So what’s a poor iPhone user to do once their initial 18 or 24 months with O2 are up? For once the answer is very simple indeed: rather than waste time and effort trying to hack your phone with hardware or software, which can all-too-easily end by “bricking” the device, just ask O2 to unlock it for you!
That’s right, O2 will be happy to remove the lock from any iPhone it originally supplied. O2 even provides an unlocking web page to help you do this (although it isn’t publicised particularly well).
What you might find surprising is that this unlocking service is free, and O2 will even unlock iPhones that are still under contract, although it goes without saying that you’ll have to honour what remains of that contract. They’ll also unlock PAYG phones, although there’s a £15 charge for that.
I used this facility to unlock an iPhone 3G that Apple’s PR team gave me some time ago – I simply shoved an O2 SIM into it, loaded it up with £20 credit and then filled in the unlock form. Within a few days a message popped up on my phone saying that it was unlocked.
Actually, it wasn’t really unlocked – if you shove another network’s SIM in it you’ll get the dreaded “invalid SIM” message. What you need to do is, with this other SIM in the iPhone, connect to your PC or Mac and fire up iTunes. It will reboot itself and then it will recognise the SIM.
If that SIM comes from one of Apple’s official mobile network partners (O2, Vodafone and Orange in the UK), you should even find the APN correctly configured for network access. It’s a shame that more
iPhone owners don’t realise that O2 offers this service, but perhaps this column will go some way towards remedying that.
Saturday, July 23, 2011
Don't bank on your phone: Too easily hacked
Alex Fidgen of MWR InfoSecurity, one of the biggest cybercrime-busting outfits in Britain came out with a very scary statement this week.
It's normal line of business is to legally hack into computers to test and improve their company's security. More recently MWR has turned its attention to smartphones and found that it can crack open every new handset it sees.
"The mobile phone industry is not fit for purpose, especially for financial transactions," says Fidgen. "The evidence is irrefutable. You cannot be assured of security with modern smartphones. As soon as the handset is compromised, then any data is up for grabs."
Fidgen says the fault lies with the handset manufacturers rather than the network providers or banks. In the race to bring new phones and new features to the market, many have left security low on the agenda.
Yet modern smartphones are in effect PCs with phones attached and, particularly when they are used in public Wi-Fi hotspots, they can become fatally compromised.
Trojans can enter a smartphone in many devious ways. All you have to do is click on a link or attachment that contains the virus, and within seconds it can secretly seize control of the phone. That link might be a tinyurl in Twitter. The attachment could be a vCard, the standard format for sending a business card to a phone.
Or it could be that you are accessing a website in a cafe. At Wi-Fi hotspots, fraudsters create bogus gateways, known as "evil twins", to which the latest mobile phones will automatically connect.
As the Guardian revealed in April, once a connection is established, all the information passing through the gateway can be read directly or decrypted, allowing fraudsters to harvest user names, passwords and messages.
Until now, these attacks have been rare but now experts say that's just because smartphones are still taking off. "We're walking into a minefield," says Fidgen, who has been warning about the risks of mobile banking for several months, "but nobody's bloody listening."
It's normal line of business is to legally hack into computers to test and improve their company's security. More recently MWR has turned its attention to smartphones and found that it can crack open every new handset it sees.
"The mobile phone industry is not fit for purpose, especially for financial transactions," says Fidgen. "The evidence is irrefutable. You cannot be assured of security with modern smartphones. As soon as the handset is compromised, then any data is up for grabs."
Fidgen says the fault lies with the handset manufacturers rather than the network providers or banks. In the race to bring new phones and new features to the market, many have left security low on the agenda.
Yet modern smartphones are in effect PCs with phones attached and, particularly when they are used in public Wi-Fi hotspots, they can become fatally compromised.
Trojans can enter a smartphone in many devious ways. All you have to do is click on a link or attachment that contains the virus, and within seconds it can secretly seize control of the phone. That link might be a tinyurl in Twitter. The attachment could be a vCard, the standard format for sending a business card to a phone.
Or it could be that you are accessing a website in a cafe. At Wi-Fi hotspots, fraudsters create bogus gateways, known as "evil twins", to which the latest mobile phones will automatically connect.
As the Guardian revealed in April, once a connection is established, all the information passing through the gateway can be read directly or decrypted, allowing fraudsters to harvest user names, passwords and messages.
Until now, these attacks have been rare but now experts say that's just because smartphones are still taking off. "We're walking into a minefield," says Fidgen, who has been warning about the risks of mobile banking for several months, "but nobody's bloody listening."
Friday, July 15, 2011
Monday, July 11, 2011
Thursday, July 7, 2011
The Human Brain has difficulty calculating RISK!
The human brain struggles with comprehending risk. We find it difficult to translate the mathematical fact of probability into an accurate assessment of danger. This can be especially true in medicine, where emotion frequently clouds rational thinking.
In one study, Gigerenzer and his colleagues asked doctors in Germany and the United States to estimate the probability that a woman with a positive mammogram actually has breast cancer, even though she’s in a low-risk group: 40 to 50 years old, with no symptoms or family history of breast cancer. To make the question specific, the doctors were told to assume the following statistics couched in terms of percentages and probabilities about the prevalence of breast cancer among women in this cohort, and also about the mammogram’s sensitivity and rate of false positives:
The probability that one of these women has breast cancer is 0.8 percent. If a woman has breast cancer, the probability is 90 percent that she will have a positive mammogram. If a woman does not have breast cancer, the probability is 7 percent that she will still have a positive mammogram. Imagine a woman who has a positive mammogram. What is the probability that she actually has breast cancer?
The trick is to think in terms of “natural frequencies” — simple counts of events — rather than the more abstract notions of percentages, odds, or probabilities. As soon as you make this mental shift, the fog lifts.
This is the central lesson of “Calculated Risks,” a fascinating book by Gerd Gigerenzer, a cognitive psychologist at the Max Planck Institute for Human Development in Berlin.
In a series of studies about medical and legal issues ranging from AIDS counseling to the interpretation of DNA fingerprinting, Gigerenzer explores how people miscalculate risk and uncertainty. But rather than scold or bemoan human frailty, he tells us how to do better — how to avoid “clouded thinking” by recasting conditional probability problems in terms of natural frequencies.
The correct answer is roughly 9 percent.
How can it be so low? Gigerenzer’s point is that the analysis becomes almost transparent if we translate the original information from percentages and probabilities into natural frequencies:
Eight out of every 1,000 women have breast cancer. Of these 8 women with breast cancer, 7 will have a positive mammogram. Of the remaining 992 women who don’t have breast cancer, some 70 will still have a positive mammogram.
Imagine a sample of women who have positive mammograms in screening. How many of these women actually have breast cancer?
Since a total of 7 + 70 = 77 women have positive mammograms, and only 7 of them truly have breast cancer, the probability of having breast cancer given a positive mammogram is 7 out of 77, which is 1 in 11, or about 9 percent.
Notice two simplifications in the calculation above. First, we rounded off decimals to whole numbers.
That happened in a few places, like when we said, “Of these 8 women with breast cancer, 7 will have a positive mammogram.”
Really we should have said 90 percent of 8 women, or 7.2 women, will have a positive mammogram. So we sacrificed a little precision for a lot of clarity.
Second, we assumed that everything happens exactly as frequently as its probability suggests. For instance, since the probability of breast cancer is 0.8 percent, exactly 8 women out of 1,000 in our hypothetical sample were assumed to have it. In reality, this wouldn’t necessarily be true.
Things don’t have to follow their probabilities; a coin flipped 1,000 times doesn’t always come up heads 500 times. But pretending that it does gives the right answer in problems like this.
Although reformulating the data in terms of natural frequencies is a huge help, conditional probability problems can still be perplexing for other reasons. It’s easy to ask the wrong question, or to calculate a probability that’s correct but misleading.
Labels:
probabiliity,
risk,
risk appetite,
risk management,
statistics
Friday, July 1, 2011
Researchers discover 'indestructible' botnet
Security researchers at Kapersky Labs have discovered botnet software that uses a range of techniques to remain undetected, making it "practically indestructible".
Computers infected by the software, called TDL-4, fall under control of the botnet's criminal owners and can be used to pump out spam or commit other online attacks. Communication with the botnet's command and control servers takes place over a public peer-to-peer file-sharing network and is protected by a custom encryption algorithm, making it very hard to track down the botmasters in charge and shut them down.
More than 4.5 million computers running Windows have been infected by TDL-4, but they're unlikely to know it. The malware installs itself in the computer's master boot record, a part of the system that loads before the operating system starts up, hiding it from most anti-virus programs and bypassing Window's security altogether.
What's worse, the malware runs its own anti-virus software to ensure that it doesn't have to share the infected computer with any other malicious programs. TDL-4 scans for around 20 common competitors and prevents them from contacting their command and controls servers. This also serves to stop users noticing anything is wrong - you might notice a slowdown if your computer is running a menagerie of malware, but a single botnet can remain undetected.
Computers infected by the software, called TDL-4, fall under control of the botnet's criminal owners and can be used to pump out spam or commit other online attacks. Communication with the botnet's command and control servers takes place over a public peer-to-peer file-sharing network and is protected by a custom encryption algorithm, making it very hard to track down the botmasters in charge and shut them down.
More than 4.5 million computers running Windows have been infected by TDL-4, but they're unlikely to know it. The malware installs itself in the computer's master boot record, a part of the system that loads before the operating system starts up, hiding it from most anti-virus programs and bypassing Window's security altogether.
What's worse, the malware runs its own anti-virus software to ensure that it doesn't have to share the infected computer with any other malicious programs. TDL-4 scans for around 20 common competitors and prevents them from contacting their command and controls servers. This also serves to stop users noticing anything is wrong - you might notice a slowdown if your computer is running a menagerie of malware, but a single botnet can remain undetected.
Subscribe to:
Posts (Atom)

