Researchers at David Ben Gurion University in Israel have demonstrated controlling a toy rocket launcher attached to an air gapped computer by another computer nearby (see article). There are lots of limitations to this attack, but still it shows how a motivated attacker like the NSA or its competitors, can suck data out of a […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
I have to both harass and complement Hilton. Until recently, Hilton was offering Honors members 1,000 points to change their passwords. First the harassment: A security staffer at BancSec figured out that you could hijack any other Honors account by guessing or knowing the account number and making a small change to the site’s HTML. The […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
UPDATE: KARE11 in Minneapolis is reporting that if you include attorney’s fees and other costs, Target will be on the hook for around $25 million (see article) and that payments could begin as early as April 30th. NPR is reporting that Target has agreed to set up a $10 million fund for victims of last […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
CSO Online wrote an article on how easy it is to compromise the controls that ISPs and domain registrars have put it place. I will describe it in more detail in a minute, but here is the short version: Businesses are much more concerned about keeping customers happy than they are about keeping customers secure. […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
Two more insurance companies, Premera Blue Cross and Lifewise, joined the club that no one wants to be a member of and announced that they were both breached (see here and here). Premera said that 11 million records were hacked and Lifewise lost 250,000. Both said the breaches started in May of last year […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
PC World is reporting that researchers, looking for servers that were susceptible to the FREAK attack, found that some manufacturers have taken a shortcut when it comes to security. First, FREAK is an attack that allows attackers to force a encryption session between a user and a server to use a very weak 512 bit […]
Continue reading →
[DISPLAY_ACURAX_ICONS]