Wednesday, February 8, 2012

adware in your pocket

from here

whether or not things like android.counterclank qualify as malware or not (do the intricacies of malicious intent really matter when the unanimous consensus among users is that it's unwanted?) is of secondary importance to me. what really boggles my mind is that mobile app developers are actually falling for this con when desktop adware is still so fresh in people's minds (well, my mind, at any rate).

Tuesday, February 7, 2012

access all the things

from here

i have it on good authority that some employers actually do give contractors more access than their own employees. pretty ridiculous if you ask me.

if you give outside contractors more access...

if you give outside contractors more access than you give your own employees, then you might be a security idiot.

(inspiration - though you have to ask @diami03 for permission to be able to see it)

Monday, February 6, 2012

malware support

from here

just taking a little pot shot at the citadel trojan that brian krebs detailed back in january

Friday, February 3, 2012

veribad, verisign. veribad indeed.



so apparently verisign was breached back in 2010 and has yet to satisfactorily explain the details of what happened. not a good way to behave when much of the security of the web depends on you being trustworthy.

(unmodified image sources one and two)

if you think using a taser...

if you think using a taser is an appropriate response to someone walking their dog without a leash, you might be a security idiot

(inspiration)

Thursday, February 2, 2012

i don't always participate in DDoS attacks...

from here

so apparently someone in anonymous finally figured out how to provide their DDoS minions with plausible deniability, even if they can't provide them with actual anonymity. low orbit ion cannon has been made into a web-based version that people can be tricked into visiting and launching attacks from their browser.

TrueSuccess

from here

inspired by the news that a US court has decided that the 5th amendment can't be used when it comes to encryption

Wednesday, February 1, 2012

windows guilt accuser

from here

sometimes the line between malware and legitimate software isn't as clear-cut as we'd like (such as opt-in adware, or spyware to monitor prison inmates) so i started to wonder (genuinely) whether windows genuine advantage could qualify as a kind of ransomware. after all, it does demand that you (if you have a pirated copy of windows) pay microsoft for a legal copy of their software and prevents certain functions until you do.

ransomware vs. backups

from here

apparently ransomware (malicious software that demands a ransom in order to regain access to your computer or prevent notification of authorities to supposed illegal activity) is on the rise. we'll see if backup media will follow suit.