Google launches leaked-password checker, will bake it into Chrome in December

Credit to Author: Gregg Keizer| Date: Fri, 04 Oct 2019 04:06:00 -0700

Google has launched a web-based hacked-password checker, part of its efforts to bake an alert system into Chrome.

Called “Password Checker,” the service examines the username-password combinations stored in Chrome’s own password manager and reports back on those authentication pairings that have been exposed in publicly-known data breaches.

The web version can be found at passwords.google.com<>, the umbrella site for Chrome users who run the browser after logging in with their Google account, then use that to synchronize data – including passwords – between copies of Chrome on different devices.

To read this article in full, please click here

Read more

Throwback Thursday: Everybody gets an F

Credit to Author: Sharky| Date: Thu, 03 Oct 2019 03:00:00 -0700

As the IT communications manager at this university, pilot fish is the person who sends out memos about IT policy to users. And he does just that when a phishing email starts circulating on campus.

Never send your user name and password to anyone via email, he warns them, and to give them an example of what to look out for, he pastes in the text of the phishing attempt.

Within minutes, his inbox is flooded with responses from students sending him their campus passwords, their Gmail passwords, their Yahoo passwords and more.

Sharky is looking for fish, not phish. Send me your true tales of IT life at sharky@computerworld.com. You can also subscribe to the Daily Shark Newsletter.

To read this article in full, please click here

Read more

Time to install Microsoft's mainstream September patches – and avoid the dregs

Credit to Author: Woody Leonhard| Date: Wed, 02 Oct 2019 11:00:00 -0700

Read more

Post-retirement Windows 7 patches: Not just for the big dogs now

Credit to Author: Gregg Keizer| Date: Wed, 02 Oct 2019 05:29:00 -0700

Microsoft on Tuesday changed its plans for selling Windows 7 post-retirement support, saying that it will offer patches-for-a-price to any business, no matter how small, that’s willing to pay.

“Through January 2023, we will extend the availability of paid Windows 7 Extended Security Updates (ESU) to businesses of all sizes,” Jared Spataro, an executive in the Microsoft 365 group, wrote in a post to a company blog.

Microsoft had announced the ESU program in September 2018. Since April, when the company started selling ESU, only customers with volume licensing deals for Windows 7 Enterprise or Windows 10 Professional have been eligible to purchase the support add-on.

To read this article in full, please click here

Read more

Microsoft Patch Alert: Botched IE zero-day patch leaves cognoscenti fuming

Credit to Author: Woody Leonhard| Date: Mon, 30 Sep 2019 10:16:00 -0700

So you think Windows 10 patching is getting better? Not if this month’s Keystone Kops reenactment is an indicator.

In a fervent frenzy, well-meaning but ill-informed bloggers, international news outlets, even little TV stations, enjoyed a hearty round of “The Windows sky is falling!” right after the local weather. It wasn’t. It isn’t – no matter what you may have read or heard.

The fickle finger of zero-day fate

Microsoft has a special way of telling folks how important its patches might be. Every individual security hole, listed by its CVE number, has an “Exploitability Assessment” consisting of:

To read this article in full, please click here

Read more

Cheers!

Credit to Author: Sharky| Date: Fri, 27 Sep 2019 03:00:00 -0700

Pilot fish has a sweet deal with one of the owners of a local drinking establishment he frequents. The bar owner is in the habit of using the main office computer for what fish calls “nonstandard business activity.” What does that mean? Suffice to say that that computer gets infected by viruses a couple of times a year. Bar owner would then call fish and ask for expedited service.

Fish stops by on his way home, grabs the tower, and disinfects the hard drive at home. He usually returns the system to the bar late that night or on his way to work the next morning.

Either way, the next time he stops by for an adult beverage, he receives a gift card that usually covers several rounds.

To read this article in full, please click here

Read more

What do we know about the big, scary, exploited, emergency-patched IE security hole CVE-2019-1367?

Credit to Author: Woody Leonhard| Date: Wed, 25 Sep 2019 07:29:00 -0700

Read more

Apple just made Safari a better fit for the enterprise

Credit to Author: Jonny Evans| Date: Wed, 25 Sep 2019 07:15:00 -0700

Enterprise users can now wrap a new layer of security around their web services, thanks to Apple’s introduction of support for USB security keys in Safari 13.0.1.

Enterprise class security

Dongles aren’t a terribly convenient security protection for most people, but government, military and regulated industries are always searching out new ways to secure themselves, and their data.

FIDO2-compliant USB security keys – such as those made by Yubico – add a layer of security to the verification process:

To read this article in full, please click here

Read more