Category Archives: Internet Security

Google Has Declared Symantec Harmful To Internet Security – UPROXX

Denis Linine / Shutterstock.com

Its rare Google outright goes to war on a company. Especially not a company as big and well-known as Symantec. But Google has done precisely that, in a move thats surprised the IT community and is about to make life miserable for a fair chunk of the internet.

Google has publicly said it no longer trusts the cryptographic certificates Symantec issues and that Chrome will view them as harmful. Think of a cryptographic certificate as the digital equivalent of getting carded at a bar. You encrypt whatever youre sending at your computer, and then use the certificate to encrypt it again. In order to read it, whoever youre sending it to needs both your private key, and the certificate they used. So if, say, a hacker has inserted himself between you and your banks website, he may have your private key, but once hes asked for the certificate, hes boned.

This isnt a minor issue; if the companies issuing these certificates get sloppy, there are enormous consequences. One Dutch company shut down after it came out it was issuing certificates to Iranian spies. And this has been an issue with Symantec since 2015 so the fact they havent bothered to clean up their act in two years, with millions of dollars at stake, is troubling. Google claims Symantec has issued 30,000 bad certificates.

The good news, if you run a website that issues these certificates, is that you can get new ones for free. But its unlikely most people will be aware of this problem, until it starts screwing up their sites.

(via Boing Boing)

Here is the original post:
Google Has Declared Symantec Harmful To Internet Security - UPROXX

The Senate just voted to undo landmark rules covering your Internet privacy – Washington Post

On March 23 the Senate voted to repeal FCC rules that protect consumers' online data from their Internet providers. The vote now heads to the House. (Jhaan Elker/The Washington Post)

Senate lawmakers voted Thursday torepeal a historic set of rules aimed at protecting consumers' online data from their own Internet providers, in a move that could make it easier for broadband companies to sell and share their customers' usage information for advertising purposes.

The rules, which prohibit providers from abusing the data they gatheron their customers as they browse the Web on cellphones and computers, were approved last year over objections from Republicans who argued the regulations went too far.

U.S. senators voted 50 to 48 to approve a joint resolution from Sen. Jeff Flake (R-Ariz.) that would preventthe Federal Communications Commission's privacy rules from going into effect. The resolution also would bar the FCC from ever enacting similar consumer protections. It now heads to the House.

[How a single Internet provider could end up making money off you several times over]

Industry groups welcomed the vote.

Our industry remains committed to offering services that protect the privacy and security of the personal information of our customers, said NCTA The Internet and Television Association, a trade group representing major cable providers. We support this step toward reversing the FCCs misguided approach and look forward to restoring a consistent approach to online privacy protection that consumers want and deserve.

Consumer and privacy groups condemned the resolution.

It is extremely disappointing that the Senate voted today to sacrifice the privacy rights of Americans in the interest of protecting the profits of major Internet companies, including Comcast, AT&T, and Verizon, Neema Singh Giuliani, legislative counsel for the American Civil Liberties Union, said in a statement.

The FCC didn't immediately respond to a request for comment.

The agency'srules are being debated as Internet providers no longer satisfiedwith simply offering Web access race to become online advertising giants as large as Google and Facebook. To deliver consumers from one website to another, Internet providers must see and understand which online destinations their customers wish to visit, whether that's Netflix, WebMD or PornHub.

With that data, Internet providers would like tosell targeted advertising or even share that informationwith third-party marketers. But the FCC's regulations place certain limits on the type of data Internet providers can share and under what circumstances. Under the rules, consumers may forbid their providers from sharing what the FCC deems sensitive information, such as app usage history and mobile location data.

Opponents of the regulation argue the FCC's definition of sensitive information is far too broad and that it creates an imbalance between what's expected of Internet providers and what's allowed for Web companies such as Google. Separately from Congress, critics of the measure have petitionedthe FCC to reconsider letting the rules go into effect, and the agency's new Republican leadership has partly complied. In February, President Trump's FCC chairman, Ajit Pai, put a hold on a slice of the rules that would have forced Internet providers to better safeguard their customer data from hackers.

The congressional resolution could render unnecessary any further action by the FCC to review the rules; Flake's measure aims to nullifythe FCC's privacy rules altogether. Republicans argue that even if the FCC's power to make rules on Internet privacy is curtailed, state attorneys general and the Federal Trade Commission could still hold Internet providers accountable for future privacy abuses.

But Democrats saythat preemptive rules arenecessary to protect consumers before their information gets out against their will.

At a time when our personal data is more vulnerable than ever, its baffling that Senate Republicans would eliminate the few privacy protections Americans have today, said Rep. Frank Pallone Jr. (N.J.), the ranking Democrat on the House Energy and Commerce Committee. Pallone added in a statement Thursday that he hoped his House Republican colleagues will exercise better judgment when it becomes their turn to vote on the resolution.

On Wednesday, Senate Democrats challenged the idea that the FTC could take responsibility for regulating Internet providers' privacy practices.

The Federal Trade Commission does not have the rulemaking authority in data security, even though commissioners at the FTC have asked Congress for such authority in the past, said Sen. Bill Nelson (Fla.), the top Democrat on the Senate Commerce Committee.

See the article here:
The Senate just voted to undo landmark rules covering your Internet privacy - Washington Post

What the Cloudbleed disaster says about the state of internet security – Information Age

With data at the centre of every business decision, it should be a top priority of all organisations to invest in a cloud provider that can offer sophisticated methods of data protection and always puts data security at the top of its list

Last month, Cloudflare, a web content delivery network, revealed that a security bug had caused sensitive data to leak from its customers websites.

The security bug, or Cloudbleed, was found in a part of the Cloudflare system that powered vital security features.

The Cloudbleed contamination resulted in private information leaking into the code of other web pages in the Cloudflare network. The data exposed ranged from private messages and IP addresses to cookies and passwords and was activated as early as September 2016.

Data breaches, such as the Cloudbleed leak, highlight the fact that cloud computing, when executed improperly, can make data incredibly vulnerable. If organisations use a cloud provider that doesnt offer the highest levels of security, it can have catastrophic effects.

>See also:The security challenges with the Internet of Things

In the event that data is lost, stolen or contaminated with malicious software, it can cost businesses time, money and their reputation.

But despite these risks, cloud computing is a necessity in todays business environment as it affords companies the flexibility, scalability and mobility they need to provide customers with the best service possible.

However, to balance security with the opportunities that cloud brings, it is vital that companies find a cloud provider that utilises security features such as data encryption, two-factor authentication and sophisticated intrusion prevention and detection software.

As businesses develop their online presence by offering online portals or forums to customers and employees, it makes it easier for vulnerabilities in company data to be exploited.

Considering that passwords are constantly under threat from malware, it is vital that businesses opt for a cloud hosting provider that has measures in place to protect its data should a password be compromised.

Two-factor authentication is an extra layer of security that requires users to enter both a traditional password and provide a physical security token or biometric password such as a fingerprint or retina scan.

By enforcing a second method of authentication on any online portals or company login pages, business owners can have peace of mind that their data is safe.

By deploying a cloud strategy, businesses can share data easily and quickly. However, it is important that critical corporate data is protected at all times, both in situ and in transit.

Encrypted data requires a specific decryption key to transform the information into readable plaintext. This means that even if data is intercepted or reaches the wrong hands it cannot be read or exploited without the key.

>See also:The Trojan horse: 2017 cyber security trends

Data encryption gives businesses complete control over what information needs to be protected, who can view this information and how it should be accessed. This means the most vital data has the greatest level of protection at any given time without hindering the flexibility and mobility that businesses require.

Over the last year, malware attacks have increased in both frequency and sophistication. According to research by the US government, in 2016, over 4,000 ransomware attacks were recorded on a daily basis. This represents a 300% increase in the number of daily attacks from the previous year.

In order to combat this growing issue, many companies invest money in security solutions that only create a perimeter fence around the most important data. Instead of continuously re-building these security perimeters, businesses should focus on implementing a network that can offer real-time threat awareness and continuous vulnerability discovery.

>See also:Busting the 7 myths of cyber security

To successfully provide this robust network, businesses must invest in a cloud provider that treats security as a business management problem. By using a provider that measures threat awareness at all times and operates an integrated prevention system, businesses can be certain that their data is constantly being monitored and protected against malware threats.

It is clear that data security should be a key part of any businesses IT strategy. Whether a business stores its data fully or partially in the cloud, events such as the Cloudbleed leak show just how important is it to choose a cloud provider that is trustworthy.

With data at the centre of every business decision, it should be a top priority of all organisations to invest in a cloud provider that can offer sophisticated methods of data protection and always puts data security at the top of its list.

Sourced by Jake Madders, director at Hyve Managed Hosting

Read more here:
What the Cloudbleed disaster says about the state of internet security - Information Age

Internet of Things security: What happens when every device is smart and you don’t even know it? – ZDNet

Will you bother updating your internet-connected toaster?

Billions more everyday items are set to be connected to the internet in the next few years, especially as chips get cheaper and cheaper to produce -- and crucially, small enough to fit into even the smallest product.

Potentially, any standard household item could become connected to the internet, even if there's no reason for the manufacturers to do so.

Eventually that processors needed to power an IoT device will become effectively free, making it possible to turn anything into a internet-enabled device.

"The price of turning a dumb device into a smart device will be 10 cents," says Mikko Hyppnen, chief research officer at F-Secure.

However, it's unlikely that consumer will be the one who gains the biggest benefits from every device their homes collecting data; it's those who build them who will reap the greatest rewards -- alongside government surveillance services.

"It's going to be so cheap that vendors will put the chip in any device, even if the benefits are only very small. But those benefits won't be benefits to you, the consumer, they'll be benefits for the manufacturers because they want to collect analytics," says Hyppnen, speaking at Cloud Expo Europe.

For example, a kitchen appliance manufacturer might collect data and use it for everything from seeing how often the product breaks to working out where customers live and altering their advertising accordingly in an effort to boost sales -- and the user might not even know this is happening, if devices have their own 5G connection and wouldn't even need access to a home Wi-Fi network.

"The IoT devices of the future won't go online to benefit you -- you won't even know that it's an IoT device," says Hyppnen.

"And you won't be able to avoid this, you won't be able to buy devices which aren't IoT devices, you won't be able to restrict access to the internet because they won't be going online through your Wi-Fi. We can't avoid it, it's going to happen."

Indeed, it's already started, with devices you wouldn't expect to need an internet connection -- including children's toys -- being discovered to have gaping cybersecurity vulnerabilities.

These scenarios, says Darren Thomson, CTO & vice president of technology services at Symantec, are occurring because those in the technology industry are thinking about whether they could connect things to the internet, but aren't thinking about whether they should.

"Could I attach my dog to the internet? Could I automate the process of ordering a taxi on my mobile phone? We're obsessed with could we problems. That's how we live our lives and careers, we invent things and we solve problems. We're good at 'Could we'," he said, also speaking at Cloud Expo Europe.

No matter the reason why things are being connected to the internet, Thomson agrees with Hyppnen about what the end goal is: data collection.

"The connectivity of those devices is impressive and important. But what's more important is how that's coming to bare across various markets. Every single sector on the planet is in a race to digitise, to connect things. And very importantly, to collect data from those things," he says.

However, various incidents have demonstrated how the Internet of Things is ripe with security vulnerabilities as vendors put profit and speed to market before anything else, with cybersecurity very low down the list of priorities.

Retrofitting updates via the use of patches might work for a PC, a laptop or even a smartphone, but there are huge swathes of devices -- and even whole internet-connected industrial or urban facilities -- for which being shutdown in order to install and update is impossible.

"The security industry to date is predicated on the benefit of the retrofit. IT has designed insecure systems then we've secured them. That's kind of OK in a world where a device can have some downtime," says Thomson.

"But a car, a building, a city, a pipeline, a nuclear power facility can't tolerate downtime. So if we don't build security and privacy in to our designs from the very first whiteboard, we're going to leave ourselves with a problem."

Not only that, but as IoT devices become more and more common, people will start to ignore them

"The reality of the human mind is as we embed things, we tend to forget about them, we get complacent about them. Many of you are probably wearing a smart device on your wrist to monitor your behaviour and exercise routines. But no doubt two weeks after you started wearing it, you forgot it was there," he says.

"The danger from a psychological perspective is that people forget about that technology and forget about the risks associated with it and our own personal mitigation of that risk."

Even now, consumers are too blas about connected devices, keen to jump on the latest technological trends failing to realise the associated security risks. Then even if they do, they remain unclear on how to secure the IoT devices -- that is, if there is the option of securing it in the first place.

"Nobody reads the manual, especially to page 85 where it says how to change the default credentials, or page 90 where it says how to set up user accounts and restrict access to the admin interface, or page 100 where it says how to segment your network," says Hyppnen.

He likens it to the "exact same problem we had in the 80s" when people wouldn't even bother to set a time on their video recorder as it involved picking up the manual, so it'd end up always flashing 12:00.

It's therefore important for the Internet of Things cybersecurity loopholes to be shut sooner rather than later so as to avoid nightmare scenarios where hackers could exploit vulnerabilities to attack anything from pacemakers and other medical devices, to connected cars to even entire industrial facilities.

But are IoT device manufacturers going to do this anytime soon? Probably not.

"The manufacturers of IoT devices are unlikely to fix this by themselves. They're unlikely to start investing more money in their IoT devices for security because money is the most important thing in home appliances," says Hyppnen

"When you buy a washing machine, price is the most important selling point. Nobody's asking, 'does it have a firewall or intrusion prevention systems?' Cybersecurity isn't a selling point for a washing machine, so why would manufacturers invest money in it?" he adds.

It might eventually be regulation which has to fix this problem; as Hyppnen points out, device safety is already regulated. "When you buy a washing machine, it must not short circuit and catch fire, we regulate that. Maybe we should regulate security," he says.

Read more here:
Internet of Things security: What happens when every device is smart and you don't even know it? - ZDNet

CUJO is cuter than Wall-E, and it’s the only internet security device you’ll ever need – Yahoo News

Everything in your home that connects to the internet and we mean EVERYTHING is vulnerable to attack. Sure you have antivirus software on your PCs, but what about your smartphones and tablets? What about your TVs? What about your Amazon Echo, your home security cameras and your baby monitors? Most people dont even realize how vulnerable all of these devices can be, and to be honest, you shouldnt have to worry about hackers breaking into your network and using your Nest Cam to spy on you and record you.

Thats where CUJO comes in. This little gadget might look even more adorable than Wall-E, but it means business. CUJO takes just a few minutes to set up and once its configured, it uses machine learning to safeguard every internet-connected gadget in your home, from PCs and tablets to smart lights, Alexa speakers, TVs and web-connected thermostats.

Here are a few key features:

Its every single internet security device you need, all rolled up into one cute little orb. Of note, there are three different ways to buy CUJO. For a limited time you can get the device and a lifetime subscription for $249, or you can pay $179 for the CUJO box and 18 months of service, or $99 for the box and 180 days of service. If you choose one of the latter two options, CUJO service costs $8.99 after the included service period expires.

You can learn more on CUJOs website. Definitely check it out.

Trending right now:

See the original version of this article on BGR.com

See the original post here:
CUJO is cuter than Wall-E, and it's the only internet security device you'll ever need - Yahoo News

Fix crap Internet of Things security, booms Internet daddy Cerf – The Register

Vint Cerf, one of the fathers of the internet, has weighed in on Internet of Things security, warning that a Mirai botnet-style incident could happen again unless vendors start taking responsibility for their goods.

The biggest worry I have is that people building [IoT] devices will grab a piece of open source software or operating system and just jam it into the device and send it out into the wild without giving adequate thought and effort to securing the system and providing convenient user access to those devices, Cerf told the Association for Computing Machinery (ACM) organisation at its 50th Turing Award celebrations.

Such fears have been expressed time and again by both security and IoT advocates. Cerf highlighted the impact of the Mirai botnet, which was used in a DDoS attack that leveraged millions of unsecured IoT devices to attack DNS servers operated by US outfit Dyn.

The result was that large chunks of the internet disappeared from view. Dyns DNS services were used by a number of large and popular sites including Github, Netflix and Reddit.

We saw the Dyn attacks coming as a result of a lot of webcams being hacked, and the hacking was trivial, Cerf, nowadays employed by Google as its chief Internet evangelist, continued. Either they had no access control or they had a well-known and publicized username and password. So, I consider that kind of thing to be irresponsible. And companies looking to make their brands attractive are going to have to pay a lot more attention to security and privacy and access control if their users are going to endorse their products.

Cerf also balked at taking the mickey out of the fad for adding internet connectivity to anything and everything (such as toothbrushes), saying: Ive sort of given up ridiculing Internet enabling of things because Ive discovered that, even if it sounds crazy on the surface, there may actually be something useful arising.

He added: Lets just stick with internet enabling of everything, but on the other side of that, lets make sure that when we do that, we think our way through the security, safety and reliability of the systems.

Read more:
Fix crap Internet of Things security, booms Internet daddy Cerf - The Register

Carpe Diem: home internet security – KFOX El Paso

When it comes to keeping people from accessing your personal life and home through the internet, you can often be your worst enemy. Our tech expert Adam Gamwell of Gamwell Technologies said the solution is simple. The best step you can take to your protect your privacy, is to change the default password on any home device that is connected to the internet. All these items come with a default password that Gamwell said most people choose to ignore out of laziness.

The tendency is to get the item out of the box, set it up and make it start working right away. The default password is vastly overlooked Gamwell said and hackers can download the pass codes to these devices on line, and sometimes just by pass them on their own because they are so easy to compromise.

The other mistake you can make that could potentially compromise your privacy, is writing down the pass code that you choose in the event you do the safe thing and change the default password. "Never write down the password unless you plan to lock in safe," said Gamwell. In the next segment, we will show you a better way to store your passwords, and what to buy to make sure you are maximizing your internet protection at home.

Link:
Carpe Diem: home internet security - KFOX El Paso

Motivation Monday: home internet security – KFOX El Paso

Motivation Monday: home internet security

In a world in which we are all for evermore connected through home devices that operate via the internet, we are in many ways also connected to criminals. This week, Adam Gamwell, of Gamwell Technologies, will demonstrate and explain how to overcome what he said is the No. 1 security weakness in American homes today: internet vulnerabilities.

Although there has been much debate lately about the capabilities and methods of America's top intelligence agencies to tap into homes through internet-supported devices, Gamwell said, "It's their job to know how to do that." What you really need to be worried about, Gamwell said, is the multibillion-dollar criminal industry that exists solely to violate your privacy and pillage your finances by accessing your personal information. And all it takes, to do that is hacking into your home internet devices.

In the next segment, Gamwell will walk us through the simple steps of how to protect your home from hackers without spending any money at all.

See the original post:
Motivation Monday: home internet security - KFOX El Paso

Medical records of 26m patients at risk because of GP surgeries’ failing internet security – The Sun

Records at 2,700 practices in England one in three could be accessed by strangers

THE medical records of 26million patients are at risk because of a failing in GP surgeries internet security.

Records at 2,700 practices in England one in three could be accessed by strangers, The Daily Telegraph reports.

Getty Images

The Information Commission is probing concerns that a GP switching on enhanced sharing to allow a hospital to access data also allows access by thousands of others.

Receptionists to medics in hospitals, pharmacies, care homes and jails can all look up sensitive files.

It is claimed patients were not told records could be accessed like this and could fall into criminal hands.

The head of the BMAs IT committee has written to all GPs who use SystmOne, owned by TPP, urging them to take urgent action.

A spokesman for the Information Commissioner told Pulse magazine: We do have data protection compliance concerns about SystmOnes enhanced data sharing.

TPP said practices using SystmOne must fully inform patients or turn off record sharing.

Continued here:
Medical records of 26m patients at risk because of GP surgeries' failing internet security - The Sun

Free Internet Security | Why Comodo Internet Security Suite …

Comodo Internet Security offers complete protection

...from viruses, Trojans, worms, buffer overflows, zero-day attacks, spyware and hackers. Comodo Internet Security alerts you whenever potential malware attempts to attack or gain access to your system.

Comodo Internet Security program combines powerful antivirus protection, an enterprise class packet filtering firewall, advanced host intrusion prevention, application control and anti-spyware in one supremely powerful application.

Built from the ground upwards with your security in mind, Free Internet Security offers 360 protection by combining powerful Antivirus protection, an enterprise class packet filtering firewall, advanced host intrusion prevention and automatic sandboxing of unknown files.

Comodo's Internet Security suite differs from traditional antivirus software in that it also includes other layers of protection, including anti-spyware, parental controls, privacy protection and much more. This Free Internet Security suite is a complete package that you can download and install for peace of mind.

Using this free internet security software, you defend your PC from malicious software such as viruses, you prevent your personal information from being stolen and you protect your children from Internet dangers.

See more here:
Free Internet Security | Why Comodo Internet Security Suite ...