Technology Get the latest on technology, electronics and software…

The Official Internet/Computer Security News Discussion Thread

Thread Tools
 
Old 01-27-2020, 06:06 PM
  #561  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts
New Intel Vulnerability
https://cacheoutattack.com/
https://www.pcworld.com/article/3516...ving-soon.html

List of affected products
https://software.intel.com/security-...ction-sampling
Old 04-14-2020, 12:07 PM
  #562  
Moderator
 
Mizouse's Avatar
 
Join Date: Oct 2004
Location: Not Las Vegas (SF Bay Area)
Age: 40
Posts: 63,276
Received 2,793 Likes on 1,988 Posts
https://www.bleepingcomputer.com/new...-the-dark-web/

LOL, never trusted Zoom.

Also my company sent out a companywide email at the beginning of the shelter at home to not use Zoom due to security issues.
Old 04-14-2020, 12:51 PM
  #563  
Senior Moderator
 
thoiboi's Avatar
 
Join Date: Apr 2010
Location: SoCal, CA
Posts: 47,187
Received 8,709 Likes on 6,716 Posts
Update 4/13/20: Made it clearer that credential stuffing attacks are not unique to Zoom. and added AmIBreached service from Cyble.



Any site is susceptible to credential stuffing if they don't have 2FA/MFA enabled and we continue to have an uneducated populace who insists on using the same username/password on every site
The following users liked this post:
Mizouse (04-14-2020)
Old 04-14-2020, 03:04 PM
  #564  
Moderator
 
Mizouse's Avatar
 
Join Date: Oct 2004
Location: Not Las Vegas (SF Bay Area)
Age: 40
Posts: 63,276
Received 2,793 Likes on 1,988 Posts
it was TLDR
Old 04-15-2020, 08:32 AM
  #565  
Moderator
Regional Coordinator (Southeast)
 
CCColtsicehockey's Avatar
 
Join Date: Dec 2003
Location: Mooresville, NC
Age: 38
Posts: 43,593
Received 3,789 Likes on 2,555 Posts
@thoiboi or anyone else? Just asking but do you guys go as far as using different passwords for even internet forums? Just curious what most people do. I do for everything remotely even critical but if someone really wants to post as me so bad on a car site or other internet forums then have at it. I know I could start adding those sites to my password manager but just haven't bothered.
Old 04-15-2020, 11:02 AM
  #566  
Moderator
 
Mizouse's Avatar
 
Join Date: Oct 2004
Location: Not Las Vegas (SF Bay Area)
Age: 40
Posts: 63,276
Received 2,793 Likes on 1,988 Posts
i use a password manager. so everything gets a different password.
The following users liked this post:
#1 STUNNA (04-17-2020)
Old 04-15-2020, 01:40 PM
  #567  
Senior Moderator
 
thoiboi's Avatar
 
Join Date: Apr 2010
Location: SoCal, CA
Posts: 47,187
Received 8,709 Likes on 6,716 Posts
1Password password generator for most/all websites. It works for me, i love it.
The following users liked this post:
#1 STUNNA (04-17-2020)
Old 04-15-2020, 01:51 PM
  #568  
Moderator
 
Mizouse's Avatar
 
Join Date: Oct 2004
Location: Not Las Vegas (SF Bay Area)
Age: 40
Posts: 63,276
Received 2,793 Likes on 1,988 Posts
Originally Posted by thoiboi
1Password password generator for most/all websites. It works for me, i love it.
yup, i use 1Password too. also Apple iCloud Keychain.
Old 04-17-2020, 05:26 PM
  #569  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 44,101
Received 10,486 Likes on 6,356 Posts
Yup, I use LastPass. Every website has a gibberish randomly generated password. I only know my Lastpass, Apple ID, and the passwords for my computers
Old 12-19-2020, 10:22 AM
  #570  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts
https://www.extremetech.com/computin...erable-in-2019

Security Researcher: ‘solarwinds123’ Password Left Firm Vulnerable in 2019

...
Security researcher Vinoth Kumar told Reuters that he contacted the company in 2019, alerting it that anyone could access its update server by guessing the password “solarwinds123.” Reuters also reports that hackers claiming they could sell access to SolarWinds’ computers since 2017. It is not clear from the wording of the story whether the offer was for a method of infiltrating SolarWinds itself, or if the black hat was offering to sell access to computers that used SolarWinds software.

“Kyle Hanslovan, the cofounder of Maryland-based cybersecurity company Huntress – noticed that, days after SolarWinds realized their software had been compromised, the malicious updates were still available for download.”

I want to be clear that this specific password is
not thought to be the means by which Cozy Bear accessed SolarWinds network management tool, dubbed Orion, but it speaks to a terrible security culture at the company, given the data security needs of its customers. Because Orion is often used to manage routers and switches inside large corporate networks, penetrating the software gave black hats a marvelous window into the external and internal network traffic of nearly 20,000 companies, federal agencies, and other types of organizations.
...


Old 12-19-2020, 01:21 PM
  #571  
Senior Moderator
 
Yumcha's Avatar
 
Join Date: Dec 2001
Posts: 167,491
Received 22,854 Likes on 14,002 Posts
Exclamation US scrambling to understand fallout of suspected Russia hack

Sigh.

https://www.theguardian.com/technolo...ncies-congress
Old 12-19-2020, 02:14 PM
  #572  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts
Wait until we find out that Dominion was indeed hacked, but the hackers thought that 10,000,000 extra votes for Don would be way more than enough. It makes sense that Don was pissed at Dominion and Putin didn't congratulate Biden until the Electoral College did its thing.

Last edited by doopstr; 12-19-2020 at 02:25 PM.
Old 12-19-2020, 02:46 PM
  #573  
Registered but harmless
 
Will Y.'s Avatar
 
Join Date: Aug 2005
Location: Los Angeles, CA
Age: 59
Posts: 14,847
Received 1,107 Likes on 765 Posts
Originally Posted by Yumcha
But Loser donnie says( ok, tweets) that it could just as easily be China that did the hack. Why blame Russia?
Old 12-19-2020, 02:49 PM
  #574  
Senior Moderator
 
Yumcha's Avatar
 
Join Date: Dec 2001
Posts: 167,491
Received 22,854 Likes on 14,002 Posts
Originally Posted by Will Y.
But Loser donnie says( ok, tweets) that it could just as easily be China that did the hack. Why blame Russia?
China, Iran, Canada, Mexico, Germany, Britain, France, Italy, Chad, Brazil, Peru, Panama, South Korea...

Anyone BUT Russia.
Old 01-23-2021, 09:24 PM
  #575  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts
https://www.businessinsider.in/stock...w/80406500.cms

Intel drops 9% after a reported hack forced the chipmaker to release its 4th-quarter earnings early

Shares in Intel fell as much as 9% on Friday, after the company said its corporate website was hacked, pushing the chipmaker to release its fourth-quarter earnings earlier than planned.

George Davis, Intel's chief financial offer, told the Financial Times a hacker gained unauthorized access to sensitive data tied to its earnings report that was set to be published after the market close on Thursday. But upon finding out about the attack, the chipmaker released its results six minutes before the market close.
"An infographic was hacked off of our PR newsroom site," Davis told the newspaper. "We put our earnings out as soon as we were aware." Without providing further details, he said the breach was caused by an unlawful action that didn't involve any unintentional disclosure by Intel.An Intel spokesperson told Insider the company is investigating reports that non-authorized access may have been obtained to one graphic from its earnings report.Intel's fourth-quarter results exceeded investor expectations and beat the company's own forecast on the back of strong PC sales. The chipmaker saw quarterly revenue fall 1% year-on-year to $20 billion, but still beat the $17.49 billion estimate of analysts polled by Refinitiv. Net income for the quarter came in at $1.52 per share, compared to $1.10 expected.
Intel's shares closed up almost 7% at $62.46 on Thursday, but erased gains after the reported hacker's access to information.


Old 08-18-2022, 07:10 PM
  #576  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 44,101
Received 10,486 Likes on 6,356 Posts
Old 08-19-2022, 12:35 PM
  #577  
Moderator
 
Mizouse's Avatar
 
Join Date: Oct 2004
Location: Not Las Vegas (SF Bay Area)
Age: 40
Posts: 63,276
Received 2,793 Likes on 1,988 Posts
Fkn annoying you have to update the entire OS just for a security update with Safari.
Should be pushed independently or maybe via the App Store.

edit: just remembered that this will be a new feature in iOS 16. The Rapid Security Responses. Took them long enough.

Last edited by Mizouse; 08-19-2022 at 12:37 PM. Reason: I’m dumb
Old 08-20-2022, 07:51 PM
  #578  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts
I hate how long it takes to manually update an iPhone now. Mac takes forever too.
The following users liked this post:
#1 STUNNA (08-21-2022)
Old 01-17-2023, 09:15 PM
  #579  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 44,101
Received 10,486 Likes on 6,356 Posts
Well this fucking sucks. LastPass got hacked badly. They got hacked months ago and just finally the Thursday before Christmas announced that hackers had got into their 3rd party backup server and stole ALL the data. Not just customer names and email addresses, fucking everything. Everyone's LastPass vaults are now in the hands of hackers so if your master password wasn't secure you're fucked.

They now have until the end of time to crack the master password and once they do they have access to all of your accounts. Yout now have to reset the password for every website you had saved in LastPass.

Most security experts are saying to switch to another Password Manager. I'm switching to 1Password. Bit Warden is supposedly another good option. 1Password is better than LastPass because they encrypt everything, LastPass didn't encrypt the website URLs so hackers can see what sites they'll gain access to before cracking your master password, 1Pass also uses a master password along with a secret key that they don't know or store anywhere so if they were to get hacked as bad as LastPass they still wouldn't be able to signin without the secret key.

It was easy to move your passwords over to 1Password

Follow this guide

https://support.1password.com/import-lastpass/

1Pass is also offering to refund me for the rest of my LastPass subscription, going through that process now.

Old 01-17-2023, 09:41 PM
  #580  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts
Pisses me off. Just within the last few years I stopped relying on my browser's password store and started using Last Pass. I should have dumped them when they started charging to use it on laptop and mobile. On the bright side I do have a complex master password.
Old 01-20-2023, 02:33 PM
  #581  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 44,101
Received 10,486 Likes on 6,356 Posts
Since i had 6 months left on my LastPass subscription 1Pass is giving me half off the first year (pricing between both are about the same) to switch

If you switch go here to get a partial discount

https://1password.com/switch
The following users liked this post:
doopstr (01-20-2023)
Old 01-20-2023, 04:58 PM
  #582  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts


T-Mobile announces another data breach, impacting 37 million accounts

https://www.theverge.com/2023/1/20/23563825/tmobile-data-breach-api-customer-accounts-hacker-security
The attacker obtained customer names, billing addresses, emails, phone numbers, and birth dates through an internal API.
Old 01-21-2023, 06:13 PM
  #583  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 44,101
Received 10,486 Likes on 6,356 Posts
1Password has a builtin 2FA capability, if you set it up as the authenticator app then it will autofill the 6 digit code, no need to open a 2nd app. This is huge.
Old 03-04-2023, 04:40 PM
  #584  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts
https://www.forbes.com/sites/daveywi...h=7d65e43d28fc

The final LastPass hack attack bombshell drops

"This was accomplished by targeting the DevOps engineer’s home computer and exploiting a vulnerable third-party media software package, which enabled remote code execution capability and allowed the threat actor to implant keylogger malware. The threat actor was able to capture the employee’s master password as it was entered, after the employee authenticated with MFA, and gain access to the DevOps engineer’s LastPass corporate vault."
The following users liked this post:
#1 STUNNA (03-04-2023)
Old 03-04-2023, 07:41 PM
  #585  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 44,101
Received 10,486 Likes on 6,356 Posts
Originally Posted by #1 STUNNA
1Password has a builtin 2FA capability, if you set it up as the authenticator app then it will autofill the 6 digit code, no need to open a 2nd app. This is huge.

It works in iOS too, sort of, it automatically puts the code into your iOS clipboard but you still have to manually paste it in
Old 03-23-2023, 02:45 PM
  #586  
Moderator
 
Mizouse's Avatar
 
Join Date: Oct 2004
Location: Not Las Vegas (SF Bay Area)
Age: 40
Posts: 63,276
Received 2,793 Likes on 1,988 Posts



https://www.theverge.com/2023/3/23/2...ck-crypto-scam

Last edited by Mizouse; 03-23-2023 at 02:48 PM.
The following 2 users liked this post by Mizouse:
#1 STUNNA (03-26-2023), doopstr (03-23-2023)
Old 03-25-2023, 11:15 PM
  #587  
Moderator
 
Mizouse's Avatar
 
Join Date: Oct 2004
Location: Not Las Vegas (SF Bay Area)
Age: 40
Posts: 63,276
Received 2,793 Likes on 1,988 Posts
The following users liked this post:
#1 STUNNA (03-26-2023)
Old 04-02-2023, 05:34 PM
  #588  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts
lol, just went to icloud.com. Cert error, expired. Come on Apple.

Old 06-02-2023, 04:22 PM
  #589  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts

https://arstechnica.com/security/202...ware-backdoor/

Millions of PC motherboards were sold with a firmware backdoor

Hidden code in many Gigabyte motherboards invisibly and insecurely downloads programs.

Old 08-22-2023, 07:47 AM
  #590  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 44,101
Received 10,486 Likes on 6,356 Posts
@Whiskers
Old 08-22-2023, 09:46 AM
  #591  
Go Giants
 
Whiskers's Avatar
 
Join Date: Aug 2004
Location: PA
Age: 53
Posts: 69,916
Received 1,235 Likes on 824 Posts
Meh
Old 09-02-2023, 06:13 PM
  #592  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts
Any reason why I wouldn't want to use Google Password Manager as a replacement for LastPass?
Old 09-07-2023, 09:29 AM
  #593  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 44,101
Received 10,486 Likes on 6,356 Posts

“I’m confident enough that this is a real problem that I’ve been urging my friends and family who use LastPass to change all of their passwords and migrate any crypto that may have been exposed, despite knowing full well how tedious that is.”
Old 09-07-2023, 08:32 PM
  #594  
Moderator
 
Mizouse's Avatar
 
Join Date: Oct 2004
Location: Not Las Vegas (SF Bay Area)
Age: 40
Posts: 63,276
Received 2,793 Likes on 1,988 Posts
Updating my phone. I have recently gotten a couple text messages with an image related to Bitcoin and some link.

annoyingly if I want to click the “report junk” button I have to open the message.


https://arstechnica.com/gadgets/2023...ios-macos/amp/


Apple patches “clickless” 0-day image processing vulnerability in iOS, macOS

Old 09-10-2023, 10:16 AM
  #595  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts
Originally Posted by #1 STUNNA
https://twitter.com/verge/status/1699736894844661847

“I’m confident enough that this is a real problem that I’ve been urging my friends and family who use LastPass to change all of their passwords and migrate any crypto that may have been exposed, despite knowing full well how tedious that is.”
Ugh, I have 125 passwords in mine. Here I go.
Old 09-11-2023, 03:43 PM
  #596  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 44,101
Received 10,486 Likes on 6,356 Posts
Yeah it sucks
Old 09-12-2023, 03:36 PM
  #597  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts
I'd like the 4 hours of my life back I used to change the passwords of the sites that I cared about. I think it was the first time that I changed my AZ password in 22 years.
The following users liked this post:
#1 STUNNA (09-12-2023)
Old 09-12-2023, 05:12 PM
  #598  
Sanest Florida Man
Thread Starter
 
#1 STUNNA's Avatar
 
Join Date: Aug 2007
Location: Florida
Posts: 44,101
Received 10,486 Likes on 6,356 Posts
I hope you used random generated passwords
Old 06-08-2024, 07:07 AM
  #599  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts
The following users liked this post:
#1 STUNNA (06-08-2024)
Old 07-19-2024, 04:10 PM
  #600  
Team Owner
 
doopstr's Avatar
 
Join Date: Jan 2001
Location: Jersey
Age: 52
Posts: 25,430
Received 2,177 Likes on 1,194 Posts



Quick Reply: The Official Internet/Computer Security News Discussion Thread



All times are GMT -5. The time now is 04:26 AM.