Feds love SMS

Today I learned NIST no longer admits cell phone SMS authentication is horribly insecure. NIST SP800-63B Published June 2017 refutes earlier guidance to avoid SMS authentication because security. #fedslovesms Tweets
The Year of Threat

The Year of Threat

I am officially declaring 2017 the year of threat. Following years of rhetoric about state-based attacks and who is at fault for what major system compromise the public seems to finally have come to grips with a few indisputable notes us security pros have been...
Run of the mill “infosec researcher”.

Run of the mill “infosec researcher”.

A couple of months ago I reported a chained vector vulnerability which affected a corner case 2-Factor bug to Facebook. While their security department utilizes the same anonymous ticketing system their consumer support department I found the encounter professional...

SEC Security Lunacy

  This may be more huff and puff than real news, at least to anyone in the security industry — it’s just all too common. These sorts of things happen at any and all organizations (though few are likely to admit it). SEC staffers slammed for serious...