Assata Shakur Speaks - Hands Off Assata - Let's Get Free - Revolutionary - Pan-Africanism - Black On Purpose - Liberation - Forum  

Assata Shakur Main Forum Portal Arcade Links/Downloads TTDC Search RBG Tube Warrior Chat Store Free Email Donate News
Go Back   Assata Shakur Speaks - Hands Off Assata - Let's Get Free - Revolutionary - Pan-Africanism - Black On Purpose - Liberation - Forum > Help, Suggestions And Security Center > P C Tech Advice & Technology
Forgot Password? Register

P C Tech Advice & Technology Post your PC related problems, share info related to the internet, test your avatars or images here.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-20-2008
Jahness's Avatar
OniOni Warrior
 
Join Date: Mar 2005
Location: In amerikkka! Stolen from Afrika!
Posts: 6,819
Thanks: 1,681
Thanked 1,112 Times in 695 Posts
Gender: Sister
Rep Power: 562
Jahness has a reputation beyond reputeJahness has a reputation beyond reputeJahness has a reputation beyond repute
Jahness has a reputation beyond reputeJahness has a reputation beyond reputeJahness has a reputation beyond reputeJahness has a reputation beyond repute
Arrow Protecting against Wi-Fi, Bluetooth, RFID data attacks

Protecting against Wi-Fi, Bluetooth, RFID data attacks

Protecting against Wi-Fi, Bluetooth,
RFID data attacks


By Elinor Mills,
CNET

NEW YORK--Using a laptop, cell phone headset, building access badge, credit cards, or even a passport can make you a walking target for data thieves and other criminals, a security expert warned at the Last HOPE hacker conference here late Friday.

In a frightening but entertaining session entitled "How do I Pwn Thee? Let me Count the Ways" (pwn is hacker speak for "own" or control), a hacker who goes by the alias "RenderMan" explained how most people are at risk and don't even know it.

By now most people probably know they should be careful using Wi-Fi networks, especially public hotspots that don't encrypt data transmissions and where network access points can be spoofed. These issues leave Web surfers at risk of having their data stolen, receiving fake Web pages and other information, and having their computers completely taken over, he said.

Even airplane passengers who either ignore stewardess requests to disable Wi-Fi or don't know how to turn it off are not immune to attacks from others in the airplane, he added.

RenderMan suggests that people disable Wi-Fi when it is not in use and use VPNs and firewall software.

Bluetooth headset users are at risk because of a security hole in the technology and default PINs that don't get changed, he said. Exploiting vulnerabilities someone can break in and steal data from the phones, make calls without the cell phone owner knowing, listen in on and break into conversations, and even spy on people by turning the device into a bug.

He advises that people change the default password, disable the Bluetooth on the phones, turn off the headsets when not in use, and limit access to the data and features when communicating with other Bluetooth devices.

Many people don't realize that new U.S. passports have RFID technology with weak encryption that makes the data on the chip easy to read with the proper reader device. (See related video below).

The U.S. government attempted to mitigate the privacy threat by putting a metal foil layer on the front and back cover of the passports, but the stiffness of the foil pops the passport open as much as an inch, wide enough for RFID readers to snatch the data, RenderMan said, showing a video to demonstrate this.

"There is no rule that says that if the chip doesn't work, they will refuse you access to the border. You will get increased scrutiny, but it's still a valid document," he said. "So, liberal application of a hammer can negate a lot of the possible" problems.

But doing willful damage to the passport is a crime, one attendee pointed out. "I fell, really hard," RenderMan deadpanned.

RFID used in transit and building access badges has also been proven to be insecure, allowing someone to use an RFID reader to copy data off the card and make a clone of it, he said.

A security flaw in the Mifare Classic Chip used in transit systems is the subject of a court case in The Netherlands. The maker of the chip, NXP Semiconductors, sued to block a university from publishing details of the problems, but a court ruled on Friday that the research can be made public.

Even traditional keys are vulnerable, RenderMan said. For instance, photographs of spare keys for electronic-voting machines displayed on a Web page were used to make replicas with similar-looking keys, he said. A video demo showed how someone filed down a key from a hotel mini-bar and was able to open up the memory card slot of a Diebold voting system.

Credit: CNET News Michael Aiello, president of DIFRwear, demonstrates at Last HOPE how easy it is to swipe the data off someone's RFID-enabled credit card, building access badge, or passport from a few feet away. DIFRwear sells wallets and cases to protect cards from data thieves.

Protecting against Wi-Fi, Bluetooth, RFID data attacks - Yahoo! News

Copyright © 2008 CNET Networks, Inc., a CBS Company.
__________________
Posted In The Spirit of Learning & Sharing
One Love & Respect Always

***************************************
The Quest for knowledge stops at the grave.
HIM Emperor Haile Selassie I.


If you fail to prepare,
you are preparing to fail!


Mind what you want, because someone wants your mind.

Working together, the ants ate the elephant.

Reply With Quote
The Following User Says Asante sana to Jahness For This Useful Post:
Moorbey (07-20-2008)
Reply

Lower Navigation
Go Back   Assata Shakur Speaks - Hands Off Assata - Let's Get Free - Revolutionary - Pan-Africanism - Black On Purpose - Liberation - Forum > Help, Suggestions And Security Center > P C Tech Advice & Technology

Bookmarks

Tags
attacks, bluetooth, data, protecting, rfid, wifi


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
IT Channel Seeing Growth in RFID Projects, CompTIA Survey Reveals Jahness P C Tech Advice & Technology 0 08-05-2008 11:46 PM
RFID Tracking Allows Prisons to More Closely Monitor Inmates Moorbey Prison / Police Industrial Complex 2 07-17-2008 07:45 PM
Can We use RFID technology for accessible information? Pragmatic Open Forum 19 05-13-2008 11:48 AM
Encryption takes a hit as new flaws surface in Bluetooth and AES Jahness P C Tech Advice & Technology 0 06-14-2005 07:45 PM
Mozilla flaws could allow attacks, data access Jahness P C Tech Advice & Technology 0 04-20-2005 12:31 PM


New To Site? Need Help?

All times are GMT -4. The time now is 06:43 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2
The Talking Drum Collective
Page generated in 1.35213 seconds with 16 queries
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147