by mfisch | Jan 26, 2018 | Information Security
Today I learned NIST no longer admits cell phone SMS authentication is horribly insecure. NIST SP800-63B Published June 2017 refutes earlier guidance to avoid SMS authentication because security. #fedslovesms Tweets by mfisch | Dec 14, 2017 | Uncategorized
I am officially declaring 2017 the year of threat. Following years of rhetoric about state-based attacks and who is at fault for what major system compromise the public seems to finally have come to grips with a few indisputable notes us security pros have been... by mfisch | Apr 25, 2017 | Information Security
A couple of months ago I reported a chained vector vulnerability which affected a corner case 2-Factor bug to Facebook. While their security department utilizes the same anonymous ticketing system their consumer support department I found the encounter professional... by mfisch | May 20, 2015 | Information Security
URL: BIS Proposal & Comments Bureau of Industry and Security export restriction proposal and my comments below … The Bureau of Industry and Security (BIS) proposes to implement the agreements by the Wassenaar Arrangement (WA) at the Plenary meeting in... by mfisch | Nov 9, 2012 | Uncategorized
This may be more huff and puff than real news, at least to anyone in the security industry — it’s just all too common. These sorts of things happen at any and all organizations (though few are likely to admit it). SEC staffers slammed for serious...