Showing posts with label infosec. Show all posts
Showing posts with label infosec. Show all posts

Saturday, July 6, 2013

Privacy and Smartphones


I feel a bit naive starting with the definition of a smartphone. A recent infographic by the Lebanese carrier "Touch" posted on their facebook page shows that 82.66 % of people using their mobile service are using either a Blackberry, an Iphone or an Andriod phone.

Anyways, a Smartphone is a small handheld electronic device that has features of both a mobile phone and a computer. This device allows us to communicate voice, text, and video, along with sending pictures, sending emails, managing bank accounts, and sharing locations.

Similar to PCs and Laptops, smartphones are currently equipped with powerful processors providing the user with high computing power. Yet unlike ordinary PCs and laptops, smartphone are always in our hand or in our pockets, their small size and easy mobility makes them man's best friend.

Privacy is a major concern to smartphone users; No matter what they do, there will always be seen and unseen pitfalls that may lead to the loss of privacy

Privacy Compromised:

Service Provider

By using a mobile phone, you can rest assured that your service provider is by default retaining log files that include:  
  • Incoming and outgoing calls: the phone numbers you call, the numbers that you receive calls from, and the duration of the call;
  • Incoming and outgoing text messages: the phone numbers you send texts to and receive texts from;
  • How often you check your e-mail or access the Internet;
  • Your location. (GPS / Cell usage)

In addition to the default data collected by your Smartphone service provider, you should also be aware of the possible privacy issues surrounding the collection or disclosure of:

  • Any photos or video you take on your phone;
  • The contacts you have stored in your phone;
  • Passwords;
  • Financial data;
  • What you store in your phone's calendar;


Picture Geo-tags

Depending on the brand and settings, your smartphone can use its built-in GPS capability to embed your exact location into the file of photos you take using the smartphone’s camera, this process is called geotagging. If you happen to share any geotagged picture, people can use the geotag to track your movements or find out where you live. 

Malware

Malware is malicious software that poses a threat to your smartphone just as it does to your computer. The apps on your smartphone are a rich environment for transmitting malware. Some malware care about stealing money (financial), other malware are concerned only with collecting data and transmitting it to a remote receiver.

Free Apps and Advertisers 

There are hundreds of thousands of applications for smartphones across all platforms, anyone can create an app. Most of these applications are free, free means cost free and not risk free. These apps can collect all sorts of data and transmit it to the app-maker and/or third-party advertisers. It can then be shared or sold.  Most free applications contain ads, to customize these ads up to the user preferences, personal date should be collected from the user‘s smartphone.

The privacy concern here is that information captured could be used to build a complete profile about you without your knowledge or approval.


Protect yourself 

1- Limit others' physical access to your Smartphone

A person who gains access to your smartphone can see all your private stuff or even worse they can physically install a malware capable of collecting data and then discretely transmit this data to other parties.

So in order to decrease the risk of privacy loss via physical access to your smartphone you should:
  • Password protect your phone; 
  • Do not allow your smartphone to automatically remember login passwords for access to email, VPN, and other accounts;
  • Use your phone’s security lockout feature. Set the phone to automatically lock after a certain amount of time not in use;
  • Install security software that allows you to remotely lock your phone and wipe the data;
  • Never leave your phone unattended. 


2- Usage of Public Wi-Fi Networks

When your smartphone uses a public Wi-Fi network to connect to the Internet (eg. coffee shop), it may be possible for others to “see” the data being transmitted by your smartphone so: 

  • Avoid the usage of untrusted public Wi-Fi networks 
  • If not possible, when using public and untrusted Wi-Fi networks. Do not conduct activities that use sensitive information such as mobile banking.

3- Mobile Security Software

Many individuals take great care to protect their computers with security software, but forget to do the same with their smartphones. Products from Eset, AVG, and McAfee may be able to:

  • Protect your smartphone against malware,
  • Back up your smartphone data, store data elsewhere
  • Track your phone if it is lost or stolen;
  • Lock your phone remotely, and wipe your data remotely.


4- Applications

Install applications only from trusted application sources. Read carefully what the application is trying to access before you install / use it, and only then decide whether to use this application or not. 

To most of us, the smartphones are the last thing we put from our hand before we sleep and the first thing we check when we wake up in the morning.  I think they deserve a little more caution on our part. 

Read more about Mobile Security


Tuesday, June 26, 2012

Again! I’m Not Falling for That One!

From time to time I review my email junk folder to check if a legitimate message got stuck in there, and in order to keep myself updated of new techniques and methods utilized to scam people into disclosing their confidential information.
 
Recently I ran across an email message, apparently from paypal requesting me to update my records in order to continue using their services. 
Since I really don't have a paypal account yet, this email is definitely a scam.
 
Upon More Investigation, carefully following the link mentioned in the email in order to update my non existing records, I was redirected to a webpage that looks like the original Paypal.com website

  
The first thing that caught my attention was the address of this fake Paypal page was the URL of this page



I tried to login to this false paypal page using incorrect and offensive credentials, i was redirected to a "Session timed out" page, and of course the credentials I used where sent, stored (stolen) by the creators of this illegitimate page.

Note that, the first thing that a user should check before disclosing any confidential data is the correctness of the URL for the page requesting this information. 


Always look for the httpS.

 


I wonder how many people took the bait and were scammed by this scenario.
The good thing is that the Firefox browser started to alert people before accessing the false paypal webpage by displaying this message 



Finally, don't fall for these scams, exercise a keen sense of responsibility, awareness and an appropriate dose of suspicion before disclosing personal information.   

Friday, June 1, 2012

Six ways to secure your Facebook!

Facebook has become big part of our lives. It is integrated in our social and private life. Nevertheless, Facebook users still face an obstacle, an issue that will exploit their privacy. Security is an essential issue when it comes to social networking, and if you don't secure your Facebook, you are in trouble. Here are six ways to secure your Facebook.

1. Go to your "Account Settings" by clicking on the arrow in the top right corner of your Facebook and selecting "Account Settings". Next, select the "Security" tab on the left side of the page, this will take you to this page:



2. Click on the first item labeled "Secure Browsing" and check "Browse Facebook on a secure connection (https) when possible". Don't forget to save your changes.



3. Next click on "Login Notifications" and check either Email or Text message/Push notification or both.



4. Edit "Login Approvals" and check the box. This will send you a text message to your phone whenever a user attempts to login to your Facebook account from an unrecognized computer or browser.



5. Click on the "Facebook Ads" tab on the right left side of the page


Then click on "Edit third party ad settings" and "Edit social ad settings" set share to "no one" in both.



6. Finally, go to your "Privacy Settings" reachable from the top right corner by clicking on the arrow. Set the default sharing permission to "friends".

Tuesday, May 8, 2012

New Technology Protects your Storage Devices

We previously discussed USB flash drive security and how to protect it. ThumbDrive has developed a new technology to prevent unauthorized access to the information stored on your USB by using a fingerprint authorization.


This USB has some advantages and disadvantages. Aside from securing your data, the advantages of this USB is that you can configure it to grant access to at most three users. You can also partition the USB flash drive to divide the storage capacity into secured data and open or unsecured data. It is a small, easy to set up and easy to access USB with an interface that reads your fingerprint.

Unfortunately, this USB has two major disadvantages, cost and storage capacity. Storage capacity is an essential issue when buying storage devices. The ThumbDrive flash drive is available in 16, 32, 64 and 128MB, which is relatively small compared to our day-to-day flash drives. The reason behind this issue is that the flash drive is mainly designed to hold confidential files, and these files are usually personal files, legal documents, and financial or accounting data that don’t require huge storage capacity. So capacity isn’t really an issue here. Another major disadvantage is cost. The ThumbDrive touch 16MB costs $160, 128 MB $465, which is really a major concern for the buyer.

Another solution for securing sensitive data on your flash drive is by using the newly designed “Voicelok Voice Authenticating USB drive”. This USB uses “voicecode”, in other words, it uses voice recognition to secure your data. The USB’s software detects precise frequencies and shades in the user’s voice. The advantages of this flash drive is that its price is much more reasonable than the fingerprint flash drive and has a better storage capacity, around $46 for a 8GB USB. Unfortunately this USB is still not reliable as the reviews indicate.

If you want my advice, the best solution is to check the “Lenovo ThinkPad USB Portable Secure Hard Drive”. The hard drive protects the data from unauthorized access by requiring the user to enter a code into the numeric pad located on the hard drive. It allows up to ten different users and an administrator. It has a huge storage capacity compared to the fingerprint flash drive and its price is perfect, $179 for 160GB and $219 for the 320GB. The size of the hard drive is similar to the size of any other normal hard drive.
Paying a little extra money to protect your information that can cost you a lifetime is worth it. If you have sensitive information and don’t want it falling in the wrong hands, I suggest you go for reliable technology like fingerprint flash drives or the numeric pad hard drive.

Wednesday, May 2, 2012

Ten Ways to Protect And Safeguard Your PC

Since the use of computers has become an integrated part of our lives, information security has become a greater challenge; here are the Ten Commandments to protect and safeguard your PC:

  • Keep your operating system updated (install patches and service packs). If you are using Microsoft Windows turn ON Automatic Update.
  • Keep your third party applications updated especially your web browsers. New web browser exploits are discovered regularly and can severely impact your PC. 

 2- Use an Antivirus / Anti-Spy / Anti-Adware
  • There are many good and free anti-malware applications that are free and can be downloaded and installed easily. I personally use AVG (free and effective)
  • Usage of anti-spy and anti-adware application will help you preserve your identity and privacy while using the internet. I personally use two: Spybot Search and destroy, and Lavasoft Ad Aware.
  • Keep your antivirus definitions updated or else you will be vulnerable to multiple types of threats that your current antivirus cannot detect.
  • Full scan your PC periodically.
  • Don’t panic: sometimes anti-spy-adware applications generate false positive alerts where for example some legitimate browser cookies are flagged as adware and scheduled for deletion.

 3- Use Windows firewall 
  • Although many professionals consider Windows firewall to be dumb and bypass-able, there is no reason why you shouldn’t utilize this extra free, built-in feature in your windows (Available on all Windows versions from XP and up)
  • Use third Party firewall to increase your defense against internet attacks, I personally use:  Zonealram

 4- Turn on the popup blocker
  • Pop-ups are usually used for advertising purposes they appear to grab your attention and redirect you from one website to their own. But not all pop-ups are used for advertising purposes; others are planted with malicious intent. Some use these programs to distribute adware, spyware and more dangerous types of malware (Trojans and even Rootkits)
  • Recent Browsers give you the ability of blocking Pop-ups, and the option of choosing which sites are allowed to pass pop-ups
  
 5- Suspicious Mails are not to be Opened 
  • Never open emails that look or feel suspicious to you or not known to you, Use the “Mark as Phishing – Scam – Spam- Junk” option that most email providers utilize.
  • Some malicious Emails contain links that direct users to malicious websites that aim to harvest usernames and passwords of social media websites such as Facebook and Twitter or financial websites.
  • Never communicate your confidential data via email. Confidential data includes but not limited to usernames, passwords, addresses, telephone numbers, and social security number. Note that: Legitimate companies will never ask you to share your credentials via email.

  6- Caution When downloading Software
  • Exercise extreme caution when downloading applications and software from the internet because these applications could carry different types of malware.
  • Cracks and serial number generators are hosts to many kinds of malicious codes that most of the times can’t be detected by antivirus applications.

7- Usage of USB and External Storage Devices 
  • Transferring data from one PC to another using an external storage media without the proper information security measures could lead to virus infections, data loss and data theft.
  • Disable auto run functionality in windows, although most antivirus software perform an activity monitor over files trying to slip into your pc from an external storage, but mistakes do happen.
  • Always scan the USB memory sticks, mp3 players, iPods, and Mobile phones memory cards before browsing its content. Always: better safe than sorry.
  • Don’t compromise your data; don’t use your semi full 500 GB External Hard Disk that contains “Your Lifetime Data Backup” as a transfer media to copy small files less than 8 GB from one PC to another. Get a memory card for this task – 8 GB sticks are currently cheap easy to handle, easy to carry and protect.

 8- Back-up Data
  • Perform periodical backup of your data, and please taking a copy of your “important files” To your D: drive (which is the same primary drive, but another partition) is not considered backup.
    Backup should be done on an External media such as USB drive or Hard Disk; I personally keep two backup copies on two different media storages. 

9- System Restore – Time Machine
  • Use Windows System Restore to create restore point before doing any major change to your operating system. If something goes wrong you can use this option to restore windows to a previous saved point.
  • Similar to System Restore on Windows, time machine works on OS-X. Backup is done seamlessly provided the designated drive is connected. And restore option allows users to restore from multiple points simultaneously.

10- Password Protection
  • Passwords are unique strings of characters that users provide in conjunction with a User ID, to gain access to an information resource.
  • Passwords should be at least eight characters long including upper and lower case letters along with digits and punctuation characters.
  • Should not be a word in any language
  • You shouldn’t reveal your password in an email message.
  • You shouldn’t talk about or HINT the format of your password in front of others.

 It is not hard to protect and safeguard your Data and PC, you just have to exercise some attention, and run the extra mile

Sunday, April 22, 2012

Scams: The Story Never Ends

Last week, I received 2 missed calls from an unknown number, When I called the number back a voice with an accent said "hi sir, this is Etisalat (The main mobile operator in UAE), congratulations you won AED500,000. Please turn off your phone, and get your sim out and read the last 3 digits on it, they should read 639 (apparently all Etisalat sims end with this number) and call me back" - I said ok, and closed.

He made another missed call after 5 min, he said did you check, I confirmed and said that I should receive my gift. Here I asked why do you make missed call, and not call, if you are from Etisalat, he said they are calling me, but it's is an issue in the network (Etisalat is suddenly having problems with my sim only).

He asked for my name, and nationality, I gave fake ones, he said that they opened an account with my name in Dubai Islamic Bank and gave me an account number. And then he said, one more thing is needed, I have to go to the nearest supermarket, buy AED2,000 worth of Etisalat vouchers to verify that I'm an Etisalat user.

I started laughing and told him, I will get them later, he said no, now, you have 15 min, you are on the air on the radio and people are listening to me as I speak.
I ended the call by threatening them, and I called the police who took the number and promised to take action.

Surprisingly, I was telling this story to a friend, and he told me that he fell for it, and after giving them the pins for the vouchers, they asked for another set of AED2,000 and another one ( they turn greedy once they capture a prey)
They ripped him AED 6,000 and you know what happened.

 Again, spotting scams requires a little bit of awareness and questioning. I hope that this post saves some people from getting conned.

Thursday, April 19, 2012

Certified and Validated

In this post, I will elaborate more on HTTPS. We previously discussed the term phishing in this blog. To summarize, phishing is an attempt to manipulate or trick a person into providing confidential information to an individual that is not authorized to receive such information. To protect yourself from phishing, recent web browsers have developed a way for checking if a website is valid or not.

Web browsers trust HTTPS websites based on certificate authorities which come pre-installed in their software. Examples of certificate authorities are “Microsoft” and “VeriSign”. In the example below, the bank's web site is verified by "VeriSign, Inc."

Always look for the green address bar. Recent web browsers show a green address bar in order to tell the user that this web site is legit and trustworthy. Its purpose is to give more confidence to the user and ensure them that they are visiting a trusted web site.

This issue plays an important role in Information Security. Next time you visit a web site make sure you look for the green address, especially web sites that ask for important and private information and web sites for payment transactions. To reassure yourself, check the certificate to know if this site is validated.

Saturday, April 14, 2012

Cookies, should we really like them

What are Cookies?
Cookies are small, mostly circular pieces of sweets, that are fun to... Oops Sorry!

Cookies are small, often encrypted text files that are stored silently on a user's computer. These files are designed to carry a little amount of data specific to a particular client and website. Cookies are automatically created when a browser loads a website, allowing a server to deliver a custom made page to a particular user every time this user goes back to the same website.

Cookies Expiry Periods
The expiry time of a cookie is assigned when the cookie is originally created. Some cookies are deleted or purged when the current browser window is closed (Session cookie), but others can be made to last for a longer period of time (Persistent cookie). Yet some can last for one year or even more.

Are Cookies Secure enough?
Internet security and privacy is of huge concern. Cookies do not in themselves present a threat to privacy, since they can only be used to store information that the user has volunteered or that the web server already has. But the existence of cookies poses an inherent risk of being abused

Cookies are NOT viruses, nor are they malicious; using a plain text format, they are not compiled pieces of code so they cannot be executed nor are they self-executing. Accordingly, they cannot make copies of themselves and spread to other networks to execute and replicate again. Unable to perform these functions, they are not classified as Malware. However, breaches of browser security can allow tracking cookies to be placed. These cookies can be used to follow users from one site to another, forming comprehensive profiles. Users consider this to be a violation of privacy, and in the wrong hands this information can potentially be exploited for questionable purposes. For that reason several anti-malware products flag cookies as candidates for deletion after standard virus and/or spyware scans.

Cookies can be exploited
Several malicious activities could be associated with the existence of cookies much like: Network eavesdropping, publishing false sub-domain – DNS cache poisoning, and Cross-site scripting. (More on these attacks in later posts)

Traffic on a network can be intercepted and read by computers on the network other than the originator (Especially over unencrypted open Wi-Fi). This traffic includes cookies sent on ordinary unencrypted HTTP sessions. When network traffic is not encrypted, attackers can read the communications of other users on the network, including HTTP cookies as well as the entire contents of the conversations.

How to live with cookies
Due to the fact that many of the largest and most-targeted websites use cookies by default, cookies usage is almost inevitable. Websites like Facebook, YouTube, Gmail, and many others require the usage of cookies for best performance and presentation. Even search settings require cookies for language settings.

Here are some tips you can use to ensure worry-free cookie-based browsing:
  • Most modern browsers support different levels of cookie acceptance, expiration time and ultimately deletion. Change your browser settings “Cookie Settings” to your preference.
  • When sharing PC access, you should make sure to set your browser to purge browsing data every time the browser is closed.
  • Don’t use other's / Public wireless networks especially when communicating sensitive information over the internet.
  • Use Https rather than Http when available.
  • Use a capable and updated anti-malware software.
  • Routinely back-up your computer to prevent data loss.
  • Make sure your browser is updated: security patches are applied when you update your browser.
Finally you should acknowledge that Cookies are widely used and can't really be avoided. If you wish to enjoy your internet surfing experience by navigating to “cookie creating websites” you should have a clear understanding of how cookies operate, and how to protect them from being abused. After all you are responsible of taking the necessary security measures to ensure your information security.