My boss (possibly soon-to-be former boss–the parting is amicable if it happens) has an interesting approach to buying cars. He pays cash for the car, then finds out what his monthly payment would be, and deposits that amount in a savings account for five years to pay himself back, with interest. Then he uses the money in that account to buy his next car. Read more
If you use a Linksys router, you need to drop everything now and upgrade it
If you own a Linksys WRT54GL or EA2700 router, both devices have serious security vulnerabilities. Serious enough that the only way to continue using them safely is to load an alternative firmware such as DD-WRT on them. That’s not entirely a bad thing; DD-WRT is more capable, and unlike most consumer-oriented firmware, allows you to disable WPS.
The EA2700, in particular, is so trivially easy to hack it’s laughable–all it takes is entering a predictable URL into a web browser. That’s it.
Putting right E.T. for the Atari 2600
The AMI BIOS breach of 2013
A security professional’s nightmare happened to AMI this week. Tons of confidential data, including the source code for the UEFI BIOS for Intel Ivy Bridge-based systems and an AMI-owned private key for digital signatures, turned up on a wide-open FTP server for all comers to download anonymously. This AMI BIOS breach has numerous implications.
The implications are nearly limitless. To a malware author, this is like finding a hollowed-out book at a garage sale stuffed with $100 bills with a 25-cent price sticker on the front. If you’re a budding security professional, count on being asked in job interviews why you need to protect confidential information. The next time you get that question, here’s a story you can cite.
Take a peek at Bill Gates’ pre-Microsoft resume
Bill Gates and Paul Allen posed for a re-creation of a famous early Microsoft photograph this week; at the same event, Gates’ pre-Microsoft resume surfaced.
Although it’s counterintuitive, AT&T’s new password policy makes sense
AT&T has a new password policy that forbids the use of certain common words in passwords, including some words of a colorful nature.
Yes, it reduces the number of possible passwords, but that isn’t exactly a bad thing.
Firefox 20 is out. I don’t blame you if you wait for 20.1.
I need to sync my haircut cycle with Firefox’s release cycle. It’s that time again. Version 20 is out, and it has some new features, but as frequently as dot-one releases follow new releases, I don’t blame you if you wait.
I usually update at least one of my machines right away, if only out of curiosity, but tend to let the others lag a day or two. Or a week.
How I once took down a network, including a radio station
I met up Monday night with some other security professionals for some emergency networking of the professional kind. One of the attendees, a penetration tester, had a little incident where he took down a production system when he conducted his penetration test. The system owners were a bit arrogant, and, well, they paid for it.
I’ve taken down a network too, but in my case it wasn’t something security-related. No, in my case, I was a 20-year-old desktop support technician working in a college computer lab, making an honest mistake.
Scratchbuilding, Marx-style
I saw a modern-production Lionel box car in a hobby shop one weekend. I wanted it, but I really wanted it in Marx 3/16 style, so it would look right with my Marx #54 KCS diesels pulling it. But I face very long odds of ever getting that car in Marx 3/16 unless I build it myself.
So I started building. And you can too.
What I learned about air travel by globetrotting back and forth to Baltimore and D.C.
In 2011-2012, I flew to Baltimore or Washington D.C. a lot–probably eight times, if not more. Internet pal Rob O’Hara wrote about his recent flight to Seattle this weekend; predictably, they lost his bags.
Here’s what I learned by getting to know the Baltimore area by plane.
