ody Tech Savvy: technology
Showing posts with label technology. Show all posts
Showing posts with label technology. Show all posts

Former US Spy Chiefs Urge Congress To Renew Internet Surveillance Law

Tuesday, 24 October 2017

The program, authorised under Section 702 of the Foreign Intelligence Surveillance Act, allows US spy agencies to eavesdrop on and store vast amounts of digital communications from foreign suspects living outside the United States.

Former US intelligence officials who worked for both Republican and Democratic presidents urged Congress on Monday to renew an internet surveillance program they said has stopped terrorist plots and helped policymakers steer through international crises.
The program, authorised under Section 702 of the Foreign Intelligence Surveillance Act, allows US spy agencies to eavesdrop on and store vast amounts of digital communications from foreign suspects living outside the United States. It will expire on December 31 if Congress does not act.

"We have personally reported to our Presidents - Republican and Democratic - and to the Congress details of plots disrupted based on information from Section 702," the former intelligence chiefs said in letters to congressional leaders that were seen by Reuters.

"We strongly urge the Congress to reauthorize the program and continue allowing the intelligence community to protect our country," they wrote.

The letter's signatories include former directors of US national intelligence, the CIA and the National Security Agency; and a former attorney general.

Rights groups, including the American Civil Liberties Union, oppose the law in its current form because it sometimes incidentally collects communications of Americans. Those communications can then be subject to searches without a warrant by the Federal Bureau of Investigation for criminal and national security investigations.
The Senate Intelligence Committee is expected to privately vote on Tuesday on a bill to reauthorize Section 702 that privacy advocates say will largely lack their reform priorities.


Senator Ron Wyden, a Democratic member of the panel, sent a letter on Monday urging committee leaders to allow a vote to take place publicly, saying the bill "will have enormous impact on the security, liberty, and constitutional rights of the American people" and should be debated in the open.

A bipartisan group of lawmakers in the House of Representatives earlier this month introduced legislation intended to install new privacy protections for 702 surveillance, including a partial restriction on the FBI's ability to access American data that would require agents obtain a warrant when seeking evidence of a crime.

The former spy chiefs' letter was sent to the Republican and Democratic leaders of the Senate and House, and heads of the Senate and House Intelligence and Judiciary committees.

Implementation of the Section 702 program, they wrote, has received positive reviews from the independent Privacy and Civil Liberties Oversight Board.

The letter was signed by former directors of national intelligence Dennis Blair, James Clapper and Mike McConnell; former attorney general Michael Mukasey; former CIA director John Brennan; former NSA chief Keith Alexander; and Michael Hayden, who led both the CIA and the NSA.


(Reporting by Warren Strobel and Dustin Volz; editing by Grant McCool)

Heads Up! Cross the Street. Then Update Facebook | Reading This While Walking? In Honolulu, It Could Cost You...

Pedestrians on Hotel Street at Fort Street Mall in Honolulu. Honolulu enacted a law, set to take effect Wednesday, that allows the police to fine pedestrians up to $35 for viewing their electronic devices while crossing streets in the city and surrounding county. 


You see them everywhere: people walking with their eyes glued to their mobile phone screens on busy streets. But walking and texting can be dangerous — and cities in the United States and Europe have begun to do something about it.

Honolulu has passed a law, which will take effect Wednesday, that allows the police to fine pedestrians up to $35 for viewing their electronic devices while crossing streets in the city and surrounding county. Honolulu is thought to be the first major city to enact such a ban.

“This is really milestone legislation that sets the bar high for safety,” said Brandon Elefante, the City Council member who proposed the bill. Pedestrians, he said, will share the responsibility for their safety with motorists.

In the United States, pedestrian deaths in 2016 spiked 9 percent from the year before, rising to 5,987, the highest toll on American roads since 1990, according to federal data. One reason may be the sharp rise in smartphone use, “a frequent source of mental and visual distraction” for both drivers and walkers, a report by the Governors Highway Safety Association found.

I’m guilty myself,” said Charles Chan Massey, chief executive of Synaxis Meetings & Events, a management firm, who uses the time walking to and from meetings and business lunches to catch up on calls, texts and emails.

“A lot of people do it; they know it’s risky and do it anyway. They convince themselves that ‘this text is important,’” he said. “It’s something we need to be aware of.”

There is a dearth of data directly linking distracted walking to pedestrian injuries and deaths, but it seems to be a global problem, too. Preliminary studies “give a hint to unsafe behavior,” said Dr. Etienne Krug, director of the Department for Management of Noncommunicable Diseases, Disability, Violence and Injury Prevention at the World Health Organization.
Charles Chan Massey, chief executive of a management firm, in San Francisco. “I’m guilty myself” of using his smartphone while walking. “A lot of people do it; they know it’s risky and do it anyway,” he added.

People who text and walk, for example, are nearly four times as likely to engage in at least one dangerous action, like jaywalking or not looking both ways, and take 18 percent more time to cross a street than undistracted pedestrians. Solutions, Dr. Krug said, are “hard to legislate and even harder to enforce.”

A number of other cities have come up with creative ways to help protect so-called cellphone zombies, who talk, text, listen to music, check their email and even snap selfies. Initiatives include low-tech efforts, like edgy signs in Hayward, Calif. (“Heads Up! Cross the Street. Then Update Facebook.”) and no-selfie zones in Mumbai, and specially designed traffic lights in Europe and several pieces of legislation in reaction to Honolulu’s new law.

Last month, the Board of Supervisors in San Mateo County, Calif., unanimously passed a resolution prohibiting pedestrians’ use of cellphones while crossing streets. It’s not enforceable, as state law governs such issues, but David Canepa, who introduced the measure, said it was an important springboard; the resolution is expected to go to the California Legislature for statewide consideration in January.

“There is chaos in the crosswalks,” said Mr. Canepa, who admits to a few close calls with distracted driving and walking himself. “I know it’s an issue. I’ve lived it. My cellphone is my life.”

As children, he said, we are taught to look both ways when crossing a street, but “you can’t look both ways when you’re looking down and texting.”

Critics are concerned about personal freedom and slow to adjust to new ideas, Mr. Canepa said. “But at the end of the day, people understand the value of public safety,” he added. “This legislation is practical and is common sense. It will save lives.”

At least 10 states have debated similar legislation dealing with distracted pedestrians or bicyclists; none of it has passed, according to the National Conference of State Legislatures. Legislation is pending in two states, the group said, and in September, New York passed a law that directs New York City to study its efforts to educate the public on the dangers of distracted walking.
Texting while walking in San Francisco’s Union Square neighborhood. 

Municipal laws are not tracked, but Rexburg, Idaho, may have been among the first to adopt a citywide ban, in 2011. The city recorded five pedestrian deaths in a short period in a concentrated area. It was a high toll, given the city’s size: about 35,000 residents.

“It was a shock to our system,” said Stephen Zollinger, Rexburg’s city attorney.

Distracted walking was suspected. Along with other safety measures, Rexburg barred pedestrians from using hand-held devices — except while talking — while crossing public streets, he said, and “we’ve not had a pedestrian fatality since.”

Bodegraven, a small town near Amsterdam, tried a different approach. This year, it embedded LED-illuminated strips in the crosswalk at a busy intersection — right in the line of sight of people staring at their phones. When the traffic lights turn red or green, so do the lights at ground level, alerting pedestrians when it’s safe to cross.

The pilot program aims to anticipate trends, not reverse them, said Dolf Roodenburg, the project leader and a traffic engineer in the Netherlands. If it’s successful, the town hopes to install the lights at more intersections and on bike paths, and offer them to other cities.

In Augsburg, Germany, similar lights were installed last year after a teenager using her smartphone was struck and seriously injured by a tram when she walked onto the tracks.

There are, of course, contrary points of view on the effectiveness of legislating pedestrian behavior.

Janette Sadik-Khan, a former commissioner of the New York City Department of Transportation and now transportation principal at Bloomberg Associates, which advises mayors around the world, said laws against texting and walking were not the answer. They have no basis in any research, are poorly conceived and distract from the road design and driver behavior issues that are responsible for most crashes, she said.

“It’s an easy way out. Engineering is a lot more difficult, but a lot more efficient,” Ms. Sadik-Khan said. “Traffic safety is very serious business in government, based in sound analysis.”

She and others recommended focusing on proven strategies like vehicle speed reduction, which is one of the most effective ways to reduce deaths, as survival rates are higher in low-speed collisions.

Vehicle design can also help. “In some countries, cars are designed to be more forgiving to pedestrians,” said Deborah A. P. Hersman, president and chief executive of the National Safety Council. Making bumpers softer and modifying the front ends of vehicles can reduce the severity of a pedestrian impact, but only 44 countries, mostly in Europe, require manufacturers to apply these protections, according to the W.H.O. The United States is not among them.

Rochelle Sobel, founder of the Association for Safe International Road Travel, a nonprofit group, said it was important for Americans traveling abroad to learn the local road culture. In the Dominican Republic, pedestrians do not have the right of way, and in some countries, drivers routinely ignore traffic regulations.

For example, they may fail to stop at intersections or red lights, Ms. Sobel said. In many low- and middle-income countries, where about 90 percent of the world’s road-traffic deaths occur, according to the W.H.O., pedestrians often share poorly maintained roads with animals, carts, cars, buses and trucks. Those roads are already high-risk environments not designed for walking, Ms. Sobel said.

Ms. Hersman, who previously served as chairwoman of the National Transportation Safety Board, said concerns about government overreach often lessened with time. Laws requiring seatbelt use or restricting smoking initially met resistance but now are widely accepted.

“It’s important to have an open mind,” she said. “Society can move forward.”

Mr. Massey of Synaxis said it would take some convincing for people to see value in laws to combat distracted walking.

“I agree in principle — begrudgingly,” he said. “It’s a bit Big Brotherish. We don’t like that in this country.”

European efforts are more realistic, Mr. Massey added. “I think the lights are brilliant,” he said. “It reflects an understanding of human nature: People are going to do it anyway, so let’s make it safer.”


Source:

Google Now Lets You Take a Virtual Walk on Mars

Sunday, 22 October 2017

If you are curious about the unknown terrains of the Red Planet, here is your chance to take a walk on Mars for free all the while staying in your living room, thanks to Google's immersive experience initiative Access Mars.

Google collaborated with NASA to produce Access Mars that lets users wander the actual dunes and valleys explored by NASA's Curiosity rover.


"The experience is built using WebVR, a technology that lets you see virtual reality right in your browser, without installing any apps. You can try it on a virtual reality headset, phone, or laptop," Ryan Burke, Interactive Producer at Google's Creative Lab wrote in a blog post late on Thursday.

.
The experience was adapted from NASA Jet Propulsion Laboratory's OnSight software, which assists scientists in planning rover drives and even holding meetings on Mars.

Imagery from NASA's Curiosity rover provided the terrain.


"We've been able to leverage VR and AR technologies to take our scientists to Mars every single day," said Victor Luo, lead project manager at JPL's Ops Lab, which led the collaboration.


"With Access Mars, everyone in the world can ride along," Luo said.


Since being rolled out to JPL's scientists in 2015, OnSight has made studying Martian geology as intuitive as turning your head and walking around.


Access Mars lets anyone with an internet connection take a guided tour of what those scientists experience.


A simple walkthrough explains what the Curiosity rover does and details its dramatic landing in 2012.


Google said that JPL will continuously update the data so that users see where Curiosity has just been in the past few days or weeks.


"All along the way, JPL scientist Katie Stack Morgan will be your guide, explaining key points about the rover, the mission, and some of the early findings," Burke added.

Also Read


How to Run Two WhatsApp Accounts on One Phone (Dual WhatsApp)?

  • It's possible to have two copies of WhatsApp on one phone
  • Obviously, it has to be a dual-SIM phone
  • Some phone makers offer it as a built in feature
 Here are the detailed steps to run two WhatsApp accounts on your Xiaomi phone, but it's very similar for the other two as well:

After you've installed WhatsApp, go to Settings.
Tap on Dual Apps. On Honor phones this is called App Twin, and on Oppo it's Clone App.
You'll see a list of apps that can work with the feature, and toggles on the side. Turn the toggle on to clone any app.
That's it, you're done. Check if your manufacturer supports app cloning as well, and if yes, then these steps should work to get a second copy of WhatsApp on your phone. It's a little different on a Vivo phone, so we'll just explain that first, and then talk about how to set up the second WhatsApp.

How to run two WhatsApp accounts on a Vivo phone
The steps for Vivo are very similar to other brands, but slightly different. To clone WhatsApp on a Vivo phone (we tested this on a Vivo V5s), simply follow these steps:


  1. Go to Settings.
  2. Scroll down to find App Clone, and tap it.
  3. Now, toggle the switch to enable Display the Clone button.
  4. Next, Install WhatsApp on your phone via Google Play.
  5. Long press on any app icon. You'll see a small 'x' to remove apps, but some, like WhatsApp, will also have a small '+' symbol.
  6. Tap the + to clone WhatsApp on your phone.
Okay, so at this point, you should have two copies of WhatsApp on your phone. Here's what you have to do next.

Setting up Dual WhatsApp
Setting up your second WhatsApp account is extremely simple, just like setting up the first one. In case you've got any doubts though, here are the detailed steps.


  • Start the second WhatsApp.
  • On the next page, tap on Agree and Continue.
  • Next, you can grant files and contacts access to this copy of WhatsApp by tapping Continue and following on-screen instructions, or tap on Not now for now.
  • Now, you have to verify your phone number. This is the crucial part - remember, it has to be the second SIM phone number, if you type in you primary number you're just shifting WhatsApp access from one app to the next.
  • Once you've typed in your number, tap Next, then confirm the number by tapping on OK.
  • WhatsApp will then send a verification code to check the number, which it will auto-read if you've granted permissions. Otherwise, just type in the verification number, and you're good to go. In case you don't get the SMS, you can also tap the Call button on-screen to get a verification phone call.

That's it - now you've got two versions of WhatsApp running on your phone. You'll be able to send and receive messages using both numbers, so it's useful if you want to separate your personal usage from your professional usage, for example.

You can also use the steps given above to install multiple copies of other apps. If you want two Twitter apps or two Facebook apps on your phone, for personal use and a business account, for example, that's easy to do following the same steps, except you'd clone those apps instead of WhatsApp, obviously.

What if my phone doesn't support app cloning?
If your phone doesn't support app cloning, there's still a couple of ways to go ahead and install a second copy of WhatsApp. You'll still need a dual-SIM phone, in order to send and receive messages from two accounts. There are a few popular methods that we found online, and the one we thought was best is an app called Parallel Space.

As the name suggests, this app creates a parallel "space" where you can install apps, which allows you to clone different apps. Here are the steps to using this app:

  1. You have to first install Parallel Space from Google Play. Once you start the app, it will immediately take you to a Clone Apps page.
  2. Select all apps you want to clone, and tap the Add to Parallel Space button.
  3. Next, you'll be taken to the parallel space, where the app is run in a virtual install on your phone.
  4. Now, continue to set up WhatsApp as described above.
That's it, you can use WhatsApp and other apps by accessing them through the Parallel Space app. The app is free but ad-supported, although ads can be removed with a subscription available as an in-app purchase; it's Rs. 30 per month, Rs. 50 for three months, Rs. 80 for six, and Rs. 150 for a lifetime subscription. Once again, this can also be used for apps like Facebook.

Another method which we found on a lot of sites is to install an app called GBWhatsApp, but this involves installing the app via APK, which does have a small element of risk involved. Besides that, it's only useful for a single scenario, which is running dual WhatsApp, so we believe that using Parallel Space is a better choice.

Laptops in Checked Bags Pose Fire and Explosion Risk, FAA warns airlines about electronics in checked bags

Saturday, 21 October 2017



A TSA official removes a laptop from a bag for scanning. Joe Penney / Reuters file
The U.S. government is urging the world airline community to ban large, personal electronic devices like laptops from checked luggage because of the potential for a catastrophic fire.

The Federal Aviation Administration said in a paper filed recently with a U.N. agency that its tests show that when a laptop’s rechargeable lithium-ion battery overheats in close proximity to an aerosol spray can, it can cause an explosion capable of disabling an airliner’s fire suppression system. The fire could then rage unchecked, leading to “the loss of the aircraft,” the paper said.

The U.N. agency, the International Civil Aviation Organization, sets global aviation safety standards, although member countries must still ratify them. The proposed ban is on the agenda of a meeting of ICAO’s panel on dangerous goods being held this week and next week in Montreal.
Also Read
The FAA has conducted 10 tests involving a fully-charged laptop packed in a suitcase. A heater was placed against the laptop’s battery to force it into “thermal runaway,” a condition in which the battery’s temperature continually rises.

In one test, an 8-ounce aerosol can of dry shampoo — which is permitted in checked baggage — was strapped to the laptop. There was a fire almost immediately and it grew rapidly. The aerosol can exploded within 40 seconds.

The test showed that because of the rapid progression of the fire, Halon gas fire suppressant systems used in airline cargo compartments would be unable to put out the fire before there was an explosion, the FAA said.

The explosion might not be strong enough to structurally damage the plane, but it could damage the cargo compartment and allow the Halon to escape, the agency said. Then there would be nothing to prevent the fire from spreading.

Other tests of laptop batteries packed with potentially dangerous consumer goods that are permitted in checked baggage like nail polish remover, hand sanitizer and rubbing alcohol also resulted in large fires, although no explosions.
Also Read
As a result, the paper recommends that passengers shouldn’t be allowed to pack large electronic devices in baggage unless they have specific approval from the airline.

The paper says the European Safety Agency, the FAA’s counterpart in Europe; Airbus, one of the world’s largest makers of passenger airliners; the International Federation of Airline Pilots’ Association, and the International Coordinating Council of Aerospace Industries Association, which represents aircraft makers, concurred in the recommendation.

The paper doesn’t address whether the ban should extend to domestic flights, but points out the risk that baggage containing a large electronic device could be transferred from one flight to another without the knowledge of the airline.

The FAA said it believes most devices larger than a smartphone are already being carried by passengers into the cabin, rather than put in checked bags.

Rechargeable lithium batteries are used in consumer products ranging from cellphones and laptops to electric cars. Manufacturers like them because they pack more energy into smaller packages, but the batteries can self-ignite if they have a manufacturing flaw, are damaged, exposed to excessive heat, overcharged or packed too closely together.
Also Read
The fires can burn up to 1,100 degrees Fahrenheit, close to the melting point of the aluminum used in aircraft construction.

Since 2006, three cargo jets have been destroyed and four pilots killed by in-flight fires that investigators say were either started by batteries or made more severe by their proximity.

Earlier this year, the U.S. imposed a ban on laptops in the cabins of planes coming into the country from 10 Middle Eastern airports for security reasons. The ban was fully lifted in July after U.S. officials said airports in the region had taken other steps to increase security. 

FAA warns airlines about electronics in checked bags

As airlines flying into the United States adjust to new, tighter security rules designed to catch bombs or explosives hidden in electronic devices, the Department of Transportation is weighing in on the safest place in a plane for laptops, tablets and other devices powered by lithium-ion batteries.

It is not in the cargo hold, according to the FAA. The agency's Office of Hazardous Materials Safety says portable electronic devices pose less of a fire threat when carried on-board instead of being packed into checked bags.

In a notice the agency issued earlier this week, the FAA said, "devices containing lithium metal or lithium ion batteries (laptops, smartphones, tablets, etc.) should be transported in carry-on baggage and not placed in checked baggage."

The primary reason laptops are safer in the passenger cabin is because the flight crew or passengers at least have a chance to put out a fire if one is sparked by the batteries in an electronic device.

That conclusion is not an edict banning airlines from allowing passengers to put their electronics in checked bags.
Also Read
In fact, the agency says if devices are packed in bags that will go in the cargo hold of flights, they "should be completely powered down to the OFF position (they should not be left in sleep mode), protected from accidental activation, and packed so they are protected from damage."

The advisory backs up a complaint issued by many in the airline industry after the Department of Homeland Security issued tighter security rules for certain flights from the Middle East to the U.S. earlier this year. Those rules, which have since been modified, banned passengers from having electronic devices larger than a cell phone in their carry-on bags. At the time, Homeland Security was acting on intelligence that indicated terrorists may try to hide an explosive in an electronic device or use several devices to detonate a bomb.

As soon as that rule went into effect in March, safety advocates warned of the potential risk of lithium-ion batteries igniting in a checked bag and sparking a larger, uncontrollable fire in the cargo hold that could bring down a commercial airplane.

That concern prompted the Fire Safety Branch of the FAA to conduct tests looking at the potential hazards of putting laptop computers and other electronic devices in checked bags.

It's conclusion was clear: large electronics are safer in the passenger cabin than in the cargo hold.

In late June, the U.S. modified its security protocol for all international flights, requiring enhanced security ranging from tighter screening to the use of new, more advanced, carry-on bag screeners that can more easily detect a potential bomb.

"It is time we raise the global baseline of aviation security," said John Kelly, secretary of Homeland Security in announcing the tighter security rules.

Since then, several airlines say they have enhanced security and have announced the TSA has approved their procedures.
Also Read:


You Really Need to Stop Using Public Wi-Fi without a VPN right now | Stop using public Wi-Fi......

Tuesday, 17 October 2017

On Monday, security researchers disclosed a severe flaw in the protocols used by all modern Wi-Fi networks that gives hackers a way to steal personal information from nearly all of your internet-connected devices, including smartphones, laptops, tablets, and smartwatches. The weakness leaves your credit card numbers, passwords, chat messages, emails, photos, and other personal information at risk. It could even let attackers inject and manipulate data by adding ransomware or malware onto a website.
Also Read
Yes, we all hear these dire warnings about scary “hackers” all the time. But this one is serious. So serious, in fact, that you should avoid connecting any of your tech to public Wi-Fi unless you’re certain its received patches to fix a critical weakness in the wireless standard.

Here’s what you need to know before working remote results in a full-blown disaster.

Every Wi-Fi device is vulnerable

While all Wi-Fi-enabled devices are affected by the flaw, Android smartphones and Linux computers are most vulnerable to a particularly devastating variant of the attack.

The most effective attack was used against “clients,” not access points (like your home router), but you should still avoid connecting to public Wi-Fi services. The attack, dubbed “KRACK,” is only effective if the hacker is in proximity to your device, so you’re likely more safe at home or at work. But popular areas for public Wi-Fi, like your local coffee shop or airport, remain at risk.

Not only do these networks allow access without authentication, but there is also the uncertainty that the equipment providing the connection is outdated and, therefore, unsecure. There’s virtually no way of knowing if a public access point has received the necessary updates to fix the KRACK flaw or whether those updates were ever installed.
Also Read

When can I reconnect?

None of the online guides for safely browsing public Wi-Fi will save you from this latest vulnerability. We recommend staying away from public Wi-Fi until your devices receive software updates that fix the issue. If you’re not sure, search your device’s manufacturer to see if they’ve released a statement on the matter or created a support page with links on how to update your device’s Wi-Fi security. Until then, use cellular networks when possible or connect your gadgets directly to a router to bypass the wireless protocol.

The good news is that you don’t need to rely on businesses and venues to update the firmware on their routers. The security researchers who discovered KRACK, Mathy Vanhoef, explained here.

“No, luckily implementations can be patched in a backwards-compatible manner. This means a patched client can still communicate with an unpatched access point, and vice versa. In other words, a patched client or access points sends exactly the same handshake messages as before, and at exactly the same moments in time. However, the security updates will assure a key is only installed once, preventing our attacks.”

Even without KRACK, public Wi-Fi is considered extremely insecure. To bolster your defenses, you should always use a virtual private network (VPN) when connecting to a public Wi-Fi access point. A VPN will encrypt your traffic and give you an added layer of protection.

Consider the following seven security tips to keep prying eyes out of your devices:

Don’t use public Wi-Fi to shop online, log in to your financial institution, or access other sensitive sites — ever
Use a Virtual Private Network, or VPN, to create a network-within-a-network, keeping everything you do encrypted
Implement two-factor authentication when logging into sensitive sites, so even if malicious individuals have the passwords to your bank, social media, or email, they won’t be able to log in
Only visit websites with HTTPS encryption when in public places, as opposed to lesser-protected HTTP addresses
Turn off the automatic Wi-Fi connectivity feature on your phone, so it won’t automatically seek out hotspots
Monitor your Bluetooth connection when in public places to ensure others are not intercepting your transfer of data
Buy an unlimited data plan for your device and stop using public Wi-Fi altogether

The more you take your chances with a free network connection, the greater the likelihood that you will suffer some type of security breach. There is a saying in the cybersecurity industry that there are three types of people in the world: those who have been hacked, those who will be hacked, and those who are being hacked right now and just don’t know it yet. The better you protect yourself, the greater your chances of minimizing the potential damage. Remember: Falling victim to public Wi-Fi’s dangers is a question of when, not if.
Also Read





Every Wi-Fi device you own Almost ALL phones, tablets and PCs vulnerable to this devastating cyberattack | WARNING WI-FI

Wi-Fi WARNING - Almost all devices vulnerable to hackers
Every Wi-Fi device you own Almost ALL phones, tablets and PCs vulnerable to this devastating cyberattack | WARNING

HACKERS can target almost ANY smart device around the world thanks to a vulnerability in WPA2 Wi-Fi security. Here's everything you should know about this threat.

A severe weakness discovered in the WPA2 Wi-Fi protocol means all of your internet-connected devices—laptops, smartphones, tablets, TVs, and more—are vulnerable to a devastating attack.

The vulnerability in the WPA2 security protocol leaves virtually everyone who connects to the internet via Wi-Fi at risk of devastating attacks that can reveal everything you do online as well as your most sensitive personal information.

Apple iOS, Windows, Android and any smart device that uses Wi-Fi are all at risk of an attack, cybersecurity experts have warned today.

The newly discovered KRACK exploit affects the WPA2 security protocol, a standard for Wi-Fi security used on almost every Wi-Fi router.

Attackers in range of your devices can use Key Reinstallation Attacks, or KRACKs, to steal your credit card numbers, passwords, chat messages, emails, photos, and other personal information previously thought to be safely encrypted. The vulnerability also lets attackers inject and manipulate data by adding ransomware or malware onto a website. The flaws were found in the protocols that secure all modern WiFi networks, which means it doesn’t only impact specific products, but every device capable of connecting to WiFi.
Also Read
“The attack works against all modern protected Wi-Fi networks,” Mathy Vanhoef, one of the TKU Leuven University researchers who discovered the WPA2 vulnerability, wrote.

The attack can break into a network by exploiting a four-way “handshake” that’s used to create a key for encrypting traffic. Researchers found that an attacker can force key resets by collecting and replaying transmissions of the third handshake, effectively breaking down the encryption protocol. This is the first attack on the Wi-Fi protocol that doesn’t involve password guessing. It’s important to note that while the attack allows hackers to eavesdrop on traffic flowing from your router, it can’t be used to take over the device.

Variants of the attack affect Android, Linux, Apple, Windows, OpenBSD, MediaTek, Linksys, and other companies who sell internet-connected products. The security researchers who found the flaw say devices running unpatched versions of Android and Linux are vulnerable to a particularly “catastrophic” attack.

Several companies have already issued patches that fix the Wi-Fi vulnerability.

Microsoft told Forbes that all users who manually apply the latest update or have automatic updates enabled are protected.

Apple has not commented on whether its latest versions of macOS and iOS are vulnerable.

Google promised a fix for its devices “in the coming weeks.” Until then, we recommend you avoid connecting to public Wi-Fi.

All data transmitted from 41 percent of existing Android devices via Wi-Fi can be decrypted, even if a website uses HTTPS protocol for an additional layer of protection.
Also Read:
The best way to protect yourself against this widespread vulnerability is to update all of your devices when a solution becomes available. That includes your gadgets and Wi-Fi access points. The Wi-Fi Alliance, a governing body that sets the standards for WiFi, will work with device vendors to make sure they update their products with the latest software. A broad notification to vendors of affected devices was sent out on August 28.

It’s not clear if the WiFi flaw is actively being exploited in the wild.

In theory it allows a hacker within range of a Wi-Fi network to read passwords, credit card numbers and photos sent over the internet.  

Other sensitive information that can be obtained thanks to this exploit is chat app messages and e-mails.

The WPA2 Wi-Fi vulnerability has been a closely guarded secret for weeks, with today’s revelations a co-ordinated disclosure.

The terrifying exploit was unearthed by researchers led by Mathy Vanhoef from the Belgian university KU Leuven.

The experts, after discovering the exploit, carried out a “proof-of-concept” attack on an Android smartphone to learn more about the vulnerability.

Vanhoef said the attack would work against “all modern protected Wi-Fi networks” and “if your device supports Wi-Fi, it is most likely affected”.

In the paper on the Krack Attacks website, the researchers said: "All protected Wi-Fi networks use the four-way handshake to generate a fresh session key and so far this 14-year-old handshake has remained free from attack.

"Every Wi-Fi device is vulnerable to some variants of our attacks.” 
Wireless security warned about the widespread Wi-Fi vulnerability
Vanhoef and his team said the KRACK attack is “exceptionally devastating” against Android 6.0.

Most modern Wi-Fi networks have traffic encrypted by either the WPA or WPA-2 protocols.

These have existed since 2003 and until now have never been broken.

When a user connects to a secure network, a four-way “handshake” takes place between a device and a router.

This is to ensure that no one can decrypt the traffic, but Vanheof’s team discovered a way to install a new key during the third step of the process.

This exploit lets hackers gain access to data transmitted over a network which can be stolen, or used to carry out a cyber attack.

The US Government has also today issued a warning about the KRACK attack, saying anyone using the WPA2 standard is probably compromised.

The security alert about the flaw came from the US Computer Emergency Readiness Team (Cert).

They said: "US-Cert has become aware of several key management vulnerabilities in the four-way handshake of wi-fi protected access II (WPA2) security protocol.

"Most or all correct implementations of the standard will be affected."

Security researchers have said that changing your Wi-Fi password will NOT help prevent attacks.

However, it’s to be expected that patches for devices will be issued in the coming weeks to protect against this vulnerability.

So it’s worth updating router firmware and all devices to the latest patches available.

Also, seeing as access points for the general public aren’t likely to be patched quickly it’s worth avoiding Wi-Fi whenever possible.

Ars Technica, who first reported on the KRACK flaw, gave advice about what to do when Wi-Fi is the only connection option available.

If that’s the case, people should use HTTPS, STARTTLS, Secure Shell or other protocols to encrypt web and e-mail traffic.

As a fall-back plan, users should consider using a virtual private network as an extra safety measure. 

But make sure you choose your VPN providers carefully.

Simon Migliano, Head of Research, Top10VPN.com, said: “Now that Wi-Fi security has been compromised, using any kind of shared network now severely risks your privacy - even if it is password-protected. 

When you connect to the Wi-Fi in your local coffee shop or the airport, it’s now much easier for hackers to force you onto a cloned network that they control without you realising anything has happened.

“With your internet traffic now exposed, it’s easy for hackers to steal your personal information. 

“Even encrypted sites on HTTPS are not necessarily safe as in this kind of man-in-the-middle attack, hackers can neutralise the security from such sites allowing interception of log-in credentials.

“They can also force you onto cloned versions of the websites you visit in order to capture your information - all without you realising anything suspicious is happening.”
Most Popular




 

CONNECT WITH US ON FACEBOOK

Follow us Google +

JOIN OUR GROUP ON FACEBOOK

CONNECT WITH US ON GOOGLE Collections

Featured post

The Basics of Flood Insurance

Many homeowners don’t realize that a standard homeowner policy does not cover flood damage. That is why it is so important to purchase add...

Tracked By

Total Pageviews