Artificial Ignorance & Pen Testing - Kevin Johnson - PSW #785

Google Now Supports Passkeys, Risky New Top Level Domains, Twitter’s Encryption Dilemma

In this episode, we explore the arrival of passwordless Google accounts that use “passkeys,” which offer enhanced usability and security. We discuss the benefits of passkeys over traditional passwords, but also why ...
Governments Try to Ban Encryption (Yet Again)

Governments Try to Ban Encryption (Yet Again)

Déjà vu: Yet again, they’re tugging on the “think of the children” strings. But you can’t make math illegal ...
Security Boulevard
The LastPass Attack Gets Worse, What is Gamification, Signal's Encryption Standoff

The LastPass Attack Gets Worse, What is Gamification, Signal’s Encryption Standoff

Popular password manager LastPass suffered a second attack that lasted for over two months. Now new and disturbing information is being released about the attack. Scott discusses the benefits and challenges of ...

Interview with Signal’s New President

Long and interesting interview with Signal’s new president, Meredith Whittaker: WhatsApp uses the Signal encryption protocol to provide encryption for its messages. That was absolutely a visionary choice that Brian and his ...
data security, GDPR, Strike Force privacy, vendors, RFPs, cloud, data security DLP Iran DUMPS Conti Hackers Sandbox government HackerOne IBM data security

Hackers Use Telegram, Signal, Dark Web to Help Iranian Protesters

Protesters against the Iran regime are getting a boost to aid their efforts from hacking groups who are using Telegram, Signal and the dark web to get around government restrictions. “Key activities ...
Security Boulevard
How 1-Time Passcodes Became a Corporate Liability

How 1-Time Passcodes Became a Corporate Liability

Phishers are enjoying remarkable success using text messages to steal remote access credentials and one-time passcodes from employees at some of the world's largest technology companies and customer support firms. A recent ...
Live at DEF CON 30 feat. Kevin Johnson

Multi-Factor Authentication Fatigue Attack, Signal Account Twilio Hack, Facebook and Instagram In-App Browser

A Cisco employee was compromised by a ransomware gang using a technique called multi-factor authentication fatigue, an attack on the Signal messenger app’s SMS service Twilio potentially disclosed the phone numbers of ...
‘Shame on You, Moxie Marlinspike’—Fake Cash Scheme Pollutes Signal Nonprofit

‘Shame on You, Moxie Marlinspike’—Fake Cash Scheme Pollutes Signal Nonprofit

Creator of the Signal encrypted messaging app, Moxie Marlinspike, is suddenly stepping down as CEO of Signal. Some say greed has turned him. Are the critics fair? You decide ...
Security Boulevard