Friday Squid Blogging: Jumbo Flying Squid in the South Pacific
The population needs better conservation.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
The population needs better conservation.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Clive Robinson • March 20, 2026 8:37 PM
@ ALL,
Final report on SW Europe blackout.
I know this is likely to be of limited interest to many. But it is an aspect of security that is going to become more relevant as,
1, AI data centers stress the grid.
2, Solar/Wind multipoint feed-in to the grid increases.
“28 April 2025 Blackout
The final report of the Expert Panel on the 28 April 2025 blackout in continental Spain and Portugal identifies the causes of the blackout and outlines recommendations to strengthen the resilience of Europe’s interconnected electricity system.“
https://www.entsoe.eu/publications/blackout/28-april-2025-iberian-blackout/
Clive Robinson • March 20, 2026 9:55 PM
@ All US tax payers.
US Tax Software has a serious backdoor in it that is not being addressed or fixed.
Yup as it’s getting toward that time when you have to do your tax a lot of US taxpayers world wide turn toward software for assistance.
Well it turns out one supplier is sending it out with a significant back door they are not addressing…
Worse they have included the private key so anyone can use the back door to do things you would rather they could not[1].
The person who found it says of it,
H&R Block tax software installs a TLS backdoor
“here in the US because tax season is coming up and some of you may be using H&R Block Business 2025. I discovered that the software installs a root CA named “WK ATX ServerHost 2024” (expiry 2049) into your local machine trusted root certificate store. They also helpfully include the private key to this certificate in a DLL file. This certificate does not identify itself as “H&R Block” anywhere and does not get uninstalled when you uninstall the software.
I’ve been able to successfully use this root CA + mitmproxy to manipulate TLS traffic on a brand new virtual machine on the same network with a DNS spoofing attack.”
Read the rest at,
https://news.ycombinator.com/item?id=47457162
[1] This sort of backdoor is why I talk about using two computers that are “suitably gapped” with,
1, One used to do Private things and never gets connected to any external communications.
2, The second being used to connect to external communications but is never used for Private things.
This way such “back doors” can not be reached or (ab)used.
Subscribe to comments on this entry
Sidebar photo of Bruce Schneier by Joe MacInnis.
Anonymous • March 20, 2026 5:27 PM
Squids are important