Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Tuesday, May 7, 2019

Shut down Apps?


The thought for this blog post started with the idea of security regarding remaining logged in to mobile apps. The question being does that open any doors for hackers to access data on either other apps or your phone? It ended up going down quite a rabbit hole of security and hacking techniques that only go to show that cybercrime and security is ever-present and evolving.

Cross-Site Request Forgery (CSRF) has been a known vulnerability since 2001. According to The Open Web Application Security Project CSRF is defined as:
A type of attack that occurs when a malicious web site, email, blog, instant message, or program causes a user’s web browser to perform an unwanted action on a trusted site when the user is authenticated. A CSRF attack works because browser requests automatically include any credentials associated with the site, such as the user’s session cookie, IP address, etc. Therefore, if the user is authenticated to the site, the site cannot distinguish between the forged or legitimate request sent by the victim. 

If you are logged in to sites and the cybercriminal can get you to visit one of their web sites or open an infected email or IM they then can make your browser send requests to the other sites posing as you. Thus, gaining access to whatever you have open. This kind of attack generally only occurs within the same browser. In other words, having clicked on a malicious site the attack could flow across any other sites you have open within that browser. Not jump to another browser say Safari to Firefox. An open browser could not transfer the attack to an open app as the two store their own credentials or cookies and do not share. The same goes for apps themselves. They store their own data. The malware would need a conduit to access other apps or your phone.

Heck of an opening to a business blog. Why do you need to know this? It is why it is important to log out of company websites and software either on your desktop or your mobile.

Developing security

Over the years sites and apps have become more security conscious. Shutting down your logon after a period of non-activity and/or making you log in every time. Sometimes a pain to log back in but it’s for your own security. With the addition of biometric features on mobiles, even the pizza ordering apps require a fingerprint to gain access. Games and social media apps/sites tend to keep you logged in. The term being “frictionless” because the developers want you to have easy access, at all times, to keep you engaged in their product.

We do a lot of browsing and an increasing amount on our mobile devices. Lots of times your thumbs get fat and you errantly click on the wrong thing. It doesn’t take much to click on the wrong link, even if you close it right away it may be too late. The same goes for links within emails. We get a ton of email to business accounts. It’s hard to distinguish every email between real and spam. Spam emails and links get opened. When employees are accessing company databases and files they are using those same computers to access their company email. Depending on computer use policies or adherence to the policy, employees may also be accessing their personal email accounts and browsing the web. This is when the company system becomes vulnerable to CSRF attacks and others.

Watering hole attack

It is what the name implies. A cybercriminal monitors a company’s employees to determine where they congregate, e.g.-restaurants, bars, etc. The criminal bets that one or more of the employees will access the “watering hole’s” website for menu information, reservations, etc. The criminal places malware on the establishment’s site. When an employee does visit the site the criminal then has access to the employee’s computer or phone. Any company files or databases that are open (logged in to) are now free game for the criminal.

None of this is or the precautions are new. The same security tenets we’ve heard over and over still hold true.  
Don’t open or click on suspicious emails or links in emails texts/IMs especially while logged into other accounts.
Don’t keep sites open-Logout
Change passwords frequently
Don’t use the same password for multiple sites
Don’t save passwords on your browser
Keep system security updated

I’m not a cybersecurity expert just a security conscious user. Hope that this information has been helpful.

Regarding the initial reason, I started doing this research, open mobile apps. It appears that it is OK to leave them open. Again most security conscientious apps like financial will time out and require login. So a criminal gaining access to your phone and then entering your bank account through your bank app is probably low.

Most risks to mobile apps occur at the server level or through poor app development, not actions by the user. Although using public WiFi (Wifi for dummies) is one of the biggest user faults to app security.
Research for the blog revealed information debunking an iPhone myth. Quitting apps does not help save battery life. The iPhone OS is designed for multitasking and places the app in suspension until needed. Closing and reopening the app actually causes the phone to use more power as it is starting the app from scratch. So keeping open frequently used apps doesn’t affect battery life.

Please feel free to share. Check the archives for other posts about privacy and online security.
Are you being watched? February 2018
Keys to the vault August 2015
There’s been a breach February 2015



Monday, January 21, 2019

Locking down the Internet of Things

WiFi security on the Internet of Things
Have you gotten all of your new tech gadgets hooked up after Christmas? Seems like every gift that had a plug also had a phone app and connected to Wi-Fi. Throughout the year as new toys or even appliances enter your home, setting up individual devices isn’t that noticeable. But after Christmas rolls through and you start setting up all the new goodies it really makes you sit back and notice-You have entered the new age of a smart home. Without realizing it we have created our own attachment to the Internet of Things (IoT).

That's a lot of things

Leichtman Research Group in 2018 found that 74% of U.S. homes had at least one smart device. Statista estimates that there will be 42.2 million smart homes in 2019. Spending on IoT devices was $23.3 billion (yes, billion) and is estimated to be $75 billion by 2025.  While there are Bluetooth connections, the primary connection for IoTs is Wi-Fi. Statista reported that the average number of connected devices per person, worldwide, in 2015 was 3.47 and is estimated to be 6.58 by 2020. That is connected devices per person. Multiply that by people in your home and the for-the-common-good devices like appliances, cameras, plugs, bulbs, etc, and that’s a lot of connectivity. 

If you want to keep up with technology it is how it’s going to be. I didn’t set out to convert the ol’ analog home to “smart”. It just happened. Garage door opener, a new appliance here and there, TVs, Hey Google, Hey Siri, Alexa, before you know it you’re your home is smart. The router sent me a message, yes it communicates as well, that the network was getting full. You’re aware of connectivity for your phones and computers but forget about the other electronics-appliances/TVs/cameras/power strips/gaming systems/eBooks, etc-that are on all the time and trying to communicate with the mother ship. Not only are these devices taxing on your home network they are all portals for security breaches.

Anyone of these connected devices can be hacked at the source, through the controlling app, or the company that provides the service. All the more reason to review your home network security.  If you haven’t done so recently, with the onset of all your new tech wonderness, you’ll need to upgrade your Internet service.  Most times these types of upgrades come with new routers. 

Security

One of the first actions you should take on all routers and new devices is set up your own logins and passwords. Many people still use the default settings, which cybercriminals are aware. Changing this information will at least slow them down. I say slow down because, as we’ve seen, anyone can be hacked. At least changing the settings will offer some protection.

For all of your connected devices actually, read the setup instructions and pay attention to what you are agreeing to during the process. Data collection is big business and those companies want your data. As consumers get more privacy savvy the product providers are finding counteractions. I recently loaded an app that wanted access to my phone’s camera, microphone, location, and to send user data. Answering no to any of those requests denied the user access. Or sometimes certain features are denied or dampened if the user doesn’t agree to the terms.

Devices that listen, your phone, TV, Echo, Google home, are also collecting data and have been proven to also be recording your conversations. In the interest of improving their service, of course. Again, go through the setup and privacy menus carefully. Understand what the device, i.e.-manufacturer is asking you to allow.

Overall, you have to understand that if you allow “smart” devices into your home you are giving up privacy. It’s hard not to get caught up in the technology craze, but understand that what you’re getting yourself into.

Please see the blog archive for other posts relating to privacy.

Tuesday, February 6, 2018

Are you being watched?


Do you feel safe in your home? Your exterior is probably pretty well defended against intruders with metal doors and deadbolts, locking windows, and maybe an alarm system. How about intruders from within?  “…The call is coming from inside the house”, an oft repeated quote from the 1979 movie, When a Stranger Calls, can still make your skin crawl when you’re all alone, think you heard a noise, and then the phone rings. Just the thought of an intruder with you in your home can be terrifying. There may not be physical intruders inside your home at this moment, but someone may be listening or quite possibly watching.

Internet of things

Kevin Ashton of Procter & Gamble first coined “Internet of things” in 1999. It is defined as network of devices, appliances, vehicles, etc. that connect and exchange data through the Internet. It is estimated the Internet of things will be populated with 30 billion devices by 2020.

Technology has always invaded our homes as we excitedly open the boxes to the latest modern conveniences. In the early days of the 1900’s telephones began appearing in homes. The 1950’s saw televisions showing up in living rooms. People started bringing home desktop computers in the 1980’s. Those computers were connected to the Internet in the 1990’s.  Phones went on our belts and into our pockets in the 2000’s and then became handheld computers. The first Internet connected appliance was a LG refrigerator released in 2000. According to Statista.com, there were nearly 36 million smart home devices sold in the U.S. in 2017. Over 40 million smart TV’s were sold in the U.S. in 2016 and 244 million worldwide.

Privacy

The remote accessibility of household devices creates new security issues everyday. As appliances get “smarter” their vulnerability also increases. Smart devices only work to their full capability if they are connected to the Internet. Once that occurs they are searchable and hackable. When the device reaches out to the web it declares itself open for business. Hackers are always looking for unsecure networks and devices to exploit. If not for gain then just because then can.

We first heard about these types of intrusions in 2015 two years after consumers starting bringing home smart TV’s.  Samsung released TV’s in 2013 that could listen to voice commands from their owners. The problem? The TV has to be listening all the time to pick up the commands. What was “heard” was being transmitted via the Internet. Samsung warned consumers, through privacy policies, that spoken words are being captured and transmitted through the voice recognition system. Consumers were further warned not to hold personal conversations in front of the television. But who read or reads the privacy policies, right?

Another popular device entering our homes are web accessible cameras. We set these up to watch the nanny, housekeeper, or house in general. There are even petcams available that not only allow owners to watch their pets but speak to them and deliver treats remotely. The first cameras imbedded in teddy bears, sold as a “nanny cams”, began appearing on the market in 1992. The first cameras to transmit remotely via IP were sold by Axis Communications in 1996. Today, the market is flooded with cameras and phone apps that allow web transmission of live video. It’s fun to watch Mr. Snugglekins romp around the house. But if you can access your webcam remotely, so can someone else.

Hacking

The device most people have heard stories about and are aware is the camera on your computer. Yes, they can be used against you. Unlike the movies, your home computer usually has to be “infected” with malware that you allowed in my clicking on a link or visiting a sketchy website. As with all of your devices, locally, you have to let someone in for them to be monitored. Not to say that you and your devices could not be specifically targeted and intruded. With the effort it could be done. Hackers and, yes, governments have the capability to access the television microphones, computer and remote cameras, turning them on and off and recording at will. However, most likely you’ve been the victim of malware.

The privacy and security issue with smart appliances is the collection and transmission of data. First, your viewing habits, conversations, actions are being collected. Second, the data is being transmitted to the Internet and held on third party servers. All of which can be hacked. So no matter the security measures you take at home, your personal data is vulnerable once it hits the WWW.

The thing is, you allow them into your home with the purchase, unpacking, and setup to connect to your network. Data transmissions you are unaware of because you have most likely allowed the device to set itself up per the manufacturer’s settings. Any warning or setup recommendations were clicked through and unread. Admit it. You’ve done it. Who reads the privacy settings on a new device? Or whenever you allow an update? That’s what the manufacturers are counting on. The key word in the previous paragraph is “allow”. You’re inviting the snooping by purchasing the device, bringing it into your home, and allowing self setup.

Your appliances aren’t the only ones listening. There’s been conspiracies floated the last couple of years that Facebook is listening to your conversations to better target ads. While feasible it is unlikely and has been debunked by several sources. Facebook may not be overhearing conversations but they, as is Google, “listening” by recording your search habits and even communications in messaging and emails apps to better address advertising. Netflix was recently caught by tweeting about the number of times a few viewers had watched one of its programs, trying to be funny. Netflix admitted that it did track viewing habits of subscribers.

Security

When you invite smart appliances into your home you give up your privacy. You have to consider these devices as other persons and guard your privacy accordingly. Take the time to read the manufacturer privacy policies. Read the manual setup instructions and adjust the device settings accordingly. Block cameras in sensitive areas or turn them towards the wall when you’re home.

This reads like an Orwellian or tinfoil hat conspiracy. It wasn’t meant to be or to keep you from enjoying the conveniences of technology. Just be aware of the surroundings you’ve created. Any smart device has to be considered to be listening or watching. Alexa, Siri, Google, they all have to be listening all the time to be able to pick up your commands.

Please feel free to share. Read other posts about security in the blog archive.

Wednesday, July 26, 2017

Employee implants



In 1985, Dr. Hannis Stoddard invented an injectable microchip based pet recovery system. In the last decade Hollywood picked up on the theme by injecting humans with microchips. Who knows what goes on in the secret world of the military and espionage? This week a Wisconsin company made the news when it announced that employees had been offered microchip implants to use as a method for building access and food purchases. This is something that’s happening and is going to change the workplace.

What are Microchips?

Microchips are rice-sized radio frequency identification devices that use passive Near Field Communication (NFC) technology to transmit data when held a few inches away from readers. Passive meaning that the microchips hold data that the reader recognizes but the devices cannot receive data. The devices were popularized in the 1990’s for recovery use in pets, being injected under the skin in the neck/shoulder area.

The technology was tested for office uses in 1998 when British scientist Kevin Warwick experimented with microchip implants to open doors, and switch on lights. The technology has been experimented with since that time for commercial and medical uses with little success or popularity.

In January 2015, the Swedish company Epicenter began offering voluntary implants to its employees. The chips are used as a replacement for magnetic key cards to access secure areas and for use as payment in company stores. For human use in this manner, the microchip is inserted in the fleshy area between the thumb and forefinger. Three Square Market, a Wisconsin technology company, have partnered with the same Swedish company who conducted the inserts for Epicenter and plans on using the technology in the same manner.  This is the first time the technology has been used in a broad setting tagging workers.

Microchipping issues

All new technology brings concerns of privacy and security, which begets legal debate and regulation. In this instance the technology also raises religious concerns.

According the National Conference of State Legislatures, nineteen states have some law referencing microchipping. Five of those states (California, Missouri, North Dakota, Oklahoma, Wisconsin) have specific laws prohibiting the mandatory implantation of microchips. Some states currently use tag/bracelet based RFID technology to track prisoners. After some recent high profile escapes there has been legislative debate to use tracking implants on prisoners.

Mark Gasson is a British scientist who is a proponent of enhancing humans through the use of implanted technology. In 2009, Gasson inserted a microchip into his own hand and went on to demonstrate that not only could the device be hacked but could receive a computer virus. This and other experiments raise security concerns. Implanted microchips have the potential to store personal and health data. As with any data storage device, the implants would have to be protected against hacking.

Wearable technology is not new to the workplace. Watch like and other devices are used to track employees throughout their day. The November 2016 post, Employee monitoring, gave an overview of wearable tech in the workplace. The concerns raised were legality of employer access to health data as well as monitoring outside of the workplace. With implanted devices the concerns are the same except in this instance the employee cannot be separated from the monitoring device.

Another issue is of a religious concern. Christians believing that this type of technology is another step closer to the writings in the book of Revelation. The EEOC has ruled in favor of Christian employees in past cases where a company has implemented fingerprint scanning.

The few people I've spoken to have said no way. The Swedish company, Epicenter, has parties celebrating an employee's decision to be implanted. The Wisconsin company, Three Square Market, already has fifty employees agreeing to the implants.

Employers considering this or any type of employee tracking devices should do considerable research. Definitely work with an attorney to develop policies and updates to employee handbooks.
Technology is ever changing our world. Whenever any new piece of technology or approach to employee monitoring is introduced there will be legal issues. How the devices are deployed, what they are used for, how data is collected and stored, and what the data is used for will all present legal challenges.

George Orwell is probably very happy.

Read other posts regarding employee monitoring and privacy. Please feel free to share and like.
Employee monitoring November 2016

Monday, April 24, 2017

Teach your employees well


Small business hacking is becoming more prevalent. The payoff isn’t as big but the opportunity is greater and security is lacking. Security firm Symantec reported in 2016 that 43% of cyber attacks were against small business. Small businesses have little in the way of security and employee training. They often have more to lose in the sense that they have less cash flow or all of their money is tied up in their business. Making them more likely to pay ransoms. (Ransomware is explained in more detail in our post-If you ever want to see your files again…)

Attacks can be as simple as rerouting the web address to a porn site, locking all of the computers for a ransom, all the way to hacking financial data and cleaning out bank accounts. More than half of the companies attacked were forced to go out of business. Maintaining sound computer security cannot be emphasized enough.

The website Small Business Trends, in an article posted January 3, 2017, stated that 48% of attacks are caused by an employee error. In addition to updating security software one of the biggest defenses owners can deploy is educating their employees on cyber attack indicators. The malware has to enter the system somehow. Simply clicking on attachments will send the virus into the network to do its work. The more stealthy viruses will enter the system without a show of existence. These are meant to mine data from the system. By the time you find the virus the bank accounts are fleeced.

Regularly train employees on different types of attacks and how to defend against them. Establish a policy for computer usage. Explain what is acceptable Internet use. Malware can be injected via email attachments or links to websites. These links can be introduced through email or social media. Demonstrate what a suspicious email, link, social media contact looks like. Practice solid password policies and change regularly. Encourage employees to speak up when something is suspicious and do not click on the suspicious activity.

Even if you do not think you store valuable data, although customer records are a valuable commodity, the chance of losing your business data or risking a financial attack is too great a chance to take.

See our blog archive for other posts relating to cyber security:



Monday, August 8, 2016

If you ever want to see your files again…





One computer in the office has a warning that it is being held ransom, “Provide 500 bitcoins to unlock the system”, is the message emblazoned on the screen. Any computer that requested data from the original would fall prey to the malware, which is now spreading through the office. The IT department had already been notified and the tech is running through the office unplugging data cables trying to isolate the attack.  No, this isn’t a mega corporation. It was a less than 100 employee accounting firm.

An automotive service center with less than 20 employees had a similar experience. The office manager starts the computers for the day and she sees a message that her computer has been locked. Pay up if you want the decryption key. An ordinary Joe is surfing the net when a warning appears on his monitor that all of his photographs have been encrypted. If he wants to have access ever again, he’ll need to pay $1200.

Ransomware has been in the news lately. More than likely you’ve heard the stories of hospitals, police departments, or large corporations having their computers locked and given a price to pay to have them set free. Or the more common terminology, held for ransom.  But cybercriminals are not just targeting institutions or corporations. As security features are improved, the criminals move on to more vulnerable prey. Any size business or any person can fall victim. Yes, the bigger fish will offer a more lucrative payday, but stack enough pennies and eventually you will have a dollar.

Definition and history

Ransomware is a type of malware that infects a computer or network preventing users from accessing the system until a ransom is paid for the decrypt key. There are two kinds. The first is called “locker” which locks the user’s computer. The second and more sophisticated is called a Crytovirus, which targets specific files (Photos, personal, financial), encrypting them until a ransom is paid. Ransom payment is usually requested in the form of the electronic currency Bitcoin. (Bitcoin converts to roughly $575 U.S. dollars) Symantec estimates that over 60% of the malware detected is of the cryptovirus variety and the average ransom paid in the U.S. is $300.

The Symantec white paper, Evolution of Ransomware, August 2015, gives this chronology of ransomware appearances: The first ransomware appeared in 1989, but wasn’t that effective due in large part to the lack of the Internet. Crypto ransomware came on the scene in 2005. As each version was detected and defended against, the writers would learn from mistakes and rewrite the code to make the malware more resistant to computer security features. In 2008, the criminals began secreting the malware in the form of fake antivirus programs. The programs would appear to scan and identify problems and then ask the user for up to $100 to fix the fake problems. In 2011, cybercriminals moved away from the antivirus attacks and began completely disabling the victim’s computers. Criminals then stopped mimicking anti virus problems and jumped to directly locking the computer using a law enforcement warning style of hoax. This was so effective that law enforcement themed ransomware became quite popular between 2012 and 2014.

Like most malware, ransomware is delivered via an attachment to an email. The user clicks on the legitimate looking file and the malicious code is delivered. However, as users became savvier to suspicious emails and clicking on attachments, malware developers have learned to hide their code in websites. Either bogus sites setup for the purpose of delivering malware or within legitimate sites. Once the malware infects a computer it begins encrypting files. If the infected computer is attached to a network the malware spreads as that computer interacts with the network.

On the FBI website, FBI Cyber Division Assistant Director James Trainor writes, “These criminals have evolved over time and now bypass the need for an individual to click on a link. They do this by seeding legitimate websites with malicious code, taking advantage of unpatched software on end-user computers.”

Who is vulnerable?

Institutions, government agencies, big or small business, even personal computers can be targeted or infected. Some attacks are targeted and some are just malware creator’s phishing for victims.  For most small business and individuals it is the latter. Anyone or any business can be victimized. As with identity fraud it is not a matter of if but when. The world is so electronically social that malware gets passed around like a rhinovirus. Eventually, someone close to you will be victimized or you yourself.

Smaller businesses and individuals are more susceptible due to a lack of computer knowledge and access to technical support. They also lack an effective backup system. Files being held ransom or the threat of a fake criminal charge coupled with the lack of technical support make personal computers users more likely to pay.

The FBI, Internet Crime Complaint Center (IC3) reports that while companies and organizations are the primary targets, the IC3 continues to receive reports from individuals. According to reports to the IC3, most individuals are told that their personal/financial information or photos will be publicly released if a bitcoin ransom is not paid within a certain timeframe. Ransom amounts range from $250 to $1,200.

Prevention

For business and individuals alike one of the main defenses is education. Know what the dangers are and be prepared. Businesses need to educate their employees on the tactics of cyber criminals and how to react if they feel they have been victims. After providing education and training, some companies will send their own “suspicious” emails to employees. The emails will look legit enough with the guise of signing up for training or providing personal information for system updates. However, each email will have the telltale signs of phishing that was thoroughly explained to employees. The IT department will monitor how many fall for the trick and how many reported it. Then they will provide further training and education to the employees.

The FBI confirms that ransomware has been around for several years. But there was an increase in 2015 with incidents still on the rise in 2016 due to lack of preparedness and protection. The FBI doesn’t support paying a ransom. Cyber Division Assistant Director James Trainor said, “Paying a ransom doesn’t guarantee an organization that it will get its data back—we’ve seen cases where organizations never got a decryption key after having paid the ransom. Paying a ransom not only emboldens current cyber criminals to target more organizations, it also offers an incentive for other criminals to get involved in this type of illegal activity. And finally, by paying a ransom, an organization might inadvertently be funding other illicit activity associated with criminals.”

What the FBI does recommend is prevention and a business continuity plan. The FBI website offers the below tips for businesses and individuals when dealing with a ransomware threat:

Prevention Efforts
  •  Make sure employees are aware of ransomware and of their critical roles in protecting the organization’s data.
  • Patch operating system, software, and firmware on digital devices (which may be made easier through a centralized patch management system).
  • Ensure antivirus and anti-malware solutions are set to automatically update and conduct regular scans.
  • Manage the use of privileged accounts—no users should be assigned administrative access unless absolutely needed, and only use administrator accounts when necessary.
  • Configure access controls, including file, directory, and network share permissions appropriately. If users only need read specific information, they don’t need write-access to those files or directories.Disable macro scripts from office files transmitted over e-mail. Implement software restriction policies or other controls to prevent programs from executing from common ransomware locations (e.g., temporary folders supporting popular Internet browsers, compression/decompression programs).

Business Continuity Efforts
  • Back up data regularly and verify the integrity of those backups regularly.
  • Secure your backups. Make sure they aren’t connected to the computers and networks they are backing up.

At the very least, educate your employees and have a conversation with whoever manages your computer system. At home, resist the urge to fall for “click bait” and pay attention to where you’re surfing. As for your smartphone? Don’t be lulled into a false sense of security. Your phone is a connected device. Someone, somewhere is figuring out a way to get in.

See our blog archive for other posts relating to security issues:

Thursday, August 27, 2015

Keys to the vault


iPhone®s have a feature that enable users to share files via Bluetooth®. You simply activate Bluetooth® on your phone and search for the other person’s phone signal. Rather than send several emails or texts with photos it is simple file transfer. We successfully completed this method of file sharing in a public setting. Very simple and convenient. What was noted was the number of open Bluetooth® connections that were also within range. This is like walking around with your purse wide open or leaving your car keys in the door lock.

Bluetooth® use developed slowly, but once other technology caught up it’s use exploded. Bluetooth® was developed in the early 1990’s. It wasn’t until 2000 that the first mobile phone with Bluetooth® technology came to market. In 2001, laptops and peripherals (printer, ear pieces, car kits) came to market. The next several years produced everyday items that could connect via Bluetooth®, such as TVs, glasses, watches, and appliances. Around 2005 is when Bluetooth® became a popular feature on phones. After Smartphone’s took off in 2007, it became a standard feature and every year since more uses between phones and other devices have been released.

Hacking into Bluetooth began almost as soon as it became widely available on phones. Once consumers began using their phones for more financial exchanges and social media hackers seized on the opportunity to exploit users lack of knowledge in regards to security and Bluetooth® connections. Most phones at startup activate the Bluetooth® feature. The user has to purposely turn off the connection. However, few do, either because they are unaware or actually use features such as earpieces or car connections. When not using the devices users leave their phones in the discoverable mode.

Hacking exposure

As with Wi-Fi, hackers love sitting in public places scanning for phone signals in public places. They setup shop in common, high traffic (use) areas by sending an open Wi-Fi signal or intercepting Bluetooth® connections between phones and peripherals. Bluebugging is a term to describe identity theft by hacking access to mobile commands on Bluetooth®-enabled devices that are in discoverable mode. Your phone is tricked into thinking that it is connected to the peripheral when it is actually connected to the hacker’s device. Once intercepted the hacker can take control of the device and/or retrieve data.

In July 2015, hackers successfully hacked into the system of a Jeep Liberty, taking control of the vehicle’s comfort, operational, and safety systems too include braking. This was done purposely to prove the vulnerability to automakers. But if one person figured it out you can be sure there is a long line of others.

As of this writing, research revealed there was little data regarding the number of Smartphones or personal accounts used on Smartphones that are hacked. It is doubtful that the lack of data is due to a low occurrence, but rather lack of realization, little reporting and/or notice by the media. You may occasionally see a flip phone or non-Smartphone but these types of phones are becoming rare. Many carriers do not offer these types of phones. There are an estimated 183 million Smartphone users in the U.S. alone, 2 billion worldwide. Next time you’re in public take a moment to look around and let it sink in how people around you have phones. Probably safe to say everyone.

New target

Just as your home computer  became vulnerable in the 1990’s, your phone is now the target. Only with your home computer you almost have to invite the hacker in through malware or ill advised website visit. Your phone on the other hand is with you all the time exposing it’s signals to the public wherever you go.

Most times you won’t even realize that your phone has been hacked. Not until strange social media posts surprise you or you notice withdrawals from your bank account. You home computer will get a virus. You’re email account will be hacked. Your credit card information will be stolen. And growing every year, someone will be kind enough to file your taxes for you, for the small fee of receiving your refund.

Eventually your phone will be hacked.  The best you can do is try to limit your vulnerability by keeping the doors shut.  Limit you public broadcasting of a Bluetooth® signal and use of public Wi-Fi. Turn off your Bluetooth® when not needed. If you do use password protected accounts through public connections, change your passwords after each use. Watch your data usage for spikes. Constantly check your financial accounts as part of your regular security routine.