Google Search

Showing posts with label House. Show all posts
Showing posts with label House. Show all posts

Sunday, December 29, 2013

Security flaw with a difference - the Xerox scanner that makes your house smaller!

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Friend and former colleague Graham Cluley just drew my attention to an astonishing security problem with Xerox scanners.

I bet you it isn't the sort of problem you're thinking of, either.

You may have read "scanner insecurity" stories before, and they've probably dealt with conventional security problems.

These were probably things such as incompletely deleted data left behind on the hard disks of decommissioned scanners; poor security configuration in network-enabled scanners, such as default passwords; and exploitable vulnerabilities in image-handling code built in to scanners.

This problem is quite different.

(For all we know, this flaw may be present in other vendors' scanners, too, as it is a consequence of an algorithm chosen for compression. Xerox comes into it simply because that is the brand of scanner in the story.)

A Germam computer scientist, David Kriesel, was perusing the rooms depicted on some building plans he had scanned on a Xerox WorkCenter scanner.

He spotted an alarming anomaly: high quality errors.

That sounds odd, and it was.

Normally, when you notice scanning errors, it's because the quality is poor and the details illegible.

A room that is 15m2 on the original might looks like 1?m2 on the scanned copy, with the 5 scanned so badly it doesn't even look like a digit.

Or the 15 might be blurred, or have sufficiently many stray pixels in it, to look like an indecisive 16.

What you don't expect is that a crisply printed 21m2 on the original would be rendered as a crisply scanned 14m2, say, on the copy.

In other words, given the analog-to-digital nature of the scanning process, you'd expect imperfections, but you'd also expect the unreliable parts to look unreliable, thus making their unreliability self-documenting.

It turns out that the Xerox scanner in question was using a compression scheme called JBIG2, which emerged from the grandly-named Joint Bi-level Image Experts Group.

Bi-level images, as the name suggests, have just one bit per pixel, such as the images used in fax machines (if you remember them).

And JBIG2 has a clever, yet, with hindsight very reckless, feature: if two "swatches" of the image look like each other, the same data is used for both swatches, so that they effectively become identical.

This technique works perfectly in lossless compression, e.g. the deflate algorithm used in ZIP files, where the repeat of a string of characters such as NOTEWORTHY would be encoded as "repeat the ten characters I saw 164 bytes ago", not as another NOTEWORTHY.

But if imperfect matches were allowed, you might find NOTEWORTHY encoded as a repeat of NOT WORTHY, introducing an error that would be very hard to spot, despite the fact that the two phrases are antonyms.

The "fix", for our German computer scientist, seems to have been to use TIFF compression instead, a lossless image compression option supported by the scanner he was using.

Update: Xerox emailed us at 2013-08-10T11:15Z to point us at some official advice on the issue. In summary: JBIG2 compression isn't on by default. If you're worried someone might have changed the compression settings, a reset to factory defaults will change them back. Also, Xerox will be producing an optional patch that will prevent JBIG2 being turned on at all. (If you aren't sending faxes, you probably don't need it.)

The lesson to be learned here, other than that Graham has an excellent eye for interestingly quirky stories, is that algorithm choices are really important.

Imagine this sort of image transposition in a CCTV system that just recorded a crime.

Instead of a blurry and obviously inconclusive image of the perpetrator, which would make it obvious that evidence would have to be sought elsewhere, you might end up with a clear and convincing image of someone who just happened to look like the perpetrator.

Where security is concerned, it's not just how safely you store what you've collected, it's how reliably you collect it in the first place.

Follow @duckblog


View the original article here

Friday, December 13, 2013

White House mulls waving cash at businesses to get them to beef up cybersecurity

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The White House. Image courtesy of ShutterstockThe White House is thinking about basically bribing businesses to get them to patch leaky cybersecurity.

According to Politico, the US government is pondering, specifically, tax breaks, insurance perks and other legal benefits for businesses that do some serious overhaul of their digital defenses.

Politico recently got its hands on a May 21 presentation from the Department of Homeland Security (DHS) that raised the notion of such incentives.

The incentives aren't yet finalized.

They would be designed to entice critical infrastructure players in particular, such as power plants and water systems, to adopt voluntary standards that are now being drafted by government and industry in response to an executive order from President Barack Obama.

The standards will be hammered out by DHS and the National Institute for Standards and Technology (NIST). The bodies will be working with businesses to create a security framework that businesses will, ideally, adopt on their own volition.

Politico pointed out that the financial lures also need to be run through federal agencies, including DHS and the Treasury Department, to determine how tasty the enticements can be, either with or without the help of a Congress that has proved, unfortunately, markedly unhelpful.

The 12-page document from DHS - which Politico refrained from publishing - reportedly mulls not only financial and market benefits, but also legal benefits, including limited lawsuit protection for participating companies.

It's wonderful to hear about incentives like this, particularly if they might spur organizations into getting insurance that could help to protect them from potentially devastating costs of data breaches or other cybersecurity dangers.

As it is, insurance professionals will tell you that many, if not most, businesses mistakenly think that general liability policies will cover them in times of cybersecurity mayhem.

Such policies won't, but there are policies that will, and it's wise to learn about them and know what questions to ask about such policies to make sure an organization is as well-covered as possible.

As Politico reports, experts believe that those organizations that adopt upcoming cybersecurity standards could be well-positioned to get breaks on such insurance, being able to point to the standards as evidence that they're following best practices.

Cash. Image from ShutterstockThis is the juicy stuff that could greatly help to improve security postures.

As it is, the Homeland Security page about cybersecurity incentives is as dry as a sun-baked bone.

DHS talks about secure software engineering, security breach forensics, better training and the instillation of personal data "ownership" - all worthy, mind you, but all very blah, blah, blah.

Tasty cash, on the other hand? Much more interesting, I'd wager.

Let's hope that the Feds can get something done, with or without the help of Congress.

Follow @LisaVaas

Follow @NakedSecurity

Image of White House and bag of cash courtesy of Shutterstock.


View the original article here

Sunday, April 8, 2012

US House declines to block employers demanding Facebook passwords

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

House of Represenatives logoThe US House of Representatives on Wednesday voted down a bid to stop telecommunications companies from demanding Facebook logins from prospective job applicants.

The proposal [PDF], titled "Mind Your Own Business on Passwords," came from Rep. Ed Perlmutter, a Colorado Democrat, as the House debated over an act that aims to reform the Federal Communications Commission (FCC).

Perlmutter proposed that the bill be sent back to committee amended with a paragraph allowing the FCC to bar telecoms from requiring the logins.

V3 quoted Perlmutter as saying:

"No American should have to provide their confidential personal passwords as a condition of employment. Both users of social media and those who correspond share the expectation of privacy in their personal communications."

Many have shared his sentiment, particularly during the week following several reports of companies and government agencies who request Facebook login so that interviewers can have a look-see at anything a job applicant has marked private.

In fact, 91% of polled Naked Security readers agree that it should be illegal.

As the Associated Press noted, the legality of the practice is dubious indeed. Proposed legislation in Illinois and Maryland would forbid public agencies from asking for social network access.

Private property sign

Given that requiring Facebook logins of job applicants had nothing to do with the issue at hand, the House's refusal to amend the FCC reform bill this week does nothing to clear up the question of legality.

In fact, as CBS News's Declan McCullagh pointed out, Perlmutter's was little more than "a transparent, if clever, delaying tactic."

As McCullagh wrote, all Perlmutter had to do was suggest an amendment, not send the whole thing back to committee.

At any rate, McCullagh notes, it's not companies regulated by the FCC that are being profiled as Facebook login requesters. Rather, the anecdotes regarding login demanders have mostly sprung from the actions of law enforcement agencies, which aren't regulated by the FCC and wouldn't be affected by the bill.

CBS News quoted Rep. Greg Walden, the Oregon Republican who chairs a communications and technology subcommittee, agreed with Perlmutter that "it's awful" for employers to feel free to demand passwords and then "go snooping around."

The problem is, Perlmutter's amendment wouldn't have protected anybody, Walden said during the floor debate:

"Your amendment doesn't protect them. It doesn't do that. Actually, what this amendment does is say that all of the reforms that we are trying to put in place at the Federal Communications Commission, in order to have them have an open and transparent process where they are required to publish their rules in advance so that you can see what they're proposing, would basically be shoved aside. They could do whatever they wanted on privacy if they wanted to, and you wouldn't know it until they published their text afterward. There is no protection here."

Perlmutter's delaying tactic says more about Democrats' opposition to the Republican-backed bill to reform the FCC than it does about a sincere desire to protect Facebook users' privacy.

The bill, titled the Federal Communications Commission Process Reform Act of 2012, would require the currently Democratic-controlled agency to be more transparent and to prepare economic impact analyses.

The House rejected Perlmutter's amendment by a vote of 184 to 236. The FCC reform measure itself was approved by a vote of 247 to 174. It has not yet been approved by the Senate.

screenshot of White House statementThe White House released a statement [PDF] on Monday claiming that the GOP bill would prevent the FCC from exercising "its statutory duty to protect the public interest."

This is not about privacy. This is a sideshow, a scuffle between the parties.

The question of privacy deserves to be more than a spurious footnote used to jam the gears of an unrelated bill. Let's hope that the proposed legislation in Illinois and Maryland does the job by actually focusing on the issue at hand.

Follow @LisaVaas

Private property image courtesy of shuttershock


View the original article here

Sunday, March 4, 2012

House Panel: NASA Could Be Hackers' Next Target

Could hackers attack the International Space Station?

That’s what the House Science, Space, and Technology Subcommittee on Investigations and Oversight wants to know.

The panel will hear from NASA’s chief information officer and its inspector general at a hearing on Wednesday.

Besides basic operations like e-mail, NASA uses computer systems to control space missions like the International Space Station and the Hubble Space Telescope. And the potential for cyberattacks on those systems is growing, according to a subcommittee briefing document.

“The threat of cyberattack to agency satellite operations, mission support, and technology research is increasing in sophistication and frequency,” the document said.

In addition, NASA represents a major trove of scientific and technical knowledge that could be targeted by cyberthieves. In 2009 and 2010 the agency reported more than 5,000 incidents of malicious software or unauthorized access in its computers, according to the House panel.

“Because of NASA’s stature as an agency on the vanguard of technological progress, the tampering or corruption of scientific data from unauthorized intruders is a serious concern,” the briefing document concluded.


View the original article here