Showing posts with label but that's none of my business. Show all posts
Showing posts with label but that's none of my business. Show all posts

Wednesday, May 31, 2023

I hope they protect health information better than they protect baggage

from here and here

I would probably have a pretty cavalier attitude towards an airline asking me to get on a scale, but that doesn't change the fact that it is protected health information and I'm really not sure I trust an airline to protect my health information. Also, just because I'm cavalier about it doesn't mean other people would be or should be.

Friday, May 19, 2023

When someone shows you who they are, believe them

from here and here

So it turns out the recently charged discord leak suspect was repeatedly caught mishandling classified info, rifling through documents that had nothing to do with his job, and all he ever seemed to get were warnings. One has to wonder how many times were they planning on turning a blind eye to him abusing his access before they finally handed out real consequences.

Tuesday, March 28, 2023

Might as well be twirling your moustache

from here and here

Sometimes you really have to wonder what's going through malware writers' minds when they leave clues like that in their malware. I'm not saying this is what gave them away, but it certainly didn't do them any favours.

Thursday, February 23, 2023

Department of Duh-fense

from here and here

I really expected better of the Department of Defense. I mean, defending things is supposed to be their entire raison d'etre. You'd think they wouldn't get tripped up by forgetting to password protect a server, but I guess they're just as fallible as everybody else. 

Friday, January 13, 2023

With features like that, who needs keyloggers?

from here and here

I know it's not intentionally a keylogger, but there isn't much separating it from one. It does record keystrokes and it does output them without your knowledge or consent. The main difference is that it doesn't provide a way to get your keystrokes into a particular hacker's hands - although if it just starts spitting them out randomly it is entirely possible some of your sensitive keystrokes may find their way into some random hacker's hands. That would be very unlucky, but this is Friday the 13th.

Monday, August 29, 2022

No clicks for you

from here and here

Of course heartless corporations are going to double-down on their toxic business practices, but don't listen to their arguments. Ads have been a security threat for a long time, and if an advertising company hasn't come to terms with that fact about the Internet yet then they don't deserve your attention.

Monday, September 20, 2021

How not to save money

from here

Whether or not you believe the attempts at attributing this attack, the fact remains that someone managed to slip malicious code into software that moves millions of dollars around, and there really should be better checks to make sure that sort of thing can't happen.

Thursday, August 15, 2019

The Suprema example of how not to do security

from here

When your job is protecting things but you don't bother protecting your customer's information it's pretty much always going to wind up being a fail.

Monday, July 22, 2019

Talk about slacking off

from here

Apparently Slack didn't show abundant enough caution the first time around and now have to try again. Somehow I tend to think 4 years later is too late to do any real good. If those credentials were going to be misused it would probably have already happened by now.

Tuesday, July 2, 2019

'Unhackable' computer is patently absurd

from here

It's amazing to me that the patent office granted this guy a patent for an unhackable computer. It's clearly snake-oil. Claiming something is unhackable has never worked out in the past. Ever.

Monday, June 3, 2019

Wanting the unwanted

from here

This story about someone bidding over a million dollars at auction for a malware infested laptop (and they knew about the malware) is bizarre. I mean, if there's really a demand for malware infested machines then it seems like there should be a cheaper way to go about getting them. If all else fails just reach out to the people trying to get rid of the ones they already have.

Wednesday, October 31, 2018

If it's FIPS I sips

from here

Having recently become constrained by FIPS 140-2 compliance I found myself wondering "How am I supposed to hash passwords?". Then I wondered "How have other FIPS 140-2 compliant vendors been hashing passwords?" - and then I thought of the most obvious answer* and all the breaches of government systems seemed a lot less surprising.

(*Using a cryptographic hash instead of a password hash)

Wednesday, September 5, 2018

Let's just hope it doesn't become everyone's business

from here

The Australian government wants backdoors built into things and justifies it with an example of a perp using Snapchat and Facebook, which aren't encrypted  and which already have facilities to provide law enforcement with everything they need.

(Thanks to Alec Muffet for tweeting the analysis)

Thursday, July 26, 2018

It's amazing what you get to see at a SECURITY conference

from here

The strongest part of the security behind RSA SecurID tokens is that the code on the little screen on the token isn't easy to guess and changes too often to be brute forced. None of that matters if an attacker can SEE it.

Tuesday, July 3, 2018

Basics First

from here

Don't bother worrying about state-sponsored attackers if you haven't figured out how to keep out the kids yet.

Friday, May 4, 2018

LOVEINT is in the air

from here

Oh Facebook. Either your data is meant to help people find love in the creepiest way imaginable, or it's not. Please make up your mind.

Considering all the things Facebook has pulled over the years, the idea of turning it into a dating site gives me the chills, and the fact that they don't like their employees doing precisely that seems to suggest at least some at Facebook feel the same way.

Monday, April 16, 2018

You know your OpSec stinks when...

from here

Sometimes the logs you leave behind are digital, and sometimes they're physical. Either way they'll give you away.

Friday, February 23, 2018

Votey McVoteface for 2020

from here

Oh, you thought voting machines were air-gapped? Yeah, not so much, apparently.