WhatsApp Making Waves
As the Federal Government (IE: Big Brother) continues to hammer away any form of privacy,
WhatsApp is making waves.
What is WhatsApp?
By the websites defintion:
“WhatsApp Messenger is a cross-platform mobile messaging app which allows you to exchange messages without having to pay for SMS. WhatsApp Messenger is available for iPhone, BlackBerry, Android, Windows Phone and Nokia and yes, those phones can all message each other! Because WhatsApp Messenger uses the same internet data plan that you use for email and web browsing, there is no cost to message and stay in touch with your friends.”
“In addition to basic messaging WhatsApp users can create groups, send each other unlimited images, video and audio media messages.”
So what’s different with WhatsApp, and why the waves?
“End-to-end encryption is available when you and the people you message are on the latest versions of WhatsApp.”
This means all the messages, photos, other media sent from one user to another (with the latest version) is secure. Your privacy is safe. Think about that for a moment.
Recently the FBI is forcing Apple to create software to hack into their own system. Source:
“This is not a case about one isolated iPhone,” writes Apple attorney Marc Zwillinger in today’s brief. “Rather, this case is about the Department of Justice and the FBI seeking through the courts a dangerous power that Congress and the American people have withheld: the ability to force companies like Apple to undermine the basic security and privacy interests of hundreds of millions of individuals around the globe.”
During the fight in the courts, FBI then admits it has already hacked the phone.Source:
Whoops.
My thought? They have always had the method and means. They just wanted Apple to play along with creating a backdoor, publicly.
Now with the knowledge of the Federal Government’s ability to hack I-phones, one more privacy has been lost to America.
Which brings us back to WhatsApp.
With end to end encryption, the idea is no weak spots for the Federal Government or 3rd party to intercept your messages. This would give WhatsApp billion users the security and freedom in knowing a would be hacker is not eavesdropping.
To verify that a chat is end-to-end encrypted in WhatsApp:
- Open the chat.
- Tap on the name of the contact or group to open the contact info/group info screen.
- Tap Encryption to view the QR code and 60-digit number.
Hearing this, I had to try it out myself. The app is free, through the smartphone.
According to WhatsApp Encryption Overview…
“Once a session has been established, clients exchange messages
that are protected with a Message Key using AES256 in CBC
mode for encryption and HMAC-SHA256 for authentication.
The Message Key changes for each message transmitted,
and is ephemeral, such that the Message Key used to
encrypt a message cannot be reconstructed from the session
state after a message has been transmitted or received.”
This means each message a new unique encryption is provided, making it more difficult to crack.
“The Message Key is derived from a sender’s Chain Key that
‘ratchets’ forward with every message sent. Additionally, a new ECDH
agreement is performed with each message roundtrip to create a new
Chain Key. This provides forward secrecy through the combination
of both an immediate “hash ratchet” and a round trip ‘DH ratchet’.”
In other words, a pretty good method to keep your conversation to you and your desired audience only.
#ThePlexusPrepper
Share and Enjoy
• Facebook • Twitter • Delicious • LinkedIn • StumbleUpon • Add to favorites • Email • RSSYou can also check out the Facebook Page, Prepping for SHTF
11:36 AM | 0 Comments
Crackers phish with Fliers
Interesting. I would think they could at least narrow down subjects due to their geographical activity.
Cybercriminals Try Phishing With Fliers
By Thomas Claburn
Read the Original Article at InformationWeek
The link advertised leads to malicious hacking script that attempts to establish a connection to a Web site that Symantec said has been associated with malware.
As part of their ongoing effort to convince people to visit malicious Web sites, cybercriminals are experimenting with a new medium: phony advertisement fliers.
In a post on the SANS Internet Storm Center blog, security consultant Lenny Zeltser describes a scheme to drive traffic to a malicious Web site using pamphlets left on cars.
A few days ago, yellow fliers appeared on cars in Grand Forks, N.D., Zeltser reports. They purported to be parking violation notices and advised recipients to go to a specific Web site "to view pictures with information about your parking preferences." (If you've never heard of parking preferences, you're not alone.)
At the specified Web site, visitors found snapshots of cars at area parking lots, along with the instructions, "To view pictures of your vehicle from Grand Forks, North Dakota download here," followed by a link to a file called PictureSearchToolbar.exe.
Once installed, that program downloaded a malicious DLL and attempted to establish a connection to a Web site that Symantec said has been associated with malware.
"The initial program installed itself as a browser helper object for Internet Explorer that downloaded a component from childhe.com and attempted to trick the victim into installing a fake anti-virus scanner from bestantispyware securityscan.com and protectionsoft warecheck.com," Zeltser explains in his post. "Attackers continue to come up with creative ways of tricking potential victims into installing malicious software. Merging physical and virtual worlds via objects that point to Web sites is one way to do this. I imagine we'll be seeing such approaches more often."
Don't worry too much, though. The sentence construction in the fake Windows security alert rather ruins the scam. The alert reads like a transcription of the Russian-inflected English uttered by Chekov on the original Star Trek series: "Your system requires immediate anti viruses check!"
4:46 AM | 0 Comments
White hat demonstrates security vulnerabilities in radio technology
An interesting article on the fallacy of RFID security for our passports, and building access. Rather than the RFID company suing Chris, they should hire him as a consultant to beef up their holes in security.
But that would make too much sense.
Hacker clones passports in drive-by RFID heist
White hat demonstrates security vulnerabilities in radio technology
A British hacker has shown how easy it is to clone US passport cards that use Radio Frequency ID chips by conducting a drive-by test on the streets of San Francisco.
Chris Paget, director of research and development at Seattle-based IOActive, used a $250 Motorola RFID reader and an antenna mounted in a car's side window and drove for 20 minutes around San Francisco, with a colleague videoing the demonstration.
Paget picked up the details of two US passport cards, which are fitted with RFID chips and can be used instead of traditional passports for travel to Canada, Mexico and the Caribbean.
"I believe that RFID is very unsuitable for tagging people," he said. "I do not believe we should have any kind of identity document with RFID tags in them. My ultimate goal would be to see the entire Western Hemisphere Travel Initiative scrapped."
Paget claimed that it would be relatively simple to make cloned passport cards from the information he had gathered.
Genuine passport cards support a 'kill code' which can wipe the card's data, and a 'lock code' that prevents the tag's data being changed. But Paget believes that these protections are not being used and that, even if they were, the radio interrogation is done in plain text so is relatively easy for a hacker to collect and analyse.
The ease with which the passport cards were picked up is even more worrying considering that fewer than a million have been issued to date.
Paget is a renowned 'white hat' ethical hacker, and has made the study of the security failings of RFID something of a speciality.
In 2007 he was due to present a paper on the subject at the Black Hat security conference in Washington, but was forced to abandon the plans after an RFID company threatened him with legal action.
Paget points out that RFID tags are increasingly being used in physical security systems such as building access cards, and that the technology needs significant extra security before it can be considered safe for commercial use.
5:56 AM | 0 Comments