7/11/13

Brute-force attack on Club Nintendo website results in 24,000 compromised accounts

Nintendo recently revealed that nearly 24,000 Club Nintendo accounts have been hacked following what was close to a month-long brute-force attack. We are being told that members’ full names, home address, phone numbers and e-mail addresses were compromised during the attack although billing information like credit cards thankfully aren’t a part of the rewards site.
The attack appears to have only affected Club Nintendo users in Japan and was only noticed last week following a large number of access errors. In total, Nintendo said there were 15 million unauthorized login attempts during the attack.
Despite the fact that there doesn’t appear to be any real security threat, it is a bit concerning that it took so many failed logins before Nintendo even became aware of the issue. The company has since issued an e-mail to affected Club Nintendo members urging them to change their passwords as existing passwords have all been wiped.
Club Nintendo allows members to build points, or “coins,” that can be traded in for promotional items. Members can earn points simply by buying Nintendo products, registering their gear and providing feedback. Other perks include a free warranty extension program for registered systems as well as access to limited-edition bonus items like CDs, gifts and exclusive events.
This is the second high profile gaming-related hack in less than a week. If you recall, Ubisoft’s website was hacked earlier this month as sensitive information including user names, e-mail addresses and encrypted passwords were all compromised. It’s worth pointing out that the two incidents don’t appear to be linked, however.

UK asks Google to revise privacy policy or face enforcement action

Google’s move to a unified privacy policy generated quite a stir when it was announced last year. Although the search giant defended the changes as a way to simplify privacy -- with a single document instead of 60 -- and a more intuitive experience across its own services. Indeed, little had changed in terms of how Google could gather and combine data, but the move still raised concerns with privacy watchdogs around the globe.
Now, following fifteen months of debate and scrutiny, European authorities are giving Google an ultimatum asking them to revise their privacy policy. The latest to chime in is UK’s Information Commissioner's Office (ICO), which says the policy raises “serious questions” about compliance with the UK Data Protection Act.
Specifically, the ICO found three main areas of concern. First, the group says Google needs to provide more information about how it processes users’ personal data. Google also needs to inform users specifically what their personal data is being used for so they fully understand the implications of using Google’s services; and lastly it must inform users when retention of personal data might exceed service users’ reasonable expectations.
Should Google fail to amend its privacy policy by September 20, the ICO could issue an enforcement notice through the courts and potentially fine the company with up to £500,000.
The warning follows similar complaints from the equivalent organization France last month, which put a legal order in place on its recommendations, giving Google three months to respond or face court action. Other European nations running investigations into Google’s policy include Spain, Germany, Italy, and the Netherlands.

Microsoft working with partners to fix trackpad behavior in Windows 8.1, first round of updates for public preview roll out

Microsoft is working towards fine tuning all aspects of Windows 8.1 ahead of release later this year. Despite its touch-centric nature, one area where the operating system hasn’t really shined is in its support of gestures across different laptop trackpads. According to The Verge, the company is finally taking the issue seriously and is working closely with partners to ensure a consistent experience on all devices.
Although the collaboration is still in the early stages, Intel, Elan, and Synaptics are all on board to allow Windows 8.1 to directly control the pointer, multi-touch, and gesture support in trackpads.
Areas of focus include smoother scrolling, better zooming and panning support, accidental activation prevention  to filter out non-deliberate touches, as well as supporting the full range of gestures available on Windows 8.1 so that laptop trackpads work more like mini touch-screens, similar to how Apple’s trackpads operate.
The initiative is being called "Precision Touchpad" support and we may see its first results in laptops shipping by the end of the year. At this point it’s unclear if the improved trackpad functionality will be limited to new devices or if firmware updates for existing Windows 8 machines are forthcoming.

First round of updates for 8.1: no critical flaws

On a somewhat related note, the recently released Windows 8.1 Preview has received its first round of fixes this morning. Available through Windows Update, the patch includes six updates that address a number of different issues, two of those issues are rated as “important” while the remaining four are listed as “recommended.”
One of the important updates involves new virus definitions for Windows Defender, while the other improves compatibility with a number of third-party programs AutoCAD, Parallels Desktop, Norton security software, and AVG Internet Security. The four recommended updates address an issue with Windows Store apps crashing upon launch, a bug that kept IE11 from resuming downloads, an issue that prevented signing in to certain apps with Google accounts, and improving “the robustness of data files in Windows 8.1.”
The updates are available for both Windows 8.1 and Windows RT 8.1.

IIP bureau of U.S. State Department spent $630,000 on Facebook ‘likes’

The International Information Programs (IIP), a bureau of the U.S. State Department, spent $630,000 on Facebook advertising campaigns in 2011 and 2012, and according to a report from the Inspector General, they may not have gotten their money’s worth.
The campaigns were effective at gaining fans for four of the Bureau’s Facebook pages; they jumped from 100,000 to over two million during the two-year effort.
The Inspector General’s report reveals that some people aren’t pleased with the expenditure, citing complaints about ‘buying fans’ that potentially clicked ‘like’ once but were not engaged and then never returned.
Following a week of monitoring, the Inspector General’s office found that only 2 percent of the Bureau’s Facebook fans could be categorized as ‘engaged audience’ members, that is, people who are liking, sharing, and commenting.
According to RT, Facebook changed their policies in September 2012, dictating that content will only show up in friends of fans’ newsfeed when the user is an ‘engaged fan.’ This adjustment to the rules resulted in a significant decrease in the value of the Bureau’s purchases fan base.
“This change sharply reduced the value of having large numbers of marginally interested fans and means that IIP must continually spend money on sponsored story ads or else its ‘reach’ statistics will plummet,” the IG report said.
The report calls attention to the growing use artificially bolstered social media services. Instead of gaining fans or followers organically through useful, interesting, and engaging content, companies are able to buy there way to a massive audience.
Those selling the advertisements may be the only ones winning in these scenarios; users are served with content they aren’t interested in, and companies waste tens and hundreds of thousands of dollars on ineffective marketing.

Android flaw leaves 99% of devices open to attacks, details to be revealed at BlackHat

Mobile security company Bluebox claims to have discovered a flaw in Android that could leave any device released in the last four years vulnerable to attacks. The method demonstrated allowed modifying an app’s code without affecting its cryptographic signature, inserting malicious code completely unnoticed, leading to anything from data theft to creating botnets. The implications are huge, the researchers say.
Although specifics were left under wraps, the core issue involves discrepancies in how Android applications are verified and installed. As Bluebox explains, all Android apps contain cryptographic signatures to verify their authenticity. But through the use of some sort of “master key”, malicious coders are able trick Android into believing an app is unchanged even if its APK code has been modified.
The vulnerability has reportedly been around since the release of Android 1.6 in 2009 and Google was notified about it in February. But due to the way Android updates work, it’s up to manufacturers to produce and release firmware updates for their specific hardware, and so far only the Galaxy S 4 has been patched.
As proof of the vulnerability’s existence, Bluebox  CTO Jeff Forristal accompanied his blog post with a screenshot from an HTC device that had system-level software information modified to display “Bluebox” in the Baseband Version string (a value normally controlled & configured by the system firmware).
Technical details and related tools will be released at his BlackHat USA 2013 talk by the end of the month.
It’s worth noting that for all the doom and gloom that Bluebox is spelling -- it appears to be a serious issue after all -- falling prey to hackers would require you to download an actual app that has been modified with malicious code. In other words, it requires user action, and most likely downloading from a non-official source.

DirectX 11.2 said to be a Windows 8.1 / Xbox One exclusive

Microsoft’s upcoming DirectX 11.2 update, first shown off at the company’s Build conference last month, promises to deliver a host of new features and performance improvements in games and apps. But according to reports, the update is reportedly being limited to Windows 8.1 and next generation consoles like the Xbox One.
This exclusivity isn’t something new, however, as Microsoft pulled a similar move when transitioning to DirectX 11.1 as that update requires the use of Windows 8. Before that, DirectX 10 was a Windows Vista exclusive which left Windows XP users high and dry.
Perhaps this is one of Microsoft’s ways to help nudge Windows XP, Vista and 7 users toward upgrading to Redmond’s latest but whether or not it’ll work remains to be seen. Such requirements really did little to lead to the commercial success of Vista or Windows 8 but this time around, the timing is a bit different. Xbox One is just around the corner and if a number of games use it, perhaps it could take root better.
DirectX 11.2 brings with it a new key feature known as Direct3D tiled resources. Microsoft’s Antoine Leblond demonstrated the feature during Build which essentially lets developers easily use GPU and system RAM to store textures. This can be used to pull high resolution assets into a scene without overburdening the graphics card. For consumers, it could ultimately lead to an unprecedented amount of detail that won’t appear fuzzy or blurred when viewed close up.

Google remembers Roswell UFO incident with Doodle game

A detailed account of what took place in Roswell, New Mexico, exactly 66 years ago today may never be released to the public but in the meantime, Google is offering up their own explanation in the form of a Doodle game to celebrate the anniversary.
The latest interactive Doodle pits the player as an alien that has crash-landed on Earth. The object of the game is to help our alien friend get back to his home planet by finding missing pieces of his spacecraft. Players control the alien using mouse clicks and must solve a series of puzzles. Each step you successfully complete gets you one step closer to returning home.
Don’t expect a walk in the park, however, as the simple game actually takes a bit of thought and a little time to complete. That said, it is kind of fun if you’re looking for something to occupy your time. Once all of the components of the ship have been recovered, the alien boards the craft and zips away.
Upon completion, the game gives the user search results based on the Roswell UFO incident of 1947.
The game is loosely based on eyewitness reports of what many say actually happened 66 years ago – the crash of a UFO carrying extraterrestrial life. US officials ultimately said a military surveillance balloon is what crashed but most aren’t buying that story. Over the years, the incident has been a source of controversy that has helped to fuel multiple conspiracy theories.