Mostrando entradas con la etiqueta SECURITY. Mostrar todas las entradas
Mostrando entradas con la etiqueta SECURITY. Mostrar todas las entradas

lunes, 13 de enero de 2020

This Government-Subsidized Phone Comes With Malware

Posted by New event enero 13, 2020, under | No comments

The Android devices are a part of the FCC's Lifeline Assistance Program, which makes free or subsidized phones available to millions of low-income users.



An Android phone subsidized by the US government for low-income users comes preinstalled with malware that can't be removed without making the device cease to work, researchers reported on Thursday.
ARS TECHNICA
This story originally appeared on Ars Technica, a trusted source for technology news, tech policy analysis, reviews, and more. Ars is owned by WIRED's parent company, CondĂŠ Nast.
The UMX U686CL is provided by Virgin Mobile's Assurance Wireless program. Assurance Wireless is an offshoot of the Lifeline Assistance program, a Federal Communications Commissions plan that makes free or government-subsidized phone service available to millions of low-income families. The program is often referred to as the Obama Phone because it expanded in 2008, when President Barack Obama took office. The UMX U686CL runs Android and is available for $35 to qualifying users.
Researchers at Malwarebytes said on Thursday that the device comes with some nasty surprises. Representatives of Sprint, the owner of Virgin Mobile, meanwhile said it didn't believe the apps were malicious.
The first is heavily obfuscated malware that can install adware and other unwanted apps without the knowledge or permission of the user. Android/Trojan.Dropper.Agent.UMX contains striking similarities to two other trojan droppers. For one, it uses identical text strings and almost identical code. And for another, it contains an encoded string that, when decoded, contains a hidden library named com.android.google.bridge.Liblmp.
Once the library is loaded into memory, it installs software Malwarebytes calls Android/Trojan.HiddenAds. It aggressively displays ads. Malwarebytes researcher Nathan Collier said company users have reported that the hidden library installs a variant of HiddenAds, but the researchers were unable to reproduce that installation, possibly because the library waits some amount of time before doing so.
The malware that installs these programs is hidden in the phone's settings app. That makes it virtually impossible to uninstall, since the phone can't operate properly without it. "Uninstall the Settings app, and you just made yourself a pricey paper weight," Collier wrote.
The second unpleasant surprise delivered by the UMX U686CL is something called Wireless Update. While it provides a mechanism for downloading and installing phone updates, it also loads a barrage of unwanted apps without permission. The app is a variant of Adups, an app from a China-based company by the same name. In 2016, researchers caught Adups surreptitiously collecting user data on hundreds of thousands of low-cost phones from BLU.
"From the moment you log into the mobile device, Wireless Update starts auto-installing apps," Collier said. "To repeat: There is no user consent collected to do so, no buttons to click to accept the installs, it just installs apps on its own."
While all of the installed apps Malwarebytes examined were clean and free of malware, the presence of a feature that automatically installs apps poses an unacceptable risk, particularly since removing the feature prevents the phone from receiving updates. Collier's post classified Wireless Update as malware, but JĂŠrĂ´me Segura, Malwarebytes' head of threat intelligence, told me its actual classification is a PUP, or potentially unwanted program, since there's no evidence the apps that are installed are malicious.
In any event, the two apps analyzed by Malwarebytes make use of the UMX U686CL a bad choice. The fact that it's made available to low-income users only worsens the insult. Malwarebytes said it notified Assurance Wireless of its findings and asked why the phone it sells comes with preinstalled malware. So far, no one has responded. In an email, Sprint officials said: "We are aware of this issue and are in touch with the device manufacturer Unimax to understand the root cause, however, after our initial testing we do not believe the applications described in the media are malware."
It's not hard to find online discussions like this one complaining of annoying displayed ads and apps automatically installing on the device without user permission. A similar thread discusses ads that display on the homescreen even when a browser isn't running.
Over the years, preinstalled malware has been found on a raft of low-cost Android phones from a variety of providers and manufacturers. An incomplete list includes a backdoor on hundreds of thousands of BLU devices, a powerful backdoor and rootkit also on BLU devices, and covert downloaders on 26 different phone models from various manufacturers.
It seems the price people often pay for low-cost phones is compromised security and privacy. While many users may not be able to afford them, buying phones from mainstream and well-known providers located outside of China is likely to be a better choice.
This story originally appeared on Ars Technica.

More Great WIRED Stories

Security News This Week: The FBI Wants Apple to Unlock iPhones Again

Posted by New event enero 13, 2020, under | No comments

Snooping Ring employees, Skype contractors, and more of the week's top security news.



After anxious days awaiting Iran's response to the US assassination of Qasem Soleimani, the country sent missiles flying at two Iraqi military that housed US troops—who knew about it well in advance, thanks to an early warning system that dates back to the Cold War. In a rare reversal from the norm, Donald Trump followed up by using Twitter to defuse tensions rather than escalate them further. Iran's still on a path to developing nuclear capabilities, but they won't get there any time soon.
As far as anyone knows, Iran hasn't countered the US directly with a cyberattack, but a new report shows that they've spent the last year probing US critical infrastructure. All of which is to say, let's hope both parties stick with deescalation.
On the home front, Amazon swatted at money-saving extension Honey just in time for the holidays, warning users that it was a security risk without specifying how. Google welcomed alleged spy app ToTok back into the Google Pay Store, while the jury's still out for Apple. And TikTok recently patched bugs that could have let attackers take over a victim's account. (No, that doesn't mean it's spying on you.)
It was an active week for Facebook; the company made its Privacy Checkup feature a wee bit more granular, acknowledged that encrypting Messenger end-to-end by default will take years, and suffered a bug that doxxed the admins of Pages. Otherwise all good, though.
And while you may have heard that Russia disconnected itself from the internet over the holidays, that's not quite right. But the Kremlin's efforts to censor the internet are very real, and increasingly broad.
And that's not all! Every Saturday we round up the security and privacy stories that we didn’t break or report on in-depth but think you should know about nonetheless. Click on the headlines to read them, and stay safe out there.
Stop us if you've heard this one before: The FBI has asked Apple to unlock the iPhone of a mass shooter. As it did when the agency did the same in the San Bernadino investigation, Apple has declined. The Cupertino company regularly complies with subpoenas for data stored in its cloud, but argues that breaking into a locked iPhone would be require undermining its own encryption, which in turn would make all iPhones less safe. The prolonged fight in 2016 ended in something of a draw, when the FBI found a way to unlock the iPhone on its own. While its request hasn't escalated to a court fight yet, it's only a matter of time before it tries for a rematch.
We've written about the risks inherent in using SMS-based two-factor authentication since 2016. Since then, the plague of so-called SIM-swap attacks that it enables have only grown, hitting even Twitter CEO Jack Dorsey. This week, researchers at Princeton University's Center for Information technology detailed the many, many ways that SMS 2FA can go wrong, including multiple failings on the part of carriers to vet SIM-swap requests. If this doesn't convince you to switch to an authenticator app, nothing will.
By now it's no longer surprising that every voice assistant has a small army of human contractors behind it, transcribing recordings to improve accuracy. (Or did, until the public backlash.) Skype, however, reportedly hit an impressive low by not only using contractors in China but letting them listen to recordings through a Chrome web browser, and were encouraged to all long through the same account and password. In other words, it would have been almost comically easy to compromise the sensitive data. Microsoft told The Guardian that it has since moved its transcription efforts out of China and into "secure facilities." It's unclear exactly what that means, but the bar appears to be extremely low.
To continue the theme: In a letter to US senators this week, Ring acknowledged that four employees sought improper access to video taken by its customers' cameras over the last four years. The company says that of them were fired for violating company policy, and that currently only three employees can access stored customer videos.

More Great WIRED Stories

All the Ways Facebook Tracks You—and How to Limit It

Posted by New event enero 13, 2020, under | No comments

All the Ways Facebook Tracks You—and How to Limit It


If you have a Facebook account—and even if you don't—the company is going to collect data about you. But you can at least control how it gets used.



It won't come as much of a surprise that Facebook tracks you on its platform—that's why it can resurface your birthday photos from five years ago—but you might not yet realize the scope and the depth of its tracking all across the internet. Facebook's tentacles stretch out across other websites and services, into the various apps you're using on your phone, and to the places you physically visit in the real world—especially if you decide to check in on Facebook while you're there.
Some of this comes with the territory of using Facebook: If you want to take advantage of its features, then you have to give up a certain amount of information about yourself. But Facebook has ways of keeping tabs on people who aren't even signed up for the service. Fortunately, there are numerous ways to limit the volume of data that it logs.
How hard you want to pull back depends to a certain extent on how much you trust Facebook. The social network behemoth says it uses your data to show relevant ads and keep you safe; if someone signs into your account from a country you're not usually in, for instance, Facebook can flag the activity as suspicious.
However, this is not a company with a good track record when it comes to looking after your data. Irrespective of how Facebook itself has used your information, it's certainly been careless in the ways that information has been shared with third parties.
To make matters more complicated, Facebook owns WhatsApp and Instagram, too, and can pool some of the information it gathers in those apps as well. The best way to limit Facebook's tracking is to quit all three apps for good. If that's too extreme for you, we've got some more suggestions.
For reference, the Facebook data policy is here, and you can read a more user-friendly explainer on how your data is handled here.
On the Web

page showing add settings
COURTESY OF FACEBOOK

If you want to use Facebook, you give it permission to log your activity on the site: where you check into, the groups you join, who you interact with. This data is primarily used to serve up advertising that's more relevant to you, which in turn makes more money for Facebook.
You can't really stop Facebook from collecting this information—it's the deal you make when you sign up—but you can limit how it affects the advertising you see by visiting the ad preferences page in your account on the web. Open up Your interests to get a quick glance at what Facebook thinks you're int. It might have made some assumptions that are well wide of the mark.


Under the Your information tab, you can see some of the ways Facebook is targeting advertising at you: your relationship status, your job title, where you went to college, and more. If you don't want some or all of these pieces of information to be used by advertisers, hit the relevant toggle switch.
Open up Ad settings to make even more changes. Here you can control whether Facebook can use data from its marketing partners—and there are an awful lot of them—to put more relevant advertising in front of you. If you don't want this to happen, switch the setting from Allowed to Not allowed.
Bear in mind that these settings don't reduce the number of advertisements you see on Facebook, nor do they delete the data that Facebook has amassed on you. They just stop advertisers from specifically targeting you using that data. If you're happily married, you might suddenly start seeing ads for dating sites, but Facebook itself will still know your relationship status.
Facebook's reach also goes way beyond Facebook itself. It has partnerships with a whole host of marketing firms and ad networks so that activities on other sites—including but not limited to logging into a third-party service with your Facebook account—can be combined with your Facebook profile.
This activity has attracted enough bad press that Facebook announced a tool in August called "Off-Facebook Activity" that will disconnect this data from what you actually do on Facebook. It's a more comprehensive solution, but still not widely available. It also still doesn't affect how much data Facebook actually collects, it just breaks the association between what you do on Facebook and off it. If you're shopping for shoes on a third-party retail site, you won't suddenly see ads for them all over your News Feed.

page showing multiple screens
COURTESY OF FACEBOOK

This off-Facebook activity is also monitored whether or not you have a Facebook account. Tracking tools like the Facebook Pixel enable websites and online retailers to get information about their visitors, including whether they come back. A vast number of third parties are using Facebook's advertising and tracking technologies, which means it isn't just Facebook you need to worry about.
Site owners are able to build up a profile of who is visiting their pages, and Facebook collects even more data about what people are shopping for and looking at on the web. If that data can be added to a Facebook profile so much the better for Facebook, but the social network can still use in general terms to analyze aggregated user behavior.


More broadly, you can stop some of the web activity being used to target you with ads by visiting the YourAdChoices site run by the Digital Advertising Alliance. You'll notice Facebook advertising targeting is on the list of entries—tick the Opt Out box to do just that. Note that you'll need to do this separately for each browser you use; for the biggest impact, you should opt out of all the other platforms as well.
Locking down tracking in your browser is also recommended: Look out for the option to block third-party cookies in your browser settings (the sort that can track activity across multiple sites), and consider using well-respected tracker blocking browser extensions such as Ghostery or Privacy Badger.
On Mobile Devices

page showing permissions
COURTESY OF FACEBOOK

Much of what we've already said applies to Facebook's mobile apps as well. If you want to limit what Facebook knows about you, you're best off not installing the mobile apps at all. Doing so gives Facebook permission to log the Wi-Fi networks you connect to, the type of phone you have, the other apps you have installed, and more besides, as well as everything you do on Facebook itself.
You can't stop all of this data collection, but you can curb it. Head to the Facebook permissions page—under Apps and notifications and Facebook in Android settings and under Facebook in iOS settings—to block Facebook's access to your phone's location, your contacts, your phone's microphone and camera, and more.
The bad news? Even with location tracking turned off, Facebook still makes note of the approximate location that you access the web from via your IP address. It's only a rough guide—and Facebook says it's necessary to keep accounts secure and users verified—but you can't stop this from happening if you use Facebook.
More bad news: Other apps send data to Facebook as well, often automatically. Almost everyone has a Facebook account, and third-party apps want to make use of that data, whether it's to target users with advertising or to simplify the login process and get more user data as a result. Facebook isn't working in isolation here, and has many profitable partnerships with other apps and data brokers.
It's worth emphasizing that Facebook, like Google, promises to use this treasure trove of data to improve its services and make life safer and more convenient for its users, as well as generating more profitable ads across its network. You are, after all, using everything Facebook offers for free. If you don't trust Facebook's intentions—which is by now understandable—then you really need to quit using it altogether.


If you're going to stay with it, limit your activity and become a social media lurker. Don't check into locations, don't tag photos, and don't fill out quizzes that tell you which Disney character you are. Keep your profile information down to a minimum, and think twice about sharing anything at all. On the phone, consider using Facebook on the mobile web instead of in the app.

page showing privacy settings
COURTESY OF FACEBOOK

Keep the apps you've connected to Facebook down to a minimum as well; you can find a list on the web here. Not only does this restrict the third parties who have access to your data, it's also a good idea from a security point of view, limiting the number of ways hackers could potentially get at your data.
Facebook knows full well that users are uneasy about its data collection policies, and is trying to push out tools that ostensibly offer more control. In reality, these don't do much in regards to data collection, and are more about how that data is used to personalize ads. At this stage, if you don't want Facebook to know a lot about you, you really need to close down your Facebook, Instagram, and WhatsApp accounts and not look back.
More general privacy tips can slow down Facebook, too: Use a VPN to disguise your location, lock down your browser's privacy settings so you're not tracked so extensively by marketers, and make liberal use of your browser's incognito mode wherever you can. Ultimately though, using Facebook comes with a cost, even if it's not paid up front in dollars and cents.

Tags

Blog Archive