Your new CAC, Linux, Mac, and You

Earlier posts outlined howto utilize OpenSC to ensure your CAC worked in Linux or Mac. The problem is that there are new 144k CAC being passed out that do not work with the current coolkey or OpenSC toolsets. What is a happy Federal employee to do?! First you need to find a Windows computer that can access the https://software.forge.mil In a strange turn of events you will be unable to download the software necessary for your true platform of choice to access the software. Its a chicken and egg problem… ...

January 19, 2011 · 2 min · Nick

Configuring OpenBSD softraid for encryption

My original idea was to post a dual how-to for both softraid and svnd, but due to the size of the posts with screenshots, I have decided against that. Since softraid is the path forward in the OpenBSD world I will start here. This post is not dial-up friendly, so be patient while it loads from my poor server. This post is part of my larger OpenBSD crypto series for which the other posts are below: ...

January 19, 2011 · 4 min · Nick

Closed Network != Security

To this day I am flabbergasted by the assertion that because your network is not connected to the big “I” Internet you can practice lax security. Countless places I have walked in the door to find unencrypted email traffic, no antivirus, and zero firewalls. Like the Masons of the middle ages they draw the boundary around the castle/network and assume they are safe. As architects and security professionals it is up to us to remind the Castle Builders that the threat of today is not warded off with simple walls of rock… ...

January 19, 2011 · 5 min · Nick

WAMU{.org/.com}

WAMU, our local NPR station in DC, left me with a cliff hanger as I rushed back from the grocery store. In the days prior to the streaming web I would have just sat with the car idling in the driveway. Tonight though I was able to rush up the stairs and start the live stream. I made one strategic mistake though. I went to http://wamu.com rather than http://wamu.org I thought the outcome was share worthy: ...

January 18, 2011 · 2 min · Nick

OpenBSD Drive Encryption Benchmarks

Let me start by saying I am not a benchmarker. At all…so these results are posted for friendly banter and I make no claim to their validity. Consider this the glxgears of filesystem testing. The testing was done with two identical OpenBSD 4.8 installs running in VMware Fusion 3.1 on a Mac Mini Server. The bonnie test was done to the same /home partitions mounted in crypto volumes. In green you will find the winner for each category. ...

January 9, 2011 · 1 min · Nick