Security Blog Feed
At $560M, losses from online crime nearly doubled in 2009 - Wed, 17 Mar 2010
The Internet Crime Complaint Center (IC3) recently released their report on 2009 Internet crime statistics. As you can probably guess, there were more complaints, more losses, higher average loss per incident. IC3 is a federally funded non-profit, a joint operation between the FBI and the National White Collar Crime Center (NW3C). In brief: Complaints received: 336,655 Total loss: [...]
1024-bit RSA encryption cracked by carefully starving CPU of electricity - Tue, 09 Mar 2010
Several researchers the University of Michigan have succeeded in cracking the RSA security technology which protects all ecommerce and online banking transactions. The university scientists found that they could deduce tiny pieces of a private key by injecting slight fluctuations in a device’s power supply as it was processing encrypted messages. In a little more than [...]
9 ways to make your enterprise secure - Thu, 04 Mar 2010
Small business or large, studies show that all companies are at risk of attack by hackers. Government agencies including the FBI have suggested using a separate computer for all transactions involving money or sensitive information, but from a business view, that isn’t scalable or practical. So we’re gonna spill the beans for you. We’re not [...]
First Direct serves up more than just no-fee banking - Mon, 01 Mar 2010
First Direct bank in the UK has been the first British bank to embrace Twitter. Does that really surprise anyone? As a 100% online bank, they’ve maintained a business pace a few clicks ahead of competitors in online services. But last weekend their clients and colleagues got a little surprise. First Direct’s Twitter account was duped, [...]
New attack reveals user identities - Fri, 26 Feb 2010
Browsing on the web just became a little more scary. A group of researchers found a way to deploy an attack that can "de-anonymize" the users behind the browser (research paper available in PDF format). Focusing on the users of social networking sites (LinkedIn.com, Facebook, Xing.com, etc.), these security researchers show how to de-anonymize a [...]
Phishing is Phutile! - Fri, 19 Feb 2010
I was in a conversation this week with someone else in the online security space and I happened to mention that I think Tricerion’s Safe Login is pretty darn sweet. He was a proponent of a keyfob token that additionally used a USB chord and a card too. Yikes. That’s too complicated for me. In [...]
Turning Green into Cash - Phishing for Carbon Emissions Permits - Tue, 09 Feb 2010
A world wide phishing attack on carbon emissions trading registries forced registries in nine countries to shut down, while in other countries trading was temporarily suspended. Fake registries (phishing sites) were set up by a group of criminals who then sent out messages to thousands of users in different companies, making off with about 250,000 [...]
Need a job? Cyberthieves are hiring! - Thu, 04 Feb 2010
Well, it might not be the best career move and it probably won’t help you pad your resume, but hey – income is income, right? According to Reuters cyberthieves are hiring, and they’re placing ads online. One site, for example, pays $180 (£112) for each 1,000 times that malware is downloaded onto a [...]
Twitter's been phished! - Wed, 03 Feb 2010
2 of my 3 Twitter accounts asked me to reset my password this morning when I signed in. It seems that a third party application may have compromised accounts, but stories abound about what really happened. What I can tell you is that I know enough about where to share my passwords that I didn’t accidentally [...]
Security, Perceived Security, and Economics - Sat, 30 Jan 2010
The good folks over at Credit Card Processing Gist posted an article yesterday naming the flaws of Verififed By Visa and MasterCard’s Secure Code. Flawed technology and poor design meet good economics – telling us that price is the trump card when it comes to online authentication. When we talk about the authentication space there are [...]
