Your phone's motion sensors may reveal your PIN, passwords

April 11, 2017

London, Apr 11: Hackers can steal your PINs and passwords just from the motion of your phone when you type in the information, warn experts who have unveiled how easy it is for malicious websites and installed apps to spy on you. Cyber experts at Newcastle University in the UK have shown it is possible to crack four-digit PINs with a 70 per cent accuracy on the first guess - 100 per cent by the fifth guess - using just the data collected via the phone's numerous internal sensors.

phoneDespite the threat, the research shows that people are unaware of the risks and most of us have little idea what the majority of the twenty five different sensors available on current smart phones do. While all the major players in the industry are aware of the problem, no-one has yet been able to find a solution.

"Most smart phones, tablets, and other wearables are now equipped with a multitude of sensors, from the well-known GPS, camera and microphone to instruments such as the gyroscope, proximity, NFC, and rotation sensors and accelerometer," said Maryam Mehrnezhad, research fellow at Newcastle University. "But because mobile apps and websites don't need to ask permission to access most of them, malicious programmes can covertly 'listen in' on your sensor data and use it to discover a wide range of sensitive information about you such as phone call timing, physical activities and even your touch actions, PINs and passwords," said Mehrnezhad.

"More worrying, on some browsers, we found that if you open a page on your phone or tablet which hosts one of these malicious code and then open, for example, your online banking account without closing the previous tab, then they can spy on every personal detail you enter," she said. "And worse still, in some cases, unless you close them down completely, they can even spy on you when your phone is locked," she added.

"Despite the very real risks, when we asked people which sensors they were most concerned about we found a direct correlation between perceived risk and understanding," said Mehrnezhad. "So people were far more concerned about the camera and GPS than they were about the silent sensors," she said.

Sensors are now commonplace in smart devices and are largely responsible for the boom in mobile gaming and health and fitness apps, and soon in all devices in the Internet of Things (IoT), researchers said. The data provided by them combined with the growing computational ability of mobile phones and tablets has transformed the way we use them.

In total, the team identified 25 different sensors which now come as standard on most smart devices and are used to give different information about the device and its user. Only a small number of these - such as the camera and GPS - ask the user's permission to access the device. The research was published in the International Journal of Information Security.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 22,2020

Kochi, May 22: During the nationwide COVID-19 lockdown, Kerala recorded the highest number of cyber attacks followed by Punjab and Tamil Nadu, a study by anti-virus software firm K7 Computing said on Thursday.

In a statement issued in Chennai, the company said its K7 Computing's Cyber Threat Report, a comprehensive analysis of cyber attacks during the lockdown has found that Kerala recorded the highest number of cyber attacks during this period. The report analyses various cyber attacks within India during the pandemic and reveals that threat actors targeted the state with COVID-themed attacks aimed at exploiting user trust.

In Kerala, regions like Kottayam, Kannur, Kollam, and Kochi saw the highest hits with 462, 374, 236, and 147 attacks respectively, while the state as a whole saw around 2,000 attacks during the period - the highest thus far in the country.

This was followed by Punjab with 207 attacks and Tamil Nadu with 184 attacks, the company said.

The sudden surge in the frequency of attacks witnessed from February 2020 to mid-April 2020 indicates that scamsters across the world were exploiting the widespread panic around coronavirus at both the individual and corporate level.

These attacks aimed to compromise computers and mobile devices to gain access to users' confidential data, banking details, and cryptocurrency accounts.

The key threats seen during this period ranged from phishing attacks to rogue apps disguised as COVID-19 information apps that targeted users' sensitive data. Phishing attacks were noticed more in Tier-II and Tier-III cities while the metros fared better. Smaller cities saw over 250 attacks being blocked per 10,000 users.

Users from Ghaziabad and Lucknow seem to have faced almost 6 and 4 times the number of attacks as Bengaluru users.

According to the statement, a majority of the recorded attacks were phishing attacks with sophisticated campaigns that could easily snare even the most educated users. These attacks were aimed at heightening users' fears and creating a sense of urgency to take action.

K7 Labs noticed phishing attacks where scamsters posed as representatives of the United States Department of Treasury, the World Health Organization (WHO), and the Centres for Disease Control and Prevention (CDC), the company said.

Users were encouraged to visit links that would automatically download malware on the host computer such as the Agent Tesla keylogger or Lokibot information-stealing malware, infamous banking Trojans such as Trickbot or Zeus Sphinx, and even disastrous ransomware.

Other attacks included infected COVID-19 Android apps like CoronaSafetyMask that scam users with promises of masks for an upfront payment; the spyware app Project Spy; and seemingly genuine apps that are infected with dangerous malware like banking Trojans such as Ginp, Anubis and Cerberus.

"Covid-19 has created an ideal situation for various threat actors to target individuals and enterprises alike. The panic caused by the stringent lockdown measures and rapid spread of this virus has left many people looking for more information on the situation," J. Kesavardhanan, Founder and CEO of K7 Computing was quoted as saying in the statement.

"Threat actors exploit this fear to their advantage and scam users into downloading malicious software and divulging sensitive information like banking codes. The need to be cyber cautious has never been greater. This is more so in the case of corporates who have adopted a work from home policy hurriedly without adequate cyber hygiene. We have seen an increase in attacks on enterprises and SME employees as well," he added.

Such attacks are expected to continue till normalcy returns. Social engineering attacks targeted at winning users' trust will gain momentum.

Healthcare institutions, well-known government offices, and international organisations will continue to be a prime target throughout the pandemic, the statement said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
January 4,2020

Washington D.C: One of the greatest spectacles of modern art is still thriving in the Australian outback as confirmed by satellite imagery of NASA. The Marree Man is a massive geoglyph depicting an aboriginal hunter, that spans over 2.6 miles in the Southern Australian region.

Discovered by a pilot in 1998, its origin still remains a mystery even to this date.

The Marree Man was given a new lease of life in 2016 when a group of people from the neighboring town of Marree plowed its lines to avert its fading due to erosion.

After NASA shared the image of the art-work that was taken in June, the efforts of the good samaritans turned out to be a total success, reported CNN Travel.

The restoration team believes that the refurbished Marree Man would last longer than its original version.

According to NASA, "They [the team] created wind grooves, designed to trap water and encourage the growth of vegetation. They hope that eventually, the man will turn green."

In a previous article, CNN reported that an entrepreneur by the name of Dick Smith took upon himself to unravel the geoglyph's mystery in 2016. His team combed through all the available evidence but couldn't find anything conclusive.

In 2018 he even offered a 5,000 Australian dollar reward for anyone who knows the identity of its creator.

Nobody turned up with an answer but it was speculated that unknown artist lives in Alice Springs or even might be an American.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
July 19,2020

New Delhi, Jul 19: Indian equities will be driven by a host of factors like corporate earnings, coronavirus cases trend and geo-political developments this week, according to analysts.

Market participants will also keenly watch the progress of monsoon, with experts saying that the farm sector revival will play a key role in lifting the coronavirus-hit economy.

"With no major event, the ongoing earnings season and global cues will continue to dictate the market trend. Besides, the progress of monsoon will also be closely watched," Ajit Mishra, VP - Research, Religare Broking, said.

Globally, the rising coronavirus infections and geo-political tensions have created uncertainty on the economic recovery front.

With India's COVID-19 cases fast approaching the 11 lakh mark, the third-highest behind the US and Brazil, and the death toll nearing 27,000, participants are expected to tread cautiously going forward.

At global level, confirmed COVID-19 cases have crossed 1.4 crore and deaths totalled about 6 lakh.

Markets globally will closely follow developments on the trade and political level between the US and China, according to analysts.

"We would continue witnessing stock-specific action as the earnings season unfold. Though the near-term momentum looks positive, we would advise traders to be cautious, given flaring US-China trade relations, persistent rise in virus cases and implementation of fresh lockdowns in parts of the country," said Siddhartha Khemka, Head - Retail Research, Motilal Oswal Financial Services Ltd.

HDFC Bank will remain in focus on Monday after having announced its June quarter earnings on Saturday.

The lender reported 19.6 per cent rise in its standalone net profit at Rs 6,658.62 crore for April-June 2020; while its income rose to Rs 34,453.28 crore during the quarter.

Other major companies to announce their quarterly results this week are Axis Bank, Bajaj Finance, Hindustan Unilever Limited, Bajaj Auto and ITC.

"Going ahead market participants will closely track the development related to covid vaccine, the rising infection of coronavirus, development on economic activities, corporate earnings and US-China relationship," said Sumeet Bagadia, Executive Director, Choice Broking.

On weekly basis, the Sensex gathered 425.81 points or 1.16 per cent, and the Nifty gained 133.65 points or 1.24 per cent.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.