Password Length vs Complexity There are indeed two properties to a password: Complexity (number of possible characters in each position) Length (number of positions) The 'randomness' of a password is simple to calculate: complexity ^ length, where ^ is exponentiation. As you might know, changing the exponent (the…
Cyber Security
Answered Mar 21, 2022
·
726 Views
Read answer →
For intel management and security status you can completely and permanently (unless you reinstall it) disable Intel Active Management Technology, Intel Small Business Technology, and Intel Standard Manageability on Windows. These are components of the Intel Management Engine firmware. While Intel ME still runs, the…
Cyber Security
Answered Mar 17, 2022
·
8.1K Views
Read answer →
Regular USB keylogger keyboards that exfiltrate their data via Bluetooth or WiFi can easily be hidden inside a keyboard. The Bluetooth loggers require the attacker to come into range to dump their contents, but a WiFi based adapter that's pre-configured with a network key doesn't even require the attacker to be…
Cyber Security
Answered Mar 15, 2022
·
1.1K Views
Read answer →
If you believe Apple, is FaceTime secure can be answered as FaceTime traffic is end-to-end encrypted using AES-256. This is secure, in the sense that somebody intercepting the traffic can not decrypt it (as far as is publicly known). However, crypto is hard and the security could be compromised if Apple has made an…
Cyber Security
Answered Mar 14, 2022
·
1.5K Views
Read answer →
Here's the answer I was looking for myself, and could not find until I experimented with both having and not having a passphrase: When the private key is encrypted, then you have to enter the SSH key passphrase every time you need to use it. Then I learned about the "ssh-agent" daemon/service that can cache the…
Cyber Security
Answered Mar 14, 2022
·
842 Views
Read answer →
You said "I want to be 100% sure that my machine only connects where and when I want it to", but do you have a strategy for covering what is sent? UDP in block is always a good idea, but to browse the web you'd want to be able to connect out on port 80, and at that point malware has a way to communicate out. You…
Cyber Security
Answered Mar 14, 2022
·
805 Views
Read answer →
The aluminium coating of the CD reacts and creates plasma. So it burns the CD effectively. A microwave CD is the one with no data as all its data gets erased and the CD gets destroyed when microwaved.
Cyber Security
Answered Mar 11, 2022
·
508 Views
Read answer →
I love xkcd 936 and agree with his basic point -- passphrases are great for adding entropy, but think he low balled the entropy on the first password. Let's go through it: Random dictionary word. xkcd: 16 bits, Me: 16 bits. A random word from a dictionary with ~65000 words is lg(65000) ~ 16. Very reasonable Adding in…
Cyber Security
Answered Mar 11, 2022
·
1.5K Views
Read answer →
The extension chrome://flags/#allow-insecure-localhost can be explained as - A similar situation is issuing a certificate (for example, from an internal corporate CA) withdNSName = localhost iPAddress = 127.0.0.1I doubt any publicly-trusted CAs will issue a cert for localhost, so a setting like this is probably needed…
Cyber Security
Answered Mar 11, 2022
·
1.7K Views
Read answer →
A Signature is a bit of cryptographic wizardry where you take some smallish piece of data - almost always the cryptographic hash (something like SHA256) digest of a message, file, or other data blob - and then perform an operation on it (called signing) with a private key. Since only you should ever have access to…
Cyber Security
Answered Mar 11, 2022
·
516 Views
Read answer →
You should check the reputation of the site or the comments of the file. As someone told you in comments, unless someone is using a day 0 attack or and unpatched vulnerability you will be safe. You can't do anything more before you download the torrent. If you want to do the torrent scan for any kind of malware after…
Cyber Security
Answered Mar 10, 2022
·
2.3K Views
Read answer →
WPA2 EAP-PSK uses WPA2-Enterprise to do an 802.1X authentication to server. It uses the PSK method of EAP and allows a client to authenticate with just the use of a PSK. The pros of WPA2-PSK is that it is supported in every 802.11 device of relatively recent manufacture (2nd gen 802.11g or so). It is simple to set up…
Cyber Security
Answered Mar 10, 2022
·
2.4K Views
Read answer →