Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday

,



Artist’s impression of a small Australian built satellite to help gather intelligence for the ‘Five Eyes’ intelligence network involving Australia, USA, UK, Canada and NZ.




THERE is going to be a highly secretive meeting being held in Queenstown this weekend, which is a gathering of intelligence and security agencies related to the Five Eyes — the spying partnership of the United States, Australia, Canada, the United Kingdom and New Zealand.


The NZ Heraldreports people believed to be attending include Federal Bureau of Investigation (FBI) director James Comey and Central Intelligence Agency (CIA) director Mike Pompeo.


It is understood about 15 agencies, which carry out intelligence for Five Eyes, are attending the conference.


In a statement released yesterday, a spokesman for Prime Minister Bill English confirmed a number of senior officials were coming for a conference hosted by the Government, but would not reveal what the conference was.


“Due to specific security requirements we cannot comment further at this time. However, as police have pointed out they are not aware of a visit to Queenstown by a current or former head of state.”


Speculation about the visit was sparked after the Otago Daily Times reported a “very, very important person” was set to arrive in the region and strong security measures were underway in preparation.





Not a terrible location for a secret spy meeting.

Not a terrible location for a secret spy meeting.Source:Supplied





The ODT said it was understood the operation would continue for about a week with golf featuring on the itinerary.


Visits by the top spies are usually kept under wraps, although former Prime Minister John Key last year disclosed the then US director of intelligence Jim Clapper was in town when asked why a US plane was at the military terminal in Wellington. Clapper visited on his way to Australia for a Five Eyes conference.


He retired before last year’s US elections and Coats was sworn in March.


The director of national intelligence is the chief intelligence adviser to the President and oversees the 16 agencies within the US intelligence community including the CIA and National Security Agency.


Queenstown, and Arrowtown in particular have long been a magnet for international figures.


Former United States President Bill Clinton stayed at Millbrook Resort in 1999 after an Apec leaders’ meeting in Auckland.


This story first appeared on the NZ Herald and has been republished with permission.

Thursday

,



The Android app Flashlight LED Widget is a malicious trojan which can steal banking credentials and intercept text messages. Picture: Supplied.




SECURITY experts have identified a seemingly helpful Android app on the Google Play store that can mimic Australian banking apps to steal banking details and send them to Russian hackers.


Eset malware researcher Lukas Stefanko discovered the app Flashlight LED Widget was a malicious trojan that 5000 people downloaded the app before it was pulled from the Google Play.


“We’ve seen fake screens for Commbank, NAB and Westpac Mobile Banking, but also for Facebook, WhatsApp, Instagram and Google Play,” he said in the blog post on the dangerous app.


Mr Stefanko said this app was a greater threat than most malware because it was able to dynamically change depending on the apps on the infected phones.


“The trojan can display fake screens mimicking legitimate apps, lock infected devices to hide fraudulent activity and intercept SMS and display fake notifications in order to bypass two-factor authentication,” he said.


“The malware can affect all versions of Android. Because of its dynamic nature, there might be no limit to targeted apps — the malware obtains HTML code based on apps installed on the victim’s device and uses the code to overlay the apps with fake screens after they’re launched.”


The first time the app launches on a phone, it takes a photo of the phone’s owner and identifies their location. If the person is in Russia, the Ukraine or Belarus, the app deactivates which Mr Stefanko said was presumably to avoid prosecution in the hacker’s home country.


When the user launches their banking app, the trojan creates a fake version which captures the person’s credit card or banking details and sends them back to the Russian server.


Android phone users who have downloaded the app should immediately delete it.


Mr Stefanko said to delete this app, which is designed to block moves to remove it, people will need to boot their phone in safe mode.






,

The new cards are currently being tested in South Africa, and MasterCard hopes to roll them out to the rest of the world by the end of 2017. Even if that happens, though, you’ll still have to wait for your bank or financial institution to get on board.


Once the technology is ready for the public, here’s how it should work. Your bank will inform you that the biometric card is available, and if you’re interested, you’ll have to go to an enrollment center (most likely a bank) to get your fingers scanned. An encrypted digital template of your fingerprint is stored on the card’s EMV chip. You can save up to two prints, but they would both have to be yours — you can’t authorize someone else to use your card with their fingers. After your templates are saved, your card is ready to be used at compatible terminals worldwide — merchants don’t have to get new equipment to accept your fingerprint-enabled plastic.



The card itself is surprisingly no thicker than a regular credit card. The fingerprint sensor is a small, thumbnail-sized rectangle that sits at the top right corner, and is easily accessible when you stick the card into a payment terminal.


During a recent demo, I tried to use a MasterCard rep’s biometric card with my finger, and received a “Transaction denied” message from the test payment terminal. When she carried out the faux-purchase, the payment went through, and the machine began printing a receipt. What really surprised me was the speed at which it happened.


When the terminal asks you to insert the card, it’s communicating to the bank information like your identity and the amount of the transaction. Then, it verifies your identity by asking for your fingerprint. The sensor reads your finger, and sends the information to the card’s chip, which determines if you’re the owner. If you are, it sends a “Yes” or “Authorized” message to the bank, which then allows the payment to pass.



At my demo, the authorization process happened almost instantly, which is reasonable given it’s all happening on the card instead of going through the bank. When it was me using the card, however, it took a slight pause to register that I wasn’t certified. I didn’t have trouble learning the new process at all, either — it’s intuitive and straightforward to simply leave your finger on the card as you slide it into a payment dock.


Of course, this method is only compatible with chip-and-pin cards, so it won’t work with stores that only accept the older magnetic stripe models. But embedded chip technology has become increasingly popular in the US, thanks largely to regulations making financial institutions and merchants liable for breaches resulting from a lack of support for chip-and-pin cards. Getting a new biometric card is troublesome, since it would require a trip to the bank and a potentially long wait. But the convenience and the joy you’ll get from waving that fancy new plastic in your friends’ faces may make that agony worthwhile.




[ Source:-http://q.gs/DgVcc ]

Wednesday

,

Microsoft’s phone sign-in works similarly to Google’s sign-in prompts in that it uses a mobile app (available for iOS, Android and Windows Phone) to confirm your identity, but you’ll never actually need to type a password when signing on to Microsoft services. Once you’ve set up your Microsoft Account in the app, you can enable phone sign-in through the settings menu. The next time you log in to your Microsoft Account on the desktop, you only need to enter your username and you’ll receive a notification on your phone to approve the login. Tap approve, and you’re in. The notifications act as a safeguard against unauthorized login attempts and the app can also create a unique code that works as a second authentication factor for OAuth logins.


Of course, you can always switch back to your password if you’ve somehow been separated from your phone, but Microsoft says the whole process is “easier than standard two-step verification and significantly more secure than only a password.”



[ Source:-http://q.gs/DgLfQ ]

Follow Us @soratemplates