Thursday, 3 September 2009

Skype hack (at last?)

I'm conscious that my blog postings now resemble a London bus - you wait for ages, then three come along at once - but I had to share this with you.

Ruben Unteregger wrote a Skype phone call Trojan three years ago, then a few days ago he released the source code. Now, unsurprisingly, something very similar has appeared in the wild. I continue to be pleased that we don't allow Skype (or any real time protocols in fact) in our business.

Defending the Enterprise webcast

My recent webcast "Defending the Enterprise with more than Silver Bullets" is now available to view in recorded format here

Saturday, 29 August 2009

How safe is your online bank?

When Which? Computing asked me to help evaluate online banking services, I expected to find very similar results amongst the ten banks they selected. However, as their press release says, there were some pretty big differences. Although we only looked at the visible security measures in place, some banks appeared to offer little to help defend against simple keyloggers.

I know that there are some sophisticated banking Trojans around, using man-in-the-browser attacks, but surely that's not an excuse to ignore defending against simpler malware and physical keyloggers?

Obviously banks need to balance good security against usability, being concerned that consumers may be put off by complex authentication processes. But with the vast increase in the number of Trojans, and more and more people using public WiFi and shared computers, Barclays' approach of using a PINsentry device seems like the most secure option.

Sunday, 17 May 2009

A day off

Having decided to have a day off, I find myself browsing the National Museum of Computing web site. I first met Tony Sale about ten years ago and his enthusiasm was infectious. If you haven't visited Bletchley Park then I strongly recommend it - not only to learn about the history of computing but also the incredible work done by the code breakers during World War II. If you've got a few quid (or dollars or Euros) to spare, then consider a donation to either of these excellent organisations.

Saturday, 2 May 2009

The show is over ... and web authentication bypass

Well, that's Infosecurity Europe over for another year - our 7th as exhibitors and my 11th as a speaker (I think). The new venue at Earls Court seemed to be viewed by most people as a big improvement and I have to agree - the show felt more relaxed yet more alive.

Our press conference on web authentication bypass was well received, with Computer Weekly and Infosecurity Adviser reporting the story. We'll be explaining more about this problem, which stems from poor web site configuration, at our next white-hats.co.uk meeting on 15 May. The fact that the problem affects web portals as well as e-commerce sites and that even two-factor authentication is no protection makes this an important issue for discussion.