security-nightmare:-many-networked-doorbells-let-hackers-into-the-house

Security nightmare: Many networked doorbells let hackers into the house

The IT security of “intelligent” doorbells equipped with video cameras, which can be bought for comparatively little money on online marketplaces such as Amazon, eBay or Wish, is not well ordered. This was the result of a test by the IT security company NCC Group for the British online magazine “Which?” surrender. The identified weaknesses therefore range from logon information that is firmly encoded in the hardware, to authentication problems, to data transfer to China. In some cases, the devices are delivered without the latest security updates being installed and long-standing critical errors have been corrected The researchers should find out what smart bells are good for, which cost significantly less than the market leaders from Amazon Ring or Google Nest and mostly come from China. They examined models from Victure, Qihoo and Accfly as well as unbranded products with titles like “HD Wi-Fi Video Doorbell V5”, “Smart WiFi Doorbell (YinXn)” or “Smart Wifi Doorbell – XF-IP 007 H “.

Overall, the experts give the devices a bad rating, which is a” nightmare “in the area of the Internet of Things. The security problems beyond aggressive data collection are massive. In addition, some of the video bells turned out to be “clones” of the Victure model, which not only took over its flaws, but also made them worse. The original contained an undocumented HTTP service on port 80. This required login data which could easily be extracted by one of the “Copy Cats”. Unencrypted WLAN IDs and passwords were found in log files.

The smartphone apps for controlling the digital bells also rely on unencrypted communication, which makes life easy for hackers. “HTTPS was not enforced on a number of devices or did not even exist as a communication method for a number of mobile applications,” the analysis said. For example, the Victure mobile application requested a root certificate via an HTTP request. Sensitive information, user names and passwords could be recorded with simple test instruments.

So many attack possibilities We encountered the Qihoo device the auditors on an undocumented, fully functional DNS service. In principle, this could simply be misused as a channel for the spread of malware. Current indications of such an active “rabbit hole” were not detectable.

Another possible attack vector was the misuse of QR codes. According to the report, a hacker who has access to a user’s cloud-based camera backup could also get their hands on the device’s QR code. The attacker could decrypt it and read the WLAN data with a password.

According to the researchers, the bell hardware is often not securely attached. It was then easy to remove and manipulate. The devices would usually sit loosely in a screwed or glued-on bracket. They could be stolen within a few seconds. Only one of the camera systems had a pressure sensor, which triggered an alarm if tampered with. This can also be prevented by a 2.4 GHz jammer.

No good words Help me the hardware is an attacker in a position to access the videos recorded by the bell and stored on an SD card, the experts say. For example, he could research the typical behavior of residents. In addition, the firmware can be extracted in order to obtain the access data to a network again or to identify further weak points.

The researchers found that one of the devices was still used for “key reinstallation attacks” (Krack ) was prone. This WLAN gap should actually be sealed since 2019. It enables attackers to read encrypted data traffic in plain text, to steal information and – depending on the network configuration – to smuggle in malicious code. Accfly and Victure, the only ones to publish contact information, did not respond to inquiries from Which. US civil rights activists had previously criticized the fact that ring apps are also big data throws.

(mho)

spyware:-microsoft-and-google-support-facebook-against-the-nso-group

Spyware: Microsoft and Google support Facebook against the NSO Group

Microsoft, Google, Cisco, the Internet Association and VMWare support Facebook in the proceedings against the NSO Group. The Israeli company had hacked WhatsApp accounts using malware 1400 – from journalists, lawyers, human rights activists and government officials, among others.

Microsoft has published the letter with multiple signers. It reads: “Private companies like NSO Group are working hard to develop surveillance tools and sell them to governments and other customers as ‘cyber surveillance as a service’.” This makes it possible to listen in on conversations, read text messages and e-mails, view photos and contact lists and download all of the data and search history. This is illegal in the USA.

Immunity thanks to governments The NSO is trying to do this Group to avert a proceeding. The company stated that immunity must apply because government agencies bought the software and were not used to monitor it yourself.

Facebook’s supporters try to protect its products from cyber criminals. “Every year 120 billions of dollars are invested in security worldwide,” the letter said. There is also an explanation of the other dangers – for example, using the example of the ransomware attack on a bank in Ukraine 2017, because of this in the USA and other regions of the world Productions had to be stopped. In their opinion, immunity for a private company is absolutely the wrong way to go. Imitators have already tried to produce similar software.

The first legal proceedings had already resulted in success for Facebook. However, a default judgment was issued against which the NSO Group defends itself. Since then, Facebook has also requested that the content of the case be decided.

(emw)

google-and-nickelback-really-want-you-to-look-at-your-photographs

Google and Nickelback really want you to look at your photographs

Nickelback has created a parody version of its own song “Photograph” for a new Google Photos ad, and it’s a lot more entertaining than you might suspect. In the ad, Nickelback lead singer Chad Kroeger mercilessly makes fun of himself, fully leaning into the “Photograph” meme and its usefulness in explaining all sorts of graphs and in illustrating framed copies of other memes, as Kroeger instructs viewers to “look at them” in his unmistakable, raspy voice.

The ad’s lyrics and photos touch on Kroeger’s “noodle hair” and his passion for photographing dessert. That it manages to both be a nice example of Google Photos’ features and a cute use of the old meme makes it worth a watch.

“Photograph” is 15 years old, and the meme connected to it has been around for almost as long, so seeing the ad is bound to spark some memories, which is exactly Google’s intention. While it’s not quite an original idea for an ad, Google gets a pat on the head for being aware of the joke. Nickelback also wrote the new lyrics for the parody version, according to an email Google sent to The Verge, so the band’s having some fun too.

Viral videos cemented Nickelback’s status as a meme, but here at The Verge, “Nickel-rolling” is what first comes to mind when we think of the band. Nickel-rolling is the unfortunate practice of trolling people with songs, lyrics, and images from the band Nickelback, like a Rickroll for the Nickelback generation.

The band has been the butt of jokes in the past, but if I’m honest, “Photograph” is a catchy song — good luck getting it out of your head if you watch the whole Google Photos ad. I think a lot of the ironic hate towards Nickelback is fading — I know it is for me. When we discussed the new ad, Verge editor Nick Statt summed up the phenomenon well:

I feel like every thing the internet hates eventually becomes endearing, because the curve of internet culture bends toward “not being a jerk” as everyone just grows up.

Whether someone at Google is admitting to being a Nickelback fan or simply reviving an old joke, some levity might be necessary given Google’s new storage policy in Photos. The company announced it will end its unlimited storage offer for “high quality” photos after June 1st, 2021. If you want to store more than 15GB after that cut-off, you’ll have to subscribe to Google One. Yes, Google would like you to look at your photographs, and it fully expects you to pay for the privilege of storing them.

iliad-launches-the-bomb-(timed):-here-is-the-first-rate-with-5g-for-less-than-e-10-with-70gb!

ILIAD launches the bomb (timed): here is the first rate with 5G for less than € 10 with 70GB!

Iliad’s first offer arrives with the 5G network: it’s called Flash 70 and will allow who will activate it (by 21 January 2021) to have up to 70 GB also under 5G network, unlimited calls and SMS at a price of only 9. 99 ??. Here are the details.

by Bruno Mucciarelli published , at 12: 32 in the Telephony channel

Iliad

Iliad decides to throw the bomb before Christmas and proposes from today until 21 January 2021 the first rate with support for the 5G network. It’s called Flash 70 and is precisely the first offer of the operator with 5G included , available for all (new users and users from all operators) with 70 GB at only 9, 99 ?? . Inside the offer, however, there are also unlimited minutes and SMS and, like all offers, also the possibility of not having remodulations in the future or even hidden costs.

Iliad Flash 70: here is the first rate with 5G included

How does the new rate work and what are its costs? Flash 70 sees the presence of a respectable bundle with the possibility of having up to 70 GB of traffic data to be exploited also, and herein lies the novelty, under the new 5G network in Italy. An incredible novelty especially because the rate is completed with everything that we usually found in the Iliad offers, that is, the minutes of calls and unlimited SMS for the whole month. The price? Only 9, 99 ?? but in this case the rate will be activated until the next 21 January 2021.

FLASH 70

  • Unlimited minutes of calls to all national fixed and mobile numbers
  • Unlimited SMS to all
  • 70 GB of data traffic under the 5G network (where available) with Hotspot included
  • COST: 9. 99 ?? per month
  • WHERE TO ACTIVATE IT: ONLINE or STORE
  • Activation COST + SIM: 9. 99 ??

As always, the transparency and quality offered by iliad have won over 6.5 million in less than 3 years

users, who have chosen the generous offers of the operator ready to amaze again with the first

offered in Italy with 5G included for less than 10 EUR. An offer available for a limited time, until 10

January 2021, which has no equal on the market.

ILIAD: other offers

Next to this the only item offer is proposed that allows you to have unlimited calls but practically without data for internet browsing. Here is specifically what it provides:

VOICE

  • Unlimited Minutes of calls to all national fixed and mobile numbers
  • Unlimited SMS Towards all
  • 40 MB of data traffic under the 4G network with Hotspot included
  • COST: 4. 99 ?? per month
  • WHERE TO ACTIVATE IT: ONLINE or STORE
  • Activation COST + SIM: 9. 99 ??

But alongside these two offers, Iliad proposes still the old Giga 40 and the Giga 50 which, although not visible on the website directly, can still be activated.

GIGA 50

  • Unlimited minutes of calls to all national fixed and mobile numbers
  • Unlimited SMS Towards all
  • 50 GB of data traffic under the 4G network with Hotspot included
  • COST: 7. 99 ?? per month
  • WHERE TO ACTIVATE IT: ONLINE or STORE
  • Activation COST + SIM: 9. 99 ??

GIGA 40

  • Unlimited Minutes of calls to all national fixed and mobile numbers
  • Unlimited SMS Towards all
  • 40 GB of data traffic under the network 4G with Hotspot included
  • COST: 6. 99 ?? per month
  • WHERE TO ACTIVATE IT: ONLINE or STORE
  • Activation COST + SIM: 9. 99 ??