Hacking, Security & Privacy - Page 51
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 51
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Ex-Microsoft privacy adviser doesn't trust MS after NSA PRISM leaks
Caspar Bowden worked for Microsoft between 2002 and 2011 as its Chief Privacy Adviser, but now says he doesn't trust Microsoft's security after he read the stories about the NSA PRISM system after NSA whistleblower Edward Snowden stepped up with the leaks.
Bowden was in control of the privacy policy for 40 countries that Microsoft operated in, but strangely he didn't have anything to do with the United States side of Microsoft's privacy. Bowden says he was simply unaware of the PRISM data-sharing network when he was with the software giant. He said "I don't trust Microsoft now," where he added that he now uses open source software that allows him to peer into the underlying code.
The former privacy adviser to Microsoft said that the NSA PRISM system was undermining democracy by sharing citizens' private information with the UK's GCHQ and intelligence agencies in Australia, New Zealand and Canada. He added: "The public now has to think about the fact that anybody in public life, or person in a position of influence in government, business or bureaucracy, now is thinking about what the NSA knows about them. So how can we trust that the decisions that they make are objective and that they aren't changing the decisions that they make to protect their career? That strikes at any system of representative government."
Continue reading: Ex-Microsoft privacy adviser doesn't trust MS after NSA PRISM leaks (full post)
John McAfee has a solution to our NSA spying problems, will cost $100
John McAfee, modern day eccentric millionaire and founder of McAfee Antivirus, announced over the weekend that he has devised a plan to block the illegal--and legal--spying from the NSA once and for all. McAfee outlined his plan on Saturday while speaking at an event in San Jose, California.
The big plan involves a device created by McAfee which he calls "D-Central." The gadget is essentially a wireless networking hub that allows smartphones, tablets, laptops, and any other Wi-Fi connected device to access what is basically a darkweb-like network that blocks mainstream intrusion from the government. The D-Central device would retail for $100 or less and McAfee says that he has been planning the device for several years now.
D-Central will provide not only a private (darkweb) connection, but will provide a public one as well and can be used to share files, chat, and research without ever unveiling your identity. McAfee said that the device has a range of about three blocks, and at the moment D-Central "is round in shape" and features "no screens". A working prototype is said to be just six months away and McAfee is actively searching for partners to help with development. Anyone looking for more information can hit up the source below to check out the official D-Central website.
Continue reading: John McAfee has a solution to our NSA spying problems, will cost $100 (full post)
Dropbox asks for permission to publish gov surveillance requests
Dropbox has jumped onto the transparency bandwagon with fellow tech giants such as Google, Microsoft, Twitter, and Facebook. Today, Dropbox announced that it has filed an amicus brief with the Foreign Intelligence Surveillance Court.
The brief requests that the court give permission to all Internet companies to disclose all requests for information regarding their users when it comes to matters of national security. This would allow Dropbox to publish a list of every information request it has received regarding its users from governments both foreign and domestic.
Dropbox says that "the Court should not permit the government to invoke the mere label of 'national security' to justify the speech restraints it seeks." Currently tech companies can publish how many requests they received, but only on non-gag law enforcement requests, and can only disclose a vague number range when dealing with national security requests.
Continue reading: Dropbox asks for permission to publish gov surveillance requests (full post)
NSA has no issues sharing your personal data with Israel
On September 11 of all days, a new leak from Edward Snowden has appeared online thanks to The Guardian, which reports that the NSA shares raw intelligence data with Israel without sifting through it first.
Snowden revealed the startling news, with an intelligence-sharing agreement detailed in a memorandum of understanding between the US spy agency and its Israel counterpart. This has unveiled that the NSA hands over intercepted communications that would contain American citizens' phone call records and e-mails (and most likely much, much more). The agreement between the spy agencies has no legally binding limits on the use of the data by the Israelis.
The deal was inked back in March 2009, with the agreement between the US and Israeli spy agencies "pertaining to the protection of US persons" repeatedly stressing the constitutional rights of Americans to privacy, as well as the need for Israeli intelligence staff to 'respect these rights.' The agreement saw the Israeli spy agency with "raw Sigint", which is signal intelligence.
Continue reading: NSA has no issues sharing your personal data with Israel (full post)
NSA has hacked into Android, BlackBerry and iPhones, accessed data
Der Spiegel is at it again, reporting that it has NSA documents in its hands that state that the US spy agency accessed data from Apple iPhones, BlackBerry devices and Android-based devices.
Der Spigel stated that most smartphone data can be accessed, including users' contact lists, text message logs and information on geographical locations. The NSA has set up working parties that makes sure each of the main mobile OS' had a "back door" that was accessible to spies. This has stirred memories in Germany, where the paper is based, of the Nazis and the communist era from decades ago.
The one company that has the most at stake would be BlackBerry, who has proudly sold devices on the fact that they the encryption in them is too strong for anyone to crack. Google and Apple, we both know have worked with the NSA previously, so this news should come as a shock to no one. This news also comes on the heels of our latest report where we talked about common encryption protocols were nothing for the NSA.
Continue reading: NSA has hacked into Android, BlackBerry and iPhones, accessed data (full post)
US Government is Facebook's largest requester of user information
Today, Facebook revealed that the US government accounts for the vast majority of the requests for information it receives about its subscribers. The social network said that it was legally required to comply with 79 percent of the 12,000 requests it received from the US government about 21,000 individuals who have profiles on the website.
The US government is not the only guilty party though, as the UK government submitted about 2000 requests on over 2300 Facebook users, which it was obligated to turn over 68 percent of the requests. On the lower-end of the spectrum, Australia requested info on 601 users, of which 64 percent were granted. Facebook chose to release this information in an effort to be transparent after accusations of being close partners with the NSA in the infamous PRISM scandal.
In a blog post, Facebook's general counsel, Colin Stretch, wrote: "As we have made clear in recent weeks, we have stringent processes in place to handle all government data requests... We believe this process protects the data of the people who use our service, and requires governments to meet a very high legal bar with each individual request in order to receive any information about any of our users."
Continue reading: US Government is Facebook's largest requester of user information (full post)
Chinese websites go down as massive DDOS attack hits its .cn domain
Early Sunday morning, the Chinese government says that it faced what is described as the largest Direct Denial of Service (DDoS) attack that the country has ever seen. The attackers targeted China's Top Level Domain (TLD) .cn and effectively took down all Chinese websites using the .cn TLD.
China's Internet Network Information Center said that the attacks began around 2 AM early Sunday morning and lasted for about two hours with the DDoS attack falling off around 4 AM. The Wall Street Journal spoke with web host CloudFlare about the incident and how it affected Internet traffic. It said that there was a 32 percent drop in traffic across all the Chinese domains hosted on its network during the attack. "It is not necessarily correct to infer that the attacker in this case had a significant amount of technical sophistication or resources," CloudFlare CEO Matthew Prince wrote to the Journal. "It may have well have been a single individual."
At the moment, Chinese officials and industry analysts are not sure why the attacks occurred or if there was a specific target they were hoping to take down. With the attacks lasting only two hours, not much damage occurred, but we've seen this sort of thing in the past with short attack serving as a way to test the waters for a much larger future attack. In 2013, China has come under several major cyber attacks but has also led several cyber attack campaigns itself.
Continue reading: Chinese websites go down as massive DDOS attack hits its .cn domain (full post)
US-based League of Legends servers hacked, password reset implemented
Something that just hit my inbox minutes ago is from Riot Games, announcing that they've had their US-based servers hacked. The attack didn't hit all of its servers, but just a 'portion' of its US servers.
The hackers were able to access usernames, e-mail addresses, salted password hashes, and some first and last names. Riot Games is also investigating that approximately 120,000 transaction records from 2011 that contained hashed and salted credit card numbers has been accessed. The League of Legends developer is contacting these players to alert them.
In order to hopefully escape more issues, Riot Games will require players in the US to change their passwords within the next 24 hours. Once this time hits, you'll be automatically prompted to change your password anyway.
Continue reading: US-based League of Legends servers hacked, password reset implemented (full post)
Vulnerability found in Tor Browser Bundle, beams info back to the NSA
In the ongoing saga of NSA spying, it appears that not even the darknet is safe. Today, reports came in that an exploit has been discovered in the Tor version of Firefox 17 that comes packaged with the Tor browser bundle. An exploit in the browser's code allowed malware to be injected into the system which then beamed the machine's hostname and MAC address back to a remote server in Reston, Virginia.
The exploit was based on a vulnerability that arises when websites on the darknet attempted to run JavaScript. After a little digging, sources found that the remote server located just outside of Washington DC then sent those hostnames and MAC addresses to NSA servers located all over the country. The exploits as well as the NSA spying were discovered by Baneki Privacy Labs, a collective of Internet security researchers, and VPN provider Cryptocloud.
The vulnerability is only present in the Windows version of the Firefox Extended Support Release 17 browser that was bundled with the Tor Browser Bundle before June of this year. Because automatic updating is turned off in this version, anyone who downloaded the Tor Browser Bundle before June is susceptible to the spying. Tor recommends that users download the new version of the Browser Bundle to stay secure.
Continue reading: Vulnerability found in Tor Browser Bundle, beams info back to the NSA (full post)
Samsung Smart TVs could let hackers watch you via built-in webcam
With all the recent revelations and allegations about the NSA and other foreign agencies been able to spy on you through backdoors in your computers and through the microphones on your smartphones, tablets, and other mobile devices, it should come as no surprise that your Smart TV may be spying on you as well.
It's not pleasant all the stories are popping up at the same time, as this week the world's largest security conference known as Black Hat took place in Las Vegas, Nevada. Yesterday, two researchers named Aaron Grattafiori and Josh Yavor demonstrated several vulnerabilities found in the 2012 models of Samsung's Smart TV line. The demonstration took place as Black Hat was wrapping up and it showed how hackers could turn on the built-in camera, take control of social media apps, and access files that were stored on the television.
"Because the TV only has a single user," Grattafiori explained in an interview with Mashable, "any type of compromise into an application or into Smart Hub, which is the operating system--the smarts of the TV--has the same permission as every user, which is, you can do everything and anything."
Continue reading: Samsung Smart TVs could let hackers watch you via built-in webcam (full post)
WSJ: FBI can remotely activate Android and laptop microphones
If you still thought you had privacy after all of the news you've been reading about the NSA PRISM system, or the GCHQ, then you'd be wrong. Very wrong. The Wall Street Journal is now reporting that the FBI has the power to remotely activate microphones in Android smartphones and laptops to record conversations.
This is all coming from a single anonymous former US official, who says that remotely forcing a cellular microphone to listen in on a conversation isn't something new. The FBI used something they called "roving bugs" to spy on alleged mobsters back in 2004, and further back in 2002 they used the roving bugs to keep tabs on supposed criminals using the microphone in a vehicle's emergency call system.
The anonymous US official said that there is a dedicated FBI group that regularly hacks into computers, where they use a mix of custom and off-the-shelf surveillance software which they purchase from private companies. One of the Journal's sources said that the "Remote Operations Unit" will sometimes install software by physically plugging in a USB device, but they can also do it through the Internet by "using a document or link that loads software when the person clicks or views it."
Continue reading: WSJ: FBI can remotely activate Android and laptop microphones (full post)
AMD responds to hardware backdoor allegations
Yesterday, I covered a story about the big chip manufacturers allegedly installing hardware level backdoors into the processors used in all of our PCs. The allegations came from two security industry experts who both claim to have proof of concept demonstrations already. Earlier today, AMD's Michael Silverman contacted me with an official statement on the matter in which he called the allegations "unfounded."
With the Black Hat conference wrapping up today, we will be keeping our eyes open for any whitepapers or proof of concept demos that prove the backdoors exist. I have reached out to both of the security experts for statements as well, but have yet to receive a response. If and when that response comes in, I will be sure to post an update.
Continue reading: AMD responds to hardware backdoor allegations (full post)
AMD and Intel in bed with NSA? Are backdoors built into processors?
The Australian Finance Review has just published a new story that suggests that the NSA may have hardware level backdoors built into current generation AMD and Intel processors. Leading security expert Steve Blank says that he first caught on to the practice when he noticed that the NSA had access to Microsoft emails before they were encrypted. He says that he would be extremely surprised if the NSA did not have access to a processor microcode level backdoor on every PC in America.
His reasoning behind the theory is quite simple. The sheer power needed to brute force crack AES 256-bit encryption on a single file would be equivalent to "the power of 10 million suns" and that a hardware backdoor would require almost no effort to enter and would allow agents access inside your PC in a matter of minutes. Jonathan Brossard, another expert in the security field, demonstrated this as a proof of concept at last year's Black Hat conference. These backdoors are made possible because they are placed inside the microcode which is stored on the chip itself and gets updated every time Microsoft, Apple, or any other OS pushes out an update.
Continue reading: AMD and Intel in bed with NSA? Are backdoors built into processors? (full post)
Using just basic tools, all GPS units across the world can be hacked
According to a new study, the world's GPS system is open to hackers who could hack virtually any and all GPS units and take control of commercial airliners, for example.
The tools required are simple: a laptop, a small antenna, and an electronic GPS "spoofer" which would cost $3,000. The report comes from GPS expert Todd Humphreys and his team at the University of Texas who took control of a sophisticated navigation system that was built into an $80 million, 210-foot super-yacht in the Mediterranean Sea.
Humphreys told Fox News: "We injected our spoofing signals into its GPS antennas and we're basically able to control its navigation system with our spoofing signals." The team hacked into the yacht's navigation system by sending it counterfeit radio signals and were able to navigate the ship off course, steering it in any direction they wanted.
Continue reading: Using just basic tools, all GPS units across the world can be hacked (full post)
Ubuntu user forums hacked, 1.8 million user credentials stolen
Over the weekend, the Ubuntu forums went down after a massive security breach resulted in over 1.8 million user credentials being stolen. Canonical made a decision to put the forums in maintenance mode in an attempt to ward off any further attacks. The company says that the attackers managed to get away with every user's local username, password, and email address that was stored in the Ubuntu forum's database.
The company says in the passwords were stored as salted hashes instead of plaintext, but they still recommend that you change any and all passwords that were used on other services such as email, Facebook, or other forum accounts in which you might have use the same password. Canonical says that Ubuntu One, Launchpad, and other related services were not affected by the breach and users of those services need not worry.
Continue reading: Ubuntu user forums hacked, 1.8 million user credentials stolen (full post)
GitHub suffers massive DDoS attack, says it is recovering quickly
Today, the popular version control code repository GitHub issued a statement to the media announcing that it has been fending off a massive attack on its system which managed to knock it servers off-line early Friday morning. The company said that around 10:40 UTC the site was struck with a massive DDoS attack from unknown sources.
Roughly an hour and a half later, the company had implemented processes that began to alleviate the load on their servers but things were not yet back to full functionality. "We've put mitigation in place that should deflect the attack, and services are recovering. We're continuing to monitor closely," GitHub said in a statement.
This is the second large DDoS attack against GitHub this year with the first happening back in March. Before that, the site experienced another massive attack in September 2012 and one before that during February 2012 that lasted for a whole week. It is unclear who keeps attacking the site or what motivates them to try and bring down the service.
Continue reading: GitHub suffers massive DDoS attack, says it is recovering quickly (full post)
HP caught red-handed installing secret backdoors into their enterprise storage products
After the last month or so with the unveiling of the NSA PRISM system from Edward Snowden, as well as GCHQ, you'd think people would be up in arms over their security. How deep does the rabbit hole go, you ask?
Well, it's now coming to the point where Hewlett-Packard have had to admit, for the second time in a month, that they've built secret backdoors into their enterprise storage products. Technion, a blogger, is the one who has blown the whistle on this one, who saw the security issue in one of HP's StoreOnce systems last month, but then found more backdoors in HP's storage and SAN products.
HP's statement, after Technion blew the whistle, admitted that "all HP StoreVirtual Storage systems are equipped with a mechanism that allows HP support to access the underlying operating system if permission and access is provided by the customer."
Defcon organizers ask feds to not attend the hacker conference this year, marks first time ever since the event was founded
When it was first founded over 20 years ago, Defcon was been known as the gathering place where anarchist, geeks, hackers, and the feds could all hang out, talk security and get along on neutral ground. Unfortunately for the feds, the NSA has managed to break a bond of trust that lasted over two decades.
This morning, we learned that the organizers of the Defcon Hacker Conference, held in Las Vegas Nevada, have asked that all federal employees planning to attend the show to please sit out this year as they are not welcome. This may seem like a drastic move to some, but others see it as a way to express the loss of trust many in the online community are feeling at the moment.
"For over two decades DEF CON has been an open nexus of hacker culture, a place where seasoned pros, hackers, academics, and feds can meet, share ideas and party on neutral territory," Jeff Moss, aka The Dark Tangent, wrote in a blog post published Wednesday night. "Our community operates in the spirit of openness, verified trust, and mutual respect."
Ubisoft hacked, recommends you change your password
Ubisoft has announced that one of their sites was hacked and allowed unauthorized access to user account data. Ubisoft has not revealed the number of affected users, though it potentially could be the entire Ubisoft customer base as most of Ubisoft's games require a user account to play. The company has recommended that users change their passwords and passwords on any site that makes use of the same password.
The hackers will have to decrypt the passwords before they are useful, though this shouldn't take too long. Ubisoft stresses that the hackers did not obtain any payment data as it is not stored by the gaming studio. We're hoping to find out just how many of Ubisoft's customers were affected by the hacking, but we're not sure Ubisoft will be forthcoming with that data.
Continue reading: Ubisoft hacked, recommends you change your password (full post)
Microsoft will pay you up to $100,000 for finding bugs in Windows 8.1
Are you a good bug finder? You might be able to collect a nice paycheck from Microsoft. Microsoft has offered up $100,000 as a top prize for finding an exploit that allows you to bypass the protections built into Windows 8.1. The time frame for this bounty program is ongoing and requires a truly novel exploitation technique.
Microsoft has offered up an additional $50,000 if you provide defensive ideas along with the Mitigation Bypass bug, bringing your grand total to $150,000. This time frame is also ongoing.
Microsoft isn't just concerned with Windows 8.1 security. They have also offered up 30 days to submit critical vulnerabilities found in Internet Explorer 11 Preview on Windows 8.1 Preview. This period will go from June 26 to July 26, 2013. Qualifying bugs are worth up to $11,000.
Continue reading: Microsoft will pay you up to $100,000 for finding bugs in Windows 8.1 (full post)


