• unilogou. Powered by Blogger.

    Showing posts with label CRIME. Show all posts
    Showing posts with label CRIME. Show all posts

    Tuesday, 2 August 2016

    Yahoo 'Aware' Hacker Is Advertising 200 Million Supposed Accounts on Dark Web

    Posted By: Uni logo - 01:13:00
    An infamous cybercriminal is promoting 200 million of affirmed Yahoo client certifications on the dim web, and the organization has said it is "mindful" of the programmer's cases, yet has not affirmed nor prevented the authenticity from securing the information.

    On Monday, the programmer known as Peace, who has already sold dumps of Myspace and LinkedIn, recorded gathered qualifications of Yahoo clients on The Real Deal commercial center. Peace told Motherboard that he has been exchanging the information secretly for quite a while, however just now chose to offer it transparently.

    "We know about a case," a Yahoo representative told Motherboard in an email, before the information was made open. The organization did not deny that the client points of interest were Yahoo clients, regardless of being inquired as to whether it related to the organization's own records.

    "We are focused on ensuring the security of our clients' data and we consider any such claim important. Our security group is attempting to decide the truths. Yippee strives to keep our clients safe, and we generally urge our clients to make solid passwords, or surrender passwords by and large by utilizing Yahoo Account Key, and utilize distinctive passwords for various stages."


    As indicated by an example of the information, it contains usernames, hashed passwords (made with md5 calculation), dates of birth, and sometimes move down email addresses. The information is being sold for 3 bitcoins, or around $1,860, and apparently contains 200 million records from "2012 in all probability," as indicated by Peace. Until Yahoo affirms a rupture, notwithstanding, or the full dataset is discharged for check, it is conceivable that the information is ordered and repackaged from other significant information spills.

    Peace told Motherboard, "well fuck them they dont need to affirm well better for me they dont do secret word reset." Many organizations issue watchword resets to accounts influenced by information breaks, or even preemptively for a situation like this in which the provenance of spilled information is not so much clear.

    Motherboard got a little example of the information—just 5000 records—before it was freely recorded, and found that a large portion of the two dozen Yahoo usernames tried by Motherboard corresponded to real records on the administration. (This was finished by heading off to the login segment of Yahoo, entering the email address, and clicking next; when the email location wasn't remembered, it was impractical to proceed.)

    Be that as it may, when Motherboard endeavored to contact more than 100 of the locations in the specimen set, numerous returned as undeliverable. "This record has been debilitated or ceased," read one autoresponse to a considerable lot of the messages that neglected to convey legitimately, while others read "This client doesn't have a yahoo.com account."

    Thursday, 5 May 2016

    No one organizes any crime on Slack, apparently

    Posted By: Uni logo - 07:18:00


    Slack released its second annual transparency report today, revealing that it has received a grand total of one government request for user data. Just one.
    The number is somewhat remarkable when compared with the rest of the industry. Facebook recently announced that it received 19,235 requests from U.S. agencies over a six-month period. Google disclosed 12,002 requests for user data from the U.S. in its most recent transparency report. Even Uber fielded some law enforcement requests for its users’ data — 469 requests in six months. But the single-digit transparency report isn’t unusual for Slack: Last year, in its first-ever transparency report, Slack revealed that it had received zero government requests.
    Of course, Facebook, Google and Uber all serve far more people than Slack does — but Slack, which hosts 2.7 million users, is no slouch.
    When asked why their numbers (or number, really) might be so low, a representative for Slack told TechCrunch that the company hasn’t done an analysis on the number of requests received so it couldn’t be sure what a standard number might be.
    “We think the number may be low because Slack is a relatively young company,” the representative added.
    So maybe law enforcement just hasn’t noticed Slack exists yet. Or maybe the kind of crime being facilitated on Slack — because, realistically, someone has to have used one of the most popular organization tools on the market to organize a crime by now — isn’t drawing significant law enforcement attention.
    But as Slack’s userbase continues to grow, it’s likely that law enforcement interest in obtaining Slack messages will as well. Slack has added 500,000 users since February alone. And Slack messages are a tempting target for law enforcement. As WhatsApp, iMessage, and other chat services debut end-to-end encryption that limits access to message data, Slack messages are encrypted only in transit.
    Slack isn’t eager to hand over data to government agencies, though. “In releasing this report, we want to reiterate our position of opposing government-mandated ‘backdoors,’ especially any government demands for access to user data that would compromise our users’ security,” Slack said in a blog post announcing the transparency report. The company also announced that it had not provided any data in response to its single request.
    And even if you are using Slack to chat about how to rob a bank or pull off a ransomware attack, Slack isn’t peeking over your shoulder to monitor that content. “As a business tool, Slack leaves administration of the team to account owners and does not proactively screen content,” a representative said.

    Copyright © 2016 Uni logo™ is a registered trademark.

    Designed by Unilogou. Hosted on Blogger Platform.