Monday, October 08, 2012

Skimmers May Use Smartphones To Steal Credit Card Information

) – The increasingly popular radio frequency identification (RFID) credit cards that allow consumers to pay by tapping may be making it easier for crooks to steal valuable information with their smartphones. By tapping machines equipped with radio frequency readers, people can conveniently pay with RFID credit and debit cards without having to enter PIN numbers. According to the owner of Identity Stronghold, Walt Augustinowicz, credit card skimmers made up of about $100 worth of parts easily obtained online can steal enough information to clone credit cards. Similarly, tech-savvy scammers can also use their smartphones to steal information with just a simple tap. As Augustinowicz demonstrated, a hacker can develop a smartphone app or game that looks harmless, but when it gets close enough to an RFID card, the app launches and scans the card’s information and sends the details off to the hacker’s email address. Augustinowicz said that if hackers are talented enough, they can develop RFID information-stealing apps and games that many may mistake as something benign and download them. “Hundreds of people start downloading it, and they just sit back and watch their email box fill up with credit card numbers they can use,” he said. Not all smartphones are at risk for these virus-like apps and games, though. Only phones with near field communication like Google Wallet Android technology that allows for pay by tapping have the safety dangers. pay by tapping have the safety dangers. However, as pay-by-tapping technology becomes more widely used, security expert, Eddie Schwartz, said RFID software will become an industry standard. “It’s a good thing that people are pointing out these vulnerabilities. It forced us as an industry to be more vigilant and to take the necessary steps to protect our assets,” he said. To protect your information, Augustinowicz recommends buying a protective case or wrapping cards in tin foil to block RFID signals.

The Dangers of Using Wi-Fi on Smart Phones

The Dangers of Using Wi-Fi on Smart Phones by Phillip Richards The next time you use your smart phone’s Wi-Fi to access the internet be careful that you are not also exposing yourself to hackers who can actually access information on your phone and login passwords as well. There is a growing threat with the broad use of internet hotspots for hackers to steal information that they gather with fake Wi-Fi gateways. And once these crooks get you to use their Wi-Fi connection they can decrypt the information on your phone and then sell it to 3rd parties or use it themselves to steal your identity. It has been estimated that there are over 100 million smart phone users in the United States alone. And this number continues to grow as smart phones overtake the use of feature phones and the ordinary cell phones that once dominated the market. One of the most useful features of these phones is the ability to access the internet via Wi-Fi. But since this wireless connection to the internet requires no identification, all mobile browsers see is a name of a Wi-Fi hotspot. And even with the best identity theft protection with services like Lifelock and Trusted ID, you are still at risk of identity theft if you access public Wi-Fi hotspots with your smart phone. To make the problem even worse, many smart phones will connect to an available hotspot automatically without the cell phone user doing anything about it. So even if your smart phone is just powered on and just sitting there a crook with the right software and hardware can hack into your personal life when your phone connects to the Wi-Fi connection he has setup. Companies are working on making Wi-Fi more secure, but it is increasingly difficult with more public places making free internet access available. All a hacker has to do is visit a high-traffic public coffee shop or park and setup his own fake Wi-Fi gateway. Then, while a user is surfing the internet and entering usernames and passwords, this information is automatically being picked up with the hacker’s software. Identity thieves are using the information picked up from fake Wi-Fi hotspots to access email accounts, bank accounts, and Facebook accounts and all of this information can be used to steal an identity while the hacker remains completely anonymous. So what can smart phone users do to prevent this? First of all, instead of using a public Wi-Fi hotspot you should just use your phones service provider to access personal accounts. So if you want to check your email, login to Facebook, or check your bank account, just use your phone’s 3g or 4g service. You can still use public Wi-Fi hotspots but only use it for generic internet surfing. Any internet usage that will not give away any personal data should be fine. However, if you know the internet connect is secure you should be ok to use it on your smart phone. If your cell phone has the ability to automatically connect to hotspots whenever they become available you should turn this feature off. Or you can just turn the Wi-Fi off until you know you are going to use it. Having it on just drains your battery anyway, so you really have no reason to leave it on.

Saturday, September 03, 2011

Heat From Your Fingertips helps hackers

The secret codes typed in by banking customers can be recorded using the residual heat left behind on the keypad, says a group of researchers from the University of California at San Diego.





Hckers Use Infrared

Saturday, August 27, 2011

Researchers say they've hacked car door locks

A group of computer security researchers in Israel and Belgium say they've discovered the electronic equivalent of a Slim Jim -- a way to pop the electronic door locks on most cars without ever touching them.

Drivers don't have to worry about their cars being hacked just yet – a baseball bat is still a more effective auto theft tool – but the announcement shows yet again that newfangled security devices can be more vulnerable than you think.

Most modern cars are now equipped with convenient remote keyless entry systems. Now it seems that tool could be a convenient way for criminals to break into hundreds of cars in an afternoon.


--------------------------------------------------------------------------------

By listening in on the wireless "conversation" between a car and its key, the researchers found they could crack the code that keeps the communication secret. Then they were able to emulate the electronic key and trick the car into unlocking itself.

Nearly all cars with remote keyless entry use an encryption system called KeeLoq. It was developed during the 1980s and purchased by Microchip Technology Inc. in the 1990s. Like all encryption systems, KeeLoq scrambles messages so they can't be read by anyone who intercepts them. Only someone -- or something -- with the appropriate deciphering key can unscramble the message.

Eli Biham, a computer science professor at the Technion-Israel Institute of Technology, says there are 18 billion possible keys for a KeeLoq transmission, making it practically impossible for even the fastest computer to work out the key through brute force.

"But," he said, "we found a shortcut."

By intercepting several transmissions from the electronic key and analyzing them, Biham and his colleagues say they were able to eliminate many of those 18 billion possibilities and work out a master key in about one day. All that's required is remote access to one key for about an hour -- say, while a person is sitting in his office with the key still in a shirt pocket.

Then, after working out the encryption scheme, Biham's group says it can unlock all cars using that master key within a few minutes.

"In modern ciphers, you don't expect this to happen," Biham says, noting that carmakers are still relying on 20-year-old cryptography to keep cars safe. "I don't understand how companies sell cryptography from the 1980s."

'Badly broken'
The research paper, called "How to Steal Cars, (PDF)" was presented at the Crypto 2007 conference at the University of California, Santa Barbara, last week. Exact details for exploiting the discovery won't be published for several months, Biham says, but Microchip Technology was informed weeks ago.

"KeeLoq is badly broken," the paper says, adding, tongue-in-cheek, "Soon, cryptographers will all drive expensive cars."

advertisementadvertisement
advertisement
Microchip wouldn't comment on the team's discovery.

"Microchip Technology Inc. doesn't address matters of security in the public domain," was all that spokesman Eric Lawson would say.

But other cryptography experts said the research was significant.

"This is a very practical application of cryptanalysis," said Jon Callas, chief technology officer with the encryption firm PGP Corp., who attended the presentation. "There is a larger lesson here, which is some of these devices aren't as secure as they are being sold to us."

Slim Jim a bigger threat
Still Callas isn't worried about his car locks being hacked just yet. There are several barriers to using the technology. While a key hacker would be able to pop the lock on the door and perhaps disarm and alarm, he or she probably couldn't get the car started without using old-fashioned car theft tools, he said. And even with the most sophisticated computers, hacking the locks still takes over an hour, while a baseball bat can do just as good a job in a second or two.

"There is not a whole lot of threat to the end consumer," he said. "A guy with a Slim Jim is a bigger threat."

The method could prove lucrative under the right circumstances, however. A thief armed with a master key could park a car with listening devices in the middle of a shopping mall lot and eavesdrop on every car as a driver parks, walks away, and pushes their key to lock the doors. Within seconds, the transmission could be intercepted, analyzed, paired with information about a known master key and used to pop the locks. A criminal could theoretically open hundreds of cars each day that way, stealing a treasure trove of iPods and GPS gadgets without leaving a trace

"That would be worth someone's time," Callas said. Victims "would have a hard time convincing (their) insurance companies that this had happened."

A simple fix
Modest adjustments to encryption tools would foil such a plot, Callas said. Biham's method requires tricking the car's system into answers a long series of questions. But the use of "throttling" -- inserting a delay after every three requests, as some Web sites now do – can slow or eliminate such brute force attacks. So Callas has no plans to disable his electronic locks, which could be done by disconnecting the car's battery while parked.

"I'm more concerned about losing my radio presets than having my car stolen like this," he joked.

Intense research into Keeloq by several groups began last year after proprietary information about KeeLoq's cryptography was leaked onto a Russian Web site. Biham said the information aided his group's research, but argued that properly implemented cryptography should withstand publication of such details.

Both he and Callas were critical of Microchip for not publishing its cryptographic scheme in public earlier, which would have allowed researches to probe it for holes.

advertisementadvertisement
advertisement
"Those of us who are in the field believe that algorithms should be published from the start because an analysis can strengthen them," Callas said. "We only use public algorithms because in long term they are more secure."

While the immediate threat to car owners is low, Biham says the research shows the technology used to protect remote keyless entry systems is outdated.

"There are other tools criminals can use today (to steal cars) that are easier," Biham says. "But we show that it's possible to (hack the locks) and these systems to be replaced."

Tuesday, July 26, 2011

16 Suspected 'Anonymous' Hackers Arrested in Nationwide Sweep

Sixteen suspected members of "Anonymous" were arrested this morning in states across the country, from California to New York, in a federal raid on the notorious hacking group.

The arrests Tuesday, first reported by FoxNews.com, are part of an ongoing investigation into Anonymous, which has claimed responsibility for numerous cyberattacks against a variety of websites, including Visa and Mastercard.



July 19, 2011: FBI agents execute a search warrant at the Long Island, NY, home of a suspected member of notorious hacking group Anonymous.
Related Stories
EXCLUSIVE: FBI Raids Homes of Suspected 'Anonymous' Hackers
LulzSec Hackers Claim Attack on Sun Website
Hacker Group Says It Stole U.S. Military Email Addresses, Passwords
Hackers Hit Washington Post, Affecting 1.27 Million Users
The Department of Justice, in announcing the arrests and more than 35 search warrants in the case, said the case stemmed from an alleged cyberattack on the website PayPal over its action against controversial group WikiLeaks, one of the inspirations for the hacker group Anonymous.

Fourteen of the arrests were identified in the same indictment out of California, while two separate criminal complaints filed out of courts in Newark, N.J., and Tampa, Fla., name the two other alleged hackers. All are believed to have been involved in carrying out nationwide coordinated distributed denial of service (DDoS) attacks on multiple high-profile, billion-dollar companies.

"In retribution for PayPal’s termination of WikiLeaks’ donation account, a group calling itself Anonymous coordinated and executed distributed denial of service (DDoS) attacks against PayPal’s computer servers using an open source computer program the group makes available for free download on the Internet," the Justice Department said in a news release.

The department identified the suspects in the California indictment as Christopher Wayne Cooper, 23, aka “Anthrophobic;” Joshua John Covelli, 26, aka “Absolem” and “Toxic;” Keith Wilson Downey, 26; Mercedes Renee Haefer, 20, aka “No” and “MMMM;” Donald Husband, 29, aka “Ananon;” Vincent Charles Kershaw, 27, aka “Trivette,” “Triv” and “Reaper;” Ethan Miles, 33; James C. Murphy, 36; Drew Alan Phillips, 26, aka “Drew010;” Jeffrey Puglisi, 28, aka “Jeffer,” “Jefferp” and “Ji;” Daniel Sullivan, 22; Tracy Ann Valenzuela, 42; and Christopher Quang Vo, 22. One individual’s name has been withheld by the court.

They are charged with various counts of conspiracy and intentional damage to a protected computer, which carries a maximum sentence of 10 years in prison and a fine of up to $250,000. Each count of conspiracy carries a maximum penalty of five years in prison and a $250,000 fine.

Also Tuesday, Scott Matthew Arciszewski, 21, was arrested in Florida on charges of intentional damage to a protected computer for allegedly accessing without authorization the Tampa Bay InfraGard website and uploaded three files.

And Lance Moore, 21, of Las Cruces, N.M., was arrested on the New Jersey indictment, which accuses him of stealing confidential business information stored on AT&T’s servers and posting it on a file-sharing site. He is charged with one count of accessing a protected computer without authorization.

U.S. law enforcement officials also told FoxNews.com that the arrest of a 16-year-old hacker in London, who goes by the online user name Tflow, was related to the raids in the U.S.

Some of the arrests were out of the San Francisco field office, sources said. Earlier in the day, the FBI executed search warrants at the New York homes -- two in Long Island, N.Y., and one in Brooklyn, N.Y. -- of three suspected members of Anonymous, FoxNews.com reported.

More than 10 FBI agents arrived at the Baldwin, N.Y., home of Giordani Jordan with a search warrant for computers and computer-related accessories, removing at least one laptop from the premises.

The Anonymous group is a loose collection of cybersavvy activists inspired by WikiLeaks and its flamboyant head Julian Assange to fight for "Internet freedom" -- along the way defacing websites, shutting down servers, and scrawling messages across screens web-wide.

The Anonymous vigilante group recently turned its efforts to the Arizona police department, posting personal information of law officers and hacking and defacing websites in response, the group claims, to the state's controversial SB1070 immigration law.

While Anonymous is largely a politically motivated organization, splinter group LulzSec -- which dominated headlines in the spring for a similar streak of cyberattacks -- was largely in it for the thrills.

The metropolitan police in London arrested the first alleged member of the LulzSec group on June 20, a 19-year-old teen named Ryan Cleary. Subsequent sweeps through Italy and Switzerland in early July led to the arrests of 15 more people -- all between the ages of 15 and 28 years old.

The two groups are responsible for a broad spate of digital break-ins targeting governments and large corporations, including Japanese technology giant Sony, the U.S. Senate, telecommunications giant AT&T, Fox.com, and other government and private entities



Read more: http://www.foxnews.com/scitech/2011/07/19/exclusive-fbi-search-warrants-nationwide-hunt-anonymous/#ixzz1TDsHoPxm

Thursday, April 28, 2011

Sony Was Hacked

Hi Again,
Just in case you haven't heard Sony's online gaming network was hacked and been shutdown for a week now . Finally all the deatails are beginning to come out


Hackers broke into the Sony Playstation Network on April 19 and personal information – such as names, addresses and even credit card numbers — from 77 million PlayStation subscribers worldwide may be compromised.

Sony Was Hacked

Tuesday, February 22, 2011

Here's a great free resource

Hi Everyone ,
Here's another great place that will help you out greatly .Learn from how stuff works

Identity Theft

Thursday, January 27, 2011

It's Tax Time Again

Hi Everyone,
I hope all of you are keeping safe out there. When money is being exchanged the crooks are extra busy and at tax time with so much money and information floating around it pays to be safe. Here's an interesting twist i just heard about.

Extortion Virus Fools Victims Into Thinking They Must Buy Anti-Virus Software


Friday, January 07, 2011

The Spy In Your Hand




Well I hope everyone had a fun and safe holiday but as usual the scammers never rest and there's a lurking problem that's come to my attention. With the advent of everyone using smartphones and downloading apps there is a dangerous backdoor many are not aware of

Smartphone Spyware

Friday, July 02, 2010

What's Old Is New Again

Hi Everyone,
By now you've all heard about the gang of Soviet spies we had here in the states. One of the suspect went old school dumpster diving and graveyard hunting to create a new identity. It was discovered by the deceased's brother.

Soviet Spies

Thursday, June 10, 2010

Health Care Law Scams

State insurance commissioners and attorney generals are warning consumers about a new wave of scams that are exploiting uncertanties about the new health care laws. Scam artits may call, email or show up at your door saying that under the new law you must have health insurance or got to jail.

This is not true. Never signup for an insurance policy without calling you state insurance department to findout if the policy is legitimate and the seller is liscensed. Never give out your credit card number or social security number to anyone you don't know.

Tuesday, June 01, 2010

The Dangers of Using a Debit Card

Well summer is here and there will be lots of travel and the thieves wil be hard at work for your vaction dollars so please be aware.

Consumers need to be particularly careful during vacation season because identity thieves come out in droves. That makes it pivotal that consumers keep their debit cards on ice, said Beth Givens, director of the Privacy Rights Clearing House and one of the nation's foremost experts on keeping your private information private

Cebit Card Dangers

Thursday, April 22, 2010

Special Alert

Hi Everyone,
It's the time of year where everyone is starting to get outside and travel a lot more which canleave you open to this scam which has been reportedly spreading quickly .

ATM Users Warned About Credit Card Skimmers
April 22, 2010 02:04 PM
(Washington Post) — Cases of a hard-to-detect form of credit card fraud are showing up more frequently in the Washington region, police say, including a recent case in Rockville, where a skimming device that reads encrypted credit card data was found in a Wachovia bank branch ATM. A credit card skimmer is a device that uses a card scanner and camera to capture credit card information. The skimmer is placed over the card slot reader and reads the magnetic swipe, while a hidden miniature camera in the device works in tandem to record the personal identification number

More on Credit Card Scimmers

Monday, March 22, 2010

A Picture Is Worth A Thousand Words

Hello,
For all of you who like to learn by other than reading I've put together a couple of million words together all about identity theft and online scams. They are in the form of Identity Theft Videos

Thursday, March 18, 2010

Please Don't Lose Your Mind

Hi Again,
In today's world of everyone trying to get in on the social craze some of us go overboard and overshare . This can leave us open to a wide variety of crime including credit card fraud and identity theft among others. To see what I mean check out

Please Rob Me

Wednesday, March 03, 2010

Microsoft Scores One For The Little Guy

Hi Everyone,

In the never ending battle against hackers it seems Microsoft is taking an aggresive approach to hinder the attacks leading to credit card fraud and identity theft this includes spam an malware

Stop Identity Theft

Tuesday, February 16, 2010

A Never Ending Battle

Identity theft and credit card fraud is constantly growing but hackers are being caught. here's a who's who of been causing all the chaos.

Convicted: Nine Notorious Hackers of Our Time

Experts Gather For Hackers' Convention

Every year in Arlington, Va., thousands of computer security experts, hackers and FBI agents attend BlackHat in hopes of learning how to stop the next big cyber threat. Events include hacking competitions and training, as well as lectures on computer security

Hackers Convention

Thursday, January 28, 2010

Fighting Cybercrime

Welcome back,
It's now 2010 and things are really cranking up due to the recession and the rapid advancements in technology. I came across this story which will give you a great overall picture of things the way they are.

Fighting Cybercrime-One digital thug at a time