world of internet security, latest cyber security news,information,updates on technology,it job vacancies,internet security,breaches,and safeguards

Sunday, 15 July 2018

HOW TO CHECK THE SECURITY OF YOUR GOOGLE CHROME EXTENSIONS

with 0 Comment

Have you ever found out that your chrome is acting weird after adding an extension or you discovered you are being served with malicious content after making a search in google. 
The question is "do you have chrome extensions installed", "do you bother verifying the source of this extensions before installing"?

It is no doubt that Google chrome has become a de facto standard of browsers with nearly 60 percent of market share across all platforms as of June 2018.

Aside from its easy to use interface, security and speed, one of its main features is its wide range of extensions that covers wide range of niche and needs.

What are Chrome extensions?

Chrome extensions are small applications that reside inside Google Chrome. They are build on web technologies like HTML, JavaScript and CSS. They add specific functionalities to Google Chrome’s broad capabilities. 

Can Chrome Extensions be dangerous?

Chrome extensions are small plugin apps that reside within your browser. Therefore, they could potentially have full access to all your data in your browser, such as the websites you visit, the content of these websites, what you enter in forms (e.g. passwords), and more.

Chrome extensions have a layered permission system that could potentially narrow an individual extension’s access to your data to what the extension really needs. But such a system is only as effective as the people who are using it. If you accept every permission a Chrome extension asks for without a second thought nothing can be done.

While Google scans every Chrome extension that is submitted to Chrome Web Store, there are still some malicious ones that slip through the net. And as if things are not bad enough, Google Chrome allows extensions to be installed from third-party websites through something called the inline install API. The good news is that the search behemoth has announced that this functionality will be gradually phased out. From Chrome 71 in early December 2018, the inline install API for Google Chrome will be completely removed from developers’ options.

There are a lot of scenarios that could make an extension dangerous, even after it has been installed. So you have to keep an eye on your Chrome extensions, not only when installing, but also after they have been installed.

WHAT TO DO BEFORE INSTALLING CHROME EXTENSION

Make sure you really need the extension

This one is not about the extension you intend to install but rather proper security hygiene. Every functionality that you add to your system will increase your possible attack surface. There are several cool and funny things out there but if you don’t really need it don’t install it.

Create a dummy Chrome profile to check out possible extensions first

If you are like me, you can’t always adhere to the previous rule. Checking new software is not only fun but may be part of your day-to-day work. After all, how would you know if a Chrome extension will help you increase your productivity without installing it? Creating a new dummy Chrome profile for testing purposes is a reasonable precaution that can help prevent a lot of tears.

Never install an extension from outside of the Chrome Web Store

Google has already enforced this policy for Chrome extensions that are published after June 12th, 2018. But if you have previously installed an extension from somewhere outside of Chrome Web Store, uninstall it now and look for an official alternative on Chrome Web Store.


Make sure you are installing the right extension

This may sound too easy but it isn’t. Earlier this year AdGuard, a company that offers ad blocking products, revealed a list of five malicious Chrome extensions that in all had compromised over 20 million users. Here’s the list of the malicious extensions:

AdRemover for Google Chrome™ (10M+ users)
uBlock Plus (8M+ users)
Adblock Pro (2M+ users)
HD for YouTube™ (400K+ users)
Webutation (30K+ users)
Now have a look at the following list of legitimate extensions:

AdBlock (10M+ users)
Adblock Plus (10M+ users)
AdBlocker Ultimate(750K+ users)
uBlock (500K+ users)
uBlock Origin (10M+ users)
uBlock Plus Adblocker (800K+ users)
And many, many more…

Check out the extension’s website

Not every Chrome extension has a website. There are some popular ones that are programmed and maintained by individual developers. A professionally made website for a bogus extension is also something that malicious actors can create. But checking the website of an extension gives you a more informed picture and can help you make a better decision.

Check the permissions when installing

The permissions an extension asks for should make sense and be as narrow as possible (e.g. a screen capture extension doesn’t need read access to all your data). Keep the extension’s description in mind. If it claims to add functionality to a specific service like Gmail but wants access to all your data on all the domains you visit, don’t install it.

Check the extension’s code

And finally, if you have the skills and necessary time, check the extension’s code. Chrome extensions are built on web technology like JavaScript, HTML, and CSS. So the code is usually readable unless the developers have somehow obfuscated it. Many extensions are hosted on GitHub where you can easily view and download them. The rest you can view in your browser’s Developers tools or find them on your hard drive.

Final thoughts

Chrome Web Store is a jungle full of wonders, both good and bad. So if you go out exploring, go prepared and if you decide to take something extraordinary home with you, think twice.


SILICON VALLEY TARGETS AFRICA AS NEW TECH FRONTIER

with 0 Comment

Lagos is currently attracting interest of global technology giants to tap into its emerging market of young, talented and connected Africans. With its colorful hammocks and table tennis table, a new tech hub in the Lagos metropolis wouldn't look out of place among the start-ups on the other side of the world in Silicon Valley.

But the NG_Hub office is in the suburb of Yaba -- the heart of Nigeria´s burgeoning tech scene that is attracting interest from global giants keen to tap into an emerging market of young, connected Africans.

Recently both Facebook and Google launched initiatives nearby.

This week, The Vice-President of Nigeria, Prof Yemi Osinbajo was in California to court US tech investors for what he said could herald a "fourth industrial revolution" back home.

But Nigeria is not alone in  piquing the interest of tech giants.

Few weeks back, Google announced its intention of opening Africa´s first artificial intelligence lab in Ghana's capital, Accra.
According to demographics, Africa's population is estimated to be 1.2 billion, with 60% of them below 24. by 2050, United Nations estimated the population to double to 2.4 billion.

Tech researcher Daniel Ives at GBH Insights in New York said "This offers a clear opportunity for companies like Google and Facebook to really go all the way in and put a pole in the sand". 

" If you look at Netflix, Amazon, Facebook, Apple, where is a lot of that growth coming from? It´s international," he told AFP.

Facebook currently doesn't have a permanent office in Nigeria, its currently operating from the NG_Hub in yaba area of Lagos. Its head of public policy in Africa Ebele Okobi, said during the opening of the premises that the goal was to cultivate the nascent technology community.

The social network has pledged to train 50,000 people across the country and always equip them with the digital skills required to succeed", she added. 

In exchange, Facebook, which currently has over 26 million users in Nigeria, gains more users and access to a  massive market to test new products and strategies.

She also added "We are invested in the ecosystem. Just the fact that they are engaging... that in of itself is a goal,".

Cyber colonialism? 

Many African governments have given the tech titans an enthusiastic welcome.

In California, Osinbajo said the Nigerian government will "actively support" Google´s "Next Billion Users" plan to "ensure greater digital access in Nigeria and around the world".

Few sectors in Africa inspire as much hope as technology, which has the potential to revolutionize everything from farming to healthcare. Some examples include Ubenwa, a Nigerian start-up that developed an application that identifies music and films from snippets.

Ubenwa analyses a baby´s cry using AI to diagnose birth asphyxia, a major cause of death in Africa when babies don´t get enough oxygen and nutrients before, during or immediately after birth.

Detecting the problem early could save thousands of lives.

"Africans should be responsible to come up with the solutions," said Tewodros Abebe, a doctoral student studying language technology at Addis Ababa University in Ethiopia.

"Unless we are involved, no one can understand the existing problems in our continent."

Abebe dismissed fears that what Facebook and Google are doing represents a form of so-called cyber colonialism.

"Working collaboratively I think is a good way of technology transfer for Africa," he said. "If they are only looking for business, that´s colonisation."

'Epocalypse Now'
As Africa´s technology sector grows, fuelled by growth in mobile phone use, so too does pressure on governments to protect its citizens´ personal data.

Osinbajo told tech leaders Nigeria was keen to create the right environment for development, including for regulation.

But the debate over privacy is muted in many African countries, unlike in Europe, which recently passed tougher new data protection laws.

Facebook has also been at the centre of a storm for failing to protect user data in connection with claims of manipulation in the 2016 US presidential election and the Brexit referendum.

Global Justice Now, an anti-poverty group, fears tech companies are being given free rein to create a global surveillance state.

"We could find ourselves sleepwalking towards a world in which a handful of tech companies exercise monopoly control over whole swathes of the world economy, further exacerbating inequality between the global north and the global south," said the activist group in a May 2018 report titled "Epocalypse Now".

Renata Avila, from the World Wide Web Foundation in Geneva that campaigns for digital equality, said that has not come to fruition but there were pressing concerns.

"The message is that Africa needs investment and it needs to develop these industries, so usually it´s a pro-business narrative," said Avila, a digital rights researcher.

"But there is little oversight," she added, warning that without regulation, people were vulnerable to exploitation.

Wednesday, 13 June 2018

Bitcoin value tumbles as hackers loot CoinRail cryptocurrency exchange

with 0 Comment


Over the weekend, the small South Korean cryptocurrency exchange CoinRail confirmed via Tweet that it had been hacked. On its site, CoinRail explained that 70% of coins/token reserves were moved offline to safe storage in a cold wallet.



Of the 30% of coins that were leaked, CoinRail said that some 80% had been “frozen/withdrawn/redeemed or equivalent”, with the rest under investigation with law enforcement, related exchanges and coin developers.

On Sunday, the price of Bitcoin tumbled 10% to a two-month low, to under $6,700.By Monday, media outlets including Bloomberg, the Wall Street Journal, Reuters, and the Guardian, put two and two together and came up with a loss of up to $42 million as the Bitcoin drop dragged down the value of other cryptocurrencies.
Here’s Bloomberg’s chart of the sudden drop that coincided with the CoinRail news:


Media has directly blamed the hack for crashing markets. How fair is that, though?

If you take a close look at what CoinDesk has depicted as the jaggedly rising (and falling) values from 1 February 2017, on through to the 16 December 2017 peak of $19,343, on into the slip-sliding value that followed, well, you’ll poke your eye out. At the time of writing, it was at $6,760.18, down about two-thirds from its high.

What does a South Korean exchange have to do with it, really? It’s hard to say. The value of Bitcoin was clearly on its way down before the CoinRail hack. After its high of nearly $20,000 four months prior, Bitcoin had its worst quarter ever: in April, it had lost $119 billion in value. Ethereum and Ripple also fell off a cliff: Ethereum fell 47.7%, while Ripple toppled 77%.

The price of cryptocurrency fluctuates wildly even on a good day. Could CoinRail have caused this most recent dip? Maybe. Or maybe it’s due to regulatory moves, as suggested by Smartereum, an Ethereum news service.

While government regulation could help to stabilize Bitcoin, Smartereum suggests, in the short term, it could cause drastic drops, such as happened in China and South Korea. In September, China’s second largest exchange said it would stop trading at the end of the month in response to reports that Beijing was set to ban cryptocurrency trading. Bitcoin price fell on the move. China had already banned Initial Coin Offerings (ICOs), a risky financial instrument being used by start-ups to raise funds.

Value likewise dropped in South Korea when the country forced traders to identify themselves. Maybe regulations will help to calm down rampant speculation in the long term, but in the near term, it helps to turn the value charts into rollercoasters. Perhaps the real story isn’t “hack of an exchange makes Bitcoin value tumble. The other is through the all-too-frequent occurrence of simple daylight robbery. For all their impenetrable cryptography, cryptocurrencies are often exchanged and stored on less than impenetrable websites – also known as “exchanges.”

Just because Bitcoin is resistant to hacking doesn’t mean its resistance gets transferred to the exchanges. The exchanges weren’t made by Bitcoin founder Satoshi Nakamoto after all, they were made by the same people who make all the other websites in the world.

Want to upload your private keys to an exchange to make trading easier? That puts your keys at the mercy of that site’s security, which is an entirely unknown quantity. Websites can be hacked, and keys can be stolen. And don’t count on the Government to protect your assets: the exchanges aren’t backed by any governments or central banks.

Besides that, exchanges are run by people who may or may not be trustworthy, and may not be regulated. They could be crooks, incompetent or brilliantly clever. They might even be as clever as Satoshi, but how much coinage are you willing to bet they are?

Monday, 30 October 2017

Hacking site hacked by hackers

with 2 comments

We try not to guffaw at cyber crime, but sometimes – especially on a Monday just after reading a report from  Bleeping Computer in which a cyber crook turned on his fellow crooks by hacking their underground forum and saying he would expose them to the cops…

…unless they forked over $50,000:

MESSAGE TO BASETOOLS OWNER:

Hello, you have only 24 hours to pay 50.000$ OTHERWISE YOU WILL BE 
EXPOSED AROUND THE WORLD & ALSO WE HAVE TOO MANY PROOFS THAT WE HAVEN'T 
INCLUDED THEM HERE AND THOSE WE WILL SENT TO THE RELEVANT BODIES


The crook uploaded some of his “proofs” to the Basetools hacking site itself, presumably to cause maximum embarrassment amongst the site’s criminal community.

These published “proofs” included a screenshot that’s supposed to show the web administration panel of the Basetools forum, listing the pseudonyms of the last 15 buyers and sellers, as well as the last 9 refunds. Seems that the crooks have problems trusting each other on many different levels.

To pay or not to pay?

We don’t want to be seen as offering advice to cybercriminals, but we’d strongly urge against paying up in extortion cases like this. It’s clear that the data has already been stolen – and some of it already shared with the world, let alone with US law enforcement – so paying now won’t do much good.

In ransomware demands, the extortion typically covers a decryption key for data that almost certainly wasn’t copied by the crooks – in other words, if you decide you aren’t going to pay up, the crooks have nothing further to squeeze you with.

But when the crooks already have copies of your data, and are threatening to besmirch, embarrass or defraud you by exposing it, paying the fee won’t do anything to stop them besmirching you anyway.Or coming back for more money next week.
For what it’s worth, it seems that the Basetools site owners haven’t quite figured out what to do yet – at the time of writing, their underground forum said:


What to do?

Hackers hacking hackers sounds funny, and perhaps it is – but if hackers can be hacked, then so can you, if you aren’t careful. We don’t know how this attack happened, but the obvious precautions you can take for your own online service include:

  1. Patch promptly: If the crooks know what server software version you are using, and it has a known security hole, they may very well be able to break in automatically. In other words, if you haven’t patched, you’re the low-hanging fruit.
  2. Choose decent passwords: If the crooks can guess your password, or if you used the same password on another site that already got hacked, then the crooks don’t need to do any hacking themselves – they can just login directly.
  3. Use two-factor authentication (2FA): A one-time code that changes every time you login means that just guessing or stealing your password isn’t enough. If the code is calculated on or sent to your phone, then the crooks need your phone (and its unlock code) as well, which is a higher bar to jump over.
  4. Check your logs: If you keep log files for auditing purposes, for example so you can check who logged in when, examine them proactively in order to find out about security anomalies sooner rather than later.    Honour amongst thieves, eh?