MrZaius.com

Sean Crago's notes from Nepal

Skip to: Content | Sidebar | Footer

Category: security

Netbook security – Still inadequate

8 July, 2009 (13:47) | linux, netbooks, security | By: MrZaius

I’ve been roundly disappointed by the Xandros Linux build on my 20GB Eee PC 900, but not quite enough to remove it. Ubuntu et al take far too long to boot; Moblin shouldn’t work, given its new Atom requirement; Windows is too bloated and slow to boot, although it would be okay with a conventional [...]

OpenDNS no panacea

30 August, 2008 (12:27) | security | By: MrZaius

The entire technical community needs to be a great deal more careful and cautious about promoting OpenDNS as a cure-all for security concerns in DNS. I used their service in the States for quite some time, and, while there were several major problems, it actually would have been an adequate solution for the security concerns [...]

NTC Update

15 August, 2008 (09:28) | security | By: MrZaius

NTC still hasn’t responded to any of my concerns or met the relatively simple http://www.doxpara.com test. It’s gotten so bad that I’m seriously considering punking down the cash to buy dedicated VPN hardware here and in the US, but that doesn’t help everyone else stuck behind their proxy and broken DNS servers. I’ll continue to try [...]

Steer clear of NTC – CERT VU#800113

29 July, 2008 (08:58) | security | By: MrZaius

NTC is ignoring repeated emails on this subject for two days, after the bug’s been thoroughly beaten to death in the technical and even popular press for three weeks straight. Even worse, I’ve seen some evidence that they may already be getting hit by this attack or another type of DNS or proxy cache poisoning [...]

Nepal Telecom Review – Cheap but grotesquely insecure and making a lot of progress

27 July, 2008 (14:15) | security | By: MrZaius

Summary: Nepal Telecom provides a decent, though not exemplary ADSL service, but compromises user security by running DNS servers prone to cache poisoning and a presumably equally obsolete Squid proxy that there is no way around, short of using a VPN from off-network.
Update: Obviously I’ve had further issues with these guys in terms of reporting [...]