Google Search

Sunday, December 8, 2013

Sysadmin day? *SYSADMIN DAY*? Angry techie takes against Naked Security...

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Not everyone is pleased that we've been asked to recognise the efforts of our IT staffers today. No sooner had we launched our Worst things to ask a sysdmin poll than we received an anonymous email from a disgruntled sysadmin called Simon Oliver Meone. He questioned the sincerity of, well, the whole world, really. Having binned his mail to start with, we suddenly thought you might benefit from his jaundice. So we extracted his email from the virtual wastebasket, smoothed it flat and published it here.

\sarcasm{on}

Dear Naked Security,

\sarcasm{off}

Just saw your smug little piece about being nice to sysadmins today.

SYSADMIN APPRECIATION DAY?

Did I read that correctly? I'll tell you what I think of that! Read my lips...on second thoughts, you never bothered to learn how to do that, did you? Did you never stop to wonder how it is I seem to know what you want before you reach my desk? Apart from reading your email and your instant messages, of course, which is actually the easiest way to do that trick, if I'm honest.

Because *I* learned to lip read, that's why, so I know what you're saying from a distance. You're probably wondering why I bothered, but then most things to do with technology probably make you wonder, so that was hardly worth saying.

The reason should be obvious - it's so I don't need audio while I'm watching all those old episodes of Star Trek that I stashed in the hidden P2P directory on your laptop. That means I am able to be attentive and get in a good couple of pertinent and toadying observations during those interminable monthly corporate conference calls, because I can *listen* to the call while *watching* Kirk and Spock do exciting intergalactic stuff.

You, on the other hand, have to *watch* the conference call while *listening* to Nigella Lawson do something culinary with a root vegetable that appears to fill you with wonder, so you never get to show appreciation to your office overlords at just the right time.

And why is that you lot are so star-struck by those celebrity chefs?

There's one of them that goes around pouring liquid nitrogen on things to make these amazing desserts, and you're like, "Wow! Check that chemical reaction!' Firstly, nitrogen is inert. Cooking with liquid nitrogen isn't CHEMISTRY, it's PHYSICS. Secondly, who do you think invented the use of cryogenics in the kitchen? OK, in our case, in the server room.

How do you think sysadmins make ice cream? We *pioneered* the use of industrial-grade processes to prepare individual meal portions!

Actually, I have to say that I met a Navy noncom once who was way, way ahead of our tribe in the sledgehammer-to-crack-nuts school of gastronomy. Did you know that if you lash one of those single-cup stove-top espresso makers to the breech of a 5"/54 Mark 45, the exothermic violence when the weapon fires gives you a perfect shot with every shot?

Anyway, you've got this poll going on where you are trying to teach people not to say things that you think sysadmins don't like to hear, such as "You don't look very busy" and "We're out of coffee."

And that is why I am writing to you to complain.

I LIKE to hear that you think I don't look very busy, because I AIM not to look very busy, and I do that by NOT being very busy.

Think about it.

I spent years - at school, at home, at college, in my first job, in my second job, in between home-made ice creams (try pouring chocolate milk into liguid N2 and tell me it's not superb), in my (m..n)th jobs for 2 < m <= n - learning how to program.

I can program in Bash, Python, C, D, Haskell, ocaml, Lua, Befunge, Erlang - any language at all except Java, in fact, which I refuse to learn on doctrinal grounds - so I don't NEED to be busy.

I've BEEN busy, writing code to do everything for me.

I've even written some Perl modules that watch those Star Trek episodes for me while I'm listening to conference calls, using advanced image processing to detect when the USS Enterprise reaches a new planet. Then it sends me an IM, so I can stop working on the other code I'm writing and watch only the good bits.

(The new code will respond automatically to the IMs about the new planets, and start watching for me to make sure it's not a new planet I already know about, and then I won't need to be distracted as much by Star Trek, leaving me free to catch up on Dr Who while I'm watching Star Trek while I'm on the conference calls.)

And the other thing I want to complain about is that bit about not saying, "We're out of coffee."

I LIKE it when you tell me *you're* out of coffee. Why would *I* be out of coffee just because *you* are?

The question you really need to ask is, "Why are *we* out of coffee, while *you* are not?"

See what I'm saying?

Yours sincerely,

S. O. Meone

System Administrator (Smartest Amidst Irony)

Follow @duckblog

PS. Sysadmins do love their users really. Especially users bearing pizza. Even if it's made using conventional convection cooking techniques. So please enter, and get your colleagues to enter, the Sophos Win-A-Pizza-Party competition, and make some sysadmin's day! Click here to enter. (Only residents of the UK or the USA are eligible to win. Sorry about that.)


View the original article here

Saturday, December 7, 2013

Data Breach Week, SIMs cracked, carders busted - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

How safe is the SIM in your mobile phone? Could it be remotely infected with malware?

Possibly - watch this week's 60 Second Security and find out more!

? Can't view the video on this page? Watch directly from YouTube. Can't hear the audio? Click on the Captions icon for closed captions.

It feels like we just had "Data Breach week", with Apple's Developer Center, Ubuntu Forums, Lakeland and even Stanford University having "better change your password" moments.Crypto researcher Karsten Nohl claims he's found a way to recover remotely the secret key buried in older SIM cards, so he can sign any code he wants and put it on your phone.Five sidekicks of notorious TJ Maxx hacker Albert Gonzalez, currently serving 20 years, have been charged with carding crimes in New Jeresy and New York.

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Apple, balic, Blackhat, bust, Cryptography, data breach, DES, developer center, FBI, Gonzalez, karsten nohl, Lakeland, nohl, salt, SIM, Stanford, TJ Maxx, Ubuntu, university


View the original article here

Friday, December 6, 2013

PRISM: 50% of Americans approve of NSA's internet spying program

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

According to data from the Pew Research Center, 50% of Americans approve of their government’s collection of telephone and internet data as part of anti-terrorism efforts.

The research was conducted by Pew between July 17 - 21, just six weeks after Edward Snowden blew the whistle on PRISM - the US government's omnipresent internet spying initiative.

This apparent approval by a slim majority of Americans (50% approve and 44% disapprove) is all the more surprising given what else the survey has to tell us.

Only 18% believe that data collection is limited to metadata22% believe the program is limited to anti-terrorism30% believe courts provide adequate limits on what's collected

It seems that the American public doesn't believe what it has been told about PRISM by the government, nor that its citizens are adequately protected by their courts.

Indeed 63% believe that the NSA is logging the contents of emails and phone calls despite President Obama's insistence that "Nobody is listening to your telephone calls".

Perceptions of the Governments Data Collection Program

Perhaps most surprisingly, the program garners a 47% approval rate even amongst that very group of respondents who believe that the government is recording phone calls and emails.

In fact the program still has a 40% approval rating even amongst people who believe their own emails and phone calls have been logged.

The basic split between those who approve and those who don't was mirrored in the US Congress last week when the House of Representatives voted by a slim majority (50% vs 47%) to continue funding the NSA's internet dragnet.

I think that vote encapsulates the significance of these numbers. Whilst PRISM does not enjoy runaway support, the revelation of its existence, and all that its existence implies, simply has not energised people in the way many of us expected it would.

Lindsay MillsIf the TV and print media are any reflection of the public mood then Snowden's uncovering of a vast domestic surveillance grid is not nearly as significant as the international game of Where's Wally/Waldo that followed. Or the fact that his girlfriend is a pole dancer with a diverting range of self portraits.

Within the computer security community at least, there are signs of life.

At the same time as Pew was running its research, Joseph Bonneau became the inaugural recipient of the NSA's award for the Best Scientific Cybersecurity Paper for The science of guessing: analyzing an anonymized corpus of 70 million passwords.

Although he accepted the award, he also took the opportunity to say via his blog that he thought a free society is not compatible with the NSA in its current form.

A situation for which he gives the spooks a pass, laying the blame squarely at the feet of his nation's politicians.

...I’m ashamed we’ve let our politicians sneak the country down this path.

In accepting the award I don’t condone the NSA’s surveillance. Simply put, I don’t think a free society is compatible with an organisation like the NSA in its current form. Yet I’m glad I got the rare opportunity to visit with the NSA and I’m grateful for my hosts’ genuine hospitality ... It affirmed my feeling that America’s core problems are in Washington and not in Fort Meade.

The apparent ambivalence of the US public at large to the government's vast data collection effort, in spite of the obvious concerns about it, can perhaps be attributed in part to the extraordinary power that the threat of terrorism invokes.

The Pew Research Center's own research into survey wording showed that when internet surveillance was described as “part of anti-terrorism efforts” it garnered 9% more support than when this goal was not mentioned.

Whilst fighting terror is certainly a real and pressing task for government we can be sure that politicians have shown a willingness to use terror as a smokescreen in the past.

A concern that Justin Amash himself raised when introducing his bill to curtail NSA funding for PRISM:

They'll tell you that the government must violate the rights of the American people to protect us against those who hate our freedom.

Reassuringly there are also signs within the survey that invoking the threat of terrorism isn't a blank cheque.

Survey respondents were asked to say whether government anti-terror policies had 'not gone far enough to protect the country' or 'gone too far in restricting civil liberties'.

Pew has asked that question twelve times since 2004 and this was the first time that more people have expressed greater concern about civil liberties than security.

Govt Anti-Terror Policies

Follow @NakedSecurity

View the original article here

Thursday, December 5, 2013

Would you tell Google your Wi-Fi password? You probably already did…

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

US privacy and computer security advocate Micah Lee describes himself, amongst other things, as "a staff technologist for EFF and the project maintainer of HTTPS Everywhere."

In other words, he has a healthily holistic view of the use of encryption on the internet.

So it wasn't surprising, earlier this week, to see him post a suggestion to the Android Open Source Project about security.

His suggestion was entitled "Backup and restore" should offer encrypted backups:

The "Back up my data" option in Android is very convenient. However it means sending a lot of private information, including passwords, in plaintext to Google. This information is vulnerable to government requests for data.

If you're an Android user, the option he's talking about is the Backup & reset page in Settings:

In the screenshot above, the feature is turned off.

Most users, however, probably have it enabled because it is, as Micah points out, very convenient.

The idea is that if you lose your device, or merely feel the need to reflash it, you can much more quickly get back to where you were.

Instead of just reinstalling your favourite apps and starting afresh, your new device will know how to get online straight away, how to get into your Twitter account, and how many Angry Birds levels you haven't conquered yet.

Clearly, Google keeps a raft of configuration data on your behalf, because if you have the option enabled and then decide to turn it off you get this dialog:

So how risky is this option?

It's not risky in the sense, for example, of the recent flaw in the Tumblr app on iOS.

There, Tumblr forgot to secure the actual transmission of personally identifiable information (PII), such as your password.

That meant that crooks at a coffee shop, for example, might easily be able to sniff out and extract your Tumblr password.

The Android issue is more subtle: the data is encrypted in transit, and Google (for all we know) probably stores it encrypted at the other end.

But it's not encrypted in the sense of being inaccessible to anyone except you.

That's obvious because, as a comment on Micah's abovementioned posting pointed out, you can recover your data from Google even after you've wiped (or lost) your device, or changed your Google account password.

In other words, Google can unilaterally recover the plaintext of your Wi-Fi passwords, precisely so it can return those passwords to you quickly and conveniently even if you forget your device password and have to start over.

That's just the sort of convenience which many users will trade against security.

So, let's say some Three Letter Agency were to use some prismatic techqniue to acquire those Wi-Fi passwords from Google.

Is that likely? If so, would it be bad?

I have to say that it probably would be, if only because the list of Wi-Fi networks and passwords on your device is most likely much more extensive than just your own network in your own home.

You'd effectively be helping to built a list of passwords to go with the already-existing and extensive maps of Wi-Fi access points built up over years, both by Google and others.

You probably don't want to help anyone, friend or foe, to do that.

The solution is to encrypt everything "for your eyes only" before you back it up anywhere, especially into the cloud.

And the problem with that is it's not quite as convenient, not least because there's no password-free way to recover that backed-up data, for example if you forget your password.

That's the dilemma we all face.

Are you prepared to accept a digital equivalent of locking your keys in the car forever (for example if you forget your full-disk encryption password and didn't save the recovery key)?

Or would you prefer to have what amounts to a backdoor to your own, or worse still, to other people's, personal information?

What do you think? Let us know in the comments below...

Follow @duckblog


View the original article here

Tuesday, December 3, 2013

Oracle ships giant raft of patches – but none of them for Java

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Oracle's latest Patch Tuesday has come and gone, with the database-and-more behemoth putting out patches for 89 vulnerabilities.

Twelve products sets in the Oracle stable get from 1 to 21 patches each.

These squash a total of 45 RCEs, or Remote Code Execution vulnerabilities.

In Oracle's own words, which are actually well chosen and plainly put, RCEs are defined as:

vulnerabilities [that] may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password.

The affected product suites are listed below. (Oracle and Sun Systems Products, by the way, means Solaris, if you remember that.)

Oracle Enterprise Manager Grid ControlOracle Supply Chain Products SuiteOracle and Sun Systems Products

The one Oracle product conspicuous by its absence from this list is Java.

That's because Java is still on its own once-in-four-months update schedule, and received its most recent Critical Patch Update (CPU) last month.

This should be the last time this that Java will have to march to the tune of its own drum.

October 2013 is Oracle's annual "patchinox", when patches for Java and the rest of Oracle's products coincide.

The company has said that from then on, all non-emergency Critical Patch Updates will take place quarterly, at the same time.

Follow @duckblog


View the original article here

Sunday, December 1, 2013

Gun-wielding penguin takes over Ubuntu Forums, waves AK-47 at Linux users everywhere

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Mark Shuttleworth is famous for two things: for being the first African in space, and for founding Canonical, the company behind Ubuntu Linux.

? I know it't not really Ubuntu Linux. It's Ubuntu, a computing platform based on GNU/Linux and including lots more besides. But we shall call it "Ubuntu Linux" as a sort of handy abbreviation.

Ubuntu was arguably the first Linux distro to attract the attention of ungeeks, to provide an installer that tended to "just work" without any jargon, and to gain a foothold of any sort amongst the type of user that would otherwise perfectly happily have paid for Windows or OS X.

As a result, it spawned a range of online forums dedicated to supporting and nurturing its large fan base, handily collated into the Ubuntu Forums portal.

Ubuntu Forums is bankrolled by Canonical, and should look something like this:

Over the weekend, however, it looked like this:

(That's supposed to be Tux, the penguin mascot of Linux, waving an AK-like assault weapon in his flippers.)

By now, the day after the attack, there's just a breach alert holding page put up by Canonical:

It's hard to imagine what the hackers hoped to achieve by taking out a bunch of free forums for a free distro of a free operating system.

Some commenters in the Twittersphere can't find rhyme or reason either, and have let rip with opprobrious tweets to make their displeasure known:

Of course, one perfectly likely explanation for the hack is clear from Canonical's mea culpa letter: for the personally identifiable information (PII) that it yielded.

Unfortunately the attackers have gotten every user's local username, password, and email address from the Ubuntu Forums database.

With close to 2 million signed-up members, that could mean a lot more spam for a lot of people.

And for those who have chosen poor passwords, the stolen password database could mean worse than that.

Canonical stated that:

The passwords are not stored in plain text, they are stored as salted hashes.

It might have been handy if Canonical had said what sort of salting-and-hashing was used, to give some idea of how quickly an attacker could try a dictionary of passwords against the stolen data.

On the other hand, if you change your password as soon as the Forums come back on line (and it's likely Canonical will force everybody to do so anyway, for safety's sake), and you haven't used the same password anywhere else, you ought to be OK.

Here's our advice:

When you choose a password, don't pick anything obvious. Attackers put the most likely passwords at the top of their dictionary lists, so the tougher your password, the later it will fall, if at all.Don't use the same password on multiple sites. Doing so means that your login details on the most important site are at risk from an attack on the least secure one.If you store password databases, use a strong salt-and-hash system (e.g. bcrypt, scrypt or PBKDF2) that makes it much harder and slower for attackers to go through their password dictionary, but not so slow that it's impracticable to verify individual passwords when your users login.

Follow @duckblog


View the original article here

Apple takes Dev Center down for days, finally admits, “We got owned!”

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

What a weekend!

First Ubuntu and now Apple have admitted to large-scale breaches of their user databases.

The Ubuntu Forums hackers called attention to themselves by changing the main screen to a cartoon of an AK-47-wielding penguin, and Canonical owned up as soon as it could.

But Apple's breach was less obvious at first, with the Developer Center simply going offline with the most generic sort of explanation:

We apologize that maintenance is taking longer than expected.

Apple told developers whose membership would expire during the outage not to worry, giving them a free extension and reassuring them that their apps wouldn't be ejected from the App Store:

If your program membership was set to expire during this period, it has been extended and your app will remain on the App Store.

But as the outage dragged on from last Thursday into the weekend, some observers began to ask if there were more sinister reasons than merely a maintenance window gone wrong.

After all, Apple is one of the massive success stories of the modern cloud economy (iTunes, QED), which makes maintenance alone a decreasingly likely explanation the longer it takes.

It turns out the cynics were right.

Apple's Developer Centre was penetrated, with Cupertino admitting that the attackers seemed to be after personally identifiable information (PII).

The main developer page looks OK at first sight:

But if you try to click through to any of the developer-specific locations, such as the iOS Dev Center or the Mac Dev Center, you don't get very far:

The notice, which was also sent by email to registered developers, now admits the reason for the extended maintenance:

Last Thursday, an intruder attempted to secure personal information of our registered developers from our developer website. Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed. In the spirit of transparency, we want to inform you of the issue. We took the site down immediately on Thursday and have been working around the clock since then.

Investigating a breach of this sort requires considerable circumspection, not least because you need to make sure that such evidence as you have available for law enforcement is safe and sound before you say too much.

That might explain Apple's delay in telling it like it is, but I'm still not quite sure how many friends in the developer community Apple will win by invoking "the spirit of transparency" some two-and-a-half days late.

The next part of Apple's admission, which seems to be intended to explain why actually fixing things is taking longer than might have been expected, says:

In order to prevent a security threat like this from happening again, we're completely overhauling our developer systems, updating our server software, and rebuilding our entire database.

It sounds slightly worrying to hear that Apple is updating its server software after the incident.

With all of this in mind, here's what we recommend:

Patch early, patch often.Proactive security isn't just for Windows users.If you suffer a breach, remember that honesty is the best policy, and time is of the essence.

What now?

Well, let's hope that operating system data breach notifictions aren't like buses, where you wait a while and then three come at once.

Ubuntu/Linux, then Apple/OS X...who/what, do you think, would be next?

Follow @duckblog


View the original article here