Weekly Update 374

Presently sponsored by: Identity theft isn’t cheap. Secure your family with Aura the #1 rated proactive protection that helps keep you safe online. Get started.

Think about it like this: in 2015, we all lost our proverbial minds at the idea of the Kazakhstan government mandating the installation of root certificates on their citizens’ devices. We were outraged at the premise of a government mandating the implementation of a model that could, at their

Continue reading Weekly Update 374

Acuity Who? Attempts and Failures to Attribute 437GB of Breached Data

Presently sponsored by: Identity theft isn’t cheap. Secure your family with Aura the #1 rated proactive protection that helps keep you safe online. Get started.

Allegedly, Acuity had a data breach. That’s the context that accompanied a massive trove of data that was sent to me 2 years ago now. I looked into it, tried to attribute and verify it then put it in the “too hard basket” and moved onto

Continue reading Acuity Who? Attempts and Failures to Attribute 437GB of Breached Data

Weekly Update 373

Presently sponsored by: Webinar: ‘How to Defend Against the Evilginx2.’ Kuba Gretzky (Evilginx2) & Marcin Szary (Secfense) show a tool that counters MFA bypass.

Most of this week’s video went on the scraped (and faked) LinkedIn data, but it’s the ransomware discussion that keeps coming back to mind. Even just this morning, 2 days after recording this live stream, I ended up on nation TV talking about the DP World

Continue reading Weekly Update 373

Hackers, Scrapers & Fakers: What’s Really Inside the Latest LinkedIn Dataset

Presently sponsored by: Webinar: ‘How to Defend Against the Evilginx2.’ Kuba Gretzky (Evilginx2) & Marcin Szary (Secfense) show a tool that counters MFA bypass.

I like to think of investigating data breaches as a sort of scientific search for truth. You start out with a theory (a set of data coming from an alleged source), but you don’t have a vested interested in whether the claim is true or not, rather you

Continue reading Hackers, Scrapers & Fakers: What’s Really Inside the Latest LinkedIn Dataset

Weekly Update 372

Presently sponsored by: Need centralized and real-time visibility into threat detection and mitigation? We got you! Discover the CrowdSec Console today.

Yes, the Lenovo is Chinese. No, I’m not worried about Superfish. Yes, I’m running windows. No, I don’t want a Framework laptop. Seemed to be a lot of time this week gone on talking all things laptops, and there are clearly some very differing

Continue reading Weekly Update 372

Weekly Update 371

Presently sponsored by: Got Linux? (And Mac and Windows and iOS and Android?) Then Kolide has the device trust solution for you. Click here to watch the demo.

So I wrapped up this week’s live stream then promptly blew hours mucking around with Zigbee on Home Assistant. Is it worth it, as someone asked in the chat? Uh, yeah, kinda, mostly. But seriously, having a highly automated house is awesome and I suggest that most people

Continue reading Weekly Update 371

Weekly Update 370

Presently sponsored by: Got Linux? (And Mac and Windows and iOS and Android?) Then Kolide has the device trust solution for you. Click here to watch the demo.

I did it again – I tweeted about Twitter doing something I thought was useful and the hordes did descend on Twitter to tweet about how terrible Twitter is. Right, gotcha, so 1.3M views of that tweet later… As I say in this week’s video, there’

Continue reading Weekly Update 370

Weekly Update 369

Presently sponsored by: Online fraud is everywhere. Secure your finances and personal info with Aura’s award-winning identity protection. Protect your identity now.

There seemed to be an awful lot of time gone on the 23andMe credential stuffing situation this week, but I think it strikes a lot of important chords. We’re (us as end users) still reusing credentials, still not turning on MFA and still trying to sue when we

Continue reading Weekly Update 369

Weekly Update 368

Presently sponsored by: Online fraud is everywhere. Secure your finances and personal info with Aura’s award-winning identity protection. Protect your identity now.

This must be my first “business as usual” weekly update since August and damn it’s nice to be back to normal! New sponsor, new breaches, new blog post and if you’re in this part of the world, a brand new summer creeping over the

Continue reading Weekly Update 368

Safe, Secure, Anonymous, and Other Misleading Claims

Presently sponsored by: NTT’s Samurai XDR offers affordable enterprise-grade security for businesses of any size. $40 /endpoint/year. Try it free for 30 days!

Imagine you wanted to buy some shit on the internet. Not the metaphorical kind in terms of “I bought some random shit online”, but literal shit. Turds. Faeces. The kind of thing you never would have thought possible to buy online until… Shitexpress came along. Here’s

Continue reading Safe, Secure, Anonymous, and Other Misleading Claims