Julie188 writes "Windows 8 PCs will use the next-generation booting specification known as Unified Extensible Firmware Interface (UEFI). In fact, Windows 8 logo devices will be required to use the secure boot portion of the new spec. Secure UEFI is intended to thwart rootkit infections by using PKI authentication before allowing executables or drivers to be loaded onto the device. Problem is, unless the device manufacturer gives a key to the device owner, it can also be used to keep the PC's owner from wiping out the current OS and installing another option, such as Linux."
A collection of articles and resources of interest to the modern software developer
Your work is going to fill a large part of your life, and the only way to be truly satisfied is to do what you believe is great work. And the only way to do great work is to love what you do.
-- Steve Jobs
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
Wednesday, September 21, 2011
How Microsoft Can Lock Linux Off Windows 8 PCs - Slashdot
How Microsoft Can Lock Linux Off Windows 8 PCs - Slashdot
Monday, September 12, 2011
Kevin Mitnick Answers - Slashdot
Kevin Mitnick Answers - Slashdot
Last week, you asked Kevin Mitnick questions about his past, his thoughts on ethics and disclosure, and his computer set-up. He's graciously responded; read on for his answers. (No dice on the computer set-up, though.) Thanks, Kevin.
Thursday, August 11, 2011
MosBase: Grails Security - XSS Prevention using Html-Codecs
MosBase: Grails Security - XSS Prevention using Html-Codecs
There are so many applications out there that don’t care about Cross-site scripting (XSS) attacks.
Grails has a nice feature for fixing this basic XSS issue. All you need to do is set the default-codec to html in your Config.groovy
Monday, August 8, 2011
web development - The Definitive Guide To Forms based Website Authentication - Stack Overflow
web development - The Definitive Guide To Forms based Website Authentication - Stack Overflow
Please help us create the definitive resource for this topic. We believe that stackoverflow should not just be a resource for very specific technical questions, but also for general guidelines on how to solve variations on common problems. "Form Based Authentication For Websites" should be a fine topic for such an experiment.
Tuesday, August 2, 2011
Meet Comex, The 19-Year-Old iPhone Uber-Hacker Who Keeps Outsmarting Apple - Andy Greenberg - The Firewall - Forbes
Meet Comex, The 19-Year-Old iPhone Uber-Hacker Who Keeps Outsmarting Apple - Andy Greenberg - The Firewall - Forbes
“I didn’t think anyone would be able to do what he’s done for years,” says Charlie Miller, a former network exploitation analyst for the National Security Agency who first hacked the iPhone in 2007. “Now it’s been done by some kid we had never even heard of. He’s totally blown me away.”
Wednesday, May 4, 2011
Marlinspike's Droid Firewall Kills Tracking - Slashdot
Marlinspike's Droid Firewall Kills Tracking - Slashdot
mask.of.sanity writes "The first dynamic Android firewall, dubbed WhisperMonitor, has been released by respected security researcher Moxie Marlinspike. The firewall will allow users to stop location-tracking apps and restrict connection attempts by applications. Marlinspike, whose company created the application, designed WhisperMonitor in response to the incidence of location tracking and malware on Android platforms. It monitors all outbound connection attempts by applications and the operating system, and asks users to permit or block any URLs and port numbers that are accessed."
Monday, April 11, 2011
Apple AirPlay Private Key Exposed - Slashdot
Apple AirPlay Private Key Exposed - Slashdot
An anonymous reader writes "James Laird has reverse engineered the Airport Express private key and published an open source AirPort Express emulator. 'My girlfriend moved house, and her Airport Express no longer made it with her wireless access point. I figured it'd be easy to find an ApEx emulator — there are several open source apps out there to play to them. However, I was disappointed to find that Apple used a public-key crypto scheme, and there's a private key hiding inside the ApEx. So I took it apart (I still have scars from opening the glued case!), dumped the ROM, and reverse engineered the keys out of it.'"
Subscribe to:
Posts (Atom)