Saturday, December 28, 2013

Data breach at Target highlights need to focus on cyber security

http://crossroadsnews.com/news/2013/dec/27/data-breach-target-highlights-need-focus-cyber-sec/

Data breach at Target highlights need to focus on cyber security

12/27/2013, 6 a.m.
As big banks and credit card companies scramble to protect consumers after a massive data breach at retail giant Target, small-business owners also should be concerned about cybersecurity.
Between Nov. 27 and Dec. 15, cyber thieves made off with data from 40 million credit and debit card accounts of people who shopped at Target’s 1,800 stores in the United States and 124 in Canada.
As stolen data flood the underground black market, at least three class-action lawsuits have been filed.
The U.S. Small Business Administration says cyber threats are an issue for everyone, and small businesses are becoming more common targets for such threats and crimes because they often have fewer preventive or responsive resources.
It offers some of the essentials in “What is cybersecurity?” its latest online training course.
With the help of technology and best practices, cybersecurity is the effort to pro-tect computers, programs, networks and data from attack and damage.
Why is cybersecurity important?
Consider all the information you have that needs to be secure – personal information for employees, partner information, sensitive information for customers/clients, and sensitive business information.
It’s essential to do your part to keep these details safe and out of the hands of those who could use your data to compromise you, your employees and your small business.
CNN reports that nearly half of the data breaches that Verizon recorded in 2012 took place in companies with less than 1,000 employees. A Symantec report showed that 31 percent of all attacks in 2012 happened to businesses that had less than 250 employees, and another Symantec report showed cyber attacks were up 81 percent in 2011.
Common cyber threats and crimes
There’s a broad range of information security threats. Some of the most common include Web site tampering, data theft, denial-of-service attacks and malicious code and viruses.
Website tampering can take many forms, including defacing your site, hacking your system and compromising Web pages to allow invisible code that will try to download spyware onto your device. Data theft also can come in various forms, and the problems depend on what kind of data is stolen. Examples include theft of computer files; theft of laptops, computers and devices; interception of emails; and identity theft.
A denial-of-service attack happens on a computer or Web site and locks the computer and/or crashes the system, resulting in stopped or slowed work flow. Malicious code and viruses are sent over the Internet and aim to find and send your files, find and delete critical data, or lock your computer or system. They can hide in programs or documents and make copies of themselves – all without your knowledge.
What can I do?
The first step to protecting the information in your business is to establish comprehensive security policies – and keep them up-to-date. Make sure your employees know and adhere to your policies and best practices for Internet, email and the desktop.
Tips to keep in mind:
n Don’t respond to popup windows telling you to download drives.
n Don’t allow Web sites to install software on your device.
n Don’t reply to unsolicited emails.
n Use screen locks and shut off your computer at the end of the day.
Ensure that your computer hardware and software are updated regularly. Change passwords periodically and use firewalls to protect your systems. You also should back up your data on a regular basis so that if anything is compromised, you have a copy.
To learn more about how to help make your business more cyber secure, check out the self-paced online training course “Cybersecurity for Small Businesses” at www.sba.gov.

Target: just 'cause it's 3DES doesn't mean it's secure

Target: just 'cause it's 3DES doesn't mean it's secure
 
In a blogpost referring to the recent breach of millions of debit cards, Target claims there is no danger, because the PIN is encrypted with Triple-DES at the terminal, and decrypted at the payment processor. Since hackers stole only the encrypted PINs, Target claims the debit card info is useless to the hackers.

This is wrong. Either Target doesn't understand cybersecurity, or they are willfully misleading the public, or they are leaving out important details. In all probability, it's the last item: they left out the detail of there being salt.

Yes, Triple-DES cannot be broken by hackers. If they don't have the secret key, they can't decrypt the PIN numbers. But here's the deal: hackers can get PINs without decrypting them, because two identical PINs decrypt to the same value.

For example, let's say that the hacker shopped at Target before stealing the database. The hacker's own debit card information will be in the system. Let's say the hacker's PIN was 8473. Let's say that this encrypts to 98hasdHOUa. The hacker now knows that everyone with the encrypted PIN of "98hasdHOUa" has the same pin number as him/her, or "8473". Since there are only 10,000 combination of PIN numbers, the hacker has now cracked 1000 PIN numbers out of 10 million debit cards stolen.

This just gets one debit card. The hacker can crack the rest using the same property. The hacker simply starts at PIN number "0000", and then using online sites, starts using that number, trying one card at a time, until s/he gets a hit. On average, the hacker will have to try 10,000 before a good result is found. Once found, all debit cards with the same encrypted PIN of "0000" are moved aside to the "known" category. The hacker then repeats the process with "0001", "0002", and so on for all combinations.

This process is further simplified by the fact that some PIN numbers are vastly more common than others. People choose simply patterns (like "0000"), birthdays, and so on. The hacker can create a popularity distribution among the cracked PINs. Since "1234" is the most popular PIN number, the hacker can look at the most popular encrypted PIN and try that first. It'll probably work, but if not, s/he can try the next most popular encrypted PIN, until a match for 1234 is found. The top most popular 100 PINs can be discovered with only a few thousand attempts, giving over a million cracked debit cards to work with. This is something that can be done even if a person had to stand in front of an ATM for hours trying one card after another.

One way to correct this is to salt the encryption, such as using the credit card number as part of the key that encrypts the PIN, or as part of additional data prepended to the PIN. Done this way, every PIN number now decrypts to a different value. If they did this, then it would indeed be the same as if no PIN information were stolen at all.

As Mathew Greene describes, the Payment Card Industry (PCI) standards indeed call for salt, so this is probably what Target did.

It's nice that Target gives intermediate results of their investigation. Transparency like this should be commended. But they should just give us the raw information, like the specific PCI standard they follow, without the marketing spin about whether it's secure or not. I suppose I should've just known the PCI standard off the top of my head and filled in the blanks myself, but when I see incomplete info like this, it makes me distrust their honesty/competence instead.
http://blog.erratasec.com/2013/12/target-displays-its-incompetence.html#.Ur622cKA3IU

Can hackers decrypt Target's PIN data?

Friday, December 27, 2013

Can hackers decrypt Target's PIN data?

Short answer: probably not.

Slightly longer answer: it depends on whether they have access to the encryption key, or to a machine that contains the encryption key.

In case you have no idea what I'm talking about: there was recently a massive credit card breach at Target. If you're like many people you probably heard about this three times. First in the news, then again in your email when Target notified you that you were a victim, and finally a third time when you checked your credit card bill. Not a proud day for our nation's retailers.

The news got a bit messier today when Target announced the thieves had also managed to get their hands on the PIN numbers of unfortunate debit card customers. But this time there's a silver lining: according to Target, the PIN data was encrypted under a key the hackers don't have.
Snyder said PIN data is encrypted at a retail location’s keypad with Triple-DES [3DES] encryption and that data remains encrypted over the wire until it reaches its payment processor. Attackers would have to have compromised the point-of-sale system and intercepted the PIN data before it is encrypted in order to have accessed it.
Several folks on Twitter have noted that 3DES is no spring chicken, but that's not very important. Aside from a few highly impractical attacks, there isn't much to worry about with 3DES. Moreover, PCI standards appear to mandate unique keys for every payment terminal, which means that the attackers would need to compromise the terminals themselves, or else break into the back-end payment processor. If Target is to be believed, this has not happened.

Others have pointed out that PINs are pretty short. For example, there are only 10,000 4-digit PINs -- so surely the attackers can "brute-force" through this space to figure out your PIN. The good news is that encryption is decidedly not the same thing as password hashing, which means this is unlikely to be a serious concern. Provided that Target is being proactive and makes sure to change the keys now.

Of course you shouldn't take my word for this. It helps to take a quick look at the PCI PIN encryption standards themselves. Before you encrypt a 4-digit PIN, the PIN is first processed and in some cases padded to increase the complexity of the data being encrypted. There are four possible encryption formats:
  • Format 0. XOR the PIN number together with the Primary Account Number (PAN), usually the rightmost twelve digits of the card number, not including the last digit. Then encrypt the result using 3DES in ECB mode.
  • Format 1. Concatenate the PIN number with a unique transaction number and encrypt using 3DES in ECB mode.
  • Format 2. Pad with some fixed (non-random) padding, then encrypt in 3DES/ECB with a unique, derived per-transaction key (called a DUKPT). Update: only used for EMV cards.
  • Format 3. Pad with a bunch of random bytes, then 3DES/ECB encrypt.
Notice that in each case the encryption is ECB mode, but in Formats 0, 1 and 3 the plaintext has been formatted in such a way that two users with PIN "1234" are unlikely to encrypt exactly the same value under the same key. For example, consider the Format 0 encryptions for two users with the same PIN (1234) but different PANs:
(PIN) 0x1234FFFFFFFF ⊕ (PAN) 0x937492492032 = 0x81406DB6DFCD
(PIN) 0x1234FFFFFFFF ⊕ (PAN) 0x274965382343 = 0x357D9AC7DCBC
Notice that the values being encrypted (at right) will be quite different. ECB mode has many flaws, but one nice feature is that the encryption of two different values (even under the same key) should lead to effectively unrelated ciphertexts. This means that even an attacker who learns the user's PAN shouldn't be able to decompose the encrypted PIN without knowledge of the key. Their best hope would be to gain access to the terminal, hope that it was still configured to use the same key, and build a dictionary -- encrypting every possible PIN under a specific user's PAN -- before they could learn anything useful about one user's key.

This does not seem practical.

The one exception to the above rule is Format 2, which does not add any unpredictable padding to the plaintext at all. While the PIN is padded out, but there are still exactly 10,000 possible plaintexts going into the encryption. PCI deals with this by mandating that the payment terminal derive a unique key per transaction, hopefully using a secure key derivation function. Update: this one probably isn't used by Target.

All of this is a long, dull way of saying that encryption is not like password hashing. Provided that you can keep the keys secret, it's perfectly fine to encrypt messages drawn from even small message spaces -- like PINs -- provided you're not an idiot about it. The PCI standards clearly skirt the borders of idiocy, but they mostly steer clear of disaster.

So in summary, Target debit card users are probably just fine. Until tomorrow, when we learn that the thieves also have the decryption keys. Then we can panic.

Friday, December 27, 2013

Hundreds of thousands of card numbers stolen in casino company breach

Adam Greenberg                    

Hundreds of thousands of card numbers stolen in casino company breach

Thousands of credit and debit card numbers were stolen in the breach.
Thousands of credit and debit card numbers were stolen in the breach.
It was no classic Sin City heist, but the end result was the same when hackers compromised the payment system of Affinity Gaming in a potentially months-long attack and made off with hundreds of thousands of credit and debit cards belonging to gamblers at any one of the company's casinos.
An investigation is currently ongoing, but Affinity made the announcement on Friday, almost 24 hours after retail giant Target announced that 40 million of its customers may have had credit and debit cards and CVV codes stolen in a hacking incident.
Even though Affinity is notifying individuals who visited any of its Nevada, Iowa, Missouri and Colorado gaming facilities between March 14 and Oct. 16, the group still has not confirmed the exact date the attack initially began.
Affinity attorney Jim Prendergast said between 280,000 and 300,000 cardholders were impacted, according to reports. Some of those impacted individuals used their cards at Affinity-owned Primm Center Gas Station in Nevada, according to a notification on the company website.
Affinity learned of the incident on Oct. 24, after law enforcement contacted the Las Vegas-based group regarding fraudulent charges possibly linked to a data breach of the Affinity payment system, according to the notification.
An immediate investigation involving outside data forensics experts revealed that the payment system had been infected with malware, resulting in the compromise of the credit and debit cards. The system was quickly secured to protect customer accounts, according to the statement.
The notification did not indicate if the company will be offering anything to affected individuals, nor did it highlight steps taken to prevent a similar incident from occurring, but Affinity is encouraging all impacted individuals to monitor accounts for suspicious activity.
An Affinity spokesperson did not immediately respond to an SCMagazine.com request for comment.

http://www.scmagazine.com/hundreds-of-thousands-of-card-numbers-stolen-in-casino-company-breach/article/327054/

Security 'PGP' Encryption has had Stay-Powering but Does it Meet Today's Enterprise Demands?

Security 'PGP' Encryption has had Stay-Powering but Does it Meet Today's Enterprise Demands?
By Ellen Messmer, 27-Dec-2013


PGP encryption, as industry old-timers know, started out as "Pretty Good Privacy" invented by Phil Zimmermann in 1991, and since then, was sold on to various corporate owners until it ended in the hands of Symantec in 2010. While it is a widely used vintage brands, does PGP public-key encryption still meet today's enterprise demands, given the rise of cloud computing and mobile? PGP encryption, as industry old-timers know, started out as "Pretty Good Privacy" invented by Phil Zimmermann in 1991, and since then, was sold on to various corporate owners until it ended in the hands of Symantec in 2010. While it is a widely used vintage brands, does PGP public-key encryption still meet today's enterprise demands, given the rise of cloud computing and mobile? Enterprise managers are somewhat mixed on that, though PGP, over two decades old, is so well known that Symantec, which dropped the PGP moniker in favor of "Symantec Encryption," still reminds everyone it's "powered by PGP technology." In addition, there's "OpenPGP," the IETF standard that was championed by Phil Zimmermann, that can be implemented by companies without licensing. Symantec declines to discuss how many customers it has exactly in the PGP realm, but it does point out that Symantec has invested resources in developing what it inherited with PGP. For example, Symantec offers client app software for both Apple iOS and Google Android devices as part of its Desktop Email Encryption. Symantec says its email encryption encrypts e-mail directly from an end user machine. The result, according to Symantec, is encrypted mail is delivered directly to a user's device and they use the Symantec Mail Encryptor App to reply. +Also on Network World: The weirdest, wackiest and coolest sci/tech stories of 2013 | The worst security SNAFUs of 2013 + But despite this kind of PGP-related development work, one sticking point is managing the digital certificates needed for end-to-end encryption and decryption, especially when it comes to sharing files securely between two separate companies as outside business partners. "It's too problematic," says Yuval Illuz, associate vice president and head of global infrastructure and IT operations at network equipment company ECI Telecom about digital certificate management among business partners. "It's not something you need today. You change suppliers all too often." Illuz said his company has migrated off the PGP-based Symantec Encryption e-mail and filing sharing software that the firm once used for secure communications with business partners. Instead, ECI adopted a different type of exchange, the RSAccess product from Safe-T, in which two nodes are set up on each side of a firewall to support requests for sensitive data from suppliers, business partners and customers. It can also create directories for the cloud-based Dropbox service. Everything is encrypted but it doesn't depend on certificates, but strong passwords, to get information, he says. But ECI is sticking with Symantec Encryption for some things, particularly for in-house use. "The laptop encryption for PGP, we are still using it," he says, expressing confidence about the security and manageability involved in it. Since acquiring PGP, Symantec has released secure file-sharing with Dropbox in what it calls its File Share Encryption integration with Dropbox. Symantec says it works by simply checking a box in the management server so anything sent to Dropbox is automatically encrypted with the appropriate keys. Not everyone, however, feels the need to migrate away from managing certificates with business partners. "We have a lot of business partners," says Dylan Taft, systems engineer at Rochester General Hospital, who says he relies on managing separate PGP-based encryption keys for secure file sharing. "PGP is not an issue." The hospital uses the Ipswitch MOVEit File System which makes use of the protocol OpenPGP. The hospital uses what's called MOVEit Central from Ipswitch for exchange of business-to-business documents. "PGP works at the application layer," says Taft, saying the hospital can encrypt with its PGP key and the recipient can decrypt with theirs. "The data we send is long files, and it's not a problem." Some complaints about Symantec Encryption have been heard related to the need to renew VeriSign certificates each year in order to be able to decrypt old e-mail if it's held encrypted for an extended period of time that way. VeriSign was also acquired by Symantec, and like PGP, VeriSign s a vintage brand that is now officially referred to as Symantec "powered by VeriSign." Asked if this is a general practice at Symantec in terms of certificate renewal associated with Symantec Encryption (PGP) products, Symantec responded, "No, the need for certificate renewals is based on the user using VeriSign certificates vs. self-signed certificates created with the Symantec Encryption Management Server." Symantec points out, "Symantec Gateway Email Encryption and Symantec Desktop Email Encryption both allow certificates to be used to store keys. The certificates are self-signed certificates, created and signed by Symantec Encryption Management Server." Symantec points out that using a self-signed certificate, rather than a certificate with a trusted root, would eliminate the need to pay to renew the certificate. Symantec keeps some of the old traditions around PGP alive by publicly making the source code publicly available for peer review. Ellen Messmer is senior editor at Network World, an IDG website, where she covers news and technology trends related to information security.
Twitter: MessmerE.
E-mail: emessmer@nww.com
Read more about wide area network in Network World's Wide Area Network section.
http://www.computerworld.in/news/%27pgp%27-encryption-has-had-stay-powering-but-does-it-meet-today%27s-enterprise-demands%3F?utm_medium=referral&utm_source=t.co

Thursday, December 26, 2013

NSA paid 10M$ to RSA to insert an encryption backdoor in its solution


by paganinip on December 21st, 2013
 
RSA_EMC_logo-631x272
Last revelation based on the documents leaked by Edward Snowden is related to the allegedly encryption backdoor inserted by RSA in the BSafe software.
Is it possible to insert an encryption backdoor in one of most popular cryptographic products?
Probably it is just a question of money if the request came from the NSA, according a recent report apparently the fee is $10 million. This is our weekly revelation from document leaked by Edward Snowden, a mine of scaring information that is shaking the IT industry and in particular the world of Intelligence and Security.
Reuters agency revealed that as a key part of a campaign to embed encryption backdoor into widely used computer products, the U.S. National Security Agency signed a secret contract with RSA, the cost of the coperation si $10 million.
“Documents leaked by former NSA contractor Edward Snowden show that the NSA created and promulgated a flawed formula for generating random numbers to create a “back door” in encryption products, the New York Times reported in September. Reuters later reported that RSA became the most important distributor of that formula by rolling it into a software tool called Bsafe that is used to enhance security in personal computers and many other products.” states the Reuters article.
It is a new earthquake, the RSA received $10 million (more than a third of the revenue that the interested division of  RSA had earned during the last year) to set the buggy NSA formula as te default method for number generation in the BSafe software.
RSA-BSafe encryption backdoor
Two people familiar with RSA’s BSafe application revealed to Reuters that the company had received the money in exchange for making the NSA’s cryptographic formula as the default for encrypted key generation in BSafe.
The reputation of the RSA is seriously impacted, in September Snowden leaked documents that demonstrated that NSA intentionally inserted flaws in RSA’s encryption tokens.
NSA acted by weakening encryption standards, inserting encryption backdoor into encryption products of main vendors, in this way the Agency using supercomputer-backed password crackers is able to break encryption used to back popular technologies including HTTPS and SSH.
“Now we know that RSA was bribed,” “I sure as hell wouldn’t trust them. And then they made the statement that they put customer security first,” is the comment of the popular security expert Bruce Schneier “You think they only bribed one company in the history of their operations? What’s at play here is that we don’t know who’s involved,” he added.
The revelation raise many doubt on the relationship of US Government and private IT companies that provide common used encryption solution like Symantec and Microsoft.
“You have no idea who else was bribed, so you don’t know who else you can trust,” Schneier said.
RSA did not return a request for comment, and did not comment for the Reuters story.

Wednesday, December 25, 2013

Target hackers might have encrypted PINs

By  Jim Finkle REUTERS
David Henry REUTERS

Wednesday December 25, 2013              
 
                 
The hackers who attacked Target Corp. and compromised up to 40 million credit cards and debit cards also managed to steal encrypted personal identification numbers (PINs), according to a senior payments executive familiar with the situation.
One major U.S. bank fears that the thieves will be able to crack the encryption code and make fraudulent withdrawals from consumer bank accounts, said the executive, who spoke anonymously.
Target spokeswoman Molly Snyder said “no unencrypted PIN data was accessed” and there was no evidence that PIN data has been “compromised.” She confirmed that some “encrypted data” was stolen, but declined to say whether that included encrypted PINs.
The No. 3 U.S. retailer said last week that hackers stole data from as many as 40 million cards used at Target stores during the first three weeks of the holiday shopping season.
Target has not said how its systems were compromised, although it described the operation as “ sophisticated.” The U.S. Secret Service and the Justice Department are investigating. Officials have declined to comment.
The attack could end up costing hundreds of millions of dollars, but it is unclear so far who will bear the expense.
While bank customers typically are not liable for losses because of fraudulent activity on their credit and debit cards, JPMorgan Chase & Co. and Santander Bank said they have lowered limits on how much cash customers can take out of teller machines and spend at stores.
The unprecedented move has led to complaints from consumer advocates about the inconvenience it caused. But sorting out account activity after a fraudulent withdrawal could take a lot more time and be worse for customers.
Security experts said it is highly unusual for banks to reduce caps on withdrawals, and the move likely reflects worries that PINs have fallen into criminal hands, even if they are encrypted.
While the use of encryption codes might prevent amateur hackers from obtaining the digital keys to customer bank deposits, the concern is that it might not stop the kind of sophisticated cyber criminal who was able to infiltrate Target.