Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

Wednesday, January 15, 2020

Yes, the NSA discovered a major security threat in the Windows 10 operating system. No, the Russians are not suddenly hacking you.

The IT world was waiting on pins and needles yesterday for a high profile Microsoft Windows 10 security patch, and the US National Security Agency (NSA) has enlightened us as to why. Apparently the government agency has discovered a serious flaw in Windows 10 that could expose users to surveillance or serious data breaches.

The NSA confirmed (link) that the vulnerability affects Windows 10 and Windows Server 2016. It said that it flagged the dangerous bug because it "makes trust vulnerable." However, it wouldn't say when it found the flaw and declined to discuss it further until Microsoft released a patch.

The vulnerability was found in a Windows component called crypt32.dll, which handles "certificate and cryptographic messaging functions," according to Microsoft. An exploit in that area could affect authentication on Windows desktops and servers, sensitive data on Microsoft's Internet Explorer and Edge browsers and many third-party applications. Hackers could also use it to spoof digital signatures, making malware look like a legitimate app.

A software patch was released yesterday to critical Windows 10 clients including the US military and managers of key internet infrastructure. Microsoft has since released updates for all customers, urging them to install them "as quickly as practical." as this flaw is being noted the second most severe in Microsoft's rating system. Microsoft has confirmed it has not yet been exploited, but is still a major security issue.

Wednesday, June 4, 2014

Google now testing super secure email.

It's called "End-to-End" encryption, and it's the best way to stop anyone from snooping on your emails. Google would turn your emails into jumbled code, and the only person who can see the email in plain text is the trusted person on the other end.

Hackers don't stand a chance. In fact, neither does the National Security Agency. It's the kind of encryption ex-NSA contractor Edward Snowden used to communicate with journalists before he went public last year with damning documents proving the extent of U.S. government surveillance. It's what spies use...it's that good.

But End-to-End is not available just yet. In a blog post, Google said the program is in a public testing phase. After that, you'll be able to download the app and add it to your Google Chrome Web browser. If you use the browser, it'll work with any Web-based email provider.

"We recognize that this sort of encryption will probably only be used for very sensitive messages or by those who need added protection," wrote Stephan Somogyi, a Google product manager who oversees security and privacy, in the blog. "But we hope that the End-to-End extension will make it quicker and easier for people to get that extra layer of security should they need it."

Here's how Google's super encryption would work: Imagine you want to send a sensitive letter by mail. You can't just lick the envelope shut. Postal workers might open it. But they can't open a lock.
Your friend buys a padlock, opens it and sends it to you. He keeps the key. You receive his lock, place your letter inside a box and close it with your friend's lock. You send it. Now only he can open it with his private key, which never left his possession.

Google will let you share locks, but never keys. So far, End-to-End encryption has proven tamper-proof.

This is only the latest move by Silicon Valley giants to beef up their security since last year's revelations that the U.S. government is gathering our emails and phone calls without warrants. In December, executives at the world's largest technology firms called on the U.S. government to respect Internet privacy rights, dial back its intelligence gathering and make spying programs more transparent.

Since then, Microsoft and Yahoo have been working on encrypting the information they house and transmit. Facebook CEO Mark Zuckerberg called President Obama directly to complain about the NSA. And they've all shed light on the scope of secret data requests.

Source: CNN Money

Thursday, July 11, 2013

The federal government has been asked to stay away from Defcon hacker event this year!

The federal government is persona non grata at this year's Defcon.

For the first time in the 21-year-history of the famed hacker's convention, government employees are being asked to stay away, albeit in a polite fashion.

Def Con founder Jeff Moss, aka The Dark Tangent, posted the following plea on the event's Web site late Wednesday:
Feds, we need some time apart.
For over two decades DEF CON has been an open nexus of hacker culture, a place where seasoned pros, hackers, academics, and feds can meet, share ideas and party on neutral territory. Our community operates in the spirit of openness, verified trust, and mutual respect.
When it comes to sharing and socializing with feds, recent revelations have made many in the community uncomfortable about this relationship. Therefore, I think it would be best for everyone involved if the feds call a "time-out" and not attend DEF CON this year.
This will give everybody time to think about how we got here, and what comes next.
The Dark Tangent
Moss, who also advises the Department of Homeland Security on security issues, told Reuters he believes the Defcon community needs some time to digest the recent leaks about U.S. surveillance programs.

"The community is digesting things that the Feds have had a decade to understand and come to terms with," Moss said. "A little bit of time and distance can be a healthy thing, especially when emotions are running high."

But Def Con won't be hiring a bunch of bouncers to throw out the Feds.

"We are not going on a witch hunt or checking IDs and kicking people out," Moss added.

Def Con has always been geared toward hackers, researchers, and other security devotees. But employees from the CIA, the FBI, the NSA, and other government branches have been welcome and have attended for many years.

General Keith Alexander, the head of National Security Agency, even gave a keynote speech at last year's event. Alexander was asked at the time whether the government was snooping on its citizens and denied that the NSA was gathering information on all Americans.

Source: CNET