Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Friday, August 7, 2020

Russia is Expert at Online Disinformation

At her Thursday keynote, Stanford Internet Observatory's research manager Renee DiResta explained how Russian military intelligence – the GRU – and the private Internet Research Agency (IRA) were putting the likes of China to shame. Security companies and government agencies have good reason to move their focus from Beijing to Moscow, she warned.

The basic methods of hacking public opinion are fairly simple, DiResta explained. Fake accounts generate content and spam it out on social media to amplify the message. If enough real people pick up and the posts go viral the mainstream media kicks in and amplifies the desired message still further.

In Russia's case, it spreads divisive material, stolen information, and fake news in an attempt to turn Americans against each other, sour civil society, sow doubt, and create distractions, leaving people unsure of what's really going on. This worked. In China's case, it tried to make people like China. This didn't work.

https://www.blackhat.com/us-20/briefings/schedule/#hacking-public-opinion-21289


Friday, August 16, 2019

Abuse of Online Privacy Rules Means Personal Info Can Be Compromised - So Require Credentials

With the introduction of Europe's General Data Protection Regulation, firms in Europe and around the globe should be aware that social engineering tactics can be used to acquire an individual’s sensitive data.

“…For social engineering purposes, GDPR has a number of real benefits, Pavur said. Firstly, companies only have a month to reply to requests and face fines of up to 4 percent of revenues if they don't comply, so [the] fear of failure and time are strong motivating factors.

In addition, the type of people who handle GDPR requests [is] usually admin or legal staff, not security people used to social engineering tactics. This makes information gathering much easier….” See this article.

Direct email marketing, for example, is already regulated under the EU's e-Privacy Directive. Such rules require consent before someone can be sent direct marketing. A so-called "soft opt-in" makes this slightly easier. If a firm has an existing relationship, for instance, if a customer has bought a product from them before, they may still contact that recipient.

The European Union is updating the rules on electronic communications just as the UK is hustling to engage its own Data Protection Act in place, considering how Brexit will affect tech firms. The continued flow of data between the UK and the rest of Europe (and the world) depends on governments’ ability to interact.

Tuesday, August 6, 2019

Known Apple Vulnerability Remains Unpatched

Apple Wireless Direct Link (AWDL) is at the core of Apple services like AirPlay and AirDrop, and Apple has been including AWDL by default on all devices the company has been selling, such as Macs, iPhones, iPads, Apple watches, Apple TVs, and HomePods.

It seems that the AWDL protocol, installed on over 1.2 billion Apple devices, contains vulnerabilities that enable attackers to track users, crash devices, or intercept files transferred between devices via man-in-the-middle (MitM) attacks.
These are the findings of a research project that started last year at the Technical University of Darmstadt, in Germany, and has recently concluded, and whose findings researchers will be presenting later this month at a security conference in the US. The project sought to analyze the Apple Wireless Direct Link (AWDL), a protocol that Apple rolled out in 2014 and which also plays a key role in enabling device-to-device communications in the Apple ecosystem. While most Apple end users might not be aware of the protocol's existence, AWDL is at the core of Apple services like AirPlay and AirDrop, and Apple has been including AWDL by default on all devices the company has been selling, such as Macs, iPhones, iPads, Apple watches, Apple TVs, and HomePods. But in the past five years, Apple has never published any in-depth technical details about how AWDL works. This, in turn, has resulted in very few security researchers looking at AWDL for bugs or implementation errors.

Monday, December 26, 2011

Today, the Settling of Grievances


The day after Xmas (or perhaps, on Festivus itself), the airing of grievances is a regular event in the Termini household. This corresponds with Wren's Day (St Stephen's day), when kids mark betrayal by the tiny wren…


So I'm marking today with a list of tech issues I'd like to see addressed in the coming new year.


  • Apple TV. No, not this one, I mean a forthcoming Apple TV. Will I be speaking to my TV, instead of fumbling with remotes? In the Termini house, we use a Mac Mini connected to a Visio tv to get our info-tainment. I got to sample the above-mention AppleTV over Xmas, and mostly liked it. But still too limiting (filtered access to YouTube?? Really, Apple).
  • Kill off NetBooks already. As regular readers know, I did make an initial foray into the NetBook world while ago (well, ok, maybe I dabbled in Hakintosh). And quickly abandoned it (well, re-gifted to my daughter) when I started developing for the iPad. If you look at the apps available for iPad that are business-savvy (Pages, Keynote, Bento), the battery life, the form-factor, you'd agree. NetBooks are a dead-end branch of the PC tree.
  • Speaking of killing off, get rid of the wallet! In Japan, you pay for many things with your mobile phone. Google is in the forefront with their approach. I have attempted a kludge approach myself. Come on VISA and MasterCard, get on board to end the tyranny of plastic cards.
  • Cyber-criminals. Please, people, lock up your data! At least encrypt peoples' login/password or other vital data, so when the inevitable Chinese or Russian hacker snatches your data, they can't run up credit card bills.


Finally, in concluding the tradition, I'll end with a happy thought, instead of a b*tch. I enjoy working in the tech field -- I get to meet lots of people, I feel like I'm frequently solving problems and making some small part of peoples' lives easier, and I get to tackle unusual problems. As much the above complaints might nag me, I am thankful to be in this field, making good use of my talents.