The latest episode of PBS’s Exposé shows local new investigators uncovering three different chasms in airport security. At one airport, a graveyard shift security guard lets in employees and delivery guys without doing a security screening, how easy it is to walk up to a regional commercial jet, and a woman with a IED taped to her leg getting past the TSA. The full show is available for free online.
security
Security Firm Says Hackers Can Access Vonage Calls
It’s not a good week for Vonage. VoIP Security firm Sipera has announced that they’ve discovered a vulnerability in Vonage’s equipment that can allow hackers to take control of user accounts to intercept calls, make calls via the accounts, eavesdrop, or launch DoS attacks. Although most VoIP systems are about as secure as sending IM messages over a public wifi network (that is, not secure at all), Vonage has a couple of special problems with its Motorola adapters not authorizing requests, which leaves a special door open for bad people doing bad things. The problem also affects adapters from Grandstream and Globe7.
Spy On Your Kids With Hi-Tech Snoopware
They’re all less cost-effective than talking to your kids and listening to what’s going on, but we guess that’s too hard to package and sell that.
iPhone Security Is On Par With Windows 95
We owe Apple an apology, because it turns out they weren’t kidding when they said that opening the iPhone up to 3rd party software was just asking for trouble. That’s because the iPhone runs every single app as “root,” which is computerese for “more power than Steve Jobs.” It was this root access that made the Safari exploit possible back in July, and it can’t be fixed without a complete redesign of the firmware.
Tomato Juice Spill Causes Massive Delays At LaGuardia
Lines the length of city blocks filled New York’s LaGuardia airport Saturday morning after a careless worker spilled tomato juice onto one of the five x-ray machines in the American Airlines terminal. A TSA spokesman cast the tomato juice’s victory over the machines as a failure of science, saying: “That’s the risk you take when you deal with technology.” Passengers were understandably pissed.
When CBS 2 HD told one woman the reason for the delays, she asked if we were “kidding,” but it was no joke. The Transportation Safety Administration confirmed the spill knocked out one of the five units that screen thousands of passengers here each day.
TSA Fails To Find Bombs 60% Of The Time
According to a new report from the Transportation Security Administration, TSA agents failed to find fake bombs during security tests 60% of the time.
Add Super-Protection To Your Logins With $5 Security Key
If you have a PayPal or eBay account, or use OpenID to login to participating sites, then for $5 you can add a second layer of security that is virtually impossible to break unless the thief physically locates you and steals a little plastic device. The PayPal Security Key is a small, keychain-ready fob with a unique ID that’s tied to your account. It generates a new six-digit code very 30 seconds, which you have to enter whenever you log in. The down side is you have to have your security key with you in order to read the code. But the benefits are huge: you basically have a 2nd password that changes 2,880 times every day—and that isn’t available anywhere online.
How To Spot Fake Craigslist And eBay Listings
Planning on doing some buying or selling online? Wired offers some tips on how to spot scammers when you’re on eBay or Craigslist.
6 Online Shopping Scams To Watch Out For
1. Missing Auction Goods – Auction fraud represents over a third of Internet scam complaints every year. Your safest bet is to pay with plastic so you gain the protections of the Fair Credit Billing Act. When plastic’s not an option, setting up an account through PayPal or BillPay that connects to your credit card is the next best bet.
eBay Hacked, User Accounts Disabled, No Personal Information Compromised
eBay has been hacked, says Ars Technica, and several members have had their accounts disabled. eBay’s Trust and Safety team issued a statement in which they said (adorably) that the hacker was “a known fraudster to us.”
Experian, Equifax, and TransUnion To Offer Credit Freezes
All three credit reporting agencies recently announced plans to let consumers freeze their credit files. Credit freezes provide security at the cost of convenience: access to credit reports and scores is prevented without the consumer’s express authorization, making it difficult to open new accounts or lines of credit. Freezes are considered one of the best, albeit drastic, ways to guard against identity theft.
GoDaddy Hushing Up Customer Credit Card Data Breach?
Did domain name registrar GoDaddy have a credit card security breach that they’re not telling anyone about? That’s what Reader Newcxns thinks. Two weeks ago, one of his Citi cards was replaced. One week later, another. The only thing Citi would tell him is that “a merchant” reported a possible data breach. No merchant has sent any data breach reports to Newcxns. In typical fashion, banks and vendors like to hide it when their security systems fail and compromise your account information.
All Charges Dropped Against Circuit City Receipt Refuser
Legal charges have been dropped against Michael Righi (pictured), the guy arrested after refusing to show his receipt to Circuit City, and his driver’s license to a police officer, in exchange for Righi’s pledge to not sue the city. On his blog, Righi writes that he was willing to fight the city to the end without forfeiting any rights whatsoever, but he wanted to spare his family, who would have been principal witnesses, from a protracted legal battle.
../../../..//2007/09/20/on-monday-we-reported-that/
On Monday, we reported that TD Ameritrade knew since May 2007 about data breaches that resulted in thousands of its customers getting penny stock spam, but it turns out the breach could have happened as early as November 2005. [Network World]