Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

Antbleed, The Bitcoin Backdoor

April 27, 2017 by Marc Handelman in All is Information, Bitcoin, Cryptocurrency, Cryptography, Economics, Dubious Methodology, Information Security

Catalin Cimpanu writing at Bleeping Computer, regales us with the tale of Antbleed, a newly discovered tidbit of backdoor code found on Bitcoin mining devices. Oops.

April 27, 2017 /Marc Handelman
All is Information, Bitcoin, Cryptocurrency, Cryptography, Economics, Dubious Methodology, Information Security

Tallinn Cyber Security Conference 2017, 'Panel Discussion, Klaid Mägi, Siret Schutting, Amar Singh, Adrian Davis and Joseph Carson'

April 27, 2017 by Marc Handelman in All is Information, Conferences, Education, Estonia, Information Security, Security Education
April 27, 2017 /Marc Handelman
All is Information, Conferences, Education, Estonia, Information Security, Security Education

Tallinn Cyber Security Conference 2017, Aleks Koha's 'Privacy as a Foundation for Your Security Perimeter' →

April 26, 2017 by Marc Handelman in All is Information, Conferences, Education, Information Security, Estonia, Security Education, Privacy
April 26, 2017 /Marc Handelman
All is Information, Conferences, Education, Information Security, Estonia, Security Education, Privacy

The IoT Chain →

April 26, 2017 by Marc Handelman in All is Information, Anti-Patterns, Computer Science, Information Security, IoT, IoT Security, Hardware Security

Meanwhile, in troubling IoT news, a paper (published by the IACR) entitled "IoT Goes Nuclear: Creating a ZigBee Chain Reaction" & authored by Eyal Ronen, Colin O’Flynn, Adi Shamir and Achi-Or Weingarten (a Weizmann MSc student); we find - perhaps - the ultimate ZigBee nightmare... Today's Must Read (and while your're at it, check out the video to round out your day). Thanks and Tip O' The Hat

April 26, 2017 /Marc Handelman
All is Information, Anti-Patterns, Computer Science, Information Security, IoT, IoT Security, Hardware Security

Webroot, The Latest SNAFU →

April 25, 2017 by Marc Handelman in All is Information, Security Failure, Information Security, Governance, Security Governance, Security Heal Thyself, Security Testing, Vulnerabilities, Vulnerability Research

Iain Thomson, writng at El Reg, reports on Webroot's latest SNAFU. I'll leave it to his illustrative prose to tell the tale.

April 25, 2017 /Marc Handelman
All is Information, Security Failure, Information Security, Governance, Security Governance, Security Heal Thyself, Security Testing, Vulnerabilities, Vulnerability Research

Tallinn Cyber Security Conference 2017, Joseph Carson's 'How Does a Hacker Stay Secure and Safe Online?' →

April 25, 2017 by Marc Handelman in All is Information, Attacker Tracking, Attacker Anti-Tracking, Security Education, Conferences, Education, Information Security, Patterns, Anti-Patterns
April 25, 2017 /Marc Handelman
All is Information, Attacker Tracking, Attacker Anti-Tracking, Security Education, Conferences, Education, Information Security, Patterns, Anti-Patterns

Tallinn Cyber Security Conference 2017, Juned Mirza's 'How the Layered Approach of PCI Shall Secure Customer's Cedit Card Information' →

April 24, 2017 by Marc Handelman in All is Information, Conferences, Education, Information Security, PCI, Estonia
April 24, 2017 /Marc Handelman
All is Information, Conferences, Education, Information Security, PCI, Estonia

DDoS Attackers Offer Customer Loyalty Points →

April 24, 2017 by Marc Handelman in All is Information, Crime, Criminal Enterprise, Network Security, Information Security

via El Reg's John Leyden, comes the astonishing tale of the commercialization of crime - in this case, DDoS attacks; and don't miss the Loyalty Points! Today's Must Read.

April 24, 2017 /Marc Handelman
All is Information, Crime, Criminal Enterprise, Network Security, Information Security

Microsoft Owned LinkedIn Creepy New Bluetooth Feature →

April 21, 2017 by Marc Handelman in All is Information, Blatant Stupidity, Demise of Privacy, Tracking, Information Security

Further proof that the End-Of-The-World-Is-Near: Microsoft Corporation's (NasdaqGS: MSFT) LinkedIn just released a new update for the Company's already slightly-suspicious mobile app that permits Bluetooth connectivity (for location tracking) to fellow LinkedIn members. Reportedly, the feature does not require the app to be running... What could possibly go wrong?

April 21, 2017 /Marc Handelman
All is Information, Blatant Stupidity, Demise of Privacy, Tracking, Information Security

Tallinn Cyber Security Conference 2017, Michael Goedeker's 'The Other Side of Analysis' →

April 21, 2017 by Marc Handelman in All is Information, Conferences, Education, Estonia, Information Security
April 21, 2017 /Marc Handelman
All is Information, Conferences, Education, Estonia, Information Security

Suit of Bose →

April 20, 2017 by Marc Handelman in All is Information, Awareness, Common Sense, Communications, Data Security, Demise of Privacy, Devices, Information Security, Signals, Privacy, 18 U.S.C. §§ 2510-2522

News of an interesting privacy related lawsuit, via Fortune writer Jeff John Roberts, is now swirling around personal electronics manufacturer Bose Corporation. Apparently, collecting data (and a viloation of the so-called Wire Tap Act (Codified in 18 U.S.C. §§ 2510-2522)) - through a companion app to the company's best-in-class noise canceling headphones, and the misuse thereof, is the gist... Stay Tuned. Hat Tip

"The complaint accuses Boston-based Bose of violating the WireTap Act and a variety of state privacy laws, adding that a person's audio history can include a window into a person's life and views. "Indeed, one’s personal audio selections – including music, radio broadcast, Podcast, and lecture choices – provide an incredible amount of insight into his or her personality, behavior, political views, and personal identity," says the complaint, noting a person's audio history may contain files like LGBT podcasts or Muslim call-to-prayer recordings." - via Fortune writer Jeff John Roberts

April 20, 2017 /Marc Handelman
All is Information, Awareness, Common Sense, Communications, Data Security, Demise of Privacy, Devices, Information Security, Signals, Privacy, 18 U.S.C. §§ 2510-2522

Tallinn Cyber Security Conference 2017, Kalev Kuusik's 'Redefining IT Security' →

April 20, 2017 by Marc Handelman in All is Information, Conferences, Information Security, Estonia
April 20, 2017 /Marc Handelman
All is Information, Conferences, Information Security, Estonia

Google Complicit In Fake Google Maps Site Listings? →

April 19, 2017 by Marc Handelman in Advertising, All is Information, Alternate Attack Vectors, Crime, Web Security, Information Security

Is Google Inc. aka Alphabet Inc (NasdaqGS: GOOG) complicit in the enormous numbers of fake links (of which, redirect users to false and/or fraudulent sites) in Google Maps? Of course they are, as, by definition, they own it. What's worse, the company possesses the in-built capability to police those links to protect it's users, but does not - in reality - do so.

April 19, 2017 /Marc Handelman
Advertising, All is Information, Alternate Attack Vectors, Crime, Web Security, Information Security

Tallinn Cyber Security Conference 2017, Marcos Placona's 'I just hacked your app!' →

April 19, 2017 by Marc Handelman in All is Information, Conferences, Education, Information Security, Application Security, Estonia
April 19, 2017 /Marc Handelman
All is Information, Conferences, Education, Information Security, Application Security, Estonia

Ad Blocker Data Leakage →

April 18, 2017 by Marc Handelman in All is Information, Data Leakage, Adware, Advertising

Reportedly, there is a method to identify users through the utilization of ad blocking browser plugins and applications. Not particularly surprising, given the already intrusive nature of advertising in general...

April 18, 2017 /Marc Handelman
All is Information, Data Leakage, Adware, Advertising

Tallinn Cyber Security Conference 2017, Jessica Barker's 'How to Stop Cyber Security Awareness-Raising Going Wrong' →

April 18, 2017 by Marc Handelman in Conferences, Education, Information Security, All is Information, Awareness, Estonia
April 18, 2017 /Marc Handelman
Conferences, Education, Information Security, All is Information, Awareness, Estonia

...with homage to Dr. Englebart ( http://dougengelbart.org )

MOAAB* →

April 17, 2017 by Marc Handelman in All is Information, Anti-Patterns, Computer Science, Computer Vision

via Vice's Motherboard writer Jason Koebler, comes this bad-news-for-advertisers screed detailing the work of Princeton and Stanford researchers to corral said ad-miscreants... The research team has crafted a computer-vision-based ad-blocker, that is reportedly 100% efficient in it's intended purpose. Phenomenal.

* Mother of All Ad Blockers

April 17, 2017 /Marc Handelman
All is Information, Anti-Patterns, Computer Science, Computer Vision

RSA 2017, Cyber/Physical Security and the IoT: National Security Considerations →

April 13, 2017 by Marc Handelman in All is Information, Conferences, Information Security, IoT Security, National Security
April 13, 2017 /Marc Handelman
All is Information, Conferences, Information Security, IoT Security, National Security

Jack's Right →

April 13, 2017 by Marc Handelman in All is Information, Common Sense, Transport Security, Transport Layer Security, TLS, Web Security, Network Security

Of course he is; and why wouldn't he be? Just plain old common sense, dammit. Read his superlatively on-target post, and you'll understand exactly why - in fact - Jack is right.

April 13, 2017 /Marc Handelman
All is Information, Common Sense, Transport Security, Transport Layer Security, TLS, Web Security, Network Security

SANS CTI 2017, Aaron Shelmire's 'Effective Threat Intel Management' →

April 12, 2017 by Marc Handelman in All is Information, Education, Conferences, Threat Intelligence
April 12, 2017 /Marc Handelman
All is Information, Education, Conferences, Threat Intelligence
  • Newer
  • Older