Thursday, June 30, 2016

Google knows more about you than anyone.


         Google is becoming one stop shop for all Internet activities right from search, videos, books, maps and many more. Google collects information about users to provide them with targeted advertisements. Recently Google introduces a new concept of "My Activity".

          Google's new My Activity will store all of your activities in Google products like searches, videos and everything. You can control the information that Google can use. The information allowed to Google will be used to provide users with specific targeted advertisements.

          Google is also about to roll out new "Prompt" feature by which one can customize the ad that are displayed based on various filters. The option is known as opt-in feature.

           This option will provide users more control over the advertisements. Example you are browsing on your mobile device and you dislike the ad, you can delete the ad and it can be deleted across all your devices rather than deleting on each devices.

            If you prefer privacy to be main concern you can have ultimate privacy control by controlling what are all information should be allowed for Google to track.

P.S: The post is to create awareness and not to create any negative impact.

Saturday, June 25, 2016

Dozens of malicious Android Apps.


              Being an open-source operating system, #Android is exposed to a large attack vector due to the publicity and also the enormous amount of users across globe. Recently dozens of Android applications that cause harm to device has been revealed.

               Trend Micro detected a family of malicious applications that are being hosted in the Google Play Store has the capability of rooting almost 90 percent of Android devices.

                Rooting is the process of gaining super user privilege to the device. User who roots his/her mobile can customize anything from scratch, but it is highly not recommended due to the security risks it possess.

                 Rooting opens front door of the device for anyone and so any attack vector can attack the device. Its like the defense shield being teared apart. The apps are dubbed as "#Godless" has already been downloaded many times.

                 Once installed it uses Android Framework Tools to root the device and then it contacts the attackers Command and Control server and download the application further needed to exploit the devices.

                  It also make sure that it is not noticable to the users. It is highly recommended for any user to review the developer before downloading any applications from Google Play Store.

                 Many malicious applications are in the form of games, flashlight and other utilities for the devices.

P.S: The post is to create awareness and not to create any negative impact.

Thursday, June 23, 2016

Google Prompt - Easier 2 factor authentication.


              Due to the increase in data breaches and the account hacks, it has been a tough time for everyone to secure their account from breaches. One of the solution exists till now is 2 factor authentication. Recently Google has made this 2 factor authentication a lot easier one.

               Many finds it difficult to use 2 factor authentication since it takes 10 to 15 seconds extra and also some other problems with devices. There is also an other way around to use Google Authenticator application that will generate the code everytime similar to RSA token.

               Now, Google made it very easier, all the user have to do is to just tap. Whenever the 2 factor authentication has been in effect, a popup message will arrive, just tap the message to sign-in. It is the pop up message through notification.

               To enable this feature login to the account and just enable 2 factor authentication and then select the "#Google Prompt" in the second dialog box and then provide the phone number from which the account has to be authenticated.

                Requirement for this feature to work is, if you own an Android device then updation of Google Play Store will do good. In case of iPhone, Google search application is needed and it should be signed in with the same account to use #Google Prompt.

P.S: The post is to create awareness and not to be missued.

Tuesday, June 7, 2016

Modify/Delete Facebook messages after sent to others.


            Facebook owned messenger has been used as a famous messenging service among users. It is very common question among users how to modify/delete the messages after it has been sent. Recently a security researcher has found a solution for this.

            Once the message has been sent from the Android messenger application it can be altered or deleted. Facebook messenger assigns a unique identifier to every message and it can be viewed from the php file.

            Once the php file has been comes up with the id of the message, it can be altered or modified and once it has been updated the target will get only the updated or revised message which has been updated recently.

           The bug however is a simple has been notified to the Facebook and they stated that the bug doesnot possess serious threat as they are using Anti-Spam and Anti-Malware solutions in their systems.

           Only the Android version of Facebook messenger application has this simple bug and has been patched by the Facebook team.

           The way how to do it is published online and it can be viewed here.

P.S: The post is to create awareness and not to be misused.

Saturday, June 4, 2016

Earn more Gems for Clash of Clans, Diamonds for HayDay.


           "Desire is the root cause of all miseries". It is true that curiosity or the desire for wrong deed costs more. Hay Day, Clash of Clans are the games that has billions of users across globe and is very famous. This article will explain you #how to get more gems.

            Before that let me explain the working of those games. They are server side games in which your device will only have the client package that receives data from the server everytime you load the app. This is why you need Internet connection for playing those games.

             Your application will update the information at regular time basic like if you lose gem by 2 it will be updated to the server. If you exit the app the last update will be saved and sent to the client when you load after some time.

              There are games in olden days in which total game will be installed in the device which allow some pretty hack like cheat code. Imagine you are playing hay day and you are having 10 diamonds, you are tampering the request and make it 100 and send it to the server, the server will validate it by calculating the distance. Is it possible to get 90 diamonds in a second? No, server discard the request and the app will exit or restart with old settings.

               All requests will be validated by the server before updating the setting. Now imagine is it possible to get more gems, diamond by easy click and go process? Few days back I personally received a story from my friend.

               Player of CoC receives a whatsapp message from a person stating "Wanna get more gems click the link below", clicking the link and entering some details make me lose the game and also ACCESS to GMAIL account (Remember Google has Single Sign On mechanism which allows you to access all google product with one service signed in). Now game lost, account loss, not to mention Android phone has your google account linked.

               Adverse effects of clicking the link are

1. Loss of game
2. Loss of gmail / any account access
3. Some action can be taken in Android phone since it is integrated with google account.

              Beware of these type of messages as they are spreading in massive amount. It may affect the system also. Never go for any hack available online or any download file which may be a malware. 

P.S: The post is to create awareness and not to create any negative impact.

Either Encryption or AI - Facebook Messenger App.


             Every giant in Internet service domain started offering End to End Encryption so as to protect the data that has been sent between entities without being monitored in between. Recently Facebook set to roll out a new feature in its messenger application.

             Facebook is rolling out its messenger application that offers either End to End Encryption or Artificial Intelligence as opt in feature. Many researchers debated over the opt in feature available in smarter Google app.

             Users are allowed to select either encryption or smarter bot feature. With this feature the application will make flexibility to user to decide whether they want either privacy or smarter app.

              Facebook is yet to roll out the version and by updating the application users can enjoy this new feature.

P.S: The post is to create awareness and not to create any negative impact.