A simple way to kill off Twitter trolls

@th3j35t3r writes on his blog:

Simply put. If Jim is blocked by John, Jim can no longer even utter Johns handle/twittername in a tweet. If he attempts to the tweet simply doesn’t process or gets sinkholed. Period. The end. Forever, or until John unblocks him. This approach would not infringe on Jim’s ‘freedom of speech’, he can still say whatever he likes, but he can’t include John. This approach would be self-policing essentially allowing users to decide if they are being abused or harassed and allowing them to take immediate actions without relying on Twitter to minimize the problem effectively. This approach would not be an overhead on Twitters current infrastructure and would require NOTHING by way of extra storage capacity.

Trolls are the ugly side of Twitter, but @th3j35t3r’s proposal seems very elegant to me.

So how about it Twitter?

Find out more, and check out his amusing flowchart, by reading @th3j35t3r’s blog post.

Continue reading A simple way to kill off Twitter trolls→

Tor users in the States were hacked by Australian authorities

Joseph Cox at Motherboard writes:

Australian authorities hacked Tor users in the US as part of a child pornography investigation, Motherboard has learned.

The contours of this previously-unreported hacking operation have come to light through recently-filed US court documents. The case highlights how law enforcement around the world are increasingly pursuing targets overseas using hacking tools, raising legal questions around agencies’ reach.

In one case, Australian authorities remotely hacked a computer in Michigan to obtain the suspect’s IP address.

While I’m sure that the vast majority of us are keen for child abuse websites to be shut down, and their users brought to justice, we are not all comfortable with intelligence agencies breaking the law themselves to achieve this.

Legal processes need to be put in place to not only prevent criminals from hacking into systems they shouldn’t and stealing private information, but also to prevent over-zealous law enforcement agents from stepping over the line.

Just because something can be done doesn’t mean it should be done.

Also, we need to stop thinking that state-sponsored hacking is something done by the Russians and Chinese against the Americans and the Brits. Or it’s something that the Americans and Brits do against the Russians and Chinese.

The true story is that just about everyone is up to it.

I would be shocked if any even semi-sophisticated intelligence agency anywhere in the world wasn’t using the internet, and methods used by criminal hackers, to spy upon the governments, businesses and citizens of other countries.

Continue reading Tor users in the States were hacked by Australian authorities→

Blogger turns tables on cyber-scammer by infecting them with ransomware

BBC News reports:
A French security researcher says he managed to turn the tables on a cyber-scammer by sending him malware.
Technical support scams try to convince people to buy expensive software to fix imaginary problems.
But Ivan Kwiatkowski played… Continue reading Blogger turns tables on cyber-scammer by infecting them with ransomware→

Someone seems to be trying to spy on VeraCrypt’s security audit

At the start of this month OSTIF (the Open Source Technology Improvement Fund) announced that it had agreed a plan to get the open source disk encryption tool VeraCrypt independently audited.

The audit, which would look for security holes and weaknesses in VeraCrypt’s code, would be done in co-ordination with vulnerability researchers from QuarksLab.

So far, so good. Especially as you may remember that VeraCrypt’s predecessor, TrueCrypt, was mysteriously discontinued a couple of years back leading to all manner of conspiracy theories.

Now, the bad news… OSTIF says that its confidential PGP-encrypted communications with QuarkLabs about the VeraCrypt security audit may be being mysteriously intercepted:

We have now had a total of four email messages disappear without a trace, stemming from multiple independent senders. Not only have the emails not arrived, but there is no trace of the emails in our “sent” folders. In the case of OSTIF, this is the Google Apps business version of Gmail where these sent emails have disappeared.

This suggests that outside actors are attempting to listen in on and/or interfere with the audit process.

We are setting up alternate means of encrypted communications in order to move forward with the audit project.

If nation-states are interested in what we are doing we must be doing something right. Right?

Let the speculation begin…

Continue reading Someone seems to be trying to spy on VeraCrypt’s security audit→

Get FREE threat intelligence on hackers and exploits with the Recorded Future Cyber Daily

Get trending info on hackers, exploits, and vulnerabilities every day for FREE with the Recorded Future Cyber Daily [Sponsor]

Graham Cluley Security News is sponsored this week by the folks at Recorded Future. Thanks to the great team there for their support!

Recorded Future provides deep, detailed insight into emerging threats by automatically collecting, analyzing, and organizing billions of data points from the Web.

And now, with its FREE Cyber Daily email all IT security professionals can access information about the top trending threat indicators – helping you use threat intelligence to help make better decisions quickly and easily.

Which means that you will be able to benefit from a daily update of the following:

  • Information Security Headlines: Top trending news stories.
  • Top Targeted Industries: Companies targeted by cyber attacks, grouped by their industries.
  • Top Hackers: Organizations and people recognized as hackers by Recorded Future.
  • Top Exploited Vulnerabilities: Identified vulnerabilities with language indicating malcode activity. These language indicators range from security research (“reverse engineering,” “proof of concept”) to malicious exploitation (“exploited in the wild,” “weaponized”).
  • Top Vulnerabilities: Identified vulnerabilities that generated significant amounts of event reporting, useful for general vulnerability management.

Infosec professionals agree that the Cyber Daily is an essential tool:

“I look forward to the Cyber Daily update email every morning to start my day. It’s timely and exact, with a quick overview of emerging threats and vulnerabilities. For organizations looking to strengthen their security program with threat intelligence, Recorded Future’s Cyber Daily is the perfect first step that helps to prioritize security actions.” – Tom Doyle, CIO at EBI Consulting.

So, what are you waiting for?

Sign up for the Cyber Daily today, and starting tomorrow you’ll receive the top trending threat indicators.


If you’re interested in sponsoring my site for a week, and reaching an IT-savvy audience that cares about computer security, you can find more information here.

Continue reading Get FREE threat intelligence on hackers and exploits with the Recorded Future Cyber Daily→

Sage suffers data breach, putting details of UK and Irish businesses at risk

Online accounting software company Sage has suffered a data breach, putting the details of a “small number” of its UK and Irish business customers at risk.
As the company briefly noted on its website:
We believe there has been some unauthorised access … Continue reading Sage suffers data breach, putting details of UK and Irish businesses at risk→

Video jacking – hopefully not coming to a USB charging cord near you

Krebs on Security writes:

Dubbed “video jacking” by its masterminds, the attack uses custom electronics hidden inside what appears to be a USB charging station. As soon as you connect a vulnerable phone to the appropriate USB charging cord, the spy machine splits the phone’s video display and records a video of everything you tap, type or view on it as long as it’s plugged in — including PINs, passwords, account numbers, emails, texts, pictures and videos.

We know about the risks of having your devices hacked by malicious chargers, and of juice jacking where you plug your phone in for a quick power boost at a kiosk at a shopping centre, hotel lobby or airport, only to have your data snarfled.

But video jacking seems like yet another novel way to grab information from HDMI-ready smartphones.

Is there a widespread risk of this happening? Almost certainly not. But it’s still wise for smartphone users to take care over where they plug in their devices, perhaps bringing their own USB charger on trips with them to plug into an power socket when their battery life is running low.

And manufacturers clearly could do more to display an obvious notification to users when HDMI output is enabled, warning of potential dangers.

Continue reading Video jacking – hopefully not coming to a USB charging cord near you→

Found an iOS zero-day? This firm will pay you $300,000 more than Apple

Exodus Intelligence is offering half a million dollars ($300,000 more than the maximum offered by Apple) to anyone who can sell them an iOS zero-day exploit.
The post Found an iOS zero-day? This firm will pay you $300,000 more than Apple appeared first… Continue reading Found an iOS zero-day? This firm will pay you $300,000 more than Apple→