Tiffany B. Brown

a mish-mosh of stuff

Posts tagged: Security

Big brother is Google
One reaction is to diversify: Hotmail instead of Gmail, MapQuest instead of Google Maps, AOL Instant Messenger instead of Google Chat ’ though that would mean losing the accumulated benefits of linked services. Another reasonable response is to focus efforts on improving our (new) media literacy so that we’re more mindful of how much even [...] [18 Feb 2010]
To password mask or not password mask?
That is the question Jakob Nielsen sparked with last summer’s column: Stop Password Masking. In this week’s A List Apart, Lyle Mullican discusses The Problem with Passwords, and writes: However, making such a sweeping change to a fundamental user interaction could present serious problems. Consider some contexts in which a password might need to be [...] [9 Feb 2010]
Security vulnerability found in WordPress; Upgrade to 2.6.3
News of a vulnerability in the Snoopy open source PHP library has surfaced. WordPress uses the Snoopy library to power feeds in administration section’s Dashboard. A fix — WordPress 2.6.3 — was released today. You can download the entire package, or just download the two affected files and upload them to your server. [23 Oct 2008]
What I’m reading: Privacy, security, pervasive technology and society
I’ve been thinking about pervasive technology, society, macroeconomics, the Internet, control, our environment, our mass delusions surrounding privacy, and the efficacy of voting this morning. They’re seemingly unconnected, and yet very connected. I like to think that I am an above-average user of technology by American standards. And yet, if I am overwhelmed by the [...] [1 Aug 2008]
Trusting Anil Dash not to f*ck up my site with evil JavaScript
Below is a snippet of an entry from Anil Dash‘s blog on the possibilities of using embed, object and JavaScript for serving all kinds of content — not just movies. The obvious question is ‘How much should you trust code from strangers?’ And can this be done in a safe(-ish), secure(-ish) way? Possibly related: Cross-domain [...] [14 Mar 2008]
Sniffing users’ browser history and Firefox extensions to stop it
Go read Niall Kennedy’s post about using JavaScript to sniff a user’s browser history. It’s an inventive use of your user’s browser history, though I suspect it could potentially be used — in combination with cookies and logins — to detect which of your users are also regular porn surfers. With that little bit of [...] [8 Feb 2008]
TrueCrypt now available for Mac OS X
With its latest version, TrueCrypt has released a version for Mac OS X. OS X comes with its own encryption feature known as FileVault. But in my experience, FileVault can cause some performance issues. If you don’t regularly log out of your machine, you may find yourself running out of hard-drive space faster than you [...] [6 Feb 2008]
Damn … my VPS is being cracked
UPDATE: What appears to have happened … Yeah, as I type this, I’m getting hit with an attack. I’m not precisely sure of the motive. I just know that there are two directories on my server that should not be there and the attack appears to be coming through a specific URL. It’s been happening [...] [7 Nov 2007]