Security

Researcher Wows Black Hat With NFC-based Smartphone Hacking Demo 95

alphadogg writes "At the Black Hat Conference in Las Vegas Wednesday, Accuvant Labs researcher Charlie Miller showed how he figured out a way to break into both the Google/Samsung Nexus S and Nokia N9 by means of the Near Field Communication (NFC) capability in the smartphones. NFC is still new but it's starting to become adopted for use in smartphone-based purchasing in particular. The experimentation that Miller did, which he demonstrated at the event, showed it's possible to set up NFC-based radio communication to share content with the smartphones to play tricks, such as writing an exploit to crash phones and even in certain circumstances read files on the phone and more."
Security

Apple Hacker Charlie Miller To Demo Dangers of Near-Field Communications 149

An anonymous reader writes "Apple's hacker nemesis Charlie Miller, who the company banned from its app store developer program, apparently hasn't been waiting around for his suspension to be lifted. His latest pet project is hacking near-field communications (NFC), and at Black Hat USA in Vegas this month, he will demonstrate the dangers of using your smartphone to pay your cab fare. (But when his Apple 'sentence' is up, look out)."
IOS

New iPhone Prototypes Have Integrated NFC chips and Antenna 114

zacharye writes "Apple's next-generation iPhone will feature an integrated NFC chip according to a new report, suggesting the Cupertino, California-based company may soon make its entrance into the mobile payment space. A report from 9to5Mac states that an analysis of code from Apple's latest iOS software includes references to an integrated NFC chip and antenna."
Crime

Android App Lets You Steal Contactless Credit Card Data 221

mask.of.sanity writes "An Android application capable of siphoning credit card data from contactless bank cards has appeared on the Google Play store. The app was developed by a security penetration tester for research purposes and will steal card numbers and expiry dates, along with transactions and merchant IDs. It requires a near field device capable phone, or accessory."
Security

New York City Pushes Plan To Prevent Cyberattacks On Elevators, Boilers 171

coondoggie writes "Imagine what would happen if an attacker broke into the network for the industrial control systems for New York City's elevators and boiler systems and decided to disrupt them, imperiling the lives of hundreds of thousands of residents relying on them. Think it could never happen? Think again. 'You could increase the speed of how elevators go up or down,' says Steve Ramirez, business analyst, analysis and communications in the Office of the CIO of the New York City Housing Authority, which provides public housing for low- to moderate-income families in the five boroughs of the city. And if attackers ever successfully penetrated the network-based industrial control systems for the boilers, they could raise the heat levels for municipal boilers, causing them to explode." Maybe Bruce Schneier could run a new movie-scenario contest about ways this could play out.
Security

DHS Asked Gas Pipeline Firms To Let Attackers Lurk Inside Networks 114

wiredmikey writes "According to reports, which were confirmed Friday by ICS-CERT (PDF), there has been an active cyber attack campaign targeting the natural gas industry. However, it's the advice from the DHS that should raise some red flags. 'There are several intriguing and unusual aspects of the attacks and the U.S. response to them not described in Friday's public notice,' Mark Clayton wrote. 'One is the greater level of detail in these alerts than in past alerts. Another is the unusual if not unprecedented request to leave the cyber spies alone for a little while.' According to the source, the companies were 'specifically requested in a March 29 alert not to take action to remove the cyber spies if discovered on their networks, but to instead allow them to persist as long as company operations did not appear to be endangered.' While the main motive behind the request is likely to gain information on the attackers, letting them stay close to critical systems is dangerous. The problem lies in the complexities of our critical infrastructures and the many highly specialized embedded systems that comprise them."
Patents

Nest Labs Calls Honeywell Lawsuit 'Worse Than Patent Troll' 137

UnknowingFool writes "Over a year ago, Nest Labs launched the Learning Thermostat. The brainchild of Tony Fadell, former head of Apple's iPod and iPhone division, the Learning Thermostat promised a self-programming and wifi-enabled thermostat that would save energy costs. After some glowing reviews, Nest found itself in a patent infringement lawsuit against Honeywell. Nest responded with multiple claims calling Honeywell 'worse than a patent troll.' Among Nest's claims: Honeywell hid prior art (some on some previous patents that they owned) and inapplicable patents (patent on mechanical potentiometer when Nest's product does not include one). Nest's stance is that Honeywell filed the lawsuits not to extract money but to set back progress so that they can control the industry."
Microsoft

End of Windows XP Support Era Signals Beginning of Security Nightmare 646

colinneagle writes "Microsoft's recent announcement that it will end support for the Windows XP operating system in two years signals the end of an era for the company, and potentially the beginning of a nightmare for everyone else. When Microsoft cuts the cord on XP in two years it will effectively leave millions of existing Windows-based computers vulnerable to continued and undeterred cyberattacks, many of which hold the potential to find their way into consumer, enterprise and even industrial systems running the latest software. Although most of the subsequent security issues appear to be at the consumer level, it may not be long until they find a way into corporate networks or industrial systems, says VMWare's Jason Miller. Even scarier, Qualsys's Amol Sarwate says many SCADA systems for industrial networks still run a modified version of XP, and are not in a position to upgrade. Because much of the software running on SCADA systems is not compatible with traditional Microsoft OS capabilities, an OS upgrade would entail much more work than it would for a home or corporate system."
Input Devices

Reinventing the Clapper With a Knock-Based Home Automation Controller 92

An anonymous reader writes with a snippet from Hack a Day: "Clap On! Clap Off! was super awesome when The Clapper came out in the mid-eighties. Now [Mathieu Stephan] is trying to make the concept much more functional. He put together a controller that lets you knock on walls to control things around the house. It's called the Toktoktok project and uses small boxes to receive user input and control items like lamps and computers." As the project website points out, Stephan is keeping the project intentionally open.
Iphone

Apple Wins Patent For "iWallet" 176

redletterdave writes "Apple won a major patent for its 'iWallet' technology, which is a digital system that uses near-field communication (NFC) technology to complete credit card transactions and manage subsidiary financial accounts directly on your iPhone. On the home screen for iWallet, users can see their entire credit card profiles, statements, messages from their banks, and even adjust preferences or add additional cards. Within preferences, users can schedule credit card payments and set parental controls on their children, which allows kids to use their iPhones as wallets but limits the extent to which they can use it. Users can track their payments and statements within the iTunes billing system, which keeps the credit card information safe and secure."
Nintendo

Iwata Confirms Nintendo Network, New Wii U Controller Functions 111

New submitter DeanCubed writes "In a Nintendo investor meeting, CEO Satoru Iwata confirmed a new Nintendo Network for the company's 3DS and upcoming Wii U game systems. This includes multiple user accounts per console (not tied to hardware, a first for Nintendo) and digitally distributed retail software releases for their online store. Iwata also noted that the Wii U's tablet controller will feature NFC (Near Field Communication) functionality, allowing the ability to use figurines and cards to input visual data to the console. They are hoping to use this to make micro-transactions for paid DLC easier."
Security

Researchers Find Slew of Flaws In SCADA Hardware, Software 110

Trailrunner7 writes "At the S4 security conference this week, 'Project Basecamp,' a volunteer-led security audit of leading programmable logic controllers (PLCs), performed by a team of top researchers found that decrepit hardware, buggy software and pitiful or nonexistent security features make thousands of PLCs vulnerable to trivial attacks by external hackers that could cause PLC devices to crash or run malicious code. 'We were looking for a Firesheep moment in PLC security,' Peterson told the audience of ICS security experts. They got one. 'It's a blood bath mostly,' said Wightman of Digital Bond. 'Many of these devices lack basic security features.' While the results of analysis of the various PLCs varied, the researchers found significant security issues with every system they tested, with some PLCs too brittle and insecure to even tolerate security scans and probing."
Open Source

Adafruit's Open-source Wearable Platform, Flora 62

ptorrone writes "Limor 'Ladyada' Fried's NYC based Open-source electronics studio, Adafruit, today announced their new open wearable platform called the FLORA (blog post & video). The FLORA is Arduino compatible as well as supporting a variety of sensors and add-on devices including: Bluetooth, GPS, 3-axis accelerometer, compass module, flex sensor, piezo, IR LED, push button, embroidered + capacitive keypad, OLED and more. The first round of hardware is in the hands of testers to create wearable projects."
Security

SCADA Vulnerabilities In Prisons Could Open Cell Doors 134

Orome1 writes "Many prisons and jails use SCADA systems with PLCs to open and close doors. Using original and publicly available exploits along with evaluating vulnerabilities in electronic and physical security designs, researchers discovered significant vulnerabilities in PLCs used in correctional facilities by being able to remotely flip the switches to 'open' or 'locked closed' on cell doors and gates."
Security

Was Russia Behind Stuxnet? 281

An anonymous reader writes "Despite the U.S. and Israel being widely assumed to be responsible for Stuxnet, Russia is the more likely culprit, says U.S. Air Force cyber analyst. The nuclear gangsterism of the past 20 years gives it plenty of motive. Quoting: 'So what better way to maintain Russian interests, and innocence, than to plant a worm with digital U.S.-Israeli fingerprints? After all, Russian scientists and engineers are familiar with the cascading centrifuges whose numbers and configuration – and Siemen’s SCADA PLC controller schematics – they have full access to by virtue of designing the plants. ... the observers of the virus could alert the Iranians before full nuclear catastrophe struck. The Belarusian computer security experts who 'discovered' the code seemingly played that role well. They didn't seem too preoccupied with reverse engineering the malicious code to see what it was designed to do.'"
Security

SCADA Hacker: Water District Used 3-Character Password 213

Trailrunner7 writes "In an e-mail interview with Threatpost, a hacker who compromised software used to manage water infrastructure for South Houston, Texas, said the district had HMI (human machine interface) software used to manage water and sewage infrastructure accessible to the Internet and used a password that was just three characters long. The hacker, using the handle 'pr0f' took credit for a remote compromise of supervisory control and data acquisition (SCADA) systems. Communicating from an e-mail address tied to a Romanian domain, the hacker told Threatpost that he discovered the vulnerable system using a scanner that looks for the online fingerprints of SCADA systems. 'This was barely a hack. A child who knows how the HMI that comes with Simatic works could have accomplished this,' he wrote in an e-mail."
Cellphones

Making Sensitive Data Location Aware 69

An anonymous reader writes "In a breakthrough that could aid spies, keepers of medical records, and parents who want to prevent their kids from 'sexting,' a team of Virginia Tech researchers has created software to remotely put smart phones under lockdown. The phones are given permission to access sensitive data while in a particular room, but when the devices leave the room, the data is completely wiped. A general, for example, could access secret intelligence while visiting a secure government facility without fear that his or her smart phone or tablet computer might later be lost or stolen, the team's lead researcher said. 'This system provides something that has never been available before. It puts physical boundaries around information in cyberspace.'" Unless the phone or other device can also take screenshots, or doesn't have that software installed.
Bug

SCADA Problems Too Big To Call 'Bugs,' Says DHS 92

chicksdaddy writes "With the one year anniversary of Stuxnet upon us, a senior cybersecurity official at the Department of Homeland Security says the agency is reevaluating whether it makes sense to warn the public about all of the security failings of industrial control system (ICS) and SCADA software used to control the U.S.'s critical infrastructure. DHS says it is rethinking the conditions under which it will use security advisories from ICS-CERT to warn the public about security issues in ICS products. The changes could recast certain kinds of vulnerabilities as 'design issues' rather than a security holes. No surprise: independent ICS experts like Ralph Langner worry that DHS is ducking responsibility for forcing changes that will secure the software used to run the nation's critical infrastructure. 'This radically cuts the amount of vulnerabilities in the ICS space by roughly 90%, since the vast majority of security "issues" we have are not bugs, but design flaws,' Langner writes on his blog. 'So today everybody has gotten much more secure because so many vulnerabilities just disappeared.'"
Security

Italian Hacker Publishes 0day SCADA Hacks 106

mask.of.sanity writes "An Italian security researcher, Luigi Auriemma, has disclosed a laundry list of unpatched vulnerabilities and detailed proof-of-concept exploits that allow hackers to completely compromise major industrial control systems. The attacks work against six SCADA systems, including one manufactured by U.S. giant Rockwell Automation. The researcher published step-by-step exploits that allowed attackers to execute full remote compromises and denial of service attacks. Auriemma appeared unrepentant for the disclosures in a post on his website."
Security

Hackers Could Open Convicts' Cells In Prisons 203

Hugh Pickens writes "Some of the same vulnerabilities that the Stuxnet superworm used to sabotage centrifuges at a nuclear plant in Iran exist in the country's top high-security prisons where programmable logic controllers (PLCs) control locks on cells and other facility doors. Researchers have already written three exploits for PLC vulnerabilities they found. 'Most people don't know how a prison or jail is designed; that's why no one has ever paid attention to it,' says John Strauchs, who plans to discuss the issue and demonstrate an exploit against the systems at the DefCon hacker conference next week. 'How many people know they're built with the same kind of PLC used in centrifuges?' A hacker would need to get his malware onto the control computer either by getting a corrupt insider to install it via an infected USB stick or send it via a phishing attack aimed at a prison staffer, since some control systems are also connected to the internet, Strauchs claims. 'Bear in mind, a prison security electronic system has many parts beyond door control such as intercoms, lighting control, video surveillance, water and shower control, and so forth,' adds Strauchs. 'Once we take control of the PLC we can do anything (PDF). Not just open and close doors. We can absolutely destroy the system. We could blow out all the electronics.'"

Slashdot Top Deals