Skip to main content

Posts

Showing posts with the label security

Microsoft Wireless Desktop 2000 protects that sensitive area between your peripherals

Microsoft's new wireless keyboard-and-mouse duo aims to thwart keystroke spies with full AES 128-bit encryption on over-the-air data -- an improvement on older wireless models that have proven to be easy pickings for hacker-types. You can pick up the Wireless Desktop 2000 now for $40, but that won't buy you protection from more common threats like Shandong phishmongers, nor will it make up for security loopholes in your other peripherals. Speaking of which, are you still using that seemingly innocent USB coffee-cup warmer? Microsoft

PSN 'Welcome Back' package is here, our long global nightmare is over

O frabjous day! Callooh! Callay! Seriously, even a few Engadget editors are chortling in joy. PSN and Qriocity service has been restored in the Americas, Europe, and Asia and to celebrate (and soothe the seething frustration of its customers) Sony has launched its "welcome back" program. To be eligible you'll have to have been a member before April 20th but, otherwise, it's relatively qualifier free. Fire up the PlayStation Store and head to the "Welcome Back" tab to claim your pair of free games (you've got five different options on the PS3 and four on the PSP). In addition everyone gets a month of PlayStation Plus gratis and there's a selection of "On Us" movie rentals available over the weekend. There are a few other freebies to placate the masses too, like 100 free items in PlayStation Home, while Current Plus and Music Unlimited Premium subscribers get a 60 and 30 day handout respectively. If you've got any burning questions yet t...

Sony begins full restoration of its PSN and Qriocity services (update: intermittent issues)

Can it be happening? Is Sony's security nightmare finally over? Seems to be. On Tuesday, Sony promised full restoration of its PlayStation Network and Qriocity services in the Americas, Europe, and Asia (excluding Japan, Hong Kong, and South Korea) by the end of the week. Now Sony is proclaiming that today is the day for full restoration with details of its "welcome back" package to be announced from each region. The PlayStation Store is already up with a "huge lineup" of new games, demos, add-ons, themes, avatars, and videos along with an updated Playstation Plus. Hey, look on the bright side Sony, even though you've lost the confidence of millions of your customers, at least now they're aware of yourQriocity service. Full press release after the break. Update : Working fine for us from London. We signed in to the PlayStation Store and even fired up Black Ops multiplayer just for kicks. Update 2 : We're now seeing error "80710D36" occ...

FaceNiff makes Facebook hacking a portable, one-tap affair (video)

Remember Firesheep? Well, the cookie snatching Firefox extension now has a more portable cousin called FaceNiff. This Android app listens in on WiFi networks (even ones encrypted with WEP, WPA, or WPA2) and lets you hop on to the accounts of anyone sharing the wireless connection with you. Right now it works with Facebook, Twitter, YouTube, and Nasza-Klasa (a Polish Facebook clone), but developer Bartosz Ponurkiewicz promises more are coming. You'll need to be rooted to run FaceNiff -- luckily, we had such a device laying around and gave the tap-to-hack app a try. Within 30 seconds it identified the Facebook account we had open on our laptop and had us posting updates from the phone. At least with Firesheep you had to sit down and open up a laptop, now you can hijack Twitter profiles as you stroll by Starbucks and it'll just look like you're sending a text message (but you wouldn't do that... would you?). One more image and a video are after the break. FaceNiff

Google admits sensitive email accounts have been hacked, some users knew months ago (update: US says no government accounts compromised)

The  Contagio  security blog posted evidence back in February of targeted attacks against government and military officials on Gmail. Today, nearly four months later, Google has finally admitted this is true: hundreds of personal accounts have been compromised by hackers it believes to be working out of Jinan, the capital of China's Shandong province. The accounts include those of "senior U.S. government officials, Chinese political activists, officials in several Asian countries (predominantly South Korea), military personnel and journalists." The hijackers' aim appears to have been to spy on their targets using Google's automatic forwarding function. But unlike the PSN fiasco, Google insists its internal systems "have not been affected." Instead it seems the hackers used a phishing scam, possibly directing users to a spoof Gmail website before requesting their credentials. Google says its own "abuse detection systems" disrupted the campaign ...

Fujitsu fingerprint / palm reader does large-scale biometric identification, won't tell fortunes

So it can't predict the future, but the latest biometric reader from Fujitsu  can  tell that you're one in a million -- quite literally. Looking something akin to the love child of Simon and a Polaroid camera, this as-of-yet unnamed device is apparently the "world's first biometric authentication technology that combines data on palm vein patterns with fingerprint data from three fingers." That's a mouthful, but Fujitsu says the combination of these two biometric authentication techniques allows for accurate identification of an individual in a pool of one million in just two seconds. What's more, it expects to up that capacity to groups of ten million by the end of 2011. For professional evildoers rocking three fingers and a palm, maybe now's a good time to start rethinking your career path.  Fujitsu

Sony Pictures hacked by Lulz Security, 1,000,000 passwords claimed stolen

Oh, Sony -- not again. We've just received numerous tips that Lulz Security has broken into SonyPictures.com, where it claims to have stolen the personal information of over 1,000,000 users -- all stored (disgracefully) in plain text format. Lulz claims the heist was performed with a simple SQL injection -- just like we saw the last time around. A portion of the group's exploit is posted online in a RAR file, which contains over 50,000 email / password combos of unfortunate users. We've downloaded this file (at our own risk, mind you) and can verify these sensitive bits are now in the wild, though it remains unclear if what's published matches reality. In addition to user information, the group has blurted out over 20,000 Sony music coupons, and the admin database (including email addresses and passwords) for BMG Belgium employees. Fresh off the heels of the PlayStation Network restoration, we're guessing the fine folks in Sony's IT department are now surviving...

Sony promises global PSN restoration by week's end, except in some parts of Asia

It looks like Sony's long, PSN nightmare is finally coming to an end -- almost. Today, the company announced that it will restore PlayStation Network and Qriocity services in the Americas, Europe andmost of Asia by week's end. The only exceptions are Hong Kong, South Korea and Japan, where users will have to await further details before regaining full access. Speaking to the  Wall Street Journal , spokeswoman Yuki Kobayashi added that Sony is in the process of finalizing an agreement to protect credit card owners in these three countries, where authorities have taken a particularly cautiousapproach to the data breach. This means that the company won't see global restoration by the end of May, as previously hoped, but Kobayashi said the plans were delayed simply because Sony needed more time to fully secure its infrastructure (sound familiar?). PlayStation Blog Wall Street Journal

Pentagon says cyber attacks are acts of war: send us a worm, get a missle in return?

Well, the Pentagon is finally fed up with hackers picking on its buddies and foreign intelligence taking shots at its computer systems, and has decided that such cyber attacks can constitute an act of war. Of course, the powers that be won't be bombing you for simply sending them some spyware, but attempts to sabotage US infrastructure (power grids, public transit, and the like) may be met with heavy artillery. It's unclear how our government will identify the origin of an attack or decide when it's serious enough to start shooting, but Uncle Sam is looking to its allies to help create a consensus answer for those questions. The retaliatory revelation is a part of the Pentagon's new cyber strategy that'll be made public in June -- so saboteurs beware, your next internet incursion might get you an ICBM in your backyard. Wall Street Journal

Skype taken to task by angry users over claimed crapware payload (update: disabled for now)

The Skype forums are a hive of panic and abuzz with accusations that either the company is bundling crapware with its VoIP app or has a serious security problem. Users are reporting that a strange, new, and difficult to uninstall program is finding its way on to their PCs called EasyBits GO. EasyBits is the company that has powered Skype's games channel since 2006, but at least until now its wares have not been standalone software. One moderator has declared EasyBits Go is  not  part of Skype and suggested customers immediately run a malware scan, but mods are volunteers and not official representatives of the company, so we're taking it with a grain of salt. Another (later) post from a forum admin simply states that Skype is looking into the issue and will release an official statement, though we have no idea when that might actually happen and we're awaiting reply to our own request for comment. It appears that a rep from EasyBits Media has taken to the forums t...

Metaphor recognition software aims to distinguish friend from foe

While it's only right that people be protected from bad poetry, this could be taking things a tad too far. Intelligence officials at the Office of Incisive Analysis (no, really) have determined that metaphors could be of vital significance to national security. By, well, incisively analyzing the way people use metaphors in everyday conversations, they believe they can reveal "underlying beliefs and world views" -- such as negative feelings towards a particular country. Now they're calling on civilian scientists and academics to help them do this automatically using pattern recognition and supercomputers. Of course there's always the risk that smart terrorists will switch to using similes instead. The Telegraph IARPA

RSA SecureID hackers may have accessed Lockheed Martin trade secrets, cafeteria menus

RSA SecureID dongles add a layer of protection to everything from office pilates class schedules to corporate email accounts, with banks, tech companies, and even U.S. defense contractors using hardware security tokens to protect their networks. Following a breach at RSA in March, however, the company urged clients to boost other security methods, such as passwords and PIN codes, theoretically protecting networks from hackers that may have gained the ability to duplicate those critical SecureIDs. Now, Lockheed Martin is claiming that its network has come under attack, prompting RSA to issue 90,000 replacement tokens to Lockheed employees. The DoD contractor isn't detailing what data hackers may have accessed, but a SecureID bypass should clearly be taken very seriously, especially when that little keychain dongle is helping to protect our national security. If last month's Sony breachdidn't already convince you to beef up your own computer security, ...

New CyanogenMod lets you rule Android app permissions with an iron fist

We've recently seen Google crack down on rogue apps and patch some server-side security issues, but let's not forget Android does have a small measure of built-in security: app permissions. But as with those pesky EULAs, many users tend to breeze through the permissions screen. And Android forces even the most attentive readers to accept or deny  all  permissions requested by an app. But the newest nightly builds of the CyanogenMod custom ROM include a clever patch allowing users to grant and revoke permissions individually -- something like the TISSA security manager we're still awaiting. Obviously playing God with permissions can crash your applications: with great power comes great responsibility. But we figure if you're running aftermarket firmware on a rooted phone, you're comfortable experimenting. See how it works in the video after the break, then hit the source link to download. Androinica CyanogenMod

Sony estimates $3.2b loss this year, $171 million cost for PSN breach

It has not been a good year for Sony, which was affected both by the massive earthquake in March and the PSN outage that spanned from April into May. There couldn't be any doubt that those things would have a drastic impact on the company's bottom-line, and it's now taking the time to give investors an idea of just how big an impact that could be -- even though the financial issues lie largely elsewhere. Sony is set to announce its full financial report for its fiscal year this Thursday and, to soften the blow, estimates have been revised steeply downward. Previously Sony predicted a ¥70 billion ($855 million) profit, but now thinks a ¥260 billion ($3.14 billion)  loss  is rather more accurate -- a ¥360 billion non-cash charge taking the wind out of ¥200 billion in operating income. The earthquake was directly blamed for a loss of ¥22 billion, but that figure could certainly grow as this estimate is only through the end of March. Additionally, Sony has p...

Sony BMG Greece hacked, company's security woes continue

It's the  security  nightmare that just won't end, and right now there's got to be plenty of Sony executives beginning to wish someone would pinch them already. After taking quite a PR and financial beating over the PSN breach, now the Greek site of Sony BMG has been hacked and the account info of thousands of users has been posted online. According to the Sophos blog  Naked Security , the attack does not appear to have been particularly sophisticated and was carried out using an automated SQL injection tool that demands more patience than skill. While the data dump reveals the usernames, real names, and email addresses of registered SonyMusic.gr customers, other fields (including passwords and telephone numbers) are either empty or contain fake data -- suggesting the hack was not entirely successful. Here's hoping Sony takes this as an opportunity to seriously baton down those security hatches. Naked Security

PlayStation 3 system update 3.61 available now, 'phased restoration' of PSN begins today (update)

Ladies and gentlemen, your PS3 may technically be able to connect to PlayStation Network now, but we're not through the woods yet -- today, Sony is issuing a mandatory System Update (v3.61) which will prepare your game machine  for that magical day when the company actually throws the switch . In the meanwhile, Sony says the update will prompt you to change your PlayStation Network password, which will likely rank among the easiest decisions that you've ever made. Update:  Sony's just announced that a "phased restoration" of PlayStation Network and Qriocity is beginning today, and that online gaming, Music Unlimited, Netflix, Hulu, Vudu and MLB.TV should rolling out right now in Europe and North America. Watch cool cat Kaz Hirai deliver the good news in a video after the break. Update 2:  Sony's got a map of the US up, and will be lighting up individual states -- check out our more coverage link to get a rough idea of when you'll be able to play ....

WebGL flaw leaves GPU exposed to hackers

Google spent a lot of time yesterday talking up WebGL, but UK security firm Context seems to think users should disable the feature because it poses a serious security threat, and the US Computer Emergency Readiness Team (CERT) is encouraging people to heed that advice. According to Context, a malicious site could pass code directly to a computer's GPU and trigger a denial of service attack or simply crash the machine. Ne'er-do-wells could also use WebGL and the Canvas element to pull image data from another domain, which could then be used as part of a more elaborate attack. Khronos, the group that organizes the standard, responded by pointing out that there is an extension available to graphics card manufacturers that can detect and protect against DoS attacks, but it did little to satisfy Context -- the firm argues that inherent flaws in the design of WebGL make it very difficult to secure. Now, we're far from experts on the intricacies of low-level hardware securit...

Dutch telco KPN using deep packet inspection to monitor mobile customers, throttle services

KPN set off some alarms in Holland last month when it announced a plan to start charging customers separate fees for using VoIP, streaming video, and sending instant messages. But, the question remained: how exactly would it keep mobile data users honest? The answer turns out to be deep packet inspection, which examines network traffic to identify what you're sending and where it's going. It's been suspected that the secret ingredient in KNP's service-throttling sauce was DPI, but it was finally confirmed in a presentation to investors recently. In fact, Mark Fisher, the director of KPN Mobile, bragged that it was the "very first" provider to be "able to identify by deep packet inspection what is actually the destination as data packages go along." Predictably, privacy and net neutrality advocates are up in arms, with some claiming it is a violation of the Dutch Data Protection Act. We just hope someone nips this in the bud soon -- we don't need...

Bee venom used to create ultra-sensitive explosives sensor

We knew that well-trained bees were capable of sniffing out dynamite and other explosives, but researchers at MIT have now come up with a slightly less militant way to use our winged friends as bomb detectors. A team of chemical engineers at the school recently developed a new, ultra-sensitive sensor that's sharp enough to detect even one molecule of TNT. Their special ingredient? Bee venom. Turns out, a bee's poison contains protein fragments called bombolitins, that react to explosive compounds. To create the detector, researchers applied these bombolitins to naturally fluorescent carbon nanotubes. Whenever an explosive molecule binds with the protein fragments, the interaction will alter the wavelength of the carbon cylinder's fluorescent light. The shift is too small for the naked eye to pick up on, but can be detected using specially designed microscopes. If it's ever developed for commercial use, the sensor could provide a more acute alternative to the spectromet...