Research

Audits, Attacks and False Positives

Audits, Attacks and False Positives

Recently, several security companies detected phishing pages using the name of a core DNC system. These pages attempted to trick users into providing their login credentials by spoofing the legitimate login page for a Democratic Congressional Campaign Committee (DCCC) application buil …

Read Story

The Difficulty of Profiling Hackers

The Difficulty of Profiling Hackers

The public image of any given group of people tends to be created by mass media. Whether it is a tribe of Amazonian warriors or a modern terrorist leader, mass culture will project its own image on them. Hackers are no different. First Published 20th August 2018 When kids get up to no …

Read Story

Reddit's Hack & The Risks of Phone-Based 2-Factor Authentication

Reddit's Hack & The Risks of Phone-Based 2-Factor Authentication

While it is clear that the 2FA implementation was not at fault here, there are significant risks associated with phone based 2FA that warrant serious consideration before you make this type of authentication method available to users. First Published 6th August 2018 r/LetsHackReddit 4 …

Read Story

Subscribe by email