passwords

Breaking the Password Barrier: FIDO’s Path to Seamless Security
As the digital world rapidly expands, the need for secure, seamless authentication becomes more urgent. At the forefront of this evolution is FIDO (Fast Identity Online), promoting password-less authentication that combines convenience ...
Security Boulevard

Personal Digital Security Impacts Physical Security
Maintaining personal security online is more critical than ever as it impacts your physical security. Privacy breaches are becoming increasingly sophisticated, targeting individuals as well as organizations. We’ve put together tools and ...

Enhancing Active Directory Protection Through Strong Password and Access Management
An effective way to improve AD security is to implement both strong password policies and robust permissions management and monitoring ...
Security Boulevard

Oasis Security Details MFA Security Flaw Found in Microsoft Cloud Services
Oasis Security today revealed that it worked with Microsoft to fix a flaw in its implementation of multi-factor authentication (MFA) that could have been used by cybercriminals to gain access to every ...
Security Boulevard
Good Essay on the History of Bad Password Policies
Stuart Schechter makes some good points on the history of bad password policies: Morris and Thompson’s work brought much-needed data to highlight a problem that lots of people suspected was bad, but ...

Hacked Robot Vacuums, Secret Printer Tracking Dots
Tom Eston | | credential stuffing, Cyber Security, cyber threat, Cybersecurity, Data Privacy, Digital Privacy, Ecovac, Episodes, government, hacked, Hacking, Information Security, Infosec, Internet of things, iot, passwords, Podcast, Podcasts, printer, Printer Tracking Dots, printers, Privacy, Reality Winner, robot, Robot Vacuum, robots, security, surveillance, technology, tracking, Tracking Dots, Vacuum, Weekly Edition
In episode 351, hosts Tom and Scott explore an unusual incident where robot vacuums were hacked to shout obscenities, exposing significant IoT security issues. The discussion includes the mechanics of the Bluetooth ...

Emergency Satellite Messaging, Stagnation in User Cybersecurity Habits
Tom Eston | | Amateur Radio, android, Apple, Baofeng, Cyber Security, cyber threat, Cybersecurity, cybersecurity awareness, Data Privacy, Digital Privacy, disaster, Episodes, facebook, HAM Radio, hurricane, Information Security, Infosec, ios, linkedin, password manager, passwords, Podcast, Podcasts, Privacy, Radio, satellite, Satellite Communication, Satellites, security, Security Awareness, social media, SpaceX, Starlink, technology, TMobile, Weekly Edition
In the milestone 350th episode of the Shared Security Podcast, the hosts reflect on 15 years of podcasting, and the podcast’s evolution from its beginnings in 2009. They discuss the impact of ...

Kia Security Flaw Exposed, NIST’s New Password Guidelines
Tom Eston | | Authentication, biometrics, cars, Connected Cars, Cyber Security, cyber threat, Cybersecurity, Data Privacy, Digital Privacy, Episodes, Hacking, Information Security, Infosec, Kia, MFA, Multi-Factor Authentication, NIST, Password, password complexity, Password Guidelines, Password Policy, Password reset, Password Resets, passwords, Podcast, Podcasts, Privacy, security, technology, web application, web application vulnerability, Weekly Edition
In this episode, the hosts discuss a significant vulnerability found in Kia’s web portal that allows remote control of various car features via their app, potentially enabling unauthorized unlocking and tracking. The ...
Unmasking the Hack-to-Trade Scheme: A Cautionary Tale for Executives
Chris Pierson | | Digital Executive Protection, Executive Online Protection, Fraud, passwords, Scams
In a shocking revelation, federal prosecutors have charged UK national Robert B. Westbrook with orchestrating a sophisticated “hack-to-trade” scheme that netted him millions of dollars. By exploiting vulnerabilities in Office365, Westbrook allegedly ...
NIST Recommends Some Common-Sense Password Rules
NIST’s second draft of its “SP 800-63-4“—its digital identify guidelines—finally contains some really good rules about passwords: The following requirements apply to passwords: lVerifiers and CSPs SHALL require passwords to be a ...