sMobile ? "width=device-width,initial-scale=1.0,minimum-scale=1.0,maximum-scale=1.0" : "width=1100"' name='viewport'/> android xda: online security
Showing posts with label online security. Show all posts
Showing posts with label online security. Show all posts

Thursday, 11 August 2016

Hackers Breach the Ultra-Secure Messaging App Telegram in Iran

Telegram

Telegram Accounts Hacked – Susceptibility of SMS Text Message


According to Reuters, over a dozen Iranian Telegram accounts, like the messaging app having a focus on security have been compromised in the last year due to the susceptibility of an SMS text message.They have recognized around 15 million Iranian users’ phone numbers, which seems to be the biggest known breach of the encrypted communication systems as informed by cyber researchers to Reuters.

 According to independent cyber researcher Collin Anderson and Amnesty International technologist Claudio Guarnieri, studying Iranian hacking groups for three years has informed that the attack which had occurred this year, had not been reported earlier, has endangered the communication of activists, journalist together with several others in sensitive positions in Iran, where Telegram is said to be utilised by around 20 million users.

Telegram tends to endorses itself as an ultra-secure instant messaging system since all the data is encrypted from beginning to end which is known as end-to-end encryption. Various other messaging services comprising of Facebook Inc., WhatsApp state that they have the same proficiencies. Telegram, which is headquartered inBerlin, states that it has 100 million active subscribers and is extensively usedin Middle East, inclusive ofthe Islamic State militant group and in Central and Southeast Asia as well as Latin America.

Authorization Code –Diverted by Phone Company/Shared with Hackers


According to Anderson and Guarnieri, the susceptibility of Telegram is in its use of SMS text messages in activating new devices. When a user tends to log on to Telegram from a new phone, the company directs them with an authorization code through SMS which can be diverted by the phone company and shared with the hackers, according to the researchers.

Equipped with the codes, the hackers can now add new devices to the Telegram account of the user enabling them to read chat histories together with the new messages. Anderson had informed during an interview that they had over a dozen cases where Telegram accounts have been negotiated through ways that sound like fundamentally coordinated with the cellphone company.

According to the researchers, Telegram’s dependence on SMS verification tends to make it defenceless in any country where the cellphone companies are possessed or profoundly influenced by the government.

Iranian Hacking Group – Rocket Kitten


Telegram spokesman stated that customers could defend against these attacks by not relying on the verification of SMS. Telegram enables though it is not essential that customers create passwords which could be reset with the so-called recovery emails.

The spokesman, Markus Ra has informed that if one has a strong Telegram password and the recovery email is secure, the attackers can do nothing about it. The researchers believe that the Iranian hacking group Rocket Kitten is responsible for the Telegram breaches based on resemblances to the setup of past phishing attacks credited to the group.

There is a prevalent rumour that Rocket Kitten tends to have ties to the Iranian government. John Hultquist, managing the cyber espionage intelligence team at the security firm FireEye, of Rocket Kitten has informed that `their focus generally revolves around those with an interest in Iran and defense issues however their action is completely global. With regards to Telegram attacks, it has also been suggested by the researchers that SMS messages could have been conceded by Iranian cell phone companies, which is an industry that has prospective links with the government

Sunday, 24 July 2016

How to Stay Anonymous Online

Anonymous Online
Credit:MIT News

New Privacy Pattern – Strong Security Guarantees


Privacy networks tend to guard individuals living under exploitive regimes from scrutiny of the Internet usage. However from recent discovery of susceptibilities in most of the well-known networks, Tor has urged computer scientists in endeavouring to come up with more secured privacy patterns. In July, at the Privacy Enhancing Technologies Symposium, scientists at MIT’s Computer Science and Artificial Intelligence Laboratory and the Ecole Polytechnique Federal de Lausanne will be presenting a new privacy pattern which would offer strong security guarantees though will use bandwidth more efficiently than its ancestors.

In tests, the systems of the researchers needed only one-tenth as much time just like secure experimental systems in transferring a large file between unidentified users. Albert Kwon, a graduate scholar in electrical engineering and computer science and first author on the new paper, said that the initial use case that they thought of was to do anonymous file-sharing where the receiving end and sending end do not know each other.

The reason was that things like honeypotting, where spies tend to offer services through an anonymity network in order to entrap its users, are a real issue. However they have also studied applications in microblogging, something like Twitter, where one would want to secretly broadcast your messages to everyone.

Heart of System – Sequence of Servers - Mixnet


The system invented by Kwon and his co-authors, his advisor, Srini Devadas, the Edwin Sibley Webster Professor of Electrical Engineering and Computer Science at MIT, David Lazar, a graduate student too in electrical engineering and computer science together with Bryan Ford SM `02 PhD’08, an associate professor of computer and communication sciences at Ecole Polytechnique Federale de Lausanneworks on many prevailing cryptographic techniques though connects them in a novel way.

The heart of the system is a sequence of servers called a mixnet wherein each server tends permutes the order where it receives messages before it is passed on to the next. If messages from Sender Alice, Bob and Carol tend to reach the first server in the order A, B, C that server would send them to the second server in an altered order like C, B, A. The second server would permute them before sending them to the third and so on. The message that had been tracked from the point of origin, by an opponent would not know which was which by the time they had exited from the latest server

The New System – Riffle


It is this reshuffling of the messages which is said to be named – Riffle, for the new system. Similar to several privacy systems, Riffle tends to also use a technique known as onion encryption – Tor, in which case is an abbreviation for `the onion router’.

In the case of onion encryption, the sending computer tends to wrap each message in many films of encryption utilising a public key encryption system such as those that tend to protect most of the online financial transactions. Each of the servers in the mixnet seems to remove only one layer of encryption so that last server only knows the final destination of the message.

To prevent message tampering, Riffle tends to use a system known as verifiable shuffle. Due to the onion encryption, the messages which each server seems to forwards do not look like the one it received, it has peeled off a layer of encryption. However the encryption could be done in a way which the server would generate a mathematical proof which the messages it sends seems valid operations of the ones receiving it.

Wednesday, 4 May 2016

Hackers Steal Millions of Minecraft Passwords

Minecraft

Minecraft Passwords Stolen by Hackers


Login data of more than seven million members of the Minecraft site Lifeboat has been stolen by hackers. Lifeboat is a service for determined servers and customized multiplayer games for Minecraft Pocket Edition and this data breach tends to affect customers who seem to use the service. If one has used Minecraft Pocket Edition without signing up for Lifeboat, it is ok but if one used Lifeboat, they would possibly get a message compelling them to change the password for the site in early 2015 which was because the company was aware about the hack, though it had not made the information public till recently. Lifeboat permits members to run servers for customised, multiplayer maps for smartphone edition of Minecraft.

There is confirmation that the information that is stolen comprising of email addresses and passwords is provided on site that trade in hacked data. Investigation recommends that passwords were weakly protected and hence attackers could work them out with ease. Evidence regarding the breach had been passed to Tony Hunt, independent security expert, who stated that he had received the list from someone who tends to trade in stolen identifications. Most of the people had informed him that the data had been circulating on dark net sites.

Passwords for Lifeboat Hashed – Little Security


Mr Hunt had mentioned that the data had been stolen in early 2016 though the breach had only been known, now. He said that passwords for Lifeboat accounts were hashed though the procedure utilised provided little security. Hashing is said to be a technique utilised to scramble passwords in order that they are not easily read if the data tends to get stolen or lost. According to Mr Hunt, usually a Google search for hashed password would practically provide it in an accurate plain text and people familiar in cracking tools could possibly computerize and accelerate this procedure.

He further stated that a Google search for a hashed password could quickly return the correct plain text value and well known cracking tools could automate as well as speed up this procedure. He had mentioned in a blogpost regarding the breach that a large percentage of those passwords would be reverted to plain text in a short time. He also informed that this often tends to lead to other security problems since several people re-use passwords and find out one which could lead attackers to compromise accounts on other sites. Lifeboat, in a statement provided to Motherboard, had stated that it had taken action in limiting the damage.

How to Minimise Damage to Users


It informed the news site that when this occurred in early January, they figured the best thing for their players was to quietly force password resets without letting the hackers know they had limited time to act, adding that it now used stronger hashing procedures. It also mentioned that they had not received any reports of anyone being damaged by this. Mr Hunthad been critical of the company for `quietly’ compelling the password re-set stating this policy had left him speechless.

As an alternative, he said that Lifeboat should have done more in alerting users so that they could change passwords rapidly if they used the same one on other sites. He said that the first thing which should be a priority with any company after an incident like this is `How to minimise the damage to the users’.