
Showing posts with label data security. Show all posts
Showing posts with label data security. Show all posts
Facebook, the largest social networking site, rewarded a 10-year-old boy with $10,000 for discovering a bug that allows to delete other people's Instagram comments.
Boy is the youngest person yet to receive a reward from Facebook's bug bounty program. Facebook, has paid more than $4.3 million to more than 800 researchers around the world since the program began five years ago.

Boy was identified by Finnish newspaper Iltalehti only by his first name, Jani. He informed "I wanted to see if Instagram's comment field could stand malicious code. Turns out it couldn't."
Facebook said the glitch was fixed in February and the reward was paid in March.
Jani informed he learned coding from Youtube videos and found a way to delete user comments from Instagram accounts.
He said he was thinking about a career in data security, but for now his plans include buying a new bike and a football with his reward money.
Soon, Apple users might have to face big security threat. As second time FBI has unlocked iPhone without Apple's assistance. Firstly, iPhone discovered in connection with the San Bernardino terror attacks was unlocked last month. Now, FBI has managed to crack a second device – this time, it was an iPhone 5S used by a drug dealer in New York.

Now FBI has drop the case, which involved demanding Apple’s help to open an iPhone used by Syed Rizwan Farook, a gunman in the December shooting in San Bernardino terror attack. The case had become increasingly contentious as Apple refused to help the authorities, inciting a debate about whether privacy or security was more important.
However, unlike the San Bernardino incident in which the agency had to spend over a million dollars to crack the device, the government said in a court filing that it had obtained a passcode that it used to unlock the iPhone in the Brooklyn case. Due to which FBI has withdrew its request for a court order to get Apple’s assistance in the matter.
It’s worth noting that FBI didn't specify "an individual" from which they got passcode. There are still more than 1,000 iPhones in police custody that law enforcement can’t break into US has demanded Apple’s help in at least 10 more cases to break into iOS devices.
While the FBI may indeed have been able to gain access to the data on two iPhones this year, it’s not likely that it will let Apple off the hook in the ongoing legal battle over people’s right to privacy and the company’s duty to grant backdoor access to its devices.
In a statement issued to Reuters, Justice Department spokeswoman Emily Pierce said that the cases have “never been about setting a court precedent; they are about law enforcement’s ability and need to access evidence on devices pursuant to lawful court orders and search warrants.”
Yet law enforcement’s ability to now unlock an iPhone through an alternative method raises new security threats. The development can also creates new conflicts between the government and Apple about the method used to open the device and whether that technique will be disclosed. Lawyers for Apple have previously said the company would want to know the procedure used to crack open the smartphone.
WhatsApp has a new end-to-end encryption feature feature few days ago , and it promises a more secure and private communication between users.In its official website, WhatsApp reiterated its dedication to privacy and providing a secure line of messaging among its 1 billion users worldwide ever since its release in 2010.
Available on the latest version of the app, users will no longer have to worry about their messages being pried into by hackers or the similar-minded people.
“When end-to-end encrypted, your messages, photos, videos, voice messages, documents, and calls are secured from falling into the wrong hands,” the website reads.End-to-end encryption simply means the message sent through WhatsApp can only be read by the sender and the recipient, no one in between, not even the app.
WhatsApp’s owes its new privacy measure to Open Whisper Systems, the company that developed Signal Protocol.According to the company’s website, integration of the new security protocol started last year and was completed last April 5 across all platforms of WhatsApp.
These include “chats, group chats, attachments, voice notes, and voice calls across Android, iPhone, Windows Phone, Nokia S40, Nokia S60, Blackberry, and BB10.”
WhatsApp’s encryption is turned on by default for all users
Users so far have no choice to opt out of the encryption for now (considering the number of encryption cases popping up worldwide, we are pretty sure nobody would want to opt out). As long as you have an updated version of the WhatsApp app on your supported mobile platform, you and your friends can now enjoy the perks of secure and end-to-end encrypted conversations turned on by default without any extra taps.
How do I know that encryption is switched on?
Well you simply tap on the profile or the info page(tap on the name in the header) of your contact, where you will find a section describing the status of the encryption of your chats and calls.The latest version of Whatsapp app
No matter which platform you are on, you may have noticed a slew of updates (like on iOS) that claimed “Bug fixes” coming in the past few days. Indeed, this was the WhatsApp team making a couple of tweaks, with most of it coming from the server side and some for a user’s smartphone. With that said, you and your friends will need update their respective WhatsApp apps on their respective smartphones that run different mobile operating systems (Android, iOS etc.). If your friend has not updated their app to the latest version you will be notified about the same in the info page under encryption.
The verification mess
Upon accessing the info page, you will be able to check on the status of your encryption. The point to be noted here is that it is turned on by default, meaning you do not need to go any further.
Only those who updated their app later or changed their smartphone after the time the encryption was rolled out who will need to access this area to verify (or check) whether their encryption is working or not (in all probability it will be, but more on that in our next pointer). So for the most of us, we will not need to tap on the Encryption section.
It is still a bit of a mess
Even though most will not need to access the Encryption section on the info page, users may have noticed that some of their friends even with their updated versions of the app still show that their messages are not encrypted. While the WhatsApp states that their apps may not be updated to the latest one, we think that this is a bug. We tested out the same in our office and with one iOS user connecting to an Android user, things worked fine.
WhatsApp Encryption problems
With another Android user however, it kept showing encryption turned off even though the iOS user was greeted with a chat encryption turned on message. This could either be a bug, or its just that the feature is gradually rolling out server side, so there is absolutely no indeed no need to panic.
End-to-end encryption
End-to-end encryption on WhatsApp applies to everything or every feature that is available on WhatsApp. Whether it’s calls, messages, photos, videos, files, and even voice messages, all of them will be encrypted. So technically nobody apart from you or your friend will be able to understand them. In transit from one device to another the data will only appear to be garbled text without the keys to put that text together, which resides on devices being used to communicate. Moreover, there are separate keys for each conversation or chat so WhatsApp has provided something really secure indeed.
Today’s internet-connected world brings with it several security and privacy issues. Smartphones have become our primary medium of accessing the internet. Whether at home or at work, our smartphones are especially vulnerable to these issues.
We have listed 7 ways which can help you protect your smartphone from a potential hack or virus.
We have listed 7 ways which can help you protect your smartphone from a potential hack or virus.
Get an Antivirus App
Downloading an antivirus application can secure your device, but it’s not the only safeguard you need. Usually, any files transferred from other devices, like PCs can also contain malware and viruses. While mobile antivirus can protect against such viruses, the best course of action would be to avoid moving files directly between devices or scan each file using a high-rated antivirus before sending it to your smartphone.
Downloading an antivirus application can secure your device, but it’s not the only safeguard you need. Usually, any files transferred from other devices, like PCs can also contain malware and viruses. While mobile antivirus can protect against such viruses, the best course of action would be to avoid moving files directly between devices or scan each file using a high-rated antivirus before sending it to your smartphone.
Avoid Public Wi-Fi
Connecting to public Wi-Fi networks is just like inviting intruders into your private life. It is one of the most unsecure things in the world. A huge majority of people still use it because it’s free. But the fact is that with public hotspots, even a novice hacker can eavesdrop on your private emails, passwords and account details with a little bit of tinkering.
If you do need to use the internet outside your home and have to do anything remotely sensitive, you’re better off using your mobile internet. If you don’t have access to that, then you will be better off using a VPN app in conjunction with public wifi. These VPN apps come with built-in data encryption to keep your activities secure.
Connecting to public Wi-Fi networks is just like inviting intruders into your private life. It is one of the most unsecure things in the world. A huge majority of people still use it because it’s free. But the fact is that with public hotspots, even a novice hacker can eavesdrop on your private emails, passwords and account details with a little bit of tinkering.
If you do need to use the internet outside your home and have to do anything remotely sensitive, you’re better off using your mobile internet. If you don’t have access to that, then you will be better off using a VPN app in conjunction with public wifi. These VPN apps come with built-in data encryption to keep your activities secure.
Turn Off Bluetooth Unless Required
Bluetooth is often used for short-range device communication. Whether you are transferring data or connecting to a multimedia device over Bluetooth, you are exposing your device to hackers. While using this technology at home may not pose much of a threat, but when Bluetooth is activated away from home, your device can be bluejacked (remote hijacking).
In short, your device can be accessed by hackers even if you are using the latest iterations of Bluetooth i.e. BT versions 4.1 or even 4.2. To prevent hijacking and snooping risks, Bluetooth should always be off when not in use.
Bluetooth is often used for short-range device communication. Whether you are transferring data or connecting to a multimedia device over Bluetooth, you are exposing your device to hackers. While using this technology at home may not pose much of a threat, but when Bluetooth is activated away from home, your device can be bluejacked (remote hijacking).
In short, your device can be accessed by hackers even if you are using the latest iterations of Bluetooth i.e. BT versions 4.1 or even 4.2. To prevent hijacking and snooping risks, Bluetooth should always be off when not in use.
Keep IP and MAC addresses hiddenPeople are often unaware that IP address is a gateway to their device. These are like digital addresses, since IPs can be used to locate any device. There are many softwares or apps which can be used to keep your IP address hidden over the world wide web. However, devices are exposed when connected to the same local area network.
Each connected device is recognized by its MAC Address (name). When in a public place or when using an internet connection that is being shared by others, you are potentially open to remote attacks. Anyone with your MAC address can specifically target your device if they desire.
The only way around this is to keep your digital identity hidden by using VPNs and a reliable Firewall app which can protect against any hacking attempts.
Each connected device is recognized by its MAC Address (name). When in a public place or when using an internet connection that is being shared by others, you are potentially open to remote attacks. Anyone with your MAC address can specifically target your device if they desire.
The only way around this is to keep your digital identity hidden by using VPNs and a reliable Firewall app which can protect against any hacking attempts.
Never Trust Apps From Unknown Sources
All smart devices come with their own respective app stores. Android devices usually come with Google Play Store, iOS devices come with Apple App Store, and Windows devices have their own store. Despite that, users often choose to install apps from different websites and other unknown sources.
The first thing to do is to avoid unknown sources for apps. There’s no guarantee that the app you have downloaded hasn’t been tempered with already or if it’s actually a malware app. It’s better to avoid apps from outside the official app stores. However, if it is really necessary, then download the app from its official website. Even then you should read app reviews to know what you are getting into.
Use a Numeric Password rather than a Pattern Lock
Pattern locks are very easy to bypass. If you consider privacy to be important, use pins or passwords. While patterns may be easy to unlock repeatedly, pins and passwords offer far greater security. You can double your security by using third party security apps which offer changing pins. They protect you even when you unlock your phone in front of somebody.
Another alternative would be to get your hands on a phone with a fingerprint scanner. Smartphones with such security features are difficult to fool and ordinary people will stand little chance if they attempt to pry into your personal files.
Jailbreaking or Rooting
Some of you might not understand terms such as jailbreaking or rooting. To describe these terms simply, Jailbreaking or Rooting is the process of gaining advanced access to your device’s software and hardware via an OS vulnerability. This allows you to increase your phones functionality, customizability and gives you access to a realm of developer mods.
However, it’s not all that great. With such advanced access, you risk your device’s security. Hackers can make use of any flaws in your device security and take control of your device in a manner which is not possible otherwise. Other than that, you void your warranty and risk bricking your device.
In short, it’s not something you should meddle with unless you are comfortable with the risks. Even then, you should read about your device on public forums, if you don’t understand anything better leave it or try it out on a spare device to get some hands-on practice.
Hopefully, these 7 fundamental tips will help you keep your smartphone better protected against hackers and attackers. They may sound like common-sense tips, but they can ensure that your data remains safe and secure at all times.
WhatsApp has decided to expand its encryption scheme to voice calls, as the fight between the U.S. government and Apple expands to include other major technology firms.
WhatsApp, Snapchat, Facebook and Google are now all working on their own systems to increase user privacy and keep government hands off of messaging data. As the court battle between Apple and the U.S. Department of Justice rages on, many major Silicon Valley companies -- supporters of Apple in its resistance to handing over encryption backdoors to U.S. law enforcement -- have announced their own projects to increase the privacy and encryption of data exchanged on their platforms as well.
Google is considering enforcing other products with the end-to-end encryption used for Gmail. Snapchat has said it's working on its own security measures. And Facebook's WhatsApp messenger has announced plans to encrypt voice calls and group messages this week, according to an exclusive report by The Guardian.
Lines Drawn
Virtually every technology firm has at least explored, if not implemented, encryption schemes for data exchanged on their platforms, but the wave of new data security measures can -- without question -- be seen as a response to the fight between Apple and the FBI.
As Latin Post previously reported, the FBI attempted, through a court order, to compel Apple to create a modified, less secure version of its iOS operating system. The agency wanted to use the custom version of iOS to bypass security features on the encrypted iPhone owned by one of the San Bernardino shooters.
But Apple balked at the order, saying that it amounted to compelling a company to create a so-called backdoor that could make any iPhone insecure. The company claimed this would open a veritable Pandora's Box that could undermine the privacy of all Apple users -- and likely the company itself -- if it were to ever leak from the agency's control.
Beyond that practical argument, the fight between Apple and the Department of Justice has gotten uglier and more personal recently, with prosecutors questioning Apple's motives and honesty. At the same time, Facebook, Google and other heavyweights have joined in publicly on Apple's side.
Battle Brewing
If Facebook, Google and others filing amicus briefs on behalf of their Cupertino rival wasn't enough to show the growing divide between the government and Silicon Valley, announced expansions to encryption programs certainly is.
Of particular note in the growing encryption battle is WhatsApp, one of the world's most popular free messaging services, which is owned by Facebook. The app already encrypts users' messages by default, but the company has made a major, costly move by extending encryption to voice calls. WhatsApp isn't expanding encryption as just a show of support for Apple, though.
Virtually every technology firm has at least explored, if not implemented, encryption schemes for data exchanged on their platforms, but the wave of new data security measures can -- without question -- be seen as a response to the fight between Apple and the FBI.
As Latin Post previously reported, the FBI attempted, through a court order, to compel Apple to create a modified, less secure version of its iOS operating system. The agency wanted to use the custom version of iOS to bypass security features on the encrypted iPhone owned by one of the San Bernardino shooters.
But Apple balked at the order, saying that it amounted to compelling a company to create a so-called backdoor that could make any iPhone insecure. The company claimed this would open a veritable Pandora's Box that could undermine the privacy of all Apple users -- and likely the company itself -- if it were to ever leak from the agency's control.
Beyond that practical argument, the fight between Apple and the Department of Justice has gotten uglier and more personal recently, with prosecutors questioning Apple's motives and honesty. At the same time, Facebook, Google and other heavyweights have joined in publicly on Apple's side.
Battle Brewing
If Facebook, Google and others filing amicus briefs on behalf of their Cupertino rival wasn't enough to show the growing divide between the government and Silicon Valley, announced expansions to encryption programs certainly is.
Of particular note in the growing encryption battle is WhatsApp, one of the world's most popular free messaging services, which is owned by Facebook. The app already encrypts users' messages by default, but the company has made a major, costly move by extending encryption to voice calls. WhatsApp isn't expanding encryption as just a show of support for Apple, though.
It Could Get Ugly
In fact, WhatsApp, and Facebook by extension, has been locked in its own battle with a government ordering it to decrypt user messages. That controversy has already gotten much more unpleasant than anything between Apple and the FBI.
This year, Brazil's federal government has repeatedly ordered WhatsApp to decrypt user messages that police forces say will provide key evidence against drug traffickers and other unsavory criminal elements in the country.
WhatsApp has responded to the Brazilian government much as Apple has to the FBI, saying it literally had no technical ability to provide those messages. Twice this year, Brazil has blocked WhatsApp from operating in the country as a result, though only temporarily after Brazilians protested because they depend on the app for daily communication.
Beyond temporary blocks, and beyond anything Apple has experienced with the U.S. government, Brazilian federal police actually arrested Facebook's VP for Latin America in early March for "repeated non-compliance" with government decryption orders. That, too, was only temporary. The executive's detention was reversed only hours later, after a higher court found the arrest to be "extreme and disproportionate."
But it ominously shows where the encryption battle between technology companies and governments may be headed, even more so now that Silicon Valley is beefing up its security and closing ranks with Apple.
In fact, WhatsApp, and Facebook by extension, has been locked in its own battle with a government ordering it to decrypt user messages. That controversy has already gotten much more unpleasant than anything between Apple and the FBI.
This year, Brazil's federal government has repeatedly ordered WhatsApp to decrypt user messages that police forces say will provide key evidence against drug traffickers and other unsavory criminal elements in the country.
WhatsApp has responded to the Brazilian government much as Apple has to the FBI, saying it literally had no technical ability to provide those messages. Twice this year, Brazil has blocked WhatsApp from operating in the country as a result, though only temporarily after Brazilians protested because they depend on the app for daily communication.
Beyond temporary blocks, and beyond anything Apple has experienced with the U.S. government, Brazilian federal police actually arrested Facebook's VP for Latin America in early March for "repeated non-compliance" with government decryption orders. That, too, was only temporary. The executive's detention was reversed only hours later, after a higher court found the arrest to be "extreme and disproportionate."
But it ominously shows where the encryption battle between technology companies and governments may be headed, even more so now that Silicon Valley is beefing up its security and closing ranks with Apple.
When a bank is robbed, the loot will often contain a wad of manipulated banknotes. These will explode en route and release a colorful dye, marking the money as stolen. Researchers use a similar principle to identify spyware on smartphones. Computer scientists from the Center for IT Security, Privacy and Accountability (CISPA) have now developed a matching application for the current version of the Android smartphone operating system, allowing for a more precise monitoring of malicious apps.
Android is the most widely used operating system for smartphones in the world, despite the fact that Android users are virtually blackmailed when installing new applications. Either they accept that the program will gain access to certain information, such as their personal contacts or Internet access details, or else they cannot use the app. The latest version of Android meanwhile allows users to reject some of these access requests during installation, but even so this gives a somewhat false sense of security.
"Even if an app tells me which data it would like to use, I still have no idea what it intends to do with the data," says Oliver Schranz, who completed his PhD at the Saarbrücken Graduate School of Computer Science at Saarland University. His assessment is confirmed, for instance, by a recent study conducted by the US security firm Appthority. According to their research, more than 88 percent of Android apps developed for industry use are secretly spying on user data in some way or another. At the Center for IT Security, Privacy and Accountability (CISPA), Schranz, together with Philipp von Styp-Rekowsky and Sebastian Weisgerber, developed an app that will help individual users and companies to track what is going on in suspicious apps.
The CISPA app is based on the "Taint Tracking" method, which can be compared to the colorful dye explosion triggered in a bundle of banknotes, a technique often used to track bank robbers. Hence the researchers named their app "TaintArtist." Whenever an app accesses sensitive or privacy-relevant information, the data in question is highlighted with a kind of marker. Even if the data is altered in the process, say when new calculations are performed, the marker will remain attached even to the new results. "This lets us track the flow of information from the monitored app in more precise ways," Schranz says. Whenever the data is passed on to functions, which might then send the data out from the smartphone or display other suspicious behavior as defined in a preset corpus of rules, the pertinent markers are checked. And if the CISPA app does discover data abuse, it will set off an alarm. All that users have to do is to install the tracking app and then choose which other apps they want monitored, and what exactly should be allowed or prohibited in each of them.
Until now, this kind of information flow analysis would have made system modifications necessary, in ways that are hardly feasible for laymen. To make the same service available for all users with just a few simple steps, the Saarbruecken researchers made use of a novelty in the two most recent Android versions: In the newer versions, Android no longer executes the intermediate representation of the program code directly, but translates it into executable machine language on the device first. This allows Schranz and his team to edit the code that is needed for the markers while the translation is taking place. The code of the examined app would not have to be changed, but it would work at a slightly slower pace, according to the researchers. "Given the fact that smartphones today can handle virtually all processes within milliseconds, the increases in runtime will be hardly noticeable to users," says Schranz. This is why he is convinced that the app is also useful for businesses. "If employees use their own devices at work, with our app the company can make sure that certain data never leaves these devices," says Schranz. Whether their app will be embedded into a commercial product or will be available free of charge in future, is still open.
The government's personnel agency announced Wednesday that it has hired a full-time cyber-security expert to help modernize its fleet of aged computer systems following a massive breach of US personnel records.
Clifton Triplett says his mission is twofold: To create a "new culture of security" at the Office of Personnel Management and upgrade some of the oldest information technology systems in government - quickly. He will serve as as the senior cyber and information technology adviser to the acting OPM Director Beth Cobert.
"Some of it's organizational," Triplett said in an interview before his new role was announced. "We need to create a new culture that [computer] security is part of our lives, and make sure our employees and contractors understand that." So if there is another potential intrusion by cyber thieves, "How do we react more rapidly?" Triplett said. "It's retooling to some extent, training the workforce and the organizational structure" of who does what.
Triplett, 57, who is moving to Washington from Houston, has built a reputation as a cyber-security and IT fix-it - and build-it -guy for the private sector, helping Fortune 200 companies in defense, telecommunications, oil field services, tractor, automotive and aerospace do what he's come to the government to do. A West Point graduate who attained the rank of major, he worked on computer security for almost a decade at the Defense Department.
In his new job, the stakes are particularly high. The breaches, which the Obama administration believes were carried out by the Chinese government, exposed the personal data of more than 22 million people in their employment and background investigation files. It included Social Security numbers, performance evaluations, and even the names of family members and friends who were listed as references on millions of applications for security clearances.
OPM, through a contractor, is notifying the victims that their information may have been compromised and offering them identity theft protections.
Now, the agency is focusing on how to permanently shore up its systems to prevent new attacks.
What made the systems so vulnerable is their age. "Let's go back to some of the route causes," Triplett said. "At the time these systems were created, the whole cyber threat was focused as something that might happen at defense or intelligence agencies, not a [human resources] system."
And those agencies addressed the threats much earlier, he said. But for an agency focused on human resources for federal employees, "The people who wrote the applications at the time. . . . This wasn't their forte," he said. "They wrote stuff that was for onboarding personnel records." It's the same problem a lot of companies have: "Legacy systems that were never designed with security in mind."
Since the breaches were discovered in recent months, OPM has put in place "many band-aids," Triplett said, as well as security fixes the agency says are permanent. Now the task is to install advanced security firewalls, continuous monitoring of its systems and other measures to prevent cyber-attacks.
Triplett said he is anxious to consult with the agency's inspector general, who has been critical of its efforts to upgrade its IT systems and who brought his concerns into the open at to numerous congressional hearings on the breaches.
Of course, modernizing these systems will be costly and require new funding from Congress, another battle in confronting cyber threats.
Whether spurred by work regulations or the desire for personal data security, many of us spend more time than we'd like entering PIN codes and passwords to access our devices. Biometric authentication tools, specifically fingerprint sensors, can help us reclaim those moments by providing access with the touch of a finger.
The technology isn't new, but it's only in the past few years that it's started to become standard on mobile devices. This week, we trace the ascent of the fingerprint sensor, from its early days as a peripheral to the embedded technology that's simplifying and securing our mobile lives.


