<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Phone Security Software &#124; Mobile Secure Communications &#124; Wireless Security Software &#187; Information Security</title>
	<atom:link href="http://blog.gold-lock.com/category/information-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.gold-lock.com</link>
	<description>Everything you need to know about encryption and information security</description>
	<lastBuildDate>Fri, 18 Mar 2011 07:22:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>Hackers penetrate RSA&#8217;s servers</title>
		<link>http://blog.gold-lock.com/2011/03/18/hackers-penetrate-rsas-servers/</link>
		<comments>http://blog.gold-lock.com/2011/03/18/hackers-penetrate-rsas-servers/#comments</comments>
		<pubDate>Fri, 18 Mar 2011 07:22:09 +0000</pubDate>
		<dc:creator>Gold Lock Team</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[SecurID]]></category>
		<category><![CDATA[two-factor]]></category>

		<guid isPermaLink="false">http://blog.gold-lock.com/?p=459</guid>
		<description><![CDATA[RSA was the victim of an extremely sophisticated cyber attack which resulted in the possible theft of the two-factor code used by their SecurID products. The exact risk to customers isn’t clear, but there is risk that the assurance of two factor authentication has been reduced.]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone" title="SecurID Targeted by Hackers" src="http://www.people.fas.harvard.edu/~brunelle/091117.odyssey/img/rsakeyfob.gif" alt="" width="228" height="125" /></p>
<p>RSA was the victim of an extremely sophisticated cyber attack which resulted in the possible theft of the two-factor code used by their SecurID products.</p>
<p>The exact risk to customers isn’t clear, but there is risk that the assurance of two factor authentication has been reduced.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gold-lock.com/2011/03/18/hackers-penetrate-rsas-servers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Confidential Data Not Safe On Solid State Drives</title>
		<link>http://blog.gold-lock.com/2011/02/18/confidential-data-not-safe-on-solid-state-drives/</link>
		<comments>http://blog.gold-lock.com/2011/02/18/confidential-data-not-safe-on-solid-state-drives/#comments</comments>
		<pubDate>Fri, 18 Feb 2011 08:34:11 +0000</pubDate>
		<dc:creator>Gold Lock Team</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[secure erase tools]]></category>
		<category><![CDATA[Solid State Disk]]></category>
		<category><![CDATA[Solid State Drive]]></category>
		<category><![CDATA[SSD]]></category>
		<category><![CDATA[UCSD]]></category>
		<category><![CDATA[University of California]]></category>

		<guid isPermaLink="false">http://blog.gold-lock.com/?p=454</guid>
		<description><![CDATA[Researchers at University of California have torn apart Solid State Drives (SSDs) and have found remnant data even after running several open source and commerical secure erase tools. They&#8217;ve also proposed some changes to SSDs that would make them more secure.  Once information is stored on SSDs, getting it off isn&#8217;t easy at all.]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone" title="SSD - Keeps confidential information longer than intended?" src="http://www.gizmomart.com.au/images/ssd.jpg" alt="" width="264" height="256" /></p>
<p>Researchers at University of California have torn apart Solid State Drives (SSDs) and have found remnant data even after running several open source and commerical secure erase tools.</p>
<p>They&#8217;ve also proposed some changes to SSDs that would make them more secure.  Once information is stored on SSDs, getting it off isn&#8217;t easy at all.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gold-lock.com/2011/02/18/confidential-data-not-safe-on-solid-state-drives/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chinese Hackers Penetrate Canadian Government</title>
		<link>http://blog.gold-lock.com/2011/02/18/chinese-hackers-penetrate-canadian-government/</link>
		<comments>http://blog.gold-lock.com/2011/02/18/chinese-hackers-penetrate-canadian-government/#comments</comments>
		<pubDate>Fri, 18 Feb 2011 08:28:29 +0000</pubDate>
		<dc:creator>Gold Lock Team</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[Canada]]></category>
		<category><![CDATA[Chine]]></category>
		<category><![CDATA[classified information]]></category>
		<category><![CDATA[federal information]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[unprecedented cyberattack]]></category>

		<guid isPermaLink="false">http://blog.gold-lock.com/?p=449</guid>
		<description><![CDATA[An unprecedented cyberattack on the Canadian government from China has given foreign hackers access to highly classified federal information, and forced at least two key departments off the internet. The attack, first detected in early January, left Canadian counter-espionage agents scrambling to determine how much sensitive government information may have been stolen and by whom. [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone" title="Chinese Hackers Attack Canadian Government" src="http://upload.wikimedia.org/wikipedia/commons/a/a4/Flag_of_Canada_merged_with_the_Flag_of_China_(2-1).jpg" alt="" width="384" height="193" /></p>
<p>An unprecedented cyberattack on the Canadian government from China has given foreign hackers access to highly classified federal information, and forced at least two key departments off the internet.</p>
<p>The attack, first detected in early January, left Canadian counter-espionage agents scrambling to determine how much sensitive government information may have been stolen and by whom. Canadian public sentiment towards China is deteriorating.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gold-lock.com/2011/02/18/chinese-hackers-penetrate-canadian-government/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Browsing, Email, and Phone Calls &#8211; Recorded</title>
		<link>http://blog.gold-lock.com/2010/10/23/browsing-email-and-phone-calls-recorded/</link>
		<comments>http://blog.gold-lock.com/2010/10/23/browsing-email-and-phone-calls-recorded/#comments</comments>
		<pubDate>Sat, 23 Oct 2010 08:23:19 +0000</pubDate>
		<dc:creator>Gold Lock Team</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[communication]]></category>
		<category><![CDATA[e-mail communications]]></category>
		<category><![CDATA[phone interception]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[UK government]]></category>
		<category><![CDATA[UK police]]></category>

		<guid isPermaLink="false">http://blog.gold-lock.com/?p=444</guid>
		<description><![CDATA[The UK government plans to introduce legislation that will allow the police to track every phone call, email, text message and website visit made by the public. The information will include who is contacting whom, when and where and which websites are visited, but not the content of the conversations or messages. Every communications provider [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.gold-lock.com/wp-content/uploads/2010/10/uk-database.jpg"><img class="alignnone size-full wp-image-445" title="UK Database" src="http://blog.gold-lock.com/wp-content/uploads/2010/10/uk-database.jpg" alt="" width="300" height="300" /></a></p>
<p>The UK government plans to introduce legislation that will allow the police to track every phone call, email, text message and website visit made by the public. The information will include who is contacting whom, when and where and which websites are visited, but not the content of the conversations or messages. Every communications provider will be required to store the information for at least a year.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gold-lock.com/2010/10/23/browsing-email-and-phone-calls-recorded/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A GSM Interceptor = $1,500</title>
		<link>http://blog.gold-lock.com/2010/08/02/a-gsm-interceptor-1500/</link>
		<comments>http://blog.gold-lock.com/2010/08/02/a-gsm-interceptor-1500/#comments</comments>
		<pubDate>Mon, 02 Aug 2010 16:58:33 +0000</pubDate>
		<dc:creator>Gold Lock Team</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[$1500 GSM Interceptor]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking tools]]></category>
		<category><![CDATA[RF antennas]]></category>
		<category><![CDATA[SIM cards]]></category>

		<guid isPermaLink="false">http://blog.gold-lock.com/?p=439</guid>
		<description><![CDATA[A security researcher created a $1,500 cell phone base station kit (including a laptop and two RF antennas) that tricks cell phones into routing their outbound calls through his device, allowing someone to intercept even encrypted calls (non Gold Lock) in the clear. Most of the price is for the laptop he used to operate [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.gold-lock.com/wp-content/uploads/2010/08/1500-Dollar-Interceptor.jpg"><img class="alignnone size-medium wp-image-440" title="1500 Dollar Interceptor" src="http://blog.gold-lock.com/wp-content/uploads/2010/08/1500-Dollar-Interceptor-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p>A security researcher created a $1,500 cell phone base station kit (including a laptop and two RF antennas) that tricks cell phones into routing their outbound calls through his device, allowing someone to intercept even encrypted calls (non Gold Lock) in the clear. Most of the price is for the laptop he used to operate the system. The device tricks the phones into disabling encryption and records call details and content before they are routed on their proper way through voice-over-IP. The low-cost, home-brewed device mimics more expensive devices already used by intelligence and law enforcement agencies — called IMSI catchers — that can capture phone ID data and content. The devices essentially spoof a legitimate GSM tower and entice cell phones to send them data by emitting a signal that&#8217;s stronger than legitimate towers in the area. Encrypted calls are not protected from interception because the rogue tower can simply turn it off. Although the GSM specifications say that a phone should pop up a warning when it connects to a station that does not have encryption, SIM cards disable that setting so that alerts are not displayed.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gold-lock.com/2010/08/02/a-gsm-interceptor-1500/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>India Demands Easier Interception, Threatens RIM, Skype and Google</title>
		<link>http://blog.gold-lock.com/2010/07/03/indian-government-demands-formats-easier-to-intercept-threatens-rim-skype-and-google/</link>
		<comments>http://blog.gold-lock.com/2010/07/03/indian-government-demands-formats-easier-to-intercept-threatens-rim-skype-and-google/#comments</comments>
		<pubDate>Sat, 03 Jul 2010 09:34:04 +0000</pubDate>
		<dc:creator>Gold Lock Team</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://blog.gold-lock.com/?p=431</guid>
		<description><![CDATA[India&#8217;s Department of Telecommunications has been asked by the government to serve a notice to Skype and Research In Motion to ensure that their email and other data services comply with formats that can be read by security and intelligence agencies, or face a ban in India if they do not comply within 15 days. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.gold-lock.com/wp-content/uploads/2010/07/rim-blackberry-logo-1.jpg"><img class="alignnone size-medium wp-image-432" title="Blackberry Interception by Government" src="http://blog.gold-lock.com/wp-content/uploads/2010/07/rim-blackberry-logo-1-300x202.jpg" alt="" width="300" height="202" /></a></p>
<p>India&#8217;s Department of Telecommunications has been asked by the government to serve a notice to Skype and Research In Motion to ensure that their email and other data services comply with formats that can be read by security and intelligence agencies, or face a ban in India if they do not comply within 15 days. A similar notice is also being sent to Google, asking it to provide access to content on Gmail in a readable format.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gold-lock.com/2010/07/03/indian-government-demands-formats-easier-to-intercept-threatens-rim-skype-and-google/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tor &#8211; Anonymity Online?</title>
		<link>http://blog.gold-lock.com/2010/06/02/tor-anonymity-online/</link>
		<comments>http://blog.gold-lock.com/2010/06/02/tor-anonymity-online/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 14:35:25 +0000</pubDate>
		<dc:creator>Gold Lock Team</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[exit routers]]></category>
		<category><![CDATA[Julian Assange]]></category>
		<category><![CDATA[New Yorker]]></category>
		<category><![CDATA[Tor]]></category>
		<category><![CDATA[Wikileaks]]></category>

		<guid isPermaLink="false">http://blog.gold-lock.com/?p=424</guid>
		<description><![CDATA[The New Yorker is featuring a long and detailed profile of Julian Assange, founder of Wikileaks. From this Wired&#8217;s Threat Level pulls out one salient detail: that Wikileaks&#8217; initial scoop came from documents intercepted from Tor exit routers. The eavesdropping was pulled off by a Wikileaks activist — neither the New Yorker nor Wired knows [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.gold-lock.com/wp-content/uploads/2010/06/WikiLeaks-540x304.jpg"><img class="alignnone size-full wp-image-425" title="WikiLeaks Original Documents" src="http://blog.gold-lock.com/wp-content/uploads/2010/06/WikiLeaks-540x304.jpg" alt="" width="324" height="182" /></a></p>
<p>The New Yorker is featuring a long and detailed profile of Julian Assange, founder of Wikileaks. From this Wired&#8217;s Threat Level pulls out one salient detail: that Wikileaks&#8217; initial scoop came from documents intercepted from Tor exit routers. The eavesdropping was pulled off by a Wikileaks activist — neither the New Yorker nor Wired knows who or even in what country he or she resides.</p>
<p>The siphoned documents, supposedly stolen by Chinese hackers or spies who were using the Tor (torproject.org) network to transmit the data, were the basis for Wikileaks founder Julian Assange&#8217;s assertion in 2006 that his organization had already &#8216;received over one million documents from 13 countries&#8217; before his site was launched &#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gold-lock.com/2010/06/02/tor-anonymity-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quantum Encryption Hacked</title>
		<link>http://blog.gold-lock.com/2010/05/22/quantum-encryption-hacked/</link>
		<comments>http://blog.gold-lock.com/2010/05/22/quantum-encryption-hacked/#comments</comments>
		<pubDate>Sat, 22 May 2010 09:43:41 +0000</pubDate>
		<dc:creator>Gold Lock Team</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[crypto noise level]]></category>
		<category><![CDATA[cryptographers]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[interception]]></category>
		<category><![CDATA[Quantum Cryptography]]></category>
		<category><![CDATA[University of Toronto]]></category>

		<guid isPermaLink="false">http://blog.gold-lock.com/?p=421</guid>
		<description><![CDATA[Yesterday, it was announced that physicists at the University of Toronto in Canada have successfully attacked a commercial quantum cryptography system for the first time in history. Quantum cryptography was considered by some to be unbreakable, however, like many other security systems, the technology was built making various assumptions, and in the real-world not all [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.gold-lock.com/wp-content/uploads/2010/05/Quantum.jpg"><img class="alignnone size-full wp-image-422" title="Quantum Encryption Hacked" src="http://blog.gold-lock.com/wp-content/uploads/2010/05/Quantum.jpg" alt="" width="400" height="359" /></a></p>
<p>Yesterday, it was announced that physicists at the University of Toronto in Canada have successfully attacked a commercial quantum cryptography system for the first time in history.</p>
<p>Quantum cryptography was considered by some to be unbreakable, however, like many other security systems, the technology was built making various assumptions, and in the real-world not all these assumptions have proved to be reliable. In this case, the assumption that the physicists targeted relates to the level of tolerance for noise and associated communication errors.</p>
<p>In order to ensure the security is still intact, quantum cryptographic systems monitor the communication error rate, because a high error rate is indicative that the communication is being intercepted. Because it is impossible to eliminate errors entirely, the cryptographers assumed that an acceptable level of noise or error rate would be 20%.</p>
<p>However, in practice, it was found that there are always errors introduced during the preparation of quantum states and this extra noise exposes the system to an &#8220;intercept and resend attack&#8221;. By intercepting and reading some quantum bits and then sending them on, in such a way that the error rate remains at only 19%, the physicists demonstrated that it is possible to break quantum encryption on a commercially available system.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gold-lock.com/2010/05/22/quantum-encryption-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Governments May Forge SSL Certificates</title>
		<link>http://blog.gold-lock.com/2010/03/27/governments-may-forge-ssl-certificates/</link>
		<comments>http://blog.gold-lock.com/2010/03/27/governments-may-forge-ssl-certificates/#comments</comments>
		<pubDate>Sat, 27 Mar 2010 06:47:40 +0000</pubDate>
		<dc:creator>Gold Lock Team</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[certificate authorities]]></category>
		<category><![CDATA[disclosure of private data]]></category>
		<category><![CDATA[filefox]]></category>
		<category><![CDATA[firefox plugin]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[ssl certificate]]></category>
		<category><![CDATA[Verisign]]></category>

		<guid isPermaLink="false">http://blog.gold-lock.com/?p=415</guid>
		<description><![CDATA[Researchers are poking holes in the chain of trust for SSL certificates which protect sensitive data. According to these hypothesized attacks, governments could compel certificate authorities to give them phony certificates that are signed by the CA, which are then used to perform man in the middle attacks. They point out that Verisign already makes [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_416" class="wp-caption alignnone" style="width: 364px"><a href="http://blog.gold-lock.com/wp-content/uploads/2010/03/ssl.jpg"><img class="size-full wp-image-416 " title="Is SSL Becoming Pointless?" src="http://blog.gold-lock.com/wp-content/uploads/2010/03/ssl.jpg" alt="" width="354" height="236" /></a><p class="wp-caption-text">Is SSL Becoming Pointless?</p></div>
<p>Researchers are poking holes in the chain of trust for SSL certificates which protect sensitive data. According to these hypothesized attacks, governments could compel certificate authorities to give them phony certificates that are signed by the CA, which are then used to perform man in the middle attacks.</p>
<p>They point out that Verisign already makes large sums of money by facilitating the disclosure of US consumers&#8217; private data to US government law enforcement. The researchers are developing a Firefox plugin that checks past certificates and warns of anomalies in the issuing country, but not much can help if government starts spying on the secure connections of its own citizens.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gold-lock.com/2010/03/27/governments-may-forge-ssl-certificates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Memory Cards of 3,000 Phones Infected By Malware</title>
		<link>http://blog.gold-lock.com/2010/03/20/memory-cards-of-3000-phones-infected-by-malware/</link>
		<comments>http://blog.gold-lock.com/2010/03/20/memory-cards-of-3000-phones-infected-by-malware/#comments</comments>
		<pubDate>Sat, 20 Mar 2010 05:37:17 +0000</pubDate>
		<dc:creator>Gold Lock Team</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Conficker worm]]></category>
		<category><![CDATA[HTC]]></category>
		<category><![CDATA[Mariposa botnet]]></category>
		<category><![CDATA[memory cards]]></category>
		<category><![CDATA[microSD]]></category>
		<category><![CDATA[password stealer]]></category>
		<category><![CDATA[vodafone]]></category>

		<guid isPermaLink="false">http://blog.gold-lock.com/?p=386</guid>
		<description><![CDATA[On March 8, a security company  employee plugged a newly ordered HTC Magic phone from Vodafone into a Windows computer, where it triggered an alert from the antivirus software. Further inspection of the phone found the device&#8217;s 8GB microSD memory card was infected with a client for the now-defunct Mariposa botnet, the Conficker worm, and [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.gold-lock.com/wp-content/uploads/2010/03/infected-memory-cards.jpg"><img class="size-full wp-image-387     alignnone" title="Infected Memory Cards" src="http://blog.gold-lock.com/wp-content/uploads/2010/03/infected-memory-cards.jpg" alt="Best Encryption Software" width="400" height="400" /></a></p>
<p>On March 8, a security company  employee plugged a newly ordered HTC Magic phone from Vodafone into a Windows computer, where it triggered an alert from the antivirus software.</p>
<p>Further inspection of the phone found the device&#8217;s 8GB microSD memory card was infected with a client for the now-defunct Mariposa botnet, the Conficker worm, and a password stealer for the Lineage game.</p>
<p>At that point it was at thought to be an issue with a specific refurbished phone.</p>
<p>On Wednesday another phone surfaced with traces of the Mariposa botnet. And now Vodafone is saying that as many as 3,000 HTC Magic phones <a href="http://www.itworld.com/[primary-term]/101644/malware-infected-memory-cards-3000-vodafone-mobiles" target="_blank">may be affected</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gold-lock.com/2010/03/20/memory-cards-of-3000-phones-infected-by-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

