Archive

Posts Tagged ‘insecurity’

Samsung innocent of laptop bugging, insecurity firm apologises

April 3rd, 2011 No comments

KOREAN HARDWARE GIANT Samsung didn’t put keylogging software on its laptops, and the company partly responsible for causing the fuss has made a grovelling apology.

A report accused Samsung of releasing two of its laptops with a pre-installed keylogger, which is able to log keystrokes and take screenshots. It resulted in a major PR blow-up, with the Korean firm forced to issue a statement denying that it had stuck Starlogger in its hardware to spy on people.

In a blog post, the insecurity firm Gfi Labs confirmed that the keylogger detection was based on a false positive in its Vipre antivirus software. Alex Eckelberry, general manager of Gfi security, said, “We have no one to blame but ourselves.”

Gfi Lab’s Vipre software detected C:\WINDOWS\SL, the Slovenian language directory for Windows Live, as malware. This is the same directory path used by the StarLogger keylogger, hence the confusion.

Eckelberry said of the directory, “At some point several years after the original detection was written, Windows Live started using that directory to install Slovenian language files for Windows Live.”

“Samsung started pre-installing Windows Live, including all the languages, and there you have the problem we’re having today.”

Although it was a big mistake by Gfi, rival insecurity firm F-Secure stuck up for the company, saying the original report was flawed.

F-Secure’s security chief Mikko Hyponnen said in a blog post, “Unfortunately Mohamed Hassan (CISSP),who did the original analysis did not double-check his findings and blamed Samsung instead.”

“Apparently he did not look at the contents of the ‘SL’ folder at all.” µ

McAfee buys another mobile insecurity outfit

July 31st, 2010 No comments

INSECURITY OUTFIT McAfee has bought its second mobile security company in as many months.

It has bought Tencube, which makes remote location wipe and locking technology, for an undisclosed amount of cash.

In June McAfee bought Trust Digital for that outfit’s mobile management and security tools.

What appears to interest McAfee is Tencube’s Wavesecure service, which includes remote locate, lock, backup and wipe technology that allows users to find and secure lost mobile phones.

Basically it means that the phone will also automatically go into lock-down mode if it is used with an unauthorized wireless account. It will then ring up the user’s emergency contact number and say where it is.

Wavesecure locked phones also show a permanent message on the screen explaining how to return the phone to its owner, at least until the battery runs out.

McAfee has a cunning plan to offer a child locator service using the technology, which means that you will have to take your child’s phone away from them when you try to lose them. µ