Ben Bradlee, the former top editor of The Washington Post who oversaw
the paper's coverage of the Watergate scandal, has died, the newspaper
said Tuesday.
He was 93.
Tuesday, October 21, 2014
Yo, Jimmy. You know how to use this thing?
Newly released documents definitively show that local law enforcement in Washington, DC, possessed a cellular surveillance system—commonly known as a "stingray"—since 2003.
However, these stingrays literally sat unused in a police vault for six years until officers were trained on the devices in early 2009.
"It's life imitating The Wire," Chris Soghoian, a staff technologist at the American Civil Liberties Union, told Ars. "There's an episode in Season 3 where [Detective Jimmy] McNulty finds a [stingray] that has been sitting on the shelf for a while." (more)
However, these stingrays literally sat unused in a police vault for six years until officers were trained on the devices in early 2009.
"It's life imitating The Wire," Chris Soghoian, a staff technologist at the American Civil Liberties Union, told Ars. "There's an episode in Season 3 where [Detective Jimmy] McNulty finds a [stingray] that has been sitting on the shelf for a while." (more)
Traveling to China? Have an iPhone? Clear Your Cloud First
Chinese authorities just launched “a malicious attack on Apple” that could capture user names and passwords of anyone who logs into the iCloud from anywhere in the country, the well-respected censorship watchdog GreatFire.org reports.
With that information, a hacker can view users contacts, photos, messages and personal information stored in the cloud.
China has an estimated 100 million iPhone users in China, and all of them could be vulnerable, GreatFire reports, thanks to a “man in the middle” attack that tricks users into believing they are logging into a secure connection, when they are actually logging into a Chinese government-controlled site instead. (more)
With that information, a hacker can view users contacts, photos, messages and personal information stored in the cloud.
China has an estimated 100 million iPhone users in China, and all of them could be vulnerable, GreatFire reports, thanks to a “man in the middle” attack that tricks users into believing they are logging into a secure connection, when they are actually logging into a Chinese government-controlled site instead. (more)
A Police Commander's Wife, Their Unlicensed PI Business and Spyware...
Woo-woo-woo-woo-woo-woo, nyunt, nyunt, nyunt!
A Monterey County woman was charged with wiretapping a police officer and possessing "illegal interception devices,” according to the Northern California District Attorney’s office. The District Attorney said that Kristin Nyunt, age 40, allegedly intercepted communications made by a police officer on his mobile phone.
Nyunt is the ex-wife of former Pacific Grove Police Commander John Nyunt, and she has already been sentenced to eight years and four months in prison after pleading guilty in July to five counts of identity theft, two counts of computer network fraud, one count of residential burglary, and two counts of forgery.
In the latest charges [PDF], the District Attorney accused Nyunt of using illegal spyware including MobiStealth, StealthGenie, and mSpy to intercept "sensitive law enforcement communication” in real time. Nyunt allegedly placed the spyware on a police officer’s phone surreptitiously, although court documents do not detail how or why...
...between 2010 and 2012, Nyunt and her husband operated an unlicensed private investigator business called Nyunt Consulting and Investigative Services Corporation and used access to their customers’ devices and information to later commit identity theft. (more)
A Monterey County woman was charged with wiretapping a police officer and possessing "illegal interception devices,” according to the Northern California District Attorney’s office. The District Attorney said that Kristin Nyunt, age 40, allegedly intercepted communications made by a police officer on his mobile phone.
Nyunt is the ex-wife of former Pacific Grove Police Commander John Nyunt, and she has already been sentenced to eight years and four months in prison after pleading guilty in July to five counts of identity theft, two counts of computer network fraud, one count of residential burglary, and two counts of forgery.
In the latest charges [PDF], the District Attorney accused Nyunt of using illegal spyware including MobiStealth, StealthGenie, and mSpy to intercept "sensitive law enforcement communication” in real time. Nyunt allegedly placed the spyware on a police officer’s phone surreptitiously, although court documents do not detail how or why...
...between 2010 and 2012, Nyunt and her husband operated an unlicensed private investigator business called Nyunt Consulting and Investigative Services Corporation and used access to their customers’ devices and information to later commit identity theft. (more)
Labels:
business,
cell phone,
dumb,
Hack,
lawsuit,
police,
privacy,
scam,
spyware,
wiretapping
Staples Suspects Hackers - That Was Easy
Staples, the nation’s largest office supply retailer, said Monday it is investigating a "potential issue" involving credit card data at its stores.
Staples spokesman Mark Cautela said in an email that the retailer has contacted law enforcement to help with its investigation.
"We take the protection of customer information very seriously and are working to resolve the situation," Cautela said in an email. “If Staples discovers an issue, it is important to note that customers are not responsible for any fraudulent activity on their credit cards that is reported on a timely basis." (more) (now-hack-the button)
Staples spokesman Mark Cautela said in an email that the retailer has contacted law enforcement to help with its investigation.
"We take the protection of customer information very seriously and are working to resolve the situation," Cautela said in an email. “If Staples discovers an issue, it is important to note that customers are not responsible for any fraudulent activity on their credit cards that is reported on a timely basis." (more) (now-hack-the button)
Monday, October 20, 2014
Business Phone VoIP Hack - Phreaking Expensive
Bob Foreman’s architecture firm ran up a $166,000 phone bill in a single weekend last March. But neither Mr. Foreman nor anyone else at his seven-person company was in the office at the time... (hackers) routed $166,000 worth of calls from the firm to premium-rate telephone numbers in Gambia, Somalia and the Maldives...
The scheme works this way, telecommunications fraud experts say: Hackers sign up to lease premium-rate phone numbers, often used for sexual-chat or psychic lines, from one of dozens of web-based services that charge dialers over $1 a minute and give the lessee a cut...
Hackers then break into a business’s phone system and make calls through it to their premium number, typically over a weekend, when nobody is there to notice. With high-speed computers, they can make hundreds of calls simultaneously, forwarding as many as 220 minutes’ worth of phone calls a minute to the pay line...
...telecom experts advise people to turn off call forwarding and set up strong passwords for their voice mail systems and for placing international calls. (more)
The scheme works this way, telecommunications fraud experts say: Hackers sign up to lease premium-rate phone numbers, often used for sexual-chat or psychic lines, from one of dozens of web-based services that charge dialers over $1 a minute and give the lessee a cut...
Hackers then break into a business’s phone system and make calls through it to their premium number, typically over a weekend, when nobody is there to notice. With high-speed computers, they can make hundreds of calls simultaneously, forwarding as many as 220 minutes’ worth of phone calls a minute to the pay line...
...telecom experts advise people to turn off call forwarding and set up strong passwords for their voice mail systems and for placing international calls. (more)
A Royal Sting Spybusting Trick You Can Use
Kate Middleton reportedly thinks that someone is keeping a close eye on the day-to-day happenings of the palace.
The reports have suggested that there is an over enthusiastic photographer or someone who is getting to know all the royal secrets.
"Middleton's paranoid that someone inside the palace is leaking her secrets. It's her worst nightmare," a source told Life &Style magazine...
The report added that the royal couple is taking required step to have a very private life. "They're trying desperately to find out who's spying on them by giving out false information to different people. If any of that information comes out, they'll know who's responsible." (more)
The reports have suggested that there is an over enthusiastic photographer or someone who is getting to know all the royal secrets.
"Middleton's paranoid that someone inside the palace is leaking her secrets. It's her worst nightmare," a source told Life &Style magazine...
The report added that the royal couple is taking required step to have a very private life. "They're trying desperately to find out who's spying on them by giving out false information to different people. If any of that information comes out, they'll know who's responsible." (more)
Sunday, October 19, 2014
Business Espionage via Crowd Sourcing
Crowd sourcing any part of your secret project can blow your cover and evaporate your competitive advantages. Take your marketing materials for example. Just requesting help on a crowd source web site can alert the competition to your plans.
via frankie.bz...
Two weeks ago I discovered through a crowd sourcing portal for graphic design that a competitor of my client is preparing to launch a whole new product line. They where pitching for a “name” and “logo design” for a range of products.
I informed my client about the pitch and ask them if they knew something about the new product line. They didn’t and neither did the market – a scoop so to say. The information in the pitch was valuable to my client since it contained a very good description about the features of the new product line and when it will be launched. Therefore the client informed its sales force and they are now prepared to answer questions of their clients.
What can we learn from this experience?
via frankie.bz...
Two weeks ago I discovered through a crowd sourcing portal for graphic design that a competitor of my client is preparing to launch a whole new product line. They where pitching for a “name” and “logo design” for a range of products.
I informed my client about the pitch and ask them if they knew something about the new product line. They didn’t and neither did the market – a scoop so to say. The information in the pitch was valuable to my client since it contained a very good description about the features of the new product line and when it will be launched. Therefore the client informed its sales force and they are now prepared to answer questions of their clients.
What can we learn from this experience?
- Do not crowd source design of “secret” products – especially if the pitch can be seen without any registration
- Do not describe your product in the project brief – send the description to an interested designer after he has signed a non disclosure agreement
- Do not link directly to your competitors site – I’ve found out about the pitch because I’ve seen hundreds of visitors coming from a non-industry related site
- Do prohibit your employees to blog, twitter, Facebook about a new product
- Use a project code name that does not relate to your industry or product
- Do not use Cloud-Services for your product development - unless you are sure that none of the information can be made available to the public
- Visit crowd sourcing portals on a regular basis and search for projects related to your industry and competitors
- Use Google Alerts not only to monitor the web activity of your firm and brands, but also of your competitors
- Use crowd sourcing traditionally by letting the crowd search through social networks, forums and the web for information about your competitors
- Sign up and monitor the support forums of your main competitors (if they have one). If they don’t have one try to open a user-to-user support forum for your competitors products – and see what happens.
1958 - The Hollow Coin Spy Case
CIA Archives: The Hollow Coin - Espionage Case of Rudolf Abel (1958)
Vilyam (Willie) Genrikhovich (August) Fisher (Вильям Генрихович Фишер) (July 11, 1903 — November 16, 1971) was a noted Soviet intelligence officer. He is generally better known by the alias Rudolf Abel, which he adopted on his arrest. His last name is sometimes given as Fischer; his patronymic is sometimes less exactly transliterated as Genrikovich.
The Hollow Nickel Case (also known as The Hollow Coin), refers to the method that the Soviet Union spy Vilyam Genrikhovich Fisher (aka Rudolph Ivanovich Abel) used to exchange information between himself and his contacts, including Mikhail Nikolaevich Svirin and Reino Häyhänen.
On June 22, 1953, a newspaper boy (fourteen-year-old newsie Jimmy Bozart), collecting for the Brooklyn Eagle, at an apartment building at 3403 Foster Avenue in Brooklyn, New York, was paid with a nickel (U.S. five cent piece) that felt too light to him. When he dropped it on the ground, it popped open and contained microfilm inside. The microfilm contained a series of numbers.
He told the daughter of a New York City Police Department officer, that officer told a detective who in two days told an FBI agent about the strange nickel. After the FBI obtained the nickel and the microfilm, they tried to find out where the nickel had come from and what the numbers meant...
Vilyam (Willie) Genrikhovich (August) Fisher (Вильям Генрихович Фишер) (July 11, 1903 — November 16, 1971) was a noted Soviet intelligence officer. He is generally better known by the alias Rudolf Abel, which he adopted on his arrest. His last name is sometimes given as Fischer; his patronymic is sometimes less exactly transliterated as Genrikovich.
The Hollow Nickel Case (also known as The Hollow Coin), refers to the method that the Soviet Union spy Vilyam Genrikhovich Fisher (aka Rudolph Ivanovich Abel) used to exchange information between himself and his contacts, including Mikhail Nikolaevich Svirin and Reino Häyhänen.
On June 22, 1953, a newspaper boy (fourteen-year-old newsie Jimmy Bozart), collecting for the Brooklyn Eagle, at an apartment building at 3403 Foster Avenue in Brooklyn, New York, was paid with a nickel (U.S. five cent piece) that felt too light to him. When he dropped it on the ground, it popped open and contained microfilm inside. The microfilm contained a series of numbers.
He told the daughter of a New York City Police Department officer, that officer told a detective who in two days told an FBI agent about the strange nickel. After the FBI obtained the nickel and the microfilm, they tried to find out where the nickel had come from and what the numbers meant...
Chinese Phone Turns Smart Spy
China-based leading smartphone manufacturer Xiaomi, which recently marked a successful entry into the Indian market, is allegedly a security threat. It has been accused by the Indian Air Force (IAF) of sending user data to remote servers located in China -- a charge that amounts to spying...
Field Reports
• F-secure, a leading security solution company, recently carried out a test of Xiaomi Redmi 1s, the company’s budget smartphone, and found that the phone was forwarding carrier name, phone number, IMEI (the device identifier) and numbers from address book and text messages back to Beijing.
• A Hong Kong-based mobile phone user claims to have tested the Redmi Note smartphone and found it was automatically connected to an IP address hosted in China. The data transmitted included photo in media storage and text messages also.
According to the PhoneArena report, looking up the website of the company owning the IP address in the range 42.62.48.0-42.62.48.255 reveals that the website owner is www.cnnic.cn. CNNIC is the administrative agency responsible for Internet affairs under the Ministry of Information Industry of People’s Republic of China. It is based in the Zhongguancun hi-tech district of Beijing.
Therefore, the IAF in its alert to all of its Commands has stated that air warriors and their family members are advised to refrain from using these devices. (more)
Xiaomi MI Hongmi 1280x720 MIUI V5 |
• F-secure, a leading security solution company, recently carried out a test of Xiaomi Redmi 1s, the company’s budget smartphone, and found that the phone was forwarding carrier name, phone number, IMEI (the device identifier) and numbers from address book and text messages back to Beijing.
• A Hong Kong-based mobile phone user claims to have tested the Redmi Note smartphone and found it was automatically connected to an IP address hosted in China. The data transmitted included photo in media storage and text messages also.
According to the PhoneArena report, looking up the website of the company owning the IP address in the range 42.62.48.0-42.62.48.255 reveals that the website owner is www.cnnic.cn. CNNIC is the administrative agency responsible for Internet affairs under the Ministry of Information Industry of People’s Republic of China. It is based in the Zhongguancun hi-tech district of Beijing.
Therefore, the IAF in its alert to all of its Commands has stated that air warriors and their family members are advised to refrain from using these devices. (more)
Saturday, October 18, 2014
Privacy Rights Fact Sheets
Privacy Fact Sheets
California Medical Privacy Series
Friday, October 17, 2014
Even Good Spys Have a Bad Day Once in a While
The Australian Security Intelligence Organisation (Asio) inadvertently spied on its own employees,
in one of a series of surveillance breaches in the past 12 months compiled by Australia’s intelligence watchdog.
The Inspector General of Intelligence and Security (Igis) annual report was tabled in parliament on Thursday, and identified a series of breaches of Asio’s spying powers at a time when the federal government is granting the agency unprecedented new powers. (more)
in one of a series of surveillance breaches in the past 12 months compiled by Australia’s intelligence watchdog.
The Inspector General of Intelligence and Security (Igis) annual report was tabled in parliament on Thursday, and identified a series of breaches of Asio’s spying powers at a time when the federal government is granting the agency unprecedented new powers. (more)
Binder Flaw Threatens to Blow Apart Android Security
Security researchers have warned of a serious security flaw in Android which could potentially leave every device open to attack.
The vulnerability is in the operating system’s ubiquitous inter-process communication (IPC) tool known as Binder, according to a Black Hat Europe presentation on Thursday by Check Point researchers Nitay Artenstein and Idan Revivo...
“Subverting this component allows an attacker to see and control almost all important data being transferred within the system,” the two say in their research paper. (more)
The vulnerability is in the operating system’s ubiquitous inter-process communication (IPC) tool known as Binder, according to a Black Hat Europe presentation on Thursday by Check Point researchers Nitay Artenstein and Idan Revivo...
“Subverting this component allows an attacker to see and control almost all important data being transferred within the system,” the two say in their research paper. (more)
Hackers Target Hong Kong Protesters via iPhones
When the Hong Kong protests were at their height, activists using WhatsApp received messages advertising a program that promised to help them coordinate protests.
When the demonstrators downloaded the program through a link in the message, it turned out to be malicious software—most likely created by the Chinese government—that hacked their smartphones.
Lacoon Mobile Security, based in San Francisco, began to analyze the phony app after spotting unusual communication on the networks of its corporate clients, some of whose employees had downloaded it. In tracing the spyware’s path to the websites where it sent data, Lacoon’s researchers found a much rarer species of malware: a version that can steal information from iPhones. (more) (video)
When the demonstrators downloaded the program through a link in the message, it turned out to be malicious software—most likely created by the Chinese government—that hacked their smartphones.
Lacoon Mobile Security, based in San Francisco, began to analyze the phony app after spotting unusual communication on the networks of its corporate clients, some of whose employees had downloaded it. In tracing the spyware’s path to the websites where it sent data, Lacoon’s researchers found a much rarer species of malware: a version that can steal information from iPhones. (more) (video)
Thursday, October 16, 2014
FBI to Congress - More Power Please
The FBI is asking Congress to give it new powers to force technology companies to turn over private information on their customers.
FBI Director James Comey warned Thursday that new technologies are making it easy for criminals to hide incriminating information from police...
For several years, the FBI has been warning about the problem of new technologies allowing criminals to "go dark." But Comey explained that his new push was prompted by the decisions by Apple and Google to provide default encryption on their phones that will make it impossible to unlock them for police, even when faced with a court order. (more)
FBI Director James Comey warned Thursday that new technologies are making it easy for criminals to hide incriminating information from police...
For several years, the FBI has been warning about the problem of new technologies allowing criminals to "go dark." But Comey explained that his new push was prompted by the decisions by Apple and Google to provide default encryption on their phones that will make it impossible to unlock them for police, even when faced with a court order. (more)
Subscribe to:
Posts (Atom)