The Mactans charger uses a BeagleBoard for its computational power. Billy Lau, Yeongjin Jang, and Chengyu Song Plugging your phone into a charger should be pretty safe to do. It should fill your phone with electricity, not malware. But researchers from Georgia Institute of Technology have produced fake chargers they’ve named Mactans that do more than just charge your phone: they install custom, malicious applications onto iPhones. Their bogus chargers—which do, incidentally, charge the phone—contain small computers instead of mere transformers. The iPhone treats these computers just as it does any other computer; instead of just charging, it responds to USB commands. It turns out that the iPhone is very trusting of USB-attached computers; as long as the iPhone is unlocked (if only for a split second) while attached to a USB host, then the host has considerable control over the iPhone. The researchers used their USB host to install an app package onto any iPhone that gets plugged in. iOS guards against installation of arbitrary applications with a strict sandboxing system, a feature that has led to the widespread practice of jailbreaking. This attack doesn’t need to jailbreak, however. Read 6 remaining paragraphs | Comments
Link:
Trusting iPhones plugged into bogus chargers get a dose of malware
A man who has won about $1.5 million in poker tournaments has been arrested and charged with running an operation that combined spam, Android malware, and a fake dating website to scam victims out of $3.9 million, according to Symantec. Symantec worked with investigators from the Chiba Prefectural Police in Japan, who earlier this week “arrested nine individuals for distributing spam that included e-mails with links to download Android.Enesoluty —a malware used to collect contact details stored on the owner’s device, ” Symantec wrote in its blog . Android.Enesoluty is a Trojan distributed as an Android application file. It steals information and sends it to computers run by hackers. It was discovered by security researchers in September 2012. Read 4 remaining paragraphs | Comments
If you don’t follow the often-shady world of Bitcoin , you may not be familiar with Bitcoin Savings and Trust (BTCST), a virtual bitcoin-based hedge fund that many suspected of being a scam. BTCST shut down in August 2012, and on Wednesday the Securities and Exchange Commission (SEC) formally charged its founder, Trendon Shavers, with running a Ponzi scheme. In a statement , the SEC said Shavers “raised at least 700, 000 Bitcoin in BTCST investments, which amounted to more than $4.5 million based on the average price of Bitcoin in 2011 and 2012 when the investments were offered and sold.” The government’s financial regulator alleges that Shavers violated a number of federal financial regulations. In court documents , the SEC wrote: Read 2 remaining paragraphs | Comments
The British government has announced that it will approve testing of driverless cars on public roads in the United Kingdom before the end of 2013. According to a new 80-page report published on Tuesday entitled “Action for Roads: A network for the 21st century, ” a team at Oxford University and Nissan have already begun work but have only been testing in private areas. The plan comes less than a year after Florida , California , and Nevada have approved similar testing. Michigan is not far behind, either. Read 3 remaining paragraphs | Comments