Wednesday, September 7, 2016

Google Records Your Voice Conversations – Here’s How To Delete Them

ISS_3138_04538 (300 x 200)

If you’ve been using Google for voice communication, whether through Android or Gchat, chances are that everything you said so far on the platform has been recorded.

For Google, just talking is enough to trigger automatic recording of voice conversations. The company quietly records every conversation that happens through the medium.

This feature was introduced by Google to let people make searches with voice control. Also recording voices enables Google to enhance it’s language recognition system which is responsible for giving results when you do a voice based search.

You can also listen to these recordings and if you wish, you can also delete the information stored which was collected.

Read more http://www.independent.co.uk/life-style/gadgets-and-tech/news/google-voice-search-records-stores-conversation-people-have-around-their-phones-but-files-can-be-a7059376.html

The post Google Records Your Voice Conversations – Here’s How To Delete Them appeared first on Cyber Security Portal.



from Gilbertine Onfroi

Tuesday, September 6, 2016

[SANS ISC Diary] Malware Delivered via ‘.pub’ Files

I published the following diary on isc.sans.org: “Malware Delivered via ‘.pub’ Files“.

While searching for new scenarios to deliver their malwares[1][2], attackers launched a campaign to deliver malicious code embedded in Microsoft Publisher[3] (.pub) files. The tool Publisher is less known than Word or Excel. This desktop publishing tool was released in 1991 (version 1.0) but it is still alive and included in the newest Office suite. It is not surprising that it support also macros… [Read more]

[The post [SANS ISC Diary] Malware Delivered via ‘.pub’ Files has been first published on /dev/random]



from Xavier

"Awareness Summit Talk - John Scott on Three Key Skills"

Editor's Note: Over the coming weeks we will post recaps of speakers' talks from the 3rd Annual Security Awareness Summit. Today John Scottfrom Bank of Englandshares details from histalk and experiences from the summit.If you missed the summit, consider the European Security Awareness Summit 11 November in London. Back in the dawn of time, … Continue reading Awareness Summit Talk - John Scott on Three Key Skills

from lspitzner

Thursday, September 1, 2016

[SANS ISC Diary] Maxmind.com (Ab)used As Anti-Analysis Technique

I published the following diary on isc.sans.org: “Maxmind.com (Ab)used As Anti-Analysis Technique“.

A long time ago I wrote a diary[1] about malware samples which use online geolocalization services. Such services are used to target only specific victims. If the malware detects that it is executed from a specific area, it just stops. This has been seen in Russian malware’s which did not infect people located in the same area … [Read more]

 

[The post [SANS ISC Diary] Maxmind.com (Ab)used As Anti-Analysis Technique has been first published on /dev/random]



from Xavier

"Awareness Summit Talk - Janet Roberts on Leveraging the Security Awareness Maturity Model"

Editor's Note: Over the coming weeks we will post recaps of speakers' talks from the 3rd Annual Security Awareness Summit. TodayJanet Roberts from Zurich Insuranceshares details from hertalk and experiences from the summit. If you missed the summit, consider the European Security Awareness Summit 11 November in London. Building a security awareness program is kind … Continue reading Awareness Summit Talk - Janet Roberts on Leveraging the Security Awareness Maturity Model

from lspitzner

68 million passwords were dumped online in recent Dropbox hack

02E97250 (300 x 200)

Earlier this week, Dropbox suffered a hack and had its users force reset passwords that it claims were stolen in a 2012 breach. The following message was given to the users.

Our security teams are always watching out for new threats to our users. As part of these ongoing efforts, we learned about an old set of Dropbox user credentials (email addresses plus hashed and salted passwords) that we believe were obtained in 2012.

Our analysis suggests that the credentials relate to an incident we disclosed around that time

If you haven’t logged in on Dropbox, you will have to change your passwords. Furthermore, if you started using Dropbox before mid 2012, you should also reset your password.

The hack was so big that a file was obtained sized around 5GB which contained the details of 68,680,741 accounts.

Read more https://nakedsecurity.sophos.com/2016/08/31/dropbox-hack-leads-to-68-million-passwords-dumped-online/

The post 68 million passwords were dumped online in recent Dropbox hack appeared first on Cyber Security Portal.



from Gilbertine Onfroi

Wednesday, August 31, 2016

Does Having Windows On Your Laptop Make Top IT Security Professionals Misjudge You?

windows-laptop-hackedThis is a very common question between newcomers to cybersecurity and ethical hacking in general. It seems that most experienced ethical hackers prefer using OSX and Linux to Windows. That’s why a lot of newbies feel that they will be judged if a professional sees Windows on their system.

Popular hacker Adrian Lamo had a say on this recently.

He said that yes, while a lot of people will probably have Linux or OSX installed on their machines, it would not be right to judge someone by the cover.

In his early days during DEFCON attendance, Lamo was sitting at the conference with his laptop running Windows and was connected to the internet using TCP/IP. He told that he too encountered some folk walking by looking at him using AOL and laughed as they passed by. He wasn’t really surprised at that time because AOL didn’t really had a good repo amongst the hacker community. So he was instantly ranked a n00b.

But then he recalled that many of those people who judged him didn’t know that AOL had a exploit in it that allowed him to create accounts that would allow him to log in and drop off the system within the next 17 minutes with absolutely no trace left behind while still remaining connected.

He also said that AOL at that time had a virtual network adapter which allowed him to configure his own network preferences to connect to the internet using the address that was assigned to that adapter. This allowed him to browse in complete invisibility.

So in short, according to Lamo, a good craftsman does not need special tools to work with. They are capable of big things using the tools that are made available to them. So whether you use Linux, OSX or Windows, it does not make you a noob or a pro. There will still be people who will judge you, but your skills are what matters the most.

When asked if Lamo would judge anyone using Windows on their machine, he said absolutely not. No one should judge by the books cover.

So whether you use Windows or not, it’s the skill set that matters. Show your skills to IT experts and that should get you the label of IT professional instead of a noob.

The post Does Having Windows On Your Laptop Make Top IT Security Professionals Misjudge You? appeared first on Cyber Security Portal.



from Gilbertine Onfroi