Secure QR Login (SQRL)

Thursday, October 3rd, 2013

There's a new web authentication method being proposed by Steve Gibson over at grc.com and initially it looks really good and does seem to solve most, if not all, of the current security/privacy problems we have with traditional username/password authentication. In a nutshell, website login pages will display a QR code ...

Security researchers create undetectable hardware trojans

Tuesday, September 17th, 2013

A team of security researchers from the U.S. and Europe has released a paper showing how integrated circuits used in computers, military equipment and other critical systems can be maliciously compromised during the manufacturing process through virtually undetectable changes at the transistor level. As proof of the effectiveness of the approach, ...

LastPass and the NSA Controversy

Tuesday, September 10th, 2013

With news that the United States National Security Agency has deliberately inserted weaknesses into security products and attempted to modify NIST standards, questions have been raised about how these actions affect LastPass and our customers. We want to directly address whether LastPass has been or could be weakened, and whether our users’ ...

The NSA Is Breaking Most Encryption on the Internet

Thursday, September 5th, 2013

The new Snowden revelations are explosive. Basically, the NSA is able to decrypt most of the Internet. They're doing it primarily by cheating, not by mathematics. It's joint reporting between the Guardian, the New York Times, and ProPublica. I have been working with Glenn Greenwald on the Snowden documents, and I have seen a lot ...

HTTP Nowhere for Firefox blocks all but encrypted traffic

Wednesday, August 28th, 2013

Protecting your privacy online is a hot topic right now, with PRISM looming over the heads of all Internet users. But even if you take PRISM aside, there is a drive towards privacy on the Internet. One of the things that users need to be aware of is the difference between ...