Showing posts with label USB Key. Show all posts
Showing posts with label USB Key. Show all posts

Thursday, 12 November 2015

Windows BitLocker Decryption Leak Made Possible


A vulnerability in Windows that Microsoft patched this month made it possible in certain circumstances for attackers to hard disks that were encrypted with BitLocker to decrypt. BitLocker encryption software from Microsoft which is present on certain versions of Windows.

To gain access to encrypted hard drives, there are several options, such as using a PIN, USB key, or Trusted Platform Module (TPM). On Windows, however, found himself a vulnerability through which an attacker could bypass Kerberos authentication and attacked computers could decrypt hard disks encrypted with BitLocker.

In the case of the now-remedied vulnerabilities an attacker could abuse it here only if the attacked system without BitLocker PIN or USB key used, the computer was located and the attacker had physical access to the machine in a domain. According to Microsoft, there are no known cases in which the vulnerability is actually attacked. In order to solve the problem is Microsoft Security Bulletin MS15-122 appeared.

Sunday, 6 September 2015

Chrysler Calls 7800 SUVs Back Because Of Vulnerability



Chrysler has in the United States 7800 SUVs because of a vulnerability in the radios recalled. Using the vulnerability, an attacker can remotely the system "manipulate," the carmaker. Recently, scientists show how remote a Jeep could partially control.

Chrysler says it has already taken measures to prevent such attacks. Through these measures will be blocked access to certain vehicle systems. For this, customers or dealers do not have to do anything. The vulnerability which the 7800 SUVs are now being recalled is different from the problem that the two researchers demonstrated in July and which the carmaker 1.4 million vehicles called back.

As with the recall in this case goes to a voluntary recall. The problem is with Jeep Renegade SUVs of 2015 with a 6.5-inch touchscreen. Customers receive a USB stick which they can update the car software itself. Another option is to download the software or go through the dealer, who will perform the installation. For this purpose, no fee will be charged.

In the press release Chrysler also announced that it is not aware of any accidents or complaints were the result of attacks on the vulnerability. Below is a picture of the USB key that was sent recently to American car owners to patch the previously discovered vulnerability in Chrysler cars. An action where security experts much criticism had on.

Friday, 14 August 2015

Dropbox Secure Accounts With USB Key



Users who want to protect their Dropbox account additional courses may also log in via a USB key. The 'security key' functions as a second security factor during login. Once the password is entered, the presence of the Universal 2nd Factor (U2F) security key checked. In addition, the USB device works only on dropbox.com and can thus prevent phishing.

According Dropbox security key, thus providing protection to more than two-factor authentication via SMS is the case. For the login makes use of the security key U2F-protocol developed by the FIDO Alliance. This is an alliance of IT companies that want to eliminate the password and therefore come up with alternative solutions.

Dropbox users to log in via the USB key will first set in their account. At this moment U2F only dropbox.com in conjunction with Google Chrome. The USB key is via different suppliers to obtain. Last year, Google decided U2F for logging in to Google Accounts support .