Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Monday, November 11, 2013

Gen Y workers OK with flouting cloud, byod policies

IT World Canada has an interesting article on an issue a lot of my customers have been asking about lately:

Corporate IT administrators may have more to worry about than just the wave of smart watches, Google glasses and other wearable computing devices that could flood the enterprise soon. A recent survey of indicates that more than half of Generation Y workers are prepared to contravene corporate bring your own device and cloud computing policies if it cramps their personal and professional computing and social networking activity.


Thursday, December 13, 2012

Skynet Botnet Controlled Over Tor

A botnet has been discovered that uses a hidden Tor IRC service for command and control. Although Tor tends to be on the slow side, the extra layers of anonymity make it significantly difficult and maybe even impossible to locate either the C&C servers, or the people running them.

All kinds of direct hack attacks probably occur over the Tor network. This use however, is interesting in that there currently is no known method for shutting them down. I expect that once a compromised server is found, researchers will begin looking for vulnerabilities on the hidden Tor services in the hopes of finding a vulnerability that exposes the actual IP information.

The article discusses how the bots are being used to mine bitcoins.

Either way, this is interesting, and probably will soon be the de facto way to run botnets.

Wednesday, December 12, 2012

Ransom hackers encrypt medical centre's entire database

An Australian medical centre is reported to be considering paying a ransom demand of $4,000 AUD (US$4215) after blackmailers broke into the organisation’s servers and encrypted its entire patient database.

 If crime doesn't pay, why is this clinic considering making it profitable? Paying ransom only perpetuates the problem. Instead they should be spending the money on securing their systems. The clinic should be asking themselves:


  1. Why should I make this crime profitable for the attacker? 
  2. How do I know they will provide the password and instructions for decrypting the data? 
  3. How do I know that if I decrypt the database, the data hasn't been tampered with? 
  4.  If I pay the ransom, what is to stop them from increasing the demand lest they publish the data online?
  5. What is a better plan for securing the systems and moving on? 


They already lost once. If they don't bite the bullet and move on, they risk losing again and again. They would also be giving the attackers valuable incentives for attacking more sites.

Saturday, August 20, 2011

AES crypto broken by 'groundbreaking' attack


Cryptographers have discovered a way to break the Advanced Encryption Standard used to protect everything from top-secret government documents to online banking transactions.


Biclique Analysis allows 2 bits to be knocked off the key, speeding up brute force attacks by up to 5 times.


It still takes a little longer than you'll be around (trillions of years) to crack a 256 key this way. But they're well on the way.


Sunday, June 19, 2011

Quantum Cryptography Not All It's CRACKED Up To Be.

This story is an easy-to-read easy-to-understand description of a flaw in quantum cryptography that allows an observer to determine the quantum key. Until now, this was theoretically impossible. If my 20 years in information security has taught me one thing, it is that hackers love impossibilities.

Tuesday, March 8, 2011

Nexus S Android Sniffs and Emulates RFID tags

The Nexus S Android phone is capable of reading and emulating RFID. An application called Farebot demonstrates how the phone could be used to emulate RFID fare cards. This apparently could make it cheaper and more convenient for transit riders. However, the software's author also points out how many of these cards keep records trip information in clear-text. This creates a bit of a privacy issue since it is so easy for this software to read cards from people who merely happen to walk close enough to you.

Currently FareBot can parse and display balance and trip history information from Seattle’s ORCA card, and can dump raw data from any other MIFARE DESFire card including San Francisco’s Clipper card. FareBot is open-source and designed to be flexible so that hopefully other developers will add support for other types of cards.

Friday, October 1, 2010

Blackberry Encryption Cracked

Elcomsoft, the overseas infosec group who seem to be able to break into just about everything, have now cracked the Blackberry encryption mechanism.

It seems like only yesterday when certain freedom-free countries were complaining that they couldn't read Blackberry messages sent by their own hostile population.

Thursday, September 2, 2010

Using a Blackberry in the UAE?

Apparently Arabic blackberries aren't the only devices with neutered security controls.  According to Slate, mobile phone company Etisalat is the digital certificate authority in the UAE. This would allow Etisalat to decrypt any messages relying on their services.

It is worth noting that Etisalat is already known to spy on their Blackberry users, by deliberately keeping copies of all emails passing through the service.

Monday, August 2, 2010

A DEF CON speaker was detained at the US border and asked about his involvement with the Wikileaks.org whistle-blowing website. They returned his laptop, but three of his cell phones were confiscated, and will probably never be seen again.

After mentioning this during his presentation (which was about onion routing), he was greeted by FBI agents who hoped to probe him. One of the spooks was quoted as saying "sometimes it's nice to have a conversation to flesh things out."

Tuesday, July 27, 2010

MoD Squad Loses an Unencrypted Laptop Every Other Day

For the past 2 years, the British Ministry of Defense has been on a losing streak. 120 laptops are known to have been stolen, and 220 more went missing one way or other. Most of them did not use encryption.

What else did they lose?
  • 593 CDs, DVDs and diskettes
  • 215 memory cards
  • 96 USB hard drives
  • 13 cell phones
  • 600,000 records of recruits and potential recruits
In previous years, things were just as bad. Clearly their infosec team should be looking at Follow-Up as a key security Control.

Friday, May 21, 2010

Unbreakable Encryption already Broken

After 10 years of hearing different theories of how quantum mechanics can be used to implement unbreakable encryption, a fellow Canadian has done the deed, and discovered a fairly simple method for deriving the secret keys used in an encrypted communication. It seems appropriate to mention that every time scientists start talking like salesmen, calling their "discoveries" unbreakable, unbeatable, undetectable, etc, someone comes along to prove the theory wrong. Ah well, better luck next time.