Infolinks In Text Ads

Sponsor

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Saturday, January 2, 2021

Malaysia Digital Bank License

With Hong Kong and Singapore having accelerated the issuance of their digital banks licenses, is Malaysia’s foray into the space a bit slow?

Based on this week’s announcement by Bank Negara, digital bank licenses will be issued only by the first quarter of 2022. The concern is would the Malaysian digital bank landscape have lost ground by then? Globally, digital banks are already in advance stages of operations.

To be sure, setting the rules right on the onset for digital banking is of utmost importance. It involves the main artery of the economy, namely the banking system. Perhaps this is why Malaysia’s central bank is not rushing the matter.

On Thursday, Bank Negara issued a policy document on licensing framework for digital banks following a six-month public consultation.

Bank Negara said the licensing framework for digital banks aims to enable the innovative application of technology to uplift the financial well-being of individuals and businesses and foster sustainable growth.

This includes expanding meaningful access to and promoting responsible usage of suitable financial solutions to the unserved and underserved segments.

The framework adopts a balanced approach to enable admission of digital banks with strong value propositions while safeguarding the integrity and stability of the financial system, as well as depositors’ interests.

To achieve these outcomes, a simplified regulatory framework will be applied to digital banks during the initial stage of operations, commensurate with an asset threshold of not more than RM3bil for three to five years.

Submission of applications to conduct digital banking business or Islamic digital banking business shall be made to the Bank no later than June 30,2021.

Up to five licenses may be issued to qualified applicants. Notification on the grant of license will be made by the first quarter of 2022, Bank Negara said.

It does seem that the central bank is on the right track with ensuring only the most qualified applicants get to run digital banks.

That said, one wonders how the digital banking space will grow globally and whether Malaysian licenses could have lost any ground by 2022.



Stalkerware? Do You Experience It?

Your smartphone, your PC, your laptop – most of the devices we use are to some degree vulnerable to so-called stalkerware, software installed without your knowledge and aimed at obtaining sensitive data, like personal photos or login details. 


In a nutshell, stalkerware “can result in the theft of data, monitoring of emails, SMS and MMS messages sent and received and even intercept your phone calls for the purposes of eavesdropping”, the Coalition against Stalkerware says.

The platform, a joint initiatve by aid organisations and IT security companies, aims to combat stalking, harassment and domestic violence by addressing the issue of stalkerware.

“Stalkerware services imply that their customers personally know victims, because these commercial spyware apps are manually installed. Users have to download the app, install it and enter credentials that are received after purchasing,” the Coalition explains further.

Anyone who loses their smartphone for a short period of time or has lent it to someone else for a longer time should therefore check it for changed or unknown settings, the initiative recommends.

On Android devices, for example, the setting “Unknown Sources” in the security menu is deactivated by default. If it’s suddenly activated, however, it could have been manipulated.

An unexpected discharge of the battery can also be a sign of stalkerware. Other indications are unknown apps or processes and webcam permissions that have not been granted by the device owner.

Even active sessions for which you have not logged in can indicate installed stalkerware.

Stalkerware is used for hidden digital surveillance, among other things. Removing it is not easy, but not impossible either. The Coalition against Stalkerware offers advise on how to do so on its website.

However, if you delete it, the respective offender is also warned. Victims of cyberstalking should therefore prepare a security plan and get expert help, for example from organisations that support victims of domestic violence.

Monday, December 21, 2020

Why Undersea Fiber Cables Prone To Cyber Attack?

Believe or not, it's easy to tap into any undersea fiber cables. What you need to have is
  • Suitable Ship with at least DP2 or DP3 capabilities
  • Technical team to undergo physical tapping
  • Software and Hardware suitable for tapping
So... to do the Cyber Attack need enough funding. How big is the funding is questionable. At least maybe few million dollars.



Critics in the U.S. government say a new 8,000-mile cable beneath the Pacific Ocean is bait for foreign spies. But advocates counter that these fears are overblown, and the first direct fiber link from the U.S. to Hong Kong is worth it.

The Department of Justice's statement lays out the specifics of its objections. The planned cabling connects the U.S. to Hong Kong, Taiwan, and the Philippines. Much of the cabling will be owned by Google and Facebook, but one partner, the Hong Kong-based Pacific Light Data Co. Ltd., is among the largest telecoms in China.

The DoJ approves of everything but the length of cable that will connect to and terminate in Hong Kong, which China contentiously controls. Officials have said they worry that China’s unsubtle espionage will descend on the cable as a point that can be exploited.

Because of the high speed of the very long cable system, data trying to shortcut around the world could pass through Chinese territory in a way it may not have before. In simple terms, the U.S. government claims it worries that data will be “wiretapped.”

Undersea cables are built to last, either way. The nature of their placement means they must be extremely tough, and these cables have a fiber (or ethernet, telephone, telegraph) core surrounded by staggered layers of thick metal strands for protection. Then the entire assembly is protected by outer layers of rubber or carbon fiber.

Someone determined enough can still snap a cable like this, because the protections are designed for accidental deep-sea contact first and foremost. If the cables are smashed by rocks or improbably run over by ships, they’ll be fine.

For now, a thin social contract holds the network together, as anyone snipping the global internet is hurting themselves, too. But the cable to Hong Kong is seen as an attack surface once the data gets there—not while it’s underwater.

Saturday, December 19, 2020

DJI Being Listed As No-Go In USA

Even though Donald Trump has been ousted from the Oval Office, the US policies is still the same. All policies on China is still intact including any Chinese based technology that were used by Chinese Military.

Drone technology is also not spared.



DJI, one of the largest and most popular drone companies in the world has been added to the US Department of Commerce’s Entity List, designating the Chinese company as a national security concern and banning US-based companies from exporting technology to the company.

The ban was put in place through the same mechanism as the US government’s ongoing ban on Huawei products, and is primarily focused on blocking the export of US technology to the drone-maker. As such, the ban will make it difficult for US businesses to provide parts or components for DJI to use in its drones, which is likely to disrupt the company’s supply chain. 

It may also make it difficult for US stores to directly sell DJI products or transact with the company, particularly if China responds to the action with further restrictions.

The filing also allows for a “case-by-case review for items necessary to detect identify and treat infectious disease; presumption of denial for all other items.” It is unclear which of DJI’s drones and drone accessories might qualify for this exemption, if any.

The new additions to the entity list came alongside a more specific action against China’s Semiconductor Manufacturing International Corporation, or SMIC, which was listed in response to purported ties between the company and the Chinese military.

But the United States government has also cited several concerns in the past over security issues with the drones, which are largely made in China and contain Chinese parts. The Department of the Interior has announced plans to ground its drone fleet as it reviews whether there are any major security concerns of Chinese spying or cyberattacks. 

And the Department of Justice banned buying foreign-made drones which includes DJI’s products using agency funds back in October, citing similar security concerns. The Department of Defense has certified several other drones from competitors like Parrot and Skydio for governmental use instead, after several years of review.

Wednesday, December 16, 2020

What If Apple Running Their Own Search Engine?

What do you think when Apple started running their own search engine? Yes. I know it will not be easy for Apple to compete with Google Search but with many people around the world are using Apple product (MacBook, iPhone, iPad and others), surely it can capture the market with ease.

Small corners of the internet are ablaze with the news that Apple has significantly ramped up its search bot activity. Search bots typically scan websites in order to rank and index them for search engine results. When you look for something on a search engine, the results that appear are ordered by “ranking”, meaning that the result that is most accurate to what you are looking for appears at the top. 

This increase in activity also appears alongside pressure from the UK competition commission to break up Apple’s multi-billion dollar sweetheart deal with Google. The deal ensures that Google is the default search engine for Apple’s iOS devices. Many are now anticipating that Apple is on track to launch its own search engine soon.

I'm sure this will bring much fanfare to all Apple user who are frustrated with the things running behind when using Google Search. Most people that I know already feel suspicious about Google and their technology. They feel that Google are watching all their track and feed them to the third party.

Apple’s search engine will have a different future if rumors about its business model are true. Apple has been focusing heavily on user privacy recently, including but not limited to, publicly refusing to give secret access to its devices to the FBI. It will be very much in line with this “privacy-first” position that Apple chooses not to make money from advertising, which involves exposing customer usage data to third parties. 

Instead, it could simply sell more of its highly profitable devices and subscriptions to privacy-conscious customers. By not following Google’s footsteps, Apple does not have to engage with the search giant on its terms.



With its latest iOS 14 update, Apple has already started swapping out Google search results in favor of its own. Most iOS users have barely noticed the change for all the reasons given above. But this silent swapping does not come without its own set of challenges. By defaulting to its search engine instead of Google on its devices, Apple will open itself to monopoly criticism from competition commissions in a variety of markets. It is also likely to upset the advertising industry who could lose their reach to Apple customers. The Apple customer base is a coveted one thanks to its better than average buying power, and by making it easier for users to avoid search ads, Apple might just create a tectonic shift in the advertising industry as a whole. 

Google’s dominance on internet search will not come to an end with Apple’s entry into the foray, but it would definitely weaken in the face of increasing consumer preference for privacy. Given that Google’s business model differs dramatically from Apple’s, it is likely that the search giant would have to learn to uncomfortably live with its rival’s search engine instead of pivoting to compete with it head-on.

Thursday, May 16, 2013

Making Money Out Of Thin Air

In early 2010, Nish Bhalla sat down at his computer with one objective: steal a huge amount of money from a bank.

real ATM printed receipt
It wasn't a typical heist. Bhalla is the chief executive of Security Compass, a company that tests security systems at banks, retailers, energy companies and other organizations with sensitive data. His clients -- including the bank branch in the United States that he targeted in his 2010 attack -- pay him to break into their systems.

It can be easier than most people think. The alleged thieves who made headlines last week for their $45 million bank heist used a similar type of attack that "created" money out of nowhere.

Bhalla talked and explained his caper.

Here, in four easy steps, is how he made himself into a millionaire.

Step one, get access. Bhalla had one big advantage on actual thieves: His client gave him access to the bank's internal network. For real-world crooks, there are some surprisingly easy ways to get in.

It's possible, Bhalla said, to gain access in some places simply by logging on to the bank's wireless network -- an amenity more and more banks are providing as a service to customers. Once you're on the bank's Wi-Fi, the internal and external networks are frequently not segregated enough. It can be possible to fool the bank's other computers into thinking that your computer is a bank computer, a process known as "arp spoofing."

Another on-ramp: Someone posing as a janitor could insert a thumb drive into a teller's system and reboot it using a new operating system, which would enable them to access the hard drive of the teller's system. From there, user names and passwords are often readable. Because he could simply log straight into his client's network, Bhalla and his assistants skipped the "get physical access" step and dove straight into finding the money.

Step two, start exploring. Bhalla used "sniffer" software, available online for free, to map out which of the bank's systems were connected to each other.

Then he "flooded" switches -- small boxes that direct data traffic -- to overwhelm the bank's internal network with data. That kind of attack turns the switch into a "hub" that broadcasts data out indiscriminately.

The machines that the tellers use quickly became Bhalla's prime target. Again, the sniffer software was deployed to look for login information and passwords in the data flood. Eventually, one hit. He was inside a teller's machine.

Step three, move up the ranks. Amazingly, the information being sent between the tellers' computers and the branch's main database was not encrypted. This meant passwords and bank account numbers were all out in the open.

Step four, cash in. Rather than steal money from depositors' accounts, Bhalla just invented a new account for himself.

"We went into the database where the accounts are and set up an account with $14 million," Bhalla explained. "We just created $14 million out of thin air."

If he wanted to, he could have walked into any bank branch, transferred the money to an offshore account, and never have had to work again. Instead, he went to an ATM to print out a record of his ill-gotten wealth.

"The bank executives were extremely surprised," Bhalla said. "Their faces were shocked."

The bank promptly deleted Bhalla's bounty, he said, and took steps to shore up its network.

In the heist that came to light last week, federal officials say the thieves hacked into networks at firms that process transactions for pre-paid debt cards and created accounts with high spending limits. From there, it was just a matter of making physical debt cards for those accounts and going around to ATMs to withdraw the cash.

"They just updated the database with that debit-card information," Bhalla said. "That's how simple it was."

In many cyber bank heists, including the recent $45 million scam, it's hard to pin down who is ultimately liable for any losses. It's typically not individual customers. U.S. law protects consumer checking and savings accounts from losses stemming from fraud. Business accounts, though, have fewer protections.

Bhalla said some financial institutions have insurance to cover the losses -- but he noted that insurance companies are reluctant to issue policies with high coverage limits because the risks in this area area still poorly understood.

In the end, he said the losses are likely born by a combination of the company, insurance firms and governments.

@ Global Info Center
Freelance Jobs