Showing posts with label smart phones. Show all posts
Showing posts with label smart phones. Show all posts

Sunday, January 24, 2021

Cyber: Cyber Security for Consumer Internet of Things (IoT)

 


Still olden but golden, when it comes to IoT Connected Devices


I have briefly touched upon IoT (Internet of Things) at my blog previously:

Fast moving wireless world

https://trewmte.blogspot.com/2014/10/fast-moving-wireless-world.html

The Internet of Things (IoT)

https://trewmte.blogspot.com/2016/03/the-internet-of-things-iot.html

The Rise of (IoT) Domestic Appliance Forensic Examiners

https://trewmte.blogspot.com/2016/03/the-rise-of-iot-domestic-appliance.html

Smart Phones with Smart Homes

https://trewmte.blogspot.com/2016/06/smart-phones-with-smart-homes.html

eSIM - Observing Possible Outcomes Part 1

https://trewmte.blogspot.com/2019/12/esim-observing-possible-outcomes-part-1.html


I am adding update reference materials available on IoT and Cyber, if you haven't seen this info or weren't aware, which you might find useful.

ETSI in February 2019 released the first globally applicable standard for consumer IoT security:

etsi-releases-first-globally-applicable-standard-for-consumer-iot-security?jjj=1611490283528

This publicised event introduced the ETSI Stand ts_103645v010101 (2019)

CYBER; Cyber Security for Consumer Internet of Things

ts_103645v010101p.pdf

In 2020 ETSI updated the standard ts_103645v020102 with enhanced baseline requirements:

CYBER; Cyber Security for Consumer Internet of Things: Baseline Requirements

ts_103645v020102p.pdf

The object of these standards is to improve security and privacy. A common default password for all products are to be scrubbed with a unique default password per device applied instead. Moreover, it should not be possible to enable the password set at default in the first place once user changed. Apparently, many IoT (consumer) products on the market may still not (even today) meet this password objectives or other more basic requirements that have been stated in this newly released standard. 

Measures vendor companies should understake range from adopting simple installation and user guidance with good documentation in support; good hardware/software security engineering practice; for personal privacy the standard sets out protection objectives for all sensitive personal data required to be stored securely - that is both on devices, themselves, and in any related services e.g. in the cloud. Any personal data should be encrypted and should be protected against attack; and with clear instructions how consumers can easily delete their personal data.

Whilst this standard provides consumers with confidence in their IoT product, it equally has been designed to allow vendors companies sufficient flexibility to enable them to innovate and find the best solution for security and privacy for their particular IoT products. Password protection, encryption, and safe deletion are some solutions. Others could be block-off network ports; close-off software not being used; avoidance of exploited data (OOR) by adoption of a validation approach; secure-boot mechanisms (hardward-based); with ease and secure device software updates (e.g. use- menu selection or autonomic/automated (e.g. ZTP etc)). These are possible solutions.

I did like that ETSI had included specific demands about disclosure in this standard for vendor companies to identify, act upon and promptly report vulnerabilities.

However, from a cyber aspect, the ETSI Technical Committee on Cybersecurity (TC CYBER) has overseen and published over 50 cyber standards, some of which are referenced below:

ETSI TS 103 744 V1.1.1 (2020-12)Published

CYBER; Quantum-safe Hybrid Key Exchanges


ETSI TS 103 523-1 V1.1.1 (2020-12)Published

CYBER; Middlebox Security Protocol; Part 1: MSP Framework and Template Requirements


ETSI TS 103 718 V1.1.1 (2020-10)Published

CYBER; External encodings for the Advanced Encryption Standard


ETSI TR 103 644 V1.2.1 (2020-09)Published

CYBER; Observations from the SUCCESS project regarding smart meter security


ETSI TS 103 485 V1.1.1 (2020-08)Published

CYBER; Mechanisms for privacy assurance and verification


ETSI TR 103 619 V1.1.1 (2020-07)Published

CYBER; Migration strategies and recommendations to Quantum Safe schemes


ETSI EN 303 645 V2.1.1 (2020-06)Published

CYBER; Cyber Security for Consumer Internet of Things: Baseline Requirements


ETSI TS 103 645 V2.1.2 (2020-06)Published

CYBER; Cyber Security for Consumer Internet of Things: Baseline Requirements


ETSI TR 103 306 V1.4.1 (2020-03)Published

CYBER; Global Cyber Security Ecosystem


ETSI TR 103 644 V1.1.1 (2019-12)Published

CYBER; Increasing smart meter security


ETSI TR 103 618 V1.1.1 (2019-12)Published

CYBER; Quantum-Safe Identity-Based Encryption


ETSI TR 103 331 V1.2.1 (2019-09)Published

CYBER; Structured threat information sharing


ETSI TS 103 523-3 V1.3.1 (2019-08)Published

CYBER; Middlebox Security Protocol; Part 3: Enterprise Transport Security


ETSI TS 103 523-3 V1.2.1 (2019-03)Published

CYBER; Middlebox Security Protocol; Part 3: Enterprise Transport Security


ETSI TS 103 645 V1.1.1 (2019-02)Published

CYBER; Cyber Security for Consumer Internet of Things


ETSI TR 103 370 V1.1.1 (2019-01)Published

CYBER; Practical introductory guide to Technical Standards for Privacy


ETSI TS 103 457 V1.1.1 (2018-10)Published

CYBER; Trusted Cross-Domain Interface: Interface to offload sensitive functions to a trusted domain


ETSI TR 103 642 V1.1.1 (2018-10)Published

CYBER; Security techniques for protecting software in a white box model


ETSI TS 103 523-3 V1.1.1 (2018-10)Published

CYBER; Middlebox Security Protocol; Part 3: Profile for enterprise network and data centre access control


ETSI TR 103 617 V1.1.1 (2018-09)Published

CYBER; Quantum-Safe Virtual Private Networks


ETSI TR 103 305-1 V3.1.1 (2018-09)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 1: The Critical Security Controls


ETSI TR 103 305-2 V2.1.1 (2018-09)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 2: Measurement and auditing


ETSI TR 103 305-3 V2.1.1 (2018-09)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 3: Service Sector Implementations


ETSI TR 103 305-5 V1.1.1 (2018-09)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 5: Privacy enhancement


ETSI TR 103 305-4 V2.1.1 (2018-09)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 4: Facilitation Mechanisms


ETSI TR 103 306 V1.3.1 (2018-08)Published

CYBER; Global Cyber Security Ecosystem


ETSI TS 103 458 V1.1.1 (2018-06)Published

CYBER; Application of Attribute Based Encryption (ABE) for PII and personal data protection on IoT devices, WLAN, cloud and mobile services - High level requirements


ETSI TS 103 307 V1.3.1 (2018-04)Published

CYBER; Security Aspects for LI and RD Interfaces


ETSI TS 103 532 V1.1.1 (2018-03)Published

CYBER; Attribute Based Encryption for Attribute Based Access Control


ETSI TR 103 456 V1.1.1 (2017-10)Published

CYBER; Implementation of the Network and Information Security (NIS) Directive


ETSI TS 102 165-1 V5.2.3 (2017-10)Published

CYBER; Methods and protocols; Part 1: Method and pro forma for Threat, Vulnerability, Risk Analysis (TVRA)


ETSI TR 103 570 V1.1.1 (2017-10)Published

CYBER; Quantum-Safe Key Exchanges


ETSI TR 103 421 V1.1.1 (2017-04)Published

CYBER; Network Gateway Cyber Defence


ETSI TR 103 306 V1.2.1 (2017-03)Published

CYBER; Global Cyber Security Ecosystem


ETSI TS 103 307 V1.2.1 (2016-10)Published

CYBER; Security Aspects for LI and RD Interfaces


ETSI TR 103 305-2 V1.1.1 (2016-08)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 2: Measurement and auditing


ETSI TR 103 305-3 V1.1.1 (2016-08)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 3: Service Sector Implementations


ETSI TR 103 305-4 V1.1.1 (2016-08)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 4: Facilitation Mechanisms


ETSI TR 103 305-1 V2.1.1 (2016-08)Published

CYBER; Critical Security Controls for Effective Cyber Defence; Part 1: The Critical Security Controls


ETSI TR 103 331 V1.1.1 (2016-08)Published

CYBER; Structured threat information sharing


ETSI TR 103 304 V1.1.1 (2016-07)Published

CYBER; Personally Identifiable Information (PII) Protection in mobile and cloud services


ETSI TR 103 369 V1.1.1 (2016-07)Published

CYBER; Design requirements ecosystem


ETSI EG 203 310 V1.1.1 (2016-06)Published

CYBER; Quantum Computing Impact on security of ICT Systems; Recommendations on Business Continuity and Algorithm Selection


ETSI TS 103 307 V1.1.1 (2016-04)Published

CYBER; Security Aspects for LI and RD Interfaces


ETSI TR 103 303 V1.1.1 (2016-04)Published

CYBER; Protection measures for ICT in the context of Critical Infrastructure


ETSI TS 103 487 V1.1.1 (2016-04)Published

CYBER; Baseline security requirements regarding sensitive functions for NFV and related platforms


ETSI TR 103 308 V1.1.1 (2016-01)Published

CYBER; Security baseline regarding LI and RD for NFV and related platforms


ETSI TR 103 306 V1.1.1 (2015-11)Published

CYBER; Global Cyber Security Ecosystem


ETSI TR 103 309 V1.1.1 (2015-08)Published

CYBER; Secure by Default - platform security technology


ETSI TR 103 305 V1.1.1 (2015-05)Published

CYBER; Critical Security Controls for Effective Cyber Defence

Sunday, June 05, 2016

Smart Phones with Smart Homes

There is a great detail of research into smart homes. An interesting article about smart phones and smart homes has been published by Senic ( https://blog.senic.com/smartphone-smart-home-3b5af00c1bfd#.af5985efq ) outlining issues involved with attempting to bring together technologies to interact together under the guise of the Internet of Things (IoT).  The spinning beach ball is part of the analysis Senic is undertaking into understanding how consumers interact and their sensory perceptions:  vision, oral and aural coordination. As smart homes and IoT are still evolutionary early knowledge to assist understanding of the struggles right now could help examiners and investigator with no skillsets and experiences in these fields later on.

Friday, April 10, 2015

Free Mobile JTAG Training and Tools

Visitors to trewmte.blogspot.com may recall a discussion thread posted back in 2012 regarding a JTAG Tutorial http://trewmte.blogspot.co.uk/2012/09/jtag-tutorial.html. The purpose of that thread was to enable students, newcomers and experienced mobile/smart phone examiners to get a feel for JTAG before undertaking such examinations or purchasing tools etc.

Today, Kevin Swartz from www.nowsecure.com has released a FREE three-part training course specifically for JTAGing smart phones. Kevin has dropped a line to me saying "Hi Greg, yes, please feel free to link to any of our free resources pages: https://www.nowsecure.com/resources/".

The FREE three-part training course:

PDF Download: https://www.nowsecure.com/resources/jtag-forensics-training/

JTAG 101 videos:
https://www.youtube.com/playlist?list=PLkotz0CYBQDrXpvO0UZlmrUpQLtegPgWI

JTAG 102 videos:
https://www.youtube.com/playlist?list=PLkotz0CYBQDp_YMS_jMXSjKsvgWtL8e_p

Thanks Kevin. You're a decent chap for your kind gesture to help out students, newcomers and experienced examiners in the community.

Sunday, December 29, 2013

EU common charger for all mobiles/tablets

Members of the European Parliament have presented a persuasive first stage plan, based upon reduction of waste and consumer easy for charger migration when changing to a new handset, to the Council of Members for the need for a universal charger for all new mobiles sold into the EU.

2012/0283(COD)
26.4.2013
***I
DRAFT REPORT
on the proposal for a directive of the European Parliament and of the Council on the harmonisation of the laws of the Member States relating to the making available on the market of radio equipment (COM(2012)0584 – C7-0333/2012 – 2012/0283(COD))
Committee on the Internal Market and Consumer Protection


In accordance with the amendment to Article 2(3) of the proposed Directive.
Amendment 3

"appropriate type throughout the Union may be necessary. Interoperability between radio equipment and accessories such as chargers simplify use of radio equipment and reduce unnecessary waste."

"throughout the Union is necessary in some cases. Interoperability between radio equipment and accessories such as chargers simplifies use of radio equipment, reduces unnecessary waste and costs. A renewed effort to develop a common charger would therefore be highly desirable and consequently be beneficial in particular for consumers and other end-users."


If the further proposed stages receive approval the timescale envisaged to introduce a universal charger common to all new mobile phones could be available on the market by 2017 at the earliest. That is because members states will be given two years to transpose the new directive into local legislation.

Of course, the technical realisation needs to be transformed into an approved technical standard. Some years ago the EU approved micro-USB for use with smart phones. However, as the EU has yet to (a) decide the which standard will be ratified for the proposed universal charger; (b) given there has been technology advances since the earlier approval for use of micro-USB; (c) mobile tablets etc have also proliferated in the marketplace; the directive would need to cover these too, as would the Directive's need to have applicablity to other forms of radio equipment using a charger supplied into the EU for consumer use.

Of the various connector types it could be the universal charger connector may come in several guises. Two that come to mind are Apple's Lightning connector and the new type-C connector USB3.1 recently annouce by the USB Standards Group. Both would already be in the marketplace before the two-year deadline has expired.

Apple's Lightning connector
http://en.wikipedia.org/wiki/Lightning_(connector)







USB Standards Group type-C connector USB 3.1
http://www.usb.org/press/USB-IF_Press_Releases/Type-C_PR_20131203_Final.pdf
http://www.usb.org/developers/USB-Futures.pdf


Image Source - http://www.mrgco.com/blog/usb-3-0-promoter-group-announces-new-type-c-connector-for-usb/ 

Friday, July 19, 2013

Android DDMS Vulnerability

Android DDMS Vulnerability

A suggested in-memory patch solution to the DDMS vulnerability is reported in this article:

https://securityledger.com/2013/07/security-start-up-university-team-on-android-patch-app/

The article states "The flaw is located in an Android component known as the Dalvik Debug Monitor Service (or DDMS), the virtual machine that runs software on Android devices. The vulnerability affects almost all Android devices in use, could allow a malicious actor to modify a legitimate, signed Android application without affecting the application’s cryptographic signature. That would prevent Android from noticing the changes when the application is installed."

So to prevent any new threat occuring ReKey can help you do this. However, what is the solution where threat already existed on the Android phone prior to the in-memory patch being installed? Are there any known affects (exploits that add or alter data or cause call events etc)? Could those 'affects' impact on the weight given to evidence extracted and harvested from a particular smart phone?

How relevant is the above to device examination?   Computer forensic examiners spend hours and days sifting through data and studing how a program installs, executes and stores activity generated by use of a program. Smart phones are now highly complex radio communication and electronic devices running a multitude of internal operating programs, user access programs fashioned to the device, interfaces to connect to other devcies and, all importantly, programs to communicate using radio transmission/receiver technologies GSM, W/CDMA, LTE, Wi-Fi, Bluetooth/IRDA, RFID/NFC.

In the early days of mobile phone examination the SIM Card was the focus of attention as little occurred by way of the handset itself. Evolved feature handsets have transformed mobile phones to smart phones and processes of acquiring data have largely become mechanical with plug-in tools pumping out data in production line fashion. Invariably examiners cannot rely simply one one tool but require a toolbag of tools. These tools in themselves are still not enough as the art and skill of interpretation as to the cause and effect and meaning of data are not present in the tools. Sure, tools may show e.g. a (static/active) graph of internet activity of a smart phone once data has been harvested from it but does the tool confirm whether the smart phone automated that process or whether it involved human intervention to cause the intenet activity?

Evolved, too, has the (U)SIM. Which means understanding of what is actually stored on it and applications that run from it, the (U)SIM, cannot be ignored when it comes to automated processes and human intervention.

Image - SIM Toolkits (STKs): Proactive SIM enables and allows a SIM to issue commands and action responses and thus may be susceptable to generating events in a manner and form that needs to be understood (see: GSM11.14).

The DDMS vulnerability reminds us that over-reliance on a tool simply to extract and harvest data and then present the data in a eye-pleasing format is not enough. Understanding the program/s and apps on a smart phone and in a USIM, its genuineness and originality, how data and records are caused to be generated and the interpretation of the records and data is now where we are at. Production line (bang it on, bang it out) recordings of only call activity, phonebooks, texts, IM messages, graphics, internet etc is fast becoming an incomplete methodology for smart phone and USIM examination.

Monday, April 22, 2013

Tools and Methods for Water Damaged Phones

Tools and Methods for Water Damaged Phones

It's worth recording the links from a discussion that has been being going on about water damaged phones:

Ultrasonic cleaning - http://www.ibreakityoufixit.com/shop/catalog/2
Vermiculite - http://www.cmmp-france.com/shawatecgb.html
Fingerprint Study - http://www.ucidiver.com/fingerprint_study.html
Solder Cleaning - www.tayloredge.com/reference/Science/solder_cleaning.pdf
Isopropyl alcohol - http://gorum.ca/clen-pcb.html
Non-forensic chip off - http://trewmte.blogspot.co.uk/2011/02/mobile-phone-chip-off.html
Reballing - www.emulation.com/pdf/102003BGA_Reballing_Instruction_Manual.pdf
Thermal Profiling - http://en.wikipedia.org/wiki/Thermal_profile
RSS - http://en.wikipedia.org/wiki/File:RSS_Components_of_a_Profile1.svg
Thermal Sensor Probes - http://www.thermometersuperstore.co.uk/acatalog/Probes.html


Updated subject matter:

Hydrophobic Coatings on Electronic Devices

I have been looking further into mobile phone exposure to water to see whether there has been any research or techniques or processes used in manufacturing to combat water damage / corrosions etc. Hydrophobic Coatings appears to offer one solution.

More cell phones are damaged by water than by any other means, and this damage often requires the devices to be discarded. The number of damaged phones is also increasing because these phones are now taken almost everywhere. Chemical vapor deposition may be used to provide a solution to this problem. For example, the phones may be coated with a hydrophobic monolayer or multilayer of fluorosilanes. Bonding of the fluorosilane may be adopted for improvement purposes using a primary adhesion layer, which may be a different silane monolayer, e.g., an isocyanatosilane, and/or by introduction of hydroxyl groups via plasma treatment. The latter process is identified as typically rapid and economical and can be applied both on oxide and polymeric materials. The presence of OH groups can be assayed by XPS, ToF-SIMS and ATR-FTIR. The density of surface hydroxyl groups can be varied by changing the proportions of etch gases, the time and intensity of the plasma treatment, and the system base pressure. The hydrophobicity of the surface can be characterised by contact angle goniometry and XPS and ToF-SIMS analysis of fluorine. Resistance to abrasion can be tested with a Martindale abrasion tester.

These selection of applied treatments appear to reduce and slow down the water damage/corrosion and present improved chances of memory retention in unspoiled memory chips.

I see a relevance for knowing about treatments, such as the above, as it can help on many levels: as background prep knowledge, towards a recovered exhibit examination procedure, for use in advisory role as to why some water damaged phone exhibits could produce better results or capable of undergoing tests than others phones, and so on.

Tuesday, November 20, 2012

Mobile Flash Data Erasure

Mobile Flash Data Erasure

Secure your smartphone and tablet


                                                  Photo courtesy of Blancco

The growth in smart phones naturally means consumers will see even more utilities and tools similiar to those found on PCs, laptops and notebooks etc. A trend that is growing in relation to cleansing of personal details and company information stored logically and physically is called mobile flash data erasure (MFDE).

Service erasure
A group called www.tabernus.com/ promote "Tabernus also provides erasure solutions for Mobile Phones, USB, SSD (solid state devices) & other types of Flash removable memory and may other data holding devices too!"

Software erasure
Of course, there is a comparison for mobile phone flash erasure available from  http://www.blancco.com/us/erase-smartphones/

The above examples are in addition to hardware encryption:

Device specific denied data access
Hardware Encryption: The iPhone 3GS and later, and all iPads, support built-in hardware encryption. All user data can be automatically encrypted in hardware at all times. This is used primarily for wiping the device rather than to stop attacks. Erasing the entire flash storage would be slow, so instead wiping works by destroying the encryption key, which instantly makes all user data inaccessible (Securosis).

And flash memory management:

Flash Memory Management Systems
Wear leveling ( http://en.wikipedia.org/wiki/Wear_leveling ) as well routines used in garbage collection solutions ( http://en.wikipedia.org/wiki/Garbage_collection_%28SSD%29#Garbage_collection and http://en.wikipedia.org/wiki/Garbage_collection_%28computer_science%29 ) can lead to potential loss due to overwriting existing deleted data.

From an examiner's point of view, MFDE is most likely to have a huge impact on deleted data recovery (DDR) from flash chips. The methodology and science behind Chip Off and JTAG is currently used for recovery of deleted data from a  range of mobile devices. Overwriting 0101010101 (zeros and ones) or null values over particular areas or the entire area of the flash memory may make Chip Off and JTAG redundant in certain types of investigations and cases in the future.

Saturday, May 26, 2012

Trace Log Generator

Trace Log Generator

I am looking into creating a new handset tool that generates a trace log of commands sent to the handset and responses received.

Quite a few times I have raised this and largely there is a stone-wall silence about why examiners 'cannot' or 'will not' provide the actual trace log associated with their examination, so that this can be checked. That is an unhealthy taboo to be active in forensics (and for evidence) and needs to be side-stepped.

The idea of the trace log that produces units of information and exported for consideration is similar to that generated by some imaging tools, which allow, as complete as possible, an examination.

This tool I believe should not compete with current tools in the same way that they perform, but the trace log should be inexpensive as the generated file will be a trace log, secured in such a manner that the original should not be altered by accident and when an examination takes place should avoid accidental contamination of the original. However, the managed principle extraction technique is based upon starting at binary and working upwards in order to allow the data to be viewed through independent products.

Additionally, I expect the trace log generator to perform tracing on a make-by-make basis, which means there should be a trace log generator module for each make. This will allow examiners to only buy what they need as opposed to have the reading capability of X-makes/models where it is an extremely low probability of examiners coming into contact with them.

There is a list of benefits but I suspect two key objectives that will benefit in the mobile forensics industry

1) Those whose job requirement limits them to push-button selection for reading an exhibit can produce the trace log first and then use another tool

2) Those who are experienced can use the trace log without needing to hector the less experienced to qualify what they have done during the acquistion examination period.

Additionally, I also envisage some form of (self)employment to arise out of this where programmers can create modules within the framework of the trace log generator and share in the revenue generation stream and at the same time see their contribution in a product generated by and for the forensic community.

I liked to know what you think?

Sunday, May 20, 2012

Evidence is one thing, Understanding is another

Evidence is one thing, Understanding is another

I like Nokia. They were in at the beginning and presented the World with options, and so many walked behind, in their footsteps.  The Nokia 110 and 112 still hasn't stopped the examiner from seeing potential evidence:


Seeing through the eyes of experienced examiners:


Mobile phones - understanding their contribution to evidence.

Friday, April 27, 2012

Data and Time Stamps

Data and Time Stamps

An important issue to bear in mind when dealing with any analogue or digital device that contain a 'clock', for the production of a 'date and time stamp', is whether the clock's inaccuracy might not disbar evidence when considering the operation of the device and content found stored on/in a device.

McKeown was convicted of drink-driving following a Lion intoximeter breathalyser test. It was found that the date and time stamp was erroneous when compared to the material time of the breath test. On Appeal their Lordships identified that the fact that the date and time stamp was erroneous would not of itself prevent the 'machine' to still carry out an effective breathalyser test (DPP v McKeown [1997] 1 WLR 295).

Such cases provide useful material to research whether:

1) The ruling, could it be applicable to mobile/smartphones to carry out an effective process or recording where the clock is inaccurate?

2) What impact that might have regarding the admissibility of the content in files stored/residing on mobile/smartphones (or indeed tablets etc) could still be seen as unaffected due to an erroneous clock?

3) Could a clock's inaccurate date and time stamp allow content to be altered or amended before being presented for admissibility?

There are many layers of investigation involved in each of the narratives above, and there are other questions that haven't been raised.  Some food for thought, yes, but also a reminder that extracting and harvesting data  from a digital device is only a fraction of the work involved when dealing with mobile telephone evidence.

Thursday, November 17, 2011

FAB LAB Manchester

FAB LAB Manchester

(For those international readers of my blog, that is 'Manchester' in the Great U of K)

People often refer back to the early days of the BBC Microcomputer,  Commodore 65, ZX Spectrum and Amstrad CPC. Nostalgic, well maybe, but with that style of programming it doesn't mean it has gone forever.

Have you seen Fab Lab in Manchester (http://www.fablabmanchester.org/) - what a great idea.
Creating-Interactive-Devices-With-The-Arduino-Beginner-Course

I heard about this place on BBC Radio Four. They have built their own basic computer board with operating system and just needs terminal devices added.  From there anyone can programme the system to do 'something'.

In essence teaching how to programme from the floor upwards.

Here are the excellent images of retro devices of the early 1980s and links to their background.














Other material on mobile programming:
fundamentals-principles-mobile-phone

Tuesday, November 08, 2011

Screenspy program can read texts and emails

The NewScientist online website ran an article on the 2nd November 2011 about new surveillance method relating to a touchscreen spy that reads text and email messages on your smart phone.

"......dubbed iSpy, that can identify text typed on a touchscreen from video footage of the screen or even its reflection in windows or sunglasses. Video from an ordinary mobile phone camera can be used to spy on a person from 3 metres away. And a snoop with a digital SLR camera that shoots HD video could read a screen up to 60 metres away."

"Their method exploits a feature meant to aid typing on small touchscreens: magnified keys. Letters on a virtual Android or iPhone keyboard pop up in larger bubbles when pressed. The program analyses video footage and identifies the letters based on the bubble locations on screen. Pop-ups for neighbouring letters like E and R can overlap, so the program assigns an accuracy probability to each detected letter. The program correctly identifies letters more than 90 per cent of the time.."

Screenspy program can read texts and emails.html