Sunday, 24 July 2016

3D print of a murdered man's fingers to unlock his phone



Credit: Planet Biometrics

Using a fingerprint in place of a PIN or password to secure your phone is not a way to improve security.

This has been emphasised by news that Professor Anil Jain of Michigan State University is producing 3D prints of a murdered man’s fingers, as an aid to police unlocking the victim’s phone. Police hope that information in the phone may help them in identifying the murderer.

http://gizmodo.com/police-want-to-3d-print-a-dead-mans-fingers-to-unlock-h-1784102211
/ Apple help break in to hack iPhone police 3D print fingers dead man fingerprints unlock phone Michigan State University professor Anil Jain six U.S. patents fingerprint recognition police laboratory ask for help catching murderer ongoing investigation scans victim’s fingerprints previous arrest unlocking his phone make model provide clues killed PhD student Sunpreet Arora printed all 10 digits scans coated them layer metallic particles mimic conducive skin easier read final 3D-printed fingers aren’t finished ready for police try many phones biometric data require PIN entered used two days fingerprint unlock legality case further proof fingerprints not really safest way securing private data dead man judge ruled suspects required unlock phone fingerprint Fifth Amendment protects right avoid self-incrimination illegal force give out passcode biometric indicators fingerprints not covered Fifth Amendment ruling PIN
/

Saturday, 23 July 2016

How secure is your fitness tracker?



Microsoft Band 2
Credit: AV-Test

Your fitness band or smartwatch collects a lot of important data about you, & communicates it to your smartphone. At each step, personal data is potentially open to interception by third parties.


Striiv Fusion
Credit: AV-Test

Some health insures provide various incentives for policy holders to buy & use fitness trackers. Rationale is that fit policy holders are healthier & so cost the health insurer less. Some insurers require evidence, from the fitness tracker, that the user is reaching targets. This can create an incentive for the user to tamper with data.


Pebble Time – fewest risk points among the devices tested
Credit: AV-Test

AV-Test evaluated 8 fitness bands & watches:

Apple Watch
Pebble Time
Basis Peak
Microsoft Band 2
Mobile Action Q-Band
Runtastic Moment Elite
Striiv Fusion
Xiaomi MiBand

https://www.av-test.org/en/news/news-single-view/seven-fitness-wristbands-and-the-apple-watch-in-a-security-check-2016/
/ how secure fitness band fitness tracker smartwatch smart watch smart-watch seven fitness wristbands Apple Watch security check 2016 fitness wristbands smart watches extremely popular sports fans health insurance companies subsidizing purchase tracker rewarding their use fit people cost insurance companies less experts from AV-TEST examined 7 fitness wristbands Android Apple Watch security result manufacturers disappointing errors smart watches fitness wristbands trackers popular recommended health insurers Europe legal playing field health insurance companies subsidize wearables United States offers premium rebates policyholder is able to demonstrate efforts per fitness tracker New York startup Oscar Health pays policyholders one dollar per day reach daily fitness goal 2014 over 26 million wearables sold 2015 75 million 2016 exceed 100 million high security risks fitness trackers test evaluated latest best-selling fitness wristbands Pebble watch Apple Watch wristbands operate corresponding app Android smartphone findings summarized test trackers apps laboratory very detailed test report available as a PDF Apple Watch special case test methods cannot be directly applied Android iOS evaluation Apple Watch products tested Basis Peak Microsoft Band 2 Mobile Action Q-Band Pebble Time Runtastic Moment Elite Striiv Fusion Xiaomi MiBand Apple Watch experts focused two special issues perspective private user data recorded tracker app secure against spying hacking third parties health insurers other companies data tracker app secure against tampering attackers may use data exploit user's disadvantage private data rightly needs to be protected health insurance companies reward policyholders policy holders reaching fitness goal fitness tracker app manipulated exploited eventually tamper tampering three test steps risk assessment testers fitness wristband 10 testing criteria tracker application online communication graph risk assessment test candidates testers criterion as a risk fault security gap not chosen heightened or high risk penetration areas evaluated explicitly open door testers hack risk area analyzed attacker consequences tracker connection authentication tampering visibility fitness trackers use Bluetooth connect smartphone traditional problems examined first security aspect invisibility for Bluetooth devices can't connect rack during pairing devices visible security offered wristbands Microsoft Pebble Mobile Action claims capability still visible BLE privacy Bluetooth safety aspect function BLE privacy feature Android 5.0 feature device repeatedly generates new MAC address Bluetooth connection actual address never disclosed therefore not trackable technology only used Microsoft Band 2 ability to be found device connected very secure solution exclusive Bluetooth pairing tracker only allows connection one known smartphone test only used by Basis Peak Microsoft Band 2 Pebble Time allows connections several devices user required manually confirm each one that is also secure Xiaomi MiBand simple yet safe method successful pairing no longer visible allows no more connections wristbands from Striiv Runtastic Mobile Action fail to use reliable technology prevent connections unknown devices authentication third-party smartphone successfully paired tracker additional safety feature authentication secondary security threshold consistently Basis Peak Microsoft Band 2, Pebble Time Xiaomi use the technology quite simple to circumvent additional security implement it inadequately tamper protection health insurance companies courts rely authenticity data tested integrity safeguard access protection data stored in the tracker protection configured prevents access third parties eliminates tampering data smartphone owner Basis Microsoft Pebble Xiaomi basic protection device Xiaomi fooled weak authentication third-party make wristband vibrate change alarm times completely reset the tracker to factory settings fitness trackers Striiv Mobile Action adequate functioning authentication safety mechanisms vulnerable to tampering Striiv Fusion values body measurements user changed superhuman parameters used as inputs calculation distance traveled calorie burn tracker Mobile Action modify stored user information weight height step length test values used directly calculation calorie burn distance traveled app safeguarding code check local storage technology tracker secure corresponding app smartphone weakest link testing apps save data accessible other apps smartphone security functions non-rooted rooted root Android devices prevent access data saved accessible to everyone Xiaomi MiBand committing this error stores extensive log file app activity completely open area log transmitted data user information body measurements authentication process code obfuscation second test object Identify sloppy programming apps apps use code obfuscation technology prevents reverse engineering hides useful information from attackers apps Mobile Action Pebble Xiaomi technology apps Basis Runtastic raised flags obfuscation enable attackers products Microsoft Striiv obfuscation perform an app analysis log debug info programming error output log debug information important information outputs security mechanisms defeated process app Mobile Action works cleanly information attackers secure online communication connections app communication monitored un encrypted transmitted good news connections encrypted encrypt intercept intercepted open HTTP connections unencrypted contents secure connection readable installation of a root certificate evaluation possible pathway users manipulate transmitted data Basis Pebble security sufficiently protected against unwanted access monitor secure connections successfully tamper with them authentication synchronization data readable lack of security fitness wristbands similar errors current test security risk assessment trackers Pebble Time Basis Peak Microsoft Band 2 most secure minor errors offer few opportunities attackers tampering test smaller defects firmware update fitness wristband Mobile Action multiple risk factors function invisible has deficiencies authentication tamper protection test user data modified back door Runtastic Striiv Xiaomi most risk points products tracked easily authentication tamper protection code apps obfuscated data traffic manipulated monitored root certificates Xiaomi stores data unencrypted smartphone comprehensive security study testing fitness trackers Apple Watch security check Apple Watch fitness tracker iPhone safely handle data retrieved test Apple Watch configured Android devices iOS Android risk criteria performed not relevant Apple device trackers controlled visibility BLE privacy controlled connectivity online communication connections encrypted manipulated using root certificates visibility Bluetooth controlled by the user watch constantly tracked BLE privacy different MAC address Bluetooth newly activated almost impossible to track airplane mode switched on and off genuine MAC address Bluetooth components controlled connectivity Apple special theft prevention technique Watch paired with an account released with great effort factory reset thief sells smart watch new user Apple Watch uses encrypted connections additionally secured updates unencrypted via HTTP connections encrypted further secured testers read information geo data of user location street address Android devices root certificate installed connections monitored user more access data tamper Apple Watch high security rating testers vulnerabilities attackers gain access watch /

Friday, 22 July 2016

Adobe Flash – two more nails in the coffin



Credit: PC World

There are a number of reasons to disable Flash on your browser – most obvious is security. Adobe asked users to stop using it months ago.

Soon there will be two more reasons to remove Flash content from web sites

● almost all Flash content will be blocked by Google’s Chrome browser by the end of the year

● Mozilla’s Firefox will block, “certain Flash content that is not essential to the user experience”, starting in August


http://www.lifehacker.com.au/2016/07/mozilla-will-start-blocking-superfluous-flash-content/
/ Mozilla blocking superfluous Flash content Google committed to blocking Adobe Flash Chrome browser Mozilla stop non-essential Flash content displayed Firefox browser starting August HTML5 supplanted Flash preferred technology support rich media websites good riddance Flash numerous security vulnerabilities concerted effort move websites off Flash plugin Mozilla blog post August Firefox block Flash content user experience support legacy Flash content future changes Firefox users enhanced security improved battery life faster page load better browser responsiveness Firefox blocking specific Flash content invisible to users reduce Flash crashes hang hangs minimise website compatibility problems changes limited to a short curated list Flash content replaced with HTML HTML5 Mozilla moving away from plugins implementing web APIs replace their functionality drop all APAPI plugins Flash /

Thursday, 21 July 2016

2014 was the hottest year on record – until 2015



Another record high temperature year apparently in progress
Credit: NASA/National Oceanic & Atmospheric Administration (NOAA)/Climate Central

But look at 2016.

Last post about the continuing series of record hot years, on these pages, was in January of this year.

Unfortunately, as shown in the graph at the top of this item, the trend which was apparent in January has continued.

http://www.climatecentral.org/news/first-half-of-2016-record-hot-by-far-20540

And June 2016 was the 14th consecutive month of record heat for the globe.1 Fourteen consecutive record hot months is, in itself, a record.

NOAA has a summary of global climate information for every month since January 2012 at https://www.ncdc.noaa.gov/sotc/summary-info/global/201201
__________

1 NOAA: “Global Summary Information - June 2016”, https://www.ncdc.noaa.gov/sotc/summary-info/global/201606
/ First half 2016 blows away temp records record hot June 2016 will be the hottest year on record globally data released running average global temperatures during 2016 monthly numbers from NASA National Oceanic and Atmospheric Administration NOAA planet on track surpass 2015 hottest on record 2016 blown that out of the water Gavin Schmidt director NASA’s Goddard Institute for Space Studies 2016 boost exceptionally strong El Niño record temps excess heat built up in Earth’s atmosphere accumulating greenhouse gases heat raising global sea levels disrupting ecosystems more extreme weather events every month this year has been record warm globally among the first ever recorded exceed 1°C 1.8°F above average NASA NOAA all six months of the year so far exceeded that remarkable benchmark compared to preindustrial temperatures El Niño temperature departures record-high levels June above 20th century average NOAA above 1951-1980 average NASA June record warm for the contiguous U.S intense record-breaking heat wave NOAA record unprecedented 14 consecutive record-hot months streak Deke Arndt head climate monitoring division NOAA National Centers for Environmental Information long-term warming trend setting records beyond anything we had seen before early 2015 June’s record heat year-to-date above the 20th century average NOAA above average NASA temperatures excess global temperature data baselines comparing temperatures long-term warming trend nations have agreed goal keeping warming under 2°C 3.6°F above temperatures from preindustrial times manmade greenhouse gases increasing in the atmosphere end of the century current global temperatures into perspective NASA NOAA data two datasets averaged compared average from 1881-1910 preindustrial era above the average Arctic sky-high temperatures this year record-low sea ice levels roasting Arctic temperatures extended into Alaska hottest temperature Arctic coast oceans persistent warmth NOAA global average ocean temperature above the 20th century average largest such departure in 137 years of records elevated temperatures record third year of a global coral bleaching event water changes temperature air landglobal ocean heat temperatures record pace forecasts predictions La Niña global temperatures year warmest long-term trend of warming is clear record heat of the 15 warmest years on record, 14 have occurred in the 21st century warmest on record climate variability factors strength of the La Niña warmest years on record /

Wednesday, 20 July 2016

SpaceX rocket lifts off on cargo run, then lands at launch site (video)



Falcon 9 SpaceX rocket launches a Dragon capsule from Cape Canaveral – next stop for the Dragon capsule is the International Space Station – next stop for the Falcon 9 launch vehicle is a controlled landing just a few miles from the spot this photograph was taken
Credit: AP/The Sydney Morning Herald

A Falcon 9 SpaceX rocket launched from Cape Canaveral at 00:45 USA EDT (04:45 GMT) on Monday 08 July.

At the top of the 23 story space vehicle was a Dragon capsule packed with almost 5,000 pounds (2268kg) of payload, including a 7.8 feet (2.4 m) docking ring. When attached to the International Space Station, it will allow docking with the manned vehicles currently under development by SpaceX & Boeing. First test flights are scheduled to begin in 2017.

After separation of the Dragon capsule, the Falcon 9 flew itself back to a point just a few miles south of its launch pad.

Video below is just over 30 minutes in length
Ten second countdown begins just after 16:45
Landing begins around 24:50



https://uk.news.yahoo.com/spacex-rocket-lifts-off-cargo-060218878.html

http://www.smh.com.au/technology/sci-tech/spacex-rocket-lifts-off-on-cargo-run-then-lands-itself-at-launch-site-20160718-gq8jmi.html

http://www.reuters.com/article/us-space-station-spacex-idUSKCN0ZY0BA
/ SpaceX rocket lift off cargo runlands launch site unmanned SpaceX rocket blasted off Cape Canaveral Florida early Monday cargo ship International Space Station landed itself launch site 23-story-tall Falcon 9 rocket Elon Musk’s Space Exploration Technologies SpaceX lifted off Cape Canaveral Air Force Station Dragon capsule 5,000 pounds 2,268 kg food supplies equipment miniature DNA sequencer first to fly in space aboard capsule metal docking ring diameter 7.8 feet 2.4 metres meters attached station commercial spaceships under development SpaceX Boeing ferry astronauts station $100-billion laboratory orbits orbit flies 250 miles 400 km above Earth manned craft scheduled begin test flights next year NASA retired fleet space shuttles United States Russia ferry astronauts ISS International Space Station cost more than $70 million per person Dragon cargo ship two-day journey station Falcon 9 booster rocket separated flew itself back to the ground touch touching down south launch pad pair sonic boom good launch good landing Dragon NASA technology SpaceX developing rockets refurbished re-used slashing launch costs touchdown SpaceX successfully landed Falcon rockets ground ocean platform SpaceX launch recovered rockets Hans Koenigsmann vice president mission assurance /

Tuesday, 19 July 2016

US Government operational security guidance for intelligence officers & friends playing Pokémon GO


You are probably aware of the malware risks associated with playing Pokémon GO, but there are other risks, including those to privacy & physical safety.


Who is Thomas Rid? He's Professor of Security Studies at King's College London & author of “Rise of the Machines”.
/ official app application download developer Niantic Google Play Store Apple App Store malware GPS data connection WiFi 3G 4G data play playing geotag geo-tag geo tag geotagged geo tagged geo-tagged personal email Gmail account log in login Google credentials expose your credentials app owner security holes patched playing Pokémon GO Pokémon Trainers Club throw away Gmail account trainer name screen name mindful of surroundings taking pictures foreground background revealing identity location street signs government buildings disable AR embedded in photograph picture metadata physically visiting Pokéstop gym driving capture /

Monday, 18 July 2016

Edna the electric drive train test mule meets Tesla & Ferrari at the drag strip (video)


California-based electric-car startup Atieva recently drag raced its powertrain test mule, Edna, against a Tesla Model S & a Ferrari California.



It’s not the best looker, but Edna gets to the finish line first. Which variant of the Tesla Model S is used in the race isn’t specified, but it is unlikely to be the highest performing P90D – at least not in Ludicrous mode. Tesla claims that a P90D in Ludicrous mode can reach 60 mph (96.6 kph) in 2.8 seconds.1 Edna, as the video shows, is credited by its creator with a 0-60 mph time of 3.08 seconds.

On the other hand, the test mule is hampered by a heavier body with inferior aerodynamics. Atieva claims that their production vehicle will reach 60 mph 0.4 seconds faster than Edna – that's faster than a P90D in Ludicrous mode. However, production is planned for 2018, & it is likely that Tesla will have something faster by then. Many other manufactures have electrics on the drawing board – other startups & some established names – so the Atieva production vehicle is likely to enter a crowded market.

http://electriccarsreport.com/2016/07/watch-edna-electric-van-beats-tesla-ferrari-drag-race/

http://electrek.co/2016/07/13/atieva-edna-races-all-electric-van-against-tesla-model-s-ferrari-video/


http://www.roadandtrack.com/new-cars/future-cars/news/a29996/where-did-this-900-horsepower-electric-van-come-from/
__________

1 Tesla Motors: https://www.tesla.com/models/design
/ California based electric-car startup Atieva recently race powertrain test vehicle mule Edna Tesla Ferrari drag race Edna converted Mercedes-Benz Vito commercial van Ferrari California Tesla Model S lining up specs Tesla startup Model S P90D Ludicrous mode drag race Atieva test vehicle Edna two electric motors two sets of power electronics two gearboxes one battery storing 87 kWh energy over 900 horsepower software components Edna test powertrain system motor control algorithms regenerative braking behaviors accelerator pedal feel cooling strategies Edna electric van accelerate 0 to 60 mph 3.08 seconds Atieva chassis body final product 60 mph 0.4 seconds faster Atieva engineering former Tesla VP Model S Chief Engineer Peter Rawlinson working luxury electric sedan 2018 electric-car startup raised significant funding build half-billion-dollar electric car factory California /