WhatsApp doesn’t properly erase your deleted messages, researcher reveals

iOS security researcher Jonathan Zdziarski claims to have found a worrying weakness in WhatsApp, that could open a door for intelligence agencies and other prying eyes to snoop upon your private conversations, even after they have been “deleted” from t… Continue reading WhatsApp doesn’t properly erase your deleted messages, researcher reveals→

Citibank IT guy deliberately wiped routers, shut down 90% of firm’s networks across America

Citibank IT guy deliberately wiped routers, shut down 90% of firm’s networks across America

The truth is that the person hacking you may not be someone you’ve never met, wearing a hoody on the other side of the world. They could be sat right next to you, wearing a business suit.

Read more in my article on the Tripwire State of Security blog.

Continue reading Citibank IT guy deliberately wiped routers, shut down 90% of firm’s networks across America→

Citibank IT guy deliberately wiped routers, shut down 90% of firm’s networks across America

The truth is that the person hacking you may not be someone you’ve never met, wearing a hoody on the other side of the world. They could be sat right next to you, wearing a business suit.

The post Citibank IT guy deliberately wiped routers, shut down 90% of firm’s networks across America appeared first on The State of Security.

Continue reading Citibank IT guy deliberately wiped routers, shut down 90% of firm’s networks across America→

Sorry, your Motorola Android isn’t going to get monthly security updates

Well, this sucks if you’ve spent good money on a Motorola smartphone.
The firm has confirmed to Ars Technica that it isn’t going to commit to monthly security updates, even though Google will have released patches for the Android operating system.
Here… Continue reading Sorry, your Motorola Android isn’t going to get monthly security updates→

LastPass security hole could have seen hackers steal your passwords

Mathias Karlsson, a security researcher at Detectify Labs, writes:

Stealing all your passwords by just visiting a webpage. Sounds too bad to be true? That’s what I thought too before I decided to check out the security of the LastPass browser extension.

In his article, Karlsson explains how he was able to trick LastPass into believing that it was on the real Twitter website, and cough up the users’ credentials because of a bug in the LastPass password manager’s autofill functionality.

The same technique could have been used to steal passwords associated with other websites.

Yeuch!

The good news is that Karlsson believes in responsible disclosure, and so informed LastPass of the problem. In more good news LastPass fixed the issue in less than a day (and awarded Karlsson a $1,000 bug bounty for his efforts).

Karlsson recommends that LastPass users disable the autofill functionality and enable multi-factor authentication for better security.

Although his discovery is troubling, I agree with Karlsson when he points out that using a password manager is still better than reusing passwords on different websites.

PS. Well-known vulnerability researcher Tavis Ormandy has also tweeted overnight that he has also found a flaw in LastPass. Details have not yet been made public, and LastPass is reportedly working with him on resolving the issue.

PPS. Readers with good memories will recall that LastPass was acquired by LogMeIn last year to the concern of some. Overnight it has been announced that LogMeIn is itself being acquired by Citrix.

Continue reading LastPass security hole could have seen hackers steal your passwords→

SentinelOne says if you get hit by ransomware, it will pay the ransom

SentinelOne writes:

We’ve created the first ever Ransomware Cyber Guarantee – a warranty for our product’s performance. It’ll give you the best protection from ransomware attacks – and if we miss something and you get infected – we’ll pay the ransom. It’s that simple. And it’s how security is supposed to be. If you can block something – why not guarantee it? Would you buy a new shiny car without manufacturer warranty?

In other words, self-proclaimed “next generation endpoint security solution” SentinelOne says it’s entirely comfortable paying money to criminals.

Of course it’s a marketing stunt, but still one – I must admit – that leaves a nasty taste in my mouth.

Couldn’t SentinelOne have just offered to throw in a decent backup program?

Continue reading SentinelOne says if you get hit by ransomware, it will pay the ransom→