Remove about-us news
article thumbnail

The UK Bans Default Passwords

Schneier on Security

The Product Security and Telecommunications Infrastructure Act 2022 (PSTI) introduces new minimum-security standards for manufacturers, and demands that these companies are open with consumers about how long their products will receive security updates for. This sort of thing benefits all of us everywhere.

Passwords 270
article thumbnail

No-Fly List Exposed

Schneier on Security

I can’t remember the last time I thought about the US no-fly list: the list of people so dangerous they should never be allowed to fly on an airplane, yet so innocent that we can’t arrest them. The list is back in the news today, having been left exposed on an insecure airline computer.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Deepfake Election Interference in Slovakia

Schneier on Security

The fact-checking department of news agency AFP said the audio showed signs of being manipulated using AI. I just wrote about this. Consider this a preview to their actions in the US next year. Countries like Russia and China tend to test their attacks out on smaller countries before unleashing them on larger ones.

Media 244
article thumbnail

Zoom Lied about End-to-End Encryption

Schneier on Security

The facts aren’t news, but Zoom will pay $85M — to the class-action attorneys, and to users — for lying to users about end-to-end encryption, and for giving user data to Facebook and Google without consent.

article thumbnail

US Cyber Safety Review Board on the 2023 Microsoft Exchange Hack

Schneier on Security

US Cyber Safety Review Board released a report on the summer 2023 hack of Microsoft Exchange by China. Here are a few news articles. It was a serious attack by the Chinese government that accessed the emails of senior U.S. government officials. It’s worth reading in its entirety. This is their third report.

Hacking 267
article thumbnail

Threat actors breached two crucial systems of the US CISA

Security Affairs

The US Cybersecurity and Infrastructure Security Agency (CISA) agency was hacked in February, the Recorded Future News first reported. In response to the security breach, the agency had to shut down two crucial systems, as reported by a CISA spokesperson and US officials with knowledge of the incident, according to CNN.

Hacking 133
article thumbnail

Microsoft Signing Key Stolen by Chinese

Schneier on Security

A bunch of networks, including US Government networks , have been hacked by the Chinese. The hackers used forged authentication tokens to access user email, using a stolen Microsoft Azure account consumer signing key. The phrase “ negligent security practices ” is being tossed about—and with good reason.