720-891-1663

Are 1-Time Passcodes a Corporate Liability?

No. Not really. Are bad 1-time passcodes a corporate liability? Yes, but bad anything is a liability. In the wake of the Twilio breach, my buddy Brian Krebs posted an item titled “How 1-Time Passcodes Became a Corporate Liability”. In one sense, he is right because most companies chose the easiest one 1-time passcode to […]

Continue reading → [DISPLAY_ACURAX_ICONS]

AI Detecting Gun Scanners at Schools has been a “Clusterf***”

Schools are legitimately trying to figure out ways to keep students safe from gun and other violence. Unfortunately, there are no simple ways to do this. Some schools are trying to use AI to solve the problem, but the reality that schools are experiencing using this technology is, apparently, quite different from what is represented […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Containing a Breach Can Backfire

A cybersecurity vendor for one of Mexico’s largest banks sent a cease-and-desist to a cybercrime forum saying that an auction on the site for data stolen from the bank – data for 10 million customers – was fake news and harming the bank’s reputation. So what did the web site’s administrator do? Not what the […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News For The Week Ending August 12, 2022

Windows 11 May Damage Data on Some CPUs Microsoft issued a warning that computers that use the Vector AES instruction set might damage data , but they don’t say how or why. Microsoft says fixes in June and May prevent further damage but the result is that encryption is much slower after the patch. They […]

Continue reading → [DISPLAY_ACURAX_ICONS]

There is a Lesson Here for Someone

Remember the Equifax breach a few years ago? Almost 150 million people were affected. Now its competitor is under the microscope. The class action microscope. A class action has been filed that says that Experian did little to prevent account takeovers by bad guys. The suit, quoting Brian Krebs’ blog (yes, really), says that hackers […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News for the Week Ending August 5, 2022

US Emergency Alert System Has a Minor Bug Homeland Security has issued an alert that there are critical vulnerability in the Emergency Alert System encoder and decoder devices. If left unpatched, it would allow a hacker to issue fake warnings of emergencies. The EAS is the nationwide alert system that is used to warn citizens […]

Continue reading → [DISPLAY_ACURAX_ICONS]