Your phone's motion sensors may reveal your PIN, passwords

April 11, 2017

London, Apr 11: Hackers can steal your PINs and passwords just from the motion of your phone when you type in the information, warn experts who have unveiled how easy it is for malicious websites and installed apps to spy on you. Cyber experts at Newcastle University in the UK have shown it is possible to crack four-digit PINs with a 70 per cent accuracy on the first guess - 100 per cent by the fifth guess - using just the data collected via the phone's numerous internal sensors.

phoneDespite the threat, the research shows that people are unaware of the risks and most of us have little idea what the majority of the twenty five different sensors available on current smart phones do. While all the major players in the industry are aware of the problem, no-one has yet been able to find a solution.

"Most smart phones, tablets, and other wearables are now equipped with a multitude of sensors, from the well-known GPS, camera and microphone to instruments such as the gyroscope, proximity, NFC, and rotation sensors and accelerometer," said Maryam Mehrnezhad, research fellow at Newcastle University. "But because mobile apps and websites don't need to ask permission to access most of them, malicious programmes can covertly 'listen in' on your sensor data and use it to discover a wide range of sensitive information about you such as phone call timing, physical activities and even your touch actions, PINs and passwords," said Mehrnezhad.

"More worrying, on some browsers, we found that if you open a page on your phone or tablet which hosts one of these malicious code and then open, for example, your online banking account without closing the previous tab, then they can spy on every personal detail you enter," she said. "And worse still, in some cases, unless you close them down completely, they can even spy on you when your phone is locked," she added.

"Despite the very real risks, when we asked people which sensors they were most concerned about we found a direct correlation between perceived risk and understanding," said Mehrnezhad. "So people were far more concerned about the camera and GPS than they were about the silent sensors," she said.

Sensors are now commonplace in smart devices and are largely responsible for the boom in mobile gaming and health and fitness apps, and soon in all devices in the Internet of Things (IoT), researchers said. The data provided by them combined with the growing computational ability of mobile phones and tablets has transformed the way we use them.

In total, the team identified 25 different sensors which now come as standard on most smart devices and are used to give different information about the device and its user. Only a small number of these - such as the camera and GPS - ask the user's permission to access the device. The research was published in the International Journal of Information Security.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 12,2020

New Delhi, Jun 12: The Supreme Court on Friday asked Solicitor General Tushar Mehta to convene a meeting of the Finance Ministry and RBI officials over the weekend to decide whether interest incurred on EMIs during the moratorium period can be charged by banks.

A bench comprising Justices Ashok Bhushan, Sanjay Kishan Kaul and M.R. Shah queried Mehta as the court was concerned since the Centre has deferred loan for three months.

"Then how can interest of these 3 months be added?" the apex bench asked. Mehta replied: "I need to sit down with the RBI officials and have a meeting."

SBI's counsel, senior advocate Mukul Rohatgi, intervened during the proceedings and said "all banks are of the view that interest cannot be waived for a six month EMI moratorium period".

"We need to discuss it with the RBI," insisted Rohatgi.

Justice Bhushan then asked Mehta to convene a meeting of the RBI and Finance Ministry officials over the weekend, and listed the matter for further hearing on June 17.

The top court, during the hearing, indicated that it was not considering a complete waiver of interest but was only concerned that postponement of interest shouldn't accrue further interest on it.

After the RBI said the waiver of interest charges on EMIs during moratorium will lead to loss of 1 per cent of the nation's GDP, the top court had earlier asked the Finance Ministry to reply, whether the interest could be waived or it would continue during the moratorium period.

The top court said these are not normal times, and it is a serious issue, as on one hand moratorium is granted and then, the interest is charged on loans during this period.

"There are two issues in this (matter). No interest during the moratorium period and no interest on interest," said Justice Bhushan. The observation from the bench came on a petition by Gajendra Sharma, in which he sought a direction to declare portion of the RBI's March 27 notification as ultra vires to the extent it charged interest on the loan amount during the moratorium period.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 19,2020

Cybersecurity researchers on Monday warned of a Trojan malware campaign which is targeting India's co-operative banks using COVID-19 as a bait.

Seqrite, the enterprise arm of IT security firm Quick Heal Technologies, detected the new wave of Adwind Java Remote Access Trojan (RAT) campaign.

Researchers at Seqrite warned that if attackers are successful, they can take over the victim's device to steal sensitive data like SWIFT logins and customer details and move laterally to launch large scale cyberattacks and financial frauds.

According to the researchers, the Java RAT campaign starts with a spear-phishing email which claims to have originated from either the Reserve Bank of India or a nationalised bank.

The content of the email refers to COVID-19 guidelines or a financial transaction, with detailed information in an attachment, which is a zip file containing a JAR based malware.

Upon further investigation, researchers at Seqrite found that the JAR based malware is a Remote Access Trojan that can run on any machine which has Java runtime enabled and hence it can impact a variety of endpoints, irrespective of their base operating system.

Once the RAT is installed, the attacker can take over the victim's device, send commands from a remote machine, and spread laterally in the network.

In addition, this malware can also log keystrokes, capture screenshots, download additional payloads, and extract sensitive user information, Seqrite said, adding that such attack campaigns can effectively jeopardise the privacy and security of sensitive data at the co-operative banks and result in large scale attacks and financial frauds.

To prevent such attacks, users need to exercise ample caution and avoid opening attachments and clicking on web links in unsolicited emails.

Banks should also keep their operating systems updated and have a full-fledged security solution installed on all the devices, Seqrite advised.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 18,2020

New Delhi, Jun 18: Vodafone Idea on Thursday told the Supreme Court that it has incurred Rs 1 lakh crore losses as it insisted it is not in a position to furnish bank guarantees.

A bench comprising Justices Arun Mishra, S. Abdul Nazeer, and M.R. Shah, taking up the adjusted gross revenue (AGR) matter through video conferencing, directed the telecom companies to submit their financial documents and books for the last 10 years.

Asking Vodafone if it was a foreign company, the bench said that how can the company say it would not furnish any bank guarantee.

"What if you fly away overnight in future without paying anything?" it asked.

Senior advocate Mukul Rohatgi, representing Vodafone Idea, denied his client is a completely foreign firm and cited before the bench its tie-ups and investments.

Vodafone owes over Rs 58,000 crore as AGR dues and so far, has paid close to Rs 7,000 crore.

Rohatgi contended before the court that the telecom company is in a tough situation, and cannot furnish any fresh bank guarantee, as profits have eluded the company in past many quarters. He submitted before the bench that Rs 15,000 crore bank guarantees are lying with the government, and his client's losses are over Rs 1 lakh crore.

"I cannot offer any more surety," he informed the bench.

Justice Mishra noted that this is public money and these dues should be recovered. "Do not tell us that you will pay if you were to make profits... the money must come," he noted.

Justice Shah observed that the telecom industry is the only industry which earned during the Covid-19 pandemic. "After all, this money will be used for public welfare", he said.

Rohatgi argued that his client would have to fold up if orders were issued to clear dues tomorrow. "11,000 employees will have to go without notice, as we cannot pay them," he added.

Senior advocate Abhishek Manu Singhvi, appearing for Bharti Airtel, contended before the court that out of Rs 21,000 crore AGR dues, the company has already deposited a sum of Rs 18,000 crore.

He argued that his client has given a bank guarantee, in excess of demand, to DoT, and supported the proposal for phased repayment of remaining AGR dues. He insisted that the company needs to sit down with the government and calculate the dues. Airtel owes Rs 25,976 crore after paying Rs 18,000 crore, as per the government.

Senior advocate Arvind Datar, representing Tata Telecom, informed the bench that his client has paid Rs 6,504 crore in AGR dues so far, and furnishing a bank guarantee may adversely impact investments in the sector.

The total AGR dues are close to Rs 1.5 lakh crore.

The top court will now take up the matter in the third week of July.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.