FIPS 140-2 Level 2 Certified USB Memory Stick Cracked
Kind of a dumb mistake: The USB drives in question encrypt the stored data via the practically uncrackable AES 256-bit hardware encryption system. Therefore, the main point of attack for accessing the plain text data stored on the drive is the password entry mechanism. When analysing the relevant Windows program, the SySS security experts found a rather blatant flaw that…

Related Posts
Microsoft has confirmed reports of a security flaw in its Windows operating system that hackers could use to temporarily destabilize Windows 7 PCs. The software giant also acknowledged that blueprints for exploiting the flaw are now available online. At issue is a so-called “denial-of-service” vulnerability in the component of Windows...
Interesting research: Analysing our data for security, though, shows that essentially all human-generated names provide poor resistance to guessing. For an attacker looking to make three guesses per personal knowledge question (for example, because this triggers an account lock-down), none of the name distributions we looked at gave more than 8 bits...
Microsoft on Tuesday released software updates to fix at least 15 security flaws in Windows, Windows Server and Microsoft Office. One of the patches addresses a flaw so serious that users could find their Windows PCs compromised just by visiting booby-trapped Web sites. Richie Lai, director of vulnerability research for patch management firm Qualys,...
How not to destroy evidence: In a bold and bizarre attempt to destroy evidence seized during a federal raid, a New York City man grabbed a flash drive and swallowed the data storage device while in the custody of Secret Service agents, records show. The article wasn’t explicit about this — odd, as it’s the main question any reader...
I don’t know if this is real, but it seems perfectly reasonable that all of Facebook is stored in a huge database that someone with the proper permissions can access and modify. And it also makes sense that developers and others would need the ability to assume anyone’s identity. Rumpus: You’ve previously mentioned a master password,...
Hackers broke into an online comic strip syndication service Thursday, embedding malicious code that sought to exploit a newly discovered security flaw in Adobe Reader and Acrobat, Security Fix has learned. On Monday, Adobe Systems Inc. said it was investigating reports that criminals were attacking Internet users via a previously unknown security...
A sophisticated new piece of malware that targets command-and-control software installed in critical infrastructures uses a known default password that the software maker hard-coded into its system. The password has been available online since at least 2008, when it was posted to product forums in Germany and Russia. The password protects the...
The lab has a survey request. As Windows 7 gains market share, code signing is becoming more important for software developers. A byproduct of more clean code being signed is that malware authors now have greater incentives to get their stuff signed in order to prevent it from being easily distinguished from legitimate software. With this in mind,...
A sophisticated new piece of malware that targets command and control software installed in critical infrastructures uses a known default password that the software maker hard coded into its system and that has been available online since at least 2008 when it was posted to product forums in Germany and Russia. The password protects the database...
Impressive: This presentation will show the first experimental implementation of an eavesdropper for quantum cryptosystem. Although quantum cryptography has been proven unconditionally secure, by exploiting physical imperfections (detector vulnerability) we have successfully built an intercept-resend attack and demonstrated eavesdropping under realistic...
Related Tweets from Twitter
There was an error processing the Feed, if this is your page, please check the information provided in your profile.
Related News from Digg
-
Security experts: NIST encryption standard may have NSA backdoor
[Security]
Cryptography expert Bruce Schneier is warning software developers that a random-number algorithm documented in a NIST encryption standard may be susceptible to a backdoor planted by the NSA.
736 Diggs, 75 Comments
-
Portrait of the Modern Terrorist as an Idiot
[Security]
Terrorism is a real threat, and one that needs to be addressed by appropriate means. But allowing ourselves to be terrorized by wannabe terrorists and unrealistic plots -- and worse, allowing our essential freedoms to be lost by using them as an excuse -- is wrong. Commentary by Bruce Schneier.
1091 Diggs, 98 Comments
-
The Human Brain is a Poor Judge of Risk
[General Sciences]
When an animal -- lizard, bird, mammal, even you -- senses something that's a potential danger, the amygdala is what reacts immediately, triggering the fight-or-flight response. This kind of thing works great if you're a lizard or a lion. We humans have a completely different pathway to cope with analyzing risk. Commentary by Bruce Schneier.
632 Diggs, 52 Comments
-
Why Smart Cops Do Dumb Things
[Security]
Much of our country's counterterrorism security spending is not designed to protect us from the terrorists, but instead to protect our public officials from criticism when another attack occurs. Commentary by Bruce Schneier.
981 Diggs, 59 Comments
-
Worried about the airline losing your luggage? No problem. Just pack a gun.
[Security]
The airline wouldn't want to be responsible for losing a gun, right? That's one photographer's solution to making sure his expensive camera equipment is watched carefully by the airline when he has to check it as luggage. He packs a starter pistol in his camera bag and declares it as a firearm.
3689 Diggs, 116 Comments