Showing posts with label online security. Show all posts
Showing posts with label online security. Show all posts

Tuesday, September 27, 2016

Yahoo hack: It's not just Verizon; AT&T customers should be worried too.

The massive hack that Yahoo disclosed last week is a headache for Verizon, the telecom giant set to take ownership of the company early next year.

Rival AT&T should be nervous too...

That's because many AT&T customers get the option to use a Yahoo Mail account to manage services like home broadband, wireless and pay-television services.

It's the outgrowth of a partnership from 15 years ago between Yahoo and AT&T (then called SBC Communications), bringing AT&T broadband customers to Yahoo's search engine and media services, including Yahoo Mail. At the time, critics hailed the deal as a landmark partnership that would better combat the growing power of AOL and Microsoft's MSN portal.

Today, AOL is part of Verizon, Microsoft's MSN is no more and AT&T likely isn't feeling so great about the deal.

Yahoo said Thursday that the hack compromised at least half a billion accounts containing user names, email addresses and passwords. That makes it the biggest attack ever. US Senator Mark Warner has asked the Securities and Exchange Commission to investigate the matter.                                    
The hack puts AT&T in an uncomfortable position. The company is still waiting for data from Yahoo on the specific customers who may have been affected, according to a person familiar with their dealings.

"We began investigating immediately and requested information from Yahoo necessary to determine which email accounts may have been compromised," the company said in a statement. "In the meantime, we are in the process of notifying potentially affected customers."

Chances are, a significant number of AT&T customers are affected.

AT&T was in the middle of breaking up with Yahoo before the attack, having announced in May that it would instead tap Synacor to handle its internet and mobile portal business.
The loss of the deal, worth an estimated $100 million a year, came at a time when chatter had heated up over potential suitors for Yahoo. AT&T was among the rumored bidders, but Verizon snagged the internet pioneer with a $4.8 billion offer.

For now, AT&T is offering little advice to its customers beyond the standard line: regularly change your passwords.

That, along with these other tips, is advice everyone should heed.

Wednesday, June 4, 2014

Google now testing super secure email.

It's called "End-to-End" encryption, and it's the best way to stop anyone from snooping on your emails. Google would turn your emails into jumbled code, and the only person who can see the email in plain text is the trusted person on the other end.

Hackers don't stand a chance. In fact, neither does the National Security Agency. It's the kind of encryption ex-NSA contractor Edward Snowden used to communicate with journalists before he went public last year with damning documents proving the extent of U.S. government surveillance. It's what spies use...it's that good.

But End-to-End is not available just yet. In a blog post, Google said the program is in a public testing phase. After that, you'll be able to download the app and add it to your Google Chrome Web browser. If you use the browser, it'll work with any Web-based email provider.

"We recognize that this sort of encryption will probably only be used for very sensitive messages or by those who need added protection," wrote Stephan Somogyi, a Google product manager who oversees security and privacy, in the blog. "But we hope that the End-to-End extension will make it quicker and easier for people to get that extra layer of security should they need it."

Here's how Google's super encryption would work: Imagine you want to send a sensitive letter by mail. You can't just lick the envelope shut. Postal workers might open it. But they can't open a lock.
Your friend buys a padlock, opens it and sends it to you. He keeps the key. You receive his lock, place your letter inside a box and close it with your friend's lock. You send it. Now only he can open it with his private key, which never left his possession.

Google will let you share locks, but never keys. So far, End-to-End encryption has proven tamper-proof.

This is only the latest move by Silicon Valley giants to beef up their security since last year's revelations that the U.S. government is gathering our emails and phone calls without warrants. In December, executives at the world's largest technology firms called on the U.S. government to respect Internet privacy rights, dial back its intelligence gathering and make spying programs more transparent.

Since then, Microsoft and Yahoo have been working on encrypting the information they house and transmit. Facebook CEO Mark Zuckerberg called President Obama directly to complain about the NSA. And they've all shed light on the scope of secret data requests.

Source: CNN Money

Wednesday, August 7, 2013

Do you save passwords in Google Chrome? Maybe you should reconsider...

You might want to think twice before you let someone borrow your computer.

The most obvious risk of allowing someone else access to your desktop is that they can impersonate you, using any app where you’re already signed in. They could send prank messages using your default email client, or profess your undying love for Justin Bieber using your logged-in Twitter account.

That’s annoying, but far from fatal.

But the situation becomes considerably worse if you use Google Chrome to save and sync passwords for easy logins at your favorite websites. An intruder who has unrestricted access to your computer for even a minute can view and copy all of your saved passwords just by visiting an easy-to-remember settings page: chrome://settings/passwords.

That link opens the local copy of your saved password cache, which is synchronized to every machine where you sign in with your Google account.

And the funny thing is, anyone who visits that page can see the plaintext version of every saved password just by clicking a button.

The saved password list shows the web address, username, and password for each saved set of credentials. Initially, the saved password is displayed as a row of asterisks. But if you click the masked password, you see a “Show” button that you can click to immediately display the saved password.

A malicious or spiteful intruder who can lure you away from your computer briefly can see your saved passwords, then close the settings page. And you have no idea that your credentials have been compromised.

Source: ZD Net