1Password for Teams and Business1password.com
As always I'm extremely grateful to 1Password for supporting the newsletter. If you have passwords or secure notes to share with your colleagues, I highly recommend you give them a try.
As always I'm extremely grateful to 1Password for supporting the newsletter. If you have passwords or secure notes to share with your colleagues, I highly recommend you give them a try.
It's official. I now spend more time on this one segment than on the rest of the newsletter. Plenty of security work left to do people.
Hard to miss this bit of news this week. When you call someone and, before the other person answers, add yourself to the call's group, you hear the other side even if they haven't picked up yet. And if they mute your call the camera of that person even turns on. Ouch.
Japan has given the green light to allow government workers to try and hack into unsecured IoT devices, to then alert their owners of the problem. This is in preparation of the 2020 Olympics, where they fear large-scale hacking attacks such as the ones during the last games.
Interesting view into the impact of GDPR so far: over 95.000 complaints, 255 initiated investigations, and over 41.000 reported data breaches.
The update also deprecates TLS 1.0 and 1.1, as a first step towards removing support all together in 2020. If you somehow still use these in your company, you might want to get on that.
Do you remember the news of how someone (quite cleverly, I have to admit) "open-sourced" a seed generator for IOTA wallets, but secretly made the random number generator predictable so he could steal it all? It's worth a re-read really. Well, they caught the guy.
Europol took down one of the best known "DDoS for hire" services last year, called webstresser.org. They've also obtained a list of 151.000 registered users of the service, and plan to start prosecuting them.
A project between several universities and insurance companies researched the hypothetical impact of a world-wide ransomware infection, with an estimated bill of $193 billion.
Sure, it's a bit of scaremongering. But I can't help but wonder how far WannaCry would have gotten without the kill switch, and how far new strains could go.
It's not that new or groundbreaking, but it's good to know it happens.
You might know 'whaling', where an attacker acts like the CEO and e-mails an employee asking for a wire transfer.
This one is a bit different: the attacker acts like a regular employee, and asks HR to change their account information. That way they get the salary of the employee that was impersonated.
Just like with whaling, which has already cost a total of over $12 billion, it's cheap and easy to execute.
All other horrible Facebook news aside, this is an interesting post on how they handle security in their company. The post describes their layered approach, involving secure frameworks, automated testing, human testing and reviews, and a bug bounty program.
Very interesting set of excerpts on how commerce on Darknet marketplaces is evolving to stay ahead of law enforcement. The full article is worth a read too.