New Security Warning Issued For Google’s 1.5 Billion Gmail And Calendar Users

Story by Davey Winder – Forbes

Google’s Gmail email service is used by upwards of 1.5 billion people. The Google Calendar app, meanwhile, has been downloaded more than a billion times from the Play Store. Security researchers have this week warned that threat actors are exploiting the popularity of both in order to target users with a credential-stealing attack.  Here’s what you need to know.

What does this attack involve?

Security researchers working at Kaspersky have revealed how threat actors are using the tight, and automatic, integration between different Google services in order to target users with malicious exploits.

In what the researchers refer to as a “sophisticated scam,” users of the Gmail service are being targeted primarily through the use of malicious and unsolicited Google Calendar notifications. Anyone can schedule a meeting with you, that’s how the calendar application is designed to work. Gmail, which receives the notification of the invitation, is equally designed to tightly integrate with the calendaring functionality.

When a calendar invitation is sent to a user, a pop-up notification appears on their smartphone. The threat actors craft their invitations to include a malicious link, leveraging the trust that user familiarity with calendar notifications brings with it.

The researchers have noticed attackers throughout the last month using this technique to effectively spam users with phishing links to credential stealing sites. By populating the location and topic fields to announce a fake online poll or questionnaire with a financial incentive to participate, the threat actors encourage the victim to follow the malicious link where bank account or credit card details can be collected. By exploiting such a “non-traditional attack vector,” the criminals can get around the fact that people are increasingly aware of common methods to encourage link-clicking.

Is this just a phishing thing then?

“Beyond phishing, this attack opens up the doors for a whole host of social engineering attacks,” says Javvad Malik, security awareness advocate at KnowBe4. Malik told me that in order to gain access to a building, for example, you could put in a calendar invite for an interview or similar face to face appointment such as building maintenance which, he warns “could allow physical access to secure areas.”

Hugo van den Toorn, manager of Offensive Security at Outpost24, agrees that the danger extends beyond the pure phishing realm. “This phishing attack specifically leveraged the intended functionality of a certain mobile application,” van den Toorn explains, “likely they could have also added attachments with malware targeting these users.”

How can you best mitigate the risk?

Kaspersky advises users to turn off the automatic adding of calendar invitations by going to the “Event Setting” menu in Google Calendar and disabling the “automatically add invitations” option by enabling the “only show invitations to which I’ve responded” one instead. Furthermore, it is advised that “Show declined events” in the View Options section is also left unchecked.

If turning off the automatic adding of events to your calendar is impractical, and it’s likely to be just that for many who rely on this type of scheduling, then Boris Cipot, a senior security engineer at Synopsys, has some general mitigation advice. “Question every email and in this case invitation you receive,” he says, “if it feels weird, wrong or unusual then ask the person who sent this invite if they really sent it.”

Obviously, there’s also the “do not click on any links or attachments” advice to be had. “Whenever in doubt it’s better to delete,” Cipot warns, but ultimately the Kaspersky advice should be followed he says. “Automation is not your friend in cases such as this, so do not let your calendar app put invitations automatically into your calendar,” Cipot concludes.

For full story, click here.

Teen Hacked Apple Twice Hoping to get Job.

Teen hacked Apple twice hoping to get job but got caught by FBI and police.

A 17-year-old Australian boy accused of hacking Apple twice in an effort to get a job has pleaded guilty to multiple computer hacking charges.

The teenager hacked into Apple’s mainframe in December 2015 and then once more in early 2017 to download internal documents and data. The FBI eventually discovered the incident and reported it to the Australian Federal Police (AFP).

According to the Australian court, the teen said he committed the hack because he heard of a person in Europe that also hacked Apple but ended up getting a job out of it.

Given that the teen was only 13 when he first hacked Apple, the magistrate accepted the defense’s argument that he had “no idea about the seriousness of the offense.” The magistrate noted the teen has since been using his computer skills for good at school, as per his classmates and teachers.

Further, Apple confirmed that no customer information was accessed by the teenager and it didn’t incur any losses during the hacking.

For those reasons, the magistrate did not convict the boy, instead opting to he’s on a $500 AUD (roughly $465 CAD) good behavior bond for nine months.

Source: ABC News and Bradly Shankar

Need a Reason to Drop Google Chrome?

Google is planning to restrict modern ad blocking Chrome extensions to enterprise users only. This is despite a backlash to an announcement by Google in January proposing changes that will stop certain ad blockers from working efficiently.

The proposal–dubbed Manifest V3–will see a major transformation to Chrome extensions that includes a revamp of the permissions system. It will mean modern ad blockers such as uBlock Origin—which uses Chrome’s webRequest API to block ads before they’re downloaded–won’t work. This is because Manifest V3 sees Google halt the webRequest API’s ability to block a particular request before it’s loaded.

A single sentence buried in the text of Google’s response to the complaints, which clarified the changes: “Chrome is deprecating the blocking capabilities of the webRequest API in Manifest V3, not the entire webRequest API (though blocking will still be available to enterprise deployments).”

In other words, paid enterprise-only users will still have the ability to block unwanted content. It probably means enterprise customers can develop in-house Chrome extensions, not for ad blocking use. For everyone else, the changes announced in January will remain the same.

It’s annoying, to say the least, but the reason for these changes is obvious: Ads are at the heart of Google’s business model.

There are many users who won’t use Chrome without an ad blocker, so it will see some switch to other providers such as Firefox. However, Firefox has had its own issues over recent weeks.

So, now might be the time to switch to another browser, such as Brave. Brave is built upon Chromium so all existing Chrome plugins and even themes work on it and reduces your digital footprint, protecting your privacy.

Another option is using DNS level methods that blacklists adverts as well as malicious URLs.

VA3DBJ Weather Station Back Online

The VA3DBJ Weather station is now back online. The software has been updated to latest version of Cumulus. You can access directly by typing weather.va3dbj.ca in your browser.

This weather updates every 2 minutes but the gauges are updated every minute or two.  You can also receive hourly reports via Twitter at my VA3DBJWeather Twitter account.

Morse Code Marks 175 Years of Dots and Dashes

The first message sent by Morse code’s dots and dashes across a long distance travelled from Washington, DC to Baltimore on Friday, 24 May 1844 — 175 years ago. It signaled the first time in human history that complex thoughts could be communicated at long distances almost instantaneously. Until then, people had to have face-to-face conversations; send coded messages through drums, smoke signals and semaphore systems; or read printed words.

Thanks to Samuel FB Morse, communication changed rapidly, and has been changing ever faster since. He invented the electric telegraph in 1832. It took six more years for him to standardize a code for communicating over telegraph wires. In 1843, the US congress gave him US$30 000 to string wires between the nation’s capital and nearby Baltimore. When the line was completed, he conducted a public demonstration of long-distance communication.

Morse wasn’t the only one working to develop a means of communicating over the telegraph, but his is the one that has survived. The wires, magnets and keys used in the initial demonstration have given way to smartphones’ on-screen keyboards, but Morse code has remained fundamentally the same, and is still — perhaps surprisingly — relevant in the 21st century. Although I have learned, and relearnt, it many times as a Boy Scout, an amateur radio operator and a pilot, I continue to admire it and strive to master it.Morse’s key insight in constructing the code was considering how frequently each letter is used in English

Morse’s key insight in constructing the code was considering how frequently each letter is used in English.

The most commonly used letters have shorter symbols: “E”, which appears most often, is signified by a single “dot”. By contrast, “Z”, the least-used letter in English, was signified by the much longer and more complex “dot-dot-dot (pause) dot”.

In 1865, the International Telecommunication Union changed the code to account for different character frequencies in other languages. There have been other tweaks since, but “E” is still “dot”, though “Z” is now “dash-dash-dot-dot”.

The reference to letter frequency makes for extremely efficient communications: simple words with common letters can be transmitted very quickly. Longer words can still be sent, but they take more time.

Metal wires

The communications system that Morse code was designed for — analogue connections over metal wires that carried a lot of interference and needed a clear on-off type signal to be heard — has evolved significantly.

The first big change came just a few decades after Morse’s demonstration. In the late 19th century, Guglielmo Marconi invented radio-telegraph equipment, which could send Morse code over radio waves, rather than wires.

The shipping industry loved this new way to communicate with ships at sea, either from ship to ship or to shore-based stations. By 1910, US law required many passenger ships in US waters to carry wireless sets for sending and receiving messages.

After the Titanic sank in 1912, an international agreement required some ships to assign a person to listen for radio distress signals at all times. That same agreement designated “SOS” — “dot-dot-dot dash-dash-dash dot-dot-dot” — as the international distress signal, not as an abbreviation for anything but because it was a simple pattern that was easy to remember and transmit. The Coast Guard discontinued monitoring in 1995. The requirement that ships monitor for distress signals was removed in 1999, though the US Navy still teaches at least some sailors to read, send and receive Morse code.

Aviators also use Morse code to identify automated navigational aids. These are radio beacons that help pilots follow routes, travelling from one transmitter to the next on aeronautical charts. They transmit their identifiers — such as “BAL” for Baltimore — in Morse code. Pilots often learn to recognise familiar-sounding patterns of beacons in areas they fly frequently.

There is a thriving community of amateur radio operators who treasure Morse code, too. Among amateur radio operators, Morse code is a cherished tradition tracing back to the earliest days of radio. Some of them may have begun in the Boy Scouts, which has made learning Morse variably optional or required over the years. The Federal Communications Commission used to require all licensed amateur radio operators to demonstrate proficiency in Morse code, but that ended in 2007. The FCC does still issue commercial licences that require Morse proficiency, but no jobs require it anymore. Because its signals are so simple – on or off, long or short – Morse code can also be used by flashing lights

Because its signals are so simple — on or off, long or short — Morse code can also be used by flashing lights.

Many navies around the world use blinker lights to communicate from ship to ship when they don’t want to use radios or when radio equipment breaks down. The US Navy is actually testing a system that would let a user type words and convert it to blinker light. A receiver would read the flashes and convert it back to text.

Skills learnt in the military helped an injured man communicate with his wife across a rocky beach using only his flashlight in 2017.

Perhaps the most notable modern use of Morse code was by Navy pilot Jeremiah Denton, while he was a prisoner of war in Vietnam. In 1966, about one year into a nearly eight-year imprisonment, Denton was forced by his North Vietnamese captors to participate in a video interview about his treatment. While the camera focused on his face, he blinked the Morse code symbols for “torture”, confirming for the first time US fears about the treatment of service members held captive in North Vietnam.

Learning Morse code

Blinking Morse code is slow, but has also helped people with medical conditions that prevent them from speaking or communicating in other ways. A number of devices — including iPhones and Android smartphones — can be set up to accept Morse code input from people with limited motor skills.

There are still many ways people can learn Morse code, and practice using it, even online. In emergency situations, it can be the only mode of communications that will get through. Beyond that, there is an art to Morse code, a rhythmic, musical fluidity to the sound. Sending and receiving it can have a soothing or meditative feeling, too, as the person focuses on the flow of individual characters, words and sentences. Overall, sometimes the simplest tool is all that’s needed to accomplish the task.

  • Written by Eddie King, PhD student in electrical engineering, University of South Carolina
  • This article is republished from The Conversation under a Creative Commons licence

WWV Celebrating 100 Years

The National Institute of Standards and Technology Radio Station WWV will be celebrating its 100-year anniversary in October 2019. The oldest continuously operating radio station in the world deserves a grand celebration.

The National Institute of Standards and Technology (NIST) and the Northern Colorado Amateur Radio Club (NCARC) have reached an agreement and are working together to organize the event.

NIST will focus on the plans for Tuesday, October 1, when they will host a recognition ceremony and an open house at the radio station north of Fort Collins. 

NCARC will operate a special event amateur radio station, call sign WW0WWV, on the WWV property starting September 28 and going 24-hours a day through October 2. The goal is to make as many U.S. and world-wide contacts during the 120-hour period as possible, using multiple bands and multiple modes on at least 4 simultaneous transmitters. The effort will require hundreds of volunteer operators.

Information on the Special Events Station visit: http://wwv100.com
https://www.nist.gov/news-events/events/2019/10/nist-radio-station-wwv-100-year-anniversary

Safe and Ad Free Browsing

Ever since my bad experience with Facebook and their other products, I have been working on ways to minimize my digital footprint. I moved over to other social media sites that have no ads and don’t ask or use your private information. With the demise of Google Plus in April (2019), I decided that it was the perfect opportunity to research and move to other products that decrease my digital footprint and at least work to safe guard my web browsing. This is a living post, per-se, that I will be maintaining with new and updated information.

Ad Free DNS

AdGuard DNS is a free Domain Name System service provided by the AdGuard company. You can use this DNS service to block advertising and trackers. It works like this: when a website sends a request to an ad network, the DNS sends back a “null” response. For example, when a web page looks up the domain name “ads.facebook.com” the DNS will not find that name. This means all networks request are never loaded — this is the most efficient way to block them. This blocking may even speed up your web browser slightly.

Besides blocking advertising, AdGuard DNS will also blocks trackers and malware phishing sites.

Default Ad-Blocking DNS

Use these servers to block ads, tracking and phishing:

  • 176.103.130.130
  • 176.103.130.131

Or use IPv6 addresses:

  • 2a00:5a60::ad1:0ff
  • 2a00:5a60::ad2:0ff

Family Protection DNS

Default + blocking adult (porn) websites + safe search:

  • 176.103.130.132
  • 176.103.130.134

Or use IPv6 addresses

  • 2a00:5a60::bad1:0ff
  • 2a00:5a60::bad2:0ff

For more information on AdGuard DNS, click here.

Web Browsers

Your web browser knows a lot about you, and tells the sites you visit a lot about you as well—if you let it. I have been testing out a number of browsers that specifically caters to those that want safer browsing experience and free of most ads.

Brave Browser

Here is one that I have been using for a while and it works pretty well, when used with the AdGuard DNS protection.

Brave is the latest unique browser to join the ever-expanding market. The open source and free browser from Brave Software Inc. has positioned itself as the browser that loads faster with better privacy protection. The firm was co-founded by Brendan Eich, the creator of JavaScript and a co-founder of Mozilla. Brave keeps data safe and provides users with the power to save or delete it. It features a built-in ad tracker and blocker. Unlike most common browsers, Brave also helps to fight phishing and malware.

Brave blocks ads automatically. Users are no longer required to search the web for a perfect ad blocker. The auto-blocking protects your device from malware and extensive tracking by advertisers. Brave is also working on a plan to replace ads that appear harmful.

Tracking ads by Brave is accurate. Users are served with the right ads because Brave does the tracking using local data. If an ad is irrelevant to the user, it is pulled down. You get the appropriate ads based on this model. A user’s data stays within the device since they have no third parties involved.

While Brave blocks third-party cookies, the first party cookies are not blocked by default. Users have the option to prevent or enable cookies on a given website.

However, Brave does not block ads displayed in search results. You will be able to see AdWords advertisements within Google’s results. This is because Ad blocking extensions don’t stymie search ads either.

Blocking of malicious ads automatically allows safe browsing. Brave does not have access to identifiable user data. The anonymity aggregated ad campaign related data is used for accounting. However, this data cannot be traced back to a user’s device.

Brave also comes with additional tactics to boost privacy while browsing. The incorporation of HTTPS everywhere allows usage of web encryption whenever available.

The fingerprinting feature bars third parties from tracking your activity. This feature can be activated in the settings tab.

Brave offers a clean and crisp interface that is intuitive to use. It has all the elements you would expect in your ideal browser. Furthermore, Brave’s individual tabs sport icons for quick identification, and hovering the cursor over a tab offers details on the page in that tab without having to click on the tab and activate it.

The browser also displays statistics about the content the browser has blocked. These statistics are very useful. Furthermore, it displays photos, the current time and shortcuts to your favorite sites. Like other websites, one would expect these features to have an effect on speed. However, this is not the case. Brave is very easy to use, with a streamlined design and the useful option to preview the content of tabs.

Brave’s load speeds emerge on top. The fast browsing is supported by Brave’s lack of thirds party ads. You, therefore, have less content to download before accessing your favorite website. However, Brave’s rendering speeds come a bit after Google Chrome and Mozilla.

Brave is set up on the Chromium platform. Chromium is an open-source system that also powers popular browsers like Google Chrome and soon Microsoft Edge. Based on the Chromium capability, you can almost use all Chrome extensions on Brave. The extensions on Chrome can be added to Brave through the Chrome Web Store.

For more information and downloads, click here.

No More Ads

I have disabled the ads on VA3DBJ.ca, as they were not beneficial at all and I have started to push for an ad free environment. I have also decreased the amount of personal tracing as well, to only those that would benefit you and the operation of the site.

I have also limited some tracking, with the exception of the Google reCAPTCHA function for the Contact Us section and twitter tracking for the tweeting of the VA3DBJ hourly weather reports and warnings.

I have limited the amount of SEO tracking as well, allowing just enough tracking so that pages can be re-posted to social media accounts.

I have also enabled GDPR to meet the new European Union requirements.

Space Pioneer Astronaut Owen Garriott, W5LFL, SK

ARRL reports the US astronaut who pioneered the use of Amateur Radio to make contacts from space — Owen K. Garriott, W5LFL — died April 15 at his home in Huntsville, Alabama. He was 88.

Garriott’s ham radio activity ushered in the formal establishment of Amateur Radio in space, first as SAREX — the Shuttle Amateur Radio Experiment, and later as ARISS — Amateur Radio on the International Space Station.

“Owen Garriott was a good friend and an incredible astronaut,” fellow astronaut Buzz Aldrin tweeted. “I have a great sadness as I learn of his passing today. Godspeed Owen.”

An Oklahoma native, Garriott — an electrical engineer — spent 2 months aboard the Skylab space station in 1973 and 10 days aboard Spacelab-1 during a 1983 Space Shuttle Columbia mission. It was during the latter mission that Garriott thrilled radio amateurs around the world by making the first contacts from space.

Thousands of hams listened on 2-meter FM, hoping to hear him or to make a contact. Garriott ended up working stations around the globe, among them such notables as the late King Hussein, JY1, of Jordan, and the late US Senator Barry Goldwater, K7UGA. He also made the first CW contact from space. Garriott called hamming from space “a pleasant pastime.”

“I managed to do it in my off-duty hours, and it was a pleasure to get involved in it and to talk with people who are as interested in space as the 100,000 hams on the ground seemed to be,” he said in an interview published in the February 1984 edition of QST. “So, it was just a pleasant experience, the hamming in particular, all the way around.”

Although Garriott had planned to operate on ham radio during his 10 days in space, no special provisions were made on board the spacecraft in terms of equipment — unlike the situation today on the International Space Station. Garriott simply used a hand-held transceiver with its antenna in the window of Spacelab-1. His first pass was down the US West Coast.

“[A]s I approached the US, I began to hear stations that were trying to reach me,” he told QST. “On my very first CQ, there were plenty of stations responding.” His first contact was with Lance Collister, WA1JXN, in Montana.

ARISS ARRL Representative Rosalie White, K1STO, met Garriott when he attended Hamvention, “both times, sitting next to him at Hamvention dinner banquets,” she recounted. “Once when he was a Special Achievement Award winner, and once with him and [his son] Richard when Richard won the 2009 Special Achievement Award. Owen was unassuming, very smart, kind, and up to date on the latest technology.” Garriott shared a Hamvention Special Achievement Award in 2002 with fellow Amateur Radio astronaut Tony England, W0ORE.

Richard Garriott, W5KWQ, was a private space traveler to the ISS, flown there by the Russian Federal Space Agency, and he also carried ham radio into space.

Experts Predict a Long, Deep Solar Minimum

Dr.Tony Phillips on April 10, 2019

If you like solar minimum, good news: It could last for years. That was one of the predictions issued last week by an international panel of experts who gathered at NOAA’s annual Space Weather Workshop to forecast the next solar cycle. If the panel is correct, already-low sunspot counts will reach a nadir sometime between July 2019 and Sept 2020, followed by a slow recovery toward a new Solar Maximum in 2023-2026.

“We expect Solar Cycle 25 will be very similar to Cycle 24: another fairly weak maximum, preceded by a long, deep minimum,” says panel co-chair Lisa Upton, a solar physicist with Space Systems Research Corp.

The solar cycle is like a pendulum, swinging back and forth between periods of high and low sunspot number every 11 years or so. Researchers have been tracking the cycle since it was discovered in the 19th century. Not all cycles are alike. Some are intense, with lots of sunspots and explosive solar flares; the Space Age began with a big booming solar maximum. Others are weak, such as the most recent, Solar Cycle 24, which peaked in 2012-2014 with relatively little action.

Researchers are still learning to predict the ebb and flow of solar activity. Forecasting techniques range from physical models of the sun’s inner magnetic dynamo to statistical methods akin to those used by stock market analysts.

“We assessed ~61 predictions in the following categories: Climatology, Dynamo, Machine Learning/Neural Networks, Precursor Methods, Spectral/Statistical Methods, Surface Flux Transport, and Other,” says Upton. “The majority agreed that Solar Cycle 25 would be very similar to Solar Cycle 24.”

“Here,” she says, “is a figure showing the last minimum and where we are with the current minimum.”

“As you can see – we haven’t quite reached the lowest levels of the last cycle – where we experienced several consecutive months with no sunspots. However, the panel expects that we should reach those levels.”

In recent years, the Internet has buzzed with the idea that a super-deep solar minimum such as the 70-year Maunder Minimum of the 17th century might cool the Earth, saving us from climate change. That’s not what the panel is saying, however.

“There is no indication that we are currently approaching a Maunder-type minimum in solar activity,” says Upton. Solar minimum will be deep, but not that deep.

The panel predicts a “fairly weak” Solar Cycle 25. What does that mean? Saying that a solar cycle is “weak” is a bit like saying hurricane season will be “weak.” In other words, there may be fewer storms, but when a storm comes, you’d better batten down the hatches. “Weak” Solar Cycle 24 produced a number of intense X-class solar flares, strong geomagnetic storms, and even a Ground Level Event (GLE) when solar energetic particles reached Earth’s surface. An equally “weak” Solar Cycle 25 could do the same 3 or 4 years hence.

Meanwhile, we have solar minimum. This is a widely misunderstood phase of the solar cycle. Many people think it brings a period of dull quiet. In fact, space weather changes in interesting ways. For instance, as the sun’s magnetic field weakens, holes open in the sun’s atmosphere. Emerging streams of solar wind buffet Earth’s magnetic field, sustaining auroras even without solar flares and sunspots. Some observers believe that Solar Minimum auroras have a distinctive palette, pinker than during other phases of the solar cycle.

The sun’s weakening magnetic field also allows cosmic rays to enter the solar system. Energetic particles from deep space penetrate Earth’s atmosphere with a myriad of possible effects ranging from changes in upper atmospheric electricity to extra doses of radiation for people on airplanes.

Finally, the sun dims, especially at extreme ultraviolet wavelengths. This, in turn, causes the upper atmosphere to cool and contract. Aerodynamic drag that would normally cause satellites to decay is reduced; space junk accumulates. This effect makes solar minimum a terrible time to blow up satellites–although people do it anyway.

The Solar Cycle Prediction Panel is comprised of scientists representing NOAA, NASA, the International Space Environment Services, and other U.S. and international scientists. Their April 5th prediction was preliminary, and they plan to issue a refined forecast by the end of 2019. Stay tuned.