acm-header
Sign In

Communications of the ACM

Blogroll


bg-corner

CSE Releases Malware Analysis Tool
From Schneier on Security

CSE Releases Malware Analysis Tool

The Communications Security Establishment of Canada -- basically, Canada's version of the NSA -- has released a suite of malware analysis tools: Assemblyline is...

Reaper Botnet
From Schneier on Security

Reaper Botnet

It's based on the Mirai code, but much more virulent: While Mirai caused widespread outages, it impacted IP cameras and internet routers by simply exploiting their...

Hacking Back
From Schneier on Security

Hacking Back

Hacking back is a terrible idea that just will not die. Josephine Wolff takes apart the new hacking back bill that was introduced in the House recently....

Friday Squid Blogging: "How the Squid Lost Its Shell"
From Schneier on Security

Friday Squid Blogging: "How the Squid Lost Its Shell"

Interesting essay by Danna Staaf, the author of Squid Empire. (I mentioned the book two weeks ago.) As usual, you can also use this squid post to talk about the...

Wondermark on Security
From Schneier on Security

Wondermark on Security

Another comic....

Denuvo DRM Cracked within a Day of Release
From Schneier on Security

Denuvo DRM Cracked within a Day of Release

Denuvo is probably the best digital-rights management system, used to protect computer games. It's regularly cracked within a day. If Denuvo can no longer provide...

Security Flaws in Children's Smart Watches
From Schneier on Security

Security Flaws in Children's Smart Watches

The Norwegian Security Council has published a report detailing a series of security and privacy flaws in smart watches marketed to children. Press release. News...

IoT Cybersecurity: What's Plan B?
From Schneier on Security

IoT Cybersecurity: What's Plan B?

In August, four US Senators introduced a bill designed to improve Internet of Things (IoT) security. The IoT Cybersecurity Improvement Act of 2017 is a modest piece...

Security Flaw in Infineon Smart Cards and TPMs
From Schneier on Security

Security Flaw in Infineon Smart Cards and TPMs

A security flaw in Infineon smart cards and TPMs allows an attacker to recover private keys from the public keys. Basically, the key generation algorithm sometimes...

New KRACK Attack Against Wi-Fi Encryption
From Schneier on Security

New KRACK Attack Against Wi-Fi Encryption

Mathy Vanhoef has just published a devastating attack against WPA2, the 14-year-old encryption protocol used by pretty much all wi-fi systems. Its an interesting...

Friday Squid Blogging: International Squid Awareness Day
From Schneier on Security

Friday Squid Blogging: International Squid Awareness Day

It's International Cephalopod Awareness Days this week, and Tuesday was Squid Day. I can't believe I missed it. As usual, you can also use this squid post to talk...

My Blogging
From Schneier on Security

My Blogging

Blog regulars will notice that I haven't been posting as much lately as I have in the past. There are two reasons. One, it feels harder to find things to write...

Technology to Out Sex Workers
From Schneier on Security

Technology to Out Sex Workers

Two related stories: PornHub is using machine learning algorithms to identify actors in different videos, so as to better index them. People are worried that it...

Impersonating iOS Password Prompts
From Schneier on Security

Impersonating iOS Password Prompts

This is an interesting security vulnerability: because it is so easy to impersonate iOS password prompts, a malicious app can steal your password just by asking...

More on Kaspersky and the Stolen NSA Attack Tools
From Schneier on Security

More on Kaspersky and the Stolen NSA Attack Tools

Both the New York Times and the Washington Post are reporting that Israel has penetrated Kaspersky's network and detected the Russian operation. From the New York...

Changes in Password Best Practices
From Schneier on Security

Changes in Password Best Practices

NIST recently published their four-volume SP800-63-3 Digital Identity Guidelines. Among other things, they make three important suggestions when it comes to passwords...

White House Chief of Staff John Kelly's Cell Phone was Tapped
From Schneier on Security

White House Chief of Staff John Kelly's Cell Phone was Tapped

Politico reports that White House Chief of Staff John Kelly's cell phone was compromised back in December. I know this is news because of who he is, but I hope...

Friday Squid Blogging: Baby Ichthyosaurus Fed on Squid
From Schneier on Security

Friday Squid Blogging: Baby Ichthyosaurus Fed on Squid

New discovery: paper and article. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered. Read my blog...

Yet Another Russian Hack of the NSA -- This Time with Kaspersky's Help
From Schneier on Security

Yet Another Russian Hack of the NSA -- This Time with Kaspersky's Help

The Wall Street Journal has a bombshell of a story. Yet another NSA contractor took classified documents home with him. Yet another Russian intelligence operation...

Replacing Social Security Numbers
From Schneier on Security

Replacing Social Security Numbers

In the wake of the Equifax break, I've heard calls to replace Social Security numbers. Steve Bellovin explains why this is hard....
Sign In for Full Access
» Forgot Password? » Create an ACM Web Account