The European Union on Monday prohibited the use of X-ray body scanners in European airports, parting ways with the U.S. Transportation Security Administration, which has deployed hundreds of the scanners as a way to screen millions of airline passengers for explosives hidden under clothing.
The European Commission, which enforces common policies of the EU's 27 member countries, adopted the rule “in order not to risk jeopardizing citizens’ health and safety.”
Some news, views and musing about things going on in the Information Security World.
Wednesday, November 16, 2011
Police trick 19 criminals into coming forward with free beer
Undercover officers at Derbyshire police sent letters to dozens of people who had evaded arrest asking them to ring a marketing company to collect a free crate of beer.
A total of 19 suspects fell for the hoax and called the number on the letter, which put them through to police officers based at Chesterfield Police Station.
They were told that they needed to arrange a date and time for the free alcohol to be dropped off at an agreed address.
But instead of being handed free ale the wanted men found themselves confronted by police, handcuffed and under arrest.
A total of 19 suspects fell for the hoax and called the number on the letter, which put them through to police officers based at Chesterfield Police Station.
They were told that they needed to arrange a date and time for the free alcohol to be dropped off at an agreed address.
But instead of being handed free ale the wanted men found themselves confronted by police, handcuffed and under arrest.
Tuesday, November 8, 2011
What is Phlashing
Phlashing is a permanent denial of service (DoS) attack that exploits a vulnerability in network-based firmware updates. Such an attack is currently theoretical but if carried out could render the target device inoperable.
Rich Smith, head of HP's Systems Security Lab, discovered the vulnerability and demonstrated the attack at the EUSecWest security conference in June 2008. In a real-world execution, an attacker could use remote update paths in network hardware, which are often left unprotected, to deliver corrupted and flash this to the device. As a result, the device would become unusable.
Rich Smith, head of HP's Systems Security Lab, discovered the vulnerability and demonstrated the attack at the EUSecWest security conference in June 2008. In a real-world execution, an attacker could use remote update paths in network hardware, which are often left unprotected, to deliver corrupted and flash this to the device. As a result, the device would become unusable.
Friday, September 30, 2011
Lie Detector Leads to Execution of Innocent Man
Chiang Kuo-ching, a Taiwanese airman was executed in 1997 for the rape and murder of a five-year-old girl. Military investigators tortured a confession out of Chiang after he failed to pass a lie detector “test.” Since then, DNA evidence and a palm-print have incriminated a different person.
Clenching your butt at the wrong time will cause you to appear guilty on a polygraph. It's time to throw this system out with the water dousers.
Clenching your butt at the wrong time will cause you to appear guilty on a polygraph. It's time to throw this system out with the water dousers.
Thursday, September 29, 2011
Scientists Can Use WiFi to Count Your Breaths and Spy on You
Wireless networks which measure received signal strength (RSS) can be used to reliably detect human breathing and estimate the breathing rate, an application we call "BreathTaking". Although an individual link cannot reliably detect breathing, the collective spectral content of a network of devices reliably indicates the presence and rate of breathing.
Key Words:
physical security,
privacy,
security controls,
spying
Thursday, September 8, 2011
Award BIOS Flashing Trojan
I used to talk about the possibility of a virus or worm writing boot code on hard drives, or flashing devices with new configurations, or even entirely new code. It seems there is now a trojan out there that does just that. Yes the site is in Chinese. But it describes a trojan that flashes Award BIOS code to add a few new functions on bootup.
Symantec has more details on how it infects the hard drive Master Boot Record (MBR) and specifically targets and alters the Award BIOS. Other BIOS brands are not affected.
Symantec has more details on how it infects the hard drive Master Boot Record (MBR) and specifically targets and alters the Award BIOS. Other BIOS brands are not affected.
Key Words:
0-day,
computer viruses,
security controls,
trojan
Tuesday, September 6, 2011
Richard Branson lost his memoirs in blaze
Airline tycoon Richard Branson lost his autobiography and 15 years worth of handwritten notes when a fire ripped through his retreat in the British Virgin Islands.
This is a good time to remind everyone that your backups should be stored somewhere well away from the systems they are taken from. Otherwise they can both go up in smoke.
This is a good time to remind everyone that your backups should be stored somewhere well away from the systems they are taken from. Otherwise they can both go up in smoke.
Key Words:
data destruction,
physical security,
security controls
Subscribe to:
Posts (Atom)