Foxmarks Uses Vulnerable MD5 Certificates

Tuesday, January 13th, 2009

I decided to try the ever popular Firefox plugin called Foxmarks that lets you sync and back up your bookmarks and passwords across multiple computers.  I didn't feel comfortable using the password sync quite yet because it will take me a while to trust a 3rd party with that kind ...

Browser Bug Could Allow Phishing Without Email

Monday, January 12th, 2009

A bug found in all major browsers could make it easier for criminals to steal online banking credentials using a new type of attack called "in-session phishing," according to researchers at security vendor Trusteer. In-session phishing (pdf) gives the bad guys a solution to the biggest problem facing phishers these days: ...

Google adds HTTPS-only browsing to Chrome

Friday, January 9th, 2009

Google has quietly released a pre-beta version of Google Chrome 2.0 with a new HTTPS-only browsing mode. The new feature lets users add “force-https to your Google Chrome shortcut” to only load Web sites with valid security certificates.   “Sites with SSL certificate errors will not load,” the company explained. The newest Chrome ...

Weak Password Brings ‘Happiness’ to Twitter Hacker

Tuesday, January 6th, 2009

An 18-year-old hacker with a history of celebrity pranks has admitted to Monday's hijacking of multiple high-profile Twitter accounts, including President-Elect Barack Obama's, and the official feed for Fox News. The hacker, who goes by the handle GMZ, told Threat Level on Tuesday he gained entry to Twitter's administrative control panel ...

Google Named No. 3 Spam Provider

Tuesday, January 6th, 2009

According to this eWeek article, Google has been named the #3 spam provider in the world according to the most recent Spamhaus Statistics. They are stating the reason as "Spammers have had success cracking the CAPTCHA tests and creating Gmail accounts from which to spam. Because the spam comes from a ...