Monday, December 14, 2015

What security risks are hidden in your Christmas presents this year?

security risks in Christmas presents


Once upon a time, a Christmas tree surrounded by elaborately wrapped gifts represented a security threat because the festive season has traditionally been the busiest time on the burglar’s calendar. These days, if the festive wrapping paper, gift boxes, cellophane and ribbons under your tree disguise tech toys and mobile devices, the threat could be more invisible – and potentially even more costly.


Tech toys, WIFI enabled games, wearable devices, tablets, mobile phones and even big-ticket items like laptops are already predicted to be among some of the most popular gifts this Christmas.


The Toy Retailers Association has revealed its list of the 12 toys expected to be most popular at Christmas 2015 in the UK, predicting the number one gift could be Vtech’s Baby Toot-Toot Friends Busy Sounds Discovery House. Did we just say Vtech?


According to gizmag, today’s kids expect their toys to connect to the internet, pair with smart devices, and let them join in the latest tech trends, often before their parents. However, while there are good reasons parents should think twice before buying tech toys for their kids, as you will read below, security risks aren’t just confined to gadgets for children.


Christmas gifts could be the equivalent of the Trojan Horse


As the concept of the Internet of Things (IoT) rapidly becomes reality as more and more objects are embedded with electronics, software, sensors and network connectivity that enables them to collect and exchange data, how many of your Christmas gifts could be the equivalent of the Trojan Horse? It was a decisive end to the Trojan War when the Greeks used subterfuge to enter the city of Troy, hiding some of their army inside a huge wooden horse. After pretending to sail away, the unsuspecting Trojans pulled the horse into their city as a victory trophy. Later that night the Greek force crept out of the horse and opened the city gates for the rest of the Greek army to enter and destroy the city. What attackers could be potentially unleashed in your Christmas gifts?


 


Think twice before buying the following gifts


From big brand gaming consoles to experimental wearable devices, many manufacturers are struggling to keep up with hackers and attackers.


Christmas Security Risk #1: Gaming consoles that ask for too many personal details


video-controller-336657_playstation


Gaming consoles can be hacked and personal data stolen. According to many commentators, Sony’s Playstation is most likely to be targeted by hackers after personal details about millions of Playstation Network (PSN) users were stolen back in 2011. Many believe that Sony has not responded appropriately and continues to ask for the type of personal and financial data that banks do, without the same security measures in place. Recently some hackers set out to prove that that cyber security at Sony remains weak by unleashing a massive distributed denial of service (DDos) attack.


 


Christmas Security Risk #2: Tablets and apps that store data on the manufacturer’s server


VTech_ELPs_011


When tablets, or apps that run on them, ask children for any personal data (such as names, addresses and birthdates), ask them to upload a profile photo, record audio conversations or store chat logs, it potentially puts your family at risk if these files are stored on the manufacturer’s servers.


A hacker took advantage of this last month, stealing data from 4.8 million customers including gigabytes worth of profile photos, audio files and chat logs sitting on Chinese electronic toy manufacturer VTech’s servers, after VTech had encouraged parents to take the headshots of both themselves and their children and use them with apps like Kid Connect that enable them to interact with each other. The hacker then downloaded almost 200 gigabytes’ worth of these photos as well as chat logs and recordings of conversations. Many have questioned why VTech stored the data on its servers in the first place and while the company responded by switching off the servers, blogger Dan Goodin says “it was of little help to the millions of people already affected by this epic privacy blunder”.


Christmas Security Risk #3: Wi-Fi enabled dolls, teddy bears and toy robots


pMAT1-hellobarbie


Wi-Fi enabled dolls, teddy bears and toy robots pose a risk because hackers can extract information including Wi-Fi network names, account IDs and MP3 files. Hackers could also hijack and decrypt the session cookie that identifies you to a service like Twitter or Google, and then take over your accounts without needing your password. But this is just the tip of the iceberg. Attackers could also intercept communication between a child and his or her toy. For example, Hello Barbie enables real-time conversations between children and the doll by recording audio and uploading it to the cloud for instant processing of artificial intelligence-based responses. Security researcher Matt Jakubowski recently managed to hack the Hello Barbie operating system and says the information he’s been able to extract would enable the attacker to find someone’s house, access their home network and retrieve everything that the toy has recorded.


Christmas Security Risk #4: Smartwatches


iphone-1021292_1920


A research study conducted by Hewlett-Packard released in July this year analyzed 10 smartwatches and found that every single one of them contained significant vulnerabilities, including insufficient authentication, lack of encryption and privacy concerns. The top selling smartwatch for kids last Christmas was the Vtech Kidizoom, designed for 6-12 year olds. While it wasn’t included in the HP research study, Vtech’s recent security breach with its tablet (see #3 above) should put parents on watch.


Christmas Security Risk #5: Fitness trackers


Nike-FuelBand-SE


Wearable devices for grown-ups like Fitbit Force, Jawbone Up, Fitbug Orb, Nike FuelBand SE store vast amounts of personal data about the user. The devices link the gathered information to a user profile connected to a laptop or smartphone through a Bluetooth connection and also send the information to the cloud for safekeeping. The potential for a hack exists during the data exchanges. While a lot of the information from the device (such as number of miles run) is not sensitive, it gives hackers backdoors into laptops and smartphones loaded with personal information.


Christmas Security Risk #6: Gaming consoles that don’t turn off


books-493252_emsi


There is a risk that hackers could exploit gaming consoles while they are apparently lying idle. Some believe this risk is much greater now that there are an army of devices that not only allow, but also expect, to be remotely controlled and reprogrammed, like the Nintendo Wii, which can communicate with the Internet even when the power is apparently turned off. This is because “off” doesn’t always mean “off”, it can mean “on standby”. Security experts advise that if users expect the Nintendo Wii to be truly off, they need to pull both the power plug and Ethernet cable. If it’s battery powered or you’re on WIFI the only way to know you are completely secure when not using the Wii is to switch off the wireless network.


Christmas Security Risk #7: Smartphones and their apps


mobile-605439_emsi


A few years ago, the European Union Agency for Network and Information Security identified the top 10 security risks for smartphone users and these pretty much remain the same today, although the popularity of apps like WhatsApp that have attracted more scammers, elevating the risk of phishing to a new high.


Here’s what we think are today’s top risks:


  1. Phishing attacks – an attacker collects user credentials (such as passwords and credit card numbers) by means of fake apps or text messages and emails that seem genuine. See our recent WhatsApp blog.

  2. The smartphone is stolen or lost and its memory or removable media are unprotected, allowing an attacker access to the data stored on it.

  3. The smartphone is decommissioned improperly allowing an attacker access to the data on the device.

  4. The smartphone has spyware installed, allowing an attacker to access another’s data but actually making them just as vulnerable. The majority of these “spy apps” are actually scams that load malware onto the would-be-spy’s phone.

Christmas Security Risk #8: Toys with microphones and cameras


android-994910_1920


Toys that contain microphones and cameras could theoretically listen in on conversations, spy on children and control home appliances without parental permission.


Google has recently patented technology that enables all of this.


 


Christmas Security Risk #9: Giving someone a hug


cat-289591_emsi


With all the risks inherent in digital gifts, why not try a non-digital gift like a “hug” this festive season? The only security risk is that you might get a hug in return! Actually, Christmas is not about giving gifts, but giving. So think about not only giving someone a hug, but also giving the gift of your own presence, spending time with your children, family and friends, instead of just buying another gadget to have them entertained.


And if we’ve completed scared you off buying a physical gift entirely and you’d rather donate money to a charity on behalf of your loved ones, then follow these precautions because scammers can take advantage of those who are trying to be generous this Christmas:


  1. Always verify that the organization is authentic and not a fake clone of a well-known charity

  2. Never donate if some unknown entity/person asks you do so by email

  3. Do a Google search to see if there are any reports that the charity is a scam, or has been targeted by scammers.

Christmas Security risk #10: Socks that aren’t made with natural fibres


socks-73925_emsi


Socks that aren’t made with wool or cotton come with their own inherent risks. You might have to open every door and window to air out the house because of bad foot odour, making you vulnerable to an old fashioned domestic burglary!


Speaking of burglaries, see our list of other cyber-related Christmas security threats below…


 


Other cyber-related security threats at Christmas


Cyber-related security threats at Christmas don’t just come neatly wrapped. It’s important to be security conscious wherever you’re shopping – whether it’s online or at a bricks and mortar store – and when you’re not home.


  1. Always remember you should NEVER send your full credit card details (name, number, expiry date and security code) by any non-encrypted channels such as email. The details must be sent exclusively via encrypted websites that use “https” instead of “http” in the website address.

  1. If you’re using a credit or debit card either in-store or online, check your bank statements regularly – even now that chip technology, which stores data on integrated circuits rather than magnetic stripes, has become the gold standard, stolen card data can still be used for fraud in situations where a card is not physically present because other people can use the stolen card details for online purchases.

  1. Many security experts also believe retailers are more at risk during the festive season. Perhaps reconsider shopping online during the Christmas peak-trading period, when DDoS traffic could be disguised as peak sales traffic and may not be identified as related to an attack.

  1. Many retailers now encouraging you to download their in-store apps, so be aware that these can also be vulnerable to attacks and security breaches. Ask questions about how your personal data will be protected. Use only the tried and tested apps – be very wary of being an early adopter in these cases. (You might also want to ensure you’ve got the latest version of Emsisoft Mobile Security installed.)

  1. With online shopping becoming more and more commonplace, never give permission for deliveries to be left outside in a visible place as it provides a clear signal to would-be burglars that nobody is home.

  1. Don’t leave discarded boxes of expensive items (e.g. TVs, tablets, desktop computers) outside the house after Christmas. They are to burglars what honey is to bees – and if a thief is trying to decide which house to break into in the street, it makes you the most obvious target.

What to do before you connect…


While unwrapping a shiny new gadget might well bring joy on Christmas day, some security experts believe the problems could really start when people try to connect such devices to their home or office networks. There have been recent reports of so-called “trojanised adware” affecting Android phones and a new iOS malware called XcodeGhost. Usually applications are not allowed to access the files created by other applications, however with root access, which is enabled by both the Android and iOS malware, those limitation are easily bypassed. A team of Security experts are concerned it is only a matter of time before sophisticated attacks can exploit the potential of mobile devices to act like a backdoor to office networks.


If you are planning on buying either yourself or someone you love a shiny new Windows computer or laptop,  it’s a good idea to invest in some solid protection. When you’ve got the latest version of Emsisoft Anti-Malware installed, you can be worry-free about malware this holiday season.


christmas-993304_emsi




Related Posts:


  • Merry Christmas from Emsisoft

  • Got a new Android for the Holidays? Malware may have come…

  • Sony got hacked (again!) – no Playstation this…

  • Emsisoft Mobile Security 1.0 released!

  • Beware of these popular WhatsApp scams




What security risks are hidden in your Christmas presents this year?

Thursday, December 3, 2015

Why we believe it’s not ethical to sell antivirus software for Windows XP any longer

A few weeks ago, Windows XP turned 14.


Have you heard about the concept of dog years? It’s based on the belief that one dog year is equivalent to seven human years. Well, there’s also a theory that one computer year equals 20 human years. When you apply the concept of dog years to computers, a 14-year-old computer would be 280 years old in human years – and it’s difficult to argue with the idea that an operating system is any different. In fact, hardware usually outlives software, which should remove all doubt that XP has passed its use-by date.


Microsoft clearly thinks so, given that it wound up support for XP in April 2014.


dog-734689_1920


Yet, according to the latest newmarketshare data, XP is still the second most popular operating system, with an 11.68% market share in October 2015. While this falls well behind current market leader Windows 7, which has 55.71% of market share, it’s still a significant number.


Only about five per cent of Emsisoft users are still running XP. While this is far fewer than the proportion still using XP in the general population (showing how savvy our customers are), we think it’s still too many. If you are still running XP or Vista, or know someone who is, read on – it could save you thousands of dollars and innumerable hours of anxiety.


 


Prepare to dodge the bullets if you’re being told you’re still protected


Old operating systems like XP and Vista are not only insecure because of their age but also because they lack several operating system kernel features that help anti-virus and anti-malware providers deliver their critical security features.


As tech writer and all-round geek Chris Hoffman says, Windows XP is the security equivalent of Swiss cheese. Not only does Microsoft no longer support XP, as of July this year, it no longer provides virus definitions and updates for its Malicious Software Removal Tool. There are new threats all the time. This year, there’s been an increase in ransomware along with a super-critical bug that opens a doorway, through an OpenType fonts vulnerability, and gives attackers full access to your PC.


7050959_s


Even with the best anti-virus or anti-malware solution in place, you’re vulnerable to attack. It’s a bit like installing a state-of-the-art home security system and then leaving all your doors and windows open when you go away for the weekend.


Put simply, it’s no longer ethical to sell antivirus software that pretends to protect XP and Vista when both lack significant security features in their core structures.


 


What have frogs got to do with XP and Vista?


You know how many developing countries leapfrog technologies and end up more equipped than some so-called developed nations? Think of Bangladesh, which has gone from having very few telephones to almost everybody owning a cell phone, skipping landline phones altogether. Some new cities in China have adopted solar power, completely bypassing fossil fuels.


One of the reasons Windows XP has remained so popular is that its successor Windows Vista was so unpopular. And even though Microsoft released Vista’s successor Windows 7 back in 2009, it took a few years to be embraced – only overtaking XP in total market share at the end of 2011.


However, if you are one of those who have been reluctant to upgrade to either Windows 7 or 8.1, it is now time to leapfrog the majority of Windows users and switch to Windows 10.


Just like these leapfrogging countries and cities, moving from XP to Windows 10 is an opportunity to skip inferior technologies and more directly to a more advanced system.


5570130_s


According to Dan Graziano at CNET, Windows 10 “isn’t like the horrors you may have heard about with Windows 8”. In fact, it isn’t all that different from Vista or XP from a visual standpoint. As well as a return to the familiar Start button and desktop interface that XP and Vista users know and love, Windows 10 offers a huge range of new features.


If you’ve heard rumours about how Windows 10 is spying on its users, check out ‘The truth about Windows 10 spying on almost everything you do’ for our detailed analysis. There are several steps you can take to maximize your privacy while using Windows 10, and we encourage you to explore these options.


And, like Emsisoft, Microsoft’s latest operating system operates as a service rather than a single product that will inevitably become obsolete. Effectively, you sign up as a customer for ongoing updates to its features and functionality. All Windows 10 devices will continue to receive updates “for the supported lifetime of the device”. In other words, it will be updated for as long as your hardware meets the specifications.


If you’re running XP or Vista, buying a license today for Windows 10 Home will cost $119 (£99). The Professional version costs $199 (£189).


Once you’ve installed Windows 10, you will be able to automatically upgrade to Emsisoft Anti-Malware and Emsisoft Internet Security version 11, which was released on 12 November and represents another leap in technology. You can find out more about the features here. As always, all customers who already own a valid Emsisoft license will receive this new version at no cost.


 


Watch your computer speed up with a new OS


If you’re worried that some of your software programs won’t run on Windows 10, a virtual machine environment (or the XP compatibility mode that’s included in Windows 10) could be the solution. This means you can keep using your XP software and hardware while at the same time knowing you’re doing so on a modern, supported, secure operating system.


Even though this is a good option, some of you may still wonder whether it would be better to buy a new PC or laptop, but that’s generally unnecessary – most people are pleasantly surprised how much faster their computer runs with a new operating system.


757417_s


However, some older machines may not be capable of running it. Basically, you will need the following:


  • Processor: 1GHz CPU or faster

  • RAM: 1GB (32-bit) or 2GB (64-bit)

  • Disk space: 16GB (32-bit) or 20GB (64-bit)

  • Graphics: DirectX 9-capable video card with WDDM driver

If your computer doesn’t meet these specifications, you may wish to consider buying a new PC or laptop.


 


The sun is setting


Emsisoft Anti-Malware 11 and Emsisoft Internet Security 11 will not run on XP and Vista, but the good news is that we will keep providing daily updates for XP and Vista users running Version 10 of our security suites until April 2016 as planned, so you have a little more time to upgrade.


Since Microsoft first announced that it was no longer backing XP back in April 2013, Emsisoft has been committed to giving our customers this decent “sunset provision”. However, even with our extended protection your Windows XP computer will still be vulnerable to an attack. If someone discovers a flaw in the operating system and decides to exploit it, Microsoft will not issue a patch.


With Windows 10 now available, is there really any good reason to delay? Consider upgrading today.


new-zealand-149_1280_crop



Related Posts:


  • Support for Windows XP and Vista will end April 2016

  • Reminder: Microsoft Ends Support for Windows XP April 8th,…

  • Emsisoft Extends Protection for Windows XP

  • Patch Tuesday: It Doesn’t Apply to Windows XP

  • Emsisoft supports Windows 10




Why we believe it’s not ethical to sell antivirus software for Windows XP any longer

Friday, October 30, 2015

20 things that can go terribly wrong when you ask the wrong peer for security advice

Millions of people every year fall victim to scams, hackers, and malware. You’ve heard it all before, right? Instead of lecturing you about the importance of security software with a lengthy essay, we decided to take the issue to the public. We hand-picked 20 of your peers and this is what they had to say on the matter:


A great-great-grand mother



A search engine



A good friend



A doctor



A neighbor



An email provider



A straight-forward-guy



A master chef



An architect



A security guard



A lonely person



An entertainer



A freeware addict



A patriot



A politician



A journalist



A surveillance firm



The big guys



A true believer



Dave



Have more? Let us have it!



Related Posts:


  • Vulnerabilities in Oracle Java Cloud Publicly Disclosed

  • Is it ethical to sell zero day exploits?

  • Top 10 senior citizen scams that affect the whole family

  • Antivirus, Anti-Malware, Anti-PUP? What is Emsisoft really?

  • When a surveillance state hacking firm gets hacked




20 things that can go terribly wrong when you ask the wrong peer for security advice

Wednesday, October 28, 2015

The strange case of malware that protects your PC

What if some secret, Internet vigilante was protecting PCs from threats? In a shroud of mystery, he would type out code in the middle of the night, a dark hoodie pulled over his face…


And load malware onto your router.


It may seem like the plot of a high-stakes thriller novel, but it’s a real-life scenario (minus, perhaps, the hoodie). The Internet security firm Symantec has reported code, named Wifatch, that attacks home routers. The twist?


Wifatch actively protects its victims from other forms of malware.


What is Wifatch?


Wifatch is a piece of code that connects routers to a peer-to-peer network of similarly infected devices. If that doesn’t sound familiar, review our post on botnet to learn about how an infection like this can turn your PC into a zombie.


The original detector of the code was an independent security researcher, L00t_myself, who noticed it on his own home router. Symantec has been following Wifatch for a while now, noting the following about the sophisticated code:


  • It is written in the Perl programming language

  • It targets following architectures: ARM (83%), MIPS (10%), and SH4 (7%)

  • It connects infected devices to a peer-to-peer network

What’s especially odd is that router infections are generally secured for pretty evil reasons. But Wifatch hasn’t delivered any kind of payload…at least, not yet.


So far, it seems, Wifatch is actually protecting systems against malware.


Wifatch is…protecting you?


Wifatch is using this botnet of infected routers to distribute threat updates and remedy malware infections, instead of issuing DDoS attacks like you would expect.


What’s more, Symantec reports that the malware is trying to harden the infected devices. It even tells owners when to change passwords or update firmware. In a sense, Wifatch is fighting fire with fire – or malware with malware.


messagewifatch

Wifatch seems suspiciously helpful. Source: Symantec



But the plot thickens. The creator of Wifatch reached out to Symantec, and was subsequently interviewed for their blog. He admits that while he has no malicious intentions, Wifatch could have an exploitable bug or someone could steal the key.



Can I trust you to not do evil things with my devices?


Yes, but that is of no help – somebody could steal the key, no matter how well I protect it. More likely, there is a bug in the code that allows access to anybody.



So ultimately, even if the creator of the code has good intentions, your PC is at risk for a malicious payload as a result of Wifatch.


The bottom line


While Wifatch is very interesting malware, it isn’t one you should be trying to contract. The reality is, a secure PC wouldn’t have Wifatch to begin with. You wouldn’t like it if a superhero was hiding in your house all the time just in case someone broke in. It’s still an invasion of your privacy, so Wifatch is ultimately malware.


Remember to have a secure anti-malware program and to create complex passwords. As the creator of Wifatch himself said:



Linux.Wifatch doesn’t use elaborate backdoors or 0day exploits to hack devices. It basically just uses telnet and a few other protocols and tries a few really dumb or default passwords (our favourite is “password”). These passwords are well-known – anybody can do that, without having to steal any secret key.


Basically it only infects devices that are not protected at all in the first place!



Have a great, vigilante-free day!









  • Related Posts:


    • Firmware Vulnerabilities Discovered on Linksys and ASUS…

    • Exploit kit attacks DNS settings of over 50 different router

    • NetUSB hack puts Millions of home users at risk

    • IRC botnets have evolved to steal passwords and avoid…

    • Hacker group LizardSquad used home routers to attack Xbox…




    The strange case of malware that protects your PC

Wednesday, October 21, 2015

What’s the deal with protection vs cleaning?

Ever wonder why you need to have protection when you can just use a removal tool if you get a virus? This video aims to help you realize the importance of real-time protection through several examples and demonstrations.


Malware is dangerous – don’t forget that it can permanently destroy or encrypt your files. If you read our previous article on cleaning vs protection, you know how important it is to stop malware in its tracks. Luckily, our video producer Leo walks you through how Emsisoft Anti-Malware can prevent infection in the first place. It’s a great way to recap this importatn topic and see protection in action.



Have a great, infection-free day!



Related Posts:


  • Innovations to Emsisoft Anti-Malware 8.1

  • Cleaning vs. Protection – Why you shouldn’t rely

  • Warning: File Encrypting Ransomware, Now on Android

  • CryptoWall Malvertisments on Yahoo, AOL, Match.com and More

  • Emsisoft Runs 4 month Malware Protection Marathon at…




What’s the deal with protection vs cleaning?

Tuesday, October 6, 2015

Why every Android user should take the Stagefright leak very seriously

A vulnerability in Android called Stagefright was exposed at the 2015 Black Hat conference in early August. You may have heard of it, if only because the media frenzy that followed claimed that hundreds of millions of phones could be hacked with a single text – but is any of that true? If that were the case, surely Google, the developer of the popular operating system, would have fixed it by now…right?


(image: pocket-lint.com)

(image: pocket-lint.com)



 


What is Stagefright and why should you care?


You may have grown accustomed to all of the vulnerabilities, bug and alerts out there in technology land. You’re calm because you know that ultimately there will be a patch to fix it, right?


Unfortunately, it’s not so simple with the Stagefright leak. Think of a doomsday film where a deadly asteroid is about to strike Earth, and there’s no way for scientists to divert it with their fancy technology. That’s basically what’s going on – the Stagefright bug, due to the nature of the Android world, isn’t likely to be addressed any time soon. If things don’t change, it’s only a matter of time before an exploit strikes and brings chaos to an unthinkable number of devices.


So, yes, it is possible that you could receive a strange video text, not even open it, and some cyber criminal halfway around the world could start spying on you through your video camera. But that’s only one possibility.


If a hacker gets into your device through the Stagefright vulnerability, he could gain access to your address book, apps, message history, personal emails, and all the information tied to your Google account. This means that every bit of information tied to your Google account – from Gmail to Google Drive – is up for grabs: financial information, browsing history, personal messages and classified work documents…


It’s imperative you understand that your phone isn’t the only thing at risk. Your whole digital life is at risk.


How does Android work, exactly?


To understand the Stagefright vulnerability properly, it’s important to look at the Android architecture. Android is very modular operating system, so things run in separate processes. This is in part thanks to the Dalvik virtual machine, which is the component in most Android phones (it has been replaced entirely by Android runtime in Android 5.0) that allows each app to run separately and independent of the Linux kernel. This keeps apps from detrimentally interfering with each other or with the operating system.


android_appsThis means program processes rely on IPC or inter-process communications to work together. This is known as application sandboxing (or application containerization), and one of the alleged advantages of this is that keeping applications isolated improves overall security.


Stagefright is what processes media in Android’s MediaServer, written primarily in C++. It handles all video and audio files, and provides playback facilities. It also extracts metadata for the Gallery (like thumbnails or dimensions of a video).


How Stagefright reaches you


So it might be fair to assume that since the programs on your phone are sandboxed, most aspects of the system are safe from a single vulnerability. But while the compartmentalized nature of Android is supposed to keep programs from interfering, MediaServer is a very privileged service that has access to audio, bluetooth, camera, internet, and more. What’s worse, many phone manufacturers have given the Stagefright component system permissions on their devices, which is only a step below root access.


In layman’s terms: a hacker could gain access to your entire device.


An attacker only needs your phone number to conduct a successful hack. He or she could remotely execute code through a video sent via MMS. It would require no action on your part, as Android phones are set to preload videos. The attacker can even delete the message after sending it, leaving you with little more than a mysterious notification.


If that doesn’t sound horrifying enough, that isn’t the worst of it. The reality is, that’s just one way that the vulnerability can be exploited. It’s up to the hackers of the world to discover the rest.


Who figured this out?


Joshua J. Drake, an Android security expert, is the man behind the research. He is the Senior Director of Platform Research at Zimperium Enterprise Mobile Security, and the Author of “Android Hacker’s Handbook”. He’s also the founder of the #droidsec research group, an Android-focused research community.


With the support of Zimperium and Optiv, Drake conducted this security research, using his “droid army” – a collection of 51 Android devices. You can learn more about how he conducted his research in his presentation at the Black Hat conference in Las Vegas.


A fragmented Android world


Android is one of the world’s most popular operating systems and it has a unique story. The rate of development is incredibly fast, but that development doesn’t come without a price. Since original equipment manufacturers and carriers are able to adapt the operating system due to its open source nature, this leads to a number of iterations that have unique update and patching needs – over 24,000 models currently exist in the Android ecosystem.


The biggest problem with this vulnerability, as Ars Technica writer Ron Amadeo points out, is that original equipment manufacturers have been able to adapt the Android code to work with their devices. This creates a dilemma where an unthinkable amount of patches would have to be made in order to successfully protect the majority of Android phones out there, and no single company, team, or entity is responsible for getting this issue under control. Because updates will focus on newer phones, and many patches will be dependent upon a myriad of manufacturers and carriers to distribute them, it is possible that millions to hundreds of millions of devices will remain vulnerable indefinitely.


What’s being done?


Google, as well as number of manufacturers and carriers have responded with patches for the following devices.


Zimperium has also launched its ZHA Alliance to address the issue of communication between relevant manufacturers and carriers on the issue. As Zimperium so aptly stated, “According to our understanding of the Android ecosystem, security issues reported to Google are only shared with active partners”.


Zimperium has also released an app known as the Stagefright Detection app, which can help you identify if your phone is actually affected by the vulnerability.


So what’s the problem?


You might think that since the patches are rolling out, there shouldn’t be any further problems. Surely the patches will trickle down to older phones, and Zimperium will help facilitate that communication between Google, carriers, and manufacturers


Even if that is the case and the majority of phones get patched up, there may be an issue with the effectiveness of Google’s first patch. Security researcher Jordan Gruskovnjak at Exodus Intelligence has reported that the initial patch released by Google was inadequate. The Exodus team was able to craft an MP4 that could bypass the patch. They even claim that Zimperium’s Stagefright Detection app will green-light your patched phone, even though it’s still vulnerable.


Google has responded to the situation, asserting in a statement to The Verge, “We’ve already sent the fix to our partners to protect users, and Nexus 4/5/6/7/9/10 and Nexus Player will get the OTA update in the September monthly security update”.


If that wasn’t bad enough, Rob Miller from MWR Labs has found another vulnerability that can bypass the sandbox mechanism. Originally reported back in March, it seems that Google has yet to release a relevant patch. Researchers at Trend Micro have claimed to have also found a vulnerability, this time in Android MediaServer, which they reported to Google back in June (Google published a fix in early August).


The reality is, even if Google’s next patch is effective it doesn’t address the full story. The Stagefright media circus simply revealed a can of worms that opened long ago – Android has some major security flaws, and the broken chain of distributors and manufacturers makes it nearly impossible to rectify.


What you can do


If you have an Android phone with version 2.2 or higher, it may seem that there isn’t much left in your control. But we encourage you to do all you can to take security into your own hands.


While it’s true that there are limits to your autonomy in the face of all of the vulnerabilities your phone could be riddled with, there are several steps you can take to make your experience on Android safer. Even if you don’t have an Android phone, you can use these tips and apply them to your own smartphone experience.


Change your settings


It’s important to acknowledge that while Zimperium illustrated an exploit through MMS and that’s what the media has held onto, this is just an example of how the vulnerability can be exploited, so disabling auto-retrieval will not necessarily protect you from all possible hacks. Joshua J. Drake himself said at the Black Hat conference that the Stagefright bug is exposed via multiple attack vectors.


With that being said, the MMS attack has been receiving a lot of attention, and it’s possible that cyber criminals are getting ideas. So it’s best to deactivate auto-retrieval as it preloads videos and messages for you. Here is how to disable the auto-retrieval feature on the most common messaging applications:


Google Hangout


Open the app and select Settings by tapping the three horizontal lines in the top left corner. Click the Settings wheel and then select SMS. Uncheck Auto-retrieve MMS.


hangout_zimperium

Source: Zimperium



WhatsApp


Select Settings by clicking the three dots icon, and then select Chat Settings. Tap Media auto-download and go to the When connected on Wi-Fi. Deselect videos, and then do the same under the When using mobile data option.



whatsapp_en2whatsapp_en5whatsapp_en1


cleaning-px


Google Messenger


Touch the three vertical dot icon in the upper right corner. Select Settings and then Advanced. Then deselect Auto-retrieve.


Messanger_Lookout3

Source: Lookout



Messanger_Lookout4


 


 


 


 


 


 


 


 


 


 


 


 


 


Messages


Navigate to More and select Settings, then More settings. Click Multimedia messages and then slide the Auto retrieve toggle to the left.


samsung_zimperium1

Source: Zimperium



samsung_zimperium-730x643

Source: Zimperium



Even after deactivating auto-retrieval, be wary of manually loading an MMS from an unknown source, and if you want to be extra safe, don’t load one from friends or family either. They can unknowingly put you at risk if their phone is compromised.


Your consumer choices


While most normal people don’t have the resources to buy the latest and greatest model of every device, it’s important to consider the likelihood that future devices will be more secure than current models. Additionally, important security patches and updates generally won’t be released to devices that can’t support newer versions of Android.


Remember to educate yourself on the operating systems and programs you use, and vigilantly update to newer versions if possible. For example, the Mozilla Firefox browser was also affected by the Stagefright vulnerability, but the issue has been rectified since version 38.


Make your voice heard


Just because the mainstream media has dropped the issue as of late doesn’t mean the Stagefright bug doesn’t affect millions of people around the globe. Voice your own concerns and demand that your carrier keep you updated on the issue.


Make noise on your social media channels and tag Google, your carrier, and your manufacturer in your posts. Forward articles related to the Stagefright issue to your Android-using loved ones.


Switch your operating system


This is an option for more experienced users and not a recommendation for most people. Still, it is an option and should be discussed with more regularity. If your inclined to try this option, consider using firmware with a regularly updated ROM, such as CyanogenMod.


You will need to root your phone, and if you do this you will most likely lose your warranty with your manufacturer. Also be aware that this move will not make you 100% clear of the Stagefright vulnerability or other bugs. The advantage is that you have an Android device, but the hassle of waiting on manufacturers and carriers to adapt patches is removed, and you can receive updates more immediately.


As the months go by, we can only hope that there is a real solution to this issue. Remember to stay informed about security updates, subscribe to newsletters, and follow security blogs. Talk to your friends and family, and assert your rights to privacy and safety as a consumer. While developments in technology move at an impressive rate, there’s no point in having all of these fancy devices if we’re moving towards a digital Armageddon. Remember, safety is just as important as progress.


Have a great, exploit-free day!



Related Posts:


  • Alert! Default Browser app on 75% of Androids is vulnerable

  • ALERT: Fake ID Lets Malware Impersonate Legit Android Apps

  • The end of FREAK: Massive SSL vulnerability finally patched

  • Installer hijack vulnerability threatens almost half of all…

  • Ransomware hacks Android’s front-facing camera to take




Why every Android user should take the Stagefright leak very seriously