Google Search

Showing posts with label Leaks. Show all posts
Showing posts with label Leaks. Show all posts

Tuesday, November 19, 2013

Facebook leaks are a lot leakier than Facebook is letting on

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Remember last week, when Naked Security et al. told you that Facebook leaked email addresses and phone numbers for 6 million users, but that it was really kind of a modest leak, given that it's a billion-user service?

OK, scratch the "modest" part.

The researchers who originally found out that Facebook is actually creating secret dossiers for users are now saying the numbers don't quite match up.

The number of affected users Facebook noted in a posting on its security blog is far less than what they themselves found, and Facebook is also "hoarding non-user contact information - seen when it was also shared and exposed in the leak," writes ZDNet's Violet Blue.

The bug involved the exposure of contact details when using the Download Your Information (DYI) tool to access data history records, which resulted in access to an address book with contacts users hadn't provided to Facebook.

Selecting privacy settings in FacebookWhat that means is that even if you don't share details of your own personal information with Facebook, Facebook well may have gotten it through other people in your network who've let Facebook have access to their contact lists.

Facebook accidentally combined these "shadow" profiles with users' own Facebook profiles and then blurted both data sets out to people who used the DYI tool and who had some connection to the people whose data was breached.

It's understandable why Facebook users are steamed.

Facebook has gotten information you didn't choose to share, has retained it, and has inadvertently left it open for unauthorized access since at least 2012.

Some users, in fact, complained in comments that the bug persisted even after Facebook reportedly fixed it, according to Violet Blue.

Packet storm reported on Wednesday that its researchers, who had prior test data verifying the leak, were able to compare what they knew was being leaked with what Facebook reported to its users.

Packet Storm claims that Facebook didn't come clean about all the data involved.

From its posting:

"We compared Facebook email notification data to our test case data. In one case, they stated 1 additional email address was disclosed, though 4 pieces of data were actually disclosed. For another individual, they only told him about 3 out of 7 pieces of data disclosed. It would seem clear that they did not enumerate through the datasets to get an accurate total of the disclosure...

"Facebook claimed that information went unreported because they could not confirm it belonged to a given user. Facebook used its own discretion when notifying users of what data was disclosed, but there was apparently no discretion used by the 'bug' when it compiled your data. It does not appear that they will take any extra steps at this point to explain the real magnitude of the exposure and we suspect the numbers are much higher."

Not only is the extent of exposed data likely to expand, Packet Storm says, but the number of people affected is much higher than 6 million, given that Facebook has only contacted its users.

Here's how Facebook replied when Packet Storm asked about contacting non-users about the breach:

"We asked Facebook if they enumerated the information in hopes that their reporting had a bug but we were told that they only notified users if the leaked information mapped to their name.

"We asked Facebook what this means for non-Facebook-users who had their information also disclosed. The answer was simple - they were not contacted and the information was not reported. Facebook felt that if they attempted to contact non-users, it would lead to more information disclosure."

That's a "weak, circular" argument, Packet Storm complains.

To better protect users' contact and personal information, the researchers suggest that Facebook can simply adopt this suggested flow:

1. When a person uploads someone's contact information, Facebook should automatically correlate it to what they have shared on their profile (and obviously only suggest them as a friend if their settings allow it). If their settings do not allow it, they should treat it as a user not in Facebook (see #2). If the information uploaded includes data specific to an individual who does not already have that data included in their profile, Facebook should provide a notification along the lines of:

"You are attempting to add data about John Smith that he has not shared with Facebook. How do you want to handle this situation?"

Two options are provided:

A) "Ask John Smith's permission to add this information"

B) "Discard additional information"

If they choose option A, John Smith is notified by Facebook the next time he logs in and gets to decide what he wants to do with HIS data. Seems simple enough.

2. When a person uploads someone's contact information and it does not correlate to any Facebook user, they should be able to use it for the Invitation feature with the caveat that Facebook automatically deletes all data within 1 week. The invite to the person can say "this link will expire in 1 week", which it should anyways. When an individual uses the invitation link to sign up, THEY will decide what information to share with Facebook.

That does seem simple enough, but Facebook hadn't responded to the suggestion at the time of writing.

While we wait for Facebook to (maybe) fix a situation that seems far more widespread than originally reported, we can help each other out by immediately removing our imported contacts, to keep everybody's personal data out of this swamp.

If you haven't done so already, you can easily remove uploaded contacts here.

Follow @LisaVaas

Follow @NakedSecurity


View the original article here

Thursday, June 7, 2012

Yahoo leaks its own private key via new Axis Chrome extension

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Tarnished Axis logoYahoo has just released a new browser for iPad and iPhone, dubbed "Axis," along with corresponding extensions for desktop versions of Chrome, Firefox, Safari, and Internet Explorer 9.

The new browser is supposed to tightly integrate search with web browsing and has a built-in feature to synchronize one's mobile and desktop experience.

While that might interest some, there's far more interesting news for those interested in computer security.

In a move which is likely to take away some of the shine from the new product's launch, Yahoo mistakenly bundled its private key inside the Chrome extension version of Axis.

Oops.

Yahoo's private key revealed

A private key is used by a developer to sign an extension package in order to prove that the extension is actually from the developer. If a malicious third party were to obtain the private key, they would be able to release an extension signed with that developer's certificate.

In other words, any of us could write an app and fairly convincingly pretend that it was actually from Yahoo.

Nik Cubrilovic, who discovered this major error, quickly took to Twitter and then to his blog to write about his discovery (along with notifying Yahoo).

Shortly thereafter, Cubrilovic used Yahoo's own certificate to sign a forged version of the Chrome extension as a proof of concept.

Cubrilovic writes about the implications of Yahoo's inclusion of the private certificate:

"The clearest implication is that with the private certificate file and a fake extension you can create a spoofed package that captures all web traffic, including passwords, session cookies, etc. The easiest way to get this installed onto a victims machine would be to DNS spoof the update URL. The next time the extension attempts to update it will silently install and run the spoofed extension."

Yahoo has since released an updated version of the extension that removes the private key.

Now that the original private key has been leaked to the public, Yahoo has begun using a new certificate so that the old one can be revoked.

It is not entirely clear whether the Chrome browser itself can determine whether an extension has been signed with a revoked developer certificate, or how Chrome would behave in this circumstance. Cubrilovic and others plan to conduct additional tests.

If you downloaded the Yahoo Axis Chrome extension shortly after it was released, you may want to go to http://axis.yahoo.com and upgrade to the latest version.

On the other hand, it might be better to wait a few days before using Yahoo Axis to give researchers an opportunity to find additional security flaws.

Follow @theJoshMeister

View the original article here

Wednesday, January 4, 2012

Data leaks at Stratfor and Care2 mark the end of a year riddled with data theft

function utmx_section(){}function utmx(){}(function(){var k='1156989329',d=document,l=d.location,c=d.cookie;function f(n){if(c){var i=c.indexOf(n+'=');if(i>-1){var j=c.indexOf(';',i);return escape(c.substring(i+n.length+1,j')})();Data leaks at Stratfor and Care2 mark the end of a year riddled with data theft | Naked Security /* */

Sorry, something happened and we couldn't sign you up. Please come back later and try again.

Congratulations, you've successfully signed up for our daily news! Check your inbox soon, we've sent you an email.

Sorry, that email doesn't look right to us so we haven't added it to our list.

We're adding your address to our list...

Join thousands of others, and sign-up for Naked Security's newsletter

Antivirus and Security Software from SophosGlobal websites    Press    About us    Contact us Naked SecuritySkip to contentSearch for:

Archive by date |author |category

Send us a tip | Subscribe by RSS

Follow us on TwitterJoin us on FacebookCheck out the SophosLabs YouTube channelConnect with us on LinkedInMalwareSpamSocial networksData lossLaw & OrderApplePodcastVideoMoreAbout Most Wi-Fi routers susceptible to hacking through security featureData leaks at Stratfor and Care2 mark the end of a year riddled with data theft

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Don't forget you can subscribe to the SophosLabs YouTube channel to find all our latest videos.

Hi there! If you're new here, you might want to subscribe to our RSS feed for updates.

Already using Google+? Follow Naked Security's Graham Cluley for the latest security news.

On LinkedIn? Join the Naked Security discussion group and connect with your peers in the security industry.

Sorry, something happened and we couldn't sign you up. Please come back later and try again.

Congratulations, you've successfully signed up for our daily news! Check your inbox soon, we've sent you an email.

Sorry, that email doesn't look right to us so we haven't added it to our list.

We're adding your address to our list...

Join thousands of others, and sign-up for Naked Security's newsletter

by Chester Wisniewski on December 30, 2011|1185982 Commentshttp%3A%2F%2Fnakedsecurity.sophos.com%2F2011%2F12%2F30%2Fdata-leaks-at-stratfor-and-care2-mark-the-end-of-a-year-riddled-with-data-theft%2FData+leaks+at+Stratfor+and+Care2+mark+the+end+of+a+year+riddled+with+data+theft2011-12-30+22%3A35%3A43Chester+Wisniewskihttp%3A%2F%2Fnakedsecurity.sophos.com%2F%3Fp%3D118598

Filed Under: Data loss, Featured, Podcast, Privacy

2012 aheadWas 2011 the year of the data leak? Could be, but it is hard to tell.

From my vantage point writing daily about the most important stories in information security, data theft may not have been the most important story of 2011, but it certainly impacted more regular people and raised their awareness about the problem of all of their data being "in the cloud".

I shared my thoughts on this today with John Moe on Marketplace Tech Report from American Public Media in the United States.

Marketplace logoYou can listen to my thoughts on 2011 alongside John Moe, Jonathan Zittrain, Susan Crawford and Danah Boyd in this four minute podcast.


(30 December 2011, duration 4:00 minutes, size 1.9 MBytes)

While Anonymous/LulzSec dominated the data breach headlines, what became clear was that more and more organizations are collecting data about us and doing a poor job of protecting that information.

Compliance rules like HIPPA/HITECH, PCI and others are not really having their intended impact as health records, credit cards, passwords, birth dates and more were all stored insecurely on often woefully unpatched systems.

Datalossdb.org logoThe number of records stolen was enormous. Sony alone was hacked more than 20 times and lost over 100 million records.

The bulk email marketing company Epsilon leaked names and email addresses from some of the world's most trusted brands like Best Buy, Marks & Spencer, Marriott Rewards, Walgreens and Chase Bank.

South Korean social media users were hit hard when Cyworld and Nate were compromised (both owned by SK Communications) and hackers made off with more than 35 million records.

Like video games that aren't related to Sony? Chances are your data was leaked when the Steam user forums were breached or when Square Enix was hit twice in 2011.

Citibank credit cardCitibank credit cards users had card information compromised affecting more than 200,000 people as well as customers of handmade cosmetics company Lush.

Of course the biggest story at the end of 2011, wrapping up the year of unsecured data has been the attack Anonymous made on Stratfor.

Stratfor, a company focused on security intelligence services, was attacked by Anonymous who have allegedly acquired 75,000 addresses, credit cards and names of their customers and then posted them publicly.

Sadly it seems companies still aren't learning the lesson of protecting their customers information, even after all of these headlines and millions of dollars in lost reputation to the companies involved.

It was brought to my attention that Care2.com's website was hacked revealing usernames and passwords for the sites nearly 18 million users.

Naked Security reader Bob emailed us to point out that Care2 is storing passwords insecurely.

Care2 logoRather than storing passwords as a salted cryptographic hash that would not reveal their customers passwords if stolen (or make it much more difficult) they are storing them either in plaintext or in a reversible format.

According to the companies own FAQ about the data breach "Q. What can I do to recover my password?
A. Visit http://www.care2.com/retrieve_password Enter your user name or email address in the green box titled “Forgot your password or log-in name?” Your password will be emailed to you."

Care2 FAQ

Really!? After the attackers made off with all of your customer information you still are following the same insecure practices that put your customers information at risk in the first place?

Where does this leave us? Think carefully about who you share personal information with, and before doing so carefully weigh whether they need that information or not.

And for the sake of all of your digital presence use unique passwords for every site you access. There are great tools to help you like Keepass or LastPass.

To quote American folk singer Pete Seeger "When will they ever learn? When will they ever learn?".

Follow @chetwisniewski

Tags: 2011, Care2, Citibank, Cyworld, DataLossDB, epsilon, Marketplace, passwords, Sony, Square Enix, Steam, Stratfor

Most Wi-Fi routers susceptible to hacking through security featureRelated PostsGuest blog: Ten tips for protecting sensitive data in your organisationTen tips for protecting sensitive data in your organisationHandcuffedDrive250What can you learn from the deluge of data leakage news?BP in troubled waters over Gulf oil spill data spillBP in troubled waters over Gulf oil spill data spillImage (1) hannaford.jpg for post 14780Three men charged in 130 million credit card identity theft2 Responses to Data leaks at Stratfor and Care2 mark the end of a year riddled with data theftJon W says:December 30, 2011 at 11:17 pm

Dear care2:
Instead of emailing our passwords back, why not just post a list of the email addresses & passwords on Facebook and we'll just pick out some to use...?

Replyjessi slaughter says:December 31, 2011 at 4:18 am

dropping the pete seeger reference in a stratfor story! well done chet, have a very happy new years!

ReplyLeave a Reply Cancel replyYour email address will not be published. Required fields are marked *

Name *

Email *

Website

Comment

You may use these HTML tags and attributes:
       

Notify me of follow-up comments via email.

About the authorChester Wisniewski is a Senior Security Advisor at Sophos Canada. He provides advice and insight into the latest threats for security and IT professionals with the goal of providing clear guidance on complex topics.You can follow Chester on Twitter as @chetwisniewski or send him an email at chesterw@sophos.com.View all posts by Chester WisniewskiPopularRecentRelatedTimHortons250Free coffee from Starbucks and Tim Hortons? No, it's a Facebook scamFacebook's ticker privacy scareFacebook's ticker privacy scare, and what you should do about itWant to see who has viewed your Facebook profile? Take care..Want to see who has viewed your Facebook profile? Take care..WiFiAllianceLogo250Most Wi-Fi routers susceptible to hacking through security featureFree Costco Gift Card for all Facebook users? Scam spreads quicklyFree Costco Gift Card for all Facebook users? Scam spreads quicklyiStock2012ahead250Data leaks at Stratfor and Care2 mark the end of a year riddled with data theftWiFiAllianceLogo250Most Wi-Fi routers susceptible to hacking through security featureno-30-dec-250Samoa moves to the other side of the world - and misses a day!HMRC250logoHMRC phishing scam promises end of year refund28c3logoLarge percentage of websites vulnerable to HashDoS denial of service attackGuest blog: Ten tips for protecting sensitive data in your organisationTen tips for protecting sensitive data in your organisationHandcuffedDrive250What can you learn from the deluge of data leakage news?BP in troubled waters over Gulf oil spill data spillBP in troubled waters over Gulf oil spill data spillImage (1) hannaford.jpg for post 14780Three men charged in 130 million credit card identity theftVideo posts

More videos this way

dragon-video-250VIDEO: How to solve the #dragontattoo #sophospuzzleTyposquatting - study reveals the real risks when you mistype a website's name [VIDEO]Typosquatting - study reveals the real risks when you mistype a website's name [VIDEO]laptop_250Identify your missing security patches this Christmasfb-stumble-video-250VIDEO: Awkward! Facebook VP stumped by BBC question60ss-20111128-250IHC, Mac malware, Nerd New Year, Conficker and Privacy à la Google - 60 Sec SecurityTwitter Feedgcluley: Facebook distributing White Hat Debit Card to Bug Bounty Winners http://t.co/MToOc2gmabout 1 hour agogcluley: Which passwords should you share with your girlfriend? http://t.co/AR8zNYoX Some interesting responses..about 4 hours agogcluley: Anonymous imposters: hiding behind the AntiSec identity http://t.co/VxaK2lOUabout 4 hours agogcluley: Hackers may have accessed Gordon Brown's emails http://t.co/czvtbH2Yabout 6 hours ago
© 1997-2012 Sophos Ltd. All rights reservedLegalPrivacyJobsRSSutmx_section("Test trigger")jQuery(document).ready(function($){ Gravatar.profile_cb = function( h, d ) { WPGroHo.syncProfileData( h, d );}; Gravatar.my_hash = WPGroHo.my_hash; Gravatar.init( 'body', '#wpadminbar' ); });

View the original article here

Wednesday, October 26, 2011

Anonymous Takes Down Massive Child Pornography Server, Leaks User Names - Geekosystem

In a move that we can all get behind, hacker group Anonymous has announced that they have taken down a huge cache of child pornography and released 1,589 usernames of the website’s patrons. The action came as part of Operation Darknet, which targets illicit websites that are part of an unindexed and therefore unsearchable corner of the Internet.

The server in question is owned by Freedom Hosting, and apparently services over 40 child pornography websites. The largest of these, disturbingly called Lolita City, was said to contain over 100gb of child pornography.

Interestingly, the Anonymous hack is extremely well documented. In two separate Pastebin posts, the hackers involved provide a timeline of events, as well as some of the methodologies they used in tracking and taking down the servers.

According to their timeline, the hackers first became aware of Lolita City while leading a related campaign against a portion of the Hidden Wiki which included links to child pornography. While working to suppress the Hidden Wiki for linking to child pornography, the group turned their attentions to the websites linked on the Wiki. Through their investigations, they discovered that many of the sites shared a similar “fingerprint” in that they were supported and hosted by a company called Freedom Hosting.

The group then issued an ultimatum to Freedom Hosting to remove the content, or be shut down through their attacks. Freedom Hosting refused, and has since been the target of the hacker’s ire.

While attacks by the hacker group have often been divisive, going after the supporters of child pornography is something that is hard to criticize. In fact, this might be the best application of the groups’ talents; an intersection of Internet knowledge and the ability to carry out electronic attacks. Of course, preventing child pornography from being moved around the Internet doesn’t stop the predators that created the materials. Hopefully, law enforcement will take up the information gleaned by the group and start making some arrests.

(via Security News Daily, Examiner)

Relevant to your interests


View the original article here