{"id":11585,"date":"2018-02-24T10:45:37","date_gmt":"2018-02-24T18:45:37","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/02\/24\/news-5356\/"},"modified":"2018-02-24T10:45:37","modified_gmt":"2018-02-24T18:45:37","slug":"news-5356","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/02\/24\/news-5356\/","title":{"rendered":"The Rick Gates Plea, an Apple Watch Mess, and More Security News This Week"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5a907c33afa4b44b413e5433\/master\/pass\/SecurityRoundup-AppleWatches.jpg\"\/><\/p>\n<p><strong>Credit to Author: Brian Barrett| Date: Sat, 24 Feb 2018 14:00:00 +0000<\/strong><\/p>\n<p><span class=\"lede\">Robert Mueller&#x27;s indictment <\/span>of Russia&#x27;s Internet Research Agency\u2014also known as the &quot;troll factory&quot;\u2014feels like years ago at this point. It&#x27;s only been a week! And we <a href=\"https:\/\/www.wired.com\/story\/inside-the-mueller-indictment-a-russian-novel-of-intrigue\/\">took a deep dive into what it really says<\/a> about Russia&#x27;s propaganda efforts during the 2016 presidential campaign and beyond. Trump campaign advisor <a href=\"https:\/\/www.wired.com\/story\/what-rick-gates-guilty-plea-means-for-muellers-probe\/\">Rick Gates has also copped a plea deal with Mueller&#x27;s team<\/a>\u2014which could have big implications for the investigation going forward.<\/p>\n<p>We also got a rare look inside the <a href=\"https:\/\/www.wired.com\/story\/north-korean-hacker-group-apt37\/\">toolkit of an up and coming North Korean hacking group<\/a>, called APT37, which has recently started to branch out beyond targeting just its neighbors to the south. Meanwhile, cryptojacking struck once more, this time <a href=\"https:\/\/www.wired.com\/story\/cryptojacking-tesla-amazon-cloud\/\">glomming onto Tesla&#x27;s public cloud to mine cryptocurrency<\/a>. The silver lining? While sensitive data was apparently exposed, the hackers don&#x27;t appear to have pilfered any of it.<\/p>\n<p class=\"paywall\">For whatever the inverse of a silver lining is, we look to US Customs and Border Protection, which has required RFID chips in passports for over a decade but <a href=\"https:\/\/www.wired.com\/story\/us-border-patrol-hasnt-validated-e-passport-data-for-years\/\">never got around to installing the software that verifies the cryptographic signature<\/a>, making forgeries and tampering potentially easier. And did you know that <a href=\"https:\/\/www.wired.com\/story\/facebook-mandatory-malware-scan\/\">Facebook makes some users download antivirus software<\/a>? It&#x27;s true! And weird! And not ideal!<\/p>\n<p class=\"paywall\">And while it&#x27;s a rarity, there also was some good news this week. <a href=\"https:\/\/www.wired.com\/story\/facebook-mandatory-malware-scan\/\">WhatsApp co-founder Brian Acton has infused $50 million into Signal<\/a>, the <a href=\"https:\/\/www.wired.com\/story\/ditch-all-those-other-messaging-apps-heres-why-you-should-use-signal\/\">gold standard for encrypted messaging<\/a>, which should secure its viability for years to come.<\/p>\n<p class=\"paywall\">And there&#x27;s more. As always, we\u2019ve rounded up all the news we didn\u2019t break or cover in depth this week. Click on the headlines to read the full stories. And stay safe out there.<\/p>\n<p class=\"paywall\">Since October of last year, devices at an Apple repair center in Elk Grove, California have called 911 an average of 20 times a day, for a total of about 1600 dials, according to a local CBS affiliate. Apple acknowledged the issue in a statement, saying, &quot;We take this seriously and we are working closely with local law enforcement to investigate the cause and ensure this doesn\u2019t continue.&quot; That investigation likely won&#x27;t take long; the Apple Watch automatically calls 911 if you hold the side button down for several seconds. Tapping the side button of your iPhone five times in succession does the same, if you&#x27;re on iOS 11. Those features are obviously helpful to people in legitimate danger. But unless Apple can wrangle its Elk Grove process to stop the influx of false alarms, it may end up blocking actual calls from getting through.<\/p>\n<p class=\"paywall\">Here&#x27;s a novel way to launder money, as <a href=\"https:\/\/krebsonsecurity.com\/2018\/02\/money-laundering-via-author-impersonation-on-amazon\/\" target=\"_blank\">reported by<\/a> Krebs on Security: Use a computer to generate about 60 pages&#x27; worth of text. Slap a title and cover on it and toss it in the Kindle Store under someone else&#x27;s identity. Charge several hundred dollars for it. Buy it dozens of times with stolen credit cards, pocketing the 60 percent cut that Amazon shares with authors, and sticking the person whose name you stole with the tax bill. It sounds a little convoluted, but no more than your average John Barth short story. And in the case reported by Krebs, the scammers were able to successfully launder $24,000.<\/p>\n<p class=\"paywall\">Consumer spyware is a bit of a scourge, as Motherboard <a href=\"https:\/\/motherboard.vice.com\/en_us\/topic\/when-spies-come-home\" target=\"_blank\">has covered<\/a> extensively. It becomes potentially even more alarming, though, when those consumers also happen to work for the FBI, DHS, or ICE. According to hacked data from spyware provider Mobistealth, people with email addresses from those and other law enforcement organizations have purchased the so-called stalkerware, as well as at least 40 members of the US Army.<\/p>\n<p class=\"paywall\">Cryptographic certificates are an important part of internet security; they let your computer know that any given piece of software comes from the company it claims to. This week, researchers at Recorded Future released research that shows the market for counterfeit certificates jumped starting last year. The concern here is more over niche or targeted operations, given the expense of a fake, but the results can be vicious, tricking antivirus protections into thinking an intruder is legitimate.<\/p>\n<p class=\"related-cne-video-component__dek\">Heads up, iPhone owners. iOS 11 comes with a batch of security features that merit your attention.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/apple-repair-center-barrages-sacramentos-911-operators\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5a907c33afa4b44b413e5433\/master\/pass\/SecurityRoundup-AppleWatches.jpg\"\/><\/p>\n<p><strong>Credit to Author: Brian Barrett| Date: Sat, 24 Feb 2018 14:00:00 +0000<\/strong><\/p>\n<p>A Mueller probe plea, and Apple snafu, and more of the week&#8217;s top security news.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714],"class_list":["post-11585","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11585","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=11585"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11585\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=11585"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=11585"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=11585"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}