Thursday, August 31, 2017

Journalists Generally Do Not Use Secure Communication

This should come as no surprise:

Alas, our findings suggest that secure communications haven't yet attracted mass adoption among journalists. We looked at 2,515 Washington journalists with permanent credentials to cover Congress, and we found only 2.5 percent of them solicit end-to-end encrypted communication via their Twitter bios. That's just 62 out of all the broadcast, newspaper, wire service, and digital reporters. Just 28 list a way to reach them via Signal or another secure messaging app. Only 22 provide a PGP public key, a method that allows sources to send encrypted messages. A paltry seven advertise a secure email address. In an era when anything that can be hacked will be and when the president has declared outright war on the media, this should serve as a frightening wake-up call.

[...]

When journalists don't step up, sources with sensitive information face the burden of using riskier modes of communication to initiate contact­ -- and possibly conduct all of their exchanges­ -- with reporters. It increases their chances of getting caught, putting them in danger of losing their job or facing prosecution. It's burden enough to make them think twice about whistleblowing.

I forgive them for not using secure e-mail. It's hard to use and confusing. But secure messaging is easy.



from Journalists Generally Do Not Use Secure Communication

Wednesday, August 30, 2017

Hospital Stays Can Take Out More Than Your Organs

The Cyber Theft Threat in Healthcare and how Service Providers can Transform Risk to Reward You went to the hospital to get your appendix out and one week later your identity was taken from you as well.  How did this happen? In their 2017 Data Breach survey, Verizon found that ransomware has jumped up from […]

The post Hospital Stays Can Take Out More Than Your Organs appeared first on Radware Blog.



from Hospital Stays Can Take Out More Than Your Organs

711 MILLION email accounts weaponized by Onliner for spam campaigns

The Onliner spambot weaponized a whopping 711 million email accounts to distribute spam emails laden with malware. David Bisson reports.

from 711 MILLION email accounts weaponized by Onliner for spam campaigns

New ESET research uncovers Gazer, the stealthy backdoor that spies on embassies

Researchers uncover the activities of the notorious Turla cyberespionage group, and specifically a previously undocumented backdoor that has been used to spy on consulates and embassies worldwide. Read more in my article on the We Live Security blog.

from New ESET research uncovers Gazer, the stealthy backdoor that spies on embassies

‘House of Cards’ publisher exposes gigabytes of sensitive client files

A backup drive on the publisher's network exposed gigabytes of sensitive client data -- including unpublished books, invoices, details of royalty payments, and contracts.

from ‘House of Cards’ publisher exposes gigabytes of sensitive client files

The NSA’s 2014 Media Engagement and Outreach Plan

Interesting post-Snowden reading, just declassified. (U) External Communication will address at least one of "fresh look" narratives: (U) NSA does not access everything. (U) NSA does not collect indiscriminately on U.S. Persons and foreign nationals. (U) NSA does not weaken encryption. (U) NSA has value to the nation. There's lots more....

from The NSA’s 2014 Media Engagement and Outreach Plan

CeX Notifies Two Million Registered Customers of Online Security Breach

CeX has notified up to two million customers about an online security breach that might have compromised their personal data. On 29 August, the second-hand goods chain that specializes in computer and video games announced it had suffered a security event. As quoted in a statement posted to its website: “We have recently been subject […]… Read More

The post CeX Notifies Two Million Registered Customers of Online Security Breach appeared first on The State of Security.



from CeX Notifies Two Million Registered Customers of Online Security Breach