Signal Adds Cryptocurrency Support

According to Wired, Signal is adding support for the cryptocurrency MobileCoin, “a form of digital cash designed to work efficiently on mobile devices while protecting users’ privacy and even their anonymity.”

Moxie Marlinspike, the creator of Signal and CEO of the nonprofit that runs it, describes the new payments feature as an attempt to extend Signal’s privacy protections to payments with the same seamless experience that Signal has offered for encrypted conversations. “There’s a palpable difference in the feeling of what it’s like to communicate over Signal, knowing you’re not being watched or listened to, versus other communication platforms,” Marlinspike told WIRED in an interview. “I would like to get to a world where not only can you feel that when you talk to your therapist over Signal, but also when you pay your therapist for the session over Signal.”

I think this is an incredibly bad idea. It’s not just the bloating of what was a clean secure communications app. It’s not just that blockchain is just plain stupid. It’s not even that Signal is choosing to tie itself to a specific blockchain currency. It’s that adding a cryptocurrency to an end-to-end encrypted app muddies the morality of the product, and invites all sorts of government investigative and regulatory meddling: by the IRS, the SEC, FinCEN, and probably the FBI.

And I see no good reason to do this. Secure communications and secure transactions can be separate apps, even separate apps from the same organization. End-to-end encryption is already at risk. Signal is the best app we have out there. Combining it with a cryptocurrency means that the whole system dies if any part dies.

EDITED TO ADD: Commentary from Stephen Deihl:

I think I speak for many technologists when I say that any bolted-on cryptocurrency monetization scheme smells like a giant pile of rubbish and feels enormously user-exploitative. We’ve seen this before, after all Telegram tried the same thing in an ICO that imploded when SEC shut them down, and Facebook famously tried and failed to monetize WhatsApp through their decentralized-but-not-really digital money market fund project.

[…]

Signal is a still a great piece of software. Just do one thing and do it well, be the trusted de facto platform for private messaging that empowers dissidents, journalists and grandma all to communicate freely with the same guarantees of privacy. Don’t become a dodgy money transmitter business. This is not the way.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Florida School District Held to Impossibly High Ransom

Florida School District Held to Impossibly High Ransom

Cyber-criminals behind a cyber-attack on a Florida school district are demanding a ransom payment of $40m in cryptocurrency. 

The computer system of Broward County Public Schools was compromised at the beginning of March by data-locking ransomware in a Conti gang operation. The attack caused a system shutdown but left classes undisturbed. 

Broward is the sixth-largest school district in the United States with 271,000 students and an annual budget of around $4bn. 

The district, which is based in Fort Lauderdale, negotiated with the ransomware gang for two weeks. Conti initially said it would accept $15m in Bitcoin if the district paid up within 24 hours.

But the ransomware gang reportedly ended communications with its victim after rejecting the district’s offer to pay $500k. 

Screenshots of the negotiations posted to the gang’s dark website appear to show Conti telling a district official that the $40m ransom “is a possible amount for you.”

The Broward negotiator replied: “This is a PUBLIC school district. You cannot possibly think we have anything close to this!”

Conti claimed to have stolen personal information belonging to the district and threatened to make the data public. But Broward County Public Schools said in a statement Thursday: “We have no evidence that any individuals’ personal information has been accessed or removed from our network or compromised in any way.”

Cybersecurity experts are currently working with the district to investigate the incident and remediate affected systems. 

“Efforts to restore all systems are underway and progressing well. We have no intention of paying a ransom,” said a spokesperson for the district.   

Broward County joins a growing list of public school districts victimized by ransomware. In 2020, the districts of Fairfax County, Virginia; Hartford, Connecticut; Baltimore County, Maryland; and Fort Worth, Texas, were all targeted. 

Commenting on the Broward attack, SecPod’s CEO Chandra Basavanna told Infosecurity Magazine: “While there have been numerous attacks targeting education institutions over the last couple of weeks, this specific attack is unique in that its ransom demand was one of the highest ever. 

“Given that every major attack sets a precedent for others to emulate, we’ll likely see other threat actors one-up each other beyond what is currently making headlines.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Parrot Launches Bug Bounty Program

Parrot Launches Bug Bounty Program

European drone manufacturer Parrot has partnered with crowdsourced security platform YesWeHack to launch a Bug Bounty program.

By setting up the two-phase program, Parrot hopes that potential vulnerabilities in its drones, mobile applications, and web services will be identified by YesWeHack’s community of more than 22,000 cybersecurity researchers.

“After the integration of cybersecurity from the initial design phase of Parrot drones, the Bug Bounty launched with YesWeHack completes the audits and brings an additional step of control,” said Victor Vuillard, chief security officer and CTO cybersecurity of the Parrot Group. 

“In the event of a flaw, YesWeHack’s community of cybersecurity researchers will detect it and allow Parrot to correct it, before real attackers can misuse it.” 

The program will begin with a private phase, in which exclusive access to Parrot products being developed for sale will be given only to selected security researchers. Once this phase is complete, and the commercialization process has been completed, the products will enter a public bug bounty program.

“We are delighted to support Parrot in its commitment to the drone and user’s data security,” said YesWeHack CEO Guillaume Vassault-Houlière. “The richness and diversity of the YesWeHack community offers the spectrum of skills required to cover the full range of perimeters, whether hardware or applications.”

Vassault-Houlière added that the new program will add to the cybersecurity assessment of Parrot conducted recently by professional offensive security services company Bishop Fox. 

He said: “The public Bug Bounty phase, which will take place in a second phase, will allow Parrot’s products to be confronted with the expertise of several thousand researchers, thus reinforcing its transparency in cybersecurity.”

Parrot launched the world’s first consumer drone in 2010. Its contemporary models are made with built-in encryption and privacy features that copy with the EU’s General Data Protection Regulation (GDPR).

The ANAFI USA drone that Parrot manufactures in America earned the company a place on the USA’s Blue sUAS list of five government-approved drone manufacturers.  

“Parrot’s mission is to meet the immense security needs of the professional market,” said Vuillard.

“The use of drones continues to grow exponentially in the professional sector, and our cutting-edge features ensure the protection of sensitive data at all times.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Australia Considers Social Media ID Requirement

Australia Considers Social Media ID Requirement

Australia is mulling the introduction of a compulsory points-based ID verification system for users of social media and online dating sites. 

Under the new proposal, individuals would be required to prove who they are by submitting 100 points of ID before they are allowed to use a service. Permissible forms of identification could include a driver’s license, Medicare card, birth certificate, or passport.

The solution was devised on the premise that removing users’ anonymity would decrease instances of online abuse, trolling, and cyberbullying. 

Currently, Australians are not required to provide ID to use most online platforms; however, some ask users to verify their identity by supplying a phone number and/or an email address.

The ID rule was one of 88 recommendations made in a recent federal parliamentary committee report proposing a range of strategies to decrease family, domestic, and sexual violence.

“In order to open or maintain an existing social media account, customers should be required by law to identify themselves to a platform using 100 points of identification, in the same way as a person must provide identification for a mobile phone account, or to buy a mobile SIM card,” states the report. 

“Social media platforms must provide those identifying details when requested by the eSafety Commissioner, law enforcement or as directed by a court.”

A “substantial increase” in criminal penalties and fines for technology-facilitated abuse was also called for in the report, as a way to deter netizens from “errant behavior.’’ 

Swinburne University senior lecturer in digital media Dr. Belinda Barnet was skeptical about the effectiveness and wisdom of placing large quantities of sensitive personal data in the care of social media companies and online dating websites.

“It’s a long bow to draw that if we give our passport to Facebook then suddenly people will not be abusive. There’s no research to support that assumption,” Barnet told the Sydney Morning Herald.

She added: “We’d be giving over these identity documents to proprietary platforms that do not have our best interests at heart.”

A spokesperson for Facebook said the company was currently reviewing the suggestions included in the report and would “continue to work with the government as they consider the recommendations.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Attacks Grew by 485% in 2020

Ransomware Attacks Grew by 485% in 2020

Ransomware attacks increased by an astonishing 485% in 2020 compared to 2019, according to Bitdefender’s 2020 Consumer Threat Landscape Report, which highlighted the ways cyber-criminals targeted the COVID-19 pandemic.

Interestingly, nearly two-thirds (64%) of the ransomware attacks took place in the first two quarters of 2020.

The report, which analyzed data from Bitdefender’s Global Protective Network (GPN), revealed that proprietary operating systems used in IoT devices made up 96% of all detected vulnerabilities, while a 335% surge in Smart TV vulnerabilities occurred compared to 2019.

The researchers also looked at how malicious actors utilized social engineering techniques last year. Android was especially heavily targeted to spread malware and malicious apps in this way, experiencing a 32% growth in reported threats during the second half of 2020. Many of these involved impersonating popular video conferencing software and medical apps, especially during the early stages of the COVID-19 pandemic. For example, April and May accounted for 14% and 12% of the total number of Android reports last year.

A huge rise in potentially unwanted application reports was also detected by the researchers, up by 320% year-on-year. While these will not always necessarily be malicious, they can impact user experiences by slowing down systems, displaying unexpected ads or even installing additional software.

In addition, a 189% year-on-year increase in vulnerabilities in network-attached storage (NAS) devices was observed.

Bogdan Botezatu, director of threat research and reporting at Bitdefender, commented: “Our 2020 findings depict consumers under constant assault from cyber-criminals looking to capitalize on fear and societal uncertainty accompanying the global pandemic. Cyber-criminals will stop at nothing to use outlier events and human empathy to line their pockets. As the pandemic continues we are constantly seeing attacks evolve through malware delivery mechanisms, inventive social engineering and new exploits.” 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

AddSecure Acquires Telia Finland’s Alerta Business

AddSecure Acquires Telia Finland’s Alerta Business

Critical data and communications security firm AddSecure has completed the acquisition of Telia Finland’s Alerta business, allowing it to bolster its platform and provide the basis for further growth.

AddSecure announced its intention to acquire the business back in September 2020, and the agreement has now been approved by the Finnish government.

Telia Finland is a major telecommunications provider, and its Alerta business offers products designed to enable secure alarm transmission and remote management of multiple systems targeted at the public sector and private companies.

The deal means that AddSecure will now be able to include Alerta’s solutions as part of its offerings to customers. All Alerta’s 19 employees will also transfer to AddSecure under the arrangement.

Commenting on the acquisition, Magnus Lengdell, president smart alarms, AddSecure, said: “We expect Alerta to be a meaningful contributor to AddSecure’s growth in 2021 and beyond, as we build on our position as the leading provider of alarm transmission, secure communications and smart solutions in Finland.

“As an established provider of secure communications and solutions, we look forward to providing Alerta’s customers with the same level of service and integrity that they have enjoyed from Telia.”

AddSecure also stressed that existing Alerta customers will not experience any interruption in their alarm monitoring service, and the transition will not affect the operation of the alarm systems.

The security of telecom networks has become a major issue over the past year, particularly in light of the rollout of 5G. In the UK, a new bill is currently being prepared that will impose strict new security rules on telecommunication companies. This will include obliging public telecoms providers to report security compromises and share information with UK telecoms regulator Ofcom.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk