Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Saturday, 27 July 2013

Extreme Reality turns skeletons into biometric signatures



Gesture control is the new mouse, but Extreme Reality co-founder and CTO Dor Givon believes the underlying technology for tracking body motion could be a boon for security applications. The company, based in Herzelia, Israel, has patented software technology for enabling full-body, 3D motion control to any device via a standard 2D camera.
Unlike Microsoft's popular Kinect gesture controller, which requires a special camera and sensor, or PointGrab's hand-gesture recognition software, Extreme Reality's Motion software recognizes and tracks the three dimensions of a user's skeletal joints and then converts the joint movement into a continuous dynamic motion.
Some PC manufacturers, such as Samsung and NEC, are including Extreme Motion on some of their PCs and video game developers are incorporating the technology into PC and tabletgames. Side-Kick Games' Top Smash Tennis, for example, uses Extreme Motion to allow players to use full-body motion to hit virtual tennis balls. Leading console makers Sony and Nintendo may adopt the technology, Givon said.
The company is now taking its Extreme Motion technology into the security field. "We are working with skeletal information in a way that enables differentiation between people," he said. "We can analyze skeletal data and generate a unique biometric signature, so it could recognize an individual when they want to log into a device or enter a secured perimeter. It's the first technology that allows full-body 3D motion capture to recognize an individual's gait as a biometric signature."
Dor Givon CTO and co-founder of Extreme Reality.
Extreme Reality's software overlays a 3D engine on a 2D skeleton, creating a single highly accurate image, Givon said. It mathematically eliminates "noise," such as positions that are physically out of bounds for the range of human motion and joints. Unlike wireless infrared-based controllers, Extreme Reality's software technology can work in direct sunlight as well as low light conditions, Givon said.
Givon contends that gait analysis can provide much greater accuracy than face recognition. "Face-recognition technology is very limited. You have to be in a similar position every time for analysis. If someone wants to avoid face recognition they can just put on sunglasses or a beard. They way people walk is hard to change," he said.
He cautioned that the technology is not a stand-alone or bullet proof solution, and expects that his company's technology will become available in third-party security products next year."It's an additional set of alarms, not a replacement for the human eye detecting suspicious behavior in a crowd," Givon said. "It's accurate enough to be deployed as part of holistic solution."
Extreme Reality's technology could also be applied to augmented reality experiences and wearable devices. "We can change the environment from moment you wake up in morning," Givon said. "The rooms knows it's you, and can enhance the environment with augmented reality elements that let you control them with your body in the most natural way. It could be integrated with fitness apps and simulators for activities like golf. This can be deployed in every moment in our life."
Extreme Reality has 45 employees, and has raised about $14 million in private investment.


Sunday, 21 July 2013

Amid Apple developer site outage, users report unauthorized password resets

Reports on social-networking and microblogging sites may signal security trouble for Apple.
Apple's Dev Center, the member's only area for paid developers, has been down for about two days, for no given reason. Stating, "we'll be back soon," Apple said Thursday that the site was "undergoing maintenance for an extended period."
Apple's developer entrance site, however, remains up andworking fine.
Friday rolled on, and the site's outage continued. iOS and OS X developers began to get cranky, particularly during a time in which iOS 7 and OS X Mavericks are in beta and developers remain eager to get their hands on the latest software bits. 
Existing application developers are unable to access any part of the developer site -- including downloads, help, guides, support, and crucial developer tools. More worryingly, developers that need peer support are unable to access Apple's developer forums, where paid application writers discuss all things software.
The site's message changed late Friday to state the maintenance is "taking longer than expected." It added: "If your program membership was set to expire during this period, it has been extended and your app will remain on the App Store."According to posts on various sites, iTunesConnect and app provisioning are working fine, but the developer portal site appears to be taking the brunt of the issue.
Rumblings across social networks and developer forums point to concern that Apple may have suffered a security breach, similar to an attack on Dropbox last year, which led to a spam attack on many of its users. The logic is that any scheduled maintenance would likely not come at a time during beta testing.
Emergency maintenance, such as to patch or fix a security flaw or lapse, could happen at any time and without warning.
Twitter has also been abuzz with reports that users have received password reset e-mails, including some repeated attempts, as reports from Neowin and Hacker News noted.
re-upload
Not every developer has received an Apple password reset request -- whether authorized by Apple, or sent as a result of an attacker or hacker attempting to reset a developer's password without permission.
(We also checked other keywords, such as "google reset" and "microsoft reset," and even "account reset" on social-media sites, and nothing appeared particularly out of order.)
A number of Apple developers on Twitter responded when asked if they had received a password reset e-mail. This seems to point toward a spattering of password reset e-mails rather than Apple forcing its users to change their passwords.
Tumblr co-founder and Instapaper creator Marco Arment said in a tweet Saturday afternoon: "The longer it goes, the more I believe the security-issue theory."

But if it is a security issue, there still remain unanswered questions over what happened.
Apple, a company that is notoriously secretive, will have to not only admit to its users what happened to cause the outage and downtime but also explain in precise detail what happened, when, how, and ultimately why.
The unauthorized password reset e-mails that have been landing in in-boxes over the past 24 hours likely have nothing to do with a flaw the company patched in March. A flaw in the iForgot password reset system could have allowed an attacker to reset an account with just an e-mail address and date of birth. 
At this point, in true style for the Cupertino, Calif.-based technology giant, it's not saying anything to any effect. We've put in questions to Apple, but did not hear back by publication time.
We'll keep this article updated as and when more comes in.




Thursday, 21 March 2013


Security hole allows anyone to bypass and disable Galaxy Note 2’s lockscreen [video]

 
galaxy-note-2
One of the ways to protect your smartphone from the prying eyes of others is to set a secure lockscreen; be it with the PIN, pattern, or password lock. But then again, they might not be good enough if you own a Samsung handset running Android 4.1.2, or in this particular case, the Galaxy Note 2.
Terrence Eden has opened our eyes last week about the security flaw on the Note 2 that allows well-informed individuals to bypass the phone’s lockscreen. Now, a similar lockscreen bug has been discovered.

All they have to do is place an emergency call from the lockscreen, enter any bogus number, hit the green dial button, dismiss the error message, and press the back button. That’s all it takes for someone to gain access to your homescreen – albeit only for a split second.
However, his video demonstration shows how those windows of opportunity – considering that the process can be easily repeated over and over again – were more than enough to let him access Google Play, do a Voice Search on a lockscreen disabler app, install and run the app, and ultimately defeat the system.
It took some persistence, but he pulled it off in less than 3 minutes.
Eden has contacted Samsung about the bug and the South Korean said that a software patch should be on its way soon. In the meantime, you may want to be extra careful with where you place your precious phone. Better yet, keep it safe with you at all times.