Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

Jack's Right →

April 13, 2017 by Marc Handelman in All is Information, Common Sense, Transport Security, Transport Layer Security, TLS, Web Security, Network Security

Of course he is; and why wouldn't he be? Just plain old common sense, dammit. Read his superlatively on-target post, and you'll understand exactly why - in fact - Jack is right.

April 13, 2017 /Marc Handelman
All is Information, Common Sense, Transport Security, Transport Layer Security, TLS, Web Security, Network Security

Kicking the Certificate Habit →

March 07, 2017 by Marc Handelman in All is Information, Simplicity, Web Security, WebTrust, Trust, TOFU, Information Security, Authentication, Must Read

Dr. Jaap-Henk Hoepman's security posts (via his blog), detailing his provocative yet fundamentally sound thoughts on the subject of terminating the utilization of certificates is today's absolute MustRead.

The basic idea - A few days ago I explained the idea including a mechanism to detect phishing attacks. This makes the protocol more complex, and creates confusion. So let’s try again, explaining the basic idea first. Whenever a browser sets up a new TLS connection with a domain, the web server serving that domain respond with its public key (instead of a certificate, as is currently the case) in the initial TLS handshake. (This is more precise than saying that the web server sends its public key in the header of every page it sends.)... Read more at Dr. Hoepman' blog

March 07, 2017 /Marc Handelman
All is Information, Simplicity, Web Security, WebTrust, Trust, TOFU, Information Security, Authentication, Must Read

Goatse of Cloudbleed →

February 27, 2017 by Marc Handelman in All is Information, Web Security, Information Security, Data Security, Data Leakage, Must Read

via the eponymous Phoneboy, comes his take on the latest security foible of a major backend provider (in this case Cloudflare), entitled 'Cloudflares with a Chance of Goatse', Mr. Welch-Abernathy explains it all, in imitiable form. Today's MustRead.

February 27, 2017 /Marc Handelman
All is Information, Web Security, Information Security, Data Security, Data Leakage, Must Read

Mozilla Firefox Certificate Cache Coughs Up Credentials →

February 24, 2017 by Marc Handelman in All is Information, Cruft, Data Leakage, Poor Coding Practices, Application Security, Web Security

Meanwhile, in cruft news...

A Tale of Cruftery

First discovered by security researcher Alexander Klink, and discussed on his shift or die blog, the leakage documentation he has amassed is a tour de force in correct handling of the discovery. Mozilla's response has been a tad lackadaisical and (disappointlingly) still in telemetry data gathering mode as of this post.

The Workaround

Superb work by Alexander; nonetheless, he does suggest regular cleansing your browser user profile (if you are so unlucky as to be using the browser under scrutiny, yet most likely, a good idea on any browser). There are many tools available that deal with the cache cleaning task (both scripted and manual, GUI-based and not, both in-built and otherwise). Enjoy the cruft. H/T

February 24, 2017 /Marc Handelman
All is Information, Cruft, Data Leakage, Poor Coding Practices, Application Security, Web Security

Fingered →

January 16, 2017 by Marc Handelman in Accountability, All is Information, Analytics, Application Security, Attribution, Cybersecurity, Fingerprinting, Forensication, Information Security, Web Security

Relatively new fingerprinting techniques were brought to my attention last week (H/T), that (reportedly) focus on the identification of browser users and utilization across multiple application deployments. Enjoy.

January 16, 2017 /Marc Handelman
Accountability, All is Information, Analytics, Application Security, Attribution, Cybersecurity, Fingerprinting, Forensication, Information Security, Web Security

Google's Keys to Security, Pragmatism At It's Finest →

December 26, 2016 by Marc Handelman in All is Information, Cryptography, Data Security, Information Security, Web Security

Read it (PDF) and be pleased that all-well-might-indeed-be-right-with-the-Universe, at least in user-land universal 2nd factor crypto that, is...

h/t

December 26, 2016 /Marc Handelman
All is Information, Cryptography, Data Security, Information Security, Web Security

DNSChanger, Redux →

December 19, 2016 by Marc Handelman in All is Information, Attacks, Steganography, Information Security, Web Security

Apparently, DNSChanger has reared it's pernicious head again, infecting large numbers of unwary users and vectored through steganographic code malware inclusion within major news site banner ads... This time, per The Hacker News reporter Swati Khandelwal, comes the bad news of both the vector and the attack.

December 19, 2016 /Marc Handelman
All is Information, Attacks, Steganography, Information Security, Web Security

O'Reilly Security 2016, Phil Stanhope's 'Internet Zombie Apocalypse' →

December 06, 2016 by Marc Handelman in All is Information, Conferences, Education, Information Security, Web Security, Network Security, Networks, Distributed Attacks
December 06, 2016 /Marc Handelman
All is Information, Conferences, Education, Information Security, Web Security, Network Security, Networks, Distributed Attacks

ISOC 2016 Global Internet Report →

November 25, 2016 by Marc Handelman in Accountability, All is Information, Information Security, Database Security, Data Security, Web Security, WebTrust, Online Trust, ISOC

Behold, the Internet Society's 2016 Global Internet Report: 'The Economics of Building Trust Online: Preventing Data Breaches. Fascinating reading.

November 25, 2016 /Marc Handelman
Accountability, All is Information, Information Security, Database Security, Data Security, Web Security, WebTrust, Online Trust, ISOC

BSides Augusta 2016 - David Coursey's 'This One Weird Trick Will Secure Your Web Server!' →

October 16, 2016 by Marc Handelman in Conferences, Information Security, Web Security
October 16, 2016 /Marc Handelman
Conferences, Information Security, Web Security

Blind XSS →

May 13, 2016 by Marc Handelman in All is Information, Information Security, Web Security

From BruteLogic (via Firewall Consultant's Trey Blalock) comes this treatise on Blind XSS.

May 13, 2016 /Marc Handelman
All is Information, Information Security, Web Security

95 Percentile →

March 21, 2016 by Marc Handelman in All is Information, Information Security, Web Security

Reported by Security Week, comes the revelation that 95% of all HTTPS servers do not possess HTTP Strict Transport Security (aka HSTS) deployments.

As Netcraft’s Paul Mutton explained in a recent blog post, these vulnerabilities can be exploited in phishing, pharming and man-in-the-middle (MiTM) attacks when a user unintentionally attempts to access a secure site via HTTP, meaning that the attacker does not have to spoof a valid TLS certificate to be successful. These attacks are easier to be carried out compared to those targeting TLS, such as the DROWN attack. - via SecurityWeek

March 21, 2016 /Marc Handelman
All is Information, Information Security, Web Security

Verizon's Cookie

March 08, 2016 by Marc Handelman in All is Information, Data Security, Information Security, Web Security

Super Cookie, that is...

March 08, 2016 /Marc Handelman
All is Information, Data Security, Information Security, Web Security
too-late4.jpg

Mozilla Privacy Fix, Too Late?

November 27, 2015 by Marc Handelman in All is Information, Demise of Privacy, Web Security, Information Security

The always erudite Richi Jennings, writing at Computerworld expounds on the apparent longevity (or not) of Mozilla Foundations' Firefox web browser, and the privacy quotient, thereto. Today's Must Read.

November 27, 2015 /Marc Handelman
All is Information, Demise of Privacy, Web Security, Information Security

Mozilla To Release Track Protection →

September 25, 2015 by Marc Handelman in All is Information, Brilliant, Web Security, Information Security

via Martin Brinkmann at the extraordinary GHacks blog, comes word of Mozilla Foundations' Firefox anti-tracking components slated for release in Firefox Stable 42 on November 3rd, 2015. Outstanding!

September 25, 2015 /Marc Handelman
All is Information, Brilliant, Web Security, Information Security

Mozilla Privacy and Security Settings →

August 24, 2015 by Marc Handelman in All is Information, Application Security, Information Security, Privacy, Web Security

via gHacks, comes this superlative compendium of Mozilla's Firefox Security and Privacy related settings. All conveniently packaged for ease of deployment. And, as with any modification of the platform you have chosen, examine the settings thoroughly, test exhaustively, and deploy with mindful caution. Enjoy.

August 24, 2015 /Marc Handelman
All is Information, Application Security, Information Security, Privacy, Web Security

Google Initiates Attack Site Reporting

March 04, 2015 by Marc Handelman in All is Information, Information Security, Intelligence, Web Security

via Anthony Freed, writing at Norse Coporation's Darkmatters blog, comes this better-late-than-never tale of Google Inc.'s (NasdaqGS: GOOG) effort to warn users of attack sites prior to the user opening up the miscreant's page.

March 04, 2015 /Marc Handelman /Source
All is Information, Information Security, Intelligence, Web Security

Saturday Security Maxim

February 28, 2015 by Marc Handelman in Security Maxim, Web Security, Physical Security, Network Security, Information Security

Infinity Maxim: There are an unlimited number of security vulnerabilities for a given security device, system, or program, most of which will never be discovered (by the good guys or bad guys).

Comment: This is probably true because we always find new vulnerabilities when we look at the same security device, system, or program a second or third time, and because we always find vulnerabilities that others miss, and vice versa. - as compiled by Roger G. Johnston, Ph.D., CPP, Argonne National Laboratory

February 28, 2015 /Marc Handelman
Security Maxim, Web Security, Physical Security, Network Security, Information Security

Twenty Eight Teams Advance to CyberPatriot National Finals Competition →

January 29, 2015 by Marc Handelman in All is Information, Education, Information Security, Web Security, Networks, Network Security

News, of the latest crop of secondary school cyber-defense teams advancing into the finals of the CyberPatriot National Finals Competition. CyberPatriot has additional information for those of you that wish to attend the live National Finals Competition on March 13th through and inclusive of March 15th, 2015 in National Harbor, Maryland. Congratulations to All!

 

 

 

 

 

January 29, 2015 /Marc Handelman
All is Information, Education, Information Security, Web Security, Networks, Network Security

GoDaddy, Compromised Again... →

January 22, 2015 by Marc Handelman in Blatant Stupidity, Common Sense, Information Security, Web Security, Vulnerabilities

What, really? Apparently, GoDaddy security has failed to measure up, yet again. via Swati Khandelwal writing at HackerNews, comes the sorry tale of failed code (in the form of XSRF vulnerabilities), obvious failed quality control, and on top of all of that, no security checks pre-deployment. Astounding.

January 22, 2015 /Marc Handelman
Blatant Stupidity, Common Sense, Information Security, Web Security, Vulnerabilities
  • Newer
  • Older