Archive for May, 2018

Cell Phone Tracking Firm Exposed Millions Of Americans’ Real-time Locations

Posted in Commentary with tags on May 18, 2018 by itnerd

You’ve likely never heard of a company called LocationSmart. But I will let security researcher Brian Krebs tell you why you should care:

On May 10, The New York Times broke the news that a different cell phone location tracking company called Securus Technologies had been selling or giving away location data on customers of virtually any major mobile network provider to a sheriff’s office in Mississippi County, Mo.

On May 15, ZDnet.com ran a piece saying that Securus was getting its data through an intermediary — Carlsbad, CA-based LocationSmart.

Wednesday afternoon Motherboard published another bombshell: A hacker had broken into the servers of Securus and stolen 2,800 usernames, email addresses, phone numbers and hashed passwords of authorized Securus users. Most of the stolen credentials reportedly belonged to law enforcement officers across the country — stretching from 2011 up to this year.

None of that is good. But it actually gets worse. Apparently the LocationSmart website had a bug in its website that allowed anyone to see where a person is located without obtaining their consent:

LocationSmart’s demo is a free service that allows anyone to see the approximate location of their own mobile phone, just by entering their name, email address and phone number into a form on the site. LocationSmart then texts the phone number supplied by the user and requests permission to ping that device’s nearest cellular network tower.

Once that consent is obtained, LocationSmart texts the subscriber their approximate longitude and latitude, plotting the coordinates on a Google Street View map. [It also potentially collects and stores a great deal of technical data about your mobile device. For example, according to their privacy policy that information “may include, but is not limited to, device latitude/longitude, accuracy, heading, speed, and altitude, cell tower, Wi-Fi access point, or IP address information”].

But according to Xiao, a PhD candidate at CMU’s Human-Computer Interaction Institute, this same service failed to perform basic checks to prevent anonymous and unauthorized queries. Translation: Anyone with a modicum of knowledge about how Web sites work could abuse the LocationSmart demo site to figure out how to conduct mobile number location lookups at will, all without ever having to supply a password or other credentials.

“I stumbled upon this almost by accident, and it wasn’t terribly hard to do,” Xiao said. “This is something anyone could discover with minimal effort. And the gist of it is I can track most peoples’ cell phone without their consent.”

Well, that’s very disturbing. This demo software was promptly taken offline when the story broke. But there’s a larger issue here. Which is the security of your data and what you should expect in terms of privacy. A US senator is poking around the edges of this, but this requires a more stringent response. As in the four telcos and all of the companies above need to come in front of congress to answer some tough questions about this.

Guest Post: NordVPN Discusses What Happens To Millions Of Facebook User Profiles Scraped by Scholars?

Posted in Commentary with tags on May 17, 2018 by itnerd

Just two months ago, the #deletefacebook hashtag was trending all over the Internet due to the Cambridge Analytica scandal. Back then, it was revealed that Facebook had allowed third parties to scrape users’ personal data. Aleksandr Kogan, a University of Cambridge psychology professor, had obtained the data of about 87 million Facebook users, which was then used in the Trump election campaign, among others.

Since then, it has come to light that – besides Mr. Kogan – various other scholars have been harvesting information from Facebook accounts, capturing the behavior of millions of individuals.

For example, Swedish and Polish researchers were using a program called “scraper” that logged every comment and interaction from a selected number of Facebook pages for about two years.

“It is still not clear how the data of these millions of scraped profiles is being used,” said Marty P. Kamden, CMO of NordVPN. “As for Cambridge Analytica, at least we know where this data went –it was used to influence elections. How about all the other millions of profiles, collected by other scholars? We know that academic institutions do not always have experts in online security and data protection. Past experience shows that lots of this private information is stored on unsecure servers, and may be sold to marketers, stolen by hackers or handed over to political parties or consulting firms.”

The retained data may include people’s interests, preferences, geographical location, political profile and much more. The amount of collected data allows to match it with profiles and identify the actual people hiding behind anonymized profiles and to target them with specific messages, whether commercial or political. It can also end up in the wrong hands, allowing hackers to expose private information or to blackmail Facebook users.

NordVPN recommends following some simple rules that can help avoid being tracked on Facebook. It’s important not to use any third-party apps, such as quizzes, that require access to a user’s profile. It’s also advisable to revoke access to Facebook apps that are no longer in use or that offer users to get likes or followers.

Outside of Facebook, users should use ad blockers, regularly delete cookies and install anti-tracking browser extensions, such as Disconnect Private Browsing or Privacy Badger. Using a VPN is also crucial – it helps to browse the Internet privately and encrypts the data between a user’s device and the VPN server.

Review: Anker PowerLine Micro USB 3ft Cable

Posted in Products with tags on May 17, 2018 by itnerd

I needed a bunch of Micro USB cables to charge my cycling gear. To that end, I picked up six of these cables:

NRmzCIdtTW+r8DOR22OVWA

This is the Anker PowerLine Micro USB 3ft Cable which bills itself as a cable that is rugged and charges faster because it is made of thick gauge wire and has reduced cable resistance. Now the charging part is hard to quantify with the items that I was testing them with as they didn’t support fast charging. But I will say that this is a quality cable. It’s reinforced at both ends to resist breakage. It has an outer shell that is clearly made to be durable. Plus it comes with a velcro strap to keep things neat and tidy.

The price makes this cable a total winner. I paid $7 per cable on Amazon and come in five different colors as well as they come in a variety of lengths and types. If you need to pick up a few cables for your devices, this is great option for you.

Review: Anker 60W 6-Port Family-Sized Desktop USB Charger with PowerIQ Technology

Posted in Products with tags on May 17, 2018 by itnerd

Last year I got a high tech road bike that has a Garmin cyclocomputer as well as front and rear safety lights that need to be recharged. Ditto for my wife and her bike. Thus I decided to have a dedicated charger for it. We travel with our bikes as evidenced by our trip to Newfoundland last year, so it has to be easy to pack as well and should be able to be used worldwide.

Enter the Anker 60W 6-Port Family-Sized Desktop USB Charger with PowerIQ Technology:

igot1p63sfudunnuqvh0a.jpg

Above you can see the charger as well as the power cable it comes with. It also comes with an adhesive strip to allow you to stick the charger to a wall or under a cabinet. It measures 14.6 x 13.8 x 3.8 cm which means it takes up very little real estate. Yet it will still charge six devices.

If you need to use this somewhere other than North America, it can support 100-240V, though you’ll have to source your own cables or use an adapter. If you have a phone that supports Qualcomm Quick Charge 3.0 technology, it will charge your phone at high speed. It feels very solidly built and I think it will hold up over repeated usage. When I tested it by charging all the cycling gear at the same time, it didn’t even get warm which implies that its ability to manage heat is great.

The best part about this charger is the price. I paid $40 CDN on Amazon which is great value for money in my mind. If you have a big family, or you need to charge a lot of devices, this is a must buy as far as I am concerned.

NovaTel GPS Technology Employs Darktrace’s Defenses

Posted in Commentary with tags on May 16, 2018 by itnerd

Darktrace, the AI company for cyber defense, has today announced that NovAtel, part of global technology group Hexagon AB, has selected the Enterprise Immune System to defend its network. NovAtel’s concerns about state-sponsored cyber criminal activity and insider threat led it to deploy Darktrace AI for proactive cyber defense of its valuable intellectual property.

NovAtel’s high-precision Global Positioning System (GPS) technology is utilized across industries for drone helicopter-steering, autonomous vehicles, and emergency dispatch systems. The organization joins a long list of innovative technology companies, including Inphi, Raspberry Pi, and MACOM, that rely on Darktrace to secure their IP.

Darktrace is the world’s leading AI company for cyber defense. Created by mathematicians, the Enterprise Immune System uses machine learning and AI algorithms to detect and respond to cyber-threats across diverse digital environments, including cloud and virtualized networks, IoT and industrial control systems. The technology is self-learning and requires no set-up, identifying threats in real time, including zero-days, insiders and stealthy, silent attackers.

CRTC Steps In To Fix Emergency Alert System

Posted in Commentary with tags , on May 16, 2018 by itnerd

According to the Financial Post, the CRTC is working with all of its partners to fix the technical errors that caused the test emergency alerts to be inconsistently distributed to Canadians. Which is a good thing as the rollout of this system can best be described as a hot mess as evidenced by everything in this post on the subject. The fact that a real alert earlier this week which was an Amber Alert sparked complaints highlights the fact that action needs to be taken immediately to fix this.

Now I have been very critical of the CRTC over the years. But if they can fix this and give Canadians the alert system they need and deserve, I’ll all for it.

In A Further Snub Of The UK Zuckerberg Goes To Brussels To Explain The Data Leakage Scandal

Posted in Commentary with tags on May 16, 2018 by itnerd

Apparently Facebook CEO Mark Zuckerberg does want to speak to foreign politicians about the data leakage scandal. According to EU President Antonio Tajani, Zuck has accepted an invite to go to Brussels Belgium to meet with the EU Parliment. Which is interesting because he blew off a similar invite from UK politicians only yesterday:

https://twitter.com/EP_President/status/996766251765682176

It isn’t clear yet whether Zuckerberg’s meetings at the EU Parliament will be held in public or behind closed doors. But the fact that he’s going at all is a clear middle finger to politicians in the UK who I am sure are trying to come up with some way to compel him to make an appearance in London whether he wants to or not.

Rogers Responses To The Lack Of Apple Watch LTE Support Appear To be Incredibly Tone Deaf

Posted in Commentary with tags on May 16, 2018 by itnerd

Even though I am no longer a Rogers wireless customer so that I could get an Apple Watch (review to come in the next couple of weeks by the way), I still follow this story as I get a lot, and I do mean a lot of comments from frustrated Rogers customers on this. As I watch Rogers try to deal with what must be a public relations nightmare, I note a very disturbing trend in terms of how Rogers is responding to this. Rogers seems to be responding in a way that seems to be incredibly tone deaf. Take this response that Rogers served up to a Twitter user:

Justin Prest has a point here. Rogers from what I could tell didn’t even try to say anything to keep a 25 year customer. I point that out because I have seen the people behind Rogers social media accounts try to jump in to save a customer who is talking about leaving. Instead they stuck with a modified version of the party line which is “We don’t currently support Apple Watch. Keep an eye on our website for updates on our products and services.” Now I guess you can’t get in trouble for repeating that. But it really doesn’t help them to give their customers the warm and fuzzies. And now customers are even trolling them on that:

Now the second tweet was sent two minutes after the first one. Keep that in mind as I post what Rogers replied with:

Well. Mr Patrick called it. Either Rogers didn’t see the second Tweet, or they simply don’t care and are sticking to the party line. Also, by the time customers start calling the responses from Rogers on Twitter like Babe Ruth calls home runs, Rogers has a major problem on its hands. As in, they have lost the plot when it comes to managing this from a PR perspective. That’s not good if you’re Rogers.

Then there’s this:

https://twitter.com/NigelMather13/status/996360810120318976

Now this could be fact, or a salesperson in a Rogers store or authorized dealer going rogue. But in the absence of actual facts, it allows this sort of thing to happen. That’s not good for anyone.

I’ve said it before and I will say it again. Though I will say it again packaged slightly differently. Instead of these incredibly lame and tone deaf responses, Rogers needs to simply come out and say what their plans are. Or, if they’ve not going to support the Apple Watch with LTE, just say so and put an end to this so that customers can make decisions on the telco that best meets their needs. If they are going to support it, say when. Cookie cutter responses are not winning the day for them, thus they really need to demonstrate that their customers matter to them by not giving them tone deaf responses.

Leading Canadian Power Company Entegrus Fortifies Security Posture with Pulse Secure

Posted in Commentary with tags on May 16, 2018 by itnerd

Pulse Secure, the leading provider of Secure Access solutions to both enterprises and service providers, today announced that Entegrus has successfully deployed Pulse Policy Secure advanced network access control (NAC), to strengthen overall visibility and access security across their hybrid IT infrastructure. Entegrus, a Canadian energy company, leveraged their existing Pulse Secure virtual private network (VPN) implementation to expedite NAC deployment and fortify their infrastructure in accordance with National Institute of Standards and Technology (NIST) and North American Electric Reliability Corporation (NERC) guidelines. As a result, their security organization extended visibility for remote and on-premise users and devices, as well as enhanced endpoint compliance and Internet of Things (IoT) risk mitigation.

Entegrus serves over 58,000 customers throughout Ontario. They bring electricity, renewable energy and water across three large regions, with a workforce spread out over 2,300 square miles. Entegrus’ objective is to provide safe, reliable and cost-effective provision of energy and related billing services, while providing high levels of service to its customers, partners and the communities it serves. IT security plays a critical role in protecting their delivery of energy and data services.

Ensuring always active control while maintaining flexible, seamless access to network and application resources is an essential requirement for utility providers. Within such highly regulated industries, best practices dictate a constant cycle of security readiness review and improvement to meet an increasingly potent threat posed by cyber threat actors. NAC provides foundational endpoint intelligence, resource access enforcement and IoT defenses that support industry and regulatory compliance guidelines. These compliance requisites apply to both regional and large national critical infrastructure providers.

For stretched IT departments, Pulse Secure’s Secure Access solutions are designed to streamline deployment and on-going administration using an easy, integrated, policy-driven platform that works with a customer’s existing installed base and network infrastructure. In addition, Pulse Secure’s VPN solution utilizes the same endpoint client, policy engine and appliance management as the NAC solution. Entegrus took advantage of this platform capability to rapidly implement NAC. As a result, they gained dynamic intelligence, unified policy management, automated enforcement and threat response through a single management console. Organizations can read the complete case study at https://www.pulsesecure.net/customer-success/entegrus-strengthens-security-posture.

Numerous benefits exist, including a simplified method of managing complex policies and user access rights, as well as an enforceable method of checking end-point devices to ensure that only properly patched operating systems can connect to the network. Another advantage of Pulse Policy Secure was evident after Entegrus recently merged with London, Ontario-based St. Thomas Energy.

Here’s a video on this deployment:

Zuckerberg To British MPs: Screw You, I Ain’t Talking To You

Posted in Commentary with tags on May 16, 2018 by itnerd

Okay. Maybe he didn’t say that. But he might as well have given that he’s once again rebuffed British MP’s attempts to get him to testify about the data leakage scandal in Parliament. This comes via a letter (Warning: PDF) from Facebook to the Digital, Culture, Media and Sport Committee. Considering that he and his minions are not fully answering questions that the MP’s are putting to them, it sets up a bit of a Mexican standoff. MP’s can’t bring him in from the US to testify. And he can avoid having to testify if he never goes to the UK. Thus it isn’t clear what the next steps are. But I will say that the optics of this suck for Zuck as it looks like he has something to hide and he thinks he’s above the law. After all, a reasonable person or company would want to clear the air when it comes to a matter of this importance. Thus why doesn’t he want to clear the air?