Cybersecurity & Privacy
The start of the end for Symantec cert trust on Google's Chrome
A little history Early 2017, a security researcher (Andrew Ayer from SSLMate) discovered that three certificate authorities (Symantec Trust Network, GeoTrust Inc., and Thawte Inc), owned by Symantec, had improperly issued 108 TLS certificates. It is important to understand that these improperly issued certificates would allow a threat actor to spoof or impersonate a website that was using HTTPS. 9 of these certificates were issued without the knowledge of the domain owners. 99 were issued without proper validation of domain ownership.
Was Google, Apple, Facebook & Microsoft traffic redirected to Russia?
TL;DR: Internet traffic to and from major tech companies (Apple, Facebook, Google, Microsoft, Twitch, NTT Communications and Riot Games) were redirected through a Russian provider Wednesday. This appears to have been a deliberate hijack and not an error. ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- BGP is a routing and reachability protocol used on internet backbones around the world. It is what allows carriers to find routing information between each other (in simple terms). 2 BGP monitoring services have reported short changes to the routing of key internet giants, and they do not believe this was a mistake.
How do I test the speed of my VPN service
How can you test the speed (performance) of my VPN service provider? I receive this question regularly, and I thought it was about time I wrote an article about it. When evaluating internet speed, there are dozens or hundreds of different parameters that can influence your final score. In the world of VPN, these may include: The distance between you and the VPN server - even though most of your traffic is flowing at the speed of light, users have become accustomed to super speedy internet and even the slightest delay is noticed.
How do I test my VPN to determine if it is leaking?
When something leaks, it's usually bad news. A leaking pipe in the kitchen or a leaking radiator. The same principle applies to your VPN. When a poorly designed VPN fails and leaks your data, that's the start of a bad day. Unfortunately, there is no visible indication that your VPN is leaking. Obviously, well-designed VPN services do not leak, my favourites being: VyprVPN Review Honest review of the ProtonVPN service Honest review of the Tunnelbear VPN service When looking for VPN leaks, we typically evaluate these angles:
AI.Type Android Keyboard leaks data from 31M users
ZDNet got the scoop on this significant leak. AI.type, a third-party keyboard replacement for Android has leaked data for its 31 million users online. How did this happen? A database administrator didn't secure the database. Anyone with basic skills could access and query the unprotected database and "have fun" with the 577 GB of data it contained. What type of data leaked? The leak includes fun elements like name, email address, precise user geolocation data, city and country. Researchers have also found [that some records contain] phone numbers, IP addresses dates of birth, gender, etc.
Trick to get a VPN Unlimited lifetime account for $18
I've written about the VPN Unlimited service before, you should go read the review. If you check out the VPN Unlimited purchase page, you will see that they are running a promo and selling it for $149.99. Normally StackSocial sells this same plan for $49.99 but wait ... <img src="https://ekiledjian2.micro.blog/uploads/2025/f39a0c5db6.jpg" alt=""> They are currently running a promo and have marked it down to $29.99, but wait ... <img src="https://ekiledjian2.micro.blog/uploads/2025/005bb5dc17.jpg" alt=""> If you add it to your cart and use the code CYBER40 at checkout, the price drops to $18.
Improve your internet security right now, easily and for free
Quad9 is a new DNS service launched by a non-profit consortium (founding members are IBM Security, Packet Clearing House & Global Cyber Alliance). The promise of the Quad9 DNS service is good security using the knowledge of some of the world's leading security research firms, by merely changing your default DNS server and ALL for free. The service is (not so creatively) called Quad9 because the DNS address is 9.9.9.9 Is the Quad9 service fast? I used the free DNS Benchmark tool by Steve Gibson with connections from Canada, the USA, the UK and Switzerland.
How to protect your Bitcoin from theft
Bitcoin is all the rage, and everyone is talking about it. Any discussion or write up about Bitcoin usually starts with the fact that is it a decentralized digital currency. Decentralized means that no government or company controls it and it also means each participant is on his/her own when it comes to protecting their Bitcoin investment. With US fiat currency saved in a bank, you have a high level of confidence that the money will be there in a day, week, month or a year.
OPSEC - Introduction to Malware
What is malware Malware is shorthand for Malicious Software and has been around almost from the start of computing. Its main purpose is to harm the computer or the user. Malware has been known to steal login credentials, monitor the user, tamper with information (breaking integrity), steal information or just making the system unusable. Malware can be designed by a nefarious teenager in his mother's basement looking to make a name for himself or by a state-sponsored threat actor against activists or journalists.
ChromeOS 62 rolling out now with Krack patch
Google started rolling out Chrome 62 to Windows and Mac clients about a week ago and now most Chromebook users should have received the update. For those that haven't realized it, Chromebook updates typically lag behind their Windows/Mac counterpart by about a week. <img src="https://ekiledjian2.micro.blog/uploads/2025/5dc282352a.jpg" alt=""> What does ChromeOS 62 bring? ChromeOS 62 brings an improved file manager, improved OS notifications, and most importantly vulnerability fixes (including the famous KRACK vulnerability). Pressing and holding a file in the file manager now allows you to select a file (or more) instead of bringing up the right-click menu.