Thursday, 5 June 2014

Zero-interaction authentication: A new system that could end passwords

Zero-interaction authentication: A new system that could end passwords
                  The new system could make passwords redundant.

05 Jun 2014


Washington: Researchers, led by an Indian-origin scientist, are developing an easy-to-use, secure login protection that eliminates the need to use a password.

Researchers from the University of Alabama at Birmingham are working on a secure login protection known as zero-interaction authentication. Zero-interaction authentication enables a user to access a terminal, such as a laptop or a car, without interacting with the device.

Access is granted when the verifying system can detect the user’s security token — such as a mobile phone or a car key — using an authentication protocol over a short-range, wireless communication channel, such as Bluetooth.

It eliminates the need for a password and diminishes the security risks that accompany them. A common example of such authentication is a keyless entry and start system that unlocks a car door or starts the car engine based on the token’s proximity to the car.

However, existing zero-interaction authentication schemes are vulnerable to relay attacks, commonly referred to as ghost-and-leech attacks, in which a hacker, or ghost, succeeds in authenticating to the terminal on behalf of the user by colluding with another hacker, or leech, who is close to the user at another location.

“The goal of our research is to examine the existing security measures that zero—interaction authentication systems employ and improve them,” said Nitesh Saxena, associate professor in the Department of Computer and Information Sciences and co—leader of the Center for Information Assurance and Joint Forensics Research.

“We want to identify a mechanism that will provide increased security against relay attacks and maintain the ease of use,” said Saxena, who led the research.

The researchers examined two types of sensor modalities that could protect zero-interaction systems against relay attacks without affecting usability.

First, they examined four sensor modalities that are commonly present on devices: Wi-Fi, Bluetooth, GPS and audio. Second, they looked at the capabilities of using ambient physical sensors as a proximity-detection mechanism and focused on four: ambient temperature, precision gas, humidity and altitude.

Each of these modalities helps the authentication system verify that the two devices attempting to connect to each other are in the same location and thwart a ghost-and-leech attack.

The research, done in collaboration with the University of Helsinki and Aalto University in Finland, showed that sensor modalities, used in combination, provide added security.

“Users will be able to use an app on their phones to lock and unlock their laptops, desktops or even their cars, without passwords and without having to worry about relay attacks,” said Babins Shrestha, a UAB doctoral student and co-author on the study.


Saturday, 5 April 2014

Unearthing Facebook holes, Mark Zuckerberg company to pay hackers


 

Biggest holes that could be exploited by hackers to get an entry into the social networking plan to snoop or steal user information has been revealed.

Under the Facebook (FB) Bug Bounty program, that is aimed to evaluate FB services and report bugs, hackes around the world are reporting bugs to safeguard the social networking platform. In the year 2013 it received 14,763 submissions of which 687 were valid and were eligible for rewards says the Mark Zuckerberg company.

For the year 2014 the company is looking at encouraging the best research in the most valuable areas, and is going to continue increasing the reward amounts for high priority issues. “The volume of high-severity issues is down, and we're hearing from researchers that it's tougher to find good bugs,” says Collin Greene is a Security Engineer at Facebook.

Last year program saw India as the biggest contributor of bugs. Indian hackers contributed the largest number of valid bugs at 136, with an average reward of $1,353. USA reported 92 issues and averaged $2,272 in rewards; Russia received an average of $3,961 for 38 bugs, Brazil and the UK were third and fourth by volume, with 53 bugs and 40 bugs, respectively, and average rewards of $3,792 and $2,950.

Monday, 31 March 2014

Fastest utorrent download settings

here I will show you how to speed up your utorrent downloads, but it does only depend on your connection speed from your provider

Latest Best Port: 11136 or 14911 or 111132 or 13218 or 53906 or 54327

Keep Updated

Have a look the images bellow and enjoy fastest utorrent download speed.













Saturday, 29 March 2014

Samsung Galaxy S5 Root Method Released Before Shipping Date


Samsung Galaxy S5 release date is still nearly two weeks away but it seems that the device has already got a root method alive and kicking for at least one of its variant. It has now been confirmed that famous XDA developer, ChainFire, has been successful in rooting the SM-G900F variant (international-LTE variant) of the Galaxy S5 and that you can expect US carrier variants like Verizon, Sprint, AT&T and T-Mobile to follow soon.


ChainFire’s famous CF-Auto-Root tool which according to him has rooted “Galaxy S1, Galaxy S2, S4, S4, Galaxy Note, Note2, Note3, dozens of Tab models, etc!” and “has clocked over 22.5 million downloads” is now also available for the yet to release Samsung Galaxy S5. This script can be flashed via PC or by using Samsung’s own ODIN tool.
While he refrained from getting into the specifics to keep it simple, ChainFire says that his CF-Auto-Root tool currently flashes a temporary modified recovery and then installs the SuperSU app after which it flashes the stock recovery again. The instructions for rooting the Samsung Galaxy S5 are fairly simple and should be under the realm of every user who has even the slightest experience of rooting a Galaxy device.

Unfortunately, this root method works only for the SM-G900F variant of the Samsung Galaxy S5 since it requires a modified recovery, this method will most probably do more harm than good to the carrier models of the handset. However, you can be rest assured about your future Verizon, Sprint, AT&T or T-Mobile branded Samsung Galaxy S5 because ChainFire has already confirmed that “there’ll be a lot of models, but I believe this will be the most common ‘international’ model”.
Since Samsung Galaxy S5 still hasn’t been made available commercially, there are not many people who were able to test the root method but for what it is worth, ChainFire does say that his root tool will break Samsung’s Knox security suite.