Skip to main content

Posts

Showing posts with the label security

How to change the default KeePass password options

The post How to change the default KeePass password options appeared first on BardTech . KeePass is an open source password manager for the Windows operating system (and other operating systems thanks to ports) that ticks all the right boxes for me. While I can understand the appeal of cloud-based password managers — access your passwords everywhere as long as you have your credentials for the account at hand — it is always overshadowed by the fact that your data is saved in the cloud which has privacy and security implications. The past has shown that servers operated by companies that operated password managers are high profile targets that may get breached just like any other server and that they are not without security issues either . It should be clear that the same thing can happen to your own system but the difference is that you have full control over your own system whereas you have zero control over how your data is stored or processed if you use an online manager. ...

3 Free VPNs for Kodi (But the Best VPN for Kodi Is Paid)

The post 3 Free VPNs for Kodi (But the Best VPN for Kodi Is Paid) appeared first on BardTech . If you’re using Kodi, you’ve probably decided that a VPN is a wise idea, especially if you’re going to use some sketchy add-ons. But you aren’t ready to spend money on a proper VPN, what are your options? Well, you can start off with this list of free VPNs that you can use with your Kodi box. Do You Need a VPN for Kodi? Using a VPN ( see our guide to VPN terminology ) for Kodi is about more than avoiding detection when using illegal add-ons. Kodi is remotely hackable, and add-ons can be riddled with security flaws. Whether you’re accessing illegal content, adding legal streams, or simply using the approved add-ons, you might be making your Kodi less secure and more susceptible to man-in-the-middle and keylogger attacks. Even rogue subtitle files can hack your device! Kodi isn’t anonymous, which means that anyone observing your activity online (whether a hacker or a government agency...

John McAfee’s ‘unhackable’ Bitfi wallet got hacked — again

The post John McAfee’s ‘unhackable’ Bitfi wallet got hacked — again appeared first on BardTech . If the security community could tell you just one thing, it’s that “nothing is unhackable.” Except John McAfee’s cryptocurrency wallet, which was only unhackable until it wasn’t — twice. Security researchers have now developed a second attack, which they say can obtain all the stored funds from an unmodified Bitfi wallet. The Android-powered $120 wallet relies on a user-generated secret phrase and a “salt” value — like a phone number — to cryptographically scramble the secret phrase. The idea is that the two unique values ensure that your funds remain secure. But the researchers say that the secret phrase and salt can be extracted, allowing private keys to be generated and the funds stolen. Using this “cold boot attack,” it’s possible to steal funds even when a Bitfi wallet is switched off. There’s a video below. on a completely unrelated note, here is a @Bitfi6 being cold boot at...

Watchdog says 2020 Census systems are riddled with security flaws

The post Watchdog says 2020 Census systems are riddled with security flaws appeared first on BardTech . With a census just two years away, the Census Bureau has a cybersecurity problem. That’s a key takeaway from the congressional watchdog, the Government Accountability Office, which oversees the government’s spending. In a new report published Thursday, the non-partisan agency said that the government’s Census Bureau has only a few months to fix thousands of security vulnerabilities that may put personal citizen data at risk. The census, conducted by the federal government decennially, provides the government data on the population. Ahead of the 2020 census, the Bureau began testing all 44 key systems necessary to support the new option of allowing citizens to send their responses over the internet, a scheme that will save the government billions of dollars . The two-year test, set to complete in April 2019, has found close to 3,100 security issues and weaknesses, the report ...

Amazon is quietly doubling down on cryptographic security

The post Amazon is quietly doubling down on cryptographic security appeared first on BardTech . The growth of cloud services — with on-demand access to IT services over the Internet — has become one of the biggest evolutions in enterprise technology, but with it, so has the threat of security breaches and other cybercriminal activity. Now it appears that one of the leading companies in cloud services is looking for more ways to double down and fight the latter. Amazon’s AWS has been working on a range of new cryptographic and AI-based tools to help manage the security around cloud-based enterprise services, and it currently has over 130 vacancies for engineers with cryptography skills to help build and run it all. One significant part of the work has been within a division of AWS called the Automated Reasoning Group, which focuses on identifying security issues and developing new tools to fix them for AWS and its customers based on automated reasoning , a branch of artificial inte...

Firefox will soon start blocking trackers by default

The post Firefox will soon start blocking trackers by default appeared first on BardTech . Mozilla today announced that its Firefox browser will soon automatically block all attempts at cross-site tracking by default. There’s three parts to this strategy. Starting with version 63, which is currently in testing in the browser’s nightly release channel, Firefox will block all slow-loading trackers (with ads being the biggest offender here). Those are trackers that take more than five seconds to load. Starting with Firefox 65, the browser will also strip all cookies and block all storage access from third-party trackers. In addition, Mozilla is also working on blocking cryptomining scripts and trackers that fingerprint users. As usual, the timeline could still change, depending on how these first tests work out. “In the physical world, users wouldn’t expect hundreds of vendors to follow them from store to store, spying on the products they look at or purchase,” Mozilla’s Nick Nguyen...

How to Download All the Data LinkedIn Has About You

The post How to Download All the Data LinkedIn Has About You appeared first on BardTech . LinkedIn was one of Microsoft’s biggest buys. So, the two platforms get connected at the hip when you link LinkedIn to your Microsoft apps. The information LinkedIn has about you support several Microsoft services. For instance, you can see LinkedIn information on the Resume Assistant in Microsoft Word and profile cards in Outlook. But this raises a question:  How can I see the data LinkedIn has about me? How to Download the Data LinkedIn Has About You LinkedIn has a well thought out privacy policy. It gives you control and access to all your data through the Privacy tab in the account settings. Apart from the usual advertising opt-outs and sharing controls, LinkedIn also allows you to download all your data in a machine-readable format. Sign into LinkedIn. Click your Profile picture at the top of the LinkedIn page. Select Settings & Privacy from the dropdown. Click t...

This is Google’s Titan security key

The post This is Google’s Titan security key appeared first on BardTech . Google isn’t one to shy away from bold claims. “We have had no reported or confirmed account takeovers since implementing security keys at Google,” a spokesperson told TechCrunch. And it’s probably true. Think of a security key as like a two-factor authentication code that’s sent to your phone — but instead a USB stick in your pocket. Two-factor authentication is stronger than just a username and password, but text message codes can be intercepted and many sites and services don’t yet support  the stronger authenticator codes. Security keys are one of the strongest lines of defense against account breaches. That’s because a hacker on the other side of the world trying to break into your account needs not only your password but also your physical key — and that’s not something a hacker can easily or covertly steal. Although there are a handful of security key brands out there — Yubikey and Fei...

Xiaomi Mi Mix 2S Android Pie beta with September security patch now available

The post Xiaomi Mi Mix 2S Android Pie beta with September security patch now available appeared first on BardTech . Xiaomi Mi Mix 2S was one of the few devices that got the beta version of Android Pie alongside the Google Pixel devices. After the official release of Android 9, Xiaomi started closed alpha testing of the Android Pie builds. They were testing the system in China, and @xiaomiui Telegram channel was able to leak some photos along with the actual build. Being an alpha version, of course, it was unstable and full of bugs. Now, thanks to a tip from @Tadi777 on our Telegram group, we have the link to the latest beta version of Android Pie for Xiaomi Mi Mix 2S. There are two versions available, one for the Global ROM and another for the Chinese ROM. Keep in mind that both of them are MIUI Recovery ROMs. So, you don’t really have to wipe anything from the device before installing. You can flash them via a custom recovery like TWRP . Looking at the build.prop of the bu...

Valimail offers US election boards, campaigns and voting vendors its email anti-spoofing service for free

The post Valimail offers US election boards, campaigns and voting vendors its email anti-spoofing service for free appeared first on BardTech . Valimail, an enterprise email security firm , announced that it will offer its email protections for free to relevant government workers and campaigns through the 2018 midterms. That offer covers state election boards, voting system vendors and major party U.S. election campaigns, including congressional, statewide and gubernatorial candidates. The company will also offer the same email fraud prevention service, known as Valimail Enforce , to the Democratic National Committee and Republican National Committee at no cost through the 2020 U.S. presidential election. “Bad actors are trying to disrupt our elections and sow chaos in our democracy,” Valimail CEO and co-founder Alexander García-Tobar said in a statement. “They are targeting email because it is one of the weakest points in digital communications.” As Valimail observes, spear phi...

Privacy groups ask senators to confirm US surveillance oversight nominees

The post Privacy groups ask senators to confirm US surveillance oversight nominees appeared first on BardTech . A coalition of privacy groups are calling on lawmakers to fill the vacant positions on the government’s surveillance oversight board, which hasn’t fully functioned in almost two years. The Privacy and Civil Liberties Oversight Board, known as PCLOB, is a little-known but important group that helps to ensure that intelligence agencies and executive branch policies are falling within the law. The board’s work allows them to have access to classified programs run by the dozen-plus intelligence agencies and determine if they’re legal and effective, while balancing Americans’ privacy and civil liberties rights. In its most recent unclassified major report in 2015, PCLOB called for an end of the NSA’s collection of Americans’ phone records . But the board fell out of quorum when four members left the board last year, leaving just the chairperson . President Obama did no...

What Is SIP? macOS System Integrity Protection Explained

The post What Is SIP? macOS System Integrity Protection Explained appeared first on BardTech . macOS changed significantly with the release of 10.11 El Capitan and the introduction of System Integrity Protection, or SIP for short. It’s a security measure that had some pretty big implications for the operating system back in 2015. These days, most of us have adapted to a post-SIP macOS. But you might still wonder what it is, what exactly it does, and why you’re best off leaving it alone. So let’s take a look at SIP, what purpose it serves, and why it came about in the first place. What Is System Integrity Protection? Put simply, System Integrity Protection is a security measure Apple introduced to protect certain parts of your macOS installation and core processes, and to vet third-party kernel extensions. It actively protects parts of your system from modification, and blocks installation of insecure extensions. While you have SIP enabled, certain areas are entirely off-limits ...

Air Canada confirms mobile app data breach

The post Air Canada confirms mobile app data breach appeared first on BardTech . Air Canada has confirmed a data breach on its mobile app, which the airline said may affect 20,000 people — or 1 percent — of its 1.7 million app users. The company said it had “detected unusual log-in behavior” occurring between August 22-24. According to an email to customers, attackers may have accessed basic profile data, including names, email addresses and phone numbers — but also more sensitive data that users may have added to their profiles, including passport numbers and expiry date, passport country of issuance, NEXUS numbers for trusted travelers, gender, dates of birth, nationality and country of residence. But credit card data was not accessed, the airline said. It’s not known if there was a direct breach of Air Canada’s systems or if hackers attempted to reuse passwords from other sites that may have also been used on Air Canada’s mobile app. When reached, an Air Canada spokesper...

Xage security automation tool could protect power grid from hackers

The post Xage security automation tool could protect power grid from hackers appeared first on BardTech . Xage , the company that wants to help make infrastructure more secure using the blockchain, announced a new policy manager tool to help protect utilities and other critical infrastructure from hackers and automate regulatory compliance. Xage CEO Duncan Greatwood says the product is partly to fill in a need in the product portfolio, but also is designed to help customers comply with a new wave of regulations coming out of the Department of Homeland Security designed to protect the electricity grid from hacking, particularly from a hostile nation-state. Greatwood says the government previously was only worried about the core network assets, but over time, it has become clear that hackers have been looking to attack technology on the edge of the utilities network like substations and local control centers, even as granular as sensors and voltage controllers. The New York Times r...

Abbyy leaked 203,000 sensitive customer documents in server lapse

The post Abbyy leaked 203,000 sensitive customer documents in server lapse appeared first on BardTech . Abbyy, a maker of optical character recognition software, has exposed a trove of sensitive customer documents after a database server was left online without a password. The exposed server was found by former Kromtech security researcher Bob Diachenko , who now works independently. In a blog post shared prior to publication, he said one of the company’s MongoDB servers was mistakenly configured for public access. He told TechCrunch that the server contained 203,896 scanned files , including contracts, non-disclosure agreements, memos and other highly sensitive documents dating back to 2012. The data also included corporate usernames and scrambled passwords. The Moscow-based company specializes in document capture products and services, including converting physical documents to searchable and indexable digital content across a range of languages. The company claims to serve...

Kairos’ Brian Brackeen to show off facial recognition tech at Disrupt SF

The post Kairos’ Brian Brackeen to show off facial recognition tech at Disrupt SF appeared first on BardTech . Privacy and security continue to be a top-line issue in our world today. This puts facial recognition in a bit of a grey area, as it could offer incredible benefits to our security and open up vulnerabilities when it comes to our privacy. Luckily, Kairos CEO and cofounder Brian Brackeen will be joining us at Disrupt to chat about all this and more. The idea for Kairos came when Brackeen was working on HR time-clocking systems at Apple. People were cheating the system, which spurred Brackeen to implement facial recognition. Long before Apple ever introduced FaceID, Brackeen knew that this type of verification would have big implications on the broader ecosystem. But those implications can be just as negative as they can positive, a fact that Brackeen is keenly aware of. “Facial recognition-powered government surveillance is an extraordinary invasion of the privacy of all ...

Weak passwords let a hacker access internal Sprint staff portal

The post Weak passwords let a hacker access internal Sprint staff portal appeared first on BardTech . It’s not been a great week for cell carriers. EE was hit with   two security bugs and T-Mobile admitted a data breach . Now, Sprint is the latest phone giant to admit a security lapse, TechCrunch has learned. Using two sets of weak, easy-to-guess usernames and passwords, a security researcher accessed an internal Sprint staff portal. Because the portal’s log-in page didn’t use two-factor authentication, the researcher — who did not want to be named — navigated to pages that could have allowed access customer account data. Sprint is the fourth largest US cell network with 55 million customers. TechCrunch passed on details and screenshots of the issue to Sprint, which confirmed the findings in an email. “After looking into this, we do not believe customer information can be obtained without successful authentication to the site,” said a Sprint spokesperson. “Based on the in...