Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, 12 November 2025

word of the day: slopsquatting

I have grave doubts about LLMs and their ilk: there is no "there" there.  But that will have to wait for a future blog post.  One thing they are known for is "hallucinating", or generating things that have plausible form, but no denotation, such as citing non-existent legal cases, scientific references, and ... code modules.

This last one is new to me, discovered in a comment on Ask a Manager.  I write my own code, of course.  But apparently some people are happy to have AI write code for them.  I suppose yet another form of AI slop shouldn't surprise me.  However, the associated security vulnerability is even more worrying than some random bogus citations.  It's the problem of slopsquatting:

Like other forms of gen AI, coding AI makes up references to non-existent code libraries. “Slopsquatting” is when a malicious actor creates malicious code with the name of one of these non-existent code libraries. When you run your AI-generated code, instead of throwing an error it automatically downloads and runs that malicious code.

This is why we can't have nice things.

Friday, 28 January 2022

a new phishing attempt

 This is a new phishing attempt I haven’t seen before, rather more plausible than most:

NEW REPLY TO SUPPORT CASE #1643367968 28.01.2022

Dear  , It has recently come to my attention that your support case from exactly one year ago (28.01.2021) has gone unanswered because of a system error. I immediately sent my superior Richard, an email and explained that you made a complaint at the service desk in the store but that the exact details were also lost. I can see here that there was something wrong with a purchased item, but you were not able to return or exchange said item. This is against store policy, so we have decided that we will compensate you. The value of the compensation is obviously quite high because the matter took so long to solve.

But you don't need to worry about that , it's our pleasure because we value you as a customer. What I need from you now is that you validate your email address XXX@XXX.XXX by replying to this email. Your reply can simply be empty, as long we can see you replied to this message we can take care of the rest and make sure you get what's rightfully yours.

Kind regards,

Polly Gallagher

Regional Response Administrator


Head Office

Falcon Way, Shire Road,

Welwyn Garden town,

Hertfordshire,

AM5 2PW


There are, however, several red flags (which I won’t post here, as I don’t want the scammers to fix them!)

The website De-Reviews has an explanation of what happens if you respond,  It’s the obvious things: they ask for personal details to scam you, and try to put spyware on your computer.

This is why we can’t have nice things.




Monday, 14 January 2019

book review: A Burglar's Guide to the City

Geoff Manaugh.
A Burglar's Guide to the City.
Farrar, Straus and Giroux. 2016

There is a standard way to use a building: enter by the doors, look though the windows. There is a standard way to use a city: travel along the roads. Burglars don’t use buildings and cities in standard way: some enter buildings though windows, drop through hatches and ceilings, cut through walls; some move around cities through tunnels, either pre-existing or self-dug. Manaugh describes many of these alternate uses: some exceedingly clever, some just plain dumb. And he describes attempts to thwart the burglars, from law-enforcement helicopter patrols to high security panic rooms.

I have come across, in fiction if not in reality, many of the concepts here, but they are all engagingly presented. One aspect I found particularly intriguing was how law enforcement could get lost in certain kinds of locations. In one case it was helicopter pilots over a regular grid of streets, in another it was officers on the ground in a huge building with several identical parts. Both were lost in “a maze of twisty little passages, all alike”. We know the solution to this: drop landmarks. Law enforcement would like home owners to paint identifiers on their roofs. Alternatively, architects could design more varied structures: “a maze of twisty little passages, all different”, with the necessary landmarks already present.

Being able to think “sideways”, like a burglar, is a useful skill when designing any artefact: it will be misused, if not on purpose, then at least accidentally. Having these misuses catered for up front in the design is a plus. Having these literally concrete examples in mind can makes for more vivid analogies when trying to think sideways.






For all my book reviews, see my main website.

Friday, 7 September 2018

not suspicious at all

I've just received an email.

It contains the following 4 images:



Yes, an email that looks like a load of text is actually four images.  The first bullet in this pseudo-text has the excellent advice "Please do not click on any links you do not recognise."

The middle two images (the last three bullets, with the bold telephone number and the bold "here") not only are links, but you are explicitly invited to click on one.  These links have extremely unrecognisable URLs like "http://links.mkt529.com/servlet/M= ailView?ms=3DMjE4MTcxMTAS1&r=3DMjExMTk3OTQyNDQwS0&j=3DMTMwMzMzNDgwNwS2&mt= =3D1&rt=3D0"

So, an email warning me about a potential data breach that is itself either (i) a phishing attack; or (ii) from someone who does not understand their own security advice!

Sigh.

Wednesday, 28 December 2016

reinforce the spots that don’t have bullet holes

Bruce Schneier on one aspect of security theatre:
Security Risks of TSA PreCheck 
PreCheck tells us that, basically, there are no terrorists. If 1) it’s an easier way through airport security that terrorists will invariably use, and 2) there have been no instances of terrorists using it in the 10+ years it and its predecessors have been in operation, then the inescapable conclusion is that the threat is minimal. Instead of screening PreCheck passengers more, we should screen everybody else less. 


For all my social networking posts, see my Google+ page

Friday, 27 May 2016

Justin Bieber and Beyonce are not aliens

Prof Angela Saase
On Wednesday I was down in London, for the 2016 Hopper Colloquium, and the 6th annual Karen Spärck Jones lecture. This year, the lecture was by Professor Angela Saase, Director of the UK Research Institute in Science of Cyber Security, speaking on the parlous state of computer security.

Like the previous one of these lectures I attended, this was entertaining, informative, and thought provoking.  In a nutshell: there is a lot known about how to get good computer security; most developers and their companies ignore it, and are ignorant of it.

Take passwords.  We all know that a long strong password, frequently changed, makes for good password security, right?  Wrong!  What is actually needed is a password that the user can remember, changed only when suspicious activity has been spotted, and protected via technological defence in depth.

Unusable security, including multiple long complex changing passwords, is bad security.  If your product is unusable, users will go elsewhere.  If they can’t go elsewhere (you are the only provider, or, more likely, everywhere else is just as bad), they will circumvent the process, thereby making the system less secure overall.  If they can’t circumvent, their productivity will simply plummet.

As Saase puts it: Users are Not the Enemy.  Usability is not a luxury, to be grudgingly added in when the call centres are groaning under the weight of frustrated callers.  Apparently a major company had a call centre of 100 people doing nothing but reset passwords, and it is not alone.  Talk about productivity plummeting!

The most eye-opening part of the talk was when Saase described a study of three major companies, who had volunteered to be studied because they had good processes.  In summary, they actually had: no criteria for usability; no user involvement; no usability testing; little or no security testing; no understanding of the impact of the design on productivity or sales; internal security policies violated by their own developers; …

It’s not that usability insights are new.  In 1883,  Auguste Kerckhoffs published six principles for secure cryptography; three are about usability!

The solution?  Don’t push the risks onto the users.  Engage with them.  Use technology to provide defence in depth.  Implement only provably effective security policies.  And most of all, convince the developers and their managers that usability is not a luxury: it is an essential security requirement!



Oh, and this post title?  Well, one of the talks at the Hopper Colloquium was about the relationship between post titles and click-throughs. The result: more click-throughs when the title includes famous people (these two, whoever they may be, were given as examples), and include a negative.  Let’s see how it works.

Okay, okay.  Click-bait.  I won’t do it again!

Monday, 17 August 2015

never email a password

I’ve just registered with a new grant management system.  They wanted a password, obviously, and clearly wanted a strong one, because they required a minimum length, and a mix of characters from different classes.  They went one further, and also wanted an answer to a memorable questions.  So far, so good.  (Well, apart from one of the options being mother’s maiden name.  Not exactly secret in this day and age.  But I use a password manager, so I can easily provide a random answer without worrying about losing it.)

They emailed me confirmation of my registration.

The email contained my login id.  And my password, in the clear.

screenshot of email, modified
Sigh.

[while looking for an interesting and relevant link to add in here, I found this beautiful page.]

For all my social networking posts, see my Google+ page

Monday, 6 July 2015

gotcha

Note to self: two-factor authentication where your landline drops your internet connection, and then the web page times out before the connection re-establishes, is not useful.  (And no, I couldn’t change the contact number to my mobile, because to do that I needed to two-factor authenticate myself…)


For all my social networking posts, see my Google+ page

Friday, 3 April 2015

sequestering carbon, several books at a time XLIII

The latest batch:



And now off to the Eastercon, where Jim Butcher is a Guest of Honour.

Saturday, 28 March 2015

sequestering carbon, several books at a time XLII

The latest batch, all fiction.


There’s a few new series/authors we are trying out, plus some stalwarts.

Including a new Jo Walton!  Yay!

All we have to do now is find time to read them.

Friday, 17 October 2014

muddled metaphors

Theresa May and muddled metaphors:
But she added that there was “a necessity in having the material in order to be able to search it in a very targeted way” and it was “hugely important” to have “large amounts” of it. 
“The ability to interrogate that bulk data – to look for that needle in the haystack – is an important part of the processes that people go through in order to keep us safe,” she told the intelligence and security committee.
Actually, when looking for a needle in a haystack, the smaller the haystack, the easier the problem!




For all my social networking posts, see my Google+ page

Thursday, 28 August 2014

sequestering carbon, several books at a time XXIX

The latest batch:

This includes two copies of the Worldcon Souvenir Book, and some books recommended on BoingBoing (you’re not helping, guys!)