Schneier on Security

Subscribe to Schneier on Security feed
2025-03-30T16:23:09Z
Updated: 11 hours 40 min ago

Spyware Maker NSO Group Found Liable for Hacking WhatsApp

Tue, 12/24/2024 - 7:04am

A judge has found that NSO Group, maker of the Pegasus spyware, has violated the US Computer Fraud and Abuse Act by hacking WhatsApp in order to spy on people using it.

Jon Penney and I wrote a legal paper on the case.

Criminal Complaint against LockBit Ransomware Writer

Mon, 12/23/2024 - 12:04pm

The Justice Department has published the criminal complaint against Dmitry Khoroshev, for building and maintaining the LockBit ransomware.

Friday Squid Blogging: Squid Sticker

Fri, 12/20/2024 - 5:00pm

A sticker for your water bottle.

Blog moderation policy.

Mailbox Insecurity

Thu, 12/19/2024 - 10:24am

It turns out that all cluster mailboxes in the Denver area have the same master key. So if someone robs a postal carrier, they can open any mailbox.

I get that a single master key makes the whole system easier, but it’s very fragile security.

New Advances in the Understanding of Prime Numbers

Wed, 12/18/2024 - 11:40am

Really interesting research into the structure of prime numbers. Not immediately related to the cryptanalysis of prime-number-based public-key algorithms, but every little bit matters.

Hacking Digital License Plates

Tue, 12/17/2024 - 12:04pm

Not everything needs to be digital and “smart.” License plates, for example:

Josep Rodriguez, a researcher at security firm IOActive, has revealed a technique to “jailbreak” digital license plates sold by Reviver, the leading vendor of those plates in the US with 65,000 plates already sold. By removing a sticker on the back of the plate and attaching a cable to its internal connectors, he’s able to rewrite a Reviver plate’s firmware in a matter of minutes. Then, with that custom firmware installed, the jailbroken license plate can receive commands via Bluetooth from a smartphone app to instantly change its display to show any characters or image...

Short-Lived Certificates Coming to Let’s Encrypt

Mon, 12/16/2024 - 7:06am

Starting next year:

Our longstanding offering won’t fundamentally change next year, but we are going to introduce a new offering that’s a big shift from anything we’ve done before—short-lived certificates. Specifically, certificates with a lifetime of six days. This is a big upgrade for the security of the TLS ecosystem because it minimizes exposure time during a key compromise event.

Because we’ve done so much to encourage automation over the past decade, most of our subscribers aren’t going to have to do much in order to switch to shorter lived certificates. We, on the other hand, are going to have to think about the possibility that we will need to issue 20x as many certificates as we do now. It’s not inconceivable that at some point in our next decade we may need to be prepared to issue 100,000,000 certificates per day...

Upcoming Speaking Events

Sat, 12/14/2024 - 12:01pm

This is a current list of where and when I am scheduled to speak:

The list is maintained on this page.

Ultralytics Supply-Chain Attack

Fri, 12/13/2024 - 11:33am

Last week, we saw a supply-chain attack against the Ultralytics AI library on GitHub. A quick summary:

On December 4, a malicious version 8.3.41 of the popular AI library ultralytics ­—which has almost 60 million downloads—was published to the Python Package Index (PyPI) package repository. The package contained downloader code that was downloading the XMRig coinminer. The compromise of the project’s build environment was achieved by exploiting a known and previously reported GitHub Actions script injection.

Lots more details at that link. Also ...

Jailbreaking LLM-Controlled Robots

Wed, 12/11/2024 - 7:02am

Surprising no one, it’s easy to trick an LLM-controlled robot into ignoring its safety instructions.

Full-Face Masks to Frustrate Identification

Tue, 12/10/2024 - 7:06am

This is going to be interesting.

It’s a video of someone trying on a variety of printed full-face masks. They won’t fool anyone for long, but will survive casual scrutiny. And they’re cheap and easy to swap.

Pages