Bruce Schneier's Blog

Iscriviti a feed Bruce Schneier's Blog
A blog covering security and security technology.
Aggiornato: 5 ore 13 min fa

Friday Squid Blogging: Squid Scalp Massager

18 Maggio, 2012 - 23:26
Cheap! As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered....
Categorie: Code

Kip Hawley Reviews Liars and Outliers

18 Maggio, 2012 - 13:06
In his blog: I think the most important security issues going forward center around identity and trust. Before knowing I would soon encounter Bruce again in the media, I bought and read his new book Liars & Outliers and it is a must-read book for people looking forward into our security future and thinking about where this all leads. For...
Categorie: Code

Cybersecurity at the Doctor's Office

17 Maggio, 2012 - 19:28
I like this essay because it nicely illustrates the security mindset....
Categorie: Code

Rules for Radicals

17 Maggio, 2012 - 14:20
It was written in 1971, but this still seems like a cool book: For an elementary illustration of tactics, take parts of your face as the point of reference; your eyes, your ears, and your nose. First the eyes: if you have organized a vast, mass-based people's organization, you can parade it visibly before the enemy and openly show your...
Categorie: Code

USB Drives and Wax Seals

16 Maggio, 2012 - 20:50
Need some pre-industrial security for your USB drive? How about a wax seal? Neat, but I recommend combining it with encryption for even more security!...
Categorie: Code

Security Vulnerabilities in Airport Full-Body Scanners

16 Maggio, 2012 - 13:15
According to a report from the DHS Office of Inspector General: Federal investigators "identified vulnerabilities in the screening process" at domestic airports using so-called "full body scanners," according to a classified internal Department of Homeland Security report. EPIC obtained an unclassified version of the report in a FOIA response. Here's the summary....
Categorie: Code

U.S. Exports Terrorism Fears

15 Maggio, 2012 - 13:17
To New Zealand: United States Secretary of Homeland Security Janet Napolitano has warned the New Zealand Government about the latest terrorist threat known as "body bombers." [...] "Do we have specific credible evidence of a [body bomb] threat today? I would not say that we do, however, the importance is that we all lean forward." Why the headline of this...
Categorie: Code

The Trouble with Airport Profiling

14 Maggio, 2012 - 13:19
Why do otherwise rational people think it's a good idea to profile people at airports? Recently, neuroscientist and best-selling author Sam Harris related a story of an elderly couple being given the twice-over by the TSA, pointed out how these two were obviously not a threat, and recommended that the TSA focus on the actual threat: "Muslims, or anyone who...
Categorie: Code

Friday Squid Blogging: New Book on Squid

11 Maggio, 2012 - 23:58
Kraken: The Curious, Exciting, and Slightly Disturbing Science of Squid. And a review. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered....
Categorie: Code

Smart Phone Privacy App

11 Maggio, 2012 - 13:42
MobileScope looks like a great tool for monitoring and controlling what information third parties get from your smart phone apps: We built MobileScope as a proof-of-concept tool that automates much of what we were doing manually; monitoring mobile devices for surprising traffic and highlighting potentially privacy-revealing flows [...] Unlike PCs, we have little control over the underlying privacy and security...
Categorie: Code

Security Fail

10 Maggio, 2012 - 12:46
Funny....
Categorie: Code

RuggedCom Inserts Backdoor into Its Products

9 Maggio, 2012 - 13:24
All RuggedCom equipment comes with a built-in backdoor: The backdoor, which cannot be disabled, is found in all versions of the Rugged Operating System made by RuggedCom, according to independent researcher Justin W. Clarke, who works in the energy sector. The login credentials for the backdoor include a static username, "factory," that was assigned by the vendor and can't be...
Categorie: Code

A Foiled Terrorist Plot

8 Maggio, 2012 - 20:14
We don't know much, but here are my predictions: There's a lot more hyperbole to this story than reality. The explosive would have either 1) been caught by pre-9/11 security, or 2) not been caught by post-9/11 security. Nonetheless, it will be used to justify more invasive airport security....
Categorie: Code

Overreacting to Potential Bombs

8 Maggio, 2012 - 14:03
This is a ridiculous overreaction: The police bomb squad was called to 2 World Financial Center in lower Manhattan at midday when a security guard reported a package that seemed suspicious. Brookfield Properties, which runs the property, ordered an evacuation as a precaution. That's the entire building, a 44-story, 2.5-million-square-foot office building. And why? The bomb squad determined the package...
Categorie: Code

Naval Drones

7 Maggio, 2012 - 13:52
With all the talk about airborne drones like the Predator, it's easy to forget that drones can be in the water as well. Meet the Common Unmanned Surface Vessel (CUSV): The boat -- painted in Navy gray and with a striking resemblance to a PT boat -- is 39 feet long and can reach a top speed of 28 knots....
Categorie: Code

Friday Squid Blogging: Squid Bicycle Parking Sculpture

4 Maggio, 2012 - 23:01
Neat. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered....
Categorie: Code

Tampon-Shaped USB Drive

4 Maggio, 2012 - 20:31
This vendor is selling a tampon-shaped USB drive. Although it's less secure now that there are blog posts about it....
Categorie: Code

Facial Recognition of Avatars

4 Maggio, 2012 - 13:31
I suppose this sort of thing might be useful someday. In Second Life, avatars are easily identified by their username, meaning police can just ask San Francisco-based Linden Labs, which runs the virtual world, to look up a particular user. But what happens when virtual worlds start running on peer-to-peer networks, leaving no central authority to appeal to? Then there...
Categorie: Code

Criminal Intent Prescreening and the Base Rate Fallacy

3 Maggio, 2012 - 13:22
I've often written about the base rate fallacy and how it makes tests for rare events -- like airplane terrorists -- useless because the false positives vastly outnumber the real positives. This essay uses that argument to demonstrate why the TSA's FAST program is useless: First, predictive software of this kind is undermined by a simple statistical problem known as...
Categorie: Code

Al Qaeda Steganography

2 Maggio, 2012 - 19:41
The reports are still early, but it seems that a bunch of terrorist planning documents were found embedded in a digital file of a porn movie. Several weeks later, after laborious efforts to crack a password and software to make the file almost invisible, German investigators discovered encoded inside the actual video a treasure trove of intelligence -- more than...
Categorie: Code

Pagine