• unilogou. Powered by Blogger.

    Showing posts with label Security. Show all posts
    Showing posts with label Security. Show all posts

    Saturday, 13 August 2016

    Nancy Pelosi blames new hack attack on Russian hackers

    Posted By: Uni logo - 23:14:00


    House Minority Leader Nancy Pelosi warned fellow Democrats on Saturday to change their cellphone numbers and not let family members read their text messages after personal and official information of Democratic House members and congressional staff was posted online.
    Pelosi told Democratic lawmakers that the Democratic Congressional Campaign Committee and other Democratic Party entities were the target of "an electronic Watergate break-in."
    As a result, a mix of personal and official information of Democratic members and hundreds of congressional staff, purportedly from a hack of the DCCC, was posted online, Pelosi said.
    personal and official information of Democratic members and hundreds of congressional staff was posted online
    A hacker who calls himself Guccifer 2.0 (an apparent reference to the first hacker called Guccifer) took credit for posting the information Friday night. He had claimed responsibility for the recent hack of Democratic National Committee emails, which roiled the Democratic National Convention last month.
    Pelosi said she was flying from Florida to California when she heard about the posting of information such as cell phone numbers
    "Upon landing, I have received scores of mostly obscene and sick calls, voicemails and text messages," Pelosi said in her letter to colleagues. "Please be careful not to allow your children or family members to answer your phone or read incoming text messages. This morning, I am changing my phone number and I advise you to do so as well. "
    Pelosi said the chief information security officer of the House, John Ramsey, in coordination with U.S. Capitol Police, has sent communications to those people whose email addresses have been made public about how to address the problem. The chief administrative officer of the House has also sent an email stating that the House computer system has not been compromised, but urged members and staff to be vigilant about opening emails and websites.
    I have received scores of mostly obscene and sick calls, voicemails and text messages
    Ramsey, in a memo distributed by Pelosi, advised lawmakers to change passwords to all email accounts that they use and strongly consider changing non-House email addresses if possible. 
    Should lawmakers or staff receive any threats or observe suspicious activity, they should contact U.S. Capitol Police and local police, he said in the memo.
    Rep. Ben Ray Luján, D-N.M., the chairman of the Democratic Congressional Campaign Committee, was holding a conference call with lawmakers on Saturday evening along with cybersecurity experts who have been investigating and responding to the breach.
    "This is a sad course of events, not only for us, but more importantly for our country," Pelosi said in urging lawmakers to join the conference call with Lujan.
    While Guccifer 2.0 has described himself as a Romanian hacker and denies working for Russia, online investigators assert that he is linked to Russia.
    Disclosures of email showing DNC staffers privately supporting Hillary Clinton during the presidential primary while publicly maintaining they were neutral in her race with Bernie Sanders led to the resignation of DNC chair Debbie Wasserman Schultz.

    Friday, 5 August 2016

    Apple introduces its first security bounty program

    Posted By: Uni logo - 11:57:00


    Apple is launching its first security bounty. The news comes on the heels of a presentation from Apple’s Ivan Krstic at the annual Black Hat USA security conference in Las Vegas. 
    Krstic runs security engineering and architecture at Apple and presented an in-depth look at iOS security. This was Apple’s first appearance at Black Hat in four years. 
    Since its battle with the FBI this spring, Apple has been more outwardly focused on discussing its commitment to security. To that end, Apple is opening up its first security bounty program. The program, which will roll out in September, will accept security submissions in a number of areas. Depending on the type of exploit found, researchers and their organizations will get more money. 
    The categories and issues up for consideration, along with their bounties, are as follows:  
    • Secure boot firmware components – up to $200,000.
    • Extraction of confidential material protected by the Secure Enclave Processor – up to $100,000.
    • Execution of arbitrary code with kernel privileges – up to $50,000.
    • Unauthorized access to iCloud account data on Apple servers – up to $50,000.
    • Access to sandboxed processes to user data outside of the sandbox – up to $25,000.
    Organizations can accept the money Apple offers or they can donate it to a charity of their choice. Apple says that if researchers choose to donate to a charity, they will consider matching that donation. 
    Apple tells me it may also award researchers who share significant critical vulnerabilities not outlined above. 
    Unlike many security bounty programs, this program is not open to the public. For now, Apple is partnering with a dozen or so security researchers and organizations to focus on finding flaws. 
    But Apple tells me that this isn’t an attempt to be exclusive. The plan is to open it up to more individuals and organizations over time. Apple also says that if someone not associated with an invited organization responsibly discloses a vulnerability, that feedback will be welcome and they may be invited to join the formal process. 
    Apple says that it spoke to a number of other companies who have already run successful security bounties and that advice – which was to start small (as to reduce the signal/noise ratio) and then ramp up – contributed to the decision to only involve a few organizations and researchers at the start. 

    A long time coming 

    Although it’s great that Apple is introducing a security bounty, it's worth noting that the company has taken its time getting here. Nearly every other major tech company – including Microsoft, Google and Facebook – have offered security bounties for years. 
    So what took so long?  
    Apple tells me that although it has been working with outside researchers for years, it has consistently received feedback – from experts inside and outside of the company – that it is more difficult to identify significant security vulnerabilities without a bounty program.  
    As a result, it makes sense that the company would look (finally!) to outside organizations and researchers to offer their own feedback. 
    It probably doesn’t hurt that the focus on Apple’s security is now more pointed than ever before. With more eyes on Apple security – and more people trying to bypass it (whether it’s law enforcement or hackers), it makes sense to get more eyes focused on finding flaws. 
    I understand the need to limit — at least initially — involvement in the bounty program, but I do hope Apple commits to expanding the individuals and groups involved quickly. iOS as a platform deserves as many eyes on it as possible.
    For now, the focus of the bounty is on iOS, but Apple says that it is open to expanding the bounty program to other platforms (including macOS) and other areas, once the program ramps up.

    Thursday, 28 July 2016

    Security experts have cloned all seven TSA master keys

    Posted By: Uni logo - 04:45:00

    Key escrow — the process of keeping a set of keys for yourself “just in case” — has always been the U.S. government’s modus operandi when it comes to security. From the disastrous Clipper chip to today, the government has always wanted a back door into encryption and security. That plan backfired for the TSA.
    The TSA, as you’ll remember, offers a set of screener-friendly locks. These locks use one of seven master keys that only the TSA can use — until 2014. In an article in The Washington Post, a reporter included a shot of all seven keys on a desk. It wasn’t long before nearly all the keys were made available for 3D printing and, last week, security researchers released the final key.
    At last week’s HOPE Conference in New York, hackers calling themselves DarkSim905, Johnny Xmas, and Nite 0wl explained how — and why — they cracked the TSA keys.
    “This was done by legally procuring actual locks, comparing the inner workings, and finding the common denominator. It’s a great metaphor for how weak encryption mechanisms are broken — gather enough data, find the pattern, then just ‘math’ out a universal key (or set of keys),” said Johnny Xmas. “What we’re doing here is literally cracking physical encryption, and I fear that metaphor isn’t going to be properly delivered to the public.”
    The keys, should you be interested, are here and can be printed on a 3D printer.
    The TSA, for their part, doesn’t care, telling The Intercept that “The reported ability to create keys for TSA-approved suitcase locks from a digital image does not create a threat to aviation security. These consumer products are ‘peace of mind’ devices, not part of TSA’s aviation security regime.”
    In other words, you might as well not use locks at all.

    Wednesday, 27 July 2016

    This solar-powered home security cam is truly wireless and 100% green

    Posted By: Uni logo - 13:03:00
    Https%3a%2f%2fblueprint-api-production.s3.amazonaws.com%2fuploads%2fcard%2fimage%2f154552%2fring-stick-up-cam-review-6

    "The raccoons are back," I frustratingly said to my wife the night after installing the Ring Stick Up Cam in our backyard. 

    You see, last summer we had a mommy raccoon and her three babies coming into our backyard and ravaging through bins, looking for every morsel of cat food they could find. 
    We made some changes. We started storing the food inside and assumed we had gotten rid of them once and for all. We were wrong, and now I have the video to prove it. 
    Ring first broke into home security with its Ring Video Doorbell. When someone rings the doorbell, an alert is sent to your smartphone and you can view and talk to whoever's at your door. Alternatively, the doorbell can begin recording when it detects motion at your door and send alerts to your phone. And thanks to its built-in infrared LEDs, the camera works at night. 
    The $199 Ring Stick Up Cam works in a similar fashion, save for the doorbell part. Ring’s goal is to help ease your security fears by providing multiple products that complement one another instead of forcing you to buy a doorbell from Ring and an outdoor security camera from another company.

    IMAGE: JASON CIPRIANI/MASHABLE
    With the Stick Up Cam, Ring basically took its doorbell design, changed the housing color to all black and removed the doorbell button. 
    The two of them look nearly identical. That’s a bit disappointing, especially when you take into consideration the company’s Video Doorbell Pro, which is smaller and far more stylish.
    Recycled design aside, the Stick Up Cam isn’t necessarily ugly. Its black housing is unassuming, albeit a little mundane — a welcome trait for a security camera you want to draw as little attention to as possible. 

    Set-up is simple 

    Ring uses its Android or iOS app to complete initial setup of the Stick Up Cam, something you’ll want to do before mounting it to an outside wall.
    Using the provided Micro USB cable, you charge the camera and then follow instructions in the app. The process involves pressing a button on the back of the camera, searching and connecting to its temporary Wi-Fi network and connecting it to your personal Wi-Fi network. 

    IMAGE: JASON CIPRIANI/MASHABLE
    Installation, on the other hand, can be a bit more involved depending on your comfort level with a screwdriver and putting holes into your house’s exterior. Inside the box you’ll find screws, a screwdriver, a drill bit, and two different mounts. 
    Using any combination of the provided tools, you can do everything from mount the cam to an overhang or directly to an outside wall. 
    Because I have to return the product after the review period ends, I didn’t want to put any holes in my home. But after looking through the instructions it was clear that installing the camera is a straightforward process that shouldn’t take more than 15 minutes. 
    Don’t worry about placing it somewhere rain or snow can’t reach; the camera is weather resistant and should be able to withstand some moisture. My review sample survived three heavy rainstorms in as many weeks without any issues.

    Solar power is optional 


    IMAGE: JASON CIPRIANI/MASHABLE
    Ring states the battery in the Stick Up Cam should last six to 12 months on a single charge, depending on activity and use of its Live View feature. Alternatively, you can provide constant power to the camera through a Micro USB cable and a smartphone charger. Or you can spring for the $50 Solar Panel to provide consistent power to the Stick Up Cam. 
    The Solar Panel comes with a 5-foot Micro USB cable and a weather-resistant sleeve to help protect the charging port when connected to the camera. 

    IMAGE: JASON CIPRIANI/MASHABLE
    Ring advises users to place the panel in an area where it will receive direct sunlight for two or three hours every day. Naturally, Ring includes all appropriate mounting supplies in the box along with the Solar Panel. 
    I used the panel during my time with the Stick Up Cam, and found the battery to maintain a charge of 65 to 70 percent. 

    Motion detection still needs some work 


    IMAGE: SCREENSHOT: JASON CIPRIANI/MASHABLE
    Having used the Ring Video Doorbell for the past year, I’ve grown accustomed to its finicky motion alerts. I’ve gone through troubleshooting with customer care, turned off motion detection altogether, turned off only particular sections the camera monitors, turned it back on, and everything in between. 
    I’ve come to live with the fact that it’s not perfect and that I have to deal with the random motion alerts pushed to my phone. 
    As much as I wanted to believe things would be different with the Stick Up Cam, they weren't. I received several alerts during testing in which I was unable to see any movement at all in the recorded video. I don’t know if something quickly passed by the camera and it didn’t start recording fast enough or if there was a bug that flew by and set off the motion sensor. Look at this video and see if you can find what triggered it. I sure can’t see anything. 
    For its part, Ring tells me the company is constantly working on improving motion detection for the Doorbell and the Stick Up Cam through software updates (installed without you having to do a thing), and that the Pro version of its Doorbell has "more advanced motion features." Why that same technology wasn’t brought over to the Stick Up Cam is a mystery to me.

    Live view and cloud recording 


    IMAGE: JASON CIPRIANI/MASHABLE
    All Stick Up Cam users have access to the company’s Live View feature. Using Live View, you don’t have to wait for a motion alert to view your camera’s stream. You can open the app, tap a button and watch. 
    In testing the feature before launch, I never had an issue with the amount of time it took to establish a connection (both on Wi-Fi and a cellular connection), nor did I experience any issues with stream quality. The Stick Up Cam captures 720p video, by the way. 
    Ring offers a cloud recording plan at a cost of $3 a month or $30 per year for each camera connected to your Ring account. With an active subscription, you can go back and view old videos captured during a motion or live view event, complete with audio from both involved parties. 

    Peace of mind is worth the price 


    IMAGE: JASON CIPRIANI/MASHABLE
    Thankfully, the highlight of my time with the Stick Up Cam was it capturing the raccoon helping itself to dinner. 
    The Stick Up Cam did provide peace of mind. Knowing if anything was moving around on the side of my house, be it an animal or would-be bad guy, I would at least have video proof. 
    The overall design is boring and the fact that motion alerts arrive when there’s no motion is annoying. Hopefully, Ring is able to figure out the second of these frustrations through future software updates. 
    Spending $200 on a camera, plus another $50 for the solar panel, is an investment. But it's an easily justifiable one if you live in an area where added serenity will help you and your family sleep better at night. 

    Ring Stick Cam

    The Good

    Quick, easy installation and setup  Provides peace of mind and extra security  Can view a live stream from camera, from anywhere on your phone or computer

    The Bad

    Boring design  Too many false motion alerts

    The Bottom Line

    The Ring Stick Up Cam with an attached Solar Panel is a truly wireless security camera for those looking to monitor more than just a front door.

    Wednesday, 29 June 2016

    Why Signal is better for privacy than WhatsApp or Google Allo

    Posted By: Uni logo - 04:51:00
    Https%3a%2f%2fblueprint-api-production.s3.amazonaws.com%2fuploads%2fcard%2fimage%2f129448%2fphone-20

    This spring, text messages got a lot more private. In April, the world’s most popular messaging service, WhatsApp, announced it would use end-to-end encryption by default for all users, making it virtually impossible for anyone to intercept private WhatsApp conversations, even if they work at Facebook, which owns WhatsApp, or at the world’s most powerful electronic spying agency, the NSA. Then in May, tech giant Google announced a brand new messaging app called Allo that also supports end-to-end encryption.
    Making the news even better from a privacy standpoint is that both WhatsApp and Allo use a widely respected secure-messaging protocol from Open Whisper Systems, the San Francisco-based maker of the messaging app Signal.
    To recap, there are now at least three different instant-message services that implement robust encryption: WhatsApp, Signal and Allo. How is someone who cares about their privacy and security to choose between them?
    In this article, I’m going to compare WhatsApp, Signal and Allo from a privacy perspective.
    While all three apps use the same secure-messaging protocol, they differ on exactly what information is encrypted, what metadata is collected, and what, precisely, is stored in the cloud — and therefore available, in theory at least, to government snoops and wily hackers.
    In the end, I’m going to advocate you use Signal whenever you can — which actually may not end up being as often as you would like.

    What’s up, WhatsApp?

    With more than 1 billion users, WhatsApp is the world’s most popular messaging app. Which is why it was huge news among encryption advocates when the company a year and a half ago announced a partnership with Open Whisper Systems to integrate the Signal protocol into its product. The rollout was gradual, starting only on the Android version of WhatsApp and only for one-on-one text communication, but by this past April, WhatsApp was able to announce it was using the Signal protocol to encrypt all messages, including multimedia messages and group chats, for all users, including those on iOS, by default.
    So if a government demands the content of WhatsApp messages, as in a recent case in Brazil, WhatsApp can’t hand it over — the messages are encrypted and WhatsApp does not have the key.
    But it’s important to keep in mind that, even with the Signal protocol in place, WhatsApp’s servers can still see messages that users send through the service. They can’t see what’s inside the messages, but they can see who is sending a message to whom and when. And according to the WhatsApp privacy policy, the company reserves the right to record this information, otherwise known as message metadata, and give it to governments:
    WhatsApp may retain date and time stamp information associated with successfully delivered messages and the mobile phone numbers involved in the messages, as well as any other information which WhatsApp is legally compelled to collect.
    A WhatsApp spokesperson told the Committee to Protect Journalists, “WhatsApp does not maintain transaction logs in the normal course of providing its service.” However, the company makes no promises and could easily record and hand over metadata in response to a government request without violating its own policy.
    When you first set up WhatsApp, you’re encouraged, but not required, to share your phone’s contact list with the app. This helps the WhatsApp service connect you with other users quickly and easily. A WhatsApp spokesperson confirmed to me that the company retains contact list data, which means that WhatsApp could also hand over your contact list in response to a government request.
    Finally, online backups are a gaping hole in the security of WhatsApp messages. End-to-end encryption only refers to how messages are encrypted when they’re sent over the internet, not while they’re stored on your phone. Once messages are on your phone, they rely on your phone’s built-in encryption to keep them safe (which is why it’s important to use a strong passcode). If you choose to back up your phone to the cloud — such as to your Google account if you’re an Android user or your iCloud account if you’re an iPhone user — then you’re handing the content of your messages to your backup service provider.
    By default, WhatsApp stores its messages in a way that allows them to be backed up to the cloud by iOS or Android. WhatsApp does let you remove your chats from these cloud backups if you go out of your way to do so, which I recommend you do, if you use WhatsApp to discuss anything sensitive.

    Allo, World

    The first thing to understand about Google’s forthcoming Allo app is that, by default, Google will be able to read all of your Allo messages. If you want end-to-end encryption via the Signal protocol, you need to switch to an “incognito mode” within the app, which will be secure but include fewer features.
    It’s 2016. We should be moving toward a future where the conversations we have on our phones are private, but Allo’s lack of default encryption is clinging to the past. Google releasing a new messaging app without default end-to-end encryption is like Tesla announcing a brand new model that only lets you use the airbags when you’ve disabled the entertainment system. As NSA whistleblower Edward Snowden put it, Allo’s defaults are “dangerous” and “unsafe.”
    On the other hand, Google is trying something brand new, applying so-called machine learning techniques directly to your conversations. Allo hooks into an artificial intelligence called Google Assistant, which will read all of your messages and offer suggested responses, in your own slang, that it thinks you would likely write yourself. It also brings Google search directly into your conversations — you and your friends could, for example, search for a restaurant, pick one out, and make a reservation without having to leave the app.
    Allo’s machine learning features prevent Google from turning on end-to-end encryption for all messages, since Google needs to be able to ingest the content of messages for the machine learning to work, a Google spokesperson told me. The spokesperson also said Google isn’t ready, until Allo is released later this summer, to make any promises about where user data will be stored or for how long.
    The technology behind Allo looks very cool, but it’s moving in the wrong direction with regard to privacy. If privacy is important to you, you should use a messaging app that encrypts messages by default instead.
    Along with Allo, Google is also releasing a new video calling app called Duo. Unlike Allo, all video calls in Duo will be end-to-end encrypted by default. Google isn’t releasing details — how the encryption works, if it’s possible for users to independently verify that it’s secure, or if metadata of the calls will be retained on Google’s servers — until it’s publicly released.
    Allo and Duo will both be covered under Google’s privacy policy. Unfortunately, this policy doesn’t break out details about specific Google products.

    Signal in the Noise

    The first thing that sets Signal apart from WhatsApp and Allo is that it is open source. The app’s code is freely available for experts to inspect for flaws or back doors in its security. Another thing that makes Signal unique is its business model: There is none. In stark contrast to Facebook and Google, which make their money selling ads, Open Whisper Systems is entirely supported by grants and donations. With no advertising to target, the company intentionally stores as little user data as possible.
    Like WhatsApp, all messages sent over Signal are end-to-end encrypted, and Open Whisper Systems doesn’t have the keys to decrypt them. What about message metadata, your phone’s contact list, and cloud backups?
    Signal’s privacy policy is short and concise. Unlike WhatsApp, Signal doesn’t store any message metadata. Cryptographer and Open Whisper Systems founder Moxie Marlinspike told me that the closest piece of information to metadata that the Signal server stores is the last time each user connected to the server, and the precision of this information is reduced to the day, rather than the hour, minute, and second.
    Signal users must share their contact list with the app in order to find other users — in WhatsApp, this is optional but recommended. But Signal doesn’t directly send your contact list to the server. Instead, it uses what’s known as a cryptographic hash function to obfuscate phone numbers before sending them to the server. (It also truncates the hashed phone numbers, if we’re being precise about things.) The server responds with the contacts that you have in common and then immediately discards the query, according to Marlinspike.
    If you back up your phone to your Google or iCloud account, Signal doesn’t include any of your messages in this backup. WhatsApp’s gaping backup issue simply doesn’t exist with Signal, and there’s no risk of accidentally handing over your private messages to any third-party company.
    Of course, this also means there’s no way to back up your Signal data to the cloud — a feature that some users find useful. If you lose your phone and restore a new one from backup, you simply lose all of your chat history. The Android version of Signal lets users locally export and import app data, for example if you’re switching to a new phone but still have your old one, but the iOS version of Signal does not support this.
    In short, if a government demands that Open Whisper Systems hand over the content or metadata of a Signal message or a user’s contact list, it has nothing to hand over. And that government will have just as little luck requesting backups of Signal messages from Google or Apple.
    From a user privacy perspective, Signal is the clear winner, but it’s not without its downsides.
    Compared to WhatsApp’s 1 billion users, Signal’s user base is minuscule. Marlinspike said that they don’t publish statistics about how many users they have, but Android’s Google Play store reports that Signal has been downloaded between 1 and 5 million times. The iPhone App Store does not publish this data.
    This means that if you install the Signal app, chances are you’ll have to convince your friends, family, and colleagues to install it as well before you can benefit from Signal’s top-grade privacy protection. If you install WhatsApp, chances are a lot of your contacts are already using it, and you can begin having encrypted conversations with minimal effort.
    Signal also has fewer features and gets improved at a slower pace than its corporate competitors. For example, an early version of Signal Desktop has been available since the end of 2015, but it’s only available for Android users — iPhone support has not yet been developed, and it’s unclear when it will be finished. WhatsApp has a desktop version that works regardless of the type of phone you use.
    Marlinspike told me that Open Whisper Systems has three full-time staff: two software developers and one person who handles user support and project management. With such incredibly limited resources, it’s surprising that they’ve accomplished as much as they have.
    Have something to add to this story? Share it in the comments.
      This article originally published at The Intercept here

      Copyright © 2016 Uni logo™ is a registered trademark.

      Designed by Unilogou. Hosted on Blogger Platform.