Forgot your password?
typodupeerror

Comment: Re:Only if they can do it with out getting shot (Score 1) 926

by bdlarkin (#33375220) Attached to: GPS Tracking Without a Warrant Declared Legal
You might want to reread that self-defense clause again.

Yep

80R SB378 (Texas) The actor's belief that the force was immediately necessary as described by this subsection is presumed to be reasonable if the actor: (1) knew or had reason to believe that the person against whom the force was used: (A) unlawfully and with force entered, or was attempting to enter unlawfully and with force, the actor's occupied habitation, vehicle, or place of business or employment; (B) unlawfully and with force removed, or was attempting to remove unlawfully and with force, the actor from the actor's habitation, vehicle, or place of business or employment; or (C) was committing or attempting to commit aggravated kidnapping, murder, sexual assault, aggravated sexual assault, robbery, or aggravated robbery;

If the cop is doing something to your car or truck that is legal, then that's ok. You can't shoot them when they show up to execute a search warrant either.

Comment: Re:no need for a technical solution (Score 1) 396

by bdlarkin (#31571968) Attached to: How To Avoid a Botnet Infection?
there is no need for a technical solution..assuming this is for a business, fire anyone who decides to infect a company-owned PC with malware. (make sure your AUP/HR Policies *clearly* state this).

Great! So all someone needs to do to get his boss fired is to get his machine infected? What about the CFO? CEO? How long would that policy be in place with a little targeted mischief?

What about the case of the user that gets infected because he visited a legitimate website that was serving up malware because they got hacked by a SQL injection attack last night? What if visiting the (now malicious) website was part of her job (reviewing press releases, whatever).

Not sure if your "Just set the AUP right in the first place" suggestion was a joke or a legitimate suggestion.

Comment: Re:Constitutionally Speaking (Score 2, Informative) 282

by bdlarkin (#30659718) Attached to: Does Cheap Tech Undermine Legal Privacy Protections?
Don't bet on the cop not looking at your documents anyway. In the interest of "security".

http://volokh.com/2009/11/04/the-deputy-who-helped-himself-to-the-defense-attorneys-casefile

The video shows a criminal court hearing in which a deputy assigned to court security walks over to the defense attorney’s papers on the counsel table and starts to look at the papers. Eventually he reaches down and pulls out a document from the stack of papers, passes it off to another deputy, and then the other deputy walks away with it.

At least in some jurisdictions....

Comment: Re:Social engineering attack (Score 1) 605

by bdlarkin (#30610026) Attached to: Do Your Developers Have Local Admin Rights?
Excellent examples, and kinda proves the point I was trying to make. If you can't trust them with root then you can't trust their code. He's lucky if getting fired is as far as it went.

The examples you point out are kind of exceptions to the rule (purposeful security policies, production systems, dev teams different than build teams, etc). The grandparent post was talking about "local admin" so I wasn't really trying to address the production system example but rather the local desktop/dev server type restrictions.

The requirement for local admin for most Windows code is one of my peeve issues with Windows.

Agreed and ditto. Security isn't a setting but an end-to-end process.

Sorry for being snarky before, the "forgmarch" line set off my BS meter, especially in a "local admin" context.

And oops on my part for posting the reply initially as AC

Comment: Re:Social engineering attack (Score 1) 605

by bdlarkin (#30609058) Attached to: Do Your Developers Have Local Admin Rights?
All hail you! The mighty sysadmin. I'd love to know details, especially since it got him "frogmarched", but it sounds like so much bravado.

As I said, there are HIDS packages that will track this, as would a competent sysadmin. In my unix example some admins would check permissions on files they put in your sudo list, most don't, especially if they have to do it all the time. The cool thing about social engineering is that you usually aren't even breaking corporate policy, your getting someone ELSE to break corporate policy for you!

In my experience most admin's aren't worth their salt. I say this as an admin myself but with a developer background. I've been on both sides of the issue.

There are other ways. Keyloggers,for example. "Hey Mr. admin, it says I need admin authority to do xyzzy, can you enter your credentials on my keyboard here? Thanks very much.

I don't bring up these examples as ways around security, but rather to bring up the issue of trust. If you can't trust your developer with local admin, you probably can't trust his code, especially compiled code.

For an excellent example see Ken Thompson's paper.

Personally, with vmware and cheap hardware it's easy enough to run your own non-corporate image than it is to get around the security, but there are ways. YMMV.

Comment: Social engineering attack (Score 1) 605

by bdlarkin (#30607662) Attached to: Do Your Developers Have Local Admin Rights?
It's trivial to get admin priveleges. You are a developer after all. Just develop/package your own backdoor trojan/etc that gets installed with root priveleges. Then get those fancy administrators to install it for you with their admin rights. If they ask what it is, tell them its some libraries for a development project. The number of times you'll be asked will be next to nil though. Voila, you can do what you want after that. Not that I've done it, but on the unix side, you could ask for a sudo exception for a program that's in a directory that's writable to you. Boom you have root any time you need it. You're a developer! Use your skills! Yeah yeah, there are some HIDS systems that will catch this sort of thing, but there are ways around that too. After all your root/admin at some point. If you don't trust your developers with root, then you shouldn't trust their code!

Debug is human, de-fix divine.

Working...