Saturday, May 28, 2016

Don't have Facebook Account ? No need they can track you.


       Facebook being one of the giant in Social Networking get its major share of revenue from advertisements. They are using targeted Ad service to gain money. Recently there has been a statement that Facebook can track even if user don't have account.

        Google owns one of the Ad service in the name of Adsense which will display the targeted ad to their clients. This is by monitoring the user activities online. To make it simple go and visit any commercial portal and look for an item, you will see the same in whatever page you loaded provided it is Adsense powered.

         Likewise Facebook is going to extend their business beyond Social Networking and they are gonna use Third Party Cookie information that supports Facebook plugins to provide targeted ad to the audience.

        Facebook states that they are not selling any user data to marketing agency but they got a huge amount through marketing in the first quarter alone.

       With this huge step there is no need that one should have an account in Facebook to get targeted Ad now even a person with no Facebook account can get Ad from Facebook through third party cookie information.

P.S: The post is to create awareness and not to create any negative impact.

Wednesday, May 25, 2016

Google Trust API to replace passwords.


          Passwords are used from very olden days to provide authentication to any service. It is to be noted that the password strength plays a major role in the security of the system. Recently Google introduced a new way to replace passwords.

          Many people are not aware of the password strength or having negligence decided to use simple passwords such as "123456" or "p@ssw0rd" as their account passwords.

          There has been many hacks due to the simple passwords, but many are not even changing their passwords keeping it vulnerable.

          Google inorder to keep it low introduced a new way of authentication known as #Trust API that can identify a person who they are claiming to be.

           This API idenifies a person by taking Biometrics into consideration such as face and also other parameters such as voice pattern, typing pattern and timings, location. These parameters are considered and then decision is made.

            Earlier there has been a method that the device unlock and lock if it is under a specific location and this is the upgraded version to it in the name of #Trust API.

            If the parameters fails to identify a person then he / she will be asked to enter their password in order to provide access to the service.

P.S: The post is to create awareness and not to create any negative impact.

Saturday, May 21, 2016

How to decrypt TeslaCrypt Ransomware.


          As an advancement in malwares, its period for Ransomwares. It encrypts all the files in the computer or device and demands a ransom to be paid in the form of Bitcoins to get the decryption key. Recently they released the master key for TeslaCrypt.

          #TeslaCrypt is one such ransomware that demands around $500 in the form of Bitcoins as ransom to provide decryption key to the victims. Now the master key that decrypts the files has been released, not by any security professionals but by the ransomware authors themselves.

           The ransomware authors posted that "Project is Closed" and they also posted the decryption master key with which all the files can be decrypted. Eset developed a new free decrypter tool to decrypt the files.

           If you are one of the victim of #TeslaCrypt you can decrypt your files using either using this tool or using this tool.

           For any analysis the master key is as below

440A241DD80FCC5664E861989DB716E08CE627D8D40C7EA360AE855C727A49EE

           The main reason for the attack of ransomware are

1. Downloading attachment in email from unknown sender.
2. Visiting or initiating download from unknown or fake site.
3. Malware infection.

P.S: The post is to create awareness and not to create any negative impact.

Thursday, May 19, 2016

Android Instant Apps.


         Android owns a lion share in smartphone market and is being used by billions if users world wide. Android is bringing many awesome features these days. Recently in the developer conference a new cool feature has been released by the team.

          Consider you are going to book a movie ticket but doesnot have the corresponding application. You may download the application or share it from friends, but these options seems to be a tedious some times. Google came up with an idea to solve the issue.

           Hereafter no need that you have to install the application or download the application to execute them, just use them. All you have to do is to click on the URL use the application then close the window.

           It is not like opening the application in the browser, the concept is known as #Instant apps. All the user have to do is to click on the corresponding URL and then the miniature version of the application pops up, make the action then close the application.

            No need for bandwidth consumption and waiting to download the application but the existing apps has to be modified by the developers to meet this new feature.

            It also offers "Call to action" with which the application can be downloaded if the user finds it interesting. The feature will be released offically and it will be supported by Android 2.2 (Jelly bean) and later versions.

P.S: The post is to create awareness and not to create any negative impact.

Allo Duo - Smart Apps from Google.


           Google has been researching in the field of AI (Artificial Intelligence) for quite long time and have made many advancements. Now they have introduced a new application that uses AI. The app is said to be more smarter.

            #Allo is a messaging application that uses AI to give more smarter answer and then uses the machine learning that helps in growing smarter. It gives replies to the users in the form of pictures and also in the form of stickers and emoticons.

            Allo is powered with Google search engine and which can be used by typing @google to invoke the feature while chatting with others. It also makes a search with pictures to find the picture that you are interested or thinking.

            Allo can also be used to book hotels, restaurants and also finding scores and make a Google search. It also offers End to End Encryption if activated the #incognito mode.

             Duo is the video calling application that also uses End to End Encryption to secure the chat and also Allo offers the feature of expiring chats.

             The application is yet to be released officially by Google for both Android and iOS users.

P.S: The post is to create awareness and not to create any negative impact.

Saturday, May 14, 2016

Microsoft removes Wi-Fi Sense Password Sharing feature.


             Microsoft released its latest version of operating system in the name of #Windows 10. It has many new features and one among them is Wi-Fi Sense password sharing. Recently Microsoft decided to remove Wi-Fi Sense password sharing feature.

             Wi-Fi Sense password sharing feature let others connect to the network and it let others share the network. There is no option to select any selected contact for sharing Internet.

              The password can be shared with contact list in Facebook but can't select any separate contact. This feature is not widely appreciated though. Through this option it is possible to conduct Man in the Middle attack.

               With fewer response from the users, Microsoft planned to drop the feature in its latest release Windows 10 build 14342. This version has been released for testing. 

                The company will remove Wi-Fi sense password sharing option from its anniversary update, but the company will keep Wi-Fi sense features that let users to connect to open networks.

P.S: The post is to create awareness and not to create any negative impact.

Wednesday, May 11, 2016

WhatsApp for Desktop and Mac.


           WhatsApp being one of the famous application used by billions of users globally has new feature. Earlier this year the company rolled out End to End Encryption for all users. Recently WhatsApp released its official desktop software.

            Few months back, WhatsApp released its web client through which any user can use WhatsApp through the browser if it is compatible. After that it offered End to End Encryption to its billion users as default setting.

            Now the company has released desktop software for using the service. It is available for both Windows and OS X. All that need is to have Windows 8 and above for Windows users and OS X 10.9 or above to work.

            With this new release any user can use the service through this software. Once installed, just scanning the QR code as in case of web client will make it work.

             The software is released officially and is available for download. You can visit the page here for direct download link.

P.S: The post is to create awareness and not to be misused.

Monday, May 9, 2016

Apple's iMessage on Android phones.


          Apple provide an encrypted messaging system in the name of #iMessage that allows Apple users to send end to end encrypted message. Recently a developer came up with the solution to send iMessages to Android phones.

           It needs a Mac or iMac for messaging. The service is not provided by Apple officially and is done by a developer through a smart little hack.

           The name of the code he developed is known as #PieMessage. It needs a OS X client as a server to route the messages to an Android phone. The entire work is done by Mac systems.

           It receives the Apple script to capture iMessages as they arrive on the system and then uses Java app to scoop the message. It then forward it to the Android phone which will inturn display in the custom application.

          The limitations are one can't send group message but can receive one and it will not show "typing" message. Apple may block this service in near future as it may cause risk.

           The developer released PoC for public reference and also the code is available online through GitHub.

P.S: The post is to create awareness and not to be misused.

Thursday, May 5, 2016

Quantum Computer Online by IBM.


          Quantum computers has been a great research work for the past year. Giants like Google and Yahoo are in experimental phase. Recently IBM build its first Quantum computer prototype like version online.

          Quantum computers work much faster than the conventional computers because they use Quantum mechanics for computations. Normal computers uses "bits" for representation of data whereas Quantum computer uses "qubit" for representation which works more faster.

          First prototype has been developed by IBM and they have released it online for public to use it and perform computations. 

           The computer has been placed at New York and the users can access it through cloud interface online. A Quantum computer with computational power of 50 qubits will be more faster than any super computers that exists.

            IBM is also plaaning to build a Quantum computer of computation power 50-100. Now users can use the IBM's computer by filling the form asking for details and with the invitation any user can access its computational power.

           You can access that through this link.

P.S: The post is to create awareness and not to be misused.

Wednesday, May 4, 2016

New iPhone Phishing scam.


            Phishing is one of the increasing cyber attack that has a high success rate as it exploits the human trust. Phishing is usually done to steal some sensitive information. Recently a new phishing scam has been uncovered in twitter.

           Phishing is usually done by creating a fake website and luring the victim to visit the page and give away the sensitive information. It can be password, debit/credit card details and also ATM pin.

          Few days back there has been posts in twitter by some celebrities stating that they received message (text) stating that "Your iCloud account has been deactivated and needs to be reactivated by clicking the link below".

          There is a link below which will take you to some other site and there it gets the passwords and thus the account can be compromised or can be used for any other cyber attacks.

          It has been posted by two celebrities in twitter and Apple stated that they didnt send any message like this.

           It is very normal for users to receive messages pretending to be from Banks asking for details and may also from any financial organizations. 

           Users are recommended not to respond to this kind of messages and if done it is highly recommended to change the password immediately.

            Users can now view this blog also through https://kingprakatheesh.blogspot.in HTTPS is now supported for this blog. Thanks to all readers.

P.S: The post is to create awareness and not to create any negative impact.