turvallisuus.org
|
Digitoday / Tietoturva Digitoday - uusimmat uutisotsikot ICT-alalta Effi vaatii Arhinmäeltä: Vihellä piraattilaki poikki! Effille aiemmin armollinen Paavo Arhinmäki on järjestön viimeinen paras toivo piraattilain kaatamiseksi. Skimmaus hurjassa kasvussa Maksukorttien kopioinnit kasvoivat selvästi viime vuonna ja etenkin syksyllä, poliisin tilastot kertovat. Kiina laajentaa videovalvontaa Kiinan laaja videoseuranta terävöityy ja laajenee edelleen lähivuosina. Kameravalvonta digitalisoituu ja sen käyttö yleistyy myös sisämaassa. Chuck Norrisin vuoro kuolla Facebookissa Huijarit vetivät Chuck Norris -vivusta Facebookissa. Älä lankea tähän huijaukseen. Google panee käyttäjätiedot yhteen säkkiin Hakukoneyhtiö Google hylkää yli 60 eri yksityisyyssäännöstöään. Sen kaikkiin palveluihin tulee yksi yhteinen yksityisyydensuojapolitiikka. Google saa entistä helpommin selville käyttäjän kiinnostuksen kohteita. EU antaa satikutia tietomurtojen salailijoille Euroopan komission esittämät uusitut tietosuojasäännöt pyrkivät parantamaan kuluttajien turvaa internetissä. Yrityksille heilutetaan sekä keppiä että porkkanaa. Bottijahdissa jäljet johtivat Pietariin Ohjelmistoyhtiö Microsoft epäilee 31-vuotiasta venäläistä Kelihos-bottiverkon pyörittämisestä. Facebook näyttää kohta erilaiselta Loputkin Facebookin käyttäjät saavat Timelinen käyttöönsä lähiviikkoina. Aikaa tietojensa tarkistamiseen on seitsemän päivää. Pirate Bay tulostaa vaikka leikkiauton Piraattisivusto Pirate Bay on perustanut uuden tiedostoluokan. Sen kautta on tarkoitus jakaa tulostustiedostaja 3D-tulostimille. Suomen passi on rasite Megauploadin Kim Dotcomille Megauploadin perustaja ja internet-miljonääri Kim Dotcom ei pääse vapaalle jalalle takuita vastaan. Apple lipsautti väärennöksen App Storeen Applen portinvartijoilta pääsi läpi suosittua kuvasovellusta teeskennellyt sovellus. Yrityskauppa ennakoi turvallisempia tweettejä Twitter on ostanut haittaohjelmien torjuntaan erikoistuneen Dasientin. IPhone 4S ja iPad 2 murtuivat lopulta Laitteiden murtamiseen pätevät samat varoitukset kuin ennenkin. Google+ hyväksyy arskat ja reiskat Googlen sosiaaliyhteisö alkaa tunnistaa jäseniä heidän lempinimensä tai toisen nimensä mukaan. Automaatti ansoitettiin Iittalassa, Oulussa väärä hälytys Poliisin maanantaihin mahtui oikea skimmaustapaus Iittalassa, Oulussa automaatin käyttäjät huolestuivat turhaan. Schneier on Security A blog covering security and security technology. Password Sharing Among American Teenagers Interesting article from the New York Times on password sharing as a show of affection. "It's a sign of trust," Tiffany Carandang, a high school senior in San Francisco, said of the decision she and her boyfriend made several months ago to share passwords for e-mail and Facebook. "I have nothing to hide from him, and he has nothing to... Evidence on the Effectiveness of Terrorism Readers of this blog will know that I like the works of Max Abrams, and regularly blog them. He has a new paper (full paper behind paywall) in Defence and Peace Economics, 22:6 (2011), 583?94, "Does Terrorism Really Work? Evolution in the Conventional Wisdom since 9/11, Defence and Peace Economics": The basic narrative of bargaining theory predicts that, all else... Federal Judge Orders Defendant to Decrypt Laptop A U.S. federal judge has ordered a defendent to decrypt her laptop.... Supreme Court Rules that GPS Tracking Requires a Warrant The U.S Supreme Court has ruled that the police cannot attach a GPS tracking device to a car without a warrant. EDITED TO ADD (1/26): It seems I was wrong when I said that the ruling forces the police to get a warrant before placing a GPS tracking device on a car. The ruling is much more complicated and nuanced.... Research into an Information Security Risk Rating The NSF is funding research on giving organizations information-security risk ratings, similar to credit ratings for individuals: Existing risk management techniques are based on annual audits and only provide a snapshot of a partner's security posture. However, new vulnerabilities are discovered everyday and the industry needs a solution that enables a business to continuously monitor changing risk posture of all... Using Plant DNA for Authentication Turns out you can create unique signatures from plant DNA. The idea is to spray this stuff on military components in order to verify authentic items and detect counterfeits, similar to SmartWater. It's a good idea in theory, but my guess is that the security is not going to center around counterfeiting the plant DNA, but rather in subverting the... Authentication by "Cognitive Footprint" DARPA is funding research into new forms of biometrics that authenticate people as they use their computer: things like keystroke patterns, eye movements, mouse behavior, reading speed, and surfing and e-mail response behavior. The idea -- and I think this is a good one -- is that the computer can continuously authenticate people, and not just authenticate them once when... The Continued Militarization of the U.S. Police The state of Texas gets an armed patrol boat. I guess armed drones weren't enough for them.... The Onion on Facebook Funny news video on Facebook and the CIA.... Using False Alarms to Disable Security I wrote about this technique in Beyond Fear: Beginning Sunday evening, the robbers intentionally set off the gallery's alarm system several times without entering the building, according to police. The security staffers on duty, who investigated and found no disturbances, subsequently disabled at least one alarm. The burglars then entered through a balcony door.... Going Dark to Protest SOPA/PIPA Tomorrow, from 8 am to 8 pm EST, this site, Schneier on Security, is going on strike to protest SOPA and PIPA. In doing so, I'll be joining Wikipedia (in English), BoingBoing, WordPress, and many others. A list of participants, and HTML and JavaScript code for anyone who wants to participate, can be found here.... Tor Opsec Good operational security guide to Tor.... The Register - Security Biting the hand that feeds IT Students busted for hacking computers, changing grades 'Very bright kids' too bright for their own good Three high school juniors have been arrested after they devised a sophisticated hacking scheme to up their grades and make money selling quiz answers to their classmates.? Facebook flings clickjack spam lawsuit at ad-slingers Social network teams up with Washington State to hound marketing firm Facebook and US state of Washington have filed lawsuits against marketing firm Adscend Media over alleged clickjacking and spam practices, as the social networking giant finally gets tough with scammers operating on the site.? US lawmakers question Google over privacy policy Politicos ask if Chocolate Factory's new rules violate an FTC agreement Google is insisting that its new privacy policy will still give its users control, after criticism in a letter from US members of Congress.? Judges set timetable for McKinnon case resolution Pentagon hacking suspect has been waiting for 10 YEARS... Senior judges have set a timetable to speed up resolution in the long-running Gary McKinnon extradition case, effectively setting a deadline for the Home Office to respond to evidence that McKinnon is too infirm to withstand the stress of a US trial and likely imprisonment over alleged Pentagon hacking offences.? Microsoft exec says Safe Harbor framework is 'alive and well' Privacy critic: 'It's dead. We just forgot to bury it' CPDP Privacy advocates have expressed concern about Brussels' Commissioner Viviane Reding's decision to leave in place the Safe Harbour framework used by some companies to transfer data from Europe to the US.? Google emails Virgin Media subscribers ... about privacy Infuriated customers want to know how the Goog got their addresses Fuming Virgin Media customers have taken to the telco's forum to complain that their email addresses have been used by Google, instead of being kept private.? Blackhole crimeware kit drives web threat spike Report: Conficker also still causing mayhem Fake anti-virus scams are on the wane but drive-by-download threats have rocketed over the past year thanks to the hugely popular Blackhole crimeware kit, while Conficker remains prolific some three years after its release, according to Sophos.? Symantec's profits up in calm third quarter Growth in security and compliance keeps ship steady CEO Enrique Salem stands crisp and smart on the poop deck of the good ship Symantec, looking back at a straight course and ahead to more growth. It's a pretty unexciting third quarter story really.? Why O2 shared your mobile number with the world And why they'll probably do similar again O2 has been sharing customers' phone numbers with every website they visited, but O2 isn't the only offender - it's just the one that slipped up and got caught.? pcAnywhere let anyone anywhere inject code into PCs Symantec plugs holes in desktop remote-control tool Symantec is urging users to patch pcAnywhere, its remote control application, following the discovery of a brace of serious security flaws.? OpIreland hackers spank gov sites as 'Irish SOPA' nears Angry hacktivists land on Irish shores Anonymous took out several key Irish government websites last night and promised more disruption to come in retaliation for new SOPA-like legislation which it claimed would make it easier for copyright-holders to block access to file sharing and other sites in the country.? Pwn2Own 2012 touts bigger prizes, drops mobile hacks Make $60,000 with a few carefully injected bytes Organisers of security conference CanSecWest have changed the rules for the next outing of its Pwn2Own computer hacking contest.? O2 3G stops giving punters' mobile numbers to websites HTTP header blooper stamped out within hours after outcry After a flurry of complaints, O2 engineers appear to have shut off the proxy server quirk that leaked to websites the phone numbers of punters browsing the net on 3G connections.? Reding's 'right to be forgotten' bill polarises Euro biz world Rewriting data protection law in internet age EU Justice Commissioner Viviane Reding will imminently table a draft bill that will ? if passed in Parliament ? require internet firms to be upfront about the user data they hold.? Super-powered 'frankenmalware' strains detected in the wild Virus-worm crossbreeds will trash systems faster than ever before Viruses are accidentally infecting worms on victims? computers, creating super-powered strains of hybrid software nasties.? [CaRP] XML error: no element found at line 53 - Infosec Writers Latest Security Papers Papers submitted by security professionals are published on the site and archived for readers. Categories include cryptography, E-mail security, exploitation, firewalls, forensics, honeypots, IDS, malware & wireless security. Old School Newbie Guide circa 2000 This is a flashback paper written by the founder and creator of SWG, our original site. Later it changed ownership and direction and became ISW. To those that remember Raven, enjoy! This is in celebration of our 10 year anniversary at ISW! Analysis of Malicious Software Infections Kenneth Davis submits this paper on a study of Malicious Softwares. He discussed the threats and ways to help mitigate the risks associated. Malware in Information Security Jared Dukes submits this paper on Malware. He discusses the history of Malware as well as reasons one could become infected. DoS! Denial of Service Kevin Hattingh submits this educational paper on DoS. He includes a dmonstration as well as how it is being used in modern day attacks. An Analysis of the IDS Penetration Tool: Metasploit Josh Marquez writes this introductory paper on Metasploit. Experimental Review of IPSec Features to Enhance IP Security Shilpa Nandamuri writes this paper that discusses IPSEC, how it works and touches on IKE, AHs and ESP for those not familair with it. Cloud Computing – Storm Clouds or is it Smooth Flying? Cary Whitaker writes about the concerns of Cloud Computing and gives some great reasons to take it seriously. The Evolving World of Computer Security and Laws Jashua Garris writes about Information Security and laws, citing specific cases to demonstrate the importance of a solid security program. Web Access Management and Single Sign-On Dale Huggins takes a look at Single Sign On solutions for web aaplications. Reverse Honey Trap Aditya Sood and Rohit Bansal contribute with this great paper that looks into striking inside antivirus engines and analyzers. SecurityFocus News SecurityFocus is the most comprehensive and trusted source of security information on the Internet. We are a vendor-neutral site that provides objective, timely and comprehensive security information to all members of the security community, from end users, security hobbyists and network administrators to security consultants, IT Managers, CIOs and CSOs. News: Change in Focus Change in Focus News: Twitter attacker had proper credentials Twitter attacker had proper credentials News: PhotoDNA scans images for child abuse PhotoDNA scans images for child abuse >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 News: Conficker data highlights infected networks Conficker data highlights infected networks Brief: Google offers bounty on browser bugs Google offers bounty on browser bugs Brief: Cyberattacks from U.S. "greatest concern" Cyberattacks from U.S. "greatest concern" >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 Brief: Microsoft patches as fraudsters target IE flaw Microsoft patches as fraudsters target IE flaw Brief: Attack on IE 0-day refined by researchers Attack on IE 0-day refined by researchers News: Monster botnet held 800,000 people's details Monster botnet held 800,000 people's details >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 News: Google: 'no timetable' on China talks Google: 'no timetable' on China talks News: Latvian hacker tweets hard on banking whistle Latvian hacker tweets hard on banking whistle News: MS uses court order to take out Waledac botnet MS uses court order to take out Waledac botnet >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 Infocus: Enterprise Intrusion Analysis, Part One Enterprise Intrusion Analysis, Part One Infocus: Responding to a Brute Force SSH Attack Responding to a Brute Force SSH Attack Infocus: Data Recovery on Linux and ext3 Data Recovery on Linux and <i>ext3</i> >> Advertisement << Can you answer the ERP quiz? These 10 questions determine if your Enterprise RP rollout gets an A+. http://www.findtechinfo.com/as/acs?pl=781&ca=909 Dark Reading - All Stories Dark Reading is the premier online resource helping information security professionals manage the balance between protection and access. It offers breaking news and analysis on attacks, breaches and vulnerabilities, as well as strategies for protecting enterprise data. It also offers guidance on setting risk management and compliance policies. New Drive-By Spam Infects Those Who Open Email -- No Attachment Needed Getting infected just got a whole lot easier, researchers say The Mechanics Of Breach Notification Organizations need to know what constitutes a breach of identity data according to state laws and how to respond Security Careers: A Closer Look At Digital Investigations Security incident response and forensics are, at heart, people problems. Here are some tips for making the most of them Smartcards: Still A Smart Choice? Despite recent security compromises, smartcard technology still has high potential Study: The Aftermath Of A Breach New Ponemon-Experian study Hopping Aboard The Mobile Payment Bandwagon? Bring A Helmet Implementing mobile payment systems presents a high risk, high reward opportunity Six-Year-Old Breach Comes Back To Haunt Symantec Security firm warns users to halt use of pcAnywhere until it finishes patching it, but says older Norton products not at risk from previously 'inconclusive' 2006 security incident Hacktivists Turn To DNS Hijacking Coach, UFC fallvictim to attacks that redirect their Web traffic Database Password Storage Exposes Need For Better ID Management DreamHost and other password breaches show weaknesses in the way passwords are stored DNSSEC Error Caused NASA Website To Be Blocked Comcast’s new DNSSEC-based service detected improper signing of NASA site Looking Over The RIM And Into The Chasm What security folks need to learn from RIM's rapid and accelerating downfall... EU's More Stringent Data Privacy Proposal Poses Challenges For Businesses Proposed changes to data privacy laws in Europe have garnered mixed praise Videoconferencing Can Be The Bug In The Boardroom Recent research underscores that insecure video conferencing systems can allow hackers to listen into a company's confidential discussions. Firms should take steps to evaluate their systems and secure them Judge Rules In Favor Of Decryption A woman accused of real-estate fraud must turn in unencrypted copy of a hard drive, despite Fifth Amendment protest Microsoft Names Alleged Botnet Operator Behind Kelihos Russian suspect worked for antivirus and software development firms in Russia Business Continuity News Business continuity and disaster recovery news from around the world. Provided by Continuity Central, the international business continuity news and information portal. Can you trust the cloud mega-companies with critical aspects of your business... Google decision highlights a key risk of relying on public cloud providers for business continuity. David Honour comments. COSO issues risk appetite thought paper 'Enterprise Risk Management - Understanding and Communicating Risk Appetite.' UK businesses urged to plan for network traffic load during the Olympics Intergence offers five tips for protecting mission critical applications. 'Cyber Security Strategies: Achieving Cyber Resilience' New guidance document from the Information Security Forum. UK Climate Change Risk Assessment 700 potential impacts of climate change in a UK context examined. Disaster prevention to be at the heart of UN work for the next five years Pressing the world for a push on disaster prevention, UN Secretary-General, Ban Ki-moon has rolled out a 'Five Year Action Agenda.' Business continuity briefs Short news pieces. RSS by CARP |