Die wunderbare Welt von Isotopp

Unlearning Descriptive Statistics

Avatar of @isotopp@infosec.exchange Kristian Köhntopp - February 6, 2017

Anscombe’s Quartet by Schutz

Unlearning Descriptive Statistics explains many things you should know about working with Numbers that your Statistics Class in University probably did not explain properly. If they did, maybe Graphite would not hurt so much, with all the Averaging going on where it shouldn’t, and maybe Gill Tene would not have had to give talks like How NOT to measure latency (which is awesome, by the way and if you haven’t seen this talk, do it right now).

Parser Bug Hell

Avatar of @isotopp@infosec.exchange Kristian Köhntopp - February 3, 2017

Wireshark Bug Stats

So Debian just posted an advisory for over 40 bugs in tcpdump . tcpdump is a tool that collects traffic on the network, and then parses its way down the stack from the Ethernet or other physical frames all the way through the IP and TCP stacks to the application layers and the data formats in there.

Parsing data is hard. Even the actual full blown applications normally reading that data often have problems parsing their own data format, and they are crashing if you throw malformed data at them. That’s called Fuzzing , and there is a bunch of pretty amazing LLVM tools available to make this possible in a systematic and automated way.

Racing our galaxy

Avatar of @isotopp@infosec.exchange Kristian Köhntopp - February 2, 2017

Why is our galaxy moving through space, and into which directions is everything else moving?

Scientists at the Hebrew University of Jerusalem have been mapping these forces, and found a very empty region in space that seems to push a lot of galaxies away from it, as well as a (previously known) region thats attracting them.

The result looks like a billion light year magnet:

The dipole repeller

Europol discovers CGN

Avatar of @isotopp@infosec.exchange Kristian Köhntopp - February 1, 2017

The Council of the European Union discusses the “problem” of Carrier Grader NAT, and would like to see all Ip address logging and storage extended to port numbers, as well as all NAT state tables to be stored and preserved, in order to be able to resolve Internet accesses to subscriber identities, says Statewatch .

The paper in question has been submitted by EUROPOL and claims that clients are “going dark”. The scarcity of IP v4 addresses leads to more and more subscribers being subject to carrier grade NAT (CGN). In CGN, subscribers are not assigned a public IP number, but are only getting an internal, non-unique IP address. Only when IP packets are leaving the provider network, their addresses are being translated into public addresses.

Exponential Fuck-Off

Avatar of @isotopp@infosec.exchange Kristian Köhntopp - February 1, 2017

»Damian: The solution is to send emails with increasing frequency
@markzabaro: It’s called exponential fuck-off.«
  – https://mobile.twitter.com/dgryski/status/826385338104954881

Nobody wants backup. Everybody wants restore.

Avatar of @isotopp@infosec.exchange Kristian Köhntopp - February 1, 2017

Operations matter. I know the Hipster crowd does not like to hear that, cloud or not. But reality has a way of making itself heard, whether you like it or not.

Gitlab.com just discovered that.

So some sysadmin deleted the wrong folder, which in itself should not be a problem.

Bielefeld Conspiracy hits Facebook

Avatar of @isotopp@infosec.exchange Kristian Köhntopp - January 26, 2017

Westfalenblatt knows:

Yesterday all references to the place name “Bielefeld” have been replaced with “Bielefeldverschwörung ” (Bielefeld Conspiracy):

Facebook showing “Bielefeldverschwörung” (Bielefeld Conspiracy) instead of the proper city name.

Bielefeld is a typical while label city in Germany. In fact, it is conspiciously inconspicious, and that is, so the conspiracy theory fabricated by Achim Held in 1993, because the city does not actually exist. It’s a fake location that protects something else on the map, probably an entrance to the Hollow Earth or something else, but we don’t actually know.

Chinese New Year, and birthrate anomalies

Avatar of @isotopp@infosec.exchange Kristian Köhntopp - January 26, 2017

Coming up: Chinese New Year on 28. January. The coming year is a year of the Fire Rooster , and apparently these things mean a lot to a lot of people. So what influence does the Chinese Zodiac have? Well, one sign that is supposed to be very unlucky is the Fire Horse. An article from 2012 explains:

People born during the year of the Fire Horse are notorious for being bad luck. People born during a Fire Horse years are said to be irresponsible, rebellious, and overall bad news. And for some reason, women are said to be especially dangerous Fire Horses. They supposedly sap their family’s finances, neglect their children, and drive their father and husband to an early grave.

Command line access to the Mac keychain

Avatar of @isotopp@infosec.exchange Kristian Köhntopp - January 26, 2017

I am getting my payslips in electronic form, as an encrypted, password protected PDF. It’s not a super secret password, and the encryption is more against accidentally opening the file than it is to keep the content of the file actually secret.

After shipping the PDF home, I am archiving it for tax purposes, but in order to make the archival safe, I am storing the original file as well as the decrypted cleartext version of it. To do that, I wrote a shell script, which contained the password in a variable in clear.

Finished Reading: Maddrax 443 "Die Erleuchteten"

Avatar of @isotopp@infosec.exchange Kristian Köhntopp - January 26, 2017

Maddrax 443: Die Erleuchteten ”, Jo Zybell (german language, EUR 1.49)

So Maddrax is one of those pulp series that are sold in booklet format in train stations, right next to romance novels. The setting echoes Planet of the Apes or other post-apocalyptic scenarios with Sci-Fantasy elements.

During a failed space mission involving firing nukes at an asteroid/alien terraformship on a collision course with earth, Matthew ‘Matt’ Drax is transported five centuries into the future, where he finds a barbarian wilderness sparsely populated by mutant survivors of the impact and barbarians.