New on TechNewsWebsite

Slidehare Introduces New Tracking Analytics Tool

In May 2012, LinkedIn acquired document presentation startup SlideShare. Since that time, the company has been integrating itself into Li...

13 Feb 2013 | undefined comments | Read more

Google's 2016 Mobile Revenue Projected to Reach $20 Billion

Marin Software has released a new report looking at mobile search advertising around the world. The report cites data from Cowen and Compan...

13 Feb 2013 | undefined comments | Read more

Oracle To Release More Java Patches

On February 1, Oracle pulled the trigger early on the February release, which had originally been scheduled for February 19, due to a s...

10 Feb 2013 | undefined comments | Read more

Google Chrome Is Blocking a Bunch of Major Sites for Malware, Even YouTube

If you were just cruising around the web today and got hit smack in the face with a Google Chrome malware error, you weren't the only on...

10 Feb 2013 | undefined comments | Read more

Google Integrates Third-Party Web Apps More Deeply Into Google Drive

Google Drive launched last year, and it's had no trouble making headway against competitors like SkyDrive, Dropbox and iCloud. And thoug...

09 Feb 2013 | undefined comments | Read more
New Reviews

Best alternative Linux desktops 5 reviewe

The desktop on your Linux box used to stand for something very simple. If you were a KDE user, you valued control, power and the ability ...

27 Jan 2013 | undefined comments| Read more

Microsoft LifeCam Studio review

A 1080p webcam sounds a little ridiculous doesn't it. But of course, webcams aren't just for video calls, they're for recording your ...

24 Jan 2013 | 1 comments| Read more

McAfee AntiVirus (AV) Plus 2013 Review

McAfee AntiVirus (AV) Plus 2013 is a sub-$50 home security suite featuring a redesigned user interface (UI), along with extra security too...

20 Jan 2013 | 0 comments| Read more

10 Essential DIY apps for iPhone and iPad

DIY: depending on your point of view, it's either the most pleasurable way to spend a weekend, or a necessary evil designed to keep you fro...

20 Jan 2013 | 0 comments| Read more

Hands on: Nikon D5200 review

Ever since Nikon put a 24-million effective pixel sensor in the D3200 we've been expecting this pixel count to reach a little further u...

20 Jan 2013 | 0 comments| Read more

Facebook Graph Search: what is it and how do you use it?

Well, Facebook didn't reveal a new phone or operating system today - instead the social network announced a new Graph Search. This new ...

18 Jan 2013 | 0 comments| Read more

Acer Iconia W510 Review : Tablet

Acer Iconia W510 : Wide-screen tablet with a clever dock Acer's Iconia W510 is a 16:9, widescreen Windows 8 tablet with a nicely-desig...

18 Jan 2013 | 0 comments| Read more

BREAKING NEWS

TECHNOLOGY

Denso Wireless Smartphone Charger For Vehicles

  An image of the new charger (data courtesy of Denso)  Denso Corp. of Japan is proud to announce that they believe they are ...

25 Jan 2013 | 0 comments| Read more

“Air Mouse” – integrated wireless mouse and keyboard

Thanko is now selling “Air Mouse” which is a wireless mouse unified with a keyboard. By Internal gyro-censor recognizing the tilt, it a...

25 Jan 2013 | 0 comments| Read more

Intel and Safaricom announce Yolo, Africa’s first Intel-Inside smartphone

Intel and Safaricom have announced Africa’s first Intel-powered smartphone, the oddly-named Yolo. The handset is being launched in Kenya,...

25 Jan 2013 | 0 comments| Read more

New Snapdragon S4 features integrated modem

The first mobile devices with Qualcomm’s new quad-core Snapdragon chip, which features an integrated modem, will be shown off later this ...

22 Jan 2013 | 0 comments| Read more
COMPUTING

LG launches 15.6-inch U560 ultrabook

LG has introduced the U560 15.6-inch Windows 8 ultrabook. The device centers on 1080p IPS display for wide viewing angles and better colo...

24 Jan 2013 | undefined comments| Read more

Lenovo grows Middle East market share

Lenovo announced on Monday that it is now the number-four PC manufacturer in the Middle East and Africa, based on the latest preliminary ...

22 Jan 2013 | 0 comments| Read more

Follow Us On Facebook

WEB

Slidehare Introduces New Tracking Analytics Tool

In May 2012, LinkedIn acquired document presentation startup SlideShare. Since that time, the company has been integrating itself into Li...

13 Feb 2013 | Read more
MOBILE TECH

Ubuntu Phones To Land In October

While iOS and Android rule, and Windows Phone dukes it out with BlackBerry for third, a new player will enter the smartphone fray in Q3 t...

07 Feb 2013 | Read more
REVIEWS

Best alternative Linux desktops 5 reviewe

The desktop on your Linux box used to stand for something very simple. If you were a KDE user, you valued control, power and the ability ...

27 Jan 2013 | Read more
SOFTWARE

Windows 8 Skype gets contact blocking in update

Windows 8 users running Skype will now have the option to exert greater control over who can contact them, thanks to a new software updat...

31 Mar 2013 | Read more
APP'S

10 Best Video Editing Apps For iPhone And iPad

Besides video shooting and playing, now you can edit and share video on iPhone directly under the help of iPhone video editing apps. With ...

07 Feb 2013 | Read more
TELEVISION

Amazon to develop 'Zombieland' TV show for Prime Instant Video

Amazon will develop a TV show adaptation of the hit movie Zombieland for its Prime Instant Video service, it was reported on Monday. T...

21 Jan 2013 | Read more
CAMERAS

Hands on: Nikon D5200 review

Ever since Nikon put a 24-million effective pixel sensor in the D3200 we've been expecting this pixel count to reach a little further u...

20 Jan 2013 | Read more
TABLETS

Did Google really design a Chromebook with a Retina touchscreen?

Could a super high-definition Google-designed Chromebook be coming soon to a table near you? According to Geek.com, a video that appeared...

07 Feb 2013 | Read more

Popular News

Twitter Button from twitbuttons.com

Doubts cast over Mega security

While the world’s online sharing community is excited about Kim Dotcom’s bold new venture, the file-storage and sharing service Mega, it is already drawing criticism from security researchers, who advise not to trust it.

The advice is based on how the site protects users’ data, analysts say.

Dotcom threw a large launch party for Mega on Sunday at his mansion outside of Auckland, New Zealand. The service is the successor to Megaupload, the file-sharing site that Dotcom and his colleagues were indicted for in the U.S. in January 2012 on copyright infringement charges.

The flamboyant Dotcom is assuring Mega’s users that the site’s encryption will protect their privacy and data, but the implementation of that encryption scheme is fundamentally flawed, observers say.

Mega uses SSL (Secure Sockets Layer), a widely used protocol for encryption across the internet for securing the connection between its users’ computers and its own servers. Once an SSL connection is made, Mega pushes JavaScript code to a person’s browser, which then encrypts the person’s files before the data is sent to Mega’s servers.

The problem is that SSL has long been recognised as a weak point on the web. In 2009, security researcher Moxie Marlinspike created a tool called SSLstrip, which allows an attacker to intercept and stop an SSL connection. The attacker can then spy on whatever data the user sends to the fake website.

Since Mega fundamentally relies on SSL, “there is really no reason to be doing client-side encryption,” Marlinspike said in an interview on Monday. “These kinds of schemes are vulnerable to all of the problems with SSL.”

Someone who attacks Mega using SSLstrip could then send their own custom malicious JavaScript to the victim’s browser. The user would inevitably divulge his password, which would allow the attacker to decrypt all his data stored with Mega.

If Mega’s servers were compromised, it would also be possible for an attacker to deliver modified, malicious JavaScript, said Nadim Kobeissi, developer of the encrypted instant messaging program Cryptocat.

“Every time you open the website, the encryption code is sent from scratch,” Kobeissi said “So if one day I decide I want to disable all encryption for you, I can just serve your username different code that doesn’t encrypt anything and instead steals your encryption keys.”

A safer way would be for Mega to use a signed browser extension to encrypt the data, which would prevent tampering by an attacker, Marlinspike said. Alternatively, an installed software client would accomplish the same end, he said, without exposing a user to the insecurities of SSL.


Marlinspike said that he thinks Mega users fundamentally don’t care that much about security, since they’re just interested in file sharing. Since Mega will just see encrypted data on their servers, the set-up appears to absolve the site’s founders from the copyright infringement issues of Megaupload.

“All that matters is the operators of Mega can claim they don’t have the technical ability to inspect the contents on the server for copyright infringement,” Marlinspike said.

Like any new online service, Mega’s code is already being prodded. On Sunday, it was revealed the site had a cross-site scripting flaw, which, in some cases, can allow an attacker to steal a user’s cookies, which would allow at least a temporary takeover of a victim’s account. It was quickly fixed.

“XSS issue was resolved within the hour,” wrote Bram van der Kolk, one of the founders of Mega and Megaupload, on Twitter on Sunday. “Very valid point, embarrassing bug.” 

Posted by Unknown on 7:36 AM. Filed under , , , , , , , , , , , , , , , , , . You can follow any responses to this entry through the RSS 2.0

0 comments for Doubts cast over Mega security

Leave comment

Thanks for Your Comment.!

Popular News

Popular News

Photo Gallery