ComRȁde PyRate

Tuesday, 4 August 2015

Windows 10 to deliver updates and App downloads via Peer-to-Peer Technology


microsoft-windows-10-peer-to-peer
Does downloading Windows updates from Microsoft's servers and waiting too long really annoy you? It might not be with the arrival of Windows 10. Microsoft seems to make a major change in Windows 10 to the way it delivers updates for the software.

The leaked version of Windows 10 build 10036 (the current version is build 9926) allows you to grab OS updates from Microsoft as well as other computers, whether they're on your local network or on the Internet.

Yeah, it's a Peer-to-Peer (P2P) technology Microsoft is going to use in order to deliver both app and operating system updates.

Peer-to-Peer, or P2P Technology is usually associated with file sharing services like BitTorrent to download illicit copies of movies and albums, and of course, those endless Linux ISOs you've been downloading.

However, Redmond is embracing the technology as an efficient means to deliver software updates to its users around the globe.

Peer-to-Peer downloads will be optional in Windows 10. The new dialog box titled "Choose how you download updates" offers Windows users an option to "Download apps and OS updates from multiple sources to get them more quickly".

Once turned ON, the option delivers you choices to
  • Download apps and OS updates from Microsoft and PCs on my local network
  • Download apps and OS updates from Microsoft, PCs on my local network, and PCs on the Internet
Besides accelerating the upgrade process, P2P feature could save precious bandwidth if you have a multiple PCs in your house. 

Redmond's move is not at all surprising, as the software maker bought Pando Networks in 2013, which is the maker of a peer-to-peer file sharing technology, similar to BitTorrent.

So far, the leaked screenshot is not confirmed by the company neither it released any official announcement, but you can expect the new release of an official Windows 10 preview shortly that will likely include the new changes.

However, if Microsoft really includes P2P technology for updating its software, it will be an interesting option for enabling distributed updates, rather than updating through Windows Server Update Services. Home users might appreciate the faster downloads that will come with peer-to-peer downloads.

Windows 10 Wi-Fi Sense Explained: Actual Security Threat You Need to Know


Windows 10 Wi-Fi Sense Explained: Actual Security Threat You Need to Know
Just one day after Microsoft released its new operating system, over 14 Million Windows users upgraded their PCs to Windows 10.

Of course, if you are one of the Millions, you should aware of Windows 10's Wi-Fi Sense feature that lets your friends automatically connects to your wireless network without providing the Wi-Fi password.

Smells like a horrible Security Risk! It even triggered a firestorm among some security experts, who warned that Wi-Fi Sense is a terrible and dangerous feature and that you should disable it right away.

Even some researchers advised Windows 10 users to rename their Wi-Fi access points.

Before discussing the risks of Wi-Fi Sense, let's first know how it works.

How Windows 10 Wi-Fi Sense works?


Windows 10 Wi-Fi Sense feature allows you to share your Wi-Fi password with your friends or contacts, as well as lets you automatically connect to networks that your friends and acquaintances have connected to in past, even if you don't know the password.

Now, when those friends are within the range of your Wi-Fi network, Windows 10 automatically joins the network with that saved password you just shared with your friends and logs them in, without prompting them for a password.

Enabled by Default, but It's not the actual Security Threat, Here's Why:


Wi-Fi Sense feature is enabled by default in Windows 10 to make it easier for users to receive instant access to the Shared Networks by their Friends or Contacts.

But, But, But… did you notice that the feature says "For networks I select..."?

"Enabled by default" doesn't mean your Wi-Fi passwords are automatically going to be shared with your Facebook or Skype contacts by default, unless you won’t manually configure your Wi-Fi Sense settings to share selected network access with any contact group.

Under "For networks I select..." option, you can explicitly control which group of contacts from which social networks get access to which Wi-Fi Network.

Until or unless you do not offer your Wi-Fi password to Wi-Fi Sense, it will not let selected contact group to connect to your network.

This means Wi-Fi password sharing option is OFF for every social network by default.

And of course even if you choose to share your Wi-Fi network with your contacts, Wi-Fi Sense only shares Internet access and not your actual Wi-Fi password.

Why You Should be Scared of Wi-Fi Sense (Actual Security Threat)


Microsoft promoted Wi-Fi sense as:

In simple words, now you don't need to read out loud your Wi-Fi password, character by character when your friends are at your home and want to use The Internet. So similarly, you don’t need to shout across the office or your friend’s house "What’s the Wi-Fi password?"

However:

"If you choose to share with your Facebook friends, any of your Facebook friends who are using Wi-Fi Sense on a Windows Phone will be able to connect to the network you shared when it's in range, You can't pick and choose individual contacts." -- Microsoft FAQ says.

As a general Internet user, I used to accept almost every friend request on the Facebook and also communicate with lots of people on Skype or Outlook. In short, the majority of people in my contact list are whom I don't know personally or trust.

So, If I can't choose any individual contact from my list, then enabling "Network password sharing feature" will share my network access with all my contacts in the selected social network.

Microsoft also Argued:

Neither it allows anyone to access your local resources so that nobody can hunt through your personal files.

However, We know that...

The biggest threat of sharing your Wi-Fi access with everyone on a list is just like you are allowing hackers to position themselves between you and the connection point i.e. Man-in-the-Middle attack.

In such attack scenarios, the hacker can access every piece of information you're sending out on the Internet, including important emails, account passwords or credit card information.

Sitting on the same network, an attacker can also target your machine directly using Metasploit or any other hacking tool.

Ultimately, Windows 10 Wi-Fi Sense probably is not the most secure feature in the world, but it is not that bad either, if in future, Microsoft could allow Windows 10 users to choose individual contacts from a group.

For Now… Should You Stop Using It?


Like many things in life, we have to make a choice between things that make our life comfortable and that provide us absolute security.

AND, if you are concerned more about security, just turn Wi-Fi Sense OFF.

How to Turn Windows 10 Wi-Fi Sense OFF?


To disable Wi-Fi Sense, go to Windows Settings, then Network & Internet and then click "Change Wi-Fi settings," and then "Manage Wi-Fi settings."

From there, you can change a variety of settings. Turn OFF everything under the Wi-Fi Sense heading; disable WI-Fi password sharing with Facebook, Outlook, or Skype; and have Wi-Fi Sense forget the list of known Wi-Fi networks.

Saturday, 25 July 2015

The Hacker Search Engine “Shodan” is the Scariest Search Engine on Internet

shodan-hacker-search-engine
Launched in 2009, Shodan is more of a prying eye across the world through the IoT rather than just a simple search engine. John Matherly, its creator, named his project after the villainous computer in the video game System Shock. As in present, Shodan is living up to his name. Already designated as ‘world’s scariest search engine’, it is commonly called the hacker search engine.
Shodan shows you what Google doesn’t. Designed with an aim to link all the devices connected to the Internet, it took no time to become a play zone for hackers and experimenters. Shodan works by collecting and stacking HTTP addresses from various devices linked over the Internet across the world. The indexing is done on the basis such as country, OS and brand.

Shodan’s scanning power can be assumed from the fact that it can detect the traffic lights, security cameras, control systems for gas stations, power grids, and even nuclear power plants. Most of these public services use little measures for online security and once exposed to hackers or terrorist organizations, the results could be disastrous.
If you have installed telnet enabled security cameras in your home for “security”, then you might want to put them away. Hackers can breach into your system if your IoT hub is exposed on the Internet using this hacker search engine. It won’t be easy, however, it is not impossible either.
There are a number of devices out there that still run on their default passwords or no passwords at all. Shodan crawls through the Internet for such accessible devices and you are shown 50 of those if you have an account on Shodan. If you could give the website the reason to check these devices with their fees, you would get information of all the devices.
Though, even if you can,  we highly recommend you to not misuse Shodan, the hacker search engine.
For more updates and interesting stories from fossBytes, subscribe to our newsletter.

Sunday, 8 March 2015

Siri/Cortana listening posts for Apple/Microsoft and their marketeers


Invasion of Privacy by Siri and Cortana brought out in open

“Everything you’ve ever said to Siri/Cortana has been recorded…and I get to listen to it” says an employee of Walk N’Talk Technologies

A Redditor, FallenMyst today stated the obvious on a Reddit thread, people other than the users can easily hear what the user says to Siri and Cortana and in all probability may use it to harm the user in long run.
FallenMyst stated in the thread that he had just joined a tech firm, Walk N’Talk Technologies where he got to listen into the sound bytes, match it with what is said in an audio click and then give the feedback about the quality to his bosses.
I started a new job today with Walk N’Talk Technologies. I get to listen to sound bites and rate how the text matches up with what is said in an audio clip and give feedback on what should be improved.
So far so good for FallenMyst because he thought that the sound bytes being given to him for benchmarking may be random. However he noticed a pattern in the voice samples and realised that they were sound samples of users giving voice commands to their smartphones using either Apple’s Siri or Microsoft’s Cortana.
Hearing the personal communications from users which is not supposed to heard by anyone other than the user and Siri/Cortana put FallenMyst in a moral dilemma.
“Soon, I realized that I was hearing peoples commands given to their mobile devices. Guys, I’m telling you, if you’ve said it to your phone, it’s been recorded…and there’s a damn good chance a 3rd party is going to hear it, FallenMyst states on the thread.
It seems that whatever that a users says to Siri/Cortana is being recorded and saved in the clouds and is available for listening to an unwanted third party.
Though it may be innocent stuff like “Siri, do you like me?” but in the end, a unwanted person is hearing a personal communication meant to be for Siri/Cortana’s ears only.
“I heard everything from kiddos asking innocent things like “Siri, do you like me?” to some guy asking Galaxy to lick his bxxxxxe. I wish I was kidding,” FallenMyst states.
Further, if such information is indeed being store by Apple and/or Microsoft, did they obtain users explicit permission to store it. Can Apple/Microsoft guarantee that such personal communications are not used by it/breached by hackers and used against the user.  Sometimes, innocent stuff can land you in a soup.
The post has already received a thousand upvotes on Reddit since it was posted an hour ago.  Many redditors have given their views and comments on the post. Some of the top comments are given below :
[–]mjrbac0n 1 point 55 minutes ago
“It’s helps pay for the device, like commercials.” Once the sound waves leave your mouth, you don’t own them anymore anyway.
[–]TheGreenJedi1 point
So i have a quick question OP,
If I remember some similar articles about this stuff happening the data is scrubbed of name and location and many other details, it’d be pretty hard for it to get traced back to a user in regards to the sexting.
Is that true?
Voice Commands are only going to get better through the work your doing at “Walk N’Talk Technologies.” So I’m really not surprised. I consider it my duty to future generations to help this technology work. I’m slightly surprised at the number of people using it for sexting though.
[–]jpgray1 point
Pretty interesting. I wonder if there’s going to be court cases in the near future on this sort of thing & stuff like the samsung TVs and xbox kinect recording people unwittingly. I don’t care what terms of use you agree to when you buy your device, people aren’t knowingly giving consent to this level of monitoring and it’s definitely an invasion of privacy.
Redditor jpgray has a point there, perhaps Apple and Microsoft should get ready for a class action suit for invasion of privacy and breach of trust!

Saturday, 7 March 2015

Android Malware hijacks the smartphone during the “shutting down” process.




A new Android Malware has been discovered by AVG which can be “spying” on the user even when the phone is in “Switch off mode”

Mobile Malware Research Team AVG have discovered a new bug which is of great concern to all the Android smartphone users.
Usually when user shuts down or puts off the Android phone a dialog box opens asking for 3 options: Power Off, Airplane Mode or Mute. Usually user would select the Power Off option and then the Android phone would shut off. Mobile security AVG team discovered that this Malware captures the “root permission” level of the Power Off process. Once this is done the malware will inject the virus so that the entire Power Off process is locked.
With the malware taking over the Power Off process, whenever the victim clicks the Power Off button an artificial dialog pops up and then the entire fake shutdown process takes place which would resemble as if actually the phone is shutting down. However in reality the phone is still active and working.
The Malware can then use the phone to click photos, even make some outgoing calls and anything that it wants to do using the phone. As of now the security team has acknowledged this virus as an “unknown Android Malware” (no name suggested yet) and all the Android users have been warned against this virus. Also the only remedy which can be applied as a safety measure would be to remove battery from the Android phone to ensure 100% switch off of these phones.
Security service providers should come up with a suitable anti-malware for this menace as removing the battery every time to shut down the Android smartphone would not be feasible, if some is infected with the malware.