Category Archives: Technology
Port Knocking
Remember when you used to only open the door when a certain pattern of knocks was heard? You can do the same with ports – the so-called “Port Knocking”. It provides another layer of security to your system as ports are not opened until the correct knocking pattern is received.
Haven’t installed or tried this myself, but may do over the weekend.
http://www.boynux.com/how-to-enable-port-knocking-in-linux/?goback=.gde_102999_member_269001685
https://en.wikipedia.org/wiki/Port_knocking
http://www.microhowto.info/howto/implement_port_knocking_using_iptables.html
https://wiki.archlinux.org/index.php/Port_Knocking
http://www.debian-administration.org/articles/268
http://www.zeroflux.org/projects/knock/
Check your etiquette: Nine LinkedIn faux pas to avoid
The Duel: Timo Boll vs. KUKA Robot – YouTube
Sintel, Big Buck Bunny and Tears of Steel on Wuaki
Wuaki is a streaming service like Netflix, Love Film and Amazon Prime. I found it when I was clicking through the apps on my Panasonic Viera TV, and found that the three Blender-made short films were all there. You can also access them on the web interface. Oh, and they’re free to rent and watch, so you can’t get better than that.
Best Advice: Never Give Up | LinkedIn
Fix the iPhone’s Security Bug On Jailbroken Phones without Upgrading
Behind iPhone’s Critical Security Bug, a Single Bad ‘Goto’
Some software bugs are infinitely subtle and complicated. Others are comprehensible almost at a glance to anyone who dabbled in BASIC as a kid. The iOS 7 bug is in the latter group.
Did you see it? This function is called when a iPhone connects to an encrypted site over SSL: it’s meant to verify that the encryption key is being vouched for — digitally signed — by the operator of the website.
But notice the two “goto fail” lines, one after the other. The first one belongs there. The second is a typo. That extra, duplicative line diverts the program’s execution, like a bypass stent, right past a critical authentication check. The part where the digital signature is actually checked is dead code, never reached.
Behind iPhone’s Critical Security Bug, a Single Bad ‘Goto’ | Threat Level | Wired.com.
Something just blew up. In Apple’s face. Big time.
Why Apple’s Recent Security Flaw Is So Scary.
On Friday, Apple quietly released iOS 7.0.6, explaining in a brief release note that it fixed a bug in which “an attacker with a privileged network position may capture or modify data in sessions protected by SSL/TLS.” That’s the understated version. Another way to put it? Update your iPhoneright now.
Oh, and by the way,OS X has the same issues—except there’s no fix out yet.
In simple terms, someone can intercept traffic between you and the site your accessing, and pull of a “Man in the Middle” attack:
I could make all manner of snarky comments on this, but I won’t.
Identity
I was playing an online game (a game which I no longer play), and that game had in-game purchases. Up to a point, I was able to use a certain e-funds provider (not PayPal, but along those lines) to pay, then it suddenly reported that it was unable to complete the transaction. So I emailed them, and they said they needed me to provide them proof of identity. So I sent them a partially blanked copy of my Driving License and bank account. They came back saying they needed the unblanked version. My response was that no-one should be sending crucial identity documents such as these over an unsecure channel such as email without first masking important details, and I would find an alternative means of paying – basically telling them to shove it – I’m taking my business elsewhere.
They came back 5 minutes later with the typical legal text saying they would process it as part of the DPA, they were a member of this security body, etc.
Nope, still going to take my business elsewhere.





You must be logged in to post a comment.