30 November

For the sake of humanity, I once again draw your attention to Trilogy mentioned yesterday. I want to confirm that the 10/10 rating was not a mistake.

I wish weekends were much longer.

29 November

We spent an hour in the garden. She has done up a few christmas decorations and a few paintings for our living room.

Last weekend, I ordered Trilogy by The Cure. 3 hours back to back of Pornography, Disintegration and Bloodflowers. I have been watching some of it today. Robert is being his usual calm self, the show and music blends together. 10/10.

All the while, the bunnies were being sarcastic:

[22:08] <reverse> Just like when holsta talks about `absolute security'.
[22:08] <reverse> `Client side authentication' and whatnot.
[22:08] <Liebach> You just need a good hardware firewall for that.
[22:08] <reverse> Of course.
[22:09] <jlouis_> oh, so we are in danger since miracle doesnt have any?
[22:09] <reverse> And huge encryption keys.
[22:09] <jlouis_> 1024000 bits, we got to be secure
[22:09] <reverse> jlouis_, holsta disabled it, because otherwise the Internet
        didn't work.

13 November

It has been a rough week. Monday morning I was up at 5.30 to catch a flight, went to bed at midnight. Got up Tuesday at 7.30, went to bed at 2am. Got up at 7.30 on Wednesday, went to bed at 2am. I am going out again tonight (Thursday) for more drinks. This may hurt a little.

9 November

Being a Microsoft whore now, I am off early tomorrow morning to Microsoft IT Forum 2003 in Copenhagen. I made sure I have working dstumbler and dsniff as there will be plenty of access points around. Anyone taking bets on the number of passwords I will come home with?

She left to visit her sister and former co-workers today.

Not only do I hate passwords. I also hate account lock-out policies that do just not make any sense. Just what is the point of locking an account out after 3 attempts, when successful authentication requires two factors to be present? Completely pointless. If you must have account lockout enabled, set the number of attempts to something like 50. That will stop real attackers and not hurt people who fat-finger they password 3 times in a row.

Please people, think hard about your threat model before you define a password policy. Most of your silly attempts to become "secure" really bother the fuck out of me. Fuckity-fuck!

8 November

While cases of the blind leading the blind has always existed, the blind are now easier to identify via their websites. Google's link: feature can in many cases, once one blind person has been found, be utilised to find more of the blind. One such well known blind person is self-proclaimed security expert Steve Gibson (grc.com). Two blind individuals who follow him are the self-proclaimed security and web designer gurus at edbguru.dk, Kenneth and Kimmie.

I would hate to think that these people actually get any business or are allowed to advise anyone on computer security or web design. The advice currently dispensed on their website regarding virus, hacking and spy-ware is not correct. The website does not validate as standards compliant HTML and the entire design breaks a dozen or so best practice rules about decent web design.

Oh, and the grammar is completely horrible. No, wait. The entire page is grammarless. Someone teach these people the meaning of a full stop, please!

2 November

Hi. I have not emptied my spam folder since 9 October, resulting in 4800 messages, taking up 718 megabytes of diskspace. That is almost a gigabyte per month. This internet thing is going to be dead in the water before long.