Independent

IndependentKrebs

Look-Alike Domains and Visual Confusion

Credit to Author: BrianKrebs| Date: Thu, 08 Mar 2018 16:55:13 +0000

How good are you at telling the difference between domain names you know and trust and imposter or look-alike domains? The answer may depend on how familiar you are with the nuances of internationalized domain names (IDNs), as well as which browser or Web application you’re using. For example, how does your browser interpret the following domain? I’ll give you a hint: Despite appearances, it is most certainly not the actual domain for software firm CA Technologies (formerly Computer Associates Intl Inc.), which owns the original ca.com domain name: https://www.са.com/ Go ahead and click on the link above or cut-and-paste it into a browser address bar. If you’re using Google Chrome, Apple’s Safari, or some recent version of Microsoft’s Internet Explorer or Edge browsers, you should notice that the address converts to “xn--80a7a.com.” This is called “punycode,” and it allows browsers to render domains with non-Latin alphabets like Cyrillic and Ukrainian. Below is what it looks like in Edge on Windows 10; Google Chrome renders it much the same way. Notice what’s in the address bar (ignore the “fake site” and “Welcome to…” text, which was added as a courtesy by the person who registered this domain):

Read More
ComputerWorldIndependent

Study: FinTech, other industries should open blockchain sandboxes and work with regulators

Credit to Author: Lucas Mearian| Date: Wed, 07 Mar 2018 14:11:00 -0800

For regulators to understand blockchain’s cybersecurity benefits and risks, they must first have a deeper understanding of the technology – and businesses hold the key to that, according to new research.

Governments around the world are beginning to increase regulatory oversight of cryptocurrencies, such as bitcoin, which are underpinned by blockchain’s distributed ledger technology. In turn, businesses that use private or “permissioned” blockchain networks are likely to also see more oversight, according to experts.

To read this article in full, please click here

Read More
ComputerWorldIndependent

Criminals pay just $15 for Apple iCloud account IDs, report claims

Credit to Author: Jonny Evans| Date: Wed, 07 Mar 2018 03:59:00 -0800

One of the biggest reasons Apple users need to beware of phishing attacks is that compromised iCloud accounts are among the most valuable of those traded on the dark web at $15 per account.

All your data are belongs to us

Think about the value of your Apple ID data: Not only is your account the golden portal into all your personal data, but it unlocks all manner of other valuable items: credit card details, online purchasing, passwords for your websites and more.

That’s why every Apple ID user really should think about the value of the data they are trying to protect and create tough alphanumeric passcodes, even if they do need to spend significant time memorising those codes.

To read this article in full, please click here

Read More
IndependentKrebs

What Is Your Bank’s Security Banking On?

Credit to Author: BrianKrebs| Date: Tue, 06 Mar 2018 21:24:17 +0000

A large number of banks, credit unions and other financial institutions just pushed customers onto new e-banking platforms that asked them to reset their account passwords by entering a username plus some other static identifier — such as the first six digits of their Social Security number, or a mix of partial SSN, date of birth or surname. Here’s a closer look at what may be going on (spoiler: small, regional banks and credit unions have grown far too reliant on the whims of just a few major online banking platform providers). You might think it odd that any self-respecting financial institution would seek to authenticate customers via static data like partial SSN for passwords, and you’d be justified for thinking that, too. Nobody has any business using these static identifiers for authentication because it’s all for sale on most Americans quite easily and cheaply in the cybercrime underground. The Equifax breach might have “refreshed” some of those data stores for identity thieves, but most U.S. adults have had their static details on sale for years now. On Feb. 16, KrebsOnSecurity reader Brent Hoeft shared a copy of an email he’d just received from his financial institution Associated Bank, which at $30+ billion in assets happens to be Wisconsin’s largest by asset size.

Read More
ComputerWorldIndependent

Feds move to secure mobile devices with machine learning, biometrics

Credit to Author: Lucas Mearian| Date: Tue, 06 Mar 2018 03:24:00 -0800

Amid the growing use of mobile devices for work by federal employees, U.S. defense and intelligence agencies are fast adopting biometrics and other alternative ways of  computers, smartphones and tablets, according to a new report.

More than 90% of federal agency IT officials in an online survey said their organizations provide secure mobile access for work-issued devices, but less than 20% support workers’ personal devices to access most agency systems. Forty percent of those same officials voiced concern about securing personal devices, according to the online survey of federal government IT and cybersecurity officials.

To read this article in full, please click here

Read More
ComputerWorldIndependent

Get the February Microsoft patches applied, unless you’re using Win10 Fall Creators Update

Credit to Author: Woody Leonhard| Date: Mon, 05 Mar 2018 11:57:00 -0800

Granted, February’s patches from Microsoft weren’t as malevolent as January’s patches, but they still managed to knock out lots and lots of PCs. That said, if you can tiptoe around the problems, now is a good time to get the latest versions of the latest patches installed.

Problems with Win10 Fall Creators Update

The worst problem I see at this point involves clobbered USB connections on Win10 Fall Creators Update (version 1709) machines after installing the latest cumulative update, KB 4074588. To its credit, Microsoft has acknowledged the problem. But the only offered fix, a complex manual workaround, would drive a hardened MS-DOS junkie to drink.

To read this article in full, please click here

Read More
IndependentSecuriteam

beVX Conference Challenge

Credit to Author: SSD / Noam Rathaus| Date: Sun, 04 Mar 2018 07:27:05 +0000

During the event of OffensiveCon, we launched a reverse engineering and encryption challenge and gave the attendees the change to win great prizes. The challenge was divided into two parts, a file – can be downloaded from here: https://www.beyondsecurity.com/bevxcon/bevx-challenge-1 – that you had to download and reverse engineer and server that you had to access … Continue reading beVX Conference Challenge

Read More