Tag Archives: history

Tiptoeing Through Vulnerabilities

BombI sympathize with developers who throw up their hands and say, “I don’t do security stuff.” No matter what you choose, there’s a trade off that could go wrong. It’s especially troublesome if one deploys a “security website.” I’ve deployed security education websites in many environments over the past 20 years, and I rarely achieve the security level I’d like.

I wanted to watch a security webinar today.  But the webinar requires Adobe Flash, in which security researchers seem to uncover 1 or 2 vulnerabilities a month. I discarded Flash when upgrading my OS a couple years ago. It’s ironic that a security webinar might tempt it back onto my machine.

Continue reading Tiptoeing Through Vulnerabilities

Boak’s Puzzle: Disposing of Classified Trash

Boak's History of US COMSECRecently I was skimming through the NSA’s “classified history of COMSEC” (Volume 1 and Volume 2).  This “history” is a transcription of lectures by David G. Boak, who liked to explain NSA-related topics from a historical perspective. He clearly inspired a generation of NSA’s employees. The last “real” page of the document contains a humorous story and a crypto puzzle (link to extract in pdf).

The NSA had an incinerator in their old Arlington Hall facility that was designed to reduce Top Secret crypto materials and such to ash. Someone discovered that it wasn’t in fact working. Contract disposal trucks had been disposing of this not-quite-sanitized rubish, and officers tracked down a huge pile in a field in Ft. Meyer.

How did they dispose of it? The answer is encrypted in the story’s text! Continue reading Boak’s Puzzle: Disposing of Classified Trash