Viewing posts tagged wireless-cellular-mobile-devices
Google search reveals private Telstra customer data
Posted by: admin 11 years, 6 months ago
A man googling for some information on SMS carrier access codes stumbled upon private Telstra customer data. The data could be used to authenticate a user to the phone company, allowing account take-over. There appears to be a pattern:
Authentication as a Service - mixed incentives
Posted by: admin 13 years, 4 months ago
In the past, we've commented on the 'Vendor-in-the-middle' issues in the past, in particular we've pointed out this weakness when using SMS as a one-time passcode delivery mechanism. As always, such reliance may be ok based on your risk tolerance. Another example of this risk occurred to me today when someone on twitter mentioned pointed to this Wordpress plugin that add two-factor authentication to Wordpress using Google's authenticator. There is also one for SSH via a PAM module.
A world without static passwords
Posted by: admin 14 years, 1 month ago
I wanted to quickly clarify my brief twitter rant about SMS authentication. This was all started by Chris Wysopal's tweet about Zeus's new mobile MiTM attacks and that "phones are not secure enough for 2 factor". Zeus is now targeting the text messages that banks are using for authenticating transactions.
iPhone Software Token updated
Posted by: admin 15 years, 6 months ago
Apple has released the updated iPhone Software Token. This update fixes various bugs.
Another nail for SMS authentication
Posted by: admin 15 years, 7 months ago
Now that European banks are using SMS messaging for authentication, criminals are paying top dollar for used Nokia phones that can be reprogrammed due to a bug to work with any phone number. We've discussed why SMS authentication is a bad idea before. Here's more evidence.
Recent Posts
- Blast-RADIUS attack
- The latest WiKID version includes an SBOM
- WiKID 6 is released!
- Log4j CVE-2021-44228
- Questions about 2FA for AD admins
Archive
2024
2022
- December (1)
2021
2019
2018
2017
2016
2015
2014
- December (2)
- November (3)
- October (3)
- September (5)
- August (4)
- July (5)
- June (5)
- May (2)
- April (2)
- March (2)
- February (3)
- January (1)
2013
2012
- December (1)
- November (1)
- October (5)
- September (1)
- August (1)
- June (2)
- May (2)
- April (1)
- March (2)
- February (3)
- January (1)
2011
2010
- December (2)
- November (3)
- October (3)
- September (4)
- August (1)
- July (1)
- June (3)
- May (3)
- April (1)
- March (1)
- February (6)
- January (3)
2009
- December (4)
- November (1)
- October (3)
- September (3)
- August (2)
- July (5)
- June (6)
- May (8)
- April (7)
- March (6)
- February (4)
- January (427)
2008
- December (1)
Categories
- PCI-DSS (2)
- Two-factor authentication (3)
Tags
- wireless-cellular-mobile-devices (7)
- Two-factor authentication (10)
- Wireless, cellular, mobile devices (6)
- NPS (1)
- Phishing and Fraud (111)
- Active Directory (1)
- pam-radius (3)
- privileged access (2)
- Cloud Security (10)
- Mutual Authentication (60)
- Web Application Authentication (1)
- Authentication Attacks (99)
- pci (50)
- Security and Economics (97)
- WiKID (133)
- pam (2)
- VPN (1)
- Installation (2)
- RADIUS Server (1)
- Open Source (64)
- Tutorial (2)
- Strong Authentication (35)
- Information Security (137)
- Transaction Authentication (13)
- Miscellaneous (100)
- Linux (2)
- transaction-authentication (6)
- Two Factor Authentication (254)