article thumbnail

Tracking World Leaders Using Strava

Schneier on Security

Way back in 2018, people noticed that you could find secret military bases using data published by the Strava fitness app. Soldiers and other military personal were using them to track their runs, and you could look at the public data and find places where there should be no people running. Six years later, the problem remains.

article thumbnail

Zales.com Leaked Customer Data, Just Like Sister Firms Jared, Kay Jewelers Did in 2018

Krebs on Security

In December 2018, bling vendor Signet Jewelers fixed a weakness in their Kay Jewelers and Jared websites that exposed the order information for all of their online customers. This week, Signet subsidiary Zales.com updated its website to remediate a nearly identical customer data exposure.

Scams 298
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

MasterCard DNS Error Went Unnoticed for Years

Krebs on Security

Passive DNS records from DomainTools.com show that between 2016 and 2018 the domain was connected to an Internet server in Germany, and that the domain was left to expire in 2018. The Russian search giant Yandex reports this user account belongs to an “Ivan I.” ” from Moscow. ne ” instead of “ awsdns-06.net.”

DNS 361
article thumbnail

Gavelblocken, 2018

Adam Shostack

The 2018 Gavle Goat is up and tweeting at @gavelebocken. The Gavle Goat is up. Previously.

130
130
article thumbnail

Threat Modeling Thursday: 2018

Adam Shostack

What would you like me to cover in my Blackhat talk, " Threat Modeling in 2018 ?" So this week's threat model Thursday is simply two requests: What would you like to see in the series? Attacks always get better, and that means your threat modeling needs to evolve.

Media 130
article thumbnail

Threat Modeling in 2018: Attacks, Impacts and Other Updates

Adam Shostack

Check out my talk from Blackhat 2018 Blackhat has released all the 2018 US conference videos. My threat modeling in 2018 video is, of course, amongst them. Slides are linked here.

130
130
article thumbnail

Threat Modeling Thursday: 2018

Adam Shostack

STRIDE Machine Learning Conflict And of course, because it's 2018, there's cat videos and emoji to augment logic. The current core outline is: What are we working on The fast moving world of cyber The agile world Models are scary What can go wrong? Threats evolve! Yeah, that's the word. Wednesday, August 8 at 2:40 PM. *

130
130