Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, November 21, 2011

The Bad Guys are Going After Android... Malware Expands 500% since July 2011

Lookout Logo.png
If you are an Android user and arent' currently using some type of anti-malware protection such as Lookout Mobile Security, you probably should be looking into it.
States from Juniper Networks research has shown an increase in malware of 472% since July 2011 with the majority of this activity coming in September & October. That's right, the last 2 months have shown a tremendous amount of growth in Android malware.
It seems that most of the threat comes from criminal elements that are looking to steal data. This is usually done by taking legitimate apps, hacking them, and then putting them into the Android MarketPlace appearing as the legitimate app. However, when installed they carry with them a dangerous trojan horse payload.
The problem is exploding because Google isn't as controlling of their apps as Apple is. They don't really analyze apps that are submitted and don't control what apps can be installed. Because of those 2 points , the bad guys are exploiting the weaknesses to their advantage.
As an Android user, I've used Lookout almost since day 1. I immediately installed it on my Galaxy II that I'm testing as well. Lookout scans the phones daily and also scans all apps installed or updated to make sure they are safe. If you are an Android user, I'm highly recommending you look at a program like t his... especially if you are using your phone for banking or online shopping.

Friday, September 30, 2011

What Your Mobile Provide *Really* Knows About You

Pondering.jpg

Just because you're paranoid doesn't mean they're not out to get you...

I've often said that my personal privacy is dead. My Tahoe with OnStar tracks everywhere I go and I'm sure GM has a record of every time I've called OnStar for directions and where they sent me. Toll booths using EZ Pass know when & where your car crossed the toll line. Time Warner knows where I surf & what channels I watch. SiriusXM knows what channels I listen to & what songs are played. Tivo tracks what shows I record & what channels I view.

And then there is my phone... Sprint knows where I've been, who I've called, who has texted me... you name it. We are all so dependent on our phones that they have become central to our lives. But did you ever really consider what your wireless company knows about you and how long they keep it? Would you like to know?

Well, thanks to the American Civil Liberties Union of North Carolina, you can now find out. The group filed a Freedom of Information Act claim and managed to get all the info from the Justice Department.

Curious about what *they* know about you? Take a look at the document called "Retention Periods of Major Cellular Service Providers". This link is courtesy of Wired.com, but you can find the document in other parts of the Internet as well.

Tuesday, June 14, 2011

A Self Erasing Hard Drive? Toshiba Gives Security a Big Boost

Toshiba Self Eraser.jpeg
Imagine the following scenario: Someone steals one of your computers. However, you are security conscious & have the BIOS password protected. This means that the system will not even begin to boot until the correct password is given. This is pretty good security until the thief removes the hard drive and puts it in a different machine or a portable hard drive enclosure where it will be treated as an auxiliary drive. Once that happens, your data is plain to see.
However, Toshiba has put a wrinkle in the above scenario with hard drives that will totally wipe themselves clean if they are connected to a different machine.
These Self Erasing Drives or SED for short encrypts all data on the drive & then unecrypts it when ever access is needed. If the drive is accessed by another machine, the drive senses this and destroys the keys. This leaves the data encrypted with a 256-bit AES algorithm and no way to decode it.
Here is what Toshiba has to say about these amazing pieces of hardware:

Toshiba adds advanced access security, built-in hardware data encryption, and wipe technology features to its 2.5-inch, 7,200 RPM Serial ATA storage products with the MKxx61GSYG series hard disk drives. The self-encrypting drive (SED) provides government-grade AES-256 hardware encryption incorporated in the disk drive�s controller electronics. Based on the widely endorsed Opal Security Subsystem Class (Opal SSC) specification from the Trusted Computing Group** (TCG), the MKxx61GSYG enables secure host authentication, strong data encryption and data-theft prevention features on such systems as notebook or desktop PCs, multi-function printers, point-of-sale systems, thin clients and service kiosks. Toshiba expands on the Opal SSC by adding unique security features which may be used to �wipe� protected data from the disk or deny access to protected data if access credentials are invalid, for example, if the disk drive were to be removed from the host platform.

Targeted at security-sensitive applications, the drive�s built-in hardware encryption reduces compatibility concerns associated with software encryption, while delivering transparent performance gains and a lower total cost of ownership. Deployment is fast and secure because data is encrypted during normal write/read operations. Toshiba�s wipe technology features can significantly shorten re-purposing and data cleansing operations while helping to assure compliance with data security policy. The Toshiba AES-256 encryption algorithm is certified to FIPS 197 by the US National Institute of Standards and Technology (NIST). In addition, the Toshiba MKxx61GSYG SED provides features to enable secure remote administration, using such capabilities as Intel�s Active Management Technology (AMT).

The MKxx61GSYG is compatible with leading third party security management applications, allowing seamless deployment of SEDs alongside pre-existing software encryption. Unlike software encryption, which is dependent on CPU performance and system memory capacity, the MKxx61GSYG encrypts at full storage I/O speeds and scales seamlessly in multi-drive applications.

For the full low-down, check out Toshiba's site.

Tuesday, May 3, 2011

Sony Still Having Security Problems

SOE.jpg
Ever had a really bad day? I mean a really bad day? Well, Sony is having one now, so if you've ever had one, you know how they feel.
As if this recent post wasn't bad enough, now the Wall Street Journal is reporting that Sony has suffered another security breach. This one deals with the Sony Online Entertainment division which makes multiplayer games for PC's.
It seems that there is a potential on this hack that 12,700 non-U.S. accounts and 10,700 bank account numbers from 2007 have been lifted. At least they didn't wait as long to let you know this time. This one happened earlier today and Sony is already getting the word out.
It seems that this particular attack gave the hackers access to 24.6 million customer personal accounts.
Sony has stated that its systems have been under attack for 6 weeks and they are not sure why.
Scary? You bet it's scary. For the full version of this story, head on over to the Wall Street Journal.

Thursday, April 28, 2011

Sony Playstation Network is Hacked-User Info Stolen

If you haven't heard or if you don't have a Sony Playstation & play online, between April 17th and April 19th someone hacked into the global Playstation network and made off with quite a bit of info. It also brought the network to its knees keeping it offline since then and as of Wednesday it was still inaccessible.

It seems that the hacker or hackers potentially made off with: users' names, home addresses, email addresses, birthdates, PlayStation Network usernames and passwords, and answers to password security questions.

Here is the official word from Sony. At this point I'd be following the Playstation Blog pretty closely if I were a user. Also, Microsoft has reported to users that there have been Phishing attacks on its network. Needless to say, if you are your kids are users of any online gaming networks, it certainly is important to be aware of these types of security issues.

Valued PlayStation Network/Qriocity Customer:
We have discovered that between April 17 and April 19, 2011, certain PlayStation Network and Qriocity service user account information was compromised in connection with an illegal and unauthorized intrusion into our network. In response to this intrusion, we have:

  1. Temporarily turned off PlayStation Network and Qriocity services;
  2. Engaged an outside, recognized security firm to conduct a full and complete investigation into what happened; and
  3. Quickly taken steps to enhance security and strengthen our network infrastructure by re-building our system to provide you with greater protection of your personal information.

We greatly appreciate your patience, understanding and goodwill as we do whatever it takes to resolve these issues as quickly and efficiently as practicable.

Although we are still investigating the details of this incident, we believe that an unauthorized person has obtained the following information that you provided: name, address (city, state, zip), country, email address, birthdate, PlayStation Network/Qriocity password and login, and handle/PSN online ID. It is also possible that your profile data, including purchase history and billing address (city, state, zip), and your PlayStation Network/Qriocity password security answers may have been obtained. If you have authorized a sub-account for your dependent, the same data with respect to your dependent may have been obtained. While there is no evidence at this time that credit card data was taken, we cannot rule out the possibility. If you have provided your credit card data through PlayStation Network or Qriocity, out of an abundance of caution we are advising you that your credit card number (excluding security code) and expiration date may have been obtained.

For your security, we encourage you to be especially aware of email, telephone, and postal mail scams that ask for personal or sensitive information. Sony will not contact you in any way, including by email, asking for your credit card number, social security number or other personally identifiable information. If you are asked for this information, you can be confident Sony is not the entity asking. When the PlayStation Network and Qriocity services are fully restored, we strongly recommend that you log on and change your password. Additionally, if you use your PlayStation Network or Qriocity user name or password for other unrelated services or accounts, we strongly recommend that you change them, as well.

To protect against possible identity theft or other financial loss, we encourage you to remain vigilant, to review your account statements and to monitor your credit reports. We are providing the following information for those who wish to consider it:

U.S. residents are entitled under U.S. law to one free credit report annually from each of the three major credit bureaus. To order your free credit report, visit www.annualcreditreport.com or call toll-free (877) 322-8228.

We have also provided names and contact information for the three major U.S. credit bureaus below. At no charge, U.S. residents can have these credit bureaus place a �fraud alert� on your file that alerts creditors to take additional steps to verify your identity prior to granting credit in your name. This service can make it more difficult for someone to get credit in your name. Note, however, that because it tells creditors to follow certain procedures to protect you, it also may delay your ability to obtain credit while the agency verifies your identity. As soon as one credit bureau confirms your fraud alert, the others are notified to place fraud alerts on your file. Should you wish to place a fraud alert, or should you have any questions regarding your credit report, please contact any one of the agencies listed below.

Experian: 888-397-3742; www.experian.com; P.O. Box 9532, Allen, TX 75013
Equifax: 800-525-6285; www.equifax.com; P.O. Box 740241, Atlanta, GA 30374-0241
TransUnion: 800-680-7289; www.transunion.com; Fraud Victim Assistance Division, P.O. Box 6790, Fullerton, CA 92834-6790

You may wish to visit the web site of the U.S. Federal Trade Commission at www.consumer.gov/idtheft or reach the FTC at 1-877-382-4357 or 600 Pennsylvania Avenue, NW, Washington, DC 20580 for further information about how to protect yourself from identity theft. Your state Attorney General may also have advice on preventing identity theft, and you should report instances of known or suspected identity theft to law enforcement, your State Attorney General, and the FTC. For North Carolina residents, the Attorney General can be contacted at 9001 Mail Service Center, Raleigh, NC 27699-9001; telephone (877) 566-7226; or www.ncdoj.gov. For Maryland residents, the Attorney General can be contacted at 200 St. Paul Place, 16th Floor, Baltimore, MD 21202; telephone: (888) 743-0023; or www.oag.state.md.us.

We thank you for your patience as we complete our investigation of this incident, and we regret any inconvenience. Our teams are working around the clock on this, and services will be restored as soon as possible. Sony takes information protection very seriously and will continue to work to ensure that additional measures are taken to protect personally identifiable information. Providing quality and secure entertainment services to our customers is our utmost priority. Please contact us at 1-800-345-7669 should you have any additional questions.

Sincerely,
Sony Computer Entertainment and Sony Network Entertainment

Tuesday, February 22, 2011

SSD's are not Easy to Erase - I'm not recommending them for Patient Data Storage at This Time

I've been excited for a while now about the possibilities of SSD's (solid state drives) these types of hard drives have been showing up for the past year or so in netbooks and some other types of portable devices.

The benefits are that they have no moving parts. This means they consume much less power (which is why a netbook battery can last all day) and they also don't have moving parts to wear out.

No, however, comes word that you can't use commercial "wiping" software to reliably remove all the data. Basically this means that no matter what you do, some of your info may still be on the drive. Now, you can always remove them and destroy them with a hammer, etc, but if you've been using software to totally erase your old "regular" hard drives, it looks like that option doesn't work well for SSD's.

Monday, January 31, 2011

If You Haven't Changed Your Amazon Password in a While... Do So Now!

It seems that Amazon has acknowledged some type of flaw with their password system that allows people to log into your account with variations of your password.

Supposedly the flaw only affects those who haven't changed their password in years.

Rather than repeat the whole post, I'll provide a link to the story I read at Wired. Check it out and change your password!

Wednesday, November 17, 2010

Large Software Announces docLock - Military Grade File Protection

Looking to secure your documents and files? Nowadays who isn't? If that's the case then take a look at docLock. It's something I'll be evaluating in the next few weeks and I'm excited to be able to use it.

Here's all the info:

Enjoy peace of mind while ensuring privacy and protection of sensitive data
SAN DIEGO, Calif. (November 16, 2010)  Large Software, a provider of easy-to-use consumer software including PC Tune-UpTM, announced today the launch of docLockTM, a software tool that allows users to protect and secure files and folders on their PC with military-grade password protection  all with just a click. In addition to protecting sensitive data, the software also makes managing this protection a breeze with advanced features such as a password generator and a visual password function that allows users to conceal their hard-to- remember password in a photo. Since data must often be shared, the software offers a host of ways to securely share protected documents, photos, videos, Zip files, PDFs (or even entire folders) with others even if they don't have the software. Users also have the option to securely create portable versions of protected documents that can be easily transported via memory stick, USB drive, flash drive, external hard drives, or other mobile storage device. An ideal gift for the holidays, docLock is available at a reduced price of $29.95 for a limited time (MSRP of $49.95 thereafter).

Perfect for home users or equally ideal for accountants, lawyers, stockbrokers, bankers, small business owners, or anyone interested in protecting sensitive or confidential computer data,
docLock offers complete protection and management of users computer data. Use docLock to protect computer files such as tax returns, financial documents, credit information, medical records, photos, videos, etc. In addition, docLock goes a step further with its protection to include features such as Secure Delete and Clean Free Space which make it easy to remove files and free space so that deleted files will be completely unrecoverable  especially useful for those who may be upgrading to a new computer this holiday season.

For added convenience and quick sharing, docLock allows users to e-mail locked files to recipients that might not have docLock installed, and to make all locked files portable by transferring locked files from PC to PC using any USB/Flash drive, again without having to have docLock installed.

We want to show people how easy and pain-free it can be to protect your files and information since we believe very strongly in the old adage better safe than sorry, said Nick Forcier, CEO of Large Software. You can now e-mail sensitive documents and the recipients do not have to download any software to open the files, they just need the password you create for them. Whether you're a computer pro or just an everyday user, docLock was built for those concerned about their privacy.

ABOUT LARGE SOFTWARE
Large Software is an innovative software solution provider that applies new thinking and ideas to create simple, valuable, and trusted experiences with technology. The company's premier product, PC Tune-UpTM, enables users of all technical levels to quickly and easily clean their computers and keep them running smoothly. Large Software is a privately-owned company that was founded in 2006 by NNJ Corporation. The company is headquartered in San Diego, California. For more information, please visit www.largesoftware.com.