Webcameras and their possible misuse have been a hot topic lately, what with the alleged ‘laptop spycam‘ case currently ongoing against a high school in Philadelphia, US.
Now, by and large, webcams can be tremendously useful. They’re used in a huge variety of legitimate settings, from home security to cross-country family chats, from peak hour traffic monitoring to the porn industry (ahem). In fact, webcams are only a concern if someone takes unauthorized control of one for their own ends.
Before looking into this though, firstly – is that even likely to happen to the average user? Do most people need to worry about a peeping-tom webcam?
Well, strictly speaking, if your computer is secure and uninfected, can’t be accessed remotely, and has some kind of physical protection (strong password, locked case, tied up with string) to prevent people from accessing it when unattended, then no, no worries – you’re good.
If your computer is not as secure as you’d like; if you don’t control the software installed on it; if you don’t know how to configure the settings on the programs installed – it’s still pretty unlikely, though there’s still a chance. Logically, it’s like the odds of being struck by lightning – possible, but improbable.
The trouble is, when it comes to privacy, ‘rational’ can have a hard time fighting ‘emotional’. Personally, there’s just something about the thought of someone spying on me through my own webcam that creeps the bejeesus out of me. It’s like finding an eyeball staring back at you through the keyhole of a cupboard door.
So, let’s say you’d like that small possibility to be even slighter. How exactly could some depraved perv..ahem, attacker get control of your webcam? Well, there are really only a few ways your webcam can be taken over:
The program used to control a webcam may include a remote admin feature allowing someone not physically present to control it (usually over the Internet). Remote admin functionality could also be added in a separate program.
If you aren’t permitted to modify the control program’s settings, or aren’t allowed to install/uninstall programs (more true of company-issued laptops than personal owners), or just don’t know how to do it, well…basically, someone else has control. Hopefully, they’re not the sort to snoop.
For those with full control of their system, trojans are probably more relevant. These are malicious programs (usually disguised as a PDF or document file) that secretly install other programs onto a computer. For spying to be a concern, the installed program has to be a backdoor – which is basically remote admin software, only nastier. Examples include Backdoor:W32/Hupigon, Backdoor:W32/PoisonIvy and Backdoor:W32/SDBot.MB.
Again, the chances of getting hit by a trojan carrying a backdoor payload boils down to juggling probabilities – if the computer has no AV protection, if it is connected to the Internet and/or if you transfer files to it without scanning them first, if an infected file is a trojan and if it has a backdoor as its payload…You get the idea. It’s happened before, as this reports shows, but how likely you are to get hit really depends on how secure you are.
Possibly the least likely, but definitely the creepiest is when someone literally sits down at your computer and switches on the webcam, or installs remote admin software, without you being aware of it. This is basically stalking behavior, with a few cases reported; there have even been movies (most recently, Alone With Her) made on this premise.
Is it a possibility? Yes. Is it likely? There’s absolutely no figures or surveys on this, so all I can say is that unless you have reason to believe you’re being stalked, most likely not.
So, how to ensure you’re as safe as can be from being spied on? And let’s assume I don’t just say ‘get a good antivirus program’ (because that’d be a shameless plug), or the usual stuff about protecting your computer. What can you do? A lot, actually.
You could choose a webcam with security features. Most webcams today come with an LED light that switches on whenever the cam is transmitting. Or get a webcam with a lens cover (oddly these seem to have fallen out of fashion, are people more trusting these days?).
Then there’s this cute humanoid figure-like ‘anti-peeping‘ webcam, with arms that move automatically or manually to cover its ‘eye-lens’ – I haven’t been able to get my hands on this yet, so if someone has this already, let me know how it works out!
If you already have a webcam, you can go through the settings for its control program – if there’s a remote admin feature included and you’re not using it, make sure it’s disabled. You may need to check the documentation for the program to do this.
If you’re using a wireless webcam setup, make sure your wireless network is secured, so that noone can nick the webcam feed off your own network. Maybe not with WEP though; the stronger WPA2 would be nice.
Some less techie things you can do are:
1. Unplug it when not in use (if it’s an external web-cam).
2. Turn it to face a wall when not in use (doesn’t mute the mic, though).
And for some really no-brainer fixes….
Or Post-It notes (some students in the spycam laptop case reportedly used this as well).
Or Blu-tack (I haven’t tried this myself, but a commenter in a forum mentioned it might help with blocking microphone transmissions as well).
Heck, even a tea cosy would do.
When IT savvy fails, a MacGuyver solution might do the trick.
CC image credit: Itiro
On Tuesday Apple announced its latest iPhone models and a new piece of wearable technology some have been anxiously waiting for -- Apple Watch. TechRadar describes the latest innovation from Cupertino as "An iOS 8-friendly watch that plays nice with your iPhone." And if it works like your iPhone, you can expect that it will free of all mobile malware threats, unless you decide to "jailbreak" it. The latest F-Secure Labs Threat Report clears up one big misconception about iOS malware: It does exist, barely. In the first half of 2014, 295 new families and variants or mobile malware were discovered – 294 on Android and one on iOS. iPhone users can face phishing scams and Wi-Fi hijacking, which is why we created our Freedome VPN, but the threat of getting a bad app on your iOS device is almost non-existent. "Unlike Android, malware on iOS have so far only been effective against jailbroken devices, making the jailbreak tools created by various hacker outfits (and which usually work by exploiting undocumented bugs in the platform) of interest to security researchers," the report explains. The iOS threat that was found earlier this year, Unflod Baby Panda, was designed to listen to outgoing SSL connections in order to steal the device’s Apple ID and password details. Apple ID and passwords have been in the news recently as they may have played a role in a series of hacks of celebrity iCloud accounts that led to the posting of dozens of private photos. Our Mikko Hypponen explained in our latest Threat Report Webinar that many users have been using these accounts for years, mostly to purchase items in the iTunes store, without realizing how much data they were actually protecting. But Unflod Baby Panda is very unlikely to have played any role in the celebrity hacks, as "jailbreaking" a device is still very rare. Few users know about the hack that gives up the protection of the "closed garden" approach of the iOS app store, which has been incredibly successful in keeping malware off the platform, especially compared to the more open Android landscape. The official Play store has seen some infiltration by bad apps, adware and spamware -- as has the iOS app store to a far lesser degree -- but the majority of Android threats come from third-party marketplaces, which is why F-Secure Labs recommends you avoid them. The vast majority of iPhone owners have never had to worry about malware -- and if the Apple Watch employs the some tight restrictions on apps, the device will likely be free of security concerns. However, having a watch with the power of a smartphone attached to your body nearly twenty-four hours a day promises to introduce privacy questions few have ever considered.
Everybody probably agree that the net has developed a discussion culture very different from what we are used to in real life. The used adjectives vary form inspiring, free and unrestricted to crazy, sick and shocking. The (apparent) anonymity when discussing on-line leads to more open and frank opinions, which is both good and bad. It becomes especially bad when it turns into libel and hate speech. What do you think about this? Read on and let us know in the poll below. We do have laws to protect us against defamation. But the police still has a very varying ability to deal with crimes on the net. And the global nature of Internet makes investigations harder. Most cases are international, at least here in Europe where we to a large extent rely on US-based services. This is in the headlines right now here in Finland because of a recent case. The original coverage is in Finnish so I will give you a short summary in English. A journalist named Sari Helin blogged about equal rights for sexual minorities, and how children are very natural and doesn’t react anyway if a friend has two mothers, for example. This is a sensitive topic and, hardly surprising, she got a lot of negative feedback. Part of the feedback was clear defamation. Calling her a whore, among other nasty things. She considered it for a while and finally decided to report the case to the police, mainly because of Facebook comments. This is where the really interesting part begins. Recently the prosecutor released the decision about the case. They simply decided to drop it and not even try to investigate. The reason? Facebook is in US and it would be too much work contacting the authorities over there for this rather small crime. A separately interviewed police officer also stated that many of the requests that are sent abroad remain unanswered, probably for the same reason. This reflects the situation in Finland, but I guess there are a lot of other countries where the same could have happened. Is this OK? The resourcing argument is understandable. The authorities have plenty of more severe crimes to deal with. But accepting this means that law and reality drift even further apart. Something is illegal but everybody knows you will get away with the crime. That’s not good. Should we increase resourcing and work hard to make international investigations smoother? That’s really the only way to make the current laws enforceable. The other possible path is to alter our mindset about Internet discussions. If I write something pro-gay on the net, I know there’s a lot of people who dislike it and think bad things about me. Does it really change anything if some of these people write down their thoughts and comment on my writings? No, not really. But most people still feel insulted in cases like this. I think we slowly are getting used to the different discussion climate on the net. We realize that some kinds of writing will get negative feedback. We are prepared for that and can ignore libel without factual content. We value feedback from reputable persons, and anonymous submissions naturally have less significance. Pure emotional venting without factual content can just be ignored and is more shameful for the writer than for the object. Well, we are still far from that mindset, even if we are moving towards it. But which way should we go? Should we work hard to enforce the current law and prosecute anonymous defamers? Or should we adopt our mindset to the new discussion culture? The world is never black & white and there will naturally be development on both these fronts. But in which direction would you steer the development if you could decide? Now you have to pick the one you think is more important. [polldaddy poll=8293148] Looking forward to see what you think. The poll will be open for a while and is closed when we have enough data. Safe surfing, Micke
Our Freedome VPN service hit a new milestone this summer. We added our newest location in Paris, France and now have 11 nodes in 10 different countries: Canada (Toronto) Finland (Espo) France (Paris) Germany (Sachsen) Hong Kong Italy (Milan) Netherlands (Amsterdam) Singapore Spain (Madrid) Sweden (Stockholm) United Kingdom (London) United States (East Coast) United States (West Coast) That means regardless where you are in world, you can pick any of these locations to mask your whereabouts and use any of the services you love. Freedome also acts a VPN to encrypt your data so a free Wi-Fi network is safe for private transactions along, and it includes anti-virus, anti-tracking, and anti-phishing. It's been localized into 10 different locations and will soon be available for iOS devices. If you travel -- our just want your phone to think you're traveling -- this is the kind of protection you need. Get it now from the Google Play or iTunes store. Cheers, Sandra, UPDATED: Hong Kong and Singapore were added on September 15, 2014. [Image by jvieras via Flickr]