Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Thursday, October 14, 2010

Facebook offers temporary log-ins for public computers

Facebook is launching one-time passwords in an effort to make it safer to log on to the social network from public computers.

It also claims the system will help prevent cyber-criminals accessing users' accounts.

Users need to text the words 'otp' to 32665 and they will be sent a temporary password that will expire after 20 minutes.

But security experts questioned whether the system was safe.

Continue reading the full at the BBC

Wednesday, August 25, 2010

So what has been going on with iTunes and PayPal?

"Users' experience suggests that there is some account cracking going on at the iTunes Store. But why, who and how?"

So what has been going on with iTunes and PayPal?


How to choose a secure password for your accounts
GRC Ultra High Security Password Generator

Saturday, December 5, 2009

Several Restaurants Sue Vendor for Unsecured Card Processor

"Seven restaurants have sued the maker of a bank card-processing system for failing to secure the product from a Romanian hacker who breached their systems.

The restaurants, located in Louisiana and Mississippi, filed a class-action suitagainst Georgia-based Radiant Systems for producing a point-of-sale (POS) system that they say was not compliant with payment card industry security standards and resulted in an undetermined number of customers having their debit and credit card numbers stolen.

The suit alleges that the system stored all the data embedded on the bank card magnetic stripe after the transaction was completed — a violation of industry security standards that made it a high-risk target for hackers.

Also named in the suit is Computer World, a Louisiana-based retailer, which sold and maintained Radiant’s Aloha POS system.

According to plaintiffs, Computer World’s technicians allegedly installed the remote-access program PCAnywhere on the systems to allow its technicians to fix technical problems from off-site. The only problem is, the company failed to secure the program. The suit alleges that the system was not up to date with software patches, and the PCAnywhere remote log-in and password that technicians used to access the POS systems was the same at every one of the 200 Louisiana locations where the system was installed. According to one of the plaintiffs who spoke with Threat Level, the default login was “administrator” and the password was “computer.”

As a result, a hacker, believed to be based in Romania, accessed the systems of at least 19 businesses through the PCAnywhere software, and possibly others plaintiffs say. "

Image courtesy California State Controller’s Office & Wired

Read the full story by Kim Zetter of Wired