2012-05-10

OpenDNS launches a tool to encrypt DNS requests


DNS requests [by default] are unencrypted, meaning that an interloper monitoring a person's internet traffic, such as over an unencrypted public Wi-Fi access point at an airport or cafe, could see the requests and compromise a person's privacy.
Full Story

Users Still The Weakest Link in the Security Chain


Well, it is an age old known fact. One of the many articles that talks about it

2012-05-07

Engineering mistake exposes clear-text passwords for Lion


A debugging switch inadvertently left on in the current release of Lion, version 10.7.3, records in clear text the password needed to open the folder encrypted by the older version of FileVault.
Full Story

2012-05-03

Stenography used by al Qaeda


On May 16 last year, a 22-year-old Austrian named Maqsood Lodin was being questioned by police in Berlin. He had recently returned from Pakistan via Budapest, Hungary, and then traveled overland to Germany. His interrogators were surprised to find that hidden in his underpants were a digital storage device and memory cards. Buried inside them was a pornographic video called "Kick Ass" -- and a file marked "Sexy Tanja."
Full Story

Browser For Hackers

Best browser for hackers with built in features for hackers- OWASP Mantra Browser Security Framework for penetration testers
Full Story 

Hackers blackmail Belgian bank with threats to publish customer data

The hackers call their demand an "idiot tax" because the information was unencrypted on the bank's web server
Cyber Extortion

2012-05-02

Google StreetView's Wi-Fi Snooping

Okay, there was an intentional reason why I didn't post about this 2010 matter.

The Story via PCWorld:
Google's Wi-Fi woes started in 2010 after the company received a request from Germany's data protection authority to audit the information that Street View cars collected. As part of the project, Google was recording publicly available identifying information from Wi-Fi routers around the world in order to create a router location database to help improve the accuracy of location-based services for Android phones and other Google products. But the search giant also said its cars had mistakenly collected fragments of user data in the process.
Google's Response:
Google publicly apologized for the action, and got an external auditor to check their code, and also validate they have deleted all the personal information.

Realistic View:
So, how much personal data, could a moving car have picked up? If a person leaves his house door open, and a person standing on the street, inadvertently peeps inside and catches a glimpse of a confidential piece of paper - then who is at fault?