Showing posts with label protect. Show all posts
Showing posts with label protect. Show all posts

Wednesday, 7 August 2013

iOS 7 to protect against charger-based hacks of Apple devices

Apple has announced that the newest iOS 7 beta release includes a security update to protect its mobile devices from hacks using a modified phone charger or battery.

Last month, researchers from Georgia Tech revealed that a readily available circuit board could be concealed in a docking station or battery and used to exploit weaknesses in Apple’s mobile security.



154452714-iphone-chargers-290px.jpg
The researchers, who notified Apple of the vulnerability earlier this year, presented a proof-of-concept demonstration at the Black Hat USA 2013 conference in Las Vegas.

The researchers said the proof-of-concept malicious charger was built with a limited amount of time and a small budget.

In a summary of the presentation, the researchers said they had injected arbitrary software into current-generation Apple devices running the latest operating system (OS) software.

“All users are affected, as our approach requires neither a jailbroken device nor user interaction,” the summary said.

At the Black Hat conference, researchers Yeongjin Jang, Chengyu Song and Billy Lau used their proof-of-concept modified charger to infect a connected iPhone with a virus, causing the handset to call the smartphone of a team member.

The method could be used by cyber criminals to steal sensitive data or take control of the device remotely, they said.

The vulnerability does not affect Android devices because Google’s mobile operating system warns users when their device is plugged into a computer.

Apple’s fix, which is available in the latest iOS 7 beta release, is in the form of a notification to users warning them that they are not connected to a standard charger.

The fix will be included in the final version of iOS 7, which is due for release this autumn.

In announcing the security update, Apple thanked the Georgia Tech researchers for their “valuable input”.

Technology suppliers such as Microsoft have been severely critical of security researchers who fail to disclose vulnerabilities before going public.

In June, the company joined the growing list of other technology suppliers offering a bounty to reward those who report bugs to discourage them from selling their discoveries on the open market.

Microsoft said its new bug bounty schemes are aimed at helping to improve the resilience of its products through responsible disclosure of flaws that hackers could exploit.

Wednesday, 3 July 2013

New trust wants to protect digital Bitcoins like physical gold: In vaults

A U.S. regulatory filing for a Bitcoin investment trust from the Winklevoss twins said they will protect the virtual currency like gold bars—in vaults.

Cameron and Tyler Winklevoss, famous for their early association with Facebook, are selling the trust as a way for institutional and retail investors to invest in bitcoins without dealing with the hassle of exchanges and the thorny security problems around storing bitcoins.

The goal of the fund centers on an anticipated appreciation if bitcoins become more widely used as a means for exchange. Some businesses are using bitcoins, but volatile exchange rates and regulatory issues remain a concern.

In a 74-page document filed with the U.S. Securities and Exchange Commission on Monday, the twins write they will use a network of secure vaults around the U.S. to store their investors' bitcoins.

Their company, Winklevoss IP, owns intellectual property related to patent-pending technology that will be used by the trust, the filing reads. That includes what is described as a "proprietary security protocol."

A bitcoin is essentially a secret number that can be transferred to another computer using public-key cryptography. A bitcoin has a private key that if unencrypted allows the coin to be sent to another computer using peer-to-peer software.

A bitcoin transaction is seamless and fairly quick, but since the private key is often stored on a person's computer or with a web-based service, hacking remains a real risk.

Some bitcoin enthusiasts have written private keys down on pieces of paper in so-called "offline" wallets. But losing a private key to a bitcoin means that it can never be used and is lost forever.

The long list of risks highlighted in the SEC filing shows that an investment with the twins' trust is only for those with steely nerves. And they make no guarantee that the security system will be able to thwart hackers.

The trust's sponsor, Math-Based Asset Services, which is owned by Winklevoss Capital Management, is not liable for losses due to "failure or penetration" of the security system, absent gross negligence, fraud or criminal behavior by the sponsor, the filing reads.
 
Also, the people responsible for the day-to-day administration of the trust "will also not be liable for any system failure or third-party penetration of the security system."

They also anticipate their trust "may become a more appealing target of security threats as the size of the trust's assets grows."

The warnings may not put off people familiar with bitcoin, which has made a handful of people who bought in after the system launched in 2009 very wealthy.

Many others, however, have racked up losses after buying bitcoins during a rapid, speculative rise to $260 per coin in April before falling as low as $56. A single bitcoin sold for around $90 on Tuesday, according to the largest exchange, Mt. Gox in Japan.

The Winklevoss twins told The New York Times in April that they held as many as 1 percent of all of the bitcoins in circulation. There are about 11.3 million bitcoins in circulation, putting their holdings conservatively at $9 million today.

According to their plans, the trust would offer "baskets" of shares, of which each share is comprised of one-fifth of a bitcoin. The baskets would be redeemed in blocks of 50,000 shares based on an average bitcoin market price calculated from exchanges.

Friday, 21 June 2013

Encryption can’t protect your data while you’re logged in

You carry a lot of data and sensitive information on your laptop, tablet, and smartphone. The standard method of protecting that information from prying eyes is to encrypt it, rendering the data inaccessible. But with most encryption software, that information becomes accessible the moment you log in to the device as a matter of convenience.


Think about what information that might be: names, postal and email addresses, and phone numbers for friends, family, clients, and business associates; calendar events indicating where you’ll be and when you’ll be there; personal photographs; and more. You might also have proprietary information about your company, clients, information that companies have entrusted you under the terms of non-disclosure agreements, and other sensitive information that should be secured.

Encrypting data protects it from unauthorized access.

Encryption basically scrambles the data so it’s nothing but unusable gibberish to anyone who isn’t authorized to access or view it.


And that’s great, but ask yourself this: How many steps must you go through to decrypt your data? Encryption is designed to protect data, but it should also be seamlessly accessible to the user—it should automatically decrypt, so you don’t have to jump through hoops to use your own encrypted data. And that means it’s not protected at all if someone finds your laptop, smartphone, or tablet in a state that doesn’t require a log-in password.


The Department of Justice and the National Security Administration—the same NSA that allegedly has omnipotent access to all data everywhere—have expressed frustration over iOS 6 and declared its encryption to be virtually impenetrable. There is a way to bypass it, but only Apple knows the magic trick, and there’s a massive backlog of requests from law enforcement.