Friday, November 1, 2013

Sounds like the Matrix has this one!

Have you ever had one of those impossible-to-delete malware infections?
You know, no matter what you do, it keeps coming back?
You can't even boot from a CD-ROM, because it won't let you.
Furthermore, you unplug the network cable. And remove the network card, and it is still communicating with the outside world, somehow.
This bad boy (badBIOS, actually) they found out, was using the laptop's built-in microphone and speaker to communicate via ultrasonic sounds!
Good narrative here.

Be careful of who you link/friend, regardless of who else they know. Fake ID gets endorsements, job offers, etc.

Something to think about when you get new LinkedIn or Facebook requests. Several security professionals befriended this fake social media identity (matching fake LinkedIn and FaceBook accounts) in this story.
This non-person received endorsements and job offers. Some offered to help her get a laptop at her new job that would help her get access to things she would not have otherwise had access to.
When "she" sent out an e-card around Christmas time, it contained a link to some software that installed spyware on people's computers. It required their interaction to allow it to install, but it worked very well anyway.
I think my number one takeaway from this story is the fact that the first people duped into linking up and friending this fake person gave her the credibility to link up with other people who would not have been fooled otherwise.