So much for being anonymous
May 10, 2010 Opinion, Security News
I just read an interesting article at abuse.ch about anonymizing proxy use and the privacy and security concerns that many of us don’t take into account.
*** The bad things you don’t know about such proxies ***
Unfortunately the other site of the coin looks much worse:
- You don’t know who run these proxies
- You don’t know if these proxies are secure and clean from any malware and drive-bys
- You don’t know the intentions of the persons who runs these proxies (maybe they have mean ill?)
But you have must be aware of one fact: Those proxies aren’t anonymous! Web Proxy scripts like Glype&Co have a free configurable option wheter the administrator of the (glype-) proxy wants to log the requests which are passing his proxy or not. And you can be sure that the most Glype administrators will do.
Go have a read here.
Words to the Wise
Nov 13, 2009 Opinion
Recently Dave from the DailyDave security mailing list said something very insightful that I wanted to re-post here:
When you go into security consulting engagements with a new business
unit you usually face a few questions from the developers and business
owners. “What is it exactly that you’re going to tell us?”We always answer this the same way: “Things that will surprise you.”
Most developers have read a lot about security these days – they
understand SQL Injection, Cross Site Scripting, access control, not to
use their own cryptographics, and all sorts of other security truisms.What they can’t possibly understand is how a hacker’s mind works, and
what they’re likely to find. Even security specialists who have only
worked defence often have never really seen a hacker go.Largely I think this is because there’s a difference between someone
playing cards with chips and someone with their house and life on the
line. People say penetration testing is a model of an attacker. But how
do you model obsession?- -dave
I totally agree. We can use the same tools, adopt the same techniques, but the mind of an intruder may be so completely alien to any defender that the yawning gulf of difference in mindsets that separates us prevents comprehension and hinders our efforts to combat them.



