給自己一個選擇 :既然家中的電視機只能播粗制濫造的TVB 節目,我已準備好用智能電話和平扳電腦收看其它台。
This is Warren Kwok's Internet note pad, electronic diary, online rubbish journal, whatever you might name it ! It is an archive of my random thoughts in a chronological order. I am not good at reporting boring things and change them to lively. If you find this blog boring, sorry that it is your problem.
2013/12/22
2013/12/16
2013/12/10
reformgovernmentsurveillance.com
This site has the worst web server configuration in the world.
reformgovernmentsurveillance.com
It listens on an IP address instead of a fully qualified domain name. Digital certificate and https can not be applied. Lack of "robots.txt", no 404 Error page and I believe there are many other apparent flaws.
reformgovernmentsurveillance.com
It listens on an IP address instead of a fully qualified domain name. Digital certificate and https can not be applied. Lack of "robots.txt", no 404 Error page and I believe there are many other apparent flaws.
2013/11/29
2013/11/28
SMTP over TLS, do it or not
After careful deliberation, I propose to my department not to do SMTP over TLS. I am sure I make the right decision. The considerations are as follows:
2. There is no standard or recommended practices if self-signed certificates can be allowed in server or client sides.
3. Equally, there is no standard or recommended practice whether servers should request clients to present their certificates for authentication.
4. In the lack of industry practice, network administrators just arbitrarily make their SMTP TLS settings or using the defaults provided by commercial off-the-shelf packages of security gateways/appliances.
5. A lot of mail servers which might have operated for many years have outdated CA list. 5. In case of mail delivery failure, it is nearly impossible to conduct trouble-shooting nor request the other side to amend their settings.
Opportunistic TLS encryption could only be achieved if there is supporting recommended industry practice
1. There might be less than 1 % of mail servers globally supporting this function.
2. There is no standard or recommended practices if self-signed certificates can be allowed in server or client sides.
3. Equally, there is no standard or recommended practice whether servers should request clients to present their certificates for authentication.
4. In the lack of industry practice, network administrators just arbitrarily make their SMTP TLS settings or using the defaults provided by commercial off-the-shelf packages of security gateways/appliances.
5. A lot of mail servers which might have operated for many years have outdated CA list. 5. In case of mail delivery failure, it is nearly impossible to conduct trouble-shooting nor request the other side to amend their settings.
Opportunistic TLS encryption could only be achieved if there is supporting recommended industry practice
2013/11/27
6to4 address connectivity problem
Port25.com is a renowned world leader on enterprise-grade email solutions. How can port25.com has this crazy setting in MX:
port25.com. 3600 IN MX 100 mail.port25.com.
mail.port25.com. 3600 IN AAAA 2002:453f:951e::1
This leads me to issue my last serious warning to all network administrators: 6to4 addresses should not be used to set up web and email servers, whether in test mode or production mode. They cause a lot of troubles. Please use 6in4 tunneling.
port25.com. 3600 IN MX 100 mail.port25.com.
mail.port25.com. 3600 IN AAAA 2002:453f:951e::1
This leads me to issue my last serious warning to all network administrators: 6to4 addresses should not be used to set up web and email servers, whether in test mode or production mode. They cause a lot of troubles. Please use 6in4 tunneling.
2013/11/25
Generate CA cert and sign server cert
Many IT bloggers have written down the steps for making self-signed certificates. I should jotted down my own notes on how to generate my own CA cert and use the CA cert to sign my own server cert. The procedures, if I can recall correctly, should more or less be as follows:
**** Generate my own CA cert/key and sign
my own server cert ****
#openssl genrsa -des3 -out myca.key 4096
[Generate a key for self-signed CA, require
to generate a passphrase to protect the key]
#openssl req -new -x509 -days 3650 -key
myca.key -out myca.crt
[Use the key to create a X.509 certificate
with the name myca.crt]
#openssl genrsa -des3 -out v6-mail.com.key
2048
[Generate a key for my server]
#openssl req -new -key v6-mail.com.key -out
v6-mail.com.csr
[Generate certificate signing request from
the server key]
#openssl x509 -req -days 3650 -in
v6-mail.com.csr -CA myca.crt -CAkey myca.key -set_serial 01 -out
v6-mail.com.crt
[Sign the csr with my CA cert and CA key,
set the serial number to 01 and generate a signed public key in crt format]
#openssl rsa -in v6-mail.com.key -out
new.v6-mail.com.key
(remove passphrase of in a new server keyfile)
#openssl rsa -in myca.key -out
new.my-ca.key
(remove passphrase in a new CA keyfile)
rm v6-mail.com.key,
mv new.v6-mail.com.key v6-mai.com.key
rm myca.key
mv new.my-ca.key myca.key
**** End of Processs *****
2013/11/23
SMTP over TLS for Gmail
Great, just found out that Gmail performs SMTP over SSL/TLS without caring whether the server or client cert in the other side is signed by a CA. This ensures 100 % support for encryption. That’s says, we can use a self-signed certificate. A million thanks to Gmail.
2013/11/21
HSBC email server settings
What the hell is that in my maillog, hsbc attempting to send as Hang Seng Bank? That's why I always say HSBC ignores security.
Nov 21 01:31:18 i3way sendmail[2228]: STARTTLS=server, relay=psmtp9.hsbc.com.hk [203.112.90.17], version=TLSv1/SSLv3, verify=OK, cipher=DHE-RSA-AES256-SHA, bits=256/256
Nov 21 01:31:19 i3way dkim-filter[5266]: rAKHVI5N002228 external host psmtp9.hsbc.com.hk attempted to send as hangseng.com
Nov 21 01:31:18 i3way sendmail[2228]: STARTTLS=server, relay=psmtp9.hsbc.com.hk [203.112.90.17], version=TLSv1/SSLv3, verify=OK, cipher=DHE-RSA-AES256-SHA, bits=256/256
Nov 21 01:31:19 i3way dkim-filter[5266]: rAKHVI5N002228 external host psmtp9.hsbc.com.hk attempted to send as hangseng.com
2013/11/18
免費電視發牌顧問報告
早前立法局欲引用權力及特權法,取得四份顧問報告內容。現在不用了,顧問報告的主要內容已暴光,行會黑箱作業,689自把自為已是無可抵賴的事實,七百萬人現在都知整件事完全沒有公義,你條 689 民望還有排跌呀。
2013/11/01
空降政務官做署長
絕不能空降政務官做署長,一旦空降,專業工程師的晉升機會被閹割,共有五個職級同事無得升,包括副署長、助理署長、總工程師、高級工程師及工程師,連帶畢業生都少個機會入職做政府工程師 !
http://news.mingpao.com/20131101/gaa1h.htm
屋宇署長有權處理及清拆危險建築物,這涉及保障市民生命財產,此等任務必須由受過訓練的專業工程師才可勝任。
http://news.mingpao.com/20131101/gaa1h.htm
屋宇署長有權處理及清拆危險建築物,這涉及保障市民生命財產,此等任務必須由受過訓練的專業工程師才可勝任。
2013/10/28
Scooter
For over 10 years,
whenever I feel not happy, I listen to the songs of Scooter and then things in
my mind change. “Faster, harder, scooter”, “move your ass”, “Apache rocks the
bottom”, so many to follow. Thanks for the
fantastic music, Scooter. You guys are
awesome.
2013/10/27
2013/10/19
2013/10/18
Over 25% of Verizon Wireless Traffic Is Now Over IPv6
Over 25% of Verizon Wireless Traffic Is Now Over IPv6
Needless for me to mention that IPv6 is part of LTE. It is a shame that LTE operators in HK do not offer IPv6 to end users.
2013/10/14
Giving up data roaming services
CSL has increased the daily charge of data roaming from HK$168 to HK$198, an increase of 18 %. I can not afford such a high daily charge. For my next trip, I will rent a pocket wifi device which is charged at HK$88 per day, available at Telecom Square:
http://www.telecomsquare.hk/
http://www.telecomsquare.hk/
2013/10/13
2.4 GHz WiFi channels
My experience tells me that among the three non-overlapping channels in the 2.4GHz WiFi band, channel 6 is always more congested than channel 1 and 11. I don’t know why ?
2013/10/10
2013/10/07
翻牆 ? 進牆 ?
一位貪婪的親友要求我教他們一家人使用 VPN ,以便到大陸網站玩遊戲和下載軟件。雖然我教曉了他們使用 VPN,作為資訊保安業成員,這是一件很痛苦的事,因為香港境內將會多幾台彊屍電腦,惟有千丁萬囑他們加裝防毒軟件。唉,身不由己。
2013/09/30
Subscribe to:
Posts (Atom)



