Ofer For You (1)

Showing posts with label Spying. Show all posts
Showing posts with label Spying. Show all posts

Wednesday, 26 November 2014

Verizon Wireless Injects Identifiers to Track Mobile Customers’ Online Activities





The Nation's largest telecom operator 'Verizon Wireless' is tracking its customers' mobile internet traffic by adding a token to Web requests traveling over its network, in order to facilitate targeted advertising even if a user has opted out of their Customer Proprietary Network Information (CPNI) options.

The Precision Market Insights division of Verizon is collecting users' data from more than two years with the launch of the Unique Identifier Token Header (UIDH) under its Relevant Mobile Advertising program. The company also expanded its program to cover all Verizon Wireless subscribers.

UIDH TRACKS CUSTOMERS' EVERY MOVE ON WEB
When consumers visit certain websites or mobile apps, The Verizon network is adding cookie-like X-UIDH header tokens to Web requests traveling over its network with a unique value/identifier for every particular mobile device.

This Verizon's solution is called the PrecisionID, which is being used to create a detailed picture of users' interests and help clients tailor advertisements, according to Verizon's own documentation.

The outcome is that the second largest cellular communication provider in U.S. Verizon Wireless is sending a unique identifier for you to each and every unencrypted website you visit using your mobile device, which means that, at worst scenario, advertisers can track your every move everywhere you have been.

Though the company started navigating the service two years ago, security experts began warning of the issue this week. "Verizon is rewriting your HTTP requests to insert a permacookie? Terrible," senior staff technologist with the Electronic Frontier Foundation, Jacob Hoffman-Andrews, tweeted about the issue on Wednesday.

USERS' EVERY PERSONAL DATA IS COLLECTED
Verizon Wireless Injects Identifiers to Track Mobile Customers’ Online Activities
The UIDH value changes each week would provide targeted advertisements under Verizon's Precision Market Insights from participating advertisers which could request location and market-segment information. The information used by advertisers include subscribers' postal address, device types and language preferences to build profiles along with gender, age and hobby and personal interests.
"In addition, we will use an anonymous, unique identifier we create when you register on our websites. This may allow an advertiser to use information they have about your visits to online websites to deliver marketing messages to mobile devices on our network," Verizon said on its website. "We do not share information that identifies you personally outside of Verizon as part of this program. [Some of this information was] obtained from other companies."
VERIZON TRACKS EVEN YOU'VE OPT OUT
The strange thing is you can't do anything about the issue because even if you opt out of all the Verizon tracking, by either using a privacy mode in your browser and enable Do Not Track, or by using a different browser, or even if you change to a new phone, or use a tethered laptop for browsing, in all ways you are not safe.

UIDH allows Verizon to link a website visitor to its own internal profiles, in an attempt to allow client websites to target advertising at specific segments of the consumer market.

HOW TO PROTECT YOURSELF
Though, Verizon offers privacy settings, but they don't prevent sending the X-UIDH header. The only known solution left with you is to encrypt all your browsing. You can do this using HTTPS Everywhere, but this only works if the website supports HTTPS. Because this issue is already being exploited in the wild so the best solution is to use full encryption using a VPN like Tunnelbear or TOR.

Next, let's get Verizon Wireless to change this policy, by arguing that the service is essentially tracking users and that companies paid for a fundamental service that should not be using the data for secondary purposes.

By "Kunal Vohra", Director@H2K

Having Problem..??!!! Connect with Admin
BBM: 7F72A48D


 Kunal Vohra
Download Our Official Android App & Get Free Internet



"The Hackers Street"

For Daily Updates 

Wednesday, 29 October 2014

Sony Xperia Devices Secretly Sending User Data to Servers in China



Sony Xperia Devices Secretly Sending User Data to Servers in China
If you own a Sony smartphone either the Android 4.4.2 or 4.4.4 KitKat firmware then inadvertently you may be transmitting your data back to the servers in China, even if you haven’t installed any application.

Quite surprising but it’s true. I know many of you haven’t expected such practices from a Japanese company, but reports popping up at several forums suggest that some new Sony Xperia handsets seem to contain theBaidu spyware.

MYSTERIOUS BAIDU SPYWARE
About a month ago, a group of community users of Sony smartphone detected the presence of a strange folder, named “Baidu”, mysteriously appeared from among those present in various versions of Android for these handsets.

The creepy part is that the folder is created automatically without the owners permission and there is no way of deleting it. Even if someone tries to remove it, it instantly reappears as well as unticking the folder from device administrator equally seems to do nothing, neither does starting the phone in Safe Mode.
Just unpacked my Sony Z3 compact, haven't installed a single app and its connecting to China. I am not so concerned about the folder itself but my phone now has a constant connection to an IP address in Beijing which I am not too happy about.” Reddit user commented.
The Baidu folder appears to be created by Sony’s ‘my Xperia’ service each time a connection is made and is reported to be sending pings to China. There is no further information known on what these pings are transmitting but nevertheless they do seem to be transmitting.

PERSONAL INFORMATION SEND TO CHINA
Going deep, several users reported they found that the Chinese government is able to detect the status and identity of the device, take pictures and make videos without the consent of the user. A user, going by the handle Elbird, posted on Sony Forums that with the help of Baidu folder, the Chinese Government can:
  • Read status and identity of your device
  • Make pictures and videos without your knowledge
  • Get your exact location
  • Read the contents of your USB memory
  • Read or edit accounts
  • Change security settings
  • Completely manage your network access
  • Couple with bluetooth devices
  • Know what apps you are using
  • Prevent your device from entering sleep mode
  • Change audio settings
  • Change system settings
AFFECTED PRODUCTS
Sony Xperia Devices Secretly Sending User Data to Servers in China

Thankfully this is a spyware and you can check to see if you have or not. If you see the folder named Baidu in your device then your device contains the spyware. But, for users it isn't the folder which seems to be the real cause for concern, though; it’s the fact that the phones open a connection to servers.

According to the reports affected devices include the new Sony Xperia Z3 and Z3 Compact, and several users from the Reddit community have also reported about the presence of this folder on their mobile phones, too — and not necessarily phones made by Sony. One owns an HTC One M7, another an HTC One X, a few others the OnePlus One.

STEPS TO DISABLE BAIDU SPYWARE
  1. Backup your important data and factory reset the device.
  2. Turn on the device and go to Settings -> Apps -> Running and Force stop both “MyXperia” apps.
  3. Then remove the baidu folder using File Kommander app.
  4. Go to Settings -> About Phone -> Click 7 times on the Build Number to enable developer mode.
  5. Download or Install the Android SDK on your computer and then connect the Sony device to it using USB cable.
  6. Run the adb tool terminal : adb shell 
  7. In adb shell, type the command: pm block com.sonymobile.mx.android
  8. Exit adb shell
  9. Reboot the device.
Note that the spyware does not necessarily affect the process or functionality of your mobile devices, so you shouldn't be worried in this respect. Sony has not officially responded to this ‘baidu’ folder issue. 


However, the company has recognized the issue and has said that in the next release the problem will be fixed. Unless Sony can roll out some kind of fix in the near future then it seems you might have to wait until Lollipop rolls out in January before you can get rid of Baidu.

Recently Chinese smartphone manufacturer Xiaomi has been called out for spying on personal user data using their smartphones. According to F-Secure Xiaomi Smartphones were sending user data back to the servers based in China.

By "Kunal Vohra", Director@H2K

Still Having Problem..!!! Connect with Admin
BBM: 7F72A48D


 Kunal Vohra
Download Our Official Android App & Get Free Internet



"The Hackers Street"

For Daily Updates