I have to both harass and complement Hilton. Until recently, Hilton was offering Honors members 1,000 points to change their passwords. First the harassment: A security staffer at BancSec figured out that you could hijack any other Honors account by guessing or knowing the account number and making a small change to the site’s HTML. The […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
UPDATE: KARE11 in Minneapolis is reporting that if you include attorney’s fees and other costs, Target will be on the hook for around $25 million (see article) and that payments could begin as early as April 30th. NPR is reporting that Target has agreed to set up a $10 million fund for victims of last […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
The Electronic Communications Privacy Act was written 29 years ago. Before Google. Before Facebook. Even before AOL. The rules that ECPA set up were based on how we worked 29 years ago. While there have been many attempts to change ECPA, including the Electronic Communications Privacy Act Amendments Act of 2015 (ECPAA), none, so far, […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
CNet wrote about a man who was arrested at the Halifax (Canada) airport for refusing to hand over the passcode for his cellphone to the Canadian border agents. Even if you are not paranoid, it should make you think about what gadgets you take across the border. Here are some details of this case. He […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
CSO Online wrote an article on how easy it is to compromise the controls that ISPs and domain registrars have put it place. I will describe it in more detail in a minute, but here is the short version: Businesses are much more concerned about keeping customers happy than they are about keeping customers secure. […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
Two more insurance companies, Premera Blue Cross and Lifewise, joined the club that no one wants to be a member of and announced that they were both breached (see here and here). Premera said that 11 million records were hacked and Lifewise lost 250,000. Both said the breaches started in May of last year […]
Continue reading →
[DISPLAY_ACURAX_ICONS]