Friday, July 24, 2015

Web App Security Reading - 20150724

I was on a boring conference call this morning and noticed I'd accumulated quite a glut of WebAppSec reading links. I figured I'd dump them here for people to peruse and give me a way to cleanup my bookmarks :)


Tuesday, February 24, 2015

Nexus 7 and Android 5.0.2 - Lag Fix

So I'm not a heavy tablet user, but I did manage to snag a Nexus 7 (8GB) for free at a conference a few years ago. I use it (what I feel is lightly) for a few games, RSA soft token, email, some browsing/reading, etc. After upgrading to 5.0.2 it's been a painful beast. I had initially thought that this was likely due just to NEW OS and OLD hardware. However after doing some digging last night I came across a number of suggestions to wipe the cache partition. Instructions can be found here: How to wipe cache partition Nexus 7 or like this.

Friday, October 17, 2014

Things you heard here first....

So I was thinking the other night, we've got cameras everywhere now and people take "Selfies". I predict that in the not too distant future we'll have rigs for using multiple cameras or we'll have some sort of Star Trek tech that allows us to take 3D images or scenes. Therefore I'm coining the term "Self3"* or "Self3D".....that's right folks you read it here first :D

Next just this morning I caught an article on slashdot (Making Best Use of Data Center Space: Density Vs. Isolation). Which talks about an idea called "dense isolation" so I'm going to coin the term "densolation".....that's right you read it here first :)

Friday, April 04, 2014

Notables - Mar 2014

Yes I'm posting March notables in April, but I've been sitting on these for a while.
Crooked Souls : Crooked Parkers - Your soul is in question. Great site, print their citations and put them on windshields of those that park like asshats. Hopefully they save their souls by making a charitable donation.
I also came across this image and it had some meaning to me so I thought I'd pass it along:
More to follow.....

Friday, August 16, 2013

Fall 2013 TV Premiere Schedule

Monday, September 16th
8 p.m. - Bones (Global ... wiki)
9 p.m. - Sleepy Hollow (Global ... wiki)

Tuesday, September 17th
8 p.m. – Anger Management ((CTV (2?) ... wiki)

Sunday, September 22nd
10 p.m. - Hostages *NEW* (CTV ... wiki)

Monday, September 23rd
10 p.m. - The Blacklist *NEW* (Global ... wiki)

Tuesday, September 24th
8 p.m. - NCIS (Global ... wiki)
8 p.m. – Marvel’s Agents of S.H.I.E.L.D. *NEW* (CTV ... wiki)
9 p.m. - NCIS: LA (Global ... wiki)
10 p.m. - Chicago Fire (Global ... wiki)
10 p.m. - Person of Interest (New to CTV ... wiki)

Wednesday, September 25th
8 p.m. - Revolution (
10 p.m. – CRIMINAL MINDS (CTV ... wiki)

Thursday, September 26th
8 p.m. – The Big Bang Theory *One-Hour Premiere* (CTV ... wiki)
9 p.m. – GREY’S ANATOMY (CTV ... wiki)
10 p.m. - Elementary (Global ... wiki)

Friday, September 27th
8 p.m. – MasterChef Junior *NEW* (CTV)
10 p.m. – BLUE BLOODS (CTV ... wiki)

Sunday, September 29th
10 p.m. - The Good Wife (Global ... wiki)
10 p.m. – THE MENTALIST (CTV ... wiki)

Thursday, October 3rd
10 p.m. - Scandal (CityTV ... wiki)

Wednesday, October 9th
7 p.m. – The Tomorrow People *NEW* (CTV ... wiki)
8 p.m. – ARROW (CTV ... wiki)

Tuesday, May 14, 2013

Teach Parents Tech

It's funny, it's simple, check it out: Teach Parents Tech Use it, enjoy it. While Let Me Google That For You is good for various online forum replies etc, it isn't "really" family friendly, whereas Teach Parents Tech could be considered so.

Monday, April 29, 2013

Hotmail to .... Grrr Hate Web Messenger

So the upgrade Microsoft recently forced from old to has been pretty ok in my books. The interface is clean and pretty snappy performance wise.

One thing I have found that I dislike is the new auto-login to web messenger. I don't need to chat with people, this is my email interface.

Some people suggest blocking via hosts file, however that didn't seem very user friendly. I did however come across this solution which uses ad-block (or ad-block plus) and custom filters in Firefox and seems to work nicely. I didn't go to the step of customizing styles via stylish but I mostly use hotmail from large monitors where giving up 5% width isn't an issue.

Great Instructions - Disable Messenger auto-login on hotmail or web mail interfaces

Thursday, October 04, 2012

Windows 8 Keyboard Shortcuts

I'm a big fan of Keyboard shortcuts, you'll notice a number of posts previously on my blog regarding such.

I don't have Win8 yet but was just reading a review: Idea Man: Paul's take on Windows 8. I figured it would be a good move to record the following for future use/reference:

Win+C: All charms
Win+Q: Search charm
Win+H: Share charm
Win: Start charm
Win+K: Devices charm
Win+I: Settings charm
Win+Q: Search apps (tip: an even easier way to search apps is to just begin typing from the Start screen)
Win+W: Search settings
Win+F: Search files  

Apps (Metro)
Win+Z: Get to app options
Win+.: Snap app to the left
Win+Shift+.: Snap app to the right
Alt+F4: Close an app  

Win+D: Open Desktop
Win+,: Peek at desktop
Win+B: Back to desktop

Win+X: Open system utility settings menu
Win+PrntScrn: Take screenshot and save to Pictures
Win+Tab: Open switch list
Win+T: Preview open windows in taskbar
Win+U: Open Ease of Access Center
Win+Spacebar: Switch language and keyboard
Win+Enter: Open Windows Narrator

Previous Keyboard Shortcut Posts: Part 1 Part 2 Part 3

Tuesday, August 14, 2012

xkcd On Password Strength

This is an older cartoon, but I was pruning bookmarks today and came across it.

I'm going to add it here because it's one of my favs.

Monday, August 13, 2012

Fall 2012 Premiere Schedule

2012-08-28: Added Revolution.
2012-08-14: Added linkage & Last Resort details.
2012-08-13: This is a work-in-progress.

Tuesday, Sept. 11
9:30 p.m. – Guys with Kids (Global ... wiki)

Monday, Sept. 17
8 p.m. - Bones (Global ... wiki)
10 p.m. - Revolution *NEW* (

Monday, Sept. 24
10 p.m. – CASTLE (CTV ... wiki)

Tuesday, Sept. 25
8 p.m. - NCIS (Global ... wiki)
9 p.m. - NCIS: LA (Global ... wiki)
10 p.m. – CRIMINAL MINDS (New Time Period) (CTV ... wiki)
10 p.m. - Private Practice (CityTV ... wiki)

Wednesday, Sept. 26
9 p.m. – LAW & ORDER: SVU *TWO-HOUR PREMIERE* (CTV Two ... wiki)
10 p.m. – CSI (CTV)

Thursday, Sept. 27
8 p.m. – THE BIG BANG THEORY (CTV ... wiki)
8 p.m. - Last Resort *NEW* (Global ... wiki)
9 p.m. – GREY’S ANATOMY (CTV ... wiki)
9 p.m. - Person of Interest (CityTV ... wiki)
10 p.m. – FLASHPOINT (CTV ... wiki)
10 p.m. - Scandal (CityTV ... wiki)
10 p.m. - Elementary *NEW* (Global ... wiki)

Friday, Sept. 28
9 p.m. - Fringe (CityTV ... wiki)
10 p.m. – BLUE BLOODS (CTV ... wiki)

Sunday, Sept. 30
8 p.m. – THE AMAZING RACE (CTV ... wiki)
10 p.m. - The Good Wife (Global ... wiki)
10 p.m. – THE MENTALIST (CTV ... wiki)

Wednesday, Oct. 10
8 p.m. – ARROW *NEW* (CTV Two ... wiki)
10 p.m. - Chicago Fire (Global ... wiki)

Friday, Oct. 26
8 p.m. - Touch (Global ... wiki)

Tuesday, October 11, 2011

CIRA IDN Consultation

I may update this with further thoughts later, but I wanted to get this up so people became aware of it....

Check it out, get a chance to have your thoughts heard:

"When a domain name works with any character beyond the a-z alphabet, it's called an Internationalized Domain Name (IDN). CIRA is considering the implementation of French character IDNs so that .CA domain names can be written correctly in French. Find out more about IDNs and about our proposed launch policy."

While I think this is an interesting idea I see lots of problems with implementing this change.

  1. Lots of software will have to be updated to accommodate the change (DNS server software, DNS client software, all kinds of security packages [AV, FWs, IDS, IPS, etc])...

  2. Adding other characters to DNS just BEGS FOR ABUSE. Think of the phishing possibilities using Domain Names with accented characters?

  3. The change requires user education that will NEVER happen. it's hard enough to get users to pay attention to standard English domain names...

  4. Companies will now have to pay for and maintain registrations for even more DNS entries for actual translations of their name and the numerous misspellings (assuming they care that a malicious individual may squat on such and ruin their name etc).

I haven't been able to find out but I doubt that anyone has actually done any analysis vs. Canadian HoneyPots/HoneyDNS to see if users are actually trying to use accented characters for DNS. It seems like this is going to "fix" something that isn't broken or add support for something that the community doesn't really need or want.

If the greater community actually wants to do this why don't we go full foreign character support at the same time? Fix/enhance software to handle all characters at the same time (instead of piece-meal), etc.