Friday, October 30, 2015

Security Director Alert - 80% Chance Your Card Key System Can Be Bypassed

A device the size of a quarter that can be installed in 60 seconds on a proximity card reader could potentially be used to break physical access controls in 80 percent of deployments.

The device, dubbed BLEKey, is used to read cleartext data sent from card readers to door controllers to either clone cards or feed that data to a mobile application that can be used to unlock doors at any number of installations.

The hack unveiled at Black Hat is worrisome for facilities reliant on proximity cards and readers for access to buildings in critical industries or enterprises. Researchers Eric Evenchick, an embedded systems architect at electric car manufacturer Faraday Future, and Mark Baseggio, a managing principal consultant at Optiv (formerly Accuvant), used the ubiquitous HID cards and readers in a number of successful demos during their talk, but said that it’s likely the same weaknesses that facilitate their attacks are present in devices from other manufacturers. more video

Really Scary: 29:35 minutes into the video they explain how to make a card-key interceptor, stick it into a back pack, go to the target workplace, get in an elevator with employees (or just close to one of them), secretly read everyone's cards, and make a clone card.
Happy Halloween ~Kevin

The Disorderly Orderly, or Spycam Peek-A-Boo in the ICU

India - Police have arrested a 30-year-old male orderly of Rajiv Gandhi Cancer Institute and Research Centre

on charges of filming women after allegedly putting up spy camera in changing room for nurses.

A nurse spotted the spy camera in the changing room inside the intensive care unit (ICU) on the third floor and alerted a security guard, said sources.

Police have reportedly recovered two obscene video clips from his spy camera, which was installed for around 12 hours, said sources. Police will now try to retrieve deleted data, added the sources. more

Police vs Spy Blimp in PA - Shotguns Preveil

PA - State police used shotguns Thursday to deflate a wayward military surveillance blimp that broke loose in Maryland and floated for hours before coming down into trees in the Pennsylvania countryside.

Curious residents trickled into a staging area as the military began gathering up some 6,000 feet of tether, the blimp’s huge hull and a smaller tail piece, a process expected to take at least through Friday.

The white behemoth still had helium in its nose when it went down in a steep ravine on Wednesday afternoon, and the easiest way to drain the gas was to shoot it, U.S. Army Captain Matthew Villa said. State police troopers peppered the blimp with about 100 shots. more How it all started.

The Ultimate Spy vs Spy

via Mark Frauenfelder, Boing Boing
It was a wordless one-page comic about two oddly pointy faced spies, one dressed in black and the other dressed in white. Other than their different colored outfits, they behaved identically. They hated each other and created elaborate Rube Goldberg type machines to try to kill each other. Sometimes their machines worked, often, they’d backfire. They were tricky but usually too clever for their own good.


This anthology colorizes 150 “Spy vs Spy” comics drawn by Antonio Prohías from 1961 until his death in 1987. The book also includes a collection of “Spy vs Spy” comics by the talented cartoonist Peter Kuper, who took over the strip when Prohías died. The anthology features a section of wonderful “Spy vs Spy” tribute drawings by noted cartoonists such as Peter Bagge, Bob Staake, Darwyn Cooke, Gilbert and Jaime Hernandez, and Bill Sienkiewicz. There’s also a biography of the Cuban-born Prohíasm and a new 4-page color strip by MAD luminary Sergio Aragones about his friendship with Prohías. With all the new material here, this book is a must for anyone who loves “Spy vs Spy.”

Spy Vs Spy: An Explosive Celebration
by Antonio Prohías and Peter Kuper
Liberty Street, 2015, 224 pages, 8.8 x 0.8 x 11.2 inches
$16.46 at Amazon

Thursday, October 29, 2015

Spycam Ejection

Australia - A Brisbane landlord has been slammed for installing CCTV cameras inside his rental property and spying on his tenants, who he evicted once they complained.

Renters Ben and Lila - who withheld their surnames - told Channel Nine's A Current Affair they noticed they were being recorded on the first day they moved into their new apartment.

The security camera was set up in the lounge room, switched on and recording.

According to the program, the furious flatmates immediate flicked the switch on the camera, before they were contacted by the landlord who said they had to turn it back on.  more video

Crackdown on Users of DroidJack Spyware

Law enforcement officials in almost half a dozen European countries have searched the homes of people suspected of having used software to spy on mobile phone users...

In Germany, prosecutors searched the homes of 13 people on Tuesday, they said, adding raids had also taken place in Britain, France, Belgium and Switzerland. They did not have further information on the raids in other countries.

The suspects in Germany, aged between 19 and 51, are believed to have bought and used smartphone software DroidJack, which allows surveillance of phones that use Google's Android...

The software allows users to monitor a smartphone's data traffic, eavesdrop on phone conversations or hijack a phone's camera without its owner noticing. It can also be used to spy on smartphone users as they access online banking systems. more

Bud Flight - Spies on the Go

The two-state battle for a federal spy agency’s new regional headquarters is heating up,
with Missouri Gov. Jay Nixon on Wednesday announcing plans to publicly push to keep the agency in St. Louis as hundreds of supporters gathered across the Mississippi River to tout a potential Illinois location.

At stake in the bistate regional fight are more than 3,000 high-tech jobs at the National Geospatial-Intelligence Agency paying an average of $75,000.

The defense and intelligence agency is considering four sites to replace its current location near the Anheuser-Busch brewery south of downtown St. Louis. more

Business Espionage: Buy Your Batting Average with Blackmail

Former big leaguer Lenny Dykstra admitted to spending "half a million bucks" on private investigators to dig up dirt on umpires during his playing career.

Dykstra says he then used the information not necessarily to bribe umpires, but to intimidate them into giving him favorable calls. "Fear does a lot to a man," he says. Here's the video:


 "Their blood is just as red as ours. Some of them like women, some of them like men, some of them gamble," said Dykstra. He then imagined a scenario in which he asked the umpire if he "covered the spread last night" after a called strike, then the strike zone shrunk to his advantage.

"It wasn't a coincidence that I led the league in walks the next few years," he added. Dykstra led the league with 129 walks in 1993 while with the Phillies. His previous career high was 89 walks, though he missed plenty of time with injuries. Dykstra's walk rate did spike from 1993-94:

This App Turns Your Smartwatch into an Eavesdropping Device

There are times when being able to easily record audio is a serious advantage in your day to day life. Whether that means you do it for work, school, or anything else, now you can easily do it with Wear Audio Recorder on your Android Wear device. Whether it's a short moment or a full meeting, this app has got you covered.
Wear Audio Recorder has a fantastic look that is both simple and stylish. Unsurprising when you realize that they're using Google's Material Design. On your Smart Watch, this app doesn't have a ton of features. What it does, it does well. Recording is as simple as opening the app, and tapping record. more

Why do I mention it?
So you will know what you're up against.

Wednesday, October 28, 2015

Spies in Space: The Final Frontier in Espionage

Space, the ‘final frontier’, is rapidly becoming an extra-terrestrial battleground for corporate espionage and other types of cyber attack as hackers seek to gain commercial advantage from rival networks operating in the $330-billion space economy...

The amount of data now being beamed between satellites supporting commercial networks on earth is growing rapidly, making them a ripe target for cyber attacks, said Luca del Monte, a senior strategist at the European Space Agency, and one of many experts who attended the annual International Astronautical Congress last week in Israel.

Space presents a double opportunity for hackers – the hardware up in orbit and the information it transmits. more

The 'Spy in a Bag' Case Continues

Gareth Williams was blackmailed with 'staged photos in Las Vegas hotel room' by Russian spies, claims former KGB agent...

A former KGB major says he believes Gareth Williams was murdered by Russian hit men as the MI6 spy refused to become a double agent, even after they blackmailed him by taking compromising, staged photographs.

The former major and intelligence officer Boris Karpichkov, who was exiled from Russia and now lives in the UK with a new identity, told his version of events to The Daily Mail. He claims to have a source high up in Russian intelligence services.

Mr William’s dead body was found locked in a bag in his Pimlico flat in 2010. He has been a codebreaker at GCHQ but at the time was on secondment to MI6 at their offices in Vauxhall, London. more

Criptyque Launches Pryvate™, the First Fully Secure Communications Platform

Criptyque, the secure communications provider, today announced the launch of Pryvate™, the first all-encompassing and fully encrypted communications platform for mobile devices. Pryvate secures communication services across email, voice calls, conference calls, video calls and instant messenger to protect consumers and businesses from cybercriminals, intruders, corporate espionage, hackers and more.

The Pryvate application provides triple-layered security powered by top-of-the-line 4096-bit encryption, with AES 256-bit key management and DH key exchange. It offers truly seamless independent, network agnostic security combined with high quality of service at a low cost.

Initially available on Apple and Google Play stores, the service provides security by generating unique encryption keys on the devices of both users who communicate via the application. Once a key is used, a new key is created for every subsequent interaction and auto renew for every call, IM, message, session etc. Pryvate has no access to users’ encryption keys past, present or future: making it impossible to leak, hack, collaborate or give away keys, which makes all communication through Pryvate totally secure and impervious to hacking. more

Business Espionage: HSBC Nemesis Falciani Mocks Swiss Justice a Mile From Border

Herve Falciani, the Frenchman wanted on charges of industrial espionage in Switzerland, has opted to skip his trial at the country’s top court and instead plead his case before a jury of journalists at a French hotel, less than a mile from the Swiss border.
The Frenchman was the star attraction at a conference billed “Investigative Journalism in the Time of Wikileaks” Wednesday at the Domaine de Divonne. The hotel and casino is a 20-minute drive from Geneva, where Falciani took client data from HSBC Holdings Plc’s private bank nearly a decade ago. more

Tuesday, October 27, 2015

What's in The Washington Post basement?

Nixon tapes and Cold War spy photos.

Deep in the basement of the Washington Post newsroom, national security reporter Walter Pincus is rediscovering 40 years worth of handwritten notes, White House telephone records and declassified spy photos. As the Post prepares to move into a new building in December, he’s digging up details on many of the historical stories he’s worked on. (Jorge Ribas and Jayne W. Orenstein / The Washington Post) more

Corporate Espionage that Flies Below the Radar

by Kevin G. Coleman, SilverRhino
Headlines about economic, corporate and industrial espionage have been in abundance lately and for good reason... Several subject matter experts agree that much of these espionage activities that target businesses are criminal-based.

Recently while on the executive floor of one large company a new twist to espionage tradecraft popped up.

Drone at office window story.
After entering a conference room, a note on the whiteboard caught my attention: “DO NOT ERASE.” Seeing that on a whiteboard filled with financial numbers, notes, diagrams and so on is not an uncommon occurrence. When I was looking out the windows, I saw a drone slowly fly by. Given the camera capabilities that are now available and becoming common on drones, it would not be difficult to capture what was on those whiteboards. The images are digitally captured, cropped, enhanced extracted and then sold...

Today economic, corporate and industrial espionage is big business. With significant money being made selling corporate secrets, this threat will only grow. more