Googlephone security team seeks bug hunters - The Register - Security

20 August, 2008 11:37 AM
Android needs You

Google's Android security team has appealed to bug hunters to help it iron out flaws in the platform.…

Gag order lifted for students who hacked subway card - The Register - Security

19 August, 2008 10:46 PM
MIT students free to discuss gaping holes

Three Massachusetts Institute of Technology undergraduates are once again free to publicly discuss gaping security holes in the Boston subway system after a federal judge refused to renew a gag order requested by transportation officials.…

Mystery Fedora disruption prompts security fears - The Register - Security

19 August, 2008 03:54 PM
Did security breach prompt ground-up rebuild?

The majority of servers supporting the Fedora Linux distribution were back online on Tuesday following a mystery disruption.…

Goldfish customers sent wrong bills - The Register - Security

19 August, 2008 01:34 PM
'We're sorry about that. We're sorry about that'

A printing mix-up resulted in thousands of Goldfish credit card customers receiving other people's bills.…

Vodafone exec stabbed to death in country home - The Register - Security

19 August, 2008 11:05 AM
Man questioned

Police are questioning a man following the murder of a senior Vodafone UK executive on Saturday.…

Symantec nabs PC Tools for added street cred - The Register - Security

19 August, 2008 09:48 AM
G'day to added anti-spyware

Security and storage giant Symantec has agreed to buy specialist Australian-based anti-spyware firm PC Tools. Terms of the deal were undisclosed in Monday's announcement.…

'Malvertizement' epidemic visits house of Newsweek.com - The Register - Security

18 August, 2008 07:48 PM
Symptoms felt 'all over the net'

Newsweek.com is one of several high-profile websites suspected of running rogue banner advertisements that try to trick visitors into installing fraudulent anti-malware programs, security researchers warn.…

Pirated movie downloads offered as Zango sweetener - The Register - Security

18 August, 2008 05:27 PM
Holy warez, Batman

Zango affiliates are offering gateway access to pirated films, including the Hollywood blockbuster The Dark Knight, in a bid to induce users into accepting adware.…

Cisco plugs online meeting bug - The Register - Security

18 August, 2008 11:40 AM
Buffer buffed

Cisco has plugged a buffer overflow flaw involving its popular WebEx online meeting client.…

North Queenslanders - You got to love them! - Beast Or Buddha

18 August, 2008 12:30 AM

With in-laws up there, I must admit to having a soft-spot for North Queenslanders. There’s been books written about them and regularly, they’ll come up with some beauties. Great start to another week:

Mount Isa Mayor invites “ugly women” - giving them a chance to find a bloke!
http://www.townsvillebulletin.com.au/article/2008/08/16/15499_news.html

Now we stumbled upon this one by chance. The section on what “ladies” should wear is a classic:
http://www.cairnsdining.com/xmasparty-etiquette.html

There should be a whole blog dedicated to North Queesland stories!

Dummies Guide to Internet Security v.43564563 - Beast Or Buddha

16 August, 2008 03:35 PM

Yes, some are still paid to teach us the problems:

http://www.cpni.gov.uk/Products/technicalnotes/3677.aspx

Thank you! 2008?

GlobalSign revokes cert of rogue security app - The Register - Security

16 August, 2008 08:57 AM
Certified malware exposes shortcomings of digital certificates

GlobalSign has revoked the digital certificate of a rogue security application, which acquired the veneer of respectability by parading the credentials while trying to scam users.…

Mystery web attack hijacks your clipboard - The Register - Security

15 August, 2008 06:02 PM
No, Macs are not immune

A new web-based attack is making the rounds that tries to spread poisonous links by hijacking end users' clipboards.…

Microsoft ramps up vuln ActiveX controls cull - The Register - Security

15 August, 2008 03:58 PM
Third-party fire and exploit block

This week's Patch Tuesday update was nearly as difficult to digest as a Michael Phelp's breakfast. It contained 11 bulletins covering 26 underlying vulnerabilities, the most in two years.…

Murdered Chinese students linked to online betting scam - The Register - Security

15 August, 2008 10:14 AM
Forum threats over football bets

The two Chinese Newcastle University graduates murdered last weekend could be linked to a complex web betting scam, Northumbrian Police believe.…

Home Office reaches half-way hash in secure data handling - The Register - Security

15 August, 2008 10:09 AM
Encryption bureau to operate like internal post office

Analysis The UK Home Office has introduced procedures to handle encrypted personal data from external partners. However, guidelines on how the new Home Office Central Cryptography service will work raise concerns about possible shortcomings with the service which, while a big improvement, falls below best practice in sectors such as banking.…

Judge refuses to lift order squelching students' subway card hack - The Register - Security

14 August, 2008 11:39 PM
Can't get no relief

A federal judge has refused to strike down an order gagging three Massachusetts Institute of Technology undergraduates from discussing gaping security holes in electronic payment systems used by Boston's transit agency.…

Bear prints found on Georgian cyber-attacks - The Register - Security

14 August, 2008 04:08 PM
Shots by both sides

Security researchers claim to have uncovered evidence pointing to a link between Russian state-run businesses and cyber-attacks against Georgia.…

µTorrent silently fixes long-standing zero-day vuln - The Register - Security

14 August, 2008 01:54 PM
No fanfare here

Popular BitTorrent client µTorrent has quietly patched a vulnerability that created a means for hackers to load malware onto the PCs of file-sharers simply by persuading them to open a poisoned Torrent.…

AOL phisher jailed for 7 years - The Register - Security

14 August, 2008 11:31 AM
Greeting card scam man gets maximum sentence

A Connecticut man was sentenced to seven years in prison on Wednesday for masterminding a phishing scam targeting AOL members.…

Apple faithful snared in phishing scam targeting Mac.com users - The Register - Security

13 August, 2008 11:26 PM
More MobileMe carnage

Hundreds of Mac users have been snared in a phishing scam that coincided with the glitches in the roll-out Apple's MobileMe service.…

Security researchers' accounts ransacked in embarrasing hacklash - The Register - Security

13 August, 2008 07:26 PM
'War' aims to shame

On Sunday morning, security consultant Alan Shimel woke to discover that his personal blog, which is frequented by countless peers and reporters, was pointing to a website featuring explicit gay porn. Equally disturbing, he found someone had cracked open his Yahoo! Mail account and aired sensitive documents he filed with the Internal Revenue Service.…

Cybercrime bust highlights PIN terminal insecurity - The Register - Security

13 August, 2008 04:16 PM
Clear and present danger

Analysis UK police arrests of a gang reckoned to have tampered with Chip and PIN entry devices to harvest PIN numbers and cardholder details have sparked calls to revamp the security of devices.…

Criminals hijack terminals to swipe Chip-and-PIN data - The Register - Security

13 August, 2008 12:39 PM
Police arrest two in raid on counterfeit card factory

Sophisticated cybercrooks have developed a technique for tampering with the PIN Entry Devices on Chip-and-PIN readers to steal users' card details and PINs.…

Bumper Patch Tuesday plugs multiple Office flaws - The Register - Security

13 August, 2008 11:32 AM
11 updates, six critical in latest Microsoft update

Critical vulnerabilities in Microsoft Office star in the latest edition of Microsoft's Patch Tuesday updates.…

How poor crypto housekeeping left OpenID open to abuse - The Register - Security

13 August, 2008 06:02 AM
Internet bouncer snooze leads to 'small earthquake'

Slipshod cryptographic housekeeping left some OpenID services far less secure than they ought to be.…

ALRC - Data Breach Notification Recommendation……Flawed Approach? - Beast Or Buddha

13 August, 2008 04:48 AM

Unless I’ve missed something and it’s certainly not in section “51. Data Breach Notification” of this 2600 plus page Australian Law Reform Commission document, we’re still lacking some fundamental basics to any data breach notification law being successful.

As it currently sits and is proposed, the organisations that stand to be impacted the most are the ones that probably have the better Information Security and Privacy policies in place.

In basic terms, if you’ve got good practices and controls in place, you’re more likely to detect a breach and/or disclosure of private and confidential information. Thus, you will have to openly disclose. No need to drill down into the potential business and reputational implications to the organisation.

If your practices and controls around information protection are weak, you’re probably clueless as to whether a breach has occured so what you don’t know doesn’t get reported. Practice the 3 monkeys approach to Information Security and proposed data breach disclosure laws will have little impact upon you.

These laws will never be succesful without supporting legislation/regulation around basic and minimum security practices and controls. See previous post on this topic:

Regulation does not need to be considered bad. See discussion on regulation here.

We can debate whether high-level statements of requirements in the Privacy Act will cut it, but in my opinion, they won’t……they haven’t so far, so what would change things now?

Colchester Hospital sacks manager over lost laptop - The Register - Security

12 August, 2008 12:27 PM
Holiday car break-in leads to dismissal

Colchester University Hospital has sacked one of its managers over the theft of his work laptop, which contained unencrypted patient records.…

Virus writers go for Olympic gold - The Register - Security

12 August, 2008 10:43 AM
Back-ends left open to superbly over-muscled Trojan

Websites carrying news of the Olympic games have been targeted in a new wave of SQL injection attacks. Vulnerabilities in sites including New Delhi Television Limited's NDTV.com have been booby-trapped with exploits designed to install malware onto users' computers.…

Patched DNS servers still vulnerable to cache poisoning - The Register - Security

11 August, 2008 09:06 PM
But the sky won't fall just yet

Large swaths of the internet remain at risk from a potentially crippling vulnerability in the net's address lookup system even after installing emergency patches, a researcher has warned.…

'I've cracked Nokia S40 security', claims researcher - The Register - Security

11 August, 2008 02:35 PM
Gimme €20k and I'll show you how

Updated A lone researcher claims to have discovered a raft of security issues with Nokia's mid-range handsets, allowing him to remotely install malicious applications with unprecedented capabilities - but he's asking for €20,000 for the details.…

Russian cybercrooks turn on Georgia - The Register - Security

11 August, 2008 01:26 PM
Infamous rent-a-bot krew gets political

Conflict between Georgia and Russia on the ground has been accompanied by the relaunch of cyber-attacks against Georgian government websites.…

Intel papers over remote attack chip flaws ahead of demo - The Register - Security

11 August, 2008 12:11 PM
Researcher's guns spiked

Intel has fixed a pair of flaws in its chips ahead of a planned demonstration of remote attacks on them by security researcher Kris Kaspersky.…

Federal judge halts Defcon talk on subway card hacking - The Register - Security

09 August, 2008 08:52 PM
Barn door closed a little too late

Defcon A federal judge on Saturday gagged three Massachusetts Institute of Technology undergraduates from publicly presenting research at Defcon demonstrating gaping holes in the electronic payment systems of one of the nation's biggest transit agencies.…

Surfing Google may be harmful to your security - The Register - Security

09 August, 2008 01:02 PM
When gadgets attack

Defcon A well-known researcher specializing in website security has strongly criticized safety on Google, arguing the world's biggest search engine needlessly puts its millions of users at risk.…

McKinnon UFO hack 'looked like cyberterrorist attack' - The Register - Security

09 August, 2008 07:53 AM
Axis of eccentricity

US prosecutors involved in the long-running fight to extradite the British Pentagon hacker Gary McKinnon have defended their dogged pursuit of the UFO hunter.…

Agency sues to stop Defcon speakers from revealing gaping holes - The Register - Security

09 August, 2008 06:08 AM
Sorry, Charlie

Defcon A transit agency in New England has filed a federal lawsuit to stop three Massachusetts Institute of Technology undergraduates from publicly presenting research at Defcon demonstrating gaping security holes in two of the agency's electronic payment systems.…

GPS tracking slapped on laptop recovery service - The Register - Security

08 August, 2008 12:15 PM
Absolute knows where your PC lives

Absolute Software has added GPS tracking to its laptop theft-recovery and asset-tracking service. This will allow asset managers to track laptops to within 10 metres.…

MS preps 12 fixes for August Patch Tuesday - The Register - Security

08 August, 2008 10:15 AM
Could this prompt a sysadmin recall?

Microsoft is preparing 12 security fixes - seven critical - as part of the August edition of its regular Patch Tuesday update cycle.…

Rogue reporters kicked out of conference for network snooping - The Register - Security

08 August, 2008 03:46 AM
When hacks hack

Black Hat Three rogue journalists were ejected from the Black Hat security conference after being accused of connecting monitoring tools to the press room computer network and sniffing reporters' passwords.…