Security Leftovers
-
The Key to Securing Hybrid Cloud Environments is Zero-Trust [Ed: Misused buzzwords, often leveraged by purveyors of back doors]
Unlike traditional models that grant implicit trust based on network location, zero-trust assumes that no entity should be trusted by default.
-
Standards/Consortia
-
Techdirt ☛ Wyden Again Warns That ‘SS7’ Telecom Flaw Lets Foreign Countries Broadly Spy On American Communications
For many many years, experts have warned about massive longstanding flaws in Signaling System 7 (SS7, or Common Channel Signaling System 7), a series of protocols hackers can exploit to track user location, dodge encryption, and even record private conversations. Governments and various bad actors routinely exploit the flaw to covertly spy on wireless users around the planet without them ever knowing.
It’s extremely bad, and we’ve know about the problem for a long while. 60 Minutes aired a profile on the issue back in 2016. Senator Ron Wyden demanded answers as early as 2017 from mobile phone companies as to why they haven’t done more to thwart the abuse. I’d always lazily assumed we weren’t rushing to fix the problem because it was also being broadly exploited by the U.S. government.
-
-
Windows TCO
-
Scoop News Group ☛ Justice Department unveils charges against alleged LockBit developer
The U.S. Department of Justice revealed charges Friday against Rostislav Panev, a dual Russian and Israeli national, for his alleged role as a developer in the notorious LockBit ransomware group. Panev was arrested in Israel following a U.S. provisional arrest request and is currently awaiting extradition.
-