The Windows Security App

Going back as far as the 2004 release of Windows XP SP2, Windows has offered various GUIs to help users understand the security state of their PC. In modern Windows 10 and Windows 11, this graphical user interface is called the “Windows Security Center/App“. The Windows Security App (WSA) is a surface upon which WindowsContinue reading “The Windows Security App”

Attack Technique: AI Clones

Attackers are adept at using new technologies to enhance their attacks. Earlier this afternoon, for example, I got call from “American Express” suggesting that I needed to “verify a transaction.” The caller used a robotic voice similar to the one used by American Express’ automated systems, and only obvious signals that it was a scamContinue reading “Attack Technique: AI Clones”

Web Security is Too Hard

It started innocently enough. I saw a tweet about a new product offering from one of my favorite companies, Cloudflare. Neat! I clicked through to the site and there it is: And huzzah!, my preferred handle, @ericlaw is still available. I’d better hurry to claim it before someone else gets it! Since I’m already aContinue reading “Web Security is Too Hard”

Attack Techniques: Fake Captive Portals

When a device first joins a network, the upstream network hardware has full control over its traffic and can allow/block any packets sent from the device from reaching the Internet. Many public networks (typically Wi-Fi, but sometimes wired), located in hotels, coffee shops, mass transit, schools, etc. require that the user accept Terms of UseContinue reading “Attack Techniques: Fake Captive Portals”