Thursday, July 28, 2011

Seriously? A.k.a. "My adventures with "ePolicy Orchestrator"

From the why-oh-why-do-you-hate-me department:

Seriously? We have to break the official IT computer naming policy because you product refuses to be installed on a system that has a (perfectly legit) underscore in it's name?

I usually don't get frustrated with a product until after I install it.


It only after I change the computer name, that I get this error on my Windows 7 professional installation:


Of course, that document is not part of the installation, only the "product guide" is. 

Update 1:
I now have a super duper "Windows Server 2008 R2 - 64 bit" installation.   Guess what I get when the installation starts?  A new error!

"8.3 naming convention"?  Wait...  Didn't you just force me to upgrade to "Windows super duper"? And then you complain that you don't have the features from DOS in 1981?  And no, the "installation guide" doesn't mention anything about this.


Update 2:
After some Googleing, a registry change, installing MS SQL, configuring port, choosing various passwords (whose complexity requirement are kept a secret), the installer finally got running.

And I was awarded with....

At this point, only 1 comment makes sense:
Update 3:

Wondering if I was running the latest version, I found out

  • McAfee's beta portal is seriously broken
    • it refuses my (stored) password 
    • it doesn't really execute password resets (although it says it does)
  • That doesn't really matter, since there is a an open FTP server from which one can download any beta software they ever released.
  • That also doesn't really matter, since I was already testing with the latest version, EPO 4.6 RC3.
  • The beta seems to expire really quickly, in this case: May 31, 2011 (it was released mid march)
So, saying in the spirit, I used an ancient "hack" technique from the 80s.  It's called "setting the clock back".
Result:
30 minutes of installation dialogs later:


Allow me to say:



Tuesday, July 19, 2011

Pretty Good Ponderings?

Yesterday, I finally got around to generate a new PGP/GPG key pair, and obsoleted 2 old ones.   They were created in 1994 and 1998.   I couldn't even generate a revocation for the oldest one, since the "IDEA" cipher is  no longer supported.

Let me rephrase that in context:

I can mathematically prove that I was active in computer security before many of the attackers that I defend against, were born.


In other news:
Djee, I'm old.  But in this industry, we call that "well-tested and peer-reviewed".

P.S: For those wanted the shiny new bits on their keyring, the magic incantation is:


gpg --recv-keys 0x788a1200b221877e

Thursday, June 23, 2011

Yahoo & speed of innovation

While on my quarterly check of “email address that I haven’t used this decade”, I noticed the congratulatory email from Yahoo.

 

After 13 years of spam-filled ugliness, they are going to upgrade their email interface.    

 

I will get right on using them again! (Around 2019 or so)

Sunday, March 6, 2011

Physchic computer support

Can you help me with my computer?

Is it no longer working? 
Eh... yeah.. weirdest thing...
Did you let your kids use it?
Yeah, little Billies computer was acting up...
And you let him use your login, instead of a "Guest" account?
Yeah, it was just for little while...
And that was a full-privilege administrator account?
Yeah, that's how the computer came...
And you left him alone like that?
Yeah, well, I had to go to work.
So the first thing he did was install "Limewire"?
Yes, how do you know?
So he thought he scored some free music, but nobody told him music files don't end in .mp3.exe ?
Eh... what's an EXE?
So he installed whatever the trojan of the week is, and now your computer won't connect to anything any more?
Yeah, exactly!  How do you know? 

Wednesday, December 29, 2010

This is why we can't have nice and secure things...

I recently received an invite for "shtyle.fm".   If you never heard about it, you are in good company, as it can best be described as "Myspace's retarded cousin".

So when I got the request from a family member to look at her pictures on there, I reluctantly started the sign-up process, making sure to only use throw-away info....  until this screen stopped me dead in my tracks.

Some facts about this screen that may to seem obvious at first glance:

  • It's a mandatory part of the sign up process
  • It promises a free virtual teddy bear! 
  • It requires you to fill in the credential of a real email account.
  • It validates the credentials, and throws an error if you give it fake information
  • The information is submitted and transmitted in the clear, over http, without any encryption (although the page seems to include an unused JavaScript implementation of RSA for some reason)
  • The page has (at least) a XSS vulnerability: Enter "+alert(1)+" in the email box (with quotes) and see what happens.
  • In case a connection is successfully made, the application will sift through your inbox for email addresses of your friends and send them personal invites in your name
Are we scared yet?   No?  Neither seems to be the thousands of happy users on that site.

The security professional in me gets the shills, but the social human in me appreciates the service provided here.  It provides a different view on your friends and acquaintances:

If you are somebody who gives up your credentials to anybody who asks, than that indicates how reliable you are.  Don't count on borrowing my car keys.
If you consciously sell out all your friends for the promise of a virtual teddy bear,... I think that says something about your moral value system.