Segnalibri al 13 gennaio 2012

Continua a leggere

Segnalibri al 13 ottobre 2011

Continua a leggere

Segnalibri al 5 settembre 2011

Continua a leggere

Segnalibri al 9 agosto 2011

Continua a leggere

Segnalibri al 26 giugno 2011

Continua a leggere

Segnalibri al 29 maggio 2011

Continua a leggere

Segnalibri al 27 aprile 2011

Cloud

  • Access all your data. Anytime, anywhere, from any device.

    Tags: #backup #storage #sync

    16 aprile 2011

  • For the past several days I have been focused on understanding the inner workings of several of the popular file synchronization tools with the purpose of finding useful forensics-related artifacts that may be left on a system as a result of using these tools. Given the prevalence of Dropbox, I decided that it would be one of the first synchronization tools that I would analyze, and while working to better understand it I came across some interesting security related findings. The basis for this finding has actually been briefly discussed in a number of forum posts in Dropbox’s official forum (here and here), but it doesn’t quite seem that people understand the significance of the way Dropbox is handling authentication. So, I’m taking a brief break in my forensics-artifacts research, to try to shed some light about what appears to be going on from an authentication standpoint and the significant security implications that the present implementation of Dropbox brings to the table.

    Tags: #dropbox #security #authentication

    13 aprile 2011

  • I also urge the company to abandon its deduplication system design, and embrace strong encryption with a key only known to each user. Other online backup services have done it for some time. This is the only real way that data can be secure in the cloud.

    Tags: #dropbox #security #encryption

    13 aprile 2011

  • Tarsnap is a secure online backup service for BSD, Linux, OS X, Solaris, Cygwin, and can probably be compiled on many other UNIX-like operating systems. The Tarsnap client code provides a flexible and powerful command-line interface which can be used directly or via shell scripts.

    Tags: #backup #encryption #security

    13 aprile 2011

Continua a leggere