Showing posts with label what year is it. Show all posts
Showing posts with label what year is it. Show all posts

Thursday, July 13, 2023

The patches that never end

from here and here

Maybe you thought Internet Explorer would be ancient history by now, but unfortunately Microsoft is still making security updates for it.

Thursday, February 2, 2023

I just had a QNAP

from here and here

It's hard to believe, but the year is 2023 and people are still creating products with SQL injection vulnerabilities. I can only guess that the Q in QNAP doesn't stand for quality. It might stand for quick, because that's how fast you can get pwned with a vulnerability like that.

Friday, December 9, 2022

Microsoft's IE, they put that shit in everything

from here and here

Thanks to Microsoft's misguided efforts to make their inferior browser an integral part of the Windows platform, the IE rendering engine was stuck into all sorts of things - and now, even though the browser has long since been deprecated, governmental hackers are still using IE exploits to break into systems because IE is embedded into MS Office products. Thanks for nothing, Microsoft.

Friday, February 11, 2022

They'll take your privacy and security. Seriously.

from here

It seems that when it comes to privacy and security, the government's position seems to be that, instead of it being a right, we have to EARN IT. Of course we never actually will earn it in their eyes, so there's little reason for us to go along with them on this. 

Tuesday, December 14, 2021

Even Google fails at asset management

from here

This is your irregular reminder to check your network to see if there are any servers on it that don't need to be there anymore. One less server is one less thing to patch and one less thing that could be exploited in the absence of a patch (and if it's been running for 21 years you've got to think it's missing a few patches)..

Tuesday, July 20, 2021

Last century called and they want their vuln back

from here

I kid you not, I was holding up photos in front of face recognition cameras 20 years ago, and I'm pretty sure I wasn't the first person to think of it. This recent finding may have a novel way of presenting the captured image to the system, but it's still just feeding a captured image to the system. Since the only real tricky bit was the fact that the system required an infrared image, I suspect a photo printed with infrared ink might have done the trick without needing to rely on any camera funny-business.

20 years and face rec is still being bypassed in fundamentally the same way. Is it any wonder I have no faith in biometrics?

Tuesday, July 6, 2021

What could possibly go wrong?

from here

Telling users to disable their antivirus was a shady thing software vendors advised their customers decades ago, before the malware problem exploded. It's mind boggling to learn that some are still doing it, and worse they're makers of remote administration software that is used by managed service providers who remotely administer the systems of hundreds of organizations - with a fairly predictable outcome

There are better ways of dealing with false alarms on the software you make than getting your customers to disable their security or worse getting them to disable their own customers security.

Tuesday, April 6, 2021

A year that starts with 2

from here

If we were talking about days it would be days that end in Y, but because we're talking about years it's years that start with 2.

Yes, Facebook had yet another breach. You should probably head over to Have I Been Pwned to see if you're affected by this (or any other) breach

Friday, November 20, 2020

It's obviously not the year of the password manager

from here

You'd think with all the extra free time people had this year they'd have finally worked out how to use a password manager to keep track of their passwords so they wouldn't need to use ridiculous ones like "123456" and "password" anymore. 

Thursday, February 13, 2020

Throwback Thursday for scammers

from here

Some attackers are highly creative geniuses. And then there's the other guys. Reusing a scam from years ago is not exactly an original thought, and I can't help but wonder what took them so long? Even unoriginal scammers could have simply jumped on the bandwagon back when this was new.

Tuesday, April 16, 2019

People still use WinRAR?

from here

I've used WinRAR in the distant past, but I'll be honest, as soon as Windows started natively supporting ZIP files I stopped bothering with 3rd party compressed archive tools, and I would have thought a lot of other people would have too. So colour me surprised that there's both a large enough user base to support widespread exploitation but also a large enough user base to make criminals consider trying to exploit it in the first place.

Thursday, March 21, 2019

What's next, the Caesar cipher?

from here

Cisco may discourage it's use, but for a cipher that was broken in 1863 it's hard to understand why it would be in modern equipment, or even legacy equipment at all. At some point backwards compatibility just becomes plain backwards.

Thanks to Liam O for tweeting about this ridiculous state of affairs.

Friday, March 8, 2019

The more things change, the more they stay the same

from here

There's literally over a decade of broken privacy promises, so I can't imagine why their newest one should be considered any differently.

Tuesday, February 26, 2019

Shockingly insecure

from here

Millions of people, who presumably have little or no choice about which utility company they use, have their security compromised by poor password security on the vendor's side. It's a data breach waiting to happen

Thursday, September 6, 2018

Couldn't they have just used a crypto-miner like normal cyber-criminals?

from here

Nothing quite like a true story to inspire a WTF? reaction. The idea that scareware is somehow still a viable model for a criminal enterprise in 2018 is only the tip of the WTF iceberg here.

Thanks to my mom for calling me at work about this ridiculous nonsense on her PC.

Thursday, June 2, 2016

What's Next? Friendster?

from here and here

If you're a MySpace user then I suppose you might want to change your password. That assumes, of course, that you can remember what your username and password were after all this time.