SCCyberworld

Showing posts with label Bitcoin. Show all posts
Showing posts with label Bitcoin. Show all posts

Tuesday, January 21, 2014

PayPal Looks Ahead: Six Predictions for 2014

By David Marcus, President of PayPal

As the President of PayPal, I have a unique opportunity to work with peers and strategise with partners across many industries about solving real problems and delivering exciting new experiences for consumers and retailers. That leads to a pretty privileged view into what’s coming next. I have had some fascinating conversations about how technology is transforming shopping experiences, leading to my prediction of 6 main developments for 2014:

1. Traditional retail fights back
In recent years, technology innovation from companies has disrupted traditional retail by making it easy for consumers to browse in a store and then buy online at the cheapest possible price. It’s a practice called “showrooming” and in-store merchants understandably hate it. This year, retailers will start leveraging and converting their retail footprint into logistical assets to enable shoppers to buy anywhere they want: in-store, on mobile, and on the web, and get fast-delivery, or pick-up in store the same day. Local will be more important than ever – and from our perspective we couldn't be more excited about innovations like PayPal Beacon which will transform the retail environment for your local main street by bringing back opportunities for personalised service all driven by mobile.

2. Mobile will transform commerce forever
Many consumers are just beginning to experience the freedom, flexibility, and fun of mobile payments and shopping, and they’re going to want more. This will lead to a flood of new payment experiences built on technologies such as sensors, geolocation, and the cloud that will soon make standing in a long checkout line and paying with a card seem like something out of the Stone Age.

3. iOS and Android will drive a retail revolution
Last year, I predicted the beginning of the end of the fixed-location cash register in favour of mobile checkout technology. In 2014, I believe the entire retail infrastructure will follow suit. In less than four years since the launch of the iPad, tablets have become a fixture of our everyday lives. This year, they’ll become a standard tool in retail environments too, and merchants will use them for everything from Point of Sale to inventory, fulfilment, customer relationship management, and more.

4. Bitcoin will continue to gain ground (but not as a currency)
Bitcoin will continue to attract more people as a store of value and a speculative investment asset. I predict that the value of Bitcoin still has the potential to double this year, but I believe it will have a hard time becoming mainstream as a currency, due to its expected continued volatility amidst regulation authorities and governments figuring out what to make of the cryptocurrency.

5. The year of disruption . . .
I love disruption - it’s when rules get broken and new ideas are born and tested that things get interesting. This trend has been gathering momentum over the last year or so as smaller players in the payments industry power a wave of startups that use mobile payments to fuel segment-transforming new business models. (Full disclosure: PayPal recently acquired Braintree, which provides the payment technology engine behind disruptive startups like Uber, Airbnb, and OpenTable.)

In 2014, people will be seeing larger payments entities scramble to accelerate the pace of their innovation to catch up to these smaller and more nimble competitors. Meanwhile, smaller players will scramble to achieve the scale and experience needed to compete in a global business. As a result, billions of dollars will be at play in the payment industry, and 2014 will be a year of game-changing disruption.

6. . . . and consolidation in the payments industry
The payments industry has a lot of players, and no doubt there’s a ton of great innovation out there, but a lot of it works better in combination than on its own. Some of today’s bright young firms will never achieve the scale to survive without joining forces with someone bigger. This will lead to a wave of acquisitions in 2014. Meanwhile, new alliances will create intriguing partnerships that span payments, retail, and more. It simply won’t be the same industry in 12 months that it is today.

So that’s where I see payments headed in 2014. Whether you agree or disagree with my thought starters, I think we can all agree that this industry is in the midst of incredible and exciting change right now. It’s going to be an amazing ride over the next 12 months.

Friday, December 27, 2013

Trend Micro Discovers Bitcoin-mining Malwares is Rising in APAC Region

Japan and Australia are the most affected and Bitcoin users are advised to be wary of the possibility of personal information leak

Kuala Lumpur, 26 December 2013 - Bitcoin has become a well discussed topic during the past few weeks, especially when people find this virtual currency is tradable and as valuable as real currency. Because of this, Bitcoin has gained much attention and interest of hackers and cybercriminals. Trend Micro Inc. (TYO: 4704;TSE: 4704), the global leading internet security vendor has observed the spreading of Bitcoin-mining malwares recently and most of the affected countries are from the APAC region. Trend Micro reminds Bitcoin owners the importance of keeping their wallets safe from theft by separating their Bitcoin wallets and to manage the Bitcoin account offline which will diminish potential cyber threats.

“Bitcoin users have become the hot target for cybercriminals as Bitcoin transaction is permanent and has no reversal of charges. If you are the victim of credit card fraud, you can appeal to your bank to reverse the transaction and in many cases, they will.  On the other hand, once your Bitcoin wallet is compromised by hackers there is no recourse to undo the transaction. In fact, there is no regulator or authority that Bitcoin users can appeal to if they fall victim to theft or fraud” said Goh Chee Hoh, Managing Director, SEA Region, Trend Micro Inc.

Trend Micro Smart Protection Network has detected 3 malwares called BKDR_BTMINE, TROJ_COINMINE and HKTL_BITCOINMINE which turns infected systems into Bitcoin miner, making them virtual assets for the criminals. There are more than 12,000 PCs globally affected by Bitcoin-mining malwares which are causing severe slowdown of PC systems.

Trend Micro found that four out of the six countries with the highest number of Bitcoin-mining malwares infected computers are from the APAC region, with Japan being the top followed by Australia, India and Taiwan at the 3rd, 4th and 6th position respectively.

Executing malwares into the victims’ computer to mine Bitcoin is a new type of cybercrime. Bitcoin mining, the process which creates new Bitcoin created, is resource-intensive hence Bitcoin-mining malwares can slow down the infected computer due to the increased CPU load and subsequently raise power consumption.

To protect themselves from cyber threats, Trend Micro advises Bitcoin users to understand the way Bitcoin is being transacted and to manage it with the same caution and prudence that applies to real currency. Besides using security software to filter malwares, Trend Micro also suggests Bitcoin users not to put all Bitcoin in a single wallet. They should divide their Bitcoin into income account for inbound transaction, and expense account for outbound transactions. For additional precaution, they should also consider managing all the wallets offline. Trend Micro also reminds Bitcoin users that although Bitcoin is claimed to be “anonymous”, the transaction records are still in public and it leave traces. Consequently, given enough circumstantial evidence, criminals can identify and obtain the owners’ personal information.

For more information on Bitcoin threats and other security updates, please kindly follow Trend Micro Trendlabs Security Intelligence blog at http://blog.trendmicro.com/trendlabs-security-intelligence/bitcoin-price-hike-spurs-malware-wallet-theft/.

Wednesday, December 18, 2013

Kaspersky Lab makes its forecasts for the coming year

December 17, 2013¬Kaspersky Lab’s experts have made their predictions about 2014. Not surprisingly, much of what they have seen in their crystal balls is connected to the fall-out from Edward Snowden’s revelations.

End user forecast

Cybercriminals will target...

your privacy
After the Snowden scandal of 2013, people are determined to keep their private life under wraps despite the attentions of intelligence agencies around the world. That means protecting the information stored on their computers and devices and ensuring their online behavior remains confidential. This will lead to greater popularity for VPN services and Tor-anonymizers as well as increased demand for local encryption tools.

your money
In 2014, Kaspersky Lab’s experts expect cybercriminals to continue developing tools to steal cash – directly or indirectly. To plunder pockets directly, the fraudsters will further refine their tools designed to access the bank accounts of mobile device owners (mobile phishing, banking Trojans).  Mobile botnets will be bought and sold and will also be used to distribute malicious attachments on behalf of third parties. To support indirect thefts, it is likely that we will see more sophisticated versions of the Trojans which encrypt the data on mobile devices, preventing access to photos, contacts and correspondence until a decryption fee is handed over. Android-based smartphones will no doubt be the first to be targeted.

your Bitcoins
In 2014 Kaspersky Lab’s experts expect considerable growth in the number of attacks targeting Bitcoin users’ wallets, Bitcoin pools and stock exchanges. Find out how to keep your Bitcoins safe here.

Business forecast

for Internet service providers
A number of popular Internet services have already announced the implementation of additional measures to protect user data, for example, encryption of all data transmitted between their own servers. Implementing more sophisticated protection measures will continue, and is likely to become a key factor when users choose between rival web services.

for cloud storage providers
Hackers are targeting cloud service employees, seeing them as the weakest link in the security chain. A successful attack here could hand cybercriminals the keys to huge volumes of data. In addition to data theft attackers may be interested in deleting or modifying information - in some cases manipulated misinformation could be worth even more to those who commission the attacks. This is an on-going trend.

for software developers
The theft of popular product sources (gaming industry, mobile apps developers, etc) gives attackers an excellent opportunity to find vulnerabilities in the products and then to use them for their own fraudulent purposes. In addition, if cybercriminals have access to the victim’s repositories, they can modify the program source code and embed backdoors into it.

for rivals
Snowden’s leaks have demonstrated that one of the goals of cyber espionage between states is to provide economic aid to “friendly” companies. This factor has broken down ethical barriers which initially restrained business from using unconventional methods to compete with their rivals. In the new realities of cyberspace, businesses are contemplating the possibility of conducting this kind of activity for themselves. Companies will employ cyber-mercenaries, organized groups of qualified hackers who can offer bespoke cyber-espionage services.

The World Wide Web forecast
“The Internet has begun to break up into national segments. Snowden’s revelations have intensified the demand for rules prohibiting the use of foreign services. Individual countries are no longer willing to let a single byte of information out of their networks. These aspirations will grow ever stronger and legislative restrictions will inevitably transform into technical prohibitions. The next step will most likely be attempts to limit foreign access to data inside a country. As this trend develops further it may lead at some point to the collapse of the current Internet, which will break into dozens of national networks. The shadowy Darknet then will be the only truly world-wide web”, says Alexander Gostev, Chief Security Expert, Global Research & Analysis Team.

Several countries have adopted or are planning to adopt legislation prohibiting the use of foreign services. In November, Germany announced that all communications between the German authorities would be fully locked within the country. Brazil has announced its plans to build an alternative Internet channel so as not to use the one that goes through Florida (USA).

The full report is available on securelist.com

Wednesday, December 4, 2013

Key security incidents that shaped threat landscape in 2013

Petaling Jaya, December 4 2013. Some of the revelations of the past year raised questions about the way we use the Internet nowadays and the type of risks we face. In 2013 advanced threat actors have continued large-scale operations, and cyber-mercenaries, specialist APT groups “for hire” which focus on hit-and-run operations emerged. Hacktivists were constantly in the news, together with the term “leak”, which is sure to put fear into the heart of any serious sys-admin out there. In the meantime, cybercriminals were busy devising new methods to steal money or Bitcoins.

Privacy loss: Lavabit, Silent Circle, NSA and the loss of trust

No ITSec overview of 2013 would be complete without mentioning Edward Snowden and the wider privacy implications of his revelations. One of the first visible effects was the shutdown of encrypted email services such as Lavabit and Silent Circle. The reason was their inability to provide such services under pressure from law enforcement and other governmental agencies. Another story which has implications over privacy is the NSA sabotage of the elliptic curve cryptographic algorithms released through NIST.

New “old” cyber-espionage campaigns: up to 1800 victim organizations in 2013
• The majority of the cyber-espionage campaigns that Kaspersky Lab’s analysts have seen were designed to steal data from governmental agencies and research institutions – Red October, NetTraveler, Icefog and MiniDuke all behave this way.
• The most widespread campaign of the year was NetTraveler espionage which affected victims from 40 countries all over the world.
• For the first time ever cybercriminals harvested information from mobile devices connected tothe victims’ networks – clear recognition of importance of mobile to hackers.
• Red October, MiniDuke, NetTraveler and Icefog all started by ‘hacking the human’. They employed spear-phishing to get an initial foothold in the organizations they targeted

 “We predicted 2012 to be revealing and 2013 to be eye opening. That forecast proved correct – 2013 showed that everybody is in the same boat. In truth, any organization or person can become a victim. Not all attacks involve high profile targets, or those involved in ‘critical infrastructure’ projects. Those who hold data could be of value to cybercriminals, or they can be used as a ‘stepping-stones’ to reach other targets. This point was amply illustrated by Icefog attacks this year. They were part of an emerging trend that appeared in 2013 – attacks by small groups of cyber-mercenaries who conduct small hit-and-run attacks. Going forward, we predict that more of these groups will appear as an underground black market for ‘APT’ services begins to emerge”, - Costin Raiu, Director of the Global Research and Analysis team, Kaspersky Lab commented.

Stealing money – either by directly accessing bank accounts or by stealing confidential data – is not the only motive behind security breaches. They can also be launched to undermine the reputation of the company being targeted, or as a form of political or social protest. Ongoing hacktivist activities have continued this year as well. ‘Anonymous’ group has claimed responsibility for attacks on the US Department of Justice, Massachusetts Institute of Technology and the web sites of various governments. Those claiming to be part of the ‘Syrian Electronic Army’ claimed responsibility for hacking the Twitter account of Associated Press and sending a false tweet reporting explosions at the White House – which wiped $136 billion off the DOW. For those with the relevant skills, it became easier to launch an attack on a web site than it is to co-ordinate the real-world protests.

Bitcoins ruling the world
The Bitcoin system was implemented back in 2009. In the beginning, this crypto currency was used by hobbyists and mathematicians. Soon, others – mostly ordinary people, but also cybercriminals and terrorists, joined them. They provide an almost anonymous and secure means of paying for goods. In the wake of the surveillance stories of 2013, there is perhaps little surprise that people are looking for alternative forms of payment. And it is gaining popularity – in November 2013, the mark surpassed the 400$ for one Bitcoin.

The methods used by cybercriminals to make money from their victims are not always subtle. Apart from Bitcoins, which could potentially be stolen, ‘ransomware’ programs became a popular means of making easy money – cybercriminals block access to a computer’s file system, or encrypt data files stored on the computer. Then they warn you that you must pay in order to recover your data. This was the case with the Cryptolocker Trojan. The cybercriminals give their victims only three days to pay up, accepting different forms of payment, including Bitcoin.

The full report is available on securelist.com.