Hottest Posts

Showing posts with label Techno. Show all posts
Showing posts with label Techno. Show all posts

CIA spy attempt on Apple proved futile


Another NSA leak revealed that the CIA was trying to undermine the encryption used in iPhones and insert secret surveillance backdoors into applications. Surveillance methods were presented at NSA’s secret annual conference dubbed “jamboree”.

The most worrying effort was the creation of a dummy version of Apple’s development software called Xcode. The latter is normally used by developers all over the world to create apps for iOS. Apparently, the modified version of Xcode would allow the surveillance agencies to insert surveillance backdoors into any mobile app created in it. This leak may prompt security audits among Apple developers to find out if they used compromised software or not.

The sad part is that sustained hacking efforts against Apple devices, very popular in the United States and all over the world, continue to strain difficult relations between Apple and the American government. Although Apple used to be a partner in the notorious Prism program (a kind of a legal backdoor to get user data by the secret agencies), the company then has stepped up efforts to protect user privacy. This is when it launched its own encryption in iMessages.

This “jamboree” also revealed the attempts to use keylogger software, i.e. the one that records and transmits everything a victim types, into systems via Apple’s software update tool. Finally, a sophisticated approach to breaking encryption was revealed, which used the activity pattern of the phone processor while it is encrypting data in order to gain access to the core software the iPhone runs.

These are not the only activities of intelligence agency against Apple: a year ago, a variety of exploits were revealed that the NSA and its fellows used against mobile phones.


--ExtraTorrent. 

Not in front of the telly: Warning over 'listening' TV


http://www.remigh.blogspot.com

Samsung is warning customers to avoid discussing personal information in front of their smart television set.
The warning applies to TV viewers who control their Samsung Smart TV using its voice activation feature.
Such TV sets 'listen' to every conversation held in front of them and may share any details they hear with Samsung or third parties, it said.
Privacy campaigners said the technology smacked of the telescreens, in George Orwell's 1984, which spied on citizens.

Data sharing
The warning came to light via a story in online news magazine the Daily Beast which published an excerpt of a section of Samsung's privacy policy for its net-connected Smart TV sets.
The policy explains that the TV set will be listening to people in the same room to try to spot when commands are issued. It goes on to warn: "If your spoken words include personal or other sensitive information, that information will be among the data captured and transmitted to a third party."
Corynne McSherry, an intellectual property lawyer for the Electronic Frontier Foundation (EFF) which campaigns on digital rights issues, told the Daily Beast that the third party was probably the company providing speech-to-text conversion for Samsung.
She added: "If I were the customer, I might like to know who that third party was, and I'd definitely like to know whether my words were being transmitted in a secure form."
Soon after, an activist for the EFF circulated the policy statement on Twitter comparing it to George Orwell's description of the telescreens in his novel 1984 that listen to what people say in their homes.

In response to the widespread sharing of its policy statement, Samsung has issued a statement to clarify how voice activation works.
It said the privacy policy was an attempt to be transparent with owners in order to help them make informed choices about whether to use some features on its Smart TV sets, adding that it took consumer privacy "very seriously".
Samsung said: "If a consumer consents and uses the voice recognition feature, voice data is provided to a third party during a requested voice command search. At that time, the voice data is sent to a server, which searches for the requested content then returns the desired content to the TV."

It added that it did not retain voice data or sell the audio being captured. Smart-TV owners would always know if voice activation was turned on because a microphone icon would be visible on the screen, it said.
The third-party handling the translation from speech to text has not been named.
Samsung is not the first maker of a smart, net-connected TV to run into problems with the data the set collects. In late 2013, a UK IT consultant found his LG TV was gathering information about his viewing habits.
Publicity about the issue led LG to create a software update which ensured data collection was turned off for those who did not want to share information.

Source:BBC.com

Android App Adware from Google Play infects millions of gadgets


Android users are being warned that several popular apps that were on the official Google Play store appear to have contained hidden code that made malicious ads pop up.

Security firm Avast said that one of the apps involved - a free version of the card game Durak - had been downloaded up to 10 million times, according to Google Play's own counter.

Google has now blocked access.

But one expert noted that the problem might be less widespread than feared.

Avast said that it first became aware of the issue after a member of the public contacted it after carrying out his own investigation into how his Nexus 5 smartphone had come to be infected with malicious code.

The "adware" was causing spurious pop-up messages to appear that had been made to look like system notifications. These told him his phone was running "slow" and that he needed to install new software to fix the problem.

If he followed the on-screen prompts he was then directed to download other apps, only some of which were legitimate.

"You get re-directed to harmful threats on fake pages, like dubious app stores and apps that attempt to send premium SMS behind your back or to apps that simply collect too much of your data for comfort while offering you no additional value," wrote Avast's malware analyst Filip Chytry.

The original apps were said to have held off showing the pop-ups until seven or more days after being installed, which the analyst suggested was intended to mask the fact that they were responsible.

"Most people won't be able to find the source of the problem and will face fake ads each time they unlock their device," he wrote.

"I believe that most people will trust that there is a problem that can be solved with one of the app's advertised 'solutions' and will follow the recommended steps, which may lead to an investment into unwanted apps from untrusted sources."

In addition to the Durak card game, other apps alleged to be involved include:

    A Russian language IQ test, which Google Play indicates had been downloaded up to five million times
    A Russian history educational tool, which Google Play indicates had been downloaded up to 50,000 times

A search by the BBC for other apps made by the same developers revealed dozens more apps, including video games, a psychology guide, wedding planning software and cookery tips - all of which have now been blocked.


The publishers involved have not replied to requests for comment.

A spokesman for Google said: "We're just confirming that all of the apps in the report have been suspended and nothing more."
Inflated numbers

Although Google Play's own site indicated the software had been downloaded many millions of times, one security researcher was cautious about the figures.

"I would take the numbers with a pinch of salt because one thing that malware authors might do is deliberately up the amount of downloads in order to make an app appear more popular than it really is," said Dr Steven Murdoch from University College London's information security research group.

"Google does scan for malware that it knows about and it also has some more advanced techniques to detect malicious behaviour.

"But these don't work 100% of the time and some apps do slip through the checks - and there is a continual cat and mouse game of people looking for malware and the authors trying to bypass the checks.
"


Although Avast is using the publicity it has generated to promote its own security software, Dr Murdoch noted that it too would fail to identify all new types of malware.

One alternative, he said, was to check reviews.

Several people who had downloaded the Durak card game had posted warnings on Google Play as far back as November 2013, that they suspected it was forcing pop-up ads to appear.

"But that's still not going to catch everything," Dr Murdoch added.

"Phone users ultimately have to trust the operating system vendor - whether that's Google or Apple [or someone else] to protect them."


Source-BBC

Commission on Human Rights and Administrative Justice (CHRAJ) website restored after hack.

http://www.remigh.blogspot.com-CHRAJ

In the early hours of Tuesday February 2, 2015, the official website of the Commission on Human Rights and Administrative Justice (CHRAJ) was hacked by a hacker by the name Hani Xavi who is believed to be from Tunisia according to the hack signature on CHRAJ's website after the hack which even included the Tunisian flag at a stadium.

The Head of public affairs of CHRAJ, Mad. Comfort Akosua Edu confirmed that the website was certainly hacked by some Tunisian hackers and also included that all information on the site's server was flawless after the site was restored.
Here is what she said...

"We have alerted national information technology agency to block the site. We have also asked them to initiate investigations to find out what really happened but information on our server is intact" 

Click here to read on the site hack.

Black Hack: Official website of Commission on Human Rights and Administrative Justice (CHRAJ) has been hacked.

http://www.remigh.blogspot.com-hacker
Hacking has been the new trend on Ghanaian official websites now , just a couple of weeks after eleven(11) sites were hacked which included the Government of Ghana website by black hackers without ethics based in Turkey, a hacker from Tunisia has also hacked into the Commission on Human Rights and Administrative Justice (CHRAJ) website.

The hacker left a trace after the black hack on the CHRAJ website.
A signature of the hacker was left on the home page of the CHRAJ website which links him up Tunisia.

This is what was found on the home page of CHRAJ's website, 
 " #Hacked by – Hani Xavi

#Fallaga_Tunisian_Team

#1.2.3 Viva_Tunisie"

He added, a photo of the Tunisian flag at a stadium to the above message, www.chrajghana.com.

Authorities are said to be working hard to restore the website.

The Turkish government has since assured of helping the government of Ghana expose these unethical hackers.

Gmail users can now send and receive money just by $/£ Attachments


Money transmitting is now so easy  since Google introduced "Send money in Gmail". You can now send money to friends and family even if you are just chipping in for lunch or refunding your room mate for your share of the rent or paying back a colleague just by a simple email.
Image Credit-Google.

Sending money in Gmail is just like attaching any other document.
You do this by hovering over the $/£  paperclip at the attachment area after you click to compose an email, enter the amount of money you wish to send, you then add the email address of the person you want to send money to and press send.

However you need a Google Wallet Balance to claim your money if you are receiving for the first time by linking to your debit card or bank account. You can keep the money in your Wallet Balance for later sending, spending on Google Play or instantly transferring into your bank account.

This feature is available in the US and soon to be available for 18 years and above Gmail users in the UK, watch out for the £ icon soon,

Former GREDA boss nabbed in connection with sim box fraud.

http://www.remigh.blogspot.com-greda-boss

An anti-fraud collaboration between the security agencies and telecom service providers in the country has led to the arrest of some persons involved in a SIM Box fraud syndicate in Ghana.

The operation which led to the arrest of the suspects which included the former President of the Ghana Real Estate Developers Association, (GREDA) Alex Tweneboah has been described as one of the major busts in recent times.

The suspects who have been named as Ebenezer Boateng, Victor Owusu, Kwadwo Asare, Alvin Habib, Francis Abbey, Alexander Tweneboah and David Ayikyi were paraded at a press conference together with their equipment in Accra on Monday.

Members of the syndicate according to the investigators, carried out the illegal termination of telephone calls also known as SIM box operations and deprived telecom operators and the state revenue.
Suspects arrested so far

Between October 2010 and August 2014, SIM box fraud cases recorded were 13, resulting in the arrest of 17 suspects made up of Ghanaians and foreign nationals.

One of the kingpins, an Italian arrested in connection with SIM box fraud, has been sentenced to five years’ imprisonment, while the other cases are pending before the courts.


What is SIM Box?

In recent times, fraudulent SIM Box operations have gained prominence in many parts of the world especially in Africa. The fraud takes place when individuals or organizations illegally terminate a voice call which is the preserve of registered licensed network operators, usually at lower cost than the approved rates.

These are then used to channel national or international calls away from licensed international gateway operators and presented as local calls on unlicensed networks.

The net result of this illegal termination of minutes is a significant loss of international call revenue to both mobile network operators and the state.

According to the National Communications Authority (NCA), such a development creates lower customer satisfaction and affects mobile networks through the removal of caller line identity, network congestion on same cell, high authentication attempts over networks as well as long waiting time and difficulty in connection.

Aside these, there is a generally poor quality of services including voice signal delay and an excessive number of dropped calls, according to the NCA.

The scale of SIM box fraud to the NCA is driven by the easy availability of GSM gateway hardware and the wide range of different offers available from mobile network operators, which makes it possible for organizations to effectively go into business, terminating GSM calls and generating thousands in revenue which, should otherwise have been collected by network operators.

Source: Graphiconline
Copyright © 2015 remiGh.blogspot.com