28 February 2012

Security Misc.

Some Security items:

Redphone 0.4 removed from AndroidApps, beta may be available..

Redphone uses ZRTP, Diffie-Hellman key exchange and the Secure Real-time Transport Protocol (SRTP) for encryption.
..ZRTP designed by Phillip Zimmerman, the inventor of PGP


Download free from Android market
RedPhone 0.4

UPS! APP NOT FOUND
That app seems to be not longer available on Android Market.

..need someone to call, join #whispersystems on irc.freenode.net

.._________________________________
Airport woes

Moxie Marlinspike, was met by two U.S. Customs and Border Protection agents at the door of his plane when he arrived at JFK airport on a Jet Blue flight from the Dominican Republic. ..held him for 4 1/2 hours,..seized Marlinspike’s laptop and two cellphones, and asked for his passwords..

Marlinspike refused, and the devices were later returned to him.

“I can’t trust any of these devices now,”.. “They could have modified the hardware or installed new keyboard firmware.”

Marlinspike gained attention last year at the Black Hat security conference in Las Vegas when he revealed a serious vulnerability in how internet browsers verify digital security certificates. ..He released two free tools that would help an attacker conduct such an attack.

Three months later, PayPal froze his account


.....ticket agents, .. were blocked from producing a boarding pass for him without first calling .. Department of Homeland Security. Secure Flight .....


Others.....
security researcher Jake Appelbaum, was detained in July at a New Jersey airport,..on his way to the DefCon hacker conference ..a U.S. rep for WikiLeaks, was questioned ..three-hour period about WikiLeaks,..Julian Assange and Appelbaum’s opinion about the wars in Iraq and Afghanistan.

...David House was met by U.S. customs agents as he deplaned earlier this month at Chicago’s O’Hare ..from Mexico....had his laptop seized

..House helped set up the Bradley Manning Support Network, ..
wired

___________________________________________________________________

5 for SMS




whispersys has no downloads .. just points to Android MArket

Beta may be here try
brothersoft


Phones on which beta may work
brothersoft

aaa

____________________________________________________________________________________________


Code signing FAQs available at:
thawte
- Hey lets send Shuttleworth into space AGAIN (just kidding, and thanks for all the Ubuntu)

____________________________________________________________________________________________

Slow trains?
Australian firm Sequoia Smart Solutions [Freemantle?] €5m for designing the smart- card system. (not a huge amount?)
Leap card, 10 years late and €26m over budget.( sounds fairly typical)

It allows Dublin commuters to top up on credit in advance and then swipe it for cheaper fares on trains, buses and trams.  (this is a feature, , surely, not a bug)

..Irish Independent reveal for the first time how a host of companies benefited from repeated delays in the project, which pushed costs up from €29.6m to €55.4m. (the ii article reveals typical incompetence, not malicious delaying??)
__________________________________________________


AdMob, Mobclix, InMobi, etc. can pillage all sorts of information from unsuspecting users. Users will blame you, not the advertising company

__________________________________
Stuxnet video
digitalbond   c/o Bruce Schneier schneier
__________________________________
Some Security puff :
The BIG-IP Edge Client app provides not only full SSL VPN access from iPhones and
iPads,

Center for Information Security (http://www.cisecurity.org) offers
a multipoint checklist that includes implementing Network Intrusion Detection.. load-balancing/failover to combat
Denial of Service or shutdown...sterilize WHOIS records of personal information that can be used for social
engineering ..Open Web Applications Security Project’s (OWASP –
http://www.owasp.org) AppSec tutorial series ..hardening Apache. M.. http://xianshield.org/guides/apache2.0guide.html).
..separate partitions for binaries, html documents and logs, ..
Apache in its own, nonprivileged group (i.e. not nobody), removing its shell and locking its login.


__________________________________

No comments:

Post a Comment