Thursday, September 28, 2006

Contactless Cards: Are Privacy Jitters Legit?

While the cards are a boon to merchants and are part of a large new RFID industry -- from manufacturers who make the tags and readers to software companies that create data analytics for ROI -- the technology also presents some security concerns as merchants may have the ability to track goods and services more closely than some would like.

You can read more about it here.

Sunday, September 24, 2006

Worried about the airline losing your luggage? No problem. Just pack a gun.

The airline wouldn't want to be responsible for losing a gun, right? That's one photographer's solution to making sure his expensive camera equipment is watched carefully by the airline when he has to check it as luggage. He packs a starter pistol in his camera bag and declares it as a firearm.

You can read more about it here.

Thursday, September 21, 2006

Two Serious Windows Flaws Uncovered

The first is a zero day exploit that affects Internet Explorer (and Outlook) even on fully patched copies of Windows XP. The second is a file corruption bug in Windows 2000 introduced by a Microsoft patch. Steve Gibson has fixes for both in his Security Now podcast, plus an interview with the fellow who discovered the VWL exploti.

You can read more about it here.

Wednesday, September 20, 2006

Watching a phishing attack live

Yesterday, I watched a phishing attack unfold live. After informing the phished bank and US CERT I was able to see in real time the details people entered on the phishers site. Here's what I saw.

You can read more about it here.

Tuesday, September 19, 2006

AG Gonzales Wants ISPs to Save User Data

Attorney General Alberto Gonzales said Tuesday that Congress should require Internet service providers to preserve customer records. Gonzales acknowledged the concerns of some who say legislation might be overly intrusive and encroach on privacy rights, but argued that prosecutors need them to fight child pornography.

You can read more about it here.

Diebold Vote Hack - CNN Video

CNN explores the possibility of midterm e-vote hacks. You should wonder why elections boards across the US aren't doing anything to address the numerous problems with paperless electronic voting machines. These machines, primarily made by Diebold, leave no paper trail, there is no way to verify votes!

You can read more about it here.

#1 Secutiry Threat: Cross-site scripting

Web administrators beware: cross-site scripting vulnerabilities are now far more attractive targets than more notorious bugs such as buffer overflows. Buffer overflows have long been one of the most common types of bugs attacked by malware, with Intel and AMD even building in hardware support for an anti-buffer overflow technology.

You can read more about it here.