Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, 8 August 2012

Wired Writer gets Hacked Hard

If you haven't heard about this story, it worth a look. A Wired writer was hacked on Friday. His MacBook, iPhone, Twitter account, and GMail all taken over. The interesting part is that most of the hacks used social engineering to get enough information about his accounts to take them over. No password cracker or anything like that.

Monday, 9 July 2012

A place to report Phishing Scams

Internet IconPhishing scams seem to be an epidemic these days. Text messages seem to be just the latest way for crooks to SPAM us. But take heart, CERT has setup an e-mail address for reporting phishing URLs. Send an e-mail to phishing-report@us-cert.gov with the URL in the message. In my case, I seem to have repeatedly won Target.com gift cards!!! Woo hoo!



Your entry in our drawing WON you a FREE $1000 Target Giftcard enter XXX at www.target.com.ppdf.biz/ to claim it and we can ship it to you immediately


For the non-tech savy readers, if you look at the domain name, you will notice instead of it ending in target.com the URL actually ends in target.com.ppdf.biz. This, of course, is not a Target website and is most likely a crook trying to steal your credit card number and/or other information.



It would seem to me that given someone has to actually pay for the domain that law enforcement could follow the money and shutdown these sites quickly. But when I looked at the Internet Crime Complaint Center (IC3) and the FCC website for reporting similar information, filling out the forms was way too difficult. In addition, they wanted way too much information. My guess is these sites are for folks who have already been scammed. But its seems like in this case it would be better to focus on preventing crimes rather than on reporting on crimes that already happened.



For more information, see http://www.us-cert.gov/nav/report_phishing.html

Monday, 23 April 2012

OS X Mountain Lion Adds App Certificates



I found this story from MacWorld on the new certificate system that is being added to the next version of OS X. In essence, any application you wish to install and run on a Mac will need a certificate from Apple identifying the developer. Apple does not have to vet the app, but developers do need to get the certs to sign their apps with.



A few thoughts.

  • On the plus side of the ledger, this is intended to and should prevent a lot of malware. That is a good thing and should make for secure systems.

  • As long as Apple makes the process relatively inexpensive and easy to use, it should be good. Charging too much would, of course, be devastating to the platform.

  • However, I do wonder how well this will work if you are installing an application and your Internet connection is down. Or if you are on a plane without an Internet connection.

  • In Mountain Lion, you can still install unsigned applications by answering some security questions. So your computer is not totally locked down.

  • I do wonder if a more free market approach would be better. Allowing trusted 3rd parties to issue certificates would provide a feeling that Apple is not trying to control everything.

  • Not sure this help with browser based attacks which would seem more likely in the years to come.

Monday, 30 August 2010

Java Glassfish Security Annotations

Duke WavingHad to do a little research on setting up basic authentication on Glassfish v3. Here are the two best articles I ran across on the subject.







Tuesday, 23 March 2010

Upgrade Firefox to 3.6.2

Firefox LogoFirefox 3.6 has a serious security flaw that needs updating. From the menu, choose Help, then Check for Updates. That should get you the latest and greatest version of the browser.

Wednesday, 9 April 2008

AJAX Authentication

I'm starting another AJAX project at work. So as usual, my mind was wandering and I got to thinking about how do you do authentication in AJAX. I found this really good little write up:
http://roborant.info/main.do?entry=1331