KNOB Attack
The spec allowed 1 byte of entropy?!? What the hell were they smoking?
bluetooth  vulnerability  low  entropy  session  key  security  hacking  pentesting 
8 weeks ago by asteroza
So, fun thing Bloomberg did years ago, the B-Unit...
An updated generic version of the B-Unit as a yubikey alternative would be interesting...
bloomberg  security  card  2FA  private  key  optical  hardware  electronics  devices 
12 weeks ago by asteroza
How to BYOK (bring your own key) to AWS KMS for less than $15.00 a year using AWS CloudHSM | AWS Security Blog
Interesting, a one time import from CloudHSM to KMS to start you secret keys right, for those who need to do the HSM thing, then make a secure backup of the HSM in S3 to resurrect it if needed, then kill off the HSM
AWS  CloudHSM  KMS  migration  security  HSM  secret  key  generation  encryption 
may 2019 by asteroza
[SOLVED] Office 2019 - No MSI to install. How do I install it? - MS Office - Spiceworks
Read the comments about fixing the XML for VL 2019 standard, not retail ProPlus
microsoft  office  2019  install  standard  MAK  key 
february 2019 by asteroza
FIDO ®-Multi-Interface | FEITIAN
Looks like google's new Titan security key is an OEM Feitian multi, but allegedly with google built firmware (because Feitian firmware has had issues in the past...)
google  titan  USB  U2F  FIDO  NFC  BLE  bluetooth  security  key  hardware  electronics  devices  2FA  OTP  TOTP  authentication 
july 2018 by asteroza
Security Key Enforcement to Help Deter Phishing  |  Google Cloud
Google soon to be selling their own U2F/FIDO keys called Titan, in USB and BLE flavors. Yubikey not pleased...
google  2FA  U2F  FIDO  security  key  hardware  electronics  devices  USB  BLE  NFC  bluetooth 
july 2018 by asteroza
dgraph-io/badger: Fast key-value DB in Go.
has higher write performance for certain penalties in read
badger  key  value  store  database  noSQL  go  opensource 
june 2018 by asteroza
Security Settings for COM objects in Office
How to kill flash in office, don't forget the wow6432node keys to cover 64bit OS with 32bit office
windows  security  office  flash  block  registry  key 
june 2018 by asteroza
Bowley Lock Company
Interesting anti lockpicking design using an internal pin shield design
door  lock  padlock  slotted  key  security  hardware 
april 2018 by asteroza
Signed Malware
Implies the codesign certs and private keys leaked, which would be the older SHA-1 type that used files/exportable keys. That, or people using the newer dongle based SHA-2 codesign certificates were leaving the dongle plugged in, someone infiltrated the malware to be signed, performed the signature, then exfiltrated the signed malware back out of that company's build environment.
codesign  certificate  private  key  signed  malware  security  reference  information 
november 2017 by asteroza
B-Unit | Bloomberg Professional Services
A sort of beefed up FIDO U2F device, but with higher hardware protection features. Uses a photoreceptor to receive codes from the terminal screen itself, so no NFC/bluetooth/USB
bloomberg  terminal  authentication  portable  private  key  token  hardware  electronics  devices  security 
november 2017 by asteroza
Securing customer data with KMS and Envelope Encryption in Node.js
Interesting pyramid/stacked encryption model to encrypting data with per tenant keys, but the weak point is the AWS KMS stored master key
AWS  cryptography  stacked  envelope  encryption  federated  key  rotation  security  cloud 
october 2017 by asteroza
square/keywhiz: A system for distributing and managing secrets
interesting trick of allowing a FUSE mount of pseduo-files for accessing secrets to allow use with apps that can't handle this kind of secret management normally
security  vault  private  key  password  sharing  management  software  opensource 
september 2017 by asteroza
biokoda/actordb: ActorDB distributed SQL database
highly sharded distributed relational database, using SQLite backend. If you replicate the same thing to all nodes though, it effectively becomes rqlite though.
ActorDB  distributed  SQLite  RDBMS  database  sharding  key  value  store 
june 2017 by asteroza
yahoo/mdbm: MDBM a very fast memory-mapped key/value store.
Larry McVoy claims the version before yahoo fiddled with it was faster, and is in Bitkeeper?
MDBM  memory  mapped  key  value  store  noSQL  database  Delicious 
may 2017 by asteroza
dryman/opic: Fast serialization framework for C
Doing this in C because C++ results in runtime dependencies?
object  serialization  framework  hash  table  map  key  value  store  index  Delicious 
may 2017 by asteroza
Trialling Windows 10 Linked Clones with VMware Horizon View 7 | virtualhobbit
So the trick to faking KMS is setting composer to skip activation, then using a filler KMS key? But what about MAK's?
windows  10  VMware  view  horizon  7  license  activation  MAK  KMS  key  Delicious  skip  composer 
february 2017 by asteroza
Provisioning VMware Horizon View desktops fails with error: View Composer Agent ...
When you need to use a MAK key on a Horizon PoC, you need this, as it defaults to KMS activation otherwise
VMware  view  horizon  windows  license  key  MAK  activation  KMS  Delicious  composer  guest  VM  customization  error 
february 2017 by asteroza
dxa4481/truffleHog: Searches through git repositories for high entropy strings, ...
Good for hunting accidentally leaked AWS keys, but rumor is AWS is already hunting for AWS keys on github and disabling them so...
github  secret  key  high  entropy  string  search  engine  software  opensource  Delicious 
january 2017 by asteroza
