Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, November 22, 2018

60 Million USPS Users' Data Left Exposed Over A Year Despite The Notification By A Researcher.


U.S. Postal Service has addressed a gap security that allowed a person with an account at usps.com to not only view but in some cases to modify account details on behalf of more than 60 million users of a system called Informed Visibility.
An anonymous researcher who discovered the flow informed the #USPS a year ago but has not received any response nor a fix to the problem. Due to the danger that to security flow posed, the same researcher contacted KrebsOnSecurity but also informed the journalist that he/she wished continued to remain anonymous.
KrebsOnSecurity contacted the USPS after confirming his findings, and USPS promptly addressed the issue.

The problem stemmed from an authentication weakness in a USPS Web component known as an “application program interface,” or API tied to a Postal Service initiative called “Informed Visibility,” which according to the USPS is designed to let businesses, advertisers and other bulk mail senders “make better business decisions by providing them with access to near real-time tracking data” about mail campaigns and packages. You can get more information about the issues here.

Tuesday, November 04, 2014

nogotofail, A Tools From Google To Test And Secure SSL.

Google's Android Security Team has built and for a while has been using a tool, called nogotofail, to verify that the devices or applications them and us using are safe against known TLS/SSL vulnerabilities and misconfigurations. Nogotofail works for most OS' in the use today like, Android, iOS, Linux, Windows, Chrome OS, OSX, basically any device you use today to connect to the Internet. nogotofail also comes with an easy-to-use client to configure the settings and get notifications on Android and Linux. There is an attack engine which can be deployed as a router, VPN server, or proxy.
To make TLS/SSL more secure and usable, Google released the tool as an open source project.OSS brings best of the industry together and makes projects like these even more versatile. Thanks to Google and the Android Security team, now anyone can test their applications, contribute new features, provide support for more platforms, and help improve the security of the Internet. Getting started instructions are here.
Google Online Security Blog: Introducing nogotofail—a network traffic security testing tool

Wednesday, July 20, 2011

Protecting Users From Malware Using Knowledge Gained From Data


You may have seen an unusual sign if you visited Google recently, like in the image above. That is Google and power of data acting together with security engineers to protect you.
If you see the message, your machine is infected with a strange variant on malware.
Google was able to detect that computers infected with this strain of malware is sending traffic to Google via a set of proxy servers.
Google expect to help out users with eradicating these malware by warning users when traffic is coming from these proxies. Users are directed to a special help page to work with antivirus software to remove infections.
So far this is what Google / we know about these infections;
  • The malware appears to have gotten onto users' computers from one of roughly a hundred variants of fake antivirus, or "fake AV" software that has been in circulation for a while. We aren't aware of a common name for the malware.
  • We believe a couple million machines are affected by this malware.
  • We've heard from a number of you that you're thinking about the potential for an attacker to copy our notice and attempt to point users to a dangerous site instead. It's a good security practice to be cautious about the links you click, so the spirit of those comments is spot-on. We thought about this, too, which is why the notice appears only at the top of our search results page. Falsifying the message on this page would require prior compromise of that computer, so the notice is not a risk to additional users.
  • In the meantime, we've been able to successfully warn hundreds of thousands of users that their computer is infected. These are people who otherwise may never have known.

Official Google Blog: Using data to protect people from malware