1.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://chris.milbert.com/AIM_Encryption/adium1.jpg" alt="" border="0" /&gt;&lt;/a&gt;I used to use encrypted chat but only 3 of my friends had compatible versions, so unless this were to gain traction amongst a high proportion of your friends, it is probably not very useful.  However, the novel abilities of OTR would be nice to see in other products.&lt;br /&gt;&lt;br /&gt;Imagine someone capturing your secret key and having the ability to decrypt all your previous communications.  That's what happened to the Nazis &lt;a href="http://en.wikipedia.org/wiki/History_of_cryptography"&gt;when they got lazy and started reusing keys&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-8537231988203021740?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/8537231988203021740/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=8537231988203021740' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/8537231988203021740'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/8537231988203021740'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/12/off-record-messaging-forward-security.html' title='Off the record messaging (forward security)'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-1196386384887759233</id><published>2007-12-04T20:50:00.001-08:00</published><updated>2007-12-04T21:00:11.171-08:00</updated><title type='text'>How to build a kitchen timer</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_yJtDj8W6PjY/R1YuUP3eOvI/AAAAAAAAAAo/ihUtqcgriQA/s1600-h/main_view.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 259px; height: 194px;" src="http://3.bp.blogspot.com/_yJtDj8W6PjY/R1YuUP3eOvI/AAAAAAAAAAo/ihUtqcgriQA/s320/main_view.jpg" alt="" id="BLOGGER_PHOTO_ID_5140346950081460978" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_yJtDj8W6PjY/R1YvdP3eOwI/AAAAAAAAAAw/4NuG0f-9ygE/s1600-h/main_board_2.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 262px; height: 194px;" src="http://3.bp.blogspot.com/_yJtDj8W6PjY/R1YvdP3eOwI/AAAAAAAAAAw/4NuG0f-9ygE/s320/main_board_2.jpg" alt="" id="BLOGGER_PHOTO_ID_5140348204211911426" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Check out &lt;a href="http://www.frisnit.com/timer/index.html"&gt;these circuit diagrams&lt;/a&gt;.  What? It's a &lt;span style="font-style: italic;"&gt;kitchen timer&lt;span style="font-style: italic;"&gt;.&lt;/span&gt;&lt;/span&gt;  What did you &lt;span style="font-style: italic;"&gt;think&lt;/span&gt; it was?&lt;br /&gt;&lt;br /&gt;The guy from &lt;a href="http://www.frisnit.com/"&gt;frisnit.com&lt;/a&gt; has lots of great projects.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;It's a kitchen timer. Use it to time spaghetti, or maybe an egg. It uses two PICs, one acts as a keyboard encoder, the other drives the display and supports the timer functions. You key in the desired time and press '#'. It's accurate to 1/100th of a second, which can make all the difference I'm sure you'll agree&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Also, the duct tape is critical to it's operation!  Let me know when you attempt to bring one of these on board an airplane!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-1196386384887759233?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/1196386384887759233/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=1196386384887759233' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/1196386384887759233'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/1196386384887759233'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/12/how-to-build-kitchen-timer.html' title='How to build a kitchen timer'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_yJtDj8W6PjY/R1YuUP3eOvI/AAAAAAAAAAo/ihUtqcgriQA/s72-c/main_view.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-2716789368491643040</id><published>2007-12-04T20:14:00.000-08:00</published><updated>2007-12-04T20:40:53.130-08:00</updated><title type='text'>Radio scanning in Louisiana, frequency lists available</title><content type='html'>Radio scanning in Louisiana, frequency lists available&lt;br /&gt;&lt;a href="http://ultratoast.googlepages.com/myscanner.csv"&gt;(Current list that I use.)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ultratoast.googlepages.com/brfreqlist.csv"&gt;(Current list of open channels of all kinds of businesses and agencies)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Louisiana is supposed to be switching over to the &lt;a href="http://www.radioreference.com/modules.php?name=RR&amp;amp;sid=4347"&gt;Louisiana Totally Interoperable Environment (LATIE)&lt;/a&gt; system for all police, fire, EMS, etc radio communications.  Some parishes are up and running, and some are taking their time.  Listed at that link are frequencies and ID codes for State Police, local police, and basically every other LATIE equipped department.  Please note that Lafayette Parish has switched over to encryption with their systems.  To listen to LATIE traffic you must have one of two different models currently available.  The &lt;a href="http://www.universal-radio.com/catalog/scanners/1396.html"&gt;Uniden BCD369T&lt;/a&gt; handheld going for $300-500, or the &lt;a href="http://wiki.radioreference.com/index.php/BCD996T"&gt;super bad-ass Uniden BCD996T&lt;/a&gt; which is basically sentient.&lt;br /&gt;&lt;br /&gt;Here is the forum for LATIE related questions for hobbyists:&lt;br /&gt;&lt;a href="http://www.radioreference.com/forums/forumdisplay.php?f=13"&gt;http://www.radioreference.com/forums/forumdisplay.php?f=13&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;My personal belief is that encryption is too difficult for the state guys to even mess with for at least one more generation of gear.  Most agencies will continue to use the easiest, cheapest, oldest, and least secure methods of communication until they are forced to adhere to some new minimum requirement.  This is good for those of us who want to hear them talk (including reporters, news channels, and any hobbyist.)&lt;br /&gt;&lt;br /&gt;I've compiled a massive list of *currently used, non-trunk frequencies of everyone from the cops to mcdonalds and drive throughs, and LSU services available here below the fold.  Please enjoy.&lt;br /&gt;&lt;br /&gt;If the cops are going to be blasting their radio waves directly into my apartment, then they have no right to complain that I decide to listen to them.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-2716789368491643040?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/2716789368491643040/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=2716789368491643040' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/2716789368491643040'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/2716789368491643040'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/12/radio-scanning-in-louisiana-frequency.html' title='Radio scanning in Louisiana, frequency lists available'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-8062425746653587022</id><published>2007-12-02T16:58:00.000-08:00</published><updated>2007-12-02T17:26:33.944-08:00</updated><title type='text'>Mac Users:  Set Your File Vault Master Password</title><content type='html'>Since this blog is, at least in part, about bringing to your attention possible security threats, I'll make my first post here about a threat I recently thought up.  I mentioned this to a friend and, the more we discussed it, the scarier it seemed.  Luckily, there's a simple fix.&lt;div&gt;&lt;br /&gt;&lt;div&gt;The threat in question is the threat of an unset Master Password on your macintosh's File Vault.  Now, many of you are like me, and have been so scared reading about File Vault that you don't currently intend to ever turn it on.  But, at the very least, you should set a Master Password in the File Vault preferences pane (System Preferences &gt; Security &gt; File Vault).  Doing so will NOT turn on File Vault.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Why, you ask?  Well, I suppose that depends, in part, on where you're using your computer.  Mine, a Powerbook G4 running Leopard, stays open on my desk all day.  I'm a graduate student at a university, and my desk is in an office I share with many others.  The office itself remains open during the day and so passers by theoretically have direct access to my machine.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I regularly leave it there, protected by a laptop lock, and go get coffee, teach lab, or take a walk.  In addition to this physical protection, I've recently disabled automatic login and turned on password requirements to wake the computer from sleep or screen saver (both in System Preferences &gt; Security &gt; General).  I've also made an encrypted disk image (using Disk Utility) that contains all of my sensitive data.  This encrypted disk image means that even if someone gains physical access to my machine with the login passwords down, my most sensitive data is safe from prying eyes.  But despite all of these measures, the File Vault Master Password is another security hole that is too easily plugged to risk ignoring it.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It's an unlikely scenario, but one in which you would be completely fucked if it were to occur.  Let's say I'm off getting coffee and my officemates are off doing whatever they are doing.  Now further assume that in a moment of forgetfulness, I left my computer open and didn't trigger the screen saver.  A person with malicious intent could walk in before the screen saver automatically starts and, unopposed, access the File Vault Preferences.  If the Master Password is unset, they could set it themselves and trigger File Vault to lock up my home directory.  I would come back from coffee to an unusable machine in which all of my precious personal data, including any encrypted disk images that I put sensitive stuff in, was encrypted with a key that I did not possess.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;While it's true that the antagonist still shouldn't have access to my most personal data, because it's in the encrypted disk image that I never mount unless I'm actively using, it would deny ME access to my own data, which is almost as bad.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I admit, it's an improbable happening, but one that, nonetheless, remains well within the realm of possibility and for which the countermeasures are far too easy to justify ignoring.  If you set the Master Password, then you and your computer are safe from would-be practical jokers or evil office trolls who might encrypt your home directory without giving you the key.   Having the Master Password set doesn't require you to turn File Vault on, but it does allow you to turn it off if someone else turns it on.  And, if that's not enough of an incentive to make you take action, I don't know what is.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-8062425746653587022?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/8062425746653587022/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=8062425746653587022' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/8062425746653587022'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/8062425746653587022'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/12/mac-users-set-your-master-password.html' title='Mac Users:  Set Your File Vault Master Password'/><author><name>Artificial Selection</name><uri>http://www.blogger.com/profile/16974261499331664829</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-6347602138551137085</id><published>2007-11-30T19:39:00.000-08:00</published><updated>2007-11-30T19:50:46.781-08:00</updated><title type='text'>WEP Cracking with kismac (you can't hide)</title><content type='html'>A friend recently informed me that he would be securing his wireless network with WEP encryption and hiding his SSID.  While this is a good idea and will deter 99.99% of evil crax0z, it's important to remember that WEP is not safe.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://youtube.com/watch?v=rwFqcdlkrLs"&gt;In this video we see&lt;/a&gt; someone crack a WEP network and recover the password in 10 minutes, even though the SSID is hidden.  They use the excellent tool &lt;a href="http://kismac.macpirate.ch/"&gt;kismac&lt;/a&gt;, which is great for casual wardriving as well as packet interception and WEP cracking.&lt;br /&gt;&lt;br /&gt;Remember, &lt;a href="http://en.wikipedia.org/wiki/Security_through_obscurity"&gt;security through obscurity&lt;/a&gt; only works if you are actually obscure!&lt;br /&gt;&lt;br /&gt;----------------&lt;br /&gt;And a great article on preventing hacks by running software so ancient that nobody remembers how to hack into it.  &lt;a href="http://www.theregister.co.uk/2002/06/06/security_through_obsolescence/"&gt;Security through obsolescence&lt;/a&gt;.  Even the article is old.&lt;br /&gt;&lt;blockquote&gt;"I have one box still running a version of Solaris that's so old none of the script kiddies can figure it out," Brian says. "They tend to focus on the latest and greatest, and don't have the slightest idea how to handle my old Sun box."&lt;br /&gt;Brian points out that some of the most secure Department of Defense Web sites -- ones that don't make headlines by getting cracked all the time -- run old versions of Mac OS and the venerable WebSTAR server suite. "&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-6347602138551137085?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/6347602138551137085/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=6347602138551137085' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/6347602138551137085'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/6347602138551137085'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/11/wep-cracking-with-kismac-you-cant-hide.html' title='WEP Cracking with kismac (you can&apos;t hide)'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-4361058024158324969</id><published>2007-11-28T23:56:00.000-08:00</published><updated>2007-11-28T23:59:41.084-08:00</updated><title type='text'>Copy the key.  Make a good first impression.</title><content type='html'>copy a key using a soda can, copier, scissors.&lt;br /&gt;&lt;a href="http://www.instructables.com/id/S232P32F9056XNQ/"&gt;http://www.instructables.com/id/S232P32F9056XNQ/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You can easily get the master key for a building by asking the secretary to borrow it because you "forgot your X in room Y." &lt;br /&gt;&lt;a href="http://searchsecurity.techtarget.com/tip/1,289483,sid14_gci865450,00.html"&gt;Social engineering. &lt;/a&gt; Learn it, love it, design against it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-4361058024158324969?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/4361058024158324969/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=4361058024158324969' title='65 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/4361058024158324969'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/4361058024158324969'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/11/copy-key-make-good-first-impression.html' title='Copy the key.  Make a good first impression.'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>65</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-300014228324227408</id><published>2007-11-26T23:25:00.000-08:00</published><updated>2007-11-26T23:36:13.555-08:00</updated><title type='text'>The Death of Facebook</title><content type='html'>&lt;a href="http://informationweek.com/news/showArticle.jhtml?articleID=204203573"&gt;http://informationweek.com/news/showArticle.jhtml?articleID=204203573&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cory Doctorow, eminent SF Author and contributor to BoingBoing finally tells about the billion dollar elephant in the room.&lt;br /&gt;&lt;span style="font-size:78%;"&gt;*disclaimer.  I used to think Cory Doctorow was a publicity hungry SF faker, but after reading his work, I recognize his brilliance.  The man can write.  He is no poseur.&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div style="text-align: left;"&gt;&lt;span style="font-size:100%;"&gt;There is a reason that LiveJournal faded, and Blogger, and MySpace is on the way, and Friendster, and Linkedin, and Orkut, etc.  Facebook is this week's boring rehash.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;Everyone googles themselves, no one wants to be googled.  You want to be found by long lost friends but you don't lose touch with long lost friends, you lose touch with creepy weirdos that you maybe kinda liked to hang out with, but now you'd rather save the energy and just not talk to.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;Except you get a friend request.  Then you're an asshole for saying no.  So you start signing in less frequently because this person who you kinda liked to hang out with, but you don't really interact with anymore is now part of your "friends list" and you see every goddamn message they post.  You can't escape me, I can't escape you, neither of us politely.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;Let's all pretend that we're not "that guy".  Right.  You're "that guy" to &lt;span style="font-style: italic;"&gt;somebody&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;Facebook is a waste of your time and everybody's money.  Close your account.  In 10 years, all these undergrads will wonder why they wasted 6 hours a day on some stupid facebook garbage when they were missing out on college life.  Oh well.  C'est la vie.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-300014228324227408?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/300014228324227408/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=300014228324227408' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/300014228324227408'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/300014228324227408'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/11/death-of-facebook.html' title='The Death of Facebook'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-1202502473572913921</id><published>2007-11-24T23:34:00.000-08:00</published><updated>2007-11-25T00:26:46.300-08:00</updated><title type='text'>Firefighters sidestep the 4th ammendment</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;a href="http://www.msnbc.msn.com/id/21940968/"&gt;Firefighters sidestep the 4th ammendment&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;What scares me is not the sentiments of the author, nor the mainstream publication, but the blind obsequious acceptance.  Only &lt;a href="http://encyclopediadramatica.com/1984"&gt;DoubleThink&lt;/a&gt; could allow someone to even write these words in the US.  I do not fear the Authoritarians. &lt;a href="http://en.wikipedia.org/wiki/Right-wing_Authoritarianism"&gt;I fear their followers.&lt;/a&gt;  These are they.  Let's fisk.&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(102, 0, 0);font-size:130%;" &gt;&lt;blockquote&gt;Unlike police, firefighters and emergency medical personnel don’t need warrants to access hundreds of thousands of homes and buildings each year, putting them in a position to spot behavior that could indicate terrorist activity or planning&lt;/blockquote&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;You say this like it's a good thing.&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(102, 0, 0);font-size:130%;" &gt;&lt;blockquote&gt;Since the Sept. 11, 2001, terrorist attacks, Americans have given up some of their privacy rights in an effort to prevent future strikes. &lt;/blockquote&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;We did not give them up.  They were taken from us.&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(102, 0, 0);font-size:130%;" &gt;&lt;blockquote&gt;The American Civil Liberties Union says using firefighters to gather intelligence is another step in that direction.&lt;/blockquote&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;Ok, wrong analogy, how about &lt;a href="http://images.google.com/imgres?imgurl=http://i.imdb.com/Photos/Mptv/1391/12706_0024.jpg&amp;amp;imgrefurl=http://aol.imdb.com/gallery/mptv/1391/Mptv/1391/12706_0024.jpg.html%3Fhint%3Dtt0060390&amp;amp;h=420&amp;amp;w=400&amp;amp;sz=43&amp;amp;hl=en&amp;amp;start=8&amp;amp;sig2=6uunf5neSk7IHzw8tMahkQ&amp;amp;um=1&amp;amp;tbnid=2VXWvDQEdeZPCM:&amp;amp;tbnh=125&amp;amp;tbnw=119&amp;amp;ei=cylJR96QL5aCeoqMyO4L&amp;amp;prev=/images%3Fq%3Dfahrenheit%2B451%26svnum%3D10%26um%3D1%26hl%3Den%26client%3Dsafari%26rls%3Den-us%26sa%3DN"&gt;Fahrenheit 451.&lt;/a&gt;  Burning forbidden knowledge via firefighters? Check!&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(102, 0, 0);font-size:130%;" &gt;&lt;blockquote&gt;“They’re really doing technical inspections, and if perchance they find something like, you know, a bunch of RPG (rocket-propelled grenade) rounds in somebody’s basement, I think it’s a no-brainer,” &lt;/blockquote&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;Srsly.  Does that happen often?  Has any firefighter ever found an RPG in someone's burning down house?  Call up the Malibu guys;  no I'll wait.  Srsly.  I mean.. who the hell writes sentences like that?  "But what if we found a buncha RPGS in a basement."  That's actually what he said.  Is this an epidemic?&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(102, 0, 0);font-size:130%;" &gt;&lt;blockquote&gt;said Jack Tomarchio, a senior official in Homeland Security’s intelligence division.&lt;/blockquote&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;Oh well that explains everything.  FAIL.&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(102, 0, 0);font-size:130%;" &gt;&lt;blockquote&gt;When going to private residences, for example, they are told to be alert for a person who is hostile, uncooperative or expressing hate or discontent with the United States; unusual chemicals or other materials that seem out of place; ammunition, firearms or weapons boxes; surveillance equipment; still and video cameras; night-vision goggles; maps, photos, blueprints; police manuals, training manuals, flight manuals; and little or no furniture other than a bed or mattress.&lt;/blockquote&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;Fact.  You have described every engineering student in the USA.&lt;br /&gt;They list 19 criteria.  I would fall under 17 of those.&lt;br /&gt;&lt;br /&gt;Clearly I am a terrorist.  Me, &lt;/span&gt;&lt;span style="font-style: italic;font-size:130%;" &gt;and&lt;/span&gt;&lt;span style="font-size:130%;"&gt; the cat.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-style: italic;font-size:78%;" &gt;(for those playing at home, I would behave or own the following in a private residence: 1) hostile, 2) Uncooperative, 3) expressing discontent with the US, 4) unusual chemicals, kinda vague eh? 5) materials out of place, 6) ammunition, ye gods tons of it. 7) firearms, boy howdy 2nd Amendment. 8) weapons boxes, they send ammo in these.  9) surveillance equipment, i have a police scanner and some mirrors. 10) still and video cameras, who doesn't have these? 11) night vision goggles, they're fun.  12) Maps, of my city, in my car, 13) photos, 14) training manuals, vague as hell, but yes.  15) I have a book on cesnas.  16) little or no furniture?  hi all college males.&lt;br /&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 0, 0);"&gt;“We’re there to help people, and by discovering these type of events, we’re helping people,”&lt;br /&gt;&lt;/span&gt;&lt;/blockquote&gt;Wow.  Whatever makes you sleep at night buddy.&lt;br /&gt;&lt;span style="color: rgb(102, 0, 0);"&gt;&lt;blockquote&gt;And the fire service is also represented in at least 13 state and regional intelligence “fusion” centers across the country — where local, state and federal agencies share information about &lt;span style="font-weight: bold;"&gt;terrorism and other crimes.&lt;/span&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;a href="http://www.schneier.com/blog/archives/2007/08/mission_creep_a.html"&gt;Bruce Schneier specifically warned about these "fusion" centers and mission creep. &lt;/a&gt; It's like reading tomorrow's newspaper.&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(102, 0, 0);font-size:130%;" &gt;&lt;blockquote&gt;“So we see things and observe things that may be useful to law enforcement,” he said. “We can walk into your house. We don’t need a search warrant.”&lt;/blockquote&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;Yeah Bob, that's kinda the problem.  See.. the 4th Amendment.  You are an authoritarian follower.&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(102, 0, 0);font-size:130%;" &gt;&lt;blockquote&gt;But Cade said that until recently, there’s been no mechanism for fire departments to share what they learn with law enforcement and intelligence analysts who could use it.&lt;/blockquote&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;Fire departments are unable to use telephones?  Riiiiiiiight.&lt;br /&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="color: rgb(102, 0, 0);font-size:130%;" &gt;Homeland Security said if its program with New York is expanded across the country, civil rights and civil liberties training would be included.&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-size:130%;"&gt;Yes.  DHS is such a huge defender of civil liberties.  Heckuva job DHS.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-1202502473572913921?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/1202502473572913921/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=1202502473572913921' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/1202502473572913921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/1202502473572913921'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/11/firefighters-sidestep-4th-ammendment.html' title='Firefighters sidestep the 4th ammendment'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-1772301899399501096</id><published>2007-11-20T20:38:00.000-08:00</published><updated>2007-11-20T20:45:15.680-08:00</updated><title type='text'>Copy a key using a soda can, copier, scissors.</title><content type='html'>Instructables.  What a great site.  I did a similar trick after "borrowing" the master key from the departmental secretary.&lt;br /&gt;&lt;br /&gt;Who wants to carry around 12 different large metal pointless keys?  Get yourself a master key.  What does most every place of business have?&lt;br /&gt;Soda machines&lt;br /&gt;Copy machines&lt;br /&gt;Scissors&lt;br /&gt;Crappy security about who gets master keys.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.instructables.com/id/S232P32F9056XNQ/"&gt;How to make a working duplicate of a door key&lt;/a&gt; with a copy machine, soda can, scissors, etc.&lt;br /&gt;Are xerox machines good enough to literally xerox a key put on the glass and have the same dimensions on the output paper?  Yes.  :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-1772301899399501096?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/1772301899399501096/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=1772301899399501096' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/1772301899399501096'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/1772301899399501096'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/11/copy-key-using-soda-can-copier-scissors.html' title='Copy a key using a soda can, copier, scissors.'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-6940109144353987369</id><published>2007-11-14T23:31:00.000-08:00</published><updated>2007-11-14T23:42:19.458-08:00</updated><title type='text'>Three types of authentication.</title><content type='html'>Security theory:  There are 3 ways to authenticate yourself.  Most of the time you may prefer anonymity, but in some cases, you must &lt;span style="font-weight: bold;"&gt;prove you are who you say you are.&lt;/span&gt; &lt;br /&gt;If you are trying to access my house, my safe deposit box, my hard drive, etc, you must authenticate to the satisfaction of the door knob, the bank, or the filesystem respectively.&lt;br /&gt;&lt;br /&gt;These are the 3 methods of Authentication:&lt;br /&gt;&lt;br /&gt;What you have -- keys, badges, ID, passcards, tokens.&lt;br /&gt;    These are physical objects and go towards identifying you by what you physically *own*.  The obvious problem here is that objects can be taken and are not tied or "signed" to any particular person.  This makes it easy to loan your verification for temporary uses like valet parking, but objects can be stolen.  Keys can be duplicated, IDs can be faked, and nobody knows what the heck a valid badge looks like anyway.&lt;br /&gt;How many FBI badges or CIA ID cards have you seen?  How would you know if it's real?&lt;br /&gt;&lt;br /&gt;What you are, your DNA, fingerprints, voice match, cadence of your typing, your walk, talk, act.  Your smell, shoeprints, aura, your retinal scan, your vein patterns.  Anything that leaves the impression of YOU, but nothing that can come from someone else.  These are things that can be taken from you.  They cannot be faked but can be stolen.  Secondary level of security, What you are is better than what you have, but is nothing compared to what you know.&lt;br /&gt;&lt;br /&gt;What you know.  Passwords, passphrases.  Things that &lt;span style="font-style: italic;"&gt;cannot be beaten out of you&lt;/span&gt;.  Passwords cannot be compelled to be told, they cannot be stolen (from your mind), they cannot be duplicated.  Other examples include your memories. &lt;br /&gt;We've all thought about the time traveler trick.  Imagine yourself from the future convincing yourself now that you are really the future you.  You can name things that &lt;span style="font-style: italic;"&gt;only you could possibly know,&lt;/span&gt; such as your 2nd pet's name, the number of girls you've slept with, etc. &lt;br /&gt;Needless to say, this method of authentication is the most secure and the most unwieldly. &lt;br /&gt;&lt;br /&gt;In previous posts I discussed the UK woman who is being forced to reveal her decryption key.  Could this happen to you? &lt;br /&gt;&lt;br /&gt;Her door keys can be duplicated, her fingerprints can be stolen or coerced, but no court could make her, me, or you spell out your most secret passwords.  What you know is better than what you have or what you are.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-6940109144353987369?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/6940109144353987369/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=6940109144353987369' title='29 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/6940109144353987369'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/6940109144353987369'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/11/three-types-of-authentication.html' title='Three types of authentication.'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>29</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-3914980851396701326</id><published>2007-11-14T23:21:00.000-08:00</published><updated>2007-11-14T23:31:37.589-08:00</updated><title type='text'>UK Police Can Now Demand Encryption Keys</title><content type='html'>&lt;a href="http://www.lewrockwell.com/orig6/colmes1.html"&gt;Papiere Bitte&lt;/a&gt;.  UK Police can &lt;a href="http://www.schneier.com/blog/archives/2007/10/uk_police_can_n.html"&gt;demand your encryption keys&lt;/a&gt;, your passwords, presumably your PIN, and yo momma's maiden name.&lt;br /&gt;&lt;br /&gt;"Paper's please, citizen."  Those words ought to invoke fear in you.  We used to make fun of Soviet Russia where you needed internal passports.  But then we had the Red Scare, you could &lt;a href="http://en.wikipedia.org/wiki/Denial-of-service_attack"&gt;DoS&lt;/a&gt; a person.&lt;br /&gt;&lt;br /&gt;So now the UK has done it.  They are actually &lt;span style="font-weight: bold;"&gt;demanding you turn over your encryptionn keys.&lt;/span&gt;  On penalty of what?  2 yrs in jail. &lt;br /&gt;&lt;br /&gt;Lesson 1:  If your crime is punishable by more than 2 years in prison, tell them to pound sand.  You'll get off easier.&lt;br /&gt;Lesson 2:  If you don't like Susan up the street, plant an encrypted file on her and call the coppers.  She can't give them the key for what she doesn't know she has.  2 years of no more Susan.  Denial of Service of life.&lt;br /&gt;&lt;br /&gt;Lesson 3: The government &lt;span style="font-style: italic;"&gt;can't crack our encryption&lt;/span&gt;, otherwise they'd not bother forcing the keys out of us.  A rather enlightening admission don't you think?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-3914980851396701326?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/3914980851396701326/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=3914980851396701326' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/3914980851396701326'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/3914980851396701326'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/11/uk-police-can-now-demand-encryption.html' title='UK Police Can Now Demand Encryption Keys'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-3911274056064261185</id><published>2007-11-14T23:14:00.001-08:00</published><updated>2007-11-14T23:21:02.022-08:00</updated><title type='text'>Denial of Service</title><content type='html'>I'm sure you heard about the angry father-in-law who &lt;a href="http://www.schneier.com/blog/archives/2007/11/modernday_reven.html"&gt;sent an email to DHS &lt;/a&gt;to prevent his son-in-law from visiting the USA.  The son-in-law was held for over 12 hours and &lt;a href="http://news.yahoo.com/s/afp/20071102/od_afp/swedenjusticeterrorismoffbeat_071102124748;_ylt=Ah8e3WCMqHLBJaArTqoWc2is0NUE"&gt;sent back to Sweden, home of lutefisk and terrorists&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"The man, who admitted sending the email, said he did not think the US authorities would stupid enough to believe him."&lt;/span&gt;  Dear God, never underestimate the stupidity of petty dictators!&lt;br /&gt;&lt;br /&gt;Denial of Service.  Against a guy.  For an entire country.  Impressive.&lt;br /&gt;&lt;br /&gt;Next post up, we see another example.  (Hint, turning in your neighbors as Secret Commies is also a form of DoS.)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-3911274056064261185?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/3911274056064261185/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=3911274056064261185' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/3911274056064261185'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/3911274056064261185'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/11/denial-of-service.html' title='Denial of Service'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-3744253774825754607</id><published>2007-11-08T18:47:00.001-08:00</published><updated>2007-11-08T18:52:17.491-08:00</updated><title type='text'>Cracking shareware on OSX, for the lazy</title><content type='html'>Now you've installed Leopard, and you need to update all your little shareware utils.  Normally you just grab the latest serial from &lt;a href="http://www.serialz.to"&gt;serialz.to&lt;/a&gt; (get the excellent program &lt;a href="http://www.serialz.to/serialbox.html"&gt;iSerial Reader&lt;/a&gt; which comes with monthly updated databases of serials).&lt;br /&gt;&lt;br /&gt;But why go through the trouble to find old versions of software when you can crack OSX shareware yourself.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://lipidity.com/apple/shareware-licensing-techniques/"&gt;Cracking OSX shareware for the lazy.&lt;/a&gt;  Now you can spend your time telling yourself whatever it takes to get to sleep at night because you cheaped out on $10 shareware for a starving author.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-3744253774825754607?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/3744253774825754607/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=3744253774825754607' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/3744253774825754607'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/3744253774825754607'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/11/cracking-shareware-on-osx-for-lazy.html' title='Cracking shareware on OSX, for the lazy'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-4129506570543215931</id><published>2007-11-03T18:11:00.000-07:00</published><updated>2007-11-03T18:28:49.608-07:00</updated><title type='text'>Sparsebundle</title><content type='html'>Leopard includes a new type of file image called a "Sparsebundle".  How is this different from a sparseimage? What is it used for?  I'm sure someone at Apple knows, but the googlesphere doesn't seem to be doing much good.  Here's what I've learned:&lt;br /&gt;&lt;br /&gt;Sparsebundle images are like Sparseimages except they are made up of "bands".&lt;br /&gt;Sparsebundles are used by Filevault in Leopard and help with Time Machine backups.&lt;br /&gt;Bands have individual 8Mb chunks.  Time machine will only back up &lt;a href="http://episteme.arstechnica.com/eve/forums/a/tpc/f/8300945231/m/291006128831"&gt;&lt;span style="font-style: italic;"&gt;chunks that have changed&lt;/span&gt;&lt;/a&gt;. &lt;br /&gt;Sparsebundles are actually directories, you can look in them to see the data structure.  &lt;a href="http://themachackers.com/2006/12/20/filevault-doesnt-use-sparse-images-anymore/"&gt;Here is what you see.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is why Time Machine has to log out to back up your Filevaulted Users directory.  However, it is a huge bonus because otherwise, if you changed a single byte while logged in, your previous filevault structure would have changed the attributes of the &lt;span style="font-style: italic;"&gt;Entire Ginormous Sparseimage&lt;/span&gt;, which would then take hours for Time Machine to back up.&lt;br /&gt;&lt;br /&gt;Now using Sparsebundles, you log out, and Time Machine looks at the meta-data for the chunks that have changed and only backs up those.  Also, the Time Machine backup was supposed to be encrypted, this support seems to have been dropped.  But since your sparsebundle is copied whole, filevaulted users are safe.  You non-filevault using people are leaving usb drives full of your data all over the place though.  Beware.&lt;br /&gt;This appears to be a stopgap measure before&lt;a href="http://en.wikipedia.org/wiki/ZFS"&gt; ZFS&lt;/a&gt; is fully implemented.  &lt;a href="http://www.tech-recipes.com/rx/1446/zfs_ten_reasons_to_reformat_your_hard_drives"&gt;Use ZFS peoples&lt;/a&gt;.  It has snapshots and pools.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-4129506570543215931?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/4129506570543215931/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=4129506570543215931' title='70 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/4129506570543215931'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/4129506570543215931'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/11/sparsebundle.html' title='Sparsebundle'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>70</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-9043246814310711569</id><published>2007-11-01T20:49:00.000-07:00</published><updated>2007-11-01T21:00:55.333-07:00</updated><title type='text'>The War on the Unexpected</title><content type='html'>"We've opened up a new front on the war on terror. It's an attack on the unique, the unorthodox, the unexpected; it's a war on different. If you act different, you might find yourself investigated, questioned, and even arrested -- even if you did nothing wrong, and had no intention of doing anything wrong."&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.schneier.com/blog/archives/2007/11/the_war_on_the.html"&gt;Read Bruce Schneier's excellent essay.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Be afraid, be normal, "Live free or Die!" does not seem to be the prevailing wisdom today.  Wimps.  As usual Bruce tears up the baby-coddled thinking of the terror-mongers.  The people who advocate this style of followership are the children of the "Greatest Generation"?&lt;br /&gt;&lt;br /&gt;I'm a Gen-X'er myself and I have to say, piss poor show fellows, piss poor.&lt;br /&gt;I know the Boomers are scared of death and scared of non-conformity, and have nothing to live for but life itself, but grow a backbone.  Don't let the &lt;a href="http://www.boston.com/news/local/articles/2007/02/01/marketing_gambit_exposes_a_wide_generation_gap/"&gt;blikenlights&lt;/a&gt; scare you!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"Of course, by then it's too late for the authorities to admit that they made a mistake and overreacted, that a sane voice of reason at some level should have prevailed. What follows is the parade of police and elected officials praising each other for doing a great job, and prosecuting the poor victim -- the person who was different in the first place -- for having the temerity to try to trick them."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Damn you Boomers for giving away MY freedoms and for setting us on this &lt;a href="http://en.wikipedia.org/wiki/Authoritarian"&gt;authoritarian&lt;/a&gt; course.  Now we gotta fight.&lt;br /&gt;&lt;br /&gt;ultratoast&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-9043246814310711569?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/9043246814310711569/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=9043246814310711569' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/9043246814310711569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/9043246814310711569'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/11/war-on-unexpected.html' title='The War on the Unexpected'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-1913681927271349063</id><published>2007-10-28T19:43:00.000-07:00</published><updated>2007-10-28T20:04:02.664-07:00</updated><title type='text'>Fighting the petty dictators</title><content type='html'>Authoritarianism is rampant in our society.  Just last week I ran into at least 3 petty dictators.  This can be anything from the local "Officer Friendly" telling you to "Move along", to bureaucratic government office secretaries guarding their tin-pot dictatorships with utter contempt for outsiders.&lt;br /&gt;&lt;br /&gt;Hierarchy is everything to these petty people.  Big Fish, Small Pond.  But you must deal with them and it can be exasperating.  Think DMV writ large. &lt;br /&gt;&lt;br /&gt;I'll be discussing how to subvert the &lt;a href="http://en.wikipedia.org/wiki/Panopticon"&gt;Panopticon&lt;/a&gt; society for our ends.  Points to ponder in a future post are:&lt;br /&gt;1) The universal surveillance is ineffective for The Man, as no one is watching, and it acts to protect the system. &lt;br /&gt;2a) We value government transparency and personal privacy.  The government values government privacy and personal transparency.&lt;br /&gt;2b) We want to keep our secrets, while the government wants to see them, and vice versa.&lt;br /&gt;3) They can monitor the public spaces, even take your data, but we cannot effectively do this to them.&lt;br /&gt;&lt;br /&gt;Dictators small and large hate spotlights.  Atrocities are carried out in the dark, people are "disappeared."  The way to combat petty abuses of petty power are the same as to combat great abuses of great power.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;You will never win by complaining.  You are doomed to pointlessness.  There is nothing you can do to make the departmental secretary to care.  She was there before you and she'll be there after you and she'll do nothing to help you.  If you annoy her, she will make your life miserable.&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://video.google.com/videoplay?docid=-2715792117793977759&amp;amp;"&gt;Here is how you fight back.&lt;/a&gt;  Cops will lie and threaten.  &lt;a href="http://consumerist.com/consumer/travel/ata-tries-to-have-you-arrested-for-using-your-iphone-in-airplane-mode-309421.php"&gt;Flight attendants will make up rules and lie to you.&lt;/a&gt;  "Because I said so" works for mom, but not for these little nuts.  What you need is to spy on yourself.  Record everything.  Then you have a backup.&lt;br /&gt;Cops hate photographers, unfortunately for them,&lt;br /&gt; &lt;a href="http://www.krages.com/ThePhotographersRight.pdf"&gt;photographers have rights.&lt;/a&gt; (carry this on your person)&lt;span style="font-style: italic;"&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;There&lt;span style="font-style: italic;"&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-style: italic;"&gt; are &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;lots of reasons to record everything in your life, besides just happening to have some crucial evidence to redeem yourself if you are threatened.  In years to come, you may wish to recall conversations you had with others, perhaps after a death your records would console loved ones.  Perhaps someone you associate with will become famous.  Perhaps you yourself will want to hear what you sounded like as a young man or lady in 30 years time.  Think of recordings of your mother and how they are precious to you.&lt;br /&gt;&lt;br /&gt;Setting this up to be painless is easier than you might think.  I'll have a simple post soon detailing equipment.&lt;br /&gt;&lt;br /&gt;ultratoast&lt;span style="font-style: italic;"&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-1913681927271349063?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/1913681927271349063/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=1913681927271349063' title='21 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/1913681927271349063'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/1913681927271349063'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/10/fighting-petty-dictators.html' title='Fighting the petty dictators'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>21</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-904484821208348074</id><published>2007-10-23T19:52:00.000-07:00</published><updated>2007-10-23T20:03:02.927-07:00</updated><title type='text'>Comedy Computer Security</title><content type='html'>Leopard is coming out this week and has all kinds of great cryptic features that are security related.  But when you want to find a good place to eat, find a fat person and follow him.  In that spirit, I give you the &lt;a href="http://www.encyclopediadramatica.com"&gt;Encyclopedia Dramatica&lt;/a&gt;'s take on security.&lt;br /&gt;&lt;br /&gt;"Security is a broad generalization; a meme of sorts used by the government, which means absolutely nothing. Security is often found at nightclubs, government establishments, and Jesus factories, but is never found on the internet."&lt;br /&gt;&lt;br /&gt;Moar soon!&lt;br /&gt;&lt;br /&gt;"&lt;a href="http://www.encyclopediadramatica.com/They"&gt;They&lt;/a&gt; is perhaps the smartest person ever, and the perfect person to cite in an argument." omg pwniez&lt;br /&gt;&lt;br /&gt;&lt;a href="http://icanhascheezburger.com/2007/05/01/09-f9-11-02-9d-74-e3-5b/"&gt;&lt;img src="http://icanhascheezburger.files.wordpress.com/2007/05/8a93c570-4ead-4477-bcbe-e4b2472479cc1.jpg" alt="09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-904484821208348074?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/904484821208348074/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=904484821208348074' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/904484821208348074'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/904484821208348074'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/10/comedy-computer-security.html' title='Comedy Computer Security'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-6354315631948365565</id><published>2007-10-17T23:41:00.000-07:00</published><updated>2007-10-17T23:46:34.477-07:00</updated><title type='text'>Kibo is my hero</title><content type='html'>&lt;a href="http://en.wikipedia.org/wiki/Kibo"&gt;Kibo is a genius.&lt;/a&gt;   Grepping the entire Usenet feed for your name so that you can reply and appear everywhere at once.  Legendary.&lt;br /&gt;&lt;br /&gt;Next post will involve us listening to the radio waves that go through our houses.  I didn't ask for them to send signals to my living room, don't complain when we listen to them! &lt;br /&gt;&lt;br /&gt;I have a kibo number.  It is lower than yours.  Weep.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-6354315631948365565?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/6354315631948365565/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=6354315631948365565' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/6354315631948365565'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/6354315631948365565'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/10/kibo-is-my-hero.html' title='Kibo is my hero'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-3289677459282560433</id><published>2007-10-17T22:17:00.001-07:00</published><updated>2007-10-17T22:31:34.606-07:00</updated><title type='text'>More stolen laptops with personal information</title><content type='html'>Once again some laptops have been stolen which contain lots of personal information.  &lt;a href="http://www.eweek.com/article2/0,1895,2199122,00.asp"&gt;The solution by the TSA is to require encryption&lt;/a&gt;.  Perhaps they were just trying to keep up with the data loss experts here in the state of Louisiana where our LOFSA organization who recently &lt;a href="http://media.www.lsureveille.com/media/storage/paper868/news/2007/10/17/News/Security.Of.Fafsa.Tops.Compromised-3036961.shtml"&gt;lost thousands of student records&lt;/a&gt; and &lt;span style="font-style: italic;"&gt;financial information&lt;/span&gt;.  Incredible.  And in a stunning display of stupidity, LOFSA decided to &lt;a href="http://www.2theadvocate.com/news/10624752.html"&gt;&lt;span style="font-weight: bold;"&gt;wait for weeks to tell us.&lt;/span&gt;&lt;/a&gt;  Because, you know.. this isn't time sensitive or anything. &lt;br /&gt;&lt;br /&gt;Bruce Schneier and other security gurus have written extensively about the false security of companies and organizations who fail to notify their customers, and the &lt;a href="http://consumerist.com"&gt;Consumerist.com&lt;/a&gt; regularly exposes companies trying to hide their ineptitude.   The only solution to data theft is the same as the solution to the Tylenol product tampering case.  Massive overwhelming immediate disclosure and response.  Johnson &amp;amp; Johnson, to their credit, did not try to PR their way out of that mess.  They knew there was only one way to save the company after millions of customers now feared their products, overwhelming action.  Millions were spent to recall and destroy existing stocks of tylenol, and the company, this is key, *wanted you to know*. &lt;br /&gt;&lt;br /&gt;LOFSA could have bought credibility by immediate disclosure and reassurance that they were doing everything to protect us, but they decided to try to hide.  The TSA keeps losing laptops and reacts rather than pro-actively protects. &lt;br /&gt;&lt;br /&gt;What does this have to do with you?  Encrypt &lt;a href="http://www.apple.com/macosx/features/filevault/"&gt;YOUR laptop&lt;/a&gt;, YOUR data.  If it's bad enough for thieves to get your name and identity, imagine how bad it would be if they got your whole laptop.  &lt;a href="http://unisec.blogspot.com/2007/09/nsas-guide-to-securing-mac-os-x-104.html"&gt;Encrypt today!&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-3289677459282560433?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/3289677459282560433/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=3289677459282560433' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/3289677459282560433'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/3289677459282560433'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/10/more-stolen-laptops-with-personal.html' title='More stolen laptops with personal information'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-6435180995047713637</id><published>2007-10-16T18:48:00.000-07:00</published><updated>2007-10-16T19:03:36.623-07:00</updated><title type='text'>What's in your "permanent record"</title><content type='html'>Remember that time that Mrs. Grumbly caught you putting crayons up your nose and threated to put it in your &lt;ominous&gt; &lt;span style="font-style: italic;"&gt;permanent file&lt;/span&gt;... OOOOOOOOHHH NOOOO!  Where did you think she was sending it?  That's right.  The FBI, NSA, CIA, DHL, DDF, NAACP, and NAFTA.  They *all* have a dossier on you, citizen. &lt;br /&gt;A few weeks ago I sent in my request for my &lt;a href="http://www.unsecureflight.com/request.html"&gt;DHS Travel Dossier&lt;/a&gt; (you didn't think it was really a "dossier" did you? eh? EH?! you betcha... good german.)  Recently I've traveled quite a bit and according to my passport's electronic codes, I'm 129 years old, and no one noticed this, through like 7 countries and numerous airports.  But I *did* remove my shoes, and liquids.  I'm dying to know what they actually bothered to track about me, since my age was of no importance.  Also, requesting your documents is basically free and takes about 10 minutes, no notary.  UnsecureFlight.com hosts the "&lt;b&gt;ATS Privacy Act Records Request" &lt;/b&gt;and the accompanying release form.&lt;br /&gt;&lt;br /&gt;Now &lt;a href="http://boingboing.net/"&gt;BoingBoing&lt;/a&gt; has post on &lt;a href="http://www.boingboing.net/2007/10/16/get-your-fbi-file-an.html"&gt;getting your FBI file&lt;/a&gt;, neat!  I can't wait to see what's in mine, and also to waste some bureaucrat's time.  It's called &lt;a href="http://www.getmyfbifile.com/"&gt;getmyfbifile.com&lt;/a&gt;, here's what BoingBoing says, "This site helps you automatically generate the letters you need to send in to get your own FBI file ... and while you're at it, you can also get your NSA, CIA, DIA, DSS, Secret Service, etc. files too, just by checking a few boxes."  I'm so excited, I want to cross-dress just so I get data-mined with J. Edgar Hoover.  I'll update the blog with my results when they arrive.&lt;br /&gt;&lt;br /&gt;Anecdote, I heard a story about a girl who applied to be a whitehouse intern and was questioned about having joined the "Objectivist club," which meant she had filled out a card on the back of an Ayn Rand novel and that somehow put her on a list!  Imagine what kind of lists YOU'RE on!    (This is another reason I've legally changed my name to "Void", just to screw up check cashing). &lt;br /&gt;&lt;br /&gt;&lt;a href="http://xkcd.com/327/"&gt;This is how you seriously destroy the government.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-6435180995047713637?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/6435180995047713637/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=6435180995047713637' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/6435180995047713637'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/6435180995047713637'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/10/whats-in-your-permanent-record.html' title='What&apos;s in your &quot;permanent record&quot;'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-3651662734212362120</id><published>2007-10-14T18:46:00.001-07:00</published><updated>2007-10-14T19:08:31.547-07:00</updated><title type='text'>HIDS or, screw the NSA! Host-based intrusion detection</title><content type='html'>You've secured your laptop now, according to best practices.  You have turned on FileVault disk encryption, turned off unnessary services, disabled automatic login, etc.&lt;br /&gt;Now the bastards have to come after you the old fashioned way, they have to &lt;a href="http://www.penny-arcade.com/comic/2007/07/16"&gt;penetrate your code walls and steal your internets&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;"But how can the dastardly FBI, NSA, DHL, Section 8 bastards break my code walls?" you ask.  Easily.  You are running multiple programs which phone home all the time and connect to other computers through sometimes lousy protocols or implementations.  That Weatherbug may be more of a bug than you realize.  First step is to run &lt;a href="http://www.obdev.at/products/littlesnitch/index.html"&gt;Little Snitch&lt;/a&gt;,  which  will tell you when applications connect to the net and give you the opportunity to deny them temporarily or permanently.  Next run nmap on yourself to make sure you only have approved ports open.  Now you've done your due diligence, but The Man won't give up!&lt;br /&gt;&lt;br /&gt;You need a HIDS, a &lt;a href="http://en.wikipedia.org/wiki/Host-based_intrusion_detection_system"&gt;Host-based Intrusion Detection System&lt;/a&gt;.  This kind of program will scan your machine and make sure that you haven't been pwned, running root-kits, badware, keyloggers or other garbage that the G-men (or romanian script-kiddies) would use to monitor you.  Think it can't happen?  There was  a recent case where a mafioso was busted even though he used all kinds of crazy encryption on his machine.  They used a &lt;a href="http://www.alternet.org/story/11854/"&gt;sneak-and-peak warrant&lt;/a&gt; to sneak in his house and install some nosey-ware into his machine and then watched him for *months*!!!  He'd have been better off if he was checking for file modifications.  Don't think your mighty encryption will stop them.  This ties into the above best practices by disallowing automatic login, etc.  But remember, if they have physical access to your machine, life gets much more difficult.&lt;br /&gt;We'll cover how to defeat more advanced monitoring techniques in future posts.  Remember, if they cannot just boot your machine and read it, they'll have no choice but to resort to more expensive/difficult and less effective techniques.  Our goal is to get them to the point of using &lt;a href="http://eckbox.sourceforge.net/"&gt;Van Eck Phreaking &lt;/a&gt;and having goatse as your screensaver.  Heh.&lt;br /&gt;&lt;br /&gt;Read this &lt;a href="http://www.infoanarchy.org/en/Intrusive_Surveillance"&gt;infoarnarchy article on methods of intrusive surveillance.&lt;/a&gt;  If my job was to steal your data, this is the manual I would follow.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-3651662734212362120?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/3651662734212362120/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=3651662734212362120' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/3651662734212362120'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/3651662734212362120'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/10/hids-or-screw-nsa-host-based-intrusion.html' title='HIDS or, screw the NSA! Host-based intrusion detection'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-132227288182593046</id><published>2007-10-12T20:55:00.000-07:00</published><updated>2007-10-12T21:11:08.233-07:00</updated><title type='text'>Sign Sign, Everywhere a Sign</title><content type='html'>My next project is in the style of &lt;a href="http://www.telstarlogistics.com/"&gt;Telstar Logistics&lt;/a&gt;, i.e. Urban Camouflage, or social engineering.&lt;br /&gt;"One day, I had an epiphany -- if I disguised the van to look like a work vehicle, I'd be able to park in yellow-curb zones without getting parking tickets. "&lt;br /&gt;People love signs, especially low wage, rules-oriented mindless zombies.  These people can be found everywhere such as DMVs, utility companies, airports, and especially universities.  You can tell you're dealing with someone who values rules over reason if the conversation goes something like this:&lt;br /&gt;"Hi, I'd like to do X"&lt;br /&gt;"I'm sorry, sir, you can't do X"&lt;br /&gt;"Why not?"&lt;br /&gt;"It's policy"&lt;br /&gt;"Who has the authorization to override this?"&lt;br /&gt;"It's &lt;span style="font-style: italic;"&gt;policy&lt;/span&gt;"&lt;br /&gt;... as though that is the final answer.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.obeygiant.com/main_new.php?page=articles"&gt;OBEY!  (corporate phenomenology, I'm sure you've seen these stickers)&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;Anyhow, let's mess with these people.  Around LSU you will often see little yellow laminated signs stapled to sticks in front of random parking spots that say "Reserved for ####, good for &lt;date&gt; TOWING ENFORCED".  No one ever parks in front of them.&lt;br /&gt;The other day I went to school and saw a plastic sign in front of some spots that simply said "No Parking", and sure enough, no one parked there.  I knew there was no event or anything, and the parking nazis never question their bosses or consult reason so these signs tend to stay.  The next day, the sign was still there and still no one parked there... so I did.  And then I kicked over the sign.  When I got back  to my car, I had no ticket and the sign was gone!&lt;br /&gt;So now I've made my own laminated sign on a stick and I'll keep it in my trunk and park wherever I feel like.&lt;br /&gt;Some people said, "but that's illegal!"  Huh? Not unless you want to count it as littering.  It's not my fault if other people listen to my signs!  Freedom of speech baby!&lt;br /&gt;Pics coming soon.&lt;/date&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-132227288182593046?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/132227288182593046/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=132227288182593046' title='43 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/132227288182593046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/132227288182593046'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/10/sign-sign-everywhere-sign.html' title='Sign Sign, Everywhere a Sign'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>43</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-1243941471630337161</id><published>2007-10-07T17:23:00.000-07:00</published><updated>2007-10-07T17:36:54.091-07:00</updated><title type='text'>Parking meters, or "mini-atms"</title><content type='html'>If I were homeless, I would spend all my spare time figuring out how to get into parking meters instead of bothering people for spare change.  I mean look around!  There's little boxes of money ($30-60 according to sources) spaced every 10 feet damned near everywhere in major cities.&lt;br /&gt;Why bum when you can surreptitiously slide in a &lt;a href="http://www.scribd.com/doc/3635/ebook-illustrated-secrets-of-lockpicking"&gt;home made rake and tension wrench&lt;/a&gt; into a parking meter and walk off with lunch, dinner, a pack of smokes *AND* some Thunderbird money.&lt;br /&gt;&lt;br /&gt;The parking meters around here are manufactured by Duncan parking meter company and use quarters.  There's probably a large number with no cameras, and if you time your attack to vary meters on varying days, or even just leave &lt;span style="font-style: italic;"&gt;some change&lt;/span&gt; in each one, you'd likely never get caught.&lt;br /&gt;&lt;a href="http://www.westminster.gov.uk/councilgovernmentanddemocracy/councils/pressoffice/news/pr-3566.cfm"&gt;&lt;br /&gt;These guys got greedy. &lt;/a&gt; Besides, why use an angle grinder?  That just alerts the meter maids to your presence.  The keys on these meters are generally very short 5 pin models, not tubular, very easy to pick even for a novice. &lt;br /&gt;&lt;br /&gt;Everyone robs ATMs because "that's where the money is."  Teenagers spend countless hours trying to defeat vending machines (my personal favorite was to smash nickels until they are the size of quarters). &lt;br /&gt;&lt;br /&gt;Next time you need laundry money and you realize you just dropped $.50 into the meter, think about it...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-1243941471630337161?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/1243941471630337161/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=1243941471630337161' title='53 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/1243941471630337161'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/1243941471630337161'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/10/parking-meters-or-mini-atms.html' title='Parking meters, or &quot;mini-atms&quot;'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>53</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-6198745711277834254</id><published>2007-09-27T22:37:00.000-07:00</published><updated>2007-09-27T23:00:20.565-07:00</updated><title type='text'>AWID and LSU, parking hacking</title><content type='html'>Recently Louisiana State University started up a program called &lt;a href="http://appl003.lsu.edu/PubSafety/lsuparking.nsf/$Content/Easy+Streets?OpenDocument"&gt;"Easy Streets"&lt;/a&gt; which cuts off students or general traffic from using any streets that pass through the university campus.  They are using lifting barriers and RFID detectors made by &lt;a href="http://www.awid.com/"&gt;AWID &lt;/a&gt;(Applied Wireless IDentification).  I haven't quite figured out a way to bypass the RFID system yet so I am looking for your help.  Here's what I've learned so far:&lt;br /&gt;&lt;br /&gt;1) The readers are model &lt;a href="http://www.fastaccesssecurity.com/proddetail.asp?prod=AW-LR-911"&gt;LR-911&lt;/a&gt; units.  This design has been in production for a number of years and probably has backend software from &lt;a href="http://www.ianywhere.com/products/rfid_embedded_technologies.html"&gt;iAnywhere&lt;/a&gt;.  The benefit of this is that iAnywhere supports a billion protocols and basically no encryption.  The drawback is finding out how to access this functionality.&lt;br /&gt;&lt;span style="font-size:78%;"&gt;"RFID Anywhere Appliance Edition"&lt;br /&gt;supports TCP/IP, HTTP and the EPC reader protocol. It also adds security functions, software for configuring the readers remotely from a Web browser and an application programming interface for executing business logic on the reader itself."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;2) The wand is given to each member of the faculty or staff who has access to park on our precious streets and mow down pedestrians (aka, the people who pay them).  The model of the wand is the &lt;a href="http://awid.com/solutions/detail.aspx?id=MTAyOQ==&amp;amp;product=MTAxOQ=="&gt;"MT tag"&lt;/a&gt;, and it the system operates on the 900-928 Mhz unlicensed band, from a distance of ~5 meters.&lt;br /&gt;&lt;br /&gt;3) Here are the&lt;a href="http://cq.cx/verichip.pl"&gt; instuctions on cloning a verichip&lt;/a&gt;, with code and blueprints ready to go.  While Bruce Schneier &lt;a href="http://www.schneier.com/blog/archives/2006/08/hackers_clone_r.html"&gt;discusses cloning a US Passport&lt;/a&gt; and how it's done.  &lt;a href="http://cq.cx/vchdiy.pl"&gt;This is the home-made kit to clone a verichip,&lt;/a&gt; all that should be required is a different number of wraps for the antenna.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;4) Make.org has &lt;a href="http://www.makezine.com/blog/archive/2006/01/doityourself_rfid_projects_wit.html"&gt;tons of info on projects&lt;/a&gt; to play with RFID, and there are kits with readers and tags available but they all seem to focus on the 14khz spectrum (only good for inches away), and not the relatively uncommon 900Mhz band.&lt;br /&gt;&lt;br /&gt;This RFID system is basically unencrypted and requires no handshake or verification.  It is also quite likely that part of the tag is writable and that a blank tag ($15) could be cloned.  The technology is virtually identical to Verichip except for using the 900Mhz range instead of 14khz.  Tools written for cloning Verichips and US Passports *should* be able to clone these chips also, except that building such tools is too time-consuming and difficult for me, and I cannot find a cheap source for a chip reader/writer.&lt;br /&gt;&lt;br /&gt;My next idea involves bypassing verification altogether and perhaps activating the induction loop for the exit side, however that could get me in trouble if i'm spotted going in the "out" door and would only be good for parking lot access, not general travel.  Please send ideas in the comments.  I'll add more as I get time to do more research.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-6198745711277834254?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/6198745711277834254/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=6198745711277834254' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/6198745711277834254'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/6198745711277834254'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/09/awid-and-lsu-parking-hacking.html' title='AWID and LSU, parking hacking'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-3028538876631665757</id><published>2007-09-27T21:38:00.000-07:00</published><updated>2007-09-27T21:45:15.734-07:00</updated><title type='text'>Cryptome, or how to piss off the CIA</title><content type='html'>&lt;a href="http://www.radaronline.com/from-the-magazine/2007/08/cryptome_john_young_radar_anthony_haden_guest_1.php"&gt;This guy is crazy&lt;/a&gt;.  John Young runs &lt;a href="http://www.cryptome.org"&gt;Cryptome.org&lt;/a&gt; which is a fantastic repository of questionable documents.  It's where you go to find the &lt;a href="http://cryptome.org/cia-deep-cover.zip"&gt;CIA's manual for staying in deep cover&lt;/a&gt; or the names of spies, or obscure government documents that many people would rather we not access.&lt;br /&gt;&lt;br /&gt;All paranoid people should keep an eye on this site.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-3028538876631665757?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/3028538876631665757/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=3028538876631665757' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/3028538876631665757'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/3028538876631665757'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/09/cryptome-or-how-to-piss-off-cia.html' title='Cryptome, or how to piss off the CIA'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-5656483084555547301</id><published>2007-09-23T16:26:00.000-07:00</published><updated>2007-09-23T16:30:41.696-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><title type='text'>NSA's Guide to Securing Mac OS X 10.4 Tiger</title><content type='html'>Just a quick update.  Here is Apple's own guide for securing a machine running Tiger.  Endorsed by the NSA, if it's good enough for them, it's good enough for you!&lt;br /&gt;&lt;a href="http://images.apple.com/server/pdfs/Tiger_Security_Config_021507.pdf"&gt;http://images.apple.com/server/pdfs/Tiger_Security_Config_021507.pdf&lt;/a&gt;&lt;br /&gt;Good bedtime reading for comprehensive security practices&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-5656483084555547301?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/5656483084555547301/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=5656483084555547301' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/5656483084555547301'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/5656483084555547301'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/09/nsas-guide-to-securing-mac-os-x-104.html' title='NSA&apos;s Guide to Securing Mac OS X 10.4 Tiger'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-2477376613601836814</id><published>2007-09-22T19:30:00.000-07:00</published><updated>2007-09-22T20:09:22.430-07:00</updated><title type='text'>Mac laptop stolen at the coffee shop</title><content type='html'>No, my laptop wasn't stolen, but &lt;a href="http://www.orbicule.com/undercover/nc.html"&gt;here's an interesting tale of recovery &lt;/a&gt;of one that was.  Now this is an unabashedly mac-centric site so the following guide is focused on some OS X based tools, but there are &lt;a href="http://en.wikipedia.org/wiki/Encrypting_File_System"&gt;linux versions&lt;/a&gt; and &lt;a href="http://technet.microsoft.com/en-us/library/bb457065.aspx"&gt;windows versions &lt;/a&gt;of several of these techniques.&lt;br /&gt;&lt;br /&gt;Being a mobile laptop user is wonderful, but having your laptop walk off is a heart dropping experience, not so much for the lost hardware but for the data you've got on it.  And not so much for losing the data (you are making &lt;a href="http://www.bombich.com/software/ccc.html"&gt;daily backups&lt;/a&gt; right?) but for the &lt;b&gt;thieve's access&lt;/b&gt; to it.  If you're super-paranoid, you might even worry if it wasn't a gov't &lt;a href="http://en.wikipedia.org/wiki/Black_bag_operation"&gt;black bag job&lt;/a&gt;.&lt;br /&gt;Coffee shops and college campuses are great places to steal things.  People are complacent because they consider it "their space" and forget the scale of openness.  These places have an extremely high turnover of people all of whom "look like they belong".  How do you make sure they can't see those special pictures you have stored on your machine?  Encryption and lots of it!&lt;br /&gt;&lt;br /&gt;1) First of all, turn on your screen saver password.&lt;br /&gt;2) Turn on "Require password to wake this computer from sleep or screen saver" in your Preferences -&gt; Security window.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_yJtDj8W6PjY/RvXWIq1ZfCI/AAAAAAAAAAU/u65wV6DuCLs/s1600-h/securepref.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_yJtDj8W6PjY/RvXWIq1ZfCI/AAAAAAAAAAU/u65wV6DuCLs/s320/securepref.jpg" alt="" id="BLOGGER_PHOTO_ID_5113228396374621218" border="0" /&gt;&lt;/a&gt;Your mega-super-encryption will not save you if I close your laptop, walk off with it, and plug it into a usb drive at my leisure.  I have complete access.&lt;br /&gt;&lt;br /&gt;What happens here is, they close your laptop, walk off with it, and are confronted with a password when they open it up to look at your stuff.  Their only option is to then reboot the machine, but aha!  You've also enabled "Disable automatic login" so that they must still enter a password if it is rebooted.&lt;br /&gt;&lt;br /&gt;I leave the IR function disabled because I don't want someone to figure out a way to use FrontRow or the relatively obsure IR protocols to bypass my screensaver password.  As for secure virtual memory, i'm just not that paranoid yet.  All RAM gets wiped after each reboot so they would have to know &lt;i&gt;in advance&lt;/i&gt; that I had done all this and not to restart the machine, *then* still have to figure out a way to dump the contents of RAM somewhere readable.  That is an unlikely scenario.&lt;br /&gt;&lt;br /&gt;For the same reason, I don't click "Require Password for each secure system preference" since I am the only user on this machine and if they get that far, I'm already &lt;b&gt;toast&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;3)  Turn on File Vault.  &lt;a href="http://discussions.apple.com/thread.jspa?threadID=1142259"&gt;Yes, it's scary&lt;/a&gt;.  However it is very careful to verify everything and there seems to be no speed loss.  What this does is prevent the attacker from just pulling your harddrive and putting it into another machine or usb enclosure and just reading all your data.  For this reason, &lt;a href="http://docs.info.apple.com/article.html?artnum=106482"&gt;Open Firmware Passwords&lt;/a&gt; are basically useless.  The computer is a husk that accesses a hard drive.  Why bother with trying to crack a bios password when you can just rip the drive out of it?  Does this happen?  You betcha!  &lt;a href="http://www.news.com/Skeletons-on-your-hard-drive/2100-1029_3-5676995.html"&gt;Here's tons of stories&lt;/a&gt; about &lt;a href="http://www.news.com/Laptop-theft-puts-data-of-98%2C000-at-risk/2100-1029_3-5645362.html"&gt;data recovered off of drives&lt;/a&gt; sold on ebay.&lt;br /&gt;&lt;br /&gt;Now your data is much safer.  If someone steals your laptop, at best they'll have to reformat the drive, and at worst, they'll end up with a brick of harddrive that contains a &lt;a href="http://en.wikipedia.org/wiki/Sparse_disk_image"&gt;sparseimage&lt;/a&gt; of encrypted garbage.&lt;br /&gt;&lt;br /&gt;The government could spend *years* and never recover your data.  This gives you plausible deniability, which we will discuss in a future post.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-2477376613601836814?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/2477376613601836814/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=2477376613601836814' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/2477376613601836814'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/2477376613601836814'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/09/mac-laptop-stolen-at-coffee-shop.html' title='Mac laptop stolen at the coffee shop'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_yJtDj8W6PjY/RvXWIq1ZfCI/AAAAAAAAAAU/u65wV6DuCLs/s72-c/securepref.jpg' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-5571310580533553107</id><published>2007-09-22T18:42:00.000-07:00</published><updated>2007-09-22T18:49:33.630-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='anonymity'/><title type='text'>Migrating to secure anonymity</title><content type='html'>It's too late!  You've posted on the internet with your real name.  You've posted your LiveSpaceJournalBook page with all your own details that future bosses can read.  You're trapped!  Now you're sitting around and you want to go to a forum and discuss unpopular ideas, but you don't want the NSA, FBI, bogeyman to find you or know it's you, or connect it to you at all.  How do you do this?&lt;br /&gt;&lt;br /&gt;Establish a separate identity that exists &lt;i&gt;only online&lt;/i&gt;.  The fact that you have an existing presence is a &lt;i&gt;good thing&lt;/i&gt;.  Remember that it would be mighty suspicious if you didn't have existing persona online.  Give "The Man" something to follow, give him a past, a present, a you.  Don't drop off the internet suddenly, continue posting your normal every day stuff, your fluffy dog page, your youtube videos, just don't let any of that be associated with your new &lt;b&gt;anonymous identity&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;I will be starting a series of posts of specific step-by-step instructions on how to give yourself an untraceable, secure connection and communications network to have at your disposal.  This is a guide.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-5571310580533553107?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/5571310580533553107/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=5571310580533553107' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/5571310580533553107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/5571310580533553107'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/09/migrating-to-secure-anonymity.html' title='Migrating to secure anonymity'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-2102200023243536204</id><published>2007-09-22T00:24:00.000-07:00</published><updated>2007-09-22T00:35:58.063-07:00</updated><title type='text'>Anonymous web browsing with Tor</title><content type='html'>&lt;span style="font-family: arial;"&gt;Today we will discuss Tor onion routing.  You are visiting a website but you need anonymity.  Perhaps you are looking up porn or whatever and you don't want your traffic being traced back to you.  Time for "Tor Onion Routing" found here http://tor.eff.org/&lt;br /&gt;&lt;br /&gt;The important thing to remember is that Anonymity is NOT EQUAL to encryption.  In other words, use Tor to hid your route, but remember, it encrypts nothing.  The remote sysadmin and the local sysadmin can still sniff and read all your traffic.  They just don't know where it is going to or coming from... unless you tell them in your messages.&lt;br /&gt;&lt;br /&gt;For Mozilla Firefox use &lt;a href="https://addons.mozilla.org/en-US/firefox/addon/2275"&gt;this plugin&lt;/a&gt; to add a button to your menu bar to enable Tor Onion Routing.&lt;br /&gt;Since you are using Mac OS X, use &lt;a href="http://vidalia-project.net/"&gt;Vidalia &lt;/a&gt;which is a graphical interface (GUI) to the Tor program. &lt;br /&gt;&lt;br /&gt;Now, start up Firefox and hit the torbutton and start surfing anonymously.&lt;br /&gt;You must read &lt;a href="http://www.schneier.com/blog/archives/2007/09/anonymity_and_t_1.html"&gt;Bruce Schneier's post regarding the difference between anonymity and privacy.&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-2102200023243536204?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/2102200023243536204/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=2102200023243536204' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/2102200023243536204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/2102200023243536204'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/09/anonymous-web-browsing-with-tor.html' title='Anonymous web browsing with Tor'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2582112902847616917.post-6864481908812520826</id><published>2007-09-22T00:18:00.000-07:00</published><updated>2007-09-22T00:21:08.858-07:00</updated><title type='text'>Let's break security!</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2582112902847616917-6864481908812520826?l=unisec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://unisec.blogspot.com/feeds/6864481908812520826/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2582112902847616917&amp;postID=6864481908812520826' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/6864481908812520826'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2582112902847616917/posts/default/6864481908812520826'/><link rel='alternate' type='text/html' href='http://unisec.blogspot.com/2007/09/lets-break-security.html' title='Let&apos;s break security!'/><author><name>ultra toast</name><uri>http://www.blogger.com/profile/16136709172404926374</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
