Pages

Recent Posts

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, July 14, 2011

Pentagon Planning New Cybersecurity Strategy

cyber-security

By: Kareem 

The pentagon is reportedly set to release a new strategy for protecting it’s computer systems today. The new strategy will apparently make more use of sensors, software and recent data collecting done by U.S intelligence.

The pentagon is saying they don’t want to come off as too aggressive in their new strategy saying that they’re not looking to militarize cyberspace but rather to deny other militaries access and dissuade them from attempting an attack.

In drafts of a speech set to be given today by Deputy Defense Secretary William J. Lynn III,

“Although it is certainly possible that a destructive or disruptive cyber attack could have an impact analogous to physical hostilities and therefore constitute an act of war, the vast majority of malicious cyber activity today would not cross this threshold, or justify a military response,”

It’s always wise to be wary of the military moving into any domain, be it physical or ‘cyber’ so take their words with a grain of salt and make sure you read between the lines. More on this to come.

Related Stuffs:

Source: The Washington Post

Wednesday, June 1, 2011

Supposed Chinese Spear Phishing Attack Targets US Government

gmail-hacked

By: Syeed 

Google reported in a blog post yesterday that they found evidence of a spear phishing attack that compromised the emails of some high ranking US and Asian government officials as well as civilian contractors with military interests.

According to the blog post by Google, the attackers sent out highly personalized emails to the unnamed officials, pretending to be friends, associates and collaborating organizations. The emails contained attachments which led them to false Gmail login pages that stole their passwords.

After harvesting the passwords, Google says the attackers created rules that forwarded the victims emails to their email accounts. The hackers probably also monitored the victims emails and gathered tons of personal information on them an their contacts which allowed them access to even more accounts. Google says they believe the goal of the attack seemed to be monitoring the victims emails. I would guess in an attempt to steal some military secrets.

Google is saying the  attacks originated from Jinan China, however they haven’t released any evidence to support that claim. 

Google said that they want to be as transparent about security issues as possible so that more people can be aware of potential threats. They said they have already alerted all the proper authorities, notified those who were compromised and put a stop to a hack already.

Related Stuffs:

Saturday, May 28, 2011

Quick Hit:Lockheed Martin Hacked?

 

Lockheed-Martin

According to recent reports, the U.S’ biggest defense contractor, Lockheed Martin might have fallen victim to a recent hacking attempt.

The attack was apparently carried out using RSA SecureID tokens from EMC that were stolen in another hack this past March. According to reports someone used the ID’s to break into Lockheed Martin’s company network.

Lockheed Martin isn’t commenting on what data was stolen if any. It’s pretty safe to assume that anything exceedingly top secret wouldn’t be stored on any network whatsoever, so I don’t see there really being much cause for panic. Not to mention no one knows who broke in or their intentions so it would be kind of silly to get too worried now.

Reports are also saying that once Lockheed Martin was made aware of the breach they forced everyone to change their passwords company-wide and ordered another 90,000 SecureID tokens from EMC.

Related Stuffs:

Tuesday, May 17, 2011

Android Security Flaw Leaves User Data Wide Open

android_security

By: Kareem Ali

A report from information week today, brings to light issues with security on Android devices that could lead to hackers gaining access to your personal information when you log into unsecure Wi-Fi spots.

The flaw is in the ClientLogin authentication protocol that Android devices use when they log into an open WiFi network. The tool authenticates a users account details by passing what’s know as an authToken, the authToken is sent via HTTPS which is pretty secure, the problem is the authToken that’s returned by the app comes in through regular HTTP (no encryption), which means that a cybercriminal or hacker could gain access to personal data by sniffing out the authToken and using it to access users personal data.

According to the report the data that’s left unencrypted is calendar information, contact data, and private web albums. So if someone was to hack your authToken from an unsafe WiFi connection they would be able to make any modifications to that data they choose. Including deleting and viewing.

The affected versions of Android include 2.1 up to 3.0 and everything in between. Anything older than 2.3.3 is wide open (meaning all your authTokens are being returned un-encrypted), 2.3.4 fixes the problem with calendar and contact authTokens, but still leaves your pictures out in the open.

The issue applies to all third and first-party apps on Android that use the ClientLogin protocol without HTTPS, not just Gmail, Picasa, and Google Calendar.

This is just adding more fire to the recent phone-security-paranoia flame that’s been burning since people found out their phones track them.

I personally don’t like the government being all up in my data at all, but I understand I have to give up a certain amount of privacy in this new internet/social/super phone era that we live in if I want to enjoy all the benefits of social networks, email, and my cell phone. Otherwise developers are limited in the things they can do. Foursquare wouldn’t exist if a phone couldn’t find out where you are in order to check in, Facebook wouldn’t work if my friends couldn’t find me and I couldn’t find them, etc..  That does not mean however, that I’m willing to give packet-sniffers my personal contacts.

There is a very easy way to avoid all this together just don’t sign up for Facebook or send emails or have a cellphone. If you do have a presence on the  internet and a mobile phone, and you’re a little paranoid about your data being secure here are some quick tips;

  • If you want to avoid this whole security flaw in Android there is a simple setting called airplane mode which has been on phones for quite some time, go to your wireless settings turn it on and all wireless connections will be killed. That will prevent anyone from taking your authTokens or doing any other wireless sniffing. You could also just not log into ‘open’ WiFi networks.

 

  • Study your privacy settings on whatever social network your on, learn how to block users and prevent people who aren't ‘connected’ with you directly from seeing or having access to any of your posts, tweets, check-ins or whatever it is you kids do on your internets nowadays.

 

  • Finally if your using email, I would suggest Gmail, not because it’s my favorite or the most popular, but mainly because it’s the most secure. Unless they’ve changes how the do things Gmail works by sending an encryption key to the machine your emailing so that the message can be sent through their servers encrypted and un-viewable to anyone except those with the encryption key. Once it arrives at the target email address, it’s unencrypted and made viewable. Although no one but you and the intended recipient have the key’s for the encryption there is still the matter of Google having your login info which of course means that they can go through any emails they want at any time or if given enough money by the government or investigators. But there is really now way of avoiding this beyond setting up your own email server for you and your friends separate from any third parties.

I expect that Google will be fixing this for all apps soon and force secure packet transfers for returning authTokens, until they do, I would really suggest not connecting to any open public WiFI networks (which you really shouldn’t be doing on any OS on any device anyway).

Nothing is ever secure on the internet and privacy is a joke, there was a time on the web when people realized they didn’t have to give all their real information to anyone, I remember when Facebook first came around and expected me to put ‘proper’ info on there, I was shocked, I didn’t think anyone on the internet would be stupid enough to hand over their real name and other information to a website that didn’t sell anything. At that time I understood that some places like eBay might need all that so they could ship you things and what-have-you but a fake MySpace? Why would I give them any legit information?

At any rate it seems that now, people are totally willing to put not just their own information but their friends, family and co-workers information as well. It truly is a weird and wacky world, but it’s my world and I love it.

Related Stuffs:

Monday, May 16, 2011

DropBox Not As Secure As Thought?

dropbox

By: Kareem Ali

The Federal Trade Commission is after DropBox for apparently lying to it’s customers about how safe, secure and encrypted their data is on the service.

The problem seems to stem from DropBox not being entirely forthcoming in it’s terms of service.  DropBox has modified and changed it’s terms of service since it’s release, not really a big deal usually, except in this case, they’ve made some pretty serious changes pertaining to security that could affect the way people use it or if they use the service at all.

Originally DropBox claimed that it’s service would store your data on in an encrypted fashion and that the keys to that encryption were only accessible to those who had your login information. This assumingly meant that a user had the keys to their drop box on their machine, safely behind all their own security and away from prying eyes.

The changes DropBox made now state that they (DropBox) can access and view your encrypted data, and it’s willing to give it to law enforcement (no word on if they charge or are giving it away for free like MySpace used to) if they ask. Not only that but DropBox employees also hold the keys to your encryption and have access to all your data as well. DropBox did say however that employees are prohibited from viewing your data so I guess that’s something.

This could be a mistake on DropBox’s part. Cloud storage is pretty new and kind of a touchy security thing. The biggest mistake they seem to have made here is allowing themselves access to the encryption keys at all. These things should be stored on users machines and only pass through their servers, never be stored there. If an employee was to go ‘bad’ and steal or delete a bunch of user data that could cost the company millions in downtime. Not to mention that if their servers were hacked the attacker could not only get users login information, but also the encryption keys to all their files.

There are better solutions to security when it comes to cloud storage, I’m not an expert by any means in this field so I can’t say what those are exactly, but I’m sure most DropBox users are hoping that this was just an oversight on the companies part and that they’ll implement a better, more secure system soon.

All this will be settled out in court soon, if the FTC gets their way, DropBox’s TOS will have to reflect the truth, and let all it’s users know who exactly can see their data.

Related Stuffs:

Source: Wired

Saturday, May 14, 2011

Last Past Security Breach Not As Bad As I Thought

shame-on-me

By: Kareem@techsual.com

The password hack at LastPass was not as  bad as I originally thought. Here's the facts of what really went down.

Last week I reported on a story about the password security software LastPass getting hacked. One reader pointed out that I had gotten my facts wrong, I’m not one to let pride get in the way of facts so I looked it up and it turns out he was right. Here’s the facts.

According to LastPass, they experienced some suspicious activity on their network last week and locked down all the accounts immediately. I originally stated that there had been up to 1.25 million passwords stolen, but that number is insanely inflated. I got my news from Bloomberg and my guess is they got that number from the fact that so many accounts were locked down by LastPass. The truth of the matter is that they locked down all the accounts due to the suspicious activity. It’s a good move because if they had been hacked (having not been certain at the time) then they would prevent the hacker from getting more information than they already had.

According to LastPass there was no evidence that any customer data was leaked, and that if it was it was encrypted. Normally I would balk at the encryption factor, since given enough time any encryption can be cracked. However in this case LastPass did something very very very smart…they forced everyone to change their passwords, here’s a piece from their blog:

“To counter that potential threat, we're going to force everyone to change their master passwords. Additionally, we're going to want an indication that you're you, by either ensuring that you're coming from an IP block you've used before or by validating your email address. The reason is that if an attacker had your master password through a brute force method, LastPass still wouldn't give access to this theoretical attacker because they wouldn't have access to your email account or your IP.”

They mentioned on the their blog that it might have been a little overreaction, but better safe than sorry I say.

LastPass also mentioned on their blog that they don’t have any details on what exactly happened yet, but they’re working on finding all that out. I say kudos to LastPass for being transparent on this matter and handling it so well….maybe it isn’t such a horrible idea to put all your password eggs in one basket after all.

Also I offer my apologizes for feeding into the media hyperbole and not doing my homework properly. I’ll do my best to make sure it dosen’t happen again, and thanks to the reader who pointed this out to me. I want to bring you guys the facts if I’m wrong and you know it I will make sure I fix it, no ego’s here.

Related Stuffs:

Friday, April 22, 2011

Stop Being So Paranoid About You Phone Collecting Location Data

spy_thumb

I know I put my paranoia hat on when the news started reporting about Apple collecting your location data for ‘unknown’ reasons, but now it’s time to put my common sense hat on and tell you all to relax a little bit.

I was entirely joking about the whole paranoia of how iOS’ data collection can help law enforcement track you using computer forensics. Not joking in the sense that it can’t happen but rather because I thought it was common knowledge location data was being collected, stored on devices and used in computer forensics since the days of the first smart phone. How else would they know where to route an incoming call? They have to know where your phone is or at least have a general idea to connect you to anything, that’s just the way technology works. Even thought this data has been hidden behind data center firewalls, there’s always that cache that has to sit in your memory. At least until the phone isn’t receiving power, and I don’t mean turned off.  I’ll explain later.

A good investigator will find you regardless of whether or not you use a cell phone. There are so many other, easier ways to find out where someone has been, for example ask their friends, or their parents, or just follow them on Facebook or twitter. That’s just the tip of the iceberg I’ve seen what talented investigators are capable of and trust me, they don’t need to track you by your phone. It sure makes life easy though.

All smartphones not just Apple’s collect location data for the aforementioned sending and receiving information as well as for applications. The data they store is not very specific despite what people may say, GPS location data can be pinpoint accurate, but the way that Apple and Google do it is known as cell phone tower triangulation, which dosen’t give an exact location but rather a general area. Data can be sent to that area, picked up by a base station and then sent to your cell phone’s specific frequency or it’s SID. The only thing logged in the memory is the location of the tower you were near when the data was sent.

The reasons people are reporting the data to be so accurate is due to the fact a lot of people either have GPS enabled by default, or they’re using apps like Foursquare and Facebook check –in and giving the cache their exact location.

So why dosen’t turning off your phone stop the stream of data? Without going into too much detail, basically when you turn off your phone the battery keeps a leak charge running through the phones memory that keeps it updated. It only takes about 0.6-3 watts to keep your phone sending that data. The only solution is to take the battery out of your phone altogether, or just not use one if your going to be that paranoid about people finding out where you are or have been.

Thursday, April 21, 2011

iOS Data ‘Glitch’ Was Already Known And Being Used By Law Enforcement

iPhone2

Turns out I wasn’t being so paranoid in saying that the iOS 4 data ‘glitch’ might have been Apple’s way of helping law enforcement circumvent the subpoena's that are normally necessary when investigating someone's data.

According to a young man by the name of Alex Levinson who works with computer forensics, the story that broke yesterday about Apple tracking users location data, wasn’t news to people working in the his field. He posted on his blog 3 major issues with the new ‘discovery’.

Levinson’s first beef is with people thinking that Apple is collecting the data, he wants to emphasize that Apple does not ‘harvest’ the data from your device, he says the data is collected by iOS mostly for applications running on the phone that need it for such things. You can see how this makes sense, especially if you’ve used Foursquare or Geo-tagged a Tweet.

His second beef is  that the data is neither new, nor hidden. He states that before the iOS 4 was storing the information on consolidated.db., previous versions of the operating system held the data on a file called h-cells.plist.

Third, Levinson is angry that know one in the major media noticed that this ‘discovery’ was published by him and Sean Morrissey months ago in a book they wrote called iOS Forensic Analysis. Not only that but the company that he works for Katana Forensics, has had a program that does the same thing Warden’s does and then some which is currently being used by law-enforcement in computer forensics investigations. Which leads me….

Back to my paranoid cap, if this has been known for some time and been around since before iOS 4 that proves it’s not a ‘glitch’ as some have rumored, but rather it’s intentional data collection done for a purpose. Although Levinson gives a good reason for the data being collected (for use by applications) it still dosen’t make much sense to me that the data is being collected for extended periods of time. I know some apps need to know your current location. but I don’t know of any app that needs to know where you were 6-12 months ago, I do know a lot of police and other law enforcement that would love to know that in order to build a case, and it would be pretty helpful to them to not have to pay for it or go through those annoying subpoenas.

Just thought I’d feed the paranoia wheel a little. As a side note I found a little interesting bit of information in my research, T-Mobile is the on U.S cell phone service provider that dosen’t keep a detailed user data base persistently. It’s not that they don’t want to, they just cant do it for technical reasons.

Until Apple makes it easy to take out their battery, I’m going to have suspicions.

Tuesday, April 5, 2011

Phishing Scammer Almost Gets Away With $8 Million

Phishing

A company by the name of Condé Nast, a giant publishing company was the victim of a phishing scam that almost netted the phisher $8 Million.

The complaint filed in Manhattan District Court by the U.S Attorney’s office, the accounts payable department of Condé Nast was fooled by a fake email that claimed to be on of their partners Quad/Graphics. The email included an E-Payment form which tricked the department into paying out $8 Million to the fake account between Nov 17, 2010 and Dec 30, 2010.

The account was frozen on Jan 9, 2011, before the perpetrator could withdraw the funds from the account he had set up. According to authorities he was caught because he incorporated the name using his home address.

For those of you who might not know, a phishing attack is when someone sends you an email claiming to be someone else in order to get you to open the link and give up information. Phishing can also be done by setting up fake websites with the same or similar domain names as ones you would trust in an attempt to get user login information.

I kind of like to organize the phishing attacks in two categories; there’s personal phishing and business phishing the way I see it.

An example of personal phishing would be to send someone an email claiming to be Facebook for example, the email can say you logged in from somewhere you don’t know and send you a link to a url to ‘fix’ your security settings. Once you click the link you’d be sent to a site that looks like the Facebook login site but isn’t, there you fill out your login information, maybe change a couple of pretend security settings (a good phisher will actually have you turn off any alerts rather than turn them on) and click next. At this point your sent directly to Facebook to avoid arousing suspicion and continue on about your day. Completely oblivious to the fact that you just gave your password away and turned off all your security emails. This is of course a simple example using something rather harmless in the scheme of things, phishers have been known to steal bank, social security and email login information among the many other much more dangerous threats to your security than losing a Facebook profile.

An example of a business spear phishing attack would be pretty much the same as above, you send an email, wait for someone to bait the hook, and then reel ‘em in the only real difference is motives, sometimes it’s access to a system, sometimes its wanting to wire millions of dollars to a fake account or steal proprietary information. Businesses' have a lot more to lose by phishing attacks and I think their best option would be to get phone verification with caller id before transferring any payments. It’s possible to get around that but it’s be a lot more technically than what I think most phishers are capable of.

Source: Threat Post

Monday, March 7, 2011

Facebook Playing Big Brother, But it’s for Your Own Good

 

Facebook is releasing a new system that allows users to report people they think might be at risk for committing suicide.

The system (which has already been tested and should roll out any day now) is called ‘Good Samaritan, it basically allows users to report people posting things that might lead them to believe their a threat to themselves (suicidal) to Facebook's admins, in return they'll look at the proposed page and decide whether or not they need to alert police.

This is an invasion of privacy on a whole ‘nother level. Facebook, no matter how good their intents, should not be looking into peoples lives and deciding whether or not they are going to take their own lives. I think that if one of my friends was seriously concerned with my committing suicide then they would do a little more than warn Facebook's admins, like I don’t know, calling me and talking to me, maybe having an intervention.

The point is how long will it be before people are turning each other in for crimes, or infringement or any other BS using Facebook as an anonymous snitch? I firmly believe that if anyone has a problem with me, what I post or they way I act they should feel comfortable enough in their own judgment to talk to me directly.

Maybe I’m reading too much into this, and I honestly hope I am. I hope this system never goes beyond allowing people to help others not commit suicide.

That is all, have a nice day

Oh and check the link for a much less biased article over at BBC.

Article: Facebook adds Samaritans Suicide Risk Alert System.

Twitters Bad Side Growing

twitterDarkSide

Twitter’s suspended accounts started to rise the last half of 2010 according to a security company named Barracuda Networks.

According to the report from Barracuda, the last half of 2010 saw a rise in suspended Twitter accounts,  from 2 to 20%. The graph is part of Barracuda’s annual security report.

The report also goes over Email threats, Search Malware, and Facebook security. You can read it here, it’s defiantly worth looking over if your curious as to how people get malware into your computer.

Check out the link for an article on Tech World.

Article: Twitter’s ‘dark side’ growing once again.

Stumble