Tag Archive for: read

UIDAI Seeking 20 Ethical Hackers to Protect Its Data, Plug Security Bugs. Read Details


New Delhi: Amid increasing cyber attacks against key infrastructure and government websites in India, the Unique Identification Authority of India (UIDAI) has quietly announced a “bug bounty programme” to hire 20 ethical hackers to protect its website and resources from nation-state bad actors. The recently-issued circular said that the programme will be limited to 20 registered candidates. “The UIDAI reserves the right to evaluate and select top 20 suitable candidates for participation in the programme,” the authority said in its circular.Also Read – Meta Likely to Invest $3 Million in Indian Startup ‘Better Opinions’: Report

It added that the candidate should be listed in the top 100 of the bug bounty leaders board such as HackerOne, or Bugcrowd. The candidate may also be listed in the bounty programmes “conducted by reputable companies such as Microsoft, Google, Facebook, Apple etc. or the candidate should be active in the bug bounty community/programmes and should have submitted valid bugs or received bounty in the last one year”. Also Read – What Are The Top Brands For Hackers to Steal People’s Data Via Phishing?

The bug bounty programme of the UIDAI comes at a time when earlier reports claimed that Chinese state-sponsored hackers allegedly infiltrated and stole data from it. The authority allayed the fears, saying, the leaking of Aadhaar numbers will not pose any hacking threat to bank accounts. Also Read – Aadhaar FaceRD App Launched By UIDAI | Here’s How You Can Confirm Your Identity With Face Authentication

‘Like just by knowing your ATM card number….’

“Just as by merely knowing your ATM card number, no one can withdraw money from the ATM machine; by knowing your Aadhaar number alone, no one can hack into your bank account and withdraw money,” the UIDAI said while posting some myth busters related to Aadhaar on its website. “Rest assured, there has not been a single case of financial loss due to Aadhaar. Aadhaar number alone cannot be used for banking or any other service,” it added.

Independent committee to assess candidates

The UIDAI said an independent committee will be formulated to assess and verify the candidates’…

Source…

Apple Can ‘Secretly’ Read Your WhatsApp Messages—This Is How To Stop It


Apple’s iPhone has broken Facebook’s business model this year, stripping billions in ad revenue from the social media giant. Now it seems the iPhone can also break WhatsApp’s huge new security update, unless millions of you change your settings.

“No other messaging service provides this level of security for your messages,” WhatsApp proudly told me in September, as Mark Zuckerberg proclaimed WhatsApp the first global platform “to offer end-to-end encrypted messaging and backups.” Unfortunately, a fairly well-hidden setting on your iPhone might stop this working, putting all those private WhatsApp messages where Apple can read them.

WhatsApp’s messages have been secured by end-to-end encryption for years. The issue that Facebook fixed was the security wrapper around the messaging platform’s cloud backups, hosted courtesy of Google Cloud for Android and Apple iCloud for iOS.

Until now, WhatsApp’s cloud backups have been outside its encryption, meaning that Apple or Google can access your chats and media. Law enforcement requests on Apple for iCloud data could return WhatsApp backups along with everything else. But by adding encryption, WhatsApp stops anyone but you from accessing your backups.

I have warned about the dangers of unencrypted backups multiple times. “We figured you’d be excited about this one,” WhatsApp’s spokesperson said when they called to tell me that encrypted backups was ready and set for deployment. And now it’s here. The only problem is the way Apple sets up its iPhone could spoil the party.

The issue is the iCloud backup itself—the general iPhone backup that you can use to restore your settings, home screen, app installs and data that’s only on your phone. Your iCloud backup isn’t end-to-end encrypted, Apple holds the key to all that data.

Zuckerberg has attacked iMessage in the past for security weaknesses relating to this iCloud backup. “iMessage stores non-end-to-end encrypted backups of your messages by default unless you disable iCloud,” he has warned. “Apple and governments have the ability to access most people’s messages. So, when it comes…

Source…

In Worrisome Development, ‘Skimmers’ Hack Gas Pumps to Read Credit Cards


A “skimmer” circuit board found inside a gas pump in San Diego County. Courtesy San Diego County Agriculture, Weights and Measures

A former San Diego Police Officer, Larry Avrech, had gotten a heads up from another former cop about keys being sold on the Internet that could open up gas pumps. Their first question was, is this legal?

Their second question was, why would anyone want to open up a gas pump?

The images Avrech found online showed two “gas pump replacement lock keys.”

The answer comes from Brian Krebs, a former newspaper reporter who is an expert on computers and Internet security. 

“For decades, only a handful of master keys were needed to open the vast majority of pumps in America,” Krebs said. “That has changed, but I bet there are some older stations that haven’t yet updated their locks.”  

Source…