Google Search

Showing posts with label secure. Show all posts
Showing posts with label secure. Show all posts

Monday, June 2, 2014

Quantum physics could make secure, single-use computer memories possible

Computer security systems may one day get a boost from quantum physics, as a result of recent research from the National Institute of Standards and Technology (NIST). Computer scientist Yi-Kai Liu has devised a way to make a security device that has proved notoriously difficult to build -- a "one-shot" memory unit, whose contents can be read only a single time.

The research, which Liu is presenting at this week's Innovations in Theoretical Computer Science conference, shows in theory how the laws of quantum physics could allow for the construction of such memory devices. One-shot memories would have a wide range of possible applications such as protecting the transfer of large sums of money electronically. A one-shot memory might contain two authorization codes: one that credits the recipient's bank account and one that credits the sender's bank account, in case the transfer is canceled. Crucially, the memory could only be read once, so only one of the codes can be retrieved, and hence, only one of the two actions can be performed -- not both.

"When an adversary has physical control of a device -- such as a stolen cell phone -- software defenses alone aren't enough; we need to use tamper-resistant hardware to provide security," Liu says. "Moreover, to protect critical systems, we don't want to rely too much on complex defenses that might still get hacked. It's better if we can rely on fundamental laws of nature, which are unassailable."

Unfortunately, there is no fundamental solution to the problem of building tamper-resistant chips, at least not using classical physics alone. So scientists have tried involving quantum mechanics as well, because information that is encoded into a quantum system behaves differently from a classical system.

Liu is exploring one approach, which stores data using quantum bits, or "qubits," which use quantum properties such as magnetic spin to represent digital information. Using a technique called "conjugate coding, "two secret messages -- such as separate authorization codes -- can be encoded into the same string of qubits, so that a user can retrieve either one of the two messages. But as the qubits can only be read once, the user cannot retrieve both.

The risk in this approach stems from a more subtle quantum phenomenon: "entanglement," where two particles can affect each other even when separated by great distances. If an adversary is able to use entanglement, he can retrieve both messages at once, breaking the security of the scheme.

However, Liu has observed that in certain kinds of physical systems, it is very difficult to create and use entanglement, and shows in his paper that this obstacle turns out to be an advantage: Liu presents a mathematical proof that if an adversary is unable to use entanglement in his attack, that adversary will never be able to retrieve both messages from the qubits. Hence, if the right physical systems are used, the conjugate coding method is secure after all.

"It's fascinating how entanglement -- and the lack thereof -- is the key to making this work," Liu says. "From a practical point of view, these quantum devices would be more expensive to fabricate, but they would provide a higher level of security. Right now, this is still basic research. But there's been a lot of progress in this area, so I'm optimistic that this will lead to useful technologies in the real world."


View the original article here

Sunday, June 1, 2014

Future industry: No chance for industrial pirates with highly secure networks

In the future, production facilities will be able to communicate and interact with one another, and machinery will often be remote-serviced. But no company boss wants to run the risk of opening the door to industrial espionage and sabotage with unsecure networks. A new development offers a particularly high level of security. Researchers are presenting the system at the embedded world trade fair from 25 through 27 February in Nuremberg.

Though it looks like something straight out of a science-fiction film, it will soon become a reality in the production halls of the future: products along the production lines will know where they are, which steps they have already completed, and what they still need to become a finished product. Production facilities will coordinate their work steps and exchange information with one another. There will be no need for technicians to set foot in the production halls for servicing, with machinery inspections carried out remotely instead. In a word: products and plants will be intelligent. This is also referred to as "Industry 4.0" -- meaning industry of the fourth generation, following mechanization, electrification and digitization.

There's one sticking point, though. Facilities will use a data network to communicate with one another, and even the products themselves will have to "log in." Human beings will use this network connection to control and monitor production, too -- to keep an eye on plant operation even if they don't happen to be in the production hall. On top of this, there will be remote maintenance and remote software updates. For all these functions, one thing is indispensable: secure access that keeps industrial pirates and saboteurs out. Certainly, businesses can use a normal Internet connection for this form of data traffic, securing it through a "Virtual Private Network," or VPN for short. "But there's something many people don't know: there are VPNs and there are VPNs -- and not every VPN access is secure," explains Bartol Filipovic, division director at the Fraunhofer Institute for Applied and Integrated Security (AISEC) in Garching, Germany.

That is why researchers have come up with a router that offers secure VPN access. Authorization and firewall functionalities provide additional access protection. The necessary security protocols can also be integrated directly in the industrial customer's plants and machinery. "The system is a software kit. We've already developed the basic components, and we can tailor them to fit the customer's specific requirements," Filipovic points out. The process takes around four weeks to complete. The researchers integrate simple systems at the same time, such as sensors in the pharmaceuticals industry that report filling levels or mixing ratios -- these, too, should not forward their information to unauthorized parties.

Physical protection: film sounds an alarm

On the one hand, the system protects companies from spies trying to hack their way into the network from off-site locations. On the other hand, it also outwits data thieves trying to coax secrets out of routers and circuit boards on location. A special film affixed to security-relevant casings immediately reports any attempts to unscrew the protective covering to access security-relevant data. Developed at AISEC, the film is affixed to the router casing, or directly onto the circuit boards -- the board containing key control elements such as microcontrollers, chips, diodes and other security-critical processing units -- and sealed shut at multiple points. If the router is switched off, all of the software it contains is stored in encrypted form. If it is in operation, though, it needs the decrypted program code. Each decryption key is a function of the properties of the protective film. And if these properties are changed -- by tearing open or drilling into the film to reach the circuit boards, for instance -- the film detects the attack in a few milliseconds and responds immediately: it deletes all of its unencrypted, security-relevant data.

Unauthorized intruders cannot get to the software. Data deletion is no problem for the business, however: all a company has to do is reinstall the software and affix a new protective film. "Combining software and film gives us an ideal security level," Filipovic says, "and the events of 2013 very clearly taught us just how important that can be." Secure communication software and hardware are fundamental to the evolution of production toward digitization and Industry 4.0; and protection against espionage, sabotage and product piracy is crucial to innovation and a strong competitive position.


View the original article here

Wednesday, May 14, 2014

Flaw in 'secure' cloud storage could put privacy at risk

Johns Hopkins computer scientists have found a flaw in the way that secure cloud storage companies protect their customers' data. The scientists say this weakness jeopardizes the privacy protection these digital warehouses claim to offer. Whenever customers share their confidential files with a trusted friend or colleague, the researchers say, the storage provider could exploit the security flaw to secretly view this private data.

The lead author of the new article is Duane C. Wilson, a doctoral student in the Department of Computer Science in the university's Whiting School of Engineering. The senior author is his faculty adviser, Giuseppe Ateniese, an associate professor in the department. Both are affiliated with the Johns Hopkins University Information Security Institute.

Their research focused on the secure cloud storage providers that are increasingly being used by businesses and others to house or back up sensitive information about intellectual property, finances, employees and customers. These storage providers claim to offer "zero-knowledge environments," meaning that their employees cannot see or access the clients' data. These storage businesses typically assert that this confidentiality is guaranteed because the information is encrypted before it is uploaded for cloud storage.

But the Johns Hopkins team found that complete privacy could not be guaranteed by these vendors. "Our research shows that as long as the data is not shared with others, its confidentiality will be preserved, as the providers claim," Wilson said. "However, whenever data is shared with another recipient through the cloud storage service, the providers are able to access their customers' files and other data."

The problem, Wilson said, is that privacy during file-sharing is normally preserved by the use of a trusted third party, a technological "middle-man" who verifies the identify of the users who wish to share files. When this authentication process is finished, this third party issues "keys" that can unscramble and later re-encode the data to restore its confidentiality.

"In the secure cloud storage providers we examined," Wilson said, "the storage businesses were each operating as their own 'trusted third party,' meaning they could easily issue fake identity credentials to people using the service. The storage businesses could use a phony 'key' to decrypt and view the private information, then re-encrypt it before sending it on to its intended recipient."

Wilson added, "As a result, whenever data is shared with another user or group of users, the storage service could perform a man-in-the-middle attack by pretending to be another user or group member. This would all happen without alerting the customers, who incorrectly believe that the cloud storage provider cannot see or access their data."

These storage services generally do not share the details of how their technology works, so Wilson and Ateniese substantiated the security flaw by using a combination of reverse engineering and network traffic analysis to study the type of communication that occurs between a secure cloud storage provider and its customers.

The researchers pointed out that their study focused only on three storage providers that claimed their customers' data would remain completely confidential. Other file-sharing services, such as Dropbox and Google Drive, make no pledge of privacy. Instead, they say that after a user's data is uploaded, it is encrypted with keys that are owned by the file-sharing service.

To solve the security flaw, the researchers recommend that the arrangements between customers and secure storage providers be revised so that an independent third party serves as the file-sharing "middle-man," instead of the storage company itself.

"Although we have no evidence that any secure cloud storage provider is accessing their customers' private information, we wanted to get the word out that this could easily occur," said Ateniese, who supervised the research. "It's like discovering that your neighbors left their door unlocked. Maybe no one has stolen anything from the house yet, but don't you think they'd like to know that it would be simple for thieves to get inside?"


View the original article here

Thursday, May 8, 2014

More secure communications thanks to quantum physics

One of the recent revelations by Edward Snowden is that the U.S. National Security Agency is currently developing a quantum computer. Physicists aren't surprised by this news; such a computer could crack the encryption that is commonly used today in no time and would therefore be highly attractive for the NSA.

Professor Thomas Walther of the Institute of Applied Physics at the Technical University of Darmstadt is convinced that "Sooner or later, the quantum computer will arrive." Yet the quantum physicist is not worried. After all, he knows of an antidote: so-called quantum cryptography. This also uses the bizarre rules of quantum physics, but not to decrypt messages at a record pace. Quite the opposite -- to encrypt it in a way that can not be cracked by a quantum computer. To do this, a "key" that depends on the laws of quantum mechanics has to be exchanged between the communication partners; this then serves to encrypt the message. Physicists throughout the world are perfecting quantum cryptography to make it suitable for particularly security-sensitive applications, such as for banking transactions or tap-proof communications. Walther's Ph.D. student Sabine Euler is one of them.

As early as the 1980s, physicists Charles Bennett and Gilles Brassard thought about how quantum physics could help transfer keys while avoiding eavesdropping. Something similar to Morse code is used, consisting of a sequence of light signals from individual light particles (photons). The information is in the different polarizations of successive photons. Eavesdropping is impossible due to the quantum nature of photons. Any eavesdropper will inevitably be discovered because the eavesdropper needs to do measurements on the photons, and these measurements will always be noticed.

"That's the theory" says Walther. However, there are ways to listen without being noticed in practice. This has been demonstrated by hackers who specialize in quantum cryptography based on systems already available on the market. "Commercial systems have always relinquished a little bit of security in the past," says Walther. In order to make the protocol of Bennett and Brassard reality, you need, for example, light sources that are can be controlled so finely that they emit single photons in succession. Usually, a laser that is weakened so much that it emits single photons serves as the light source. "But sometimes two photons can come out simultaneously, which might help a potential eavesdropper to remain unnoticed" says Walther. The eavesdropper could intercept the second photon and transmit the first one.

Therefore, the team led by Sabine Euler uses a light source that transmits a signal when it sends a single photon; this signal can be used to select only the individually transmitted photons for communication. Nevertheless, there are still vulnerabilities. If the system changes the polarization of the light particles during coding, for example, the power consumption varies or the time interval of the pulses changes slightly. "An eavesdropper could tap this information and read the message without the sender and receiver noticing" explains Walther. Sabine Euler and her colleagues at the Institute of Applied Physics are trying to eliminate these vulnerabilities. "They are demonstrating a lot of creativity here" says Walther approvingly. Thanks to such research, it will be harder and harder for hackers to take advantage of vulnerabilities in quantum cryptography systems.

The TU Darmstadt quantum physicists want to make quantum cryptography not only more secure, but more manageable at the same time. "In a network in which many users wish to communicate securely with each other, the technology must be affordable," he says. Therefore, his team develops its systems in such a manner that they are as simple as possible and can be miniaturized.

The research team is part of the Center for Advanced Security Research Darmstadt (CASED), in which the TU Darmstadt, the Fraunhofer Institute for Secure Information Technology and the University of Darmstadt combine their expertise in current and future IT security issues. Over 200 scientists conduct research in CASED, funded by the State Initiative for Economic and Academic Excellence (LOEWE) of the Hessian Ministry for Science and the Arts. "We also exchange information with computer scientists, which is very exciting," says Walther.

After all, the computer science experts deal with many of the same issues as Walther's quantum physicists. For example, Johannes Buchmann of the department of Computer Science at the TU Darmstadt is also working on encryption methods that theoretically can not be cracked by a quantum computer. However, these are not based on quantum physics phenomena, but rather on an unsolvable math problem.

Therefore, it may well be that the answer to the first code-cracking quantum computer comes from Darmstadt.

Bizarre quantum physics and encryption

A quantum computer could quickly crack current encryptions because it can test very many possibilities simultaneously, in the same way as if you could try all possible variations for a password at once. After all, according to the quantum physics principle of superposition, atoms, electrons or photons can have several states simultaneously; for example, they can rotate clockwise and counterclockwise at the same time.

However, if you were to measure a property of a particle, such as the direction of rotation, the superposition is lost. This phenomenon is useful for quantum cryptography. Eavesdroppers inevitably betray themselves because their measurements of the photon change the photon's characteristics. Moreover, quantum physics forbids them to copy the photon with all its properties. Therefore, they can not siphon off any information to retransmit the uninfluenced photons on to the sender of the message.

Story Source:

The above story is based on materials provided by Technische Universit?t Darmstadt. The original article was written by Christian J. Meier. Note: Materials may be edited for content and length.


View the original article here

Wednesday, December 25, 2013

Secure webmail service Lavabit suspends operation, citing legal issues

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

If you're interested in webmail security, you've probably heard of Lavabit.

It's a boutique webmail provider based in Texas, USA.

Lavabit differs from the big cloud email players, such as outlook.com and Gmail, by using encryption a bit differently.

It uses public key cryptography not only when you view your messages in your browser (that's the https:// part in the URL), but also when it stores your messages on its servers.

? Public key cryptography, secretly invented by the British in the early 1970s under the mildly confusing moniker of NSE (non-secret encryption), uses two keys, not one, to secure your data. Anyone can lock a file for you to read later, using your public key. You may publish this key openly. But only you can unlock the file, using your private key. As the name implies, this is the one you keep to yourself.

What that means is that the contents of your messages aren't just encrypted on Lavabit's disks so that they are protected from abuse if someone steals the servers.

The theory is that they can't be decrypted "in the cloud" by Lavabit, or anyone else at all, unless you hand over your private key, or someone takes it from you, lawfully or unlawfully.

If this sounds like something you've heard a lot about lately, that's probably because larger-than-life Kiwi entrepreneur Kim Dotom uses something similar in his MEGA file locker service, which opened with some fanfare early in 2013.

(Dotcom therefore not only keeps your content safe from surveillance or theft from his servers, he's also able to put his hand on his heart and say, "Your Worship, it was not possible for me to have known that those files were the complete works of Gene Roddenberry in remastered full HD video.")

Lavabit, as it happens, received a fair bit of publicity recently when it appeared that NSA whistleblower Edward Snowden, the man behind the PRISM revelations, was a user of its services.

Anyway, jumping back to the present: when I said that Lavabit "is a boutique webmail provider," that's not strictly true.

It used to be, but it isn't any more.

Founder Ladar Levison shuttered the service this week, or at least suspended it pending the outcome of some legal wrangles:

I have been forced to make a difficult decision: to become complicit in crimes against the American people or walk away from nearly ten years of hard work by shutting down Lavabit. After significant soul searching, I have decided to suspend operations. I wish that I could legally share with you the events that led to my decision. I cannot. I feel you deserve to know what's going on - the first amendment is supposed to guarantee me the freedom to speak out in situations like this. Unfortunately, Congress has passed laws that say otherwise. As things currently stand, I cannot share my experiences over the last six weeks, even though I have twice made the appropriate requests.

What can one say to that? (That's a rhetorical question. You're welcome to answer it in the comments, but please try to be brief.)

Will existing users, seemingly including at least 350,000 people, ever get their data back?

Levison certainly seems to hope so, noting that:

We've already started preparing the paperwork needed to continue to fight for the Constitution in the Fourth Circuit Court of Appeals. A favorable decision would allow me resurrect Lavabit as an American company.

What do we make of this?

If you know your Latin, you'll be familiar with the phrase post hoc ergo propter hoc.

It means "afterwards, therefore on account of," a logical fallacy that reminds you that you can't assume X caused Y simply because Y followed X.

Otherwise you'd be able to reach ludicrous conclusions such as that last night's high tide was the reason I had a cup of coffee after getting up this morning.

So the connection between Snowden and the suspension of Lavabit is so far merely chronological, not necessarily causal.

Let's hope, then, that Levison is able to revive the service, not just so his users can get back into their data, but also so we can find out the true cause-and-effect in this story.

Of course, there's a technological lesson in here for all of us, too.

Lots of people seem to think that cloud services remove the need for you to keep your own backups, on the principle that "you don't buy a dog and bark yourself."

But even if your cloud provider has impeccable credentials in respect of integrity and confidentiality, the availability of your data may be threatened by circumstances outside the control of either of you.

Follow @duckblog

Image of Dark Staffordshire Terrier cross breed howling (it looks like a bark to me) courtesy of Shutterstock.


View the original article here

Saturday, December 21, 2013

Facebook users worldwide (minus some mobile phones) now getting secure web browsing by default

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook initially introduced full-time HTTPS (secure HTTP) as an option in January 2011.

Before that, the site protected your password during login using HTTPS, but left the rest of your session unencrypted.

The change came about because, back in October 2010, a Firefox plugin called Firesheep was released as a proof of concept that sniffing an unencrypted session after login was all an attacker needed to hijack your account.

This made Facebook's new option welcome, but being opt-in meant it really didn't go far enough.

So, in an open letter in April 2011, Naked Security asked Facebook to improve privacy and safety by turning on HTTPS for everything.

In November 2012, Facebook finally did move to make secure browsing a default, at least for users in North America.

And on Wednesday, Facebook announced that it is now using HTTPS by default for all users, so the rest of the world has finally caught up. (Well, almost. Some mobile phones and carriers don't fully support HTTPS.)

Why did it take so long?

Because it involved a lot of moving parts, explains Facebook software engineer Scott Renfro.

Namely, it involved getting third-party application developers to upgrade, getting web-browser cookies to be compliant, controlling referrer headers, and migrating users to HTTPS without disrupting "in-flight" sessions, i.e. upgrading people while they're actually using the site.

Performance has also been a huge challenge, Renfro says, given the extra hoops browsers have to jump through with HTTPS:

In addition to the network round trips necessary for your browser to talk to Facebook servers, https adds additional round trips for the handshake to set up the connection. A full handshake requires two additional round trips, while an abbreviated handshake requires just one additional round trip. An abbreviated handshake can only follow a successful full handshake.

Here's an example from Renfro of how that extra latency can make users with already-slow connections suffer yet more, and how Facebook has eased the pain:

If you're in Vancouver, where a round trip to Facebook's Prineville, Oregon, data center takes 20ms, then the full handshake only adds about 40ms, which probably isn't noticeable. However, if you're in Jakarta, where a round trip takes 300ms, a full handshake can add 600ms. When combined with an already slow connection, this additional latency on every request could be very noticeable and frustrating. Thankfully, we've been able to avoid this extra latency in most cases by upgrading our infrastructure and using abbreviated handshakes.

Facebook's work on secure browsing is most certainly not done, mind you: the company says it's still working with mobile phone vendors to make it happen there.

Renfro calls HTTPS by default a "dream come true" — a goal that the company's network, security, traffic, and security infrastructure teams have been working on for years.

When Facebook first rolled out HTTPS by default, Naked Security was stuck with a heap of "Dislike" t-shirts that didn't seem appropriate anymore, so the team gave them away to readers.

Sorry, I don't know of any plans to print up "Like" t-shirts over the news that HTTPS by default is finally, for the most part, a dream come true.

But, Facebook engineers, here are two big, virtual thumbs-up for the work you've done. Let's hope it works out well for the mobile outliers, as well.

Follow @LisaVaas

Follow @NakedSecurity


View the original article here

Thursday, October 3, 2013

Not good enough, Oracle - promises to secure Java are too little, too late

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

java-170Oracle has promised to work harder to make Java more secure.

Given the constant flood of high-profile, heavily-exploited vulnerabilities, are Oracle's new ideas going to be enough to save this piece of software from drowning in bad vibes?

In a lengthy blog post last week, the head of Java development, Nandini Ramani, summed up what's been done to "address issues with the security-worthiness of Java".

A passing mention is made to "several reports of security vulnerabilities in Java".

That "several" refers to a constant barrage of vulnerabilities, patches, zero-days, more patches and more vulnerabilities, going back several years.

Oracle blog post

Java has been been home to a glut of security dangers for a long time now. In our Virus Bulletin prevalence reports, we combine data from a wide range of sources, and Java has been in the top five all this year and was the third biggest detection type overall in 2012.

Thanks to its cross-platform design, Java holes can hit multiple operating systems and have been behind some of the most high-profile and damaging attacks of the last year or two.

There are a few positive things to note in Oracle's blog post, such as the separation of client and server-side, and improved (though far from perfect) sandboxing, as many vulnerability experts have conceded.

Increasing patch releases to four times a year (plus extras in emergencies) is, of course, a step in the right direction, although the industry widely agrees that monthly would be better. Sure, frequent patch cycles are a headache for admins, but surely it's better to have a small headache once a month than a massive migraine four times a year.

So, I suppose it is a good thing that Oracle are trying to face up to the problems with Java, even if it is pushing much of the blame onto issues at Sun, before the Oracle acquisition. It's taken too long to get this far though, and things are still moving far too slowly.

spilt-coffee-170The standard advice from Naked Security has long been to disable Java in the browser at least, and to avoid installing it at all if it's not *absolutely* required.

If something is this leaky and dangerous, there must be a better option. Granted, in some businesses with creaky legacy setups, it isn't easy to adopt a new approach, but given how long this has been a major issue, many must be at least considering moving away from the platform.

For some time now, numerous voices have advocated dropping Java and called for its rapid retirement, as the tragic roller-coaster of disasters has unfolded. Now Oracle says they're stepping up to the plate, ready to do what they can to fix it, but surely it's a case of too little, too late.

If Java is entrenched in your business, I'd suggest getting busy with looking for an alternative. If you're still allowing it in your browser, just stop now.

Follow @virusbtn
Follow @NakedSecurity


View the original article here

Tuesday, March 26, 2013

IE 10 is more secure, so here's a Microsoft tool to prevent you updating by mistake

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

An alert writer over at the The Register has spotted a funny thing.

Microsoft just released a free tool to stop you upgrading to Internet Explorer 10 on Windows 7 and Server 2008 R2:

"Big deal," you say. "There is no IE 10 for Windows 7, so it doesn't sound like much of a tool to me."

Except, as The Reg points out, the availability of the tool is a sort of omen: it surely means that IE 10 for Windows 7 must be nearly ready to drop for real.

Ironically, then, Microsoft is making sure that as soon as IE 10 is ready, you're already ready to avoid it.

Sounds rather odd, but sysadmins in any but the smallest organisations tend towards trepidation over Internet Explorer updates, in case some legacy business application should go pear-shaped.

And there's the real irony: that Microsoft should need to produce a one-off anti-update tool to help you sidestep a forthcoming automatic update, as a way of discouraging you from turning off automatic updates altogether.

A sort-of "lesser of two evils" solution for change control conservatives.

Microsoft has been there before, with IE 6 staying on the shelves so far past its use-by data that the company came up with iecountdown.com, an entire website devoted to weaning people off from IE6 with an unrepentant clarion call of, "Friends don’t let friends use Internet Explorer 6."

The technique for suppressing IE 10 is pretty straightforward. Here's an excerpt from the batch-language version:

set REGBlockKey=HKLM\SOFTWARE\Microsoft\Internet Explorer\Setup\10.0set REGBlockValue=DoNotAllowIE10REG ADD "%REGBlockKey%" /v %REGBlockValue% /t REG_DWORD /d 1 /f

Even with this magic registry value set, you can manually install IE 10 (or manually force an update with WSUS) if you want to override the block.

When you're ready to let Windows Update push out IE 10 entirely automatically, you just remove the DoNotAllowIE10 registry value:

set REGBlockKey=HKLM\SOFTWARE\Microsoft\Internet Explorer\Setup\10.0set REGBlockValue=DoNotAllowIE10REG DELETE "%REGBlockKey%" /v %REGBlockValue% /f

If you want someone's word other than Redmond's that IE 10 is more secure that earlier browsers, consider the prizes on offer at this year's PWN2OWN competition for browser hacking.

IE 10 is worth $100,000 for a successful exploit; IE 9 will only fetch you $75,000:

So when will IE 10 drop onto unblocked Windows 7 PCs?

Sadly, we can't tell you that. For users not afraid of upgrading their browser, the sooner the better!

Follow @duckblog


View the original article here

Sunday, July 15, 2012

How secure are Apple's iPhone and iPad from malware, really?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Anti-virus veteran Mikko Hypponen made an interesting remark on Twitter yesterday:

"iPhone is 5 years old today. After 5 years, not a single serious malware case. It's not just luck; we need to congratulate Apple on this."

Tweet from Mikko

I'm not so sure I can agree.

Of course, there were the Ikee and Duh worms back in 2009, although one could dismiss them as not "serious" malware cases because they only infected iPhones that had been jailbroken without following the critical step of changing the default root password.

Speaking of jailbreaking, this brings up an interesting point about iOS device security.

Jailbreaking

Virtually every version of iOS has been quickly jailbroken (that is, modified to allow installation of apps and hacks not authorized by Apple or the mobile carrier).

Jailbreaking is accomplished by exploiting security vulnerabilities in iOS. The same exploits used to jailbreak (an arguably legitimate hack) could just as easily be used to infect an iOS device with malware.

Twitter reply from Josh

And what happens if you get malware on your iPhone, iPad, or iPod touch? You wouldn't necessarily know it. Not all malware has big, flashy alerts like FakeAlert malware. Some is quiet and surreptitious like Flame.

And what's worse, you wouldn't be able to detect or remove iOS malware easily because Apple doesn't allow full-featured, real-time scanning anti-virus software in the iOS App Store.

Meanwhile, you can get free anti-virus software for Android from Sophos and other vendors.

Android store under fireIn spite of the existence of Android anti-virus software, when you compare Android with iOS, there's certainly a big difference in terms of device security.

Android app stores (including Google's own) have a history of letting in malware apps, while Apple's more restrictive App Store policies and more careful application vetting tend to keep iOS users safer.

So perhaps Hypponen is right that we should be congratulating Apple, but not for the lack of iOS malware. Rather, Apple should be commended for keeping the App Store relatively safe.

I say "relatively safe" because security researcher Charlie Miller has previously figured out how to break the App Store anti-malware model using a flaw in the iOS code signing enforcement mechanism, and there have been reports of developers working around other App Store restrictions with clever tricks; see the Security Now! episode 330 transcript and search for "vetting."

And just earlier this month, a clearly bogus app purporting to be Microsoft Word 2012 was mistakenly approved by Apple, and appeared in the iOS App Store.

Bogus Microsoft Word 2012 app

Apple still has a long way to go in making the iOS platform more secure, for example not making users wait months for security patches.

It took Apple four months after the release of iOS 5.0.1 for the next security update to become available, iOS 5.1, which patched a whopping 81 vulnerabilities. That's too long. I realize that 5.1 added a lot of features, but Apple could have easily patched the 81 vulnerabilities in a security-only update and called it "iOS 5.0.2" while working on adding new features to 5.1, but they didn't do that.

Meanwhile, the jailbreaking community are masters at exploiting undisclosed vulnerabilities, and ready to exploit them whenever Apple releases a new version of iOS. If these hobbyists can collect and take advantage of vulnerabilities, just imagine what others (a government perhaps?) could do.

And this isn't fantasy, defense contractors are already openly hiring for people with experience of exploiting vulnerabilities on mobile devices.

Job description from Booz Allen Hamilton

The history of jailbreaking iPhones and iPads has provided plenty of evidence that smartphone users are being made to wait too long to get security updates for their devices.

So yes; good job, Apple. But you can do a lot better.

Follow @theJoshMeister

View the original article here