Login
FreshRSS
Login
Naked Security
Serious Security: Unravelling the LifeLock βhacked passwordsβ story
By
Paul Ducklin
β January 17
th
2023 at 17:59
Four straight-talking tips to improve your online security, whether you're a LifeLock customer or not.
Naked Security
S3 Ep117: The crypto crisis that wasnβt (and farewell forever to Win 7) [Audio + Text]
By
Paul Ducklin
β January 12
th
2023 at 17:59
Tell us in the comments... What's the REAL reason there was no Windows 9? (No theory too far-fetched!)
Naked Security
Popular JWT cloud security library patches βremoteβ code execution hole
By
Paul Ducklin
β January 10
th
2023 at 19:59
It's remotely triggerable, but attackers would already have pretty deep network access if they could "prime" your server for compromise.
Naked Security
RSA crypto cracked? Or perhaps not!
By
Paul Ducklin
β January 6
th
2023 at 19:59
Stand down from blue alert, it seems... but why not plan your cryptographic agility anyway?
Naked Security
S3 Ep116: Last straw for LastPass? Is crypto doomed? [Audio + Text]
By
Paul Ducklin
β January 5
th
2023 at 17:52
Lots of big issues this week: breaches, encryption, supply chains and patching problems. Listen now! (Full transcript inside.)
Naked Security
Serious Security: How to improve cryptography, resist supply chain attacks, and handle data breaches
By
Paul Ducklin
β January 4
th
2023 at 19:50
Lessons for us all: improve cryptography, fight cybercrime, own your supply chain... and don't steal my data and then pretend you're sorry.
Naked Security
US passes the Quantum Computing Cybersecurity Preparedness Act β and why not?
By
Paul Ducklin
β December 29
th
2022 at 20:45
Cryptographic agility: the ability and the willingness to change quickly when needed.
sc-daa-1200
Naked Security
Serious Security: MD5 considered harmful β to the tune of $600,000
By
Paul Ducklin
β November 30
th
2022 at 17:58
It's not just the hashing, by the way. It's the salting and the stretching, too!
Naked Security
The OpenSSL security update story β how can you tell what needs fixing?
By
Paul Ducklin
β November 3
rd
2022 at 00:44
How to Hack! Finding OpenSSL library files and accurately identifying their version numbers...
ossl-code-1200
Naked Security
OpenSSL patches are outΒ β CRITICAL bug downgraded to HIGH, but patch anyway!
By
Paul Ducklin
β November 1
st
2022 at 17:24
That bated-breath OpenSSL update is out! It's no longer rated CRITICAL, but we advise you to patch ASAP anyway. Here's why...
Naked Security
SHA-3 code execution bug patched in PHP β check your version!
By
Paul Ducklin
β November 1
st
2022 at 14:09
As everyone waits for news of a bug in OpenSSL, here's a reminder that other cryptographic code in your life may also need patching!
Naked Security
S3 Ep106: Facial recognition without consent β should it be banned?
By
Paul Ducklin
β October 27
th
2022 at 16:59
Latest episode - listen (or read) now. Teachable moments for X-Ops professionals!
Naked Security
Serious Security: How randomly (or not) can you shuffle cards?
By
Paul Ducklin
β October 24
th
2022 at 18:57
What if you could guess the next card correctly twice as often as you should?
card-fan-1200
Naked Security
S3 Ep105: WONTFIX! The MS Office cryptofail that βisnβt a security flawβ [Audio + Text]
By
Paul Ducklin
β October 20
th
2022 at 18:54
The coolest video game ever! And lots of solid cybersecurity advice - listen now!
pic-1200
Naked Security
Women in Cryptology β USPS celebrates WW2 codebreakers
By
Paul Ducklin
β October 19
th
2022 at 16:58
What did you do in the war, Mom? Oh, y'know, a bit of this and that...
Naked Security
Serious Security: Microsoft Office 365 attacked over feeble encryption
By
Paul Ducklin
β October 14
th
2022 at 16:59
How 2022 is your encryption?
Naked Security
Serious Security: OAuth 2 and why Microsoft is finally forcing you into it
By
Paul Ducklin
β October 10
th
2022 at 18:02
Microsoft calls it "Modern Auth", though it's a decade old, and is finally forcing Exchange Online customers to switch to it.
Naked Security
S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, healthcare security [Audio + Text]
By
Paul Ducklin
β August 18
th
2022 at 18:38
Latest episode - listen now (or read if you prefer!)
Naked Security
S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]
By
Paul Ducklin
β August 11
th
2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)
Naked Security
APIC/EPIC! Intel chips leak secrets even the kernel shouldnβt seeβ¦
By
Paul Ducklin
β August 10
th
2022 at 16:59
If you've ever written code that left stuff lying around in memory when you didn't need it any more... we bet you've regretted it!
Naked Security
Slack admits to leaking hashed passwords for five years
By
Paul Ducklin
β August 8
th
2022 at 15:14
"When those invitations went out... somehow, your password hash went out with them."
Naked Security
S3 Ep94: This sort of crypto (graphy), and the other sort of crypto (currency!) [Audio + Text]
By
Paul Ducklin
β August 4
th
2022 at 17:52
Latest episode - listen now! (Or read if that's what you prefer.)
Naked Security
Post-quantum cryptography β new algorithm βgone in 60 minutesβ
By
Paul Ducklin
β August 3
rd
2022 at 18:55
And THIS is why you don't knit your own home-made encryption algorithms and hope no one looks at them.
Naked Security
Cryptocoin βtoken swapperβ Nomad loses $200 million in coding blunder
By
Paul Ducklin
β August 2
nd
2022 at 16:12
Transactions were only approved, it seems, if they were initiated by... errrrr, by anyone.
Naked Security
GnuTLS patches memory mismanagement bug β update now!
By
Paul Ducklin
β August 1
st
2022 at 16:55
GnuTLS may well be the most widespread cryptographic toolkit you've never heard of. Learn more...
Naked Security
S3 Ep91: CodeRed, OpenSSL, Java bugs, Office macros [Audio + Text]
By
Paul Ducklin
β July 14
th
2022 at 18:47
Latest episode - listen now! Great discussion, technical content, solid advice... all covered in plain English.
Naked Security
OpenSSL fixes two βone-linerβ crypto bugs β what you need to know
By
Paul Ducklin
β July 6
th
2022 at 16:52
"As bad as Heartbleed"? We heard that concern a week ago, but we think it's less ungood than that...
Naked Security
S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix [Podcast + Transcript]
By
Paul Ducklin
β June 30
th
2022 at 12:57
Latest episode - listen and read now! Use our advice to advise your own friends and family... let's all do our bit to stand up to scammers!
Naked Security
OpenSSL issues a bugfix for the previous bugfix
By
Paul Ducklin
β June 24
th
2022 at 15:32
Fortunately, it's not a major bugfix, which means it's easy to patch and can teach us all some useful lessons.
Naked Security
He sold cracked passwords for a living β now heβs serving 4 years in prison
By
Paul Ducklin
β May 13
th
2022 at 18:31
Crooks don't need a password for every user on your network to break in and wreak havoc. One could be enough...
Naked Security
S3 Ep79: Chrome hole, a bad place for a cybersecurity holiday, and crypto-dodginess [Podcast]
By
Paul Ducklin
β April 21
st
2022 at 13:41
Do you know your Adam Osborne from your John Osbourne? Your Z80 from your 6502? Latest episode - listen now!
Naked Security
Critical cryptographic Java security blunder patched β update now!
By
Paul Ducklin
β April 20
th
2022 at 16:43
Either know the private key and use it scrupulously in your digital signature calculation.... or just send a bunch of zeros instead.
Naked Security
S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]
By
Paul Ducklin
β April 14
th
2022 at 13:39
Latest episode - listen now!
Naked Security
OpenSSH goes Post-Quantum, switches to qubit-busting crypto by default
By
Paul Ducklin
β April 11
th
2022 at 16:58
Useful quantum computers might not actually be possible. But what if they are? And what if they arrive, say, tomorrow?
cat-1200
Naked Security
S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]
By
Paul Ducklin
β March 24
th
2022 at 13:49
Latest episode - listen now!
Naked Security
OpenSSL patches infinite-loop DoS bug in certificate verification
By
Paul Ducklin
β March 18
th
2022 at 17:59
When it comes to writing loops in your code... never sit on the fence!
Naked Security
Self-styled βCrocodile of Wall Streetβ arrested with husband over Bitcoin megaheist
By
Naked Security writer
β February 9
th
2022 at 14:44
The cops say they've recovered 80% of a $72 million cryptocoin heist... but the recovered funds alone are now worth over $4 billion!
Naked Security
S3 Ep66: Cybercrime busts, wormable Windows, and the crisis of featuritis [Podcast + Transcript]
By
Paul Ducklin
β January 20
th
2022 at 17:28
Latest epsiode - listen now!
Naked Security
Serious Security: Linux full-disk encryption bug fixed β patch now!
By
Paul Ducklin
β January 14
th
2022 at 21:58
Imagine if someone who didn't have your password could sneakily modify data that was encrypted with it.
Naked Security
Serious Security: OpenSSL fixes βerror conflationβ bugs β how mixing up mistakes can lead to trouble
By
Paul Ducklin
β December 17
th
2021 at 17:57
Have you ever seen the message "An error occurred"? Even worse, the message "This error cannot occur"? Facts matter!
Naked Security
Mozilla patches critical βBigSigβ cryptographic bug: Hereβs how to track it down and fix it
By
Paul Ducklin
β December 3
rd
2021 at 17:58
Mozilla's cryptographic code had a critical bug. Problem is that numerous apps are affected and may need patching individually.
Naked Security
Samba update patches plaintext password plundering problem
By
Paul Ducklin
β November 12
th
2021 at 19:59
When Microsoft itself says STOP USING X, where X is one of its own protocols... we think you should listen.
Naked Security
S3 Ep55: Live malware, global encryption, dating scams, and secret emanations [Podcasts]
By
Paul Ducklin
β October 21
st
2021 at 18:13
Latest episode - listen now! (And sign up for our forthcoming Live Malware Demo at the same time.)
There are no more articles
β
Mark all as read