Wednesday, October 16, 2013

Week 8 Blog

The NSA and their Backdoor Secrets

One of the most fascinating things about information security is the concept of a backdoor. What is more interesting is the shear idea that the NSA desires to eavesdrop on our internet traffic through the use of a backdoor. (Schneier, 2013) “[NSA] has secret agreements with telcos to get direct access to bulk internet traffic. It has massive systems like TUMULT, TURMOIL, and TURBULENCE to sift through it all. And it can identify ciphertext — encrypted information — and figure out which programs could have created it” (Schneier, 2013). Obviously, it is a little frightening to know that the NSA can easily go through our internet communications and collect our personal information whenever they want. It is even more alarming that the NSA can undercover this encrypted information and which potential program encrypted it to begin with.

Another interesting item to note is that, “The NSA wants is to be able to read that encrypted information in as close to real-time as possible. It wants backdoors, just like the cybercriminals and less benevolent governments do. And we have to figure out how to make it harder for them, or anyone else, to insert those backdoors” (Schneier, 2013). I guess this makes it our duty to prevent the NSA from inserting these backdoors. It seems a little ironic that we have to protect ourselves from the NSA. I thought they were on our side. More specifically, it is the National Security Agency’s motto to state that they are, “Defending our Nation and Securing the Future” (National Security Agency, 2013). I hope the NSA knows exactly what they are doing by wanting to incorporate all of these backdoor “features.”

In order for NSA to design backdoors, a few concepts should be considered. For instance, the concept of low discoverability, high deniability, and lastly the concept of minimal conspiracy should be considered. (Schneier, 2013) More specifically, “Low discoverability [means] the less the backdoor affects the normal operations of the program, the better. Ideally, it shouldn’t affect functionality at all. The smaller the backdoor is the better. Ideally, it should just look like normal functional code” (Schneier, 2013). This makes sense to the idea of low discoverability. You do not want functionality to be affected at all. Next is the concept of high deniability. For instance the concept of high deniability means, “If discovered, the backdoor should look like a mistake” (Schneier, 2013). Lastly, there is the concept of minimal conspiracy. “The more people who know about the backdoor, the more likely the secret is to get out. So any good backdoor should be known to very few people” (Schneier, 2013). These concepts are all just basic ideas of how the NSA could design their backdoors. (Schneier, 2013)


Some great strategies to defend against backdoors include the following: (Schneier, 2013)

·         “Vendors should make their encryption code public, including the protocol specifications. This will allow others to examine the code for vulnerabilities.”

·         “The community should create independent compatible versions of encryption systems, to verify they are operating properly.”

·         “There should be no master secrets. These are just too vulnerable.”

·         “All random number generators should conform to published and accepted standards. Breaking the random number generator is the easiest difficult-to-detect method of subverting an encryption system.”

·         “Encryption protocols should be designed so as not to leak any random information. Nonces should be considered part of the key or public predictable counters if possible. The goal is to make it harder to subtly leak key bits in this information.”


There is no definite method to defend against backdoors. The techniques listed above offer some great techniques to help prevent backdoor problems. For instance, “With these principles in mind, we can list design strategies. None of them is foolproof, but they are all useful. I’m sure there’s more; this list isn’t meant to be exhaustive, nor the final word on the topic. It’s simply a starting place for discussion. But it won’t work unless customers start demanding software with this sort of transparency” (Schneier, 2013). It is clear that this backdoor issue is one that the public needs to be aware of so that we can all work together and try to get these problems resolved.

 

References

National Security Agency. (2013, September 4). National Security Agency Central Security Service. Retrieved October 16, 2013, from National Security Agency Central Security Service: http://www.nsa.gov/

Schneier, B. (2013, October 16). How to Design — And Defend Against — The Perfect Security Backdoor. Retrieved October 16, 2013, from Wired: http://www.wired.com/opinion/2013/10/how-to-design-and-defend-against-the-perfect-backdoor/

Friday, October 11, 2013

Week 7 Blog

Government Agencies = New Target for Attackers


Attackers have released a new virus that is seemingly only attacking government organizations. (The Yomiuri Shimbun, 2013) “Attackers implant a virus on certain websites. When people using targeted computers browse these sites, the computers [become] infected with the virus. The virus [does] not attack non-targeted computers” (The Yomiuri Shimbun, 2013). More specifically, “The virus is designed to infect only computers of certain IP addresses when users browse the altered websites on those computers” (The Yomiuri Shimbun, 2013). It’s funny to me that this new virus basically skips certain computers and only goes for government based computers. It seems like an attacker would want to take down every person that they could since they have the opportunity.

It's so fascinating that the attackers are only after governmental organizations. Obviously, there is some internal motive for these attacks. For instance, “The attackers alter websites that are frequently browsed by employees of government administrative organizations who are members of the websites. The attackers then implanted the virus on those websites, letting it await the chance to infect targeted computers so they could steal confidential information by taking control of the computers remotely” (The Yomiuri Shimbun, 2013). The attackers have a great attack mechanism in place. It seems like these attackers really had to think about their attack mechanism thoroughly so that they would be sure it worked. I am also amazed that the attackers are stealing confidential information remotely.

The attackers have really outdone their selves on this virus because “the virus is designed to infect only computers of certain IP address when users browse altered websites on those computers” (The Yomiuri Shimbun, 2013). This is just such a crazy technique for a hacker to apply when using a virus because they are clearly only targeting certain people. More interesting is the fact that, “Ordinary people using computers [. . .] are not targeted by the attackers [and they will] not get infected with the virus. [Therefore,] it is difficult for the cyber-attacks to be discovered” (The Yomiuri Shimbun, 2013). While it seems like attackers would want to take as many victims as possible these attackers don't seem to care about this approach at all. Clearly, these attackers are using other people to get to their real victims. Obviously, people who are not targets will be really happy to hear about this because they don’t have much to fear as far as becoming infected with a virus. However, governmental agencies should be very concerned because they could easily become the victim of an attack.

Reference:
The Yomiuri Shimbun. (2013, October 9). New Type of Cyber-Attack Targets Govt Bodies, Firms. Retrieved October 11, 2013, from The Japan News: http://the-japan-news.com/news/article/0000711266

Sunday, October 6, 2013

Week 6 Blog


Adobe Got Hacked

The world of Information Security is of course ever growing. Throughout all of the warnings, companies are still not choosing the best means possible to protect their customer’s personal information. Recently, Adobe was hacked. The attackers were able to obtain “customer names, encrypted credit or debit card numbers, expiration dates, and other information relating to customer orders.” (King, 2013) In fact, 3 million accounts were compromised by the attack on Adobe. (King, 2013)



            While the attackers were only able to compromise encrypted credit and debit card numbers, my concern is that the attackers maybe be able to decrypt this information in the future. It is unclear as to what type of encryption algorithms Adobe was using. Obviously, it is our hope that they used the strongest encryption algorithm possible but this does not guarantee any customer security on the matter. However, Adobe has taken some immediate action to reset all adobe passwords. (King, 2013) Therefore, Adobe has made a few attempts to help their customers.       

            Holding a customer’ private information is a very difficult task that all businesses will face. It is important that businesses employ information security professionals in order to help mitigate the risk of being vulnerable to attackers. However, eliminating all risks is not necessarily easily done. It is important to protect customer’s information because you run the risk of jeopardizing your own company’s reputation. If a business loses their reputation, they may face scrutiny from the public and even face losses in sales. It is so important that businesses take information security very seriously.

References

King, R. (2013, October 3). Adobe hacked, 3 million accounts compromised. Retrieved October 6, 2013, from CNET: http://news.cnet.com/8301-1009_3-57605962-83/adobe-hacked-3-million-accounts-compromised/

Monday, September 23, 2013

Week 5 Blog


iPhone iOS7 Users Fall Victim to Attackers


The iPhone’s new iOS7 is pretty nifty but it looks like there is already a security vulnerability that some may not know about yet. Apparently, a “SIRI vulnerability enables attackers to act on user's behalf - even when iPhone is locked” (Wilson, 2013). This vulnerability has me questioning Apple’s security standards. Obviously, Apple did not intend on have this type of vulnerability for their new iOS7 software but it does bring up the question of what security standards Apple does have in place because the vulnerability did still occur. Perhaps Apple should re-review their current security policies and standards to be sure that they are coinciding with what their current polies should hold.

“Cenzic researchers said they were able to use a locked iPhone belonging to a third party to send email and texts, make calls, access contact information, and make updates to Facebook and Twitter, all with the user's accounts and without the user's knowledge” (Wilson, 2013). Well, since I have an iPhone, this really alarms me. I just keep thinking Apple where is my security patch? I guess for now there is no patch. I supposed I could wipe my iPhone and then add all my data back once Apple decides to implement better security standards into their software. I guess this kind of defeats the purpose of buying an iPhone in the first place though. It might just be easier for Apple to hire some super smart information security personnel to help create better security polies, standards, and guidelines.

While the new iPhone iOS7 has this vulnerability, it seems that there is a way to add some protection to your device. Apparently disabling SIRI will help with this iPhone vulnerability. (Wilson, 2013) I hope that Apple will soon at least release an update that solves this security problem. Oh Apple, you are so flashy! You have the world at your disposal! Since so many people love you so much, you could at least give us some security in our relationship with you by implementing better security features.


 

Reference
 
Wilson, T. (2013, September 22). Flaw In iOS 7 Lets Attackers Take Control Of Users' iPhones. Retrieved September 23, 2013, from Security Dark Reading: http://www.darkreading.com/privacy/flaw-in-ios-7-lets-attackers-take-contro/240161623

 

Wednesday, September 18, 2013

Week 4 Blog


The Hidden Lynx Hackers


The Hidden Lynx is a professional group of hackers who partake in many different forms of exploitation. (Zetter, 2013) “The group has targeted hundreds of organizations - about half of the victims are in the U.S. - and has succeeded in breaching some of the most secure and best-protected organizations” (Zetter, 2013). The Hidden Lynx hackers are extremely sleek and have outstanding hacking abilities. (Zetter, 2013) The Hidden Lynx hacker group uses many different approaches to taking down secure infrastructures. More specifically, “The Hidden Lynx group pioneered so-called ‘watering hole attacks’ whereby malicious actors compromise web sites frequented by people in specific industries so that their computers are infected with malware when they visit the sites” (Zetter, 2013). This was one effective technique that the Hidden Lynx group has employed. Another technique the group has used is dynamic DNS. (Zetter, 2013) The Hidden Lynx "Dynamic DNS rapidly switches command-and-control servers to hide their tracks and recompiles their backdoors frequently to keep a step ahead of detection. They also switch out zero-day exploits when one is discovered” (Zetter, 2013).


Another technique that the Hidden Lynx hacker group targeted was Bit9. (Zetter, 2013) The hackers attempted to, “resemble the hackers that penetrated RSA security in 2010 and 2011. In that case, hackers targeting defense contractors went after RSA security in an attempt to steal information that would allow them to undermine the RSA security tokens that many defense contractors use to authenticate workers to their computer networks” (Zetter, 2013). In addition, “Bit9, [. . .] provides a cloud-based security service that uses whitelisting, trusted application control and other methods to defend customers against threats, making it difficult for an intruder to install an untrusted application on a Bit9 customer’s network” (Zetter, 2013).
 
Moreover, “The attackers first broke into the network of a defense contractor, but after finding that a server they wanted to access was protected by Bit9’s platform, they decided to hack Bit9 to steal a signing certificate. The certificate allowed them to sign their malware with the Bit9 certificate to bypass the defense contractor’s Bit9 protections. The Bit9 attack, in July 2012, used SQL injection to gain access to a Bit9 server that wasn’t protected by Bit9′s own security platform. The hackers installed a custom backdoor and stole credentials for a virtual machine that gave them access to another server that had a Bit9 code-signing certificate. They used the certificate to sign 32 malicious files that were then used to attack defense contractors in the U.S. Bit9 later revealed that at least three of its customers were affected by the breach” (Zetter, 2013). I found it pretty ironic that Bit9 didn’t protect its own security platform. The Hidden Lynx definitely did their research on Bit9. Perhaps, Bit9 should have done its own research first in order to prevent being hacked. It just seemed like Bit9 was an easy open target for the Hidden Lynx to attack. My favorite technique that the Hidden Lynx used was signing their malware with the Bit9 certificate. This was just brilliant. Who would ever second guess Bit9's own certificate.


The Hidden Lynx has also hacked high profile stock trading firms. (Zetter, 2013) In addition, “The Hidden Lynx group has also gone after the supply chain, targeting companies that supply hardware and secure network communications and services for the financial sector” (Zetter, 2013). They have even compromised legitimate software driver websites so that the users download drivers with Trojans. (Zetter, 2013) It seems that this group’s motive concentrates around making money, stealing assets, and intellectual property. (Zetter, 2013) In addition, according to Symantec, they the Hidden Lynx has left fingerprints all over and this allowed Symantec to trace their activities and attacks. (Zetter, 2013) The group doesn’t seem to care about covering their tracks potentially because of the time and money involved. (Zetter, 2013) It seems like even the some of the best hackers also have their own weaknesses as well. I wonder who will exploit/uncover their weaknesses.
 

Reference:


Zetter, K. (2013, September 17). State-Sponsored Hacker Gang Has a Side Gig in Fraud. Retrieved September 17, 2013, from Wired: http://www.wired.com/threatlevel/2013/09/hidden-lynx/

Sunday, September 15, 2013

Week 3 Blog

Hacking iPhone's Fingerprint Reader

Apple recently announced that its latest iPhone would have a fingerprint reader that will give the user a great and simple new way to secure their phone. (Schneier, 2013) This fingerprint reader will offer a new advantage to those who currently use their iPhone for practically every aspect of their lives. Since Apple is planning to utilize a fingerprint reader in their new iPhones, there are some problems to be aware of concerning this new addition. More specifically, can this fingerprint reader be easily hacked? Before answering this question, it is essential to understand how a fingerprint reader can initially fail to begin with. “There are two ways an authentication system can fail. It can mistakenly allow an unauthorized person access, or it can mistakenly deny access to an authorized person” (Schneier, 2013). Having this knowledge opens up obvious possibilities to how this new fingerprint reader can become hacked. For example, “Someone with a good enough copy of your fingerprint and some rudimentary materials and engineering capability - or maybe just a good enough printer - can authenticate his way into your iPhone” (Schneier, 2013). Obviously, this seems to be less of a worry because of the extreme procedures required to gain access to someone’s iPhone.

There are more concerns with the new fingerprint reader though. More specifically, “The final problem with biometric systems is the database. If the system is centralized, there will be a large database of biometric information that’s vulnerable to hacking. A system by Apple will almost certainly be local - you authenticate yourself to the phone, not to any network - so there’s no requirement for a centralized fingerprint database” (Schneier, 2013). Having a large database of biometric information would be a rather risky step to take. In addition, it would be even more of a security risk if your fingerprint were used to gain access to your iCloud account. (Schneier, 2013) More specifically, “The centralized database required for that application would create an enormous security risk” (Schneier, 2013). Therefore, while the fingerprint reader is an amazing idea for the new iPhone it does create security risks. Hopefully, Apple will find ways to mitigate these risks so that users can enjoy the new iPhone feature.
 
References
Schneier, B. (2013, September 10). If Apple’s iPhone Has Fingerprint Authentication, Can It Be Hacked? Retrieved September 11, 2013, from Wired: http://www.wired.com/opinion/2013/09/what-if-apples-new-phone-has-fingerprint-authentication/
 

Tuesday, September 3, 2013

Week 2 Blog


New Banking Malware Unleashed

  

According to an article posted on Security Week's website, there may be a new threat to the Banking industry. A new Trojan, dubbed, the “Hand of Thief” maybe a new cause for concern in the Security world. (Prince, 2013) According to Security Week’s article, “The Trojan, which is focused on stealing information from machines running Linux, includes form grabbers and backdoor capabilities and is expected to ‘graduate to become full-blown banking malware in the very near future’” (Prince, 2013). This should be very frightening to anyone who utilizes the banking industry. However, it seems that at this moment the “Hand of Thief” Trojan may still be in development which should put many people at ease at least at this point in time. (Prince, 2013) More specifically, “Hand of Thief has come to the cybercrime underground at a time when commercial Trojans are high in demand, stirring some excitement amongst criminals” (Prince, 2013). While many should take note of the fact that this Trojan may be out there in the world and ready to strike it seems that removal and the overall threat of this Trojan are currently relatively low. (Prince, 2013)
 
References
 
Prince, B. (2013, September 3). Reach of 'Hand of Thief' Banking Trojan Exceeds Grasp: RSA. Retrieved September 3, 2013, from Security Week Internet and Enterprise Security News, Insignts, & Analysis: http://www.securityweek.com/reach-hand-thief-banking-trojan-exceeds-grasp-rsa