2019年4月10日星期三

list all the
components   ------------> prepare an architecture diagram------------>Label the components and                                                                                                                          communication
                                                                                                                         |                                                                                                                                                                   |                                                                                                                                                                   |                                                                                                                                                                  \/                                                                                                                                                  Identify attack vectors
                                                          Rate the attack    <-------------for each component                                                                                     vectors                                                                                     

The following are the steps required to create an attack surface map of
any given IoT device:
• List all the components present in the target product.
• Prepare an architecture diagram.
• Label the components and the communication flows
between them.
• Identify attack vectors for each component and the
communication channel or protocol used.
• Categorize the attack vectors based on the varying
criticality.

These components involve many vulnerabilities

These components involve many vulnerabilities, some of which are
listed here.
• Firmware
• Ability to modify firmware.
• Insecure signature and integrity verification.
• Hard-coded sensitive values in the firmware—API
keys, passwords, staging URLs, and so on.
• Private certificates.
• Ability to understand the entire functionality of the
device through the firmware.
• File system extraction from the firmware.
• Outdated components with known vulnerabilities.
• Mobile applications
• Reverse engineering the mobile app.
• Dumping source code of the mobile app.
• Insecure authentication and authorization checks.
• Business and logic flaws.
• Side channel data leakage.
• Runtime manipulation attacks.
• Insecure network communication.
• Outdated third-party libraries and software
development kits (SDKs).

Web application
• Client-side injection.
• Insecure direct object reference.
• Insecure authentication and authorization.
• Sensitive data leakage.
• Business logic flaws.
• Cross-site request forgery.
• Cross-site scripting.
That list is just a sample of some of the vulnerabilities present in these
components, which should give you an idea of the kind of vulnerabilities
that affect these components.

2019年3月16日星期六

不上班的理想人生与不下班的理想人生。

今天看到一本书的书名叫《不上班的理想人生》,
心里一念,理想人生都不上班, 那么人生有多无精打采。

于是乎,临时起意,应该写上一本不下班的理想人生。

在戴尔的时候, 有的同事很厌世, 有言论说“做哪行厌倦哪行”, 我想说对,其实也不对。
看完了了动机的分析,才知道, 其实并不是厌倦, 而是失去了前进的动力。

失去动力的原因有很多因素,但是最重要的因素就是失去了推进的力量,为什么失去了推进的力量,

这里又可以摊开来说, 中国人的恶性竞争? 人的劣根性, 抑或上升到全人类的劣根性?

首先内卷化已经让我们疲惫不堪,中国人口红利已经被榨干,人的价值是无限的,但是到了这里就被单一衡量,价值无比低下。

在外企,总是感慨鬼佬生活优越, 人人大house, 我们仅仅为了一套小破房就要摇尾乞怜,低三下四,50岁之前兢兢业业,恐怕不得善终。

再对比他人的30岁,40多岁, 不禁感慨自己的地狱模式,今天想到这里,一个小时的思考, 一万个小时的重复思考。 每个人都成为了厌世的专家?

人人平等,有些人比别人更加平等。 不患寡而患不均。

理想生活就是, 物有所值, 等价交换吗?

实际上, 无论是姓社还是姓资, 制度就是让你吃不饱,然后去追求饱暖。

实际操作没有下限, 导致了没有理想生活的悲剧。

更悲惨的是,东亚社会的内卷性质,导致加大一万倍的非理想社会诞生。

难道真的等到像黑客帝国描述的那样,人机一体化, 所有理想生活都是虚拟出来的。 大家才满足得了吗?

可怕。

参与在这个过程中, 每时每刻都在关注, 投入自己的一份力量,变得更理想,才是重点吗?


宗教和鸦片, 没有这两种麻醉剂的中国社会, 如何清醒的走下去。

我还是吃我今天的酸菜鱼吧,美团调了好久,还是吃酸菜鱼。

2019年3月17日杭州
滨江亚朵。