(Italiano) Il malware Digmine estrae crittovaluta via Facebook

Sorry, this entry is only available in Italian.

Tracking People Without GPS

Interesting research: The trick in accurately tracking a person with this method is finding out what kind of activity they’re performing. Whether they’re walking, driving a car, or riding in a train or airplane, it’s pretty easy to figure out when you know what you’re looking for. The sensors can determine how fast a person… Read more »

(Italiano) Loapi: il trojan che brucia la batteria dello smartphone

Sorry, this entry is only available in Italian.

On Deniability and Duress

Imagine you’re at a border crossing, and the guard asks you to hand over all of your electronics for screening. The guard then asks that you unlock your device, provide passwords and decryption keys. Right now, he’s asking nicely, but he happens to be carrying an unpleasant-looking rubber hose, (Yes, cryptographers actually do call this… Read more »

WhatsApp Security Vulnerability

Back in March, Rolf Weber wrote about a potential vulnerability in the WhatsApp protocol that would allow Facebook to defeat perfect forward secrecy by forcibly change users’ keys, allowing it — or more likely, the government — to eavesdrop on encrypted messages. It seems that this vulnerability is real: WhatsApp has the ability to force… Read more »

Nemucod downloader spreading via Facebook

Earlier today, a friend of mine notified me of something strange going on with his Facebook account; a message containing only an image (an .svg file in reality) had been sent automatically, effectively bypassing Facebook’s file extension filter: What is an .svg file? From Wikipedia: Scalable Vector Graphics (SVG) is an XML-based vector image format… Read more »

5900 online stores found skimming [analysis]

Update Oct 17th: already 841 stores have been fixed! Thanks to everybody who tirelessly notified and fixed stores. Update Oct 14th: Github has booted my data and I have moved to Gitlab (statement from Gitlab on this case). Online card skimming is up 69% since Nov 2015 Multiple groups involved Merchants are unaware Last week… Read more »

NoScript is harmful and promotes Malware!

NoScript proudly calls itself a security extension advertising itself as an extension with “whitelist based pre-emptive script blocking approach prevents exploitation of security vulnerabilities (known and even not known yet!) with no loss of functionality…” Well, guess again. The author has a history of doing shady things, such as messing with AdBlock filters to whitelist ads… Read more »

Seriously, Put Away The Foil

I was scanning the headlines this morning, as I do, and came across this article by YLE Uutiset (News). — “Finnish police: Keep your car keys in the fridge” From YLE’s article: “These so-called smart keys work by emitting a signal when the driver touches the door handle. The lock opens when it recognises the… Read more »

Hacking Your Computer Monitor

Here’s an interesting hack against a computer’s monitor: A group of researchers has found a way to hack directly into the tiny computer that controls your monitor without getting into your actual computer, and both see the pixels displayed on the monitor — effectively spying on you — and also manipulate the pixels to display… Read more »