Google Search

Showing posts with label master. Show all posts
Showing posts with label master. Show all posts

Thursday, November 28, 2013

Facebook, the early years: handing out a master password like candy

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Mark Zuckerberg. Image courtesy of Kobby Dagan / Shutterstock.You are not paranoid about surveillance - at least, not as far as Facebook is concerned.

It appears that Facebook founder Mark Zuckerberg and his minions, in the early days, had a master password with which they could sign in to any user account and poke at whatever data we entrusted to the site.

The Guardian gleaned this from Zuckerberg's former speechwriter, Katherine Losse.

Losse told the media outlet that users should be guarded with their private data on the site - a timely warning, given the launch of Facebook's social search tool graph search.

Losse - aka Facebook employee No. 51 - joined the company in 2005 as a customer support staffer and worked her way up to being Zuckerberg's ghostwriter. She left in 2010 and, according to the Guardian, is now regarded as a rogue former employee by Facebook itself.

In 2012, she released a book, The Boy Kings, about those early years.

Recent revelations about the US National Security Agency's (NSA's) voraciously hungry appetite for surveillance may have left many users of social networking sites fretting about the government sucking up our private data, but Facebook has been privy to that data - including our passwords - from its infancy, Losse told the Guardian.

As The Guardian's Siraj Datoo points out, that's a little scary, given that plenty of users likely have never changed their passwords since they first signed up.

To make matters worse, many people commit security blasphemy by using the same password on multiple sites.

To make matters spontaneously combust in worse-osity, Losse wrote in "The Boy Kings" that in its early years, Facebook passed out the master password like candy, without vetting any of the support staffers.

Here's an excerpt from the book, courtesy of coverage from CNet's Jennifer Van Grove:

"Jake introduced us to the hanky application through which users' e-mails to Facebook flowed. Once we learned how the software worked, Jake taught us, without batting an eyelid, the master password by which we could log in as any Facebook user and access all their messages and data... I experienced a brief moment of stunned disbelief: They just hand over the password with no background check to make sure I am not a crazed stalker?"

As Losse told The Guardian, social networking users tend to assume they're the only ones who can access the information they input, but at most companies, it's probably not true, given that "at least some of the staff need to have access to user accounts in order to do their jobs."

She said:

"There has to be a way for the staff to manage and repair user account issues, and for this reason user data within most startups, especially when they are young, is never completely locked up from company staff."

At any rate, Facebook doesn't hand out a master password anymore, it says.

Nowadays, the company told CNet, employees don't have password access:

"An audit by the Irish Data Protection Commission included a detailed review of the level of access to user data that employees have at Facebook and found that we have an appropriate framework in place. Facebook employees do not have access to users' passwords."

It is, of course, preferable that we have as clear a picture as possible of what companies do with our personal data, so this history of early data yahooism is welcome.

Facebook silhouette. Image courtesy of Shutterstock.If it helps Losse to sell more books by tying it in to concern about PRISM-like surveillance, that's OK, as far as I'm concerned.

The more light we shed on these formerly murky matters, the better.

Facebook from its start could watch us, listen to us, and, probably, make fun of us and our soppy, trivial and/or really embarrassing posts and data.

Now it can't, it assures us.

If that helps to ease your compulsive surveillance suspicions, paralyzing fear of electronic privacy violation, or even, to borrow the Joy of Tech's formal diagnosis, PRISM Anxiety Disorder, all the better.

Thank you, Ms. Losse, for letting us know.

Follow @LisaVaas

Follow @NakedSecurity

Images of Facebook silhouette and Mark Zuckerberg courtesy of Kobby Dagan / Shutterstock.com.


View the original article here

Saturday, December 8, 2012

Sony PS3 hacked "for good" - master keys revealed

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Sony's PS3 has been hacked.

Perhaps "hacked" is the wrong word, because it can imply both criminality and lawful exploration. But we'll stick with "hacked" here, in the sense of "some reverse engineers have figured out how you can adapt, or jailbreak, your PS3 to make it interoperable with software of your own choice."

The PS3 has been hacked before, but Sony was able to inhibit the hack with an update to its own firmware. This is much like the history of jailbreaking on Apple's iOS, where hackers typically uncover a security vulnerability and exploit it, whereupon Apple patches the hole and suppresses the jailbreak.

But the latest PS3 break is being dubbed unpatchable and the final hack.

That's because this hack isn't giving you an exploit to use against a programming hole. It's giving you Sony's so-called LV0 (level zero) cryptographic keys.

The PS3 system software loads up as shown in the picture below:

Diagram derived from this article on popular PS3 development website ps3devwiki.

The Level Zero (LV0) loader is the mother of all field-updatable firmware components in the PS3 bootstrap process. It orchestrates the loading, and the cryptographic verification, of all the modules underneath it. As long as the LV0 loader remains the way Sony wants it, you get to run only what Sony wants you to.

Pirated games won't load, which is good for rights holders. But Linux, for example, won't run either, which is bad for you. Why shouldn't you run lawfully-acquired software of your choice on your own computer? [*]

With the LV0 keys now published, you can - at least in theory - replace the LV0 loader and run whatever you like, because you can authorise your own custom firmware (CFW). The PS3's most-secret cat is out of the bag.

Incidentally, the publication of the LV0 keys was not without some controversy and finger-pointing amongst the reverse engineering and CFW community.

It seems as though a hacking and reversing posse known as the Three Musketeers worked out the LV0 keys some time ago. Since they were, in their own words, "done with PS3 now anyways," they just sat on the information.

But some turncoat leaked it, and it eventually reached a Chinese hacking group, BlueDisk­CFW.

Well, well.

BlueDisk­CFW didn't just use someone else's work to publish a custom firmware that was unashamedly aimed at violating others' intellectual property. They planned to charge for it! Knock me down with a feather! Dishonourable software pirates! Thieves and rascals!

The Three Musketeers took exception to that.

Let's hope, when the PS4 comes out, that Sony will give up on trying to lock out jailbreakers permanently, and instead provide a way for those who want to run alternative software to do so in official safety.

When King Cnut famously ordered the tide back and failed, he wasn't an arrogant absolute ruler trying to show off.

He knew he would fail, and thereby demonstrated that to hold back the tide was impossible - and, in any case, unnecessary - even for a king.

Follow @duckblog

[*] That's a rhetorical question. There isn't a good reason why you shouldn't. Most people don't want to, and won't even try. But that's no reason why you shouldn't have the choice.

Tags: Apple, BluediskCFW, bootstrap, canute, cnut, crypto, Exploit, ios, LV0, ps3, Sony, vulnerability


View the original article here