EATING THE BRAINS THAT FEED TECHNOLOGY
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, March 04, 2010

Tracking Down The Dead

There's a fun new research project by public rights fighters at the Electronic Frontier Foundation (EFF). Panopticlick. The boffins there believe it is very likely that you can be (almost) uniquely identified by the cumulation of info in your browser. They say that the sum of installed OS, browser handle, language, plugins, local time zone, usable fonts, etc. form a profile of you that is almost as unique as a fingerprint. A few lines of Javascript can read this out. Even if your browser has a private browsing setting, that doesn't help.

Now you can just add things up. Maybe you have cookies enabled, too. Oh, that will identify you very uniquely. Maybe not, but the server could still get additional info on your rough location and ISP by looking at your IP adress, unless you use a proxy all the time.

A website can easily identify you with those information and link what you do online to your profile and you. For example Google. Just think what the big G knows about you. Their Superbowl commercial made it quite clear, ironically. Life situation, hobbies, sexual preferences, possibly illegal actions even (not depicted in the ad). It can be as detailed as you wish.

There are certain restrictions, of course. For starters, however rare your browser fingerprint may be, it is probably not unique. One in 250.000 browsers may have your info. [check your browser's uniqueness here] But they could still get a specific zombie pinned down by ISP & location. The other restriction is bigger, though. What if I update my browser? Install new plugins? New fonts? Yep, your fingerprint just changed.

With that said you'd have to take certain heuristics into consideration when trying to log someones profile. How many parameters can change in what time span? Well, fonts probably won't get deinstalled, only new ones installed. With new applications for example. A little hard, but achievable.

Now if some site had those info and your real life adress and name - like eBay or some online shop for example - it goes wild. No privacy no more, mister zombie man!

What can you do against it? Pretty much nothing. Changing your browser, plugins and so on every once in a while is not very feasible. Of course you can browse via proxies like Tor to mask your IP, but that can be rather slow and then they could log your traffic or passwords. A few ISPs don't give region handles with their DNS servers, but you have to look a bit to find one. You can deactivate Javascript and every other extension, but that would harshly hinder your internet experience. 

In the end, the digizombie of today has to take that risk. Just think about it the next time you enter something on a website.

Friday, February 26, 2010

QuickNews! A Zombie Choice To Make!

If you live in Europe and run Windows with your automatic updates on, you may have already noticed this when your computer starts up:

»An Important Choice To Make: Your Web Browser!«

This does not only sound like a slogan from the next Obama campaign, but it doesn't look too official, either. And it doesn't look too professional. Maybe a virus? Malware? Is this legit? Yes, yes it is indeed.

This funky [read: fugly] new message is due to our friend, Windows update KB976002. It enables us to choose our browser if we were not smart knowledgeable enough to know that there are other choices besides Microsoft's Internet Explorer.

Why would they do that? Well, let's look at the site it sends us to.


Well, that looks rather...awful? Anyways, in the Terms of Use we see two things. First: Yes, this site is made by Microsoft. [you can only see the imprint in countries where it is required by law, like Germany] Second: Why this page is bugging us.

»BrowserChoice.eu was designed in accordance with a competition law decision issued by the European Commission in December 2009.«


But why does Microsoft do it this way? By making this look awful, not legit and showing no transparency on where this comes from and why it is bugging me, Microsoft has pretty much ashamed itself. Or wasn't it their fault? Did the European Commission tell them to make it ugly, so people wouldn't be brainwashed by the Microsoft CI like good digizombies? Or did they just not want to spend their costy designer's time on making this look pretty, because they have been forced to? I f that is the case - cheap move Microsoft, very unprofessional.

If you have a different default browser than IE - like I do - chances are you will never see this.

Zombies East Of Africa

It was only a question of time. Viruses, worms, trojans and malware already made the jump from computer systems to portable devices like smart phones. Now rootkits are here. Unlike the above mentioned rather unnerving elements, rootkits prove to be a serious security threat. »Security? I'm not saving important data on my iPhone!« you may say. But besides the fact that there are people that have lots of sensitive data on their mobiles, that is not the point here. Think about what your cell knows about you:

- Calls.

- SMS, maybe emails.

- Appointments.

- Names, numbers and adresses.

- It goes where you go.

- It hears what you hear.

In business conferences you have your phone with you. It has a microphone and sending capabilities. Rootkits are able to access all of your phones features including WiFi, calling, speakerphone function and GPRS. Imagine someone listening in on confidential business conferences, tracking your every step. Imagine someone turning on your camera function and speakerphone while you're at home with your life partner. You see what this could mean now, yes?

Our ongoing digizombiefication has lead us to taking our phones everywhere and giving them enough power to run dangerous apps. We created the perfect spies for everyone who wants to get to us.

Flexispy is a small firm that has already incorporated a similar technology in their spyphone products. In case you want to »catch cheating wives or cheating husbands, stop employee espionage, protect children, make automatic backups, bug meetings rooms and check babysitters« or whatever reason they give to make this seem legal. Oh, wait, bugging meeting rooms? I wonder why their office is located in the Republic of Seychelles...

So far Flexispy, the mentioned rootkits and malware spread over pirated games on P2P networks like Doomboot.A-Q and Cabir all have one thing in common so far: They have to be executed/clicked/acknowledged to be installed. So far.

The danger of civil mobile trojans is not too big so far, since they can't spread on their own. What is available to the military can only be rumored so far, but they definitely have an interest here.

Of course there are anti-virus tools for your smart phone available. F-Secure, Symantec, Kaspersky, SimWorks and others all have their fingers on this emerging market, but none of them are able to detect full-blown rootkits right now. And with MetalGearA, mobile trojans armed to disable such security apps have been out for years now, too.

Next time you are in a meeting and someone asks you to turn your cell off, don't just put it in silent mode. Shut it off. No one will be listening right now, but it is hard to say when right now ends and the future begins.