Remember the good old days when security patches rarely needed patches? Because security patches themlelves were rare enough anyway?
Read moreProblems with Multifactor Authentication
October 21 2021Roger Grimes on why multifactor authentication isn’t a panacea:
The first time I heard of this issue was from a Midwest CEO. His organization had been hit by ransomware...
Read more
Fascinating research: “Generating Master Faces for Dictionary Attacks with a Network-Assisted Latent Space Evolution.”
Abstract: A master face is a face image that passes face-based identity-authentication for a large...
Read more
Backdoor Added — But Found — in PHP
April 9 2021Unknown hackers attempted to add a backdoor to the PHP source code. It was two malicious commits, with the subject “fix typo” and the names of known PHP developers...
Read moreEasy SMS Hijacking
March 19 2021
Vice is reporting on a cell phone vulnerability caused by commercial SMS services. One of the things these services permit is text message forwarding. It turns out that...
Read moreOn the Insecurity of ES&S Voting Machines’ Hash Code
March 16 2021
Andrew Appel and Susan Greenhalgh have a blog post on the insecurity of ES&S’s software authentication system:
It turns out that ES&S has bugs in their hash-code checker: ...
Read more
Medieval Security Techniques
February 12 2021Sonja Drummer describes (with photographs) two medieval security techniques. The first is a for authentication: a document has been cut in half with an irregular pattern, so that the...
Read moreNSA on Authentication Hacks (Related to SolarWinds Breach)
December 18 2020
The NSA has published an advisory outlining how “malicious cyber actors” are “are manipulating trust in federated authentication environments to access protected data in the cloud.” This is...
Read more
This is interesting:
Toward the end of the second incident that Volexity worked involving Dark Halo, the actor was observed accessing the e-mail account of a user via OWA....
Read more
Authentication Failure
December 14 2020
This is a weird story of a building owner commissioning an artist to paint a mural on the side of his building — except that he wasn’t actually...
Read more
Recent Comments