Security link roundup 7/28/08
Email Hacking Going Commercial: Dancho Danchev writes on his blog about a commercial service that uses a software package with a collection of security vulnerabilities (many are Cross Site Scripting/XSS attacks) combined with a network of contractors, a validation service, and several payment options all wrapped up in a single commercial service. This is yet another example of why XSS attacks and CAPTCHA failures are such a big problem.
How to break CAPTCHAs: Blackhat SEO covers a compendium of articles, talks, and writeups on CAPTCHA vulnerabilities and attacks. It is clear that much of the web’s CAPTCHA infrastructure is rapidly fraying. It’s increasingly difficult to build CAPTCHAs that are secure enough from automated attacks, but that do not result in large number of failures for normal people.
Cell Phone Spying: Is Your Life Being Monitored?: Geeks are Sexy has a post on commercial remote call monitoring and tracking options (many of which are legal only under specific circumstances) for mobile phones. The article covers both World Tracker and Flexispy.
Reader Resources
Commentary
- Death of the Hardware Security Appliance | Ronan Kavanagh --CEO; SpamTitan Technologies
- Archiving Challenges and Priorities: Apply Lessons Learned from a Regulated Industry | Stephen Marsh -- Founder and CEO; Smarsh Inc.
- What Can Users Do to Protect Themselves from Bots? | Michael O’Reirdan -- Chairman; Messaging Anti-Abuse Working Group (MAAWG)

Widgets & RSS Feeds
