<?xml version='1.0' encoding='utf-8' ?>

<rss version='2.0' xmlns:lj='http://www.livejournal.org/rss/lj/1.0/' xmlns:atom10='http://www.w3.org/2005/Atom'>
<channel>
  <title>Praise then darkness, and creation unfinished</title>
  <link>https://redbird.dreamwidth.org/</link>
  <description>Praise then darkness, and creation unfinished - Dreamwidth Studios</description>
  <lastBuildDate>Tue, 21 Nov 2017 19:59:55 GMT</lastBuildDate>
  <generator>LiveJournal / Dreamwidth Studios</generator>
  <lj:journal>redbird</lj:journal>
  <lj:journaltype>personal</lj:journaltype>
  <image>
    <url>https://v2.dreamwidth.org/222785/52751</url>
    <title>Praise then darkness, and creation unfinished</title>
    <link>https://redbird.dreamwidth.org/</link>
    <width>94</width>
    <height>100</height>
  </image>

<item>
  <guid isPermaLink='true'>https://redbird.dreamwidth.org/2736193.html</guid>
  <pubDate>Tue, 21 Nov 2017 19:59:55 GMT</pubDate>
  <title>new lock</title>
  <link>https://redbird.dreamwidth.org/2736193.html</link>
  <description>We had a locksmith here this morning to replace the lock (cylinder) on the apartment door.&lt;br /&gt;&lt;br /&gt;This is because, around lunchtime yesterday, the door to our apartment opened. The upstairs neighbor, not really paying attention, had gotten off the elevator at our floor, walked to this corner of the building, put the key in the lock of what he thought was his apartment, and turned it.&lt;br /&gt;&lt;br /&gt;Obviously, this isn&apos;t supposed to happen. I&apos;ve tried to unlock the wrong door before; sometimes the key will go in, but it doesn&apos;t turn. Yes, there are a finite number of lock cylinder designs, but apartments 31 and 51 in the same building shouldn&apos;t have the same one, because people are more likely to try to walk into the apartment right downstairs than some other random house on the same street.&lt;br /&gt;&lt;br /&gt;Before he left, we asked the neighbor to verify that his key really did work in our lock (i.e., that &lt;span style=&apos;white-space: nowrap;&apos;&gt;&lt;a href=&apos;https://cattitude.dreamwidth.org/profile&apos;&gt;&lt;img src=&apos;https://www.dreamwidth.org/img/silk/identity/user.png&apos; alt=&apos;[personal profile] &apos; width=&apos;17&apos; height=&apos;17&apos; style=&apos;vertical-align: text-bottom; border: 0; padding-right: 1px;&apos; /&gt;&lt;/a&gt;&lt;a href=&apos;https://cattitude.dreamwidth.org/&apos;&gt;&lt;b&gt;cattitude&lt;/b&gt;&lt;/a&gt;&lt;/span&gt; hadn&apos;t forgotten to lock up an hour before that). Then we called building management, who said the locksmith would be here between 9 and 10 this morning. He got here about 9:15, after first changing the cylinder on the upstairs apartment. He then went back upstairs, saying he wanted to make sure we now had unrelated cylinders, returned and gave us the new keys, taking the old cylinder and keys with him.&lt;br /&gt;&lt;br /&gt;As locksmith adventure go, this is pretty tame: nothing was lost or damaged, nobody was locked out, and it cost us nothing (though I&apos;ll be spending a couple of dollars at a hardware store to make &lt;span style=&apos;white-space: nowrap;&apos;&gt;&lt;a href=&apos;https://adrian-turtle.dreamwidth.org/profile&apos;&gt;&lt;img src=&apos;https://www.dreamwidth.org/img/silk/identity/user.png&apos; alt=&apos;[personal profile] &apos; width=&apos;17&apos; height=&apos;17&apos; style=&apos;vertical-align: text-bottom; border: 0; padding-right: 1px;&apos; /&gt;&lt;/a&gt;&lt;a href=&apos;https://adrian-turtle.dreamwidth.org/&apos;&gt;&lt;b&gt;adrian_turtle&lt;/b&gt;&lt;/a&gt;&lt;/span&gt; a new key).&lt;br /&gt;&lt;br /&gt;&lt;img src=&quot;https://www.dreamwidth.org/tools/commentcount?user=redbird&amp;ditemid=2736193&quot; width=&quot;30&quot; height=&quot;12&quot; alt=&quot;comment count unavailable&quot; style=&quot;vertical-align: middle;&quot;/&gt; comments</description>
  <comments>https://redbird.dreamwidth.org/2736193.html</comments>
  <category>quotidian</category>
  <category>security</category>
  <category>home</category>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>https://redbird.dreamwidth.org/1522343.html</guid>
  <pubDate>Fri, 30 Dec 2016 23:31:51 GMT</pubDate>
  <title>A thought on deleting LiveJournal accounts</title>
  <link>https://redbird.dreamwidth.org/1522343.html</link>
  <description>I know a bunch of people who are deleting their LiveJournal accounts because they&apos;re worried about the servers now being in Russia. One of them noted that they didn&apos;t want their private data being available for Putin&apos;s use.&lt;br /&gt;&lt;br /&gt;That strikes me as a good reason not to put anything private on LJ from now on, but what&apos;s there is there. I commented: &lt;br /&gt;&lt;br /&gt;Don&apos;t count on SUP to actually overwrite or otherwise get rid of the data if you delete a journal. Keeping the files while claiming they were gone wouldn&apos;t even be technically difficult: the software is &lt;em&gt;already&lt;/em&gt; supposed to keep the contents of deleted journals for 30 days in case you change your mind. My inexpert hunch is that deleting an individual entry, or editing it to replace your private content with quotes from Shakespeare or Alice in Wonderland or the first umpteen digits of pi is more likely to actually get rid of the data.&lt;br /&gt;&lt;br /&gt;&lt;img src=&quot;https://www.dreamwidth.org/tools/commentcount?user=redbird&amp;ditemid=1522343&quot; width=&quot;30&quot; height=&quot;12&quot; alt=&quot;comment count unavailable&quot; style=&quot;vertical-align: middle;&quot;/&gt; comments</description>
  <comments>https://redbird.dreamwidth.org/1522343.html</comments>
  <category>security</category>
  <category>meta</category>
  <category>lj</category>
  <category>political</category>
  <lj:security>public</lj:security>
  <lj:reply-count>7</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>https://redbird.dreamwidth.org/1488869.html</guid>
  <pubDate>Mon, 01 Feb 2016 23:18:50 GMT</pubDate>
  <title>further adventures in security questions</title>
  <link>https://redbird.dreamwidth.org/1488869.html</link>
  <description>I logged in to the TIAA-CREF website today (my retirement funds are with them, because my former employer somehow qualified as an academic institution), and they wanted me to update my security profile.&lt;br /&gt;&lt;br /&gt;That turned out to include adding security questions. The list of options this time includes, along with things that seem too easy to look up, and things that don&apos;t apply (I didn&apos;t go to the prom), several to which my reaction was &quot;I don&apos;t know&amp;hellip;&quot; I could ask my mother for my maternal grandmother&apos;s middle name; I&apos;m not sure there&apos;s any way to find out what city my paternal grandmother was born in. What country, maybe (she was born in Russia, before the revolution, and I think my father said it was Ukrainian, but we had that conversation when it would have been the Ukrainian SSR].&lt;br /&gt;&lt;br /&gt;Still, I found some I could answer without making up something random and writing it down in the list of passwords (the software would let me put &quot;How-would-I-know&quot; for my grandmother&apos;s middle name, and might have accepted &quot;pi=3.141592,&quot; but then I would need to remember having said that), and maybe I&apos;ll ask my mother for her mother&apos;s middle name the next time we talk.&lt;br /&gt;&lt;br /&gt;&lt;img src=&quot;https://www.dreamwidth.org/tools/commentcount?user=redbird&amp;ditemid=1488869&quot; width=&quot;30&quot; height=&quot;12&quot; alt=&quot;comment count unavailable&quot; style=&quot;vertical-align: middle;&quot;/&gt; comments</description>
  <comments>https://redbird.dreamwidth.org/1488869.html</comments>
  <category>random information</category>
  <category>security</category>
  <lj:security>public</lj:security>
  <lj:reply-count>5</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>https://redbird.dreamwidth.org/1196295.html</guid>
  <pubDate>Fri, 12 Feb 2010 00:50:21 GMT</pubDate>
  <title>PSA: Chip-and-pin broken</title>
  <link>https://redbird.dreamwidth.org/1196295.html</link>
  <description>The chip-and-pin authentication system is &lt;a href=&quot;http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-is-broken/&quot;&gt;badly broken&lt;/a&gt;, such that a hacker/thief with anyone&apos;s chip-and-PIN Visa or Mastercard can make arbitrary purchases. The problem appears to be that these cards can be used with chip and pin, or chip and signature, and by telling the card they&apos;re using one and the terminal they&apos;re using the other, people who know where it&apos;s broken can make purchases using any arbitrary PIN. The problem behind the problem is that there are lots of different, overlapping implementations of the security for chip-and-PIN, and lots of people with unsupported confidence that their implementations are sound.&lt;br /&gt;&lt;br /&gt;The researchers reported this to the banking industry a couple of months ago. They note that this may explain at least some of the cases of phantom withdrawals. It may make it harder for the banking industry to deny refunds on the grounds that the challenged transactions were authenticated with a PIN: the researchers demonstrated using this attack on a system that was calling the bank for authentication, getting the authentication, and completing the transaction.&lt;br /&gt;&lt;br /&gt;A cancelled card is still a cancelled card, and won&apos;t be authorized even with this attack. Also, it doesn&apos;t work at ATMs/cashpoints, only at merchants. But there are lots of stores that will sell any number of things that a thief either wants or can resell. &lt;br /&gt;&lt;br /&gt;(If you&apos;re North American and don&apos;t know what chip-and-PIN is, hope that this gets fixed for real, and on a large scale, before it&apos;s implemented as &quot;security&quot; for our credit and debit cards.)&lt;br /&gt;&lt;br /&gt;[via Bruce Schneier]&lt;br /&gt;&lt;br /&gt;&lt;img src=&quot;https://www.dreamwidth.org/tools/commentcount?user=redbird&amp;ditemid=1196295&quot; width=&quot;30&quot; height=&quot;12&quot; alt=&quot;comment count unavailable&quot; style=&quot;vertical-align: middle;&quot;/&gt; comments</description>
  <comments>https://redbird.dreamwidth.org/1196295.html</comments>
  <category>financial</category>
  <category>signal boosting</category>
  <category>security</category>
  <category>psa</category>
  <lj:security>public</lj:security>
  <lj:reply-count>1</lj:reply-count>
</item>
</channel>
</rss>
