Encryption

State of Utah outlines mistakes made allowing theft of 780K records

State of Utah outlines mistakes made allowing theft of 780K records

After losing nearly 800,000 residents personal information the State of Utah admits to not encrypting the data, leaving default passwords in place and not performing regular audits to find the mistakes.

Share

Osama Bin Laden didn't encrypt his computer files - not such a mastermind then..

Osama Bin Laden didn't encrypt his computer files - not such a mastermind then..

Ooops. If you're running a terrorist organisation, it might make sense to encrypt your files.

Clearly Osama Bin Laden didn't realise that - as some of the documents seized during the raid on his hideout in Pakistan have been made public for the first time.

Share

MasterCard and Visa payment processor compromised, up to 10 million cards stolen

shutterstock_CreditCardTerminal250

Over 10 million credit cards may have been stolen by criminals who compromised a credit card processing company last month. Read on to find out what happened and what actions you may wish to take to protect yourself.

Share

Cloud storage data risks and encryption

clouds-thumb

Are you encrypting the data you keep in the cloud? Or are you trusting the cloud storage providers to do a decent job at security?

Share

SSCC 84 - Cookie-gate, laptop security advice, Stratfor malicious emails and Facebook hacker advice

Sophos Security Chet Chat

Paul Ducklin hosts this week's Chet Chat with the tables turned... Chet is the guest. They discussed the recent Google cookie-gate incident, House Intelligence Committee advice on using laptops while traveling and the malicious emails sent to leaked Stratfor subscriber email addresses.

Share

Alleged fraudster has until next week to decrypt her hard drive for prosecutors

Alleged fraudster has until next week to decrypt her hard drive for prosecutors

Prosecutors are keen to discover what is on the encrypted laptop of Ramona Fricosu, a Colorado woman accused of committing financial fraud.

The case has raised interesting questions of whether you can be forced by law to hand over your password, or decrypt your computer.

Share

Mac FileVault 2's full disk encryption can be bypassed in less than 40 minutes

Mac FileVault 2's full disk encryption can be broken in less than 40 minutes

A company claims it can bypass Apple's FileVault 2 disk encryption "in minutes," as well as volumes encrypted with TrueCrypt.

Share

Despite what you may think, IT security *is* your business

3D illustration of grey office for routine work

If you spend a lot of time paying attention to IT (in)security it can drive you to rant on occasion. This is one of those occasions, as too many companies are putting their future and their customers at risk thinking that "IT security isn't our busniess".

Share

Stratfor's back, defiant but blushing over unencrypted subscriber data

iStock_BrokenHardDrive250

George Fried,an, CEO of Stratfor, came forth with a public statement explaining what happened in the attacks against his company last December. He admitted fault, took responsibility and accused Anonymous of censorship that doesn't come openly from governments, but rather from people hiding behind masks.

Share

Can you be forced by law to decrypt your computer? US v. Fricosu court case rages on

Passwords screenshot

Ramona Fricosu, accused of committing financial fraud, is currently in a court battle fighting to keep her encrypted data private. The prosecution say that if the government fail to demand data decryption, it will harm public interests. This article looks at the arguments for both sides and asks whether this would be possible under UK law.

Share

Researchers find many weak Stratfor passwords

passwords250

A professor at Utah Valley University analyzed the leaked password hashes stolen by Anonymous from security firm Stratfor and determined even their security minded customers choose weak passwords.

Share

Most Wi-Fi routers susceptible to hacking through security feature

WiFiAllianceLogo250

Researchers have published a paper showing how a feature implemented in modern Wi-Fi routers intended to make securing them easier, in fact makes them insecure by default.

Share

Lost USB keys have 66% chance of malware

Lost USB keys have 66% chance of malware

We bought a stash of USB keys at a major transit authority's Lost Property auction, and took a look at the sort of information people leave on the train.

Two-thirds of the keys were infected with malware, and nothing on any of the keys was encrypted...

Share

Cloud storage's hazy security lining at SC Congress NYC

whatis_icloud250

With the bring your own device (BYOD) gaining momentum, do you know how your users are managing to move their data to and fro? In all likelihood they are using the cloud. Read on for the risks and strategies to protect your sensitive information in the cloud.

Share

Randomness in cryptography - the devil's in the details

Randomness in cryptography - the devil's in the details

Kiwicon opened with a software engineering talk which was intensely focused - a case study of a single-line bug in a single source file in a single module in a 70MBbyte programming language distro.

Paul Ducklin reports from Wellington, New Zealand.

Share

Stanford Hospital leaks 20,000 patient records

CCDoNotLickStanfordHospital245

Stanford hospital lost 20,000 sensitive records through a mistake made by a third party billing company. When will our electronic health records be properly safeguarded?

Share

Why Pakistan's move against online crypto is a dangerous idea

nocrypto-square

Reports from Pakistan suggest the country's telecomms authority is pressing ISPs to comply with regulations which restrict the use of end-to-end encryption.

But this won't improve security, even against militants. In general, it will make things worse.

Share

Stolen USB stick contained police investigation details

Stolen USB stick contained police investigation details

Greater Manchester Police hunt for a stolen USB stick, containing details of an ongoing criminal investigation.

Share

Can simple Google searches reveal your secrets?

Can simple Google searches reveal your secrets?

Sophos's David Schwartzberg examines how sometimes Google can do too good a job, and can expose private encryption keys.

Share

Dropbox lets anyone log in as anyone - so check your files now!

dropbox-square

Customers of cloud-based file storing-and-sharing company Dropbox should check on the data they've entrusted to the service, following the company's admission that it messed up its access controls for several hours.

Share