Showing posts with label Information Security. Show all posts
Showing posts with label Information Security. Show all posts

Monday, April 4, 2011

Comodo hack may reshape browser security

 Major browser makers are beginning to revisit how they handle Web authentication after last month's breach that allowed a hacker to impersonate sites including Google.com, Yahoo.com, and Skype.com.
The efforts are designed to remedy flaws in the odd way Web security is currently handled. Currently, everyone from the Tunisian government to a wireless carrier in the United Arab Emirates that implanted spyware on customers' BlackBerry devices and scores of German colleges are trusted to issue digital certificates for the largest and most popular sites on the Internet.

Microsoft's manager for trustworthy computing, Bruce Cowper, told CNET that the company is "investigating mechanisms to help better secure" certificate authorities, which issue trusted digital certificates used to encrypt Web browsing, against this type of attack.
On Friday, Ben Laurie, a member of Google's security team, said the Mountain View, Calif., company is "thinking" about ways to upgrade Chrome to highlight possibly fraudulent certificates that "should be treated with suspicion."
If the technology were widely adopted and glued into major browsers, that would have made last month's Comodo breach a non-event. The Jersey City, N.J.-based company announced on March 23 that an intruder it traced to Iran compromised a reseller's network and obtained fraudulent certificates for major Web sites including ones operated by Google and Microsoft. The FBI is investigating.
Comodo alerted Web browser makers, which immediately scrambled to devise ways to revoke the fraudulent certificates. There's no evidence the certificates were misused.
Peter Eckersley, a senior staff technologist at the Electronic Frontier Foundation who has compiled a database of public Web certificates, says one way to improve security is to allow each Web site to announce what certificate provider it's using.
Each browser trusts as many as 321 certificate authorities equally, a security nightmare that allows any of them to publish fake certificates for, say, Google.com. It's as if hundreds of superintendents in New York City had the master keys to every unit in every apartment building--as opposed to the normal practice of one master key per each superintendent.
Eckersley says browsers should be developing "a way for each domain name holder to persistently specify its own private certificate authority if it wishes to." Once that is established, "mistakes at any one of thousands of other organizations would no longer give hackers a magic key to your systems," he says.
Securing domain names with a technology called DNSSEC will also play a "large" role, he says. Other long-term technical fixes that have been proposed have names like DANE, HASTLS, CAA (Comodo's Philip Hallam-Baker is a co-author), and Monkeysphere.
Comodo's revelations have highlighted the flaws of the current system. There is no automated process to revoke fraudulent certificates. There is no public list of certificates that companies like Comodo have issued, or even which of its resellers or partners have been given a duplicate set of the master keys. There are no mechanisms to prevent fraudulent certificates for Yahoo Mail or Gmail from being issued by compromised companies, or repressive regimes bent on surveillance, some of which have their own certificate authorities.
The Internet death penalty
Another option would invoke the Internet death penalty: revoking Comodo's status as a trusted source of digital certificates. Each major browser has a different list of which certificate authorities are trusted, and Comodo appears on all of them. (See related CNET article and spreadsheet.)
Mozilla says in a Web page that it is "interested in more detailed impact assessments" of how the death penalty applied to Comodo--an unprecedented punishment--would work in practice.
Cowper declined to provide details about whether a similar step is being considered for Internet Explorer: "Microsoft will not discuss any decision about Comodo's membership in the Windows Root Certificate Program." He added: "Microsoft is in ongoing discussions with Comodo regarding this incident. After completing this review and evaluating the appropriate mitigation steps, Microsoft will ensure that Comodo and other (certificate authorities) comply with any updated program requirements."
Microsoft already requires that certificate authorities submit "complete a qualified audit and submit the audit report" every 12 months. So does Mozilla.
Google's Chrome browser relies on the list of trusted certificates compiled by Microsoft and, under OS X, Apple. "We haven't deviated from the default lists, nor do we have current plans to," a Google spokesman says. Apple did not respond to a request for comment.
Melih Abdulhayoglu, Comodo's founder and chief executive, says that security has been tightened as a result of the breach in an Italian partner's network.
"There is no 100 percent security," Abdulhayoglu added. He said that "any large" issuer of digital certificates is susceptible to concerted attacks. "VeriSign and Comodo, we've both had issues."
Norway-based Opera Software, maker of the eponymous Web browser, is considering a "move towards stricter requirements regarding having revocation information available before allowing a secure connection to complete."
Opera's Yngve Pettersen wrote in a blog post last Thursday that such a requirement would make it easier to revoke certificates that were issued fraudulently.


Source: http://news.cnet.com/

Friday, March 11, 2011

Internet Explorer and Safari first to fall at Pwn2Own 2011, Chrome and Firefox still standing


Computerworld - Google's $20,000 was as safe at Pwn2Own Wednesday as if it had been in the bank.


The search giant had promised to pay $20,000 to the first researcher who broke into Chrome on the hacking contest's opening day.


But no one took up Google's offer.


"The first contestant was a no-show," said Aaron Portnoy, manager of HP TippingPoint's security research team, and Pwn2Own's organizer. "And the other team wanted to work on their BlackBerry vulnerability. So it doesn't look like anyone will try Chrome."


Only two entries had pre-registered for Chrome: Moatz Khader and one or more researchers going as "Team Anon." (Researchers may remain anonymous if they wish.) Based on a random drawing several weeks ago, Khader was to get first shot, with Team Anon second.


Team Anon is also slated to tackle RIM's BlackBerry OS on Thursday.


Late Wednesday, TippingPoint provided a tentative schedule for today's Pwn2Own; that schedule doesn't show any planned Chrome exploit.


Even if someone unexpectedly stepped up to take a crack at Chrome and exploited the browser, Google would be on the hook for just $10,000. As part of the deal it struck with TippingPoint, the two will split the $20,000 payment for a successful hack on the second or third days of the contest.


If Chrome comes out unscathed, as it now appears it will, the browser will have survived three consecutive Pwn2Owns, a record.


On Wednesday, researchers successfully exploited Safari and Internet Explorer. A team from French security company Vupen took down Safari 5 running on a MacBook Air notebook in five seconds, and independent researcher Stephen Fewer used a trio of vulnerabilities to hack IE8 on Windows 7.


Portnoy was impressed with Fewer's work. "The most impressive so far," said Portnoy. "He used three vulnerabilities to [not only] bypass ASLR and DEP, but also escape Protected Mode. That's something we've not seen at Pwn2Own before."


ASLR, for address space layout randomization, and DEP, or data execution prevention, are a pair of technologies baked into Windows that are designed to make it more difficult for exploits to reliably execute. Protected Mode is IE's "sandbox," which isolates the browser -- and thus any attack code that manages to infiltrate it -- from escaping to do damage on the system as a whole.


Pwn2Own continues today and Friday, when Mozilla's Firefox and four smartphones running Apple's iOS, Google's Android, Microsoft's Windows 7 Phone and RIM's BlackBerry OS will be in researchers' crosshairs.

Monday, February 28, 2011

Facebook plans to resume address, phone sharing

Despite congressional criticism, Facebook is planning to resume the aborted rollout of a feature that allowed the optional sharing of addresses and mobile phone numbers.


Facebook said in a letter (PDF) released today that it is evaluating different ways to "enhance user control" over information sharing that would go into effect "once the feature is re-enabled."


The social-networking site encountered some criticism in January after announcing the feature, which allowed applications to request permission to access user information. Only if the user clicked "Allow" was information shared.


Only three days after announcing the platform update, Facebook voluntarily delayed it, with Douglas Purdy writing that "we are making changes to help ensure you only share this information when you intend to do so."


Reps. Ed Markey (D-Mass.) and Joe Barton (R-Texas), who have a history of assailing tech companies including Apple and Google over perceived data transfer snafus, suggested in a letter (PDF) on February 2 that the pop-up permissions window was insufficient "given the sensitivity of personal addresses and mobile phone numbers compared to other information users provide Facebook."


Facebook's response, prepared by Marne Levine, vice president for global public policy, stressed that applications that run on the Facebook platform have long had the ability to ask for information. For example, Levine wrote, "a photo-printing application that prints photos for a user requests permission specifically to access a user's photo; a social-gaming application that allows users to play a game with his or her friends requests permission to access the user' friends list."


In last month's announcement that dealt with contact information, Levine wrote, "we allowed applications to ask users for that information, through a permissions screen...that provided clear and conspicuous notice to the user regarding what information the application is seeking."
And in response to the politicians' point about minors, Levine said that anyone under 13 is prohibited from using Facebook, and the company is "actively considering" whether to allow applications to request information from even older minors.


Markey said in a statement today that he's not satisfied with Facebook's response.
"I don't believe that applications on Facebook should get this information from teens, and I encourage Facebook to wall off access to teen's contact information if they enable this new feature," Markey said. "Facebook has indicated that the feature is still a work in progress, and I will continue to monitor the situation closely to ensure that sensitive personal user data, especially those belonging to children and teenagers, are protected."


Separately, Facebook announced last week that it's asking for comments on a proposed revamp of its privacy policy that's meant to make it easier to understand.


Source: http://news.cnet.com/

Saturday, January 22, 2011

Mobiles attract hi-tech thieves


Cyber criminals are starting to move away from Windows and targeting other technologies, says a security report.

The annual report from net giant Cisco suggests that mobile phone operating systems are becoming increasingly popular with hi-tech criminals.

It predicts 2011 will see a significant number of attacks directed at smartphones, mobile software and users.

Despite this, the vast majority of current viruses are aimed at Windows and programs that run on it.

The trend towards mobile malware took a significant turn in late 2009, says Cisco with the appearance of a virus called Zitmo. This was a mobile version of the Zeus Windows trojan that has proved hugely popular with criminals keen to steal logins to online bank accounts.

Also, wrote Patrick Peterson, senior security researcher at Cisco, improved Windows security made it harder for hi-tech criminals to find new ways to attack PCs.

A growing target, said the report, were Apple products such as the iPhone. Statistics gathered by Cisco suggest a growing number of vulnerabilities are being found in Apple operating systems.

Cisco said Apple's close oversight of what can run on its phones was limiting the effectiveness of attacks but many people were "jailbreaking" their phones putting them at risk from unofficial apps that have malicious elements buried within them.

Apple was not alone among mobile operating systems attracting attention, said the report, attacks were also starting to focus on Google's Android software.

Mr Peterson said Cisco had seen lots of research and development by criminal groups as they focus on mobiles and work out the best way to attack portable gadgets.

Evidence of this was seen in the localised and targeted phishing scams sent out to mobiles as criminals seek to trick groups of users into handing over passwords.

Trojans aimed at Android that booby trap apps that run on phones or bury premium rate links in ads were also starting to turn up. For instance, in late December 2010 the Geinimi trojan for Android was found that can steal almost any of the data on a handset.

"The relative youth of the Android OS, including its apps and ecosystem, combined with the sheer number of users will make this a very attractive platform for exploitation," Scott Olechowski, threat research manager at Cisco.

Source: http://www.bbc.co.uk/

Tuesday, January 18, 2011

Facebook Drops Another 'P' Bomb

Facebook no doubt hoped to minimize the repercussions from its latest privacy change by announcing it late on Friday, but there could be a heavier blowback from its move than the company anticipated. "Many [users] won't realize that they have given permission for their phone numbers to be gathered," said Appitalism.com CEO Simon Buckingham. When they do, he predicted, hell is going to break loose.


Facebook dropped a privacy bombshell on an unsuspecting user base before the start of the holiday weekend: Going forward, it will make a user's address and mobile phone number accessible as part of the User Graph object. That means that users' addresses and mobile numbers are now available to third party developers of such apps as, say, FarmVille.


Facebook acknowledged it was dealing with "sensitive information" in the blog post making the announcement. For that reason, it created a special opt-in permission requirement for the phone number and address to be explicitly granted to the application developer  through Facebook's standard permissions dialog.


It also pointed out that these permissions only provide access to a user's address and mobile phone number -- not to friends' addresses or mobile phone numbers.


Privacy Uproar


Privacy and security  advocates, not surprisingly, were unimpressed by Facebook's nod to consumers with its opt-in form.


"It is a consent requirement, but the notice is so confusing to users it makes it seem as though the information is necessary for the application to work," Marc Rotenberg, EPIC executive director, told MacNewsWorld. "Then there is the very real risk that over time Facebook will change the default opt-in to opt-out. After all it has made so many changes to its privacy policy, why not this one too at some point?"


Facebook did not respond to MacNewsWorld's request for comment in time for publication.


As for Facebook's decision to grant developers this information, Rotenberg expressed more scorn.


In general, granting information to third parties has become a very slippery slope, with little attention being paid to what they are using it for.


"Increasingly, it is being used for purposes other than app development," noted Rotenberg, "such as advertising or behavioral targeting."


Security Threat


Facebook's decision will leave users open to security threats by rogue developers, suggested Graham Cluley of Internet security research firm Sophos in a blog post.


"Facebook is already plagued by rogue applications that post spam links to users' walls, and point users to survey scams that earn them commission -- and even sometimes trick users into handing over their cellphone numbers to sign them up for a premium rate service," he wrote.


Shady app developers will find it easier to gather this data now that Facebook has legitimatized it, he continued, predicting an increase in identity theft as a consequence of making this and other data available on Facebook.


Developers are also at risk with this system, pointed out Douglas Karr, founder of DK New Media and author of Corporate Blogging for Dummies.


"Since this data isn't 'scrubbed' against national do not call and do not mail data, Facebook may be putting application developers in a precarious, dangerous position if the data is somehow misused," he said.


Another Backlash


With so many ways this decision could go wrong, there is a significant likelihood of a backlash, predicted Simon Buckingham, CEO and founder of Appitalism.com. "This is a major change for users, and many won't realize that they have given permission for their phone numbers to be gathered."


When they do, he said, hell is going to break loose. "With 600 million members, Facebook needs to err on the side of caution. This type of information is sensitive, and it is almost guaranteed that a lot of users will be unhappy about its disclosure."


Source: http://www.technewsworld.com

Wednesday, January 12, 2011

Hacker Shows How Cloud Could Wash Out Wireless Security

A hacker claims he's used Amazon's cloud services to bust open SHA-1, a wireless network security standard, and he says he'll be demonstrating his process at an upcoming Black Hat get-together. Malicious hackers could quickly set up brute-force attack systems using the cloud, but critics say real-world password cracks might not come so easily.


German hacker Thomas Roth's announcement that he used Amazon.com's cloud service to crack a wireless network security standard has left some security researchers scratching their heads. Others are merely shaking them in disbelief.


That attack was launched against the SHA-1 hash algorithm.


Roth's conclusions are that the SHA-1 algorithm is not fit for password hashing, and the compute power offered by cloud services makes it cheap and easy to launch brute-force attacks on passwords.


However, it's been known since 2005 that the SHA-1 algorithm has flaws, and the National Institute of Standards and Technology is seeking to replace it.


Also, undertaking a brute-force attack using the cloud can be costly.


"The cloud is certainly the fastest way to stand up many computers hammering on the same brute-force problem," Shawn Edmondson, director of product management for rPath, told TechNewsWorld."But that power doesn't come cheap."


Roth's Attack


Roth used a Cluster GPU instance from Amazon EC2. This has 22 GB of memory, two Intel Xeon X5570s using quad-core Nehalem architecture, two Nvidia Tesla Fermi M2050 GPUs and 1,690 GB of instance storage, Roth wrote in his blog.


It also offers a 64-bit platform and uses 10 gigabit Ethernet for "very high" I/O (input/output) performance, Roth said.


Using this platform, Roth claims he cracked all hashes from a file for passwords one to six characters long in 49 minutes.


However, Sophos security expert Paul Ducklin pointed out that Roth recovered 10 of 14 passwords on a challenge list while Ducklin recovered eight out of those 14 by merely using his MacBook Pro, running in the background, in the same time.


Further, Ducklin said that real-world password hashing schemes are more complex than the one used in the challenge list.


Ducklin added that the attack worked against very weak passwords used with a very weak password hashing system.


The System Roth Attacked


Roth reportedly claims that his attack can break wireless networks secured by applications using the WPA-PSK standard.


WPA stands for WiFi Protected Access. The WPA protocol implements the bulk of the IEEE 802.11i standard. However, it's not a strong protocol, as it was unveiled as an intermediate measure to replace the WEP protocol while 802.11i was being readied for release.


WEP, or Wired Equivalent Privacy, is a security algorithm for IEEE 802.11 wireless networks that was introduced as part of the original 802.11 protocol in 1997. It's relatively easy to crack and was superseded by WPA in 2003.


WPA has been replaced by WPA2, which requires testing and certification by the WiFi Alliance.


PSK stands for Pre-Shared Key Mode, which is also known as "Personal Mode." It's designed for home and small-office networks that don't require an 802.1x authentication server.


The Weakness of the Cloud?


Widespread criticism led Roth to subsequently point out that his real aim was to show how easy the new Amazon cloud cluster makes it to launch massively parallel attacks.


However, said rPath's Edmondson, "If you want to run 1,000 powerful servers 24/7 for a year on a hard computational problem, a roomful of blades is cheaper than public cloud time. So large-scale brute-force attacks still come down to resources and are well beyond the reach of most black-hat hackers. The cheapest and most illegal way is to use a black-market cloud -- namely, a botnet."


Roth told TechNewsWorld that he'll give a talk on his findings at the Black Hat conference, to be held in Washington, D.C., next week.


Clouds Can Strike Back Too


If such a hack using Amazon's cloud services did occur, the company would probably not be to blame because it would essentially be in the same position as a hotel owner if one of whose guests committed unlawful acts in his or her room.


But what can cloud service providers like Amazon do when people who rent their services do things they shouldn't?


"This poses a very interesting challenge for a public cloud provider, both in their acceptable use policy and in their self-policing," Edmonson said."But, as in the WikiLeaks example, Amazon is clearly willing to drop customers who break the policy."


Amazon kicked WikiLeaks off its servers after the site released sensitive diplomatic cables.


"Our terms of usage are clear, and we continually work to make sure the services aren't used for illegal activity," Amazon spokesperson Kay Kinton told TechNewsWorld."We take all claims of misuse of our services very seriously and investigate each one. When we find misuse, we take action quickly."


Searching for Security Salvation


Despite its flaws, SHA-1 is the most widely used SHA has function. Since then, some variants, like SHA-2, have been developed. However, they're too similar to SHA-1 algorithmically.


In 2007, NIST launched a competition to develop a new hash standard, SHA-3. The winner will be selected in 2012.


"SHA-3 is still in development," Richard Wang, manager of SophosLabs U.S., told TechNewsWorld. "NIST have not yet determined which of the candidate algorithms will become SHA-3."


Source: http://www.technewsworld.com