It seems that Heartland Payment Systems, the company that achieved unwanted celebrity status last year for suffering the largest credit card data breach ever, is back in the news. This time they are spinning out ways to downplay yet another major data breach.
A Heartland spokesperson is suggesting that somebody hacked into a system between Tino's Greek Cafe and Heartland, resulting in numerous fraudulent charges to the customer's credit cards. Jeff Nori, co-owner of Tino's plenty to say about the breach.
Thanks to jimmiejaz for the scoop.
Some news, views and musing about things going on in the Information Security World.
Friday, August 13, 2010
Wednesday, August 4, 2010
Lock Picking For Dummies - Part II
It seems there were quite a few more examples of various locks being unlocked in unusual ways at DEF CON this year. Some of these are downright stunning.
Should companies begin to conduct risk analysis and penetration testing on their door lock purchases?
Should companies begin to conduct risk analysis and penetration testing on their door lock purchases?
Key Words:
defcon,
hacking,
physical security,
security controls
Tuesday, August 3, 2010
One Reason Nobody Trusts Microsoft's Security Controls
Ever wondered why you are always told to buy firewall software, even though your router probably has a firewall built in, and your operating system probably does too?
Ever wondered why you have to pay for antivirus software, even though it would be fairly trivial for the operating system manufacturer to add this by default - or at least alter the obvious weaknesses that make the viruses so rampant on that specific platform in the first place?
Ever wondered why you have to pay for additional privacy controls, even when the operating system claims to have privacy built into the operating system?
Internet Explorer just became less private thanks to Microsoft bowing to the advertising agencies. That's right - they dropped the ball. The ability to mess your screen up with animated advertisements everywhere you look trumps all security and privacy controls, again.
Microsoft is falling behind so badly, next thing you know, they'll be making an iPad clone. I wonder what "new" security issues will come of that.
Ever wondered why you have to pay for antivirus software, even though it would be fairly trivial for the operating system manufacturer to add this by default - or at least alter the obvious weaknesses that make the viruses so rampant on that specific platform in the first place?
Ever wondered why you have to pay for additional privacy controls, even when the operating system claims to have privacy built into the operating system?
Internet Explorer just became less private thanks to Microsoft bowing to the advertising agencies. That's right - they dropped the ball. The ability to mess your screen up with animated advertisements everywhere you look trumps all security and privacy controls, again.
Microsoft is falling behind so badly, next thing you know, they'll be making an iPad clone. I wonder what "new" security issues will come of that.
Key Words:
0-day,
computer viruses,
hacking,
security controls
Lock Picking For Dummies
The humble paperclip seems to be all that's need to break into anything lately.
Several years ago, Mythbusters found several ways to beat biometric locks that until that episode, had supposedly never been broken before.
Have the companies promoting biometric technologies done their Follow-Up? Of course not.
The Biolock 333 is a $200 piece of crap technology that can be opened quicker with a paper clip than it can be by swiping your finger properly. This is more pathetic than cracking a Kryptonite D-Lock with a Bic Pen. At least a standard lock takes a little longer to crack.
2 thumbs down for this so-called secure product.
Several years ago, Mythbusters found several ways to beat biometric locks that until that episode, had supposedly never been broken before.
Have the companies promoting biometric technologies done their Follow-Up? Of course not.
The Biolock 333 is a $200 piece of crap technology that can be opened quicker with a paper clip than it can be by swiping your finger properly. This is more pathetic than cracking a Kryptonite D-Lock with a Bic Pen. At least a standard lock takes a little longer to crack.
2 thumbs down for this so-called secure product.
Monday, August 2, 2010
A DEF CON speaker was detained at the US border and asked about his involvement with the Wikileaks.org whistle-blowing website. They returned his laptop, but three of his cell phones were confiscated, and will probably never be seen again.
After mentioning this during his presentation (which was about onion routing), he was greeted by FBI agents who hoped to probe him. One of the spooks was quoted as saying "sometimes it's nice to have a conversation to flesh things out."
After mentioning this during his presentation (which was about onion routing), he was greeted by FBI agents who hoped to probe him. One of the spooks was quoted as saying "sometimes it's nice to have a conversation to flesh things out."
Friday, July 30, 2010
Trojan Cell Phone Apps
First the iphone and now android phones have been center focus for trojan applications that collect personal data and send it off to some nefarious foreign server. One of the trojan apps is a simple desktop wallpaper manager.
Ever wondered why some companies have such strict policies about what you may or may not install on your company-issued cellphone?
Ever wondered why some companies have such strict policies about what you may or may not install on your company-issued cellphone?
Tuesday, July 27, 2010
MoD Squad Loses an Unencrypted Laptop Every Other Day
For the past 2 years, the British Ministry of Defense has been on a losing streak. 120 laptops are known to have been stolen, and 220 more went missing one way or other. Most of them did not use encryption.
What else did they lose?
What else did they lose?
- 593 CDs, DVDs and diskettes
- 215 memory cards
- 96 USB hard drives
- 13 cell phones
- 600,000 records of recruits and potential recruits
Key Words:
encryption,
physical security,
security controls
Subscribe to:
Posts (Atom)