Showing posts with label mobile devices. Show all posts
Showing posts with label mobile devices. Show all posts

Wednesday, 13 July 2016

SumTips: 5 Reasons to NOT Download Pokémon Go

Pokémon in the wild
[Image source: Sadie Hernandez]
If you aren't one of the 10 million people who have downloaded Pokémon Go in the last 2 weeks, consider yourself lucky, not left out. The augmented reality mobile game has been praised for getting gamers off the couch and into the real world, but its unique approach has also proven to bring a host of insecurities.

SumRando offers 5 reasons mobile devices and Pokémon monsters don’t mix:

1.    Unrestricted access to your Google account: iOS users choosing to join Pokémon Go with their Google account were in for a surprise: a code error gave developers “full access” to Google accounts. According to Google, “When you grant full account access, the application can see and modify nearly all information in your Google Account.” Think: sending emails, reading documents and viewing search history and images.

2.    Game “lures” to unsafe locations: In case the threat of utilizing public Wi-Fi wasn’t bad enough (don’t forget your VPN), Pokémon Go allows players to “lure” others to selected locations. Already, four American teenagers have used the feature to target and rob fellow players.

3.    Risk of hacking for users outside of Australia, New Zealand and the United States: Pokémon Go has been officially released in only three countries, leaving eager users in the rest of the world with unofficial, security-compromising versions. Beware: in order to “side-load” unofficial versions, users must first disable security settings, leaving themselves open to malware attacks.

4.    Excessive data collection: Niantic, the startup behind Pokémon Go, has access to precise and general locations of players, as well as USB storage, contacts and network connections for Android users and camera and photos for iPhone users (along with the aforementioned Google account information). In turn, Niantic has the right to share this information with third parties, including law enforcement and buyers. Further, it is unclear how securely the small firm keeps all this data. Just imagine where it could end up…

5.    Risk of data breach: A database as full as Pokémon Go’s is simply a breach waiting to happen. Gary Miliefsky, former U.S. Department of Homeland Security advisor and current CEO of SnoopWall, a cybersecurity company, predicted, “When they hit 25 to 20 million records, they’re going to be breached, and they’re at 10 million right now.”

If you still feel an urge to chase Pokémon characters around town, try the old-fashioned trading cards. Your security will thank you.



SumRando Cybersecurity is a Mauritius-based VPN, Web Proxy and Secure Messenger provider. Surf secure and stay Rando!

Wednesday, 24 February 2016

Mobile World Congress 2016 Highlights Global Internet Inequities

This year’s Mobile World Congress is already shaping up to be one event with two contrasting missions, serving as a reminder that the technology divide between rich and poor is alive and well.

Mobile World Congress, an annual Barcelona event which attracts nearly 100,000 individuals from all walks of the mobile industry, saw a significant shift in focus this year, as the improved smartphone that was once the hallmark of the event no longer captures the attention it previously did: in the developed world, smartphones are reaching a saturation point and in emerging economies they remain out of the price point of the average consumer. As such, while some are busy seeking the next big thing, others are still on the hunt for basic Internet access—and few are looking for a more expensive phone.

Carolina Milanesi of Kantar Worldpanel ComTech summarized the dominant perspective well: “Everyone has a smart phone now. So the sellers need to try to figure out what kind of new devices will get consumers reaching for their wallets and spending their money.” For those with the cell phone they want in their pockets, this year’s Mobile World Congress has been all about the future potential of virtual reality, 5G and even smart cars.

The alternate narrative at Mobile World Congress is one that continues to be championed by Facebook’s Mark Zuckerberg. As the social platform founder pointed out, “It’s amazing that one is sitting here in 2016 and there are still four billion people worldwide who do not have access to internet.” He took advantage of the opportunity to both announce his new Telecom Infra Project and to promote the better-known Free Basics. The former will create a space for companies to collaborate in order to expand telecommunications infrastructure, in turn accelerating the pace of innovation beyond what a traditional model would allow; already, the project has been able to bring connectivity to a Philippine village that was previously without. Zuckerberg further credited Free Basics with connecting more than 1 billion people in 36 countries to basic Internet services and was confident in the service’s future, despite a recent ban in India for violating net neutrality.

Yes, Facebook has made its mission to connect all the world, but Mobile World Congress made clear that it is not alone in this endeavor. For example, American company Obi Worldphone was also in attendance, celebrating the release of its $149 MV1 smartphone. Compatible with Android 5.1 Lollipop or Cyanogen OS, the relatively inexpensive phone hopes to accommodate emerging markets in Asia, Africa, Latin America and Europe.

The disturbing trend that the first two days of Mobile World Congress only served to amplify is the reality that the developed world holds the rights to its own technological innovation as well as the innovation of others. American companies such as Facebook and Obi Worldphone claim to be part of a benevolent movement to bring equal access to all, but, as Mobile World Congress’s lack of interest in traditional mobile development makes clear, they are also part of an enterprising, entrepreneurial society desperately seeking the next big adventure. Emerging markets, take note.


Internet.org, Mobile World Congress, Facebook, State of Connectivity 2015, SumRando Cybersecurity, Secure Messenger, VPN
Internet.org's State of Connectivity 2015 [Source: Internet.org]


SumRando Cybersecurity is a South Africa-based VPN, Web Proxy and Secure Messenger provider. Surf secure and stay Rando!

Wednesday, 31 July 2013

Moscow to Start Tracking Mobile Users in Metro System

This past Monday, Russian newspaper Izvestia reported that Moscow’s metro system will be implementing an elaborate mobile device tracking system that they say will help authorities recover stolen phones. Nope, not suspicious at all.
Image courtesy of whatleydude through Creative Commons
The system experts believe will be implemented is called a “stingray” or “IMSI catcher” and basically tricks phones into using a fake cell tower. The systems have a range of about five meters and will track SIM cards rather than actual devices. As mobile users pass the devices, the system will track SIM card’s mobile subscriber numbers (MSIs), figure out the target’s route, and then relay the data to the station manager.
In an interview with Ars Technica, Privacy International’s Eric King said:
Many surveillance technologies are created and deployed with legitimate aims in mind, however the deploying of IMSI catchers sniffing mobile phones en masse is neither proportionate nor necessary for the stated aims of identifying stolen phones.
Likewise the legal loophole they claim to be using to legitimize the practice—distinguishing between tracking a person from a SIM card—is nonsensical and unjustifiable. It's surprising it's being discussed so openly, given in many countries like the United Kingdom, they refuse to even acknowledge the existence of IMSI catchers, and any government use of the technology is strictly national security exempted.
Apparently, such a tracking system shouldn’t even be legal in Russia, but authorities are saying that because the system tracks SIM cards, which are technically owned by the service provider and not the mobile phone operator, the system is legal.
Experts have pointed out that for the system to be effective, multiple IMSI catchers would need to be deployed in each station, making the system financially ridiculous if its purpose truly is to track stolen phones.

Wednesday, 12 June 2013

Your iPhone will Auto-Connect to Data Thieves

We have harped about a thousand times on the dangers of open Wi-Fi networks. Seriously people, it’s just a bad idea. And now, security researchers say they’ve found a flaw in iPhones that can force users to connect to these networks without them even knowing it.


The flaw is in the configuration settings that are set up by carriers like Vodafone and AT&T.
Imagine you had to manually reconnect each day to your home, work, or favorite coffee shop networks? That would be cumbersome. Operating systems have a great feature, allowing automatic connection to networks they previously connected to. However, this feature has security consequences: attackers can simply guess (e.g., “Apple Store”, “Boingo Hotspot”) or retrieve the SSID of previously used networks, and cause victims’ devices to automatically connect to their rogue network, without the victims’ approval. Once the victims are connected to the rogue network, the attackers can utilize common MiTM (man in the middle) tools…to attack their victims. [Skycure Security]

To test their hypothesis, the researchers took their setup to a popular restaurant in Tel Aviv, Israel and set up a fake Wi-Fi network. 60 people connected within the first minute. Holy smokes! But wait, it gets even better. Even the most security conscious mobile users fell victim. In another test, the folks at Skycure set up a similar fake network at a cybersecurity conference. In just two and a half hours, 448 cybersecurity professionals auto-connected to their network.
Fortunately, the people at Skycure aren’t hackers and never launched attacks on any of the connected iPhones, but the kind of software needed for man-in-the-middle attacks used in this kind of situation is cheap, readily available, and dead-simple to use.
The only real work-around for iPhone users is to turn off Wi-Fi when you’re not using it — which we highly recommend.

You can try SumRando for free here.

Friday, 17 May 2013

Reason You Should Be Using A VPN #428: A Saudi Telecom Company is Trying to Read Your Tweets


A cryptographer who goes by the pseudonym Moxie Marlinspike reported on his blog earlier this week that Saudi telecom company Mobily recently approached him for help with intercepting encrypted data sent from mobile apps like Twitter, Viber, and others.
I learned that they are organizing a program to intercept mobile application data… The project’s requirements come from “the regulator” (which I assume means the government of Saudi Arabia). The requirements are the ability to both monitor and block mobile data communication, and apparently they already have blocking setup. [Thoughtcrime.org]
According to Marlinspike’s email exchange with the Mobily representative, the eavesdropping initiative is part of an effort to curb communications related to terrorism. Unfortunately, a program with this kind of breadth would also result in massive privacy violations for anyone on Mobily’s network. And while Marlinspike claims their level of sophistication is pretty marginal, he also acknowledges Mobily has enough resources to make it happen.
Their level of sophistication didn’t strike me as particularly impressive, and their existing design document was pretty confused in a number of places, but Mobily is a company with over five billion in revenue, so I’m sure that they’ll eventually figure something out. What’s depressing is that I could have easily helped them intercept basically all of the traffic they were interested in (except for Twitter—I helped write that TLS code, and I think we did it well). They later told me they’d already gotten a WhatsApp interception prototype working and were surprised by how easy it was. The bar for most of these apps is pretty low.
Had Marlinspike not been approached, odds are nobody would ever know about this eavesdropping effort. And that’s kind of creepy. We no longer live in a world where default channels guarantee our personal data will remain private. But a good VPN can. So let this story act as a reminder to take your personal privacy and security seriously!

Thursday, 3 January 2013

3 Reasons Owning a Mobile Device will Suck in 2013


Best part of the new year? Predictions!

Will Rihanna leave Chris Brown? Will Katie Holmes date Bradley Cooper? Will we make contact with aliens? Here at SumRando, we are so FREAKING EXCITED for the coming year.

Sadly, the party poopers over at McAfee Labs thought we should hear about some real predictions. Ya know, the kind that are important. In their defense, they put together a pretty good list. Lots of malware, hacking and software issues. But the big takeaway?

Having a mobile device is going to suck this year.

These guys are pretty legit
From mobile worms to malicious apps and ransomware, we are all doomed. DOOMED.

Mobile worms on victims’ machines that buy malicious apps

In 2013, malware installs you!

Once criminals discover a profit-making technique that works, they’re likely to reuse and automate it. For example, Android/Marketpay.A is a Trojan horse program that buys apps from an app store without user permission. We’re likely to see crooks take this malware’s app-buying payload and add it to a mobile worm. Buying apps developed by malware authors puts money in their pockets. A mobile worm that uses exploits to propagate over numerous vulnerable phones is the perfect platform for malware that buys such apps; attackers will no longer need victims to install a piece of malware. If user interaction isn’t needed, there will be nothing to prevent a mobile worm from going on a shopping spree.

Malware that blocks security updates to mobile phones

Think you’re going to update away that app buying malware. How about nope?

One of the advantages that a mobile service provider (as opposed to Microsoft, for example) has in fighting malware is that once the cell company recognizes malware it can automatically push an update to customers to clean their devices. This works on phones that have not been rooted (or unlocked) by their owners. For mobile malware to stick around for a long time, it will have to prevent updates. Putting an app on a store that does nothing more than download external malware which locks the phone from communicating with the cell provider will achieve this.

Mobile phone ransomware “kits” that allow criminals without programming skills to extort payments

Gimme your money or I'll brick the phone!

Ransomware on Windows PCs has more than tripled during the past year. Attackers have proven that this “business model” works and are scaling up their attacks to increase profits. One way ransomware is different from other types of malware—such as backdoors, keyloggers, and password stealers—is that attackers do not rely on their victims using the infected systems for financial transactions to separate them from their money. Instead these criminals hijack the users ability to access data, communicate, or use the system at all. The victims are faced with either losing their data or paying a ransom in the hope of regaining access. One limitation for many malware authors seeking profit from mobile devices is that more users transact business on desktop PCs rather than on tablets or phones. But this trend may not last; the convenience of portable browsers will likely lead more people do their business on the go. Attackers have already developed ransomware for mobile devices. What if the ransom demand included threats to distribute recorded calls and pictures taken with the phone? [McAfee]

Sunday, 16 December 2012

Major exploit discovered in Samsung phones

Whelp, it's that time of the week again. Or at least it seems like a new major exploit is revealed every week. Anyhow, this time it's Samsung's Android smartphones that are falling victim... or at least have that potential.

User Alephzain on the xda developers forum site revealed a security flaw in several Samsung devices (demonstrated on a Galaxy S III) that allows remote access to all physical memory. Such a vulnerability could allow hackers to brick your phone, download malware, or steal some really sensitive information.

"This security hole is dangerous and expose phone to malicious apps," Alephzain wrote in the thread.

Clearly, when an exploit like this is discovered, a public forum is the best place to go first... Fortunately, another forum poster said they had confirmed that Samsung is now aware of the issue. We'll see if they do much about it.

According to the post, the exploit can be used on the following devices:

Samsung Galaxy S2 GT-I9100, Samsung Galaxy S3 GT-I9300, Samsung Galaxy S3 LTE GT-I9305, Samsung Galaxy Note GT-N7000, Samsung Galaxy Note 2 GT-N7100, Verizon Galaxy Note 2 SCH-I605 (with locked bootloaders), Samsung Galaxy Note 10.1 GT-N8000, and the Samsung Galaxy Note 10.1 GT-N8010.

Wednesday, 21 November 2012

OMG sending sexy pics with Snapchat is such a bad idea


“O-M-G!”

Don't be this girl. She ended up on
a cybersecurity blog!
“My BFF Melissa, said she was like talking to Stacy, who like, knows this guy who is like cousins with that super dreamy guy Brian that I like kind of went out with the other weekend. And like this guy said Brian is going to ask me out again. OMG. I should like totally send him a naked picture of myself with Snapchat. There’s like, no way this could go horribly wrong.”

Somewhere, someone said or thought this. And it did indeed go horribly wrong. If you aren’t in the habit of sending saucy pictures over your mobile device, then you probably have no idea what I’m talking about, so let’s back up.

Snapchat is a new app available for Android and iOS devices that allows users to snap a picture of themselves and send it to someone on a timer. Once time runs out (it has a maximum of 10 seconds), the app deletes the picture. Snapchat is marketed to teenagers and young adults who, tend to make poor life decisions send pictures they don’t want around forever. The idea, of course, is to allow users to send naughty pictures without the risk that they’ll be posted on r/gonewild the next day.

As you may have realized by now, this app is the worst idea since black highlighters.

Although Snapchat does indeed delete images after the set amount of time (though the company has issued a disclaimer that basically says “no promises”), there is absolutely nothing stopping the recipient from simply taking a screenshot or using a camera once the picture is on the screen. If a screenshot is taken, Snapchat will alert the sender. But at that point, it’s a little late, and obviously there is no warning should the receiver use a camera to take a picture of the screen.

Look, I’m not saying there is anything wrong with two consenting adults sending each other risqué self-portraits. If you trust one another and understand the risks, by all means, go crazy*. Unfortunately, Snapchat is the kind of app that tries to lull users into a very false sense of security.

Actual security measures like a good VPN are great for a lot of things and will go a long way to keep your private information safe, but in some cases, nothing replaces good old-fashioned common sense.

*For the love of God, use a VPN like SumRando if you intend to send sexy pictures. Our encryption software will make sure only those you intend see your private (literally) information.

Wednesday, 24 October 2012

8% of Android apps are vulnerable to attack


How often do you use apps on your mobile device? If you’re like us, you probably connect to the web via mobile apps dozens of times per day. And, hopefully, like us, you realize that mobile devices are no safer than personal computers when it comes to sending sensitive material over the web. Unfortunately, most people don’t share this sense of caution and operate under the false confidence that mobile devices are hack-proof or somehow more secure than a PC.

But in efforts to test this sense of security, security researchers at the Leibniz University of Hanover in Germany conducted a study looking at ways popular Android apps in the Google Play marketplace handle attacks on security protocols called Secure Sockets Layer (SSL) and Transport Layer Security (TLS).

Most browsers will show a lock image when connecting
via SSL or TLS indicating the connection is secure.
Horrifyingly, the study found that about 8% of the apps examined misused these two security protocols, leaving users’ sensitive information vulnerable to exposure. And we’re talking really sensitive data – think credit card numbers and passwords.

Fortunately, the researchers said they have no evidence these attack strategies are currently being used.

SSL and TLS work by encrypting data over network connections to, theoretically, keep user information safe from extraction. The protocols are used extensively all over the web and especially by Android applications to transmit things like credit card credentials and other sensitive data.

Researchers used a tool called MalloDroid to execute “Man in the Middle” (MITM) attacks on the selected apps. In a MITM attack, the hacker places himself in the middle of a SSL or TLS connection and monitors activity as the app communicates with its target.

We introduce MalloDroid, a tool to detect potential vulnerability against MITM attacks. Our analysis revealed that 1,074 (8.0%) of the apps examined contain SSL/TLS code that is potentially vulnerable to MITM attacks. Various forms of SSL/TLS misuse were discovered during a further manual audit of 100 selected apps that allowed us to successfully launch MITM attacks against 41 apps and gather a large variety of sensitive data. Furthermore, an online survey was conducted to evaluate users' perceptions of certificate warnings and HTTPS visual security indicators in Android's browser, showing that half of the 754 participating users were not able to correctly judge whether their browser session was protected by SSL/TLS or not. [LUH]

More than any time before, we, as consumers, rely on tech providers to protect our sensitive data. But the fact is, no company provides flawless security. At SumRando, we encourage all of our users to not only educate themselves on security issues, but to take responsibility for their online safety with a solid VPN.