The Hottest News on Your Laptop

247NEWSMARK.blogspot.com

As Long as It Is Trending, We Got It!!!

The '247NEWSMARK App' Coming Soon

News That You NEVER Knew Was Made!!!

'LIKE' Us On FaceBook

No Matter Where You Are, We've Got YOU Covered

News Fast, Anytime, Anywhere

Try Out Our Mobile Site

m.247newsmark.blogspot.com

Popular Posts

Subscribe Now!

Showing posts with label Apps and Software. Show all posts
Showing posts with label Apps and Software. Show all posts

Tuesday, 3 December 2013

The gentle art of cracking passwords

 
On the internet, the most popular colour is blue, at least when it comes to passwords.
If you are wondering why, it is largely because so many popular websites and services (Facebook, Twitter and Google to name but three) use the colour in their logo. That has a subtle impact on the choices people make when signing up and picking a word or phrase to form a supposedly super-secret password.
It's just one of the many quirks to be found in the password-picking habits of us humans. There are plenty of others. For example studies suggest red-haired women tend to choose the best passwords and men with bushy beards or unkempt hair, the worst.
These studies also reveal that when it comes to passwords, women prefer length and men diversity.
Big data These facts have come to light thanks to the vast number of passwords that have been stolen from websites and online services, says security researcher Per Thorsheim.
Adobe, LinkedIn and game website RockYou have all been hit in breaches that involved the theft of login names and passwords. Add to this the steady drip of security breaches at other firms and you have a vast corpus of data that can shed light on what passwords people pick.
The number one conclusion from looking at that data - people are lousy at picking good passwords.
Computer chip Brute force attacks throw computer power at passwords
"You have to remember we are all human and we all make mistakes," says Mr Thorsheim.
In this sense, he says, a good password would be a phrase or combination of characters that has little or no connection to the person picking it. All too often, Mr Thorsheim adds, people use words or numbers intimately linked to them.
They use birthdays, wedding days, the names of siblings or children or pets. They use their house number, street name or pick on a favourite pop star.
This bias is most noticeable when it comes to the numbers people pick when told to choose a four digit pin. Analysis of their choices suggests that people drift towards a small subset of the 10,000 available. In some cases, up to 80% of choices come from just 100 different numbers.
People power It is this realisation about human bias that has transformed the way that people, both the good guys and the bad, go about cracking passwords.
"Now brute forcing is absolutely the last tactic we would use," says Mr Thorsheim.
Brute forcing, as its name suggests, throws raw computer power at the problem of password cracking. Such an attack on a password would first try "a" and then work through all possible letter and number combinations before ending at "zzzzzzz".
Password security depended on computer power never getting to the point where billions of those sequential combinations could be tried in a reasonable amount of time. The mathematics (time multiplied by tries) defeated the crackers.
"But", says security researcher Yiannis Chrysanthou from KPMG, "it's not about mathematics any more because it's people that select the passwords."
Many security researchers look to improve their password cracking methods so they can advise companies about what they need to do to make people choose phrases that are more secure.

Cracking passwords

I tried to see how easy it is to crack passwords for myself.
Armed with a list of hashed passwords culled from one of the many sites where stolen lists are dumped every day, I looked for software that could crack them.
I turned to two of the best known, Hashcat and John The Ripper, loaded up my hashes, picked my word lists, applied my rules and let them rip.
Soon after I had a list of cracked passwords - not all of them - and I stopped the process before it had completed.
The words and phrases that emerged first were wearyingly familiar. It's no wonder that people's online accounts are regularly breached if so many are choosing obvious combinations such as "aaa123" as a password.
They also try to crack the passwords in the stolen lists to get a better idea of what people have been using. In such situations often what is being cracked is a sequence of letters known as a "hash".
These fixed-length strings of characters cannot be rewound to reveal what characters gave rise to them. However, because hashing algorithms work according to a fixed set of rules then "123456" will always produce the same seemingly random sequence of letters. Under the MD5 hashing system "123456" always produces the string: "e10adc3949ba59abbe56e057f20f883e".
Generate hashes for all the words in a long list related in one way or another to a target and there is a much better chance of guessing their password, says Mr Chrysanthou, who developed novel rules for cracking passwords while studying at Royal Holloway.
It was via this approach that he managed to crack the password: "Ph'nglui mglw'nafh Cthulhu R'lyeh wgah'nagl fhtagn".
At first glance this mangled collection of lower and upper case letters drizzled with apostrophes looks like it would be pretty secure. Unless you are a well-educated geek who knows it comes from a horror story written by HP Lovecraft.
Targeted attacks are likely to scour social media for words, names and dates important to a victim. Knowing the names of someone's children, pets, parents or street can help unpick a password very quickly.
Facebook on a phone What you do and say on social media can give clues to your passwords
The bad guys try to crack passwords, says security researcher Bruce Marshall, because they too know another truth about people - they are lazy.
This means that there is a very good chance, 70% according to some studies, that a password associated with an email address on one site might well be used to log in on one or more other online services.
Many cyber-thieves target smaller sites to get at their lists of passwords and then try them in other places to see if they have been used.
"If a criminal is cracking passwords then most likely they gathered them from a specific site and are trying to gain access to additional accounts," says Mr Marshall.
The sheer number of passwords released to the web has created another problem, he says.
"If an attacker can't gain access to the targeted site's password database then they may resort to an online password guessing attack where they try common usernames, email addresses and password combinations," he says.
So, if you want to pick a stronger password do not use simple combinations of words and numbers, choose words that are only tangentially related to you and make sure the password you use for your online banking is used for nothing else.


 source: bbcnews

Monday, 25 November 2013

Cyberattack Leads to $1 Million Bitcoin Heist


Another Bitcoin company has fallen victim of a massive cyberheist. BIPS, one of the largest European Bitcoin payment processors, lost 1,295 Bitcoin (currently worth $1 million) after a cyberattack.
As the price of Bitcoin continues to rise, cybercriminals are targeting companies with large holdings of Bitcoins in their servers. The attack on BIPS happened just a few weeks after inputs.io, which allegedly lost 4,100 BTC, worth more than $1 million at the time.

Hackers launched their initial Distributed Denial of Service (DDoS) attack on BIPS on Nov. 15, the company wrote in a Reddit post. The hackers attacked again on Nov. 17, overloading BIPS servers and somehow getting access to several online wallets, which allowed them to steal the 1,295 BTC.
BIPS, which claims to have more than 20,000 customers, offered free online wallets to store their Bitcoin online. It also offers a payment processors for merchants who want to accept payments in Bitcoin.
The company released a statement saying the attack compromised "several consumer wallets." However, it didn't specify how many accounts were hacked. BIPS' CEO Kris Henriksen told Mashable that "most of the missing funds were from our company’s own holdings," but declined to be interviewed for lack of time. "This is my fifth day without sleep," he added in an email.
After the attack, Henriksen advised his customers to avoid online wallets altogether, despite the fact that his company offered them to users. BIPS' online wallet service is now suspended.
"Attacks are not isolated to us, and if you are storing larger amounts of coins with any third party, you may want to find alternative storage solutions as soon as possible," he wrote in a BitcoinTalk forum message.
"Web Wallets are like a regular wallet that you carry cash in and not meant to keep large amounts in," he added.
But several BIPS customers, who still don't know if they'll ever get their Bitcoin back, aren't convinced by Henriksen's advice, saying he never warned them of any danger before the attack. On the contrary, the company said it was secure.
Responding to Henriksen's claim that web wallets are only meant for little amounts of Bitcoin, a BitcoinTalk forum user that goes by the name of Cubicdissection said: "At NO point did you EVER say hey you shouldn't keep your BTC with us."
"In fact, your website said: 'Your data is secure at BIPS.' So yeah, I felt pretty goddamn secure leaving my BTC balance there," he added. "Why don't you speak in plain English and quit giving us the runaround? Because it makes me think you're a liar and have something to hide."
Another user, nicknamed Genghis34, said he had 90 Bitcoin (around $73,000) in his BIPS wallet. He his now asking other victims to sign up online to form a group to potentially sue BIPS and use the threat of a lawsuit as a "negotiating block" for a settlement.
Henriksen's conclusion that online wallets aren't safe echoes what the founder of inputs.io said after his website's loss of 4,100 Bitcoin.
"I don't recommend storing any Bitcoins accessible on computers connected to the Internet," he wrote at the time.
But for victims of the BIPS heist, these warnings come too little too late.
"Bitcoin is the wild west," wrote Genghis34. "And I really doubt this was intentional on the part of bips.me — just probably overconfidence to run a wallet service without proper security."




source:mashable

Android 4.4 KitKat update hits HTC One Google Play Edition


If you own the HTC One Google Play Edition smartphone, some good news has started to turn up that you will be interested in. Reports are indicting that HTC One Google Play edition owners have begun to receive a 320MB OTD software update.
iMovie-2-580x302

Reports indicate the software update is bringing the device Android 4.4 KitKat. There are no screen shots of the update in action at this time. The update was previously tipped by HTC to be coming to this device in late January. The update is also said to be available as a developer update.
We reviewed the HTC One Google Play Edition smartphone in the past along with its sibling the Samsung Galaxy S4 Google Play Edition. There is no word at this time if the S4 Google Play Edition is getting the update soon.
The HTC One Google Play Edition smartphone uses a Snapdragon 600 processor with 2GB of RAM. It has 32GB of storage and a microSD card slot for expansion. It also has the other features you expect like Bluetooth 4.0, WiFi, NFC, and GPS.



source: slashgear

Thursday, 21 November 2013

Why Intel Is Bailing On Its Plan To Sell A Digital TV



Earlier this year, Intel Corp rented temporary retail space in New York, Los Angeles and Chicago for a splashy launch of Intel TV, a new Internet entertainment service that the chipmaker promised could revolutionize the television industry.
But when customers walk into those stores this holiday season, they will not find any set-top TV boxes or programming services for sale. Instead, they will see ultra thin laptops and new tablets from a variety of vendors that Intel hopes will help boost its massive but flagging computer chip business.
The drastic change in plans for the retail spaces follows the company's abrupt abandonment of a grand plan to become an entertainment hub in living rooms around the world - a retreat that has been rumored but not yet acknowledged by the company.
The project faced daunting challenges from the start, and Intel's new CEO, Brian Krzanich, ultimately decided the company could not afford the distraction and expense, sources familiar with the decision told Reuters.
At his first annual investor day on Thursday, Krzanich is expected to discuss the growing use of chips in everyday devices, plans to breath new life into PCs, and Intel's growing contract manufacturing business - but not Intel TV.
Sources close to the project said Intel Corp is looking to sell the TV technology, called OnCue, with Verizon Communications Inc emerging as the most likely buyer, as first reported by the AllThingsD website.
An Intel spokesman declined to comment.
Intel's retreat is a disappointment not only to former British Broadcasting Corp executive Erik Huggers, who led the project, but also to others in Silicon Valley who saw it as part of a wave of next-generation digital television products that might help break open a market tightly controlled by a handful of cable companies and entertainment conglomerates.
Technology heavyweights including Apple Inc, Amazon.com Inc Google Inc Sony Corp and Microsoft Corp all have similar ambitions. Yet thus far only Netflix Inc has proven to be a major disruption to the lucrative relationship between pay TV operators and the entertainment companies that provide them with content.

THINKING OUTSIDE THE CHIP

Intel, a storied semiconductor company that has struggled to manage the transition from traditional personal computers to mobile devices, was always an unlikely player in the digital television wars. Its traditional strengths are in chip design and manufacturing, and it has little experience selling consumer products, much less television programming.
But Paul Otellini, Intel's CEO from 2005 until May of this year, saw an opportunity for Intel to diversify into a new consumer business, one centered on a high-tech set-top box and a slick user interface. The often-clunky hardware and software provided by cable companies, and the highly controlled structure of cable packages, seemed to beg for a better solution.
Otellini entrusted the project to Huggers, a veteran TV executive who all but boasted that he knew nothing about chips. Huggers, who had originally pitched the idea, developed a business plan, and soon set up his group in offices with the flashy look of a media startup on the chipmaker's Santa Clara, California, campus.
Making his case for Intel TV to the public for the first time in February 2013 at a conference near Los Angeles, Huggers assured the audience that Intel would not offer channels a la carte, an industry buzz word despised by entertainment companies that count on "bundling" lower rated channels with popular ones.
But Huggers also said Intel would offer channel packages that "are bundled right," which many in Hollywood took to mean an attempt to slice off the less popular channels - something that would not come cheaply or easily.
While Intel never said how much it planned to charge for its TV service, Huggers billed it as a premium product, rather than a cut-rate option for consumers hoping to save money by canceling their cable subscriptions.
Huggers ultimately made only modest progress negotiating slimmer packages of channels, people familiar with the talks said. Still, by this summer, Huggers had more than 300 employees and was testing the OnCue device in the homes of thousands of Intel employees.
Many people who saw a prototype of the device, a nondescript black box, and toyed with the all-important graphical interface software, described OnCue as far superior to what is generally offered by cable and satellite TV companies.
Representatives for Verizon, Viacom Inc, NBC, CBS, Fox, Time Warner Inc and Disney's ABC all declined to comment on their discussions with Intel.

THE NEW BOSS

Krzanich, a manufacturing expert who won the top job after the Intel board decided to stick with an in-house executive, never shared Otellini's interest in Intel TV.
Meeting with a group of reporters a month into his tenure as CEO, he spoke for an hour about his mobile chip strategy. When pressed about the TV business he struck a surprisingly cautious tone, saying the company is not expert at content.
Intel's TV project was a distraction to Krzanich, company sources say. He spent his first six months as CEO focused on two threats to the chipmaker's core business - a declining PC industry and a lack of progress in smartphones and tablets.
"It's not wrong for them to look for growth wherever they can find it because they need to," said Bernstein semiconductor analyst Stacy Rasgon. "But (Krzanich) has enough on his plate to worry about."
While Huggers came close to finalizing deals with some of the major programmers, according to industry sources on both sides of the talks, the terms were such that Intel would have faced upfront outlays in the hundreds of millions regardless of how quickly the service caught on, the same sources say.
"The problem is Intel's appetite for the size of the financial risk required to launch," said Rich Greenfield, a media analyst at BTIG, noting the big commitments to media companies as well as large consumer marketing and customer service operations. He pegged launch costs in the hundreds of millions of dollars but declined to be more specific.
Intel also had to make concessions to media companies that might have made it harder to sell the service: Viewers streaming previously aired shows from some networks would not be allowed to fast-forward through commercials, for example.
Still, Intel TV would have offered far easier navigation, simple access to archived programming, and innovations in advertising delivery and personalized services. It would have also held out the potential for other features that could be readily implemented with an advanced Intel-powered set-top box and associated Internet-based services.
Ultimately, Krzanich was not willing to make the bet. Media company sources say tentative deals with Intel are now on hold as the chip company seeks a buyer for the service.
Huggers hopes to sell the television project as turnkey operation, including its technology and engineers, and would like to see the service launch under a more media-oriented company, some of the industry sources say.
For Intel, it has been a tough lesson in reinvention.
Krzanich "is a bit more of a realist than Paul was," Bernstein's Rasgon said, referring to Otellini.
"They really believed they could differentiate on the hardware," he said. "What they didn't understand when they started, because it is new, is it's about the content - not about the hardware."

Monday, 18 November 2013

UK and Irish Government Agencies include emergency alerts in Tweets

The practical uses for Twitter in the UK and Ireland, beyond sharing news and personal updates, will now include emergency alerts. Twitter UK representative Steve Summers made the announcement on Sunday via a blog post on the company’s website. Joining the Twitter alert program are 57 official governmental agencies, including the London Metropolitan Police, the office of the Mayor of London, the Environment Agency, the Child Exploitation & Online Protection Centre, the London Fire Brigade and London Ambulance Service. A full list of the agencies now offering the alert service can be found on Twitter’s website. When the participating agencies post a tweet with the hashtag “alert,” the message will also be accompanied by an orange bell graphic, a visual add-on designed to emphasize the urgency of the message. Users interested in signing up for the alert can subscribe via a special alert form on the participating agency’s Twitter account. In addition to app-based push notifications, users can also register their phone numbers with the agencies to receive SMS alert messages. However, the company's instructions warn that your number will then be discoverable by others on Twitter unless you adjust the settings on your account. In a statement obtained by Twitter, Metropolitan Police Service Commander David Martin said, “Getting fast and accurate information to the public in a major incident or terrorist attack really could make a life-saving difference. “Using social networking sites, including Twitter, gives us additional ways to talk directly to the public. Twitter Alerts means that our messages will stand out when it most matters.” source: mashable