Brian

Archive

Something else we may be able to learn from WireLurker

For years, Apple has said they don’t suffer from malware, but then every so often, something pops up and hits them fairly hard. (Not that they admit it, but they certainly aren’t any better at...

Google and Yubico Support for FIDO Announced

Today, Google and Yubico announced FIDO U2F (Universal 2nd Factor) support for Google services using U2F YubiKeys. This is great news and shows the growing realization that 2FA is needed for your critical online services,...

Rest in Peace, SSLv3

First there was Heartbleed, and now we have POODLEbleed. It seems like there is a never-ending stream of bad news about security lately. With POODLE, it has been shown that SSLv3 is insecure, and can...

Don’t let your 2FA be Shellshocked!

The recent vulnerability announced for the Bash shell has been named Shellshock (this seems to be a new news trend after the Heartbleed OpenSSL flaw). This is hopefully one of those once-in-a-generation vulnerabilities to a...

GreenRADIUS v1.2.0.2

September 28, 2014 Shellshock vulnerabilities were patched in this release. While GreenRADIUS is not typically vulnerable to this type of attack due to its configuration, this release has the final bash patch that eliminates the...