Google Search

Showing posts with label breach. Show all posts
Showing posts with label breach. Show all posts

Saturday, December 7, 2013

Data Breach Week, SIMs cracked, carders busted - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

How safe is the SIM in your mobile phone? Could it be remotely infected with malware?

Possibly - watch this week's 60 Second Security and find out more!

? Can't view the video on this page? Watch directly from YouTube. Can't hear the audio? Click on the Captions icon for closed captions.

It feels like we just had "Data Breach week", with Apple's Developer Center, Ubuntu Forums, Lakeland and even Stanford University having "better change your password" moments.Crypto researcher Karsten Nohl claims he's found a way to recover remotely the secret key buried in older SIM cards, so he can sign any code he wants and put it on your phone.Five sidekicks of notorious TJ Maxx hacker Albert Gonzalez, currently serving 20 years, have been charged with carding crimes in New Jeresy and New York.

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Apple, balic, Blackhat, bust, Cryptography, data breach, DES, developer center, FBI, Gonzalez, karsten nohl, Lakeland, nohl, salt, SIM, Stanford, TJ Maxx, Ubuntu, university


View the original article here

Wednesday, November 20, 2013

Facebook leak, Canadian spam, Opera breach - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

It's Saturday, and that means 60 Second Security, where we aim to touch on some of the more thought-provoking security topics of the past week in just one minute of video.

Why not give this week's video a go? [Higher resolution available directly from YouTube. Click the Captions icon for closed captions.]

Facebook suffers a data leakage crisis where information uploaded by X about Y may be downloadable by Z.Canada is the last G8 country to go for anti-spam legislation. Only it just got delayed again. Might be ready by 2014. Or 2017.A Korean graphical designer created an "anti-surveillance" font. It doesn't work, but, hey, it's the thought that counts.And Opera wrote up a "Security attack stopped" incident. Except it was more like "Security attack not stopped."

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, anti-spam, anti-surveillance, breach, browser, Canada, certificate, Code signing, data breach, Facebook, font, korean, leak, legislation, Malware, opera, PRISM, Spam, typeface, typography, zxx


View the original article here

Sunday, November 10, 2013

Facebook issues data breach notification - may have leaked your email and phone number

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook just published a data breach notification on its security blog.

You might not immediately notice that from the title of the article, which announces itself as an "Important Message from Facebook's White Hat Program."

But the social networking giant is, indeed, reporting a data leakage problem.

The silver lining is that the quantity of data wrongly disclosed due to Facebook's bug seems to be modest, at least by the standards of a billion-user service.

The cloud (bad pun intended) is that Facebook's systems made the fault possible in the first place.

Facebook, understandably, isn't giving the gory details of the bug and how it could have been exploited, which makes the big picture hard to see.

What it is saying, is this:

We recently received a report to our White Hat program regarding a bug that may have allowed some of a person’s contact information (email or phone number) to be accessed by people who either had some contact information about that person or some connection to them.

So let me tell you what I think the story is all about.

Bear with me, please: I'm going to take a while to set the stage first.

Imagine that Charlie Smith - one of thousands of people with that name - is on Facebook.

He's chosen to tell Facebook his email address, chazza@example.org, but not much more. He hasn't shared where he lives, the name of his employer or his phone number.

Alice joins up and decides to let Facebook at her contact lists. (Facebook squeezes you pretty hard to try to persuade you to upload as much as possible about your web of friends, for reasons that will become obvious in a moment.)

She knows a Charlie Smith; her Charles has a phone number of +1.500.555.5000, and an email address of chazza@example.org.

Facebook can now cross-match the email address and suggest that she might want to try to hook up with Charlie.

Chances are, of all the C. Smiths on Facebook, this is the one she knows.

She sends a Friend Request; it was the right Charlie, and he accepts it.

So far, so good.

Later, Bob comes along.

His contact list, which he yields up to the Facebook empire, identifies a chazza@example.org, known as Charlie Smith, currently living in Someplace, Pennsylvania, and working for the Acme Pointed Stick company.

Facebook likewise puts Bob in touch with Charlie, and thus indirectly with Alice, and the three of them end up as Facebook friends.

Alice is happy; Bob is happy; and, since he agreed to the Friend Requests, we assume Charlie is happy too.

Easy as A-B-C.

Of course, Facebook is the happiest of all, because it now knows (or can make a staggeringly likely guess at) a bunch of personal information about Charlie that he himself chose not to reveal.

Of course, as more people share more information about their contacts, and implicitly confirm the identity of those contacts through the Facebook friendships they forge, Facebook builds up an ever more detailed picture of everyone.

Welcome to the wonderful world of data mining.

You don't have to like this sort of thing, but there's not a lot you can do about it.

Even staying away from sites like Facebook, or "resigning" from them if you're already on, might not help very much.

After all, in our hypothetical example above, Charlie Smith only gave his name and email address; his address, employer and phone number were provided by other people, presumably with their informed consent.

? Alice and Bob may not have thought through the consequences of letting Facebook at their contact lists, but it was their their choice to populate their contact databases with the sort of detail they did, and their choice to let Facebook at that data.

What Facebook seems to be admitting to, in Friday's breach notification message, is that it was careless with the aggregated data accumulated from contact list uploads.

The problem, says Facebook, lay in its Download Your Information (DYI) feature, which exists so you can suck down everything you've previously entrusted to the social networking giant.

Ironically, DYI itself is an important security component of Facebook, because it helps to deal with two serious concerns about cloud-style services:

DYI improves availability, because it allows you to make your own off-site backup of everything you've stored on Facebook.DYI improves transparency, because it acts as a record of everything you've uploaded to Facebook over the years.

But there was a bug in DYI, of the data leakage/unauthorised disclosure sort.

Apparently, DYI was capable of letting you download more than you'd uploaded in the first place.

Using our example above, Bob might have ended up receiving Alice's contact data about Charlie, as well as his own, when he hit the DYI button.

In other words, Bob wouldn't just get back Charlie's address and workplace, which is what he himself uploaded, but might also have ended up with Charlie's phone number, courtesy of Alice.

That's not good at all.

It's especially bad for Charlie, who not only didn't open up his phone number to his Facebook friends, but chose not to upload it in the first place.

Facebook chose to release its statement about this breach on Friday evening, which has already raised the eyebrows of former Naked Security denizen Graham Cluley.

Friday nights, he argues, are the traditional time for burying the sort of announcements you make of necessity rather than by choice.

You can see why Facebook might want this to be a weekend story: there's a chance that it might cause some companies to rethink their "Facebook at Work" strategies, and go back to the old days where Facebook was blocked outright.

That would put a dent in Facebook's daytime traffic, for sure.

After all, if someone shares their contact list while they're at work, they might end up sharing a whole lot more, about many more people, than they really intended.

And Facebook just admitted that, somewhere in its cloud, was a bug that prevented it from taking proper care of that data.

Facebook turned off DYI once the bug was disclosed, fixed it, turned DYI back on again, and published its data breach notification.

Even if you take a cynical view of the timing and the title of the notification, I think you should be happy about some aspects of this cautionary tale:

Respect to the finder of the bug for disclosing it responsibly to Facebook so it could be fixed, even though he'd probably have got a lot more publicity if he'd told the world first.Thanks to Facebook for having a bug bounty programme so that the finder gets some sort of reward for doing the right thing.Well done to Facebook for taking the bug report seriously and fixing the problem.Congratulations to those jurisdictions that have passed strong data breach notification laws, so that this sort of problem can't just be swept under the carpet.Huzzah to those of you who take the stance of not sharing contact lists with social networking sites, on the principle that "if you don't share it, they can't lose it."

Follow @duckblog


View the original article here

Sunday, September 22, 2013

Patching your business, Yahoo breach, Google Glass, DDoS-for-hire - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Our 60 Second Security videos are back!

In the last series, we produced episodes every two weeks; this time, we're hoping to publish a weekly roundup that's quick, fun and useful.

There is a serious side to these videos: we want to give you punchy computer security anecdotes to use in your own "elevator advocacy."

You probably know the feeling.

You get in the lift, sorry, elevator, with someone who's just had a run-in with IT over a security principle that you think is obvious, but they think is tiresome.

"Who cares about Windows updates? Why do I have to change my password? What's the big deal about privacy? Who's going to hack little old me?"

60 Second Security helps you fire back friendly answers to all those questions, long before you get to Level 11.

Here you go: watch the latest security news in just 60 seconds.

In this episode:

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Congress, data breach, DDoS, FBI, Glass, Google, Japan, Patching, small biz, Small Business, yahoo


View the original article here

Tuesday, September 10, 2013

22 million user IDs may be in the hands of hackers, after Yahoo Japan security breach

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Yahoo JapanThe call has gone out to Yahoo Japan's 200 million users to change their passwords, after the company warned that it suspected hackers had managed to access a file containing 22 million user IDs.

Yahoo Japan says that it detected an attempt to gain unauthorised access to its administrative systems on Thursday at approximately 9pm local time.

Although the information taken from Yahoo Japan's servers is said not to contain passwords, or other personal identifying information required to hijack an account (such as the answers to secret questions), the site has decided that users should reset their passwords regardless.

In a press statement published on Yahoo Japan's website, the number one search engine in Japan stressed that it had not confirmed that the data had definitely leaked to the outside world, but that it deeply apologised for any inconvenience caused.

Yahoo Japan statement

Fingers crossed, only user IDs were exposed during the security breach and nothing more serious. But even user IDs should be private, and kept out of the hands of cybercriminals.

Potentially, online criminals now have a database of 22 million Yahoo Japan email addresses - and there are surely slimebags out there who would get a real kick out of spewing out a spam campaign, sending a phishing attack to Yahoo users, posing as a legitimate email from the company, or launching a targeted malware attack.

Hopefully Yahoo Japan will be investigating how the security breach occurred, and putting strong defences in place to prevent it - or anything worse - happening in future.

Follow @gcluley

View the original article here

Thursday, August 22, 2013

Reputation.com resets all user passwords following breach

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Reputation.com, one of the places that helps to bury negative search results about you, has been hacked.

The online reputation management company on Tuesday sent a letter to customers telling them that its network security personnel had recently discovered and "swiftly shut down" an external attack on its network.

Reputation.com email

Reputation.com said in the letter that the intruder(s) managed to siphon off names and email and physical addresses. In some instances, phone numbers, dates of birth and occupational information was also filched.

On top of that, a list of salted and hashed passwords for "a small minority" of users was accessed, the company said.

Although it's "highly unlikely" the passwords could be decrypted, the company immediately changed all users' passwords, it said.

What was not accessed:

Financial information, such as credit card numbers or bank account information, which the company doesn't store (hurray!), Social Security Numbers and drivers license numbers, which the company doesn't request (hurray!), Account details, including why users retained Reputation.com's services (hurray! I imagine that could get embarrassing and potentially be used to make negative content about users zoom back up in search results), Communication between users and Reputation.com, and Any details about the services users have received.

An interesting point is that the extent of the breach didn't trigger any legal obligation, worldwide (except for the US state of North Dakota. Hurray North Dakota!) to tell users about the breach, but the company thought it was important enough to let them know anyway.

Hacked image, courtesy of ShutterstockIt's such a kick in the teeth.

You think you find a site that helps you keep your private data from dribbling out of the myriad online places that siphon it off.

You imagine that the online sliming left by trolls, unhappy customers or whomever's out to get you has been, if not strangled entirely, at least buried far enough down in search results that its babbling just might be muffled.

Then somebody or somebodies goes and tries to stick a pin in those mission statements.

Well, it appears that Reputation.com's work to do those things hasn't been compromised by the attack, and much of the reason for that has to do with good security practices.

So kudos for going above and beyond disclosure requirements, and kudos for salting and hashing passwords, Reputation.com.

Follow @LisaVaas
Follow @NakedSecurity

Hacked image courtesy of Shutterstock.


View the original article here

Tuesday, August 13, 2013

How effective are data breach penalties? Are ever-bigger fines enough?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

For the past couple of years, data security company ViaSat UK has spiced up the Infosecurity Europe conference by filing an FoI (freedom of information) request for data breach statistics.

In previous years, things have ended up with ViaSat in a spot of biffo with the UK Information Commissioner's Office (ICO).

In 2011, ViaSat noted that "monetary penalties have been enforced in less than one per cent of the data losses [the ICO] has dealt with."

The company went on to suggest that this, combined with the modesty of some of the fines that were imposed, might lead to companies simply risking the fines as an alternative to doing the right thing:

Organisations could easily look at the £60,000 penalty meted out to [one company...] compared to the company's £145 million turnover, and its rarity, [...]and feel that the risk of ICO action is one they are prepared to take.

The issue of "paying instead of playing" is one that won't go away in the computer security field.

We ran a poll last year after Google coughed up $22.5 million to the US Federal Trade Commission (FTC) to dispose of charges that it "misrepresented privacy assurances to users of Apple's Safari browser."

We asked, "Are financial penalties enough to make the online behemoths play ball on privacy?"

Nearly 95% of the respondents said, "No."

That's a worrying degree of scepticism!

In 2012, the ICO brought the fight back to ViaSat, with the UK Information Commissioner on record referring to ViaSat's FoI request as a "stunt".

ViaSat's complaint in 2012 was that the private sector seemed under-represented in the statistics on UK data breach penalties, with just one penalty imposed in 263 self-reported cases, compared to eight penalties in 467 self-reported data breaches from the public sector.

This year's FoI request, however, revealed that the ICO handed out 20 penalties overall (instead of the nine in 2011/2012), in response to 1150 self-reported breaches (against the 730 in 2011/2012), and ViaSat's sound bites were correspondingly more conciliatory:

It's pleasing to see the ICO make good on its promise to use both the "carrot and the stick" when enforcing the Data Protection Act.

Some of the recent fines in the UK (or "monetary penalty notices" to give them their proper name) certainly haven't been trivial.

We've written about some of the big fines, sorry, monetary penalties, already on Naked Security.

There was £150,000 (about $230k) paid up by the Greater Manchester Police over an unencrypted USB key, for example, and £225,000 ($345k) paid by the Belfast Health and Social Care Trust.

Technologies such as encryption and DLP (data loss prevention) can, of course, go a long way towards helping you prevent data breaches, especially those that happen through ignorance or carelessness.

Device encryption, for example, helps you ensure that you don't end up making your files accessible to everyone (by accident or design) if you copy them to removable storage (by design or by accident).

And DLP heads you off at the pass before you cut-and-paste sensitive data to the wrong place, and makes sure that you don't include database fields you're supposed to omit when preparing reports.

But the abovementioned Belfast breach, you may remember, is an unyielding reminder that technology alone can't solve your data breach woes.

In that case, physical records were left behind in a mothballed hospital building; thieves broke in, got hold of confidential patient records and tried to sell them online.

Preventing data breaches is as much about attitude as it is about technology: the more you care about your own data and what happens to it, the better inclined you'll be to look after other people's.

So, why not take a look at Sophos's free IT Security DOs and DON'Ts - a downloadable toolkit which helps to keep some simple but effective security tips clear in your mind.

Check out IT Security DOs and DON'Ts

From videos and an employee handbook to posters you can put up round the office (yes, you'll see them on the walls at Sophos!), all the downloads are free, and no registration is required.

Follow @duckblog

View the original article here

Saturday, June 22, 2013

Scribd, "world's largest online library," admits to network intrusion, password breach

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

San Francisco-based document sharing site Scribd has admitted to a network intrusion.

Scribd bills itself as The World's Largest Online Library, and with a suggested 50 million users or more, it's hardly surprising that the site has attracted the attention of cybercriminals.

Details are scant, but a notification published on the company's online Support Desk states:

Earlier this week, Scribd's Operations team discovered and blocked suspicious activity on Scribd's network that appears to have been a deliberate attempt to access the email addresses and passwords of registered Scribd users.

Because of the way Scribd securely stores passwords, we believe that the passwords of less than 1% of our users were potentially compromised by this attack.

We have now emailed every user whose password was potentially compromised with details of the situation and instructions for resetting their password.

Therefore, if you did not receive an email from us, you are most likely unaffected.

The comment that less than 1% of users were potentially compromised "because of the way Scribd stores passwords" could probably have been made more clearly.

At first blush, I was inclined to interpret this to mean that 99% of passwords were stored securely, presumably by salting and hashing, leaving only a small proportion open to the scrutiny of intruders.

? We've seen cases before where websites have upgraded their password handling systems to make them safer, but seem to have failed to migrate all users to the new system in a timely fashion, leaving some users in an insecure limbo.

The good news, if you read on, is that it looks as though none of Scribd's passwords are stored in cleartext, as the company goes on to say that:

Our investigation indicates that no content, payment and sales-related data, or other information were accessed or compromised. We believe the information accessed was limited to general user information, which includes usernames, emails, and encrypted passwords.

Scribd isn't claiming any certainty in what was taken (the verb believe implies acceptance without proof), but that's not unexpected.

Determining precisely what was stolen after an electronic break-in is tricky, and pedantic readers will be quick to point out that, technically, nothing was stolen because the original copies of the data remained behind.

Scribd also isn't clarifying how the passwords were encrypted, and the company probably doesn't actually mean encrypted, either.

Salting and hashing passwords is supposed to be a one-way process that allows the passwords to be verified, but not decrypted to reveal the original cleartext.

Assuming they were hashed and salted, then, stealing the password database doesn't directly reveal anyone's password.

But it does let the crooks mount an offline attack on the database, hashing a dictionary of passwords one-by-one and noticing when a guessed password is verified against the database of hashes.

And since Scribd isn't saying what password security algorithm it used, you have little choice but to assume it was a hashing process that doesn't slow down determined attackers much.

That's why the following behaviours are important:

When you choose a password, don't pick anything obvious. Attackers put the most likely passwords at the top of their dictionary lists, so the tougher your password, the later it will fall, if at all.Don't use the same password on multiple sites. Doing so means that your login details on the most important site are at risk from an attack on the least secure one.If you store password databases, use a strong salt-and-hash system (e.g. bcrypt, scrypt or PBKDF2) that makes it much harder and slower for attackers to go through their password dictionary, but not so slow that it's impracticable to verify individual passwords when your users login.

Scribd has put up an online "breach checker" which lets you check individual email addresses against the list of probably-pwned accounts:

It would have been a nice touch if the company had used HTTPS for this particular page, rather than sending your email address, and the notification of whether it was on the at-risk list, via unencrypted HTTP:

On the other hand, since anyone can check anyone's email address anyway, and since you probably received an email advising you to change your password already if your account was potentially pwned, it probably doesn't matter.

To learn more about managing, choosing and policing passwords in your organisation, why not listen to our popular Techknow podcast on this very topic?

(If you prefer to listen offline, you can download the podcast for later.)

Follow @duckblog


View the original article here

Sunday, May 19, 2013

$5 million class action lawsuit over LinkedIn data breach dismissed

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

LinkedInAny damage done to LinkedIn users over the massive June 2012 data breach was abstract, not actual, a US judge has ruled.

Thus did a $5 million class-action lawsuit against the networking site get dismissed, before the case ever breathed the air of a court trial.

The breach resulted in the compromise of 6.5 million users' passwords.

Within hours of the passwords being posted online, over 60% of the stolen passwords had been cracked.

Within days of the June breach, the lawsuit was filed on behalf of all users by two premium LinkedIn users in the US, Katie Szpyrka and Khalilah Wright.

It charged LinkedIn with failing to use basic industry standard security practices - a failing that, the plaintiffs claimed, led to the data leak.

Specifically, the suit claimed that LinkedIn didn't store passwords in salted SHA1 hashed format, thereby failing to adhere to its Privacy Policy's promise to use industry standard protocols and technology to protect personally identifiable information.

Here's what the security part of LinkedIn's privacy policy said at the time:

In order to help secure your personal information, access to your data on LinkedIn is password-protected, and sensitive data (such as credit card information) is protected by SSL encryption when it is exchanged between your web browser and the LinkedIn website. To protect any data you store on our servers, LinkedIn also regularly audits its system for possible vulnerabilities and attacks, and we use a tierone secured-access data center.

However, since the internet is not a 100% secure environment, we cannot ensure or warrant the security of any information you transmit to LinkedIn. There is no guarantee that information may not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards.

It is your responsibility to protect the security of your login information. Please note that emails, instant messaging, and similar means of communication with other Users of LinkedIn are not encrypted, and we strongly advise you not to communicate any confidential information through these means.

Privacy Policy. Image from Shutterstock

Unfortunately for the plaintiffs, they failed to provide evidence of injury coming out of the breach that was "concrete and particularized," as well as "actual and imminent," US District Judge Edward J. Davila wrote in his decision (PDF).

The plaintiffs claimed to have gotten gipped after they ponied up the premium membership fee but then didn't get the industry-standard security the privacy policy promised.

The thing is, Davila responded, the plaintiffs didn't pay extra for that security, given that it was promised to both premium and basic (free) memberships alike.

Rather, what the premium account holders actually got in return for their fees were advanced networking tools and enhanced usage of LinkedIn's services, not great security.

He wrote:

The User Agreement and Privacy Policy are the same for the premium membership as they are for the nonpaying basic membership. Any alleged promise LinkedIn made to paying premium account holders regarding security protocols was also made to non-paying members.

Thus, when a member purchases a premium account upgrade, the bargain is not for a particular level of security, but actually for the advanced networking tools and capabilities to facilitate enhanced usage of LinkedIn’s services.

The [suit] does not sufficiently demonstrate that included in Plaintiffs’ bargain for premium membership was the promise of a particular (or greater) level of security that was not part of the free membership.

Besides, Davila said, the plaintiffs didn't even read the privacy policy to begin with (at least, they didn't allege to have read it in the suit), so how can they claim that they forked over the money for premium memberships based on what it claimed?

As far as injury goes, while Wright claimed that her password had been posted online, it didn't result in identity theft or somebody getting into her account, the judge said, so the claim of financial harm or injury just doesn't fly.

He wrote:

Wright merely alleges that her LinkedIn password was "publicly posted on the Internet on June 6, 2012". In doing so, Wright fails to show how this amounts to a legally cognizable injury, such as, for example, identify theft or theft of her personally identifiable information.

One lesson we can take from this is, apparently, that users have to take security promises and privacy policies with a grain of salt.

Beyond that, the nuances of whether a company will be found liable for security lapses, and the whys and why-nots, intrigue me.

I initially conjectured, when the lawsuit was first filed, that LinkedIn had its work cut out for it in defending itself. I was clearly wrong.

What do you think: should LinkedIn get off the hook this easily? Should a company be held liable for not meeting industry standards for security?

Please share your thoughts in the comments section below.

Follow @LisaVaas
Follow @NakedSecurity

Privacy Policy image from Shutterstock


View the original article here

Sunday, May 5, 2013

Evernote hacked - almost 50 million passwords reset after security breach

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

EvernoteEvernote, the online note-taking service, has posted an advisory informing its near 50 million users that it has suffered a serious security breach that saw hackers steal usernames, associated email addresses and encrypted passwords.

It's not clear how the hackers managed to gain access to Evernote's systems, or how long the hackers had access to Evernote's account information.

However, in an interview with TechCrunch, Evernote said that they had first noticed suspicious activity on February 28th.

The good news is that no payment details were stolen, and according to the company the hackers were not able to access notes that users had stored on the Evernote service.

Furthermore, it sounds as though the passwords were encrypted, using hashes and salting to prevent login details falling into the wrong hands. (It would be reassuring - of course - to have more details shared by Evernote of how the passwords were hashed and salted).

Evernote advisory

The investigation has shown, however, that the individual(s) responsible were able to gain access to Evernote user information, which includes usernames, email addresses associated with Evernote accounts and encrypted passwords. Even though this information was accessed, the passwords stored by Evernote are protected by one-way encryption. (In technical terms, they are hashed and salted.)

While our password encryption measures are robust, we are taking additional steps to ensure that your personal data remains secure. This means that, in an abundance of caution, we are requiring all users to reset their Evernote account passwords. Please create a new password by signing into your account on evernote.com.

What's not good news is that the hackers now have access to the usernames and email addresses of Evernote customers. It is easy to imagine how this information could be abused - for instance, the hackers could send out spam emails to those users claiming to come from Evernote, and trick them into visiting a malicious website.

And, of course, it's another cautionary tale about the risks which can exist with trusting the cloud to look after your personal information. Evernote sounds to me like it's another online service that would benefit from providing its users with additional account security - such as two factor authentication.

Evernote advises users to choose a strong password, and to be suspicious of reset password links sent to users via email. Furthermore, everyone should ensure that they are not using the same password on multiple sites.

Evernote appears to have acted reasonably rapidly in response to this security incident, and it will be interesting to see if they share any more information about how the hack might have occurred in the coming days.

Further reading: Evernote shoots itself in foot over "never click on 'reset password' requests" advice

Follow @gcluley

View the original article here

Thursday, January 24, 2013

Australian Defence Force Academy in stinkingly bad password breach

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The Australian Defence Force Academy (ADFA) is the latest high-profile organisation to become embroiled in a data breach.

Students at the Academy apply both to the Defence Force and to the University of New South Wales (UNSW), which runs the academic side of ADFA's operations in Canberra.

It turns out that a hacker calling himself Darwinare breached the UNSW's servers about a month ago and sucked down a heap of SQL database records, including those of ADFA students.

He then uploaded the data to an anonymous dump site, where interested members of the public can acquire it at will.

Fast-forward four weeks to today, and the breach is starting to attract attention, no doubt because of the connection of UNSW Canberra with the Defence Force Academy.

Darwinare brag-art

It's certainly a bad look for both the University and the Academy.

It's not the end of the world, fortunately. No juicy Defence secrets such as troop movements, aircraft plans, coastal patrol schedules, or weapons purchases have been revealed.

And UNSW did the right thing, candidly explaining the breach to those affected the day after it was reported. The breach included student ID, full name, email address and date of birth; similar data about staff was dumped, too.

Nevertheless, it shouldn't have happened, and there can be no excuses.

Worst of all, the data dump reveals that UNSW was storing usernames and passwords for at least one of its computer systems in plaintext.

To be fair, these passwords were meant just for initial login, and were therefore expected to have a short life. But passwords should never be weak or guessable, or, for that matter, stored in plaintext. And the algorithm for generating the passwords in the dump is like a timewarp back into the 1970s.

They are all just seven or eight lower-case letters long. Many are repeated. All are meant to be pronounceable - surely an unnecessary step for a password that is intended to be typed in once and then changed - which leads to a conspicuous lack of randomness. Only a small set of digraphs (two-letter pairs) is used.

That produces some comic results. One percent of the passwords, for example, end in -poo, making them rather sadly self-descriptive.

Make sure this doesn't happen to you.

Harden your web services! Bring your password handling into the 1990s, if not actually the twenty-first century! Do it today!

Thanks for listening.

Follow @duckblog

Do you run a web server at home, perhaps for friends and family, or even just for fun? How well protected are you?

Why not try our free Sophos UTM Home Edition?

You get a web application firewall, web and email filtering, IPS, VPN and more for up to 50 IP addresses.

Turn that spare PC into a full-on network security appliance!


View the original article here

Sunday, December 30, 2012

NASA suffers major data breach over stolen laptop that wasn't encrypted

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

NASA image, courtesy of ShutterstockIn March 2011, algorithms used to command and control the International Space Station were exposed.

In March 2012, it was the personally identifiable information (PII) of 2,300 employees and students.

In another incident, it was sensitive data on NASA's Constellation and Orion programs.

This time around, on 31 October, it was PII on an unspecified, but large, number of NASA employees and contractors.

All these instances involved the theft of unencrypted laptops from NASA. With this most recent theft, the space agency is finally doing something about these incidents, beyond the limited scope of its previous remediation efforts.

NASA announced on Tuesday that, effective immediately, the agency is jumping on the encryption fast track.

By 21 December, no NASA-issued laptops containing sensitive information will be allowed to leave a NASA facility unless whole disk encryption software is enabled or sensitive files are individually encrypted.

In a message sent agency-wide to all employees, Associate Deputy Administrator Richard J Keegan Jr. informed NASA staff that somebody or somebodies broke into a locked vehicle and stole official NASA documents on 31 October.

The laptop contained records with PII for a large number of employees, contractors and others, Keegan said.

He gave no explanation as to why the agency waited weeks to inform employees.

Rocket. Image from ShutterstockThe computer was protected only with a password and lacked whole disk encryption, which left the information accessible to thieves.

NASA is taking standard breach precautions, including contracting a data breach specialist, ID Experts, to notify those whose PII was compromised.

The agency is offering free credit and identity monitoring, recovery services in cases of identity compromise, an insurance reimbursement policy, educational materials, access to fraud resolution representatives, and a call center and website.

It's recommending that anybody affected activate these services ASAP.

NASA is also recommending that those affected be wary of suspicious phone calls, emails, and other communications from individuals claiming to be from NASA or other official sources that ask for personal information or verification of it.

NASA and ID Experts won't be contacting employees to ask for or to confirm personal information, Keegan said, so any such communication is sure to be bogus.

NASA's embrace of full-disk encryption has up until now been less than comprehensive.

After the March 2012 stolen laptop and PII exposure, the agency pledged:

...a full review of current IT security policies and practices with the goal of making changes to prevent a similar incident.

At that time, NASA promised that all laptop computers at NASA Kennedy Space Center, not just ones with PII or sensitive data, would have their hard drives encrypted by September 2012.

In retrospect, it would have been smarter to extend that initiative to all hard drives, throughout the entire agency, not just those at Kennedy.

Secure laptop, courtesy of ShutterstockBut that is, apparently, a lesson that NASA has now taken to heart and will implement with all due haste.

The new full-disk encryption applies to all laptops containing PII, International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) data, procurement and human resources information, and other sensitive but unclassified (SBU) data.

Keegan said that NASA's Administrator and CIO have laid out the marching orders for agency CIOs to complete whole disk encryption of the maximum possible number of laptops by 21 November.

NASA plans to complete the effort by 21 December, after which no unencrypted laptop, regardless of whether it contains PII, will be allowed to leave its facilities.

In the meantime, employees working remotely or traveling have been told to use loaner laptops if their NASA-issued laptop contains unencrypted sensitive information.

On Wednesday, a security vendor (or then again, more likely, many security vendors, but only one wrote to me directly) sent out a statement on the NASA breach that said,

"OK, whole-disk encryption might be good, but is it good enough?"

It's a question worth asking. As he said, data is in fact moving to and from laptops, in emails, files, and as data traveling to and from apps and servers.

Fortunately, NASA has also declared that storage of sensitive information on smart phones or other mobile devices is now taboo.

Let's hope they also have an eye toward all the places that data propagates, whether it's in emailed attachments, on mail servers that might be in the cloud, on smartphone mail apps, on backup tapes, or in any internal or outsourced operations.

Follow @LisaVaas
Follow @NakedSecurity

NASA image, courtesy of Songquan Deng / Shutterstock.com. Secure laptop and rocket images courtesy of Shutterstock


View the original article here

Saturday, December 29, 2012

FreeBSD shutters some servers after SSH key breach

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Venerable BSD-based operating system FreeBSD has announced a smallish system compromise.

The FreeBSD administrators took a bunch of servers offline to investigate, and published a blow-by-blow account of what they know about the breach so far.

FreeBSD isn't the first open source operating system to suffer an intrusion on its core servers.

The Linux developers famously suffered both a malware attack and a server compromise last year that saw kernel.org vanish offline for over a month.

In this case, however, the FreeBSD crew and their users don't seem to have suffered too badly.

None of the so-called base repositories were touched - that's where core components such as the kernel, system libraries, compiler, core command-line tools and daemons (server software) reside. Only servers hosting source code for third-party packages were affected.

Fortunately, the investigation so far hasn't turned up any software packages that were Trojanised by the intruders. So the knock-on effect of the break-in will probably turn out to be minimal.

The official reason is given as a likely compromise of a developer's SSH key.

SSH, or secure shell, is the predominant remote-access protocol for non-Windows systems.

It supports a range of authentication schemes; on many systems, administrators do away with across-the-wire usernames and passwords, and opt instead for authentication based on public/private key pairs.

The idea is that I generate a key pair and send you my public key.

After verifying carefully that it really is my key, e.g. with a phone call, you upload my public key to your server. My SSH client can then use my private key to log me in; your server uses the corresponding public key to verify my identity.

Since my private key is itself protected by a password (or ought to be), we continue to enjoy the benefits of password-based security - plus the advantage that knowing my password alone is not enough for an attacker. He needs a physical copy of my private key file, too.

In this case, it sounds as though the attacker did manage to steal both authentication factors - key file and password - from the developer.

This is a hearty reminder that a chain is only as strong as its weakest link.

In particular, never forget that the security of your internal systems may very well be no better than the security of any and all external systems from which you accept remote access - whether those are servers, laptops or even mobile devices.

Follow @duckblog


View the original article here

Sunday, November 4, 2012

Chinese hackers linked to breach of control systems used in electric grids

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

electricity_170Attackers breached Telvent's network, the company has informed its customers in a letter. Telvent is the maker of an industrial control system that remotely controls smart grid networks used in portions of the electric grid.

Telvent told its customers that on Sept. 10, it learned that hackers had breached its internal firewall and security systems, implanted malicious software, and stolen project files.

According to
Chinese Hackers Blamed for Intrusion at Energy Industry Giant Telvent" href="http://krebsonsecurity.com/2012/09/chinese-hackers-blamed-for-intrusion-at-energy-industry-giant-telvent/" rel="nofollow">KrebsOnSecurity, which first reported the breach, the project files concerned Telvent's
Standardized, centralized SCADA solutions from Telvent" href="http://www.telvent.com/en/business_areas/smart_grid/solutions_overview/smart_grid/smart_operations/oasys-scada.cfm" rel="nofollow">OASyS SCADA product, which offers energy firms a bridge between older technology and advanced smart grid technologies.

Telvent, which is owned by Schneider Electric, told customers that the attack spans operations in the US, Canada and Spain.

Experts detected digital fingerprints implicating a Chinese hacking group that has been tied to cyber-espionage campaigns against Western interests.

Telvent_logo

KrebsOnSecurity cited Joe Stewart, director of malware research at Dell SecureWorks, who said that website and malware names mentioned in a more recent letter from Telvent can be traced to a Chinese hacking team known as the "Comment Group."

That group, often referred to as the Comment group, has been under investigation by US intelligence for years.

Researchers told Bloomberg that during two months of monitoring last year, targeted companies spanned a vast scale as data "bled from one victim to the next":

...from oilfield services leader Halliburton Co. (HAL) to Washington law firm Wiley Rein LLP; from a Canadian magistrate involved in a sensitive China extradition case to Kolkata-based tobacco and technology conglomerate ITC Ltd. (ITC)

A loose-knit group of some 30 North American private security researchers tracking the group have called the Comment Group one of the biggest and busiest hacking groups in China.

Bloomberg quoted Shawn Henry, former executive assistant director of the FBI in charge of the agency’s cyber division, who said that typical cybersecurity headlines about data breaches scarcely hint at the scope of the group's activities:

What the general public hears about — stolen credit card numbers, somebody hacked LinkedIn (LNKD) — that’s the tip of the iceberg, the unclassified stuff. … I’ve been circling the iceberg in a submarine. This is the biggest vacuuming up of U.S. proprietary data that we’ve ever seen. It’s a machine.

Evidence indicates that at least 20 organizations have been harvested for data, many of whose secrets could give China a leg up on its path to becoming the world’s largest economy.

Bloomberg cited unnamed security experts who said that the breaches have sprung data leaks in major oil companies, who've lost seismic maps charting oil reserves, while patent law firms have been squeezed for clients' trade secrets and investment banks have been targeted for market analysis regarding global ventures of state-owned companies.

Telvent said that investigations are still under way, but it's taken the precaution of severing data links between clients and the affected portions of its internal networks.

The company also said that it hasn't yet found evidence that the attackers had been able to compromise customers' systems:

Although we do not have any reason to believe that the intruder(s) acquired any information that would enable them to gain access to a customer system or that any of the compromised computers have been connected to a customer system, as a further precautionary measure, we indefinitely terminated any customer system access by Telvent.

Telvent gave me this statement:

Telvent is aware of a security breach of its corporate network that has affected some customer files. Customers have been informed and are taking recommended actions, with the support of Telvent teams. Telvent is actively working with law enforcement, security specialists and its affected customers to ensure the breach has been contained.

Meanwhile, the Obama adminstration and Congress have grown increasingly vocal about Chinese and Russian cyber espionage and attacks, with the White House close to completing the first draft of a cybersecurity executive order designed to bring about stronger cyber security around the nation's water, electrical and transportation systems.

It's a reasonable thing to call for stronger protection around vital infrastructure.

But as Reuters pointed out in a recent report on what one top US cybersecurity official called "reckless" cyber behavior from nation states, the US's right to complain about other nations' cyber warfare might be questionable, given what is by now a widespread belief that the US and Israel were behind Stuxnet.

Follow @LisaVaas
Follow @nakedsecurity

electricity images courtesy of Shutterstock


View the original article here

Thursday, October 27, 2011

Accused hacker pleads not guilty in Sony breach - Montreal Gazette

LOS ANGELES - An accused member of the clandestine hacking group LulzSec pleaded not guilty on Monday to charges of taking part in an extensive computer breach of the Sony Pictures Entertainment film studio.

Cody Kretsinger, 23, entered not guilty pleas to one count each of conspiracy and unauthorized impairment of a protected computer during a brief hearing in U.S. District Court in Los Angeles.

U.S. Magistrate Judge Victor Kenton set a Dec. 13 trial date for Kretsinger, who spoke only in response to questions from the judge.

Kenton also ordered that Kretsinger be represented by a court-appointed public defender.

Kretsinger faces a maximum sentence of 15 years in prison if convicted. He declined to comment to Reuters after the hearing.

A nine-page federal grand jury indictment unsealed in September charges Kretsinger with obtaining confidential information from Sony Pictures’ computer systems using an “SQL injection” attack against its website, a technique commonly used by hackers to steal information.

Kretsinger, who went by the moniker “recursion,” helped post information he and his co-conspirators stole from Sony on LulzSec’s website and announced the intrusion via the hacking group’s Twitter account, the indictment charges.

LulzSec, an underground group also known as Lulz Security, at the time published the names, birth dates, addresses, e-mails, phone numbers and passwords of thousands of people who had entered contests promoted by Sony.

“From a single injection we accessed EVERYTHING,” the hacking group said in a statement at the time. “Why do you put such faith in a company that allows itself to become open to these simple attacks.”

Hackers previously had accessed personal information on 77 million PlayStation Network and Qriocity accounts, the vast majority of which were users in North America and Europe, in what was then the biggest such security breach in history.

Other high-profile firms targeted by cyber attacks included Lockheed Martin and Google Inc.


View the original article here

Monday, October 24, 2011

Hackers Spied on Board Directors After Nasdaq Breach

Results from Nasdaq's investigation into a breach it disclosed in February are trickling out. The bottom line: The attack was worse than initially expected.

Fox News said hackers who infiltrated the Nasdaq's computer systems installed malicious software on the exchange's computers that allowed them to spy on scores of directors of publicly held companies. Fox cited "two people familiar with an investigation" as sources.

The target of the attack was a Web-based software program called Directors Desk. Nasdaq OMX develops Directors Desk, which serves as a communications and information management solution for boards. Security is touted as one of its benefits.

An SQL Injection?

Gunter Ollman, vice president of research at security firm Damballa, said the sparse public information available on the NASDAQ breach and the nature of the Director's Desk Web-based application leads him to believe that remote hackers probably exploited vulnerabilities within the application that allowed them to peruse information exchanges between various company directors.

"Gaining remote access to confidential data held within the Director's Desk application could have been through SQL injection, broken authentication and session management, and URL restriction failures," Ollman said. "In my years of running penetration tests against Fortune 500 companies, these were the most common vulnerabilities that could be exploited to reveal this level of confidential data."

Some security experts are reporting that the attackers successfully installed malware on the system. In order to do this, Ollman said, the attacker would need the capability to upload files to the application and/or break out of the application itself and gain access to the server directly. Interestingly, he noted, several Open Web Application Security Project top-10 attack vectors will allow this to occur.

Web App Vulnerabilities

Ollman, for one, is not surprised at the Directors Desk revelations. That's because vulnerabilities within large Web-based applications are increasingly common. Web-based software is under constant development and change, he said, which means that vulnerabilities can be unintentionally introduced at any time.

"If there are multiple development teams working on the same application portal -- all developing their own micro applications -- then the probability of new vulnerabilities being introduced grows considerably," Ollman said. "This is why Web applications need to be security-tested continuously. Regular security assessments and penetration tests are standard requirements for running large and important Web services."

Ollman said automated tests and change-control monitoring ideally should be conducted daily, and skilled consultants should manually assess the Web application monthly. What's more, he continued, given the human element in most advanced testing, it is a good idea to rotate between penetration-testing vendors so that the tests are not limited by the skills of the individual consultants they employ or the tool sets they use to conduct their tests.

"Access to Web-based applications by attackers is important for cybercriminals -- as well as state actors," Ollman said. "Again, it bears repeating that very little is known about the specific nature of the Nasdaq attack. But given the level of access to the application and the potential to modify content upon the Director's Desk application, likely consequences could include the ability to eavesdrop on company director communications and the ability to use that information for 'virtual insider trading' processes."


View the original article here

Monday, August 22, 2011

Hackers breach BART union site

Published: Aug. 19, 2011 at 12:41 AM

SAN FRANCISCO, Aug. 19 (UPI) -- Hackers cracked into the BART Police Officers' Association Web site and released the names of 102 BART officers online, authorities say.

The hack, carried out Wednesday, was in response to the temporary disabling of underground cellular and WiFi service at downtown San Francisco BART stations, the San Francisco Chronicle reported.

The decision by BART was made in attempt to keep demonstrators at a protest scheduled for Aug. 11 from corresponding. The protest did not end up taking place.

Names of 102 officers, as well as their home addresses, e-mail addresses and passwords for the site, were posted online by a hacker group, with the comment "Yet another success," written by the hackers.

Union President Jesse Sekhon, whose information was leaked, said he and his members were distressed by the breach in security.

"These people are criminals, and we're going to forward this information to the FBI," Sekhon said. "These people need to be brought to justice. They can't be terrorizing people."

The hacking group Anonymous has claimed responsibility for hacking and extracting information from 70 police department Web sites nationwide.


View the original article here

Wednesday, July 6, 2011

Hackers claim Apple security breach

A customer types on a MacBook laptop at an Apple Store in San Francisco, U.S.A., on May 9.A customer types on a MacBook laptop at an Apple Store in San Francisco, U.S.A., on May 9.Incident part of wave of cyber attacks designed to embarrass big companiesPotential Apple breach was ppublicizedthrough a Twitter message from AnonymousIRC of cyberactivist collective AnonymousFBI inquiry into earlier incidents yields evidence of internal rifts

(FT) -- A hacking group has claimed it breached corporate security at Apple and has published what it said were two dozen administrator names and apparently encrypted passwords for a server at the US technology group.

The data was not linked to the more than 200m customer credit cards stored on the iTunes online store. The server collected survey information and therefore might have only limited use for criminals.

Nonetheless, the breach showed that a recent wave of cyberattacks designed in part to embarrass big companies would continue, even without Lulz Security , the pioneering group that drew wide attention for a similar, 50-day spree.

A potential Apple breach was publicized through a Twitter message from AnonymousIRC, one of many accounts associated with the cyberactivist collective Anonymous.

"Apple could be targeted, too. But don't worry, we are busy elsewhere", the Anonymous account wrote on Twitter.

When Lulz disbanded a week ago, it said some future attacks would be carried out by Anonymous and called on other hackers to continue the effort it calls AntiSec, for anti-security.

Apple declined to comment. On the surface, the breach at the largest music music would seem less serious than recent penetrations at big gaming groups such as Sony, which saw details of 100m online game players revealed.

Lulz drew big concern from the law enforcement authorities because it temporarily knocked offline public websites of the CIA and the UK Serious Organised Crime Agency and penetrated a joint venture between the FBI and the private sector.

In the UK, 19-year-old Ryan Cleary has been charged with denial-of-service attacks like that on Soca and is co-operating with authorities. Lulz has said that he played a tangential role in its operations.

In the past two weeks, the FBI searched two US residences in its probe, carting off computers from the homes of a teenager from Hamilton, Ohio, and a 29-year-old woman in Davenport, Iowa.

Material from the FBI's probe includes evidence of internal rifts, which are proving a fruitful source of information in the inquiry. Lulz published the Ohio teen's address and online nicknames this month as it blamed him for the arrest of Mr Cleary. The Iowa woman told the Financial Times she was outed after leaking records of the group's internal chats, which she did after they turned against a friend.

In an apparently unrelated attack on Monday, News Corp's Fox News said one of its Twitter accounts, Foxnewspolitics, had been compromised and used to send out false messages stating that US president Barack Obama had been assassinated. It said it was investigating the incidents.

© The Financial Times Limited 2011


View the original article here