Login
FreshRSS
Login
Naked Security
Smart light bulbs could give away your password secrets
By
Paul Ducklin
β August 22
nd
2023 at 19:56
Cryptography isn't just about secrecy. You need to take care of authenticity (no imposters!) and integrity (no tampering!) as well.
Naked Security
S3 Ep147: What if you type in your password during a meeting?
By
Paul Ducklin
β August 10
th
2023 at 13:34
Latest episode - listen now! (Full transcript inside.)
Naked Security
βCrocodile of Wall Streetβ and her husband plead guilty to giant-sized cryptocrimes
By
Paul Ducklin
β August 4
th
2023 at 16:52
Sentences still to be decided, but she could get up to 10 years and he could get as many as 20.
Naked Security
S3 Ep145: Bugs With Impressive Names!
By
Paul Ducklin
β July 27
th
2023 at 18:47
Fascinating fun (with a serious and educational side) - listen now! Full transcript available inside.
Naked Security
Hacking police radios: 30-year-old crypto flaws in the spotlight
By
Paul Ducklin
β July 24
th
2023 at 16:59
"Three may keep a secret, if two of them are dead."
Naked Security
S3 Ep144: When threat hunting goes down a rabbit hole
By
Paul Ducklin
β July 20
th
2023 at 14:58
Latest episode - check it out now!
Naked Security
Google Virus Total leaks list of spooky email addresses
By
Paul Ducklin
β July 18
th
2023 at 23:16
Careful with that file, Eugene!
Naked Security
Microsoft hit by Storm season β a tale of two semi-zero days
By
Paul Ducklin
β July 18
th
2023 at 20:59
The first compromise didn't get the crooks as far as they wanted, so they found a second one that did...
Naked Security
S3 Ep141: What was Steve Jobsβs first job?
By
Paul Ducklin
β June 29
th
2023 at 16:58
Latest episode - listen now! (Full transcript inside.)
Naked Security
UK hacker busted in Spain gets 5 years over Twitter hack and more
By
Naked Security writer
β June 26
th
2023 at 18:35
Not just that infamous Twitter hack, but SIM-swapping, stalking and swatting too...
Naked Security
Beware bad passwords as attackers co-opt Linux servers into cybercrime
By
Paul Ducklin
β June 21
st
2023 at 19:50
Did you prevent password-only logins on your SSH servers? On ALL of them? Are you sure about that?
Naked Security
History revisited: US DOJ unseals Mt. Gox cybercrime charges
By
Naked Security writer
β June 12
th
2023 at 16:58
Though the mills of the Law grind slowly/Yet they grind exceeding small/Though with patience they stand waiting/With exactness grind they all...
Naked Security
S3 Ep137: 16th century crypto skullduggery
By
Paul Ducklin
β June 1
st
2023 at 16:45
Lots to learn, clearly explained in plain English... listen now! (Full transcript inside.)
s3-ep137-feat-1200
Naked Security
Google leaking 2FA secrets β researchers advise against new βaccount syncβ feature for now
By
Paul Ducklin
β April 26
th
2023 at 17:59
You waited 13 years for this feature in Google Authenticator. Now researchers are advising you to wait a while longer, just in case...
Naked Security
Ex-CEO of breached pyschotherapy clinic gets prison sentence for bad data security
By
Paul Ducklin
β April 18
th
2023 at 16:56
Did the sentence fit the crime? Read the backstory, and then have your say in our comments! (You may post anonymously.)
Naked Security
Attention gamers! Motherboard maker MSI admits to breach, issues βrogue firmwareβ alert
By
Paul Ducklin
β April 11
th
2023 at 18:58
Stealing private keys is like getting hold of a medieval monarch's personal signet ring... you get to put an official seal on treasonous material.
Naked Security
S3 Ep127: When you chop someone out of a photo, but there they are anywayβ¦
By
Paul Ducklin
β March 23
rd
2023 at 17:59
Listen now - latest episode. Full transcript inside.
Naked Security
Windows 11 also vulnerable to βaCropalypseβ image data leakage
By
Paul Ducklin
β March 22
nd
2023 at 17:59
Turns out that the Windows 11 Snipping Tool has the same "aCropalypse" data leakage bug as Pixel phones. Here's how to work around the problem...
Naked Security
Bitcoin ATM customers hacked by video upload that was actually an app
By
Paul Ducklin
β March 20
th
2023 at 19:50
As the misquote goes, "Once is misfortune..." This is the second time, and you know what Lady Bracknell had to say about that...
Naked Security
S3 Ep125: When security hardware has security holes [Audio + Text]
By
Paul Ducklin
β March 9
th
2023 at 18:58
Lastest episode - listen now! (Full transcript inside.)
Naked Security
Serious Security: TPM 2.0 vulns β is your super-secure data at risk?
By
Paul Ducklin
β March 7
th
2023 at 19:59
Security bugs in the very code you've been told you must have to improve the security of your computer...
Naked Security
DoppelPaymer ransomware supsects arrested in Germany and Ukraine
By
Naked Security writer
β March 6
th
2023 at 16:16
Devices seized, suspects interrogated and arrested, allegedly connected to devastating cyberattack on University Hospital in DΓΌsseldorf.
Naked Security
S3 Ep124: When so-called security apps go rogue [Audio + Text]
By
Paul Ducklin
β March 2
nd
2023 at 19:40
Rogue software packages. Rogue "sysadmins". Rogue keyloggers. Rogue authenticators. Rogue ROGUES!
s3-ep124-auth--1200
Naked Security
Dutch police arrest three cyberextortion suspects who allegedly earned millions
By
Naked Security writer
β February 27
th
2023 at 19:33
Ever paid hush money to crooks who broke into your network? Wondered how much you can trust them?
Naked Security
Beware rogue 2FA apps in App Store and Google Play β donβt get hacked!
By
Paul Ducklin
β February 27
th
2023 at 02:10
Even in Apple's and Google's "walled gardens", there are plenty of 2FA apps that are either dangerously incompetent, or unrepentantly malicious. (Or perhaps both.)
Naked Security
S3 Ep123: Crypto company compromise kerfuffle [Audio + Text]
By
Paul Ducklin
β February 23
rd
2023 at 19:58
Latest episode - listen now! Top-notch advice for cybersecurity, both at work and at home.
Naked Security
Coinbase breached by social engineers, employee data stolen
By
Paul Ducklin
β February 21
st
2023 at 17:58
Another day, another "sophisticated" attack. This time, the company has handily included some useful advice along with its mea culpa...
Naked Security
Twitter tells users: Pay up if you want to keep using insecure 2FA
By
Paul Ducklin
β February 20
th
2023 at 17:58
Ironically, Twitter Blue users will be allowed to keep using the very 2FA process that's not considered secure enough for everyone else.
Naked Security
Serious Security: GnuTLS follows OpenSSL, fixes timing attack bug
By
Paul Ducklin
β February 13
th
2023 at 17:59
Conditional code considered cryptographically counterproductive.
Naked Security
OpenSSL fixes High Severity data-stealing bug β patch now!
By
Paul Ducklin
β February 8
th
2023 at 02:58
7 memory mismanagements and a timing attack. We explain all the jargon bug terminology in plain English...
Naked Security
Tracers in the Dark: The Global Hunt for the Crime Lords of Crypto
By
Paul Ducklin
β February 6
th
2023 at 21:53
Hear renowned cybersecurity author Andy Greenberg's thoughtful commentary about the "war on crypto" as we talk to him about his new book...
Naked Security
Finnish psychotherapy extortion suspect arrested in France
By
Naked Security writer
β February 6
th
2023 at 19:13
Company transcribed ultra-personal conversations, didn't secure them. Criminal stole them, then extorted thousands of vulnerable patients.
Naked Security
S3 Ep120: When dud crypto simply wonβt let go [Audio + Text]
By
Paul Ducklin
β February 2
nd
2023 at 17:50
Latest episode - listen now!
Naked Security
Password-stealing βvulnerabilityβ reported in KeePass β bug or feature?
By
Paul Ducklin
β February 1
st
2023 at 19:58
Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?
Naked Security
Serious Security: The Samba logon bug caused by outdated crypto
By
Paul Ducklin
β January 30
th
2023 at 19:59
Enjoy our Serious Security deep dive into this real-world example of why cryptographic agility is important!
Naked Security
S3 Ep119: Breaches, patches, leaks and tweaks! [Audio + Text]
By
Paul Ducklin
β January 26
th
2023 at 19:57
Lastest episode - listen now! (Or read the transcript.)
Naked Security
GoTo admits: Customer cloud backups stolen together with decryption key
By
Paul Ducklin
β January 25
th
2023 at 01:37
We were going to write, "Once more unto the breach, dear friends, once more"... but it seems to go without saying these days.
Naked Security
S3 Ep118: Guess your password? No need if itβs stolen already! [Audio + Text]
By
Paul Ducklin
β January 19
th
2023 at 15:53
As always: entertaining, informative and educational... and not bogged down with jargon! Listen (or read) now...
Naked Security
Serious Security: Unravelling the LifeLock βhacked passwordsβ story
By
Paul Ducklin
β January 17
th
2023 at 17:59
Four straight-talking tips to improve your online security, whether you're a LifeLock customer or not.
Naked Security
Multi-million investment scammers busted in four-country Europol raid
By
Paul Ducklin
β January 16
th
2023 at 16:10
216 questioned, 15 arrested, 4 fake call centres searched, millions seized...
Naked Security
S3 Ep117: The crypto crisis that wasnβt (and farewell forever to Win 7) [Audio + Text]
By
Paul Ducklin
β January 12
th
2023 at 17:59
Tell us in the comments... What's the REAL reason there was no Windows 9? (No theory too far-fetched!)
Naked Security
Popular JWT cloud security library patches βremoteβ code execution hole
By
Paul Ducklin
β January 10
th
2023 at 19:59
It's remotely triggerable, but attackers would already have pretty deep network access if they could "prime" your server for compromise.
Naked Security
RSA crypto cracked? Or perhaps not!
By
Paul Ducklin
β January 6
th
2023 at 19:59
Stand down from blue alert, it seems... but why not plan your cryptographic agility anyway?
Naked Security
S3 Ep116: Last straw for LastPass? Is crypto doomed? [Audio + Text]
By
Paul Ducklin
β January 5
th
2023 at 17:52
Lots of big issues this week: breaches, encryption, supply chains and patching problems. Listen now! (Full transcript inside.)
Naked Security
Serious Security: How to improve cryptography, resist supply chain attacks, and handle data breaches
By
Paul Ducklin
β January 4
th
2023 at 19:50
Lessons for us all: improve cryptography, fight cybercrime, own your supply chain... and don't steal my data and then pretend you're sorry.
Naked Security
Inside a scammersβ lair: Ukraine busts 40 in fake bank call-centre raid
By
Naked Security writer
β January 3
rd
2023 at 17:03
When someone calls you up to warn you that your bank account is under attack - it's true, because THAT VERY PERSON is the one attacking you!
Naked Security
PyTorch: Machine Learning toolkit pwned from Christmas to New Year
By
Paul Ducklin
β January 1
st
2023 at 21:36
The bad news: the crooks have your SSH private keys. The good news: only users of the "nightly" build were affected.
Naked Security
US passes the Quantum Computing Cybersecurity Preparedness Act β and why not?
By
Paul Ducklin
β December 29
th
2022 at 20:45
Cryptographic agility: the ability and the willingness to change quickly when needed.
sc-daa-1200
Naked Security
Twitter data of β+400 million unique usersβ up for sale β what to do?
By
Paul Ducklin
β December 28
th
2022 at 19:59
If the crooks have connected up your phone number and your Twitter handle... what could go wrong?
Naked Security
OneCoin scammer Sebastian Greenwood pleads guilty, βCryptoqueenβ still missing
By
Paul Ducklin
β December 19
th
2022 at 19:50
The Cryptoqueen herself is still missing, but her co-conspirator, who is said to have pocketed over $20m a month, has been convicted.
Naked Security
SIM swapper sent to prison for 2FA cryptocurrency heist of over $20m
By
Naked Security writer
β December 6
th
2022 at 17:56
Guilty party got 18 months, also has to pay back $20m he probably hasn't got, which could land him in more hot water.
Naked Security
S3 Ep111: The business risk of a sleazy βnudity unfilterβ [Audio + Text]
By
Paul Ducklin
β December 1
st
2022 at 19:58
Latest episode - listen now (or read if you prefer)...
Naked Security
Serious Security: MD5 considered harmful β to the tune of $600,000
By
Paul Ducklin
β November 30
th
2022 at 17:58
It's not just the hashing, by the way. It's the salting and the stretching, too!
Naked Security
TikTok βInvisible Challengeβ porn malware puts us all at risk
By
Paul Ducklin
β November 29
th
2022 at 19:58
An injury to one is an injury to all. Especially if the other people are part of your social network.
Naked Security
Multimillion dollar CryptoRom scam sites seized, suspects arrested in US
By
Paul Ducklin
β November 23
rd
2022 at 19:58
Five tips to keep yourself, and your friends and family, out of the clutches of "chopping block" scammers...
cryptorom-1200
Naked Security
S3 Ep108: You hid THREE BILLION dollars in a popcorn tin?
By
Paul Ducklin
β November 10
th
2022 at 17:26
Patches, busts, leaks and why even low-likelihood exploits can be high-severity risks - listen now!
Naked Security
Silk Road drugs market hacker pleads guilty, faces 20 years inside
By
Paul Ducklin
β November 8
th
2022 at 19:58
Jurisprudence isn't like arithmetic... two negatives never make a positive!
Naked Security
Twitter Blue Badge email scams β Donβt fall for them!
By
Naked Security writer
β November 4
th
2022 at 17:59
That was the week that was...
Naked Security
S3 Ep107: Eight months to kick out the crooks and you think thatβs GOOD? [Audio + Text]
By
Paul Ducklin
β November 3
rd
2022 at 17:51
Listen now - latest episode - audio plus full transcript
Naked Security
The OpenSSL security update story β how can you tell what needs fixing?
By
Paul Ducklin
β November 3
rd
2022 at 00:44
How to Hack! Finding OpenSSL library files and accurately identifying their version numbers...
ossl-code-1200
Load more articles