Hacking, Security & Privacy - Page 14
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 14
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Yahoo scanned all of your emails on behalf of the NSA
It shouldn't be surprising - but it really is, that Yahoo secretly build a custom software program to search through all of its users' incoming emails for information - all on behalf of the US intelligence sector. Yeah... Yahoo spied on your emails, before you had even read them, for the NSA, according to sources of Reuters.
Yahoo complied with classified US government demand, scanning hundreds of millions of Yahoo Mail accounts "at the behest of the National Security Agency or FBI, said three former employees and a fourth person apprised of the events", reports Reuters. The site continues: "Some surveillance experts said this represents the first case to surface of a U.S. Internet company agreeing to an intelligence agency's request by searching all arriving messages, as opposed to examining stored messages or scanning a small number of accounts in real-time".
Yahoo boss Marissa Mayer gave the order, which pissed some senior executives off to the point that in June 2015, Chief Information Security Officer Alex Stamos, left the company, joining Facebook. Yahoo said to Reuters: "Yahoo is a law abiding company, and complies with the laws of the United States". Yeah Yahoo, you sure are - a snitching little traitor (my words).
Continue reading: Yahoo scanned all of your emails on behalf of the NSA (full post)
This map shows cyber attacks in real-time
Tens of thousands of cyber attacks occur every second, but it's hard to imagine and visualize the number of attacks. Norse, a company from California that provides intelligence to many different companies, has created an interactive map where users can watch the cyber attacks in real-time.
The attacks are shown with colored lines that connect the source and the target of the attack. Norse tracks these attacks with the help of more than 8 million sensors located in 47 different countries.
The map looks really impressive, but also worrisome considering how much of our personal information and financial records are stored online.
Continue reading: This map shows cyber attacks in real-time (full post)
France's new bank cards feature ever-changing digits
French digital security company Oberthur Technologies has developed a revolutionary new bank card that should make it very difficult for fraudsters to do any damage to your account. Called Motion Code, the technology sees that three digit PIN on the back of your card change every hour for three years, meaning anyone who steals your card or acquires the digits will have minimal time to spend your money.
Most fraud occurs hours or days after cards are stolen, but no doubt the criminals will catch on and spend the money quicker upon recognizing a Motion Code card.
The downside is added difficulty in using your card remotely: no longer will you be able to memorize the PIN and use it regardless of whether you have your card on you or not. But for most, it's likely well worth it.
Continue reading: France's new bank cards feature ever-changing digits (full post)
Germany to Facebook: Stop collecting Whatsapp user data
Germany's privacy regulatory body has taken issue with Facebook collecting WhatsApp user data, ordering the company to delete the data and cease the practice, calling it "an infringement of national data protection law."
"It has to be [the user's] decision, whether they want to connect their account with Facebook," says Hamburg data protection commissioner Johnnes Caspar. "Therefore, Facebook has to ask for their permission in advance. This has not happened."
Germany -- which boasts 35 million WhatsApp users -- isn't the only European country to take issue with Facebook's approach: France and Britain have both done so, with the former stating it would monitor the situation "with great vigilance."
Continue reading: Germany to Facebook: Stop collecting Whatsapp user data (full post)
FBI boss says you should put tape over your webcam
Does your PC or laptop have a front-facing webcam? Put tape over it immediately, and treat it like locking your doors or setting up an alarm system, says FBI boss James Comey.
During the Center for Strategic and International Studies conference, Comey said: "There's some sensible things you should be doing and that's one of them. You go into any government office and we all have the little camera things that sit on top of the screen. They all have a little lid that closes down on them. You do that so that people who don't have authority don't look at you. I think that's a good thing".
We shouldn't be surprised of this warning, as Facebook CEO and founder Mark Zuckerberg was pictured with the camera on his laptop taped over. Comey has also admitted that he uses tape on his webcam.
Continue reading: FBI boss says you should put tape over your webcam (full post)
Snowden's new leak has the NSA with a secret UK spy base
Edward Snowden has leaked out some new information about the NSA having a spy base in the UK that has been intercepting satellite and other wireless communications around the world.
The base is Snowden has revealed is the Menwith Hill Station (MHS) in North Yorkshire, a 545-acre base that fronts as the Royal Air Force facility that is capable of "rapid radio relay and conduct communications research". The base had seen protestors, journalists and even terrorists interested, and now Snowden's new leak details what is happening at the base.
In a report by The Intercept, the NSA has been intercepting international communications from the base in two ways: the first is FORNSAT. FORNSAT uses the huge golf ball-shaped domes with powerful antennae to intercept transmissions between foreign satellites. The second method is called OVERHEAD, which has US government satellites finding, and monitoring smartphone calls and Wi-Fi signals on the ground.
Continue reading: Snowden's new leak has the NSA with a secret UK spy base (full post)
WhatsApp to share user data with Facebook
WhatsApp gets cozier with parent company Facebook today as it updates its privacy policy as part of a long-term plan. At some point in the months ahead, the company will begin sharing its user data with the social media giant for monetization and feature purposes. If you'd like to (mostly) opt out, follow these instructions.
Feature-wise, agreeing to the new terms will mean notifications from other services you use, like your bank when a fraudulent transaction comes up, or your airline when a flight is delayed. It also means better friend suggestions and more relevant advertising.
Continue reading: WhatsApp to share user data with Facebook (full post)
200 million Yahoo accounts hit the digital black market for $1800
A hacker named Peace has their hands-on the login credentials of 200 million Yahoo accounts, throwing them onto a dark web marketplace 'The Real Deal' for just three Bitcoins, or around $1800 USD.
Yahoo said in a statement to Motherboard that they "are aware of a claim" that Yahoo login credentials were on The Real Deal, but Yahoo has said that while it's aware of the hack, it hasn't confirmed or denied its legitimacy. Motherboard got its hands-on a sampling of the data, which includes usernames, hashed passwords, birth dates and even some backup email addresses.
The data was reportedly stolen in 2012, with the hacker adding they have traded the data privately for a while, but only decided to put it on the market recently. Yahoo hasn't pushed out a mandatory password reset announcement, which is definitely strange.
Continue reading: 200 million Yahoo accounts hit the digital black market for $1800 (full post)
US government requests for user data from Google reaches a new high
The US government requested a new record of user data from Google in the second half of 2016, with 40,677 requests impacting as many as 81,311 user accounts, reports ZDNet.
From July through to December 2015, the US government requested the 40.677 requests, an 18% increase from the first half of the year. Most of the requests are coming from the US, with 12,523 data requests in the three-month period, with requests impacting 27,157 users or accounts.
Google says it has been reporting the number of user data requests in a 6-month period going back to the second half of 2009, while it has been detailing the users and accounts it has impacted in the first half of 2011. Google notes: "Usage of our services have increased every year, and so have the user data request numbers".
Continue reading: US government requests for user data from Google reaches a new high (full post)
Facebook rolls out 'Secret Conversations' feature
Privacy is a perpetual concern with Facebook and Facebook Messenger, but it gets a little less so today as the company rolls out its 'Secret Conversations' feature.
Secret Conversations means you can create a conversation with someone that can only be seen by you and on the device of the person you're talking to, as opposed to Facebook or any potential hackers. As well, you can set your messages to disappear within a set amount of time.
As for downsides, you have to take extra action to start such a conversation, you can't view the conversation on multiple devices like you can currently, and fancy features like GIFs, videos, payments aren't supported.
Continue reading: Facebook rolls out 'Secret Conversations' feature (full post)
Mark Zuckerberg's Twitter, Pinterest accounts hacked
Even social media CEOs are susceptible to being hacked, it seems. Over the weekend, a couple of Facebook founder Mark Zuckerberg's social media accounts were compromised by Saudi Arabian hacking group OurMine Team.
OurMine is said to have found Zuckerberg's information in a recent LinkedIn dump, which they then used to gain control of his Twitter and Pinterest accounts. The group claims his password for both accounts was the surprisingly simple 'dadada', but there's reason to be skeptical of this as it also claimed it had overtaken his Instagram account, which Facebook has denied.
Both the Twitter and Pinterest account haven't been terribly active, at least not recently; Zuckerberg's Instagram account hasn't been too active either, although it has been used on a regular basis and multiple times in the last week.
Continue reading: Mark Zuckerberg's Twitter, Pinterest accounts hacked (full post)
Congress is finally investigating SS7 mobile network security flaw
Cellular networks are already pretty insecure as they are. Voice is sent unencrypted and in the clear despite having the necessary hardware to support even light encryption methods. Spoofing cellular towers, too, isn't exactly the most difficult thing to do either, but that's small potatoes compared to a vulnerability in the Signalling System No. 7 telephony protocol that can allow a potential malefactor to track you across the globe, with relative ease. Congress is now taking an interest and investigating these vulnerabilities.
The interest in the issue began with the airing of a 60 Minutes piece where Sharyn Alfonsi and a German computing enthusiast who specializes in nefarious programming techniques, showed off just how easy it is to exploit the SS7 protocol to track cellphone users. To demonstrate their point, the pair recruited US Representative Ted Lieu and asked him to use a new, not modified, iPhone when conducting staff phone calls. With just the phone number, they were able to pinpoint the location of the US Representative wherever he had the phone, and they were even able to record conversations he was having as well. It apparently didn't take much effort on the part of the researchers, either.
Mr. Lieu, following the demonstration he took part in, called for an official full investigation into the matter so that the vulnerabilities can be addressed. The flaw is something that potentially affects quite a few different markets, within the US and abroad, which could pose serious privacy issues. Not to mention if someone should use the flaw to target individuals as part of pre-meditated actions.
Continue reading: Congress is finally investigating SS7 mobile network security flaw (full post)
WhatsApp enables end-to-end encryption
One month after publicly supporting Apple in its fight for encryption, chat app company WhatsApp now features end-to-end encryption in its client. In essence, whether you're calling someone, sending a file, messaging, hosting a group chat, or anything else, you can be rest assured it's completely private from hackers, WhatsApp, and anyone else you might be paranoid about.
"We live in a world where more of our data is digitized than ever before," company CEO and founder Jan Koum says of the change. "Every day we see stories about sensitive records being improperly accessed or stolen. And if nothing is done, more of people's digital information and communication will be vulnerable to attack in the years to come. Fortunately, end-to-end encryption protects us from these vulnerabilities."
"Encryption is one of the most important tools governments, companies, and individuals have to promote safety and security in the new digital age," he continues. "Recently there has been a lot of discussion about encrypted services and the work of law enforcement. While we recognize the important work of law enforcement in keeping people safe, efforts to weaken encryption risk exposing people's information to abuse from cybercriminals, hackers, and rogue states."
Continue reading: WhatsApp enables end-to-end encryption (full post)
The FBI doesn't need to tell Apple how it broke into the iPhone 5C
We reported yesterday that the FBI had broken into the iPhone 5C used by the San Bernardino shooter, without Apple's help. It's now being reported that Appel can't force the FBI to disclose just how it broke into their smartphone.
The FBI reportedly tapped the help of an Israeli security firm, which broke into the iPhone 5C, and with Apple unable to force the FBI to show them how they did that, it could mean that other iPhones could be broken into. Why? Because Apple can't fix the security hole that the FBI went through - mainly for iPhone users, but it's obviously a hole that Apple don't know about, or at least they don't know which method the FBI used. It's quite scary there's an easy hole for a company that's not Apple, nor the FBI, can use to break into iPhones - quite easily, it seems.
Ars Technica talked with a law enforcement official, who said: "We cannot comment on the possibility of future disclosures to Apple. [There] are legitimate pros and cons to the decision to disclose, and the trade-offs between prompt disclosure and withholding knowledge of some vulnerabilities for a limited time can have significant consequences," he said while explaining the Vulnerabilities Equities Process". So, there's no legal requirement of the FBI to disclose how it broke through Apple's much-touted security... well now.
Continue reading: The FBI doesn't need to tell Apple how it broke into the iPhone 5C (full post)
Microsoft, Google, Yahoo, Comcast working on better email encryption
Encryption is a very pertinent issue in the modern age. We're at an impasse where certain individuals and groups would rather encryption be the stuff of history, perhaps even segregating encryption strengths like was common during the 80's and 90's. Email encryption isn't exactly the easiest thing to setup and requires a bit of preparation to do right. It can be cumbersome even to those that know what they're doing. A group of tech companies and independent researchers have gotten together to help make encryption of your emails easier, and much more seamless.
The new protocol that has been proposed is called SMTP STS, or Simple Mail Transfer Protocol Strict Transport Security, and is designed to ensure a secure, encrypted connection with email servers. It's not a method of encrypting your emails themselves, which would be best served by any free, or paid, PGP solution, but it adds a measure of security to email that helps to make sure that you're messages are at leat going through real, authentic mail servers to get to their destination.
What it does is talk those email servers that it's traveling through to determine whether or not the connection is secure and that it's who they say they are. If the server can be authenticated (through the use of certificates and a TLS encryption-based connection), then your message will pass along, knowing that at least that server is legit. If no encryption can be used, then there's the option that the message won't be sent.
Continue reading: Microsoft, Google, Yahoo, Comcast working on better email encryption (full post)
Amazon will restore encryption to Fire OS 5 in future update
Last week it became apparent Amazon had not included support for local encryption with Fire OS 5, which would seem to contradict its support of Apple's fight for encryption. Asked for comment on exactly that and why they would drop support when it seems all the work is done by Google anyway, an Amazon spokesperson simply told us, "We will return the option for full disk encryption with a Fire OS update coming this spring."
Amazon initially said its customers "weren't using" local encryption, so it decided not to include support for it, which appeared flimsy reasoning. Whatever the case, the company has wisely decided to change course, likely in light of how it looks currently.
Continue reading: Amazon will restore encryption to Fire OS 5 in future update (full post)
The first OS X ransomware is here, holds your Mac hostage
For what feels like forever, Windows users have been at the butt of attacks from Mac users when it comes to "but Windows is open, and gets hit by viruses, malware, and ransomware all the time". Well, that might be something of the past now.
Palo Alto Networks is claiming it's discovered the first known OS X-based ransomware, known as "KeRanger". How do you get it? You download software infected with the nasty code, with BitTorrent client Transmission, where it will encrypt your files after 72 hours, after which it'll demand that you hand over digital currency ransom to get your files back. Nice.
The latest version of Transmission, alongside Apple revoking a security certificate from another developer that KeRanger used to get past OS X's built-in defenses, should keep you safe. But, this should act as a warning: OS X isn't as safe as most people think it is, and this could be the tip of the iceberg in the months, and years to come.
Continue reading: The first OS X ransomware is here, holds your Mac hostage (full post)
State of the Internet says DDoS attacks are up 149% compared to Q3
The State of the Internet report has been released for the fourth quarter of 2015 and it highlights some of the more malicious trends coming from across the Internet. The short of it is, the volume of attacks against websites has increased through nearly every avenue than compared to the third quarter.
DDoS's in particular have seen quite the massive increase since last quarter, with a 148.85% increase in overall occurrences. The bright side is that duration seems to have been shortened, probably due to the pay-per-play nature of the services that seem to be the most used. But that didn't stop those sites from being targeted multiple times, up to 24 times in some cases. The good news is that the actual number of packets sent was lower. How very nice of these attackers.
Size of attacks seemed to be below 30Mbps, with only four that exceeded that amount and two that peaked even higher. The biggest were at around 309Gpps with 202Mpps (packets per second).That's actually a small decline in the number of big attacks, but 44.44%. But the interesting part is that the majority of attacks, some 54.45% of all the DDoS activity was focused on the gaming sector. People are getting more and more mad during and after online matches, preventing people, servers and games themselves from working right. Not to mention the massive attack on Xbox Live and the PlayStation Network.
Continue reading: State of the Internet says DDoS attacks are up 149% compared to Q3 (full post)
Amazon's Fire OS 5 dropped local encryption
Amazon's Fire OS 5 came out in September, but only now is it being discovered that the operating system no longer supports local encryption (which makes data accessible only with a passcode or key). Concerns have arisen as a result, given Amazon just filed a brief supporting Apple's defense of encryption.
Fire OS is built on Android's open-source code, which has offered local encryption for years. Fire OS 5 doesn't support the feature it turns out, and Amazon's statement on why doesn't help clear matters up much.
Continue reading: Amazon's Fire OS 5 dropped local encryption (full post)
Facebook, Google, Amazon, Yahoo file brief in support of encryption
Yesterday, Twitter, Reddit, and 15 other tech companies collectively filed an amicus brief in support of Apple and its defense of smartphone encryption. For reason unclear, other giants like Microsoft and Facebook -- which have publicly announced their support -- were not included. However, they have filed their own separate brief with the same goal.
Microsoft President and CLO Brad Smith writes in a blog post of the case, "The fact that we're discussing the All Writs Act across the country is a telling indication of the urgent need to update antiquated rules that govern digital technology and privacy. If we are to protect personal privacy and keep people safe, 21st century technology must be governed by 21st century legislation. What's needed are modern laws passed by our elected representatives in Congress, after a well-informed, transparent, and public debate."
He later continues, "We've reached a critical moment in which a new generation of mobile and cloud-based technologies have far outrun the laws that protect our safety and preserve our timeless and fundamental rights. By standing with Apple, we're standing up for customers who depend on us to keep their most private information safe and secure."
Continue reading: Facebook, Google, Amazon, Yahoo file brief in support of encryption (full post)


