Multiple Google Services Experience 90-Minute Disruption
Reports on Google's App Status dashboard show the disruption lasted for about 90 minutes before the company was able to restore normal service levels.
Last September, for instance, Amazon Web Services, which is regarded as having one of the best cloud service uptimes in the industry, experienced problems with its DynamoDB database service. The disruption lasted for 5 hours and seriously affected services at Netflix, Viber, Reddit and multiple other sites.
Azure customers had to suffer through nearly 36 hours of intermittent service before Microsoft was able to address the issue.
Interview: John Matherly on Check Point Blacklisting Shodan
Check Point has completely ignored the fact that Shodan is also used by the good guys, and that tools similar to Shodan have existed long before the service, most of which were developed by cybercrime groups.
Instead of focusing on the real threat, Check Point has decided to throw an umbrella ban on Shodan, with no guarantee that threat actors won't stop scanning the Web with other similar search engines or their own scanners.
Netflix’s fight against VPNs begins, but it’s doomed to fail. And Netflix knows it.
Netflix promised it would begin targeting those who use proxies and VPNs to watch geo-restricted content, and now it seems the company is acting on that promise.
Netflix is now available more or less globally, in almost 200 countries, but the fragmented nature of global licensing means that TV shows and movies on Netflix vary from region to region.
Netflix cracks down on proxy streaming
Due to licensing agreements, Netflix content varies between countries - many users have a virtual private network (VPN) or other proxy to get round this.
But some countries have more content than others - for example, the Australian Netflix catalogue has only about 10% of the content available to its US subscribers.
Subscribers that currently use proxies to view content outside their countries will only be able to access the service in their own countries in the coming week, the company said.
Mozilla Re-enables SHA-1 Certificate Support in Firefox
In an unexpected move, when browser vendor Mozilla released Firefox 43.0.4 on Jan. 6, it re-enabled support for newly issued SHA-1(Secure Hash Algorithm 1) security certificates. Mozilla had previously set Firefox to reject new SHA-1 signed Secure Sockets Layer/Transport Layer Security certificates as of Jan. 1.
"When their users can't access Websites, they simply switch browsers, so sticking with this policy does more harm than good to both Mozilla and their ability to raise the bar on security," he said. "I don't think Mozilla is giving up on their position, just being practical."
Internet Freedom Is Actively Dissolving in America
Broadband access is declining, data caps are becoming commonplace, surveillance is increasing, and encryption is under attack.
Opposition to citizen access to encryption has become so pervasive within the government that Hillary Clinton actively campaigned at Saturday’s debate for a “Manhattan-like project” to break encryption.
And so many, many Americans may soon be left with an insecure, surveilled, and capped internet connection dominated by broadband and cellular providers that funnel traffic to the companies they’ve made deals with.
Is U.S. Critical Infrastructure Under Attack?
A pair of recent reports allege that foreign attackers have been able to infiltrate U.S. critical infrastructure. A Wall Street Journal report alleged that Iranian hackers were able to infiltrate the operation of a dam not far from New York City. An Associated Press report alleged even more widespread risks to the U.S. power grid, in particular an attack involving power producer Calpine.
The idea that industrial control systems aren't yet fully hardened for the modern world of cyber-attacks is shared by Lila Kee, chief product officer and vice president of business development at GlobalSign
13 Million MacKeeper Users Exposed
The makers of MacKeeper — a much-maligned software utility many consider to be little more than scareware that targets Mac users — have acknowledged a breach that exposed the usernames, passwords and other information on more than 13 million customers and, er…users.
Vickery said he reached out the company, which responded quickly by shuttering public access to its user database, and publicly thanking him for reporting it.
Vickery said he was able to connect to the database that Shodan turned up for him just by cutting and pasting the information into a commercial tool built to browse Mongo databases.
Gmail Now Offers Alerts if Sensitive Data Is Being Sent
Gmail DLP works by allowing organizations to set policies that flag messages which include sensitive information such as Social Security or credit card numbers, wrote Frey. Such a policy might say that sales department workers should not share customer credit card information with vendors, for example.
"These checks don't just apply to email text, but also to content inside common attachment types―such as documents, presentations, and spreadsheets," Frey wrote. "And admins can also create custom rules with keywords and regular expressions."
Kazakhstan Decides To Break The Internet, Wage All Out War On Encryption
A new law takes effect in the new year that will require all citizens of the country to install a national, government-mandated security certificate allowing the interception of all encrypted citizen communications. In short, the country has decided that it would be a downright nifty idea to break HTTPS and SSL, essentially launching a "man in the middle" attack on every resident of the country.
Last month, Human Rights Watch described Kazakhstan as an authoritarian dictatorship with "few tangible and meaningful human rights." Freedom House, meanwhile, ranks Kazakhstan poorly when it comes to Internet freedom.