Monday, January 9, 2017

Tyre&Auto Southbourne Group: Properly taking care of your car is beneficial

Keeping the good condition of your car requires regular maintenance, and if repair is needed, it should be done correctly to make sure of the safety of everyone concerned. Tyre&Auto Southbourne Group suggests that you maintain the safety standards of your car and ensure that it is always in perfect running condition.

Knowing how to brake a car properly usually comes first before learning how to move it forward or backward, which indicates that a person should be responsible for his or her own protection as well as of other people. Tyre&Auto also views this as an essential aspect of driving a car.

The local residents of South Coast of Hampshire trust the automobile services of Tyre&Auto Southbourne Group – a family-operated company that has a great background in trading car accessories and parts. They offer services such as car servicing, tyres, brake checks, MOT’s and free seasonal tune-ups and check-ups.

Need quick tyre fitting? Tyre&Auto caters online transactions that can deliver fast tyre quotation. They can provide local collect and delivery of your car with high-quality maintenance and repair. How about an MOT test? Tyre&Auto also has it wherein it involves checking the safety of your car and the amount of exhaust emission.

The company also provides necessary assistance to your annual MOT certificate requirements through their regular reminders, which includes the due of your test, to ensure that you will renew your road tax and car insurance at the right time.

Ease, mobility, personal comfort as well as financial returns are some of the benefits of owning a car, but such vehicle can also provide emotional or psychological benefits to an individual or a family. With this in mind, Tyre&Auto Southbourne Group will continue to provide trustworthy services to their customers and will make sure that they will only deliver the best automobile services to them.


Thursday, January 5, 2017

Online Security: Fraud detection firm outs $1b Russian ad-fraud gang and its robo-browsing Methbot


A $1 billion Russia-based criminal gang has been bilking online advertisers by impersonating high-profile Web sites like ESPN, Vogue, CBS Sports, Fox News and the Huffington Post and selling phony ad slots, but that’s about to end.

Online fraud-prevention firm White Ops is releasing data today that will enable online advertisers and ad marketplaces to block the efforts of the group, which is cashing in on its intimate knowledge of the automated infrastructure that controls the buying and selling of video ads.

The group has been ramping up its activities since October so that it now reaps roughly $3 million to $5 million per day from unsuspecting advertisers and gives them nothing in return, says White Ops, which discovered the first hints of the scam in September.

When someone clicks on a video that’s posted to a Web page, the video is often preceded by a short advertising video known as pre-roll. The pre-roll slot is sold realtime – within 100 milliseconds – via an automated auction. That click to request the video is what initiates the ad auction, and the browser directly receives the pre-roll from the advertiser that wins, says White Ops CEO Michael Tiffany.

The system relies on information provided by the browser to verify what site the browser user is visiting and that it actually receives the pre-roll ad. “The ecosystem believes what the browser says about what site you’re at,” he says.

Beware Methobot

The gang, which Tiffany calls AFT13, has created a robo-browser called Methbot that spoofs all the necessary interactions needed to initiate, carry out and complete the ad transactions. So Methbot contacts an ad exchange and says it needs a pre-roll for a video on Vogue.com, for example. The system runs an instant auction, settles on an ad and sends it to Methbot, which verifies that it received it and played it.

Then the advertiser pays the entity the website that the browser claimed to be visiting, but that entity resolves ultimately to AFK13, not to Voguecom, in this example, he says.

Beyond this, AFK13 spoofs the geolocation of the IP addresses that the Methbot servers use so it seems they are all owned by U.S. internet service providers. The proxy IP addresses mask the fact that Methbot traffic is generated by servers as opposed to individual personal computers generating legitimate traffic. It also hides that the servers are located in data centers in Dallas and Amsterdam.

This helps Methbot duck detection mechanisms that look for a few IP addresses that generate enormous volumes of requests Tiffany says, enabling AFK13 to sell 200 million to 300 million false ad impressions per day for 1.3 cents per view on average, White Ops says. The fraud network does its work from an estimated 800 to 1,000 nodes in its data centers and operates 24 hours per day, with a sales cycle of 5 seconds per impression.

Methbot further avoids detection by selling the ads on more than 6,000 domains representing about 250,000 URLs.

To pull this all off, AFK13 has amassed an impressive infrastructure that includes:

·         The servers that generate all the Methbot browser activity.
·         A bank of 500,000 IPv4 addresses (worth about $4 million if sold on the open market).
·         A means of registering those IP addresses so they appear to be allocated to U.S. ISPs.
·         Methbot software.

The software has been upgraded over the period that White Ops became aware of it, Tiffany says. For example, White Ops first caught on to the scam when it noted a small error in an HTTP header used by the group. One value, known as Cache-Control, contained a colon, which violated the specification for that value. Since then the error has been corrected.

White Op has been blocking Methbot traffic for its customers, but the only way to stop it entirely is to release the list of URLs indicative of Methbot, the IP addresses used by AFK13 and the list of publisher domains it forges.

Tiffany says White Ops has also notified the FBI about the scam.

Tuesday, January 3, 2017

Tokyo Online Security: US Leads The World In Online Fraud


Global retailers can expect 12 per cent growth in online fraudulent activity in the upcoming holiday season, compared with the same period last year — and lower ticket prices on fraudster-targeted gifts and products.

That’s the analysis which falls out of new benchmark data from ACI Worldwide.

The data, based on hundreds of millions of transactions from retailers globally, provides advice that merchants can leverage to protect against fraudulent activity this holiday season.

·         Card Not Present (CNP) global online fraud attempt rates are expected to increase 12 per cent by volume over the same peak holiday period in 2015 — with sales to increase by nearly the same rate (13 per cent) in 2016.
o   Fraud and new business growth are rising at the same rate globally.
·         S. CNP fraud attempt rates are expected to increase by 43 per cent by volume.
o   Following the US adoption of EMV chip cards, which protects card data through encryption, fraud is shifting online as fraudsters are more effectively deterred from in-store fraud.
·         The 2015 trend of lower ticket prices will continue in 2016, due to alternative shipping methods (e.g. buy online/pick-up in-store), low-priced electronics and promotions.
o   In the US, attempted fraud average ticket value (ATV), or a retailer’s average size of individual sales by credit card, is expected to decline from $239 to $219, an 8 per cent decrease.
o   Fraudsters are expected to focus on cosmetics, cordless headphones, sneakers and other lower-priced items (including ‘Gift with Purchase’ products) that can be easily resold on the black market or via auction websites

According to Mike Braatz, chief product officer, ACI Worldwide, “Fraud is increasing at a rate nearly equal to general retail growth globally — and is exponentially increasing in the US, due to a seismic shift from in-store to online activity.”

He added, “Because fraudulent activity is now considered to be an everyday occurrence, consumers and merchants must take every precaution as we head into peak holiday shopping season.”

Fraud will peak on Christmas Eve with nearly 2.5 per cent fraud, due to the popularity of gift cards and last-minute shopping via buy online-pick up in-store

“Merchants need to understand their peak days and the sales that drive those high velocity times to ensure risk strategies are effective and efficient,” said Braatz. “It’s important to prioritize real-time fraud detection without alienating the consumer experience.”


Wednesday, December 28, 2016

Security and Risk Online: Experts predict 2017's biggest cybersecurity threats

From internal threats to creative ransomware to the industrial Internet of Things, security experts illuminate business cybersecurity threats likely to materialize in the next year.


If 2016 was the year hacking went mainstream, 2017 will be the year hackers innovate, said Adam Meyer, chief security strategist at SurfWatch Labs. Meyer analyzes large and diverse piles of data to help companies identify emerging cyber-threat trends. "2017 will be the year of increasingly creative [hacks]," he said. In the past, cybersecurity was considered the realm of IT departments, Meyer explained, but no longer. As smart companies systematically integrate security into their systems, the culture hackers too will evolve.

"Cybercriminals follow the money trail," Meyer said, and smart companies should adopt proactive policies. Ransomware attacks grew quickly, he said, because the attacks are "cheap to operate, and many organizations are not yet applying the proper analysis and decision-making to appropriately defend against this threat."

It's equally cheap to identify internal vulnerability to hacks and to apply preventative best practices, Meyer said. But for many companies it's not as easy to understand the cybersecurity threats most likely to impact business. To help, TechRepublic spoke with a number of prominent security experts about their predictions for near-future cybersecurity trends likely to impact enterprise and small business in 2017.

Cyber-offense and cyber-defense capacities will increase - Mark Testoni, CEO at SAP's national security arm, NS2

We will see an increased rate of sharing of cyber capabilities between the commercial and government spaces. Commercial threat intelligence capabilities will be adopted more broadly by organizations and corporations... High performance computing (HPC), in conjunction with adaptive machine learning (ML) capabilities, will be an essential part of network flow processing because forensic analysis can't stop an impending attack. HPC + adaptive ML capabilities will be required to implement real-time network event forecasting based on prior network behavior and current network operations... [Companies will] use HPC and adaptive ML to implement real-time behavior and pattern analysis to evaluate all network activity based on individual user roles and responsibilities to identify potential individuals within an organization that exhibit "out of the ordinary" tendencies with respect to their use of corporate data and application access.

Ransomware and extortion will increase - Stephen Gates, chief research intelligence analyst at NSFOCUS

The days of single-target ransomware will soon be a thing of the past. Next-generation ransomware paints a pretty dark picture as the self-propagating worms of the past, such as Conficker, Nimda, and Code Red, will return to prominence—but this time they will carry ransomware payloads capable of infecting hundreds of machines in an incredibly short timespan. We have already seen this start to come to fruition with the recent attack on the San Francisco Municipal Transport Agency, where over 2,000 systems were completely locked with ransomware and likely spread on its own as a self-propagating worm. As cybercriminals become more adept at carrying out these tactics, there is a good chance that these attacks will become more common.

As more devices become internet-enabled and accessible and the security measures in place continue to lag behind, the associated risks are on the rise. Aside from the obvious risks for attacks on consumer IoT devices, there is a growing threat against industrial and municipal IoT as well. As leading manufacturers and grid power producers transition to Industry 4.0, sufficient safeguards are lacking. Not only do these IoT devices run the risk of being used to attack others, but their vulnerabilities leave them open to being used against the industrial organizations operating critical infrastructure themselves. This can lead to theft of intellectual property, collecting competitive intelligence, and even the disruption or destruction of critical infrastructure. Not only is the potential scale of these attacks larger, most of these industrial firms do not have the skills in place to deal with web attacks in real-time, which can cause long-lasting, damaging results. This alone will become one of the greatest threats that countries and corporations need to brace themselves for in 2017 and beyond.

Industrial IoT hacks will increase - Adam Meyer, chief security strategist at SurfWatch Labs

IoT security threats have been talked about, but not really worried about by most because a serious incident had yet to occur. With the 2016 DDoS attack on Dyn, and the ripple effect it created, we will see more scrutiny on security within the IoT marketplace. Vendors will work in new security precautions, but at the same time, criminals will also increase their attention on new ways to leverage IoT devices for their own malicious purposes. There are plenty of "As-A- Service" attack capabilities on the Dark Web for hire now and we should expect creative new IoT hack services to pop up in the near future.

Internal threats will increase - James Maude, senior security engineer at Avecto

As organizations adopt more effective strategies to defeat malware, attackers will shift their approach and start to use legitimate credentials and software - think physical insiders, credential theft, man-in-the-app. The increased targeting of social media and personal email bypasses many network defenses, like email scans and URL filters. The most dangerous aspect is how attackers manipulate victims with offers or threats that they would not want to present to an employer, like employment offers or illicit content. Defenders will begin to appreciate that inconsistent user behaviors are the most effective way to differentiate malware and insider threats from safe and acceptable content.

A big part of the challenge with cyberattacks is how businesses think threats can be filtered at the perimeter. Be warned that this is not the case. Attackers are aware of how to directly target users and endpoints using social engineering. The industry needs to be more proactive in thinking about how to reduce the attack surface, as opposed to chasing known threats and detecting millions of unknown threats. With an increasingly mobile workforce and threats coming through both personal and business devices and services, the impact of perimeter defenses has decreased. Security needs to be built from the endpoint outwards.

Business security spending will increase - Ed Solis, Director of Strategy & Business Development at CommScope

Security is part of every business and IT discussion these days and it will only become more intense in 2017. We see an increase in the demand for video for surveillance, both for government and private businesses. This issue includes physical security—securing the building, people, and assets—as well as network and data security... In 2017, security conversations will continue to intensify around not only securing data and networks but physical security as well-think buildings, people, and assets. We also expect to see an increased demand for video surveillance across the public sector and private business.

Security will no longer be an afterthought - Signal Sciences' Co-Founder & Chief Security Officer, Zane Lackey

2017 will be a critical year for security, starting with how it's built into technology. DevOps and security will change the way they work together as they realize the need to integrate with each other in order to survive. With IoT on the rise, security will continue to be the primary obstacle preventing consumers from fully welcoming connected devices into their homes and lifestyles. Consumers and businesses are getting smarter and security vendors will be held more accountable in keeping them safe.


Thursday, December 8, 2016

Tyre&Auto Southbourne Group Review: Why Car Exhausts Matter

At no time in the history of human civilization have we suffered more respiratory diseases than when we began using the combustion engine at the start of the Industrial Revolution. Today, the levels of pollution in major cities around the world have reached extreme levels. Think of such cities like LA, Mexico, Bangkok and Beijing and you can imagine the thousands of people who suffocate under the fumes expelled by millions of vehicles into the atmosphere.

With the introduction of alternative energy sources to operate vehicles, however, we are beginning to cope with this growing menace to human health. In the meantime, new techniques have been developed to minimize the effects of exhaust fumes from combustion engines.  

Here are some ways in which proper exhaust control can help:

1. Reduce noise level

A professional car servicing company can provide reduction of noise (which is a form of pollution) through proper design and installation of an exhaust pipe system. A broken exhaust pipe, a result of accidents or improper care, can increase noise levels. Immediate repair is required.

2. Direct exhaust away from passengers

The exhaust from a car is designed to be directed away passengers; hence, it is at the tail end of the car or raised high up to facilitate escape into the atmosphere. Any clogging or leaks will cause the exhaust to enter through windows or holes in the chassis. Determining this seemingly minor yet unhealthy fault can help owners experience a more comfortable ride.

3. Improve engine performance  

A defective exhaust pipe decreases the ability of the engine to maximize its burning capability, hence, diminishing its power and performance. In fact, a big percentage of an engine’s power is lost due to the inefficient disposal of the waste gases resulting from the combustion process. Think of a person’s sinusitis which prevents one from breathing out the carbon dioxide from the lungs. What we expel is as important as what we take in. So it is with a car.

4. Improves fuel consumption

With proper burning, fuel consumption becomes more efficient. It also means maximizing your money spent on petrol. A defective exhaust system reduces the mileage you get out of a liter of petrol you buy.

In short, not only do we pollute the atmosphere with a faulty exhaust pipe system, we are practically burning money that virtually escapes from our pockets and enters ours lungs in the form of toxic gases and black soot. Controlling the quantity and the quality of exhaust fumes is every person’s responsibility to maintain a healthy environment.

Thursday, November 24, 2016

Security and Risk Online: Fake Retail Apps Are Surging Before Holidays

Hundreds of fake retail and product apps have popped up in Apple’s App Store in recent weeks — just in time to deceive holiday shoppers.

The counterfeiters have masqueraded as retail chains like Dollar Tree and Foot Locker, big department stores like Dillard’s and Nordstrom, online product bazaars like Zappos.com and Polyvore, and luxury-goods makers like Jimmy Choo, Christian Dior and Salvatore Ferragamo.


“We’re seeing a barrage of fake apps,” said Chris Mason, chief executive of Branding Brand, a Pittsburgh company that helps retailers build and maintain apps. He said his company constantly tracks new shopping apps, and this was the first time it had seen so many counterfeit iPhone apps emerge in a short period of time.

Some of them appeared to be relatively harmless — essentially junk apps that served up annoying pop-up ads, he said.

But there are serious risks to using a fake app. Entering credit card information opens a customer to potential financial fraud. Some fake apps contain malware that can steal personal information or even lock the phone until the user pays a ransom. And some fakes encourage users to log in using their Facebook credentials, potentially exposing sensitive personal information.

The rogue apps, most of which came from developers in China, slipped through Apple’s process for reviewing every app before it is published.

That scrutiny, which Apple markets as an advantage over Google’s less restrictive Android smartphone platform, is supposed to stop any software that is deceitful, that improperly uses another company’s intellectual property or that poses harm to consumers.

In practice, however, Apple focuses more on blocking malicious software and does not routinely examine the thousands of apps submitted to the iTunes store every day to see if they are legitimately associated with the brand names listed on them.

With apps becoming more popular as a way to shop, it is up to brands and developers themselves to watch for fakes and report them, much as they scan for fake websites, said Ben Reubenstein, chief executive of Possible Mobile, a Denver company that makes apps for JetBlue Airways, the PGA Tour and the Pokémon Company, among others.

“It’s important that brands monitor how their name is being used,” he said.

Apple removed hundreds of fake apps on Thursday night after The New York Times inquired about the specific app vendors that created many of them. Other apps were removed after a New York Post article last week drew attention to some of the counterfeits.

“We strive to offer customers the best experience possible, and we take their security very seriously,” said an Apple spokesman, Tom Neumayr. “We’ve set up ways for customers and developers to flag fraudulent or suspicious apps, which we promptly investigate to ensure the App Store is safe and secure. We’ve removed these offending apps and will continue to be vigilant about looking for apps that might put our users at risk.”

In September, Apple also embarked on a campaign to review all two million apps in the App Store and remove “apps that no longer function as intended, don’t follow current review guidelines or are outdated.” The company says that a significant number of apps have been removed and that the review is continuing.

Despite Apple’s efforts, new fake apps appear every day. In some cases, developers change the content of an app after it has been approved by Apple’s monitors. In other instances, the counterfeiters change their names and credentials, and resubmit similar apps after one round of fakes is discovered.

“It’s a game of Whac-a-Mole,” Mr. Mason of Branding Brand said.

On Friday, for example, an entity calling itself Overstock Inc. — an apparent attempt to confuse shoppers looking for the online retailer Overstock.com — was peddling Ugg boots and apparel through a fake app that was nearly identical to one banished by Apple on Thursday.

The same Chinese app developer, Cloaker Apps, created both fake Ugg apps on behalf of Chinese clients.

Jack Lin, who identified himself as the head of Cloaker, said in a phone interview in China that his company provides the back-end technology for thousands of apps but does not investigate its clients.

“We hope that our clients are all official sellers,” he said. “If they are using these brands, we need some kind of authorization, then we will provide services.”

Mr. Lin said Cloaker charged about 20,000 renminbi — about $3,000 — for an app written in English.

But like so many of the apps his company produces, Cloaker is not what it purports to be. Its website is filled with dubious claims, such as the location of its headquarters, which it says is at an address smack in the middle of Facebook’s campus in Menlo Park, Calif.

In the interview, Mr. Lin at first said he had offices only in China and Japan. When asked about the California office, he then claimed to have “tens of employees” at the Facebook address.

China is by far the biggest source of fake apps, according to security experts.

Many of the fake retail apps have red flags signaling that they are not real, such as nonsensical menus written in butchered English, no reviews and no history of previous versions. In one fake New Balance app, for example, the tab for phone support did not list a phone number and said, “Our angents are available over the hone Monday-Firday.”

Data from Apptopia show that some of the fake apps have been downloaded thousands of times, although it is unclear how many people have actually used them. Reviews posted on some of the apps indicated that at least some people tried them and became frustrated. “Would give zero stars if possible,” wrote one reviewer of the fake Dollar Tree app. “Constantly gets stuck in menus and closes what you were doing and makes you start over.”

Mr. Mason says consumers want to shop online and they search for apps from their favorite stores and brands.

“The retailers who are most exposed are the ones with no app at all,” he said. Dollar Tree and Dillard’s, for example, have no official iPhone apps, which made it easier to lure their customers to the fake apps.

But the counterfeiters have also mimicked companies that do have an official presence in the App Store, hoping to capitalize on consumer confusion about which ones are real.

The shoe retailer Foot Locker Inc., for example, has three iPhone apps. But that did not stop an entity calling itself Footlocke Sports Co. Ltd. from offering 16 shoe and clothing apps in the App Store — including one purporting to be from a Foot Locker rival, Famous Footwear.

Similarly, the supermarket chain Kroger Company has 20 iPhone apps, reflecting the various retail chains in its empire. An entity calling itself The Kroger Inc. had 19 apps, purporting to sell things as diverse as an $80 pair of Asics sneakers and a $688 bottle of Dior perfume.

Some of the fake apps have even used Apple’s new paid search ads to propel them to the top of the results screen when customers search for specific brands in the App Store.

Jon Clay, director of global threat communications for Trend Micro, an internet security firm, said Apple’s tight control over the iPhone had historically kept malicious apps out of its App Store. Fake apps appeared more often on Google’s Android platform or on third-party app stores, he said.

But that is beginning to change. Shortly after the Pokémon Go game was released in the United States in July, for example, a spate of fake iPhone apps related to the game appeared, especially in countries where the game was not yet available.

“The criminals are going to take advantage of whatever is hot,” Mr. Clay said.

Tuesday, November 8, 2016

Coalition Against Insurance Fraud: Fraud prosecutors in N.J. lose tool against defendants

Loss of pre-trial detention hampers cooperation by fraudsters

Prisons and jails across the U.S. are overcrowded, costly and at a breaking point in many states. Jurisdictions are working to ease the pressure in a variety of ways. California, for example, has released more than 30,000 inmates early in the last five years. Other states use alternative sentencing.

New Jersey is taking a different approach. It has done away with pre-trial detention except for the most-violent crimes or people who are flight risks.

Fraud prosecutors in the Garden State say the new law makes their jobs tougher. A runner employed by a staged-crash ring who gets caught no longer has to worry about making bail. The threat of pre-trial detention often spurs a runner to cooperate with law enforcement and help nail the gang’s masterminds. But no longer.

Now, runners are processed and given a summons, kind of like getting a traffic ticket.

The concern here is that the lack of pre-trial detention throws up one more roadblock for many local prosecutors who already are overworked and hesitant to take complex, time-consuming fraud cases.

There are no easy answers. It’s unlikely lawmakers will make an exception to the law for non-violent, white-collar crimes.

Deterring fraud rings is difficult, though achievable. The anti-fraud advertising campaign by the Office of Insurance Fraud Prosecutor and state AG is excellent, though it’s oriented towards everyday consumers, not organized criminals. Perhaps outreach to lower-level gang members about the dangers of committing fraud might help deter.

The best approach might be for insurers to focus even more on taking the profit out of insurance crime. Greater use of technology will detect scams earlier before claims money goes out the door. More civil suits with treble damages against crooked medical providers and other ringleaders will hurt them where it counts.

Fraud fighters around the U.S. will have to rely less on arrests and prosecutions. They still can curb insurance fraud by improvising and relying more on their creative expertise.