Security Leftovers
-
Security updates for Wednesday [LWN.net]
Security updates have been issued by Debian (cgal, ruby-rails-html-sanitizer, and xfce4-settings), Red Hat (dbus, grub2, kernel, pki-core, and usbguard), Scientific Linux (pki-core), SUSE (bcel, LibVNCServer, and xen), and Ubuntu (ca-certificates and u-boot).
-
The Pacific island nation of Vanuatu has been knocked offline for more than a month [iophk: Windows TCO]
Vanuatu's government officials first discovered suspicious activity on their networks, many of which are centrally connected, on Nov. 6. They revealed the breach to local media several days later, but have so far been fairly tight lipped about the extent of the damage, the possible culprits, and what's being done to recover service.
Some sources have suggested the attack was ransomware, in which cybercriminals break in and take data hostage in exchange for payment, though the government has not officially confirmed whether that's the case or addressed whether a ransom payment was made.
Vanuatu officials did not respond to NPR's requests for comment.
-
How do I revoke a FIDO / WebAuthN token from every service?
OK, done! My wife and I spend a very boring evening going through every single account we have which supports FIDO tokens with WebAuthN - about a dozen in total. We manually paired two keys each. We put our main key on our keyrings, then drove out to the woods and buried our spares in a a waterproof box in a top secret location1.
But what if I lost my keys?