Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Hacker Disables More Than 100 Cars Remotely
  • Five days of camp Chaos, or hacking from a tent
  • Site Leaking Unlisted(and other restricted) Phone Number Addresses
  • Three Ways to Fight Immunity
  • Third party content strikes again
  • 56 Arrested in DarkMarket Sting, Says FBI
  • Passport applicant finds massive privacy breach

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

attacker

Verizon: Data Breaches Getting More Sophisticated

Submitted by MacRonin on December 10, 2009 - 5:24pm
  • attacker
  • bank
  • Companies
  • Cryptography
  • Data Breach
  • Databases
  • Exploits
  • Hmmm
  • Infrastructure
  • Privacy
  • Quotation
  • Remember
  • Reports
  • Security
  • Verizon
  • Verizon

Verizon: Data Breaches Getting More Sophisticated: Via Threat Level.

Methods of stealing data are becoming increasingly sophisticated, but attackers are still gaining initial access to networks through known, preventable vulnerabilities, according to a report released by Verizon Business on Wednesday.

“Attacks are getting more sophisticated and more difficult to prevent,” said Wade Baker, research and intelligence principal for Verizon Business’s RISK Team, in an interview. “The attackers still usually get in the network through some relatively mundane attacks. But once they’re in, they’re getting more and more adept at getting the data they want and getting it effectively and silently. And we seem to be on a plateau in terms of our ability to detect [them].”

For example, while companies have been expanding their use of encryption to protect bank card data in transit and in storage, hackers have begun to use RAM scrapers to grab data during the few seconds it’s unencrypted and transactions are being authorized. [ Read more ... ]

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

"Evil Maid" Attacks on Encrypted Hard Drives

Submitted by MacRonin on October 23, 2009 - 8:19am
  • Activists
  • Alert
  • attacker
  • Cryptography
  • encryption
  • Exploits
  • Hmmm
  • Maid
  • Person Career
  • Person Travel
  • Privacy
  • Remember
  • Security

"Evil Maid" Attacks on Encrypted Hard Drives: Via Schneier on Security.

Earlier this month, Joanna Rutkowska implemented the "evil maid" attack against TrueCrypt. The same kind of attack should work against any whole-disk encryption, including PGP Disk and BitLocker. Basically, the attack works like this:

Step 1: Attacker gains access to your shut-down computer and boots it from a separate volume. The attacker writes a hacked bootloader onto your system, then shuts it down.

Step 2: You boot your computer using the attacker's hacked bootloader, entering your encryption key. Once the disk is unlocked, the hacked bootloader does its mischief. It might install malware to capture the key and send it over the Internet somewhere, or store it in some location on the disk to be retrieved later, or whatever. [ Read more ... ]

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Spoofed Cell Phone Texts Post Malware Threat

Submitted by MacRonin on July 31, 2009 - 1:31am
  • Alert
  • attacker
  • Company Technology
  • Exploits
  • GSM
  • Hmmm
  • How-To
  • Infrastructure
  • MMS
  • Person Career
  • Privacy
  • Quotation
  • Scams
  • Security
  • SMS
  • Telecommunications
  • Wireless

Spoofed Cell Phone Texts Post Malware Threat: Via Threat Level.

LAS VEGAS — Researchers at Black Hat showed how to send spoofed messages to mobile phones that appear to be messages delivered by the user’s mobile carrier.

The hack allows an attacker to send the messages directly from the attacker’s phone to the recipient, bypassing the carrier’s server and therefore any protections the carriers have in place to block spoofed or otherwise suspicious messages.

The attack targets Multimedia Messaging Service (MMS) on GSM networks and could trick users into installing malicious code masquerading as a software update from the carrier or clicking on a malicious link.

Zane Lackey from ISEC Partners and independent researcher Luis Miras discussed how they set up a system to capture the header information in text messages, then used modified headers to send their own specially designed messages to phones on GSM networks.

They were able to spoof messages from any sender, including trusted administrative messages that theoretically only a carrier would send. In the latter case, the messages appear to come from 611, the number carriers use to send out alerts, update notifications and other messages. [ Read more ... ]

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Vulnerabilities Allow Attacker to Impersonate Any Website

Submitted by MacRonin on July 29, 2009 - 11:18pm
  • Alert
  • attacker
  • Cryptography
  • Exploits
  • Hmmm
  • ID
  • Infrastructure
  • Moxie Marlinspike
  • Person Career
  • Privacy
  • Quotation
  • Scams
  • Security

Vulnerabilities Allow Attacker to Impersonate Any Website: Via Threat Level.

LAS VEGAS — Two researchers examining the processes for issuing web certificates have uncovered vulnerabilities that would allow an attacker to masquerade as any website and trick the user into providing him with sensitive communications.

Normally when a user visits a secure website, such as Bank of America, Paypal or Ebay, the browser examines the website’s certificate to verify its authenticity.

However, IOActive researcher Dan Kaminsky and independent researcher Moxie Marlinspike, working separately, presented nearly identical findings at the Black Hat security conference Wednesday that demonstrated how an attacker can legitimately obtain a certificate with a special character in the domain name that would fool nearly all popular browsers into believing an attacker is whichever site he wants to be.

The problem occurs in the way that browsers implement Secure Socket Layer communications. [ Read more ... ]

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Microsoft probes possible IE 7 phishing hole | CNET News.com

Submitted by MacRonin on March 20, 2007 - 1:36pm
  • Alert
  • attacker
  • Aviv Raff
  • Exploits
  • Microsoft
  • Privacy
  • Security
  • Software
  • Windows

Microsoft probes possible IE 7 phishing hole | CNET News.com: "An attacker can use an error message displayed by the latest Microsoft browser to send Web surfers to malicious Web sites that will display with the address of a trusted site, such as a bank, Aviv Raff, a developer in Israel, wrote on his Web site. Raff included an example where the error message directs the Web surfer to a site of his choice." [ Read more ... ]

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • In Bid to Sway Sales, Cameras Track Shoppers
  • Unprecedented 25-Year Sentence Sought for TJX Hacker
  • EFF Appeals Dismissal of Warrantless Wiretapping Case
  • Viacom Makes Its Case Against Yesterday's YouTube
  • Obama supports Senators draft plan to rework U.S. immigration policy - Includes National Biometric ID card for all.
  • Domain Names Can't Defend Themselves
  • Hacker Disables More Than 100 Cars Remotely
  • Judges Approves $9.5 Million Facebook ‘Beacon’ Accord
  • Hooking Up The Big Brother Machine... And Fighting It
  • Court: State Can Dump Non-Sex Offenders Into Registry
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.