FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Thursday, October 1, 2020

Using technology to provide a unique legal identity for nations and citizens

Having an identity permits inclusion in all aspects of society, especially as we become more and more connected globally. Relationships in the past were localised, meaning that we did business with people we knew and didn’t need to ask them for their ID to prove who they are. As society becomes decentralised and many transactions are completed online or electronically, the need to prove who you are becomes essential.

Legal identity is a basic human right. It acts as the gateway to social and economic inclusion, enabling access to essential services such as healthcare, education, financial aid, the right to vote and cross-border travel. However, according to the United Nations, over 1.1 billion people across the world today do not have a legal identity, meaning that they do not legally exist.

While nations have a duty to provide and protect each citizen’s legal identity, this has proven difficult to achieve in certain countries due to monetary costs, lack of capable birth regulation systems and other factors. Thankfully, new digital technologies can offer game-changing solutions for governments and citizens alike.

Why digital identities?

Technologies can assign everyone a legal digital identity in a simple, fast and secure manner. Thanks to secure communication technologies, digital identities enable the development of services with which every individual can access their rights that are attached to their unique identity. A digital identity simplifies information sharing, while access rights are differentiated and secure. This unlocks a range of solutions that can benefit a nation’s citizens, as well as organisations and businesses.

Key principles of legal digital identity

Digital identities need to meet three stringent requirements – to be inclusive, efficient and secure; in order to guarantee an individual’s legal identity. Only by following these key principles would they fulfil their intended role.

  • Inclusivity: Digital identity must be accessible to all, without discrimination, and using technologies that are adapted to the specific environment and existing infrastructure.
  • Efficiency: Digital identity needs to be secure, efficient, affordable and sustainable. It must rely on open standards and guarantee interoperability with different existing technologies, helping to provide governments with a choice in terms of equipment, and compatibility with their infrastructure.
  • Security: Digital identity must guarantee confidentiality of the data collected and be part of a legal framework of trust. Governments who deploy digital identity solutions must ensure the security of the identity verification solutions they provide to the private sector.

Benefits of legal digital identity

Introducing digital legal identities as a form of identification can provide numerous benefits for citizens, governments and the private sector. For citizens, having a digital legal identity means that they would be allowed access to social services, state financial aid and to services offered by private entities.

Digital identities provide governments with a complete view of their population, allowing them to govern from economic and social standpoints and to fight fraud and corruption. Furthermore, deploying a digital identification system provides them with the opportunity to offer services to private entities and to partly delegate the solution to the private sector.

It also provides the infrastructure for digital transactions, guaranteed by law and the judicial system, providing many advantages for private sector companies such as the ability to offer online services without the responsibility of verifying identity.

The role of biometrics in enabling legal digital identities

Biometrics make it possible to securely identify an individual, using universal characteristics that are unique for each individual, invariable, measurable and recordable. Different morphological, biological and behavioural characteristics can be used to ensure a seamless and secure identification. Today, fingerprint and facial recognition have become the most widespread form of biometric verification, globally used for air transport, ID documents and even for authorising financial transactions.

Biometrics is particularly relevant in developing countries, where some are starting identity programmes from scratch, where IDs are not yet standardised or birth registration is lacking. Once identity has been quickly established through biometric data capture, individuals have a simple and clear method of establishing or re-establishing their identity throughout their lives whenever needed.

Up until now, population identification was an international priority in terms of economic and social inclusion as well as countries’ development. COVID-19 crisis has greatly emphasised the need to accelerate the deployment of a unique digital identity systems as this would allow countries to plan and monitor the distribution of social benefits to the most vulnerable in society, to accelerate the distribution of financial aid to those in need and to ensure economic recovery in case of recurrence of such crisis.

The post Using technology to provide a unique legal identity for nations and citizens appeared first on Cybersecurity Insiders.


October 01, 2020 at 09:10PM

Instantaneous EMV card issuance translates into a higher activation yield for payment card issuers

Most EMV cards issued today reach their cardholders several days after the user completes their application. Cards get delivered via postal mail and a second mail provides the PIN code information, sometimes one or two additional days later.

Although this is a very familiar user experience for most cardholders, this method of card issuance typically means a tremendous loss of opportunities for financial services firms and can be highly inconvenient for the cardholder for four key reasons – which we’ll detail below. These challenges help to underline why the deployment of instant card issuance as the mainstream card issuance solution is an incredibly important development for Financial Institutions.

Loss of activation yield for the issuer

Cardholders can change their mind in just a matter of two or three days. A potential customer can complete an application for a new card on Monday, then decide that this new card is unnecessary on Thursday when it arrives in the mail. It’s pretty much a fundamental rule in commerce: once the purchasing decision is made, close the deal immediately. If someone applies for a new card on Monday and gets it right away, the chances they will run away are much lower and the overall activation yield is greater for the issuers. US data from Aite Group reveals that there’s up to a 32% greater activation rate thanks to instant card issuance.

Loss of transactions for the issuer

When it takes seven days or more for a card to reach a cardholder, that’s seven days without shopping using that card. If we multiply this by, say, 1000 new customers for the bank in any given year, that’s 7000 shopping days that are lost. Instant Card issuance not only gains those days back, but it also increases the chance for the newly issued card to become top of the wallet. According to Aite Group for the US market, what this means is that cards that go through the instant issuance channel generate ten more transactions in the first 30 days compared with usual postal mail issued cards.

Reduced waiting time and customer satisfaction

As we move further into the digital age, the chances that people are willing to wait for a service are getting smaller and smaller. When was the last time anyone enjoyed waiting for a service? Getting a new card right away increases chances that the card will be used by the cardholder and will clearly generate more satisfaction, which in turn means a more pleasant user experience. The same can be said for when a PIN is delivered via the Bank mobile app which provides an all-round real customer-centric digital experience. With cards clearly adopting a more digital-first model, it’s about time that financial services firms follow suit.

Higher application rates due to opportunistic sales

EMV cards can be instantaneously issued at the bank’s branch, but also anywhere secure kiosks can be located – such as a shopping mall. Consumers can be motivated to spend by the desire and opportunity to purchase what they want. If consumers can see the benefit of signing up to a new card in that immediate context, the chances that they will apply for that new card are higher. The bottom line is that by making instant issuance available, at the right place and time associated with shopping desires, it can really help to boost applications.

More cards issued, higher customer satisfaction, more opportunistic applications and, ultimately, more transactions are among the many reasons why we believe EMV instant card issuance is the future mainstream delivery experience. Find out how to make it happen here.

The post Instantaneous EMV card issuance translates into a higher activation yield for payment card issuers appeared first on Cybersecurity Insiders.


October 01, 2020 at 09:10PM

Watch Communications Acquires WCOIL ISP in Lima, OH

LIMA, Ohio–(BUSINESS WIRE)–Watch Communications announced today that it has acquired West Central Ohio Internet Link (WCOIL), a Lima, OH based company providing broadband and related services. This acquisition expands the company’s operation in central Ohio and furthers its commitment to providing high-quality solutions to rural Americans.

“We are excited to welcome WCOIL employees and customers into the Watch Communications family,” said Watch Communications President and CEO Chris Daniels. “We will build on the strong foundation of value-added services WCOIL has established in the Lima region and use that to expand offerings to all of our customers. The WCOIL team exemplifies our mission to deliver an excellent customer experience based on high-quality and reliable broadband and excellent customer service. We look forward to adding their expertise to our operation.”

WCOIL started in 1995 in the basement of Mike and Barb O’Connor, who provided Internet service through modems mounted to their basement walls. Over the years, they have built-out the company to more than 2,000 customers. WCOIL, through its founders’ entrepreneurial spirit, offers its customers traditional Internet services, business telephone service, managed IT services, business and residential security and fire systems, cybersecurity, and other technology services.

Mike O’Connor will join Watch to lead a new Services Division that will build out residential and enterprise services portfolios that include the above solutions that will eventually be offered to Watch’s entire customer base.

“We look forward to expanding the services of WCOIL to the entire Watch customer base and realizing the synergies of merging the two organizations,” O’Connor said.

Watch Communications has recently acquired Beyond Media Networks, an Illinois-based wireless internet service provider for eastern Illinois and western Indiana; Sit-CO, a fiber and fixed-wireless broadband solutions provider based in Evansville, Indiana; and Q Wireless, an Internet Service Provider in Kentucky that includes ConnectGRADD, Owensboro Online, QKY, and Community Connect.

Watch Communications partners with Microsoft Airband to leverage multiple technologies to deliver broadband solutions to areas of Kentucky, Illinois, Indiana, and Ohio that are unserved or underserved.

About Watch Communications

Founded in 1992, Watch Communications is an Internet Service Provider (ISP) using a combination of fixed wireless and fiber technologies to serve residential and business customers throughout Ohio, Indiana, Illinois, Kentucky. Watch Communications began as a wireless cable TV provider and expanded service offerings in 1998 to include the Internet. Since its creation, Watch Communications has focused on unserved and underserved small and rural markets. Watch Communications is a subsidiary of Benton Ridge Telephone. The Benton Ridge family of companies also includes Community Fiber Solutions in Indiana and Q Wireless in Kentucky and Indiana.

The post Watch Communications Acquires WCOIL ISP in Lima, OH appeared first on Cybersecurity Insiders.


October 01, 2020 at 09:09PM

Cyber Attack on International Maritime Organization IMO

After disrupting the services of France-based CMA CGM, hackers reportedly targeted London based IMO aka International Maritime Organization, a federal organization that regulates shipping.

And because of the attack, the website of the company is down and not reachable.

The shipping related UN organization says that its internal systems and email services were restored back to normalcy after they were pushed to the database of Global Integrated Shipping Information System (GISS) and Virtual publication services and IMODOCS will be soon revived.

IMO has asked the IT staff of UN Council to probe down the incident and to identify the attack and enhance security of the systems.

What’s interesting about the attack is that it just occurred two days after a cybersecurity breach occurred on the database of CMA CGM.

Note 1- Although many media sources speculate that the attack on IMO was of ransomware variant, the shipping governing agency did not confirm it. A ransomware is a kind of malware that steals a portion of data and then encrypts a database until a ransom is paid.

Note 2- IMO is an organization that takes care of safety, environmental concerns, legal matters, technical cooperation, maritime security and works towards efficacy of shipping in international waters. It has over 174 member states and 3 associate members and an assembly that governs 5 committees- namely the Maritime Safety Committee, the Maritime Environment Protection Committee, the legal committee, the Technical Co-operation Committee and the Facilitation Committee.

The post Cyber Attack on International Maritime Organization IMO appeared first on Cybersecurity Insiders.


October 01, 2020 at 08:37PM

Wednesday, September 30, 2020

AI to prevent cyber attacks on Medical Devices

The year 2017 witnessed a global outage of computer systems because of WannaCry Ransomware attack. And it was believed that over 75,000 of medical systems operating for National Health Service (NHS) in England and Scotland were virtually shut down for several days for the North Korea propelled digital outage.

This includes cancellation of critical care appointments as most of the MRI Scanners, blood storage refrigerators, operational theatres and connected ventilators could not be operated under normal circumstances.

To counter such issues in near future, scientists at the Ben-Gurion University of the Negev (BGU) have developed an AI based solution that helps in defending medical devices against malware spread or other malicious cyber attacks.

Tom Mahler, a PHD student at BGU, is leading a team of experts who are working on an artificial intelligence based technique that helps in eliminating or reducing potential cyber threats occurring from digital attacks or other human errors.

BGU research claims an AI based surveillance to be implemented on the instructions taking place between a PC to the physical components. Crafted as dual layer architecture, the model can also be inducted into the existing medical devices, thus making them secure against most sophisticated cyber attacks.

Still, a lot of research and analysis has to be done on the AI architecture.

However, a synopsis was presented at the 2020 International Conference on Artificial Intelligence in Medicine (AIME 2020) on a recent note.

The post AI to prevent cyber attacks on Medical Devices appeared first on Cybersecurity Insiders.


October 01, 2020 at 10:34AM

Most Cloud platforms serving as breeding ground for Cryptomining Malware

According to a study taken up by Aqua Security, most of the cyber attacks seen on cloud servers are mostly related to cryptocurrency mining malware rather than other forms. The research that was taken in between June 2019 and July 2020 states that out of 16,378 attacks observed on cloud platforms, most of them were related to malware or decoys deployed in one form or the other.

Aqua Security 2020 Cloud Native Threat report says that the said form of attacks increased by 250% from the previous year and the development suggests that the attack landscape has moved its base towards organized crime, where cyber crooks are hired to launch attacks on CSPs.

The year 2019 witnessed most of the hackers seen deploying crypto mining malware on cloud containers and only a few were witnessed to be used for transferring data to remote servers or to launch other form of attacks like DDoS.

As there is an increased collaboration between threat actors, a surge in the frequency and sophistication of cyber attacks is been observed. For instance, threat actors are seen as multi-stage payloads and 64-bit encoding to avoid detection.

Unpatched systems, human configuration blunders, brute force attacks, easy guess passwords were seen offering hackers a strong chance to exploit cloud servers from the beginning of this year.

Note 1- Crypto jacking or Cryptocurrency mining malware- A malware that is used to mine cryptocurrency by deploying it on computer platforms fraudulently is called crypto currency mining or crypto mining malware. So, hackers are seen harnessing the processing power of many networked computers to generate revenue in bitcoins.

Note 2-According to a study made by AdGuard, over 500 million users are seen unknowingly mining crypto currencies on their computing devices such as tablets and smart phones.

The post Most Cloud platforms serving as breeding ground for Cryptomining Malware appeared first on Cybersecurity Insiders.


October 01, 2020 at 10:32AM

What is identity and why is it important?

What is identity? 

In 1793, French mathematician and philosopher, Nicolas de Condorcet laid the foundations of “social mathematics” by studying the relationship between the individual and the collective to formalise the foundations of the democratic system. He chose the mathematical term “identity” to represent the algebraic concept of equality among citizens in terms of their legal rights and obligations.

However, identity has also come to express the differences between us. Simply speaking, identity is a combination of your physical and behavioural traits that define who you are. For example, your name is part of your identity, as is the form and colour of your eyes and your fingerprint. This set of characteristics allows you to be definitively and uniquely recognisable.

Identity plays an important role in empowering individuals to exercise their rights and responsibilities fairly and equitably in a modern society. It is imperative for social, economic and digital inclusion as it provides access to basic human rights such as healthcare, pensions, social benefits, the ability to exercise our right to vote, and beyond. But to be able to access those rights, one needs to be able to prove that they are who they claim to be.

Usually official documents such as passports and identity cards are used as a proof of your name, and your photo on these documents is the most natural link to who you are.

Official identity as a proxy for inclusion

If a country’s citizens don’t have access to an official identity, they are much more likely to miss out on a variety of essential services, due to the fact that identity touches so many aspects of our lives. For citizens, identity provides them with access to state programs that support their wellbeing. As an example, Jamaica recently approved the use of biometric authentication systems to verify those citizens accessing social welfare benefits.

Yet an official identity system is also beneficial for governments. With more citizens registered they have a much better chance of accurately understanding their population’s demographics, which in turn plays an essential role in impactful policy making.

It is for these reasons that access to a legal identity has been recognised by the United Nations General Assembly as being a fundamental sustainable development goal – ensuring a legal identity from birth to all by 2030.

Nonetheless, getting a population registered is not an easy task and there are many barriers to reaching everyone – both due to physical geographical landscapes and a lack of infrastructure to support the collection of information. On the government side, the space tends to be a fragmented one, with multiple overlapping and incompatible systems being deployed at the same time. In general, there is a lack of coordination between civil registration and identity, and with other state systems that have their own registration and credential systems. Moreover, a proportion of the population is excluded because of excessive charges, indirect costs, and convoluted processes, or simply because they don’t have physical access to the service.

So how can we ensure the responsible adoption of official identity and the necessary protections around it which ensure that it is a tool for public good?

The role of foundational ID systems

Unique identity or foundational ID systems are general-purpose identity platforms that are designed to support all forms of identity. There are no multiple or redundant registrations, meaning that one registration is created for use with all state systems. Furthermore, foundational ID systems offer improved service delivery and economies of scale, and as identity becomes a readily available commodity, a new ecosystem of different applications naturally emerges. One such ID system is India’s Aadhaar, thanks to which nearly 80 percent of India’s citizens have access to critical government services.

Here’s how an individual’s identity is established:

  • The user’s unique biographical (name, date and place of birth, etc.) and biometric data (fingerprint) is captured
  • It is then validated to establish the uniqueness of the request for an accurate digital identity
  • This unique identity is then verified against existing data in internal or external systems
  • The biometric and biographical data is authenticated against physical documents
  • And finally, a unique identity is created in the foundational system, and a private unique identity number (UIN) is assigned to the person.

Achieving identity inclusion has become ever more urgent in the aftermath of the COVID-19 pandemic as public health and economic challenges are pressuring governments to deploy essential measures such as social safety nets, health, and labour programs that ensure the health & wellbeing of the population and help restart their economies. One important link for enabling these is that all measures require inclusive identification of the population.

My colleague Jaume Dubois, who is an identity system specialist at Thales, will join other experts in the field for the ID4Africa discussion to tackle the issue of identity and inclusion and share examples of policies, approaches and technologies that have proven successful. The discussion will take place on 16 September 2020 at 2:30pm CET on International Identity Day.

We invite you to learn more about the underpinning technology and processes for secure delivery of ID services.

 

The post What is identity and why is it important? appeared first on Cybersecurity Insiders.


October 01, 2020 at 09:09AM