acm-header
Sign In

Communications of the ACM

Blogroll


bg-corner

Security Vulnerabilities in AT&T Routers
From Schneier on Security

Security Vulnerabilities in AT&T Routers

They're actually Arris routers, sold or given away by AT&T. There are several security vulnerabilities, some of them very serious. They can be fixed, but because...

Security Flaw in Estonian National ID Card
From Schneier on Security

Security Flaw in Estonian National ID Card

We have no idea how bad this really is: On 30 August, an international team of researchers informed the Estonian Information System Authority (RIA) of a vulnerability...

New Techniques in Fake Reviews
From Schneier on Security

New Techniques in Fake Reviews

Research paper: "Automated Crowdturfing Attacks and Defenses in Online Review Systems." Abstract: Malicious crowdsourcing forums are gaining traction as sources...

Friday Squid Blogging: Bioluminescent Squid
From Schneier on Security

Friday Squid Blogging: Bioluminescent Squid

There's a beautiful picture of a tiny squid in this New York Times article on bioluminescence -- and a dramatic one of a vampire squid. As usual, you can also use...

Russian Hacking Tools Codenamed WhiteBear Released
From Schneier on Security

Russian Hacking Tools Codenamed WhiteBear Released

Kaspersky Labs released a highly sophisticated set of hacking tools from Russia called WhiteBear. From February to September 2016, WhiteBear activity was narrowly...

Journalists Generally Do Not Use Secure Communication
From Schneier on Security

Journalists Generally Do Not Use Secure Communication

This should come as no surprise: Alas, our findings suggest that secure communications haven't yet attracted mass adoption among journalists. We looked at 2,515...

A Framework for Cyber Security Insurance
From Schneier on Security

A Framework for Cyber Security Insurance

New paper: "Policy measures and cyber insurance: a framework," by Daniel Woods and Andrew Simpson, Journal of Cyber Policy, 2017. Abstract: The role of the insurance...

Proof that HMAC-DRBG has No Back Doors
From Schneier on Security

Proof that HMAC-DRBG has No Back Doors

New research: "Verified Correctness and Security of mbedTLS HMAC-DRBG," by Katherine Q. Ye, Matthew Green, Naphat Sanguansin, Lennart Beringer, Adam Petcher, and...

The NSA's 2014 Media Engagement and Outreach Plan
From Schneier on Security

The NSA's 2014 Media Engagement and Outreach Plan

Interesting post-Snowden reading, just declassified. (U) External Communication will address at least one of "fresh look" narratives: (U) NSA does not access everything...

Ross Anderson on the History of the Crypto Wars in the UK
From Schneier on Security

Ross Anderson on the History of the Crypto Wars in the UK

Ross Anderson gave a talk on the history of the Crypto Wars in the UK. I am intimately familiar with the US story, but didn't know as much about Britain's verson...

Hacking a Phone Through a Replacement Touchscreen
From Schneier on Security

Hacking a Phone Through a Replacement Touchscreen

Researchers demonstrated a really clever hack: they hid malware in a replacement smart phone screen. The idea is that you would naively bring your smart phone in...

Friday Squid Blogging: Prehistoric Dolphins that Ate Squid
From Schneier on Security

Friday Squid Blogging: Prehistoric Dolphins that Ate Squid

Paleontologists have discovered a prehistoric toothless dolphin that fed by vacuuming up squid: There actually are modern odontocetes that don't really use their...

Military Robots as a Nature Analog
From Schneier on Security

Military Robots as a Nature Analog

This very interesting essay looks at the future of military robotics and finds many analogs in nature: Imagine a low-cost drone with the range of a Canada goose...

Massive Government Data Leak in Sweden
From Schneier on Security

Massive Government Data Leak in Sweden

Seems to be incompetence rather than malice, but a good example of the dangers of blindly trusting the cloud....

Your Personal Bodycam
From Schneier on Security

Your Personal Bodycam

Shonin is a personal bodycam up on Kickstarter. There are a lot of complicated issues surrounding bodycams -- for example, it's obvious that police bodycams reduce...

Insider Attack on Lottery Software
From Schneier on Security

Insider Attack on Lottery Software

Eddie Tipton, a programmer for the Multi-State Lottery Association, secretly installed software that allowed him to predict jackpots. What's surprising to me is...

iOS 11 Allows Users to Disable Touch ID
From Schneier on Security

iOS 11 Allows Users to Disable Touch ID

A new feature in Apple's new iPhone operating system -- iOS 11 -- will allow users to quickly disable Touch ID. A new setting, designed to automate emergency services...

Friday Squid Blogging: Brittle Star Catches a Squid
From Schneier on Security

Friday Squid Blogging: Brittle Star Catches a Squid

Watch a brittle star catch a squid, and then lose it to another brittle star. As usual, you can also use this squid post to talk about the security stories in the...

More on My LinkedIn Account
From Schneier on Security

More on My LinkedIn Account

I have successfully gotten the fake LinkedIn account in my name deleted. To prevent someone from doing this again, I signed up for LinkedIn. This is my first --...

Unfixable Automobile Computer Security Vulnerability
From Schneier on Security

Unfixable Automobile Computer Security Vulnerability

There is an unpatchable vulnerability that affects most modern cars. It's buried in the Controller Area Network (CAN): Researchers say this flaw is not a vulnerability...
Sign In for Full Access
» Forgot Password? » Create an ACM Web Account