[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label Privacy. Tampilkan semua postingan
Tampilkan postingan dengan label Privacy. Tampilkan semua postingan

13/03/14

How to Use Edward Snowden’s Three Tips for Digital Privacy

Former NSA contractor Edward Snowden says he has been able to outfox U.S. officials using encryption. During a webcast on NSA leaks and data security at the South by Southwest conference in Austin, Texas, Snowden shared some privacy tips for the rest of us: Encrypt your hard drive, use plug-ins for your browser that prevent organizations or companies from tracking you online, and cover your tracks with Tor, an online network that promises anonymity.
These tips range from simple to complicated depending on your computer savvy, so we’ve collected some basic info and guides to help you get started:
Encrypt your hard drive
Encryption is the “Defense Against the Dark Arts” for the digital world, said Snowden, referencing the class Harry Potter took during his Hogwarts years.
Adding password protection to files on your computer is just the first step to personal file security. Encrypting the entire hard disk on your computer ensures personal information is secure, even if your device is stolen or seized.
Newer versions of Windows and Mac operating systems come with built-in disk encryption tools. BitLocker, which encrypts your entire hard drive, comes as part of Windows 7 Ultimate and Enterprise versions, and Windows 8.1 Pro and Enterprise editionsAppleoffer detailed tutorials online on how disk encryption services can be turned on. For those with older operating systems, TrueCrypt, there’s a free program for encrypting your drive. Here’s a guide on how to download and install it.
The Electronic Frontier Foundation, an organization that works on digital rights issues, has a guide to how encryption can help in different situations.
Use browser plug-ins to avoid being tracked onlineThe Wall Street Journal’s series ‘What They Know‘ showed companies are using digital tracking for online activities such as shopping, varying prices based on shopping patterns and location information. While that may seem harmless, it’s important to know that if retailers can see you, it’s likely that others can as well.
Slowly, companies such as Google have agreed to support a do-not-track button to be embedded in most Web browsers. Google’s Chrome browser has a setting that most users can turn on to send a do-not-track request, and so does Microsoft’s Internet Explorer 10. They won’t work with all websites, but it’s a good place to begin.
Plug-ins or small software extensions available for browsers are another way to go about it. Ghostery, a plug-in available for most popular browsers, when installed will show the number of trackers detected but not automatically block them. Users have the choice to individually or in bulk block these trackers.
You can also choose sites, such as the search engine DuckDuckGo, which do not record or share your searches.
Cover your tracks with Tor Over the last few months, Tor, a network that promises anonymity and privacy online has come under the spotlight. Tor hosts a network of websites, some of which have been under the scanner of law enforcement officials for illegal activities. Late last year, the Federal Bureau of Investigation shut down Silk Road, a marketplace available only through the Tor network, for the sale of illegal drugs.
Tor may be useful for criminals, but its cloak of anonymity is increasingly a comfort to anyone looking for privacy. Tor offers its own browser that can be used to connect to news sites or instant messaging services and chat rooms that can’t be easily tracked online.
To get started on the Tor network, take the advice of the ExtremeTech blog, and download the Tor Browser Bundle available for Windows, Mac and Linux. It’s similar to using the Firefox or Chrome browser but slower, because Internet traffic is routed through a series of proxies to mask its origin.
Other ways to lower your online profile include using encrypted chat services such as SilentCircle, and encrypted mail such as Hushmail. There are even smartphones coming out soon that will offer a suite of privacy features baked right in.

Read More...

28/10/11

The Facebook Immunity System (FIS) uncovered


Facebook has recently released some interesting data from it’s ‘The Facebook Immunity System (FIS)’. According to FIS it processes and checks 650,000 actions every second (it can handle 25 billion actions every day – amazing) to maintain user safety from spam (The FIS reports just 1% of users reporting issues around spam) and other cyber related attacks.

Facebook has developed the FIS system (using a signature) that is able to differentiate between spam and legitimate messages (as well as ‘creepers’ – those who use Facebook but cause problems for others) for example basing on the links in spam messages, keywords and IP addresses. Spammers can beat this by using shortened URL services and switching systems (which switches IP addresses). When this happens the system relies on keyword scanning aka blacklist of words i.e. “iPad” or “free” are two common keywords.

Statistic: Since the introduction of FIS some three years ago, spam accounts for less than 4 percent of the total messages on Facebook.

The FIS team is supported by some 30 security experts who manually search for spam across the Facebook network with one particular threat being posed by socialbots. These are fake profile bots that behave like you or me on Facebook. Socialbots will aim to connect with as many ‘friends’ as possible in an attempt to friend users into obtaining access to your Facebook profile data. Socialbots are very difficult to detect, so the FIS has to rely on the security experts to identify the potential threats.

Statistic: FIS is probably the second largest defence system outside of the Web itself. It’s a staggering size considering the 800m+ people that use it daily.
It’s worth pointing out that a socialbot is yet to happen, however it’s only a matter of time before we see this or other similar innovations. As you know by now, FIS relies on patterns of known behaviour (aka HIPS model) rather than behaviour analysis. The FIS policy and classifier engines offer clear opportunities for future development as well as development of specification-based behavioural analysis policies rather than the current anomaly model that Facebook uses.
Read More...

17/10/11

Social Security agency leaks thousands of SSNs every year, report says

More than 400K SSNs may have leaked in last 30 years, Scripps Howard News Service says

The SSA (Social Security Administration) puts thousands of Americans at risk of identity theft each year by accidentally leaking their Social Security Numbers, names and dates of birth, according to an investigative report by the Scripps Howard New Service.

The leaks are the result of keying errors made by SSA employees when entering data into the agency's Death Master File, a database containing the records of 90 million deceased Americans.

[ Learn how to secure your systems with Roger Grimes' Security Adviser blog and Security Central newsletter, both from InfoWorld. ]

Since 1980, when the SSA first started making the file publicly available, more than 400,000 SSNs belonging to living Americans may have been inadvertently published in the Death Master File as a result of the errors, according to the report.

In most cases, the victims of the inadvertent leaks are not informed of the breach. Many discover the error only after they ran into problems such as having their bank accounts frozen, job interviews refused or having their credit, mortgage or student loan applications declined, Scripps Howard reported.

The SSA did not immediately respond to a Computerworld request for comment.

For its report, Scripps Howard reviewed three files from the Death Master File and discovered 31,931 living Americans listed erroneously in them. Dozens of those who were incorrectly listed were later contacted by the news service. None said they'd been informed of the breach by the SSA.

The SSA has admitted that it inadvertently lists about 14,000 living people in the Death Master File each year, Scripps Howard said. Using that estimate, more than 400,000 records have been released since 1980, the report noted.

In the report, Scripps Howard quotes SSA Commissioner Michael Astrue, who spoke to members of Congress about the issue last month. Astrue said that the SSA takes prompt action to correct any errors it discovers. Any breach involving the accidental leakage of SSNs is also promptly reported to the U.S. Computer Emergency Response Team.

Astrue said the SSA has so far found no instance of fraud or misuse as a result of the inadvertent exposure.
Read More...

08/10/11

Facebook/Twitter hacks by "friends" on the rise for teens and young adults

BullyA new survey of American teenagers and young adults has discovered that three out of every 10 have had their Facebook, Twitter or MySpace accounts broken into for the purposes of snooping or impersonation.

And most know who was responsible.

The poll, conducted by Associated Press-MTV, asked a total of 1355 people between the ages of 14 and 24 about their experiences online, and suggests that the problem has doubled since 2009.

A typical scenario would be a young person leaving their computer unlocked while they leave the room, or forgetting to log out of Facebook, Twitter or an email account, giving someone else present the opportunity to snoop on emails or post an embarrassing status update using the account owner's name. Richard Lindenfelzer, a 20-year-old student from Ithaca College in New York, explained how he had left his Facebook account open, giving a friend an opportunity to post comments about his love life.

"It's meant to be funny. It's supposed to be obvious that this something I would never say," explained Lindenfelzer.

Does everyone really find it so funny though?

Clearly some people are amused by their friends' antics, but the poll found that 46 percent of people were left upset by having their online accounts intruded upon.

In some cases, it may be bitchy schoolmates who are posting hurtful things on your Facebook page in your name, designed to humiliate you. Or someone snooping on their boyfriend or girlfriend's private messages.

It's understandable that many of the victims can feel violated and distressed when their password is guessed or stolen, or a momentary lapse means they left their account open for someone unauthorised to gain access.

PrivacyThe fact is that unauthorised access to an online account is illegal in most countries. By sending a message from somebody else's email account without permission, or posting an offending tweet or status update, you're both breaking the law and showing disrespect to the privacy of your friend or classmate.

Two-thirds of those who said they had been hacked confirmed that at some point they had changed their passwords as a result of the incident. 46% went further, and said they had changed their email addresses, screen name or phone number. 25% had actually taken the step of deleting a social networking account.

The world is changing, and the wide access to the internet and social networking sites are presenting young people with new issues that earlier generations simply did not have to face. We all have to learn how to behave appropriately and with respect, and not think that just because something can be done (for instance, logging into a friend's email or Facebook) that it should be done.

A Thin LineIf you act unconcerned when a friend posts a vulgar status update in your name, or blasts out an email from your account without your permission, then you are tacitly approving of the behaviour in general and not helping spread the message that accounts are supposed to be private to the individual.
Read More...

07/10/11

Kevin Mitnick - ghost in the wires, or scourge of the internet?

My previous book reviews on Naked Security have covered books which I enjoyed greatly, and which were somehow relevant to the field of computer security.
One was a novel dealing with advance fee fraud in Nigeria; the other a historical record of Second World War cryptography in the UK.

I wrote those reviews because I thought you'd enjoy those books as much as I did, and because I thought they'd be worth buying with your own after-tax income.

This review is slightly different. I read this book right to the end, and I even enjoyed it - up to a point. But I'm reviewing it merely because it relates to the field of computer security, rather than because I'd suggest that you buy it.
The book in question is the recently-published Ghost in the Wires by infamous convicted phone hacker Kevin Mitnick.

It's an example of a curious but common contradiction-in-terms genre in publishing: an autobiography written in conjunction with someone else.

Mitnick's book doesn't cover his whole life story: the bulk of it is about Mitnick the hacker, from his early age on page 3 until his release from prison in January 2000 on page 383. He wraps up the decade since his release very rapidly in the ten pages which follow.

As I mentioned above, I enjoyed this book, but only up to a point. That point was somewhere around page 123, when the repetitious descriptions of Mitnick's repetitious escapades began to wear thin.

I was also disappointed to find very little about what I'd consider hacking (whether for good or evil) in the computer science sense.

It's not all bad, however. You will learn some important lessons about security from Ghost in the Wires, based on real-life examples from Mitnick's life:

* Assume that attackers have a pathological patience. Assume that their primary intellectual gratification doesn't come from building something new, or from inventing a breakthrough to simplify the task. Mitnick will show you how he sometimes succeeded against all odds, even if that meant spending weeks or months carrying out boring, repetitive work.

* Recognise that resisting social engineering is difficult. It requires behaviour by your staff which may feel anti-social. Mitnick will show you that most employees require more than just policy documents to give them resilience against creatively and manipulatively dishonest callers and emailers. You need to provide them with practical, role-based training.

The most disappointing thing about Mitnick's book is its overall implication - perhaps, in fact, its thinly-disguised purpose - that we should trust him now that he's out of prison, has finished his supervised release, and has turned into a businessman.

In his Acknowledgments, a seven-page appendix to the book, Mitnick shows no repentance. He doesn't apologise to the very many victims he abused, lied to and cheated; nor to those whose cellphone time he ripped off and whose identities he stole; nor to those outside his own circle whom he left in potentially serious trouble or whose lives he diminished by his self-obsessed criminality.

In fact, he doesn't really acknowledge his victims at all, and he gave me the impression that he's still proud of his time as a liar and a cheat.

(He's happy, indeed, to have the back cover describe him as a "visionary".)

I have to admit that made me feel slightly cheated at having put my own money into Kevin's royalty bucket.

But you might enjoy the book right to the end if your expectation of it is merely to live vicariously the life of a computer intruder and a phone phreaker, a con-artist and a fraudster, an identity thief and a crook.

ISBN: 978-0-316-20160-5
Published: August 2011
Read More...

27/09/11

'Pepper spray' officer named by Occupy Wall Street activists [video]

A senior officer with the New York Police Department has been named online by activists associated with the Occupy Wall Street activists, in connection with the controversial use of pepper spray against a group of female protesters.

On Saturday, in an incident captured on video, a small group of seemingly peaceful protestors were said to have been doused with pepper spray by a uniformed officer.

Warning: Some readers may find the following video upsetting.


Even some of the police officers seen in the video seem shocked by the use of pepper spray.

Now, after slow motion examination of the video, the Anonymous group has published what it claims to be the spraying police officer's personal information - including phone numbers, addresses, and the names of relatives.
It is claimed that the officer was identified by online supporters of the Occupy Wall Street movement after his badge was enlarged from a photograph taken at the scene.
Alleged details of police officer
Clearly, feelings are running pretty high over this incident, and if police officers acted without provocation appropriate steps should be taken. If a police officer is guilty of an offence then obviously he should be punished.

But it feels very wrong to me to name a man who we have to assume is innocent until proven guilty, and especially dangerous to make public his address and the details of his family.

Anonymous is no stranger to releasing personal information of individuals in positions of authority. For instance, last month it released partially nude photographs of a man said to be Linton Johnson, the chief spokesperson for the San Francisco's BART, as well as names, postal addresses and email addresses of officers.

nb : nakedsecurity.sophos Read More...

26/09/11

Facebook's ticker privacy scare, and what you should do about it

Privacy
Amongst the recent new changes to appear on Facebook, there is a "ticker" (a rolling real time list of what your friends are doing).

Not everyone has received it yet, because it's on a staggered rollout, but millions have already seen it.
You'll find it on the right hand side of your Facebook page, in the collapsible chat bar.

It's smashing if you want to keep fully up-to-date with your friends' activity, but there is a problem with it.

Facebook Ticker

The ticker makes it very simple for you to eavesdrop when one of your Facebook friends says something to someone you've never heard of - and even see what the stranger originally wrote too.

Ticker eavesdropping

Testing shows that your privacy settings are working the same as they did before, providing you used them in the first place.

The appalling enforced eavesdropping in the ticker (your friend said something to someone you've never heard of) is the result of the lax or non-existent settings of your friends, so here's the deal..

What happens is this:

1. You have "friends of friends" or "public" as the privacy setting for your posts.
2. One of your Facebook friends comments on your post, or clicks "Like".
3. As well as all the people commenting on the thread seeing what has been posted (this much is normal), Facebook also tells all *their* friends what was said.
4. Your friend's settings *cannot* stop this from happening, *your* settings can protect your friends' privacy, in this instance.

Facebook privacy inline control
The ticker has just made it much easier to eavesdrop on what were probably intended to be more private conversations.

So, do this - and make your friends do it too:
* Stop using the "Friends of friends" setting. This is what is broadcasting so widely.
* If you use the "Public" setting, explain that you are doing so. Then people can decide if they want *all* of their friends to be informed of their comments.
* "Limit" all previous posts you have made via the privacy settings (unless you had "friends only" or specific lists already) - this will change everything to "friends" only and will stop people you deleted but did not block, people who sent you friend requests that you ignored, and friends of friends from seeing your activity (yes they can, if you are not on "Friends" or lists).
* Use lists to decide who you want to see things (use the privacy controls in the top right of your posts).

* Encourage your friends to restrict their setting to "friends" or custom lists too. This is the important bit.
* Inform strangers or the connecting friend when strangers show up in your feed. It is their settings that made them show up. This will illustrate to them why they also need to change their settings.

It is not just your settings that control what goes in your Facebook newsfeed and appears on your friends' tickers. Anyone's posts which have privacy set to more than "Friends" will go to all the friends of all the commenters. This is a fact! We've tested it!

Custom privacy on Facebook
Still baffled?  Don't worry.  The problem is complicated to explain, but the solution is simple.  If you want to stop strangers from seeing everything you do, you and your friends need to change your privacy settings to "Friends" or custom lists.  That's it.

The hard part is getting your friends to do it.

If you find your friends aren't understanding the issue, forget about explaining the details and "copy and paste" this to your status:

"If you don't want your actions broadcast to everyone via the ticker/News Feed please set your privacy to "Friends" and ask your friends to do the same.  Pass it on."

What *not* to tell your Facebook friends
Now, there is also a piece of advice being circulated which reads like this:
"Please do me a favor and move your mouse over my name here, wait for the box to load and then move your mouse over the "Subscribe" link. Then uncheck the "Comments and Likes". I would really rather that my comments on friends and families posts not be made public, thank You! Then re-post this if you don't want your every single move posted on the right side in the "Ticker Box" for everyone to see!"
Scroll over my name..
This appears to be the most commonly suggested solution on Facebook, and it's rubbish! It still doesn't stop *your* posts being broadcast. It's an illusion. This option stops you seeing when other people have broadcast a message to a wide audience. It does *not* stop your actions being broadcast by your friends!

You have to do this for every single one of your friends. Time consuming *and* it does not solve the problem - it just stops you from seeing it.

Please don't spread this advice, as it is confusing people and stopping the real problem from being fixed.

How to tell if a post will broadcast to all your friends:
Under each post (on the right) there is an icon which will tell you who it was shared with:
Public
GlobeThe globe icon means that the post is going to be public.
That means, if you comment your friends will be shown the comment immediately and that everyone on Facebook (except those people you have specifically blocked) can see it.
Friends
HeadsThe icon showing two heads means that the post is shared with friends only.

It should be safe to comment, with no threat of exposure to strangers via the ticker/news feed.

Custom or Friends of Friends
GearA gear icon can actually mean one of two things - either Custom or Friends of Friends. You will have to hover your mouse over the icon to see which.

Custom means that the post will be safe to comment on with no leakage to strangers via the ticker/news feed.

Friends of Friends, however, can be considered unsafe - as all your friends and all of their friends will be shown the comment immediately via the ticker/news feed.
 
You can check your own posts easily that way if you want to make sure that your settings are right.

And don't forget - next time you leave a comment on someone else's Facebook post, don't say something that you may later regret.

nb : nakedsecurity.sophos
Read More...

22/09/11

Google Plus opens to everyone - but do you still want to join?

If you will pardon the literary allusion (or, if you prefer, the flagrant plundering of someone else's catch-phrase), "Google is a foreign country: they do things differently there."

So differently, in fact, that until legal and community pressure forced Google's hand back in 2008, the company just plain refused to have a link to its Privacy policy on its main search screen. There were already 28 words on Google's home page, and that was that.

Not 27, and definitely not 29. 28 was a matter of religion; of scripture; of liturgy; and of just-jolly-clean design. That meant no room for the word "Privacy."

Eventually, the word "Google" was removed from the copyright notice, and the advertising behemoth was able to make space for privacy. (Conveniently for the Google high priesthood, the copyright symbol © - which appeared on the page and amounts to a word, since it represents a word - was defined as a non-word.)

There are still 28 words on Google's home page - if you allow yourself a fair bit of doctrinal flexibility - but the just-jolly-clean design is today sullied with a crudely-drawn animated arrow pointing at the top left corner. The arrow points at one of the ten or so words in the top menu bar which enjoy that doctrinal exemption: +You.

That's right. Google Plus is now open to everybody.

Just remember two things before you join.

* Social networking services of this sort aren't free. True, there is no cash cost associated with signing up. But you are not Google's customer - those are the advertisers, who pay money to get in front of you, based on the sort of things you do online. This means you are an informal employee, paid in kind to generate traffic and to give up information about yourself which can be monetised by Google.

* You cannot join Google Plus anonymously. You must use your real name - and you need at least two words in your name to qualify - and Google will be the final judge and jury of what constitutes your name, and how you're to write it. Google may even insist that you send it a copy of your passport to prove it.

(Unless you're a celebrity, of course. It seems that William James Adams of the Black Eyed Peas is now on Google Plus with a first name of "will.i.am" and a last name of "." Don't bank on being able to do that yourself.)

Join Google Plus if you wish. According to many people, it's been worth the wait. If you are up there you might want to even follow Naked Security's team.
But make sure you really are sure you are willing to give your true identity to Google.

And remember that you may be forced to prove it by sending a copy of official government-issued identification - even though that's an unwise thing to do if you're serious about protecting your personally identifiable information.

nb : nakedsecurity.sophos
Read More...