You Don’t Need to Burn off Your Fingertips (and Other Biometric Authentication Myths)

Presently sponsored by: 1Password is a secure password manager and digital wallet that keeps you safe online

111 years ago almost to the day, a murder was committed which ultimately led to the first criminal trial to use fingerprints as evidence. We’ve all since watched enough crime shows to understand that fingerprints are unique personal biometric attributes and to date, no two people have ever

Continue reading You Don’t Need to Burn off Your Fingertips (and Other Biometric Authentication Myths)

Welcoming the Czech Republic Government to Have I Been Pwned

Presently sponsored by: 1Password is a secure password manager and digital wallet that keeps you safe online

For the last few years, I’ve been welcome national governments to Have I Been Pwned (HIBP) and granting them full and free access to domain-level searches via a dedicated API. Today, I’m very happy to welcome the Czech Republic’s National Cyber and Information Security

Continue reading Welcoming the Czech Republic Government to Have I Been Pwned

Hello CISO – Brought to You in Collaboration with 1Password

Presently sponsored by: 1Password is a secure password manager and digital wallet that keeps you safe online

Today I’m really excited to announce a big piece of work 1Password and I have been focusing on this year, a totally free video series called “Hello CISO”. This is a multi-part series that launched with part 1 and when I say “free”, I

Continue reading Hello CISO – Brought to You in Collaboration with 1Password

Weekly Update 256

Presently sponsored by: Varonis. Reduce your SaaS blast radius with data-centric security for AWS, G Drive, Box, Salesforce, Slack and more.

Well this week went on for a bit, an hour and 6 mins in all. The 2 Apple things were particularly interesting due to the way in which both catching CSAM baddies and catching baddies who steal your things involves using technology that can be abused. Is it good tech

Continue reading Weekly Update 256

Why No HTTPS? The 2021 Version

Presently sponsored by: Varonis. Reduce your SaaS blast radius with data-centric security for AWS, G Drive, Box, Salesforce, Slack and more.

More than 3 years ago now, Scott Helme and I launched a little project called Why No HTTPS? It listed the world’s largest websites that didn’t properly redirect insecure requests to secure ones. We updated it December before last and pleasingly, noted that more websites than

Continue reading Why No HTTPS? The 2021 Version

Welcoming the Turkish Government to Have I Been Pwned

Presently sponsored by: Varonis. Reduce your SaaS blast radius with data-centric security for AWS, G Drive, Box, Salesforce, Slack and more.

Today I’m very happy to welcome the national Turkish CERT to Have I Been Pwned, TR-CERT or USOM, the National Cyber ​​Incident Response Center. They are now the 26th government to have complete and free API level access to query their government domains.

Providing governments with

Continue reading Welcoming the Turkish Government to Have I Been Pwned