Google Search

Showing posts with label Today. Show all posts
Showing posts with label Today. Show all posts

Monday, October 21, 2013

Australia’s National Consumer Fraud Week starts today – the motto is, “Outsmart the scammers!”

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Do you know someone who's been scammed online?

Chances are that you do - or you may have been scammed yourself.

Sadly, if you have been scammed, you may find some of your friends or family strangely unsympathetic.

There's still a widely-held belief that anyone who falls for an online scam must be both greedy and gullible.

? In some cases, it's true that the venality of the victim is a factor. If you send money to someone who has openly requested it as a bribe to persuade a corrupt official to pay out $22,000,000 for an oil pipeline that was never built, you have been both greedy and gullible. (You've also been a crook yourself. Don't expect sympathy.)

But there are dozens of popular online scams these days that don't require any risky character traits in the victim except a trusting nature.

Here are some examples:

Skimming. Crooks fit a duplicate card reader to an ATM so your card gets read twice when you use it.Phishing. Crooks trick you into logging in on a site that looks like your bank, but isn't.Fake competitions. Crooks persuade you to hand over personal information for geeky "prizes" that don't exist.Fake anti-virus. Crooks trick you into paying $50 for anti-virus software to "clean" malware that was never there.Fake support. Crooks pretend to be from Microsoft and offer a remote "cleanup" session for malware you don't have.

The reason I'm mentioning all of this at this particular moment is that the Australian National Consumer Fraud Week 2013 starts today.

At Sophos we enthusiatically support this sort of event, because every time anyone gets scammed - even if they lose only a modest amount, such as $10 - it hurts our society and economy as a whole.

That means that helping other people to avoid scams can be considered an important civic and economic duty for all of us.

Here are five handy "outsmart the scammers" advice points from the Australasian Consumer Fraud Taskforce:

Think twice - if a deal looks too good to be true, it probably is.Find out what other shoppers say - make sure the person that you are dealing with, and their offer, is the real deal.Protect your identity - your personal details are private and invaluable; keep them that way and away from scammers.Keep your computer secure - install software that protects your computer from viruses and unwanted programs and make sure it is kept up-to-date.Only pay via secure payment methods - look for a web address starting with ‘https’ and a closed padlock symbol. Never use a wire transfer to send money to anyone you do not know and trust, and do not share your financial details with anyone.

There's also a very handy taxonomy of scams on the Aussie government's SCAMwatch site.

Why not support National Consumer Fraud Week yourself?

Tell your less security-conscious friends and family about the SCAMwatch website, and get them to take a look at some of the many scams that are explained there.

Let's all learn to outsmart the scammers!

Follow @duckblog

If you're interested, Sophos provides a range of free security tools to help you stay safe online. Choose from Sophos Mobile Security for Android, Sophos Anti-Virus for Mac Home Edition, our Virus Removal Tool and the Sophos UTM Home Edition.


View the original article here

Sunday, October 20, 2013

UK political bigwigs demand return of snoopers’ charter. Seriously? Today?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

UK flag eye, image courtesy of ShutterstockA cluster of top political figures in the UK, including several former Home Secretaries, has issued a public letter insisting on the revival of the so-called "snoopers' charter" - legislation to give British police and intelligence services more access to personal data.

In a stirring display of bad timing, the letter, co-signed by big names from both sides of the political divide and sent to the Times newspaper, aims to break opposition to the bill from the Liberal Democrats.

The proposed £1.8 billion "Communications Data Bill", promising massive-scale harvesting of web and phone data, has always been controversial. It was pushed onto the back burner in April when Lib Dem leader Nick Clegg came out against it.

But it seems that, despite the current heavily anti-snooping mood, some people are not ready to let it lie.

A lot of these guys are getting on a bit - their job titles mostly include a "former", several reports refer to them as "senior" and even "grandees" - so maybe they have an excuse for not keeping up with current events. They're probably spending a lot of time pottering around the garden, playing bingo or watching Quincy.

They seem not to have even noticed the massive, non-stop political and social hurricane surrounding the so-(mis-)called "PRISM" leak rumpus, dominating all headlines for the last week or so.

For the moment we'll ignore the justification they give for their demands; they reference the horrific attack in London a few weeks ago, whose perpetrators were well known to MI5. This seems to indicate, if anything, that UK spies already have more information than they can possibly process and act upon, but that's by the by.

If there's anything the whole PRISM circus shows, it's that intelligence services are really bad at privacy. The NSA, famously the most top-secret of secret organisations, is actually not able to keep its own top-secret secrets especially secret.

Prism, image courtesy of ShutterstockIn essence, they hired a temp (OK, "consultant", I've never been clear on where one stops and the other starts), and let him, what? Dump a load of highly-classified documents to a personal USB stick or a CD? Or send stuff out to his personal Gmail account?

C'mon guys, where was the data security?

We're not talking about beefy armed guards running high-tech body-scanners over everyone leaving the secure facility in the back of a fake launderette, or beagles that can sniff a microdot at 20 paces. This should be covered by basic data handling policies, DLP and maybe a bit of device control.

And this is their OWN secrets. How much less careful are they with other people's?

I try to be fairly careful with my personal data, not obsessively so but taking reasonable precautions. What's the point of making the effort though?

Clearly, the cops and the secret agent men are going to compile a detailed and comprehensive dossier on everything they can find out about me, then just pop the data on a laptop or USB stick (unencrypted, of course), and leave it lying around the nearest train/taxi/rail station/airport/nightclub. Or better yet, simply put the whole database on eBay because the hard drives seem a bit old.

So, no thanks. Until "the man" proves he can look after it better, I'd rather not give him any more data than he already has. For the first time in a while, I agree with Nick.

Follow @VirusBtn
Follow @NakedSecurity

Image of UK face courtesy of Shutterstock.


View the original article here

Saturday, May 12, 2012

Important Apple security updates for Snow Leopard and Lion - get 'em today!

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Hot on the heels of the iOS 5.1.1 release, Apple has pumped out a raft of security updates for Snow Leopard (OS X 10.6) and Lion (OS X 10.7) users.

Here they are:

* OS X Lion 10.7.4.

The blurb is at DL1525; the 40,000-foot overview is at HT5167; and the all-important security details are at HT5281.

This update patches numerous vulnerabilities. These include issues at Bronze, Silver and Gold medal levels of insecurity.

There are vulnerabilities leading to information leakage (other people can look at data they're not supposed to see, up to and including raw passwords), escalation of privilege (non-admin users can get administrative access they're not supposed to have), and remote code execution (untrusted external content, such as a web page, can run software on your Mac without warning).

Notably, the 10.7.4 update fixes the recently-discovered FileVault flaw. Apple inadvertently shipped a version of FileVault - the software which seamlessly encrypts your home folder - with a debugging option turned on.

This caused OS X Lion to record your personal password in its log file, where others could retrieve it. Of course, passwords should never be stored in plaintext, so this was a monster-sized blunder.

* Security update 2012-002 for 10.6.8.

Once again, refer to HT5281 for details. This is Snow Leopard's equivalent of the 10.7.4 update.

(Some of the vulnerabilities listed in HT5281 apply only to Lion - such as the FileVault password logging fault. Some apply only to Snow Leopard. Many apply to both. Apple has chosen to document them in one place, for a total of 26 vulnerabilities patched in 19 system components.)

* Remote Desktop client update.

This patch is part of the OS X Lion point update to 10.7.4, but isn't included in the 2012-002 update pack for Snow Leopard users. So if you're on 10.6.8, you get this one separately.

* Safari 5.1.7.

This is nice! The notification is at DL1531 and some implementational detail is at HT5271. The security fixes - which include a patch for the remote code execution issue addressed two days ago in iOS 5.1.1 - are at HT5282.

New to Safari 5.1.7 is a feature which automatically turns off the Adobe Flash plugin inside your browser if it goes out of date.

When you update your Flash version - an update Apple's own processes obviously can't control - then the plugin gets reactivated.

If you really want to run with the outdated plugin, HT5271 tells you how.

But you really shouldn't. Plugins such as Flash and Java are vigorously analysed by crooks in the hope that they'll find a way to trick them into downloading program code without permission.

What more to say?

These updates should be considered either necessary (in the case of the security patches) or at the very high end of highly desirable (in the case of Safari 5.1.7).

Get 'em today!

Follow @duckblog
-

PS. Just so you know: you will need to reboot in order to activate these updates.

Tags: Apple, data leakage, Exploit, file vault, flash, Patch, rce, Safari, safety, update, vulnerability


View the original article here

Friday, September 30, 2011

Authenticity of Web pages under attack by hackers - USA Today

The keepers of the Internet have become acutely concerned about their ability to protect the most sensitive personal information such as account logons and credit card numbers.

USA TODAY

Hackers cracked three companies that work with the most popular Web browsers to ensure the authenticity of Web pages where consumers type in sensitive information.

The hacked firms are among more than 650 digital certificate authorities (CAs) worldwide that ensure that Web pages are the real deal when displayed by Microsoft's Internet Explorer, Firefox, Opera, Apple's Safari and Google's Chrome.

A hacker gained access to digital certificate supplier DigiNotar this summer and began issuing forged certificates for dozens of marquee companies.

Unable to cope with the fallout, the Dutch company filed for bankruptcy last week. Two other digital certificate companies, New Jersey-based Comodo and Japanese-owned GlobalSign, were similarly hacked this summer, exposing a glaring weakness in the Internet's underpinnings.

"The infrastructure baked into the Internet, which is based on trust, is starting to fall apart," says Michael Sutton, research vice president at security company Zscaler.

CAs digitally certify account sign-ins, shopping and other pages where consumers type sensitive data. This sets up an encrypted connection to the Web browser, which displays the form for the consumer to fill out. The browser trusts only digitally signed pages.

A counterfeiter issued valid DigiNotar certificates for 531 faked pages. Some of the pages were crafted to expertly impersonate online properties of Google, Microsoft, Skype, Equifax, Twitter, Facebook and the CIA, among others, according to consulting firm Fox-IT.

This touched off a scramble to cut off the faked pages, which were difficult for consumers to spot as faked.

The successful hacks demonstrated that it is possible to "impersonate any site on the Internet," says Josh Shaul, chief technical officer at security company AppSec.

No banks or payment-service websites were targeted, says Mikko Hypponen, chief researcher at anti-virus company F-Secure. The hackers seem much more interested in harvesting personal data from e-mail services, social networks, credit bureaus, blogging sites and anonymity services.

The pressure is on CAs and browser makers to do more to identify and quickly eradicate counterfeit certificates and faked Web pages, security experts say. "No one knows where the next breach will occur," says Jeff Hudson, CEO of digital certificate management company Venafi.

Microsoft, maker of Internet Explorer, declined to comment, as did Apple, maker of the Safari browser. "The security of the Web is our collective responsibility," says Johnathan Nightingale, Mozilla's director of Firefox engineering.

For more information about reprints & permissions, visit our FAQ's. To report corrections and clarifications, contact Standards Editor Brent Jones. For publication consideration in the newspaper, send comments to letters@usatoday.com. Include name, phone number, city and state for verification. To view our corrections, go to corrections.usatoday.com.

View the original article here