Though somewhat deterred by the major takedown of two popular underground marketplaces, cybercriminals have found alternative solutions that are growing more popular, according to new research from Digital Shadows.
A new report, Seize and Desist: The State of Cybercrime in the Post-AlphaBay and Hansa Age, found that the cybercriminal community has only been slightly quieted by the Operation Bayonet takedown of AlphaBay and Hansa, which forced tens of thousands of vendors and buyers to find new places to conduct business. Mistrust and fear have contributed to the decline of centralized marketplaces, as has the significant cost factor involved in establishing a new market.
Rather than investing in new marketplaces, criminals are focusing their processes and procedures on improving marketplace security and trust in existing sites. These tactics include blockchain DNS, user vetting and site access restrictions, domain concealment, and migration to chat and peer-to-peer (P2P) networks.
Vetting and limiting the user base is an additional challenge for site operators, who need to ensure only reputable and genuine users have access, particularly since forum users are skeptical of each other, aware that law enforcement can be posing as sellers.
To confront the issues of trust, communities have created a forum life cycle, a process by which administrators can limit new users’ access to a forum through mechanisms such as posting limits and area access restrictions.
Moving away from the centralized marketplace in favor of a more diffuse model was trending even before Operation Bayonet, and criminals are now using Telegram to conduct transactions across decentralized markets and messaging networks.
"Over the last six months, the Digital Shadows analyst teams have detected over 5,000 Telegram links shared across criminal forums and dark web sites, of which 1,667 were invite links to new groups," the report said. These covered a range of services, including cashing out, carding and cryptocurrency fraud.
Rick Holland, CISO and VP of strategy at Digital Shadows, said, “The FBI takedown has for now made the dark web marketplace model less viable. As it stands, the marketplace model appears to be in decline, but it would be naive to assume that law enforcement efforts such as Operation Bayonet have drastically reduced cybercriminal risks to both businesses and consumers."
"Instead," he continued, "as recent developments have shown, cybercriminals have taken to incorporating new processes, technologies and communication methods to continue their operations. The barriers to entry have shifted upwards and criminals are more likely to be deceived by each other. However, cybercrime ‘will find a way.’”
Source: infosecurity
Cybercriminals Work Around Road Blocks
Facebook defends sharing user data with mobile OEMs
Facebook is defending its privacy and data management practices again after the New York Times on Sunday reported that the social media giant has entered into agreements over the last decade to share user data with at least 60 mobile device manufacturers, in an effort to make its services and experiences available to device owners via integrated APIs.
According to the Times, these partnerships, which reportedly were extended to companies like Apple, Amazon, BlackBerry, Microsoft and Samsung, raise concerns that the company may not have been fully complying with a 2011 FTC consent decree -- a suggestion that could once again turn up the heat on Facebook following its Cambridge Analytica data-sharing controversy.
The Times further reports that the data sharing agreements, 22 of which have already been phased out (in April, Facebook announced it would wind down access to the APIs), have allowed Facebook's OEM partners to access the personal data of users' friends without their explicit consent -- even those who previously denied permission to share information with third parties.
Despite Facebook leadership's contention that they have largely prohibited third parties like Cambridge Analytica from accessing such user data since 2015, they apparently excluded OEMs from these restrictions, the Times report states.
In a blog post, Facebook defended itself by explaining that mobile device manufacturers are considered trusted partners who essentially act as extensions of Facebook.
"Given that these APIs enabled other companies to recreate the Facebook experience, we controlled them tightly from the get-go," states the blog post, authored by Ime Archibong, Facebook's VP of product partnerships. "These partners signed agreements that prevented people's Facebook information from being used for any other purpose than to recreate Facebook-like experiences. Partners could not integrate the user's Facebook features with their devices without the user's permission. And our partnership and engineering teams approved the Facebook experiences these companies built."
Facebook also disputed the Times' claims about OEMs having access to users' friends' information, asserting that "friends' information, like photos, was only accessible on devices when people made a decision to share their information with those friends."
Source: SC
Samsung is making a Snapdragon-powered PC
Samsung is the latest device manufacturer to take a chance on Snapdragon-powered PCs, joining the ranks of HP, ASUS and Lenovo. In addition to its new Snapdragon 850 chipset, Qualcomm announced today that the Galaxy phone maker will be integrating the card "in a future device." Given Samsung already makes Windows-powered convertibles like the Galaxy Book, which are portable enough to meet Microsoft's requirements for the "Always Connected PC" ecosystem, it's entirely possible that the upcoming device is a 2-in-1.
Since connected PCs are supposed to be smartphone-like in battery life and cellular connectivity, Samsung's expertise as a smartphone maker could give it an edge over traditional laptop brands. There aren't too many other details available, so all we can really do now is imagine and speculate on what that device might look like. Meanwhile, this collaboration is a significant one for Qualcomm as it continues to grow its list of partners for the Windows on Snapdragon platform.
Source: Samsung
Researchers power tiny medical implant from over 100 feet away
Researchers at MIT are working on tiny implantable devices that can communicate and be powered wirelessly. In the future, they could be used to deliver drugs, treat disease or monitor conditions from inside a human body. Because the devices don't require a battery, they can be pretty small and the prototype the research team has been working with is about the size of a grain of rice. But the researchers think they can get the devices to be even smaller than that.
Traditionally, using radio waves to communicate with a device inside of a human body has been difficult because the waves spread out as they pass through human tissue. But the MIT researchers, working with scientists at Brigham and Women's Hospital, created a new type of antenna system that overcomes this problem and has allowed them to communicate and power their implantable devices from a significant distance. When the device was embedded 10 centimeters deep within a pig, the researchers could send power to it from up to a meter away. When the device was just under the skin's surface, it was able to be powered from as far as 38 meters away.
"There's currently a tradeoff between how deep you can go and how far you can go outside the body," Fadel Adib, an assistant professor in MIT's Media Lab, said in a statement. "Even though these tiny implantable devices have no batteries, we can now communicate with them from a distance outside the body," he added. "This opens up entirely new types of medical applications."
The scientists are now working to improve the system's efficiency and expand the distances from which they can communicate with the devices. Their work will be presented at the Association for Computing Machinery Special Interest Group on Data Communication annual conference in August.
Source: Engadget
The Snapdragon 850 is Qualcomm's first chip built for Windows PCs
Qualcomm has developed a hobby. It's been building specialized chips for the Internet of Things and VR headsets lately, in addition to its smartphone-focused and wearable products. Today at Computex 2018 in Taiwan, the company unveiled the Snapdragon 850 -- a processor designed specifically for Windows devices. The chip is supposed to drive a new generation of Windows on Snapdragon devices around this holiday season, made by Qualcomm's numerous partners. In fact, Samsung announced today that it will be making a 2-in-1 PC powered by the Snapdragon 850.
So how is a made-for-PC chipset different from one for a phone? Not much, really. Since the Snapdragon 850 is meant to be used in devices bigger than a smartphone (like laptops and convertibles), it can run at higher clock speeds without overheating. The extra space in larger chasses allows for better dissipation. Thanks to the faster 2.96GHz clock speed (among other tweaks), the Snapdragon 850 is about 30 percent faster than the 835.
Qualcomm also optimized the Snapdragon 850's frequencies and software for PCs, but the processor's 10nm architecture is largely similar to the 835. These improvements led to noticeably quicker performance on a reference device armed with an 850, compared to the Snapdragon 835-powered laptops I've tested so far. I lightly edited a webcam-taken picture on Adobe Photoshop, and the system was surprisingly smooth and responsive. On the ASUS NovaGo, which I reviewed earlier this year, running Photoshop was possible but unstable.
I also enjoyed playing a couple rounds of 64-bit game Vendetta on the device. Since Microsoft launched 64-bit support for ARM-based PCs at Build this year, not many developers have gone to the trouble of recompiling their apps for the platform. VLC the video player was the first to do so, and Vendetta joins that list. While I wasn't blown away by the graphics on the reference device's 2K display, I was satisfied that there was no lag as I shot down several spaceships by jabbing repeatedly at the connected touchpad. If more developers recompile their apps for ARM 64, it could lead to faster performance on Windows on Snapdragon in general.
The Snapdragon 850 supports HDR displays and 4K capture through the onboard camera. While it seems ridiculous to use a laptop or tablet's camera to shoot in 4K, Qualcomm's senior director of product management Miguel Nunes told Engadget that he has seen that people want higher definition and quality to record things like training videos for video conferencing.
Qualcomm also included its X20 LTE modem on the Snapdragon 850, which it says will enable up to 1.2Gbps transfer speeds, and allow about "90 percent of operators to achieve gigabit LTE with LAA (License Assisted Access) technology." That could mean faster and more prevalent coverage for the Snapdragon-powered PCs.
In addition to all the features I've already described, the 850 is also supposed to last up to 25 hours, depending on your use. That's a lot longer than the 20 hours that the existing crop of connected PCs provide, which was already impressive. Granted, the NovaGo got less than 20 hours on our battery test, though, so that estimate might not match realworld results.
All told, Windows on Snapdragon remains an enticing platform. The Snapdragon 850, together with Microsoft's effort to natively support 64bit apps, could address some of the biggest existing problems around performance and compatibility.
Source: Engadget
Confirmed—Microsoft Buys GitHub For $7.5 Billion
Facebook Accused of Giving Over 60 Device-Makers Deep Access to User Data
After being embroiled into controversies over its data sharing practices, it turns out that Facebook had granted inappropriate access to its users' data to more than 60 device makers, including Amazon, Apple, Microsoft, Blackberry, and Samsung.
According to a lengthy report published by The New York Times, the social network giant struck data-sharing partnerships with at least 60 device manufacture companies so that they could offer Facebook messaging functions, "Like" buttons, address books, and other features without requiring their users to install a separate app.
The agreements were reportedly made over the last 10 years, starting before Facebook apps were widely available on smartphones.
Most notably, the publication suggests that the partnerships could be in breach of a 2011 consent decree by the Federal Trade Commission (FTC), which barred Facebook from granting other companies access to data of users' Facebook friends without their explicit consent.
During the Cambridge Analytica scandal revealed in March this year, Facebook stated that it already ceased allowing such third-party access in 2015 only, but the publication suggests that this does not include "makers of cellphones, tablets and other hardware."
Facebook is under heavy fire since the revelation that consultancy firm Cambridge Analytica had misused data of 87 million Facebook users to help Donald Trump win the US presidency in 2016.
In a recent test conducted by an NYT reporter on a 2013 Blackberry device using his Facebook account with roughly 550 friends, a BlackBerry app called "The Hub" was still able to harvest private data from 556 of his friends, including their religious and political views.
Not only that, but The Hub was also able to acquire "identifying information" for up to 294,258 friends of his Facebook friends.
Facebook, who said in front of Congress in March that "every piece of content that you share on Facebook you own. You have complete control over who sees it and how you share it," responded to the NYT report later Sunday in a blog post entitled "Why We Disagree with The New York Times."
In the post, Facebook said the company created the APIs for Amazon, Apple, Blackberry, HTC, Microsoft, Samsung and other device makers so that they could provide Facebook features on their operating systems at a time when there were no apps or app stores.
The post, written by VP of Product Partnerships Ime Archibong, said the data agreements with the device makers were a necessity:
"In the early days of mobile, the demand for Facebook outpaced our ability to build versions of the product that worked on every phone or operating system. It's hard to remember now, but back then there were no app stores."
"So companies like Facebook, Google, Twitter and YouTube had to work directly with operating system and device manufacturers to get their products into people's hands. This took a lot of time—and Facebook was not able to get to everyone."
"To bridge this gap, we built a set of device-integrated APIs that allowed companies to recreate Facebook-like experiences for their individual devices or operating systems. Over the last decade, around 60 companies have used them—including many household names such as Amazon, Apple, Blackberry, HTC, Microsoft, and Samsung."
The post further said that Facebook controlled these APIs tightly and that its partners signed agreements that prevented Facebook users' information from being used for anything other than to "recreate Facebook-like experience."
"Partners could not integrate the user's Facebook features with their devices without the user's permission. And our partnership and engineering teams approved the Facebook experiences these companies built," the post reads.
"Contrary to claims by the New York Times, friends' information, like photos, was only accessible on devices when people made a decision to share their information with those friends. We are not aware of any abuse by these companies."
Due to the popularity of iOS and Android few people rely on these APIs to create bespoke Facebook experiences, which is why the social network giant began "winding down" the partnerships in April, and so far ended 22 of these partnerships.
Source: The hacker News
Intel Tiger Lake CPUs to come with Anti-Malware Protection
Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...
-
Last April, Steven Schoen received an email from someone named Natalie Andrea who said she worked for a company called We Purchase Apps. She...
-
Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...
-
By Carl Herberger This is Part 2 of our series on the top 5 most dangerous DDoS attacks and how you can successfully mitigate them. ATTAC...
