Tag Archive for: wednesday

It has been a bad week for encrypted messaging and it’s only Wednesday

Enlarge (credit: Elsamuko / Flickr)

The past three days have highlighted the potential perils that can threaten people who rely on desktop computers to send encrypted messages. The events—which involve encrypted email and the desktop versions of the Signal and Telegram messaging programs—should in no way discourage people from using encryption. They do, however, provide important teaching moments about the often-overlooked limitations of these apps. More about that in a moment. First, a review of the vulnerabilities.

Monday brought word of decade-old flaws that might reveal the contents of PGP- and S/MIME-encrypted emails. Some of the worst flaws resided in email clients such as Thunderbird and Apple Mail, and they offer a golden opportunity to attackers who have already intercepted previously sent messages. By embedding the intercepted ciphertext in invisible parts of a new message sent to a sender or receiver of the original email, attackers can force the client to leak the corresponding plaintext. Thunderbird and Mail have yet to be patched, although the Thunderbird flaw has been mitigated by an update published Wednesday in the Enigmail GPG plugin.

Also on Monday, a different team of researchers disclosed a vulnerability in the desktop version of the Signal messenger. It allowed attackers to send messages containing malicious HTML and JavaScript that would be executed by the app. Signal developers published a security update on Friday, a few hours after the researchers privately notified them of the vulnerability. On Monday, Signal developers issued a new patch after discovering over the weekend that the first one didn’t fully fix the bug. (The incompleteness of the patch was independently and more-or-less simultaneously found by the researchers.)

Read 11 remaining paragraphs | Comments

Biz & IT – Ars Technica

COL Financial gets Wednesday deadline for full report on ‘breach’ – Inquirer.net


Inquirer.net

COL Financial gets Wednesday deadline for full report on 'breach'
Inquirer.net
Citing the notification, NPC said the team would look into the “likelihood of the threat and probable extent of a data breach, if any.” “Attached to the notification is a preliminary report giving additional details of what its breach response team has

and more »

data breach – Google News

The Upload: Your tech news briefing for Wednesday, June 17

Say it ain’t so: FBI probes alleged Cardinals-Astros hack

Even America’s pastime isn’t safe from cybercrime: the FBI is investigating allegations that the St. Louis Cardinals hacked into computer systems belonging to rival baseball team the Houston Astros. The investigation centers on the baseball operations database, which is said to contain statistics, video and other vital information about players.

Airbus joins the Internet satellite crowd

Count European consortium Airbus in on the business of delivering Internet service via satellites, the Verge reports. It’s going to design and build 900 orbiters for Richard Branson’s OneWeb, which aims to provide LTE, 3G, and Wi-Fi to rural communities.

To read this article in full or to leave a comment, please click here

Network World Security