Tuesday, July 16, 2013

Android Phones Vulnerable to Hackers

Android Vulnerability Patched



Android is the most popular mobile operating system in the world, installed on three quarter of a billion devices. Having a master key to all of those would give a hacker near-total control in the mobile world. Fortunately, this doomsday scenario has been narrowly avoided.


Bluebox Labs, a computer security company, recently discovered http://bluebox.com/corporate-blog/bluebox-uncovers-android-master-key/ a vulnerability in the Android operating system that leaves “99%” of Android users open to the possibility of malicious software. But the most shocking thing about this discovery is not only the breadth of the vulnerability, but its depth as well.

The “Master Key” vulnerability, if used by a hacker, would allow them to access all of a user's data on their phone. This includes text messages, account access, and photos. It is unknown at this time the full extent of this vulnerability's use.

This vulnerability makes it possible for a hacker to change the code of an app without modifying its cryptographic signature. What this means in practical terms is that a hacker could develop an app and deliver it to the Google Play store and have it downloaded by people wanting to use its functionality. Those who download the app would confirm the app's access to the file system. Then without anyone's knowledge, the hacker could then change the code of the app to act as a trojan horse, gathering data and personal information from the user's phone. This process would be invisible to the user, aside from a slight slow-down.
[pullquote]"We have not seen...any exploitation"[/pullquote]
Now the good news is that the vulnerability has already been patched by Google. They've shipped it to providers like MetroPCS and Verizon, who will deploy the update to their users' phones in the next few weeks.

More good news: According to a statement http://www.zdnet.com/google-releases-fix-to-oems-for-blue-security-android-security-hole-7000017782/ sent by Gina Scigliano, Google's Android Communications Manager, “We have not seen any evidence of exploitation in Google Play or other app stores via our security scanning tools.” So in the meantime while you're waiting for your phone to update, don't download any sketchy apps. If you're worried that you may have been infected already, you can install https://play.google.com/store/apps/details?id=com.bluebox.labs.onerootscanner to check for infection.

 

Friday, July 12, 2013

Can Facebook Give Me a Virus?

Can Facebook Give Me A Virus?



One of the questions I get asked a lot is, “can Facebook give me a virus?” With over a billion people logging in at least once a month, it’s no surprise that criminals are constantly working to find ways to get access to and exploit users. Here are the most common ways you can encounter malware from using Facebook.

The good news is that just cruising Facebook, reading your friend’s posts in your newsfeed and updating your timeline can’t give you a virus. However, many posts include links to other pages, either to read an article, view a video, get a coupon, etc... Many links on Facebook, especially those posted to open community fan pages, will send you to pages infected with viruses or malware and there’s where you run into trouble.

It used to be that getting a virus or spyware required downloading an infected file or installing a malicious program. So long as you didn’t download suspicious programs or attachments or visit file sharing sites, you were generally safe surfing the net. These days, viruses and spyware have evolved to worm their way into your system just by going to an infected webpage.

Every time there’s a big news story (like when Osama Bin Laden was killed or during a highly publicized national event or tragedy) infected links pop up all over Facebook. In some cases, you’ll be “tagged” to a post with a link claiming to be to a news story or video. Clicking the link often leads to a blank page and users think they’ve simply encountered a bad link, but they’ve already been infected. Be wary – particularly if you don’t know the original person that posted the link. It’s best to update your Facebook settings so that you are notified and have the ability to allow or disallow any tagging of your profile by others. Then you can elect “don’t allow” any time you’re tagged in a post that you don’t know or trust.

Be very cautious about links that make promises. The “Win a free iPad!” or “Get a free Starbucks gift card!” posts are almost always a scam. Either they’re an attempt to lure you to provide personal information (data mining) or will direct you to a web page that’s infected with malware.
[pullquote]Be very cautious about links that make promises.[/pullquote]

The nature of Facebook is such that many posts with malicious links appear to have generated from your friends, which gives victims a false sense of security. In many cases, the poster doesn’t realize that the link directs to an infected site. Even more common, clicking on the malicious link or installing a spyware-laced app will result in an auto-post to the victim’s timeline or blast messages to their contact list, leading their friends to see a recommendation to follow the link and further the spread of infection.

Those looking to infect users also frequently use links to videos with the tag “is this you?” and a suggestion that you were caught on film doing something unexpected. Or simply a link to a video that seems spectacular or intriguing. The link either directs you to an infected page, requires that you install an application to view the video (you’re actually installing malicious code), or asks for personal information before allowing you to view the material. Check the address listed below the video before you click to be sure that any video link you follow directs you to a reputable site that you recognize, like YouTube, CNN, etc.

Keep in mind that the ads posted to the margins and “sponsored links” take you outside of Facebook, exposing you to risk of exposure to infected weblinks. While it’s less likely that a link that Facebook approved to be included in an ad would be infected, you should exercise caution whenever you click a link that directs you off of a Facebook page.
[pullquote]Never copy and paste a command prompt into your browser.[/pullquote]Another source of malicious code is rogue apps that lure you with promises to “see who’s been looking at your profile,” or to get that (non-existent) “dislike” button. In some cases, you’ll be prompted to copy and paste script into your browser to install the application. Never, under any circumstances, follow instructions to copy and paste a command prompt into your browser. These will often reference java in the first word or two of text.

If you encounter a page that prompts you to re-login to your Facebook account, check the address in your browser bar. Criminals can create pages that look exactly like Facebook and when you enter your username and password they’re able to capture your account. Close any page that doesn’t start with www.facebook.com – if you see anything between facebook and .com, don’t trust the page.

 

Thursday, July 11, 2013

Dropbox Announcement Promises Much

Dropbox Announcement: They're "Replacing the Hard Drive"



With the amount of devices that the average person works on, it can take a lot of effort to keep track of your files. I can't count the number of times I've hunted for the latest version of a file on my phone, computer, or in the cloud. Today, Dropbox announced their plan to put an end to all of that. The Dropbox Platform, announced at their developer conference, aims to “replace the hard drive.”

Most of us are already familiar with the basic premise of the Dropbox Platform: if you've ever edited anything online, and then accessed that same file from another computer, you've used basic cloud sync features. Dropbox hopes to make “sync the new save.” Instead of having files that only exist in one location, like your phone or computer, they hope to make all of your files available wherever you need them.


The actual announcement was full of technical details for us nerds, but what it boils down to is this: Dropbox is providing Nerds and programmers with new tools to build apps for you. These apps will be able to share the same data via your DropBox account. That means your email, documents, and even progress in your Angry Birds games, will be available whenever and wherever you want them.

At launch, companies using this technology include popular services such as Shutterstock, Yahoo! Mail, and FedEx, as well as a number of smaller companies. As developers have a chance to use these tools more, we'll start to see more apps include the ability to save to Dropbox. Dropbox hopes to integrate this feature into as many apps as possible.

The three components of the feature are the Sync API, the Datastore API, and Drop-Ins. The two APIs allow programmers to interact with a user's Dropbox data without actually giving them access to the data. Basically it's a set of rules designed so that programmers can help you, but not hack you. The third component, Drop-Ins, are another set of tools for developers that speed up the development process, so that the time before their app has Dropbox functionality is reduced, and takes less work.

Following concerns over users' privacy in the wake of the NSA PRISM scandal, Dropbox has stated “We’ve seen reports that Dropbox might be asked to participate in a government program called PRISM. We are not part of any such program and remain committed to protecting our users’ privacy.”

Also announced at the conference was that the Dropbox service has now grown to 175 million users.

 

 

Wednesday, July 10, 2013

5 Easy Ways to Prevent Identity Theft

Prevent Identity Theft and Protect Yourself



The FTC estimates that as many as 9 million Americans have their identities stolen each year. According to data compiled by Zone Alarm, maker of antivirus and firewall software, identity theft results in an average cost to victim of $4,841 and takes, on average, 33 hours to resolve. With more and more of our personal information available online, it’s imperative that you take steps to protect yourself online.


Buyer beware. For as little as $30 in web hosting fees, criminals can set up fake online shop fronts to lure consumers into submitting their personal information and credit account numbers. Be wary of online retailers that you’ve never heard of, particularly if they’re offering a popular item at a lower-than-expected price.

If you can’t resist the deal, contact your credit card company to inquire if they offer one-time-use card numbers that you can use for vendors you don’t trust, or consider using a Visa or Mastercard gift card to protect your permanent account number. Never supply unnecessary personal information like your social security number, driver’s license number, or date of birth when completing an online retail transaction.

Pump up your password. I know, I know, I’m a broken record with this one. But if you’re one of the millions of Americans using the most popular passwords, such as “password,” “trustno1,” “abc123,” “monkey” or “letmein” (for the top 25 worst passwords, check out the list at SplashData: http://splashdata.com/press/pr121023.htm), you’re putting yourself at risk. Morgan Slain, CEO of SplashData (a provider of password management applications) explains, “Hackers can easily break into accounts just by repeatedly trying common passwords.” He recommends using an online password management tool. I like Lastpass (https://lastpass.com/) which can create and store unique, difficult to crack passwords for every site you visit online.

Secure your Smartphone. As more people acquire Smartphones, our personal information is going mobile. With instant access to email, social media accounts and often banking and credit account logins, Smartphones are an identity thief’s goldmine. Make sure that you password-protect the home screen to make it a little harder for a would-be criminal to access your data.

Consider storing account numbers and personal data that you regularly access (like bank account and passport numbers or alarm codes) in a cloud-based data vault program like that offered by Personal (www.personal.com/, free for iPhone and Android). Accessing the vault is password protected so it’s more secure than using notes, emails or texts stored on your phone.

Take notice of data breach notifications. With all the credit card offers, balance transfer promotions and junk mail sent by the average financial institution, it’s easy to tune out a form notification that your account data may have been compromised, but it’s important to take note. According to the “2013 Identity Fraud Report” compiled by Javelin Strategy & Research, almost 1 out of every 4 consumers that received a data breach notice letter became a victim of identity fraud. Of particular concern: “consumers who had their Social Security number compromised in a data breach were five times more likely to be a fraud victim than an average consumer.”

Take action. While the majority of identity theft activities are identified by third parties (55% vs. 45% discovered by consumers), it’s important to be proactive in your monitoring of account activity. The sooner you discover the fraud and take steps to close accounts and notify the appropriate parties, the less you stand to lose.

Tuesday, July 9, 2013

Protect Gadgets from Heat this Hot Summer

Protect Gadgets from Heat



Are you enjoying the 100+ degree summer temperatures? I am pretty sure your gadgets are not. Summer heat and activities can be brutal on electronic devices, but no one wants to leave them behind when taking the kids to the beach or the lake. There are ways to protect your phone, camera and portable media player from summer mayhem. DriveSavers (www.drivesaversdatarecovery.com), an expert in the data recovery industry since 1985, has some advice to share on the subject.


Summer sunburn. The baking sun will exact its toll on your skin, and it can be equally brutal to your electronic devices. DriveSavers advises, "Avoid leaving your devices out in direct sunlight. Electronics are not made to withstand high temperatures and may shut down when they get too hot, only to restart once they have cooled. When left in high heat for a period of time, these devices can fail and lose all data stored on them. To steer clear of these circumstances, place them in a beach bag or wrapped in a dry towel to keep them cool."

If you find your device has overheated, don't panic. Move it to a cool place (not the fridge or freezer - moisture is worse than the heat). Try holding it in front of the A/C vent in your car. Let it become cool to the touch, then attempt to power it back on.

Use caution when you're poolside. Again, from DriveSavers: "The splash of your child's big dive into the pool or the practical prank of pouring water on Mommy while she sunbathes can be casual occurrences that could cause water damage to your device. It is important to monitor where your device is in location to water and to secure your device with an appropriate protective case, whether it's a fancy waterproof case or a Ziploc bag."

If your device is dropped in the pool, power it down and dry it off – resist the urge to immediately try to turn it on as you can cause more damage. Remove the battery and SIM card, draining as much liquid as possible from the inside. Place any parts that encountered water in a Ziploc baggie full of uncooked rice for at least 48 hours to pull moisture from it. Then, reinstall the SIM card and battery and attempt to power it back on. If it doesn't back power on, consult your mobile phone company or an electronics repair professional.

Protect your photos and memory cards. According to DriveSavers, there are three major ways to avoid and prevent data loss.

1. "Never trust your camera as the single source to safeguard all of your photos. It is always best to transfer the images from the camera's flash memory to a computer hard drive as soon as possible. We recommend not deleting images or reformatting the memory card while it is still in the camera. Wait until all photos are transferred and verified before you clear your camera's memory card."

2. "Keep in mind that flash memory cards can be used about 1,000 times before they start to wear out. The best way to protect yourself and your irreplaceable images is by backing up your data. This will help guard against data loss when (not if) your hard drive fails. It's also recommended that you make additional copies of your backup media and keep a duplicate of it off site in a secure location. You can never be too safe with your memories."

3. "Carrying (memory) cards in your pocket can cause static buildup that can zap the card, making it unreadable.” DriveSavers recommends that you use the plastic case that came with the memory card. Better yet, store filled cards in your camera case so you can keep them out of the sun, sand and heat.

Blast away sand and dirt. Outdoor activities expose handheld devices to sand, dust and grime. Tiny particles can become embedded in crevices and scratch glass, lenses and hard surfaces. Don’t rub with a towel or sanitizing wipe - use a canister of compressed air to blow away debris.

If, despite all your best efforts, you discover a possible data loss, don't panic. Professionals have lots of tricks to help you recover your data. I once thought I’d lost all our photos from Hawaii due to an unreadable camera memory card, but the data was still there and I got our pictures back. Don't hesitate to consult an expert should you fall "victim" to summer mayhem.

&nbs

Tuesday, July 2, 2013

HD Antenna Makes it Easy to Get Rid of Cable

Get Rid of Cable with an HD Antenna



One of the home theater questions I get asked most often is how to get rid of cable or satellite bills without losing TV entirely. I’ve highlighted how to stream content over the Internet to your TV or computer, but many readers balk at the idea of losing real-time network TV, particularly sports and local news. If you have an HDTV with a built-in digital tuner, an HD Antenna may be the secret to ditching your cable or satellite provider once and for all.

In most metropolitan areas of the country you can receive high-def broadcasts from ABC, NBC, CBS, Fox and PBS over the air, but the trick is getting your TV to receive them and translate them into viewable content. For that you need a TV with a built-in HD tuner (or an HDTV-ready TV and an external high-def tuner) and an HDTV antenna.

While signals broadcast over the air are digital, they aren’t all HD. What’s available in your area is decided by the individual broadcast stations. If you live in an area where over-the-air HD content is available, an HD antenna will convert the signal into content your HD-capable TV can process.


HDTV signals are “line of sight,” so mounting an antenna on your roof will usually result in the best reception due to less physical interference. However, before you climb up on the roof to install an outdoor antenna, it’s worth trying out an indoor antenna. If you happen to live close to a broadcast tower and don’t have too much interference (think walls, trees, surrounding buildings, etc…) an indoor antenna may get you a decent picture.

If you’ve determined that an indoor antenna isn’t going to cut it to get you a clear and reliable picture, you’ll have to decide if you want to install an outdoor HD antenna.

There are several different kinds of antenna. It’s important to ensure that you choose the one that will allow you to receive the channels you want. The Consumer Electronics Association (CEA) and the National Association of Broadcasters (NAB) have created a color-coded system in which they classify the available outdoor antenna types. Use AntennaWeb (www.antennaweb.org/) to find the best outdoor antenna for your location and “viewing preferences.” You may be surprised at the variety of channels broadcast over the air – from TBN to Telemundo.

For a detailed walk through on how-to install an outdoor HD Antenna, check out CNET’s “Weekend Project: Free HDTV with an outdoor antenna”: http://reviews.cnet.com/4520-11249_7-6264597-4.html

Note that there are several perks that are included with your cable or satellite subscription that you’ll no longer get automatically if you cancel. The channel guide is supplied by your cable or satellite provider. To see what’s coming on you can view a list of free local TV listings online at Titan TV (www.titantv.com/). With an Internet-capable TV, you may even be able to use the TV’s browser to scroll through channel listings on your big screen.

Most cable and satellite providers include DVR service with the cable or satellite box (though there’s often an additional monthly fee for it). You can purchase a standalone DVR such as the TiVo Premiere (https://www3.tivo.com/store/premiere.do, $149) which lets you record shows and stream content from Netflix, Hulu Plus, Amazon Instant Video and more, but you’ll have to pay a monthly service fee (starting at $14.99/month with a one year commitment). Make sure to confirm that the DVR model you select is compatible with an HD antenna before you buy.

Finally, access to premium channels like HBO, Showtime, or Stars is only available via a cable or satellite provider.

 

How Your Teen is Hiding Online

What your Teen is Hiding Online: Part 2



According to a study commissioned by Internet Technology specialist McAfee, “The Digital Divide: How the Online Behavior of Teens is Getting Past Parents,” more than half of teens feel confident that they know how to hide what they do online and 71% have actually done something to hide their online behavior - a frightening statistic for parents struggling to keep up with the technology that their teens use every day. Yet half of teens polled said they’d change their online behaviors if they knew their parents were watching. Here’s how to learn if your kid is hiding something with the help of technology and what to do if they are.


The first step to determining if your teen is trying to cover their tracks is to learn the most common methods used to hide online activity. One red flag is if she quickly minimizes the browser window when you approach or rapidly changes pages when you come close (nearly half of teens polled cop to this). It’s helpful if you keep the family computer in a public area so that you can keep a more active eye on Internet browsing, or just ask her to pull back up what she was looking at.

Openly communicating about what sites you feel should be off-limits and what amount of privacy you’re comfortable extending to your child is imperative to setting expectations. This is a good opportunity to discuss why furtive browsing makes you uncomfortable.

More than half of teens polled cleared the browser history after going somewhere online that they didn’t want their parents to know about. This one’s pretty obvious – if you check the “History” option under your browser’s settings, there should be a lengthy list showing every page visited in recent days/weeks. An empty list tells you that steps were taken to intentionally hide online activity.

The easiest answer is to ask your teen why they felt it was necessary to hide where they went online. Begin the dialog about what sites you feel are unacceptable and why. If your kid felt it was necessary to clear the site from the browser history, they probably know they shouldn’t be going there.

Another method for hiding online activity is to use an un-monitored, internet-enabled mobile device (21% of teens polled say they’ve done it). From Smartphones to iPods to tablets, it seems just about everything can access the Internet these days, and mobile devices are particularly difficult for parents to keep tabs on.

Even more challenging, there are ways to hide apps, photos, videos, messages and phone calls by using apps or the hide option coded into Android. Many of these applications have names like Vault or Locker (for example, Vault, AppLock and PhotoLocker), so if you see an app on your child’s mobile device with this sort of name, open it. In many cases, the app will prompt you to enter a password to access content hidden in the folder. Even more difficult to identify, Hide it Pro (http://hideitpro.com/, free for Android or iPhone) appears on the phone under the name “Audio Manager.” When you open the app, it looks like a simple audio management tool, but pressing and holding the title bar will cause the password prompt to appear to unlock hidden content.

If you find your teen has hidden content on their mobile device, ask him or her to unlock the app or folder and show you what they’ve chosen to hide. Talk to your child about why they feel they need to hide things on their phone. Maybe they have photos or videos they want to keep private that may not necessarily be inappropriate, or don’t want friends reading their texts. If you do find that they’re storing inappropriate content or apps, it’s time to have a frank discussion about the dangers of sharing private images or information with others.

It’s best to establish your expectations for online activity early. When you hand your child his first internet-enabled device, discuss your plans for keeping an eye on where he goes and why you feel it’s an important step to keeping him safe. Consider enabling restrictions so that installing an app requires you to enter a passcode to unlock the function, allowing you ultimate oversight over the apps your child can use.

While there are some great parental monitoring software tools available (NetNanny and SpectorPro are some of our favorites), talk with your teen first. Just knowing you are actively involved may be enough to keep your kid off the “wrong side” of the web.