Massive Security Vulnerability In HTC Android Devices (EVO 3D, 4G, Thunderbolt, Others) Exposes Phone Numbers, GPS, SMS, Emails Addresses, Much More
october 2011 by vielmetti
Additionally, and the implications of this could end up being insignificant, yet still very suspicious, HTC also decided to add an app called androidvncserver.apk to their Android OS installations. If you're not familiar with the definition of VNC, it is basically a remote access server. On the EVO 3D, it was present from the start and updated in the latest OTA. The app doesn't get started by default, but who knows what and who can trigger it and potentially get access to your phone remotely? I'm sure we'll know soon enough - HTC, care to tell us what it's doing here?
htc
android
infosec
mobisec
october 2011 by vielmetti
Palantir Apologizes For WikiLeaks Attack Proposal, Cuts Ties With HBGary - Andy Greenberg - The Firewall - Forbes
february 2011 by vielmetti
Now, just a few days later, one of those firms, Palo Alto-based Palantir, has publicly cut ties with HBGary and apologized for its role in the WikiLeaks response plan, essentially verifying the reality of that plan and isolating HBGary further.
palantir
wikileaks
infosec
february 2011 by vielmetti
You Can Buy Illegal Access to U.S. Military Websites for $500
january 2011 by vielmetti
I'm going to go for the bargain and hack the State of Michigan and have some real fun. Ha! Try to find yourself on the hand now, Michiganders!
michigan-gov
security
infosec
talk-to-the-mitten
january 2011 by vielmetti
Cambridge university refuses to censor student's thesis on chip-and-PIN vulnerabilities - Boing Boing
december 2010 by vielmetti
Ross Anderson gives a smackdown to British bankers who are unhappy about a student thesis
infosec
ross-anderson
december 2010 by vielmetti
Fix your terrible, insecure passwords in five minutes
december 2010 by vielmetti
How to create a better password, by using an algorithm; of course, once the algorithm is well known, it's easy to crack passwords that use it.
via:Taryn
infosec
december 2010 by vielmetti
The Real Lessons Of Gawker's Security Mess - Forbes
december 2010 by vielmetti
Gawker's mess, via Forbes #infosec
infosec
from twitter
december 2010 by vielmetti
ARBSEC - Ann Arbor Security Meetup
february 2010 by vielmetti
ARBSEC is the first Wednesday of every month. Unlike other meetups, you will not be expected to pay dues, "join up", or present a zero-day exploit to attend.
arbsec
annarbor
security
infosec
meetup
first-wednesday
february 2010 by vielmetti
Smart meter crypto flaw worse than thought « root labs rdist
february 2010 by vielmetti
Travis describes two flaws: the PRNG is a 16-bit LFSR and it is not seeded with very much entropy. However, the datasheet recommends this random number generator be used to create cryptographic keys. It’s extremely scary to find such a poor understanding of crypto in a device capable of forging billing records or turning off the power to your house.
via:joshd
infosec
zigbee
random
prng
crypto
february 2010 by vielmetti
2008 Internet Security Report | Security to the Core | Arbor Networks Security
november 2008 by vielmetti
Finally, the surveyed ISPs also said their vendor infrastructure equipment continues to lack key security features (like capacity for large ACL lists) and suffers from poor configuration management and a near complete absence of IPv6 security features. While most ISPs now have the infrastructure to detect bandwidth flood attacks, many still lack the ability to rapidly mitigate these attacks. Only a fraction of surveyed ISPs said they have the capability to mitigate DDoS attacks in 10 minutes or less. Even fewer providers have the infrastructure to defend against service-level attacks or this year’s reported peak of a 40 gigabit flood attack.
internet
security
ddos
opsec
netsec
infosec
november 2008 by vielmetti
Threatchaos relaunches! | ThreatChaos
november 2008 by vielmetti
But, a blog buried within Network World’s community is hard to find so as of today I am re-launching threatchaos.com. With complete control over the technology I use and the features I develop this site will quickly become a valauble resource to the entire IT security industry. In addition to my daily blog posts I will be retaining people to help with news coverage. I am also embarking on several video ventures that will show up here.
infosec
stiennon
richard
threatchaos
security
blog
relaunch
november 2008 by vielmetti
Emergent Chaos: Checking in on the Security of Chequing
november 2008 by vielmetti
I remember a conversation back in 1995 or 1996 with someone who described to me how the Automated ClearingHouse (ACH) for checking worked. He explained that once you had an ACH merchant account, you sent in a message of roughly the form (src, dest, amount, reason) and money got moved. I argued with him that this was inconceivable (yeah, yeah), and he must be mis-understanding. He assured me that no, he was right, and that the reason they ran this way was because it was cheaper, and because only trustworthy people could get ACH merchant accounts.
ach
infosec
finsec
checking
check21
better-faster-cheaper-pick-any-two
november 2008 by vielmetti
Emergent Chaos: The Emergent Chaos Jazz Combo of the Blogosphere
november 2008 by vielmetti
good reliable security blog
blog
security
infosec
finsec
november 2008 by vielmetti
PC World - Eleven Charged in Massive ID Theft Scheme
august 2008 by vielmetti
The ID theft ring stole more than 40 million credit and debit card numbers, said Michael Sullivan, U.S. attorney for the District of Massachusetts. The criminals installed sophisticated "sniffer" programs on the retailers' networks, allowing them to collect credit card and password information, he said during a press conference.
creditcard
identitytheft
wireless
infosec
cardshark
august 2008 by vielmetti
Commentary: Inside the Twisted Mind of the Security Professional
august 2008 by vielmetti
Which is why CSE 484, an undergraduate computer-security course taught this quarter at the University of Washington, is so interesting to watch. Professor Tadayoshi Kohno is trying to teach a security mindset.
You can see the results in the blog the students are keeping. They're encouraged to post security reviews about random things: smart pill boxes, Quiet Care Elder Care monitors, Apple's Time Capsule, GM's OnStar, traffic lights, safe deposit boxes, and dorm -room security.
kohno
tadayoshi
design
security
infosec
hacking
psychology
schneier
bruce
social-engineering-will-get-you-what-you-want
You can see the results in the blog the students are keeping. They're encouraged to post security reviews about random things: smart pill boxes, Quiet Care Elder Care monitors, Apple's Time Capsule, GM's OnStar, traffic lights, safe deposit boxes, and dorm -room security.
august 2008 by vielmetti
Ensure Technologies: About Ensure
july 2008 by vielmetti
Founded in 1997 and headquartered in Ann Arbor, Michigan, Ensure Technologies is an innovative developer of intelligent security solutions designed to provide maximum security with minimal impact on users.
infosec
annarbor
michigan
ypsilanti
proxcard
july 2008 by vielmetti
ratproxy - Google Code
july 2008 by vielmetti
passive web application security assessment tool
via:monkey
code
ajax
security
testing
infosec
trust-but-verify
july 2008 by vielmetti
Why 'Anonymous' Data Sometimes Isn't
december 2007 by vielmetti
bruce schneier notes that birthdate + zip code + gender is probably enough to identify you. (ed43 + 48104)
security
surveillance
infosec
anonymous
birthday
december 2007 by vielmetti
DDOS attack 'really, really tested' UltraDNS | The Register
december 2007 by vielmetti
account of 2002 era attacks on the root name servers, no SLA payouts
ultradns
ddos
bgp
bgp-anycast
party-like-its-2002
infrastructure
infosec
december 2007 by vielmetti
The 'Security Digest' Archives (TM) : Phage List: archive, by date
november 2007 by vielmetti
Phage List: archive, by date. 3/11/88 - Morris Internet Worm - 20th anniversary coming up
worm
morris-worm
security
infosec
phage
security-digest
1988
november 2007 by vielmetti
Journal Inquirer - Security breach affects UConn Foundation donors
november 2007 by vielmetti
The foundation was one of 92 clients of the vendor, Convio, affected by the breach, Sponauer said.
convio
uconn
infosec
security
nptech
john-sponauer
nonprofit
foundation
november 2007 by vielmetti
Attackers Snatch Member Data from 92 Nonprofits
november 2007 by vielmetti
Attackers have stolen passwords and accounts from 92 nonprofits by infiltrating systems at Convio, the leading online marketing company for nonprofits.
convio
getactive
nonprofit
nptech
crm
saas
infosec
november 2007 by vielmetti
Miron’s Weblog » OpenSocial insecurity - no user to app authentication
november 2007 by vielmetti
no user authentication! Any user can forge anybody else’s identity when interacting with any OpenSocial application. As it currently stands, it is not possible to write secure social applications on the platform
api
facebook
identity
opensocial
security
widgets
infosec
november 2007 by vielmetti
Social Hacking
november 2007 by vielmetti
I’m really starting to wonder about the overall security of the OpenSocial platform’s design. Not to say that I know more than Google, but I am surprised these issues weren’t noticed prior to launch.
google
hacking
web2.0
opensocial
infosec
security
november 2007 by vielmetti
[OpenID] Phishing and OpenID
november 2007 by vielmetti
a significant problem with OpenID I've brought this up before and had assumed that most of these schemes would not get off the ground because of the severity and obviousness of the problem -- but I was wrong.
openid
phishing
security
infosec
november 2007 by vielmetti
Details of hijacked 24/7 ad server emerge
october 2007 by vielmetti
Hackers have hijacked a server operated by Internet advertising company 24/7 Real Media Inc. and are using it to seed legitimate Web sites with ads carrying attack code, Symantec Corp. said Friday.
infosec
hackers
ad
advertising
security
24-7-real-media
october 2007 by vielmetti
OpenID account security
october 2007 by vielmetti
3 classes of attacks on openid. (looks like a worse and worse system every time I read one of these articles)
openid
security
infosec
phishing
october 2007 by vielmetti
Links » OpenID and Phishing: Episode II
october 2007 by vielmetti
The OpenID fanboys want OpenID to work on any old platform using only standard software, and so therefore are doomed to live in the world of broken authentication. This is fine if what you protect with your OpenID is worthless, but it seems clear that the
identity
openid
phishing
security
infosec
authentication
broken
worthless
october 2007 by vielmetti
Links » OpenID: Phishing Heaven
october 2007 by vielmetti
OpenID announced the release of a new draft of OpenID Authentication 2.0 today. I’m reluctantly forced to come to the conclusion that the OpenID people don’t care about phishing, since they’ve defined a standard that has to be the worst I’ve ever
identitytheft
toread
openid
infosec
security
phishing
worst-ive-ever-seen
october 2007 by vielmetti
The Identity Corner » The problem(s) with OpenID
october 2007 by vielmetti
Beyond this, OpenID is pretty much useless. The reasons for this are many: OpenID is highly vulnerable to phishing and other attacks, creates insurmountable privacy problems, is not a trust system, suffers from usability problems, and makes it unappealing
openid
infosec
design
usability
security
october 2007 by vielmetti
Pushing String » Sun OpenID IdP: protocol and implementation review
october 2007 by vielmetti
When we put our OpenID provider through the security review wringer (many thanks to Glenn Brunette and his team for their work on this!), some nitsy OpenID protocol questions came out, along with issues of provider and consumer behavior in the wild. Some
openid
security
infosec
october 2007 by vielmetti
TJX offers deal to end data breach suit - The Boston Globe
september 2007 by vielmetti
TJX Cos. said that it reached a tentative settlement with customers who were victims of the largest security breach of personal data ever reported and that it would provide store vouchers to some people whose data were compromised and a three-day sale for
tjx
infosec
tjmaxx
september 2007 by vielmetti
Sensitive patient data stolen from nursing building - Crime
september 2007 by vielmetti
Since 8,585 tapes were stolen from the School of Nursing two weeks ago - the third data theft in the last year - University officials are stressing the importance of protecting against data theft.
michigan
annarbor
umich
nursing
infosec
theft
data
tapes
september 2007 by vielmetti
Pfizer confirms third breach involving employee data since June
september 2007 by vielmetti
The company today confirmed that as many as 34,000 of its employees may be at risk of identity theft after a former employee illegally accessed and download copies of confidential information from a Pfizer computer system without the company's knowledge.
pfizer
pfired
infosec
via:richard-stiennon
september 2007 by vielmetti
Planet-Websecurity.org: good news brought together
august 2007 by vielmetti
At this point Mike Shaver threw down the gauntlet. He gave me his business card with a hand written note on it, laying his claim on the line. The claim being - with responsible disclosure Mozilla can patch and deploy any critical severity holes within “
mozilla
security
patches
infosec
ten-freaking-days
ten-effing-days
ten-fracking-days
august 2007 by vielmetti
Planet-Websecurity.org: good news brought together
august 2007 by vielmetti
From the Pwnie Awards website, the Mass 0wnage Pwnie Award is Awarded to the person who discovered the bug that resulted in the most widespread exploitation. Also known as the Pwnie for Breaking the Internet.
security
infosec
pwnie
most-likely-to-break-the-internet
august 2007 by vielmetti
mezzoblue § Unsettling
june 2007 by vielmetti
For those who host with Dreamhost: I received a confirmation email from them at 8:27pm PST on June 5th that yes indeed, something in the neighbourhood of 3,500 FTP accounts have been compromised. If you’re on Dreamhost, time to change all your passwords
dreamhost
infosec
wordpress
spam
security
hosting
june 2007 by vielmetti
Collaborative Thinking: Corporate data slips out via Google Calendar
june 2007 by vielmetti
Google Calendar gives users the choice of keeping calendar entries private or publishing them for the world to see, but some Google Calendar users appear to be sharing their calendar information without realizing it.
calendar
google
security
infosec
june 2007 by vielmetti
Slashdot | The Real Impact of the Estonian Cyberattack
may 2007 by vielmetti
slashdot notes jose nazario's reporting on the estonian denial of service attacks
a2b3
slashdot
jose-nazario
estonia
cyberattack
ddos
infosec
may 2007 by vielmetti
Cyberattack in Estonia--what it really means | Newsmakers | CNET News.com
may 2007 by vielmetti
When it comes to denial-of-service attacks, Jose Nazario has seen just about everything.
a2b3
estonia
ddos
cybercrime
infosec
may 2007 by vielmetti
BBC NEWS | Technology | Cursor hackers target WoW players
april 2007 by vielmetti
Research by security firm Symantec suggests that the raw value of a WoW account is now higher than a credit card and its associated verification data.
credit
identity
wow
infosec
security
using-my-platinum-wow-account-to-buy-groceries
april 2007 by vielmetti
UPDATE--TJX data theft called largest ever: 45.7M credit card numbers - Network World
april 2007 by vielmetti
Detailing the sheer magnitude of a crime first reported earlier this year, TJX yesterday disclosed in financial reports that at least 45.6 million credit and debit card numbers were stolen in 2005 and another 130,000 last year by hackers who have yet to b
tjx
tjmaxx
credit
creditcard
identify
theft
fraud
infosec
april 2007 by vielmetti
TJX 10-K: computer intrusion at TJX, parent company of TJ Maxx
march 2007 by vielmetti
We suffered an unauthorized intrusion into portions of our computer systems that process and store information related to customer transactions that we believe resulted in the theft of customer data. We do not know who took this action and whether there w
tjx
edgar
10-k
sec
filing
security
infosec
credit-card
all-your-discount-merchandise-are-belong-to-us
march 2007 by vielmetti
Hamachi : Download
february 2007 by vielmetti
free vpn software. holding my recco until some infosec geek blesses it
internet
free
infosec
via:anarchivist
february 2007 by vielmetti
The Korea Times : Professor Leads ‘Indirect’ War on MS
february 2007 by vielmetti
korean internets depend on active x controls for info security, locking out mac, linux. k. professor sues
korea
microsoft
openweb
a2b3
opensource
infosec
activex
february 2007 by vielmetti
BBC NEWS | Technology | Hackers attack heart of the net
february 2007 by vielmetti
ddos against dns, film at 11
ddos
infosec
bbc
dns
february 2007 by vielmetti
ATLAS Dashboard: Global Summary
february 2007 by vielmetti
infosec dashboard of global threats and attacks
security
virus
worm
web
infosec
via:nazarijo
a2b3
february 2007 by vielmetti
» Super Bowl stadium site hacked, seeded with exploits | Zero Day | ZDNet.com
february 2007 by vielmetti
malicious javascript installs keystroke logger.
security
superbowl
virus
javascript
infosec
february 2007 by vielmetti
Gen Kanai weblog: the cost of monoculture
january 2007 by vielmetti
South Korea as a Windows only, no Mac, no firefox software monoculture. & the dangers thereof.
korea
a2b3
nethistory
security
infosec
firefox
crypto
standards
via:linkorama
january 2007 by vielmetti
LRB | John Lanchester : Short Cuts
january 2007 by vielmetti
huge amounts of spam generated by bots, problems getting worse.
internet
spam
via:jremmers
botnet
infosec
email
january 2007 by vielmetti
reddit.com: what's new online
december 2006 by vielmetti
reddit's user base has been stolen - user names, email addresses, passwords. passwords are like underwear, change yours frequently. via it harvest.
security
blog
reddit
infosec
december 2006 by vielmetti
The Safety of Internet Search Engines - Revisited
december 2006 by vielmetti
what % of search engine results are dangerous to click on? wide variety here analyzed.
google
search
advertising
infosec
december 2006 by vielmetti
Chicago area cops arrest 12 in credit card fraud scheme - Network World
november 2006 by vielmetti
good old fashioned identity theft, notes Richard Stiennon
chicago
security
fraud
infosec
november 2006 by vielmetti
Wired 14.11: Attack of the Bots
october 2006 by vielmetti
when i fight the bots the bots always win
bots
innovation
security
infosec
october 2006 by vielmetti
Visitor Networks-The Internet Protocol Journal - Cisco Systems
october 2006 by vielmetti
dory leifer on the solution space for providing guest access to the net, wired or wireless.
networks
security
wifi
innovation
community_informatics
architecture
mobile
privacy
infosec
cisco
october 2006 by vielmetti
ALA | Library Connection is “John Doe”— Board speaks about NSL order for library records
june 2006 by vielmetti
Today four Connecticut librarians spoke publicly for the first time about their experience as recipients of a National Security Letter (NSL) demanding library records.
infosec
patriot
patriotact
library
libraries
security
privacy
superpatron
june 2006 by vielmetti
The Yes Men
april 2006 by vielmetti
see also Andy Bichlbaum interview on Teeter Talk
culture
identity
infosec
subversion
performance
politics
art
media
april 2006 by vielmetti
Bruce Schneier on the NSA and Bush's illegal eavesdropping:
february 2006 by vielmetti
Echelon is the world's largest information vacuum cleaner.
schneier
bush
NSA
echelon
wiretap
infosec
february 2006 by vielmetti
The Common Vulnerability Scoring System
april 2005 by vielmetti
Jim Duncan has been working on this
jimduncan
cvss
cve
vulernablity
infosec
april 2005 by vielmetti
Rohini Srihari
march 2005 by vielmetti
pursuing research on "unintended information revelation" at SUNY Buffalo
infosec
to:jose
march 2005 by vielmetti
related tags
***** ⊕ 10-k ⊕ 24-7-real-media ⊕ a2b3 ⊕ ach ⊕ activex ⊕ ad ⊕ advertising ⊕ ajax ⊕ all-your-discount-merchandise-are-belong-to-us ⊕ android ⊕ annarbor ⊕ anonymous ⊕ api ⊕ arbsec ⊕ architecture ⊕ art ⊕ authentication ⊕ bbc ⊕ better-faster-cheaper-pick-any-two ⊕ bgp ⊕ bgp-anycast ⊕ birthday ⊕ blog ⊕ botnet ⊕ bots ⊕ broken ⊕ bruce ⊕ bush ⊕ calea ⊕ calendar ⊕ cardshark ⊕ check21 ⊕ checking ⊕ chicago ⊕ cisco ⊕ code ⊕ community_informatics ⊕ convio ⊕ credit ⊕ credit-card ⊕ creditcard ⊕ crm ⊕ crypto ⊕ culture ⊕ cve ⊕ cvss ⊕ cyberattack ⊕ cybercrime ⊕ data ⊕ ddos ⊕ deadlink ⊕ design ⊕ dns ⊕ dnssec ⊕ dreamhost ⊕ echelon ⊕ edgar ⊕ email ⊕ estonia ⊕ facebook ⊕ filing ⊕ finsec ⊕ firefox ⊕ first-wednesday ⊕ foundation ⊕ fraud ⊕ free ⊕ getactive ⊕ google ⊕ hackers ⊕ hacking ⊕ hacks ⊕ hosting ⊕ htc ⊕ identify ⊕ identity ⊕ identitytheft ⊕ infosec ⊖ infrastructure ⊕ innovation ⊕ internet ⊕ javascript ⊕ jimduncan ⊕ john-sponauer ⊕ jose-nazario ⊕ kohno ⊕ korea ⊕ libraries ⊕ library ⊕ linkedin ⊕ malware ⊕ media ⊕ meetup ⊕ michigan ⊕ michigan-gov ⊕ microsoft ⊕ mobile ⊕ mobisec ⊕ monkey ⊕ morris-worm ⊕ most-likely-to-break-the-internet ⊕ mozilla ⊕ nethistory ⊕ netsec ⊕ networks ⊕ niels-provos ⊕ nonprofit ⊕ nptech ⊕ NSA ⊕ nursing ⊕ openid ⊕ opensocial ⊕ opensource ⊕ openweb ⊕ opsec ⊕ palantir ⊕ party-like-its-2002 ⊕ patches ⊕ patriot ⊕ patriotact ⊕ performance ⊕ pfired ⊕ pfizer ⊕ phage ⊕ phishing ⊕ politics ⊕ privacy ⊕ prng ⊕ proxcard ⊕ psychology ⊕ pwnie ⊕ random ⊕ reddit ⊕ relaunch ⊕ research ⊕ richard ⊕ ross-anderson ⊕ saas ⊕ schneier ⊕ search ⊕ sec ⊕ security ⊕ security-digest ⊕ services ⊕ skype ⊕ slashdot ⊕ social-engineering-will-get-you-what-you-want ⊕ spam ⊕ standards ⊕ stiennon ⊕ subversion ⊕ superbowl ⊕ superpatron ⊕ surveillance ⊕ tadayoshi ⊕ talk-to-the-mitten ⊕ tapes ⊕ ten-effing-days ⊕ ten-fracking-days ⊕ ten-freaking-days ⊕ testing ⊕ theft ⊕ threatchaos ⊕ tjmaxx ⊕ tjx ⊕ to:jose ⊕ toread ⊕ trust-but-verify ⊕ uconn ⊕ ultradns ⊕ umich ⊕ usability ⊕ usb ⊕ using-my-platinum-wow-account-to-buy-groceries ⊕ via:anarchivist ⊕ via:hackers ⊕ via:joshd ⊕ via:jremmers ⊕ via:linkorama ⊕ via:monkey ⊕ via:nazarijo ⊕ via:richard-stiennon ⊕ via:Taryn ⊕ virus ⊕ voip ⊕ vulernablity ⊕ web ⊕ web2.0 ⊕ widgets ⊕ wifi ⊕ wikileaks ⊕ wireless ⊕ wiretap ⊕ wordpress ⊕ worm ⊕ worst-ive-ever-seen ⊕ worthless ⊕ wow ⊕ ypsilanti ⊕ zigbee ⊕Copy this bookmark: