How Not To Do Security

Tuesday, March 20th, 2007

Poor security questions

Our bank is a small local bank. In general they’ve been very good to deal with. They offer a web interface through which we can access our account, pay bills, etc. The web interface is nothing special… it works, it has a couple of quirks and unnecessary page reloads.

Recently they decided they needed to beef up security. I ran into this on my own personal account a while back, and was unhappy about it. Now they’ve done it to our business account.

The security mechanism consists of them asking three questions and requiring answers to them. Then, in the future if they decide that you might be accessing the account from a different computer from the one you usually do, they may ask the questions and block your access to the account if you can’t answer them.
(more…)

Wordpress 2.1.1 Major Security Issue

Sunday, March 4th, 2007

 2006 07 Wordpress Tattoo Logo

The Wordpress 2.1.1 distribution was cracked recently and a couple of files were tampered with. The malicious version was only online for a few days; the original version was safe. But if you’ve installed and are running Wordpress 2.1.1, the Wordpress maintainers strongly advise that you update to version 2.1.2 instead. Check the link below for their report.

The CVS distribution is intact, so if you installed from it you’re safe.

(more…)

Sponsored Links