Showing posts with label condescending wonka. Show all posts
Showing posts with label condescending wonka. Show all posts

Wednesday, March 1, 2023

Gives new meaning to the term "auto theft"

from here and here

Of course there are a number of other scenarios one can imagine with autonomous vehicles operating against the wishes of their owners, and a few of them come from the mind of Stephen King. However, given how car thieves have already adopted technological approaches to stealing cars, I have no doubt this will be one of the first ways crooks exploit this new technology.

Friday, December 23, 2022

The last straw for LastPass

from here and here

How does a password management company make such a grave error as not protecting URLs? Knowing you have an account on a questionable website is sensitive in and of itself, without giving away the username or password, and by sensitive I mean it can get folks killed in some places.

This metadata will also be useful for phishing attacks, so if you're a LastPass user, you might see an increase in phishing emails. However, since the breach itself was months ago, the increase might have already happened.

Password managers are still good, of course, but maybe not this particular one, and maybe not online ones. Online password managers are incredibly valuable targets, while each of us individually is  generally not. An offline password manager would require someone getting through your own defenses to compromise you instead of compromising millions of users at once. 

Wednesday, October 19, 2022

I didn't see anything when I slipped and fell into the database

from here and here

A quick check of Have I Been Pwned indicates that yes, SHA1 is still being used. 

I didn't think it would be worth it to look for MD5 at first, I was so sure the age of MD5 was over and I would have had to look for a while to find an example, but nope, there was a breach using MD5 added at the beginning of this year. I didn't have to look far at all.

Monday, September 12, 2022

Taking our security seriously in 3...2...1...

from here and here

I can't imagine Patreon's recent firing of their entire security team ending in anything less than some kind of compromise. There will be no continuity of security. Anyone hired on after this will either be struggling to figure out what those before them did without anyone to on-board them, or they're going to be starting over from scratch.

Wednesday, July 27, 2022

The most dangerous thing they ever caught

from here and here

They may have caught it but they didn't stop it. They don't stop much, after all.

Monday, April 11, 2022

Follow the money

from here and here

Realistically, if the feds can track down purveyors of child sexual abuse material through the blockchain, they can track down ransomware operators too. There's absolutely no added complexity.

Friday, August 13, 2021

Nobody gives in just once

from here

Apple turning their devices into a surveillance system and then saying "We'll only allow it to look for one kind of thing, trust us" has got to be one of the most tone deaf moves they've made in a loooong time. Of course they'll abandon that promise in the future, and most people already know this. Only the most gullible Apple fan boys would believe the promises they're making surrounding this.

Thursday, October 29, 2020

A backdoor for one is a backdoor for all

from here

Y'know what's better than telling the government what will happen to the backdoors they're asking for? Reminding them of what's already happened to the ones they had

Monday, August 31, 2020

Send bitcoins if you want your brain back

from here

So based on this article, scrambling your brain with ransomware might be a bit of a stretch. However, if they can figure out the position of a pigs legs, how much more difficult would it be to read keystrokes (you know, like the ones when you enter your password)? I feel like maybe they didn't think this through all the way.

Monday, July 6, 2020

Should have called it Leakr because you know what's going to happen

from here

Every social networking site in existence has suffered a data breach. The operators of Parler must be out to lunch if they think their site will be any different or that they can collect that piece of information and actually keep it safe.

Tuesday, April 7, 2020

Don't bite the hand that aids you

from here

Aren't state-sponsored hackers supposed to be intelligent? Interfering with the organization trying to help bring an end to the pandemic that's afflicting your country (among many others) doesn't seem like a terribly well thought out plan.

It's almost as if they don't realize it works against their best interests, which makes me seriously question the basic premise that APTs are supposed to be smart.

We're all in rough shape right now. This isn't rocket science. Stay the fuck at home, and leave the helpers alone.

Wednesday, February 19, 2020

Friday, May 17, 2019

It definitely is...

from here

It seems like an incredibly stupid trick, but I guess it follows the same logic we've seen before - the people who can tell it's a scam think it's so obvious that there's no need to do anything about it and that leaves the scammer free to exploit the people who don't know it's a scam. 

However, if someone is claiming to be part of some official agency and demanding you pay them with gift cards or else then that is definitely a scam.

Wednesday, May 8, 2019

Forget Linux, this is the year of Facebook on the desktop

from here

With Facebook's plans to escape the browser (and the sandbox it represents), I expect to see them find new and worse ways to abuse the greater privilege they'll have with a native desktop app.

The question we should all be asking is, how long until the Facebook rootkit?

Tuesday, April 23, 2019

What could possibly go wrong?

from here

Always be wary of advice to disable your AV. Unless it's causing a problem that's literally stopping you from using the computer, there should be another way to deal with the problem.

And if it is causing a problem that's preventing you from using the computer, only disable it for the few moments it takes to change whatever setting needs changing or uninstall whatever update needs uninstalling. You don't want to leave the door open to attackers too long and you certainly don't want to risk forgetting it's disabled.

Monday, January 7, 2019

Cutting off your nose to spite your face

from here

If you value security, you need to pay the people who carry out security work. If they don't get paid, they eventually stop working, just as hundreds of TSA personnel are transitioning towards. Virtually no one can afford to work unpaid long term.

Tuesday, December 18, 2018

Never reuse password predictions

from here

It's that time of year again. Time for people to make predictions, and one of the predictions that seems to have the most staying power is the end of passwords. The prediction never comes true, though, and it probably never will.

Friday, December 14, 2018

Algorithms speak louder than words

found on the Mozilla blog

If you're going to tell people you take their data (and the security/privacy thereof) seriously, you better be able to put your money where your mouth is. That means spending the time, effort, and money on using something better than MD5, which has been deprecated for 20 some odd years.

Monday, October 29, 2018

This is the faux-lice, we have you surrounded

from here

It's amazing who gets to carry a badge and a gun in Michigan. About as amazing as seeing anti-malware companies teaming up with malware vendors, and I imagine there will be just as much done about it - absolutely nothing.

Friday, October 12, 2018

Passwords don't make everything more secure

from here

Thanks to Bloorjack Horseman for reminding me of this problem. Though I haven't encountered it (yet) with Adobe Reader (probably because I use something else to view PDFs), I have seen needless sign-in requirements added to other things, like Visual Studio.

You might think that forcing you to log into an app makes it more secure. Taken to an absurd extreme you might even think this would solve the problem of software vulnerabilities because PoC exploits wouldn't even be able to pop CALC.EXE without knowing the right password.

But here's the paradox - the more things that require passwords, the more people will get burned out from entering passwords and ultimately the more it will encourage people to not only use simple passwords but to also reuse them everywhere.

Adding sign-in requirements to things that could (and for a long time did) work perfectly well without them is just going to exacerbate the password problems we're already struggling with. It will make security worse, not better.