WHAT'S NEW?
Loading...
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts


I talked about the FBI attempting to force Apple to unlock their iPhone for them, but now it seems like the FBI doesn't need that anymore. That's because they've allegedly hacked the encryption on the iPhone themselves, and are already agreeing to help Arkansas prosecutors hack their iPhone as well. While we don't know exactly how the FBI hacked the iPhone, we do know one thing. If it can be done to one, it can be done to them all. Most people aren't against the government having the ability to get into their homes if they're breaking the law (and for probable reason) but this isn't just one phone. Imagine the government making a master key that can unlock every person's house door. What if it got stolen? What if a corrupt official were to use it without probable cause? These kinds of questions are what are being raised about the technique the FBI used to hack the iPhone.

Not only is this bad news for us, but it's also bad news for Apple. Now there is a security issue in their phones, which can cause people to not buy them. This is the government directly getting in the way of free enterprise. If the government keeps this all-access key instead of giving it up to Apple to fix, I can only see Apple retaliating. For a country that is so lucky to have so many tech giants' headquarters reside, it sure is odd that our government is so against technological progress.

Thankfully, the government probably won't have use for this vulnerability for much longer. Since it's almost inevitable that an exploit like this will not stay a secret, it will eventually get leaked and make its way back to Apple. Still, when so many iPhones will stay in evidence, unupdated, it begs the question of just how many iPhones local and federal governments will have access to.

Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety.  - Benjamin Franklin

Image source: Forbes 


You must have been living under a rock if you haven't heard about this by now, but just in case Patrick Star is reading this, I'll explain what happened.

Last December there was a terrorist attack in San Bernardino, California. This attack resulted in 14 deaths and 22 injuries. Now, the courts have ruled that Apple has to help the FBI and the United States government hack into the perpetrator's iPhone. Apple has rightfully opposed this ruling, citing the security issues that can and will result from them doing this.

Apple has the capability to do this. Encryption is a word commonly thrown around, but few outside of the tech industry really understand what it means. Encryption is when data, in this case the user data on an iPhone, is scrambled in a way that it becomes unreadable without a specific key. Without the key, it is virtually impossible for anyone but the best hackers to break that encryption. Once the encryption algorithm is broken, any device using the same algorithm can be easily broken as well. What the FBI wants Apple to do is create a custom iOS update that they're going to install on this specific iPhone that will decrypt its data. That's great, right? It's only for one iPhone. Wrong.

With this piece of software that the FBI wants Apple to create, it not only allows the FBI to unlock anyone's iPhone, but it creates a backdoor that anyone will soon be able to access. If that software is leaked in any way, there is no way to tell how widespread it could get. Creating a backdoor is not just leaving it open for one person, it leaves iPhones vulnerable to everyone. When this happens, iPhones become completely insecure. The whole point of computer security is to completely close any gaps in the security. If there's even one gap, it can and will be exploited. Intentionally creating a flaw as large as this one can only have terrible consequences.

I'm not saying that it's not important that this phone doesn't get hacked, but there are a few things to consider. One, it is not Apple's responsibility to provide the FBI with the tools to hack its secure devices. And two, if they do, it will completely destroy Apple's reputation as a company that values security. Because of this, Tim Cook, Apple's CEO, has written a public letter to its customers on this topic of encryption. (Here.) I completely support Apple taking a stand against a court who obviously doesn't understand the repercussions of this order.

VPNs, or Virtual Private Networks, allow you to access the Internet from a different server. This might be useful if you're at home, needing to do something from your work's internet. Lately, however, VPNs have been useful for a whole lot more. There are entire companies devoted to selling VPN servers to allow users to access the internet through them. But why would you want to?

First, I'll go over the path your data takes when connected to a typical commercial VPN server. VPNs are the middleman between you and the rest of the Internet. When you send out a message saying "Hey!", instead of being sent directly to whatever messaging service you're using, that request is sent to the VPN. The VPN then passes that "Hey!" on to the messaging server. Likewise, when a message "Hello" is sent back, it's sent from the messaging server, to the VPN server, to you. Most VPNs also offer encryption services as well, so that nobody can read your data except you.



Okay, but why do you need this? Think of it this way. What if the message you sent out said something personal or confidential? What if someone intercepted that message along the way to the messaging server, like the NSA or a hacker? You wouldn't want anyone getting ahold of that information and tracing it back to you. So VPNs let you hide behind them to protect your anonymity. Every computer sends out a specific IP address that can be traced back to you, and it's public to anything you connect to. Every website, program, anything has access to your IP address. But if you send out that message to the VPN first, and then the VPN delivers it, all that website or program gets is the VPN's IP address. Not yours. This also allows you to pretend you're from a different country and get around geographic blocks on certain websites.

The bad news is, VPNs cost money. It costs money to run a server and there are no ads to pay for it. The good news is, they're fairly cheap and easy to set up depending on where you buy your VPN from. I recommend Private Internet Access, where you can get a full year of VPN access for less than $40. You can usually find an even better deal during the holidays. Once you buy it, they're as simple as installing a program and picking the server closest to you. Be careful about cheap or free VPNs that aren't considered trustworthy. All your data is going through them! Pick one with a long history of happy customers, and one that promises to not keep logs of their customers' data.

Once you have a VPN going, no-one can track you. Your data is encrypted and safe from start to finish. You can even use a VPN on your phone! So if you're big on security, spend a bit on a VPN so you'll never have to worry again.