Main Menu
Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Topics - bill

#21
Hardware & Technology / Anyone here a HAM?
March 03, 2016, 04:04:20 AM
Several people in my circles have been suggesting I get my HAM radio licence. Particularly in Japan where we're moments away from having our entire communications infrastructure destroyed by an earthquake, it didn't sound like a bad idea. I'm just wondering how much prep it takes to pass those licencing tests. I'd have to travel several hours to another city to take the test so it would take a bit of effort in addition to the study.
#22
QuoteThis is Why People Fear the ‘Internet of Things’

Imagine buying an internet-enabled surveillance camera, network attached storage device, or home automation gizmo, only to find that it secretly and constantly phones home to a vast peer-to-peer (P2P) network run by the Chinese manufacturer of the hardware. Now imagine that the geek gear you bought doesn’t actually let you block this P2P communication without some serious networking expertise or hardware surgery that few users would attempt.

This is the nightmare “Internet of Things” (IoT) scenario for any system administrator: The IP cameras that you bought to secure your physical space suddenly turn into a vast cloud network designed to share your pictures and videos far and wide. The best part? It’s all plug-and-play, no configuration necessary!
#23
Another timely article telling us that the IoT devices in our homes really need more security.

QuoteThe government just admitted it will use smart home devices for spying

If you want evidence that US intelligence agencies aren't losing surveillance abilities because of the rising use of encryption by tech companies, look no further than the testimony on Tuesday by the director of national intelligence, James Clapper.

As the Guardian reported, Clapper made clear that the internet of things – the many devices like thermostats, cameras and other appliances that are increasingly connected to the internet – are providing ample opportunity for intelligence agencies to spy on targets, and possibly the masses. And it's a danger that many consumers who buy these products may be wholly unaware of.

"In the future, intelligence services might use the [internet of things] for identification, surveillance, monitoring, location tracking, and targeting for recruitment, or to gain access to networks or user credentials," Clapper told a Senate panel as part of his annual "assessment of threats" against the US.
#24
Web Development / Are your HTTP headers secure?
January 28, 2016, 01:25:48 AM
I need to get this implemented on my sites: Content Security Policy (CSP)
Looks like a great way to thwart cross-site scripting attcks.

This guy has a scanner https://securityheaders.io/ that grades your headers just like SSL Labs does for certs. He also has a CSP policy builder https://report-uri.io/home/generate/ but there are a lot of options in there that I'd need to look into.

Anyone here use a CSP?
#25
Web Development / Material Design Lite
July 07, 2015, 02:24:48 AM
QuoteOn Medium today, Google Developers introduced us to a useful little tool called Material Design Lite. In simple terms, it's a library of components that will make it very easy to apply Material Design elements to standard old HTML, JavaScript, and CSS. The library includes all sorts of page elements: Cards! Click-sensitive menus! Gem-toned buttons! Lovely little physics-enhanced toggles! "If you just want to pick some colors, customize a template and ship a Material experience, we try to help make that process simpler," the team explains.

Interesting design framework if you want your site to look like an Android phone...
#26
Not surprising

QuoteConsumers Spend 85% Of Time On Smartphones In Apps, But Only 5 Apps See Heavy Use

Based on this data and other findings in the new report, Forrester advises businesses to design their apps only for their best and most loyal or frequent customers – because those are the only one who will bother to download, configure and use the application regularly. For instance, most retailers say their mobile web sales outweigh their app sales, the report says. Meanwhile, outside of these larger players, many customers will use mobile websites instead of a business' native app.

#27
Agrh. Not fun to wake up to this news. LastPass issued a security notice saying that account email addresses, password reminders, server per user salts, and authentication hashes were compromised. I'm not too worried about my account contents, but it's a bit of a pain to have to acclimate to a new master password.

https://blog.lastpass.com/2015/06/lastpass-security-notice.html/
#28
Hackers build a new Tor client designed to beat the NSA
http://www.dailydot.com/politics/tor-astoria-timing-attack-client/

QuoteWith the threat of powerful intelligence agencies, like the NSA, looming large, researchers have built a new Tor client called Astoria designed specifically to make eavesdropping harder for the world's richest, most aggressive, and most capable spies.

#30
Traffic / A Year of DuckDuckGo
March 30, 2015, 06:09:50 AM
A Year of DuckDuckGo http://www.designwithtom.com/blog/2015/3/23/a-year-of-duckduckgo

An interesting blog post about this guy's experience with DDG. The only thing that doesn't really parallel my experience is the Instant Search features. I haven't see a lot of them. I still find it necessary to go to GG for some stuff like calculations or currency conversion in the SERPs. I guess DDG is catching up.
#31
Hardware & Technology / BIOS Hacking
March 25, 2015, 04:50:44 AM
BIOS Hacking https://www.schneier.com/blog/archives/2015/03/bios_hacking.html

Interesting article that collects snippets from the tech press about hacking the BIOS.
#32
Web Development / considering a vBulletin 5 upgrade
March 20, 2015, 05:20:54 AM
I have an old vBulletin 3.8 forum that is starting to show its age and I wanted to consider an upgrade...possibly to vBulletin 5. This is on a closed Intranet system so I don't have to worry about search engines or the general public.

However, after doing some online research I have a hard time looking past all the people bad-mouthing vBulletin 5. Can it really be as awful as these trolls make it out to be? If it is, I'd be open to consider alternatives. Digital Point keeps a page of data up about forums: https://tools.digitalpoint.com/cookie-search It shows vBulletin5 uptake is really small.

My current site is actually running vbDrupal, which is a now defunct hack of Drupal and vB that allowed the administration of the users through vB, with all of the front end CMS features of Drupal. That's one reason vB5 appealed to me; With the moderate CMS/blog features in addition to the forum I could control content access to not just the forum, but the entire site, with one logon for each user.
#33
Water Cooler / Some guy has invented Synthehol
March 03, 2015, 12:56:35 PM
This stuff will sell itself...

QuoteThis Professor Has Invented a Pill That Eliminates Hangovers

The first of Nutt's wonder drugs is "alscosynth," a non-toxic inebriant drink that induces the same I-reeeeally-luuuurve-you-man effects of alcohol, but carries no risk of hangover, aggression, loss of control or any of the general mess that comes from hammering your liver with a toxic compound.

"It targets the parts of the brain that give the good effects of alcohol but not those that give the bad effects," explains Nutt, who hopes the alcohol substitute will be marketed as a companion to regular alcoholic drinks, and be relatively cheap to buy.
#34
According to all the hype, HTTP/2 should be faster, more efficient, and more secure (due to the addition of mandatory TLS). Are we ready for the new protocol?

http://arstechnica.com/information-technology/2015/02/http2-finished-coming-to-browsers-within-weeks/#p3
#35
What happened to the Truecrypt audit that everyone paid for? Well, here's an update.
http://blog.cryptographyengineering.com/2015/02/another-update-on-truecrypt-audit.html
#36
I'm sure you're all dying to find out if the UK used NSA data to spy on you ...
#37
http://www.businessinsider.com/google-plan-to-beat-microsoft-office-2015-2

I knew Office was struggling to find a way to get people to continue paying for Office somehow, but I didn't know Google Apps had become that much of a potential competitor. Did MS drop the ball on this one too?
#38
Water Cooler / Canary Watch
February 03, 2015, 02:08:18 AM
https://www.canarywatch.org/

Wonder if this will catch on.

Regardless I'm going to follow their feed.
#39
Phil Zimmerman (PGP), Ladar Levison (Lavabit), and team release Secure Email Protocol DIME. Their claim is that DIME is to SMTP as SSH is to Telnet
http://darkmail.info/ (Full specs, sourcecode, etc.)
#40
More scary tracking technology for advertisers to use instead of cookies:

QuoteMeet the Online Tracking Device That is Virtually Impossible to Block

A new, extremely persistent type of online tracking is shadowing visitors to thousands of top websites, from WhiteHouse.gov to YouPorn.com.

First documented in a forthcoming paper by researchers at Princeton University and KU Leuven University in Belgium, this type of tracking, called canvas fingerprinting, works by instructing the visitor's Web browser to draw a hidden image. Because each computer draws the image slightly differently, the images can be used to assign each user's device a number that uniquely identifies it.

Like other tracking tools, canvas fingerprints are used to build profiles of users based on the websites they visit — profiles that shape which ads, news articles, or other types of content are displayed to them.