Saturday, December 6, 2014

Crews maintaining 450 ICBMs had just one wrench with which to attach nuclear warheads



Staff at bases in North Dakota, Wyoming and Montana had to send the toolkit to each other via FedEx, the review found. Mr Hagel said that problem had now been rectified.

Inspectors reportedly ignored the fact that ageing blast doors at nuclear silos would no longer seal shut.

On staffing, the reviews found that a culture of micromanagement and extreme exam-testing distracted from major problems with equipment and nuclear readiness.


Thursday, December 4, 2014

Sony Kept Thousands of Passwords in a Folder Named "Password"


I especially like ALL_SSL_Certs_2012.xlsx!

The second trove of data snuck out sometime yesterday, and it didn't take long for Buzzfeed to stumble upon the Facebook, MySpace (an ancient form of Facebook), YouTube, and Twitter "usernames and passwords for major motion picture social accounts." Likely due to the fact that they were saved in a huge file called "Password." Which contained even more passwords called things like "Facebook login password." So they would know that that was the password. Because who needs encryption or security or common sense or even the vaguest attempt at grade-school level online safety.

Friday, November 28, 2014

Cheap Black Friday Android tablets: Security threats found

 "Bluebox Labs purchased over a dozen of these Black Friday 'bargain' Android tablets from big name retailers like Best Buy, Walmart, Target, Kmart, Kohl's and Staples, and reviewed each of them for security," the company wrote on its blog. "What we found was shocking: most of the devices ship with vulnerabilities and security misconfigurations; a few even include security backdoors. What seemed like great bargains turned out to be big security concerns. Unfortunately, unsuspecting consumers who purchase and use these devices will be putting their mobile data and passwords at risk."

More:
http://bgr.com/2014/11/26/cheap-black-friday-android-tablets/

Tuesday, November 11, 2014

New Attack Method Can Hit 95% Of iOS Devices

 FireEye recommends that organizations warn users to protect themselves three ways. One, users shouldn't install apps from third-party sources other than Apple's official store or an enterprise app store. Two, users shouldn't click on install buttons on a pop-up from third-party web pages. Three, if iOS shows an alert with an "Untrusted App Developer" warning, users should click "Don't Trust" and uninstall the app immediately.

More:
http://www.darkreading.com/new-attack-method-can-hit-95--of-ios-devices/d/d-id/1317359

Saturday, October 25, 2014

IAF asks personnel not to use Xiaomi phones

 IAF personnel and their families have been asked to desist from Chinese 'using Xiaomi Redmi 1s' phones as these are believed to be transferring data to their servers in China and could be a security risk.

"F-secure, a leading security solution company, recently carried out a test of Xiaomi Redmi 1s, the company's budget smartphone, and found that the phone was forwarding carrier name, phone number, IMEI (the device identifier) plus numbers from address book and text messages back to Beijing," says an advisory issued by the IAF to its personnel.

The IAF note, issued some weeks back, has been prepared by the intelligence unit based on the inputs from Indian Computer Emergency Response Team (CERT-In), according to IAF sources.

More:
http://m.timesofindia.com/india/IAF-asks-personnel-not-to-use-Xiaomi-phones/articleshow/44926994.cms

Thursday, October 23, 2014

New Fitbit activity tracker release, price, specs, new features



Here we look at what to expect from the next Fitbit tracker, when it will be available, and what it will cost. We're basing our report on the latest rumours and leaks, historical data, rival trackers, and recent Fitbit trademark applications for a Fitbit Surge, Fitbit Charge and PurePulse. In what may be no coincidence, just weeks after the razzmatazz unveiling of the Apple Watch, first Gizmodo then The Verge suddenly get leaked information each on one of the new trackers.

Fitbit Charge activity tracker leak

New Fitbit Charge and Charge HR trackers: new features – Force replacement and heart-rate monitor


More:
http://mobile.pcadvisor.co.uk/features/gadget/3531709/new-2014-fitbit-surge-charge-activity-tracker-release-date-price-specs-features/

Thursday, October 16, 2014

This POODLE bites: exploiting the SSL 3.0 fallback


SSL 3.0 is nearly 18 years old, but support for it remains widespread. Most importantly, nearly all browsers support it and, in order to work around bugs in HTTPS servers, browsers will retry failed connections with older protocol versions, including SSL 3.0. Because a network attacker can cause connection failures, they can trigger the use of SSL 3.0 and then exploit this issue.

Disabling SSL 3.0 support, or CBC-mode ciphers with SSL 3.0, is sufficient to mitigate this issue, but presents significant compatibility problems, even today. Therefore our recommended response is to support TLS_FALLBACK_SCSV. This is a mechanism that solves the problems caused by retrying failed connections and thus prevents attackers from inducing browsers to use SSL 3.0. It also prevents downgrades from TLS 1.2 to 1.1 or 1.0 and so may help prevent future attacks.

Tuesday, October 14, 2014

Truly scary SSL 3.0 vuln to be revealed soon: sources



Gird your loins, sysadmins: The Register has learned that news of yet another major security vulnerability - this time in SSL 3.0 - is probably imminent.

 

Maintainers have kept quiet about the vulnerability in the lead-up to a patch release expected in in the late European evening, or not far from high noon Pacific Time.

 

Details of the problem are under wraps due to the severity of the vulnerability.

 

To that end it is unknown what platforms were impacted, but as SSL is very widely used any flaw will require plenty of urgent attention ... and probably be unwelcome news to a tech community already reeling from the recent Shellshock vulnerability in Bash and the Heartbleed flaw.

 

The SSL flaw won't be the only thing keeping security bods and system administrators busy. A dangerous worm has been discovered exploiting a zero-day flaw (CVE 2014-4114) in all versions of Microsoft Windows and Server 2008 and 2012.

 

From:

http://www.theregister.co.uk/2014/10/14/nasty_ssl_30_vulnerability_to_drop_tomorrow/?mt=1413288787389

Saturday, October 11, 2014

DEFCON Router Hacking Contest Reveals 15 Major Vulnerabilities



According to the rules of the contest, an entry wasn't considered valid unless the contestant also showed proof of disclosure to the manufacturer. Here's a full list of routers in which 0-days were reported in Track 0, along with our current understanding of the fix in progress:

  • ASUS AC66U; reported, but no response from the manufacturer.
  • Netgear WNDR4700; reported, but no response from the manufacturer.
  • D-LINK 865L; reported, and manufacturer confirms it is working on a fix, currently in beta.
  • Belkin N900; reported, and manufacturer acknowledgedbut was unclear on providing a fix.
  • TRENDnet TEW-812DRU; reported, and manufacturer claims all reported 0-days are fixed.
  • Actiontec Q1000; reported, and manufacturer acknowledged the report.

For details please see the full contest results.

Tuesday, October 7, 2014

OMB gives DHS new powers to scan some civilian agency networks for cyber threats



OMB added this new requirement for DHS to scan civilian agency networks in the aftermath of the Heartbleed vulnerability. During that time, DHS had to get permission from agencies to scan their networks, which delayed its mitigation strategy by a few days.

DHS made it clear in May during a House hearing that it needed Congress to give it more authorities to scan agency networks.

Andy Ozment, the assistant secretary of the Office of Cybersecurity and Communications in DHS, told Federal News Radio in an interview before OMB issued the FISMA guidance that when DHS doesn't have the explicit authorities that it needs and Congress wants them to have, it makes everything harder.

More:

Friday, October 3, 2014

Hackers’ Attack on JPMorgan Chase Affects Millions -



Until just a few weeks ago, executives at JPMorgan said they believed that only one million accounts were affected, according to several people with knowledge of the attacks.

As the severity of the intrusion — which began in June but was not discovered until July — became more clear in recent days, bank executives scrambled for the second time in three months to contain the fallout and to reassure skittish customers that no money had been taken and that their financial information remained secure.

The hackers appeared to have obtained a list of the applications and programs that run on JPMorgan's computers — a road map of sorts — which they could crosscheck with known vulnerabilities in each program and web application, in search of an entry point back into the bank's systems, according to several people with knowledge of the results of the bank's forensics investigation, all of whom spoke on the condition of anonymity.


Saturday, September 27, 2014

43% of companies had a data breach in the past year

 Even in companies that have breach plans in place, employees aren't convinced they will work. Only 30% of those responding to the survey said their organization was "effective or very effective" at creating such plans.

One reason might be that few companies seem to take the need seriously. Of the companies surveyed, just 3% looked at their plan of action each quarter. Thirty-seven percent hadn't reviewed or updated their plan since it was first put in place.

More:
http://www.11alive.com/story/news/2014/09/24/43-of-companies-had-a-data-breach-in-the-past-year/16144167/

Friday, September 19, 2014

World Wide Web inventor slams Internet fast lanes: ‘It’s bribery.’

 "We need rules," said Berners-Lee. "If businesses are to move here and start here rather than start in Europe or Brazil or Australia — they're going to look around and make sure, 'Oh, does the power stay up?' And they'll look for other things. "Is the Internet open?' Will they have to effectively bribe their ISPs to start a new service? That's what it looks like from the outside. It's bribery."

More:
http://www.washingtonpost.com/blogs/the-switch/wp/2014/09/19/world-wide-web-inventor-lashes-out-at-internet-fast-lanes-its-bribery/

CDC: 90% of kids who died last flu season didn't get vaccine


SALT LAKE CITY — The flu took the lives of more than 100 children in the U.S. last flu season, and most of those kids didn't get a flu shot.

That's according to a new report by the Centers of Disease Control and Prevention, aimed to encourage Americans to get vaccinated now. The flu kills up to approximately 36,000 people each year, but less than half of the population gets an annual flu shot. That's something the CDC wants to change.


Saturday, September 6, 2014

The Police Tool That Pervs Use to Steal Nude Pics From Apple’s iCloud



On Tuesday afternoon, Apple issued a statement calling the security debacle a "very targeted attack on user names, passwords and security questions." It added that "none of the cases we have investigated has resulted from any breach in any of Apple's systems including iCloud® or Find my iPhone."

But the conversations on Anon-IB make clear the photo-stealing attacks aren't limited to a few celebrities. And Zdziarski argues that Apple may be defining a "breach" as not including a password-guessing attack like iBrute. Based on his analysis of the metadata from leaked photos of Kate Upton, he says he's determined that the photos came from a downloaded backup that would be consistent with the use of iBrute and EPPB. If a full device backup was accessed, he believes the rest of the backup's data may still be possessed by the hacker and could be used for blackmail or finding other targets. "You don't get the same level of access by logging into someone's [web] account as you can by emulating a phone that's doing a restore from an iCloud backup," says Zdziarski. "If we didn't have this law enforcement tool, we might not have the leaks we had."

Friday, September 5, 2014

US Air Force admits to quietly changing a regulation that now requires all personnel to swear an oath to God -- Airmen denied reenlistment for practicing constitutional rights

 ...
The Air Force said it cannot change its AFI to make "so help me God" optional unless Congress changes the statute mandating it.

Miller pointed out that Article VI of the Constitution prohibits requiring religious tests to hold an office or public trust.

"Forcing [the airman] to swear to a supreme being as a condition of his reenlistment is tantamount to a 'religious test' and is therefore violative of this constitutional provision as well," Miller said
...

More:
http://www.airforcetimes.com/article/20140904/NEWS05/309040066/Group-Airman-denied-reenlistment-refusing-say-help-me-God-

Thursday, September 4, 2014

Well, isn't that special... Army can't track spending on $4.3b system to track spending, IG finds



The problem, according to the IG, is that the Army has failed to comply with a variety of federal laws that require agencies to standardize reporting and prepare auditable financial statements.

"This occurred because DOD and Army management did not have adequate controls, including procedures and annual reviews, in place to ensure GCSS-Army compliance with Treasury and DOD guidance," the IG report concludes.

"Although Army personnel have been responsive to correcting deficiencies identified during the audit, the Army has spent $725.7 million on a system that still has significant obstacles to overcome" to comply with federal financial reporting laws.


Tuesday, September 2, 2014

Apple says iCloud is safe and secure, stolen celebrity pics were targeted accounts

 Apple said it has completed more than 40 hours of investigation to date, and found that the iCloud accounts in question were compromised based on practices that are "all too common on the Internet."

The company's statement dispels rumors that a wider exploit of its iCloud services, including the Find My iPhone function, played a part in the leaks. Apple recommends that its users employ a strong password, and also enable two-step verification to maximize security.

More:
http://appleinsider.com/articles/14/09/02/apple-says-icloud-is-safe-and-secure-stolen-celebrity-pics-were-targeted

Monday, September 1, 2014

Android security mystery - 'fake’ cellphone towers found in U.S.



"What we find suspicious is that a lot of these interceptors are right on top of U.S. military bases." says Goldsmith.  "Whose interceptor is it?  Who are they, that's listening to calls around military bases?  The point is: we don't really know whose they are."

Baseband attacks are considered extremely difficult – the details of the chips are closely guarded. "Interceptors" are costly devices – and hacking baseband chips is thought to be technically advanced beyond the reach of "ordinary" hackers, ESD says. The devices vary in form, and are sold to government agencies and others, but are computers with specialized software designed to defeat the encryption of cellphone networks. The towers target the "Baseband" operating system of cellphones – a secondary OS which sits "between" iOS or Android, for instance, and the cellular network.