Skype is adding an option for encrypted conversations

Soon, your chats on Skype can be just as secure as conversations on Signal, the service used by US Senators. Microsoft is integrating the open source Signal protocol, used by WhatsApp, Google, Facebook and Signal itself, into test versions of Skype as ‘ Private Conversations ‘ for end-to-end encrypted communications. There are a few restrictions: You can’t turn an existing chat into a Private Conversation, and must start each one by sending a request to one of your contacts. They don’t carry over between devices, so if you switch platforms, you’ll have to send a whole new request. And finally, Private Conversations are currently available in preview only for Skype Insiders, the service’s beta tester community. Via: Windows Central Source: Signal blog , Skype: Private Conversations

Link:
Skype is adding an option for encrypted conversations

Millions of high-security crypto keys crippled by newly discovered flaw

Enlarge / 750,000 Estonian cards that look like this use a 2048-bit RSA key that can be factored in a matter of days. (credit: Steve Jurvetson ) A crippling flaw in a widely used code library has fatally undermined the security of millions of encryption keys used in some of the highest-stakes settings, including national identity cards, software- and application-signing, and trusted platform modules protecting government and corporate computers. The weakness allows attackers to calculate the private portion of any vulnerable key using nothing more than the corresponding public portion. Hackers can then use the private key to impersonate key owners, decrypt sensitive data, sneak malicious code into digitally signed software, and bypass protections that prevent accessing or tampering with stolen PCs. The five-year-old flaw is also troubling because it’s located in code that complies with two internationally recognized security certification standards that are binding on many governments, contractors, and companies around the world. The code library was developed by German chipmaker Infineon and has been generating weak keys since 2012 at the latest. The flaw is the one Estonia’s government obliquely referred to last month when it warned that 750,000 digital IDs issued since 2014 were vulnerable to attack . Estonian officials said they were closing the ID card public key database to prevent abuse. Last week, Microsoft , Google , and Infineon all warned how the weakness can impair the protections built into TPM products that ironically enough are designed to give an additional measure of security to high-target individuals and organizations. Read 18 remaining paragraphs | Comments

Read the original post:
Millions of high-security crypto keys crippled by newly discovered flaw

IRS hands fraud prevention contract to Equifax despite massive hack

You’d think that government agencies would be reticent to work with Equifax given that it just exposed the private info of more than 145 million people through a preventable hack , but a massive data breach apparently isn’t enough of a deterrent. The Internal Revenue Service recently awarded Equifax a fraud prevention contract that will have it verifying taxpayer identities. And crucially, it was a no-bid, “sole source” contract — Equifax was deemed the only company capable of fulfilling demand. In practice, officials didn’t have much of a choice. Credit reporting in the US is dominated by three large companies (Equifax, Experian and TransUnion), and Equifax is arguably the powerhouse of the bunch. However, that only underscores the problem here: the IRS had to trust a crucial anti-fraud system to a company that not only had sloppy online security practices, but has been reluctant to take full responsibility for its mistakes. There’s a real chance that the hack will get Equifax to clean up its act in time to improve its handling of IRS data. We wouldn’t count on it, though, and there’s always the possibility that the IRS will fall afoul of the kind of data breach that prompted this anti-fraud contract in the first place. Via: Politico Source: FedBizOpps.gov

Follow this link:
IRS hands fraud prevention contract to Equifax despite massive hack