The Mac Hacker’s Handbook

The Mac Hacker's Handbook is the best reference for Mac-specific attack information that I have found. At 368 pages, it may appear small compared to the typical 750+ page security tome. That's because the authors have done a near-perfect job of sticking to the topic at hand, the Mac. The ... Read More

MyYearbook

| | egoblogging, security
I've been wasting a bunch of time on MyYearbook.com, a MTWWTOSNS (massively time-wasting web-two-oh social-networking site.) If you'd like to descend into madness with me, click here join join for my personal gain:Be Ryan's FriendSeveral interesting aspects to this one, for security people. First, the are many sociological aspects. For ... Read More
Little Brother

Little Brother

| | review, secphil, security
I just finished reading Little Brother by Cory Doctorow while on a plane to Seattle for a Windows Secrets meetup.There are a few audiences one might rate this book against. Probably the only fair one is the one Cory wrote for, young adult readers who need an introduction to electronic ... Read More

Is Microsoft dropping Apple 0-day?

| | security
Just saw this link show up in my RSS reader:Microsoft Security Advisory (953818) Blended Threat from Combined Attack Using Apple’s Safari on the Windows PlatformFrom the advisory:FAQWhat causes this threat?A combination of the default download location in Safari and how the Windows desktop handles executables creates a blended threat in ... Read More

More on Orkut worm

| | Malware, security
Yes, my HTML/Javascript-fu is weak. So much so that I didn't know we were dealing with pure Javascript. Javascript that just happens to exist to facilitate posting Flash movies and games, so that's why it has "Flash" written all over it.To back up several steps... I received an email from ... Read More

Orkut "virus"

| | Malware, security
More of a worm, actually.I had an email from Orkut this evening telling me I had a new scrapbook entry. I don't really use Orkut, but I signed up a while back, and friended a bunch of people I know. The scrapbook entry was a bit cryptic:2008 vem ai... que ... Read More

The Ladies of Infosec

| | secphil, security
I was at an event not long ago, and the woman in the group was really pissed. In a room full of nothing but security geeks, someone asked her "Oh, do you do security work?"This didn't happen with any of the guys. The question they got was "Where do you ... Read More

Secure Guardrails