Data Security Category - Security Boulevard https://securityboulevard.com/category/blogs/data-security/ The Home of the Security Bloggers Network Mon, 24 Jul 2023 17:05:36 +0000 en-US hourly 1 https://wordpress.org/?v=6.2.2 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Data Security Category - Security Boulevard https://securityboulevard.com/category/blogs/data-security/ 32 32 133346385 ‘China’ Azure Breach: MUCH Worse Than Microsoft Said https://securityboulevard.com/2023/07/azure-breach-worse-richixbw/ Mon, 24 Jul 2023 17:03:58 +0000 https://securityboulevard.com/?p=1982521 Satya Nadella and President Xi Jinping

Storm-0558 Breaks: Satya and Pooh, sitting in a tree, K.I.S.S.I.N.G.

The post ‘China’ Azure Breach: MUCH Worse Than Microsoft Said appeared first on Security Boulevard.

]]>
1982521
The Future of Data Analytics: 9 Emerging Trends and Technologies to Watch Out https://securityboulevard.com/2023/07/the-future-of-data-analytics-9-emerging-trends-and-technologies-to-watch-out/ https://securityboulevard.com/2023/07/the-future-of-data-analytics-9-emerging-trends-and-technologies-to-watch-out/#respond Mon, 24 Jul 2023 14:59:58 +0000 https://www.ishir.com/?p=93635 In the rapidly evolving digital age, data has become the new currency, and organizations are harnessing its power to gain valuable insights and make informed...Read More

The post The Future of Data Analytics: 9 Emerging Trends and Technologies to Watch Out appeared first on ISHIR | Software Development India.

The post The Future of Data Analytics: 9 Emerging Trends and Technologies to Watch Out appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2023/07/the-future-of-data-analytics-9-emerging-trends-and-technologies-to-watch-out/feed/ 0 1982590
Microsoft Lost Its Keys, Voice Cloning Scams, The Biden-Harris Cybersecurity Labeling Program https://securityboulevard.com/2023/07/microsoft-lost-its-keys-voice-cloning-scams-the-biden-harris-cybersecurity-labeling-program/ https://securityboulevard.com/2023/07/microsoft-lost-its-keys-voice-cloning-scams-the-biden-harris-cybersecurity-labeling-program/#respond Mon, 24 Jul 2023 04:00:34 +0000 https://sharedsecurity.net/?p=101499 In this episode, we discuss the recent Microsoft security breach where China-backed hackers gained access to numerous email inboxes, including those of several federal government agencies, using a stolen Microsoft signing key to forge authentication tokens. A TikTok influencer used a voice cloning app to expose a cheating boyfriend. But wait, there’s more to this […]

The post Microsoft Lost Its Keys, Voice Cloning Scams, The Biden-Harris Cybersecurity Labeling Program appeared first on Shared Security Podcast.

The post Microsoft Lost Its Keys, Voice Cloning Scams, The Biden-Harris Cybersecurity Labeling Program appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2023/07/microsoft-lost-its-keys-voice-cloning-scams-the-biden-harris-cybersecurity-labeling-program/feed/ 0 1982480
Review: Can We Trust the Waterfox Browser? (Updated 2023) https://securityboulevard.com/2023/07/review-can-we-trust-the-waterfox-browser-updated-2023/ https://securityboulevard.com/2023/07/review-can-we-trust-the-waterfox-browser-updated-2023/#respond Sat, 22 Jul 2023 14:00:00 +0000 https://avoidthehack.com/review-waterfox-browser

Waterfox came into the browser scene in 2011, coming right out the box with official x64 support (a rarity among browsers at the time) and promoted itself as an "ethical browser."

However, many things have changed in the browser landscape, and even the Waterfox project as whole since 2011.

With these changes, can Waterfox be a viable privacy-focused browser?

Let's do our best to find out.

Overview

Here's Waterfox at a glance...

PROS

  • Light on System Resources ()
  • Compatible with most Firefox Extensions ()
  • "No telemetry" and "Limited Data Collection" (this could change, given the first con below)

CONS

  • Bought by analytics/adverising company, System1, which is the same company that bought search engine StartPage. More info
  • Still needs
    about:config tweaks
    found in Mozilla Firefox to be a more "true" privacy browser
  • Nonexistent mobile support (this may be a con for some people)

Revisiting Waterfox in 2023

Waterfox has changed some since publishing this post. Most notably, Waterfox has returned to its previous independent status and has streamlined its lineup.

Waterfox is independent


the official waterfox logo

As of July 2023, Waterfox announced it has returned to its former status as an independent project - presumably, shedding their association with System1. For the unaware, System1 had invested in Waterfox in late 2019, and while they did nothing explicitly violating user privacy, their “backing” of Waterfox wasn’t well-received by many (including myself in the initial version of this review)

This association with System1 was the primary con associated with Waterfox; Waterfox had been partnered with System1 for roughly 1 year when the initial post was published. At the time it seemed deliver on its promises of an optimized and more private experience for users, despite its association with System1.

As noted later in the review, System1 had never (overtly) did anything to be labeled as “untrustworthy,” but suspicions persisted because of its analytics/advertising connections. As such, because of this association, it appeared the greater privacy community (and myself included) lost trust in Waterfox - or confidence was shaken up enough not to widely recommend it over other privacy-oriented browsers.

A refreshed download/install experience

Waterfox still downloads and installs quickly. The website has been overall simplified. It is far easier to find relevant information and download the appropriate version of Waterfox.


waterfox website home page

Since the publication of the initial version of this post, Waterfox has moved into release of its 4th generation. Waterfox Classic is still around, though it appears to no longer share the same code repository or immediate resources with the newest generation of Waterfox.

With the 4th generation of Waterfox, users on substantially older systems may find difficulty running the browser. However, users are still able to download older, stable releases of Waterfox if desired. though isn’t expressly recommended due to older versions (including Waterfox Classic) missing security patches from upstream Gecko.

While Waterfox still does not have an official release on Android or iOS as of this update, users can download the older Android version if desired - though this isn’t recommended because the Android version is ridiculously old and missing years’ worth of security fixes and updates. Running extremely outdated software, such as a browser, undermines basic security and negatively affects your privacy due to needless exposure to vulnerabilities.

First Launch

Waterfox launches quickly, which was also noted in the initial post. Nothing’s changed there.


waterfox initial launch showing the latest patch notes and announcement

Upon first launch of this new, independent-from-System1 Waterfox version, I used Portmaster to capture DNS queries made:

Domain Description
waterfox.net The official Waterfox website.
location.services.mozilla.com Mozilla's geolocation service.
content-signature-2-cdn.mozaws.net Service validating data sent between client and other Mozilla services
firefox.settings.services.mozilla.com Latest login breach information from Mozilla.
ocsp.digicert.com Well known + valid OCSP service
r3.0.lencr.org Let's Encrypt domain for providing OCSP data
shavar.services.mozilla.org Mozilla updater service for its tracking protection project
ciscobinary.openh264.org OpenH264 Video Codec download server

Background connections made by Waterfox on initial launch

A little bit to unpack here for the initial launch, but nothing too bad. On my first launch since last installing this browser, Waterfox took me to its patch notes hosted on its website waterfox.net - so this is not really a background connection.

The server hosting Waterfox.net has OCSP stapling enabled, which checks websites' certificates revocation status; Digicert is perhaps the most well-known provider of this service. Lencr.org is owned by Let's Encrypt, which provides free TLS certificates for websites (so you connect via HTTPS instead of HTTP).

Like Firefox, on the first launch after install, Waterfox fetches and downloads Cisco's OpenH264 video codec from ciscobinary.openh264.org. This video codec encodes and decodes in real-time, which makes it great for use in other real-time browser applications (ex: WebRTC).

The other domains are connections to various Mozilla services, as noted in the table.

Waterfox appears to still uphold its no telemetry claim

Similar to vanilla Firefox, Waterfox can be configured using the about:config settings to be more privacy-friendly. It is also compatible with add-ons designed for vanilla Firefox as well; Waterfox still comes with uBlock Origin, an open-source wide spectrum ad/tracker blocker, by default. Additionally, the default search remains Bing.

By default, Waterfox still does not have the opt-out telemetry ("Firefox Data Collection and Use") in its settings, signaling this has been removed in the source code - which is a good thing. Waterfox still uses some Mozilla services, though.

While using Waterfox, I noticed regardless of the sites I visited, it usually made background connections to:

Domain Description
bing.com Bing is a search engine by Microsoft.
firefox.settings.services.mozilla.com Latest login breach information by Mozilla
push.services.mozilla.com Web Push notifications service by Mozilla
aus1.waterfox.net Automatic update service for Waterfox

Background queries made by Waterfox while browsing

Connecting to Bing (bing.com) in the background concerned me. But I relatively quickly found that in the preferences/settings pane, Waterfox enables search suggestions by default; since Bing is the default search provider, connections to Bing pull search suggestions as you type them in the URL bar.

However, the issue with this is the forwarding of your search queries to the selected default search engine in real-time, before ever hitting Enter. Disabling search suggestions fixed this issue altogether. Though, if you prefer search suggestions, then its best to use a private search engine as the default browser search instead.

Of course, some may find the initial and default connections Waterfox makes concerning. However, let’s remember vanilla default Firefox is just...

The post Review: Can We Trust the Waterfox Browser? (Updated 2023) appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2023/07/review-can-we-trust-the-waterfox-browser-updated-2023/feed/ 0 1982464
Dell Adds Orchestration Capabilities to Data Protection Platform https://securityboulevard.com/2023/07/dell-adds-orchestration-capabilities-to-data-protection-platform/ Fri, 21 Jul 2023 17:25:51 +0000 https://securityboulevard.com/?p=1982347 Dell zero trust Network Security multi-cloud zero-trustQualys multi-cloud Wi-Fi 6 access point zero-trust cloud security remote data protection

Dell Technologies added orchestration capabilities to its data protection software that makes it simpler for IT teams to schedule backup.

The post Dell Adds Orchestration Capabilities to Data Protection Platform appeared first on Security Boulevard.

]]>
1982347
Software Supply Chain Attackers Targeting Banks, Checkmarx Says https://securityboulevard.com/2023/07/software-supply-chain-attackers-targeting-banks-checkmarx-says/ Fri, 21 Jul 2023 15:46:14 +0000 https://securityboulevard.com/?p=1982335 supply chain SMB Cowbell Cyber cyberattack colonial ransomware insurance attacks access

Two banks earlier this year were the targets of open source supply chain attacks, the first of their kind in the industry.

The post Software Supply Chain Attackers Targeting Banks, Checkmarx Says appeared first on Security Boulevard.

]]>
1982335
R.I.P. Kevin Mitnick, 1963–2023 https://securityboulevard.com/2023/07/rip-kevin-mitnick-richixbw/ Fri, 21 Jul 2023 13:33:00 +0000 https://securityboulevard.com/?p=1982320 Kevin Mitnick

Kevin is Free: Hackers’ hacker dies, aged 59.

The post R.I.P. Kevin Mitnick, 1963–2023 appeared first on Security Boulevard.

]]>
1982320
House Panel OK’s Bill to Ban Law Enforcement from Buying Data from Brokers https://securityboulevard.com/2023/07/house-panel-oks-bill-to-ban-law-enforcement-from-buying-data-from-brokers/ Thu, 20 Jul 2023 18:36:54 +0000 https://securityboulevard.com/?p=1982188 detection-as-code, misconception

Legislation that would ban law enforcement and federal agencies from buying consumer data from data brokers without a warrant is on its way to the full House.

The post House Panel OK’s Bill to Ban Law Enforcement from Buying Data from Brokers appeared first on Security Boulevard.

]]>
1982188
New P2P Worm Puts Windows and Linux Redis Servers in its Sights https://securityboulevard.com/2023/07/new-p2p-worm-puts-windows-and-linux-redis-servers-in-its-sights/ Thu, 20 Jul 2023 16:35:18 +0000 https://securityboulevard.com/?p=1982166 P2PInfect network security, phishing, ChatGPT, AI, identity, hacking, AI, Chat GPT, ChatGPT malware threat ransomware CNA REvil EtterSilent ransomware dark web

A new peer-to-peer (P2P) worm, P2PInfect, is spreading across instances of the Redis open source database software in the cloud.

The post New P2P Worm Puts Windows and Linux Redis Servers in its Sights appeared first on Security Boulevard.

]]>
1982166
Business Continuity Planning: How Data Security Can Help to Minimize Disruption https://securityboulevard.com/2023/07/business-continuity-planning-how-data-security-can-help-to-minimize-disruption/ https://securityboulevard.com/2023/07/business-continuity-planning-how-data-security-can-help-to-minimize-disruption/#respond Thu, 20 Jul 2023 14:30:00 +0000 https://insights.comforte.com/business-continuity-planning-how-data-security-can-help-to-minimize-disruption Business Continuity Planning: How Data Security Can Help to Minimize Disruption

Business disruption is inevitable today. And increasingly it’s down to cyber incidents. Attacks caused $10.3bn in losses last year, in cases reported to the FBI alone. Even this figure is likely to be just the tip of the iceberg. With so much at stake, organizations need to look at ways to minimize the downtime that can result in serious financial and reputational damage.

The post Business Continuity Planning: How Data Security Can Help to Minimize Disruption appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2023/07/business-continuity-planning-how-data-security-can-help-to-minimize-disruption/feed/ 0 1982257