Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, April 10, 2014

BBC News - Heartbleed Bug: Public urged to reset all passwords

Several tech firms are urging people to change all their passwords after the discovery of a major security flaw. 


 "On the scale of one to 10, this is an 11” -Bruce Schneier Security technologist 

 The Yahoo blogging platform Tumblr has advised the public to "change your passwords everywhere - especially your high-security services like email, file storage and banking". 

 Security advisers have given similar warnings about the Heartbleed Bug. It follows news that a product used to safeguard data could be compromised to allow eavesdropping. 

 OpenSSL is a popular cryptographic library used to digitally scramble sensitive data as it passes to and from computer servers so that only the service provider and the intended recipients can make sense of it.  

If an organisation employs OpenSSL, users see a padlock icon in their web browser - although this can also be triggered by rival products.


Security Now 450


How the Heart bleeds
The end of updates for Windows XP, AnyDVD, the Heart Bleed Bug, and more.
View or listen to Security Now 450

Security Now 451


TrueCrypt & Heartbleeds Part2
The previous week consisted of nearly a single story: Heartbleed. It was only "nearly", though, because we also received the results from the first phase of the TrueCrypt audit.
View or listen to Security Now 451

Thursday, February 27, 2014

Update NOW: OS X Mavericks v10.9.2 and Security Update 2014-001

Apple released OS X 10.9.2 and Security Update 2014-001, which includes a fix for a major SSL security flaw that first came to light on Friday, after the release of iOS 7.0.6. 

You can test if your OS has been patched by visiting https://gotofail.com.


OS X Mavericks 10.9.2 Update (Combo) http://support.apple.com/kb/DL1726
Security Update 2014-001 (Mountain Lion) http://support.apple.com/kb/DL1729
Security Update 2014-001 (Lion) http://support.apple.com/kb/DL1727
Security Update 2014-001 Server (Lion) http://support.apple.com/kb/DL1728


Monday, February 24, 2014

Everything We Know About The Huge Security Flaw That Affects (Nearly) All iPhones, iPads, And Apple Computers

 "A software bug called "Gotofail" currently affects every single Apple device, whether it's an iPhone, iPad, or desktop or laptop computer. If you have not updated your machine in the last few days, your Apple device is currently vulnerable.

Apple revealed that the security flaw in its iOS operating system for iPhone and iPad affects encryption. That's how data gets sent over the Internet without you having to worry about people reading your emails or stealing your credit card number when you buy something from Amazon. 
The name "Gotofail" is a reference to the "goto" computer command.

A fix recently went out to iOS customers that renders this bug a non-issue, so if you haven't updated your iPhone or iPad's software recently, be sure to do so. There's a full guide right here, but you'll want to plug your phone in as if you're charging it, open the Settings app, select "General," then "Software Update," and follow the instructions that appear.

OS X users are still waiting for a fix. Official word from Apple is that it will come "very soon."
"

Continue reading the Business Insider Story by Dylan Love

Tuesday, October 16, 2012

Opinion: FBI security scare means Apple's iPhone beats Android for BYOD enterprise

Apple [AAPL] already leads the mobile enterprise with its iOS devices, and seems likely to consolidate its grip in the months ahead, with the security of its platforms giving the firm a sure grasp on hearts and minds in corporate IT, while its competitor gets named and shamed in an FBI warning. Click to read: FBI security scare means Apple's iPhone beats Android for BYOD enterprise

Saturday, July 23, 2011

Forget Passwords and Let the Browser Remember - Technology Review

An experimental tool removes the need to hand your credentials over to lots of different websites.

"The Mozilla Foundation, a nonprofit corporation that makes the Firefox browser, released an experimental tool last week that could dramatically change the way people identify themselves online."

Forget Passwords and Let the Browser Remember - Technology Review

Thursday, July 21, 2011

Apple Safari 5.1 increases security

Safari 5.1 includes improvements to performance, stability, and security.
Apple Safari 5.1 increases security

Sunday, January 23, 2011

Apple Taps Former Navy Information Warrior for Global Director of Security

Apple has tapped security expert and author David Rice to be its director of global security, three sources who know Rice have confirmed to me. He’s expected to start at Apple in March.

Apple Taps Former Navy Information Warrior for Global Director of Security

Friday, November 12, 2010

Apple smashes patch record with gigantic update

Computerworld - Apple on Wednesday patched more than 130 vulnerabilities in Mac OS X, smashing a record the company set last March when it fixed over 90 flaws.

The update for OS X 10.6, a.k.a. Snow Leopard, and OS X 10.5, better known as Leopard, was Apple's first since September and the seventh for the year.

Calling the update "huge," Mac vulnerability expert Charlie Miller pointed out that even with a staggering 134 patches, there were plenty of flaws still around.

"Apple releases huge patch, still miss all my bugs," said Miller in a tweet late Wednesday. "Makes you realize how many bugs are in their code, or they're very unlucky."

Continue reading the story by Gregg Keizer

Thursday, November 4, 2010

Mac OS X Boonana Trojan Horse trojan.osx.boonana.a

"SecureMac has discovered a new trojan horse in the wild that affects Mac OS X, including Snow Leopard (OS X 10.6), the latest version of OS X. The trojan horse, trojan.osx.boonana.a, is spreading through social networking sites, including Facebook, disguised as a video. The trojan is currently appearing as a link in messages on social networking sites with the subject "Is this you in this video?"

When a user clicks the infected link, the trojan initially runs as a Java applet, which downloads other files to the computer, including an installer, which launches automatically. When run, the installer modifies system files to bypass the need for passwords, allowing outside access to all files on the system. Additionally, the trojan sets itself to run invisibly in the background at startup, and periodically checks in with command and control servers to report information on the infected system. While running, the trojan horse hijacks user accounts to spread itself further via spam messages. Users have reported the trojan is spreading through e-mail as well as social media sites."

Continue reading the SecureMac Security Bulletin



FYI: Sophos has announced the world's first free business-strength anti-virus program for Macs. The Mac anti-virus product (used by big companies around the world) available for free download to home consumers.

Thursday, October 14, 2010

Facebook offers temporary log-ins for public computers

Facebook is launching one-time passwords in an effort to make it safer to log on to the social network from public computers.

It also claims the system will help prevent cyber-criminals accessing users' accounts.

Users need to text the words 'otp' to 32665 and they will be sent a temporary password that will expire after 20 minutes.

But security experts questioned whether the system was safe.

Continue reading the full at the BBC

Thursday, September 23, 2010

Beleaguered Windows users take heart Microsoft just tossed you a bone!

Free Microsoft Security Essentials formerly only free for home users is now free for small business users!

Microsoft Security Essentials has won a lot of praise since its introduction last year. The anti-malware software is unobtrusive and reasonably effective, and its price—free—can't be beat. One fly in the ointment has been the software's licensing terms; MSE is only licensed for home users. Businesses have to look elsewhere for their anti-malware needs.

That's set to change, at least a little, next month. From early October, small businesses—defined here as those with ten PCs or fewer—can use MSE, too. Microsoft claims that enterprise security software is too expensive, complicated, and hard to use for these organizations, hence its decision to expand the reach of MSE.

Read the full story by Peter Bright

Wednesday, August 25, 2010

So what has been going on with iTunes and PayPal?

"Users' experience suggests that there is some account cracking going on at the iTunes Store. But why, who and how?"

So what has been going on with iTunes and PayPal?


How to choose a secure password for your accounts
GRC Ultra High Security Password Generator

Monday, August 2, 2010

Microsoft quashed & diluted IE8's privacy features to appease advertisers inside and outside the company

The online habits of most people who use the world's dominant Web browser are an open book to advertisers. That wasn't the plan at first.

In early 2008, Microsoft Corp.'s product planners for the Internet Explorer 8.0 browser intended to give users a simple, effective way to avoid being tracked online (InPrivate Filtering). They wanted to design the software to automatically thwart common tracking tools, unless a user deliberately switched to settings affording less privacy.

That triggered heated debate inside Microsoft. As the leading maker of Web browsers, the gateway software to the Internet, Microsoft must balance conflicting interests: helping people surf the Web with its browser to keep their mouse clicks private, and helping advertisers who want to see those clicks.

In the end, the product planners lost a key part of the debate. The winners: executives who argued that giving automatic privacy to consumers would make it tougher for Microsoft to profit from selling online ads. Microsoft built its browser so that users must deliberately turn on privacy settings every time they start up the software.

Read the full story at the Wall Street Journal by NICK WINGFIELD

Tuesday, July 6, 2010

iTunes accounts plundered, Apple's App store needs better control mechanisms

"iTunes accounts have been compromised by money-loving criminals. It all started on Sunday, when The Next Web noticed that the list of the top 50 best selling application in the "Books" category contained 40 applications from the same application developer - one Thuat Nguyen."

iTunes accounts plundered, Apple's App store needs better control mechanisms

Monday, May 31, 2010

Google Dumps Microsoft Windows Company-Wide!


"Employees wanting to stay on Windows required clearance from “quite senior levels”, one employee said. “Getting a new Windows machine now requires CIO approval,” said another employee."

Monday, May 17, 2010

How to Quit Facebook Without Actually Quitting Facebook

With all the privacy issues surrounding Facebook, many people are considering quitting the site altogether. If you're not ready to take it that far, here's how to avoid the privacy breaches without completely deleting your account and losing touch with your friends.













Photo by Ludovic Berton.


Should I Quit Facebook Altogether?
We've all had that one friend who deactivated his/her Facebook and was never seen again, because no one could establish contact. As if the telephone, email, and IM were never invented, many people are at a loss as to how to contact you if your Facebook isn't an easy click away. Even if the situation isn't quite that dire, Facebook is still how a lot of people keep connected, and severing that connection completely is a big deal.

But now, privacy-minded folks have many legitimate reasons you should quit Facebook (or reasons you should but can't go through with it), the same thing is on everyone's mind: Is the grief of quitting worth avoiding future privacy breaches?

The Less Extreme Alternative
Luckily, there is another, more middle-of-the-road option. That's not to say this isn't still extreme—this isn't for the faint of heart. It isn't a tutorial about how to change your privacy settings. This is a tutorial on how to create the most minimalist Facebook profile possible, with as little information on yourself as possible, to be used only for communication between you and your friends. You won't be able to do much on the site; you probably won't even visit the site that often. This is not for people who want to continue using Facebook; it is for the people who are ready to up and quit tomorrow, but don't want to miss out on the next party just because they care about their privacy. So if you're really ready to give up wall posts, comments, Farmville, and fan pages, here's how to proceed without falling off the face of the Earth.

Continue reading the full article at LifeHacker by Whitson Gordon

Thursday, April 8, 2010

Macintosh = Hacker-Proof?

Charlie Miller has a habit of upending Apple's security claims.

Charlie A. Miller loves his Macbook Pro laptop. And his four other Apple ( AAPL - news - people ) PCs, the iPhone he uses daily and two older iPhones he keeps for tinkering. But his relationship with the company that created those gadgets is somewhat more complicated.

In March, for instance, the 36-year-old security researcher publicized his discovery of 20 security vulnerabilities in Apple's software. Each would allow a cybercriminal to take over the computer of a user who's tricked into opening a certain PDF attachment or who simply visits an infected Web page using Apple's Safari browser.

That haul of bugs is a record even for Miller, who over the last four years has become perhaps the world's most prominent Mac hacker. It may also be definitive proof that Apple devices aren't safe "right out of the box," as the company has claimed for years. "When I first began saying that Macs were less secure than Windows, everyone thought I was an idiot," says Miller. "So I had to prove it again and again and again."

In 2007 Miller became the first to hack the iPhone, using a flaw in its Safari browser to remotely gain control of the not-so-smart phone. Six months later he hacked a Macbook Air in two minutes at a competition in Vancouver. Last summer he revealed a method that allowed him to virally hijack the iPhone using text messages spread via a user's contact list.

Miller says his latest research doesn't aim to show off his elite hacking skills,most of which he learned over five years as a global network exploitation analyst for the National Security Agency. Instead, he wants to show just how easy it is to find chinks in the armor of commonly used software. Miller used a technique known as "dumb fuzzing" to find flaws. He ran the procedure more persistently than most hackers, leaving his fuzzing program to throw junk information at each target for three weeks before mining the data for exploitable flaws.

As for Apple, Miller says the company has learned to accept, if not appreciate, his work. He usually gives Apple weeks of notice before publicly describing its bugs. "They're always very polite," he says. "But I suspect they wish I didn't exist."

Read the full story at Forbes.com by Andy Greenberg

Updated:
Apple Patches Pwn2Own Bug

Tuesday, April 6, 2010

Your Boss may be watching you

CNN's T.J. Holmes talks with tech guru Mario Armstrong about being tracked in the workplace.

Tuesday, March 30, 2010

Apple delivers record monster security update

Apple today patched 92 vulnerabilities, a third of them critical, in a record update to its Leopard and Snow Leopard operating systems.

Security Update 2010-002 plugged 92 holes in the client and server editions of Mac OS X 10.5 and Mac OS X 10.6, breaking a record that has stood since March 2008 . The update dwarfed any released last year, when Apple 's largest patched 67 vulnerabilities .

More than 40% of the vulnerabilities patched today, 37 out of the 92, were accompanied by the phrase "may lead to arbitrary code execution," which is Apple's way of saying that a flaw is critical and could be used by attackers to hijack a Mac. Apple does not assign ratings or severity scores to the bugs it patches, unlike other major software makers, such as Microsoft and Oracle .

Read the full Computer World story

Download the patches from Apple:
Apple OS X 10.5.X users
Apple OS X 10.6.X users
Microsoft Windows Bonjour users