Home Blog Page 396

A Critical Apple AirDrop Vulnerability Allows Hackers To Install Malware Silently In Apple iOS and OSX

airdrop vulnerability

After the release of Apple’s latest operating system, iOS 9, a cyber security company has uncovered a bug in earlier versions of the software that can be exploited silently over AirDrop to install malware on iPhones and iPads.

The vulnerability affects any iOS versions supporting AirDrop from iOS 7 onwards, as well as Mac OS X versions from Yosemite onwards.The latest iOS 9 and Mac OS X El Capitan, version 10.11 includes a security update for this nasty AirDrop vulnerability that could be exploited to take full control of your iPhone or Macs, forcing most of the Apple users to download the latest update.

Australian security researcher Mark Dowd has disclosed the serious vulnerability in AirDrop, that the bug allows anyone within range of an AirDrop user to hack into their device and install malware on their operating system.Apple’s Airdrop is very similar to WiFi Direct – both technologies enable files and data to be shared between devices with minimal input from the user. The feature is available on both iPhones and Apple Macs, although it is switched off by default.This means it could be performed in public areas, such as coffee shops, stores, public transit or any other area where the phone is within wireless reach of the attacker.

To initiate the attack, all a hacker has to do is to send a file via AirPlay to an iOS or OS X user running iOS 7 or later, and Yosemite, respectively. It doesn’t even matter if the recipient accepts the incoming transfer, as the malware attack is initiated.The hacker would then have to wait patiently for the user to reset the iPhone or Mac for any reason so that the malware app can be installed. How can a non-App Store app be installed that easily you ask? Well, the hacker would use an Apple certificate to sign it, fooling the OS into believing it’s a genuine piece of software – the kind that enterprises would release to their fleet of Apple devices.

“The [malware] app is restricted by its sandbox.However since you sign the app, you can grant some entitlements that allow it to do things like read contacts, get location information, use the camera or whatever other entitlements legitimate apps can be allowed to have.” — Dowd told Forbes.

Dowd also provided a video demonstration showing the real time attack on his iPhone running iOS 8.4.1.

iOS 9 and OS X 10.11 fixes the problem, so get them as soon as possible. Also, you can just turn off AirDrop when you’re not using it, to avoid such potential issues in the near future, especially if you don’t plan to, or can’t, update to the latest iPhone and Mac software versions.

Earlier today it was reported that a security researcher has discovered a vulnerability in version 5 of Android (Lollipop) that allows an attacker to crash the lockscreen and gain access to a locked device, even if encryption is enabled.

Major Security Flaw In Android Lollipop Allows Anyone To Unlock Your Smartphone

android lollipop vulnerability

In this year we saw many security flaws in Android Operating system,it seems that they fails to provide a first class security guard to this popular platform.Recently a security analyst at the University of Texas’s have discovered that some devices running on Android Lollipop can be unlocked and accessed basically by by entering a very long password causing the lock screen to crash.The vulnerability potentially affects 21% of Android devices in use and requires the attacker to simply overload the lockscreen with text.

The hack consists of basic steps like entering a long, arbitrary collection of characters into the phone’s Emergency Call dial pad and repeatedly pressing the camera shutter button. Researcher John Gordon, who outlines the full hack in this security notice and demonstrates it in the video below, says the trick offers full access to the apps and data on affected phones. And by using that access to enable developer mode, he says that an attacker could also connect to the phone via USB and install malicious software.

Gordon says he stumbled on the lock screen vulnerability while messing with his phone during a long East Texas road trip.

“I’m sitting in the passenger seat, bored, with no signal on my phone, so I start poking around and seeing what unexpected behavior I can cause.A few idle hours of tapping every conceivable combination of elements on the screen can do wonders for finding bugs.”

Gordon tested the attack only on Nexus devices, but he believes it likely works on other Android devices that use version 5 of the operating system. He reported the issue to Google in late June and Google released a fix for the security hole on Wednesday for its line of Nexus devices, describing the bug as of “moderate” severity, but that it was not actively being exploited by attackers, according to the company’s knowledge.

About 20% of the billion android devices across the world run Google’s latest version called Lollipop, including new devices from Samsung, LG and Sony.These devices will require a software update to fix the bug, but users will have to rely on the manufacturer of the smartphone and their mobile phone operator to roll out the update, rather than Google directly.The attack requires physical access to the smartphone, and cannot be performed remotely. Users worried by the attack can change their lockscreen preferences to a pattern unlock or Pin code, which can be up to 16 characters long, instead of a password.

After the Stage fright security vulnerability , Google, Samsung, LG and other Android smartphone manufacturers recently pledged to release monthly security updates for their latest devices, in an attempt to help prevent this kind of attack being used.

Samsung’s Dual-Screen Foldable Smartphone Might Launch In January

As per a new report, the top mobile brand Samsung may be preparing to launch a foldable smartphone next year.According to a new leak published to Chinese social network Weibo, Samsung’s most advanced flexible smartphone, which is codenamed Project Valley or Project V, will debut next January.

According to GForGames, the device has previously been rumored to feature a dual-display setup, with a larger display on the inside that might fold over when the shell is closed. There will apparently be two versions of the handset, both powered by Qualcomm Snapdragon processors.Regardless of the choice of CPUs, the terminal apparently has 3 GB of RAM, a built-in SD card slot for expandable storage, and a built-in non-removable battery.And reports also claimed that Samsung is heavily invested in testing the Snapdragon 820 and that the aforementioned company is the first OEM to receive test samples from Qualcomm Qualcomm’s next flagship processor, which it may also be using in the Galaxy S7.

foldable smartphone samasung project valley
Image Source: AndroidAuthority

However, Samsung Display has previously stated that “the commercialization of foldable smartphones will be possible in 2016” and a patent for Samsung’s dual-screen Project Valley foldable smartphone cropped up earlier this year too. Samsung certainly seems to be working on this type of device in some capacity, but there’s always a big leap from prototype to a retail product.

That’s all we know for now.Everybody is thinking its just a rumour so let’s wait for a couple of months for the big launch.

 

Soon There Will Be A Facebook Dislike Button

facebook dislike button

It’s finally here, ” Dislike ” button is here.Facebook confirmed that they are working on one of the most frequently requested feature ” Dislike ” button.

Yesterday in a public Q&A session held at Facebook’s headquarters in Menlo Park, California, the company’s chief executive Mark Zukerberg relieved this surprise that the company was working on a way to show empathy for victims of tragedies and other things that are inappropriate to Like, news outlets around the world sprung into action saying the masses would soon get their wish..The Dislike button has long been the most requested feature from Facebook users.

“I think people have asked about the Dislike button for many years…today is the day where I actually get to say that we’re working on it, and are very close to shipping a test of it.We didn’t want to just build a Dislike button because we don’t want to turn Facebook into a forum where people are voting up or down on people’s posts. That doesn’t seem like the kind of community we want to create.” — Mark Zuckerberg said in a public Q&A 

A “dislike” button has been constantly requested by some users since the introduction of the now-iconic “like” button in 2009.And in the past, Facebook has resisted the notion of a dislike button, saying it preferred to encourage positive interactions among its 1.5 billion users.

Zuckerberg will host another townhall-style Q&A later this month. Indian Prime Minister Narendra Modi will be the guest and the two will discuss how communities can work together to address social and economic challenges.

Indian Government To Replace Microsoft Windows With Its Own Operating System BOSS

BOSS OS

As the part of ” Make In India ” program, Indian government is going to  launch a new and improved version of its own operating system (OS) named Bharat Operating System Solutions (BOSS).According to the reports BOSS replace Microsoft Windows and all other OS for official use in future.

The new Linux-based operating system BOSS is developed by C-DAC (Centre for Development of Advanced Computing), with the help of Gujarat Technical University, DRDO and some other private computer manufacturers.The officials are planning to make it available to all government stakeholders later this month.

The main reason for the replacement of OS is because of countless attacks by Chinese hackers on key government websites and protect govt. data’s from other major vulnerabilities.

“Government’s need have a fully secure network. Fresh codes unique to the system have been written for the OS. Its source code that makes it safe and secure will have to be guarded at all cost,”  — sources told DNA.

Reportedly, the new OS comes with a virtual keyboard on the display screen itself and a bulk file converter which ensures a safe and speedy transfer of data. And it will support 18 languages including regional languages including Kannada, Bengali, Marathi, Gujarati and Malayalam.It has successfully tested fending itself from all kinds of attacks during the past three months of trial. Several government agencies including the Army intelligence were given the task to attack it to test its vulnerability status but they all failed to break it.

National Resource Centre for Free/Open Source Software (NRCFOSS) of India developed BOSS in 2007. The latest version of BOSS was released in 2013 and has undergone many changes to fit the process. The OS has almost all the features of Microsoft Windows and is completely secured and easy to use.However, the new OS can help India take a substantial step to prepare defend any type of cyber attacks to official online services and will be able to take care of both the individual computer as well as the networking.

Indian Scientists Developed A New Algorithm To Prevent Cybercrime

cybercrimes [TechLog360.com]

Indian researchers have developed a new keystroke algorithm that can use unique human typing patterns to make online authentication processes more secure, reliable and cheap and prevent cybercrime to an extend.

The new method developed by researchers at the Department of Computer Science and Engineering, Jeppiaar Engineering College, Chennai, hopes to alleviate some of the common issues for internet users including loss of password, growing prowess of hackers, and easy access to methods such as phishing and usage of bots.

Like fingerprint scans, retina scans and facial recognition, keystroke dynamics are a biometric – they measure a unique human characteristic.

“As the typing pattern varies from person to person, this can be used as a suitable method for the authentication process more effective than others,” — researchers J Visumathia and P Jesu Jayarin wrote in the Journal of Applied Security Research.

The new keystroke template algorithm combines measures from existing models to increase precision. To test their algorithm, the researchers built a programme that users could log into using passwords of varying length.

While entering their credentials, keystroke dynamics were recorded.Results indicate that their algorithm was successful in decreasing login errors and making improper authentication very unlikely, thus advancing keystroke dynamics analysis as a viable e-security measure.

This method is especially appealing for its relative ease of implementation, as the information needed to evaluate human typing patterns is already present in computers, researchers said.The researchers call for additional testing before the new algorithm can be used as a security measure.So lets hope soon we will see a new method to control cybercrimes.

“We concluded from the results presented that keystroke dynamics analysis holds big potential as an authentication method, but the methods used in the process have to be improved before it can be used as an independent security measure,” — researchers said.

Qualcomm Snapdragon Flight – The Technology To Develop Advance Consumer Drones Ever

snapdragon-flight-platform

Most of the high-end Android phones out their have have been built around Qualcomm’s Snapdragon 800 series SoCs (system on a chip). Now Qualcomm came with a new idea to develop next generation of drones.So Qualcomm Technologies, Inc announced Qualcomm Snapdragon Flight platform, specifically designed for consumer drones and robotics,  at the Qualcomm: Accelerating Robotics event.Hugo Swart, senior director of product management, made the announcement, followed by a live demo of the Snapdragon Flight reference drone—one of the world’s smallest 4K flying cameras that showcases the power of Snapdragon Flight.

snapdragon-flight-platform
Snapdragon Flight robotics development platform. Source::Qualcomm

We are using Qualcomm Snapdragon processor in our Android phones and we know what it capable for.It’s a tiny piece of silicon with a multi-core processor, a graphics-processing engine for everything from games to 4K video to photos, components that help you squeeze more out of your battery, GPS and wireless radio, display drivers for high-res screens, and all the brains and guts of what a modern phone can do.And now same Qualcomm Snapdragon processor that makes all of that possible is now “smart” enough to be the brains of a robot.

“Today, drones are made from multiple component vendors providing separate solutions for photography, navigation and communications, adding to the cost and bulk of consumer drones.The Qualcomm Snapdragon Flight brings together the technologies that have defined the mobile industry onto a single board, enabling OEMs to build drones that are lighter, smaller, easy to use and affordable with long battery life and superior functionalities.”  Raj Talluri, senior vice president, product management, Qualcomm Technologies, Inc

snapdragon-flight-platform
Snapdragon Flight reference drone. Source::Qualcomm

The Qualcomm Snapdragon Flight platform has been specifically designed for the rapidly growing consumer drone segment.The Snapdragon Flight features advanced processing power, real-time flight control on the Qualcomm Hexagon DSP, built-in Qualcomm 2×2 Wi-Fi and Bluetooth connectivity, and a leading global navigation satellite system (GNSS) optimized to support highly accurate location positioning. The Snapdragon Flight is designed to enable the advanced features that drone consumers want most, including:

  • 4K Video – 4K high resolution camera support, image enhancement and video processing capabilities and simultaneous 720p encoding for first person view
  • Advanced Communication and Navigation – Dual-band 2×2 802.11n Wi-Fi, Bluetooth 4.0, and 5 Hz GNSS location capabilities with advanced real-time flight control on Hexagon DSP
  • Robust Camera and Sensor Support – 4K stereo VGA, optic flow cameras, inertial measurement unit (IMU), barometer sensor support and ports for additional sensors
  • Qualcomm Quick Charge Technology – Supporting fast battery charging in between video/picture sessions

Since Qualcomm Technologies also announced that Yuneec, a leading developer of consumer and professional drones with a long history of innovation in electric aviation, will be one of the first companies to embrace the Snapdragon Flight. Yuneec plans to release a drone based on the platform in 2016.

Most Advanced iPhone Comes With A Very Low Battery Capacity

iPhone 6s battery

Apple’s next generation iPhone, iPhone 6S and iPhone 6S Plus was launched early in this week.Apple claims iPhone 6S will be the most advanced iPhone ever and it is true.But I don’t know why they equipped it with a battery pack that has a lower capacity than its predecessor.

Yes iPhone 6S have many advanced features, especially the new advanced pressure-sensitive touchscreen feature.But Apple downgrades iPhone 6S with wimpy 1715mAh battery.The video introduction of the 3D Touch interface, narrated by Apple’s design supremo Sir Jony Ive, includes a shot of the inside of the new Apple handset and its 1715mAh battery pack – which is smaller than the 1810mAh battery in the iPhone 6 released last year.

https://youtu.be/cSTEB8cdQwo

According to MacRumors, not only to iPhone 6S but also the 5.5-inch iPhone 6S Plus also has a smaller battery pack, moving from a 2910mAh in the iPhone 6 Plus to a 2750mAh pack.The physically smaller battery is the result of Apple cramming more hardware into the iPhone 6S and 6S Plus models. With the addition of a new “3D Touch” engine – which will open extra menus and trigger other actions if you press harder on the screen – Apple had to sacrifice the larger battery in order to have room for the additional gadgetry.

Even with the smaller battery, however, Apple claimed that the new models get the same battery life as their predecessors. The iPhone 6S lists its 3G battery life at 14 hours, while the 6S Plus claims a 24-hour battery life.This is apparently due to Apple building battery-saving measures into the new version of iOS. The iOS 9 build, set for release to the public on September 16, boasts features designed to extend battery life in all iPhones. With the OS coming bundled on the 6S and 6S Plus, Apple is able to claim the same battery life despite the smaller battery packs.

The iPhone 6S is also powered by a 14nm 64-bit ARMv8 A9 processor, whereas the iPhone 6 has a 20nm 64-bit ARMv8 A8 system-on-chip. That shrink in transistor gate size is likely to cut the power drain of the newer model somewhat – Apple said the A9 uses three-quarters of the power of the A8.

How that battery life claim will translate to real-world use has yet to be seen. New iPhone features, such as 4K video recording and the Live Pictures photo, could take their toll on battery life and result in users getting less operating time than they anticipated with the new iPhone.