Fitness Balance & Calories Tracker are two apps that have been removed from the Apple Store for tricking users into approving in-app purchases using Touch ID. How did they do it? Quite cleverly actually.
As part of the initial set up you are asked for a finger print scan to view your personal calorie tracker and diet recommendations. As your fingerprint is being scanned, pop ups appear asking you to approve several payments. Of course because you are having your fingerprint scanned, the payments are marked as approved. Very clever. You would admire the creativity if they weren’t racking up charges on your credit card.
This new attack vector gives us another thing that we need to watch out for when using apps, inappropriate use of Touch ID. Lucky for us if you have been victimized by this scam, all you have to do is contact Apple and ask for a refund.
With the release of IOS 12 it was discovered that by using Siri, you could bypass the lock screen. Unfortunately, the latest security update does not fix that problem. To ensure that your phone stays secure, change your settings to disable Siri when the screen is locked.
To change your settings:
- Open settings.
- Select Siri & search.
- Scroll down to find Allow Siri When Locked.
- Click to disable it.
Armed with nothing more than your phone number, criminals can steal your WhatsApp account. How? By registering your phone number on their phone. Here is how it works.
First the attacker makes a request to have your phone number registered to the WhatsApp application on their phone. When WhatsApp receives the request, they text a verification code to your phone. The scammers make their request in the middle of the night or when you are on a flight so you don’t see the verification code. With the text not answered, WhatsApp offers to read out the code and leave it in a voicemail.
If your cell phone carrier has a default password set up for voicemail and you have not changed it, the criminal simply enters the default password and boom…they can hear the verification code. Once they enter that code, the account gets transferred over to their phone. The attacker then sets up two step verification on the account and you have no way of getting it back.
The moral of the story, set strong and unique password for your voicemail. While you are at it, do that with all your accounts.
If you have an Android phone or an IOS phone that has the Google app on it, Google could be following your every move. Most people are aware that you can turn the Location Services off on your iphone and disable Location reporting on your Android phone. You may even know how to turn off Location History so Google doesn’t store a record of where you have been. What you probably don’t know is, Google has been deceiving you.
AP News has found that when you turn off those services, it only disables the viewable timeline. However every time you open Google Maps, get some weather updates or use Chrome for a search, it tracks you and stores time-stamped location data from your devices.
Fortunately, there is a way to truly turn off the location tracking. Google buried it deep within their account settings. To keep nosy Google from tracking you in any way:
- Open the Google app on your mobile device.
- Click the Settings icon in the upper left hand corner.
- Select Manage your Google Account.
- Select Personal info & privacy.
- Select Activity Controls.
- Select Web & App Activity.
- Click the slider to disable Web & app activity. It should turn gray.
Windows users have heard about the tech support scam that informs them their computer has a virus and they need to call a 1-800 number to unlock it. Creative criminals are now using the same tactic with iphone users. They have seeded several porn sites with malware. After your visit, a large dialog box appears on your phone informing you that your phone has been locked because you visited an illegal porn site. It all looks very official as it correctly displays the model of your phone and the URL of the porn site. It then gives you a hyperlink to a number to call to get your phone unlocked.
In reality, your phone isn’t locked at all. If you call the number you get connected to a hacker who then attempts to get information and money from you. Although this scam leverages a visit to a porn site, a similar scam can be set up with any type of website. It can also target any kind of phone. It may be iphone users that are currently targeted, but it won’t take long for this scam to show up on Android phones as well.
Never call a number that shows up in an alert or notification on your phone. Never click on security warning links either. If you do connect to a call center and start to feel uncomfortable, hang up. Apple will never lock your phone and then ask you to call a number to get it unlocked. Come to think of it, neither will Google or Android.
Two step verification keeps criminals from accessing your account if your password is compromised. It is a great way to add an added level of security to your accounts. However, enterprising criminals have found a way around it.
How did they do it? Is there some back door that they found? Have they created a new brute force hack technique? Nope. They just ask for the verification code. Low tech social engineering strikes again.
Here is how it works. They send you a text that looks like it comes from Google notifying you of a password reset. If you don’t want your password reset, you are instructed to text the word STOP. Once you do, you are asked to text 822 back to be sent a verification code to stop the password reset. Once you receive the verification code, they ask you to text them the code back to confirm that you don’t want the password reset. Pretty clever huh?
Of course what is happening is they are trying to get into your account but can’t because they don’t have the verification code. By playing the stop the password reset game they are hoping to catch you off guard so you just sent them the code.
For the record, no one will ask you if you don’t want to do something with your account. As soon as someone asks you for confirmation to NOT do something, you know the jig is up. This is just another reminder that we have to read our texts and emails carefully and question anything that seems odd. The criminals count on you to react without thinking. Stop them in their tracks, think before you react.
If you have been using MyFitnessPal from Under Armour, change your password immediately. On March 25 Under Armour learned that usernames, email addresses and hashed passwords were taken from about 150 million user accounts.
The good news is the passwords were hashed or scrambled and will need to be decoded before they can be used. The bad new is, the thieves may use phishing emails to acquire your password directly instead of doing the hard work of decoding it. Change your password directly in the app or through their website instead of using a link in an email.
If you use your MyFitnessPal password for other apps or websites, make sure you change those passwords as well.
What are they?
New vulnerabilities called Meltdown and Spectre have been found in computer processors built after 2009 that allow a program to steal data from your computer system’s memory without your permission or knowledge. It affects everything that has a computer processor including your computer, tablet, phone and IoT (Internet of things such as a smart thermostat).
Why should I be concerned?
These vulnerabilities have the potential to allow hackers to covertly fetch sensitive information such as passwords from system memory allowing access to your online banking, social networking accounts and the like. To make matters worse, the attack can be made via your browser.
How is the problem fixed?
As these vulnerabilities are in the main processing chip on the computer, the ultimate fix will be to change the processor codes, the firmware or the chip itself. However, the problem can be mitigated by modifying how the software interacts with the processor. As a result, software and hardware vendors are currently developing patches for these vulnerabilities.
What is IT Services doing about it?
We are following our standard processes to manage the patches for these vulnerabilities.
What do I have to do?
You do not need to update your workstation, it will be done by the MRU patch management process. Your regular updates include all required patches. If you have a Mount Royal laptop or device and you aren’t sure that it is getting updated, please visit the IT Service Desk.
Install updates for all your personal portable devices and home machines as soon as they become available. Make sure that your browser is updated as well. Please note that not all anti-virus programs are compatible with Microsoft’s latest updates. If your machine has incompatible anti-virus software, the Microsoft updates will not be uploaded and your machine will be left vulnerable. Check your anti-virus program’s website to see if it is compatible.
Make sure you visit official/trusted websites to get your updates or use the update feature from within your software. We do not recommend clicking on links and opening attachments in emails claiming to have a link to the latest updates or patches. Criminals may take this opportunity to send out fake security patch or update emails with malicious links to try and trick you into downloading their malware.
For more details on the vulnerabilities, check out the sources for this article:
Researchers have discovered a vulnerability in Bluetooth enabled devices that would allow an attacker to take control of them with no action on the part of the user. The majority of manufacturers have issued updates to patch this vulnerability. As Bluetooth is a fairly complicated protocol, experts warn that there may be more vulnerabilities not yet discovered. To protect yourself, make sure you:
- Keep your device updated.
- Turn off Bluetooth when not using it
There is a lovely iOS feature called AirDrop which allows you to sent files to anyone within Bluetooth range anonymously. It has facilitated the rather disturbing practice of bluejacking, sending pics of your privates to random strangers in order enjoy the look of shock on their faces. By default this feature is enabled so you can receive files from anyone on your contact list. However some people have inadvertently changed the settings so they can receive files from anyone.
To prevent such unpleasantness, it is recommended that you disable your AirDrop unless you are using it. To turn AirDrop off:
- Swipe up to view the Control Center.
- Select AirDrop Receiving.
- Select Receiving Off.