Archive for the ‘Articles’ Category

Sunday October 31, 2010 08:27

Global Security Challenge Finalists Announced

The Global Security Challenge will see companies from around the globe enter the finals for security innovation development funding.

Friday February 26, 2010 12:31

Password Security

There is an interesting investigation into an issue with a GoDaddy hosted website. The investigation touches on a number of different things but one of them is that GoDaddy stores passwords without hashing them.
I did my undergraduate computer science degree in the early 1970s and even then we were taught that passwords should always be hashed (we called them one-way-ciphers back then). Instead of comparing the actual password to whatever was typed, the typed password Read more…

Friday February 26, 2010 12:18

NIST Certified USB Drives Cracked

Three NIST certified USB drives (those from Kingston, Sandisk and Verbatim) have been cracked. It turns out that the protocol for communicating between the password checking software on the host, and the encryption engine on the drive itself was very naively implemented. A fixed string was sent from the host to the drive to indicate that the password had been entered correctly and so to unlock the drive. Of course, any other mechanism for sending Read more…