Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
How did rapper JAY Z take the concept of Magna Carta to a whole new level?
Watch this week's 60 Second Security and find out!
? Can't view the video on this page? Watch directly from YouTube. Can't hear the audio? Click on the Captions icon for closed captions.
Google's Android operating system has another security hole. Same story as before: uou can tamper with other peoples' digitally-signed packages and Android won't notice.Rapper JAY Z's latest album release, "Magna Carta", was preceded by a custom Android app that had some privacy boffins up in arms.Tumblr managed to forget the S in HTTPS in a recent release of its iOS app. The social networking company is "tremendously sorry."
(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)
http://twitter.com/duckblog
Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Android, APK, app, carter, Code signing, data breach, Data Collection, EPIC, Exploit, exra field, Google, https, ios, Jay Z, master keys, Privacy, sniffing, Social Networking, Spam, Tumblr, vulnerability
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
News, opinion, advice and research: Chet and Duck (Chester Wisniewski and Paul Ducklin) bring you their unique and entertaining combination of all four in their regular quarter-hour programme.
Chester's been on the road, so this epsiode of the Chet Chat is a couple of days late for logistical reasons.
We apologise for that, but Chet and Duck think it's no less interesting nevertheless!
In fact, this week's main story - the two-in-a-row exploits against Android code verification - intrigued your presenters so much that they resolved to link up and record this show, come what may.
And so, here it is: SSCC Episode #113.
(You can keep up with our podcasts via RSS or iTunes, and catch up on previous Chet Chats and other Sophos podcasts by browsing our podcast archive.)
The news wires have been buzzing with the "master keys" attack, and the "extra field" attack, both of which let you create Android Package files (APKs) that show one set of content to Google's cryptographic verification, and another to the installer.
Chet and Duck explain what happened, come up with some ideas that would have avoided the problem in the first place, explain what to do about it, and wonder how long before the fixes are on your handset.
From Android to iOS, where Tumblr published a version of its app that somehow managed to leave out the part that encrypts your PII before sending it over the internet.
Chet wonders how the average user is supposed to spot that sort of bug.
Nintendo got pounded by crackers who mounted a month-long password guessing attack.
The crooks only got hold of 24,000 passwords as a result (only!), and it looks as though those successes were largely down to using dictionaries of usernames and passwords from earlier hacks.
What to do? Federated identity? Password managers? A slimmer digital lifestyle?
Chet and Duck discuss the pros and cons of various ways to address the problem of password re-use.
And Chet's going to be at BlackHat 2013, and at DEF CON, so be sure to look him up in Vegas and say, "Hi."
Duck won't be there in body but you will find him present in mind and spirit, as he's putting together a special #sophospuzzle for the occasion.
The puzzle will go up on Naked Security, so everyone can have a go, but BlackHatters can enter at Sophos's booth at the trade show and win a secret prize!
(It's a cool secret prize, which Duck lets slip in the podcast, and Chester bemoans being ineligible to win.)
Don't forget: for a regular Chet Chat fix, follow us via RSS or on iTunes.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Unless you work in the customer support business, it's possible you haven't even heard of Zendesk.. but chances are that you are familiar with some of the companies who use Zendesk's customer service portal to answer questions and build an online support community.
Big names that use Zendesk include Tumblr, Twitter and Pinterest.
And - unfortunately - hackers broke into Zendesk's systems this week and accessed the email addresses of Tumblr, Twitter and Pinterest customers who had attempted to get support.
Zendesk has published more details on its blog, under the refreshingly frank title of "We've been hacked":
We’ve become aware that a hacker accessed our system this week. As soon as we learned of the attack, we patched the vulnerability and closed the access that the hacker had. Our ongoing investigation indicates that the hacker had access to the support information that three of our customers store on our system. We believe that the hacker downloaded email addresses of users who contacted those three customers for support, as well as support email subject lines. We notified our affected customers immediately and are working with them to assist in their response.
Twitter has contacted affected users, and reassured them that passwords were not compromised as part of the Zendesk customer breach:
Emailing a small percentage of Twitter users who may have been affected by Zendesk's breach. No passwords involved. zendesk.com/blog/weve-been…— (@Support) February 22, 2013
For its part, Tumblr has sent out emails to its affected users, as you can see in the following example shared by a Naked Security reader:
You can't imagine that Tumblr, Twitter or Pinterest are delighted to find themselves in a position to send such emails to customers. Even though they weren't to blame, their customers are impacted by Zendesk's security breach.
Even though passwords were not taken as part of this hack (Zendesk wouldn't have had access to those - which is a relief), this is still a serious security incident which could have unpleasant ramifications.
For instance, the hackers who have stolen the email addresses could now craft malicious emails to the email addresses of Twitter, Pinterest and Tumblr users and try to trick them into clicking on dangerous links or attachments.
My advice if you are one of the unfortunate people impacted by the Zendesk breach is to - as always - be very careful about emails you receive, and be cautious about opening unsolicited email attachments or clicking on embedded links.