From Sophos Naked Security:
Are you encrypting your documents? Here’s what happens when you don’t
"In June 2015, someone connected to Plymouth University accidentally sent a spreadsheet containing the salaries, pensions and allowances of 245 senior staff to the wrong email address.
The error was reported to the UK’s Information Commissioner (ICO), and the file was said to have been deleted by the recipient. Until, that is, the same file turned up last week in the inbox of a local newspaper from an anonymous source."
The purpose of this blog is to help small-medium businesses (SMB's) deal effectively with their unique cyber security needs. With over 15 years experience in IT and cyber security I will show SMB's how they can leverage their limited resources to develop effective cyber defenses to the most common threats using information security best practices and no/low cost tools.
LinkedIn: http://www.linkedin.com/in/ecissorsky/
Twitter: @ecissorsky
Showing posts with label Encryption. Show all posts
Showing posts with label Encryption. Show all posts
Tuesday, May 9, 2017
Thursday, May 4, 2017
7 Steps to Fight Ransomware
From Dark Reading:
7 Steps to Fight Ransomware
"Perpetrators are shifting to more specific targets. This means companies must strengthen their defenses, and these strategies can help.
Ransomware can be a highly lucrative system for extracting money from a customer. Victims are faced with an unpleasant choice: either pay the ransom or lose access to the encrypted files forever. Until now, ransomware has appeared to be opportunistic and driven through random phishing campaigns. These campaigns often, but not always, rely on large numbers of emails that are harvested without a singular focus on a company or individual."
7 Steps to Fight Ransomware
"Perpetrators are shifting to more specific targets. This means companies must strengthen their defenses, and these strategies can help.
Ransomware can be a highly lucrative system for extracting money from a customer. Victims are faced with an unpleasant choice: either pay the ransom or lose access to the encrypted files forever. Until now, ransomware has appeared to be opportunistic and driven through random phishing campaigns. These campaigns often, but not always, rely on large numbers of emails that are harvested without a singular focus on a company or individual."
Monday, May 1, 2017
Microsoft Turns Off Wi-Fi Sense After Risk Revealed
From DataBreach Today:
Microsoft Turns Off Wi-Fi Sense After Risk Revealed
"Remember Microsoft's Wi-Fi Sense? The Windows 10 feature shared encrypted passwords to Wi-Fi networks with user's Skype and Outlook contacts. The idea was that friends could then easily connect to other networks without needing login details. But it raised privacy and security concerns."
Microsoft Turns Off Wi-Fi Sense After Risk Revealed
"Remember Microsoft's Wi-Fi Sense? The Windows 10 feature shared encrypted passwords to Wi-Fi networks with user's Skype and Outlook contacts. The idea was that friends could then easily connect to other networks without needing login details. But it raised privacy and security concerns."
Wednesday, July 22, 2015
Hardware encryption market revenue to reach $36.4 billion by end of 2015
From Help Net Security:
Hardware encryption market revenue to reach $36.4 billion by end of 2015
There are a variety of ways to secure data, either on the perimeter or within the LAN, but the most fundamental method in a defense-in-depth model is hardware encryption. The advantage of hardware-based solutions is that they bypass many of the typical drawbacks of software-based solutions like performance degradation or vulnerability to attacks aimed at the encryption key stored in memory.
Because encryption is available at drive-level, this solution is not dependent on any software or operating system used, and usually cannot be turned off by users.
Hardware encryption market revenue to reach $36.4 billion by end of 2015
There are a variety of ways to secure data, either on the perimeter or within the LAN, but the most fundamental method in a defense-in-depth model is hardware encryption. The advantage of hardware-based solutions is that they bypass many of the typical drawbacks of software-based solutions like performance degradation or vulnerability to attacks aimed at the encryption key stored in memory.
Because encryption is available at drive-level, this solution is not dependent on any software or operating system used, and usually cannot be turned off by users.
Monday, July 20, 2015
UK minister: Cyber-security a 'priority' for government, but no ban on encryption
From SC Magazine:
UK minister: Cyber-security a 'priority' for government, but no ban on encryption
Vaizey, minister of state at the department for culture, media and sport (DCM) and the department for business, innovation and skills (BIS), was the keynote speaker at an event hosted by think-tank Reform in London today, where he announced several new government initiatives while also talking up its digitalisation efforts and local cyber-security companies.
UK minister: Cyber-security a 'priority' for government, but no ban on encryption
Vaizey, minister of state at the department for culture, media and sport (DCM) and the department for business, innovation and skills (BIS), was the keynote speaker at an event hosted by think-tank Reform in London today, where he announced several new government initiatives while also talking up its digitalisation efforts and local cyber-security companies.
Thursday, July 16, 2015
New RC4 Attack Dramatically Reduces Cookie Decryption Time
From ThreatPost:
New RC4 Attack Dramatically Reduces Cookie Decryption Time
Two Belgian security researchers from the University of Leuven have driven new nails into the coffin of the RC4 encryption algorithm.
A published paper, expected to be delivered at the upcoming USENIX Security Symposium next month in Washington, D.C., describes new attacks against RC4 that allow an attacker to capture a victim’s cookie and decrypt it in a much shorter amount of time than was previously possible.
New RC4 Attack Dramatically Reduces Cookie Decryption Time
Two Belgian security researchers from the University of Leuven have driven new nails into the coffin of the RC4 encryption algorithm.
A published paper, expected to be delivered at the upcoming USENIX Security Symposium next month in Washington, D.C., describes new attacks against RC4 that allow an attacker to capture a victim’s cookie and decrypt it in a much shorter amount of time than was previously possible.
Thursday, July 9, 2015
FBI director insists Silicon Valley can solve the encryption dilemma - if they try hard enough
From Help Net Security:
FBI director insists Silicon Valley can solve the encryption dilemma - if they try hard enough
On Wednesday, the US Senate Judiciary Committee got to hear from FBI director James Comey and DOJ Deputy Attorney General Sally Quillian Yates on how end-to-end encryption employed by certain companies (but mostly Apple) is becoming a problem for law enforcement's investigations.
Waving the threat of ISIS and terrorism before the Committee, Comey in particular chose not to believe that cryptographers, technologists and security experts know what they are talking about, and said that the companies have probably not tried hard enough to come up with a viable answer on how to provide access to law enforcement, but keep criminals out.
FBI director insists Silicon Valley can solve the encryption dilemma - if they try hard enough
On Wednesday, the US Senate Judiciary Committee got to hear from FBI director James Comey and DOJ Deputy Attorney General Sally Quillian Yates on how end-to-end encryption employed by certain companies (but mostly Apple) is becoming a problem for law enforcement's investigations.
Waving the threat of ISIS and terrorism before the Committee, Comey in particular chose not to believe that cryptographers, technologists and security experts know what they are talking about, and said that the companies have probably not tried hard enough to come up with a viable answer on how to provide access to law enforcement, but keep criminals out.
Tuesday, June 30, 2015
Stealthy Fobber Malware Takes Anti-Analysis To New Heights
From Dark Reading:
Stealthy Fobber Malware Takes Anti-Analysis To New Heights
Built off the Tinba banking Trojan and distributed through the elusive HanJuan exploit kit, Fobber info-stealer defies researchers with layers upon layers of encryption.
Stealthy Fobber Malware Takes Anti-Analysis To New Heights
Built off the Tinba banking Trojan and distributed through the elusive HanJuan exploit kit, Fobber info-stealer defies researchers with layers upon layers of encryption.
A stealthy new info-stealing browser injection malware aims to make security researchers' job very difficult. Fobber evades detection and defies anaylsis by sliding from one program to another, using randomly generated filenames, encrypting command-and-control communications with a custom algorithm, and encrypting individual pieces of code within the payload, so that each function must be separately, painstakingly decrypted before it can be run.
Monday, June 29, 2015
NIST Revises Key Computer Security Publication on Random Number Generation
For all you crypto enthusiasts out there.
From the National Institute of Standards and Technology:
NIST Revises Key Computer Security Publication on Random Number Generation
In response to public concerns about cryptographic security, the National Institute of Standards and Technology (NIST) has formally revised its recommended methods for generating random numbers, a crucial element in protecting private messages and other types of electronic data. The action implements changes to the methods that were proposed by NIST last year in a draft document issued for public comment.
From the National Institute of Standards and Technology:
NIST Revises Key Computer Security Publication on Random Number Generation
In response to public concerns about cryptographic security, the National Institute of Standards and Technology (NIST) has formally revised its recommended methods for generating random numbers, a crucial element in protecting private messages and other types of electronic data. The action implements changes to the methods that were proposed by NIST last year in a draft document issued for public comment.
The updated document, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, describes algorithms that can be used to reliably generate random numbers, a key step in data encryption.
Tuesday, June 2, 2015
Facebook moves to encrypt the emails it sends users
Kudos to Facebook. Encryption is a good thing.
From Sophos Naked Security:
Facebook moves to encrypt the emails it sends users
Facebook announced that it's introducing an experimental new feature that lets users add OpenPGP public encryption keys to their profiles so that Facebook can encrypt the email notifications it sends them.
From the post:
From Sophos Naked Security:
Facebook moves to encrypt the emails it sends users
Facebook announced that it's introducing an experimental new feature that lets users add OpenPGP public encryption keys to their profiles so that Facebook can encrypt the email notifications it sends them.
From the post:
Whilst Facebook seeks to secure connections to your email provider with TLS, the stored content of those messages may be accessible as plaintext (with attachments) to anyone who accesses your email provider or email account.
To enhance the privacy of this email content, today we are gradually rolling out an experimental new feature that enables people to add OpenPGP public keys to their profile; these keys can be used to "end-to-end" encrypt notification emails sent from Facebook to your preferred email accounts.
Friday, May 29, 2015
If we want strong encryption, we'll have to fight for it
From Help Net Security:
If we want strong encryption, we'll have to fight for it
As digital rights lawyer and special counsel to the Electronic Frontier Foundation Marcia Hofmann correctly noted in her keynote at Hack in the Box Amsterdam 2015 on Thursday, this issue is like a pendulum: sometimes, like in the wake of the 1990s crypto wars, it swings towards strong encryption, but it could now swing in the other direction.
If we want strong encryption, we'll have to fight for it
As digital rights lawyer and special counsel to the Electronic Frontier Foundation Marcia Hofmann correctly noted in her keynote at Hack in the Box Amsterdam 2015 on Thursday, this issue is like a pendulum: sometimes, like in the wake of the 1990s crypto wars, it swings towards strong encryption, but it could now swing in the other direction.
Thursday, May 28, 2015
Practical IT: What is encryption and how can I use it to protect my corporate data?
From Sophos Naked Security:
Practical IT: What is encryption and how can I use it to protect my corporate data?
There’s been a lot of talk about encryption in the media lately.
You hear about who uses encryption, and who doesn’t (lots of companies don’t, to their own detriment).
And you hear about who wants to be able to bypass encryption (some law enforcement and national security agencies), and who doesn’t (Google, Apple, privacy advocates, etc.).
Practical IT: What is encryption and how can I use it to protect my corporate data?
There’s been a lot of talk about encryption in the media lately.
You hear about who uses encryption, and who doesn’t (lots of companies don’t, to their own detriment).
And you hear about who wants to be able to bypass encryption (some law enforcement and national security agencies), and who doesn’t (Google, Apple, privacy advocates, etc.).
Monday, May 18, 2015
Open Smart Grid Protocol Alliance Plans to Fix its Weak Crypto
From ThreatPost:
Open Smart Grid Protocol Alliance Plans to Fix its Weak Crypto
The Open Smart Grid Protocol Alliance, which recently came under fire for a weak crypto implementation in its protocol, will upgrade existing devices, likely starting in September.
Harry Crijns, secretary of the OSGP Alliance in The Netherlands, said fixes have been developed and are “under [a] stress test.” It said it will then work with standards bodies such as CENELEC and ETSI in Europe to bring smart grids and devices up to speed.
Open Smart Grid Protocol Alliance Plans to Fix its Weak Crypto
The Open Smart Grid Protocol Alliance, which recently came under fire for a weak crypto implementation in its protocol, will upgrade existing devices, likely starting in September.
Harry Crijns, secretary of the OSGP Alliance in The Netherlands, said fixes have been developed and are “under [a] stress test.” It said it will then work with standards bodies such as CENELEC and ETSI in Europe to bring smart grids and devices up to speed.
New Crypto Suites Bring Perfect Forward Secrecy to Windows
From ThreatPost:
New Crypto Suites Bring Perfect Forward Secrecy to Windows
Microsoft yesterday added four cryptographic cipher suites to its default priority ordering list in Windows, a move that brings Perfect Forward Secrecy to the operating system.
Update 3042058 is available for now only on the Microsoft Download Center, affording users the opportunity to test the ciphers before bringing them into their respective IT environments. The updates are available for Windows 7, 8 and 8.1 32- and 64-bit systems, as well as Windows Server 2008 R2 and Windows Server 2012 and 2012 R2 system.
New Crypto Suites Bring Perfect Forward Secrecy to Windows
Microsoft yesterday added four cryptographic cipher suites to its default priority ordering list in Windows, a move that brings Perfect Forward Secrecy to the operating system.
Update 3042058 is available for now only on the Microsoft Download Center, affording users the opportunity to test the ciphers before bringing them into their respective IT environments. The updates are available for Windows 7, 8 and 8.1 32- and 64-bit systems, as well as Windows Server 2008 R2 and Windows Server 2012 and 2012 R2 system.
Wednesday, May 13, 2015
Rep. McCaul: Encrypted Dark Web Aids ISIS' 'Call to Arms' in US
From NewsMax:
Rep. McCaul: Encrypted Dark Web Aids ISIS' 'Call to Arms' in US
Rep. McCaul: Encrypted Dark Web Aids ISIS' 'Call to Arms' in US
The Islamic State (ISIS) is sending out a "call to arms" online to direct people in the United States to commit acts of terror, Rep. Michael McCaul said Wednesday morning, and many terrorists are using the Internet's "Dark Web" to hide their movements.
Monday, May 11, 2015
Do you know where your sensitive data lives?
From Help Net Security:
Do you know where your sensitive data lives?
The majority of IT security professionals don’t have full visibility into where all their organization’s sensitive data resides, according to Perspecsys.
Do you know where your sensitive data lives?
The majority of IT security professionals don’t have full visibility into where all their organization’s sensitive data resides, according to Perspecsys.
Wednesday, May 6, 2015
Law Enforcement Finding Few Allies On Encryption
From Dark Reading:
Law Enforcement Finding Few Allies On Encryption
At the RSA Conference in April, Homeland Security Secretary Jeh Johnson asked the assembled audience of information security professionals for their "indulgence on the subject of encryption." Law enforcement is thus far not receiving that indulgence from the security community, cloud services providers, nor some of the most security-savvy members of Congress.
Law Enforcement Finding Few Allies On Encryption
At the RSA Conference in April, Homeland Security Secretary Jeh Johnson asked the assembled audience of information security professionals for their "indulgence on the subject of encryption." Law enforcement is thus far not receiving that indulgence from the security community, cloud services providers, nor some of the most security-savvy members of Congress.
Monday, May 4, 2015
Mozilla Moving Toward Full HTTPS Enforcement in Firefox
From ThreatPost:
Mozilla Moving Toward Full HTTPS Enforcement in Firefox
The Mozilla Foundation is initiating the process to phase out insecure HTTP connections in the Firefox browser. The decision is part of a broader movement to encrypt the Web, which in the case of Mozilla Firefox, means permitting only encrypted HTTPS browser connections.
Mozilla Moving Toward Full HTTPS Enforcement in Firefox
The Mozilla Foundation is initiating the process to phase out insecure HTTP connections in the Firefox browser. The decision is part of a broader movement to encrypt the Web, which in the case of Mozilla Firefox, means permitting only encrypted HTTPS browser connections.
Thursday, March 12, 2015
How to Sabotage Encryption Software (And Not Get Caught)
From Wired:
How to Sabotage Encryption Software (And Not Get Caught)
In the field of cryptography, a secretly planted “backdoor” that allows eavesdropping on communications is usually a subject of paranoia and dread. But that doesn’t mean cryptographers don’t appreciate the art of skilled cyphersabotage. Now one group of crypto experts has published an appraisal of different methods of weakening crypto systems, and the lesson is that some backdoors are clearly better than others—in stealth, deniability, and even in protecting the victims’ privacy from spies other than the backdoor’s creator.
How to Sabotage Encryption Software (And Not Get Caught)
In the field of cryptography, a secretly planted “backdoor” that allows eavesdropping on communications is usually a subject of paranoia and dread. But that doesn’t mean cryptographers don’t appreciate the art of skilled cyphersabotage. Now one group of crypto experts has published an appraisal of different methods of weakening crypto systems, and the lesson is that some backdoors are clearly better than others—in stealth, deniability, and even in protecting the victims’ privacy from spies other than the backdoor’s creator.
Subscribe to:
Posts (Atom)