How Smart Phones are Helping Create a New Generation of "Smart Shoppers"

By sophiesummers on 12:17 PM

comments (0)

Filed Under:

Underscoring soaring consumer interest in use of internet and social media to aid in shopping, a new national survey by Leo J. Shapiro and Associates (LJS) found that two-thirds of owners use their smart phone to aid in their shopping, and over a third do so while actually inside traditional retail stores.  While at the point of sale for an item, one in ten smart phone owners report doing price checks before they buy.

These new findings point to the striking penetration of smart phone enabled shoppers or "smart-shopping" into the everyday lives of Americans.

Based on data from a hybrid phone/online study conducted in December 2011 and February  2012 with a national sample of 314 smart phone owners, the survey found that sixty-six percent (66%) use their smart phones to aid in shopping, and thirty-eight percent (38%) do so while actually in a traditional retail store.  Smart phone owners are about as likely to access shopping information in the store aisle (29%) as in the rest of the store (25%).

While actually near point of sale, shoppers are most likely to:

  • Look up facts and features (15%) 
  • Compare prices at different stores (11%) 
  • Read product reviews on retail sites (9%) 
  • Compare prices at retailer's websites (8%)

"Smart phone enabled shopping or 'smart-shopping' is rapidly becoming a mainstream activity for smart phone owners.  Given the rapid rise in smart phone ownership, traditional retailers and product brand managers face a new wave of challenges to serve increasingly informed and independent consumers," notes Owen Shapiro, Vice President of LJS. "The use of point of sale price checks breaks down one of the long-standing advantages held by retailers on 'blind priced' items – products that consumers buy infrequently or that are low involvement."

View the original article here

Microsoft SharePoint and LinkedIn data at risk from Framesniffing Attacks

By sophiesummers on 4:09 PM

comments (0)

Filed Under:

Context Information Security has highlighted a weakness in Internet Explorer, Chrome and Safari web browsers that enables remote attackers to steal sensitive information held on private Microsoft SharePoint sites, as well as mine data from other public websites such as LinkedIn. In these Framesniffing Attacks, a hidden HTML frame is used to load a target website inside the attacker’s malicious webpage to read information about the content and structure of the framed pages. The attack bypasses browser security restrictions that are meant to prevent webpages directly reading the contents of third-party sites loaded in frames.

“Using Framesniffing, it’s possible for a malicious webpage to run search queries for potentially sensitive terms on a SharePoint server and determine how many results are found for each query,” said Paul Stone, senior security consultant at Context. “For example, with a given company name it is possible to establish who their customers or partners are; and once this information has been found, the attacker can go on to perform increasingly complex searches and uncover valuable commercial information.”

Context researchers tested SharePoint 2007 and 2010 and found that by default, they do not send the X-Frame-Options header that instructs web browsers to disallow framing. This leaves these applications open to both Framesniffing and Clickjacking. As a result, any website that knows the URL of the SharePoint installation can load it in a frame and carry out these attacks, even if it is only accessible on an Intranet.

Following the discovery of this vulnerability, Context contacted Microsoft and was told: “We have concluded our investigation and determined that this is by-design in current versions of SharePoint. We are working to set the X-Frame options in the next version of SharePoint.”

Framesniffing can also be used to harvest confidential data from public websites, such as LinkedIn that don’t protect against framing. An attacker using a malicious website could build a profile of visiting users by piecing together small pieces of information leaked from different websites. For example, the product IDs of previously bought items from a shopping site could be combined with a person’s user ID from a social networking site.

Context’s blog published today at www.contextis.com/research/blog/framesniffing, includes a video that shows an attacker extracting sensitive information from a fictional corporate SharePoint installation. In the blog, Context also provides five simple steps to protect a website from this attack by adding the X-Frame-Options header. While Mozilla updated its Firefox web browser last year to prevent Framesniffing, the latest versions of Internet Explorer, Chrome and Safari are still vulnerable.

Fortunately, protecting a website from this attack is a simple matter of adding the X-Frame-Options header and in its blog, Context provides step-by-step instructions on how to do this. “Users of the Firefox browser are already protected against this attack,” said Stone. “We encourage other browser vendors to apply similar protection to their browsers but in the meantime, the onus is on individual websites to add framing protection via X-Frame-Options.”

View the original article here

Samsung Galaxy Tab 10.1 Now Available for U.S. Cellular Customers

By sophiesummers on 5:27 AM

comments (0)

Filed Under:

U.S. Cellular has announced that the Samsung Galaxy Tab 10.1 is available today, both in stores and online.



The Samsung Galaxy Tab 10.1 sports a 10.1-inch WXGA PLS TFT HD display with 1280 x 800 resolution. It has a 1GHz dual-core NVIDIA Tegra 2 processor and runs Android Honeycomb (3.2) OS. The tablet has a 3.2MP rear-facing camera with auto-focus and 720p video recording along with a 2MP front-facing one. Users will have 32GB of internal memory to store music, movies, photos, and other files on the device. It is also lightweight and slim, weighing in at a little over 1lbs and measuring 0.34 inches in thickness.

The Android-powered tablet will run on U.S. Cellular’s 4G LTE network, which boasts speeds up to 10 times faster than 3G. It is the first device introduced in U.S. Cellular’s 4G LTE device line-up.

Customers can purchase the device for $499.99 after a $100 mail-in rebate. But for those living in markets currently covered by the 4G LTE network, there is an additional $100 mail-in rebate, bringing the total price down to $399.99. Check out the U.S. Cellular website for detailed information on pricing.

View the original article here