Flaw Found in an Online Encryption Method Not As Bad As It Seems

For the geeks reading this, skip down to the links and you can get all geek.
For the end user, here is a summary.
Internet encryption traffic is based on two keys that are generated to create a secure communications channel that, if intercepted, could not be read without the key.
The vunerability that everyone is screaming about is actually found mostly in hardware devices that generate this type of key and not in big banking and e-commerce websites. No need to put on the tinfoil hat, all is well.
Now, if you’re a business that uses a remote access solution with VPN, you should pay attention. There is chance that you’re connecting through a hardware device that generates this key that may be vunerable. I would be even more concerned if you business falls under any regulatory law (HIPAA or the like). They have not revealed specifics on what hardware and software is effected so they can notify the manufacturers first before making it common knowledge. I’m sure that anyone with malicious intent has known about this longer than we care to realize.

Link to New York Times ‘run for the hills’ response.
Link to Freedom To Tinker that has done there homework and reveals the truth.
Link to ArsTechnica article.


A Hard Drive Cannot ‘Plead the Fifth’?

Ars Technica has an interesting article on an encrypted hard drive not being decrypted based on self incrimination rights. To summarize: Unencrypting a hard drive could create / display incriminating evidence. Via the Fifth Amendment rights, you can choose not give up the decrpytion password. But this judge is saying the owner of the laptop


Security Alerts and Stories

Security Alerts and Stories: An hour after a security story is published; it’s outdated. As of now, here are some security stories any average computer user should know about. WPA/WPA2 WPS (wi-fi protected setup) vunerability | This is an amazing and disturbing discovery. What’s worse is if you are not using the friendly button and


Microsoft Deployment Tookit – My experiences

I could write about the installation and tools needed; but many posts already exist about this (feel free to comment a link to). Two pieces needed. Automated Installation Kit (AIK) and Microsoft Deployment Toolkit Update 1 (is the latest as of this writing). First things first. Make a good environment for the MDT share. I


Stop American Censorship

I’ve censored the following, in protest of a bill that gives any corporation and the US government the power to censor the internet–a bill that could pass THIS WEEK. To see the uncensored text, and to stop internet censorship, visit: http://americancensorship.org/posts/9041/uncensor We ████ ████ ████. The ██████ in ██████████ █████ ‘the ██████’ ██████ ████ ████


QoS Tomatoes are Rotten

I recently had to move and was forced to leave behind my luxury wireless gigabit router with DD-WRT customized on it. This was temporary, but my new location had a WRT54GL router to use temporarily. The firmware was stock, and my need for QoS for my VoIP phones showed up. I had a good bed


Physical to Virtual Server Migration

I successfully have moved / migrated an older PowerEdge Server 2003 via the VMware Convertor Standalone software. I have previously posted about how impressive this tool was, but migrating a production server was a something I was not 100% experienced with. Things I did differently or have learned from. Write down the network adapter information.


Microsoft buys Skype – don’t panic (yet)

My knee-jerk on this news is that a historic piece of software is going away forever. We know that Microsoft is very capitalistic. So they will be making money off this as soon as possible. If they don’t go to a paid model immediately, then I see the software guts being ground into there products


Virtualization (update)

Have not posted much lately on the VMware side. Will give some quick updates. I realized my setup did not have ANY type of RAID support; just assumed this when ordering, since even the ‘cheap’ desktop motherboards include some form of RAID. So I have upgraded to: Asus PIKE SAS card. (Since the purchase, they


Quick (cell phone) rant…

I read this and now I must rant… How the hell did they NOT see that coming? As if 4g is really a new physical technology anyhow. The whole thing makes me sick. Cell providers don’t give a rats rear end about the actual people using there service; all they want is you to come