Keeping Pace in the Race for Flexibility

Flexibility and elasticity. Both rank high on the corporate agenda in the age of digital transformation and IT is no exception. From the perspective of IT, virtualization and cloud computing have become the de facto standard for deployment m… Continue reading Keeping Pace in the Race for Flexibility

Google Chrome Drops Support for TLS 1.0 and 1.1

The latest stable release of Google Chrome, version 72, has removed support for the aging 1.0 and 1.1 versions of TLS, as well as for the problematic HTTP-based Public Key Pinning protocol and FTP resources. The Transport Layer Security (TLS) protocol… Continue reading Google Chrome Drops Support for TLS 1.0 and 1.1

Next-Gen Firewall Sizing: 5 Things to Look For

An undersized firewall can be catastrophic to your network performance, availability and security posture. Selecting a firewall that is the appropriate size for your environment is arguably the most important technical decision you, the gatekeeper of … Continue reading Next-Gen Firewall Sizing: 5 Things to Look For

Equifax, others must secure apps as part of New York settlement

The New York attorney general’s office said five apps made by well-known companies could have leaked user data. The firms – Western Union, Priceline, Equifax, Spark Networks and Credit Sesame – have agreed to revamp the security of their apps as part of a settlement announced Friday. The state office said the companies failed to use the proper protocols to secure user information that is transmitted over the internet, despite assuring users about the security of the apps in question. “Businesses that make security promises to their users – especially as it relates to personal information – have a duty to keep those promises,” said Barbara Underwood, the New York attorney general, in a statement. The AG’s office said that the apps at had a “well-known security vulnerability” that could enable man-in-the-middle attacks, whereby a hacker can intercept data when it’s sent via a wireless connection. The office explained that apps that fail […]

The post Equifax, others must secure apps as part of New York settlement appeared first on CyberScoop.

Continue reading Equifax, others must secure apps as part of New York settlement

Massive Marriott Data Breach, Secure Holiday Shopping Tips, Phishing Sites Using HTTPS – WB45

This is your Shared Security Weekly Blaze for December 3rd 2018 with your host, Tom Eston. In this week’s episode: the massive Marriott data breach, secure holiday shopping tips, and phishing sites using HTTPS. Silent Pocket is a proud sponsor of… Continue reading Massive Marriott Data Breach, Secure Holiday Shopping Tips, Phishing Sites Using HTTPS – WB45

Half of all Phishing Sites Now Have the Padlock

Maybe you were once advised to “look for the padlock” as a means of telling legitimate e-commerce sites from phishing or malware traps. Unfortunately, this has never been more useless advice. New research indicates that half of all phishing scams are n… Continue reading Half of all Phishing Sites Now Have the Padlock

HTTPS for the Internet of Things

Every day, we’re connecting more and more devices over the internet. No longer does a household have a single connected computer — there are smartphones, tablets, HVAC systems, deadbolts — you name it, it’s been connected. As the Internet of Things proliferates, it has become readily apparent that security is an issue in this space. [Andreas Spiess] has been working on this very problem, by bringing HTTPS to the ESP8266 and ESP32. 

Being the most popular platform for IOT devices, it makes sense to start with the ESP devices when improving security. In his video, [Andreas] starts at the beginning, …read more

Continue reading HTTPS for the Internet of Things

Google expands its identity management portfolio for businesses and developers

Over the course of the last year, Google has launched a number of services that bring to other companies the same BeyondCorp model for managing access to a company’s apps and data without a VPN that it uses internally. Google’s flagship product for this is Cloud Identity, which is essentially Google’s BeyondCorp, but packaged for […] Continue reading Google expands its identity management portfolio for businesses and developers

Facebook’s Fake Account Crackdown, Privacy Upgrade to HTTPS, New Security Features in Apple iOS 12 – WB36

This is your Shared Security Weekly Blaze for October 1st 2018 with your host, Tom Eston. In this week’s episode: Facebook’s fake account crackdown, privacy upgrade to HTTPS, and new security features in Apple iOS 12. Silent Pocket is a pro… Continue reading Facebook’s Fake Account Crackdown, Privacy Upgrade to HTTPS, New Security Features in Apple iOS 12 – WB36