Google Search

Showing posts with label Canadian. Show all posts
Showing posts with label Canadian. Show all posts

Friday, November 22, 2013

Canadian cop claims he didn't know cyber-stalking was illegal

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Man spying. Image courtesy of ShutterstockA Canadian police officer who pleaded guilty to planting spyware on his wife's BlackBerry has been sentenced to demotion, after two years' paid suspension.

According to local news sources, a mitigating factor in his sentencing was that he didn't know that planting the cyber bug was a crime.

The unnamed (for legal reasons) officer, from the police force of Sault Ste. Marie, Ontario, was apparently drinking heavily at the time, and suspected his wife of cheating on him with a close friend.

His defense counsel argued that both the jealousy angle and the lack of clarity around such spyware should weigh in the officer's favour, an opinion supported by the eventual decision to grant a conditional discharge and place him on probation for twelve months last year, and now to sentence him to demotion to second class constable for at least two years.

The spyware he planted could apparently harvest chat and SMS data as well as monitor GPS location information, with the information gathered posted to a remote site and accessible from anywhere in the world.

The officer admitted to buying the spyware online, under his own name and with a credit card, from a US website advertising the tool as suitable for snooping on spouses suspected of infidelity.

The case was one of the first brought under new laws covering digital surveillance, as the judge at his original hearing last year pointed out. The case was treated as a gentle introduction to the new laws, with future offenders warned that they would not be treated so lightly.

It does seem a rather delicate slap on the wrist, especially for a police officer, who should be expected to be more up to speed than most people on what is permissible behaviour and what is, in fact, a crime.

The case highlights the difficulties surrounding "greyware", the "potentially unwanted applications' (aka PUA), which most quality security products will alert on if asked to, but whose developers claim they are servicing a legitimate need.

GPS map. Image courtesy of ShutterstockThe PUA issue has been around for quite a few years in the PC world, but is now becoming a particular problem in the mobile space, where this kind of snoopware is especially effective thanks to GPS location data and the intimate info many mobile users share by SMS, instant messaging and social networking apps.

With people only just starting to realise the need for security software on their mobiles to help spot stuff like this, as well as simpler security practices such as screen locks and not letting strangers fiddle with your phone, this sort of story should help hit the point home.

And from the other side, it should make it clear to people thinking about using this kind of tool to snoop on their friends and neighbours: it's not just not cool, in many jurisdictions it's a crime.

Follow @VirusBtn
Follow @NakedSecurity

Images of man spying and GPS map courtesy of Shutterstock.


View the original article here

Wednesday, November 20, 2013

Facebook leak, Canadian spam, Opera breach - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

It's Saturday, and that means 60 Second Security, where we aim to touch on some of the more thought-provoking security topics of the past week in just one minute of video.

Why not give this week's video a go? [Higher resolution available directly from YouTube. Click the Captions icon for closed captions.]

Facebook suffers a data leakage crisis where information uploaded by X about Y may be downloadable by Z.Canada is the last G8 country to go for anti-spam legislation. Only it just got delayed again. Might be ready by 2014. Or 2017.A Korean graphical designer created an "anti-surveillance" font. It doesn't work, but, hey, it's the thought that counts.And Opera wrote up a "Security attack stopped" incident. Except it was more like "Security attack not stopped."

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, anti-spam, anti-surveillance, breach, browser, Canada, certificate, Code signing, data breach, Facebook, font, korean, leak, legislation, Malware, opera, PRISM, Spam, typeface, typography, zxx


View the original article here

Monday, June 3, 2013

Fake Zendesk security notice spammed out, directs traffic to Canadian drug websites

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

I'm always on the lookout for breaking news about companies who might have had their systems hacked, so when I received the following email earlier today my interest was piqued.

Its subject line was "An important notice about security".

Fake security notice, pretending to be related to Zendesk breach

We recently learned that the vendor we use to answer support requests and other emails (Zendesk) experienced a security breach.

We're sending you this email because we received or answered a message from you using Zendesk. Unfortunately your name, email address and subject line of your message were improperly accessed during their security breach. To help keep your account secure, please:

* Don't share your password. We will never send you an email asking for your password. If you get an email like this, please let us know right away.

* Beware of suspicious emails. If you get any emails that look like they're from our Support Team but don't feel right, please let us know - especially if they include details about your support request.

* Use a strong password. If your password is weak, you can create a new one [LINK]

We're really sorry this happened, and we'll keep working with law enforcement and our vendors to ensure your information is protected.

Support Team

In a nutshell, the email claims to be from an online company which is using the Zendesk customer service portal to help it answer queries from customers.

ZendeskYou may even remember that Zendesk was hacked in February, and companies such as Tumblr, Twitter and Pinterest contacted some of their users to warn them that email addresses were possibly exposed.

What's different this time is that the body of the email doesn't really make clear *what* company is contacting me. Which seems strange.

Yes, the email mentions Zendesk - but just *who* is the company that was using Zendesk and has suffered as a result of the breach at Zendesk?

With no clear details in the email, the only way to find out is to click on the links... right?

Well, if you do that, you'll find your browser taken on a journey which ultimately (via some temporary redirects) leads you to a Canadian pharmacy website, trying to sell you Viagra and Cialis:

Canadian Pharmacy website

In short, the whole email is a campaign - using the disguise of an important security notice (complete with sensible advice to use strong passwords, and be wary of unsolicited emails!) to trick you into clicking on the link.

These cybercriminals certainly have some gall.

Of course, whoever is behind this campaign could easily change the redirects to point to a more malicious webpage, or a phishing site if they wished. Which would make it even worse.

Interestingly, this isn't the only way in which the spammers have been promoting this particular online drugs store.

Paul Baccas in SophosLabs uncovered for me that in the last 24 hours we have also had reports from customers who have received bogus Facebook notifications pointing to the same site.

Facebook-related spam message

We all probably know someone who is so addicted to Facebook, and stalking their friends' online activity, that they wouldn't hesitate from clicking on a link which they believed had come from the social network.

Remember to always practice safe computing online, including the rule about always being suspicious of unsolicited emails.

If you're not careful, you might not only be visiting spammers' websites - you could also potentially be putting your computer and its sensitive data in danger.

Follow @gcluley

View the original article here