Privacy

Ring Reportedly Outed Camera Owners To Police With a Heat Map (theverge.com) 102

Amazon-owned home surveillance company Ring gave law enforcement a heat map that let police see all devices installed in an area, allowing them to view users down to the street level. CNET first reported the news. From a report: While the feature was removed in July, law enforcement could reportedly use the function to search for the concentration of cameras in a neighborhood, and even see circles drawn around individual user locations. The documents that revealed the feature were obtained by a privacy researcher and shared with the publication. The feature was so specific, according to CNET, that police could essentially obtain the specific location of Ring customers. While police can request videos from users through Ring, the company has denied that it provides information to law enforcement on who, specifically, owns their products. Ring said in a statement to CNET that zooming in on the map "would not provide actual device locations."
Bug

A Bug In Microsoft's Login System Put Users At Risk of Account Hijacks (techcrunch.com) 20

Microsoft has fixed a vulnerability in its login system that could have been used to trick unsuspecting victims into giving over complete access to their online accounts. TechCrunch reports: The bug allowed attackers to quietly steal account tokens, which websites and apps use to grant users access to their accounts without requiring them to constantly re-enter their passwords. These tokens are created by an app or a website in place of a username and password after a user logs in. That keeps the user persistently logged into the site, but also allows users to access third-party apps and websites without having to directly hand over their passwords. Researchers at Israeli cybersecurity company CyberArk found that Microsoft left open an accidental loophole which, if exploited, could've been used to siphon off these account tokens used to access a victim's account -- potentially without ever alerting the user.

CyberArk's latest research, shared exclusively with TechCrunch, found dozens of unregistered subdomains connected to a handful of apps built by Microsoft. These in-house apps are highly trusted and, as such, associated subdomains can be used to generate access tokens automatically without requiring any explicit consent from the user. With the subdomains in hand, all an attacker would need is to trick an unsuspecting victim into clicking on a specially crafted link in an email or on a website, and the token can be stolen. [...] Luckily, the researchers registered as many of the subdomains they could find from the vulnerable Microsoft apps to prevent any malicious misuse, but warned there could be more.

Cloud

Dutch Politician Faces 3 Years In Prison For Hacking iCloud Accounts, Leaking Nudes (zdnet.com) 31

An anonymous reader writes: "Dutch prosecutors have asked a judge for a three-year prison sentence for a local politician who doubled as a hacker and breached the personal iCloud accounts of more than 100 women, stealing and then leaking sexually explicit photos and videos online," reports ZDNet. The hacker (VVD politician Mitchel van der K.) is believed to have been part of the Celebgate (TheFappening) movement. Between 2015 and 2017, van der K. used credentials leaked at other sites to hack into iCloud accounts belonging to acquaintances and Dutch celebrities, from where he stole nudes and sex tapes. Some he leaked online, some he kept for himself. Victims included acquaintances, but also local celebrities, such as Dutch YouTube star Laura Ponticorvo and Dutch field hockey star Fatima Moreira de Melo. After he was arrested, van der K. claimed he was forced to hack his victims by other hackers, an excuse which the prosecution quickly knocked down, pointing out that half of his victims were friends and acquaintances, and not celebrities that would be of interest to other hackers. Days before he was arrested, van der K. was also elected to his city's council, a position from which he resigned.
Security

FaceApp and Other Russian Apps Pose Potential Counterintelligence Threats, Says FBI (axios.com) 22

The FBI warned in a letter to Senate Minority Leader Chuck Schumer (D-N.Y.) Monday that it considers mobile applications developed in Russia, including the popular photo-aging app "FaceApp," to be "potential counterintelligence threats." Axios reports: FaceApp is a Russian-owned mobile application that allows users to upload photos of themselves and see what they may look like at a different age. Experts warned about potential privacy and national security concerns when the app spiked in popularity this past summer, prompting Schumer to request that the FBI and Federal Trade Commission look into the matter in July. "The FBI considers any mobile application or similar product developed in Russia, such as FaceApp, to be a potential counterintelligence threat, based on the data the product collects, its privacy and terms of use policies, and the legal mechanisms available to the Government of Russia that permit access to data within Russia's borders." The agency goes on to say: "Russia's intelligence services maintain robust cyber exploitation capabilities [...] the [Russian Federal Security Service] can remotely access all communications and servers on Russian networks without making a request to ISPs."

The FBI said it will coordinate for notifications and investigations, and will work with applicable task forces if the app is perceived as a threat to "elected officials, candidates, political campaigns or political parties." Schumer said in a statement: "In light of FBI's warning that FaceApp, and similar applications developed in Russia, poses a potential counterintelligence threat to the United States, I strongly urge all Americans to consider deleting apps like FaceApp immediately and proceed with extreme caution when downloading apps developed in hostile foreign countries."

Mozilla

Mozilla Removes Avast and AVG Extensions From Add-on Portal Over Snooping Claims (zdnet.com) 26

Mozilla today removed four Firefox extensions made by Avast and its subsidiary AVG after receiving credible reports that the extensions were harvesting user data and browsing histories. From a report: The four extensions are Avast Online Security, AVG Online Security, Avast SafePrice, and AVG SafePrice. The first two are extensions that show warnings when navigating to known malicious or suspicious sites, while the last two are extensions for online shoppers, showing price comparisons, deals, and available coupons. Mozilla removed the four extensions from its add-ons portal after receiving a report from Wladimir Palant, the creator of the AdBlock Plus ad-blocking extension. Palant analyzed the Avast Online Security and AVG Online Security extensions in late October and found that the two were collecting much more data than they needed to work -- including detailed user browsing history, a practice prohibited by both Mozilla and Google.
Spam

People Worldwide Have Received More Than 26 Billion Spam Calls This Year (techcrunch.com) 113

Do you feel you have been receiving more spam calls of late? You are probably not wrong -- or alone. From a report: The volume of spam calls has grown by 18% globally this year, according to Truecaller. In its annual report published Tuesday, the Stockholm-based firm said users worldwide received 26 billion spam calls between January and October this year -- up from 17.7 billion during the same period last year. The United States remains the eighth most spammed country, where the volume of robocalls increased by 35% this year. In a separate report earlier this year, Truecaller estimated that 43 million Americans were scammed last year and lost about $10.5 billion. The growth is despite the efforts local carriers and authorities have made in the country. Brazil again topped the list for the most spammed country. The culprit behind the increasingly growing spam calls in the country are its own telecom operators and internet service providers. Truecaller said that in the last 12 months, calls from the operators have increased from 32% to 48%.

[...] One of the takeaways from the report is just how complex it is to understand the nature of these spam calls. There is no common thread -- or culprit -- behind these calls. In some markets, such as South Africa (ranked sixth in the report), spammers are mostly making fraudulent tech support calls and conducting job offer scams. Peru, ranked second, and Indonesia, ranked third, have seen spam calls explode in the nation. In Peru, users received more than 30 spam calls in the month. Most of these calls were made by financial services that are looking to upsell credit cards and loans.

Privacy

DHS Wants Airport Face Recognition Scans To Include US Citizens (techcrunch.com) 104

The Department of Homeland Security wants to expand facial recognition scans in the airport to also include citizens, which had previously been exempt from the mandatory checks. TechCrunch reports: In a filing, the department has proposed that all travelers, and not just foreign nationals or visitors, will have to complete a facial recognition check before they are allowed to enter the U.S., but also to leave the country. Facial recognition for departing flights has increased in recent years as part of Homeland Security's efforts to catch visitors and travelers who overstay their visas. The department, whose responsibility is to protect the border and control immigration, has a deadline of 2021 to roll out facial recognition scanners to the largest 20 airports in the United States, despite facing a rash of technical challenges.

But although there may not always be a clear way to opt-out of facial recognition at the airport, U.S. citizens and lawful permanent residents -- also known as green card holders -- have been exempt from these checks, the existing rules say. Now, the proposed rule change to include citizens has drawn ire from one of the largest civil liberties groups in the country. "Time and again, the government told the public and members of Congress that U.S. citizens would not be required to submit to this intrusive surveillance technology as a condition of traveling," said Jay Stanley, a senior policy analyst at the American Civil Liberties Union. "This new notice suggests that the government is reneging on what was already an insufficient promise," he said. "Travelers, including U.S. citizens, should not have to submit to invasive biometric scans simply as a condition of exercising their constitutional right to travel. The government's insistence on hurtling forward with a large-scale deployment of this powerful surveillance technology raises profound privacy concerns," he said.

Programming

Microsoft is Creating a New Rust-Based Programming Language For Secure Coding (zdnet.com) 69

Under Project Verona, Microsoft is working to make Windows 10 more secure by integrating Mozilla-developed Rust for low-level Windows components. "'Memory safety' is the term for coding frameworks that help protect memory space from being abused by malware," reports ZDNet. "Project Verona at Microsoft is meant to progress the company's work here to close off this attack vector." From the report: Microsoft's Project Verona could turn out to be just an experiment that leads nowhere, but the company has progressed far enough to have detailed some of its ideas through the UK-based non-profit Knowledge Transfer Network. Matthew Parkinson, a Microsoft researcher from the Cambridge Computer Lab in the UK who's dedicated to "investigating memory management for managed programming languages," gave a talk last week focusing on what the company is doing to address these memory issues.

In the talk, Parkinson discussed the work Microsoft has done with MemGC, which is short for Memory Garbage Collector, for Internet Explorer (IE) and Edge. MemGC addressed vulnerabilities in the standard browser feature known as a Document Object Model (DOM), a representation of the data used by browsers to interpret web pages. Google's elite Project Zero hackers were impressed with Microsoft's MemGC after canvassing major browsers. [...] The other class of bugs Microsoft is working on to address relates to uninitialized memory in a way that also doesn't kill performance. [...] Parkinson said Microsoft is rewriting some "targeted" components in Rust. His talk focused on language design and compartmentalization. "If we want compartments, and to carve up the legacy bits of our code so [attackers'] exploit code can't get out, what do we need in the language design that can help with that?" This is Project Verona and Parkinson said it was the first time he'd discussed the project, which will be made open source "soon". It is a new language for what Microsoft is calling "safe infrastructure programming."
"The challenge for Microsoft is dealing with the 'application spectrum,' which spans from C# for desktop apps through to C and C# for Exchange, ASP.NET, Azure, and device drivers, to deep Windows components like memory management and boot loaders and the Windows kernel hardware abstraction layer (HAL)," the report says.

"The ownership model in Verona is based on groups of objects, not like in Rust where it's based on a single object," said Parkinson. "In C++ you get pointers and it's based on objects and it's pretty much per object. But that isn't how I think about data and grammar. I think about a data structure as a collection of objects. And that collection of objects as a lifetime. So by taking ownership at the level of ownership of objects, then we get much closer to the level of abstraction that people are using and it gives us the ability to build data structures without going outside of safety."
Security

Vulnerability In Fully Patched Android Phones Under Active Attack By Bank Thieves (arstechnica.com) 98

An anonymous reader quotes a report from Ars Technica: A vulnerability in millions of fully patched Android phones is being actively exploited by malware that's designed to drain the bank accounts of infected users, researchers said on Monday. The vulnerability allows malicious apps to masquerade as legitimate apps that targets have already installed and come to trust, researchers from security firm Promon reported in a post. Running under the guise of trusted apps already installed, the malicious apps can then request permissions to carry out sensitive tasks, such as recording audio or video, taking photos, reading text messages or phishing login credentials. Targets who click yes to the request are then compromised.

Researchers with Lookout, a mobile security provider and a Promon partner, reported last week that they found 36 apps exploiting the spoofing vulnerability. The malicious apps included variants of the BankBot banking trojan. BankBot has been active since 2017, and apps from the malware family have been caught repeatedly infiltrating the Google Play Market. The vulnerability is most serious in versions 6 through 10, which account for about 80% of Android phones worldwide. Attacks against those versions allow malicious apps to ask for permissions while posing as legitimate apps. There's no limit to the permissions these malicious apps can seek. Access to text messages, photos, the microphone, camera, and GPS are some of the permissions that are possible. A user's only defense is to click "no" to the requests.
"The vulnerability is found in a function known as TaskAffinity, a multitasking feature that allows apps to assume the identity of other apps or tasks running in the multitasking environment," reports Ars Technica. While Google has removed the [unnamed] malicious apps from its Play Store, according to Promon, the vulnerability is still unfixed in all versions of Android.

"Promon is calling the vulnerability 'StrandHogg,' an old Norse term for the Viking tactic of raiding coastal areas to plunder and hold people for ransom," the report adds. "Promon researchers said they identified StrandHogg after learning from an unnamed Eastern European security company for financial institutions that several banks in the Czech Republic reported money disappearing from customer accounts."
Software

Putin Signs Law Making Russian Apps Mandatory On Smartphones, Computers (reuters.com) 64

Russian President Vladimir Putin on Monday signed legislation requiring all smartphones, computers and smart TV sets sold in the country to come pre-installed with Russian software. Reuters reports: The law, which will come into force on July 1 next year, has been met with resistance by some electronics retailers, who say the legislation was adopted without consulting them. The law has been presented as a way to help Russian IT firms compete with foreign companies and spare consumers from having to download software upon purchasing a new device. The country's mobile phone market is dominated by foreign companies including Apple, Samsung and Huawei. The legislation signed by Putin said the government would come up with a list of Russian applications that would need to be installed on the different devices.
China

All New Cellphone Users In China Must Now Have Their Face Scanned (technologyreview.com) 69

An anonymous reader quotes a report from MIT Technology Review: Customers in China who buy SIM cards or register new mobile-phone services must have their faces scanned under a new law that came into effect yesterday. China's government says the new rule, which was passed into law back in September, will "protect the legitimate rights and interest of citizens in cyberspace." It can be seen as part of an ongoing push by China's government to make sure that people use services on the internet under their real names, thus helping to reduce fraud and boost cybersecurity. On the other hand, it also looks like part of a drive to make sure every member of the population can be surveilled. The Financial Times reported yesterday that tech companies in China are helping to create influential United Nations standards for the facial recognition technology, which will help shape rules on how facial recognition is used around the world.
IOS

iOS Apps Could Really Benefit From the Newly Proposed Security.plist Standard (zdnet.com) 13

Security researcher Ivan Rodriguez has proposed a new security standard for iOS apps, which he named Security.plist. From a report: The idea is simple. App makers would create a property list file (plist) named security.plist that they would embed inside the root of their iOS apps. The file would contain all the basic contact details for reporting a security flaw to the app's creator. Security researchers analyzing an app would have an easy way to get in contact with the app's creators. Rodriguez said the idea for Security.plist came from Security.txt, a similar standard for websites, that was proposed in late 2017. Security.txt is currently going through an official standardization process at the Internet Engineering Task Force (IETF), but it has been widely adopted already, and companies like Google, GitHub, LinkedIn, and Facebook, all have a security.txt file hosted on their sites, so bug hunters can get in touch with their respective security teams. Rodriguez, who is an amateur bug hunter in iOS apps, said he decided to propose a similar thing for iOS apps because getting in touch with an app's dev or security team has been a problem in the past. "I spend most of my free time poking mobile applications which has lead me to find many vulnerabilities and I have yet to find one that has an easy way to find the correct channel to responsibly disclose these issues,"Rodriguez told ZDNet.
Security

Now Even the FBI is Warning About Your Smart TV's Security (techcrunch.com) 126

If you just bought a smart TV on Black Friday or plan to buy one for Cyber Monday tomorrow, the FBI wants you to know a few things. From a report: Smart TVs are like regular television sets but with an internet connection. With the advent and growth of Netflix, Hulu and other streaming services, most saw internet-connected televisions as a cord-cutter's dream. But like anything that connects to the internet, it opens up smart TVs to security vulnerabilities and hackers. Not only that, many smart TVs come with a camera and a microphone. But as is the case with most other internet-connected devices, manufacturers often don't put security as a priority. That's the key takeaway from the FBI's Portland field office, which just ahead of some of the biggest shopping days of the year posted a warning on its website about the risks that smart TVs pose. "Beyond the risk that your TV manufacturer and app developers may be listening and watching you, that television can also be a gateway for hackers to come into your home. A bad cyber actor may not be able to access your locked-down computer directly, but it is possible that your unsecured TV can give him or her an easy way in the backdoor through your router," wrote the FBI. The FBI warned that hackers can take control of your unsecured smart TV and in worst cases, take control of the camera and microphone to watch and listen in.
Security

Millions of SMS Text Messages Exposed In Unencrypted Database (techcrunch.com) 17

"A massive database storing tens of millions of SMS text messages, most of which were sent by businesses to potential customers, has been found online," reports TechCrunch. The database belongs to a company that works with over 990 cell phone operators and reaches more than 5 billion subscribers around the world, according to the researchers.

TechCrunch writes: The database is run by TrueDialog, a business SMS provider for businesses and higher education providers, which lets companies, colleges, and universities send bulk text messages to their customers and students. The Austin, Texas-based company says one of the advantages to its service is that recipients can also text back, allowing them to have two-way conversations with brands or businesses.

The database stored years of sent and received text messages from its customers and processed by TrueDialog. But because the database was left unprotected on the internet without a password, none of the data was encrypted and anyone could look inside. Security researchers Noam Rotem and Ran Locar found the exposed database earlier this month as part of their internet scanning efforts... Many of the messages we reviewed contained codes to access online medical services to obtain, and password reset and login codes for sites including Facebook and Google accounts...

One table alone had tens of millions of messages, many of which were message recipients trying to opt-out of receiving text messages.

IT

Ask Slashdot: Is Your Company Using Linux Desktops? 198

SomeoneFromBelgium writes: Yesterday I spoke to a friend of mine who works for a company developing mostly integrated network solutions which are purely Linux-based. He complained that he was unable to convince his IT department to provide him and his fellow developers and testers with a Linux desktop. They stated that "it was more secure when using a VM".

We both agreed that the more likely problem is that the IT department is solely geared towards a Windows desktop environment and that they have neither the skills nor the inclination to support any other platform.

This got me wondering: is this also your experience?

I bet Slashdot's readers have stories to tell, with enlightening experiences in corporate workplaces over the years gone by. So feel free to share your thoughts, opinions, and anecdotes in the comments.

And is your company using Linux desktops?
Communications

SMS Replacement is Exposing Users To Text, Call Interception Thanks To Sloppy Telecos (vice.com) 32

A standard used by phone carriers around the world can leave users open to all sorts of attacks, like text message and call interception, spoofed phone numbers, and leaking their coarse location, new research reveals. From a report: The Rich Communication Services (RCS) standard is essentially the replacement for SMS. The news shows how even as carriers move onto more modern protocols for communication, phone network security continues to be an exposed area with multiple avenues for attack in some implementations of RCS. "I'm surprised that large companies, like Vodafone, introduce a technology that exposes literally hundreds of millions of people, without asking them, without telling them," Karsten Nohl from cybersecurity firm Security Research Labs (SRLabs) told Motherboard in a phone call.

SRLabs researchers Luca Melette and Sina Yazdanmehr will present their RCS findings at the upcoming Black Hat Europe conference in December, and discussed some of their work at security conference DeepSec on Friday. RCS is a relatively new standard for carrier messaging and includes more features than SMS, such as photos, group chats, and file transfers. Back in 2015, Google announced it would be adopting RCS to move users away from SMS, and that it had acquired a company called Jibe Mobile to help with the transition. RCS essentially runs as an app on your phone that logs into a service with a username and password, Nohl explained.

Security

Hacker Stole Unreleased Music and Then Tried To Frame Someone Else (zdnet.com) 41

US authorities charged a Texas man this week for hacking into the cloud accounts of two music companies and the social media account of a high-profile music producer, from where he stole unreleased songs that he later published online for free on public internet forums. From a report: When the man realized he could be caught, he contacted one of the hacked companies and tried to pin the blame on another individual. According to court documents published on Monday by the Department of Justice, the suspect is a 27-year-old named Christian Erazo, from Austin, Texas. US authorities say that Erazo worked with three other co-conspirators on a series of hacks that took place between late 2016 and April 2017. The group's primary targets were two music management companies, one located in New York, and the second in Los Angeles. According to investigators, the four hackers obtained and used employee credentials to access the companies' cloud storage accounts, from where they downloaded more than 100 unreleased songs. Most of the data came from the New York-based music label, from where the Erazo and co-conspirators stole more than 50 GBs of music. Erazo's indictment claims the group accessed the company's cloud storage account more than 2,300 times across several months.
Security

Only a Few 2020 US Presidential Candidates Are Using a Basic Email Security Feature (techcrunch.com) 88

Just one-third of the 2020 U.S. presidential candidates are using an email security feature that could prevent a similar attack that hobbled the Democrats during the 2016 election. From a report: Out of the 21 presidential candidates in the race, according to Reuters, only seven Democrats are using and enforcing DMARC, an email security protocol that verifies the authenticity of a sender's email and rejects spoofed emails, which hackers often use to try to trick victims into opening malicious links from seemingly known individuals. It's a marked increase from April, where only Elizabeth Warren's campaign had employed the technology. Now, the Democratic campaigns of Joe Biden, Kamala Harris, Michael Bloomberg, Amy Klobuchar, Cory Booker, Tulsi Gabbard and Steve Bullock have all improved their email security. The remaining candidates, including presidential incumbent Donald Trump, are not rejecting spoofed emails. Another seven candidates are not using DMARC at all.
Security

Hidden Cam Above Bluetooth Pump Skimmer (krebsonsecurity.com) 113

Brian Krebs: Tiny hidden spy cameras are a common sight at ATMs that have been tampered with by crooks who specialize in retrofitting the machines with card skimmers. But until this past week I'd never heard of hidden cameras being used at gas pumps in tandem with Bluetooth-based card skimming devices. Apparently, I'm not alone. "I believe this is the first time I've seen a camera on a gas pump with a Bluetooth card skimmer," said Detective Matt Jogodka of the Las Vegas Police Department, referring to the compromised fuel pump pictured here.

Image.

It may be difficult to tell, but the horizontal bar across the top of the machine (just above the 'This Sale $' indicator) contains a hidden pinhole camera angled so as to record debit card users entering their PIN.

IT

A Firmware Update Removed the Noise-Cancelling Function From Bose's Noise-Cancelling Headphones. No Word From Bose if It Plans To Fix It (theregister.co.uk) 138

Owners of Bose QuietComfort 35 headphones are still trying to get the company to either fix or roll back a firmware update that removed noise-cancelling functions from their over-ear gear. From a report: The problems date back to July and some owners seem to have managed to get Bose to exchange their cans for the company's shiny new 700 headphones. We were contacted by a reader who was first given a set of version II headphones when his V1 set were borked. When the updated firmware borked them as well, he declined the offer of a replacement set and was given a pair of 700s. Firmware version 4.5.2 was fingered as the main culprit. Like all Bose gear, the cans don't come cheap -- they'll set you back $335 to be precise, or $450 for a pair of limited edition white 700s. Pissed-off punters have filled a deafening 182 pages of Bose's support forums with complaints. One has even set up a Change.org petition to beg for a pause on firmware updates until a fix is found.

Slashdot Top Deals