Archive for February, 2007

Lawsuits, patent claims silence Black Hat talk

Wednesday, February 28th, 2007

RFID hacking demo pulled after HID threatens legal action. “This thing is simpler than a Furbie,” he said, referring to the plush electronic play toy of years past. Moreover, the HID patents in question are public documents, containing all the information needed to build the RFID cloner, he said. Indeed, HID marketing materials for its Smart Card technology notes that “by using diversified unique keys and industry standard encryption techniques, the risk of compromised data or duplicated (smart) cards is reduced,” and that “these security measures are not implemented in proximity cards, giving contactless smart cards a significant security advantage.”

Original post by Forum of Incident Response and Security Teams – Daily Security News

Report: VA funds wasted in data loss

Wednesday, February 28th, 2007

While the Department of Veterans Affairs reeled last year from the theft of a computer loaded with personal data on 26.5 million vets, VA officials wasted as much as $135,000 on a bungled analysis of the missing information. A report by the VA’s inspector general is a tale of favoritism, a late-night contract award, inept contractor employees, expensive restaurant meals and a sabotaged office computer.

Original post by Forum of Incident Response and Security Teams – Daily Security News

Reverse hacker describes ordeal

Wednesday, February 28th, 2007

The former network intrusion detection analyst was fired in January 2005 after he shared information relating to an internal network compromise with the FBI and the U.S. Army. Carpenter said he had done so only for national security reasons. He said his independent investigations of a May 2004 breach had unearthed evidence showing that the intruders who had broken into Sandia’s networks belonged to a Chinese hacking group called Titan Rain that also had attacked other sensitive networks and stolen U.S. military and other classified documents.

Original post by Forum of Incident Response and Security Teams – Daily Security News

MySpace hackers avoid extortion rap

Wednesday, February 28th, 2007

Blackmail charges have been dropped against a pair of hackers accused of mounting an extortion scam against MySpace as part of a plea-bargaining agreement. Shaun Harrison, 19, and Saverio Mondelli, 20, of Suffolk County, New York, pleaded guilty to developing code that tracked MySpace users in exchange for an agreement by prosecution lawyers to drop charges that they attempted to extort $150,000 from MySpace.

Original post by Forum of Incident Response and Security Teams – Daily Security News

Comodo resolves site validation glitch

Wednesday, February 28th, 2007

Digital certificate firm Comodo has restored services to normal after websites displaying Comodo’s Trust Logo were reduced to a crawl on Friday. Comodo’s Trust Logo validates a website’s identity to surfers, building confidence in ecommerce. But problems contacting the trustlogo.com site resulted in sites that displayed the logo failing to load as normal.

Original post by Forum of Incident Response and Security Teams – Daily Security News