Cybersecurity & Privacy
Saudi Aramco Twitter account hacked
Due to recent attacks again Twitter and high profile Twitter users, Twitter has started implementing new security measured. Now we learn that the official account of Saudi Aramco (the world’s largest oil producer) was hacked by “Mister Rero”. Saudi Aramco is no stranger to infosec issues and had 30,000 workstations hacked last year. Don’t forget other twitter accounts were also recently hacked from Burger King, Jeep, etc.
Evernote will implement 2 factor authentication
A couple of days ago, I wrote about Evernote being hacked and the fact that it is the new reality for cloud services. Now we learn that Evernote intends to implement 2 factor authentication. In case you were not aware, Evernote was hacked and it forced its 50 million users to reset their passwords. According to InformationWeek, they will offer some kind of 2 factor authentication for all of their users before the end of the year.
Evernote hacked
Earlier this weekend, my beloved Evernote emailed its customers advising them that they had detected acking attempts and they had reset all of the user passwords as a precaution. They were adamant that no user information was accessed. Unlike LinkedIn (whose stolen passwords were easily decrypted), the Evernote passwords are stored hashed and salted which means decrypting them is a long and tedious job (which will likely make it unpractical). They also promised to released software updates that will make changing the password easier.
Can I trust Huawei mobile phones?
Big media loves stories that vilify someone because it sells papers or grabs eyeballs. Over the last couple of months, information security (or insecurity) has provided dozens of opportunities for media to create heroes and villains. One of the countries that are constantly vilified is China and many consumers looking for their next cell phone are wondering if they should buy a Huawei cell phone or not. Every once in a while, I get an email from a reader wondering what the risk is of buying a “Chinese made mobile device”.
250,000 twitter accounts hacked
It has been a bad week for popular websites (getting hacked). Now Twitter has come forward and acknowledged that 250,000 accounts were hacked. The attacker may have had access to email addresses, encryption passwords and session tockens. What is worrisome is that Twitter has claimed that the attack was "extremely sophisticated" and that they saw this same pattern of attach against other sites. Twitter is being proactive and is forcing users of those affected accounts to immediately change their passwords (those affected should have received an email from the company).
Whatsapp breaking Canadian privacy laws
It seems everyone’s favorite cross-platform Instant Messaging app has is violating Canadian privacy laws (according to the Office of the Privacy Commissioner of Canada). The OPC found that on all devices (except IOS 6), the App requires access to the users address book to function. This means that non WhatsApp user information is being stored on the WhatsApp servers without the permission of these users. WhatsApp is “trying to meet” Canadian regulations by adding encryption and other protections but the OPC believes they are not yet compliant with Canadian law and will continue monitoring the firms progress.
How to properly lock down your Facebook privacy settings
Facebook has gone to great length to make sure everyone know that Graph Search won’t reveal anything that isn’t already visible to the person conducting the search. However people may be able to find information about you because of privacy setting misconfigurations you may have made. It is a great time to make sure you have properly locked down your Facebook privacy settings. Click on the little gear icon (upper right hand side) and choose “Privacy Settings”. First Then
Employees leaking information to competitors
As an infosec leader working for a large multinational, a lot of risks keep me up at night. Most execs still believe (mistakenly) that the biggest risks come from the outside. Imagine my interest when I learned that AMD is suing 6 former employees because it believes they leaked over 100,000 documents ("trade secret materials relating to developing technology") to NVIDIA. The complaint says these employees took the info with them when they switched employers. AMD claims to have uncovered evidence of their claim using “forensically revealed data”.
Silent Circle enables secure VOIP calling from Android
I wrote about Silent Circle in October and was excited to learn that they recently released an Android app and enabled Out of Circle calling. Silent Circle will enable secure voice, text, email and video chatting from any Silent Circle client to another (Android -> Android or Android -> iPhone).
The app can be downloaded from the Google Play Store. Using their service is simple and straightforward. You download the app, create an account and then pay the $20 monthly service fee. As soon as this is done, you will be able to call Silent Circle to Silent Circle securely regardless of where in the world you are (over WIFI, 3G or 4G).
They also added an "Out-Circle Access" which will enable Silent Circle users to call regular phone lines. You link is encrypted from the device until the Silent Circle boundary (which is a nice feature for people working in some questionable countries). This feature costs an additional $29 a month but includes unlimited calling to Canada, US and Puerto Rico.
Here is the full Press Release
Private encryption service developed by PGP inventor Phil Zimmermann protects voice and video calls on both Android and iOS devices across cellular and Wi-Fi networks Download image WASHINGTON, Jan. 16, 2013 /PRNewswire/ -- Silent Circle, a global private encrypted communications firm revolutionizing…
How many of your Twitter followers are fake?
With all the talk about fake Facebook/Twitter/Youtube followers, you may be wondering how many of your Twitter followers are real people and how many are bots. Enter Twitter Audit. The company describes itself as Each audit takes a random sample of 5000 Twitter followers for a user and calculates a score for each follower. This score is based on number of tweets, date of the last tweet, and ratio of followers to friends. We use these scores to determine whether any given user is real or fake.