Última actualització: 01/05/2007; 03:27:59
Weblog d'en Xavi Caballé
«Al meu país la pluja no sap ploure: o plou poc o plou massa; si plou poc és la sequera, si plou massa és la catàstrofe»
Raimon - Al meu país la pluja

dijous, 26 / abril / 2007


El libro verde de BarcelonaDisponible a Google Books la digitalització de «El libro verde de Barcelona», editat l'any 1848.

La versió digitalitzada correspon a la còpia emmagatzemada a la biblioteca de la Harvard University. Es pot baixar la versió PDF del text.


Envia-ho a la tafanera Desa-ho a del.icio.us | 12:20 (# Enllaç permanent) | Comentaris: | Trackback:


SecuStickL'altre dia en parlava aquí del SecuStick, una memòria USB amb capacitat d'autodestrucció. Bé, ja hi ha qui l'ha provat i les conclusions no són massa positives: Secustick gives false sense of security
Because the stick supposedly self-destructs after several wrong attempts at keying in the password, we decided to put that feature to the test first.

(...)

Opening the Secustick reveals two easily recognizable elements: a flash controller and a piece of NAND memory, which in this case has been manufactured by Hynix. A little research taught us that this type of controller is a very basic type that doesn't have any specific security features, and although we couldn't find a datasheet of the memory module, we did discover one from a similar model on the internet, and learned that it has a special pin that allows or denies writing to the chip, based on its voltage.

(...)

By soldering a wire between the special pin and the earth we could be sure that no data on the chip could be altered

Secustick hacked

When we re-inserted the stick into the PC and deliberately typed a wrong password, the screen read: 'Wrong password, 6 attempts left'. So we tried again, and the message on the screen read 'Wrong password, 6 attempts left' once again. Goody! The stick left unable to store the number of password attempts, we could now try out passwords indefinitely without having to fear that the stick would self-destruct. Time to take a closer look at the software.

(...)

It should be clear that the stick's security is quite useless: a simple program can be used to fool the Secustick into sending its unlock command without knowing the password.

(...)

Our advice should be clear: anyone with 130 euros to spare for a shiny metal USB stick with a necklace is free to go out and spend it on the Secustick, but those who want to carry their data around safely are better off searching for a more advanced model, or to use a regular stick in combination with a program such as TrueCrypt.
 


Envia-ho a la tafanera Desa-ho a del.icio.us | 09:55 (# Enllaç permanent) | Comentaris: | Trackback:

© Copyright 1996-2007 Xavier Caballe. . Si no s'indica expressament el contrari, el material publicat en aquest weblog es distribueix d'acord amb la llicència Creative Commons. El contingut és responsabilitat única i exclusivament del seu autor i no té cap relació amb les seves activitats professionals.
Wishlist
Abril 2007
Diu Dil Dim Dim Dij Div Dis
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30          
Mar   Mai

RSS




Contingut actualitzat




Categories


Darrers comentaris

Arxiu

Contingut antic
(ja no s'actualitza)


Articles
(fins maig 2003)



Versions anteriors
d'aquesta pàgina

Webs d'amics
jcea
Vicent Partal
Jordi Mas
Toni Hermoso
Mercè Molist
Mina Nabona-Jassans

Gurus
Scripting News
Jon Udell
Bruce Sterling
Bruce Schneier
Howard Rheingold
Reflexiones e irreflexiones
Atalaya
Cuaderno de bitácora
Linotipo
Pedro Jorge Romero

Seguretat
reversing.org
Seguridad de la información
Somiatruites, Ciberderechos
     en la red

eN Espiral ~> Juanma Merino
Navega seguro

PDA
CosesPalm
PalmCat
CanalPDA.com

Cultura
El Llibreter