similar to microsoft's banned.h used during Vista's development as part of their secure development lifecycle work. Basically lots of unsafe string function marking.
may 2019 by asteroza
Standards for a highly secure Windows 10 device | Microsoft Docs
New MS minimum specs for high security Windows 10 setups. Nothing terribly surprising, but the push to hypervisor based security means they are slowly starting to push towards a Qubes approach?
november 2017 by asteroza
Some sort of SD card form factor TPM/smartcard/VPN module for android? Mudge related...
april 2017 by asteroza
SEI CERT C++ Coding Standard: Rules for Developing Safe, Reliable, and Secure Sy...
CERT provides for free a C++ SDL programming guideline set, and there's a companion C guide too
march 2017 by asteroza
BitLocker can't encrypt drives because of service crashes in svchost.exe process in Windows 7 or Windows Server 2008 R2
Asus motherboards with UEFI secure boot can cause 7 to fail to boot, with the red screen of death, because 7 can't actually use secure boot
may 2016 by asteroza
Genode - Genode Operating System Framework
Now supporting encapsulating linux as a TrustZone in the USB Armory's secure areas.
december 2015 by asteroza - Whispering Off The Record
IM service that uses forced OTR and has a tor hidden service entrance, with servers that do no logging at all on LUKS FDE rigs. Better than nothing...
october 2015 by asteroza
Allows mounting LUKS encrypted volumes on windows without EXT2IFS.
august 2015 by asteroza
Sorta popular secure messaging app, but the company backing the network has no warrant canary and the devs refuse to answer if they've been served an NSL recently, so they've been served.
june 2015 by asteroza
Home -
Can't say how secure this is, and a likely target for intelligence groups, but hey, better than nothing?
february 2015 by asteroza
Tiger XS
Apparently this is used by some government officials in europe
october 2014 by asteroza
I wonder if a business can be made of this, though every government on earth will hate you...
september 2014 by asteroza
Computer Laboratory: BERI open-source hardware downloads
CHERI is built on the MIPS ISA, but concepts are portable to RISC-V and ARMv8.
july 2014 by asteroza
Encrypted email, based in Switzerland.
Eh, if they don't make this a host-proof hosting type situation, then it doesn't pass the smell test. Also, browser javascript crypto is asking to get owned, because you are loading external software. Did we also mention unencrypted metadata due to public SMTP, public ledger bitcoin payment providing user tracking, and the Swiss not being so private these days? I can appreciate making integrated PGP more usable to mere mortals, but if this isn't Snowden-grade, it isn't enough.
may 2014 by asteroza
Android KitKat | Android Developers
HCE is an end run around cellphone carriers excessively controlling the SE (secure element) portion of NFC, effectively locking out competitors in the contactless mobile payments space. But now Visa/MasterCard have announced HCE support for cloud storage of credit cards, effectively breaking the carrier stranglehold and opening the way for more Google Wallet like services..
march 2014 by asteroza
WhiteHat Aviator - The most secure browser online
This seems like a private label chromium with a lot of security tweaks, unfortunately closed source for mac OSX.
november 2013 by asteroza
Bitmessage Wiki
P2P using bitcoin architectural parts. There's a channel like feature, and an email gateway service as well.
august 2013 by asteroza
Pond - Pond
Interesting tor based async messaging server/protocol, sorta the encrypted equivalent of email without leaking too much metadata.
august 2013 by asteroza
Covert Browser
The humorous part is you have to buy this at the iTunes store on an Apple product, which feels like the antithesis of privacy and anonymity...
november 2011 by asteroza
App that creates an embedded secure partition to isolate work apps/email/data. In theory allows a work/play divide on an otherwise personal phone. As to how safe it is, well, encrypted partition generally only provides you security for data at rest if implemented well, and various levels of security for data on teh move (when the secure partition is mounted). There's also the security issues between apps. Android may be UNIX multiuser, but it was designed fundamentally as a single GUI user/operator OS, with resulting design compromises. VMware's Horizon hypervisor setup is a slightly better security solution since that takes the OS out of the equation in theory...
october 2011 by asteroza
Hackers break SSL encryption used by millions of sites • The Register
Use a MitM proxy to inject some bad javascript that executes a chosen plaintext on a specific website, to allow recovery of the secure cookie for that site.
september 2011 by asteroza
A quantum encryption idea utilizing the secure citadel concept to force the decryption to occur at a specific location.
august 2010 by asteroza
How to wipe free disk space in Linux? - Super User
seems like I would need to do the following for a quick and dirty disk free space zeroing, if I wasn't going to script a dd megafile operation (doing the dd zero file file is a bit scary, but this is essentially doing the same thing...)

sfill -f -l -l -z /
july 2010 by asteroza
The service which will gather and store uploaded video/audio from Taser/AXON's new head mounted video camera. The idea being, a remote third party video evidence collection repository of police action tends to provide somewhat objective evidence of police actions. Though it could just as easily be the new YouTube version of COPS...
march 2009 by asteroza
