Friday, May 23, 2014

Invasive Brain-Hacking Software May Soon Become a Reality

In the near future it may become possible to extract sensitive information from the brain with the help of invasive software or spyware.

It is not really important if you want to share this information with anyone or not because this software will force you to do it against your will.
Your thoughts will no longer be only yours.

At USENIX Security conference, scientists showed that it is really possible to "program" your mind through software to force you to reveal information that all people would prefer not to share with the world.

The Brain-Computer Interface (BCI) becomes more and more cheap and widely used. As stated in the research paper on the feasibility of side-channel attacks with brain-computer interfaces, this system analyzes brain activity and thus makes communication between a user and an external device possible. In recent decades, the BCI has been applied mainly in the medical field and was aimed at increasing the quality of life for patients suffering from severe neuromuscular disorders.


This time, security researchers from the Universities of OxfordGeneva and California have created the software specifically designed to search for sensitive data, such as your home location, your debit card PIN, your birth date, etc.

The software has been tested on 28 participants who were quite cooperative and had no idea that they would accept brain "invasion".

The experiments reached 10 to 40% chance of success in obtaining useful information. At present, this device still resembles science fiction, but the technology does not stop developing, and maybe in the near future, such «brain-hacking» software will be available.

This technology of mind control will undoubtedly cause controversy. Many people will wonder who should be allowed to use this type of software and why. Should the police have the opportunity to use this technology on suspects to prevent or solve crimes? And what about the privacy rights of an individual? And finally, what will happen in the brain, if the brain scan software contains malware? There are still many unanswered questions...

Tuesday, March 18, 2014

Backdoor found in samsung galaxy

Backdoor samsung galaxy devices
Google’s Android operating system may be open source, but the version of Android that runs on most phones, tablets, and other devices includes proprietary, closed-source components.

Phone makers, including Samsung ships its Smartphones with a modified version of Android, with some pre-installed proprietary software and because of lack in independent code review of those closed-source apps, it is complex to authenticate its integrity and to identify the existence of backdoors.


Paul Kocialkowski, the developers of the Replicant OS has uncovered a backdoor pre-installed onSamsung Galaxy devices and the Nexus S, that provides remote access to all the data in the device.
Replicant OS is an open source operating system based on the Android mobile platform, which aims to replace all proprietary Android components with their free software counterparts.
In a blog post, He explained that Samrtphones come with two separate processors, one for general-purpose applications processor that runs Android OS and the other one known as the Modem, responsible for communications with the mobile telephony network.

The Researcher found that a Samsung's IPC protocol runs in the background, which is bound to the communications processor, and allows the modem to remotely read, write, and delete files on the user's phone storage. Samsung IPC protocol, implements a class of requests, known as RFS commands, that allows the modem to perform remote I/O operations on the phone’s storage.
"The spying can involve activating the device's microphone, but it could also use the precise GPS location of the device and access the camera, as well as the user data stored on the phone. Moreover, modems are connected most of the time to the operator's network, making the backdoor nearly always accessible."
This backdoor might have been placed there accidently, but remote ability of modifications to the user’s personal data without user knowledge poses a serious threat.
"It is possible to build a device that isolates the modem from the rest of the phone, so it can't mess with the main processor or access other components such as the camera or the GPS."
"The incriminated RFS messages of the Samsung IPC protocol were not found to have any particular legitimacy nor relevant use-case. However, it is possible that these were added for legitimate purposes, without the intent of doing harm by providing a backdoor." he said.

"However, some RFS messages of the Samsung IPC protocol are legitimate (IPC_RFS_NV_READ_ITEM and IPC_RFS_NV_WRITE_ITEM) as they target a very precise file, known as the modem's NV data." he added.

The researcher identified multiple Samsung devices affected by this vulnerability, including; Nexus S, Galaxy S, Galaxy S2, Galaxy Note, Galaxy Tab 2, Galaxy S 3, and Galaxy Note 2.

38% Employees in US Organizations are not aware about BYOD Policy

In this busy world it is quite difficult to manage professional, personal and social existence. A person is involved everywhere and it is expected from the person to be obeyed towards his work. Organization with the aim of superior growth gives more flexibility to its employees and allows them time flexibility, cell phone uses, use of office Wi-Fi etc. BYOD (Bring Your Own Device) is an evolving concept in modern organizations.
Employees stick to their devices every time, but they are often unaware about security risk associated with usage of personal device. They literally give little importance or totally unaware about BYOD policy of organizations. These are some findings of a survey taken out by security expert Absolute Software.

The survey Objective:

The object of survey was to discover and understand the attitude of employees towards BYOD (Bring Your Own Device) policy, data security, privacy, and responsibility.

What is BYOD?


byod
Before revealing further about the survey, we should focus on BYOD. It means when an employee use his laptop, Smartphone, PDAs at both work place and home. There should be a strict policy about device usage to secure official data of company. In this regard, BYOD policy comes into existence. BYOD policy makes their employees secure and help IT department to handle such devices by obeying company security parameters.

The Survey Methodology:

The survey was conducted from 15 to 29 November 2013 among 750 US adults who utilize their mobile phone for work purpose. Uses of laptops, iPad, PDAs are not included in this survey; only mobile phones usage details are covered. They are associated with different industries like banking, retail, healthcare, and energy. All these industries have capacity of more than 1K employees.
Lancope and the Ponemon institute have recently done a survey to check the level of awareness about Computer Security Incidents in organization.

Key Findings:

A shocking result came from the survey that compels organizations & employees to think over use of personal device security and its privacy.
  • Almost 2/3 employees use their mobile phone for both personal and official use. More than 50% employees have their own mobile phone, and the rest use phones owned by the company.
fig 1 byod
  • Almost 71% respondents feel that some of their data on work phone is private. The rest respondents do not keep personal data on a work phone.
fig 2 byod
  • Employees considered many categories like personal email, social media data, music, notes. However, email and contacts ranked as the most vital information stored on a work phone. Personal and work contact and official login details also ranked subsequently.
fig 3 byod
  • 59% employees considered that the corporate data on work phone is worth less than $500. While 60% considered their private data is worth less than $500.
fig 4 byod
  • There were 94% responders believed that their workplace is moderately secured, while 61% said that they need strict security in workplace.
fig 5 byod
  • There were 62% reported that their company follows policy about lost phone. There were 23% respondents do not know about such policy.
fig 6 byod
  • 72% respondents believed that an employer should be penalized for leaking personal data, while 94% agreed that there should be improvement in this regard.
fig 7 byod
  • 75% respondents believed that they should be penalized on losing corporate data, while 25% believed that data security is not their task.
fig 8 byod
  • After losing a work phone, 57% respondents said that they have not still changed their security habits.
fig 9 byod
  • 75% responders said that they should be penalized upon losing a work phone, while many of them who had lost a phone said they are not punished at that time but replaced the device or had a talk with authority.
fig 10 byod
Tim Williams, director at mobile enterprise data expert and Director, Product Management at Absolute Software said, “If firms don’t set clear policies that reflect the priority of corporate data security, they can’t expect employees to make it a priority on their own”.
From the above survey, it is clear that organizations are not up to the mark in terms of BYOD policy. Employees are not taking security in a serious manner even after losing their device. Such attitude of workers can put organization data at risk and it will be costly for organizations.