Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

9.09.2011

Android devices exposed: 7 ways to thwart hackers


A new report highlighting a huge spike in threats against Google's Android platform is out. It has got something for us to be concerned about.
Mobile threats are rising, but actual attacks against smartphones and tablets are still a tiny fraction of the number of new threats that target your PC, and to a lesser extent, your Mac. And remember the law of big and little numbers. When a number is small, it doesn't take a huge addition to pack a big percentage change.

The news here is this: malware targeting the Android platform jumped 76% in the second quarter of the year, making it the most popular target for makers of malware that attacks mobile devices, according to researchers at McAfee, the anti-virus and computer security company now owned by Intel.

The reasons for the spike aren't hard to discern. Hackers like to attack popular platforms, and Android phones are now outselling Apple's iPhones. In order of popularity with hackers, Android is followed by the fading Symbian operating system and Java ME. If you're alert, you'll notice that iOS is not in the top three; in fact it's not on McAfee's list at all.


To explain why, let's take a look at a report issued by Symantec, McAfee's major rival in the personal security business. In June, Symantec said:

iOS's security model offers strong protection against traditional malware, primarily due to Apple's rigorous app certification process and their developer certification process, which vets the identity of each software author and weeds out attackers.
Malware targeting the Android platform jumped 76 percent in the second quarter of the year, making it the most popular target for makers of malware that attacks mobile devices, according to researchers at McAfee, the anti-virus and computer security company now owned by Intel.
McAfee

Google has opted for a less rigorous certification model, permitting any software developer to create and release apps anonymously, without inspection. This lack of certification has arguably led to today's increasing volume of Android-specific malware.

Those points are essentially the same as what the McAfee researchers have to say about Android vs Apple mobile device security.

How to Be Safe
Just because you're statistically unlikely to be killed by a lightning strike, that doesn't mean playing golf in a thunder storm is a good idea. Similarly, don't take my calming words as licence to pay no attention to security for your Android device. Malware is out there, and it targets personal information that you really don't want some bad guy to get his hands on.

Here are seven things you can do to thwart the hackers
1.  Use a security app designed for Android - Lookout Mobile Security is getting the best reviews I've seen. It's a free app (although there's also a beefier premium version) that does a number of things, including scan downloads for viruses. It also works as a phone tracker in case your Android is lost or stolen. Lookout has a website that will track its location. It also allows you to wipe your data remotely, lock the phone or set off an unpleasant alarm. Finally, there's a website associated with the app you can use for backup.

2.  Always check app permissions - Whenever you download or update an app, you are given a list of permissions for that app. If an app is asking for things it shouldn't need, get rid if it.

3.  Don't install Android Package files - As our colleagues at PCWorld explained: "When Angry Birds first came to Android, you could only get it through a third party. This is called 'sideloading' or, installing apps using an .APK file. While Angry Birds wasn't malware, it is highly advisable not to download and install .APK files that you randomly come across. Most of the time you won't know what the file contains until you install it. By then it's too late."

4.  Bank with authorised apps only - Online banking and bill pay is a great convenience, but to be safe, only use apps supplied by your bank.

5.  Only download popular apps - I know this sounds pretty stodgy, but there's a reason for it. Apps that have been downloaded a lot aren't likely to be poisoned. For that matter, they're likely to actually be worth downloading - if you believe in the wisdom of crowds, that is.

6.  Download from reputable publishers - If you're uncertain about an app, do a quick search under the publisher's name. If you find a number of apps with good reviews and lots of downloads, chances are you're dealing with a reputable outfit.

7.  Keep an eye on your wireless bill - Some rogue apps do things like make expensive calls to foreign numbers in order to fatten the bank account of various intermediary sites at your expense. Often the calls happen in the background or at times when you don't realise your phone is doing something.

9.05.2011

How to overcome Facebook security risk due to Faceniff


FaceNiff is an Android application that lets users access web sessions profiles over Wi-Fi networks, easily hijacking into the connected Facebook, Twitter, YouTube, Amazon and other accounts.

FaceNiff is developed by Bartosz Ponurkiewicz who created the Firefox extension Firesheep, that lets users hijack Facebook and Twitter sessions over Wi-Fi networks. Unlike Firesheep, FaceNiff works on WPA-encrypted Wi-Fi networks also.

Bartosz says on his website that the app is for educational purposes only, and urges users not to install it if it is illegal in their country.

To get started, you need to download and install FaceNiff from the official website here.

To protect your account from Faceniff, use SSL option while accessing FB from public networks. Change can be made in the setting menu of Facebook. 



The app is confirmed to be working on the following devices.

  • HTC Desire CM7
  • Original Droid/Milestone CM7
  • SE Xperia X10
  • Samsung Galaxy S
  • Nexus 1 CM7
  • HTC HD2
  • LG Swift 2X
  • LG Optimus Black – original rom
  • LG Optimus 3D – original rom
  • Samsung Infuse

Here’s a video of FaceNiff in action

8.18.2011

The unofficial Facebook privacy Guide

Introduction
To fully understand privacy on Facebook, and how it's likely to evolve, you need to understand one thing. In short: Facebook executives want everyone to be public. As
the service evolves executives tend to favour open access to information, meaning as time marches on information you think is private will slowly become public.
That doesn’t mean you can’t be priv ate if you w ant to; Facebook gives its users the option to lock things down. But users need to be aware of the controls, how to use
them and how to prepare for future Facebook privacy changes. Facebook hasn’t, and w on’t, make this information obv ious, and that’s w here this guide comes in.

A realistic look at privacy online
Think about the reality of your information online. Information about you is already available in many places, so you need to remain aware of the whole picture in order to keep yourself, your friends and your family safe.
Ensure that the information you put online can't be collected to put yourself or anyone you know in danger. For example:
I f your name and address appear in the phone book, don't publicly tell people on Facebook when you're going away for the weekend.
A basic way to guard your privacy is to behave as if every piece of information online is already public. Given this premise, try not to add anything to a picture that allows a stranger to know exactly where you will be, where you live or puts you in danger in any way.
I t's a good idea to understand the many ways in which your privacy could be breached online. It's not always what you might expect.
Your friends might share your information without knowing you wanted to keep it private. For example:
◦ Putting photos of you online or tagging you in photos (especially those which make it clear where you were at a given time).
◦ Sharing your phone number, address or child's name.
◦ Mentioning publicly that you are going away for the weekend.
◦ Excitedly sharing news you only wanted a few people to know.
◦ Accidentally sharing a screenshot that shows your private information.
Someone might deliberately share your information. For example.
◦ After a relationship break-up or a fight between friends.
◦ Because of jealousy or rivalry (love triangles, classmates, co-workers, siblings). Someone might be tricked or coerced into showing your information as they
see it.
Someone else might have a security breach (virus, left account logged in).
People might lie about who they are to get your trust (or someone else's).
Default privacy settings may change.
Someone might hack into your data.
Police might legitimately ask to access your data (or a friend's data),
exposing your actions to a public court case.
There may be a glitch that exposes information.
A hacker or ex-friend may deliberately spread misinformation about you.
You get the idea: human error and technical glitches can and will occur, while some people may hurt you deliberately.
The best defence? Be careful what is online in the first place. Privacy settings help, but that’s it. Don't ev er trust the settings to protect you entirely.
I f there is anything you specifically want to keep private for any reason, make sure your friends know what it is and why. For example:
You may work in a profession where it is prudent to keep your true identity obscured (teaching, law, military secrets, mental health care).
The trick with setting your privacy settings is to consider all possible privacy breaches, then use the privacy settings to minimise the possibility of a breach (or reduce the damage caused by a breach). For example:
I f you never put your sexy bedroom photos on Facebook, then a Facebook glitch will never accidentally be make them public. 
Better still: don't take any.
Set your privacy settings so that photos of you are, tagged by other people, are seen only by a specific list of friends. This means unflattering party photos taken aren’t seen by everyone you know.
Filtering, so that your co-workers can't see comments on your wall, will limit their exposure to personal comments made by your friends.
Hopefully we've got you thinking about what you need to control, and why. The rest of this guide looks at how , so let’s get started!

Operation Cleanup: Complete Malware Recovery Guide


Introduction

This guide will help you clean your computer of malware. If you think your computer is infected with a virus or some other malicious software, you may want to use this guide. It contains instructions that, if done correctly and in order, will remove most malware infections on a Windows operating system. It highlights the tools and resources that are necessary to clean your system. Malware is a general term for any malicious software, including viruses, trojans, rootkits, spyware and adware.
Many different symptoms indicate a malware infection. Sometimes, the symptoms can be difficult to detect. Below is a list of symptoms you may experience when you are infected with malware:
 Your computer shows strange error messages or popups.
 Your computer takes longer to start and runs more slowly than usual.
 Your computer freezes or crashes randomly.
 The homepage of your web browser has changed.
 Strange or unexpected toolbars appear in your web browser.
 Your search results are being redirected.
 You start ending up at websites you didn't intend to go to.
 You cannot access security related websites.
 New icons and programs appear on the desktop that you did not put there.
 Your desktop background has changed without your knowledge.
 Your programs won’t start.
 Your security protection have been disabled for no apparent reason.
 You cannot connect to the internet or it runs very slowly.
 Your programs and files are suddenly missing.
 Your computer is performing actions on its own.

Related Posts Plugin for WordPress, Blogger...