FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

S3 Ep147: What if you type in your password during a meeting?

By Paul Ducklin β€” August 10th 2023 at 13:34
Latest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

S3 Ep145: Bugs With Impressive Names!

By Paul Ducklin β€” July 27th 2023 at 18:47
Fascinating fun (with a serious and educational side) - listen now! Full transcript available inside.

☐ β˜† βœ‡ Naked Security

Hacking police radios: 30-year-old crypto flaws in the spotlight

By Paul Ducklin β€” July 24th 2023 at 16:59
"Three may keep a secret, if two of them are dead."

☐ β˜† βœ‡ Naked Security

Microsoft hit by Storm season – a tale of two semi-zero days

By Paul Ducklin β€” July 18th 2023 at 20:59
The first compromise didn't get the crooks as far as they wanted, so they found a second one that did...

☐ β˜† βœ‡ Naked Security

S3 Ep137: 16th century crypto skullduggery

By Paul Ducklin β€” June 1st 2023 at 16:45
Lots to learn, clearly explained in plain English... listen now! (Full transcript inside.)

s3-ep137-feat-1200

☐ β˜† βœ‡ Naked Security

S3 Ep125: When security hardware has security holes [Audio + Text]

By Paul Ducklin β€” March 9th 2023 at 18:58
Lastest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Serious Security: TPM 2.0 vulns – is your super-secure data at risk?

By Paul Ducklin β€” March 7th 2023 at 19:59
Security bugs in the very code you've been told you must have to improve the security of your computer...

☐ β˜† βœ‡ Naked Security

DoppelPaymer ransomware supsects arrested in Germany and Ukraine

By Naked Security writer β€” March 6th 2023 at 16:16
Devices seized, suspects interrogated and arrested, allegedly connected to devastating cyberattack on University Hospital in DΓΌsseldorf.

☐ β˜† βœ‡ Naked Security

S3 Ep124: When so-called security apps go rogue [Audio + Text]

By Paul Ducklin β€” March 2nd 2023 at 19:40
Rogue software packages. Rogue "sysadmins". Rogue keyloggers. Rogue authenticators. Rogue ROGUES!

s3-ep124-auth--1200

☐ β˜† βœ‡ Naked Security

Beware rogue 2FA apps in App Store and Google Play – don’t get hacked!

By Paul Ducklin β€” February 27th 2023 at 02:10
Even in Apple's and Google's "walled gardens", there are plenty of 2FA apps that are either dangerously incompetent, or unrepentantly malicious. (Or perhaps both.)

☐ β˜† βœ‡ Naked Security

Serious Security: GnuTLS follows OpenSSL, fixes timing attack bug

By Paul Ducklin β€” February 13th 2023 at 17:59
Conditional code considered cryptographically counterproductive.

☐ β˜† βœ‡ Naked Security

OpenSSL fixes High Severity data-stealing bug – patch now!

By Paul Ducklin β€” February 8th 2023 at 02:58
7 memory mismanagements and a timing attack. We explain all the jargon bug terminology in plain English...

☐ β˜† βœ‡ Naked Security

Tracers in the Dark: The Global Hunt for the Crime Lords of Crypto

By Paul Ducklin β€” February 6th 2023 at 21:53
Hear renowned cybersecurity author Andy Greenberg's thoughtful commentary about the "war on crypto" as we talk to him about his new book...

☐ β˜† βœ‡ Naked Security

S3 Ep120: When dud crypto simply won’t let go [Audio + Text]

By Paul Ducklin β€” February 2nd 2023 at 17:50
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Password-stealing β€œvulnerability” reported in KeePass – bug or feature?

By Paul Ducklin β€” February 1st 2023 at 19:58
Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?

☐ β˜† βœ‡ Naked Security

Serious Security: The Samba logon bug caused by outdated crypto

By Paul Ducklin β€” January 30th 2023 at 19:59
Enjoy our Serious Security deep dive into this real-world example of why cryptographic agility is important!

☐ β˜† βœ‡ Naked Security

GoTo admits: Customer cloud backups stolen together with decryption key

By Paul Ducklin β€” January 25th 2023 at 01:37
We were going to write, "Once more unto the breach, dear friends, once more"... but it seems to go without saying these days.

☐ β˜† βœ‡ Naked Security

Serious Security: Unravelling the LifeLock β€œhacked passwords” story

By Paul Ducklin β€” January 17th 2023 at 17:59
Four straight-talking tips to improve your online security, whether you're a LifeLock customer or not.

☐ β˜† βœ‡ Naked Security

S3 Ep117: The crypto crisis that wasn’t (and farewell forever to Win 7) [Audio + Text]

By Paul Ducklin β€” January 12th 2023 at 17:59
Tell us in the comments... What's the REAL reason there was no Windows 9? (No theory too far-fetched!)

☐ β˜† βœ‡ Naked Security

Popular JWT cloud security library patches β€œremote” code execution hole

By Paul Ducklin β€” January 10th 2023 at 19:59
It's remotely triggerable, but attackers would already have pretty deep network access if they could "prime" your server for compromise.

☐ β˜† βœ‡ Naked Security

RSA crypto cracked? Or perhaps not!

By Paul Ducklin β€” January 6th 2023 at 19:59
Stand down from blue alert, it seems... but why not plan your cryptographic agility anyway?

☐ β˜† βœ‡ Naked Security

S3 Ep116: Last straw for LastPass? Is crypto doomed? [Audio + Text]

By Paul Ducklin β€” January 5th 2023 at 17:52
Lots of big issues this week: breaches, encryption, supply chains and patching problems. Listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Serious Security: How to improve cryptography, resist supply chain attacks, and handle data breaches

By Paul Ducklin β€” January 4th 2023 at 19:50
Lessons for us all: improve cryptography, fight cybercrime, own your supply chain... and don't steal my data and then pretend you're sorry.

☐ β˜† βœ‡ Naked Security

US passes the Quantum Computing Cybersecurity Preparedness Act – and why not?

By Paul Ducklin β€” December 29th 2022 at 20:45
Cryptographic agility: the ability and the willingness to change quickly when needed.

sc-daa-1200

☐ β˜† βœ‡ Naked Security

Serious Security: MD5 considered harmful – to the tune of $600,000

By Paul Ducklin β€” November 30th 2022 at 17:58
It's not just the hashing, by the way. It's the salting and the stretching, too!

☐ β˜† βœ‡ Naked Security

The OpenSSL security update story – how can you tell what needs fixing?

By Paul Ducklin β€” November 3rd 2022 at 00:44
How to Hack! Finding OpenSSL library files and accurately identifying their version numbers...

ossl-code-1200

☐ β˜† βœ‡ Naked Security

OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway!

By Paul Ducklin β€” November 1st 2022 at 17:24
That bated-breath OpenSSL update is out! It's no longer rated CRITICAL, but we advise you to patch ASAP anyway. Here's why...

☐ β˜† βœ‡ Naked Security

SHA-3 code execution bug patched in PHP – check your version!

By Paul Ducklin β€” November 1st 2022 at 14:09
As everyone waits for news of a bug in OpenSSL, here's a reminder that other cryptographic code in your life may also need patching!

☐ β˜† βœ‡ Naked Security

S3 Ep106: Facial recognition without consent – should it be banned?

By Paul Ducklin β€” October 27th 2022 at 16:59
Latest episode - listen (or read) now. Teachable moments for X-Ops professionals!

☐ β˜† βœ‡ Naked Security

Serious Security: How randomly (or not) can you shuffle cards?

By Paul Ducklin β€” October 24th 2022 at 18:57
What if you could guess the next card correctly twice as often as you should?

card-fan-1200

☐ β˜† βœ‡ Naked Security

S3 Ep105: WONTFIX! The MS Office cryptofail that β€œisn’t a security flaw” [Audio + Text]

By Paul Ducklin β€” October 20th 2022 at 18:54
The coolest video game ever! And lots of solid cybersecurity advice - listen now!

pic-1200

☐ β˜† βœ‡ Naked Security

Women in Cryptology – USPS celebrates WW2 codebreakers

By Paul Ducklin β€” October 19th 2022 at 16:58
What did you do in the war, Mom? Oh, y'know, a bit of this and that...

☐ β˜† βœ‡ Naked Security

Serious Security: Microsoft Office 365 attacked over feeble encryption

By Paul Ducklin β€” October 14th 2022 at 16:59
How 2022 is your encryption?

☐ β˜† βœ‡ Naked Security

Serious Security: OAuth 2 and why Microsoft is finally forcing you into it

By Paul Ducklin β€” October 10th 2022 at 18:02
Microsoft calls it "Modern Auth", though it's a decade old, and is finally forcing Exchange Online customers to switch to it.

☐ β˜† βœ‡ Naked Security

S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, healthcare security [Audio + Text]

By Paul Ducklin β€” August 18th 2022 at 18:38
Latest episode - listen now (or read if you prefer!)

☐ β˜† βœ‡ Naked Security

S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]

By Paul Ducklin β€” August 11th 2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)

☐ β˜† βœ‡ Naked Security

APIC/EPIC! Intel chips leak secrets even the kernel shouldn’t see…

By Paul Ducklin β€” August 10th 2022 at 16:59
If you've ever written code that left stuff lying around in memory when you didn't need it any more... we bet you've regretted it!

☐ β˜† βœ‡ Naked Security

Slack admits to leaking hashed passwords for five years

By Paul Ducklin β€” August 8th 2022 at 15:14
"When those invitations went out... somehow, your password hash went out with them."

☐ β˜† βœ‡ Naked Security

S3 Ep94: This sort of crypto (graphy), and the other sort of crypto (currency!) [Audio + Text]

By Paul Ducklin β€” August 4th 2022 at 17:52
Latest episode - listen now! (Or read if that's what you prefer.)

☐ β˜† βœ‡ Naked Security

Post-quantum cryptography – new algorithm β€œgone in 60 minutes”

By Paul Ducklin β€” August 3rd 2022 at 18:55
And THIS is why you don't knit your own home-made encryption algorithms and hope no one looks at them.

☐ β˜† βœ‡ Naked Security

Cryptocoin β€œtoken swapper” Nomad loses $200 million in coding blunder

By Paul Ducklin β€” August 2nd 2022 at 16:12
Transactions were only approved, it seems, if they were initiated by... errrrr, by anyone.

☐ β˜† βœ‡ Naked Security

GnuTLS patches memory mismanagement bug – update now!

By Paul Ducklin β€” August 1st 2022 at 16:55
GnuTLS may well be the most widespread cryptographic toolkit you've never heard of. Learn more...

☐ β˜† βœ‡ Naked Security

S3 Ep91: CodeRed, OpenSSL, Java bugs, Office macros [Audio + Text]

By Paul Ducklin β€” July 14th 2022 at 18:47
Latest episode - listen now! Great discussion, technical content, solid advice... all covered in plain English.

☐ β˜† βœ‡ Naked Security

OpenSSL fixes two β€œone-liner” crypto bugs – what you need to know

By Paul Ducklin β€” July 6th 2022 at 16:52
"As bad as Heartbleed"? We heard that concern a week ago, but we think it's less ungood than that...

☐ β˜† βœ‡ Naked Security

S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix [Podcast + Transcript]

By Paul Ducklin β€” June 30th 2022 at 12:57
Latest episode - listen and read now! Use our advice to advise your own friends and family... let's all do our bit to stand up to scammers!

☐ β˜† βœ‡ Naked Security

OpenSSL issues a bugfix for the previous bugfix

By Paul Ducklin β€” June 24th 2022 at 15:32
Fortunately, it's not a major bugfix, which means it's easy to patch and can teach us all some useful lessons.

☐ β˜† βœ‡ Naked Security

He sold cracked passwords for a living – now he’s serving 4 years in prison

By Paul Ducklin β€” May 13th 2022 at 18:31
Crooks don't need a password for every user on your network to break in and wreak havoc. One could be enough...

☐ β˜† βœ‡ Naked Security

S3 Ep79: Chrome hole, a bad place for a cybersecurity holiday, and crypto-dodginess [Podcast]

By Paul Ducklin β€” April 21st 2022 at 13:41
Do you know your Adam Osborne from your John Osbourne? Your Z80 from your 6502? Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Critical cryptographic Java security blunder patched – update now!

By Paul Ducklin β€” April 20th 2022 at 16:43
Either know the private key and use it scrupulously in your digital signature calculation.... or just send a bunch of zeros instead.

☐ β˜† βœ‡ Naked Security

S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]

By Paul Ducklin β€” April 14th 2022 at 13:39
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

OpenSSH goes Post-Quantum, switches to qubit-busting crypto by default

By Paul Ducklin β€” April 11th 2022 at 16:58
Useful quantum computers might not actually be possible. But what if they are? And what if they arrive, say, tomorrow?

cat-1200

☐ β˜† βœ‡ Naked Security

S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]

By Paul Ducklin β€” March 24th 2022 at 13:49
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

OpenSSL patches infinite-loop DoS bug in certificate verification

By Paul Ducklin β€” March 18th 2022 at 17:59
When it comes to writing loops in your code... never sit on the fence!

☐ β˜† βœ‡ Naked Security

Self-styled β€œCrocodile of Wall Street” arrested with husband over Bitcoin megaheist

By Naked Security writer β€” February 9th 2022 at 14:44
The cops say they've recovered 80% of a $72 million cryptocoin heist... but the recovered funds alone are now worth over $4 billion!

☐ β˜† βœ‡ Naked Security

S3 Ep66: Cybercrime busts, wormable Windows, and the crisis of featuritis [Podcast + Transcript]

By Paul Ducklin β€” January 20th 2022 at 17:28
Latest epsiode - listen now!

☐ β˜† βœ‡ Naked Security

Serious Security: Linux full-disk encryption bug fixed – patch now!

By Paul Ducklin β€” January 14th 2022 at 21:58
Imagine if someone who didn't have your password could sneakily modify data that was encrypted with it.

☐ β˜† βœ‡ Naked Security

Serious Security: OpenSSL fixes β€œerror conflation” bugs – how mixing up mistakes can lead to trouble

By Paul Ducklin β€” December 17th 2021 at 17:57
Have you ever seen the message "An error occurred"? Even worse, the message "This error cannot occur"? Facts matter!

☐ β˜† βœ‡ Naked Security

Mozilla patches critical β€œBigSig” cryptographic bug: Here’s how to track it down and fix it

By Paul Ducklin β€” December 3rd 2021 at 17:58
Mozilla's cryptographic code had a critical bug. Problem is that numerous apps are affected and may need patching individually.

☐ β˜† βœ‡ Naked Security

Samba update patches plaintext password plundering problem

By Paul Ducklin β€” November 12th 2021 at 19:59
When Microsoft itself says STOP USING X, where X is one of its own protocols... we think you should listen.

☐ β˜† βœ‡ Naked Security

S3 Ep55: Live malware, global encryption, dating scams, and secret emanations [Podcasts]

By Paul Ducklin β€” October 21st 2021 at 18:13
Latest episode - listen now! (And sign up for our forthcoming Live Malware Demo at the same time.)

❌