Archive for the ‘Uncategorized’ Category

Sergey Bratus on Learning from Hackers

Wednesday, March 10th, 2010

I just saw Sergey Bratus’s talk at TROOPERS 10. He’s an interesting guy, and his talk was good. He’s a CS professor at Dartmouth, and he’s actually making an effort, on behalf of the academic community, to inject some genuine security clue into the education of CS students. He obviously has a tough topic to address, but he looks like he’s on the right track to me.

One thing he pointed out is that a lot of vulnerabilities over the years have actually resulted from the accidental creation of Turing-complete systems. (He has a nice Cthulu slide making the point.)

It struck me that one goal of “secure programming” would be the avoidance of the creation of Turing-complete systems. It’s a crazy world when it’s harder to avoid the creation of such a system than it is to actually create one.

Anyway, Marsh and I are speaking in a couple of hours. If you’re here, come by and bring your rotten tomatoes!

Un-twittering my blog

Wednesday, March 10th, 2010

Sorry for all of the blog spam; I had experimented with the idea of auto-posting my tweets to my blog, on the theory that I rarely tweet, and it tended to be the same sort of thing I’d have posted here. Turns out that I tweet more often than I thought, and generally about pretty useless stuff. :-)

On the upside, at least three people complained about it in the last 12 hours, so obviously someone still reads my blog! Heh…

Fixed. Noted for future reference. Thanks.

Heidelberg-bound

Monday, March 8th, 2010

I’m getting ready to head out to Heidelberg, Germany with Marsh to attend TROOPERS10. Marsh and I are finally doing a more technical version of the TLS talk. It should be a great time!

If you’re going to be in the area (Heidelberg or northern Switzerland, where I’m flying in/out of), drop me a line!

Light Blue Touchpaper provides…

Friday, March 5th, 2010

Light Blue Touchpaper provides rigorous grounding for what we already knew: security questions suck. http://bit.ly/aIY8ZQ (via Rootsecure)

If you thought typing ‘https:/…

Friday, March 5th, 2010

If you thought typing ‘https://gmail.com’ into your browser was the safe way to get to GMail w/o sslstrip… you’d be wrong.

ShmooCon vids up! Once again, …

Friday, March 5th, 2010

ShmooCon vids up! Once again, sorry about the sweaters. :-) http://bit.ly/ahw0CW

Had much fun on the responsibl…

Wednesday, March 3rd, 2010

Had much fun on the responsible disclosure panel. Thanks @mckeay and @hdmoore, @k3em0, @bradarkin, Michael and Tim for a fun conv.

This trend can’t possibly last…

Wednesday, March 3rd, 2010

This trend can’t possibly last: http://bit.ly/a6Pf7P #PhoneFactor would have stopped this.

After a year of absolute calm…

Wednesday, March 3rd, 2010

After a year of absolute calm, finally started getting tons of bogus ssh attempts this week to one of my vps boxes. Wonder what happened…

RT @EchoChief: HIMSS Coverage:…

Wednesday, March 3rd, 2010

RT @EchoChief: HIMSS Coverage: Steve Dispensa, CTO & Co-Founder PhoneFactor http://bit.ly/cSEY9J <– Um, uh, um… note to self: coffee!