Google Search

Showing posts with label VIDEO. Show all posts
Showing posts with label VIDEO. Show all posts

Thursday, June 12, 2014

Mobile malware, Gameover, CryptoLocker, and SSL/TLS holes - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

• How long has mobile malware been around?

• Is it really game over for Gameover and CryptoLocker?

• Which cryptographic security libraries need patching?

Find all the answers in this week's 60 Sec Security - 07 June 2014.

? Can't view the video on this page? Watch directly from YouTube.

Follow @duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Android, cabir, caribe, cryptolocker, doj, FBI, gameover, gnutls, heartbleed, Mobile, openssl, Patch, ransomware, rce, simplelocker, Symbian, takedown


View the original article here

Thursday, December 26, 2013

Infecting iOS, OpenX backdoor, toilet hole, Android malware - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Are Apple's iPhones really impervious to malware attack? What do you do if your software ends up pre-infected with a backdoor? What strength of password is appropriate for a toilet? And when will we get firmware updates for the Android code verification holes?

Watch this week's 60 Second Security and find out more!

? Can't view the video on this page? Watch directly from YouTube. Can't hear the audio? Click on the Captions icon for closed captions.

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, ad server, Android, Apple, Backdoor, bluetooth, ios, iPad, iPhone, lixil, Malware, master key, OpenX, PHP, toilet


View the original article here

Saturday, December 14, 2013

XKeyScore surveillance, Bradley Manning verdict, LinkedIn hole - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

What's XKeyScore all about? How did Bradley Manning fare? What about the authentication hole in LinkedIn?

Watch this week's 60 Second Security and find out more!

? Can't view the video on this page? Watch directly from YouTube. Can't hear the audio? Click on the Captions icon for closed captions.

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: #sophospuzzle, 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, bh2013, Bradley Manning, Cablegate, data breach, Delaware, linkedin, Manning, NSA, oauth, PRISM, surveillance, Uni Delaware, vulnerability, Wikileaks, XKeyscore


View the original article here

Saturday, December 7, 2013

Data Breach Week, SIMs cracked, carders busted - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

How safe is the SIM in your mobile phone? Could it be remotely infected with malware?

Possibly - watch this week's 60 Second Security and find out more!

? Can't view the video on this page? Watch directly from YouTube. Can't hear the audio? Click on the Captions icon for closed captions.

It feels like we just had "Data Breach week", with Apple's Developer Center, Ubuntu Forums, Lakeland and even Stanford University having "better change your password" moments.Crypto researcher Karsten Nohl claims he's found a way to recover remotely the secret key buried in older SIM cards, so he can sign any code he wants and put it on your phone.Five sidekicks of notorious TJ Maxx hacker Albert Gonzalez, currently serving 20 years, have been charged with carding crimes in New Jeresy and New York.

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Apple, balic, Blackhat, bust, Cryptography, data breach, DES, developer center, FBI, Gonzalez, karsten nohl, Lakeland, nohl, salt, SIM, Stanford, TJ Maxx, Ubuntu, university


View the original article here

Saturday, November 30, 2013

Android holed again, JAY Z and “Magna Carta”, Tumblr and HTTPS – 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

How did rapper JAY Z take the concept of Magna Carta to a whole new level?

Watch this week's 60 Second Security and find out!

? Can't view the video on this page? Watch directly from YouTube. Can't hear the audio? Click on the Captions icon for closed captions.

Google's Android operating system has another security hole. Same story as before: uou can tamper with other peoples' digitally-signed packages and Android won't notice.Rapper JAY Z's latest album release, "Magna Carta", was preceded by a custom Android app that had some privacy boffins up in arms.Tumblr managed to forget the S in HTTPS in a recent release of its iOS app. The social networking company is "tremendously sorry."

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Android, APK, app, carter, Code signing, data breach, Data Collection, EPIC, Exploit, exra field, Google, https, ios, Jay Z, master keys, Privacy, sniffing, Social Networking, Spam, Tumblr, vulnerability


View the original article here

Wednesday, November 20, 2013

Facebook leak, Canadian spam, Opera breach - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

It's Saturday, and that means 60 Second Security, where we aim to touch on some of the more thought-provoking security topics of the past week in just one minute of video.

Why not give this week's video a go? [Higher resolution available directly from YouTube. Click the Captions icon for closed captions.]

Facebook suffers a data leakage crisis where information uploaded by X about Y may be downloadable by Z.Canada is the last G8 country to go for anti-spam legislation. Only it just got delayed again. Might be ready by 2014. Or 2017.A Korean graphical designer created an "anti-surveillance" font. It doesn't work, but, hey, it's the thought that counts.And Opera wrote up a "Security attack stopped" incident. Except it was more like "Security attack not stopped."

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, anti-spam, anti-surveillance, breach, browser, Canada, certificate, Code signing, data breach, Facebook, font, korean, leak, legislation, Malware, opera, PRISM, Spam, typeface, typography, zxx


View the original article here

Saturday, November 9, 2013

Stolen webcam video listed at $1 per female victim, $1 per 100 male victims

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Red webcam. Image courtesy of ShutterstockDo only the truly paranoid stick bandages over their webcams so they don't get surreptitiously recorded?

According to a BBC Radio 5 live investigation, the rationale for doing so might be strong enough to vindicate the paranoid, given input from webcam hackers who say that such hacking is simple and that black markets for selling access to compromised computers are "thriving."

One webcam hacker who spoke to the BBC said "loads of people" are hacking webcams because it's so simple to do.

In fact, while he was being interviewed, he was on a forum with tutorials on how to hack webcams. It had about 428,000 posts, he said.

Hackers gain access to their victims' computers with remote-access Trojans (RATs) - malware that gives an intruder administrative control over its targeted computers, including, in this case, the ability to remotely control webcams.

It's an invisibly-installed malware program spread via email attachment or by tricking victims into visiting a booby-trapped site.

The BBC interviewed one victim who thinks she was victimized by webcam hacking.

Rachel Hyndman said that she noticed that her laptop camera had switched itself on while she was watching a DVD in the bath.

She was, of course, horrified:

"I was sitting in the bath, trying to relax, and suddenly someone potentially has access to me in this incredibly private moment and it's horrifying.

"To have it happen to you without your consent is horribly violating."

For the investigation, a BBC producer posed online as a computer security enthusiast in order to contact several webcam hackers from around the world - at least one of whom has since been arrested.

The investigation uncovered websites where hackers share pictures and videos of their victims aka "slaves", pages where they swap photos of "ugly slaves", sites where men swap images of female "slaves", and evidence of at least one black market where you can buy access to a woman's webcam for $1 (64p).

The same amount will get you access to 100 computers owned by men.

How common is this type of hack?

Spy on computer. Image courtesy of ShutterstockGraham Cluley told the BBC that webcam hacking is quite real.

That's evidenced by multiple arrests of perpetrators - including those looking to blackmail victims.

But while it is real, GC says, webcam hacking is rare enough that it's not quite worth freaking out over in the broader scheme of virusy things:

"There are 100,000 new virus threats created every day and it's really important to keep your security up to date because anti-virus software should protect you against most of these threats."

Still, you don't want to be one of the (albeit rare) victims.

A list of tips on avoiding getting webcam-hacked, some of which are adapted from a list provided by ChildNet International and the UK's Child Exploitation and Online Protection Centre:

Keep your antivirus and firewall protection up to date.Patch applications in a timely fashion. Be wary of email and social networking messages from strangers, and refrain from clicking on attachments or links in any such messages.Don't take your webcam into intimate places, even if an error message tells you your computer needs hot steam to clean its sensor (true story!). When not in use, cover your webcam lens (bandages work well) or point it at the wall. Think twice before stripping for a conversation - remember, whomever you're talking to can record and share the video. Teach young people how to behave safely online to avoid them becoming victims.Encourage children who've been victimized via webcam to report it to a trusted adult. If you've been victimized yourself, report it to the authorities.

Stay safe, and keep an eye on that webcam light.

Follow @LisaVaas
Follow @NakedSecurity

Image of webcam and computer spying courtesy of Shutterstock.


View the original article here

Thursday, November 7, 2013

LinkedIn unhacked, Microsoft bounties, Java in your browser - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

It's that time again - time for this week's 60 Second Security, our fun-but-serious "security news with a conscience" video series.

Watch the latest security news in just 60 seconds! [Higher resolution available directly from YouTube. Click the Captions icon for closed captions.]

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Apple, applet, bounty, browser, crack, DDoS, dictionary, Erlangen, Exploit, ios, iPad, iPhone, Java, linkedin, Microsoft, network solutions, Oracle, outage, passwords, rce, update, vulnerability, Wi-fi, Window 8.1 Preview, Windows 8.1


View the original article here

Saturday, October 19, 2013

PRISM, UK Surveillance, Sweden vs. Google, Blackberry Z10 – 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Here's the latest in our 60 Second Security video series, bringing you a fast, incisive and entertaining angle on recent computer security issues.

Watch the latest security news in just 60 seconds! (Higher resolution available directly from YouTube. Click the captions button for closed captions.)

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, BlackBerry, cloud, flash, Google Apps, law, Patch, PRISM, Privacy, salem, surveillance, Sweden, vulnerability, z10


View the original article here

Tuesday, October 15, 2013

Botnet smackdown, Oracle on Java, Passwords you can eat - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Watch our 60 Second Security videos for a fast, incisive and entertaining angle on what's been going on recently in computer security.

Here you go: the latest security news in just 60 seconds.

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 2FA, 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, botnet, citadel, FBI, java. patch, linkedin, Malware, Microsoft, Motorola, Oracle, pill, stomach, takedown, token, update, vulnerability


View the original article here

Saturday, October 5, 2013

Android malware, Liberty Reserve, CSAW, Legal ransomware - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Watch our 60 Second Security videos and arm yourself with anecdotes you can use when your friends or colleagues ask you, "Do I really need to worry about things like privacy and security?"

Here you go: the latest security stories in just 60 seconds.

In this episode:

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Android, cloud, CSAW, Fake anti-virus, Liberty Reserve, Money Laundering, piracy, ransomware, scareware


View the original article here

Sunday, September 22, 2013

Patching your business, Yahoo breach, Google Glass, DDoS-for-hire - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Our 60 Second Security videos are back!

In the last series, we produced episodes every two weeks; this time, we're hoping to publish a weekly roundup that's quick, fun and useful.

There is a serious side to these videos: we want to give you punchy computer security anecdotes to use in your own "elevator advocacy."

You probably know the feeling.

You get in the lift, sorry, elevator, with someone who's just had a run-in with IT over a security principle that you think is obvious, but they think is tiresome.

"Who cares about Windows updates? Why do I have to change my password? What's the big deal about privacy? Who's going to hack little old me?"

60 Second Security helps you fire back friendly answers to all those questions, long before you get to Level 11.

Here you go: watch the latest security news in just 60 seconds.

In this episode:

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Congress, data breach, DDoS, FBI, Glass, Google, Japan, Patching, small biz, Small Business, yahoo


View the original article here

Monday, July 22, 2013

You won't believe how crazy this password infomercial is (and neither did Ellen DeGeneres) [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Internet Password MinderOh, the joys of late night television in the United States!

When there's nothing funny on American TV, you can always rely upon an infomerical selling some crazy product to have you chuckling or simply agog in disbelief that anyone would ever buy such a thing.

Ellen DeGeneres clearly feels the same, and she recently focused some attention on a product that claimed to solve a computer security problem experienced by many internet users - how to remember your passwords.

Take a look at the video below about the "Internet Password Minder":

As one of the customers featured in the infomerical breathlessly explains:

"I don't have to worry anymore about security or identity theft... I now have all my passwords in one place. It's great"

At first I thought perhaps the people behind the "Ellen" show had made the infomercial as a spoof, but now I'm not so sure. After all, I find it hard to believe that *any* infomericals are real.

As Ellen amusingly asks, wouldn't it be cheaper to save money and write all your passwords on a $5 bill?

You could even keep the (patent-pending - don't steal the idea!) $5 bill password minder in your wallet if you liked - much more convenient than the book-sized Internet Password Minder!

Sheesh.

Here's my own video explaining how to generate a tough, hard-to-crack password that is still easy to remember.

(Enjoy this video? You can check out more on the SophosLabs YouTube channel and subscribe if you like)

If you can't remember your passwords, and have difficulty juggling different passwords for different websites, then just use password management software like KeePass, 1Password or LastPass.

It makes a lot more sense than Ellen's Internet Password Minder or a $5 note.

Well done for Ellen for raising awareness of password security issues with her large TV audience in an amusing way.

PS. Just as I was about to publish this article, I found a comment on Ellen's website from someone who claims to be the woman in the infomercial who no longer worries about identity theft.

Comment on Ellen's website

Follow @gcluley

Hat-tip: Paul Baccas of SophosLabs, who hasn't yet explained what he was doing watching Ellen.


View the original article here

Tuesday, July 9, 2013

When is a password not a password? When Excel sees "VelvetSweatshop" [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Boobytrapped Excel fileOver the last few months, I've spent a significant proportion of my time researching the CVE-2012-0158 vulnerability.

I'm glad to say that that research has paid off, and I will be presenting a technical paper at the Virus Bulletin conference in Berlin, later this year.

The paper, "Between an RTF and OLE2 place: an analysis of CVE-2012-0158 samples", will be a summary of my research so far into the threat.

One of the issues in detecting CVE-2012-0158 samples is that the delivery mechanism can be RTF, Word or Excel files.

Word and Excel files can be password-encrypted, meaning that it can be harder for an anti-virus scanning engine to see the malicious code.

The problem the attackers have, of course, is that they not only have to trick users into clicking on the attachment with social engineering, but also need to dupe their potential victims into entering a password.

With Excel, however, there is another method and that is to save the boobytrapped file as "Read Only".

"Read Only" applies the same encryption method and uses a default password chosen by the Microsoft programmers: "VelvetSweatshop".

Here is a short video showing how malware can use this default Excel password in its attempt to infect unsuspecting computer users.

(Enjoy this video? Check out more on the SophosLabs YouTube channel.)

If you would like to know more about the CVE-2012-0158 vulnerability then I urge you to attend the Virus Bulletin conference later this year. While you are there you can also listen to and meet other experts from Sophos:

My SophosLabs colleagues Numaan Huq and Peter Szabo also have a reserve paper at the conference: "Trapping unknown malware in a context web".

A strong showing for the SophosLabs experts at this year's Virus Bulletin conference, I'm sure you will agree. We look forward to meeting many of you in Berlin.

Follow @SophosLabs
Follow @NakedSecurity


View the original article here

Friday, June 7, 2013

iOS 6.1.3 security flaw allows passcode lock bypass... again [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Passcode bypassiOS 6.1.3 has only just been released by Apple, and already a security hole has been followed - allowing anyone to bypass the passcode lock on iPhones, and access private data on the device.

Embarrassingly for the Cupertino company, one of the main reasons for installing iOS 6.1.3 was that it promised to fix other security flaws that allowed the lock screen to be bypassed.

The flaw was found by "videosdebarraquito", who seems to be making a hobby of embarrassing Apple by uncovering lock bypass flaws. In a video he demonstrates that it's not particularly complicated to avoid the iOS 6.1.3 passcode lock if you have physical access to the device and a widget for removing the SIM card.

Here is videosdebarraquito's video, where he demonstrates how the passcode can be bypassed:

It appears that circumventing the passcode lock can allow an unauthorised party access to the device's photo gallery and use the phone.

The good news is that this security flaw can be easily prevented. The passcode bypass relies upon use of the "Voice Dial" feature of iPhones, which is disabled on devices using Apple's Siri voice recognition feature.

If you *aren't* using Siri, then the recommendation is to disable "Voice Dial". If you do that, your device shouldn't be prone to this passcode bypass.

Disable the Voice Dial option

You can disable "Voice Dial" on your iPhone by going to Settings / General / Passcode Lock. (Note that if you have Siri enabled you won't see an option for "Voice Dial" there, as it has been automatically disabled).

Easy as it is to avoid this flaw putting your iDevice at risk, it's still embarrassing for Apple as it comes so soon after other passcode lock bypasses were publicised.

Let's hope that Apple fixes this flaw soon, and shuts a permanent door on passcode lock bypasses.

Follow @gcluley

View the original article here

Saturday, February 16, 2013

US-wanted "bank hacker" is all smiles as he is arrested at Bangkok airport [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Hamza BendelladjAn alleged hacker, suspected by the FBI of stealing millions of dollars from online bank accounts, has been arrested by Thai police and paraded in front of the world's media.

24-year-old Hamza Bendelladj, an Algerian national, was detained this weekend at Bangkok's Suvarnnabhumi airport, as he was in transmit from Malaysia to Egypt.

Bendelladj, was brought out handcuffed and beaming broadly in front of TV cameras, seemingly untroubled by the FBI's claims that he hacked into customer accounts at 217 banks and financial companies around the world.

The Bangkok Post reports that a smiling Bendelladj denied claims made by the Thai authorities that he was on the FBI's top-10 most wanted list:

"I'm not in the top 10, maybe just 20th or 50th," the Algerian suspect said with a laugh. "I am not a terrorist."

Here's an NTDTV video report from the press conference:

Two laptops, a tablet computer, a satellite phone and a number of external hard drives were confiscated by police from Bendelladj.

Immigration police chief Pharnu Kerdlarpphon was reported as saying that Bendelladj had claimed he spent his riches living a life of luxury:

"With just one transaction he could earn 10 to 20 million dollars... He's been travelling the world flying first class and living a life of luxury."

Officials in Thailand have said that Bendelladj will be extradited to the United States as soon as possible.

One wonders if he will find that quite so amusing.

Follow @gcluley

View the original article here

Saturday, February 2, 2013

Three people arrested over "Police ransomware" computer attacks [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Money. Image from ShutterstockThe Metropolitan Police have arrested two men and a woman in connection with a spate of computer attacks that have held innocent internet users to ransom.

Ransomware is malicious software that locks you out of your computer or your data, and demands money to let you back in.

One "brand" of ransomware, widely known as Reveton, has been very widely circulated in recent months pretending to be a warning from your country's national police service, locking you out of your PC, and threatening criminal proceedings within 48 hours - usually for unspecified copyright offences.

According to a police press release, officers from the Police Central e-Crime Unit (PCeU), assisted by colleagues from Staffordshire Police, searched three properties yesterday in connection with the ransomware attacks.

A 34-year-old man and 30-year-old woman from Stoke on Trent have been arrested on suspicion of conspiracy to defraud, money laundering and possession of items for use in fraud. Additionally, a 26-year-old man also from Stoke on Trent was also arrested on suspicion of conspiracy to defraud. All three are currently in custody at a Staffordshire police station.

Naked Security's Paul Ducklin demonstrates ransomware in the following video:

(Enjoy this video? Check out more on the SophosLabs YouTube channel.)

For a deeper understanding of ransomware, check out some of our recent articles on the subject:

Follow @gcluley

Money image from Shutterstock.


View the original article here

Saturday, December 15, 2012

Should you lie on Facebook? [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

FacebookThere's something of a hoo-hah in the world of British politics today, after a senior government official advised users of social networks such as Facebook on how to protect their privacy.

Nothing controversial there, you might think. Until you realise that the advice from Andy Smith, an internet security chief at the Cabinet Office, was that you should lie about your real name and date of birth.

The BBC reports, that Smith told a parliamentary internet conference that providing fake details to social networking sites was:

"..a very sensible thing to do.. When you put information on the internet do not use your real name, your real date of birth. When you are putting information on social networking sites don't put real combinations of information, because it can be used against you."

Opposition Labour MP Helen Goodman told the BBC that she was outraged by the advice, and claimed that such behaviour could lead to more crime, not less:

"This is the kind of behaviour that, in the end, promotes crime. It is exactly what we don't want. We want more security online. It's anonymity which facilitates cyber-bullying, the abuse of children. I was genuinely shocked that a public official could say such a thing."

So, what do we think here on Naked Security?

Well, there is no doubt that cybercriminals can harvest personal information social networking profiles, and use it as an aid to identity theft.

As we have reported many times in the past, a worrying number of people are far too lax about sharing their names, addresses, phone numbers, full dates of birth, job and educational history etc on social networks like Facebook.

Last year, for instance, we reported on a British man who was jailed after stealing £35,000 (approximately US$ 55,000) from his neighbours' bank accounts with help from personal information they had posted on Facebook.

Back then, my advice to social networking users was that they should stop feeling compelled to tell the truth, the whole truth, and nothing but the truth, to such sites.

Snapshot of old article on Naked Security

It's important to know, before you take that advice, that some websites (such as Facebook) do insist in their terms and conditions that you must provide it with accurate information. The penalty, if you break their rules, is that they could kick you off the site.

Remember though - Facebook and other sites like it have no way of verifying that you did tell the truth. They won't like me much for saying it, but why risk sharing too much personal information?

Many sites want you to be honest about your real date of birth, but this is probably to stop you from pretending to be a 13-year-old schoolgirl, rather than because they think it's important you say that your birthday is on September 5th or March 3rd.

Facebook privacy option

Sadly, simply making your date of birth private on Facebook may not be enough - back in 2008 they accidentally leaked everyone's date of birth, regardless of whether users had chosen to make it private or not.

So my advice is to lie about your date of birth when you can, but don't be deceptive regarding your rough age group.

Similarly, if a website asked you for your mother's maiden name (which is a matter of public record) for the purposes of a password reminder, why not make up the answer? For instance, say "Xena Warrior Princess", "Robert Mugabe" or "Archduke Franz Ferdinand of Austria". As long as you remember it, and no-one else can guess it - that's all that matters.

The same goes for your first pet's name, or the first road that you lived on.

Yes, MP Helen Goodman is right that cyber-bullying is a real problem as the recent tragic case of Amanda Todd proves. And no-one is suggesting that you lie on websites about the personal information where the truth really matters, such as when you're filling in your tax return online.

But, on balance, I think we all need to be more careful about the information we share on the web - and realise that sometimes a little fibbing and reticence might go a long way to a safer online experience.

Maybe you feel differently? Why not have your say by leaving a comment (anyonymously if you wish) below, or take our quick online poll.

If you are on Facebook, and want to learn more about security and privacy issues on the social network, join the Naked Security Facebook page where our 190,000 strong community regularly discuss the latest threats.

Follow @gcluley

View the original article here

Monday, October 22, 2012

Twitter DMs from your friends can lead to Facebook video malware attack

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Tweetie birds. Image from ShutterstockHave you received a Twitter message from an online friend, suggesting you have been captured in a Facebook video?

A number of Naked Security readers have been in touch in recent days regarding a variety of direct messages that have been spammed out from compromised Twitter accounts.

The aim of the messages? To trick the unwary into clicking on a link.. and ultimately infect computers.

Here is one example:

Twitter direct message

your in this LoL

And here's another. Note that there are many different combinations of wording that can be used.

Twitter direct message

you even see him taping u thats awful

Users who click on the link are greeted with what appears to be a video player and a warning message that "An update to Youtube player is needed". The webpage continues to claim that it will install an update to Flash Player 10.1 onto your computer.

Malicious webpage

In this example, the program you are being invited to download is called FlashPlayerV10.1.57.108.exe, and is detected by Sophos anti-virus products as Troj/Mdrop-EML, a backdoor Trojan that can also copy itself to accessible drives and network shares.

Quite how users' Twitter accounts became compromised to send the malicious DMs in the first place isn't currently clear, but the attack underlines the importance of not automatically clicking on a link just because it appeared to be sent to you by a trusted friend.

If you do find that it was your Twitter account sending out the messages, the sensible course of action is to assume the worst, change your password (make sure it is something unique, hard-to-guess and hard-to-crack) and revoke permissions of any suspicious applications that have access to your account.

http://twitter.com/gcluley

Birds image from Shutterstock.


View the original article here

Friday, October 12, 2012

Google, Facebook, Microsoft join non-profit to promote internet's awesomeness [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The Internet is mostly a good place filled with good people trying do good things. Except for those few bad people doing bad things - people you should really watch out for when you’re online. Be careful out there! OK?

If that sounds like the fuzzy-headed advice you’d give your budding adolescent, rest assured: there’s now a website that weaves together all the messy threads of contradictory guidance in one, easy to access location.

It’s called A Platform for Good, and it has the backing of some of the internet’s leading firms, including Facebook, Google and Microsoft.

Of course, Facebook, Google and Microsoft getting together behind something is always news. So, when the three tech giants announced on Wednesday that they signed up to support A Platform For Good, we decided to look into it.

pfg_website

The partnership, which also includes Yahoo! and major carriers like AT&T, Verizon and Sprint, seeks to “highlight the positive power of the internet” and provide an online portal that helps “parents and teens connect, share and do good,” according to a press release by the Family Online Safety Institute (FOSI), a UK-based non-profit that “works to make the online world safer for kids and their families.”

FOSI and its partner organizations hope to counter the negative stereotypes of the internet as a dark and dangerous place. In a statement, FOSI said:

The stories reported in the news and infusing public conversation are focused heavily on the negative notions that don't support the research that says the majority of people's online experiences are positive. Given this climate, it is our hope that PfG (Platform For Good) will create a place to have a more balanced discussion about the role digital technology can play in our lives.

When it comes to protecting you and your kids online, A Platform for Good does a good job pulling together links to the privacy statements for the major social networks, along with information (where available) on how users can protect their privacy online.

But some of the information is still lacking. Click on Computer Security and you find a link off to Microsoft’s page on preventing spyware infections. And nothing else.

The Mobile Safety section has links to AT&T content about the dangers of texting while driving, and a (solid) Yahoo page on mobile safety tips that talks (albeit obliquely) about problems like sexting, online bullying and mobile malware.

It’s all right-minded and we’ll add it to the long list of private initiatives to foster online safety. While we’re at it, we’ll put Google, Facebook and Microsoft to the list of companies whose hearts are in the right place.

But do these initiatives work once the ink is dry on the press release?

Providing scads of links to overlapping but uncorrelated discussions of the same problems is, it seems to me, a great way to engender confusion – not understanding.

You could forgive a parent, teacher or teenager from looking at a page full of links to identical sounding programs and hitting the browser “Back” button post-haste.

The truth is that mobile malware and drive-by downloads are difficult to predict or prevent, even under the best of circumstances.
Schools that want to teach online safety should start with a frank discussion of how modern malware works, the kinds of behaviors that increase the risk of you being targeted or infected, and what to do in the unfortunate event that you become a victim.

It isn't easy, as this video shows:

There’s also something important missing with A Platform for Good – namely: a substantive discussion of the very real problems that the internet and rapid technology adoption are introducing into childhood and adolescence.

In 2011, for example, The Pew Research Center has conducted studies that found ample evidence that social media use is associated with what Pew characterized as “cruel and unkind” behavior.

True, most teens think that their peers, generally, are nice to each other online rather than mean. But Pew found that one in three girls age 12-13 said that their peers were “mostly unkind” to each other on social media.

And, when the questions became more specific, teens in focus groups had no trouble conjuring personal stories about examples of online bullying, harassment and intimidation from their own peer group. They also depicted an environment in which online action and IRL (in real life) behaviors blur.

Here’s one exchange from a peer group in Pew’s report on “Teens, kindness and cruelty on social network sites”:

MIDDLE SCHOOL GIRL: I read what they were talking about online, then I go offline and confront the person who was saying something to her.

MIDDLE SCHOOL GIRL: …Like that’s how most people start fighting because that’s how most of the fights in my school happen – because of some Facebook stuff, because of something you post, or like because somebody didn’t like your pictures.”

We’ll chalk A Platform for Good up to “good intentions,” but perhaps it’s unrealistic to expect companies like Facebook, whose financial survival hinges on getting its users to share more online, to come down hard in favor of public health in the debate about online safety and online privacy.

This is a problem that’s bigger than Facebook, Microsoft and Google, and a problem that governments and the voters that elect them have to decide to solve.

In the meantime, you can always download the free Threatsaurus: The A-Z of computer and data security threats for practical tips to stay safe from email scams, identity theft, malware and other threats.

Follow @paulfroberts Follow @nakedsecurity

girl raising hand image courtesy of ShutterStock.

Tags: A platform for good, Android, Apple, bullying, education, Facebook, Google, Malware, Microsoft, mobile devices, online safety, Privacy, schools, teachers


View the original article here