Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Last week, Apple showed that it is getting more serious about security by turning all strict about the version of Flash you're allowed to use in Safari.
OS X users received an automatic update via Apple's basic threat protection system, Xprotect, to lock old Flash player plugins out of your browser. If your browser is Safari, of course.
The idea is simple, and a good one.
Once Apple thinks you've had enough time to get around to updating Flash (two days in the case of the most recent update), it issues a new Xprotect signature that pretty much forces your hand.
Presumably (and we don't know, because this is the first time Apple has done this for Flash, though it did something similar for Java back in January 2013), the amount of time you get before Apple drops the hammer will vary depending on the apparent risk.
The most recent update was an emergency fix for an in-the-wild exploit that was being used against both Windows and Mac users.
Two days to patch an at-risk computer that you use for browsing is brisk, but nevertheless seems pretty reasonable to me.
According to Apple's notification, the Xprotect update turned up on 28 Feb 2013, and produces a warning like this inside the window that Flash is trying to use:
Clicking on it takes you to an OS X supplied dialog that explains more:
From here, of course, at least as things stand today), there's not much that Apple and OS X can do except to shovel you into Adobe's update process, so, as Apple explains, the dialog doesn't achieve much more than taking you to Adobe's Flash Player installer website.
You have to complete the necessary process yourself:
As I've mentioned previously, Adobe's update process is straightforward, but mildly intrusive, as it requires you to shut down many applications, including the browser from which you got to Adobe's download page in the first place.
If you back off at this point so you can come back later when it's more convenient, Adobe will will re-download the whole installer, which is a further annoyance for those on the road, who may be paying over the odds for bandwidth.
But it works, and it's worth doing: Flash, like Java, is a popular, multi-platform attack vector for the Bad Guys, with three updates in February 2013 alone (on the seventh, the twelfth and the 26th of the month).
Don't forget that you can check whether you have Flash active in your browser, and, if so, what version you are using by visiting Adobe's Flash/About page.
This also handily shows you what versions are current on which platforms:
Solaris users will be surely be happy to note they're still on the list, albeit a couple of point releases behind.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
After being hacked, Evernote, quite responsibly, has sent out emails to its users informing them of the security breach - and letting them know that it has decided to reset all passwords.
The email goes on to give some password advice - including a warning:
Never click on 'reset password' requests in emails - instead go directly to the service.
That's a very sound piece of advice, because of the obvious threat - after millions of Evernote customers had their usernames and email addresses stolen - of phishing email attacks.
But take a closer look at the email that Evernote has sent out, with the subject line "Evernote Security Notice: Service-wide Password Reset":
Uh-oh, in the same email that Evernote tells users not to click on 'reset password' requests sent via email, they have clickable links.
And what might make some recipients pause for thought is that the links don't go directly to evernote.com, but instead link to a site called mkt5371.
Now, before you panic that someone is attempting to phish your Evernote credentials with a craftily-designed email, just relax.
This was just carelessness on Evernote's part. mkt5371 is a domain owned by Silverpop, an email communications firm who Evernote has clearly employed to send emails to its 50 million or so affected users.
The links in this case *do* end up taking you to Evernote's website - but go silently via Silverpop's systems first.
Presumably that's so Evernote can track and collect data on how successful the email campaign has been.
That's a technique commonly used in a normal marketing email communications, but looks very out of place in an email about a security breach which tries to hammer home the point to "Never click on 'reset password' requests in emails - instead go directly to the service".
You could certainly understand why someone freaked out by the Evernote security breach would be alarmed to receive an email with links like that.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Evernote, the online note-taking service, has posted an advisory informing its near 50 million users that it has suffered a serious security breach that saw hackers steal usernames, associated email addresses and encrypted passwords.
It's not clear how the hackers managed to gain access to Evernote's systems, or how long the hackers had access to Evernote's account information.
However, in an interview with TechCrunch, Evernote said that they had first noticed suspicious activity on February 28th.
The good news is that no payment details were stolen, and according to the company the hackers were not able to access notes that users had stored on the Evernote service.
Furthermore, it sounds as though the passwords were encrypted, using hashes and salting to prevent login details falling into the wrong hands. (It would be reassuring - of course - to have more details shared by Evernote of how the passwords were hashed and salted).
The investigation has shown, however, that the individual(s) responsible were able to gain access to Evernote user information, which includes usernames, email addresses associated with Evernote accounts and encrypted passwords. Even though this information was accessed, the passwords stored by Evernote are protected by one-way encryption. (In technical terms, they are hashed and salted.)
While our password encryption measures are robust, we are taking additional steps to ensure that your personal data remains secure. This means that, in an abundance of caution, we are requiring all users to reset their Evernote account passwords. Please create a new password by signing into your account on evernote.com.
What's not good news is that the hackers now have access to the usernames and email addresses of Evernote customers. It is easy to imagine how this information could be abused - for instance, the hackers could send out spam emails to those users claiming to come from Evernote, and trick them into visiting a malicious website.
And, of course, it's another cautionary tale about the risks which can exist with trusting the cloud to look after your personal information. Evernote sounds to me like it's another online service that would benefit from providing its users with additional account security - such as two factor authentication.
Evernote advises users to choose a strong password, and to be suspicious of reset password links sent to users via email. Furthermore, everyone should ensure that they are not using the same password on multiple sites.
Evernote appears to have acted reasonably rapidly in response to this security incident, and it will be interesting to see if they share any more information about how the hack might have occurred in the coming days.
Further reading: Evernote shoots itself in foot over "never click on 'reset password' requests" advice
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
For over 12 centuries an intense battle has been fought between the code-makers and the code-breakers.
We previously talked about some ciphers that have been defeated and the impact it had. However, despite decades (or centuries!) of cryptanalysis there are many ciphertexts which still successfully conceal their contents.
Here's a roundup of my top ten, with links to groups actively tackling them provided where possible.
Dorabella – 1897, Wolverhampton, UK, Yahoo! Group
The Enigma Variations isn't the only cryptic legacy of the renowned English composer Sir Edward Elgar. In a letter sent to his close friend Dora Penny (‘Dorabella’) Elgar included an encrypted message consisting of 87 symbols.
Dorabella was never able to understand the message herself and despite a couple of decryptions being proposed over the years, there is no universally accepted solution.
The same symbols have also been found on a 1886 Liszt concert programme of Elgar’s (the ‘Liszt fragment’) which suggest perhaps a musical solution, though a 1920’s notebook of his contains the same symbols and practice attempts at encryption.
Other symbols found on these pages could contain the key to decryption.
Beale Papers – 1885, Virginia, US
Legend tells us of three ciphertexts published in an 1885 pamphlet by an anonymous author, which reveals the location of hidden treasure discovered by Thomas J. Beale and buried somewhere in Virginia in 1820.
The author depicts the story of the gold discovery, how they came into possession of the three messages, and how they cracked the second of these. They show that this second message is a book cipher with the American Declaration of Independence as the key and the decryption of it outlines the contents of the treasure (worth around $20 million).
Treasure hunters should note, however, that textual analysis of the pamphlet suggests that both the pamphlet and the ciphertexts were written by the same person, leading many people suspect it to be a hoax.
The Zodiac Killer – 1968-9, Northern California, US
The identity of a serial killer responsible for attacks against of at least four men and three woman in the US, is unknown to this day. During the period of these attacks, the self-dubbed 'Zodiac' sent a series of taunting messages to the police and newspapers which contained a total of four ciphertexts.
One of these has been decrypted and was shown to be a homophonic substitution cipher (multiple symbols per letter) using 57 symbols to encrypt 23 different letters. Warning: Explicit themes below.
I LIKE KILLING PEOPLE BECAUSE IT IS SO MUCH FUN IT IS MORE FUN THAN KILLING WILD GAME IN THE FORREST BECAUSE MAN IS THE MOST DANGEROUE ANAMAL OF ALL TO KILL SOMETHING GIVES ME THE MOST THRILLING EXPERENCE IT IS EVEN BETTER THAN GETTING YOUR ROCKS OFF WITH A GIRL THE BEST PART OF IT IS THAE WHEN I DIE I WILL BE REBORN IN PARADICE AND THEI HAVE KILLED WILL BECOME MY SLAVES I WILL NOT GIVE YOU MY NAME BECAUSE YOU WILL TRY TO SLOI DOWN OR ATOP MY COLLECTIOG OF SLAVES FOR MY AFTERLIFE ABEORIETEMETHHPITI
(Original typos included.)
The meaning of the last 18 letters is unclear, and the remaining three ciphertexts have never been successfully decrypted. The messages sent from the Zodiac at this time are clearly authentic, and cracking the other ciphertexts could finally reveal the killer's identity.
Ricky McCormick's Notes – 1999, Missouri, US
Here's another case of an unsolved cipher which could lead to the identification of a murderer. In June 1999, the body of 41-year-old Ricky McCormick was discovered in a cornfield in Missouri, US. Twelve years later, it came to light that two encrypted notes were found in his pockets.
Though considered by the FBI as a homicide, McCormick's killer has never been caught nor the notes decrypted. None of McCormick's family members know how to read his notes, and in the words of FBI crypto-chief Dan Olson, “We are really good at what we do, but we could use some help with this one.”
Anyone with information on how to crack the cipher should submit their ideas directly to the FBI.
Voynich Manuscript – 15th Century, Italy
Purchased by book dealer Wilfrid Voynich in 1912, the 240-page Voynich manuscript has been labelled one of the world's most mysterious manuscripts.
It consists of six distinct sections, containing undecipherable text alongside herbal, astronomical, biological, cosmological and pharmaceutical illustrations.
The text uses over 170,000 symbols and displays statistical properties akin to that of natural languages. While further statistical analyses point towards the manuscript being a hoax, it is generally considered that it is too elaborate for this to be the case.
Either way, the Voynich manuscript has attracted the attention of many cryptanalysts over the years, most notably the military cryptanalyst William Friedman.
Linear A – Ancient Crete, 18th Century BCE
Linear A is one of over 25 writing systems that, unlike Hieroglyphics, remain undecipherable.
Clay tablets unearthed by archaeologists on the Greek island of Crete hint at an ancient Minoan empire, possibly the origins of the Greek legend 'Theseus and the Minotaur'.
Symbols from one set of tablets (dating from 1450 to 1375 BCE) are from a language known as Linear B, of which a decipherment was finally published in 1953. The decipherment of an older set of tablets (dating from 1750 to 1450 BCE) has never been accomplished.
These inscriptions, dubbed Linear A, are clearly the written system that Linear B was derived from, yet the understanding of Linear B sheds no light on Linear A.
D'Agapeyeff Cipher – 1939, Oxford, UK, Yahoo! Group
It is somewhat of a tradition for books on the topic of cryptology to contain a cipher left as a challenge to readers. The cipher challenge published in D'Agapeyeff's Codes and Cipher remains unsolved.
Ignoring the final three zeros as padding, the message consists of 196 (14²) two-digit pairs, the first digit being one of {6, 7, 8, 9, 0} and the second being one of {1, 2, 3, 4, 5}. This allows for encryption of 25 letters (5x5 matrix) and should be fairly straightforward to crack.
D'Agapeyeff, however, later admitted to having forgotten how he encrypted his impenetrable message and the cipher was removed from future editions of the book. It is very likely that the message has never been cracked due to errors in the encryption.
Kryptos – 1990, CIA Headquarters, US, Yahoo! Group
Another cipher challenge lies in the grounds of the US Central Intelligence Agency; a cryptographic sculpture designed by artist Jim Sanborn and placed there in 1990.
Kryptos falls into the category of 'partially solved', with three ciphertexts having been cracked but the fourth and final remaining a mystery and actively pursued by amateur and professional cryptanalysts alike.
The first two are encrypted with the Vigenère polyalphabetic substitution ciphers, while the third is an elaborate transposition cipher. These first three ciphers allegedly contain a clue to unlock the elusive final cipher.
Kryptos has since been referenced in popular culture multiple times (it is used as a theme in Dan Brown's The Lost Symbol) and is set to continue to baffle intellectual minds for many years to come.
Blitz Ciphers – World War II, London, UK
All of the ciphertexts discussed so far are well documented and have been analysed by many over the years. On the contrary, there is little known about the so called 'Blitz' ciphers discovered during World War II in a bombed cellar in East London, UK, but only recently published last January.
Photographs taken of some of the papers found in a wooden box concealed in the cellar wall show around 50 distinct calligraphic symbols. The origins of these cryptic documents are unknown, though it is speculated that they could potentially be 18th century Freemason ciphers.
More information and analysis is definitely required to rule out possibility of it being another a hoax.
D-Day Pigeon – June 6th, 1944, France
Last November, the remains of a messenger pigeon were discovered in a chimney in Surrey, UK, with the attached message intact.
The message, addressed to ‘X02’ from ‘W Stot Sjt.', consists of 27 five-letter groups and is one of two duplicate messages sent from Nazi-occupied France during the D-Day landings.
The encryption used most likely relies on a codebook with each group of letters having a specific meaning. The message was possibly also super-enciphered (cipher of a cipher) with a one-time pad (theoretically unbreakable cipher).
This means without the authentic cryptographic material used at the time it is impossible to verify a proposed decryption.
The official statement from GCHQ reads, "Hundreds of these proposed solutions have been carefully examined by our expert cryptanalysts at GCHQ. So far none have proved credible.”
Leave a comment below, or tweet me @julianbhardwaj with your ideas on how/if any of these ciphertexts could ever be solved!
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
If you are one of the more than two million people who follow Donald Trump on Twitter, you might have seen an unusual tweet from the impossibly coiffed real estate mogul yesterday.
Rather than plugging his "The Apprentice" American TV show, or chirping up on a political issue, the multi-millionaire appeared to have chosen to quote a lyric by hip-hop artist Lil' Wayne.
These hoes think they classy, well that’s the class I’m skippen
It turns out that Donald Trump had, in reality, had his Twitter account hacked.
The offending tweet was swiftly erased, and "the Donald" - who doesn't believe in cover-ups - posted an explanation:
My Twitter has been seriously hacked--- and we are looking for the perpetrators.
Twitter will soon be irrelevant if lowlifes are so easily able to hack into accounts.
Of course, things could have been much worse. Imagine if Donald Trump's hijacked Twitter account had been exploited to post a link to a malicious website, for instance. With some clever social engineering ("Win free tickets for 'The Apprentice' grand final"?) you can easily picture many people clicking on a dangerous link and potentially infecting their computers with malare or having their passwords phished.
Quite how Trump's account was compromised is unclear, but a reasonable guess would be that he had either chosen a weak, easy-to-guess password, or that he was using the same password in multiple places. Never a good idea.
Multi-millionaire Trump stopped short of fellow celebrity Jeremy Clarkson, who vowed to kill the people who hacked his Twitter account earlier this week.
Have you joined thousands of others, and become a loyal listener to the "Chet Chat" yet?
Sophos has been recording security-related podcasts since 2006.
One of our most popular shows is the regular "Chet Chat" series, hosted by Senior Security Advisor Chester Wisniewski.
Chet discusses the latest security news with a series of experts, and offers actionable advice on what you and your company should do about it.
The latest "Chet Chat", episode 103, features Chet and popular guest Paul "Duck" Ducklin, who bring you their customary and entertaining mixture of insight, expertise, scepticism, and advice:
(24 February 2013, duration 15:24 minutes, size 9.3 MBytes)
Sophos Security Chet Chat #103 (MP3)
The Chet Chat typically lasts about 15 minutes, so why not make it a regular quarter-hour in your lunchtime security fix, or listen to it as part of your commute?
And why not take a look at the back-catalogue of Sophos Podcasts in our archive? We have loads of interesting stuff for your listening pleasure.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Unless you work in the customer support business, it's possible you haven't even heard of Zendesk.. but chances are that you are familiar with some of the companies who use Zendesk's customer service portal to answer questions and build an online support community.
Big names that use Zendesk include Tumblr, Twitter and Pinterest.
And - unfortunately - hackers broke into Zendesk's systems this week and accessed the email addresses of Tumblr, Twitter and Pinterest customers who had attempted to get support.
Zendesk has published more details on its blog, under the refreshingly frank title of "We've been hacked":
We’ve become aware that a hacker accessed our system this week. As soon as we learned of the attack, we patched the vulnerability and closed the access that the hacker had. Our ongoing investigation indicates that the hacker had access to the support information that three of our customers store on our system. We believe that the hacker downloaded email addresses of users who contacted those three customers for support, as well as support email subject lines. We notified our affected customers immediately and are working with them to assist in their response.
Twitter has contacted affected users, and reassured them that passwords were not compromised as part of the Zendesk customer breach:
Emailing a small percentage of Twitter users who may have been affected by Zendesk's breach. No passwords involved. zendesk.com/blog/weve-been…— (@Support) February 22, 2013
For its part, Tumblr has sent out emails to its affected users, as you can see in the following example shared by a Naked Security reader:
You can't imagine that Tumblr, Twitter or Pinterest are delighted to find themselves in a position to send such emails to customers. Even though they weren't to blame, their customers are impacted by Zendesk's security breach.
Even though passwords were not taken as part of this hack (Zendesk wouldn't have had access to those - which is a relief), this is still a serious security incident which could have unpleasant ramifications.
For instance, the hackers who have stolen the email addresses could now craft malicious emails to the email addresses of Twitter, Pinterest and Tumblr users and try to trick them into clicking on dangerous links or attachments.
My advice if you are one of the unfortunate people impacted by the Zendesk breach is to - as always - be very careful about emails you receive, and be cautious about opening unsolicited email attachments or clicking on embedded links.