A new Trojan virus that targets Android smartphones covertly records users' phone calls. Unfortunately, this malicious software is just one part of a new trend in hacking that targets Android and Apple iOS devices.
A new Android virus records users’ phone calls without their knowledge, reports Network World.
Tuesday, August 2, 2011
New #Android #virus secretly records phone calls - #mobile #security
Friday, July 1, 2011
Thursday, June 30, 2011
TDL-4 creates 4.5 million PC ‘indestructible’ botnet #security
New malware TDL-4 has features that may make it indestructible, enslaves over 4.5 million PCs in early 2011
According to Kaspersky Lab, a new TDSS rootkit variant called TDL-4 has infected more than 4.5 million PCs worldwide in just the first three months of 2011. The security experts say that this sneaky malware is one of the most technologically sophisticated threats to date. Because of upgrades from the previous TDL-3 incarnation, this new TDL-4 has the ability to create a botnet that is practically ‘indestructible’.
Tuesday, June 28, 2011
Friday, June 24, 2011
#Data is the new platform, and #social is the intelligence — #Tech News and Analysis
Michael was on hand to present the Accenture Technology Vision 2011, a cross-industry research project that takes stock of the evolving trends in IT and how they will impact business and society as a whole. The research team looked into 400 hypotheses based on input from scientists, architects and engineers. They found fifty that held true, which they consolidated into eight trends:
- Data takes its rightful place as a platform.
- Analytics is driving a discontinuous evolution from business intelligence.
- Cloud computing will create more value higher up the stack.
- Architecture will shift from server-centric to service-centric.
- IT security will respond rapidly, progressively—and in proportion.
- Data privacy will adopt a risk-based approach.
- Social platforms will emerge as a new source of business intelligence.
- User experience is what matters.
Wednesday, April 20, 2011
Facebook Adds Two Factor Authentication for Login and Redesigns Family Safety Center
This morning Facebook announced the release of several new tools to help users stay safe while using the site. Soon, users will be able to enable two factor authentication to add an additional layer of security to logins. HTTPS browsing has been improved, and the anti-bullying social reporting tool has been rolled out more areas of the site. Facebook has also redesigned the Family Safety Center to be more visually oriented and easy to navigate.
With such a large user base and open Platform, safety issues are inevitable, so Facebook is trying provide as many preventative tools and resources as possible.
In January, Facebook began allowing users to browse the site over a secure HTTPS connection. Facebook recently noted that 9.6 million users are now browsing with HTTPS. However, third-party applications must specify a secure canvas or tab URL, otherwise users are shown a roadblock indicating they’d have to be switched to an HTTP connection to use the app. If users accepted the switch then navigated away from the app, they would still be using HTTP. Now Facebook will automatically return users to HTTPS whenever they finish using an app that doesn’t support it.
Friday, February 11, 2011
Google Rolls Out 2-Step Verification to Help Protect Your Account
Google warns that it may take up to 15 minutes to go through the setup process for this, but honestly kids, it's worth it.
The process requires two indepedent factors to authenticate your identity. In other words, when you log into your Google account, you'll need the usual username and password, but then you'll also need a second code in order to move forward - a process similar to the one that's available on most banking websites.
This second code isn't one that you'll write down (and potentially lose) on scraps of papers or one that you'll use again and again on multiple sites (decreasing its security). Rather, it is generated by Google, then sent as an SMS message to your phone or via an authentication app (available for Android, Blackberry or iPhone). This code will be generated for each log-in. And, in Google's words, "when you enter this code after correctly submitting your password we'll have a pretty good idea that the person signing in is actually you."
You'll have the option to have your computer remember this second verification step for 30 days, so you won't need to re-enter that code every time you boot up your machine.
Thursday, January 20, 2011
Self-Service: Bank of America's MyFraudProtection Allows Online Review of Suspicious Card Transactions (NetBanker)
How it works
______________________________________________________________________Step 1: Following the link, I ended up at an entirely new site, running outside online banking where I was required to re-enter my account number (screen 2), last 4 of SSN, zip, and phone number (see screen 3).
Step 2: I was then required to answer random questions pulled from the credit bureau to authenticate myself (screen 4).
Step 3: Finally, I was able to review and approve the transactions in question (screen 5). Then I was thanked and told I could use my card again (screen 6).
However, after all this, I was still not able to pay my account online and had to call after all. The rep told me that it takes between 2 and 24 hours for online banking access to become available (note 1).
______________________________________________________________
Analysis
_______________________________________________________________________All-in-all, I liked the system. However, it needs to be more integrated into online banking (see note 2). Given all the extra work required to authenticate myself, it would have been faster just to call the 800-number. If I was a normal customer, that's what I'd do next time. I hate the stress of going through the authentication process, with everything on autopay who can remember their exact payment amounts anymore?
And worse, there is a security disconnect here. I log in to my credit card account only to be told it's unavailable and that I should login to some site I've never heard (that doesn't even have a Bank of America URL, note 3) and turn over personal info. It looks more like a crude phishing ploy than something from a major bank. And as far as I can recall, there was no customer education on this process.
So, I applaud Bank of America for making transaction verification self-service. But there's still much work to be done before it replaces the phone process.
1. Main Bank of America Account Overview screen (14 Jan 2011)
Monday, January 17, 2011
Facebook Now Shares Phone Number & Address With Third-Party Apps
"Because this is sensitive information," reads the announcement, "[...]permissions must be explicitly granted to your application by the user via our standard permissions dialogs." Take a look at the example permission dialogs box, however, and tell us if you think this is enough.
As All Facebook points out, there is very little here to call attention to the fact that Facebook would now be sharing something that it previously did not share. In this particular dialog box, it's only one of two items, but many similar boxes contain more. "[Users] probably won't notice the addition of the words 'current address and mobile phone number' to the text, and likely click 'allow' without noticing that they're actually granting more access than ever before," writes Jackie Cohen for All Facebook.
Friday, January 7, 2011
HOW TO: Make Sure Your Smartphone Payments Are Secure
Better Understand Where Your Data Lives
Above and beyond everything else, common sense dictates: If there’s enough money in the bank, someone will try to steal it. 7-Eleven only carries $20 cash at night for a reason.
Your payment data should solely be stored on your phone and not in someone else’s database with tens of thousands of other credit card numbers. It’s hard to steal from someone if there’s no money in the safe. This is the only thing that truly deters hackers from going after a big score.
Keeping your payment data solely in your phone is equivalent to keeping your credit card in your wallet.
For consumers, you can usually find out where data is being stored by perusing a website carefully or reading well-researched articles and reviews. Journalists are doing a better and better job of ferreting out where your data lives, and how it is being passed around.
For app developers and payments services, keeping the data out of their servers absolutely involves more work and clever engineering. It’s hard to avoid any third parties (whether for processing or hardware), because those third parties can make things a lot easier on a startup. It’s worth it to start down this path if you haven’t already, since consumers will increasingly demand it.
Be Confident the Data’s Encrypted
The very best approaches to mobile security never send your payment information in any way that an enabled hacker in proximity could intercept your data.
It should be a priority to have industry-standard encryption. Customer smartphones talk directly to the POS. Ideally vendors and companies won’t even need this extra data in the first place.
Your Cheat Sheet
In sum, the stakes are high when the smartphone replaces the wallet. We have to rethink where the data lives and who has access to it, convenience notwithstanding. We’re all responsible for asking the hard questions to be informed consumers when we support a carrier, manufacturer, vendor network and technology.
Here’s your cheat sheet for owning your mobile transaction financial health. I urge you to ensure that your credit card information is:
- Only sent to the venue’s POS system, rather than passing through third party services.
- Only stored on your phone, where it’s safest, and not in the cloud.
- Always encrypted when it is sent to the POS system, where the transaction is taking place.
Sunday, November 28, 2010
12.5% of E-commerce Transactions Will Be Mobile By the End of 2013, Gartner Predicts by Bank Systems & Technology
By year-end 2013, location information or profile information from mobile phones will be used to validate 90 percent of mobile transactions, according to analysts at Gartner. The analysts said the rapid adoption of smartphones is forcing banks, social networks and other e-commerce providers to implement the kinds of fraud detection capabilities that have become mainstream with fixed-line computing.
Friday, November 26, 2010
63% of Consumers Prefer Credit Card Verification By Fingerprint Over PIN, Signature or Photo by Bank Systems & Technology
Responding to the question, "Which do you believe is the safest method to prove your credit card is being used by you?" the online poll found that 63 percent of more than 300 respondents preferred fingerprints as the best method for identity verification and authentication as compared to photo identification (20 percent), PIN numbers (13 percent) and handwritten signatures (six percent).
Monday, October 25, 2010
EVERYBODY PANIC! -> Firesheep Lets You Hack Twitter, Facebook Accounts Easily
Developer Eric Butler has exposed the soft underbelly of the web with his new Firefox extension, Firesheep
, which will let you essentially eavesdrop on any open Wi-Fi network and capture users’ cookies.
As Butler explains in his post, “As soon as anyone on the network visits an insecure website known to Firesheep, their name and photo will be displayed” in the window. All you have to do is double click on their name and open sesame, you will be able to log into that user’s site with their credentials.
One word: wow.
![]()
It’s not hard to comprehend the far-reaching ramifications of this tool. Anytime you’re using an open Wi-Fi connection, anyone can swiftly access some of your most private, personal information and correspondence (i.e. direct messages, Facebook mail/chat)— at the click of a button. And you will have no idea.
Saturday, October 23, 2010
Citibank First to Test Revolutionary Credit Card System, Card 2.0
Next month, Citibank will begin testing Card 2.0, a groundbreaking new credit and debit card device that securely links multiple accounts.
These futuristic cards stole the show at the DEMO startup conference last month in Silicon Valley. The cards have embedded buttons and graphic displays, yet they’re as thin and flexible as a normal credit card.
Citi’s version of the card will allow users to select between two buttons on the card at the register. One button will let the user pay with reward points; the other button lets them pay with credit. Cardholders can pay with rewards points anywhere their Citi credit card is accepted.
The cards will be called 2G (as in “second generation,” a naming convention similar to that of other mobile gadgets); each one will contain a chip and a battery with about four years of life.
Citi’s employees have been testing 2G cards since May, according to reports, and the bank plans to roll the cards out to its customer base in mid- to late 2011. Some cardholders will be selected to start using 2G cards now.
Citi’s Dividend Platinum Select MasterCard and its PremierPass Elite are both rewards-focused cards; they’ll be the first to be offered as 2G cards.
Jeff Mullen is CEO of Dynamics, Inc., the company behind the cards. He told The New York Times that Citi’s 2G cards were mere baby steps, saying, “We are just scratching the surface with what these cards can do with these initial products… We are trying to be the innovation arm of an industry that has never had one.”
Here’s a demonstration of how some other Card 2.0 products work:
Tuesday, September 28, 2010
Why the Stuxnet worm is like nothing seen before - tech - 27 September 2010 - New Scientist
Stuxnet is the first worm of its type capable of attacking critical infrastructure like power stations and electricity grids: those in the know have been expecting it for years.
On 26 September, Iran's state news agency reported that computers at its Bushehr nuclear power plant had been infected by Stuxnet.
New Scientist explains the significance of the worm.
wow.. crazy dangerous world we're heading towards..