Securosis Blog

Yes folks, Black Friday is less than two weeks away and the silly season is upon us. As someone born and bred in good old North Jersey (until I could legally escape), land of honey and shopping malls, this is a time so deeply ingrained into my subconscious that I’ve occasionally found myself sleepwalking around the nearest parking lot, looking for our old wood-paneled station wagon.

Database Security Vulnerability Stats

Rich · November 10, 2006

These numbers are totally fascinating- check it out here.

Keep in mind that some database systems (like SQL Server) only run on a single platform, while the others (you know who) run all over the place.

Mac FileVault Encryption Update

Rich · November 10, 2006

Back in August I finally broke down and encrypted my computer using the built in FileVault feature in Mac OS X.

As a security professional I admit that I normally assume someone I’m dealing with isn’t necessarily honest; especially if they’ve done something to draw my attention. I learned early on that most humans have an unbelievable capacity for deceit, and they use it on a daily basis. In many cases the individual is so believable because they’ve convinced themselves that what they’re doing/saying is either the truth (when it’s clearly not), or they’re justified for some bullshit reason (like “the…

As the silly season comes to a close with today’s election (at least for, like, a week or so) there’s a change to the political process I’ve been thinking about a lot. And it’s not e-voting, election fraud, or other issues we’ve occasionally discussed.

From BoingBoing:

If you experience any irregularities in voting today, call 1-866-OUR-VOTE, the hotline for the National Campaign for Fair Elections. EFF lawyers and many others are standing by across the country to take legal action to remove malfunctioning voting machines, keep polls open, etc.

An unpatched vulnerability being exploited in the wild.

When I’m on a Windows system (I run it virtualized on my Mac for work) I tend to use multiple browsers since even Firefox has issues at times.

After reviewing the materials I could find online I directly contacted Thierry Zoller and he was kind enough to respond with more details. In his words (with permission). Short version is the flaw is well patched, but the exploit is a new technique of getting a remote shell. No kernel bugs this time:

I have no details, but am investigating.

http://isc.sans.org/diary.php?storyid=1817

I know there are some Bluetooth 0days floating around for various platforms, but this one wasn’t on my list.

In the comments of my last post, bkwatch reminds me that paper ballots are from from perfect.

I totally agree.