Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, December 14, 2011

SECURITY FIRM SAYS GOOGLE WALLET NOT SECURE


Security firm ViaForensics recently said Google Wallet does not properly protect personal data, including credit card balance information, on a rooted Nexus S smartphone. Google Wallet is an NFC-based mobile payment system for Android that is accepted by a number of retailers in the United States. It is currently only officially available on the Nexus S and Nexus S 4G. “While Google Wallet does a decent job securing your full credit cards numbers, the amount of data that Google Wallet stores unencrypted on the device is significant,” ViaForensics said in a recent report. “Many consumers would not find it acceptable if people knew their credit card balance or limits.”

Friday, October 21, 2011

iPHONE 4S SHIPS WITH SIRI RELATED SECURITY THREAT


The popular virtual assistant feature on the iPhone 4S that allows users to schedule appointments, search the web, check the weather and more, may be a security threat to users who want to keep private information away from prying eyes — and ears. CNET discovered that Siri’s default security setting allows users to access the iPhone 4S feature even when the phone is locked. That means if you leave your iPhone in a cab, for example, a thief could easily access your address book, appointments and other personal information. Thankfully, there is an easy way to turn the setting off. Simply visit Settings and click General, then click Passcode Lock and toggle the option for “Allow access to Siri when locked with a passcode” to Off. The iPhone 4S will now require the the phone to be unlocked before it allows access to Siri.

Monday, October 3, 2011

HTC PHONES GIVE UP PERSONAL INFORMATION


A security hole found in some HTC Android phones could give apps with Internet permissions access to information like a user’s location and their text messages, Android Police reported today. The vulnerability is part of HTC’s Sense UI and affects a subset of the brand’s most popular phones, including the HTC Thunderbolt and the EVO 4G.

The affected HTC phones have an application package titled HTCLoggers.apk installed with root-level access. Apps with Internet permissions can access HTCLoggers.apk, which provides access to information like GPS data, WiFi network data, memory info, running processes, SMS data (including phone numbers and encoded text), and system logs that can include information like e-mail addresses and phone numbers. When called upon, the logging program opens a local port that will provide this data to any app that asks for it. Apps can send the data off to a remote server for safekeeping, as shown by a proof-of-concept app that Android Police researchers developed.

The authors note that the flaw can’t be fixed in the stock Sense UI without an update or patch from HTC. The owners of the relevant phones (a partial list: Thunderbolt, EVO 3D, EVO 4G, EVO Shift 4G) can delete HTCLoggers from their devices if they root the phones. While the report doesn’t note any concrete examples of nefarious use of the HTCLogger data, this is far more access than Google allows via Android by default—typically, the OS doesn’t let information of this type off a device without direct consent. HTC has made no official reply to inquiries from the researchers, and has not commented on this issue.

Friday, August 5, 2011

MICROSOFT OFFERING "MAD LOOT" TO ENCOURAGE SECURITY DEVELOPERS


Microsoft has announced they will pay developers for the next big idea in security. It's just not any amount of money though. According to the video, it is "mad loot and lots of it." Microsoft is betting the large first prize of $200,000 will entice developers to create the next big security offering. To win first prize the developers will have to create a "novel runtime mitigation technology designed to prevent the exploitation of memory safety vulnerabilities".

The second place finisher will receive $50,000 while third place finishers will get MSDN Universal subscriptions. Winners will be announced at the Blackhat security conference in 2012 and all participants have until April 2012 to submit their prototype and descriptions.

Click here to watch the video.

Wednesday, July 27, 2011

APPLE LAPTOPS CAN BE HACKED TO EXPLODE


Apple’s newer MacBook, MacBook Air and MacBook Pro notebooks have a security flaw that can allow hackers to remotely prevent the batteries from charging. Better yet, hackers can exploit the same flaw and remotely cause batteries to explode. Apple laptops’ new “smart” battery technology is intended to provide added control over power management, and it does just that. Unfortunately, it also gives hackers added control because the microcontroller chip that ships in recent Apple laptops can be accessed remotely using a default password shared by each and every notebook.

Charlie Miller, the security expert who discovered the vulnerability, plans to showcase the flaw next month at the Black Hat security conference. There, Miller will show that he is able to access the battery controller remotely and cause it to refuse a charge, or even heat up until it catches fire and explodes. “These batteries just aren’t designed with the idea that people will mess with them,” Miller told Forbes last week. “What I’m showing is that it’s possible to use them to do something really bad.” Thankfully, the security expert also intends to showcase a fix for the flaw, which Apple will hopefully implement as soon as possible.

Thursday, June 30, 2011

UNIVERSAL AND VIACOM HACKED LEAKING USERS PASSWORDS AND INFORMATION; ANTISEC CLAIMS RESPONSIBILITY


A hacking group named LulzSec made headlines recently for attacking high visibility targets, including Sony and the U.S. government. LulzSec announced earlier this week that it was stopping its operations, and rumor has it many of the members joined up with Anonymous’ “AntiSec” hacking group. Now that group is making its own headlines. On Tuesday AntiSec claimed responsibility for attacks against Universal and Viacom.

According to The Wall Street Journal, the hackers released personal data, including passwords, from the Universal Music Website. It also obtained and leaked information about Viacom’s network. It’s unclear how many users were affected by the security breach, although we hope to hear an official word from both firms in the near future.

Friday, June 17, 2011

MICROSOFT PASSING ON WEBGL CITING SECURITY CONCERNS

Microsoft has decided not to support the web-based 3D standard because it wouldn't be able to pass security muster. Highest on the list of concerns is that WebGL opens up a direct line from the internet to a system's GPU.

To make matters worse, holes and bugs may crop up that are platform or video card specific, turning attempts to plug holes in its defense into a game of whack-a-mole -- with many players of varying reliability. Lastly Microsoft, like security firm Context, has found current solutions for protecting against DoS attacks rather unsatisfying.

Lack of support in Internet Explorer won't necessarily kill WebGL and, as it matures, Microsoft may change its tune, but it's still a pretty big blow.

Tuesday, June 7, 2011

RSA ADMITS DATA STOLEN, OFFERS TO REPLACE TOKENS


RSA Security is offering to provide security monitoring or replace its well-known SecurID tokens—devices used by millions of corporate workers to securely log on to their computers—"for virtually every customer we have," the company's Chairman Art Coviello said in an interview.

In a letter to customers Monday, the EMC Corp. unit openly acknowledged for the first time that intruders had breached its security systems at defense contractor Lockheed Martin Corp. using data stolen from RSA.

Mr. Coviello didn't specify what happened to the tokens at Lockheed. But as a precaution, he said RSA will offer to replace nearly all tokens—millions of them used by government agencies and businesses ranging from Rolls Royce Motor Cars Ltd. to PokerStars.com.

Tuesday, May 24, 2011

SONY BMG GREECE HACKED


It's the security nightmare that just won't end, and right now there's got to be plenty of Sony executives beginning to wish someone would pinch them already. After taking quite a PR and financial beating over the PSN breach, now the Greek site of Sony BMG has been hacked and the account info of thousands of users has been posted online.

According to the Sophos blog Naked Security, the attack does not appear to have been particularly sophisticated and was carried out using an automated SQL injection tool that demands more patience than skill. While the data dump reveals the usernames, real names, and email addresses of registered SonyMusic.gr customers, other fields (including passwords and telephone numbers) are either empty or contain fake data, suggesting the hack was not entirely successful.

Thursday, May 19, 2011

GOOGLE CONFIRMS SECURITY FLAW, ROLLS OUT SERVER SIDE FIX


No Android security flaw is good news for Google, but the recently discovered ClientLogin issue that left the OS vulnerable to impersonation attacks is surely at least a bit more welcome than some of the alternatives. That's because the flaw can be fixed at the server-side level (rather than on millions of Android phones), and Google has now confirmed that a fix is rolling out today, although it may take a few more days for it to cover all users (there's no action required on your part).

The company's not quite out of the woods just yet, though -- while we've confirmed with Google that the fix addresses the issues with Calendar and Contacts, the problem with Picasa remains, and there's still no indication of a fix for it. Incidentally, Google had already fixed the Calendar and Contacts issues on the phone-side with Android 2.3.4 (although that still left 99 percent of phones vulnerable), but it too is still stuck with the Picasa vulnerability.

Wednesday, April 20, 2011

SKYPE FOR ANDROID UPDATE FIXES GAPING SECURITY HOLE; ADDS 3G CALLING


Verizon Android users have had 3G Skype calling since this time last year, but the latest app release -- v1.0.0.983 for those of you keeping tabs -- brings 3G calling to the masses, without the need for a VZW-sanctioned app. The update also patches a rather significant security hole discovered last week, which could let third-party apps get hold of your personal information. We're glad to see that's no longer the case, and who's going to object to free calling as part of the deal as well? Make sure your phone's running Android 2.1 (2.2 for Galaxy S devices) and head on over to the Android Market to get updated.

Sunday, April 3, 2011

TIVO'S EMAIL SERVICE PROVIDER BREACHED


Epsilon, Tivo's email service provider, has been hacked. The breach apparently has compromised the security of some users names and email addresses. A rigorous investigation has concluded that no other personal data was exposed, however it's not just TiVo that's affected -- other big names, such as JPMorgan Chase, Citi, US Bank, Kroger, and Walgreens have also affected by the breach.

If you have subscribed to any of those company's email lists, you may want to consider using a spam filter.

Saturday, March 19, 2011

HUGE MAJORITY OF NORTH AMERICANS LIKE SECURE MOBILE PAYMENTS


A recent study conducted by payment solution provider Mobio Identity Systems suggests that North Americans are eager to see mobile payments become a reality. At the same time, however, security is a top concern for the majority of potential users.

Mobio recently surveyed 1,085 people across North America and found that the overwhelming majority — 94% — would use mobile payments if they knew the system was secure. Mobio’s study also found that 73% of respondents said security was their main concern regarding mobile payments, while 12.4% said simplicity and 8.5% said speed. As such, it’s safe to say companies looking to bring mobile payments to the mainstream market must focus a tremendous amount of effort on security.

Friday, March 18, 2011

RSA HACKED, EFFECTIVENESS OF SECUREID TOKENS QUESTIONED


RSA, the security division of EMC and producer of the SecurID systems used by countless corporations (and the Department of Defense), has been hacked. Yesterday it sent out messages to its clients and posted an open letter stating that it's been the victim of an "advanced" attack that "resulted in certain information being extracted from RSA's systems" -- information "specifically related to RSA's SecurID two-factor authentication products."

The company assures that the system hasn't been totally compromised, but the information retrieved "could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack." RSA is recommending its customers beef up security in other ways, including a suggestion that TSA's customers "enforce strong password and pin policies." Of course, if security admins wanted to rely on those they wouldn't have made everyone carry around SecurID tokens in the first place.

Wednesday, February 23, 2011

WINDOWS 7 SERVICE PACK 1 NOW AVAILABLE


Microsoft has finally released Windows 7 Service Pack 1 to the masses. It is currently listed as an Important update, but is not checked in Windows Update. The service pack is a whopping 1.95GB and contains a number of improvements and optimizations.

The most notable additions are:

  • A bug fix for HDMI audio devices that stopped working after restarting the computer
  • Corrected behavior when printing mixed-orientation XPS documents
  • Changed behavior of the "Restore previous folders at logon" functionality so that all folders are restored to their previous position, rather than in cascading order based on the most recently active folders.
The service pack also contains all the previously released updates and security patches.

Tuesday, February 1, 2011

BRITISH AIRPORTS TO USE HOLOGRAPHIC SECURITY AGENTS


Starting today, London Luton and Manchester airports will beam in images of holographic agents to prep passengers for the security line. London will have Holly and Graham while Manchester will have Julie and John. According to Luton's Glyn Jones, "Holly and Graham are not going to have a hangover; they're not going to have a row with their partner the night before."

Video introducing the holographic security agents:

Sunday, January 30, 2011

ANDROID 2.3 SECURITY BUG DISCOVERED


Xuxian Jiang, a researcher at North Carolina State Unversity, has uncovered a security bug in the next version of Google's Android OS, Gingerbread. According to Jiang, the bug allows malicious websites to access a persons microSD card and upload the contents, including voicemails, photos and online banking information, to a remote server.

The flaw appears to be very similar to a known bug in previous version of Android that was thought to have been corrected in Gingerbread. Jiang says the fix for this bug in Gingerbread though is easily bypassed. Google is said to be working on a solution to the problem, but it is not known when a patch will appear.

Find the Best Headphones for your Lifestyle - EarphoneSolutions.com

Thursday, January 27, 2011

FACEBOOK CLOSING SECURITY HOLE SWITCHING TO HTTPS FOR LOGINS


Facebook has at long last offered an option to use the encrypted "HTTPS" protocol, a feature it will begin rolling out today but won't finish for a "few weeks." You should check now if it's available, and sign up as soon as it is enabled for your account.

By default, Facebook sends your access credentials in the clear, with no encryption whatsoever. HTTPS solves this longstanding problem by encrypting your login cookies and other data.

A blogger using a freely available program called Firesheep was able to steal up to 40 Facebook logins in 30 minutes in a New York Starbucks recently.

You can sign up for Facebook HTTPS by going to Account Settings and then selecting "Account Security," third from the bottom. Then click under "Secure Browsing" — if it's there. Facebook says everyone should have this by the end of the day, but in the meantime you might be missing the relevant option toggle.

Savings on HP Printers 125x125

Thursday, December 2, 2010

GOOGLE CHROME DEV BUILD SANDBOXES FLASH


On Wednesday Google announced a new developer test version of its Chrome Web browser that will place the code of Adobe's Flash Player plug-in in its own sandbox. For now, the update just applies to the Windows Versions of the browser.

A sandbox isolates the running code from the rest of the operating system so that its has no access to critical processes or data, thus preventing it from either intentionally or unintentionally doing harm. Flash has been famously criticized by Apple CEO Steve Jobs for its lack of security and stability.

Google already uses sandboxing for HTML rendering and JavaScript execution, making it one of the most secure browsers available.

The announcement appeared on the blog dedicated to Chromium, as the open source browser engine project is called. (To further complicate things, the company also plans an upcoming operating system, Chrome OS, using some of the same Chromium code base.) The blog post states that Google engineers have been working closely with Adobe to implement the plug-in sandboxing. Adobe recently used the technique in its own Reader X plugin for Acrobat PDF files.

According to the post, written by Google software engineers Justin Schuh and Carlos Pizano, "This first iteration of Chrome's Flash Player sandbox for all Windows platforms uses a modified version of Chrome's existing sandbox technology that protects certain sensitive resources from being accessed by malicious code, while allowing applications to use less sensitive ones. This implementation is a significant first step in further reducing the potential attack surface of the browser and protecting users against common malware." [PC Mag]


Hand-Dipped Berries & Holiday Gifts Starting at $19.99

Wednesday, October 13, 2010

FACEBOOK ADDS NEW SECURITY FEATURES

Facebook has implemented two new security features to make its website more secure regardless of where you access it from.  The first is a one-time use password.  If you are in a location or using a machine where you don't feel secure using your regular password, Facebook will text you a one-time use password.  The password is good for 20 minutes.  To request a one-time password text "opt" to 32665.  You will need to add your mobile number to your account and have it verified before requesting the password though.

The second new feature is remote logoff.  If you forget to log out of Facebook, you can log in on another device, go to Account Settings page and you will be able to see and kill any active sessions. [Geek]

gay-blog-member-of-the-best-gay-bloggers