Showing posts with label Skype. Show all posts
Showing posts with label Skype. Show all posts

Friday, January 18, 2013

PSA Security & Hacking: Shylock Banking Trojan now spreading via Skype

Primary source https://www.csis.dk/en/csis/blog/3811

As someone that is computer security conscious, I avoid online banking completely.

For friends, family, & others that insist on online banking I suggest either of the following:

  • Use a Live CD, Brian Kreb has excellent articales on how to do this http://krebsonsecurity.com/2012/07/banking-on-a-live-cd/ or http://krebsonsecurity.com/banking-on-a-live-cd/
  • Use a recent iOS device, iPhone 4S or newer, iPad 2 or newer, iPod Touch 5th generation or newer.  There are significant hardware security improvements that started with those respective devices. 
I also strongly suggest if using the iOS devices, to turn off Simple Passcode, and use a Pass Phrase, even if you don't lock your iOS device all the time, this will enable whole device encryption.

Clear instructions & screenshot for turning off Simple Passcode http://www.computerworld.com/s/article/9231627/Kenneth_van_Wyk_Shutting_down_security_gotchas_in_iOS_6?taxonomyId=17&pageNumber=1

The reason for this, is that a hacker with right software, can use a computer to try passwords, they can also bypass the 10 try feature.

So if your using the Simple Passcode, which is just a 4 digit number, they will probably be able to hack it in less than an hour.

However, if you use a Pass Phrase, like I <3 my iPad.  I hate green beans! the hacker will have a much more difficult time.  [Note, don't use that pass phrase, it is just to illustrate the concept.]

Since instead of only 4 numbers, there are 34 characters, counting the blank spaces, plus your using uppercase letters , lowercase letters, numbers, special characters, and blank spaces.

The hacker won't have any idea how long your password is, and by using at least one of all possible upper/lower case, numbers, symbols, and blank spaces you make hackers job a lot harder.

For more on passwords see http://cliffsesportcorner.blogspot.com/2012/05/steve-gibsons-haystacks-needles.html

Additional links:


Wednesday, November 14, 2012

PSA Security & Hacking: Skype Password Reset Exploit

Edited to add:  Skype is Patched now

http://heartbeat.skype.com/2012/11/security_issue.html
[UPDATE:14/11/2012@15:28GMT]
Early this morning we were notified of user concerns surrounding the security of the password reset feature on our website. This issue affected some users where multiple Skype accounts were registered to the same email address. We suspended the password reset feature temporarily this morning as a precaution and have made updates to the password reset process today so that it is now working properly. We are reaching out to a small number of users who may have been impacted to assist as necessary. Skype is committed to providing a safe and secure communications experience to our users and we apologize for the inconvenience.

*****************

This story is breaking all over net now, I like Sophos Naked Security's article the best http://nakedsecurity.sophos.com/2012/11/14/skype-security-hijack/

They refer to this article http://thenextweb.com/microsoft/2012/11/14/security-hole-allows-anyone-to-hijack-your-skype-account-using-only-your-email-address/

Supposedly this has been used in the wild for months, evidently posted about on Russian forums that long ago.

Official Skype statement from http://heartbeat.skype.com/2012/11/security_issue.html:
We have had reports of a new security vulnerability issue. As a precautionary step we have temporarily disabled password reset as we continue to investigate the issue further. We apologize for the inconvenience but user experience and safety is our first priority 

Don't have any other details to provide at the moment.