
I wonder what the combination is.
2012-01-14
2011-07-24
Lock Fail
Simplex-style pushbutton locks are ubiquitous in the medical industry. They're used on medicine carts, cabinets, lockers and doors. This is a cabinet that is designed to hold a thin-client workstation and/or patient record portfolios, and restrict access to ethernet ports.


Yep. You can open this one by sliding the exposed latch with your finger.
Labels: fail, lockpicking, locks, physicalsecurity
2009-10-12
On cloud computing
It seems everyone is blaming a general failure of cloud computing for the massive data loss that hit Danger, Microsoft and T-Mobile over the weekend.
From what I've read, a failed storage upgrade occurred without a good, solid backup in place. That sounds a lot more like a failure in backup, planning and design than a failure of cloud computing to me. Had the storage folks at my office made the same mistakes, that's what would have been said -- right before the human resources folks came to "have a talk" with the team.
It just so happens that T-Mobile's sidekick phones rely on a lot of back-end storage, so there's the whole "cloud" element to things. I'm not familiar enough with the Danger platform to know how easy it is to back up your own data, but I'd hope it's possible.
I think it goes for any service where you've entrusted storage of your data to someone else: make sure you back it up yourself, if you think it's important. The difference with the Danger/T-Mo disaster, I think, is that it was a lot less obvious to end-users that the data wasn't all stored permanently on the phone. Clearly, "cloud computing" was collateral damage in the wake of a much more mundane failure. The fact that it was completely avoidable offers little comfort for those affected.
Shifting gears: Along comes this piece on how e-mail is becoming less and less relevant.
The thing that separates e-mail as we know it from other messaging platforms is the fact that e-mail is decentralized. Using information stored in DNS, all Internet-facing e-mail servers can properly send mail to the correct server for a given address. IRC is another decentralized communication protocol. The days of decentralized infrastructure are fading fast, though, being replaced by walled gardens that want your constant attention, and many of them requiring a separate account and password. These walled gardens are supposed to be "the new way" of communicating.
You can't easily backup everything you've received through Twitter or Facebook, and the people who communicate with you there have to have accounts. Sure, anyone can get an account. What about Google Wave? Very few of the people I REALLY want to collaborate with have an account. So, while I do see a lot of value in these services for certain things, I don't think that any of them are quite ready to fill the roll that e-mail currently provides. Chiefly: if I have a local e-mail client running on my system, I don't need to suckle at the teat of the Interwebs in order to rifle through my data. It's right there, on my computer. Web mail has indeed blurred the line, but the good web-mail providers still offer mechanisms to back-up your data or use an offline mail client such as Thunderbird.
OpenID somewhat fixes the need to have multiple accounts and passwords scattered all over the web, but shifting authentication "into the cloud" just means that each OpenID account we have will be more catastrophic if compromised. OpenID is tantamount to using the same username and password everywhere, and we know how well that works for security.
How do you backup your cloud data? Well, for starters, you can try a native-client RSS aggregator such as Liferea. One thing that "Cloud" is doing is making syndication possible through ubiquitous RSS feeds. Backups won't work perfectly on every site, for example: you won't actually download all of the photos from Flickr with RSS, you'll only get links to them. It will nicely archive text content, though. This is good for things such as blog posts, twitter conversations and the like.
2009-09-18
Verizon Wireless customers: Privacy Fail
I got this lovely IED of Privacy Fail in my inbox this morning. See the circled text. It looks like we get opted-in by default! If you don't want to be sold and traded at Verizon's every whim, you should probably try to hunt this down or access the setting in your VZW account.
Update: According to Mike Fratto (@mfratto) it's old news. How long have we been opted in, anyways!? He points out in your account, go to VZW→My Profile→View/Edit Privacy(CPNI) Settings to change
2009-07-09
Not news: smuggling bomb parts into federal buildings
ABC News: Bomb materials smuggled into fed buildings
Federal investigators had no trouble smuggling bomb-making materials past ill-trained and poorly supervised guards at federal buildings, senators were told at a hearing Wednesday.The thing is that if you poke around the office supply closet and the broom room, you will undoubtedly be able to amass everything that's needed to wreak some serious havoc.
2009-04-08
Lock Fail
Actually, there are locks built into the doors of this roadside telecom cabinet (and they are locked), but these two chintzy padlocks have been unlocked like this for the past few days. I'm not sure what the deal is here, but I chuckle every time I pass it.
Labels: fail, locks, physicalsecurity, wrong
2009-02-09
Hacking Sleep (or why a 'bedtime' is over-rated)
HiR's response? "Go to bed earlier!"
2009-01-27
Fake Hacking: You're doing it wrong
As seen on Fringe this evening. That's supposed to be an IP Address.
At least they could have used an RFC 1918 Non-Routable Address.
2008-12-31
Zune doesn't like leap years
GenesisWave pointed this out on the Cowtown Computer Congress mailing list.
Q: Why did this occur at precisely 12:01 a.m. on December 31, 2008?
There is a bug in the internal clock driver causing the 30GB device to improperly handle the last day of a leap year.
What a riot. Well, your Zune will work tomorrow. In the meantime, check out i-Hacked.com's Zune Fix. They had the first working walk-through I saw.
2008-12-27
You're Doing It Wrong: Whiteboard Security
Smart whiteboards can take what's drawn on them and print them, store them, e-mail them and a whole variety of other fun things. Panasonic is bringing password protection to these features. [Via Engadget]
...The film and steel boards look pretty traditional at first glance, but underneath of that plain jane facade is a highly advanced security system. You see, each board can accept passwords, which will in turn restrict the ability to transfer information from the board to USB flash memory. For those cleared for access, the whiteboards can transfer on-screen information to a PC via USB, though we suspect you'll have to handle the encryption on your end. 'Course, neither of these will run you cheap, but you know your underground supervisor won't mind shelling out upwards of two large to make sure schematics to rule the world aren't intercepted by meddling rivals.of course, you can practically