Showing posts with label Passwords. Show all posts
Showing posts with label Passwords. Show all posts

Friday, April 14, 2017

Hackers Can Steal Your Passwords Just by Monitoring SmartPhone Sensors


Tuesday, April 11, 2017 Swati Khandelwal





Do you know how many kinds of sensors your smartphone has inbuilt? And what data they gather about your physical and digital activities?

An average smartphone these days is packed with a wide array of sensors such as GPS, Camera, microphone, accelerometer, magnetometer, proximity, gyroscope, pedometer, and NFC, to name a few.

Now, according to a team of scientists from Newcastle University in the UK, hackers can potentially guess PINs and passwords – that you enter either on a bank website, app, your lock screen – to a surprising degree of accuracy by monitoring your phone's sensors, like the angle and motion of your phone while you are typing.



The danger comes due to the way malicious websites and apps access most of a smartphone's internal sensors without requesting any permission to access them – doesn't matter even if you are accessing a secure website over HTTPS to enter your password.


Your Phone doesn't Restrict Apps from Accessing Sensors' Data
Your smartphone apps usually ask your permissions to grant them access to sensors like GPS, camera, and microphone.

But due to the boom in mobile gaming and health and fitness apps over the last few years, the mobile operating systems do not restrict installed apps from accessing data from the plethora of motion sensors like accelerometer, gyroscope, NFC, motion and proximity.

Any malicious app can then use these data for nefarious purposes. The same is also true for malformed websites.

"Most smartphones, tablets and other wearables are now equipped with a multitude of sensors, from the well-known GPS, camera, and microphone to instruments such as the gyroscope, proximity, NFC, and rotation sensors and accelerometer," Dr. Maryam Mehrnezhad, the paper's lead researcher, said describing the research.

"But because mobile apps and websites don't need to ask permission to access most of them, malicious programs can covertly 'listen in' on your sensor data and use it to discover a wide range of sensitive information about you such as phone call timing, physical activities and even your touch actions, PINs and passwords."

Video Demonstration of the Attack
Scientists have even demonstrated an attack that can record data from around 25 sensors in a smartphone. They have also provided a video demonstration of their attack, showing how their malicious script is collecting sensor data from an iOS device.

The team wrote a malicious Javascript file with the ability to access these sensors and log their usage data. This malicious script can be embedded in a mobile app or loaded on a website without your knowledge.



Now all an attacker need is to trick victims into either installing the malicious app or visiting the rogue website.

Once this is done, whatever the victim types on his/her device while the malicious app or website running in the background of his phone, the malicious script will continue to access data from various sensors and record information needed to guess the PIN or passwords and then send it to an attacker's server.


Guessing PINs and Passwords with a High Degree of Accuracy
Researchers were able to guess four-digit PINs on the first try with 74% accuracy and on the fifth try with 100% accuracy based on the data logged from 50 devices by using data collected from just motion and orientation sensors, which do not require any special permission to access.

The scientists were even able to use the collected data to determine where users were tapping and scrolling, what they were typing on a mobile web page and what part of the page they were clicking on.

Researchers said their research was nothing but to raise awareness to those several sensors in a smartphone which apps can access without any permission, and for which vendors have not yet included any restrictions in their standard built-in permissions model.

"Despite the very real risks, when we asked people which sensors they were most concerned about we found a direct correlation between perceived risk and understanding," Mehrnezhad said. "So people were far more concerned about the camera and GPS than they were about the silent sensors."Mehrnezhad says the team had alerted leading browser providers such as Google and Apple of the risks, and while some, including Mozilla and Safari, have partially fixed the issue, the team is still working with the industry to find an ideal solution.

More technical details can be found in the full research paper, titled "Stealing PINs via mobile sensors: actual risk versus user perception," published Tuesday in the International Journal of Information Security.

Tuesday, December 13, 2016

Legion: Here’s how to keep your online accounts safe from malicious attacks by hacker groups

Legion: Here’s how to keep your online accounts safe from malicious attacks by hacker groups

Representational Image
By 
The hacking group Legion seems to be going after high level targets, in a campaign similar to the one executed by OurMine. The Legion group does not seem to be as sophisticated as OurMine, because they are choosing targets from an already compromised data, instead of deliberately finding ways to take down marks of interest. There are some elementary safety precautions that you can take to secure yourself against attacks by groups such as Legion.
One of the OurMine takedowns of Mark Zuckerberg’s social media accounts compromised Twitter and Pinterest at one go. Zuckerberg apparently used a “dadada” as the password, even though Zuckerberg is safe enough to physically put a tape over the webcam of his laptop. Being paranoid is a good idea when it comes to information security, and every additional security measure helps, even if it is a bit of tape. The main takeaway from the attack is to use different passwords for different accounts.
zukerberg_tapes
Paranoia is a security feature
The leaked passwords used by Vijay Mallya in the hack showed that he had taken this precaution to a certain extent. A number of base text strings were used, with variations added on top. Now someone who has access to these base strings and variations can attempt to guess passwords for new accounts. It is important to constantly cycle passwords for critical accounts, and not share the same passwords across services. Variations might be simple to remember, but it is more secure to have completely different alphanumeric strings.
Lastpass is a password manager that works across platforms.
Lastpass is a password manager that works across platforms.
Keeping track of multiple usernames and passwords can be daunting, a secure password manager such as LastPass is better than saving your passwords in a notepad file in your email inbox. The mobile application available on iOS and Android allows users to store their passwords behind the biometric security offered by a fingerprint scanner. One common mistake is to write down your passwords on a sheet of paper, it is worse to list all your usernames and passwords on a single sheet of paper.
Asus ZenFone 3 Laser 18
Constantly cycling passwords protects users from compromised dumps. If a service offers two factor authentication, it is better to activate it to prevent hostile takeovers to accounts. Most popular email, social networking and content distribution platforms support two factor authentication. Another vector of attack is through the secret questions set at time of account creation. Do not key in the actual answers to the questions, as someone who knows users personally can guess the answers. Instead use obscure questions, as well as hard to guess answers, even if a known person attempts to takeover your account. Guessing the answers to the secret questions is one of the most common ways accounts are compromised.
Haveibeenpwnd shows which data breaches contain your data.
Haveibeenpwnd shows which data breaches contain your data.
It is a good idea to check if any of your accounts have already been compromised. Haveibeenpwned is such a service that allows users to check if their email addresses or usernames are compromised in any of the large well known data dumps. These are large dumps of login credentials farmed from compromised third party sites.
The site will let you know in which dump your credentials appear, and you can take steps to safeguard that account. There is also a mention of what details were compromised in the particular hack. Users can sign up to be alerted when their accounts are compromised in future hacks. Checking the site periodically is a good idea to keep your accounts safe.

Saturday, December 3, 2016

App Review: Enpass, an extremely versatile password manager with extensive cross-platform support

password manager apps reviews
password manager apps 

By Rehan Hooda / 03 Dec 2016 , 11:05


Mobile apps are the cornerstone of the smartphone experience, regardless of the platform that one may use. There has been a lot of talk about the whole moving away from apps to services model with the focus on different type of interactions with machines, AI and services with the imminent arrival of bots. But, bots and the full AI experience as portrayed by HAL 9000 in Space Odyssey or Jarvis in Iron Man still seems a distant dream. Apps, manual input of content and effort will still be around until AI services are improved and self-contained with privacy instead of current ‘need to send everything to a server to make sense.’
Cybersecurity1
To begin with, a lot of development has been happening around cyber security. Specially with demonetisation and lot of people moving online for their banking needs, the need to have secure passwords is pertinent. We have seen that despite numerous reports, instructions and advice by experts and services about the need to create a solid password, majority of the passwords are either ‘Password’ or ‘12345’. Thankfully most services which value consumer data security and privacy have mandatory instructions about the number of lower case characters, upper case characters, numbers and special characters should be added to a password.
Image Credit: EcoEnergy Wipro Twitter
Image Credit: EcoEnergy Wipro Twitter
As the number of digital services increase, the number of passwords and sensitive details like the backup security answers or password recovery code needs to be store also increases. Which the increasing amount of data, the need for password wallets or password managers is paramount. Enpass comes to fit the space brilliantly well.
I have been using the app since last 2-3 years and have seen it all, right from rebranding of the UI to republishing the Android app. Enpass is brilliant in every way and has grown with each update. The app is available on a wide range of platforms including iOS, Android, Blackberry, Windows UWP, MacOS, Windows PC, Linux and Chromebook along with a portable pen drive version. The company has also added support for Android Watch and it can be enabled in the Android Watch menu under settings in the Android app.
The app is free to download, however, the mobile apps, for iOS, Android and Blackberry, the company has put a restriction on the number of saved passwords that one can see. The free mobile version of the app only allows users to use and see 20 passwords in your database and beyond that you will need to purchase the app.
Enpass Password Manager Setup
Enpass includes a powerful password generator which lets you generate passwords and save them. It also allows you to tweak the ‘Recipe’ of the password to add in digits, symbols and characters. The app developer has added fingerprint API support for Android and TouchID support for iOS along with an Enpass keyboard for Android where you can authenticate and enter login details in any app using the autofill of the keyboard. Also, the company has added ‘tap to enter login details’ in the app. This feature dubbed as ‘Enpass Autofill Service’ uses the Android Accessibility feature and gives you a ‘Tap to fill’ notification in the notification drawer.
Enpass Password Manager Setup
While adding a new password, it will ask you to select the category of the password where the app provides a template for the data that you can store. You can change the icon of the password to match your service and also add new Field or reorder fields according to your preference.
The exception system of the app is a combination of open source and proprietary code to maximize the security. AES-256 is an industrial standard used by military and 24,000 rounds of PBKDF2 provides users advanced protection against brute force and side channel attacks.
Enpass Password Manager Setup
The app comes with a built-in browser where you can browse the web and Enpass takes care of all the passwords you will use on the internet. The app gives the option to change the User Agent String in the app along with the search engine of the browser. You can open the app and copy passwords and paste them on other apps, but also adds an option to clear the clipboard after specified time.
Enpass Password Manager Setup
Security and Browser options in Settings menu
The most important feature of the app and which I love is the app gives you an option to store the data file on the cloud service of your liking and nothing is stored on Enpass servers. All the data is encrypted with 256-bit AES encryption with 24,000 rounds of PBKDF2 and open-source SQLCipher encryption engine. You can store it on your Google Drive, OneDrive, Dropbox, Box, Folder or WebDAV or ownCloud. Before you start, you are required to set a Master Password which will be used to unlock the encrypted data file. Once set and running, you can set a pin code or fingerprint under the security section.
Even though the app is overall solid and the developer issues updated regularly to introduce new features and fix bugs, I wish that the Enpass Keyboard experience is improved to ensure that one doesn’t have to authenticate the app 2-3 times to enter two simple details.
Enpass Password Manager Setup
Restoring data after Install
Another important feature is the option to backup as well as restore the data over Wi-Fi, which means you can keep the data on a secure pen drive or hard drive and restore and backup the new passwords to the database to external storage or a secure private Wi-Fi. The app is free on desktop and costs $9.99 per platform and I have purchased it on all the mobile platforms that I use. Though $9.99 is slightly on steep side, the amount of functionality offered by the app does complete justice to the pricing.
Do let us know any apps worth recommending in the comments section below.

Tuesday, September 27, 2016

iOS 10 Vulnerability Makes Bruteforcing Backup Passwords Up To 2,500 Times Faster (Updated)

ElcomSoft, a Russian digital forensics and IT security firm, announced that it found a flaw in iOS 10’s backup password mechanism that allows its password cracking tools to bruteforce a password 2,500 times faster compared to when the old iOS 9 mechanism was being used.

iOS 10's Backup Password Mechanism Vulnerability

The firm said that Apple introduced a secondary password verification mechanism for local backups that existed in parallel to the old mechanism. However, the new system allows password-cracking tools to skip certain security checks, and thus bruteforce passwords 2,500 times faster.
The most modern password-cracking tools, including ElcomSoft’s own “Phone Breaker,” use GPU acceleration to bruteforce passwords. However, because the company has just learned about this iOS 10 flaw, it has only had time to update its tools for breaking passwords while using only the CPU. Even so, bruteforcing passwords on iOS 10 is still 40 times faster than bruteforcing them with GPUs on iOS 9.

Backup Passwords, An Easy Target

According to ElcomSoft, the reason its tools now try to focus on breaking the security of backups is because iOS has gotten increasingly more secure, and there are fewer and fewer ways to break into the system and extract its data. Backups remain the easiest vector for now.
Breaking the backup password also gives access to keychain data such as app passwords, authentication tokens, credit card information, Wi-Fi network information, and any other sensitive information that app developers may have thought needs to be stored securely.
Normally the keychain data is encrypted and the key is stored in the Secure Enclave, which can’t be easily hacked. According to ElcomSoft, even if you jailbreak a 64-bit iPhone, you can’t extract the key from the Secure Enclave. However, if you decrypt the backup password, you would be able to decrypt keychain data on a iOS 10 device.

Six Million Passwords Per Second

When testing the new bruteforcing method that takes advantage of iOS 10’s new backup password verification mechanism, ElcomSoft said that it achieved the following results:
  • iOS 9 (CPU): 2,400 passwords per second (Intel i5)
  • iOS 9 (GPU): 150,000 passwords per second (NVIDIA GTX 1080)
  • iOS 10 (CPU): 6,000,000 passwords per second (Intel i5)
Despite the fact that a single dual core Intel Core i5 CPU was being used, ElcomSoft could still try six million passwords every second. If GPU acceleration would be enabled, it’s likely that the tool could bruteforce passwords even faster.
Updated, 9/23/2016, 2:35pm PT: Apple responded to our request for comment with the following statement:
"We're aware of an issue that affects the encryption strength for backups of devices on iOS 10 when backing up to iTunes on the Mac or PC," said an Apple spokesperson. 
"We are addressing this issue in an upcoming security update. This does not affect iCloud backups. We recommend users ensure their Mac or PC are protected with strong passwords and can only be accessed by authorized users. Additional security is also available with FileVault whole disk encryption," he added
Related Posts Plugin for WordPress, Blogger...