Google Search

Wednesday, May 7, 2014

Quantum physics secures new cryptography scheme

The way we secure digital transactions could soon change. An international team has demonstrated a form of quantum cryptography that can protect people doing business with others they may not know or trust -- a situation encountered often on the internet and in everyday life, for example at a bank's ATM.

"Having quantum cryptography to hand is a realistic prospect, I think. I expect that quantum technologies will gradually become integrated with existing devices such as smartphones, allowing us to do things like identify ourselves securely or generate encryption keys," says Stephanie Wehner, a Principal Investigator at the Centre for Quantum Technologies (CQT) at the National University of Singapore, and co-author on the paper.

In cryptography, the problem of providing a secure way for two mutually distrustful parties to interact is known as 'two-party secure computation'. The new work, published in Nature Communications, describes the implementation using quantum technology of an important building block for such schemes.

CQT theorists Wehner and Nelly Ng teamed up with researchers at the Institute for Quantum Computing (IQC) at the University of Waterloo, Canada, for the demonstration.

"Research partnerships such as this one between IQC and CQT are critical in moving the field forward," says Raymond Laflamme, Executive Director at the Institute for Quantum Computing. "The infrastructure that we've built here at IQC is enabling exciting progress on quantum technologies."

"CQT and IQC are two of the world's largest, leading research centres in quantum technologies. Great things can happen when we combine our powers," says Artur Ekert, Director of CQT.

The experiments performed at IQC deployed quantum-entangled photons in such a way that one party, dubbed Alice, could share information with a second party, dubbed Bob, while meeting stringent restrictions. Specifically, Alice has two sets of information. Bob requests access to one or the other, and Alice must be able to send it to him without knowing which set he's asked for. Bob must also learn nothing about the unrequested set. This is a protocol known as 1-2 random oblivious transfer (ROT).

ROT is a starting point for more complicated schemes that have applications, for example, in secure identification. "Oblivious transfer is a basic building block that you can stack together, like lego, to make something more fantastic," says Wehner.

Today, taking money out of an ATM requires that you put in a card and type in your PIN. You trust the bank's machine with your personal data. But what if you don't trust the machine? You might instead type your PIN into your trusted phone, then let your phone do secure quantum identification with the ATM (see artist's impression). Ultimately, the aim is to implement a scheme that can check if your account number and PIN matches the bank's records without either you or the bank having to disclose the login details to each other.

Unlike protocols for ROT that use only classical physics, the security of the quantum protocol cannot be broken by computational power. Even if the attacker had a quantum computer, the protocol would remain secure.

Its security depends only on Alice and Bob not being able to store much quantum information for long. This is reasonable physical assumption, given today's best quantum memories are able to store information for minutes at most. Moreover, any improvements in memory can be matched by changes in the protocol: a bigger storage device simply means more signals have to be sent in order to achieve security. (The idea of 'noisy storage' securing quantum cryptography was developed by Wehner in earlier papers.)

To start the ROT protocol, Alice creates pairs of entangled photons. She measures one of each pair and sends the other to Bob to measure. Bob chooses which photons he wants to learn about, dividing his data accordingly without revealing his picks to Alice. Both then wait for a length of time chosen such that any attempt to store quantum information about the photons is likely to fail. To complete the oblivious transfer, Alice then tells Bob which measurements she made, and they both process their data in set ways that ensure the result is correct and secure within a pre-agreed margin of error.

In the demonstration performed at IQC, Alice and Bob achieved a random oblivious transfer of 1,366 bits. The whole process took about three minutes.

The experiment adapted devices built to do a more standard form of quantum cryptography known as quantum key distribution (QKD), a scheme that generates random numbers for scrambling communication. Devices for QKD are already commercially available, and miniaturised versions of this experiment are in principle possible using integrated optics. In the future, people might carry hand-held quantum devices that can perform this kind of feat.

"We did the experiment with big and bulky optics taking metres of space, but you can well imagine this technology being shrunk down to sit happily next to classical processing circuits on a small little microchip. The field of integrated quantum optics has been progressing in leaps and bounds, and most of the key pieces required to implement ROT have already been successfully demonstrated in integrated setups a few millimetres in size," says Chris Erven, who performed the experiments at IQC as a PhD student under the supervision of Raymond Laflamme and Gregor Weihs. Weihs is now at the University of Innsbruck, Austria. Erven is now a postdoctoral fellow at the University of Bristol, UK.


View the original article here

Tuesday, May 6, 2014

Mobile users may not buy into instant gratification cues, gimmicky ads

Gimmicky contest ads and flashy free-prize messages may be an instant turnoff for mobile users, according to Penn State researchers.

In a study, a tempting offer of a free prize drawing for registering on a mobile website led users to distrust the site, said S. Shyam Sundar, Distinguished Professor of Communications and co-director of the Media Effects Research Laboratory.

Sundar said that in an increasingly information-loaded world, people tend to lean on cues, such as icons and messages, for decision-making shortcuts, called heuristics. However, some cues may elicit user reaction in the opposite direction of what most marketers would anticipate.

"Even though we turn to our mobile devices for instantly gratifying our need for information, we may not be persuaded by advertising appeals for instant gratification," said Sundar. "It's a boomerang effect--marketers may think that they are activating the instant gratification heuristic when they display time-sensitive offers, but what they're actually doing is cuing red flags about the site."

Mobile users tend to be more knowledgeable about technology than regular users.

"It could be that an instant gratification message makes mobile users, who tend to be more tech savvy, leery about the site," said Sundar.

Even though free-prize ads are ubiquitous on the internet, marketers may want to seek other ways to reach mobile customers, according to the researchers.

The researchers, who presented their findings? Apr. 28 at the Association for Computing Machinery's Conference on Human Factors in Computing Systems, also tested a warning cue that seemed to prompt more conflicting reactions from users, said Sundar. When a security alert -- a caution icon with a warning message -- appeared, users became more worried about security, as expected. However, users were willing to reveal more information about their social media accounts after viewing the security prompt.

One possible explanation for this behavior is that the security cue makes the users distinguish more carefully between public and private information.

"People may feel that the social media information is already public information, not necessarily private information, and they are not as concerned about revealing social media information," said Sundar, who worked with Bo Zhang, Mu Wu, Hyunjin Kang and Eun Go, all doctoral students in mass communications. "The 'privacy paradox' of giving away information when we are most concerned about its safety may not be all that paradoxical if you consider that the information we give away is not quite private."

The researchers recruited 220 participants to test four different mobile sites. The participants were first asked to navigate to a mobile site. One site included a caution symbol and a security warning that the site was insecure and another site contained a gift box icon with a message that the user could win a free prize for registering. A third site showed both a warning and an instant gratification message and a fourth site, which featured neither alerts, served as the control in the study. Except for these cues, all other content in the four sites was identical.

Participants could choose how much or how little personal, professional, financial or social media information they provided in the registration form, which served as a measure of their information disclosure behaviors. After registering, they filled out an online questionnaire about their impressions of the mobile website.


View the original article here

Monday, May 5, 2014

Software analyzes apps for malicious behavior

Apps on web-enabled mobile devices can be used to spy on their users. Computer scientists at the Center for Security, Privacy and Accountability (CISPA) developed software that shows whether an app has accessed private data. To accomplish this, the program examines the "bytecode" of the app in question. The researchers show their program at the upcoming computer expo Cebit in Hannover.

Last year at the end of July the Russian software company "Doctor Web" detected several malicious apps in the app store "Google Play." Downloaded on a smartphone, the malware installed -- without the permission of the user -- additional programs which sent expensive text messages to premium services. Although Doctor Web, according to its own statement, informed Google immediately, the malicious apps were still available for download for several days. Doctor Web estimates that in this way up to 25,000 smartphones were used fraudulently.

Computer scientists from the German Saarland University have now developed software which can discover such malicious apps already in the app store. The software detects pieces of code where the app accesses sensitive data and where data is sent from the mobile device. If the software detects a connection between such a "source" and such a "sink," it reports that as suspect behavior. To give an example of such a malicious source-sink combination, Erik Derr explains: "Your address book is read; hundreds of instructions later and without your permission an SMS is sent or a website is visited." Derr is a PhD candidate at the Graduate School of Computer Science and does research at the Center for IT-Security, Privacy and Accountability (CISPA), only a few yards away.

To identify a functional relation between source and sink, the computer scientists from Saarbr?cken use new methods of information flow analysis. As input they provide suspicious combinations of accesses on the application programming interface. As the software needs a lot of computational power and storage, it runs on a separate server. "So far we have tested up to 3000 apps with it. The software analyzes them fast enough that the approach can also be used in practice," Derr says.


View the original article here

Sunday, May 4, 2014

Bank of England to hire penetration testers to attack financial firms

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Bank of EnglandThe Bank of England this year will hire penetration testers to poke and kick at the computer-system defences of more than 20 major UK banks and other financial players.

Sources familiar with the programme told the Financial Times (registration required to view article) that it's going to enlist testers certified by CREST, a not-for-profit organisation that represents the infosec industry.

Financial institutions have already proved susceptible to what's being called the latest, biggest security threat since the birth of the internet: the OpenSSL Heartbleed buffer overflow vulnerability.

One such was American Funds, the third largest US mutual fund family, which last week advised some customers to change user names and passwords.

According to Business Recorder, the company emailed about 825,000 clients to tell them that they'd been exposed to "a very narrow window of risk" and advised that they change user names, passwords, and security questions and delete their browsing histories.

Canada's tax agency, the Canada Revenue Agency, also recently announced that 900 social insurance numbers (SINs) were stolen by hackers exploiting Heartbleed over a six-hour period.

Andrew Gracie, the director of the UK's special resolution unit within the Bank of England, will reportedly oversee the UK pen testing programme.

The Financial Times reports that the testing will build on the lessons of Operation Waking Shark 2, a simulation of a major cyber attack on UK financial firms that was carried out in London on 12 November 2013.

The four-hour exercise simulated attack by a hostile nation state on the UK's financial sector, set to cover a three-day period, the last day of which coincided with "Triple Witching" (when contracts for stock index futures, stock index options and stock options all expire on the same day).

BoE reported (PDF) the lessons learned from Waking Shark 2 in February.

The exercise pointed to three main areas for future work:

The need to identify a single industry body to coordinate communications.Making sure that firms know that they need to report major incidents to regulators right away. Fine-tuning and getting used to working with the Cyber Security Information Sharing Partnership (CISP) platform - a data threat sharing platform - used during the exercise.

According to The Financial Times, Waking Shark 2 involved 220 people, 20 institutions and infrastructure providers, and a host of government agencies, but it didn't target individual companies' systems.

Hole. Image courtesy of ShutterstockIn fact, this is the first time that UK banking authorities are taking on the task of testing for vulnerabilities in this broad fashion, as opposed to the typical scenario of having firms conduct their own, internal penetration testing, the news outlet reports.

Is your own organisation looking at pen testing? Perhaps while casting a frightened eye toward Heartbleed, in particular?

As Sophos' Ross McKerchar pointed out when he gave these tips on how to manage cost-effective pen testing, this stuff can very quickly get very pricey.

Focusing on testing the right things in the right manner is key to getting the best bang for your buck, he says.

What about us security civilians? Can we pen-test our own systems?

Well, yes... carefully.

Serious penetration testing can really mess up a site. When done on a business level, nightmares such as crashing servers, exposing sensitive data, corrupting crucial production data or causing other damage by mimicking the actions of malicious attackers can ensue.

Home users don't have such broad risk areas, but it's still wise to proceed with caution.

Naked Security has these tips for home users to penetration test their own computers.

As Lee Munson notes, pen testing can be as simple as asking somebody to try to guess your passwords. If even a technically unsophisticated person can guess that you're using "password" or "123456" (please tell us you're not), you know you've got some work to do!

Check lists of the most commonly used passwords.

See any of yours on there? Change them! Use upper and lowercase letters, numbers and special characters, and make them as long as possible.

And yes, I know, that list dates back to 2010. Unfortunately, the top favorites haven't changed much!

Follow @LisaVaas

Follow @NakedSecurity

Image of hole courtesy of Shutterstock.


View the original article here

Saturday, May 3, 2014

LibreSSL aims to prevent the next Heartbleed

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Stop HeartbleedThe wonderful thing about the internet is that it is full of people who do.

You'd be forgiven for not noticing them - it can sometimes feel like the information superhighway is a gridlock of people yelling, beeping their horns and not listening, but trust me, underneath all that posturing it's crawling with doers.

This legion of achievers creates and maintains a vast mass of occasionally useful and somewhat interlocking pieces of software.

At any one time enough of the individual pieces are able to work successfully with other pieces that, like a whirlpool in a raging torrent, our online universe emerges as a stable structure amidst a boiling froth of software birth, growth, decline, death and rebirth.

Regardless of how any individual project or decision is managed the internet as a whole is an ecosystem organised along Darwinian lines.

There are as many motives for all this doing as there are individuals engaged in it but a vast amount of the really important stuff that's being done, the creation of building blocks that others will arrange and rearrange to create their own projects, is executed by small groups of specialists who work for free and then simply give their software away.

One such team of doers is the OpenSSL team. Their eponymous encryption library, produced by a tiny team with meagre funding, was so useful, so successful and so widely used and integrated that, without any decision being taken that it should, it proliferated until it became a critical piece of internet infrastructure.

That proliferation is what made the Heartbleed bug so devastating. OpenSSL was everywhere and so was its nastiest bug.

The code's primary defenses against bugs and flaws are a) that it's developed by people who know what they're doing and b) their work is open to scrutiny - anyone who wants to can look at it, poke it, test it, suggest changes or take it away and make their own version.

Of course, just because everyone can look it doesn't mean that anyone does. It's easy to assume that somebody else is minding the commons and when it turns out they aren't a tragedy is sure to follow.

Most of the time, people are happy to go about their business without thinking about how the internet's building blocks work or how they're built. Even most of the doers are so busy doing what they're doing that they can't concern themselves with how every little thing they rely upon was done.

One such team were the folks at OpenBSD.

OpenBSDOpenBSD is a robust and well established computer operating system that works a lot like Unix or Linux and aims to be the #1 most secure operating system. The team behind it have reputation for being doers when it comes to security.

The OpenSSL library has been included with the OpenBSD operating system for years and it seems that during that time the OpenBSD team have been happy to trust that the OpenSSL team would make a decent fist of looking after their own.

That was before Heartbleed. That bug, it seems, was the last straw.

The credo of the doers is that when you need a bit of software to do something that it doesn't do, you fix it yourself. What the OpenBSD team need the OpenSSL library to do is to be less broken and they've given up waiting for the current maintainers to fix it.

The Rubicon lay somewhere between the discovery of freelists and the unfixed bug ... That unfixed bug (still unfixed in OpenSSL even now, two weeks later, despite OpenBSD, FreeBSD, and Debian all patching it out of tree) galvanized the team. It was clear that a fork was the only solution and that working with upstream [the OpenSSL team] would be a futile effort.

Of course they can't take the code away from the current maintainers but because the code is open source they are free to either lend a hand, write a better replacement or try to do a better job than the current owners with what's there already.

They've taken the latter course of action, calling their OpenSSL fork LibreSSL. And, being the doers that they are, they've got busy rewriting, refactoring and flensing (and this being the OpenBSD team there's probably been some swearing, eyeball rolling and falling out too).

Scrutiny, vitality and evolution have returned to stagnant but critically important corner of the ecosystem.

Follow @MarkStockley

Follow @NakedSecurity


View the original article here

Friday, May 2, 2014

Parents win against cloud storage of US students’ private information

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Privacy

inBloom logoPeople are a little touchy about data collection nowadays.

They were most certainly touchy about inBloom, a non-profit that was offering to house and manage student data for public school districts across the US by extracting a dizzying array of information - we're talking 400 data fields - from disparate school databases as well as from new, optional, sometimes intrusive categories that inBloom also offered.

Since inBloom's rollout in 2013, privacy and security experts and parents have been aghast at schools sucking up everything from students' tax ID numbers to intimate family details (including options to identify family members as "foster parent" or "father’s significant other") with inBloom.

That outrage spelled doom for inBloom, which announced on Monday that it's closing up shop.

inBloom CEO Iwan Streichenberger said in a post that the progress of the platform - which stored the extracted student data in the cloud and then fed it back via dashboards for teachers to track the progress of individual students - was hamstrung by the fact that the public furrowed its brow over data misuse:

It is a shame that the progress of this important innovation has been stalled because of generalized public concerns about data misuse, even though inBloom has world-class security and privacy protections that have raised the bar for school districts and the industry as a whole.

InBloom was a well-funded endeavor designed as a kind of glue to hold together products coming from what the New York Times says is a $8 billion prekindergarten through 12th-grade education technology software market.

The big names behind it were the Bill and Melinda Gates Foundation, the Carnegie Foundation, Carnegie Corporation and others, who donated some $100 million as seed money.

inBloom began rather brightly, signing on districts in seven client states: Colorado, Delaware, Georgia, Illinois, Kentucky, North Carolina, and Massachusetts.

For their parts, Louisiana and New York signed on whole-hog to use inBloom on a statewide basis.

According to Reuters, inBloom's database held details on millions of children by 3 March 2013.

Things quckly turned sour when savvy parents began to realize the security and privacy implications.

In Louisiana, parents over the summer were incensed to find that the state had uploaded their children’s Social Security Numbers to inBloom in spite of inBloom's policies, which explicitly prohibit storage of SSNs.

Louisiana subsequently declared that they would remove all student data from the database.

According to the NYT, as of October 2013, only three of the nine states that had originally signed up to participate were actively pursuing the service.

Like Louisiana, New York also backed out of plans to use the service earlier this month, after legislation was passed that prohibited the state department of education from giving student information to data aggregators like inBloom.

Of course, parents had every right to scream like hell about this technology, which many thought had been embraced without due consideration of the risks involved in storing such a vast array of private information.

Despite the "world-class security and privacy protections" that CEO Streichenberger cited in his note on Monday, before the service was taken offline, the privacy and security section of inBloom's website stated:

inBloom, Inc. cannot guarantee the security of the information stored in inBloom or that the information will not be intercepted when it is being transmitted.

Much of the information was already collected by schools and shared with software or service companies, including grades, attendance records, academic subjects, course levels, and disabilities.

Other information concerned more intimate areas, including reasons for enrollment changes ("withdrawn due to illness" or "leaving school as a victim of a serious violent incident").

Before inBloom's site shuttered most of its pages, it contained a video suggesting one scenario of how student data would be used.

One image, captured by the NYT, shows a sample of how (fictional) students' data could be presented, including bar graphs measuring how much a given student "actively participates", "shows enthusiasm" and "resists distractions".

inBloom example image, courtesy of NYT

Is that labeling something we want big-data crunching software companies to do to our children?

Parents and privacy experts said no.

The Electronic Privacy Information Center (EPIC) keeps tabs on the war to protect students' privacy.

Whether it's Google admitting to data-mining students' emails to target advertisements at them, the Education Department's weakening of privacy law to allow private companies and government agencies to access student records without obtaining student consent, or a myriad other privacy-weakening government and corporate actions, it's very clear to see that inBloom is just one battle won.

The war rages on.

inBloom is down, but the concepts of using big data in this way, to facilitate educators' jobs and to enhance individualized teaching of students, aren't dying with it.

Expect more battles to come.

Follow @LisaVaas

Follow @NakedSecurity


View the original article here

Thursday, May 1, 2014

Tokyo airport employee loses handwritten passcodes ahead of Obama visit

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Tokyo Haneda Airport. Image courtesy of ShutterstockThe dangers associated with writing passwords down were expertly demonstrated by a Japanese airport worker over the weekend as the country prepared for the first visit by a US president in almost 20 years.

Rubbish bins and luggage lockers have been sealed and over 16,000 police officers have been mobilised in the capital city of Tokyo ahead of President Barack Obama's visit Wednesday night - but it may be the loss of several passcodes that has caused the biggest security headache so far.

Speaking on Tuesday, a transport ministry official said that an employee of Skymark Airlines at Tokyo's Haneda International Airport mislaid a printout containing key passcodes on Sunday.

The document was found just thirty minutes later on the floor of the departure lobby but the Japanese government were not prepared to take any chances.

Whilst there is no word on which areas of the airport would have been accessible with the lost codes, the ministry instructed the company that manages Haneda International to change them immediately in order to avoid even the slightest chance of a security breach.

The security faux pas comes at an awkward time for the airport, as it is just one month since the Metropolitan Police Department created a dedicated counter-terrorism unit tasked with securing the facility after the number of international flights was increased by almost fifty percent.

The same airport is also set to become a key destination when the Olympic games are hosted in the city in 2020.

It also comes at a time when airport security in general is under the spotlight following the news that a 16-year-old boy had survived a five-hour flight in an aircraft's wheel well. The lad had jumped a fence at San Jose airport and was able to gain access to the plane's undercarriage without alerting security.

But the Tokyo airport isn't alone in having a problem with remembering security codes or passwords without the need to write them down – other organisations have had a good go at embarrassing themselves recently too.

Two years ago a televised ESPN interview took place in front of a wall which proudly displayed two passwords, and in February a CBS Super Bowl report clearly displayed the TV station's WiFi username and password in the background.

Password. Image courtesy of ShutterstockYou may also remember the Polish television broadcast that featured a woman being interviewed in front of a whiteboard that displayed the company's login credentials and Prince William's RAF photos that showed off an incredibly lame password choice.

So how can you choose a password that is both strong and easy enough to remember without having to write it down?

This video from Sophos gives some great practical advice on doing just that.

As said in the video, it would be foolish to then reuse that same password across the entire web because, should it be compromised in any way, the bad guys will then have access to ALL of your accounts.

Therefore, it would be wise to also use a password manager, such as KeePass or LastPass, which will allow you to store many complex passwords whilst only needing to remember one - and, whatever you do, don't write it down!

Follow @Security_FAQs

Follow @NakedSecurity

Image of Tokyo Airport and password courtesy of Shutterstock.


View the original article here