Cryptography


RSA Hack Yields SecurID Secrets

RSA Security, a division of EMC Corp. has admitted that it was the victim of a sophisticated attack that resulted in the theft of secrets related to its SecurID two-factor authentication product.

Device-Level Encryption Comes to Android

As attacks on mobile devices such as iPhones, iPads, Android phones and tablets have surged in recent months, security researchers and customers have continued to look for ways to lock down their devices and protect the data they store on them. Whisper Systems has jumped into the fray with WhisperCore, a new device-level encryption application for Android.

Twitter Gives Users Option to Turn On HTTPS by Default

Twitter has changed the way that users access the company’s main site, now giving them the option to enable HTTPS by default, forcing a secure connection for most interaction with the service. However, the change does not apply to all of the popular apps users employ to access Twitter on smartphones and other devices.


SAN FRANCISCO–Many carriers and mobile providers are touting
smartphones as the future of secure mobile payment systems, enabling
users to pay for purchases with an app on their phones, and this already
reality in many parts of Asia and Europe. However, researchers have
discovered that some of the more popular smartphone platforms leak
sensitive data during these transactions that could allow criminals to
spoof a victim’s phone and make purchases with the victim’s account.

Google has introduced a new two-step authentication feature for Gmail users that it says will significantly increase the security of the free mail service. The system enables users to set up a method for obtaining a secret code that will be required, along with a password, to access a Gmail account.