Categories
Uncategorized

Summer (in)Security 2013

I return from Holiday and am catching up on security news.  I’ll update this thread as the day and season proceeds.  Stay Frosty. :shank:

 

Microsoft hijacks domains in attempted botnet takedown.  The problem here, is how disruptive this effort was and the security researchers it screwed in the process.

 

NSA is Balls Deep in 100% Verizon call monitoring and far beyond.  Image attached is from EFF article.  Shit is out of any sort of logic or reasonable action, by our Gov’t Overlords.  Thank you Mr Snowden, for peeling away the veneer of privacy bluffs.

 

In the UK, A Bank lost 74 laptops, over 6000 accounts and 20000 user records.  Asset Manage, much? Guess not.

 

Personal experience:  Apple sessions can be hijacked.  Unless a friend’s kid grabbed my phone and somehow guessed my iTunes password, I saw a ‘Blackjack’ program downloaded to my phone while on Holiday.  I deleted it to see some mandarin text show for the program description.  I was unable to report the program as a security exploit.

So all is not flawless in the land of Apple, as the same for Android devices.  Like kernel flagging level exploits

 

In a sudo-humorous result of the NSA sniffing, Cloud Storage is just about as insecure (business especially) as we feared.

 

So I guess the EU wants to behead ‘Hackers’?  How else can you increase the penalties?

 

Back on the global auditing of the internet by the US, I’d advise joining Mozilla and friends in signing the petition against the NSA auditing.

Attached Thumbnails

  • nsa.jpg