Access control and authentication - News, Features, and Slideshows

News

  • Researchers demo cloud security issue with Amazon AWS attack

    Researchers from the Horst Goertz Institute (HGI) of the Ruhr-University Bochum (RUB) in Germany have demonstrated an account hijacking attack against Amazon Web Services (AWS) that they believe affects other cloud computing products as well.

  • Researchers demo cloud security issue with Amazon AWS attack

    Researchers from the Horst Goertz Institute (HGI) of the Ruhr-University Bochum (RUB) in Germany have demonstrated an account hijacking attack against Amazon Web Services (AWS) that they believe affects other cloud computing products as well.

  • Exploit-powered Android Trojan uses update attack

    A new variant of the DroidKungFu Android Trojan is posing as a legitimate application update in order to infect handsets, according to security researchers from Finnish antivirus vendor F-Secure.

  • XSS web attacks could live forever, researcher warns

    Websites that accidentally distribute rogue code could find it harder to undo the damage if attackers exploit widespread browser support for HTML5 local storage and an increasing tendency for heavy users of Web apps never to close their browser.

  • GlobalSign plans to reopen Tuesday despite web server hack

    GlobalSign expects to bring its certificate-issuing systems back online on Monday, and resume business Tuesday, it said over the weekend. The U.S. certificate authority (CA) stopped issuing new SSL certificates last Tuesday in order to audit its security, after being named as a target by the hacker who claimed to have attacked Dutch CA DigiNotar.

  • Google's two-step authentication goes worldwide

    Google <a href="http://googleblog.blogspot.com/2011/07/2-step-verification-stay-safe-around.html">said Thursday</a> that it has rolled out its two-step authentication sign-in system to 40 languages across over 150 countries.

  • Passwords in Mac OS X can be pilfered with new tool

    A company that makes password recovery tools has released one that can snatch passwords from a locked or sleeping Macintosh running Mac OS X Lion by plugging another computer into the Mac's FireWire port. The attack technique is several years old and the only way to defend against it is to turn the Mac off.

  • UK operators say voicemail weaknesses fixed

    As the phone hacking saga continues to grip the U.K., mobile operators contend that spying on someone's voicemail messages wouldn't be possible today as several weaknesses in the systems have been eliminated.

[]