Category Archives: Security
Facebook: We Failed Timeline Hacker
Facebook has long been associated with all manner of negative connotations, from murder, rape, party-crashing, yet, when one person tries to point out a security hole, they getting the virtual equivalent of a f**k off, denial that it is a bug, and a metaphorical middle finger? So the hacker then takes it higher and gets suspended for violating T+Cs? Why am I not surprised by Facebook’s behaviour? Because that is what I have come to expect of Facebook.
I am thankful I have no Facebook account. I used to many moons ago, and terminating it was probably the best decision of my life.
LastPass Passwords Exposed for Some Internet Explorer Users
Internet Explorer, a malicious hacker’s dream. Am I the only one to think that as long as you have it installed, you’ve got a hole in your system?
LastPass Passwords Exposed for Some Internet Explorer Users.
Do you have the dumbest PIN in ATM history?- MSN Money
Is your Credit/Debit/ATM card PIN in this list? Change it — NOW.
1. 1234
2. 1111
3. 0000
4. 1212
5. 7777
6. 1004
7. 2000
8. 4444
9. 2222
10. 6969
Security
As a result of the Ubuntu Forums hack recently, I’ve now had to spend several hours going through all my internet logins accounts to see whether or not I have used the same password anywhere else. Not surprising, I have so I have to go through and change them all. Fortunately, LastPass allows me to generate secure passwords which I can use to replace other passwords. The only real place where I would be concerned if they have access would by emails, but I have 2-factor authentication turned on there, and have had it turned on for many months, and they need my email address, password AND phone to get into my account. Even my backup codes are stored on a TrueCrypt volume stored on a LUKS partition on my laptop so they would need two passwords to get at those.
Mind you, it IS good that these forums were hacked, it’s given me a reason to go through my accounts and see which ones I still use and which ones I can delete.
Related articles
- Ubuntuforums.org Hacked (it.slashdot.org)
- Ubuntu Forums (blenderfox.com)
- Ubuntu Forums Hacked, All User Names and Passwords Have Been Stolen (news.softpedia.com)
- IMPORTANT! Ubuntu Forums Hacked (unixmen.com)
- Ubuntu Forums Hacked, 1.8 Million Passwords, E-Mails & Usernames Stolen (omgubuntu.co.uk)
- The Most Unsafe Passwords of 2012 Look a Lot Like the Ones from 2011 (staples.com)
- Email and passwords compromised after attack on Ubuntu Forums (news.en.softonic.com)
- Ubuntu forum hack sets same-password users at risk (itwriting.com)
- Ubuntu Forum Security Breach (news.slashdot.org)
- Notice of security breach on Ubuntu Forums site (canonical.com)
Ubuntu Forums
Hello,
You are receiving this message because you have an account registered with this address on ubuntuforums.org.
The Ubuntu forums software was compromised by an external attacker. As a result, the attacker has gained access to read your username, email address and an encrypted copy of your password from the forum database.
If you have used this password and email address to authenticate at any other website, you are urged to reset the password on those accounts immediately as the attacker may be able to use the compromised personal information to access these other accounts. It is important to have a distinct password for different accounts.
The ubuntuforums.org website is currently offline and we are working to restore this service. Please take the time to change your ubuntuforums.org account password when service is restored.
We apologize for any inconvenience to the Ubuntu community, thank you for your understanding.
The Canonical Sysadmins.
Related articles
- Ubuntu Forums Hacked, All User Names and Passwords Have Been Stolen (news.softpedia.com)
- Ubuntu Forums Hacked (sucuri.net)
- Ubuntuforums.org Hacked (it.slashdot.org)
- Email and passwords compromised after attack on Ubuntu Forums (news.en.softonic.com)
- Notice of security breach on Ubuntu Forums site (canonical.com)
- Neil Oosthuizen: Ubuntu Forums (nlsthzn.com)
- Ubuntu Forums Hacked – Millions of Username, password, email address stolen (ehackingnews.com)
- Linux forum hacked and user details collected (pcauthority.com.au)
- Passwords of 1.8M Ubuntu Forums users compromised in hack (net-security.org)
Google WTF
Just got this in the email from Google Wallet:
Hello,
As you may know from your existing banking relationships, European law requires that payments providers take steps to verify the identities of their customers. Google has designed procedures to comply with those requirements while protecting and respecting the confidentiality of your personal information.
Please be aware that your account has been temporarily suspended and will remain so until you have completed our verification process. To learn how to resolve this issue, please visit the following link within three business days:
http://support.google.com/wallet/bin/request.py?hl=en&contact_type=bvid
Please note that failure to provide the requested verification documents may result in account closure.
Sincerely,
The Google Wallet TeamGoogle Payment Ltd is authorised and regulated by the Financial Services Authority.
Google Payment Ltd is a company registered in England and Wales with company number 5903713. Its registered address is Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ.
Sincerely,The Google Wallet Account
Checking the link (which isn’t phished by the looks of it) says they want a scan of two forms of ID. One of:
- Identification cannot be expired.
- Driver’s license
- Passport information page
- National identification card
- State-issued identification
- Permanent residence card
- A different form of government-issued identification
and one of:
- Bank statement
- Credit/debit card statement with the first 12 digits blacked out (Do not send an image of your credit card).
- Utility bill
There is NO WAY I’m going to upload scans of my ID to any company unless its required for things such as security clearance or country visas, or required for work-related purposes.
Clicked on “Report Phishing” :)
Tails – Privacy for anyone anywhere
In case you haven’t seen this, Tails (The Amnesic Incognito Live System) is a live incognito DVD/USB which you can use to boot off any machine that supports USB boot (and for those which don’t boot of USB, you can use PLOP).
All connections go through Tor and since its a live disk, nothing is left on the hard disk (unless you choose to save something off the Internet, I guess).
I’ve been tinkering with Tor and managed to get my DNS routed through Tor, with my normal DNS as a backup, although routing traffic is a bit tricker, since not applications like to play with the Tor network properly. Some applications such as Vuze provide SOCKS capability, which allows routing of traffic through the Tor network via proxy. Others, like Chrome/Chromium don’t offer this as well, and you have to fudge it.
Bitbucket Outage
Looks like it wasn’t just me that was having trouble with the BB service.
They mention a webcrawler caused the problem. I wonder which one it was? ¬_¬
2-step verification – Accounts Help
Some may not know, but Google supports 2FA (2-Factor Authentication), and this basically means you need two items of information to log into your Google Account. Paypal also has this option.
I only found out about this through LastPass when I was cleaning up some old (and no longer used) accounts. This is worth a look and maybe switching on. But, as with most forms of authentication, you need to balance the convenience and risk (See related articles)
2-step verification – Accounts Help.
Related articles
- Google 2-step login verification flaw allows account hijacking (net-security.org)
- How We Extended Google 2FA to Every SaaS App (meldium.com)
- Bypassing Google’s Two-Factor Authentication (duosecurity.com)
- Google squishes login-bypass bug perfect for account hijackers (go.theregister.com)


