Independent

IndependentKrebs

San Diego Sues Experian Over ID Theft Service

Credit to Author: BrianKrebs| Date: Fri, 23 Mar 2018 16:31:26 +0000

The City of San Diego, Calif. is suing big three consumer credit bureau Experian, alleging that a data breach first reported by KrebsOnSecurity in 2013 affected more than a quarter-million people in San Diego but that Experian never alerted affected consumers as required under California law. The lawsuit, filed by San Diego city attorney Mara Elliott, concerns a data breach at an Experian subsidiary that lasted for nine months ending in 2013. As first reported here in October 2013, a Vietnamese man named Hieu Minh Ngo ran an identity theft service online and gained access to sensitive consumer data held by Experian’s subsidiary by posing as a licensed private investigator.

Read More
ComputerWorldIndependent

More Windows patches — and warnings about the Win10 1709 update KB 4089848

Credit to Author: Woody Leonhard| Date: Fri, 23 Mar 2018 06:52:00 -0700

“Hey, Cortana.” (Pause.) “Is my PC working yet?”

It’s getting to the point that patches come flying out of Microsoft on any odd day. On most odd days, for that matter. Yesterday, Thursday, was no exception. On March 22 we saw all of these new patches:

Cumulative Updates for Win10

All three of the active versions of Win10 got cumulative updates — the second set in the past two weeks:

  • KB 4089848 brings 1709 (Win10 Fall Creators Update) up to Build 16299.334 – seems to have fixed the problem with the January Delta update
  • KB 4088891 brings 1703 (Win10 Creators Update) up to build 15063.994
  • KB 4088889 brings 1607 (Win10 Anniversary Update) up to build 14393.2155 – this one’s a bit surprising because 1607 is due to go off life support in a couple of weeks.

We also got Servicing Stack Updates for two of the three active versions of Win10:

To read this article in full, please click here

Read More
ComputerWorldIndependent

Blockchain to ‘radically’ transform anti-fraud, anti-money-laundering efforts

Credit to Author: Lucas Mearian| Date: Fri, 23 Mar 2018 03:20:00 -0700

Read More
IndependentKrebs

Survey: Americans Spent $1.4B on Credit Freeze Fees in Wake of Equifax Breach

Credit to Author: BrianKrebs| Date: Thu, 22 Mar 2018 14:08:46 +0000

Almost 20 percent of Americans froze their credit file with one or more of the big three credit bureaus in the wake of last year’s data breach at Equifax, costing consumers an estimated $1.4 billion, according to a new study. The findings come as lawmakers in Congress are debating legislation that would make credit freezes free in every state. The figures, commissioned by small business loan provider Fundera and conducted by Wakefield Research, surveyed some 1,000 adults in the U.S. Respondents were asked to self-report how much they spent on the freezes; 32 percent said the freezes cost them $10 or less, but 38 percent said the total cost was $30 or more. The average cost to consumers who froze their credit after the Equifax breach was $23. A credit freeze blocks potential creditors from being able to view or “pull” your credit file, making it far more difficult for identity thieves to apply for new lines of credit in your name.

Read More
IndependentSecuriteam

SSD Advisory – Western Digital My Cloud Pro Series PR2100 Authenticated RCE

Credit to Author: SSD / Noam Rathaus| Date: Wed, 21 Mar 2018 14:48:51 +0000

Vulnerability Summary A vulnerability in the Western Digital My Cloud Pro Series PR2100 allows authenticated users to execute commands arbitrary commands. Credit An independent security researcher has reported this vulnerability to Beyond Security’s SecuriTeam Secure Disclosure program. Vendor Response The vendor was notified on the 28th of November 2017, and responded that they take security … Continue reading SSD Advisory – Western Digital My Cloud Pro Series PR2100 Authenticated RCE

Read More
IndependentKrebs

15-Year-old Finds Flaw in Ledger Crypto Wallet

Credit to Author: BrianKrebs| Date: Tue, 20 Mar 2018 17:19:11 +0000

A 15-year-old security researcher has discovered a serious flaw in cryptocurrency hardware wallets made by Ledger, a French company whose popular products are designed to physically safeguard public and private keys used to receive or spend the user’s cryptocurrencies. Hardware wallets like those sold by Ledger are designed to protect the user’s private keys from malicious software that might try to harvest those credentials from the user’s computer.  The devices enable transactions via a connection to a USB port on the user’s computer, but they don’t reveal the private key to the PC. Yet Saleem Rashid, a 15-year-old security researcher from the United Kingdom, discovered a way to acquire the private keys from the Ledger devices. Rashid’s method requires an attacker to have physical access to the device, and normally such attacks would fall under the #1 rule of security — namely, if an attacker has physical access to your device it is not your device anymore.

Read More
ComputerWorldIndependent

Could these grain-sized computers using blockchain networks thwart counterfeiters?

Credit to Author: Lucas Mearian| Date: Tue, 20 Mar 2018 10:39:00 -0700

Read More
ComputerWorldIndependent

Why Cambridge Analytica means it’s time for an Apple social network

Credit to Author: Jonny Evans| Date: Mon, 19 Mar 2018 07:37:00 -0700

The emerging Cambridge Analytica/Facebook affair, in which people’s personal data was allegedly used for purposes it should not have been used for, shows the danger of surveillance capitalism and the need for a new approach to social networking — and that’s what Apple can provide.

Understand history, but don’t repeat it

History shows us that Apple has never succeeded in creating a social network. Ping, launched in 2010, was closed down in 2012 due to lack of interest.

To read this article in full, please click here

Read More