Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904890 times)

0 Members and 10 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3030 on: July 16, 2014, 01:43:51 PM »
European cloud data not protected against US Government
Read: http://www.zdnet.com/blog/igeneration/microsoft-admits-patriot-act-can-access-eu-based-cloud-data/11225
link article author = Zack Whittaker

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline MikeBCda

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2247
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3031 on: July 16, 2014, 10:58:46 PM »
Beware Keyloggers at Hotel Business Centers
http://krebsonsecurity.com/2014/07/beware-keyloggers-at-hotel-business-centers/
There was an interesting article in this morning's Sophos newsletter -- the German government is seriously considering abandoning email entirely and switching to old-fashioned typewriters for communications.  And not even electric, let alone electronic, ones, they're talking about antique totally-manual machines.  I was surprised to learn that key-logging devices go all the way back to the IBM Selectric, probably the most widely used electric typewriter ever.
Intel Atom D2700, 2 gig RAM, Win 7 x64 SP1 & IE-11, Firefox 51.0
(default). 320 gig HD, 15Mb DSL, Win firewall, Avast 12.3.2280 free, SpywareBlaster, MBAM Prem., Crypto-Prevent

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3032 on: July 16, 2014, 11:52:13 PM »
Beware Keyloggers at Hotel Business Centers
http://krebsonsecurity.com/2014/07/beware-keyloggers-at-hotel-business-centers/
There was an interesting article in this morning's Sophos newsletter -- the German government is seriously considering abandoning email entirely and switching to old-fashioned typewriters for communications.  And not even electric, let alone electronic, ones, they're talking about antique totally-manual machines.  I was surprised to learn that key-logging devices go all the way back to the IBM Selectric, probably the most widely used electric typewriter ever.
Interesting comment.

With IoT devices on the way, (if they're not here already) expect more of the same, maybe worse.  IoT devices don't sell, then maybe less of a security concern.

http://en.wikipedia.org/wiki/Internet_of_Things
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48596
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37548
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3035 on: July 18, 2014, 07:47:18 PM »
Does cars come with Antivirus in the future?

Chinese hackers take command of Tesla Model S
http://www.cnet.com/news/chinese-hackers-take-command-of-tesla-model-s/




Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3036 on: July 19, 2014, 02:58:09 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89132
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3037 on: July 19, 2014, 03:13:47 PM »
NSA critics: Dropbox hostile to privacy
Read: hxxp://www.theguardian.com/technology/2014/jul/17/edward-snowden-dropbox-privacy-spideroak

For more secure alternatives, see: ( hxxp://lifehacker.com/the-best-cloud-storage-services-that-protect-your-priva-729639300 )
For a more secure alternative: hxxp://www.arxshare.com

polonus

I use dropbox, for some images and files. But in all honesty I don't store anything on any on-line storage that is in any way confidential/private.

I simply don't trust any on-line storage, regardless of its supposed privacy protection and stick to my normal adage don't publish/store anything on-line that you do not wish to be seen/accessed by anyone.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3038 on: July 19, 2014, 06:28:16 PM »
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37548
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3039 on: July 20, 2014, 01:11:49 AM »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48596
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3040 on: July 20, 2014, 03:27:58 PM »
Google's Chrome Web Browser Is Killing Your Laptop Battery
http://www.forbes.com/sites/ianmorris/2014/07/14/googles-chrome-web-browser-is-killing-your-laptop-battery/
I guess it's a good thing that my laptop is always plugged in. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3041 on: July 20, 2014, 04:04:28 PM »
EFF states that the HTTP protocol should die completely and should definitely be gone from the Internet,
this because it is unencrypted and because of NSA-critical revelations etc.
Read: http://www.tomsguide.com/us/http-must-die,news-19188.html  link article author Paul Wagenseil
Only ads and content delivery (trackers) are still in need of HTTP, and also is avast! av, because it cannot scan inside HTTPS  :o  ::).
So insecure HTTPS is not flagged, certification issues only reported by Google and Comodo????
What about insecure policies alerted? (Recx Security Analyser for Google Chrome, Calomel SSL-validation add-on for firefox   ;D ).

The EEF standpoint can be read here: https://www.eff.org/event/hope-x

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3042 on: July 20, 2014, 04:11:44 PM »
Interesting observation to the above issue:
Quote
It appears that every Alexa-ranked company from China offers NO SSL, which facilitates gov censorship and Amazon, Yandex, Instagram, Ebay, Craigslist all force http (as does OpenDNS non-dashboard use), likely due to mixed content.
- Quote taken from list link below.
See list link: https://docs.google.com/spreadsheets/d/1HirCBS8bK89-jPrLc2cmru48R-3s9mUTJVwni3DO_Sw/pubhtml

pol
« Last Edit: July 20, 2014, 04:15:05 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89132
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3043 on: July 20, 2014, 06:18:09 PM »
EFF states that the HTTP protocol should die completely and should definitely be gone from the Internet,
this because it is unencrypted and because of NSA-critical revelations etc.
Read: http://www.tomsguide.com/us/http-must-die,news-19188.html  link article author Paul Wagenseil
Only ads and content delivery (trackers) are still in need of HTTP, and also is avast! av, because it cannot scan inside HTTPS <$1alt="" title="" onresizestart="return false;" id="smiley__$2" style="padding: 0 3px 0 3px;" /> <$1alt="" title="" onresizestart="return false;" id="smiley__$2" style="padding: 0 3px 0 3px;" />.
So insecure HTTPS is not flagged, certification issues only reported by Google and Comodo?<$1alt="" title="" onresizestart="return false;" id="smiley__$2" style="padding: 0 3px 0 3px;" />
What about insecure policies alerted? (Recx Security Analyser for Google Chrome, Calomel SSL-validation add-on for firefox  <$1alt="" title="" onresizestart="return false;" id="smiley__$2" style="padding: 0 3px 0 3px;" /> ).

The EEF standpoint can be read here: https://www.eff.org/event/hope-x

polonus

Well it has been an aspiration of avast to be able to scan https content, in so much as it does with secure email traffic. But I rather think it is more complex than that simple explanation and no date/time frame or avast version was given for these aspirations.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3044 on: July 20, 2014, 06:32:17 PM »
Hi DavidR,

I fully understand what you mean to say.
Reality and the EFF desired development are two quite different things.
It also isn't clear what is reality here.
It is all a little too little and too late.
These developments should have started years and years ago.
Now with hindsight knowledge we have quite another view of what http: security is.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!