clinicallyawesome

Nikon D90

I got my first DSLR and I’m having a blast with it. On my third day with the camera I managed to get some awesome shots:

From Random
From Random
From Random

I think they’re awesome, at least. I’m having fun with it.

clinicallyawesome

Got Froyo on My Incredible

This morning I found that Froyo was available for my Incredible. =D

After the update, I found that the crapware previously available in the Verizon section of the Market was “preinstalled”. D=

Granted, I haven’t tried VZ Navigator so maybe it’s super awesome. But the reason I’ve never tried it is because Maps works great and I have no need… for any of this software.

clinicallyawesome

High-Def for the Internet

I think I missed my calling in Marketing/PR. If we want to sell people on IPv6, here’s the slogan:

IPv6: It’s High-Def for the Internet.

True to the spirit of Marketing/PR, I make no statements about the truth of my slogan.

clinicallyawesome

Guerilla Feature Request

You want a feature in a piece of software but you don’t want to implement it yourself. Luckily, you have access to the repository.

Don’t bother actually working on the feature. Don’t bother putting in a feature request. Instead, add a unit test that checks for the feature and check that in. When the software starts failing unit tests the maintainers will have to decide to toss the test or fix the test by implementing the feature. This would be slightly more effective if the checkin included other tests that were actually useful.

I think this may be apex of Test-Driven Development.

clinicallyawesome
“Web 2.0 has killed all the bullshit gatekeepers and put us directly in touch with the bullshit authors.”
clinicallyawesome

Rode to Work

This time it was 19:40 in to work. I haven’t been sleeping well so I haven’t been riding. I need to get back on the horse.

clinicallyawesome

Bogus Log Generator

I wonder what the legal implications might be of a framework that makes it easy to create generators for bogus but convincing log data.

Prosecution: “Your honor, I present to the court computer logs that show that the defendant participated in online activities for which he is charged.”

Defense: “Your honor, I present to the court computer logs that are completely falsified but are completely indistinguishable in form from the logs presented by the prosecution.”

Flying Monkies, GO!

clinicallyawesome

Rode to Work

Actually, I’ve ridden to work about five times since I last posted about it. Totally different route now.

  • Distance: 4.4 miles
  • Moving Time: 18:09
  • Riding Music: Bassnectar - Mesmerizing the Ultra

I think the time is a personal best but I’ve only tracked it with the GPS twice now. Good riding music, but a little bland for my taste. Would be appropriate to play in a gym where they have that special selection of music that sounds upbeat but isn’t actually exciting.

  • Moving Time Home: 19:45 - stuck behind a couple slowpokes.
clinicallyawesome

Anonymizer Universal on Anroid

While at Anonymizer I got to use Anonymizer Universal and I thought it was pretty sweet. It doesn’t take long with a packet sniffer on a popular public wireless access point to see that you have little protection if any without some sort of VPN. Anonymizer Universal is a commercial VPN service that protects your traffic on the local network and allows it to exit through Anonymizer. I got it working on my Android phone using a little hand-configuration. This doesn’t require the phone to be rooted/jailbroken; it’s part of the standard functionality. Note that while it works, it’s not a supported platform…

clinicallyawesome

I'll Be Here All Week

  • Raffy: I'm quite surprised BP's networks aren't getting a "Free of charge" penetration test right about now
  • crunge: maybe they are
  • crunge: Raffy: however, if there are any security holes....
  • crunge: anyone?
  • crunge: not
  • crunge: getting
  • crunge: successfully
  • crunge: plugged.
clinicallyawesome

No Longer With Anonymizer

I guess this is a bit late but it shouldn’t be Earth-shattering news to anyone. April 30th was my last day at Anonymizer. I had never before been in the position of leaving a job I liked but an opportunity fell into my lap that was too good to pass up. I’ve taken up a position as a security engineer at a Fortune 500 company in the Silicon Valley area that’s doing a lot of interesting things and has a lot of interesting challenges to wrestle with. As such, I had to relocate to the valley which, aside from moving away from my friends and family, was an exciting proposition.

There are a few things I’d like to say about Anonymizer. First and foremost is that they really are passionate about people’s privacy. Lots of people have said that it’s the perfect place for the government to back door to spy on us citizens. While that’s an accurate observation, at the time I left there was no back door, no special eavesdropping equipment or privileges for anyone, and no plans for those things to change. Unfortunately I can’t go into further detail without risking disclosing proprietary information. I believe in the products I used, Nyms and Anonymizer Universal, enough to continue using them to protect my privacy.

I would also like to mention that Anonymizer was a really interesting place to work. If you’re in the San Diego area and you think you know your stuff when it comes to networking, Linux, etc, it’s worth shooting them your resume.

Anyway, new beginning for me. This is the first time I’ve done security as the focus of my job rather than something orthogonal to my job. I expect I’ll have a lot more security stuff to talk about fairly soon. I was in the San Diego area for 12 years and while I liked it I’m excited to explore a new city. I expect to enjoy doing a lot of touristy stuff without having a short vacation window to explore the bay area.

clinicallyawesome

wepwn

Some months ago I wrote a couple scripts to capture the workflow of cracking WEP. Essentially you could use the scripts to scan for targets and then specify the target to attack by ESSID or BSSID.

I came into a situation where I needed to learn python so I consolidated those scripts into a single python script and that is wepwn. It was developed on Backtrack 4 but may work on other Linux distros without modification.

I was reluctant to release it without much testing but it’s not going to get much testing in my environment beyond what I’ve done. I’d appreciate feedback, bug reports, or patches. Enjoy.

clinicallyawesome
Our Savannah Monitor died today.

I’m sorry, ‘zilla.

Our Savannah Monitor died today.

I’m sorry, ‘zilla.

clinicallyawesome

UK to Kill off National ID Card Program

Way to go UK!

clinicallyawesome
Two dads are better than none.

Yes!

Two dads are better than none.

Yes!