Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

May 3, 2016

University of Michigan and Microsoft Recognize Study Showing Flawed Security For Smart Homes



But new findings suggest these systems could hold hidden opportunities for hackers to break inside without being noticed. The University of Michigan used malicious apps to hack Samsung's SmartThings in four successful attacks that opened electric doors, changed devices to vacation mode and set off fire alarms.

[From article]
Transforming a home into an 'intelligent agent' allows users to monitor, control and secure it via apps and a smartphone.
But new findings suggest these systems also give hackers the tools needed to operate smart locks, change access codes and set off Wi-Fi enabled smoke detectors.
The University of Michigan hacked Samsung's SmartThings in four successful attacks and used the systems own SmartApps to carry each one out.
'It’s important to note that all the vulnerabilities are hypothetical and haven’t affected SmartThings customers’ because of the approval and review processes they have in place, but they have still worked with the researchers to further secure the platform based on their findings,' a SmartThings spokesperson told DailyMail.com in an email.
The University of Michigan, in collaboration with Microsoft, says this study is 'the first in-depth empirical security analysis of a popular emerging smart home programming platform'.
By evaluating the platform's security design and investigating the 499 SmartThings third-party apps (SmartApps), researchers found the biggest problem is that 40 percent of the apps are 'over-privileged'.
The idea that an app is over-privileged means it can gain access to more operations on the device than it needs to perform its function.
'The access SmartThings grants by default is at a full device level, rather than any narrower,' Atul Prakash said, computer science professor at the University of Michigan.
During the first attack, researcher were able to unlock electric doors by simply sending users a malicious link in a third-party app.
If users clicked on the URL, they were brought to the SmartThings website to login their credentials.
A hacker can then redirect a bug to the app and capture the login data to 'inject' a new code into the electric door lock.
The researchers also found that it is possible for developers to create an authentication method called OAuth incorrectly.
This flaw, in combination with the over-privileged SmartApps, allowed hackers to create their own PIN code into the door lock – without the homeowners knowing.
The team showed that an existing SmartApp could be remotely used to make a spare door key virtually by programming an additional PIN into the electronic lock.
Or another can 'eavesdrop' on someone setting up their PIN code for the lock, which will then text it to the hacker.


The SmartApp, which they called a 'lock-pick malware app' was camouflaged as a battery level monitor and only showed the need for that capability in its code.
Earlence Fernandes, a doctoral student in computer science and engineering who led the study, said that 'letting it control your window shades is probably fine.'
'One way to think about it is if you'd hand over control of the connected devices in your home to someone you don't trust and then imagine the worst they could do with that and consider whether you're okay with someone having that level of control,' he said.
The final attacks were carried out by tricking tricking devices inside the home.
The team was able to inject erroneous events in fire alarms or lights that turned them on or switched them to vacation mode.
These results have implications for all smart home systems, and even the broader Internet of Things, researchers said.
'The bottom line is that it's not easy to secure these systems' Prakash said.
'There are multiple layers in the software stack and we found vulnerabilities across them, making fixes difficult.'
The researchers told SmartThings about these issues in December 2015 and the company is working on fixes.
The researchers rechecked a few weeks ago if a lock's PIN code could still be snooped and reprogrammed by a potential hacker, and it still could.
'Protecting our customers' privacy and data security is fundamental to everything we do at SmartThings,' CEO at SmartThings Alex Hawkinson shared in a recent blog post.
'We are fully aware of the University of Michigan/Microsoft Research report and have been working with the authors of the report for the past several weeks on ways that we can continue to make the smart home more secure as the industry grows.'



http://www.dailymail.co.uk/sciencetech/article-3569789/So-smart-home-Researchers-reveal-major-security-flaws-Samsung-s-SmartThings-let-hackers-unlock-doors-set-alarms.html

So much for the smart home: Researchers reveal major security flaws in Samsung's SmartThings system that let hackers unlock your doors and set off alarms
Researchers found 40% of 499 SmartApps are over-privileged
Hackers can create new PIN code by sending users malicious link in app
Injected erroneous events used to trick devices to turn on or shut down
By STACY LIBERATORE FOR DAILYMAIL.COM
PUBLISHED: 14:06 EST, 2 May 2016 | UPDATED: 14:57 EST, 2 May 2016

January 25, 2016

Hidden Tricks For Windows Ten





[From article]
Windows 10 is now installed on more than 200 million gadgets worldwide. That's quite a feat in the tech world, since its official release was only six months ago. If your computer is one of those gadgets, you've probably found Windows 10 has its share of sheer winning features and, unfortunately, very frustrating steps.
[. . .]
Want to know even more about Windows 10? I have a slew of step-by-step tips and tricks about Windows 10 at Komando.com.

http://www.foxnews.com/tech/2016/01/23/5-windows-10-tricks-need-to-know.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+foxnews%2Fmost-popular+%28Internal+-+Most+Popular+Content%29

5 Windows 10 tricks you need to know
By Kim Komando
Published January 23, 2016 

June 11, 2015

Middle Finger Emoji Coming To Microsoft Windows





Microsoft’s Windows 10 will bring rude middle finger emoji
Microsoft has added a swearing middle finger emoji, and a grey default colour, as part of its plan to shake up the little smileys in its new operating system. Windows 10 will be the first operating system to support the swearing hands, a decision some have hailed as brave. Apple’s iOS and Google’s Android don’t yet support the swearing finger, which was approved as part of the emoji keyboard in mid-2014.

September 13, 2012

New Computer Sends Out Malware, Microsoft Sues


[From article]
"As soon as we powered on this particular computer, of its own accord without any instruction from us, it began reaching out across the Internet, attempting to contact a computer unfamiliar to us," Stratton said in the document filed with the court.
Stratton and his colleagues also found Nitol to be highly contagious. They inserted a thumb drive into the computer and the virus immediately copied itself onto it. When the drive was inserted into a separate machine, Nitol quickly copied itself on to it.
[. . .]
more than 37 million malware connections have been blocked from 3322.org, according to Microsoft.

http://apnews.myway.com/article/20120913/DA18PLQ80.html

From brand new laptop to infected by pressing 'on'
AP
Sep 13, 4:35 AM (ET)
By RICHARD LARDNER

December 22, 2009

Will Microsoft Give Away Free Copies of WORD?


http://www.breitbart.com/article.php?id=D9COH00O0&show_article=1

AP
Court: Microsoft violated patent; can't sell Word
Dec 22, 2009 01:29 PM US/Eastern

February 21, 2009

Obama's Stimulus Bill (also known as the Lobbyist Enrichment Act) grants millions to billionaire.


http://www.businessinsider.com/obama-stimulus-saves-microsoft-billionaire-hundreds-of-millions-phew-2009-2

Obama Stimulus Saves Microsoft Billionaire Hundreds Of Millions
Nicholas Carlson|
Business Insider
Feb. 19, 2009, 8:00 AM

February 3, 2009

Farther is Better

Farther is Better

Good thinking Deval. (Kyle Cheney, State House News Service, “Patrick to tout Microsoft's Cambridge location in West Coast trip,” Cambridge Chronicle, February 03, 2009) Why would anyone in California want to go to the suburbs of San Francisco to consult with Microsoft? You can come 3,000 miles to Cambridge to get your technical advice. Those Harvard Corporate lawyers are smart. Are you writing or doing any research for your book on this trip Governor?

http://www.wickedlocal.com/cambridge/news/x1851001083/Patrick-to-tout-Microsofts-Cambridge-location-in-West-Coast-trip

Patrick to tout Microsoft's Cambridge location in West Coast trip
By Kyle Cheney/State House News Service
Cambridge Chronicle
Tue Feb 03, 2009, 05:52 PM EST