Showing posts with label hackers. Show all posts
NSA Monitoring ISIS' Cyber Capabilities
As U.S. military leaders outlined their strategy before Congress to fight Islamic State militants on the battlefield, the National Security Agency chief said on Tuesday he was watching the media-savvy group's cyber capabilities.Asked whether the Sunni Muslim group was planning cyber attacks on U.S. interests, Admiral Mike Rogers said he could not discuss specifics of the organization's technical capabilities.
"We need to assume that there will be a cyber dimension increasingly in almost any scenario that we're dealing with," Rogers said at a cybersecurity conference in Washington. Islamic State, which controls large swaths of Iraq and Syria, has posted carefully choreographed beheading videos online, trumpeted its violent acts on Twitter and used social media to recruit foreign Islamists to the fight.
"Its public messaging and social media is as slick and as effective as any I've ever seen from a terrorist organization," Homeland Security Secretary Jeh Johnson told the Council on Foreign Relations in New York last week.
Cybersecurity expert James Lewis of the Center for Strategic and International Studies said he did not think Islamic State posed any immediate cyber threat to American interests. While there may be no imminent or specific cyber threat from Islamic State, there is a wide-ranging intent to damage the West, a congressional aide said. Different jihadist groups have talked about launching cyber attacks and it may be just a matter of time before they find someone capable of doing it, the aide said on condition of anonymity.
Rogers, speaking generally on how cybersecurity threats are proliferating across all aspects of American life, said: "There is nothing but increased activity out there." As Pentagon officials told Congress on Tuesday they were preparing for a longer-term campaign against Islamic State in Syria and Iraq, Rogers said cyber defense was a long-haul effort.
The U.S. Cyber Command he leads hopes to have 6,200 cyber employees by 2016 to detect and deflect such threats, and Rogers urged greater cooperation on cybersecurity between government, business and industry. "There are a lot of groups out there - individuals, nation-states - who feel that this is an area worth investing in, because it achieves positive outcomes for them if they can penetrate systems," Rogers said at the Billington Cybersecurity Summit.
Tuesday, 30 September 2014
Posted by Unknown
Android's Next Version Will Come With Default Encryption
Yesterday, Apple commented that iOS 8 the user data stored on iPhones or iPads are fully encrypted, so no one, not even Apple, can access them, even with a court or government order. This is certainly an interesting point for the operating system of the Apple company, and Google seem to think the same. The reason is that a few hours after these statements, the guys at Google have announced that Android 5.0, the next version of the popular operating system for mobile devices, also have default data encryptio.
As we say, by this measure, the data stored on devices with newer versions of iOS and Android will be completely inaccessible, unless the person has the correct password. Three years ago, Google already offers the ability to encrypt our data Phones with Android installed, but this measure, it simply ceases to be a possibility , becoming a default feature. As a result, all users will benefit from this improved safety, because until now, it was an option that activated only those with technical expertise.
Undoubtedly, the two companies that dominate the market for mobile operating systems take such measures is something to behold. Anything that increases the security and privacy of user data is welcome.
A List of 5 Million 'Gmail Passwords' Leaked
A list of almost 5 million combinations of Gmail addresses and passwords
was posted online on Tuesday. But the passwords seem to be old, and
they don't appear to actually belong to Gmail accounts. Instead, it
seems that many of the passwords were taken from websites where users
used their Gmail addresses to register, according to some of the leak's
victims as well as security experts.
For example, someone might have signed up for a website with the username "myaddress@gmail.com" and the password "mypassword." The list exposed this week makes it look like "mypassword" is the password for the Gmail account itself, but the user's actual Gmail password might be totally different.
The list was posted on a Russian Bitcoin forum on Tuesday evening, and local media started reporting on it on Wednesday. We can't confirm the authenticity of all the email addresses on the list, but a Mashable employee, Evan Engel, saw that his old Gmail password, which he hasn't used in years, is part of the leak.
A Google spokesman told Mashable that the company has "no evidence that our systems have been compromised," and security experts seem to agree that the passwords are either old Gmail passwords obtained through phishing, or are passwords that were actually used on other sites.
Matteo Flora, a computer security expert, reviewed the dumped file and found that around 60 email addresses were in his address book. After he alerted those people, 30 of them told him that the password either was never used for their Gmail accounts or was very old, Flora told Mashable.
Chester Wisniewski, a senior security adviser for security firm Sophos, told Mashable that he expects many of these accounts not to be valid. "There is no honor among thieves as they say, and often stunts like this are released as a sad attempt at gaining credibility among other criminals," he said.
Several Reddit users also confirmed that they found their email addresses in the leak, but that the associated password has never been their Gmail password.
To check if your password was one of the leaked, plug your Gmail address into this trusted tool from KnowEm. Alternatively, if you aren't comfortable giving out your email, you can change all your passwords now. Simply type your email address into the IsLeaked tool to see if your account has been exposed.
However, the tool is not without controversy. Life Hacker actually isn’t promoting it anymore after it said it discovered the “tool” was made public just two days before the Gmail leak was reported.
Google said in a blog post late Wednesday that "less than 2% of the username and password combinations might have worked," adding one more reason not to overreact to this dump.
Google also said that it has contacted the owners of the affected accounts "and have required those users to reset their passwords." So if you haven't heard back from Google, you should be fine. (Though periodically changing your password isn't a bad idea, and two-factor is a must.)
Meanwhile, more security experts seem to agree that the leak is probably almost entirely made of old passwords tken from previous leaks and dumps. Whoever put this particular one together, probably "concatenated several dozen dumps" and then published only the Gmail usernames and password combinations he found, said Jeremi Gosney, the co-founder of PasswordsCon, a hacker conference focusing specifically on passwords and other methods of authentication.
For example, someone might have signed up for a website with the username "myaddress@gmail.com" and the password "mypassword." The list exposed this week makes it look like "mypassword" is the password for the Gmail account itself, but the user's actual Gmail password might be totally different.
The list was posted on a Russian Bitcoin forum on Tuesday evening, and local media started reporting on it on Wednesday. We can't confirm the authenticity of all the email addresses on the list, but a Mashable employee, Evan Engel, saw that his old Gmail password, which he hasn't used in years, is part of the leak.
A Google spokesman told Mashable that the company has "no evidence that our systems have been compromised," and security experts seem to agree that the passwords are either old Gmail passwords obtained through phishing, or are passwords that were actually used on other sites.
Matteo Flora, a computer security expert, reviewed the dumped file and found that around 60 email addresses were in his address book. After he alerted those people, 30 of them told him that the password either was never used for their Gmail accounts or was very old, Flora told Mashable.
Chester Wisniewski, a senior security adviser for security firm Sophos, told Mashable that he expects many of these accounts not to be valid. "There is no honor among thieves as they say, and often stunts like this are released as a sad attempt at gaining credibility among other criminals," he said.
Several Reddit users also confirmed that they found their email addresses in the leak, but that the associated password has never been their Gmail password.
To check if your password was one of the leaked, plug your Gmail address into this trusted tool from KnowEm. Alternatively, if you aren't comfortable giving out your email, you can change all your passwords now. Simply type your email address into the IsLeaked tool to see if your account has been exposed.
However, the tool is not without controversy. Life Hacker actually isn’t promoting it anymore after it said it discovered the “tool” was made public just two days before the Gmail leak was reported.
Google said in a blog post late Wednesday that "less than 2% of the username and password combinations might have worked," adding one more reason not to overreact to this dump.
Google also said that it has contacted the owners of the affected accounts "and have required those users to reset their passwords." So if you haven't heard back from Google, you should be fine. (Though periodically changing your password isn't a bad idea, and two-factor is a must.)
Meanwhile, more security experts seem to agree that the leak is probably almost entirely made of old passwords tken from previous leaks and dumps. Whoever put this particular one together, probably "concatenated several dozen dumps" and then published only the Gmail usernames and password combinations he found, said Jeremi Gosney, the co-founder of PasswordsCon, a hacker conference focusing specifically on passwords and other methods of authentication.









