If you use CentOS like I do (which usually just means you're too cheap to use RHEL, like I am), then this may be of interest to you. Jim Perrin, of BOFH Hunter recently created a new page under the CentOS wiki HOWTO section called OS Protection. It serves as a guide to hardening CentOS [...]
CentOS Wiki - Hardening CentOS Guide
July 20, 2009
Encryption tools for Sysadmins
June 29, 2009
Every once in a while, someone will ask me what I use for keeping passwords securely. I tell them that I use password safe, which was reccommended to me when *I* asked the question. Other times, people will ask for simple ways to encrypt or store files. If you're looking for something robust, cross platform, [...]
Ouch.
May 15, 2009
More on the security front, flight simulator site Avsim had its entire datastore wiped out by a cracker. That reminds me, I've got to change my tapes.
Security is a process and not plug&play
May 15, 2009
I got a SANS pamphlet in the mail today, which makes me feel guilty. Not really guilty, as in "I should go but I'm not" (even though I should, and I'm not), but because in terms of IT security, I've sort of been in the "Oh, I'm sure that'll be fine while I'm doing all [...]
Musings on Computer Security
February 23, 2009
This is another from my LiveJournal, written October 14th, 2006: While reading my new "Netscreen Firewalls" book for work, I chanced upon the following sentence (paraphrased): "ScreenOS is more secure than open source operating systems, because it's source is unable to be searched for vulnerabilities" Normally I would ignore such tripe as the rantings of [...]
Password retention and storage
August 28, 2008
I got an email from a reader yesterday asking about how I generated and stored my passwords securely. The reader was interested in what methods were available to sysadmins for managing diverse passwords for different machines and devices. I had to laugh at my password generation scheme (run 'fortune' a couple of times, pick some [...]
Posted in




Email me



content rss