The german hacker club CCC claims that they found a trojan malware used by german federal police (german source).
It seems that the software has many security issues and, even worse, has abilities which are illegal under german law.
The interesting question is now: Does it really originate from german authorities? Of course they deny that. And if so, how would one prove that? It seems that the trojan uses command servers outside of germany. At the moment it is unclear who operates these machines.
I do not expect that this will ever be resolved completely. It's way too embarrassing.
Update: The Bavarian Government accepted responsibility for the trojan. Antivirus vendors claim that it would be caught be heuristic malware detectors. Looks like there is an egg on someone's face.
Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts
Monday, 10 October 2011
Thursday, 28 January 2010
Identifying PCs by Browser Settings
My browser fingerprint, as determined by panopticlick in a project started by the Electronic Frontier Foundation is currently unique under approximately 500000 browsers. Most of the identifying information comes from browser plugins and installed fonts - my font set alone makes my browser unique. To be more precise, my browser sends out 19 bits of identifying information.
To make things worse: you can even deduce someone's affiliations from the installed fonts to target spearfishing attacks. Big companies as well as political parties like to use special fonts to generate an unique look in their documents.
I get identical results for safari, firefox and chrome. Switching off javascript reduces the amount of information available to the identificator by 3 bits.
The lowest result I get is for my iPhone: only 11.02 bits of information. It would seem to me that most iPhones look equal.
Sunday, 8 November 2009
PhoneSnoop Turns BlackBerries into Bugs
A simple BlackBerry program called PhoneSnoop will turn your BlackBerry into a bug. The attacker will install it on a BlackBerry he found lying around. Then calling the BlackBerry from a preconfigured telephone number will put the Balckberry into SpeakerPhone mode and all conversations near the affected BlackBerry can be overheard at the remote end of the call.
This is not a security issue of the BlackBerry operating system, because the root cause here is that the attacker had full control over the phone when he installed the software. For a minimum level of security, the BlackBerry should be configured to require a password ofter a short period of inactivity.
However, the morale here is that you shouldn't think "I don't have sensitive information on my telephone, so I don't need to secure it".
Sunday, 18 October 2009
Kaspersky wants to end Internet Anonymity
In an interview with zdnet Asia Eugene Kaspersky suggests to put an end to internet anonymity. He says "I'd like to change the design of the Internet by introducing regulation--Internet passports, Internet police and international agreement". Well, first this won't happen because it would be way to expensive. Even if an established system like OpenID would be used as the source of the identity management required here all ISPs and website operators would have to adopt their software. Second, it should not happen because anonymity is sometimes a part of freedom.
However the present system of website logins is a mess and should be fixed by using a voluntary identity management system.
Cnet reports that Comcast have a similar initiative where they disconnect users with infected PCs. This is also problematic, but it sounds a little better becasue it's good internet citizenship not to act as a springboard for internet criminals.
Realistically spaking, the responsibility for PC security remains with the vendors, not with the users as long as the systems are too complicated to be fully managed by the end users.
Labels:
privacy,
single sign on,
society,
web security
Sunday, 27 September 2009
Google suggest Online Payment with Single Sign On
Google has suggested a micropayment System to the Newspaper Association of America. How is this asecurity issue? They suggest to combine it with a Single Sign On System also operated by Google.
I welcome paid-for Internet content because I believe that advertising As the only Business model for online content endangers the journalistic quality of the articles. The dependency on the advertisers leads to articles written for the advertisers, not for the readers. Also, I hope that flash and popups will become less intrusive if publishers get an additional revenue stream.
The bad news is that Google would know even more about their users, in particular if they operate the micropayment system.
I really would prefer having a small micropayment token connected to my computer that performs Single Sign On and micropayment operations under my control.
I welcome paid-for Internet content because I believe that advertising As the only Business model for online content endangers the journalistic quality of the articles. The dependency on the advertisers leads to articles written for the advertisers, not for the readers. Also, I hope that flash and popups will become less intrusive if publishers get an additional revenue stream.
The bad news is that Google would know even more about their users, in particular if they operate the micropayment system.
I really would prefer having a small micropayment token connected to my computer that performs Single Sign On and micropayment operations under my control.
Labels:
e-cash,
e-commerce,
privacy,
single sign on,
society
Tuesday, 18 August 2009
Whole Genome Amplification allows DNA Spoofing
Israele researchers found that using a variant of polymerase chain reaction called 'whole genome amplification' it is possible to produce macroscopic amounts of DNA from very small samples. This can be used to create fake evidences at crime scenes. The fabricated samples have been tested with commercially available test kits.
This underlines two insights we all should know since long:
- Don't trust on DNA alone to convict people
- Be careful with large databases - their contents might be stolen
Update (209-08-20): Another Israeli company, Nucleix, claims that they have a DNA analysis kit that can distinguish between real and amplificated DNA. This looks ver much like another armamaent race to me.
Wednesday, 12 August 2009
Flash Cookies
Kate McKinley from iSEC Partners notes that Adabe's flash browser plugin can be used to store persistent data and thus track internet usage. Even worse, those flash cookies cannot be deleted through the browser settings. She descrribes a complicated procedure for managing and deleting flash cookies. This is annoying.
Subscribe to:
Posts (Atom)