Pages

Showing posts with label hacker. Show all posts
Showing posts with label hacker. Show all posts

Oct 4, 2012

Facebook scans private messages for brand page mentions, admits a bug is boosting Likes

facebook private messages

Some suspicious Like counts suggest that Facebook is scanning private messages and hitting the Like button for its users accordingly.

This week a Hacker News post indicated that Facebook is reading our privately sent messages, scanning them for content, and Liking pages depending on said content. For instance, if you send a friend a message about the Beyonce concert that includes a corresponding link, it’s possible Facebook will go ahead and Like Beyonce’s official page for you – maybe even twice.

A video explaining how the social network scans and analyzes message content for “likeable” data showed how one such message increased Like counts by two – the video has since been pulled from YouTube. But privacy researcher and consultant Ashkan Soltani created a test page to see if sending a link via Facebook Messages could bump up its likes. You can try it by grabbing this link, and without hitting Like, send it via private message to a Facebook friend – and before you do, note the number of Likes. Once sent, that number should increase by two. You can watch this in action below. 

okc like boostWhile the test page method consistently works, there’s a little more confusion about actual brand pages. I sent a handful of brand page links to a Facebook friend, noting the number of Likes before and after. Though the numbers increased, there’s no way to definitively tell if this is from my sending them or from other users legitimately hitting Like on these pages.

Still, there’s some pretty overwhelming evidence to suggest Facebook is reading private messages. Soltani, who also originally saw the post on Hacker News and checked out the since-pulled YouTube video, explains. “The video was focusing on how to boost likes, and one thing I noticed from the demonstration was that in order to do this, he was sending private messages, and this implies Facebook is scanning private messages.” Basically, when you send a link through a message on Facebook, it creates a thumbnail that you essentially are previewing. Facebook does monitor this preview to make sure you aren’t sending malware – a simple security system. “But the value only gets increased when the link is actually sent – the preview and URL verification won’t increase the number of Likes,” Soltani tells me.

“We know Google has been doing this for awhile, but I think it’s surprising for most people that Facebook is doing it,” he says.

Not only is it surprising that Facebook is monitoring messages, but that it’s leading to Like-boosting. It does two things for brands: One, it gets them those new Likes. Two, it gives them a more accurate view of their organic shares. Privacy options on Facebook mean it can be difficult for marketers to track how their pages are being shared, but Facebook reviewing what’s in private messages mean they can get a better idea – Soltani, in fact, found that Facebook Insights were reporting the increase in organic shares of his page over private messages.  

fb insights organic shares

In response to the report, a Facebook spokesperson says that while private information isn’t being shared out of messages, data is being recorded to give brands better organic share numbers and also admits there appears to be a bug increasing Likes: 

“Absolutely no private information has been exposed. Each time a person shares a URL to Facebook, including through messages, the number of shares displayed on the social plugin for that website increases. Our systems parse the URL being shared in order to render the appropriate preview, and to also ensure that the message is not spam. These counts do not affect the privacy settings of content, and URLs shared through private messages are not attributed publicly with user profiles. We did recently find a bug with our social plugins where at times the count for the Share or Like goes up by two, and we are working on fix to solve the issue now. To be clear, this only affects social plugins off of Facebook and is not related to Facebook Page likes. This bug does not impact the user experience with messages or what appears on their timelines.”

It’s an interesting twist shortly after Facebook has staked so much in ridding the site of Like-jacking and faked Likes – not to mention the social network’s unending bid to win user trust. 


Source : digitaltrends[dot]com

Aug 21, 2012

How a new dad keeps tab on his newborn with DIY laser and Wiimote hack

By extracting the camera sensor from a Wiimote, hacker Gjoci built an inexpensive baby breathing monitor via a light triangulating method.

Even before blogger and hacker who simply goes by Gjoci became a dad, he spent weeks attempting to build a baby breathing monitor for the upcoming arrival of his daughter. But unlike your average baby breathing monitor, Gjoci crafted the device out of a Wiimote sensor and 1 milliwatt lasers to help detect whether his newborn was still peacefully sleeping.

Gjoci was able to accomplish this by disassembling a Wiimote and using the camera sensor to recognize three spots of lights. He then positions three 1 milliwatt lasers to watch over his newborn as she sleeps, allowing the device to detect the small movements of light as the baby breathes. These movements account for anywhere between just two to four pixels, making it perfect for the Wiimote’s extracted camera sensor to detect such detailed changes. There are also lights on the actual sensor computerboard that flashes in a pulse-like pattern, similar to what you’d see when measuring sound noise.

Every few milliseconds, the camera would check if the spots of lights are still gently shifting. If the breathing becomes irregular according to abnormal light patterns, Gjoci would be alerted with a buzzer sound. So far, the device has only given Gjoci a “very low number of false alarms,” and no hardware crashes or malfunctions. Still, you gotta wonder if the baby is curious as to why there are beams of light hovering over her body each time she awakes.

Gjoci claims since newborns don’t move very much, it seems fairly safe to use lasers on the child without running the risk of flashing into her eyes. This, of course, is still somewhat debatable in the Hack A Day comments section. Some readers suggest using infrared LED lights with reflective tape on the baby’s clothes to shine lights back to the camera sensor to reduce the safety risk from little to zero. Others question the possibility of a thermal detection.

Whatever the adaptations, the possibility of hacking a Wiimote into something much more useful outside of gaming is a remarkable and creative idea. If you want to read more on how Gjoci created the device, follow him on his blog. In meantime, here are a few videos of the sensor’s demonstration.


Source : digitaltrends[dot]com

Aug 19, 2012

Don’t trust that text: How the iPhone SMS spoof works

Sample iPhone text scam

A hacker claims to have found an SMS trick to which iPhones are particularly vulnerable, but how does it work, and why can't Apple stop it?

Late Friday, a blog focused on iOS security research claimed to have found a severe security flaw in iOS. It’s not a way to install malware or otherwise run destructive code, but it is an effective way to create fraudulent text messages that could be used in phishing schemes. While any phone that uses SMS text messaging is vulnerable, UI aspects of the iPhone make it a particularly tempting target. Since then, Apple has claimed the vulnerability lies in SMS technology, not iOS, and that it has no way of fixing it. So how does such a gaping hole in SMS security work?

As pod2g’s security blog explains, the vulnerability originates in the Protocol Description Unit system that’s used to transmit text messages. When you create an SMS message on your phone and hit the Send button, your phone translates the message into PDU terms, tosses it across the network to its recipient, and the phone at the other end catches the bundle of PDU code and translates it into whatever display format the recipient phone uses. But if you’re handy with raw code, you can bypass all the technology that UI designers have worked so hard to make nice and instead create a message in raw PDU text format.

That’s where shenanigans can begin. Just by typing a few words into a text string, a nasty spammer can change the User Data Header in the PDU code, and make it appear to the recipient that the text is coming from their beloved “Mother,” “The FBI,” “Messengers From Space,” or any other recipient they choose to specify. So you could get a message from “Mom” asking you to “Please log into this bank site so we can pay for your Uncle’s kidney surgery” or some other piece of  phishing trickery. Even more maliciously, someone who knew the name of your trusted contacts could send, for example, a message that appears to be from your buddy Dave claiming to have had an affair with your house-pet, driving you into a jealous frenzy for nothing but their own amusement. More seriously, courts have used SMS messages as evidence, so this scam could be used to falsely prove that someone violated a restraining order, or is engaged in criminal conspiracy.

The iPhone is especially vulnerable because of its SMS user interface. In a typically Jobsian pursuit of cleanliness, the iPhone doesn’t display the phone number of whoever sent you a message, only the name of the sender. So if “Uncle Jed” is texting you from a phone number in Kazakhistan, there’s no way to tell that you’re getting messages from a suspicious number. Obviously, the iPhone isn’t the only phone to keep those ugly integers tucked away in the pursuit of elegance, but it’s by far the most prominent, and therefore the one with the most to lose if its interface gets regarded as a security risk.

Apple has dealt with phishing vulnerabilities on the iPhone before, as well as phishing scams built around the Apple ID. Unfortunately, this vulnerability is inherent to the SMS protocol, making it much harder to unilateraly fix it. Seth Bromberger, a security consultant at NCI Security, suggests that the iPhone should display an originating number but it’s hard to imagine Apple cluttering up its clean lines with the kind of numeral strings that we all stopped remembering the day we got a built-in contacts list. For now, Apple has issued a statement telling users to be careful, and mentioning that hey, by the way, if you and all your friends just used iPhones exclusively then you would automatically be texting with the iMessage system, where these problems can’t happen. So perhaps the solution to this iPhone vulnerability is to buy an iPhone for all the people who might text you. Everybody wins. 


Source : digitaltrends[dot]com