If you haven’t yet read that the Department of Homeland Security found a critical flaw in X11, you have now. The flaw is pretty simple: if (getuid() == 0 || geteuid != 0) should have been if (getuid() == 0 || geteuid() != 0) This is one of the stupidest errors I have seen in a long time. GCC would have even mentioned that it was a warning! If someone had bothered running RATS or Splint, they probably would have picked it up. You didn’t need Coverity to find it. Programmers are under a lot of stress, but that doesn’t excuse them from doing basic checking on their code. At least *start* with a warning free compile.
Category: software
I was recently listening to the radio and heard the technology guru talking about Carbonite. I’ve also recently heard mention of Mozy. Both of these are fully automatic online backup solutions which, once you install, back up every file written to your disk. Carbonite even keeps previous versions of files (and deleted files) for 30 days after modifications were made, just in case the problem is not corruption or loss, but user error. Both services encrypt the files on the PC using Blowfish before transmission; typically with a key that is generated by (and archived by) the service. Mozy has, and Carbonite is planning to release, the capability of using your own encryption key which is not archived by their[…]
The Portable Document Format (PDF) standard is a good way to store documents that need to be accessible to multiple platforms. The standard provides formats for the display of many types of data, such as text, images, interactive forms, and multimedia content. The PDF standard also provides for security capabilities, including file encryption and digital signatures. The digital signature capability makes the PDF format very attractive for businesses that require an accessible, strong method of authentication for document workflows. There are currently several open source libraries available for converting documents to PDF format, parsing existing PDFs, and even allowing access to some of the inner attributes of PDF files. Most of them also support the encryption capabilities defined by the[…]
Had a customer come to us with an interesting question. Deep in the Outlook settings for connecting with Exchange, they found this option: (click to enlarge). Now what was this encryption supposed to protect? What algorithm(s) are used? Who manages the keys? Why aren’t these boxes checked by default? It seems that the Exchange 2000 Resource Kit had some of our answers. Encrypted RPC uses a 40-bit RSA algorithm called RC4 to encrypt data while it is on the network. You can configure Outlook to use encrypted RPC so communication between clients and servers is secure and no users can tamper with messages during transit. Exchange 2003 seems to allow you to improve on the limited security of 40-bit RC4[…]