teases: on • reblogs: on

ShortFormBlog

Read a little. Learn a lot. • Ask Us Stuff!FAQArchiveTimeline

Tagged: security

Our best freaking stuff right now:

June 9, 2013
11:44 • 1 week ago
May 22, 2013
17:19 • 4 weeks ago
Good news for Burger King: After many months of people asking for it, Twitter finally offers two-step verification for its users. “Of course, even with this new security option turned on, it’s still important for you to use a strong password and follow the rest of our advice for keeping your account secure,” the company emphasizes.

Good news for Burger King: After many months of people asking for it, Twitter finally offers two-step verification for its users. “Of course, even with this new security option turned on, it’s still important for you to use a strong password and follow the rest of our advice for keeping your account secure,” the company emphasizes.

May 4, 2013
12:20 • 1 month ago
Why are these people wearing ponchos? Simple. Because they couldn’t bring umbrellas with them. During today’s Kentucky Derby event, officials bumped up security, preventing thousands of attendees from bringing in backpacks, large purses, and despite the rain forecast, umbrellas. The tightened security comes weeks after the Boston Marathon bombing caused an unprecedented security crackdown in the city of Boston. (photo by Charlie Riedel/Associated Press)

Why are these people wearing ponchos? Simple. Because they couldn’t bring umbrellas with them. During today’s Kentucky Derby event, officials bumped up security, preventing thousands of attendees from bringing in backpacks, large purses, and despite the rain forecast, umbrellas. The tightened security comes weeks after the Boston Marathon bombing caused an unprecedented security crackdown in the city of Boston. (photo by Charlie Riedel/Associated Press)

April 29, 2013
21:57 • 1 month ago

woody:

Hey shortformblog, you’re mostly wrong. 

Because Twitter cannot prevent the type of attack which has caused so many brands to loose their twitter account - malware (specifically keyloggers) logs the users credentials when they log into twitter.com, which the attacker then uses to make a perfectly “legitimate” login at a later time. 

How do you prevent this as a user, given that its the #1 vector of attack for these big name brand hijackings? Use a computer that you know isn’t infected with MalWare. How do you ensure that a computer doesn’t have any malware? Never connect it to the internet (or if you do connect, only use twitter.com, and not browsing or emailing).

Does this make sense for the average user? Not at all. Does it make sense for a global brand or news agency who want to avoid what happened to AP? Easily. The $1200 hypothetical laptop is far cheaper than the damage to a brand from a high publicity hijacking. 

The reason that I say “mostly” is that twitter could prevent this by using Google Authenticator or some other form of two-factor authentication. This would be unneeded for a normal user, but would allow big brands to add the extra security. I suspect that Twitter is probably working on this right now, and that this announcement is just until it is deployed.

You realize these accounts are used by multiple users and organizations as large as AP use third-party apps, right? And that numerous people use that single account, right? And that social media pretty much only works because you can share links? This solution is not realistic. It’s a band-aid solution until Twitter gets its stuff together.

The problem here is that large brands have been asking for that two-factor solution for at least two years (Facebook launched it two years ago, and Google has had it for years), and now, Twitter is feeling some serious pain because they only hired someone to work on the two-factor thing within the past six months.

They can’t block such attacks because they haven’t built out their system to deal with them. 

If Twitter was serious about protecting its users, it would have been working on this solution before it got to this point, especially considering the seriousness of the problems being raised and the size of the brands it was courting. But instead, they’re playing catch-up. The best solution to bad security is being proactive.

The hypothetical dedicated laptop is not the problem. The fact that the hypothetical dedicated laptop was required in the first place is the problem.

October 11, 2012
19:20 • 8 months ago
September 26, 2012
13:04 • 8 months ago

  • 100GB worth of website logs remained publicly available on the servers of the Institute of Electrical and Electronics Engineers. Some of the unencrypted plaintext files included user names, passwords, and users’ site activity.
  • 100k computer engineers, including employees of Apple and Google, had their personal data compromised by the oversight. IEEE is the world’s largest professional trade organization for computer engineers, and the leak affected nearly one-fourth of its 411,000 members. So what was the most common password? “123456” source

Follow us on Facebook:
September 4, 2012
08:11 • 9 months ago

  • 12 million the number of Apple iOS device identifiers in the FBI’s custody, according to AntiSec
  • 1 million the number of device numbers AntiSec publicly leaked early Tuesday morning source

» Wait a sec … the FBI had them? Well, funny story about that. Back in March, the group says they gained access to a computer owned by an FBI official. Just by chance, they found a file on the agent’s desktop titled “NCFTA_iOS_devices_intel.csv” — a long list of 12 million UDID identifiers for iOS devices, along with a number of other pieces of personal info. AntiSec released just 1 million of the UDID numbers (which you can analyze here to see if you were nailed), but it’s worth keeping in mind that the odds may not be super-high of getting hit. There are 410 million iOS devices on the market, as of July. The problem for many is that the FBI reportedly had this info in the first place. What did they need it for, and why was it sitting on some dude’s desktop?

UPDATE: The FBI says that there is “no evidence” they had a file like the one described above.

Follow ShortFormBlog • Find us on Twitter & Facebook

August 13, 2012
21:50 • 10 months ago
New tech site “Terms of Service; Didn’t Read” wants to expose what they call “the biggest lie on the Web.” To put it simply, nobody actually reads the Terms of Service. They just say they do. And in the case of some services, such as TwitPic (above), this is pretty evil. Did you know they can sell your photos to a news wire without paying you? Scary, right?

New tech site “Terms of Service; Didn’t Read” wants to expose what they call “the biggest lie on the Web.” To put it simply, nobody actually reads the Terms of Service. They just say they do. And in the case of some services, such as TwitPic (above), this is pretty evil. Did you know they can sell your photos to a news wire without paying you? Scary, right?

July 28, 2012
03:18 • 10 months ago

twentysomethingfloater says: in the words of ed love, “C’MON SON”. Those pws were basic, ya’ll gotta step your game up some degrees. I mean, ya’ll a pretty big deal, of course people are gonna try to hit you.

» SFB says: We had secure passwords. Matt was making a joke. We worked very hard to prevent this from happening after the first round — to the point of removing app access from the backend — and apparently that wasn’t enough. We’ll work harder to ensure security in the future. — Ernie @ SFB

July 26, 2012
15:25 • 10 months ago

Malte Spitz’s presentation, ”Your Phone Company Is Watching”, explores just how much can be extrapolated from the information collected by his cell phone carrier as a result of the EU’s Data Retention Directive. Working with ZEIT Online, Spitz used 35,830 lines of data to create a downloadable, interactive map chronicling his daily life during a six month period. “If you have access to this information, you can see what society is doing,” says Spitz, adding, “If you have access to this information you can control your society.” source

Follow our TumblrSend us a TweetBe our Facebook pal

Recent posts and stuff we dig:
July 22, 2012
16:21 • 11 months ago

  • $50 million in funding from Congress went to the RNC and the DNC each to ensure that the two major political conventions this year are safe
  • $13.6 million was spent by the RNC on big safety items ahead of the conference — like 200 bicycles, 13 electric all-terrain vehicles and one armored truck source

» Trying to learn from St. Paul: In 2008, the Republican National Convention was held in St. Paul, Minn., where protesters often got violent and police confrontations were common. No one was seriously injured, but many were arrested (including journalists). Because St. Paul was one of the smallest cities to host a national political convention, its security and enforcement was slightly unprepared. Tampa is taking no chances this year. ”We’ve extensively studied St. Paul,” said Tampa City Attorney Jim Shimberg. “We’ve had meetings with folks in St. Paul, to find out what went well and what went wrong.”

Follow ShortFormBlog • Find us on Twitter & Facebook

July 12, 2012
13:46 • 11 months ago

  • 450,000 Yahoo accounts were compromised, along with large quantities of database information that hacker group “DD3Ds Company” say they found completely unencrypted
  • 420,000 Formspring username and password hashes leaked this week, forcing the company to reset the passwords of all 28 million registered users in an effort to protect users’ data  source

» It hasn’t been a great summer for cyber-security, particularly when you consider how many well-known companies keep getting caught with lackluster security in place. So, how many more of these stories do you think it will take before major corporations quit storing user data in plain-text format?

Follow ShortFormBlog • Find us on Twitter & Facebook

July 11, 2012
12:40 • 11 months ago
June 20, 2012
19:01 • 12 months ago

  • $5 million lawsuit filed against recently-hacked LinkedIn source

» Illinois resident Katie Szpyrka, represented by Edelson McGuire, filed the suit nearly two weeks after the passwords first hit the web. Szpyrka claims that the ease with which hackers accessed user information constitutes a violation of promises that LinkedIn made to consumers. LinkedIn disputes Szpyrka’s claim, and intends to fight the suit in court. “No member account has been breached as a result of the incident,” said LinkedIn spokeswoman Erin O’Harra, adding, “We have no reason to believe that any LinkedIn member has been injured.”

Follow ShortFormBlog • Find us on Twitter & Facebook

More posts:

 

ShortFormBlog is the product of Ernie Smith, Seth Millstein, Chris Tognotti, Sami Main, Scott Craft, Matthew Keys, Julius the laid-off RSS robot, awesome links from awesome sources, a hacked version of Wordpress, Tumblr's Tumblarity, the letter Q, the number 13 and a series of tubes.

Copyright 2009-2013 Ernie SmithAsk us stuff!E-mail usFollow us on TwitterFollow us on Facebook

    TwitterCounter for @shortformblog   Real Time Web Analytics   Creative Commons License Real Time Web Analytics