|
Biting the hand that feeds IT Copyright: Copyright 2008, Situation Publishing Fri, 03 Oct 2008 16:25:21 +0200 Hotmail, Gmail and kitchen-based checks all neuteredSpammers have reportedly defeated revised CAPTCHAs from both Google and Microsoft.… Mon, 29 Sep 2008 14:15:17 +0200 Lost in transliterationMozilla has published an update to its popular Firefox web browser designed to fix a password saving glitch.… Fri, 29 Aug 2008 17:44:51 +0200 Carder crooks say they canUpdated Cybercrooks are targeting self-service checkout systems in UK supermarkets to cash-out compromised US credit and debit card accounts.… Tue, 26 Aug 2008 12:36:28 +0200 8 million records? Huh, more like 10Hotel chain Best Western has denied falling victim to a large-scale hacking attack.… Tue, 26 Aug 2008 10:57:48 +0200 And a few more gone AWOLA computer hard disc containing one million sets of bank details was bought on eBay for just £35.… Fri, 22 Aug 2008 13:46:31 +0200 Address harvesting all too easyApple has inadvertently made it easy for spammers to create a database of MobileMe email addresses.… Thu, 21 Aug 2008 11:57:52 +0200 Portsmouth Asda links to credit card hackAnalysis The organised tampering of PIN entry devices to commit credit card fraud, which led to arrests in Birmingham last week, has been linked to a breach in an Asda store on the outskirts of Portsmouth.… Tue, 19 Aug 2008 15:34:08 +0200 'We're sorry about that. We're sorry about that'A printing mix-up resulted in thousands of Goldfish credit card customers receiving other people's bills.… Wed, 13 Aug 2008 08:02:03 +0200 Internet bouncer snooze leads to 'small earthquake'Slipshod cryptographic housekeeping left some OpenID services far less secure than they ought to be.… Fri, 08 Aug 2008 04:25:07 +0200 Clone me, pleaseBlack Hat The annual Black Hat conference in Las Vegas has become one of the premier venues for exposing lax security practices that put the unwashed masses at risk. In an interesting twist, a researcher is calling out conference organizers for supplying 4,500 attendees with an RFID-enabled badge that has widely known security weaknesses.… Wed, 06 Aug 2008 12:39:26 +0200 Claims they'll fool e-readers. Uh huh huhThe 'fraud-proof' e-passport can be copied and altered, a Dutch security researcher has demonstrated. In tests conducted for the Times, Jeroen van Beek of the University of Amsterdam changed the chip data in a normal UK e-passport to contain a picture of Osama bin Laden. The paper also reports that van Beek has contrived to have a passport in the name of Elvis Presley accepted by a public e-reader in a Dutch town hall.… Tue, 29 Jul 2008 12:18:05 +0200 Game on for the passport fraudsters?A consignment of 3,000 "useless" blank biometric passports has been stolen on its way to British embassies throughout the world. Or at least, the Identity & Passport Service says they're useless.… Mon, 21 Jul 2008 12:38:43 +0200 Airport workers join their bossesUnions representing airline and airport staff are to tell Home Secretary Jacqui Smith that her plan to force staff to carry ID cards will add nothing to airport security.… Fri, 18 Jul 2008 16:45:36 +0200 Freedom of speech trumps allDutch researchers will be able to publish their controversial report on the Mifare Classic (Oyster) RFID chip in October, a Dutch judge ruled today.… Mon, 14 Jul 2008 11:38:34 +0200 Computer fault buggers barriersUpdated London commuters are suffering more problems than usual this morning, thanks to the weekend failure of the Oyster card readers at tube stations and on buses.… Mon, 14 Jul 2008 09:02:05 +0200 New CRB regs produce a nation of suspectsAnalysis If we had suggested, ten years ago, that one day soon, the government would draw up a list of prescribed occupations: that they would build a database of millions of people who would need to register for those occupations; and that a committee of Public Safety would be set up with power of absolute veto over every individual on the database; it is just possible that you would have decided that even El Reg had taken leave of its oh-so-cynical senses.… Thu, 10 Jul 2008 14:25:56 +0200 Promises 'dramatic reduction' in scam emailseBay and PayPal have linked up with Gmail to roll out technology designed to block fraudulent emails and phishing attacks.… Wed, 09 Jul 2008 13:38:44 +0200 Still embedding passport, address and email thoughRFID technology won't feature on every ticket for the forthcoming Beijing Olympics - but those that do have it will contain an embedded chip with the holder's home address, passport details and email address.… Tue, 08 Jul 2008 12:59:28 +0200 Report publication 'irresponsible'Chipmaker NXP, formerly Philips Semiconductors, is taking Dutch Radboud University to court on Thursday to prevent researchers publishing their controversial report on the Mifare Classic chip.… Mon, 07 Jul 2008 12:22:37 +0200 Names, addresses, bank accounts and sort codesNorthcliffe Media, owner of the Daily Mail, is the latest company to lose a laptop load of sensitive staff information.… Fri, 27 Jun 2008 20:55:35 +0200 IANA and ICANN succumb to NetDevilzThe websites of two of the net's most critical oversight organizations were hijacked by Turkish hackers who sent visitors to rogue pages that challenged the overseers' authority.… Wed, 25 Jun 2008 18:25:57 +0200 Don’t kill the messengerThe publication of a scientific paper by Radboud University that discusses design flaws of the MIFARE chip in cards such as the Oyster travelcard may be in jeopardy. Dutch secretary of state Tineke Huizinga has urged the university not to publish any secrets that may lead to abuse.… Wed, 25 Jun 2008 17:35:28 +0200 Buddy hacker account compromise risk pluggedYahoo! has fixed a vulnerability that left users of its popular webmail service at risk of having their login credentials stolen.… Tue, 24 Jun 2008 08:02:03 +0200 Fakeale reduxMalware authors have created a strain of scareware packages that lifts the name of an infected user from the registry of an infected PC in order to create more convincing scams.… Wed, 11 Jun 2008 13:07:41 +0200 Post code lottery fixCredit card conmen have developed a technique for making fraudulent purchases in the UK appear more legitimate.… Tue, 10 Jun 2008 11:15:54 +0200 Two gangs blamed for attacks on credulous high-rollersTargeted phishing attacks against high-rollers reached new heights over the last two months, according to a study by iDefense.… Mon, 02 Jun 2008 17:57:49 +0200 IT finally hits the fan months after tapes go AWOLCouriers lost magnetic tapes containing the personal details of 4.5 million people who had dealt with the Bank of New York Mellon, it has emerged. The incident happened three months ago, but has only surfaced after legal papers were filed in the state of Connecticut.… Wed, 28 May 2008 15:32:27 +0200 Soaraway lossesIdentity fraud grew alarmingly in the UK last year, with affluent Londoners particularly at risk, according to figures from credit reference agency Experian.… Fri, 23 May 2008 20:40:57 +0200 Social spammingUpdated Facebook has fixed a cross site scripting flaw that left its users at risk from scripting attacks.… Wed, 07 May 2008 12:22:48 +0200 Home Office chucks in the cards?Plans for the widespread introduction of fingerprint passports and ID cards, already delayed until 2012, have receded further into the distance with the publication of the latest Identity & Passport Service cost report for the ID scheme. This effectively pulls the plugs on the network of IPS-run interview centres, and lobs future responsibility for these and for biometric enrolment over to private sector companies.… Wed, 16 Apr 2008 18:56:20 +0200 Sweet temptationWomen are four times more likely than men to give out "passwords" in exchange for chocolate bars.… Wed, 16 Apr 2008 11:42:01 +0200 Skyhook, line and sinkerPunters using Wi-Fi based positioning systems on their mobile devices would do well to look before they leap. Security vulnerabilities have discovered location spoofing flaws in the Skyhook positioning system that might be used to lead users astray.… Wed, 09 Apr 2008 11:52:14 +0200 So who hacked Hansard?At the end of February Home Office minister Meg Hillier explained the UK ID scheme security system to the Home Affairs Committee. "The National Identity Register, essentially," she said, "will be a secure database; ...hack-proof, not connected to the Internet... not be accessible online; any links with any other agency will be down encrypted links."… Tue, 08 Apr 2008 17:44:24 +0200 Who did you text last night?One in five married UK couples admit to electronic snooping on their spouses, says a report from Oxford University. The report found that many married partners spy on their partner's emails and text messages. One in eight (13 per cent) confessed to checking on internet history files to monitor sites visited by their better halves.… Fri, 04 Apr 2008 14:01:58 +0200 Brands and Cameron pitch the fix for government's Big ID problemEarly last month Jacqui Smith unveiled the latest revision of the ID card roadmap. On the same day, by happy coincidence, Microsoft bought Credentica's U-Prove assets and hired Dr Stefan Brands. On the one hand, a discredited and failing strategy staggers on under its fourth Home Secretary, while on the other...?… Fri, 04 Apr 2008 09:02:02 +0200 Customers liable for lossesThe banking industry has re-affirmed a policy that makes online banking customers responsible for losses if they have out of date anti-virus or anti-phishing protection. New Banking Codes for consumers and businesses took effect on Monday.… Thu, 03 Apr 2008 22:47:11 +0200 Pressganged into submissionAn Australian high school has stopped fingerprinting its children, on receiving a caning from the country’s press.… Wed, 02 Apr 2008 01:20:56 +0200 Software that knows if you're mad - or a lonerWhen the president of a prestigious patent and trademarking firm began receiving emails threatening to bring down its operations unless he paid a $17m ransom, he knew he had to take action. He reported the incident to the Federal Bureau of Investigation, but agents were unable to identify the culprit.… Tue, 25 Mar 2008 14:23:44 +0100 No fakes detected - terrorists all move to BelgiumInterviews for first time passport applicants have been massively successful - because, er, no fraudulent applications at all have been detected since the government introduced the system last May. In answer to a Freedom of Information request, the Home Office said last week that 38,391 interviews had been held to date, 222 applications were currently under investigation, but that so far no application had been rejected.… Mon, 24 Mar 2008 15:31:52 +0100 National security now wholly funded by shoppingThe government, the British Airports Authority and the Information Commissioner's Office are arguing over fingerprinting at Heathrow's new Terminal 5, which is due to open on Thursday. T5 is to use a 'count them all in, count them all out' biometric system to log entry and exit to the departure lounge, but the ICO thinks the move may breach the Data Protection Act, and has demanded an explanation from BAA.… Tue, 18 Mar 2008 16:11:48 +0100 Supermarket identity sweepA New England-based supermarket chain has warned of an information security breach that exposed an estimated 4.2 million credit card records.… Wed, 12 Mar 2008 17:29:19 +0100 Lands security lab on SingaporeIBM today snapped up privately-held security software firm Encentuate for an undisclosed sum.… Wed, 12 Mar 2008 06:02:02 +0100 The keys to London Underground, and plenty moreSecurity researchers say they've found a way to crack the encryption used to protect a widely-used smartcard in a matter of minutes, making it possible for them to quickly and cheaply clone the cards that are used to secure office buildings and automate the collection of mass transportation fares.… Thu, 06 Mar 2008 15:15:20 +0100 Smith offers series of compelling propositionsThe latest stage in the long slow death of the UK ID scheme became official this morning, as Home Secretary Jacqui Smith unveiled a two-pronged revised delivery plan, aimed first at selected groups of workers and teenagers. This effectively confirms the strategy proposed by the leaked ID scheme Options Analysis earlier this year, and kicks back the widespread issuing of the cards until 2012.… Wed, 05 Mar 2008 16:41:01 +0100 Smokescreen for a retreat?Airport workers could be the first to be issued with compulsory ID cards, claimed Tory shadow home secretary David Davis today, citing government documents leaked to his party. Home Secretary Jacqui Smith is due to make a speech on the future of ID cards tomorrow, and Davis suggests that she is likely to announce a postponement until 2012, while making them compulsory for selected groups of victims.… Wed, 05 Mar 2008 10:55:43 +0100 Will put privacy at risk for no added securityEurope's top privacy watchdog has condemned planned European border controls as weak and based on inconclusive evidence, claiming they will put Europeans' privacy at risk with no guarantee of increased security.… Fri, 29 Feb 2008 10:59:16 +0100 Beefs up data responsibilityHM Revenue and Customs has appointed 37 staff to protect information, since it lost personal records on 25 million people last November.… Tue, 19 Feb 2008 13:47:18 +0100 Breaking up with Facebook is (less) hard to doIt was a long time coming but the web's favourite has-been-in-the-making, Facebook, has finally agreed to let users who are bored with it wrest their personal information from its advertising salesmens' clutches.… Fri, 08 Feb 2008 09:02:03 +0100 Sanity check pleaseCredit checking giant Equifax left Reg reader Thomas flummoxed when it told him to send copies of the front and back of his debit card when he asked for a credit report.… Wed, 06 Feb 2008 00:18:25 +0100 Slippery slopeA senior US Department of Homeland Security official has floated the idea of requiring citizens to produce federally compliant identification before purchasing some over-the-counter medicines.… |