Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904970 times)

0 Members and 8 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4590 on: April 01, 2016, 04:16:15 PM »
Thank you, essex, for setting this out to us.
No reason to panic, but we must take care
and keep all hands on deck.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4592 on: April 04, 2016, 01:43:31 PM »
Alert from my daily scanning experiences:
Loads of servers do not have this Public-Key-Pins set. Also CloudFlare has this insecurity! This we can establish from a Symantic Crypto URL Scan on the Certificate(s): 
Quote
Public-Key-Pins   HTTP Public Key Pinning protects your site from MiTM attacks using rogue X.509 certificates. By whitelisting only the identities that the browser should trust, your users are protected in the event a certificate authority is compromised. Certificate is not in Google's EV whitelist.


polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37548
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4594 on: April 06, 2016, 10:48:22 AM »
Are Exploit Kits Doomed? New F-Secure Threat Report Says Yes
https://www.f-secure.com/en/web/press_global/news/news-archive/-/journal_content/56/1075444/1551427?p_p_auth=Afyyx1oa&refererPlid=1081937


Quote
Exploits, which have become one of the most common vehicles for malware in the past decade, need out-of-date software in order to accomplish their goal of getting through security holes. But that software, Sullivan says, will be harder and harder to find. For example, with HTML 5's capability to "do it all", the need for third party browser plugins has mostly been eliminated. And today's browsers themselves are auto-updated, without the need for the user to intervene, so users always have the latest version.



Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48597
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4595 on: April 06, 2016, 01:55:44 PM »
Are Exploit Kits Doomed? New F-Secure Threat Report Says Yes
https://www.f-secure.com/en/web/press_global/news/news-archive/-/journal_content/56/1075444/1551427?p_p_auth=Afyyx1oa&refererPlid=1081937


Quote
Exploits, which have become one of the most common vehicles for malware in the past decade, need out-of-date software in order to accomplish their goal of getting through security holes. But that software, Sullivan says, will be harder and harder to find. For example, with HTML 5's capability to "do it all", the need for third party browser plugins has mostly been eliminated. And today's browsers themselves are auto-updated, without the need for the user to intervene, so users always have the latest version.
As we can see here, auto-updates is a good thing.
Why isn't it also considered good when Avast decided to implement it with it's program ??? "Program updates will now be set to Auto by default."
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4596 on: April 06, 2016, 05:54:36 PM »
Firefox browser is in need of a new secure extension sandbox. Why? Read here: http://www.theregister.co.uk/2016/04/04/top_firefox_extensions_can_hide_silent_malware_using_easy_prefab_tool/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48597
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4597 on: April 06, 2016, 06:03:37 PM »
Firefox browser is in need of a new secure extension sandbox. Why? Read here: http://www.theregister.co.uk/2016/04/04/top_firefox_extensions_can_hide_silent_malware_using_easy_prefab_tool/

polonus
By now, we should all have realized that the only way to be totally safe from all of the dangers of the internet,
is to totally avoid ever visiting it. Since that's impossible unless you want to become a total hermit, we simply need to accept
that using modern technology and browsing the internet also exposes us to certain dangers.
We can only learn to minimize these dangers. We can never totally avoid them with out avoiding the internet.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37548
  • Not a avast user

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37548
  • Not a avast user
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4599 on: April 07, 2016, 06:57:17 PM »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48597
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4600 on: April 07, 2016, 09:38:36 PM »


FBI spills iPhone hacking secret to Senators
Now everyone will know.  :o  The crooks already knew how. :)
« Last Edit: April 07, 2016, 09:40:15 PM by bob3160 »
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4601 on: April 08, 2016, 04:09:35 PM »
Giorgio Maone, the developer of NoScript, in a reaction to the new extension insecurity found up for firefox extensions:
https://hackademix.net/2016/04/08/crossfud-an-analysis-of-inflated-research-and-sloppy-reporting/

It needs the eye of the experienced security researcher to smell out code with malicious intent right away.
And I can agree hearing a lot of script music will make that you could better discerns between real music and dissonants,
aka benevolent coding and code wrought by malcreants for malicious purposes.
A whitelisting of browser extensions however could be a good thing, I do not like mine to come with hidden crap like adware etc.

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37548
  • Not a avast user

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4603 on: April 10, 2016, 02:24:02 PM »
What security admins are putting off but better should implement right away: http://www.theregister.co.uk/2016/04/08/weekend_reading_five_security_things_youre_not_doing_but_should/
Article by Darren Pauli on an advice by SANS' Johannes Ullrich.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #4604 on: April 10, 2016, 02:30:10 PM »
End2end encryption may be on the line: http://www.theregister.co.uk/2016/04/08/draft_of_encryptionborking_bill_floated/
Quote
"For the first time in America, companies who want to provide their customers with stronger security would not have that choice – they would be required to decide how to weaken their products to make you less safe."

For one thing, it will kill end-to-end encryption.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!