Apple Abandoned Plans for Encrypted iCloud Backup after FBI Complained

This is new from Reuters:

More than two years ago, Apple told the FBI that it planned to offer users end-to-end encryption when storing their phone data on iCloud, according to one current and three former FBI officials and one current and one former Apple employee.

Under that plan, primarily designed to thwart hackers, Apple would no longer have a key to unlock the encrypted data, meaning it would not be able to turn material over to authorities in a readable form even under court order.

In private talks with Apple soon after, representatives of the FBI’s cyber crime agents and its operational technology division objected to the plan, arguing it would deny them the most effective means for gaining evidence against iPhone-using suspects, the government sources said.

When Apple spoke privately to the FBI about its work on phone security the following year, the end-to-end encryption plan had been dropped, according to the six sources. Reuters could not determine why exactly Apple dropped the plan.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Journalist Denounced for Alleged Involvement with Brazilian Criminal Organization

US Journalist Denounced for Alleged Involvement with Brazilian Criminal Organization

Brazilian prosecutors have denounced American journalist Glenn Greenwald for his alleged involvement with a cybercrime organization that hacked cell phones to commit bank fraud.

Greenwald is best known for a series of reports published from June 2013 by The Guardian newspaper that detailed the global surveillance programs of the United Kingdom and the United States. The reports were based on classified documents disclosed by Edward Snowden and whistle-blowing events involving WikiLeaks.

In a criminal complaint filed by federal prosecutors in Brazil on Tuesday, Greenwald is accused of being involved with a criminal organization that hacked mobile devices and committed bank fraud and money laundering. 

According to the complaint, the organization is behind a number of hacks perpetrated last year in which cell phones belonging to public officials and prosecutors were compromised. Among the officials whose devices were hacked was the Brazilian minister of justice and public security, Sérgio Moro.

Seven individuals are named and denounced in the complaint, including computer programmer Gustavo Henrique Elias Santos and his wife, Suelen Oliveira, who allegedly recruited people to participate in a series of scams.

Greenwald was named as an auxiliary to the criminal organization’s activities after a recording of a conversation between the journalist and the organization’s alleged hacker Luiz Molição emerged. The recording was found on a MacBook seized by Brazilian police from the house of Walter Delgatti Netto, who prosecutors allege was one of the organization’s leaders. 

In the audio, Molição confirms that a phone hack is ongoing. He then asks Greenwald for guidance on the possibility of “downloading” the content of other people’s Telegram accounts before the journalist publishes certain articles on his website, The Intercept.

Prosecutors allege that Greenwald then advised Molição to cover the criminal gang’s tracks by deleting archives of material that they had sent to the journalist. Deleting the material could hinder a police investigation and possibly reduce the criminal liability of the individuals behind the hack. 

The complaint states that the criminal organization carried out 126 telephone, telematic, or computer interceptions and 176 invasions of third-party computer devices. An investigation into whether the hacks resulted in financial profits is ongoing, and the possibility of future judicial proceedings has not yet been ruled out.

The Intercept and Greenwald both released statements on Tuesday labeling the federal prosecutor’s allegations as an attack on Brazil’s free press “in line with recent abuses by the government of far-right President Jair Bolsonaro.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Fake Smart Factory Captures Real Cyber-threats

Fake Smart Factory Captures Real Cyber-threats

A fake industrial prototyping company created by cybersecurity researchers has become the target of real-life cyber-attackers. 

Researchers at Trend Micro established the faux firm and maintained it for a six-month period in 2019 to learn about the threats facing companies that use Operational Technology. The honeypot was compromised for cryptocurrency mining, targeted by two separate ransomware attacks, and used for consumer fraud.

The fake concern consisted of real industrial control systems (ICS) hardware and a mix of physical hosts and virtual machines that ran the factory. Among these machines were several programmable logic controllers (PLCs), human machine interfaces (HMIs), separate robotic and engineering workstations, and a file server.

The honeypot went live on May 6, with a fake client base composed of large anonymous organizations from critical industries. By July 24, a threat actor had entered the fake company’s system and downloaded a cryptocurrency miner. Researchers observed the attacker returning regularly to relaunch their miner.

By August, researchers had observed multiple incidences of compromise, with one threat actor performing reconnaissance activities and another causing system shutdowns. Ransomware attacks using Crysis and a Phobos variant were carried out against the fake company in September and October, respectively. 

Greg Young, vice president of cybersecurity for Trend Micro, said the research indicated that industrial companies are primarily vulnerable to bog standard cyber-threats.

He said: “Too often, discussion of cyber threats to ICS has been confined to highly sophisticated, nation-state level attacks designed to sabotage key processes. While these do present a risk to Industry 4.0, our research proves that more commonplace threats are more likely.”

Young warned owners of small smart factories against the dangers of thinking that their company’s size makes them somehow immune to the threat of cyber-attack.

He said: “Owners of smaller factories and industrial plants should not assume that criminals will leave them alone. A lack of basic protections can open the door to a relatively straightforward ransomware or cryptojacking attack that could have serious consequences for the bottom line.”

Smart factory owners can reduce the risk posed by malicious threat actors by minimizing the number of ports they leave open and also by strictly enforcing access control policies.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Facebook Crime Rises 19% as UK Tries to Police Social Media

Facebook Crime Rises 19% as UK Tries to Police Social Media

The UK government is planning to police social media by issuing sites with a new code of conduct.

Social media firms will be required by law to protect children from viewing any content deemed to be “detrimental to their physical or mental health or wellbeing,” according to a report published yesterday in The Daily Telegraph.

Failure to act in line with the government-backed code could result in fines and penalties that could potentially lose an offending company billions of pounds in revenue.  The current code of conduct was created in 2017 and updated in April 2019.

News of the stricter code comes as statistics obtained from the British police reveal an alarming increase in the number of reported crimes linked to Facebook. 

Data obtained from 20 different UK police forces under a Freedom of Information (FOI) request indicates that in the financial year 2019–20, the number of Facebook-related crimes reported to the police was 32,451. When compared to the same period in 2017–18, this total shows an increase in crime of 19%.

Official figures from the police list the total number of crimes with a connection to Facebook as 55,643. Data shared under the FOI request revealed that Leicestershire Police received the highest number of reports of Facebook-linked crimes. In total, the English Midlands force said it had recorded 10,405 such incidents, of which 408 involved victims categorized as “vulnerable.”

Lancashire Constabulary reported the second-highest number of crimes linked to the social media giant. The North West England force said it had recorded 8,829 Facebook-connected crimes, of which 718 were harassment, 179 were sexual offences, 1,007 involved offensive messages, and 1,497 were classified as malicious communication.  

Greater Manchester Police reported 8,230 Facebook-linked crimes, many of which involved “engaging in sexual activity with a child.”

The FOI request was put out by the Parliament Street think tank. Figures obtained by the think tank via a FOI request for offenses that mentioned Instagram or Facebook in the crime notes found that Instagram had been used by pedophiles, stalkers, burglars, and drug dealers to commit 15,143 crimes since 2017. The total number of cases associated with both sites since 2017 is 70,786.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Apple Dropped iCloud Encryption Plans After FBI Complaint: Report

Apple Dropped iCloud Encryption Plans After FBI Complaint: Report

Apple dropped plans to offer end-to-end encrypted cloud back-ups to its global customer base after the FBI complained, a new report has claimed.

Citing six sources “familiar with the matter,” Reuters claimed that Apple changed its mind over the plans for iCloud two years ago after the Feds argued in private it would seriously hinder investigations.

The revelations put a new spin on the often combative relationship between the law enforcement agency and one of the world’s biggest tech companies.

The two famously clashed in 2016 when Apple refused to engineer backdoors in its products that would enable officers to unlock the phone of a gunman responsible for a mass shooting in San Bernardino.

Since then, both FBI boss Christopher Wray, attorney general William Barr and most recently Donald Trump have taken Apple and the wider tech community to task for failing to budge on end-to-end encryption.

Silicon Valley argues that it’s impossible to provide law enforcers with access to encrypted data in a way which wouldn’t undermine security for hundreds of millions of law-abiding customers around the world.

They are backed by world-leading encryption experts, while on the other side, lawmakers and enforcers have offered no solutions of their own to the problem.

Apple’s decision not to encrypt iCloud back-ups means it can provide officers with access to target’s accounts. According to the report, full device backups and other iCloud content was handed over to the US authorities in 1568 cases in the first half of 2019, covering around 6000 accounts.

Apple is also said to have handed the Feds the iCloud backups of the Pensacola shooter, whose case sparked another round of calls for encryption backdoors from Trump and others.

It’s not 100% clear if Apple dropped its encryption plan because of the FBI complaint, or if it was down to more mundane usability issues. Android users are said to be able to back-up to the cloud without Google accessing their accounts.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Exposes 250 Million Call Center Records in Privacy Snafu

Microsoft Exposes 250 Million Call Center Records in Privacy Snafu

Microsoft briefly exposed call center data on almost 250 million customers via several unsecured cloud servers late last year, according to researchers.

Bob Diachenko spotted the major privacy snafu a day after databases across five Elasticsearch servers were indexed by the BinaryEdge search engine on December 28.

Each contained a seemingly identical trove of Microsoft Customer Service and Support (CSS) records spanning a 14-year period. The records included phone conversations between service agents and customers dating back to 2005, all password-free and completely unprotected, according to Comparitech.

Most personally identifiable information (PII) was redacted from the records, but “many” apparently contained customer email and IP addresses, support agent emails and internal notes and descriptions of CSS cases.

This presented not just a phishing risk but a valuable collection of data for tech support scammers who impersonate call center agents from Microsoft and other companies to install malware on victim machines and steal financial data.

“With detailed logs and case information in hand, scammers stand a better chance of succeeding against their targets,” explained Comparitech’s Paul Bischoff.

“If scammers obtained the data before it was secured, they could exploit it by impersonating a real Microsoft employee and referring to a real case number. From there, they could phish for sensitive information or hijack user devices.”

However, Microsoft was praised for acting swiftly to lock down the exposed servers.

After being informed by Diachenko on December 29, the firm had secured all data by December 31.

Microsoft is just the latest in a long line of companies that have exposed sensitive consumer data through cloud misconfigurations.

These include Choice Hotels, Honda North America, Adobe and Dow Jones.

Sometimes the leaks come from suspected cyber-criminals. Back in December, over one billion email and password combos were exposed via an unsecured Elasticsearch database, with many collected from a previous 2017 breach.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk