Friday, May 29, 2015

Five Ways You'll Be Hacked on Cyber Monday


According to a June 2014 study by the Center for Strategic and International Studies, the likely annual cost to the global economy from cybercrime could reach $575 billion. It's a big number. Here are five ways hackers will try to get you to contribute to it while you enthusiastically search for the best deals on Black Friday and Cyber Monday. Hack #1 -- Social Engineering - the process of manipulating people to give up private information. Some of the most well publicized hacks in recent memory have been socially engineered. What's more likely... Apple's iCloud being hacked or someone (such as Kate Upton or Jennifer Lawrence) being tricked or willingly "lending" their password to someone? If you are checking out on an obscure website this Cyber Monday and the site asks you to "confirm" the last four digits of your social security number, you're about to be hacked. No commerce site needs your social security number, not even the last four digits. The request will look innocuous, you'll be busy getting a deal on that awesome pair of rare Nike kicks, and you'll be one step closer to having your credit card spoofed or worse. Countermeasures -- Don't give up more information than is absolutely necessary. Hack #2 -- Phishing - the act of defrauding an online account holder of financial information by posing as a legitimate company. Got an email from Amazan.com? Yeah, that's not Amazon. Look closely. Thanksgiving is one of the heaviest phishing days of the year, because fewer people paid to protect you from phishing attacks are working. Phishing attacks are actually 336% more common on Thanksgiving, meaning you're far more likely to receive a suspicious email in your inbox on Cyber Monday. There's a reason Gmail sent that email to your Spam folder. Leave it there. If you didn't ask for it, don't click on it! There's no reason to give out your financial info because a scammer decided to send you a halfway decent-looking email. Countermeasures -- Carefully, carefully, carefully check who emails are from. If you're not sure about a sender, it's best to avoid that email and deal. Hack #3 -- "Scammer Grammar" and General Scamming Behavior - If a website features many misspellings and grammatical errors, be wary. No company that genuinely wants your business will rush to put up a listing that looks like it was typed by a third grader. Beware of sites that require payment via wire transfer, or that require you to act immediately to secure the product. Consumer Affairs says, "Beware of 'act now' offers that tell you the seller is a soldier needing cash for possessions before deploying to a war zone or a recent divorcee wanting to unload her former husband's belongings. These tactics are often bait to empty your wallet. Most of the time the items don't even exist." Another big scam is the auction follow-up email hack. If you miss out on an auction or timed deal, ignore follow-up emails with the same offer. Scammers love to track auction sites and contact losing bidders to direct them away from secure buying environments. If you lose an item, move on to another auction. Countermeasures -- Don't shop on sites that look like they were designed by practitioners of phonetic writing or sites that would have looked awesome in 2004. Hack #4 -- Fake Black Friday Ads - Inauthentic Black Friday ads re-direct you to places you shouldn't be, or may install malware/unwanted software on your computer. Everyone's looking for the best deals, so cyber criminals love to release fake Black Friday ads that trick you into visiting sites you otherwise wouldn't visit. If you want to find great Cyber Monday deals, go directly to reputable websites, whether they're vendors (Best Buy, Amazon, Walmart) or trusted third-party aggregators (BFAds.net). To protect yourself against phony ads, don't change up your browsing habits from the rest of the year. Go directly to websites instead of through Google. Walmart isn't selling a 60" HDTV for $97. If, by some miracle, that's a real sale, you better believe it's going to be front and center on Walmart.com.Countermeasures -- Don't search for phrases like "best Cyber Monday deals." Don't go to websites you've never heard of.Hack #5 -- Site Swap - Ambitious scammers build entire fake sites that look shockingly similar to popular retailers. This is a more complicated hack, and sometimes the most convincing - so pay attention. You will almost always get to a fake site through a search engine or a mistyped URL. But sometimes fake sites are used in combination with email hacks. The most sophisticated versions are single pages that actually link to the real sites so the information request looks more legitimate. If you're not sure about a link, there are a few great resources at your disposal. Sites like getlinkinfo.org or wheredoesthislinkgo.com will show you exactly where a suspicious link goes. Still not sure? It's probably fake. Move on. The chance of landing a great deal is not worth credit card fraud or a credit score hit. Countermeasures -- Go directly to retailers' sites, rather than through search engines. Don't click on links from any email you can't verify. Sufficiently armed with countermeasures? I hope so. This should be a wonderful holiday season for consumers and retailers alike. There are great deals to be had on Ultra HD sets (they've come down 84% from last year). I've seen amazing deals on phones and tablets, to say nothing of stunning array of wearables on sales this year. Happy Thanksgiving from all of us at shellypalmer.com - practice safe computing and enjoy the holiday.

Your Computer Could Be Hacked Using Only Sound


Is your computer audio-enabled? That might be enough to get it hacked, according to recent findings from German researchers with the Fraunhofer Institute for Communication, Information Processing, and Ergonomics. As revealed in a paper for the Journal of Communications, the researchers successfully hacked computers using nothing but sound. Before you start worrying about your own machine, take a second to pity anyone you know in the computer security industry. The most secure computers in the world are completely isolated from other machines -- protected by "air gaps," with no Internet connection, no shared phone lines, nothing. Conventional wisdom goes that such computers are impossible to hack unless the hacker has direct, physical access to the machine. Or at least that was the conventional wisdom prior to the German discovery. The Fraunhofer researchers started researching audio hacks after considering how malicious hackers might break into these highly secure systems and computers. In their paper's introduction, they note that hackers of the past often used "parts of the operating system that were not considered for communication" to insert malicious data into otherwise highly secure systems. The researchers adopted the mindset of a hacker when designing a sound-only hack for stealing data from deliberately isolated computers. Audible noises could in theory be used to pass data between such computers and the "hacker" computer, but the researchers, wishing to remain as inconspicuous as hackers, instead chose to use sounds at a frequency inaudible to human ears (similar to the noise made by dog whistles). Building upon preexisting technology used to transmit data under water by sound waves, the researchers were able to use the microphone and speakers in an unmodified Lenovo T400 personal computer to transmit small amounts of information -- keystrokes in the test case, though the hack could also transmit encryption keys, small text files and even passwords -- from an isolated computer to a compromised one. The researchers also tested the range of audio hack, and found that on unmodified computers, the method worked for distances up to 65 feet -- a range which can be expanded almost indefinitely with use of special "mesh networks," which can wirelessly transmit audio long distances. The conclusion? According to the study, "acoustical networking as a covert communication technology is a considerable threat to computer security." For high-security computers that require audio, the researchers suggest sound-filtering as a way to block covert acoustical attacks. For everyone else, simply disable your machine's audio.

Thursday, May 28, 2015

Hacker Succeeds In Breaking Into HealthCare.gov For First Time


A hacker broke into HealthCare.gov and installed malicious software on one of its servers in the first successful breach of the health insurance exchange, federal officials said Thursday. No personal data were stolen from the Obamacare site as the hacker accessed only a test server that did not contain consumer information, according to Kevin Griffis, a senior adviser at the Department of Health and Human Services. "Data was not transmitted outside the agency, and the website was not specifically targeted," Griffis said in a statement. "We have taken measures to further strengthen security." A spokesman for the Department of Homeland Security said that agency helped remove malicious software that was designed to launch denial-of-service attacks -- a common tactic used by hackers to flood websites with traffic until they crash. The hacker broke into the server sometime in July, according to The Wall Street Journal, which first reported the breach on Thursday. The malware was discovered on Aug. 25 during a routine security test, federal officials said. The server was guarded by an easy-to-crack default password and the hackers appeared to have installed the malware for use in future cyberattacks against other websites, according to the Journal. The breach of HealthCare.gov marks the latest in a spate of hacking against both major corporations and government agencies. Earlier this week, Home Depot appeared to be the latest retailer to get hacked when a huge cache of credit and debit card data linked to purchases at the store went on sale on a black market website. Last week, JPMorgan said it was investigating a possible cyberattack after reports that hackers stole gigabytes of data, including customer credit and savings account information, from its network. The federal government hasn't fared much better. In July, Chinese hackers broke into the databases of the Office of Personnel Management, which contains files on federal employees, including those who apply for top-secret clearances. After its Oct. 1 debut last year, HealthCare.gov was plagued with problems, including repeated glitches that lasted for weeks and initially prevented millions of people from signing up for health insurance. The site was fixed after the White House hired dozens of engineers and programmers from tech industry giants like Google and Oracle to repair it. More than 8 million people have signed up for insurance via the federal and state health care exchanges, federal officials said in May. The security of the federal website has been an especially sensitive issue given the fierce political battle over Obamacare. Rep. Darrell Issa (R-Calif.), chairman of the House Oversight and Government Reform Committee, has been investigating potential security vulnerabilities in the site. Mitre, a contractor hired to check the site's security, found 28 security flaws in a test last October. Administration officials said last year that those flaws had been fixed or did not pose a threat, according to The Washington Post.

Almost All Of The World's Biggest News Organizations Have Been Targeted By Hackers


SINGAPORE (Reuters) - Twenty-one of the world's top-25 news organizations have been the target of likely state-sponsored hacking attacks, according to research by two Google security engineers. While many internet users face attacks via email designed to steal personal data, journalists were "massively over-represented" among such targets, said Shane Huntley, a security software engineer at Google. The attacks were launched by hackers either working for or in support of a government, and were specifically targeting journalists, Huntley and co-author Morgan Marquis-Boire said in interviews. Their paper was presented at a Black Hat hackers conference in Singapore on Friday. "If you're a journalist or a journalistic organization we will see state-sponsored targeting and we see it happening regardless of region, we see it from all over the world both from where the targets are and where the targets are from," Huntley told Reuters. Both researchers declined to go into detail about how Google monitors such attacks, but said it "tracks the state actors that attack our users." Recipients of such emails in Google's Gmail service typically receive a warning message. Security researcher Ashkan Soltani said in an earlier Twitter post that nine of the top-25 news websites use Google for hosted email services. The list is based on traffic volumes measured by Alexa, a web information firm owned by Amazon.com Inc. California-headquartered Google also owns VirusTotal, a website that analyses files and websites to check for malicious content. "TIP OF THE ICEBERG" Several U.S. news organizations have said they have been hacked in the past year, and Forbes, the Financial Times and the New York Times have all succumbed to attacks by the Syrian Electronic Army, a group of pro-government hackers. Huntley said Chinese hackers recently gained access to a major Western news organization, which he declined to identify, via a fake questionnaire emailed to staff. Most such attacks involve carefully crafted emails carrying malware or directing users to a website crafted to trick them into giving up credentials. Marquis-Boire said that while such attacks were nothing new, their research showed that the number of attacks on media organizations and journalists that went unreported was significantly higher than those made public. "This is the tip of the iceberg," he said, noting a year-long spate of attacks on journalists and others interested in human rights in Vietnam, including an Associated Press reporter. The attacks usually involved sending the target an infected email attachment masquerading as a human rights document. While many of the world's biggest media players have been targeted in these attacks, small news organizations, citizen journalists and bloggers were also targeted, Huntley said, noting hacking attacks on journalists in Morocco and Ethiopia. The problem, Marquis-Boire said, was that news organizations have been slower than other businesses in recognizing the threat and taking action. "A lot of news organizations are just waking up to this," he said. Many journalists are now taking individual action to protect their computers and email accounts, he said. "We're seeing a definite upswing of individual journalists who recognize this is important."

Anonymous Is Going To War With The KKK Over Ferguson Protests


WASHINGTON -- Members of the hacker collective Anonymous are targeting the Ku Klux Klan after the designated hate group reportedly threatened protesters in Ferguson, Missouri. The hackers claim to have seized two KKK Twitter accounts and say that they have launched denial-of-service attacks against a number of white supremacist websites affiliated with the Klan. The group has also publicized personal information allegedly belonging to KKK members. “We want the KKK gone, forever,” a person going by the username “SiX” told The Huffington Post on Monday in an Anonymous Internet Relay Chat about the operation. “Don’t worry, we know what we’re doing.” The latest campaign, #OpKKK, began on or around Friday, after the KKK’s Missouri chapter reportedly threatened to use “lethal force” against people protesting the killing of unarmed teenager Michael Brown by a policeman in Ferguson. Tensions in the Missouri town have escalated in recent days as protesters await a grand jury's decision about whether or not to indict the police officer, Darren Wilson. On Sunday, Anonymous members claimed to have taken over a Twitter account, @KuKluxKlanUSA, which they said was run by an official Klan member. They also said they had taken down various websites associated with the hate group, some of which were still down as of Monday. ZDNet, an information technology site, reported Monday that Anonymous was claiming to have hacked another Twitter account, @YourKKKCentral, purportedly belonging to the group. In addition, members of Anonymous have been publicly posting social media accounts, photos and other personal information allegedly belonging to KKK members. The hackers have posted the information on Twitter, under the hashtag #HoodsOff, as well on the website Pastebin.com. A Twitter user going by the name @AnonyOps said, “I heard three cops got outed. Their twitter was stolen ;)” On Sunday night, some members were scheming on the operation’s chat room about how to send pizzas to a white supremacist’s house. Gabriella Coleman, a professor at McGill University who recently authored the book Hacker, Hoaxer, Whistleblower, Spy: The Many Faces of Anonymous, said the operation appears to have been started by a sub-faction of Anonymous’ ongoing “Operation Ferguson” campaign. That campaign began in August as, in part, an effort to publicly name the police officer who shot Brown. #OpKKK, Coleman added, has help from Latin American and Australian members of Anonymous. In the chat with HuffPost, a person going by the name “Anoniter” said Anonymous' members are cross-referencing “all instances of membership to ascertain true identity ... We use basic information that they provide on their site. We then cross it with other online applications to pinpoint exactly who they are." “We ensure that no innocent person would be ousted," Anoniter added. The group hasn’t always correctly identified its targets in the past. Earlier this year, as part of Operation Ferguson, a member of the hacker group mistakenly outed a Ferguson cop who was not responsible for the shooting. The officer soon received hundreds of death threats. A person using the name “anonpanda” pointed out that the KKK was “an easy target to pick on, cuz we kinda get the moral high ground.” The user said, "i could not give a bother about the KKK... i am norwegian, they dont bother me." “i just want to blow out some steam," anonpanda added. Thomas Robb, the national director of the Knights of the Klu Klux Klan, told HuffPost that he’d had threats against his website, but as of Monday, it was still running. He pointed out that “our membership is kept on computers that don’t have access to the Internet.”

How To Protect Yourself From Domain Thieves


Most of us are aware that hackers can steal our financial information. But few people realize that hackers can also go after other valuable property online, like web addresses. Short, catchy URLs can be worth millions of dollars, making them prime targets for thieves. On Monday, The Huffington Post reported on domain theft, a scheme in which hackers steal valuable Internet addresses and sell them in online forums or extort their rightful owners. If a hacker steals your domain name, there’s often little you can do to get it back. But how do you protect your website from getting hijacked in the first place? BE SKEPTICAL OF EMAILS Start by questioning emails that claim to come from a domain registrar like GoDaddy. Hackers often steal website addresses by sending fake emails to their owners. The bogus emails include malicious software that allows thieves to gain control of their victims’ email accounts and approve the transfer of their domain names. The bogus email might say: “Urgent attention! We believe your account has been compromised and payment method is no longer valid. Please log in and correct information,” according to Dave Piscitello, a senior security technologist for ICANN, a California-based nonprofit responsible for managing the Internet address system. Once a hacker has control of your email account, the criminal can transfer your website into his or her control, and you might not be able to get it back. TAKE EXTRA SECURITY MEASURES Choose a domain registrar that offers added security features, like GoDaddy's two-step authentication, that make it harder for hackers to break into your domain account. You should also request your domain be placed on “Registrar Lock,” which requires you to "unlock" the domain before you transfer it by logging in to the registrar's website. With the lock in place, a hacker would need access to both your email account and your registrar account. For an extra $8 a year, GoDaddy will also hide your contact information -- including your email address -- from a public list of domain owners known as the “Whois” database. This prevents thieves from knowing how to contact you to send a bogus email, according to the company. For even more security, Web.com offers an extra feature that prevents anyone from transferring a domain name to another account until a company representative has called the account owner on the phone and that person has provided a nine-digit PIN code to prove their identity. However, the added security comes with a hefty price tag -- $1,850 for the first year, and $1,350 for each additional year. KEEP YOUR RECORDS If your domain name is stolen, you’re more likely to recover it quickly if you've kept documents related to the website, such as billing and registration records. Such documents can help in a lawsuit or when the domain registrar investigates the theft. To get your domain back, “you have to demonstrate you've been a victim,” Piscitello said. “Without documentation, your recourse is very limited.”

Security Mistakes You Make Every Day


We all try to go about our days as smoothly as possible, but unfortunately, we live in a world where it seems like there are threats lurking around every corner. Even if you think you're doing things by the book, you are probably making a number of security mistakes every day that could potentially be costly to your identity and your life. Whether you're at home or on the go to work or play, there are critical things you can easily avoid by taking some time to think before acting. Security mistakes you make at home You have an easy-to-guess Wi-Fi password (or none at all). Although it might seem like less of a hassle to employ a simple password or not use one at all, leaving your home network unprotected is inviting trouble. Not only might neighbors without scruples connect to your Wi-Fi and hog the bandwidth you're paying for, but also criminals can easily hack into an unprotected network and steal your information. Additionally, be wary of connecting to unprotected networks in your area. Legally, you shouldn't do this anyway -- it is considered theft to use someone else's private Wi-Fi. But it is also dangerous, as some shady people set up fake networks in hopes people will connect and practically drop their data into their laps. Create a strong password for your Wi-Fi and try to change it on a regular basis. Some people even set up a separate guest network for visitors, which helps to keep your home network secure for members of the household. Your life is documented on social media. The beauty of social media is that it lets us connect with friends and strangers all over the world. Many apps have popped up that let you share every little thing you do, whether it's the restaurants you eat at or the places you visit with your friends. Sharing is wonderful, when it's with friends and family, but if you don't keep a close watch on your privacy settings, you could be sharing all the information someone needs to know in order to steal your identity or rob your house while you're away on vacation. Get a grip on your security settings, and think before you share. You throw bills and other documents straight into the trash. Junk mail is aggravating, but you put yourself at risk when you throw those pre-approved credit card offers directly into the trash. Many small-time thieves are not above dumpster diving, and they can use documents you throw away to steal your identity. The best solution is to invest in a shredder with cross-cut capability and shred any documents you plan to throw out. This will ensure peace of mind because it shreds papers into tiny confetti-like pieces, making it impossible for anyone to piece them back together. Security mistakes you make at the office Your personal life is not left at the office door. We're all guilty of checking our personal email when we're supposed to be working, but if you aren't careful, this could cost you more than just a reprimand. The workplace should be treated as a sacred space, separate from home. You might think there's no harm checking a few personal websites or keeping your own files on your work computer, but a data breach into your office network could result in more than just what the company keeps on file being stolen. Additionally, leaving papers with important information lying around your office puts you at risk. A lot of identity theft is committed by people you know, or those who have access to your home or business. Keep personal paperwork in a locked drawer or filing cabinet or, better yet, take it home. You write passwords down on sticky notes. It can be difficult to remember all of the passwords we use each day, especially since it's now recommended that we make them longer and more challenging. Some offices require mandatory password changes every 30-90 days, and it might be tempting to cut corners by writing down your new password on a sticky note that you affix to your monitor. However, doing this is like leaving a key to your house dangling from a string on your porch. If you have trouble remembering your password, consider more secure manners of storing it, such as in a password manager app or locked file on your mobile device. Security mistakes you make on the go You use public Wi-Fi networks. Sure, it's convenient to connect to the free Wi-Fi in Starbucks or the airport, and you can certainly save on data charges from your carrier by doing so. However, these networks are unsecured and that makes them dangerous. Criminals can connect to these networks and use them as hunting grounds for data to steal from unsuspecting people around them. If you do choose to connect to a public network, take care not to use any apps or websites that deal with personal data -- such as banking or logging in to check on the status of your tax return. Out running errands and really need to check your account balance? Turn off Wi-Fi and use your mobile device's encrypted 3G or 4G network instead; this network is typically more secure than an unsecured, public Wi-Fi connection. Private conversations aren't private in public. While it might be tempting to conduct business or catch up with a friend during your commute or lunch break, these conversations are rarely as private as you might think. Cell phones make it so we can connect with anyone from just about anywhere. It's convenient, but if other people are around not only are you potentially disrupting their peace and quiet, but you are also broadcasting everything you're saying to them. Talking about your weekend plans or providing the receptionist at your doctor's office with personal information, such as your Social Security number, over the phone makes you a potential target for criminals nearby. Make sure you use discretion in public and move to a private space, such as your car, when you must divulge sensitive information.