Showing posts with label Online Security. Show all posts
Showing posts with label Online Security. Show all posts

Sunday, 29 November 2015

Major Security Flaws In Hacked Toy Manufacturer VTech


The Chinese manufacturer of educational toys VTech where recently the data of 4.8 million adults and 200,000 children were stolen customer data had not properly secured, according to the Australian security expert Troy Hunt that captured customer data analyzed.

Recently managed to get an attacker access to the customer database and approached Vice Magazine. The journalist of the magazine then contacted Hunt to verify the data. Hunt was sent several files, the largest of which was 1,7GB. This file, called parent.csv, he found the details of 4.8 million people. It was e-mail addresses, names, IP address, mailing address and encrypted passwords. The password proved to be hashed with the MD5 algorithm. It is therefore not directly readable, but MD5 has long been considered unsafe because it is easy to 'crack'. This allows an attacker can still retrieve the password.

VTech had not taken additional measures to protect the passwords, such as the use of "salts" and "stretching". However, it is not the only security problem, says Hunt. As the website does not use SSL, so all communications, including passwords, unencrypted occurs. There is no cryptographic protection of sensitive data, the expert noted. The website appears to provide a SQL statement back at login. The attacker said that he had come in via SQL injection, a problem that has been known since 1998 but is ignored by some companies still. Finally Hunt criticizes the extensive use of Flash on the website of VTech.

The expert also manages the website Have I Been Pwned, where Internet users can check whether they appear in the database of hacked websites. The data of the 4.8 million adults from the database of VTech here are now added. That does not apply to the data of 227 000 children who also were in the stolen data. Hunt has not been added. VTech has confirmed a burglary, but do not know how the attacker managed to get inside.

Monday, 5 October 2015

Interpol And Europol Launch Task Force Against Cyber Crime


Interpol and Europol will together launch a task force to improve the international fight against cyber crime and where law enforcement agencies from other countries can join. There will also be an alliance against abuse of digital currency to be set up by criminals.

These are two of the results of the Europol INTERPOL Cyber Crime Conference, which took place last week in The Hague.The Joint Cooperation & Compatibility Cyber Crime Taskforce Europol and Interpol will create a compatibility list to harmonize the different legal systems and codes for data requests. This should improve cooperation between different law enforcement agencies.

There will also be an alliance against abuse of digital currency for criminal transactions and money laundering. Particular attention was focused on policy, boosting operational cooperation and developing and providing training to combat the criminal use of digital currency. For example, law enforcement agencies empowered to detect digital currency of criminals, seize and confiscate.

Sunday, 4 October 2015

GitHub Introduces Logging Via USB Key


The popular online platform for developers GitHub has a new method added to allow users to login securely and advises developers to also to add their own software to the login method. It is the Universal 2nd Factor (U2F) standard of FIDO Alliance.

It is an authentication standard that during the next logon password also checks the presence of a U2F USB key. This hardware key acts as a second security factor. The key works only on the real website of GitHub, which as phishing and man-in-the-middle attacks must be prevented. U2F standard supports several platforms and browsers and requires no installation of drivers or software.

There are several manufacturers that offer U2F USB keys, which can all be used, but GitHub has launched an action with Yubico, provider of the YubiKey. Before developers on GitHub can log in via the USB key they need to be first through their account register. Last year, decided Google already U2F in to Google Accounts and set in August did Dropbox so. U2F as said from the FIDO Alliance, an alliance of IT companies like Microsoft, ING, Google and Intel, who want an end to the password and therefore working on alternative solutions.

Thursday, 17 September 2015

Writer Loses Part Of His Life's Work By Ransomware


A New Zealand writer who for 50 years on a book about cars works is a part of his life's work lost by ransomware and the man did not have backups. The 73-year-old Bruce Utting in his life had some 200 cars owned and operated since 1965 trying to write about a book.

Recently touched his computer infected with ransomware which encrypted files. To regain access to the files he had to pay $ 500. If it was not paid on time would amount to $ 1000 are doubled. Utting knocked on NetSafe, an organization sponsored by the government that gives online security advisory. "It was suggested that I should throw this computer and a new one had to buy, as there was no safe way to format or to avoid the risk of reinfection," said the writer.

Utting then decided to go to the police, but they sent him back to NetSafe. The organization advised not to pay the ransom, even letting victims of ransomware regularly know that after paying their files to recover. The British anti-virus firm Sophos understands else that pay victims, especially if they have no backups. Despite all warnings the writer did not have backups, so the encrypted files can not be retrieved in a different way.

Utting was lucky however, as ransomware but four or five chapters encrypted. He uses a very old version of Microsoft Works for writing his book and the earlier chapters were not recognized by the ransomware and encrypted, reports the New Zealand news site Stuff. The writer is now planning to buy a new computer.

Tuesday, 25 August 2015

Amazon.com Is Going To Stop Flash Ads



Due to recent changes in Google Chrome, Firefox and Safari, Amazon decided to order from September 1 no more Flash ads on Amazon.com to accept. According to the Internet shop is the reason that browsers have changed when Flash content is displayed on websites the way.

Not only browser developers have restricted the operation of Flash content. Security experts regularly advise to remove Flash Player in the browser. The new policy is to ensure that ads on the website to keep working. Flash is already longer under fire, both because of the security issues with Adobe Flash Player, as well as technology for displaying video content.

Recently let Facebook CSO Alex Stamos yet know that with the support of Adobe Flash to stop, then follow the browser developers. In this way, web developers are forced to upgrade their tools and programs to HTML5, since they postpone now that due to the permanent Flash support.

Friday, 14 August 2015

Dropbox Secure Accounts With USB Key



Users who want to protect their Dropbox account additional courses may also log in via a USB key. The 'security key' functions as a second security factor during login. Once the password is entered, the presence of the Universal 2nd Factor (U2F) security key checked. In addition, the USB device works only on dropbox.com and can thus prevent phishing.

According Dropbox security key, thus providing protection to more than two-factor authentication via SMS is the case. For the login makes use of the security key U2F-protocol developed by the FIDO Alliance. This is an alliance of IT companies that want to eliminate the password and therefore come up with alternative solutions.

Dropbox users to log in via the USB key will first set in their account. At this moment U2F only dropbox.com in conjunction with Google Chrome. The USB key is via different suppliers to obtain. Last year, Google decided U2F for logging in to Google Accounts support .

Saturday, 25 July 2015

Google: Consumers Wary Of Security Updates


Average Internet users are wary of security updates, and consider even mistaken as a security risk, according to research ( pdf ) from Google. The Internet giant decided the security behaviour of 231 294 security experts and Internet users who are not experts to compare.

For example, among other things, to the top five security measures take any consideration of both groups. It shows that average Internet users underestimate the importance of security updates seriously. 35% of the experts called to install security updates as a security measure, while only 2% of users doing this. As a result, the installation of the patches is a security measure, with the largest difference between users and experts.


Further research into this behaviour shows that 39% of the experts shows automatically install updates, while among users is 29%. In addition, 25% of the experts said that updates are installed immediately. When the user, this is done by only 9%.According to the researchers did not make installing updates as timely as possible with bad past experiences or that users do not realise its effectiveness.

Passwords

The study also shows that password management is important for both users and experts, but there different approaches are used. The experts often use password managers. The difference between experts and users is a factor of three. 24% of users said for some accounts using a password manager, while it is 73% of the experts. Furthermore, users will find anti-virus software very important, while experts prefer other measures.

"Our results show that experts and non-experts take various measures to protect themselves on the Internet. The action of the experts be experts considered good advice, while the actions of the non-experts get mixed reactions from experts," said the researchers. They argue that there is room for improvement when it comes to identifying the main security and to then make this clear to users.

Sunday, 26 April 2015

Free Online Service Scans Inbox Passwords


Many Internet users would save passwords in the inbox of their email account, so that risk once the account is hacked. Security Dash Lane has developed an online service that checks the contents of the inbox on passwords and then displays.

In this way, users can see which online accounts they have all signed up and how many passwords and login data are yet to be found in their inbox. Even if the accounts are no longer used this forms according Dash Lane a risk because they can help logging in to other accounts, especially if the same password is used for multiple accounts.

Dash Lane forgets to mention that an attacker access to the email account has in many cases other accounts registered to take over at the e-mail account by resetting the password, assuming a different password for these accounts than that of the email account is used. Scan Inbox , such as the online service is called, is free to use. Found personal information according Dash Lane only visible to users and not for the company.