The IEEE is against mandated encryption backdoors

The Institute of Electrical and Electronics Engineers (IEEE) has added its voice to the chorus of security experts, privacy advocates, lawmakers and other prominent individuals who are against the idea of mandated encryption backdoors. “We oppose… Continue reading The IEEE is against mandated encryption backdoors

Women in Information Security: Nitha Suresh

Last time, I talked with Glenda Snodgrass. She’s a founder and the president of The Net Effect, a cybersecurity services company. This time, I had a fascinating discussion with Nitha Suresh. She taught me a bit about penetration testing and aircraft data networks. Kimberly Crawley: Hi Nitha! Tell me a bit about what you do. […]… Read More

The post Women in Information Security: Nitha Suresh appeared first on The State of Security.

The post Women in Information Security: Nitha Suresh appeared first on Security Boulevard.

Continue reading Women in Information Security: Nitha Suresh

VU#739007: IEEE P1735 implementations may have weak cryptographic protections

The P1735 IEEE standard describes methods for encrypting electronic-design intellectual property(IP),as well as the management of access rights for such IP. The methods are flawed and,in the most egregious cases,enable attack vectors that allow recovery of the entire underlying plaintext IP. Implementations of IEEE P1735 may be weak to cryptographic attacks that allow an attacker to obtain plaintext intellectual property without the key,among other impacts. Continue reading VU#739007: IEEE P1735 implementations may have weak cryptographic protections

Attack Method Highlights Weaknesses in Microsoft CFG

As Microsoft hardens its defenses with tools such as Control Flow Guard, researchers at Endgame are preparing for the reality of Counterfeit Object-Oriented Programming attacks to move from theoretical to real. Continue reading Attack Method Highlights Weaknesses in Microsoft CFG