Posts

U.S federal laws you should learn about that pertain to computer crimes

Introduction Today, we are going to discuss a list of U.S federal laws, that you should probably be familiar with if you want to become a Information Security "pro" or a Security Administrator here in the U.S. I am going to reference the SANS document below [1] as your primary resource, but I am briefly going to summarize and bullet-list each U.S federal law. You may also need to know any of these laws, if you have to work with local law enforcement or other federal investigators such as the F.B.I and D.H.S CISA, if your company has suffered some sort of major data breach. Even if you ARE NOT a lawyer it does help to have a firm grasp of these laws in context and an understanding of what they mean. Let's begin: U.S Federal Computer Laws: Computer Fraud and Abuse Act - This law is used for charging Black Hat Hackers with crimes, which include DDoS attacks, data breaches, and using malicious code to damage computer networks. If the damage is more then $5,000 dollars t...

A general "checklist" for securing MySQL/MariaDB varient relational databases in Linux

Introduction I am back with a a new topic for this week! a couple of months ago, I was playing around with and testing out MySQL database here in Fedora, so that I can learn the ropes for it if I need to configure and use it someday! I decided to create a simple security "checklist" for the first blog entry this week, to help get you moving in the right direction, after reading some suggestions from the manual. Instead of going into a detailed fashion, about what exact steps you need to take to secure the database in the best possible fashion exactly, I am going to list some "general" purpose steps that you can take if you are building a LAMP stack for instance in Linux. Here is the list (It's not exhaustive), but I may or may not add more resources to it in the future! [1] Common Security tips for securing MySQL/MariaDB databases: Make sure that only certain individuals have "root" access to the database (see below) Always put root passwords into ...

Practical applications for I.T professionals looking to implement Symmetric Cryptography in Windows/Linux

Introduction Hello everyone, I FINALLY have a "somewhat" new topic to discuss in this weeks entry. I noticed a lot of professors who attempt to teach Network Security to their students either in a Computer Science or I.T setting do a very poor job of actually teaching the concepts and instead focus on a lot of "jargony" high-level Number Theory, that is truly not necessary if you plan on implementing cryptographic algorithms! This might be fine for an advanced subject of Cryptography in general, but often leads students confused and quite frankly puts most of them to sleep. Today instead I am going to be focusing in on "tools" one could potentially use in order to implement Network Security on computers in a way that makes sense in their school projects or in their day to day I.T job. I am briefly going to cover an number of of pieces of software that can be used for hard-disk encryption. Without further ado, we can begin to break everything down and le...

A collection of recursive algorithm techniques in C that can be applied to real-world applications

Introduction Hello avid blog readers! After months of enjoying the summer and basking in the warm weather, I am finally back with an entry for the month of September. Today I am going to look at something that is a little more on the technical side and something that mostly only software developers would care about. If you aren't interested in the inner workings of recursive algorithms and how one can implement them in C, feel free to skip this entry. I will be back with another one for the month of October, that might be more accustomed to the usual entries and topics that I am discussing in this blog. Let's begin and start with the basics (Note: This blog entry assumes you have never taken a Computing I or II course before in college and have no prior knowledge writing algorithms in C. It DOES ASSUME you are familiar with the C programming language though) What is recursion? Recursion according to a simple definition in [1] is a circular definition. When something is d...

Encoding Opus files in Linux with opusenc for your own collection and HTML 5

Introduction Hello everyone! I am finally back to writing a new blog entry, after taking a very long month off. I hope all of my U.S readers had a great Fourth of July and are enjoying the summer. Today, I am going to be discussing and showing you how to encode with the the new IETF working audio codec called "Opus". Briefly, Opus is a combination of Xiph.org "CELT" codec and Skype's "SILK" codec combined into one project. It's a low-latency audio codec that was designed with "scalability" in mind and does things "fundamentally" different, even though it should sound the same if not better in different situations for speech and music. The project was finally completed this past winter and standardized and will be used in the new WebRTC project (for video conferencing), Skype (for video calls), and other companies that wish to use it. Google is NOW (as of July 2013) incorporating it, into the next generation codebase of WebM, wh...

Three "must listen" to Thin Lizzy albums from the 70's you should hear in your lifetime if you are fan of "Vintage Rock"

Introduction Hello, everyone. I am back this week after taking a long month off. In this month's entry, I am going to be switching gears back to the topic of music. No one can and should underestimate the value that music has on society and it's cultural significance. Today, I am briefly going to be looking at three of what I would argue are three of Thin Lizzy's "best" albums from the late 1970's and the significant impact they have had on Rock N' Roll over the last fourty or so years. I am going to rate them and then try to convince you the listener, why you should listen to them or at least "consider" listening to these albums if you are a fan of Vintage Rock. Like always, it will be up to you determine whether or not they have any intrinsic value. Now that I have got that out of the way, I can begin to describe my favorite Thin Lizzy albums from the 1970's: Three of my top favorite Thin Lizzy albums Bad Reputation (1977) - Phil Lyno...

Why I am proud to be a Bostonian and why you should visit sometime!

Introduction I first want to apologize for my month long absence, if you are a monthly reader to my blog. Many events has transpired over the last month or so. I was finally able to complete two out of three courses that I started back in January. One of them was collectively referred to as "Legal Aspects of Cyberspace". I took this course in a effort to increase my "legal knowledge" for this blog, and so that I could consult with an expert or someone with a J.D in aspect of the legal field, be it Intellectual Property all the way up to Criminal law! Having this knowledge helps me to help you the reader, better understand legal concepts and how exactly the law works on a case by case basis. In any event, I was happy to complete that course successfully with an A. The other reason I have not had time to update is simply, because my city has come under a domestic terrorist attack as of late. Unless you live under a rock you can see from every "news" media o...

My top five "must play" video games of 2013

Introduction This week I am back with a new entry for all of my readers. This entry is going to be abbreviated, simply because I do not have a lot of time to go into lengthy technical post regarding tech stuff. Next week's entry or the week after next, I will try to find some technical stuff that I believe you "may" find interesting. Today, I am going to discuss my top five "must play" video games of 2013! If you are avid gamer or even if you are not, you may have these same games on your list. Many of the "most anticipated" games of 2013 are coming out this month (in February) or next month in March. Here are the list of games that made my top five list, with some commentary describing what the game is about and why you may want to "consider" picking yourself up a copy or buying it on the net. Like always, you may agree or concur with my particular "tastes". If there are other games that you feel deserve to be on the list or you ...

What the U.S vs. Fricosu (2011) case "might" mean for future law and Cloud Computing cases regarding encryption!

Introduction Hello readers! I have been working on school stuff and finally at the end of the week do I now have time to update "The Labyrinth" and discuss "important" developments that you need to know in the field of Law and Technology!. It also helps greatly, that I am taking a "computer law" course this semester as a free elective for my major, along with two other courses in an effort to obtain my Bachelors degree in December, but enough about that. Let me give you a "brief" overview, regarding what I am going to be discussing today. In this week's entry, I am briefly going to summarize the U.S vs. Frisocu (2011) case and how it "may" related to future law cases involving encryption and encryption in the "cloud" i.e the developments we are seeing play out with the Kim Dot Com "strategy" (Note: I am not going to comment on whether or not "Mega" website is "ethical" or not. You should go ...

Fifteen or more "must listen" to Definitive Deep & Tech House productions you need to hear on Spotify

Introduction I promised an entry on more law stuff, but because it requires a substantial amount of information and time to write, I am putting that off for another couple of weeks. Also, I "redesigned" the layout template, so that it's much "cleaner" looking! In today's brief post, I am going to be sharing the recent "collaborative" playlist that I created on Spotify. If you are a user who enjoys listening to EDM (Electronic Dance Music) and are interested in more of the "underground sound", rather then faux paux commercial stuff that is played on the radio, you will definitely appreciate this playlist. It's a blend of Deep House and Tech House. Briefly, Deep House has been around, since the early 90's and consists of usually deep resonating bassline, "soulful" vocals, shorter track lengths (on average of five minutes), and a mid-tempo BPM range around 118-122 BPM. Tech House usually complements Deep House. It's t...

Revisiting the "ZeroAccess" rootkit and understanding why earlier variants continue to propagate on the Internet

Introduction Welcome back! this week, I will be discussing the "ZeroAccess" rootkit, revisiting how it works, what can remove it, and why this piece of malware has seen a tremendous surge as of late, after having first been discovered in 2010! Briefly, the "ZeroAccess" rootkit is a "stealthy" piece of malware that usually installs itself, via a "drive-by-download" on the Internet or it's sometimes called in the hacking world "pharming". Some of these websites consist of javascript code written using, what programmers refer to as "shellcode" to take advantage of zero-day exploits in either the web-browser itself (something that has declined steadily over the last few years, because of sandboxed apps like Google Chrome) or Java and Adobe PDF! The exact "mechanism" is quite complicated and varies from machine to machine, generally unpatched XP, Vista, or Windows 7 machines are usually the BIGGEST targets (XP espec...

Why one should be "concerned", but not "paranoid" about I.T security in the age of "big data"!

Introduction I am back writing again this week, after a rather abbreviated entry last weekend, surrounding a couple of albums from the 1980's I was listening to, that sounded as though they were twenty-years ahead of their time. This week, I will be talking about the "Psychology of security" if you will and the "paranoia" surrounding it!. It should be dully noted, that this weeks entry was inspired by a rather "elegant rant", but some poster on "Slashdot" a couple of days ago, that was being blown out proportion (you can look up the post yourself on their if you would like, I won't be referencing here, because I consider it be "nonsensical" in some regard). Let's start by separating "fact" from "fiction". Afterwards, we will continue to work our way into conclusion about "news" sites on the Internet, from there on out. "Fact" vs. "Fiction" and some underlying "assum...

A short list of three "must listen" to sleeper albums from the 1980's that were twenty years ahead of their time

Introduction I wanted to start off this week's entry, by saying I hope everyone in the U.S and all of my readers around the world enjoy the upcoming holiday and have a wonderful New Years!. In this week's entry, I am going to be exploring music from the 1980's AGAIN (this may or may not be a re-occurring theme in the future). The difference between this week's entry and the music entry I wrote a couple of weeks ago, is these albums (while 80's in nature) sound as though they could have been written in this decade or even today for that matter! These artists and albums were about twenty-years ahead of their time. If you like "old classics" that don't sound as though they written thirty years ago, you will like this week's entry! Here is the list I came up with. Like always, you may agree or concur with it. If you have any comments or concerns let me know! Here is a short list I came up with this weekend: "sleeper" albums from the 1980...

The delicate balance between protecting security and eroding civil liberties under U.S Foreign Intelligence Surveillance Act

Introduction In this week's entry, I will be discussing a piece of U.S legislation that has been in place, since the Carter Administration in the United States circa 1978. I realize I have several readers, from all over the world, including the U.S who read my blog on weekly basis. This law is applicable to readers outside of the U.S, but will only make sense to you are familiar with U.S statutory laws. It applies to both U.S and non-U.S citizens equally, but from a civil liberties standpoint ONLY if you are U.S citizen. The first question your probably asking is what is this law about and how does it apply to computers? The answer to that in short, is according to most Criminal Justice textbooks, FISA is a law that dictates how and when the U.S is able to conduct electronic surveillance for foreign intelligence and national security purposes outside of the U.S. It's been the subject of frequent debate [1] here in the U.S, in post 9/11 world on, whether or not there is enough...

A list of five "must listen" to 80's rock/pop albums the defined the decade!

Introduction I have decided to "mix" things up a bit and discuss my other favorite past-time in this weeks first blog entry "music". Today, I am going to be taking a break from I.T and I.T law subjects that I have been hammering home, over the last few entries. I will be discussing a list of "five" must have albums that I believe IMO "defined" the 1980's, that you must must listen to, if you enjoy various genre's of music in general. These were handcrafted from my own personal collection! enjoy. You may agree or concur with the list. Without further ado, here are the five albums that I came up with handpicked! Five 80's Rock/Pop albums that "defined" the decade Michael Jackson - Thriller (1982) - Michael Jackson second solo album with producer Quincy Jones that has sold over 50 million copies worldwide, making it the single best selling album of all time!  Prince - Purple Rain (1984) - An album based around the ficti...

Transcoding with Theora 1.1/1.2 using ffmpeg2theora 0.28 or better for your own collection in Linux and HTML 5 video

Introduction Today, I am going to be showing you how to encode with Theora 1.1 library using ffmpeg2theora 0.28 tool in Linux. Briefly, Theora is an open source video codec, that was donated to the Xiph.org foundation by On2 video in 2004 (The same company Google recently bought that consists of VP8 codec portion in WebM!). Attempts where made to include it in the HTML 5 standard in 2007, by members of the W3C. Those attempts were met with heavy resistance. One of the main problem with the earlier builds of Theora, was the perceived lack "quality" with encoder and how it was not on "par" with H.264 standard put forth by the MPEG consortium. Proponents of the H.264 video, claimed it was "inferior", because it did not have the same level of glossy sophistication and there were too many macro-blocking artifacts, due to a older codebase with no bi-predictive frames, such as those of the newer more advanced H.264 codec. The lead developer and engineer of ma...

Transcoding H.264 files to Google's WebM format (VP8/Vorbis) in FFMPEG 0.6 or better using Linux for your own collection and HTML 5

Introduction Note: I want to stress that I DO NOT CONDONE using this guide to encode movies that are infringing upon international and local copyright laws (which include the WIPO Treaty in Europe and the DMCA in the U.S). These examples ASSUME your encoding material in which you OWN The RIGHTS too! I will not be held responsible for individuals that are using it to encode copyrighted material in those respective countries! If there are disputes about this or any other questions please DO NOT hesitate to contact me right away! Thank you. This week I am going to focus on showing you how to transcode videos to WebM, which is playable in both VLC and most HTML 5 compatible web browsers including Firefox, Chrome, Opera, and I.E 10! If you recall way back several months ago (if you had been following my old blog) I showed you some code snippets for how to encode directly to WebM using an older version of libvpx 0.6.1 code named "Bali", that came out last year, but has since be...

Encoding Vorbis files in Linux using oggenc for your own music collection and HTML 5

Introduction In today's topic, I will be showing readers different ways you can encode your music collection, if you just moved over to Linux from Windows using open source codecs! You do not have to encode your music files with Vorbis, due to the fact that MP3 is also supported in Linux and HTML 5, but there are some substantial benefits to doing in this day and age (at least from the perspective of an open-source nerd 8-)). The first is you don't have to worry about royalty's and licensing rates (especially if you are opening up a store for indie musicians). The second is that both objectively and subjectively Vorbis sounds substantially better and has been greatly improved with the help of dedicated "audiophiles" and the open source community, since it's first public release over a decade ago, way back in 2002. Today, I will show you some tips and tricks if you are new to encoding your music collection in Linux using the oggenc command-line program in Li...

The three "biggest" U.S I.T Regulatory Compliance laws every Information Security professional should know by heart!

Introduction Everyone knows how complicated regulatory laws can become, luckily for us our "good friends" over at Microsoft have put together a page that sums up what you need to know about I.T regulatory compliance laws. Microsoft summarizes each one and goes into more depth. I am just going to provide a brief overview of what federal laws, you need to focus on if your organization is part of any of the industries, mentioned on the Microsoft page I referenced and below. Note: Some states have state law statutes surrounding regulatory compliance frameworks, such as California and my home state of Massachusetts! Microsoft does NOT mention every state law statue below (just California). The United States is one of the "few" countries in the world that has "strict" state and federal laws surrounding regulatory compliance, unlike i.e United Kingdom. Keep that in mind as you move forward, due to the fact that these laws may overlap and you might have to u...