Sunday, September 22, 2013



Well, that didn't take long.

"Hackers from the Chaos Computer Club (CCC) say they have successfully bypassed the biometric security of Apple's recently released TouchID on an iPhone 5s."(Mike Lennon, Security Week, 21 Sep 2013)

See the complete article on how they did it here: http://www.infosecisland.com/blogview/23397-Hackers-Defeat-Apples-TouchID-on-an-iPhone-5S.html

On the dirty tricks front (NSA) there weren't any new revelations this week, just reaction:

"Security firm RSA sent an advisory to their developer customers warning against use of a toolkit that employs an NIST encryption algorithm by default that is suspected to have been “backdoored” by the NSA." (Anthony Freed, InfoSec Island, 21 Sep 2013)

This is an example of the damage to trust I believe the NSA has wrought, and trust in the strength of the encryption algorithms used to secure so much of the underpinnings of the internet is vital. I don't think the Law of Unintended Consequences has run it's course yet.


"Goodnight and goodluck"--to all of us.

Mark V2


Sunday, September 15, 2013

League of government sneaks and cheaters (LoGSC)

Continuing my rant from last week, what does this headline:


FBI admits what we all suspected: It compromised Freedom Hosting’s Tor servers

have in common with this one:

New York Times provides new details about NSA backdoor in crypto spec
other than that they're both from Ars Technica?

They're both reports about the abuse of power in the pursuit of lofty goals (national security).  Next the abuses will be in pursuit of base goals (the preservation of power), if history is any guide.  I'm not saying there's anyway back-I believe we're already over the precipice.  I'm just pointing out the road signs as we slide by, into a dark and ugly future.  The wheel turns.  

Or maybe not:  NIST: "we are not deliberately... working to undermine or weaken encryption."  At least one government agency, and it's still one of my favorites, doesn't appear to be in the League....yet.  

Maybe I'm a cynic, or have read too much dystopian sci-fi, but I'm reminded of this poem, by William Butler Yeats:
The Second Coming
Turning and turning in the widening gyre   
The falcon cannot hear the falconer;
Things fall apart; the centre cannot hold;
Mere anarchy is loosed upon the world,
The blood-dimmed tide is loosed, and everywhere   
The ceremony of innocence is drowned;
The best lack all conviction, while the worst   
Are full of passionate intensity.

Surely some revelation is at hand;
Surely the Second Coming is at hand.   
The Second Coming! Hardly are those words out   
When a vast image out of Spiritus Mundi
Troubles my sight: somewhere in sands of the desert   
A shape with lion body and the head of a man,   
A gaze blank and pitiless as the sun,   
Is moving its slow thighs, while all about it   
Reel shadows of the indignant desert birds.   
The darkness drops again; but now I know   
That twenty centuries of stony sleep
Were vexed to nightmare by a rocking cradle,   
And what rough beast, its hour come round at last,   
Slouches towards Bethlehem to be born?

To paraphrase the poignant words of Edward R. Murrow, "Goodnight and goodluck"--to all of us.

Mark V2

Friday, September 6, 2013

So the top InfoSec news of the week has to be the revelation that not only has the NSA been scooping up all the inter-bits, everywhere, all the time, but that they can decrypt all most all of them.  They do this not only by (limited) brute-force cracking, but by "acquiring" commercial keys, by hook or by crook.

What chafes my butt about this is that to paraphrase Pres. Obama, we HAD this "public discussion" back in the '90s when NSA wanted to require the CLIPPER chip. The subject was debated, extensively, by all stake-holders, and the DEMOCRATIC decision was that we valued our privacy more than the government's need to provide security.

Apparently, the NSA decided they are above the law, and so they subverted the will of the people and reached their goals anyway.

"Power tends to corrupt, and absolute power corrupts absolutely."  - Lord Acton

Monday, August 26, 2013

Dear Reader,

Why are you here? At this blog site I mean, not the existential "Why am I here?"

If you're sure you have nothing better to do at the moment than to read this blog, then:

Welcome!  Here you will find random musings generally, usually--but probably not exclusively--related to what's happening in the exciting world of Information Security, and my journey/ odyssey / trials as I complete a masters degree in Cyber Security at Bellevue University, Bellevue Nebraska.

Let me begin by introducing myself.  I prefer the appellation "V2" which can be pronounced as vee-two or as vee-squared.  Makes no difference.  I'm retired from the USAF after 23 years and I'm using my GI Bill to attend school.

I've been a Certified Information Systems Security Professional (CISSP) since 2006, and have been working in what the DoD calls Information Assurance (IA) since 1984.  You probably know the field as Information Security or INFOSEC for short.  It's supposition on my part, but I believe the DoD started calling it IA to differentiate it from all the other "SECS" they already have:  COMSEC, OPSEC, PERSEC, etc.

Anyway, I intend to post my thoughts about current events in INFOSEC at least weekly.  I will try to make them humorous and engaging, but considering the content, pleas don't judge me too harshly.



Mark V2