{"id":12598,"date":"2018-06-16T10:45:12","date_gmt":"2018-06-16T18:45:12","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/06\/16\/news-6366\/"},"modified":"2018-06-16T10:45:12","modified_gmt":"2018-06-16T18:45:12","slug":"news-6366","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2018\/06\/16\/news-6366\/","title":{"rendered":"A Snooping Soccer App, a Decades-Old Bug, and More Security News This Week."},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5b2437d32b3a2d7b093344cf\/master\/pass\/RealMadrid-SecurityRoundup-966631410.jpg\"\/><\/p>\n<p><strong>Credit to Author: Brian Barrett| Date: Sat, 16 Jun 2018 13:00:00 +0000<\/strong><\/p>\n<p><span class=\"lede\">Did you hear? <\/span>There was a summit this week! A good ol\u2019 fashioned meeting of world powers, in which <a href=\"https:\/\/www.wired.com\/story\/north-korea-summit-denuclearize-history\/\">North Korea promised to denuclearize<\/a> for at least the seventh time in the last 30 years. In the process, President Donald Trump says he gave North Korean dictator Kim Jong Un his direct phone number, which if true <a href=\"https:\/\/www.wired.com\/story\/trum-kim-jong-un-direct-number-bad-idea\/\">was a terrible idea<\/a>. Oh, and even if North Korea does actually go through with ditching its nukes this time, it\u2019s going to be almost impossible to <a href=\"https:\/\/www.wired.com\/story\/north-korea-summit-nuclear-promises\/\">hold them accountable<\/a>.<\/p>\n<p>The <a href=\"https:\/\/www.wired.com\/story\/inspector-general-report-criticizes-fbi-comey-some-want-more\/\">Inspector General report of the FBI\u2019s actions during the 2016 presidential campaign<\/a> came out this week as well. Despite what Trump\u2019s tweets might have you believe, it did not exonerate the president\u2019s campaign in terms of potential Russian collusion. It did, however, show that the FBI and its former director James Comey made some not-great decisions in its probe of the Clinton email server. In a happier moment for the Justice Department, <a href=\"https:\/\/www.wired.com\/story\/silk-road-roger-clark-extradited\/\">alleged Silk Road consigliere Roger Clark was extradited<\/a> from Thailand to the United States this week. They also took down <a href=\"https:\/\/www.wired.com\/story\/feds-bust-nigerian-email-scammers\/\">dozens of Nigerian email scammers<\/a>, but that\u2019ll barely make a dent.<\/p>\n<p class=\"paywall\">Everyone from Paul Manafort to Michael Cohen learned that <a href=\"https:\/\/www.wired.com\/story\/encrypted-messaging-isnt-magic\/\">encrypted messaging isn\u2019t magic<\/a> this week, and you should too before misplaced trust gets you in trouble. Anduril <em>is<\/em> a magic sword in the <em>Lord of the Rings<\/em> universe, but also the name of <a href=\"https:\/\/www.wired.com\/story\/palmer-luckey-anduril-border-wall\/\">former Oculus Rift wunderkind Palmer Luckey\u2019s company<\/a> that exists to build a virtual borrder wall.<\/p>\n<p class=\"paywall\">If you\u2019re traveling to Russia for the World Cup, you\u2019re <a href=\"https:\/\/www.wired.com\/story\/world-cup-2018-travel-russia-secure-devices\/\">virtually sure to get hacked<\/a> unless you take some straightforward precautions. And US senators want straightforward answers from Amazon about exactly how much the Echo snoops on its owners.<\/p>\n<p class=\"paywall\">But wait, there&#x27;s more! As always, we\u2019ve rounded up all the news we didn\u2019t break or cover in depth this week. Click on the headlines to read the full stories. And stay safe out there.<\/p>\n<p class=\"paywall\">A week ago, the developers of the most popular soccer app in Spain, La Liga, pushed an update that asked permission to access a smartphone\u2019s mic and GPS settings. It then used that permission to listen for unlicensed broadcasts of games in public spaces. La Liga says any audio that gets captured is converted into binary code, which it then matches up against a control code to see if you\u2019re watching something no one paid for. This is bad! No matter how they mask the actual audio they\u2019re grabbing, it\u2019s still a significant privacy violation\u2014hard to imagine many people granted mic permission with the expectation it\u2019d be used like this\u2014and a risk, depending on how securely they capture and store the audio. An own goal, indeed.<\/p>\n<p class=\"paywall\">It\u2019s nowhere near as bad as <a href=\"https:\/\/www.wired.com\/story\/meltdown-spectre-bug-collision-intel-chip-flaw-discovery\/\">Meltdown and Spectre<\/a>, the speculative execution attacks that rattled the entire hardware industry, but Lazy FP state restore, the latest CPU vulnerability, is still a worrying continuation of this year\u2019s least welcome security trend. Affecting all Intel Core processors from 2011\u2019s Sandy Bridge line onward, the bug could allow an attacker to pull data from even encryption software. It\u2019s apparently both hard to pull off and easy to fix, so chalk it up to a good reminder that there\u2019s there\u2019s danger in them there chips.<\/p>\n<p class=\"paywall\">A critical vulnerability in a number of email encryption tools that rely on PGP encryption all patched a vulnerability this week that would have let attackers spoof digital signatures of people with public keys. It didn\u2019t work in the default configuration, but anyone who turned on the \u201cverbose\u201d setting was potentially susceptible. Even more fun: The bug dates back 20 years. This is distinct from the <a href=\"https:\/\/www.wired.com\/story\/efail-encrypted-email-flaw-pgp-smime\/\">Efail encrypted email vulnerability<\/a> that surfaced in March and ultimately less worrisome. But it\u2019s still a good reminder to only put so much faith in the tools you use to protect your privacy.<\/p>\n<p class=\"related-cne-video-component__dek\">It\u2019s 2017! It\u2019s time to start using an encrypted messaging app. Why? Using end-to-end encryption means that no one can see what you\u2019re sharing back and forth.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/popular-spanish-soccer-app-used-phone-mics-to-snoop\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5b2437d32b3a2d7b093344cf\/master\/pass\/RealMadrid-SecurityRoundup-966631410.jpg\"\/><\/p>\n<p><strong>Credit to Author: Brian Barrett| Date: Sat, 16 Jun 2018 13:00:00 +0000<\/strong><\/p>\n<p>Encrypted email, a 20-year-old bug, and more security news this week. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714],"class_list":["post-12598","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=12598"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12598\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=12598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=12598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=12598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}