Sunday, November 29, 2015

Jeff Kell Obituary

I worked with Jeff for over 20 years.  He will be missed.

Wednesday, November 25, 2015

"eDellRoot2," Another Dell Cert Found

Another certificate has been found issued by Dell on some of its computers that would allow the bad guys to "sniff" your surfing.

FAA Pushing Voluntary Drone Registration

Register your unmanned aircraft (less that 55 lbs) with the FAA for the stability and security of the US Airways.

Malware Planted at Hilton Hotels, Check Your Credit Card Statements

If you've stayed at a Hilton recently, time to review your CC statements and see what Hilton is doing to protect you.

Tuesday, November 24, 2015

Dell Responds to "eDellRoot"

A "Sorry" and instructions on how to remove the bad certificate.  They will issue a software update Nov 24 to automatically remove it.

Wordpress.com No Longer Running "WordPress Interface"

The interface to the hosted version of WordPress has been rewritten "from the ground up." 

Monday, November 23, 2015

Dell's "SuperFish" Certificate Error

Dell has a self signed certificate that is accepted and can be easily used by malware that might be installed on a PC.

Nanophotonics - The Power of White Lasers

Could allow for the implementation of LiFi, network connectivity over indoor lighting.

Apple, Google, Twitter, Facebook, and Others Say We Need Strong Encryption

Big companies seem to agree that government backdoors could be exploited by the bad guys and if they know about the backdoor they will just use another layer of encryption.

Saturday, November 21, 2015

Windows 10 Virtual Desktops

I have found the virtual desktops on OS X to be vital to my usage of a laptop, Windows 10 has a similar technology.

New Versions of Nmap and Wireshark

Nmap has been updated to version 7 while Wireshark is now at version 2.

TrueCrypt Passes Another Audit

A German security firm audited TrueCrypt and found it "safe to use."

Thursday, November 19, 2015

Amazon Enables Two Factor Authentication

You can now secure your Amazon browsing with TFA.

Comcast Leaking Names and Locations of XfinityWiFi Customers

Your Comcast-provided XfinityWiFi router may be offering WiFi to other Xfinity customers in the area.  That services seems to be leaking real names and locations to search engines.

Zero Day Exploit Cost Chart

Wired is reporting on the costs of exploits from the firm Zerodium.  WordPress and the like are the cheapest.

BadBarCode - Hacking with Bar Codes

A researcher has shown how to hack vulnerable apps using embedded special control characters.

Wednesday, November 18, 2015

Freeing up space with Google Photos

Soon the Google Photo App will suggest photos you can delete from your device (because they've been uploaded to Google) and the Google Photo Site will suggest "downgrading" the quality of your photos to save space.

Google+ now focusing on Collections and Communities

New focus, new "home stream," new look.  Google is trying to get you to use G+ as some combination of Reddit and Facebook.

VirusTotal now accepts Android and OS X Malware

The largest malware sandbox now can handle both Android and OS X malware samples.

Monday, November 16, 2015

Saturday, November 14, 2015

Linked In app may be pilfering your data even though you said no

A user on Reddit (granted not the WSJ) details on efforts to keep contact info from the Linked In App.

You can't hear it, but you phone could be talking to your tablet and their both tracking you...

Now it appears that ads, running on two different devices, may be able to emit a sound at a frequency "beyond human hearing" to "pair" with each other in an effort to better track you.

Thursday, November 12, 2015

Windows 10 November Update

Microsoft will soon release a large update for Windows 10 including fixes and new (mostly enterprise friendly) features.  In the Windows NT days this would be Service Pack 1.

Wednesday, November 11, 2015

Tuesday, November 10, 2015

Adobe November Patch Tuesday

Adobe has released an updated version of Flash that patches 17 vulnerabilities.  If you use Flash, patch now.  Windows 10 and Chrome automatically patch Flash.

Microsoft November Patch Tuesday

There are several critical vulnerabilities including ones that affect Internet Explorer and Edge (the new Windows 10 browser.)  Make sure to patch your Microsoft products ASAP.

List of 590k Comcast Usernames and Password found.

A security researcher found almost 600000 usernames and passwords for sale on the Dark Web.  Comcast says it wasn't a breach, but better to reset your password just in case.

Monday, November 9, 2015

Website Ransomware

A new Linux malware scans for vulnerable sites (bad plugins) encrypts files (php, txt, html, etc.)  and demands payment to get them back.

Thursday, November 5, 2015

New OmniRAT Multi Platform Malware for $25

Avast has found a cheap malware that can give you control over Android, Mac, Windows, and Linux.

New Ransomware Will Post Your Dirty Laundry

A new version of the Crypto* malware will encrypt your stuff and post your sensitive files if you don't pay.

Don't get your Android Apps from 3rd Party Stores

Over 20000 "trojanized" apps that will "root" your device and steal your data.