Tag Archives: security
AJAX SHA-1/256/384/512 Hash Generator Released

AJAX SHA-1/256/384/512 Hash Generator Released

In addition to the other handy AJAX-enabled utilities we released, we’ve just added a SHA (1, 256, 384 and 512) generator utility to the collection.
Enjoy!

Read full storyComments { 0 }
4square-gowalla-iphone-app-password-sent-plaintext

Foursquare and Gowalla iPhone Apps Sending Passwords in Plaintext

Martin Kou did some Wireshark’ing this morning on the Foursquare iPhone application and found out it is logging you in to Foursquare by sending your password in plaintext over the wire.
Foursquare replied and said they are rolling out an HTTPS authentication-based login today which is good news, but seriously, 1 million users later and how [...]

Read full storyComments { 1 }
atm-card-slot-panel

ATM Card Skimmer Crimes Rampant in South East

We reported on ATM Card Skimmers in the past. It was amazing to most readers (me too!) how “normal” the addition of a card skimmer on your average ATM looks. Of course they are manufactured to slip onto the equipment unnoticed, but there is always that hope that you are attentive enough to catch such a [...]

Read full storyComments { 6 }
google-buzz-sergey-brin

Google Throws Privacy Out the Window by Default with Buzz

Update #1: Today Google rolled out the first of what we hope is many of the Buzz privacy controls that were lacking at launch. The changes include:

More visible option to not show followers/people you follow on your public profile
Ability to block anyone who starts following you
More clarity on which of your followers/people you follow can [...]

Read full storyComments { 0 }
how-to-crack-any-padlock

How to Crack any Padlock

Pretty awesome real-world algorithm guide for cracking any padlock out there — not that secure for folks in-the-know:

Read full storyComments { 0 }
atm-fullsized-digital-skimmer

ATM Card Skimmers – Hidden in Plain Sight and Hard to Spot

Recently ran across this article at KrebsonSecurity analyzing common ATM skimmers that they found installed around the city and I was amazed at how well hidden they were — I’m almost certain I’ve used an ATM or gas pump with a skimmer on it now that I look at these.

One common theme that seems to [...]

Read full storyComments { 8 }
national-flag-of-the-uae

Re-entry into UAE / Dubai Fine for Americans and 34 Other Exempt Countries

If you have ever wanted to go to Dubai or anywhere else inside the United Arab Emirates and read recently about the new “no re-entry into the UAE in under 30 days” law that is going around you are probably thinking like I was: “Well, screw that trip…”.
As it turns out, this law firstly seems [...]

Read full storyComments { 0 }
visa-logo-card

Verified by Visa is Useless

I was just shopping on Newegg and decided to purchase some more RAM for my computer. I added the item to my shopping card, hit purchase, entered my Credit Card info and hit Finish.
I had forgotten that I had enabled the frustratingly stupid “Verified by Visa” check-out security process in the past… I somehow always [...]

Read full storyComments { 0 }
windows-vista-driver-security-dialog-no-driver-info

Microsoft Will Never Understand Usability – Vista Device Driver Security Example

We took our first look at Microsoft’s inbility to create something genuinely useful and a minature review of Vista when we evaluated Windows Vista Backup at the beginning of the year. The premise of that article being that by evaluating a single program, and all the usability/functionality flaws it had, you got an impression of [...]

Read full storyComments { 0 }
lock screen

Using host.allow and hosts.deny for Quick Network Security

While configuring a firewall is by far the best way to secure your system, there are times when you need a way to access a remote server that doesn’t compromise security.
A quick fix for boxes that need to be in the De Militarized Zone (DMZ) for a short period of time is to modify your [...]

Read full storyComments { 0 }
telephoto-key-picture-for-sd-key-algorithm

Software Algorithm to Recreate Keys from Photo Only

John Hering sent in a link to a story about UC Sand Diego computer programmers that have developed an image-recognition software algorithm that can reproduce a physical key only from a picture of the key.
Maybe not the most surprising thing in the face of recently announced 2D-to-3D image generation technology, but leads to an interesting [...]

Read full storyComments { 0 }
wi-fi-logo-high-quality

WPA Wi-Fi Encryption Cracked

I guess it was only a matter of time utnil someone found a quick way to break WPA Wi-Fi Encryption.  Erik Tews and his co-researcher Martin Beck found a way to break the Temporal Key Integrity Protocol (TKIP) key used by WPA in a relatively short amount of time: 12 to 15 minutes.  So far [...]

Read full storyComments { 1 }
Palantir Orb

Stream Your Video Feeds with Palantir

Snapshot from palantir.santinoli.com:

Over the past couple of weeks I’ve dabbled with the idea to add a webcam to my personal site that monitored a couple of pet furballs. The task was not too straight forward. I ran into many hiccups with alpha software and missing libraries. Most of the software related to [...]

Read full storyComments { 0 }
vodafone-logo

Vodafone Study Confirms 25% of Security Breaches are due to Mobile Devices

Interesting tid-bit from Vodafone UK this morning, looks like after a long-winded study they found that:
25% of companies experience a security breach due to mobile device (notebook, cell phone) use in unapproved ways.
50% of employees have no idea their companies have mobile device use-policies in place.
Sounds to me like the companies are the issue here [...]

Read full storyComments { 0 }

Android's Unlock Screen is a Level of Security

Google’s Android mobile platform has a pretty interesting approach to the unlock screen that makes it more than just a simple way to avoid hitting buttons in your pocket. Android’s unlock screen actually introduces a new level of security to the device that didn’t previously exist on mobile phones without introducing an annoying new system [...]

Read full storyComments { 0 }
Easy Encryption in Java and Python with Keyczar

Easy Encryption in Java and Python with Keyczar

Do you need to encrypt small text data, like serial numbers or customer numbers in your web application?  With the amount of data being transmitted online and the increasing need to protect customers against identity theft, encryption is the one and only choice to keep customers safe. Unfortunately, implementing encryption is a daunting task [...]

Read full storyComments { 0 }
fly-clear-registered-flyer-card

Fast-Pass Air Travel System 'Clear' Data Stolen, Not So Fast Anymore

“Clear” is a fast-pass-esque air-travel system run by a 3rd party company that allows passengers to pay $100/year to pre-register all their humanly personal information in exchange for what amounts to a “fast pass through security” card seen on the left.
The only down-side is what happens when all that insane amount of personal information is [...]

Read full storyComments { 0 }
Apple Hands Out Account Login Because Someone Asked

Apple Hands Out Account Login Because Someone Asked

They say that the chain is only as strong as the weakest link… unfortunately for you, if that weakest link is a retarded Customer Service Rep at Apple and he’s reading an email that says:
am forget my password of mac,did you give me password on new email marko.[redacted]@yahoo.com
And decides “Heck, I should probably email this [...]

Read full storyComments { 0 }
airport-security-screening-old-crippled-man

US Govt. Thinks Citizens Are a Constant Threat

The Washington Times is reporting that the Department of Homeland Security (DHS) expressed “great interest” in a “safety bracelet” that all air-travelers would be forced to wear if implemented.
This information was from a promotional video (Link Dead, they have removed the movie after all the attention it got) over at the Lamperd Less Lethal website.
The [...]

Read full storyComments { 0 }
iphone-email-inbox-unsecure

Securely Formatting / Erasing an iPhone

With the news getting around that pre-owned iPhones are actually shipping with previous-owner personal information on them, cops recovering data off of iPhones and word that AT&T is ramping up their pre-owned iPhone plan, learning how to correctly wipe your iPhone so all traces of personal information are gone is important.
Luckily Securosis put together a [...]

Read full storyComments { 0 }
Insane CCTV Network in London Doesn't Help

Insane CCTV Network in London Doesn't Help

Well that’s a shocker… it looks like the incredible network of closed-circuit television security cameras in London (and slowly being built out here in the US in most major cities) is actually not doing a damn thing to curb petty theft which was the entire platform building the stupid thing stood on in the first [...]

Read full storyComments { 0 }

AT&T/Cingular EDGE Network Down in Midwest

What is going on with the internets today… reports of AT&T/Cingular’s “server” that handles their entire EDGE network being down for the Midwest today, and could be fixed as late as Feb 5th.
I declare more shenanigans… Chinese hackers! (or zombies)

Read full storyComments { 0 }
New RFID Passports: Staging for the NAU

New RFID Passports: Staging for the NAU

We have blogged in the past about the desire of the international bankers to create the North American Union (Canada, United States, Mexico) along with a common currency: The Amero.
Now you can watch for yourself as the first steps towards creating this reality are set into place, regardless of the outcry against it.
First Step: Create [...]

Read full storyComments { 0 }

New Credit Card Cross-Sell-Like Scams Used by Vendors

12 Angry Men did an awesome write-up on a new type of “scam” used by shady marketing companies to automatically opt-you-in to very small month reoccurring charges that you are most likely to not notice on your credit card using some trickery of how credit card data is handled in a typical HTTP session. Here [...]

Read full storyComments { 0 }