Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, March 23, 2020

Here are some cyber security tips you should know when working remotely.

One of the key preventative measures for the spread of COVID-19 is social distancing. Luckily, in this increasingly connected world we can continue our professional and private lives virtually. However, with huge increases in the number of people working remotely, it is vital that we also take care of our cyber "hygiene".

Awareness and preparedness are both vital - you'll want to be sure you have the following basics:
 
  • Secure wifi connection. Most wifi systems at home these days are correctly secured, but some older installations might not be. With an insecure connection, people in the near vicinity can snoop your traffic.
  • Fully updated antivirus system in place.
  • Up to date security software. Security tools such as privacy tools, add-ons for browsers etc need to be up to date. Patch levels should be regularly checked.
  • Remember to back up periodically. All important files should be backed up regularly. In a worst case scenario, staff could fall foul of ransomware for instance. Then all is lost without a backup.
  • Lock your screen if you work in a shared space. (You really should be avoiding co-working or shared spaces at this moment - social distancing is extremely important to slow down the spread of the virus).
  • Make sure you are using a secure, encrypted connection to your work environment.
Things employers should do: 
  • Provide initial and then regular feedback to staff on how to react in case of problems. Who to call, hours of service, emergency procedures and how they evolve.
  • Give suitable priority to the support of remote access solutions. Employers should provide at least authentication and secure session capabilities (essentially encryption).
  • Ensure adequate support in case of problems.
  • Define a clear procedure to follow in case of a security breach.
  • Consider restricting access to sensitive systems where it makes sense.
If you have any questions about these tips or need to setup remote login to your office, give us a call at 781-816-9437.

Tuesday, January 17, 2017

A warning to all the selfie queens out there: you can be hacked!

Next time someone poses for a selfie with their fingers held up in a peace sign, maybe tell them to leave it at a smile.

An ordinary photo of the universal sign of goodwill might be enough for a thief to copy a fingerprint, thanks to the high quality of digital photos these days. And since Touch ID and similar technologies turn fingerprints into keys that unlock our devices and the data we keep in them, that’s cause for concern.

Just by casually making a peace sign in front of a camera, fingerprints can become widely available.

A team at the NII’s Digital Content and Media Sciences Research Division, Japan was able to reconstruct fingerprints spotted in pictures taken from up to 3 meters away.

“Fingerprint data can be re-created if fingerprints are in focus with strong lighting in a picture.” - Isao Echizen, a professor at Japan’s National Institute of Informatics

The peace sign is a common expression in social media pictures, but this technique could conceivably be applied to other common gestures like waving or giving a thumbs up. Matched with a person’s face, that makes for a significant amount of biometric data that identity thieves could do real damage with.

How Thieves Could Get Fingerprints From Selfies

The technique described by Echizen uses no special software, but does require good lighting - so for the moment you can feel free to flash whatever signs you like when the light is low. As mobile cameras become more and more powerful, though, selfies will become a bigger security liability.

The better alternative might be to make sure you aren’t relying on fingerprint security measures whenever possible. Or just avoid selfies altogether.

Monday, November 28, 2016

Forget old school alarm systems! This drone security system is sure to protect your valuables!

A new startup wants to turn drones into guardian angels for our homes.

Sunflower Labs - with headquarters in Silicon Valley and Zurich, Switzerland - announced a new security system on Thursday that detects possible threats and investigates them with a drone.

The drone streams video to your smartphone, so you can see and decide if your home is at risk or not.

Sunflower Labs, which is now accepting participant applications, will start beta tests in mid-2017. The startup sees itself as a complement to traditional alarms.

Here's how it works: The Sunflower Home Awareness System relies on the drone and a handful of in-ground smart lights to watch over your house. It detects motion, vibration and sound. By analyzing this data, the system can distinguish between a human, a car and animals. To do so, it uses artificial intelligence to identify the disturbance and determine if it's potentially dangerous. For example, trusted visitors such as mail delivery persons will be recognized by how they approach the home and how long they stand at the front door.

When a person approaches and lingers outside the back door, Sunflower Labs will send a push notification to your smartphone and ask if you'd like to investigate.

If you say yes, the drone will lift off from its perch - on a balcony, deck or patio - and fly to where the suspicious person is located. The drone hovers 30 feet above the visitor until you tell it to return to its nest. The app includes an option for a home owner to notify local police.

False alarms are a common problem for home alarm systems. CEO Alex Pachikov expects sending the drone to investigate before calling the police will solve this issue. The system also has the benefit of keeping an eye on all of your property. Most alarm systems are set up to guard only the entries and exits to a home.

The propellers automatically shut off if they hit anything and are designed to be quiet due to its broad size.

The drone currently weighs almost two pounds, but the company wants to get it down to half a pound before it ships. It also features two cameras and only collects footage of a home owner's property to protect neighbors' privacy.

The price to use the system is unclear as of now, but the lights are expected to cost $159 each. Meanwhile, the drone can be rented for a fee, comparable to what traditional alarm systems cost.

Friday, February 20, 2015

Lenovo in hot water after shipping laptops with malware pre-installed.

Computer maker Lenovo has been shipping laptops pre-packaged with malware that makes you more vulnerable to hackers - all for the sake of serving you advertisements.

Made by a company called Superfish, the software is essentially an Internet browser add-on that injects ads onto websites you visit.

Besides taking up space in your Lenovo computer, the add-on is also dangerous because it undermines basic computer security protocols.

That’s because it tampers with a widely used system of official website certificates. That makes it hard for your computer to recognize a fake bank website, for instance.

Customers started spotting this on their Lenovo computers in mid 2014.

After facing a fierce backlash by customers and computer security experts this week, Lenovo acknowledged that "user feedback was not positive." As of January, Lenovo has stopped pre-loading the software on new computers, a company spokesman said. Lenovo also promised it "will not pre-load this software in the future" and said it disabled the feature on its servers, which essentially kills the program on everyone’s computer.

Source: Yahoo Tech

Wednesday, June 4, 2014

Google now testing super secure email.

It's called "End-to-End" encryption, and it's the best way to stop anyone from snooping on your emails. Google would turn your emails into jumbled code, and the only person who can see the email in plain text is the trusted person on the other end.

Hackers don't stand a chance. In fact, neither does the National Security Agency. It's the kind of encryption ex-NSA contractor Edward Snowden used to communicate with journalists before he went public last year with damning documents proving the extent of U.S. government surveillance. It's what spies use...it's that good.

But End-to-End is not available just yet. In a blog post, Google said the program is in a public testing phase. After that, you'll be able to download the app and add it to your Google Chrome Web browser. If you use the browser, it'll work with any Web-based email provider.

"We recognize that this sort of encryption will probably only be used for very sensitive messages or by those who need added protection," wrote Stephan Somogyi, a Google product manager who oversees security and privacy, in the blog. "But we hope that the End-to-End extension will make it quicker and easier for people to get that extra layer of security should they need it."

Here's how Google's super encryption would work: Imagine you want to send a sensitive letter by mail. You can't just lick the envelope shut. Postal workers might open it. But they can't open a lock.
Your friend buys a padlock, opens it and sends it to you. He keeps the key. You receive his lock, place your letter inside a box and close it with your friend's lock. You send it. Now only he can open it with his private key, which never left his possession.

Google will let you share locks, but never keys. So far, End-to-End encryption has proven tamper-proof.

This is only the latest move by Silicon Valley giants to beef up their security since last year's revelations that the U.S. government is gathering our emails and phone calls without warrants. In December, executives at the world's largest technology firms called on the U.S. government to respect Internet privacy rights, dial back its intelligence gathering and make spying programs more transparent.

Since then, Microsoft and Yahoo have been working on encrypting the information they house and transmit. Facebook CEO Mark Zuckerberg called President Obama directly to complain about the NSA. And they've all shed light on the scope of secret data requests.

Source: CNN Money

Monday, March 24, 2014

Microsoft will break into your Outlook, Hotmail, and instant messenger accounts if it deems necessary.

The company's ability (and willingness) to take such an approach became apparent this week. Microsoft admitted in federal court documents that it forced its way into a blogger's Hotmail account to track down and stop a potentially catastrophic leak of sensitive software. The company says its decision is justified.

From the company's point of view, desperate times call for desperate measures.

"In this case, we took extraordinary actions based on the specific circumstances," said John Frank, one of the company's top lawyers, in a blog post Thursday night.

According to an FBI complaint, Microsoft in 2012 discovered that an ex-employee had leaked proprietary software to an anonymous blogger. Fearing that could empower hackers, Microsoft's lawyers approved emergency "content pulls" of the blogger's accounts to track it down. Company investigators entered the blogger's Hotmail account, then pored over emails and instant messages on Windows Live. The internal investigation led to the arrest on Wednesday of Alex Kibkalo, a former Microsoft employee based in Lebanon.

Although the move could be perceived as a breach of trust, Microsoft says it's allowed to make such unilateral decisions. It pointed to its terms of service: When you use Microsoft communication products, (Outlook, Hotmail, Windows Live) you agree to "this type of review ... in the most exceptional circumstances," Frank wrote.

Microsoft's legal team thought there was enough evidence suggesting the blogger would try selling the illegally obtained intellectual property. In such instances, law enforcement agents would typically seek a warrant, but Microsoft said it didn't need one. The servers storing the information are on its own property.

Ginger McCall, a director at the Electronic Privacy Information Center, said those actions are deeply troubling, because they show "Microsoft clearly believes that the users' personal data belongs to Microsoft, not the users themselves."

"This is part of the broader problem with privacy policies," she said. "There are hidden terms that the users don't actually know are there. If the terms were out in the open, people would be horrified by them."

Microsoft recognizes that it's a sensitive topic, especially as the nation grapples with revelations about the extent of warrantless surveillance on Americans by their own government -- spying that Microsoft and other major tech companies have loudly criticized.

That's why Microsoft is instituting a new policy: In the future, it'll loop in an outside lawyer who's a former federal judge and seek his or her approval.

In a move that might be deemed ironic, Microsoft will now add its own internal searches to its biannual transparency reports on government surveillance.

Source: CNN

Wednesday, August 7, 2013

Do you save passwords in Google Chrome? Maybe you should reconsider...

You might want to think twice before you let someone borrow your computer.

The most obvious risk of allowing someone else access to your desktop is that they can impersonate you, using any app where you’re already signed in. They could send prank messages using your default email client, or profess your undying love for Justin Bieber using your logged-in Twitter account.

That’s annoying, but far from fatal.

But the situation becomes considerably worse if you use Google Chrome to save and sync passwords for easy logins at your favorite websites. An intruder who has unrestricted access to your computer for even a minute can view and copy all of your saved passwords just by visiting an easy-to-remember settings page: chrome://settings/passwords.

That link opens the local copy of your saved password cache, which is synchronized to every machine where you sign in with your Google account.

And the funny thing is, anyone who visits that page can see the plaintext version of every saved password just by clicking a button.

The saved password list shows the web address, username, and password for each saved set of credentials. Initially, the saved password is displayed as a row of asterisks. But if you click the masked password, you see a “Show” button that you can click to immediately display the saved password.

A malicious or spiteful intruder who can lure you away from your computer briefly can see your saved passwords, then close the settings page. And you have no idea that your credentials have been compromised.

Source: ZD Net

Friday, July 26, 2013

The new school ID: iris scans.

By the fall, several schools -- ranging from elementary schools to colleges -- will be rolling out various iris scanning security methods.

Winthrop University in South Carolina is testing out iris scanning technology during freshman orientation this summer. Students had their eyes scanned as they received their ID cards in June.

"Iris scanning has a very high level of accuracy, and you don't have to touch anything, said James Hammond, head of Winthrop University's Information Technology department. "It can be hands free security."

The college will be deploying scanning technology from New Jersey-based security company Iris ID.

South Dakota-based Blinkspot manufactures iris scanners specifically for use on school buses. When elementary school students come aboard, they look into a scanner (it looks like a pair of binoculars). The reader will beep if they're on the right bus and honk if they're on the wrong one.

The Blinkspot scanner syncs with a mobile app that parents can use to see where their child is. Every time a child boards or exits the bus, his parent gets an email or text with the child's photograph, a Google map where they boarded or exited the bus, as well as the time and date.

Iris-scanning is part of a growing trend called "biometrics," a type of security that recognizes physical characteristics to identify people. As the technology becomes faster and cheaper to build, several security equipment manufacturers are looking at biometric methods like iris scanning as the ID badge of the future.

In the next year, industry insiders say the technology will be available all over-- from banks to airports. That means instead of entering your pin number, you can gain access to an ATM in a blink. Used in an airport, the system will analyze your iris as you pass through security, identifying and welcoming you by name.

One company developing that technology is Eyelock. The company's scanners are already in use in foreign airports and at high-security offices, including Bank of America's North Carolina headquarters.

Eyelock's technology records video of your eyeball and uses an algorithm to find the best image of each eye. Eyelock is also entering the school market, piloting their devices in elementary school districts and nursery schools around the country.

"Imagine a world where you're no longer reliant on user names and passwords," Eyelock CMO Anthony Antolino told CNNMoney. "If we're going through a turnstile and you have authorization to go beyond that, it'll open the turnstile for you, if you embed it into a tablet or PC, it will unlock your phone or your tablet or it will log you into your email account."

Eyelock's airport security technology can process up to fifty people per minute.
"You walk through without stopping, you look at the camera, it recognizes you in less than one second," Antolino said. "In the case of customs, by the time you approach the customs agent your profile would pull up and present your documents for authorization."

Though some privacy advocates worry that convenience could be coming at the expense of security.

The iris scanning companies note that the data their scanners collect is encrypted -- an outsider would only see 1s and 0s if they went in search of your iris scans. And the companies themselves don't collect any of the data -- the schools, airports and businesses that use them own the data.

"It's sort of like a brave new world; the new technology is sort of scary," said Page Bowden, a parent of a student at Winthrop University's on-campus nursery school. "But when you stop to actually think about it, and think about the level of security that [it] affords you as a parent and your children, it's worth it."

Source: CNN Money

Thursday, July 11, 2013

The federal government has been asked to stay away from Defcon hacker event this year!

The federal government is persona non grata at this year's Defcon.

For the first time in the 21-year-history of the famed hacker's convention, government employees are being asked to stay away, albeit in a polite fashion.

Def Con founder Jeff Moss, aka The Dark Tangent, posted the following plea on the event's Web site late Wednesday:
Feds, we need some time apart.
For over two decades DEF CON has been an open nexus of hacker culture, a place where seasoned pros, hackers, academics, and feds can meet, share ideas and party on neutral territory. Our community operates in the spirit of openness, verified trust, and mutual respect.
When it comes to sharing and socializing with feds, recent revelations have made many in the community uncomfortable about this relationship. Therefore, I think it would be best for everyone involved if the feds call a "time-out" and not attend DEF CON this year.
This will give everybody time to think about how we got here, and what comes next.
The Dark Tangent
Moss, who also advises the Department of Homeland Security on security issues, told Reuters he believes the Defcon community needs some time to digest the recent leaks about U.S. surveillance programs.

"The community is digesting things that the Feds have had a decade to understand and come to terms with," Moss said. "A little bit of time and distance can be a healthy thing, especially when emotions are running high."

But Def Con won't be hiring a bunch of bouncers to throw out the Feds.

"We are not going on a witch hunt or checking IDs and kicking people out," Moss added.

Def Con has always been geared toward hackers, researchers, and other security devotees. But employees from the CIA, the FBI, the NSA, and other government branches have been welcome and have attended for many years.

General Keith Alexander, the head of National Security Agency, even gave a keynote speech at last year's event. Alexander was asked at the time whether the government was snooping on its citizens and denied that the NSA was gathering information on all Americans.

Source: CNET

Thursday, June 27, 2013

Yahoo raising security concerns for 'recycling" old e-mail addresses.

Yahoo has announced a plan to "recycle" old e-mail addresses, a move meant to free up accounts for folks who want them but that has sparked privacy concerns.

In a blog post, senior vice president Jay Rossiter announced that Yahoo e-mail accounts that have been dormant for more than a year will be reset so that active users can have access to them.
"If you're like me, you want a Yahoo! ID that's short, sweet, and memorable like albert@yahoo.com instead of albert9330399@yahoo.com," he wrote.
 
The one-year period will officially begin July 15, when users can "claim" a dormant account name. They'll find out in mid-August if they got the account they wanted.
 
It's clearly an effort by Yahoo, which has been working to redefine and rejuvenate itself under new CEO Marissa Mayer, to re-engage older users and reward active ones. But it has security experts nervous.
 
Security analyst Graham Cluley doesn't mince words.
 
"In short: as an idea it sucks, and it shows Yahoo's lack of respect to customers who created accounts with them in years gone by," Cluley wrote Wednesday.
 
Cluley lists several scenarios where the plan could backfire. They include situations in which a user has another primary e-mail account, but has given their Yahoo address as a backup in case of security situations, lost passwords and the like.
 
He said the move appears to be "an underhanded way to get people to re-engage with the site" and that people who may not actively use their Yahoo mail, but use it to store old messages and other documents, could lose them without ever realizing it.
 
Mat Honan of CNN content partner Wired, himself the recent victim of a high-profile hack, called the move "a spectacularly bad idea."
 
In the wake of such complaints, Yahoo released a followup statement saying it's sure the transition can be made without compromising security.
 
"We're committed and confident in our ability to do this in a way that's safe, secure and protects our users' data," the company said.
 
The vast majority of inactive Yahoo IDs don't have a mailbox associated with them, the company said, and any personal data associated with the accounts will be deleted.
 
During a 30-day deactivation period, bounce-back e-mails will alert senders that the deactivated account no longer exists and Yahoo will unsubscribe those accounts from newsletters, commercial e-mail alerts and the like.
 
Businesses, financial institutions, social networks and other e-mail providers will be sent notifications about e-mail addresses that have been deactivated.
 
Source: CNN

Tuesday, June 11, 2013

New Facebook feature trusts friends to reset your password.

Have you forgotten or lost your Facebook password? Relax. You can now turn to friends for help.
Facebook on Thursday rolled out Trusted Contacts account recovery, a feature it has tested with a limited number of people as the Trusted Friends capability since 2011.

Users can select three to five trusted contacts from their security settings at any time. These contacts should be available via phone or in person.

This feature could be helpful when a user suffers a mass compromise, meaning he or she loses access both to email and other accounts as a direct result of malware infestation. However, these cases are rare, and most users lose access only to specific accounts in targeted phishing schemes.

How it works:
Once users go into their Facebook Security Settings and select three to five people as trusted contacts, Facebook notifies those people.

When users can't log into their Facebook accounts, they can turn to their trusted contacts for help. Each contact will get a security code with instructions on how to use it. Users need security codes from three trusted contacts to recover their Facebook accounts.

When there's a problem, Facebook will generate an URL dynamically and the user's trusted contacts go into their own personal security settings and find the URL. The URL will give the contact a code and instructions on what to do with it.

Source: Tech News World