Google Search

Showing posts with label target. Show all posts
Showing posts with label target. Show all posts

Sunday, June 8, 2014

Privacy compliance for big data systems automated: Search engine code is moving target that eludes manual audits

Web services companies, such as Facebook, Google and Microsoft, all make promises about how they will use personal information they gather. But ensuring that millions of lines of code in their systems operate in ways consistent with privacy promises is labor-intensive and difficult. A team from Carnegie Mellon University and Microsoft Research, however, has shown these compliance checks can be automated.

The researchers developed a prototype automated system that is now running on the data analytics pipeline of Bing, Microsoft's search engine. According to Saikat Guha, researcher at Microsoft, it's the first time automated privacy compliance analysis has been applied to the production code of an Internet-scale system and is a reflection of Microsoft's commitment to creating the technology necessary to further safeguard the privacy of customers.

Employing a new, lawyer-friendly language to specify privacy policies and using a data inventory to annotate existing programs, the researchers showed that a team of just five people could manage a daily compliance check on millions of lines of code written by several thousand developers.

They presented their research findings at the 35th IEEE Symposium on Security & Privacy, May 18-21, in San Jose, Calif.

"Companies in the United States have a legal obligation to declare how they use personal information they gather and it's also good business to establish a bond of trust with customers," said Anupam Datta, associate professor of computer science and electrical and computer engineering. "But these systems are constantly evolving and their scale can be daunting. The manual methods typically used for checking compliance are labor intensive, yet too often fail to catch all violations of policy."

"Tens of millions of lines of code are already in the pipeline," noted Shayak Sen, a Ph.D. student in computer science who interned at Microsoft Research India and the lead student author on the study. "And during our implementation on Bing, we found that more than 20 percent of the code was changing on a daily basis." At these large scales, automated methods offer the best hope of verifying compliance.

"One reason that gaps exist between policies set by a company's privacy team and the code written by software developers is that the two groups don't speak the same language," Datta said. Lawyers and privacy champions typically have little experience in programming and developers attempting to translate policies into code can get tripped up by ambiguities in the language of the privacy policies.

So the researchers developed a language -- Legalease -- that could be easily learned and used by privacy advocates. It employs allow-deny rules with exceptions, a structure that is found in many privacy policies and laws, such as the Health Insurance Portability and Accountability Act (HIPAA), and is expressive enough to capture the real policies of an industrial-scale system such as Bing.

In preliminary usability testing, a dozen Microsoft employees were given a one-page document explaining Legalease and spent an average of under 5 minutes studying it. They then took an average of less than 15 minutes to encode nine Bing policy clauses regarding how user information can be used. "They were able to perform this task with a high degree of accuracy, which is encouraging," Sen said.

But encoding privacy policies correctly means little if it cannot be applied to large codebases written by large teams of programmers. To solve this dilemma, the researchers leveraged Grok -- a data inventory that annotates existing programs written in languages typically employed by MapReduce-like systems, such as those used by Bing and Google -- for their backend data analytics over user data.

Grok performs this automated annotation by combining information from different sources with varying levels of confidence. For instance, automated pattern-matching to column names can be performed across an entire database, but with low confidence, while annotations by developers have high confidence, but low coverage.

Grok had been developed by Microsoft Research and deployed by Bing for the express purpose of automating privacy compliance checking the previous year, but writing policies for Grok was cumbersome.

"Legalease was the final piece of the automated privacy compliance jigsaw puzzle," Guha said. "Developed over Sen's internship and subsequent collaboration with CMU, Legalease bridged privacy teams with Grok, and through Grok, with the developers."

Datta said automating the process of compliance checks could push the industry to adopt stronger privacy protection policies.

"Sometimes, companies want to make their policies stronger, but hesitate because they are not sure they can ensure compliance in these large systems," he explained, noting that online privacy policy compliance is enforced in the United States by the Federal Trade Commission.

The research team included Sriram K. Rajamani of Microsoft Research in Bangalore, India; Janice Tsai of Microsoft Research, Redmond, and Jeannette Wing, corporate vice president of Microsoft Research and former head of CMU's Computer Science Department.

This research was supported, in part, by the Air Force Office of Scientific Research and the National Science Foundation.


View the original article here

Thursday, June 13, 2013

TDoS attacks target US emergency call centers

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Red telehone. Image from ShutterstockEmergency call centers in the US are suffering a rise in TDoS (telephony denial of service) attacks, according to an alert issued recently by the Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI).

According to the alert, reposted [PDF] on security journalist Brian Krebs's site, dozens of attacks have targeted PSAP administrative lines (not the 911 emergency line), tying up the system from receiving legitimate calls.

Air ambulance, ambulance and hospital communication lines have been targeted, in addition to various businesses and public entities, the alert goes on, including the financial sector.

The recent attacks are aimed at extortion. Here's how they work, according to DHS and the FBI:

An individual calls, claiming to represent a payday loan collections company.The caller typically has a strong accent and asks to speak with a current or former employee about an outstanding debt.The caller demands payment of $5,000 because an employee (who no longer works for the company or never did) defaulted on a loan. When the target fails to cough up the money, the attacker launches a TDoS.The organization is then inundated with a continuous stream of calls for an unspecified but lengthy period of time.Phone service is disrupted, preventing incoming and/or outgoing calls.

Call center operators. Image from ShutterstockThe agencies are speculating that these businesses and emergency services in particular are being targeted because phone lines are crucial to their operations.

The current TDoS attacks are, at this point, skipping over emergency service 911 lines.

Emergency hotlines aren't always spared in TDoS attacks, of course.

UK police last year arrested two teenage boys following a series of prank calls and TDoS attacks launched against the Anti-Terrorist Hotline.

More recently, as CSO's Antone Gonsalves notes, last month, the Louisiana State Analytical and Fusion Exchange, a center for distributing information across law enforcement offices, reported a similar extortion scheme against two public sector entities, including a 911 call center.

The current attacks against US emergency services, which last for intermittent time periods over several hours, are creating a deluge of calls large enough to force roll-over to alternate facilities, the FBI and DHS reported.

The attacks are sporadically re-starting over weeks or months.

While these attacks are clearly profit-motivated, past TDoS attacks have been, apparently, pranks, albeit on the malicious side.

In 2008, it was the Gladys Porter Zoo in Houston, Texas that suffered a barrage of calls after cryptic SMS text message spam was sent to thousands of people, saying things like:

New text message. Image from Shutterstock Call now someone is looking for you.Call now and we will settle this.Somebody talking down on you, look for themHey y is someone calln me and lookn for u n askn me where r u at n where u live heres tha # tell then to stop calln me

...and telling them to call the zoo's number. The phone-clogging continued on into May, when the zoo eventually threw in the towel and called in the FBI to help.

Dublin Zoo suffered a similar fate around the same time, with at least 5,000 people receiving SMS text message spam that prodded them to urgently ring the zoo's phone number and ask for a fictitious person (Rory Lion, Anna Conda, C Lion or G Raffe according to news reports such as this one from the Irish Independent).

Whether TDoS attacks are launched as pranks, as vendettas, or as extortion schemes, they serve to cripple their targets.

Zoos don't deserve that any more than ambulance services or the like.

The stakes, however, are potentially higher when you're talking about crippling life-saving businesses. Even if these attacks aren't targeting 911 emergency lines, they still reflect a blatant disregard for humanity.

Please, if you can help the DHS or FBI pull the plug on these malicious schemes, fill them in on the details of any attacks that have targeted your business, and encourage your peers to do the same.

The agencies have offered these recommendations for targeted organizations:

Don't pay the blackmail. Report all attacks to the FBI by logging onto the website http://www.ic3.gov/default.aspx. Use the keyword "TDoS" in your report title. Identify your organizations as a public safety answering point (PSAP) or Public Safety organization. List as many details as possible, including: Calls logs from the “collection” call and TDoS Time, date, originating phone number and traffic characteristicsCall-back number to the “collections” company or requesting organizationMethod of payment and account number where the “collection” company requests the debt to be paidAny information that you can obtain about the caller, or his/her organization Contact your telephone service provider; they may be able to assist by blocking portions of the attack.

Follow @LisaVaas
Follow @NakedSecurity

Red telephone, call center operators and text message images from Shutterstock


View the original article here

Saturday, March 30, 2013

Super Bowl scamday: survey scammers target Twitter

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Twitter

With less than 16 hours to go, internet con men are taking advantage of the largest yearly event in sport. The American Super Bowl contest has garnered extra attention this year because the coaches of the opposing teams are brothers.

As usual, internet fraudsters are capitalizing on the spectacle and luring unsuspecting NFL fans into completing a survey. The purveyors of this survey are not who you think.

The scam begins with someone being silly enough to send or retweet a tweet with the words "Super Bowl."

Super Bowl Tweet

Immediately the auto-responder bot attempts to trick the person who sent the tweet with a lure. The account doesn't appear to be that different from any corporate brand:

Scam Twitter account

If you aren't paying attention you might click on the profile and view the link. It leads to a garden variety survey scam. Many brands create special Twitter accounts and this acclimates everyday users into thinking these accounts might be legitimate.

SuperScam

Anyone who clicks on this offer is not getting a fan pass. No, they are simply having their personal details sold off to the highest criminal bidder.

While it is easy to get caught up in the excitement of a major sporting event, you should only trust information from official and trusted sources.

I don't care much for football, but I will be watching for the commercials. What I won't be doing is clicking unsolicited ads or dreaming about my "free" anything.

I might be a Grinch, but I learned a long time ago that nothing worth any real value is free.

http://twitter.com/chetwisniewski

View the original article here

Thursday, July 19, 2012

Facebook to target ads based on what mobile apps we use

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook MobileDo you use your Facebook account to log onto places like LinkedIn and Yelp from your phone?

If so, get ready to start seeing ads in your mobile device's Facebook News Feed that will be targeted based on your mobile app usage.

Here's how it will work, according to the Wall Street Journal: if you like to play Zynga Inc.'s "Words with Friends," your mobile News Feed will soon target you with ads for yet more Zynga games.

If the WSJ's sources are correct about all this, the new ads will represent a boundary-breaking move for an ad-delivery company, given that none has thusfar tracked consumers on the basis of mobile app usage.

The ads will be enabled by the Facebook Connect feature, which lets users easily log in to third-party sites, applications, mobile devices and gaming systems with their Facebook identities.

Facebook Connect

Sources familiar with Facebook's plans told the WSJ that the company is launching a new type of mobile advertising that will target consumers based on what apps they use, "pushing the limits of how companies track what people do on their phones."

But wait, there's more.

The unnamed sources told the WSJ that beyond tracking consumers' use of mobile apps, Facebook is also pondering whether to track what people do on those apps.

Facebook trackingThat move would be an even bigger game-changer. As it now stands, mobile-ad networks only target consumers based on what ads a person clicks on from his or her mobile browser.

Both Apple and Google track their users' mobile apps, but neither company tracks what people do in those apps.

One of the WSJ's sources said that Facebook will charge advertisers every time an app is installed on a user's smartphone.

That's a highly profitable prospect, the WSJ noted, for obvious reasons - i.e., a heck of a lot more consumers download apps than click on ads:

Facebook can charge significantly more for an app installation than it can for the traditional cost of every one thousand people who have viewed an ad.

Privacy advocates would far prefer that Facebook let users log in with Facebook Connect and then have a way to opt out of the new mobile ad targeting.

The WSJ quoted Justin Brookman, director of the Center for Democracy and Technology's project on consumer privacy, who noted that consumers just aren't used to having ad companies peering over their shoulders every time they use a mobile app:

"Once you're signed in, are you really expecting that Facebook is going to be watching you while you're on there?"

LinkedIn on an iPhoneOf course, with the post-IPO Facebook now under the gun to monetize features such as Facebook Connect, it's hard to imagine that the company won't track what people do in their mobile apps.

What would that look like? The possibilities are limited only by our activities while using mobile apps.

Searching for experts in a given field - say, infosec! - in LinkedIn, for example, would open up whole new worlds of targeted advertising.

One of the WSJ's sources said the new ads might be announced on July 16, unless privacy concerns convince the company to hold off on mentioning it until Chief Operating Officer Sheryl Sandberg conducts the company's first earnings call with analysts on July 26.

The new ads would then launch on July 30, the source said.

What do you think of Facebook's plans to target adverts in this way? Let us know by leaving a comment below.

Follow @LisaVaas

View the original article here

Sunday, March 4, 2012

House Panel: NASA Could Be Hackers' Next Target

Could hackers attack the International Space Station?

That’s what the House Science, Space, and Technology Subcommittee on Investigations and Oversight wants to know.

The panel will hear from NASA’s chief information officer and its inspector general at a hearing on Wednesday.

Besides basic operations like e-mail, NASA uses computer systems to control space missions like the International Space Station and the Hubble Space Telescope. And the potential for cyberattacks on those systems is growing, according to a subcommittee briefing document.

“The threat of cyberattack to agency satellite operations, mission support, and technology research is increasing in sophistication and frequency,” the document said.

In addition, NASA represents a major trove of scientific and technical knowledge that could be targeted by cyberthieves. In 2009 and 2010 the agency reported more than 5,000 incidents of malicious software or unauthorized access in its computers, according to the House panel.

“Because of NASA’s stature as an agency on the vanguard of technological progress, the tampering or corruption of scientific data from unauthorized intruders is a serious concern,” the briefing document concluded.


View the original article here

Wednesday, January 4, 2012

Hackers target emails of UK's Gordon Brown - report - Reuters India

Former British Prime Minister Gordon Brown delivers his speech during the opening session of the Global Progress Foundation Conference in Madrid October 18, 2011. REUTERS/Sergio Perez/Files

Former British Prime Minister Gordon Brown delivers his speech during the opening session of the Global Progress Foundation Conference in Madrid October 18, 2011.

Credit: Reuters/Sergio Perez/Files

LONDON | Mon Jan 2, 2012 5:25pm IST

LONDON (Reuters) - British police have found evidence that private investigators working for newspapers hacked into the email account of former Prime Minister Gordon Brown while he was finance minister, The Independent newspaper reported on Monday.

Hundreds of other people may have also had their emails intercepted, perhaps as many as were caught up in the phone hacking scandal at News International's now defunct News of the World tabloid, the paper said.

Detectives were looking at evidence from about 20 computers seized from private investigators, the newspaper reported.

The team at London's Scotland Yard police headquarters were looking into the possibility that several newspaper titles commissioned private detectives to access computers, The Independent said, citing an unnamed source.

The Brown emails under scrutiny dated from the time he was Britain's finance minister before he became prime minister in 2007. Former Labour advisor and lobbyist Derek Draper was also targeted, The Independent said.

The Metropolitan police would not comment on the report.

"We are not prepared to give a running commentary on this investigation," a spokesman said.

News International, the British newspaper arm of Rupert Murdoch's News Corporation (NWSA.O), also declined to comment.

The group closed the News of the World in July 2011 after evidence emerged that investigators working for the title hacked into the mobile phone voicemails of celebrities, politicians and even murder victims.

It is the only newspaper that has admitted phone hacking, although some journalists and celebrities have said the practice was widespread in the tabloid press.

News International's titles were not singled out in the Independent's report on email hacking.

(Reporting by Paul Sandle; Editing by Andrew Heavens)


View the original article here

Tuesday, January 3, 2012

Hackers target emails of UK's Gordon Brown: report

LONDON (Reuters) - British police have found evidence that private investigators working for newspapers hacked into the email account of former Prime Minister Gordon Brown while he was finance minister, The Independent newspaper reported on Monday.

Hundreds of other people may have also had their emails intercepted, perhaps as many as were caught up in the phone hacking scandal at News International's now defunct News of the World tabloid, the paper said.

Detectives were looking at evidence from about 20 computers seized from private investigators, the newspaper reported.

The team at London's Scotland Yard police headquarters were looking into the possibility that several newspaper titles commissioned private detectives to access computers, The Independent said, citing an unnamed source.

The Brown emails under scrutiny dated from the time he was Britain's finance minister before he became prime minister in 2007. Former Labour advisor and lobbyist Derek Draper was also targeted, The Independent said.

The Metropolitan police would not comment on the report.

"We are not prepared to give a running commentary on this investigation," a spokesman said.

News International, the British newspaper arm of Rupert Murdoch's News Corporation, also declined to comment.

The group closed the News of the World in July 2011 after evidence emerged that investigators working for the title hacked into the mobile phone voicemails of celebrities, politicians and even murder victims.

It is the only newspaper that has admitted phone hacking, although some journalists and celebrities have said the practice was widespread in the tabloid press.

News International's titles were not singled out in the Independent's report on email hacking.

(Reporting by Paul Sandle; Editing by Andrew Heavens)


View the original article here

Monday, January 2, 2012

'PrivateX' hackers target more gov't websites

MANILA, Philippines - Hackers who defaced the website of Vice President Jejomar Binay and at least 5 other sites have warned that they will attack more government websites.
Posts made in the past few days on the Facebook page of the PrivateX hackers' group mentioned several other government agencies.
"Expect us," said a December 29 message, with an attached article from the Department of of Social Welfare and Development.

The hacker group's founder, in an email to abs-cbnNEWS.com, said one of their members identified as "Blackrain" will answer questions about the hacking incidents soon.

The group's latest post on Monday made fun of the Department of Health by creating a page with an ASCII art showing a large nuclear explosion.

"Anonymous #OccupyPhilippines ProjectX PrivateX Philker," the message below the image said. "We are Anonymous, We are legion, We don't forgive, We don't forget."

Other government websites mentioned by the group in the page are those belonging to the Optical Media Board, the Philippine National Radiation Institute, the Senate Electoral Tribunal, the Commission on Appointments, the Philippine Racing Commission, and sites owned by the local governments of Libon, Camiguin, and Manaoag.

Some of the websites remained defaced Monday afternoon.

OVP admits website hacked

Meanwhile, the Office of the Vice President's (OVP) website has been fixed.

Joselito Salgado, head of the OVP's media affairs division, said the website has hacked by the PrivateX group around 4 p.m. on Sunday and was down for more than 15 hours.

He said the OVP's website is being hosted by the Advanced Science and Techology Institute (ASTI), an agency under the Department of Science and Technology (DOST).

"We have been informed that ASTI is looking into the incident and will put in place the needed safeguards," Salgado said.

"The OVP website provides information on the programs, projects and services of the Office of the Vice President. It also provides the public the opportunity to bring their concerns to the attention of VP Binay. Unfortunately, the hacking incident has deprived the public, particularly our Overseas Filipino Workers with a channel to communicate with the Vice President," he said.

PrivateX, in a statement, said it does not seek to taunt the OVP website's administrator "but to point out that transferring to a paid hosting doesn't mean that you are secured."

"We did not delete any file on the server but we created an index.html and redirected the index.php to index.html (Deface page)," they added.


View the original article here

Hackers target emails of Gordon Brown - report

LONDON (Reuters) - Police have found evidence that private investigators working for newspapers hacked into the email account of former Prime Minister Gordon Brown while he was finance minister, The Independent newspaper reported on Monday.

Hundreds of other people may have also had their emails intercepted, perhaps as many as were caught up in the phone hacking scandal at News International's now defunct News of the World tabloid, the paper said.

Detectives were looking at evidence from about 20 computers seized from private investigators, the newspaper reported.

The team at London's Scotland Yard police headquarters were looking into the possibility that several newspaper titles commissioned private detectives to access computers, The Independent said, citing an unnamed source.

The Brown emails under scrutiny dated from the time he was finance minister before he became prime minister in 2007. Former Labour advisor and lobbyist Derek Draper was also targeted, The Independent said.

The Metropolitan police would not comment on the report.

"We are not prepared to give a running commentary on this investigation," a spokesman said.

News International, the British newspaper arm of Rupert Murdoch's News Corporation, also declined to comment.

The group closed the News of the World in July 2011 after evidence emerged that investigators working for the title hacked into the mobile phone voicemails of celebrities, politicians and even murder victims.

It is the only newspaper that has admitted phone hacking, although some journalists and celebrities have said the practice was widespread in the tabloid press.

News International's titles were not singled out in the Independent's report on email hacking.

(Reporting by Paul Sandle; Editing by Andrew Heavens)


View the original article here

Tuesday, August 23, 2011

AntiSec hackers target Vanguard Defense exec - CNET

By: Jonathan E. Skillings August 19, 2011 8:58 AM PDT Print E-mail Share 4 comments

The hacktivist group AntiSec says it has released a gigabyte of private documents from Vanguard Defense Industries, including e-mails from an executive connected with a cybersecurity organization it has targeted previously.


In a post on Pastebin this morning, AntiSec said the e-mails belong to Richard Garcia, a senior vice president at Vanguard who is also a board member at InfraGard, an FBI program that teams up public and private cybersecurity efforts. In June, AntiSec affiliate LulzSec hacked the Web site of InfraGard Atlanta, releasing passwords and other sensitive information.


Describing InfraGard as "a sinister alliance," AntiSec gloated about this latest breach:



It is our pleasure to make a mockery of InfraGard for the third time, once again dumping their internal meeting notes, membership rosters, and other private business matters.


Within the booty you may find lots of shiny things as we did not have time to follow up on all the data. Safe to say, that despite previous disclosure in the media...Mr. Garcia did not bother to change any of his many many passwords found in his spool at the time of this release. So here's also a shoutout to all Lulz Lizards still following our mischiefs: Have fun withthe data of Mr. Garcia, former Assistant Director to the L.A. FBI office who now sells his cybersecurity "skills" to the Military and Government for brazen amounts of money.


Vanguard, based in Conroe, Texas, makes an unmanned aerial vehicle called the ShadowHawk, used in commercial as well as law enforcement and military settings, and also provides security consulting services.


AntiSec said the new breach was perpetrated "not only to cause embarrassment and disruption to VanguardDefense Industries, but to send a strong message to the hacker community" that it will continue to target military contractors, law enforcement agencies, and "white hat sellouts," a reference to hackers who work with police and other establishment groups.


Earlier this month, AntiSec issued a "Shooting Sheriffs Saturday Release" of what it said was 10GB of data stolen from U.S. law enforcement agencies, including private e-mails, passwords, data from informants, Social Security numbers, and credit card information.


Update 10:24 a.m.: In a phone conversation with CNET, Vanguard CEO Michael Buscher said the company had determined that there was no breach of its servers or Web site, but rather that it was Garcia's personal Gmail account that was accessed.


Nothing in the the material that was released by AntiSec involved sensitive data from Vanguard, or proprietary or customer information, Buscher said. The approximately 1GB of information, he said, centered primarily on Garcia's role at InfraGard.



Related stories:
? Keeping up with the hackers (chart)
? AntiSec hackers post stolen police data as revenge for arrests
? Hackers target Sony, Nintendo and FBI partner Web site
? Exclusive: CEO says hackers tried to extort data, money

Share Print E-mail Jonathan E. Skillings E-mail Jonathan E. Skillings E-mail Jonathan E. Skillings

If you have a question or comment for Jonathan E. Skillings, you can submit it here. However, because our editors and writers receive hundreds of requests, we cannot tell you when you may receive a response.


Submit your question or comment here: 0 of 1500 characters

Jonathan Skillings is managing editor of CNET News, based in the Boston bureau. He's been with CNET since 2000, after a decade in tech journalism at the IDG News Service, PC Week, and an AS/400 magazine. He's also been a soldier and a schoolteacher. E-mail Jon.

Topics: Privacy and data protection, Vulnerabilities and attacks Tags: AntiSec, FBI, InfraGard, hackers

Tuesday, July 12, 2011

NUTS: Hackers Target Government, Apple and Samsung Continue Battle - Forbes (blog)

Jul. 10 2011 - 6:14 am | 1,096 views | 0 recommendations |

Hackers continued their wave of attacks, targeting several politicians including President Obama, while Apple attempts to put a stop to Samsung’s sales in the U.S.

News Under the Sun is a weekly column rounding up all the events on in the mobile industry. Want the news but don’t want it every day? Subscribe to our weekly Facebook or Twitter page.

Hackers Shift to Political Figures

Hacker group “Script Kiddies” gained access to the Twitter account of Fox News and posted a fake message about the assassination of President Obama. White House officials quickly assured the nation of the president’s safety.

Meanwhile, hacktivist group Anonymous targeted Orlando Mayor Buddy Dyer by posting photos of a Guy Fawkes mask hanging outside his home, as well as a photoshopped image of two headless police officers. The threats accompanied attacks on the city’s police websites.

Anonymous is proclaiming its disapproval with Orlando’s new policy against feeding the homeless without a license.

Besides political targets, AntiSec, a mix of Anonymous and former LulzSec hackers, broke into an Apple server and collected 26 administrative usernames and passwords. The group claims to have gained entry through a security flaw in third-party software.

The recent spate of attacks prompted European officials to form the International Cyber-Security Protection Alliance, or ICSPA, in an effort to protect organizations against future attacks.

On a positive note, Sony re-launched its PlayStation Network and Qriocity music services in Japan after an 11-week blackout. Nearly 100 million accounts were compromised due to the attacks in April.

Apple Versus Samsung: The Saga Continues

Apple filed a complaint with the International Trade Commission, asking for a ban on Samsung products in the U.S., claiming four of Samsung’s devices — the Galaxy S 4G, Infuse 4G, Droid Charge and Galaxy Tab 10.1 tablet — violated its iPhone and iPad patents.

In response, Samsung denied the allegations and said it will continue to sell its products until it is legally prevented to do so. The ITC filing hints may offer a faster settlement between the warring companies, since it takes less time to decide than the courts.

Apple’s App Store Breaks Records, Other Break Security

Apple’s App Store platform is expected to surge with apps and e-books at a rate of 39 percent over the next three years, reaching an estimated $13 billion in revenue by 2013.

After debuting in 2008, users have downloaded 15 billion apps. There are now more than 200 million iOS devices worldwide, each with an average of 75 apps.

In total, more than 425,000 apps are currently available in the App Store.

However, the Apple’s popularity has made it a target among hackers. The company acknowledged a security flaw in iOS, allowing attackers to infect users’ devices with malicious software and give them administrative privileges.

Hackers may gain access to information like passwords, online banking data, e-mail and contact information, as well as a person’s camera or calls.

In the courtroom, a judge rejected Apple’s request to stop Amazon from using the “AppStore” name. Apple claims customers may confuse Amazon’s “AppStore” with Apple’s “App Store.”

Amazon is allowed to use its AppStore term up until a trial date for October 2012.

In future products, Apple filed two patents related to augmented reality and transparent touch screens. The AR patent gives Apple a way to populate live photos and video feeds from iPads and iPhones with digital information, allowing users to easily identify unknown objects and places.

The transparent screen patent allows Apple to overlay real-time images with digital data, hinting at improved iPad features in the future.

Cloud Competition Gets Crowded

Swedish-based Spotify is joining the fray in the U.S. The music-streaming service had planned to launch months ago, but licensing negotiations with major record labels delayed its debut.

Meanwhile, Amazon offered unlimited Cloud Drive and Player storage, allowing users to host as much music as they wish for a $20 annual fee.

Consumers unwilling to pay can still host up to 5-gigabytes of music files, as well as upload unlimited files purchased from Amazon. They also receive a free 20-gigabyte storage locker for photos and video.

Verizon Caps Data, Introduces New Phones

Verizon ended its unlimited data plans, ushering in tiered plans starting at $30 a month for 2-gigabytes of data.

Customers already with unlimited contracts can keep their plans for the duration of the contract, but new customers must sign up for capped data plans.

The carrier said about 95 percent of its customers consume less than 2-gigabytes per month, suggesting users will pay the same under the limited plans.

Meanwhile, Verizon plans to sell the Droid Bionic on August 4. The phone packs a 1-gigahertz dual-core chip, 512-megabytes of RAM, a 4.3-inch screen and 8-megapixel camera.

It also unveiled the Motorola Droid 3, which will debut later this summer for $200 with a two-year contract. The device will run on Android 2.3, along with a dual-core processor, 4-inch display, including an 8-megapixel camera capable of capturing 1080p video.

Google+ Sees Familiar Face, NFC Goes Social

Google last week launched its Google+ social network, amid positive reviews. And its most followed member so far is none other than Facebook CEO Mark Zuckerberg.

So far, Zuckerberg amassed over 21,000 followers, beating even Google co-founders Larry Page and Sergey Brin, both with less than 15,000 followers.

Google also launched a Google+ app for Android, which includes a mobile payment component. The app is still in beta, but Nexus device owners can now scan near-field communication, or NFC, tags and post information as a status update on their Google+ accounts

The features blend the world of mobile payments with location check-in sites like Foursquare and Facebook.

The Internet giant is in the courtroom as well. Transcenic filed a complaint against Google, Microsoft and AOL’s MapQuest, claiming Google’s street view-perspective technology, used in Google Maps, violates its patent for collecting and manipulating panoramic imagery.

The Louisiana company is seeking unspecified damages in Federal Delaware District Court.

HTC Sees Profits Rise

HTC posted record sales due to the popularity of its Android phones and a surge in demand from Asia. The company shipped about 11 million units in the April-June period, more than double the total from a year ago.

HTC is pushing ahead by buying chip-designer S3 Graphics for $300 million. The deal gives HTC a portfolio of 235 patents, which it can use to protect itself in the increasingly-heated patent infringement arena, as well as provide it with technology to improve its smartphone lineup.

Nortel Sale Under Investigation

Canadian regulators are investigating the winning $4.5 billion bid for bankrupt telecom Nortel.

Canadian Industry Minister Christian Paradis said the results of the auction, including its 6,000 patents, are subject to the Investment Canada Act, which require the country to gauge whether any foreign investment or acquisition more than $312 million benefits or hurts the country.

A group of major companies including Apple, Microsoft, Sony, Ericsson and Research in Motion won the auction for patents relating to 4G, Wi-Fi, search engines and other telecom areas.

Facebook, Skype Team Up for Video Calling

Facebook announced a partnership with Skype to bring video chat to its 750 million users. The move beefs up Facebook’s offerings before a showdown with Google+. To use the service, people need to download a plug-in for their browsers.

ISPs Cracking Down on Piracy

Internet service providers partnered with entrainment companies to curb online piracy. ISPs agreed to a six-strikes warning program to reprimand those suspected of downloading copyrighted music and movies from sites like BitTorrent.

The Copyright Alert System will monitor users of illegal file-sharing services. If users are caught sharing copyrighted files, the alert system will send users’ ISP a notice to dole out punishment. ISPs can then issue up to six warnings before reducing users’ Internet speeds or suspending services until illegal file-sharing stops.

Government Deals with Online Sexual Material, Cell Phones in Cars

Judge Ralph Beistline struck down an Alaska law that aims to hold adults criminally liable for distributing sexually explicit material to minors over the Internet. Beistline sided with the group of plaintiffs that filed a lawsuit last August, saying such a law violates the First Amendment.

The judge agreed, saying the Internet lacks a reliable mechanism for verifying the age of Internet users.

Meanwhile, the Governors Highway Safety Association, or GHSA, concluded cell phone use while driving increases the chance of crashing. The group studied over 350 scientific papers released since 2000, and found a link between texting and higher risks while driving, but it remains inconclusive on how to prevent phone-related car crashes.

But, the GHSA did agree with a ban on cell phone use for teenaged drivers, who are the highest risk for crashes.

Meanwhile, New Jersey ruled tracking one’s spouse by GPS legal and not an invasion of privacy.

The case originated when Kenneth Villanova’s wife suspected he was cheating but couldn’t confirm this as the private investigator she hired was unable to follow the suspected husband. She then placed a GPS unit in the glove compartment of the vehicle they owned together, eventually tracing him to another woman’s driveway.

Nokia Firesale, Store Closure

Nokia announced it will cut prices on its current line of smartphones, including the popular N8, C7 and E6 models, by 15 percent in Europe, as it readies the release of its Windows phones next year. Nokia claims these cuts are normal and part of on-going business.

Meanwhile, the company is shutting down its Vertu luxury mobile phone stores in Japan. The company said it will continue to do business with Japanese craftsmen on products sold in other markers.

Microsoft Targets Samsung

Microsoft is seeking $15 for each Android device Samsung sells because of alleged patent infringement. If Microsoft demands payment, Samsung may be looking at a shelling out $45 million to Microsoft for past Galaxy S 2 sales alone.

Samsung aims to negotiate a lower fee of $10 per device, in exchange for a deeper partnership with Microsoft to create smartphones using the Windows Phone platform.

It’s a Sad World for RIM

RIM fell to third place behind Apple and Google. The once-strong company now controls just 24 percent of the market, behind Apple’s 26 and Google’s 38, according to ComScore.

Last week, the company agreed to conduct an independent study to determine the effectiveness of a leadership change, much to the chagrin of investment firm of Glass Lewis & Co.

The investor had wanted to conduct a vote over whether to split up RIM’s executive roles at this year’s shareholders meeting. The firm says a change, not a study, is needed to fix the company.

Sprint May Finally Get iPhone

Sprint may add the iPhone to its lineup before Christmas, according to Citadel Securities. If so, the company may attract customers since it is the last U.S. carrier to offer unlimited data plans.

The iPhone is expected to boost Sprint’s fortunes, especially if it struggles to survive in a post-AT&T and T-Mobile merger.

Cell Phones May Not Cause Cancer After All

A group of experts from the U.S., U.K. and Sweden found no convincing evidence linking cell phone use to cancer. The group also added there is little evidence to suggest radio signals trigger tumors. But committee cannot definitively say there is no connection at all between the two.

Meanwhile, a group of researchers are using smartphones to diagnose cataracts.

A team of MIT scientists developed the Catra System, which allows a user to look through an eyepiece that slides onto a smartphone or other mobile devices like tablets. The patient sees lines on the screen and pushes a button when the lines start to cloud. If there are enough lines that look cloudy, Catra diagnoses the cataract and recommends treatment.

Samsung Profits Dip, Sends Nexus S to Space

Samsung profits took a significant hit, even after the success of its Galaxy tablets. The company’s ongoing dispute with Apple casts doubt on the company’s future, especially if Samsung is forced to pay Apple for patent infringement.

Meanwhile, the company’s Nexus S phone joined rival Apple’s iPhone in space aboard the Atlantis space shuttle. The device is set to conduct several experiments with its computing power and camera.

Obama Holds Twitter Town Hall Meeting

President Barack Obama received nearly 170,000 questions and comments at his Twitter town hall meeting. The event was moderated by Twitter co-founder and chairman Jack Dorsey.

More than a quarter of the questions dealt with jobs, while 10 percent were about education. This was the first-ever online, live presidential town hall meeting.

Ebay Strengthens PayPal Service

Ebay purchased mobile payment provider Zong for $240 million. Ebay plans to connect the service’s 3.2 billion users and 250 wireless carriers with PayPal.

Shoppers use Zong to pay for items with their mobile phones by entering their mobile phone numbers, which Zong then verifies the transaction and charges the customer’s cell phone bill.

Japan Strikes… Metal

Japanese researchers reportedly found gadolinium, lutetium, terbium and dysprosium in the mud beneath the Pacific Ocean near Hawaii. These are the same metals needed to make iPhones, iPads and other gadgets.

Experts believe the find could total billions of tons of materials, which could be more than 1,000 times the amount found in land sources locally mostly in China.

News Under the Sun is a weekly column rounding up all the events on in the mobile industry. Want the news but don’t want it every day? Subscribe to our weekly Facebook or Twitter page.

This post originally appeared at Mobiledia.


View the original article here

Monday, July 11, 2011

Hackers to Target Apple Devices?

{"s" : "aapl,amzn,c,ek,emc,erts,goog,lmt,nok,sne","k" : "a00,a50,b00,b60,c10,g00,h00,l10,p20,t10,v00","o" : "","j" : ""} Zacks Equity Research, On Friday July 8, 2011, 4:55 pm EDT

German authorities have identified potential security flaws in Apple Inc.’s (NasdaqGS: AAPL - News) devices such as iPhone, iPad and iPod that are feared to be vulnerable to cyber attacks. According to reports from the Associated Press, German security agencies cautioned that the security hole may be exploited by hackers to steal confidential data from the devices.

Germany's Federal Office for Information Security is of the opinion that hackers can infect Apple devices by sending malicious emails in the form of Portable Document Formats (PDF). Thereafter, once the unaware users are deceived to open the PDFs, the hackers will get accessibility to the administrative rights of the devices.

In such a case, hackers have the access to steal or use confidential information such as passwords, online-banking data, calendars, e-mails and intercept telephone conversations and the location of the user.

Meanwhile, Apple commented that the security issue will be resolved as it is in the process of plugging the loophole in its security by an upcoming software upgrade, which will be available for its iPhone, iPad and iPod touch devices.

Incidentally, this German agency had found another flaw in Apple software last year. That time, Apple had successfully fixed the issue with a software patch.

So far, however, it has been noticed that these attacks on smartphones and other handheld Internet gadgets has been rare. Hackers have been much more focused on PCs. However, we believe that with the growing use of smartphones and other Internet gadgets, as well as the growing ecommerce on these devices, hacking attacks will no doubt increase.

In the present day scenario, users seem to put down every bit of information in the smartphones, ranging from bank account numbers, social security numbers, as well as passwords to access other varied and important data.

We therefore believe that smartphone makers should be more careful while securing the devices as its vulnerability will have a profound impact on its user.

Looking Back at High Profile Hacking Incidents

Cyber security has emerged as the most discussed topic in the technology market over the last few months. As corporations, government agencies, banks and video game companies have been plagued by cyber attacks, online security has become a major concern for all.

However, the last few months have been particularly embarrassing for cyber security providers such as EMC Corp. (NYSE: EMC - News), after some high-profile hacking was reported at Sony Corp. (NYSE: SNE - News), EMC’s own RSA division, defense contractor Lockheed Martin Corp. (NYSE: LMT - News), banker Citigroup Inc. (NYSE: C - News), search company Google Inc. (NasdaqGS: GOOG - News), video game companies Electronic Arts Inc. (NasdaqGS: ERTS - News) and Sega Sammy Holdings Inc.

Moreover, government agencies like the IMF and CIA were also targeted. The Oak Ridge National Laboratory, which works closely with the U.S. Energy Department, also fell prey to cyber attack. In February 2011, France’s finance ministry suffered a cyber attack, aimed at stealing files on the G-20 summit in Paris.

Amid the growing number of cyber attacks, corporations and companies both in the private and public sector are looking for stricter and more stringent cyber security measures to plug the loopholes in the system.

For detailed report, read: Security -- Top Priority in 2011

Recommendation

Apple is a great company with a loyal customer base, international expansion, competitive pricing strategy and a solid cash position. We remain positive on Apple’s long-term growth. However, increasing competition in most of its major product segments, possible delays in product launch, higher operating expenses and increasing legal complexities compel us to maintain our Neutral rating over the long term (6-12 months).

Of late, Apple has been in a spot with all the legal battles pertaining to patent rights with HTC, Eastman Kodak Co. (NYSE: EK - News), Samsung and Amazon.com Inc. (NasdaqGS: AMZN - News). Moreover, Apple has settled the patent dispute with Nokia Corp. (NYSE: NOK - News), but will have to make a one-time payment to the latter and is to pay regular royalties going forward. Financial details were not divulged.

More importantly, Apple has received unfavorable verdicts in a couple of cases at the International Trade Commission (ITC). As ITC has the authority to block import of products that infringe U.S patents, the lawsuits could cause a dent in Apple’s very sizeable cash balance. It may have to pay a hefty fine or a recurring license fee, which will hurt its profitability going forward.

Currently, Apple has a Zacks #3 Rank, which implies a Hold rating in the near term.

APPLE INC (AAPL): Read the Full Research Report

ELECTRONIC ARTS INC (ERTS): Read the Full Research Report

GOOGLE INC CL A (GOOG): Read the Full Research Report

AMAZON.COM INC (AMZN): Read the Full Research Report

NOKIA (NOK): Read the Full Research Report

E M C CORP MASS (EMC): Read the Full Research Report

EASTMAN KODAK CO (EK): Read the Full Research Report

CITIGROUP INC (C): Read the Full Research Report

LOCKHEED MARTIN CORP (LMT): Read the Full Research Report

Zacks Investment Research


View the original article here

NUTS: Hackers Target Government, Apple and Samsung Continue Battle

Hackers continued their wave of attacks, targeting several politicians including President Obama, while Apple attempts to put a stop to Samsung's sales in the U.S.

News Under the Sun is a weekly column rounding up all the events on in the mobile industry. Want the news but don't want it every day? Subscribe to our weekly Facebook or Twitter page.

Hackers Shift to Political Figures

Hacker group "Script Kiddies" gained access to the Twitter account of Fox News and posted a fake message about the assassination of President Obama. White House officials quickly assured the nation of the president's safety.

Meanwhile, hacktivist group Anonymous targeted Orlando Mayor Buddy Dyer by posting photos of a Guy Fawkes mask hanging outside his home, as well as a photoshopped image of two headless police officers. The threats accompanied attacks on the city's police websites.

Anonymous is proclaiming its disapproval with Orlando's new policy against feeding the homeless without a license.

Besides political targets, AntiSec, a mix of Anonymous and former LulzSec hackers, broke into an Apple server and collected 26 administrative usernames and passwords. The group claims to have gained entry through a security flaw in third-party software.

The recent spate of attacks prompted European officials to form the International Cyber-Security Protection Alliance, or ICSPA, in an effort to protect organizations against future attacks.

On a positive note, Sony re-launched its PlayStation Network and Qriocity music services in Japan after an 11-week blackout. Nearly 100 million accounts were compromised due to the attacks in April.

Apple Versus Samsung: The Saga Continues

Apple filed a complaint with the International Trade Commission, asking for a ban on Samsung products in the U.S., claiming four of Samsung's devices -- the Galaxy S 4G, Infuse 4G, Droid Charge and Galaxy Tab 10.1 tablet -- violated its iPhone and iPad patents.

In response, Samsung denied the allegations and said it will continue to sell its products until it is legally prevented to do so. The ITC filing hints may offer a faster settlement between the warring companies, since it takes less time to decide than the courts.

Apple's App Store Breaks Records, Other Break Security

Apple's App Store platform is expected to surge with apps and e-books at a rate of 39 percent over the next three years, reaching an estimated $13 billion in revenue by 2013.

After debuting in 2008, users have downloaded 15 billion apps. There are now more than 200 million iOS devices worldwide, each with an average of 75 apps.

In total, more than 425,000 apps are currently available in the App Store.

However, the Apple's popularity has made it a target among hackers. The company acknowledged a security flaw in iOS, allowing attackers to infect users' devices with malicious software and give them administrative privileges.

Hackers may gain access to information like passwords, online banking data, e-mail and contact information, as well as a person's camera or calls.

In the courtroom, a judge rejected Apple's request to stop Amazon from using the "AppStore" name. Apple claims customers may confuse Amazon's "AppStore" with Apple's "App Store."

Amazon is allowed to use its AppStore term up until a trial date for October 2012.

In future products, Apple filed two patents related to augmented reality and transparent touch screens. The AR patent gives Apple a way to populate live photos and video feeds from iPads and iPhones with digital information, allowing users to easily identify unknown objects and places.

The transparent screen patent allows Apple to overlay real-time images with digital data, hinting at improved iPad features in the future.

Cloud Competition Gets Crowded

Swedish-based Spotify is joining the fray in the U.S. The music-streaming service had planned to launch months ago, but licensing negotiations with major record labels delayed its debut.

Meanwhile, Amazon offered unlimited Cloud Drive and Player storage, allowing users to host as much music as they wish for a $20 annual fee.

Consumers unwilling to pay can still host up to 5-gigabytes of music files, as well as upload unlimited files purchased from Amazon. They also receive a free 20-gigabyte storage locker for photos and video.

Verizon Caps Data, Introduces New Phones

Verizon ended its unlimited data plans, ushering in tiered plans starting at $30 a month for 2-gigabytes of data.

Customers already with unlimited contracts can keep their plans for the duration of the contract, but new customers must sign up for capped data plans.

The carrier said about 95 percent of its customers consume less than 2-gigabytes per month, suggesting users will pay the same under the limited plans.

Meanwhile, Verizon plans to sell the Droid Bionic on August 4. The phone packs a 1-gigahertz dual-core chip, 512-megabytes of RAM, a 4.3-inch screen and 8-megapixel camera.

It also unveiled the Motorola Droid 3, which will debut later this summer for $200 with a two-year contract. The device will run on Android 2.3, along with a dual-core processor, 4-inch display, including an 8-megapixel camera capable of capturing 1080p video.

Google+ Sees Familiar Face, NFC Goes Social

Google last week launched its Google+ social network, amid positive reviews. And its most followed member so far is none other than Facebook CEO Mark Zuckerberg.

So far, Zuckerberg amassed over 21,000 followers, beating even Google co-founders Larry Page and Sergey Brin, both with less than 15,000 followers.

Google also launched a Google+ app for Android, which includes a mobile payment component. The app is still in beta, but Nexus device owners can now scan near-field communication, or NFC, tags and post information as a status update on their Google+ accounts

The features blend the world of mobile payments with location check-in sites like Foursquare and Facebook.

The Internet giant is in the courtroom as well. Transcenic filed a complaint against Google, Microsoft and AOL's MapQuest, claiming Google's street view-perspective technology, used in Google Maps, violates its patent for collecting and manipulating panoramic imagery.

The Louisiana company is seeking unspecified damages in Federal Delaware District Court.

HTC Sees Profits Rise

HTC posted record sales due to the popularity of its Android phones and a surge in demand from Asia. The company shipped about 11 million units in the April-June period, more than double the total from a year ago.

HTC is pushing ahead by buying chip-designer S3 Graphics for $300 million. The deal gives HTC a portfolio of 235 patents, which it can use to protect itself in the increasingly-heated patent infringement arena, as well as provide it with technology to improve its smartphone lineup.

Nortel Sale Under Investigation

Canadian regulators are investigating the winning $4.5 billion bid for bankrupt telecom Nortel.

Canadian Industry Minister Christian Paradis said the results of the auction, including its 6,000 patents, are subject to the Investment Canada Act, which require the country to gauge whether any foreign investment or acquisition more than $312 million benefits or hurts the country.

A group of major companies including Apple, Microsoft, Sony, Ericsson and Research in Motion won the auction for patents relating to 4G, Wi-Fi, search engines and other telecom areas.

Facebook, Skype Team Up for Video Calling

Facebook announced a partnership with Skype to bring video chat to its 750 million users. The move beefs up Facebook's offerings before a showdown with Google+. To use the service, people need to download a plug-in for their browsers.

ISPs Cracking Down on Piracy

Internet service providers partnered with entrainment companies to curb online piracy. ISPs agreed to a six-strikes warning program to reprimand those suspected of downloading copyrighted music and movies from sites like BitTorrent.

The Copyright Alert System will monitor users of illegal file-sharing services. If users are caught sharing copyrighted files, the alert system will send users' ISP a notice to dole out punishment. ISPs can then issue up to six warnings before reducing users' Internet speeds or suspending services until illegal file-sharing stops.

Government Deals with Online Sexual Material, Cell Phones in Cars

Judge Ralph Beistline struck down an Alaska law that aims to hold adults criminally liable for distributing sexually explicit material to minors over the Internet. Beistline sided with the group of plaintiffs that filed a lawsuit last August, saying such a law violates the First Amendment.

The judge agreed, saying the Internet lacks a reliable mechanism for verifying the age of Internet users.

Meanwhile, the Governors Highway Safety Association, or GHSA, concluded cell phone use while driving increases the chance of crashing. The group studied over 350 scientific papers released since 2000, and found a link between texting and higher risks while driving, but it remains inconclusive on how to prevent phone-related car crashes.

But, the GHSA did agree with a ban on cell phone use for teenaged drivers, who are the highest risk for crashes.

Meanwhile, New Jersey ruled tracking one's spouse by GPS legal and not an invasion of privacy.

The case originated when Kenneth Villanova's wife suspected he was cheating but couldn't confirm this as the private investigator she hired was unable to follow the suspected husband. She then placed a GPS unit in the glove compartment of the vehicle they owned together, eventually tracing him to another woman's driveway.

Nokia Firesale, Store Closure

Nokia announced it will cut prices on its current line of smartphones, including the popular N8, C7 and E6 models, by 15 percent in Europe, as it readies the release of its Windows phones next year. Nokia claims these cuts are normal and part of on-going business.

Meanwhile, the company is shutting down its Vertu luxury mobile phone stores in Japan. The company said it will continue to do business with Japanese craftsmen on products sold in other markers.

Microsoft Targets Samsung

Microsoft is seeking $15 for each Android device Samsung sells because of alleged patent infringement. If Microsoft demands payment, Samsung may be looking at a shelling out $45 million to Microsoft for past Galaxy S 2 sales alone.

Samsung aims to negotiate a lower fee of $10 per device, in exchange for a deeper partnership with Microsoft to create smartphones using the Windows Phone platform.

It's a Sad World for RIM

RIM fell to third place behind Apple and Google. The once-strong company now controls just 24 percent of the market, behind Apple's 26 and Google's 38, according to ComScore.

Last week, the company agreed to conduct an independent study to determine the effectiveness of a leadership change, much to the chagrin of investment firm of Glass Lewis & Co.

The investor had wanted to conduct a vote over whether to split up RIM's executive roles at this year's shareholders meeting. The firm says a change, not a study, is needed to fix the company.

Sprint May Finally Get iPhone

Sprint may add the iPhone to its lineup before Christmas, according to Citadel Securities. If so, the company may attract customers since it is the last U.S. carrier to offer unlimited data plans.

The iPhone is expected to boost Sprint's fortunes, especially if it struggles to survive in a post-AT&T and T-Mobile merger.

Cell Phones May Not Cause Cancer After All

A group of experts from the U.S., U.K. and Sweden found no convincing evidence linking cell phone use to cancer. The group also added there is little evidence to suggest radio signals trigger tumors. But committee cannot definitively say there is no connection at all between the two.

Meanwhile, a group of researchers are using smartphones to diagnose cataracts.

A team of MIT scientists developed the Catra System, which allows a user to look through an eyepiece that slides onto a smartphone or other mobile devices like tablets. The patient sees lines on the screen and pushes a button when the lines start to cloud. If there are enough lines that look cloudy, Catra diagnoses the cataract and recommends treatment.

Samsung Profits Dip, Sends Nexus S to Space

Samsung profits took a significant hit, even after the success of its Galaxy tablets. The company's ongoing dispute with Apple casts doubt on the company's future, especially if Samsung is forced to pay Apple for patent infringement.

Meanwhile, the company's Nexus S phone joined rival Apple's iPhone in space aboard the Atlantis space shuttle. The device is set to conduct several experiments with its computing power and camera.

Obama Holds Twitter Town Hall Meeting

President Barack Obama received nearly 170,000 questions and comments at his Twitter town hall meeting. The event was moderated by Twitter co-founder and chairman Jack Dorsey.

More than a quarter of the questions dealt with jobs, while 10 percent were about education. This was the first-ever online, live presidential town hall meeting.

Ebay Strengthens PayPal Service

Ebay purchased mobile payment provider Zong for $240 million. Ebay plans to connect the service's 3.2 billion users and 250 wireless carriers with PayPal.

Shoppers use Zong to pay for items with their mobile phones by entering their mobile phone numbers, which Zong then verifies the transaction and charges the customer's cell phone bill.

Japan Strikes... Metal

Japanese researchers reportedly found gadolinium, lutetium, terbium and dysprosium in the mud beneath the Pacific Ocean near Hawaii. These are the same metals needed to make iPhones, iPads and other gadgets.

Experts believe the find could total billions of tons of materials, which could be more than 1,000 times the amount found in land sources locally mostly in China.

News Under the Sun is a weekly column rounding up all the events on in the mobile industry. Want the news but don't want it every day? Subscribe to our weekly Facebook or Twitter page.

This post originally appeared at Mobiledia.

Also Read

View the original article here

Sunday, July 10, 2011

Hackers Select a New Target: Other Hackers

SOMINI SENGUPTA and NICK BILTON, On Tuesday July 5, 2011, 9:58 am EDT

The hackers, calling themselves the A-Team, assembled a trove of private information and put it online for all to see: names, aliases, addresses, phone numbers, even details about family members and girlfriends.

But their targets were not corporate executives, government officials or clueless bank customers. They were other hackers.

And in trying to unmask the identities of the members of a group known as Lulz Security, the A-Team was aiming to take them down a peg — and, indirectly, to help law enforcement officials lock them up.

The core members of Lulz Security “lack the skill to do anything more than go after the low-hanging fruit,” the A-Team sneered in its posting last month.

In recent weeks, attacks on companies like Sony and government sites like senate.gov have raised concerns about increasingly organized and brazen hackers. On Monday, a Twitter account for Fox News was hijacked.

But much of the hacking scene is a fractious free-for-all, with rival groups and lone wolves engaged in tit-for-tat attacks on each other, often on political or ideological grounds but sometimes for no better reason than to outwit — or out-hack — the other guy.

The members of Lulz Security, or LulzSec, have been at the center of the sniping lately. The group won global attention through attacks on the C.I.A., Sony, the Arizona state police and other organizations, putting at risk the personal information of tens of thousands of people in the process. Even as they attacked, the LulzSec members craftily concealed their own identities, all the while articulating an ever-changing menu of grievances, from government corruption to consumer rights.

LulzSec’s provocative attacks and flamboyant style made it a tempting target. Other hackers, equally adept at maintaining their anonymity, have been seeking to penetrate the online aliases of the group’s members.

Late last month, LulzSec announced that it was disbanding, and that its members would continue their activities under other banners. But the F.B.I. and other agencies are continuing their pursuit, aided by information unearthed by other hackers. In fact, the Lulz Security members face the real possibility that if they are caught, it will be their fellow hackers who led the authorities to their doorsteps.

“This unfortunately represents one of few ways law enforcement gets good inroads into this community,” said Bill Woodcock, research director at the Packet Clearing House, a nonprofit group in Berkeley, Calif., that tracks Internet traffic.

In hacker parlance, to be unmasked is to be dox’d, as in documented. And by hacker logic, to be dox’d is to be put out of business. An online alias is an essential weapon: it conceals a person’s name and whereabouts, while allowing the creation of an alternate identity.

Indeed, the handbook for new recruits to Anonymous, the global hacker collective from which Lulz Security sprang earlier this year, contains tips on safeguarding one’s identity — from how to steer clear of Web sites that track online activity to masking one’s Internet provider.

One of the tools it suggests is Tor, a network of virtual tunnels originally developed by the United States Naval Research Laboratory to protect online government communications. “In our world,” the handbook concludes, “a good defense is the best offense.”

Despite the detailed profiling by the A-Team and other hacker groups including Team Poison and Web Ninjas, no professed Lulz Security member has admitted to being dox’d, and some have merrily denied it. But the campaign seems to have had some effect.

The A-Team’s supposed outing of seven of Lulz Security’s members coincided with the group’s announcement that it was disbanding. And a spokesman for the group, using the alias Topiary, bid a public farewell in typically impish language: “Sailing off — watch your backs and follow the north wind, brazen sailors of the ’verse.”

The A-Team posting about LulzSec included mundane personal details. The sister of one purported LulzSec member, it said, was a bartender in a bowling alley in a small British town. Another member was described as “very ugly.” A third, the group railed, cannot hack at all: “He doesn’t actually do anything except give interviews.”

Part of the posting, complete with misspellings, went to the heart of the hackers’ paradox: “If your anonymous no one can find you. No one can hurt you, so your invincible,” it said. “The problem with this idealogy, is it’s on the internet. The internet by definition is not anonymous. Computers have to have attribution. If you trace something back far enough you can find its origins.”

Lulz Security was not above outing one of its own. A member known as m_nerva leaked some of its chat room discussions to the media. In retaliation the group posted what it said was m_nerva’s personal information, including an address in Hamilton, Ohio.

Last week the F.B.I. raided a home in Hamilton but made no arrests, according to local media reports. An F.B.I. spokeswoman, Jenny Shearer, would not comment on what she said was a continuing investigation.

In an interview with the BBC Web site, a spokesman for LulzSec who called himself Whirlpool said of the group’s opponents: “They keep trying to bring us down, we mock them, they get flustered and make snide comments, we laugh.”

Meanwhile the Web Ninjas, who publish a blog called LulzSec Exposed, declared their intentions this way: “We have tried our best doxing LulzSec and keep doing it until we see them behind bars.”

Topiary’s fellows do not seem to be in a mood to venture off into the north wind forever. Since announcing its dissolution, LulzSec has melted into a broader movement called AntiSec, which potentially has thousands of hackers on its side, including those associated with Anonymous. Hackers have continued to torment the Arizona police because of their role in a state crackdown on illegal immigrants, leaking officers’ personal e-mail last week.

Security companies and government agencies have a long history of relying on current or former hackers in the fight against computer crimes. One new wrinkle is the way that attacks on government targets have given rise to a small but loud faction of patriotic, presumably American hackers who are fighting back on their own, said Gabriella Coleman, an assistant professor at New York University who is researching a book on Anonymous. The fights have also become more public and spectacular, in part because of platforms like Twitter.

“Warring becomes an art form itself,” Ms. Coleman said. “There is that game quality to it. They’re claiming they can’t be found. It’s a huge trophy if you can.”


View the original article here

Friday, July 8, 2011

Hackers Select a New Target: Other Hackers - New York Times

The hackers, calling themselves the A-Team, assembled a trove of private information and put it online for all to see: names, aliases, addresses, phone numbers, even details about family members and girlfriends.

But their targets were not corporate executives, government officials or clueless bank customers. They were other hackers.

And in trying to unmask the identities of the members of a group known as Lulz Security, the A-Team was aiming to take them down a peg — and, indirectly, to help law enforcement officials lock them up.

The core members of Lulz Security “lack the skill to do anything more than go after the low-hanging fruit,” the A-Team sneered in its posting last month.

In recent weeks, attacks on companies like Sony and government sites like senate.gov have raised concerns about increasingly organized and brazen hackers. On Monday, a Twitter account for Fox News was hijacked.

But much of the hacking scene is a fractious free-for-all, with rival groups and lone wolves engaged in tit-for-tat attacks on each other, often on political or ideological grounds but sometimes for no better reason than to outwit — or out-hack — the other guy.

The members of Lulz Security, or LulzSec, have been at the center of the sniping lately. The group won global attention through attacks on the C.I.A., Sony, the Arizona state police and other organizations, putting at risk the personal information of tens of thousands of people in the process. Even as they attacked, the LulzSec members craftily concealed their own identities, all the while articulating an ever-changing menu of grievances, from government corruption to consumer rights.

LulzSec’s provocative attacks and flamboyant style made it a tempting target. Other hackers, equally adept at maintaining their anonymity, have been seeking to penetrate the online aliases of the group’s members.

Late last month, LulzSec announced that it was disbanding, and that its members would continue their activities under other banners. But the F.B.I. and other agencies are continuing their pursuit, aided by information unearthed by other hackers. In fact, the Lulz Security members face the real possibility that if they are caught, it will be their fellow hackers who led the authorities to their doorsteps.

“This unfortunately represents one of few ways law enforcement gets good inroads into this community,” said Bill Woodcock, research director at the Packet Clearing House, a nonprofit group in Berkeley, Calif., that tracks Internet traffic.

In hacker parlance, to be unmasked is to be dox’d, as in documented. And by hacker logic, to be dox’d is to be put out of business. An online alias is an essential weapon: it conceals a person’s name and whereabouts, while allowing the creation of an alternate identity.

Indeed, the handbook for new recruits to Anonymous, the global hacker collective from which Lulz Security sprang earlier this year, contains tips on safeguarding one’s identity — from how to steer clear of Web sites that track online activity to masking one’s Internet provider.

One of the tools it suggests is Tor, a network of virtual tunnels originally developed by the United States Naval Research Laboratory to protect online government communications. “In our world,” the handbook concludes, “a good defense is the best offense.”

Despite the detailed profiling by the A-Team and other hacker groups including Team Poison and Web Ninjas, no professed Lulz Security member has admitted to being dox’d, and some have merrily denied it. But the campaign seems to have had some effect.

The A-Team’s supposed outing of seven of Lulz Security’s members coincided with the group’s announcement that it was disbanding. And a spokesman for the group, using the alias Topiary, bid a public farewell in typically impish language: “Sailing off — watch your backs and follow the north wind, brazen sailors of the ’verse.”

The A-Team posting about LulzSec included mundane personal details. The sister of one purported LulzSec member, it said, was a bartender in a bowling alley in a small British town. Another member was described as “very ugly.” A third, the group railed, cannot hack at all: “He doesn’t actually do anything except give interviews.”


View the original article here

Wednesday, July 6, 2011

Amy Winehouse hackers to target Justin Bieber - The Guardian

Justin Bieber and Lil B Justin Bieber, left and Lil B. Photograph: Isaac Brekken/Getty

Hackers using Lil B as their mascot have vandalised the websites of Amy Winehouse and singer Lauren Pritchard, claiming they also have data on Justin Bieber, Klaxons and, er, "[a] hundred thousand hundred trillion" Lady Gaga fans. Calling themselves SwagSec (Swagger Security), the group has waded into a crowded war of hack and double-hack, declaring their rivalry with both Anonymous and so-called "anti-sec" groups such as LulzSec.

Whereas other high-profile hackers have made their names breaking into servers operated by Bank of America, AT&T or Sony, SwagSec seem more musically minded. The name itself is a pop term: "swag" is Lil B's most notorious catchphrase, since taken up by everyone from Tyler, the Creator to Cher Lloyd. SwagSec claim to be a group of gay, black hackers, flying in the face of white hacker stereotype, and inverting the scene's typical juvenile homophobia. "We are here to take back the internet from the white devil," they wrote on Twitter. "We startin wid Amy Winehouse."

In their posting at AmyWinehouse.com, archived by the Daily Swarm , SwagSec warned other hackers to stop attacking Universal Music, Winehouse's label. "UMusic is our territory," they wrote. "We've had dis box on lock 4 yearz son." Last week, Anonymous's Operation AntiSec dumped hundreds of files linked to Universal and Viacom, including usernames and passwords. Soul singer Lauren Pritchard, whose website was also defaced, is another Universal artist. Both artist's websites have more or less since been restored.

California rapper Lil B doesn't seem directly linked to the group, but his face is plastered all over their work – and the timing of his supporters' hacks can't hurt. Just last week, Lil B released his new album, I'm Gay. Although he has been hailed for the way his album title challenges the hip-hop status quo, it turns out to be more of a publicity stunt than a rap Stonewall. "I'm not a gay man," he told Complex. The album's lyrics also make no mention of homosexuality. In fact, perhaps Lil B's most revolutionary move was to make the album available for free .

Ultimately, SwagSec's hackings may have less to do with wreaking havoc and more to do with catching the attention of one of their favourite musicians. "Shoutout 2 Lil B," they wrote on Amy Winehouse's website. "We fuckin luv u. If u mention us in a new trak brotha, we give u our bitchez. Promise."


View the original article here

Hackers target Apple server

stshank: Facebook blocked a tool for moving friends' contact info to Gmail/Google+, but a possible workaround is in the works. http://cnet.co/kv1W01


View the original article here

Tuesday, July 5, 2011

Hackers Select a New Target: Other Hackers

The hackers, calling themselves the A-Team, assembled a trove of private information and put it online for all to see: names, aliases, addresses, phone numbers, even details about family members and girlfriends.

But their targets were not corporate executives, government officials or clueless bank customers. They were other hackers.

And in trying to unmask the identities of the members of a group known as Lulz Security, the A-Team was aiming to take them down a peg -- and, indirectly, to help law enforcement officials lock them up.

The core members of Lulz Security "lack the skill to do anything more than go after the low-hanging fruit," the A-Team sneered in its posting last month.

In recent weeks, attacks on companies like Sony and government sites like senate.gov have raised concerns about increasingly organized and brazen hackers. On Monday, a Twitter account for Fox News was hijacked.

But much of the hacking scene is a fractious free-for-all, with rival groups and lone wolves engaged in tit-for-tat attacks on each other, often on political or ideological grounds but sometimes for no better reason than to outwit -- or out-hack -- the other guy.

The members of Lulz Security, or LulzSec, have been at the center of the sniping lately. The group won global attention through attacks on the C.I.A., Sony, the Arizona state police and other organizations, putting at risk the personal information of tens of thousands of people in the process. Even as they attacked, the LulzSec members craftily concealed their own identities, all the while articulating an ever-changing menu of grievances, from government corruption to consumer rights.

LulzSec's provocative attacks and flamboyant style made it a tempting target. Other hackers, equally adept at maintaining their anonymity, have been seeking to penetrate the online aliases of the group's members.

Late last month, LulzSec announced that it was disbanding, and that its members would continue their activities under other banners. But the F.B.I. and other agencies are continuing their pursuit, aided by information unearthed by other hackers. In fact, the Lulz Security members face the real possibility that if they are caught, it will be their fellow hackers who led the authorities to their doorsteps.

"This unfortunately represents one of few ways law enforcement gets good inroads into this community," said Bill Woodcock, research director at the Packet Clearing House, a nonprofit group in Berkeley, Calif., that tracks Internet traffic.

In hacker parlance, to be unmasked is to be dox'd, as in documented. And by hacker logic, to be dox'd is to be put out of business. An online alias is an essential weapon: it conceals a person's name and whereabouts, while allowing the creation of an alternate identity.

Indeed, the handbook for new recruits to Anonymous, the global hacker collective from which Lulz Security sprang earlier this year, contains tips on safeguarding one's identity -- from how to steer clear of Web sites that track online activity to masking one's Internet provider.

One of the tools it suggests is Tor, a network of virtual tunnels originally developed by the United States Naval Research Laboratory to protect online government communications. "In our world," the handbook concludes, "a good defense is the best offense."

Despite the detailed profiling by the A-Team and other hacker groups including Team Poison and Web Ninjas, no professed Lulz Security member has admitted to being dox'd, and some have merrily denied it. But the campaign seems to have had some effect.

The A-Team's supposed outing of seven of Lulz Security's members coincided with the group's announcement that it was disbanding. And a spokesman for the group, using the alias Topiary, bid a public farewell in typically impish language: "Sailing off -- watch your backs and follow the north wind, brazen sailors of the 'verse."

The A-Team posting about LulzSec included mundane personal details. The sister of one purported LulzSec member, it said, was a bartender in a bowling alley in a small British town. Another member was described as "very ugly." A third, the group railed, cannot hack at all: "He doesn't actually do anything except give interviews."

Part of the posting, complete with misspellings, went to the heart of the hackers' paradox: "If your anonymous no one can find you. No one can hurt you, so your invincible," it said. "The problem with this idealogy, is it's on the internet. The internet by definition is not anonymous. Computers have to have attribution. If you trace something back far enough you can find its origins."

Lulz Security was not above outing one of its own. A member known as m_nerva leaked some of its chat room discussions to the media. In retaliation the group posted what it said was m_nerva's personal information, including an address in Hamilton, Ohio.

Last week the F.B.I. raided a home in Hamilton but made no arrests, according to local media reports. An F.B.I. spokeswoman, Jenny Shearer, would not comment on what she said was a continuing investigation.

In an interview with the BBC Web site, a spokesman for LulzSec who called himself Whirlpool said of the group's opponents: "They keep trying to bring us down, we mock them, they get flustered and make snide comments, we laugh."

Meanwhile the Web Ninjas, who publish a blog called LulzSec Exposed, declared their intentions this way: "We have tried our best doxing LulzSec and keep doing it until we see them behind bars."

Topiary's fellows do not seem to be in a mood to venture off into the north wind forever. Since announcing its dissolution, LulzSec has melted into a broader movement called AntiSec, which potentially has thousands of hackers on its side, including those associated with Anonymous. Hackers have continued to torment the Arizona police because of their role in a state crackdown on illegal immigrants, leaking officers' personal e-mail last week.

Security companies and government agencies have a long history of relying on current or former hackers in the fight against computer crimes. One new wrinkle is the way that attacks on government targets have given rise to a small but loud faction of patriotic, presumably American hackers who are fighting back on their own, said Gabriella Coleman, an assistant professor at New York University who is researching a book on Anonymous. The fights have also become more public and spectacular, in part because of platforms like Twitter.

"Warring becomes an art form itself," Ms. Coleman said. "There is that game quality to it. They're claiming they can't be found. It's a huge trophy if you can."


First published on July 5, 2011 at 12:00 am

View the original article here