Security

Another EUSecWest NFC Trick: Ride the Subway For Free 135

itwbennett writes "At the EUSecWest security conference in Amsterdam, researchers showed how their 'UltraReset' Android app can read the data from a subway fare card, store that information, and reset the card to its original fare balance. The researchers said that the application takes advantage of a flaw found in particular NFC-based fare cards that are used in New Jersey and San Francisco, although systems in other cities, including Boston, Seattle, Salt Lake City, Chicago and Philadelphia, could also be vulnerable."
Android

Android Hacked Via NFC On the Samsung Galaxy S 3 198

An anonymous reader writes with an item from The Next Web: "Security researchers participating in the Mobile Pwn2Own contest at the EuSecWest Conference in Amsterdam [Wednesday] demonstrated how to hack Android through a Near Field Communication (NFC) vulnerability. The 0day exploit was developed by four MWR Labs employees (two in South Africa and two in the UK) for a Samsung Galaxy S 3 phone running Android 4.0.4 (Ice Cream Sandwich). Two separate security holes were leveraged to completely take over the device, and download all the data from it."
Encryption

Private Key Found Embedded In Major SCADA Equipment 105

sl4shd0rk writes "RuggedOS (A Siemens Subsidiary of Flame and Stuxnet fame), an operating system used in mission-critical hardware such as routers and SCADA gear, has been found to contain an embedded private encryption key (PDF). Now that all affected RuggedCom devices are sharing the same key, a compromise on one device gets you the rest for free. If the claims are valid, systems in use which would be affected include U.S. Navy, petroleum giant Chevron, and the Wisconsin Department of Transportation. The SCADA gear which RuggedOS typically runs on is often connected to machinery controlling electrical substations, traffic control systems, and other critical infrastructure. This is the second security nightmare for RuggedCom this year, the first being the discovery of a backdoor containing a non-modifiable account."
Bug

ICS-CERT Warns of Serious Flaws In Tridium SCADA Software 34

Trailrunner7 writes "The DHS and ICS-CERT are warning users of some popular Tridium Niagara AX industrial control system software about a series of major vulnerabilities in the applications that are remotely exploitable and could be used to take over vulnerable systems. The bugs, discovered by researchers Billy Rios and Terry McCorkle, are just the latest in a series of vulnerabilities found in the esoteric ICS software packages that control utilities and other critical systems. The string of bugs reported by Rios and McCorkle include a directory traversal issue that gives an attacker the ability to access files that should be restricted. The researchers also discovered that the Niagara software stores user credentials in an insecure manner. There are publicly available exploits for some of the vulnerabilities."
Cellphones

Alternative To QR Code Uses NFC and Cheap Rectennas 164

An anonymous reader writes "The BBC reports researchers in Korea have developed a technology that can be used as a viable alternative to QR codes. Made of plastic and electronic ink, the rectennas cost less than one penny each to produce and use the NFC standards for wireless radio communication to devices. They are seen as a cheap, easy-to-print and environmentally friendly way to overcome the limitations and inconvenience of QR codes, the usage of which has greatly increased in the last few years."
Cellphones

Did Apple Buy Fingerprint Security Firm For Mobile Wallet? 35

Hugh Pickens writes "Reuters reports that Apple will buy fingerprint sensor technology developer AuthenTec for about $356 million, striking a deal that could help Apple bring fingerprint technology, already used in mobile phones in Japan for authentication of mobile payments, to markets such as the United States, where mobile-wallet services have been slow to catch on. Some analysts expect the iPhone 5 to include some form of mobile payments technology. 'In the past 5 years, the growth of iPhone and Android smartphones has made mobile data security essential, not just a "nice-to-have" feature,' says Ben Yu, Managing Director of Sierra Ventures, one of the early investors in AuthenTec. 'People have their whole lives on the phones.' AuthenTec's embedded fingerprint scanners and other identity-related software is particularly useful now that Near Field Communications, or NFC-enabled, phones have begun to appear in the market. Analyst Colin Gillis says AuthenTec technology could potentially also help Apple combat problems such as theft of its more portable products such as iPhones. 'If they could have a way where they could tie the phone to a user more tightly, that would make sense for them,' says Gillis. The price tag for AuthenTec is a drop in the bucket of Apple's cash pile of $117.2 billion. 'We'll see if it's a one-off or if Tim Cook will start to level his cash balance and acquire talent,' adds Gillis."
Security

Researcher Wows Black Hat With NFC-based Smartphone Hacking Demo 95

alphadogg writes "At the Black Hat Conference in Las Vegas Wednesday, Accuvant Labs researcher Charlie Miller showed how he figured out a way to break into both the Google/Samsung Nexus S and Nokia N9 by means of the Near Field Communication (NFC) capability in the smartphones. NFC is still new but it's starting to become adopted for use in smartphone-based purchasing in particular. The experimentation that Miller did, which he demonstrated at the event, showed it's possible to set up NFC-based radio communication to share content with the smartphones to play tricks, such as writing an exploit to crash phones and even in certain circumstances read files on the phone and more."
Security

Apple Hacker Charlie Miller To Demo Dangers of Near-Field Communications 149

An anonymous reader writes "Apple's hacker nemesis Charlie Miller, who the company banned from its app store developer program, apparently hasn't been waiting around for his suspension to be lifted. His latest pet project is hacking near-field communications (NFC), and at Black Hat USA in Vegas this month, he will demonstrate the dangers of using your smartphone to pay your cab fare. (But when his Apple 'sentence' is up, look out)."
IOS

New iPhone Prototypes Have Integrated NFC chips and Antenna 114

zacharye writes "Apple's next-generation iPhone will feature an integrated NFC chip according to a new report, suggesting the Cupertino, California-based company may soon make its entrance into the mobile payment space. A report from 9to5Mac states that an analysis of code from Apple's latest iOS software includes references to an integrated NFC chip and antenna."
Crime

Android App Lets You Steal Contactless Credit Card Data 221

mask.of.sanity writes "An Android application capable of siphoning credit card data from contactless bank cards has appeared on the Google Play store. The app was developed by a security penetration tester for research purposes and will steal card numbers and expiry dates, along with transactions and merchant IDs. It requires a near field device capable phone, or accessory."
Security

New York City Pushes Plan To Prevent Cyberattacks On Elevators, Boilers 171

coondoggie writes "Imagine what would happen if an attacker broke into the network for the industrial control systems for New York City's elevators and boiler systems and decided to disrupt them, imperiling the lives of hundreds of thousands of residents relying on them. Think it could never happen? Think again. 'You could increase the speed of how elevators go up or down,' says Steve Ramirez, business analyst, analysis and communications in the Office of the CIO of the New York City Housing Authority, which provides public housing for low- to moderate-income families in the five boroughs of the city. And if attackers ever successfully penetrated the network-based industrial control systems for the boilers, they could raise the heat levels for municipal boilers, causing them to explode." Maybe Bruce Schneier could run a new movie-scenario contest about ways this could play out.
Security

DHS Asked Gas Pipeline Firms To Let Attackers Lurk Inside Networks 114

wiredmikey writes "According to reports, which were confirmed Friday by ICS-CERT (PDF), there has been an active cyber attack campaign targeting the natural gas industry. However, it's the advice from the DHS that should raise some red flags. 'There are several intriguing and unusual aspects of the attacks and the U.S. response to them not described in Friday's public notice,' Mark Clayton wrote. 'One is the greater level of detail in these alerts than in past alerts. Another is the unusual if not unprecedented request to leave the cyber spies alone for a little while.' According to the source, the companies were 'specifically requested in a March 29 alert not to take action to remove the cyber spies if discovered on their networks, but to instead allow them to persist as long as company operations did not appear to be endangered.' While the main motive behind the request is likely to gain information on the attackers, letting them stay close to critical systems is dangerous. The problem lies in the complexities of our critical infrastructures and the many highly specialized embedded systems that comprise them."
Patents

Nest Labs Calls Honeywell Lawsuit 'Worse Than Patent Troll' 137

UnknowingFool writes "Over a year ago, Nest Labs launched the Learning Thermostat. The brainchild of Tony Fadell, former head of Apple's iPod and iPhone division, the Learning Thermostat promised a self-programming and wifi-enabled thermostat that would save energy costs. After some glowing reviews, Nest found itself in a patent infringement lawsuit against Honeywell. Nest responded with multiple claims calling Honeywell 'worse than a patent troll.' Among Nest's claims: Honeywell hid prior art (some on some previous patents that they owned) and inapplicable patents (patent on mechanical potentiometer when Nest's product does not include one). Nest's stance is that Honeywell filed the lawsuits not to extract money but to set back progress so that they can control the industry."
Microsoft

End of Windows XP Support Era Signals Beginning of Security Nightmare 646

colinneagle writes "Microsoft's recent announcement that it will end support for the Windows XP operating system in two years signals the end of an era for the company, and potentially the beginning of a nightmare for everyone else. When Microsoft cuts the cord on XP in two years it will effectively leave millions of existing Windows-based computers vulnerable to continued and undeterred cyberattacks, many of which hold the potential to find their way into consumer, enterprise and even industrial systems running the latest software. Although most of the subsequent security issues appear to be at the consumer level, it may not be long until they find a way into corporate networks or industrial systems, says VMWare's Jason Miller. Even scarier, Qualsys's Amol Sarwate says many SCADA systems for industrial networks still run a modified version of XP, and are not in a position to upgrade. Because much of the software running on SCADA systems is not compatible with traditional Microsoft OS capabilities, an OS upgrade would entail much more work than it would for a home or corporate system."
Input Devices

Reinventing the Clapper With a Knock-Based Home Automation Controller 92

An anonymous reader writes with a snippet from Hack a Day: "Clap On! Clap Off! was super awesome when The Clapper came out in the mid-eighties. Now [Mathieu Stephan] is trying to make the concept much more functional. He put together a controller that lets you knock on walls to control things around the house. It's called the Toktoktok project and uses small boxes to receive user input and control items like lamps and computers." As the project website points out, Stephan is keeping the project intentionally open.
Iphone

Apple Wins Patent For "iWallet" 176

redletterdave writes "Apple won a major patent for its 'iWallet' technology, which is a digital system that uses near-field communication (NFC) technology to complete credit card transactions and manage subsidiary financial accounts directly on your iPhone. On the home screen for iWallet, users can see their entire credit card profiles, statements, messages from their banks, and even adjust preferences or add additional cards. Within preferences, users can schedule credit card payments and set parental controls on their children, which allows kids to use their iPhones as wallets but limits the extent to which they can use it. Users can track their payments and statements within the iTunes billing system, which keeps the credit card information safe and secure."
Nintendo

Iwata Confirms Nintendo Network, New Wii U Controller Functions 111

New submitter DeanCubed writes "In a Nintendo investor meeting, CEO Satoru Iwata confirmed a new Nintendo Network for the company's 3DS and upcoming Wii U game systems. This includes multiple user accounts per console (not tied to hardware, a first for Nintendo) and digitally distributed retail software releases for their online store. Iwata also noted that the Wii U's tablet controller will feature NFC (Near Field Communication) functionality, allowing the ability to use figurines and cards to input visual data to the console. They are hoping to use this to make micro-transactions for paid DLC easier."
Security

Researchers Find Slew of Flaws In SCADA Hardware, Software 110

Trailrunner7 writes "At the S4 security conference this week, 'Project Basecamp,' a volunteer-led security audit of leading programmable logic controllers (PLCs), performed by a team of top researchers found that decrepit hardware, buggy software and pitiful or nonexistent security features make thousands of PLCs vulnerable to trivial attacks by external hackers that could cause PLC devices to crash or run malicious code. 'We were looking for a Firesheep moment in PLC security,' Peterson told the audience of ICS security experts. They got one. 'It's a blood bath mostly,' said Wightman of Digital Bond. 'Many of these devices lack basic security features.' While the results of analysis of the various PLCs varied, the researchers found significant security issues with every system they tested, with some PLCs too brittle and insecure to even tolerate security scans and probing."
Open Source

Adafruit's Open-source Wearable Platform, Flora 62

ptorrone writes "Limor 'Ladyada' Fried's NYC based Open-source electronics studio, Adafruit, today announced their new open wearable platform called the FLORA (blog post & video). The FLORA is Arduino compatible as well as supporting a variety of sensors and add-on devices including: Bluetooth, GPS, 3-axis accelerometer, compass module, flex sensor, piezo, IR LED, push button, embroidered + capacitive keypad, OLED and more. The first round of hardware is in the hands of testers to create wearable projects."
Security

SCADA Vulnerabilities In Prisons Could Open Cell Doors 134

Orome1 writes "Many prisons and jails use SCADA systems with PLCs to open and close doors. Using original and publicly available exploits along with evaluating vulnerabilities in electronic and physical security designs, researchers discovered significant vulnerabilities in PLCs used in correctional facilities by being able to remotely flip the switches to 'open' or 'locked closed' on cell doors and gates."

Slashdot Top Deals