Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, September 15, 2011

Understanding the security story of the year: “Iranian” hack attack on SSL

Last week's attack on Dutch certificate authority DigiNotar completely blew my attempt to avoid the Internet while I was on holidays: it seemed like enormously important news, but of such a highly technical bent that none of the traditional nonspecialist media could coherently discuss it.

In short, one of the companies that is authorized to create SSL certificates that your browser trusts -- the certificates that let you make trusted, private connections to your bank, your Gmail, your government -- was terminally compromised. The most likely culprit is a boastful "Iranian hacker" who claims to be a patriot who compromised the CA in order to allow the Iranian government to forge certs from Gmail and other companies to facilitate spying on dissidents.

Now, Electronic Frontier Foundation staffers Eva Galperin, Seth Schoen and Peter Eckersley have written a timely postmortem on the attack, explaining what's known, what's speculated, the risk it presents to you, and what you can do to make yourself safer now and in the future. This is the kind of analysis I was hoping for when I interrupted my net.fast last week -- it's pretty crucial stuff to know.

SSL certificates are the glue that holds the encrypted portions of the Internet together — they are how your browser knows that the website you visit is the website you intended to visit. The official report on the attacks from Fox-IT includes data from DigiNotar that suggests that over 300,000 (primarily Iranian) Internet users may have been had their communications intercepted, but the danger to Internet users extends well beyond Iran.

The problem we face with Certificate Authorities is not just that there are particular vulnerabilites in any one CA. Rather, the massive structural crisis is that, as the SSL Observatory has shown, there are many hundreds of certificate authorities and an attacker only needs to break into one of those order to start issuing fraudulent certificates. Furthermore, these CAs appear to exist within around fifty countries' jurisdictions. Any one of these countries could conceivably compel a CA to create fraudulent certificates for purposes of espionage or for spying on that country's citizens. The DigiNotar hack has merely underlined how fragile the certificate authority system really is. Anyone who values the privacy and security of their communications and financial transactions online should take steps to protect themselves.

Statements have appeared strongly suggesting that the DigiNotar attacker is the same person who attacked Comodo earlier this year. The Tor Project has published extensive updates on the scope of the attack, including the list of the 531 fraudulent certificates issued by DigiNotar. This list shows that the attacker was prepared to facilitate spying against many major Internet sites. The attacker claims to be an individual Iranian who has chosen to help the government monitor individuals' communications. Additionally, he claims to have compromised four additional as-yet-unspecified certificate authorities. If true, the Iranian government may still have the power to forge new certificates in the name of these other authorities.

A Post Mortem on the Iranian DigiNotar Attack

View the original article here


This post was made using the Auto Blogging Software from WebMagnates.org This line will not appear when posts are made after activating the software to full version.

Sunday, August 28, 2011

Flying While Black and Reading Antique Aviation Books lands folk musician in Security Theater Hell

Via the ACLU and the Boston Globe, a first-hand account of how "security theater" makes us no safer, and a lot less free.

Massachussetts-based folk musician Vance Gilbert (Twitter), a law-abiding citizen who is black, 6 feet tall, and loves poodles, was harassed and humiliated on a flight out of Boston—apparently in part because he was reading book about old-time airplanes.

The TSA scanners and screeners had no problem with him. His problems began after he boarded his United Airlines flight, and appear to have been the work of the flight crew.

Here is his account, shared with the ACLU. He titled it "Racial Profiling First Hand," and signs the essay, "Flying While Black & Reading Antique Aviation Books." Snip:

Policeman: "Did you have a problem with your bag earlier?"

Me: "No sir, not at all. The flight attendant wanted it secured elsewhere other than behind my feet, and I opted to put it under the seat in front of me. It's my wallet, even though there's only 30 bucks in it…And all that was done without belligerence, or words for that matter…it was all good. A few beats...

Policeman: "Sir, were you looking at a book of airplanes?"

Me: "Yes sir I was. I am a musician for money, but for fun I study old aircraft and build models of them, and the book I was reading was of Polish Aircraft from 1946."

Policeman: "Would you please go get that book so that i can see it?"

I go back onto the plane - all eyes are on me like I was a common criminal. Total humiliation part 2. After a couple of minutes he says, "Why, this is all Snoopy Red Baron stuff..."

Me: "Yes sir, actually the triplane you see is Italian, from 1921 a little after World War 1..."

"Racial Profiling First Hand" (boston.com, via @lizditz)

Vance Gilbert's music is pretty great. You can buy it and support the guy here.

The ACLU is pretty great, too, and you can support them here.

Related: this Boston Globe item, "Musician ‘humiliated’ on flight." James Fallows wrote about Gilbert's ordeal in The Atlantic.


View the original article here


This post was made using the Auto Blogging Software from WebMagnates.org This line will not appear when posts are made after activating the software to full version.

Saturday, August 27, 2011

Security researchers trace RSA hack and SecureID breach to lame Excel spreadsheet phishing

F-Secure found the file that was used to hack RSA and compromise the SecureID system. Kim Zetter of Wired News has more here.

This week Finnish security company F-Secure discovered that the file had been under their noses all along. Someone — the company assumes it was an employee of RSA or its parent firm, EMC — had uploaded the malware to an online virus scanning site back on March 19, a little over two weeks after RSA is believed to have been breached on March 3. The online scanner, VirusTotal, shares malware samples it receives with security vendors and malware researchers.

RSA had already revealed that it had been breached after attackers sent two different targeted phishing e-mails to four workers at its parent company EMC. The e-mails contained a malicious attachment that was identified in the subject line as “2011 Recruitment plan.xls.”

None of the recipients were people who would normally be considered high-profile or high-value targets, such as an executive or an IT administrator with special network privileges. But that didn’t matter. When one of the four recipients clicked on the attachment, the attachment used a zero-day exploit targeting a vulnerability in Adobe Flash to drop another malicious file — a backdoor — onto the recipient’s desktop computer. This gave the attackers a foothold to burrow farther into the network and gain the access they needed.


View the original article here


This post was made using the Auto Blogging Software from WebMagnates.org This line will not appear when posts are made after activating the software to full version.