Archive for August, 2007

DefCon 15 wrap-up, shoutouts, plugs, etc.

Sorry for being late to the game on this one, you’ve probably already read several personal accounts and all the stories and headlines that originated from Las Vegas last weekend. For those interested, below is my experience at my first DefCon ever, and my first time to Las Vegas. I’ve been to ShmooCon earlier this […]

Getting started in lockpicking

This past weekend at DefCon, I had the opportunity to hang out with a couple people at the Lockpicking Village. I first met Deviant Ollam and Mouse and the crew back at ShmooCon. It was a lot of fun; I learned to break out of a pair of handcuffs in just a few seconds. Since […]

Full-disclosure debate gone mainstream (v. terrorism)

Today I came across a news article in reply to a question asked by Steven D. Levitt, “If you were a terrorist, how would you attack?” The blog posting has struck controversy among many people, and it just reminds me of all the full-disclosure debates we have had in the security industry. Does spelling out […]

Security Tools for OS X — DenyThumbDrives

The other day I posted about a problem regarding the default behavior under OS X, which ignores permissions for mounted firewire drives. I decided to look for a solution to this rather than relying on administrators to set the proper option. What I uncovered is a nifty tool called DenyThumbDrives that allows you to […]

Insecure Permissions on Firewire Hard Disks - OS X

When you mount a firewire hard disk under OS X it will mount with the ‘Ignore ownership on this volume’ option set. What this means is that owner information and file permissions will be ignored. Apple does this so that you can share a disk across multiple systems that may not have the […]