<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Last Watchdog &#187; Imminent threats</title>
	<atom:link href="http://lastwatchdog.com/category/imminent-threat/feed/" rel="self" type="application/rss+xml" />
	<link>http://lastwatchdog.com</link>
	<description>on Internet security by Byron Acohido</description>
	<lastBuildDate>Wed, 25 Apr 2012 20:37:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>Angry Birds and other Facebook apps score low on privacy</title>
		<link>http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/</link>
		<comments>http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/#comments</comments>
		<pubDate>Sun, 22 Apr 2012 20:25:12 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12309</guid>
		<description><![CDATA[A new service that grades how each of Facebook&#8217;s top third-party apps respects consumers&#8217; privacy was released late Sunday by research firm PrivacyChoice. The free tool, Privacyscore for Facebook, spells out privacy policies and tracking practices of more than 200 top Facebook apps, including games, work-related programs and sharing apps. Online tracking is fueling a [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12310" href="http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/angry-birds150px/"><img class="alignleft size-full wp-image-12310" title="angry birds150px" src="http://lastwatchdog.com/wp/wp-content/uploads/angry-birds150px.jpg" alt="" width="150" height="150" /></a>A new service that grades how each of Facebook&#8217;s top third-party apps respects consumers&#8217; privacy was released late Sunday by research firm PrivacyChoice. The free tool, <a href="http://apps.facebook.com/privacyscoreapps/">Privacyscore for Facebook</a>, spells out privacy policies and tracking practices of more than 200 top Facebook apps, including games, work-related programs and sharing apps.</p>
<p>Online tracking is fueling a heated national debate over whether new do-not-track laws are needed to safeguard consumers&#8217; online privacy. Leaders in the online advertising industry use a version of Privacyscore to self-police the tracking practices of online advertising networks, and thus head off new laws. Privacy experts welcomed the consumer version.</p>
<p><object id="flashObj" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="360" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="bgcolor" value="#FFFFFF" /><param name="flashVars" value="videoId=1573851130001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="base" value="http://admin.brightcove.com" /><param name="seamlesstabbing" value="false" /><param name="allowFullScreen" value="true" /><param name="swLiveConnect" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" /><param name="name" value="flashObj" /><param name="flashvars" value="videoId=1573851130001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="allowfullscreen" value="true" /><embed id="flashObj" type="application/x-shockwave-flash" width="425" height="360" src="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" name="flashObj" allowscriptaccess="always" swliveconnect="true" allowfullscreen="true" seamlesstabbing="false" base="http://admin.brightcove.com" flashvars="videoId=1573851130001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" bgcolor="#FFFFFF"></embed></object><br />
&#8220;This certainly is going to be a useful tool for consumers, but it may actually be even more useful in pushing application developers, who don&#8217;t like getting poor grades, to look more closely at their own privacy practices,&#8221; says Jules Polonetsky, director of the Future of Privacy Forum, a Washington, D.C., think tank on data security.</p>
<p>Facebook&#8217;s pervasive Web presence comes with &#8220;a responsibility to hold people who are developing apps on their platform accountable for the (privacy) assertions that they&#8217;re making,&#8221; says Craig Spiezle, executive director of the Online Trust Alliance.</p>
<p>Facebook&#8217;s David Swain noted that the company requires app developers to agree to its privacy policies. &#8220;If we find an app has violated our policies … we take action,&#8221; Swain says.</p>
<p>According to PrivacyChoice, 140 different tracking entities routinely collect information about users of the top Facebook apps. Trackers can correlate that data to profiles of individuals&#8217; browsing behavior across multiple Web pages in order to deliver more relevant ads. &#8220;It&#8217;s up to users to know the privacy risk of sharing personal data with apps,&#8221; says Jim Brock, PrivacyChoice founder and CEO.</p>
<p>Privacyscore&#8217;s top score is 100. Deductions are made for sharing data with an excessive number of tracking entities, failing to honor deletion requests, failing to provide an opt-out choice or storing consumer data for long periods.</p>
<p>Gamemaker Zynga, for instance, registers an overall score of 82 for 17 Facebook games. The game Slingo, with 17 million players, scores 80, losing points partly because it connects to 59 trackers. Zynga general counsel Reggie Davis says Zynga welcomes tools such as Privacyscore. And Zynga&#8217;s online tutorial, PrivacyVille, rewards its users for learning more about the company&#8217;s privacy policies.</p>
<p>—</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/video-documentary-reveals-details-inception-pc-viruses/" rel="bookmark" class="crp_title">Video documentary reveals details of the inception of PC viruses</a></li><li><a href="http://lastwatchdog.com/video-examines-poisoned-search-results-kate-middelton/" rel="bookmark" class="crp_title">Video examines poisoned search results for Kate Middleton</a></li><li><a href="http://lastwatchdog.com/cyber-attacks-mobile-devices-gain-meaningful-traction/" rel="bookmark" class="crp_title">Cyber attacks on mobile devices gain meaningful traction</a></li><li><a href="http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/" rel="bookmark" class="crp_title">Mobile devices carry intrinsic security flaws</a></li><li><a href="http://lastwatchdog.com/visa-risk-chief/" rel="bookmark" class="crp_title">Visa risk chief calls for increased use of smart cards, password tokens</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Workarounds arise as Apple readies cure for Mac infections</title>
		<link>http://lastwatchdog.com/workarounds-arise-apple-readies-cure-mac-infections/</link>
		<comments>http://lastwatchdog.com/workarounds-arise-apple-readies-cure-mac-infections/#comments</comments>
		<pubDate>Thu, 12 Apr 2012 20:39:12 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Steps forward]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12278</guid>
		<description><![CDATA[If you suspect your Mac might be one of the 600,000 or so computers infected with the Flashback virus, Finnish antivirus company F-Secure has issued a free tool that detects and removes the nasty infection. Another detection tool you can use has been made available by Russian antivirus firm Kaspersky. Meanwhile, Apple has issued a [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12279" href="http://lastwatchdog.com/workarounds-arise-apple-readies-cure-mac-infections/macs_duo150px/"><img class="alignleft size-full wp-image-12279" title="Macs_duo150px" src="http://lastwatchdog.com/wp/wp-content/uploads/Macs_duo150px.jpg" alt="" width="150" height="143" /></a>If you suspect your Mac might be one of the 600,000 or so computers<a href="http://lastwatchdog.com/milestone-botnet-comprised-600000-infected-macs/"> infected with the Flashback virus, </a>Finnish antivirus company F-Secure has<a href="http://www.f-secure.com/weblog/archives/00002346.html"> issued a free tool </a>that detects and removes the nasty infection.</p>
<p>Another detection tool you can use has been<a href="http://flashbackcheck.com/"> made available</a> by Russian antivirus firm Kaspersky. Meanwhile, Apple has <a href="http://support.apple.com/kb/HT5244">issued a statement i</a>ndicating that it is continuing to work on an offical detection and innoculation tool.</p>
<p>It&#8217;s not just individual Mac owners who ought to take heed. Network security firm Lancope says companies with employees who use Macs would be wise to check for infected Apple computing devices.</p>
<div id="attachment_12280" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-12280" href="http://lastwatchdog.com/workarounds-arise-apple-readies-cure-mac-infections/jody-ma-kissling90px/"><img class="size-full wp-image-12280" title="Jody Ma Kissling90px" src="http://lastwatchdog.com/wp/wp-content/uploads/Jody-Ma-Kissling90px.jpg" alt="" width="90" height="130" /></a><p class="wp-caption-text">Kissling</p></div>
<p>&#8220;Enterprises should also bolster their defenses,&#8221; says Lancope vice president Jody Ma Kissling. &#8220;As the market share for Macs continues to increase, end users, corporations and Apple itself must all be prepared for a subsequent rise in attacks targeting Apple&#8217;s Mac OS X.&#8221;</p>
<p>Neil Roiter, research director at Corero Network Security says &#8220;cyber criminals now consider Macs profitable targets. Mac users should protect their computers with antivirus software, encrypt sensitive information and follow the common-sense advice not to click on links or open email attachments from unknown sources.&#8221;</p>
<p><object id="flashObj" width="425" height="360" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9,0,47,0"><param name="movie" value="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" /><param name="bgcolor" value="#FFFFFF" /><param name="flashVars" value="videoId=1554145984001&#038;playerID=35146470001&#038;playerKey=AQ~~,AAAACC1laJk~,tMO2d6O4midjZXg1vCvdWWjRZdwrH9hC&#038;domain=embed&#038;dynamicStreaming=true" /><param name="base" value="http://admin.brightcove.com" /><param name="seamlesstabbing" value="false" /><param name="allowFullScreen" value="true" /><param name="swLiveConnect" value="true" /><param name="allowScriptAccess" value="always" /><embed src="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" bgcolor="#FFFFFF" flashVars="videoId=1554145984001&#038;playerID=35146470001&#038;playerKey=AQ~~,AAAACC1laJk~,tMO2d6O4midjZXg1vCvdWWjRZdwrH9hC&#038;domain=embed&#038;dynamicStreaming=true" base="http://admin.brightcove.com" name="flashObj" width="425" height="360" seamlesstabbing="false" type="application/x-shockwave-flash" allowFullScreen="true" swLiveConnect="true" allowScriptAccess="always" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></embed></object></p>
<p>Roger Thompson, chief emerging threats researcher at vendor-neutral testing and certification firm ICSA Labs, explains the significance of the emergence of a major botnet comprised entirely of Macs.</p>
<p>He observes that Mac infections were considered rare for much of the past two decades &#8220;as a natural consequence of relative market opportunity for the bad guys. Put another way, there were way more PCs than Macs, so there was simply more opportunity for a return on their development and marketing effort.&#8221;</p>
<p>What the existence of a massive Mac botnet highlights, Thompson says, is that &#8220;Mac malware is not just a reality, but is now a genuine problem. The issue is that for a decade, Apple has made a point of telling users that they had no malware problem, and the result of that is that Mac users have no antibodies, when it comes to malware. They don&#8217;t expect it, and too many people will click on, and install, anything.&#8221;</p>
<p>The bottom line for Mac users: they will have to install and keep current antivirus programs and make sure all application updates, for things like Java, iTunes and Adobe Flash are quickly installed, just like Windows users.</p>
<p>&#8220;There will soon be a name for Mac users who are not doing this: victims,&#8221; says Thompson.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/video-documentary-reveals-details-inception-pc-viruses/" rel="bookmark" class="crp_title">Video documentary reveals details of the inception of PC viruses</a></li><li><a href="http://lastwatchdog.com/video-examines-poisoned-search-results-kate-middelton/" rel="bookmark" class="crp_title">Video examines poisoned search results for Kate Middleton</a></li><li><a href="http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/" rel="bookmark" class="crp_title">Angry Birds and other Facebook apps score low on privacy</a></li><li><a href="http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/" rel="bookmark" class="crp_title">Mobile devices carry intrinsic security flaws</a></li><li><a href="http://lastwatchdog.com/cyber-attacks-mobile-devices-gain-meaningful-traction/" rel="bookmark" class="crp_title">Cyber attacks on mobile devices gain meaningful traction</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/workarounds-arise-apple-readies-cure-mac-infections/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Mobile devices carry intrinsic security flaws</title>
		<link>http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/</link>
		<comments>http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/#comments</comments>
		<pubDate>Mon, 09 Apr 2012 17:57:37 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Steps forward]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12252</guid>
		<description><![CDATA[By Byron Acohido, USA TODAY, 09Apr2012, P1B Those cool mobile devices beloved by consumers carry deep-rooted security flaws that are only now being discovered and addressed. That’s the upshot of two recent deep examinations of popular mobile devices. The findings highlight how designers of the current generation of smartphones and tablet PCs failed to fully [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12253" href="http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/smartphone-array150px/"><img class="alignleft size-full wp-image-12253" title="smartphone array150px" src="http://lastwatchdog.com/wp/wp-content/uploads/smartphone-array150px.jpg" alt="" width="150" height="140" /></a>By Byron Acohido, USA TODAY, 09Apr2012,<a href="http://www.usatoday.com/tech/news/story/2012-04-08/smartphone-security-flaw/54122468/1"> P1B</a></p>
<p>Those cool mobile devices beloved by consumers carry deep-rooted security flaws that are only now being discovered and addressed.</p>
<p>That’s the upshot of two recent deep examinations of popular mobile devices. The findings highlight how designers of the current generation of smartphones and tablet PCs failed to fully account for the security and privacy implications.</p>
<p>“Today&#8217;s smartphones and tablet devices perform the same functions as a PC,” says Dan Hoffman, chief of mobile security at Juniper Networks.“However, the vast majority of devices lack security software and mistakenly rely upon the operating system to keep people safe.”</p>
<p><object id="flashObj" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="360" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="bgcolor" value="#FFFFFF" /><param name="flashVars" value="videoId=1537973447001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="base" value="http://admin.brightcove.com" /><param name="seamlesstabbing" value="false" /><param name="allowFullScreen" value="true" /><param name="swLiveConnect" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" /><param name="name" value="flashObj" /><param name="flashvars" value="videoId=1537973447001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="allowfullscreen" value="true" /><embed id="flashObj" type="application/x-shockwave-flash" width="425" height="360" src="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" name="flashObj" allowscriptaccess="always" swliveconnect="true" allowfullscreen="true" seamlesstabbing="false" base="http://admin.brightcove.com" flashvars="videoId=1537973447001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" bgcolor="#FFFFFF"></embed></object></p>
<p>In one study, Cryptography Research showed how it is possible to eavesdrop on any smartphone or tablet PC as it uses cryptographic keys to protect sensitive operations, such as when a mobile device is being used to make a purchase, conduct online banking or access a company’s virtual private network.</p>
<p>The secret keys can be deciphered, enabling a criminal to use them to access a financial account or a company network, says Benjamin Jun, Cryptography Research’s chief technology officer.</p>
<div id="attachment_12254" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-12254" href="http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/benjamin-jun90px/"><img class="size-full wp-image-12254" title="Benjamin Jun90px" src="http://lastwatchdog.com/wp/wp-content/uploads/Benjamin-Jun90px.jpg" alt="" width="90" height="118" /></a><p class="wp-caption-text">Jun</p></div>
<p>“These type of attacks do not require the device to be modified and there is usually no observable sign that an attack is in progress,” Jun says.</p>
<p>Cryptography Research is “working with one of the major smartphone and table companies right now to put countermeasures in,” Jun says. No known actual attacks have occurred, he says.</p>
<p>In another theoretical study, researchers at security firm McAfee, a division of Intel, demonstrated several ways to remotely hack into Apple iOS, the operating system for iPads and iPhones.</p>
<p>McAfee’s research team remotely activated device microphones and recorded conversations taking place in the vicinity of the hacked device. They also stole secret keys and passwords, and were able to pilfer sensitive data, including call histories, e-mail and text messages.</p>
<p>“This attack method shows ways that advanced attackers can compromise and control devices indefinitely,” says Ryan Permeh, McAfee’s principal security architect. “This can be done with absolutely no indication to the device user.”</p>
<p>Apple spokeswoman Trudy Muller declined comment.</p>
<p>Security experts and law enforcement officials anticipate that cybergangs will accelerate actual attacks as consumers and companies begin to rely more heavily on mobile devices for shopping, banking and working.</p>
<p>“Responsibility for addressing these security concerns is far reaching,” says Hoffman. “The broader security community needs to assist in providing all users the highest-level of protection.”</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/video-documentary-reveals-details-inception-pc-viruses/" rel="bookmark" class="crp_title">Video documentary reveals details of the inception of PC viruses</a></li><li><a href="http://lastwatchdog.com/video-examines-poisoned-search-results-kate-middelton/" rel="bookmark" class="crp_title">Video examines poisoned search results for Kate Middleton</a></li><li><a href="http://lastwatchdog.com/cyber-attacks-mobile-devices-gain-meaningful-traction/" rel="bookmark" class="crp_title">Cyber attacks on mobile devices gain meaningful traction</a></li><li><a href="http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/" rel="bookmark" class="crp_title">Angry Birds and other Facebook apps score low on privacy</a></li><li><a href="http://lastwatchdog.com/visa-risk-chief/" rel="bookmark" class="crp_title">Visa risk chief calls for increased use of smart cards, password tokens</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Why Apple needs to be more forthcoming with patching</title>
		<link>http://lastwatchdog.com/apple-forthcoming-patching/</link>
		<comments>http://lastwatchdog.com/apple-forthcoming-patching/#comments</comments>
		<pubDate>Fri, 06 Apr 2012 22:39:16 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12246</guid>
		<description><![CDATA[The disclosure of a massive botnet comprised entirely of Macs is serving as a lightning rod for the community of a few hundred top virus hunters who would like to see Apple become more collaborative about defending the Internet against cybercriminals. “Maybe Apple will feel a little of the pain their users are now feeling [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_12247" class="wp-caption alignleft" style="width: 160px"><a rel="attachment wp-att-12247" href="http://lastwatchdog.com/apple-forthcoming-patching/paul-henry150px/"><img class="size-full wp-image-12247" title="Paul Henry150px" src="http://lastwatchdog.com/wp/wp-content/uploads/Paul-Henry150px.jpg" alt="" width="150" height="153" /></a><p class="wp-caption-text">Henry</p></div>
<p>The disclosure of a massive botnet comprised entirely of Macs is serving as a <a href="http://www.zdnet.com/blog/bott/new-mac-malware-epidemic-exploits-weaknesses-in-apple-ecosystem/4726?tag=nl.e539">lightning rod</a> for the community of a few hundred top virus hunters who would like to see Apple become more collaborative about defending the Internet against cybercriminals.</p>
<p>“Maybe Apple will feel a little of the pain their users are now feeling and get serious about being more candid and perhaps more revealing in their patch release notifications,” says Paul Henry, security and forensic analyst at network security company  Lumension,.</p>
<p>Henry notes that calculating the number of infected Macs has been relative easy, since the Trojan “actually sends a copy of each infected Mac&#8217;s UUID to the command and control server.”</p>
<p>Some 300,000 of the 600,000 Macs infected by the Flashback Trojan are located in the U.S., including 274 in Cuppertino, Apple’s hometown in Silicon Valley, according to Tweets from Ivan Sorokin, a malware analyst at Russian antivirus company Dr. Web.</p>
<p>Sorokin used sinkhole technology to redirect the botnet traffic to their own servers to count infected Macs.</p>
<p>Henry says that  “Apple still lacks any urgency in their patch release and in fact, users had to be lucky enough to have checked.</p>
<p>“Simply put, if Apple wants to be taken seriously as an enterprise provider, they need to be more timely and candid about their patches,” Henry continues.  “How else will administrators understand the necessary sense of urgency to prioritize and deal with security issues?”</p>
<p>Apple has been issuing patches roughly once a month, much like Microsoft issues security fixes on the second Tuesday of each month, known as Patch Tuesdsay.</p>
<p>“Apple should take a lesson from Microsoft and formally adopt a monthly process and provide, at minimum, the same level of disclosure users have come to expect from Microsoft,” says Henry.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/patch-tuesday-bonanaza-microsoft-oracle-apple-issue/" rel="bookmark" class="crp_title">Patch bonanaza: Microsoft fixes pile onto updates from Oracle, Apple, Adobe</a></li><li><a href="http://lastwatchdog.com/apple-anti-virus-now-available/" rel="bookmark" class="crp_title">Apple anti-virus now available</a></li><li><a href="http://lastwatchdog.com/milestone-botnet-comprised-600000-infected-macs/" rel="bookmark" class="crp_title">Milestone botnet comprised of 600,000 infected Macs</a></li><li><a href="http://lastwatchdog.com/workarounds-arise-apple-readies-cure-mac-infections/" rel="bookmark" class="crp_title">Workarounds arise as Apple readies cure for Mac infections</a></li><li><a href="http://lastwatchdog.com/sophos-release-fee-mac-antivirus-shows-hackers-targeting/" rel="bookmark" class="crp_title">Welcome to the Wild Wild Web Mac lovers</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/apple-forthcoming-patching/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Milestone botnet comprised of 600,000 infected Macs</title>
		<link>http://lastwatchdog.com/milestone-botnet-comprised-600000-infected-macs/</link>
		<comments>http://lastwatchdog.com/milestone-botnet-comprised-600000-infected-macs/#comments</comments>
		<pubDate>Thu, 05 Apr 2012 19:06:31 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12232</guid>
		<description><![CDATA[This was inevitable. A cyber gang has assembled a botnet comprised of Apple Macs, not Windows PCs. An unpatched portion of Java left Mac users prone to the Flashback Trojan, which causes the machine to quietly report to a command and control server for further instructions. Mac users  can get infected by navigating to a [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12233" href="http://lastwatchdog.com/milestone-botnet-comprised-600000-infected-macs/macbook-pro175px/"><img class="alignleft size-full wp-image-12233" title="MacBook Pro175px" src="http://lastwatchdog.com/wp/wp-content/uploads/MacBook-Pro175px.jpg" alt="" width="175" height="106" /></a>This was inevitable. A cyber gang has <a href="http://content.usatoday.com/communities/technologylive/index#.T33jpo4743Y">assembled a botnet</a> comprised of Apple Macs, not Windows PCs.</p>
<p>An unpatched portion of Java left Mac users prone to the Flashback Trojan, which causes the machine to quietly report to a command and control server for further instructions.</p>
<p>Mac users  can get infected by navigating to a viral web page pre-loaded to deliver a driveby download tuned to exploit this Java vulnerability &#8212; much the same as Windows PC users.</p>
<p>The  Russian antivirus company <a href="http://news.drweb.com/show/?i=2341">Dr. Web</a> says some 600,000 Macs have been infected, several of which include devices based in Cupertino, California, the home of Apple. So if your Mac has been balky lately, this could be the explanation.</p>
<p><strong>Swiss Army knife</strong></p>
<p>Botnets are used to spread spam and infections, participate in denial of service attacks, hijack online bank accounts etc. Botnets are the Swiss Army Knife of cybercrime. And when your machine is performing bot duties, your processing efficiencies naturally get sapped. It was only a matter of time before this common experience of Windows PC users came home to roost with Mac users.</p>
<p>One commenter to <a href="http://arstechnica.com/apple/news/2012/04/flashback-trojan-reportedly-controls-half-a-million-macs-and-counting.ars?comments=1#comments-bar">Ars Technica&#8217;s coverage</a> noted:</p>
<blockquote>
<div>My wife&#8217;s first gen core duo macbook pro hard drive is always  busy, which i thought was due to limited hard drive space. Even after  cleaning out ~15 gigs of space, the OS is slow and often unresponsive,  and the HD is clickety clacking all the time. I sure hope I don&#8217;t have  it. I&#8217;m going to check first thing when I get home. Has anyone&#8217;s machine  here tested positive? If so, does this sound familiar?</div>
</blockquote>
<p>Apple has since patched the Java flaw. F-Secure has supplied details on how to diagnose and<a href="http://www.f-secure.com/v-descs/trojan-downloader_osx_flashback_i.shtml"> fix the problem</a>, but warns that the steps are tricky.</p>
<p><strong>Wake up call</strong></p>
<p>“This  latest wave of infections is a wake-up call to Mac users that their  system is not immune to threats,&#8221; says Mike Geide, senior security researcher at Zscaler ThreatLabZ. &#8220;And the need to follow best security  practices, such as remaining current with patches, is ubiquitous &#8212; it  doesn&#8217;t matter if you’re using Windows, Mac, or even mobile phone.”</p>
<div id="attachment_12234" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-12234" href="http://lastwatchdog.com/milestone-botnet-comprised-600000-infected-macs/dave-marcus90px/"><img class="size-full wp-image-12234" title="Dave Marcus90px" src="http://lastwatchdog.com/wp/wp-content/uploads/Dave-Marcus90px.jpg" alt="" width="90" height="127" /></a><p class="wp-caption-text">Marcus</p></div>
<p>Dave Marcus, director of advanced research and threat intelligence at McAfee Labs, says the existence of a major Mac botnet comes as no surprise. He advises Mac users to do as Windows PC users do: keep antivirus protection and all Apple patches current.</p>
<p>&#8220;Attackers are leveraging years of success from writing PC malware and they&#8217;re doing the same thing in the Mac world,&#8221; says Marcus. &#8220;Cybercriminals will attack any operating system with valuable information, and as the popularity of Macs increase, so will attacks on the Mac platform.&#8221;</p>
<p>&#8211;By Byron Acohido</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/apple-forthcoming-patching/" rel="bookmark" class="crp_title">Why Apple needs to be more forthcoming with patching</a></li><li><a href="http://lastwatchdog.com/workarounds-arise-apple-readies-cure-mac-infections/" rel="bookmark" class="crp_title">Workarounds arise as Apple readies cure for Mac infections</a></li><li><a href="http://lastwatchdog.com/apple-anti-virus-now-available/" rel="bookmark" class="crp_title">Apple anti-virus now available</a></li><li><a href="http://lastwatchdog.com/macs-emerge-virus-carriers-windows-networks/" rel="bookmark" class="crp_title">Macs emerge as virus carriers into Windows networks</a></li><li><a href="http://lastwatchdog.com/apple-macs-targeted-phishers-intensely-windows-pcs/" rel="bookmark" class="crp_title">Apple Macs targeted by phishers just as intensely as Windows PCs</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/milestone-botnet-comprised-600000-infected-macs/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Merchants, consumers on hook due to card processor breach</title>
		<link>http://lastwatchdog.com/merchants-consumers-hook-due-breach/</link>
		<comments>http://lastwatchdog.com/merchants-consumers-hook-due-breach/#comments</comments>
		<pubDate>Fri, 30 Mar 2012 22:40:34 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12212</guid>
		<description><![CDATA[Merchants and consumers could be the big losers in the latest case of hackers cracking the complex systems used to process credit and debit card transactions. Visa and MasterCard acknowledged Friday that they’ve been alerting banks about a major breach of an unnamed payment card processing firm. The Wall Street Journal, citing unnamed sources, named [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12214" href="http://lastwatchdog.com/merchants-consumers-hook-due-breach/card-swipe163px/"><img class="alignleft size-full wp-image-12214" title="Card swipe163px" src="http://lastwatchdog.com/wp/wp-content/uploads/Card-swipe163px.jpg" alt="" width="163" height="146" /></a>Merchants and consumers could be the big losers in the <a href="http://www.usatoday.com/tech/news/story/2012-03-30/mastercard-security-breach/53887854/1">latest case</a> of hackers cracking the complex systems used to process credit and debit card transactions.</p>
<p>Visa and MasterCard acknowledged Friday that they’ve been alerting banks about a major breach of an unnamed payment card processing firm. The<em> Wall Street Journal,</em> citing unnamed sources, <a href="online.wsj.com/article/SB10001424052702303816504577313411294908868.html?mod=WSJ_hp_LEFTTopStories">named </a>Atlanta-based Global Payments as the processor in question.</p>
<p>Global Payments declined interview requests.</p>
<p>Security blogger Brian Krebs, who<a href="http://krebsonsecurity.com/2012/03/mastercard-visa-warn-of-processor-breach/#more-14393"> broke the story</a>, says thieves cracked into the processor’s systems between Jan. 21 and Feb. 25, and may have swiped more than 10 million credit and debit card transactions records, originating from an unknown number of merchants, banks and credit unions.</p>
<div id="attachment_12218" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-12218" href="http://lastwatchdog.com/merchants-consumers-hook-due-breach/avivah_litan90px-3/"><img class="size-full wp-image-12218" title="avivah_Litan90px" src="http://lastwatchdog.com/wp/wp-content/uploads/avivah_Litan90px2.jpg" alt="" width="90" height="134" /></a><p class="wp-caption-text">Litan</p></div>
<p>Gartner banking security analyst Avivah Litan says unverified reports point to a New York City street gang with Central American ties taking over &#8221; an administrative account that was not protected sufficiently.&#8221;</p>
<p>“I’ve spoken with folks in the card business who are seeing signs of this breach mushroom,” says Litan.</p>
<p>MasterCard issued a statement advising cardholders to contact the financial institution that issued their cards with any concerns. Visa emphasized that no Visa systems were breached.</p>
<p>However, criminals know better than to try to waste time on highly defended systems, and have been consistently successful cracking support system. “Sooner or later they find some weakness  in the highly complex chain of systems that they can exploit,” says Geoff Webb, of data security firm Credant Technologies.</p>
<p>Credit card processors have been breached before. Heartland Payment Systems lost 130 million payment card records generated by 250,000 merchants and restaurants in 2008 -2009.</p>
<p>It’s not just card processors that are being targeted.  Last year  hackers stole payment card information for more than <a href="http://lastwatchdog.com/sony-playstation-network-data-breach-timeline/">100 million customers </a>of Sony’s PlayStation Network.</p>
<p>And earlier this year online shoe retailer Zappos disclosed hackers took e-mail and shipping addresses, phone numbers and account passwords for some <a href="http://lastwatchdog.com/zappos-hack-shows-risk-e-mail-account-username/">24 million customers</a>, data useful for identity theft.</p>
<p>“Any business that’s capturing payment data is a target,” says Mark Bower, analyst at  Voltage Security.</p>
<p>Consumers whose debit card account information landed in criminals’ hands with this latest breach are at heightened risk. That’s because gangs are adept at quickly manufacturing faked cards to make large cash withdrawals from ATMs. And the consumer’s cash goes missing until a theft is reported and reimbursement carried out, which can take several days.</p>
<p>“You should always be watching your statements for unauthorized transactions but right now people should be extra vigilant,” says Steve Coggeshall chief technology officer at ID Analytics.</p>
<p>Retailers are also uniquely exposed. Some 46 states have now enacted data breach disclosure laws that require merchants and payment card issuing banks and credit unions to notify customers whose card numbers are stolen.</p>
<p>Many of these data loss disclosure laws impose stiff fines if notifications are not done in a timely manner, says Ted Julian, of Co3, a Cambridge, Mass.-based start-up that helps retailers manage the repercussions of credit card theft.</p>
<p>States could pursue a windfall in fines levied against merchants and card-issuing banks and credit unions who are slow to notify consumers that their credit or debit card number is in criminals&#8217; hands. &#8220;Merchants are definitely on the hook for these state disclosures, because they are the ones who have the consumer relationship,&#8221; Julian says.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/secrecy-shrouds-breach-payment-cards-processor/" rel="bookmark" class="crp_title">Secrecy shrouds breach of possibly a third payment cards processor</a></li><li><a href="http://lastwatchdog.com/heartland-payment-systems-merchants-cyberthieves/" rel="bookmark" class="crp_title">Heartland Payment Systems asks merchants to help stop cyberthieves</a></li><li><a href="http://lastwatchdog.com/pci-compliance-ineffective-stopping-data-thieves/" rel="bookmark" class="crp_title">PCI compliance often ineffective in stopping data thieves</a></li><li><a href="http://lastwatchdog.com/lack-of-transparency-on-heartland-breach/" rel="bookmark" class="crp_title">Lack of transparency on Heartland breach</a></li><li><a href="http://lastwatchdog.com/visa-risk-chief/" rel="bookmark" class="crp_title">Visa risk chief calls for increased use of smart cards, password tokens</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/merchants-consumers-hook-due-breach/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Caller ID spoofers raid online banking accounts</title>
		<link>http://lastwatchdog.com/caller-id-spoofers-raid-online-banking-accounts/</link>
		<comments>http://lastwatchdog.com/caller-id-spoofers-raid-online-banking-accounts/#comments</comments>
		<pubDate>Fri, 16 Mar 2012 11:56:48 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12189</guid>
		<description><![CDATA[By Byron Acohido, USA TODAY, 16March2012, P1B Cyberthieves are stepping up phone-calling scams to pilfer from consumers’ online banking accounts. In the second half of 2011, Pindrop Security detected more than 1 million fraudulent calls, including 189,439 in December, a 52% spike from the 124,258 calls tracked in July, according to a first of its [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12190" href="http://lastwatchdog.com/caller-id-spoofers-raid-online-banking-accounts/1203116_spooftel223/"><img class="alignleft size-full wp-image-12190" title="1203116_spooftel223" src="http://lastwatchdog.com/wp/wp-content/uploads/1203116_spooftel223.jpg" alt="" width="225" height="105" /></a>By Byron Acohido, USA TODAY, 16March2012, <a href="http://www.usatoday.com/tech/news/story/2012-03-14/caller-id-phone-spoofing/53554430/1">P1B</a></p>
<p>Cyberthieves are stepping up phone-calling scams to pilfer from consumers’ online banking accounts.</p>
<p>In the second half of 2011, Pindrop Security detected more than 1 million fraudulent calls, including 189,439 in December, a 52% spike from the 124,258 calls tracked in July, according to a first of its kind reporte released Thursday.</p>
<p>“Mobile is a growth area for online banking fraud,” says Stan Stahl, president of the Los Angeles chapter of the Information Systems Security Association, a tech professionals group that’s working with financial institutions to stem all forms of online banking fraud.</p>
<p><object id="flashObj" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="360" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="bgcolor" value="#FFFFFF" /><param name="flashVars" value="videoId=1508469961001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="base" value="http://admin.brightcove.com" /><param name="seamlesstabbing" value="false" /><param name="allowFullScreen" value="true" /><param name="swLiveConnect" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" /><param name="name" value="flashObj" /><param name="flashvars" value="videoId=1508469961001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="allowfullscreen" value="true" /><embed id="flashObj" type="application/x-shockwave-flash" width="425" height="360" src="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" name="flashObj" allowscriptaccess="always" swliveconnect="true" allowfullscreen="true" seamlesstabbing="false" base="http://admin.brightcove.com" flashvars="videoId=1508469961001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" bgcolor="#FFFFFF"></embed></object></p>
<p>Many of the bogus calls were tied to caller ID spoofing – a way to place a phone call that causes the recipient’s phone to display a caller ID number that appears to originate from a trusted party.</p>
<p>Phone call spoofers often begin by luring a cell phone user into divulging account information via an automated call or text message that appears to come from the user’s bank. Next, the crooks call the bank, spoofing a patron’s phone number and correctly answering security questions to trick the customer rep into carrying out fraudulent cash transfers or issuing new credit cards to mailing addresses they control.</p>
<p>The use of spoofed calls to hijack online banking accounts is one slice of a thriving, multi-billion dollar online banking fraud industry. Cyber robbers also <a href="http://lastwatchdog.com/ten-fold-rise-malicious-ads-bedevils-publishers-consumers/">spread poisoned links on webpages </a>and in e-mail and on social networks to take control of consumers’ PCs. They then embed programs, called banking Trojans, that let them stealthily tap into online banking accounts.</p>
<p><strong>Billions stolen</strong></p>
<p>Based on cases it has worked on with law enforcement and victim companies, Dell SecureWorks estimates that small- and medium-sized businesses in the U.S. and Europe lose as much $1 billion a year from online banking accounts. The financial services industry contends the security of computing devices is the responsibility of the companies and often <a href="http://lastwatchdog.com/perils-online-banking-cyberrobbers-escalate-attacks/">do not reimburse </a>theft losses from online business accounts.</p>
<p>The financial services industry often does not reimburse such losses. &#8220;We&#8217;d expect business owners to be a bit more savvy and have more resources at their fingertips,&#8221; says Carol Kaplan, spokeswoman for the American Bankers Association. &#8220;That doesn&#8217;t mean we&#8217;re not seriously concerned about the problems small businesses are having, and there continues to be huge gobs of investment into shoring up security.&#8221;</p>
<p>Results of an ABA survey of 95 financial institutions, released exclusively to USA TODAY, show the number of commercial account takeovers by cybercrooks rose 260% in 2011 vs. 2009. However, the average loss per victimized company decreased 92% during the same period.</p>
<p>&#8220;Financial institutions are becoming more effective at stopping illicit transactions from being executed,&#8221; says Doug Johnson, the ABA&#8217;s vice president of risk management policy.</p>
<p>Individual consumers are getting hit too, but typically get made whole by the banks &#8212; if they catch and report theft from online accounts quickly. In those instances, the banks bear the loss.</p>
<p>“It is incredibly difficult to measure losses from consumer accounts, but it’s probably higher than $1 billion a year,” says Dale Gonzalez, Dell SecureWorks mobile product strategist. Droves of less-skilled cyberthieves, equipped with free, easy-to-use account hijacking tools “are absolutely targeting consumers,” Gonzalez says.</p>
<p>Spoofed call attacks, in particular, are catching on because they are easy to do and difficult to defend, law enforcement  officials and security analysts say. Consumers’ names, phone numbers and e-mail can be purchased inexpensively from hackers who specialize in cracking into databases, like the gang that<a href="http://lastwatchdog.com/zappos-hack-shows-risk-e-mail-account-username/"> swiped 24 million customer records </a>from online  shoe retailer Zappos.</p>
<p><strong>Easy pickings</strong></p>
<p>What’s more caller ID spoofing techniques are trivial to master; free and cheap automated programs are readily available on the Internet. In the last six months of 2011, bogus calls were placed in connection with online banking scams directed at 30 of the 50 largest financial institutions in the U.S., says Pindrop CEO Vijay Balasubramanian.</p>
<p>“We are continuing to see this rising trend,” says Balasubramanian. “There appears to be a network effect as word of successful scams gets relayed to other fraudsters.”</p>
<p>ISSA’s Stahl says tech companies and banks need to do more to stem the tide of attacks. Part of the solution: being more transparent to small businesses and consumers about the risks of online banking.</p>
<p>“Online bank fraud is at epidemic levels, there’s no question about that,” Stahl says. “Right now there is inadequate security against the many kinds of attacks that lead to online banking fraud, and that’s only going to get worse, not better.”</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/video-documentary-reveals-details-inception-pc-viruses/" rel="bookmark" class="crp_title">Video documentary reveals details of the inception of PC viruses</a></li><li><a href="http://lastwatchdog.com/video-examines-poisoned-search-results-kate-middelton/" rel="bookmark" class="crp_title">Video examines poisoned search results for Kate Middleton</a></li><li><a href="http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/" rel="bookmark" class="crp_title">Mobile devices carry intrinsic security flaws</a></li><li><a href="http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/" rel="bookmark" class="crp_title">Angry Birds and other Facebook apps score low on privacy</a></li><li><a href="http://lastwatchdog.com/visa-risk-chief/" rel="bookmark" class="crp_title">Visa risk chief calls for increased use of smart cards, password tokens</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/caller-id-spoofers-raid-online-banking-accounts/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Cyber attacks on mobile devices gain meaningful traction</title>
		<link>http://lastwatchdog.com/cyber-attacks-mobile-devices-gain-meaningful-traction/</link>
		<comments>http://lastwatchdog.com/cyber-attacks-mobile-devices-gain-meaningful-traction/#comments</comments>
		<pubDate>Wed, 07 Mar 2012 20:14:10 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12172</guid>
		<description><![CDATA[Something the security community has been fretting about for a few years, seems to have finally arrived in earnest: cybercriminals are going mobile. Nearly one in five mobile phone users have experienced some type of security threat with their device. That&#8217;s the finding of a Cloudmark survey of 1,000 cellphone users, scheduled to be released [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12173" href="http://lastwatchdog.com/cyber-attacks-mobile-devices-gain-meaningful-traction/ipad_in_use175px/"><img class="alignleft size-full wp-image-12173" title="iPad_in_use175px" src="http://lastwatchdog.com/wp/wp-content/uploads/iPad_in_use175px.jpg" alt="" width="175" height="131" /></a>Something the security community has been <a href="http://lastwatchdog.com/case-tighter-security-internet-connected-devices/">fretting</a> about for a few years, seems to have finally arrived in earnest: cybercriminals are <a href="http://www.usatoday.com/money/industries/technology/story/2012-03-05/mobile-security-threats/53357486/1">going mobile.</a></p>
<p>Nearly one in five mobile phone users have experienced some type of security threat with their device. That&#8217;s the finding of a Cloudmark survey of 1,000 cellphone users, scheduled to be released Tuesday.</p>
<p>Poisoned text messages, nearly non-existent in the U.S. a few years ago, grew 300% in 2010 and 400% in 2011, accounting for about 1% of all text messages. &#8220;We&#8217;ve gone from totally clean to a trickle,&#8221; says Rachel Kinoshito, head of Cloudmark&#8217;s security operations. &#8220;Most people are seeing about one a month.&#8221;</p>
<p><object id="flashObj" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="360" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="bgcolor" value="#FFFFFF" /><param name="flashVars" value="videoId=1485431907001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="base" value="http://admin.brightcove.com" /><param name="seamlesstabbing" value="false" /><param name="allowFullScreen" value="true" /><param name="swLiveConnect" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" /><param name="name" value="flashObj" /><param name="flashvars" value="videoId=1485431907001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" /><param name="allowfullscreen" value="true" /><embed id="flashObj" type="application/x-shockwave-flash" width="425" height="360" src="http://c.brightcove.com/services/viewer/federated_f9?isVid=1" name="flashObj" allowscriptaccess="always" swliveconnect="true" allowfullscreen="true" seamlesstabbing="false" base="http://admin.brightcove.com" flashvars="videoId=1485431907001&amp;playerID=102195605001&amp;playerKey=AQ~~,AAAABvaL8JE~,ufBHq_I6Fnyou4pHiM9gbgVQA16tDSWm&amp;domain=embed&amp;dynamicStreaming=true" bgcolor="#FFFFFF"></embed></object></p>
<p>That foothold is part of a broader concern. Variations of scams that infest the Internet, through PC browsers, have begun spreading on a meaningful scale through mobile devices. And it looks like the bad guys are just getting warmed up.</p>
<p>One type of poison text message involves tricking people into signing up for worthless services for which they get billed $9.99 a month. Another type lures them into doing a survey to win a free iPhone or gift card. Instead, the attacker gets them to divulge payment card or other info useful for identity-theft scams.</p>
<p>&#8220;Malicious attacks have exploded well beyond e-mail, and we are very aware of their move to mobile,&#8221; says Jacinta Tobin, a board member of the Messaging Anti-Abuse Working Group, an industry group combating the problem.</p>
<p>Meanwhile, hackers are repurposing skills honed in the PC world to attacks on specific mobile devices. Particularly, handsets using Google&#8217;s Android operating system are frequently the target of hackers. In December, anti-virus company F-Secure tracked down 1,639 unique malicious Android apps — disguised as free apps and circulating on websites across the Internet. That&#8217;s up from 48 in January 2011.</p>
<p>One type offered and delivered a free copy of the popular Angry Birds game. But the victim is also unwittingly signed up for a premium-rate texting service and charged an extra $10 a month on his or her phone bill, says F-Secure researcher Sean Sullivan.</p>
<p>Network security company Juniper Networks says the pool of bad apps it has been tracking swelled 86% in February from January. Nearly half of the poisoned Android apps analyzed by Juniper were classic spyware, says Dan Hoffman, head of Juniper&#8217;s mobile security business.</p>
<p>&#8220;We&#8217;ve identified malware that can steal credentials from e-mail and mobile banking applications,&#8221; Hoffman says. &#8220;These attacks can be devastating.&#8221;</p>
<p>The online industry is on high alert. The working group— whose members include AT&amp;T, Verizon, Comcast, Facebook, PayPal and Time Warner— convened in San Francisco last month to join forces on defending new mobile threats.</p>
<p>&#8220;We need to stay ahead of what&#8217;s happening with mobile abuse, social networking abuse and malware,&#8221; says Tobin. &#8220;It makes sense for us to collaborate across all these channels.&#8221;</p>
<p>For more information about reprints &amp; permissions, visit our FAQ&#8217;s. To report corrections and clarifications, contact Standards Editor Brent Jones. For publication consideration in the newspaper, send comments to letters@usatoday.com. Include name, phone number, city and state for verification. To view our corrections, go to corrections.usatoday.com.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/video-documentary-reveals-details-inception-pc-viruses/" rel="bookmark" class="crp_title">Video documentary reveals details of the inception of PC viruses</a></li><li><a href="http://lastwatchdog.com/video-examines-poisoned-search-results-kate-middelton/" rel="bookmark" class="crp_title">Video examines poisoned search results for Kate Middleton</a></li><li><a href="http://lastwatchdog.com/mobile-devices-carry-intrinsic-security-flaws/" rel="bookmark" class="crp_title">Mobile devices carry intrinsic security flaws</a></li><li><a href="http://lastwatchdog.com/angry-birds-facebook-apps-score-privacy/" rel="bookmark" class="crp_title">Angry Birds and other Facebook apps score low on privacy</a></li><li><a href="http://lastwatchdog.com/visa-risk-chief/" rel="bookmark" class="crp_title">Visa risk chief calls for increased use of smart cards, password tokens</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/cyber-attacks-mobile-devices-gain-meaningful-traction/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Microsoft-Google privacy tussle widens spotlight on invasive practices</title>
		<link>http://lastwatchdog.com/microsoft-google-privacy-tussle-widens-spotlight-invasive/</link>
		<comments>http://lastwatchdog.com/microsoft-google-privacy-tussle-widens-spotlight-invasive/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 18:07:20 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12112</guid>
		<description><![CDATA[By Byron Acohido USA TODAY, 22Feb2012, P1B Mud-slinging between tech rivals is nothing new. But the red hot issue of online privacy has pushed it to another level. Last week Google scrambled to deflect criticism that it tracked the online activities of users’ of Apple’s Safari web browser against their wishes, by circumventing an anti-tracking [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12113" href="http://lastwatchdog.com/microsoft-google-privacy-tussle-widens-spotlight-invasive/ie-logo150px/"><img class="alignleft size-full wp-image-12113" title="IE logo150px" src="http://lastwatchdog.com/wp/wp-content/uploads/IE-logo150px.jpg" alt="" width="150" height="146" /></a>By Byron Acohido</p>
<p>USA TODAY, 22Feb2012, <a href="http://www.usatoday.com/tech/news/story/2012-02-21/google-microsoft-browser-privacy/53198146/1http://">P1B</a></p>
<p>Mud-slinging between tech rivals is nothing new. But the red hot issue of online privacy has pushed it to another level.</p>
<p>Last week Google scrambled to deflect criticism that it tracked the online activities of users’ of Apple’s Safari web browser against their wishes, by <a href="http://lastwatchdog.com/google-takes-heat-tracking-safari-users-wishes/">circumventing</a> an anti-tracking mechanism.</p>
<p>On Tuesday the search giant <a href="http://www.zdnet.com/blog/bott/google-defense-cites-study-arguing-for-stronger-privacy-regulation/4538">lashed out</a> at Microsoft in response to allegations that it has been doing much the same to users of Windows Internet Explorer browser.</p>
<p>Google and Facebook have been <a href="http://lastwatchdog.com/google-congress-deleting-profiling-data-not-practicable/">under pressure</a> from Congress and the Federal Trade Commission to disclose more about their tracking techniques.</p>
<p><strong>Widespread tracking</strong></p>
<p>Ironically, this latest tempest, stirred up by Microsoft, could widen the spotlight and invite scrutiny of Microsoft’s own tracking practices, and those of  Microsoft, Apple, Twitter, Amazon and thousands of web companies in the hunt for online advertising revenue, says Al Hilwa, software applications analyst at IDC.</p>
<p>“The web industry has gravitated towards advertising as the primary source of income and (tracking) data is the fuel the industry runs on,” Hilwa says.</p>
<p>In a <a href="http://blogs.msdn.com/b/ie/archive/2012/02/20/google-bypassing-user-privacy-settings.aspx">blog posting </a>on Monday, Microsoft corporate vice-president Dean Hachamovitch accused Google of issuing tracking mechanisms designed to bypass technology called P3P. Internet Explorer uses P3P  to screen the privacy policies of any entity engaged in online tracking to determine if they’re up to snuff.</p>
<p>Google senior vice president Rachel Whetstone responded by blasting P3P as “largely non-operational.” As proof, she pointed to a 2012 Carnegie Mellon <a href="http://www.cylab.cmu.edu/research/techreports/2010/tr_cylab10014.html">research report</a> revealing some 11,000 websites routinely by-pass P3P.</p>
<p><strong>&#8216;We have to lie&#8217;</strong></p>
<div id="attachment_12114" class="wp-caption alignleft" style="width: 100px"><a rel="attachment wp-att-12114" href="http://lastwatchdog.com/microsoft-google-privacy-tussle-widens-spotlight-invasive/lorrie-cranor90px/"><img class="size-full wp-image-12114" title="lorrie Cranor90px" src="http://lastwatchdog.com/wp/wp-content/uploads/lorrie-Cranor90px.jpg" alt="" width="90" height="126" /></a><p class="wp-caption-text">Cranor</p></div>
<p>The professor who ran that study, Lorrie Faith Cranor, says many website operators bypass P3P by mistake, while others do it on purpose to circumvent Microsoft’s attempt at grading privacy policies.</p>
<p>Google and Facebook, Cranor says, are in the latter group. Each use tracking mechanisms that bypass P3P so that popular features, such Facebook’s Like button, and Google Gmail logon services. Otherwise those features would not work.</p>
<p>Google essentially says, ‘we have to lie because if we didn’t lie we couldn’t do these cool features,” Cranor says.</p>
<p>Whetstone contends that channeling tracking mechanisms through P3P makes little sense. “It is impractical to comply with Microsoft’s request while providing modern web functionality,” she says</p>
<p>Hachamovitch, meanwhile, insists that Google should “commit to honoring P3P.”</p>
<p>Yet, the 2010 Carnegie Mellon study found even some Microsoft websites bypass P3P, as do sites from Godaddy, Hulu and Amazon.</p>
<p>“My students and I discovered that Google, Facebook and thousands of others essentially have bogus privacy policies,” Cranor says. “In some cases they put them in place on purpose. In other cases, it may be mistakes in computer code, or the person running the website might be doing whatever it takes to make it (tracking mechanism) run properly.”</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/google-takes-heat-tracking-safari-users-wishes/" rel="bookmark" class="crp_title">Google takes heat for tracking Safari users against their wishes</a></li><li><a href="http://lastwatchdog.com/congress-obamas-privacy-bill-rights-law/" rel="bookmark" class="crp_title">Will Congress make Obama&#8217;s Privacy Bill of Rights law?</a></li><li><a href="http://lastwatchdog.com/obama-calls-consumer-privacy-bill-rights/" rel="bookmark" class="crp_title">Obama calls for a Consumer Privacy Bill of Rights</a></li><li><a href="http://lastwatchdog.com/consumer-groups-herald-ftcs-call-do-track-mechanism/" rel="bookmark" class="crp_title">Consumer groups herald FTC&#8217;s call for a &#8220;Do Not Track&#8221; mechanism</a></li><li><a href="http://lastwatchdog.com/facebook-fails-provide-clear-answers-web-tracking/" rel="bookmark" class="crp_title">Facebook fails to provide clear answers on Web tracking</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/microsoft-google-privacy-tussle-widens-spotlight-invasive/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google takes heat for tracking Safari users against their wishes</title>
		<link>http://lastwatchdog.com/google-takes-heat-tracking-safari-users-wishes/</link>
		<comments>http://lastwatchdog.com/google-takes-heat-tracking-safari-users-wishes/#comments</comments>
		<pubDate>Fri, 17 Feb 2012 23:23:31 +0000</pubDate>
		<dc:creator>bacohido</dc:creator>
				<category><![CDATA[For consumers]]></category>
		<category><![CDATA[Imminent threats]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Top Stories]]></category>

		<guid isPermaLink="false">http://lastwatchdog.com/?p=12100</guid>
		<description><![CDATA[Yet more evidence of the gold rush to harvest and store profiling data on Internet users: Google came under fire today by several members of Congress after a Stanford University grad student disclosed how the search giant has been tracking the online activities of users of Apple&#8217;s Safari web browser, despite the default use of [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-12101" href="http://lastwatchdog.com/google-takes-heat-tracking-safari-users-wishes/spyeye/"><img class="alignleft size-full wp-image-12101" title="SpyEye" src="http://lastwatchdog.com/wp/wp-content/uploads/SpyEye.jpg" alt="" width="150" height="142" /></a>Yet more evidence of the gold rush to harvest and store profiling data on Internet users:</p>
<p>Google came <a href="http://content.usatoday.com/communities/technologylive/post/2012/02/google-facing-congressional-backlash-over-tracking-of-safari-users-/1#.Tz7cy8pAdAE">under fire </a>today by several members of Congress after a Stanford University grad student disclosed how the search giant has been tracking the online activities of users of Apple&#8217;s Safari web browser, despite the default use of a browser mechanism to block such tracking.</p>
<p><a href="http://lastwatchdog.com/false-fears-spread-track-privacy-mechanism/">Jonathan Mayer</a>, a grad student and privacy researcher, wrote about Google&#8217;s Safari tracking techniques in <a href="http://webpolicy.org/2012/02/17/safari-trackers/">this blog posting. </a>Mayer&#8217;s findings got wide attention after the Wall Street Journal featured it in a news story published Friday morning.</p>
<p>Rachel Whetstone, Google&#8217;s senior vice president of communications and public policy, says the Journal &#8220;mischaracterizes what happened and why.&#8221;</p>
<div id="attachment_12107" class="wp-caption alignleft" style="width: 86px"><a rel="attachment wp-att-12107" href="http://lastwatchdog.com/google-takes-heat-tracking-safari-users-wishes/rachel-whetstone76px/"><img class="size-full wp-image-12107" title="Rachel Whetstone76px" src="http://lastwatchdog.com/wp/wp-content/uploads/Rachel-Whetstone76px.jpg" alt="" width="76" height="103" /></a><p class="wp-caption-text">Whetstone</p></div>
<p>Whetstone says the Safari browser &#8220;contained functionality that then enabled other Google advertising cookies to be set on the browser.&#8221; She says Google&#8217;s engineers &#8220;didn&#8217;t anticipate that this would happen.&#8221; The search giant has started removing these advertising cookies from Safari browsers, she says.</p>
<p>Even so, backlash has followed. Rep. Mary Bono Mack, R-Calif., is asking Google to reappear before Congress to explain how it tracks the online activities of iPhone and iPad users. Bono Mack moderated a closed door briefing two weeks ago at which two Google executives answered questions about a major privacy policy change the search giant is about to make.</p>
<div id="attachment_11895" class="wp-caption alignleft" style="width: 112px"><a rel="attachment wp-att-11895" href="http://lastwatchdog.com/larry-page-show-testify-congress/mary-bono-mack_102px/"><img class="size-full wp-image-11895" title="Mary Bono Mack_102px" src="http://lastwatchdog.com/wp/wp-content/uploads/Mary-Bono-Mack_102px.jpg" alt="" width="102" height="130" /></a><p class="wp-caption-text">Bono Mack</p></div>
<p>&#8220;Google has some tough new questions to answer in the wake of this latest privacy flap, and that&#8217;s why I am asking them to come in for another briefing.&#8221; Says Bono Mack. &#8220;These types of incidents continue to create consumer concerns about how their personal information is used and shared.&#8221;</p>
<p>Meanwhile, Representatives Ed Markey, D-Mass., Joe Barton, R-Tex., and Cliff Stearns, R-Fla., fired off a letter to the Federal Trade Commission asking the agency to investigate whether Google&#8217;s Safari tracking violates a standing consent order that restricts Google from misrepresenting its privacy policies.</p>
<p>&#8220;Google&#8217;s practices could have a wide sweeping impact because Safari is a major web browser used by millions of Americans,&#8221; the letter states. &#8220;We are interested in any actions the FTC has taken or plans to take to investigate whether Google has violated the terms of its consent agreement.&#8221;</p>
<p>Sen. Jay Rockefeller, D-WV,weighed in, indicating Google may have to answer to the U.S. Senate, as well.</p>
<p>&#8220;According to press reports, Google circumvented consumer choice and may have paved the way for third-party ad networks—including Google&#8217;s own DoubleClick—to track consumers against their will,&#8221; says Rockefeller. &#8220;If so, this practice may have violated the company&#8217;s own stated privacy practices. I fully intend to look into this matter and determine the extent to which this practice was used by Google and other third parties tocircumvent consumer choice.&#8221;</p>
<p>The FTC already is dealing with legal action taken last week by the Electronic Privacy Information Center asking a federal court judge to order the agency to enforce that same standing consent order Markey, Barton and Stearns want applied to the Safari tracking snafu. EPIC filed suit to get the FTC to enforce the consent decree to stop Google from making a sweeping privacy policy change on March 1. Should Google move ahead with that March 1 change, it can begin to more readily index and profile users of its search, Gmail, Google Apps, YouTube, Picasa and other popular services. And consumers wishing to patronize more than one of these free services will have no way to say no to such profiling practices.</p>
<p>EPIC also wrote to the FTC today, urging the agency to enforce the consent order with respect to Google&#8217;s practices tracking Safari users. EPIC&#8217;s letter contends that Google &#8220;took elaborate measures to circumvent the Safari privacy safeguards, and it benefited from the misrepresentations by the commercial value it surreptitiously obtained.&#8221;</p>
<p>Mayer, the Stanford researcher, also described how the techniques Google has been using to track Safari users have also been used by three other online ad companys: Vibrant Media, Media Innovation and PointRoll, whose parent company is Gannett, USA TODAY&#8217;s parent company.</p>
<p>A Gannett spokeswoman told the Wall Street Journal that the Safari tracking techniques PointRoll uses were part of limited test.</p>
<p>&#8211;Byron Acohido</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://lastwatchdog.com/google-execs-lack-clarity-closed-door-briefing-congress/" rel="bookmark" class="crp_title">Google execs lack clarity in closed-door briefing of Congress</a></li><li><a href="http://lastwatchdog.com/microsoft-google-privacy-tussle-widens-spotlight-invasive/" rel="bookmark" class="crp_title">Microsoft-Google privacy tussle widens spotlight on invasive practices</a></li><li><a href="http://lastwatchdog.com/larry-page-show-testify-congress/" rel="bookmark" class="crp_title">Will Larry Page show up to testify before Congress?</a></li><li><a href="http://lastwatchdog.com/epic-asks-court-block-googles-privacy-policy/" rel="bookmark" class="crp_title">EPIC asks court to block Google&#8217;s new privacy policy</a></li><li><a href="http://lastwatchdog.com/google-congress-deleting-profiling-data-not-practicable/" rel="bookmark" class="crp_title">Google to Congress: deleting profiling data &#8216;not always practicable&#8217;</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://lastwatchdog.com/google-takes-heat-tracking-safari-users-wishes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

