<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Secure by default</title>
	<link>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/</link>
	<description>Let's just see where this is going for now, okay?</description>
	<pubDate>Tue, 18 Nov 2008 21:28:11 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.2</generator>

	<item>
		<title>by: arikb</title>
		<link>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-2552</link>
		<pubDate>Sat, 29 Jul 2006 09:13:21 +0000</pubDate>
		<guid>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-2552</guid>
					<description>Now that's interesting. WPA-encrypted networks that can be broken into within 15 minutes of sniffing - that's news to me. You're not talking about WEP, right? Can you please supply more details?</description>
		<content:encoded><![CDATA[<p>Now that&#8217;s interesting. WPA-encrypted networks that can be broken into within 15 minutes of sniffing - that&#8217;s news to me. You&#8217;re not talking about WEP, right? Can you please supply more details?
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: dera (binary loc)</title>
		<link>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-2540</link>
		<pubDate>Fri, 28 Jul 2006 21:14:35 +0000</pubDate>
		<guid>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-2540</guid>
					<description>and arik, I can break into a WPA network with MAC filtering in less than 15 minutes.  More than enough time to not look suspicous.  The guy I'm with jumps out of the car, walks into a nearby building or the place we a targeting, looks around, acts intrested in an item/service, and when he gets back the router's firmware has been upgraded to our version, which records every 1 and 0 that passes through it and sends it off to us.  and if someone asks a question in the process, why I am sitting there with a laptop on in their parking lot, I am playing a nice game of chess against the computer (that is in the middle of a good game, saved from a few nights before) on a seperate desktop so they don't see a thing.  If they ask, I tell them my friend's fake name and if he calls in to check, sure enough, there is a guy with that name sitting there asking about the latest version of some overprices piece of software and negociating a price for extra addons and a few hundred more seats.

God I love pen. testing.  The look on a smug CEO's face when he finds out how easily you can screw him- priceless.</description>
		<content:encoded><![CDATA[<p>and arik, I can break into a WPA network with MAC filtering in less than 15 minutes.  More than enough time to not look suspicous.  The guy I&#8217;m with jumps out of the car, walks into a nearby building or the place we a targeting, looks around, acts intrested in an item/service, and when he gets back the router&#8217;s firmware has been upgraded to our version, which records every 1 and 0 that passes through it and sends it off to us.  and if someone asks a question in the process, why I am sitting there with a laptop on in their parking lot, I am playing a nice game of chess against the computer (that is in the middle of a good game, saved from a few nights before) on a seperate desktop so they don&#8217;t see a thing.  If they ask, I tell them my friend&#8217;s fake name and if he calls in to check, sure enough, there is a guy with that name sitting there asking about the latest version of some overprices piece of software and negociating a price for extra addons and a few hundred more seats.</p>
<p>God I love pen. testing.  The look on a smug CEO&#8217;s face when he finds out how easily you can screw him- priceless.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: dera</title>
		<link>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-2539</link>
		<pubDate>Fri, 28 Jul 2006 21:07:57 +0000</pubDate>
		<guid>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-2539</guid>
					<description>noam: uber hackers?  I have friends who are complete morons who can shove an auditor livecd into their media tray, pass a few commands and fuck a wireless network.

More like count on it that your neightbors are not intrested or have IQ's lower than 70.</description>
		<content:encoded><![CDATA[<p>noam: uber hackers?  I have friends who are complete morons who can shove an auditor livecd into their media tray, pass a few commands and fuck a wireless network.</p>
<p>More like count on it that your neightbors are not intrested or have IQ&#8217;s lower than 70.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: arikb</title>
		<link>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-338</link>
		<pubDate>Wed, 28 Sep 2005 21:34:31 +0000</pubDate>
		<guid>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-338</guid>
					<description>It's better than nothing. You're protected from the occational hot-spotter.

If you upgrade to WPA, that's much more significant.</description>
		<content:encoded><![CDATA[<p>It&#8217;s better than nothing. You&#8217;re protected from the occational hot-spotter.</p>
<p>If you upgrade to WPA, that&#8217;s much more significant.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: noam</title>
		<link>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-336</link>
		<pubDate>Wed, 28 Sep 2005 21:30:41 +0000</pubDate>
		<guid>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-336</guid>
					<description>From what I can tell even those who go through a few extra clicks to
secure their wireless network aren't very safe. I just configured a wireless
network in my new apartment for myself and my roomate to use.

I've setup a 128-bit encryption key and MAC access list. Still, someone can hack
the key in a few days, fake his MAC address and get everything he wants...

I'm counting on the fact that my neighbors aren't uber-hackers.

By the way, that Linksys is extremely sexy (Please don't make any assumptions
regarding my sex life based on this comment).</description>
		<content:encoded><![CDATA[<p>From what I can tell even those who go through a few extra clicks to<br />
secure their wireless network aren&#8217;t very safe. I just configured a wireless<br />
network in my new apartment for myself and my roomate to use.</p>
<p>I&#8217;ve setup a 128-bit encryption key and MAC access list. Still, someone can hack<br />
the key in a few days, fake his MAC address and get everything he wants&#8230;</p>
<p>I&#8217;m counting on the fact that my neighbors aren&#8217;t uber-hackers.</p>
<p>By the way, that Linksys is extremely sexy (Please don&#8217;t make any assumptions<br />
regarding my sex life based on this comment).
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Saar Drimer</title>
		<link>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-301</link>
		<pubDate>Wed, 14 Sep 2005 11:38:16 +0000</pubDate>
		<guid>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-301</guid>
					<description>This applies to many big outlets (like Costco)... simply, the return lines are very long on the weekends.</description>
		<content:encoded><![CDATA[<p>This applies to many big outlets (like Costco)&#8230; simply, the return lines are very long on the weekends.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: arikb</title>
		<link>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-298</link>
		<pubDate>Wed, 14 Sep 2005 00:59:05 +0000</pubDate>
		<guid>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-298</guid>
					<description>Thanks, Saar. Yes there was a 'reduced price item', for $2 less. Needless to say I didn't take it. You can see how good a product is by the ratio of unopened/returned boxes on the shelf.

What's wrong with returns on a weekend? I just had to ask...</description>
		<content:encoded><![CDATA[<p>Thanks, Saar. Yes there was a &#8216;reduced price item&#8217;, for $2 less. Needless to say I didn&#8217;t take it. You can see how good a product is by the ratio of unopened/returned boxes on the shelf.</p>
<p>What&#8217;s wrong with returns on a weekend? I just had to ask&#8230;
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Saar Drimer</title>
		<link>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-297</link>
		<pubDate>Tue, 13 Sep 2005 22:02:55 +0000</pubDate>
		<guid>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-297</guid>
					<description>Well, these things can be handled by the manufacturers... but why would they bother? They are not liable for any loss of anything. As long as &quot;society&quot; has &quot;hackers&quot; to blame in the mass media, all will remain the same.

As for Fry's... you caught them on a good year. Up to about a year ago shopping there was not so pleasant. They improved greatly, especially on customer service and returns. First, don't ever buy something with a &quot;returned merchandise&quot; sticker on it unless it is &lt;em&gt;significantly&lt;/em&gt; cheaper and you are willing to come back to return it. Second, open &lt;em&gt;anything&lt;/em&gt; expensive &lt;em&gt;in front&lt;/em&gt; of the clerk to see that is it brand new, even if it shrink wrapped and &quot;looks&quot; new. I once bought a motherboard that looked new, but the inside was a mess. Third, never attempt a return on the weekends. Happy shopping at Fry's it's heaven for geeks like us; I'll miss it.</description>
		<content:encoded><![CDATA[<p>Well, these things can be handled by the manufacturers&#8230; but why would they bother? They are not liable for any loss of anything. As long as &#8220;society&#8221; has &#8220;hackers&#8221; to blame in the mass media, all will remain the same.</p>
<p>As for Fry&#8217;s&#8230; you caught them on a good year. Up to about a year ago shopping there was not so pleasant. They improved greatly, especially on customer service and returns. First, don&#8217;t ever buy something with a &#8220;returned merchandise&#8221; sticker on it unless it is <em>significantly</em> cheaper and you are willing to come back to return it. Second, open <em>anything</em> expensive <em>in front</em> of the clerk to see that is it brand new, even if it shrink wrapped and &#8220;looks&#8221; new. I once bought a motherboard that looked new, but the inside was a mess. Third, never attempt a return on the weekends. Happy shopping at Fry&#8217;s it&#8217;s heaven for geeks like us; I&#8217;ll miss it.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: SecuriTeam Blogs &#187; Secure by default</title>
		<link>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-293</link>
		<pubDate>Tue, 13 Sep 2005 05:09:32 +0000</pubDate>
		<guid>http://arik.baratz.org/wordpress/2005-09-12/secure-by-default/#comment-293</guid>
					<description>[...] Originaly posted in my blog [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Originaly posted in my blog [&#8230;]
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
