Explore top 10 tips to secure your open-source projects now. Read More
×It turns out that stealing someone's Google Wallet funds isn't that much more difficult than stealing that person's actual wallet, according to a few recently publicized exploits. "I think these types of vulnerabilities threaten to kill the adoption of NFC before it is even fully born," said the Yankee Group's Carl D. Howe. "All forms of mobile payment rely on being able to trust the payment system.". Mobile shopping received a setback last week when security researchers discovered flaws in Google (Nasdaq: GOOG) Wallet that could potentially expose its PIN to enterprising hackers. When Google introduced its wallet, it bragged that it was secure because transaction information was stored in a "secure element" in Wallet-enabled phones. What researchers at a security outfit called zVelo discovered, though, was that the PIN for the wallet was stored outside the "secure element" where it could be cracked with a brute force attack. The link for this article located at Tech World is no longer available. . Challenges in digital commerce stemming from weaknesses in Google Pay expose shortcomings in password encryption techniques.. Google Wallet Security, Mobile Payment Threats, NFC Security Issues. . LinuxSecurity.com Team
Gawker Media has admitted passwords were stolen in a hack on its user databases. Whilst the stored passwords were encrypted, Gawker said, simple ones may still be vulnerable to a brute force attack, where constant attempts to crack the key are made until the hackers are successful.. Users have been advised to change their passwords for Gawker websites and for any other site on which they use that same password. The link for this article located at IT Pro UK is no longer available. . Vox Media advised members to update their passwords after a security incident jeopardized their information. Secure your accounts immediately.. Gawker Media, Password Security, Cyber Attack Awareness, Data Integrity. . LinuxSecurity.com Team
Sysadmins have begun noticing a coordinated attack on servers with open SSH ports that tries to stay under the radar by only attempting to guess a password three times from any compromised machine. Instead of mounting an attack form a single compromised host, hackers have worked out a means to relay a brute force attack between multiple assault machines. Do you have SSH open on your Linux machine? If so make sure that all your user's passwords are strong. Check out your system logs and see if attackers are trying to guess your passwords.. The link for this article located at channelregister is no longer available. . Recognizing synchronized brute-force login attempts targeting vulnerable credentials on UNIX systems and the significance of log surveillance.. ssh security,password management,server attack prevention. . Bill Locke
Get the latest Linux and open source security news straight to your inbox.