Showing posts sorted by date for query RSA. Sort by relevance Show all posts
Showing posts sorted by date for query RSA. Sort by relevance Show all posts

Friday, April 21, 2023

Purveyors of used data

This is not surprising at all:

You know that you're supposed to wipe your smartphone or laptop before you resell it or give it to your cousin. After all, there's a lot of valuable personal data on there that should stay in your control. Businesses and other institutions need to take the same approach, deleting their information from PCs, servers, and network equipment so it doesn't fall into the wrong hands. At the RSA security conference in San Francisco next week, though, researchers from the security firm ESET will present findings showing that more than half of secondhand enterprise routers they bought for testing had been left completely intact by their previous owners. And the devices were brimming with network information, credentials, and confidential data about the institutions they had belonged to.

The researchers bought 18 used routers in different models made by three mainstream vendors: Cisco, Fortinet, and Juniper Networks. Of those, nine were just as their owners had left them and fully accessible, while only five had been properly wiped. Two were encrypted, one was dead, and one was a mirror copy of another device.

Like I said, not particularly surprising.  If you get rid of a device, you really should at the minimum do a factory reset.

Monday, March 6, 2023

No, Chinese researchers didn't crack RSA

RSA is the encryption that underpins secure Internet messages.  Without it, there would basically be no commercial Internet.  So it was concerning to see a paper published saying that Chinese researchers have a quantum encryption technique that cracks RSA.  Except, not so fast:

The paper from 24 researchers in China might have remained a matter for those well-versed in advanced mathematics, cryptography, and quantum computing – a fairly small set of people – but for the fact that it got noticed by cryptographer Bruce Schneier.

"This is something to take seriously," he wrote in his blog on January 3rd, 2023. "It might not be correct, but it’s not obviously wrong."

Schneier did not take a position on the paper, but the following day The Financial Times took notice in an article titled, "Chinese researchers claim to find way to break encryption using quantum computers."

Evidently they haven't.

Late that day, on January 4, Scott Aaronson, chair of computer science at The University of Texas at Austin, and director of its Quantum Information Center, offered a rebuttal with a succinct three word review of the paper: "No. Just No."

Crypto mathematics is notoriously hard to do right, and deceptively easy to screw up.  It looks like this paper made an unwarranted assumption that a particular algorithm is much faster when using quantum cryptography.  It's actually no faster than plain jane cryptography.

So secure Internet messages are safe, at least for now.

Wednesday, January 15, 2020

A most unusual (but critical) Windows security update

There is a nasty security bug in Microsoft Windows 10 and Windows Server 2016.  You will want to update your operating system today.  Here's a handy guide on how to check if you already have the update, and if not how to get it manually.  This covers Windows 7, 8, and 10; if you have an older version then it's no longer supported and you don't really have any good options.  Skip to the end of this post for some thought on what to do.

But this is a really interesting security bug, not because of the nature of the bug itself but from how it was reported.  The bug is in the cryptographic subsystem, the library that does all the encryption routines.  This is pretty critical - not only does it handle the encryption of your browser traffic, but even more importantly (WAY more importantly) it verifies that you are talking to the actual web server that you want to and not some skeevy H4x0R site.  Most importantly of all, it verifies that the software you download (including, say, Windows security updates) are actually from Microsoft (and not from some skeevy H4x0R site).

Yeah, this is important.

But the interest here is that this was reported to Microsoft by the NSA.  Remember the Edward Snowden revelations?  NSA is ground zero for collecting attack techniques and code that the Fed.Gov can use against its enemies, foreign and domestic.  Here was a vulnerability present on literally every modern Windows computer in the universe, and they up and tell Microsoft to go build a patch for it.

Remember, these are the same guys who weakened the elliptic curve encryption routines so they could break all the web traffic, and these are the guys who paid RSA Data Security, Inc. tens of millions of dollars to slip weaknesses into the most popular encryption code sold at the time.  Now they're giving away the farm, so to speak.

Hmmmmm.  Here's the story and the interesting bit:
The NSA’s Neuberger said in a media call this morning that the agency did indeed report this vulnerability to Microsoft, and that this was the first time Microsoft will have credited NSA for reporting a security flaw. Neuberger said NSA researchers discovered the bug in their own research, and that Microsoft’s advisory later today will state that Microsoft has seen no active exploitation of it yet.
What's weird is that this is how you're supposed to do things - find a bug, report it to the developer, developer creates a patch, developer gives you credit for finding the bug.  But NSA actually did this, rather than keep the exploit secret.  Maybe some foreign government had discovered the vulnerability and somehow NSA found this out.  Who knows?    In any case, well done to NSA for doing it the Right Way.

But if you have Windows 10, go patch now.

If you have old Windows - say, XP you don't have support anymore.  It's no longer being maintained, so no more security patches.  You really have three choices here:

1. Stay on XP, and realize that some day you're going to get pwned.  It's sad to say, but it's not if you will get something take over your computer, it's when.

2. Upgrade to a newer version of Windows, which probably will mean buying a new computer.  Windows is famously resource hungry, and Windows 10 will be slow as molasses on a computer that came loaded with XP.  ASM826 and I put up a series of posts on backing up your data, so you can move everything over (you do back up your data, don't you?)

3. Load Linux on your existing computer.  Linux is a lot happier on old hardware then modern Windows is, and the backup techniques in the posts linked above will work just dandy on it.  Here's an old post recommending Linux Mint.

Monday, December 30, 2019

Thoughts on what's past, and what's ahead

A Republic, if you can keep it. 
- Benjamin Franklin, on the adoption of the Constitution
The swamp won't get drained:
Let me be clear on this: Once ruling hierarchies get beyond a certain point, they cannot be reformed. And I am sure that the modern West is beyond that point.
  • Do we really believe that central bankers will just lay down their monopolies?
  • Can we seriously expect a hundred trillion dollars of debt to be liquidated without any consequences?
  • Do we actually believe that politicians will walk away from their power and apologize for abusing us?
  • Do we really think that the corporations who own Congress will just give up the game that is enriching them?
  • Does anyone seriously believe that the NSA is going to say, “Gee, that Fourth Amendment really is kind of clear, and everything we do violates it… so, everyone here is fired and the last person out will please turn off the lights”?
It's a sobering post, in a let's party like it's 460 AD sort of way.  It reminded me of this old post:
I could keep myself up all night and into tomorrow by listing different groups of royalty and the ways they scam the system.
…except "scam the system" is a misnomer. I am not listing defects in a perfectable system. I am describing the system.
It is corrupt, corrupt, corrupt. From Ted Kennedy who killed a woman and yet is toasted as a "lion of liberalism", to George Bush who did his share of party drugs (and my share, and your share, and your share…) while young yet let other youngsters rot in jail for the exact same excesses instead of waving his royal wand of pardoning, to thousand of well-paid NSA employees who put the Stasi to shame in their ruthless destruction of our rights, to the Silicon Valley CEOs who buy vacation houses with the money they make forging and selling chains to Fort Meade, to every single bastard at RSA who had a hand in taking the thirty pieces of silver, to the three star generals who routinely screw subordinates and get away with it (even as sergeants are given dishonorable discharges for the same thing), to the MIT cops and Massachusetts prosecutor who drove Aaron Swartz to suicide, to every drug court judge who sends 22 year olds to jail for pot…while high on Quaalude and vodka because she's got some fucking personal tragedy and no one understands her pain, to every cop who's anally raped a citizen under color of law, to every other cop who's intentionally triggered a "drug" dog because the guy looked guilty, to every politician who goes on moral crusades while barebacking prostitutes and money laundering the payments, to every teacher who retired at age 60 on 80% salary, to every cop who has 50 state concealed carry even while the serfs are disarmed, to every politician, judge, or editorial-writer who has ever used the phrase "first amendment zone" non-ironically: this is how the system is designed to work.
The system is not fixable because it is not broken. It is working, 24 hours a day, 365 days a year, to give the insiders their royal prerogatives, and to shove the regulations, the laws, and the debt up the asses of everyone else.
I'm come to welcome the idea of the coming breakup, and Governor Blackface's Virginia reindeer games.  Donald Trump is a Romantic, in his attempt to drain the swamp.  It's tilting at windmills, a noble effort doomed to defeat.  The breakup that will follow won't reform the system, it will break the system into a million pieces.  Only then can the Res Publica shed all the layers of corruption that have attached themselves to the state.

Of course, new layers will emerge to take their place, but a fragmentation of power will make control of the center less attractive.  It's sad that likely millions will die during this breakup, as the current Powers That Be violently lurch towards the realization that they are Rome's last Emperor.
The generality of princes, if they were stripped of their purple, and cast naked into the world, would immediately sink to the lowest rank of society, without a hope of emerging from their obscurity.
- Edward Gibbon, The Decline And Fall Of The Roman Empire

Thursday, December 28, 2017

NSA caught with its fingers in the encryption cookie jar

Again.  There's a quite interesting blog post by a Johns Hopkins cryptographer where he writes about how he and a colleague found NSA's fingerprints on an encryption backdoor:
Yesterday, David Benjamin posted a pretty esoteric note on the IETF’s TLS mailing list. At a superficial level, the post describes some seizure-inducingly boring flaws in older Canon printers. To most people that was a complete snooze. To me and some of my colleagues, however, it was like that scene in X-Files where Mulder and Scully finally learn that aliens are real. 
Those fossilized printers confirmed a theory we’d developed in 2014, but had been unable to prove: namely, the existence of a specific feature in RSA’s BSAFE TLS library called “Extended Random” — one that we believe to be evidence of a concerted effort by the NSA to backdoor U.S. cryptographic technology.
I wrote about the back story on RSA four years ago.  Re-reading that post, I think that I let RSA off the hook too easily - there is credible reason to think that RSA did take $10M from NSA to weaken their widely used crypto library.  The blog post above goes into why they think they have evidence of this, in software in the wild.

But the overall feeling of betrayal in my post is still fresh.  And reading between the lines in the the linked post above, it seems that I'm by no means the only one.  Security professionals don't talk about "hackers" - that's for the press.  Pros refer to the "adversary".  I suspect that a lot of the technical gurus on the IETF (the Internet standards committee) consider the NSA to be the adversary now.  Quite frankly, NSA earned ever bit of that.

Hat tip: Bruce Schneier.

Wednesday, March 2, 2016

What causes NSA to lose sleep at night?

It's not whether Apple will unlock an iPhone:
Admiral Michael Rogers, head of the NSA and the US Cyber Command, has told delegates during his keynote address at RSA 2016 the three things that keep him awake at night. 
His first fear is an online attack against US critical infrastructure, which he said was a matter of when it will happen, not if. Citing the recent Ukrainian power grid hack as an example, Rogers said that the target was an obvious one and security systems in the US national critical infrastructure were not strong enough.
While #3 on his list is pretty obvious, his second insomnia-inducing worry is pretty darn interesting.  RTWT.

But he closes with a plea that I think will fall on deaf ears:
The NSA can't handle all of this itself, he said, and pleaded with the assembled security experts to bring their skills to the government in partnerships.
I've been quite critical about how NSA's behavior over the last 15 years has alienated a large portion of the security industry practitioners.  I haven't seen anything over the last year or two to cause me to change that - and the whole FBiPhone incident is causing even more collateral damage.

NSA has a lot of smart people, and the ones who are trying to fight the Bad Guys are fighting the Good Fight.  But they have a huge branding problem to overcome.  Adm. Rogers isn't addressing that.

Friday, January 10, 2014

More fallout from the NSA spying scandal

More security gurus are refusing to work with companies that collaborate with the NSA:
With reports last month that RSA Security worked with the NSA under a $10 million contract to weaken internet security, a number of speakers have withdrawn from the company's annual security conference due to be held next month.

RSA Security, owned by data storage giant EMC, has disputed claims that it intentionally introduced the flawed encryption algorithm, but otherwise has declined to discuss the media report.

The revelation supplemented documents leaked by former NSA contractor Edward Snowden showing that the NSA had tried to weaken internet encryption.

The withdrawals from the highly regarded conference represent early blowback by experts who have complained that the government's surveillance efforts have, in some cases, weakened computer security, even for innocent users.
Trust is fragile.  Easily lost, it's hard to get back.

Thursday, December 26, 2013

I hope this isn't correct

But I fear that it might be:
I could keep myself up all night and into tomorrow by listing different groups of royalty and the ways they scam the system.

…except "scam the system" is a misnomer. I am not listing defects in a perfectable system. I am describing the system.

It is corrupt, corrupt, corrupt. From Ted Kennedy who killed a woman and yet is toasted as a "lion of liberalism", to George Bush who did his share of party drugs (and my share, and your share, and your share…) while young yet let other youngsters rot in jail for the exact same excesses instead of waving his royal wand of pardoning, to thousand of well-paid NSA employees who put the Stasi to shame in their ruthless destruction of our rights, to the Silicon Valley CEOs who buy vacation houses with the money they make forging and selling chains to Fort Meade, to every single bastard at RSA who had a hand in taking the thirty pieces of silver, to the three star generals who routinely screw subordinates and get away with it (even as sergeants are given dishonorable discharges for the same thing), to the MIT cops and Massachusetts prosecutor who drove Aaron Swartz to suicide, to every drug court judge who sends 22 year olds to jail for pot…while high on Quaalude and vodka because she's got some fucking personal tragedy and no one understands her pain, to every cop who's anally raped a citizen under color of law, to every other cop who's intentionally triggered a "drug" dog because the guy looked guilty, to every politician who goes on moral crusades while barebacking prostitutes and money laundering the payments, to every teacher who retired at age 60 on 80% salary, to every cop who has 50 state concealed carry even while the serfs are disarmed, to every politician, judge, or editorial-writer who has ever used the phrase "first amendment zone" non-ironically: this is how the system is designed to work.

The system is not fixable because it is not broken. It is working, 24 hours a day, 365 days a year, to give the insiders their royal prerogatives, and to shove the regulations, the laws, and the debt up the asses of everyone else.
Happy holidays, everyone.

Monday, December 23, 2013

Did RSA take $10M from the NSA to weaken crypto?

Over the weekend a story broke saying that venerable security company RSA took $10M from the NSA to weaken the crypto in their widely used software toolkit, bsafe.  This is probably the most widely used commercial encryption library, and so weakening it would be of enormous use to the NSA's monitoring capabilities.  It would also effectively destroy RSA's reputation.

RSA has issued a response in which they categorically deny being the NSA's stooge:
Recent press coverage has asserted that RSA entered into a “secret contract” with the NSA to incorporate a known flawed random number generator into its BSAFE encryption libraries.  We categorically deny this allegation.

We have worked with the NSA, both as a vendor and an active member of the security community. We have never kept this relationship a secret and in fact have openly publicized it. Our explicit goal has always been to strengthen commercial and government security.
Key points about our use of Dual EC DRBG in BSAFE are as follows:
  • We made the decision to use Dual EC DRBG as the default in BSAFE toolkits in 2004, in the context of an industry-wide effort to develop newer, stronger methods of encryption. At that time, the NSA had a trusted role in the community-wide effort to strengthen, not weaken, encryption.
  • This algorithm is only one of multiple choices available within BSAFE toolkits, and users have always been free to choose whichever one best suits their needs.
  • We continued using the algorithm as an option within BSAFE toolkits as it gained acceptance as a NIST standard and because of its value in FIPS compliance. When concern surfaced around the algorithm in 2007, we continued to rely upon NIST as the arbiter of that discussion.
  • When NIST issued new guidance recommending no further use of this algorithm in September 2013, we adhered to that guidance, communicated that recommendation to customers and discussed the change openly in the media.
RSA, as a security company, never divulges details of customer engagements, but we also categorically state that we have never entered into any contract or engaged in any project with the intention of weakening RSA’s products, or introducing potential ‘backdoors’ into our products for anyone’s use.
Highlighting by me.  The two highlighted items really get to the heart of why the security industry is so angry about what the NSA has been doing.  They spent years establishing a relationship of trust with the industry and researchers.  Then they exploited that trust for personal gain at the expense of everyone else.

While I don't at all want to minimize the horrific crime of child abuse, that will give you a bit of the flavor of how the security industry looks at Ft. Meade now.  It was a rape, a rape of those who had trusted them as teacher and protector.

This is going to cause enormous problems for NSA.  I simply don't see how anyone will ever want to cooperate with them outside a public forum.  Nobody who values their reputation will be willing to be accused of slipping an NSA mickey into a crypto library.

And nobody on a standards body will ever again listen to NSA recommendations for changes to algorithms.  As a matter of fact, those recommendations will make the hair on the back of people's necks stand up, and lots of people will start to reverse engineer the NSA's math to see what games they're playing.

Bottom line, it's now no longer possible for NSA to help secure the nation, at least from an encryption point of view.  May as well shut down the National Computer Security Center.

This is a crying shame, brought about by unbelievably incompetent management.  I remember when the NSA were the Good Guys, back before they raped the community.

Thursday, August 1, 2013

Overheard at Black Hat: "Who here has seen the film 'Sneakers'?"

This question was asked in a session about security problems in crypto-mathematics.  Half the hands went up.   I wonder if the speaker reads Borepatch?

There may be a problem in the encryption that underlies Secure Sockets Layer (SSL) - this is the stuff that protects you when you browser to some https:// location.  While the encryption isn't broken, there's a lot of mathematical analysis going on in this field that is showing partial results.  Already this year there have been three published paper on the Discrete Logarithm Problem (don't worry about the details).  There hadn't been any progress for 30 years, and now this is the new mathematical hotness.  It it becomes possible to solve this problem then we have exactly the situation shown in Sneakers - everything on the Internet will be able to be decrypted.  Worse, the techniques likely will be easy to implement, and so everything will be vulnerable, all in the space of a week or two.

They call this the Cryptopocalypse.  Slides (and maybe video) of the session should be posted there in a day or two, and if you're interested you should check it out.  It was the best presentation on encryption that I've ever seen.

Even more interesting is that the recommendations - to use Elliptic Curve encryption (don't worry about the details).  The Russian crypto system GOST was based on this.  It isn't based on the RSA standard we use here, that depends on Discrete Logarithms.  In the film, the Soviet Attache said that their encryption was different, and that the decryption box wouldn't work against them.

All in all, the world is a very strange place where so much prediction seems to have come from Hollywood.

Sunday, July 28, 2013

Movie recommendation: Sneakers

Most films about technology age poorly.  Tron is fun to watch, but the fun is the retro graphics, not because of any lasting amazement at the tech involved.  Films dealing with computer hacking age particularly poorly, with some (*cough* Hackers *cough*) past their sell-by date at their premiere.

Sneakers is an exception to this rule, a film about hacking that if anything is improving with age.  We watched it last night, and its relevance is more striking today than when it was introduced 20 years ago.

Sure, it has some of the old retro fun, like acoustic-coupled modems.  But the fundamental premise (and thus the film's dramatic tension) is still fresh.

The protagonists are a motley group of computer hackers, ne'er-do-well pranskters who find themselves unexpectedly in possession of a mysterious electronic box.  Because they're hackers, they figure out what it does - it's a universal decryptor, able to break the encryption used to protect any site - government, banks, electric power grid*.

The rest of the film is about how the box gets taken by a shadowy  organization that is clearly Up To No Good, and how the group uses their skillz - believably - to get it back.

Back In The Day, those of us at Three Letter Intelligence Agency loved this film.  We even had a theory about what it did; the clue was a remark from the Russian Attache character that they use a different coding scheme, and the box wouldn't work against them - it was only useful decrypting American's data.  We thought that it would factor large prime numbers, allowing you to break the RSA encryption that is at the heart of X.509**.

The most striking thing was how NSA wanted this so bad that they sent a field team to recover it***.  The revelations about massive NSA data collection programs targeting American citizens has made this fresh again.  In fact, that's why we watched it.  If anything, it's more relevant now than it was in 1991.

If you haven't seen this, you're in for a treat.  If you have seen it, you too will likely be struck at the film's staying power.  Highly recommended.

* If only our grid were protected as well as shown in this film.

** Sorry, just a short diversion into crypto-geeking.  However, the assumption is that it's not feasible to factor large primes; if someone figures out how to do this then you would indeed be able to decrypt pretty much everything, or masquerade as pretty much anyone.  Just like in the film.

*** We all laughed and laughed about this.  Now I wonder.

Friday, May 10, 2013

ITAR Kabuki

I was one of the guys who had this T Shirt:


Back In The Day, encryption was considered a munition, controlled under the International Trafficking in Arms Regulations (ITAR).  Actually it still is, but the interpretation is a little less stupid than it was: back then computer source code that could be compiled into a program that would encrypt data was considered a munition and export (including posting on the Internet) was forbidden by the Fed.Gov.

Then Phil Zimmerman wrote a program called Pretty Good Privacy (PGP) and all hell broke loose.

Zimmerman was criminally investigated for posting his source code.  The reaction was sort of a crypto-nerd version of the Streisand Effect, with people coming out of the woodwork to mirror the source code all over the world.  The T-shirt is a different flavor of mockery: it's 3 lines of PERL code that implements the RSA encryption algorithm.  It was in theory illegal to wear this shirt when you left the country.

After three years, the Fed.Gov gave up.  No charges were filed, and people freely downloaded PGP from wherever they wanted.  If you have a commercial product you still need an export license if it contains crypto, but there have been no more hassles about people posting technical documents since 1996.

Until now.  Tam goes into some depth about what ITAR means for firearms components, but my take is that none of this really matters.  It's Security Kabuki by the Fed.Gov.  They know that the Defense Distributed design is being hosted all over the world (I hear that it's up on Kim Dotcom as well as Bittorrent).  The folks at Defense Distributed have made their point and gotten their press, so it doesn't hurt them to take down their web site:
Wilson says he will comply with the order. But he points out that given the nature of the Internet, that doesn't mean it will be taken down off of all servers. In fact, it almost certainly won't mean that.
Despite taking down his files, Wilson doesn’t see the government’s attempts to censor the Liberator’s blueprints as a defeat. On the contrary, Defense Distributed’s radical libertarian and anarchist founder says he’s been seeking to highlight exactly this issue, that a 3D-printable gun can’t be stopped from spreading around the global Internet no matter what legal measures governments take. “This is the conversation I want,” Wilson says. “Is this a workable regulatory regime? Can there be defense trade control in the era of the Internet and 3D printing?”

But everyone knows that the toothpaste is out of the tube.  We know it.  The Fed.Gov knows it.  And we know that they know.  The Internet has already detected the censorship, interpreted it as damage, and in a millisecond was able to route around it. 


Or guns, it seems.  Mockery will infuriate the Empty Suits, inflaming them to still more idiocy.  Mock away.  It's Happy Culture Warrior time.

Monday, February 25, 2013

Hacking: your pad or mine?

Remember, only use your Powers for good:
The folks at security tools company Pwnie Express have built a tablet that can bash the heck out of corporate networks. Called the Pwn Pad, it’s a full-fledged hacking toolkit built atop Google’s Android operating system.

Pwnie Express will be selling the cool-looking hack machines — based on Google’s Nexus 7 tablets — for $795. They’ll be introduced at the RSA security conference in San Francisco next week, but Pwnie Express is also releasing the Pwn Pad source code, meaning that hackers can download the software and get it up and running on other types of Android phones and tablets.

Some important hacking tools have already been ported to Android, but Pwnie Express says that they’ve added some new ones. Most importantly, this is the first time that they’ve been able to get popular wireless hacking tools like Aircrack-ng and Kismet to work on an Android device.

“Every pen tester we know has a phone and a tablet and a laptop, but none of them has been able to do pen-testing from the tablet,” says Dave Porcello, Pwnie Express’s CEO.
Looks pretty cool, actually:


At that price point, there's really no excuse for companies not to be using it to test the security of their own systems.  It might be really interesting if you scripted things, so that the security guard could just carry one around on his patrols.  If the pad found any internal problems, it could email the security team.

Thursday, February 21, 2013

Security Smorgasbord, vol 5 no 1

Microsoft asks Is everything we know about passwords wrong? Interesting:
Federal Reserve Regulation E guarantees that US con-
sumers are made whole when their bank passwords are
stolen. The implications lead us to several interest-
ing conclusions. First, emptying accounts is extremely
hard: transferring money in a way that is irreversible
can generally only be done in a way that cannot later
be repudiated. Since password-enabled transfers can
always be repudiated this explains the importance of
mules, who accept bad transfers and initiate good ones.
This suggests that it is the mule accounts rather than
those of victims that are pillaged. We argue that pass-
words are not the bottle-neck, and are but one, and by
no means the most important, ingredient in the cyber-
crime value chain. We show that, in spite of appear-
ances, password-stealing is a bad business proposition.
When is it time to patch Adobe Reader and Java?  Any day that ends in "-day":
Adobe and Oracle each released updates to fix critical security holes in their software. Adobe’s patch plugs two zero-day holes that hackers have been using to break into computers via Adobe Reader and Acrobat. Separately, Oracle issued updates to correct at least five security issues with Java.

The Java update comes amid revelations by Apple, Facebook and Twitter that employees at these organizations were hacked using exploits that attacked Java vulnerabilities on Mac and Windows machines.
Related:
Removing Java from your browser

Apple finally patches Java for OS X

Adobe Reader: security is now 3% less sucky
Security infrastructure vendors under attack

We've seen attacks against security technology vendors over the last few years: RSA, McAfee, a number of certificate granting firms.  Add a new one to the list:
Bit9, a company that provides software and network security services to the U.S. government and at least 30 Fortune 100 firms, has suffered an electronic compromise that cuts to the core of its business: helping clients distinguish known “safe” files from computer viruses and other malicious software.

Waltham, Massachusetts-based Bit9 is a leading provider of “application whitelisting” services, a security technology that turns the traditional approach to fighting malware on its head. Antivirus software, for example, seeks to identify and quarantine files that are known bad or strongly suspected of being malicious. In contrast, Bit9 specializes in helping companies develop custom lists of software that they want to allow employees to run, and to treat all other applications as potentially unknown and dangerous.
It's an interesting technology, because antivirus techniques are always closing the barn door after the horse gets out.  Bit9's whitelisting technology reverses this: anything new is unusual and suspicious.  They have some clever ways to make sure that new updates from iTunes are added to the "good" list, so they've done decently well with forward thinking customers and have (so far) avoided the big problems with implementation and day to day operations that a lot of other technologies have encountered (*cough* IDS *cough*).

But their white list is only as good as the security of their list.  Bad Guys seem to have penetrated their network and added malware to the "good" list.  Several Bit9 customers seem to have been compromised this way.

I expect the trend of attacking security infrastructure to continue.  As Willie Sutton is said to have replied when asked why he robbed banks, "that's where the money is."  Penetrating technology infrastructure lets you get into the targets you really want much more easily.

Wednesday, October 10, 2012

Online banking: hacking storm clouds gather

I have been warning people away from online banking basically the whole time I've been blogging.  The reasons were pretty diffuse, based on experience built over a number of years.  Now I'm suggesting that people do not bank online, and actually tell their bank that electronic transactions should be blocked.  The reason is that it looks like there's a hacking storm a'coming:
Last week, security firm RSA detailed a new cybecriminal project aimed at recruiting 100 botmasters to help launch a series of lucrative online heists targeting 30 U.S. banks. RSA’s advisory focused primarily on helping financial institutions prepare for an onslaught of more sophisticated e-banking attacks, and has already received plenty of media attention. I’m weighing in on the topic because their analysis seemed to merely scratch the surface of a larger enterprise that speaks volumes about why online attacks are becoming bolder and more brash toward Western targets.

...
The campaign, purportedly to be rolled out between now and the Spring of 2013, proposes organizing hacker cells throughout the cybercriminal community to collaborate in exploiting these authentication weaknesses before U.S. banks erect more stringent controls. “The goal – together, en-masse and simultaneously process large amount of the given material before anti-fraud measures are increased,” vorVzakon wrote. A professionally translated version of his entire post is available here.
Krebs has a detailed and insightful analysis, and if you bank online you really need to RTWT.  What is most interesting is the quote from the hacker who is organizing this effort, vorVzakon:
Many saw videos on neighboring forums, where I openly demonstrate my cars, house and face.
What do I want to say?
That if you accurately target customers in the USA while being in Russia then you can fear nothing while living in your country. Except the one thing – you should never expose yourself during заливы ["залив" means "in the process of stealing victim's money from a bank account"].
I am the obvious example of the fact that you can fear nothing in our country, you can live openly and calm.”
The long arm of the law may or may not reach onto Russian soil, particularly with the Russian government increasingly unimpressed with Hillary Clinton's "Overload" button.  Given the recent court decision ruling that banks do not have to cover losses due to hacked accounts, my advice is that you should not bank online until this settles down.  Call your bank have have them set up a block on electronic transactions, and you should be in decent shape.

Monday, February 27, 2012

John Nash, the NSA, mental illness, and Hollywood Beefcake

John Nash is the brilliant mathematician and Nobel Laureate who was depicted in the film A Beautiful Mind.



The film, of course, is a fictionalized account of his life, but he was undoubtedly one of the greatest mathematicians of the 20th Century.  He made critical contributions to the field of Game Theory (modeling how people rationally make decisions), which explains a lot about why his Nobel was in Economics, not Mathematics.  He was also schizophrenic, and thinks that he got better without the aid of modern pharmaceuticals.

Well, it turns out that his work anticipated modern cryptography by decades, as shown in his recently declassified 1955 letter to the National Security Agency:
The National Security Agency (NSA) has recently declassified an amazing letter that John Nash sent to it in 1955.  It seems that around the year 1950 Nash tried to interest some US security organs (the NSA itself was only formally formed only in 1952) in an encryption machine of his design, but they did not seem to be interested.  It is not clear whether some of his material was lost, whether they ignored him as a theoretical professor, or — who knows — used some of his stuff but did not tell him.
Fittingly, the declassified letter was "discovered" (well, popularized on the Internet) by Ron Rivest, the "R" in the RSA encryption algorithm that your computer uses every day.

Even more interesting, he is active today in economics, working on ideas for sounder currency in this day of Quantitative Easing and hidden inflation.  Ron Paul should get him on the team.

But enough crypto-geekery.  He was played in the film by Russell Crowe.  As a service to my Lady Readers, here's some of Russell Crowe's beautiful, err, mind:

Tuesday, April 19, 2011

Why the Fed.Gov's Internet ID is a persistently bad idea

The Fed.Gov's Internet ID plan is back:

As we reported, on Friday the United States Department of Commerce and a host of privacy and security experts met at Stanford University to discuss the mapping out of an "Identity Ecosystem" for cyberspace.

That would be a place, Commerce Secretary Gary Locke explained at the event, "where individuals and organizations can complete online transactions with greater confidence... putting greater trust in the online identities of each other... and greater trust in the infrastructure that the transactions run across."

We know what you're thinking. Locke knows it too.

"Let's be clear," he quickly added. "We are not talking about a national ID card."
And the original Income Tax was going to be capped at 3% ...

But that's not why this is a bad idea.  It's not even the very weak tea used to justify the plan (click through to read the extremely unpersuasive example scenarios that this "solves").

The problem is that a central, authoritative database of user identities is a huge target for the Bad Guys.

Imagine that the Fed.Gov establishes this program.  Imagine that it actually is useful - as useful as they plan.  You can get all sorts of validated access to sensitive data, based on their database vouching for you.

What Bad Guy wouldn't want to get access to that?

Furthermore, the security of the database system itself will be pathetic, its guardians incompetent, and so the data in it will be subject not just to disclosure, but to tampering.  How do we know this?

Because the Fed.Gov can't keep malware out of even its classified networks.  You know, the ones protected by large staffs of well-trained security gurus using all the latest security technology (no, I'm not being sarcastic here).  And it's not just them.  RSA, one of the world's premier security vendors, was hacked recently.  The Bad Guys were after information on how to break RSA's two-factor authentication tokens (basically, a password replacement device).  These devices are used by every security-conscious organization on the planet.

Even with all their skill and technology, even with the motivation to keep this from happening, RSA got hacked:
The number of enterprises hit by APTs grows by the month; and the range of APT [Advanced Persistent Threats, industry jargon for custom trojan horse malware - Borepatch] targets includes just about every industry. Unofficial tallies number dozens of mega corporations attacked; examples are in the press regularly, and some examples are here, and here.



These companies deploy any imaginable combination of state-of-the-art perimeter and end-point security controls, and use all imaginable combinations of security operations and security controls. Yet still the determined attackers find their way in. What does that tell you?

The first thing actors like those behind the APT do is seek publicly available information about specific employees – social media sites are always a favorite.  With that in hand they then send that user a Spear Phishing email. Often the email uses target-relevant content; for instance, if you’re in the finance department, it may talk about some advice on regulatory controls.

The attacker in this case sent two different phishing emails over a two-day period. The two emails were sent to two small groups of employees; you wouldn’t consider these users particularly high profile or high value targets. The email subject line read “2011 Recruitment Plan.”

The email was crafted well enough to trick one of the employees to retrieve it from their Junk mail folder, and open the attached excel file. It was a spreadsheet titled “2011 Recruitment plan.xls.

The spreadsheet contained a zero-day exploit that installs a backdoor through an Adobe Flash vulnerability (CVE-2011-0609). As a side note, by now Adobe has released a patch for the zero-day, so it can no longer be used to inject malware onto patched machines.
And the Fed.Gov thinks they can prevent this from happening to their uber-identity database?  Good luck with that.

So the problem with this proposal is not that it's an idiotic crock full of FAIL, the problem is that it might just succeed well enough to become the Mother Lode target.  That's why it's a bad idea.  So why is it a persistently bad idea?

Law Enforcement has a strong, almost visceral dislike of Internet anonymity.   This is an institutional dislike, meaning that there's very little difference between the two political parties.  Other countries have an even deeper dislike for Internet anonymity, and would like to eliminate it as a means to better control their populations.

At the bottom, governments are hierarchical structures comfortable with top-down control.  The idea of a self-organizing population is a divide-by-zero error.  And so we see repeated attempts by the government to impose some sort of top-down control onto the Internet.  It's a bad idea, because control always means restricting access to part of the information on the 'Net, which means that the population has less access to information, which means that the 'Net is less useful.  The governments always tell themselves that the reduced productivity that comes from their plans will be small - tiny, really, almost undetectable.

Oooooooh kaaaaaaay.

I'd be more impressed with their ability to forecast the future if they weren't steering the FAIL Boat full speed towards the shoals that RSA just pitched up upon.

So the proposal is a bad idea, it's always been a bad idea, it will remain a bad idea, and it - sadly - will keep coming back.

Tuesday, April 12, 2011

How hard is security?

It's so hard that security companies get hacked:
The website of web application security provider Barracuda Networks has sustained an attack that appears to have exposed sensitive data concerning the company's partners and employee login credentials, according to an anonymous post.
It looks like a SQL Injection attack, which works like this:


The press has the expected sort of gloating.  I'm much more sympathetic.  Barracuda had the motivation to try to keep this from happening.  They had the technical expertise to try to keep this from happening.  They had the technology to try to keep this from happening.

You could say the same about RSA, which has some of the best security technology around.  They got hacked, too.

This is hard.  What makes it really hard is that there's big money in Black Hat hacking, so big that the Bad Guys are almost certainly better funded than the Good Guys.

Interesting times.

Sunday, December 7, 2008

Ubuntu Linux - ready for the home?

I've been running Ubuntu Linux for a couple weeks. Insty today pointed to an article about Linux for corporate use, so this seemed to be the time to write about whether it's ready for the home.

The answer is yes and no.

Like The Hitchhiker's Guide to the Galaxy (42?), the fact that the answer is opaque means that we didn't ask the right question. So the question needs to be: what is it you do at home? For some of this, Linux is the shizzle Flippity Floppity Floop. For other things, it's still not there. This post will spend some time on the different things you might do, and whether Linux is ready for this.

Email, Web Browsing, Internet Chat, and Office Apps.

Ready. Boy, howdy, is it ready. For most of this, in fact, you'll be better off with Linux. Windows comes with an email client called "Outlook Express" which is stuffed to overflowing with security problems. The same goes for Internet Explorer.

Ubuntu comes with the Firefox web browser, Evolution email client, a chat client, and a softphone. Not only should it be pretty painless moving to these, but you'll almost certainly be better off from a security perspective.

Gun Nuts Radio works great out of Ubuntu. I haven't tried using my Softphone to call in, but I can listen and chat just fine.

As to word processing, spreadsheets (hello, budget!), or PhotoShopping H-S Precision fake ads with The Gimp, Linux is the clear winner. It's all installed by default, and it's all free.

iPod and iPhone support.

Apple's iPod is mostly supported, although you'll want to go get the Banshee media player. You'll also have to do a small level of installation and configuration for MP3 support. This is not at all difficult; knowing that you have to do this is the trick.

You'll give up some things, though. While it's really easy to set up playlists in Banshee, those playlists don't get sync'ed to the iPod. I'm pretty sure that there's a way to do this, but it's not obvious how.

And forget the iTunes store, which simply doesn't work with Banshee. Now I don't buy music from iTunes, so this isn't a problem for me. However if you like to do this, then this may be a deal breaker for you.

The kids have quite a lot of music from iTunes. They dislike Vista quite a bit - the networking is either too smart or not smart enough, so that while it figures out that there's an intermittent problem with the under powered Fiber Optic router from Verizon, it's not smart enough to figure out that the router's back on-line. So while everything else figures out the network is back, Vista needs a kick in the seat of the pants.

But without iTunes, I can't move them off Vista. Note to Apple marketing: you're not building up any good will here Chez Borepatch, you know. If you don't want to do the port yourself, open up the specs - I'm sure that the Banshee team would jump at the chance, and you'd get more music revenue.

Oh, and iPhone? Fuggedaboutit. Nothing on Linux supports the iPhone (or iPod Touch), since the interface is different. I expect that this will change pretty soon, since this is a major development priority in LinuxLand. Personally, even though I use an iPhone, this isn't a problem; I just don't really feel the need to sync my Jesus Phone.

But note to Apple: most of the apps in the App Store tell me that I have to upgrade my iPhone software to run them. I have to use iTunes to upgrade the phone. iTunes doesn't run on Linux. You'd get more App Store revenue if you gave me a way to do this.
Bottom line: If you absolutely have to have iPod Touch/iTunes/iPhone, then this is a show stopper.

Apple Marketing = Teh Stupid.
Games.

It's been a while since I've been much of a gamer, but this is not Linux's strong suit. If you want to play World of Warcraft or PC Games, you probably don't want Linux.

Now you can set up VMWare to run Windows and play games on a virtual computer, but I haven't tried. I'm pretty sure it works, and may even work pretty well, but this isn't going to be straight forward.
Bottom line: If you're a hard core PC Gamer, the Linux isn't for you.
Other stuff.

I have a decent desktop system here Chez Borepatch: Dual Core 2.6 MHz CPU. Ubuntu has an odd way of using it. The CPU cooling fan keeps toggling on and off, which is distracting, and suggests to me that my kernel isn't optimized well for dual core.

Firefox also does not handle memory as well on Linux as it does on Windows XP. I have 2 GB of RAM that I'm going to pop in the box after I post this, so that may address some of this. However, with only three tabs in Firefox, it's burning 400 MB and one entire CPU core.

Note that this is probably a Firefox thing. I can run lots of other apps at the same time (The Gimp, the Epiphany browser, file windows), so there's plenty of power left. It's strange to see one core more or less pegged at 100%, though. It seems related to Firefox browsing sites with lots of rich media content, like Edge's place.

So where does this leave us?

Well, I'm mostly happy - certainly happy enough that I'm not even going back to SuSE 10 Linux, which was my previous favorite. I'm absolutely not loading Windows (and yes, I have a license for this system, thanks for asking).

I'm pretty confident that I'll smooth off the rough edges on my iPod experience RSA. It may be possible to create playlists now, and I just need to much with it a bit. If not, Banshee seems to be maturing at warp speed, so it will likely be here soon.

I really like the installation and update mechanism in Ubuntu (the old Debian Apt method). You want Banshee? Point your system towards theirs, and your installer will say "Hey, d00d, you want to get Banshee?" It takes care of everything after that. Security updates are as easy. Yes, your mom could handle this.

Oh, and security? Only a million times better than Windows. Notably better than Mac, too, so you Mac fanboys can stop smirking.

Will I update the kids? Not yet. I'd either need to set up VMWare, or find out if iTunes runs under WINE (a Windows emulator). Until then they're stuck with Vista and ipconfig /renew.