Cyber – Eraser https://eraser.heidi.ie Secure Erase Files from Hard Drives Thu, 17 Sep 2020 12:56:36 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.2 https://eraser.heidi.ie/wp-content/uploads/2019/07/cropped-eraser-avatar-32x32.png Cyber – Eraser https://eraser.heidi.ie 32 32 Brave Browser Tips and Tricks https://eraser.heidi.ie/brave-browser-tips-and-tricks/ Thu, 17 Sep 2020 12:50:37 +0000 https://eraser.heidi.ie/?p=1470

The popularity of the Brave browser has grown tremendously due to its emphasis on privacy and giving users more control over their activity. You’re no longer the product, as is the case with conventional browsers using trackers to sell information to marketers and profiting from your personal data. What’s more, by blocking trackers and using less memory during operation, it provides a faster browsing experience for users, be it on desktop or smartphones. Once you install it, here are ways how you can set it up to get the most out of the browser.

Getting things ready

As you shift your activities to the Brave browser, two things will be important to ensure that you have smooth operations going forward:

  • Setting Brave as your default browser

That way, whenever you’re opening links, going through your social sites, accessing your mail and other activities, you will remain protected by Brave’s security shields. To have it as your default browser, you will get this option under the settings menu. The easiest way is to simply launch the browser and click on the button prompting you to make it the default browser.

Brave Default
  • Importing your settings

Like moving into a new home and bringing your furniture with you, you’ll want to bring over your bookmarks, saved passwords, browsing history and cookies from your previous browser. The import window will enable you to select the specific browser data that you will want to bring to Brave.

You can import them right from the Welcome Tour after installing the browser. In case you skipped this bit, launch the browser and click on the horizontal lines that are at the upper right corner, select settings, and in the window that pops up, click on “Import bookmarks and settings”. 

Brave Settings

Select the browser that you want to get the data from, then click on “Import”

 

Personalising the browser

Next is tweaking the browser to suit your individual preferences. This is where aspects like selecting the colour schemes and extension tools for your browsing experience come in.  Here are a couple:

  • Enable Dark Mode

  1. Go to settings
  2. Click on the Appearance tab
  3. On the Brave Colours options, change from Light to Dark. 
Brave Dark Mode
Brave Dark Mode

If you already have dark mode for your OS, you can simply inherit this by clicking on “Same as Windows” option thus giving it the same appearance with the rest of the system, so that whenever you change the OS settings the browser will automatically adapt to it. 

  • Choosing a customised theme

You can get more customisable themes from Chrome Webstore.

Here, you can use any of the themes just as you would on Chrome. Select the preferred theme, then click on “Add to Brave”. For instance, let’s pick on Oceanic theme:

brave-customise-theme

This will be quick and straightforward, and it gives you the opportunity to pick from a wide assortment of themes to suit your particular taste.

Increase your privacy when browsing

  • Use DuckDuckGo as the default search engine

To take your privacy a notch higher, you can choose to set the default search engine to DuckDuckGo. This is because alternatives like Google will keep a record of the queries that you type into the search bar.  Brave itself shields you from intrusions like the cookies, ads, and pop-ups, but when you’re using Google and similar search engines your privacy may be compromised. Making the switch to DuckDuckGo will ensure that your searches aren’t tracked. This is also accessed from the Settings window as shown below.

Brave DuckDuckGo default

Select DuckDuckGo, and you’re good to go. 

  • Use Brave with Tor

Using Brave’s private window, DuckDuckGo and (The Onion Router) together will make it extremely difficult for your online activities to be tracked. The websites being visited will also find it hard to identify or track the IP addresses that access it when browsing with this mode. You can use the browser with Tor by selecting the option from the drop-down menu after clicking the three horizontal lines on the top right corner. 

Brave with Tor

Make money with Brave Ads

The browser also allows you to monetise the amount of time you spend online. That way, over the course of your normal browsing activities, you will get to rake in some cheddar. This is through the Brave rewards, which can be accessed by clicking that triangle that’s on the upper right section of the browser.

Brave Ads

From the ads section, you can set the frequency of the number of ads that you want. You get to choose between 1 – 5 ads per hour. Ads will pop up in a non-intrusive way as you carry on with your normal browsing. When you view the ad and click on it, it will direct you to the target site, and you earn BAT (Basic AttentionTokens) in the process.

Are you a publisher or content creator? Joining the Brave Rewards Creators program will enable you to earn BAT tokens through tips from visitors coming to your website or channel and viewing your content. You also earn when you refer new users to Brave.  

Reward your favourite sites

On the other end of the spectrum, you can support content creators using BAT. This is basically like tipping the content creators for a job well done. 

This is through the auto-contribute feature, that enables the sites to receive your contributions based on how much you use the sites. Brave also gives you the flexibility to set how the payments will be made.  Click on the section indicated below to access the settings.

brave-award-sites

The wallet that the browser creates for the BAT tokens can also be linked to Bitcoin and other digital assets. You can also purchase the BAT tokens from cryptocurrency exchanges, or get BAT from special promotions that are done by Brave. 

Sync desktop browser and mobile app

This enables you to sync your browser across your different devices. Access the sync option from the dropdown menu, and click on “Start a new Sync Chain” and select phone/tablet. It will provide you with a QR code that can be scanned.

Brave Sync Desktop Browser with Mobile

From your other device, access the sync settings on the Brave app, select “I have a Sync Code” and scan the QR on your desktop browser.

Brave Sync QR Codes

If you’re syncing to another desktop PC or laptop, select “Start a new Sync Chain” and pick computer. You will be provided with 24 unique words.  On the target computer, select “I have a Sync Code” and enter these words.

Note that the words are sensitive, and should be treated like a password. If anyone accesses them, they can compromise your synced data.

Block social media

Some sites have single-sign on for Google and Facebook. Brave has a feature that disables this, and also blocks the embedded posts from LinkedIn, Twitter etc. This is accessed from the Settings, and you get to toggle the options as you see fit. 

Brave Block Social Media

In addition to enhancing your privacy, it also helps you in saving on the costs that you spend on data, since you will not be downloading the extra content. Less power is also spent, saving your device’s battery life. Let’s get more into this with the next Brave browser tip.

 

Save more power

Disabling scripts on the sites you visit also comes in handy in reducing your device’s energy consumption. 

For instance, when browsing through BBC news site, you may simply want to read news articles and not waste data bundles or power on the numerous videos and similar content that will be loaded as a result of scripts. To block them, click on the Brave Shields icon and toggle on the Scripts Blocked option.

Brave save more power
]]>
Erase Files from Mac – Product Review https://eraser.heidi.ie/erase-files-from-mac-product-review/ Fri, 10 Jul 2020 09:59:32 +0000 https://eraser.heidi.ie/?p=1329

Sure, you can delete a file from your Mac—but is it really gone? The usual method doesn’t really remove the file from the device. Here’s a breakdown of what happens:

  1. Move to Trash – Puts the file in the trash can, where it sits until you empty it. It’s just like that bin at home, where the contents need to be taken out when the garbage collectors arrive.
  2. Empty trash can – It marks the space as “Available” for the system, so that future files can be saved on that spot.

Before the data is overwritten the next time that the Mac will need space, the original file will still be there—which is why deleted files can be recovered. However, there are times you want to ensure that the data you’ve deleted is completely eviscerated from your Mac. These are the likes of financial records, intimate photos that would be damaging should someone get their hands on them, or other kinds of data that you don’t want anyone to ever access.

What Happened To The Secure Empty Trash Option?

Previously, Apple had provided the Secure Empty Trash menu item which overwrote the files being deleted with “meaningless data”. This option on Apple’s Finder was available for 12 years, from OS 10.3 Panther, being dropped with OS 10.11, El Capitan.  It would remove the file’s index and overwrite it with zeroes. This didn’t mean that the files were completely out of reach, given that a government agency or high-end criminal enterprise could have the resources needed to read it as an electromagnetic ghost. However, the overwritten data was out of reach of the everyday users and businesses who wouldn’t have the time or money for it.

Unfortunately, this feature is no longer available. The item was originally designed around hard disk drives (HDDs). On the other hand, Solid State Drives (SSDs) store files in a different manner—from the SSD’s controllers to the memory locations—that prevents this option from providing the desired result.  Apple decided that it was better to remove the Secure Empty Trash item from the menu since it risked not being fully effective in deleting files.

To quote the El Capitan v10.11 security release notes:

“An issue existed in guaranteeing secure deletion of Trash files on some systems, such as those with flash storage. This issue was addressed by removing the “Secure Empty Trash” option.”

As such, third-party apps are now required. Handy data shredding solutions have been developed to ensure that the data is completely removed from the system. Here is a review of the products that are in the market:

 

5 Applications To Permanently Erase Files From Mac

Shredo

This compact app from MyMixApps uses software algorithms to overwrite data over the existing file, instead of simply directing the OS to reduce the space. Basically, the data gets scrambled so severely that it cannot be retrieved. You don’t need to use the Trash option here. Just drag and drop the file onto any of the three circles that are on Shredo’s translucent window.

Here, you have three options of digitally shredding the data, based on the speed and level of security you want:

Shredo Shredding Methods

You can add more files into Shredo and queue them for destruction by clicking the “green +” button, or adding files through the Services menu in the Finder.  Shredo can also be used to remove data on external volumes and flash drives, and here the shredding time will vary based on their size, and the method that you’ve selected. It also comes with a Privacy Scan feature for removing privacy threats like browser history and cookies from your Mac.

BitRaser File Eraser (Mac)

One of the products from Stellar Data Recovery Inc, this app comes with 17 data wiping algorithms to permanently erase your files, preventing them from being retrieved by data recovery software. These include Zeros, DoD 5220.22-M, and the Gutmann 35-pass.

BitRaser

Some of its key features include:

  • Hard Drive Wiping- It clears your entire hard drive with just a click of a button.
  • File and Folder Wiping- Here, you can delete those sensitive files and folders that you don’t want to be accessed later on.
  • Wipe Internet Browsing Data -This includes cookies, temporary internet files, session data, flash information, cookie data and other information from your web browsers. This is not limited to Safari, but also extends to programs that have embedded browsing, such as Camino, iCab, Omniweb, Navigator and similar apps.
  • Message Data Wipe- The app scans your messaging apps, deleting the data that’s stored in them. These are the likes of the messages themselves, login information, to the media files that have been sent and received. 

BitRaser window

You also get to wipe data from free space (those spaces that hold deleted files from the past), system traces—such as log files that have been made in the operating system, all through to file histories on apps like iPhoto, All Apps,  iTunes, Finder, and VLC Player. It has a friendly user-interface, with the buttons that are easy to navigate. With the advanced scheduling, you can set the system to automatically wipe specific files and folders, or whole volumes once, daily, weekly, or monthly. 

CleanMyMac’s Shredder

CleanMyMac is essentially your Mac’s maid, deep cleaning your unit to free up disc space. However, it comes with an additional utility-Shredder, that can be used to permanently remove data from your hard drive.

CleanMyMac

With this application, you can only erase files—not wipe the entire drive. It also doesn’t have different wiping algorithms to choose from. On the other hand, it does come with maintenance tools to improve on the performance of your Mac.  This keeps your device fast, while also allowing you to remove sensitive files as needed and protect your privacy.

File Shredder — Mac Optimizer Pro

The larger Mac Optimizer Pro app is also a utility software, securing your device, getting rid of junk files, and optimising the Mac’s performance.

File Shredder

One of its features is the File Shredder, that uses multiple-overwrite military-grade technology to get rid of your sensitive files, that way they will not be recoverable. The random binary data ensures that even the lightest traces of the original file will be out of reach of data recovery software. Additional utility functionalities from the app, from freeing up the hard drive space, removing the old cache files and managing your start-up apps and login items give you an all-rounded tool to manage your Mac.

Permanent Eraser for Mac

This is a free app from Edenwaith. It empties the trash using methods like DOE-compliant 3-pass secure erase, and Gutmann method to overwrite the data. Simply click on its icon to empty the trash, or drag and drop files onto it.

Permanent Eraser

The whole process of overwriting the data, scrambling the original file name, and also truncating the file size, then unlinking it from the system, ensures that the erase data will not be retrievable through conventional means. For instance, the 3-pass DoE uses two passes of random data, then a third pass using a predefined data pattern. This secures your files against individuals and businesses who would be forced to spend lots of time and money to uncover it. Certainly, the 35-pass Gutmann method will give you more security.

Downloading and installing it takes a few seconds. While there isn’t a really interactive user interface to work with, the app does provide a pop window when you’re about to erase the tiles that are in the trash. Drag Permanent Eraser into the Finder’s toolbar to integrate it, or use the sidebar to give you quick access when removing the files from your system. Permanent Eraser menu

From its General Preference pane, you can set the erasing level you want for the files, plus CDs and DVDs. Select the desired rewritable optical disc (CD-RW or DVD-RW), then drag it onto the Permanent Eraser icon to completely overwrite the disc’s data.

Conclusion

Ensuring that the data has been permanently been removed is key for your own protection. This is especially before you sell, donate, or trade in your Mac. You don’t want to have your sensitive files being recovered by an unscrupulous individual who buys the hard drive from a flea market months later.  Use file shredding tools to get rid of your sensitive files.

Remember to turn on FileVault on your Mac. It will secure your data automatically, by encrypting the content on your disk. Using FileVault together with any of these data shredding apps will eliminate any chances of your files being recovered by prying eyes.

 

]]>
Cryptocurrency – The Ultimate Knowledge Base https://eraser.heidi.ie/cryptocurrency-the-ultimate-knowledge-base/ Tue, 09 Jul 2019 18:43:50 +0000 https://eraser.heidi.ie/?p=1161 What is Cryptocurrency?

Cryptocurrency is a geeky, technical, and misunderstood term. However, significant organisations, banks, and companies are aware of their importance. In this day and time, it is difficult to find any organisation that has not invested time and money into Cryptocurrencies. Cryptocurrency is the digital currency of the future. It is decentralised and safe. However, there is more to Cryptocurrencies than just these basics.

How did cryptocurrency originate?

Cryptocurrency did not originate as a currency, but rather as a side product of another invention, the Peer to Peer Electronic Cash System. Satoshi Nakamoto, the inventor of Bitcoin, intended to save double spending by utilising a peer-to-peer network. This network has no central authority.

How does the peer-to-peer network work?

Realising digital cash means requiring a payment network with accounts, balances, and transaction details. The major problem faced here is that these networks have to prevent one entity from spending the same amount twice. A central server records all balances, thus preventing the entities from spending the same amount of money twice.

The peer-to-peer network built by Satoshi solved the centralisation of balances by making the system decentralised. In the peer-peer network, every peer needs to maintain a list of all transactions. All peers check if the future transactions taking place are valid or an attempt to double spend. If any peer disagrees, transactions are broken.

What exactly are Cryptocurrencies?

Cryptocurrencies are nothing but limited entries in a database that cannot be changed until and unless specific conditions are met.

The money in your bank account too is just an entry in the database. The entry can only be changed under specific conditions. If the condition of you physically owning the coins and notes is met, then the amount in your database is decreased. Hence, money is just a verified entry in databases. A central database handles transactions of your money.

Cryptocurrencies are similar to the money you own, except the fact that there is no central database to keep track of the Cryptocurrency you own. The database is accessed, shared, and maintained by all servers in the network. Cryptocurrency transactions are hence handled in a decentralised manner.

What is blockchain?

Blockchain is the technology used by Cryptocurrencies to keep a decentralised track of all transactions. A blockchain is essentially a list of records called blocks, linked using cryptography. Each block in the blockchain system consists of a cryptographic hash of the previous block, the transaction data, and a timestamp.

In essence, blockchain is resistant to modification of data. Once a block is verified, it is irreversible and permanent. The blockchain system does not have a central authority but is shared with an immutable ledger. Hence, everything built on the blockchain is transparent, and everyone involved is accountable for their actions.

Example bitcoin transaction using blockchain technology

Let us take a look an example bitcoin transaction:

1. Bitcoin Cryptocurrency comprises of a network of peers.
2. Each peer maintains a complete history of all the transactions and the balance of every account.
3. Let us assume a transaction where A gives X Bitcoin to B. A transaction file is created denoting this transaction and is signed by A’s private key. This is basic public key cryptography.
4. After the transaction file is signed, it is broadcasted in the network and sent from one peer to the other. This is basic p2p-technology.
5. The whole network immediately knows about the transaction.
6. The transaction has to be confirmed for the process to be complete. Confirmation is critical in Cryptocurrencies. As long as the transaction is unconfirmed, it can be forged and is incomplete.
7. Only miners confirm transactions. Anyone can be a miner. However, miners need to invest some work in their computers.
8. To confirm transactions, miners have to find the SHA 256 Hash that connects a new block with its predecessor.
9. After finding the solution, the miner builds a block and adds it to the blockchain. Doing so rewards the miner a specific number of Bitcoins.
10. Since the difficulty of finding the hash increases the amount of computer power invested by the miner, only a certain amount of Cryptocurrency token can be created at a given time. This ensures that forged transactions do not take place.

What are the revolutionary properties of cryptocurrencies?

What makes Cryptocurrencies revolutionary? Why are Cryptocurrencies in such hype these days? There are some properties of Cryptocurrencies that make them extremely reliable, secure, and different than other forms of money.

Cryptocurrencies are secured not by people, but by math. There are more chances of you being hit by lightning, than the chances of your Bitcoin address being compromised. Listed below are the transactional and monetary properties of Cryptocurrencies:

Fast and global
Cryptocurrency transactions are propagated instantly in the network and are confirmed fast. Since peers are located all around the world, Cryptocurrencies are also global.

Secure
Cryptocurrencies are locked by a public key cryptography system and are secured not by people but by maths. Big numbers and strong cryptography makes it impossible to break Cryptocurrency.

Irreversible
Once a transaction is confirmed, you cannot reverse it. It is important to understand that sending your funds accidentally to a hacker or scammer is also set to stone, and you cannot reverse the transaction.

Pseudonymous
It is not possible to connect Cryptocurrencies, which are random chains of characters, to real-world identities.

Permissionless
Using Cryptocurrency is permissionless. You can download the Cryptocurrency software for free, receive, and send Cryptocurrencies without asking for permission from any central authority.

Controlled supply
Cryptocurrency supplies are limited. The schedule written in the code limits the supply of tokens. The monetary supply of a Cryptocurrency in the future can be calculated in the present day and time.

No debt
The money in your bank account is created by debt. However, Cryptocurrencies do not represent debts but rather just represent themselves. Cryptocurrency is as solid as coins of gold.

Some well-known Cryptocurrencies include:

• Bitcoin
• Litecoin
• Ethereum
• Ripple
• NEO
• Waves
• Bither
• STK Token
• Mycelium Token
• NeverDie
• Insanity Coin
• ZCash
• Dash
• XRP
• Monero
• Bitcoin Cash

]]>
Virtual Private Network (VPN) https://eraser.heidi.ie/virtual-private-network-vpn/ Mon, 07 Jan 2019 11:53:22 +0000 https://eraser.heidi.ie/?p=1114

If you access the internet, or if you are a technically savvy person, you might have heard the term VPN floating around a lot. What exactly is a VPN and how does it allow you to be secure over the internet? Read on to find out.

What is a VPN?

A Virtual Private Network is essentially a service that allows you to benefit from the management, functionality, and security of a private network despite connecting to the internet via a public network. In other words, a VPN service lets you access the web safely by hiding your online actions and routing your connection through a server. A VPN can also be thought of as a secure tunnel between two or more devices, thus allowing you to access the web anonymously.

How does a VPN work?

It is now established that a VPN network allows you to access the web securely. How exactly does a VPN work? This is what happens when you connect the web through a VPN:

  1. When connecting to the internet using a VPN service, you start the VPN client from your computer/device. Your VPN service provider provides this VPN client.
  2. The VPN client encrypts your data even before your Internet Service Provider or any interested party can access it.
  3. Your encrypted data reaches the VPN server and is routed to the online destination. Your online destination can be a bank website, a search engine, or a video sharing website.
  4. When the encrypted data and request reaches the destination, the online destination sees that the request/data is coming from a VPN Server. Your computer and your location, however, remains hidden from the online destination.

Hence, connecting to the web through a VPN has these benefits:

• Your data is encrypted even before it reaches your ISP.
• If someone does peek at the data you are sending, they can only see the encrypted information.
• The destination site sees that the VPN server is the origin of the request and not your computer.
• It becomes difficult to identify your computer, or what you are doing.

The web consists of several servers which are interconnected with each other and which share your data amongst each other to let you browse a page. This leaves your personal data out in the open. If you are just surfing a normal website, this mechanism does not harm you. However, if you are browsing your online banking website, your important work website or your business email, then the chances of your data being compromised are huge.

There is no mechanism to hide your location and details from the online destination when accessing the web without a VPN. Your data remains in the open, and the online destination, as well as any interested party, can view it with ease.

How secure is a VPN?

The benefits of surfing the internet through a VPN is outweighed by the questions on VPN security. VPN security is a topic that causes a lot of debate amongst IT professionals. The fact that no two services are identical adds up to the complexity of determining the security level of VPN services. Additional complexities are added upon by the fact that VPN services are driven by legal and policy limitations and the laws of the country where the VPN service is located. The VPN services provided by a company generally depends on the given factors:

Legal factors and Company strategy

VPN service providers are there to protect your data and secure your privacy when connecting to the web. It is, however, important to note that they too are governed by local laws of the country and their own company strategy. There might be cases when the company is ordered to share their records with the court. In other cases, there can be international agreements between two nations to share web activity details. Hence, the borderline of VPN security is ultimately governed by the VPN service that you use. In other words, a VPN is only as secure as the VPN provider itself.

VPN Protocols

Another factor governing VPN security is VPN Protocols. A VPN protocol determines how data transmission occurs over a VPN service. Some protocols are elaborated below:

• PPTP (Point-To-Point Tunneling Protocol)
This is the oldest protocol in use and is a part of the Windows operating system. It uses a TCP control channel to encapsulate point to point packets. However, this protocol falls back in terms of security. It is advisable to avoid a VPN service provider who offers this protocol.

• L2TP/ IPsec (Layer 2 Tunneling Protocol)
This protocol uses keys at each end of your data tunnel to establish a secure connection, but the execution is not very safe. This is another protocol to avoid as its security is debatable and has been questioned a lot.

• SSTP (Secure Socket Tunneling Protocol)
This protocol is also built by Microsoft and is established with SSL/TLS encryption. It works by employing symmetric-key cryptography, meaning that only the parties participating in the transfer can decode the data. Since SSL/TLS encryption is a de facto standard for web encryption in this age, SSTP is a very secure solution.

• OpenVPN
OpenVPN is the most versatile and the most secure protocol in this age and time. It is based on the SSL/TLS protocol and is an open source project which is being improved by hundreds of developers constantly. It secures the connection by using keys which are only known by the participating parties.

• IKEv2 (Internet Key Exchange, Version 2)
This is another protocol built by Microsoft and is an iteration of Microsoft’s previous protocols. It is hence more secure than the other protocols designed by Microsoft. It works by producing the same symmetric key for the communicating parties.

Generally, most VPN’s allow you to select the protocol service to use. The combination of OpenVPN and IKEv2 is the most secure way to use a VPN service.

Is VPN fully legal?

Yes. VPN is a legal service. However, the roles related to VPN services are murky and are different everywhere. Hence, there are different interpretations to as if VPN is a fully legal service or not.

VPNs are legalized in countries like the UK, US, Canada, and Western Europe. VPN services are not legalized in countries like Oman, Russia, UNA, China, Turkey, Iran, Iraq, North Korea, and Turkmenistan. What matters, in this case, is your physical location when using a VPN service.

Find the laws of your local government to know the legal rules related to a VPN service, before deciding to take it up.

Does VPN make you 100% anonymous?

A VPN does not make you 100% anonymous, but it does to some extent. The extent to which a VPN can offer anonymity is however impressive.

Without a VPN, your data is open and subjected to breaches. Your connection remains fully open, and any person with the right tools can peek into the data you are sending over. Having a VPN in the middle means creating a barrier between you and the destination, and encrypting your data. The extent of anonymity of a VPN service depends on the following:

• Logs
If the VPN service keeps logs, then the extent of anonymity is somewhat reduced.

• Jurisdiction
The jurisdiction of the location of the VPN service makes a huge difference to the anonymity of VPN. If a VPN service provider is forced to keep records, then the government might come asking questions that need answering.

• Encryption mechanism and protocol used
The anonymity of VPN also depends on the security of the protocol and the encryption mechanism used.

Make your choice wisely, depending on the extent of anonymity that you require. A VPN service that does not keep logs/records and uses a good encryption mechanism and protocol will work best in keeping you anonymous.

What are the VPN logging policies?

The logging policies of VPN services significantly determines the level of anonymity and privacy that you obtain from the service. Every VPN service has its own logging policy, and the extent of logs they keep depends on their company strategy and local government rules. The logs that a service provider may save include the:
• User activity
• Payment logs
• Connection/ disconnection timestamps
• Devices used
• IP addresses

Tying these details back to you would be difficult, but is doable if a company would deliberately want to trace you. The fewer logs that the service provider keeps, the better will it be for you.

Beware of VPN service providers who ensure anonymity in their sales materials but do not implement it in real. Read a VPN provider’s privacy policy carefully, to know the logging policies that they implement.

Is it okay to use free VPNs in comparison to paid VPNs?

A good VPN service requires a lot of money to run. Costs associated with data transfer, robust servers, employees and infrastructure, etc. causes a VPN service provider to invest a lot into their services. If a VPN service is offered for free, you can be sure of the fact that a lot of compromises have been made.

A free VPN earns money by either having a logging activity for their own reasons or by displaying a lot of advertisements. Free VPN services can also be selling your data to a third party.

The average cost of paid VPNs rounds about to as little as 3-5 dollars a month. Subscribing for a VPN service one to two years upfront can offer you even more discounted rates.

The bottom line of this discussion is the fact that VPN services cost very little but are a good investment when it comes to increased online privacy. Using free VPN services can be even more expensive than it initially seems.

Is VPN Safe for Torrenting?

Generally speaking, VPN services can be used for torrenting. However, it depends on the service you are using and the kind of things that you torrent.

Torrenting is a protocol used to transfer files over the internet. However, it does not define the types of files being transferred. Torrenting is perfectly legal if you have the rights to the data being transferred. Regardless of the VPN services you use, piracy, however, is illegal.

VPNs have their own policy regarding torrenting. Most VPN solutions allow torrenting. However, some VPN services might have their own logging policies for torrenting. Generally, a VPN that does not log your other activities will not keep logs for your torrenting activities. Hence, the use of VPN for torrenting depends on a VPN provider’s logging policy and the type of content you torrent.

Another aspect that determines if a VPN is good for torrenting is the download speed that the service offers. This information is difficult to obtain, so it’s good to read some reviews related to the torrenting download speed that a VPN service offers before you make a choice.

Can VPN be used to Watch Netflix/Hulu?

You can use VPN to watch Netflix/ Hulu, but it again depends on the VPN that you use.

Netflix is available in over 130 countries, but its shows are not distributed equally. Due to legal issues, TV stations have the right to Netflix’s own shows, and those shows might not be available in specific regions.

Netflix and Hulu block content based on location filters. If your country is banned, it essentially means that you will be banned.

However, this problem is solved when you use a VPN to watch Netflix/ Hulu. When using a VPN, you can select the server that you want to connect with. To watch a show on Netflix/ Hulu, you can easily select the server in the country where the show is available. Since Netflix/ Hulu will not be able to see your location, but the location of the VPN server, you can watch the content with ease. Hence, VPN’s can actually help you gain access to Netflix and Hulu content that you could not obtain otherwise.

Does VPN Work on Android/iOS?

Yes. A VPN service can work on Android/ IOS. Many VPN services let you download mobile apps for Android or IOS and set up a VPN connection easily.

However, do not be tempted with free VPN apps for Android and iOS. Research by the International Computer Science Institute and the University of California Berkeley states that amongst the 280 free Android apps that use Android VPN permissions, 75% use tracking libraries, 38% of those apps are malware and 84% of those apps leak the user’s traffic details.

Does VPN Work on SmartTV/Kodi?

Smart TVs and Kodi boxes also use internet connections and using VPNs can help you keep your streams private. To enable a VPN connection in your Smart TV/ Kodi box, you can configure it on the device, or configure it on the router itself.

Most quality VPNs offer the ability to configure your Smart TV with a VPN connection. The steps for configuration differs from VPN to VPN. To configure VPN on your router, refer to the section below.

How to Install VPN on a Router?

The best way to ensure that everything in your home goes through a VPN connection is to configure VPN on the router itself. With this, you will no longer have to install VPN in your individual mobile devices, TV, desktop, etc.

Make sure that your router is compatible with VPNs before you start the configuration. You can do this by checking the website of the manufacturer product on the router. The setup of VPN on a router differs from service to service. You will just have to fill up some standard forms and the process to configure VPNs on a router is pretty straightforward.

How to use the VPN & Tor Combination?

Tor is a service that routes traffic through a worldwide network of random nodes to conceal the user’s location and usage. Using a Tor hence makes it difficult to trace internet activity.

While Tor and VPN are different fundamentally, they can be used as a combination to ensure increased online privacy and security. Tor is 100% free, and there are no limitations when using the free version. To combine the advantages of Tor and VPN:

  1. Enable your VPN connection.
  2. Use the Tor browser to browse the internet.

The VPN connection and Tor web browser now run at the same time. This setup will be considerably slower than the standard VPN-only procedure of accessing the internet. However, the main advantage of this setup is that you get super privacy.

What are Kill Switches and IP Leaks?

Kill Switch

A kill switch automatically kills your internet connection if the safe, encrypted connection drops. A VPN with a kill switch is desirable as your device might attempt to access the internet with a normal connection if a connectivity issue arises in the VPN connection. Not having a kill switch can expose your data when your device switches from the VPN connection to the unprotected connection.

IP Leaks

IP Leaks can occur when your VPN connection fails to hide your IP when you browse the internet. Good VPN services have clever scripts that prevent IP leaks. However, sometimes the underlying issue is with your computer configuration, browser, extensions and the apps that you use. Hence, IP leaks are not entirely VPN problems.

Hence, a good VPN service has clever programming hacks to avoid IP leaks and has a kill switch mechanism that will keep you entirely secure.

When to use a VPN?

There are many advantages of using a VPN service:

• It allows you to access geo-blocked content by hiding your location.
• It hides your activity on the web.
• It encrypts the data you send over the internet.
• It helps you access any Wi-Fi through a protected connection.
• It makes you anonymous on the web.

In conclusion, a good, paid VPN is a good investment (at just 3-5$ a month) if privacy, anonymity, and security are important to you or your business.

When not to use a VPN?

There is no reason not to use a VPN service if online security and privacy are important to you. VPN is an additional layer of security over SSL protocols, antivirus programs, etc. There are not many downsides of using a VPN service as it is a cost-effective and efficient way to ensure online privacy and security. On the contrary, beware of using the so-called free VPN services.

NEED A VPN?

]]>
Smartphone Security – (Android/IOS) https://eraser.heidi.ie/smartphone-security-android-ios/ Mon, 07 Jan 2019 10:59:07 +0000 https://eraser.heidi.ie/?p=1097 Smartphone security is not a new concept in itself, but its scope is changing day by day. While smartphones were used as a mere means of communication in the past, they are being used to store everything from important work-related details to bank account information.

If a potential vulnerability causes your smartphone data to be compromised, then it might turn out to be a potential catastrophe. They say prevention is better than cure. There are many ways how your smartphone’s data might be hindered with, and a number of solutions for the same. If you use a smartphone, it is a smart idea to stay updated about the kinds of potential threats and the preventive measures against them.

Theft Proof your Mobile Data

Taking preventive measures to theft-proof your mobile data saves you much trouble later. Stop malware makers and phishers on their tracks by taking these preventive measures into account:

  1. Lock your mobile
    As simple as it sounds, locking your smartphone is one of the most basic things that you can do to ensure smartphone security. If your phone gets lost by any chance, a simple PIN lock can prevent someone from immediately doing any harm to your personal data. It gives you the time and the chance to block your credit card details or block access to other important data. Locking your data is as simple as setting a PIN code, pattern lock, password or Fingerprint lock.
    • Password
    A password is a strong, secure way to lock your phone. Passwords can be difficult to guess, and it can help ensure that your personal data remains personal. However, typing a password into your mobile phone several times a day can turn out to be cumbersome. Use passwords only when you need the highest level of security.
    • PIN
    A PIN code can turn out to be a simple alternative to a password. It can be shorter, easier to remember and easier to type in several times a day. Using a 4 digit pin is a good solution, as there are 10 thousand different combinations. Just make sure not to choose something obvious like 1234 or 4321.
    • Pattern Lock
    A pattern lock allows you to draw a pattern using a grid of nine dots. You can create a huge combination of patterns, and it is easier to enter multiple times throughout the day. However, patterns are only as secure as the kind of pattern you create. Another con of using a pattern lock is the fact that someone can easily remember your pattern by just looking over their shoulder. Hence, patterns are recommended only if you have nothing to worry about.
    • Fingerprint Sensor
    Not all smartphones have fingerprint sensors. However, all new models of smartphones being shipped nowadays have fingerprint sensors embedded in them. A fingerprint sensor is by far the most secure and fast means of unlocking your phone. The only problem is that not all smartphone have a proper placing of the fingerprint sensor. Fingerprint sensors are hence the most recommended means of locking your smartphone. Use a PIN code or password only as a backup.
  2. Add protection
    Use the security features that come in your Android/ iPhone devices. Apple device users can turn on the “Find My iPhone” feature in iCloud, which might come handy in locating a missing device and erasing important data using an activation lock feature.
  3. Set strong passwords
    Be it your social media account, or your banking login account, setting a strong password everywhere is mandatory. Your password should be a unique combination of letters, numbers and special characters and should be difficult to guess. Do not use the same password everywhere, and use a password manager to keep track of all your passwords. Setting strong passwords is another method to ensure smartphone security and prevent someone from tampering with your personal information.
  4. Use apps from the Google Play Store or the Apple Store
    Apple Store and the Google Play Store continuously remove fraudulent apps from the marketplace. Rarely, Google and Apple do fail at protecting the influx of fake apps that seep into the Google Store and Apple Store unknowingly. However, it can be said that the Google Play Store and Apple Store are safer than ever now and downloading apps from these stores are comparatively more secure than downloading bogus apps from unreliable third-party applications.
  5. Use device encryption
    Encrypt your Android smartphone/ iPhone to encrypt the data in your phone. Encryption differs greatly from a simple PIN or passcode. Even if a hacker gets in through the lock screen, your personal information is rendered useless/unreadable unless they have the encryption key. The downside to encrypting your mobile data is that it takes you longer to log in to your device. However, using device encryption takes security one step further and is usable when you have extremely vital data in your smartphone.
    If you are an IOS user, setting device encryption is as simple as setting up a passcode to lock your device. The option can be found under Settings > Passcode.
    If you are an Android user, note that the lock screen and device encryption are separate entities but related. You cannot encrypt your data without turning on the lock screen. To enable device encryption, plugin in your device, set a strong password and navigate to Settings > Security > Encrypt Device. Follow the on-screen instructions and complete the process. Once you encrypt your phone, you cannot turn it off without factory resetting your phone.
  6. Use a Virtual Private Network
    Use a mobile Virtual Private Network to ensure that the free Wi-Fi you use when you have that sip of coffee on the way to work does not come back to bite you. However, make sure that you do not use a free VPN service as they usually don’t work.
  7. Use an anti-virus software
    Use a suitable, paid, anti-virus software to prevent malware from attacking your smartphone data. Some smartphone security anti-virus software also offers the feature of phone tracking, which might not work as expected, but are good-to-have additions.
  8. Delete unused applications
    Constant security updates of apps make the apps secure. However, not all apps regularly release patches, hence stagnant and unused apps might turn out to be an open door for a possible attack. Delete unused apps to reduce the chances of an attacker entering your phone to obtain vital information.
  9. Turn off unused connections
    Turning off Bluetooth and Wi-Fi when not in use does not only save your battery life but can also prevent your smartphone from possible attacks. Open network connections can be used to attack you hence it is advisable to turn off all connections when not in use.

Mobile Threats and Scams

Mobile threats and scams have become a rampant problem as smartphones are in the hands of every average person in this era. There are some common types of fraud committed through mobile devices that one should be aware of:

  1. Phishing
    This is one of the easiest ways for scammers to steal personal data. You get a message, asking to enter your login information. This information is then used to make purchases through the app to which you revealed the information. The same login information can also be used to gain access to other apps that you use since a normal user has the same login credential across several applications.
  2. Vishing
    Vishing is much like phishing and is its telephone equivalent. It involves the act of calling unsuspecting users by appearing to be a legitimate business. Scammers then extract vital information by making the victim think that they will profit. For example, a scammer might call you by pretending to be your bank and asking you for your PIN, or call you as an IRS agent asking for your tax details.
  3. Fraudulent websites
    A smartphone has a smaller screen than that of a desktop computer. Hence, it is difficult to differentiate a fraudulent website from a real one in a smartphone than on a computer. The difference in the logo, quality, and display of the website is un-noticeable in a smaller screen. The use of phony websites and information tampering using fraudulent websites are thus more common on a smartphone.
  4. Subscription fraud
    Fraudulent users gain access to a person’s information and use it to sign up for an expensive subscription. This kind of fraud falls among the most common mobile fraud.
  5. Stolen devices
    If your smartphone gets stolen, fraudulent users can use the device to make purchases through apps.
  6. SMS Fraud
    This kind of fraud usually involves sending SMS on behalf of a user, without his/her knowledge. The SMS is sent to make a purchase, which the user is unaware of. The payments received by the purchase then benefits the fraudulent user.
  7. Phantom apps
    Fake apps of well-known companies can also prove to be a big scam that lures users to pay fraudsters unknowingly. For example, a phony version of Google Wallet was released in 2014, that tricked users to paying money for cheap cars.
  8. Drive-by downloads
    The malware installed into your phone without your consent is referred to as drive-by downloads. Visiting the wrong website can generally trigger these drive-by downloads to be installed in your mobile device and causing harm later.
  9. Viruses and Trojans
    Viruses and Trojans attack your mobile devices by attaching themselves to legitimate programs and later hijacking your smartphone system. Viruses and Trojans can also send premium, costly, text messages.
  10. Network spoofs
    Network spoofs are fake access points set up by hackers to look like Wi-Fi networks. They are set up in high traffic locations with names like “Free Wi-Fi” or “Coffeehouse Wi-Fi” to lure users into creating accounts to log in. Most people generally use the same login credentials to log in to several places. The same username and password obtained from this account are used to gain access to the duped user’s email and banking details.

How to spot Fake Android Apps?

One of the major mobile scam on trend nowadays are fake Android apps that act as masters of disguise and cause harm to your personal data. Copycat apps are released extensively on a daily basis. It is difficult to keep track of which app is genuine and which is not. It is hence important for every smartphone user to know how to spot fake android apps and ensure their smartphone security.

  1. Research
    Before you download an app, do some background research on the number of downloads and the number of reviews that the app has. In some cases, lesser reviews might be an indication of a developer just starting out. In other cases, it might be a scammer intent on tricking you into downloading their malicious app.
  2. Read reviews
    Short and vague reviews or very less number of reviews are often the sign of malicious apps. Some reviews can also give you an insight into the pain shared by other users who have been duped by the app.
  3. Notice details
    Notice the details like the images and design of the app. If they look unprofessional and shoddy, it is probably a fake Android app put together to dupe unknowing users.
  4. Watch out for clones
    Most malicious and fake apps are the clones of the more popular apps. Examine the name of the developer and read reviews carefully in order to differentiate between the original app and the fake one.
  5. Read the documentation
    Good developers usually push out some minor description of what the app does. Read the documentation carefully to figure out if the app has just been pushed out to lure customers, or if it has actually been created with care.

How Free are Free apps?

Everyone loves free stuff. However, everyone also knows that not many things are actually free. The internet is full of free things to offer. How free are free apps? Have you paused before downloading a free app? Do you ever pause to realize that when you download a free app, you give something in return, i.e., your personal information?

Why is your personal information important?

Information is a commodity. Facebook and Google offer free services but collect, sell and analyze user data on behalf of advertisers. The information we share for free is monetized in a big way. When using an app for free, you are giving away your valuable information in return.

Every time you download a free app, you generally share:

• Your browsing history
• Your SMS app
• Your contact list
• Access to your camera
• Access to manipulate your cookies

This data is analyzed and used to deduce the advertisement content of products that you are most likely to purchase.

How do free apps earn money by using your personal data?

Since it is established that free apps are not actually free and take up your personal information in return, read on to find out the ways how free apps earn money:

  1. Online games
    Applications like WeChat (a messaging app in China) earn money through their online games which require purchases to unlock special features.
  2. Advertisement
    Online advertising is a big business, and it is driven by the personal data that you share to a free app. Most free apps also earn money through advertising the products that you are most likely to purchase.
  3. In-app purchases
    Some applications allow the user the download the application for free, but require money to unlock special features.
  4. Add-on services
    Many free applications like LinkedIn earn by offering add-on services. They obtain revenue from providing a platform for these add-on services.

How to protect yourself from free apps?

A huge percentage of top free Android and iOS apps have found to pose some risk to the users. It is always safe to know ways to protect yourself from free apps and prevent your personal data from being used.

  1. Be careful of what you install
    You might be asked to grant various permissions of an app. However, when you are granting permission to a free app, make sure you review the permissions first. For example, if you download a calculator, it does not make sense for the calculator to access your photos, contacts and other mobile data. Sometimes, just some common sense can save your personal data from being monetized.
  2. Stay updated
    Install your mobile updates as soon as they are available. Updating can be a gruesome process and can hamper your activities, but the updates are usually packaged with security updates that are essential in ensuring safety against unauthorized access of data.
  3. Review your installed applications
    You might have at some point in time, given unnecessary permissions to some free apps that you have downloaded. Review the installed applications and the permissions provided to them from time to time. Changing and reviewing application permissions can prevent the misuse of your personal data.

Other Mobile Threats

There are a number of other less common, but equally threatening mobile threats that one should be aware of:

  1. Spyware
    A jealous co-worker or a nosy spouse might install a hidden, application into your smartphone to keep track of your whereabouts. This kind of application is known as spyware, and needless to state, you would not want to be tracked and have your privacy compromised.
  2. Broken cryptography
    Some apps that you download into your mobile might have crappy code including weak encryption mechanisms that any hacker break. Flaws in an app created in haste is common, and hacking such apps is easier in comparison.
  3. Improper session handling
    Improper session handling can let your personal data float free into the hands of scammers with ease. To ease the access mechanism of mobile devices, many apps use tokens. These tokens allow users to access the application multiple times without forcing them to re-authenticate themselves. For security, apps need to generate new tokens with each access attempt. Not doing so can leave the app exposed and vulnerable to attacks and impersonation.

A normal, tech-savvy person has access to a huge load of information on the types of smartphone threats and the ways to prevent them. However, few people take smartphone security seriously and implement methods to ensure the protection of their personal data. It is always advisable to ensure that your personal data remains truly personal by doing whatever needs to be done to keep scammers at bay.

]]>
How to Secure your Home Wi-Fi Network Yourself https://eraser.heidi.ie/how-to-secure-your-home-wi-fi-network-yourself/ Wed, 18 Oct 2017 10:06:35 +0000 https://eraser.heidi.ie/?p=923

Anyone within range of a home WI-FI network can potentially hack into it. If you are a prime target for someone, then they may have even managed to leave a signal booster somewhere. If you spot someone sitting in a car outside with their head bent down, they may not be sleeping. They may be intruding on your life in ways you do want. Would you like to know how to secure your home WI-FI network … if so read on.

How to Secure your Home Wi-Fi Network in 7 Steps

  1. Routers come with a generic name and password, i.e. one per brand and model. Incredibly, these are in the public domain. Sometimes they do not even have that level of protection. We recommend you change your router password to greater strength. If you forgot it, restore the factory settings, and then change them.
  2. Routers have settings determining the level of encryption. You can log on the internet and change the level and the user password. The process is too technical to explain in a short post. Visit this link to learn more about this.
  3. Now disable your guest networks. The risks have become too high to grant trusted friends and colleagues open, password-free access. Your router is a pathway to your own computer once you log on. Think of the fellow in the car across the street.
  4. Each WI-FI model has a service-set-identifier so users can recognize it. This often identifies the WI-FI brand, making it dead easy to guess the generic logons. Change it to something that identifies with your brand. Change it anyway if someone is abusing the privilege you granted.
  5. Wireless-protected set-up allows devices to handshake with your WI-FI by automatically sharing your network name and password. This may be manually possible by pushing buttons on both devices. If you have a dedicated coffee-shop network you could take a chance, provided you stayed off it yourself
  6. Next, upgrade your router’s operating software. Manufacturers upgrade their ‘firmware’ when they learn of security holes. However, upgrades are seldom automatic. Check your router settings at least every 30 days for updates. If you like, you could ask Tomato to replace it with their bespoke code.
  7. It is always a good idea to give your wi-fi hub physical protection when not at home. Turn it off to reduce hacking time. If this does happen, then at least you are there to take action. Position counts too. Place the router in the middle of the space where your users are. This also reduces signal strength to outside.

This completes our suggestions for how to secure your home WI-FI network itself, without calling in technicians and paying money.

How to Avoid Cross-Infection to Your Device

A chain is only as strong as its weakest link. We know that. But, how often do we actively consider the probability of a WI-FI user having an infected device. Make sure your own equipment has multiple security layers, and the latest anti-virus and anti-spyware software.

Smaller devices, smartphones, laptops, and tablets are especially at risk because we connect to so many networks. Their risk of infection is thus higher, and this could spread to your business PC. If you do not want to spend more money on anti-virus protection, best keep them away from your network.

Simple Precautions to Secure your Home Wi-Fi Network

We are tempted to bog down in technology when increasing wi-fi security, and overlook the obvious. An old, legacy router may be a simple device unable to handle these things. Heimdal Security believes most insecure sites are in the business economy, society, personal, and blogging spheres. Shopping, news and media only come after them. Things are not always what we expect, are they? Ideally, we should only link to trusted sources…

 

HOME SECURITY TIPS AND CONSIDERATIONS: ASSESSING EVERYTHING FROM THE FRONT DOOR TO THE ROUTER

Many people have a natural inclination to protect their valuables, their homes and their household. Because of this, home security is a rather popular topic of discussion for homeowners everywhere. It can be helpful to know how to make a home seem less attractive to burglars and how to take a more active role in protecting your belongings. There’s no shortage of home security advice, products, and services available to homeowners at the push of a button. However, while it is prudent to assess a home’s security from time to time, there’s no reason to live in fear. Making a home more secure is often much easier than many people think.

In this guide, we address these issues as well as the habits that can be developed to make a home more secure. We’ll also take a look at the growing problem of porch pirates and residential cyber crime. And finally, we’ll take a closer look at the various components to consider that may be offered with a home security system. Read on…

]]>
Passphrases versus Passwords & Why the Dilemma https://eraser.heidi.ie/passphrases-versus-passwords-why-the-dilemma/ Mon, 02 Oct 2017 12:13:05 +0000 https://eraser.heidi.ie/?p=916 Passwords are under increasing attack by online guessing software. We can counter this to an extent with random-generated ones. As these are hardly memorable, we resort to writing them down or keeping them on the cloud with KeePass, LastPass, etc. Passphrases may be more memorable, but there are risks attached to them too.

Passphrase Security – There Are No Shortcuts

A passphrase is a series of words cobbled together. Hence we would type “sweet molly malone” as sweetmollymalone. But there is a catch to this. The original is a published phrase. And hence in the database of cracking sites such as crackstation.net. ‘sweetmollymalone” would fall victim to an aggressive attack in a matter of seconds.

We are not linguists. The entropy of written English is outside the scope of this post. Passphrases that are less than 50 characters long are generally weak per this Wikipedia article. We can strengthen them further by using a combination of uppercase and numeric.

The passphrase we use, and its components should ideally not appear in any language database, because this makes it vulnerable to a dictionary attack. Since this is impractical, the workaround is making up our own phrase using uncommon words, and definitely not common joiner words like because, but, and, if, the, and so on.

Using acronyms can help us remember, as they may have when we crammed for exams. For example, “corker” could help us remember:

crackerjackoblidahrepublicankangarooenvelopesrenaissance

But we would still have the problem of typing this correctly, including on a smartphone on a commuter train or a bus.

Comparing Our Passphrase Dilemma with Password Options

Brute force password hacking makes them increasingly unsafe on standalone devices like mobiles and desktops. It helps a little if we copy and paste them because we do not leave a shadow of keystrokes. Of course, we should always use a protected browser before we go near banking / financial sites.

A strong password should be at least twenty, and ideally thirty characters or more. It should not cobble together dictionary words, famous names, and famous places. There should be a mix of upper, and lower cases, and characters. Like the ones we download from password-generator sites, this makes them nigh impossible to remember, and that is the rub. We have gone around in a circle and returned to copying and pasting from a secured environment.

Did a Password Management Service Just Ping?

It definitely did, although that is not necessarily a warranty, a password service is utterly reliable. Sites like KeePass and LastPass can afford a higher degree of encryption than we will ever dream of on our own devices. But, as we have mentioned so many times before on other posts, they are only as good as the people that program and support them.

  • Lastpass keeps encrypted user names and passwords in client accounts. It has various levels of permissions. At the lowest, it automatically inserts these on log-in pages associated with them. There have been a number of security lapses.
  • KeePass stores user names, passwords, and other data in encrypted files. It types the information into dialogues, web forms etc. when the user presses a hot key. By its own admission, Keepass is open to attacks too.

Neither of the sites we chose for illustration is totally bulletproof. The risk from hacking is higher if we use the same passphrases (or passwords) for multiple pages. They are, however, arguably more secure than standalone operating systems. We close with a reminder of the criteria for stronger passphrases.

  • Not a famous quotation from scripture, famous literature etc
  • Easy enough to remember and type in character-perfectly
  • Sufficiently long to be hard to guess, even randomly
  • Nothing even a close friend might be able to intuitively guess
  • Not famous movie names, sports teams and cultural references

We very much doubt that is the last word on passwords and passphrases. We will post advisories here if there are sudden changes.

]]>
Do Solid State Drives SSD’s Really Destroy Data https://eraser.heidi.ie/do-solid-state-drives-ssds-really-destroy-data/ Wed, 13 Sep 2017 17:35:13 +0000 https://eraser.heidi.ie/?p=909 External hard disc drives (HHD’s) and solid state drives (SSD’s) are both useful places to store large amounts of data, or to back up files. They are compatible with computing devices, and being portable we can ‘carry our business in a briefcase’ everywhere we go. They may also fall into malicious hands if we are not careful. The similarity ends there because the hardware inside them is different.External hard disc drives (HHD’s) and solid state drives (SSD’s) are both useful places to store large amounts of data, or to back up files. They are compatible with computing devices, and being portable we can ‘carry our business in a briefcase’ everywhere we go. They may also fall into malicious hands if we are not careful. The similarity ends there because the hardware inside them is different.

How the Hardware inside SSD’s Differs

HHD’s have a spinning disc inside them, and an actuator read-write arm to transfer the data. SSD’s, on the other hand, are disc drives with arrays of semiconductor memory using integrated circuits. To understand how this memory functions, we have to understand computer architecture, and more specifically computer memory.

A Very Brief Overview of Computer Memory

We acknowledge contributions from MUD before we continue. We find them a great place to look when we need to clear the muddy waters of technology beyond our normal lens. Computer architecture contains three levels:

1. The uppermost cache, where the machine does its active work like calculations and procedures. Engineers keep the electrical pathways short so access to data is virtually immediate.

2. The middle memory ground we call random access memory, or RAM for short. Computers use this to store active processes and programs so they can get to these fast. Access is a nano second slower.

3. The actual hard disc: This functions as a ‘permanent’ library of programs, documents, audio files and so on. When we decide to access these, it takes a little longer to transfer them from disc to memory.

SSD technology does these downloads faster than hard drives by as much as a factor of ten. Again, we have to delve into technology to understand how this happens.

How Solid State Drives Process Data and Delete It

An SSD’s flash memory does not clear when it shuts down, unlike a HHD. Instead, it stores the information permanently in a grid of high-speed electric cells. These cells are arranged in sections called pages. These pages are in turn bunched in blocks.

Solid state drives can only write data to empty pages in a block. This contrasts sharply with hard disk drives that can write data to any available location. Thus, if we want to write a new version of a document to an SSD, it creates an entirely new version on another page. This begs the question, what happens if we want to get rid of the old file.

What Deleting Files on a Solid Data Drive Achieves

Again, we have to thank the engineers at MUD for simplifying things for us. When we delete a file on a hard drive disc, the master file index simply tags it as belonging in the recycle bin, not the folder. The actual data remains intact until we overwrite that spot on the drive. Since the storage space is random, this can take a while.

The waters are muddier when it comes to deleting files on SSD’s. They are forever rearranging files to optimize storage. The information may eventually be overwritten, but again it may not. Read how a bunch of engineers from University of California only achieved 25% to 96% success when they tried to delete records. Hence a shadow of the information always remained on the SSD.

The Only Way to Delete Data from SSD’s with Certainty 

You already know the answer. The only definite, absolute, and fool proof way to destroy data on an SSD (or an HDD) is to reformat the device. You could even go one stage further, and squash it with a steamroller, as writer Terry Pratchett’s pal did to his unfinished manuscripts in accordance with his last will and testament. We are happy the vintage steam-driven beast made in 1923 survived intact. The data apparently did not.

]]>
Can we trust where Smartphone Manufacturers source their Components? https://eraser.heidi.ie/can-we-trust-where-smartphone-manufacturers-source-their-components/ Tue, 05 Sep 2017 09:12:41 +0000 https://eraser.heidi.ie/?p=906 The Woot 17 Conference had some interesting topics on its agenda from 16 to 18 August 2017. It released its workshop papers on a free, open source basis because it wants a wider public to benefit from research. Today, we focus on a report titled ‘Shattered Trust: When Replacement Smartphone Components Attack’ by researchers from Ben Gurion University.

They question whether we are right to trust non-franchise repairers with our phones just because they may be cheaper. They are concerned that smartphone manufacturers buy in some components from third parties. These could include near field communication readers, wireless controlling chargers and orientation sensors. Hence, they are not in control of cowboy phone repairers that source them directly from component manufacturers.

How a Cowboy Phone Repairer Could Hack Your Phone
We wish we were there ourselves and could report directly. Hence, we are grateful for input from Ars Technica we acknowledge freely. The researchers simulated two standalone attacks using malicious touchscreen hardware, with secret chips that compromised a stock Android phone.

Their two ‘victims’ were a Huawei Nexus 6P, and a LG G Pad 7.0. In both instances, they replaced the screens with ones they had tampered with. Then they were able to log keyboard patterns and inputs covertly, upload malware apps, and even take pictures and email them back to them. This suggests a targeted phone user’s privacy could literally go out the window.

Worse still, the malicious parts ‘booby trapping the screens cost less than $10 and bypassed the phones’ on-board security features. Moreover, the devices – which were potentially open to mass-manufacture – were ‘indistinguishable from legitimate ones, a trait that could leave many service technicians unaware of the maliciousness.’ Only a skilled technician might be able to detect them if they took the device apart.

The Research Serves to Highlight a Security Disparity
The researchers confirm the original phone manufacturers ‘closely guard’ the iOS and Android operating systems, and that they remain within a ‘trust boundary’ until they leave the works in a sealed box. It is also safe to assume the hardware is similarly reliable, provided the manufacturers maintain their quality systems intact.

The disparity takes over as soon as a third party services their product outside the trust boundary, because this not under their sphere of control. The researchers conclude, “The threat of a malicious peripheral existing inside consumer electronics should not be taken lightly. As this paper shows, attacks by malicious peripherals are feasible, scalable, and invisible to most detection techniques.

“A well-motivated adversary may be fully capable of mounting such attacks in a large scale or against specific targets. System designers should consider replacement components to be outside the phone’s trust boundary, and design their defences accordingly.

The ‘Chip-in-the-Middle’ Basis Behind The Successful Attacks
The Ben Gurion University researchers embedded a chip in a normal, standard touchscreen. This affected the communication bus responsible for transferring data from the device hardware to the software drivers in the operating system. The malicious integrated circuit placed between the two dimensions was able to modify, monitor, or interfere with their communications.

This chip-in-the-middle contained code able to covertly complete actions not initiated by the phone user. It could, for example unlock patterns and keyboard inputs, take photos and relay them, substitute phishing urls, and remotely install apps without the phone owner knowing this happened.

A hot air blower was all the researchers needed to separate the touchscreen controllers so they could connect the chips. They suggest a variety of countermeasures they think phone manufacturers should take. They also think the industry needs a certification program for aftermarket parts. We had no idea how wide open we were until we uncovered the research.

]]>
Is your Car Hacking Into Your Phone? https://eraser.heidi.ie/is-your-car-hacking-into-your-phone/ Tue, 29 Aug 2017 08:37:23 +0000 https://eraser.heidi.ie/?p=900 Smartphone Privacy & Security: Is Your Car Hacking Into Your Phone
Something slipped quietly into news feeds in the midst of the hype about China’s smartphones being porous, and India demanding data security assurances from her Asian neighbour. This quiet clip appeared in an article on an Orlando news site titled ‘Car tech privacy: Your car’s infotainment system might be grabbing data from your phone’. We decided this needed a closer look.

Cars Increasingly Have Minds of Their Own Computers
The snowballing number of computers in cars is another surprise encircling us in the Internet of Things. There are dozens of them adjusting the fuel and air that enters engines, triggering airbags, tensioning seatbelts, preventing brakes locking, and even allowing us to open the door, sit behind the wheel, and operate a computer-controlled key.

If Google has its way, our cars could soon be driving hands free. Someday we may even send the car solo to collect our internet shopping – what a pleasure that would be!

And Their Car Stereos Do More than Simply Play Music
In 2013, the United States Cyber Security Division wanted to know more about what was happening in cars. This makes sense given the worrisome attacks by car drivers nowadays in mainland Europe. Early experiments focused on planting physical surveillance devices with cellular communication capability.
Then they went one stage further, potentially affecting the privacy of the very citizens they were hoping to protect, by hacking into a car’s digital memory.

The U.S. Cyber Security Division’s project piggybacked onto a motor accident reconstruction system able to interrogate a car’s infotainment and telematics. This enabled them to geo-locate a vehicle at a particular split-second in past time, and calculate its speed and trajectory on impact. The company concerned was Berla, based in Maryland.

It does not take a leap of science to realise this information could travel live over a cellular connection. In 2016, Berla released this video detailing the seventy different computing devices it knew of in the average car.
Berla believes the most sophisticated cars may have up to one hundred different computers managing their advanced systems. Most vehicles have up to five networks joining these up. Together, this represents enough data to fill a one-terabyte drive in forty hours. More than a few of these devices report metrics to manufacturers over cellular space.

They Have Stereos Able to Hack Our Smartphones
Hands-free mobile while driving links our smartphone into this network of car computing devices. Entertainment systems now have Bluetooth and USB connections. Soon wireless near field communication will do away with wires as smoothly as Apple Android describes here. NFC can connect with passive devices and power them with an electromagnetic field.

Prepare to be worried about your car entertainment knowing more about what’s on your phone than you know about yourself. This could include call history, contacts, login codes and more travelling via USB or Bluetooth to the infotainment computer.

This Technology Is Not New, It Is Proven to Work
On 15 January 2017 Forbes staff writer Thomas Fox-Brewster posted ‘Car Tapping: How Feds Have Spied on Connected Cars for 15 Years.’ We should take him seriously. Thomas has freelanced for The Guardian, Vice Motherboard, Wired, and BBC.com since 2010, among many others. He was named BT Security Journalist of the year in 2012 and 2013 for a range of exclusive articles.

In 2014, he landed Best News Story for a feature on US government harassment of security professionals. We will draw the threads together with this quote from his article:

“It was little surprise to find General Motors had repeatedly worked with cops to hand over not just location, but also audio where conversations were recorded when the in-car cellular connection was switched on”.
There is no regulatory standard over this we know of, and as far as we are aware no way to turn the snooping off without interfering with the digital that manages our cars and keeps them safe. The message is clear. We are no longer private when we use our smartphones in our cars, in the hope of nobody eavesdropping on what we say.

]]>