GoDaddy Has My Passwords?

Securi Security has a post over on their site that describes a harrowing situation with a virtual server that they rented from GoDaddy.

Securi is a bit paranoid (aren’t we all?) and moved secure shell from the default port of 22/tcp to an obscure port, and then placed a honeypot on 22/tcp (very smart).

One day he noticed these entries:

Jan 8

Forensics 1, Kingston 0

Have you ever wondered how two similarly branded MicroSD cards can differ greatly in reliability? The truth is… not all cards are created alike - even if they have the same brand on the card.
I came across this brilliant bit of persistent forensic …

AMEX and Passwords - Now With 128-bit Encryption!

Dear American Express,

Does anyone actually proofread responses that your company sends to clients that have security concerns?

Let’s look at what happened to Larry Seltzer of PC Magazine, shall we?

Larry complained that the password requirements for AMEX’s site are drastically insufficient. Aye, they are. Take a look for yourself:

Larry politely wrote th