Security

Articles about Security on omid.dev — guides, topics, and notes from the field.

Twitter goes secure – say goodbye to Firesheep with "Always use HTTPS" option

Published: March 17, 2011 Reading time: 2 min

Sophos Labs: Good news on the social networking security front is that Twitter has finally got its act together to offer an Always use HTTPS option. If you turn on this option, all of your personalized interaction with Twitter will be encrypted – not only while you are logging in, but also while you are posting tweets. A lot of people fail to recognize the value of using HTTPS on Twitter. As long as your username and password are sent over HTTPS, so no-one can sniff them out of the ether, who cares if your tweets go over plain HTTP? After all, a tweet is meant to be public. ...

Continue Reading

Vanessa Hudgens meets FBI to discuss nude photo hack

Published: March 17, 2011 Reading time: 3 min

Nude photos and videos of Vanessa Hudgens, the star of “High School Musical”, have surfaced on the net, with speculation rife that they have been released by a hacker who broke into the 22-year-old’s Gmail account. So far, so normal for saucy celebrity news. But what’s different on this occasion is that not only has Vanessa Hudgens reported to have met law enforcement officers to discuss the crime, but as many as 50 other celebrities are said to have been targeted by a hacking gang dead set on stealing compromising snaps and information. ...

Continue Reading

Spammers Exploit Japan’s Catastrophic State

Published: March 14, 2011 Reading time: 2 min

Symantec: Only a few days ago, Japan experienced one of the worst earthquakes in its history. The earthquake registered 8.9 on the Richter scale and triggered an enormous tsunami. The heart-wrenching images on television have left the world shaken. It was the worst earthquake and tsunami in the past century and at least 50 countries have since received related tsunami warnings. As the death and injury tolls continue to rise, one must not forget those who awake to exploit such delicate situations—spammers continue to maintain the guise of charitable institutions and governmental organizations! Don’t be surprised to suddenly see an email message in your inbox marked as URGENT and pleading with you for “monitory help” [sic] or a phishing mail urging you to donate to the rehabilitation of those affected by the quake and tsunami. Use prudence in finding out the genuine intent of email senders before you reach out or respond. ...

Continue Reading

PWN2OWN – Apple v. Google v. Microsoft v. Mozilla v. BlackBerry!

Published: March 14, 2011 Reading time: 3 min

Sophos Labs Blog: If you’re interested in computer security, you’ve probably heard of PWN2OWN. It’s a competition which has become an annual fixture at the annual CanSecWest conference in Vancouver, British Columbia. The competition gets its name because, as the CanSecWest organizers explain, “If you can execute arbitrary code (PWN) on these [laptops or mobile phones] through a previously undisclosed browser (Firefox, IE, Safari) exploit, you can go home with one (OWN).” ...

Continue Reading

More Browser Updates

Published: March 14, 2011 Reading time: 1 min

Avira TechBlog: Well, actually we expect some more updates as some security vulnerabilities have been revealed at the Pwn2Own contest during the CanSecWest security conference. Google is the first and pushes out version 10.0.648.133 – which fixes one security vulnerability within WebKit (the base of the Blackberry, Chrome and Safari webbrowsers). As usual, the update is spread via the built-in automatic update mechanism. Users can make sure to use the latest version by clicking on the tool symbol and choosing the “About Chrome” menu entry. ...

Continue Reading

Apple’s Safari browser embarrassed at Pwn2Own, hacked in 5 seconds

Published: March 13, 2011 Reading time: 1 min

Safari just got served. At this year’s Pwn2Own conference, security firms and enthusiasts are doing their very best to discover and deploy exploits to some of the world’s most popular browsers. Chrome, Firefox, Internet Explorer, and Safari, they’re all on the menu for conference attendees and some have definitely faired better than others. Google issued a challenge, promising $20,000 to any person or team that could crack Chrome on the conferences opening day, but the two teams scheduled to take a swing backed down. Firefox is, for the time being, still standing, and, per usual, Microsoft’s Internet Explorer was taken down without much fuss. But which browser faired the worst? That would be Apple’s Safari. A French security research firm named Vulpen managed to break into Safari running on a MacBook Air in a cool five seconds. The company noted that the Safari update issued by Apple yesterday — version 5.0.4 — fixes some of the vulnerabilities, but not all. The takedown of Safari 5.0.3 used exploits that are still available in the updated code base. Go ahead Apple detractors, have a little fun in the comments section. ...

Continue Reading

Here's some good news for Mac users! Go Avira!

Published: March 12, 2011 Reading time: 3 min

Avira’s Anti-Virus Technology Used by ZeoBIT in New System Utility – MacKeeper Avira provides anti-malware scanning engine to MacKeeper App Tettnang / Silicon Valley, March 11, 2011 – IT security expert Avira announced today that it licensed its industry-leading antivirus product to Silicon Valley-based ZeoBIT to be used in ZeoBIT’s MacKeeper product. MacKeeper is an all-in-one app that includes 16+ unique features for security, cleaning, data control and optimization for Macintosh computers. ...

Continue Reading

A Mini-Newsletter From Your Google Chrome Security Team

Published: March 9, 2011 Reading time: 3 min

Google Chrome Security Team wrote: We’re always working hard to enhance the Chrome browser with bug fixes, new defenses and new features. The release of Chrome 10 is no different, and there are some items worth highlighting: Chrome 10: Flash sandboxing With Chrome 10, our first cut of the previously announced Flash sandboxing initiative is now enabled by default for the Windows platform on Vista and newer. Additionally, because we automatically update Flash to the latest and most secure version, this should provide useful defense in depth. ...

Continue Reading

Google removes Android malware so you don't have to

Published: March 7, 2011 Reading time: 3 min

BetaNews.com: Android handsets infected with malware are getting a cleaning job from Google. On March 2nd, Google removed 21 apps from the Android Marketplace that contained malicious code (the number of infected apps is now 58). Now Google is “remotely removing the malicious applications from affected devices” and “pushing an Android Market security update to all affected devices that undoes the exploits to prevent the attacker(s) from accessing any more information from affected devices,” according to a blog post by Rich Cannings, Android security lead. ...

Continue Reading

Google acquires Zynamics

Published: March 2, 2011 Reading time: 1 min

Internet giant buys into security. Internet giant Google has acquired software analytics firm Zynamics, it was announced yesterday. The German company, which was founded in 2004 by CEO Thomas Dullien (aka Halvar Flake) to research the automation of reverse engineering and code analysis, now produces four reverse-engineering tools:BinDiff, VxClass, BinNavi and BinCrowd, which are widely used by researchers in the security community. Google has not provided any clues as to how it plans to make use of the Zynamics technology, other than to bolster the protection offered to Google users. Details of the acquisition were not revealed. ...

Continue Reading