<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jonathan&#039;s blog &#187; security</title>
	<atom:link href="http://blog.jonathangazeley.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.jonathangazeley.com</link>
	<description>A journal of Linux, gadgets, and their incompatibility. And other stuff.</description>
	<lastBuildDate>Sun, 05 Feb 2012 22:34:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>On the security and longevity of data</title>
		<link>http://blog.jonathangazeley.com/2009/11/on-the-security-and-longevity-of-data/</link>
		<comments>http://blog.jonathangazeley.com/2009/11/on-the-security-and-longevity-of-data/#comments</comments>
		<pubDate>Wed, 04 Nov 2009 18:56:02 +0000</pubDate>
		<dc:creator>Jonathan</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[backup]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[death]]></category>
		<category><![CDATA[files]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.jonathangazeley.com/?p=558</guid>
		<description><![CDATA[I was musing today about the lifetime of my data, and what might happen to it after I die. I&#8217;m a jolly character, aren&#8217;t I? But there are two questions here. First there&#8217;s the question of my private data &#8211; e.g. online banking stuff and other personal documents that I want to keep to myself [...]]]></description>
			<content:encoded><![CDATA[<p>I was musing today about the lifetime of my data, and what might happen to it after I die. I&#8217;m a jolly character, aren&#8217;t I?</p>
<p>But there are two questions here. First there&#8217;s the question of my private data &#8211; e.g. online banking stuff and other personal documents that I want to keep to myself for now, but may well have to be released to the executor of my will or whatever.</p>
<p>Then there&#8217;s the question of the data I&#8217;d love to share. For example my photographs and musical recordings &#8211; I&#8217;d like to think that they will persist long after I&#8217;ve gone. Maybe even wind up in a futuristic museum so people can marvel at how we used to live. Perhaps.</p>
<h2>Private data</h2>
<p>If I died tomorrow, would my family be able to get at my private files? It&#8217;s a bit more involved than looking in a box-file on top of my wardrobe. Nobody has an account on my home server and PC except me, and nobody else knows my root password (I hope).</p>
<p>But I don&#8217;t want to give anyone access to my data today. I don&#8217;t want to create accounts for other people that can access my stuff, and I don&#8217;t want to tell anyone my password. Can you imagine telling somebody all your passwords and saying they weren&#8217;t allowed to use them until your death?</p>
<p>That&#8217;s not to say that my data is totally inaccessible. My disks are not encrypted so booting from a live CD would be an easy way to read the data without having to log on as me. This would be an easy job for most of my geeky friends, but I don&#8217;t think my parents, brothers or girlfriend would be able to do it. Would my next-of-kin have the initiative to ask one of my colleagues or friends to &#8220;hack&#8221; my systems in the event of my untimely death?</p>
<p>I expect if the circumstances of my death were suspicious, police would confiscate my computers anyway and examine them. A police computer expert would have no problem in extracting the data, but whether or not they would hand it over to my family is a different question.</p>
<p>Of course for accounts I hold with third parties, such as online banking, email companies and of course my employers, it is usually possible to present a death certificate and the account will be opened for the executor.<sup>[<a href="http://blog.jonathangazeley.com/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?url=IzE=">1</a>, <a href="http://blog.jonathangazeley.com/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?url=IzI=">2</a>]</sup> But this doesn&#8217;t apply to my systems.</p>
<p>The flip-side of allowing access to my data is that the executor or next-of-kin gets access to <strong>all</strong> of my data. After I die, I may well be happy for the executor of the will to browse my financial and legal documents, but what if I don&#8217;t want him or her to know about my plans to take over the world, or my illegal downloads? What if I have some embarrassing secrets that I don&#8217;t want my family to find out about?</p>
<p>The only two approaches here are to specify in my will which files should be deleted and which should be kept<sup>[<a href="http://blog.jonathangazeley.com/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?url=IzM=">3</a>]</sup>, or to encrypt everything that I do not wish to be read. Bear in mind that if you wish to make the encryption effective, you will also need to encrypt the backups.</p>
<p>Maybe the best idea would be to write down my password and some brief instructions for accessing my data if necessary, and then seal this in an envelope to be kept in a safe place with my will. Anything I don&#8217;t want seen, <strong>ever</strong>, can be encrypted. Then it should be straightforward for the relevant people to get access to my private documents, with minimal risk of abuse.</p>
<h2>Public data</h2>
<p>As I touched upon in the introduction, the second section is to do with the longevity of my created data. A large part of this is to do with choosing an appropriate format, and ensuring that the format stays current.</p>
<p>For example, my photos are currently stored on a hard disk, formatted with the ext4 filesystem, and saved as TIFF images. They are backed up, but that&#8217;s mainly irrelevant here. The point is that I don&#8217;t expect my hard disks to still be working in ten years&#8217; time, and there&#8217;s a fair chance that today&#8217;s popular filesystems won&#8217;t be in widespread use after a decade either.</p>
<p>While I&#8217;m alive, it&#8217;s easy for me to move my things around. Let&#8217;s suppose next year hard disks start to become obsolete and a new type of memory card becomes commonplace. It will be easy for me to copy my photos from my hard disk onto this new memory card. I can also convert my images from their TIFF format to tomorrow&#8217;s shiny new format if necessary.</p>
<p>But who will do this after I&#8217;m dead?</p>
<p>It was easy for me. After my grandad died, I inherited a box of 35mm slides, as well as some 35mm negatives and some 6&#8243;×4&#8243; prints. Things you can see with your eyes don&#8217;t tend to go obsolete in a decade. Provided I look after these physical photos and protect them from heat, light and moisture, they are likely to last for decades or centuries.</p>
<p>I&#8217;ve also scanned them in and archived them on disk &#8211; where they are safe from paper-curling humidity, but still prone to obsolescence as I mentioned above.</p>
<p>So long as I have backups and I keep with the times and convert my photos to whatever format is appropriate and save them on whatever media is current, I can&#8217;t see a problem. I could even make prints of all my photos and store them securely.</p>
<p>The snag comes when I die, and I will have to entrust my photos to a descendant. Hopefully they will treasure the photos and look after them, as I am doing with my late grandfather&#8217;s work &#8211; but there&#8217;s no guarantee. If I didn&#8217;t have an interest in photography myself, it&#8217;s entirely plausible that I might have declined my grandad&#8217;s slides.</p>
<p>It seems here that the best approach is to preserve my data while I&#8217;m still alive and kicking, and make it known to my family that I wish my photos to be looked after when I&#8217;m gone. Hopefully they will take heed!</p>
<p>Perhaps undermining the tone of this whole article, I might add that I&#8217;ll be dead so why should I care! <img src='http://blog.jonathangazeley.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<h2>References</h2>
<ol>
<li><a name="1"></a><a href="http://blog.jonathangazeley.com/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?url=aHR0cHM6Ly93aW5kb3dzbGl2ZWhlbHAuY29tL2NvbW11bml0eS90LzE1MDA4NS5hc3B4">https://windowslivehelp.com/community/t/150085.aspx</a></li>
<li><a name="2"></a><a href="http://blog.jonathangazeley.com/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?url=aHR0cDovL3d3dy5uZXdzLmNvbS5hdS90ZWNobm9sb2d5L3N0b3J5LzAsMjgzNDgsMjYzMDM5MjctNTAxNDIzOSwwMC5odG1s">http://www.news.com.au/technology/story/0,28348,26303927-5014239,00.html</a></li>
<li><a name="3"></a>Maybe this could be automated, and my will could specify the path to a script that deletes some things and preserves others.</li>
</ol>
 <img src="http://blog.jonathangazeley.com/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=558" width="1" height="1" style="display: none;" />]]></content:encoded>
			<wfw:commentRss>http://blog.jonathangazeley.com/2009/11/on-the-security-and-longevity-of-data/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Mac OS X security flaw?</title>
		<link>http://blog.jonathangazeley.com/2009/06/mac-os-x-security-flaw/</link>
		<comments>http://blog.jonathangazeley.com/2009/06/mac-os-x-security-flaw/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 14:59:08 +0000</pubDate>
		<dc:creator>Jonathan</dc:creator>
				<category><![CDATA[OS X]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[lock]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.jonathangazeley.com/?p=131</guid>
		<description><![CDATA[I think I may have stumbled across a security problem in OS X on my Macbook. To recreate it, you need to satisfy the following conditions: Enable locking the screen after waking from sleep or screensaver Connect to an 802.1x-authenticated wireless network. Don&#8217;t set to remember password. Shut the lid to put it to sleep [...]]]></description>
			<content:encoded><![CDATA[<p>I think I may have stumbled across a security problem in OS X on my Macbook. To recreate it, you need to satisfy the following conditions:</p>
<ul>
<li><a href="http://blog.jonathangazeley.com/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?url=aHR0cDovL29zeGRhaWx5LmNvbS8yMDA3LzA0LzIzL2Fzay1vcy14LWRhaWx5LWhvdy1kby1pLWxvY2stYS1tYWMtb3MteC13b3Jrc3RhdGlvbi8=">Enable locking</a> the screen after waking from sleep or screensaver</li>
<li>Connect to an 802.1x-authenticated wireless network. Don&#8217;t set to remember password.</li>
<li>Shut the lid to put it to sleep</li>
<li>Open the lid to wake it up. There will be a time during which the screen backlight is on, but the screen is displaying plain black before the unlocking password box appears. During some of this time, any keys you press will be sent to the 802.1x authentication window, which is &#8220;behind&#8221; the black screen, as it also appears upon waking. The timing is hard to get right though.</li>
<li>These screenshots show the two states of the unlock box. Apologies for the quality &#8211; can&#8217;t take screenshots while locked so had to take a photo <img src='http://blog.jonathangazeley.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </li>
<div id="attachment_136" class="wp-caption aligncenter" style="width: 310px"><a href="http://blog.jonathangazeley.com/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?url=aHR0cDovL2Jsb2cuam9uYXRoYW5nYXplbGV5LmNvbS93cC1jb250ZW50L3VwbG9hZHMvMjAwOS8wNi9kc2MwMDE0MGIuanBn"><img class="size-medium wp-image-136" title="The unlock box - with focus" src="http://blog.jonathangazeley.com/wp-content/uploads/2009/06/dsc00140b-300x186.jpg" alt="The unlock box - with focus" width="300" height="186" /></a><p class="wp-caption-text">The unlock box - with focus</p></div>
<div id="attachment_137" class="wp-caption aligncenter" style="width: 310px"><a href="http://blog.jonathangazeley.com/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?url=aHR0cDovL2Jsb2cuam9uYXRoYW5nYXplbGV5LmNvbS93cC1jb250ZW50L3VwbG9hZHMvMjAwOS8wNi9kc2MwMDE0MWIuanBn"><img class="size-medium wp-image-137" title="The unlock box - without focus" src="http://blog.jonathangazeley.com/wp-content/uploads/2009/06/dsc00141b-300x183.jpg" alt="The unlock box - without focus" width="300" height="183" /></a><p class="wp-caption-text">The unlock box - without focus</p></div>
<li>After a second, the unlocking password box will appear. If you got your timing right, it will appear without focus. In this case, your keystrokes are still being sent to the 802.1x password box which has focus, despite being invisible. You also have the ability to press Tab to move between fields and Return to submit. This gives you the ability to authenticate someone on a wireless network using any credentials! When they come to unlock their Mac, there will be no obvious indication that they&#8217;re authenticated on a wireless network as someone else.</li>
<li>This next screenshot shows what the 802.1x box looks like, after unlocking. As you can see, I&#8217;ve entered the word <em>hello</em> through the locked screen!</li>
</ul>
<div id="attachment_134" class="wp-caption aligncenter" style="width: 310px"><a href="http://blog.jonathangazeley.com/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?url=aHR0cDovL2Jsb2cuam9uYXRoYW5nYXplbGV5LmNvbS93cC1jb250ZW50L3VwbG9hZHMvMjAwOS8wNi9waWN0dXJlLTIucG5n"><img class="size-medium wp-image-134" title="The 802.1x login box that causes the problem" src="http://blog.jonathangazeley.com/wp-content/uploads/2009/06/picture-2-300x187.png" alt="The 802.1x login box that causes the problem" width="300" height="187" /></a><p class="wp-caption-text">The 802.1x login box that causes the problem</p></div>
<p>I spotted this bug accidentally on my Mac when I was a bit hasty typing in my unlock password, and was shocked to see it appear in the 802.1x username box after I unlocked successfully.</p>
<p>I&#8217;m using Leopard, 10.5.7. I&#8217;d be very interested to hear from anyone who can recreate this bug on other versions of the OS.</p>
<p>I&#8217;d be ever more interested to hear from anyone who figures out how to enter keystrokes through a lock screen to an arbitrary application. I&#8217;ve tried this, and Control+Tab doesn&#8217;t work, so you can&#8217;t immediately switch to other windows. I&#8217;ve also tried successfully entering my 802.1x credentials through the lock screen to dismiss the 802.1x box, but after that my keystrokes are not accepted.</p>
 <img src="http://blog.jonathangazeley.com/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=131" width="1" height="1" style="display: none;" />]]></content:encoded>
			<wfw:commentRss>http://blog.jonathangazeley.com/2009/06/mac-os-x-security-flaw/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

