Security Leftovers
-
Encountered and Reported Security Issues in MS Office
In the most recent ' Security Now 'Podcast #893' by Steve Gibson, he discussed the fact that Microsoft has chosen not to fix a well understood security vulnerability currently in their OME (Office Method Encryption), that has existed for years, a commonly used system, which claims to have a means to encrypt text in Office, say before sending it or storing it.
BUT they use ECB 'Electronic Code book' as a 'secure' method, which is well known to leak information. ECB is well known to be insecure. Microsoft has refused to fix or patch the Windows Office method. I have personally examined ECB in the past, and its problems are obvious and well known. Especially for cases like stolen or diverted data. (Ransomware?) A major issue for assumed security in MS Office.
-
The Defender’s Advantage Cyber Snapshot Issue 2 — More Insights From the Frontlines | Mandiant
In the latter half of this year we’ve reported on a number of threats from information operations campaigns to widespread campaigns targeting Microsoft 365, Duo Authentication, and cryptocurrency platforms, and our continued tracking of activity from advanced state-sponsored threat actor groups.
-
How Matter is a key step forward for cybersecurity [Ed: Equating surveillance with "cybersecurity"?]
One of my favorite things about the Matter home interoperability protocol is that even if it doesn’t make it easy to manage my crazy complex smart home right from the beginning — or ultimately, ever — it does mandate some basic security requirements for connected devices. This is a big deal!