Category Archives: Security

Denial of service attack | Building Feedly

Feedly is being hit by a DDoS. Feedly was touted as the replacement to Google Reader when Google decided to pull the plug on it. And a lot of people moved over to Feedly as a result. I was one of them.

Criminals are attacking feedly with a distributed denial of service attack (DDoS). The attacker is trying to extort us money to make it stop. We refused to give in and are working with our network providers to mitigate the attack as best as we can.

We are working in parallel with other victims of the same group and with law enforcement.

We want to apologize for the inconvenience. Please know that you data is safe and you will be able to re-access your feedly as soon as the attack is neutralized

Denial of service attack | Building Feedly.

Student Loan Company rapped after data breaches

 

The Information Commissioner’s Office (ICO) has criticised the Student Loans Company Limited after a series of data breaches involving customers’ records.

The business reported several incidents where information held about customers, including medical details and a psychological assessment, had been sent to the wrong people.

 

An ICO investigation found that not enough checks were carried out when documents were being scanned to add to customer accounts, and more sensitive documents actually received fewer checks.

Student Loan Company rapped after data breaches.

The IE flaw that Microsoft refuses to patch – Telegraph

And why are you still using Windows?

A flaw in Microsoft’s Internet Explorer which leaves users vulnerable to hackers has not been fixed, despite its discoverer giving the company six months grace to do so before publishing details.

The IE flaw that Microsoft refuses to patch – Telegraph.

Video: eBay cyber attack: why you should change your password now – Telegraph

Auction site eBay asked all its 233m users to change their passwords following a “cyber attack” that saw their names, email and postal addresses, phone numbers and dates of birth fall into the hands of hackers.

(Video inside link)

Video: eBay cyber attack: why you should change your password now – Telegraph.

Secrets, lies and Snowden’s email: why I was forced to shut down Lavabit | Comment is free | theguardian.com

The owner of Lavabit, the encrypted email service used by Edward Snowden finally tells his story. And it makes uncomfortable reading.

Secrets, lies and Snowden’s email: why I was forced to shut down Lavabit | Comment is free | theguardian.com.

Heartbleed and the after-effects

עברית: לוגו של התוסף HTTPS Everywhere לפיירפוקס

Heartbleed certainly shook up a lot of companies, and whilst a lot of companies did their best to get system updated, doing so has caused users side effects, including me.

I use an extension for Chrome/Chromium called HTTPS Everywhere and this forces HTTPS connections to the site you’re visiting. However, since the patching of Heartbleed, some sites have started misbehaving and only work “properly” if I use either the Incognito mode (which means no extensions), or if I deactivate HTTPS Everywhere for the site in question. The side effect of this, unfortunately, means my net traffic to the site in question is exposed via non-secure HTTP. Fortunately, I have encountered only two sites so far which have this problem, neither of them I am too concerned (at the moment) about:

If I encounter any more, I’ll post it here.

Has Heartbleed Made You Think Twice About Open Source Security? Think Again. | Spree Commerce

 

…when there is a need for a security patch or other bug fix, the person in control of implementation is…you. With closed source, you need to wait for the enterprise in control to fix the problem and make it available to users. For example, Akamai, one of the best, most sophisticated technology firms on the planet, is still working to address its Heartbleed vulnerabilities. Thus, users have no choice but to wait on Akamai for a complete fix. Open source users can do what they want with the code. They can use a patch that has been made available on Github, or can otherwise modify their code as they see fit. In fact, because Spree is open source and its users control their own code, they can choose to replace OpenSSL altogether if they so desire.

Has Heartbleed Made You Think Twice About Open Source Security? Think Again. | Spree Commerce.

LastPass Now Tells You Which Heartbleed-Affected Passwords to Change

 

This week, a giant security hole came to lightthat affects a large portion of the internet. As different sites recover, you’ll need to change your passwords, and now LastPass tells you when to do so.P

Due to the nature of the Heartbleed bug (read more here), you’ll need to wait until affected sites update their infrastructure before you change your passwords. LastPass’ ever-useful Security Check tool now includes recommendations for Heartbleed, letting you know which sites have closed the hole, when, and if you should update yet.P

To run the tool, just click on the LastPass extension and head to Tools > Security Check. After running the tool, you’ll get the results (shown above) so you know what passwords to change. Hit the link to read more.P

LastPass Now Tells You Which Heartbleed-Affected Passwords to Change.

Widespread Encryption Bug, Heartbleed, Can Capture Your Passwords

Some websites running SSL encryption, such as Airbnb, Pinterest, USMagazine.com, NASA, and Creative Commons, among others, were exposed to a major security bug called Heartbleed on Monday.

The bug was reportedly discovered by a member of Google’s security team and a software security firm called Codenomicon.

A number of other websites may, according to a list being distributed on GitHub, be vulnerable to the bug as well.

The bug affects web servers running Apache and Nginx software, and it has the potential to expose private information users enter into websites, applications, web email and even instant messages.

And while most security experts advise that you always use websites and services offering SSL security encryption whenever possible, the Heartbleed bug has the ability to allow malicious operators to defeat this security layer and capture passwords as well as forge authentication cookies and obtain other private information.

security patch for the bug was announced on Monday, but many websites are still playing catch up. That’s why websites like the Tor Project are, only somewhat tongue-in-cheek, advising that you stay off the Internet this week if you really care about your security.

Widespread Encryption Bug, Heartbleed, Can Capture Your Passwords.