Archive for April, 2008

An update on Protocol hopping covert channels

At last year’s Blackhat US 2007, the dominant discussion was around Joanna Rutkowska and Alex Tereshkin’s “New Blue Pill” vs. Peter Ferrie, Nate Lawson, and Tom Ptacek’s VT-x Rootkit Detection techniques.  This included some follow-up material on the Matasano blog including Side-Channel Detection Attacks Against Unauthorized Hypervisors and some confusion by Rich Mogull which led […]

CERT on Securing your web browser

‘Lo and behold, CERT has an excellent document on Securing your web browser!  They cover IE, Firefox, and Safari — three secure references for the three most popular browsers.
The documentation and links provided are great.  I was actually surprised that they covered quite a bit of important topics and that the recommendations they gave are […]

New blog over at Neohapsis Labs

The fine folks over at Neohapsis Labs appear to have a new blog focused on security related information.  Technically, I guess they’ve had it up since January, but the posts are more frequent now.  I just added them to my RSS feeds.
Both Mike Murray and Cris Neckar have posted some interested tidbits ranging from technical […]

Privacy, Google, Scroogle, and You

In an article on the CNet Blogs, Chris Soghoian writes on Privacy: What should Google do?
Brilliant article.  A must read.
I have one question, one comment, and one look into the future.
Question: We might be able to trust Scroogle not to steal our search queries and tie them to an individual (i.e. an invasion of privacy), […]