Showing posts with label Github. Show all posts
Showing posts with label Github. Show all posts

Wednesday, April 12, 2017

WikiLeaks reveals that NSA has been spying on Pakistan’s mobile networks

WikiLeaks reveals that NSA has been spying on Pakistan’s mobile networks
The US National Security Agency (NSA) has been spying on Pakistan’s mobile networks, whistleblowing organisation WikiLeaks has tweeted. “Hundreds of NSA cyber weapons variants publicly released including code showing hacking of Pakistan mobile system,” @wikileaks tweeted.
According to a report in Express Tribune on Monday, the hacker group “Shadow Brokers” released a new cache of information detailing how the NSA accessed private and public networks in other countries. A researcher on Twitter who identifies himself as ‘x0rz’ decrypted the files and uploaded them on Github, a web-based repository and internet hosting service.
“The researcher confirmed that the archives include evidence of NSA operators’ access inside the GSM network of Mobilink – one of the Pakistan’s most popular mobile services provider,” the report noted. The hacker group had previously released data suggesting the US agency may have been monitoring hundreds of IP addresses in Pakistan. The encrypted files were being decrypted by security researchers around the world.
“Shadow Brokers” had initially wanted to auction its data cache in exchange for Bitcoin but as no buyer turned up, they released the data online. This is not the first time that reports have surfaced claiming that the US NSA is snooping on other countries. According to a Daily Mail report in 2014, WikiLeaks disclosed documents that suggested the Bharatiya Janata Party (BJP) was among six political parties from around the world the NSA was authorised to conduct surveillance on for gathering foreign intelligence. The authorisation was given by a secret American court, it said.
The leak was planned months ahead of Prime Minister Narendra Modi’s visit to the US, the report claimed. Another report in the Washington Post that also came in 2014 said the US has long had broad no-spying arrangements with four countries – Britain, Canada, Australia and New Zealand – in a group known collectively as the “Five Eyes”.
“But a classified 2010 legal certification – approved by the Foreign Intelligence Surveillance Court and included among a set of documents leaked by former NSA contractor Edward Snowden – lists 193 countries [including India], that would be of valid interest for US intelligence,” the Post said.
Publish date: April 12, 2017 11:45 am| Modified date: April 12, 2017 11:41 am

Tuesday, January 31, 2017

Facebook introduces delegated recovery to secure accounts for third party services

Facebook introduces delegated recovery to secure accounts for third party services

Image: Which.co.uk
By 
Facebook has introduced a new method for recovering lost accounts for third party services through a method known as delegated recovery. The new feature is being introduced first for GitHub, and is planned to be rolled out to other third party services based on how well the process works for GitHub. Users can recover their lost GitHub accounts through Facebook verification, instead of using an e-mail address or phone numbers.
The new method is called delegated recovery, and Facebook has published the protocols on its open source site at GitHub. Both Facebook and GitHub intend to publish open source implementations of the security protocol in various programming languages as references for developers. Facebook plans to eventually open up the authentication and account recovery mechanism for any third party service. Facebook also wants to allow users with accounts in third party services, such as GitHub, the ability to recover their lost Facebook accounts.
This is how delegated recovery works. Users have to set up the account recovery process in advance. Users have to save a recovery token that is generated by Facebook on request. The recovery token is encrypted, and Facebook or GitHub does not read any personal information, but only confirm that the person trying to access the accounts is the same. If a GitHub account is lost, users can re-authenticate on Facebook, and Facebook sends the recovery token to GitHub with a timestamped counter-signature. The entire process takes place through a browser, over https, and requires only a few mouse clicks.
Security questions are risky as they expose accounts to compromise by those who personally know the individual. If fake answers are given, the recovery questions are inconvenient. Re-using the same security questions and answers across accounts also exposes the users to more malicious attacks. Using recovery emails and SMS are dated, and do not guarantee end to end security, and are getting less reliable with an influx of the next wave of internet users. Facebook hopes to address these problems with the delegated recovery protocol. Facebook and GitHub will jointly reward those who find security issues with the delegated recovery protocol.
The announcement follows close on the heels of Facebook improving the security of its own accounts by allowing authentication of accounts through physical USB keys. GitHub already supports a login process that authenticates accounts through physical USB keys. The physical USB keys use the U2F standard developed by Google and Yubico.

Saturday, October 22, 2016

Massive DDoS Attack Against Dyn DNS Service Knocks Popular Sites Offline


Massive DDoS Attack Against Dyn DNS Service Knocks Popular Sites Offline






UPDATE — How an army of million of hacked Internet-connected smart devices almost broke the Internettoday.

Cyber attacks are getting evil and worst nightmare for companies day-by-day, and the Distributed Denial of Service (DDoS) attack is one such attacks that cause a massive damage to any service.

Recently, the Internet witnessed a record-breaking largest DDoS attack of over 1 Tbps against France-based hosting provider OVH, and now the latest victim of the attack is none other than Dyn DNS provider.

A sudden outage of popular sites and services, including Twitter, SoundCloud, Spotify, and Shopify, for many users, is causing uproar online. It's because of a DDoS attack against the popular Domain Name System (DNS) service provider Dyn, according to a post on Ycombinator.

DNS act as the authoritative reference for mapping domain names to IP addresses. In other words, DNS is simply an Internet's phone book that resolves human-readable web addresses, like thehackernews.com, against IP addresses.

Dyn DNS is used by many websites and services as their upstream DNS provider, including Twitter, Spotify, SaneBox, Reddit, Box, Github, Zoho CRM, PayPal, Airbnb, Freshbooks, Wired.com, Pinterest, Heroku and Vox Media properties.

All of these sites and services are reportedly experiencing outages and downtime, either completely or partially.

Here's an internet outage map from Level3:
dyn-dns-ddos-attack















According to Dyn DNS, the DDOS started at 11:10 UTC and is mostly affecting its customers in the East Coast of the United States, specifically Managed DNS customers.
"We are aware of the ongoing service interruption of our Managed DNS network. For more information visit our status page," Dyn tweeted.
At the time, it's not clear who is behind this DDoS attack, but the company said its engineers are working on "mitigating" the issue.

Here's the statement posted by Dyn on its website:
"This attack is mainly impacting US East and is impacting Managed DNS customers in this region. Our Engineers are continuing to work on mitigating this issue.

Starting at 11:10 UTC on October 21th-Friday 2016 we began monitoring and mitigating a DDoS attack against our Dyn Managed DNS infrastructure. Some customers may experience increased DNS query latency and delayed zone propagation during this time. Updates will be posted as information becomes available.

Customers with questions or concerns are encouraged to reach out to our Technical Support Team."
What websites are down for you? Let us know in the comments below.

We'll update the story as soon as we get to hear more about the attack. Stay Tuned!
Related Posts Plugin for WordPress, Blogger...