Thursday, September 14, 2017

I sense another governmental agency coming

from here

Maybe it's just me but I think if you take 14 months to clean up after a USB worm, maybe banning an antivirus vendor's products from being used in your agencies isn't such a good idea. Honestly, you need all the help you can get.

Perverse incentives for security updates

found on Quick Meme

There's a kernel of truth in this conspiracy theory. When Sun has figured out a way to monetize attempts to update their software (by nagging you and then pre-checking a checkbox to install a 3rd party toolbar) then there's something kind of suspicious about Java requiring a security update - the argument could be made that they have a financial incentive to leave a few vulnerabilities in the product in order to force users to go through the install process all over again and in at least some cases forget to uncheck the checkbox for that toolbar.

Wednesday, September 13, 2017

What happens when your face is your password

from here

Our faces are probably the part of the human body that we change the most often, whether it's with shaving or makeup or surgery or injury. Of all the biometrics one could use to unlock a device, it is perhaps the most problematic.

That's one way to disinfect your computer

found on Chuckles Network

On the one hand, this may very well eliminate biological viruses so the statement could actually be true. On the other hand I now want there to be a malware removal tool called Lysol to take advantage of this kind of misunderstanding.

Tuesday, September 12, 2017

Not the kind of 'friendly' skies you want to fly

from here

Maybe we could fly the professional skies in stead? Or better yet, how about the polite skies? That sounds good to me.

Fraud or not

posted to the Boing Boing forum by forceblink

The complicated problem of figuring out whether something like this is a scam or not is the fact that Equifax seems to have behaved in some decidedly scammy ways in the past. There needs to be a way to protect yourself without giving up the very same sorts of data that was compromised in the first place, and Equifax needs to stop trying to screw victims over.

Monday, September 11, 2017

Identity Theft 'Protection'

from here

I can't imagine how consumers are supposed to trust Equifax now that they've been breached and over 100 million records were exposed. It's a good thing for Equifax that they don't need consumers to trust them, they just need other businesses who get breached to give them their own customers' details in order to offer those customers free credit monitoring in response to their own breach.

Ultimately, though, it is the fate of all large databases of valuable information to eventually be breached. We need to rethink what information we compile and hold on to for the long term.

I'd wait too, wouldn't you?

found on Imgur bur originally from Carbon Based Slice

They say patience is a virtue, but I guess it's also a part of good OpSec by helping you avoid entering secrets into computers you don't (and probably shouldn't) trust.

Of course 2 factor authentication could help in this scenario, but many 2 factor authentication schemes these days use the phone, so....

Friday, September 8, 2017

Crooks don't want to work harder than they have to

from here

If you're looking for money then you rob banks because that's where the money is. If you're looking for personal info then you rob Equifax because increasingly that's where the personal info is.

There's actually a couple of reasons why breaching Equifax may have been easier than compiling the data

  1. Equifax may not have done a good job of protecting the data (we don't know yet)
  2. The more breaches there are the more work is required to collect the data from all the various sources

No master keys allowed

found on Imgur

A password that a lot of people use is a password that will get you into a lot of accounts without much effort. Eliminating this is a good thing.

The weird thing is that it would have been harder to do this without all the password breaches because they're what tell us what the commonly used passwords are.