Monthly Archives: October 2005

Properly securing wireless networks on the cheap

In part the reason CAcert exists is because very early on I realised how much a waste of time many of the security features that existed in the devices at the time (and even now still to a large extent).

Later on 802.1x came into the picture, but that has numerous complications with prerequisites with requiring you to setup RADIUS depending how you decide to go about configuring everything.

It’s worth noting that over the last few years the prices on access point routers have been dropping to the point that they can be now had in Australia for about the AU$100 price point (about US$50-70), the other interesting thing to note is that a number of companies making these devices ended up using linux on them rather then writing a custom OS which in turn lead to them being forced to release source code under provisions in the GPL.

This is where things start to get very interesting because on one hand we have cheap off the shelf small form factor devices and on the other we have th complete source code and tools to make customised firmware versions. These two events lead some smart cookies to take the sources and build up some amazing functionality along the way by taking software in the world of linux software.

So a long story short this is good news for people looking to better secure their wireless network and in such an easy and simplistic manner, via OpenVPN and these embedded devices, OpenVPN is a great choice because it seems as good as IPSec in terms of security, unless you happen to have state secrets to guard and I’m sure there are better options available from commercial vendors.

I’ve just spent the last couple of days experimenting with a Linksys WRT54G and managed to string together a guide on setting up a wireless access point router with OpenVPN and getting a linux laptop to talk to it as well.

CONISLI 2005, São Paulo, Brazil

Happening in October 3rd to 5th in São Paulo, the third edition of Conisli, one of the biggest Free and Open Source Software events in Brazil, will have several assurers around. No booth was arranged, even though we are trying to organize something. If you want to help assure people, or you are interested in being assured, drop an email to evaldo@gardenali.biz .

EuroBSDCon 2005 @ Basel, Switzerland

November 25 – 27 2005, EuroBSDCon is the main european BSD conference where members from all BSD teams meet and share experience and first hand know-how with the users of BSD systems.

There will be enough assurers to get full points. More information you’ll get at the info desk and the OpenBSD table.

see you there.

Complete failure of Oracle security response and utter neglect of their responsibility to their customers

The following was posted to the bugtraq mailing list:

Dear security community and Oracle users,
Many of my customers run Oracle. Much of the U.K. Critical National Infrastructure relies on Oracle; indeed this is true for many other countries as well. I know that there’s a lot of private information about me stored in Oracle databases out there. I have good reason, like most of us, to be concerned about Oracle security; I want Oracle to be secure because, in a very real way, it helps maintain my own personal security. As such, I am writing this open letter.

Extract from interview between Mary Ann Davidson and IDG

IDGNS: “What other advice do you have for customers on security?”

Davidson: “Push your vendor to tell you how they build their software and ask them if they train people on secure coding practices. ”

Now some context has been put in place I can continue.
Continue reading

SFD Hungary – CAcert Assurance Party

Hungary’s only Software Freedom Day event has been organized in Szeged. It is a city in the south with a big university and high involvement in open source.

There was a CAcert lecture and assurance party successfully held, about 50 new members joined the community. We were three assurers there.

More about the event:
SFD Szeged home: www.inf.u-szeged.hu/opensource/events.php
Lecture slides: www.artificis.hu/talks/sfd05