Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2889505 times)

0 Members and 5 Guests are viewing this topic.

Offline Dwarden

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1793
  • Ideas, that's ocean without borders!
    • Bohemia Interactive
https://twitter.com/FoltynD , Tech. Community, Online Services & Distribution manager of Bohemia Interactive

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5101 on: February 24, 2017, 01:18:35 AM »

Offline Dwarden

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1793
  • Ideas, that's ocean without borders!
    • Bohemia Interactive
« Last Edit: February 24, 2017, 09:57:23 AM by Dwarden »
https://twitter.com/FoltynD , Tech. Community, Online Services & Distribution manager of Bohemia Interactive

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5103 on: February 24, 2017, 01:48:34 PM »
Hi Dwarden,

When will they finally admit the general infrastructure of bulk hosters as a rule is insecure by design.

We all and specially here on the old continent have been very naive to think our data were securely dealt with,
and could not leak to the highest bidders. To admit this pnewed holed status is one thing,
to do something about it is another.

One fails to meet standards anywhere. Small example when  that biggest name in ketchup (name starts with H.)could not meet up with the rabbinical prescribed amout of genuine tomato extract in their ketchup product for Jerusalem so it would loose the name ketchup for the product,  is a shame. Despite of that they still go around with tinker bells in Schul'.

In the meantime you can check on what websites you leaked private data here: http://www.doesitusecloudflare.com/

As a volunteer website security analyst here and website error-hunter I see the insecurity of the general infrastructure almost every day.
When are they gonna tackle the problems or are there some "vested interests"that would rather not see that day.

Damian
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5104 on: February 24, 2017, 02:37:58 PM »
What many European website owners did now or will do as i assume?
I guess a lot of American websites follow their example.

Lots of websites in Europe did or will do the following.
Research the impact for their websites.
Research suspicious logins for accounts on their site, none detected probably.
CloudFlare reverse proxy functionality de-installed.
All password reset tokens been reset.
All existing (https-)sessions have been reset.
All passwords of accounts were reset.
Password reset-link to website, mailed to users.
Migrationplan started to halt the use of CloudFlare completely.

Bye, bye CloudFlare! Extra bonus, tor-users do not have to fill out captcha's all the time.
When you went here earlier, you could have known: http://www.crimeflare.com/

When you have lost "trust", you have a gigantic problem how to gain it back again.

Damian
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
« Last Edit: February 24, 2017, 02:59:06 PM by Pondus »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5106 on: February 28, 2017, 06:42:24 AM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5107 on: February 28, 2017, 02:52:57 PM »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5108 on: February 28, 2017, 03:07:21 PM »
Gigantic data-breach in cloudbleed with CloudPets: https://twitter.com/troyhunt/status/836320506127101953
& https://motherboard.vice.com/en_us/article/internet-of-things-teddy-bear-leaked-2-million-parent-and-kids-message-recordings

Your iAAs is as secure as the connection it takes.

When you do no longer play with your kids and communicate through an insecure app, you are in for such a fiasco.

Hold the CEO of that firm liable and fine them into banktrupcy, that should set an end to it and also warn others to pay more attention where security is concerned.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
« Last Edit: February 28, 2017, 06:19:42 PM by Be Secure »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5111 on: March 01, 2017, 04:09:23 AM »
Dridex’s Cold War: Enter AtomBombing
The Dridex malware project continues to evolve, and 2017 is likely to be another year of change for this Trojan.
https://securityintelligence.com/dridexs-cold-war-enter-atombombing/
« Last Edit: March 01, 2017, 04:11:25 AM by Be Secure »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5112 on: March 01, 2017, 03:04:55 PM »
Open bug at Bluecoat has not been patched within one and a half year's time and now prevents Google from a TLS-update: https://bugs.chromium.org/p/chromium/issues/detail?id=694593

Sounds like a flagellant's race, one step forward and two steps back. A shame really obstructing a more secure infrastructure.

As rumours have it and the same Bluecoat bug existed inside TLS 1.2 Bluecoat left the bug there for nine years. In digital time that is almost a century and could be qualified as persistent hole.

polonus



« Last Edit: March 01, 2017, 03:08:32 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5113 on: March 02, 2017, 01:52:09 AM »
Did you also experienced this on Febr. 24th last? We, the wife and I, experienced it on our Google Android accounts, but failed to get an explanation why it happened. Read about it here: https://www.theregister.co.uk/2017/03/01/google_still_silent_on_mass_logout/

The disappeared explanation by Google's:
Quote
Google posted and then deleted a message related to the deauthentication event on its Cloud Status Dashboard.

The disappeared message, cited in various online posts on the topic, reportedly said, "To summarize; [sic] some long-lived OAuth tokens have inadvertently been invalidated."

That makes sense: token invalidation would require anyone using a Google Account-related service to login again. It also may explain the wording some people saw when asked by Google to log back in: that a change had been made to their account, although no such change was visible in the security section of their account settings.

That said, the disappearance of the dashboard post is puzzling.

Anyone to speculate what it just was that Google had to hide from us all here?
What CloudPets more now will come out of the Google hat?  :o ;D ;D ;)
Failing infrastructure all around, all hands on deck, friends!

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #5114 on: March 02, 2017, 08:14:31 AM »
Yahoo says about 32 million accounts accessed using 'forged cookies'
http://www.reuters.com/article/us-yahoo-databreach-idUSKBN1685UY