Further reading on spooks

not the normal catz

A friend of a friend asked:

Can anyone recommend credible, well-sourced books that go into real detail about what the security services are able to do, surveillance-wise? Reading that they have the ability to turn a mobile phone into a remote microphone without it being switched on seemed far-fetched, but I really want to know more – it’s so easy to cross over into “conspiracy theory” type stuff, but the Snowden revelations recently make me think the whole damned lot might be true.

It’s a short question, with few clear answers, and a lot of conjecture. So here’s an effort with what I’ve seen, read and inferred, and has nothing to do with what my day job may say in any formal statement. The very short answer is “no”, we don’t yet know. That will take a year or so to understand what we have now, and all the implications: this will take time. But that’s not helpful for now.

Read more…

posted: 10 Sep 2013

STARTTLS and FreeBSD

I can never find a good set of instructions for enabling STARTTLS in FreeBSD and sendmail. The one I keep coming back to is this STARTTLS section in this OpenBSD set, as the pathnames all match: http://www.dsrw.org/~dlg/sysadmin/sendmail/

It’s really quite easy, and there’s no excuse for any one, and certainly no excuse for any service, to not turn STARTTLS for SMTP on.

posted: 24 Aug 2013