Category Archives: Internet Security

Internet Security Software | Trend Micro USA

Trend Micro Internet Security is rated 4.6 out of 5 by 3001.

Date published: 2017-03-15

Date published: 2017-03-10

Date published: 2017-03-08

Date published: 2017-03-05

Date published: 2017-03-04

Date published: 2017-02-28

Date published: 2017-02-25

Date published: 2017-02-18

windows

Safeguard against email scams..

Stop ransomware and other threats before they reach your PC.

Secure your privacy on social media.

Fix common PC problems and optimize performance.

Let children explore safely while restricting time and access.

Dont get tricked into revealing your personal information. Well protect you from spam emails hiding phishing scams and ransomware.

Give your system a makeover. Trend Micro Internet Security fixes common PC problems and restores performance to top speed.

Rest easy while you connect on your favorite social media sites. We identify privacy settings on Facebook, Google+, Twitter, LinkedIn, and other social media to thwart threats.

windows mac android ios

Number of devices protected

Protects against ransomware

yes

Blocks 250M+ daily threats daily

yes

Safeguards against email scams

yes

Keeps children safe online

yes

Secures privacy on social media

yes

Fixes and optimizes systems

yes

Protects and manages passwords

yes

windows

Number of devices protected

Protects against ransomware

yes

Blocks 250M+ daily threats daily

yes

Safeguards against email scams

yes

Keeps children safe online

yes

Secures privacy on social media

yes

Fixes and optimizes systems

yes

Protects and manages passwords

windows

Number of devices protected

Protects against ransomware

yes

Blocks 250M+ daily threats daily

yes

Safeguards against email scams

yes

Keeps children safe online

Secures privacy on social media

Fixes and optimizes systems

Protects and manages passwords

Protects against ransomware

Blocks 250M+ daily threats daily

Safeguards against email scams

Keeps children safe online

Secures privacy on social media

Fixes and optimizes systems

Protects and manages passwords

Secures mobile devices

$39.95 $89.95

$39.95 $79.95

$39.95

5TMbyuyYWfKjITmE4hv5xg1BnFv24cU4rs48qx1ovjE=

Read the original:
Internet Security Software | Trend Micro USA

Are you undermining your web security by checking on it with the wrong tools? – The Register

Your antivirus and network protection efforts may actually be undermining network security, a new paper and subsequent US-CERT advisory have warned.

The issue comes with the use of HTTPS interception middleboxes and network monitoring products. They are extremely common and are used to check that nothing untoward is going on.

However, the very method by which these devices skirt the encryption on network traffic through protocols like SSL, and more recently TLS, is opening up the network to man-in-the-middle attacks.

In the paper [PDF], titled The Security Impact of HTTPS Interception, the researchers tested out a range of the most common TLS interception middleboxes and client-side interception software and found that the vast majority of them introduced security vulnerabilities.

"While for some older clients, proxies increased connection security, these improvements were modest compared to the vulnerabilities introduced: 97 per cent of Firefox, 32 per cent of e-commerce, and 54 per cent of Cloudflare connections that were intercepted became less secure," it warns, adding: "Alarge number of these severely broken connections were due to network-based middleboxes rather than client-side security software: 62per cent of middlebox connections were less secure and an astounding 58per cent had severe vulnerabilities enabling later interception."

Of the 12 middleboxes the researchers tested ranging from Checkpoint to Juniper to Sophos just one achieved an "A" grade. Five were given "F" fail grades meaning that they "introduce severe vulnerabilities" and the remaining six got "C" grades. In other words, if you have a middlebox on your network and it's not the Blue Coat ProxySG 6642, pull it out now.

Likewise, of the 20 client-side pieces of software from 12 companies, just two received an "A" grade: Avast's AV 11 for Windows (not Mac), and Bullguard's Internet Security 16. Ten of the 20 received "F" grades; the remaining eight, "C" grades.

TLS and SSL encrypt comms between a client and server over the internet by creating an identity chain using digital certificates. A trusted third party provides that certificate and it verifies that your connection is to a trusted server.

In order to work, therefore, an interception device needs to issue its own trusted certificate to client devices or users would constantly see warnings that their connection was not secure.

Browsers and other applications use this certificate to validate encrypted connections but that introduces two problems: first, it is not possible to verify a web server's certificate; but second, and more importantly, the way that the inspection product communicates with the web server becomes invisible to the user.

In other words, the user can only be sure that their connection to the interception product is legit, but has no idea whether the rest of the communication to the web server, over the internet is secure or has been compromised.

And, it turns out, many of those middleboxes and interception software suites do a poor job of security themselves. Many do not properly verify the certificate chain of the server before re-encrypting and forwarding client data. Some do a poor job forwarding certificate-chain verification errors, keeping users in the dark over a possible attack.

In other words: the effort to check that a security system is working undermines the very security it is supposed to be checking. Think of it as someone leaving your front door wide open while they check that the key fits.

What's the solution? According to US-CERT, head to the website badssl.com to verify whether your inspection product is doing proper verification itself. And of course, check out the SSL paper and make sure you're not running any of the products it flags as security fails on your network.

See original here:
Are you undermining your web security by checking on it with the wrong tools? - The Register

Bruce Schneier on New Security Threats from the Internet of Things – Linux.com (blog)


Linux.com (blog)
Bruce Schneier on New Security Threats from the Internet of Things
Linux.com (blog)
Security expert Bruce Schneier says we're creating an Internet that senses, thinks, and acts, which is is the classic definition of a robot. I contend that we're building a world-sized robot without even realizing it, he said recently at the Open ...

Follow this link:
Bruce Schneier on New Security Threats from the Internet of Things - Linux.com (blog)

Internet security – Wikipedia

Internet security is a branch of computer security specifically related to the Internet, often involving browser security but also network security on a more general level as it applies to other applications or operating systems on a whole. Its objective is to establish rules and measures to use against attacks over the Internet.[1] The Internet represents an insecure channel for exchanging information leading to a high risk of intrusion or fraud, such as phishing.[2] Different methods have been used to protect the transfer of data, including encryption and from-the-ground-up engineering.[3]

A computer user can be tricked or forced into downloading software onto a computer that is of malicious intent. Such software comes in many forms, such as viruses, Trojan horses, spyware, and worms.

A denial-of-service attack (DoS attack) or distributed denial-of-service attack (DDoS attack) is an attempt to make a computer resource unavailable to its intended users. Although the means to carry out, motives for, and targets of a DoS attack may vary, it generally consists of the concerted efforts to prevent an Internet site or service from functioning efficiently or at all, temporarily or indefinitely. According to businesses who participated in an international business security survey, 25% of respondents experienced a DoS attack in 2007 and 16.8% experienced one in 2010.[4]

Phishing occurs when the attacker pretends to be a trustworthy entity, either via email or web page. Victims are directed to fake web pages, which are dressed to look legitimate, via spoof emails, instant messenger/social media or other avenues. Often tactics such as email spoofing are used to make emails appear to be from legitimate senders, or long complex subdomains hide the real website host.[5][6] Insurance group RSA said that phishing accounted for worldwide losses of $1.5 billion in 2012.[7]

Applications used to access Internet resources may contain security vulnerabilities such as memory safety bugs or flawed authentication checks. The most severe of these bugs can give network attackers full control over the computer. Most security applications and suites are incapable of adequate defense against these kinds of attacks.[8]

TCP/IP protocols may be secured with cryptographic methods and security protocols. These protocols include Secure Sockets Layer (SSL), succeeded by Transport Layer Security (TLS) for web traffic, Pretty Good Privacy (PGP) for email, and IPsec for the network layer security.

IPsec is designed to protect TCP/IP communication in a secure manner. It is a set of security extensions developed by the Internet Task Force (IETF). It provides security and authentication at the IP layer by transforming data using encryption. Two main types of transformation that form the basis of IPsec: the Authentication Header (AH) and ESP. These two protocols provide data integrity, data origin authentication, and anti-replay service. These protocols can be used alone or in combination to provide the desired set of security services for the Internet Protocol (IP) layer.

The basic components of the IPsec security architecture are described in terms of the following functionalities:

The set of security services provided at the IP layer includes access control, data origin integrity, protection against replays, and confidentiality. The algorithm allows these sets to work independently without affecting other parts of the implementation. The IPsec implementation is operated in a host or security gateway environment giving protection to IP traffic.

Some online sites offer customers the ability to use a six-digit code which randomly changes every 3060 seconds on a security token. The keys on the security token have built in mathematical computations and manipulate numbers based on the current time built into the device. This means that every thirty seconds there is only a certain array of numbers possible which would be correct to validate access to the online account. The website that the user is logging into would be made aware of that devices' serial number and would know the computation and correct time built into the device to verify that the number given is indeed one of the handful of six-digit numbers that works in that given 30-60 second cycle. After 3060 seconds the device will present a new random six-digit number which can log into the website.[9]

Email messages are composed, delivered, and stored in a multiple step process, which starts with the message's composition. When the user finishes composing the message and sends it, the message is transformed into a standard format: an RFC 2822 formatted message. Afterwards, the message can be transmitted. Using a network connection, the mail client, referred to as a mail user agent (MUA), connects to a mail transfer agent (MTA) operating on the mail server. The mail client then provides the senders identity to the server. Next, using the mail server commands, the client sends the recipient list to the mail server. The client then supplies the message. Once the mail server receives and processes the message, several events occur: recipient server identification, connection establishment, and message transmission. Using Domain Name System (DNS) services, the senders mail server determines the mail server(s) for the recipient(s). Then, the server opens up a connection(s) to the recipient mail server(s) and sends the message employing a process similar to that used by the originating client, delivering the message to the recipient(s).

Pretty Good Privacy provides confidentiality by encrypting messages to be transmitted or data files to be stored using an encryption algorithm such as Triple DES or CAST-128. Email messages can be protected by using cryptography in various ways, such as the following:

The first two methods, message signing and message body encryption, are often used together; however, encrypting the transmissions between mail servers is typically used only when two organizations want to protect emails regularly sent between each other. For example, the organizations could establish a virtual private network (VPN) to encrypt the communications between their mail servers over the Internet.[10] Unlike methods that can only encrypt a message body, a VPN can encrypt entire messages, including email header information such as senders, recipients, and subjects. In some cases, organizations may need to protect header information. However, a VPN solution alone cannot provide a message signing mechanism, nor can it provide protection for email messages along the entire route from sender to recipient.

MIME transforms non-ASCII data at the sender's site to Network Virtual Terminal (NVT) ASCII data and delivers it to client's Simple Mail Transfer Protocol (SMTP) to be sent through the Internet.[11] The server SMTP at the receiver's side receives the NVT ASCII data and delivers it to MIME to be transformed back to the original non-ASCII data.

A Message authentication code (MAC) is a cryptography method that uses a secret key to encrypt a message. This method outputs a MAC value that can be decrypted by the receiver, using the same secret key used by the sender. The Message Authentication Code protects both a message's data integrity as well as its authenticity.[12]

A computer firewall controls access between networks. It generally consists of gateways and filters which vary from one firewall to another. Firewalls also screen network traffic and are able to block traffic that is dangerous. Firewalls act as the intermediate server between SMTP and Hypertext Transfer Protocol (HTTP) connections.[13]

Firewalls impose restrictions on incoming and outgoing Network packets to and from private networks. Incoming or outgoing traffic must pass through the firewall; only authorized traffic is allowed to pass through it. Firewalls create checkpoints between an internal private network and the public Internet, also known as choke points (borrowed from the identical military term of a combat limiting geographical feature). Firewalls can create choke points based on IP source and TCP port number. They can also serve as the platform for IPsec. Using tunnel mode capability, firewall can be used to implement VPNs. Firewalls can also limit network exposure by hiding the internal network system and information from the public Internet.

A packet filter is a first generation firewall that processes network traffic on a packet-by-packet basis. Its main job is to filter traffic from a remote IP host, so a router is needed to connect the internal network to the Internet. The router is known as a screening router, which screens packets leaving and entering the network.

In a stateful firewall the circuit-level gateway is a proxy server that operates at the network level of an Open Systems Interconnection (OSI) model and statically defines what traffic will be allowed. Circuit proxies will forward Network packets (formatted unit of data ) containing a given port number, if the port is permitted by the algorithm. The main advantage of a proxy server is its ability to provide Network Address Translation (NAT), which can hide the user's IP address from the Internet, effectively protecting all internal information from the Internet.

An application-level firewall is a third generation firewall where a proxy server operates at the very top of the OSI model, the IP suite application level. A network packet is forwarded only if a connection is established using a known protocol. Application-level gateways are notable for analyzing entire messages rather than individual packets of data when the data are being sent or received.

Web browser statistics tend to affect the amount a Web browser is exploited. For example, Internet Explorer 6, which used to own a majority of the Web browser market share,[14] is considered extremely insecure[15] because vulnerabilities were exploited due to its former popularity. Since browser choice is more evenly distributed (Internet Explorer at 28.5%, Firefox at 18.4%, Google Chrome at 40.8%, and so on)[14] and vulnerabilities are exploited in many different browsers.[16][17][18]

Antivirus software and Internet security programs can protect a programmable device from attack by detecting and eliminating viruses; Antivirus software was mainly shareware in the early years of the Internet,[when?] but there are now[when?] several free security applications on the Internet to choose from for all platforms.[19]

A password manager is a software application that helps a user store and organize passwords. Password managers usually store passwords encrypted, requiring the user to create a master password; a single, ideally very strong password which grants the user access to their entire password database.[20]

So called security suites were first offered for sale in 2003 (McAfee) and contain a suite of firewalls, anti-virus, anti-spyware and more.[21] They also offer theft protection, portable storage device safety check, private Internet browsing, cloud anti-spam, a file shredder or make security-related decisions (answering popup windows) and several were free of charge[22].

Go here to see the original:
Internet security - Wikipedia

Internet security company launches a perfume line to promote cybersecurity – Mashable


Mashable
Internet security company launches a perfume line to promote cybersecurity
Mashable
Kaspersky is a company that creates software to protect homes and businesses from viruses and internet threats and now they will also be making perfume. The company is partnered with Scarlett London, a well-known fashion and lifestyle blogger based in ...

Read this article:
Internet security company launches a perfume line to promote cybersecurity - Mashable

Firewall Test, Web Tools and Free Internet Security Audit …

I have some fantastic free tools that you cant live without, I cant tell you how many times visitors found and fixed serious flaws on their computer or website that would have leaked private information or given the competition the upper hand!

If youre worried about privacy, concerned with speed or just want to learn more, youll love the security audits, speed tests and free software while webmasters will love our website utilities, such as our link checker, sitemap creator and our website monitoring services.

Our most popular web tools and security services:

Firewall Test: The key to Internet Security begins with a firewall, but when configured wrong, even the best firewall can leave you exposed and vulnerable.Our free firewall test and exploit scanner checks to make sure you are not leaving yourself open to attack!

Digital Footprint: Its amazing how much information a person gives away when they surf the internet; do you know how much personal information you are giving away? Our test will show you your digital footprint so that you can better understand your privacy!

Internet Speed Test: This free Internet Speed Test is extremely accurate, simple to use and results are very easy to understand. Find out if your internet service provider is really giving you the speed you need. Our speed test is voted best on the net!

Antispam: An extremely effective way of taking money out of the pockets of spammers. This is an extremely popular tool and very effective. Help fight spam by using this free tool.

Sitemap Generator: This free tool allows you generate XML Sitemaps for Yahoo, Microsoft and Google Sitemaps. It is an excellent way to check your site for errors, discover load times and gives an external perspective of your site what bots see!

Free Website Monitoring: Own a website and want to monitor it for changes? Find out if your ISP is having problems, pages change or unauthorized ports have been opened on your firewall.

Read more:
Firewall Test, Web Tools and Free Internet Security Audit ...

Internet security in the spotlight: How is the internet safer today than it was 20 years ago? – Mobile Business Insights (blog)

The internet connects users all over the world, promoting communication, education and innovation. Mobile banking and digital wallets simplify commerce for millions, particularly in developing areas. Wearable devices provide users with real-time health and exercise data, while the Internet of Things (IoT) allows everyday objects to communicate with one another, providing superior control and relevant logistics for consumers and businesses alike. As this digital connectivity continues to grow, so does the need to promote safety in all parts of online activity, from financial payments and internet security threats to predatory behaviors and even cyberbullying.

Security experts are stepping up their participation and collaborating across borders to uplift the internets positive influences while addressing its problems. Given the growing role of digital innovation among enterprise brands, even the worlds largest countries have a vested interest in the goals and beliefs organized through this awareness.

By focusing on the good deeds by users that make the internet a safer place, its possible to champion the role younger generations have played in building a better online world. Yet its still important to reflect on the past and to consider which challenges await in the future.

It may sound counterintuitive, but hackers have played a big role in creating a safer internet for modern-day users. However, as VICE pointed out, its wrong to portray all hackers as the bad guys. In reality, many of them are making positive contributions to the safety and integrity of the internet, so much that they are playing the role of a digital immune system.

This is to say that hackers are particularly skilled at sniffing out and eradicating threats. Banking institutions and other companies including entire governments have employed hackers in the past to have them identify potential security weaknesses before a threatening entity can exploit them. The US government famously sponsored a Hack the Pentagon contest that rewarded hackers for identifying bugs in the organizations security front.

VICE also noted that hackers have been actively involved in developing medical device security that prevents malicious hackers from hijacking insulin pumps and injuring or even killing people.

As the reputation for hackers has improved, there has been continued organization and collaboration among these professionals, who have grown more powerful and productive by creating groups devoted to certain types of security. Increased support of these organizations is pushed forward to improve internet security for all users.

Though clear, significant progress has been made in taming the Wild West that was once the internet, plenty of work remains and new challenges continue to surface. Of particular concern in 2017 are the dangers associated with the IoT. This mobile ecosystem has endless potential to transform virtually every aspect of daily life for consumers around the world. However, this deep penetration of mobile technology also presents clear challenges if its leveraged by hackers.

For one, IoT devices create new entry points and new security challenges to overcome. Managing these large ecosystems is hard: A single enterprise could have thousands of devices in its IoT environment, and only one of them needs to be compromised for the entire system to be put at risk. Meanwhile, IoT devices have recently been used to execute distributed denial-of-service (DDoS) attacks, which can be used to direct the traffic of thousands (or even millions) of devices toward a single server, effectively shutting it down and causing it to incur massive security costs.

In cases where mobile technology is being used to save lives, it also creates a security concern that is literally life-or-death to those users. These high stakes require continued attention by the worlds best hackers to ensure its possible to defend against cybersecurity threats.

Today, online users can take comfort in knowing the internet is safer now than it was even a few years ago. Yet as the digital landscape changes, continued efforts must be made to stay ahead of these security threats.

More here:
Internet security in the spotlight: How is the internet safer today than it was 20 years ago? - Mobile Business Insights (blog)

Jim Mullen: Unsocial internet security | Columnists | auburnpub.com – Auburn Citizen

I was having a hard time logging into my newspaper's web page, and finally got a tech person on the phone. After a little while, she asked if she could give me a new password.

Of course I said "yes," but I wondered why I needed a password at all. This wasn't my bank account, it was a newspaper subscription. Was somebody going to pretend to be me, log in and pay my bill? Please, let them. Then I realized, the password was for the newspaper's protection, not mine. They don't want someone reading it online for free. (You can still go down to the diner and read the print version for free, but that's another story.) But something tells me that no hacker would break into a newspaper to read the front page. They'd be looking to raid the paper's bank account. Sorry, can't help you there.

There have been a lot of stories about passwords and chip cards and ransomware and hackers in the news recently. Almost every minute of the day, you can find an expert on TV saying something like, "If you have a computer and it's hooked up to the internet, you've been hacked."

Experts are such a comfort.

Most people I know, even if they use computers at home and at the office, don't know enough about them to tinker with them or add basic security measures like a password manager program, two-step verification and a VPN. Which is why, when you call most companies' help lines, you're put on hold for half an hour. Because everyone with a computer is calling them, and the people smart enough to fix your problem don't want to spend all day talking to dummies like us. It's frustrating to be on either end of that phone conversation.

But here's the odd thing about hackers. If you're smart enough to hack into my computer, you're smart enough to get a real job. A job that pays more than hacking, has health care and retirement benefits, has a nice view of an office park and with little or no chance of being hauled off in handcuffs in the middle of the night by a multinational task force. You might even meet someone at the office that you can date and maybe, eventually have children with. You might make some friends. A highly unlikely scenario in the damp, smelly basement at Hacker Central where you work now, drinking highly caffeinated "energy drinks" and eating leftover pizza. Yes, you probably can't wear sweatpants at a real job and you'll have to pay taxes, but you'll be making a ton of money legally. That's gotta count for something.

Being a hacker must be like being one of those painters who make fake Rembrandts that sell for millions of dollars. First of all, you don't make millions, your dealer does. And if you're that good, why not just paint your own stuff? OK, maybe it won't sell for millions of dollars, but it will sell for something. And even if it doesn't sell, you can brag about it. Bragging about your fake Rembrandts is pretty much a police raid waiting to happen.

The sad thing is that we enable hackers. Research shows that people hate remembering and changing their passwords. Which really isn't a big problem if all you're doing online is reading email from your grandchildren and posting pictures on Pinterest. Who cares if you get hacked? Sure, it's inconvenient, but you can get a new email account. The real problem is that the people who work at your credit card company, at your stockbroker's, at your bank, at your statehouse and in your local and federal government hate remembering and changing their passwords as much as you do.

But don't worry: They're all getting technical help the same way I do: from their 13-year-old neighbor kids.

More here:
Jim Mullen: Unsocial internet security | Columnists | auburnpub.com - Auburn Citizen

Internet-connected ‘smart’ devices are dunces about security – ABC News

These days, it's possible to use your phone and sometimes just your voice to control everything from your TV to your lights, your thermostat and shades, even your car or medical device. (At least, once you have gadgets that can listen.)

But the WikiLeaks allegation that the CIA commandeered some Samsung smart TVs as listening devices is a reminder that inviting the "Internet of Things" into your home comes with some risk.

How safe are your connected devices? Tread carefully, but don't freak out, experts say.

A GROWING INDUSTRY

Connected devices are unquestionably popular. Research firm Gartner expects there to be 8.4 billion connected "things" in use in 2017, up 31 percent from 2016. By 2020, this number could reach 20.4 billion, with smart TVs and digital set-top boxes serving as the most popular consumer gadgets.

For businesses, meanwhile, smart electric meters and commercial security cameras are expected to be the most popular "internet of things" products.

Such gadgets are convenient, but they can present easy targets for hackers. In October of 2016 hackers seized control of webcams and digital video recorders and recruited them into internet "botnets" that launched denial-of-service attacks against popular websites such as Netflix and Twitter, forcing them offline for some users.

LIMITED GOVERNMENT

There's a growing call for regulation to secure connected devices, but it's unclear whether this will happen. Last year, the Department of Homeland Security released a report describing runaway security problems with devices that recently gained internet capabilities, a collection that includes medical implants, surveillance cameras, home appliances and baby monitors.

"The growing dependency on network-connected technologies is outpacing the means to secure them," Department of Homeland Security Secretary Jeh Johnson said at the time. This, of course, was during the Obama administration; more regulation so far appears unlikely under President Donald Trump.

Forrester Research analyst Josh Zelonis said consumers can't wait for the government to fix things. Instead, he said, people have to demand that manufacturers are accountable for the security of their products and that they support the products throughout the product's lifetime, not just when it's sold.

Which, of course, is far easier said than done.

BRAND APPEAL

One problem: Many people don't realize they have to secure connected devices with passwords like they do with computers. "People don't think of a TV or a camera as a computer and that's all it is," said Gartner analyst Avivah Litan.

If a device comes with a default password, it needs changing the moment you hook it up. Similarly, your Wi-Fi password shouldn't still be the one it came out of the box; it needs a hard-to-guess passphrase to ensure that it can't be easily hacked.

Another problem: Cheaper devices from no-name companies also pose more of a security risk. While big companies like Apple, Amazon or Samsung can patch up security holes as soon as they find them, smaller companies don't have the resources or, sometimes, the ability or willingness to do so.

"Bigger companies typically have more resources and more to lose, so they are typically more secure," said Patrick Moorhead, analyst at Moor Insights & Strategy.

Password-protecting most connected devices, though, should go a long way toward ensuring they won't be used to take down Netflix.

"Don't buy from smaller vendors," Moorhead said. "Don't buy devices that don't encrypt data everywhere." And change the password if you can.

MEASURED CAUTION

Sydnee Thompson, a 24-year-old from Troy, Michigan, is cautious but ultimately sanguine about her connected devices. She has an internet-connected TV, but she's been reluctant to get a "smart" device like Amazon's Echo home assistant because of worries that it would always be listening and that others might also.

But Thompson uses a smartphone and already assumes that if the government wants to track her, it can. "If the government wants to find out something about you, they will," she said. "It's just the world we live in."

Cameron Matz from Stafford, Virginia, said he has several smart TVs and plans to keep using them. "We can't be afraid to live our life because some person out in the world is listening in on your conversation about daily activities."

AP Tech Writer Tali Arbel in New York contributed to this report.

See the article here:
Internet-connected 'smart' devices are dunces about security - ABC News

Derry internet security expert warns that advanced internet technology ‘a risk to us all’ – Derry Now

Derry native Robert OBrien, CEO of MetaCompliance, a global Information Security and Compliance software company, says a lack of regulation in the surge of the Internet of Things is posing a serious risk to the general public.

"In the race to develop smart devices for mass consumption, it appears that there was little thought given to security. The rise of the Internet of Things has in turn given rise to an increased cyber threat to our homes.

The Internet of Things (or IoT) is about connecting a growing number of everyday devices over the internet, items that can talk to us, applications and each other.

Mr OBrien made the comments following claims that the US intelligence community has been using the IoT to hack a number of well-known and everyday products including Smart TVs, cars and mobile devices.

He added: The truth be told, when it came to whole internet of things nobody really thought about security. Thankfully that is beginning to change as more and more people become educated to the risks.

He said last months call in Germany for parents to destroy My Friend Cayla dolls further illustrates safety concerns over the IoT.

Researchers said the bluetooth device embedded in the toy could be employed by hackers to listen and talk to children while they play with it.

Mr OBrien said: "There is no doubt that this doll represents a risk to children and there are many other devices which pose a risk. When it comes to children and online cyber threats, a zero tolerance approach is the only response.

The Cayla doll should be considered a computer. Would you let someone access your kids computer? From a security point of view there is only one tip I would offer on this and that is to put it in the bin. I would advise not letting children use these types of devices at all.

He warned that 'there are many items in the same category as this doll in home'.

If you have a story or want to send a photo or video to us please contact the Derry Now editorial team on 028 7129 6600 for Derry City stories Or 028 7774 3970 for County Derry stories. Or you can email [emailprotected] at any time.

An online petition has been created as part of a campaign by two Derry schools to have a shared campus in the city. Groarty Integrated Primary School ...

All good things come to an end, and unfortunately for City of Derry that was the case at the weekend. They couldnt dent the title hopes of Dublin s...

A well-known Derry businessman has died. John Bradley was one of the main figures involved in the long-established Bradley & McLaughlin Funeral Di...

Continued here:
Derry internet security expert warns that advanced internet technology 'a risk to us all' - Derry Now