🍍David Longenecker🍍

@dnlongen
35 Followers
99 Following
91 Posts
A little red, a little blue, a little hackery, a little forensicating. #infosec and #dfir

This is a strange future. I thought I was talking with a hearing-impaired friend last night. It turned out he didn't hear a word I said - but not for the typical reason.

He was streaming a baseball game to his bluetooth-equipped hearing aids!

The CEO's password was just "password"

Whiskey.
With a side of Tango.
And a heaping helping of Foxtrot.

"For years, cybersecurity startup Tanium Inc. pitched its software by showing it working in the network of a client...but Tanium never had permission...a company selling security actually was giving outsiders an unauthorized look at information from inside its customer’s system"

https://www.wsj.com/articles/cybersecurity-startup-tanium-exposed-california-hospitals-network-in-demos-without-permission-1492624287?tesla=y

[ Yes! I know! You -can- get the money back on a fraudulent debit charge....

....after the bank has investigated, etc.

Why bother going through that hassle? Use a credit card so they act as a firewall to soak any fraudulent charges, and pay it off immediately after.]

IHG done got pwned again.

https://threatpost.com/ihg-confirms-second-credit-card-breach-impacting-1000-plus-hotels/125033/

So if you stayed at a Holiday Inn Express [or Crowne Plaza, or... ] then you probably should pay attention to your card statements.

This is why it's always better to use a credit card rather'n a debit card if possible - gamble with the bank's money, not yours.

@dnlongen Yeah. I'm just saying I think a mutually authenticated channel would be neat. Is there such a thing as diffie-hellman for humans?
@terribleplan Depends on how paranoid I am. Definitely not over a cell carrier in the vicinity of a security conference ;-)
@terribleplan that's a great question. Authenticating myself is more meaningful if I'm the one initiating the call. If the call originates from them, truth be told I am likely to hang up and call back through a trusted channel.
@munin And yes, I have given feedback privately to that effect :-)
@munin not KBI. A code sent via SMS or email. It's not ideal by any stretch of the imagination, but it's a significant step up from anyone else I have heard of.