Google rolls out a security testing tool dubbed 'nogotofail' designed to help developers and cyber security researchers to make sure that the HTTPS connections are not vulnerable to security flaws or common configuration errors that allow intruders to exploit it. 'nogotofail' tool is used to counter 'goto fail' security flaw that affected Apple machines and other systems. The tool ensures that internet-connected devices and applications are not susceptible to transport layer security (TLS) and secure sockets layer (SSL) flaws. The deployment of this tool can be made on router, a Linux machine, or a VPN server and works for Android, Chrome OS, iOS, Linux, OS X, and Windows. The aim of this tool is to provide users a risk free HTTPS connection to ensure that their information is transmitted securely over the internet. <more>
Saturday, November 15, 2014
Visa's contactless payment system security flaw
Visa - a digital payment company is under fire for its contactless payment system by a cyber security researcher from Newcastle University. According to researcher, criminals can make illegal huge transactions in any currency from visa holder accounts through point-of-sale machines. The researcher claims, an intruder enters the amount needed to be transferred after creating a fake POS terminal on a mobile phone or ATM. When a Visa card contacts with that POS terminal, approval of transaction is made with a code supplied by the card. That code is used by the bank to release the fund. Lead researcher, Martin Emms told that POS terminal can read a card even it is placed in the wallet. <more>
Friday, November 7, 2014
0-day flaw in Samsung 'Find My Mobile' service
Samsung smartphones users are being warned by National Institute of Standards and Technology (NIST) due to a newly discovered zero-day security flaw found in its 'Find My Mobile' service. The issue occurs due to improper validation of a lock-code data of the sender received during communication. 'Find My Mobile' service provides users to locate their lost devices and allow users to lock down their devices remotely so that no one else is able to access it. Cyber security researcher Mohamed Abdelbaset Elnoby is credited for finding out security vulnerability in the service. The flaw allows remote attackers to lock or unlock the affected device via CSRF attack. <more>
Subscribe to:
Posts (Atom)