Microsoft Announces Windows 10 BlackBerry Launches Passport in India for Rs. 49,990 The World's Slimmest SmartPhone : Gionee Elife S5.1 iOS 8 Has Finally Arrived Apple Unveils iPhone 6 and iPhone 6 Plus

Showing posts with label server. Show all posts

Government May Ban Gmail and Yahoo Email Services For Official Use


Popular email services like Gmail and Yahoo! are likely to be banned for official use to safeguard critical and sensitive government data. A proposal to this effect is being moved by Department of Electronics and Information Technology (DeitY) for Cabinet approval by month-end, sources said.
Government communication, barring those of Ministry of Defence and External Affairs, will be done using the platform of the National Informatics Centre (NIC), they added.

While Defence Ministry has its own separate secure email server, the External Affairs too may follow suit. The move comes amid concerns about rising cybercrime and hacking incidents. Earlier this week, five million usernames and passwords of Google were reported to have been leaked online by Russian hackers. Government is expected to route official communication through the National Informatics Centre's (NIC) email service.

DeitY has drafted the policy on use of email for government offices and departments and views and comments of ministries concerned are being taken on this, sources said.

Sources said the policy seeks to protect large amount of critical government data and aims to make it mandatory for government offices to communicate only on nic.in platform, not on commercial email services Gmail, Yahoo!, Hotmail, etc. The policy is expected to cover about 5-6 lakh Central and state government employees for using the email service provided by NIC, they added. To ensure smooth working of the NIC platform, DeitY will soon require about Rs 4-5 crore to ramp up NIC infrastructure.

Besides, a total investment of around Rs 50-100 crore would be required for full operationability of the policy, including integrating emails with cloud so that official data can be saved on a cloud platform and can then be easily shared with the concerned government ministries and departments.
Governments globally have also been trying to secure their official communication post fallout of the Snowden saga, which contended the US intelligence agencies used a secret data- mining programme to monitor worldwide Internet data to spy on various countries, including India.
Thursday, 18 September 2014
Posted by Unknown

A List of 5 Million 'Gmail Passwords' Leaked

A list of almost 5 million combinations of Gmail addresses and passwords was posted online on Tuesday. But the passwords seem to be old, and they don't appear to actually belong to Gmail accounts. Instead, it seems that many of the passwords were taken from websites where users used their Gmail addresses to register, according to some of the leak's victims as well as security experts.

For example, someone might have signed up for a website with the username "myaddress@gmail.com" and the password "mypassword." The list exposed this week makes it look like "mypassword" is the password for the Gmail account itself, but the user's actual Gmail password might be totally different.

The list was posted on a Russian Bitcoin forum on Tuesday evening, and local media started reporting on it on Wednesday. We can't confirm the authenticity of all the email addresses on the list, but a Mashable employee, Evan Engel, saw that his old Gmail password, which he hasn't used in years, is part of the leak.

A Google spokesman told Mashable that the company has "no evidence that our systems have been compromised," and security experts seem to agree that the passwords are either old Gmail passwords obtained through phishing, or are passwords that were actually used on other sites.

Matteo Flora, a computer security expert, reviewed the dumped file and found that around 60 email addresses were in his address book. After he alerted those people, 30 of them told him that the password either was never used for their Gmail accounts or was very old, Flora told Mashable.
Chester Wisniewski, a senior security adviser for security firm Sophos, told Mashable that he expects many of these accounts not to be valid. "There is no honor among thieves as they say, and often stunts like this are released as a sad attempt at gaining credibility among other criminals," he said.
Several Reddit users also confirmed that they found their email addresses in the leak, but that the associated password has never been their Gmail password.

To check if your password was one of the leaked, plug your Gmail address into this trusted tool from KnowEm. Alternatively, if you aren't comfortable giving out your email, you can change all your passwords now. Simply type your email address into the IsLeaked tool to see if your account has been exposed.

However, the tool is not without controversy. Life Hacker actually isn’t promoting it anymore after it said it discovered the “tool” was made public just two days before the Gmail leak was reported.


Google said in a blog post late Wednesday that "less than 2% of the username and password combinations might have worked," adding one more reason not to overreact to this dump.
Google also said that it has contacted the owners of the affected accounts "and have required those users to reset their passwords." So if you haven't heard back from Google, you should be fine. (Though periodically changing your password isn't a bad idea, and two-factor is a must.)

Meanwhile, more security experts seem to agree that the leak is probably almost entirely made of old passwords tken from previous leaks and dumps. Whoever put this particular one together, probably "concatenated several dozen dumps" and then published only the Gmail usernames and password combinations he found, said Jeremi Gosney, the co-founder of PasswordsCon, a hacker conference focusing specifically on passwords and other methods of authentication.
Friday, 12 September 2014
Posted by Unknown

Apple Is Gathering Celebrity Login Info For iCloud Hack Investigation


Apple is working directly with celebrities and their publicists to investigate the alleged iCloud hack that may have played a large part in a large cache of nude photographs being released online. Part of that investigation involves obtaining Apple account login information of the people affected, Mashable has learned.

It's not known exactly why Apple needs its users' login information, but presumably it gives them a level of access into a user's account records that they otherwise wouldn't be able to obtain, at least not easily. The company does say that password information stored in iCloud is encrypted and can't be read by Apple. Apple's internal investigation may shine some light on how nude photos of dozens of celebrities were gathered and then released over the weekend. While some have pointed to a potential vulnerability in iCloud security (which has reportedly been patched), there are indications, including the age of some of the photos, that the cache was part of a larger, more complicated effort.

At the same time, the FBI is looking into the iCloud hack, although it stopped short of saying it was opening a full investigation. The incident also raises unsettling questions about the general state of security for cloud storage services, which are now a major part of both personal services and business workflow.
Thursday, 4 September 2014
Posted by Unknown

Categories

Designed by Cyber Freak

News Flash


Blog Archive

Powered by Blogger.

Copyright © Cyber Era News. All rights reserved.- Powered by Eravations - Designed by Shantanu Chauhan -