Hackers manage to access 150 phones an hour through Wi-Fi
Experts in London have proved it's possible to use drones to steal data
They modified an aircraft capable of tapping into a phone's Wi-Fi settings
Once it had access, it was able to read and steal personal information
Called Snoopy, the drone takes advantage of smartphones that actively search for networks
From this it can also see networks those devices have accessed in the past
During tests, hackers exposed credit card information and passwords
By Sarah Griffiths
News that hovering drones can now steal passwords from unsuspecting phones will do little to ease fears that the widespread use of unmanned aircraft could infringe upon our privacy.
Hackers in the U.S have managed to 'steal' information, including Amazon passwords, bank details and even people’s home addresses using an aircraft.
While it might sound like the crime of the century, the exercise was an experiment to show it is possible to use drones to tap into a smartphone’s Wi-Fi settings and access valuable information
Hackers have proved that it is possible to steal information, including Amazon passwords, bank details and even home addresses from smartphones that have Wi-Fi turned on, using specially adapted drones (a stock image of a quadcopter is pictured)
The test was conducted in London and the group will share their findings at the Black Hat Asia cybersecurity conference in Singapore next week, CNN reported.
The drone, known as Snoopy, seeks out smartphones that have Wi-Fi turned on.
It then makes use of built-in technology which can see what networks the phones have accessed in the past.
In theory, almost any drone could be adapted to do this.
HOW CAN A DRONE STEAL SOMEONE'S IDENTITY?
The drone, known as Snoopy, seeks out smartphones that have Wi-Fi turned on.
It then makes use of built-in technology which can see what networks the phones have accessed in the past.
In theory, almost any drone could be adapted to do this.
Phones 'noisily' reach out to networks, according to the experts.
Snoopy looks for this activity and when hovering nearby it emits a signal masquerading as another network.
The phone ‘trusts’ that it is accessing a trusted Wi-Fi network but instead connects to the quadcopter's network.
Snoopy can then intercept everything a smartphone sends and receives and allows skilled hackers to see passwords, bank details and the phone's location.
.
London-based Sensepost security researcher Glenn Wilkinson, said: ‘Their phone will very noisily be shouting out the name of every network its ever connected to.
'They'll be shouting out, “Starbucks, are you there?...McDonald's Free Wi-Fi, are you there?”’
When this happens, Snoopy hovers nearby and emits a signal masquerading as another network and the phone ‘thinks’ it is accessing a trusted Wi-Fi network.
However, when it connects to the quadcopter’s network, Snoopy will intercept everything a smartphone sends and receives using a complicated method described by the company.
Wilkinson said: ‘Your phone connects to me and then I can see all of your traffic.’
He is able to see the websites a person visits, any credit card information entered or saved, their location, usernames and passwords.
In the wrong hands, this could potentially leave a mystified smartphone user out of pocket.
The hackers managed to gain access by looking at a unique identification number known as a Media Access Control (MAC) address. This number matches web traffic to a specific device.
To demonstrate the effectiveness of the technology, Wilkinson spent an hour with CNN showing them how he could obtain network names and GPS coordinates for 150 smartphones used by Londoners.
While collecting metadata and network names is not strictly illegal, intercepting passwords and credit card details with the intent of using them is.
The ethical hackers said they're demonstrating the technology to highlight how vulnerable smartphone users can be.
The drones might seem even more threatening to people than remote hackers because the aircraft can hover close to potential ‘victims’ are incredibly mobile.
There is a prospect that the technology could be put to good use for law enforcement purposes, however, such as identifying looters in a riot.
While it is not thought that anyone is currently using this snooping technique in the real world, smartphone users can protect themselves by shutting off their Wi-Fi when they are not using it, or only access secure networks.
Showing posts with label identity theft.id theft. Show all posts
Showing posts with label identity theft.id theft. Show all posts
Monday, April 07, 2014
Monday, October 08, 2012
Skimmers May Use Smartphones To Steal Credit Card Information
) – The increasingly popular radio frequency identification (RFID) credit cards that allow consumers to pay by tapping may be making it easier for crooks to steal valuable information with their smartphones.
By tapping machines equipped with radio frequency readers, people can conveniently pay with RFID credit and debit cards without having to enter PIN numbers.
According to the owner of Identity Stronghold, Walt Augustinowicz, credit card skimmers made up of about $100 worth of parts easily obtained online can steal enough information to clone credit cards.
Similarly, tech-savvy scammers can also use their smartphones to steal information with just a simple tap.
As Augustinowicz demonstrated, a hacker can develop a smartphone app or game that looks harmless, but when it gets close enough to an RFID card, the app launches and scans the card’s information and sends the details off to the hacker’s email address.
Augustinowicz said that if hackers are talented enough, they can develop RFID information-stealing apps and games that many may mistake as something benign and download them.
“Hundreds of people start downloading it, and they just sit back and watch their email box fill up with credit card numbers they can use,” he said.
Not all smartphones are at risk for these virus-like apps and games, though. Only phones with near field communication like Google Wallet Android technology that allows for pay by tapping have the safety dangers.
pay by tapping have the safety dangers.
However, as pay-by-tapping technology becomes more widely used, security expert, Eddie Schwartz, said RFID software will become an industry standard.
“It’s a good thing that people are pointing out these vulnerabilities. It forced us as an industry to be more vigilant and to take the necessary steps to protect our assets,” he said.
To protect your information, Augustinowicz recommends buying a protective case or wrapping cards in tin foil to block RFID signals.
Thursday, November 19, 2009
It's Holiday Time Again
Well the year is almost coming to a close and the holiday season is upon us. During this time it pays to be extra vigilant while using your personal info. CBS News has had and excellent expose on Identity Theft in it's many forms if you missed it there links are a must see.
Your Id being sold online
Stolen Pictures
Medical Id Theft
Your Id being sold online
Stolen Pictures
Medical Id Theft
Wednesday, September 02, 2009
Woman Wanted for Major Mail Theft Ring in Upstate
Hi Again,
Even we mostly hear about the big credit card heists there are still local operators that do a lot of damage.
Upstate Mail Teft Ring
Even we mostly hear about the big credit card heists there are still local operators that do a lot of damage.
Upstate Mail Teft Ring
Tuesday, August 18, 2009
Feds charge man in largest U.S. case of identity theft
U.S Secret Service | Albert Gonzalez is a computer hacker who was involved in a major credit card fraud scheme, according to the U.S. Secret Service.
Feds charge man in largest U.S. case of identity theft
Feds charge man in largest U.S. case of identity theft
Thursday, November 08, 2007
A Good First Step? What Do You Think??
WASHINGTON (Reuters) - A bipartisan bill that would let victims of
identity theft seek restitution for money and time they spent repairing
their credit history was introduced on Tuesday in the Senate.
Read the whole article at
Id Theft Protection
identity theft seek restitution for money and time they spent repairing
their credit history was introduced on Tuesday in the Senate.
Read the whole article at
Id Theft Protection
Subscribe to:
Posts (Atom)

