<?xml version="1.0"?>
<rss version="2.0">
<channel>
  <title>Darwin&#039;s Theories - Security category</title>
  <link>http://theories.darwinsys.com:80/categories/security/</link>
  <description>Call it a Blog if you like -- Ian</description>
  <language>en</language>
  <copyright>Ian Darwin</copyright>
  <lastBuildDate>Wed, 08 May 2013 01:45:00 GMT</lastBuildDate>
  <generator>Pebble (http://pebble.sourceforge.net)</generator>
  <docs>http://backend.userland.com/rss</docs>
  
  
  <item>
    <title>Web Site Fail du jour</title>
    <link>http://theories.darwinsys.com:80/2012/07/24/1343143920000.html</link>
    
      
        <description>
          &lt;p&gt;
So Vizio has this real nice Google TV set-top box called the &lt;a href=&#034;http://www.vizio.com/costar/overview/&#034;&gt;Co-Star&lt;/a&gt;, that they are now taking pre-orders for. But the web site is a total fail from the human factors point of view. It has fields for allowing you to enter different shipping and billing addresses,  but when you do, it tells you they have to be the same!
This was confirmed by their support person as having been reported to those responsible.
&lt;/p&gt;
&lt;p&gt;
Not only that, the Billing Address has to be in the good ole&#039; USA. The list of countries that they know about, in fact only includes the United States. &#034;There are no other countries on the planet. Wahoo! We won! Oh, wait, that means we can&#039;t sell to most of the world&#039;s population. Boohoo!&#034;
&lt;/p&gt;
&lt;p&gt;
Given the variety of Amurrican dot-coms that can&#039;t figure out how to ship to 
Canada, I have of course invested the time in setting up an account with a
re-shipping company appropriately enough called &lt;a href=&#034;http://reship.com/&#034;&gt;reship.com&lt;/a&gt;. So entering a US shipping address is no problem. But the billing address has to be the same for this fool web site, but I have to list my home address in Canada for the bank to believe that it&#039;s me placing the order. And that I cannot do. Site fail.
&lt;/p&gt;
And not only that, but when we tried to buy using their combined &#034;buy and sign up&#034; form, we got this classic cheesy SQL fail about a foriegn constraint violation. Nice message: it gave out the names of both affected tables and some of the columns. Sorry script kiddies but I&#039;m not reproducing that here, you&#039;ll have to offer a valid credit card to see it in action.
&lt;/p&gt;
&lt;p&gt;
Oh, and one more thing? The logout page gave a 500 server error trying to display the &#034;log out success&#034; page. This one we can probably blame on first-day sales load.
The others are site fail.
&lt;/p&gt;
        </description>
      
      
    
    
    
    <category>Android</category>
    
    <category>Web</category>
    
    <category>Internet</category>
    
    <category>Security</category>
    
    <comments>http://theories.darwinsys.com:80/2012/07/24/1343143920000.html#comments</comments>
    <guid isPermaLink="true">http://theories.darwinsys.com:80/2012/07/24/1343143920000.html</guid>
    <pubDate>Tue, 24 Jul 2012 15:32:00 GMT</pubDate>
  </item>
  
  <item>
    <title>Security Theatre, Part n</title>
    <link>http://theories.darwinsys.com:80/2009/12/31/1262291700000.html</link>
    
      
        <description>
          According to a &lt;a href=&#039;http://news.bbc.co.uk/2/hi/americas/8435285.stm&#039;&gt;BBC report&lt;/a&gt; on the latest security theatre, airline customers are now to be subject to the following indignities for in-flight entertainment:
&lt;ul&gt;
&lt;li&gt;Customers to remain seated during final hour of flight;
&lt;li&gt;No access to hand luggage and a ban on leaving possessions or blankets on laps during this hour.
&lt;/ul&gt;
Now I don&#039;t know about you, but I don&#039;t find this very comforting. The thought of being forced to sit still is inculcated in obedient citizens from kindergarten (a German word meaning roughly &#034;vegetable garden to grow kids&#034;). But at a certain point things like bladder pressure will win out. And what happens if you&#039;re in mid-whiz at the one-hour mark? Do you get shot by the air marshall while trying to return to your seat? (Watch the news for this one, folks).  The entire process is utterly ridiculous. If the bomber had tried to light his fuse at the 45 minute mark into the flight, who can doubt that they&#039;d ban visiting the toilet between 37 and 52 minutes after takeoff?
&lt;p&gt;
Remember the shoe bomber and how airport security made everybody take their shoes off before flight? Didn&#039;t stop the next religious fanatic with a fuse to light, did it?
&lt;p&gt;
The notion of an allegedly civilized nation dancing its &#034;security&#034; policies in the wind every time there&#039;s a real or perceived threat, to so vastly inconvenience its population while at the same time making no difference to the actual terrorists, is so laughable it&#039;s earned the term &#034;security theater&#034; - putting on a big show, but doing nothing for actual security.
&lt;p&gt;
It&#039;s not just me saying so. See Bruce Schnier&#039;s many &lt;a href=&#039;http://www.schneier.com/blog/archives/2006/08/terrorism_secur.html&#039;&gt;writings on this topic&lt;/a&gt;, and his essay
&lt;a href=&#039;http://www.schneier.com/essay-155.html&#039;&gt;The Psychology of Security&lt;/a&gt;.
Bruce is a well-known cryptology and security researcher; he knows whereof he speaks.
TSA, not so much.

        </description>
      
      
    
    
    
    <category>Politics</category>
    
    <category>Security</category>
    
    <comments>http://theories.darwinsys.com:80/2009/12/31/1262291700000.html#comments</comments>
    <guid isPermaLink="true">http://theories.darwinsys.com:80/2009/12/31/1262291700000.html</guid>
    <pubDate>Thu, 31 Dec 2009 20:35:00 GMT</pubDate>
  </item>
  
  <item>
    <title>Protecting Your Castle</title>
    <link>http://theories.darwinsys.com:80/2008/12/21/1229877300000.html</link>
    
      
        <description>
          SANS.org has a nice white paper showing how to protect your home network using OpenBSD and other free software. According to the abstract:&lt;br /&gt;
&lt;hr width=&#034;100%&#034; size=&#034;2&#034; /&gt;
&amp;quot;It is possible to clean up the back yard with Free Open Source Software and a little design. Using off the shelf components and Open Source software the family geek can deploy a more multilayered security stance that will provide far more visibility and control over the network. This is not to say that large swaths of the Internet can be cleaned up just by plugging in a box, but to say that if anything should be a safe haven on the internet, it should be the family network, the backyard. It makes sense to clean up the backyard before taking on the world&amp;rsquo;s trash.&amp;quot;&lt;hr width=&#034;100%&#034; size=&#034;2&#034; /&gt;
Presumably the same techniques would apply to the average small business. Check it out at &lt;a href=&#034;http://www.sans.org/reading_room/whitepapers/firewalls/32933.php&#034;&gt;http://www.sans.org/reading_room/whitepapers/firewalls/32933.php&lt;/a&gt; [PDF].&lt;br /&gt;
&lt;br /&gt;
P.S. According to &lt;a href=&#034;http://www.bartleby.com/73/861.html&#034;&gt;Bartleby&lt;/a&gt;, the quotation in my subtitle, while commonly attributed to William Pitt, comes to us in its present wording from a pr&amp;eacute;cis done by Lord Henry Peter Brougham some sixty years later.
        </description>
      
      
    
    
    
    <category>Open Source Software</category>
    
    <category>OpenBSD</category>
    
    <category>Internet</category>
    
    <category>Security</category>
    
    <comments>http://theories.darwinsys.com:80/2008/12/21/1229877300000.html#comments</comments>
    <guid isPermaLink="true">http://theories.darwinsys.com:80/2008/12/21/1229877300000.html</guid>
    <pubDate>Sun, 21 Dec 2008 16:35:00 GMT</pubDate>
  </item>
  
  <item>
    <title>It&#039;s true what they say about airport security</title>
    <link>http://theories.darwinsys.com:80/2008/10/18/1224362460000.html</link>
    
      
        <description>
          &amp;quot;Airport security in America is a sham&amp;mdash;&amp;ldquo;security theater&amp;rdquo; designed to make travelers feel better and catch stupid terrorists. Smart ones can get through security with fake boarding passes and all manner of prohibited items&amp;mdash;as our correspondent did with ease...&amp;quot;&lt;br /&gt;
&lt;br /&gt;
There&#039;s nothing I can add to &lt;a href=&#034;http://www.theatlantic.com/doc/200811/airport-security&#034;&gt;this&lt;/a&gt;. While you&#039;re there, check the other security-related articles on the site.
        </description>
      
      
    
    
    
    <category>Politics</category>
    
    <category>Security</category>
    
    <comments>http://theories.darwinsys.com:80/2008/10/18/1224362460000.html#comments</comments>
    <guid isPermaLink="true">http://theories.darwinsys.com:80/2008/10/18/1224362460000.html</guid>
    <pubDate>Sat, 18 Oct 2008 20:41:00 GMT</pubDate>
  </item>
  
  <item>
    <title>Ian&#039;s Top Ten Today, #2</title>
    <link>http://theories.darwinsys.com:80/2008/07/17/1216348440000.html</link>
    
      
        <description>
          Here&#039;s a few more tidbits. As I said &lt;a href=&#034;http://theories.darwinsys.com/2008/03/06/1204829460000.html&#034;&gt;last time&lt;/a&gt;, &amp;quot;This is not a monthly or even a regular listing; I&#039;ll repeat this when I have another ten.&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;ol&gt;
    &lt;li&gt;&lt;a href=&#034;http://www.fff.org/freedom/fd0803a.asp&#034;&gt;The Demise of Conscience, Part 1&lt;br /&gt;
    &lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#034;http://chronicle.com/free/v52/i10/10a01401.htm&#034;&gt;The Man Who Would Murder Death&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#034;http://music.download.com/&#034;&gt;Free (legal) MP3 music downloads&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#034;http://www.salon.com/opinion/greenwald/2008/07/15/complicity/index.html&#034;&gt;Tyranny begins with &lt;strike&gt;lawmakers&lt;/strike&gt; lawbreakers&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#034;http://www.salon.com/opinion/greenwald/2008/07/08/accountability/index.html&#034;&gt;Aug. 8, 1974 vs. July 9, 2008&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#034;http://www.breakthematrix.com/node/10780&#034;&gt;Strangebedfellows! | BREAK THE MATRIX &lt;br /&gt;
    &lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;And three on 9/11 Conspiracies: &lt;a href=&#034;http://news.bbc.co.uk/2/hi/americas/7485331.stm&#034;&gt;&amp;quot;Third Tower Mystery Solved&amp;quot;&lt;/a&gt; (a better view shows the facts)&lt;br /&gt;
    &lt;/li&gt;
    &lt;li&gt;&lt;a href=&#034;http://www.scienceblog.com/cms/scientists-and-engineers-simulate-jet-colliding-with-world-trade-center-11483.html&#034;&gt;Simulation shows building damage by jet&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;How 9/11 Conspiracy Theorists were defeated&lt;/li&gt;
&lt;/ol&gt;
        </description>
      
      
    
    
    
    <category>Politics</category>
    
    <category>Security</category>
    
    <comments>http://theories.darwinsys.com:80/2008/07/17/1216348440000.html#comments</comments>
    <guid isPermaLink="true">http://theories.darwinsys.com:80/2008/07/17/1216348440000.html</guid>
    <pubDate>Fri, 18 Jul 2008 02:34:00 GMT</pubDate>
  </item>
  
  </channel>
</rss>
