Showing posts with label Mobile Security. Show all posts

Credit Card Fraud Reported After People Purchased OnePlus Smartphones

If you purchased OnePlus devices through the official site in the last few months, your credit card details could be at risk. Many users who bought OnePlus devices later reported suspicious activity on their credit card statement.

According to a security firm Fidus, the issue could be associated with how the payment process happens, not the OnePlus website. The site is developed using the Magento eCommerce platform which the researchers say has been targeted by attackers multiple times.
As the payments page is hosted on the OnePlus site, the credit card details can be intercepted by the attackers. They have a small window before the details get encrypted and sent to the third-party server for processing.


In their official response made on the OnePlus forum, the Chinese smartphone maker said they’re investigating the credit card fraud reports and agreed that the buyers who used their credit cards directly to make purchases are among the affected ones.

OnePlus said all the payment processing is done on the servers of their payment service provider. When a buyer chooses “Save this card for future tractions,” the card details are stored on the third-party server. The OnePlus site only saves an encrypted token which is used by the payment server to fetch the payment details of the buyer.

OnePlus also clarified that they have been shifting away from Magento platform and re-designing their website with custom code. Also, they never used Magento’s payment module. So, it’s unlikely their site is affected by the Magento bugs discovered in the past.

While the company was quick to issue a statement, it doesn’t seem it would of much help to the buyers who got money sucked from their accounts. People who are seeing unknown transactions in their statement are advised to contact their banks immediately and get things sorted.
Monday, 22 January 2018
Posted by Sivapriya

Cyber Security and Your Mobile Phone

With increasing numbers of us using our mobile devices in nearly every aspect of our busy lives, one of the most important things to do is stay safe and secure when online.

Mobile Malware like Viking Hoard that created a botnet and affected Android devices, or Pegasus that affected both iOS and Android devices masquerading and an app to harvest data are very real threats which were primarily used for adware purposes, now they have been seen rooting millions of devices with malware effectively opening the back door on infected devices.
The thought that your mobile could be used for any purpose, and that includes stealing sensitive data is very scary, and very real.

One simple way to help protect yourself via your phone is to regularly check the status of your mobile apps and the updates. Delete them if they are no longer supported in the Apple or Google stores.

Of course, it is also vital to have good security software installed on your mobile devices. User behavior and awareness need to evolve alongside the continued threat of malware and possible spyware.

For instance, if you were going to play at a mobile casino it would be bad practice to simply pick one randomly and then give your banking details over to the site, just like you would not give your details over to an insurance site easily. Luckily there are honest sites out there still, sites like mobile slots UK have to adhere to the rules and regulations set out by the Gambling Commission or they will get their operator’s license revoked.

Any site should be transparent and have all of its information set out in an easy to see, jargon-free way, especially if you are going to spend any money on it, and this goes for all sites, whether they are online casinos, car insurance sites, clothing stores or any of the millions of sites where you can spend your hard-earned cash.

Interestingly on online casinos, BOKU is becoming one of the most widely used forms of paying for games online. It works by either adding the cost of the games your play to your monthly contract or taking the cost of the games from your ‘pay as you go account.’

Using this form of payment method means you do not have to give any bank details or credit card details to the site at all, in fact, you don’t even have to have a bank account.

With increasing numbers of people becoming reticent about giving banking details, companies like BOKU provide an alternative that appeals to many.

Thursday, 10 August 2017
Posted by Sivapriya

WhatsApp Found Collecting Data on Calls and Phone Numbers

WhatsApp, one of the most popular online calling apps, has been exposed by a group of researchers who identified how app’s internal protocol is storing call duration and personal information of the participants.


Though, WhatsApp has never claimed itself to be an anonymous calling service but this new research has unveiled new information on how the app’s communication systems have been powered.

According to the researchers at the University of New Haven, WhatsApp uses FunXMPP protocol (deviated version of XMPP) XMPP has been used by Google for one its communication services, the Gtalk.

The researchers also analyzed the exchanges of messages between the Android phone and WhatsApp server. What they found was that WhatsApp has set up a complete system of gathering the data.

First they authenticated the users involved in the call and then a communication channel was setup using Opus codec at 8 or 16 KHz. After this, they established the call’s relay servers and endpoint IP addresses.

The scraping of data doesn’t end here; researchers were able to identify the app sending Metadata like phones number, timestamp, audio codec for the call and the call duration to its servers.

Read More ..




Tuesday, 3 November 2015
Posted by Sivapriya

widget

Pageviews

Cloud Label

Blogumulus by Roy Tanck and Amanda Fazani

- Copyright © 2013 Redback IT Academy -- Powered by Redback - Designed by @ Redback Studio -