Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, 17 May 2011

Dropbox drops the lies.

Dropbox has been found to publish misleading info regarding the security of the files you upload to the service. Dropbox has earlier always stated that the files the users synchronize are strongly encrypted and that not even employees can access the files.

But. The PhD and blogger Christopher Soghoian recently discovered that Dropbox uses a function which control that the files you upload doesn't already exist, and therefore saves lot's and lot's of space.

He then questioned how it could work if Dropbox couldn't access the users failes, he got the answer:

Employees at Dropbox doesn't have any access to the users files. They can only be unlocked with the users mail and password.

Only a few day after Christopher recieved the mail, Dropbox changed the information on their website to:

The ones hired at Dropbox are not allowed to view the information you upload to Dropbox. We have a small staff of employees who must have access to your information because of legal reasons and only happens in very rare cases.

Another week passed and Dropbox edited the information in their User Agreement. It now said:

Under certain circumstances the users information may be shared with a thirdhand part if we feel that are good reasons to do so. It can involve the following situations; a) to maintain laws; b) to protect a person from harm or death; c) to prevent frauds or misuse of Dropboxs services; d) to protect Dropbox property.

Simply said, Dropbox can decrypt your files and share them with a thirdhand party if they feel it fitting. Dropbox doesn't specifie if they only share with the police or if they share with other authorites or corporations.

Christopher has filed a 16 pages long complaint to the American Chamber of Commerce. He want Dropbox to admitt that the users file is not safe like they've said before, and that Dropbox send an email to the 25 million users with an excuse which cleary explains this.

Saturday, 7 May 2011

Better safe than Sony

An american investigation has revealed that Sony knew about the securityflaws -and chose not to fix them.

Apparently security experts discovered several forumtopics which discussed PSN's lacking security.
These forums showed that PSN used Apache Web Server software, which either was patched or had firewalls installed, and the forums was monitored by Sonys employees for two to three months without taking any actions.

The investigators even saw posts on criminal forums which said that the value on information from Sony had sunk because it was too easy to obtain.

Tuesday, 3 May 2011

Playstation h4ck3d!!! -Again

It's almost two weeks since Sony was hacked and perhaps millions of peoples information was leaked. Now Sony is hacked again.

It wasn't until this weekend that Sony held a press conference and apoligized for the security breach.
Kazuo Hirai said that it is not clear if the users credit card information is endangered but as much as ten million players credit cards may be in danger. He also said that they are rebuilding Playstation 3's securitysystem with more firewalls, better and faster ways to encrypt data and discover hackerattacks.

At monday, we got to know that Sony had been hacked again, this time Sony Online Entertainment was the target. Station.com was shut down and up to 24 million users can be affected.
Sony says that the hackers managed to lay their hands on old databases from 2007 where almost 13 000 users credit card information was stored. These accounts are from Holland, Germany, Austria and Spain, at this moment it's unsure if the main database is affected.

As a bribe, Sony is gifting "special selected content" which can be downloaded for free. Also a free month of Playstation Plus will be awarded.