Showing posts with label socially awesome awkward penguin. Show all posts
Showing posts with label socially awesome awkward penguin. Show all posts

Friday, March 10, 2023

Pre-Owned

from here and here

Not to make you paranoid about buying used computers, but they probably should be shown at least a little extra care - wipe the drives and install a fresh operating system before they're used.

Wednesday, May 25, 2022

Now anyone can come from the land down under

from here and here

I'm sure I've dated myself with that title, but as badly as the person who thought a 4 digit encryption key was strong enough. They were clearly from far, far in the past. 

Friday, June 4, 2021

So much for those backups

from here

While Exagrid did have to go back and ask for the decryption tool a second time (apparently not only did their backup solution work to restore their data, they didn't manage to make a backup of the decryption tool either), they would have been in a bind even if their technology had been able to work for them because ransomware doesn't just encrypt data anymore - the operators make their own backups of your data and threaten to expose it if you don't pay up. 

Unfortunately, while restoring from backups is absolutely the ideal approach to getting your data back, it's frequently no longer sufficient for dealing with ransomware incidents because of the added blackmail approach.

Thursday, March 25, 2021

What could possibly go wrong?

from here

Even after changing direction they still don't seem to be thinking about spam. If someone can send harassing content then they can also send any other kind of unwanted content. In fact the attempt to connect itself may be unwanted. I can't tell you how many times I've seen emails from people at other businesses wanting to connect for business purposes. In theory this is what Slack was trying to facilitate but it would still be unwanted commercial messaging from my perspective. I don't want to connect with them, I'm not the right person at my company to reach out to, and frankly I doubt my company is interested in fielding invitations from every Tom, Dick, and Harry organization out there.

Don't call us, we'll call you.

Friday, March 12, 2021

Imagine being that desperate for antivirus

from here

Do they have difficulty getting security software in China? It actually seems quite amazing that an advanced persistent threat group would have to resort to such means to get the software. Couldn't they just get it from a torrent site or something?

Monday, April 6, 2020

Military grade self-own

from here

I can't help but wonder what the captain of that Venezuelan naval vessel was thinking when they attacked a passenger cruise liner. Clearly the armed military vessel was no match for an armoured but otherwise unarmed cruise ship.

Attackers need to be careful they don't bite off more than they can chew.

Wednesday, November 27, 2019

How not to stay hidden

from here

This story may focus on the victim and the mistakes they made, but I'm more interested in the mistakes the attacker made. Did they fall asleep? Did they forget to check the progress? Did it never occur to them there might not be enough room to zip up all the data they wanted to exfiltrate?

Thursday, April 18, 2019

Guess they didn't need a backdoor after all

from here

I would like it very much if the EFF actually convinced Facebook to take their advice and stand up for the people, but this is Facebook we're talking about. Of course an abusive organization is going to let other abusive organizations run slipshod all over the general public. So long as it doesn't affect their bottom line, all they have to do is keep paying lip-service to privacy.

Tuesday, March 5, 2019

Who could have possibly seen that coming?

from here

After the umpteenth privacy controversy, why are we still using Facebook? Oh, right, they automate emotional labour.

Thursday, January 5, 2017

The 'convenience' of biometrics

from here

TouchID is often framed as a convenience, and I'm sure it is... until it isn't.

Thanks to Dave Lewis for sharing his hot tub problems (surely a subset of first world problems) on Twitter.

Thursday, October 20, 2016

Oh Security Vendors, You So Silly

from here

I don't know what the vendors at SECTor were thinking, but that's definitely what they were doing.

Thursday, April 24, 2014

Too Bad I Can't Operate My Mouth Securely

from here

OpSec (aka operational security - basically behaving or using technology in a secure manner) and SecOps (aka security operations - basically performing duties related to providing security) are not the same thing. Not even close.