Major Flaw In Android Can Let Hackers In With Just An MMS

Android is the most popular mobile operating system in the Universe: More than 80 percent of smartphones run on it. According to mobile security experts at Zimperium, there’s a gaping hole within the software program — one that might let hackers break into somebody’s cellphone and take over, just by sending a text. According to the BBC, this exploit could affect more than a billion phones world wide.

Just An MMS?

In this attack, the target would not need to open an attachment or download a file that is corrupt. The malicious code would take over immediately, the second you receive a text from the hacker or a compromised system.

“This happens even before the sound that you’ve received a message has even occurred,” says Joshua Drake, safety researcher with Zimperium and co-writer of Android Hacker’s Handbook. “That’s what makes it so dangerous. It might be absolutely silent. You may not even see anything.”

Here’s how the exploit would work: The ‘bad person’ creates a short video, hides the malware inside it and texts it to your number. As soon as the message is received by the cellphone, Drake says, “it does its initial processing, which triggers the vulnerability.”

The messaging app Hangouts immediately processes videos, to keep them ready in the smart phone’s gallery. That means the consumer does not have to waste time looking. But, according to Drake, this invites the malware right in.

If you are utilizing the telephone’s default messaging app, he explains, it is “a tiny bit less harmful.” You would have to view the textual contents before it processes the attachment. But, to be clear, “it doesn’t require in either case for the targeted person to need to play back the media at all,” Drake says.

Once the attackers get in, Drake says, they’d have the ability to do anything — copy or transmit the data, delete it, take over your microphone and camera to watch each and every word and move. “It’s really up to their imagination what they do as soon as they get in,” he says.

Solution

According to Zimperium, this set of vulnerabilities impacts nearly every Android cellphone in use. Drake says he found it in his lab, and he doesn’t believe that hackers are currently exploiting it — at least not yet.

In correspondence in April and May, he shared his findings with Google, which makes the Android operating system. He even sent along patches to fix the bugs.

“Basically, within forty eight hours I had an e-mail telling me that they’d accepted all the patches I sent which was nice,” he says. “You know, that is an excellent feeling.”

Adrian Ludwig, the lead engineer for Android safety at Google, stated that they’ve notified partners and already dispatched a fix to the smartphone makers that use Android.

Whether it gets to the people’s smart phones isn’t in Google’s hands.

According to security firm F-Secure, 99 percent of mobile malware threats in the first quarter of 2014 had been designed to run on Android devices.

Android phones are very completely different from iPhones, for instance. Apple runs a closed system: It controls the hardware and software, the iOS, and it is simple to ship out a major revamp. The firm says 85% of iPhone customers have the latest operating system.

Android Central, a famous blog, has described the challenge of updating the operating system as an “impossible problem.” Earlier this year, an exploit discovered in the Android Web-browsing app was left largely un-patched too.

Updated 5:21 p.m. 27 July: Google Issues Statement + response from companies

Google has said:

“We thank Joshua Drake for his contributions. The security of Android users is extremely important to us and so we responded quickly and patches have already been provided to partners that can be applied to any device.

“Most Android devices, including all newer devices, have multiple technologies that are designed to make exploitation more difficult. Android devices also include an application sandbox designed to protect user data and other applications on the device.”

Smartphone Manufacturers

HTC:

“Google informed HTC of the issue and provided the necessary patches, which HTC began rolling into projects in early July. All projects going forward contain the required repair.”

Silent Circle:

“We patched ‘Blackphone’ weeks in the past!”

Other manufacturers have yet to respond. We will update the page as soon as we get a response from them.

Update: Thanks to reddit user Patchsalts for correcting us. It should have been MMS instead of SMS

United Nation says encryption & anonymity vital to free speech

0
Data encryption is crucial to free speech, because it gives the privacy and safety essential in at this time’s digital age, a brand new United Nations report states. It calls on the US Congress to prohibit Washington from requiring corporations to offer “backdoor entry.”

“Encryption and anonymity, separately or together, create a zone of privacy to protect opinion and belief,” says the report written by David Kaye, a special rapporteur within the UN’s Office of the High Commissioner for Human Rights.

The report, which shall be introduced to the UN Human Rights Council in the coming month, comes as many governments try and put “back doors” in encryption programs to help law enforcement agencies.

Kaye speaks out in opposition to such back doors within the report, calling on the US Congress to “prohibit the Government from requiring companies to weaken product security or insert back-door access measures.”

“States ought to avoid all measures that weaken the security that individuals might enjoy on-line, such as backdoors, weak encryption standards and key escrows,” the report states, including that encryption is critical for artists, journalists, whistle blowers, and plenty of others.

In an interview with the Washington Post, Kaye stated back doors “lead to insecurity for everyone, even if intended to be for criminal law enforcement purposes.”

It comes as the United States continues to participate in an ongoing privacy debate, in an effort to balance privacy rights and national security.

 One aspect of the token is tech firms, many of which have rushed to encrypt their programs following Edward Snowden’s 2013 NSA revelations.

READ MORE: UK Police Admits to investigating journalists for covering Snowden files

However, Obama administration officials are pushing for encryption with a backdoor, or “master key,” which can be utilized by law enforcement and other agencies.

On Wednesday, US Attorney General Loretta Lynch echoed the administration’s wishes, stating that she has “grave concerns” about encryption being utilized by “individuals whose sworn duty is to hurt Americans here and abroad.”

Speaking at a cyber warfare convention on Wednesday, National Security Agency’s director Mike Rogers stated encryption is “not bad,” and that it’s a “fundamental part of the future.”

However, he continued by asking whether or not it was possible to create “some mechanism” which permits governments to “access info that directly pertains to the safety of our respective nations” whereas being “conscious” that citizens’ rights have to be protected.

The reply to Rogers’ question, according to Kaye, is a clear-cut “no.” Kaye says that compromised encryption will merely weaken everybody’s safety on-line.

He added that those with the abilities to exploit the weak factors of compromised encryption would be capable to simply achieve this – whether or not those individuals had been “State or non-State, legitimate, or criminal.”

The report, which has been welcomed by encryption advocates, additionally warns against state prohibitions of anonymity on-line – together with real-identify registration, SIM card registration, or banning of anonymity instruments such as Tor (or the upcoming HORNET), adding that such requirements intrude with the freedom and liberty of expression.

Russia’s Stealthy Fifth Generation Nuclear Bomber in Big Trouble

Speaking at the Samara-based Kuznetsov Plant of the United Engine Corporation, a Russian defense company, Russian Deputy Defense Minister Yuri Borisov told reporters that manufacturing of the PAK DA has been delayed so that Tupolev Tu-160M2 bomber’s production can be resumed.

russian tu 160
A Russian Tu-160 about to takeoff

The Kremlin planned on introducing its fifth-generation PAK DA bomber into service beginning in 2023. However, the PAK DA project has been pushed back again and Russia will instead concentrate on manufacturing of an updated version of the Soviet-era Tu-160 (Russian: Туполев Ту-160, NATO reporting name: Blackjack) supersonic nuclear bomber.

“According to the plans, serial production of the [Tu-160] aircraft new version [the Tu-160M2] is to be implemented starting from 2023,” Russian Deputy Defense Minister Yuri Borisov told at a press conference on 17th July. “The PAK DA project will be somewhat shifted beyond [2023], otherwise there is no sense in it.”

According to Russia Beyond the Headlines, the decision to begin constructing the updated Tu-160M2 at the expense of the fifth-generation PAK DA was made by Russian President Vladimir Putin in May.

According to the National Interest, this decision to modernize the Tu-160 , when the Russian Economy is in a tumble could ultimately lead to the complete abandonment of the PAK DA. The enhancements that the new TU-160M2 will feature embody many designs that were intended for the PAK DA, and the modernized aircraft is “also expected to have a service life of around 40 years.”

Among the upgrades for the TU-160M2 are a newly modernized engine that will enhance the plane’s flight range by over a thousand kilometers, along with several new missiles that will improve the aircraft’s combat capabilities, IHS Jane’s 360 notes.

This is not the only occasion of Russia having to scale back on its military modernization ambitions. The Kremlin is also facing problems in financing its third-generation Armata tank. Harvard scholar Dmitry Gorenburg estimates that Russia will only be able to field a maximum of 330 Armata tanks by 2020, a fraction of the 2,300 initially planned.Moreover, the Moscow Times reported that the programs which have experienced a delay on account of sanctions include: “manufacturing of Navy guard ships, Beriyev Be-200 amphibious planes, Vikhr anti-tank missiles, remote control & radio monitoring equipment for Igla surface-to-air missiles, and weapon launch systems for Tupolev-160 strategic bomber planes.”

Moscow’s failure to follow projections for top notch weaponry is a common theme. There’s a pattern of Russia announcing huge projects before drastically scaling back its plans. In March, for example, Russian media outfit RT announced that Kremlin would eventually be able to deploy eighty PAK TA transport super-planes — even though Russia has not made a single prototype of the aircraft.

In scaling back the Armata and these two advanced aircraft, the Russia clearly realizes that it is significantly easier and more cost efficient to modify existing programs for future use — although it isn’t as exciting from a propaganda point of view.

UK Police Admits To Investigating Journalists For Covering Snowden Files

0

Remember when a journalist David Miranda was detained at the Heathrow Airport for 9 hours during transit in 2013? The reason given was an anti-terrorism regulation, indirectly claiming that journalism can be terrorism. Apparently, UK law enforcement is doubling down on that claim, with a the brand new admission that there is an ongoing and open criminal investigation into the reporters who’ve printed from the  Snowden leaks.

Snowden’s first disclosures from the National Security Agency (NSA) had been revealed in June 2013 by Glenn Greenwald in The Guardian, a UK based newspaper. Greenwald, now residing in Brazil, left in October 2013 to co-found The Intercept.

The Guardian’s revelations included particulars about dragnet D.R. Internet spying operations, the publicity of which infuriated high British authorities officers and led to the newspaper being pressured into destroying exhausting drives containing copies of the paperwork.

Apparently the UK law enforcement has gone bonkers and are going to great lengths to intimidate journalists, even once forcing the Guardian to destroy a laptop which contained the Snowden files, sighting the ‘National Security’.

A secretive British police investigation focusing on journalists working with Edward Snowden’s leaked paperwork stays ongoing two years after it was quietly launched.

The intimidation has been taken up a notch. Greenwald’s new publication, the Intercept, has been engaged in an ongoing Freedom of Information battle with the Metropolitan Police Service of UK to find out out if the Met is investigating journalists, and the police, after denying to confirm for many months, have finally confirmed in an email to Ryan Gallagher, an author of The Intercept, that the police is in fact still criminally investigating those journalists involved with the Snowden files. The email from the Police states that:

“the mps can confirm that it continues to conduct investigation into the events as described above”

As the reporters didn’t really commit a crime, it appears that the only motive for the investigation is to harass journalists who may publish such articles or might do so in the future.

The Intercept reports that:

“The main reason the investigation is still carrying on is probably to create a degree of uncertainty around journalists and their advisers about what can and cannot be done in terms of carrying documents,” said Stephens, who is a companion at London firm Howard Kennedy. “They are trying to shake down and instill fear into journalists and discourage them from exposing issues that have to do with national security.”

 

Links in the Article

 

 

Google incorporating a truth score; anti-vax & conspiracies to rank lower

3

THE web is full of rubbish. Conspiracy theories, anti-vaccination sites and fact-free “information” constantly makes first page results on the most visited search engine of the world, Google. Google may have a cure – rank websites according to their truthfulness.

Currently, the search giant counts the number and variety of incoming hyperlinks to a domain and page as a proxy for the quality and popularity, determining where it appears in search results. So pages that many other websites link to are ranked high. This system has given us the search engine as we all know it at present, however, the system can be abused by ‘shady’ websites by making a large number of spammy links pointing to their own sites. Many firms today provide ‘SEO services‘, and claim that they can bring your site at the top of search results using certain keyword.

New Scientist’s Hal Hodson reports on the proposed Knowledge-Based Trust rating:

The software works by tapping into the Knowledge Vault, the vast store of facts that Google has pulled off the internet. Facts the web unanimously agrees on are considered a reasonable proxy for truth. Web pages that contain contradictory information are bumped down the rankings.

Google has recently implemented a form of Knowledge-Based Truth rating with its medical search results. Now, doctors and medical experts vet search results about health issues, which means tha anti-vaccination propaganda is not going to appear in the top for a “autism” search, for example.

Top Fifteen Images from the Space & Beyond

0

 

These are the best ever images of our marvelous universe (or the little that we know of). We have shortlisted the top 15 images from the hundreds, mostly taken by the Hubble Space Telescope. All on one page, unlike blogs or sites that force you to click 20 pages for 10 pictures, with proper credits. The last 10 photos have actually been selected by Zoltan Levay, the imaging team leader at Space Telescope Science Institute for the National Geographic.

[rev_slider top10space]

 

If you like these, please share the post so others can benefit too! Thanks

Special thanks to https://hubblesite.org/ for providing us with the images! You can visit them for many more photographs and the wonderful stars and galaxies!

Get paid to park your car at the Airport? Now there’s an app for that!

Getting a free automobile wash and vacuuming and the airport sounds good. What’s even higher is getting paid for leaving your automotive.

flightcar pickup
When you come back, FlightCar will ship you directions in your airport pickup and take you again to their location. If your automotive was rented, your verify can be within the mail!

FlightCar, a peer-to-peer car sharing service operating at airports, also being hailed as an Airbnb for cars, has launched its new iPhone app. When you park at the airport, FlightCar workers park and wash your automobile, at no cost—and will rent your car to different travelers. If so, you get will paid. The service was first launched from San Francisco International Airport, USA in February 2013. It has now expanded operations to 14 airports across the United States, with plans to expand even more.

“It’s not really a rental car company and it’s not really a parking company; it’s sort of in the middle,” said co-founder and President Kevin Petrovic.

Petrovic and co-founder CEO Rujul Zaparde — both aged 20 and Ivy League dropouts — say they are tapping into the market that makes apps and websites that grant fill to loan or sell their private holding, lodging, clothes or car to someone else for a fee, like Airbnb, Poshmark, Getaround, Thredup and dozens of others.

“More people are going to have extra assets that they may not need and are willing to share it, and other people are willing to rent it at the right price. It is good for the economy overall and it’s good for the individual.” said Hans Tung, managing partner at GGV Capital, which led a $13.5 million financing round for FlightCar in 2014.

How does it Work?

FlightCar lets folks parking at the airport rent their automobiles out to other pre-screened traveling members. Every rental is insured up to a million dollars and they guarantee you a clean car when you come back. Apart from that, members also get free parking, and if their car gets rented out,  they get paid depending on the model of the car, the airport they left it at and the number of miles it gets driven.

car rental
Available only from the iOS right now, the company may launch an android version soon

You can estimate your payout at this page. Flightcar claims that members who rent using their service get the lowest rental charges compared to the market, with free insurance coverage and free extras. There is no sign up fees for new members.

Boeing and “Hacking Team” wants to implant spywares via Drones

There are a number of ways in which government agencies, hackers and spooks can steal data from your computer, however Insitu, a subsidiary of Boeing, an American multinational corporation that makes and sells airplanes, rotor craft, rockets and satellites etc, would love to have the ability to deliver spyware through drones.

The plan is described in internal emails from the Italian firm ‘Hacking Team‘, which makes software programs that can remotely infect a suspect’s computer or smartphone, accessing information and recording calls, chats, emails and more. Recently, hackers were able to penetrate Milan-based company earlier this month and they released hundreds of gigabytes of company information online. Wikileaks has published them here: https://wikileaks.org/hackingteam/emails/

Among the emails is a recap of a meeting in June of this year, which gives a “road map” of projects that Hacking Team’s engineers are currently involved in.

scaneagle
ScanEagle prototype in Flight – Insitu

The request seems to have originated with a question from the Washington-based Insitu, which makes a variety of unmanned systems, including the small ScanEagle surveillance drone, which has long been used by the militaries various countries, including the United States. Insitu additionally markets its drones for law enforcement.

An Insitu engineer wrote to Hacking Team this April: “We see potential in integrating your Wi-Fi hacking functionality into an airborne system and would be interested in starting a dialog with one of your engineers to go over, in more depth, the payload capabilities including the detailed dimensions, weight, and power specs of your Galileo System.” (Galileo is the title of the latest version of Hacking Team’s spyware, generally known as Remote Control System.)

In an internal email, a Hacking Team account supervisor suggests that they could do so using a “TNI,” or “tactical network injector.” A TNI is a portable, physical device, which an operator can use to plug into a network the target is using — such as an open Wi-Fi network in a restaurant or a cafe. When the targeted individual uses the Internet for any task, like reading the news or watching a video, the device intercepts that traffic and injects the malicious code that secretly installs Hacking Team’s spyware.

Hacking Team gained notoriety in recent times as human rights and digital security advocates discovered traces of its spyware on the computer systems of journalists and political activists from Ethiopia, Morocco and elsewhere. The leaked information confirmed that Hacking Team sold its merchandise to many countries with dubious human rights records, and also to agencies in the USA, where the use of such spyware continues to be the subject of controversy.

History: The Apache Gun Revolver

This distinctive Swiss Knife of weapon’s is known as the Apache Gun Revolver, also referred to as the Apache Knuckle Duster Pepperbox Antique French Revolver and it was designed and patented in 1869 by a Frenchmen known as Louis Dolne.

  apache revolver apache gun 2 

 It was mostly used and made popular by the Les Apaches, the French underworld figures of the early 1900s. A 9 mm revolver of similar design (without any official recognition) was allegedly used by British commandos during the World War II, although precise statistics about manufacturing numbers and technical details are still classified.

apache gun

apache revolver
Source: Wikimedia

 

As you can see, there is no barrel, due to which the revolver’s effective range is very restricted, however since all of its parts can be folded inward towards the cylinder, it is easily concealable inside a pocket.

apache revolver

It was common to leave an empty chamber with no cartridge underneath the hammer to prevent shooting oneself while having it concealed in a pocket, because the weapon has no trigger guard or safety. This weapon isn’t capable of being aimed precisely due to its lack of front and rear sights. Despite its limited potential, the revolver proved lethal at close range.

Video from texasgunblog.com’s YouTube Channel:

 

Two must-have technologies to access your workstation remotely from anywhere – Hosted Cloud Desktop and SharePoint Hosting Service with 24*7 tech-support powered by one of the best DaaS provider – Apps4Rent, Add complete office suite to the same workstation by visiting www.O365CloudExperts.com.

Instagram finally upgrading their image resolution!

Until now, all footage uploaded on the favored Instagram service had been saved at a meager 640 x 640 pixel decision, actually not sufficient to make the most of larger and higher shows like Retina. Just some months in the past, that decision was worse than the 640s, it was 615 x 615! Many customers have been complaining of high quality and measurement discount in photographs uploaded to Instagram.

Well, on 3rd July 2015, it seems, Instagram has began addressing that very situation, as pictures sent to the popular image sharing app are now being saved in a better 1080 x 1080 size. This means the quality (if measuring by number of pixels) will increase by almost 3 times! Although, still not at par with high end devices, the upgrade is still significant.

This change isn’t ‘official’ yet. The higher-resolution photos aren’t yet being displayed as such by Instagram, which maintains its smaller default for now. But a quick look at the source code reveals that new images uploaded to it are being saved in 1080 x 1080 pixels. We expect that Instagram will soon announce the update, possibly in the coming weeks, along with changes to its API. There has been no word by Instagram on this development

To see the 1080px pictures on Instagram, use a browser to open up an Instagram photo page’s source code, then search for “.jpg” inside it. The first result ought to be the URL to the larger version of the image. It may look something like this: https://gadgtecs.com/wp-content/uploads/2015/07/11357838_1422850654710351_1818444069_n1.jpg
These aren’t merely 640px photos stretched out to fill the larger canvas; but genuinely higher quality pictures. Even the present version of Instagram’s apps are storing the images in this higher quality, so an app update won’t be needed.
Comparison: Instagram’s older 640px vs the newer 1080px

A photo posted by GadgTecs (@gadgtec) on

better quality picture
1080x