Sunday, February 21st, 2016 (
No comments yet)
When I teach, I explain how most of the breaches and problems you hear in the world aren't about clever hackers or sophisticated attackers, but instead about weak security. This has just become my new go-to example.
Basically after you logged into your account as a Citi customer, the URL contained a code identifying your account. All you had to do was change around the numbers and boom, you were in someone else's account.
What that means is that if you were to look at the address in your bar at the top of the browser, it contains the name of the website you're on and (as is typical) a whole lot of other junk like this:
http://www.citibank.com/account.asp?were=dumbbell&we=shouldhaveknownbetter
One of the values in the "lots of other junk" area told Citibank who's account to show. If you just entered any random number, the website would think you were the user with that ID and show you their page. Given that this kind of issue is one that security professionals have known about and handled for more than a decade apparently large (and rich) companies can somehow manage to forget the basics.
Source
Tags:
Account Security,
Banks,
Big Business,
Negligence,
Utter Failure
Tuesday, March 19th, 2019 (
No comments yet)
Ok so maybe not ONE click. But someone has put together a simple tool that you can use to take over the active sessions of anyone within wireless range of you. Hang out at the Starbucks free wi-fi and you'll be able to control the Facebook or other accounts of people nearby. It's an attack that was always simple to do for those who know how, but now any idiot can do it with a simple new interface.
By the way, they mention a few protections from this at the bottom of the article, but here's one more.
Tags:
Account Security,
Facebook,
Hacking
Saturday, March 23rd, 2019 (
No comments yet)
Of course this isn't a problem limited only to Facebook, but the FBI issued a warning about the rise of hijacking scams. This is where a bad guy gets your login information through various means and then poses as you on your account. They'll send an urgent request for help or money to all your friends who may be fooled and comply (as in the case of Bryan Rutberg).
Tags:
Account Security,
Facebook,
FBI,
Hijacking,
Identity Theft,
Internet,
Scams - Ripoffs - Dirty Tricks,
Social Networking
Monday, March 25th, 2019 (
No comments yet)
Sarah Palin's Yahoo account has been broken into and e-mails found there posted to Wikileaks. I would say this was a pretty rotten thing to do, but the perpetrators claim they did it to prove that Palin has been using her private e-mail to circumvent recordkeeping laws about government business. If that's true, then perhaps this needed to happen.
Tags:
Account Security,
Congress,
Hacking,
Onstar,
Sarah Palin