For solutions to these and other problems please contact us at The-Techy.com

TD customers question how Visa Debit chequing accounts were compromised | CBC News

July 18, 2019 Leave a comment
Categories: General

Slack resets thousands of user passwords four years after hack – The Verge

July 18, 2019 Leave a comment
Categories: General

Google joins Microsoft and deprecates XSS Auditor for Chrome

July 16, 2019 Leave a comment

In an effort to remove overhead and avoid the backlash, Chromium devs have decided to remove xss filtering from future versions of chrome.

https://portswigger.net/daily-swig/google-deprecates-xss-auditor-for-chrome

Categories: General

Let’s make Security everyone’s concern

May 11, 2019 Leave a comment

In what I consider to be a concise delivery of how Cybersecurity can affect all of us, this guy has gone in front of the Committee on Public Safety and National Security to tell our politicians why Security is important and what is at stake!

I have known Thomas Davies for several years and consider him well versed in Cybersecurity. He understands how the bad guys continue to penetrate our computers despite the best methods of network defence and has taken the time to share his perspective with our government.

I included this session from April 1 of this year and have snipped a few minutes of what was an hour and a half where many of our Canadian brethren helped hit home the message that ‘Cybersecurity cannot do it alone’. Gone are the days where the masked man on the white horse can swoop in and save the day because there aren’t enough masked men (and women) in our industry, anywhere.

We built a network of interconnected endpoints using a communication method that just wasn’t designed to be secure. We then built applications on top of those networks that were also not designed to be secure. Netscape came along and created a way to provide some security and here we are several decades later. (Not blaming anyone here but this is what we did and now we have to live with the consequences) 😎

My hope is that our government and other countries like ours, will come to understand that without the resources required to ‘try and keep the ship from taking on water’ our electronic commerce will be in jeopardy. It is only a matter of time before a major outage could occur as a result of a major cyber incident.

I am not sure any type of legislation can help us solve this problem in the near future but it might be time for our government to get involved before it’s too late.

Kudos to you Thomas Davies for being part of the solution. I am proud to call you a friend! (we are still friends right?)

Categories: General

Common Vulnerabilities in the 21rst Century

March 7, 2019 Leave a comment

I was reading an article on Twitter about heap based vulnerabilities when I came across this descriptive list of explanations and their causes.

Many of these show up as browser based flaws and now hit home why sabdboxing is very important for browser sessions.

This list is a good reference for developers and security professionals and can be useful when searching for bugs.

Categories: General

Password advice from the masses

February 28, 2019 Leave a comment

Whenever I travel and have an opportunity to speak with people from around the world I realize that most of us all have similar issues…

Categories: General

Maybe we will see Elvis again this year in Vegas

February 28, 2019 Leave a comment

Imagine how lucky I was to find Elvis, alive and well in Vegas during my trip last August.

I am planning to attend Blackhat again this year and I hope he is really still with us 🤔.

If you are planning to be in Vegas the first week in August this year, reach out to me and if we are all very lucky, we might get a chance to see him again.

Categories: General

Phishing… as easy as 1,2,3

December 2, 2018 Leave a comment

In this short video article, watch how someone can take a few pieces of your personal data and ruin part of your life!

Trust no one and be careful what you share and with whom.

Categories: General

Cyber Security Hub | Incident Of The Week: HSBC Bank Alerts U.S. Customers of Data Breach

December 2, 2018 Leave a comment

In this article, we learn about how HSBC lost 14k personal records and they want everyone to know, they have not seen any fraud yet?

With your personal data flying around like this, are you really just worried about one service provider?

https://www.cshub.com/attacks/articles/incident-of-the-week-hsbc-bank-alerts-us-customers-of-data-breach

Categories: General

Crackenbox2 – how to repurpose your Bitcoin miner

October 29, 2018 Leave a comment

I have been busy at a new job lately and have not had any time to contribute. I found myself so busy in fact that I had purchased some hardware for a new hash killer and did not even open it for several months. I thought this was as good a time as any to create a writeup on how to make your own hash crack computer.

For anyone who was late to the party – Bitcoin mining could be done by creating a computer similar to the one used below but the cost associated with mining your own Bitcoin has gone up making it cost prohibitive. Here is a great way to put those computers to work for you as a security professional / bad guy by cracking passwords.

crackenbox2-GPU

Using four graphics cards that can be purchased for approx. 400.00 each, any average hacker could build him/herself a password cracking computer that could brute force your passwords.

Firstly, I used a MSI Z170A Motherboard with four PCI-E slots (first one is x8 and the other 3 run x4). This is fine because the real power comes from the GPU on the graphics cards and passes back to the bus at normal speeds. Next we add a i3 (6100) and some Ram (4x4G). We put it in a nice case with 5 x 120mm fans to circulate the heat (the GPUs will create a lot of heat and can shutdown if you don’t remove the heat from the area). Finally we need a power supply to power all four of the GPUs so I purchased a 1300w EVGA all for a total of approx. 3,000.00 (YMMV).

crackenbox2

Approaching speeds of almost 60 billion guesses per second, any mortal could destroy a 9 character Windows password that used ANY combination of upper, lower, number or special characters in about an hour.

It’s as easy as using a free, opensource operating system like Ubuntu and loading some additional software to create your own computer that you *could* use to mine Bitcoin but you could probably make more money cracking hashes for profit!

 

Categories: General