Going back as far as the 2004 release of Windows XP SP2, Windows has offered various GUIs to help users understand the security state of their PC. In modern Windows 10 and Windows 11, this graphical user interface is called the “Windows Security Center/App“. The Windows Security App (WSA) is a surface upon which WindowsContinue reading “The Windows Security App”
Category Archives: security
Attack Technique: AI Clones
Attackers are adept at using new technologies to enhance their attacks. Earlier this afternoon, for example, I got call from “American Express” suggesting that I needed to “verify a transaction.” The caller used a robotic voice similar to the one used by American Express’ automated systems, and only obvious signals that it was a scamContinue reading “Attack Technique: AI Clones”
Web Security is Too Hard
It started innocently enough. I saw a tweet about a new product offering from one of my favorite companies, Cloudflare. Neat! I clicked through to the site and there it is: And huzzah!, my preferred handle, @ericlaw is still available. I’d better hurry to claim it before someone else gets it! Since I’m already aContinue reading “Web Security is Too Hard”
Authenticode and UAC
When a user attempts to run a file with elevated privilege, Windows will show a User Account Control elevation prompt that asks whether the user trusts the file to run. For a regular file, the user will see a prompt like this: For a file signed by a certificate in the Untrusted Certificates store, elevationContinue reading “Authenticode and UAC”
Attack Techniques: Fake Captive Portals
When a device first joins a network, the upstream network hardware has full control over its traffic and can allow/block any packets sent from the device from reaching the Internet. Many public networks (typically Wi-Fi, but sometimes wired), located in hotels, coffee shops, mass transit, schools, etc. require that the user accept Terms of UseContinue reading “Attack Techniques: Fake Captive Portals”