Google Search

Showing posts with label blames. Show all posts
Showing posts with label blames. Show all posts

Tuesday, April 16, 2013

Facebook owns up - admits network breached, blames "Java in the browser"

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

There's a scene in the movie The Social Network where Mark Zuckerberg is arguing with Eduardo, his CFO.

Eduardo's just frozen Facebook's bank account.

The plan is to get Zuckerberg's attention and to try to get Zuck back on what Eduardo thinks is the straight and narrow.

But Zuckerberg is irate.

He thinks it might end up with an unpaid bill and thus a network outage, and that won't do!

Zuck rants:

Let me tell you the difference between Facebook and everybody else: WE DON'T CRASH EVER!

It's only a movie, of course.

In real life it's not true that Facebook never goes down, but when you consider its size and the online activity it supports, Facebook's uptime and availability is astonishing. Stellar. Intergalactic, even.

The movie version of Zuckerberg goes on to explain:

If the servers are down for even a day, our entire reputation is irreversibly destroyed. Users are fickle... Even a few people leaving would reverberate through the entire user base.

But what about getting owned by hackers?

What effect do you think that might have?

If you're the world's biggest social network, and if collecting, storing and using other people's personal information is your bread and butter?

Hold your horses, because we're about to find out.

Facebook just published an article entitled Protecting People On Facebook, and it doesn't cover what you might at first expect when you see the title.

Sure, it starts upbeat enough:

Facebook, like every significant internet service, is frequently targeted by those who want to disrupt or access our data and infrastructure. As such, we invest heavily in preventing, detecting, and responding to threats that target our infrastructure, and we never stop working to protect the people who use our service.

But that's followed by a hint of what's coming next:

The vast majority of the time, we are successful in preventing harm before it happens, and our security team works to quickly and effectively investigate and stop abuse.

And then the bombshell. OK, not really a bombshell. Let's be fair and say it's actually a pretty candid admission for which the company deserves at least a nod of respect:

Last month, Facebook Security discovered that our systems had been targeted in a sophisticated attack. This attack occurred when a handful of employees visited a mobile developer website that was compromised. The compromised website hosted an exploit which then allowed malware to be installed on these employee laptops.

Later on in the article, Facebook claims that it has "found no evidence that Facebook user data was compromised," and and for what it's worth, I'm willing to accept that claim.

? Update. In an interview with Ars Technica, Facebook CSO Joe Sullivan has admitted that the crooks made off with information from the laptops themselves. ("What you typically find on an engineer's laptop, including corporate data, e-mail, and some software code.") But despite being able to get "some limited visibility" into Facebook's production systems, Sullivan confirmed that a forensic review found no evidence that the crooks got away with any data off those systems. Close, in a word, but no cigar. (Added 2013-02-16T22:11Z)

The crooks had a Java zero-day at their disposal, and this exploit let them infiltrate Facebook's network and inject malware.

But the company says it was fully patched and anti-virused, and it sounds as though the malware that followed the exploit was quickly spotted and cleaned up, with no lasting harm done.

Just one suggestion to Facebook developers: why not read Naked Security?

We've given you loads of good reasons to turn off Java in your browser, starting from the middle of last year.

That alone could have side-stepped this problem.

Even just using a browser with click-to-play (so that Java and Flash applets, amongst others, can't launch quietly in the background from compromised websites) would surely have been enough.

I'm guessing now, but I'd be very surprised if the mobile developer website alluded to above actually required Java, so there would have been no reason to have Java turned on for that site.

Similarly, the mobile developer website could have considered using outbound web or packet filtering to block the egress of Java applets if, indeed, its site was never supposed to serve them up in the first place.

? IPS technology is usually thought of as a way to keep bad guys out, not least because it stands for intrusion prevention system. But most decent IPSes work bidirectionally, and can act as effective EPSes, or exfiltration preventers, too. You filter email for spam both ways (don't you?), because you can, and because it makes sense. The same applies with network traffic in general. If the bad guys have already got in, you may as well stop them getting back out as well!

Having said all that, it remains for me to ask. You have turned off Java in your browser, haven't you?

If not, here you are: How to turn off Java in your browser.

And fear not that you will break JavaScript: Java is not JavaScript.

Follow @duckblog


View the original article here

Tuesday, July 12, 2011

Rupert Murdoch set for UK as Rebekah Brooks blames 'betrayal' by hackers - Herald Scotland

REBEKAH Brooks, News International’s chief executive, last night claimed she had been “betrayed” by the News of the World phone hackers as her boss Rupert Murdoch announced he will fly into the UK today to deal with the growing crisis.

The former editor of the tabloid newspaper revealed her anger in a meeting with staff who will lose their jobs after the last edition is published tomorrow.

Ms Brooks, who is expected to hold crisis meetings with Mr Murdoch today, told workers: “I’m just as sorry as you are that people we trusted let us down, and that’s the case. If being betrayed is a resignation issue then maybe I’ve read it wrong, but I think I’m much more useful leading this company through this.”

She hinted that further revelations were to come in the hacking scandal and they would understand “in a year” why Britain’s biggest-selling Sunday newspaper had to close.

It came as the Crown Office called on Strathclyde Police to examine claims of phone hacking in Scotland, which could involve up to 1000 News of the World victims.

At News International’s London headquarters, Ms Brooks told staff the newspaper was forced out of business because advertisers saw the brand as toxic. She told staff she had “visibility” on revelations to come and “in a year you will understand why this decision was taken”.

However, James Murdoch, the company’s chairman, has stripped Ms Brooks of her role leading its internal investigation, which will now be done by other senior managers.

Last night, News International denied reports a senior executive had shredded “massive quantities” of emails.

Meanwhile, Andy Coulson, 43, the former News of The World editor, was released from police custody after being arrested nine hours earlier over allegations of phone hacking and payments to police officers.

Prime Minister David Cameron’s ex-director of communications left Lewisham police station, in south-east London, on bail amid a media scrum, saying: “There is an awful lot I would like to say but I can’t at this time.”

Clive Goodman, 53, the former News of the World royal editor, who was jailed over the scandal, was also arrested and bailed over alleged police bribery.

A 63-year-old man was last night arrested and is being held on suspicion of corruption.

It was claimed yesterday a News International executive deleted a huge number of emails from an archive believed to contain evidence crucial to the police’s phone hacking inquiry.

The file is believed to stretch back to 1995 and includes details of correspondence between News of the World staff and freelance workers, including private investigators.

A source close to the Metropolitan Police inquiry was reported as saying “massive quantities” of emails were related from the archive on two occasions.

Investigators are believed to know who is responsible for the deletions after following an electronic paper trail and the Crown Prosecution Service is understood to be deciding whether to charge the executive with perverting the course of justice.

A News International spokeswoman said: “This assertion is rubbish. We adopted a documented email retention policy in line with our US parent’s records management policy. We are co-operating actively with police and have not destroyed evidence.”

After, Ed Miliband, the Labour leader, again denounced the Prime Minister for an “appalling error of judgment” in appointing Mr Coulson. Mr Cameron refused to apologise but said he took “full responsibility” for the appointment.

Making clear he wanted to give his “friend” a “second chance”. The Prime Minister admitted it had not worked out because of the relentless attention on his spin doctor.

Mr Cameron said he had had background checks done on Mr Coulson but when pressed about warnings allegedly given to him by editors, the Prime Minister said he could not recall them.

Later, a No 10 source denied Mr Cameron was warned directly about Mr Coulson. There had been a telephone conversation in November 2009 between Alan Rusbridger, editor of The Guardian, and Steve Hilton, the PM’s aide, but “nothing specific” was mentioned in relation to the ex-tabloid editor and “nothing was passed on” to the PM.

Mr Cameron told journalists he wanted to “get to the bottom” of the phone hacking scandal and agreed a judge should lead the public inquiry.

Ian Bell: Page 15

Leader comment: Page 16

Letters special: Page 16


View the original article here