Wednesday, March 5, 2014

Target Executive Resigns After Credit Card Data Breach


A senior executive at Target has resigned following the massive credit card data breach at the retail giant.
 
Chief Information Officer Beth Jacob, who had been in the post since 2008, stepped down effective Wednesday, the company said.
 
Target's chief information officer has resigned following the massive credit card security breach at the retailer. Steven Senne / ASSOCIATED PRESS
A Target retail store in Watertown, Mass. Target's chief information officer has resigned following the massive credit card security breach at the retailer.
In a statement, Target's Chairman, President, and CEO Gregg Steinhafel said the retailer is overhauling its information security and compliance structure. The company originally said a data breach compromised 40 million credit and debit card accounts between Nov. 27 and Dec. 15. Then on Jan. 10, it said hackers also stole personal information - including names, phone numbers as well as email and mailing addresses - from as many as 70 million customers.
 
"As a first step in this effort, Target will be conducting an external search for an interim CIO who can help guide Target through this transformation," Steinhafel said.
 
As part of this transition, the company said it is working with an external adviser to help evaluate its technology.
 
Target is still grappling with the fallout of the theft. The company said last week that its profit for the fourth quarter fell 46 percent on a revenue decline of 5.3 percent as the breach scared off customers.
 
- The Associated Press contributed to this report.

Tuesday, March 4, 2014

Facebook to Buy Drone Company Titan Aerospace for $60 Million

    

The next step on Facebook's path to Internet-connecting the entire globe is a high-tech one: buying up drones.
 Facebook is slated to buy New Mexico-based drone maker Titan Aerospace for about $60 million, a source confirmed to CNBC on Tuesday. The blog TechCrunch first reported the news of a possible Facebook-Titan deal.

Facebook is supposedly interested in Titan because its solar-powered drones — which can reportedly stay airborne for five years — can help Facebook achieve its goal of providing Internet access around the world.

Last year Facebook announced it would lead an initiative called Internet.org, which aims to bring Internet connectivity to the two-thirds of the world's population that currently lacks access. Facebook could potentially launch Titan's drones in those unconnected regions.

A $60 million price tag would likely be welcome to the privately held Titan, but it's a small fraction of the $16 billion that Facebook shelled out for messaging app WhatsApp last month.

Drones have recently emerged as a burgeoning area of technology, with even major U.S. companies like FedEx and Amazon hoping to employ the unmanned devices. (The commercial use of drones is not currently permitted by the U.S. Federal Aviation Administration, but the group is slated to unveil new guidelines by the end of 2015.)

Facebook also wouldn't be the first to use floating devices for global Internet connectivity. Last summer Google launched Project Loon, a pilot program testing Internet access via solar-powered helium balloons.

6 Reasons the Galaxy S5 Beats the iPhone 5s

Tech Media Network (Laptop)
6 Reasons the Galaxy S5 Beats the iPhone 5s
 
Comparing Samsung's Galaxy S5 to Apple's iPhone 5s is like pitting the Tesla Model S against the Ford Model T. From its more capable camera to its cutting-edge fitness features, Samsung's new flagship phone has a slew of amenities that Apple, famous for being the last to embrace new technologies (NFC anyone?), will probably add to the iPhone 7s.
I could spill a vat of digital ink, detailing every way in which the Galaxy S5 is the best 2014 has to offer and the iPhone 5s feels like an average Android device from 2012. However, iPhone users would have to scroll a lot to read them on their low-res displays. Here are the six biggest reasons why the Galaxy S5 beats the iPhone 5s.

1. Larger, Better Display

In an age when most flagship phones have full-HD displays 5 inches or larger, the iPhone 5s' 4-inch, 1136 x 640-pixel display is such a relic that it should come with a cassette adapter. Sure, the iPhone's screen has good color fidelity and a sharp 326 pixels per inch, but it can't hold a candela to Samsung's 5.1-inch, 1920 x 1080p super AMOLED panel.

A larger screen means a better movie-viewing experience, more-legible Web pages and books, and larger keys on the virtual keyboard for accurate typing. With a full-HD resolution, the Galaxy S5 shows the best online videos at an eye-popping 431.9 PPI, with no downscaling required. Better still, the Galaxy S5 has a new technology that adjusts not only the brightness, but also the contrast ratio and color gamut, to provide a superior experience in direct sunlight and other challenging conditions.


2. Much More Powerful Camera

The iPhone 5s' 8-MP camera takes photos with great color accuracy and sharpness, but it only captures half the detail of the Galaxy S5's 16-MP shooter. But it's not all about megapixels. The Galaxy S5 has real-time HDR (high-dynamic range), which uses different exposure levels for different parts of an image, while the iPhone can only provide this functionality on individual shots, not on videos or in preview mode.

The Galaxy S5 allows you to refocus your images after capturing them so you can focus on that face in the background rather than on the person in front. Add in previous Samsung features like Eraser Mode, which removes photobombers, and Best Face, which helps you pick the best smile for each person in a group photo, and you have a photography experience that's generations ahead of Apple's.

3. Longer Battery Life

If you want a built-in excuse for not answering that 5 p.m. email from your boss, get an iPhone 5s. With its puny 1,560-mAh battery, Apple's phone lasted a miserable 5 hours and 46 minutes on the Laptop Mag Battery Test, which consists of continuous Web surfing over 4G LTE. If you don't pick up your phone much or buy a battery case, you can make it through the day with the iPhone 5s. But why worry about it?

In contrast, Samsung equips the Galaxy S5 with a 2,800-mAh battery and a new Ultra Power Saving Mode that turns the settings down when you're running low on juice. Samsung also provides a removable back panel that lets you replace its battery, either with a spare of the same size or a third-party extended battery.

4. Water Resistance

Drop your iPhone 5s in the toilet, and you might as well flush it, because it's never coming back. However, if your Galaxy S5 should take a potty pitfall, you can hold your nose for 29 minutes before fishing it out and rinsing it off. Samsung's IP67-certified phone can survive up to 30 minutes submerged in 1 meter (about 3 feet) of water. If it's like the Sony Xperia Z, which boasts the same water resistance, the Galaxy S5 will continue streaming music to your Bluetooth speaker while submerged.


5. Better Security, Manageability

Apple earned kudos for embedding a fingerprint sensor into the iPhone 5s' home button, but Samsung has taken biometric security to the next level on the Galaxy S5. In addition to using the Galaxy S5's fingerprint reader (which is also built into the home button) to unlock the phone, you can enter a "private mode" that provides added security for your most sensitive documents and emails. The sensor also integrates with PayPal for secure online purchases.

Samsung also bundles the Galaxy S5 with its unique KNOX environment, which places business data and apps into a separate environment. Your corporate IT manager can feel secure knowing that your apps, business contacts and emails all live in a secure area of your phone, while you can feel comfortable knowing the IT department is not looking at your personal data.

6. Heart-Rate Monitor and Health Features

Whether you're trying to lose weight or just want to know how bad a shape you're in, Samsung has a built-in heart rate monitor that will capture your beats per minute when you stick a finger on the sensor. The Galaxy S5 also comes with a new version of S Health, the company's very detailed fitness software. The app includes a pedometer, diet advice and many ways of tracking your exercise and weight loss goals. With the iPhone 5S, you'll need to buy a fitness band and find your own fitness app.

Rob Pegoraro
Feb 10, 2014
 
image

Your email just got broken into? Sorry, it’s not personal. It’s business.

That may not console you much when you realize that your email account was “pwned” through malware or deceit. But, really, the hackers who went after it probably had nothing against you personally. They were instead focused on potentially profitable uses of your email.

This is a point that can easily get lost in the coverage of nightmare hacking scenarios like the 2012 instance in which Wired writer Mat Honan had his Gmail and iCloud accounts hijacked, then saw his iPhone, iPad and MacBook remotely wiped, all so a teenage guy could have fun broadcasting inanities from his three-character Twitter handle @mat.

But, most of the time, crooks going after your email have nothing more ambitious in mind than using it to spam people about fraudulent offers or malicious downloads.

“For the most part, compromised webmail accounts are used to send spam (some of which may contain links to malware),” writes Johannes Ullrich, chief research officer at the SANS Institute.

In a subsequent conversation, he said that not only has the use of hacked email addresses for spam stayed pretty much constant, but in some ways such addresses have become more valuable. How so? Stronger authentication systems deployed by major mail services have made it harder to send a spoofed message — one that looks like it’s from a legitimate address when it isn’t. So, since email impersonation is harder, the bad guys need to take over accounts to send messages that look real.

The value of a hack
What else can a hacker do with a hijacked account? McAfee public-sector chief technical officer Scott Montgomery sketched out one easy possibility: “Let’s say I compromise your Yahoo mail, your Google mail, whatever — what is the likelihood that you have reused that same password at multiple locations?”

That’s right. Stealing one password can open up access to a multitude of a user’s accounts. So take this opportunity to redo yours; for the most security, use a service like LastPass, 1Password or Dashlane to generate and store random passwords for you.

But even if a victim was smart enough to use different passwords for anything of serious value, it won’t matter if an attacker can reset them online — with the only needed confirmation being a click on an email sent to an inbox that the attacker already controls.

Or, as Brian Krebs reported last March, the attacker can skip even that minimal step by asking the bank nicely via email for help completing a wire transfer.

Ullrich said SANS hasn’t seen too many instances of this, thanks mainly to the fact that it’s more profitable to confine that particular scam to cases “where they know that this person deals with large amounts of money.”
In one particularly ambitious attack SANS is investigating, the scammer steps into existing business correspondence to try to fool a customer into sending money to the wrong place. “It appears to happen quite a bit with real estate,” Ullrich observed.

The worst attack Montgomery suggested one last, still uglier use for a hijacked email: Instead of just spamming friends with some bogus offer, they try to get them to click and install “ransomware” that then locks them out of their own files unless they pay off the scammer.

A site password plus an email address that itself is secured with only a password shouldn’t open the door to moving money around. But while most Web-mail services now offer two-step verification — yes, you should turn it on — only a handful of name-brand banks and other financial institutions also do.

I don’t think you can legislate a requirement for two-step verification, but having to reimburse enough customers for losses ought to have an educational effect on banks that haven’t let customers lock their accounts with more than a username and password.

Online security laws need to change That doesn’t mean the folks in Washington have nothing at all to do on this front. Beyond the absence of a national law requiring companies to notify you if they lose your data, the primary law aimed at networked crime — the Computer Fraud and Abuse Act — needs a rewrite of its own.

That’s not because it’s too tolerant of hacking attempts; it’s because it now defines them so broadly that it can be used to target legitimate security research. In an upcoming column, I’ll explain why the CFAA has become many techies’ least favorite law.

Yahoo Tech is a brand new tech site from David Pogue and an all-star team of writers. Follow us on Facebook for all the latest.
Jill Scharr, Tom's Guide
Mar 3, 2014
 

 
This malware is sick: The experimental “Chameleon” malware spreads rapidly among WiFi networks in densely populated areas, much as a disease spreads through crowded urban areas. 
Developed in a laboratory at the University of Liverpool in England, Chameleon is the first malware known to propagate by hopping from one WiFi network to another.


MORE: Best Antivirus Software 2014“It was assumed … that it wasn’t possible to develop a virus that could attack WiFi networks; but we demonstrated that this is possible and that it can spread quickly,” Alan Marshall, one of the paper’s co-authors, said in a statement.

Chameleon is technically a worm, not a virus, because it replicates without human assistance by trying to crack the password of each new WiFi router it encounters. Chameleon nevertheless behaves like a biological infectious organism, jumping among overlapping WiFi networks much as an airborne disease spreads among humans.

The researchers simulated Chameleon infections in London and Belfast and found that just a few infections can spread the worm to “thousands of infected devices within 24 hours.”

Furthermore, because Chameleon doesn’t migrate beyond WiFi routers, it is undetectable to current antivirus software, which scans for threats on computers and the Internet.

In its current state, Chameleon doesn’t do much more than replicate itself and identify poorly protected WiFi networks, but the researchers say in their paper that such malware could be used to eavesdrop on Internet traffic, alter or destroy data packets, or destroy an infected WiFi router.

Chameleon doesn’t exist in the wild, so there’s no real risk of infection. The good news is that a strong WiFi password will keep your router safe from this kind of malware; if it can’t break into your router, it will simply move on to the next available one.

The bad news is that many commercial and private WiFi networks have weak passwords or simply aren’t password-protected at all.

In that sense, a WiFi password is like a vaccine; having it will protect not only you, but the people — or WiFi routers — around you as well.

See also:
13 Security and Privacy Tips for the Truly Paranoid‘War Biking’ San Francisco Reveals Lousy WiFi Security

Email jscharr@techmedianetwork.com or follow her on Twitter (@JillScharrand Google+. Follow Tom’s Guide on Twitter, Facebook and  Google+

Progress! Soon You May Actually Be Able to Unlock Your Mobile Phone

image
You know that when you “buy” a mobile phone, you don’t actually have full access to it. Most phones are locked to the carrier you bought them from. But buying a phone may soon look more like actually owning a phone, thanks to a bill to legalize phone unlocking that passed the House last week and faces decent odds in the Senate.

Requiring an act of Congress to use things you’ve paid for as if they are actually your property is maddening. It’s also tech policy as usual. What’s less usual is seeing forward momentum in this area.

While the Unlocking Consumer Choice and Wireless Competition Act sponsored by Rep. Bob Goodlatte (R-Va.) is a flawed solution, it still represents one of the few times when Congress has not just refrained from passing an awful law but moved to fix an older bad law.

The bad law in question is the Digital Millennium Copyright Act, which when it passed in 1998 made it a crime to circumvent “a technological measure that effectively controls access” to a copyrighted work. Bizarrely, our mobile phones were caught up in that sweep.

Stretching the lawSo do wireless carriers lock the SIM card slots of phones to protect software copyrights? Not really. They do it to make it harder for you to switch to another carrier (even though they already have early-termination fees to thwart your defection). But the wonderfully elastic DMCA was easily stretched to cover this situation.

The 105th Congress wasn’t completely oblivious about the blank check it gave to Big Copyright with that law, and so the DMCA included a provision that lets the librarian of Congress, on the advice of the register of copyrights, grant temporary exemptions to the anti-circumvention clause. That’s exactly what Librarian James H. Billington did in 2006 when he allowed phone unlocking.

Alas, in subsequent exemption rulings he narrowed that right before extinguishing it almost completely in 2012, on the grounds that “consumers now have access to a variety of unlocked phones.” As in, why whine about not being able to unlock your paid-for iPhone when you can buy a new, unlocked iPhone for $450 and up?

At that point, unlocking-service entrepreneur Sina Khanifar and Republican policy wonk Derek Khanna got righteously mad and filed a petition at the White House’s site.

Theirs easily crossed the required 100,000-signature threshold and drew a more serious response than, say, an earlier request that the U.S. build a Death Star. Wrote senior adviser R. David Edelman: “The White House agrees with the 114,000+ of you who believe that consumers should be able to unlock their cell phones without risking criminal or other penalties.”

That got a few policy wheels turning a little faster. By the end of last year, some public nagging by new Federal Communications Commission Chairman Tom Wheeler led to the major carriers pledging to unlock the phone of any out-of-contract subscriber on request — and even to notify them when they’d (ahem) unlocked that option.

That didn’t make the Unlocking Consumer Choice bill irrelevant — the industry promise covers only current and former subscribers, not recipients of their old phones. And it doesn’t let you ask somebody else to unlock the phone.

Making the illegal even more illegal Goodlatte’s bill, endorsed by the Obama administration in December, does both. And on Feb. 25, it passed the House 295-114 … with one tiny, last-minute change. That revision added a line ruling out “unlocking of wireless handsets or other wireless devices, for the purpose of bulk resale.”

That’s nowhere near the worst change slipped into a bill days before passage, but it was enough to draw denunciations from prior supporters like Public Knowledge and the Electronic Frontier Foundation.

The change was supported by a committee report that explains that “ongoing criminal enterprises … profitably steal large numbers of smartphones for resale after they are unlocked. This legislation would not enable such enterprises to avoid prosecution under the law for the underlying theft or for the circumvention.”

That is silly. Who was ever going to legalize stealing phones? And it does not square with the carriers refusing Samsung’s offer to preload Absolute Software’s kill switch LoJack service on some phones, which I can confirm locks a phone from further use even after you try to reset it to factory condition.

Don’t get used to it
But the worst problem with Goodlatte’s bill is that it does nothing to stop this cycle from repeating at the next DMCA exemption proceeding in 2015. Our rights to use the things we buy should not be subject to editing by unelected officials every three years — not least when they can’t even be consistent in their decisions.

This bill also doesn’t address all the other ethically sound things that remain crimes under the DMCA — for instance, like when I rip DVDs to my computer so my toddler can keep watching them after she inevitably scratches or breaks them. There is a bill that would fix that — the Unlocking Technology Act, sponsored by Rep. Zoe Lofgren (D-Calif.), would make it a crime to defeat a digital lock only if you’re actually trying to rip off somebody’s copyright.

That’s eminently sensible. And therefore likely to take a lot longer to get anywhere than last week’s more modest phone-unlocking bill.

Email Rob at rob@robpegoraro.com; follow him on Twitter at @robpegoraro