SECURITY: Germany may dictate no end-to-end encryption

Tuesday, October 14, 2025

https://digitalchew.com/2025/10/05/chat-control-could-break-encryption-warns-signal/

Chat Control Could Break Encryption, Warns Signal
Reginald Edward
October 5, 2025

*** begin quote ***

Key Takeaways

  • Signal’s president warns Germany that Chat Control could destroy user privacy.
  • Chat Control forces apps to scan messages before encryption.
  • The plan would weaken secure chats and allow mass surveillance.
  • Signal says it will leave the EU if Chat Control becomes law.
  • Germany’s vote on Chat Control could shape global privacy rules.

*** end quote ***

And what happens when one Gooferment does it —  whatever the particular “it” is, other Gooferments think “what a great idea” and do it too.

Argh!

— 30 —


SECURITY: Q-day threats — post-quantum security

Monday, September 29, 2025

https://blog.cloudflare.com/you-dont-need-quantum-hardware/?utm_source=tldrinfosec/

You don’t need quantum hardware for post-quantum security

2025-09-19

Luke Valenta

*** begin quote ***

You don’t need quantum hardware for post-quantum security (15 minute read)

Organizations can prepare for quantum computing threats (Q-day) using post-quantum cryptography (PQC) deployed on existing hardware without needing expensive quantum technologies like quantum key distribution (QKD) or quantum random number generators (QRNG). Being “quantum ready” means systems remain secure after quantum computers can break conventional cryptography. Beware of vendor claims that quantum hardware products are necessary for quantum-resistant security. Organizations should prioritize implementing PQC algorithms on current infrastructure rather than investing in quantum hardware solutions that are neither necessary nor sufficient for protection against quantum adversaries.

*** end quote ***

This has huge implications for both digital signatures and ₿itcoin.

— 30 —


SECURITY: Fake US and Canadian IDs

Sunday, September 28, 2025

https://hackread.com/chinese-network-ofake-us-canadian-ids/?utm_source=tldrinfosec

Chinese Network Selling Thousands of Fake US and Canadian IDs

  • New investigation exposes a China-based ring that sold over 6,500 fake United States and Canadian IDs using well-planned covert packaging. Learn how this operation threatens national security and enables financial crime.

by Deeba Ahmed — September 19, 2025

*** begin quote ***

Chinese Network Selling Thousands of Fake US and Canadian IDs (3 minute read)

CloudSEK exposed a China-based operation called “ForgeCraft” that sold over 6,500 counterfeit US and Canadian driver’s licenses and Social Security cards to more than 4,500 buyers, generating over $785,000 in revenue through 83 websites and using covert packaging methods to ship fake IDs hidden in everyday items. The sophisticated fake documents feature scannable barcodes, holograms, and UV markings and pose national security risks by enabling financial fraud, bypassing border checks, and potentially facilitating voter fraud. CloudSEK researchers identified the main operator’s location in Xiamen, China, and shared evidence with authorities to disrupt the operation.

*** end quote ***

So how do we stop this?

Clearly, this is an “epidemic” and undermines everything that needs “security”.

Must be a way to create a crypto hash and block chain implementation to compare it with.

— 30 —


SECURITY: Don’t forget the old printer as a “data leak”

Thursday, September 18, 2025

FROM TLDR Information Security 2025-09-10

*** begin quote ***

USB drives are still a problem – but they’re not your only data exfiltration risk (Sponsor)

While most organizations focus on blocking USB devices, attackers and insiders can just as easily steal data through network shares, cloud storage, or even local folder access. You need visibility and control over ALL storage access points.

*** end quote ***

Yeah, but I remember that brokers used to keep a shadow book at home.  Meticulously copying or printing duplicates of “their” Client accounts.  

Now it’s easy to just use your phone to take a picture.  AI or software will even extract the text from the picture so no reentering data drudgery. 

I’ve even seen utilities that will put files into QR codes for backup and recovery.

Never underestimate human inginuity to get what they want. Be it drugs, sex, money, or data.

— 30 —


SECURITY: Does Uber know who’s really driving?

Tuesday, August 26, 2025

https://www.ericpetersautos.com/2025/08/11/why-ride-hailing-is-not-as-safe-as-you-think/

Why Ride-Hailing Is Not as Safe as You Think
By badger – August 11, 2025

*** begin quote ***

Even with driver photos and license details, identity fraud is possible. Some drivers rent accounts or share them illegally. That raises big safety questions. Safety becomes an illusion when systems are not properly enforced. You might not know who is actually behind the wheel. This illusion affects both riders and drivers alike. When safety is marketed more than it is practiced, everyone loses in the end.

*** end quote ***

I know that Uber has updated their app with a code you give the driver and you get a photo of the driver.  I thought that would be enough.  

BUT, (and there is always a BIG butt), the “renting” and “sharing” of accounts shows a monkey wrench into their system.

Maybe they should require you to take a picture of the driver that then Uber can use AI to confirm who’s really driving?

— 30 —


SECURITY: No technology needed for this hack; just call up and lie

Sunday, August 17, 2025

https://www.wnd.com/2025/08/helpdesk-havoc-why-clorox-is-suing-indian-company/

Why Clorox is suing Indian company for $380 million

  • In Clorox’s telling, the hacker didn’t crack advanced encryption or spear-phish executives. He just called Cognizant on the phone and lied

By Amanda Bartolotta  —  August 7, 2025

*** begin quote ***

In a San Francisco courtroom, the Clorox Company recently dropped a legal bombshell – a $380 million lawsuit against Indian-American information technology company Cognizant, alleging gross negligence in a 2023 cyberattack.

In the complaint dated July 22, 2025, Clorox contends a hacker simply called Cognizant’s helpdesk, lied about being an employee and was handed network credentials – no identity verification, no oversight, just a password transfer. The resulting cyberattack ended up paralyzing Clorox’s operations, costing upwards of $49 million in remediation and much more in lost business.

*** end quote ***

Way back when I ran an information security desk, long before “password managers”, in the “yellow sticky note” era, I was challenged to reduce the number of password resets my group was doing.  Not for security; a cost saving attempt.  (We figured that every call cost the company about 50$ in lost productivity.)  So my team came up with a great solution, when a call came in for a forgotten password, we’d just have the person have his supervisor call in for a reset.  Laugh!  Calls dropped dramatically.  It was trivial to verify the supervisor since we’d just call them back at their number listed in the company phonebook.  (Those still existed.)  Then the supervisor would connect the employee and we’d do the reset.  Call dropped so much we had weekly pool when the next one would come in.  (Dollar a head per week.  Pool grew about 20$ per week.)  Sometimes we went a month without a reset.

Guess outsourcing your help desk was NOT so cost effective?

— 30 — 


SECURITY: Your own domain can prevent phishing

Saturday, July 12, 2025

An Original Thought

May I suggest that you have your own domain?

The common wisdom, or is that common whizdumb, is to own your own name as a domain name. I own “reinke.cc”. (I like saying “sea sea me at reinke.cc”! me@reinke.cc will actually work!) 

It gives one quite a bit of control. And, it’s very cheap. I know three solutions: wordpressdotcom with gmail, email only with 1and1, and domain+email+webspace also at 1and1. 

My point is not that you should use 1and1. http://www.1and1.com/?k_id=9113251 I could care less which one you use. It’s that getting on to your own domain with email is cheap and easy. 

And, it’s not aol, hotmail, yahoo, or gmail. It IS your own “personal brand”. And, the “bad guys” can’t fool you!

If you have your own domain, you can “bulletproof” your email from phishing and frauds!

Let’s assume that you have “your own domain” named “yourowndomain.com”, and you bank at “your bank” at “yourbank.com”.

You give “yourbank.com” your email address as “yourbankcom@yourowndomain.com”.  (Be prepared for some strange looks when you do this because the folk never heard of such and email address.)

Then you can set up an email filter  — let’s use Gmail as an example  —  that says:

  • Comes from “yourbank.com” and
  • Is addressed to “yourbankcom@yourowndomain.com” and 
  • You specify an label of “yourbank”

So all your email comes into GMAIL and gets assigned a label “INBOX”.

  • Anything that comes in that purports to be from “yourbank” MUST have the GMAIL assigned label of both “INBOX” and “yourbank”.
  • You can also set up an email filter for addressed to “yourbankcom@yourowndomain.com” and NOT addressed from “yourbank.com” and label it “PHISHING ATTACK”.
  • You can also set up an email filter for addressed NOT to “yourbankcom@yourowndomain.com” and addressed from “yourbankcom@yourowndomain.com” and label it “BANK GAVE OUT YOUR EMAIL ADDRESS”.

Pretty tricky and quickly eliminates PHISHING ATTACKS and identifies when the “BANK GAVE OUT YOUR EMAIL ADDRESS”.

Applause please?  

Why the email providers can’t protect you by using the appropriate internet protocols is beyond me!

*** begin quote ***

Email authentication methods and protocols 

  • SPF (Sender Policy Framework)

    A sender policy framework (SPF) is a record published in your DNS that lists all the IP addresses that are allowed to send emails on behalf of your domain. When an incoming email is received, the recipient server will check the SPF record to verify if the sending IP address is authorized to send emails for that particular domain. If it’s not listed in the SPF record, there’s a higher chance that the email will be marked as spam or blocked altogether. While SPFs can help to prevent spam and phishing attempts, they also may reject legitimate emails in situations where the sender’s domain SPF records aren’t properly configured.

  • DKIM (DomainKeys Identified Mail)

    DKIM stands as a pivotal technology in the battle against email spoofing by attaching a digital signature to each outgoing email, linked directly to the sender’s domain name. This signature enables the recipient’s email server to verify whether an email purportedly sent from a specific domain is authorized by that domain’s owner. Given that emails often undergo multiple hops—redistributed by mailing lists or forwarding rules—DKIM ensures that signed messages can be reliably relayed by any server, maintaining their integrity and authenticity throughout their journey.

  • DMARC (Domain-based Message Authentication, Reporting, and Conformance)

    The DMARC protocol was built on top of SPF and DKIM, and relies on senders and receivers sharing information to ensure a smooth validation process. DMARC refers to SPF and DKIM records to validate a sender’s identity, along with testing whether the domain they use is found in the “from” address. If an email does not pass the validation test, DMARC provides rules on how to treat the message based on certain conditions. This protocol can help domain owners block phishing attacks by filtering such messages into spam, or rejecting them altogether.

  • BIMI (Brand Indicators for Message Identification)

    If you’ve ever seen an email from a brand that included their logo right in the sender column, that brand was using BIMI. Improving email security with BIMI involves using an authentication system that enables trusted senders to display an icon of their choice directly in senders’ inboxes. BIMI can boost recipients’ trust in your messages, while heightening visibility of your brand.

  • MTA-STS (Mail Transfer Agent Strict Transport Security)

    MTA-STS is a security standard that enables you to send and receive messages securely over an encrypted SMTP connection. The MTA-STS protocol enhances email security by enabling an SMTP client to confirm the server’s identity during the TLS handshake. It does this by requiring the server to present its certificate fingerprint, which the client then matches with a trust store of certificates from verified servers. This process ensures the client does not connect to fraudulent servers, maintaining secure communication. 

  • TLS reporting

    TLS reporting is a mechanism that enables email senders to report issues with TLS connectivity.

    T is more effective when used alongside MTA-STS. The strict enforcement mode of MTA-STS will prevent email delivery if TLS issues are detected, ensuring a higher level of security and reliability in email communications.

  • ARC (Authenticated Received Chain)

    ARC acts as a “chain of custody” for email messages. It enables every entity involved in processing the message to clearly see which entities have previously interacted with it. At every stage of handling, it provides a detailed authentication assessment. The primary advantage of ARC, now adopted by the majority of mail servers, is its solution to a significant issue: previously, when a DMARC-protected email was forwarded, it would fail DKIM authentication and, consequently, DMARC. ARC preserves all original authentication information, allowing the final recipient’s mail server to verify that the email was DKIM authenticated before being forwarded.

*** end quote ***

— 30 —


SECURITY: SMS is not a good 2FA (Second Factor Authentication)

Saturday, May 10, 2025

https://www.makeuseof.com/security-apps-protect-your-data/?utm_medium=newsletter&utm_campaign=MUO-202505090800&utm_source=MUO-NL&user=cmVpbmtlZmpAZ21haWwuY29t&lctg=7e6c3cd411d6a815afa18582d54bd455914c43c5f69df1448b8ec20ee4959f71

Install These 5 Security Apps Now to Protect Your Data
Jowi Morales

<< EDITOR ADDED DATE 2025-05-07>>

*** begin quote ***

Authenticator

Usernames and passwords are no longer as secure as you might think; that’s why you should switch to two-factor authentication (2FA)to help secure your online access. You can easily set this up on most accounts, including your accounts on Google, Meta, and more, ensuring that any potential hacker who has compromised your username and password combination still needs a one-time password to gain access.

However, we don’t recommend using SMS for your 2FA code because of its many disadvantages. For example, if you’ve been specifically targeted by personal identity thieves, they can trick your mobile provider into transferring your number to a SIM card that they have (called SIM swap), meaning they will receive your OTP codes on their device. Furthermore, SMS messages can be intercepted, meaning someone targeting you can easily steal your OTPs even if you did not lose access to your SIM card. And if you lose your phone signal (or your service provider runs into problems), you won’t get your codes and will be unable to access your accounts.

*** end quote ***

Personally, I use Google Authenticator. But I have AUTHY, LASTPASS, and BITWARDEN. Can’t say I prefer one over another, but given how stuff gets “deprecated” (i.e., abandoned), I’m ready to switch.

I have a running debate with my bank about their use of SMS.  So far, I’m losing but I’m still nagging.

Argh!

—30—


SECURITY: Don’t just take your power from any source?

Wednesday, April 30, 2025

https://arstechnica.com/security/2025/04/ios-and-android-juice-jacking-defenses-have-been-trivial-to-bypass-for-years/

SON OF JUICE JACKING ARISES

  • iOS and Android juice jacking defenses have been trivial to bypass for years
  • New ChoiceJacking attack allows malicious chargers to steal data from phones.

Dan Goodin – Apr 28, 2025 7:00 AM 

*** begin quote ***

Word that juice-jacking-style attacks are once again possible on some Android devices and out-of-date iPhones is likely to breathe new life into the constant warnings from federal authorities, tech pundits, news outlets, and local and state government agencies that phone users should steer clear of public charging stations.

As I reported in 2023, these warnings are mostly scaremongering, and the advent of ChoiceJacking does little to change that, given that there are no documented cases of such attacks in the wild. That said, people using Android devices that don’t support Google’s new authentication requirement may want to refrain from public charging.

*** end quote ***

This reinforces my personal preference for having an external battery for recharge.  All my cars and my EDC pack have an ANKER power block, my own power plug, and 3 short USB-A cables.  My SOP is to not use “public ports” unless I have no other choice.  Suggest that anyone who values their security should do the same.

—30—


SECURITY: may verify “authentic” accounts

Friday, April 25, 2025

https://bsky.social/about/blog/04-21-2025-verification

A New Form of Verification on Bluesky
April 21, 2025 by The Bluesky Team

*** begin quote ***

In 2023, we launched our first layer of verification: letting individuals and organizations set their domain as their username. Since then, over 270,000 accounts have linked their Bluesky username to their website. Domain handles continue to be an important part of verification on Bluesky. At the same time, we’ve heard from users that a larger visual signal would be useful in knowing which accounts are authentic.

*** and ***

During this initial phase, Bluesky is not accepting direct applications for verification. As this feature stabilizes, we’ll launch a request form for notable and authentic accounts interested in becoming verified or becoming trusted verifiers.

*** end quote ***

Interesting that they MAY verify real people. 

With or without a “subscription”?

Often thought that ISPs if they wanted could tie a User’s identity to the credit card they pay with.  Also, they COULD, but don’t allow such an identity to create sub accounts for children and young adults.  

Wouldn’t this cut down on the number and kind of bots that spam the inet with trash?

Seems so simple to me.

Argh!

—30—