<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Last Watchdog &#187; For consumers</title>
	<atom:link href="http://lastwatchdog.com/category/for-consumers/feed/" rel="self" type="application/rss+xml" />
	<link>http://lastwatchdog.com</link>
	<description>on Internet security by Byron Acohido</description>
	<lastBuildDate>Wed, 25 Apr 2012 20:37:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>Another Lisabeth Salander-like hacker-hero is born</title>
		<link>http://lastwatchdog.com/lisabeth-salander-like-hacker-hero-born/</link>
		<comments>http://lastwatchdog.com/lisabeth-salander-like-hacker-hero-born/#comments</comments>
		<pubDate>Wed, 25 Apr 2012 20:01:49 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12298</guid>
		<description><![CDATA[A killer cop. Eight dead prostitutes. A reclusive Brazilian sex trader. Toss in an amoral hacker, named JD, rallying to aide two old friends, who just happen to be Massachusetts state police detectives, and you have the recipe for Dennis Fisher&#8217;s new thriller, Motherless Children. Fisher squeezed out time around his day job as editor [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12299" href="http://lastwatchdog.com/lisabeth-salander-like-hacker-hero-born/bookjacket_fisher150px/"><img class="alignleft size-full wp-image-12299" title="Bookjacket_Fisher150px" src="http://lastwatchdog.com/wp/wp-content/uploads/Bookjacket_Fisher150px.jpg" alt="" width="150" height="151" /></a>A killer cop. Eight dead prostitutes. A reclusive Brazilian sex trader. Toss in an amoral hacker, named JD, rallying to aide two old friends, who just happen to be Massachusetts state police detectives, and you have the recipe for Dennis Fisher&#8217;s new thriller, <a href="http://www.amazon.com/Motherless-Children-ebook/dp/B007TX62P8/ref=sr_1_11?s=%3Cbr%20/%3Ebooks&amp;ie=UTF8&amp;qid=1334408169&amp;sr=1-11"><em>Motherless Children</em></a>.</p>
<p>Fisher squeezed out time around his day job as editor of Kaspersky Lab&#8217;s security blog, Threatpost, to pen and publish his first novel, released last week. Prior to his current gig, Fisher was an editor and writer, focused on information security, at TechTarget.</p>
<div id="attachment_12304" class="wp-caption alignleft" style="width: 185px"><a rel="attachment wp-att-12304" href="http://lastwatchdog.com/lisabeth-salander-like-hacker-hero-born/dennis-fisher175px-2/"><img class="size-full wp-image-12304" title="Dennis Fisher175px" src="http://lastwatchdog.com/wp/wp-content/uploads/Dennis-Fisher175px1.jpg" alt="" width="175" height="246" /></a><p class="wp-caption-text">Fisher</p></div>
<p>No surprise, then, that this work of fiction contains an info sec subplot. Hot on the trail of a serial killer, the detectives get stymied by an inability to legally examine the contents of the suspect&#8217;s computer. Enter JD, who agrees to help out with some stealthy cybersnooping. He also leaves a rootkit behind that ultimately figures into a climactic scene at the end of the book.</p>
<p>There&#8217;s clearly an eager global audience for works of fiction that feature lone wolf hackers. Lisabeth Salander, the fictional hacker-heroine of the late Swedish journalist Stieg Larsson&#8217;s<a href="http://www.stieglarsson.com/Millennium-series"><em> Girl With The Dragon Tatoo</em></a> trilogy, comes to mind.</p>
<p>Fisher says he got the idea for the book while commuting to Boston every day.  &#8220;I&#8217;d drive by this really nasty looking swamp on the way home. It was right by the side of the highway and had the feel of something from a horror movie, with burned-out tree trunks sticking out of the water,&#8221; Fisher says. &#8220;I started wondering what had happened there and what could be under the water.</p>
<p>&#8220;I started wondering what had happened there and what could be under the water. I eventually came up with the beginning of the plot, with there being dead bodies found in the water and then went from there. I imagine that most writers start either with a character or a plot idea, but for me it started with that location.&#8221;</p>
<p>He describes <em>Motherless Children</em> as &#8220;a story about the small decisions that can define our lives, the true nature of good and evil and finding the strength to do what needs to be done–regardless of the consequences.&#8221;</p>
<p>JD, the hacker-hero, is &#8221; based loosely on a couple of researchers and there are several small inside security jokes in the book that folks in the community will like, I think,&#8221; Fisher adds.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/white-house-cyber-security-post-remains-unfilled/" rel="bookmark" class="crp_title">White House cyber security adviser post remains unfilled</a></li><li><a href="http://lastwatchdog.com/chilling-effect-megaupload-raid-spreads/" rel="bookmark" class="crp_title">Chilling effect of MegaUpload raid takes hold</a></li><li><a href="http://lastwatchdog.com/sen-susan-m-collins-stuxnet-worm-work-lone-hacker/" rel="bookmark" class="crp_title">Sen. Susan M. Collins: Stuxnet worm not the work of lone hacker</a></li><li><a href="http://lastwatchdog.com/myspace-samy-worm-creator-seeks-impress-girlfriendquickly/" rel="bookmark" class="crp_title">Seeking to impress his girlfriend, Samy worm creator introduces huge new attack surface</a></li><li><a href="http://lastwatchdog.com/usa-today-book-review-zero-day-threat/" rel="bookmark" class="crp_title">USA Today book reviewer calls ZDT &#8220;daring&#8221;</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/lisabeth-salander-like-hacker-hero-born/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Angry Birds and other Facebook apps score low on privacy</title>
		<link>http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/</link>
		<comments>http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/#comments</comments>
		<pubDate>Sun, 22 Apr 2012 20:25:12 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12309</guid>
		<description><![CDATA[A new service that grades how each of Facebook&#8217;s top third-party apps respects consumers&#8217; privacy was released late Sunday by research firm PrivacyChoice. The free tool, Privacyscore for Facebook, spells out privacy policies and tracking practices of more than 200 top Facebook apps, including games, work-related programs and sharing apps. Online tracking is fueling a [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12310" href="http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/angry-birds150px/"><img class="alignleft size-full wp-image-12310" title="angry birds150px" src="http://lastwatchdog.com/wp/wp-content/uploads/angry-birds150px.jpg" alt="" width="150" height="150" /></a>A new service that grades how each of Facebook&#8217;s top third-party apps respects consumers&#8217; privacy was released late Sunday by research firm PrivacyChoice. The free tool, <a href="http://apps.facebook.com/privacyscoreapps/">Privacyscore for Facebook</a>, spells out privacy policies and tracking practices of more than 200 top Facebook apps, including games, work-related programs and sharing apps.</p>
<p>Online tracking is fueling a heated national debate over whether new do-not-track laws are needed to safeguard consumers&#8217; online privacy. Leaders in the online advertising industry use a version of Privacyscore to self-police the tracking practices of online advertising networks, and thus head off new laws. Privacy experts welcomed the consumer version.</p>
<p><object id="flashObj" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="360" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="bgcolor" value="#FFFFFF" /><param name="flashVars" value="videoId=1573851130001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="base" value="http://admin.brightcove.com" /><param name="seamlesstabbing" value="false" /><param name="allowFullScreen" value="true" /><param name="swLiveConnect" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" /><param name="name" value="flashObj" /><param name="flashvars" value="videoId=1573851130001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="allowfullscreen" value="true" /><embed id="flashObj" type="application/x-shockwave-flash" width="425" height="360" src="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" name="flashObj" allowscriptaccess="always" swliveconnect="true" allowfullscreen="true" seamlesstabbing="false" base="http://admin.brightcove.com" flashvars="videoId=1573851130001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" bgcolor="#FFFFFF"></embed></object><br />
&#8220;This certainly is going to be a useful tool for consumers, but it may actually be even more useful in pushing application developers, who don&#8217;t like getting poor grades, to look more closely at their own privacy practices,&#8221; says Jules Polonetsky, director of the Future of Privacy Forum, a Washington, D.C., think tank on data security.</p>
<p>Facebook&#8217;s pervasive Web presence comes with &#8220;a responsibility to hold people who are developing apps on their platform accountable for the (privacy) assertions that they&#8217;re making,&#8221; says Craig Spiezle, executive director of the Online Trust Alliance.</p>
<p>Facebook&#8217;s David Swain noted that the company requires app developers to agree to its privacy policies. &#8220;If we find an app has violated our policies … we take action,&#8221; Swain says.</p>
<p>According to PrivacyChoice, 140 different tracking entities routinely collect information about users of the top Facebook apps. Trackers can correlate that data to profiles of individuals&#8217; browsing behavior across multiple Web pages in order to deliver more relevant ads. &#8220;It&#8217;s up to users to know the privacy risk of sharing personal data with apps,&#8221; says Jim Brock, PrivacyChoice founder and CEO.</p>
<p>Privacyscore&#8217;s top score is 100. Deductions are made for sharing data with an excessive number of tracking entities, failing to honor deletion requests, failing to provide an opt-out choice or storing consumer data for long periods.</p>
<p>Gamemaker Zynga, for instance, registers an overall score of 82 for 17 Facebook games. The game Slingo, with 17 million players, scores 80, losing points partly because it connects to 59 trackers. Zynga general counsel Reggie Davis says Zynga welcomes tools such as Privacyscore. And Zynga&#8217;s online tutorial, PrivacyVille, rewards its users for learning more about the company&#8217;s privacy policies.</p>
<p>—</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/video-documentary-reveals-details-inception-pc-viruses/" rel="bookmark" class="crp_title">Video documentary reveals details of the inception of PC viruses</a></li><li><a href="http://lastwatchdog.com/video-examines-poisoned-search-results-kate-middelton/" rel="bookmark" class="crp_title">Video examines poisoned search results for Kate Middleton</a></li><li><a href="http://lastwatchdog.com/cyber-attacks-mobile-devices-gain-meaningful-traction/" rel="bookmark" class="crp_title">Cyber attacks on mobile devices gain meaningful traction</a></li><li><a href="http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/" rel="bookmark" class="crp_title">Mobile devices carry intrinsic security flaws</a></li><li><a href="http://lastwatchdog.com/visa-risk-chief/" rel="bookmark" class="crp_title">Visa risk chief calls for increased use of smart cards, password tokens</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Workarounds arise as Apple readies cure for Mac infections</title>
		<link>http://lastwatchdog.com/workarounds-arise-apple-readies-cure-mac-infections/</link>
		<comments>http://lastwatchdog.com/workarounds-arise-apple-readies-cure-mac-infections/#comments</comments>
		<pubDate>Thu, 12 Apr 2012 20:39:12 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Steps forward]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12278</guid>
		<description><![CDATA[If you suspect your Mac might be one of the 600,000 or so computers infected with the Flashback virus, Finnish antivirus company F-Secure has issued a free tool that detects and removes the nasty infection. Another detection tool you can use has been made available by Russian antivirus firm Kaspersky. Meanwhile, Apple has issued a [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12279" href="http://lastwatchdog.com/workarounds-arise-apple-readies-cure-mac-infections/macs_duo150px/"><img class="alignleft size-full wp-image-12279" title="Macs_duo150px" src="http://lastwatchdog.com/wp/wp-content/uploads/Macs_duo150px.jpg" alt="" width="150" height="143" /></a>If you suspect your Mac might be one of the 600,000 or so computers<a href="http://lastwatchdog.com/milestone-botnet-comprised-600000-infected-macs/"> infected with the Flashback virus, </a>Finnish antivirus company F-Secure has<a href="http://www.f-secure.com/weblog/archives/00002346.html"> issued a free tool </a>that detects and removes the nasty infection.</p>
<p>Another detection tool you can use has been<a href="http://flashbackcheck.com/"> made available</a> by Russian antivirus firm Kaspersky. Meanwhile, Apple has <a href="http://support.apple.com/kb/HT5244">issued a statement i</a>ndicating that it is continuing to work on an offical detection and innoculation tool.</p>
<p>It&#8217;s not just individual Mac owners who ought to take heed. Network security firm Lancope says companies with employees who use Macs would be wise to check for infected Apple computing devices.</p>
<div id="attachment_12280" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-12280" href="http://lastwatchdog.com/workarounds-arise-apple-readies-cure-mac-infections/jody-ma-kissling90px/"><img class="size-full wp-image-12280" title="Jody Ma Kissling90px" src="http://lastwatchdog.com/wp/wp-content/uploads/Jody-Ma-Kissling90px.jpg" alt="" width="90" height="130" /></a><p class="wp-caption-text">Kissling</p></div>
<p>&#8220;Enterprises should also bolster their defenses,&#8221; says Lancope vice president Jody Ma Kissling. &#8220;As the market share for Macs continues to increase, end users, corporations and Apple itself must all be prepared for a subsequent rise in attacks targeting Apple&#8217;s Mac OS X.&#8221;</p>
<p>Neil Roiter, research director at Corero Network Security says &#8220;cyber criminals now consider Macs profitable targets. Mac users should protect their computers with antivirus software, encrypt sensitive information and follow the common-sense advice not to click on links or open email attachments from unknown sources.&#8221;</p>
<p><object id="flashObj" width="425" height="360" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9,0,47,0"><param name="movie" value="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" /><param name="bgcolor" value="#FFFFFF" /><param name="flashVars" value="videoId=1554145984001&#038;playerID=35146470001&#038;playerKey=AQ~~,AAAACC1laJk~,tMO2d6O4midjZXg1vCvdWWjRZdwrH9hC&#038;domain=embed&#038;dynamicStreaming=true" /><param name="base" value="http://admin.brightcove.com" /><param name="seamlesstabbing" value="false" /><param name="allowFullScreen" value="true" /><param name="swLiveConnect" value="true" /><param name="allowScriptAccess" value="always" /><embed src="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" bgcolor="#FFFFFF" flashVars="videoId=1554145984001&#038;playerID=35146470001&#038;playerKey=AQ~~,AAAACC1laJk~,tMO2d6O4midjZXg1vCvdWWjRZdwrH9hC&#038;domain=embed&#038;dynamicStreaming=true" base="http://admin.brightcove.com" name="flashObj" width="425" height="360" seamlesstabbing="false" type="application/x-shockwave-flash" allowFullScreen="true" swLiveConnect="true" allowScriptAccess="always" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></embed></object></p>
<p>Roger Thompson, chief emerging threats researcher at vendor-neutral testing and certification firm ICSA Labs, explains the significance of the emergence of a major botnet comprised entirely of Macs.</p>
<p>He observes that Mac infections were considered rare for much of the past two decades &#8220;as a natural consequence of relative market opportunity for the bad guys. Put another way, there were way more PCs than Macs, so there was simply more opportunity for a return on their development and marketing effort.&#8221;</p>
<p>What the existence of a massive Mac botnet highlights, Thompson says, is that &#8220;Mac malware is not just a reality, but is now a genuine problem. The issue is that for a decade, Apple has made a point of telling users that they had no malware problem, and the result of that is that Mac users have no antibodies, when it comes to malware. They don&#8217;t expect it, and too many people will click on, and install, anything.&#8221;</p>
<p>The bottom line for Mac users: they will have to install and keep current antivirus programs and make sure all application updates, for things like Java, iTunes and Adobe Flash are quickly installed, just like Windows users.</p>
<p>&#8220;There will soon be a name for Mac users who are not doing this: victims,&#8221; says Thompson.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/video-documentary-reveals-details-inception-pc-viruses/" rel="bookmark" class="crp_title">Video documentary reveals details of the inception of PC viruses</a></li><li><a href="http://lastwatchdog.com/video-examines-poisoned-search-results-kate-middelton/" rel="bookmark" class="crp_title">Video examines poisoned search results for Kate Middleton</a></li><li><a href="http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/" rel="bookmark" class="crp_title">Angry Birds and other Facebook apps score low on privacy</a></li><li><a href="http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/" rel="bookmark" class="crp_title">Mobile devices carry intrinsic security flaws</a></li><li><a href="http://lastwatchdog.com/cyber-attacks-mobile-devices-gain-meaningful-traction/" rel="bookmark" class="crp_title">Cyber attacks on mobile devices gain meaningful traction</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/workarounds-arise-apple-readies-cure-mac-infections/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Mobile devices carry intrinsic security flaws</title>
		<link>http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/</link>
		<comments>http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/#comments</comments>
		<pubDate>Mon, 09 Apr 2012 17:57:37 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Steps forward]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12252</guid>
		<description><![CDATA[By Byron Acohido, USA TODAY, 09Apr2012, P1B Those cool mobile devices beloved by consumers carry deep-rooted security flaws that are only now being discovered and addressed. That’s the upshot of two recent deep examinations of popular mobile devices. The findings highlight how designers of the current generation of smartphones and tablet PCs failed to fully [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12253" href="http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/smartphone-array150px/"><img class="alignleft size-full wp-image-12253" title="smartphone array150px" src="http://lastwatchdog.com/wp/wp-content/uploads/smartphone-array150px.jpg" alt="" width="150" height="140" /></a>By Byron Acohido, USA TODAY, 09Apr2012,<a href="http://www.usatoday.com/tech/news/story/2012-04-08/smartphone-security-flaw/54122468/1"> P1B</a></p>
<p>Those cool mobile devices beloved by consumers carry deep-rooted security flaws that are only now being discovered and addressed.</p>
<p>That’s the upshot of two recent deep examinations of popular mobile devices. The findings highlight how designers of the current generation of smartphones and tablet PCs failed to fully account for the security and privacy implications.</p>
<p>“Today&#8217;s smartphones and tablet devices perform the same functions as a PC,” says Dan Hoffman, chief of mobile security at Juniper Networks.“However, the vast majority of devices lack security software and mistakenly rely upon the operating system to keep people safe.”</p>
<p><object id="flashObj" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="360" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="bgcolor" value="#FFFFFF" /><param name="flashVars" value="videoId=1537973447001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="base" value="http://admin.brightcove.com" /><param name="seamlesstabbing" value="false" /><param name="allowFullScreen" value="true" /><param name="swLiveConnect" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" /><param name="name" value="flashObj" /><param name="flashvars" value="videoId=1537973447001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="allowfullscreen" value="true" /><embed id="flashObj" type="application/x-shockwave-flash" width="425" height="360" src="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" name="flashObj" allowscriptaccess="always" swliveconnect="true" allowfullscreen="true" seamlesstabbing="false" base="http://admin.brightcove.com" flashvars="videoId=1537973447001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" bgcolor="#FFFFFF"></embed></object></p>
<p>In one study, Cryptography Research showed how it is possible to eavesdrop on any smartphone or tablet PC as it uses cryptographic keys to protect sensitive operations, such as when a mobile device is being used to make a purchase, conduct online banking or access a company’s virtual private network.</p>
<p>The secret keys can be deciphered, enabling a criminal to use them to access a financial account or a company network, says Benjamin Jun, Cryptography Research’s chief technology officer.</p>
<div id="attachment_12254" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-12254" href="http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/benjamin-jun90px/"><img class="size-full wp-image-12254" title="Benjamin Jun90px" src="http://lastwatchdog.com/wp/wp-content/uploads/Benjamin-Jun90px.jpg" alt="" width="90" height="118" /></a><p class="wp-caption-text">Jun</p></div>
<p>“These type of attacks do not require the device to be modified and there is usually no observable sign that an attack is in progress,” Jun says.</p>
<p>Cryptography Research is “working with one of the major smartphone and table companies right now to put countermeasures in,” Jun says. No known actual attacks have occurred, he says.</p>
<p>In another theoretical study, researchers at security firm McAfee, a division of Intel, demonstrated several ways to remotely hack into Apple iOS, the operating system for iPads and iPhones.</p>
<p>McAfee’s research team remotely activated device microphones and recorded conversations taking place in the vicinity of the hacked device. They also stole secret keys and passwords, and were able to pilfer sensitive data, including call histories, e-mail and text messages.</p>
<p>“This attack method shows ways that advanced attackers can compromise and control devices indefinitely,” says Ryan Permeh, McAfee’s principal security architect. “This can be done with absolutely no indication to the device user.”</p>
<p>Apple spokeswoman Trudy Muller declined comment.</p>
<p>Security experts and law enforcement officials anticipate that cybergangs will accelerate actual attacks as consumers and companies begin to rely more heavily on mobile devices for shopping, banking and working.</p>
<p>“Responsibility for addressing these security concerns is far reaching,” says Hoffman. “The broader security community needs to assist in providing all users the highest-level of protection.”</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/video-documentary-reveals-details-inception-pc-viruses/" rel="bookmark" class="crp_title">Video documentary reveals details of the inception of PC viruses</a></li><li><a href="http://lastwatchdog.com/video-examines-poisoned-search-results-kate-middelton/" rel="bookmark" class="crp_title">Video examines poisoned search results for Kate Middleton</a></li><li><a href="http://lastwatchdog.com/cyber-attacks-mobile-devices-gain-meaningful-traction/" rel="bookmark" class="crp_title">Cyber attacks on mobile devices gain meaningful traction</a></li><li><a href="http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/" rel="bookmark" class="crp_title">Angry Birds and other Facebook apps score low on privacy</a></li><li><a href="http://lastwatchdog.com/visa-risk-chief/" rel="bookmark" class="crp_title">Visa risk chief calls for increased use of smart cards, password tokens</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Why Apple needs to be more forthcoming with patching</title>
		<link>http://lastwatchdog.com/apple-forthcoming-patching/</link>
		<comments>http://lastwatchdog.com/apple-forthcoming-patching/#comments</comments>
		<pubDate>Fri, 06 Apr 2012 22:39:16 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12246</guid>
		<description><![CDATA[The disclosure of a massive botnet comprised entirely of Macs is serving as a lightning rod for the community of a few hundred top virus hunters who would like to see Apple become more collaborative about defending the Internet against cybercriminals. “Maybe Apple will feel a little of the pain their users are now feeling [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_12247" class="wp-caption alignleft" style="width: 160px"><a rel="attachment wp-att-12247" href="http://lastwatchdog.com/apple-forthcoming-patching/paul-henry150px/"><img class="size-full wp-image-12247" title="Paul Henry150px" src="http://lastwatchdog.com/wp/wp-content/uploads/Paul-Henry150px.jpg" alt="" width="150" height="153" /></a><p class="wp-caption-text">Henry</p></div>
<p>The disclosure of a massive botnet comprised entirely of Macs is serving as a <a href="http://www.zdnet.com/blog/bott/new-mac-malware-epidemic-exploits-weaknesses-in-apple-ecosystem/4726?tag=nl.e539">lightning rod</a> for the community of a few hundred top virus hunters who would like to see Apple become more collaborative about defending the Internet against cybercriminals.</p>
<p>“Maybe Apple will feel a little of the pain their users are now feeling and get serious about being more candid and perhaps more revealing in their patch release notifications,” says Paul Henry, security and forensic analyst at network security company  Lumension,.</p>
<p>Henry notes that calculating the number of infected Macs has been relative easy, since the Trojan “actually sends a copy of each infected Mac&#8217;s UUID to the command and control server.”</p>
<p>Some 300,000 of the 600,000 Macs infected by the Flashback Trojan are located in the U.S., including 274 in Cuppertino, Apple’s hometown in Silicon Valley, according to Tweets from Ivan Sorokin, a malware analyst at Russian antivirus company Dr. Web.</p>
<p>Sorokin used sinkhole technology to redirect the botnet traffic to their own servers to count infected Macs.</p>
<p>Henry says that  “Apple still lacks any urgency in their patch release and in fact, users had to be lucky enough to have checked.</p>
<p>“Simply put, if Apple wants to be taken seriously as an enterprise provider, they need to be more timely and candid about their patches,” Henry continues.  “How else will administrators understand the necessary sense of urgency to prioritize and deal with security issues?”</p>
<p>Apple has been issuing patches roughly once a month, much like Microsoft issues security fixes on the second Tuesday of each month, known as Patch Tuesdsay.</p>
<p>“Apple should take a lesson from Microsoft and formally adopt a monthly process and provide, at minimum, the same level of disclosure users have come to expect from Microsoft,” says Henry.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/patch-tuesday-bonanaza-microsoft-oracle-apple-issue/" rel="bookmark" class="crp_title">Patch bonanaza: Microsoft fixes pile onto updates from Oracle, Apple, Adobe</a></li><li><a href="http://lastwatchdog.com/apple-anti-virus-now-available/" rel="bookmark" class="crp_title">Apple anti-virus now available</a></li><li><a href="http://lastwatchdog.com/milestone-botnet-comprised-600000-infected-macs/" rel="bookmark" class="crp_title">Milestone botnet comprised of 600,000 infected Macs</a></li><li><a href="http://lastwatchdog.com/workarounds-arise-apple-readies-cure-mac-infections/" rel="bookmark" class="crp_title">Workarounds arise as Apple readies cure for Mac infections</a></li><li><a href="http://lastwatchdog.com/sophos-release-fee-mac-antivirus-shows-hackers-targeting/" rel="bookmark" class="crp_title">Welcome to the Wild Wild Web Mac lovers</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/apple-forthcoming-patching/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Milestone botnet comprised of 600,000 infected Macs</title>
		<link>http://lastwatchdog.com/milestone-botnet-comprised-600000-infected-macs/</link>
		<comments>http://lastwatchdog.com/milestone-botnet-comprised-600000-infected-macs/#comments</comments>
		<pubDate>Thu, 05 Apr 2012 19:06:31 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12232</guid>
		<description><![CDATA[This was inevitable. A cyber gang has assembled a botnet comprised of Apple Macs, not Windows PCs. An unpatched portion of Java left Mac users prone to the Flashback Trojan, which causes the machine to quietly report to a command and control server for further instructions. Mac users  can get infected by navigating to a [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12233" href="http://lastwatchdog.com/milestone-botnet-comprised-600000-infected-macs/macbook-pro175px/"><img class="alignleft size-full wp-image-12233" title="MacBook Pro175px" src="http://lastwatchdog.com/wp/wp-content/uploads/MacBook-Pro175px.jpg" alt="" width="175" height="106" /></a>This was inevitable. A cyber gang has <a href="http://content.usatoday.com/communities/technologylive/index#.T33jpo4743Y">assembled a botnet</a> comprised of Apple Macs, not Windows PCs.</p>
<p>An unpatched portion of Java left Mac users prone to the Flashback Trojan, which causes the machine to quietly report to a command and control server for further instructions.</p>
<p>Mac users  can get infected by navigating to a viral web page pre-loaded to deliver a driveby download tuned to exploit this Java vulnerability &#8212; much the same as Windows PC users.</p>
<p>The  Russian antivirus company <a href="http://news.drweb.com/show/?i=2341">Dr. Web</a> says some 600,000 Macs have been infected, several of which include devices based in Cupertino, California, the home of Apple. So if your Mac has been balky lately, this could be the explanation.</p>
<p><strong>Swiss Army knife</strong></p>
<p>Botnets are used to spread spam and infections, participate in denial of service attacks, hijack online bank accounts etc. Botnets are the Swiss Army Knife of cybercrime. And when your machine is performing bot duties, your processing efficiencies naturally get sapped. It was only a matter of time before this common experience of Windows PC users came home to roost with Mac users.</p>
<p>One commenter to <a href="http://arstechnica.com/apple/news/2012/04/flashback-trojan-reportedly-controls-half-a-million-macs-and-counting.ars?comments=1#comments-bar">Ars Technica&#8217;s coverage</a> noted:</p>
<blockquote>
<div>My wife&#8217;s first gen core duo macbook pro hard drive is always  busy, which i thought was due to limited hard drive space. Even after  cleaning out ~15 gigs of space, the OS is slow and often unresponsive,  and the HD is clickety clacking all the time. I sure hope I don&#8217;t have  it. I&#8217;m going to check first thing when I get home. Has anyone&#8217;s machine  here tested positive? If so, does this sound familiar?</div>
</blockquote>
<p>Apple has since patched the Java flaw. F-Secure has supplied details on how to diagnose and<a href="http://www.f-secure.com/v-descs/trojan-downloader_osx_flashback_i.shtml"> fix the problem</a>, but warns that the steps are tricky.</p>
<p><strong>Wake up call</strong></p>
<p>“This  latest wave of infections is a wake-up call to Mac users that their  system is not immune to threats,&#8221; says Mike Geide, senior security researcher at Zscaler ThreatLabZ. &#8220;And the need to follow best security  practices, such as remaining current with patches, is ubiquitous &#8212; it  doesn&#8217;t matter if you’re using Windows, Mac, or even mobile phone.”</p>
<div id="attachment_12234" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-12234" href="http://lastwatchdog.com/milestone-botnet-comprised-600000-infected-macs/dave-marcus90px/"><img class="size-full wp-image-12234" title="Dave Marcus90px" src="http://lastwatchdog.com/wp/wp-content/uploads/Dave-Marcus90px.jpg" alt="" width="90" height="127" /></a><p class="wp-caption-text">Marcus</p></div>
<p>Dave Marcus, director of advanced research and threat intelligence at McAfee Labs, says the existence of a major Mac botnet comes as no surprise. He advises Mac users to do as Windows PC users do: keep antivirus protection and all Apple patches current.</p>
<p>&#8220;Attackers are leveraging years of success from writing PC malware and they&#8217;re doing the same thing in the Mac world,&#8221; says Marcus. &#8220;Cybercriminals will attack any operating system with valuable information, and as the popularity of Macs increase, so will attacks on the Mac platform.&#8221;</p>
<p>&#8211;By Byron Acohido</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/apple-forthcoming-patching/" rel="bookmark" class="crp_title">Why Apple needs to be more forthcoming with patching</a></li><li><a href="http://lastwatchdog.com/workarounds-arise-apple-readies-cure-mac-infections/" rel="bookmark" class="crp_title">Workarounds arise as Apple readies cure for Mac infections</a></li><li><a href="http://lastwatchdog.com/apple-anti-virus-now-available/" rel="bookmark" class="crp_title">Apple anti-virus now available</a></li><li><a href="http://lastwatchdog.com/macs-emerge-virus-carriers-windows-networks/" rel="bookmark" class="crp_title">Macs emerge as virus carriers into Windows networks</a></li><li><a href="http://lastwatchdog.com/apple-macs-targeted-phishers-intensely-windows-pcs/" rel="bookmark" class="crp_title">Apple Macs targeted by phishers just as intensely as Windows PCs</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/milestone-botnet-comprised-600000-infected-macs/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Merchants, consumers on hook due to card processor breach</title>
		<link>http://lastwatchdog.com/merchants-consumers-hook-due-breach/</link>
		<comments>http://lastwatchdog.com/merchants-consumers-hook-due-breach/#comments</comments>
		<pubDate>Fri, 30 Mar 2012 22:40:34 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12212</guid>
		<description><![CDATA[Merchants and consumers could be the big losers in the latest case of hackers cracking the complex systems used to process credit and debit card transactions. Visa and MasterCard acknowledged Friday that they’ve been alerting banks about a major breach of an unnamed payment card processing firm. The Wall Street Journal, citing unnamed sources, named [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12214" href="http://lastwatchdog.com/merchants-consumers-hook-due-breach/card-swipe163px/"><img class="alignleft size-full wp-image-12214" title="Card swipe163px" src="http://lastwatchdog.com/wp/wp-content/uploads/Card-swipe163px.jpg" alt="" width="163" height="146" /></a>Merchants and consumers could be the big losers in the <a href="http://www.usatoday.com/tech/news/story/2012-03-30/mastercard-security-breach/53887854/1">latest case</a> of hackers cracking the complex systems used to process credit and debit card transactions.</p>
<p>Visa and MasterCard acknowledged Friday that they’ve been alerting banks about a major breach of an unnamed payment card processing firm. The<em> Wall Street Journal,</em> citing unnamed sources, <a href="online.wsj.com/article/SB10001424052702303816504577313411294908868.html?mod=WSJ_hp_LEFTTopStories">named </a>Atlanta-based Global Payments as the processor in question.</p>
<p>Global Payments declined interview requests.</p>
<p>Security blogger Brian Krebs, who<a href="http://krebsonsecurity.com/2012/03/mastercard-visa-warn-of-processor-breach/#more-14393"> broke the story</a>, says thieves cracked into the processor’s systems between Jan. 21 and Feb. 25, and may have swiped more than 10 million credit and debit card transactions records, originating from an unknown number of merchants, banks and credit unions.</p>
<div id="attachment_12218" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-12218" href="http://lastwatchdog.com/merchants-consumers-hook-due-breach/avivah_litan90px-3/"><img class="size-full wp-image-12218" title="avivah_Litan90px" src="http://lastwatchdog.com/wp/wp-content/uploads/avivah_Litan90px2.jpg" alt="" width="90" height="134" /></a><p class="wp-caption-text">Litan</p></div>
<p>Gartner banking security analyst Avivah Litan says unverified reports point to a New York City street gang with Central American ties taking over &#8221; an administrative account that was not protected sufficiently.&#8221;</p>
<p>“I’ve spoken with folks in the card business who are seeing signs of this breach mushroom,” says Litan.</p>
<p>MasterCard issued a statement advising cardholders to contact the financial institution that issued their cards with any concerns. Visa emphasized that no Visa systems were breached.</p>
<p>However, criminals know better than to try to waste time on highly defended systems, and have been consistently successful cracking support system. “Sooner or later they find some weakness  in the highly complex chain of systems that they can exploit,” says Geoff Webb, of data security firm Credant Technologies.</p>
<p>Credit card processors have been breached before. Heartland Payment Systems lost 130 million payment card records generated by 250,000 merchants and restaurants in 2008 -2009.</p>
<p>It’s not just card processors that are being targeted.  Last year  hackers stole payment card information for more than <a href="http://lastwatchdog.com/sony-playstation-network-data-breach-timeline/">100 million customers </a>of Sony’s PlayStation Network.</p>
<p>And earlier this year online shoe retailer Zappos disclosed hackers took e-mail and shipping addresses, phone numbers and account passwords for some <a href="http://lastwatchdog.com/zappos-hack-shows-risk-e-mail-account-username/">24 million customers</a>, data useful for identity theft.</p>
<p>“Any business that’s capturing payment data is a target,” says Mark Bower, analyst at  Voltage Security.</p>
<p>Consumers whose debit card account information landed in criminals’ hands with this latest breach are at heightened risk. That’s because gangs are adept at quickly manufacturing faked cards to make large cash withdrawals from ATMs. And the consumer’s cash goes missing until a theft is reported and reimbursement carried out, which can take several days.</p>
<p>“You should always be watching your statements for unauthorized transactions but right now people should be extra vigilant,” says Steve Coggeshall chief technology officer at ID Analytics.</p>
<p>Retailers are also uniquely exposed. Some 46 states have now enacted data breach disclosure laws that require merchants and payment card issuing banks and credit unions to notify customers whose card numbers are stolen.</p>
<p>Many of these data loss disclosure laws impose stiff fines if notifications are not done in a timely manner, says Ted Julian, of Co3, a Cambridge, Mass.-based start-up that helps retailers manage the repercussions of credit card theft.</p>
<p>States could pursue a windfall in fines levied against merchants and card-issuing banks and credit unions who are slow to notify consumers that their credit or debit card number is in criminals&#8217; hands. &#8220;Merchants are definitely on the hook for these state disclosures, because they are the ones who have the consumer relationship,&#8221; Julian says.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/secrecy-shrouds-breach-payment-cards-processor/" rel="bookmark" class="crp_title">Secrecy shrouds breach of possibly a third payment cards processor</a></li><li><a href="http://lastwatchdog.com/heartland-payment-systems-merchants-cyberthieves/" rel="bookmark" class="crp_title">Heartland Payment Systems asks merchants to help stop cyberthieves</a></li><li><a href="http://lastwatchdog.com/pci-compliance-ineffective-stopping-data-thieves/" rel="bookmark" class="crp_title">PCI compliance often ineffective in stopping data thieves</a></li><li><a href="http://lastwatchdog.com/lack-of-transparency-on-heartland-breach/" rel="bookmark" class="crp_title">Lack of transparency on Heartland breach</a></li><li><a href="http://lastwatchdog.com/visa-risk-chief/" rel="bookmark" class="crp_title">Visa risk chief calls for increased use of smart cards, password tokens</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/merchants-consumers-hook-due-breach/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Caller ID spoofers raid online banking accounts</title>
		<link>http://lastwatchdog.com/caller-id-spoofers-raid-online-banking-accounts/</link>
		<comments>http://lastwatchdog.com/caller-id-spoofers-raid-online-banking-accounts/#comments</comments>
		<pubDate>Fri, 16 Mar 2012 11:56:48 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12189</guid>
		<description><![CDATA[By Byron Acohido, USA TODAY, 16March2012, P1B Cyberthieves are stepping up phone-calling scams to pilfer from consumers’ online banking accounts. In the second half of 2011, Pindrop Security detected more than 1 million fraudulent calls, including 189,439 in December, a 52% spike from the 124,258 calls tracked in July, according to a first of its [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12190" href="http://lastwatchdog.com/caller-id-spoofers-raid-online-banking-accounts/1203116_spooftel223/"><img class="alignleft size-full wp-image-12190" title="1203116_spooftel223" src="http://lastwatchdog.com/wp/wp-content/uploads/1203116_spooftel223.jpg" alt="" width="225" height="105" /></a>By Byron Acohido, USA TODAY, 16March2012, <a href="http://www.usatoday.com/tech/news/story/2012-03-14/caller-id-phone-spoofing/53554430/1">P1B</a></p>
<p>Cyberthieves are stepping up phone-calling scams to pilfer from consumers’ online banking accounts.</p>
<p>In the second half of 2011, Pindrop Security detected more than 1 million fraudulent calls, including 189,439 in December, a 52% spike from the 124,258 calls tracked in July, according to a first of its kind reporte released Thursday.</p>
<p>“Mobile is a growth area for online banking fraud,” says Stan Stahl, president of the Los Angeles chapter of the Information Systems Security Association, a tech professionals group that’s working with financial institutions to stem all forms of online banking fraud.</p>
<p><object id="flashObj" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="360" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="bgcolor" value="#FFFFFF" /><param name="flashVars" value="videoId=1508469961001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="base" value="http://admin.brightcove.com" /><param name="seamlesstabbing" value="false" /><param name="allowFullScreen" value="true" /><param name="swLiveConnect" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" /><param name="name" value="flashObj" /><param name="flashvars" value="videoId=1508469961001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="allowfullscreen" value="true" /><embed id="flashObj" type="application/x-shockwave-flash" width="425" height="360" src="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" name="flashObj" allowscriptaccess="always" swliveconnect="true" allowfullscreen="true" seamlesstabbing="false" base="http://admin.brightcove.com" flashvars="videoId=1508469961001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" bgcolor="#FFFFFF"></embed></object></p>
<p>Many of the bogus calls were tied to caller ID spoofing – a way to place a phone call that causes the recipient’s phone to display a caller ID number that appears to originate from a trusted party.</p>
<p>Phone call spoofers often begin by luring a cell phone user into divulging account information via an automated call or text message that appears to come from the user’s bank. Next, the crooks call the bank, spoofing a patron’s phone number and correctly answering security questions to trick the customer rep into carrying out fraudulent cash transfers or issuing new credit cards to mailing addresses they control.</p>
<p>The use of spoofed calls to hijack online banking accounts is one slice of a thriving, multi-billion dollar online banking fraud industry. Cyber robbers also <a href="http://lastwatchdog.com/ten-fold-rise-malicious-ads-bedevils-publishers-consumers/">spread poisoned links on webpages </a>and in e-mail and on social networks to take control of consumers’ PCs. They then embed programs, called banking Trojans, that let them stealthily tap into online banking accounts.</p>
<p><strong>Billions stolen</strong></p>
<p>Based on cases it has worked on with law enforcement and victim companies, Dell SecureWorks estimates that small- and medium-sized businesses in the U.S. and Europe lose as much $1 billion a year from online banking accounts. The financial services industry contends the security of computing devices is the responsibility of the companies and often <a href="http://lastwatchdog.com/perils-online-banking-cyberrobbers-escalate-attacks/">do not reimburse </a>theft losses from online business accounts.</p>
<p>The financial services industry often does not reimburse such losses. &#8220;We&#8217;d expect business owners to be a bit more savvy and have more resources at their fingertips,&#8221; says Carol Kaplan, spokeswoman for the American Bankers Association. &#8220;That doesn&#8217;t mean we&#8217;re not seriously concerned about the problems small businesses are having, and there continues to be huge gobs of investment into shoring up security.&#8221;</p>
<p>Results of an ABA survey of 95 financial institutions, released exclusively to USA TODAY, show the number of commercial account takeovers by cybercrooks rose 260% in 2011 vs. 2009. However, the average loss per victimized company decreased 92% during the same period.</p>
<p>&#8220;Financial institutions are becoming more effective at stopping illicit transactions from being executed,&#8221; says Doug Johnson, the ABA&#8217;s vice president of risk management policy.</p>
<p>Individual consumers are getting hit too, but typically get made whole by the banks &#8212; if they catch and report theft from online accounts quickly. In those instances, the banks bear the loss.</p>
<p>“It is incredibly difficult to measure losses from consumer accounts, but it’s probably higher than $1 billion a year,” says Dale Gonzalez, Dell SecureWorks mobile product strategist. Droves of less-skilled cyberthieves, equipped with free, easy-to-use account hijacking tools “are absolutely targeting consumers,” Gonzalez says.</p>
<p>Spoofed call attacks, in particular, are catching on because they are easy to do and difficult to defend, law enforcement  officials and security analysts say. Consumers’ names, phone numbers and e-mail can be purchased inexpensively from hackers who specialize in cracking into databases, like the gang that<a href="http://lastwatchdog.com/zappos-hack-shows-risk-e-mail-account-username/"> swiped 24 million customer records </a>from online  shoe retailer Zappos.</p>
<p><strong>Easy pickings</strong></p>
<p>What’s more caller ID spoofing techniques are trivial to master; free and cheap automated programs are readily available on the Internet. In the last six months of 2011, bogus calls were placed in connection with online banking scams directed at 30 of the 50 largest financial institutions in the U.S., says Pindrop CEO Vijay Balasubramanian.</p>
<p>“We are continuing to see this rising trend,” says Balasubramanian. “There appears to be a network effect as word of successful scams gets relayed to other fraudsters.”</p>
<p>ISSA’s Stahl says tech companies and banks need to do more to stem the tide of attacks. Part of the solution: being more transparent to small businesses and consumers about the risks of online banking.</p>
<p>“Online bank fraud is at epidemic levels, there’s no question about that,” Stahl says. “Right now there is inadequate security against the many kinds of attacks that lead to online banking fraud, and that’s only going to get worse, not better.”</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/video-documentary-reveals-details-inception-pc-viruses/" rel="bookmark" class="crp_title">Video documentary reveals details of the inception of PC viruses</a></li><li><a href="http://lastwatchdog.com/video-examines-poisoned-search-results-kate-middelton/" rel="bookmark" class="crp_title">Video examines poisoned search results for Kate Middleton</a></li><li><a href="http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/" rel="bookmark" class="crp_title">Mobile devices carry intrinsic security flaws</a></li><li><a href="http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/" rel="bookmark" class="crp_title">Angry Birds and other Facebook apps score low on privacy</a></li><li><a href="http://lastwatchdog.com/visa-risk-chief/" rel="bookmark" class="crp_title">Visa risk chief calls for increased use of smart cards, password tokens</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/caller-id-spoofers-raid-online-banking-accounts/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Cyber attacks on mobile devices gain meaningful traction</title>
		<link>http://lastwatchdog.com/cyber-attacks-mobile-devices-gain-meaningful-traction/</link>
		<comments>http://lastwatchdog.com/cyber-attacks-mobile-devices-gain-meaningful-traction/#comments</comments>
		<pubDate>Wed, 07 Mar 2012 20:14:10 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12172</guid>
		<description><![CDATA[Something the security community has been fretting about for a few years, seems to have finally arrived in earnest: cybercriminals are going mobile. Nearly one in five mobile phone users have experienced some type of security threat with their device. That&#8217;s the finding of a Cloudmark survey of 1,000 cellphone users, scheduled to be released [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12173" href="http://lastwatchdog.com/cyber-attacks-mobile-devices-gain-meaningful-traction/ipad_in_use175px/"><img class="alignleft size-full wp-image-12173" title="iPad_in_use175px" src="http://lastwatchdog.com/wp/wp-content/uploads/iPad_in_use175px.jpg" alt="" width="175" height="131" /></a>Something the security community has been <a href="http://lastwatchdog.com/case-tighter-security-internet-connected-devices/">fretting</a> about for a few years, seems to have finally arrived in earnest: cybercriminals are <a href="http://www.usatoday.com/money/industries/technology/story/2012-03-05/mobile-security-threats/53357486/1">going mobile.</a></p>
<p>Nearly one in five mobile phone users have experienced some type of security threat with their device. That&#8217;s the finding of a Cloudmark survey of 1,000 cellphone users, scheduled to be released Tuesday.</p>
<p>Poisoned text messages, nearly non-existent in the U.S. a few years ago, grew 300% in 2010 and 400% in 2011, accounting for about 1% of all text messages. &#8220;We&#8217;ve gone from totally clean to a trickle,&#8221; says Rachel Kinoshito, head of Cloudmark&#8217;s security operations. &#8220;Most people are seeing about one a month.&#8221;</p>
<p><object id="flashObj" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="360" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="bgcolor" value="#FFFFFF" /><param name="flashVars" value="videoId=1485431907001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="base" value="http://admin.brightcove.com" /><param name="seamlesstabbing" value="false" /><param name="allowFullScreen" value="true" /><param name="swLiveConnect" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" /><param name="name" value="flashObj" /><param name="flashvars" value="videoId=1485431907001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="allowfullscreen" value="true" /><embed id="flashObj" type="application/x-shockwave-flash" width="425" height="360" src="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" name="flashObj" allowscriptaccess="always" swliveconnect="true" allowfullscreen="true" seamlesstabbing="false" base="http://admin.brightcove.com" flashvars="videoId=1485431907001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" bgcolor="#FFFFFF"></embed></object></p>
<p>That foothold is part of a broader concern. Variations of scams that infest the Internet, through PC browsers, have begun spreading on a meaningful scale through mobile devices. And it looks like the bad guys are just getting warmed up.</p>
<p>One type of poison text message involves tricking people into signing up for worthless services for which they get billed $9.99 a month. Another type lures them into doing a survey to win a free iPhone or gift card. Instead, the attacker gets them to divulge payment card or other info useful for identity-theft scams.</p>
<p>&#8220;Malicious attacks have exploded well beyond e-mail, and we are very aware of their move to mobile,&#8221; says Jacinta Tobin, a board member of the Messaging Anti-Abuse Working Group, an industry group combating the problem.</p>
<p>Meanwhile, hackers are repurposing skills honed in the PC world to attacks on specific mobile devices. Particularly, handsets using Google&#8217;s Android operating system are frequently the target of hackers. In December, anti-virus company F-Secure tracked down 1,639 unique malicious Android apps — disguised as free apps and circulating on websites across the Internet. That&#8217;s up from 48 in January 2011.</p>
<p>One type offered and delivered a free copy of the popular Angry Birds game. But the victim is also unwittingly signed up for a premium-rate texting service and charged an extra $10 a month on his or her phone bill, says F-Secure researcher Sean Sullivan.</p>
<p>Network security company Juniper Networks says the pool of bad apps it has been tracking swelled 86% in February from January. Nearly half of the poisoned Android apps analyzed by Juniper were classic spyware, says Dan Hoffman, head of Juniper&#8217;s mobile security business.</p>
<p>&#8220;We&#8217;ve identified malware that can steal credentials from e-mail and mobile banking applications,&#8221; Hoffman says. &#8220;These attacks can be devastating.&#8221;</p>
<p>The online industry is on high alert. The working group— whose members include AT&amp;T, Verizon, Comcast, Facebook, PayPal and Time Warner— convened in San Francisco last month to join forces on defending new mobile threats.</p>
<p>&#8220;We need to stay ahead of what&#8217;s happening with mobile abuse, social networking abuse and malware,&#8221; says Tobin. &#8220;It makes sense for us to collaborate across all these channels.&#8221;</p>
<p>For more information about reprints &amp; permissions, visit our FAQ&#8217;s. To report corrections and clarifications, contact Standards Editor Brent Jones. For publication consideration in the newspaper, send comments to letters@usatoday.com. Include name, phone number, city and state for verification. To view our corrections, go to corrections.usatoday.com.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/video-documentary-reveals-details-inception-pc-viruses/" rel="bookmark" class="crp_title">Video documentary reveals details of the inception of PC viruses</a></li><li><a href="http://lastwatchdog.com/video-examines-poisoned-search-results-kate-middelton/" rel="bookmark" class="crp_title">Video examines poisoned search results for Kate Middleton</a></li><li><a href="http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/" rel="bookmark" class="crp_title">Mobile devices carry intrinsic security flaws</a></li><li><a href="http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/" rel="bookmark" class="crp_title">Angry Birds and other Facebook apps score low on privacy</a></li><li><a href="http://lastwatchdog.com/visa-risk-chief/" rel="bookmark" class="crp_title">Visa risk chief calls for increased use of smart cards, password tokens</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/cyber-attacks-mobile-devices-gain-meaningful-traction/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Will Congress make Obama&#8217;s Privacy Bill of Rights law?</title>
		<link>http://lastwatchdog.com/congress-obamas-privacy-bill-rights-law/</link>
		<comments>http://lastwatchdog.com/congress-obamas-privacy-bill-rights-law/#comments</comments>
		<pubDate>Thu, 23 Feb 2012 15:43:18 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[For technologists]]></category>
		<category><![CDATA[Obama watch]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Steps forward]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12139</guid>
		<description><![CDATA[Getting a divided Congress to pass any hard-edged privacy legislation is the next big hurdle President Obama faces in getting his Consumer Privacy Bill of Rights made the law of the land. &#8220;We urge the Administration to ensure that it carries out this process in a fair and transparent manner, and that consumer voices are [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12140" href="http://lastwatchdog.com/congress-obamas-privacy-bill-rights-law/congress_interior175px/"><img class="alignleft size-full wp-image-12140" title="Congress_interior175px" src="http://lastwatchdog.com/wp/wp-content/uploads/Congress_interior175px.jpg" alt="" width="175" height="111" /></a>Getting a divided Congress to pass any hard-edged privacy legislation is the next big hurdle President Obama faces in getting his Consumer Privacy Bill of Rights made the <a href="http://content.usatoday.com/communities/technologylive/post/2012/02/will-obamas-privacy-bill-of-rights-become-law/1">law of the land</a>.</p>
<p>&#8220;We urge the Administration to ensure that it carries out this process in a fair and transparent manner, and that consumer voices are heard and acted on,&#8221; Susan Grant, Director of Consumer Protection at Consumer Federation of America, adds:</p>
<p>In an unusual move, the White House convened a press conference at 4:30 p.m. Eastern on Wednesday to<a href="http://lastwatchdog.com/obama-calls-consumer-privacy-bill-rights/"> announce </a>the details, imposing an embargo – which all media outlets accepted without question – to midnight. Here are the seven rights:</p>
<ul>
<li><strong>Individual Control:</strong> Consumers have a right to exercise control over what personal data organizations collect from them and how they use it.</li>
<li><strong>Transparency:</strong> Consumers have a right to easily understandable information about privacy and security practices.</li>
<li><strong>Respect for Context: </strong>Consumers have a right to expect that organizations will collect, use, and disclose personal data in ways that are consistent with the context in which consumers provide the data.</li>
<li><strong>Security:</strong> Consumers have a right to secure and responsible handling of personal data.</li>
<li><strong>Access and Accuracy:</strong> Consumers have a right to access and correct personal data in usable formats, in a manner that is appropriate to the sensitivity of the data and the risk of adverse consequences to consumers if the data are inaccurate.</li>
<li><strong>Focused Collection: </strong>Consumers have a right to reasonable limits on the personal data that companies collect and retain.</li>
<li><strong>Accountability:</strong> Consumers have a right to have personal data handled by companies with appropriate measures in place to assure they adhere to the Consumer Privacy Bill of Rights.</li>
</ul>
<p><strong>Watering down</strong></p>
<div id="attachment_12141" class="wp-caption alignleft" style="width: 102px"><a rel="attachment wp-att-12141" href="http://lastwatchdog.com/congress-obamas-privacy-bill-rights-law/john-simpson92px/"><img class="size-full wp-image-12141" title="John SImpson92px" src="http://lastwatchdog.com/wp/wp-content/uploads/John-SImpson92px.jpg" alt="" width="92" height="134" /></a><p class="wp-caption-text">Simpson</p></div>
<p>&#8220;The real question is how much influence companies like Google, Microsoft, Yahoo and Facebook will have intheir inevitable attempt to water down the rules that are implemented and render them essentially meaningless,&#8221; says John Simpson, spokesman for Consumer Watchdog. &#8221; I am skeptical about the &#8216;multi-stakeholder process&#8217;, but am willing to make a good faith effort to try it.</p>
<p>Simpson and others remain concerned about the Commerce Department&#8217;s role in shaping consumer privacy protections. &#8221; Commerce&#8217;s job — quite correctly — is to promote the interests of business, not protect consumers,&#8221; he says. &#8220;If nothing else, the report demonstrates the growing concern about online privacy. Perhaps this is one of the few issues where true bipartisan action will be possible this year.&#8221;</p>
<p>As proposed by the White House, the bill of recognizes the need to for heightened protections for children and teens on the Internet.</p>
<p>&#8220;If we want to ensure that the Internet economy continues to be strong and vital, consumers need to be able to trust that the information collected about them will not be misused. This announcement sets the stage for that to begin to happen,&#8221; says Ellen Bloom, Senior Director of Federal Policy for Consumers Union, the policy and advocacy arm of Consumer Reports.</p>
<p><strong>Power moves</strong></p>
<p>The next steps will entail Washington D.C.-style power brokering, says Jeffrey Chester, executive director of the Center for Digital Democracy.</p>
<div id="attachment_11936" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-11936" href="http://lastwatchdog.com/google-execs-give-closed-door-briefing-ceo-stays/jeffrey_chester_90px-8/"><img class="size-full wp-image-11936" title="jeffrey_chester_90px" src="http://lastwatchdog.com/wp/wp-content/uploads/jeffrey_chester_90px7.jpg" alt="" width="90" height="122" /></a><p class="wp-caption-text">Chester</p></div>
<p>&#8220;The new framework largely depends on the development of voluntary codes of conduct, to be negotiated between consumer groups and companies like Google, Facebook, Microsoft, Yahoo and others, Chester says. &#8220;Consumers groups will engage in these negotiations in good faith.  But we cannot accept any &#8216;deal&#8217; that doesn’t really protect consumers, and merely allows the data-profiling status quo to remain.&#8221;</p>
<p>Another part of the White House privacy framework calls for the Digital Advertising Alliance to add to its efforts to self-police its members by improving  an existing Do Not Track mechanism many of its members already make available to consumers.</p>
<p>&#8221;   The plan by the DAA to add Do-Not-Track to its self-regulatory system could derail a promising privacy effort by the Worldwide Web Consortium standards group (W3C) that is being designed to give consumers greater control over data collection,&#8221; contends Chester. &#8220;The new DAA scheme will enable companies to continue to collect profiling data on users, and merely prevent the delivery of targeted ads. DAA members are terrified about the development of a DNT system with teeth, which would stop so much data collection, profiling and tracking.&#8221;</p>
<p><strong>California cracks down</strong></p>
<p>On a parallel track, the Associated Press <a href="http://www.usatoday.com/tech/news/story/2012-02-22/california-mobile-apps-privacy/53214500/1">reports</a> that  California is cracking down on invasive mobile apps.</p>
<p>California Attorney General Kamala Harris is calling for the tech giants vying in the mobile space &#8212; Apple, Google, Microsoft, Amazon Research In Motion and Hewlett-Packard  &#8212; as well as thousands of mobile app developers to give people advance warning before extracting and storing sensitive information from smartphones and tablet PCs.</p>
<p>Harris began discussing the need for better privacy protections with six powerful companies that have shaped the mobile computing market, spawning nearly 1 million applications over the past four years, the AP reports.</p>
<p>&#8220;We are assuming everyone is going to cooperate in good faith and not get cute,&#8221; Harris told AP reporter Mike Liedtke.</p>
<p>Harris , a Democrat, is taking her stand out west, at the same time fellow Californian, Mary Kay Bono, a Republican Congresswoman, and several other Republican lawmakers are clamoring for more details about Google and Facebook conduct online tracking. The tech giants put themselves in the spotlight by recently announcing new initiatives to extend how they index and cross-reference data about what consumer do on their PCs and mobile devices.</p>
<p>Google has begun rolling out a new user privacy policy that will make it easier for the search giant to correlate information about anyone who uses multiple Google services, such as Google search, plus Gmail, Google Apps, YouTube, Picasa or Google+.  Facebook is rolling out a new user interface &#8212; Timeline &#8212; that makes it easier to search and digest chronologically-assembled data about a person. Each is trying to out do each other in a race to sell more online advertising. Each insists  they  provide consumers with ample choice and control over such tracking data.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/obama-calls-consumer-privacy-bill-rights/" rel="bookmark" class="crp_title">Obama calls for a Consumer Privacy Bill of Rights</a></li><li><a href="http://lastwatchdog.com/white-house-issues-historic-call-u-s-privacy-bill/" rel="bookmark" class="crp_title">White House issues historic call for U.S. privacy bill of rights</a></li><li><a href="http://lastwatchdog.com/privacy-advocates-push-google-led-effort-kill-online/" rel="bookmark" class="crp_title">Privacy advocates push back against Google-led effort to kill online advertising rules</a></li><li><a href="http://lastwatchdog.com/google-execs-give-closed-door-briefing-ceo-stays/" rel="bookmark" class="crp_title">Google execs to give closed-door briefing, CEO stays home</a></li><li><a href="http://lastwatchdog.com/critics-house-do-not-track-hearing-skewed-consumers/" rel="bookmark" class="crp_title">Critics say House do-not-track hearing skewed against consumers</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/congress-obamas-privacy-bill-rights-law/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

