Articles by "Security"

A major security event has 20 keynote speakers, and only one is a woman. Experts say recruiting at events that exclude women keeps the field male-dominated.

Cisco Chairman and CEO John Chambers delivers a keynote address during the RSA Conference in 2009. This year, 19 out of 20 keynote speakers will be men
At a major cybersecurity event in April, the only woman out of 20 keynote speakers is a social commentator.

Her name is Monica Lewinsky, and she advocates to prevent cyberbullying.

The other 19 keynote speakers and moderators, who will present during the four-day RSA Conference in San Francisco, are men. Of those men, all but one are cybersecurity experts.

The lineup has frustrated people in the cybersecurity field, with Facebook's chief security officer, Alex Stamos, taking to Twitter to criticize the conference organizers for leaving women out of RSA's top speaking roles. He even suggested he'd host an alternate conference nearby with a host of women experts, at which his role would be to hand out popcorn.
Lewinsky said on Twitter that she found out about the all-male lineup this week, and told USA Today in a statement that she's asked organizers to do better. "I'm disappointed by this oversight but RSA has about six weeks until the conference, so I'm optimistic that the matter will be rectified by then," she said.

RSA Conference vice president and curator Sandra Toms said in an interview that the lineup is not finalized and more women could join the list of keynote speakers before the event begins. US Homeland Security Secretary Kirstjen Nielsen has been formally invited, for example, but isn't yet confirmed to speak. Other invitations to women keynote speakers are still pending, Toms said.

"We strive each year for a diverse speaking panel," Toms said.

The dustup reflects a persistent problem in tech that happens to be even worse in cybersecurity. Women work in just 11 percent of jobs in this field (PDF). That's bad because security companies say they can't hire skilled people fast enough. Alienating women with the potential to excel at cybersecurity could make us all less safe, especially as hackers continually hammer computer networks to steal our sensitive information.

It also comes as tech conferences continue to take heat for gender bias. In January, organizers of CES, a giant consumer electronics trade show in Las Vegas, took criticism for excluding women from their slate of speakers, too. And in 2016 at Defcon, a major hacking conference in Las Vegas, women complained of a hostile atmosphere that left them feeling unwelcome.

Who's responsible?

But who exactly is to blame for the lack of women at tech conferences and in cybersecurity jobs around the world? Well, nobody is raising a hand to take sole responsibility for that one.

Women cybersecurity leaders: RSA Conference can't find you
Pau Barrena/Getty Images
 Toms said the lack of diversity overall in cybersecurity makes it hard to find women for the conference. "We acknowledge that there is a lack of women in cybersecurity and it's part of a larger lack of diversity in the larger tech space."

So, it's the fault of the tech industry at large that RSA organizers couldn't fill any of those roles with women cybersecurity and tech experts. While that could sound like a dodge, it's not not true -- just look at the companies sponsoring the event.

After all, that's where most of the keynote speakers come from, including companies like Microsoft, Symantec and McAfee, plus RSA Security, a cybersecurity company owned by Dell that sponsors the conference but isn't the same entity that organizes the event. The SANS Institute is an educational sponsor, which Toms said was an "in-kind" arrangement in which the organization offered training presentations in exchange for space on the sponsor list.

Most of the speakers come from senior leadership positions in those sponsor companies. That senior leadership is in every instance a group that's mostly men. Here's how it breaks down at each company that's sponsoring the event and sending a keynote speaker:
  • Juniper Networks: Zero women.
    No women in an 18-person leadership team.
  • SANS Institute: Zero women.
    No women in a six-person faculty.
  • Symantec: 11 percent women.
    Two women in a 18-person leadership team.
  • RSA Security: 13 percent women.
    One woman in an eight-person leadership team.
  • Akamai: 13 percent women.
    Two women in a 15-person leadership team.
  • Microsoft: 19 percent women.
    Three women in a 16-person leadership team.
  • Cisco: 22 percent women.
    14 women in a 64-person leadership team.
  • IBM: 29 percent women.
    Six women in a 21-person leadership team.
  • McAfee: 30 percent women.
    Three women in a 10-person leadership team.
Neither IBM, McAfee nor the SANS Institute responded to requests for comment. Akamai, Juniper, Microsoft, and Symantec didn't provide a comment for this story. Cisco didn't provide a comment on the lack of women keynote speakers at the conference, but a spokeswoman said the company recognizes the shortage of women in the cybersecurity industry.

RSA Security (the company, not the conference) responded with the following statement from a spokeswoman. "RSA recognizes the need for diversity in the technology industry in general, which includes cybersecurity," the spokeswoman said. "We believe in creating a global business that harnesses the power of the best and brightest talent, regardless of their gender, background, religion, nationalities and race."

The conference organizers don't seem to be limited to keynote speakers from sponsor companies, though. Three keynote speakers don't appear to have direct ties to sponsor companies. Two of them are cryptography experts. Whitfield Diffie helped lay the groundwork for what would become known as the RSA public-key system, a tool that lets users send a coded message that only the intended recipient can read. Moxie Marlinspike is the creator of Open Whisper Systems, the company behind the encrypted chat app Signal.

The recruiting cycle

There could be a direct connection between how welcoming a conference is to women and who gets recruited to work at a cybersecurity company. In a report from last week on women in cybersecurity, business analysts at Forrester said companies currently "focus on recruiting from industry events that have been proven unwelcoming to women."

That creates a vicious cycle in which companies hire fewer females. That, in turn, could cause conferences to have a harder time finding women experts to speak at the next event.

Toms said the audience at RSA is typically 20 percent women, which is higher than the general population of women cybersecurity workers. What's more, its two events for young professionals and students attract even higher rates of women.

Cisco spokeswoman Robyn Blum said the company is a sponsor of the Women in Cybersecurity event taking place in March and is hosting an event next week focused on bringing young women into tech careers.

In a blog post about improving diversity in the cybersecurity workforce, Cisco's chief security and trust officer, John Stewart, said women still face too many obstacles in the field. "We have a long way to go for talent, skills and character to overcome gender as a qualification," he said, "especially in leadership and executive roles."

source:CNet News

Despite Uber debacle, HackerOne’s CEO argues why every company should work with hackers
In November, Uber disclosed that a year earlier, in 2016, hackers had stolen 57 million driver and rider accounts and that it paid them a $100,000 ransom to delete the information. The breach was reportedly part of Uber’s bug bounty program, wherein it pays hackers to test its software for vulnerabilities. But the amount was exorbitant by typical standards, and the episode has fueled criticism over the bug bounty practice, which is seen by some as funding criminal activity.

At an industry event in San Francisco this week, Marten Mickos, the CEO of HackerOne — which runs Uber’s bug bounty program — answered questions about Uber’s hacking, which is now the subject of at least four lawsuits. His interviewer, cybersecurity reporter Kate Conger, also pressed him on the definition of a good versus bad hacker — and whether there’s much of a difference.

Excerpts from their sit-down follow, edited for length.

KC: For those who don’t know, what does HackerOne do?

MM: The simple truth today is that every single system will get hacked. And the only question is, who do you want to get hacked by? People you trust or criminals? If you choose the former, you swallow that pill, you come to us. We have 160,000 ethical hackers in our network who will hack you within 24 hours. They’ll tell you how they broke in and you’ll pay them a lot of money, but it’s much, much less than if you swallow the other pill.

KC: You were in the news recently and maybe not for the most positive reasons: You administered Uber’s bug bounty program and it got wrist-slapped for [losing the data] of 57 million people and paying out $100,000 to the hacker to keep him quiet. Do you think that behavior muddies the water between ethical hackers and bug bounty programs and bribery?

MM: I’m not here to comment on any particular case. I can note, however, that it hasn’t been shown than 57 million records have been lost forever. They might have been lost for a short time only, but we’ll leave that to others to figure out. But it’s clear that in the world of hacking, if there is intrusion and data exfiltration or extortion, it has nothing to do with ethical hacking or bug bounty programs.

The line there is very clear. We’re very fortunate to run Uber’s bug bounty program and many other really large programs [including for the U.S.] Air Force, Army, and Pentagon. So sure, with technology always, it’s the same technology used for good and bad purposes, and technology itself doesn’t have an opinion about what it’s being used for.

KC: So is that the ethical line between a good and bad hacker — data exfiltration? You can break in as long as you don’t take anything?

MM: The difference between the hacker and the criminal is intent. If you’re an ethical hacker and you’re looking for vulnerabilities in order to report them, you must break in. If you have a neighborhood watch and you ask your neighbors to see if they can break into your house, they have to break in to show you that they can do it. Once inside the house, they shouldn’t take anything, though.

The same idea applies [with bounty programs]. [Hackers] have to show that it’s possible to break in. That’s where you get to the question of authorized versus unauthorized conduct, and then again, it’s the owner of the house who decides which is which. When you break into the house, how much do you need to do? Do you need to bring something outside to show it was possible or not? And that’s an individual decision for every customer of ours, who determines what they need as proof. The more proof you need, the deeper the hackers need to go to find it.

KC: In the security industry in particular, a lot of things that are considered best practices seem from the outside sketchy, for lack of a better word. When we were talking earlier about the Uber situation [before the event], you said you felt like Uber averted a lot of risk. Can you talk about what you meant by that?

MM: When you say things look sketchy, things look sketchy when we are fearful, and we are fearful when we have too little information. Once you understand something, it doesn’t look sketchy anymore.

We represent a new model that hasn’t been done, so many people on first blush think that it’s dangerous when it’s actually the opposite. There’s an exact analogy to immunization and vaccines and how they work. The ethical hacking and bug bounty work is the immune system of the internet, so you have to create some of the bad stuff in order to create the defense.

It’s similar here. So when you actually do a bug bounty program, you can have situations where it can escalate or de-escalate. Some of these hackers are no older than 15 . . . [and] there is excitement in the moment. These are hunters; they are hunting for a trophy. And when they find it, they get very excited. And they may in the excitement say something, do something, or ask for something that the other side finds problematic. If you then have the ability to de-escalate the situation, everybody will be happy and step by step, everybody will learn the proper conduct. There are many situations where properly managed bug bounty programs will diffuse situations that otherwise could have gotten out of hand.

KC: You recently testified before the Senate. What was that like?

MM: It was fantastic actually. I’ve never done it before, and I’m not even from this country, so it had special meaning for me.

The Senate asked us to testify for them two weeks ago to tell them what bug bounty and vulnerability disclosure programs are. So at the highest level of legislation in this country now, they have an understanding of the importance of hackers, [and know] we need them. We need hackers more than anything else.

But seeing the senators and their staff, the people working there [who are] seemingly underpaid and overworked are so sharp. I sent them one evening probably 20 URLs [along with] all our white papers and studies and literature — everything — and by the morning they’d read it and they had very good questions. And in the hearing, every senator who spoke up said they believed in ethical hacking. They think bug bounty programs are a vital part of security in today’s society.

KC: One of the cool things about the last year, between Russian and hacking, is people finally care about hacking.

Some [of the hackers we work with] are teenage boys and girls today, and they’ll write us and say their life has changed. They bought an apartment for their mother, or they bought a motorbike for themselves. They show up on social media in their HackerOne hoodies. That’s their identity. It’s shaping them into respectable, contributing citizens who take responsibility for the world. It’s amazing to see how these young people stand up when we adults have been screwing up this world.

KC: You’ve told me you try to be frugal. When you’re raising all this money (roughly $75 million to date), where does frugality enter the picture?

MM: Not when you are raising money. No, no. When you are raising money, you talk about the biggest numbers you’ve heard anybody utter. [Laughs.]

You have to remember when you build a company to never believe your own PR and never to believe that you have to spend the money you get from VCs. You can raise a lot of money, but you don’t have to spend it — even when they say you should, which has happened in my career, in a company that went bankrupt.

VCs don’t take as much responsibility for their dollars as they take for their time. So as a CEO, you have to treat it as your own money and spend it wisely.

The world says it’s so inexpensive today to do a startup today and to use open source software and to run your business in the cloud, and of course you can. Yet you end up paying for all kinds of additional services. We are paying for 150 different software or SaaS packages right now. So you have to watch out who has an account and who can use it for what. You can easily spend all your money without noticing so you want to be careful — unless you are one of our competitors, in which case, do spend your money. If you run out of cash, that’s fine with me.

source:TechCrunch

The SEC is reportedly tightening the screws on cryptocurrency offerings

US regulators have begun a broad investigation into initial coin offerings of cryptocurrencies, according to The Wall Street Journal.

The SEC is reportedly tightening the screws on cryptocurrency offerings
The SEC is reportedly tightening the screws on
cryptocurrency offerings.
Securities and Exchange Commission
US regulators apparently are pushing harder to squeeze the snake oil out of the new cryptocurrency technology.

Digital currency and its underlying technology, blockchain, has the potential to refashion financial transactions and data sharing. But there are plenty of shenanigans, particularly through the money-raising process called initial coin offerings (ICOs), through which people can invest in new cryptocurrencies.

Now the Securities and Exchange Commission is cracking down more aggressively and has sent cryptocurrency companies dozens of subpoenas and information requests, The Wall Street Journal reported Wednesday. The SEC's requests seek information on investors, marketing materials, details on people involved and their locations, and more, according to lawyers who've seen the requests, reports cryptocurrency news site CoinDesk. One request was 25 pages long and "hyper-detailed," according to an unnamed lawyer CoinDesk heard from.

Plenty of people have gotten rich off cryptocurrencies like bitcoin and ether as valuations surged along with investor interest in 2017. The frenzy has slowed down for now. But startups, big businesses and cryptocurrency enthusiasts are still actively pushing the technology, and its long-term future is uncertain.

The SEC didn't immediately respond to a request for comment. But there's growing evidence it's taking a stand against shady ICOs. SEC Chairman Jay Clayton in January warned lawyers and accounts that they were falling short in their duties when it came to ICOs. "I have instructed the SEC staff to be on high alert for approaches to ICOs that may be contrary to the spirit of our securities laws and the professional obligations of the US securities bar," Clayton said.

The SEC has taken enforcement actions, too. In December, the agency froze assets of a cryptocurrency firm it alleged was a fraud, halted an ICO in January for another it called "an outright scam" and suspended trading in February in three companies that claimed cryptocurrency or blockchain dealings.

Today's initial coin offerings make the cryptocurrency realm very much like the wild west, Marina Niessner, an assistant professor of finance at Yale School of Management, said in an earlier interview. But eventually, the lawless phase will end, she predicted.

"My guess is a lot of the cryptocurrency stuff is probably going to go away," she said. Blockchain, though, which can be applied more broadly to business transactions and data-handling technology, "is probably here to say. It'll streamline a lot of finance."

source:CNet News

After introducing legislation targeting credit bureaus' bottom lines, the Massachusetts senator says, "Equifax is still making money off their own breach."

Sen. Elizabeth Warren speaks during a protest in front of the Consumer Financial Protection Bureau headquarters in November
Sen. Elizabeth Warren has led the charge against Equifax for not doing enough to protect its customers before it was hit with a major data breach last year. Now she's saying the credit reporting agency might be making money off this breach.

"Equifax may actually make money off this breach because it sells all these credit-protection devices, and even consumers who say, 'Hey, I'm never doing business with Equifax again' -- well, good for you, but you go buy credit protection from someone else, they very well may be using Equifax to do the back office part," Warren said in an interview with Marketplace. "So Equifax is still making money off their own breach."

Equifax was hit with a massive data breach in September, when hackers stole data on more than 100 million consumers. Personal details like Social Security numbers and addresses were stolen, which has left those customers vulnerable to identity theft.

Since the breach, Warren, a Democrat from Massachusetts, and Sen. Mark Warner, a Democrat from Virginia, have authored a bill to make the laws tougher on credit reporting agencies. Introduced in January, it aims to make data breaches hurt companies' bottom lines. The legislation also address how credit reporting agencies collect consumer data and what they do to stop hackers.

"The financial incentives here are all out of whack," Warren said in a statement last month. "Equifax allowed personal data on more than half the adults in the country to get stolen, and its legal liability is so limited that it may end up making money off the breach."

If passed into law, the bill would give the US Federal Trade Commission the authority to inspect the companies that collect vast amounts of financial data on consumers to make sure they're protecting that information. It would also let the agency fine them in the event of a data breach -- $100 per affected consumer as a minimum. Half of that money would be redistributed to the consumers caught up in the data breach.

In the case of the Equifax breach, that would have meant a fine of at least $14.3 billion. However, the fines would be capped at 50 percent of a company's gross revenue from the prior year.

Warren released a report earlier this month called "Bad Credit: Uncovering Equifax's failure to protect America's personal information." In the report, she details the hack and proposes ways to fight cyber threat, including levying financial penalties against credit reporting agencies that don't fully safeguard their customers' data.

Neither Warren nor Equifax immediately responded to request for comment.

source:CNet News

NBC says US intelligence agencies didn't tell states of Russia's role in attacks on election systems. Homeland Security calls the report "inaccurate."

An NBC report says seven states were targeted by hacking campaigns prior to the 2016 election, but none knew Russia was behind the attacks
Russia gained varying levels of access to voter registration systems and election-related websites in seven states leading up to the 2016 election, according to a report from NBC News. Three intelligence officials told the news outlet that then-President Barack Obama requested a report on hacking attempts on the US election system in the last weeks of his presidency, and that was the analysis they gave him.

Authorities in the states affected -- Alaska, Arizona, California, Florida, Illinois, Texas and Wisconsin -- told NBC that US intelligence officials informed them about the attacks but didn't say Russia was behind them. The state authorities and the intelligence officials all said they believe no votes were changed and no voters were taken off the rolls.

A spokesman for the US Department of Homeland Security, which is charged with helping state and local election agencies protect their systems from hackers, called the report "factually inaccurate and misleading" on Twitter.

"As we have consistently said, DHS has shared information with affected states in a timely manner, and we will continue to do so," said the spokesman, Tyler Houlton. "We have no intelligence -- new or old -- that corroborates NBC's reporting that state systems in 7 states were compromised by Russian government actors."

The report highlights the challenges presented by securing the voting systems of the US, which are fractured among states, counties and other localities. That fragmented system could be seen as a benefit, because hackers can't compromise the whole system with one attack. But it also means the federal government has a big job when it comes to detecting hacking campaigns and helping state and local governments defend themselves.

On Tuesday, the departing head of the National Security Agency, Mike Rogers, told US senators that President Donald Trump hasn't given his agency enough power to fight back against foreign hacking campaigns on election infrastructure.

In an interview with CNET, Homeland Security's chief cybersecurity official, Jeanette Manfra, said the question of whether hackers truly "breached" any systems was "a matter of endless debate." There have been no reports of voting machines being successfully hacked, and a scenario in which hackers influence an election by changing votes is "nearly impossible," Manfra said.

However, the perception that voting systems are vulnerable is itself a problem, Manfra noted. If hackers could seize control of a state's public-facing elections website, for example, they could create confusion and distrust. Security: Stay up-to-date on the latest in breaches, hacks, fixes and all those cybersecurity issues that keep you up at night.

source:CNet News

China-based iCloud users are facing a change in  how Apple handles the privacy of their data

Apple is moving encryption keys for China-based users' data from the US to the Asian country. Some say that's bad for dissidents. Apple says the keys are safe.

China-based iCloud users are facing a change in  how Apple handles the privacy of their data
China-based iCloud users are facing a change in
how Apple handles the privacy of their data.
James Martin/CNET
Apple has privacy advocates worried over a change in how it protects the data of iCloud users in China, according to a pair of reports.

The data, such as messages, emails and photos, is shielded from prying eyes by encryption, which means it's coded. But Apple will begin storing the keys for the code not in the US, as it's done till now, but in China, say reports this week by Reuters and The Wall Street Journal.

That means Chinese authorities won't have to go through US courts to compel Apple to give them access to data. The move is a response to new laws in China, which say cloud services offered to citizens there must store data in the country and be operated by Chinese companies.

At the end of the month, Apple will begin shifting the data to China and partner with a local company with ties to the Chinese government. Apple hasn't said when the encryption keys themselves will be moved overseas.

Privacy advocates say the switch could mean trouble for political dissidents and others. Apple says, though, that the keys will be kept in a safe location and that Apple itself will maintain control of them. The company says it will hand over data only in response to valid legal requests from Chinese authorities and that it hasn't built in any backdoors for access.

An Apple representative told the news outlets that the company advocated against iCloud being subject to the new laws but was unsuccessful. The rep also said Apple decided that discontinuing the iCloud service in China would make for a bad user experience and "less data security and privacy for our Chinese customers."

Amazon and Microsoft also partner with China-based companies to offer cloud storage services there and tap in to the huge Chinese market. The two US-based tech giants declined to tell the Journal where encryption keys will be stored for those businesses.

Apple told the news outlets that it's sending warning of the switch-over to iCloud users in China. Users there can opt out of iCloud to avoid having their data stored in the country. The company also said it won't move anyone's data until they accept the new China terms of service. Users whose settings are configured for a different country, or for Hong Kong or Macau, won't have their data stored on Chinese servers. Reuters includes Taiwan on that list; The Journal doesn't.

Neither Apple nor Amazon immediately responded to CNET's request for additional comment. Microsoft declined to provide added comment.

Security: Stay up-to-date on the latest in breaches, hacks, fixes and all those cybersecurity issues that keep you up at night.

source: CNET

1Password bolts on a ‘pwned password’ check
Password management service 1Password has a neat new feature that lets users check whether a password they’re thinking of using has already been breached. At which point it will suggest they pick another.

This is in addition to the more usual password strength indicator bar that tries to encourage web users to improve their security practices. The pwnage check builds on that by further reducing the risk of password reuse because it’s verifying if the specific password has appeared in a number of known data breaches.

Here’s a video of the new feature in action:


To power the feature, 1Password is leaning on Pnwed Passwords, a service launched by Troy Hunt last summer, and updated this month with a chunk more password data. It now contains around half a billion downloadable passwords, harvested by Hunt from various online dumps resulting from all sorts of different data breaches. The passwords in the database have been hashed by Hunt with SHA-1.

Hunt is best known for creating the Have I Been Pwned? breach notification service. And indeed it was through running that free online check, which lets people sign up to be informed if/when their email address surfaces in a data breach, that the idea for Pwned Passwords came about — as he says one of the most common reactions to people being informed their email had been found in a breach was to ask if they could also check whether their password had been breached.

Thing is, knowing your data has been found among millions of breached credentials, which you’re told includes emails and passwords, but not knowing exactly what was compromised in your case can feel frustrating. Although changing your password is always the sensible thing to do in such a situation.

And while Hunt has always resisted calls to make breached plain text passwords searchable (for obvious security and privacy reasons), the size of modern data breaches — which can almost routinely involve multi-millions of users these days — has demonstrably ramped up pressure on Have I Been Pwned? to also offer some sort of check for pwned passwords too.

Although, to be clear, Hunt’s Pwned Passwords service is not intended for people to check their actual passwords. Because no one should be typing actual passwords into another third party service, even one run by a such a demonstrably good guy.

(Hunt himself makes this point, writing: “[D]on’t enter a password you currently use into any third-party service like this! I don’t explicitly log them and I’m a trustworthy guy but yeah, don’t. The point of the web-based service is so that people who have been guilty of using sloppy passwords have a means of independent verification that it’s not one they should be using any more.”)

But he’s has done something much more useful and interesting than simply providing an amusing way to find out that “password” has been used as a password more than 3.3 million times in this database. Or that “123456” has been used over 20.7M times. (Which can itself provide a handy ‘security 101’ lesson if you need to help, for example, a less tech-savvy relative get up to speed on password risks.)

Because Hunt has made the pwned passwords downloadable and queryable via an API — in a way that does not entail the sharing of full passwords with third parties.

And this is what 1Password is using to power its new pwnage check.

Cloudflare gets some credit here too. After Hunt created the password database, he says he was contacted by a Cloudflare developer, Junade Ali, who wanted to make use of the database to improve password security but also wanted to incorporate an anonymity model to enable validation of leaked passwords without risking passwords being leaked in the process.

Ali has blogged here about the approach he took, using a mathematical property called k-anonymity — and both Hunt and 1Password are using this method to enable password checks against Pwned Passwords that don’t share the full hash of the password being checked (which would be a bad idea because it could create a breach risk).

“[O]ur approach adds an additional layer of security by utilising a mathematical property known as k-Anonymity and applying it to password hashes in the form of range queries,” writes Ali. “As such, the Pwned Passwords API service never gains enough information about a non-breached password hash to be able to breach it later.”

Only the first five characters of the 40 character hash of the password to be validated are sent to the server hosting the password database, which then returns a list of leaked password hashes that contain the same five initial characters. After that it’s just a trivial local comparison between the hashed password and the list to see whether or not there’s a match.

Of course even if there is no match found during a pwnage check it does not absolutely guarantee the password you want to use hasn’t been breached or compromised in some way. But it’s at very least a way of weeding out passwords that absolutely have been breached — and nudging users away from reusing insecure credentials. A horrible practice which, er, has sometimes even caught out some very techie people.

1Password says the password check service is available now to everyone with a 1Password membership. To check their passwords users need to sign into their account on 1Password.com, then click “Open Vault” to view their items and then click an item to see its details.

After that it says they need to enter keyboard sequence Shift-Control-Option-C (or Shift+Ctrl+Alt+C on Windows) to unlock the proof of concept, and then they can click the new “Check Password” button which appears next to the password.

Hunt has flagged a number of other services which have also incorporated the “first generation of Pwned Passwords” on his blog, including some which will entirely block password reuse, adding: “My hope is that they inspire others to build on top of this data set and ultimately, make a positive difference to web security for everyone.”

To be clear, he’s made the Pwned Passwords database and API freely available. Further burnishing his good guy credentials. source:TechCrunch

SEC urges clearer disclosures about cybersecurity risks

Updated guidance offers suggestions on how and when public companies should disclose breaches and risks.

The US Securities and Exchange Commission on Wednesday issued new guidance on how and when public companies should disclose cybersecurity risks and breaches.

The "interpretive guidance" document (PDF) urges informing investors of risks in a timely fashion, including vulnerabilities that have not yet been targeted by hackers. The guidance also says executives should refrain from trading in the company's stock while in possession of nonpublic information about significant cybersecurity attacks.

The commission, which unanimously approved the updated guidance, believes the document will help "promote clearer and more robust disclosure by companies about cybersecurity risks and incidents, resulting in more complete information being available to investors," SEC Chairman Jon Clayton said in a statement.

The commission's guidance comes amid a surge in wide-reaching cybersecurity hacks and vulnerabilities, including one last year at Equifax in which cybercrooks stole a treasure trove of personal information from as many as 143 million people in the US. The credit-monitoring firm said it learned of the massive hack in July, but it waited until September -- more than a month -- to reveal it publicly.

Three days after the company discovered the breach, nearly $1.8 million in stock trades were made by Equifax executives, including the company's chief financial officer. The company has said the stock sales were pre-scheduled, but the US Justice Department has reportedly opened a criminal investigation into the trades.

Security: Stay up-to-date on the latest in breaches, hacks, fixes and all those cybersecurity issues that keep you up at night.

source:CNet

What's the key to solid encryption technology? Well, pouring $50 million into its development can't hurt

WhatsApp co-founder and former Facebooker Brian Acton is putting millions into the encrypted-chat app and will head up a new foundation devoted to furthering privacy.

Edward Snowden is probably happy about this. But the FBI might not be.

Signal, the popular technology designed to keep prying eyes out of instant messages and other computer communications, has just gotten a $50 million shot in the arm. The Signal Protocol is used in Facebook Messenger, WhatsApp and Skype, among other apps, including the standalone Signal Messenger.

WhatsApp co-founder Brian Acton is ponying up the money and will also serve as executive chairman of the new Signal Foundation, which is being established by Open Whisper Systems, the open-source project behind the Signal encryption technology. Acton left WhatsApp and Facebook last year.

The not-for-profit Signal Foundation will initially focus on improving Signal Messenger and may one day roll out other privacy-oriented technologies, according to a blog post published Wednesday by Acton and Signal Protocol co-author Moxie Marlinspike.

"As more and more of our lives happen online, data protection and privacy are critical," Acton wrote in the post. "Everyone deserves to be protected. We created the Signal Foundation in response to this global need. Our plan is to pioneer a new model of technology nonprofit focused on privacy and data protection for everyone, everywhere."

Snowden and others wary of surveillance have made known their fondness for the technology. There's a big debate over encryption though, with the FBI and other law enforcement agencies saying it's getting impossible for them to crack, handing criminals, terrorists and others an invaluable tool for planning their exploits and creating an "urgent public safety issue."

Security: Stay up-to-date on the latest in breaches, hacks, fixes and all those cybersecurity issues that keep you up at night.

source:CNet

A message demanding money on a computer hacked by a virus. Such viruses, or "ransomware," are part of what makes crime so easy in the digital age, says a report

Why? Because the digital era has made crime easier than ever, says a new report from McAfee and the Center for Strategic and International Studies.

The internet has made life easier in a whole lot of ways. Love that convenience? So do criminals.

A report out Wednesday says cybercrime may now be costing businesses worldwide as much as $600 billion, and it points to the ease of digital crime as the reason.

"The digital world has transformed almost every aspect of our lives, including risk and crime, so that crime is more efficient, less risky, more profitable and has never been easier to execute," Steve Grobman, chief technology officer for computer security company McAfee, said in a statement. McAfee developed the report (PDF) along with the Center for Strategic and International Studies, a nonprofit, bipartisan think tank.

The fastest-growing tool for digital crooks right now? Ransomware, the report says. That's malicious software that can lock up your computer files till you send hackers a ransom payment. Attackers used it in the headline-grabbing WannaCry assault that hit hospitals, banks, telecommunications companies and warehouses in the middle of last year.

More than 6,000 illegal online marketplaces now offer ransomware for sale, says the McAfee-CSIS report. And if the buy-it-and-try-it, DIY approach seems like a headache, would-be criminals can simply hire a contractor -- ransomware-as-a-service is getting more popular.

Indeed, general cybercrime-as-a-service has gotten more sophisticated, says the study, with everything from custom malware to attack kits to botnet rentals available for convenience-seeking cyberbaddies.

The report also says the advent of cryptocurrencies has made it easier for digital troublemakers to actually make money off their crimes.

What's to be done? The study says that if data about cyberthreats was better standardized and cybersecurity requirements were better coordinated, businesses could more effectively protect themselves.

Security: Stay up-to-date on the latest in breaches, hacks, fixes and all those cybersecurity issues that keep you up at night.

source:CNet

Sqreen wants to become the IFTTT of web app security
French startup Sqreen recently launched a Security Hub with dozens of plugins to put you in control of the security of your web app. In many ways, it feels like enabling tasks on popular automation service IFTTT.

Sqreen participated in TechCrunch’s Startup Battlefield and Y Combinator’s current batch. The vision of the product hasn’t changed. Sqreen lets you protect your web service with little effort from your side.

Big companies have dedicated security teams that protect services, try to run attacks to find weaknesses and more. Smaller companies don’t necessarily have enough time and money to build a dedicated team. But your product is still vulnerable to SQL injections, XSS attacks and brute-force attacks.

Sqreen isn’t a firewall. You just have to install a library package on your server and add a couple of lines at the top your source code to require the Sqreen module in your application.

Once this is done, Sqreen monitors attacks in real time without a big performance hit — the startup says there’s a 4 percent CPU overhead. Sqreen now works for web apps in Node.js, Ruby, PHP, Python or Java.

In addition to protecting you against common attacks, Sqreen makes security recommendations so that you can regularly fix vulnerabilities. And with GDPR coming soon, tech companies have a greater responsibility when it comes to protecting customer data and disclosing hacks.

Customers wanted to know more about what Sqreen was doing. That’s why Sqreen launched a security hub with documented plugins.

“All security vendors are very secretive,” Sqreen co-founder and CEO Pierre Betouin. “Usually, you can’t test the product and you have no information on what they do. We were like this at the beginning of Sqreen. Our positioning was really ‘install our library and we’ll cover a range of security features.’”
...
You can find a plugin to protect you against SQLite injections, vulnerable dependencies, XSS Javascript injections in various frameworks, bot activity, etc.

Sqreen will recommend plugins for your app depending on the technologies and frameworks you’re using. You can then enable or disable each plugin and configure notifications on Slack or PagerDuty for instance.

In the future, you can imagine that third-party companies could contribute to this marketplace and add new plugins. Sqreen is also working on other plugins related to email abuse and payment page protection.

In addition to those new features, Betouin is moving to San Francisco and opening an office there. Companies like Front, Mindbody, BlaBlaCar, Triplebyte, Toptal and Algolia are now using Sqreen.

source:TechCrunch

119,000 Passports and Photo IDs of FedEx Customers Found on Unsecured Amazon Server
Thousands of FedEx customers were exposed after the company left scanned passports, drivers licenses, and other documentation on a publicly accessible Amazon S3 server.

The scanned IDs originated from countries all over the world, including the United States, Mexico, Canada, Australia, Saudi Arabia, Japan, China, and several European countries. The IDs were attached to forms that included several pieces of personal information, including names, home addresses, phone numbers, and zip codes.

The server, discovered by researchers at the Kromtech Security Center, was secured as of Tuesday.

According to Kromtech, the server belonged to Bongo International LLC, a company that aided customers in performing shipping calculations and currency conversations, among other services. Bongo was purchased by FedEx in 2014 and renamed FedEx Cross-Border International a little over a year later. The service was discontinued in April 2017.

“After a preliminary investigation, we can confirm that some archived Bongo International account information located on a server hosted by a third-party, public cloud provider is secure,” said FedEx in a statement to Gizmodo. “The data was part of a service that was discontinued after our acquisition of Bongo.”

FedEx added there’s “no indication” of the data being “misappropriated.” Its investigation into the matter is ongoing.

According to Kromtech, more than 119,000 scanned documents were discovered on the server. As the documents were dated within the 2009-2012 range, its unclear if FedEx was aware of the server’s existence when it purchased Bongo in 2014, the company said.

Bob Diachenko, Kromtech’s head of communications, said that essentially anyone who might’ve used Bongo’s services between 2009 and 2012 may have had their identity compromised. It’s possible the data has been exposed online for several years, he said.

“This case highlights just how important it is to audit digital assets when a company acquires another and to ensure that customer data is secured and properly stored before, during, and after the sale,” Kromtech said in a statement. “During the integration or migration phase is usually the best time to identify any security and data privacy risks.”

source:Gizmodo

The UK’s National Cyber Security Centre has attributed last year’s NotPetya attack to the Russian military.

UK officials say Russia was behind the NotPetya, aka GoldenEye, ransomware attack
The UK government has attributed a massive ransomware attack from 2017 to the Russian military.

The NotPetya ransomware targeted companies in Ukraine, attacking its government, financial and energy institutions last June. It ended up causing collateral damage to global companies with offices in Ukraine, including Maersk, FedEx and Merck. The cyberattack ended up costing Maersk up to $300 million in lost revenue.

"The Kremlin has positioned Russia in direct opposition to the West, yet it doesn't have to be that way," said Tariq Ahmad, foreign office minister for cybersecurity. "We call upon Russia to be the responsible member of the international community it claims to be rather than secretly trying to undermine it."

Ahmad said Russia's "reckless" attack showed a "continued disregard for Ukrainian sovereignty" and cost organizations across Europe hundreds of millions of pounds.

The Ukraine government said it found evidence linking the attack to Russian hackers in July. UK officials also noted that the hackers used ransomware as a disguise for an attack clearly meant to destroy data and cause chaos. This is only the second time the agency has attributed an attack to a nation-state. The first was when the NCSC attributed the WannaCry ransomware attack to North Korea.

source:CNet

Cryptocurrency like bitcoin is easy money for criminals

Bitcoin and its brethren have earned a reputation for fast returns on investment, but they're vehicles for exploitation too.

This is part of "Blockchain Decoded," a series looking at the impact of blockchain, bitcoin and cryptocurrency on our lives.

Cryptocurrency like bitcoin is easy money for criminals
Image: CNet
The Winklevoss twins aren't the only ones getting rich off cryptocurrency. Criminals are raking it in too.

Thanks to the meteoric rise of bitcoin over the past year, you've probably heard of cryptocurrency, or digital money that uses blockchain encryption technology for transaction security. By mid-December, the value of one bitcoin reached more than $19,000. It's since fallen below $7,000, though it's recovered some ground over the past week.

Bitcoin is the best-known cryptocurrency on the market. However, there are more than 1,500 cryptocurrencies out there, some with goofy names like Dogecoin, PinkDog and Californium.

Before you get too excited about using or trading this new form of money, be aware that cryptocurrencies are rife with criminal activity. Cryptocurrency, for instance, is the preferred form of payment when hackers lock up your computer for ransom, such as in last year's widespread WannaCry attack. Likewise, there are viruses that turn computers into slave machines mining for cryptocurrency. Hackers have also created malware disguised as cryptocurrency apps, tricking folks who think they're cashing in on the trend.

"It's usually being used for something illegal," said Steve McGregory, the application and threat intelligence director at security firm Ixia. He estimates that 99 percent of illegal activities online use cryptocurrency.

This is cryptocurrency's dark side, which sometimes gets lost in the hype over the rocketing value of bitcoin and its brethren. But just as digital currency has turned into a hot new investment vehicle, it's given hackers and cybercriminals new opportunities for exploitation.

Even old-school cons have taken a new blockchain twist, with consumers excitedly buying new forms of cryptocurrency only to find they're little more than hot air and false promises.

"With cryptocurrency, it's like choose-your-own adventure," said Rick Holland, a cybercrime researcher at security company Digital Shadows. "People can pick so many routes to target victims now."

Hide the money

The reasons that cryptocurrency has become a trusted, valued form of money are the same reasons it has become an invaluable asset for cybercriminals, who want to get paid for their efforts.

All cryptocurrency transactions use a mix of public and private keys to keep payments secure and, in some scenarios, completely secret. You can see where the money goes and which wallets its headed to. But if you can't link the wallet to a person, the identity remains secret.

Watch this:Cryptojacking: The hot new hacker trick for easy money

That anonymity allows cybercriminals to sell information from massive breaches, such as the 145.5 million Social Security numbers stolen from Equifax or data from 3 billion hacked Yahoo accounts, without worrying about law enforcement tracking who's buying or selling it. Likewise, the WannaCry hackers demanded victims each pay $300 worth of bitcoin to get their devices back to normal last year. Criminals even use cryptocurrency to pay for online classes that teach ways to use stolen credit card numbers. That cover has helped boost the ranks of cybercriminals, despite the nascent efforts of governments to crack down. For example, the European Union and the UK are working to crack down on the anonymous nature of cryptocurrency, out of concern that it helps terrorist groups and their money-laundering efforts. The EU plans to require platforms where bitcoins are traded to report suspicious sales and to monitor users, while the UK wants officials to oversee online transactions. In November, Stephen Barclay, then-economics secretary to the UK treasury, said the government expects these changes to take effect this year.

Banking on botnets

Botnets, a mass of hijacked computers under the control of a hacker, were once primarily used to fire off spam emails or initiate distributed denial-of-service attacks, which essentially block a website by overwhelming it with traffic.

But with cryptocurrency, hackers found another purpose for botnets: making money.

Cryptocurrency is bought and sold, but it must also be mined, or verified, with immense computing power. Given the processing chops needed to mine cryptocurrency, the cost of the electricity to run the machines can be higher than the mining revenue. But if you're not using your own computer, there's little expense eating into your profits. When the Mirai botnet hit in 2016, hackers took control of thousands of connected devices around the world.

"We were expecting DDoS attacks, but then we started seeing loads of people dropping bitcoin-mining payloads on the routers and cameras," McGregory said. "If you get thousands of these, you can make money off of someone else's machine and it's easy pickings."

McGregory spotted malware designed to stay hidden on hacked machines and mine for cryptocurrency in the background. If you owned one of these computers, the effect would be a dramatic slowdown in performance. And that wasn't even a sophisticated attack.

Mining malware is sold online for as cheap as $35, according to security researchers from Recorded Future.

McGregory said mining apps in the Google Play Store have been downloaded more than 10 million times. He's found them in fake puzzle games, crosswords and tic-tac-toe apps. He's also spotted one called Reward Digger, in which the player earns virtual coins but in actuality is helping hackers mine bitcoin.

Mugging malware

If you can't mine cryptocurrency or get a botnet to do it for you, there's always the old-fashioned way: stealing it.

Some malware searches for cryptocurrency wallets and empties them via virtual burglary. In October, antivirus company Kaspersky Lab researchers discovered CryptoShuffler, a trojan that lets hackers change the wallet address from a victim's computer to their own, essentially diverting the funds away from the intended person.

Because of the anonymity of transactions, a victim doesn't know what happened until it's too late. Since Kaspersky discovered it, the trojan has stolen 23 bitcoins, now worth around $210,000.
In December, NiceHash, another cryptocurrency mining marketplace, said it had been hacked to the tune of $62 million. And unlike money stolen from a bank, police can't find it and victims won't ever get it back.

Old crimes, new tech

The connection between cryptocurrency and crime is only going to get worse as investments continue to boom.

The US Securities and Exchange Commission last year cracked down on a cryptocurrency scheme that it said raised more than $15 million before it was busted. The alleged scammers promised wild returns on the launch of a new digital currency, but the SEC said that investments went toward their personal expenses instead.

Holland predicts that it'll be five to 10 years before governments can get a handle on digital currency crimes, and even then it may not be possible. That's because the schemes will just evolve.

"It's a new twist on an old game," Holland said. "But now the scale at which you can do this is high and the likelihood of you being busted is low."

source:CNet

For much of the world, fake news is less of a problem than fake food. One start-up is using the technology behind bitcoin to create anti-counterfeit labels.

This label may look like it doesn't do much, but the technology behind it protects you from becoming a victim of fake food, according to Walimai
This is part of "Blockchain Decoded," a series looking at the impact of blockchain, bitcoin and cryptocurrency on our lives.

Alexander Busarov used to buy a popular brand of pet food for Gulchatai, his Siamese cat, from Taobao, China's sprawling eBay-like auction site. That changed when the kitty landed at the vet's after eating from a shipment that looked strikingly different from store-bought tins.

Gulchatai eventually recovered -- she had acute gastroenteritis -- but the episode worried Shanghai-based Busarov. How could he ever know, he wondered, if what he was buying online was real?

So in April 2015, Busarov, a former McKinsey consultant, and Yaroslav Belinskiy, another Russian expat, established Walimai, which makes high-tech anticounterfeiting labels for products like baby food. The labels use blockchain, the technology behind the controversial bitcoin cryptocurrency, to ensure whatever they're stuck to hasn't been tampered with.

"Fake food is a way more serious problem than fake designer bags," Busarov said, pointing to a rash of fake rice and eggs that has plagued China. "It threatens health and sometimes even lives."

For more than bitcoin

Walimai isn't the first company to reimagine the use of blockchain, which entered the mainstream as a secure ledger for recording cryptocurrency transactions and is essentially a way to hard-wire trust. The Swedish government, for instance, is testing a land registry backed by blockchain to track property transactions and save taxpayers more than $106 million annually. In Australia, a startup called Everledger uses blockchain to trace blood diamonds, action that it says prevents an estimated $45 billion in fraud each year. Expanding its upscale uses, the company later used the technology to verify the quality of fine wine.

The food industry might not leap to mind as a hotbed of fraud, but more and more incidents of foodstuffs being sold as something they aren't have cropped up in recent years. The cases range from the inclusion of cheap ingredients that aren't listed on the package to an item being passed off as something else entirely. Four years ago, Chinese officials arrested more than 900 people for selling "mutton" that was actually rat meat. And just last month, 22 people were hospitalized after drinking whiskey tainted with methanol.

Watch this:What the heck is blockchain?

Fake food isn't limited to China. That extra virgin olive oil you put on your salad? It's likely bogus. Up to 80 percent of olive oil sold in the US doesn't meet legal standards, according to a CBS News report, which also found that cheese, caviar and truffles are often faked. In 2013, Swedish furniture giant IKEA had to recall meatballs sold at its cafes after they were found to contain horsemeat. Switzerland's Nestle also recalled frozen beef meals that were found to have horsemeat in them amid a wave of tainted meat products in Europe.

"Food fraud is present around the world and has been since food commerce has existed," said Dr. Geoff Allen, chief executive of the Asia Pacific Centre for Food Integrity. Walimai and similar antifraud systems can help slow the spread of doctored food, Allen says, adding "there is no silver bullet."

Walimai isn't the only company to attempt fighting food fraud with blockchain.


Walmart, the huge American retailer, partnered with IBM and Tsinghua University in China last October to explore how food products can be tracked with blockchain tech. Since then, trials have successfully traced pork products from farm to shelf in China, and the origins of mangoes sold in a Walmart outlet in the US. The entire process to trace the mangoes' origins took less than a week, which Frank Yiannas, Walmart's vice president of food safety, told Fortune is much faster than it would take without blockchain.

"One of the reasons food fraud can occur today is because many parts of the food system lack transparency," Yiannas said in an email. Blockchain, he added, "will be the equivalent of shining a light" on each link in the food chain.

In August, nine other companies across the global food supply chain, including Nestle and Unilever, joined the Walmart-IBM collaboration, hoping to discover new areas in the industry that could benefit from blockchain.

Alibaba, China's titanic equivalent of Amazon, is working to figure out how new technology, including blockchain, can be used to fight fake food. In May, it announced the Global Traceability Management Program, which includes using blockchain tracking in its Tmall Global shopping platform. It launched in August.

Peace of mind

The labels that Walimai, which was originally named Verify, produces look like hospital bracelets attached to product packaging. An RFID chip sits on the label, while the straps contain an antenna that communicates with the company's blockchain-based backend system through the Walimai app, which customers download to their phones. (The app is available for iOS or Android.)

The labels identify each unit, serving as a passport while the product makes its way through the food chain. Whenever the product changes hands during production, an encoder scans the label so that data -- think time, place and content -- are updated in Walimai's system.

Recording the data is where Walimai's blockchain technology comes in. Each time the encoder scans the label, the data is recorded in the blockchain. It's secure because that piece of data can be written into the blockchain only once, existing from that point on as immutable read-only information.

The labels can't be cloned because each one has a unique code. The labels also can't be removed without destroying the antenna, which leaves them useless. When products arrive in stores, customers use the app to scan a unit's QR code and access the product's history.

All this protection, of course, comes at a cost. Products bearing a Walimai label generally retail at a 20 percent premium to comparable goods, but it's a cost some consumers are willing to pay.

Using expensive special labels may seem like a stretch for many people. But the alternative -- importing products from overseas -- is even more costly. Still, that's what plenty of Chinese parents do for foodstuffs like baby formula, a particularly sensitive product after six infants died consuming tainted formula a decade ago.

During a pilot test that started a year ago, Walimai has found that people are willing to pay for peace of mind, Busarov said, especially in less developed cities where fraud is more serious.

That makes sense, especially if the alternative is a late-night trip to the vet.

source:CNet

Cyberattack hits Winter Olympics during the opening ceremony

The Pyeongchang Winter Olympics' internal servers crashed in the attack, as did public Wi-Fi. Officials confirmed the attack, but won't identify the perp.

Cyberattack hits Winter Olympics during the opening ceremony
VCG/Getty
Reports in January from cybersecurity company McAfee claimed that organisations associated with the Pyeongchang Winter Olympics were targeted by a hacking "campaign." Perhaps unsurprisingly, that wasn't the last cyberattack aimed at the Winter Olympics.

Officials confirmed Sunday that the Winter Games were hit by a cyberattack during Friday's opening ceremony, though they opted not to reveal the attackers.

"We know the cause of the problem but that kind of issues occurs frequently during the Games. We decided with the [International Olympics Committee] we are not going to reveal the source," Pyeongchang organising committee spokesman Sung Baik-you told reporters, according to Reuters. "All issues were resolved and recovered [Saturday] morning."

The attack crashed some of the Winter Games' internal servers as well as the public Wi-Fi, South Korea's Yonhap News Agency reported, which lead to some customers being unable to print out their tickets for the show.

Russia, a country not represented in the Winter Games due to doping concerns, predicted before the event that it would be blamed for a cyberattack on the festivities. "We know that Western media are planning pseudo-investigations on the theme of 'Russian fingerprints' in hacking attacks on information resources related to the hosting of the Winter Olympics Games in the Republic of Korea," Russia's foreign ministry said, according to Reuters.

Meanwhile, fingers are often pointed at North Korea following cyberattacks and hackings, with the controversial country being blamed by the US for the WannaCry hacks of last year, and other breaches dating back to 2009. However, it comes at a time when North and South Korea, nations who've been at war with one another since the 1950s, are making efforts at unity.

Watch this:Worst hacks of the year


source:CNet

Using a script called Coinhive, a website for fans of deepfake videos mined cryptocurrency Monero on visitors' computers, researchers found

A website for fans of doctored videos used its visitors’ computers to mine Monero. It’s the latest way hackers can abuse your computer’s processing power.

Using a script called Coinhive, a website for fans of deepfake videos mined cryptocurrency Monero on visitors' computers, researchers found
Using a script called Coinhive, a website for fans of deepfake videos mined cryptocurrency Monero on visitors' computers, researchers found
Your computer can do amazing things for you, but what can it do for hackers? Try this: make money.

That's what happened when web users navigated to a forum for fans of doctored videos, called deepfakes. According to researchers from Malwarebytes, code running on the website commandeered visitors' computers to mine Monero, a form of cryptocurrency, as long as the webpage was open on the browser.

It's sneaky, strange and possibly genius. "If they had enough traffic, that would absolutely generate a lot of profit," said Stephan Simon, a security researcher at Binary Defense Systems.

Just because this happened on a deepfakes forum, don't think this couldn't happen to you. Sure, the deepfakes phenomenon is all kinds of weird, involving fake celebrity videos that insert actor Nicolas Cage into movies he didn't star in, or any celebrity into porn scenes they never filmed. But hackers are trying to mine cryptocurrency on every kind of device, harnessing the computing power of regular people to cash in on the bonanza of blockchain-driven digital currency.

It even has a name: cryptojacking.

On Monday, a Chinese cybersecurity firm said it found malicious software on Android phones and smart TVs that was mining Monero for hackers. In January, a security researcher revealed that hackers could use public Wi-Fi networks to mine cryptocurrency on computers that connect to them. And as far back as September, another security researcher found cryptojacking software on official Showtime Network websites.

Experts say two things have helped bring about this state of affairs. First, the growing value of cryptocurrencies like Monero, Bitcoin and Ethereum has put a premium on computing power. It takes a lot of oomph, and time, from computers to run the software that creates more Monero, and it's a stealthy shortcut to use a crowd of strangers' computers without their knowledge.

Second, the creation of mega-botnets like Mirai has shown that large numbers of computers, phones and smart home devices can be harnessed to serve a hacker's whims.

"When there was more or easier money to be had, there was motive" to build more botnets, Simon said. "Cryptocurrency has helped it accelerate."

Some forms of cryptojacking work only while a web page is open, and others keep your computer chugging under its orders even after you close the browser tab. Hackers use something called Coinhive, a library of code written in Javascript, to force the computer to mine Monero.

Cryptojacking is only so harmful to its victims. In essence, it slows computers way down, and potentially heats them up. Just imagine that sad whining sound you hear when your computer's fan has kicked into high gear. Some web browsers block the malicious scripts. Opera announced in Decemberthat it would block the scripts in a beta version of its eponymous browser, saying they were bad for users' computers. It calls the feature "NoCoin."

"Bitcoins are really hot right now, but did you know that they might actually be making your computer hotter?" the company said in its announcement.

Victims of cryptojacking do tend to be dipping their toes into the shady end of the internet. In addition to deepfake forums (which were kicked off Reddit due to ethical concerns), torrenting and porn websites have served up cryptojacking scripts, experts noted.

Fans of deepfakes might've become targets because there's a higher chance they have powerful computers, said Chris Boyd, a malware researcher at security firm Malwarebytes who examined the deepfakes forum running Coinhive. That's because it takes a certain amount of processing power to make the fake videos. But then again, other types of sites have fallen victim to the ploy too. So basically, no one's safe. source:CNet

The seized domain. Screengrab via popcorntime.dk
A Danish man has been handed down a six-month conditional sentence for merely sharing information about Popcorn Time, the once-popular torrent-based streaming client that was targeted for extermination by copyright lawsuits.

According to the Copenhagen Post, a court in Odense found the man guilty of “promoting the illegal online film streaming service Popcorn Time via his website popcorntime.dk.” It’s the first time in the country that a man has been convicted of “participating in the promotion of streaming services,” prosecutor Dorte Køhler Frandsen told the paper, adding that “The decision is a clear signal to those who help spread illegal pirate services.”

Popcorn Time is basically a torrent client that looks like Netflix, which once described it as a top competitor. From the Post’s description, it doesn’t seem like the individual in question was doing anything other than instructing people on how to set up the client:
More specifically, the man was convicted of offering a guideline about how Danish users could download the Popcorn Time app, how to install and use it, and how to avoid being discovered by the authorities.
The court moved to seize some 500,000 kroner (around $82,300) he had made from advertising revenue on the site and assigned him 120 months of community service, though he has two weeks to appeal, according to the Post.

As noted by TorrentFreak, the popcorntime.dk domain now displays a warningto users in both Danish and English:
The Danish State Prosecutor for Serious Economic and International Crime is presently conducting a criminal investigation that involves this domain name. As part of the investigation the state prosecutor has requested a Danish District Court to transfer the rights of the domain name to the state prosecutor. The District Court has complied with the request.
An archived version of the site contained links to Popcorn Time apps hosted on other websites, as well as various other apps for streaming purposes.

If the court’s intent was to scrub the web of information about Popcorn Time, they appear to have been (predictably) unsuccessful. While the original developers of the project pulled it from Github in 2014, development has been independently continued by numerous other teams and various versions of the software remain trivially easy to locate online including a semi-official successor. Similarly, the archived version of the site continues to be accessible via the link above.

The Github repository for one of Popcorn Times’ successors. Screengrab via Github
The Github repository for one of Popcorn Times’ successors.
Screengrab via Github
Though many copyright holders have moved on from suing individual downloaders to trying to force websites which distribute torrents offline, using Popcorn Time-derivative apps without identity-masking tools like a VPN is not without its risks. In 2015, some German users received demands for 815 euros from a firm representing 21st Century Fox, Warner Brothers, and German film and TV studios on the basis that the users not only downloaded content but uploaded it through Popcorn Time.

source:Gizmodo

MKRdezign

Contact Form

Name

Email *

Message *

Powered by Blogger.
Javascript DisablePlease Enable Javascript To See All Widget