Tag: security
-
Bypassing WordPress / Jetpack's "Prove your humanity:" CAPTCHA
Popular WordPress plugin Jetpack provides a CAPTCHA whose sole purpose seems to be to frustrate humans. It does nothing to stop bots, as Dan demonstrates with a browser plugin that circumvents it.
-
Security Breaches Don't Affect Stock Price
Security Breaches Don't Affect Stock Price - Schneier on Security (schneier.com) false Interesting research: "Long-term market implications of data breaches, not," by Russell Lange and Eric W. Burger. Abstract: This report assesses the impact disclosure of data breaches has on the total returns and volatility of the affected companies' stock, with a focus on the …
-
I'm harvesting credit card numbers and passwords from your site. Here's how.
I’m harvesting credit card numbers and passwords from your site. Here’s how. (hackernoon.com) false
It’s been a frantic week of security scares — it seems like every day there’s a new vulnerability. It’s been a real struggle for me personally to pretend like I understand what’s going on when asked about it by family … -
Secure Messaging Apps Comparison
SecureMessagingApps.com
This site maintains a table cross-referencing the most popular "secure" messaging apps (WhatsApp, Signal, Skype etc.) against their security features, so that you can make an informed decision.
The tl;dr is, of course, what I've been saying all along: use Signal! (at least until Riot is more mature...) -
"I Forgot My PIN": An Epic Tale of Losing $30,000 in Bitcoin
In January 2016, I spent $3,000 to buy 7.4 bitcoins. At the time, it seemed an entirely worthwhile thing to do. I had recently started working as a research director at the Institute for the Future’s Blockchain Futures Lab, and I wanted firsthand experience with bitcoin, a cryptocurrency that uses a blockchain to record transactions …
-
A hacker stole $31M of Ether - how it happened and what it means for Ethereum
Yesterday, a hacker pulled off the second biggest heist in the history of digital currencies.
Around 12:00 PST, an unknown attacker exploited a critical flaw in the Parity multi-signature wallet on the Ethereum network, draining three massive wallets of over $31,000,000 worth of Ether in a matter of minutes. Given a couple more hours, the hacker … -
Password Rules Are Bullshit
Of the many, many, many bad things about passwords, you know what the worst is? Password rules.
If we don't solve the password problem for users in my lifetime I am gonna haunt you from beyond the grave as a ghost pic.twitter.com/Tf9EnwgoZv
— Jeff Atwood (@codinghorror) August 11, 2015
Let this pledge be duly … -
Let them paste passwords
One of the things people often tweet to us @ncsc are examples of websites which prevent you pasting in a password. Why do websites do this? The debate has raged - with most commentators raging how annoying it is.
So why do organisations do this? Often no reason is given, but when one is, that reason … -
A Russian Slot Machine Hack Is Costing Casinos Big Time
In early June 2014, accountants at the Lumiere Place Casino in St. Louis noticed that several of their slot machines had—just for a couple of days—gone haywire. The government-approved software that powers such machines gives the house a fixed mathematical edge, so that casinos can be certain of how much they’ll earn over the long … -
Defeating Quantum Algorithms with Hash Functions
In this post I’ll explain why quantum computers are useless to find hash function collisions, and how we can leverage this powerlessness to build post-quantum signature schemes. I’ll then describe a quantum computing model that you can try at home, and one where hash function collisions are easy to find...
JP Aumasson (Kudelsi Security) -
TLS 1.3 FTW
In common slang, FTW is an acronym "for the win" and while that's appropriate here, I think a better expansion is "for the world."
We're pleased to announce that we have sponsored the development of TLS 1.3 in OpenSSL. As it is one of the most widely-used TLS libraries, it is a good investment for the … -
evilpass
Checks how strong your user's password is via questionably ethical means.
Drew DeVault -
Against DNSSEC
All secure crypto on the Internet assumes that the DNS lookup from names to IP addresses are insecure. Securing those DNS lookups therefore enables no meaningful security. DNSSEC does make some attacks against insecure sites harder. But it doesn’t make those attacks infeasible, so sites still need to adopt secure transports like TLS. With TLS …
-
Troy Hunt: HTTPS adoption has reached the tipping point
That's it - I'm calling it - HTTPS adoption has now reached the moment of critical mass where it's gathering enough momentum that it will very shortly become "the norm" rather than the exception it so frequently was in the past. In just the last few months, there's been some really significant things happen that …
-
NISTs new password rules what you need to know
It’s no secret. We’re really bad at passwords. Nevertheless, they aren’t going away any time soon.
With so many websites and online applications requiring us to create accounts and think up passwords in a hurry, it’s no wonder so many of us struggle to follow the advice of so-called password security experts.
At the same time, the …








