720-891-1663

Multi-Factor Authentication is NOT a Silver Bullet

As hackers got better, so did developers. Multi-Factor authentication, a technique which requires something that you know, like a password and something that you have, like an SMS message on your phone, makes the lives of crooks harder, but far from impossible to attack and here is why. One way this is done is via […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Feds Fine Capital One for Shoddy Cloud Security

Dial back your wayback machine to September of last year. Capital One announced a hack of their Amazon environment by an ex-Amazon employee the previous July that was possible to due an incorrect configuration of their security settings. Fast forward to today and the feds announced an $80 million fine for bad cloud hygiene. The […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Here is a Match – Lawyers+Security Pros

There are an amazing number of misconfigured Amazon S3 buckets. I have no clue why. No company should be in this boat any more. Truffle Security said that a team of there security pros STUMBLED across about 4,000 of them. What was in them? Login credentials – not great. Security keys – even worse. API […]

Continue reading → [DISPLAY_ACURAX_ICONS]