The attacker who stole Hacking Team's data gained access to an employee's computer while the victim was still logged in.
The attacker either had direct physical access to Christian Pozzi's PC or they used malware to achieve a similar level of access. Whichever way it was, we can tell that Christian was logged in at the time simply by looking at a folder name among the files that were leaked onto the internet.
Showing posts with label data leaking. Show all posts
Showing posts with label data leaking. Show all posts
Saturday, 18 July 2015
Wednesday, 11 June 2014
Are Chromebooks insecure travel companions?
Do not connect a Chromebook to a public wireless network if you don't want to risk leaking personal information.
This advice is not some half-baked journalistic opinion but comes direct from the UK government’s National Technical Authority for Information Assurance (CESG).
The CESG advises that even for data with the lowest security classification [PDF], labelled 'OFFICIAL', Chromebooks are unsuitable for a number of reasons, one being that the Virtual Private Network (VPN) included is not up to scratch and there are no viable alternatives.
Yesterday the organisation published its End User Devices Security Guidance: Chrome OS, which states:
If you don't use a VPN when using public WiFi then you are at no greater risk when using a Chromebook than any other device, but if you are security conscious and want to stay safe when moving around at home and abroad it's better to stick with an Android tablet than move over to a Chromebook.
This advice is not some half-baked journalistic opinion but comes direct from the UK government’s National Technical Authority for Information Assurance (CESG).
The CESG advises that even for data with the lowest security classification [PDF], labelled 'OFFICIAL', Chromebooks are unsuitable for a number of reasons, one being that the Virtual Private Network (VPN) included is not up to scratch and there are no viable alternatives.
Yesterday the organisation published its End User Devices Security Guidance: Chrome OS, which states:
"The VPN has not been independently assured to Foundation Grade, and does not currently support some of the mandatory requirements expected from assured VPNs. The VPN can be disabled by the user and some Google traffic is sent prior to the VPN being established resulting in potential for data leakage onto untrusted networks. Without assurance in the VPN there is a risk that data transiting from the device could be compromised"There is a similar warning in the Android guide that the in-built VPN for Android 4.4 has not been assured, although it does not appear to leak data automatically and there are alternatives available.
If you don't use a VPN when using public WiFi then you are at no greater risk when using a Chromebook than any other device, but if you are security conscious and want to stay safe when moving around at home and abroad it's better to stick with an Android tablet than move over to a Chromebook.
Thursday, 5 June 2014
Three Android Security Essentials
I recommend the following three tools for improving your security when using Android phones.
These will allow you to:
Two tools are free. I've included one that is not because I believe that the free alternatives are not sufficient.
Google Android Device Manager
Why: Ring, lock or erase your phone remotely
Cost: Free
Where: Already installed or Google Play Store
Install the application if necessary and visit the management console using another computer (phone, tablet or PC), logging in with a Google account that is present on your phone.
If you lose your phone nearby you can locate it using its ringer. If you lose it further afield you can locate it using GPS. If it's really lost or stolen you can wipe it.
More information, including a video on what the wiping process looks like.
F-Secure Freedome
Why: Use public WiFi networks safely
Cost: £20.99/year (or £2.99/month)
Where: Google Play Store
Prevent others from monitoring your internet use, passwords and other sensitive data by clicking the Protection button.
When it says 'On' your connection to the internet is encrypted, even if the websites you use do not use encryption.
Additionally this product claims to protect against web-based threats including harmful applications, websites and sites that track your online activity.
If you are considering a free VPN bear in mind that you don't necessarily know who is running it and what information they are taking from you to fund it.
Google Authenticator
Why: Increased security for your internet accounts
Cost: Free
Where: Google Play Store
Not only available for Android, this security tool makes your internet accounts much harder to crack.
Compatible services include Google Apps and Mail; Dropbox; LastPass; and WordPress. That is just a short list of those using Authenticator.
These will allow you to:
- Locate or disable a lost or stolen phone
- Prevent surveillance of your WiFi and mobile data use
- Further improve the security of your internet accounts
Two tools are free. I've included one that is not because I believe that the free alternatives are not sufficient.
Google Android Device Manager
Why: Ring, lock or erase your phone remotely
Cost: Free
Where: Already installed or Google Play Store
Install the application if necessary and visit the management console using another computer (phone, tablet or PC), logging in with a Google account that is present on your phone.
If you lose your phone nearby you can locate it using its ringer. If you lose it further afield you can locate it using GPS. If it's really lost or stolen you can wipe it.
More information, including a video on what the wiping process looks like.
F-Secure Freedome
Why: Use public WiFi networks safely
Cost: £20.99/year (or £2.99/month)
Where: Google Play Store
Prevent others from monitoring your internet use, passwords and other sensitive data by clicking the Protection button.
When it says 'On' your connection to the internet is encrypted, even if the websites you use do not use encryption.
Additionally this product claims to protect against web-based threats including harmful applications, websites and sites that track your online activity.
If you are considering a free VPN bear in mind that you don't necessarily know who is running it and what information they are taking from you to fund it.
Google Authenticator
Why: Increased security for your internet accounts
Cost: Free
Where: Google Play Store
Not only available for Android, this security tool makes your internet accounts much harder to crack.
Compatible services include Google Apps and Mail; Dropbox; LastPass; and WordPress. That is just a short list of those using Authenticator.
Wednesday, 13 November 2013
Quick and dirty redaction
If you want to obscure secret information in a document for publication here's a quick and easy way to do it, without downloading any special tools and without printing the files out and scanning them back in again.
If you know about the issues with electronic redaction just skip down to the pictures below.
Sometimes people and organisations need to release documents after having removed some particularly sensitive content. This process, often known as redaction, used to be simple. One would run a thick black pen over the data you wanted to hide and photocopy the result. Redacting electronically introduces some pretty dire pitfalls.
In 2007 the Fédération Internationale de l' Automobile (FIA) published transcripts from the World Motor Sports Council hearings into allegations that McLaren was spying on Ferrari. Its attempts at redaction were woefully ineffective and could be bypassed by selecting the text from the document and pasting it into a text editor.
The black blocks designed to obscure the secret information were ignored and the secrets revealed.
There are special tools available to help redact documents and Microsoft provides a dedicated tool for Microsoft Word 2007. The NSA has published guidelines on redacting Word and PDF files, which are freely available online [direct PDF download]. It also includes useful information on removing metadata, which can reveal a lot of interesting information you may wish to keep private.
The following steps require no special tools. You just need a third-party PDF generator, such as CutePDF Writer, and a free version of Adobe Reader.
Quick and dirty redaction
1. Load or create your document in Microsoft Word and cover any sensitive information with black boxes, courtesy of Word's Insert Shapes feature. Ensure that these boxes are 0 per cent transparent!
2. Save the document as a PDF. You can print it to PDF format using the third-party PDF printer driver or save it as a PDF using Word's own in-built PDF generator. At this stage the PDF is not secure. You will be able to copy and paste text that is hidden beneath the black boxes.
3. Load the PDF into Adobe Reader and print it again, this time using the third-party driver (e.g. CutePDF Writer). Choose the driver and then select Advanced. Tick the Print As Image option.
4. The result is a PDF file from which no text may be selected, even the text that is not secret. Readers can take screenshots of the file and even copy and paste parts of a page, but these are graphics and not text.
If you know about the issues with electronic redaction just skip down to the pictures below.
Sometimes people and organisations need to release documents after having removed some particularly sensitive content. This process, often known as redaction, used to be simple. One would run a thick black pen over the data you wanted to hide and photocopy the result. Redacting electronically introduces some pretty dire pitfalls.
In 2007 the Fédération Internationale de l' Automobile (FIA) published transcripts from the World Motor Sports Council hearings into allegations that McLaren was spying on Ferrari. Its attempts at redaction were woefully ineffective and could be bypassed by selecting the text from the document and pasting it into a text editor.
The black blocks designed to obscure the secret information were ignored and the secrets revealed.
There are special tools available to help redact documents and Microsoft provides a dedicated tool for Microsoft Word 2007. The NSA has published guidelines on redacting Word and PDF files, which are freely available online [direct PDF download]. It also includes useful information on removing metadata, which can reveal a lot of interesting information you may wish to keep private.
The following steps require no special tools. You just need a third-party PDF generator, such as CutePDF Writer, and a free version of Adobe Reader.
Quick and dirty redaction
1. Load or create your document in Microsoft Word and cover any sensitive information with black boxes, courtesy of Word's Insert Shapes feature. Ensure that these boxes are 0 per cent transparent!
2. Save the document as a PDF. You can print it to PDF format using the third-party PDF printer driver or save it as a PDF using Word's own in-built PDF generator. At this stage the PDF is not secure. You will be able to copy and paste text that is hidden beneath the black boxes.
3. Load the PDF into Adobe Reader and print it again, this time using the third-party driver (e.g. CutePDF Writer). Choose the driver and then select Advanced. Tick the Print As Image option.
4. The result is a PDF file from which no text may be selected, even the text that is not secret. Readers can take screenshots of the file and even copy and paste parts of a page, but these are graphics and not text.
Categories:
data leaking,
tips
Tuesday, 17 September 2013
USB condom pumped up in press
Some IT news websites have posted excited articles about a new 'USB condom' that protects devices from hostile charging stations.
Unless I'm missing something, I think this excitement is a little unwarranted.
The threat
You plug your phone into an untrusted USB charger. This is secretly connected to a computer that mounts the phone's storage and accesses its data. This is known as 'juice-jacking'.
The solution
If you must charge your devices using an untrusted charging station you may improve your security by turning them off completely. You should receive a faster charge that way, too.
Alternatively use a USB charging cable, which is like a regular cable but the data pins are not connected. You can make one of these yourself very cheaply. It's not hard but, if you don't want to DIY, ready-made options are inexpensive - frequently less than £5.
The USB condom
The USB condom works by "cutting off the data pins in the USB cable and allowing only the power pins to connect through." So, very much the same as a USB charging cable then.
Pricing for this connector is not yet available* but, if it is very much lower than £5, it'll be a worthy addition to any security-conscious traveller's cable bag.
* UPDATE (18/09/2013): Pricing for these devices is now available. The USB Micro-B and USB Type A models are $9.99 each. In my opinion that is poor value for money.
Unless I'm missing something, I think this excitement is a little unwarranted.
The threat
You plug your phone into an untrusted USB charger. This is secretly connected to a computer that mounts the phone's storage and accesses its data. This is known as 'juice-jacking'.
The solution
If you must charge your devices using an untrusted charging station you may improve your security by turning them off completely. You should receive a faster charge that way, too.
Alternatively use a USB charging cable, which is like a regular cable but the data pins are not connected. You can make one of these yourself very cheaply. It's not hard but, if you don't want to DIY, ready-made options are inexpensive - frequently less than £5.
The USB condom
The USB condom works by "cutting off the data pins in the USB cable and allowing only the power pins to connect through." So, very much the same as a USB charging cable then.
Pricing for this connector is not yet available* but, if it is very much lower than £5, it'll be a worthy addition to any security-conscious traveller's cable bag.
* UPDATE (18/09/2013): Pricing for these devices is now available. The USB Micro-B and USB Type A models are $9.99 each. In my opinion that is poor value for money.
Categories:
android,
data leaking,
ios,
personal privacy,
security for normal people,
social engineering,
tips
Monday, 5 August 2013
The mystery of Google's app for wiping and locating phones
The Register wrote, "Google has announced that it will begin offering a free device location and security service for Android phones and tablets for the first time later this month, addressing a longstanding (sic) omission in Mountain View's mobile OS."
Such security features are often included with anti-malware applications, while there are also dedicated apps that provide only the location and memory-wiping abilities.
The news that Google was going to launch its new Android Device Manager security service and application made me a little confused. I thought it already had put out something similar ages ago. In fact I remember seeing an app called Google Apps Device Policy on pretty much every device that I've used.
Here is Google's description of Google Apps Device Policy:
***THIS APP IS FOR GOOGLE APPS FOR BUSINESS, EDUCATION, AND GOVERNMENT USERS ONLY***Google Apps Device Policy makes your Android device more secure* Ring or locate a lost device via My Devices (https://www.google.com/apps/mydevices)* Remotely lock device or change pin* Administrators can enforce security policies and remotely wipe devices
The app is clearly only available to use for those who pay for Google Apps. Indeed, if you visit the URL above you'll see a message verifying that fact.
My confusion was compounded, however, when I came to verify the name of the app before writing this article. My current phone and tablet, a Nexus 4 and Nexus 7, are running the latest version of Android (4.3) and now no longer show Google Apps Device Policy as being available.
As the first screenshots above show, though, the program was certainly installed at some point. In fact it has been installed not only on the devices I use day to day but also on the first Android phone I ever bought and all devices bought since.
It's great news that ordinary users will have access to these features. It's just a little surprising that a similar, installed product seems to have become invisible or been removed.
Categories:
android,
data leaking,
personal privacy,
protection in the cloud,
security software
Friday, 2 August 2013
Choosing a secure PIN
Credit, debit and ATM cards are usually protected by a four-digit number.
This Personal Identification Number (PIN) is supposed to prevent an unauthorised person from using the card.
Choosing a good PIN makes a great deal of sense. Here's how to pick a good one, or at least how to avoid a bad one.
It seems that good sense is lacking with many people, who use predictable PINs such as 1234, 1111 and 0000.
How do we know this? Nick Berry, from DataGenetics, analysed passwords that had been leaked onto the internet. He concentrated on the four-digit passwords, working on the fair assumption that if people are using four-digit passwords for internet services then there will be some correlation between their choices and the numbers people choose for bank cards and other systems that use four-digit PINs.
He discovered that, out of 3.4 million records, the three sequences above were by far the most common. They were almost certainly chosen with intent, rather than being generated randomly.
The top 20 PINs accounted for 26.83 per cent of all passwords in the database, which means that a bad guy would only need to try 20 codes to achieve success in one quarter of sessions.
Within the top 20 you will find all repeated sequences of a single number: 0000, 1111, 2222, 3333, 4444, 5555, 6666, 7777, 8888, 9999.
So in other words, if you want to guess someone's PIN try each of the above sequences in turn and you stand a very good chance of success.
The least popular choice was 8068. So we should all start using that one, right? Definitely not. As Nick writes:
One quite amusing part of Nick's research is that the number 2580 crops up fairly high on the list, at #22 Look at your telephone key pad to discover why this is a popular choice.
I know of at least one PIN-protected door to which no-one who uses it can tell you the PIN. They have all memorised the combination using a visual pattern (e.g. top left, bottom-right, middle-right, middle-left) rather than by the numbers (1964).
This Personal Identification Number (PIN) is supposed to prevent an unauthorised person from using the card.
Choosing a good PIN makes a great deal of sense. Here's how to pick a good one, or at least how to avoid a bad one.
It seems that good sense is lacking with many people, who use predictable PINs such as 1234, 1111 and 0000.
How do we know this? Nick Berry, from DataGenetics, analysed passwords that had been leaked onto the internet. He concentrated on the four-digit passwords, working on the fair assumption that if people are using four-digit passwords for internet services then there will be some correlation between their choices and the numbers people choose for bank cards and other systems that use four-digit PINs.
He discovered that, out of 3.4 million records, the three sequences above were by far the most common. They were almost certainly chosen with intent, rather than being generated randomly.
The top 20 PINs accounted for 26.83 per cent of all passwords in the database, which means that a bad guy would only need to try 20 codes to achieve success in one quarter of sessions.
Within the top 20 you will find all repeated sequences of a single number: 0000, 1111, 2222, 3333, 4444, 5555, 6666, 7777, 8888, 9999.
So in other words, if you want to guess someone's PIN try each of the above sequences in turn and you stand a very good chance of success.
The least popular choice was 8068. So we should all start using that one, right? Definitely not. As Nick writes:
Warning - Now that we’ve learned that, historically, 8068 is (was?) the least commonly used password 4-digit PIN, please don’t go out and change yours to this! Hackers can read too! They will also be promoting 8068 up their attempt trees in order to catch people who read this (or similar) articles.The key to a secure PIN is to choose one that is not predictable. So maybe looking at the most- and least-used ones published in such articles is a good idea so that they can be avoided. You want your PIN to be lost in the middle ground.
One quite amusing part of Nick's research is that the number 2580 crops up fairly high on the list, at #22 Look at your telephone key pad to discover why this is a popular choice.
I know of at least one PIN-protected door to which no-one who uses it can tell you the PIN. They have all memorised the combination using a visual pattern (e.g. top left, bottom-right, middle-right, middle-left) rather than by the numbers (1964).
Categories:
criminal economy,
data leaking,
personal privacy,
security for normal people,
tips
Monday, 15 April 2013
Is it infected?
How do you know if a system is infected with malware?
This question is important to journalists, testers and other reviewers of anti-malware software.
The security product may claim to have defeated the threat but you need to dig down into the system using forensic tools to be sure that it has succeeded.
The following links and notes are intended for the journalists who attended Kaspersky Lab's reviewers workshop this week:
Wireshark
http://www.wireshark.org/download.html
http://wiresharkdownloads.riverbed.com/wireshark/win32/Wireshark-win32-1.8.6.exe
http://wiresharkdownloads.riverbed.com/wireshark/win64/Wireshark-win64-1.8.6.exe
CaptureBAT
https://www.honeynet.org/node/315
https://www.honeynet.org/files/CaptureBAT-Setup-2.0.0-5574.exe
>> CaptureBAT.exe -l demo.txt -n -c
Autoruns
http://technet.microsoft.com/en-US/sysinternals
WinPrefetchView
http://www.nirsoft.net/utils/win_prefetch_view.html
http://www.nirsoft.net/utils/winprefetchview.zip
Volatility
https://code.google.com/p/volatility/
https://volatility.googlecode.com/files/volatility-2.2.standalone.exe
>> volatility-2.2.standalone.exe -f stuxnet.raw pslist
>> volatility-2.2.standalone.exe -f stuxnet.raw psscan
>> volatility-2.2.standalone.exe -f stuxnet.raw psxview
Malware Analyst's Handbook
http://www.malwarecookbook.com
http://goo.gl/7gONZ (specific page on Amazon.com)
Stuxnet analysis
http://mnin.blogspot.co.uk/2011/06/examining-stuxnets-footprint-in-memory.html
This question is important to journalists, testers and other reviewers of anti-malware software.
The security product may claim to have defeated the threat but you need to dig down into the system using forensic tools to be sure that it has succeeded.
The following links and notes are intended for the journalists who attended Kaspersky Lab's reviewers workshop this week:
Wireshark
http://www.wireshark.org/download.html
http://wiresharkdownloads.riverbed.com/wireshark/win32/Wireshark-win32-1.8.6.exe
http://wiresharkdownloads.riverbed.com/wireshark/win64/Wireshark-win64-1.8.6.exe
CaptureBAT
https://www.honeynet.org/node/315
https://www.honeynet.org/files/CaptureBAT-Setup-2.0.0-5574.exe
>> CaptureBAT.exe -l demo.txt -n -c
Autoruns
http://technet.microsoft.com/en-US/sysinternals
WinPrefetchView
http://www.nirsoft.net/utils/win_prefetch_view.html
http://www.nirsoft.net/utils/winprefetchview.zip
Volatility
https://code.google.com/p/volatility/
https://volatility.googlecode.com/files/volatility-2.2.standalone.exe
>> volatility-2.2.standalone.exe -f stuxnet.raw pslist
>> volatility-2.2.standalone.exe -f stuxnet.raw psscan
>> volatility-2.2.standalone.exe -f stuxnet.raw psxview
Malware Analyst's Handbook
http://www.malwarecookbook.com
http://goo.gl/7gONZ (specific page on Amazon.com)
Stuxnet analysis
http://mnin.blogspot.co.uk/2011/06/examining-stuxnets-footprint-in-memory.html
Categories:
anti-virus testing,
books,
data leaking,
in the lab,
rootkit,
security software,
tips
Thursday, 31 January 2013
HMV Twitter account reports mass staff firing
![]() |
| Twitter temporarily shut down soon after the HMV posts were deleted |
Apparently a mass staff sacking was taking place at the same time.
The messages were repeated by many Twitter users, who picked up on one message in particular that stated, "Just overheard our Marketing Director... ask 'How do I shut down Twitter?'"
As I and others started to track and copy the messages, tagged as #hmvXFactorFiring, it became clear that they were being deleted simultaneously.
Twitter then went offline sporadically, the site showing that, "Twitter is over capacity." This instability continued for some time.
UPDATE: At around 15:30 the BBC reported that HMV administrators announce 190 job losses. It wrapped up its report by mentioning the disgruntled Twitter messages.Here is the complete list of messages. Start from the bottom to read them in order.
---
HMV Twitter account: @hmvtweets
Date: 31/01/2013
Time: Last (top) message sent around 14:40
---
5m
hmv @hmvtweets
Especially since these accounts were set up by an intern (unpaid, technically illegal) two years ago.
7m
hmv @hmvtweets
...and those hard working individuals, who wanted to make hmv great again, have mostly been fired, there seemed no other choice.
8m
hmv @hmvtweets
Under usual circumstances, we'd never dare do such a thing as this. However, when the company you dearly love is being ruined...
9m
hmv @hmvtweets
Just overheard our Marketing Director (he's staying, folks) ask "How do I shut down Twitter?" #hmvXFactorFiring
22m
hmv @hmvtweets
Sorry we've been quiet for so long. Under contract, we've been unable to say a word, or -more importantly - tell the truth #hmvXFactorFiring
23m
hmv @hmvtweets
There are over 60 of us being fired at once! Mass execution, of loyal employees who love the brand. #hmvXFactorFiring
25m
hmv @hmvtweets
We're tweeting live from HR where we're all being fired! Exciting!! #hmvXFactorFiring
Categories:
blogging,
data leaking
Howto: Secure Java in three easy steps
Java has had a poor security reputation for some years now but January 2013 saw spectacular failures. Despite numerous fixes internet threats continue to break into victims' computers using security holes in Java.
If you uninstall Java you will be significantly safer than if you don't, but is that really the answer? After all, you may need to use Java to run some important piece of software. Or Minecraft.
The Java attacks that everyone is talking about are varied but occur when the victim browses an infected website. You can increase your computer's security massively by disabling Java in the browser, rather than throwing the baby out with the bathwater and ditching Java entirely.
Here's how you do it.
1. Open the Windows Control Panel and select the Java section.
2. Click on the Security tab.
3. Untick the option called 'Enable Java content in the browser' and click OK.
These instructions won't work if you are using a version of Java earlier than Java 7 Update 10. You should always update Java as a matter of course so, if you don't have the option listed in step three above, update and then try again.
If you uninstall Java you will be significantly safer than if you don't, but is that really the answer? After all, you may need to use Java to run some important piece of software. Or Minecraft.
The Java attacks that everyone is talking about are varied but occur when the victim browses an infected website. You can increase your computer's security massively by disabling Java in the browser, rather than throwing the baby out with the bathwater and ditching Java entirely.
Here's how you do it.
1. Open the Windows Control Panel and select the Java section.
2. Click on the Security tab.
3. Untick the option called 'Enable Java content in the browser' and click OK.
![]() |
| 3. Untick the option called 'Enable Java content in the browser' |
Categories:
criminal economy,
data leaking,
identity theft,
personal privacy,
security for normal people,
tips
Saturday, 19 January 2013
Howto: Handle a hacked email account
If your friends complain that you have sent them spam, your email account has probably been compromised.
First I'll explain what has happened, then what hasn't and, finally, what you should do about it.
What has happened?
Someone has obtained the password to your web-based email account. They have logged in and sent spam, quite possibly in the form of links to dubious or even dangerous websites, to contacts you have saved in your online address book.
Your password may have been stolen when you logged into your email account, possibly because you used a public wireless service at some stage. If so you almost certainly were not logged in using an encrypted connection.
An alternative way in which an attacker can acquire your email password is to send you a fake email that purports to come from your email service (e.g. Yahoo!). Such 'phishing' emails ask that you log into a fake website. When you type in your password it saves it and the person operating the site now has your details.
Sometimes an email service will be hacked and user's passwords stolen. This happened to Yahoo! last summer. In Yahoo!'s case the passwords appear to have been stored unencrypted, which is surprisingly unprofessional if true.
What has not happened?
The attacker has not just written emails and labelled them with your email address. While such 'spoofing' is possible, the fact that the spam was sent to your contacts indicates that the attacker has accessed your account.
There is no reason to assume that a hacker or a virus has compromised your personal computer. You can discover if the email was sent by your computer or someone else's by comparing email messages you sent yourself to the spam messages received by your contacts.
To find out how to do this, see Who sent the email? below.
What can you to to fix the problem?
1. Log into your email service and enable encrypted connections if available. The setting may be labelled HTTPS or SSL. Yahoo! Mail only offered this option in January this year, and it's not on by default. This article shows how to secure a Yahoo! Mail account.
2. Once you have addressed step one, and not before, change your password to something new and not obvious. For password tips, and a reason not to re-use the same one on different sites, see here.
(If you change your password before enabling encryption your new password will travel over the internet in plain text, which increases the chance that it could be stolen.)
3. Some email accounts let you specify an associated email account. If you lock yourself out of your main email service access may be granted via this secondary account. Check that the attacker has not changed this address to one that he controls.
4. Continue to be aware of phishing email threats and avoid falling for their tricks.
5. Be wary of using public WiFi just as a general rule.
6. To guard against having your details stolen or leaked change your passwords regularly.
Who sent the email?
All email messages contain technical details about the systems that they touch, from their origin to their destination. Look at the 'headers' to see who really sent the message.
In the following example message #1 was sent by the spammer, while message #2 was sent legitimately by the victim. I've trimmed out a lot of unnecessary headers below. Look at the underlined parts. I have changed some details to protect the innocent.
MESSAGE #1
Delivered-To: simon@h@k.me
...
Received: from [77.255.73.226] by web162906.mail.bf1.yahoo.com via HTTP; Mon, 14 Jan 2013 04:15:46 PST
MESSAGE #2
Delivered-To: simon@h@k.me
...
First I'll explain what has happened, then what hasn't and, finally, what you should do about it.
What has happened?
Someone has obtained the password to your web-based email account. They have logged in and sent spam, quite possibly in the form of links to dubious or even dangerous websites, to contacts you have saved in your online address book.
Your password may have been stolen when you logged into your email account, possibly because you used a public wireless service at some stage. If so you almost certainly were not logged in using an encrypted connection.
An alternative way in which an attacker can acquire your email password is to send you a fake email that purports to come from your email service (e.g. Yahoo!). Such 'phishing' emails ask that you log into a fake website. When you type in your password it saves it and the person operating the site now has your details.
Sometimes an email service will be hacked and user's passwords stolen. This happened to Yahoo! last summer. In Yahoo!'s case the passwords appear to have been stored unencrypted, which is surprisingly unprofessional if true.
What has not happened?
The attacker has not just written emails and labelled them with your email address. While such 'spoofing' is possible, the fact that the spam was sent to your contacts indicates that the attacker has accessed your account.
There is no reason to assume that a hacker or a virus has compromised your personal computer. You can discover if the email was sent by your computer or someone else's by comparing email messages you sent yourself to the spam messages received by your contacts.
To find out how to do this, see Who sent the email? below.
What can you to to fix the problem?
1. Log into your email service and enable encrypted connections if available. The setting may be labelled HTTPS or SSL. Yahoo! Mail only offered this option in January this year, and it's not on by default. This article shows how to secure a Yahoo! Mail account.
2. Once you have addressed step one, and not before, change your password to something new and not obvious. For password tips, and a reason not to re-use the same one on different sites, see here.
(If you change your password before enabling encryption your new password will travel over the internet in plain text, which increases the chance that it could be stolen.)
3. Some email accounts let you specify an associated email account. If you lock yourself out of your main email service access may be granted via this secondary account. Check that the attacker has not changed this address to one that he controls.
4. Continue to be aware of phishing email threats and avoid falling for their tricks.
5. Be wary of using public WiFi just as a general rule.
6. To guard against having your details stolen or leaked change your passwords regularly.
Who sent the email?
All email messages contain technical details about the systems that they touch, from their origin to their destination. Look at the 'headers' to see who really sent the message.
In the following example message #1 was sent by the spammer, while message #2 was sent legitimately by the victim. I've trimmed out a lot of unnecessary headers below. Look at the underlined parts. I have changed some details to protect the innocent.
MESSAGE #1
Delivered-To: simon@h@k.me
...
Received: from [77.255.73.226] by web162906.mail.bf1.yahoo.com via HTTP; Mon, 14 Jan 2013 04:15:46 PST
MESSAGE #2
Delivered-To: simon@h@k.me
...
Received: from [64.40.54.xxx] by web162904.mail.bf1.yahoo.com via HTTP; Mon, 14 Jan 2013 10:44:51 PST
What these tell us is that both the attacker and the victim used Yahoo! Mail using the web (HTTP) interface.
We can also see that the spammer was operating from an IP address of 77.255.73.226, while the victim was using 64.40.54.xxx.
Using an online tool like http://whois.domaintools.com we can find out where these people are based.
At the time of the attack the spammer was based in Warsaw. The tool reports the following (and more):
IP Information for 77.255.73.226
IP Location: Poland Warsaw Netia Sa
ASN: AS12741
Resolve Host: 77-255-73-226.adsl.inetia.pl
IP Address: 77.255.73.226
The victim's IP address, on the other hand, leads us to believe (correctly) that he was working from Seattle.
Thus we can conclude that the spammer was accessing the compromised email account using a web interface from Poland, rather than via the victim's PC in Seattle.
Categories:
data leaking,
identity theft,
personal privacy,
security for normal people,
social engineering,
spam,
threats,
tips
Sunday, 6 January 2013
Film scanner bundled with botnet
German coffee chain Tchibo has admitted to selling a film slide scanner that is infected with malware.
The company, which carries a range of gadgets alongside hot drinks, distributed a Hama scanner, the drivers for which were infected with the Conficker worm.
The is not the first time that consumer electronics have been accompanied by malicious code:
18/03/2010 Energizer Trojan keeps going
09/10/2008 Infected Asus Eee PCs
14/03/2008 Pre-installed viruses
Categories:
data leaking,
malware from legitimate sources,
personal privacy,
threats
Thursday, 20 December 2012
Popular disk encryption systems cracked
If you want your laptop's data to remain secure, even when stolen, one excellent solution is to encrypt the hard disk's partitions or even the whole disk.
Popular options include Microsoft's BitLocker, Symantec's PGP Whole Disk Encryption and the open source TrueCrypt software.
That news sounds frightening for those who use the above products to secure their data.
For those who work in digital forensics, however, the arrival of this tool will be welcome.
Elcomsoft has just announced that all of these encryption systems can be cracked by its new product, Elcomsoft Forensic Disk Decryptor.
![]() |
| Elcomsoft Forensic Disk Decryptor |
For those who work in digital forensics, however, the arrival of this tool will be welcome.
Until now data protected by these products was essentially unrecoverable without a suspect's cooperation.
It is important to note that the decrypting software will only be able to access the data under the following conditions:
- The target PC is running and...
- ...the attacker/investigator is able to obtain a memory dump.
Actually, there is an exception. If the computer was powered off, but had been put into hibernation mode while the encrypted disks/partitions were mounted, the investigator can also recover the necessary encryption keys.
Elcomsoft's blog post reminds us that it is possible to take a memory dump via a Firewire port.
There is a brute-forcing option available via the company's distributed processor cracking system (think SETI@home for password breaking).
If you use these encryption tools the safe option is to either shut down your computer completely, when leaving it unattended, or to unmount encrypted volumes before putting the computer into hibernation mode.
Categories:
data leaking,
personal privacy,
security software
Monday, 17 September 2012
Malware on new PCs not installed at factory
Microsoft has reported that some new computers are infected with malware.
The mainstream and technical media has taken up this disturbing story and published nearly identical versions, complete with the same quotes.
Sadly they often miss the main point of this incident.
What most stories on this subject claim: malware is pre-installed on new computers at the factory.
What Microsoft's document actually states: malware was found on a computer bought from a shop.
In the report's own words:
The BBC's version of events claims that, "Malware inserted on PC production lines, says study" continuing with the same flawed statement, "Several new computers have been found carrying malware installed in the factory, suggests a Microsoft study."
The Daily Mail's over-long headline warns that, "Hacker warning as research finds malware installed on computers before they even leave the production line". The report then uses the now-familiar, albeit grammatically incorrect, opening gambit of, "Criminals are installed malware on PCs before they even leave the factory."
There are a vast number of cookie cutter stories very similar to those above on the web.
Microsoft never made this claim, though. In fact its initial research was into the security of supply chains, rather than the internal security of factories. It is far more likely for a small business on the low-margin retail end of the line to engage in this sort of criminal activity than it is for a major manufacturer to compromise itself in this way.
Only one in 20 computers bought by Microsoft was infected.
In its report Microsoft claims to have found a copy of malware known as Nitol on just one of 20 computers that a researcher purchased. Three other PCs contained a few files that (unspecified) anti-virus software detected as being malware. This does not necessarily equate to an infection, though. In fact, as Microsoft notes, "The computer that contained the Nitol virus was the only one that was actively running."
Microsoft has published an article about its findings, which links to the document mentioned above, on its blog.
While this particular piece of research has been misrepresented, there have been verified cases of malware being installed at factories in the past:
18/03/2010 Energizer Trojan keeps going
The mainstream and technical media has taken up this disturbing story and published nearly identical versions, complete with the same quotes.
Sadly they often miss the main point of this incident.
What most stories on this subject claim: malware is pre-installed on new computers at the factory.
What Microsoft's document actually states: malware was found on a computer bought from a shop.
In the report's own words:
"Microsoft’s researchers purchased a Windows laptop computer from computer reseller in Shenzhen, China, which had been carelessly or intentionally infected with Nitol.A."The Guardian's story uses the headline, "Malware being installed on computers in factories, warns Microsoft" and opens with, "Criminals are installing malware on PCs before they leave the factory, according to Microsoft."
The BBC's version of events claims that, "Malware inserted on PC production lines, says study" continuing with the same flawed statement, "Several new computers have been found carrying malware installed in the factory, suggests a Microsoft study."
The Daily Mail's over-long headline warns that, "Hacker warning as research finds malware installed on computers before they even leave the production line". The report then uses the now-familiar, albeit grammatically incorrect, opening gambit of, "Criminals are installed malware on PCs before they even leave the factory."
There are a vast number of cookie cutter stories very similar to those above on the web.
Microsoft never made this claim, though. In fact its initial research was into the security of supply chains, rather than the internal security of factories. It is far more likely for a small business on the low-margin retail end of the line to engage in this sort of criminal activity than it is for a major manufacturer to compromise itself in this way.
Only one in 20 computers bought by Microsoft was infected.
In its report Microsoft claims to have found a copy of malware known as Nitol on just one of 20 computers that a researcher purchased. Three other PCs contained a few files that (unspecified) anti-virus software detected as being malware. This does not necessarily equate to an infection, though. In fact, as Microsoft notes, "The computer that contained the Nitol virus was the only one that was actively running."
Microsoft has published an article about its findings, which links to the document mentioned above, on its blog.
While this particular piece of research has been misrepresented, there have been verified cases of malware being installed at factories in the past:
18/03/2010 Energizer Trojan keeps going
09/10/2008 Infected Asus Eee PCs
14/03/2008 Pre-installed viruses
Friday, 3 August 2012
Sharing passwords with Tesco
"Every little helps," says the Tesco motto. Well, it seems that the UK's largest supermarket needs a little help with securing online customers' passwords.
Tesco's online shopping site does not protect customer passwords as thoroughly as it should. This in turn puts customers at risk because they probably use the same password with Tesco and other online services.
It is not realistic to expect people to have a unique password for every online service that they use. Normal people are not interested in security and have neither the time nor the energy to maintain (let alone memorise) a long list of strong passwords.
There are all sorts of clever solutions to this problem, including software that generates passwords that are impossible to memorise and then handle the passwords for you, providing access to the password-protected web sites. LastPass is just one example.
Realistically, though, the vast majority are going to use a handful of passwords for everything that they do. Quite likely some of these passwords will be on the list of common passwords published by ZDNet.
Another problem with managing passwords using applications is that increasingly people are accessing websites with multiple devices, such as smartphones. Windows and Mac applications and browser plugins don't transfer easily to all of the available mobile handsets.
If you have a small selection of passwords then I have some urgent advice for you.
There is an interesting list of sites that send users' passwords over email in cleartext on the Plain Text Offenders website.
---
If you are concerned about this type of problem you could create a short list of passwords, including some very strong ones as well as some very easy to remember ones. Use the strong ones for your most important services, possibly using a small variation for each. Use the less strong versions for less important services.
Is this ideal? Definitely not, but until online security moves away from simple username and password authentication regular users have little other choice.
Tesco's online shopping site does not protect customer passwords as thoroughly as it should. This in turn puts customers at risk because they probably use the same password with Tesco and other online services.
It is not realistic to expect people to have a unique password for every online service that they use. Normal people are not interested in security and have neither the time nor the energy to maintain (let alone memorise) a long list of strong passwords.
There are all sorts of clever solutions to this problem, including software that generates passwords that are impossible to memorise and then handle the passwords for you, providing access to the password-protected web sites. LastPass is just one example.
Realistically, though, the vast majority are going to use a handful of passwords for everything that they do. Quite likely some of these passwords will be on the list of common passwords published by ZDNet.
Another problem with managing passwords using applications is that increasingly people are accessing websites with multiple devices, such as smartphones. Windows and Mac applications and browser plugins don't transfer easily to all of the available mobile handsets.
If you have a small selection of passwords then I have some urgent advice for you.
- Do you have a Tesco online shopping account?
- Do you have any other online accounts for which you have used the same password as your Tesco account?
- Are these accounts in any way connected to important personal information or services, such as your email account(s) and financial services?
If you answered 'yes' to all of the above questions then it would be wise to log into every one of those services, except the Tesco site, and change your password immediately.
It is completely understandable, if not advisable, that you might want to use the same password for all of these services. If you do, do not then change your Tesco password to match this new one.
The reason for this urgent advice is that Tesco does not handle passwords in a particularly secure way. This has been publicised by Troy Hunt, who highlighted some problems with Tesco's website on his own site a few days ago.
---
If you are concerned about this type of problem you could create a short list of passwords, including some very strong ones as well as some very easy to remember ones. Use the strong ones for your most important services, possibly using a small variation for each. Use the less strong versions for less important services.
Is this ideal? Definitely not, but until online security moves away from simple username and password authentication regular users have little other choice.
Categories:
data leaking,
personal privacy,
security for normal people,
tips
Computer attack statistics
Did you know that global cost of cyber crime is $1 trillion?Or that buying counterfeit software DVDs is likely to contain malware?
The great $1 trillion scandal
$1 trillion is a lot of money, especially considering that the United States makes around $14 trillion a year.
It is possible, of course, that this figure is not accurate. In fact, it is very likely that this amount is wrong.
This has not stopped the media, leading politicians and other high-profile figures from quoting it.
Notable persons include US President Obama and NSA director General Keith Alexander. And security firm McAfee, which dropped the figure into a report it published last year.
Wired has published an insightful article that investigates the origin of the $1 trillion figure for money lost to cyber crime.
It found that a number of researchers and other experts had contributed in one way or another to the report, and that few of them recognised the veracity of the figure.
Here are some of their comments when asked about it:
Ross Anderson, security engineering professor, University of Cambridge
“I would have objected at the time had I known about it. The intellectual quality of this [$1 trillion number] is below abysmal.”Jackie Rees Ulmer, associate professor, ProPublica
"I expressed my concern with the number as we did not generate it... It is almost certainly the case that I would have told them the number was unsupportable."Sal Viveros, a McAfee's PR person who oversaw an older McAfee report, said that the figure was calculated as a result of a survey. The company took the total lost revenue that was reported and "multiplied it by the number of similar companies in the countries we studied," according to Viveros.
Does pirated software put you at risk of identity theft?
In October 2007 I met with Michala Alexander, then Microsoft's UK head of anti-piracy. I was news editor of Computer Shopper.
She claimed to have research that found, depending on which country you visit, that there was a good chance pirated software on physical media would be infected with malware.
Alexander told me, "People who buy pirated software are putting themselves at risk of cyber crime and identity theft."
The research did not appear to be available from Microsoft, though, and I discovered that the figures came from an IDC report called The Risks of Obtaining and Using Pirated Software. This seemed promising because, although the report was sponsored by Microsoft, IDC is both respected and independent.
However, IDC's report was based on research that involved software downloads. It explicitly did not address physical disks on sale abroad.
And so we return full circle to Microsoft, which provided some data for the same IDC report that it had sponsored."IDC did not test physical media. We did, however, review the work Microsoft conducted earlier in the year analyzing disks obtained by Microsoft employees who purchased mid-grade counterfeit software in various countries around the world."
Microsoft's own research does not support its own headline conclusions of heavy malware infections. In fact it does not mention malware at all, although it does refer to additional program files and tools used to bypass copy protection controls.
Microsoft placed research on physical counterfeit media into a report otherwise wholly dedicated to the malware threat of downloading counterfeit software. This made a close association, causing Microsoft to make incorrect conclusions in its press releases and press briefings.
Today Microsoft's anti-piracy web page states things a little more clearly:
"In an IDC study, 25% of web sites studied that offered counterfeit or pirated software also attempted to install spyware or Trojans... In studies conducted on counterfeit versions of Microsoft software... more than 40% of the... counterfeit disks installed contained additional programs or binaries with known vulnerabilities."It's interesting to note that installing any version of Windows, even from trustworthy media, will install programs with known vulnerabilities.
Categories:
criminal economy,
data leaking,
threats
Tuesday, 15 May 2012
Bring your own device?
![]() |
| BYOD has limits |
I was speaking on a panel at the SecureCloud 2012 conference in Frankfurt last week and the inevitable question about 'bring your own device' (BYOD) was posed.
The main theme of the conference seemed to be regulatory compliance. Don't stop reading. I'm not going to dig into that can of worms. Suffice to say that compliance is largely about rules and regulations. These may need to be in place for legal reasons but, as we'll see, they are certainly not a panacea.
So, given the question and the tone of the event, and the fact that plenty of people already connect their devices to their employer's network, my answer was along these lines:
- Yes, employees should be able to connect their devices (in most normal cases).
- Yes, employers should be able to prevent them from doing so (in certain cases, if there is a good reason).
- This prevention does not have to be a technical solution.
The third point caused a stir. Really? Surely to meet with the rules and regulations the computers and networks need to be controlled with a fist of iron? What about application controls? Website blocking? Network monitoring? Surely these are the answers?
These are all useful ways to find out what's happening but, if you lock things down too much, the following will happen:
- Regular users, who are doing nothing wrong, will be hampered in their work.
- Malicious users, who are trying to steal information, will still find a way.
The answer is not to impose strong technical measures but to let the users know that they are being watched and that any infractions will be dealt with.
While sat in front of the audience considering these issues I compared the situation to parents attempting to ensure that their children's internet access was a safe and pleasant experience. Should they install parental controls? Limit access using an automatic schedule? Block certain types of websites and applications? (Read more on this).
By all means, if you want to make work for yourself and increase the chances of your kids missing homework deadlines, lock the systems down. Alternatively, have conversations about risk and discuss safe and sensible online behaviour.
Children and unwise employees will always find a way around technical controls. I know of one occasion in which an employee didn't just bring in their own computer. They installed a wireless router on the company network. They did so even after the IT department sent out a message banning the use of personal network equipment.
Naturally the idiots involved (the users, not the IT dept.) failed to implement any security, such as a password. They created an instant and easily-accessible backdoor to the network.
The solution? HR.
Categories:
data leaking,
security software
Friday, 20 April 2012
Free encryption tools
Encrypting personal data is a sensible thing to do. If you computer is lost or stolen then at least your sensitive files are not at risk of being abused.
There are a number of common ways to do this:
Each of those options has its benefits and downsides. All can be achieved for free. Free encryption has been available for a long time but it is frequently hard to use.
PGP/GPG
Pretty Good Privacy (PGP) and GnuPG (GPG) aren't suitable for consumers simply because, even with the optional graphical interfaces, the very concepts that they rely on are not trivial to understand. They also usually involve both the sender of secrets and the receiver being equally competent.
Anyone can understand the idea that you can password-protect a file. Public key encryption is a little harder to understand and explaining it usually involves analogies involving Bob, Alice and Eve.
PGP/GPG are really useful tools. They just aren't that easy for regular users to handle.
PGPdisk
This fantastic tool allows you to create an encrypted archive that appears as an extra hard disk e.g. F:\
Any files placed into this disk are encrypted automatically and transparently. The user can act as if using a standard internal or USB drive. In fact you can place the archive on an external drive, which is quite a sensible thing to do.
Unmount the disk and the files are locked. Unlocking the files involves entering a password for the archive or for the private key (if you used it to create the archive).
You can also create self-decrypting archives. This means that the files are bundles into one Exe file. Send this to someone who knows the password and they can extract the files without owning a copy of PGPdisk. The downside to this is that you have to let them know the password in a secure way.
PGPdisk used to be free but this changed and you had to buy the commercial version of PGP to obtain it. Since Symantec bought PGP it's not clear to me whether or not it is still available at all. Free versions for Windows and Mac are still available from the PGPi website, but these are pretty ancient versions.
Windows EFS
Windows Encrypting File System, which is available on the more expensive versions of Windows XP, Vista, 7 and (soon) 8 is very easy to use but it has some significant problems too.
These include the ease with which users can lock themselves out of their computers and data, the complication of backing up an encryption certificate and the fact that the files are not protected while the user is logged in. This means that malware can steal data, even if the thief who stole your laptop cannot.
There is also some confusion over what happens when you copy encrypted files to other disks.
Here's an example of EFS going horribly wrong in a home environment. I encrypt some folders on my laptop. The laptop is shut down and the files are safe. I forget my password and boot the laptop using a password reset tool such as the Offline NT Password & Registry Editor. While I can access all of the unencrypted files, I have sadly lost access to the encrypted ones forever (unless I made a backup of my encryption certificate).
In a similar way, a vandal with access to the laptop could reset the password using the bootdisk mentioned above and then just walk away, having locked me out of my encrypted files.
Businesses and technical users will be aware of the need to backup the encryption certificate and should be able to cope with corrupted systems. They probably also have full, unencrypted backups. The same is unlikely of most home users.
TrueCrypt
The TrueCrypt software provides a relatively easy way to encrypt files, and has some very advanced features. However, it's interface is not as intuitive as some would like.
One really useful feature is its ability to fully encrypt the hard disk, including the boot partition. Anyone who does this will have some technical knowledge and interest, which is just as well because forgetting your password would be disastrous!
Sophos Free Encryption
Sophos Free Encryption provides a similar feature to to one that is provided in PGPdisk. This allows you to create self encrypted archives, a bit like password-protected Zip files.
Winzip, 7z and other password-protected archive tools
It is perfectly possible to store files in password-protected Zip files. This is the quick and easy way to achieve some level of privacy, although it is less convenient that using more transparent tools such as PGPdisk, TrueCrypt or EFS.
For example, finding files on your hard disk is easy when you can use Windows' search tools, Google Desktop or some other method. Searching inside encrypted Zip files, or creating catalogues of them, is a non-trivial task for regular home users.
Some older versions of Zip tools have a vulnerability that allows passwords to be recovered very easily using a variety of free or inexpensive tools.
There are a number of common ways to do this:
- Encrypt each file, one file at a time, manually.
- Create a bundle of files in one archive and encrypt the archive.
- Automatically encrypt all files placed into a specific folder/directory.
- Automatically encrypt all files placed into a virtual hard disk.
- Encrypt the entire hard disk, or portions of it.
Each of those options has its benefits and downsides. All can be achieved for free. Free encryption has been available for a long time but it is frequently hard to use.
PGP/GPG
Pretty Good Privacy (PGP) and GnuPG (GPG) aren't suitable for consumers simply because, even with the optional graphical interfaces, the very concepts that they rely on are not trivial to understand. They also usually involve both the sender of secrets and the receiver being equally competent.
Anyone can understand the idea that you can password-protect a file. Public key encryption is a little harder to understand and explaining it usually involves analogies involving Bob, Alice and Eve.
PGP/GPG are really useful tools. They just aren't that easy for regular users to handle.
PGPdisk
This fantastic tool allows you to create an encrypted archive that appears as an extra hard disk e.g. F:\
Any files placed into this disk are encrypted automatically and transparently. The user can act as if using a standard internal or USB drive. In fact you can place the archive on an external drive, which is quite a sensible thing to do.
Unmount the disk and the files are locked. Unlocking the files involves entering a password for the archive or for the private key (if you used it to create the archive).
You can also create self-decrypting archives. This means that the files are bundles into one Exe file. Send this to someone who knows the password and they can extract the files without owning a copy of PGPdisk. The downside to this is that you have to let them know the password in a secure way.
PGPdisk used to be free but this changed and you had to buy the commercial version of PGP to obtain it. Since Symantec bought PGP it's not clear to me whether or not it is still available at all. Free versions for Windows and Mac are still available from the PGPi website, but these are pretty ancient versions.
Windows EFS
Windows Encrypting File System, which is available on the more expensive versions of Windows XP, Vista, 7 and (soon) 8 is very easy to use but it has some significant problems too.
These include the ease with which users can lock themselves out of their computers and data, the complication of backing up an encryption certificate and the fact that the files are not protected while the user is logged in. This means that malware can steal data, even if the thief who stole your laptop cannot.
There is also some confusion over what happens when you copy encrypted files to other disks.
Here's an example of EFS going horribly wrong in a home environment. I encrypt some folders on my laptop. The laptop is shut down and the files are safe. I forget my password and boot the laptop using a password reset tool such as the Offline NT Password & Registry Editor. While I can access all of the unencrypted files, I have sadly lost access to the encrypted ones forever (unless I made a backup of my encryption certificate).
In a similar way, a vandal with access to the laptop could reset the password using the bootdisk mentioned above and then just walk away, having locked me out of my encrypted files.
Businesses and technical users will be aware of the need to backup the encryption certificate and should be able to cope with corrupted systems. They probably also have full, unencrypted backups. The same is unlikely of most home users.
TrueCrypt
The TrueCrypt software provides a relatively easy way to encrypt files, and has some very advanced features. However, it's interface is not as intuitive as some would like.
One really useful feature is its ability to fully encrypt the hard disk, including the boot partition. Anyone who does this will have some technical knowledge and interest, which is just as well because forgetting your password would be disastrous!
Sophos Free Encryption
Sophos Free Encryption provides a similar feature to to one that is provided in PGPdisk. This allows you to create self encrypted archives, a bit like password-protected Zip files.
Winzip, 7z and other password-protected archive tools
It is perfectly possible to store files in password-protected Zip files. This is the quick and easy way to achieve some level of privacy, although it is less convenient that using more transparent tools such as PGPdisk, TrueCrypt or EFS.
For example, finding files on your hard disk is easy when you can use Windows' search tools, Google Desktop or some other method. Searching inside encrypted Zip files, or creating catalogues of them, is a non-trivial task for regular home users.
Some older versions of Zip tools have a vulnerability that allows passwords to be recovered very easily using a variety of free or inexpensive tools.
Categories:
data leaking,
personal privacy,
security software,
windows 7,
windows 8,
windows vista
Thursday, 12 April 2012
OS X security (2002)
Ten years ago I wrote an article about OS X security for Mac User magazine.
The article noted that Mac users were now using a new operating system that was far more likely to face threats such as malware.
In light of the recent Flashback threat, and the resultant interest in Mac threats, I've pasted it below. Most of it is still relevant today.
[Note: If you are worried about the Flashback threat, you can check and clean your system using one or more of these tools.]
Securing Mac OS X
by Simon Edwards
Mac OS X opens more potential security holes to hackers. So how do you protect yourself?
Your Mac is at risk from hacker attacks, now more than ever. And if you don't take active steps to secure it you will be used as a Spam gateway, an unwitting accomplice of further hacker attacks or even a stooge in a bank robbery.
This isn't hype, it's reality. When Apple started shipping Macs loaded with OS X it was making a very powerful operating system available to thousands of users. But while people rejoiced in a new user interface and greater stability, many have not realised that by adopting a well-known operating system (UNIX) they have also opened themselves up to a raft of old and new security vulnerabilities.
The reason that Macs have been relatively free of remotely exploitable security holes is because the people who find and use such holes are only interested in the operating systems that they will commonly find on the Internet. Mac OS 9 is not common in comparison with Solaris, AIX, Windows NT and Linux operating systems, which is why the latter have been plagued by hackers for what feels like forever.
But OS X works in much the same way as Linux, Solaris and other UNIX-based systems. It can use the same software and, therefore, inherits the same benefits and vulnerabilities. The solution is not to revert to OS9, though. Instead, read this feature and you'll be able to lock down your Mac OS X machine against the most prevalent attacks.
First line of defence
OS X is a multi-user operating system, which means that many different people can use the computer at different times. Their application settings, e-mail and other files are kept separate so that one user cannot delete another's important data, or read his e-mail. While this means that the system is potentially more secure than a Mac OS 9 system, with regards to local users, the level of that security is only as good as the users' passwords. A recent survey found that 25 per cent of users believe that 'banana' is a strong password. This is incorrect for a number of reasons.
Firstly, banana is a real word that can easily be guessed by a password-cracking tool. Cracking tools work using dictionaries, and only resort to the very slow method of brute-forcing after all dictionary words have been tried. The brute force approach works like this: the cracker starts at 'a' and works through the alphabet, then adds another letter and continues through every permutation of letters, numbers and punctuation marks. This can take months, and it took our 700MHz system 28 days to crack the simple password 'rumble9'.
If you insist on using passwords of less than eight characters (not recommended), at least change them every month. That way you will foil this kind of attack most of the time. You should also use a mixture of capital and lower-case letters, numbers and punctuation marks. 'Mac_+Us3r01' is a good password but 'macuser' is not.
Service included
Programs such as a Web server, FTP server or a remote access utility are known as services. An Internet host is of little use unless if provides at least one service, but by doing so it is exposing itself to attack. A hacker needs something to hack at, and an old SMTP (mail), DNS, or Web server is sometimes all that is necessary. The trick is to run only those services that are really necessary.
Allowing remote access with older versions of Mac OS X meant enabling Telnet. This service lets you log in from a terminal on another computer, be it a Mac, PC or even PDA, and control the server as if using its own keyboard.
While this may seem like a very useful feature, Telnet is not a secure method of working. The problem is that when you log on using Telnet you have to enter your username and password, which is sent across the network (and maybe even the Internet, if you are logging in to a Web server installed in another building). Telnet sends these details in plain text, which can be intercepted by a hacker using a network sniffer. He will see 'user fred.bloggs' followed by 'password BaNa_na9'. Even though Fred has used a strong password, the hacker now knows it and can hack the system.
Mac OS X v.10.0.1 has replaced Telnet with SSH (Secure Shell), which is much better. It encrypts the connection so that instead of seeing the username and password, the hacker just sees digital garbage instead.
FTP also suffers from the same plaintext vulnerability as Telnet. You can replace FTP with the SSH equivalent, SFTP (Secure FTP) or SCP (Secure Copy). For details on setting up and using SSH, see the walkthrough below.
Updates
As we've already seen, updating your software can avoid some major problems. But even if you have a perfectly working Web server with SSH installed, things are not always as safe as they seem. New security holes emerge all the time and you'd be wise to subscribe to the main security mailing lists if you intend your Internet-connected Mac to survive. The best ones include the large selection at SecurityFocus (www.securityfocus.com).
For example, during the month in which this article was written, security updates were released to fix holes found in the Apache Web server, SSH, the Web scripting language PHP, the printing system, Internet Explorer 5.1, crontab, fetchmail, the firewall software ipfw, Telnet and a whole load of others. Failing to updates any of these packages could result in a hacker taking remote control of your computer, which is the ultimate goal for them and the ultimate nightmare for you.
The best way to update your software is to set the Software Update program to check for updates every day, or every week if you only connect to the Internet sporadically. To run this utility open the System Preferences and select Software Update option.
Buffer overflows
Security holes come in a number of shapes and sizes, and you can even create your own if you're not careful. The most common threat comes from buffer overflow attacks. The principle behind these is that a program installed on your system is written in such a way that when an attacker feeds it too much information it crashes.
In an analogy where the computer's memory is an empty glass and the incoming data is a flow of milk, a buffer overflow would occur if you tried to pour a pint of milk into a half-pint glass. Obviously some milk is going to spill onto the table, which results in a mess - or a crash, in the case of a computer system. But a clever hacker can cause the overflowing data to move into another part of the computer's memory, where it will be run. This is how they gain access to your system without even bothering about cracking your passwords.
Firewalls
One way to restrict a hacker's access to your system is by using a firewall. This program decides which information can flow out of and into your system. You can use a firewall to allow Internet users to access your Mac on port 80, which is the networking port used by most Web servers, but to deny access to any other port. SSH usually runs on port 22, so you'll probably want to allow external access to this port as well, if you want to administer the Web server from any Internet-connected location in the world.
But your file sharing ports, networked printer port and ports for other services that should only be available to the local network, not the Internet, need to be blocked off. Disallow all but the most necessary ports for outbound traffic too. That way you prevent malicious applications from sending important data out to an attacker on the Internet (see Viruses and backdoors below).
For a detailed description of setting up the firewall supplied with Mac OS X, see Configuring Mac OX X's firewall with BrickHouse, 19 April 2002, p79.
Wireless networks
While wireless networks are doubtless very cool and quite useful, remember that they increase the range of your network beyond your office. If you don't use encrypted networking (such as with SSH) you might as well stick a network port on the wall outside and wait for the hackers to jack in. There are plenty of tools that hackers can use to locate and crack your wireless network, but with a little care you can make it not worth their while to try.
If you're running a seriously expensive business over a wireless network consider setting up a virtual private network (VPN) to provide the encryption, and place dedicated firewalls between the wireless section of the network and other workstations. By treating the wireless part as an untrusted network, just as you would treat the Internet, you reduce the risk of a wireless attack massively.
Viruses and backdoors
While there are not many viruses that can affect UNIX operating systems directly, they are more than capable to moving through UNIX mail servers and onto the Mac and PC systems further down the chain. If your Mac is being used as an e-mail server you should consider installing an anti-virus program, which will strip out viruses intend on damaging your users' OS 9 Macs and Windows PCs. McAfee and Symantec have released Mac OS X anti-virus programs that will do the job.
The direct danger to Mac OS X systems is that once a hacker has compromised the security, using a buffer overflow attack or by exploiting some other weakness, he will install a backdoor that will allow him to return more easily. You can patch your system until you're blue in the face, but if you don't know about the backdoor you might as well give up.
When a hacker installs a backdoor he may replace some of your useful files with doctored versions that seem to behave properly but are actually helping to hide the hacker's files and activities. For example, he might have placed a stash of useful files in a directory called /hacks. The less command would display this directory, but a doctored version could be made that displayed every directory except this one.
We need a way to discover if files have been changed. CheckMate is a program that can scan essential files and create a special index of them, using checksums (see the Jargon box). If an important file is replaced the checksum will change and CheckMate will notify you that something is up. Knowing that your system has been compromised this heavily will help you save time when trying to work out what's wrong. If you find your basic files have been replaced there is only one thing to do - reinstall. Then install every possible update and run CheckMate again before connecting to the Internet.
File encryption
When you send an e-mail across the Internet it can be read by a large number of people, whether you know it or not. E-mail is created, sent and received in plain text, and passes through a number of systems on its journey to the intended recipient. Hackers with snuffer programs, mail system administrators and people with access to the computer used by your contact can all read the message, which is why sensitive information should always be encrypted.
Files stored on your hard disk should also be encrypted if they are sufficiently important. For example, if you've used CheckMate to generate an index of checksums you'll need to be sure that the hacker hasn't edited it to avoid an alert. Encrypt it and he's locked out. To encrypt e-mail and local files you'll need a good encryption package like PGP or GnuPG. The former is very easy to use and comes with a graphical installer, the latter is free but needs to be loaded from the Terminal command line.
To do this you'll need to download the GNU Privacy Guard file (GnuPGOSX1.0.6r6.dmg.gz) from http://macgpg.sourceforge.net, as well as the Darwin patch, which is called gnupg-1.0.6-darwin. Next, type:
tar -ax gnupg-1.0.6.tar.gz
To copy the Darwin patch into the folder that this creates, patch the software and install it type the following lines in order:
cp gnupg-1.0.6-darwin.diff gnupg-1.0.6/
cd gnupg-1.0.6/
patch -p 1 < gnupg-1.0.6-darwin.diff
./configure
make
sudo make install
You can now download the plethora of GUI helper tools from the same site. Or download the non-commercial version of PGP from pgpi.com.
Conclusion
If this article has started you worrying about Internet security, it has done its job. But while the Internet can be a hostile place, taking the simple steps listed here will make you almost invulnerable to the most common attacks. Just being aware of the risks puts you in a minority, and it's a good club to join.
Talk the talk
Buffer overflow A common but highly technical type of hacker attack, that is avoided by keeping software on the computer as up-to-date as possible. A successful attack allows the hacker to run commands on your system at the highest possible level of authority.
Checksum A checksum is a code that can be generated to represent a file. It is virtually impossible for two different files to have the same checksum, so it can be thought of as a fingerprint or DNA profile. This makes check summing an ideal technique for detecting if a file has been changed by a hacker.
Encryption The scrambling of a file or message so that it is readable only by the person for which it is intended. Encryption can be used for Internet traffic too (see SSH below), and is most commonly encountered when buying from a Web site - those yellow padlocks are indicative of an encrypted Web session.
Firewall A software program or hardware device that controls the type of network traffic able to pass through it. Usually used to protect computers or even whole networks from the Internet, they are now being installed by some to keep wireless networks safe.
Ports Different Internet services running on the same computer use different ports. This means that someone trying to connect to a system using FTP won't interfere with the Web server on the same machine. FTP uses port 21 whereas Web servers usually run on port 80. Services: A server is a computer that provides services to other users. Examples included POP3 mail, telnet or SSH remote access and Domain Name Services (DNS). Services are controlled by a file called /etc/inetd.conf.
SSH The Secure Shell creates an encrypted connection to your Mac, which means that hackers cannot see what you're up to, or what your password is. SSH can also be used to create virtual private networks (VPNs) across the very unprivate Internet.
Trojan A file that looks like something you want to run, but carries a less pleasant payload such as a computer virus or backdoor that creates a secret entry point for a hacker into your system.
UNIX These days UNIX is considered to mean a type of operating system, rather than a specific one. Solaris, Linux, FreeBSD and AIX are all types of UNIX, or are based on UNIX. Mac OS X is based on Darwin, which in turn is a version of BSD UNIX.
Using SSH
For security purposes, a server is any computer hooked up to the Internet that's capable of providing network services such as Web, FTP or mail. If you want to control your Mac OS X server remotely you'll need to use SSH, which has replaced the less secure Telnet originally shipped with the operating system. If you've never updated your installation you won't have SSH. You are strongly advised to download the very latest updates as soon as possible, particularly if your system spends any time at all connected to the Internet - even using a dial-up modem connection.
In this walkthrough we are assuming that your system is fully up to date and that you want to administer your computer from somewhere else on the local network. There is no real difference between doing this and coming in from the Internet. If you want to do connect from the Net you will need to ensure that any protective firewalls between you and the Internet will allow connections through port 22 or it won't work.
STEP ONE
Enabling remote access
Go to the Sharing System Preferences panel and choose the Sharing option from the Internet and Network section. Tick the Allow Remote Login box, which enables the Secure Shell (SSH) service. This operates on port 22, which is the default used by just about everybody. You absolutely must ensure that you are using Mac OS X version 10.0.1 or later, otherwise your remote access will be provided via Telnet, which is significantly less safe to use. We are using version 10.1.4 here.
STEP TWO
Establish a connection
Here we are assuming that you have two computers connected to the same network, one allowing remote access and that has an IP address of 10.0.0.1. You can determine the IP address of your remote server by going to System Preferences, choosing Network and viewing the settings for Built-in Ethernet. Start a terminal session on the non-remote access Mac (Terminal is available from the Utilities folder) Type: 'ssh username@10.0.0.1'. Use your own username and enter your password when prompted. Answer 'yes' when asked if you want to connect.
STEP THREE
Run commands
You can now administer your computer over the network, or even over the Internet. You'll need to have administrator rights to be able to change the system. These are provided in System Preferences from the Users option. Running 'top' will show you what processes (programs and background operations) are running. You can use the sudo command to run critical commands that require the ultimate level of authority. To reboot the Mac type 'sudo shutdown -r'.
STEP FOUR
Copying a file
Use the scp to copy a file from the server. Here we typed 'scp spge@10.1.22.23:backup backup', which has the effect of running scp, connecting to the server at 10.1.22.23, grabbing a file called backup and saving it as 'backup' on our system. The following line in the screenshot lists all files beginning with the letter 'b'. Using the list command (ls) with the -l switch shows more information, such as the file size, the date of its creation and who has permission to read or edit it.
Further information
Pretty Good Privacy (PGP) E-mail and general file encryption utility that can make your files unreadable to everyone but yourself
Free, for personal use
http://www.pgpi.com
GNU Privacy Guard Essentially a free version of PGP, you'll also need to download some other utilities to make it extra friendly to use.
Freeware, even for commercial use
http://macgpg.sourceforge.net
CheckMate Generate and compare checksums of essential files to discover if a hacker has altered your system.
Free, while in beta
http://personalpages.tds.net/~brian_hill/checkmate.html
Hints and tips
Watch your logs!
When a hacker takes over you system is won't be quietly, but unless you look through your log files you'll never know what's happened. It is necessary to know how a hacker broke in, even if you are going to reinstall your whole system, because that way you can fix the problem. Reinstalling will just reset your computer and the hacker can come back in the same way he did before. You'll find your logs in the directory called /var/log. Type 'last' from the terminal to see who's been logging in, and when.
Keep an eye on your users
If only you and a couple of other people are using the Mac there should only be a handful of names in the user list accessible from System Preferences - Users. If odd entries appear you can be sure that someone has administrator-level control of your system. If you want to know who's logged in at any one time type: w from the terminal command line to see a list. You should also check the /Users directory to see if any extra sub-directories have been created. This would indicate that someone has gained access to your system.
First Published in MacUser, Vol 18 No 13, 28 June 2002.
The above article is © Dennis Publishing Limited 2002. UK property of Dennis Publishing Ltd. This article may not be reproduced or transmitted in any form in whole or in part without the written consent of the publishers.
The article noted that Mac users were now using a new operating system that was far more likely to face threats such as malware.
In light of the recent Flashback threat, and the resultant interest in Mac threats, I've pasted it below. Most of it is still relevant today.
[Note: If you are worried about the Flashback threat, you can check and clean your system using one or more of these tools.]
Securing Mac OS X
by Simon Edwards
Mac OS X opens more potential security holes to hackers. So how do you protect yourself?
Your Mac is at risk from hacker attacks, now more than ever. And if you don't take active steps to secure it you will be used as a Spam gateway, an unwitting accomplice of further hacker attacks or even a stooge in a bank robbery.
This isn't hype, it's reality. When Apple started shipping Macs loaded with OS X it was making a very powerful operating system available to thousands of users. But while people rejoiced in a new user interface and greater stability, many have not realised that by adopting a well-known operating system (UNIX) they have also opened themselves up to a raft of old and new security vulnerabilities.
The reason that Macs have been relatively free of remotely exploitable security holes is because the people who find and use such holes are only interested in the operating systems that they will commonly find on the Internet. Mac OS 9 is not common in comparison with Solaris, AIX, Windows NT and Linux operating systems, which is why the latter have been plagued by hackers for what feels like forever.
But OS X works in much the same way as Linux, Solaris and other UNIX-based systems. It can use the same software and, therefore, inherits the same benefits and vulnerabilities. The solution is not to revert to OS9, though. Instead, read this feature and you'll be able to lock down your Mac OS X machine against the most prevalent attacks.
First line of defence
OS X is a multi-user operating system, which means that many different people can use the computer at different times. Their application settings, e-mail and other files are kept separate so that one user cannot delete another's important data, or read his e-mail. While this means that the system is potentially more secure than a Mac OS 9 system, with regards to local users, the level of that security is only as good as the users' passwords. A recent survey found that 25 per cent of users believe that 'banana' is a strong password. This is incorrect for a number of reasons.
Firstly, banana is a real word that can easily be guessed by a password-cracking tool. Cracking tools work using dictionaries, and only resort to the very slow method of brute-forcing after all dictionary words have been tried. The brute force approach works like this: the cracker starts at 'a' and works through the alphabet, then adds another letter and continues through every permutation of letters, numbers and punctuation marks. This can take months, and it took our 700MHz system 28 days to crack the simple password 'rumble9'.
If you insist on using passwords of less than eight characters (not recommended), at least change them every month. That way you will foil this kind of attack most of the time. You should also use a mixture of capital and lower-case letters, numbers and punctuation marks. 'Mac_+Us3r01' is a good password but 'macuser' is not.
Service included
Programs such as a Web server, FTP server or a remote access utility are known as services. An Internet host is of little use unless if provides at least one service, but by doing so it is exposing itself to attack. A hacker needs something to hack at, and an old SMTP (mail), DNS, or Web server is sometimes all that is necessary. The trick is to run only those services that are really necessary.
Allowing remote access with older versions of Mac OS X meant enabling Telnet. This service lets you log in from a terminal on another computer, be it a Mac, PC or even PDA, and control the server as if using its own keyboard.
While this may seem like a very useful feature, Telnet is not a secure method of working. The problem is that when you log on using Telnet you have to enter your username and password, which is sent across the network (and maybe even the Internet, if you are logging in to a Web server installed in another building). Telnet sends these details in plain text, which can be intercepted by a hacker using a network sniffer. He will see 'user fred.bloggs' followed by 'password BaNa_na9'. Even though Fred has used a strong password, the hacker now knows it and can hack the system.
Mac OS X v.10.0.1 has replaced Telnet with SSH (Secure Shell), which is much better. It encrypts the connection so that instead of seeing the username and password, the hacker just sees digital garbage instead.
FTP also suffers from the same plaintext vulnerability as Telnet. You can replace FTP with the SSH equivalent, SFTP (Secure FTP) or SCP (Secure Copy). For details on setting up and using SSH, see the walkthrough below.
Updates
As we've already seen, updating your software can avoid some major problems. But even if you have a perfectly working Web server with SSH installed, things are not always as safe as they seem. New security holes emerge all the time and you'd be wise to subscribe to the main security mailing lists if you intend your Internet-connected Mac to survive. The best ones include the large selection at SecurityFocus (www.securityfocus.com).
For example, during the month in which this article was written, security updates were released to fix holes found in the Apache Web server, SSH, the Web scripting language PHP, the printing system, Internet Explorer 5.1, crontab, fetchmail, the firewall software ipfw, Telnet and a whole load of others. Failing to updates any of these packages could result in a hacker taking remote control of your computer, which is the ultimate goal for them and the ultimate nightmare for you.
The best way to update your software is to set the Software Update program to check for updates every day, or every week if you only connect to the Internet sporadically. To run this utility open the System Preferences and select Software Update option.
Buffer overflows
Security holes come in a number of shapes and sizes, and you can even create your own if you're not careful. The most common threat comes from buffer overflow attacks. The principle behind these is that a program installed on your system is written in such a way that when an attacker feeds it too much information it crashes.
In an analogy where the computer's memory is an empty glass and the incoming data is a flow of milk, a buffer overflow would occur if you tried to pour a pint of milk into a half-pint glass. Obviously some milk is going to spill onto the table, which results in a mess - or a crash, in the case of a computer system. But a clever hacker can cause the overflowing data to move into another part of the computer's memory, where it will be run. This is how they gain access to your system without even bothering about cracking your passwords.
Firewalls
One way to restrict a hacker's access to your system is by using a firewall. This program decides which information can flow out of and into your system. You can use a firewall to allow Internet users to access your Mac on port 80, which is the networking port used by most Web servers, but to deny access to any other port. SSH usually runs on port 22, so you'll probably want to allow external access to this port as well, if you want to administer the Web server from any Internet-connected location in the world.
But your file sharing ports, networked printer port and ports for other services that should only be available to the local network, not the Internet, need to be blocked off. Disallow all but the most necessary ports for outbound traffic too. That way you prevent malicious applications from sending important data out to an attacker on the Internet (see Viruses and backdoors below).
For a detailed description of setting up the firewall supplied with Mac OS X, see Configuring Mac OX X's firewall with BrickHouse, 19 April 2002, p79.
Wireless networks
While wireless networks are doubtless very cool and quite useful, remember that they increase the range of your network beyond your office. If you don't use encrypted networking (such as with SSH) you might as well stick a network port on the wall outside and wait for the hackers to jack in. There are plenty of tools that hackers can use to locate and crack your wireless network, but with a little care you can make it not worth their while to try.
If you're running a seriously expensive business over a wireless network consider setting up a virtual private network (VPN) to provide the encryption, and place dedicated firewalls between the wireless section of the network and other workstations. By treating the wireless part as an untrusted network, just as you would treat the Internet, you reduce the risk of a wireless attack massively.
Viruses and backdoors
While there are not many viruses that can affect UNIX operating systems directly, they are more than capable to moving through UNIX mail servers and onto the Mac and PC systems further down the chain. If your Mac is being used as an e-mail server you should consider installing an anti-virus program, which will strip out viruses intend on damaging your users' OS 9 Macs and Windows PCs. McAfee and Symantec have released Mac OS X anti-virus programs that will do the job.
The direct danger to Mac OS X systems is that once a hacker has compromised the security, using a buffer overflow attack or by exploiting some other weakness, he will install a backdoor that will allow him to return more easily. You can patch your system until you're blue in the face, but if you don't know about the backdoor you might as well give up.
When a hacker installs a backdoor he may replace some of your useful files with doctored versions that seem to behave properly but are actually helping to hide the hacker's files and activities. For example, he might have placed a stash of useful files in a directory called /hacks. The less command would display this directory, but a doctored version could be made that displayed every directory except this one.
We need a way to discover if files have been changed. CheckMate is a program that can scan essential files and create a special index of them, using checksums (see the Jargon box). If an important file is replaced the checksum will change and CheckMate will notify you that something is up. Knowing that your system has been compromised this heavily will help you save time when trying to work out what's wrong. If you find your basic files have been replaced there is only one thing to do - reinstall. Then install every possible update and run CheckMate again before connecting to the Internet.
File encryption
When you send an e-mail across the Internet it can be read by a large number of people, whether you know it or not. E-mail is created, sent and received in plain text, and passes through a number of systems on its journey to the intended recipient. Hackers with snuffer programs, mail system administrators and people with access to the computer used by your contact can all read the message, which is why sensitive information should always be encrypted.
Files stored on your hard disk should also be encrypted if they are sufficiently important. For example, if you've used CheckMate to generate an index of checksums you'll need to be sure that the hacker hasn't edited it to avoid an alert. Encrypt it and he's locked out. To encrypt e-mail and local files you'll need a good encryption package like PGP or GnuPG. The former is very easy to use and comes with a graphical installer, the latter is free but needs to be loaded from the Terminal command line.
To do this you'll need to download the GNU Privacy Guard file (GnuPGOSX1.0.6r6.dmg.gz) from http://macgpg.sourceforge.net, as well as the Darwin patch, which is called gnupg-1.0.6-darwin. Next, type:
tar -ax gnupg-1.0.6.tar.gz
To copy the Darwin patch into the folder that this creates, patch the software and install it type the following lines in order:
cp gnupg-1.0.6-darwin.diff gnupg-1.0.6/
cd gnupg-1.0.6/
patch -p 1 < gnupg-1.0.6-darwin.diff
./configure
make
sudo make install
You can now download the plethora of GUI helper tools from the same site. Or download the non-commercial version of PGP from pgpi.com.
Conclusion
If this article has started you worrying about Internet security, it has done its job. But while the Internet can be a hostile place, taking the simple steps listed here will make you almost invulnerable to the most common attacks. Just being aware of the risks puts you in a minority, and it's a good club to join.
Talk the talk
Buffer overflow A common but highly technical type of hacker attack, that is avoided by keeping software on the computer as up-to-date as possible. A successful attack allows the hacker to run commands on your system at the highest possible level of authority.
Checksum A checksum is a code that can be generated to represent a file. It is virtually impossible for two different files to have the same checksum, so it can be thought of as a fingerprint or DNA profile. This makes check summing an ideal technique for detecting if a file has been changed by a hacker.
Encryption The scrambling of a file or message so that it is readable only by the person for which it is intended. Encryption can be used for Internet traffic too (see SSH below), and is most commonly encountered when buying from a Web site - those yellow padlocks are indicative of an encrypted Web session.
Firewall A software program or hardware device that controls the type of network traffic able to pass through it. Usually used to protect computers or even whole networks from the Internet, they are now being installed by some to keep wireless networks safe.
Ports Different Internet services running on the same computer use different ports. This means that someone trying to connect to a system using FTP won't interfere with the Web server on the same machine. FTP uses port 21 whereas Web servers usually run on port 80. Services: A server is a computer that provides services to other users. Examples included POP3 mail, telnet or SSH remote access and Domain Name Services (DNS). Services are controlled by a file called /etc/inetd.conf.
SSH The Secure Shell creates an encrypted connection to your Mac, which means that hackers cannot see what you're up to, or what your password is. SSH can also be used to create virtual private networks (VPNs) across the very unprivate Internet.
Trojan A file that looks like something you want to run, but carries a less pleasant payload such as a computer virus or backdoor that creates a secret entry point for a hacker into your system.
UNIX These days UNIX is considered to mean a type of operating system, rather than a specific one. Solaris, Linux, FreeBSD and AIX are all types of UNIX, or are based on UNIX. Mac OS X is based on Darwin, which in turn is a version of BSD UNIX.
Using SSH
For security purposes, a server is any computer hooked up to the Internet that's capable of providing network services such as Web, FTP or mail. If you want to control your Mac OS X server remotely you'll need to use SSH, which has replaced the less secure Telnet originally shipped with the operating system. If you've never updated your installation you won't have SSH. You are strongly advised to download the very latest updates as soon as possible, particularly if your system spends any time at all connected to the Internet - even using a dial-up modem connection.
In this walkthrough we are assuming that your system is fully up to date and that you want to administer your computer from somewhere else on the local network. There is no real difference between doing this and coming in from the Internet. If you want to do connect from the Net you will need to ensure that any protective firewalls between you and the Internet will allow connections through port 22 or it won't work.
STEP ONE
Enabling remote access
Go to the Sharing System Preferences panel and choose the Sharing option from the Internet and Network section. Tick the Allow Remote Login box, which enables the Secure Shell (SSH) service. This operates on port 22, which is the default used by just about everybody. You absolutely must ensure that you are using Mac OS X version 10.0.1 or later, otherwise your remote access will be provided via Telnet, which is significantly less safe to use. We are using version 10.1.4 here.
STEP TWO
Establish a connection
Here we are assuming that you have two computers connected to the same network, one allowing remote access and that has an IP address of 10.0.0.1. You can determine the IP address of your remote server by going to System Preferences, choosing Network and viewing the settings for Built-in Ethernet. Start a terminal session on the non-remote access Mac (Terminal is available from the Utilities folder) Type: 'ssh username@10.0.0.1'. Use your own username and enter your password when prompted. Answer 'yes' when asked if you want to connect.
STEP THREE
Run commands
You can now administer your computer over the network, or even over the Internet. You'll need to have administrator rights to be able to change the system. These are provided in System Preferences from the Users option. Running 'top' will show you what processes (programs and background operations) are running. You can use the sudo command to run critical commands that require the ultimate level of authority. To reboot the Mac type 'sudo shutdown -r'.
STEP FOUR
Copying a file
Use the scp to copy a file from the server. Here we typed 'scp spge@10.1.22.23:backup backup', which has the effect of running scp, connecting to the server at 10.1.22.23, grabbing a file called backup and saving it as 'backup' on our system. The following line in the screenshot lists all files beginning with the letter 'b'. Using the list command (ls) with the -l switch shows more information, such as the file size, the date of its creation and who has permission to read or edit it.
Further information
Pretty Good Privacy (PGP) E-mail and general file encryption utility that can make your files unreadable to everyone but yourself
Free, for personal use
http://www.pgpi.com
GNU Privacy Guard Essentially a free version of PGP, you'll also need to download some other utilities to make it extra friendly to use.
Freeware, even for commercial use
http://macgpg.sourceforge.net
CheckMate Generate and compare checksums of essential files to discover if a hacker has altered your system.
Free, while in beta
http://personalpages.tds.net/~brian_hill/checkmate.html
Hints and tips
Watch your logs!
When a hacker takes over you system is won't be quietly, but unless you look through your log files you'll never know what's happened. It is necessary to know how a hacker broke in, even if you are going to reinstall your whole system, because that way you can fix the problem. Reinstalling will just reset your computer and the hacker can come back in the same way he did before. You'll find your logs in the directory called /var/log. Type 'last' from the terminal to see who's been logging in, and when.
Keep an eye on your users
If only you and a couple of other people are using the Mac there should only be a handful of names in the user list accessible from System Preferences - Users. If odd entries appear you can be sure that someone has administrator-level control of your system. If you want to know who's logged in at any one time type: w from the terminal command line to see a list. You should also check the /Users directory to see if any extra sub-directories have been created. This would indicate that someone has gained access to your system.
First Published in MacUser, Vol 18 No 13, 28 June 2002.
The above article is © Dennis Publishing Limited 2002. UK property of Dennis Publishing Ltd. This article may not be reproduced or transmitted in any form in whole or in part without the written consent of the publishers.
Categories:
criminal economy,
data leaking,
identity theft,
os x,
personal firewalls,
personal privacy,
security software,
threats,
tips
Monday, 2 April 2012
Military grade data protection
![]() |
| Miliitary-grade Garibaldi biscuits |
It's fairly common practice for disk wiping and encryption software to make such claims. But what does 'military grade' actually mean?
The short answer is, it doesn't really mean anything.
At best it could mean that, at some stage in the past, a military organisation has approved the use of an item. This could be an encrypted USB drive or a packet of Garibaldi biscuits (aka Biscuits Fruit AB).
Another possibility is that the military has some standards in place, to which all equipment that it uses must comply.
Bullets are one good example. The British Army uses a standard sized bullet that works in its regular rifles and machine guns. In fact, this ammunition is compatible with the US Army's M16 rifle and with other weapons used by NATO countries.
File/disk encryption
The sort of software and hardware that consumers have access to is not equivalent to the high-end equipment that the military uses for important tasks.
However, even specialist chips are not invulnerable so 'military-grade' does not mean uncrackable.
Disk wiping
One classic claim made by disk wiping software is that it conforms to the Department of Defense's standards for data sanitisation. In fact you may often see reference to an impressive-looking 'standard' called DoD 5220.22-M.
This claim has always been fairly meaningless and, since mid-1997, it's been entirely irrelevant. Here's why:
- Not all data is equally sensitive. Highly secret data is treated quite differently to that which is less important. DoD 5220.22-M doesn't cover a specific security level of data.
- An old standard is not necessarily the best practice today. It possibly wasn't even that great an idea when it was first formalised. Governments and the military do not always use the best equipment on the market.
Governmental organisations may have to destroy disks physically if they contain certain levels of sensitive data. In less sensitive cases they may use strong magnetic fields to wipe data. Currently PC software is unable to achieve either of these goals.
Imagine you see an advert for disk-wiping software that promises military-grade data destruction. It invokes DoD 5220.22-M to support its claim. It's fair to assume that if the US Department of Defense has formalised a standard, and if this software conforms to it, then its users would be about as secure as anyone in the world.
This is an incorrect assumption.
Disk wiping software overwrites data one or more times to make it hard to recover. Before June 1997 DoD 5220.22-M supported this technique as a valid one - although it didn't specify whether or not this was appropriate for secret or unimportant files.
After June 1997 the only supported methods of disk sanitisation was either using magnetic fields or physical destruction. If you download the current DSS Clearing and Sanitization Matrix you'll see that magnetic disks must be degaussed (a/b) or physically destroyed (l).
An example
There are plenty of developers that market their tools in this rather misleading way. I'll demonstrate this using LSoft Technologies' Active@ KillDisk, but there are plenty of others that do the same.
[Possibly the most honest I've seen is the Linux utility scrub, which has documentation including caveats.]
The KillDisk site claims that:
The above link leads to an outdated Clearing and Sanitization Matrix, which permits the use of overwriting on magnetic disks when sanitising. It does, however, note that:
If you want to wipe your hard disk before selling it, then a disk wiping program is probably good enough. However, if it contained data that you never, ever want anyone to discover then destruction is the only real answer.
If you want to destroy the data on a hard disk, so that it can never be recovered, you might want to explore the following options:
Destroy the platters:
Destroy the entire disk:
Imagine you see an advert for disk-wiping software that promises military-grade data destruction. It invokes DoD 5220.22-M to support its claim. It's fair to assume that if the US Department of Defense has formalised a standard, and if this software conforms to it, then its users would be about as secure as anyone in the world.
This is an incorrect assumption.
Disk wiping software overwrites data one or more times to make it hard to recover. Before June 1997 DoD 5220.22-M supported this technique as a valid one - although it didn't specify whether or not this was appropriate for secret or unimportant files.
After June 1997 the only supported methods of disk sanitisation was either using magnetic fields or physical destruction. If you download the current DSS Clearing and Sanitization Matrix you'll see that magnetic disks must be degaussed (a/b) or physically destroyed (l).
An example
There are plenty of developers that market their tools in this rather misleading way. I'll demonstrate this using LSoft Technologies' Active@ KillDisk, but there are plenty of others that do the same.
[Possibly the most honest I've seen is the Linux utility scrub, which has documentation including caveats.]
The KillDisk site claims that:
"If you use FDISK, FORMAT utilities, or DELETE standard operating system command for data removal, there is always a chance to recover deleted files (using undelete or unformat tools) and use against the owner's will."Directly under this correct statement is this line:
→ DoD 5220.22 M compliant ←The clear implication is that by using this tool you remove the aforementioned chance of data recovery.
The above link leads to an outdated Clearing and Sanitization Matrix, which permits the use of overwriting on magnetic disks when sanitising. It does, however, note that:
"THIS METHOD IS NOT APPROVED FOR SANITIZING MEDIA THAT CONTAINS TOP SECRET INFORMATION."On another page the site lists some useful definitions, without providing any context:
3 - US DoD 5220.22-M
The write head passes over each sector three times. The first time with zeros (0x00), second time with 0xFF and the third time with random characters. There is one final pass to verify random characters by reading.
4 - US DoD 5220.22-M (ECE)So what should you do?
The write head passes over each sector seven times. The first time with zeros (0x00), second time with 0xFF and the third time with random characters, the fourth time with 0x96, and then first three passes repeated again. There is one final pass to verify random characters by reading.
If you want to wipe your hard disk before selling it, then a disk wiping program is probably good enough. However, if it contained data that you never, ever want anyone to discover then destruction is the only real answer.
If you want to destroy the data on a hard disk, so that it can never be recovered, you might want to explore the following options:
Destroy the platters:
Destroy the entire disk:
Categories:
data leaking,
personal privacy,
security software
Subscribe to:
Posts (Atom)






















