bk99.de entertain the web since 1997

Blog 2011

19 posts

Projects, Linux, networks, systems, finds and internet standards from 2011.

Linux on a DE0-Nano FPGA

Hackaday follows a detailed guide that brings together uClinux, a soft-core processor and custom LED hardware on the DE0-Nano. The DE0-Nano cost about 80 to 100 US dollars at the time. The guide used Fedora 14 as the build system.

Read the full post

UEFI Secure Boot: Why signed firmware could lock out Linux

Shortly before Windows 8, Matthew Garrett explains the key model of UEFI Secure Boot and warns that computers with only OEM and Microsoft keys will no longer boot a generic Linux. According to Garrett’s analysis, signed Linux versions fail because of GPL bootloaders, self-built kernels and the lack of a central signing authority. The assessment: it is too early to panic, but not too early to be concerned.

Read the full post

Insecure factory settings in Wi-Fi routers from T-Online and Vodafone

In 2011 many routers from Telekom and Vodafone came with a preconfigured WPA key that was in some cases derived from the MAC address of the Wi-Fi interface. Attackers could capture the MAC address and use it to guess the key. Looking at almost 14,000 access points, the students Stefan Viehböck and Manuel Müller found that 17 to 25 percent still used a default Speedport or EasyBox SSID, presumably mostly with the default key.

Read the full post

Securing Linux and BSD servers properly

Philipp Pobaschnig shows why default installations are not a finished security strategy and how small, systematic changes close typical attack paths. Server hardening is a recurring operational process rather than a one-off checklist. The most secure feature is often the service nobody had to install.

Read the full post

RFC 6265: HTTP cookies: State on the web

RFC 6265 unifies cookie syntax and browser behaviour for session-related state over HTTP. Automatically attached state makes applications easier and increases CSRF and tracking risks. Secure defaults matter more than policies added later.

Read the full post

New features, known security hole

In January 2011 ICQ 7.4 appeared with an improved chat history, better Facebook integration and notifications of new mail from Gmail, Yahoo and Mail.ru. Users could switch faster between chat, SMS, voice and video calls. However, the developers had not fixed a known security hole in the auto-update function.

Read the full post

8 June is IPv6 Day

Facebook, Google, Yahoo, Akamai, Limelight and the Internet Society declared 8 June 2011 World IPv6 Day. For 24 hours they wanted to offer their main services over IPv6 as well, in order to test the infrastructure under real load. According to Google, only about 0.2 percent of users could use IPv6 at the time, while the last large IPv4 blocks were being allocated.

Read the full post

Piwik 1.1 closes critical security holes

In January 2011 the free web analytics software Piwik appeared in version 1.1 with security holes closed. As a precaution, the developers had commissioned Stefan Esser’s company SektionEins with a five-day review of the source code. Its hardening advice was incorporated into the new version.

Read the full post