background preloader

Computer Security

Facebook Twitter

Hackers break into Subaru Outback via text message. Microsoft patent allows for web-based spying technology (Updated) A recently revealed Microsoft patent could create wiretaps for several kinds of Internet communications, including video and voice calls over Skype, which Microsoft acquired in May. Federal law enforcement agencies have had difficulties tracking and recording criminal and terrorist conversations online. Back in September, it was reported that law enforcement officials wanted to expand the government’s powers to wiretap Internet services. Microsoft’s new technology could help make this a reality. The spying technology, called “Legal Intercept,” would allow currently existing products to be modified to “cause the communication to be established via a path that includes a recording agent,” according to the filing with the U.S. Patent and Trademark Office. Once a connection is established, the agent is able to “silently record” a conversation.

The filing specifically calls out the ability to record any kind of voice-over-Internet-protocol (VoIP) communications. There's a Botnet Called TDL-4 That's Virtually Indestructable. Here’s How U.S. Spies Will Find You Through Your Pics.

Mobile Phone

Researcher sees security issue with wireless insulin pumps, hackers could cause lethal doses. LulzSec Shuts Down, Ends Hacking Campaign. LulzSec, the hacker group that has hacked the CIA, U.S. Senate, Nintendo, Sony and others, has surprisingly announced that it is disbanding. LulzSec, short for Lulz Security, claims that it intended to only operate for 50 days as an attempt to revive the AntiSec movement, which is opposed to the computer security industry. "For the past 50 days we've been disrupting and exposing corporations, governments, often the general population itself, and quite possibly everything in between, just because we could," the hacker group said in its announcement.

"All to selflessly entertain others - vanity, fame, recognition, all of these things are shadowed by our desire for that which we all love. " The release continues on, explaining that the organization is not tied to its LulzSec identity and has succeeded in bringing back the AntiSec movement. As its final parting gift, the group released one last data dump with data allegedly taken from AT&T, AOL, Disney, Universal, EMI and the FBI. WhiteHat Security hacks into Chrome OS, exposes extension vulnerability at Black Hat. Researchers Discover How To Use Square for Credit Card Fraud. Researchers attending the Black Hat security conference on Thursday demonstrated two ways in which Square — a mobile gadget that enables Android, iPhone, iPad and iPod touch users to accept credit card payments — can be hacked to accept stolen credit card data, with very little technical hardware required and "no technical skills at all.

" Adam Laurie and Zac Franken, directors of Aperture Labs, discovered that due to a lack of encryption in the current Square app and free dongle for swiping cards, the mobile payment system can be used to steal credit card information, without even having the physical credit card. Square works by converting credit card data into an audio file that is then transmitted to the credit card issuer for authorization.

In order to bypass the need to swipe a card, Laurie wrote a simple program — in fewer than 100 lines of code — that enables him and Franken to feed magnetic strip data from stolen cards into a microphone and convert that data into an audio file.