50 karma · joined October 9, 2013
Honestly this release might be a little early for IBM as well. Any sort of verbose error message is at least a low risk information disclosure finding on a pentest and a verbose database error message is a strong indicator the application is vulnerable to SQL injection. Even if not vulnerable, it's blood in the water and should be fixed before hitting production.
[1]http://www-01.ibm.com/support/knowledgecenter/SSATW2_7.3.0/c...
I am not the first to point out that it is stupidly easy to bruteforce passcodes that are based on digits (like many phone passcodes are). The FBI lamenting unbreakable phone encryption and the accompanying media buzz borders on farcical and is disingenuous given that there is still a backdoor on the iPhone[1] on port 62078. Am I missing anything?
Now I'm curious of the methods of decrypting data in transit. Does the NSA have the tools to break PKI based encryption at 1 trillion guesses/sec? I have some wild guesses, but if anyone knows I'd love to hear it.
[1]http://lists.gnupg.org/pipermail/gnupg-users/2010-October/03...
NTLM - 1.2 billion/sec
MD5(Wordpress)- 600 million/sec
bcrypt - 1,000/sec
1 trillion hashes/sec on a key stretching algorithm like bcrypt would be pretty horrific and might require quantum computing, while the same performance on MD5 might be achieved with <50k in hardware (very rough estimates).I've heard rumors of storage technology that can store thousands of petabytes in a home appliance form factor. With that can kind of storage it would make sense to just start making salted rainbow tables. Even without fabled hardware, the Bluffdale NSA facility might have the capacity for it. I haven't even done napkin-based calculations yet to see if this is possible, so if anyone has some idea please speak up :-)
edit: formatting
With this in mind I've wondered what would happen if,say, 100% of the proceeds from asset forfeiture went to ALS. I expect ALS would benefit very little but at least it would save thousands of people from having their assets stolen by the police. It turns out I'm not the first person to have this idea. The Fifth Amendment Integrity Restoration Act (FAIR)[2] seeks to remove the profit incentive and conflict of interest from civil asset forfeiture (along with some other good ideas). There have been other attempts for reform in various states, but FAIR has a lot of potential to change things at the federal level.
1-https://www.ij.org/asset-forfeiture-report-california 2-https://www.govtrack.us/congress/bills/113/s2644
Now that I'm thinking about it transparent bridge mode might do the trick as well.
While you still have the Q1000, be sure that you have the remote interface disabled and use the NoScript browser plugin. Those two items will mitigate a lot of the risk.
I replaced my Actiontec Q1000 with a used Zyxel Q1000Z I got for $30. I haven't had time to assess the Q1000Z yet, but it does not have any known 0-day vulnerabilities.
As the article says the manufacturer has acknowledged the vulnerability, but I have not heard from them for quite a while. I've begun to wonder how much time has to pass without a fix before it would be irresponsible of me not to fully disclose the vulnerability. Lately I've been thinking that full disclosure may be the only responsible way to disclose a vulnerability. But I am still conflicted.
Self Determination Theory (SDT, http://www.selfdeterminationtheory.org/) has a few ideas on how to answer this question. SDT provides some tools to deconstruct the concept of self esteem.
Traditional self perception is mainly concerned with a healthy self esteem. Under this paradigm it is only natural for people to regularly evaluate themselves by looking at past success/failures and by comparing themselves to others.
SDT provides an alternative to the traditional "self as an object" approach with a "self as a process" approach. While someone operating under the "self as an object" approach may ask themselves "Am I a good person? Am I worthy?", under SDT other questions like "Am I making good choices?" are much more important. This allows a person to view their own actions more objectively. Past mistakes are more readily available to be acknowledged and used to inform the future since they do not implicate an individual's self worth.
The book Mindset (http://www.amazon.com/Mindset-How-Fulfil-Your-Potential-eboo...) by Carol Dweck draws on a lot of SDT foundational concepts. The premise of the book explores and contrasts two mindsets: the static mindset and the growth mindset. If someone with the static mindset gets easy A's in school they take it to mean that they are smart. If someone with the growth mindsets get's easy A's it feels like a waste of time because it's not challenging. The author also discusses the benefits of praising a child's effort rather than just telling them how smart they are. It's a huge topic and I'm barely scratching the surface, but I think I've shown the top of this particular rabbit hole.
I still struggle with leveraging my failures constructively, but I have found learning about these concepts has enriched my life and helped me discover a hacker's mindset.