Paul Moore

Paul Moore


Kickstarter Password Managers: The good, the iffy and the dangerous.
aes

Kickstarter Password Managers: The good, the iffy and the dangerous.

Over the last few months, Kickstarter has been awash with password managers. Unless you're willing to invest and use a ridiculously tiny comments box, it's impossible to comment or ask further questions so others can see their response. Rather than clutter the comments area, this article will provide a very high-level overview of each product; a summary of why you should/shouldn't use them. Don't forget to bookmark it, as it's likely to be updated frequently. Kickstarter: https://www.ki
Value security?  Avoid TalkTalk.
encryption

Value security? Avoid TalkTalk.

Update 18/10/2014: TalkTalk have now upgraded their SSL configuration; providing a much healthier "A-" on Qualys. More importantly, it's now PCI compliant. -- Cheap viagra, cialis & diet pills I could benefit from a diet pill or two, but I'm pretty sure my Dad isn't the source of this unbeatable offer. His TalkTalk email's been hacked! Trouble is, he runs 1Password, so his passwords all look like this: ls!4ahivKH=:wOMSkY>tM6_L/?n#3}?mWHTIqP5Fe10HSl I'm damn sure our residen
hacked

The difference between two-factor and two-step authentication.

No lengthy article this time folks, just a flow diagram to demonstrate the differences between two-factor authentication and two-step verification. (full size) Why isn't an OTP via SMS a 2nd factor? At first glance, the mobile phone appears to be "something we have" (one of 3 factors necessary to be multi-factor), but that's not quite true. The device itself isn't key to successfully authenticating, but rather the OTP delivered to it. If it were truly a 2nd factor, it would be impos
identity

Does Two Factor Authentication Actually Weaken Security?

This article flies in the face of general consensus. As you're here, you either share this view or you're questioning my sanity and/or logic. Adoption Rates Ultimately, the success of any new technology hinges on the end-user. Trouble is, 2FA isn't new... we've used it in various contexts since the 1960s. An ATM machine for example, requires your PIN (something you know) and your card (something you have). When it comes to web-based authentication however, I'd argue it's actually an
decryption

Virgin Media: You're only as secure as your weakest link.

Avid followers will know, I've long been an advocate of password managers... specifically 1Password. So much so, I'm often criticised for treating it as a panacea. With that in mind, it's about time I outlined another risk which isn't immediately obvious; one which allows me access to almost any site you use and renders your long, unique & immensely-strong password redundant. I am, of course, referring to the security of your email provider. Preface On August 27th, I received a tweet

Bye WordPress, Hello Ghost!

Hello folks. Just a very quick post to welcome you to the latest version of the RR blog. For the last 2 years, the site was built on WordPress. I was never entirely happy with the theme/layout and the 2/3 seconds it took to load each article. It was heavily optimised but still couldn't offer a great real-world foundation to grow the blog. Queue "Ghost" - A blog platform built entirely on NodeJS. It's light, simple and fast. Seriously, mind-blowingly fast! Coupled with NGINX and a variety o
aes

How secure is #Roboform? The 5 minute challenge.

TL;DR - Your master password is sent to Siber Systems and the mobile applications are insecure. Described by its creators, Siber Systems, as "completely secure using military grade encryption", Roboform has been knocking about since 1999. Now, I have a rule when testing password managers.  If the vendor describes it as "military grade" or "completely secure", I'll set aside 5 minutes to demonstrate why that's never, ever true. Solid security is a mixture of security & usability; a balancin
benefits

Council Tax, PCN & Benefits Payment Data Leaked! Are you affected?

Well, I guess it had to happen at some time. To be fair, I was parked on double yellow lines. No excuses, no basis to contest the penalty... I was in the wrong. In those 10 minutes however, I unwittingly caused Walsall Metropolitan Borough Council sufficient financial hardship to warrant a £70 fine; reduced to £35 if I paid within 14 days.  In a cleansing act of contrition, I paid via the "secure online payment system". What's wrong? Your private, confidential payment details are being
broadband

Virgin Media SuperHub: 7 second security flaw...

OK folks, no waffling, no hyperbole... I'll get straight to the point. If you run a Virgin Media SuperHub or Superhub 2, your network is not secure. The Boot Sequence When you switch on your device, it takes roughly a minute to fully boot, bring up the network cards/WiFi and start the DHCP server; needed to assign an IP to each device wanting to connect.  During that time, the device brings up the WiFi card without any form of encryption. Let me explain with a timeline view... (clic
banking

cyberstreetwise.com - Really bad #infosec advice.

Be Cyber Streetwise is a cross-government campaign, funded by the National Cyber Security Programme, and delivered in partnership with the private and voluntary sectors. The campaign is led by the Home Office, working closely with the Department for Business, Innovation and Skills and the Cabinet Office. On January 13th 2014, I read an article on the BBC website about a new government initiative on cyber security called cyberstreetwise.com. With the above description in mind, I had a qui
cashplus

CashPlus: "It is secure" - Ooooh no it isn't.

As part of a wider research project, I joined CashPlus in June (18th to be precise), which is purportedly... better than a business bank account So I paid the £29.99 annual membership fee and waited for the card to arrive. Less than a week later, the card arrived and I headed over to MyCashPlus.co.uk to register & activate the card.  For those of you that don't follow me... I use AgileBits' 1Password to generate and manage my passwords.  If you're still trying to think up and remember pass
1password

Forgot your password? You're doing it wrong.

Have you ever struggled to remember a username or password?  Join the club. Wouldn't it be great if you could log in to every site using the same password, without compromising your security?  Now you can! Introducing AgileBits 1Password, the gold standard in decentralized identity & password management for Windows, Mac, iPhone, iPad, Android and unofficially, Linux. So, what's it do? In short, it removes all the hassle from any sign in/sign up process. Next time you're scratching