Tag Archive for: broken

Hopelessly broken wireless burglar alarm lets intruders go undetected

Enlarge (credit: SimpliSafe.com)

A security system used in more than 200,000 homes has an unfixable flaw that allows tech-savvy burglars to disarm the alarm from as far away as a few hundred feet.

The wireless home security system from SimpliSafe is marketed as costing less than competing ones and being easier to install, since it doesn’t use wires for one component to communicate with another. But according to Andrew Zonenberg, a researcher with security firm IOActive, the system’s keypad uses the same personal identification number with no encryption each time it sends a message to the main base station. That opens the system to what’s known as a replay attack, in which an attacker records the authentication code sent by the valid keypad and then recycles it when sending rogue commands transmitted over the same radio frequency.

“Unfortunately, there is no easy workaround for the issue since the keypad happily sends unencrypted PINs out to anyone listening,” Zonenberg wrote in a blog post published Wednesday. “Normally, the vendor would fix the vulnerability in a new firmware version by adding cryptography to the protocol. However, this is not an option for the affected SimpliSafe products because the microcontrollers in currently shipped hardware are one-time programmable. This means that field upgrades of existing systems are not possible; all existing keypads and base stations will need to be replaced.”

Read 4 remaining paragraphs | Comments

Technology Lab – Ars Technica

Have you broken your security resolutions yet?

Keeping your resolutions
New year's resolutions

Image by Usodesita

We are almost halfway through the first month of 2016 and I am sure many people have already let their personal resolutions fall apart. But what about your professional resolutions? How have they held up? Is it easier to shore up your network’s security than exercise every day? These security professionals offer up their resolutions for the new year.

To read this article in full or to leave a comment, please click here

Network World Security

No more excuses: Google needs to fix Android’s broken update system – BGR


BGR

No more excuses: Google needs to fix Android's broken update system
BGR
At some point, says Armasu, Google will need to take charge of Android security updates whether carriers and OEMs like it or not. Given how slow Google has been in reacting to these kinds of issues, however, it seems such a major step is still likely
Google and Samsung offer monthly Android security updatesOR-Politics.com
Samsung To Release Android Security Updates Each MonthSentinel Republic
Android Security Patches Not Enough to Stop Stagefright ExploitChristianity Daily
PPP Focus.com –eWeek
all 371 news articles »

“android security” – read more

Broken NFC terminals, lack of retail support stifling Apple Pay usage

Apple Pay got off to a hot start after its debut in October, attracting 11% of all credit card-using households and converting 66% of iPhone 6 users in its first four months on the market, according to an ongoing study of more than 3,000 credit card users conducted by market research firm Phoenix Marketing International.

Although iPhone users appeared eager to try out Apple’s new mobile payment plan – the study estimates that more than 88% of those who set up an Apple Pay wallet went on to make a purchase with it either in a retail store or in a mobile app – they have run short on opportunities to use them in the time since.

“The demand is there: 59% of Apple Pay users have gone into a store and asked to make a purchase with Apple Pay,” Greg Weed, Phoenix Marketing International director of research, said in a statement. “But so is the disappointment: 47% visited a store that was listed as an Apple Pay merchant only to find out that the specific store they visited did not accept (or were not ready to accept) Apple Pay.”

To read this article in full or to leave a comment, please click here

Network World Colin Neagle