Thursday, May 1
ISC Podcast Episode 3
Apple's Safari Market Share on Windows Tripled!
What went wrong with the Podcast?
ISC Podcast Episode 3
Monday, April 28
Focus
Sunday, April 20
Software Update -- Did Apple Do Enough?
Now, I am an Apple user, an AVID Apple user. I own no less then 15-20 of their products, and an avid Apple defender. But even I said that Safari being automatically checked and enabled for download and installation on Windows machines was going a step too far. I don't mind if it was there for download, but automatically checked? Meh.
Now, I don't have a Windows machine, so I haven't been able to experience this myself, but apparently Apple issued an update to Software Update last week that moved Safari down to a block called "Optional Downloads", instead of being labeled as an update. Well, it's a great step, but I still am of the opinion that Apple didn't go far enough. Safari is still checked by default!?
What's the big deal? It's just an update, or even an optional download. Well, that's fine except that Safari was checked even on machines that didn't have Safari installed on it. Apple wasn't the forcing the download on people, but it sure wasn't making it obvious that it was an optional download.
So my question is, did Apple go far enough? I don't think they did, I would like to see it unchecked by default as an optional download. I don't mind if Apple offers the Windows users a better browsing experience. ;) But I do mind if they make the browser seem like it's a part of an already existing installation.
The problem wouldn't be so bad, but I know at some point in the near future someone, whether it's Apple or some other agency , will report that Safari as "x" amount of market share, which me, as an Apple guy will say "Yeah! We have "X"!". But will it really be a real metric?
Joel Esler
http://www.joelesler.net
Monday, April 14
News on the Podcast

For those of you with Twitter
News on the Podcast

For those of you with Twitter
Wednesday, April 9
iTunes is borked
iTunes is borked
Killbits
Tuesday, April 8
Podcast Episode 2 available tomorrow
Podcast Episode 2 available tomorrow
Monday, April 7
GTD in Leopard, with Mail.app and iCal, redux
Thursday, April 3
MSFT Tuesday for April 8, 2008
MSFT Tuesday for April 8, 2008
Snort releases version 2.8.1
* Ability to read multiple PCAPs from the command line
* Support for GRE encapsulation for both IPv4 and IPv6
* Support for IP over IP tunneling for both IPv4 and IPv6
* An SSL preprocessor to allow the ability to ignore encrypted traffic
* Update to HTTP Inspect to identify overly long HTTP header fields
* Updates to IPv6 support
Quicktime, Frontrow, and iTunes updates
Quicktime, Frontrow, and iTunes updates
Tuesday, April 1
Apple having an iPhone shortage
Apple having an iPhone shortage
Monday, March 31
Comment becoming a post
"anonymous said...
How is it even remotely weak? Considering most virii spreading around these days is done via browser related vulnerabilities, I hardly would consider it "weak".
If it is so easy to discover browser vulnerabilities then how come IE7 held up on the Windows box (until the 3rd day when it was owned by flash)? How come you don't have any browser vulnerabilities credited to your name?
I hate to be "that guy", but the guy that won Pwn2Own walked away with $10k and a new laptop. I doubt he cares too much what bloggers think of him or his vulnerability, especially someone that hasn't done any similar research. Don't bash someone else's work unless you can reproduce it yourself.
Mon Mar 31, 08:55:00 AM"
My response:
Dear person-who-didn't-leave-their-name,
Who says I was bashing work? I still think it's a weak vulnerability.
I'm not saying that the guy that discovered it is stupid, or that the exploit itself is stupid -- props to him for getting 10k and a fat laptop. I'm saying that most of the journalists and bloggers out there are saying things like "Mac owned in 2 minutes". Really? Was it owned in two minutes? Or did the guy merely have the exploit already set up on his webpage before the contest began. Does that make sense? I don't like sensationalist headlines, essentially.
I'm also not saying it's easy for someone to discover the vulnerability, I am sure it took alot of research and fuzzing. I am saying now-a-days, there are alot of browser vulnerabilities. It seems like every week there is at least one. I'm not saying that the research that is done by the people isn't worthwhile, I am just not a fan of browser vulnerabilities, because, as I said.. It's easy to switch browsers.
I do think it was interesting that Windows held up until Flash was introduced. But what kind of metrics are we using here? A machine wasn't able to get exploited in one week? It takes more time than that doesn't it?
All punditry. I guess I just miss the days of remote server side exploits like ws_ftp, IIS, and the like.
Saturday, March 29
New Calendar phishing

Pwn2Own
New Calendar phishing

Friday, March 28
Top 30 podcasts in iTunes

Top 30 podcasts in iTunes

Thursday, March 27
A new podcast hits the airwaves
A new podcast hits the airwaves
Monday, March 24
Happy Birthday OSX!

Happy Birthday OSX!

Sunday, March 23
Happy Easter
Happy Easter
Wednesday, March 19
APPLE-SA-2008-03-19 AirPort Extreme Base Station Firmware 7.3.1
Fresh on the heels of yesterday's huge Apple Security Update 2008-0002, today Apple released 2008-03-19 firmware update for the current (and pre-gigabit) Airport Extreme Base Stations.
AirPort Extreme Base Station with 802.11n*
CVE-ID: CVE-2008-1012
Available for: AirPort Extreme Base Station with 802.11n*
Impact: A maliciously crafted AFP request may lead to a denial of
service
Description: An input validation issue exists in the AirPort Extreme
Base Station's handling of AFP requests, which may cause file sharing
to become unresponsive. This update addresses the issue by performing
additional validation of AFP requests. This issue does not affect
Time Capsule or AirPort Express. The fix for this issue is available
in the following separate updates:
- - AirPort Extreme with 802.11n (Fast Ethernet) 7.3.1
- - AirPort Extreme with 802.11n (Gigabit Ethernet) 7.3.1
Credit to Alex deVries for reporting this issue.
More info here. (Although, I think I posted the whole thing above...)
To update to the newest firmware, open Airport Utility that is in your Utilities Folder in Applications. (If you are using a Mac, if you are using it for Windows, well, I don't know where it's at. ;) It should automatically check for the newest update and prompt you. It's a two click download and update.
APPLE-SA-2008-03-19 AirPort Extreme Base Station Firmware 7.3.1
Fresh on the heels of yesterday's huge Apple Security Update 2008-0002, today Apple released 2008-03-19 firmware update for the current (and pre-gigabit) Airport Extreme Base Stations.
AirPort Extreme Base Station with 802.11n*
CVE-ID: CVE-2008-1012
Available for: AirPort Extreme Base Station with 802.11n*
Impact: A maliciously crafted AFP request may lead to a denial of
service
Description: An input validation issue exists in the AirPort Extreme
Base Station's handling of AFP requests, which may cause file sharing
to become unresponsive. This update addresses the issue by performing
additional validation of AFP requests. This issue does not affect
Time Capsule or AirPort Express. The fix for this issue is available
in the following separate updates:
- - AirPort Extreme with 802.11n (Fast Ethernet) 7.3.1
- - AirPort Extreme with 802.11n (Gigabit Ethernet) 7.3.1
Credit to Alex deVries for reporting this issue.
More info here. (Although, I think I posted the whole thing above...)
To update to the newest firmware, open Airport Utility that is in your Utilities Folder in Applications. (If you are using a Mac, if you are using it for Windows, well, I don't know where it's at. ;) It should automatically check for the newest update and prompt you. It's a two click download and update.
Verizon sets rules for Open Development
Verizon sets rules for Open Development
Tuesday, March 18
Questions I was Googled for today

Science fiction author Arthur C. Clarke dies aged 90
-
Without going off the deep-end here and discussing every single Snort rule keyword, I just wanted to touch on a few modifiers that people so...
-
Recently I needed the ability to grab a domain name (specifically the hostname) out of a URL using Shortcuts. I wanted to integrate this f...
-
For those of you that haven't heard of DropBox, it's essentially a synced drive that is stored on DropBox's servers (in the clou...