An analysis of the Nomx secure communications device
61–70 of 77 posts
Re: An analysis of the Nomx secure communications device
#62Re: An analysis of the Nomx secure communications device
#63Re: An analysis of the Nomx secure communications device
#64> Contrary to the blogger's claim that this was an easy, simply hack, in fact, the blogger couldn't make the code work and requested other participants to support his attempts and publicly stated so on his blog. The "payload" he developed was from a third party named Paul.
That's embarassingly bad logic. The fact that this particular guy wasn't an expert at XSS doesn't make the hack hard, and the fact that it exists at all is the issue. What a bunch of fuckin' jokers.
Re: An analysis of the Nomx secure communications device
#65Their response (on their homepage) is awful: http://nomx.com/ "nomx Passes Security Tests After Blogger Claims to Have Penetrated nomx - UK blogger makes false claims he can access nomx remotely - UK blogger fails to access nomx remotely"
http://www.bbc.co.uk/news/technology-38934822
> Addressing the issue of old software, he said Nomx planned to let users choose which updates should be applied to their device.
> "We will selectively allow users to pick and choose when that becomes available but today we're not forcing any types of updates," he said, adding that updates can introduce vulnerabilities.
> "Updates actually cause a cascading effect and now you're patching patches and that is not a good place to be in," he told Click.
Re: An analysis of the Nomx secure communications device
#66> "We've advised them that they should not use the nomx admin while surfing any other sites which contain malware or were otherwise compromised" That's so hilariously misguided I don't even know where to start!
[1] https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%...
Re: An analysis of the Nomx secure communications device
#67Wow. The title kind of gave away that this was going to be a fun read, but I did not expect it to be that bad. Even if the vendor did not make those bold claims and simply sold it as a hassle-free email appliance for home users and small businesses, it would be borderline fraudulent. With the bold claims attached it almost looks like performance art to ridicule all the snake oil-peddlers out there.
Re: An analysis of the Nomx secure communications device
#68I read through the patent application cited in the article [1] so I can explain what the device is supposed to be doing. The "secret sauce" is it can send email between two Nomx devices without using DNS or other third party servers, avoiding DNS attacks. The handshake between two devices sets up DNS records on each device so they can locally resolve each other. There's a mechanism so if a device changes IP address,…
As far as how it actually works on the device the author also showed the relevant portion of the postfix config where it checks if the domain is in the handshake table and if it is then connect to that IP on port 26 with the hardcoded default cert.
Maybe they plan on creating something based on that patent someday but right now what they're selling as based on that patent has nothing to do with it.
Re: An analysis of the Nomx secure communications device
#69Earlier quoted context omitted.
For Microsoft/Hotmail, you'll want to register your IP with their feedback loop (Junk Mail Reporting Program): https://postmaster.live.com/snds/JMRP.aspx It's free. A bonus of this is that you get reports about emails from your IP that their users mark as spam.
Thanks Mike! I know you work on a lot of email tools. What is your go-to resource when someone asks about deliverability? If you're written something up yourself I'd appreciate a link!
Re: An analysis of the Nomx secure communications device
#70>For Media - Some statistics:
Number of nomx accounts that have been compromised since inception: 0
Number of Gmail accounts that have been compromised in the United States (from 2014): About 5 million to 24 million depending on source
How about the TOTAL number of (respectively) nomx accounts and gmail accounts (from 2014)?
I mean, 0/(something) is undoubtedly a smaller number than 5-24*10^6/(a very HUGE number), but maybe the (something) is so little that the target in itself is irrelevant...