×
Encryption

Building Deception Into Encryption Software 106

holy_calamity writes "MIT Technology Review reports on a new cryptosystem designed to protect stolen data against attempts to break encryption by brute force guessing of the password or key. Honey Encryption serves up plausible fake data in response to every incorrect guess of the password. If the attacker does eventually guess correctly, the real data should be lost amongst the crowd of spoof data. Ari Juels, who invented the technique and was previously chief scientist at RSA, is working on software to protect password managers using the technique."
Advertising

Rovio Denies Knowledge of NSA Access, Angry Birds Website Defaced Anyway 71

Nerval's Lobster writes "Rovio Entertainment, the software company behind Angry Birds, denies that it knowingly shares data with the NSA, Britain's GCHQ, or any other national intelligence agency. But that didn't stop hackers from briefly defacing the Angry Birds website with an NSA logo and the title 'Spying Birds.' Rovio's troubles began with a New York Times article that suggested the NSA and GCHQ had installed backdoors in popular apps such as Angry Birds, allowing the agencies to siphon up enormous amounts of user data. The Times drew its information from government whistleblower Edward Snowden, who has leaked hundreds of pages of top-secret documents related to NSA activities over the past few months. 'The alleged surveillance may be conducted through third party advertising networks used by millions of commercial web sites and mobile applications across all industries,' Rovio wrote in a statement on its website. 'If advertising networks are indeed targeted, it would appear that no Internet-enabled device that visits ad-enabled web sites or uses ad-enabled applications is immune to such surveillance.' The company pledged to evaluate its relationships with those ad networks. The controversy is unlikely to dampen enthusiasm for the Angry Birds franchise, which has enjoyed hundreds of millions of downloads across a multitude of platforms. It could, however, add momentum to continuing discussions about the NSA's reach into peoples' lives."
Twitter

Developer Loses Single-Letter Twitter Handle Through Extortion 448

Hugh Pickens DOT Com writes "Naoki Hiroshima, creator of Cocoyon and a developer for Echofon, writes at Medium that he had a rare one-letter Twitter username — @N — and had been offered as much as $50,000 for its purchase. 'People have tried to steal it. Password reset instructions are a regular sight in my email inbox,' writes Hiroshima. 'As of today, I no longer control @N. I was extorted into giving it up.' Hiroshima writes that a hacker used social engineering with Paypal to get the last four digits of his credit card number over the phone then used that information to gain control of his GoDaddy account. 'Most websites use email as a method of verification. If your email account is compromised, an attacker can easily reset your password on many other websites. By taking control of my domain name at GoDaddy, my attacker was able to control my email.' Hiroshima received a message from his extortionist. 'Your GoDaddy domains are in my possession, one fake purchase and they can be repossessed by godaddy and never seen again. I see you run quite a few nice websites so I have left those alone for now, all data on the sites has remained intact. Would you be willing to compromise? access to @N for about 5 minutes while I swap the handle in exchange for your godaddy, and help securing your data?' Hiroshima writes that it''s hard to decide what's more shocking, the fact that PayPal gave the attacker the last four digits of his credit card number over the phone, or that GoDaddy accepted it as verification. Hiroshima has two takeaways from his experience: Avoid custom domains for your login email address and don't let companies such as PayPal and GoDaddy store your credit card information."

Slashdot Top Deals