Searching for "hacker"

Cybersecurity Risks in schools

FBI Warns Educators and Parents About Edtech’s Cybersecurity Risks

By Tina Nazerian     Sep 14, 2018

https://www.edsurge.com/news/2018-09-14-fbi-warns-educators-and-parents-about-edtech-s-cybersecurity-risks

The FBI has released a public service announcement warning educators and parents that edtech can create cybersecurity risks for students.

In April 2017, security researchers found a flaw in Schoolzilla’s data configuration settings. And in May 2017, a hacker reportedly stole 77 million user accounts from Edmodo.

Amelia Vance, the director of the Education Privacy Project at the Future of Privacy Forum, writes in an email to EdSurge that the FBI likely wanted to make sure that as the new school year starts, parents and schools are aware of potential security risks. And while she thinks it’s “great” that the FBI is bringing more attention to this issue, she wishes the public service announcement had also addressed another crucial challenge.

“Schools across the country lack funding to provide and maintain adequate security,” she writes. “Now that the FBI has focused attention on these concerns, policymakers must step up and fund impactful security programs.”

According to Vance, a better approach might involve encouraging parents to have conversations with their children’s’ school about how it keeps student data safe.

++++++++++
more on cybersecurity in this IMS blog
https://blog.stcloudstate.edu/ims?s=cybersecurity

blockchain fixes

187 Things the Blockchain Is Supposed to Fix

Erin Griffith 

https://www-wired-com.cdn.ampproject.org/c/s/www.wired.com/story/187-things-the-blockchain-is-supposed-to-fix/amp
 
Blockchains, which use advanced cryptography to store information across networks of computers, could eliminate the need for trusted third parties, like banks, in transactions, legal agreements, and other contracts. The most ardent blockchain-heads believe it has the power to reshape the global financial system, and possibly even the internet as we know it.
 
Now, as the technology expands from a fringe hacker toy to legitimate business applications, opportunists have flooded the field. Some of the seekers are mercenaries pitching shady or fraudulent tokens, others are businesses looking to cash in on a hot trend, and still others are true believers in the revolutionary and disruptive powers of distributed networks.
 
Mentions of blockchains and digital currencies on corporate earnings calls doubled in 2017 over the year prior, according to Fortune. Last week at Consensus, the country’s largest blockchain conference, 100 sponsors, including top corporate consulting firms and law firms, hawked their wares.
 
Here is a noncomprehensive list of the ways blockchain promoters say they will change the world. They run the spectrum from industry-specific (a blockchain project designed to increase blockchain adoption) to global ambitions (fixing the global supply chain’s apparent $9 trillion cash flow issue).
 

Things Blockchain Technology Will Fix

  • Bots with nefarious intent
  • Skynet
  • People not taking their medicine
  • Device storage that could be used for bitcoin mining
  • Insurance bureaucracy
  • Electronic health record accessibility
  • Health record storage security
  • Health record portability
  • Marine insurance risk
  • Cancer
  • Earning money on personal data
  • Pensions
  • The burden of car ownership
  • Inability to buy anything with cryptocurrency
  • Better marketplaces for nautical shipping services
  • Better ways to advertise to your friends
  • Better ways to trade forex with your friends
  • Ownership shares in ancient sunken treasures
  • Poverty
  • Complying with Know Your Customer laws
  • Complying with Anti-Money-Laundering laws
  • Complying with securities laws in token sales
  • Censorship
  • A use for QR codes
  • Rewards for buying alcohol by subscription
  • Tracing water supplies
  • Dearth of emergency responders
  • High cost of medical information
  • Improved digital identity authentication
  • Managing real estate workflow
  • International real estate purchases
  • Physical branches for crypto banking
  • Physical branches for crypto exchanges
  • Private equity
  • Venture capital
  • AIDS, also online sales of classic Japanese domestic cars
  • Efficiency and transparency at nonprofits
  • Incorporating local preferences in decentralized banking options
  • Boosting sales for local businesses
  • A digital-only investment bank
  • Containers to transport sensitive pharmaceuticals and food
  • Protecting consumer information on mobile
  • Helping mobile phone users monetize their data
  • Not enough interconnection in the world
  • Complexity and risk in the crypto market
  • Expensive AI research
  • Counterfeit goods
  • Connecting “innovation players” and “knowledge holders”
  • Movie industry’s slow and opaque accounting practices
  • Global supply chain’s $9 trillion cash flow issue
  • Trust in the global supply chain
  • Economic crisis
  • Cash flow problems at small and medium-sized businesses
  • Improving the use of data in the transportation and logistics industries
  • Poverty among African farmers
  • Transparency in the food supply chain
  • Ad fraud
  • Fake news
  • False news
  • Settling payments faster
  • Speeding transactions
  • The unbanked
  • The underbanked
  • The bidding process in art and collectibles markets
  • Assessing the value of collectibles
  • Diamond industry’s high banking and forex fees
  • The illicit diamond trade
  • Availability of digital games
  • Currency for eSports
  • Currency for eSports betting
  • Currency for sports betting
  • Storing scholarly articles
  • Health insurance providers billing processes
  • Currency for healthcare providers
  • Shortage of workers with advanced tech skills
  • Lack of diversity in tech
  • Elder care
  • Rights management for photographers
  • Content rights management
  • Simplifying the logo copyrighting process
  • Ticketing industry’s “prevalent issues”
  • Crowdsourcing for legal dispute resolution
  • Securing financial contracts
  • Paper
  • Automation
  • Control of personal data
  • Control of personal credit data
  • No way to spend crypto
  • Advertising for extended reality environments
  • Human suffering
  • Security for luxury watches
  • Authenticity in cannabis sales
  • Crypto rewards for cannabis-focused social media site
  • Crypto payments for rating cryptoassets
  • Crypto payments for taking surveys, watching videos and clicking links
  • Crypto rewards for video game skills
  • Crypto rewards for time spent playing video games
  • Buying, selling and trading your social media friends
  • Crypto rewards for social media sharing
  • Free mobile data for watching ads
  • Crypto rewards for watching entertainment content
  • Gold-backed cryptocurrency
  • Crypto-backed gold
  • Metals-backed cryptocurrency
  • Precious metals-based cryptocurrency
  • “Tokenizing” real world items
  • Nashville apartment buildings
  • Monaco real estate
  • Financial infrastructure for trading within video games
  • Checking ID for purchases like alcohol
  • “Uber for alcohol” on blockchain
  • Inefficiencies in cargo delivery
  • Branded tokens for merchants to reward customers
  • Fraud and corruption among non-profits
  • Better transparency at non-profits
  • Better transparency around impact investing
  • Bitcoin mining uses too much energy
  • Home appliances mining for bitcoin while not in use
  • Bitcoin mining using hydropower
  • Large corporations’ carbon footprints
  • “Decarbonizing” electricity grids
  • Climate change
  • Trust in governments
  • Trust in corporations
  • Trust in social networks
  • Trust in media
  • Universal billing system for travel industry
  • Decentralized Uber and Lyft
  • Online gambling not fair
  • Online gambling sites take commission
  • Helping retailers hurt by Amazon
  • Online retail fraud
  • Paying for things with your face
  • Streamlining interactions among shoppers, retailers and brands
  • Linking content across computers, tablets and phones
  • Ranking apps by their value
  • Aligning creativity and recognition for content creators
  • Improving payments for artists on Spotify and Pandora
  • Online piracy
  • Improving the technology of the Russian gas industry
  • A blockchain equivalent of Amazon, Groupon and Craigslist
  • Too many non-value-added costs
  • Unregulated prison economies
  • Standardizing the value of advertisements
  • Advertising not transparent enough
  • Old real estate practices
  • Free public information from silos
  • Speeding the rendering of animated movies
  • Selling items for crypto instead of regular money
  • Borders
  • Man-in-the-middle hacks
  • Security sacrifices that come with innovation
  • Scams, fraud and counterfeits
  • Tools to build decentralized apps
  • Blockchain infrastructure
  • Removing barriers separating blockchains
  • Safety in buying and selling blockchain tokens
  • Improving privacy in online file storage
  • ICO projects could benefit from the “wisdom of the crowd”
  • Improving privacy of blockchain
  • Decentralized database for decentralized technologies
  • Improving trust and confidence in blockchain system
  • More cohesive user experiences across blockchain and the cloud
  • Democratizing gold trading
  • Giving investors more control of their assets
  • Simplifying the cryptocurrency transaction process
  • Trading indexes as tokens
  • Improving crypto safekeeping solutions
  • Simplifying ICO investment, trading and cryptocurrency
  • Improving institutional-grade crypto asset management
  • “Painstakingly slow” manual crypto wallet process
  • More open global markets
  • Easier way to invest in real estate
  • Easier way to invest in Swiss real estate
  • Easier way to combine smart contracts with crowdfunded home loans
  • Easier way to borrow against crypto holdings
  • Faster porn industry payment options
  • Lower porn industry payment fees
  • Identifying and verifying users in online dating
  • Improving traditional banking services for crypto world
  • Cryptocurrency based on Game Theory, IBM’s Watson, and other theories
  • Better social network + blockchain + AI + human touch
  • Improving content streaming on the blockchain
  • Supply chain transparency
  • Increasing public sector trust of cryptocurrencies
  • Education around blockchain technology
  • Blockchain not mainstream enough
 
++++++++++++++++++++++++++
more on blockchain in this IMS blog
https://blog.stcloudstate.edu/ims?s=blockchain

Are your phone camera and microphone spying on you

Are your phone camera and microphone spying on you?

https://www.theguardian.com/commentisfree/2018/apr/06/phone-camera-microphone-spying

Apps like WhatsApp, Facebook, Snapchat, Instagram, Twitter, LinkedIn, Viber

Felix Krause described in 2017 that when a user grants an app access to their camera and microphone, the app could do the following:

  • Access both the front and the back camera.
  • Record you at any time the app is in the foreground.
  • Take pictures and videos without telling you.
  • Upload the pictures and videos without telling you.
  • Upload the pictures/videos it takes immediately.
  • Run real-time face recognition to detect facial features or expressions.
  • Livestream the camera on to the internet.
  • Detect if the user is on their phone alone, or watching together with a second person.
  • Upload random frames of the video stream to your web service and run a proper face recognition software which can find existing photos of you on the internet and create a 3D model based on your face.

For instance, here’s a Find my Phone application which a documentary maker installed on a phone, then let someone steal it. After the person stole it, the original owner spied on every moment of the thief’s life through the phone’s camera and microphone.

The government

  • Edward Snowden revealed an NSA program called Optic Nerves. The operation was a bulk surveillance program under which they captured webcam images every five minutes from Yahoo users’ video chats and then stored them for future use. It is estimated that between 3% and 11% of the images captured contained “undesirable nudity”.
  • Government security agencies like the NSA can also have access to your devices through in-built backdoors. This means that these security agencies can tune in to your phone calls, read your messages, capture pictures of you, stream videos of you, read your emails, steal your files … at any moment they please.

Hackers

Hackers can also gain access to your device with extraordinary ease via apps, PDF files, multimedia messages and even emojis.

An application called Metasploit on the ethical hacking platform Kali uses an Adobe Reader 9 (which over 60% of users still use) exploit to open a listener (rootkit) on the user’s computer. You alter the PDF with the program, send the user the malicious file, they open it, and hey presto – you have total control over their device remotely.

Once a user opens this PDF file, the hacker can then:

  • Install whatever software/app they like on the user’s device.
  • Use a keylogger to grab all of their passwords.
  • Steal all documents from the device.
  • Take pictures and stream videos from their camera.
  • Capture past or live audio from the microphone.
  • Upload incriminating images/documents to their PC, and notify the police.

And, if it’s not enough that your phone is tracking you – surveillance cameras in shops and streets are tracking you, too

  • You might even be on this website, InSeCam, which allows ordinary people online to watch surveillance cameras free of charge. It even allows you to search cameras by location, city, time zone, device manufacturer, and specify whether you want to see a kitchen, bar, restaurant or bedroom.

++++++++++++++++++
more on privacy in this IMS blog
https://blog.stcloudstate.edu/ims?s=privacy

more on surveillance in this IMS blog
https://blog.stcloudstate.edu/ims?s=surveillance

 

ePub converter

Online converter

https://ebook.online-convert.com/convert-to-epub

https://www.zamzar.com/convert/epub-to-pdf/

https://calibre-ebook.com/ — (https://lifehacker.com/5509965/how-can-i-convert-pdfs-and-other-ebooks-to-the-epub-format)

Using Adobe InDesign to convert PDF to ePub: https://forums.adobe.com/thread/976831

and

https://www.quora.com/What-is-the-best-free-PDF-to-EPUB-converter

+++++++++++
more on ePub in this IMS blog
https://blog.stcloudstate.edu/ims?s=epub

cybersecurity threats for schools

The top 5 cybersecurity threats for schools

BY EARL D. LAING November 29th, 2017
https://www.eschoolnews.com/2017/11/29/cybersecurity-threats-schools/

1. Link Security

From ransomware to phishing and other types of security breaches, direct contact is the number one way that you can create a vulnerability in your system. Those who commit these online crimes are finding smarter and sneakier ways to infiltrate your data every day. Sometimes the attack can even come as an email from a legitimate sender, or appear to be a perfectly normal message on social media. The goal is usually to get you to click on a link.

Solution: Make sure the security preferences for your email account(s) are set up to filter spamming, phishing and executable files that aren’t recognized.

2. Unknown Devices

Solution: Your IT system should include a solution that tracks all devices, including those not owned by your school, that enter the network.

3. Out of Date Technology

Contrary to popular misconception, user interaction isn’t always required for a cyber attack to be launched. The WannaCry attack targeted hundreds of computers all with the same security vulnerability on their Windows operating systems.

Solution: Again, an IT solution that tracks all devices is important, but one that can also check on software upgrades and block access to certain apps is ideal.

4. User Error

A data breach in Florida is just one example of the chaos user error can provoke. This issue didn’t begin with hackers at all. It began with carelessness that caused sensitive information to become public.

User error occurs regularly, and a common root of this is failing to restrict access to files or certain sites that may be compromised.

Solution: Restrict user access to sensitive documents only to those who absolutely need them, and make sure that your site architecture is set up to require a secure login for access. You may also want to create a white list of safe sites and applications and block the rest.

5. No Backup

As disheartening as it sounds, even when you take all the necessary precautions to protect your vital information, data breaches can still occur. When an attack happens, it’s often a major blow to productivity to try and get all the information back into a secure place. Worse, vital work can be lost for good.

Solution: Install a backup system on each school device that sends data to a remote server throughout the day (not just at night) to help make sure nothing is lost.

+++++++++++++++
more on cybersecurrity in this IMS blog
https://blog.stcloudstate.edu/ims?s=cybersecurity

Malware, Phishing, Hacking, Ransomware

Keeping Safe in a Digital World

How Not to be Hacked

Malware, Phishing, Hacking, Ransomware – oh my! Learn about the threats to you, your users and your library.  During this session, we will explore the threats to online security and discuss solutions that can be implemented at any level. Most importantly, we will look at how we can educate our users on current threats and safety

Date: December 5th, 10AM

Presenter: Diana Silveira

Register: https://netforum.avectra.com/eweb/DynamicPage.aspx?Site=SEFLIN&WebCode=EventDetail&evt_key=bec597af-02dd-41a4-9b3a-afc42dc155e4

Webinar December 5, 2017 10 AM

  • create policies. e.g. changing psw routinely
  • USB blockers for public computers (public libraries). like skimmers on gas stations
  • do not use admin passwords
  • software and firmware updates.
  • policy for leaving employees
  • HTTP vs HTTPS
  • Cybersecurity KNowledge Quiz Pew research Center
    http://www.pewinternet.org/quiz/cybersecurity-knowledge/ 

diana@novarelibrary.com

slideshare.net/dee987

facebook.com/novarelibrary

twitter @Novarelibrary

+++++++++++
more on hacking in this IMS blog
https://blog.stcloudstate.edu/ims?s=hacker

weaponizing the web RT hybrid war

Fake news and botnets: how Russia weaponised the web

https://www.theguardian.com/technology/2017/dec/02/fake-news-botnets-how-russia-weaponised-the-web-cyber-attack-estonia

The digital attack that brought Estonia to a standstill 10 years ago was the first shot in a cyberwar that has been raging between Moscow and the west ever since

It began at exactly 10pm on 26 April, 2007, when a Russian-speaking mob began rioting in the streets of Tallinn, the capital city of Estonia, killing one person and wounding dozens of others. That incident resonates powerfully in some of the recent conflicts in the US. In 2007, the Estonian government had announced that a bronze statue of a heroic second world war Soviet soldier was to be removed from a central city square. For ethnic Estonians, the statue had less to do with the war than with the Soviet occupation that followed it, which lasted until independence in 1991. For the country’s Russian-speaking minority – 25% of Estonia’s 1.3 million people – the removal of the memorial was another sign of ethnic discrimination.

That evening, Jaan Priisalu – a former risk manager for Estonia’s largest bank, Hansabank, who was working closely with the government on its cybersecurity infrastructure – was at home in Tallinn with his girlfriend when his phone rang. On the line was Hillar Aarelaid, the chief of Estonia’s cybercrime police.

“It’s going down,” Aarelaid declared. Alongside the street fighting, reports of digital attacks were beginning to filter in. The websites of the parliament, major universities, and national newspapers were crashing. Priisalu and Aarelaid had suspected something like this could happen one day. A digital attack on Estoniahad begun.

“The Russian theory of war allows you to defeat the enemy without ever having to touch him,” says Peter Pomerantsev, author of Nothing is True and Everything is Possible. “Estonia was an early experiment in that theory.”

Since then, Russia has only developed, and codified, these strategies. The techniques pioneered in Estonia are known as the “Gerasimov doctrine,” named after Valery Gerasimov, the chief of the general staff of the Russian military. In 2013, Gerasimov published an article in the Russian journal Military-Industrial Courier, articulating the strategy of what is now called “hybrid” or “nonlinear” warfare. “The lines between war and peace are blurred,” he wrote. New forms of antagonism, as seen in 2010’s Arab spring and the “colour revolutions” of the early 2000s, could transform a “perfectly thriving state, in a matter of months, and even days, into an arena of fierce armed conflict”.

Russia has deployed these strategies around the globe. Its 2008 war with Georgia, another former Soviet republic, relied on a mix of both conventional and cyber-attacks, as did the 2014 invasion of Crimea. Both began with civil unrest sparked via digital and social media – followed by tanks. Finland and Sweden have experienced near-constant Russian information operations. Russian hacks and social media operations have also occurred during recent elections in Holland, Germany, and France. Most recently, Spain’s leading daily, El País, reported on Russian meddling in the Catalonian independence referendum. Russian-supported hackers had allegedly worked with separatist groups, presumably with a mind to further undermining the EU in the wake of the Brexit vote.

The Kremlin has used the same strategies against its own people. Domestically, history books, school lessons, and media are manipulated, while laws are passed blocking foreign access to the Russian population’s online data from foreign companies – an essential resource in today’s global information-sharing culture. According to British military researcher Keir Giles, author of Nato’s Handbook of Russian Information Warfare, the Russian government, or actors that it supports, has even captured the social media accounts of celebrities in order to spread provocative messages under their names but without their knowledge. The goal, both at home and abroad, is to sever outside lines of communication so that people get their information only through controlled channels.

+++++++++++++++++++++
24-hour Putin people: my week watching Kremlin ‘propaganda channel’ RT

https://www.theguardian.com/media/2017/nov/29/24-hour-putin-people-my-week-watching-kremlin-propaganda-channel-rt-russia-today

 Wednesday 29 November 2017 

According to its detractors, RT is Vladimir Putin’s global disinformation service, countering one version of the truth with another in a bid to undermine the whole notion of empirical truth. And yet influential people from all walks of public life appear on it, or take its money. You can’t criticise RT’s standards, they say, if you don’t watch it. So I watched it. For a week.

Suchet, the son of former ITV newsreader John Suchet and the nephew of actor David Suchet, has been working for RT since 2009. The offspring of well-known people feature often on RT. Sophie Shevardnadze, who presents Sophie & Co, is the granddaughter of former Georgian president and Soviet foreign minister Eduard ShevardnadzeTyrel Ventura, who presents Watching the Hawks on RT America, is the son of wrestler-turned-politician Jesse Ventura. His co-host is Oliver Stone’s son Sean.

My note; so this is why Oliver Stone in his “documentary” went gentle on Putin, so his son can have a job. #Nepotism #FakeNews

RT’s stated mission is to offer an “alternative perspective on major global events”, but the world according to RT is often downright surreal.

Peter Pomerantsev, author of Nothing Is True and Everything Is Possible, about Putin’s Russia, and now a senior visiting fellow in global affairs at the London School of Economics, was in Moscow working in television when Russia Today first started hiring graduates from Britain and the US. “The people were really bright, they were being paid well,” he says. But they soon found they were being ordered to change their copy, or instructed how to cover certain stories to reflect well on the Kremlin. “Everyone had their own moment when they first twigged that this wasn’t like the BBC,” he says. “That, actually, this is being dictated from above.” The coverage of Russia’s war with Georgia in 2008 was a lightbulb moment for many, he says. They quit.

+++++++++++++++

more on Russian bots, trolls:
https://blog.stcloudstate.edu/ims/2017/11/22/bots-trolls-and-fake-news/

+++++++++++++++
more on state propaganda in this IMS blog
https://blog.stcloudstate.edu/ims/2017/11/21/china-of-xi/

Mac OS High Sierra

ANYONE CAN HACK MACOS HIGH SIERRA JUST BY TYPING “ROOT”

ANDY GREENBERG 11.28.17 05:47 PM

https://www.wired.com/story/macos-high-sierra-hack-root/

THERE ARE HACKABLE security flaws in software. And then there are those that don’t even require hacking at all—just a knock on the door, and asking to be let in. Apple’s macOS High Sierra has the second kind.

malicious code running on the operating system could steal the contents of its keychain without a password.

Apple does have a bug bounty, but only for iOS, not MacOS.

1 2 3 4 5 6