Google Search

Showing posts with label Science. Show all posts
Showing posts with label Science. Show all posts

Thursday, October 17, 2013

Biostamps - freedom from password tyranny, or Hollywood science?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Biostamp, courtesy of MC10Last week Motorola execs showed off experimental biostamps - digital "tattoos" capable of authenticating you to your phone.

Could this be the ultimate solution to the problem of authentication, or is it just a sci-fi pipe dream?

The biostamps are basically flexible electronic circuits attached to the skin, which theoretically can communicate wirelessly with any device which needs to check who you are.

The concept evolved from medical research, and was picked up by Google subsidiary Motorola Mobility, who are looking into making it a reality.

An alternative option, also presented by their bosses at the recent Wall Street Journal D11 conference, is a pill which emits identifying signals from the stomach.

The problem of identity is the biggest headache in computer security. Verifying you are who you say you are is at the heart of most security issues, and being able to pose as someone else - to their bank, say, or to their email or social networking provider - is the main aim of the vast bulk of malware and cybercrime.

What's needed is an end to the weak, clunky and decrepit authentication system on which we base most of our security - passwords.

With the speed modern computers can process guesses, and humanity's apparently incurable lack of originality, their usefulness has reached an end.

So what should we do instead?

Two-factor authentication is much in the headlines lately.

Most of us carry some sort of mobile device, so why not use it to prove who we are? In combination with a traditional password, that should make things much more secure.

Nice idea, as far as it goes. But still clunky and awkward.

It relies on you having your device handy, and requires you to faff around consulting it and feeding in complicated codes between devices. Also, not all that secure, as man-in-the-middle attacks have proven.

So a way of uniquely identifying a person, simply and automatically with minimal mental effort, could be a great step forward.

Fingerprints seem like the obvious option, but the laptop I'm typing on has an alleged fingerprint reader, and I seem to be able to pass its test with my elbow, while my finger is completely ignored. Effective contact-less authentication without moving a muscle seems far better.

But are these "electronic tattoos" or swallowable dongles really viable? And if they are, are they really the right way to go?

Hand bar code, courtesy of ShutterstockThey sound like something from a sci-fi movie, but in the past reality has caught up with some pretty wild ideas from the sci-fi world.

The first problem with Motorola's ideas as they are is that they are temporary.

These biostamps apparently last only a couple of weeks, while the pill version might last longer but would eventually be, ahem, ejected.

So they'd need to be replaced. You wouldn't want to go too long without your ID, so you'd maybe keep a stash of pills/stamps handy, in your wallet say, or beside the bed.

Bad move. Get your wallet stolen or your house burgled, suddenly your 100% verifiable identity's been shared with the whole black market.

An alternative would be to have the things built on-the-fly and dispensed by a dependable source. Maybe a machine in the street, which you would authenticate yourself to using the last dregs of power in your previous patch or pill.

The dispenser and the process of creating the dingus would have to be pretty hack-proof though, which has proven to be beyond humanity's abilities so far.

Longer term you might think it would be good just to have a permanent implant, put in at birth. Now we're really hitting sci-fi territory - Hollywood loves a nice implant.

As things develop you could maybe include some storage in there too, at first just a handy flash drive for moving your files around but further ahead perhaps backing up your memories to save space in your brain.

Beyond the obvious civil liberties problems, there are religious issues with such body modifications.

And of course there will always be slow adopters. In any decent dystopia there has to be an underground resistance movement of course, but they can usually be overcome with a tough regime of drugs and brutally enforced compliance.

Heart rate, courtesy of ShutterstockNext up, you'd need the thing to know you were alive, and ideally awake. The pills are powered by stomach acid, so should die when they leave the body.

Hopefully they would have some controls to prevent them being rinsed off and rebooted.

With the stamps though, you wouldn't want a bad guy tearing it off or, even worse, removing whatever body part it's attached to and taking that to the nearest ATM.

The biostamps are based on a design meant for health monitoring anyway, so that shouldn't be a problem. Where it gets difficult is if the health monitoring goes too far and starts trying to guess when you're going to die.

From there it's only a short step to controlling how long you deserve to live.

Knowing you're awake is important so that you couldn't be doped or knocked out and used as a snoozy key to your house/phone/bank account etc. Detecting consciousness is likely to be fairly viable, but really you'd want the thing to know that you actually want to be identified, to avoid brush-past ID theft.

This issue exists with current contact-less bank cards, but there it can be overcome with simple signal-blocking wallets.

To do it with built-in kit we're looking at mind-reading, which I'm sure the big search providers and social network sites would love a piece of.

It wouldn't take long to start seeing adverts beamed straight into the brain.

Things look pretty bleak for the biostamp then. A fun idea, but probably not a viable solution to the authentication problem.

It looks like we're going to be stuck with passwords for a while at least, so make sure you practice safe password management.

And keep watching the skies!

Follow @virusbtn
Follow @NakedSecurity

Image of hand bar code and vital signs courtesy of Shutterstock.
Image of biostamp courtesy of MC10.


View the original article here

Friday, March 8, 2013

Computer science student first praised, then expelled for poking around

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Computer science student first praised, then expelled for poking around. Image from ShutterstockA computer science student has been expelled from Montreal's Dawson College for poking at what he calls "sloppy coding" in the college's software - sloppiness that compromised the security of more than 250,000 students' personal data.

According to the National Post, the student, 20-year-old Ahmed Al-Khabaz, had been working on a mobile app that would have allowed students easier access to their college accounts.

Al-Khabaz and a colleague - Ovidiu Mija - discovered the flaw in the college's Omnivox Portal software.

Omnivox Portal, made by Skytech Communications, is advertised as a hub for all internal communications at educational institutions.

Al-Khabaz, a member of the school's software development club, told the National Post that a security hole in the portal software allowed "anyone with a basic knowledge of computers" to gain access to all information a college has on a student, including social insurance number, home address, phone number, and class schedule.

Al-Khabaz said he felt morally obligated to report the problem, not knowing that his actions would be negatively construed:

"I saw a flaw which left the personal information of thousands of students, including myself, vulnerable... I felt I had a moral duty to bring it to the attention of the college and help to fix it, which I did. I could have easily hidden my identity behind a proxy. I chose not to because I didn’t think I was doing anything wrong."

In fact, Dawson College initially gave the pair a pat on the back for their initial code-poking.

Dawson College Director of Information Services and Technology François Paradis met with the two on October 24th, congratulating them for their work and promising that he and Skytech would fix the problem immediately.

Two days later, Al-Khabaz decided to check whether the software had in fact been fixed.

He used a web vulnerability scanner called Acunetix. Within minutes, he told the National Post, Skytech President Edouard Taza rang him up and accused him of launching a cyber attack:

"He said that this was the second time they had seen me in their logs, and what I was doing was a cyber attack. I apologized, repeatedly, and explained that I was one of the people who discovered the vulnerability earlier that week and was just testing to make sure it was fixed. He told me that I could go to jail for six to twelve months for what I had just done and if I didn't agree to meet with him and sign a non-disclosure agreement he was going to call the RCMP and have me arrested. So I signed the agreement."

Taza, while acknowledging that he mentioned police and legal consequences, denied making threats:

"All software companies, even Google or Microsoft, have bugs in their software... These two students discovered a very clever security flaw, which could be exploited. We acted immediately to fix the problem, and were able to do so before anyone could use it to access private information."

But while the initial flaw report was welcome, Taza said, subsequently using the vulnerability scanner was a no-no:

"This type of software should never be used without prior permission of the system administrator, because it can cause a system to crash. [Al-Khabaz] should have known better than to use it without permission, but it is very clear to me that there was no malicious intent. He simply made a mistake."

The college deemed it far more serious than just an honest mistake. The college's professors voted, 14 to one, to expel Al-Khabaz for what they called a "serious professional conduct issue."

Al-Khabaz deems his academic career "completely ruined."

He said:

"I was acing all of my classes, but now I have zeros across the board. I can’t get into any other college because of these grades, and my permanent record shows that I was expelled for unprofessional conduct. I really want this degree, and now I won’t be able to get it. My academic career is completely ruined. In the wrong hands, this breach could have caused a disaster. Students could have been stalked, had their identities stolen, their lockers opened and who knows what else. I found a serious problem, and tried to help fix it. For that I was expelled."

Was Al-Khabaz in the wrong to have scanned for vulnerabilities? Even if he did it without malice?

White cowboy hat. Image from ShutterstockUnfortunately, the answer is yes. Automated tools can crash systems or worse, as security researcher Jeremiah Grossman notes in this article on how vulnerability scanners can harm sites.

White-hat hacking requires authorization - otherwise, it's illegal.

Was the college overzealous in the punishment?

It depends. How well did their instructors get across the lesson that using such tools can do harm and is illegal unless authorized? Do they include it in their coursework?

If not, then college administrators should take their share of blame in this incident and include such material in the curriculum, post haste.

If tutelage in the proper use of vulnerability scanners has in fact been included in the curriculum, then Al-Khabaz's conduct was unprofessional.

Whether it was unprofessional to the point of expulsion and career-ruining, well, geez, I don't know about that.

Administrators could have, at least, allowed the student to air his side of the story - which, apparently, they did not, denying his appeal.

Commenters on coverage of the story have expressed a desire to hire the young man. Hopefully, this won't be a career-stopper for him.

Hopefully, his tale will bring attention to the nuances of using these automated tools.

Like Uncle Ben said to Peter Parker, with great power comes great responsibility. Let's hope educational venues aren't shirking their duty to teach students what that responsibility looks like.

Follow @LisaVaas
Follow @NakedSecurity

Rusty lock
and white cowboy hat images from Shutterstock.


View the original article here

Wednesday, July 13, 2011

Hackers hit Washington Post, expose 1.2 million accounts - Christian Science Monitor

An unknown group of hackers hit the jobs section of the Washington Post website last week, making away with the personal information of more than 1.2 million users. In a FAQ posted this afternoon, reps for the Post sought to play down the extent of the hack, assuring users that the worst that they will probably weather is a series of spam emails, which should obviously be ignored (the spam emails, not the FAQ).

Skip to next paragraph

"[Y]ou should be aware that you may receive some unsolicited e-mail (spam) as a result of this incident," Post exec Beth Diaz wrote in a letter to users. "As a general matter, you should always avoid opening suspicious or unsolicited e-mail, never respond to or click any links in spam, and avoid providing personal or financial information in an e-mail – especially credit card information, bank account information, passwords, and ID numbers."

Still, this isn't particularly great news for the Post, or for other newspapers, which typically require online readers to fork over a small amount of personal information – usually an email address and name, and sometimes more – before registering on the site. Readers like to trust that that personal information will be kept safe, not left exposed to marauding groups of hackers, whomever those marauding groups of hackers may be.

Speaking of which: Is it possible, as Kyle Wagner coyly hints over at Gizmodo, that the Washington Post attack could be the work of Anonymous or any of the other members of the AntiSec campaign? Horizons readers will remember that Anonymous has been very active in recent weeks, hitting the online home of the Arizona Police Department, among other targets.

Answer: Sure, it's possible that Anonymous is behind the attack. It fits the bill for AntiSec, which has typically targeted large governmental and media outposts. But then again, no one has yet claimed credit for the attack, and claiming credit is something that Anonymous likes to do. Stay tuned for more.


View the original article here