Wednesday, January 27, 2016

Software : Lenovo's file-sharing app actually used this terrible password

Software : Lenovo's file-sharing app actually used this terrible password


Lenovo's file-sharing app actually used this terrible password

Posted:

Lenovo's file-sharing app actually used this terrible password

Lenovo has just patched up a piece of its software to remove major security flaws which included a rather unbelievable password blunder.

By now, we're all used to the regular articles about how Joe Public's password practices are terrible, but you wouldn't expect a computing giant like Lenovo to use a default password that made the worst passwords of 2015 list for one of its apps.

Unfortunately, as Core Security spotted, that's exactly what Lenovo did with its ShareIt app for Windows and Android, a program that allows file sharing between PCs and phones/tablets, which comes with a default password which is the same for every user when it sets up a Wi-Fi hotspot in order to facilitate the transfer of files.

And that default password was: '12345678'. Which just happens to be third place on the latest stupid passwords list (only bested by the slightly less secure because it's shorter '123456', and that old chestnut 'password').

In other words, anyone could connect to the hotspot via a device with Wi-Fi, either knowing the password was this, or simply by guessing the password given its eminently guessable nature, and subsequently view the files (via an HTTP Request to the web server launched by the program).

No encryption

Core Security also noted that the files being shared were transferred via HTTP with no encryption used, a further vulnerability which is obviously bad news and could potentially allow an attacker to view the data being transferred.

However, as we said at the outset, the good news is that all this has now been changed with the latest patch – so if you use ShareIt, do make sure you update to the latest version.

ShareIt is used for quick and convenient file sharing by some 30 million folks across the world.

Via: PC Gamer

Microsoft's new iOS News Pro app promises news you can use

Posted:

Microsoft's new iOS News Pro app promises news you can use

The problem with news is that there's a lot of it. We're surrounded by breaking news every minute of every day.

So how do we separate the useful news from the useless news? Microsoft reckons it's by using its new News Pro app, which surprised everybody by launching on iOS today, going up against iOS 9's own Apple News app.

Described by Microsoft as "hyper-relevant news for your work", News Pro uses Bing to try and create a custom news feed that caters to your individual career. Whether you're an IT manager or a plumber, News Pro promises to bring you all the best news, and none of the rubbish you don't care about.

News Unlimited

Once downloaded, you're prompted to sign in via LinkedIn or Facebook, with the app then creating a custom feed based on your profile information.

The app itself is reminiscent of every other news app in existence (how much can you really do with news feeds, anyway), but does offer a convenient "Speedy" mode to cut back on the junk in order to load stories quickly.

The free app from Microsoft Garage (the same group behind that ridiculous alarm clock app) is only available in the US at the moment, though you can play around with the browser version anywhere.

No comments:

Post a Comment