Showing posts with label media. Show all posts
Showing posts with label media. Show all posts

Monday, 30 September 2013

Hackers target social media, step up mobile attacks

Social media has become a top target of hackers and mobile devices are expanding that target, IBM reported last week in its X-Force 2013 Mid-Year Trend and Risk Report.

Attacks on businesses are getting increasingly sophisticated, the report said. Some attacks studied by IBM researchers were opportunistic—exploiting unpatched and untested web applications vulnerable to basic SQL injection or cross-site scripting.

Others were successful, the report continued, because they violated the basic trust between end user and sites or social media personalities thought to be safe and legitimate.

"Social media has become a new playground for attackers," said Kevin Skapinetz, program director for product strategy for IBM Security Systems.

social

The report noted that a growing trend this year is the takeover of social media profiles that have a large number of followers. The trend continues to play a pivotal role in the way attackers are reaching their targets.

"It's one thing to get an email or spam from someone you've never heard of," Skapinetz said in an interview. "It's another thing to have one of your friends have their account compromised and send you a link that might interest you."

Traditional sources of online aggravation can't resist the siren call of social media, either. "Even if email is used in an attack, it will be under guise of coming from a social media account," he said. "Attackers are becoming more operationally sophisticated."

Social media attacks can affect more than the usual suspects, too. Social media exploits affect more than individuals; they can negatively impact enterprise brand reputation and cause financial losses, the report said.

Mobile devices are also becoming a hacker magnet. "Although mobile vulnerabilities continue to grow at a rapid pace, we still see them as a small percentage of overall vulnerabilities reported in the year," the report said.

What may be making matters worse is the proliferation of mobile devices in the workplace under Bring Your Own Device Programs. "BYOD—what a nightmare that can be for any organization," HBGary's Threat Intelligence Director, Matthew Standart, said in an interview.

mobile security

"It's difficult to protect your data even when you own all your devices and getting visibility into all your devices is a challenge in itself," Standard said. "Allowing users to bring their own devices increases the complexity tenfold."

The IBM report also noted that Distributed Denial of Service (DDoS) attacks are being used for more than just disrupting service at target sites. The attacks are being used as a distraction, allowing attackers to breach other systems in the enterprise.

"Both attacks and attack threats are being used as decoys," Marc Gaffan, co-founder of Incapsula, said in an interview.

"The attackers will bring down a website, get the IT people focused in a certain direction, tie up their resources on the DDoS attack while a more sophisticated breach is performed with no one paying attention," Gaffan said.

A decoy attack could also be used in conjunction with a phishing attack, he added. For example, a phishing message could be sent to a bank's customers asking them to use an alternative URL because the bank is having trouble with its common web address. A recipient may follow good security practices and paste the common URL for the bank in his browser.

Because the bank is under a DDoS attack, however, they can't connect to the institution, he said. So, in desperation, they click on the URL in the phishing message and get infected.

Those kinds of misdirection DDoS attacks, though, haven't become mainstream. "They are occurring, but they're relatively rare," said Daniel Peck, a research scientist at Barracuda Networks.

The IBM report also questioned the dedication of many organizations to sound security basics. "Many of the breaches reported in the last year were a result of poorly applied security fundamentals and policies and could have been mitigated by putting some basic security hygiene into practice," the researchers wrote.

"Attackers seem to be capitalizing on this 'lack of security basics' by using a model of operational sophistication that allows them to increase their return on exploit," they wrote.

"The idea that even basic security hygiene is not upheld in organizations, leads us to believe that, for a variety of reasons, companies are struggling with a commitment to apply basic security fundamentals," the researchers wrote.

Barry Shteiman, senior security strategist with Imperva, said in an interview that the lack of adherence to basics could be due to a fundamental misunderstanding of security by companies. "They don't understand the difference between a safety belt and auto insurance," he said. "They don't understand that it's more important to protect themselves than to preserve their reputation after a breach has been made."

John Mello writes on technology and cyber security for a number of online publications and is former managing editor of the Boston Business Journal and Boston Phoenix.
More by John P. Mello Jr


View the original article here

Thursday, 12 September 2013

How to download streaming media and watch it anywhere, anytime

Subscribing to Hulu Plus or Netflix is a great deal—until you find yourself on a less-than-perfect Internet connection. Perversely, your streaming media library is most valuable in places where you can’t access the Internet: Watching a movie or burning through episodes of your favorite TV show is the best way to get through a long plane trip, a car ride, or a vacation in the middle of nowhere.

Luckily, you can use third-party software and a few tricks to download streaming video from Amazon, Hulu, and Netflix. Now you can watch your entertainment on your terms, even in places where your cherished Amazon Prime account is inaccessible.

Bottling the Amazon Prime Instant Video stream

At first blush Amazon appears to offer an easy option with its downloadable Unbox Player, but the fine print renders Amazon’s own tool almost useless for practical purposes.

Sure, you can use the Unbox Player to download movies and television shows you’ve rented or purchased on Amazon, but you can’t use it to download the Amazon Prime Instant Video content that you can stream through your Amazon Prime subscription. The Unbox Player does let you stream that stuff, but streaming through Unbox isn’t any different than streaming through your browser.

Amazon’s Unbox player is great for downloading digital copies of movies and TV shows you’ve purchased on Amazon, but you can’t use it to save streaming Instant Video for later. If you want to do that, you’ll have to turn to some unorthodox third-party alternatives.

I rented a movie on Amazon to test whether Unbox could indeed download files for later. A half hour and several rounds of quitting out of the program and refreshing my recent purchases later, the film finally showed up in Unbox for offline viewing.

The user experience was unpleasant, and offered no added convenience compared with watching video in my browser or through iTunes. Amazon’s official solution to the offline-viewing problem is a bit of a wash. Fortunately, as I’ll discuss later, some unsanctioned third-party alternatives can give you considerably more control over your streamed media.

Hulu doesn’t provide an official download option. Viewers who want to record streaming movies and TV for later enjoyment should try RTMPDumpHelper, a free utility designed to download media that you’re streaming via RTMP (Real Time Messaging Protocol, which Hulu uses). Your experience may differ on Linux, but on Windows you can simply download RTMPDumpHelper and the RTMPDump Toolkit, unzip both into one folder, and then open the RTMPDumpHelper program.

RTMPDumpHelper will walk you through the process of establishing a proxy server that will intercept any RTMP streams (including those for Hulu and several smaller video-streaming sites) and save them as an MP4 file. Be warned, though: Setup can be somewhat finicky, and the documentation is a little technical.

RTMPDumpHelper will capture media to your hard drive from your browser as you stream it, allowing you to record a copy of your favorite movies and shows for offline viewing.

During my testing, RTMPDump never successfully attached itself to Chrome—my browser of choice—even after I tried multiple suggested solutions online. I eventually gave up and opened Firefox, which RTMPDump readily recognized.

However, even after RTMPDump was hooked into my browser, about a third of the time the program failed to notice that I was streaming a new video from Hulu. I had to reload the page—but since it was easy to see whether the stream was being recorded in the RTMPDumpHelper window, the extra step added only a few seconds of inconvenience.

Futzing with RTMPDumpHelper can be a little frustrating, but the results are worth your trouble. Of all the methods I used, RTMPDump produced usable video the fastest—usually just a few moments after my streams finished, taking minimal processing time compared with other options. It also recorded video in a format (MP4) that was easy to transfer to my phone or tablet, or to watch later on my PC. In fact, if RTMPDump were a ubiquitous utility, it would be the best way to download streaming media, period. The problem is, most streaming sites—including Netflix, the biggest name in streaming video—don’t use RTMP.

If downloading videos from Amazon and Hulu seems difficult, well, I’m afraid Netflix has made the process almost impossible. Several years ago you could intercept a stream directly from Netflix, à la RTMPDump, but Netflix wised up and now exerts much tighter control over your streaming data.

In fact, the only reliable method I could find to get a copy of a Netflix stream was to record it from the screen. Plenty of programs, including free options such as CamStudio, will let you record both the audio and the video from your computer screen as it plays.

Recording the video yourself does come with a few caveats. First, it’s a demanding task that will tax your PC’s hardware. Often your recordings can contain a lot of skipped frames if you’re trying to capture video at a fairly high resolution, especially on older computers that have their hands full just streaming full-screen video in the first place.

Second, the files produced when you perform screen capturing are typically huge. For example, before I tweaked all the settings in CamStudio, my sample videos exceeded 200MB for just 30 seconds of footage. You’ll need to experiment to figure out the optimal balance of recording size and quality for you and your available storage.

Inexpensive screen-recording programs such as Audials give you the power to record and store anything you can play on your PC screen.

That said, such problems become easier to deal with if you upgrade from free to paid software. Although screen-capturing with Audials, a $25 program, is still a system-intensive task that leaves you with gigantic files, paying for the software unlocks a lot of settings and presets. With most streams in my tests, the procedure was as easy as entering a URL and then letting the program open a new tab to begin recording. Getting the file size to reasonable levels (less than 1GB for an hour-long program) took very little tweaking.

Screen recording has other advantages as well. Since you’re merely recording the video that’s playing on your screen, you can use this trick with any streaming service. I eventually managed to record a stream using Audials on all three of the major streaming services, and you could do the same thing with Twitch, YouTube, or any other online video service.

You can save some time and hassle by automating your streaming media recording completely. PlayLater is a new service that lets you queue up your accessible streaming media and records it for you in the background. It delivers an MP4 file after the stream ends, without interrupting your other computing tasks.

Paying $20 a year, or $40 for a lifetime subscription, allows you to use the PlayLater service and search for any stream on any service to which you legally have access. For paid services such as Amazon Prime or Netflix, you’ll need to enter your login information; once you do, PlayLater presents an easy-to-use interface for finding streaming video and saving it to your computer as fast as you can stream it.

If all of that sounds too good to be true—or legal—don’t worry: Thanks to a 2010 ruling that protects the consumer’s right to watch “time-shifted” media (the same one that makes recording streams yourself legal), the service should be protected.

PlayLater has positioned itself as a DVR for online streams, which should be perfectly legal. Of course, the law surrounding copyright and online media is constantly shifting, but for now PlayLater is offering a service that simply automates the legal recording and rewatching of online video that you could perform yourself.

Of course, no matter which method you choose, once your recordings are in a file format that’s right for you, the world is your oyster. Your newly captured media can reside on your phone or tablet for safekeeping. Depending on which formats your mobile devices prefer, you may need to convert the file, but that’s simple enough—and you’ll never again have to worry because, say, Netflix removed Farscape from its streaming library while you were right in the middle of the second season (just as a crazy example). You’ll even be able to use your downloaded media with services such as Plex, which makes watching video from Netflix or Hulu on your home-theater system way more convenient.

David Daw has studied the history and future of television and has a master's in Broadcast and Electronic Communication Arts from San Francisco State University along with a BA in genre fiction from NYU.
More by David Daw


View the original article here

Tuesday, 27 August 2013

Google blocks Chromecast app that streams local media files

You can stream a lot of content to a Chromecast dongle, but one thing you can’t do is stream your personal files from an Android device—and according to one developer, Google's actively working to keep it that way.

A beta version of an Android application called AllCast has lost the ability to stream content to Chromecast from Android apps such as the photo gallery, Dropbox, and Google Drive.

“Google's latest Chromecast update intentionally breaks AllCast,” said Android developer Koushik Dutta in a recent Google+ post. The company removed a developer option called “video_playback,” which as its name suggests, allowed any application to support video playback.

Dutta believes this is a sign that Google will not be friendly toward third-party developers of Chromecast apps compared to the relative openness Android developers enjoy on Google Play. “The Chromecast will probably not be indie developer friendly,” Dutta said in his post. “The Google TV team will likely only whitelist media companies.”

“We’re excited to bring more content to Chromecast and would like to support all types of apps, including those for local content,” Google said in a statement when we reached out to them for comment. “It’s still early days for the Google Cast SDK, which we just released in developer preview for early development and testing only. We expect that the SDK will continue to change before we launch out of developer preview, and want to provide a great experience for users and developers before making the SDK and additional apps more broadly available.”

Indeed, in its Chromecast developer documentation, Google says that all functionality is subject to change.

Regardless, Google certainly hasn’t made it easy for Chromecast users to stream their own video files to their TV—an obvious feature deficit. Competitors such as Apple TV already allow you to stream content from your PC or iOS device; however, Apple restricts video formats to h.264 and a specific type of MP4.

Many critics suspect that Google left out the ability to stream personal videos to make its new Web-meets-TV platform more attractive to movie and television studios concerned about piracy. Instead of buying approved content from Google Play or Amazon, the argument goes, users could just download a pirated copy of Sunday night’s Breaking Bad episode and send that to Chromecast.

If the speculation is accurate, it’s rather unfair to limit obvious functionality on Chromecast just to make sure Hollywood doesn’t get spooked, especially since Apple TV could broadcast pirated video to your TV right now. Plus, anyone with the technical know-how to download a pirated video (especially via torrents) likely figured out how to put that content on their TV long before Chromecast showed up.

If you’re absolutely dying to stream personal videos to your Chromecast, one workaround for now is to try casting from your PC. Our recent primer on seven Chromecast tips and tricks shows you how to easily access a PC’s file system from an open Chrome tab.

Updated at 11:23 a.m. PT with a comment from Google.

Ian is an independent writer based in Tel Aviv, Israel. His current focus is on all things tech including mobile devices, desktop and laptop computers, software, social networks, Web apps, tech-related legislation and corporate tech news.
More by Ian Paul


View the original article here

Friday, 16 August 2013

Review: Corel Painter X3 makes natural media more accessible

Corel Painter X3 $429.00 Corel Painter X3 remains a compelling tool for creating traditional-looking artwork with a computer, especially now that it's easier to navigate.

Download Now

Corel Painter faces a problem similar to that of Microsoft Office: When you're already at the top of your field, it's hard to see the path to improvement. Just like Office is the go-to suite for everyday productivity tasks, Corel Painter is the go-to application for serious artists looking to create natural-looking paintings and concept sketches using a computer. That gives Corel the enviable problem of trying to get artists to upgrade from a program that's already more than good enough...a problem the company tackles ably in Painter X3.

Painter's Start screen tries to be both inviting and inspiring.

Corel's solution: Keep the powerful tools, but make everything more accessible. Almost every change and addition in the new Corel X3 is meant to lower the learning curve, make features easier to discover, or make common drawing tasks simpler than they used to be.

Take, for example, the all-new brush search engine: Previous versions of Corel came packed to the gills with impressive brushes, including my personal favorites, Real Watercolor and Real Wet Oil. While established users could appreciate having dozens and dozens of brushes to choose from, novice users could find the sprawling brush selection menu daunting. The new search engine tackles this by avoiding the menu altogether: Simply type "pencil," and get a list of all of the pencil brushes Corel Painter offers, no matter where they are located in the brush menu.

Thanks to the new brush search engine, you no longer have to dig through the menu to find the brush you want.

Even once you find a brush with a name that sounds like what you need ("Real 6B Soft Pencil"), you'd still want to see what it actually looks like on paper. This is where another new feature comes in handy: Stroke preview. Simply hover over the brush's name, and a small pop-up shows you what you can expect once you put the brush to your canvas. The preview shows just a single, isolated stroke, so you will still need to learn how to read it, but it can help.

Corel's cloning feature makes it easy to create paintings based on photos.

Many artists base their paintings on reference images, and Painter X3 makes it relatively easy to inject such images into your workspace. Reference images float in their own mini-windows which you can drag around and even take outside the main Corel Painter window. You can zoom and pan them, and it is easy to quickly sample colors from them.

For budding artists who need more of a helping hand, the newly enhanced cloning workflow can come in handy. You can now place a reference image next to your work, and see a cloning crosshairs moving around on the source image as you work on your painting, letting you easily see what exactly you're cloning. At its simplest, this lets you render a photo into a painting using just a handful of strokes.

The new perspective feature is handy mainly for artists who already know what they're doing.

Another new addition to X3 are perspective guides, which make it easier to draw street scenes, rooms, and other images with a sense of depth and perspective. This feature could be made more accessible in future versions: It currently ships with just four presets bearing names that assume you know what you're doing, such as "Point Standard Horizon" and "Point Worms-Eye View."

All in all, Painter X3 is an iterative release, with no major groundbreaking features...but really, Corel Painter doesn't need such features to retain its lead in the natural-media painting world. Making the application more accessible is a good move, and one that I hope to see continued in the next iteration of this venerable art application.

Note: The Download button takes you to the vendor's site, where you can download the latest version of the software.


View the original article here

Monday, 5 August 2013

Email security strongest from social media, report reveals

Email from social media brands is some of the safest on the Internet, while electronic posts from financial services brands is some of the riskiest, says a report released last week by an email security provider.

"Consumers may be worried about their privacy settings, but in terms of protecting consumers via email, social media is the clear leader," said the report from Agari, which analyzed more than a trillion emails during the second quarter of this year.

Agari uses that analysis to create a Trust Index for email in financial services, e-commerce, social media, travel, logistics, and gaming industries.

The index is based on a Trust Score—a reflection of the adoption and deployment of security measures in an industry to protect its customers from malicious email—and a Threat Score—which provides a measure of relative risk based on malicious activity and attempted attacks.

Social media led all industry sectors during the June quarter with a Trust Score of 73.1, out of a possible 100.

Ranking companies and industries based on the ThreatScore, and TrustScore benchmarks gives consumers and leading brands visibility into how aggressively a sector is being threatened and which companies are taking action to secure email and protect consumer data and trust, the report explained.

"Social media has been far more aggressive about protecting their customers and far more responsive to keep up with the technologies available to protect their customers," Agari founder and CEO Patrick Peterson said in an interview.

Among those technologies is DMARC (Domain-based Message Authentication, Reporting and Conformance), which Agari's report said can virtually eliminate brand abuse through fraudulent email attacks and drastically reduces the risks of consumer loss, reputation damage, and financial liability.

"A lot more people should be using DMARC because it allows administrators and organizations to be able to reject mail if it doesn't match certain parameters no matter where it says it's coming from," said Paul Ferguson, vice president for threat intelligence at Internet Identity.

Nevertheless, Ferguson was skeptical of the glowing grades given social media by Agari. "We see daily campaigns with emails harboring malicious content that's masquerading as DHL, Fedex, Dun & Bradsteet or social media like Facebook and Linkedin," he said.

In fact, social media may contribute to the problem by fueling a growing culture of interrupt-alerts that demand attention without forethought. "It allows bad guys to blend in with that noise," Ferguson explained.

Other sectors analyzed by Agari didn't fare as well as social media. "The most significant, but not at all surprising, discovery comes from financial services where there has been a huge spike in malicious activity, more than doubling from the prior quarter," the report said.

"In fact, consumers are seven times more likely to receive a malicious email from their bank than from any other type of company," it said.

Despite that spike, financial services still managed a Trust Score of 39.7, a seven percent jump over the previous quarter and significantly higher than the worst sector in the report: travel, with a score of 17.2.

"This sector, and the airlines in particular, is doing the least of all industries we analyzed to secure email and prevent their consumers from becoming victims of an attack," the report said.

"Even airlines like JetBlue that are well known for being leaders in delivering a better digital experience, are putting customers at risk with very little effort in preventing these types of attacks," the report added.

Agari also reported that many consumers do not realize that 95 percent of data breaches start with a phishing email. "I think we can safely say that after however years it has been, we've lost the battle of educating about threats," George Tubin, a senior security strategist with Trusteer, told CSOonline.

"We're just not going to be able to educate people to identify these things," he said.

"We need to keep educating, but the only way we're going to be successful with this is to fight these technology attacks with technology defenses," Tubin said. "We shouldn't be relying on human judgement to determine what's a legitimate email and what isn't."

John Mello writes on technology and cyber security for a number of online publications and is former managing editor of the Boston Business Journal and Boston Phoenix.
More by John P. Mello Jr


View the original article here

Wednesday, 31 July 2013

Bogus Chrome, Firefox extensions pilfer social media accounts

Trend Micro has found two malicious browser extensions that hijack Twitter, Facebook and Google+ accounts.

The attackers plant links on social media sites that, if clicked, implore users to install a video player update. It is a common method hackers use to bait people into downloading malicious software.

The bogus video player update lures people in a macabre manner: it says it leads to a video of a young woman committing suicide, according to Trend's description.

The video player update carries a cryptographic signature that is used to verify that an application came from a certain developer and has not been modified, wrote Don Ladores, a threat response engineer, with Trend.

"It is not yet clear if this signature was fraudulently issued, or a valid organization had their signing key compromised and used for this type of purpose," he wrote.

Hackers often try to steal legitimate digital certificates from other developers in an attempt to make their malware look less suspicious.

If the video update is executed, the malware then installs a bogus Firefox or Chrome extension depending on which browser the victim uses.

The malicious plugins try to appear legitimate, bearing the names Chrome Service Pack 5.0.0 and the Mozilla Service Pack 5.0. Ladores wrote that Google now blocks the extension that uses its name. Another variation of the extension claims it is the F-Secure Security Pack 6.1.0, a fake product from the Finnish security vendor.

The plugins connect to another website and download a configuration file, which allow them to steal the login credentials from a victim's social networking accounts such as Facebook, Google+, and Twitter. The attackers can then perform a variety of actions, such as like pages, share posts, update statuses and post comments, Ladores wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


View the original article here