Showing posts with label spybot. Show all posts
Showing posts with label spybot. Show all posts

Monday, February 20, 2017

Czech Mate, or Here's Looking at You Id

Forty-foot statue of David Black Trifot is part of a new multi-genre space outside the city Photo Czech Centre, which is now open to the public. more

Wednesday, February 8, 2017

FutureWatch: Powerless Bugs or Teslabestiola II (update)

Back in 2013, the Security Scrapbook alerted you to Ambient Backscatter as a developing technology with extreme potential, including electronic surveillance / eavesdropping. 

At that time I said, "Ambient Backscatter research is in its infancy. Imagine the possibilities. Technical espionage could see its biggest advancement since the transistor."

Today, Jeeva Wireless, is developing this technology and is about to come out of stealth mode. 

The technology is so interesting, NASA has posted Federal contract opportunity NND1710133Q, "a sole source contract under the authority FAR 13.106-1(b)(1)(i)."

Here is the update...


"A group of University of Washington engineers has raised capital to develop and commercialize a power-efficient way to generate WiFi transmissions.


Jeeva Wireless just reeled in a $1.2 million round, co-founder Shyamnath Gollakota confirmed with GeekWire. He declined to provide more details about the cash and how Jeeva will use it, as the Seattle startup is still in stealth mode.

The company’s co-founders are the same UW researchers who co-authored a study last year for a Passive Wi-Fi system that can generate WiFi transmissions using 10,000 times less power than conventional methods.

Not even low-power options such as Bluetooth Low Energy and Zigbee can match the system’s energy efficiency, based on the study that earned the UW team a place on MIT Technology Review’s top-ten list of breakthrough technologies in 2016. With the fresh funding, it appears that the company is ready to commercialize its innovation" more

Television-Spying Case - Vizio to Pay $2.2 Million

The Federal Trade Commission said Monday that Vizio used 11 million televisions to spy on its customers.

The company agreed to pay $2.2 million to settle a case with the FTC and the New Jersey attorney general’s office after the agencies accused it of secretly collecting — and selling — data about its customers’ locations, demographics and viewing habits.

“Before a company pulls up a chair next to you and starts taking careful notes on everything you watch (and then shares it with its partners), it should ask if that’s O.K. with you,” Kevin McCarthy, an attorney with the FTC’s Division of Privacy and Identity Protection, wrote in a blog post. “Vizio wasn’t doing that, and the FTC stepped in.”

As part of the settlement, Vizio neither confirmed nor denied wrongdoing. more

Friday, January 13, 2017

Wake for the Spycam Monkey

How do you photograph skittish wildlife up close and personal? Design a camera robot that looks just like them. That’s the idea behind Spy in the Wild, a new documentary series on BBC.

While the producers anticipated using the disguised cameras to get unique shots, they didn’t anticipate what would happen when a group of Langur monkeys thought the animatronic camera had “died.”

The new series, which aired Thursday in the U.K. on BBC and is set to premiere in the U.S. on PBS on February 1, aims to capture what wildlife videographers often have a hard time finding: emotions.

A preview for the series shows the monkeys interacting with the camera, but where it really starts to get interesting is when one monkey tries to play with the fake Langur and ends up bringing it into a tree — and letting go.


With animatronics only in the face, the Langurs appear to think the camera monkey has died. The unexpected turn of events allows the crew to film how the animals react when one of their own die. The monkeys gather around the motionless camera and older Langurs pull younger monkeys into a hug. more

Thursday, December 8, 2016

Chatty Kathy's Grandkids May be Criminals

Internet-connected toys pose privacy risks to children, and their parents often aren’t aware, according to advocacy groups for children and consumers.

A complaint filed Tuesday with the Federal Trade Commission alleges that two talking dolls—My Friend Cayla and I-Que Intelligent Robot, both made by Genesis Toys Inc.—collect and use personal information from children in violation of rules prohibiting unfair and deceptive practices.

The complaint was drafted by several groups, including the Campaign for a Commercial Free Childhood, a coalition of groups dedicated to ending child-targeted marketing, and Consumers Union. The groups also filed complaints with data protection, consumer protection and product safety regulators for the European Union, France, the Netherlands, Belgium, Ireland and Norway. more grandma

Monday, November 28, 2016

3 Ways Corporate Spies Might Be Watching Your Business and How to Stop Them

Business is a game of constant competition, but the widespread emergence of covert surveillance and tracking tools has expanded the playbook. Now, industrial espionage has a new dimension.

In the corporate world, the practice is nothing new. In fact, it's been a marketing tactic for decades... But the digital age has given corporate spying a new face. And with the modern proliferation of web-based spying options, corporate surveillance is more sophisticated and covert than ever.

Today, corporate spies for hire carry titles like "Competitive Intelligence Analyst" and "Competitive Market Strategist." There are many lucrative opportunities for these workers. And they might be watching your business right now. Here are three of the ways they do it—and also how to dodge their efforts. more

Tuesday, November 22, 2016

Business Espionage: GSM Bugs Are Mini Cell Phones in Disguise

(from a seller's website in the UK)
GSM bugs are also known as mobile phone bugs and infinity bugs. Based around mobile technology, these devices provide a discreet listening facility with an unlimited distance.

Click to enlarge.
Up until a few years ago radio frequency transmitters were relied upon to provide an eavesdropping solution, albeit over only relatively short distances, generally up to about 800 metres line of sight. These devices are still available, but have been outlawed by OFCOM legislation and are therefore not legal to sell into the UK or operate in the UK without a radio broadcast licence. GSM Bugs use the existing GSM network as a transmission tool.

When they fist became available, the GSM bugs were literally modified mobile phones that auto-answered silently to open up the microphone and listen into the surrounding environment. These devices are still available today and some dedicated (dead phone) units have had enhanced microphone adjustments to make them more attuned to pick up sounds in a wider area, turning them into dedicated listening devices.

As the technology has moved on, these eavesdropping devices have become smaller and more sophisticated. They are really only restricted in size at present by the battery size, however, some of the latest units are built into mains powered devices such as multi-plug adapters and mains sockets, thereby making them invisible to the naked eye and with no power consumption restrictions.

Some of these eavesdropping devices are obviously for the UK market.
Bugs for other electrical standards are also available. 


Do you have electrical extension strips in your office?
Have they been inspected and sealed by a TSCM specialist

~Kevin

Thursday, November 17, 2016

This $5 Device Can Hack Your Locked Computer In One Minute

Next time you go out for lunch and leave your computer unattended at the office, be careful. A new tool makes it almost trivial for criminals to log onto websites as if they were you, and get access to your network router, allowing them to launch other types of attacks.

Hackers and security researchers have long found ways to hack into computers left alone. But the new $5 tool called PoisonTap, created by the well-known hacker and developer Samy Kamkar, can even break into password-protected computers, as long as there’s a browser open in the background. Kamkar explained how it works in a blog post published on Wednesday.


And all a hacker has to do is plug it in and wait. more

Thursday, November 10, 2016

Business Espionage Problem: Car Spy Photographers Using Drones

...automakers are looking at ways to put a stop to this practice.

Click to enlarge.
One answer may be coming from the German company Deutsche Telekom, which is working with developers on ways to keep drones out of certain areas.

The American company Dedrone also has a DroneTracker system that can locate drones more than half a mile away. We're sure that more creative and interesting means of inhibiting drones are coming down the road as well. more

Monday, September 19, 2016

Spy Chip Implants - Common Complaint - Best handled with an X-ray

United Kingdom-based NRI (A Non-Resident Indian is a citizen of India who holds an Indian passport and has temporarily emigrated to another country for six months or more...) who claims ‘spying chips’ were installed in his body would be examined at Jalandhar’s Army hospital after the Ministry of Home Affairs forwarded his plea requesting their removal to the Punjab government.

Harinder Pal Singh, who returned from the UK three years ago, claimed British police had installed chips in his body for spying...

Narrating his bizarre-sounding story... “I went to UK in 1987 at the age of 15 with my grandmom. One day, I was sleeping in my room and some plainclothes policemen made me unconscious and got instruments installed in my body.”

“In 1996, my nearly four-year-old daughter died in an accident, which was changed into murder. I was convicted for it and sentenced to 15 years. After completing my jail term on February 13, 2013, I was deported,’’ he claimed. more

Wednesday, September 14, 2016

Hey Kids - Learn How to Operate a Stingray IMSI-Catcher!

Using mass surveillance software without a warrant is almost as easy as installing Skype, according to leaked footage and instruction manuals for Harris Corp. stingray devices.

The footage, obtained by the Intercept, shows Harris Corp.'s Gemini software being used on a personal computer demonstrating how accessible the program is with a noticeable lack of any registration keys, proof of ownership, or safety measures to ensure the software was only used for authorized purposes.

The manuals include instructions for several Harris surveillance boxes, including the Hailstorm, ArrowHead, AmberJack, KingFish and other products in the RayFish Product Family.

Some features mentioned in the manuals are the ability to impersonate four cellular communication towers at once, monitor up to four cellular provider networks at once, and the ability to knock a targets devices down to an inferior network, such as from LTE to 2G.

The manual also details how to set up a target or “subscriber” and how to set up bulk surveillance, according to a Gemini device “Quick Start Guide” that was leaked on DocumentCloud. more

Monday, August 22, 2016

Facebook Surveillance Would Make Santa Jealous, or...

...98 personal data points that Facebook uses to target ads to you...

Say you’re scrolling through your Facebook Newsfeed and you encounter an ad so eerily well-suited, it seems someone has possibly read your brain.

Maybe your mother’s birthday is coming up, and Facebook’s showing ads for her local florist. Or maybe you just made a joke aloud about wanting a Jeep, and Instagram’s promoting Chrysler dealerships.

Whatever the subject, you’ve seen ads like this. You’ve wondered — maybe worried — how they found their way to you...

While you’re logged onto Facebook, for instance, the network can see virtually every other website you visit. Even when you’re logged off, Facebook knows much of your browsing: It’s alerted every time you load a page with a “Like” or “share” button, or an advertisement sourced from its Atlas network. Facebook also provides publishers with a piece of code, called Facebook Pixel, that they (and by extension, Facebook) can use to log their Facebook-using visitors. more

Friday, August 12, 2016

"DiskFiltration" - Siphons Data Even When Computers are Disconnected from the Internet.

Researchers have devised a new way to siphon data out of an infected computer even when it has been physically disconnected from the Internet to prevent the leakage of sensitive information it stores. 

The method has been dubbed "DiskFiltration" by its creators because it uses acoustic signals emitted from the hard drive of the air-gapped computer being targeted. It works by manipulating the movements of the hard drive's actuator, which is the mechanical arm that accesses specific parts of a disk platter so heads attached to the actuator can read or write data.

By using so-called seek operations that move the actuator in very specific ways, it can generate sounds that transfer passwords, cryptographic keys, and other sensitive data stored on the computer to a nearby microphone. The technique has a range of six feet and a speed of 180 bits per minute, fast enough to steal a 4,096-bit key in about 25 minutes. more

Solution: Upgrade to a solid state drive.

Wednesday, August 10, 2016

Car Key Fobs — Wireless = Useless

...a team of researchers from the University of Birmingham and the German engineering firm Kasper & Oswald plan to reveal two distinct vulnerabilities they say affect the keyless entry systems of an estimated nearly 100 million cars. 

One of the attacks would allow resourceful thieves to wirelessly unlock practically every vehicle the Volkswagen group has sold for the last two decades, including makes like Audi and Škoda. The second attack affects millions more vehicles, including Alfa Romeo, Citroen, Fiat, Ford, Mitsubishi, Nissan, Opel, and Peugeot.

Both attacks use a cheap, easily available piece of radio hardware to intercept signals from a victim’s key fob, then employ those signals to clone the key. The attacks, the researchers say, can be performed with a software defined radio connected to a laptop, or in a cheaper and stealthier package, an Arduino board with an attached radio receiver that can be purchased for $40. “The cost of the hardware is small, and the design is trivial,” says Garcia. “You can really build something that functions exactly like the original remote.”

...they were able to extract a single cryptographic key value shared among millions of Volkswagen vehicles. By then using their radio hardware to intercept another value that’s unique to the target vehicle and included in the signal sent every time a driver presses the key fob’s buttons, they can combine the two supposedly secret numbers to clone the key fob and access to the car. “You only need to eavesdrop once,” says Birmingham researcher David Oswald. “From that point on you can make a clone of the original remote control that locks and unlocks a vehicle as many times as you want.” more
original paper

Friday, August 5, 2016

Does dropping malicious USB sticks really work?

Of course it does.
Common sense.  
I warned about this years ago. 
Now, we have empirical evidence!



Research presented this week at BlackHat by Elie Bursztein of Google’s anti-abuse research team shows that the danger is alarmingly real:
  • …we dropped nearly 300 USB sticks on the University of Illinois Urbana-Champaign campus and measured who plugged in the drives. And Oh boy how effective that was! Of the drives we dropped, 98% were picked up and for 45% of the drives, someone not only plugged in the drive but also clicked on files.
It seems folks just can’t resist picking up a USB stick that they see lying around – Bursztein says that it only took six minutes for the first device that he “lost” to be picked up.One would like to imagine that people are less likely to plug in a USB drive if it is clearly labelled with the owner’s contact details, and that appears to be borne out by the statistics.
On each type of drive, files consistent with the USB stick’s appearance were added. So, “private” files were added to USB sticks that were unlabelled or were attached to keys or a return label, “business” files to sticks marked confidential, etc.

However, in reality each of the files was actually an HTML file containing an embedded image hosted on the researcher’s server. In this way they were able to track when files were accessed. more

Smartphone Security Alert - "Juice Jacking" or... Getting your phone's brain drained at the airport,

“Juice-jacking” as the new travel scam is called, targets desperate travelers in need of a charge. Daniel Smith, a security researcher at Radware explains how this works.

“Attackers can use fake charging stations to trick unsuspecting users into plugging in their device. Once the device is plugged in the user’s data and photos could be downloaded or malware can be written onto the device.”

Hackers can download anything that is on your phone since the charging port is doubling as a data port. We’re talking passwords, emails, photos, messages, and even banking and other personal information via apps.

How to Prevent Juice-Jacking 
“Don’t use public charging stations. more

Solutions...
  • This is a tiny and lightweight external battery that is easy to travel with: Amazon.com
  • Plug into your laptop to charge your phone if you’re traveling with one and don’t have an external charger. 
  • If you absolutely need to use public charging stations you can block the data transfer using SyncStop ($19.99).

Friday, July 29, 2016

Remotely Turning Office Equipment into Bugging Devices

You think about securing your laptop, but what about your desk phone, monitor, or printer?

Ang Cui, who heads up Red Balloon Security in New York City, has a particularly innovative way of hacking these devices. Using a piece of malware called “funtenna,” he’s able to make devices transmit data over radio (RF) signals, and then pick them up with an antenna. He’s basically using software to turn this equipment into bugging devices. more
(If video space is blank, click here.)
This is one reason why businesses conduct regularly scheduled bug sweeps (TSCM) of their offices and conference rooms. If you are not plugging these information leaks yet, call me. I'll help you put a protection strategy in place. ~Kevin

Friday, July 22, 2016

Amazon Mute on Echo Eavesdropping

We may never know if the feds have hijacked Amazon Echo.

Amazon has so far issued two transparency reports since it began declaring how many government data demands and wiretap orders it receives.

Both reports outlined how many subpoenas, search warrants, and court orders the company received to cloud service Amazon Web Services. While its cloud makes up a significant portion of the data that it gathers, the company also collects vast amounts of data from its retail businesses, mobile services, book purchases, and requests made to Echo.

But an Amazon spokesperson wouldn't comment on whether the company will expand its transparency report. more

Tuesday, July 12, 2016

1970's CIA Dragonfly Spy - Ripley's Believe It or Not

In the 1970s, the CIA developed the Insectothopter, an unmanned surveillance drone disguised as a dragonfly.

video

  • The Insectothopter was the size of a dragonfly
  • It was painted to look like a dragonfly
  • It was powered by a small gasoline engine made by a watchmaker
  • And jets of gas were used to propel it forward
  • Because it was too difficult to control in even a slight crosswind, the project was abandoned

Saturday, July 9, 2016

World's Biggest Bug (You need it if you want to bug aliens.)

China Wants To ‘Eavesdrop’ On Aliens With This Giant Radio Telescope

Click to enlarge
China hoisted the final piece into position on what will be the world's largest radio telescope, which it will use to explore space and help in the hunt for extraterrestrial life, state media said.

The Five-hundred-meter Aperture Spherical Telescope, or FAST, is the size of 30 football fields and has been hewed out of a mountain in the poor southwestern province of Guizhou. more