Thursday, January 17, 2013

Good Morning America Demonstrates Webcam Spying

Good Morning America demonstrates how easy it is to perform webcam spying.  Most people don't know that webcam hacking is very easy to do.  Watch for your self.  Don't be the next victim protect yourself now with the Best Webcam Cover on the market.  C-SLIDE

Wednesday, January 16, 2013

See You Typing


Spying on someone by hacking into his webcam is disturbingly easy. Why don't more people do it?

By Christopher Beam|Posted Monday, April 6, 2009, at 5:09 PM ET

The China-based cyber-spy network known as "GhostNet" is a sophisticated group of hackers capable of logging its victims' keystrokes, stealing their documents, capturing images from their screens—and staring creepily at them through their webcams.

In a report released last month, Canadian researchers concluded that GhostNet has cracked at least 1,295 computers in 103 different countries, specifically targeting the Dalai Lama and other Tibetan activists and officials. Stealing documents and logging keystrokes—that I understand. You can get all sorts of useful information reading someone's e-mail or looking at their bank records. But peeking at them through their Web cameras? That seems creepy even by the standards of shady cyber-spying rings. It's one thing to read the Dalai Lama's IM conversations. It's another to actually watch him LOL.

GhostNet might be the most prominent example yet of webcam infiltration, but it's certainly not the first. The practice dates back to 1998, when a group of hackers calling itself the Cult of the Dead Cow designed a piece of software that, when downloaded onto a computer, let someone control the machine remotely. Anything you could do sitting at your desk, they could do thousands of miles away, from creating documents to playing MP3s to popping open the disk drive. They dubbed the program Back Orifice—a twist on Microsoft's BackOffice. The authors "were not malicious guys," says Frank Heidt, CEO of Leviathan Security. "They thought it was funny as hell."

Webcam scams do occur, though they're far less common than other types of online extortion. In 2004, four hackers in Spain were arrested after threatening to post candid webcam videos online unless their victims paid up. In 2008, a Canadian man told young girls that he had nude pictures of them and would post them on the Internet unless they posed for him again.

Governments and businesses have adapted. For example, the Department of Defense has regulations about where you can carry a laptop. And unlike the most advanced computer worms, this isn't a threat that's constantly evolving to outpace security measures.

Since Back Orifice hit the market, the basic methods of cyber-peeping haven't changed much: Just get your target to download an e-mail attachment or click a link that triggers an automatic download, activate the camera, then sit back and watch. "Writing the malware is a total triviality" even for middling programmers, Heidt says. Back Orifice is still available for download, and beginners can find instructions on how to write their own programs with a simple Google search. Or you can just take a college course on how to do it.

What's changed is the prevalence of cameras. You can't buy an Apple laptop these days without a built-in camera. Even Sony's smallest notebook has a webcam. Sometimes they're practically invisible: The MacBook Air's built-in camera is "so smartly integrated, you hardly notice it's there," brags Apple. That said, almost all laptops have a light that turns on whenever the camera is on—a feature that hackers can't disable since it's controlled electronically, not programmatically.

Still, webcam espionage isn't very common. Most scammers are interested in money, and video of someone's slack-jawed mug isn't going to yield much cash. "Most stuff you'd capture on a camera, they've already posted on Facebook," says Kevin Haley of Symantec Security Response. *Even if you did have hundreds of hours of video and audio capturing someone's conversations, it's a lot harder to index and search than written information. (Some programs solve this problem by activating the camera only if they sense movement.) If it's profit the hacker wants, the contents of the computer are much more valuable than whatever's happening in front of it.

If someone hacks into a webcam, therefore, it's usually a targeted attack. Pure creepiness is one motivation. A 15-year-old girl in Texas reported in 2004 that a hacker who took over her computer would eject the disk drive and say things like, "I like your shirt."

Then there's spying on people you'd like to keep an eye on, such as, say, your spouse. One could see this being useful for private investigators, though PIs I spoke with say they don't know of anyone hacking into webcams as part of their work. "The technology is there for it to happen," says Charles McLaughlin, a PI in Andover, Mass. "But in the private sector, although there are some characters willing to break the law, most reputable PIs don't." You might get away with it if you install the spyware own your own computer—say, the one in the bedroom—but even that gets into shady legal territory.

More threatening than video is audio. By accessing a computer's microphone, you turn the computer into a bug. It's also more clandestine than video, since the microphone is always on and there's usually no light to tip you off when it's recording. "The mic thing worries me a lot more," says Chris Wysopal of the security firm Veracode. "Unless you can lip-read, [video alone] isn't that useful."

So how do you prevent someone from spying on you? The usual Internet hygiene applies. Don't click the weird attachment your computer-illiterate relatives send you, update your antivirus software regularly, and so forth. If you want to be really cautious, the best solution is the simplest: Put a piece of tape over the camera. It may be the laptop equivalent of the tinfoil hat, but it's the only way to absolutely guarantee privacy. The microphone is trickier, since you can't tape it up. You can disable it, though, by plugging a converter or some other cord into the computer's microphone jack, which turns off the internal mic.

But ultimately, there's only so much you can do. Vulnerability is a fact of cyber life: Anytime you open a portal to the outside world, it makes intrusion possible. The problem is when we don't even know the portal exists, or are only dimly aware of it. There's a general rule that you shouldn't write anything in an e-mail that you wouldn't want shared with the world. Perhaps the same should apply to dancing in your underwear while your laptop is watching.  Read More>
Don't be the next victim protect yourself now with the best webcam cover on the market C-SLIDE.

Tuesday, January 15, 2013

C-SLIDE at the NYIGF


C-SLIDE will be at the New York International Gift Fair introducing our Webcam Covers to retailers for the first time.  If you are a retailer we will see you there on January 24-30th.
http://www.nyigf.com/

Wednesday, January 2, 2013

How to Protect Yourself From Webcam Spying

Here is another happy C-SLIDE Customer.  Hear how he protects himself from webcam spying.  Don't be the next victim buy a C-SLIDE now.

Monday, December 31, 2012

Facebook eliminated potential 'webcam spying' hack this summer


A Facebook security vulnerability, which could have been exploited to activate a user's webcam and record them without their knowledge, was closed off this summer, it has been revealed.

Facebook paid Indian research firm XY Security a $2,500 (UK£1,546, AUD$2,409) "bounty" in July for discovering the issue and drawing the bug to its attention, the social network has confirmed.

The flaw, which Facebook said had never exploited by a potential 'Peeping Tom', could, conceivably have troubled users who had already agreed to give Facebook permission to access the camera.

Beyond that the user would have to be 'tricked' into visiting a malicious page, then agree to activate the camera - allowing the spy/pervert to begin recording.

Five times the going rate

Facebook must have felt the threat was serious at it paid five times its usual rate to the two researchers who reported the flaw.

"This vulnerability, like many others we provide a bounty for, was only theoretical, and we have seen no evidence that it has been exploited in the wild," Facebook spokesperson Josh Wolens told Bloomberg.

"Essentially, several things would need to go wrong - a user would need to be tricked into visiting a malicious page and clicking to activate their camera, and then after some time period, tricked into clicking again to stop/publish the video."

Facebook is one of many Silicon Valley heavyweights (other notables being Google and Mozilla) who offer 'bug bounties', paying out millions to researchers who spot flaws and potential dangers.

 

There will always be another hack.  The only way to protect yourself from webcam spying is with a webcam cover.  C-SLIDE is the best webcam cover on the market today buy one now.

Monday, December 17, 2012

Is your TV Watching you? Security ALERT Over Samsung's Smart TV.


 

TV Owners that have the Plasma 8000 series, the 7500 LED LCD series, the 8000 LED LCD series or the 9000 LED  LCD series might want to know that HACKERS claim they can access to these TV's  

·         Security experts reveal they have been able to gain access to the device and scour its hard drives and connected drives for information

·         They claim to have 'complete root access' allowing them to install malicious software that could monitor its cameras and microphones

·         More and more devices that connect to the Internet are leaving unwitting consumers vulnerable to such hacking attacks

 Samsung's Smart TV could used by hackers to watch everything that happens in your living room by gaining access to the device's built-in camera and microphones, it has been claimed.

Malta-based security firm ReVuln posted a video showing how its researchers had learned to crack the television to access its settings - including any personal information stored on it.

'We can install malicious software to gain complete root access to the TV,' they claim in the video.

With such malware installed, hackers could use the Smart TV's built-in microphones and camera to hear and see everything in front of it.

Samsung's Smart TV can be used to browse the internet, use social networks, watch net-based commercial film streaming services and play online games, among other things, from the comfort of your sofa.

The devices can also be controlled by voice commands and gestures, using their microphones and cameras to detect what is happening in front of them.

However, while the Smart TV's are connected to the internet they are vulnerable to hackers who can access the device and access files stored on them.

Luigi Auriemma, co-founder of ReVuln, says he has found a way to track down the IP address of the device and gain access to seize control and scour any drives connected to it.

The video appears to show he is able to access remote files and information like the viewing history, as well as siphon data from USB drives attached to a compromised set.

Mr Auriemma told Ars Technica: 'At this point the attacker has complete control over the device.

Devices from lighting systems to air conditioners to computer games consoles now rely on online functionality, but their operating systems often do not have the same kinds of security measures now commonly deployed on Microsoft and Apple powered devices.

At the moment, ReVuln's exploit only works once hackers have managed to breach the network which the television is connected to. As such, Mr Auriemma told NBC News, he expects the main danger is of hackers targeting specific companies or individuals.

'In our opinion, it’s more interesting and realistic to think about attacks [against] specific targets reached via open/weak/hacked Wi-Fi or compromised computers of a network, instead of mass-exploiting via the Internet,' he said.

'That’s interesting due to the effects of the vulnerability (retrieving information and the possibility of monitoring) which are perfect for targeted attacks, from a specific person with a TV at home to a company with TVs in its offices.'

Revuln plans to sell information on the vulnerabilities to the highest bidder, the Register reported, claiming this will 'speed up' fixes faster than merely reporting them to the manufacturer.

The company would not go into details about the flaws it has discovered.

The possibilities of such vulnerabilities are worrying with increasing numbers of consumer electronics devices being equipped with sensors, cameras and microphones to detect what is happening around them.

A spokesman for Samsung said: 'We have discovered that only in extremely unusual circumstances a connectivity issue arises between Samsung Smart TV’s released in 2011 and other connected devices. We assure our customers that our Smart TVs are safe to use.

'We will release a previously scheduled software patch in January 2013 to further strengthen Smart TV security. We recommend our customers to use encrypted wireless access points, when using connected devices.'


The simple fix is not a patch which will also be hacked but a webcam cover that fits the Samsung Smart TV product line.  These webcam covers can be purchased at C-SLIDE.
 
 
 

 

 

Friday, December 14, 2012