Showing posts with label BlackPOS. Show all posts
Showing posts with label BlackPOS. Show all posts

Saturday, January 18, 2014

Why the 'Internet of Things' may never happen

It's also a lousy name for a great idea that is doomed from the start. Here's why. 

 

Computerworld - Research firm Gartner says the "Internet of Things" will have 26 billion connected devices by 2020.
Maybe. But connected to what? And how? Here's what you need to know about the "Internet of Things" phenomenon.

There will be no 'Internet of Things'

The label "Internet of Things" is used to describe Internet-connected devices that communicate without human involvement.
For example, as you read this article, you're using the regular Internet. You're a human being who is communicating with another human being (Yours Truly), and this communication is facilitated by many other human beings (editors, web designers, engineers, etc.). Like Soylent Green, the Internet is made out of people -- and computers whose main purpose is to help people use the Internet.
The "Internet of Things" is different mainly in that it's not made out of people.
Let's imagine a scenario 10 years into the future when the "Internet of Things" is supposed to be established. You come home with a hypothetical "smart toaster," which connects to the Internet. You plug it into a kitchen outlet. The toaster boots up, finds the home Wi-Fi network and sends out a query to all the other smart devices registered to you. Your alarm clock, smart toothbrush, TV, smartphones, tablets, PCs, smart glasses, smart smoke detector, home automation base station, smart clothes, smart fridge, smart washer and dryer and smart kitty litter box each in turn introduces itself to the toaster, telling its unique identifiers and what they're capable of doing. The toaster responds in kind. In the future, the toaster can send and receive instructions from other devices.
For example, you have friends over for breakfast and make several slices of toast. There's a lot of heat and a little smoke, and your smart smoke detector suspects a fire. So it sends out a message to the other devices saying, in effect, "is anyone creating heat and smoke?" The toaster can respond the equivalent of: "Yeah, it's me. No fire here and nothing to be alarmed about." So the smoke alarm doesn't sound.
"Things" are connecting to each other and interoperating without human involvement. That's one consumery example of the "Internet of Things." (There will be industrial and other applications on a massive scale.)
The "Internet of Things" is a bad name because "things" don't have their own Internet. They use the regular Internet. There is no separate "Internet of Things."
"Things of the Internet" would be closer. And "things that interact with other things without human involvement" would be even more accurate.
Another reason why the "Internet of Things" is a bad name is that the devices can make these connections without using the Internet. Some can connect peer-to-peer, or over a local network, without going online. The ability to connect to the Internet is not a necessary criterion for inclusion in the "Internet of Things" category.

Oh, and one more (fatal) problem

There's one more problem with the label "Internet of Things" -- it implies Internet-like compatibility and universality of communication standards that may never happen.
The basic standards for the Internet were developed before there were powerful companies with a vested interest in excluding competitors from markets. By the time the big Internet companies were rich enough to throw billions of dollars around to get their way, the standards, such as TCP/IP and others that make the Internet universal, were already well established.
This is not the case for the Internet of Things. The phenomenon is arising in an industrial environment of powerful companies that each want an unlevel playing field in their favor, or that have strong and mutually exclusive ideas about how the industry should work.
Former Apple executive Jean-Louis Gassée calls it the "basket of remotes" problem.

 

Batman vs Superman pushed back to 2016 by Warner Bros



Warner Bros has pushed back the release date of the as yet untitled film that will bring together superheroes Superman and Batman, delaying it by almost a year to May 2016, the studio has confirmed.

Ina statement, it said this was to "allow the filmmakers time to realize fully their vision, given the complex visual nature of the story.”
The sequel to last year's hit Superman film Man of Steel was revealed at the Comic-Con convention in July by director Zack Snyder, who said the two DC Comics' caped crusaders will face off against each other.
Replacing the Man of Steel sequel slot of 17 July, 2015 will be a still untitled production of Peter Pan, directed by Atonement's Joe Wright.
"We are happy to take advantage of these coveted summer dates, which are perfect for two of our biggest tentpole releases," said Dan Fellman, president of domestic distribution.
Many comic book fans were dismayed by the announcement that Ben Affleck would play Batman Many comic bookfans were dismayed by the announcement that Ben Affleck would play Batman
In August last year, Warner Bros President Greg Silverman confirmed Ben Affleck would play Batman in a decision that proved controversial among fans of the DC Comic hero.
Affleck, 41, who won multiple awards as the director of Iran hostage crisis film Argo earlier in 2013, will appear alongside British actor Henry Cavill, star of Superman reboot Man Of Steel.
Snyder said in a statement that Affleck will provide an “interesting counter-balance” to Cavill’s Superman.
“He has the acting chops to create a layered portrayal of a man who is older and wiser than Clark Kent and bears the scars of a seasoned crime fighter, but retain the charm that the world sees in billionaire Bruce Wayne,” Snyder said. “I can't wait to work with him."



Six more U.S. retailers hit by Target-like hacks

Six more U.S. retailers hit by Target-like hacks

Security firm IntelCrawler also identified a 17-year-old Russian it says wrote the BlackPOS malware, a version of which was used against Target

 

IDG News Service - Cybercriminals have stolen payment card data from six more U.S. retailers using similar point-of-sale malware that compromised Target, a computer crime intelligence company said Friday.
The conclusion comes from a study of members-only forums where cybercriminals buy and sell data and malicious software tools, said Dan Clements, president of IntelCrawler, which conducted the analysis.
The retailers have not been publicly named, but IntelCrawler is providing technical information related to the breaches to law enforcement, Clements said in a telephone interview Friday.
IntelCrawler has also identified a 17-year-old Russian who it says created the BlackPOS malware, which intercepts unencrypted payment card data after a card is swiped. Security experts believe malware based on BlackPOS was used against Target.
The teenager, who goes by the online nickname "ree4," sold more than 40 copies of BlackPOS to cybercriminals in Eastern Europe and elsewhere, according to forum postings IntelCrawler analyzed.
Clements said IntelCrawler is "90 percent" sure of its finding, based on the forum postings and sources it communicated with.
The forum posts indicate the teenager sold the malware for US$2,000 or for a share of the profits that came from monetizing stolen payment card details, Clements said.
BlackPOS was also sold to "carding" websites such as .rescator, Track2.name and Privateservices.biz that trade in stolen card details, according to IntelCrawler.
BlackPOS was originally called Kaptoxa, which is Russian slang for potato. Clements said the Russian teenager eventually renamed the malware BlackPOS during a fresh marketing push.
Dallas-based security company iSight Partners wrote in a report earlier this week on the Target hack, which it called the "Kaptoxa operation." It says the hackers used a high level of skill to gain stealthy access to the retailer's network.
Since early 2013, IntelCrawler has seen a brisk trade in login credentials for POS terminals on underground forums, suggesting cybercriminals are still finding gaps in industry security recommendations for how payment card data is handled.
Cybercriminals were selling "remote desktop protocol" credentials for POS terminals, which would allow them access to the machines, Clements said.
In many cases, default passwords had not been changed on the terminals, which were located in the U.S., Australia and Canada, he said. In other cases, cybercriminals were successfully trying many combinations of usernames and passwords to find the right one, known as a brute-force attack.