Sunday, November 29, 2015

Jeff Kell Obituary

I worked with Jeff for over 20 years.  He will be missed.

Wednesday, November 25, 2015

"eDellRoot2," Another Dell Cert Found

Another certificate has been found issued by Dell on some of its computers that would allow the bad guys to "sniff" your surfing.

FAA Pushing Voluntary Drone Registration

Register your unmanned aircraft (less that 55 lbs) with the FAA for the stability and security of the US Airways.

Tuesday, November 24, 2015

Dell Responds to "eDellRoot"

A "Sorry" and instructions on how to remove the bad certificate.  They will issue a software update Nov 24 to automatically remove it.

Monday, November 23, 2015

Dell's "SuperFish" Certificate Error

Dell has a self signed certificate that is accepted and can be easily used by malware that might be installed on a PC.

Nanophotonics - The Power of White Lasers

Could allow for the implementation of LiFi, network connectivity over indoor lighting.

Apple, Google, Twitter, Facebook, and Others Say We Need Strong Encryption

Big companies seem to agree that government backdoors could be exploited by the bad guys and if they know about the backdoor they will just use another layer of encryption.

Saturday, November 21, 2015

Windows 10 Virtual Desktops

I have found the virtual desktops on OS X to be vital to my usage of a laptop, Windows 10 has a similar technology.

TrueCrypt Passes Another Audit

A German security firm audited TrueCrypt and found it "safe to use."

How Covert Channels Drain Android's Battery Life

MIT investigates how many popular apps, even when told not to communicate externally, use covert channels to transfer information about what you are doing.

Thursday, November 19, 2015

Comcast Leaking Names and Locations of XfinityWiFi Customers

Your Comcast-provided XfinityWiFi router may be offering WiFi to other Xfinity customers in the area.  That services seems to be leaking real names and locations to search engines.

Zero Day Exploit Cost Chart

Wired is reporting on the costs of exploits from the firm Zerodium.  WordPress and the like are the cheapest.

BadBarCode - Hacking with Bar Codes

A researcher has shown how to hack vulnerable apps using embedded special control characters.

Wednesday, November 18, 2015

Freeing up space with Google Photos

Soon the Google Photo App will suggest photos you can delete from your device (because they've been uploaded to Google) and the Google Photo Site will suggest "downgrading" the quality of your photos to save space.

Google+ now focusing on Collections and Communities

New focus, new "home stream," new look.  Google is trying to get you to use G+ as some combination of Reddit and Facebook.

Monday, November 16, 2015

T. Cook says no iOS/OS X convergence

So it seems that the iPad Pro v2 and derivatives wont ever run OS X.  I seem to remember S. Jobs saying no one needs a stylus as well.

Javascript flaw endangers Android Chrome App

A new zero day found in Chrome for Android could allow full access to the bad guys by just visiting a malicious site.

Saturday, November 14, 2015

You can't hear it, but you phone could be talking to your tablet and their both tracking you...

Now it appears that ads, running on two different devices, may be able to emit a sound at a frequency "beyond human hearing" to "pair" with each other in an effort to better track you.

Thursday, November 12, 2015

Windows 10 November Update

Microsoft will soon release a large update for Windows 10 including fixes and new (mostly enterprise friendly) features.  In the Windows NT days this would be Service Pack 1.

Wednesday, November 11, 2015

Tuesday, November 10, 2015

Adobe November Patch Tuesday

Adobe has released an updated version of Flash that patches 17 vulnerabilities.  If you use Flash, patch now.  Windows 10 and Chrome automatically patch Flash.

Microsoft November Patch Tuesday

There are several critical vulnerabilities including ones that affect Internet Explorer and Edge (the new Windows 10 browser.)  Make sure to patch your Microsoft products ASAP.

List of 590k Comcast Usernames and Password found.

A security researcher found almost 600000 usernames and passwords for sale on the Dark Web.  Comcast says it wasn't a breach, but better to reset your password just in case.

Monday, November 9, 2015

Website Ransomware

A new Linux malware scans for vulnerable sites (bad plugins) encrypts files (php, txt, html, etc.)  and demands payment to get them back.

Thursday, November 5, 2015

New Ransomware Will Post Your Dirty Laundry

A new version of the Crypto* malware will encrypt your stuff and post your sensitive files if you don't pay.

Don't get your Android Apps from 3rd Party Stores

Over 20000 "trojanized" apps that will "root" your device and steal your data.