139 karma · joined November 24, 2011
And then it might get resolved well...
Whilst limiting passwords isn’t good, with storage in that way i’m nt sure I see many viable attacks on a 12 char random password.
Online brute force will hit the lockout on the site, and even assuming you could get access to the server hosting the encrypted passwords and HSM you cant decrypt the passwords (unless they have made some horrific setup errors), so the only offline attack is to try and brute force the encryption key, which is unlikely to be easy.
One example i use is an agent i deploy to kubernetes clusters to do some security scanning. The scripts are ruby and the image clocks in at 9MB compressed https://hub.docker.com/r/raesene/kaa-agent/tags/
It's not a perfect solution but it's an option to consider
The reason I disagree is that if you use something like gmail or outlook.com for logins/ password resets there Is a nasty potential problem which Is if the provider locks you out of your account you could be completely stuffed.
There have been cases of people losing access to their accounts because of ToS breaches in the past. If that account is your login account for other systems you could also lose access to those.
Might I suggest you take a break from the keyboard, perhaps go for a nice walk in the fresh air:)
Reinstalling an os is a technical task, which requires some knowledge to do effectively. Having been doing this for 25 years or so, I can safely say it's easier now than it used to be...
Seems a bit harsh to me... if Microsoft still occupied the same kind of dominent position they did 15 years ago it would be a different story, but now there are a lot more viable alternatives
Can you provide any citations for the assertion that Microsoft are currently (2016) forcing hardware companies to tie their products to Windows?
Several of these other platforms are already closed to one degree on another, with iOS probably being the most restrictive, so I'm not sure I see Microsoft as being dominent enough to warrant a claim of monopoly power any more
But Prince Charles isn't the head of state... So assuming that you're suggesting that this principle doesn't just apply to the head of state, where do you cut the line? Should everyone in the royal family be barred from expressing their opinion privately or publicly?
Finding sql injection requires active testing of the site which, without authority to test, may fall into a gray area of uk law about whether its in breach of the computer misuse act.
Now you'd hope the company will take this as intended, but some organisations will take being embarassed like this poorly.
You'd just build up a body of images of "person 1" then cross-reference with flight records till you narrow it down to only being one possible person who had been on all those flights...
So what would this achieve. Well having a "privacy reform" party candidate on all the ballots would draw attention to the problem, in that voters would see the name and potentially hear about the platform. Also getting on the ballots would be likely to draw some mainstream media attention (heck the Monster raving loony party gets attention in the UK when it's on the ballot at by-elections)
Then if the party actually gets a decent number of votes, it may persuade mainstream parties to change their positions. My feeling is that at the moment none of them think it's that important a topic, so aren't formulating policies on the topic.
Personally I think it's a good idea to try and do something about this now, as once the idea that PRISM etc are fine and accepted gets embedded into culture, the next steps are likely to follow (e.g. what the US seems to be seeing with DEA and other law enforcement areas getting access to data). How long would it be before your local police are trawling your smartphone GPS data to see if you were speeding...)
If the numbers in those are accurate it looks like write endurance shouldn't be a problem at least for any consumer drive. The estimate on that review was 12 years in a typical consumer setup, and I'd reckon that almost everyone would have replaced a laptop or PC in that kind of timeframe.
If the version headers are removed a manual attacker would have to try harder (make more requests) to attempt to identify whether the server software is a vulnerable version or not. this increases the opportunities for detective software controls (e.g. IDS) to detect the attacker and to potentially allow for defensive actions (e.g. IP blocking)
Also if a server version banner is present an at vuln. is discovered in that version its much more efficient for attackers to only hit known vulnerable versions and those can be mined from either things like shodan or the Internet census 2012 data.
A smart attacker would probably want to only hit known vulnerable targets to maximise the time before their attack is noticed and analyzed by defensive organisations and if you hit all servers, that'll include all the honeypots out there, making it more likely that your attack gets noticed and new signatures are pushed to alert/block it.