My experience on my daily works... helping others ease each other

Showing posts with label Critics. Show all posts
Showing posts with label Critics. Show all posts

Wednesday, March 21, 2012

IETC-RFC 6561 - Recommendations for the Remediation of Bots in ISP Networks

Dear All,

IETC (Internet Engineering Task Force) has release a recommendation for remediation of Bots in ISP Networks (Release for Comments) number 6561 (ISSN: 2070-1721). Lead by Livingood and shared by ISOC.org.

It can be viewed from ISOC site or view from here.
Share:

Friday, March 16, 2012

Improved Recursive Function that is not improving at all

#include

#include
void printIntegesr(int n);
main()
{
   int number;
   cout << “\nEnter an integer value :”;
   cin << number;
   printIntegers(number);
}


void printIntegers (int nom)
{
    cout << “\Value : “ << nom;
    printIntegers (nom);
}

The above is the original recursive function which will definitely put the program in infinite mode.


#include
#include


void printIntegers(int n);


main()
{
   int number;
   cout<<“\nEnter an integer value :”;
   cin >> number;
       printIntegers(number);
}


void printIntegers (int nom)
{
    if (nom >= 1)
          cout << “\Value : “ << nom;
     printIntegers (nom-2);
}

What is wrong with the above 'improved recursive function'?

Not sure? Guess what will happen if the condition is met? It will print out the value and then move to the next step and continue to call the function again. What if the condition failed? It will just call the function again. And this will continue in a never ending loop.

The above two code is extracted from a lecture note. An email has been send to them for confirmation.

How to solve that?

Here the fraction of it on how it can be solved.... have fun trying. BTW, the above infinite loop code will allowed hackers to hack into the program :)

void printIntegers (int nom)
{
    if (nom >= 1)
          cout << “\Value : “ << nom;
    if ( nom < 1 )
         exit(1);
     printIntegers (nom-2);
}
Share:

Anonymous is good and Google is dirty word

1. Anonymous is 'good' for security
Exploits of hacktivist group help improve companies' security posture by exposing vulnerabilities, but its threat remains despite key members of the group being arrested, security insiders warn. Read detail at ZDNet Asia

Comments:
The author said that the group is good to business of security company but put up lots of damages to the effected victims. As for me, the good of them is absolutely more than the bad things. After all, there are also white-hat hackers whom get paid for hacking. This 'Anonymous' do it for free and what they did is beyond capability of white-hat hackers. Why? Because the managed to hack without getting information from the victims whereas the good hackers had preliminary discussion first before hacked and they normally hacked what is allowed. "Your best friend is Your ENEMY. He will describe everything you are exactly including your weaknesses" - Sun Tzu in Art of War.

2. 'Google' a dirty word in healthcare services.
Two days ago, I returned to the healthcare services provider, where I had done the examination, for a review of the results and to get any advice on problem areas I might have with regard to my well-being.

I was told I had borderline cholesterol levels, so I asked the doctor what foods I should avoid and what I should consume more of to bring the numbers down to the normal range. Her reply? "Go Google it."
Read the full article at ZDNet Asia
 
Comments:
The author is sharing her friends experience on meeting a doctor that proposed her to 'google' for sample of healthy food and how frustrated the person was when he/she was expecting a good proposal from the doctor. And there are few comments too.
Yes, I do agreed that the 'Internet of Things' started by Google and other IT giant had make people like me gone lazy on sharing our expertise and advises. It is a bit tired of saying same things continuously. Thus, by putting the information on the NET and make it available for access to all is much easier and reduce the tense. However, the information in this 'boundless' world should not be used as total information. It should be used to enhance knowledge thus ensure when you met a doctor or expert, you can discuss better and get better input.

That's all my comments on this two articles.
Share:

Monday, March 12, 2012

Comparative Analysis on 7 Commercial Anti-Virus

This is a report on comparative analysis done by PassMark Software on seven known commercial anti-virus tools. The comparative analysis is done on:

  1. ESET Smart Security 4 Business Edition
  2. Kaspersky Business Space Security
  3. McAfee Total Protection for Endpoint
  4. Microsoft Forefront Client Security
  5. Symantec Endpoint Protection
  6. Sophos Endpoint Security and Data Protection
  7. Trend Micro Worry-Free Business Security: Standard Edition


The criteria used for evaluation are:

  1. Installation and configuration
  2. Migration
  3. Default Policies
  4. Client Installation
  5. Interface Design
  6. Client and Policy Management
  7. Remote Management
  8. Updates
  9. Common Use Cases
  10. Effectiveness
  11. Performance


Based on the comparative analysis done, ESET came out first and followed by Kaspersky and Symantec. For detail reports, please get it here.


I'm looking for comparative analysis on free/OSS antivirus tools as I believed many home/personal user will used this rather than spending extra pocket money to used commercial anti-virus product.

On the other hand, this evaluation is more generic evaluation. I do preferred a detail analysis on Effectiveness and Stability and Zero-day attack prevention capability which is not performed here. Anyway, it can be a baseline/guides for those who wish to buy any of the seven commercial product for their business needs.
Share:

Thursday, January 19, 2012

Memory Overflow: C versus Java

Memory overflow (a.k.a buffer overflow, buffer overrun, overflow) is a vulnerability in applications causes by programming errors or ignorant of security by developers [1], [2], [3]. Memory overflow is a vulnerability whereby an attackers or hackers can exploit a code in programs that can trigger overflow in Computer's memory system (stack, heap, BSS, and data segment) [4], [5], [6], [7], [8], [9]. Between all programming, this issue is significant in C and Java [10], [11], [12], [13]. Between C and Java, the issue is more critical in C than Java [14], [15], [16]. Table below shows the comparison that I've done between those two.

Table 1: C versus Java





















References:
[1] Viega, J., & McGraw, G. (2002). Building Secure Software: How to Avoid Security Problems the Right Way (2nd Printing ed.). Addison-Wesley.

[2] Seacord, R. (2005). Secure Coding in C and C++. United States of America: Addison-Wesley Professional.

[3] Kaspersky Lab ZAO. (n.d.). Software vulnerabilities . Retrieved November 19, 2011, from Securelist: http://www.securelist.com/en/threats/vulnerabilities?chapter=35

[4] Sycracuse University. (2011). Buffer-Overflow Vulnerabilities and Attacks.

[5] Kratkiewicz, K., & Lippmann, R. (2005). A Taxonomy of Buffer Overflows for Evaluating Static and Dynamic Software Testing Tools. NIST Workshop on Software Security Assurance Tools, Techniques, and Metrics. Long Beach, California.

[6] Fayolle, P. -A., & Glaume, V. (2002). A Buffer Overflow Study: Attacks and Defenses. Unpublished, SecurityFocus.

[7] Kundu, A., & Bertino, E. (2011). A New Class of Buffer Overflow Attacks. Proceedings of the 2011 31st International Conference on Distributed Computing Systems (pp. 730 - 739). Minneapolis: IEEE Computer Society.

[8] Conover, M., & Team, w. S. (1999, January). w00w00 on Heap Overflows. Retrieved November 28, 2011, from CGSecurity: http://www.cgsecurity.org/exploit/heaptut.txt

[9] Shao, Z., Zhuge, Q., He, Y., & Sha, E. H.-M. (2003). Defending Embedded Systems Against Buffer Overflow via Hardware/Software. Proceedings of the 19th Annual Computer Security Applications Conference. Washington, DC, USA: IEEE Computer Society.

[10] Cenzic Inc. (2009, November 9). Cenzic Web Application Security Trends Report Shows Increase in Hacker Attacks on Web Sites Exploiting Faults in Popular Web Browsers and Software. Retrieved January 30, 2011, from http://www.cenzic.com/pr/200911091/

[11] MITRE Corporation. (2012). Vulnerability Search. Retrieved January 10, 2012, from CVE Details - The ultimate security vulnerability datasource: http://www.cvedetails.com/vulnerability-search.php

[12] MITRE Corporation. (2012). Vulnerability Search - Java Overflow. Retrieved January 10, 2012, from CVE Details - The ultimate security vulnerability datasource: http://www.cvedetails.com/vulnerability-search.php?f=1&vendor=&product=Java&cveid=&cweid=&cvssscoremin=&cvssscoremax=&psy=&psm=&pey=&pem=&usy=&usm=&uey=&uem=&opdos=1&opec=1&opmemc=1&opov=1

[12] Mandalia, R. (2011, December 07). Microsoft Holds Java Vulnerabilities Responsible in Nearly Half of All Attacks. Retrieved January 10, 2012, from ITProPortal - 24/7 Tech Commentary & Analysis: http://www.itproportal.com/2011/12/07/microsoft-holds-java-vulnerabilities-responsible-nearly-half-all-attacks/

[14] Baker, & Graeme. (2008, January 11). Schoolboy hacks into city's tram system. Retrieved November 17, 2011, from The Telegraph: http://www.telegraph.co.uk/news/worldnews/1575293/Schoolboy-hacks-into-citys-tram-system.html

[15] Chen, T. M. (2010). Stuxnet, the Real Start of Cyber Warfare. IEEE Network , 24 (6), 2 - 3.

[16] Carty, D. (2010, February 3). Apple's Wozniak: Toyota Has Software Problem. (CBS Interactive Inc) Retrieved November 18, 2011, from CBS News: http://www.cbsnews.com/8301-503983_162-6169804-503983.html

[17] One, A. (1996). Smashing the Stacks for Fun and Profit. Phrack Magazine , 7 (49).

[18] Viega, J., Bloch, J., Kohno, Y., & McGraw, G. (2000). ITS4: a static vulnerability scanner for C and C++ code. 16th Annual Conference of Computer Security Applications (ACSAC), (pp. 257 - 267). New Orleans, LA , USA.

[19] Krsul, I. V. (1998). Software Vulnerability Analysis. Phd Thesis, Purdue University.

 [20] Alhazmi, O. H., Woo, S. W., & Malaiya, Y. K. (2006). Security Vulnerability Categories in Major Software Systems. 3rd IASTED International Conference on Communication, Network, and Information Security (CNIS), (pp. 138 - 143).

[21] Howard, M., LeBlanc, D., & Viega, J. (2010). 24 Deadly Sins of Software Security - Programming Flaws and How to Fix Them. McGraw-Hill.

[22] Howard, M., LeBlanc, D., & Viega, J. (2005). 19 Deadly Sins of Software Security - Programming Flaws and How To Fix Them. Emeryville, California, USA: McGraw-Hill/Osborne.

[23] Andersen, L. O. (1994). Program Analysis and Specialization for the C Programming Language. PhD Thesis, University of Copenhagen, Computer Science Department.

[24] National Institute of Standards and Technology. (2012, 16 01). Vulnerability Summary for CVE-2012-0266. Retrieved 16 01, 2012, from National Vulnerability Database: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0266

[25] Open Source Vulnerability Database (OSVDB). (2012, 01 11). 78252 : NTR ActiveX Control Boundary Error Multiple Method Parameter Handling Overflow . Retrieved 01 16, 2012, from OSVDB: http://osvdb.org/show/osvdb/78252

[26] National Institute of Standards and Technology. (2008, October 09). Vulnerability Summary for CVE-2000-0146. Retrieved January 10, 2012, from National Vulnerability Database: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2000-0146

[27] IBM X-Force. (2011). IBM X-Force 2010 Trend and Risk Report. Technical Report, IBM.

 [28] Martin, B., Brown, M., Parker, A., & Kirby, D. (2011, September 13). 2011 CWE/SANS Top 25 Most Dangerous Software Errors. (S. Christey, Ed.) Retrieved September 28, 2011, from Common Weakness Enumeration (CWE): http://cwe.mitre.org/top25/

 [29] HewlettPackard. (2011). 2010 Full Year Top Cyber Security Risks Report - In-depth analysis and attack data from HP DVLabs. Technical Report, HP.

 [30] Cenzic Inc. (2010, March 2). Cenzic Web Application Security Trends Report Reveals 90 Percent of Web Applications Vulnerable, Adobe One of The Most Vulnerable. Retrieved January 30, 2011, from https://cenzic.com/pr_20100302/

[31] Chechik, D. (2011, December 16). Prevalent Exploit Kits Updated with a New Java Exploit. Retrieved January 10, 2012, from M86 Security Labs: http://labs.m86security.com/tag/java/

[31] Open Source Vulnerability Database (OSVDB). (2012). The Open Source Vulnerability Database. Retrieved January 10, 2012, from OSVDB: http://osvdb.org/

[33] MITRE Corporation. (2012). CVE Details. Retrieved January 10, 2012, from CVE Details: http://www.cvedetails.com

[34] IBM. (2012). Retrieved January 10, 2012, from IBM Internet Security System: http://xforce.iss.net

[35] Secunia. (2012). Retrieved January 10, 2012, from Secunia - Stay Secure: http://secunia.com/advisories/

[36] National Institute of Standards and Technology. (2012). Common Vulnerability Scoring System Version 2 Calculator. Retrieved January 10, 2012, from National Vulnerability Database: http://nvd.nist.gov/cvss.cfm?calculator&version=2

[37] Oracle Corporation. (2010). Secure Computing with Java: Now and the Future. Retrieved January 10, 2012, from ORACLE - Sun Developer Network (SDN): http://java.sun.com/security/javaone97-whitepaper.html

[38] Oracle Corporation. (2012). Java SE Security. Retrieved January 10, 2012, from ORACLE: http://www.oracle.com/technetwork/java/javase/tech/index-jsp-136007.html

[39] Fritzinger, S. J., & Mueller, M. (1996). Java™ Security. White paper, Sun Microsystems, Inc.

[40] Ahmad, N. H., Aljunid, S. A., & Ab Manan, J.-l. (2011). Taxonomy of C Overflow Vulnerabilities Attack. In Z. Jasni Mohamad, W. Mohd, & E.-Q. Eyas (Ed.), International Conferences on Software Engineering and Computer Systems. 180, pp. 376 - 390. Kuantan, Pahang: Springer.

[41] University of Maryland. (2011, December 21). FindBugs™ - Find Bugs in Java Programs. Retrieved January 10, 2012, from FindBugs: http://findbugs.sourceforge.net/

[42] SourceForge.net. (2011, November 04). PMD. Retrieved January 10, 2012, from PMD: http://pmd.sourceforge.net/

[43] Parasoft. (2012). Jtest - Java Static Analysis, Code Review, Unit Testing, Runtime Error Detection. Retrieved January 10, 2012, from Parasoft: http://www.parasoft.com/jsp/products/jtest.jsp/

[44] Coverity, Inc. (2012). Coverity Static Analysis. Retrieved January 10, 2012, from Coverity: http://www.coverity.com/products/static-analysis.html

[45] Henzinger, T. A., Beyer, D., Majumdar, R., & Jhala, R. (2008, 07 11). BLAST: Berkeley Lazy Abstraction Software Verification Tool. Retrieved November 27, 2011, from MTC - Models and Theory of Computation: http://mtc.epfl.ch/software-tools/blast/index-epfl.php

[46] National Science Foundation. (2010, August 4). Retrieved November 25, 2011, from Splint - Annotation Assisted Lightweight Static Checking: http://www.splint.org/

[47] Cousot, P., Cousot, R., Feret, J., Miné, A., & Rival, X. (2006, July 7). The Astrée Static Analyzer. Retrieved November 20, 2011, from The Astrée Static Analyzer: http://www.astree.ens.fr/

[48] MathWorks, Inc. (2011). Retrieved November 18, 2011, from Polyspace Client for C/C++: http://www.mathworks.com/products/polyspaceclientc/?s_cid=global_nav

Share:

Tuesday, January 17, 2012

I'm against SOPA and PIPA

Although I'm Malaysian and the government has yet to says anything or do something similar, I do support the others in against SOPA and PIPA. It does have significant impact to many users who love free tools/software or don't have enough money to buy expensive licensing software. After all, everything begins from free such as internet, Java language, C language, etc.

Lets go against SOPA and PIPA.

Stumbleupon Against SOPA and PIPA

The IT Giant against SOPA and PIPA



Share:

Thursday, January 12, 2012

Buffer Overflow can evolved?

It is not longer a valid question. In fact, many of us (especially in security area) know about it. Everything will evolve and eventually buffer overflow attack.

There are two interesting articles which I would love to share with you guys. The first ones was published in 2006 and I believe this is the starting point to various advance buffer overflow attack nowadays. Check it out the paper written by Kayacik et. al. at http://www.shell-storm.org/papers/files/328.pdf.

The second paper is published recently in 2011 and published in a journal which to me, this prove that this paper do have high values to security people. You can read the paper at http://www.ijcaonline.org/archives/volume13/number5/1780-2455.

This two papers have proven that my research is still valid and relevant despite the issues has been around for more than two decades. Two professor from renowned local university and a Dr (fresh grad of PhD) even requested me to change my research area and one of them even lough at me when I first presented to them my research topics and problem statement. Well, at least I stick to my idea and fight for it and now it is proven that I'm walking on the right path.

:) .. but yet, I do agree with them too that the issue should be resolved or at least minimize the impact :) and I hope that the result of my research can realize that :).
Share:

Friday, December 9, 2011

SPIE.org : SPIE Newsroom : Unconditionally secure relativistic quantum key distribution protocol

SPIE.org : SPIE Newsroom : Unconditionally secure relativistic quantum key distribution protocol

Yang and Zhuang shares a new technique making full use of QKD with some adjustment for efficiency.

It seem perfect to defend from eavesdropper or man-in-the-middle attack. But QKD is defensely against one type of attacks. The strongest link is also the weakest link. There are some flaw in current QKD implementation and I wish to share this once I completed my studies :)
Share:

Should we be taming social media?

Kapil Sibal, India's telecom minister, this week appears to have drawn more attention with his proposal to pre-filter the content on social media Web sites than all the publicity he got for some of the good work he did in the area of education. The hashtag #IdiotKapilSibal emerged as one of India's most tweeted on Tuesday. (read more)

I said:
Same goes here. Those top guys and politicians are only looking things from their perspective and propose solutions from their view and what they think it should be after getting advice from so called expert. They had never listen to majority voice down below.

At some point, I do agreed that social media/network need to be controlled or at least there are borders to some extend. However, to go deep until everything being controlled, then the meaning of "internet for everyone" and "open discussion" or "open world" or what ever term called for freedom of internet are no longer applicable. There are always ways to prevent such things without enforcing too much and to detail. You can put many preventive mechanism but the more you put, the more it build interest within people to explore and they start to learn on hacking and search for ways to get through.

Therefore, people up there and politicians, please do go down below and get the best solutions..
Share:

Malaysian will force IT to be certified.. Is this good move?

OPEN DAT Board of Computing Professionals Malaysia (BPCM)
Adalah dimaklumkan bahawa Kementerian Sains, Teknologi dan Inovasi (MOSTI) telah diberi tanggungjawab bagi mengendalikan penubuhan Lembaga Jurukomputer Malaysia (Board of Computing Professionals Malaysia - BPCM). Sehubungan dengan itu, pihak Sektretariat ingin mendapatkan pandangan dan cadangan daripada orang awam mengenai penubuhan BPCM. Satu sesi 'open day' akan diadakan mengikut ketetapan berikut:

Tarikh : 13 Disember 2011 (Selasa)
Masa : 9.30 pagi – 5.00 petang
Tempat : Dewan Perhimpunan
Aras 1, Blok C4, Kompleks C
Kementerian Sains, Teknologi dan Inovasi


Semua dijemput hadir.

Last Updated ( Friday, 09 December 2011 )
Taken from: http://www.mosti.gov.my/mosti/index.php?option=com_content&task=view&id=3667&Itemid=1

 Translated:
Ministry of Sciences, Technology and Innovation (MOSTI) has been given mandate to manage the formation of Board of Computing Professionals Malaysia (BPCM). For that reason, the secretariat wishes to get input, feedback, or comments from the public regarding BPCM. One open day session is arranged according to below:

Tarikh : 13 Disember 2011 (Selasa)
Masa : 9.30 pagi – 5.00 petang
Tempat : Dewan Perhimpunan
Aras 1, Blok C4, Kompleks C
Kementerian Sains, Teknologi dan Inovasi




What do I think:

1. Are we trying to follow what other professional such as Engineers, Lawyer, Accountant, and Doctors did? What is our purpose?
2. Does that is what currently being done in other countries such as US, UK, Europe, etc which more IT professionals living there? Why are we doing this?
3. How can this help our fresh graduates? Is there any issues causing us to propose such mechanism?

I can only seem more harm to IT professional especially malays IT professional. Believe me, there are many IT expert (malays especially) that does not have any certifications or even specialize training but being referred by many global company. And believe me, there are many expert with lots of certificates but only knows theory and get the certifications through reading but not through experiences. So what is the actual purpose of this body? Beside, I heard that you need to pay some fees to become the member (more fees and money.. not including your CISSP, EC, MVC, MVP, etc.. certificate that you need to maintain to certain extend)... and worst is that you need to be certified by that body before you can provide any IT services to malaysian company. Wow.. if that so, many bumiputera's or local company will definitely close their business.

What ever it is, lets find out next tuesday. Let us go there and share our thought.
Share:

Friday, October 28, 2011

XML vulnerability leads to calls for standards change

German scientists say weakness in cipher block chaining mode for XML encryption means secured communications between Web services can now be decrypted, and call for change in encryption standard. [read more]

What do I think?
Current encryption method, or cryptography method is still strong. I believe that they can't simply break those and decrypt XML message. There must be specific scenario or parameters required in order for them to succeed.

Nevertheless, security community can't take that for granted. Hacking tools, methods, and others related to exploiting, cracking, etc are becoming easily accessible and easy to use or implemented. Computing powers is increasing but the cost is decreasing thus enable any decryption, hacking, brute-force kind of attack, etc to be completed faster or to be execute with more power.
Share:

Tuesday, September 27, 2011

CWE: what developers of connected embedded systems need to know

Tapp and Chandran (LRDA) wrote an articles published in EETimes (online). The articles starts with sharing information on vulnerabilities and cases related to exploitation. It then goes into CWE (Common Weaknesses Enumeration), purpose, people behind it, etc. They further explain on propose tool in CWE and end-up with why LRDA should be incorporated in SDLC.

First, the title itself is totally conflicted with the contents of the articles which did not touch anything on developers related things especially in gaining knowledge on using CWE as part of their skills in securing their code. However, I tends to agree with them that there are indeed required to use multiple tools for security check.

Their conclusion are more as promoting use of tools in part of SDLC to improve security testing which I believe it is more as marketing rather than technical.

To be able a developer to use CWE, the developers must well equip with knowledge about vulnerabilities and how does it appear in codes. They can avoid it while writing the codes without waiting to use tools which it will be quite messy when dealing with millions LOC (Lines of Codes). Some of the tools even throw false alarm or too many warning as it depends on techniques implemented (PPT).

On understanding vulnerabilities, there are few ways and one of those is to understanding on the behavior and code structures from coding perspective. A paper published in Springer shares on how a taxonomy can be used by developers to understand further thus improve their security skill and usage of tools. The papers can be read here.
Share:

Friday, September 23, 2011

User privacy concerns emerge over supercookies



Difficult to remove new type of cookie which can track user history and preference, giving rise to privacy concerns, note experts, but add that supercookies aren't legal issue for now. [read more]






Share:

Tuesday, September 20, 2011

Applying Static Analysis To Medical Device Software

An interesting articles written back on 2008 by David N. Kleidermacher indicates the importance of having static analysis tool to improve reliability and sustainability of medical devices [read here]

However, as complexity increases especially on mobile devices and mission-critical devices like medical and military, static analysis tool is still far away from achieving zero-tolerant or 99.99% secure. It depends on technique and tool use by the tool to statically analyze applications stored in those devices and at the moment, and as written in my paper title "Preventing Exploitation on Software Vulnerabilities: Why Static Analysis Failed?" in WEC 2010, there are more works need to be done to improve static analysis tool capability especially when the complexity and LOC is increase.
Share:

Friday, September 16, 2011

Using static code analysis to support DO-178b certification

Paul Anderson, GrammaTech   
9/6/2011 6:29 PM EDT

In this Product How-To, Paul Anderson of GrammaTech takes you step by step through the DO-178B and how use his company’s static analysis tools to support the safety-critical software requirements of the specification [read more].

As one of my interest in software security, I keen to evaluate the effectiveness and efficiencies of GrammaTech CodeSonar on its static analysis capability using taxonomy of C Overflow Vulnerabilities Attack which I constructed for the purpose of identifying overflow vulnerabilities in C. However, due to fact (based on my email conversation between one of the company's employee), I can't evaluate theirs thus I'm not sure how their tools could help supporting the safety-critical software requirements.

And I can says one things for sure here that all tools including CodeSonar is yet to successfully help in reducing vulnerabilities in software. This can been seen by looking at various vulnerability database and advisories released by Symantec, Karspesky, Microsoft, NIST, etc. The numbers are still large and yet to see it is tremendously reduce.
Share:

Sunday, July 24, 2011

Embedded Device Security in the New Connected Era

A technical papers written by Marc Brown and publish at EETimes. It can be read/downloaded from here. It is another good technical papers although it was not really technical enough or the word used was not really technical jargon. It is very easy for non-technical person to read and understand the papers. The only limitation was references our proof on all facts/data used in the paper.
Share:

Threat Modeling for Secure Embedded Software

Klocwork had publish a paper on the above title. You can read/access it here.

I won't comments on the paper as it was a good idea/framework they proposed in the paper. The important things I would like to stress here is that the framework or idea is nothing new. It was first established by Microsoft in their SDL. It was already implemented in software development by major software vendor. They might want to re-phrase some of the contents by referring to the giant in doing threat modelling. It does not matter either you are developing normal software or embedded software as it is still treated as a software's project.
Share:

Friday, December 10, 2010

eniaga - Good Initiative but Worst Implementation

Have you come across new government initiatives? eNiaga.

It seem that either the company providing that portal is just wanna get money and deliver a portal or don't care about money (which I guarantee the company gets lots of money) but just wanna deliver a portal to help government in their initiative. Either reason, they failed to deliver at least to minimum portal interface. When I take a look at this (on 11 December 2010), I'm little bit surprise with the interface, layout, friendliness, etc. It is none here. Check it out here http://eniaga.gov.my

What is the problem?
1. Compare with Amazon, Google Book, Lowyat Net, and other portal. All items are clearly categories and segmentize. Here, everything was shown flashing in and out.

2. When you click on the menu display on your left side, it shows another page which also did the same things. What if you wanna find clothes for man? How? Looking at the design, I bet you need to wait until the product shown on the screen and then click as soon as possible as it will change to other product in a few seconds.

3. How to use the system? You need to guess. No Fact or Help that you can select.

4. Over cluttered. The display shows too many and too fast and as I said earlier, no segmentation.

5. What's next? Is this first @ trial version of the portal? Not sure. But if I were one of the people involves, I will not even release this to market yet as I know what portal means and what business portal means and also what usability means. This don't fit in to any of those. It can only be used for showcase something, but not for usage or user. It might be use to win a tender but it shall not be use as a production release.
Share:

About Me

Somewhere, Selangor, Malaysia
An IT by profession, a beginner in photography

Labels

Blog Archive

Blogger templates