Remember the other day we reported
that a security firm had discovered a
four year old vulnerability in Android
that could potentially affect up to 99%
of Android devices out there? Well the
good news is that Google wasted no
time in fixing it and according to Gina
Scigliano, Google’s Android
Communications Manager, it seems
that it has been confirmed that Google
has since provided a patch to their
partners, some of whom, like
Samsung, have begun shipping the fix
to Android devices. Basically what this
means is that while Google has the
patch ready, you might have to wait a
bit until your manufacturer
incorporates it in their next update, so
some of your friends might receive it
earlier, or maybe even later than you.
Those in countries where updates
have to go through carrier approval
probably will end up waiting much
longer. In any case hopefully
manufacturers will be getting on this
right away, so keep your eyes peeled
for any updates that your manufacturer
or carrier might be pushing to you in
the near future!
News Categories
Tuesday, 9 July 2013
Google Releases Patch To Fix Android Vulnerability
Monday, 1 July 2013
How Much Is Your Gmail Account Worth?
Many people don't realize just how
valuable their email account is
. Now, thanks to researchers at the
University of Illinois at Chicago, a
nifty tool called Cloudsweeper
calculates how much your account
would be worth, if cyber-criminals
ever managed to get control.
Whenever someone's email gets
hacked, whether through a phishing
attack, malware, guessing passwords,
or plain brute-force, a common
complaint goes something like this:
"Why did I get hacked? There is
nothing interesting in my account."
The thing is, the criminals aren't
looking for exciting gossip buried
within your correspondence or looking
at the pictures you've emailed people.
They are looking for valuable data,
such as passwords to other accounts.
Your email account is quite frequently
used for password resets. If someone
gets control of your account, that
person can search through the saved
messages and figure out what other
sites use the email address for
account recovery. Access to your
online banking account, login
credentials for Facebook and Twitter,
and details for iTunes and Amazon
accounts are all accessible via your
email account. I know many people
who treat their email accounts as
secret storage, frequently emailing
private keys and password reminders
to themselves.
My Gmail Is Worth $15
Enter Cloudsweeper, a project from
researchers at the University of
Illinois at Chicago. The tool scans all
the messages in your account to figure
out what other services use the
address to send password reset
emails, or to login to the service. The
tool also tracks services that sent the
actual password when the user
clicked on the "forgot password" link.
The tool assigns a dollar figure to the
data pieces found to determine how
much the account is worth in the
underground market.
I ran one of my Gmail accounts
through Cloudsweeper, and it
determined my account would be
worth approximately $15.30 to bad
guys. I was surprised, because I use
this account purely for accessing
Google services and don't use it to
sign up for third-party services (I
keep a separate account for that) or
for regular correspondence (a
different account for that). I'd
forgotten that I did use this account for
one of Twitter accounts, as well as
my Kindle account on Amazon.
According to the tool, my Amazon.com
account was worth approximately $15
to the criminals and Twitter was worth
$0.30.
There were some false positives, as a
result of the fact that I long ago used
this account for my PayPal account.
I've since then changed the email
address associated with PayPal, but
since I still had some of their emails
archived, CloudSweeper flagged the
service as a potential risk. I asked a
friend to scan his account, and
Facebook popped up (worth $5) on his
list of risks, except he doesn't have an
account on that social network. The
alert seems to have been fooled by
various Facebook friend requests he
received in the past that he never
deleted.
How Much Are You At Risk?
Cloudsweeper uses prices for account
types and data collected from various
sellers across multiple underground
forums to calculate how much the
information in the user's email
account is worth, said Chris Kanich,
assistant professor at UIC's computer
science department and principal
organizer of the project. It uses OAuth,
so you just have to be logged in to the
account when you run the "audit" from
the project's page. No passwords are
stored, and you can just revoke
permissions at the end so the tool no
longer has any visibility into your
account.
If nothing else, this tool is great for
spring cleaning, to wipe out some of
the old emails that you don't need to
keep anymore. Close accounts you
aren't using, or at least make sure
your information has been removed.
And once you realize just how
valuable your account is,
Sources: PC Mag
The Best Antivirus Software: New Winners and Losers
Those malware coders who cobble
together all the Trojans, viruses, and
other nasty programs are constantly
working on new creations, hoping to
get past existing antivirus defenses.
Security vendors are likewise
constantly working on new
technologies to foil the bad guys. That
means PCMag's long running Best
Antivirus story is a work in progress.
The latest revision, published earlier
this week, adds nine new or updated
programs, some of which are quite
interesting.
New Editors' Choice
Ad-Aware Free Antivirus+ 10.5 is only
a point-five revision, but my Lavasoft
contacts insisted it merited a new
review. They were right; it earned
great scores in my hands-on tests. Its
score in my malware blocking test,
9.4 points, beat out all other products
tested using the same collection of
samples, and only one of those
products matched its 94 percent
detection rate. With 83 percent
detection and 5.8 points overall, it
also beat all of the latest products,
though it didn't stay at the top.
These dandy scores along with a
super-smooth installation process
earned Ad-Aware the designation of
Editors' Choice for free antivirus. It
joins existing free Editors' Choice AVG
Anti-Virus FREE 2013 .
Funny-looking Newcomer
Funded using Kickstarter, Jumpshot is
definitely the strangest-looking
antivirus around. All antivirus and
system tune-up tasks are handled by
cartoonish "minions," each with its
own specific task. For example,
Kobayashi the ninja is in charge of
wiping out malware.
This product is actually a bootable
Linux antivirus, but you won't see any
signs of Linux. After a scan, restuls
are presented by the various minions
in cartoon talk-balloons. The
surprising fact is that Jumpshot
outscored all other recent products in
my malware removal test, even Ad-
Aware, with 86 percent detection and
6.5 points. Its tuneup measurably
improved performance on a physical
test system. Do note, though, that
you'll still need a regular antivirus for
ongoing protection, as Jumpshot is
strictly a scan-and-clean tool.
Not So Hot
The antivirus field in general is
growing and evolving, with most
products doing at least a decent job of
rooting out malware and preventing
new infections. IObit Malware Fighter
2 , recently reviewed for the first time
by PCMag, is a notable exception. In
both my malware blocking and
malware removal tests, it achieved
new low scores.
For malware removal, IObit scored an
unprecedented 0.8 of 10 possible
points; the next-lowest score was 4.2
points. IObit identified seven of my
twelve malware-infested systems as
perfectly clean. It earned just 1.5
points for malware blocking, far below
the next-lowest score of 5.9 points,
yet still managed to identify some
valid programs as suspicious. The
best thing I can say about this
program is that it has plenty of room
for improvement.
These are just three of over forty
recent antivirus reviews.
Sunday, 23 June 2013
U.K. regulator to Google: Delete Street Viewdata -- or else
But Google kept some data on hand, leading the ICO to reopen its investigation in April 2012. "Google has...confirmed that it still has in its possession a small portion of...data collected by our Street View vehicles in the UK," Peter Fleischer, Google's global privacy counsel, wrote in a letter released by the ICO last year.
He said that "Google apologizes for this error." The ICO was not pleased with that revelation. It had signed an agreement with Google in November 2010, requiring the company to fully remove all Street View data it had collected on U.K.-based residents by December 2010. But Google didn't delete everything.
Friday's ruling is essentially the decree the ICO sent down in 2010, requiring that Google delete all data within the next 35 days. Upon completion, Google must inform the ICO that the data has been deleted. If the company fails to delete the data within that period, it could be hit with a criminal offense for contempt of court.
"The ICO's investigation found that the collection of payload data by the company was the result of procedural failings and a serious lack of management oversight including checks on the code," the ICO said in a statement Friday. "But the investigation also found there was insufficient evidence to show that Google intended, on a corporate level, to collect personal data." Based on that, the ICO decided that Google should not be monetarily fined. Instead, the company can simply delete the remaining data and move on.
Facebook says bug exposed 6 million users' contact information
Facebook Inc has inadvertently
exposed 6 million users' phone
numbers and email addresses to
unauthorised viewers over the past
year, the world's largest social
networking company disclosed late
Friday.
Facebook blamed the data leaks,
which began in 2012, on a technical
glitch in its massive archive of contact
information collected from its 1.1
billion users worldwide. As a result of
the glitch, Facebook users who
downloaded contact data for their list
of friends obtained additional
information that they were not
supposed to have.
Facebook's security team was alerted
to the bug last week and fixed it within
24 hours. But Facebook did not
publicly acknowledge the bug until
Friday afternoon, when it published an
"important message" on its blog
explaining the issue.
A Facebook spokesman said the delay
was due to company procedure
stipulating that regulators and affected
users be notified before making a
public announcement.
"We currently have no evidence that
this bug has been exploited
maliciously and we have not received
complaints from users or seen
anomalous behaviour on the tool or
site to suggest wrongdoing," Facebook
said on its blog.
While the privacy breach was limited,
"it's still something we're upset and
embarrassed by, and we'll work
doubly hard to make sure nothing like
this happens again," it added.
The breach follows recent disclosures
that several consumer Internet
companies turned over troves of user
data to a large-scale electronic
surveillance program run by U.S.
intelligence.
The companies include Facebook,
Google Inc, Microsoft Corp, Apple Inc
and Yahoo Inc.
The companies, led by Facebook,
successfully negotiated with the U.S.
government last week to reveal the
approximate number of user
information requests that each
company had received, including
secret national security orders.
Copyright Thomson Reuters 2013

