Microsoft Announces Windows 10 BlackBerry Launches Passport in India for Rs. 49,990 The World's Slimmest SmartPhone : Gionee Elife S5.1 iOS 8 Has Finally Arrived Apple Unveils iPhone 6 and iPhone 6 Plus

Showing posts with label security. Show all posts

BlackBerry Launches Passport in India for Rs. 49,990


BlackBerry has launched the BlackBerry Passport, the company’s latest high-end smartphone in India. It was unveiled last week and packs a 4.5” diagonal (1440 x 1440 pixels) display with Corning Gorilla Glass 3 protection, quad-core Snapdragon 800 (MSM8974-AA) processor and runs on BlackBerry OS 10.3 with new BlackBerry Assistant, BlackBerry own personal assistant.
Blackberry keyboard also gets an update, with touch enabled keys right above, on-screen. It has a 13-megapixel rear camera with LED Flash, 2-megapixel front-facing camera and has 4G LTE connectivity. It has 3GB RAM, 32GB of internal memory with expandable memory up to 64GB. It comes pre-loaded with the Amazon appstore for all the Android app needs while the Blackberry world app store will focus on enterprise apps. We unboxed the BlackBerry Passport recently, check out the unboxing.

BlackBerry Passport Specifications :
  • 4.5-inch diagonal (1440 x 1440 pixels) 453 PPI 10-point multi-touch display with Corning Gorilla Glass 3 protection
  • 2.2 GHz quad-core Snapdragon 800 (MSM8974-AA) processor with 450MHz Adreno 330 GPU
  • 13MP Auto-Focus rear camera with 6DOF OIS, BSI sensor, 5-element f2.0 lens, LED Flash 1080p HD video recording at 60fps
  • 2MP Fixed-Focus front-facing camera with Image & video stabilization, 720p HD video recording
  • Dimensions: 128 x 90.3 x 9.3mm; Weight: 196g
  • 3.5mm audio jack, FM Radio
  • 3GB LPDDR3 800MHz RAM, 32GB internal memory, Expandable memory up to 64GB with microSD
  • 4G LTE, WiFi 802.11 b/g/n (2.4GHz and 5GHz), Bluetooth 4.0 LE, SlimPort, NFC, GPS + GLONASS
  • 3450mAh integrated non-removable battery
The BlackBerry Passport comes in Black and White colors and is priced in India at Rs. 49,990. It is available for pre-booking at Amazon.in and BlackBerry exclusive stores starting today, 29th September till October 10th and goes on sale on October 10th. Those who are pre-booking the smartphone on Amazon would get Rs. 5000 worth Amazon gift card and 5000 complimentary miles from Jet airways.
Wednesday, 1 October 2014
Posted by Unknown

Apple Releases iOS 8.0.2 Update with Bugs Fixes


The iOS 8.0.2 update also “includes improvements and bug fixes originally in iOS 8.0.1.
“We apologise for inconveniencing the iPhone 6 and iPhone 6 Plus users who were impacted by the bug in iOS 8.0.1,” Apple said.

On Wednesday, the company was forced to pull the 8.0.1 update after 60 minutes of availability, because of user reports that it was disrupting cellular network connections and Touch ID fingerprint scanning on iPhone 6 and iPhone 6 Plus models.

An Apple spokeswoman said that fewer than 40,000 devices were affected by the bug.
The following is Apple’s list of the fixes included in the 8.0.2 release:
— Fixes an issue in iOS 8.0.1 that impacted cellular network connectivity and Touch ID on iPhone 6 and iPhone 6 Plus
— Fixes a bug so HealthKit apps can now be made available on the App Store
— Addresses an issue where 3rd party keyboards could become deselected when a user enters their passcode
— Fixes an issue that prevented some apps from accessing photos from the Photo Library
— Improves the reliability of the Reachability feature on iPhone 6 and iPhone 6 Plus
— Fixes an issue that could cause unexpected cellular data usage when receiving SMS/MMS messages
— Better support of Ask To Buy for Family Sharing for In-App Purchases
— Fixes an issue where ringtones were sometimes not restored from iCloud backups
— Fixes a bug that prevented uploading photos and videos from Safari

Apple had previously delayed the introduction of third-party HealthKit-compatible apps to the App Store due to a bug in iOS 8. The buggy software release came on the heels of another fiasco for Apple: users reporting that their iPhone 6 Plus models were bending in their pockets.

Several videos appeared on the internet depicting phones being bent by hand. Apple responded to what Twitter users began calling “Bendgate” with an explanation of its iPhone 6 and 6 Plus durability tests, and a statement that only nine users had reported bent iPhone Plus models in the first six days of sales. Apple’s stock fell 3.8 per cent to $US97.87 on Thursday in the US amid the iPhone concerns.

Android's Next Version Will Come With Default Encryption


Yesterday, Apple commented that iOS 8 the user data stored on iPhones or iPads are fully encrypted, so no one, not even Apple, can access them, even with a court or government order. This is certainly an interesting point for the operating system of the Apple company, and Google seem to think the same. The reason is that a few hours after these statements, the guys at Google have announced that Android 5.0, the next version of the popular operating system for mobile devices, also have default data encryptio.

As we say, by this measure, the data stored on devices with newer versions of iOS and Android will be completely inaccessible, unless the person has the correct password. Three years ago, Google already offers the ability to encrypt our data Phones with Android installed, but this measure, it simply ceases to be a possibility , becoming a default feature. As a result, all users will benefit from this improved safety, because until now, it was an option that activated only those with technical expertise.

Undoubtedly, the two companies that dominate the market for mobile operating systems take such measures is something to behold. Anything that increases the security and privacy of user data is welcome.
Tuesday, 30 September 2014
Posted by Unknown

Android Security Flaw Affects Millions of Users


Security experts have discovered a new flaw in Android browser that allows attackers to run scripts that can read the contents of any open tab and harvest private data. The security flaw affects Android devices running any version prior to 4.4.

The flaw was first reported by ethical hacker and blogger Rafay Baloch, who has tested it on a variety of devices, since then his findings have further been confirmed by others in the security industry. According to Google's own analytics, this affects at least 75 percent of all Android users as very large proportion of new phones also ship with Android 4.3 or lower.

According to reports the problem relates the Single-Origin Policy, which can be bypassed for the Android browser by deliberately feeding it a malformed instruction which allows scripts to be run without supervision. This simple exploit allows attackers to read data even from secure sites once they are opened, and redirect the data to any external site.

According to Baloch, "A SOP bypass occurs when a siteA.com is some how able to access the properties of siteB.com such as cookies, location, response etc. Due to the nature of the issue and potential impact, browsers have very strict model pertaining it and a SOP bypass is rarely found in modern browsers, however, they are found once in a while."
Security experts have discovered a new flaw in Android browser that allows attackers to run scripts that can read the contents of any open tab and harvest private data. The security flaw affects Android devices running any version prior to 4.4.
The flaw was first reported by ethical hacker and blogger Rafay Baloch, who has tested it on a variety of devices, since then his findings have further been confirmed by others in the security industry. According to Google's own analytics, this affects at least 75 percent of all Android users as very large proportion of new phones also ship with Android 4.3 or lower.
- See more at: http://www.digit.in/mobile-phones/android-security-flaw-affects-millions-of-users-23921.html#sthash.Nu0pgKIr.dpuf
Thursday, 18 September 2014
Posted by Unknown

A List of 5 Million 'Gmail Passwords' Leaked

A list of almost 5 million combinations of Gmail addresses and passwords was posted online on Tuesday. But the passwords seem to be old, and they don't appear to actually belong to Gmail accounts. Instead, it seems that many of the passwords were taken from websites where users used their Gmail addresses to register, according to some of the leak's victims as well as security experts.

For example, someone might have signed up for a website with the username "myaddress@gmail.com" and the password "mypassword." The list exposed this week makes it look like "mypassword" is the password for the Gmail account itself, but the user's actual Gmail password might be totally different.

The list was posted on a Russian Bitcoin forum on Tuesday evening, and local media started reporting on it on Wednesday. We can't confirm the authenticity of all the email addresses on the list, but a Mashable employee, Evan Engel, saw that his old Gmail password, which he hasn't used in years, is part of the leak.

A Google spokesman told Mashable that the company has "no evidence that our systems have been compromised," and security experts seem to agree that the passwords are either old Gmail passwords obtained through phishing, or are passwords that were actually used on other sites.

Matteo Flora, a computer security expert, reviewed the dumped file and found that around 60 email addresses were in his address book. After he alerted those people, 30 of them told him that the password either was never used for their Gmail accounts or was very old, Flora told Mashable.
Chester Wisniewski, a senior security adviser for security firm Sophos, told Mashable that he expects many of these accounts not to be valid. "There is no honor among thieves as they say, and often stunts like this are released as a sad attempt at gaining credibility among other criminals," he said.
Several Reddit users also confirmed that they found their email addresses in the leak, but that the associated password has never been their Gmail password.

To check if your password was one of the leaked, plug your Gmail address into this trusted tool from KnowEm. Alternatively, if you aren't comfortable giving out your email, you can change all your passwords now. Simply type your email address into the IsLeaked tool to see if your account has been exposed.

However, the tool is not without controversy. Life Hacker actually isn’t promoting it anymore after it said it discovered the “tool” was made public just two days before the Gmail leak was reported.


Google said in a blog post late Wednesday that "less than 2% of the username and password combinations might have worked," adding one more reason not to overreact to this dump.
Google also said that it has contacted the owners of the affected accounts "and have required those users to reset their passwords." So if you haven't heard back from Google, you should be fine. (Though periodically changing your password isn't a bad idea, and two-factor is a must.)

Meanwhile, more security experts seem to agree that the leak is probably almost entirely made of old passwords tken from previous leaks and dumps. Whoever put this particular one together, probably "concatenated several dozen dumps" and then published only the Gmail usernames and password combinations he found, said Jeremi Gosney, the co-founder of PasswordsCon, a hacker conference focusing specifically on passwords and other methods of authentication.
Friday, 12 September 2014
Posted by Unknown

WhatsApp Soon Becoming Police's Powerful Assistant


WhatsApp, the popular cross-platform messaging app, is gradually becoming a very powerful tool for police departments to curb crime. The Lucknow Police has introduced a WhatsApp complaint tool where users can send their complaints about traffic offences.

Police is also planning to connect the helpline no. 1090 with WhatsApp to curb eve teasing. Railway Police is also considering to use WhatsApp to keep a track on ticket collectors, vendors selling food products, and coach attendants.

The Police department in Mumbai has set up several WhatsApp groups aimed at helping people to lodge complaint about for crime such as eve teasing. The Delhi and Kochi police also have WhatsApp helpline number to help people report about corruption in the police department. With messaging apps such as WhatsApp becoming popular among users, it's heartening to see security agencies are also staying up to date with the latest trend. Source DeccanChronical.

Indian Government Spying on Internet Users


Internet is free and a sign of empowerment for many youth. But the big question: are all our movement online is being monitored? As an online enthusiasts if your answer is in positive then you are wrong. All your online activities are being monitored and collected.

This fact could be established after a reported launched by the Software Freedom Law Centre (SFLC) titled India’s Surveillance State at the Internet Governance Forum, currently underway in Istanbul.
Those who have a look at this report confirmed that the state has put in number of Lawful Interception and Monitoring systems to keep an eye on people who spend time online.

And monitoring such people is easy. Moreover, as internet penetration increases, surveillance too will increase. R.S. Sharma, secretary, Department of Electronics & Information Technology (DeiTY), Government of India, said: “Indians without access to internet form 25% of the people in the world left out of the digital world. So it was the priority of GoI to attend sessions where we could pick up ideas on how to bridge this gap. By December 2016 we aim to bring broadband connectivity to all panchayats.”

The report also throws light to the system adopted by the government to spy on its online citizens. It is understood that an unknown number of Lawful Interception and Monitoring (LIM) systems are installed in India’s communication networks, helping officials to not only collect users’ communications data and meta-data but also to analyse them.

Nokia Lumia 830 Announced


It’s just gone official. The “first affordable flagship,” the Nokia Lumia 830, has been announced at IFA 2014 by Microsoft’s Devices and Services group. The device features an impressive camera and pretty decent specs for quite the affordable price.

It comes with Windows Phone 8.1, Microsoft Office, OneDrive, Cortana, and more. Microsoft is up-playing the fact that Windows Phone 8.1 allows for much customization to the interface like with the new “Glance” lock screen.

Microsoft has developed a new screen sharing accessory that operates with NFC-enabled Lumia devices to let you project your screen to the big screen. It has a really long name, as those Redmond people just had to call it Microsoft Screen-Sharing for Lumia Phones HD-10.
Nokia Lumia 830 Specifications :

  • Main camera sensor: 10 MP, PureView
  • Display size: 5''
  • Display resolution: HD720 (1280 x 720)
  • Processor name: Snapdragon 400
  • Maximum talk time (3G): 14.8h
  • Battery capacity: 2200mAh
  • Wireless charging: Built-in (Qi standard)
Dimensions
  • Height: 139.4 mm
  • Width: 70.7 mm
  • Thickness2: 8.5 mm
  • Weight: 150 g
Display and User Interface
  • Display size: 5 ''
  • Display resolution: HD720 (1280 x 720) 
  • Display features: Brightness control, Nokia Glance screen, Sunlight readability enhancements, Corning® Gorilla® Glass 3, Easy to clean, High brightness mode, Lumia Color profile, Sculpted glass, Wide viewing angle, Double-tap to wake
  • Display colors: TrueColor (24-bit/16M) 
  • Aspect ratio: 16:9 
  • Pixel density: 296 ppi
  • Display technology: ClearBlack, IPS LCD 
  • Touch screen technology: Super sensitive touch 
  • Sensors: Ambient light sensor, Accelerometer, Proximity sensor, Gyroscope, Magnetometer
  
Processor 
  • Processor name: Snapdragon 400 
  • Processor type: Quad-core 1.2GHz

Memory
  • User data storage: In device, Memory card, OneDrive cloud storage, App and data storage on memory card
  • RAM: 1 GB 
  • Mass memory: 16 GB 
  • Expandable memory card type: MicroSD 
  • Maximum memory card size: 128 GB 
  • Free cloud storage: 15 GB

 

Keys and Input Methods
  • User Input: Touch 
  • Operating keys: Volume keys, Camera key, Power/Lock key


Connectivity
  • SIM card type: Nano SIM 
  • Charging connectors: Micro-USB 
  • AV connectors: 3.5 mm audio connector 
  • System connectors: Micro-USB-B 
  • USB: USB 2.0 
  • Bluetooth: Bluetooth 4.0 
  • Bluetooth profiles: Advanced Audio Distribution Profile (A2DP) 1.2, Phone Book Access Profile (PBAP) 1.1, Generic Attribute Profile (GATT), Audio/Video Remote Control Profile (AVRCP) 1.4, Hands-free profile (HFP) 1.6, Object Push profile (OPP) 1.1, Personal Area Network Profile (PAN) 1.1
  • Wi-Fi: WLAN IEEE 802.11 a/b/g/n 
  • Wi-Fi security modes: EAP-TTLS/MSCHAPv2, WPA, WEP, EAP-AKA, PEAP-MSCHAPv2, WPA2 (AES/TKIP), WPA2-Enterprise, WPA2-Personal, EAP-TLS, WPA-Enterprise, EAP-SIM, WPA-Personal
  • NFC: Pairing, Secure NFC for payment, Sharing, Tagging
  • Other wireless connectivity: Wi-Fi Channel bonding, Screen projection

Productivity features
  • Personal information management features: Calculator, Clock, Calendar, Alarm clock, Reminders, Phonebook, To-do list, Family Room, Kid's Corner, OneNote, Social networks in Phonebook, Wallet, Notifications
  • Business apps: Lync (Corporate IM) free download, Company Hub for enterprise applications, Office apps: Excel, Word, PowerPoint, OneNote, OneDrive storage for documents and notes, Adobe Reader free download
  • Document formats supported: PDF, Word, Excel, OneNote, PowerPoint
  • Sync type: Exchange ActiveSync, Via Windows Phone apps, Nokia Photo Transfer for Mac
  • Sync content: Calendar, Video, Pictures, Music, Contacts.

Email and Messaging
  • Email clients: Gmail, Nokia Mail, MS Exchange Active Sync, Windows Live / Hotmail / Outlook.com, Yahoo! Mail, IBM Notes Traveler, Outlook / Office 365 / Exchange
  • Email protocols: SMTP, IMAP4, POP3
  • Email features: Viewing and editing of email attachments, Multiple email accounts, HTML emails, Inbox filtering, Text-to-speech message reader, Conversational view on email, Linked inboxes, Word flow keyboard
  • Supported instant messaging services: WhatsApp, Skype IM, WeChat, Viber, LINE, MySpace, Twitter, Yahoo! Messenger
  • Messaging features: Text messaging, Automatic resizing of images for MMS, Distribution lists for messaging, Multimedia messaging, Conversational chat style SMS, Unified inbox for SMS and MMS, Concatenated SMS for long messages, Integrated text messaging and chat, Number screening for messaging, Text-to-speech message reader.

Security
  • Enterprise security features: Mobile VPN, Remote lock and wipe, Hardware accelerated device encryption, Mobile device management, Remote security policy enforcement
  • General Security features: Device lock, PIN code, Device lock passcode, Regular signed firmware updates, Track and Protect via internet, Application certification, Application sandboxing, Backup and restore via Internet, Browser integrated anti-phishing, Remote device lock via Internet, Remote device wipe via Internet, Secure boot, Signed OS, Consumer VPN
  • Supported security standards: TLS v1.0, TLS v1.1, TLS v1.2, SSL v3.0, Suite B ciphers

GPS and navigation
  • Location and navigation apps: HERE Drive+, HERE Maps, HERE Transit, Local Scout
  • Navigation features: Public transportation routing guidance, Free maps, Offline maps, Augmented reality with LiveSight, Automatic day/night view switching, Download the latest maps with Wi-Fi, Fast search with type-ahead suggestions, Find upcoming departure times, Free global voice guided turn-by-turn drive navigation, Live traffic information, Online and offline favourites, Pin places to Start screen, Speed limit warnings, Venue maps - shopping and transport centers
  • Location technologies: Cellular and Wi-Fi network positioning, A-GPS, A-GLONASS, BeiDou, Sensor enhanced positioning

Main camera
  • Main camera sensor: 10 MP, PureView 
  • Main camera focus type: Auto focus with two-stage capture key 
  • Camera digital zoom: 4 x
  • ZEISS optics: Yes 
  • Sensor size: 1/3.4 inch 
  • Main camera f-number/aperture: f/2.2 
  • Camera focal length: 26 mm
  • Camera minimum focus range: 10 cm
  • Camera image formats: JPEG/Exif 
  • Flash type: LED flash 
  • Flash operating range: 2.0 m
  • Flash modes: Off, Automatic, On

Secondary camera
  • Secondary camera: HD 0.9 MP wide angle 
  • Secondary camera f-number/aperture: f/2.4 
  • Secondary camera - other features: Video recording, Still image capture, Video call
 

Image capturing
  • Capture modes: Video, Still
  • Scene modes: Automatic, Sports, Night
  • White balance modes: Cloudy, Incandescent, Fluorescent, Daylight, Automatic
  • Light sensitivity: Automatic, ISO 100, ISO 200, ISO 400, ISO 800, ISO 1600, ISO 3200
  • Photos viewed by: Month, Photo editor, Album, Timeline, Camera Roll, Favorites, Nokia Storyteller, Photos from social networks
 

Main video camera
  • Camera video resolution: 1080p (Full HD, 1920 x 1080) 
  • Camera video frame rate: 30 fps
  • Camera video zoom: 4 x
  • Video playback frame rate: 30 fps
  • Video playback codecs: H.263, H.264/AVC, MPEG-4, VC-1, Windows video
  • Video playback file formats: 3G2, 3GP, MP4, WMV, AVI, M4V, MOV
  • Video recording formats: MP4/H.264 
  • Video white balance modes: Cloudy, Fluorescent, Incandescent, Automatic, Daylight
 
Browsing and Internet
  • Internet browser capabilities: Internet Explorer 11 
  • Social apps: Facebook, LinkedIn, Twitter, WhatsApp
  • Photo sharing: Facebook, Send as email attachment, Share over Bluetooth, Flickr, Picasa, Tap and share images or videos with NFC, Nokia Beamer, OneDrive, Share on TV with Nokia Play To DLNA app
  • Video sharing: Video sharing to social network and internet, Facebook, Flickr, Joyn video call sharing, OneDrive, Picasa, Share on TV with Nokia Play To DLNA app, Video sharing with NFC, YouTube
  • Location sharing: WP location sharing, Foursquare
  • Wi-Fi hotspot: Up to 8 Wi-Fi-enabled devices


Data Network 
  • LTE network bands: 1, 3, 7, 8, 20
  • LTE max data speed DL: 150 Mbps 
  • LTE max data speed UL: 50 Mbps 
  • WCDMA network: 850 MHz, 900 MHz, 1900 MHz, 2100 MHz
  • WCDMA max data speed DL: HSDPA - 42.2 Mbps 
  • WCDMA max data speed UL: HSUPA - 5.76 Mbps 
  • GSM network: 850 MHz, 900 MHz, 1800 MHz, 1900 MHz
  • GSM max data speed DL: EGPRS 296.0 kbps 
  • GSM max data speed UL: EGPRS 236.8 kbps 
Power Management
  • Battery model: BV-L4A 
  • Battery capacity: 2200 mAh
  • Battery voltage: 3.8 V
  • Removable battery: Yes 
  • Maximum standby time: 22 days
  • Maximum talk time (2G): 12.9 h
  • Maximum talk time (3G): 14.8 h
  • Maximum music playback time: 78 h
  • Maximum video playback time: 10 h
  • Maximum cellular network browsing time: 11 h
  • Maximum Wi-Fi network browsing time: 14 h
  • Wireless charging: Built-in (Qi standard)
 
 The Lumia 830 comes in bright orange, bright green, white and black colors and would roll out globally starting this September at estimated to be priced of 330 Euros (Rs. 26,220 / US$430 approx.) before taxes and subsidies.

Apple Is Gathering Celebrity Login Info For iCloud Hack Investigation


Apple is working directly with celebrities and their publicists to investigate the alleged iCloud hack that may have played a large part in a large cache of nude photographs being released online. Part of that investigation involves obtaining Apple account login information of the people affected, Mashable has learned.

It's not known exactly why Apple needs its users' login information, but presumably it gives them a level of access into a user's account records that they otherwise wouldn't be able to obtain, at least not easily. The company does say that password information stored in iCloud is encrypted and can't be read by Apple. Apple's internal investigation may shine some light on how nude photos of dozens of celebrities were gathered and then released over the weekend. While some have pointed to a potential vulnerability in iCloud security (which has reportedly been patched), there are indications, including the age of some of the photos, that the cache was part of a larger, more complicated effort.

At the same time, the FBI is looking into the iCloud hack, although it stopped short of saying it was opening a full investigation. The incident also raises unsettling questions about the general state of security for cloud storage services, which are now a major part of both personal services and business workflow.
Thursday, 4 September 2014
Posted by Unknown

Times of India Takes Away Their Journalists' Privacy on Facebook and Twitter


The Times of India basically wants its journalists to hand over their Facebook and Twitter profiles - which means usernames and passwords - to the company so that the latter can use them for professional purposes. The Times of India journalist now has two options - either to convert his/her personal social media account into a company account or to create a new account to be run by the company. Moreover, no journalist will be allowed to post news and related material on their own Facebook and Twitter accounts.

The company shall be the owner of the access passwords, username and associated email address for the User Account, which shall be used by you on behalf of the Company to make posts. Company retains administration rights of the User Account, which shall be made accessible to the Company on demand. It is understood that sharing of such details of the User Account shall be an integral part of your contract with the Company and shall also be necessary for processing any settlement related to termination of such Contract.

Thus, according to the new contract, the company can post at will on the journalist's social media account even without his/her knowledge.
Even worse, the journalist will not regain exclusive use of his/her account even after he/she has left the company. Times of India will retain the right to continue operating the account in the journalist's name.
In short, as a Times of India journalist you will be promoting the company's stories and viewpoints on social media even after you quit as an employee! As the contract reads:
The company may upload news or other material on the company User Account through any means, including automated upload streams, at its sole discretion, notwithstanding any termination of your contract with the company.

Here's a relevant part from the contract:
The posts made by you on User Account shall contain news and other related material and may also contain any personal material and interaction, which we encourage. You shall inform the company about your personal user accounts and the same will be allowed by the company, subject to you refraining from posting any news and other related material on the same. The personal user account shall always belong to you and carried by you in the event of any severance of your contract with the company. At your request, while in employment, your personal user account may be converted into a company User Account. It is specifically agreed that on such conversion, all intellectual property rights in such converted User Account shall be vested in the company.

To be fair though, the company's journalists are still active on Twitter, so the new policy does not seem to have come into effect yet.

But this is not the first instance of a bizarre, even oppressive clause being part of the Times of India contract. For example, though the contract stipulates that an employee should not receive gifts from a person/s who may have dealings with the company, it even goes on to state that gifts given as prizes at exhibitions or as part of a free raffle may be accepted but 'in principle' it belongs to the company.
In conclusion, apart from the fact that the proposed social media policy constitutes a violation of the personal space of an individual, it also means the employees are reduced to virtually being PR agents of Times of India. While it is unclear whether the policy has been implemented as yet, the ethics of it must be questioned.
Monday, 1 September 2014
Posted by Unknown

You Can Hack Gmail with 92% Success Rate: Researchers


Your most trustworthy apps may be at risk. Researchers say they have found a way to hack Gmail apps with a 92 percent success rate. In a paper being presented Friday at the Usenix cybersecurity conference, the engineers said they also could steal check images from a Chase app with an 83 percent success rate and hack personal information such as address and Social Security numbers from H&R Block (success rate 92 percent), Newegg (86 percent), WebMD (85 percent), Hotels.com (83 percent) and Amazon (48 percent) apps.

The hacker would gain access by causing a user to install a seemingly harmless app such as phone wallpaper and expose a newly discovered public side channel that doesn't require privileges. This feature allows processes to share data efficiently and is quite common, since all a phone's downloaded apps interact with one operating system.

"The assumption has always been that these apps can't interfere with each other easily," researcher Zhiyun Qian said in a statement. "We show that assumption is not correct and one app can in fact significantly impact another and result in harmful consequences for the user."
The other contributors to the paper were Z. Morley Mao, associate professor at the University of Michigan, and Qi Alfred Chen, a Ph.D., student working with Mao. Qian, a recent doctoral graduate from Mao's group, is a professor at the University of California, Riverside. The researchers said they had only a 48 percent success with the Amazon app because it allows transition from one activity to almost any other, increasing the difficulty of guessing what the user is doing and finding the exact moment to steal data.

After a high-profile breach of credit card data at Target late last year, reports of cybersecurity attacks on companies and government agencies have been on the rise recently. He added that consumers will probably start looking more into state-of-the-art identification protection services.

"As secure as we thought we were a year or two ago, we're seeing another wave across app platforms everywhere," said Brian Blair, analyst at Rosenblatt Securities. "We're going to have to have app developers create a layer of new security. There's not much I see consumers can do. We have to wait for all companies that store our info to upgrade."


"Users should be cautious and only download apps from trusted sourcesbig, popular apps are hacker magnets," he said in an email. "Do a routine check of your smartphone and tablet, especially if you have little ones using the device, to ensure only apps that can be trusted are the only ones installed. Immediately uninstall apps that appear to be from unknown sources or are not necessary."

Twitter's BotMaker Tool Cuts Spam by 40 Percent


Twitter has introduced a new anti-spam system called BotMaker and says that it is responsible for a 40 percent reduction in its key spam metrics. The BotMaker anti-spam system was created with one low-latency sub-system (Scarecrow) which checks in real time the content posted on the site and decides whether the content should be approved or not. The second computationally-intense and learning sub-system (Sniper) checking in ‘near real time’ the user and content event logs that make it past the Scarecrow.

The BotMaker is constantly fed information by Scarecrow and Sniper, and issues commands to approve, deny or challenge posts. The micro-blogging site also runs periodic jobs on all the data compiled by the BotMaker system for routine checks to specific exercises by the engineering department.

Twitter’s Raghav Jeyaraman stated in an official blog post the challenges faced by the team in creating BotMaker. He stated that due to Twitter’s wide-ranging developer APIs, meant for third-parties to interact with the platform, spammers “know (almost) everything” about how the micro-blogging network functions, which makes it difficult to create an anti-spam system.

Jeyaraman wrote, “These operating conditions are a stark contrast to the constraints placed upon more traditional systems, like email, where data is private and adding latency of tens of seconds goes unnoticed. So, to fight spam on Twitter, we built BotMaker, a system that we designed and implemented from the ground up that forms a solid foundation for our principled defense against unsolicited content,” he said. “The system handles billions of events every day in production, and we have seen a 40 percent reduction in key spam metrics since launching BotMaker.”

A recent report by Twitter revealed that nearly 23 million of active users on the site are ‘Bots’. However, the company says that these accounts are not necessarily spam accounts, which make up less than 5% of total MAUs. These spam accounts affect advertisers who are interested in reaching potential customers through the micro blogging site.

Ebola Fear Used as Bait, Leads to Malware Infection


News of the Ebola virus epidemic in West Africa has hit every news outlet around the globe, and cybercriminals are once again using the latest headlines to bait victims. Symantec has observed three malware operations and a phishing campaign using the Ebola virus as a social engineering theme.

Malware and Phishing Campaigns

The first campaign is fairly simple, where attackers send out an email with a fake report on the Ebola virus to entice victims and what users actually get is an infection of the Trojan.Zbot malware. In the second campaign, cybercriminals send out an email that impersonates a major telecommunications services provider and claims to offer a high-level presentation on the Ebola virus. An attached zip file with a title like “EBOLA – PRESENTATION.pdf.zip” actually

Interestingly, the executed Trojan is not the final payload. The malware is also crafted to inject W32.Spyrat into the victim’s web browser and allows attackers to perform actions such as, log key strokes, record from the web cam, capture screenshots, create processes, open web pages, enumerate files and folders, delete files and folders, download and upload files, gather details on installed applications, the computer, and operating system, and uninstall itself.

The third campaign piggybacks on some fresh Ebola news. In the last two weeks there has been talk of Zmapp, a promising Ebola drug still in an experimental stage. The crooks entice their victims with an email claiming the Ebola virus has been cured and the news should be shared widely. The email attachment is Backdoor.Breut malware.

Another is a phishing campaign that impersonates CNN with breaking Ebola news (with some terrorism thrown in). It gives a brief story outline and includes links to an “untold story.” The email also promises “How-to” precaution information and a list of “targeted” regions. If the user clicks on the links in the email they are sent to a Webpage, asked to select an email provider, and asked to input their login credentials. If the user performs this action, their email login credentials will be sent directly to phishers. The victim is redirected to the real CNN home page.

 Symantec advises all users to be on guard for unsolicited, unexpected, or suspicious emails. If you are not sure of the email’s legitimacy then don’t respond to it, and avoid clicking on links in the message or opening attachments.

Symantec advises all users to be on guard for unsolicited, unexpected, or suspicious emails. If you are not sure of the email’s legitimacy then don’t respond to it, and avoid clicking on links in the message or opening attachments. - See more at: http://www.channelworld.in/news/ebola-fear-used-bait-leads-malware-infection-514062014#sthash.dIZnWG56.dpuf


Interestingly, the executed Trojan is not the final payload. The malware is also crafted to inject W32.Spyrat into the victim’s web browser and allows attackers to perform actions such as, log key strokes, record from the web cam, capture screenshots, create processes, open web pages, enumerate files and folders, delete files and folders, download and upload files, gather details on installed applications, the computer, and operating system, and uninstall itself.
The third campaign piggybacks on some fresh Ebola news. In the last two weeks there has been talk of Zmapp, a promising Ebola drug still in an experimental stage. The crooks entice their victims with an email claiming the Ebola virus has been cured and the news should be shared widely. The email attachment is Backdoor.Breut malware.
Another is a phishing campaign that impersonates CNN with breaking Ebola news (with some terrorism thrown in). It gives a brief story outline and includes links to an “untold story.” The email also promises “How-to” precaution information and a list of “targeted” regions.
If the user clicks on the links in the email they are sent to a Webpage, asked to select an email provider, and asked to input their login credentials. If the user performs this action, their email login credentials will be sent directly to phishers. The victim is redirected to the real CNN home page.
- See more at: http://www.channelworld.in/news/ebola-fear-used-bait-leads-malware-infection-514062014#sthash.dIZnWG56.dpuf
News of the Ebola virus epidemic in West Africa has hit every news outlet around the globe, and cybercriminals are once again using the latest headlines to bait victims. Symantec has observed three malware operations and a phishing campaign using the Ebola virus as a social engineering theme.
Malware and Phishing Campaigns
The first campaign is fairly simple, where attackers send out an email with a fake report on the Ebola virus to entice victims and what users actually get is an infection of the Trojan.Zbot malware.
In the second campaign, cybercriminals send out an email that impersonates a major telecommunications services provider and claims to offer a high-level presentation on the Ebola virus. An attached zip file with a title like “EBOLA – PRESENTATION.pdf.zip” actually
- See more at: http://www.channelworld.in/news/ebola-fear-used-bait-leads-malware-infection-514062014#sthash.dIZnWG56.dpuf
News of the Ebola virus epidemic in West Africa has hit every news outlet around the globe, and cybercriminals are once again using the latest headlines to bait victims. Symantec has observed three malware operations and a phishing campaign using the Ebola virus as a social engineering theme.
Malware and Phishing Campaigns
The first campaign is fairly simple, where attackers send out an email with a fake report on the Ebola virus to entice victims and what users actually get is an infection of the Trojan.Zbot malware.
In the second campaign, cybercriminals send out an email that impersonates a major telecommunications services provider and claims to offer a high-level presentation on the Ebola virus. An attached zip file with a title like “EBOLA – PRESENTATION.pdf.zip” actually
- See more at: http://www.channelworld.in/news/ebola-fear-used-bait-leads-malware-infection-514062014#sthash.dIZnWG56.dpuf

Can a YouTube Cat Video Infect Your Computer?


Those cute little cat video you just watched could cost you millions. And it’s not just about cat videos – innocent videos on YouTube can be used to infect computers with dangerous malware, as revealed in the latest report by Morgan Marquis-Boire, a hacker-turned-researcher. In the report created for Citizen Lab, he described how a simple network injection tool can be used to infiltrate home computers.Such video attacks that use network injections have their own strengths and weaknesses. Other attacks like watering hole and phishing need the user to do something ‘wrong’, like clicking on an infected file or link. Network injections don’t need that. Any simple browser behavior, such as watching a funny cat video, can trigger such attacks. There is a limit, however – once the user’s computer has been infected, the infection is confined to the browser. And such network injection tools aren’t even difficult to find; they can be easily procured from companies like FinFisher and Hacking Team.

These tools, or rather appliances, are physical devices that can be stored inside ISP servers all over the world. To execute an attack, the malicious code is injected into the everyday browsing traffic. One simple way to do this is by using YouTube streams that are unencrypted. The hacker can target a user and then wait for them to watch a YouTube video. They can then intercept the traffic and replace it with their own code. This would give them complete control over the user’s device.

This method can be used for any unencrypted website that offers targeted traffic, but since YouTube is one of the most commonly visited websites, it can be an easy target for hackers. Another website that can be exploited in this way is login.live.com of Microsoft. Google and Microsoft have taken a note of this vulnerability and have encrypted all targeted traffic. This has made most videos safe; however, there are other vulnerabilities that devices from FinFisher and Hacking Team can exploit.

This can turn into a high-level problem, and companies have to take action to make sure that the Internet experience can become safe for an average user. Meanwhile, users can encrypt their files to make sure that no data can be stolen from their computers. This is not the only hacking tool that is easily available. Tools that could perform man-in-the-middle attacks have been openly available for many years. For example, the Ettercap open source tool allows the hackers to intercept and manipulate traffic on LANs. This tool was developed by Marco Valleri and Alberto Ornaghi in 2001. These two guys are the founders of Hacking Team, the same company that creates network injector devices that can infect YouTube videos.

The only thing that could prevent such attacks is encryption. With the rising number of hacking cases, there is a need for an encrypted Internet that can protect an average user from malware. Web developers need to make sure that their websites are encrypted and safe to use. Until then, users need to be wary of their online activities, including watching cat videos on YouTube.

Gmail, Yahoo Make Phone Number Mandatory For New Email Ids


World's most popular free email providers Gmail and Yahoo have made telephone number mandatory for creation of new email addresses in a bid to check spam. Any person wishing to create a new email id needs to provide a telephone number which Gmail and Yahoo use for verification. Google India spokesperson claimed giving phone number was optional but repeated attempts to create a new email address on Gmail by skipping the mobile number requirement failed.

The Gmail website said that move to seek phone number is to check spam email senders. "In an effort to protect our users from abuse, we sometimes ask users to prove they're not a robot before they're able to create or sign in to accounts. Having this additional confirmation via phone is an effective way to keep spammers from abusing our systems," the website said.

Google has also limited number of accounts that a person using one telephone number can create but the website did not specify the maximum number of email account it will allow. While for Gmail a person can give either telephone or mobile number, for a new Yahoo it is now mandatory to have a mobile number.

"At Yahoo, we are committed to the security of our users. We ask our users to provide their mobile number at registration as a secondary means of authentication, in addition to their password. We would only use the number if we see any unusual activity on the account," Yahoo spokesperson said. Internet Service Providers Association of India said that there is no regulatory requirement for making telephone number mandatory for having an email address and condemned the move as such practice could expose privacy of an individual.

"This is an attack on user's privacy. This should not happen. If they (Gmail and Yahoo) are doing such a thing, then this must be recognised by Indian government on how they are collecting phone numbers," ISPAI President Rajesh Chharia said. Internet companies have been advocating at global level that there should be no kind of restriction on use of Internet and if there are any regulations on Internet, then the cost associated with compliance of those regulations should be such that it should not check proliferation of Internet usage. Though number of telecom subscriber is over 90 crore in India, a survey conducted by research firm Juxt in 2013 showed there were only about 55.48 crore people in the country who actually owned a mobile device.
Sunday, 24 August 2014
Posted by Unknown

Yahoo, Google Envision Spy-Free Emails

 
Yahoo said Thursday it will join an effort by rival Google Inc. Google to create a secure email system by next year that could make it nearly impossible for hackers or government officials to read users' messages. Even the email providers themselves won't be able to decrypt messages.

Google in June announced plans to develop spy-proof email. The addition of Yahoo is notable because the two have access to so many email users and Yahoo shed new details on the project. Google counts 425 million unique Gmail users, Yahoo 110 million.

Microsoft, which offers the free Web email service Outlook.com, has previously said it is working to incorporate encryption technologies into the service formerly known as Hotmail. Microsoft says there are more than 400 million active accounts in Hotmail and Outlook.com. Yahoo and Google say the encryption tool will be an optional feature that users will have to turn on. Engineers at the technology firms—bitter competitors in many fields—frequently talk to each other about the project, people at both companies say.

The tool will rely on a version of PGP encryption, a long-tested way of scrambling data that hasn't yet been cracked. Unlike traditional webmail services that rely on tech companies holding passwords and usernames for consumer accounts, PGP relies on users having their own encryption key stored on laptops, tablets and smartphones.

Mr. Soghoian said Yahoo and Google are taking early steps toward making the technology easier for normal consumers. Executives at both companies expect few users to adopt the technology immediately. Yahoo has altered its email process so users adopting encryption type messages in a separate window, preventing even Yahoo from reading the messages as they are typed. Mr. Stamos said his team is testing ways to get encryption keys on mobile devices. Yahoo also has to explain to users how PGP works and that it isn't a panacea for privacy concerns. For instance, it only encrypts the content of messages—not the data on who sends and receives the messages or the subject line.

Monday, 11 August 2014
Posted by Unknown

Russian Hacker Group Steals 1.2 Billion Internet User Passwords


A U.S. security firm has uncovered what appears to be the largest Internet security breach in recent memory, conducted by a group of Russia-based hackers. According to Milwaukee-based firm Hold Security, which conducted an 18-month investigation into the breach, the online gang stole 1.2 billion username and password combos, as well as more than 500 million email addresses.

The hackers pulled off the data heist, which ultimately scooped up 4.5 billion records, using unsuspecting systems of botnet network victims (in this case, computers with viruses that allowed a single operator to control a large group of affected systems) to test websites for SQL vulnerabilities. When a vulnerability was discovered, the hackers were then able to execute SQL injections, enabling them to send malicious commands to a website and steal its data, including usernames and passwords.
The group managed to steal information from 420,000 web and FTP sites, Hold Security said.

Hold Security's blog post, which details the data breach, also promotes its own services. However, an independent security expert hired by The New York Times confirmed its findings. "Your data has not necessarily been stolen from you directly," the blog post said. "It could have been stolen from the service or goods providers to whom you entrust your personal information, from your employers, even from your friends and family."

The Russia-based cyber gang is comprised of a dozen men in their 20s who began as amateur spammers by buying information on the online black market back in 2011, The New York Times reported. Ironically, the hacking revelation has come during the Black Hat computer-security conference in Las Vegas, which takes place from Aug. 2 to 7.

The Times said Hold Security is trying to develop an online tool to help individual users identify whether or not they were impacted by the data breach. Those who use the Internet for online banking and shopping will likely be the most troubled by the company's report. As for businesses, they are advised to immediately run a check to see if their websites are vulnerable to SQL injections.
"If you haven’t updated your password recently, now would be the time," Adam Kujawa, head of malware intelligence at security company Malwarebytes Labs, told Mashable. "Make sure it’s a strong password containing capital and lowercase letters, numbers and special characters. Also, don’t use the same username and password combo for every site. This is especially true for sites that have personal information like the site to your bank or credit card."

Courtesy : Mashable
Thursday, 7 August 2014
Posted by Unknown

70 Percent Smart Devices Vulnerable to Hacking: Report


According to a recent study released by Hewlett-Packard (HP), examined 10 common smart devices, including thermostats, smart TVs and webcams. Each device had approximately 25 vulnerabilities, the study claimed. Many of the vulnerabilities had to do with a lack of password strength and weak protection software. Eight out of 10 devices failed to require passwords strong enough to be useful, and the same amount put users at risk of having their personal information intercepted via cloud services.

Information technology research firm Garner predicts there will be 26 billion individual Internet of Things objects in the world by the year 2020. In 2009, there were only about nine million of these devices sold.

"The fact is, that today, many categories of connected things in 2020 don't yet exist," Gartner research director Peter Middleton said in a statement. "As product designers dream up ways to exploit the inherent connectivity that will be offered in intelligent products, we expect the variety of devices offered to explode."

"Late last year, we were hearing a lot about Internet of Things, and a bit about IoT security, but had not seen anything that focused on the complete picture of IoT security," a statement from HP read. "So, we decided to start the OWASP [Open Web Application Security Project] Internet of Things Top 10 Project, which aims to educate on the main facets of Internet of Things security that people should be concerned with."

Researchers Warn About 'BadUSB' Security Flaw


Security researchers have long warned about the dangers of malicious files on infected USB sticks. But now experts have discovered a much more dangerous threat that is even more widespread, virtually untraceable and much more difficult to solve than simply installing anti-virus software. The Berlin-based researchers reverse-engineered the software files that control how the USB drive's software works - and revealed how this so-called firmware can be reprogrammed to take complete control of a PC. Firmware is a software program, or set of instructions, programmed onto a hardware device. It tells the device how to communicate with other devices, including computers. Firmware can be thought of as 'semi-permanent' since it remains the same unless it is updated by a 'firmware updater'.

Firmware updates are installed the first time a device is used, for example, or to update a device so it works on a new operating system. Drive manufacturers will often update firmware to improve the performance of their devices. These changes are made at a central level before being pushed out to individual devices. The flaw was discovered by Karsten Nohl and Jakob Lell at Security Research Labs has been dubbed BadUSB. It affects thumb drives and external hard drives, but also any device that connects to a PC using USB. This includes keyboards and the mouse, as well as the USB drives used to charge phones and tablets.

‘The [USB] interface standard conquered the world over the past two decades thanks to its versatility.

'Almost any computer peripheral, from storage and input gadgets to healthcare devices, can connect over the ubiquitous technology. And many more device classes connect over USB to charge their batteries.

‘This versatility is also USB’s Achilles heel: Since different device classes can plug into the same connectors, one type of device can turn into a more capable or malicious type without the user noticing.’

By reprogramming the USB central firmware with malicious code, which is then pushed to individual devices, the hackers could gain access to a PC once its connected to an infected USB.  This includes emulating a keyboard and issuing commands on behalf of the user, such as opening files or installing malware. Such malware could then be used to infect any other connected USB devices. The device can also spoof a network card and change the computer’s settings to redirect web traffic to certain sites. The researchers are due to present their research at the Black Hat security conference in Las Vegas next week.

‘USB has become so commonplace that we rarely worry about its security implications,' they continued.
Sunday, 3 August 2014
Posted by Unknown

India's Security Market to Reach $1.06 Billion in 2015: Gartner


Security market in India is expected to touch $ 1.06 billion by 2015 as an increasing number of enterprises invest in these solutions to protect their business especially in the digital world, research firm Gartner today said.

According to Gartner, security vendor revenue (hardware, software and services) in India will grow from $ 882 million in 2013 to $ 953 million in 2014. This is forecast to reach USD 1.06 billion in 2015, it added.

“Organisations are today increasingly more aware of security considerations in India, driven by factors like highly visible security incidents, increasing financially (corporate espionage, underground economy) and politically (hacktivists and nation states) motivated advanced targeted attacks and renewed regulatory focus on security and privacy,” Gartner said.

Of the total market, security services (consulting, implementation, support and managed security services) accounted for more than 55 per cent and this trend is expected to continue into the foreseeable future.

“Enterprises in India that traditionally did not focus on, or invest in, a lot of security technologies are now beginning to realise the implications that a weak security and risk posture can have on their business,” Gartner Principal Research Analyst Sid Deshpande said.
Gartner said though security awareness is increasing steadily among enterprises, consumer security sub-segment will display modest growth.

“The importance of data privacy and security is not well understood by consumers in India and this situation is likely to continue to affect market growth in the consumer security space,” Gartner said.
Saturday, 2 August 2014
Posted by Unknown

Categories

Designed by Cyber Freak

News Flash


Blog Archive

Powered by Blogger.

Copyright © Cyber Era News. All rights reserved.- Powered by Eravations - Designed by Shantanu Chauhan -