You are viewing a read-only archive of the Blogs.Harvard network. Learn more.
Skip to content

Monthly Archives: December 2006

More commentary on the TSA Security Theater

Bruce Schneir is a security critic, businessman and all star crypto-expert who has been following the “boarding pass hacker” story. In a recent NYT article he offers the following on disclosure and I think it maps quite nicely to what I’ve been considering for the vulnerability research paper I’ve been helping out on. ” ‘Why […]

Interesting Web Exploit Technique

Today I found another old example of how web site operators are using browser based exploits to infect “drive by” browsers. If a user goes to the site I found today using a vulnerable browser an Iframe will deliver an advertisment which contains javascript encoded download instructions for exe’s. Observe function Go(a) { Log(‘Creating helper […]

BeanSec! December 20th 6-9pm…

We’ve now established a regular schedule for the BeanSec! events; the third Wednesday of each month. So you can mark your calendars now for December 20th at 567 Massachusetts Ave. Upstairs at the Enormous Room from 6-9pm. For the uninitiated: BeanSec! is an informal meetup of information security professionals and academics in the Cambridge/Boston area. […]

pirate bay strikes back

I found this to be a unique form of protest by Swedish site The Pirate Bay. they are opposing the tactic of a swedish isp who has decided to block it’s customers from accessing allmymp3.com. I won’t go into a long diatribe about the merits of imposing restrictions on your customers. I will however share […]

Beansec now on a regular schedule

Andy J had a really good point. Beansec was just too unpredictable to make plans for and our erratic releases of information were just a little *too* spontaneous. So to appease him and the good folks at Matasano The Chris’ and I have decided that all future Beansec events will occur on the Third Wednesday […]