Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 15

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 15

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

Amazon removed device encryption from newest Fire OS

| Mar 4, 2016 8:00 AM CST

Amazon seems to be moving in the opposite direction of the other big mobile companies that are looking to strengthen their devices security. The latest Fire OS is removing support for encryption starting with version 5.0.

The OS that Amazon uses is a fork of the Android Open Source Project, but it takes out any compatibility with Google's own apps even though it relies heavily on the underlying architecture. Notably missing now, is full device encryption, something that's been greatly improved (and mandatory on some classes of devices) with the release of Marshmallow. Apparently the option of encryption just wasn't used very much by their user-base.

What this means is that the anything that you put on it won't be automatically encrypted, making the storage open to attackers who wish to sync or connect directly to the tablet. To be clear, it only applies to anything on the tablet that's being stored. SSL/TLS connections and communication with Amazon's AWS for your cloud content is still just as safe as ever, and your content in the cloud is likely to be encrypted at rest on their servers, as well, which is quickly becoming the standard.

Continue reading: Amazon removed device encryption from newest Fire OS (full post)

US Secretary of Defense sides with Apple in encryption debate

| Mar 3, 2016 6:02 PM CST

Not all figures within the US government oppose encryption, today shows.

Secretary of Defense Ashton Carter made his position on the matter clear today at the RSA 2016 security conference, stating, "I'm not a believer in backdoors. It's not realistic and it's not technically accurate," later continuing, "[The Department of Defense is] not in the executive branch seeking legislation of this kind. I don't think writing a law without an exploration of all the technical solutions out there [is a good idea]."

He also isn't a fan of implementing "a law written by people [without tech expertise] or written in an atmosphere of anger and grief" and feels that one case shouldn't "drive the solution."

Continue reading: US Secretary of Defense sides with Apple in encryption debate (full post)

Sea pirates are embracing the future, hacking shipping companies

| Mar 2, 2016 11:00 AM CST

Pirating just became a whole lot easier thanks to the Internet. A group of sea-going pirates were able to hack into the content management system of a shipping company to pinch the shipping manifests and schedule to better plan their brazen heists.

According to a new security report by Verizon, the Internet, and hacking in general, is becoming an ever increasing resource for the seafaring thieves. Based on the evidence, however, it appears that the pirates themselves are carrying out the attacks because of the sloppy way in which they're going about it. It's proven easy to trace the activity completely to its source.

Pirating is evolving. It once was a primarily physical activity, but now they're becoming more efficient and careful. Why waste resources physically looking for ships on the open sea when you can just track precisely where they'll be by taking a look at the schedule. It's a bold move, especially when they don't seem to care that they get caught. Their mobile nature makes that point moot anyhow

Continue reading: Sea pirates are embracing the future, hacking shipping companies (full post)

New York judge rules Apple can't be forced to hack phone for drug case

| Mar 1, 2016 7:04 PM CST

A landmark decision has been reached in the ongoing data encryption war. A US magistrate judge in New York, presiding over a drug trafficking case, has ruled Apple cannot be forced to unlock an iPhone by the US government, which has been using the more than 100 year-old All Writs Act (AWA) as part of its argument. While this doesn't directly involve the bigger San Bernardino terrorism case, it's a big win for Apple and smartphone users in general who support their right to encryption, and will certainly help its argument in that case.

"The established rules for interpreting a statute's text constrain me to reject the government's interpretation that the AWA empowers a court to grant any relief not outright prohibited by law," magistrate Judge James Orenstein stated in his order.

In other words, the government overstepped its bounds in its interpretation of the AWA. Orenstein went on to conclude this is a congressional issue.

Continue reading: New York judge rules Apple can't be forced to hack phone for drug case (full post)

Tech giants to file brief supporting Apple in encryption battle

| Feb 26, 2016 1:17 PM CST

Apple today asked a judge to throw out the order requiring it to hack the phone of an attacker in the San Bernardino case and followed it up with a request of its own: that its peers stand behind it to fight for privacy.

That's happened with Microsoft, whose President and Chief Legal Officer Brad Smith declared in a congressional hearing yesterday his company's "wholehearted" support of Apple's position, and that it would file an amicus brief next week to that end. (An amicus brief is a filing that allows those not directly involved in a case to have their say in it.)

Twitter has confirmed to us they "expect to be on a brief supporting Apple" and that the "filing deadline is Wednesday."

Continue reading: Tech giants to file brief supporting Apple in encryption battle (full post)

New iPhone security measures give Apple upper hand in encryption war

| Feb 25, 2016 5:04 PM CST

Sources close to the company and security experts are saying Apple is currently working on upgrading its iPhone security measures, which would shield them from potential win by the government in the ongoing encryption war. It's said they've been working on it since before the San Bernardino attack.

The new security would be configured in such a way that a backdoor couldn't be created for it at the government's request (as is currently the case). Specifically, it addresses the vulnerability introduced by the troubleshooting system that allows Apple to update system software without a password. Once the new security in place, the government could request all it likes: Apple wouldn't be able to oblige even if it wanted to.

Experts believe Apple will be able to go through with it. Should the government win the fight, it's expected a new round of court battles would begin, at which point Apple may introduce yet more security measures, and round and round we go. In other words, Apple currently has the upper hand and will for the foreseeable future, barring Congress involvement.

Continue reading: New iPhone security measures give Apple upper hand in encryption war (full post)

Microsoft puts support behind public's right to smartphone encryption

| Feb 23, 2016 8:05 PM CST

Last week, Facebook joined the ranks of Google, Twitter, and Apple in publicly supporting one's right to smartphone encryption amidst the San Bernardino terrorist case. This left some to wonder where Microsoft was in all of this, so we inquired with the tech giant, who pointed us to a tweet by Microsoft President and CLO Brad Smith (retweeted by CEO Satya Nadella), indicating it does indeed support encryption (via the Reform Government Surveillance coalition).

The full statement reads as follows: "Reform Government Surveillance companies believe it is extremely important to deter terrorists and criminals and to help law enforcement by processing legal orders for information in order to keep us all safe. But technology companies should not be required to build in backdoors to the technologies that keep their users' information secure. RGS companies remain committed to providing law enforcement with the help it needs while protecting the security of their customers and their customers' information."

Continue reading: Microsoft puts support behind public's right to smartphone encryption (full post)

FBI ordered password reset on attacker's phone in San Bernardino case

| Feb 22, 2016 8:05 PM CST

The plot has thickened in the San Bernardino terrorist case, as it's been revealed the FBI ordered the Apple ID password on the attacker's phone be reset. The order has given rise to questions about the FBI's competence.

It started when Apple urged authorities to plug the phone of the attacker (Syed Farook) into an outlet in his office, thus triggering an iCloud backup and providing access to the desired data. However, prior to this, the FBI ordered the Apple ID password be reset.

Apple confirmed this in a new FAQ on its website, which addressed the incident as well as other questions that have arisen about the case and the company's stance on encryption.

Continue reading: FBI ordered password reset on attacker's phone in San Bernardino case (full post)

Critical DNS flaw found, allows attackers to get full control

| Feb 22, 2016 3:59 PM CST

The DNS system that forms the backbone of the Internet, resolving those names into the numbers that correspond to the actual websites we visit, has a critical flaw that effects nearly all DNS servers. That is, any server that runs Linux and relies on the GNU C standard library. A flaw in that library could case a buffer overflow, which might allow an attacker to take full control over someone's PC.

The flaw itself is actually from 2008, where it was discovered that overly long DNS names being replied to requests from those servers could result in a tragic buffer overflow in the victims browser, potentially letting an attacker execute code remotely. It's even possible to perform a full-blow man-in-the-middle attack, taking over a machine completely. It can be triggered by already malicious DNS servers.

Thankfully a fix is already ready fro most distributions of Linux, which requires only a quick update to fix. If your server distro isn't running one, then you can configure your firewall to drop long DNS responses altogether, so no overflows happen. So the majority of the Internet is largely safe, but it still might effect smaller connected and embedded devices that have Glibc that likely won't see any updates with the patched version. Routers, DVR's, some TV's and even NAS devices might still and continue to be at risk.

Continue reading: Critical DNS flaw found, allows attackers to get full control (full post)

Synaptics fingerprint sensor so small it fits on a volume rocker

| Feb 22, 2016 10:03 AM CST

Synaptics has a new fingerprint sensor that could make it that much more useful and widespread. They've been able to shrink the dimensions so much that it can be placed on side-mounted buttons or any tiny area on any device. And it's accurate too.

The minuscule Natural ID FS4304 touch-based fingerprint sensor is a scant 3.5mm wide allowing it to be placed on nearly anything. Imagine a more natural interaction with your phone, putting your fingers where they naturally lay, such as on the side of the device, and being able to unlock it more convenient. That might seem silly, but it leads to making biometrics something that can secure anything.

It also has the potential to make fingerprint readers more discreet, drawing attention away from attempting to spoof and bypass them, which is possible with enough resources (though not always successful unless under the right conditions). As we've explained here before, as part of a multi-factor authentication scheme, using your fingerprint as a biometric is one of the better and more convenient options. Unfortunately facial recognition and iris scanning isn't commonplace enough yet.

Continue reading: Synaptics fingerprint sensor so small it fits on a volume rocker (full post)

Facebook joins Google, Twitter, Apple in defense of encryption

| Feb 19, 2016 11:58 PM CST

Tech giants Google, Twitter, and Apple have publicly denounced the FBI's fight to get around phone encryption, favoring the privacy rights of their users instead. Now Facebook is hopping on board, too.

"We will continue to fight aggressively against requirements for companies to weaken the security of their systems," a Facebook spokesperson told Reuters yesterday. "These demands would create a chilly precedent and obstruct companies' efforts to secure their products."

That makes four for four. Microsoft is the biggest tech company to not yet comment on the issue; to that end, we've put in in an inquiry, and will report if we hear back.

Continue reading: Facebook joins Google, Twitter, Apple in defense of encryption (full post)

Google CEO sides with Apple on encryption debate

| Feb 18, 2016 7:00 PM CST

Yesterday, Apple CEO Tim Cook published an open letter to the company's customers, explaining why Apple feels so strongly about supporting one's right to data encryption and privacy. Shortly afterward, Google CEO Sundar Pichai chimed in on Twitter, describing the letter as "important" before siding with Cook.

"Forcing companies to enable hacking could compromise users' privacy," he writes. "We know that law enforcement and intelligence agencies face significant challenges in protecting the public against crime and terrorism. We build secure products to keep your information safe and we give law enforcement access to data based on valid legal orders, but that's wholly different than requiring companies to enable hacking of customer devices & data. Could be a troubling precedent. [I'm] looking forward to a thoughtful and open discussion on this important issue."

Continue reading: Google CEO sides with Apple on encryption debate (full post)

FBI orders Apple to build iPhone backdoor, Cook explains why it won't

| Feb 17, 2016 3:04 PM CST

As the phone encryption debate rages on, Apple CEO Tim Cook has published an open letter to the company's customers, detailing in full its stance on the personal right to privacy. The letter comes shortly after the US government has ordered Apple unlock phones at its discretion for criminal and intelligence purposes, which Apple has opposed.

Disconcertingly, the feds are employing the use of the 227 year-old All Writs Act -- which says courts can "issue all [written orders] necessary or appropriate in aid of their respective jurisdictions and agreeable to the usages and principles of law" -- in a bid to win its case.

"We were shocked and outraged by the deadly act of terrorism in San Bernardino last December," writes Cook. "We mourn the loss of life and want justice for all those whose lives were affected. The FBI asked us for help in the days following the attack, and we have worked hard to support the government's efforts to solve this horrible crime. We have no sympathy for terrorists.

Continue reading: FBI orders Apple to build iPhone backdoor, Cook explains why it won't (full post)

W3C launching new open authentication standard for the Internet

| Feb 17, 2016 12:02 PM CST

Passwords are quickly becoming an archaic creation in the minds of many a security researcher. There're definitely better, more secure and easier to use ways to authenticate yourself and login to your favorite sites. The World Wide Web Consortium (W3C) wants to change with a new open standard to help make the Internet just a little bit more secure. And not too terribly more complicated either.

The password itself is usually the weakest link in any secure system. Most people don't want to put int the required effort to create a properly complex password, or they don't follow proper password etiquette and change them, substantially enough, at regular intervals. And really, who wants to have a super long password anyway. Sometimes even strong passwords get exposed and added to rainbow tables, rendering them absolutely useless anyway. So what does one do?

Make multi-factor authentication a thing, and a common, easy to use thing at that. That's what the W3C intends to do with their FIDO 2.0 based authentication standard. They want to make an API easy for web developers to implement that can allow for many different types of authentication.

Continue reading: W3C launching new open authentication standard for the Internet (full post)

Martin Shkreli has $15m of Bitcoin scammed over Kanye album promise

| Feb 17, 2016 9:33 AM CST

A scammer has stolen $15 million worth of Bitcoins from one of the internet's most 'un-loved' celebrities, pharmaceutical man Martin Shkreli. Contacting Shkreli and pretending to be part of Kanye West's entourage, a scammer promised an early release of West's new album 'Life of Pablo' to Shkreli personally, setting the price at a hefty 37,000 Bitcoin.

Taking to Twitter in order to voice his frustrations over getting scammed, Shkreli claims to now have "quit rap," stating that "This is the worst day of my life. My mom said don't deal with these kinds of people. Nothing good comes from rap music."

Seemingly having some friends in high places, Shkreli told all of his followers that they are 'idiots' and he has "gotten in touch with Sitoshi (Bitcoin's creator) and he's agreed to help me get my money back. I always win." He ended his Tweet tirade by announcing that "And second of all I can make the money back faster than anyone so the joke is on YOU if you think I even care."

Continue reading: Martin Shkreli has $15m of Bitcoin scammed over Kanye album promise (full post)

Anonymous claims hacker released 17.8GB of files from Turkey police

| Feb 17, 2016 8:32 AM CST

Believed to be 'ROR[RG]', this hacker has been named by Anonymous as a person to successfully infiltrate Turkish national police servers, stealing private information that includes a multitude of database files.

The files have been explained as related to MySQL by International Business Times, known to be so as they are mostly presented in .myd, .myi and .frm file extensions. Available as a 2GB torrent file online, once extracted the data becomes a large 17.8GB cache of illegally-gathered information.

This breach was announced by 'TheCthulhu', further using its official Twitter account to announce "Hey #Turkey, I have something to show you tomorrow. See, if you fight your citizens, they will bite back. #standby." This isn't ROR[RG]'s first operation, being known as the hacker to infiltrate Adult Friend Finder back in 2015, releasing personal information regarding four million members.

Continue reading: Anonymous claims hacker released 17.8GB of files from Turkey police (full post)

Hack-proof RFID chips to protect credit cards and more in the future

| Feb 15, 2016 10:05 AM CST

RFID is a cheap and convenient way to communicate information between devices. The problem is that it's also incredible insecure, and easily hacked by a number of ways. But researchers from Texas Instruments and MIT have come together to make a chip that won't be so easy to steal information from.

The implications for such a development are tremendous, with the idea that the public will finally start to trust the technology for more applications. Specifically they're being designed to be nearly impervious to a common attack on RFID devices, the side-channel attack. Those work by analyzing actual power fluctuations or memory access patterns in order to determine what the cryptographic key is, to break in and steal your precious information.

The new chip doesn't prevent the reading of those physical properties, because that would mean it doesn't work at all, but instead uses a a special ferroelectric crystal material that can self-power the chip, and store small amounts of information, to prevent people from cutting the power right before a cryptographic key exchange, which can reveal that key if done properly and the right equipment and software. They'll also incorporate a random number generator on-board to use a new secret key for each transaction, meaning that each one is completely unique, and thus far safer and more secure than ever before.

Continue reading: Hack-proof RFID chips to protect credit cards and more in the future (full post)

Explore ancient virus' with the Internet Archives malware museum

| Feb 5, 2016 2:02 PM CST

If you get infected with Malware today, it's a very serious issue that could potentially compromise and complicate your life. Back in the day before the rise of botnets and ransomeware, viruses were quite cheeky and sometimes very bizarre. The Internet Archive is letting you explore what those antiquated infections could do, without the danger of course.

malware_HYMN.COM

The collection is a whimsical exploration of virii from the 1980's and 1990's that was curated by Jason Scott from Internet Archive and Mikko Hypponen, a chief researcher from F-Secure. Click on any of the examples and you'll be greeted with the animations and messages that tended to be the end result. They're safely contained within a DOS box emulator, but are without their destructive powers anymore anyway.

Continue reading: Explore ancient virus' with the Internet Archives malware museum (full post)

New biometrics uses a 'Brainprint' for identification, 97% accurate

| Feb 5, 2016 10:55 AM CST

Biometrics are something we've been using to uniquely identify other humans since the 13th Century, but the current methods are flawed and can be spoofed with enough creativity and time. So now researchers have found another novel way to uniquely identify people: With "Brainprints".

A brainprint is the unique way in which your neurons fire when reading, or doing anything. It's a distinct and consistent way to identify people. New research by the Basque Center for Cognition and Binghamton University into the brainprint has been able to show just how unique our thought patterns actually are. They were able to identify people with 97% accuracy just based on them thinking about a particular word that flashed on a monitor in front of them for a half of a second.

That's good news for the coming robot revolution, because until brain thought patterns can be faked, we'll at least be able to know whose who, and not human. But in more practical terms it could be another piece to the puzzle of authentication. As a means to make a password it's horrible, but in a multi-factor authentication scheme, it could be used to identify that you're actually who you say you are and present at the time of entering your pin or password.

Continue reading: New biometrics uses a 'Brainprint' for identification, 97% accurate (full post)

Research reveals 57% of dark web is illicit material

| Feb 4, 2016 8:01 AM CST

The darknet, or dark web, is a conglomeration of hidden services and websites that are accessible only through the Tor network. And as it would turn out, recently published research shows that over 57% of those hidden websites also happen to have some kind of illegal content on them.

The researchers, Daniel Moore and Thomas Rid from King's College London, created a custom script that parsed through some 5,025 live .onion based websites and found that 1,547 hosted some kind of material that's criminal in nature. The leading activity seems to surround drugs, with financial related criminal enterprises taking in a close second.

It's not necessarily a surprising finding, given that the idea of privacy and security tend to attract the unsavory types by their very nature. But the researchers do note that it doesn't have to be that way. And that perhaps removing hidden services from Tor could help, somehow.

Continue reading: Research reveals 57% of dark web is illicit material (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription