Category Archives: Internet Security
Law enforcement, security experts warn Snapchat users about brand new ‘Snap Maps’ feature – WPTV.com
WEST PALM BEACH, Fla. - The popular app Snapchat app is navigating tricky - and some say dangerous - territory.
The new 'Snap Maps' shows your followers your location down to the street.
People can see where you are, WPTV internet security expert Alan Crowetz explains. It's a stalker's delight. A pedophile would be all over something like this.
It's kinda rattling the security world because it's tipping off people to where you are. A lot of people don't know this update was rolled out or what it does.
Crowetz says as tech advances, we're left with a dilemma
You have to decide - do you want the convenience or do you want the security? Rarely can you get both completely, he says.
As we continue to fight for that balance, he says education is important.
Have that talk with your children, Crowetz says. A lot of parents don't know what there is out there, and what they should be concerned about. Education is number one.
Parents we spoke to were caught on both sides of the Snap Maps argument
The minute a kid goes around the corner, and someone knows you're there and knows your kid is therethat is an opportunity, says parent Alexai Perrez.
Mother Kelly Levy wasn't as concerned.
It doesn't really bother me because there's dangers everywhere, she says.
She says ultimately it comes down to parent discretion.
Some teens might be able to use that responsibly, and some may not be able to, Levy says.
The company says the Snap Maps setting is off by default.
Although many users online have claimed otherwise.
To turn it off, click on the settings tab in the corner of the screen and select Ghost Mode.
If you would like to sign up for a free internet safety checklist from Alan Crowetzclick here.
More here:
Law enforcement, security experts warn Snapchat users about brand new 'Snap Maps' feature - WPTV.com
Virgin Media customers urged to change wifi and router passwords due to internet security flaw – Cornwall Live
Comments(0)
More than 800,000 broadband customers are being urged to change their passwords immediately over security concerns.
Virgin Media said the risk to customers with a Super Hub 2 router was small", but advised them to change both their network and router passwords if they were still set as the default shown on the attached sticker.
The advice followed a Which? snapshot investigation which found that hackers could access to home networks and connected appliances in as little as four days.
Ethical security researchers SureCloud gained access to the Super Hub 2, although Virgin Media said the issue existed with other routers of the same age, not just their model.
Read next: Eleven weeks without internet despite 24 engineer visits
A Virgin Media spokesman said: "The security of our network and of our customers is of paramount importance to us.
"We continually upgrade our systems and equipment to ensure that we meet all current industry standards.
To the extent that technology allows this to be done, we regularly support our customers through advice and updates and offer them the chance to upgrade to a Hub 3.0 which contains additional security provisions."
The Which? study tested whether popular smart gadgets and appliances, including wireless cameras, a smart padlock and a children's Bluetooth toy, could stand up to a possible hack.
Read next: New fast food delivery service will bring McDonald's to your door
Some of the devices proved harder than others to infiltrate, such as the Amazon Echo, but eight out of 15 appliances were found to have at least one security flaw.
The test found that the Fredi Megapix home CCTV camera system operated over the internet using a default administrator account without a password, and Which? found thousands of similar cameras available for anyone to watch the live feed over the internet.
The watchdog said that worse still" a hacker could even pan and tilt the cameras to monitor activity in the house.
SureCloud hacked the CloudPets stuffed toy, which allows family and friends to send messages to a child via Bluetooth and made it play its own voice messages.
Which? said it contacted the manufacturers of eight affected products to alert them to flaws as part of the investigation, with the majority updating their software and security.
It did not receive a response from the manufacturers of either Fredi Megapix or CloudPets.
The consumer group said the industry needed to take the security of internet-enabled and smart products seriously by addressing the basics such as ensuring devices required a unique password before use, using two-factor authentication, and issuing regular security updates for software.
Read next: Fidget spinner released in virtual form by Google and here's how to find it online
Alex Neill, Which? managing director of home products and services, said: There is no denying the huge benefits that smart-home gadgets and devices bring to our daily lives.
However, as our investigation clearly shows, consumers should be aware that some of these appliances are vulnerable and offer little or no security.
There are a number of steps people can take to better protect their home, but hackers are growing increasingly more sophisticated.
Manufacturers need to ensure that any smart product sold is secure by design."
Read next: Heatwave melts iPhone as temperatures continue to soar across Cornwall
See original here:
Virgin Media customers urged to change wifi and router passwords due to internet security flaw - Cornwall Live
Safety Plus Security: Solutions And Methodologies – SemiEngineering
By Ed Sperling & Brian Bailey
As more technology makes its way into safety-critical marketsand as more of those devices are connected to the Internetsecurity issues are beginning to merge with safety issues.
The number of attempted cyberattacks is up on every front, which has big implications for devices used in safety-related applications. There are more viruses, ransomware, and counterfeit chips and IP. And while the total number of breaches is flat, mostly due to increased attention to security, the impact of those breaches is larger. In effect, hackers are getting better at choosing their targets.
Fig. 1: Total cybersecurity breaches. Source: Symantec Internet Security Threat Report, April 2017.
Fig. 2: Ransomware demands. Source: Symantec Internet Security Threat Report, April 2017.
This is bad enough for IT systems. But as as medical devices, cars, and industrial control systems are connected to the Internet, cybercrime increasingly will have a direct effect on personal and public safety. Moreover, while most of this has involved software in the past, chips increasingly will be part of the attack infrastructure.
There is another facet to consider with these new applications, as well. Most hardware designs today have a life expectancy of two for consumer/mobility designs, to four years for server hardware. But in the case of industrial, medical and automotive applications, electronics are supposed to last a decade or more.
Security, meanwhile, is never 100% effective, and it becomes less effective over time. Connectivity and device complexity, which is compounded by regular software updates, are contributing factors to a rise in data leakage. In addition, security measures that are considered impervious to attacks today likely will be vulnerable within several years because hacker tools and know-how are constantly evolving.
As soon as you think you have a secure device, you find a hole, said Dipesh Patel, president of the IoT Services Group at ARM. So you are never done. And devices need to be upgraded, which is done with software. That makes it more vulnerable. If you look at the Mirai attack, devices were exposed because someone decided to use default passwords.
Patel said hardware-software co-design will be a baseline necessity for security. But that will not be enough. You can supply more secure devices, but you need to educate others about the need to do things properly. Secure devices need to be complemented with other things, such as tutorials, how-to guides, and in the case of enterprises, they need to be more aware. The best solutions are a combination of technology and best practices.
But how, exactly, does this work for an autonomous vehicle or a medical device such as a pacemaker? The answer is that nothing is perfect. Numerous steps need to be considered at every level, from design through manufacturing and out into the market, and they need to be revisited regularly.
Security is a big topic for EDA, and its a big topic for the semiconductor industry, said Wally Rhines, president and CEO of Mentor, a Siemens Business. While it hasnt become critical yet, we believe that ultimately youll need to have trustworthy silicon as part of the total solution because chips will be subject to Trojans and companies will get more and more concerned about what gets into their chips and how it gets protected. Over time, it will become one more big part of IC design and verification. Tools will be available to help you, but this is a dynamic. Unlike a physics problem that you solve and it stays solved, security is one where the people working to break the security are just as smart as the people working to improve the security.
Different approaches for different markets Standards compliance adds cost, complexity and time to safety-critical designs. A chip designed for any automotive application would likely have to adhere to the ISO 26262 standard, which is essentially a best-practices checklist. But if that chip is used in the control of an autonomous vehicle, it also would have comply with the most stringent restrictions defined by the SAE and ASIL standards, as well as ISO 26262.
In the medical electronics field, it would have to adhere to a different set of standards being developed by such groups as the U.S. Food & Drug Administration and the Medical Device Innovation, Safety and Security Consortium. And in mil/aero, it would have to follow the DO-254 standards as well as various country- and region-specific regulations for supply chain integrity.
This adds a whole different level of scrutiny, validation and verification. And that, in turn, will boost the cost of a design and the time it takes to get a chip certified and into production.
With safety, we are looking at single-fault effects, and for that we know what full coverage means, said Ashish Darbari, director of product management for OneSpin Solutions. We can analyze that every fault is detected using a number of mechanisms. But for security, attacks are not equivalent to single faults. How can we measure the effectiveness of the protections for security? If we could model and specify what the interactions need to be, what must happen, what must not happen, intentional versus unintentional, then you can come up with a good set of checks that could be specified. Security is more systematic analysis, but it will always be difficult to get a handle on completeness.
In many cases, markets define what security means. Security means different things to different people, said Darbari. To one person it is about illegal access to an unprivileged user to a CPU or part of memory. Firmware plays a big role here, as well, and a lot of bad firmware can cause these issues to manifest and allow access to the hardware. What is the security vulnerability model?
Software updates add security risks, too. While updates are necessary to keep devices current and help close security holes as they are spotted, the update process itself provides another attack vector.
If you look at the market for cars, which is still evolving, over-the-air updates open up a whole new level of exposure, said Bernd Stamme, vice president of product marketing at Kilopass . At least with the CAN (controller area network) bus, to hack the system you physically have to open it up. But with over-the-air updates, physical connections are no longer required.
There is plenty of experience with securing over-the-air updates to software, particularly with set-top boxes and information technology downloads. But Stamme noted that carmakers will require sophisticated ways of distributing security keys over the network, which most have never done before. Companies need the most secure on-chip medium for this. Otherwise, if you get a hold of the chip you can reverse engineer it. The algorithms being used are well understood. If you have enough compute power, its easier to decide how to prevent this. But not all of these devices will have that.
Security solutions There are several recurring aspects to security. One is the protection of data. The addition of cryptographic capabilities to support secure communication and data storage requires software with hardware support for secure storage of keys and, in many case, acceleration is added for performance, said Tim Mace, senior manager business development in the MIPS Business Unit of Imagination Technologies. However, every additional capability added to a chip adds to the power and cost.
Security isnt free in any respect. It can affect overall chip performance, particularly if the security is active rather than passive. Active is considered more effective, but its also more expensive on every level. In some cases, it may require a separate chip or IP accelerator on the same chip.
Security is one aspect of the workload, said Anush Mohandass, vice president of marketing and business development at NetSpeed Systems. You need different chips for different workloads. And if youre using heterogeneous IP within a single chip, to get the maximum out of that chip you need to understand the workload.
It also may require such techniques as virtualization to keep the data from one function separate from another, which also affects the initial design. If you have 10 operating systems running, they should not have knowledge of each other, Mohandass said. That way there is no contamination of data.
Memories are another area that needs shoring up. The next level of protection is that they may encrypt regions of memory, said Drew Wingard, CTO at Sonics. In a more secure chip you may want to ensure that if someone was able to gain access to the entire content of the memory, they would still not be able to understand anything. That has a latency impact because you have to map the data between memory and processing.
Another common form of protection is the establishment of a secure enclave. You can run security functions isolated from other aspects of the chip, said Mike Borza, member of the technical staff for Synopsys Security IP. There are different ways to get that secure enclave. There are embedded hardware security modules that run inside the chip and are a companion to the main CPU. It is designed to provide a real, hard target for the security processing to take place. That tends to be a larger solution and adds cost in terms of IP licensing and area. For something in the class of a small router or IoT hub, the costs that may be acceptable are in the order of a few cents per chip for a chip that sells in the low single digit dollar range.
Another way to do this is to create virtual environments. Separation of the data and applications can be best implemented using an approach based on virtualization, added Mace. This is often supported by hardware memory management for performance.
Virtualization depends on the system having a memory management unit, which is not always the case with heterogeneous system. We introduced a firewall into the NoC that lives in front of the transaction destinations, Wingard explained. This builds a memory protection capability and allows the chip designer, or software people at runtime, to configure the chip to allow one region of memory to be accessible to this processor while in this mode, or these three units and the DMA engine to be able to access another part when in another mode. We can build multiple mutually secure nodes. This is easy and simple to understand and has very little software overhead if you dont have to reprogram it. There is no performance impact.
This type of system can also hunt for suspicious activity. We are starting to see things that look at traffic flows between interfaces or between ports on a bus and identify patterns that are unusual or shouldnt be happening at all, said Borza. If a network interface is talking directly to an encryption controller that is not what should be happening and may be flagged as an unusual pattern that you may want to detect. We are starting to see people build this into the fabric of the chip.
Making progress? While the fundamentals of security are understood well enough, metrics about what makes one device or IP block more secure than another are less than clear.
Security is very difficult to measure, said Asaf Ashkenazi, senior director of product management in Rambus Security Division. There is a lot of misinformation out there, and you can claim whatever you want. You can claim that security is built in, but there is not a way to measure it that has consequence. There are no guidelines or best practices.
This may be an annoyance with a consumer or business system, but it can be life-threatening in a safety-critical device. If a computer is hacked, you lose data, Ashkenazi said. But if you hack a car, industrial machine or a traffic light, you can cause reasl damage.
Until there is some formalization of the malicious fault problem, it is difficult to think about adequate analysis or automation tools. There is some research devoted to building a more objective measure for how secure something is, said Borza. An example of that is a DARPA project that is trying to build those metrics and provide a quantitative assessment of security.
This may require a simplification of the problem. One approach is based on root of trust modules that are starting to become more common, Borza explained. This recognizes that providing a small isolated environment, which uses relatively simple software, can be assessed and analyzed for vulnerabilities and immunity to certain types of attacks. The approach is to contain complexity in the security functions in order to provide a reasonable guarantee of how secure that part of the chip is. Then you can use that to bootstrap the rest of the system securely.
Perhaps the most important change that a team has to make is rooted in their mindset. Both safety and security are not solved by simply adding some special IP, or software, as an afterthought, said Mace. They need to be addressed throughout the design and manufacturing process as in both cases the overall level of safety and security of a product is limited by the weakest element.
There is no disagreement on that point. The teams that are putting out successful semiconductors have baked this in from day one, said Rob Knoth, product management director for the DSG group at Cadence. The architecture of the system and the verification plan, the physical floorplan everything has the concepts baked into it. Otherwise it becomes a horribly non-convergent process and you end up missing stuff and having to do a respin.
The industry is taking the problem seriously. Security is lagging safety by about five years, said Darbari. We will see compliance standards for security being established within five years. But if you are not even doing your functional verification properly in the first place, and relying on directed test then you dont have a hope.
Safety and security need to be baked into the methodology. Only then will they permeate through the chip as needed for both efficiency and effectiveness, concludes Mace. It is important that each stage in the development process is reviewed closely to consider the design implications. It is only when these techniques are embedded into the development tools and the design and verification processes, that new chips will be created with safety and security at their core.
Related Stories Safety Plus Security: A New Challenge (Part 1) There is a price to pay for adding safety and security into a product, but how do you assess that and control it? The implications are far reaching, and not all techniques provide the same returns. Security: Losses Outpace Gains Complexity, new and highly connected technology, and more valuable data are making it harder to keep out hackers. IoT Security Risks Grow Experts at the table, part 2: Mirai, Shodan, and where the holes are in security; establishing a chain of trust from a solid root; how to future-proof security.
See the original post here:
Safety Plus Security: Solutions And Methodologies - SemiEngineering
Global Internet Security Market – Forecasts, Drivers and Opportunity Assessment by Technavio – Business Wire (press release)
LONDON--(BUSINESS WIRE)--According to the latest market study released by Technavio, the global internet security market is expected to reach USD 137.96 billion by 2021, growing at a CAGR of almost 9%.
This research report titled Global Internet Security Market 2017-2021 provides an in-depth analysis of the market in terms of revenue and emerging market trends. This market research report also includes up to date analysis and forecasts for various market segments and all geographical regions.
According to Cisco VNI, 1.2 ZB of internet traffic was generated in 2016. Smartphone traffic accounted for 13% of this traffic. By 2021, smartphones will account for 33% of the 3.3 ZB of internet traffic that will be generated in that year. Penetration of global positioning system (GPS)-enabled smartphones will consequently increase globally during this period. The market is expected to grow constantly because of the increased demand for high-speed broadband services and consumer awareness of Internet of Things (IoT) applications such as connected homes and automobiles.
This report is available at a USD 1,000 discount for a limited time only: View market snapshot before purchasing
Buy 1 Technavio report and get the second for 50% off. Buy 2 Technavio reports and get the third for free.
Technavios ICT research analysts categorize the global internet security market into the following segments by end-user. They are:
The top three end-user segments for the global internet security market are discussed below:
Government
Smart governance solutions are extensively used in burglar alarm monitoring, homeland security, fire and emergency, as well as traffic management applications. Other areas in which these services are used include financial services, public services, and security. These solutions support government agencies to analyze and manage the causal factors of disasters. It helps to analyze the risks while planning and implementing preventive measures.
According to Rohan Joy Thomas, a lead IT security research analyst from Technavio, The increasing amounts of government expenditure on the implementation of government security installations in the developing countries, such as India and China, is one of the primary drivers for the market. Moreover, the need for cybersecurity solutions to maintain homeland security will positively affect the market growth in the coming years.
BFSI
Since the BFSI sector contains financial data of customers, it is important for these organizations to maintain data confidentiality. The instances of cyber-attacks are increasing in the form of data theft, phishing scams, and other online threats owing to an increase in the demand for online transactions through applications.
BFSI organizations are increasingly investing in cybersecurity solutions. Further, governments are implementing stringent regulations, such as the Sarbanes-Oxley Act of 2002, on the financial organizations, enforcing the use of cybersecurity solutions to prevent data theft, says Rohan.
Manufacturing
Smart mobility solutions are used in asset tracking, fleet management, and telematics to enhance the operational efficiency of retail outlets while reducing costs related to transportation and logistics. More than 20 billion connected vehicles will be on the roads worldwide by 2020.
The deployment of 4G-LTE technologies in the automotive industry is one of the primary factors responsible for the increased adoption of IoT solutions. The sector has also been witnessing a growing trend in favor of intelligent cars and transport systems, which use IoT technology to enhance safety and functionalities in vehicles with completely inbuilt systems.
The top vendors highlighted by Technavios research analysts in this report are:
Browse Related Reports:
Become a Technavio Insights member and access all three of these reports for a fraction of their original cost. As a Technavio Insights member, you will have immediate access to new reports as theyre published in addition to all 6,000+ existing reports covering segments like data center, IT spending, and enterprise application. This subscription nets you thousands in savings, while staying connected to Technavios constant transforming research library, helping you make informed business decisions more efficiently.
About Technavio
Technavio is a leading global technology research and advisory company. The company develops over 2000 pieces of research every year, covering more than 500 technologies across 80 countries. Technavio has about 300 analysts globally who specialize in customized consulting and business research assignments across the latest leading edge technologies.
Technavio analysts employ primary as well as secondary research techniques to ascertain the size and vendor landscape in a range of markets. Analysts obtain information using a combination of bottom-up and top-down approaches, besides using in-house market modeling tools and proprietary databases. They corroborate this data with the data obtained from various market participants and stakeholders across the value chain, including vendors, service providers, distributors, re-sellers, and end-users.
If you are interested in more information, please contact our media team at media@technavio.com.
Go here to read the rest:
Global Internet Security Market - Forecasts, Drivers and Opportunity Assessment by Technavio - Business Wire (press release)
Concerns in the UK Over National, Financial, Internet and Personal … – PR Newswire UK (press release)
UK consumers reported a 40 percent increase in security-related concerns since 2014, according to the new Unisys Security Index that surveyed consumers in April 2017 in 13 countries around the world. The global study gauges the attitudes of consumers on a wide-range of security-related issues.
UK respondents reported increasing concern in all four categories of the core survey: national, financial, internet and personal security. The biggest increases in concern were related to national and internet security - which rose 66 percent and 50 percent, respectively.
Highlights from the UK results include:
Salvatore Sinno, chief security architect, Unisys, said: "Factors such as terror attacks, high profile cyber-attacks and the rising cost of living are all outside the public's control and they are major contributing factors to the Unisys Security Index registering record levels of concern in the UK. Steps to advise and protect the public, such as the launch of the National Cyber Security Centre, are moves in the right direction, but we need joined up thinking across the public and private sectors to ensure the public are aware of risks, know how to avoid threats and act as securely as possible."
The Unisys Security Index scale runs from 0 - 300, where 0 represents no concern and 300 represents extreme concern. Overall the UK's Index score is at a record high of 144, up 41 points from 2014's survey. The global study gauges the attitudes of consumers on a wide range of security-related issues, with the core survey categories - Internet (150), Financial (147), Personal (141) and National (136) - all registering record highs in 2017. The global average Index score stands at 173[1] from the 13 countries surveyed, with the Philippines scoring highest (243) and the Netherlands lowest at 125.
About the Unisys Security Index
Unisys has conducted the Unisys Security Index - the only recurring snapshot of security concerns conducted globally - since 2007 in order to provide an ongoing, statistically-robust measure of concern about security. The index is a calculated score out of 300 covering changing consumer attitudes over time across eight areas of security in four categories: national security and disaster/epidemic, in the National Security category; bankcard fraud and financial obligations, in the Financial Security category; viruses/hacking and online transactions, in the Internet Security category; and identity theft and personal safety, in the Personal Security category. The 2017 Unisys Security Index is based on online surveys conducted between April 6-18, 2017 of nationally representative samples of at least 1,000 adults in each of the following countries: Argentina, Australia, Belgium, Brazil, Colombia, Germany, Malaysia, Mexico, Netherlands, New Zealand, Philippines, the U.S. and the UK. The margin of error at a country level is +/-3.1 percent at 95 percent confidence level, and 0.9 percent at a global level. For more information on the 2017 Unisys Security Index, visit http://www.unisys.com/unisys-security-index/uk
About Unisys
Unisys is a global information technology company that specializes in providing industry-focused solutions integrated with leading-edge security to clients in the government, financial services and commercial markets. Unisys offerings include security solutions, advanced data analytics, cloud and infrastructure services, application services and application and server software. For more information, visit http://www.unisys.com.
Follow Unisys on Twitter and LinkedIn.
Unisys and other Unisys products and services mentioned herein, as well as their respective logos, are trademarks or registered trademarks of Unisys Corporation. Any other brand or product referenced herein is acknowledged to be a trademark or registered trademark of its respective holder
1. The 2017 Unisys Security Index score shows a 30-point increase over its score of 143 in 2014, the last time Unisys conducted the index on a global scale. Five points of the 30 points are due to the addition of new countries to the index.
SOURCE Unisys
Continue reading here:
Concerns in the UK Over National, Financial, Internet and Personal ... - PR Newswire UK (press release)
Why Invest in Golem: It’s a Security Powerhouse – Wealth Daily
I think there's one thing we can all agree on:Internet security is now a global issue.
If you are a digital currency investor, you should be nodding.
After all, how many times have we griped and moaned over digital currency exchange outages that were caused by targeted attacks?
But internet security extends far beyond our investing niche. Internet security is a dinner table conversation where families fighting over whether or not our sitting President was placed in the White House through Russian hacking interference.
Last year, Wired predicted that we would see an increase in cyberattacks in 2017. Now, it's June, and we have witnessed the massive WannaCry malware attack, the French election being tampered with by hackers, and a clever Google Docs phishing scheme that affected thousands.
It's internet warfare.
This means that we need security and we need it now. And the companies that offer a solution to the problem will make money.
There is already a token out there that's tackling the cyberattack issue: Golem, the foundation of a new decentralized internet.
Golem came onto my radar right after Ethereum (ETH) did.
Its creators state that Golem, when implemented, will create a decentralized internet through existing hardware.
Essentially, it will piggyback off existing phones and computers to distribute and strengthen networks.
All an individual has to do is download the Golem application, and they will become part of the network.
Our current security issues exist because most internet protocols flow through warehouses filled with server farms. This means that hackers can easily target servers and bring them down through distributed denial-of-service (DDoS) attacks. Remember the Bitfinex attack that sent us through our first Ethereum drop?
Because Golem takes that centralized network and distributes it, it would answer most of our security issues. In fact, the amount of computing power required to take down a decentralized network has never existed. And it's unlikely that it ever will.
The simplicity of the idea has opened the wallets of many investors Golem's initial coin offering (ICO) sold out in less than 30 minutes.
Golem is up 6,000% from its ICO last year. It's trading for under $1but may not stay there for long.
Like all technologies, Golem will need work and development to become the powerhouse it has the potential to be.
Like Ethereum, Golem's development is happening in stages: Brass, Clay, Iron, and Stone.
Currently, we are approaching Brass Golem. As the first stage, Brass Golem will allow developers to show the world what their concept can do. It will be the first look at a fully decentralized internet. Basically, without getting into the technical details, Golem is going to be taking to the stage.
We know the product will be coming in the next two weeks. But the development team has been very firm on one thing since the beginning: They will not release a product before it's ready. In a way, this gives Golem credibility in a digital currency world crazed with ICO fever. We can't expect these things to happen overnight, but we can look at reveals (like brass) as indicators of things to come.
But since the time frame is confined to within two weeks, that means if you want to invest in Golem at a low price, you'll have to get in sooner rather than later.
As always, there is a "where to buy" section in each currency feature.
In Golem's case, 62% of trading activity happens on Poloniex. Poloniex is not as simple as Coinbase and requires that you transfer money into your account. You can transfer bitcoins or ether from your Coinbase account into Poloniex.
We are going to offer you more detailed information on how to buy soon. This information will include screencast tutorials.
You can sign up below and be put on our list to receive those updates.
P.S. We get a lot of questions about digital currency investing in the comments. The best way to get in touch with me is through my Twitter @AlexandraPerryC.
Sign up to receive the Wealth Daily newsletter - it's absolutely free! In each issue, you'll get our best investment research, designed to help you build a lifetime of wealth, minus the risk. Plus, by signing up, you'll instantly receive our new report: Surviving the Coming Economic Collapse.
We never spam! View our Privacy Policy
After getting your report, youll begin receiving the Wealth Daily e-Letter, delivered to your inbox daily.
View post:
Why Invest in Golem: It's a Security Powerhouse - Wealth Daily
Internet-Enabled Drill Demonstrates IoT Security Done Right – Threatpost
To Mark Loveless, aninternet-enabled cordless drill seemed like a perfect recipe for an IoT security nightmare.
Duo Securitys senior security researcher confessed that it sounded silly and quite possibly part of a push by the electronics maker to inject smarts into devices that ultimately turned them into hackable punching bags for adversaries to exploit. So when he examined an internet-connected Milwaukee Tool cordless drill he was pleasantly surprised to find the devices smarts were implemented in a safe and responsible manner. The results of his findings are part of research published Monday, Bug Hunting: Drilling Into the Internet of Things (IoT).
My expectations for security were very low for a smart drill, Loveless said. But after examining the security, I feel like there is hope that consumer-device IoT can be done the right way.
The drill in question was a $250 Milwaukee Tool ONE-KEY M18 Fuel 1/2 Drill/ Driver. The drill comes with an asset-management platform called One-Key. The platform allows tool owners to use a smartphone app or website to track the drills whereabouts using GPS technology. It also allows for remote custom configuration of equipment (such as the drills torque), or disable it should it be stolen.
When it comes to the world of IoT devices, there is no shortage of faulty security to keep experts such as Loveless skeptical. From IoT botnet-fueled Mirai to the co-opting of theConficker worm to target hospital IoT devices, last year alone IoT malware activity more than doubled.
That is why after Loveless closely examined the drill he was impressed to find that the manufacturer appeared to have performed comprehensive threat modeling on the device, used reliable open source software libraries correctly, and implemented strong SSL encryption.
If DVR and CCTV makers took the steps Milwaukee Tool did, Mirai wouldnt have had a chance, he said.
Thats not to say all was perfect. Loveless investigation found what he called minor flaws. One was that static passwords were hard-coded into the smartphone app. Also found, the power drill could be readily identified by a potential thief remotely via Bluetooth scanning.
With a $100 Bluetooth antenna I could scan the neighborhood and find these expensive drills within a half-mile radius, Loveless said.
During his research, it was also discovered that the GPS data used for inventory tracking could be spoofed. Basically, if I stole your drill, I could fake the GPS data to make it look like another neighbor had the drill in his toolshed, he said.
The big caveat to his research? We are talking about a drill. If this were an insulin pump, pacemaker or security alarm these flaws would be a lot more serious, Loveless confessed.
In all, four vulnerabilities were identified by Duo Security, generating two unique CVEs.
CVE-2017-3214 relates to the fact, the ONE-KEY app includes master credentials in base-64 encoded format that are needed to obtain a bearer token. The bearer token allows for read-write access to information stored in Milwaukee Tools website.
With CVE-2017-3215, the One-Key app has a bearer token that doesnt expire and stays stored on the phone. A typical bearer token has an expiration time of 1-2 hours, these have an expiration time of one year, and are stored on the phone for reuse while the phone is logged in. In the event of a compromised phone, it is possible for an attacker to gain access to the bearer token and use it, according to the report.
Loveless told Threatpost that he believes the Milwaukee Tool drill is the exception, not the rule, when it comes to IoT security. As Milwaukee competitors are racing to catch up, they have raised the bar and made security a first thought not an afterthought.
Continued here:
Internet-Enabled Drill Demonstrates IoT Security Done Right - Threatpost
Scientists Make Quantum Leap Toward Secure Quantum Internet – Top Tech News
Scientists have taken a major step towards building a global quantum internet by beaming "entangled" particles of light from a satellite to ground stations more than 700 miles apart.
The feat paves the way for a new kind of internet which draws on the curious ability for subatomic particles to be connected to one another despite being far apart and even on opposite sides of the planet.
Researchers believe that by linking particles together in this way, encrypted information could be sent from place to place across a quantum network with no danger of it being decrypted and read by others, as can be done on the existing internet.
Jian-Wei Pan, who led the research at the University of Science and Technology in Hefei in China, said the demonstration was a moment he had been dreaming of since 2003. "Many people thought it was a crazy idea, because it was very challenging," he said.
The work obliterates the previous world record for sending pairs of photons that are connected to one another by a strange rule of quantum physics first spotted by Einstein. Until now, the farthest researchers had ever sent entangled photons stood at a mere 65 miles, less than one tenth of the distance achieved in the satellite experiment.
"It's a first step, and a major step, toward creating a global quantum network," said Pan. "All the previous methods are limited to about 100km so can only work within a city."
The experiment relied on the world's first quantum-enabled spacecraft: a Chinese satellite called Micius. As it soared over China, the satellite created pairs of photons with properties that were linked through quantum entanglement. It then beamed these simultaneously to ground stations in Delingha, Lijiang and Nanshan. Each pair of particles travelled up to 1,240 miles before they reached their destinations. Details of the study are published in Science.
Pan said that the kind of cryptography used to keep data safe today relies on complex mathematics which can often be defeated by hackers. "If a future quantum network is established, the security is ensured by the laws of physics, which are unconditionally secure," he said. "It will be beneficial for all human beings."
Martin Stevens, a physicist at the National Institute of Standards and Technology in Boulder, Colorado, said he was impressed with the work. "These types of experiments are not easy to do, even within the controlled confines of a laboratory environment. Doing them between two remote ground locations and a satellite flying overhead at a speed of thousands of kilometres per hour is mind-bogglingly difficult."
In 2015, Stevens sent entangled photons down a 65 mile length of optical fibre. That is good enough for quantum communications between neighbouring towns, but it cannot work for much greater distances, because the signal is gradually lost the more optic fibre it travels down. The advantage of using a satellite is that the particles of light travel through space for much of their journey.
Anton Zeilinger at the Vienna Centre for Quantum Science also praised the work. "It's an important step towards a worldwide quantum network. If you envisage a quantum network, the question is how to cover large distances and that cannot be done with glass fibres on the ground. You have to go into space, because in glass fibres you lose the signal. It's very important to show that it works with satellites, so I'm very excited by this."
Zeilinger is working with Pan on an intercontinental quantum network and hopes to have results to report before the end of the year.
2017 Guardian Web syndicated under contract with NewsEdge/Acquire Media. All rights reserved.
More here:
Scientists Make Quantum Leap Toward Secure Quantum Internet - Top Tech News
Internet Security virus – How to remove? – 2-viruses.com
Internet Security virus is a fake antivirus program that belongs to the family of extremely aggressive rogue parasites. It is a clone of the Internet Security 2012 omitting the year number in the name. It is one more program that displays falsified information and imitates checking your system for infections while in fact it cannot detect anything. The program is installed to a random system through Trojan viruses and it is straight away configured to start automatically when computer is rebooted.
Internet Security virus launches its scanner with every login to Windows. The program imitates looking for infections and warns that your system is badly infected. Unfortunately, since Internet Security is not able to detect real threats, it displays non-existing files and presents them as infections. The program uses generic names of parasites and this way it prevents computer users from getting any information about them. The parasites detected by this malware include W32.Blaster.Worm, Email-Worm.Brontok, W32/Child-Porn.PROXY/Server, Mal/Generic-A, various TrojanDownloader versions. It is unlikely that any of these parasites are on your system, except, ironically, the TrojanDownloader which downloads Internet Security malware in first place. However, it will not be detected.
In addition, Internet Security scam warns that your system is at risk by displaying various security notifications and pop up ads which inform about system threats and recommend activating Internet Security in order to protect your computer.
You should remove Internet Security virus from your system as soon as you notice it there. Have in mind that this malware can try to block your legitimate antispyware tools and block these executables, it will also kill browsers and most of other applications. However, There are several ways to remove Internet Security from your system without resorting to system reinstal.
Note Internet Security Virus uses multiple process names names now (2013). The names used are : isecurity.exe , amsecure.exe, indefender.exe,tdefender.exe, ildefender.exe, ihdefender.exe. If the window does not closes during steps 2/3, try using these file names.
Remember that full legitimate anti-malware program like Malwarebytes Anti-Malware or spyhunter can prevent your system from being infected with this kind of infections.
Important Note:Although it is possible to manually remove Internet Security virus, such activity can permanently damage your system if any mistakes are made in the process, as advanced spyware parasites are able to automatically repair themselves if not completely removed. Thus, manual spyware removal is recommended for experienced users only, such as IT specialists or highly qualified system administrators. For other users, we recommend using Reimage or other toolsfound on 2-viruses.com.
All UsersApplication Dataisecurity.exeAll UsersAppDataisecurity.exe%TEMP%winupd.exe3C2.TMP%TEMP%[random].exeC:WINDOWSPrefetchISECURITY.EXE-1824C86D.pf
HKEY_LOCAL_MACHINESoftwareISECURITY.EXEHLEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun ISECURITY.EXEHKCUSOFTWAREMicrosoftWindowsCurrentVersionRun Internet Security 2012?
Visit link:
Internet Security virus - How to remove? - 2-viruses.com
Internet Security | NETWORK BOX
At Network Box, the emphasis is on taking away the mundane work of security so that companies can become more proactive and plan their business from a technological standpoint.
Network Box assists by allowing the IT manager to delegate the configuration and day to day maintenance to Network Box engineers whilst providing advice and expertise to enable the company to get the best return on its investment both in Network Box and its IT staff.
There are two fundamental choices to make when reviewing your internet security:
Consolidation
Legacy
Value
Consolidation can deliver significant savings
If you maintain your Legacy products then you are more likely to patch your security
Service Levels
One SLA under contract will give you peace of mind
Need to manage multiple support agreements
Skills & Training
Required for one product
Required for multiple products
Licences
Single Licence required
Multiple licences for multiple products
Management controls
Centralised on single console
Spread across multiple platforms and interfaces
Managed Service
Self-Managed Product
Control
Hosted
Localised
Change control
Provided by MSSP
Limited by product, time and skills
Service Levels
Tailored to customer needs
In-house limitations
Security Level
Choice of security provision
Limited to products & skills
Time
Delegate the issues to the managed service provider
Consumes considerable time, especially when skills are limited
Updates
One update for all services
Separate updates for each product
Management
From a single console
From separate consoles
Knowledge of threats/risk
Constantly refreshed & proactively applied
Reactive
From this exercise you will see that the value of consolidation and a managed service are the key business drivers of change in the Internet Security space. Whether you choose to switch your security to Network Box or any other vendor that provides consolidation of the Internet Security components, you can be reassured that this will deliver measurable financial, time and management benefits. To learn more about some of the companies that would endorse this view, see our case studies.
Read more here:
Internet Security | NETWORK BOX