An ultra-high security scheme that could one day get quantum cryptography using Quantum Key Distribution into mobile devices has been developed and demonstrated by researchers from the University of Bristol's Centre for Quantum Photonics (CQP) in collaboration with Nokia.
Secure mobile communications underpin our society and through mobile phones, tablets and laptops we have become online consumers. The security of mobile transactions is obscure to most people but is absolutely essential if we are to stay protected from malicious online attacks, fraud and theft.
Currently available quantum cryptography technology is bulky, expensive and limited to fixed physical locations -- often server rooms in a bank. The team at Bristol has shown how it is possible to reduce these bulky and expensive resources so that a client requires only the integration of an optical chip into a mobile handset.
The scheme relies on the breakthrough protocol developed by CQP research fellow Dr Anthony Laing, and colleagues, which allows the robust exchange of quantum information through an unstable environment. The research is published in the latest issue of Physical Review Letters.
Dr Laing said: "With much attention currently focused on privacy and information security, people are looking to quantum cryptography as a solution since its security is guaranteed by the laws of physics. Our work here shows that quantum cryptography need not be limited to large corporations, but could be made available to members of the general public. The next step is to take our scheme out of the lab and deploy it in a real communications network."
The system uses photons -- single particles of light -- as the information carrier and the scheme relies on the integrated quantum circuits developed at the University of Bristol. These tiny microchips are crucial for the widespread adoption of secure quantum communications technologies and herald a new dawn for secure mobile banking, online commerce, and information exchange and could shortly lead to the production of the first 'NSA proof' mobile phone.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Facebook initially introduced full-time HTTPS (secure HTTP) as an option in January 2011.
Before that, the site protected your password during login using HTTPS, but left the rest of your session unencrypted.
The change came about because, back in October 2010, a Firefox plugin called Firesheep was released as a proof of concept that sniffing an unencrypted session after login was all an attacker needed to hijack your account.
This made Facebook's new option welcome, but being opt-in meant it really didn't go far enough.
So, in an open letter in April 2011, Naked Security asked Facebook to improve privacy and safety by turning on HTTPS for everything.
In November 2012, Facebook finally did move to make secure browsing a default, at least for users in North America.
And on Wednesday, Facebook announced that it is now using HTTPS by default for all users, so the rest of the world has finally caught up. (Well, almost. Some mobile phones and carriers don't fully support HTTPS.)
Why did it take so long?
Because it involved a lot of moving parts, explains Facebook software engineer Scott Renfro.
Namely, it involved getting third-party application developers to upgrade, getting web-browser cookies to be compliant, controlling referrer headers, and migrating users to HTTPS without disrupting "in-flight" sessions, i.e. upgrading people while they're actually using the site.
Performance has also been a huge challenge, Renfro says, given the extra hoops browsers have to jump through with HTTPS:
In addition to the network round trips necessary for your browser to talk to Facebook servers, https adds additional round trips for the handshake to set up the connection. A full handshake requires two additional round trips, while an abbreviated handshake requires just one additional round trip. An abbreviated handshake can only follow a successful full handshake.
Here's an example from Renfro of how that extra latency can make users with already-slow connections suffer yet more, and how Facebook has eased the pain:
If you're in Vancouver, where a round trip to Facebook's Prineville, Oregon, data center takes 20ms, then the full handshake only adds about 40ms, which probably isn't noticeable. However, if you're in Jakarta, where a round trip takes 300ms, a full handshake can add 600ms. When combined with an already slow connection, this additional latency on every request could be very noticeable and frustrating. Thankfully, we've been able to avoid this extra latency in most cases by upgrading our infrastructure and using abbreviated handshakes.
Facebook's work on secure browsing is most certainly not done, mind you: the company says it's still working with mobile phone vendors to make it happen there.
Renfro calls HTTPS by default a "dream come true" — a goal that the company's network, security, traffic, and security infrastructure teams have been working on for years.
When Facebook first rolled out HTTPS by default, Naked Security was stuck with a heap of "Dislike" t-shirts that didn't seem appropriate anymore, so the team gave them away to readers.
Sorry, I don't know of any plans to print up "Like" t-shirts over the news that HTTPS by default is finally, for the most part, a dream come true.
But, Facebook engineers, here are two big, virtual thumbs-up for the work you've done. Let's hope it works out well for the mobile outliers, as well.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
A US teenager has been charged with distributing child pornography he allegedly hacked out of minors' cellphones with a bogus mobile text ad that installed phone-controlling malware.
Michael William Cook, 17, of Acworth, Georgia, was arrested on March 13 on eight counts of cruelty to children and one count of sexually exploiting children.
Cobb County Police Sgt. Dana Pierce told news outlets that Cook was arrested the previous Wednesday while at school.
Police accused Cook of posting photos of his victims to a child pornography website between November 2012 and January 2013.
According to 9News.com, Sgt. Pierce claimed that Cook sent text messages to victims from a company called "Maxi Focus Photography".
When victims clicked on a link in the text message, it installed malware that essentially gave Cook access to all information stored on the phones.
That includes access to victims' accounts on social network sites, such as Facebook and Twitter, as well as sexually explicit photos stored on the phones.
Cook allegedly downloaded offensive pictures and sent them to pornographic websites, Pierce said.
Police seized Cook's computer from his home in order to search for more photos and, potentially, more victims.
Police as of March 18 knew of eight victims, the youngest of whom is 14 years old.
Unfortunately, as Sgt. Pierce told a 9News.com reporter, even if police find all the victims, it will be difficult to figure out who they are:
"The problem we're going to have is, with those images, to be able to identify positively the victim."
Police are asking anyone who's corresponded with Maxi Focus Photography to call the Cobb County Police Department's Crimes Against Children Unit at (770) 801-3470.
Clicking on unexpected links, whether they come to our cellphones or our inboxes, is always risky behavior.
But so is the simple act of snapping a naked photo in digital form on a device that's connected to the internet.
When children do it, they put themselves at risk of unintended exposure, humiliation or serious bullying that could end tragically.
If the charges against Cook prove well-founded, this case is, unfortunately, just one more example that parents can point to while they try to steer their children away from such risky behavior.
Parents, please speak to your kids about the risks involved and encourage them to stay safe online with these tips.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
A court in London has heard that Sarah Ferguson, the former wife of Prince Andrew, is one of more than 100 people who have received significant payouts in the wake of the News of the World phone hacking scandal.
Sarah Ferguson, the former Duchess of York, demanded a public apology from the newspaper's publisher News Corporation, after reportedly having had her phone's voicemail intercepted since 2000 to feed the tabloid's appetite for juicy gossip.
Others who have received damages include Hugh Grant, former Doctor Who Christopher Eccleston and spoon-bender Uri Geller according to The Guardian.
The story of the British media's penchant for phone hacking dominated Britain's news headlines during 2011 and 2012, and has resulted in both criminal investigations and a government inquiry.
With such a high profile given to the issue, there's really no reason for anyone to have poorly-protected voicemail anymore. But in case you are still in doubt, here's our guide on how phone hacking worked, and how to make sure you're not a victim.
The story isn't over yet, of course, with ongoing police investigations into not just the interception of mobile phone voicemail systems but also the hacking of public figures' computers and email accounts using spyware Trojan horses.
Follow @gcluley
Sarah Ferguson image from Shutterstock.
Tags: Christopher Eccleston, Doctor Who, Hugh Grant, News Corporation, News of The World, NOTW, phone hacking, Royalty, Rupert Murdoch, Sarah Ferguson, Uri Geller
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Fujitsu and the Nagoya University will begin field trials for phone scam detection technology sometime this month, the organisations announced on Friday.
The scam detection system, which was first announced in March, claims to be able to recognise a phone scammer by combining voice intonation analysis with keyword recognition.
Japan's elderly population is frequently victimized by phone scams, with criminals often posing as acquaintances or authority figures such as police or lawyers.
When criminals pose as acquaintances, they often try to convince their targeted victims that they're in trouble and need money transferred to an account to bail them out.
The system works by detecting the changes in the voice pitch and levels that are common in the intonations of stressed-out victims, by recognising typical words used by voice scammers - "indebtedness," "compensation," "debt," or "repayment," for example - and by alerting family members or others that something's up.
Fujitsu and Nagoya University will equip landlines with detection devices in 100 Okayama Prefecture homes.
When a possible scam occurs, the alarm messages will go out to family members, the police, the bank, and Fujitsu.
On receiving the message, family members will contact the participant and ask what happened, to determine whether the call was in fact a scam.
Meanwhile, the police will immediately visit the participant's house to assess the situation.
Simultaneously; the bank will temporarily halt payment transactions from whatever account was designated by the participant for use in the trial. .
The trials will be carried out in collaboration with the Okayama Prefectural Police, the Okayama Pref. Information Communications unit of the National Police Agency's Chugoku Regional Police Bureau, and The Chugoku Bank.
The voice recognition part of the system might sound like eavesdropping, but Fujitsu promises that it's not.
Rather, the software ignores everything except the number of times a caller uses typical scam words, based on a keyword list provided by Japan's National Police Academy and on recordings of actual remittance-solicitation phone scams.
The technology is designed to recognise a condition known as "overtrust."
Overtrust occurs when victims are overwhelmed with distressing information and lose their powers of judgment.
Aa Fujitsu has described it, there are limits to human powers of perception and judgment. When overwhelmed with distressing information, some people, without knowing it, lose the capacity to objectively evaluate information provided by another party.
When overtrust occurs, victims tend to believe everything they're told - a situation that makes them vulnerable to getting fleeced by scammers.
It's not just the elderly who are susceptible, of course. The quick flash of a toy plastic police badge once caused me and a companion to hand over our wallets when we were touring Athens.
Fortunately, our scammers were overly greedy: they wanted more money than the pittance we had in our wallets and handed them back, asking to see our "hidden" money.
Our intonations and voice levels were likely steeped in stress.
Would you opt for a scam detection system? Would it feel intrusive?
I likely would, particularly were they to come up with a version I could wear around my neck when visiting foreign lands, where I emit the unmistakable aroma of clueless tourist.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Yesterday US copyright regulators opened up the floodgates for a public hearing (PDF) of proposals to change copyright law, including authorizing the cracking of tablets, DVDs, gaming consoles and mobile phones.
Every three years, the US Copyright Office mulls over requests to create temporary loopholes in the law that forbids circumventing encryption in the things we buy.
Changes to those loopholes have the potential to mean a lot to George Hotz.
Hotz is a hardware hacker known online as Geohot who owns a box full of Sony products. Per court order, they've been tucked away where he can't tinker with them.
As Wired's David Kravets writes, Sony last year dropped a PlayStation 3 jailbreaking lawsuit against Hotz in return for his promise to never again hack his game console or any other Sony product.
He told Wired that he hasn't touched the components since the settlement.
Before the settlement of the civil suit, he was busy figuring out how to play homemade games on the Sony console, in violation of a law that forbids cracking encryption in hardware or software, even for legal purposes.
This will be the fifth time the office has heard requests to modify the law—the Digital Millennium Copyright Act (PDF)—since it was passed in 1998.
The DMCA criminalizes both the technology and the act of circumvention, regardless of whether doing so actually infringes on a copyright.
Hotz is far from the only individual intent on the amendment hearings.
Proposed exemptions, previously granted but now expiring, include one for jailbreaking smartphones to run on a consumer's choice of carriers, one that would allow DVD cracking of motion pictures for the purpose of educational or documentary commentary, and another that would allow consumers to hack e-books digital rights management to enable read-aloud features for the visually impaired.
Public Knowledge, a public interest group involved in intellectual property law, is also seeking the legalization of technology that lets users crack encryptions on movies and TV shows they own on DVD.
That would allow consumers to watch legally purchased movies on whatever device they want and to make backups of sticky/scratched-up/chewed-on/quickly brutalized children's movies.
It just makes sense, given how comfortable we've gotten with copying copyrighted works we own from one medium to another, as is the case with CDs, writes Public Knowledge's Michael Weinberg.
This is sometimes called 'space shifting' or 'format shifting.' For example, this is what you do when you rip a CD in order to create .mp3 files to transfer to your iPod.
Another example of this is when you transfer a movie from a DVD onto a laptop or a tablet device, like an iPad. However, there is one important difference between a movie on DVD and a song on a CD: unlike the CD, DVDs are encrypted. That means that while copying a song from a CD is a one step process (copy the file), copying a movie from a DVD is a two-step process (decrypt the file, copy the file).
Users are authorized to decrypt the movie in order to watch it, but are not authorized to decrypt the movie in order to copy it. As a result, that extra DVD step (decrypting) is illegal under the DMCA. That makes it impossible to copy DVDs the same way you copy CDs.
The proponents and foes of proposed DMCA changes are lining up predictably: industry groups are against, consumer rights and knowledge freedom proponents are for.
Industry groups argue against the changes on the grounds that their business models will be ruined, that all hell will break lose vis-a-vis cyberattacks on cell phone networks, and that illegal game copies will flower like dandelions.
Here's how Sony attorney Jeffrey Cunard put it (PDF) in his comments to the Copyright Office:
If the exemption is granted, it is virtually certain that successful hackers, under the guise of the exemption, will create the tools that enable even novice users to make, distribute, download and play back illegal copies of games.
But as Wired's Kravets points out, the 2010 court decision to allow mobile phone users to jailbreak smartphones most certainly didn't squash Apple's profits, in spite of what the company predicted.
Rather, it fostered a "vibrant alternative to the tightly constrained and capriciously run Apple App Store," Kravets said.
He was referring to Cydia, a third-party app store for jailbroken iPhones, iPod Touches or iPads that recorded 4.5 million weekly users as of April 2011.
Cyberattacks didn't run wild. Apple didn't go broke.
If the new changes get accepted, will Call of Duty b**tard spawn careen across the PlayStations of a copyright wasteland?
Time will tell.
Stay tuned: Another hearing's taking place in Washington, DC, next month, with final amendments likely due to be adopted by year's end.
What do you think?
Follow @LisaVaas
Fishbowl image courtesy of shutterstock Money tree image courtesy of shutterstock Devices image courtesy of shutterstock
'Rogue' apps in market conceal malicious softwareDownloading can allow hackers to spy on your emailsApps 'steal' by sending texts to premium numbersAndroids at risk because apps aren't vetted before they join Android Market - unlike iPhone apps
Last updated at 3:17 PM on 18th November 2011
The success of phones running Google's Android software has meant cyber-attacks have risen 472 per cent in just three months - from cyber-spying apps to apps that add to your phone bill
Google's Android operating system is far, far ahead of Apple's iPhone - analysts Gartner said that phones running the operating system accounted for 52.5 per cent of the smartphone market this year, compared to 15.6 per cent for iOS devices.
But in computing, success always comes at a price.
Hackers target the most successful operating systems with their most virulent and hi-tech attacks, simply because there are more victims.
Malware infection rates amongst Android users are going up at their highest rate ever, putting huge pressure on Google to improve its security.
Since July the number of attacks has increased by 472 per cent with most of those coming in the past few weeks
The rise comes off the back of a report in May which said that over the previous year malware incidents had gone up 400 per cent.
The studies were carried out by IT security firm Juniper Networks which blamed Google’s poor security for allowing so many users to be affected.
It said that once installed malicious programmes could either send personal information to a third party, or send text messages to a premium rate number without the person’s knowledge, costing them money that is not recoverable.
Google is particularly vulnerable because it doesn't 'vet' apps in its marketplace, unlike Apple - making it open season for hackers.
HTC's Evo 4G handset runs Google's popular Android software: But the internet giant's anything-goes approach to its app store has led to an increase in cyber attacks on users
Google’s Android is now the most popular platform for downloading apps, beating the iPhone and the iPad combined.
The operating system accounted for 44 per cent of all app downloads in the second quarter of this year. Apple only got 31 per cent across all of its platforms.
Android has become a target for hackers and others with malicious intent partly because it is the market leader.
But according to Juniper Networks, Google must also take some of the blame because there is no review process before an app is placed in the App Store.
Adding to the problem is that Android is open source, meaning it is far easier to create and App for free and redesign their own hardware.
October showed a 110 per cent increase in malware sample collection over the previous month and a 171 per cent increase from what had been collected up to July 2011.
Not only are the numbers going up, but the malicious programmes are getting more sophisticated too.
In its reporter Juniper Networks said: ‘We have since seen exponential grow in Android malware over the last several months.
‘The months of October and November are shaping up to see the fastest growth in Android malware discovery in the history of the platform.
‘The majority of malicious applications target communications, location, or other personal identifying information.
‘Of the known Android malware samples, 55%, acts in one way or another as spyware.
‘The other major type of attack, which make up 44%, are SMS Trojans, which send SMS messages to premium rate numbers owned by the attacker in the background of a legitimate application, without the person’s knowledge.
‘Once these messages are sent, the money is not recoverable, and the owners of these premium rate numbers are generally anonymous.’
The report adds that the main suspects behind such programmes are the same people who targeted other phones but have shifted because Android is now the most popular operating system.