Wednesday, 13 June 2018

Google Blocks Chrome Extension Installations From 3rd-Party Sites


It's a great way for users to install an extension, but now Google has decided to remove the ability for websites to offer "inline installation" of Chrome extensions on all platforms.
Google announced today in its Chromium blog that by the end of this year, its Chrome browser will no longer support the installation of extensions from outside the Web Store in an effort to protect its users from shady browser extensions.
"We continue to receive large volumes of complaints from users about unwanted extensions causing their Chrome experience to change unexpectedly — and the majority of these complaints are attributed to confusing or deceptive uses of inline installation on websites," says ​James Wagner, Google's extensions platform product manager.
Google's browser extensions crackdown will take place in three phases:


Starting today, the inline installation will no longer work for newly published extensions.

Starting September 12th, the company will disable the inline installation feature for all existing extensions and automatically redirect users to the Chrome Web Store to complete the installation.

By December 2018, Google will also completely remove the inline install API method from Chrome 71. Developers using one-click install buttons on their websites are advised to update their links to point to the Web Store.

Monday, 11 June 2018

U.S. Builds World's Fastest Supercomputer – Summit

China no longer owns the fastest supercomputer in the world; It is the United States now.

Though China still has more supercomputers on the Top 500 list, the USA takes the crown of "world's fastest supercomputer" from China after IBM and the U.S. Department of Energy's Oak Ridge National Laboratory (ORNL) unveiled "Summit."



Summit is claimed to be more than twice as powerful as the current world leader with a peak performance of a whopping 200,000 trillion calculations per second—that's as fast as each 7.6 billion people of this planet doing 26.3 million calculations per second on a calculator.

Until now the world's most powerful supercomputer was China's Sunway TaihuLight with the processing power of 93 petaflops (93,000 trillion calculations per second).

Since June 2012, the U.S. has not possessed the world's most powerful supercomputer, but if Summit performs as claimed by IBM, it will be made straight to the top of the Top500 supercomputer list which will be published later this month.


In the most recent Top500 list of the world's top supercomputers, published in November 2017, China still has more supercomputers with the US owned 143 of the top 500 while China owned 202.


Housed at Oak Ridge National Laboratory (ORNL) in Tennessee, Summit is developed by IBM in collaboration with Nvidia, RedHat, and InfiniBand networking specialists Mellanox and cost $200 million to build.

Summit consists of 4,608 compute servers, each of which has two IBM Power9 CPUs running at 3.1GHz with 22 processing cores running in parallel. That's over 200,000 CPU cores across all of Summit.

Each pair of Power9 chips is connected to six Nvidia Tesla V100 graphics chips (GPUs). In total, the system also features more than 10 petabytes of memory (RAM).

The ORNL team says Summit is the first supercomputer made bespoke for use in artificial-intelligence (AI) applications, like machine learning and neural networks.
"Summit's AI-optimized hardware also gives researchers an incredible platform for analyzing massive datasets and creating intelligent software to accelerate the pace of discovery," Jeff Nichols, ORNL associate laboratory director for computing and computational sciences, said in today's announcement.
However, the ORNL team says Summit's initial uses will include work on astrophysics, cancer research, fusion energy, and addiction treatment.

IBM is also building a smaller version of Summit called Sierra, which is scheduled to go online this year at the Lawrence Livermore National Laboratory. Sierra is less powerful than Summit with only four V100 GPUs per node for maximum processing capacity of around 125 petaflops.


2018 Ransomware Hostage Rescue Manual

Request Your Free Manual Now:

"2018 Ransomware Hostage Rescue Manual"
Request
What You Need to Know To Prepare and Recover from a Ransomware Attack.

Ransomware is vicious malware that locks users out of their devices or blocks access to files until a sum of money or ransom is paid. Attacks cause downtime, data loss, possible intellectual property theft, and in certain industries an attack is considered a data breach. 

Phishing emails, compromised websites and free software are just a few ransomware tools hackers can use to extort you.

Ransomware can take many different forms, but when you boil it down, it's a simple concept to understand: ransomware is a hostage situation.

This Ransomware Hostage Rescue Manual is packed with actionable info that you need to prevent infections, and what to do when you are hit with ransomware. You will also receive a Ransomware Attack Response Checklist and Ransomware Prevention Checklist.


Offered Free by: KnowBe4
See All Resources from: KnowBe4

Sunday, 10 June 2018

Hackers Can Hijack, Sink Ships: Researchers

Insecure configurations and vulnerabilities in communications and navigation systems can allow hackers to remotely track, hijack and sink ships, according to researchers at penetration testing and cybersecurity firm Pen Test Partners.

Pen Test Partners presented its research into vulnerabilities affecting the satellite communications (satcom) systems used by vessels. The company has continued to analyze software and hardware used in the maritime industry and found that they are affected by serious flaws.

It has also created an interactive map that can be used to track vulnerable ships. The tracker combines data from Shodan with GPS coordinates and it can show vulnerable ships in real time. However, the company will only periodically refresh the data shown on the map in an effort to prevent abuse.

Satellite communications is the component that exposes ships to remote hacker attacks, as shown by Pen Test Partners last year and, at around the same time, by researchers at IOActive.

While there are some vulnerabilities in these systems themselves, the main issue is that many satcom terminals continue to use default credentials, allowing unauthorized users to gain admin-level access.

Many of the security holes disclosed this week by Pen Test Partners can be mitigated by setting a strong administrator password on the satcom terminal. Other serious issues discovered by researchers have been reported to Cobham, whose Fleet One terminal was used in experiments, and have not been disclosed.

According to researchers, once an attacker gains access to the terminal, they can replace the firmware due to the lack of proper validation checks or downgrade it to an older and more vulnerable version, and they can edit the web application running on the terminal. Experts also discovered poorly protected admin passwords in configuration files.


An even bigger problem, researchers warn, is that once an attacker gains access to the satcom terminal, they can move laterally to other systems. One of them is the Electronic Chart Display and Information System (ECDIS), which is used by vessels for navigation.
Since the ECDIS can be connected directly to the autopilot feature, hacking this system can allow an attacker to take control of a ship.

“We tested over 20 different ECDIS units and found all sorts of crazy security flaws. Most ran old operating systems, including one popular in the military that still runs Windows NT,” explained Pen Test Partners researcher Ken Munro.

In one case, the ECDIS had a poorly protected configuration interface that allowed an attacker to spoof the position of the GPS receiver on the ship and make the vessel “jump” to a slightly different location.

Reconfiguring the ECDIS can also allow an attacker to change the size of the targeted ship as seen by other nearby vessels via the automatic identification system (AIS) tracker.
“So, simply spoof the ECDIS using the vulnerable config interface, ‘grow’ the ship and ‘jump’ it in to the shipping lanes,” Munro explained. “Other ships’ AIS will alert the ship’s captain to a collision scenario. It would be a brave captain indeed to continue down a busy, narrow shipping lane whilst the collision alarms are sounding. Block the English Channel and you may start to affect our supply chain.”

Another attack scenario described by Pen Test Partners targets the operational technology (OT) systems on board a ship. These systems are used to control steering, engines, ballast pumps and other components, and they communicate via the NMEA 0183 protocol.

Since messages sent over NMEA 0183 don’t use any authentication, encryption or validation, a man-in-the-middle (MitM) attacker can modify the data and, for example, inject small errors that would cause the ship to alter its course when autopilot is engaged, researchers warn.

“The advent of always-on satellite connections has exposed shipping to hacking attacks. Vessel owners and operators need to address these issues quickly, or more shipping security incidents will occur. What we’ve only seen in the movies will quickly become reality,” Munro concluded.

Update Google Chrome Immediately to Patch a High Severity Vulnerability

Security researcher Michał Bentkowski discovered and reported a high severity vulnerability in Google Chrome in late May, affecting the web browsing software for all major operating systems including Windows, Mac, and Linux.


Without revealing any technical detail about the vulnerability, the Chrome security team described the issue as incorrect handling of CSP header (CVE-2018-6148).
"Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven't yet fixed," the Chrome security team notes.
Content Security Policy (CSP) header allows website administrators to add an extra layer of security on a given web page by allowing them to control resources the browser is allowed to load.

Mishandling of CSP headers by your web browser could re-enable attackers to perform cross-site scripting, clickjacking and other types of code injection attacks on any targeted web pages.

The patch for the vulnerability has already been rolled out to its users in a stable Chrome update 67.0.3396.79 for Windows, Mac, and Linux operating system, which users may have already receive or will receive over the coming days/weeks.

So, make sure your system is running the updated version of Chrome web browser. We'll update the article, as soon as Google releases further update.

Firefox has also released its new version of the Firefox web browser, version 60.0.2, which includes security and bug fixes. So, users of the stable version of Firefox are also recommended to update their browser.

Tuesday, 15 May 2018

The Cybersecurity 202: Security community has its own encryption debate after discovery of new flaw

Security experts are at odds over how to respond to new research showing hackers could decrypt emails that were supposed to be protected by a popular encryption tool known as PGP, or Pretty Good Privacy. 
A group of European researchers on Monday revealed a flaw in the way certain email programs handle PGP and S/MIME, a similar encryption protocol commonly used by businesses and other enterprises, as my colleague Brian Fung and I reported yesterday. 
The discovery of the flaw, dubbed Efail, blew open a rift between defenders of PGP who insist the encryption is sound — and others who say it’s time to move away from the 30-year-old technology in favor of encrypted messaging apps such as Signal.
“This whole PGP infrastructure is kind of a mess and needs to be hardened up and fixed, or we need to start using something better,” Matt Green, a cryptography expert and assistant professor at Johns Hopkins University, told me. “Signal, Wired and other encrypted chat applications aren’t vulnerable the way PGP is. They’re not only more secure, they’re more widely used.”
PGP has been the gold standard for encrypting emails since it was released in 1991. But today, people want the convenience of using their smartphones. And encrypted apps are more widely available than ever. 
With the discovery of this flaw, it’s a good time to make the switch, tweeted Barton Gellman, a senior fellow at the Century Foundation and former Washington Post reporter who covered the National Security Agency leaks by Edward Snowden: 


I'm against defeatism. I'd say "possibly not." And that assumes you're targeted by a proficient adversary. Journalists, activists, political opposition should take extra care. Large majority of people would get much more privacy out of GPG than not, and certainly from Signal. https://twitter.com/NickOchsnerWBTV/status/996039315519102977 
Ads info and privacy
Yet the flaw isn’t in PGP itself but in the way certain email programs handle it. Researchers said affected email applications include Mozilla Thunderbird, Apple Mail and some versions of Outlook. (A full list is available from the researchers' report.)
The vulnerability allows hackers to read an encrypted email by making changes to its HTML, which essentially tricks the affected email applications into decrypting the rest of the message. To do this, a hacker would need access to the victim’s encrypted emails — for example, by snooping on network traffic or otherwise compromising email accounts. 
Green explains it simply: “The attacker can modify the encrypted email, and when the person for whom it’s intended opens it or previews it, the mail program will send the contents out to a remote server the attacker has set up,” he said. “All you have to do is look at it and it will decrypt itself and send it out to the attacker.”
This could put whistle blowers, political activists and others who depend on encrypted email at risk, the researchers said in a blog post. That added urgency to warnings from the digital rights group Electronic Frontier Foundation, which urged users of the affected email programs to immediately disable tools that allow the email apps to use PGP or S/MIME. 
“Until the flaws described in the paper are more widely understood and fixed," EFF said, "users should arrange for the use of alternative end-to-end secure channels, such as Signal, and temporarily stop sending and especially reading PGP-encrypted email." 
But some security experts said these dire warnings were overkill.

My $50,000 Twitter Username Was Stolen Thanks to PayPal and GoDaddy

I had a rare Twitter username, @N. Yep, just one letter. I’ve been offered as much as $50,000 for it. People have tried to steal it. Password reset instructions are a regular sight in my email inbox. As of today, I no longer control @N. I was extorted into giving it up.


While eating lunch on January 20, 2014, I received a text message from PayPal for one-time validation code. Somebody was trying to steal my PayPal account. I ignored it and continued eating.

Later in the day, I checked my email which uses my personal domain name (registered with GoDaddy) through Google Apps. I found the last message I had received was from GoDaddy with the subject “Account Settings Change Confirmation.” There was a good reason why that was the last one.

From: <support@godaddy.com> GoDaddy
To: <*****@*****.***> Naoki Hiroshima
Date: Mon, 20 Jan 2014 12:50:02 -0800
Subject: Account Settings Change Confirmation
Dear naoki hiroshima,
You are receiving this email because the Account Settings were modified for the following Customer Account:
XXXXXXXX
There will be a brief period before this request takes effect.
If these modifications were made without your consent, please log in to your account and update your security settings.
If you are unable to log in to your account or if unauthorized changes have been made to domain names associated with the account, please contact our customer support team for assistance: support@godaddy.com or (480) 505-8877.
Please note that Accounts are subject to our Universal Terms of Service.
Sincerely,
GoDaddy

I tried to log in to my GoDaddy account, but it didn’t work. I called GoDaddy and explained the situation. The representative asked me the last 6 digits of my credit card number as a method of verification. This didn’t work because the credit card information had already been changed by an attacker. In fact, all of my information had been changed. I had no way to prove I was the real owner of the domain name.

The GoDaddy representative suggested that I fill out a case report on GoDaddy’s website using my government identification. I did that and was told a response could take up to 48 hours. I expected that this would be sufficient to prove my identity and ownership of the account.


Click on the link below to read the full story:


https://medium.com/@N/how-i-lost-my-50-000-twitter-username-24eb09e026dd