protection
Source: http://gizmodo.com/5943788/developers-suspect-the-new-kindle-fires-will-be-hack+resistant
If you were banking on hacking a new Kindle Fire to take advantage of cheap hardware without Amazon’s modded Android OS, you perhaps better think again. Developers over at XDA are speculating that they expect the new range of Fires to be too sophisticated to hack.
In particular, a forum post provides evidence which suggests that the new devices will come with more sophisticated protection, including locked bootloaders and “high security” features offered by Texas Instrument processors.
Of course, with Amazon really pushing its device-as-service concept hard, the news likely won’t ruffle the majority of Fire-user feathers. But for those who were cheekily hoping to grab a Fire HD and mod it from the off, there may well be something to grumble about. [XDA via Engadget]
Google responds)
Source: http://www.engadget.com/2012/02/20/microsoft-finds-google-bypassed-internet-explorers-privacy-sett/
There was quite a stir sparked last week when it was revealed that Google was exploiting a loophole in a Apple’s Safari browser to track users through web ads, and that has now prompted a response from Microsoft’s Internet Explorer team, who unsurprisingly turned their attention to their own browser. In an official blog post today, they revealed that Google is indeed bypassing privacy settings in IE as well, although that’s only part of the story (more on that later). As Microsoft explains at some length, Google took advantage of what it describes as a “nuance” in the P3P specification, which effectively allowed it to bypass a user’s privacy settings and track them using cookies — a different method than that used in the case of Safari, but one that ultimately has the same goal. Microsoft says it’s contacted Google about the matter, but it’s offering a solution of its own in the meantime. It’ll require you to first upgrade to Internet Explorer 9 if you haven’t already, then install a Tracking Protection List that will completely block any such attempts by Google — details on it can be found at the source link below.
As ZDNet’s Mary Jo Foley notes, however, Google isn’t the only company that was discovered to be taking advantage of the P3P loophole. Researchers from Carnegie Mellon University’s CyLab say they alerted Microsoft to the vulnerability in 2010, and just two days ago the director of the lab, Lorrie Faith Cranor, wrote about about the issue again on the TAP blog (sponsored by Microsoft, incidentally), detailing how Facebook and others also sk! irt IE’s ability to block cookies. Indeed, Facebook readily admits on its site that it does not have a P3P policy, explaining that the standard is “out of date and does not reflect technologies that are currently in use on the web,” and that “most websites” also don’t currently have P3P policies. On that matter, Microsoft said in a statement to Foley that the “IE team is looking into the reports about Facebook,” but that it has “no additional information to share at this time.”
Update: Google’s Senior Vice President of Communications and Policy, Rachel Whetstone has now issued a statement in response to Microsoft’s blog post. It can be found in full after the break.
Microsoft finds Google bypassed Internet Explorer’s privacy settings too, but it’s not alone (update: Google responds) originally appeared on Engadget on Mon, 20 Feb 2012 16:59:00 EDT. Please see our terms for use of feeds.
Permalink
ZDNet |
IE Blog | Email this | Comments
The banking industry often employs two-step security measures—similar to Google Authenticator—as an added layer of protection against password theft and fraud. Unfortunately, those systems have just been rendered moot by a highly-advanced hack.
The attack, know as the Man in the Browser method, works like this. Malicious code is first introduced onto the victim’s computer where it resides in the web browser. It will lay dormant until the victim visits a specific website—in this case, his bank’s secure website. Once the user attempts to log in, the malware activates and runs between the victim and the actual website. Often the malware will request that the victim enter his password or other security pass into an unauthorized field, in order to “train a new security system.” Once that happens, the attacker has full access to the account.
Luckily, the method is only a single-shot attack. That is, the attacker is only able to infiltrate the site once with the user-supplied pass code. But, once in, the attacker can hide records of money transfers, spoof balances and change payment details. “The man in the browser attack is a very focused, very specific, advanced threat, specifically focused against banking,” Daniel Brett, of malware testing lab S21sec, told the BBC.
Since this attack has shown that the two-factor system is no longer a viable defense, the banking industry may have to adopt more advanced fraud-detection methods similar to what secure credit cards. When compared to having your account silently drained, standing in line for the teller suddenly doesn’t seem like that much of a hassle. [BBC News via Technology Review]
Image: jamdesign / Shutterstock
Here’s A Sneak Peek At Netflix’s First Big Bet On Original Programming (NFLX)
Source: http://www.businessinsider.com/netflix-original-series-lilyhammer-2012-1
Netflix has been talking up their new original programming quite a bit, and now they’ve actually released some footage.
“Lilyhammer” tells the story of an East Coast mobster, played by “The Sopranos” actor Steven Van Zandt, who’s relocated to a small town in Norway as part of the witness protection program.
Unlike most TV shows, you’ll be able to see all eight episodes of “Lilyhammer” at once — Netflix is putting the whole series online February 6.
This seems to be a risky strategy: shows often build buzz over the course of the season, especially with a new series, and if “Lilyhammer” doesn’t catch on immediately it could have a hard time building viewership.
Netflix might be counting on a viral audience, with subscribers passing it between each other and telling their friends they need to see it. If that’s the case, it better be good.
Please follow SAI: Media on Twitter and Facebook.
Join the conversation about this story »
See Also:
- This Could Be Part Of The Reason Iran Is So Darn Defensive
- PRESENTING: The Invisible Force That’s Saving The US Economy
- Oregon’s Rose Bowl Helmet Is Even More Sparkly Than We Feared
—
drag2share – drag and drop RSS news items on your email contacts to share (click SEE DEMO)
Is Facebook Tracking You After You Cancel Your Account? Does It Even Really Matter? [Facebook]
Citing employees at Hamburg Data Protection, Bloomberg claims that Facebook’s cookies will still actively track your online activity even if you’ve cancelled your account. But it mostly just seems like tin hat paranoia.
According to the report, there’s “suspicion” and over the way Facebook is using cookies. What that means exactly is unclear, as they don’t elaborate any further aside from saying that the cookies can identify specific people. Facebook says they delete any user specific cookies, but leave some for security purposes, such as phishing.
Remaining cookies are used in “identifying spammers and phishers, detecting when somebody unauthorized is trying to access your account, helping you get back into your account if you get hacked,” and blocking underage users from re-registering with a different birth date, Facebook said.
Should Facebook be doing this without people knowing? Probably not. But even if they are collecting data on you after you cancel your account, is it different from what any other website is doing? If these are supercookies, which are considerably harder to get rid of, then yeah, it’s problematic. But sites will drop a cookie on your computer and track your data even if you’re just visiting—regardless of whether or not you have an account.
This instance doesn’t seem to be much different. Sure, Facebook has data about us that is much more focused and specific, but if you’re that paranoid about it, clear out your cookies. [Bloomberg]
—
drag2share – drag and drop RSS news items on your email contacts to share (click SEE DEMO)
Cybercrooks Target Social Networks
Source: http://feeds.marketingcharts.com/~r/marketingcharts/~3/16mASWhC9kU/
Cybercriminals are turning their attention to users of social networks such as Facebook and Twitter, according to a new report [pdf] from IT security and data protection firm Sophos.
Spam, Malware Attacks on the Rise Sophos’ Security Threat Report: 2010 indicates criminals have increasingly focused attacks on social networking users in the past 12 months, with a [...]<img src="http://feeds.feedburner.com/~r/marketingcharts/~4/16mASWhC9kU" height="1" width="1"/>
Digital Consigliere
Tags
Popular Posts
- Netflix vs Blockbuster - Perfect example of an industry replaced by a more efficient version of itself
- Coke vs Pepsi vs Dr Pepper
- Marketing Costs Normalized to CPM Basis for Comparison
- The Top Endorsement Earners In Each Sport
- 3G calling, no registration, and totally free
- AOL's Plan To Steal TV Ad Dollars Is Totally Working
- drag2share: The Most Pinned Brand On Pinterest Doesn't Even Use A Pinterest Account [THE BRIEF]
- Groupon launches Breadcrumb iPad app, vows to not be a typical POS
- HP Mini 311 Nvidia ION Netbook Hackintosh'ed
Published Articles by Dr. Augustine Fou
- #SESNY: Toward a Performance Mindset for All Advertising
- Tips for Marketers Selecting a Digital Agency
- Context Is Not King or Queen; It's Just Necessary
- 2013 New Year's Digital Marketing Resolutions
- The Good, Bad, and Ugly of Online Campaign Ratings and eGRPs
- Why You Should Banish the Net Promoter Score Immediately
- Digital Strategy To-MAY-to vs. To-MAH-to
- The Agency-Client Relationship is Forever Changed
- Targeting vs. Privacy - Who Will Win?
- Digital + Traditional = Unified Marketing
Pages
Archives
- May 2013 (66)
- April 2013 (70)
- March 2013 (114)
- February 2013 (89)
- January 2013 (136)
- December 2012 (96)
- November 2012 (130)
- October 2012 (147)
- September 2012 (94)
- August 2012 (92)
- July 2012 (112)
- June 2012 (71)
- May 2012 (82)
- April 2012 (80)
- March 2012 (122)
- February 2012 (114)
- January 2012 (129)
- December 2011 (60)
- November 2011 (54)
- October 2011 (29)
- September 2011 (17)
- August 2011 (30)
- July 2011 (18)
- June 2011 (19)
- May 2011 (23)
- April 2011 (23)
- March 2011 (52)
- February 2011 (69)
- January 2011 (108)
- December 2010 (82)
- November 2010 (67)
- October 2010 (68)
- September 2010 (44)
- August 2010 (101)
- July 2010 (61)
- June 2010 (28)
- May 2010 (28)
- April 2010 (26)
- March 2010 (33)
- February 2010 (21)
- January 2010 (12)
- December 2009 (4)
- November 2009 (2)
- October 2009 (14)
- September 2009 (6)
- August 2009 (19)
- July 2009 (34)
- June 2009 (11)
- May 2009 (4)
- April 2009 (6)
- March 2009 (13)
- February 2009 (32)
- January 2009 (25)
- December 2008 (1)
- October 2008 (1)
- June 2008 (1)
- November 2007 (1)
Prototype Web Services
- drag2share – quickly share news items by drag and drop on email addresses
- LivePhotoFrame – upload and remotely manage a digital photo frame via unique URL
- MedleyTuner – create a continuous listening experience by uploading mp3s
- MusicSamplr – discover new artists and music, listen to samples
- SharedMost – what links on ANY webpage are shared most?
- Signatory – sign and date a document and verify it hasn't been altered since that exact time.
- WebTeleprompter – just what it says it is


