Have you ever looked into researching your family tree? Have you noticed what kind of information you can find out about people, especially older people who have been around since the 1930 census (and pretty soon, the 1940 census)? Upon death, social security numbers are published in the Social Security Death Index, and some of that information is still useful. For example, my father passed away in 2000, my mom still receives social security benefits based on his SSN – which is now public information. All of the joint accounts they had together are mostly still with his social. It would make it easy to steal the identity of a dead person. The SSDI is supposed to prevent that, but[…]
Category: general
This week, I registered for the next Document Interop Initiative (DII) workshop being held at Microsoft. (Details here) The meet-up is centered around the new XML Advanced Electronic Signatures (XAdES) support in Office 2010. In my opinion, this is a great step forward for Office’s digital signature support, as XAdES provides the appropriate XML schemata to embed timestamps, revocation information and countersignatures within a digital signature on a document. Timestamp and embedded revocation support are two of the chief advantages that Acrobat digital signatures have held over Office for the past several years. Finally enabling this functionality will allow Office to compete with Acrobat on a more even playing field in terms of allowing robust, more auditable signature workflows. I’m[…]
Did you know that two thirds of all phishing attacks are sourced from a single group? This seems like a staggering statistic, except for the fact that we’ve already seen this before. Maybe those plans for world domination just might pay off… This whole Facebook privacy scare seems to finally be taking its toll on the general public as it seems Google is showing a major increase in trends data sourced from people wanting to delete their accounts. This doesn’t really surprise me much either, as we’ve talked numerous times about how to secure yourself within Facebook. Let’s hope that emergency meeting that was supposed to take place today actually accomplished something. One of the pioneers of PKI, Whit Diffie,[…]
Earlier this week, blogger and author Cory Doctorow published an account of how he fell victim to a phishing scheme: I run an up-to-date version of a very robust flavor of GNU/Linux called Ubuntu, which has a single, easy-to-use interface for keeping all my apps patched with the latest fixes. My browser, Firefox, is far less prone to serious security vulnerabilities than dogs like Internet Explorer. I use good security technology: my hard-drive and backup are encrypted, I surf through Ipredator (a great and secure anonymizer based in Sweden), and I use GRC’s password generator to create new, strong passwords for every site I visit (I keep these passwords in a text file that is separately encrypted). And I’m media-literate:[…]
Earlier this week, news reports surfaced of a security hole in a popular mobile application for sharing photos. The program, called Quip, enabled iPhone users to send picture messages to any phone without using carriers’ MMS technology, which often requires an extra monthly fee. Quip sent text messages or push notifications with a link to a web page where the recipient could view the intended picture. According to the developers of Quip, users have sent over 3 million photos using the service. But those 3 million photos did not only reach their intended viewers. The application uploaded pictures to a public web server with no encryption or authentication, and even worse, the addresses of the files followed a simple, predictable[…]
Pwn2Own winner Charlie Miller is taking a different approach this year when it comes to releasing the vulnerabilities he used to the vendors, in this case Apple, Microsoft, and Adobe. In an interview with Computerworld Charlie stated: “We find a bug, they patch it, we find another bug, they patch it. That doesn’t improve the security of the product. True, [the software] gets incrementally better, but they actually need to make big improvements. But I can’t make them do that.” From this observation Charlie decided he’s not just going to hand over the vulnerabilities to the vendors. Instead, he’s going to sit down, show them the method he used to find them, and let them do the actual work to[…]