----------------------------------------------------------------------
Message-ID: <20190707032709.GA7303@telecom.csail.mit.edu>
Date: Sun, 7 Jul 2019 03:27:09 +0000
From: Bill Horne <bill@horneQRM.net>
Subject: July 4 ALERT: Some CenturyLink customers unable to reach
911
by Jennifer Elliott
BUTTE FALLS, Ore. - More than 150 CenturyLink customers in the Butte
Falls area [were] unable to reach 911 from their landline telephones
Thursday night.
According to Emergency Communications of Southern Oregon, CenturyLink
technicians are responding, but there is not an estimated time for
restoration of services.
https://fox26medford.com/alert-some-centurylink-customers-unable-to-reach-911/
--
Bill Horne
(Remove QRM from my email address to write to me directly)
------------------------------
Message-ID: <0EB80317-A6E9-4BB7-9D12-C6811FCEA6F6@roscom.com>
Date: 5 Jul 2019 12:06:38 -0400
From: "Monty Solomon" <monty@roscom.com>
Subject: 7-Eleven Japanese customers lose $500,000 due to mobile =
app
flaw
Hackers exploit 7-Eleven's poorly designed password reset function to
make unwanted charges on 900 customers' accounts.
By Catalin Cimpanu
Approximately 900 customers of 7-Eleven Japan have lost a collective
of =EF=BF=BD=EF=BF=BD55 million ($510,000) after hackers hijacked their 7pa=
y app
accounts and made illegal charges in their names.
The 7pay mobile app was designed to show a barcode on the phone's
screen when customers reach the 7-Eleven cashier counters. The cashier
scans the barcode, and the bought goods are charged to the user's 7pay
app and the customer's credit or debit cards that have been saved in
the account.
https://www.zdnet.com/article/7-eleven-japanese-customers-lose-500000-due-to-mobile-app-flaw/
------------------------------
Message-ID: <6BD42656-499A-4406-9552-FC0F0DE37A19@roscom.com>
Date: 5 Jul 2019 12:10:38 -0400
From: Monty Solomon <monty@roscom.com>
Subject: Someone Is Spamming and Breaking a Core Component of PGP=
's
Ecosystem
Someone Is Spamming and Breaking a Core Component of PGP's Ecosystem
A new wave of spamming attacks on a core component of PGP's ecosystem has
highlighted a fundamental weakness in the whole ecosystem.
https://www.vice.com/en_us/article/8xzj45/someone-is-spamming-and-breaking-a-core-component-of-pgps-ecosystem
***** Moderator's Note *****
I'm a proponent of end-to-end encryption for both email and phone
calls, and PGP is a key part of that capability. This attack might be
from a government actor or a large NGO, depending on the number of
keys that were used: creating them is "computationally intensive," and
unless the attacks were conducted with a very limited set of keys,
only major players have the computing horsepower.
Bill Horne
Moderator
------------------------------
*********************************************
End of telecom Digest Sun, 07 Jul 2019