Archive for December, 2008

One Weak Link to Rule Them All

Wednesday, December 31st, 2008

It is said that any security system is only as strong as its weakest link. A team of researchers today proved that point yet again, showing the world how they could use known weaknesses in the encryption technology that protects online transactions to undermine the security around e-commerce. washingtonpost.com ran an in-depth story I wrote about their findings, along with a sidebar explaining the weakness in a bit more detail. Long story short: An international team of security experts (pictured at right) showed that they could undermine the system most of us rely on to secure our online transactions, so that even though the browser indicates your connection is encrypted (Web browser address starts with “https://”) and vetted by a third party to be secure and authentic, it may in fact be controlled by an attacker offering up a counterfeit Web site designed to steal your information. Web users are

Read more…

CA issues no-questions asked Mozilla cert

Monday, December 29th, 2008

Snafu highlights wider trust problem
Security researchers have uncovered weaknesses in low-assurance digital certificates that create a means for miscreants to mount more convincing man-in-the-middle (MITM) attacks.…

Read more…

Samsung digital picture frame CD infected by virus

Monday, December 29th, 2008

You’ve been iframed
Christmas gifts of Samsung Digital Picture frames could come with the unwelcome gift of malware, Amazon has warned.…

Read more…