Showing posts with label FBI. Show all posts
Showing posts with label FBI. Show all posts

Wednesday, August 2, 2017

The FBI has issued a security warning about IoT toys.

IoT toys have the potential to violate children’s privacy and safety, given the amount of pertinent information the toys can collect and store, the Federal Bureau of Investigation (FBI) warned this week in an advisory.

The sensors, microphones, data storage capabilities, cameras and other features of Internet of Things (IoT) toys are able to vacuum up extensive details about a child’s name, school, activities and even their physical location.

And if those toys are hacked, criminals could use the stolen information to harm a child, the FBI warned.

What Makes IoT Toys Vulnerable?

Data collected from interactions or conversations between children and toys are typically sent and stored by the manufacturer or developer via a server or a cloud service. In some cases, data are also collected by third party companies that manage the voice recognition software used in the toys.

Voice recordings, toy Web application passwords, home addresses, WiFi information, and sensitive personal data could be exposed if the security of the data is not sufficiently protected with the proper use of digital certificates and encryption when it is being transmitted or stored.

Smart toys connect to the Internet either directly, through WiFi to an Internet connected wireless access point; or indirectly, via Bluetooth to an Android or iOS device that is connected to the Internet.
Key factors affecting the user’s security include: the cyber security features, the toy’s partner applications and the WiFi network through which the toy connects.

Superior communications connections - where data is encrypted between the toy, WiFi access points, and Internet servers that store data or interact with the toy - are crucial to mitigate the risk of hackers exploiting the toy or eavesdropping on conversations or audio messages.

The FBI notes that Bluetooth connected toys that do not have authentication requirements (such as PINs or passwords) pose risks for unauthorized access, enabling criminals to communicate with children.

What You Can Do To Protect Your Child
  • Choose IoT toys very carefully by doing lots of research. Look for any known reported security issues regarding a toy.
  • Find out if a toy can receive firmware or software updates and security patches - and ensure the toy is running on the latest version.
  • Closely monitor your child’s activities with each toy through the toy’s parent application, if such a capability exists.
  • Ensure the toy is turned off when it is not in use.
  • Create a strong and unique login password when establishing a user account. For extra strong passwords, use lower and upper case letters, numbers and special characters.
  • Provide only what is minimally required for creating a user account.

Thursday, November 7, 2013

Silk Road, a drug & illegal services website, has somehow been reborn a month after being seized by the Feds.

The Feds may have taken down Silk Road, the online black market that's been coined the "Amazon of illegal drugs," but a little over a month later, it's re-emerged.

Not long after the bust, select users on the site received an email from a former active Silk Road user asking the community to help rebuild. The authenticity of the new forums was endorsed by former Silk Road user "Libertas."

Some users who wanted to be a part of the rebuilding gained access to "the Vendor Roundtable," a forum that outlined the details behind the launch of the new Silk Road. The administrator also called on users to volunteer for a "communication specialist" position in charge of organizing operations. "You will be assigned work to perform based on what needs to be done," read an email reviewed by CNNMoney.

Silk Road 2.0 emerged Wednesday alongside a number of other sites offering similar services.
The new Silk Road, like the original, offers everything from prescription medication to heroin.
"Silk Road is back up," a Twitter user who appears to be the owner of the new site tweeted. "Deja vu anyone? #weriseagain." The new Silk Road owner also took on the pseudonym of former leader Ross Ulbricht, Dread Pirate Roberts.

According to a former Silk Road user, the site was rebuilt by most of the major players who were heavily involved in day-to-day operations of the former site.

"Silk Road was something that had popularity that made it easy for people to continue down that path. As long as you can convince the bulk of the biggest buyers and sellers to move over to the new platform, it doesn't matter what it's called."

Before the original Silk Road was seized by the Feds, it had become one of the most sophisticated and extensive criminal marketplaces on the Internet, according to FBI Special Agent Christopher Tarbell.

But it certainly wasn't the only one. Other sites, including BlackMarket Reloaded and the Sheep Marketplace, have also been looking to attract sellers and buyers.

"Later on, newer versions that have improved in some way will pop up and regain the trust," another former Silk Road user told CNNMoney.

A priority for the reborn Silk Road is information security. The people rebuilding it are baking security measures into the site's code.

Source: CNN Money

Thursday, October 3, 2013

You can buy anything online. Apparently that includes drugs, assassins, and firearms...

According to the sealed complaint filed by the FBI, federal agents arrested Ross William Ulbricht on Tuesday afternoon, charging him with narcotics trafficking, computer hacking and money laundering.

The FBI also seized the Silk Road website, replacing its homepage with a banner noting as much.

Since its 2011 inception, Silk Road has been the go-to black market for all sorts of illegal products and services. Its draw? The online marketplace offered an easy way to find goods and services -- and transact the money in secret. The site had 957,079 registered users, according to the FBI.

The site was operated on an anonymous network known as Tor, making activity on Silk Road virtually untraceable. The only money accepted on Silk Road was the digital currency bitcoin, adding an additional layer of anonymity to buyers and sellers.

Over the past two and a half years, the FBI said the site generated revenue worth more than 9.5 million bitcoins -- valued at $1.3 billion.

The FBI said Ulbricht's net worth was essentially his value in Silk Road's commissions, which totaled more than 600,000 bitcoins ($85 million).

Silk Road wasn't restricted to illegal drugs. The FBI says it was also used to trade firearms, hire assassins and employ hackers.


Source: CNN

Thursday, July 11, 2013

The federal government has been asked to stay away from Defcon hacker event this year!

The federal government is persona non grata at this year's Defcon.

For the first time in the 21-year-history of the famed hacker's convention, government employees are being asked to stay away, albeit in a polite fashion.

Def Con founder Jeff Moss, aka The Dark Tangent, posted the following plea on the event's Web site late Wednesday:
Feds, we need some time apart.
For over two decades DEF CON has been an open nexus of hacker culture, a place where seasoned pros, hackers, academics, and feds can meet, share ideas and party on neutral territory. Our community operates in the spirit of openness, verified trust, and mutual respect.
When it comes to sharing and socializing with feds, recent revelations have made many in the community uncomfortable about this relationship. Therefore, I think it would be best for everyone involved if the feds call a "time-out" and not attend DEF CON this year.
This will give everybody time to think about how we got here, and what comes next.
The Dark Tangent
Moss, who also advises the Department of Homeland Security on security issues, told Reuters he believes the Defcon community needs some time to digest the recent leaks about U.S. surveillance programs.

"The community is digesting things that the Feds have had a decade to understand and come to terms with," Moss said. "A little bit of time and distance can be a healthy thing, especially when emotions are running high."

But Def Con won't be hiring a bunch of bouncers to throw out the Feds.

"We are not going on a witch hunt or checking IDs and kicking people out," Moss added.

Def Con has always been geared toward hackers, researchers, and other security devotees. But employees from the CIA, the FBI, the NSA, and other government branches have been welcome and have attended for many years.

General Keith Alexander, the head of National Security Agency, even gave a keynote speech at last year's event. Alexander was asked at the time whether the government was snooping on its citizens and denied that the NSA was gathering information on all Americans.

Source: CNET

Monday, June 10, 2013

Department of Justice approves Sprint & Softbank deal.

The major buyout deal between Sprint and Japanese telecommunications provider Softbank is one step closer to finalized. The U.S. Department of Justice approved the deal, handing it over for approval by the Federal Communications Commission (FCC).

In October 2012, Softbank offered Sprint $20 billion for a 70 percent stake in the company. Deal conversations were brought to a halt, however, when the concerns about national security were brought up. In March, regulators began to voice their concerns about Chinese spyware slipping into U.S. networks through the Softbank relationship. Later, in January, the DOJ, alongside the FBI and the Department of Homeland Security, launched an investigation into the deal, further stunting its process through FCC approvals.

That investigation didn't seem to rustle up much, as the DOJ approved the deal Friday in a letter the FCC. In the letter, the DOJ explained that it analyzed the “measures” Sprint and Softbank have taken to ensure national security as well as the supply chain. It’s now the FCC’s turn to green light the deal, and Softbank is seemingly confident. The company released a statement in April saying it believes the deal will be finalized by July, and that it’s deal is better than a second offer Sprint received from Dish Networks during the DOJ’s investigation.

The U.S. cable provider topped Softbank’s offer, saying it would pay $25.5 billion for majority control of the company. If Softbank’s timeline is correct, we assume we’ll hear more about Sprint’s interest in the Dish deal soon.

Source: Washington Post

Friday, May 10, 2013

FBI issues cyber security advisory that could impact all users of Microsoft Explorer 8.

Better Business Bureau (BBB) is urging all consumers and businesses to pay close attention to a Cyber Security Advisory issued by the Federal Bureau of Investigation regarding a vulnerability in Microsoft’s Internet Explorer 8 browser (IE8) that could allow scammers to access and take over users’ computers. The risk for all users – home, business and government – is high, and BBB is urging anyone with IE8 to follow the recommended steps to address the problem.

The problem was first announced yesterday, and last night Microsoft released a temporary fix.
Here is the original overview from the FBI:
“A vulnerability has been discovered in Microsoft’s web browser, Internet Explorer, which could allow an attacker to take complete control of an affected system. Exploitation may occur if a user visits or is redirected to a web page which is specifically crafted to take advantage of the vulnerability. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts may result in a denial-of-service condition.”
Microsoft today released a workaround which acts as a temporary fix. It is available at: https://support.microsoft.com/kb/2847140. The company is working on a patch to undo the vulnerability, which does not affect other versions of IE.
“BBB recommends that everyone with Internet Explorer 8 apply the temporary fix immediately,” said Ben Steinberg, Chief Information Officer of the Council of Better Business Bureaus. “If you are not sure which version you have, try running the fix. If you don’t have IE8, the fix will stop running and let you know that your system is not at risk. Microsoft will let you know when the patch is available, and you need to download that as soon as it is.”
For more details and the fix, go to: https://support.microsoft.com/kb/2847140.

Source: BBB