::Trend Micro Threat Resource Center::

15 March 2013

Doctors used silicone fingers to fool fingerprint scanner

Fingerprint scanners might not work with severed fingers, but artificial ones still manage to fool them, as proved by the recent discovery of a fraudulent scheme set up by doctors working in the Ferraz de Vasconcelos hospital in the Sao Paulo state in Brazil.



The story broke when Globo TV managed to get its hands on a video that shows 29-year old doctor Thauane Nunes Ferreira first clocking in at work by pressing her own finger onto the device, then doing the same for two colleagues by using silicone fingers.

In the footage, she seems uncomfortable doing it, and collecting the slips of paper that proved that those persons checked in. After having been arrested, she admitted to doing it for a while now, but pointed out that she was coerced into doing it by Jorge Cury, the head of the emergency room, who allegedly organized the whole scheme and threatened the ones who didn't want to participate with dismissal from their job.

It is also alleged that his own daughter was employed by the hospital, in which she hasn't set foot for over three years.

The scheme - and Cury's involvement in it - has apparently been confirmed by a doctor who resigned two years ago because he (she?) refused to break the law.

Five doctors have been suspended while the investigation goes on. Acir Fillo, the mayor of Ferraz de Vasconcelos commented that it is possible that as many as 300 hospital employees were in on the scheme and were paying to be clocked in while working somewhere else and collecting two pays.

Unfortunately, the report does not mention which fingerprint scanners are used at the hospital, but it proved that the development of this particular type of biometric device still has a way to go in order to reach a satisfactory level of assurance.

14 March 2013

Protecting Against APTs: Network Visibility

Worldwide spending on IT security reached approximately $60 billion in 2012 – a 8.4% rise from $55 billion in 2011. Yet, Fortune 500 companies continue to be in the news headlines due to data breaches. One can’t help wonder how these attacks by-pass the security controls that are already in place.

John Kindervag of Forrester Research explains why traditional security controls such as IPS and FW are inadequate against advanced targeted attacks.


Fake Pope Twitter account proves malicious potential of breaking news

Mere minutes after it become publicly known that Argentinian cardinal Jorge Mario Bergoglio was elected to serve as the new Pope, Internet users around the world began searching for him on social networks.



A Twitter account (@JMBergoglio) using his name and photo was promptly discovered, and as many users considered it to be legitimate, it attracted over 100,000 followers in just a day. They were able to read that he was very happy at being elected as Pope, and that kids are going to love him more than Santa Claus.

But, as it turns out, the account is fake and has been promptly suspended by Twitter, presumably after the Vatican PR machine got involved and requested it.

Luckily for the followers, the individual behind the account wasn't set on promoting malicious links, but this example shows just how easy it is for scammers to find a way of reaching hundreds of thousands of users by simply taking advantage of the massive interest some global events garner.

Even the Verified Account option is sometimes not enough to guarantee that the account you follow belongs to the person you are interested in.

All in all, users are advised to never follow links included in tweets, Facebook posts, or emails unless they are absolutely, 100 percent sure they will not take them to malicious sites.

13 March 2013

Tips for removing data from mobile devices

AVG released tips on how consumers can remove their personal data before they recycle or throw away their old smartphones.



In an era of frequent and seamless device upgrades, it’s easy to ditch an old handset and move on to the next. However, chances are the old device has personal information lingering on it, putting consumers at a greater risk of identity theft.

“Think about all the personal data stored on your phone: text messages, emails, even intimate photos of you or your significant other,” said Tony Anscombe, senior security evangelist at AVG. “Consumers are now carrying more and more personal information on their devices, and AVG wants to ensure everyone is well equipped to wipe out that data when the time comes. Your identity is essentially yours to lose, so take every precaution possible to stay safe.”

While the factory reset button seems like the logical place to start, numerous industry and security experts report that even after consumers carry out this exercise, personal information often remains.

The following tips will help ensure private information is erased:
  • Remove the memory and SIM cards. Both store personal data and are best kept safe in your possession or destroyed.
  • Use a data removal application to ensure data really is deleted.
  • Once the data is deleted, then run a factory reset. Instructions can be found on manufacturers’ or carriers’ websites.
  • If you are going to simply throw away your mobile phone, older handsets can contain toxic materials. Consult your local authority or drop it off at a mobile phone retailer, where they will be able to dispose of it correctly. Additionally, there are specialist companies that will take it apart and recycle each component.
  • Of course, recycling or handing it on for use is a good option; there are many charities and organizations that redistribute old phones and will even send you a pre-paid postage box to send it in. Just search on the Internet for the many options!

03 March 2013

The Five Easiest Ways to Get Your Identity Stolen

Identity theft is a huge black market industry, costing US consumers $1.52 billion in 2011 and stealing headlines all last year. Here are five habits that all but guarantee you'll become just another statistic in 2013—and how to break them:

27 February 2013

The Giant Security Hole That Facebook Doesn’t Care About

You probably assume hackers are using all sorts of devious viruses, obscure scripts, "exploits" (whatever that means, right?) and other complex means to break into accounts. But often the means of entry are stupid simple. Facebook has a huge one—and doesn't care about fixing it
There's a basic premise here that isn't a Facebook problem, but really an internet problem: it's super easy to reset someone's password. The web is an ornate, lumbering thing built on tiny little stilt legs, its foundation unfit for what came after it. It's complex stuff standing on simpler stuff. New on old. And often the old can't cut it: just ask Giz alum Mat Honan, whose online life was savaged because of the stupid-simple processes standing between assholes and us online. You don't need to be a hacker—you can just talk your way in:

Step one: Say you've forgotten your password.
Step two: Say you've forgotten your email address.
Step three: Use a security question or customer service rep to change over to a new email address—one you control.
Step four: Send a new password of your choosing to that new email address.
Step five: Log in.

This is the same lazy, methodical trick that hit Honan, breached @BurgerKing, and this past weekend, tried to crack my Facebook account. Again, and again, and again, because Facebook makes it so easy.

The crux of the problem is impossibly stupid: Facebook won't let you change your security question. The street you grew up on, the name of your first cat, your college mascot—these bits of dumb personal trivia are all it takes to claim complete control of someone else's Facebook account. You probably forgot the day you even entered yours. Luckily, it's so obvious, you'll never forget it. That's the simultaneous beauty and stupidity of the security question: eternally memorable.

But hey, what if someone happens to guess this extremely guessable piece of information about you, based on readily Google and Facebook-available details? What if they use the answer to this question to repeatedly attempt to break into your account—perhaps successfully? Shouldn't you be able to change that question to something that isn't already known by someone with clearly nefarious intentions?

You'd think so, and you'd be wrong. There's no way to manually switch your security question to something new if you're worried someone might have the answer. Or just to switch it up for the sake of switching it up, as we do with passwords. Facebook simply won't let you.