14th April 2015

Do Not Track: An Interactive Documentary Series

Who are you, what do you do and who is watching you do it? Three simple questions, posed by a new interactive documentary called Do Not Track. If you’re curious to know exactly what information you’re offering up online when you visit websites, then you’ll want to take part in the interactive portions of their upcoming sessions which run from now until June. Created by Brett Gaylor, the site deep dives into the hidden world of data ticking away under the bonnet of your browsing experience. You may already run privacy tools such as Ad blockers or browser extensions such as Ghostery, but there’s a difference between seeing a list of sites blocked and witnessing first hand where all of your data is going. Episode 1 is called Morning Rituals, and deals with “The trackers, an industry most people can’t see, control or question”. Over the morning, I give away Gigabytes of information about myself - and I give it without being asked. The short, 5 (ish) minute long films mashup looped gifs..
2nd April 2015

New Malwarebytes Anti-Exploit version is out

Did you know that the majority of new malware is delivered via the web through a process known as a drive-by download attack? The scenario is quite simple: you browse to a website and malicious code is downloaded to your computer automatically without your knowledge or approval. Contrary to some beliefs, you do not need to browse to shady websites for this to happen. In fact, all websites are a potential source of infection either because they can get compromised or because they host a malicious advertisement. Figure 1: Drive-by download scenario This phenomenon takes advantage of software vulnerabilities that exist in browsers (Internet Explorer, Firefox, etc.) as well as their plugins (Flash Player, Silverlight, Java, Reader, etc.). There is no such thing as a “safe” site anymore That is why it is crucial to keep your computer up-to-date and also get rid of programs you rarely use to reduce the potential attack surface. But even so, there are times when even the most patched m..
20th February 2015

Lenovo and the Superfish fiasco

Chinese PC manufacturer Lenovo made the news in a big way this week, but unfortunately these weren’t good news for anybody. So what is all this fuss about and what is Superfish? This is the definition from Lenovo prior to the big debacle: Superfish comes with Lenovo consumer products only and is a technology that helps users find and discover products visually. The technology instantly analyzes images on the web and presents identical and similar product offers that may have lower prices, helping users search for images without knowing exactly what an item is called or how to describe it in a typical text-based search engine. This may sound like great new technology but users have to read between the lines: Superfish is a piece of software that came pre-installed on some Lenovo PCs which is able to directly inject ads into your browser as well as intercept encrypted communications (HTTPS) by acting as man-in-the-middle (MitM). The company providing MitM capabilities, Komodia, was ..
11th February 2015

Bots Versus Cops, the Twitter Edition

Roll your own Twitter bots are becoming increasingly popular, especially ones which look at the Tweets of their creator’s main feed, jumble the words up and spew forth stream of consciousness style missives. You may want to reconsider, however, because things seem to have gone a bit wrong in the land of Bots today: wow so one of my bots sent out a death threat? I’m very sorry this happened. — ωϗϹΔ∫Σ (@Wxcafe) February 11, 2015 The person above apparently coded a Bot and gave it to another Twitter user to fire out pearls of wisdom, and everything was fine until his Bot said something…peculiar (to another Bot! Did I mention Bots talk to Bots yet?) Police saw the offending Tweet, and then this happened: The randomly-generated words made one. And so they come to me. — call of jeffthulhu (@jvdgoot) February 11, 2015 I’m going to delete my bot for now, because that’s what they want. — call of jeffthulhu (@jvdgoot) February 11, 2015 Which I think is an interesting legal angle. — call..
12th January 2015

Popular Game Rental Site Issues Statement on Alleged “Fraudulent Payment Attempts”

It’s come to light that Boomerangrentals(dot)co(dot)uk [traffic stats], is investigating claims from customers that they’ve had fraudulent payment attempts on cards registered to them. Up to now, Boomerang had made the following comments on the unfolding situation on Reddit: [1], [2]. The Boomerang website has since been taken offline (“Our website is currently down for maintenance work, please accept our apologies for any inconvenience caused”), and they just issued a statement in relation to events of the last day or two. It reads as follows: Following an initial enquiry at the end of last week, we have had a number of customers raise concerns regarding fraudulent payment attempts on their card details that are also registered with us. We are fully investigating this issue and have temporarily removed access to our website while this continues. We have contacted our Payment Provider Sagepay and our Merchant Bank World Pay and neither have any reported concerns relating to us. How..