Key Escrow that Might Work
Instead of encrypting everything with a single government key, several government agencies need to provide new public keys every day. The private key must be under the control of a court. Each secure...
View ArticleVirtual Cables for IoT Devices
IoT devices are a security nightmare: They should be easy to use / set up but hard to hack. With classic devices, the solution is “cable”. If there is no cable between two devices, they can’t talk to...
View ArticleWhen Uncle Doc Gets Hacked
Most of the time, when users get infected with a computer virus or a Trojan, it’s a nuisance. But what happens when an important person becomes a victim of a cracker like your doctor? How about this...
View ArticleSurveillance Produces Blackmail Instead of Security
They say that “good” people have nothing to hide and, therefore, nothing to fear from surveillance. Everyone of us has something to hide. When we are confronted with out dark side, immediate, temporary...
View ArticleBalancing Security
For your IT security, you want Security It must be cheap And comfortable Now choose at most two. As always in life, everything has a cost. There is no cheap way to be secure which is also comfortable....
View ArticleGood Summary of Heartbleed
This article contains a good summary of the Heartbleed bug and it’s consequences. Want to know whether you’re affected? Check sites you use here: filippo.io/Heartbleed/ Note: You will want to check the...
View ArticleHTML5 vs. Security
“HTML5 vs. Security” was a talk given by Thomas Röthlisberger of Compass Security AG which gave a nice overview over some of the security problems that HTML5 brings. Areas covered by the talk:...
View ArticleGoogle Shares Your WLAN Passwords with NSA
If you “Back up my data” is enabled on your Android phone, then Google keeps a clear-text, unencrypted copy of your WLAN passwords on its servers. Since Google is an US company, the government and its...
View ArticleOverview Of Man in the Middle Attacks
David Blake posted a current overview of Man in the Middle type attacks: 15 Surprising Ways You Could Fall Victim to a Man in the Middle Attack These include: Key-loggers (hard- and software) Browser...
View ArticleCVE Changes Counter
The Common Vulnerabilities and Exposures or CVE is a registry for security related flaws and computer systems. The old counting system allowed only for 9’999 bugs per year. That’s no longer enough....
View ArticlePasswords Suck
On Wednesday, GitHub improved their code search. A few hours later, a couple of people had tried “begin rsa private key” and got more results than any sane person would anticipate. Just in case, this...
View ArticleTargeted Spamming via Facebook
In the past few weeks, I started getting mails from friends which just contain a link: hey, Aaron http://some-dubious-link/a/b/c/ 9/25/2012 12:34:56 PM Turns out that someone is analyzing my...
View ArticleEmbarrassing Security Failure at PayPal
PayPal is one of the places who really care about security. But even they were vulnerable to XSS type of attacks using the search feature (see this article for details). At the moment, I’m not sure if...
View ArticleStand up for your freedom to install free software!
Read the truth behind so-called “Secure Boot” and sign the statement. Tagged: Freedom, FSF, Secure Boot, Security, UEFI
View ArticleWho is Responsible For Data Theft?
Would you like to see your name, address, birth date and email on a public bill board? On the main street? What if the bill board is behind a big sign “don’t read this”? If that worries you, why do you...
View ArticleTNBT – Avoiding Common Errors
Writing secure code is ever more important. There are lots of examples: HBGary, Sony, Google. Even if you’re not one of the biggest companies out there, security starts to become important as soon as...
View Article