One of the internet’s most popular BitTorrent client is now facing criticisms after several users reported last week that the torrent client silently installed a cryptocurrency mining software as part of its version 3.4.2 build 28913 build.


The mining software in question was from EpicScale, which uses some of a computer’s spare processing power to generate cryptocurrency such as Bitcoin in order to generate revenue for uTorrent as well as contribute to charity.

uTorrent in response issued a statement saying that they do have a partnership with EpicScale but asserts that the installation of the said software was completely optional. Furthermore, the company mentioned that in the last 24 hours, they have received less than a dozen inquiries about the alleged silent install out of several million offers.

At the moment, the uTorrent forum is currently suspended. The software can also be removed traditionally using Windows’ remove program option though a registry modification will remain in the Program files folder after uninstallation (users can completely erase this after uninstall is complete).

Connect with The Techie Lifestyle on your favorite social networking sites

Twitter Facebook Subscribe to RSS Feeds Google Plus Follow via Email

Remember the Heartbleed bug that affected website and servers that use the OpenSSL library. This week, Microsoft announced that they also found a vulnerability in the Windows platform that could allow hackers to take control of one’s computer by simply sending a packet of data to a Windows server.


According to Microsoft, the vulnerability called Schannel (short for Secure channel) has been found on early generations of its Windows platform dating back 2003. These include Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8, Windows Server 2012, Windows 8.1 and Windows Server 2012 R2.

The good thing is that Microsoft has already released a patch to fix the vulnerability. So the company is advising for everyone using the Windows platform to install the updates in order for the bug to be patched.

Connect with The Techie Lifestyle on your favorite social networking sites

Twitter Facebook Pinterest Subscribe to RSS Feeds Google Plus Follow via Email

Twitter-owned Tweetdeck experienced a massive technical issue today as the platform experienced an XSS (cross site scripting) security flaw that enabled hackers to access users’ account and remotely access or implant JavaScript code.


So far, the hackers were able to add annoying pop-ups on a user’s Twitter feed or automatically tweet or retweet from a hacked account. Twitter has then advised users who were affected by the issue to log in and log out of Tweetdeck and check if the issue persists.

Unfortunately, there are still reports from users that the problem hasn’t been fixed. Twitter has momentarily taken down Tweetdeck in order to “assess” the security breach. A few hours after, the social networking site has issued a security fix and re-activated Tweetdeck for all users and issued an apologetic tweet.

Connect with The Techie Lifestyle on your favorite social networking sites

Twitter Facebook Pinterest Subscribe to RSS Feeds Google Plus Follow via Email

In case you weren’t aware, there’s a new security issue that’s causing a lot of netizens to be scared (to the point of paranoia). The vulnerability is called the Heartbleed bug and affects a huge portion of the internet from social networks to cloud-based services. But how exactly does it affect consumers and websites in general? Here’s our short FYI for those who want to learn about the bug and how to keep yourself safe from it.

WHAT IS IT EXACTLY?

The Heartbleed bug is a vulnerability in OpenSSL, an open-source library used to encrypt and secure various web and email connections (these are mostly websites that have https in their addresses). For the past few years, a great number of websites have used SSL encryption in order to prevent hackers from stealing important information from websites.

With the Heartbleed bug, a hacked can pass an incorrect value to an OpenSSL extension and read up to 64KB off a website host’s memory. The process can be repeated in order to read more from the host, exposing various form of information from the website including names, passwords, content, etc.

WHO’S AFFECTED BY HEARTBLEED?

Over 60% of the web uses OpenSSL encryption from social networks to e-commerce websites. The good news (well, sort of) is that the bug was discovered by researchers at Google and a Finnish security firm, and not through a detected malicious attack.

However, the attack leaves no footprint, so there’s no sure way to tell whether the vulnerability has been used to maliciously gather information (although there are reports that the US NSA has utilized the bug to get information in its spying activities).

WHAT SHOULD WE DO TO KEEP OUR INFO SAFE?

As mentioned earlier, the bug affects a website’s host, and as such directly impacts those who manage web servers. For those who do manage websites, they must upgrade to OpenSSL version 1.0.1g, which is a new version of OpenSSL released on April 7 that fixes the vulnerability.

If you’re just an ordinary internet user, don’t be complacent. Do remember that a huge number of websites (most of which you use) utilize OpenSSL, so there might be a probability that the information you saved on that website – may it be your name, password or worse bank account information was compromised.

Connect with The Techie Lifestyle on your favorite social networking sites

Twitter Facebook Pinterest Subscribe to RSS Feeds Google Plus Follow via Email

Kaspersky Labs has just published a report about a highly sophisticated malware called The Mask that has been in circulation for almost 7 years.


Based on the code used on the malware, Kaspersky has reason to believe that the program was created by a nation-state possibly one that speaks Spanish (due to the presence of Spanish words in the coding). For instance, the name of the malware has Spanish origins (from the word Careto) and there are other pieces of data that has Spanish influence.

According to Kaspersky, the malware targets high-level offices including government institutions, embassies and large energy corporations. Victim count for the malware stands at 300+ in 30 different countries including the US, UK, France, Germany and China to name a few.

The Malware is cleverly coded and comes with its own set of tools including a rootkit and a bootkit. It is also capable or running on various operating systems including both 32- and 64-bit version of Windows, Mac, Linus and even mobile operating systems such as Android and iOS.

The Mask infects a user’s system by masquerading as an email which entices users to a malicious website disguised as a legitimate news site such as The Guardian and The Washington Post. It then can take control of the user’s communication channels from Skype conversations to sensitive encryption keys.

Connect with The Techie Lifestyle on your favorite social networking sites

Twitter Facebook Pinterest Subscribe to RSS Feeds Google Plus Follow via Email

Yahoo has announced today on its blog that it has detected a coordinated attach on its system that targeted Yahoo mail accounts.

According to the company’s investigations the list of usernames and passwords that were used to execute the attack was likely obtained from a third-party database and that Yahoo has no reason to believe that their system was directly accessed.


The breach was said to target specifically the names and email addresses stored on the affected users’ sent items folder. Yahoo has already notified the affected users and has advised them to change their passwords. Yahoo has also implemented a two-step verification process to re-secure users’ accounts.

As of the moment, Yahoo has yet to announce how many users are impacted saying the details of the breach is being used as part of an ongoing criminal investigation. 

Connect with The Techie Lifestyle on your favorite social networking sites

Twitter Facebook Pinterest Subscribe to RSS Feeds Google Plus Follow via Email

One of the worst things that can happen to a person online is to have his personal account information stolen by hackers and identity thieves. So it goes to show that social networking sites and major online service providers and product sellers are major targets for cyber-attacks as it is a gold mine for user information.


Today, Adobe becomes the latest victim in a series of cyber-attacks on major tech companies. On Adobe’s official blog, the company’s Chief Security Officer Brad Arkin announced that his team discovered a number of sophisticated attacks on the company’s network, which involved the illegal access of customer information as well as the source code for a number of Adobe products.

The company’s internal investigation revealed that the attackers accessed Adobe Customer IDs and encrypted passwords on the system, as well as removed certain information relating to 2.9 million Adobe customers, including customer names, encrypted credit or debit card numbers, expiration dates and other information related to customer orders.


According to Adobe, they are already working internally as well as with external partners and law enforcement to address the issue and have taken the necessary steps to mitigate the concern. Specifically, they are already resetting relevant customer passwords to help prevent unauthorized access to Adobe ID accounts, and notifying customers as well as the banks processing customer payments for Adobe. 

Customers whose credit or debit card information was involved will be offered the option of enrolling in a one-year complimentary credit monitoring membership where available.

Connect with The Techie Lifestyle on your favorite social networking sites

Twitter Facebook Pinterest Subscribe to RSS Feeds Google Plus Follow via Email


Facebook has been under the spotlight in terms of security issues these past few weeks due to the company’s alleged involvement in the NSA’s Project Prism. And although the company has explicitly denied such allegations, a recent security bug discovered on its website may have caused some doubts on whether or not the social giant has a backdoor access for the NSA or other US government agencies to sneak into.

Just this weekend, a security bug on Facebook has exposed account information (email and phone number) of some 6 million users to other people who were connected to them.

According to Facebook’s security team, the social network checks uploaded contact lists and address books of users in order to make friend recommendations. The problem caused by the bug was that some uploaded information (email addresses and phone numbers) were inadvertently saved to other people’s profile. So in case a person downloaded an archive of their account through the company’s Download Your Information tool, that person may get the additional information from people who are in his network.
Moreover, there was also information from non-Facebook users included in the download from tools that invite contacts to join Facebook. A Facebook representative has admitted that the bug has been on the website since last year, but it was only discovered last week. The company has also said that the bug has not been exploited maliciously and the company is reaching out to the affected users.

The social giant has also added that the exposed information wasn’t tied to any Facebook accounts in particular and wasn’t structured nor was it identifiable. Furthermore, each individual email address or telephone number was only included in a download once or twice so the information was only exposed to one person. And lastly, no other types of personal of financial information were included and only people on Facebook have access to the DYI tool.
For those affected by the bug, Facebook has already issued warning emails to users whose personal information have been compromised 
Connect with The Techie Lifestyle on your favorite social networking sites

Twitter Facebook Pinterest Subscribe to RSS Feeds Google Plus Follow via Email
2013-2015 © The Techie Lifestyle
Planer theme
Powered by Jasper Roberts Consulting - Widget