world of internet security, latest cyber security news,information,updates on technology,it job vacancies,internet security,breaches,and safeguards

Showing posts with label THREATS. Show all posts
Showing posts with label THREATS. Show all posts

Monday, 7 January 2019

How to protect your Facebook account

with 0 Comment

Here we walk you through the important settings you can change and behaviors you can implement to lock down your privacy on the social network.

Note: To change many of the settings below, Facebook will ask you to input your password. It’s a good reminder that if your password isn’t strong or unique to the site, now is the perfect time to change it!

Enable 2FA

If you only do one thing on the list in this article, do this: enable two-factor authentication (2FA). This means someone trying to break into your Facebook account needs more than just your password, they also need a second token that you own, be it a code or a physical key. The chances of someone having this in their possession are pretty small, so this step will stop most intruders in their tracks.

Facebook will walk you through the steps to enable 2FA on your account to help you get set up. You have a few options available to you for how you want to authenticate: you can choose to use a code sent to you by text message, which is easiest but not completely secure, or to use a code generated by an authenticator app on your phone, which takes a little more setup work.

If you’re really savvy and browsing using the website on a computer, Facebook also supports U2F keys like YubiKey, which is a physical key you plug into your computer’s USB port as your authentication token.

How to do it on your desktop: Go to your Facebook Settings and select Security and Login from the menu on the left. Next to Two-Factor Authentication click Edit and then Get Started.

How to do it in the app: Open Privacy shortcuts from the hamburger menu in the bottom left. Scroll down to the Account Security section and tap Use two-factor authentication. Choose whether you want to set up SMS 2FA or use an authenticator app.

You can turn on 2FA for your account from either the website or the app, you don’t have to do it in both places.

Get login alerts

If someone does manage to get into your Facebook account, you’ll want to know about it as soon as possible. If requested, Facebook can alert you to any strange-seeming logins to your account. You can be alerted via email, text message, Facebook message or even a Facebook in-app notification. It’s a little peace of mind and a very simple measure to set up.

How to do it on your desktop: In your Facebook settings, select Security and Login and scroll down to Setting up Extra Security. Hit the Edit button on Get alerts about unrecognized logins and customize how you’d like to be notified.

How to do it in the app: Open Privacy Shortcuts from the hamburger menu in the bottom left. Scroll down to the Account Security section and tap Receive alerts about unrecognised logins.

Check your connected apps

That quiz you took years ago about your star sign that you promptly posted and forgot about? All these years it’s had permission to see your profile, posts, and friends’ posts into perpetuity, so why does it still have this access?

You could have any number of apps like this quietly sniffing your information in the background. There’s an easy way to check what apps you might still have enabled, and disable them if you like. It’s best to have as few apps enabled as possible – and definitely remove permissions for any apps that you don’t recognize or remember using.

How to do it on your desktop: In your settings, go to Apps and Websites. Check the apps in your Active and Expired categories and remove any or all of them.

How to do it in the app: Open Settings from the hamburger menu in the bottom left. Scroll down to the Security section and tap Apps and Websites. Open Logged in using Facebook and check the apps in your “Active” and “Expired” categories and remove any or all of them.

Note, there is also a Business Integrations section, separate to Apps and Websites, that you might want to check for connected services too.

Be discriminating in how people find and contact you

The whole idea of Facebook is to reach out to friends and family and grow your network, but spammers and fake profiles seem to be some of the most enthusiastic users of the platform lately.

If you’re tired of getting suspicious Facebook friend invitations, or would rather not invite the risk of getting a phishy or malicious link on your Facebook wall, be discriminating in who you befriend. We suggest limiting who can contact and find you on the platform to “Friends of friends,” and to limit email and phone lookups to “Friends of friends” as well.

How to do it on your desktop: In settings, select Privacy. Modify your preferences for how you can be found on Facebook under the How people can find and contact you section.

How to do it in the app: Open Settings from the hamburger menu in the bottom left. Scroll down to the Privacy section and hit Privacy settings. Scroll down to How people can find and contact you. 

Call for backup: Choose friends to help if you’re locked out

If you’ve had issues in the past with your account being compromised – say if you’re a public figure or just very unlucky – Facebook has an option to let you select three to five people in your friends list who you can call on to help you gain control over your account if you’re ever unable to log in (say, because someone else has locked you out.)

This is not a feature that everyone will need, so if you don’t think it’s going to be that big a deal if you’re locked out of your account, feel free to skip this one. But if Facebook is your primary means for earning a living, or communicating with customers or your fanbase, this setting is worth your consideration.


The people you choose to be your backup – which Facebook calls your “trusted contacts” – should be people you know will be tech-savvy enough to know how to help you quickly (so, ideally someone who knows how to use a smartphone), and they should also know ahead of time that you’re choosing them to be a trusted contact, as Facebook will notify them that you’ve tapped them for this ‘honor’.

At no point will any of your trusted contacts have access to your Facebook account personally, nor will they be able to commandeer it at any time – they will be able to send you a code and a URL to help you log back into your account in case of an emergency.

How to do it: In Settings, go to Security and Login and scroll down to Setting up extra security. Hit edit on Choose 3 to 5 friends to contact if you get locked out and follow the instructions.

How to do it in the app: Open Settings from the hamburger menu in the bottom left. Under Security, tap Security and login and scroll down to Setting up Extra Security. Hit Choose 3 to 5 friends to contact if you are locked out.

Face recognition and tag privacy

Facebook maintains that it has face recognition capabilities for our own benefit – so we can know if we’re in a photo but haven’t been tagged, and someone can’t impersonate us by using our profile photo (we’re wise to your tricks, spambots!). But many of us also find this kind of tech creepy and intrusive. If you don’t want Facebook to proactively find you and identify you in photos, you can disable face recognition.

How to do it on your desktop: In Settings, select Face Recognition and then choose No.

How to do it in the app: Open Settings from the hamburger menu in the bottom left. Scroll down to Privacy and open Face recognition. Select No.

Note that face recognition isn’t the same as when people you know tag you in photos. If you don’t want people to tag you in photos or posts without your approval first, there’s another setting you’ll want to enable.

How to do it on your desktop: In Settings, go to Timeline and tagging and then choose On for both options in the Review section.


How to do it in the app: Open Settings from the hamburger menu in the bottom left. Scroll down to Privacy and open Timeline and tagging. Scroll down to Review and ensure both are set to On.

Keep your posts friends-only

You wouldn’t leave your front door open all the time. Why make the details of your personal life open and public for all the cybercriminals in the world to mine? Leaving your posts all public-facing is a gold-mine for criminals looking for details to try and guess security questions, or impersonate you to scam friends or family.

There’s a really easy solution here: Keep your Facebook posts out of the public eye and make the default privacy level friends-only. That way only the people you have approved and friended can see what you’re up to.

How to do it on your desktop: In settings, select Privacy. Under Your Activity set Who can see your future activity? to Friends, and click Limit past posts to retroactively make all your previous posts Friends-only as well.

How to do it in the app: Open Settings from the hamburger menu in the bottom left. Scroll down to Privacy and open Privacy settings. Under Your Activity set Who can see your future activity? to Friends, and also go back a step and turn on Limit who can see past posts too.

Be discriminating in what you do

Unfortunately, the risks to Facebook users are no longer just from external forces trying to break their way into your account. Unfortunately, we’ve learned in the last year or so that there have been a few Facebook-approved data miners, like Cambridge Analytica, that were given unfettered access to what Facebook users were up to behind the garden walls.

So the steadfast internet advice applies here as anywhere: Mind what you post, and remember that the internet is forever. Even content you post behind the friends-only filter on Facebook is not an ironclad guarantee of privacy, so use discretion and if your gut is telling you to not hit that “post” button, it’s best to listen.

Tuesday, 17 January 2017

WhatsApp ‘backdoor’ turns out to be known design feature

with 0 Comment

On Friday, The Guardian newspaper accused Facebook’s WhatsApp messaging app of having a “backdoor” security vulnerability on the basis of a security issue revealed to it by researcher, Tobias Boelter of the University of California at Berkeley.

The newspaper has since backed away from the emotive word but the fire had been lit. Was this a fair accusation to throw at WhatsApp?

The report described how the app generates a new key pair for “offline” users, for example when a user loses or changes a phone or phone number and then (after a period of time) reinstalls the app afresh

In the respected Signal app, whose underlying encryption protocol was adopted by WhatsApp in 2016, messages sent to anyone in this situation are deleted and the sender is informed that something has changed. The message can then be re-encrypted and resent after verification that the recipient is still the same person.

In WhatsApp, by apparent contrast, the sending app is simply asked to re-encrypt and re-send the message, something the sender will only be told about if alerting is turned on, after the fact.
The issue is that WhatsApp’s servers could, hypothetically, force the resend of a message using a new key under its control without the sender being able to stop that – a man-in-the-middle (MitM) compromise of sorts.

The first objection with this is that hiding a malicious key reset indefinitely would be difficult on WhatsApp given the software’s “verify security code” feature that ensures both sides are using the same key and no MiTM is taking place.

This also looks more like a design trade-off than a backdoor. As a mass-market product, WhatsApp was designed to make itself as transparent as possible and not to bother users with possibly confusing alerts about key pair changes.

The developer who co-authored the Signal protocol used by WhatsApp, Open Whisper Systems’ Moxie Marlinspike, said the backdoor claim was a misnomer:  “Under no circumstances is it reasonable to call this a ‘backdoor,’ as key changes are immediately detected by the sender and can be verified.”

“It is great that the Guardian thinks privacy is something their readers should be concerned about. However, running a story like this without taking the time to carefully evaluate claims of a ‘backdoor’ will ultimately only hurt their readers.”

For something to be a true “backdoor”, it must simultaneously satisfy two criteria beyond simply compromising security or privacy. First, it must have been put there deliberately, for either benign or villainous reasons. Second, it must be undocumented, which is to say only the people who put it there know about it.

The minute a backdoor  becomes public knowledge, it stops being one and becomes just another security flaw that needs to be fixed if that product wants to hang on to its users.

On that basis, it is inaccurate to describe the WhatsApp issue as a “backdoor” when it is really a known design compromise, and also one that people should be aware of.

Wednesday, 25 May 2016

LinkedIn password change flaw poses a potential threat to all users

with 0 Comment
LinkedIn password change flaw poses threat to at-risk accounts

A vulnerability in LinkedIn's password change process poses a potential threat to all users, especially those whose accounts might have recently been compromised.

If you've been following the news, you've likely heard about how a hacker named "Peace" is attempting to sell 117 million LinkedIn users' emails and passwords on The Real Deal, a dark web marketplace which traffics primarily in zero-day exploits.

hackers originally stole the data during the LinkedIn breach of 2012. The original hackers posted only 6.5 million usernames and passwords at the time. In reality, it appears that they had access to details of 167 million users' accounts, including 117 for which both passwords and emails were available.

Since news first broke about the true scope of this breach, many LinkedIn users have decided to change their passwords out of caution.

If they weren't careful, however, they might have just exposed their accounts to unauthorised parties regardless.

Confirm button 1040cs060712

The vulnerability in LinkedIn's password change process occurs when users are signed into their LinkedIn account on more than one device at a time and decide to change their password on one of them.
To check this vulnerability, i decided to change my password on a LinkedIn's Android mobile device while also being signed into my account on a PC. After changing my password, i discovered something interesting when i went back to my desktop:

"If you go back to your browser from PC and hit refresh, you will notice that you still remain logged in with old credentials. You can do all activities such as post, message, connect, etc but you will not be able to change password, add email addresses, or phone numbers to account. You will be received with password prompt asking for credentials, and you can still go back and perform activities. I have been monitoring this issue and noticed I can stay logged in indefinitely using this method."

With that in mind, if you happened to change your LinkedIn password at home but forgot you had logged into your profile earlier that afternoon on a public computer, an attacker could potentially exploit this bug to assume control of your account.

Screen shot 2015 09 07 at 8.42.26 am

NOTE: We advise against reusing passwords on different websites, and enable two-step verification (2SV) on their LinkedIn account.



How to protect your LinkedIn account from hackers with two-step verification (2SV)

with 0 Comment
How to enable 2SV on LinkedIn

In the wake of recent revelations about the 2012 LinkedIn data breach, many users would be wise to consider not just ensuring that they are using a unique, hard-to-crack password for their LinkedIn account - but also that they have enabled two-step verification (2SV).

Two-step verification provides an additional layer of security for your online accounts - meaning a hacker needs more than just your username (which is often your email address) and password to access an account. They also need a one-time verification code, that was perhaps sent to the genuine account owner via an SMS message or phone call.

2SV doesn't necessarily make it impossible for hackers to break into your account, but it certainly makes it more complicated - and as a result, hackers may simply spend their efforts breaking into the accounts of users who had not enabled the additional level of security.

This is why we have detailed how to enable 2SV for a number of different websites including Google, Apple, Yahoo, PayPal, Amazon, Dropbox, Twitter and Facebook.

In this article series, I will show you how you can implement 2SV on your LinkedIn account.

1. Sign into your LinkedIn account using a web browser.

2. On the homepage, you will see a picture of yourself (or a black and white image of a faceless individual) at the top right corner. Hover your cursor over that image.

A menu labeled "Account & Settings" will drop down from that icon. You can use this menu to sign out, upgrade your account, access LinkedIn's Help Center, or manage your profile's privacy and settings. The lattermost option is the one you want. Move your cursor down the menu and click on the "Privacy and Settings" option.

Linkedin 1

3. You will be redirected to your Account homepage, where you can add email addresses and phone numbers, change your password, and access additional features.

Near the middle of the page, you will see three clickable tabs: "Account," "Privacy," and "Communications." The "Account" tab should be highlighted. Move your cursor over and click on the "Privacy" tab.

Linkedin 2

4. Scroll down to the very bottom of your privacy settings page. There you will see a "Security" section with a single clickable option: "Two-step verification." This feature should be labeled "Off." Click on this feature to begin the process of enabling 2sv on your account.

Linkedin 3

5. LinkedIn will prompt you to register a mobile phone number so that you can activate 2SV. Click on the "Add a phone number" option that will automatically appear in the "Security" section under "Two-step verification."

Linkedin 4

6. You will automatically be redirected back to your "Account" page and to the "Phone numbers" feature under the "Basics" section. There, enter in your mobile phone number in the provided text field and click the blue "Send code" button.

Linkedin 5

7. LinkedIn will prompt you to enter in your password to make that change. Do so and hit the "Done" button.

8. LinkedIn will then notify you it has sent a verification code to your mobile device. Enter that code into the provided text field and click the "Verify" button.

9. With your mobile phone number now registered, repeat steps 3 and 4.

10. In the "Security" section of your privacy settings page, LinkedIn will explain how turning on 2SV will affect your account in the future. Read that explanation carefully. When you fully understand it, click on the "Turn on" hyperlinked text.

Linkedin 6

11. Once again, LinkedIn will prompt you to enter in your password. Do so and hit the "Done" button.

12. LinkedIn will then send another code to your mobile phone. As you did in step 8, enter that verification code into the provided text field and click "Verify."

13. And you're done! You will see your phone number saved under "Two-step verification" feature, which will be labeled "On."

Linkedin 7

Now every time you log into your account, you will see this page after entering in your username and password.

Linkedin 8

Simply enter in the verification code sent to your mobile phone, and you will automatically be redirected to Linkedin's home page.

Thursday, 14 April 2016

Qbot Worm Infects Over 54,000 PCs at Organizations Worldwide

with 0 Comment
Mutating Qbot Worm Infects Over 54,000 PCs at Organizations Worldwide 

The Qbot worm, also sometimes known as Qakbot, is not a new threat. First seen as far back as 2009, the malware continues to spread because online criminals have taken its original source code and continued to adapt it to evade detection.

Typically Qbot is being spread via compromised websites, hosting the Rig exploit kit. When a user visits the hacked site on a vulnerable computer, a malicious obfuscated script is silently executed to serve up the exploit and install the malware onto Windows PCs.
Furthermore, the malware is capable of detecting if it is running inside a Virtual Machine sandbox, and change its behavior in an attempt to avoid being spotted.

Qbot is primarily designed to harvest passwords and other credentials. Qbot sneaks and attempts to grab passwords from Windows’ Credential Store, potentially revealing network logins, and passwords used for Outlook, Windows Live Messenger, Remote Desktop and Gmail Messenger.

Also, Qbot attempts to access Internet Explorer’s password manager, stealing cached username and password credentials. With these details – and further credentials stolen from network traffic – Qbot’s attackers can break into FTP servers and infect other websites with exploit kits to spread their malware.

Furthermore, because of its backdoor capabilities, Qbot opens a potential route for hackers to steal sensitive data or intellectual property, disrupt infrastructure, or plant more sophisticated malware inside an organization.

Tuesday, 12 April 2016

SSL: Still Secure When Configured Correctly

with 0 Comment

The Secure Socket Layer (SSL ) protocol is under attack: in recent months, a succession of vulnerabilities and successful breaches have raised questions about the effectiveness of this ubiquitous security standard. The emergence of DROWN (Decrypting RSA with Obsolete and Weakened Encryption) in early March 2016 may have finally forced IT admins to take action.

The fact that so many attacks are now focused on SSL is more important than you might think.

SSL and its successor, TLS (Transport Layer Security), are responsible for securing a whole range of Internet services. For example, most email and FTP clients support SSL/TLS. And for VPNs based on SSL such security breaches are totally unacceptable.

It is hardly surprising that there are so many issues. SSL was developed by Netscape programmers during the nineties while working on Mosaic, the first Internet browser designed for mass web surfing. In those days security as a concept was completely different from what it is today. This, alongside market release pressures, resulted in SSL emerging as a fairly simple protocol.

Early attacks on SSL were focused on Certificate Authorities (CA) authentication. However, attackers have set their sights on this protocol and its implementation for many years now. DROWN is merely the latest example in a long list of vulnerabilities that have also included Heartbleed, Poodle and Beast.

The biggest change has been the technical capability available to cyber criminals to unearth new vulnerabilities. Twenty years ago the computational power of something like Amazon’s S3 cloud service was only possible for national governments to leverage. It was far out of the reach of the average cyber criminal who were themeselves much less sophisticated than their modern counterparts.

Implementing Standard Security Measures


The problem is unlikely to go away, at least until TLS 1.3 is introduced across the board. For now, a patch or settings adjustment is usually available for all known vulnerabilities. Aside from this it is recommended that users stick to the same best practices as they would for any other Internet service. Basic encryption and protocol versions should be set to the highest possible level. Finally, ensure the operating system is hardened and limited only to the most essential hosted services.
Share on LinkedIn

Wednesday, 6 April 2016

The Panama Papers and the nigerians involved.

with 0 Comment
 
 
 
The ‘Panama Papers‘ consist of 11.5 million confidential files revealing how billions of dollars are hidden offshore by politicians and notable figures from around the world. Leaked from one of the world’s biggest law firms, Mossack Fonseca, which is a Panama-based law firm whose services include incorporating companies in offshore jurisdictions such as the British Virgin Islands. It administers offshore firms for a yearly fee. Other services include wealth management.
 
The Panama Papers leak has been tagged the biggest information leak in history larger than the US diplomatic cables released by WikiLeaks in 2010, and the secret intelligence documents given to journalists by Edward Snowden in 2013. There are 11.5m documents and 2.6 terabytes of information drawn from Mossack Fonseca’s internal database. its 2.6 terabytes worth of data.
Here are the Nigerian(s) involved in the #panama papers scandal:
 
James Ibori
 
The former governor of the Niger Delta who pleaded guilty to money laundering and fraud charges in 2012 has been serving a 13-year jail term in the United Kingdom. However, as of now, he’s still the only Nigerian that has been featured on the ICIJ website as part of the Panama Papers scandal. From his bio on the International Consortium of Investigative Journalists  (ICIJ) ICIJ website, Ibori could be termed a serial “embezzler.”
 
The website made attributions to Ibori’s trial three years ago saying “Ibori admitted using his position as governor to corruptly obtain and divert up to $75 million out of Nigeria through a network of offshore companies, although authorities alleged that the total amount he embezzled may have exceeded $250 million.”
 
Bukola and Toyin Saraki
 
According to Premium Times, the Senate President, Bukola Saraki, and his wife Toyin may be involved in the scandal as well. The paper has alleged that the Sarakis have at least 4 undeclared assets in “secret offshore territories.” While Saraki has denied owning undeclared properties, reportedly saying he has “declared his assets properly in accordance with the relevant legislation,” and that the charges against him “are both unfounded and politically motivated,” his family name may still be tainted as his brother, Laolu Saraki is linked to one of the names on the list.
Laolu Saraki was listed in the Panama Papers as a business associate of Kojo Annan, the son of the United Nations Secretary General, Kofi Annan, whose name is very prominent on the list.
 
What does Mossack Fonseca say about the leak?

The firm won’t discuss specific cases of alleged wrong doing, citing client confidentiality. But it robustly defends its conduct. Mossack Fonseca says it complies with anti-money-laundering laws and carries out thorough due diligence on all its clients. It says it regrets any misuse of its services and tries actively to prevent it. The firm says it cannot be blamed for failings by intermediaries, who include banks, law firms and accountants.
 
 


Saturday, 26 March 2016

Cyber Most Wanted list: FBI adds two Syrian Electronic Army hackers

with 0 Comment
WANTED 

The Syrian Electronic Army (SEA) is famous for spearphishing well-known brands and news outlets.

Over the past 5 years, the group has launched attacks against targets including the White House, Harvard University, Reuters, the Associated Press, NASA, CNN, Time, the Washington Post, The Onion and Microsoft, among others.

The SEA’s attacks have included compromising the Twitter account of the Associated Press in April 2013, to post a bogus tweet that the White House had been bombed and that President Barack Obama had been injured.

That hack resulted in a short-lived but perilous dip in the stock market, to the tune of $136 billion.

They may be experts at spearphishing , but they weren’t particularly good at covering their tracks on Facebook or Google, it turns out.

That’s how investigators know the names of the three men they filed charges against on Tuesday.

They are Ahmad Umar Agha, 22, of Damascus, Syria; Firas Dardar, 27, of Homs, Syria, and Peter Romar, 36, of Walterhausen, Germany.

The FBI on Tuesday added two of them – Agha and Dardar, both believed to be in Syria – to its “Cyber Most Wanted” list and put a price tag of $100,000 on each of their heads, payable to whoever can provide information that leads to their arrest.
Agha – who has allegedly used the aliases The Pro and Th3Pr0 – is “one of the most aggressive and experienced members in SEA,” responsible for the majority of past hacks, and is “one of the more stealth members.”

He’s allegedly behind the first ever SEA attack: the defacement of the University of California’s website in July 2011.
He may be Stealth, but according to IntelCrawler, “The Pro” “unknowingly and carelessly” let slip on his Google Plus page that he worked at the SEA.

The report details a long digital trail left by the alleged hackers as they communicated via Google, Facebook, LinkedIn and other online services.

Because of that digital trail, investigators also traced Dardar, who was allegedly known online as “The Shadow.” The Feds claim that starting in 2013, Dardar worked with Peter “Pierre” Romar on an extortion scheme targeting US businesses.

According to the complaint, the pair would hack into the victims’ computers and then threaten to damage computers, and delete or sell the data unless they were paid a ransom.

The Washington Post on Tuesday cited US officials who said that Romar was arrested in Germany. The Department of Justice is seeking to extradite him.

The US has issued arrest warrants for the two men it’s placed on its Cyber Most Wanted list: “The Pro” and “The Shadow.”

Assistant Attorney General for National Security John Carlin said in a statement that the conspirators’ extortion schemes undermine their own claims of working for a noble cause – to support the embattled regime of their president.