Google Search

Showing posts with label mobile. Show all posts
Showing posts with label mobile. Show all posts

Friday, June 20, 2014

Feds swoop in, snatch mobile phone tracking records away from ACLU

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Image of Statue of Liberty, courtesy of ShutterstockThe American Civil Liberties Union (ACLU) filed a run-of-the-mill public records request about cell phone surveillance with a local police department in Florida.

The US Marshals Service last week reacted by swooping in and snatching those records out from under the ACLU's nose just hours before they were supposed to review them.

After the Feds seized the surveillance records, US Marshals then moved the physical records 320 miles away, meaning the ACLU wouldn't be able to learn how, and how extensively, police use snooping devices.

The ACLU promptly filed an emergency motion to get local police to disclose the records, which detailed how police had used a stingray to track nearby phones to a suspect’s apartment without getting a warrant.

A Florida judge last Tuesday granted the ACLU's emergency motion.

A stingray is a surveillance device that sends powerful signals to trick cell phones - including those of innocent bystanders - into transmitting their locations and their IDs.

The ACLU called the records grab an "extraordinary attempt to keep information from the public".

Even a former judge and a former United States magistrate judge found the US Marshals' action "weird" and "out of line", they told Ars Technica.

Former US magistrate judge Brian Owsley had this to say:

This one is particularly disturbing given the federal government's role in coming in and taking all of these records that were at issue in a state open government act.

In order to spirit away the records, the ACLU explains, the US Marshals waved a wand over Sarasota police detective Michael Jackson and transmogrified him - and the records - into their own property:

The Sarasota Police set up an appointment for us to inspect the applications and orders, as required by Florida law. But a few hours before that appointment, an assistant city attorney sent an email cancelling the meeting on the basis that the US Marshals Service was claiming the records as their own and instructing the local cops not to release them. Their explanation: the Marshals Service had deputized the local officer, and therefore the records were actually the property of the federal government.

The ACLU called the Marshal’s actions highly irregular:

The Sarasota detective created the applications, brought them to court, and retained the applications and orders in his files. Merely giving [the detective] a second title ('Special Deputy US Marshal') does not change these facts. But regardless, once the Sarasota Police Department received our records request, state law required them to hold onto the records for at least 30 days, to give us an opportunity to go to court and seek an order for release of the documents.

Last week, Ars Technica reported how use of the stingray in a Tallahassee, Florida, rape case only came out once testimony from a local police officer was unsealed.

The detective had told the court that he would only testify about how the stingray was used if his testimony was not made public.

That's because, the assistant attorney general told the court, the police were under a non-disclosure agreement (NDA).

Late last Tuesday, the judge ordered unsealing of the entire transcript of the suppression hearing.

The ACLU published the portion that, it says, the government tried to keep secret.

The ACLU says the released information "confirms key information about the invasiveness of stingray technology", including that:

Stingrays "emulate a cellphone tower" and "force" cell phones to register their location and identifying information with the stingray instead of with real cell towers in the area.Stingrays can track cell phones whenever the phones are turned on, not just when they are making or receiving calls.Stingrays force cell phones in range to transmit information back "at full signal, consuming battery faster."When in use, stingrays are "evaluating all the [cell phone] handsets in the area" in order to search for the suspect’s phone. That means that large numbers of innocent bystanders' location and phone information is captured.In this case, police used two versions of the stingray - one mounted on a police vehicle, and the other carried by hand. Police drove through the area using the vehicle-based device until they found the apartment complex in which the target phone was located, and then they walked around with the handheld device and stood "at every door and every window in that complex" until they figured out which apartment the phone was located in. In other words, police were lurking outside people's windows and sending powerful electronic signals into their private homes in order to collect information from within.The Tallahassee detective testifying in the hearing estimated that, between spring of 2007 and August of 2010, the Tallahassee Police had used stingrays "200 or more times."

I agree with a commenter on Ars's coverage, CQLanik, who noted that if a local police department can't allow the public to know the shady methods used to come by their evidence, then that method shouldn't be legal:

People have a right to face their accuser, and that right is being taken away by the use of secret evidence gathering.

What do you think?

Follow @LisaVaas

Follow @NakedSecurity

Image of Statue of Liberty courtesy of Shutterstock.


View the original article here

Thursday, June 12, 2014

Mobile malware, Gameover, CryptoLocker, and SSL/TLS holes - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

• How long has mobile malware been around?

• Is it really game over for Gameover and CryptoLocker?

• Which cryptographic security libraries need patching?

Find all the answers in this week's 60 Sec Security - 07 June 2014.

? Can't view the video on this page? Watch directly from YouTube.

Follow @duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Android, cabir, caribe, cryptolocker, doj, FBI, gameover, gnutls, heartbleed, Mobile, openssl, Patch, ransomware, rce, simplelocker, Symbian, takedown


View the original article here

Monday, May 12, 2014

Strong software protection needed for mobile devices

The massive adoption of mobile computing platforms creates the urgent need for secure application execution on such platforms. Unfortunately, today's mobile platforms do not support strong security solutions equivalent to smartcards in set-top boxes or to dongles to reliably control licensing terms. Furthermore, many of these mobile devices are shared for professional and private applications, and are thus intrinsically hard to control and secure.

Michael Zunke, chief technology officer of SafeNet's Software Monetization Business Unit states that "Security is ever more essential as an enabler for the sustainable innovation of mobile applications and services. Security solutions based on custom hardware security components like dongles and smart cards are not a natural fit for these mobile environments. The industry therefore needs a comprehensive security framework in which software protection is the key ingredient."

According to Brecht Wyseur, NAGRA's security architect, the big challenge in the next years will be to increase the security level of software solutions to allow for both cost effective deployment and long-term renewability, either stand-alone or in combination with a hardware root of trust.

Hence, more research is needed to come up with a solution that is strong enough to be a viable solution for an increasing number of applications in which privacy and security are essential. The ASPIRE project will create the ASPIRE software security framework which will develop, combine and integrate five different types of software protection techniques into one easy to use framework. It will deliver comprehensive, effective security metrics and a decision support system to assist the software developer.

"The integrated tool chain will allow service providers to automatically protect the assets in their mobile applications with the best local and network-based protection techniques," notes Bjorn De Sutter, coordinator of the project, adding that "ASPIRE will make mobile software more trustworthy by leveraging the available network connection and by developing a layered security approach of strong protections. We will also make it measurable by developing practical, validated attack and protection models and practical metrics."

Story Source:

The above story is based on materials provided by Ghent University. Note: Materials may be edited for content and length.


View the original article here

Saturday, May 10, 2014

Quantum cryptography for mobile phones

An ultra-high security scheme that could one day get quantum cryptography using Quantum Key Distribution into mobile devices has been developed and demonstrated by researchers from the University of Bristol's Centre for Quantum Photonics (CQP) in collaboration with Nokia.

Secure mobile communications underpin our society and through mobile phones, tablets and laptops we have become online consumers. The security of mobile transactions is obscure to most people but is absolutely essential if we are to stay protected from malicious online attacks, fraud and theft.

Currently available quantum cryptography technology is bulky, expensive and limited to fixed physical locations -- often server rooms in a bank. The team at Bristol has shown how it is possible to reduce these bulky and expensive resources so that a client requires only the integration of an optical chip into a mobile handset.

The scheme relies on the breakthrough protocol developed by CQP research fellow Dr Anthony Laing, and colleagues, which allows the robust exchange of quantum information through an unstable environment. The research is published in the latest issue of Physical Review Letters.

Dr Laing said: "With much attention currently focused on privacy and information security, people are looking to quantum cryptography as a solution since its security is guaranteed by the laws of physics. Our work here shows that quantum cryptography need not be limited to large corporations, but could be made available to members of the general public. The next step is to take our scheme out of the lab and deploy it in a real communications network."

The system uses photons -- single particles of light -- as the information carrier and the scheme relies on the integrated quantum circuits developed at the University of Bristol. These tiny microchips are crucial for the widespread adoption of secure quantum communications technologies and herald a new dawn for secure mobile banking, online commerce, and information exchange and could shortly lead to the production of the first 'NSA proof' mobile phone.


View the original article here

Tuesday, May 6, 2014

Mobile users may not buy into instant gratification cues, gimmicky ads

Gimmicky contest ads and flashy free-prize messages may be an instant turnoff for mobile users, according to Penn State researchers.

In a study, a tempting offer of a free prize drawing for registering on a mobile website led users to distrust the site, said S. Shyam Sundar, Distinguished Professor of Communications and co-director of the Media Effects Research Laboratory.

Sundar said that in an increasingly information-loaded world, people tend to lean on cues, such as icons and messages, for decision-making shortcuts, called heuristics. However, some cues may elicit user reaction in the opposite direction of what most marketers would anticipate.

"Even though we turn to our mobile devices for instantly gratifying our need for information, we may not be persuaded by advertising appeals for instant gratification," said Sundar. "It's a boomerang effect--marketers may think that they are activating the instant gratification heuristic when they display time-sensitive offers, but what they're actually doing is cuing red flags about the site."

Mobile users tend to be more knowledgeable about technology than regular users.

"It could be that an instant gratification message makes mobile users, who tend to be more tech savvy, leery about the site," said Sundar.

Even though free-prize ads are ubiquitous on the internet, marketers may want to seek other ways to reach mobile customers, according to the researchers.

The researchers, who presented their findings? Apr. 28 at the Association for Computing Machinery's Conference on Human Factors in Computing Systems, also tested a warning cue that seemed to prompt more conflicting reactions from users, said Sundar. When a security alert -- a caution icon with a warning message -- appeared, users became more worried about security, as expected. However, users were willing to reveal more information about their social media accounts after viewing the security prompt.

One possible explanation for this behavior is that the security cue makes the users distinguish more carefully between public and private information.

"People may feel that the social media information is already public information, not necessarily private information, and they are not as concerned about revealing social media information," said Sundar, who worked with Bo Zhang, Mu Wu, Hyunjin Kang and Eun Go, all doctoral students in mass communications. "The 'privacy paradox' of giving away information when we are most concerned about its safety may not be all that paradoxical if you consider that the information we give away is not quite private."

The researchers recruited 220 participants to test four different mobile sites. The participants were first asked to navigate to a mobile site. One site included a caution symbol and a security warning that the site was insecure and another site contained a gift box icon with a message that the user could win a free prize for registering. A third site showed both a warning and an instant gratification message and a fourth site, which featured neither alerts, served as the control in the study. Except for these cues, all other content in the four sites was identical.

Participants could choose how much or how little personal, professional, financial or social media information they provided in the registration form, which served as a measure of their information disclosure behaviors. After registering, they filled out an online questionnaire about their impressions of the mobile website.


View the original article here

Tuesday, April 29, 2014

Here we go again: Viber mobile messenger app leaves user data unencrypted

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

viber-app-170Viber, a mobile messenger app that allows users to make phone calls and send text messages and images for free, also gives up plenty of free user data to anyone who wants to listen.

According to researchers from the University of New Haven (UNH) in Connecticut, US, Viber's app sends user messages in unencrypted form - including photos, videos, doodles, and location images.

All of that rich data from users is also stored unencrypted on Viber's servers, rather than being deleted immediately, and is accessible without credentials, just a link, the UNH researchers said.

It's the second cryptographic blunder exposed by UNH researchers in as many weeks - the UNH Cyber Forensics Research & Education Group disclosed on 13 April 2014 that the WhatsApp messenger app also gives away user location data in unencrypted form.

Using a Windows PC as a Wi-Fi access point, the UNH team was able to capture data sent by an Android smartphone with regular traffic sniffing tools, the same approach taken by UNH in their experiments with WhatsApp.

In a video posted on the UNH website and YouTube, the researchers demonstrated capturing messages sent between two test Android phones.

Data can be intercepted by poisoned access points, by malicious users on the same Wi-Fi network, or elsewhere in the network between you and Viber.

In the video, one of the researchers said the unencrypted messages can also be retrieved from Viber's servers by anyone who knows the message URL:

The data is stored on Viber's server in an unencrypted manner. There is also no authentication method used, so anybody who has access to these links can look at this data, retrieve this data, and do whatever they want with it.

The researchers, Dr Ibrahim Baggili and Jason Moore, said in a blog post that they reported the security flaw directly to Viber before publishing their results but did "not receive a response from them."

In a statement to CNET, Viber said it would be releasing a fix soon for Android and iOS, and said the issue has been "resolved."

This issue has already been resolved. It is currently in QA and the fix will be released for Android and submitted to Apple on Monday. As of today we aren't aware of a single user who has been affected by this.

The fact is that an modern online messaging app shouldn't really be "fixing" this sort of blunder - encryption should have been baked in from the start.

And for all that Viber may have "fixed" its apps to exchange data securely now, it hasn't said anything about addressing the insecurities that UNH found in Viber's cloud, where your messages are stored.

The company also lists only Android and iOS as getting updates, leaving users of its numerous other supported platforms in the dark.

That includes users of Viber on the desktop, via Samsung's Bada ecosystem, on Microsoft's various mobile operating systems, and on Blackberry and Nokia phones.

With all of this in mind, Viber's claim that "we aren't aware of a single user who has been affected by this" rings very hollow.

After all, the company didn't bother to apologize for not spotting these problems in its own QA – and putting its customers at needless risk.

whatsapp-viber-snapchatAs is becoming all too common with the new breed of mobile messenger apps - including the Facebook-owned WhatsApp and the photo and video-sharing app Snapchat - security and privacy of user data seems to be an afterthought.

Although both WhatsApp and Viber said they will work to fix their encryption oversights, at times these young companies have exhibited a cavalier and disdainful attitude towards data privacy and security.

Viber, founded in 2010, has had a couple other security incidents in the past year.

In July 2013, a security researcher managed to use pop-up notifications from the Viber app to bypass the lock screen on an Android device.

And in April 2013, Viber's support page was hacked by the Syrian Electronic Army, although no user data was lost in the attack.

WhatsApp's founder Jan Koum famously said that "respect for your privacy is coded in our DNA," after his company was bought out by Facebook for $19 billion in March.

That's a nice sentiment, but WhatsApp has made repeated cryptographic blunders that left user data vulnerable.

Another rapidly growing messenger app, Snapchat, ignored warnings from security researchers that the app allowed unlimited searches of user phone numbers - a flaw that led to an attacker dumping 4.6 million usernames and phone numbers online after Snapchat dismissed the attack as "theoretical."

When asked to appear voluntarily before a Congressional hearing on data breaches, Snapchat refused to testify, leading one US Senator to say the company was "hiding something."

Which is ironic, since hiding user data from prying eyes doesn't appear to be one of the company's strengths.

Despite promises it made to users that their private messages would "disappear forever," Snapchat has acknowledged that user Snaps aren't deleted right away from their servers or from users' phones.

These popular messenger apps may be free, but at a cost to privacy for their hundreds of millions of users.

Follow @JohnZorabedian
Follow @NakedSecurity

Get it now for free...


View the original article here

Saturday, December 21, 2013

Facebook users worldwide (minus some mobile phones) now getting secure web browsing by default

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook initially introduced full-time HTTPS (secure HTTP) as an option in January 2011.

Before that, the site protected your password during login using HTTPS, but left the rest of your session unencrypted.

The change came about because, back in October 2010, a Firefox plugin called Firesheep was released as a proof of concept that sniffing an unencrypted session after login was all an attacker needed to hijack your account.

This made Facebook's new option welcome, but being opt-in meant it really didn't go far enough.

So, in an open letter in April 2011, Naked Security asked Facebook to improve privacy and safety by turning on HTTPS for everything.

In November 2012, Facebook finally did move to make secure browsing a default, at least for users in North America.

And on Wednesday, Facebook announced that it is now using HTTPS by default for all users, so the rest of the world has finally caught up. (Well, almost. Some mobile phones and carriers don't fully support HTTPS.)

Why did it take so long?

Because it involved a lot of moving parts, explains Facebook software engineer Scott Renfro.

Namely, it involved getting third-party application developers to upgrade, getting web-browser cookies to be compliant, controlling referrer headers, and migrating users to HTTPS without disrupting "in-flight" sessions, i.e. upgrading people while they're actually using the site.

Performance has also been a huge challenge, Renfro says, given the extra hoops browsers have to jump through with HTTPS:

In addition to the network round trips necessary for your browser to talk to Facebook servers, https adds additional round trips for the handshake to set up the connection. A full handshake requires two additional round trips, while an abbreviated handshake requires just one additional round trip. An abbreviated handshake can only follow a successful full handshake.

Here's an example from Renfro of how that extra latency can make users with already-slow connections suffer yet more, and how Facebook has eased the pain:

If you're in Vancouver, where a round trip to Facebook's Prineville, Oregon, data center takes 20ms, then the full handshake only adds about 40ms, which probably isn't noticeable. However, if you're in Jakarta, where a round trip takes 300ms, a full handshake can add 600ms. When combined with an already slow connection, this additional latency on every request could be very noticeable and frustrating. Thankfully, we've been able to avoid this extra latency in most cases by upgrading our infrastructure and using abbreviated handshakes.

Facebook's work on secure browsing is most certainly not done, mind you: the company says it's still working with mobile phone vendors to make it happen there.

Renfro calls HTTPS by default a "dream come true" — a goal that the company's network, security, traffic, and security infrastructure teams have been working on for years.

When Facebook first rolled out HTTPS by default, Naked Security was stuck with a heap of "Dislike" t-shirts that didn't seem appropriate anymore, so the team gave them away to readers.

Sorry, I don't know of any plans to print up "Like" t-shirts over the news that HTTPS by default is finally, for the most part, a dream come true.

But, Facebook engineers, here are two big, virtual thumbs-up for the work you've done. Let's hope it works out well for the mobile outliers, as well.

Follow @LisaVaas

Follow @NakedSecurity


View the original article here

Friday, November 29, 2013

Jay-Z’s ‘Magna Carta’ mobile app is too snoopy, privacy advocates complain

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Jay-Z. Image courtesy of Shutterstock.Why does Jay-Z want to know who we're talking to?

Because that's the type of information demanded by an app he released earlier this month to promote and distribute his latest album over Samsung devices.

In fact, the galaxy of permissions required by this busybody little app "verges on parody," the Electronic Privacy Information Center (EPIC) said in a complaint it filed this week with the Federal Trade Commission (FTC).

The Magna Carta App, used to promote the album, "Jay-Z Magna Carta Holy Grail", was launched 4 July on Samsung Galaxy Nexus devices in advance of the record release.

EPIC wants the FTC to stop Samsung from distributing the app until its privacy concerns are addressed and the app falls in line with the Consumer Privacy Bill of Rights [PDF].

The app requires these permissions:

To modify or delete contents of phone USB storage.To prevent phone from sleeping and view all running apps.To access your precise (GPS) and approximate (network-based) location.To read your phone status and identity (i.e. who you're talking to on voice calls).To run at startup.To test access to protected storage. To receive data from internet, view Wi-Fi connections, and view network connections.To control your phone's vibration. To find accounts on the device - in other words, to gather email addresses and social media usernames connected to the phone.

The app not only wants to know who you call, it also demands your Twitter or Facebook login so it can post on your behalf, presumably so it can create "social buzz," EPIC says.

Beyond that, people who downloaded the Magna Carta app have been forced to post a canned Facebook or Twitter message to hype the album for each song's lyrics they wanted to check out - a process that "encouraged users to flood their friends with unwanted advertising" and forced users to act as "mandatory marketing tools" to access the lyrics, EPIC says.

Users were suitably appalled. One actually paused for an entire 6 seconds.

And then, well, he or she went ahead and downloaded it.

Others are in mourning for the loss of lifespan the app sucked up.

One user's comment:

"I downloaded it, opened it, noticed the obscene amount of personal data they wanted, closed it again and uninstalled. I'd like that minute and a half of my life back please."

Observers are, naturally, assuming that Jay-Z has undertaken advanced surveillance as a hobby.

From Jon Pareles, writing for the New York Times:

"If Jay-Z wants to know about my phone calls and e-mail accounts, why doesn't he join the National Security Agency?"

Pareles is particularly irked, given lyrics from at least one Jay-Z song - "Somewhere in America" - that seem, confusingly enough, to be anti-NSA:

"Feds still lurking"

"They see I'm still putting work in..."

As Pareles points out, now Jay-Z is lurking, in our phones.

Jay-Z, if you're listening, which it seems like you are, then please, call off your Samsung colleagues.

We've got enough eavesdropping going on without you adding to the snooping.

Follow @LisaVaas

Follow @NakedSecurity

Image of Jay-Z courtesy of Shutterstock.


View the original article here

Tuesday, October 8, 2013

Android malware in pictures - a blow-by-blow account of mobile scareware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Thanks to Nagy Ferenc László of SophosLabs for the
behind-the-scenes work that he put into this article.

Fake anti-virus, also suggestively known as scareware, tricks you into paying money by pretending to find threats such as viruses and Trojans on your computer.

The scan to find the "threats" is free; the cleanup part is not.

If you do pay up, the software then pretends to remove the non-existent threats so you may not even realise that you've been scammed, on the principle that all's well that ends well.

But not only are you out of pocket, typically between $40 and $100, you're also led into a false sense of security, because the clean bill of health provided after you've paid is as bogus as the infection report at the start.

This sort of scam is most common on Windows, with OS X a long way back in second place. But other operating systems aren't exempt from the depredations of cybercriminals.

SophosLabs recently acquired an Android scareware sample going by the entirely hokum name of Android Defender. It's not particularly polished, and it crashed quite a bit as we played with it, but it does show that the scammers have an active interest in the Android ecosystem.

I thought I'd give you a guided tour of what it looks like. That way, you'll have some pointers that I hope will help you determine real from fake security software in future.

I started by creating a fresh Android 4.2.2 emulator image and firing it up.

Then I installed the malicious APK (Android Package file). In real life, you might be encouraged to download it from a handy website; I just used the Android Debug Bridge (adb) to inject it from my research computer into the emulated image.

You can see the application icon at top left, since its name conveniently starts with 'A'.

I launched it to see what would happen. It advised me that my device "is at risk of being infected," which is an understatement: my device is already infected, because Android Defender is on it.

I'm invited to buy, but there's no serious pressure yet.

The inital scan quickly suggests I have a problem.

Two viruses, one Trojan and a Malware, to be precise.

You might be inclined to believe this report, since the "threats" found are Android malware names you might have heard of.

But it's all smoke and mirrors. You don't have to be a Java coder, or even a programmer at all, to spot in the source code below that the app is using the Math.random() function to build up a list of virus names to report later.

The malware names are field-updatable, stored in Russian and in English in an XML data file that is part of the malware's APK file.

This is about as close to "malware identities" (also known as signatures, patterns or definitions) as you will find in the app.

There isn't anything to help the product actually locate viruses in infected files. There's just a list of names: when you're choosing randomly even on uninfected devices, recognition patterns just aren't needed.

Most of the viruses on the list are existing Android malware names, in order to add a ring of verisimilitude. But somehow the Windows-only virus Conficker managed to get in there.

The pressure on me to register the product is increasing, because it's now time to think about cleaning up the malware.

So I gave it my best shot, and tried to "activate" the software.

The buy page wasn't working, so I can't tell you how much the scammers intended to charge.

But it didn't matter, because I had an activation code up my sleeve from the source code itself.

We saw this happy-go-lucky attitude to activation in early Mac scareware.

Was the activation system this simplistic for experimental convenience, or is it just a prototyper's indolence? We shall probably never know.

The product crashed after I clicked the Activate button, but when I started it up again, I found that the activation had worked and my device was "fully protected."

The next system scan is no longer a scary red but a go-ahead green.

Better still, the app is pretending to have "eliminated" the malware it "detected" earlier.

In fact, the software builds a small sqlite database in which it remembers what viruses it has "found", and whether it has fraudulently "cleaned" them, so it will be consistent in its dishonesty.

There's a half-hearted privacy manager tool built in to the app, presumably because that's the sort of feature that other Android security products provide.

And there's an update page, though the crooks forgot to translate that part properly.

The update pretends to work, even listing signature files it supposedly downloaded from the internet.

(In my case, it couldn't have downloaded anything from outside - I tested in with my device in Airplane Mode, which inhibits all outbound connections. That cuts you off in the emulator, just as it would on a real device.)

Updates are only simulated once a day, in order to appear more realistic.

The app pretends that its pattern database has increased in size every time you update. Once again, the Java pseudorandom number generator is used behind the scenes.

I don't imagine you installed this progam, but if you did, you need to remove it right away.

And you couldn't have installed it without first telling your device that you wanted the freedom to go looking for software outside Google's own official Play Store.

I'd suggest, if you did so (since it ended badly enough for you to get this malware!) that you turn "Unknown sources" off once again.

And you might want to consider installing a proper Android security tool in which the detection and the cleanup are free.

Sophos Security and Antivirus is available from the Play Store, so you don't need to enable "Unknown sources" to install it.

And yes, it does actually look for threats before it reports them.

If it finds a threat, there aren't any demands. Just a warning and an instant "Uninstall" button.

In the words of many a Naked Security video and podcast, thanks for listening, and until next time, stay secure!

Follow @duckblog


View the original article here

Wednesday, June 12, 2013

Mobile device security in the US military comes under fire

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

On March 26th, the Inspector General released a report on the effects of BYOD (bring your own device) on the U.S. military.

Inspector General report

Among the report's findings:

Mobile devices were not secured to protect stored information.The US Department of Defense (DOD) did not have ability to wipe devices that were lost or stolen.Sensitive data was allowed to be stored on commercial mobile devices acting as removable media.DOD did not train users and did not have them sign user agreements.The Army CIO was unaware of more than 14,000 mobile devices used throughout the Army.

Ouch.

This from an entity that seems to have policies and regulations for everything.

The Army did implement a good policy regarding geotagging a while back, realizing the risk that came with soldiers taking pictures that automatically had location information embedded in metadata.

Location smartphone. Image from ShutterstockHowever, given the lack of management of the devices, how would the military know for sure that the geotagging has been disabled?

And if the United States Army, with all the endless policies, is having a difficult time with BYOD, how is a small or medium-sized business going to cope?

Why does this all matter?

Answer: Data loss. Stolen data is massive business for the bad guys. A phone left in a cab or at an airport can be a goldmine of sensitive information. Consider the case of the US Secret Service contractor who left two tapes of sensitive data on the DC Metro train.

What crook wouldn't have loved to have gotten a hold of two databases full of juicy personal information of agency employees, contractors and possibly informants? It's just another example that even the most "security conscious" people have forgetful moments, or moments of distraction and can easily leave something behind.

Last year, Sophos did an informal study and found that 42% of lost mobile devices aren't protected with any security measures.

Now of that number, 20% had access to business email, which could contain confidential information. Small businesses are even more at risk - just because you are small doesn't make you less of a target.

We have written several articles about handling smartphones in a business before and have provided some sage advice within about how to implement BYOD, but how do you create a BYOD policy?

Where's the best place to start? Sophos CTO Gerhard Eschelbeck outlines the following tips in a recent whitepaper.

Mobile post it. Image from Shutterstock7 steps to a BYOD security plan

Identify the risk elements that BYOD introduces. Measure how the risk can impact your business and map the risk elements to regulations, where applicable.Form a committee to embrace BYOD and understand the risks, including business stakeholders, IT stakeholders and information security stakeholders.Decide how to enforce policies for any and all devices connecting to your network including mobile devices (smartphones), tablets (e.g., iPad) and portable computers (laptops, netbooks, ultrabooks).Build a project plan to include these capabilities: Remote device managementApplication controlPolicy compliance and audit reportsData and device encryptionAugmenting cloud storage securityWiping devices when retiredRevoking access to devices when end-user relationship changes from employee to guestRevoking access to devices when employees are terminated by the companyEvaluate solutions. Consider the impact on your existing network and how to enhance existing technologies prior to next step.Implement solutions. Begin with a pilot group from each of the stakeholders' departments. Expand pilot to departments based on your organizational criteria. Open BYOD program to all employees.Periodically reassess solutions. Include vendors and trusted advisors. Look at roadmaps entering your next assessment period. Consider cost-saving group plans if practical.

Regardless of how big or small your 'army', securing your organization's devices and the data on those devices is at the front line of maintaining a strong IT security defense.

Follow @SophosLabs
Follow @NakedSecurity

Smartphone map and mobile note images from Shutterstock


View the original article here

Thursday, July 19, 2012

Facebook to target ads based on what mobile apps we use

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook MobileDo you use your Facebook account to log onto places like LinkedIn and Yelp from your phone?

If so, get ready to start seeing ads in your mobile device's Facebook News Feed that will be targeted based on your mobile app usage.

Here's how it will work, according to the Wall Street Journal: if you like to play Zynga Inc.'s "Words with Friends," your mobile News Feed will soon target you with ads for yet more Zynga games.

If the WSJ's sources are correct about all this, the new ads will represent a boundary-breaking move for an ad-delivery company, given that none has thusfar tracked consumers on the basis of mobile app usage.

The ads will be enabled by the Facebook Connect feature, which lets users easily log in to third-party sites, applications, mobile devices and gaming systems with their Facebook identities.

Facebook Connect

Sources familiar with Facebook's plans told the WSJ that the company is launching a new type of mobile advertising that will target consumers based on what apps they use, "pushing the limits of how companies track what people do on their phones."

But wait, there's more.

The unnamed sources told the WSJ that beyond tracking consumers' use of mobile apps, Facebook is also pondering whether to track what people do on those apps.

Facebook trackingThat move would be an even bigger game-changer. As it now stands, mobile-ad networks only target consumers based on what ads a person clicks on from his or her mobile browser.

Both Apple and Google track their users' mobile apps, but neither company tracks what people do in those apps.

One of the WSJ's sources said that Facebook will charge advertisers every time an app is installed on a user's smartphone.

That's a highly profitable prospect, the WSJ noted, for obvious reasons - i.e., a heck of a lot more consumers download apps than click on ads:

Facebook can charge significantly more for an app installation than it can for the traditional cost of every one thousand people who have viewed an ad.

Privacy advocates would far prefer that Facebook let users log in with Facebook Connect and then have a way to opt out of the new mobile ad targeting.

The WSJ quoted Justin Brookman, director of the Center for Democracy and Technology's project on consumer privacy, who noted that consumers just aren't used to having ad companies peering over their shoulders every time they use a mobile app:

"Once you're signed in, are you really expecting that Facebook is going to be watching you while you're on there?"

LinkedIn on an iPhoneOf course, with the post-IPO Facebook now under the gun to monetize features such as Facebook Connect, it's hard to imagine that the company won't track what people do in their mobile apps.

What would that look like? The possibilities are limited only by our activities while using mobile apps.

Searching for experts in a given field - say, infosec! - in LinkedIn, for example, would open up whole new worlds of targeted advertising.

One of the WSJ's sources said the new ads might be announced on July 16, unless privacy concerns convince the company to hold off on mentioning it until Chief Operating Officer Sheryl Sandberg conducts the company's first earnings call with analysts on July 26.

The new ads would then launch on July 30, the source said.

What do you think of Facebook's plans to target adverts in this way? Let us know by leaving a comment below.

Follow @LisaVaas

View the original article here

Friday, June 1, 2012

Should jailbreaking gaming consoles, mobile phones and tablets be legalized?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

consoles and phoneYesterday US copyright regulators opened up the floodgates for a public hearing (PDF) of proposals to change copyright law, including authorizing the cracking of tablets, DVDs, gaming consoles and mobile phones.

Every three years, the US Copyright Office mulls over requests to create temporary loopholes in the law that forbids circumventing encryption in the things we buy.

Changes to those loopholes have the potential to mean a lot to George Hotz.

Hotz is a hardware hacker known online as Geohot who owns a box full of Sony products. Per court order, they've been tucked away where he can't tinker with them.

As Wired's David Kravets writes, Sony last year dropped a PlayStation 3 jailbreaking lawsuit against Hotz in return for his promise to never again hack his game console or any other Sony product.

He told Wired that he hasn't touched the components since the settlement.

Before the settlement of the civil suit, he was busy figuring out how to play homemade games on the Sony console, in violation of a law that forbids cracking encryption in hardware or software, even for legal purposes.

This will be the fifth time the office has heard requests to modify the law—the Digital Millennium Copyright Act (PDF)—since it was passed in 1998.

The DMCA criminalizes both the technology and the act of circumvention, regardless of whether doing so actually infringes on a copyright.
fish jailbreaking

Hotz is far from the only individual intent on the amendment hearings.

Proposed exemptions, previously granted but now expiring, include one for jailbreaking smartphones to run on a consumer's choice of carriers, one that would allow DVD cracking of motion pictures for the purpose of educational or documentary commentary, and another that would allow consumers to hack e-books digital rights management to enable read-aloud features for the visually impaired.

Public Knowledge, a public interest group involved in intellectual property law, is also seeking the legalization of technology that lets users crack encryptions on movies and TV shows they own on DVD.

That would allow consumers to watch legally purchased movies on whatever device they want and to make backups of sticky/scratched-up/chewed-on/quickly brutalized children's movies.

It just makes sense, given how comfortable we've gotten with copying copyrighted works we own from one medium to another, as is the case with CDs, writes Public Knowledge's Michael Weinberg.

This is sometimes called 'space shifting' or 'format shifting.' For example, this is what you do when you rip a CD in order to create .mp3 files to transfer to your iPod.

Another example of this is when you transfer a movie from a DVD onto a laptop or a tablet device, like an iPad. However, there is one important difference between a movie on DVD and a song on a CD: unlike the CD, DVDs are encrypted. That means that while copying a song from a CD is a one step process (copy the file), copying a movie from a DVD is a two-step process (decrypt the file, copy the file).

Users are authorized to decrypt the movie in order to watch it, but are not authorized to decrypt the movie in order to copy it. As a result, that extra DVD step (decrypting) is illegal under the DMCA. That makes it impossible to copy DVDs the same way you copy CDs.

The proponents and foes of proposed DMCA changes are lining up predictably: industry groups are against, consumer rights and knowledge freedom proponents are for.

Industry groups argue against the changes on the grounds that their business models will be ruined, that all hell will break lose vis-a-vis cyberattacks on cell phone networks, and that illegal game copies will flower like dandelions.

Here's how Sony attorney Jeffrey Cunard put it (PDF) in his comments to the Copyright Office:

If the exemption is granted, it is virtually certain that successful hackers, under the guise of the exemption, will create the tools that enable even novice users to make, distribute, download and play back illegal copies of games.

But as Wired's Kravets points out, the 2010 court decision to allow mobile phone users to jailbreak smartphones most certainly didn't squash Apple's profits, in spite of what the company predicted.

Rather, it fostered a "vibrant alternative to the tightly constrained and capriciously run Apple App Store," Kravets said.

He was referring to Cydia, a third-party app store for jailbroken iPhones, iPod Touches or iPads that recorded 4.5 million weekly users as of April 2011.

Cyberattacks didn't run wild. Apple didn't go broke.

If the new changes get accepted, will Call of Duty b**tard spawn careen across the PlayStations of a copyright wasteland?

Time will tell.

Stay tuned: Another hearing's taking place in Washington, DC, next month, with final amendments likely due to be adopted by year's end.

What do you think?

Follow @LisaVaas

Fishbowl image courtesy of shutterstock
Money tree image courtesy of shutterstock
Devices image courtesy of shutterstock


View the original article here

Monday, April 30, 2012

Mobile phone carriers oppose law requiring warrants for location data

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

CTIA logoThe mobile carriers industry trade group, CTIA–The Wireless Association, is objecting to a proposed bill that would require the police to produce a warrant if it wants access to location data on people's mobile phones.

CTIA are calling the legislation "unduly burdensome" to say no to police who arrive without warrants.

The bill in question, California Location Privacy Bill (SB 1434), doesn't stop the carriers from handing over location data, but it does require that police get a warrant first.

The proposed law also states that carriers must publish reports showing the number of disclosures they've made in a given calendar year, including:

how many times each wireless provider disclosed information (and how many times it didn't)how many times the carrier contested data demandshow many users' data were disclosed.

And this report is to published on the internet by the following April.

On April 12, the CTIA wrote [PDF] to the bill's sponsor, State Senator Mark Leno, saying that CTIA opposes the proposed legislation due to "serious concerns":

"These reporting mandates would unduly burden wireless providers and their employees – who are working day and night to assist law enforcement to ensure the public’s safety and to save lives."

... and that the legislation would "confuse" them.

For example, an issue the carriers would find confusing is the definition of "location information." CTIA say that it is "so sweeping" that it could overlap basic subscriber information:

"Since the implications of this definition are unclear, wireless providers will have difficulty figuring out how to respond to requests for such information. It could place providers in the position of requiring warrants for all law enforcement requests."

Ars Technica's Cyrus Farivar, for one, is confused about why the CTIA is confused.

Here's what he had to say:

"Earlier this month, the ACLU said it received over 5,500 pages from 200 local law enforcement agencies about their tracking policies. The organization concluded that 'while cell phone tracking is routine, few agencies consistently obtain warrants.

Importantly, however, some agencies do obtain warrants, showing that law enforcement agencies can protect Americans' privacy while also meeting law enforcement needs.' In short, it seems like law enforcement can stay within the law, even when it takes the trouble to get a warrant—how is that confusing?"

wireless_warning 170Regarding the cost and labour involved in putting up reports that tell the public how they are releasing our information: well, if it's really all that costly to the poor, cash-strapped wireless providers, perhaps it's time for them to increase the fees they charge law enforcement agencies for the all-you-can-eat buffet of data they provide.

One example, as security and privacy researcher Christopher Soghoian reports, is Sprint, which charges a flat $30/month for electronic surveillance of location/GPS data.

Obviously, they're giving the data away.

Sometimes that's a good thing, such as when geolocating somebody will save his or her life. The bill addresses such situations, where time is more crucial than the need to obtain a warrant.

For all the other times?

Let's hope the bill passes. It's time for a lot more transparency from the carriers who give our data away, and a great deal more accountability from the agencies who seek it in the first place.

Follow @LisaVaas

Wireless image courtesy of Shutterstock


View the original article here

Saturday, October 1, 2011

100 texts a day limit? India tries to combat mobile phone spam

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Indian man using a mobileNew spam regulations, introduced in India, limit the users of mobile phones to sending only 100 texts per day.

The reason? To stop the growing problem of SMS text spam.

Cellphone usage is huge in India, with more than 700 million subscribers. But with that popularity comes the problem of users being constantly plagued with unwanted calls and text messages from tele-marketing firms.

Under new rules access providers will have to limit SIM owners to sending only 100 SMS text messages a day (or 3000 per month).

In addition, commercial calls and marketing text messages will only be allowed to be sent between 9am and 9pm. A relief for many users who have received mobile marketing communications in the small hours of the morning.

Last month, Indian telecoms minister Kapil Sibal rather optimistically announced that the SMS spam problem would cease to exist within six weeks, following the introduction of a national "do not call" list.

Mobile phone users in India just need to text 1909 to opt-out of receiving unsolicited calls and texts, but of course it remains to be seen if the tele-marketing companies honour the list.

Will the new regulations make a noticable dent on the torrent of SMS spam hitting Indian mobile phone users? Only time will tell.

One thing is certain - sending bulk text messages is becoming cheaper and cheaper, and is more likely to be read by the intended recipient than an unsolicited email message. As such, there will be people who will be keen to bend the rules and continue to send spam messages to mobile phones.

http://twitter.com/gcluley

View the original article here