<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>It-Security on Flying Upside Down</title>
    <link>https://crazypigeon.net/tags/it-security/</link>
    <description>Recent content in It-Security on Flying Upside Down</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Wed, 04 Oct 2017 02:55:25 +0000</lastBuildDate>
    <atom:link href="https://crazypigeon.net/tags/it-security/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CCleaner malware outbreak is much worse than it first appeared</title>
      <link>https://crazypigeon.net/2017/10/04/ccleaner-malware-outbreak-is-much-worse-than-it-first-appeared/</link>
      <pubDate>Wed, 04 Oct 2017 02:55:25 +0000</pubDate>
       <guid isPermaLink="false">https://crazypigeonblog.wordpress.com/?p=47</guid> 
      <description>&lt;p&gt;&amp;ldquo;The recent CCleaner malware outbreak is much worse than it initially appeared, according to newly unearthed evidence. That evidence shows that the CCleaner malware infected at least 20 computers from a carefully selected list of high-profile technology companies with a mysterious payload. (credit: Talos ) Previously, researchers found no evidence that any of the computers infected by the booby-trapped version of the widely used CCleaner utility had received a second-stage payload the backdoor was capable of delivering.&amp;rdquo;&lt;/p&gt;</description>
    </item>
    <item>
      <title>[$] Antipatterns in IoT security</title>
      <link>https://crazypigeon.net/2017/09/19/antipatterns-in-iot-security/</link>
      <pubDate>Tue, 19 Sep 2017 04:23:46 +0000</pubDate>
       <guid isPermaLink="false">https://crazypigeonblog.wordpress.com/?p=24</guid> 
      <description>&lt;p&gt;Lots of interesting talk about the fundamentals of a secure system and it&amp;rsquo;s applications to computers.&lt;/p&gt;
&lt;p&gt;Quote I liked (empahasis mine):&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The most basic security antipattern is to &amp;ldquo;do nothing&amp;rdquo;. That means accepting any and all risk, though. Another is to &amp;ldquo;do it yourself&amp;rdquo;; that leads to thinking the system is secure because of custom elements, such as non-peer-reviewed cryptography algorithms or implementations and security through obscurity. &amp;ldquo;Hand-rolled&amp;rdquo; security systems have not fared well over the years—developers have learned that implementing stream ciphers, for example, should not be tackled in-house. But there is still a fair amount of security by obscurity, such as &amp;ldquo;super unguessable URLs&amp;rdquo;. &lt;strong&gt;If a product becomes successful, which is what you want, the unguessable will become all-too-guessable.&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
