  Here's the article
  4. Times like this I'm glad I never put my number in any accounts online and I don't have these apps on my phone. It's not just Facebook as you can see. Crazy.
  7. would this work for all methods of encryption, or just weaker wifi security like WEP? this just brought up another related flaw... my cable provider offers free wifi hotspots all over the city - as does many other ISPs... the WiFi is open - no security, but until you enter your user name and password for your account you are stuck in a walled garden. sure you can store your devices MAC address to prevent you from having to log in every time, but would someone really question if they had to do it again? The problem with this method of authentication is it is extremely prone to MiTM attacks. anyone can set up an AP with the SSID that the ISP uses, and use a fake redirect page to require you to sign in. this not only grants the person running AP pretending to be from the ISP access to all of that ISPs WiFi hotspots at no cost (with activity being traced back to the account holder who he stole the credentials for) it also gives the person running the fake AP the credentials to log into that persons ISP account. I am not sure what could be done to close those security holes, but it seems that there is a risk in using these open hotspots. "...but would someone really question if they had to do it again? " I doubt it.
  10. Here's something I ran into from Bruce Scneier.............. Carrier IQ Spyware Spyware on many smart phones monitors your every action, including collecting individual keystrokes. The company that makes and runs this software on behalf of different carriers, Carrier IQ, freaked when a security researcher outed them. It initially claimed it didn't monitor keystrokes -- an easily refuted lie -- and threatened to sue the researcher. It took EFF getting involved to get the company to back down. (A good summary of the details is here. This is pretty good, too.) Carrier IQ is reacting really badly here. Threatening the researcher was a panic reaction, but I think it's still clinging to the notion that it can keep the details of what it does secret, or hide behind marketing statements and hair-splitting denials. Several things matter here: 1) what data the Carrier IQ app collects on the handset, 2) what data the Carrier IQ app routinely transmits to the carriers, and 3) what data can the Carrier IQ app transmit to the carrier if asked. Can the carrier enable the logging of everything in response to a request from the FBI? We have no idea. Expect this story to unfold considerably in the coming weeks. Everyone is pointing fingers of blame at everyone else, and Sen. Franken has asked the various companies involved for details. One more detail is worth mentioning. Apple announced it no longer uses Carrier IQ in iOS5. I'm sure this means that they have their own surveillance software running, not that they're no longer conducting surveillance on their users. or or or or,2817,2397156,00.asp Apple and Carrier IQ: or Excellent roundup of everything that's known about Carrier IQ:
