Tampilkan postingan dengan label cell phone. Tampilkan semua postingan
Tampilkan postingan dengan label cell phone. Tampilkan semua postingan

Kamis, 23 Februari 2012

Smartphone security gap exposes location, texts, email, expert says


latimes.com
Just as U.S. companies are coming to grips with the threats to their computer networks emanating from cyber spies based in China, a noted expert is highlighting what he says is an even more pernicious vulnerability in smartphones.

Dmitri Alperovitch, the former McAfee cyber security researcher who is best known for identifying a widespread China-based cyber espionage operation he dubbed "Shady Rat," has used a previously unknown hole in smartphone browsers to deliver an existing piece of China-based malware that can commandeer the device, record its calls, pinpoint its location and access user texts and emails. He conducted the experiment on a phone running Google's Android operating system, although he says Apple's iPhones are equally vulnerable.
"It's a much more powerful attack vector than just getting into someone's computer," said Alperovich, who just formed a new security company, called Crowdstrike, with former McAfee chief technology officer George Kutz.
Alperovich, who has consulted with the U.S. intelligence community, is scheduled to demonstrate his findings Feb. 29 at the RSA conference in San Francisco, an annual cyber security gathering. The Shady Rat attack he disclosed last year targeted 72 government and corporate entities for as long as five years, siphoning off unknown volumes of confidential material to a server in China.

Kamis, 16 Februari 2012

Chinese Telecoms May Be Spying on Large Numbers of Foreign Customers

theatlantic.com
A U.S. Congressional probe is investigating whether China's state-linked firms, which built much of the communications infrastructure in several Asian countries, is using its access for snooping.

Two Chinese telecommunications giants are under scrutiny by a US congressional committee. The outcome of the probe could have revealing implications for Central Asian states, which have used these companies to modernize their telecom sectors.
US legislators have expressed concern that Huawei and ZTE act as front companies for the Chinese government, and represent a grave "cyber-security threat." The chairman of the House Permanent Select Committee on Intelligence, Michigan Republican Mike Rogers, asserted during a congressional hearing last October that China is engaged in the "brazen and wide-scale theft of intellectual property from foreign commercial competitors."
"Attributing this espionage isn't easy, but talk to any private sector cyber analyst, and they will tell you there is little doubt that this is a massive campaign being conducted by the Chinese government," he added.

More...

Sabtu, 17 Desember 2011

Government Investigates Cellphone Wiretapping

theatlantic.com
As the government begins an investigation into Carrier IQ's cell phone-tracking software, memories of its own wiretapping scandal resurface


"Spy on unsuspecting Americans? That's our job," you can imagine federal officials indignantly declaring as they investigate cell-phone tracking by the mobile software company, Carrier IQ. The National Security Agency began secret, illegal surveillance of our phone calls and Internet activities in 2001, as we belatedly learned in 2005. Yes, 2005 is a long time ago these days, when yesterday seems like old news; but the NSA scandal deserves to be remembered, especially when the government presumes to be outraged by telecom spying.  

When it began spying on us after 9/11, the Bush Administration enlisted the assistance of telecoms willing to engage in illegal activities at its behest. (Former Qwuest CEO Joseph Nacchio later claimed that after he declined to cooperate with the surveillance program, in 2001, the government retaliated, denying the company lucrative contracts. In 2007, Nacchio was convicted of insider trading.) After the NSA program was exposed, complicit telecoms faced the risks of losing expensive civil suits. AT&T, in particular, was badly exposed, thanks to incriminating documents released by a whistleblower and a lawsuit filed by the Electronic Frontier Foundation. But not surprisingly, Congress intervened. In 2007, it retroactivelyimmunized the companies for illegal activities authorized by the president. As the late, disgraced Richard Nixon explained, prematurely, "when the President does it, it's not illegal." Voting in favor of telecom immunity, then candidate and Senator Obama apparently agreed.


More...

Senin, 31 Oktober 2011

Spouse Spy’s on the case

scpr.org

Tailing a philandering mate used to be so messy, complicated – and expensive. Private detectives aren’t cheap, after all, and someone always seems to end up dead – at least in the movies. But nowadays, suspicious spouses don’t need to call on Philip Marlowe. You can shadow your significant other just by installing Spouse Spy, or one of many similar apps, onto his or her cell phone.
A simple download lets you track comings and goings, read text messages, ogle photos, even listen in on conversations – all in real time. And of course, it’s all on the Q-T. – these apps are designed to be undetectable. But are they legal? A bipartisan group of senators, led by Al Franken (D-Minnesota) and Charles Grassley (R-Iowa) has asked the Department of Justice to look into whether these so-called “stalking apps” violate any laws.

Rabu, 05 Oktober 2011

Devices That Can Listen In on Cellphone Traffic, Control Your Phone

wsj.com

Law enforcement and military officials are increasingly using secret devices sometimes called “stingrays” to locate people via their cellphones, even when the phones aren’t in use, the Wall Street Journal reported recently. But finding people isn’t all that this type of gear can do.



These types of machines mimic a cell tower and cause your phone to connect to the machine instead of a real cellular site. Once that happens, there’s a lot that can be done to your phone.
For starters, “they can be set up to do wiretapping of the actual content,” said Matt Blaze, a computer science professor at the University of Pennsylvania and a former researcher at AT&T Labs.
Such devices also can jam phones, fake calls and text messages and drain the phone’s battery, according to documents available online for companies such as Advanced German Technology that sell these types of devices.
Other gadgets can listen to calls “passively,” meaning that instead of forcing the phone to connect to a fake base station, they simply grab signals transmitted between the mobile phone and the cellular network, allowing the operator to capture conversations.
One such device, available on the helpfully named spyshops.com, claims to be able to monitor a radius of up to about 3 miles and intercept 100 conversations simultaneously, according to the site. The device is “completely STEALTH – invisible and non-detectable, high performance and upgradeable,” the site says.

Rabu, 28 September 2011

Which Telecoms Store Your Data the Longest? Secret Memo Tells All

wired
The nation’s major mobile-phone providers are keeping a treasure trove of sensitive data on their customers, according to newly-released Justice Department internal memo that for the first time reveals the data retention policies of America’s largest telecoms.

The single-page Department of Justice document, “Retention Periods of Major Cellular Service Providers,” (.pdf) is a guide for law enforcement agencies looking to get information — like customer IP addresses, call logs, text messages and web surfing habits – out of U.S. telecom companies, including AT&T, Sprint, T-Mobile and Verizon.

The document, marked “Law Enforcement Use Only” and dated August 2010, illustrates there are some significant differences in how long carriers retain your data.

Verizon, for example, keeps a list of everyone you’ve exchanged text messages with for the past year, according to the document. But T-Mobile stores the same data up to five years. It’s 18 months for Sprint, and seven years for AT&T.

That makes Verizon appear to have the most privacy-friendly policy. Except that Verizon is alone in retaining the actual contents of text messages. It allegedly stores the messages for five days, while T-Mobile, AT&T, and Sprint don’t store them at all.

More...

Jumat, 23 September 2011

U.S. spy agency trying to go mobile

Linkreuters.com

(Reuters) - Troy Lange knows that just mentioning cellphones is enough to give security officers heartburn at the National Security Agency.

Lange, as the NSA's mobility mission manager, is developing a smartphone that he wants to bring inside the super-secret U.S. spy agency to access classified information and apps while on the move. He wants it to work as easily as any of the smartphones those that are so ubiquitous in the outside world.

That is no small vision for an agency where entire buildings are designated as Sensitive Compartmented Information Facilities, known as SCIFs in spy speak, with many restrictions to ensure the handling and discussion of secret information stays secure.

Visitors to the Fort Meade, Maryland, NSA complex are not allowed to bring outside cellphones into the building.

Lange argues that using smartphones inside areas that deal with secret material will increase efficiency.

"I want to get this into everybody's hands" -- every employee in the Defense Department, intelligence community and across government, he said, while acknowledging that kind of talk makes "the security people's heads pop off."

More...

Jumat, 02 September 2011

HTC Sneaks Spying App into Android 2.3.4 Phones

hothardware.com

Looks like HTC has quietly slipped its users a spying app that tracks an alarming amount of user behavior and sends that data off to itself and perhaps others via a mysterious service in the cloud. The snooping app came nestled with the 2.3.4 Android update pushed out to some of its smartphones such as the Sensation 4G and EVO 4G.

TrevE and Team Synergy of the InfectedROM site (and XDA fame), discovered the app. HTC includes an application called Carrier IQ and Carrier IQ recently added a user-behavior logging feature called IQ Insight Experience Manager.

According to the Carrier IQ website: "IQ Insight Experience Manager uses data directly from the mobile phone itself to give a precise view of how users interact with both their phones and the services delivered through them, even if the phone is not communicating with the network. ... Identify exactly how your customers interact with services and which ones they use. See which content they consume, even offline."

But wait there's more. Turns out that after HTC collects these stats, CIQ isn't the only app with access to them.



More...



Kamis, 01 September 2011

Court Affirms Legality Of Recording Police Officers

wbur.org

Last Friday, the U.S. First Circuit Court of Appeals issued a ruling that affirmed, stronger than ever, the rights of individuals to openly record the actions of police officers.

In 2007, a young lawyer named Simon Glik was walking through Boston Common when he saw three police officers arresting a teenager. Glik thought the officers were getting a little rough, so he flipped open his cellphone camera and started shooting video.

The officers arrested Glik for, in their minds, violating the state’s wire-tapping law, even though the whole incident happened out in public and Glik didn’t try to conceal the fact that he was recording.

The ACLU took up Glik’s cause and the courts threw out the charges against him. Since then, the Boston Police Department has been instructing personnel that the state’s wiretapping law does not apply to people making unconcealed audio or video recordings in public. But Glik and the ACLU have pressed on, suing the BPD and the individual officers for violating his First Amendment rights.

The officers moved to have the suit dismissed, saying they were just enforcing an interpretation of the law that was handed down to them by their superiors. But on Friday, the federal court disagreed.

More...

Businesses Increasingly Under Attack From Cyber-Security Threats



marketwatch.com

Cyber-Criminals Targeting Mobile Devices and Social Media Sites



SAN JOSE, Calif., Sept. 1, 2011 /PRNewswire via COMTEX/ -- SonicWALL, Inc., the leading provider of intelligent network security and data protection solutions, today issued its mid-year cyber-threat intelligence bulletin. The bulletin reveals that businesses are increasingly under attack by cyber-criminals who seek to exploit employees connecting to corporate networks via mobile devices and their rising use of social media. Growth in Android-based malware and social media scams such as click-jacking on Facebook and malicious links sent over Twitter are creating new and heightened levels of business vulnerability from data intrusion, theft and loss. Productivity and profitability are also compromised due to network and application downtime. Data for the bulletin was sourced from the SonicWALL Global Response Intelligent Defense (GRID) Network(TM), which gathers, analyzes and correlates billions of dynamic, real-time global cyber-threats.



More...

Jumat, 26 Agustus 2011

Engineers convicted in Goodyear corporate espionage case

tyrepress.com



A US federal judge has sentenced two former Wyko engineers to four years probation and 150 hours of community service after they were convicted of convicted of stealing trade secrets from Goodyear Tire and Rubber Co. in a corporate espionage case that first surfaced in 2009.




According to the Knoxville News Sentinel, federal prosecutors had wanted US district court judge Thomas W. Phillips to give Clark Alan Roberts and Sean Edward Howley at least 10 months in prison, but their lack of previous convictions and “ample” family and community support reportedly won out.



A jury found Roberts and Howley each guilty in December on 10-counts alleging they conspired to steal and use trade secrets. Roberts and Howley, who were employees of Wyko Tire Technology Inc. at the time, had been accused of visiting Goodyear’s Topeka, Kansas plant in 2007 so Howley could use his camera phone to take pictures OTR tyre production procedures.



During the trial Tom Frey, a consultant for Goodyear and a former Goodyear manager, had estimated it cost $520,000 to develop the design drawings for the equipment the defendants were convicted of photographing and that Goodyear made $17 million in 2007 from the sale of tyres that machine produces. However Judge Phillips rejected Frey as a witness and noted that he was not employed by Goodyear and had not produced documentation to verify these figures.



More...


Selasa, 23 Agustus 2011

Android becomes most attacked mobile platform

security.cbronline.com

Going rate of one million stolen email addresses is $25, says cyber security company

Google's operating system (OS) for mobile phones, Android, has become a favourite target for cyber criminals with the amount of malware targeted at Android devices jumping 76% since last quarter, to become the most attacked mobile OS.

According to computer security company McAfee's latest 'Threats Report: Second Quarter 2011', this year has also resulted in the busiest ever first half-year in malware history.

In the second quarter (2Q) of 2011, Android OS-based malware surpassed Symbian OS for the most popular target for mobile malware developers.

The report also said that while Symbian OS and Java ME remain the most targeted to date, the rapid rise in Android malware indicates that the platform could become an increasing target for cybercriminals - affecting everything from calendar apps, to SMS messages to a fake Angry Birds updates.

McAfee Labs senior vice-president Vincent Weafer said, "This year we've seen record-breaking numbers of malware, especially on mobile devices, where the uptick is in direct correlation to popularity."

Weafer also said that cyber criminals are building sophisticated malware which are difficult to detect.

More...

Selasa, 16 Agustus 2011

Phone hacking: News of the World reporter's letter reveals cover-up



guardian.co.uk

he News of the World's former royal correpsondent, Clive Goodman, who was jailed over phone hacking. A letter from him claims phone hacking was widely discussed at the paper. Photograph: Carl De Souza/AFP/Getty Images

Rupert Murdoch, James Murdoch and their former editor Andy Coulson all face embarrassing new allegations of dishonesty and cover-up after the publication of an explosive letter written by the News of the World's disgraced royal correspondent, Clive Goodman.

In the letter, which was written four years ago but published only on Tuesday, Goodman claims that phone hacking was "widely discussed" at editorial meetings at the paper until Coulson himself banned further references to it; that Coulson offered to let him keep his job if he agreed not to implicate the paper in hacking when he came to court; and that his own hacking was carried out with "the full knowledge and support" of other senior journalists, whom he named.

The claims are acutely troubling for the prime minister, David Cameron, who hired Coulson as his media adviser on the basis that he knew nothing about phone hacking. And they confront Rupert and James Murdoch with the humiliating prospect of being recalled to parliament to justify the evidence which they gave last month on the aftermath of Goodman's allegations. In a separate letter, one of the Murdochs' own law firms claim that parts of that evidence were variously "hard to credit", "self-serving" and "inaccurate and misleading".

More...

Sabtu, 30 Juli 2011

US cannot say how many had communications watched

(AP)

WASHINGTON (AP) — Like its predecessor, the Obama administration says it cannot count how many people in the U.S. have had their telephone calls and emails monitored by government agents in national security investigations under federal surveillance law.

The national intelligence office said in a letter this week to two Senate Democrats that it was "not reasonably possible to identify the number."

The senators, Ron Wyden of Oregon and Mark Udall of Colorado, worry that the government may be monitoring communications of law-abiding citizens with inadequate justification.

"We're not asking these questions to embarrass the administration or make the intelligence community's job more difficult," Wyden said in a statement Thursday. "Congress needs to know if the laws it writes are being interpreted and implemented as intended before it is asked to extend them, and failing to assure the public that government agencies aren't violating the rights of law-abiding Americans erodes public confidence and makes it harder for intelligence agencies to do their jobs."

More...

ZeuS Trojan for Google Android Spotted

krebsonsecurity.com

Criminals have developed a component of the ZeuS Trojan designed to run on Google Android phones. The new strain of malware comes as security experts are warning about the threat from mobile malware that may use tainted ads and drive-by downloads.

Researchers at Fortinet said the malicious file is a new version of “Zitmo,” a family of mobile malware first spotted last year that stands for “ZeuS in the mobile.” The Zitmo variant, disguised as a security application, is designed to intercept the one-time passcodes that banks send to mobile users as an added security feature. It masquerades as a component of Rapport, a banking activation application from Trusteer. Once installed, the malware lies in wait for incoming text messages, and forwards them to a remote Web server.

More...

Jumat, 29 Juli 2011

Flying Drone Can Crack Wi-Fi Networks, Snoop On Cell Phones

forbes.com

How do one ex-Air Force official and one former airplane hobby shop owner, both of whom happen to have decades of experience as network security contractors for the military, spend their weekends? Building a flying, unmanned, automated password-cracking, Wi-Fi-sniffing, cell-phone eavesdropping spy drone, of course.

At the Black Hat and Defcon security conferences in Las Vegas next week, Mike Tassey and Richard Perkins plan to show the crowd of hackers a year’s worth of progress on their Wireless Aerial Surveillace Platform, or WASP, the second year Tassey and Perkins have displayed the 14-pound, six-foot long, six-foot wingspan unmanned aerial vehicle. The WASP, built from a retired Army target drone converted from a gasoline engine to electric batteries, is equipped with an HD camera, a cigarette-pack sized on-board Linux computer packed with network-hacking tools including the BackTrack testing toolset and a custom-built 340 million word dictionary for brute-force guessing of passwords, and eleven antennae.

More...

Rabu, 27 Juli 2011

Lock down your cellphone

iol.co.za
Hacking into cellphones is “quite easy”, say local spyware specialists, and it has been commonplace around the world since the technology first came into circulation.

What makes it easy is the fact that few cellphone users bother to set the special PIN codes to allow them to use securely the special feature of accessing their messages from another phone. This means their cellphones remain on the service provider’s default settings – well known to all in the business.

And the user is left vulnerable to hackers such as Glenn Mulcaire, the private investigator at the centre of the UK’s News of the World phone hacking scandal.

But even in cases where the four-digit message default setting has been changed, private investigators say it is relatively easy to access – as long as you have a connection placed inside the particular service provider, or the gift of the “blag” – see sidebar.

Acting on behalf of the tabloid newspaper, Mulcaire – in search of a scoop for his employers – is alleged to have invaded the privacy of not only politicians and celebrities, but also, post-mortem, murdered teenager Milly Dowler and UK soldiers who lost their lives in Afghanistan and other theatres of war.

More...

Minggu, 17 Juli 2011

Rebekah Brooks Arrested for Cellphone Hacking, Bribery

mashable.com
Rebekah Brooks, who was in charge of Rupert Murdoch’s vast media empire in the UK, was arrested Sunday on allegations of cellphone hacking and paying off corrupt cops for information.

She’s the highest official of News Corp. to be arrested so far. According to The Washington Post, she was arrested for “conspiring to intercept communications and on corruption allegations.”

Brooks had resigned her position on Friday as chief executive of News International, according to The Telegraph. She is alleged to have authorized electronic eavesdropping of the cellphones of hundreds of unknowing victims, tapping into the voicemail of a 13-year-old murder victim, and intercepting phone calls of numerous politicians and scores of celebrities.

More...

Sabtu, 18 Juni 2011

Technical Surveillance Threat Series, "Cellular Threats".

Note: This is the first installment in the Spy vs. Spy, "Technical Surveillance Threat Series". Stay tuned. JDL

Technical Surveillance Countermeasures, better known as "TSCM", is defined by "Wikipedia" as:

"A service provided by qualified personnel to detect the presence of technical surveillance devices ("bugs") and hazards and to identify technical security weaknesses that could aid in the conduct of a technical penetration of the surveyed facility".

In the civilian world, the above service is also sometimes referred to as a "Electronic Eavesdropping Detection" sweep or survey, or a "Bug Sweep".

Myself and my team have performed hundreds of TSCM Surveys for fortune 500 corporations, celebrities, executives, embassies, government offices, businesses, private individuals, law firms, etc., etc. There is always a common theme after an area has been cleared, "How can we protect ourselves from electronic surveillance threats after you leave?" The answer is usually complex, and almost always highly dependent upon our review (and recommendations) of our clients security posture and protocols in place at the time of the survey, and after we leave.

In this post, we will deal with one of those threats, "cellular devices", cell phones or "smart phones".

During our pre-survey Technical Threat Assessment, we usually find that "cellular devices" are allowed in almost all areas. There may be a cellular policy in place, but... during our verbal debrief after the area has been cleared, is usually when we find out what we have already discovered, that either there is no security protocol or policy in place regarding the allowance of cellular devices in board rooms and high level meetings, or there is a cellular policy in place, but it is not being enforced.

Almost all cellular phones have cameras, and many smart phones have audio recording features that allow conversations in person or over a smart phone to be easily recorded, stored, and even emailed. If you're like most of us, your cell phone is rarely more than 6 feet away from you. Many have "spy software" installed that allows for the smart phone microphone to be activated in secret without the phone ringing or lighting up. While it sits innocently near you, an eavesdropper can monitor every sound in the room.

So, does this potential eavesdropping threat sound like something that you want to allow in your next confidential boardroom meeting? Can your organization really afford to ignore this type of eavesdropping threat? Does your organization have a cellular policy in place? Is it enforced?

Here are a few personal cellular security tips:

Do not let your cell phone or smart phone out of your physical possession. Most cellular monitoring programs or "spyware" has to be installed through physical possession of the target phone. One of the best countermeasures is to keep tabs on yours.

Password protect your phone. I know it's a pain, but a password on your cell phone could save you or your organization a lot of misery.

Consider a review today of your organizations policy regarding cellular devices. Better safe, than sorry. No time? Contact ComSec, we can help. JDL

Stay tuned for the next installment in the Spy vs. Spy, Technical Surveillance Threat series.

ComSec, LLc provides professional Technical Surveillance & Eavesdropping Countermeasures services to Fortune 500 corporations to small businesses, non-profits, celebrities, executives and select individuals. Headquartered in Virginia Beach, VA | Northern VA-DC-MD. Serving the United States, and select International clients abroad.



Selasa, 31 Mei 2011

Warrantless cell phone searches spread to more states

cnn

(CNN) -- Think about all the data -- photos, videos, text messages, calendar items, apps, call log, voice mail, and e-mail -- on your cell phone right now. If you're arrested, could the police search your cell phone? And would they need a warrant?

That depends on which state you're in.

In California, it is legal for police to search an arrestee's cell phone without a warrant -- ever since a January decision by the California Supreme Court.

California civil rights advocates are pushing back. The Electronic Frontier Foundation is supporting California Assembly Bill SB 914, which would require police in that state to get a warrant before searching an arrestee's cell phone.

EFF also recently filed an amicus brief in the Oregon case of James Tyler Nix, a criminal suspect who was arrested and placed in a holding cell.

According to EFF, "Forty minutes after the arrest, without a warrant, an investigator fished through the suspect's cell phone looking for evidence related to his alleged crime. Law enforcement officials claim they didn't need a warrant because the search was 'incident to arrest' -- an exception to the warrant requirement intended to allow officers to perform a search for weapons or to prevent evidence from being destroyed in exigent circumstances."

More...
Related Posts Plugin for WordPress, Blogger...