<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" >

  <title>Erik L. Arneson — Writer and Software Developer</title>
  <subtitle>Erik L. Arneson is a freelance writer and software developer with WordPress experience. He is located in Portland, Oregon.</subtitle>
  <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator>
  <link href="https://arnesonium.com/feeds/logjam.xml" rel="self" type="application/atom+xml" />
  <link href="https://arnesonium.com/" rel="alternate" type="text/html" />
  <updated>2026-06-18T15:03:10+00:00</updated>
  <id>https://arnesonium.com/feeds/logjam.xml</id>
  <author>
    <name>Erik L. Arneson</name>
  </author>
      <entry>
        
        <title>Security Link Rodeo: The Patriot Act, Logjam, and Hacked Websites</title>
        <author>
          <name>Erik L. Arneson</name>
        </author>        
        <link href="https://arnesonium.com/2015/05/another-security-link-rodeo/" rel="alternate" type="text/html" title="Security Link Rodeo: The Patriot Act, Logjam, and Hacked Websites" />
        <updated>2015-05-29T17:51:59+00:00</updated>
        <id>https://arnesonium.com/2015/05/another-security-link-rodeo</id>
          <category term="cryptography" />
        
          <category term="link-rodeo" />
        
          <category term="logjam" />
        
          <category term="nsa" />
        
          <category term="security" />
        <content type="html" xml:base="https://arnesonium.com/2015/05/another-security-link-rodeo/">&lt;p&gt;Kind of good news: Senators Ron Wyden and Rand Paul teamed up to &lt;a href=&quot;http://boingboing.net/2015/05/23/ron-wyden-and-rand-paul-kill-t.html&quot; target=&quot;_blank&quot;&gt;squash the Patriot Act extension&lt;/a&gt;. It’s going to expire on June 1st unless another vote is called on the 31st. The &lt;a href=&quot;https://en.wikipedia.org/wiki/USA_Freedom_Act&quot; target=&quot;_blank&quot;&gt;USA Freedom Act&lt;/a&gt; (which I think is good?) unfortunately didn’t make it through Senate, either.
&lt;!--more--&gt;&lt;/p&gt;

&lt;p&gt;https://twitter.com/RonWyden/status/601979044318547969&lt;/p&gt;

&lt;p&gt;Regarding the Logjam vulnerability that &lt;a href=&quot;https://arnesonium.com/2015/05/security-link-rodeo/&quot;&gt;I mentioned last week&lt;/a&gt;, if you’ve got a cloud server and you’re generating new Diffie-Hellman parameters, make sure you’ve got good random numbers! Digital Ocean has &lt;a href=&quot;https://www.digitalocean.com/community/tutorials/how-to-setup-additional-entropy-for-cloud-servers-using-haveged&quot; target=&quot;_blank&quot;&gt;advice on generating sufficient random data on cloud servers&lt;/a&gt;. The short version is that you should be running &lt;a href=&quot;http://www.issihosts.com/haveged/&quot; target=&quot;_blank&quot;&gt;haveged&lt;/a&gt; on all of your servers.&lt;/p&gt;

&lt;p&gt;https://twitter.com/dholmesf5/status/601848616525942784
&lt;!--more--&gt;
Here’s an &lt;a href=&quot;http://blog.cryptographyengineering.com/2015/05/attack-of-week-logjam.html&quot; target=&quot;_blank&quot;&gt;informative and easy-to-understand description&lt;/a&gt; of the Logjam attack by Matthew Green. He just happens to be one of the cryptographers who helped discover the problem. And the EFF talks about the implications of Logjam and how the &lt;a href=&quot;https://www.eff.org/deeplinks/2015/05/logjam-part-2-did-nsa-know-years-internet-was-broken&quot; target=&quot;_blank&quot;&gt;NSA is a bunch of jerks who really don’t care about our privacy at all&lt;/a&gt;. Seriously, NSA. It’s like you don’t even want to be our friend!&lt;/p&gt;

&lt;p&gt;The creepy mobile spyware app mSpy was recently hacked, resulting in a &lt;a href=&quot;http://krebsonsecurity.com/2015/05/mspy-denies-breach-even-as-customers-confirm-it/&quot;&gt;leak of about 400,000 user accounts&lt;/a&gt;. They spent a long time denying it. You can check &lt;a href=&quot;https://haveibeenpwned.com/PwnedWebsites#mSpy&quot; target=&quot;_blank&quot;&gt;HaveIBeenPwned&lt;/a&gt; to see if you’re one of the users.&lt;/p&gt;

&lt;p&gt;Last week it was also revealed that &lt;a href=&quot;http://gizmodo.com/huge-adultfriendfinder-hack-might-have-exposed-your-sex-1706181502&quot; target=&quot;_blank&quot;&gt;AdultFriendFinder was hacked&lt;/a&gt;, leaking about 3.9 million user records. Even worse, it is possible that “AdultFriendFinder may not get rid of data after customers leave.” This is just a reminder that you need to &lt;a href=&quot;http://blog.trendmicro.com/trendlabs-security-intelligence/being-mindful-about-what-you-share/&quot; target=&quot;_blank&quot;&gt;be mindful about what you share&lt;/a&gt; on the Internet. If you want to keep information secret and secure, make sure that &lt;strong&gt;you are the only one in control of it.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;https://twitter.com/SwiftOnSecurity/status/601854610018414592&lt;/p&gt;

&lt;p&gt;&lt;small&gt;&lt;i&gt;The featured image for this post is from Flickr user &lt;a href=&quot;http://www.flickr.com/people/7147684@N03&quot; target=&quot;_blank&quot;&gt;Jason Hollinger&lt;/a&gt;.&lt;/i&gt;&lt;/small&gt;&lt;/p&gt;</content>
      </entry>
    
</feed>
