Thursday, 7 March 2019

RSAC 2019: Better, wetter—and weirder


It’s that time again: Another RSA Conference in a rain-lashed San Francisco. This year’s theme is “Better.”

RSAC is the big infosec bunfight for hawkish vendors, arm-wavy consultants, and harassed PR mavens. Some think it’s the place to see and be seen, but others can’t wait for it to be over for yet another year.

And what caught your humble blogwatcher’s eye this year? In Security Blogwatch, we scour the Moscone Center so you don’t have to.


Read more: techbeacon.com/security/rsac-2019-better-wetter-weirder

Tuesday, 5 March 2019

Uproar Over Facebook 2FA Privacy Violation


Facebook has been caught red-handed again, so say privacy wonks. They accuse Zuckerberg’s crew of misusing phone numbers given to it for use in two-factor authentication.

Said wonks say Facebook is sharing the data with Instagram and WhatsApp to secretly link your profiles together. And that it lets miscreants look you up by your phone number, subjecting your identity to stalking, social engineering and other malicious awfulness. Facebook is also accused of violating GDPR, for using the numbers without consent.

Yet Facebook spokesdroids are unrepentant. In this inaugural SB Blogwatch, we phone a friend.


Read more: securityboulevard.com/2019/03/uproar-over-facebook-2fa-privacy-violation

Thursday, 28 February 2019

Google: 'Spectre can't be fixed.' Panic now?



Software alone can’t save us from Spectre-class vulnerabilities in modern CPUs. That’s the scary conclusion from a bone-dry research paper penned by Google engineers.

Be afraid. Be very afraid. Because there’s no evidence that CPU vendors are actually taking this thing seriously—even though they’ve known about it since June 2017 (perhaps even longer than that).

So all we have are code fixes that slow down our infrastructure without fixing the underlying problem. In this week’s Security Blogwatch, we run for the hills.


Read more: techbeacon.com/security/google-spectre-cant-be-fixed-panic-now

Friday, 15 February 2019

Richi edits another book

via Kristina Podnar:

This book, out in March 2019, lets you unleash the power of digital policy. You can sign up now to be the first to hear about the release:

kpodnar.com/book

Thursday, 14 February 2019

Hackers love Docker: Container catastrophe in 3, 2, 1...


The day we all feared would come has come. Docker and Kubernetes #containers are revealed to be badly vulnerable—along with LXC, Mesos, and several other container flavors.

An easily exploited flaw means a container can escape its paper-thin walls and execute on the host system—as root. Time to audit your trust boundaries.

Happy Valentine’s Day, DevOps peeps. In this week’s Security Blogwatch, we drop everything and patch.


Read more: techbeacon.com/security/hackers-love-docker-container-catastrophe-3-2-1