Tuesday, 6 August 2013

Aw Crap, Toilets are Hackable

Remember when we only had to worry about our computer being hacked? Those were the days. Unfortunately, as technology improves and an ever-increasing number of otherwise mundane devices are outfitted with microchips and wireless connections, we’ve also seen a rise in security vulnerabilities in everything from mobile phones to pacemakers. And now, sadly (or hilariously), even our toilets aren’t safe.

Security company Trustwave issued an advisory last week that LIXIL’s Satis line of smart toilets is vulnerable to hackers with a penchant for pranks. Among the many vital features of the toilets are the capabilities to play music, raise the lid, flush, and operate the bidet with a Bluetooth connection and an Android app. Unfortunately for the unsuspecting toilet enthusiast, LIXIL hard-coded the Bluetooth PIN “0000” into all of their toilets. This means that any ne’er-do-well with a smartphone can download the “My Satis” app and control any Satis toilet.



An attacker could simply download the "My Satis" application and use it to cause the toilet to repeatedly flush, raising the water usage and therefore utility cost to its owner.  Attackers could cause the unit to unexpectedly open/close the lid, activate bidet or air-dry functions, causing discomfort or distress to user. [Trustwave]

Here at SumRando, we’re wondering why anyone would need to remotely access a toilet. Perhaps they just like a fresh bowl?


And while hacking a toilet may be laughable for the security-minded (or anyone), the widespread neglect of basic security precautions in non-traditional wireless devices is a serious issue. Things like computer-controlled power grids, remote-controlled pacemakers, and digital medical records have dramatically improve our quality of life through greater efficiency and accuracy. But as we increase our connectedness, we also open ourselves up to substantial risk. Moving forward, it is essential that we include security and privacy in any discussion relating to technology. Unless we establish and prioritise cybersecurity best practices, we could find our progress flushed down the tubes.

You can try SumRando for free here.

Wednesday, 31 July 2013

Moscow to Start Tracking Mobile Users in Metro System

This past Monday, Russian newspaper Izvestia reported that Moscow’s metro system will be implementing an elaborate mobile device tracking system that they say will help authorities recover stolen phones. Nope, not suspicious at all.
Image courtesy of whatleydude through Creative Commons
The system experts believe will be implemented is called a “stingray” or “IMSI catcher” and basically tricks phones into using a fake cell tower. The systems have a range of about five meters and will track SIM cards rather than actual devices. As mobile users pass the devices, the system will track SIM card’s mobile subscriber numbers (MSIs), figure out the target’s route, and then relay the data to the station manager.
In an interview with Ars Technica, Privacy International’s Eric King said:
Many surveillance technologies are created and deployed with legitimate aims in mind, however the deploying of IMSI catchers sniffing mobile phones en masse is neither proportionate nor necessary for the stated aims of identifying stolen phones.
Likewise the legal loophole they claim to be using to legitimize the practice—distinguishing between tracking a person from a SIM card—is nonsensical and unjustifiable. It's surprising it's being discussed so openly, given in many countries like the United Kingdom, they refuse to even acknowledge the existence of IMSI catchers, and any government use of the technology is strictly national security exempted.
Apparently, such a tracking system shouldn’t even be legal in Russia, but authorities are saying that because the system tracks SIM cards, which are technically owned by the service provider and not the mobile phone operator, the system is legal.
Experts have pointed out that for the system to be effective, multiple IMSI catchers would need to be deployed in each station, making the system financially ridiculous if its purpose truly is to track stolen phones.

Wednesday, 24 July 2013

Syrian Electronic Army Hacks Viber Support Desk

The Syrian Electronic Army is at it again. This time hacking the support page for the Israel-based instant messaging and VoIP service Viber.

The pro-Assad hacking group claimed to have access to Viber customers' personal details including email addresses and phone numbers, though Viber representatives say no such personal information was accessed.

"Yesterday, the Viber Support site was defaced after a Viber employee unfortunately fell victim to an email phishing attack. The phishing attack allowed access to two minor systems: a customer support panel and a support administration system. Information from one of these systems was posted on the defaced page.
 



The hacked page was defaced with a blue banner that read "Hacked by the Syrian Electronic Army". The SEA can add Viber to a relatively impressive list of hacked sites and Twitter feeds including those of The Financial Times, the Associated Press, The Onion, The Guardian, Al Jazeera, and others.

Monday, 22 July 2013

Experts Say Non-U.S. VPNs Provide Better Protection

CSO Online published an awesome piece pointing out that non-U.S.-based VPNs (like SumRando) can provide an edge in protecting your information from surveillance programs.
Foreign VPNs can make snooping more difficult for U.S. government agencies because the service providers are immune from the Patriot Act. If the provider does not keep any logs on its subscribers, then collecting data would be even more difficult. [CSOOnline]
Did I mention that SumRando never keeps logs?
Remember, a VPN works by encrypting all of the information coming and going from your computer. So even if an agency like the NSA were to intercept that data stream, all they’d have is a bunch of heavily garbled content that could take years to decrypt.
The problem with American-based VPNs, as the article points out, is that they are subject to American laws like the PATRIOT Act that could require them to turn over user information. In that case, any encryption would be rendered useless because the company could turn over plain-text records.

A solid VPN along with updated anti-virus software and strong passwords should act as the foundation of every web user’s privacy and security arsenal. SumRando VPN offers 10 GB of service for free and never logs your data. Why not give us a try?

Wednesday, 17 July 2013

Google Has Your Wi-Fi Password. Does the NSA?

Just in case you haven’t already donned a tinfoil hat in light of Edward Snowden’s NSA revelations, here’s a little extra motivation. According to the Electronic Frontier Foundation (EFF), Android users who use the “back up my data” feature on their devices could be serving up their Wi-Fi passwords to data harvesters like the NSA.
Disclaimer: No evidence exists that the NSA is actually logging passwords and it is irresponsible to suggest otherwise unless actual evidence is provided. EFF has demonstrated that it is simply possible.
“The ‘Back up my data’ option in Android is very convenient,” wrote Micah Lee, staff technologist at the EFF. “However, it means sending a lot of private information, including passwords, in plaintext to Google. This information is vulnerable to government requests for data.” [ArsTechnica]
Ostensibly, Android’s backup feature is outstanding and frankly a responsible thing to use. It sends data including your call logs, system settings, and browser bookmarks to Google’s cloud so they can be easily retrieved should you lose your phone. Unfortunately, since the data is sent in plain text, any information requests could very well include more sensitive data like your Wi-Fi passwords.
“Since backup and restore is such a useful feature, and since it's turned on by default,” wrote Lee, “it's likely that the vast majority of Android users are syncing this data with their Google accounts. Because Android is so popular, it's likely that Google has plaintext Wi-Fi passwords for the majority of password-protected Wi-Fi networks in the world.”
And if that’s not unsettling enough, don’t forget that Google also mapped most of those Wi-Fi networks with their Street View program. It wouldn’t take much to link the location of the network and the corresponding password for anyone interested in snooping.

Have we mentioned you should use a VPN when you’re on Wi-Fi?