security 19 Apr 2022 Police CyberAlarm: Abysmal security, yet again. 3 attempts, 3 complete failures. Incredibly, cyberAlarm is now even worse than before.
TOFU Attack: Your registration flow is a breach waiting to happen... data 12 Mar 2021 TOFU Attack: Your registration flow is a breach waiting to happen... The risks of failing to validate an email address...
cyberalarm 02 Dec 2020 CyberAlarm: Testing the "production version"... and why you should avoid it. Reviewing the "production" build of CyberAlarm. Good grief - you couldn't make it up.
CyberAlarm: An independent security review... and why you should avoid it. cyberalarm 24 Nov 2020 CyberAlarm: An independent security review... and why you should avoid it. A brief review of CyberAlarm uncovers several serious concerns. Please read this before you deploy it.
security 23 Jun 2017 Kervball: The Kerv ring data breach... Here's what happened the day my Kerv arrived...
2fa 18 Feb 2017 Don't let them paste passwords... After months of tweets, emails & articles from eminent figures like Troy Hunt & the
banking 02 May 2016 Bank & Mobile Network Security: For want of a nail... Ever since publishing a "two factor authentication vs two step verification" article in
everykey 08 Apr 2016 EveryKey Revisited: Military grade? Give me a break. Update 27/04/16: Here are some screenshots of the EveryKey Windows app. It'
snom 13 Feb 2016 PwnPhone: Default passwords allow covert surveillance. A few weeks ago, I was asked to observe an installation of several wireless access
csrf 18 Jan 2016 Identity theft & payment fraud? That's ASDA price. Back in March 2014, I contacted ASDA to report several security vulnerabilities and despite a
password manager 23 Oct 2015 Privacy & Password Managers: A Reality Check Before we begin, let me preface this by saying... I actually quite like Steve Gibson.