Credit card thieves are getting smarter. You can, too






Card skimmers have gotten so advanced, even experts may be fooled. But there's a way to spot at least some of them.

With one swipe of a credit card, you've just paid for some gas. You may also have given thieves some very valuable information.

That's if you've just fallen victim to a skimmer.

Card skimmers, which steal your credit or debit card data when you swipe at payment and money machines, have been around for nearly a decade, disguised so you don't know you're being duped. The devices have evolved, though, and researchers say they're now at the point where you really, really can't tell the difference.

Plus, they've swept across the United States at an alarming rate. The number of breached ATMs increased sixfold from 2014 to 2015 and rose again in 2016 by 30 percent, according to FICO, an analytics software company.  In June of this year, the Federal Trade Commission put out a public warning, with tips on how you can avoid having your card information stolen.

Hackers have figured out how to create virtual skimmers -- malware that's installed remotely -- which let them steal card information without even touching the ATM, fuel pump or other device. It's an evolution from the physical skimmers, where thieves had to walk up to a machine to plant their hardware hack. In January 2016, one hacking campaign that used virtual skimmers across multiple ATMs netted thieves $13.5 million euros, security firm Trend Micro discovered.

Skimmers are getting harder and harder to notice, according to Mark Nunnikhoven, Trend Micro's vice president of cloud security. "If a machine has been compromised with software," he said, "there's no way you're able to tell."

As if you didn't already have enough to worry about when it comes to computer security.

This year alone has brought a number of threats from all kinds of angles. A few months back, ransomware took over PCs around the world, holding them hostage for payment, and that likely won't be the last time. Just last week, word came that some versions of the popular CCleaner software had been infected with malware.

Then on the credit card front, there's that massive Equifax hack, which coughed up sensitive information on nearly half the US population.

Yikes.

When 100 credit card numbers can be sold online for $19 a bundle, it's easy to see the appeal for cybercriminals. Credit card information is feeding an entire illicit ecosystem, with some thieves even opening online schools to teach the hackers of the future.

Hackers can create virtual skimmers by breaking into a bank's network -- for instance, by tricking an executive into providing access, as Nunnikhoven has seen. Instead of compromising physical ATMs one at a time, hackers can steal from multiple ATMs all at once. And there's less risk of getting caught.

"ATMs are really just very simple computers that happen to be attached to a box full of cash," Nunnikhoven said. "We have enough problems securing computers that aren't attached to cash."

The gas station problem

Banks are working to stay a step ahead of the thieves, with techniques like introducing chips on cards, which are more secure than the magnetic stripes. New rules are helping, too. As of October 2015, any stores still using old swipe terminals became liable when fraud occurs. That got businesses adopting the new tech pretty quickly. But take note: The rule doesn't apply to gas stations until 2020.

Which means thieves who used to target random ATMs in stores are now swarming to gas pumps instead.

"We're seeing an uptick of skimmers becoming more common at fuel stations," said Angel Grant, director of fraud and risk intelligence at security firm RSA. "We anticipate this to continue to grow."

At gas stations, the skimmers can be installed on card readers in less than 30 seconds, and they'll record all your card data for collection by the bad guys. It's an easy gig: Those pumps are often unattended late at night, and thieves can plug in their skimmers while pretending to get gas.

The skimmer stores the data, and the scammers return to grab the stolen credit or debit card numbers over Bluetooth, without touching the pump again.

Gas station owners aren't likely to rush to make changes. It's more expensive to upgrade pumps than ATMs.





Fighting back

On Reddit, it's a thing now to see posts of people finding card skimmers by fidgeting with the card reader on an ATM and sometimes snapping it right off. But there's an alternative: A programmer at SparkFun Electronics created an app to save you from having to brutalize your local cash machine.

Because the majority of these skimmers use Bluetooth for harvesting the stolen data, your phone should be able to detect them easily. Nathan Seidle, SparkFun's founder, created the Skimmer Scanner app to automatically detect the skimmer's Bluetooth signal, which is most noticeable at gas pumps.

The Boulder-based company worked with local police in Colorado to take a look at a popular skimmer in the region, a module called the HC-05. These modules are typically used for DIY educational projects to provide Bluetooth capabilities on homemade gadgets. But they're also extremely common for credit card skimmers, and cost only $3 each.

"They're obviously mass produced," Seidle said. "It's so cheap that they can just pepper these things all over the place."

Because these skimmers are a bargain, their Bluetooth names can't be changed -- it's always HC-05. They also have a hard-coded default password: "1234." In other words, their weak spot is the same one that can get you in trouble with lots of the gadgets in your home.

The Skimmer Scanner looks for connections with that name; then attempts to connect with the default password, the same way the thief who planted it would. The app then sends the letter "P" as a command to the Bluetooth device, and if it's a skimmer, it'll send back "M." The system has been able to detect skimmers at distances between 5 and 15 feet.

The Android app is available on the Google Play store for free, and in open-source format on Github.

Researchers said the app is a great step in fighting back, given how common the HC-05 Bluetooth module is, but it's not going to stop all skimmers.

Eventually, too, once hackers realize how dumb those Bluetooth modules are, Nunnikhoven said, they'll move onto something that isn't as detectable.

"There's a limited lifetime on apps like Skimmer Scanner," he said. "The attackers are always changing their tactics to avoid getting caught."


Source:  CNET 


China Bans WhatsApp Messenger






Popular instant messaging app WhatsApp has already been struggling for its existence in China ever since July when Chinese government blocked its users from sending photos and videos over the app.

Now, it appears that China has largely blocked Facebook-owned WhatsApp in its latest step to tighten censorship as the country prepares for a major Communist Party gathering next month.
Yes, WhatsApp no longer works in the country at all.

China has a long history of blocking and limiting access to web services, especially social networks and Western-owned sites through its Great Firewall. The service currently blocks some 171 out of the world's leading websites, including Wikipedia, Twitter, Facebook, Instagram, and many Google services in mainland China.
And now, it is WhatsApp.

Although it's unclear how long the messaging app may remain inaccessible in the country, according to Symbolic Software, a Paris-based research firm that monitors WhatsApp's situation in China, the country has restricted its users from sending even text-based WhatsApp messages within its borders.
WhatsApp was seeing severe disruptions as early as last Wednesday when some users reported WhatsApp disruptions in China, but at this time, the service has reportedly been completely blocked and only accessible via VPNs (virtual private networks) which can circumvent China's internet firewall.

But, in case you are unaware, China has begun a 14-month-long crackdown on VPNs and proxy services in the country and made it mandatory for all VPN providers to have a license from the government to use such services.

This move of censoring the end-to-end encrypted messaging app comes ahead of next month's 19th National Congress of the ruling Communist Party.
At this sensitive gathering, which takes place once every 5 years, the Chinese government will select new leaders and determine policy priorities.
By preventing its citizens from using WhatsApp, Chinese authorities hope to force them to use the secure messenger alternatives like WeChat, which offers the Chinese government with its citizens' personal data.

Neither WhatsApp nor its parent company Facebook has provided any comment on this censorship.

The move is a severe blow to the social media giant, whose main website and app have already been banned in China since at least 2009. Facebook-owned Instagram is also blocked in the country.

Now with the blocking of WhatsApp, Facebook's only left hope in China is the photo-sharing app, Colorful Balloons, which the social network stealthily released in the country last month.

Source:  the hackernews 


Why don’t big companies keep their computer systems up-to-date?


The Equifax hack, exposing 143 million people’s personal data to unknown cybercriminals starting in March but not made public until mid-September, was entirely avoidable. The company was using out-of-date software with known security weaknesses. But it appears that with Equifax, as with many organizations, those were just the beginning of the problems.

During the past three decades we’ve researched, developed and tested millions of lines of software for many purposes, including national defense and security, telecommunications, financial services, health care and online gaming. Over the years we’ve observed that the technical means by which a breach happens often reveal software vulnerabilities that need fixing.

But when the digital weaknesses are publicly known before an attack happens – as with the Equifax case – the more important element is why companies don’t move more quickly to protect themselves and the people whose data they store. As suggested by the sudden departure of three top leaders (including the CEO) at Equifax, some of the problem is technical, but another big reason has to do with management and organizational structure.

Interconnected complexity

Equifax, like most Fortune 100 firms, was using an open-source software platform called Apache Struts to run parts of its website. Every major piece of software has vulnerabilities, almost inevitably. When they’re found, typically the company or organization that writes the software creates a fix and shares it with the world, along with notifications that users should update to the latest version. For regular people, that is often as easy as clicking a button to agree to update an operating system or software application.

For businesses, the process can be much harder. In part that’s because many companies use complex systems of interacting software to run their websites. Changing one element may affect the other parts in unpredictable ways. This problem is especially true when companies use the same hardware and software for many years and don’t keep up with every update along the way. It only makes matters worse when businesses outsource their software development and maintenance, denying themselves in-house expertise to call on when problems arise.

The best practices of cyber hygiene suggest combining development and operations (known as “DevOps”) to simplify the process of regular and prompt patches and updates. Not practicing good cyber hygiene is like a doctor not washing her hands – doing so may take extra time and energy, but it protects thousands of patients from infection.

When cyber hygiene works well, it’s quite effective. In April 2017, news broke of a major flaw in iOS and Android systems that allowed hackers to remotely take over smartphones via Wi-Fi. Google and Apple immediately addressed the issue and distributed patches to fix it. This quick response indicates those companies have development and operations processes that meet industry standards for rapid and reliable writing, testing and rollout of software updates.

Trouble at the top

Beyond the inherent challenges in technology and in current business practices, corporate management can play a significant role in whether problems become disasters.

Companies that have systems for regular investment in software maintenance and rapid reaction to security vulnerabilities can respond to problems very quickly, as Apple and Google did. Equifax’s slow response suggests it wasn’t well prepared that way. And the company’s history of outsourcing development to remote off-shore locations suggests there may not have been anyone in-house who had worked on the software needing updating.

Making matters worse, the chief security officer, who retired along with the company’s chief information officer and CEO in the wake of the breach, appears not to have a technical background. That could help explain why Equifax experienced back-to-back breaches requiring outside assistance: the first in March and another in July.

Well-run companies have top executives who know the importance of having cybersecurity teams ready to work around the clock when vulnerabilities arise. And leaders need to understand the risks of placing sensitive information online, rather than the safer practice of storing it on computers disconnected – or “air-gapped” – from the internet. Unfortunately, when senior executives at companies aren’t tech-savvy, they often lack understanding of what’s at stake and how to quickly protect valuable information.

A long road ahead

It looks like Equifax’s troubles aren’t close to being over. After the major breach was revealed, it didn’t take long for victims to discover that even their attempts to freeze their credit would be thwarted by other examples of Equifax’s poor cyber hygiene: The company-created PIN a customer would use to unfreeze credit was based on the date and time of the freeze request, and therefore potentially guessable by an attacker.

More recently, the company’s official Twitter account repeatedly directed the public not to its own security site but to a phishing site seeking to trick people into disclosing their personal information.

All these problems, on top of Equifax’s slowness in repairing the key software vulnerabilities, point to corporate management as a crucial element in preventing and recovering from security breaches – or making them worse.

Source:  The Conversation 


Goodbye, login. Hello, heart scan.

The system uses low-level Doppler radar to measure your heart, and then continually monitors your heart to make sure no one else has stepped in to run your computer. Credit: Bob Wilder/University at Buffalo

A new non-contact, remote biometric tool could be the next advance in computer security.

BUFFALO, N.Y. — Forget fingerprint computer identification or retinal scanning. A University at Buffalo-led team has developed a computer security system using the dimensions of your heart as your identifier.

The system uses low-level Doppler radar to measure your heart, and then continually monitors your heart to make sure no one else has stepped in to run your computer.

The technology is described in a paper that the inventors will present at next month’s 23rd Annual International Conference on Mobile Computing and Communication (MobiCom) in Utah. The system is a safe and potentially more effective alternative to passwords and other biometric identifiers, they say. It may eventually be used for smartphones and at airport screening barricades.

“We would like to use it for every computer because everyone needs privacy,” said Wenyao Xu, PhD, the study’s lead author, and an assistant professor in the Department of Computer Science and Engineering in UB’s School of Engineering and Applied Sciences.

“Logging-in and logging-out are tedious,” he said.

The signal strength of the system’s radar “is much less than Wi-Fi,” and therefore does not pose any health threat, Xu said.

“We are living in a Wi-Fi surrounding environment every day, and the new system is as safe as those Wi-Fi devices,” he said. “The reader is about 5 milliwatts, even less than 1 percent of the radiation from our smartphones.”

The system needs about 8 seconds to scan a heart the first time, and thereafter the monitor can continuously recognize that heart.

The system, which was three years in the making, uses the geometry of the heart, its shape and size, and how it moves to make an identification. “No two people with identical hearts have ever been found,” Xu said. And people’s hearts do not change shape, unless they suffer from serious heart disease, he said.

Heart-based biometrics systems have been used for almost a decade, primarily with electrodes measuring electrocardiogram signals, “but no one has done a non-contact remote device to characterize our hearts’ geometry traits for identification,” he said.

The new system has several advantages over current biometric tools, like fingerprints and retinal scans, Xu said. First, it is a passive, non-contact device, so users are not bothered with authenticating themselves whenever they log-in. And second, it monitors users constantly. This means the computer will not operate if a different person is in front of it. Therefore, people do not have to remember to log-off when away from their computers.

Xu plans to miniaturize the system and have it installed onto the corners of computer keyboards. The system could also be used for user identification on cell phones. For airport identification, a device could monitor a person up to 30 meters away.

Xu and collaborators will present the paper — “Cardiac Scan: A Non-contact and Continuous Heart-based User Authentication System” — at MobiCom, which is billed as the flagship conference in mobile computing. Organized by the Association for Computing Machinery, the conferernce will be held from Oct. 16-20 in Snowbird, Utah.

Additional authors are, from the UB Department of Computer Science and Engineering, Feng Lin, PhD (now an assistant professor at the University of Colorado Denver); Chen Song, a PhD student; Yan Zhuang, a master’s student; and Kui Ren, PhD, SUNY Empire Innovation Professor; and from Texas Tech University, Changzhi Li, PhD.

The research was supported, in part, by the U.S. National Science Foundation.

Source:  Buffalo 


This malware just got more powerful by adding the WannaCry trick to its arsenal

Swiss banks represent a lucrative target for cybercriminals. Image: Getty

A trojan banking malware campaign has returned and now it's leveraging EternalBlue -- the leaked NSA surveillence exploit -- to target Swiss financial institutions.


Developed by the NSA but revealed to the world by a hacking group, the EternalBlue Windows security flaw exploits a version of Windows' Server Message Block (SMB) networking protocol to spread itself across an infected network using worm-like capabilities.

It was by using the EternalBlue exploit that May's WannaCry ransomware attackwas able to spread so quickly. The tool was soon adopted by cybercriminal groups looking to make their malware more powerful -- and now it's being used to steal credentials and cash from Swiss banks by the group behind the Retefe malware.

Active since 2013, the Retefe banking trojan isn't as notorious as the likes of Dridex, but targets banks in the UK, Switzerland, Austria, Sweden, and Japan. It has also been known to target Mac users.


Unlike other banking trojans, which rely on webinjects to hijack online banking sessions, Retefe routes traffic to and from the target banks through proxy servers hosted on the TOR network. These proxy sites host phishing pages designed to look like the the targeted bank's login page in order to steal credentials from victims, providing access to accounts for theft and fraud.


Retefe is typically delivered via phishing emails containing malicious Microsoft Office documents containing embedded Package Shell Objects -- although some contain malicious macros instead. If the user runs the file, a PowerShell command will run the malicious payload and install the code.


Now researchers at Proofpoint have discovered that the payload contains the configuration for EternalBlue, with code taken from a publically available proof-of-concept for the exploit posted in a dump on GitHub. The tool is now used to download the PowerShell script which installs Retefe.


While the addition of EternalBlue, malware can spread across networks. This particular installation of the exploit lacks the module responsible for infinitely spreading the malware as WannaCry did.


However, researchers note that the attackers behind Retefe could be merely experimenting with EternalBlue for now -- and that they could roll out the leaked exploit in full force in future.


"It is possible that the addition of limited network propagation capabilities may represent an emerging trend for the threat landscape as 2018 approaches," wrote Proofpoint researchers.


Indeed, those behind Retefe aren't the only threat actors looking to leverage EternalBlue to make malware more powerful. The attack group behind the Trickbot malware has also been experimenting with deploying the exploit.

Source:  zdnet 


1.4 Million New Phishing Sites Launched Each Month

The number of phishing attacks reach a record rate in 2017, but the majority of the phishing sites remain active for just four- to eight hours.

The average number of new phishing sites created in a given day has skyrocketed to more than 46,000, or 1.385 million each month, according to the Webroot Quarterly Threat Trends Report released this week.

This number of these sites is up substantially from Webroot's quarterly report released in December, which noted more than 13,000 new phishing sites were created daily.

The trend of temporary phishing sites continued with the majority of sites remaining active for only four to eight hours. The purpose of the short-lived sites, according to Webroot, is to avoid detection by such measures as block lists.

Meanwhile, the top 10 websites that were impersonated the most during the first half of the year include:

Google, 35%;
Chase, 15%;
Dropbox, 13%;
PayPal, 10%;
Facebook, 7%;
Apple, 6%;
Yahoo, 4%;
Wells Fargo, 4%;
Citi, 3%; and
Adobe, 3%.


Source:  Darkreading 


DON'T RELY ON AN UNLOCK PATTERN TO SECURE YOUR ANDROID PHONE

SMARTPHONES TODAY COMPETE over which can best secure your secrets. They encrypt your data, store the digital keys to unlock themselves on specialized hardware, and even offer fancy biometrics from fingerprints to faceprints. But many millions of smartphones remain open to an absurdly low-tech attack: a sly glance at someone's phone while they unlock it. One new study has quantified just how easy an Android-style unlock pattern—as opposed to a six-digit PIN or biometric unlock—makes the job of any over-the-shoulder snoop.

Security researchers at the US Naval Academy and the University of Maryland Baltimore County this week published a study that shows that a casual observer can visually pick up and then reproduce an Android unlock pattern with relative ease. In their tests, they found that six-point Android unlock patterns can be recreated by about two out of three observers who see it performed from five or six feet away after a single viewing. Spotting a six-digit PIN of the kind used in most iPhones, on the other hand, proved surprisingly difficult: Only about one in ten observers in the study could reproduce it after one look.

That disparity is in part due to how memorable an Android unlock pattern is for human brains, says Naval Academy professor Adam Aviv. "Patterns are really nice in memorability, but it’s the same as asking people to recall a glyph," says Aviv, who along with his fellow researchers will present the paper at the Annual Computer Security Applications Conference in Puerto Rico in December. "Patterns are definitely less secure than PINs."

In their tests, the researchers recruited 1,173 subjects from Amazon's Mechanical Turk crowdsourcing platform to watch carefully controlled videos of the unlocking online, and had subjects try guessing PINs and unlock patterns after watching the phone's owner unlock it with commonly used PINs, or patterns from five different angles and distances, averaging out those variables. They also repeated the video test with 91 people in person, just to check their online results. They found that around 64 percent of the online test subjects could reproduce a six-point pattern after one viewing, and 80 percent after two. Only 11 percent could identify a six-digit PIN after one viewing, and 27 percent after two.

For Android users who feel attached to their pattern unlock, the study did find one point of solace. Turning off the "feedback" lines that trace your finger's path as you swipe through a pattern helped significantly to reduce snooping potential. Only 35 percent of online test subjects could identify a pattern without those lines. "If you’re using a pattern and you like it, turning off those feedback lines will give you some protection," says Aviv. To do so, go to Settings > Lock screen and security > Secure lock settings, and turn off the Make pattern visible option. (Different Android versions and manufacturers will require slightly different steps.)

There are plenty of other reasons not to trust a pattern to keep your secrets safely locked up. An earlier study (which the Naval Academy's Aviv also worked on) found that the randomness of an unlocking pattern is roughly equivalent to just a three-digit PIN code. Researchers have shown they can vastly narrow patterns down with automated image recognition software based on video recorded from dozens of feet away, and even derived them fairly reliably from the smudge prints on a phone's screen. But the latest study presents evidence of the security mechanism's vulnerability to the simplest, most manual attack method yet.

The PIN versus pattern debate, of course, isn't quite as relevant as it was a few years ago. Today many Android users and most iPhone users unlock their phones with a fingerprint, or soon, with facial recognition. But smartphones still frequently fall back on PINs and patterns, when the phone first turns on, for instance, or when a biometric reader fails. And plenty of security-sensitive users disable biometrics to avoid spoofing attacks, or being forced to unlock their phone by authorities—the Fifth Amendment sometimes protects Americans who refuse to offer up their PIN, but not their finger or face.

The Naval Academy and Maryland researchers' snooping study, though, shows just how vulnerable PINs and especially patterns are to the most low-tech form of hacking there is. The lesson: If you use a pattern, switch to a six-digit PIN, or at least turn off those pattern feedback lines. It may be less convenient, but it beats peering over your shoulder with every unlock.

Source:  wired 


Intel Tiger Lake CPUs to come with Anti-Malware Protection

Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...