Friday, May 16, 2008

"My password is stronger than your password!"

"Oh, yea... Prove it!"
...even strong passwords can be cracked in seconds using an open source tool called Ophcrack.


Ophcrack is an extremely fast password cracker because it uses a special algorithm called rainbow tables. Brute-force cracking tools typically try thousands of combinations of letters, numbers and special characters each second, but cracking a password by attempting every conceivable combination can take hours or days. (by Scott Sidel)

Labels: , , , , ,

Friday, May 9, 2008

She said the man in the gabardine suit was a spy

FB-I said "Be careful his bowtie is really a wi-fi"
Next time you flip open your laptop as you wait for a flight or work at a coffee shop, beware, says the Federal Bureau of Investigation. The person next to you may be stealing your personal bank account information, address book and other files from your computer.

The agency warned earlier this week that the information on your computers may not be protected when using some of the 68,000 Wi-Fi hot spots, or local wireless Internet connections, around the country.

"Odds are there's a hacker nearby, with his own laptop, attempting to 'eavesdrop' on your computer to obtain personal data that will provide access to your money or even to your company's sensitive information," the FBI said in a advisory on its Web site.

Think that's bad, the FBI goes further to warn that if a hacker hooks into your computer, you are also connecting to his computer. That means you could be unknowingly downloading viruses and worms.

Protect yourself:
• Update the security protection on your computer with current versions of operating systems, web browsers, firewalls and antivirus and anti-spyware software.
• When tapped into a Wi-Fi network, don't conduct financial transactions or use e- mail and instant messaging.
• Change the default setting on your laptop so you have to manually select the Wi-Fi network you connect to.
• Turn off your laptop's Wi-Fi capabilities when you're not using them. (more)
Clients... Ask us to demonstrate this during our next eavesdropping detection audit.

Labels: , , , , , , ,

Tuesday, May 6, 2008

Wi-Fi FBI Spy Cry

How do hackers grab your personal data out of thin air? Supervisory Special Agent Donna Peterson of our Cyber Division said one of the most common types of attack is this: a bogus but legitimate-looking Wi-Fi network with a strong signal is strategically set up in a known hot spot...and the hacker waits for nearby laptops to connect to it. At that point, your computer—and all your sensitive information, including user ID, passwords, credit card numbers, etc.—basically belongs to the hacker. The intruder can mine your computer for valuable data, direct you to phony webpages that look like ones you frequent, and record your every keystroke.

“Another thing to remember,” said Agent Peterson, “is that the connection between your laptop and the attacker's laptop runs both ways: while he's taking info from you, you may be unknowingly downloading viruses, worms, and other malware from him.

What can you do to protect yourself?
Agent’s Peterson’s best advice is, don’t connect to an unknown Wi-Fi network. But if you have to, there are some precautions you can take to decrease the threat:
• Make sure your laptop security is up to date, with current versions of your operating system, web browser, firewalls, and antivirus and anti-spyware software.
• Don't conduct financial transactions or use applications like e-mail and instant messaging.
Change the default setting on your laptop so you have to manually select the Wi-Fi network you’re connecting to.
• Turn off your laptop's Wi-Fi capabilities when you're not using them.
(more) (How to Protect Your Computer)

Labels: , , , ,

Who's Watching You at Work?

"Surveillance is now routine business practice among American employers, both large and small, as the cost and ease of introducing have dropped. You leave your rights at the office door every day you go to work. Most surveillance is conducted without any individualized suspicion, and personal as well as business-related information is routinely collected," explained Jeremy Gruber, legal director at the National Workrights Institute.

Two-thirds of the companies included in the "2007 Electronic Monitoring & Surveillance Survey" said they monitor Internet connections. (more)

Labels: , , , , , , , ,

Monday, May 5, 2008

The Dawn of the VoIP Bug

"...transform the existing power lines in your home or small office into a high-speed network solution. Without running wires, PLC-185S takes advantage of your existing electrical wiring to create or extend a network environment. PLC-185S is also an ideal solution for homes or small offices where concrete walls, floors in multi-storied buildings, or other architectural barriers could inhibit a wireless signal.

Just plug the PLC-185S into an electrical outlet and it can turn every electrical outlet into a possible network connection to connect to any network devices, such as wireless router, network cameras, and video servers." or VoIP bugs :) (more)

Labels: , , , , ,

Friday, May 2, 2008

SpyCam Story #442 - Webcam Hijack Warning

Experts at SophosLabs™, are warning computer users about the importance of properly securing PCs, following news that a man who allegedly used computer malware to prey upon young women has been charged in Canada.

According to media reports, 27-year-old Daniel Lesiewicz has been charged with using spyware to take over the webcams of women as young as 14 and coerced them into posing naked for him. (more)

Labels: , , , , , , , ,

Saturday, April 26, 2008

16 Extra Eyes in the Florida Eye Institute

SpyCam Story #441
The mysterious tale of 16 SpyCams, 16 Microphones, and a recorder!


FL - A 45-year-old Vero Beach woman has been arrested on eight felony charges that allege illegal electronic eavesdropping on doctors, copying hard drives from their computers and the theft of a laptop.

But the seven-page complaint filed by the State Attorney's Office against Brenda Doan-Johnson, of the 3400 block of Atlantic Boulevard, does not explain why she supposedly paid a Melbourne man to place cameras and microphones in the private offices of three doctors at the Florida Eye Institute in Vero Beach.

Both a Jan. 24 Vero Beach Police report and a Jan. 28 civil lawsuit filed by three of Dr. Paul V. Minotty's business partners, say Minotty, founder of the institute, had hired a private investigator and the police report identified her as Doan-Johnson.

According to the state attorney's complaint affidavit, Doan-Johnson paid Mark Lynch, of Spy Source Warehouse in Melbourne, with a $6,000 personal check as deposit on $13,000 to install 16 video cameras, 16 microphones and a digital recorder at various places in the Florida Eye Institute — including the offices of doctors Karen Todd, Mark Gambee and Val Zudan.

Lynch worked after business hours for six days, starting Jan. 11, to install the equipment, the affidavit states, noting that audio recording apparently did not function.

Investigators reported that Doan-Johnson introduced Lynch to two other people who also were working in the building, identifying them as computer forensic specialists who were copying the hard drives from the desk computers of doctors Gambee, Todd, Zudan and Thomas Baudo.

According to investigators, Lynch phoned Gambee (!?!?!) Jan. 24 and told him about installing the electronics in Florida Eye Institute offices — including Gambee's office. The Vero Beach police were called to Florida Eye Institute the same day.

Gambee told Vero Beach officers his computer was missing. Doan-Johnson returned it, saying it was thought to be company property... (more) ...and, more to come as this case unfolds.

Labels: , , , , , , ,

Wednesday, April 23, 2008

Cautionary Tale: Prevention = Cost-Effective

Hannaford spending millions to upgrade after security breach.
Background...
Yet Another Corporate Info-Loss Confession
"But, IT said our data was secure."

Hannaford Bros. Co. said it is spending millions of dollars to enhance the security of its data network following a massive security breach that exposed up to 4.2 million credit and debit card numbers to fraud...

Hannaford President and CEO Ron Hodge apologized again Tuesday to customers for concerns and inconvenience they experienced because of the breach...

In a conference call with reporters, Hodge and Bill Homa, senior vice president and chief information officer, declined to address the cause, scope and nature of the breach, citing the ongoing criminal investigation and pending litigation.

The Hannaford case is among the largest security breaches on record but is much smaller than the tens of millions of credit cards that were exposed at TJX Cos. of Framingham, Mass., which has 2,500 stores and includes the T.J. Maxx and Marshalls chains. (more)

The "millions" figure is likely just a system fix number. The final cost, which will include: public embarrassment, loss of customer good-will and
customer ill-will lawsuit losses, can not be tallied just yet.

Recommendation:
Be smart.
Be frugal.
Be a corporate hero.
Spend the bucks to protect your company's communications privacy (voice and data)
. There is a good chance you will save money in the long run... a lot of money! ~Kevin

Labels: , , , , , , ,

Friday, April 18, 2008

FutureWatch - Eavesdropping on GSM Cell Phones

A web service that will make it easy and inexpensive to crack the GSM A5/1 encryption protocol, quickly enough for a call that is still in progress, is slated to launch at the end of April. Living right at the intersection of open hardware, open source software, software as a service, and cryptography, the service will reduce the cost and effort of cracking GSM call encryption by at least an order of magnitude.

The service is being developed by members of the GSM Software Project and demonstrates just how much things have changed in the world since the GSM system was designed. Various approaches to cracking both A5/1 (the European standard) and A5/2 (the weaker US standard) have been available for some time but this one is unique in that it should be available to researchers and hackers at the end of April in hosted api form instead of pdf.

Back in 1997, this overview of the GSM system declared that "Enciphering is an option for the fairly paranoid, since the signal is already coded, interleaved, and transmitted in a TDMA manner, thus providing protection from all but the most persistent and dedicated eavesdroppers." After all, such a radio encoding scheme made the signals invisible to typical radio band scanners.

Today, however, the availability of the Universal Software Radio Peripheral (USRP), an open hardware software defined radio that sells for about $700, combined with work being done at GNU Radio project to codify the GSM waveform (also targeted for the end of this month), makes this once reasonable point of view seem quaint. Good encryption is now a must and it appears that A5 no longer qualifies. (more)

Labels: , , , , , , , , , , , ,

Tuesday, April 15, 2008

Data Land Mines

1. A slip of the finger reveals the company secret.
- Turn off that auto-fill feature.
2. People give away passwords and other secrets without thinking.
- Engage brain. Shut mouth.
3. A trusted partner ends up not being so trustworthy with your data.
- Share sparingly.
4. Web-based apps can be portals to leaks and thieves.
- VPN it instead.
5. Hoping the worse doesn’t happen only makes it worse.
- Plan for disasters.
6. Avoiding or diluting response leadership makes breaches worse.
- Designate a buck-stopper.
7. Handling breach details sloppily tips off the perp.
- Practice 'need-to-know'.
8. Trusting "silver bullet" technology hides real threats.
- There ain't no Lone Ranger.
9. Spending unthinkingly wastes resources you might need for important threats.
- Gauge threats.
10. Don't save the wrong data.
- Only store what you need.
(more)

Labels: , , , , , ,

Sunday, April 13, 2008

...and, 85% declined to answer.

"Me, My Spouse and the Internet"
Oxford Internet Institute, University of Oxford,
Survey Results...

• 20% of married Internet users admitted to reading their partner’s emails and text messages; and
• 13% to having checked their partner’s browser history.
More than 6,000 married people were invited to take part in the study. The final sample involved 929 couples, with both partners completing a questionnaire. (more) (Project website.)

Labels: , , , , , ,

Thursday, April 10, 2008

Blackemail, Espionage or Just Coincidence?

MA - Two staff members in the school superintendent’s office spied on e-mails sent to Cambridge School Committee members over the span of one month. (more)

...administration officials did not tell the School Committee they were receiving committee e-mails from parents and others. A School Committee member only found out the two school officials were copied into School Committee e-mails after they hit “reply all” and found the duo copied in the e-mail. 14 days after it was discovered, School Committee members voted to enter contract negotiations with Superintendent Thomas Fowler-Finn. (more)

Labels: , , , , , , ,

Search Engine with Reduced Squeal

Ixquick.com deletes its users' search data (including IP addresses) within 48 hours... Furthermore Ixquick does not set any uniquely identifying cookies or share your privacy details with 3rd parties.

Labels: , , , ,

Tuesday, April 8, 2008

"What's in your IT department?"

by Naomi Grossman, bmighty.com
Caught up in the high profile case of Anthony Pellicano -- the detective on trial for racketeering and wiretapping in a case that involves lots of big names in Hollywood -- is the manager of IT security for Conde Nast publications. How exactly did that guy get his job?...


On Gawker, Ryan Tate asks the second most obvious question: "The guy who runs tech security for Condé Nast has admitted lying to the FBI and lending his services to private detective Anthony Pellicano even though he knew Pellicano was tapping people's phones. He's also been accused, in the course of Pellicano's racketeering and wiretap trial, of leaking a pre-publication copy of Vanity Fair that Pellicano mysteriously obtained, and of bragging about bugging the office of his Condé Nast supervisor. So why does he still have a job?"...

...the lessons here go beyond the need to move decisively in hiring and firing. If Reynolds could do that stuff in a huge company like Conde Nast, imagine the damage your IT guy could do in your smaller business -- where there aren't the same resources to weather a disaster. Put the time and effort into checking your IT guys out. Each one could mean the difference between life and death for your company. (more)
Well said!
You've been warned.

Labels: , , , , , , , ,

Tuesday, April 1, 2008

Corporate Espionage Arrest - AMX Corp. V.P.

Short version: AMX Corporation's Vice President, David Goldenberg, was "arrested for allegedly participating in corporate espionage practices against a competing manufacturer's representative firm."

The following is from the Bergen County (NJ) Prosecutor's press release...
NJ - Bergen County Prosecutor John L. Molinelli announced the arrest of David A. Goldenberg, D.O.B. 05/18/1962, of 432 Golf Dr., Oceanside NY. Goldenberg was arrested on March 28, 2008, on charges of Unlawful Access of a Computer System / Network (2C:20-25b); Unlawful Access of Computer Data / Theft of Data (2C:20-25c); and Conducting an Illegal Wiretap (2A:156A-27)...


The arrest stemmed from an investigation concerning the following: The Paramus Police Department received a complaint from a Paramus based corporation known as Sapphire Marketing, who specializes in high-end audio/visual systems. Representatives of Sapphire reported that they were being suspiciously and consistently underbid for contracts by a competitor for whom David Goldenberg works. They expressed suspicion of corporate espionage. Based on anomalies that the complainant noticed within their computer network and more specifically their electronic mail (e-mail) system, they suspected that the company’s e-mail system had been compromised and that e-mail was being intercepted. The Paramus Police Department (a member of the Computer Crimes Task Force) and the Bergen County Prosecutor’s Office Computer Crimes Unit initiated an investigation.

The investigation revealed that Mr. Goldenberg had engineered the passwords protecting several of the complainant’s e-mail accounts. For a period of time, Mr. Goldenberg was intercepting and reading e-mails that related to potential contracts. Mr. Goldenberg then established a free e-mail account that he had control over, and created an automatic forward of the victim’s e-mail so that they would be sent to him directly. This afforded Mr. Goldenberg advanced knowledge of Sapphire’s customers and bid prices, thus further affording him an opportunity to underbid Sapphire. Sapphire Marketing estimates the loss in revenue from Mr. Goldenberg’s actions to exceed one-million dollars. Mr. Goldenberg was arrested without incident on this date. (more) (more - scroll down)

Goldenberg was hired by AMX June 11, 2007
...
“David has a proven track record of satisfying the needs of his customers while boosting sales and profitability. He is also an aggressive marketer focused on value creation,” said Rashid Skaf, AMX president and CEO. “David is a dynamic leader who has proven that he can successfully manage and motivate a diverse team of individuals. I am confident that he will fit well into the AMX culture and accomplish great things with our company.” (more)

Labels: , , , , , , , , , ,

Monday, March 31, 2008

"But, IT said our data was secure."

Data Theft Carried Out On Network Thought Secure
Criminals involved in a massive data breach at the Hannaford Bros. and Sweetbay grocery chains stole the customer information from a part of a computer-network system that security experts had believed was secure.


As many as 4.2 million credit- and debit-card numbers were exposed in the breach.

The Hannaford data, which included customer account numbers and card expiration dates, was stolen between Dec. 7 and March 10. ...it has resulted in at least 1,800 cases of fraud.

A malicious software program, written by the thieves, intercepted the information as it went back and forth over a cable to a transaction processor in Denver. It was then transmitted to an Internet service provider somewhere outside the U.S. The software, known as malware, was planted on computer systems in every store in the two chains, the company says.

...it took a team of about 30 forensics experts and information technologists more than 10 days of round-the-clock troubleshooting to discover the malware. (more) (recent data theft list)

Labels: , , ,

Sunday, March 30, 2008

Mama Hari

...a mother writes...
"It’s a tough call knowing when to spy and when to trust.
Though my own children, 4 and 7, are too young for me to be going through pockets looking for drugs, turning up mattresses looking for porno, etc., I plan on doing those things in their teen years.

In my own childhood, my parents were way too hands-off. Both of my brothers were doing serious drugs in high school and my parents didn’t find out until it was way too late. They wanted harmony in the house and took the path of least resistance. That meant my brothers were allowed privacy, didn’t have an enforced curfew, were given car keys before they could handle that responsibility. My parents prayed maturity would come soon.

With my own children, I’ve learned that I have to stay on top of things. On the computer, my son has tried to order things online. He even asked my mom for her credit card so he could buy a Ben 10 shirt. We’ve found that we need to set the rules for which Web sites he can look at. Anything not on the ‘Kids’ section of our Web browser’s bookmarks is off limits. Still, we walk by often while he’s online, and we remind him he needs to ask if it’s a new site." (more)

Labels: , , , , ,

Sunday, March 16, 2008

13 Fired For Spying

At least 13 hospital employees are being fired, and 6 suspended, after an investigator concluded that they broke the rules by accessing (Britney) Spears' medical records without any particular reason (except their own curiosity).

Not only would Britney's medical files give them the answers to some closely guarded secrets, but a photocopied page could sell to the tabloids for thousands. (more) Hip, HIPPA, Hooray

Labels: , , , , , , ,

Saturday, March 15, 2008

7 Security Rules Employees Love to Break

Research from the Ponemon Institute finds that either companies are not setting, or employees are not following, data security procedures in several high-risk areas.

“Data Security Policies Are Not Enforced,” a survey of 893 corporate IT workers, examined the risks associated with storing and transporting sensitive information and looked at how well companies are implementing and enforcing policies to protect against this risk.

1. Copying confidential information onto a USB memory stick.
2. Accessing web-based e-mail accounts from a workplace computer.
3. Losing a portable data-bearing device.
4. Downloading personal software onto a company computer.
5. Sending workplace documents as an attachment in e-mail.
6. Disabling security and firewall settings.
7. Sharing passwords with co-workers.
(more)

Labels: , , , ,

Romper Room Magic Mirror 2008

Tune into live surveillance cameras from around the world. Free computer screen saver turns you into Mr./Ms. Panopticon. (more)

Labels: , , ,

Sunday, March 9, 2008

Computer Bug Gets Upgrade

from the seller's website...
New for 2008! eBlaster 6.0

eBlaster has been the standard in remote monitoring software for parents and employers for almost a decade. It's time for a real innovative change, and we have some very exciting news.

Blaster 6.0 is now available, and we have added features we believe you're really going to like. Now, you have the ability to change options and settings remotely without having to return to the computer on which eBlaster is installed.

What Else is New in eBlaster 6.0?
NEW! Block Web Sites
-- Block inappropriate web sites by name immediately...
NEW! Block Chat/IM Contacts
-- Block all chat and instant messaging with specific people...
NEW! Online Searches
-- records searches made on Google, AOL, MSN, and Yahoo...
NEW! Screen Snapshots with Keyword Alerts
-- Now you can actually see EXACTLY what they saw...
NEW! MySpace Activity
-- All activity on the popular but potentially dangerous MySpace site...

When was the last time you checked your computer for spyware?
eBlaster detection.

Labels: , , , , ,

Thursday, March 6, 2008

Wireless security foiled by new exploits

Just when you thought your wireless network was locked down, a whole new set of exploits and hacker tools hits.

Josh_Wright: "Enterprises are doing ... better. We are seeing fewer open networks and more organizations moving to WPA/WPA2 from WEP. There is still more than a fair share of WEP networks, sometimes motivated by the need to support legacy wireless clients (such as VoIP phones, or Symbol scanners). A lot of the enterprises I talk to feel comfortable with the security of their WPA/WPA2 networks, but they often fail to realize that this is only one piece of a wireless security strategy. Failure to address client configuration and security issues, rogue detection and home/mobile users leaves organizations exposed to attack. (more)

When did you last check the security of your wireless network?
Idea... Have us preform an on-site wireless LAN security survey.

Labels: , , ,

Wednesday, March 5, 2008

Hedge Fund vs. Hedge Fund - Spying, Stealing

NY - Elliott Associates has accused another hedge fund of spying and stealing proprietary trading technology.

The $10 billion New York-based hedge fund, run by Paul Singer, filed suit today against Cedar Hill Capital Partners alleging it of scheming to “literally steal the software in order to use it for its own trading activities,” branding the activity “nothing short of an overt act of corporate espionage.” (more)

Labels: , , , ,

In-house NSA

A rapid way to spot insider threats from individuals within an organization such as a multinational company or military installation is reported in the current issue of the International Journal of Security and Networks. The technology uses data mining techniques to scour email and build up a picture of social network interactions. The technology could prevent serious security breaches, sabotage, and even terrorist activity.

Gilbert Peterson and colleagues at the Air Force Institute of Technology at Wright Patterson AFB, in Ohio are developing technology that could help any organization sniff out insider threats by analyzing email activity or find individuals among potentially tens of thousands of employees with latent interests in sensitive topics. The same technology might also be used to spot individuals who feel alienated within the organization as well as unraveling any worrying changes in their social network interactions. (more)

Labels: , , , , , , , ,

New Gadget Can Spy On Text Messages

Suspicious spouses can check out their husband or wife's deleted texts with a new gadget. The £76 ($149.00) device can get all the data off a mobile telephone's sim card - including messages and numbers that have been deleted. The information can then be transferred to a PC or laptop through a USB port. BrickHouse Security say it is ideal to "spy on your wife, husband, teens or colleague". (more)

Labels: , , , , , , , , , ,

Thursday, February 28, 2008

Unsecured Wi-Fi Could Compromise Your Identity

CBS3.com - Special Report...
The wireless internet signal you rely on for convenience could be making things easier for internet intruders. Police said hackers could be using your computer to download illegal music, child porn, or even your bank information.


Using a simple can antenna from his car, George Sandford can burglarize homes from hundreds of yards away out in the open and without wearing a mask.

"You can open bank accounts. You get drivers licenses, you can get practically anything you want," Sandford said.

All by using relatively low tech equipment, just about anyone with knowledge can hack into computers using unsecured wireless internet or Wi-Fi signals of unsuspecting people...

"I can build a body of information about you, your back accounts," Sandford said.

Jamie Smith spoke to one unsuspecting resident, "We were able to get onto your internet just a few seconds ago," and Rebecca Hansen of Swarthmore responded, "No."

Rebecca is a client of Tech Guides Incorporated and George Sandford is far from a thief. He is actually Tech Guides' security expert. He sat down and showed Rebecca how to secure her Wi-Fi something everyone should do.

"Not securing your wireless networking is pretty much putting a sign on your house saying 'Hey, we're open,'" Sanford said. Only about half of homes with Wi-Fi are locked. If you don't your computer's connection could be slowed down by others accidentally using your Wi-Fi. (complete story with video)

Directions for securing your Wi-Fi

Labels: , , , , , , , , ,

Liechtenstein reveals industrial spying probe

Liechtenstein, focus of international investigations over tax fraud, said on Wednesday a man convicted after stealing data from a Liechtenstein bank was now being investigated for industrial espionage...

"The investigations concern suspicion of spying out business secrets for the benefit of a foreign party," the Office of the Public Prosecutor said in a statement. (more)

Labels: , , , ,

German high court conditionally approves government data spying

Germany's Constitutional Court has determined that any data stored or exchanged on PCs is private and protected by the country's constitution -- just not if you're a suspect.

The court determined that data collection directly encroaches on citizens' rights, but that authorities will be allowed to spy on suspicious individuals with high court approval. (more)

Labels: , , , ,

Wednesday, February 27, 2008

FREE Password Cracker

Here is how it works in geek-speak...
RainbowCrack is a general propose implementation of Philippe Oechslin's faster time-memory trade-off technique. In short, the RainbowCrack tool is a hash cracker. A traditional brute force cracker try all possible plaintexts one by one in cracking time. It is time consuming to break complex password in this way. The idea of time-memory trade-off is to do all cracking time computation in advance and store the result in files so called "rainbow table". It does take a long time to precompute the tables. But once the one time precomputation is finished, a time-memory trade-off cracker can be hundreds of times faster than a brute force cracker, with the help of precomputed tables.

Bottom line...
Your cat's name never was a good password anyway. Change it. (help)

Labels: , , , , ,

Industrial Espionage in Brazil

Brazil - Brazilian police said on Tuesday they were treating the theft of strategic data from Brazil's state-run energy giant Petrobras as a case of industrial espionage.

Petrobras confirmed last Thursday that four laptops and two RAM memory chips were stolen in late January from a transport container owned by the U.S. oil-field service company Halliburton, a longtime Petrobras business partner.

The data came from a drilling ship in the Santos basin, where a huge new oil reserve was recently discovered. The find could make Brazil one of the world's major oil producers...

Caetano confirmed it was not the first case of data robbery from Petrobras. The company reported similar cases to police about a year ago but said they did not involve important information.

He faulted the security in the latest case. (more)

Labels: , ,

Tuesday, February 26, 2008

Eavesdropping on private chats is... art!

Conversations from thousands of internet chatrooms, message boards and other public forums have been transformed into an electronic art piece.

Described as a unique portrait of the internet, the electronic art - called the Listening Post – forms a free exhibition at the Science Museum in London.

The piece samples text fragments of uncensored and unedited internet conversations over 231 small electronic screens standing approximately 4m high and 5m wide. The text is accompanied by computer-synthesized voices reading or singing the words that surge, flicker and disappear over the screens.

Listening Post is a collaboration by sound artist Ben Rubin and statistician and artist Mark Hansen, who wanted to address the question: "What would 100,000 people chatting online sound like?" (more)

Labels: , , , , ,

Monday, February 25, 2008

"Encryption can't save you now, Sonny Boy... Muhhahahaaaaa!"

from c|net, by Declan McCullagh...
Computer scientists have discovered a novel way to bypass the encryption
used in programs like Microsoft's BitLocker and Apple's FileVault and then view the contents of supposedly secure files.


In a paper (PDF) published Thursday that could prompt a rethinking of how to protect sensitive data, the researchers describe how they can extract the contents of a computer's memory and discover the secret encryption key used to scramble files. (I tested these claims by giving them a MacBook with FileVault; here's a slideshow.)


"There seems to be no easy remedy for these vulnerabilities," the researchers say...

Their technique doesn't attack the encryption directly. Rather, it relies on gaining access to the contents of a computer's RAM--through a mechanism as simple as booting a laptop over a network or from a USB drive--and then scanning for encryption keys. How the scan is done is one of the most clever portions of the paper. (more)

Labels: , , , , ,

Wednesday, February 20, 2008

Leaked Info Dampens First Amendment

Recent days have brought two federal court decisions with disputed First Amendment legitimacy.

In San Francisco, District Judge Jeffrey White acceded to a request by a Cayman Islands bank to shut access to the Web site Wikileaks.org, which "invites people to post leaked materials with the goal of discouraging 'unethical behavior' by corporations and governments," as the New York Times reports.

In this case, the bank, Julius Baer Bank and Trust, accused "a disgruntled ex-employee" of giving stolen documents to Wikileaks in violation of banking laws and a confidentiality agreement. (more)

First Amendment vs. Creeping Extortionography.
You decide. In the meantime, keep your information from leaking in the first place. Need help? Call us.

Labels: , , , , , , ,