Showing posts with label Encrypted Data. Show all posts
Showing posts with label Encrypted Data. Show all posts

Thursday, 12 November 2015

Apple CEO Opposes British Espionage Legislation


Apple CEO Tim Cook opposes plans by the British government, which wants access to encrypted data via a new espionage laws. Last week, the British government presented a bill which telecom providers are called to work in the interest of national security along with more extensive investigative and intelligence.

During an interview with students of Trinity College in Dublin let Cook know that he wants to persuade the British government to change the plans, reports the Press Association. "We plan to continue to encrypt end-to-end without backdoor", so stated the Apple CEO. "We will cooperate with the authorities to try to convince them that it is also considering the national security is in their interest."

Cook warned that if there backdoors are added to software, anyone can enter. "We find that the safest approach to the world is to encrypt end-to-end, without backdoor. We think this protects most people." Yesterday Cook made ​​his concerns about dealing with encryption already clear. "To protect people using any product you should encrypt. Just look at all the data breaches that occur," he told in an interview with the Daily Telegraph know. Cook also said that the weakening of encryption is not a solution. "You have to strengthen it. You have to stay ahead of the people who want to crack it."

Tuesday, 13 October 2015

Expert: Precautions LastPass Users After Purchase LogMeIn



Last Friday it was announced that the popular online password manager LastPass for an amount of $ 125 million was taken, but the new owner LogMeIn has caused some users worry. Reported that the Australian security expert Troy Hunt.

LogMeIn is a company that offers software that allows remote access to computers can be obtained. The company's image is not flawless. So let LogMeIn in 2011 that LogMeIn would always be free. Last year, however, the company announced the end of LogMeIn Free on. Another point is that the LogMeIn software is often used by telephone scammers posing as Microsoft employees. In early 2012 Hunt attention to the issue. "Unfortunately, three years later LogMeIn continues to be the preferred software of these crooks," he tells.

According to Hunt many people are also concerned about the direction that LastPass for the acquisition will go up. "Even though they say that the password manager remains independent and is not influenced, they now fall within a broader business vision and LogMeIn will influence the direction of LastPass," said security expert. He therefore anxious for LastPass users a roadmap put online that explains how simple of LastPass can be switched to 1Password, another popular password manager.

Saturday, 10 October 2015

LastPass Password Manager For Acquired 125 Million



Online password manager LastPass is today a cost of $ 125 million acquired by LogMeIn, a provider of software to log on to remote computers. LastPass is a cloud service where users their passwords for various websites in a "safe" to store.

The vault is then accessible from different devices, which should simplify logging in from a PC, smartphone or tablet. LastPass offers both free and paid versions of the software. In August there was a still a new use model introduced. Users can therefore choose which platform they want to use the software for free. Previously, users could install the password manager free only on their computers and then make it synchronize smartphone or tablet to be paid.

Both the free and paid versions LastPass will continue to support and further develop, so the company says. The software of Load Pass will now be added to the solutions of LogMeIn. Furthermore, users can expect in the coming months several new features. In June, LastPass was still a security incident to make. Attackers had managed to break into the network of online password manager and managed in order to steal users' data. It involved email addresses, reminders for passwords, user salts per server and authentication hashes. The contents of password vault would have been in no danger.

Thursday, 18 June 2015

LastPass: Password Vault Content Not In Danger


Users of the recently hacked online password manager LastPass who used a weak master password or had given a clear password hint at greater risk of attackers who knew the company to break into the master password know to figure out, but the contents of the Password Vault is not in danger.

That LastPass late in an updated statement about the attack. The attack on the online password safe were email addresses, reminders for passwords, user salts per server and authentication hashes captured. The master password is not immediately stolen by the attackers, but only the hash of this. Both the user's master password for Password Vault are hashed over 5,000 iterations of the PBKDF2-SHA256 hashing algorithm.

Creates a key that is hashed again, so as to make the authentication hash for the master password. This authentication hash is sent to the LastPass server as a user on his online password safe trying to login. "We then take that value and use a salt, a random string per user, and another 100,000 do hashing rounds and compare it with what is stored in our database in simple terms:. Cracking our algorithms is very difficult, even for the strongest computers, "said LastPass.

Advise

However, an attacker can try to guess the master password and then use the per-user salt and authentication hash to determine whether his guess was correct. Because of the large number hashing round, both locally and on the server, LastPass thinks that this will be a slow process for an attacker. If the user's master password is weak, however, whether he entered a password hint that makes it simple to guess, then an attacker much less effort required to retrieve the master password.

However, the contents of the safe password remains safe says LastPass. Once an attacker with the outdated master password namely trying to log on, he must first verify your email address. This measure applies to all login attempts from a new IP address or system.

Creak

Security expert Robert Graham investigated whether an attacker can crack the hashes. On his computer, he could guess more than 2500 passwords per second. "This may seem like a lot, but it's not as cracking passwords is exponentially difficult," said the expert. A password of five characters, with all possible characters are used and there are 64 possibilities for each character consists of up to 1 billion combinations.

A fast computer can crack this password quickly. Adding a character with 64 different options makes it 64 times harder to guess the password through a brute force attack. However, the cracking time can be shortened if a dictionary is used, says Graham. He advises LastPass users with a weak master password whatsoever to change that.

Wednesday, 17 June 2015

Data LastPass Users Stolen By Hacking


Attackers have managed to break into the network of online password manager LastPass and there have stolen user data. These are e-mail addresses, reminders for passwords, user salts per server and authentication hashes.

LastPass is a popular cloud service where users their passwords for various websites and services in a "safe" to store. In a warning to users LastPass says it is confident that the measures encryption measures are sufficient to protect by far the most users. LastPass applies various measures to protect the authentication hash, making it difficult to retrieve the original password.

However, the company has announced additional measures. For example, users who log in from a new device or IP address first verify their account via e-mail unless multi-factor authentication is enabled. Also, users will be warned to change their master password. Furthermore, all users will be notified via e-mail. Since the encrypted "safe data" has not been captured, users their passwords to adjust not stored by LastPass.

Wednesday, 25 February 2015

NSA Director Wants Access To Encrypted Data


The NSA wants technology give the secret service access to the encrypted data and communications from customers, but NSA director Mike Rogers does not speak of a "backdoor". According to Rogers, in the fight against terrorism necessary to decrypt encrypted devices.

"The discussion I have seen is mostly about all or nothing, or full encryption or no encryption", as the NSA director said yesterday during a cybersecurity forum in Washington. According to Rogers, it is feasible to establish a legal framework so that there can still gain access to encrypted data. He pointed to the fight against child pornography where technology companies with public authorities and hopes to achieve a similar cooperation in the field of encryption, reports AFP .

Alex Stamos, Chief Security Information Officer Yahoo asked Rogers if he wants technology backdoors add to their products and services. "Backdoor is not the context that I would use. If I use the term" backdoor "Sure, I think it is suspicious. Why would you want through the back door? It would be correct public should be," gave the NSA director reply . "We can develop a legal framework to do this. It's not something that we necessarily have to hide."

Saturday, 21 February 2015

Samsung Smart TV transmits voice audio unencrypted


The voice commands that smart saving TVs from Samsung and forwarding are sent unencrypted to a third party, as has discovered a security researcher. Recently there was great commotion about the voice recognition of the Samsung SmartTV which consumers via voice commands can control the TV.

Security Researcher David Lodge decided the traffic that comes to investigate the television. While he saw a connection on port 443, which normally indicates HTTPS. Lodge then decided to view the contents of the data stream and saw that it was not going to encrypted data. It was not even HTTP data, but a combination of XML, and a binary data packet. "The weasels, they use 443 / TCP to tunnel over the dates, probably because many standard default firewall configurations traffic to port 80 and 443 permit outside the network," said the researcher.



It also showed that all kinds of information on the screen is sent, such as MAC address and the version of the operating system. The voice command could be seen that he gave. It suggests Lodge that television does not listen to users unless it is activated by the command. Something, however, with each subsequent firmware update may change, making continuous listening which would be possible, he warns. Lodge Samsung therefore calls to use anyway SSL.