Privacy, simplified.

#249 – February 04, 2018

sponsor

monday.com: The perfect project management tool for developers

Oversee your team's entire workflow while organizing your design layouts, coding tasks and assets. Plan visually and communicate all in one place. Create your free account →

this week's favorite

Privacy, simplified.

Over the years, DuckDuckGo has offered millions of people a private alternative to Google, serving over 16 billion anonymous searches. Today we're excited to launch fully revamped versions of our browser extension and mobile app, extending DuckDuckGo's protection beyond the search box to wherever the Internet takes you.

Part 2: How to stop me harvesting credit card numbers and passwords from your site

I wrote a post recently describing how I distributed malicious code that gathers credit card numbers and passwords from thousands of sites in a way that’s quite difficult to detect. The comments this post received filled me with joy, expressing such sentiments as “chilling”, “disturbing”, and “utterly terrifying”. (Much like the compliments I receive on the dance floor.) In this follow-up post I’d like to put down the megaphone put forward some practical advice.

The Most Dangerous Word In Software Development

“Just” makes me feel like an idiot. “Just” presumes I come from a specific background, studied certain courses in university, am fluent in certain technologies, and have read all the right books, articles, and resources.

How a malicious seed generation website stole $4 million

Recently, Ars Technica posted an article describing how a malicious seed generator, iotaseed.io (now offline), was able to steal almost $4 million (!) worth of IOTA from its users’ wallets. The way they describe this is that the website “stored data about each seed generated along with information about the wallet it was associated with, allowing whoever was running the site (or whoever hijacked it) to simply wait until wallets were filled and then cash them out.” This made me curious, so I decided to look into the technical details of how the scam was pulled off.

5 Real World Uses for Redis

Redis is a powerful in-memory data structure store which has many uses including a database, a cache, and a message broker. Most people often think of it a simple key-value store, but it has so much more power. I will be going over some real world examples of some of the many things Redis can do for you.

newsletters