Security News > 2020 > July

E-Verify’s “SSN Lock” is Nothing of the Sort
2020-07-04 22:24

Enabling this lock is supposed to mean that for the next year thereafter, if an unauthorized individual attempts to fraudulently use a SSN for employment authorization, he or she cannot use the SSN in E-Verify, even if the SSN is that of an employment authorized individual. Password reset questions selected, the site proceeded to ask four, multiple-guess "Knowledge-based authentication" questions to verify my identity.

How to run an SSH connection through Tor
2020-07-04 03:26

Looking for a way to gain a bit more security and privacy for your SSH connections? Jack Wallen shows you how with the help of Tor.

Friday Squid Blogging: Strawberry Squid
2020-07-03 21:07

That's why my teenaged daughter respects me, for many reasons, but an important one being that I respect her and her mother and care deeply for their happiness; another important one is that I've taught her brother to treat her with respect. We live in harmony because we are each careful of how we treat all other human beings.

What are IT pros concerned about in the new normal? Security and flexibility
2020-07-03 19:15

Every company in the world has been forced to change how they work, adopt a new set of applications, and acknowledge the importance of their IT teams. SEE: Working from home: What the new normal looks like, plus remote management tips.

Barclays Bank appeared to be using the Wayback Machine as a 'CDN' for some Javascript
2020-07-03 17:30

Barclays Bank appears to have been using no less than the Internet Archive's Wayback Machine as a "Content distribution network" to serve up a Javascript file. Archive.org went down, it would presumably break Barclays' website as well.

EncroChat Hacked by Police
2020-07-03 15:39

Encrochat took the base unit, installed its own encrypted messaging programs which route messages through the firm's own servers, and even physically removed the GPS, camera, and microphone functionality from the phone. Unbeknownst to Mark, or the tens of thousands of other alleged Encrochat users, their messages weren't really secure.

E.U. Authorities Crack Encryption of Massive Criminal and Murder Network
2020-07-03 15:10

Two months ago investigators in France and the Netherlands cracked the network's encryption, allowing law enforcement to listen in to criminal communications about selling and trafficking drugs, laundering money and murdering rivals, authorities said. The service's owners apparently became aware of the criminal investigation last month, informing an estimated 60,000 users with a message warning them to get rid of their EncroChat devices because their servers-operating out of France - had been "Seized illegally by government entities," according to the NCA. The service relied on EncroChat devices, which came with pre-loaded apps for instant messaging as well as the ability to make secure internet calls, with no other "Conventional smartphone" functionality, U.K. officials said.

Facebook hoaxes back in the spotlight – what to tell your friends
2020-07-03 15:05

It's time to talk about Facebook hoaxes once more. Looking at the Naked Security articles that people have not only searched for but also read in large numbers over the past few days tells us that we're in what you might call a "Market uptick" for hoaxes at the moment.

US Senate Panel OKs Online Child Protection Bill Amid Privacy Fears
2020-07-03 13:10

A US Senate panel Thursday approved legislation aimed at combatting online child exploitation as civil liberties activists warned the measure could lead to an array of constitutional and privacy problems. The Judiciary Committee voted to approve a revised version of the Earn It Act which would eliminate "Blanket liability protection" for online platforms which fail to protect against child sexual abuse material.

Cyberattacks Possibly Involved in Explosions at Iranian Nuclear, Military Facilities
2020-07-03 13:03

Recent fires and explosions at important Iranian facilities may have been caused deliberately as part of an operation that involved cyberattacks, according to reports. There have been several incidents at major Iranian industrial facilities in recent weeks, including a fire at the Natanz nuclear enrichment site and an explosion at the Parchin military complex near Tehran, which is believed to be involved in the production of missiles.