Archive for the 'Security' Category

Foreign Character Friendly Domain Names - Security Threat?

Thursday, March 15th, 2007

Here is an article from BBC about the testing of an enhancement to the current domain name system that allows the use of Internationalized URLs.

The tests were carried out by the Internet Corporation for Assigned Names and Numbers (Icann) that oversees the running of the net’s addressing system. Currently net domains, such as bbc.co.uk, […]

Just Stop Using Google Desktop!

Saturday, February 24th, 2007

Anything that puts too much power into the hands of a single person or entity should be considered corrupting. Information is a lot like power. In this information age, who ever controls a lot of information definitely has a significant amount of power. In the light of this latest Google Desktop exploit (reported by NetworkWorld), […]

More Vishing Coverage: Voice-over-IP Under Fire?

Sunday, January 7th, 2007

Here is an IT obeserver article entitled Voice over IP under threat which talks about the potential problems of Voice-over-IP. The article describes a number of theoretical problems. However, what really stands out is the phishing example.
Let’s imagine a scenario that could become commonplace in the near future: A user has an IP telephony system […]

Vista Insecurity for Sale?

Sunday, December 17th, 2006

eWeek has an article on the alleged sale of MS Windows Vista Zero-Day Exploits. Of course, these are unconfirmed reports but at the prices that are being quoted looks like this is a triving underground industry.
Underground hackers are hawking zero-day exploits for Microsoft’s new Windows Vista operating system at $50,000 a pop, according to computer […]

TWA Boarding Pass Fiasco

Sunday, October 29th, 2006

A poor Indiana University graduate student got raided, put into custody and sued by the US Federal Government. This is in line with his recent posting of a boarding pass generator for NWA (Site was taken down already). Details of the NWA vulnerability can also be found posted by a US Senator here. So […]

Phoolproof Anti-Phishing: Is it really FOOL-proof?

Sunday, September 10th, 2006

NetworkWorld has this interesting article on a Phoolproof Anti-Phishing System. This systems utilizes mobile phones as secure keys for users browsing websites. Interesting? Here is a snippet from NetworldWorld on how it works:
Phoolproof Phishing Prevention system, the program provides strong authentication between the user’s browser and a Web site by using a third party – […]

Token-based Authentication Vulnerable to Phishers

Saturday, July 15th, 2006

Looks like phishers are really being more and more creative these days. Previously, I wrote a number of blog entries about phishing. One particular entry was about a way to use XSS vulnerabilities to beat SSL security which was previously used on Paypal. The scary part is that phisher’s already have started exploiting these […]

It Finally has a Name: Vishing - Voice Phishing

Thursday, July 13th, 2006

A few months ago, I blogged about an article that discusses the use of Voice-over-IP in phishing scams. This NetworkWorld article now gives this kind of phishing a new name. They now call it Voice Phishing or Vishing.
Secure Computing has reported an ingenious new type of phishing scam that uses VoIP telephony to entrap its […]

Microsoft Gets Sued for Windows Genuine Advantage (WGA) Tool

Friday, June 30th, 2006

Microsoft is finally getting into trouble with its Windows Genuine Advantage (WGA) Tool. I covered the possible privacy violations in a previous blog posting. Now, Microsoft is facing a class action suit filled in the US District Court in Seattle for alleged privacy violations.

The suit, filed in U.S. District Court in Seattle on Monday, concerns […]

Beating the Digital Great Wall of China

Wednesday, June 28th, 2006

For many years now, the Chinese Government has been filtering traffic with certain “offending” key words like D-e-m-o-c-r-a-c-y, F-a-l-u-n and many others. This national censorship has been accepted by most of the world as fact. Even large dotcoms such as Google, Yahoo and Microsoft have customized their Chinese search engines to not return results with […]