Wednesday, 27 May 2015

Three Great Smartphones That Won’t Leave Your Wallet Empty

nokia_lumia_930_conversations
The cheapest smartphones don’t have all the gizmos of Apple or Samsung models, but I’m impressed by how many features you do get for roughly a third of the price.
Processors are slower, yet that’s not so noticeable for basic tasks such as email,Facebook and weather checks. Video and audio are also enjoyable, as long as I’m not expecting the same performance I get on high-end phones. Batteries don’t last quite as long without a recharge but I still got about seven hours of streaming video on Hulu. Do I really need the nine to 12 hours I can get with an iPhone or Samsung Galaxy?
Because you spend so much time with your phone, there’s a case for having the best. But those come with a price tag starting at about $650 (unless you agree to a two-year contract, in which case you end up paying higher service fees for voice, text and data).
So consider how you use your phone and what features will remain most important to you over the next year or two. Before you break the bank, here are three solid phones that cover the basics:
ZTE Nubia 5S Mini (Android, $280)
The Nubia is a slim, light device with a 4.7-inch screen – the same as the iPhone 6. It looks sleek and is comfortable to hold. What’s the catch?
The Nubia’s display measures 1,280 pixels by 720 pixels, well short of what you get on the latest iPhones and top-end Samsung Galaxy devices. That resolution is adequate for 720p high-definition video, not the sharper 1020p. The camera is OK for taking everyday shots; pricier models deliver better focus and colors and take nicer low-light photos with the flash off.
However, the front camera for selfies is 5 megapixels, better than the typical phone. (The rear camera takes 13 megapixel shots, which is common.) And it comes with 4G connectivity and 16 gigabytes of memory.
Motorola Moto G (Android, $180)
Motorola has a $129 Moto E phone, and you get a good device at that price. But I’ve found photos to be subpar, especially because the camera has a fixed-focus lens, meaning it doesn’t compensate for how far away your subject is. Given how much people use the camera on their phones, I recommend spending another $50 for theMoto G.
The latest Moto G model has a large 5-inch screen that is covered with Corning’s Gorilla Glass for durability, something more common in pricier phones. The Moto G’s back is curved, which could contribute to a better grip. Like the Nubia, its display is 1,280 pixels by 720 pixels.
The rear camera is 8 megapixels, the same as the iPhone, though shots weren’t as good. The front camera is 2 megapixels.
The Moto G’s main shortcoming is the lack of 4G LTE cellular connectivity. You’re stuck with the slower 3G network. LTE is available for last year’s Moto G model, but that screen is only 4.5 inches and the camera’s resolution isn’t as good. The Moto G also starts with just 8 gigabytes of memory, when many smartphones are starting to offer 32 gigabytes.
Microsoft Lumia 635 (Windows, $179)
This 4.5-inch device doesn’t feel as sleek as top-end Lumia phones such as the Icon and the 1520. But it’s better than the $79 Lumia 530, which feels like a bar of soap, given its bulk and smaller screen. It’s worth getting the 635 instead, especially as some carriers and retailers are offering substantial discounts to bring its price close to the 530’s.
The Lumia 635 has a 5 megapixel rear camera, no flash and no front camera. It performed better than the Nubia and the Moto G in low light. Just don’t expect shots to match what the 20-megapixel Icon produces. The display resolution is lower than on the Nubia and the Moto G, and the built-in storage is again just 8 gigabytes.
But the 635 does have 4G connectivity.

NSA Planned Hack of Google App Store

google-play

The US National Security Agency developed plans to hack into data links to app stores operated by Google and Samsung to plant spyware on smartphones, a media report said Thursday.
The online news site The Intercept said US intelligence developed the plan with allies in Britain, Canada, New Zealand and Australia, a group known as the “Five Eyes” alliance.
The report, based on a document leaked by former NSA contractor Edward Snowden, said the plan aimed to step up surveillance efforts on smartphones.
The plan appeared to have been discussed at meetings involving the intelligence services in 2011 and 2012, according to the classified document. The project called “Irritant Horn” would allow the agencies to hijack data connections to app stores and surreptitiously implant malicious software on smartphones that would allow for data to be harvested.
The intelligence agencies could also use the spyware to send misinformation to targets to confuse potential adversaries, according to the report.
The Intercept said the plan was motivated in part by concerns about the possibility of “another Arab Spring,” or the spread of popular movements.
The agencies were particularly interested in the Africa region, especially Senegal, Sudan and the Congo but also targeted app store servers in France, Cuba, Morocco, Switzerland, Bahamas, the Netherlands and Russia.
At the time, the Google app store was called Android Market. It is now known as Google Play.
In developing the plan the agencies found weaknesses in UC Browser, an app owned by Alibaba Group which is popular in China and India to browse the Internet and is used by some 500 million people worldwide.
The document was also published in Canada by CBC News, which said the aim of the plan was to collect data on suspected terrorists and other intelligence targets, including their online search queries, SIM card numbers, device IDs and the location of the smartphone.
In one case, according to the CBC, analysts found a foreign military using the UC Browser app to communicate covertly about its operations in Western countries.
There was no immediate comment on the report following AFP queries to the NSA or Google. Samsung declined comment.
The report is the latest based on leaked documents from Snowden describing vast programs by NSA and other services to scoop up data in the search for terrorists.
The leaks starting in 2013 shocked many Americans and US allies and have led to calls for reform of laws governing US data collection.

Cybercriminals Use SVG Files to Distribute Ransomware

DECRYPT_INSTRUCTIONS-Virus1

Researchers at email and web security company AppRiver spotted a campaign in which malicious actors attempted to distribute a piece of ransomware with the aid of SVG files.
The attack starts with an email that appears to have a resume attached to it. The file is a ZIP archive containing an SVG file.
SVG (Scalable Vector Graphics) is an XML-based vector image format for two-dimensional graphics with support for animation and interactivity. Images and their behavior are defined in XML files.
SVG files contain a small JavaScript entry, which attackers exploited in the campaign observed by AppRiver to redirect victims to a webpage set up to push a piece of malware.
The JavaScript code in the SVG file analyzed by researchers contains an IP address that forwards users to another domain serving the notorious CryptoWall ransomware. If users execute the malicious file, their computer becomes infected and their important files are encrypted and held for ransom.
“Crypto ransomware has proven many times it is effective for attackers in getting users to actually pay the ransom. The tactic is still alive and likely to continue evolving. With the attacks still being prevalent, it’s a good idea to make sure you are covered with data backups that cannot be potentially accessed by the malware (it’s been known to encrypt network shares and NAS units),” AppRiver researchers said in a blog post.
An interesting aspect noted by experts is that the malicious executable served in this attack contains hardcoded SQL commands that appear to target a school’s database. AppRiver said some of the organizations they protected against this attack were schools, so it’s possible that someone with knowledge of SQL naming conventions used for school databases might have been trying to cause some damage with INSERT and DELETE commands.
However, researchers also pointed out that the SQL commands might have been included simply to make the analysis of the malware more complex and time consuming.
“While these appeared to be part of valid functions, it looks like they were not used during testing. Though it’s possible there were very specific parameters that needed to be met for this to go active and attempt sql changes,” researchers explained.

Tuesday, 17 March 2015

BIG DATA, BIG MESS: SOUND RISK INTELLIGENCE THROUGH COMPLETE CONTEXT

6a00d83452e85869e2019aff966213970b Big Data, Big Mess: Sound Risk Intelligence Through Complete Context
When it comes to cybersecurity, perhaps nothing has been as highly touted as the answer to every executive’s prayers as big data.
Years after “big data” became just another marketing buzzword, organizations are still grappling with the issue of how to use that data in a practical way.
Data is useful, but only if it’s being properly interpreted and conveyed. The problem isn’t with data, but with the way in which people are using it. Simply put, data alone is missing context.
Data alone presents a few problems, but many of them emerge from a single misguided view – 
that big data is the answer, not part of the answer.
Data without “complete context” is like a box of chocolates without the filling. It looks tasty, but bite into any of it and its nothing but air. All the good stuff is missing.

D-LINK PATCHES FLAWS IN IP CAMERAS, WIRELESS RANGE EXTENDERS

DCS 932L Front 1024x576 D Link Patches Flaws in IP Cameras, Wireless Range Extenders
D-Link has released firmware updates to address serious security holes affecting the company’s DCS-93xL IP cameras and the DAP-1320 wireless range extender.
According to an advisory published by the CERT Coordination Center at Carnegie Mellon University, Tangible Security researchers discovered a high-severity unrestricted file upload vulnerability (CVE-2015-2049) in the D-Link DCS-93xL family of network cameras.
The flaw affects firmware version 1.04 and possibly other versions. The camera models that run the vulnerable firmware are DCS-931L, DCS-930L, DCS-932L, and DCS-933L.
A remote, authenticated attacker can exploit the vulnerability to upload arbitrary files to a specified location on the device. The flaw can be leveraged to create, modify or delete data, and possibly even execute arbitrary code, CERT said.
The same Tangible Security researchers also identified a command injection vulnerability (CVE-2015-2050) in the firmware update mechanism of D-Link DAP-1320 wireless range extenders.
“The D-Link DAP-1320 Rev Ax firmware version 1.11 (released 22 Dec 2013) has been shown to be vulnerable. Other firmware versions prior to version 1.21b05 may also be vulnerable,” CERT noted in a separate advisory.
A remote, unauthenticated attacker can exploit the firmware update mechanism bug to execute arbitrary commands on the device. However, the attack only works if network communications can be intercepted and manipulated, CERT said.
The security hole affecting D-Link DAP-1320 has been addressed with the release of firmware version 1.21b05. As for the network cameras, the issue is fixed in the recently released version 1.10 (Rev A) and version 2.01 (Rev B) of the firmware.
D-Link’s own security advisories, which might contain additional details on the bugs, are currently undergoing approval, but the company advises users to update the firmware on their devices.
Earlier this month, D-Link released firmware updates to address multiple vulnerabilities affecting several DIR routers. The flaws, related to the ncc/ncc2 service, could have been exploited to hijack DNS configurations, inject arbitrary commands, and gain access to sensitive information.

QUALYS RELEASES SSL LABS APIS FOR AUTOMATED WEBSITE TESTING

ssl labs client test mixed content Qualys Releases SSL Labs APIs for Automated Website Testing
Cloud security and compliance solutions provider Qualys today announced the availability of free assessment APIs and a new tool that enable SSL Labs users to automate SSL vulnerability testing for websites.
Qualys SSL Labs is a non-commercial research effort that provides documentation on deploying SSL/TLS correctly, and tools that can be used to test a browser’s SSL implementation and a server’s configuration.
According to the company, the addition of API access allows security experts who manage more than one website to consolidate testing, detect configuration changes that might introduce vulnerabilities, and receive certificate expiration notifications.
The new server assessment APIs provide full access to the SSL Labs server inspection functionality, and allow users to conduct scheduled and bulk testing. The APIs also enable the integration of SSL Labs assessment with an organization’s security policies, Qualys said.
Automated and bulk testing can be carried out with ssllabs-scan, an open source command-line scanning tool that doubles as the reference API client. The new SSL Labs APIs, which can be used freely for non-commercial purposes, have already been integrated by third-party tools such as .Net Wrapper and Seccubus.
“Many organizations struggle to fully understand their exposure to various SSL/TLS security issues, due to the complexities of secure server configuration and constant change and attack disclosure in this space,” said Ivan Ristic, director of engineering at Qualys. “By offering free API access, we are enabling our users to automate website testing and regularly check their configuration in order to ensure websites are secure and protected from SSL vulnerabilities.”
Some major organizations are already planning on putting the new APIs to good use. According to Qualys, the Czech Republic (CZ) domain registry will use them to monitor over 1 million domains.

SOUTH KOREA ACCUSES NORTH OF CYBER-ATTACKS ON NUCLEAR PLANTS

South Korea Nuclear Facility South Korea Accuses North of Cyber attacks on Nuclear Plants
South Korea’s government accused North Korea Tuesday of carrying out cyber-attackslast December on its nuclear power plant operator, describing them as a provocation which threatened people’s lives and safety.
“We condemn North Korea’s persistent cyber-terror targeting our country and the international community,” the unification ministry said after investigators concluded the North was behind the attacks.
“It’s a clear provocation against our security,” the ministry said in a statement, accusing Pyongyang of “taking the life and safety of our people as a hostage”.
Tensions between the neighbors are running high after the South this month held joint military drills with the United States, which the North has condemned as provocative rehearsals for invasion.
Last December hackers published designs, manuals and other information about South Korean reactors on Twitter, along with personal information about workers at their operating company, Korea Hydro and Nuclear Power (KHNP).
The leaks prompted the South to heighten cyber-security and form an investigation team involving experts, government officials and state prosecutors.
The team on Tuesday said the hackers intended to cause a malfunction at atomic reactors, but failed to break into their control system.
It said malicious codes used in the cyber-attacks were similar to those which North Korean hackers have employed before.
“We’ve reached the conclusion that the crime was committed by a group of North Korean hackers seeking to stir up social unrest and agitation in our country,” the investigators said in a statement.
They said the hackers used multiple Internet protocol addresses based in China to send some 6,000 “phishing” emails to over 3,570 former and current KHNP workers to steal the data.
‘Social chaos’
KHNP officials have said the 23 nuclear reactors, which supply about 30 percent of the country’s electricity, were safe because their control system was separated from external networks.
They also said the material leaked by the hackers was not classified and did not affect safety.
Seoul has blamed North Korean hackers for a series of cyber-attacks on military institutions, banks, government agencies, TV broadcasters and media websites in recent years.
The United States also said the North was behind a cyber-attack which damaged the computer network of Sony’s Hollywood film unit over its controversial North Korea-themed satirical film “The Interview” last year.
Pyongyang denied involvement in the Sony hack but strongly condemned the film, which features a fictional plot to assassinate leader Kim Jong-Un.
South Korea’s unification ministry on Tuesday blasted Pyongyang for seeking to throw South Korea into “social chaos” with cyber-attacks on its crucial infrastructure.
North Korea has become increasingly bellicose in recent weeks ahead of large-scale joint military drills between the US and South Korea. One of the joint drills, Key Resolve, wound up last week, while the other, Foal Eagle, is set to continue until April 24.
The exercises are always a particularly testing time for relations between the two Koreas, who remain technically at war because the 1950-53 Korean conflict ended with a ceasefire, rather than a peace treaty.
North Korea displayed displeasure when this year’s drills began by firing two short-range missiles into the sea off its east coast. Last week it fired another seven surface-to-air missiles into the sea.