Rafal Los posed the question recently in his blog: "am I too paranoid?"
The context is he was speaking about a Twitter statistics website that he found which requires your login credentials in order to provide capabilities beyond statistics. Being the good security-minded chap that he is he looked into what this widget will do for you if you provide your credentials. Here's what he found.
It will...
* Read Tweets from your timeline.
No worries here, everyone can do that.
* See who you follow and follow new people.
Okay to the see who you follow, that's public. ...wait, "follow new people"? Why? What makes it think I want to follow these people it auto-follows? Nope, don't like this. I would accept suggestions on who to follow though.
* Update your profile.
Huh? What for? What would it add? Don't like that. Rafal mentions he doesn't even let his marketing people do that. Heh, I don't have marketing people but if I did I might let them access it...well maybe.
* Post Tweets for you.
What are you going to post? Advertisements spamming ppl? That's get me fewer followers. Ah no, no you won't you lil widget, you won't be doing this.
* Reading direct messages.
Excuse me! Why? For what purpose?
There's no way I would want a widget like this to have complete access to my Twitter profile. Am I too paranoid like Rafal? Maybe but I think for good reason, well many reasons. One such reason is need to know principle. In my opinion, this widget does not need access to some of the areas it accesses. It's the same reason why I don't give out my social security number easily or without asking why they need it. At the DMV, sure, at a department store, nope.
So no Rafal, you aren't being too paranoid...you're being sensible, safe, smart.
Check out Rafal's blog, he writes some good stuff.
http://h30499.www3.hp.com/t5/user/viewprofilepage/user-id/604516
Entry related to this topic:
http://h30499.www3.hp.com/t5/Following-the-White-Rabbit-A/Am-I-Just-Too-Paranoid-Federating-Identity-by-Twitter/ba-p/2414931
June 27, 2011
June 24, 2011
Get your milk, bread, beer, and ID theft insurance from one place...huh?
"Honey on the way home from work pick up some milk, bread, bananas, pound of hamburger, and identity theft insurance." "Wait, what?"
Bet you never heard that one before. So I was in Kroger(1) the other day picking up some of the staples and as I was walking past the end of an aisle I saw something that stopped me in my tracks. A brochure advertising identity (ID) theft protection.
My jaw dropped. I mean, come one, who goes to a grocery store to pick up ID theft protection? Not the place I would expect it.
A division of Kroger called Kroger Personal Finance offers something PrivacyGuard. Essentially it's a monitoring service which will watch your credit cards and credit information, alerting you if any anonmalies are detected. It will also alert you when someone requests your credit report.
Unfortunately it won't alert you when you are low on milk or bread. Maybe that's another service Kroger should offer: Kroger Food Pantry Monitoring. ;) Makes a little more sense than ID theft insurance.
(1) This blog posting is in no way endorsing any brand or product.
Bet you never heard that one before. So I was in Kroger(1) the other day picking up some of the staples and as I was walking past the end of an aisle I saw something that stopped me in my tracks. A brochure advertising identity (ID) theft protection.

My jaw dropped. I mean, come one, who goes to a grocery store to pick up ID theft protection? Not the place I would expect it.
A division of Kroger called Kroger Personal Finance offers something PrivacyGuard. Essentially it's a monitoring service which will watch your credit cards and credit information, alerting you if any anonmalies are detected. It will also alert you when someone requests your credit report.
Unfortunately it won't alert you when you are low on milk or bread. Maybe that's another service Kroger should offer: Kroger Food Pantry Monitoring. ;) Makes a little more sense than ID theft insurance.
(1) This blog posting is in no way endorsing any brand or product.
April 3, 2011
Major breach exposed customers of major brands
There's been a data breach (article 1, article 2) at one of the largest marketing services companies around and your email might have been exposed. The breach occurred at a company called Epsilon which handles email communications for many big brands such as Capital One, Citi, Disney, etc. Their website boasts over 2,500 clients including 7 Fortune 10 companies.
At this time the list includes about 15 companies but it's been growing, so even if you've not done business with one of the companies listed below, one that you have done business with might have been exposed.
Criminals are using the emails to send malicious software (in the form of PDFs or other documents) and/or links to websites that lead to malicious software and/or phishing scams. Be alert. Here's the list of companies confirmed to have been exposed at this time (some have links to notifications):
UPDATE 06-APR-2011 (LIST UPDATED):
1800-Flowers
Abe Books
AbeBooks
Air Miles CA
Ameriprise Financial
Barclays Bank
Beachbody
Bebe Stores Inc.
Benefit Cosmetics
BestBuy
Brookstone
Capital One
Charter Communications (Charter.com)
Citibank
City Market
Dillons
Disney
HSN (Home Shopping Network)
Eddie Bauer
Eurosport/Soccer.com
Food 4 Less
Fred Meyer
Fry's
Hilton Worldwide
JP Morgan Chase
Kroger
Jay C
King Soopers
Kroger
LL Bean Visa Card
Lacoste
Marriott International
Marriott Rewards
McKinsey & Company
Moneygram
New York & Company
QFC
Ralphs
Red Roof Inns Inc.
Ritz-Carlton
TiVo
Robert Half
Smith Brands
TD Ameritrade
TIAA-CREF
Target
The College Board
The Home Shopping Network
TiVo
US Bank
Verizon
Walgreens
World Financial Network National Bank

At this time the list includes about 15 companies but it's been growing, so even if you've not done business with one of the companies listed below, one that you have done business with might have been exposed.
Criminals are using the emails to send malicious software (in the form of PDFs or other documents) and/or links to websites that lead to malicious software and/or phishing scams. Be alert. Here's the list of companies confirmed to have been exposed at this time (some have links to notifications):
UPDATE 06-APR-2011 (LIST UPDATED):
1800-Flowers
Abe Books
AbeBooks
Air Miles CA
Ameriprise Financial
Barclays Bank
Beachbody
Bebe Stores Inc.
Benefit Cosmetics
BestBuy
Brookstone
Capital One
Charter Communications (Charter.com)
Citibank
City Market
Dillons
Disney
HSN (Home Shopping Network)
Eddie Bauer
Eurosport/Soccer.com
Food 4 Less
Fred Meyer
Fry's
Hilton Worldwide
JP Morgan Chase
Kroger
Jay C
King Soopers
Kroger
LL Bean Visa Card
Lacoste
Marriott International
Marriott Rewards
McKinsey & Company
Moneygram
New York & Company
QFC
Ralphs
Red Roof Inns Inc.
Ritz-Carlton
TiVo
Robert Half
Smith Brands
TD Ameritrade
TIAA-CREF
Target
The College Board
The Home Shopping Network
TiVo
US Bank
Verizon
Walgreens
World Financial Network National Bank
April 2, 2011
NSA to investigate NASDAQ hack

Several sources are reporting that the National Security Agency (NSA) is looking into the breach of the company that runs NASDAQ experienced back in October of 2010.
Bloomberg News interviewed former head of U.S. counterintelligence in the Bush and Obama administrations, Joel Brenner, who stated “By bringing in the NSA, that means they think they’re either dealing with a state-sponsored attack, or it’s an extraordinarily capable criminal organization.”
It's being reported that other U.S. Federal Govt agencies (FBI, Secret Service) are assisting as well.

Kim Zetter (@KimZetter) over at Wired Magazine has a good article on this topic:
http://www.wired.com/threatlevel/2011/03/nsa-investigates-nasdaq-hack/
Labels:
Counterintelligence,
Data Breaches,
FBI,
Financial,
NSA,
Secret Service,
Stocks,
US Federal Govt
Happy Birthday Portable PC
April 3, 2011: On this day 30 years ago something occurred in the PC industry that started what I'll call a revolution: the portable PC was introduced. In 1981 journalist and book author Adam Osborne released the 24 pound Osborne 1 computer. The machine was state of the art back then with a 5-inch CRT, disk drives that stored 102KB of data, 64KB of RAM, and a full size keyboard. It could even fit under the seat on a plane. But it was heavy and could not be used without plugging into AC socket; it did not have a battery.

An interesting piece of history is that one of the co-designers, Lee Felsenstein, theorized that the concept might have been borrowed from a couple of Apple employees who failed to sell the idea to Steve Jobs.
More information about the Osborne 1 can be found here.
Happy Birthday Portable PC
An interesting piece of history is that one of the co-designers, Lee Felsenstein, theorized that the concept might have been borrowed from a couple of Apple employees who failed to sell the idea to Steve Jobs.
More information about the Osborne 1 can be found here.
Happy Birthday Portable PC
March 9, 2011
Malware targeting Blackberry's
According to Trend Micro, a ZeuS banking trojan is targeting Blackberry mobile devices. Previously ZeuS variants targeting only mobile devices running Symbian and Windows Mobile had been spotted.
This story just helps bolster the point that malware's growth will occur in the mobile device world. Strap in your seatbelts, we're in for a rough ride!
http://www.finextra.com/news/fullstory.aspx?newsitemid=22336
February 9, 2011
Great Cleveland Security Event: BSidesCleveland
I wanted to direct your attention to a great security event being held in Cleveland next week: BSidesCleveland. It's a one-day event on Friday February 18, 2011 filled with interesting speakers and topics and great opportunities to network with your peers.
A local security group that I founded, the Northeast Ohio Information Security Forum, is one of the sponsors. The other local sponsor is SecureState.
Seating is limited and to if you don't have a ticket you are out of luck because it's sold out. You can still follow the goings on there via Twitter @BSidesCLE.
You can find out more about BSidesCleveland here:
http://www.securitybsides.com/w/page/27427415/BSidesCleveland

A local security group that I founded, the Northeast Ohio Information Security Forum, is one of the sponsors. The other local sponsor is SecureState.
Seating is limited and to if you don't have a ticket you are out of luck because it's sold out. You can still follow the goings on there via Twitter @BSidesCLE.
You can find out more about BSidesCleveland here:
http://www.securitybsides.com/w/page/27427415/BSidesCleveland
November 6, 2010
HTTP DDOS May Be in Your Website's Future
I found some interesting research work recently. Attackers have a new technique that can be used against your websites: HTTP DDOS.
Researcher by Wong Onn Chee discovered a way to cause a website to be slow and even take it down via a technique where POSTs are sent to a website slowly causing gridlocks the connection. It's similar to the Slowloris HTTP DDOS attack by RSnake, however this slow POST attack can't be mitigated by load-balancers like the Slowloris one can.
Check it out:
http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=228000532
Researcher by Wong Onn Chee discovered a way to cause a website to be slow and even take it down via a technique where POSTs are sent to a website slowly causing gridlocks the connection. It's similar to the Slowloris HTTP DDOS attack by RSnake, however this slow POST attack can't be mitigated by load-balancers like the Slowloris one can.
Check it out:
http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=228000532
August 24, 2010
Malware authors have their own con now, MalCon
Interested in WRITING malware? Go to MalCon.

Heh. I've heard it all. Now the malware authors have their very own conference where they can learn and teach about writing malware. Their website claims to bring together "Malware and Information Security Researchers from across the globe to share key research insights into building the next generation malwares." Okayyyyy.
I'm not sure whether this is a hoax or legit but according to Brian Krebs of Krebs on Security fame it's legit, or at least he spoke with the organizer of the event about it. The word is that Bruce Schneier is one of the leading speakers. This is interesting and seems to lend credence to its legitimacy.
Not sure who will be attending but my guess at the very least there will be a few LE and government security types "hanging" around this conference.
Heh. I've heard it all. Now the malware authors have their very own conference where they can learn and teach about writing malware. Their website claims to bring together "Malware and Information Security Researchers from across the globe to share key research insights into building the next generation malwares." Okayyyyy.
I'm not sure whether this is a hoax or legit but according to Brian Krebs of Krebs on Security fame it's legit, or at least he spoke with the organizer of the event about it. The word is that Bruce Schneier is one of the leading speakers. This is interesting and seems to lend credence to its legitimacy.
Not sure who will be attending but my guess at the very least there will be a few LE and government security types "hanging" around this conference.
August 7, 2010
Google CEO says no anonymity on future Internet
Google CEO Eric Schmidt stated in a talk at the Techonomy conference in Lake Tahoe that 'true transparency and no anonymity' are required to combat identity theft. He said the increase of information generated every day has helped social interaction but created a condition that helps identity theft thieves. He said there needs to be a verified way to identify people and that Governments will demand it.
My concern would be the procedures and policies surrounding the protection and use of this identity information. The information will need to be protected and how it will be accessed will be critical to whether the system is successful. If run poorly it could actually increase identity theft cases.
See more about the speech here: http://www.thinq.co.uk/2010/8/5/no-anonymity-future-web-says-google-ceo/
Subscribe to:
Posts (Atom)