vielmetti + infosec   69

Massive Security Vulnerability In HTC Android Devices (EVO 3D, 4G, Thunderbolt, Others) Exposes Phone Numbers, GPS, SMS, Emails Addresses, Much More
Additionally, and the implications of this could end up being insignificant, yet still very suspicious, HTC also decided to add an app called androidvncserver.apk to their Android OS installations. If you're not familiar with the definition of VNC, it is basically a remote access server. On the EVO 3D, it was present from the start and updated in the latest OTA. The app doesn't get started by default, but who knows what and who can trigger it and potentially get access to your phone remotely? I'm sure we'll know soon enough - HTC, care to tell us what it's doing here?
htc  android  infosec  mobisec 
october 2011 by vielmetti
Palantir Apologizes For WikiLeaks Attack Proposal, Cuts Ties With HBGary - Andy Greenberg - The Firewall - Forbes
Now, just a few days later, one of those firms, Palo Alto-based Palantir, has publicly cut ties with HBGary and apologized for its role in the WikiLeaks response plan, essentially verifying the reality of that plan and isolating HBGary further.
palantir  wikileaks  infosec 
february 2011 by vielmetti
You Can Buy Illegal Access to U.S. Military Websites for $500
I'm going to go for the bargain and hack the State of Michigan and have some real fun. Ha! Try to find yourself on the hand now, Michiganders!
michigan-gov  security  infosec  talk-to-the-mitten 
january 2011 by vielmetti
Cambridge university refuses to censor student's thesis on chip-and-PIN vulnerabilities - Boing Boing
Ross Anderson gives a smackdown to British bankers who are unhappy about a student thesis
infosec  ross-anderson 
december 2010 by vielmetti
Fix your terrible, insecure passwords in five minutes
How to create a better password, by using an algorithm; of course, once the algorithm is well known, it's easy to crack passwords that use it.
via:Taryn  infosec 
december 2010 by vielmetti
ARBSEC - Ann Arbor Security Meetup
ARBSEC is the first Wednesday of every month. Unlike other meetups, you will not be expected to pay dues, "join up", or present a zero-day exploit to attend.
arbsec  annarbor  security  infosec  meetup  first-wednesday 
february 2010 by vielmetti
Smart meter crypto flaw worse than thought « root labs rdist
Travis describes two flaws: the PRNG is a 16-bit LFSR and it is not seeded with very much entropy. However, the datasheet recommends this random number generator be used to create cryptographic keys. It’s extremely scary to find such a poor understanding of crypto in a device capable of forging billing records or turning off the power to your house.
via:joshd  infosec  zigbee  random  prng  crypto 
february 2010 by vielmetti
2008 Internet Security Report | Security to the Core | Arbor Networks Security
Finally, the surveyed ISPs also said their vendor infrastructure equipment continues to lack key security features (like capacity for large ACL lists) and suffers from poor configuration management and a near complete absence of IPv6 security features. While most ISPs now have the infrastructure to detect bandwidth flood attacks, many still lack the ability to rapidly mitigate these attacks. Only a fraction of surveyed ISPs said they have the capability to mitigate DDoS attacks in 10 minutes or less. Even fewer providers have the infrastructure to defend against service-level attacks or this year’s reported peak of a 40 gigabit flood attack.
internet  security  ddos  opsec  netsec  infosec 
november 2008 by vielmetti
Threatchaos relaunches! | ThreatChaos
But, a blog buried within Network World’s community is hard to find so as of today I am re-launching threatchaos.com. With complete control over the technology I use and the features I develop this site will quickly become a valauble resource to the entire IT security industry. In addition to my daily blog posts I will be retaining people to help with news coverage. I am also embarking on several video ventures that will show up here.
infosec  stiennon  richard  threatchaos  security  blog  relaunch 
november 2008 by vielmetti
Emergent Chaos: Checking in on the Security of Chequing
I remember a conversation back in 1995 or 1996 with someone who described to me how the Automated ClearingHouse (ACH) for checking worked. He explained that once you had an ACH merchant account, you sent in a message of roughly the form (src, dest, amount, reason) and money got moved. I argued with him that this was inconceivable (yeah, yeah), and he must be mis-understanding. He assured me that no, he was right, and that the reason they ran this way was because it was cheaper, and because only trustworthy people could get ACH merchant accounts.
ach  infosec  finsec  checking  check21  better-faster-cheaper-pick-any-two 
november 2008 by vielmetti
PC World - Eleven Charged in Massive ID Theft Scheme
The ID theft ring stole more than 40 million credit and debit card numbers, said Michael Sullivan, U.S. attorney for the District of Massachusetts. The criminals installed sophisticated "sniffer" programs on the retailers' networks, allowing them to collect credit card and password information, he said during a press conference.
creditcard  identitytheft  wireless  infosec  cardshark 
august 2008 by vielmetti
Commentary: Inside the Twisted Mind of the Security Professional
Which is why CSE 484, an undergraduate computer-security course taught this quarter at the University of Washington, is so interesting to watch. Professor Tadayoshi Kohno is trying to teach a security mindset.
You can see the results in the blog the students are keeping. They're encouraged to post security reviews about random things: smart pill boxes, Quiet Care Elder Care monitors, Apple's Time Capsule, GM's OnStar, traffic lights, safe deposit boxes, and dorm -room security.
kohno  tadayoshi  design  security  infosec  hacking  psychology  schneier  bruce  social-engineering-will-get-you-what-you-want 
august 2008 by vielmetti
DNS Resolver Test
For secure name resolution, it is important that your DNS resolver uses random source ports. The box below will tell you if there is something you need to worry about.
dns  networks  security  services  dnssec  monkey  niels-provos  infosec  netsec 
july 2008 by vielmetti
Ensure Technologies: About Ensure
Founded in 1997 and headquartered in Ann Arbor, Michigan, Ensure Technologies is an innovative developer of intelligent security solutions designed to provide maximum security with minimal impact on users.
infosec  annarbor  michigan  ypsilanti  proxcard 
july 2008 by vielmetti
ratproxy - Google Code
passive web application security assessment tool
via:monkey  code  ajax  security  testing  infosec  trust-but-verify 
july 2008 by vielmetti
Why 'Anonymous' Data Sometimes Isn't
bruce schneier notes that birthdate + zip code + gender is probably enough to identify you. (ed43 + 48104)
security  surveillance  infosec  anonymous  birthday 
december 2007 by vielmetti
The 'Security Digest' Archives (TM) : Phage List: archive, by date
Phage List: archive, by date. 3/11/88 - Morris Internet Worm - 20th anniversary coming up
worm  morris-worm  security  infosec  phage  security-digest  1988 
november 2007 by vielmetti
Journal Inquirer - Security breach affects UConn Foundation donors
The foundation was one of 92 clients of the vendor, Convio, affected by the breach, Sponauer said.
convio  uconn  infosec  security  nptech  john-sponauer  nonprofit  foundation 
november 2007 by vielmetti
Attackers Snatch Member Data from 92 Nonprofits
Attackers have stolen passwords and accounts from 92 nonprofits by infiltrating systems at Convio, the leading online marketing company for nonprofits.
convio  getactive  nonprofit  nptech  crm  saas  infosec 
november 2007 by vielmetti
Miron’s Weblog » OpenSocial insecurity - no user to app authentication
no user authentication! Any user can forge anybody else’s identity when interacting with any OpenSocial application. As it currently stands, it is not possible to write secure social applications on the platform
api  facebook  identity  opensocial  security  widgets  infosec 
november 2007 by vielmetti
Social Hacking
I’m really starting to wonder about the overall security of the OpenSocial platform’s design. Not to say that I know more than Google, but I am surprised these issues weren’t noticed prior to launch.
google  hacking  web2.0  opensocial  infosec  security 
november 2007 by vielmetti
[OpenID] Phishing and OpenID
a significant problem with OpenID I've brought this up before and had assumed that most of these schemes would not get off the ground because of the severity and obviousness of the problem -- but I was wrong.
openid  phishing  security  infosec 
november 2007 by vielmetti
Details of hijacked 24/7 ad server emerge
Hackers have hijacked a server operated by Internet advertising company 24/7 Real Media Inc. and are using it to seed legitimate Web sites with ads carrying attack code, Symantec Corp. said Friday.
infosec  hackers  ad  advertising  security  24-7-real-media 
october 2007 by vielmetti
OpenID account security
3 classes of attacks on openid. (looks like a worse and worse system every time I read one of these articles)
openid  security  infosec  phishing 
october 2007 by vielmetti
Links » OpenID and Phishing: Episode II
The OpenID fanboys want OpenID to work on any old platform using only standard software, and so therefore are doomed to live in the world of broken authentication. This is fine if what you protect with your OpenID is worthless, but it seems clear that the
identity  openid  phishing  security  infosec  authentication  broken  worthless 
october 2007 by vielmetti
Links » OpenID: Phishing Heaven
OpenID announced the release of a new draft of OpenID Authentication 2.0 today. I’m reluctantly forced to come to the conclusion that the OpenID people don’t care about phishing, since they’ve defined a standard that has to be the worst I’ve ever
identitytheft  toread  openid  infosec  security  phishing  worst-ive-ever-seen 
october 2007 by vielmetti
The Identity Corner » The problem(s) with OpenID
Beyond this, OpenID is pretty much useless. The reasons for this are many: OpenID is highly vulnerable to phishing and other attacks, creates insurmountable privacy problems, is not a trust system, suffers from usability problems, and makes it unappealing
openid  infosec  design  usability  security 
october 2007 by vielmetti
Pushing String » Sun OpenID IdP: protocol and implementation review
When we put our OpenID provider through the security review wringer (many thanks to Glenn Brunette and his team for their work on this!), some nitsy OpenID protocol questions came out, along with issues of provider and consumer behavior in the wild. Some
openid  security  infosec 
october 2007 by vielmetti
TJX offers deal to end data breach suit - The Boston Globe
TJX Cos. said that it reached a tentative settlement with customers who were victims of the largest security breach of personal data ever reported and that it would provide store vouchers to some people whose data were compromised and a three-day sale for
tjx  infosec  tjmaxx 
september 2007 by vielmetti
Sensitive patient data stolen from nursing building - Crime
Since 8,585 tapes were stolen from the School of Nursing two weeks ago - the third data theft in the last year - University officials are stressing the importance of protecting against data theft.
michigan  annarbor  umich  nursing  infosec  theft  data  tapes 
september 2007 by vielmetti
Pfizer confirms third breach involving employee data since June
The company today confirmed that as many as 34,000 of its employees may be at risk of identity theft after a former employee illegally accessed and download copies of confidential information from a Pfizer computer system without the company's knowledge.
pfizer  pfired  infosec  via:richard-stiennon 
september 2007 by vielmetti
Planet-Websecurity.org: good news brought together
At this point Mike Shaver threw down the gauntlet. He gave me his business card with a hand written note on it, laying his claim on the line. The claim being - with responsible disclosure Mozilla can patch and deploy any critical severity holes within “
mozilla  security  patches  infosec  ten-freaking-days  ten-effing-days  ten-fracking-days 
august 2007 by vielmetti
Planet-Websecurity.org: good news brought together
From the Pwnie Awards website, the Mass 0wnage Pwnie Award is Awarded to the person who discovered the bug that resulted in the most widespread exploitation. Also known as the Pwnie for Breaking the Internet.
security  infosec  pwnie  most-likely-to-break-the-internet 
august 2007 by vielmetti
mezzoblue § Unsettling
For those who host with Dreamhost: I received a confirmation email from them at 8:27pm PST on June 5th that yes indeed, something in the neighbourhood of 3,500 FTP accounts have been compromised. If you’re on Dreamhost, time to change all your passwords
dreamhost  infosec  wordpress  spam  security  hosting 
june 2007 by vielmetti
Collaborative Thinking: Corporate data slips out via Google Calendar
Google Calendar gives users the choice of keeping calendar entries private or publishing them for the world to see, but some Google Calendar users appear to be sharing their calendar information without realizing it.
calendar  google  security  infosec 
june 2007 by vielmetti
Dreamhost hosting platform hacked! — Open Source Candy
some details emerging of dreamhost hack problems. black hat seo spam appears to be the nature of the exploit.
dreamhost  hosting  infosec  security 
june 2007 by vielmetti
Slashdot | The Real Impact of the Estonian Cyberattack
slashdot notes jose nazario's reporting on the estonian denial of service attacks
a2b3  slashdot  jose-nazario  estonia  cyberattack  ddos  infosec 
may 2007 by vielmetti
Cyberattack in Estonia--what it really means | Newsmakers | CNET News.com
When it comes to denial-of-service attacks, Jose Nazario has seen just about everything.
a2b3  estonia  ddos  cybercrime  infosec 
may 2007 by vielmetti
BBC NEWS | Technology | Cursor hackers target WoW players
Research by security firm Symantec suggests that the raw value of a WoW account is now higher than a credit card and its associated verification data.
credit  identity  wow  infosec  security  using-my-platinum-wow-account-to-buy-groceries 
april 2007 by vielmetti
UPDATE--TJX data theft called largest ever: 45.7M credit card numbers - Network World
Detailing the sheer magnitude of a crime first reported earlier this year, TJX yesterday disclosed in financial reports that at least 45.6 million credit and debit card numbers were stolen in 2005 and another 130,000 last year by hackers who have yet to b
tjx  tjmaxx  credit  creditcard  identify  theft  fraud  infosec 
april 2007 by vielmetti
TJX 10-K: computer intrusion at TJX, parent company of TJ Maxx
We suffered an unauthorized intrusion into portions of our computer systems that process and store information related to customer transactions that we believe resulted in the theft of customer data. We do not know who took this action and whether there w
tjx  edgar  10-k  sec  filing  security  infosec  credit-card  all-your-discount-merchandise-are-belong-to-us 
march 2007 by vielmetti
Hamachi : Download
free vpn software. holding my recco until some infosec geek blesses it
internet  free  infosec  via:anarchivist 
february 2007 by vielmetti
The Korea Times : Professor Leads ‘Indirect’ War on MS
korean internets depend on active x controls for info security, locking out mac, linux. k. professor sues
korea  microsoft  openweb  a2b3  opensource  infosec  activex 
february 2007 by vielmetti
ATLAS Dashboard: Global Summary
infosec dashboard of global threats and attacks
security  virus  worm  web  infosec  via:nazarijo  a2b3 
february 2007 by vielmetti
Internet Security Operations and Intelligence II - a DA Workshop
two a2b3'ers at this security ops meeting at Microsoft. hoping for a recap
botnet  malware  cisco  microsoft  research  virus  a2b3  infosec 
january 2007 by vielmetti
Gen Kanai weblog: the cost of monoculture
South Korea as a Windows only, no Mac, no firefox software monoculture. & the dangers thereof.
korea  a2b3  nethistory  security  infosec  firefox  crypto  standards  via:linkorama 
january 2007 by vielmetti
LRB | John Lanchester : Short Cuts
huge amounts of spam generated by bots, problems getting worse.
internet  spam  via:jremmers  botnet  infosec  email 
january 2007 by vielmetti
reddit.com: what's new online
reddit's user base has been stolen - user names, email addresses, passwords. passwords are like underwear, change yours frequently. via it harvest.
security  blog  reddit  infosec 
december 2006 by vielmetti
The Safety of Internet Search Engines - Revisited
what % of search engine results are dangerous to click on? wide variety here analyzed.
google  search  advertising  infosec 
december 2006 by vielmetti
Wired 14.11: Attack of the Bots
when i fight the bots the bots always win
bots  innovation  security  infosec 
october 2006 by vielmetti
Visitor Networks-The Internet Protocol Journal - Cisco Systems
dory leifer on the solution space for providing guest access to the net, wired or wireless.
networks  security  wifi  innovation  community_informatics  architecture  mobile  privacy  infosec  cisco 
october 2006 by vielmetti
ALA | Library Connection is “John Doe”— Board speaks about NSL order for library records
Today four Connecticut librarians spoke publicly for the first time about their experience as recipients of a National Security Letter (NSL) demanding library records.
infosec  patriot  patriotact  library  libraries  security  privacy  superpatron 
june 2006 by vielmetti
The Yes Men
see also Andy Bichlbaum interview on Teeter Talk
culture  identity  infosec  subversion  performance  politics  art  media 
april 2006 by vielmetti
Rohini Srihari
pursuing research on "unintended information revelation" at SUNY Buffalo
infosec  to:jose 
march 2005 by vielmetti

related tags

*****  10-k  24-7-real-media  a2b3  ach  activex  ad  advertising  ajax  all-your-discount-merchandise-are-belong-to-us  android  annarbor  anonymous  api  arbsec  architecture  art  authentication  bbc  better-faster-cheaper-pick-any-two  bgp  bgp-anycast  birthday  blog  botnet  bots  broken  bruce  bush  calea  calendar  cardshark  check21  checking  chicago  cisco  code  community_informatics  convio  credit  credit-card  creditcard  crm  crypto  culture  cve  cvss  cyberattack  cybercrime  data  ddos  deadlink  design  dns  dnssec  dreamhost  echelon  edgar  email  estonia  facebook  filing  finsec  firefox  first-wednesday  foundation  fraud  free  getactive  google  hackers  hacking  hacks  hosting  htc  identify  identity  identitytheft  infosec  infrastructure  innovation  internet  javascript  jimduncan  john-sponauer  jose-nazario  kohno  korea  libraries  library  linkedin  malware  media  meetup  michigan  michigan-gov  microsoft  mobile  mobisec  monkey  morris-worm  most-likely-to-break-the-internet  mozilla  nethistory  netsec  networks  niels-provos  nonprofit  nptech  NSA  nursing  openid  opensocial  opensource  openweb  opsec  palantir  party-like-its-2002  patches  patriot  patriotact  performance  pfired  pfizer  phage  phishing  politics  privacy  prng  proxcard  psychology  pwnie  random  reddit  relaunch  research  richard  ross-anderson  saas  schneier  search  sec  security  security-digest  services  skype  slashdot  social-engineering-will-get-you-what-you-want  spam  standards  stiennon  subversion  superbowl  superpatron  surveillance  tadayoshi  talk-to-the-mitten  tapes  ten-effing-days  ten-fracking-days  ten-freaking-days  testing  theft  threatchaos  tjmaxx  tjx  to:jose  toread  trust-but-verify  uconn  ultradns  umich  usability  usb  using-my-platinum-wow-account-to-buy-groceries  via:anarchivist  via:hackers  via:joshd  via:jremmers  via:linkorama  via:monkey  via:nazarijo  via:richard-stiennon  via:Taryn  virus  voip  vulernablity  web  web2.0  widgets  wifi  wikileaks  wireless  wiretap  wordpress  worm  worst-ive-ever-seen  worthless  wow  ypsilanti  zigbee 

Copy this bookmark:



description:


tags: