LWN.net Logo

Security quotes of the week

For example, if the year is 2013 but the current month is less than the target month (say February), then the condition would return a result as if the current date lies before the August 2012 checkpoint value. In fact, this logic is simply flawed and incorrect. This error indirectly confirms our initial conclusion that the Shamoon malware is not the Wiper malware that attacked Iranian systems. Wiper is presumed to be a cyber-weapon and, if so, it should have been developed by a team of professionals. But experienced programmers would hardly be expected to mess up a date comparison routine.
-- Dmitry Tarakanov of Kaspersky Lab analyzes the Shamoon malware

Windows 8, set for release on 26 October, automatically deletes entries in the HOSTS file for specific domains. Try, for example, to prevent attempts to access Facebook.com, Twitter.com or ad servers such as ad.doubleclick.net by rerouting them to 127.0.0.1 by adding entries to the HOSTS file and the relevant entries will soon disappear from the HOSTS file as if by magic, leaving nothing but an empty line.
-- The H

Most importantly, a series of leaks over the past few years containing more than 100 million real-world passwords have provided crackers with important new insights about how people in different walks of life choose passwords on different sites or in different settings. The ever-growing list of leaked passwords allows programmers to write rules that make cracking algorithms faster and more accurate; password attacks have become cut-and-paste exercises that even script kiddies can perform with ease.
-- Dan Goodin in ars technica

As a Data Privacy Engineer at Google you will help ensure that our products are designed to the highest standards and are operated in a manner that protects the privacy of our users. Specifically, you will work as member of our Privacy Red Team to independently identify, research, and help resolve potential privacy risks across all of our products, services, and business processes in place today.
-- Google is looking for privacy engineers
(Log in to post comments)

Security quotes of the week

Posted Aug 23, 2012 10:31 UTC (Thu) by jengelh (subscriber, #33263) [Link]

Google: Me, me, me! — There is an “evil” accounts.google.com cookie (name="RMME") that, while not 2038, still goes until 2022.

Security quotes of the week

Posted Aug 23, 2012 12:55 UTC (Thu) by man_ls (subscriber, #15091) [Link]

But experienced programmers would hardly be expected to mess up a date comparison routine.
What a feeble argument: bugs happen even within the best families. Perhaps the "professionals" left date-handling routines to the intern?

Security quotes of the week

Posted Aug 24, 2012 9:06 UTC (Fri) by Aissen (subscriber, #59976) [Link]

I think it was supposed to be ironic.

Security quotes of the week

Posted Aug 26, 2012 14:54 UTC (Sun) by man_ls (subscriber, #15091) [Link]

Totally went over my head then. As I read it, this factoid supports the author's theory: "This error indirectly confirms our initial conclusion that the Shamoon malware is not the Wiper malware that attacked Iranian systems". Also, it is not even funny!

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds