Wednesday, March 06, 2013

HOWTOFAIL: ENTERCARD

[This is bad, and this is just the beginning of this blog post...]

Update March 29, 2013: SSL config is now at grade A! Congratulations!

Remembercard 
(brandname) is issued by Entercard, a joint venture between Swedish Swedbank and Barcleys Bank Plc. The irony of a credit card company not having a PCI-DSS compliant website is amazing. The lack of knowledge concerning users' selection of PIN codes is obvious, the lack of proper security for e-mail based marketing is shocking.

I hope this blog post will be read, understood and acted upon properly ASAP by those in charge.



Tuesday, February 19, 2013

Step 1: Securing My E-mail


The hacking of Mat Honan scared me. A lot. While there was no "advanced hacking" involved, the attackers found data across multiple services, which when combined enabled them to gain access to one service after another through password resets.

It really made me think about my own mail accounts (I've got quite a few of them), and how they are secured. I didn't really know, so I thought I should have a look. This is part 1. With more to come, this is my summary here. Make a guess for which one I prefer here:
[Click for full size]

Wednesday, February 13, 2013

Kjære Dataforeningen

Kjære Dataforeningen.

I dag skulle jeg melde meg inn i Dataforeningen. www.dataforeningen.no, og linken "Bli medlem".

Første observasjon: Linken går til en HTTP side. Ved å taste inn https i adressen kommer jeg til samme siden, men denne gang slik det skal være med HTTPS.

Det stopper dessverre ikke der, og det jeg ser er dårlig praksis. På grensen til ren slurv, eller en webtjeneste som er forsømt i mange år på driftssiden er min påstand.

Thursday, January 31, 2013

Kjære BankID

Vi er nok ikke verdens beste venner, jeg er smertelig klar over det. Bruken av Java, sentrallagret PKI som strider mot etablerte prinsipper, BankID på mobil som bare fungerer med noen operatører & modeller, samt diverse andre problemer... jeg nevner i fleng.

Likevel er jeg frekk nok til å komme med et veldig enkelt endringsforslag som kan gjøre brukeropplevelsen *litt* bedre ved innlogging i nettbank fra PC.

Thursday, January 24, 2013

Skryt til blogg.no

[Logo elegant kopiert rett fra blogg.no...]
Updated post - english summary at the bottom.

"Jeg er streng, men rettferdig."

Ordene sitter fortsatt spikret, over 20 år etter rekruttskolen. Fantastisk troppsjef, og jeg forsøker å leve opp til de ordene. Nå skal jeg gjøre noe jeg ikke har gjort før: jeg skal skryte av en rosablogg, nemlig blogg.no. For å være helt korrekt; jeg skal skryte av firmaet Bootstrap AS som står bak tjenesten.

De har på svært kort tid fikset det jeg anså som svært alvorlige sikkerhetssvakheter, etter at jeg sendte dem mail om det. Her er historien:

Friday, January 18, 2013

Tees. With comments.

It's Friday, and I'm kind lazy today, so I thought I would put up pictures of the T-shirts I made for myself for Passwords^12, and a short explanation for each of them. (Media archives right here, videos also available on youtube).


Monday, January 07, 2013

Security issues with MSXML


This is a quick & dirty blog post, partially to help a friend reach out to the world, and partially because I'm affected as well. Correction: was affected. Now removed & patched at the same time.

At my previous job one of my tasks was to manage & improve the security patch management process across all platforms, from operating systems and databases to browsers & plugins. Sometimes even down to firmware & driver updates, because of bugs and vulnerabilities. My primary focus was - no surprise - Windows installations and pretty much everything that can be installed on Windows. I did that for more than 5 years. 10-15K servers, 100-150K clients. I did well. Very well in fact, and I'm still proud of it.

Many surprises have appeared along the way, the most recent has to do with MSXML, which comes to light in this blog post.

Thursday, January 03, 2013

Facebook Poke vs Snapchat - Security Comparison

Facebook Poke vs Snapchat - on security.
@adamcaudill got me started with his tweet + blog post about some of the lack of security in Snapchat, and I just had to take a look. After hammering Snapchat for a while, I thought I could do a security comparison to Facebook Poke, their own app that does pretty much the same thing as Snapchat. If you want to see a feature comparison, take a look here at techcrunch.

While Adam does the crypto + API stuff - the inner workings of the Snapchat app - I'm more interested in the visible password stuff. And before we start talking about financial muscles, size of organisation etc between Facebook & Snapchat.... It doesn't take a giant to make good security. (Rather on the contrary I would say.)

Tuesday, January 01, 2013

Måling av reell verdi fra sosiale medier

Min Klout score Jan 1, 2013. Twitring er hovedårsaken til min score.

Jeg ble veldig nysgjerrig da +Hans-Petter Nygård-Hansen postet denne bloggposten: "Slik kan du måle din innflytelse i sosiale medier". Faktisk så nysgjerrig at jeg måtte sjekke meg selv. Jada, innrømmer glatt at jeg har et ego jeg også. :-)

Sunday, December 30, 2012

Passwords^12 - in summary

Yeah, I'm happy with that. :-)
Passwords^12 turned out to be an amazing event - although I'm not really neutral saying so.

Sorry for taking so long to come up with a few words after the conference. First there was the biochem warfare attack from you-know-his-name, then the total exhaustion after the conference, including video editing & uploading to Youtube & our media archive. I've been sleeping a lot during the past 2 weeks. :-)