In late March, before Schnuck Markets Inc. knew the extent of a
breach that compromised as many as 2.4 million debit and credit cards, a
Wal-Mart employee in Plano, Texas, saw something strange.
The employee, a loss prevention officer, noticed a woman acting
oddly. She was trying to use several payment cards at the register, and
she was buying gift cards. Both of those things raised red flags, so the
officer took the woman aside.
Later that day, the woman was charged with credit card forgery. And
sometime that same day, law enforcement authorities made a link: The
44-year-old Fort Worth, Texas, woman was attempting to shop with
counterfeit cards containing data that had been stripped from a card
used at a Schnucks grocery store, hundreds of miles away and probably
months beforehand.
While thousands of fraudulent transactions linked to the breach were
conducted all over the country, the woman's arrest is one of only a
handful made so far and it was something of a fluke.
The fact is, experts say, it's not likely that many people will be
called to account for their criminal connections to the breach.
The woman may have been what cyber-crime investigators consider a mule
or a runner a person who takes fake cards encoded with stolen data and
attempts to see if the cards work, reporting success or failure to
higher-ups.
Or she may have bought the cards on the black market, hoping to get
away with fraudulently purchased loot, or in this case, gift cards.
In other words, she is small potatoes not the person investigators
are after. The people investigators really want are likely thousands of
miles away, possibly in Eastern Europe, and they may never catch them.
Those thieves, experts say, have probably closed up shop and moved
on, vanishing without a trace, leaving people such as the woman charged
in Plano holding the proverbial bag.
Cyber-crime experts say that, given that information and given what
they know from cyber-sleuth circles the data were lifted just after
cards were swiped at the point of sale. Several said the likely culprit
was a Romanian cyber gang.
“The Schnucks breach was the result of random access memory malware,”
explained Al Pascual, a senior analyst of security risk and fraud at
Javelin Strategy & Research, a California company that advises the
payment industry. “That means there's malicious software at the point of
sale.
After a card is swiped, the data goes into the register, then it goes
to random access memory on the computer itself, and this malware pulls
it right off the memory before it's transmitted somewhere else.”
Typically, after information is stolen, it gets sold in batches on
the Internet. The thieves send the data to an IP address Internet
Protocol address where other thieves can buy the information. This used
to happen on what's known as the “dark Web,” beyond the reach of online
search engines, but now, experts said, a buyer can find stolen data
fairly easily.
“It used to be you had to know where to go,” Pascual said. “But it's
made its way into the mainstream. Now you can actually Google the
information, and you'll find forums. There are even groups on Facebook.”
After buyers get their hands on the information, they often encode it
into cards, often blank cards known as “white plastics” in the industry
or on gift cards that they recode with the stolen information. The data
can be used to buy merchandise online in “card not present”
transactions.
By the time these cards make their way down the food chain from the
hackers, through the syndicates that sell the data, to the low-level
mule or buyer on the street the IP address where the information was
sent has long gone dark, and the criminals have vanished.
“They bounce information from different IP addresses, and then they
burn them they don't use them again,” explained Jim McKee of Red Sky
Alliance, a network of cyber-security experts based in St. Louis. “So
you have a dead end. The hackers sold all the credit card numbers,
they've made their money, and they've moved on.”
Information Security, Ethical Hacking, website Security, Database Security, IT Audit and Compliance, Security news, Programming, Linux and Security.
Monday, 5 August 2013
Sunday, 4 August 2013
Google Glass
Google Glass (styled "GLΛSS") is a wearable computer with an optical head-mounted display (OHMD) that is being developed by Google in the Project Glass research and development project, with the mission of producing a mass-market ubiquitous computer. Google Glass displays information in a smartphone-like hands-free format, that can interact with the Internet via natural language voice commands.
Glass is being developed by Google X, which has worked on other futuristic technologies such as driverless cars.
Although head-worn displays for augmented reality are not a new idea, the project has drawn media attention primarily due to its backing by Google, as well as the prototype design, which is smaller and slimmer than previous designs for head-mounted displays. The first Glass demo resembles a pair of normal eyeglasses where the lens is replaced by a head-up display. Around August 2011, a Glass prototype weighed 8 pounds; the device is now lighter than the average pair of sunglasses.
Android 4.0.4 and higher
640×360 display
5-megapixel camera, capable of 720p video recording
Wi-Fi 802.11b/g
Bluetooth
16GB storage (12 GB available)
Texas Instruments OMAP 4430 SoC 1.2Ghz Dual(ARMv7)
682MB RAM "proc".
3 axis gyroscope
3 axis accelerometer
3 axis magnetometer (compass)
Ambient light sensing and proximity sensor
Bone conduction transducer
Third-party applications announced at South by Southwest (SXSW) include Evernote, Skitch, The New York Times, and Path.
On April 15, 2013, Google released the Mirror API, allowing developers to start making apps for Glass. In the terms of service, it is stated that developers may not put ads in their apps or charge fees; a Google representative told The Verge that this might change in the future.
Many developers and companies have built applications for Glass, including news apps, facial recognition, photo manipulation, and sharing to social networks, such as Facebook and Twitter.
On May 16, 2013, Google announced the release of seven new apps, including reminders from Evernote, fashion news from Elle, and news alerts from CNN. Following Googles XE7 Glass Explorer Edition update in early July 2013, evidence of a "Glass Boutique", a store that will allow synchronization to Glass of Glassware and APKs, was noted.
The first cooking application for Glass, KitchMe, was released by Coupons.com in June 2013.
For Preview about what it does you can visit: http://www.google.com/glass/start/what-it-does/
Glass is being developed by Google X, which has worked on other futuristic technologies such as driverless cars.
Although head-worn displays for augmented reality are not a new idea, the project has drawn media attention primarily due to its backing by Google, as well as the prototype design, which is smaller and slimmer than previous designs for head-mounted displays. The first Glass demo resembles a pair of normal eyeglasses where the lens is replaced by a head-up display. Around August 2011, a Glass prototype weighed 8 pounds; the device is now lighter than the average pair of sunglasses.
Hardware
Camera
Google Glass has the ability to take photos and record 720p HD video. While video is recording, a recording light is displayed above the eye, which is unnoticeable to the wearer.Touchpad
A man controls Google Glass using the touchpad built into the side of the device. A touchpad is located on the side of Google Glass, allowing users to control the device by swiping through a timeline-like interface displayed on the screen. Sliding backward shows current events, such as weather, and sliding forward shows past events, such as phone calls, photos, circle updates, etc.Technical specifications
For the developer Explorer units:Android 4.0.4 and higher
640×360 display
5-megapixel camera, capable of 720p video recording
Wi-Fi 802.11b/g
Bluetooth
16GB storage (12 GB available)
Texas Instruments OMAP 4430 SoC 1.2Ghz Dual(ARMv7)
682MB RAM "proc".
3 axis gyroscope
3 axis accelerometer
3 axis magnetometer (compass)
Ambient light sensing and proximity sensor
Bone conduction transducer
Software
Applications (Glassware)
Google Glass applications (Glassware) are free applications built by third-party developers. Glass also uses many existing Google applications, such as Google Now, Google Maps, Google+, and Gmail.Third-party applications announced at South by Southwest (SXSW) include Evernote, Skitch, The New York Times, and Path.
On April 15, 2013, Google released the Mirror API, allowing developers to start making apps for Glass. In the terms of service, it is stated that developers may not put ads in their apps or charge fees; a Google representative told The Verge that this might change in the future.
Many developers and companies have built applications for Glass, including news apps, facial recognition, photo manipulation, and sharing to social networks, such as Facebook and Twitter.
On May 16, 2013, Google announced the release of seven new apps, including reminders from Evernote, fashion news from Elle, and news alerts from CNN. Following Googles XE7 Glass Explorer Edition update in early July 2013, evidence of a "Glass Boutique", a store that will allow synchronization to Glass of Glassware and APKs, was noted.
The first cooking application for Glass, KitchMe, was released by Coupons.com in June 2013.
MyGlass
Google offers a companion Android app called MyGlass, which allows you to configure and manage your device.Voice activation
Other than the touchpad, Google Glass can be controlled using "voice actions". To activate Glass, wearers tilt their heads upward or tap the touchpad, and say "O.K., Glass." Once Glass is activated, wearers can say an action, such as "Take a picture", "Record a video", "Hangout with [person/Google+ circle]", "Google 'What year was Wikipedia founded?'", "Give me directions to the Eiffel Tower", and "Send a message to John" (many of these commands can be seen in a product video released in February 2013). For search results that are read back to the user, the voice response is relayed using bone conduction through a microphone that sits beside the ear, thereby rendering the sound almost inaudible to other people.Games
GlassBattle developed by BrickSimple and Escape developed by Advanced Mobile Applications (AMA Studios) are two Glass games that were released prior to the official release of the product. GlassBattle, which is adapted from the board game Battleship, was the first of the two to be publicized.Reception
There have been parodies and criticisms aimed at the general notion of augmented reality glasses, ranging from the potential for Google to insert advertising (its main source of revenue) to more dystopian outcomes. However, Google has stated it has no plans to insert advertising.For Preview about what it does you can visit: http://www.google.com/glass/start/what-it-does/
Subscribe to:
Posts (Atom)