Brian Krebs has an interesting article up, http://krebsonsecurity.com/2014/10/silk-road-lawyers-poke-holes-in-fbis-story/, about the trial of alleged leader of Silk Road.
Short version, government's explanation for how they found the hidden servers appears to be BS.
This seems like they are hiding real way & means that they discovered the information.
Which, though IANAL, isn't legal as I understand it, in US Trials, there is a step called "Discovery" see http://www.americanbar.org/groups/public_education/resources/law_related_education_network/how_courts_work/discovery.html & http://en.wikipedia.org/wiki/Civil_discovery_under_United_States_federal_law.
So unlike TV or Movie Courtroom drama, there isn't surprise evidence introduced in the middle of the trial.
There are several reasons why information isn't supposed to be hidden during Discovery.
Discovery reduces wasting time, Judges generally have more cases than they can get to in any given time period, so as a practical matter, parties are encouraged to settle before Court date.
It also reduces some types of false testimony & evidence, or at least makes it easier to illuminate that it is occurring.
Esports & Computer Security Blog. For SC2 tournaments see clocks immediately below. Starts with Korean time at upper left, moves west around the world till you end with PDT/PST clock for Anaheim USA. I earn a small referral fee if you click the occasional Amazon links and then purchase item. It does not affect the purchase price. For more information see "Amazon Associates" link below & left of clocks.
Showing posts with label Krebs On Security. Show all posts
Showing posts with label Krebs On Security. Show all posts
Monday, October 6, 2014
Wednesday, June 11, 2014
Security & Hacking: Windows Patch Tuesday Reminder
In case you forgot, yesterday was patch Tuesday for Windows.
Some critical fixes in this patch, for quick details on Patch Tuesdays I always recommend Brian Krebs posts http://krebsonsecurity.com/2014/06/adobe-microsoft-push-critical-security-fixes-4/
Some critical fixes in this patch, for quick details on Patch Tuesdays I always recommend Brian Krebs posts http://krebsonsecurity.com/2014/06/adobe-microsoft-push-critical-security-fixes-4/
Thursday, May 29, 2014
TrueCrypt Alternatives
Updated: Wanted to add https://www.grc.com/misc/truecrypt/truecrypt.htm green shaded box (scroll down a little) shows correspondence from devs of Truecrypt.
TL:DR Confirms that this was just an odd way of quitting.
****
For the couple people that might have missed drama with TrueCrypt see http://krebsonsecurity.com/2014/05/true-goodbye-using-truecrypt-is-not-secure/
TL:DR Looks like people(s) behind TrueCrypt are done supporting it & suggest people use something else, additionally version released with this information only decrypts previously encrypted data, won't encrypt.
In light of this situation, many people are looking for alternatives, best list I have found so far, though I know very little about the suggestions, is http://www.ghacks.net/2014/05/29/list-truecrypt-encryption-alternatives/
TL:DR Confirms that this was just an odd way of quitting.
****
For the couple people that might have missed drama with TrueCrypt see http://krebsonsecurity.com/2014/05/true-goodbye-using-truecrypt-is-not-secure/
TL:DR Looks like people(s) behind TrueCrypt are done supporting it & suggest people use something else, additionally version released with this information only decrypts previously encrypted data, won't encrypt.
In light of this situation, many people are looking for alternatives, best list I have found so far, though I know very little about the suggestions, is http://www.ghacks.net/2014/05/29/list-truecrypt-encryption-alternatives/
Thursday, January 16, 2014
Cliff's Esport Corner SITREP
As many of you have noticed, I haven't had many posts lately.
IRL stuff, my significant other had some surgery, and needed help 24/7 for some time afterwards.
Very happy to say that everything went very well for her, and that she is recovering quickly, though not quickly enough to make her happy ^_^
Things are to the point where I can start posting regular again, though it will probably start slowly and build back up to normal pace.
I didn't get to follow CES 2014 news very closely, so I would welcome anything of interest or comment about that, either in comment section or on Twitter @CliffsEsport or link https://twitter.com/CliffsEsport
I have been following the Target Credit Card Hack with great interest though, working on blog post about it, but can strongly reccomend Brian Krebs articles on it http://krebsonsecurity.com/2014/01/a-first-look-at-the-target-intrusion-malware/
IIRC Brian was the one that broke the story originally, http://krebsonsecurity.com/2013/12/sources-target-investigating-data-breach/, I remember seeing his Tweet about his Mom being interviewed about it at Target, while my girlfriend was still in the hospital.
Thanks to all my readers!
And a special thanks to everyone who offered good wishes, support, & prayers for my girlfriend's surgery & recovery, it was greatly appreciated by both of us!
IRL stuff, my significant other had some surgery, and needed help 24/7 for some time afterwards.
Very happy to say that everything went very well for her, and that she is recovering quickly, though not quickly enough to make her happy ^_^
Things are to the point where I can start posting regular again, though it will probably start slowly and build back up to normal pace.
I didn't get to follow CES 2014 news very closely, so I would welcome anything of interest or comment about that, either in comment section or on Twitter @CliffsEsport or link https://twitter.com/CliffsEsport
I have been following the Target Credit Card Hack with great interest though, working on blog post about it, but can strongly reccomend Brian Krebs articles on it http://krebsonsecurity.com/2014/01/a-first-look-at-the-target-intrusion-malware/
IIRC Brian was the one that broke the story originally, http://krebsonsecurity.com/2013/12/sources-target-investigating-data-breach/, I remember seeing his Tweet about his Mom being interviewed about it at Target, while my girlfriend was still in the hospital.
Thanks to all my readers!
And a special thanks to everyone who offered good wishes, support, & prayers for my girlfriend's surgery & recovery, it was greatly appreciated by both of us!
Tuesday, September 10, 2013
Microsoft Windows Patch Tuesday again!
That time again, if your interested in key points to this update, see Brian Krebs summary of this Patch Tuesday http://krebsonsecurity.com/2013/09/adobe-microsoft-push-critical-security-fixes-2/
Wednesday, April 17, 2013
Update on SWATting of Brian Krebs
http://krebsonsecurity.com/2013/04/swatting-incidents-tied-to-id-theft-sites/
Brian provides more details on his specific case, but most interesting part to me, was the fact that TTY are not supposed to keep records.
I probably should have realized that before, I thought main point was it made it easier for attacker to spoof phone number/location for SWATting.
Brian provides more details on his specific case, but most interesting part to me, was the fact that TTY are not supposed to keep records.
I probably should have realized that before, I thought main point was it made it easier for attacker to spoof phone number/location for SWATting.
Wednesday, March 20, 2013
Security & Hacking: "Microsoft confirms compromise of “high-profile” Xbox Live accounts"
Source & full story at http://arstechnica.com/security/2013/03/hackers-that-took-over-xbox-live-accounts-may-be-behind-ddos-attack-on-ars/ :
This ties in with Brian Kreb's recent blog post, http://krebsonsecurity.com/2013/03/the-obscurest-epoch-is-today/ were he details what he has learned so far about person(s) that SWATted him.
Oddly those people appear to have been involved in the hack or social engineering attack against Mat Honan, which Honan wrote about http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard and a later more polished article (link is good, but you may need to refresh sometimes to get it to work) http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/all/.
To see all my posts about the Mat Honan Hack click this Mat Honan Label, additional Labels can be found at bottom left of every post, and in Label Cloud at left side of Blog.
"We are aware that a group of attackers are using several stringed social engineering techniques to compromise the accounts of a handful of high-profile Xbox LIVE accounts held by current and former Microsoft employees," Microsoft officials said in a statement sent to Ars. "We are actively working with law enforcement and other affected companies to disable this current method of attack and prevent its further use."
This ties in with Brian Kreb's recent blog post, http://krebsonsecurity.com/2013/03/the-obscurest-epoch-is-today/ were he details what he has learned so far about person(s) that SWATted him.
Oddly those people appear to have been involved in the hack or social engineering attack against Mat Honan, which Honan wrote about http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard and a later more polished article (link is good, but you may need to refresh sometimes to get it to work) http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/all/.
To see all my posts about the Mat Honan Hack click this Mat Honan Label, additional Labels can be found at bottom left of every post, and in Label Cloud at left side of Blog.
Friday, March 15, 2013
Nerd News: Brian Krebs SWATting & DDoS
http://krebsonsecurity.com/2013/03/the-world-has-no-room-for-cowards/
http://arstechnica.com/security/2013/03/security-reporter-tells-ars-about-hacked-911-call-that-sent-swat-team-to-his-house/
Brian Krebs, from Krebs on Security, seems to be targeted by some criminal types.
Links above provide story.
http://arstechnica.com/security/2013/03/security-reporter-tells-ars-about-hacked-911-call-that-sent-swat-team-to-his-house/
Brian Krebs, from Krebs on Security, seems to be targeted by some criminal types.
Links above provide story.
Wednesday, February 20, 2013
Security Now with Steve & Leo, with special Guest Brian Krebs!
Stream: http://twit.tv/
I am really looking for ward to this episode.
They are going live as I blog this.
Brian's site is http://krebsonsecurity.com/
I am really looking for ward to this episode.
They are going live as I blog this.
Brian's site is http://krebsonsecurity.com/
Friday, February 15, 2013
Security & Hacking: "Exploit Sat on LA Times Website for 6 Weeks"
Makes me laugh & cry http://krebsonsecurity.com/2013/02/exploit-sat-on-la-times-website-for-6-weeks/
Snippet:
Snippet:
The Los Angeles Times has scrubbed its Web site of malicious code that served browser exploits and malware to potentially hundreds of thousands of readers over the past six weeks.
Wednesday, February 13, 2013
In case you missed it, yesterday was Microsoft Patch Tuesday
Brian Krebs has excellent review of Microsoft's Patch Tuesday http://krebsonsecurity.com/2013/02/microsoft-adobe-release-critical-security-updates/
He also covers Adobe patches for Flash Player, AIR and Shockwave.
He also covers Adobe patches for Flash Player, AIR and Shockwave.
Saturday, February 2, 2013
Hardware Hacking: "Pro-Grade Point-of-Sale Skimmer"
http://krebsonsecurity.com/2013/02/pro-grade-point-of-sale-skimmer/
I wonder if this is actually how Barnes & Noble was hacked?
http://cliffsesportcorner.blogspot.com/2012/10/security-hacking-thieves-rig-barnes.html
And for whatever reasons they don't want to disclose the connection?
Comments on Brian Krebs post are well worth reading as well, I learned BT is legit for POS (Point of Sale) devices transmitting Credit Card data as long as it is encrypted.
Link (PDF) https://www.pcisecuritystandards.org/pdfs/PCI_DSS_Wireless_Guideline_with_WiFi_and_Bluetooth_082211.pdf
Really well done work, wish I could solder as well as whoever did that!
I wonder if this is actually how Barnes & Noble was hacked?
http://cliffsesportcorner.blogspot.com/2012/10/security-hacking-thieves-rig-barnes.html
And for whatever reasons they don't want to disclose the connection?
Comments on Brian Krebs post are well worth reading as well, I learned BT is legit for POS (Point of Sale) devices transmitting Credit Card data as long as it is encrypted.
Link (PDF) https://www.pcisecuritystandards.org/pdfs/PCI_DSS_Wireless_Guideline_with_WiFi_and_Bluetooth_082211.pdf
Really well done work, wish I could solder as well as whoever did that!
Sunday, January 20, 2013
Security & Hacking: Java exploit Number ∞
http://nakedsecurity.sophos.com/2013/01/20/java-hacker-boasts-of-finding-two-more-unpatched-holes/
http://krebsonsecurity.com/2013/01/new-java-exploit-fetches-5000-per-buyer/
Seems like you can find new/more Java exploits a lot faster than they can be patched, so if your concerned about security, stop using Java on Browsers!
Course, if you want to make sure Blackhat Hackers don't starve, keep using it, </sarcasm>
http://krebsonsecurity.com/2013/01/new-java-exploit-fetches-5000-per-buyer/
Seems like you can find new/more Java exploits a lot faster than they can be patched, so if your concerned about security, stop using Java on Browsers!
Course, if you want to make sure Blackhat Hackers don't starve, keep using it, </sarcasm>
Friday, January 18, 2013
PSA Security & Hacking: Shylock Banking Trojan now spreading via Skype
Primary source https://www.csis.dk/en/csis/blog/3811
As someone that is computer security conscious, I avoid online banking completely.
For friends, family, & others that insist on online banking I suggest either of the following:
Clear instructions & screenshot for turning off Simple Passcode http://www.computerworld.com/s/article/9231627/Kenneth_van_Wyk_Shutting_down_security_gotchas_in_iOS_6?taxonomyId=17&pageNumber=1
The reason for this, is that a hacker with right software, can use a computer to try passwords, they can also bypass the 10 try feature.
So if your using the Simple Passcode, which is just a 4 digit number, they will probably be able to hack it in less than an hour.
However, if you use a Pass Phrase, like I <3 my iPad. I hate green beans! the hacker will have a much more difficult time. [Note, don't use that pass phrase, it is just to illustrate the concept.]
Since instead of only 4 numbers, there are 34 characters, counting the blank spaces, plus your using uppercase letters , lowercase letters, numbers, special characters, and blank spaces.
The hacker won't have any idea how long your password is, and by using at least one of all possible upper/lower case, numbers, symbols, and blank spaces you make hackers job a lot harder.
For more on passwords see http://cliffsesportcorner.blogspot.com/2012/05/steve-gibsons-haystacks-needles.html
Additional links:
As someone that is computer security conscious, I avoid online banking completely.
For friends, family, & others that insist on online banking I suggest either of the following:
- Use a Live CD, Brian Kreb has excellent articales on how to do this http://krebsonsecurity.com/2012/07/banking-on-a-live-cd/ or http://krebsonsecurity.com/banking-on-a-live-cd/
- Use a recent iOS device, iPhone 4S or newer, iPad 2 or newer, iPod Touch 5th generation or newer. There are significant hardware security improvements that started with those respective devices.
Clear instructions & screenshot for turning off Simple Passcode http://www.computerworld.com/s/article/9231627/Kenneth_van_Wyk_Shutting_down_security_gotchas_in_iOS_6?taxonomyId=17&pageNumber=1
The reason for this, is that a hacker with right software, can use a computer to try passwords, they can also bypass the 10 try feature.
So if your using the Simple Passcode, which is just a 4 digit number, they will probably be able to hack it in less than an hour.
However, if you use a Pass Phrase, like I <3 my iPad. I hate green beans! the hacker will have a much more difficult time. [Note, don't use that pass phrase, it is just to illustrate the concept.]
Since instead of only 4 numbers, there are 34 characters, counting the blank spaces, plus your using uppercase letters , lowercase letters, numbers, special characters, and blank spaces.
The hacker won't have any idea how long your password is, and by using at least one of all possible upper/lower case, numbers, symbols, and blank spaces you make hackers job a lot harder.
For more on passwords see http://cliffsesportcorner.blogspot.com/2012/05/steve-gibsons-haystacks-needles.html
Additional links:
- Covers weakness of older iOS devices to hacking http://www.blackbagtech.com/blog/2011/12/15/iphone-forensics-accessing-a-handset-locked-iphone-ipad-or-ipod-touch-device/
- Elcomsoft article (pdf) on password keepers, but they also cover superiority of locking iOS or Blackberry devices over Password Keepers http://www.elcomsoft.com/WP/BH-EU-2012-WP.pdf
- Verifying iOS Data Protection enabled http://support.apple.com/kb/HT4175
- Non Apple article for verifying iOS Data Protection enabled (some find Apple's Support articles less than clear) http://www.cloudcentrics.com/?p=1820
- Puppy Linux, a decent choice for Live CD http://puppylinux.org/main/Overview%20and%20Getting%20Started.htm
- Damn Small Linux another decent choice for Live CD http://www.damnsmalllinux.org/
- Place to buy Live CD or DVD with Puppy Linux (so you can just buy it and use it, without hassle of downloading & burning it yourself) http://www.osdisc.com/products/linux/puppy
Security & Hacking: Malware 2 Years ago USB Battery Charger Backdoor
Energizer Battery Charger Software Included Backdoor http://krebsonsecurity.com/2010/03/energizer-battery-charger-software-included-backdoor/
Energizer DUO USB battery charger software allows unauthorized remote system access http://www.kb.cert.org/vuls/id/154421
This is from 2010, so certainly not new concept, I hadn't heard of this specific hack before though, & to be honest, don't think I would have expected this, before reading Brian Kreb's article on it.
Though I was aware of the Vodafone issue that some of the Energizer Duo articles/comments mentioned http://research.pandasecurity.com/vodafone-distributes-mariposa/
To be clear, there wasn't Malware on the USB device itself, but in the software you could download from Energizer to monitor the device.
I didn't find any articles explaining how the Malware got inserted into the Energizer software, but some stories suggested it might have been in place for ~3 years.
If anyone has any more detail on this I would be interested in learning it.
Schneier also posted about it http://www.schneier.com/blog/archives/2010/03/back_door_in_ba.html
Energizer DUO USB battery charger software allows unauthorized remote system access http://www.kb.cert.org/vuls/id/154421
This is from 2010, so certainly not new concept, I hadn't heard of this specific hack before though, & to be honest, don't think I would have expected this, before reading Brian Kreb's article on it.
Though I was aware of the Vodafone issue that some of the Energizer Duo articles/comments mentioned http://research.pandasecurity.com/vodafone-distributes-mariposa/
To be clear, there wasn't Malware on the USB device itself, but in the software you could download from Energizer to monitor the device.
I didn't find any articles explaining how the Malware got inserted into the Energizer software, but some stories suggested it might have been in place for ~3 years.
If anyone has any more detail on this I would be interested in learning it.
Schneier also posted about it http://www.schneier.com/blog/archives/2010/03/back_door_in_ba.html
Wednesday, November 7, 2012
Security & Hacking: "Cyberheists ‘A Helluva Wake-up Call’ to Small Biz"
http://krebsonsecurity.com/2012/11/cyberheists-a-helluva-wake-up-call-to-small-biz/
And they say crime doesn't pay,
I don't know about you, but $180,000 sounds like good pay to me.
And they say crime doesn't pay,
"The St. Louis, Missouri-based firm first learned that things weren’t quite right on Wednesday, May 30, 2012, when the company’s payroll manager logged into her account at the local bank and discovered that an oversized payroll batch for approximately $180,000 had been sent through late Tuesday evening."
I don't know about you, but $180,000 sounds like good pay to me.
Wednesday, October 24, 2012
Security & Hacking: "Thieves rig Barnes & Noble PIN pads to steal credit card data"
http://nakedsecurity.sophos.com/2012/10/24/barnes-noble-pin-pad-credit-card/
Not clear yet if this attack used Skimmers or Hacking.
Note that the FBI asked Barnes and Noble to sit on this for a month, so actual attack happen a while ago, and not clear yet how long it had been active.
Days? Weeks? Months? Years?
I suspect Skimmer's of some type myself in this attack, but could have been software hack or something else.
For more on Skimmers see Krebs article "Would you have Spotted this ATM Fraud?" for even more you can see Brian Krebs entire series on Skimmers at his "All about Skimmers" were he has collected all his articles in one spot, with short intro to each article and link to full individual story.
Not clear yet if this attack used Skimmers or Hacking.
Note that the FBI asked Barnes and Noble to sit on this for a month, so actual attack happen a while ago, and not clear yet how long it had been active.
Days? Weeks? Months? Years?
I suspect Skimmer's of some type myself in this attack, but could have been software hack or something else.
For more on Skimmers see Krebs article "Would you have Spotted this ATM Fraud?" for even more you can see Brian Krebs entire series on Skimmers at his "All about Skimmers" were he has collected all his articles in one spot, with short intro to each article and link to full individual story.
Friday, October 19, 2012
" Fake AV Vendors Feel Credit Card Crunch"
Another really excellent article from Brian Krebs http://krebsonsecurity.com/2012/10/rogue-pharma-fake-av-vendors-feel-credit-card-crunch/
Not sure how to accurately summarize this article, but he opens with:
Not sure how to accurately summarize this article, but he opens with:
"New research suggests that companies behind some of America’s best known consumer brands may be far more effective at fighting cybercrime than any efforts to enact more stringent computer security and anti-piracy laws."He then mentions that things like SOPA have been pushed by legislators, but that the data suggests brand holders already handle things very well.
Tuesday, October 16, 2012
Security & Hacking: " Scrap Value of a Hacked PC"
http://krebsonsecurity.com/2012/10/the-scrap-value-of-a-hacked-pc-revisited/
EXCELLENT Article with clear picture showing what Hackers gain from hacking a computer, even a simple one just used for web surfing and email!
Brian Kreb's security blog is one of my favorite!
Think this article illustrates why, lot of computer people understand computer security, but I know as a writer just how hard it can be to communicate concepts at times.
This illustration is brilliant!
It really is an outline in visual form:
Learned about a new Bot myself today from this artical, the CAPTCHA Solving Zombie, Krebs' answered question about that in the comments with this link http://www.inwyrd.com/blog/2010/03/hijacking-koobfaces-captcha-solver/
EXCELLENT Article with clear picture showing what Hackers gain from hacking a computer, even a simple one just used for web surfing and email!
Brian Kreb's security blog is one of my favorite!
Think this article illustrates why, lot of computer people understand computer security, but I know as a writer just how hard it can be to communicate concepts at times.
This illustration is brilliant!
It really is an outline in visual form:
- Web Server
- E Mail Attacks
- Virtual Goods
- Reputation Hijacking
- Bot Activity
- Account Credentials
- Financial Credentials
- Hostage Attacks
Learned about a new Bot myself today from this artical, the CAPTCHA Solving Zombie, Krebs' answered question about that in the comments with this link http://www.inwyrd.com/blog/2010/03/hijacking-koobfaces-captcha-solver/
Subscribe to:
Posts (Atom)