Cities, Disneyland, and Software Security

Cities, Disneyland, and Software Security

| | assurance, flaws, risks, security
I like to think of our modern software infrastructure as being like a large city and posing the same trade-offs between risk and reward. We don’t wander carelessly around cities because of pickpockets, muggers, and crazy drivers. A city’s risks arise from its freedom, as does the city’s lure as ... Read More
libhairshirt vs libfootgun

libhairshirt vs libfootgun

| | Crypto, flaws, security
 Peter Gutmann, an interesting crypto-academic from New Zealand, has proposed discussing two crypto libraries, libhairshirt and libfootgun:  In libhairshirt, the crypto is hard to use, and the API is hard to use. In libfootgun, the crypto is incredibly hard to use safely but the API makes it look really easy ... Read More
Cloud Security Specialization Launched

Cloud Security Specialization Launched

The University of Minnesota now offers a Cloud Security specialization through Coursera. It contains four courses (the fourth should be finished in early 2021). While the University does not offer course credit for completing the specialization, I am using it as the basis for a graduate course this spring, offered ... Read More
Memory Sizes: Now with zetta and yotta!

Memory Sizes: Now with zetta and yotta!

| | memory sizes, Tech Teaching, yotta
One of the most popular pages on this site provides a simple conversion to map numbers of various sizes to the corresponding memory storage sizes in bits (mathematicians and other geeks often call this “log base 2”). The popular table now includes all of the international standard integer size names ... Read More
Selling It: Crypto Edition

Selling It: Crypto Edition

| | Crypto, security, stream cipher
Here is a crypto version of “Selling It,” a long-running back-page column in the magazine Consumer Reports. For those unsure of the acronyms, “SHA-256” stands for a version of the Secure Hash Algorithm yielding a 256-bit output. SHA is not encryption. People have used hash algorithms for encryption, but the ... Read More
Old Story: Leaked Voter Records

Old Story: Leaked Voter Records

My previous posting on the Proud Boys spam email speculated that voter records were widely available for such purposes. Here’s a story from 2017 reporting that voter data for about 198 million Americans was spilled from a “storage bucket” on Amazon’s Simple Storage Service (S3). The story shines a light ... Read More
“Proud Boys” Emails Are Bogus

“Proud Boys” Emails Are Bogus

| | Elections, email, security, Spam, Trump
The Proud Boys emails aren't actual threats. They're the lowest form of anonymous spam ... Read More
2021 MSSE Cloud Security Elective

2021 MSSE Cloud Security Elective

| | MSSE, Tech Teaching, training, UMN
Members of the University of Minnesota’s MSSE Class of 2021: I am offering a Cloud Security elective based on the Coursera Cloud Security specialization currently under development. The first course, Cloud Security Basics, is already live. The remaining three courses go live this fall. If we think of networked computing being ... Read More
Krebs’ Three Rules

Krebs’ Three Rules

| | krebs, Malware, online safety, security
Like most people, I'm drawn to those small lists of "rules" that promise to make our lives better. Brian Krebs reposted a list back in May that we all need to share with our older loved ones: three basic rules of online safety ... Read More
Basic Tech-y Article on Password Hacking

Basic Tech-y Article on Password Hacking

Here’s an article from last year’s Scientific American: The Mathematics of (Hacking) Passwords. If you remember your logarithms, it’s a decent read. If you don’t, you can skip the math and read the details: why longer passwords are better. (The left-hand diagram comes from Figure 2.6 of Authentication.) ... Read More