Pages

Showing posts with label database. Show all posts
Showing posts with label database. Show all posts

Nov 1, 2012

US database for stolen phones is now live, to join the international blacklist soon

The Wireless Association (CTIA) has announced the US database for stolen phones is now up and running. In case a phone gets in there it won’t be allowed to connect to any of the US networks.

The participating carriers in the database are AT&T, Cellcom, Nex-Tech Wireless, Sprint, T-Mobile USA, and Verizon Wireless. They already deployed their IMEI databases of stolen phones and the merge should be completed within a year.

Part of the merged database is already live and when a phone pops in there – it will never get service from any of those networks. In the efforts of drying the stolen phones market this database will soon join the GSMA Global IMEI database and its blacklist. That way no phone stolen stateside will work overseas and vice versa.

This surely won’t stop the phone thefts, but will make things a lot tougher for the thieves and hopefully most of them will drop this “business” eventually.


Source : blog[dot]gsmarena[dot]com

Stolen phone database goes live, as US carriers work on stamping out mobile thefts

AT&T and T-Mobile are working together on a joint database that could help reduce mobile phone thefts. It does so by blocking the stolen phone itself, not just the SIM card, and is part of a larger, unified, national database planned for this time next year.

The plan to build a unified database containing the details of all phones reported stolen in the US took a step forward this week, as the first of its kind, managed jointly by AT&T and T-Mobile, went live.

Announced back in April this year, the Federal Communications Commission brokered a deal between the all four of the US’s major network providers, and set a deadline for October 31 to get the database up and running.

It works like this: When a phone is reported stolen, its IMEI number — unique to every phone, and not tied to the easily removed SIM card — is logged and blocked, stopping it from ever being re-connected.

As networks already block the SIM card when a phone is reported stolen, avoiding unwanted charges on the customers bill, blocking the IMEI renders the phone useless too.

This should make the theft of mobile phones less attractive to criminals, as savvy buyers should be asking for, then checking the IMEI with their carrier to make sure it’s genuine and can be re-used.

AT&T and T-Mobile have created a joint database, as they’re both GSM networks and stolen phones could be connected to either one, while Verizon and Sprint are working on their own shared database. Both currently use internal lists of stolen phones.

By this time next year, all four databases will be pooled together, and smaller carriers will also have joined the scheme. Then, it will be merged with the GSMA’s international database to help prevent stolen phones being shipped in or out of the country.

Similar schemes are already in operation all over the world, and many have been for at least a decade, with countries such as the UK and Australia even providing websites where IMEI numbers can easily be checked by members of the public.

According to one mobile security firm, speaking to the Huffington Post, it’s estimated that mobile phone thefts will cost the American consumer $30 billion this year alone, making the database scheme highly desirable.


Source : digitaltrends[dot]com

Sep 10, 2012

Minority Report alert: FBI launching $1 billion face recognition project

fbi face scanning minority report

The FBI is creating its own photo database. And you thought Facebook's face scanning system was scary.

A little over a year ago, Facebook introduced face recognition software to the masses when it included the feature in its photo uploading process. And the masses, as you may assume, didn’t react all that well. There was plenty of conspiracy theory and privacy-concerned backlash, which died down as soon as everyone started talking about how the service was opt-in only. Since then, the feature has faded into the background and taken its rightful place among other Facebook-announcements-that-cause-us-to-wield-pitchforks-for-a-week-but-then-everyone’s-over-it.

But now, concerns over consumers’ image privacy have been resurrected by a billion dollar FBI project. According to New Scientist, the Federal Bureau of Investigation is launching a $1 billion effort called the Next Generation Identification (NGI) program, which will use face detection as well as “biometrics such as iris scans, DNA analysis, and voice identification to the toolkit.” The system is already being ushered in, as some states have started uploaded images (currently it sounds as if this is limited to mugshots); it’s expected to be implemented nationwide by 2014.

As all things start, intentions are good: Such highly accurate identification systems would be used to focus on criminals faster, result in quicker arrests, and potentially stop illegal activity before it happens. Of course, all of that sounds incredibly Minority Report-ish – including this example use:

“Images of a person of interest from security cameras or publics photos uploaded onto the Internet could be compared against a national repository of images held by the FBI. An algorithm would perform an automatic search and return a list of potential hits for an office to sort through and use as possible leads for an investigation.”

While current states that have participated in the pilot program have been uploading mugshots for the NGI, it’s uncertain whether this will eventually extend to include all of our images. In fact, New Scientist pointedly asked the FBI this question and no response was given.

In case it isn’t clear enough, what we very possibly have in the works here is a national civilian photograph database. Right now, the FBI hasn’t reached that far, but it’s very easy to assume it will – and it’s all legal under the US Privacy Act.

Before you start pointing fingers at Facebook and user-facing (pun intended) face recognition software companies out there (think Face.com – now Facebook-owned – and Lambda Labs), consider the amount of state and federal operations that have your images. Your license, your passport, your public transportation ID… it goes on and on. If the government wants to harness image identification, it can and it will, and it won’t have to rely on social networks for help. That said, our increasing comfort with putting our likenesses all over the Internet is only making it easier for this type of system to be enacted. 


Source : digitaltrends[dot]com

Sep 3, 2012

Oracle scrambles to patch Java exploits

Java Logo

Oracle has issued an out-of-cycle emergency update to Java to patch critical security problems - but experts say there's more to come.

Database giant Oracle has issued an out-of-cycle emergency security update to Java that aims to patch several vulnerabilities that are being actively being exploited by cybercriminals. The update — Java Version 7 Update 7 — closes loopholes that potentially allow attackers to gain complete control of a computer over a network without a username or password; moreover, the vulnerabilities specifically apply to Java applications running in desktop Web browsers. While standalone Java applications and Java running on servers isn’t affected (and that includes Oracles own server-based software), it does mean folks who can run Java in a Web browser are vulnerable — and some estimates put that number at over a billion machines worldwide.

Oracle’s highly-unusual move to issue an out-of-cycle security update comes on the heels of the Java exploits being incorporated in the widely-used Blackhole cyberattack toolkit. Blackhole is a popular cut-and-paste exploit tool that comes pre-loaded with code designed to exploit flaws in things like Adobe Flash, Adobe Reader, and Java — it’s popular with cybercriminals who lack deep technical background because it’s relatively easy to use and is regularly updated with new exploits. Kaspersky Labs were apparently the first to report Blackhole had integrated the zero-day Java exploits; the news was quickly confirmed by security firms like Sophos and ESET.

However, the situation is more complicated. Researchers at Security Explorations claim they reported the vulnerabilities just patched by Oracle all the way back in April of 2012 — nearly six months ago. Moreover, Security Explorations claims that the latest update — Java 7 Update 7 — contains another vulnerability. If confirmed by Oracle, that means another Java update could be on the way in days — or, perhaps, in six months.

Java has been highlighted as a potentially massive security threat for years, but it’s only in 2012 that it’s jumped to the forefront of mainstream security topics, first with the Flashback malware that targeted Mac OS X systems, and now with zero-day exploits targeting desktop browsers with Java enabled.

As originally envisioned by Sun, Java was intended to be a write-once, run-anywhere language that would enable developers to write applications that could be run on any computer with a Java VM, regardless of platform. However, while Java technology has found widespread use in servers and mobile devices (the Dalvik Java virtual machine was the center of Oracle’s high-profile suit against Google over Android), the market dominance of Flash and now the ascendency of HTML5 technologies make Java on the desktop unnecessary for the vast majority of Internet users. Most security researchers recommend users uninstall or disable the Java Web plug-in in their browsers.

The current Java vulnerabilities are mostly applicable to Windows and Linux users. Most Mac users are immune from these particular Java exploits, even if they have Java installed. (Apple has not shipped Java by default with Macs for some time.) Java for OS X has not been updated to Java 7, so the only potentially-vulnerable Mac users are folks who have manually installed Java SE 7 on their own.


Source : digitaltrends[dot]com

Aug 29, 2012

Drag and drog app platform Tiggzi adds database functionality

drag and drop tiggzi

WIth an emphasis on a productivity-rich UI and its new database functionality, Tiggzi competes for app developers platform love.

There is no doubt in anyone’s mind that the app economy has uprooted how we think about the technology market. In a landscape formerly dominated by hardware titans and products that targeted the IT crowd and not the everyday consumer, the app has become not only a legitimate startup idea but the foundation of the hottest, fastest-growing industry — mobile. 

Which is why it stands to reason that there’s plenty of interest not only in developing apps but in developing tools for developing apps (say that three times fast). Apps are supposed to be inherently simple and enjoyable on the user-end — and now that’s being applied to the developer side of things as well. 

One startup attempting to infuse some ease and accessibility into this process is Tiggzi. Founded last year, the company falls under the umbrella of software engineering company Exadel, and it’s a cloud-based mobile app platform that relies on the simplest of the simplest actions for app creation: Drag and drop. 

“We started Tiggzi as a prototyping tool so that developers could create their UI,” says head of community and developer relations Max Katz. “We just realized, ‘Well we can’t go much further than just building the UI with that.’ So it grew from there.” 

With Tiggzi, you’re launched into a digital workshop where, to put this in the simplest terms possible, you drag and drop the elements you want over to the device image. You can use these functions to create iOS, Android, HTML 5, and Windows Phone apps. 

Of course, while the action itself is familiar and easy, don’t confuse Tiggzi with something you can pick up sans developer skills. “At the end of the day this is a development tool, and you’ll need to have Web development skills,” Katz says, adding that HTML, Javascript, and CSS proficiency are generally what you’ll find necessary to use Tiggzi. But these skills, combined with the action-orientation and immediacy of Tiggzi turn it into a great productivity tool for developers. 

The fact that Tiggzi is entirely cloud-based and runs in the browser with no download or install necessary is also part of its allure. 

New to Tiggzi is its database. The platform previously announced it would be adding some a backend and storage for developers’ Tiggzi-made apps. It also comes with plugins so that developers can auto plug pre-made functionalities into their apps — as an example, Katz showed me how a developer could pull and put in the AT&T sms messaging feature via the available plugin. 

“We started as just the builder, but the backend services make us a platform,” says Katz. “A lot of companies have the backend, but they don’t have the builder, but we have both. We can offer the entire stack.” 


Source : digitaltrends[dot]com