The Command Line

Podcast and blog exploring digital citizenry as a creator and a consumer.

Skip to: Content | Sidebar | Footer

The Command Line Citizen

Category: Security

Diebold Gives Away Accuvote Key

23 January, 2007 (16:24) | Hacktivism, Security | By: cmdln

This is just too funny. I haven’t had a belly laugh at Diebold’s expense lately. Thanks, Professor Felten and Ross Kinard.
If Diebold wasn’t already under massive scrutiny and the state of evoting more broadly wasn’t being so actively scrutinized and discussed, this might be ever so slightly more forgivable even if still inexcusable [...]

Schneier on SHA-1 Story

22 January, 2007 (20:46) | Security | By: cmdln

I am so glad he provided archive links in his admittedly short comment on the slashdot story. He’s standing by what he said, in terms of this being an important result but not as severe as the story in question made it sound. His archived pieces also remind us that in many ways [...]

More AACS Details

18 January, 2007 (17:15) | Hacktivism, Security | By: cmdln

I guess the details that Felten explains are perhaps what drives the supposition that rights holders might express the sort of strategic thinking the previous piece in the series suggests. We haven’t seen any evidence of that shrewdness in practice, though, so the idea has to originate from *somewhere*.

Gaming the AACS Black List

12 January, 2007 (11:23) | Hacktivism, Security | By: cmdln

J. Alex Halderman has posted the next in the series of discussion of the AACS crack. I am utterly fascinated, especially by the counter intuitive aspects. It is going to be very interesting to see how closely the actual black listing matches the theories and predictions. I don’t typically credit the content [...]

Details on AACS Black Listing

11 January, 2007 (21:18) | Hacktivism, Security | By: cmdln

J. Alex Halderman has post the promised details in the series of explorations of AACS over at Freedom to Tinker. I am a bit surprised by the sophistication this seems to suggestion was designed into AACS. I guess the content industry learned their lesson with CSS and DeCSS. I wonder if, like [...]

More AACS, BackupHDDVD Details from Ed Felten (Update)

10 January, 2007 (18:46) | Hacktivism, Security | By: cmdln

Just wanted to post a pointer to the first detailed posted by Professor Felten that he promised on the subject. Haven’t even had a chance to read it, yet.
I’ve read this and here are some of my thoughts.
I would not so readily discount people’s willingness to transcode from the native HD format to DivX [...]

Ed Felten on BackupHDVD (AACS Crack)

8 January, 2007 (21:23) | Hacktivism, Security | By: cmdln

Nice to see my understanding of how this crack works has been validated by Professor Felten and his commenters. I tend to agree with him, rather than those claiming this as a non-event, though I am call and reserved in that agreement. As I mentioned in the podcast from the 7th, regardless of [...]

NYT Coverage of Botnets

8 January, 2007 (21:17) | Security | By: cmdln

Not surprisingly, the emphasis of the NYT coverage is on the impact on the commercial aspects of the internet. Secondarily, they bemoan the failure of security vendors to solve the problem.
I am glad they are covering such an important issue but I am afraid it doesn’t do a good enough job informing those it [...]

PayPal Virtual Debit Card

27 December, 2006 (14:29) | Security | By: cmdln

I cannot tell if PayPal’s new virtual debit card is really any more secure than any other form of online transaction. No, seriously, it’s apparently Windows only, working with MSIE 5.01 and later. Even though I have access to a virtual instance of Windows, I refuse to use MSIE for any personal surfing, [...]

More Extortion-ware (Not Really)

13 December, 2006 (17:05) | Security | By: cmdln

Well, not really since this does not appear to be an automated attack, rather a manual and specific one. Also, hello, “cyber cafe”? I am not sure that this constitutes a new form of hijack, but is rather a single case of blinding naivete.
I am worried about the dangers of automatic filling of [...]