Wednesday, 24 July 2013

Cyber warning over "Royal Baby" video


The Duchess of Cambridge holds her son outside the Lindo Wing of St Mary's Hospital in London on July 23, 2013. Britain's royal baby will grow up to be determined but introverted -- and a big hit with the ladies -- Chinese fortune tellers predicted on Wednesday

Cybercriminals have already taken advantage of the whirlwind of excitement surrounding the birth Prince of Cambridge, warned internet security experts today.

Malicious emails promise the latest video news - but instead deliver Trojan software into PCs, including one known to steal online banking information.

Yahoo! News has seen one example of a spam email titled ‘The Royal Baby: Live Updates’ and purporting to lead to live CNN video coverage of the birth.

“The Duke and Duchess of Cambridge have welcomed their first baby — a son and a future heir to the British throne — into the world. CNN has all the latest details of this momentous occasion,” the email says.

The email claims to come from a company called ScribbleLive, a popular media marketing service.
Spam emailClicking any of the links in the email prompted users to upgrade their Flash player plugin, but in fact downloaded a Trojan known to be used to steal personal details, including online banking information.

Security expert Graham Cluley said, “ It’s very likely that we will see more of this kind of attack. There are several common tricks hackers use – it could be asking you for a username and password to see photos of the baby, or making you complete an innocuous-looking survey.”

Social networks are another fertile ground for hackers to sow dangerous material. At the time of the announcement of the birth, 23,500 tweets mentioning the Royal baby were sent per minute.

“People should be careful what they’re clicking on Facebook and Twitter,” said Cluley.
“Links can be automatically generated to include the trending hashtags. There are also a lot of joke pictures doing the rounds – if you get into the habit of clicking on them as soon as they’re posted, you’re less likely to be careful about where they come from.”

This is not the first time that the Duke and Duchess of Cambridge have been used by hackers to spread viruses.

When their engagement was first announced, hackers were quick to hijack the most popular search engine image results – with the result that clicking on an apparently innocent picture of the couple led to a warning message asking users to download fake antivirus software, which was in fact malware designed to take over PCs and steal data.

In 2011, a story posted on Aol.co.uk about a ‘Pregnant Kate Middleton’ children’s doll was found to have been infected by hackers. Visiting the page would attempt to run malicious software in the background without users’ knowledge.

Fiberio is first touchscreen that reads fingerprints as you use it

A new fiber-optic tabletop PC system is the first which “reads” fingerprints as people use it – and could form the basis of a secure identification system for transactions in shops or banks.
Sensors inside Fiberio “read” reflected light from the table’s surface, with enough detail to identify fingerprints as a user touches the surface. Users can be identified instantly and seamlessly as they use the device. The prototype machine is multi-touch, so that several users can use it at any one time.
“Fiberio is the first interactive tabletop system that authenticates users during touch interaction – unobtrusively and securely using the biometric features of fingerprints, which frees users from carrying identification tokens,” says designer Christian Holz.
The rear-projection “Tabletop PC” will be detailed in a paper Fiberio: A Touchscreen that Senses Fingerprints to be presented at the ACM symposium on User Interface Software and Technology.
Holz suggests that Fiberio could be used in banks to, “verify that the respective user has the authority to perform the current activity – such as approve invoices above a certain value.”
The table would identify both the bank manager and the customer instantly, Holz suggests – working out both whether the manager had the authority to approve invoices, and also securely identifying the customer.
“The key that allows Fiberio to display an image and sense fingerprints at the same time is its screen material: a fiber optic plate,” says Holz.
Fiberio works using a rear-projection system, similar to the one found in Microsoft’s Surface table PCs, which are often used in point-of-sale situations. The projection system allows the machine to “read” reflections in the plate – the system could not work in its current guise in normal tablets and smartphones.
ESET Senior Research Fellow David Harley discusses the advantages of biometric systems in a We Live Security blog post, “The sad fact is, static passwords are a superficially cheap but conceptually unsatisfactory solution to a very difficult problem, especially if they aren’t protected by supplementary techniques. Biometrics and one-time passwords and tokens are much more secure, especially when implemented in hardware as a two-factor authentication measure.”