domingo, 29 de julho de 2012

Smartphones com tecnologia NFC mais expostos a falhas de segurança(Smartphones NFC more exposed to security breaches)


Os smartphones com tecnologia Near Field Comunication (NFC) estão mais expostos a falhas de segurança, que permitem aos hackers aceder indevidamente a fotos, mensagens de texto, navegar na Web e mesmo fazer chamadas de voz.
O alerta foi feito ontem durante a conferência anual sobre segurança Black Hat, na cidade de Las Vegas, EUA, por Charlie Miller - antigo hacker especializado em smartphones e atual consultor de segurança na empresa Accuvant - durante uma demonstração que revelou as facilidade de aceder aos conteúdos e funcionalidades de um Samsung Nexus S, um Galaxy Nexus e de um Nokia N9, baseados em sistemas operativos Android e MeeGo.
De acordo com o New York Times, em todos os modelos Charlie Miller conseguiu aceder a fotos, enviar textos, navegar na Internet e fazer chamadas de voz sem necessidade de tocar nesses mesmos terminais. A culpa, segundo Miller, está na tecnologia de comunicações a curta-distância Near Field Communication - que permite a dois dispositivos próximos "falar" entre eles, nomeadamente através da troca de cartões de visita, músicas, dados de versões "mobile" de jogos, ou mesmo fazer pagamentos, por exemplo.
Para demonstrar as fragilidades da tecnologia, Miller usou um smartphone com um chip que, em proximidade com um terminal Nexus S com Android, conseguiu direcionar o browser do Samsung para um site com código malicioso e, a partir daí, aceder à diretoria com todos os ficheiros do terminal atacado.

O mesmo tipo de demonstração foi também feita usando um Nokia N9 (sistema operativo MeeGo) e entrar na informação do terminal foi "canja". Neste caso, Miller explicou que a funcionalidade NFC está desativada por defeito, o que protege o terminal de ataques, mas assim que o utilizador a ativa o smartphone passa a aceitar todos os pedidos de ligação que receber.
De acordo com analistas citados pelo New York Times, cerca de 70 milhões de smartphones vendidos este ano em todo o mundo deverão incluir esta tecnologia, o que abre uma questão de segurança adicional a quem os utiliza.
Na europa os terminais com NFC são já amplamente utilizados desde 2011, enquanto nos EUA os mesmos analistas referem que a entrada está a ser feita de forma faseada, sobretudo em sistemas para pagamentos de pequenas quantias. Por exemplo, a solução Google Wallet utiliza a tecnologia NFC para permitir pagamentos, que já podem ser feitos, por exemplo, nos táxis de Nova Iorque.
Numa espécie de jogo entre o gato e o rato, a Google refere ter corrigido as vulnerabilidades de segurança em modo NFC na versão 4.01 do Android, mas Charlie Miller acabou por demonstrar as mesmas vulnerabilidades a partir da funcionalidade Android Beam, que recorre a APIs NFC para que dois telemóveis comuniquem entre si.

Smartphones with Near Field Comunication Technology (NFC) are more susceptible to security flaws that allow hackers to improperly access to photos, text messages, surf the Web and even make voice calls.
The warning came yesterday during the annual Black Hat security in the city of Las Vegas, USA, by Charlie Miller - former hacker who specializes in smartphones and current security consultant in the company Accuvant - during a demonstration showed the ease of access content and functionality of a Samsung Nexus S, a Galaxy and a Nexus Nokia N9, based on MeeGo and Android operating systems.
According to the New York Times, in all models Charlie Miller was able to access photos, send texts, surf the Internet and make voice calls without touching these same terminals. The blame, according to Miller, the communications technology is a short-range Near Field Communication - that allows two nearby devices "talk" between them, including through the exchange of business cards, music, data versions of "mobile" games , or make payments, for example.
To demonstrate the weaknesses of the technology, Miller used a smartphone with a chip that, in proximity to a terminal Nexus S with Android, could direct the browser to a Samsung site with malicious code and, thereafter, access to the Board with all Files terminal attacked.

The same demonstration was also made using a Nokia N9 (MeeGo operating system) and enter the information of the terminal was "soup". In this case, Miller explained that the NFC functionality is disabled by default, which protects the terminal from attacks, but once the user activates the smartphone starts to accept all connection requests it receives.
According to analysts cited by the New York Times, about 70 million smartphones sold this year worldwide will include this technology, which gives an additional safety concern to those who use them.
In Europe the terminals with NFC are already widely used since 2011, while in the U.S. the same analysts note that the entry is being done in phases, especially in systems for payments of small amounts. For example, the solution utilizes Google Wallet NFC to enable payment, which can now be made, eg, taxis, New York.
In a kind of game between the cat and mouse, Google states have fixed security vulnerabilities in NFC mode in version 1.4 of Android, but Charlie Miller eventually show the same vulnerabilities as the Beam feature Android, which uses APIs for NFC two mobile phones communicate with each other.

Sem comentários:

Enviar um comentário