Security News

Secret-sharing app Whisper shared secrets like last known location and actual password tokens in exposed database
2020-03-11 13:42

Whisper, a mobile app for sharing those thoughts you'd rather not make public, turns out to be better at sharing secrets than keeping them, spilling a whopping 90 metadata fields associated with users in an exposed database. In a phone interview with The Register, Dan Ehrlich, security consultant with Twelve Security, said colleague Matt Porter had spotted the unprotected Whisper ElasticSearch database.

OpenSSH eases admin hassles with FIDO U2F token support
2020-02-19 11:00

OpenSSH version 8.2 is out and the big news is that the world's most popular remote management software now supports authentication using any FIDO U2F hardware token. Adding support inside OpenSSH simply means that any U2F token can now be used, including older FIDO1 and more recent FIDO2 hardware.

YouTube ‘influencers’ get 2FA tokens phished
2019-09-24 14:50

100K or so creators in the YouTube car community were targeted by a phishing campaign that captured 2FA codes.

GitHub Now Scans Commits for Atlassian, Dropbox, Discord Tokens
2019-08-20 08:39

Microsoft-owned GitHub on Monday announced that its token scanning service will also check commits for Atlassian, Dropbox, Discord, Proctorio and Pulumi tokens that have been accidentally shared. read more

IOTA develops Trinity, a secure software wallet for IOTA tokens
2019-07-04 04:00

IOTA Foundation, a non-profit foundation focused on distributed ledger technology (DLT) and open-source ecosystem development, announced the release of Trinity, a secure software wallet for IOTA...

Yubico recalls FIPS Yubikey tokens after flaw found
2019-06-17 11:28

Security token maker Yubico has issued an important advisory affecting high-end versions of its YubiKey authentication key.

Yubico YubiKey lets you be me: Security blunder sparks recall of govt-friendly auth tokens
2019-06-13 21:57

For FIPS sake! Yubico is recalling one of its YubiKey lines after the authentication dongles were found to have a security weakness.…

On Security Tokens
2019-05-01 11:14

Mark Risher of Google extols the virtues of security keys: I'll say it again for the people in the back: with Security Keys, instead of the *user* needing to verify the site, the *site* has to...

Attackers breached Docker Hub, grabbed keys and tokens
2019-04-29 11:23

Docker, the company behing the popular virtualization tool bearing the same name, has announced late on Friday that it has suffered a security breach. There was no official public announcement....

Android phones transformed into anti-phishing security tokens
2019-04-12 10:39

A new security feature allows users of Android 7 and later to use their smartphones to authenticate themselves to their Google accounts.