Technology Get the latest on technology, electronics and software…

The Official Internet/Computer Security News Discussion Thread

Thread Tools
 
Old Jan 27, 2020 | 06:06 PM
  #561  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
New Intel Vulnerability
https://cacheoutattack.com/
https://www.pcworld.com/article/3516...ving-soon.html

List of affected products
https://software.intel.com/security-...ction-sampling
Reply
Old Apr 14, 2020 | 12:07 PM
  #562  
Mizouse's Avatar
Moderator
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Oct 2004
Posts: 64,104
Likes: 3,360
From: Not Las Vegas (SF Bay Area)
https://www.bleepingcomputer.com/new...-the-dark-web/

LOL, never trusted Zoom.

Also my company sent out a companywide email at the beginning of the shelter at home to not use Zoom due to security issues.
Reply
Old Apr 14, 2020 | 12:51 PM
  #563  
thoiboi's Avatar
Senior Moderator
15 Year Member
Community Builder
Loved
Community Favorite
 
Joined: Apr 2010
Posts: 48,301
Likes: 9,171
From: SoCal, CA
Update 4/13/20: Made it clearer that credential stuffing attacks are not unique to Zoom. and added AmIBreached service from Cyble.



Any site is susceptible to credential stuffing if they don't have 2FA/MFA enabled and we continue to have an uneducated populace who insists on using the same username/password on every site
Reply
Old Apr 14, 2020 | 03:04 PM
  #564  
Mizouse's Avatar
Moderator
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Oct 2004
Posts: 64,104
Likes: 3,360
From: Not Las Vegas (SF Bay Area)
it was TLDR
Reply
Old Apr 15, 2020 | 08:32 AM
  #565  
CCColtsicehockey's Avatar
Moderator
Regional Coordinator (Southeast)
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Dec 2003
Posts: 44,102
Likes: 4,421
From: Mooresville, NC
@thoiboi or anyone else? Just asking but do you guys go as far as using different passwords for even internet forums? Just curious what most people do. I do for everything remotely even critical but if someone really wants to post as me so bad on a car site or other internet forums then have at it. I know I could start adding those sites to my password manager but just haven't bothered.
Reply
Old Apr 15, 2020 | 11:02 AM
  #566  
Mizouse's Avatar
Moderator
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Oct 2004
Posts: 64,104
Likes: 3,360
From: Not Las Vegas (SF Bay Area)
i use a password manager. so everything gets a different password.
Reply
Old Apr 15, 2020 | 01:40 PM
  #567  
thoiboi's Avatar
Senior Moderator
15 Year Member
Community Builder
Loved
Community Favorite
 
Joined: Apr 2010
Posts: 48,301
Likes: 9,171
From: SoCal, CA
1Password password generator for most/all websites. It works for me, i love it.
Reply
Old Apr 15, 2020 | 01:51 PM
  #568  
Mizouse's Avatar
Moderator
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Oct 2004
Posts: 64,104
Likes: 3,360
From: Not Las Vegas (SF Bay Area)
Originally Posted by thoiboi
1Password password generator for most/all websites. It works for me, i love it.
yup, i use 1Password too. also Apple iCloud Keychain.
Reply
Old Apr 17, 2020 | 05:26 PM
  #569  
#1 STUNNA's Avatar
Thread Starter
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,979
Likes: 11,763
From: Florida
Yup, I use LastPass. Every website has a gibberish randomly generated password. I only know my Lastpass, Apple ID, and the passwords for my computers
Reply
Old Dec 19, 2020 | 10:22 AM
  #570  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
https://www.extremetech.com/computin...erable-in-2019

Security Researcher: ‘solarwinds123’ Password Left Firm Vulnerable in 2019

...
Security researcher Vinoth Kumar told Reuters that he contacted the company in 2019, alerting it that anyone could access its update server by guessing the password “solarwinds123.” Reuters also reports that hackers claiming they could sell access to SolarWinds’ computers since 2017. It is not clear from the wording of the story whether the offer was for a method of infiltrating SolarWinds itself, or if the black hat was offering to sell access to computers that used SolarWinds software.

“Kyle Hanslovan, the cofounder of Maryland-based cybersecurity company Huntress – noticed that, days after SolarWinds realized their software had been compromised, the malicious updates were still available for download.”

I want to be clear that this specific password is
not thought to be the means by which Cozy Bear accessed SolarWinds network management tool, dubbed Orion, but it speaks to a terrible security culture at the company, given the data security needs of its customers. Because Orion is often used to manage routers and switches inside large corporate networks, penetrating the software gave black hats a marvelous window into the external and internal network traffic of nearly 20,000 companies, federal agencies, and other types of organizations.
...


Reply
Old Dec 19, 2020 | 01:21 PM
  #571  
Yumcha's Avatar
Senior Moderator
20 Year Member
Photogenic
Community Builder
Liked
 
Joined: Dec 2001
Posts: 169,055
Likes: 23,830
Exclamation US scrambling to understand fallout of suspected Russia hack

Sigh.

https://www.theguardian.com/technolo...ncies-congress
Reply
Old Dec 19, 2020 | 02:14 PM
  #572  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
Wait until we find out that Dominion was indeed hacked, but the hackers thought that 10,000,000 extra votes for Don would be way more than enough. It makes sense that Don was pissed at Dominion and Putin didn't congratulate Biden until the Electoral College did its thing.

Last edited by doopstr; Dec 19, 2020 at 02:25 PM.
Reply
Old Dec 19, 2020 | 02:46 PM
  #573  
Will Y.'s Avatar
Registered but harmless
20 Year Member
 
Joined: Aug 2005
Posts: 14,888
Likes: 1,164
From: Los Angeles, CA
Originally Posted by Yumcha
But Loser donnie says( ok, tweets) that it could just as easily be China that did the hack. Why blame Russia?
Reply
Old Dec 19, 2020 | 02:49 PM
  #574  
Yumcha's Avatar
Senior Moderator
20 Year Member
Photogenic
Community Builder
Liked
 
Joined: Dec 2001
Posts: 169,055
Likes: 23,830
Originally Posted by Will Y.
But Loser donnie says( ok, tweets) that it could just as easily be China that did the hack. Why blame Russia?
China, Iran, Canada, Mexico, Germany, Britain, France, Italy, Chad, Brazil, Peru, Panama, South Korea...

Anyone BUT Russia.
Reply
Old Jan 23, 2021 | 09:24 PM
  #575  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
https://www.businessinsider.in/stock...w/80406500.cms

Intel drops 9% after a reported hack forced the chipmaker to release its 4th-quarter earnings early

Shares in Intel fell as much as 9% on Friday, after the company said its corporate website was hacked, pushing the chipmaker to release its fourth-quarter earnings earlier than planned.

George Davis, Intel's chief financial offer, told the Financial Times a hacker gained unauthorized access to sensitive data tied to its earnings report that was set to be published after the market close on Thursday. But upon finding out about the attack, the chipmaker released its results six minutes before the market close.
"An infographic was hacked off of our PR newsroom site," Davis told the newspaper. "We put our earnings out as soon as we were aware." Without providing further details, he said the breach was caused by an unlawful action that didn't involve any unintentional disclosure by Intel.An Intel spokesperson told Insider the company is investigating reports that non-authorized access may have been obtained to one graphic from its earnings report.Intel's fourth-quarter results exceeded investor expectations and beat the company's own forecast on the back of strong PC sales. The chipmaker saw quarterly revenue fall 1% year-on-year to $20 billion, but still beat the $17.49 billion estimate of analysts polled by Refinitiv. Net income for the quarter came in at $1.52 per share, compared to $1.10 expected.
Intel's shares closed up almost 7% at $62.46 on Thursday, but erased gains after the reported hacker's access to information.


Reply
Old Aug 18, 2022 | 07:10 PM
  #576  
#1 STUNNA's Avatar
Thread Starter
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,979
Likes: 11,763
From: Florida
Reply
Old Aug 19, 2022 | 12:35 PM
  #577  
Mizouse's Avatar
Moderator
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Oct 2004
Posts: 64,104
Likes: 3,360
From: Not Las Vegas (SF Bay Area)
Fkn annoying you have to update the entire OS just for a security update with Safari.
Should be pushed independently or maybe via the App Store.

edit: just remembered that this will be a new feature in iOS 16. The Rapid Security Responses. Took them long enough.

Last edited by Mizouse; Aug 19, 2022 at 12:37 PM. Reason: I’m dumb
Reply
Old Aug 20, 2022 | 07:51 PM
  #578  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
I hate how long it takes to manually update an iPhone now. Mac takes forever too.
Reply
Old Jan 17, 2023 | 09:15 PM
  #579  
#1 STUNNA's Avatar
Thread Starter
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,979
Likes: 11,763
From: Florida
Well this fucking sucks. LastPass got hacked badly. They got hacked months ago and just finally the Thursday before Christmas announced that hackers had got into their 3rd party backup server and stole ALL the data. Not just customer names and email addresses, fucking everything. Everyone's LastPass vaults are now in the hands of hackers so if your master password wasn't secure you're fucked.

They now have until the end of time to crack the master password and once they do they have access to all of your accounts. Yout now have to reset the password for every website you had saved in LastPass.

Most security experts are saying to switch to another Password Manager. I'm switching to 1Password. Bit Warden is supposedly another good option. 1Password is better than LastPass because they encrypt everything, LastPass didn't encrypt the website URLs so hackers can see what sites they'll gain access to before cracking your master password, 1Pass also uses a master password along with a secret key that they don't know or store anywhere so if they were to get hacked as bad as LastPass they still wouldn't be able to signin without the secret key.

It was easy to move your passwords over to 1Password

Follow this guide

https://support.1password.com/import-lastpass/

1Pass is also offering to refund me for the rest of my LastPass subscription, going through that process now.

Reply
Old Jan 17, 2023 | 09:41 PM
  #580  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
Pisses me off. Just within the last few years I stopped relying on my browser's password store and started using Last Pass. I should have dumped them when they started charging to use it on laptop and mobile. On the bright side I do have a complex master password.
Reply
Old Jan 20, 2023 | 02:33 PM
  #581  
#1 STUNNA's Avatar
Thread Starter
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,979
Likes: 11,763
From: Florida
Since i had 6 months left on my LastPass subscription 1Pass is giving me half off the first year (pricing between both are about the same) to switch

If you switch go here to get a partial discount

https://1password.com/switch
Reply
Old Jan 20, 2023 | 04:58 PM
  #582  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey


T-Mobile announces another data breach, impacting 37 million accounts

https://www.theverge.com/2023/1/20/23563825/tmobile-data-breach-api-customer-accounts-hacker-security
The attacker obtained customer names, billing addresses, emails, phone numbers, and birth dates through an internal API.
Reply
Old Jan 21, 2023 | 06:13 PM
  #583  
#1 STUNNA's Avatar
Thread Starter
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,979
Likes: 11,763
From: Florida
1Password has a builtin 2FA capability, if you set it up as the authenticator app then it will autofill the 6 digit code, no need to open a 2nd app. This is huge.
Reply
Old Mar 4, 2023 | 04:40 PM
  #584  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
https://www.forbes.com/sites/daveywi...h=7d65e43d28fc

The final LastPass hack attack bombshell drops

"This was accomplished by targeting the DevOps engineer’s home computer and exploiting a vulnerable third-party media software package, which enabled remote code execution capability and allowed the threat actor to implant keylogger malware. The threat actor was able to capture the employee’s master password as it was entered, after the employee authenticated with MFA, and gain access to the DevOps engineer’s LastPass corporate vault."
Reply
Old Mar 4, 2023 | 07:41 PM
  #585  
#1 STUNNA's Avatar
Thread Starter
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,979
Likes: 11,763
From: Florida
Originally Posted by #1 STUNNA
1Password has a builtin 2FA capability, if you set it up as the authenticator app then it will autofill the 6 digit code, no need to open a 2nd app. This is huge.

It works in iOS too, sort of, it automatically puts the code into your iOS clipboard but you still have to manually paste it in
Reply
Old Mar 23, 2023 | 02:45 PM
  #586  
Mizouse's Avatar
Moderator
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Oct 2004
Posts: 64,104
Likes: 3,360
From: Not Las Vegas (SF Bay Area)



https://www.theverge.com/2023/3/23/2...ck-crypto-scam

Last edited by Mizouse; Mar 23, 2023 at 02:48 PM.
Reply
Old Mar 25, 2023 | 11:15 PM
  #587  
Mizouse's Avatar
Moderator
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Oct 2004
Posts: 64,104
Likes: 3,360
From: Not Las Vegas (SF Bay Area)
Reply
Old Apr 2, 2023 | 05:34 PM
  #588  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
lol, just went to icloud.com. Cert error, expired. Come on Apple.

Reply
Old Jun 2, 2023 | 04:22 PM
  #589  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey

https://arstechnica.com/security/202...ware-backdoor/

Millions of PC motherboards were sold with a firmware backdoor

Hidden code in many Gigabyte motherboards invisibly and insecurely downloads programs.

Reply
Old Aug 22, 2023 | 07:47 AM
  #590  
#1 STUNNA's Avatar
Thread Starter
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,979
Likes: 11,763
From: Florida
@Whiskers
Reply
Old Aug 22, 2023 | 09:46 AM
  #591  
Whiskers's Avatar
Go Giants
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Aug 2004
Posts: 70,003
Likes: 1,260
From: PA
Meh
Reply
Old Sep 2, 2023 | 06:13 PM
  #592  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
Any reason why I wouldn't want to use Google Password Manager as a replacement for LastPass?
Reply
Old Sep 7, 2023 | 09:29 AM
  #593  
#1 STUNNA's Avatar
Thread Starter
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,979
Likes: 11,763
From: Florida

“I’m confident enough that this is a real problem that I’ve been urging my friends and family who use LastPass to change all of their passwords and migrate any crypto that may have been exposed, despite knowing full well how tedious that is.”
Reply
Old Sep 7, 2023 | 08:32 PM
  #594  
Mizouse's Avatar
Moderator
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Oct 2004
Posts: 64,104
Likes: 3,360
From: Not Las Vegas (SF Bay Area)
Updating my phone. I have recently gotten a couple text messages with an image related to Bitcoin and some link.

annoyingly if I want to click the “report junk” button I have to open the message.


https://arstechnica.com/gadgets/2023...ios-macos/amp/


Apple patches “clickless” 0-day image processing vulnerability in iOS, macOS

Reply
Old Sep 10, 2023 | 10:16 AM
  #595  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
Originally Posted by #1 STUNNA
https://twitter.com/verge/status/1699736894844661847

“I’m confident enough that this is a real problem that I’ve been urging my friends and family who use LastPass to change all of their passwords and migrate any crypto that may have been exposed, despite knowing full well how tedious that is.”
Ugh, I have 125 passwords in mine. Here I go.
Reply
Old Sep 11, 2023 | 03:43 PM
  #596  
#1 STUNNA's Avatar
Thread Starter
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,979
Likes: 11,763
From: Florida
Yeah it sucks
Reply
Old Sep 12, 2023 | 03:36 PM
  #597  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
I'd like the 4 hours of my life back I used to change the passwords of the sites that I cared about. I think it was the first time that I changed my AZ password in 22 years.
Reply
Old Sep 12, 2023 | 05:12 PM
  #598  
#1 STUNNA's Avatar
Thread Starter
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,979
Likes: 11,763
From: Florida
I hope you used random generated passwords
Reply
Old Jun 8, 2024 | 07:07 AM
  #599  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey
Reply
Old Jul 19, 2024 | 04:10 PM
  #600  
doopstr's Avatar
Team Owner
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2001
Posts: 25,967
Likes: 2,685
From: Jersey

Reply



All times are GMT -5. The time now is 05:13 PM.