Showing posts with label Theft. Show all posts
Showing posts with label Theft. Show all posts

Tuesday, July 23, 2013

Raw Data: Encryption Flaw Makes Phones Possible Accomplices in Theft

A German mobile security expert says he has found a flaw in the encryption technology used in some SIM cards, the chips in handsets, that could enable cyber criminals to take control of a person’s phone.

Karsten Nohl, founder of Security Research Labs in Berlin, said the encryption hole allowed outsiders to obtain a SIM card’s digital key, a 56-digit sequence that opens the chip up to modification. With that key in hand, Mr. Nohl said, he was able to send a virus to the SIM card through a text message, which let him eavesdrop on a caller, make purchases through mobile payment systems and even impersonate the phone’s owner.

He said he had managed the whole operation in about two minutes, using a simple personal computer. He estimates as many as 750 million phones may be vulnerable to attacks.

“We can remotely install software on a handset that operates completely independently from your phone,” Mr. Nohl said. “We can spy on you. We know your encryption keys for calls. We can read your S.M.S.’s. More than just spying, we can steal data from the SIM card, your mobile identity, and charge to your account.”

Mr. Nohl is well known in security circles. In 2009, he published a software tool that computes the 64-bit key used to encrypt conversations on GSM networks, prompting the industry to adopt better safeguards. His company, Security Research Labs, advises German and U.S. multinational companies on mobile security issues.

Mr. Nohl said the flaw he had discovered was the result of an encryption method developed in the 1970s called data encryption standard, or D.E.S. After uncovering the breach, he researched the pervasiveness of the problem by testing about 1,000 SIM cards on cellphones running on mobile networks in Europe and North America over a two-year period. The phones and SIM cards were owned and used by himself and members of his research team. Mr. Nohl said that about one-quarter of the SIM cards running the older encryption technology exhibited the flaw.

D.E.S. encryption is used on about half of the about six billion cellphones in use daily. Over the past decade, most operators have adopted a stronger encryption method, called Triple D.E.S., but many SIM cards still run the old standard. The encryption is used to disguise the SIM card, and thus a mobile phone’s unique digital signature.

Mr. Nohl has shared the results of his two-year study with the GSM Association, an organization based in London that represents the mobile industry, through a process of “responsible disclosure.” On Aug. 1, he plans to present the full details of his research at the Black Hat conference, a computer hackers’ gathering, in Las Vegas.

In a statement, a GSM Association spokeswoman, Claire Cranton, said Mr. Nohl had sent the association outlines of his study, which the organization had passed along to operators and to makers of SIM cards that still relied on the older encryption standard.

“We have been able to consider the implications and provide guidance to those network operators and SIM vendors that may be impacted,” Ms. Cranton said. She added that it was likely only a minority of phones using the older standard “could be vulnerable.”

Ms. Cranton declined to comment on Mr. Nohl’s estimate that 750 million cellphones might be open to attack, saying the association would not comment until it had reviewed Mr. Nohl’s full research findings in Las Vegas. A large maker of SIM cards, the Dutch company Gemalto, said the GSM Association had told it of Mr. Nohl’s preliminary findings. A second maker of SIM cards, the German company Giesecke & Devrient, said it had “analyzed this attack scenario.”

Gemalto has been working closely with the association and other industry groups “to look into the first outline given by Mr. Nohl,” Gemalto said in a statement. The company said the GSM Association had already disseminated Mr. Nohl’s findings to group members.

Mr. Nohl was able to derive the SIM card’s digital key by sending an SMS disguised as having been sent from the mobile operator. Carriers routinely send specially coded messages to handsets to validate customers’ identities for billing and mobile transactions.

For each message, the network and the phone verify their identities by comparing digital signatures. The message sent by Mr. Nohl deliberately used a false signature for the network. In three-quarters of messages sent to mobile phones using D.E.S. encryption, the handset recognized the false signature and ended communication.

But in a quarter of cases, the phone broke off the communication and sent an error message back to Mr. Nohl that included its own encrypted digital signature. The communication provided Mr. Nohl with enough information to derive the SIM card’s digital key.

Mr. Nohl said he had advised the GSM Association and chip makers to use better filtering technology to block the kind of messages he had sent. He also advised operators to phase out SIM cards using D.E.S. encryption in favor of newer standards. He added that consumers using SIM cards more than three years old should get new cards from their carriers.

Giesecke & Devrient, in a statement, said that it had begun phasing out SIM cards using D.E.S. encryption in 2008. The German company said the unique operating system used in its SIM cards, even those running D.E.S. encryption, would prevent a phone from inadvertently sending the kind of “message authentication code” that Mr. Nohl had used to pierce the encryption.

Mr. Nohl said he was not planning to disclose the identities of the operators whose SIM cards had performed poorly in his study at the Black Hat conference in August. But he said that he planned to publish a comparative list of SIM card security by operator in December at a computer hackers’ conference in Hamburg, Germany, called the Chaos Communication Congress.

Saturday, June 29, 2013

Chinese Firm Is Charged in Theft of Turbine Software

The indictment by a federal grand jury in Madison, Wis., outlined actions that the Chinese firm, Sinovel, took against AMSC, formerly the American Superconductor Corporation, and represents the latest skirmish in a series of trade disputes between the United States and China involving renewable energy.

AMSC said the theft in 2011 led to the loss of 500 jobs and cited the damages as lost sales and trade secrets.

The two Chinese executives are in China, and the former employee, who was working for AMSC in Austria, has returned home to Serbia, according to John W. Vaudreuil, the United States attorney. He said that the United States did not have extradition treaties with either nation, but the accused could be arrested if they traveled to a country with which the United States does have an extradition treaty.

Sinovel will face a trial here, he said, and could face fines equal to twice the damages, plus restitution to AMSC.

The employee, Dejan Karabasevic, 40, served a brief prison term in Austria related to the case, Mr. Vaudreuil said. According to the indictment, after Mr. Karabasevic quit AMSC, he was offered a lucrative contract to work for a Chinese turbine blade factory, apparently to disguise the nature of the payment to him.

The indictment is a small vindication for AMSC, which has been pursuing claims against Sinovel, a former customer, in China. AMSC says that after Sinovel stole the software, it refused delivery of merchandise it had ordered, worth more than $700 million. It is seeking $70 million in arbitration in that case. It is also suing in China for $450 million for infringement of trade secrets.

Matthew J. Jacobs, a lawyer at Vinson & Elkins, which represents Sinovel, said that he had no immediate comment. When AMSC filed for arbitration in Beijing, Sinovel filed a counterclaim for $58 million, accusing it of breach of contract.

The indictment named the executives as Su Liying, 36, deputy director of research and development at Sinovel, and Zhao Haichun, 33, a technology manager. It also says that Sinovel even exported to the Boston area a computer with stolen software that had been paid for with stimulus money.

In response to the indictment, AMSC asked the Obama administration and Congress to “re-evaluate the U.S. trade relationship with China.”

Daniel P. McGahn, the president and chief executive, said in a statement, “We have worked with law enforcement to verify that these Sinovel-manufactured wind turbines contain AMSC’s stolen intellectual property.”

“The fact that Sinovel has exported stolen American intellectual property from China back into the United States — less than 40 miles from our global headquarters — shows not only a blatant disrespect for intellectual property but a disregard for international trade law,” he said.

Saturday, June 15, 2013

Bits Blog: Smartphone Makers Pressed to Address Growing Theft Problem

George Gascón, San Francisco's district attorney, center, along with Attorney General Eric T. Schneiderman of New York, second from right, at a press conference Thursday to announce the formation of the Secure Our Smartphones initiative.Bebeto Matthews/Associated Press George Gascón, San Francisco’s district attorney, center, along with Attorney General Eric T. Schneiderman of New York, second from right, at a press conference Thursday to announce the formation of the Secure Our Smartphones initiative.

1:16 p.m. | Updated This post was changed to include the name of the company that estimated the total cost of cellphone theft.

Seeking to curb a nationwide increase in smartphone thefts, New York’s attorney general and San Francisco’s district attorney on Thursday announced an initiative to push the industry to develop technologies that will discourage theft and dry up the market for stolen devices.

The new group, the Secure Our Smartphones Initiative, will include prosecutors, political officials, law enforcement and consumer advocates from over a dozen states. The co-chairmen will be the New York attorney general, Eric T. Schneiderman, and the San Francisco district attorney, George Gascón.

Mr. Gascón and Mr. Schneiderman were scheduled to meet Thursday afternoon with representatives from Apple, Samsung, Google’s Motorola unit and Microsoft, which have about 90 percent of the smartphone market.

“It is totally unacceptable that we have an epidemic of crime that we believe can be eliminated if the technological fixes that we believe are available are put into place,” Mr. Schneiderman said.

The coalition is encouraging manufacturers to equip all smartphones with a “kill switch.” When consumers reported to providers that their cellphone had been stolen, the phone, like a stolen credit card, would be rendered inoperable.

“For the thieves who would steal them,” Mr. Schneiderman said, the phones would be “nothing more than a paperweight.”

The loss and theft of cellphones cost consumers over $30 billion in 2012, according to a recent study by Lookout, a San Francisco mobile security company. About 113 smartphones are lost or stolen each minute in the United States and, according to the Federal Communications Commission, cellphone thefts account for 30 to 40 percent of all robberies nationwide. In New York City, the thefts increased 40 percent last year alone.

“The industry has the moral and the social obligation to fix this problem,” Mr. Gascón said. “There are very few things that can be fixed with a technological solution, and this is one of them.”

Apple said on Monday that its next mobile operating system, iOS7, to be released in the fall, has a new feature called Activation Lock that will help to thwart theft. An Apple representative was not immediately available to comment.

Though he did not specify how the coalition would make manufacturers comply with its demands, Mr. Schneiderman said, “The stakes here are very high and we intend to pursue this with every tool in our toolbox.”

Sunday, March 31, 2013

Survey Details Data Theft Concerns for U.S. Firms in China

BEIJING — A quarter of companies that are members of a leading U.S. business lobby in China have been victims of data theft, a report by the group said Friday, as ties between Beijing and Washington have become increasingly strained over the threat of cyberattacks.

Twenty-six percent of the members who responded to an annual survey said that their proprietary data or trade secrets had been compromised or stolen at their China operations, according to the report from the business lobby, the American Chamber of Commerce in China.

“This poses a substantial obstacle for business in China, especially when considered alongside the concerns over I.P.R. enforcement and de facto technology transfer requirements,” the chamber said, referring to weak enforcement of intellectual property rights.

Mandiant, a U.S. computer security company, said in February that a secretive Chinese military unit was likely behind a series of hacking attacks that targeted the United States and stole data from more than 100 companies.

That set off a war of words between Washington and Beijing.

Representative Dutch Ruppersberger, Democrat of Maryland, said last month that U.S. companies had suffered estimated losses in 2012 of more than $300 billion due to the theft of trade secrets, much of it the result of Chinese hacking.

China says the accusations lack proof and that it is also a victim of hacking attacks, more than half of which originate from the United States.

Hong Lei, a spokesman for the Chinese Foreign Ministry, called the survey a “completely irresponsible action.”

“We hope the relevant side doesn’t politicize financial and trade problems, does not exaggerate the so-called issue of online leaks and does more conducive things for China and the United States,” Mr. Hong told reporters Friday.

The survey by the chamber, commonly known as AmCham, was conducted among 325 members across China late last year, before the release of the Mandiant report.

Only 10 percent of companies in the survey said they would use China-based cloud computing services, with most citing security concerns. Blocked Internet searches in China had impeded business for 62 percent of respondents.

U.S. officials have pressed China to address Internet attacks and cyberspying against U.S. companies. President Barack Obama raised hacking concerns in a phone call with President Xi Jinping of China earlier in March.

A recent assessment by U.S. intelligence leaders said that for the first time, cyberattacks and cyberespionage had supplanted terrorism as the top threat.

Most companies in the AmCham survey expressed optimism about the business outlook in China, with many reporting higher profit margins for their China units. But companies gave lower expectations for future investment and cited rising labor costs as a top concern. Perceptions that China’s investment environment is stagnating are increasing, according to the survey.

Member companies “have not felt over the last four or five years that there have been commercially significant positive changes in the business environment or the investment environment,” Christian Murck, president of AmCham China, told reporters.

“When you have an economy which is making a transition to a market economy, but which is not yet there, there is a feeling that if you are not moving forward with an indicated path of future policy that you are effectively moving backward,” he said at a briefing on the survey.

The survey also cited a steep increase in concerns over the protection of intellectual property, like copyrights and trademarks, with 72 percent of respondents saying enforcement in China was ineffective or totally ineffective, an increase of 13 percentage points over last year.

Perceptions that technology transfer was increasingly a requirement for access to China’s market also jumped 10 points to 37 percent, the chamber said, with higher rates of concern reported in the aerospace, automotive, chemical in information technology sectors.

Sunday, August 5, 2012

Grand Theft Auto V Making 'Substantial Progress'

Rockstar parent company Take-Two has provided a brief status update about Grand Theft Auto V. During the company’s first quarter fiscal 2013 earnings call today, CEO Strauss Zelnick commented that Grand Theft Auto V is in “full development” and that Rockstar has made “substantial progress” on the game’s “vast, detailed open world setting.”


Beyond that, Zelnick was coy about Grand Theft Auto V’s release date, which continues to show as "TBA" on Take-Two's release calendar. Zelnick commented “we can't talk about the credibility of a release date that we haven't announced” when asked about various reports about the game’s timing. After a question regarding how often Take-Two communicates with Rockstar about the game’s status, Zelnick simply said he “wouldn't talk publicly about the way we communicate with our teams internally” and noted that Take-Two is “blessed” to be in business with Rockstar. “We have the best creative teams in the business across our company,” he added.



Grand Theft Auto V seemed to be the focus of much of the call’s Q&A session, but one question also revolved around Agent, which, aside from a few screenshots, hasn’t been seen since it was originally announced in 2009. “We haven’t announced anything about the title yet” was Zelnick’s only comment.


Overall, Take-Two referred to the first quarter of its 2013 fiscal year as below expectations, largely pointing to lower than expected sales of Max Payne 3 (which has shipped three million units worldwide) and Spec Ops: The Line. The company earned $226.1 million for the quarter -- down $108.3 million compared to the same quarter last year -- and reported a $110.8 million loss, more than $100 million over last year’s first quarter loss of $8.6 million. “Consumers at this stage in the hardware cycle are more selective than ever,” Zelnick said. “Our teams are already trying to do groundbreaking work. Sometimes we succeed, sometimes we succeed mightily. Occasionally we are disappointed. We’d like that to be even less occasionally.”


Take-Two is investing heavily in digitally-delivered content, including mobile games and downloads. 14% of Take-Two revenue this quarter came from downloaded content, including Civilization V’s recent Gods and Kings expansion and Max Payne Mobile. A free multiplayer add-on for Max Payne 3 was announced, as well as online launches including an open beta for NBA 2K13 in China, Comedy Central’s Indecision Game for mobile and NBA 2K All Stars for the GREE platform. Catalog sales were up 50% compared to last year, including successes like Grand Theft Auto III 10th Anniversary Edition and Red Dead Redemption.



Take-Two expects this fiscal year “to be one of the best years in Take-Two's history,” projecting between $1.7 and $1.8 billion in revenue. 55% of that total is expected to come from Rockstar, with the remaining 45% coming from 2K titles. 2K’s upcoming release slate includes Borderlands 2 in September, followed by NBA 2K13 and XCOM: Enemy Unknown in October. First-person shooter XCOM is scheduled for fiscal 2014 (meaning it will arrive between April 2013 and March 2014) and BioShock Infinite is scheduled for February 2013. Take-Two also hinted at additional titles that have yet to be announced.


Take-Two noted that Borderlands 2 has some of the highest pre-order numbers in the company’s history, behind only Grand Theft Auto IV and Grand Theft Auto: San Andreas. "Consumer anticipation is phenomenal," chief operating officer Karl Slatoff commented.