Technology content trusted in North America and globally since 1999
7,637 Reviews & Articles | 56,410 News Posts

Hacking & Security Posts - Page 2

Microsoft, Google, Yahoo, Comcast working on better email encryption

By: Jeff Williams | More News: Hacking & Security | Posted: Mar 21, 2016 10:03 pm

Encryption is a very pertinent issue in the modern age. We're at an impasse where certain individuals and groups would rather encryption be the stuff of history, perhaps even segregating encryption strengths like was common during the 80's and 90's. Email encryption isn't exactly the easiest thing to setup and requires a bit of preparation to do right. It can be cumbersome even to those that know what they're doing. A group of tech companies and independent researchers have gotten together to help make encryption of your emails easier, and much more seamless.




The new protocol that has been proposed is called SMTP STS, or Simple Mail Transfer Protocol Strict Transport Security, and is designed to ensure a secure, encrypted connection with email servers. It's not a method of encrypting your emails themselves, which would be best served by any free, or paid, PGP solution, but it adds a measure of security to email that helps to make sure that you're messages are at leat going through real, authentic mail servers to get to their destination.


What it does is talk those email servers that it's traveling through to determine whether or not the connection is secure and that it's who they say they are. If the server can be authenticated (through the use of certificates and a TLS encryption-based connection), then your message will pass along, knowing that at least that server is legit. If no encryption can be used, then there's the option that the message won't be sent.

Continue reading 'Microsoft, Google, Yahoo, Comcast working on better email encryption' (full post)

State of the Internet says DDoS attacks are up 149% compared to Q3

By: Jeff Williams | More News: Hacking & Security | Posted: Mar 6, 2016 6:16 pm

The State of the Internet report has been released for the fourth quarter of 2015 and it highlights some of the more malicious trends coming from across the Internet. The short of it is, the volume of attacks against websites has increased through nearly every avenue than compared to the third quarter.




DDoS's in particular have seen quite the massive increase since last quarter, with a 148.85% increase in overall occurrences. The bright side is that duration seems to have been shortened, probably due to the pay-per-play nature of the services that seem to be the most used. But that didn't stop those sites from being targeted multiple times, up to 24 times in some cases. The good news is that the actual number of packets sent was lower. How very nice of these attackers.


Size of attacks seemed to be below 30Mbps, with only four that exceeded that amount and two that peaked even higher. The biggest were at around 309Gpps with 202Mpps (packets per second).That's actually a small decline in the number of big attacks, but 44.44%. But the interesting part is that the majority of attacks, some 54.45% of all the DDoS activity was focused on the gaming sector. People are getting more and more mad during and after online matches, preventing people, servers and games themselves from working right. Not to mention the massive attack on Xbox Live and the PlayStation Network.

Amazon removed device encryption from newest Fire OS

By: Jeff Williams | More News: Hacking & Security | Posted: Mar 4, 2016 2:00 pm

Amazon seems to be moving in the opposite direction of the other big mobile companies that are looking to strengthen their devices security. The latest Fire OS is removing support for encryption starting with version 5.0.




The OS that Amazon uses is a fork of the Android Open Source Project, but it takes out any compatibility with Google's own apps even though it relies heavily on the underlying architecture. Notably missing now, is full device encryption, something that's been greatly improved (and mandatory on some classes of devices) with the release of Marshmallow. Apparently the option of encryption just wasn't used very much by their user-base.


What this means is that the anything that you put on it won't be automatically encrypted, making the storage open to attackers who wish to sync or connect directly to the tablet. To be clear, it only applies to anything on the tablet that's being stored. SSL/TLS connections and communication with Amazon's AWS for your cloud content is still just as safe as ever, and your content in the cloud is likely to be encrypted at rest on their servers, as well, which is quickly becoming the standard.

Continue reading 'Amazon removed device encryption from newest Fire OS' (full post)

Sea pirates are embracing the future, hacking shipping companies

By: Jeff Williams | More News: Hacking & Security | Posted: Mar 2, 2016 5:00 pm

Pirating just became a whole lot easier thanks to the Internet. A group of sea-going pirates were able to hack into the content management system of a shipping company to pinch the shipping manifests and schedule to better plan their brazen heists.




According to a new security report by Verizon, the Internet, and hacking in general, is becoming an ever increasing resource for the seafaring thieves. Based on the evidence, however, it appears that the pirates themselves are carrying out the attacks because of the sloppy way in which they're going about it. It's proven easy to trace the activity completely to its source.


Pirating is evolving. It once was a primarily physical activity, but now they're becoming more efficient and careful. Why waste resources physically looking for ships on the open sea when you can just track precisely where they'll be by taking a look at the schedule. It's a bold move, especially when they don't seem to care that they get caught. Their mobile nature makes that point moot anyhow

Critical DNS flaw found, allows attackers to get full control

By: Jeff Williams | More News: Hacking & Security | Posted: Feb 22, 2016 9:59 pm

The DNS system that forms the backbone of the Internet, resolving those names into the numbers that correspond to the actual websites we visit, has a critical flaw that effects nearly all DNS servers. That is, any server that runs Linux and relies on the GNU C standard library. A flaw in that library could case a buffer overflow, which might allow an attacker to take full control over someone's PC.




The flaw itself is actually from 2008, where it was discovered that overly long DNS names being replied to requests from those servers could result in a tragic buffer overflow in the victims browser, potentially letting an attacker execute code remotely. It's even possible to perform a full-blow man-in-the-middle attack, taking over a machine completely. It can be triggered by already malicious DNS servers.


Thankfully a fix is already ready fro most distributions of Linux, which requires only a quick update to fix. If your server distro isn't running one, then you can configure your firewall to drop long DNS responses altogether, so no overflows happen. So the majority of the Internet is largely safe, but it still might effect smaller connected and embedded devices that have Glibc that likely won't see any updates with the patched version. Routers, DVR's, some TV's and even NAS devices might still and continue to be at risk.

Synaptics fingerprint sensor so small it fits on a volume rocker

By: Jeff Williams | More News: Hacking & Security | Posted: Feb 22, 2016 4:03 pm

Synaptics has a new fingerprint sensor that could make it that much more useful and widespread. They've been able to shrink the dimensions so much that it can be placed on side-mounted buttons or any tiny area on any device. And it's accurate too.




The minuscule Natural ID FS4304 touch-based fingerprint sensor is a scant 3.5mm wide allowing it to be placed on nearly anything. Imagine a more natural interaction with your phone, putting your fingers where they naturally lay, such as on the side of the device, and being able to unlock it more convenient. That might seem silly, but it leads to making biometrics something that can secure anything.


It also has the potential to make fingerprint readers more discreet, drawing attention away from attempting to spoof and bypass them, which is possible with enough resources (though not always successful unless under the right conditions). As we've explained here before, as part of a multi-factor authentication scheme, using your fingerprint as a biometric is one of the better and more convenient options. Unfortunately facial recognition and iris scanning isn't commonplace enough yet.

W3C launching new open authentication standard for the Internet

By: Jeff Williams | More News: Hacking & Security | Posted: Feb 17, 2016 6:02 pm

Passwords are quickly becoming an archaic creation in the minds of many a security researcher. There're definitely better, more secure and easier to use ways to authenticate yourself and login to your favorite sites. The World Wide Web Consortium (W3C) wants to change with a new open standard to help make the Internet just a little bit more secure. And not too terribly more complicated either.




The password itself is usually the weakest link in any secure system. Most people don't want to put int the required effort to create a properly complex password, or they don't follow proper password etiquette and change them, substantially enough, at regular intervals. And really, who wants to have a super long password anyway. Sometimes even strong passwords get exposed and added to rainbow tables, rendering them absolutely useless anyway. So what does one do?


Make multi-factor authentication a thing, and a common, easy to use thing at that. That's what the W3C intends to do with their FIDO 2.0 based authentication standard. They want to make an API easy for web developers to implement that can allow for many different types of authentication.

Continue reading 'W3C launching new open authentication standard for the Internet' (full post)

Martin Shkreli has $15m of Bitcoin scammed over Kanye album promise

By: Chris Smith | More News: Hacking & Security | Posted: Feb 17, 2016 3:33 pm

A scammer has stolen $15 million worth of Bitcoins from one of the internet's most 'un-loved' celebrities, pharmaceutical man Martin Shkreli. Contacting Shkreli and pretending to be part of Kanye West's entourage, a scammer promised an early release of West's new album 'Life of Pablo' to Shkreli personally, setting the price at a hefty 37,000 Bitcoin.




Taking to Twitter in order to voice his frustrations over getting scammed, Shkreli claims to now have "quit rap," stating that "This is the worst day of my life. My mom said don't deal with these kinds of people. Nothing good comes from rap music."


Seemingly having some friends in high places, Shkreli told all of his followers that they are 'idiots' and he has "gotten in touch with Sitoshi (Bitcoin's creator) and he's agreed to help me get my money back. I always win." He ended his Tweet tirade by announcing that "And second of all I can make the money back faster than anyone so the joke is on YOU if you think I even care."

Continue reading 'Martin Shkreli has $15m of Bitcoin scammed over Kanye album promise' (full post)

Anonymous claims hacker released 17.8GB of files from Turkey police

By: Chris Smith | More News: Hacking & Security | Posted: Feb 17, 2016 2:32 pm

Believed to be 'ROR[RG]', this hacker has been named by Anonymous as a person to successfully infiltrate Turkish national police servers, stealing private information that includes a multitude of database files.




The files have been explained as related to MySQL by International Business Times, known to be so as they are mostly presented in .myd, .myi and .frm file extensions. Available as a 2GB torrent file online, once extracted the data becomes a large 17.8GB cache of illegally-gathered information.


This breach was announced by 'TheCthulhu', further using its official Twitter account to announce "Hey #Turkey, I have something to show you tomorrow. See, if you fight your citizens, they will bite back. #standby." This isn't ROR[RG]'s first operation, being known as the hacker to infiltrate Adult Friend Finder back in 2015, releasing personal information regarding four million members.

Continue reading 'Anonymous claims hacker released 17.8GB of files from Turkey police' (full post)

Hack-proof RFID chips to protect credit cards and more in the future

By: Jeff Williams | More News: Hacking & Security | Posted: Feb 15, 2016 4:05 pm

RFID is a cheap and convenient way to communicate information between devices. The problem is that it's also incredible insecure, and easily hacked by a number of ways. But researchers from Texas Instruments and MIT have come together to make a chip that won't be so easy to steal information from.




The implications for such a development are tremendous, with the idea that the public will finally start to trust the technology for more applications. Specifically they're being designed to be nearly impervious to a common attack on RFID devices, the side-channel attack. Those work by analyzing actual power fluctuations or memory access patterns in order to determine what the cryptographic key is, to break in and steal your precious information.


The new chip doesn't prevent the reading of those physical properties, because that would mean it doesn't work at all, but instead uses a a special ferroelectric crystal material that can self-power the chip to keep them small and to prevent people from cutting the power right before a cryptographic key exchange, which can reveal that key if done properly. They'll also incorporate a random number generator on-board to use a new secret key for each transaction, meaning that each one is completely unique, and thus far safer and more secure than ever before.

Continue reading 'Hack-proof RFID chips to protect credit cards and more in the future' (full post)