FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Tuesday, October 29, 2019

Security Congress Keynote Speaker: Put Down Your Phone

session photoAt public events, speakers and performers often ask the audience to turn off their mobile phones, but Catherine Price really meant it. She asked attendees of Tuesday’s keynote speech at (ISC)2 Security Congress 2019 to actually press their phones’ power button.

“I’m going to guess a lot of people are feeling uncomfortable. A lot of you faked it. A lot of you are probably hating me right now,” said Price, a journalist and author of the book, “How to Break Up with Your Phone.”

For the next hour, Price discussed the reasons we are so tethered to our phones, what it’s doing to us, and how we can take back control. She addressed the dangers of our constant attachment to phones in order to feel connected and prevent FOMO (fear of missing out), which causes anxiety, reduces our attention span and cognitive abilities, and may trigger health effects such as high blood pressure and depression. She also offered advice on how to break the habit.

Phones, she said, are like slot machines, which are designed to hook users by releasing dopamine, a neurotransmitter that reminds us of activities we enjoy and want to keep doing. “You never know what’s going to be on your phone, which makes you want to check it even more,” she said, citing social media, news apps and email as applications that tend to hook users.

“Apps are specifically designed to make them hard to put down. Why would that be? Because they make money,” she said. She cited Facebook, which essentially treats users as a product by collecting data about users and targeting ads at them.

Phones are causing a “state of continuous partial attention,” which splits our attention between our phones and our lives. And when we are looking at the phones, our attention is further split by email and other apps on the phone. While we may think we are multitasking, that is actually impossible because our brains cannot hold two thoughts at the exact same time, Price said.

In addition to reducing attention span, phones also are hurting our creativity because the state of continuous partial attention and FOMO create an effect of ongoing crisis. The body responds to crisis by increasing cortisol levels. Cortisol is a hormonal steroid that can increase the chances of obesity, stroke, heart disease, high blood pressure, anxiety, depression and other health effects.

Phone use also reduces the protein that the brain creates to promote creativity, she said. For cybersecurity professionals, she noted, this can be a problem since people in the field need to draw on their creativity to solve cybersecurity problems.

Breaking the Habit

Price shared several practices to help users reduce their phone time:

  1. Have a positive goal. Figure out when your phone use is getting in the way of achieving that goal and try to correct that.
  2. Notice your habits. Price suggested putting a rubber band around your phone, for instance, as a reminder to use it less. When you reach for the phone, the rubber band triggers the reminder and you stop yourself.
  3. Kill the “slot machine.” Get rid of dopamine triggers by making the phone boring. Some tips she shared include making your home screen black and white; bright colors used in apps are designed to hook you.
  4. Reduce your FOMO with an antidote – JOMO (joy of missing out).
  5. Protect yourself. Build firewalls around your life to increase happiness and creativity through deliberate decisions to, for instance, not having the phone during meals, meetings and bedtime.

Vita Unplugged

Before Price took the stage, Pat Craven, director of the (ISC)2’s non-profit Center for Cyber Safety and Education, announced a pilot program called Vita Unplugged. The program’s goal is to reduce screen time among students for an hour a day to focus on other activities. The inspiration for the program, Craven said, came from reading Price’s book.

The post Security Congress Keynote Speaker: Put Down Your Phone appeared first on Cybersecurity Insiders.


October 30, 2019 at 09:08AM

Privacy Regulations: More Work for Cyber Professionals

Whenever new data privacy and cybersecurity laws go into effect, they create more work and responsibilities for cyber professionals. This reality hasn’t gone unnoticed by attorney Scott Giordano, who reminded cybersecurity professionals during a session about the California Consumer Privacy Act (CCPA) that the law will create new duties for them.

Giordano, Vice President of Data Protection at Spirion, went over details of the law, which takes effect on Jan. 1, 2020, and how organizations should prepare for it. His was one of a series of presentations at the 2019 (ISC)² Security Congress, taking place in Orlando this week, about privacy and security regulations, and their impact on how organizations go about collecting and keeping personal customer data.

The California law comes in the heels of Europe’s General Data Protection Regulation (GDPR), and employs a broad definition of personal information. It includes identifiers such as name, address, email account and passport number, as well as other data such as personal property, web purchases, and internet browser and search history. “You can see that just about anything is personal information,” Giordano said.

The law will require businesses to respond within 45 days to requests from individuals for the information companies keep about them. It also will give users the right to have their data deleted. But there are exceptions, such using the data for debugging and security incident detection.

Giordano fielded a lot of questions in a roomful of (ISC)² Security Congress attendees, who clearly are keenly interested in how the law will work and what it means to them. Giordano also shared a list of recommendations to prepare for the law, including the following:

  • Create a data inventory.
  • Create a data subject access request (DSAR) process.
  • Determine what to include in a report to fulfill a data request and how to package it. “You don’t want to crate a snowflake for every consumer; otherwise, you’re going to get buried,” he aid.
  • Determine a delivery mechanism – customer account, email, regular mail.
  • Have a protocol to “make sure nothing falls through the cracks.”

The CCPA and other regulations were the subject of a panel discussion of attorneys on Monday afternoon. Panelists talked about another upcoming data privacy statute, the New York SHIELD Act, which takes effect on March 21, 2020.

The New York law is the most prescriptive yet, said Monique Ferraro, Cyber Counsel, Global Cyber Products at the Hartford Steam Boiler Insurance and Inspection Co. It lays out what the state expects companies to implement as part of their cybersecurity programs and expands the definition of personal identification information (PII), she said.

Unlike the California law, which does not cover disclosure, the New York statute covers the reporting of breaches to the attorney general and the state police. It also covers the implementation of security programs and the need to put one or more employees in charge of them.

Coping with GDPR

Earlier on Monday, James MacKay, Deputy CISO and Data Protection Officer at insurance carrier Markel Corp., related his company’s experiences with GDPR before and after the law took effect. Four days after the law took effect, he got a call about a possible violation, he said.

Going to sessionsDocuments were mistakenly sent to two lawyers that were intended for the other, which could have been a problem because of the information they contained. Fortunately neither recipient opened the documents and the situation was resolved.

Then someone in the U.S. operations left the organization and emailed the full company phone directory to their personal address. Since the directory contained no email addresses, no violation occurred. Another incident involved an email sent to a recipient who threatened to complain to regulators because it didn’t have an opt-out link. The recipient follow through, so another issue was averted.

The incidents showed MacKay the company needed better data protection policies and procedures. This included making him Markel’s data protection officer, a position the company didn’t have before, and creating a framework for data protection. The framework covers privacy controls and procedures for communicating about data protection to the Markel board.

Part of the challenge was to establish a clear understanding of what data is used when a company launches a new service or application, and where the data comes from. Because the Markel operates in 17 countries, the framework has to be standardized across its global operations. “We are not fully there yet. We are still working on it but that’s our intention,” he said.

Markel also decided to educate all employees on GDPR and how it affects them. In addition, he has regular conversations about data protection with the CEO. Lastly, MacKay said, Markel has a process for reporting data privacy incidents, should one ever happen. “We have a defined process for reporting to the regulator, and we practice it. It’s something we feel it’s important and it’s something we feel we have to get right across all of our different regions.”

The post Privacy Regulations: More Work for Cyber Professionals appeared first on Cybersecurity Insiders.


October 30, 2019 at 09:08AM

Security Expert: AI Not Ready for Cybersecurity

Breakout session2While artificial intelligence (AI) has gotten a lot of attention in recent years as a possible solution for cybersecurity issues, Winn Schwartau argues there’s a long way to go before we can trust AI and its siblings, machine learning (ML) and deep learning (DL), to deliver the results we need.

During a presentation on the ethical bias of AI-based systems at the (ISC)2 Security Congress 2019, Schwartau said significant problems with AI need to be overcome before we can fully trust it with something as important as cybersecurity. Schwartau, a top expert on security and privacy, is the Chief Visionary Officer at The Security Awareness Company.

During a mid afternoon session at Security Congress, taking place this week in Orlando, Schwartau walked through the yet-unresolved, inherent problems with AI. For one thing, he pointed out, AI relies on probability, which creates some level of uncertainty about the results it delivers. The same algorithm might give different results when asked to resolve the same problem.

“AI is not deterministic. AI will not give you the answer under any circumstances whatsoever regardless of what your vendor of choice tells you,” Schwartau said. Using medicine as an example, Schwartau said he would “absolutely not” recommend that a doctor accept an AI-based diagnosis, though it might be helpful in deciding a course of action.

Another problem with AI comes down to a question of ethics. Schwartau used the classic ethics “trolley problem” to make his point. In this ethics conundrum, someone is asked to choose between killing one person or five when a trolley cannot be stopped. If the trolley stays on course, it will kill the five, but if a track switch is thrown to divert the trolley to another track, one person dies.

Leaving that solution to be solved by AI is problematic, he said. It would require allowing the AI engine to make a value judgment based on the information it has been fed over time. And there’s no guarantee the engine would make the right decision. There actually is no right – or perfectly acceptable – answer because one way or another in this theoretical conundrum, someone would die.

Schwartau also talked about the biases inherent in data that is fed to AI algorithms. He referred to the Microsoft Twitter bot experiment that quickly went awry when the bot was manipulated to make racist, xenophobic and sexist comments. Similar results could occur even without malice, Schwartau argued, because the humans feeding data into the AI systems may have biases they don’t even recognize.

An example of unintended bias involves experiments with using AI to hand out criminal sentences. Because the AI systems use historical crime sentencing data, and are looking at statistical correlations instead of causation, their recommendations for sentencing have been largely biased and inclined to send a disproportionate number of non-white people to jail.

Based on these issues, Schwartau expressed serious doubts about the prospect of AI solving cybersecurity issues. While he concedes that data scientists might solve issues of bias and other problems with data, it may ultimately be impossible to get AI algorithms to become truly neutral in their output.

The post Security Expert: AI Not Ready for Cybersecurity appeared first on Cybersecurity Insiders.


October 30, 2019 at 09:08AM

New payment revolution lets consumers manage ecommerce transactions from their mobile banking app

For many of us it would be practically impossible to count all of the times we’ve had to provide credit card details to online retailers. There are millions of ‘digital footprints’ of financial records across the internet, making it an arduous – likely impossible – task to find out which retailers have kept these details on file, whether that card is still in use or whether they are sitting on long-expired card details.

Imagine a future – that’s nearer than you think – where you open your mobile banking app, and in addition to all the services you already know and use, you can find a list of all the web sites where you enrolled your card(s). Imagine that for each of those retailers, you could suspend or de-activate your card or set individual monthly spending limits for each of them.

Sounds wonderful to have? The good news is that your bank, thanks to Gemalto, as a certified VTS/MDES partner for EMV tokenization, is about to bring it to you.

This is a digital payment revolution. It started five years ago with the emergence of digital wallets. EMV Tokenization is the technology behind the scenes that lets you enroll your EMV cards into wallets for mobile payment, in-app payments or in-web payments, for smartphones and wearables. This is already a massive success in the world but still has huge growth potential. Now that these digital cards have expanded to eCommerce, EMV tokens are set to replace real card data on the merchant site used at checkout.

By replacing your card with a token for your online payments, your Bank will manage the token’s life cycle. The VISA and MasterCard tokenization platform is essentially the engine room that helps to deploy these new services and drive this powerful functionality. We are helping banks to deploy this innovative customer journey through the use of its Cloud Based Developer Portal, allowing suppliers to stay up to speed with EMV token life cycle management features, by providing sample codes, testing and tracking its deployments.

On top of this up-to-date list of retailers, EMV Tokens also take care of card expiration dates automatically so you’ll never worry again about keeping your subscription accounts up to date.

Tokens also protect you from rejected payments caused by false-positive declined transactions. This can occur even if you enter your card data correctly, simply because the merchant risk management software evaluates you, you card or the transaction as risky and denies it, leading to user frustration. This is more common than you’d expect with one out of every four generation Y customers affected at least once in the last 12 months.

False-positives can hurt retailers beyond the initial lost sale. According to The Paypers it also damages the merchant’s reputation and ultimately the customer relationship.

This technology is helping to enable new services and convenience, as well as new services. Stay tuned, your bank is about to put you back in control of your online transactions, with a little help from Gemalto.

The post New payment revolution lets consumers manage ecommerce transactions from their mobile banking app appeared first on Cybersecurity Insiders.


October 29, 2019 at 09:09PM

Three developments helping to increase trust in the commercial drone ecosystem

In recent years, vast leaps forward in drone technology have helped to confirm their practical application in a variety of different environments. In times of natural disasters, such as avalanches for example, drones have help saved the lives of people buried under the snow, by scanning large mountainous areas quicker than a person on foot. What’s more, in point-to-point delivery services the speed of drones is also revolutionizing the way we transport time-sensitive goods, such as blood, to hospitals in need.

But despite their potential, there remain questions surrounding the security of commercial drones and how they would work together to deliver our goods as part of a ‘commercial drone ecosystem’. Additionally, headlines continue to highlight the security risks that accompany drone flights, including stories of mid-air collisions with commercial flights and the ease of which drones can be hacked from the ground.

With an increasing number of drones communicating both with each other and devices on the ground, it is imperative that the ‘Internet of Skies’ is safe enough for the projected wide scale network of drones it will support.

  1. Identifying pilots and Drones using Trusted Remote ID

One of the key elements that will help to engender trust in the drone ecosystem is making sure that a drone’s pilot and the drone’s own unique identity can always be identified using a Trusted Remote ID. In practice, this works the same way your cars license plate links your car to you.

By using our DroneConnect solution, identifying a drone and their pilot becomes incredibly secure and seamless. Here, biometric processes, including facial recognition and liveness detection, are gathered from the specific pilot, and then linked to their drone. This information is then kept on file by a public authority so that it can be checked against their servers before every flight, to make sure each drone is linked to its legitimate pilot. If a drone is found to be flying in an unsafe manner it can also be quickly linked to who is at its helm, so that authorities can take swift action.

Fully integrating drones into a trusted ecosystem also requires that any Unmanned Aerial Vehicle (UAV) can itself be identified and tracked – even without having to know who its pilot is. One way to do this is to place a tamper-proof box inside the drone. This box securely stores each drone’s unique digital ID, pilot and mission information, meaning it can be identified at any point in its journey, and can be monitored to ensure it is on the correct course. In addition, as the data from the digital ID is encrypted, it also protects the drone against various forms of data manipulation, such as a man-in-the-middle attack.

Directly linking drones to their pilots and giving them their own highly secure digital identities, should demonstrate to consumers that, with this technology, it will become much easier to identify people flying drones irresponsibly. Hopefully, this will reassure them that just because there are more drones in the sky, with the creation of an ecosystem, it does not mean that we won’t know exactly who these belong to and their flight paths.

  1. Seamless and Secure Connectivity

For easy worldwide deployment, drone manufacturers need their drones to connect seamlessly, securely and dependably to a variety of networks in countries across the world. Parallel to this, for consumers to put trust in the ecosystem, they will need their goods to be delivered reliably and to be sure that drones cannot be hacked, and their packages be stolen.

It is therefore key that drones cannot simply disappear off the grid. It must always be possible to pinpoint a drone’s exact location so it can be accounted for.

To ensure this is the case, technology inside the drone must secure a connection to a wireless network when the drone is flying both shorter distances (less than five miles) at lower altitudes, as well as via the Global System for Mobile Communications (GSM) for drones partaking in longer journeys.

Part of this involves making sure that any wireless networks a drone uses over short distance flights is not susceptible to being hacked, and that any data sent over the network is encrypted to reduce the security risk that it can be modified.

However, it is also essential that in both cases the drone could connect to unmanned traffic management (UTM) platforms, which would receive flight plan updates, and could command any additional data needed for before a flight. For example, before the drone could take off, its mission and flight path would have to be approved based on the fact its path did not cross a no-fly zone. Once in the air, real-time tracking would be used to monitor its route (using an IoT module inside the drone that automatically sends identity and location data) and make sure it is on the correct path. In this way, UTM platforms will allow regulations to be implemented and enable safe and secure flights.

However, at present, GSM connectivity is not 100% available at every location. It therefore remains essential that drones using GSM connectivity have a backup solution for the network they run on, such as satellite communication for beyond visual line of sight flights, or Wi-Fi for short flights.

Additionally, by the same logic, swapping from one network to another (in order to achieve the best coverage possible) must also be entirely secure and, must also be smooth process for drone operators. Therefore, to garner trust and reliability in the drone ecosystem, both for producers transporting goods, and for consumers receiving them, connectivity is key.

  1. Confidential data storage and exchange

The final pillar that would bolster trust in this ecosystem centers around the protection of confidential information that must be kept private. Take, for instance, public-safety-related information collected and processed during rescue operations – this clearly cannot be freely shared and could cause harm to the general public if it were to be intercepted by a third party. On a more personal level, imagine that a commercial drone carrying a package addressed to you was intercepted. The hacker would then have access to sensitive information, such as your place of residence and other credentials.

To make sure this cannot happen, it is crucial that data encryption mechanisms are mobilized properly. This involves making sure that legitimate data will only be shared with people and applications that hold the proper key to decrypt it, and that every point where a malicious actor could take advantage is well protected.

For example, despite the GSM network being securely encrypted, when data leaves this network and is sent to the cloud, there remains a potential gap that could be exploited by a cyber-attacker. It is therefore imperative that an end-to-end Transport Layer Security (TLS) protocol is applied, as this guarantees that the data is safe and secure from the drone all the way through to the UTM.

Finally, it is also essential that consumers fully understand what happens with their drone’s flight data after its flight, as all flight data will need to be safely stored and protected for any investigations, or for traceability purposes. To ensure that consumers can trust their data is being stored correctly, and at the highest possible standard, sensitive data needs to be collected on secure servers in the cloud and an advanced encryption mechanism must be mandatory in order to access it. This way, it very clear to the public that only authorized parties will be able to view and use this information, if they need to for the sake of an inquiry.

This new, connected world is bringing lots of advantages in day-to-day life, but it’s also bringing challenges in terms of data privacy and cyber-security. To build trust in this ecosystem, security-by-design must be the priority at every stage of the drone lifecycle – from making sure it is built into its hardware at the point of creation and at every point after until the final platform.

To unlock the potential of the skies, trust is essential. It is clear that we’ll need smart, digital and autonomous systems that are able to co-ordinate the complex web of users and flightpaths, while at the same time maintaining the incredible safety levels expected for our aircraft and airspaces.

Reducing the instances where drones are compromised or cannot be traced to an owner to hold them accountable is an essential step towards proving that an entire drone ecosystem can be safe. Only once governments, citizens and companies trust that drones are reliable and safe can companies begin to create a network of drones that fly beyond the visual line of sight.

The post Three developments helping to increase trust in the commercial drone ecosystem appeared first on Cybersecurity Insiders.


October 29, 2019 at 09:09PM

Apple issues Mobile Security warning to old iPhone and old iPad users

Apple Inc has issued a mobile security warning to owners of old iPhones and Old iPads saying their devices will be prone to vulnerabilities such as failing to connect to the internet and can easily be intercepted by hackers after this weekend.

Technically speaking, the iPhone giant has issued a warning that all its old iPhone devices are prone to GPS Clock reset in April next year, after which the devices will lose track of time. And this is reported to happen every 19.5 years.

So, iPhone and iPad users are being requested to update their software by November 3rd, 2019 i.e by Sunday this week, so that they can operate their devices without any issues after April next year.

Thus, all users of the iPhone 5, 4, 4S, iPad 2, Retina Display and 4th Generation iPads are being requested to update their software by 12 am of the said date.

And FYI for those who are not showing interest in updating their software, there is a high probability that your safari browser, email, app store, iCloud, and Maps will go offline after the said deadline.

As the Bugfix is automatically applied to Apple Software versions such as iOS 10.3.4 and 9.3. and later, those devices which are running on the said the preceding iOS versions need not worry.

BTW, all old iPhone 5s users have/will already/will receive a pop up stating to update their software with the latest security fix. Others, that is those operating their phones on older versions should get the update done on a manual note.

The post Apple issues Mobile Security warning to old iPhone and old iPad users appeared first on Cybersecurity Insiders.


October 29, 2019 at 08:50PM

Monday, October 28, 2019

Microsoft previews Azure Sphere with Cloud Security controls

Microsoft has announced the release date of its Azure Sphere which happens to be February 9th of 2020. The Linux based chip which was earlier named ‘Project Sopris’ by the tech giant was previewed to the world yesterday at the IoT Solutions World Congress.

 

Microsoft Azure Sphere is a Linux based silicon wafer that can be used to power internet-connected devices. Operating with a MediaTek MT3620 processor and an Azure Sphere OS entailed with Linux Kernel, the architecture is ambled to provide authentication, threat response and info related to on-device resources and application failure.

 

In the coming days, Azure Sphere will also be enriched with artificial intelligence, graphics, and richer UI experiences.

 

As of now, those who got an opportunity to have hands-on the chip are testing it by integrating it into consumer appliances meant for retail and manufacturing equipment.

 

Even the news is out that Azure Sphere is being used in mission-critical appliances such as “Guardian Modules” for securely connecting the devices to the internet.

 

At the same conference, Microsoft took an opportunity to introduce Azure RTOS which will be offered as a complimentary to Sphere.

 

In the coming days, the American software giant is also thinking to revamp its Azure IoT Hub with several features and that includes Azure Time Insights, a multi-layered flexible cold storage and rich analytical skills with improved scale and performance.

 

Note- MediaTek MT3620 chips were developed to support high-level security in modern connected appliances and are being used in smart homes, commercial, industrial and many other domains.

The post Microsoft previews Azure Sphere with Cloud Security controls appeared first on Cybersecurity Insiders.


October 29, 2019 at 10:17AM