Pages

Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, August 13, 2023

More than a contributor on PANCast

Have you heard of Palo Alto Networks' PANCast?

It is a podcast made by TAC engineers (me included) to Palo Alto Networks products users.
Not a sale oriented stuff, really focused on the technology, and how to use 110% capabilities of the products.

The podcast covers all possible topics : from basic troubleshooting tools by TAC to protection of your containers with Azure Container Registry (Prisma Cloud) or discussing the informations you can find in your Cortex XDR logs.

So far, I did an episode on Panorama and its capabilities as logging solution. And we have some episodes pending to be published. I know that because I am scheduling the releases of the episodes :p

So stay tuned.

Patent granted

In case you are not following me on LinkedIn, I guess you are not aware the patent application done on March 2021 has ended, and the patent has been granted officially on 31 January 2023.

The patent details can be found here.

As you will see the patent owner is Palo Alto Networks, as I disclosed my invention to my employer in their patent program.
The invention is directly something PAN-OS can benefit in order to secure communiations, and the technical issue addressed by the invention is addressed in the PAN-OS feature App-ID Cloud Engine.
(Disclaimer : I am not aware if Palo Alto Networks has or has not use the invention)

So how big achievement is it?
1- Before Palo Alto Networks decided or not to apply for a patent, you need to convince a Patent Committe of your invention, the challenge addressed by the invention.
I submitted few others ideas and they were rejected.

2- I am the first inventor (through the Patent Progam of the company) in APAC region.

3- I am also the first one working in Palo Alto Networks TAC.

Tuesday, August 25, 2015

Sécurité : un éternel recommencement

La sécurisation de l'infrastructure est un travail de tous les jours.

Les systèmes d'aujourd'hui sont beaucoup plus puissants et accessibles qu'il y a 15 ans. Et les politiques et contre-mesures appliquées à l'infrastructure doivent être en conséquence remise à jour.

Dernièrement, la vulnérabilité "FREAK" (CVE-2015-0204), puis plus récemment la vulnérabilité "logjam" (CVE-2015-4000) illustrent bien le problème, lié aux tailles de clés utilisées.
Ce qui était cher temps et en argent ne l'est plus, et il est possible de faire déchiffrer des informations qui ne l'étaient pas à l'époque.

Il est donc temps de faire un petit tour au niveau des clés utilisées pour différents fonctions (signature numérique, authentification, chiffrement, échange de clés) : changer la taille des clés (passage de clés RSA-1028 vers RSA-2048 ), changer le type de cryptographie utilisée (utilisation d'algorithmes à base de courbes elliptiques : ECxx).

Pour avoir une idée de certaines recommandations : Recommandations NSA (en anglais)



Monday, January 9, 2012

Quick fingerprinting

It is possible to do a basic fingerprinting without using specific softwares.

Monday, November 7, 2011

Stockage des mots de passe chez Free ...

Ceux qui me connaissent depuis un certain temps sur Internet, savent qu'avant "In the Packet", j'essayais de mettre quand je le pouvais des petites news sur ma page personnelle Free http://olivier.zheng.free.fr
Ces mêmes personnes ont dû remarquer que le site est indisponible depuis un certain temps maintenant aussi.