Pages

Showing posts with label codes. Show all posts
Showing posts with label codes. Show all posts

Sep 25, 2012

TouchWiz-specific hack can hard reset Galaxy S III and other Galaxy phones through their web browsers

Samsung Galaxy smartphones with the TouchWiz UI skin are susceptible to a USSD code hack, which triggers an unstoppable factory reset. The hack itself is easily triggered from malicious websites, QR codes or sent by NFC and wipes users’ phones immediately.

In order to successfully run onto a Samsung Galaxy smartphone, the hack must be either dialed in directly in the phones dialer or opened from a website using the stock browser.

Among the devices affected by the USSD code hack are the Galaxy S Advance, the Galaxy Ace, the Galaxy S II and the Galaxy S III. As far as we know Samsung is currently investigating the issue and is likely to come up with a fix or a statement soon.

Meanwhile, you can see the exploit in action demonstrated in the video below.

When tested on devices running pure Android or another user interface skin, the USSD code hack doesn’t do anything, so Galaxy Nexus users need not panic.


Source : blog[dot]gsmarena[dot]com

Sep 17, 2012

QR codes for tourism? Wikipedia-linked codes to guide visitors to Gibraltar

We see QR codes everywhere, though research suggests they're rarely scanned. Tourism officials in the British outpost of Gibraltar are hoping that won't be the case when it launches 'Gibraltarpedia', an initiative that will equip the territory's landmarks and places of interest with their own QR codes linked to Wikipedia pages offering more information.

We see QR codes all over the place, from magazines to posters to business cards. There’s even a cemetery in Denmark that’s using them to tell the life story of the deceased. A giant one turned up in a Canadian cornfield the other day, too.

Gibraltar, a small overseas territory of the UK located at the entrance to the Mediterranean in southwestern Europe, is also getting in on the act with its soon-to-launch Gibraltarpedia project. The plan is to plaster the place with QR codes giving smartphone-equipped tourists quick access to information about various sites and points of interest.

With 11 million visitors a year coming to the British outpost, tourist officials there are keen to find new ways of enriching their experience, and Clive Finlayson of the Gibraltar Museum thinks QR codes can go some way to help.

“Gibraltar is a multi-layered cake of historical events, starting with the Neanderthals of 50,000 years ago through to modern humans,” Finlayson told the BBC. “Here we have another way of getting all this information across to the world.”

The codes will take users to a Wikipedia page explaining about the place of interest. Volunteers are currently working hard on creating the new pages in a multitude of languages.

Roger Bamkin of Wikimedia, the charity that owns Wikipedia, is planning for the QR codes to communicate with the user’s handset to determine the language of the uploaded webpage.

“By scanning QR codes around them, tourists will be to able to find out about the place they are visiting in their own language, with the description written by a volunteer speaking that language,” Bamkin said.

Of course, it could be that many visitors, fearful of pricey roaming charges, will simply stick with a traditional printed guidebook rather than scanning codes. To get around this, the authorities are considering introducing free Wi-Fi.

Despite the good intentions of Gibraltar’s tourism office, getting visitors to use the codes may be an uphill struggle. The results of a recent comScore study showed that in July this year only 11 percent of UK smartphone owners scanned a QR code. That’s pretty dismal for a technology that’s been around almost 20 years.

Either way, the codes will provide tourists visiting the territory with another option for pulling up information besides guidebooks, pamphlets and apps.

While QR codes have failed to really take off in other areas, do you think it could find its place in the tourism industry? Would you be tempted to whip out your smartphone if you saw a QR code beside a famous landmark?

[Image: Artur Bogacki / Shutterstock]


Source : digitaltrends[dot]com

Sep 11, 2012

Digital publisher BlueToad claims to be unwitting source of leaked Apple UDIDs

BlueToad, a digital publishing company, has said it was the unwitting source of last week's leaked Apple UDID codes.

The story of the Apple Unique Device Identifiers, or UDID codes, leaked by hacking group Anonymous last week, has taken another turn. This time, rather than blanket denials, someone has owned up to being the unwitting source of the codes themselves. And it’s not the FBI.

NBC reports that the database of one million UDID codes came from BlueToad, a digital publishing company based in Orlando, Florida, that has a library of nearly 150 apps — primarily niche print magazines converted over for digital use — for both the iPhone and the iPad inside the iTunes App Store.

BlueToad’s attention was drawn to the missing UDID’s by security researcher David Schuetz, who documents his sterling work uncovering the source of the leak in a blog post.

He contacted BlueToad and told them of his suspicions, and the company launched an investigation, resulting in a 98-percent correlation between BlueToad’s database and that of the leaked UDIDs.

BlueToad’s CEO, Paul DeHart said “that’s 100-percent confidence level, it’s our data.”

Subsequently, DeHart published a statement on the company’s blog, saying that “a little more than a week ago, BlueToad was the victim of a criminal cyber attack, which resulted in the theft of Apple UDIDs from our systems. Shortly thereafter, an unknown group posted these UDIDs on the Internet.”

BlueToad is now working with law enforcement agencies in the ongoing investigation into the leak. To help put its business partners and the public’s minds at ease, it says it has fixed the vulnerability that allowed the UDIDs to be stolen, and has stopped storing them inside its database. BlueToad had already followed Apple’s directive to cease reporting UDIDs from its apps.

Case closed?

It would certainly seem so, as both the FBI and Apple have stated the leak didn’t come from them, and BlueToad seems convinced it’s the source. Taken at face value this way, the story now reads that hackers affiliated with Anonymous and working under the Operation AntiSec name, stole UDIDs from BlueToad’s computers, then published them saying they came from a larger file obtained from an FBI Agent’s laptop.

Agent Christopher Stangl was implicated due to his involvement with operations against Anonymous and LulzSec, as proven by his presence during a conference call that Anonymous claimed to have eavesdropped back in March.

After all, the easiest and most logical explanation is most likely true.

However, those who don’t like to connect the dots in this way will undoubtably have alternative theories. For example, the FBI could be working with BlueToad (although we can’t imagine for what reason), or the company is taking the fall — it is after all, completely innocuous — at their behest.

Even David Schuetz isn’t convinced this is the end of the story, and questions whether BlueToad is the original source, or a secondary leak.

A member of Anonymous, seemingly unfazed by the recent developments, took to Twitter to say simply “FBI-notebook – There is still no evidence. Stay tuned.”

For now at least, we’d say the file on this one needs to remain open, but on hold.


Source : digitaltrends[dot]com

Sep 6, 2012

Apple plots the end of the UDID, denies sharing them with the FBI

Following this week's leak, Apple has denied it shared any UDID codes with the FBI, and also announced the UDID will be banned from iOS 6.

Earlier this week, notorious hacking group Anonymous announced that it had more than 12 million Apple UDID identifier codes in its possession, and to prove it, released 1,000,001 of them out into the world.

In reality, it wasn’t the fact Anonymous had the UDIDs that made the story so fascinating, but rather where they came from and how it claimed to have got them; as who doesn’t love an intrigue-filled tale of eavesdropping, phishing, hacking and the FBI?

The day after the leak, and amidst considerable press attention, the FBI made several statements, with only subtle variations between them. Ultimately though, they denied that one of its laptops containing personal information had been hacked. In fact, it was so adamant that it never happened, it took to Twitter and called the allegation “TOTALLY FALSE.” Yep, in caps, to show how seriously they were treating the leak.

Hardly a surprise, as it was unlikely the FBI would hold its hands up and admit it had been careless.

But what about Apple? It had remained quiet until it provided a statement to AllThingsD.com yesterday, where to no-one’s surprise at all, it also denied any knowledge of the missing UDIDs. The statement read “The FBI has not requested this information from Apple, nor have we provided it to the FBI or any organization.”

The end of the UDID

Shocking stuff, but what came next was far more interesting. It continued to say “Additionally, with iOS 6 we introduced a new set of APIs meant to replace the use of the UDID and will soon be banning the use of the UDID.”

This, combined with Apple’s reluctance to approve apps that use the UDID code to track devices, should minimize the threat posed by this leak, although without other pertinent information, that threat was minimal anyway.

But the crux of the story, who had these UDIDs and why, remains a mystery. Right now, taking Apple and the FBI at their word, the UDIDs didn’t come from them. If you side with Anonymous though, then you’d know this is exactly what they would say, regardless of the truth.

There’s also the possibility that the UDIDs came from either a careless, or more worryingly a willing, developer. But would many developers have 12 million UDIDs? Possibly not, but then we have only seen a million of them.

So, will the truth ever come out? Now that Gawker’s Adrian Chen has bowed to Anonymous’ bizarre request to be featured on the site wearing a tutu and a shoe on his head, perhaps more information and a new leak will come soon.


Source : digitaltrends[dot]com

Sep 4, 2012

Leaked: One million iOS device identifiers stolen from FBI laptop

hacker-keyboard

A file containing one million Apple UDID codes has been leaked, after it was allegedly stolen from an FBI agent's laptop earlier this year.

Operation AntiSec has made a return, this time leaking a file containing 1,000,001 unique device identifier numbers, or UDIDs, for Apple devices. The hackers are claiming that the data was stolen from a laptop belonging to the FBI, and that in total, it contained more than 12 million UDID numbers.

The file containing the data was accompanied by a longer than usual Pastebin post, which claims that in March, a Dell laptop belonging to “Supervisor Special Agent Christopher K. Stangl,” who works for the FBI’s Regional Cyber Action Team, was compromised using a Java vulnerability and a variety of files downloaded from it.

One was the above list of 12,367,232 UDID numbers, along with other personal data such as user names, Push Notification tokens, telephone numbers, address and the originating device.

According to the post, the personal data has been removed prior to uploading, but the UDID, notification token, device name and device type apparently remains. Forbes.com’s Andy Greenberg downloaded and decrypted the file, and found it contains a massive collection of 40-character strings, all of which could pass for Apple UDID codes.

Real UDID codes?

As you’d expect, the leak raises more questions than it answers. To whom do the UDID’s belong too, and why — presuming the information on the source is accurate — would the FBI have a single file listing 12 million of them.

While labeling its existence as proof of a conspiracy will be popular, there is an equally good chance the file is part of an investigation, or was supplied to the FBI quite innocently. There’s also the chance it didn’t come from the FBI at all, but from a developer. It’s also not the first time AntiSec has targeted Apple.

In its Pastebin text, Anonymous says that the “FBI is using your device info for a tracking people project or some sh*t,” and calls for UDID codes and similar device-identifying numbers to be “erradicated (sic) from any device on the market in the future.”

Apple’s use of UDID numbers has caused controversy in the past, with even Apple telling developers to stop tracking users using the codes. UDIDs themselves don’t carry personal data, but can be combined with other information to aid device tracking and monitoring.

Over at Hacker News, at least two contributors claim to have found UDID codes relating to their personal iOS devices. One lives in the USA and the other in the UK, but no common link between them or the apps they have installed has been established.

Interestingly, Cydia developer Jay Freeman (AKA Saurik) adds to the conversation, saying that 16.7-percent of the UDID’s in the file come from jailbroken iOS devices, according to his research.

FBI Agent

As for Special Agent Christopher Stangl, it appears he exists, which potentially adds some weight to Anonymous’ claims. There is a LinkedIn profile for someone under that name, who works for the FBI and has that job title; plus in 2009, FBI Agent Chris Stangl made a video for Cyber Security Awareness Week at NYU.

His name also appears on an FBI email list published on the Internet earlier this year, which led to hackers listening into a conference call discussing the activities of LulzSec and Anonymous. It’s speculated that these addresses were phished and led to a compromised website, where a Java vulnerability was exploited.

Anonymous has said it won’t be providing any further details, but hopes that due to the large amount of leaked information, “someone should care about it.” While we’re not expecting much from the FBI, it’ll be interesting to see if Apple provides a response.


Source : digitaltrends[dot]com

Sep 3, 2012

Graveyard tech: QR codes to bring cemeteries alive

Now here's an interesting idea: QR codes in cemeteries linked to a webpage telling the life story of the deceased.

If you own a smartphone, the chances are you’ve scanned at least one QR (Quick Response) code up to now, whether it was in a magazine, on the Web, on a poster or inside a retail store.

And if a new use for the codes being tried out in Denmark takes off, you might also find yourself scanning a QR code in a cemetery before too long.

A graveyard in the city of Roskilde has started to use the codes to help commemorate the deceased, offering more information than found on a traditional headstone. Printed on a porcelain plate and attached to a small stone, the QR codes can be found in the ground beside the headstones. Scan it with a smartphone and you’re taken to a website of the deceased showing their photo alongside a summary of their life.

Roskilde resident Dorthe Frydenlund decided to place a QR code by the grave of her father, Brent. “As a family it means a lot when you are here and feel the need to commemorate Dad,” Dorthe told the BBC.

She added, “It’s not meant as a comfort, more an opportunity for other people to learn his life story. It’s a good way for my son to remember his grandfather.”

The service costs 100 euros ($123), with not just photos and text but also audio snippets and videos included on the commemorative webpage if desired.

Niels Kristian Nielsen, director of Denmark’s largest gravestone manufacturer, thinks QR codes in cemeteries will one day be commonplace.

“It’s a good way to tell the story of a person. And we all have a story. Both the farmer, the director, they all have a story. And also it makes a visit to the graveyard much more interesting,” he said.

A church council in the Danish town of Holbaek is also looking to use the codes to help provide more information to visitors, with plans to upload the obituaries of local monks who once lived in a monastery close to the town.

“There are lots of people who are important and I think their story and what they have done with their life is important,” the council’s Hanne Korsby commented. “I think it’s very important for the next generation to have this memory.”

With little more than a date of birth and death, and possibly a heartfelt or possibly witty epitaph, the regular information-poor gravestone may soon be getting a serious makeover with the inclusion of a smartphone-ready scannable QR code.


Source : digitaltrends[dot]com