Twitter invites us to say goodbye to passwords, use Digits instead

Twitter’s new credentials handling scheme is called Digits, and it’s hoping that mobile app developers use it to enable their users to sign in with their phone numbers as identifiers, along with one-time passwords SMSed to the phones.

How to kill a troll

A new Pew study confirms what we already know: online harassment is a widespread disease afflicting the internet. Ignoring trolls and hoping they’ll go away is actually quite effective, survey respondents said. Then again, how about fighting back, instead? Change is possible, be it enabled by troll-blocking software, societal shift that sees trolling evolve into a stigma, or, if all else fails, calling their mothers.

Google goes beyond two-step verification with new USB Security Key

Google’s adding support for a physical USB second factor that will first verify the login site as being a true Google website, not a fake site pretending to be Google, before it hands over a cryptographic signature.

SSCC 170 – Is the best time to shop at a store right after it has a breach? [PODCAST]

Here’s the latest episode of our weekly security podcast. Join Sophos experts Chester Wisniewski, John Shier and Paul Ducklin as they turn news into advice…

Is your phone line a ‘6-figure liability waiting to happen’?

Premium-rate service scams are sticking businesses – particularly small ones using local carriers – with outrageous phone bills, to the tune of $4.73 billion globally for 2013. Many businesses aren’t even aware that they can be stuck paying the bill (or fighting it in court).

Apple pushes out iOS 8.1 – kills the mobile POODLE and closes some, ahem, “backdoors”

The marquee vulnerablity fixed in iOS 8.1 is, as you might expect, POODLE. But there are other cryptographic fixes in iOS 8.1 that are equally important…because cryptography is notoriously hard to get right first time.