Friday, June 7, 2013

Hacker charged with stealing from police databases

Hacker charged with stealing from police databases

Peter Stanners
 
Pirate Bay co-founder Gottfrid Svartholm Warg is suspected as an accomplice of the 20-year-old who was arrested yesterday following a tip-off from the Swedish authorities
img_src
Gottfrid Svartholm Warg from the Pirate Bay is wanted as an accomplice (Photo: Scanpix)
A suspected hacker was charged today with breaking into the police’s IT system and stealing vast amounts of private information including social security (CPR) numbers.
The 20-year-old Dane was arrested yesterday following a police investigation that was started in January when Swedish authorities alerted the Danish national police, Rigspolitiet, that their IT system may have been broken into.
Gottfrid Svartholm Warg, the notorious Swedish hacker and co-founder of filesharing website the Pirate Bay, has also been charged by the Danish police, who are demanding his extradition.
Warg is currently in custody in Sweden after being arrested on suspicion of hacking into the bank Nordea and the Swedish equivalent of the CPR register, the Folkbokföringsregistret.
The Danish suspect is accused of hacking into Rigspolitiet’s IT system, which is run by CSC, a computer firm that protects a number of sensitive databases belonging to the police and other public authorities.
The IT professional, whose name was not released, is charged with stealing around 4,000,000 pieces of information from CSC’s database last year and passing them onto Warg, who attempted to use them to earn money.
The data included the email addresses and passwords of 10,000 policeman as well as CPR numbers from the driving licence database and information about wanted persons in the Shengen region.
Rigspolitiet chief Jens Højberg stated in a press release that much of the stolen data was not legibile and that CPR numbers stolen from the driving licence database were not connected to people’s names.
Despite there being no evidence the hackers had abused the information, Højberg said that the incident was very serious.
“It’s a major attack on the IT system used for the police databases and which we expect CSC to protect for us,” Højberg stated. “That is why the police are treating the case very seriously. It is of course completely unacceptable that it was possible to access the police’s database despite the very high security standards that we demand and expect from our contractors.”
Rigspolitiet has called upon the domestic intelligence agency, PET, and the counter-cybercrime division of defence intelligence agency FE to help with the investigation.
“We will assess the extent of the security breach and whether other public IT systems have been affected, and also to ensure that the necessary security measures are taken to remedy the situation,” Jacob Scharf, the head of PET, wrote in a press release. “The police’s IT systems will be thoroughly examined.”

http://cphpost.dk/news/national/hacker-charged-stealing-police-databases

Thursday, June 6, 2013

A proposed new law would require EU countries to jail hackers for a minimum of two years

Mandatory 2-year jail sentence for EU hackers comes a step closer

A proposed new law would require EU countries to jail hackers for a minimum of two years

126 billion files publicly visible on Amazon cloud, security firm finds

126 billion files publicly visible on Amazon cloud, security firm finds

126 billion files publicly visible on Amazon cloud, security firm finds

Penetration tester Rapid7 discovers sensitive information in exposed documents on Amazon's cloud storage service

            
A security company in the US has discovered thousands of publicly accessible files on Amazon's S3 cloud storage service, many of which contain sensitive information.
Rapid7 discovered the files by searching for storage 'buckets' - logical pool of storage capacity - whose access setting has been changed to 'public', from the default setting of 'private'. 
This means that a list of the contents of the bucket can be seen to anyone that knows or guesses the URL.
The company successfully guessed the URL of 12,328 buckets on the S3 service, by inserting the names of Fortune 500 companies into the standard URL format for S3.
Of those, 1,951 of which were set to 'public'. These buckets contained a combined 126 billion files, so Rapid7 analysed a cross section of 40,000 files. 
These files were found to contain such sensitive information as sales records, employee personal information, unencrypted passwords and the source code for a video game. 
"Much of the data could be used to stage a network attack, compromise users accounts, or to sell on the black market," Rapid7 wrote in a blog post.
Rapid7 advises companies to check whether their S3 buckets are set to public. "If so, think about what you're keeping in that [those] buckets and whether you really want it exposed to the internet and anyone curious to take a look."
As Rapid 7 points out, not only does Amazon set the S3 buckets to private by default, it also provides a walkthrough guide to keeping data stored on the service secure. 
The research reveals that lax security practices companies may get away with on their own IT infrastructure are highly dangerous when data is stored on the cloud. 

Sunday, June 2, 2013

Oracle: We’re investing in Java security

Oracle: We’re investing in Java security

Oracle: We’re investing in Java security
In a blog post yesterday, Oracle outlined the steps its been taking and the investments it’s been making to ensure the security of Java, its beleaguered open-source programming language.
Starting in October 2013, the company will release quarterly security patches. It also says it will respond more quickly to security issues in the future and will do better at ensuring vulnerabilities don’t make it into the codebase in the first place using automated security testing tools.
“The company has made a number of product enhancements to default security and provide more end user control over security,” writes Oracle Java software development lead Nandini Ramani on the company blog.
For the enterprise, which still relies heavily on Java, Ramani said, “The public coverage of the recently published vulnerabilities impacting Java in the browser has caused concern to organizations committed to Java applications running on servers,” implying the problem was more with PR than security on the server side. In response, Oracle introduced Server JRE as a separate distro.
The trouble started nearly a year ago, when Oracle fixed a gaping Java security hole it may have known about for months. Slow security is no security, and Oracle’s investment at that time wasn’t nearly good enough, and that vulnerability set the stage for 2013, when a string of security issues popped up.
In January, the world found out about a Java vulnerability that would allow attackers to steal information or hook up a botnet to any user with a Java plugin-running browser. At that point, the Department of Homeland Security and Apple issued memos saying no one should use Java. Oracle issued a patch, but like a junkie with a $10 habit and a $5 stash, DHS said the fix was insufficient.
Then, after an attack in February, Facebook disabled Java in a high-profile vote of no confidence. (Microsoft and Apple underwent similar attacks.)
Finally, in March, Oracle issued a big emergency Java update. The company issued a further 42 security fixes in April.
“It is our belief that as a result of this ongoing security effort, we will decrease the exploitability and severity of potential Java vulnerabilities in the desktop environment and provide additional security protections for Java operating in the server environment,” Ramani said in conclusion.
“Oracle’s effort has already enabled the Java development team to deliver security fixes more quickly, resulting in fewer outstanding security bugs in Java.”

Read more at http://venturebeat.com/2013/06/01/oracle-java-security/#re37AqwkMpWIQqRV.99

Google urges software makers to respond in one week to vulnerabilities under active attack

 
 

Google urges software makers to respond in one week to vulnerabilities under active attack

Three years ago, a group of Google engineers proposed that vendors should have 60 days to repair security vulnerabilities rated "critical" in widely deployed software – or the researchers who privately tipped them off about the issue can go public with their findings.
At the time, the authors of the blog post suggested that this two-month window considerably must shrink if the issue is being actively exploited against actual targets. On Wednesday, Google researchers announced a significantly shortened vendor response deadline that they hope others will adopt to spur quicker fixes.
"[W]e believe that more urgent action – within seven days – is appropriate for critical vulnerabilities under active exploitation," wrote Google engineers Chris Evans and Drew Hintz on Wednesday on the company's Online Security Blog. "The reason for this special designation is that each day an actively exploited vulnerability remains undisclosed to the public and unpatched, more computers will be compromised."
The researchers conceded that a seven-day deadline may be too short for software makers to push out a permanent patch, but they said it should provide enough time for them to offer tips on mitigating the threat.
"As a result, after seven days elapsed without a patch or advisory, we will support researchers making details available so that users can take steps to protect themselves," according to the post. "By holding ourselves to the same standard, we hope to improve the state of web security and the coordination of vulnerability management."
Evans and Hintz proposed the new time frame as worries grow over targeted attacks for which there is no patch, known as a zero-day, going after a "limited subset of people," they wrote.
Oftentimes, an issue that is discovered by a so-called white-hat hacker may already be known by more nefarious individuals who have the intention to leverage the bug in a malicious manner.
Last fall, Leyla Bilge and Tudor Dumitras of Symantec Research Labs conducted a study (PDF) of zero-day attacks in the wild and determined that their prevalence is more common that previously thought.
The researchers found that 0-day attacks lasted about 10 months on average before being discovered.  Through data retrieved from some 11 million computers running Symantec anti-virus software, researchers studied 18 zero-day cases that occurred between 2008 and 2010. They found that the majority of these attacks, 11, involved vulnerabilities that had never before been publicly known.
Google may have some of the strictest guidance around vulnerability reporting, but other major IT vendors, including Microsoft, also have chimed in on the disclosure debate.

Disk encryption: This is why you should always use it

Disk encryption: This is why you should always use it
           on June 1, 2013 at 3:19 pm /         
Disk encryption is one of those physical security features that determine whether I install a Linux distribution on any computer I use for serious computing. Whether it’s a server, notebook, ultrabook or any other type of *book, if it’s not a crash-and-burn unit, the hard disk drive (HDD) has to be encrypted.
And no, it’s not because I have anything to hide, it’s just that personal data should be just that – personal, and private. If you are not authorized (by the owner) to see it, you don’t.
This becomes especially important in this age of warrantless orders, sational security letters, and judicial overreach, where a bunch of trigger-happy guys from any government agency can show up at your place and cart everything and anything they can get their paws on.
Take the case of Kim Dotcom, who leaves in New Zealand. Back in January 2012, based on charges of copyright infringement related to the Megaupload file-sharing website, the New Zealand police raided his residence and bagged everything they could find. Cloned copies of his HDDs were sent to the FBI in the US of A.
Now, Kim Dotcom is not without blemishes in his character; the guy has a criminal history that dates back to his teenage years. But that’s not the point of discussion here. The gist of this article is what we can learn from the legal aspect of the case against him.
Since the raid of his residence and seizure of his assets, the raid has been deemed, by the courts, to be illegal and the warrant detailing what could be seized too broad. Virtually every single court case has come out in his favor.
In the latest decision, the judge overseeing the case ruled that all digital material taken from his residence that are not relevant to the case should be returned (to Kim). And that any copies of HDDs sent to the FBI be returned.
Too late!
Do you think the US government is going to comply with the decision of a New Zealand judge? Fat chance. Even if they did, don’t you think they’ve already made copies of the copies, and copies of the copies of the copies. And if those HDDs were not encrypted, what good will returning them at this point do.
Again, it’s too late. Lesson? Always encrypt your HDDs. It’s not about who is a good or bad guy, or who has something or nothing to hide. It’s about having the final say on who can have access to your personal data. In cases of this sort, it’s better to be in a position where the authorities are going to court to get you to give up your encryption passphrase(s).
Regarding full disk encryption in the graphical installation programs of Linux and BSD distributions, Anaconda, the Fedora systems installer, the Debian Installer, and PC-BSD‘s installer are the best. Note that the graphical installer of Sabayon is a fork of an older version of Anaconda, but it, too, has support for full disk encryption.