Thursday, May 15, 2014

Simplifying the complexities of IT security

Simplifying the complexities of IT security

17 March, 2014
IT security professionals are in danger of losing sight of the basics as systems and their protection become increasingly complex.

In the world of cyber-crime, it is a certainty that whatever you do to protect access and lock down your systems, a breach will nonetheless occur if a cyber-criminal is determined to achieve it.



Using this assumption, those in the IT security profession are left with the basic principle that has always been the fundamental of their trade and has never changed - focus on the data and make sure it is protected so that when a breach occurs, the cyber-criminal is left empty-handed.



These were the views expressed by Jason Hart, the VP Cloud at SafeNet, a former ethical hacker and a renowned expert in the tools and techniques of hacking and password vulnerabilities. Intrigued by his approach, ProSecurityZone met Jason recently in London to discuss data protection and find out why passwords are so vulnerable.



Password proliferation



Passwords are a pain and it would be better to assign them the same status as floppy disks as curious artefacts of the bygone age of obsolete technology. Unfortunately, we're not there yet and continue to have to put up with an escalating number of passwords that have to be used. Each one needs to be unique, conform to a set of rules (which may be different for each one), memorised and then changed regularly.



Such a process across multiple systems and web sites is clearly unsustainable so people write them down, re-use and re-cycle them, use their browser facility to remember passwords, list them on a spreadsheet on their computer or on their smart-phones. Some of the more tech-savvy keep them in a secure password vault, the security of which is determined by a single password needed in order to enter the vault. Whatever system you use in order to manage your unmanageable list of passwords is vulnerable.



This is one of the reasons behind Jason's opening statement when we met that we have to accept that breaches will happen and therefore need to focus on protecting the data. Passwords aren't the only means of breaching a system of course, there are many others including network vulnerabilities and capturing data in transit.



Data in transit vulnerability



Data in transit is particularly easy to hack in Wi-Fi environments which Jason was able to demonstrate in the small cafe with free Wi-Fi access where we'd chosen to meet. Using a piece of hardware cobbled together from easily available components and some similarly accessible software, Jason was able to create his own unsecured hotspot.



Using my computer to search for hotspots, I found his and logged on with ease. Once connected to Jason's hotspot, everything I did on my computer was his to analyse so I logged onto one of my password protected cloud services. To demonstrate the simplicity of harvesting login credentials using unsecured hotspots, Jason invited me to watch it as it happened using a Linux console that looked suitably geeky with its green-screen display scrolling dozens of lines of characters and no graphics. Despite the unfriendly looking interface, it took him all of 5 seconds to locate both the userid and the password in plain text that I'd passed to my cloud provider.



Hacking software for stealing data in transit at WiFi hotspots




This isn't unusual, he told me. Cloud servers are everywhere, we all use them in one form or another but most of them don't even offer two-factor authentication (2FA) for more secure access control to that all-important data. Even banks only use 2FA for transactions outside of the managed accounts. Accessing online bank accounts is more difficult because only random sequences of bits of PINs and passwords are used but to set up a new payee and transfer money to it requires a Hardware Security Module (HSM) which provides another authentication factor.



As far as Jason's demonstration was concerned, it was clear that providing a free hotspot introduces a temptation that makes users extremely vulnerable. I argued that although this may be the case for people with very low awareness of security, most people understand the vulnerability of free Wi-Fi access and are unlikely to fall into such a trap, particularly when dealing with sensitive data.



Trusted connections shouldn't be trusted



However, the reality is that free Wi-Fi comes as such a relief to people travelling on business that security is often the last thing on their minds. Nonetheless, to capture even the most security conscious browser, Jason had something much more sinister in his bag of tricks.



Using his self-assembled hardware and a downloadable piece of hacking software, Jason was able to scan my computer for all the wireless networks listed that are trusted and that I automatically connect to. The software then spoofed one of those connections and my computer automatically connected to it. I didn't have to do anything, the computer simply connected itself to a hostile hotspot thinking it was one of my trusted networks.



This would have looked a bit fishy if I'd hovered over the connection icon in the toolbar and seen the name of a network that I only use when I'm abroad but, as Jason pointed out, I was taking part in a hacking demonstration so I knew what I was looking for. Most people would have no awareness of what was going on, they would just work on their computer as normal while the hacker sifted through all the information being transmitted, searching for something useful .... or something targetted.



Focusing on the data



Hackers have always wanted your data and although this hasn't changed, their armoury for accessing it becomes more sophisticated every day. Since it's the data that's important to them, it is on this data that information security should be focused, Jason asserts.



The only effective way of doing this is by making the data unusable through encryption and effective key management. Encrypting data at rest protects it from being read if accessed and protecting data in transit protects it when it's being transmitted such as in a cafe with Wi-Fi. If my userid and password for the cloud service I'd been accessing had been encrypted for transmission, it wouldn't have been readable on Jason's Linux console.



Access control is of course also important but simple password control just isn't enough. Two-factor authentication should be deployed as a minimum and shouldn't be seen as an alternative for protecting the data through well managed encryption.



Jonathan Newell is a broadcast and technical journalist specialising in security systems and transport safety. He contributes to a range of titles in the technical press. He shares his time between the UK and Kazakhstan


Read more: http://www.prosecurityzone.com/blog/Simplifying_the_complexities_of_it_security_286.asp#ixzz31n4d6Kfo

Friday, May 9, 2014

Heartbleedfaal: 30.000 nieuwe SSL-certificaten waardeloos

Heartbleedfaal: 30.000 nieuwe SSL-certificaten waardeloos

door
heartbleed
    
Nieuws - Meer dan 30.000 SSL-certificaten zijn ingetrokken door webmasters naar aanleiding van de Heartbleedbug en vervangen door nieuwe certificaten met hergebruik van de mogelijk al gestolen private key. Daardoor zijn de nieuwe certificaten net zo nutteloos als de oude.
Nadat Heartbleed, het lek in OpenSSL, vorige maand pijnlijk in de openbaarheid kwam, hebben beveiligingsbedrijven direct drie belangrijke stappen neergelegd die website-eigenaren moesten nemen om hun beveiligde verbindingen weer betrouwbaar te maken.
Die drie stappen zijn:
1. vervang je SSL-certificaten,
2. trek de oude certificaten in,
3. gebruik een nieuwe private key.


Volgens Internetbeveiligingsbedrijf Netcraft heeft slechts 14 procent van alle getroffen websites die drie stappen gevolgd.

Wel certificaten vervangen, maar niet de private key

Van de getroffen websites heeft 5 procent wel de certificaten vervangen, maar zonder dat de private key is vervangen. Cruciaal is dat public keys die zorgen voor de verificatie van de beveiligde verbinding gegenereerd worden van de private key. Als die laatste niet is vervangen, zijn de SSL-certificaten die de public keys in zich hebben net zo waardeloos als hun voorgangers.
Heartbleed heeft ervoor gezorgd dat aanvallers mogelijk de private key van een website hebben kunnen stelen. Dat is zeer waardevol voor criminelen omdat zij via die private key een valse website in de lucht kunnen brengen die doet alsof hij de originele website is, compleet dus met een volledig betrouwbare SSL-verbinding.

Misbruik van private keys blijft dus mogelijk

Zolang de private key dus door de rechtmatige eigenaar niet is vervangen en ingetrokken, blijft misbruik van de gestolen private key mogelijk en is de aanmaak van nieuwe certificaten op basis van die private key volledig nutteloos. En dat terwijl de website-admins denken alles gedaan te hebben om Heartbleed te stoppen.
Volgens Netcraft heeft ook nog eens 57 procent van de betrokken websites geen enkele actie ondernomen en heeft 21 procent wel een nieuwe private key gebruikt om certificaten aan te maken maar hebben ze de oude private key niet buiten werking gesteld.

Monday, May 5, 2014

Heartbleed: Facts And Recommendations


What has just happened

A security vulnerability has been discovered this week. One more and why should I care, you’ll ask.
This vulnerability, romantically named “Heartbleed”, impacts some versions of a tool called OpenSSL. You know that when you enter confidential information online, such as a credit card number, you should check that there’s a lock icon in your web browser navigation bar. The lock is displayed when https protocol is used. OpenSSL is the open-source tool many websites use to handle https. So if OpenSSL is broken, online transactions are no longer confidential. This vulnerability is not a small one…

How bad is it for me?

Assume that all information you’ve been exchanging online in the last 2 years may have been eavesdropped. You regularly check your credit card transactions? Keep doing that! However, you probably don’t change your passwords regularly. Now, you should, as they may have been captured and recorded. All of them? Unless you want to check the OpenSSL version used by each and every website where you have an account, assume all your passwords may have been captured.
You’ve probably been hearing a lot about passwords in the recent weeks, months, years. Have you done something about it? If not, that’s probably the right time to do so. Remember, you should have a strong unique password for each of your sites.

How can I do that?

Ordinary people can’t, unless they maintain long lists of passwords (on a paper, in an Excel spreadsheet…). The alternative that you should seriously consider now is to use a Password Manager to create strong unique passwords and automate the connection to your websites. inWebo has such a tool available for you. It’s super easy, synchronized with your multiple devices, and free.
Free!? Where”s the trap? There’s no trap, no ad, no limitation to the number of passwords or number of devices. It’s free because our model is to charge the business and enterprise versions.
To use it, simply open an account HERE. inWebo Password Manager will propose to record your password when you connect or sign up to a website that is not yet known. Also, inWebo will propose a new, strong and unique password if you use the password lost or change password features proposed by the website.
Finally, you should pay a special attention to the passwords of your email addresses, as they are used to recover all other passwords. Make sure that the password you use for email is unique, strong, and that you have a way to recover it that doesn’t rely on other emails.


http://www.inwebo.com/blog/heartbleed-facts-and-recommendations/

Europe's cybersecurity policy settings under attack

AFP                    

       

    Even as Europe powered up its most ambitious ever cybersecurity exercise this month, doubts were being raised over whether the continent's patchwork of online police was right for the job
    .
    View photo
    Even as Europe powered up its most ambitious ever cybersecurity exercise this month, doubts were being raised over whether the continent's patchwork of online police was right for the job (AFP Photo/Thomas Samson)

    Brussels (AFP) - Even as Europe powered up its most ambitious ever cybersecurity exercise this month, doubts were being raised over whether the continent's patchwork of online police was right for the job.
    The exercise, called Cyber Europe 2014, is the largest and most complex ever enacted, involving 200 organisations and 400 cybersecurity professionals from both the European Union and beyond.
    Yet some critics argued that herding together normally secretive national security agencies and demanding that they spend the rest of 2014 sharing information amounted to wishful thinking.
    Others questioned whether the law enforcement agencies taking part in the drill should be involved in safeguarding online security, in the wake of American whistleblower Edward Snowden's revelations of online spying by western governments.
    "The main concern is national governments' reluctance to cooperate," said Professor Bart Preneel, an information security expert from the Catholic University of Leuven, in Belgium.
    "You can carry out all of the exercises you want, but cybersecurity really comes down to your ability to monitor, and for that, national agencies need to speak to each other all the time," Preneel said.
    The Crete-based office coordinating the EU's cybersecurity, the European Union Agency for Network and Information Security (ENISA), calls itself a "body of expertise" and cannot force national agencies to share information.
    As with most aspects of policing and national security, the EU's 28 members have traditionally been reluctant to hand over powers to a central organisation, even when -- as in the case of online attacks -- national borders are almost irrelevant.
    - 'Citizens and economy at risk' -
    Cyberattacks occur when the computer information systems of individuals, organisations or infrastructure are targeted, whether by criminals, terrorists or even states with an interest in disrupting computer networks.
    The EU estimates that over recent years there has been an increase in the frequency and magnitude of cybercrime and that the attacks go beyond national borders, while the smaller-scale spreading of software viruses is also an increasingly complex problem.
    The EU's vulnerability has been highlighted over recent years by a number of high-profile cyberattacks, including one against Finland's foreign ministry in 2013 and a network disruption of the European Parliament and the European Commission in 2011.
    And with Europe's supply of gas from Russia focusing attention on energy security, the highly computerised "smart" energy grids which transport and manage energy in the EU are also seen as vulnerable.
    Yet the view from Brussels is that the member states' reluctance to work together on cybersecurity amounts to "recklessness", with one EU source saying national governments were "happy to put their citizens and economy at risk rather than coordinate across the EU."
    ENISA was established in 2001 when it became clear that cybersecurity in the EU would require a level of coordination. Unlike other EU agencies, ENISA does not have regulatory powers and relies on the goodwill of the national agencies it works with.
    The agency is undaunted by its task, arguing that the simulations it stages every two years, taking in up to 29 European countries, are both effective and necessary in preparing a response to cyber-attacks.
    This week's simulation created what ENISA described as "very realistic" incidents in which key infrastructure and national interests came under attack, "mimicking unrest and political crisis" and "disrupting services for millions of citizens across Europe."
    - Responsibility with industry -
    However, Amelia Andersdotter, a Swedish member of the European Parliament with the libertarian Pirate Party, is dismissive of both the exercise and the European online security model.
    Andersdotter, along with a number of European experts, is calling for reforms to move responsibility for cybersecurity away from law enforcement agencies toward civilian bodies.
    Their argument is that a civilian agency would be better placed to coordinate a response with industry, which Andersdotter argues has not done enough to safeguard cybersecurity.
    At present, she told AFP, industry actors in software or infrastructure simply report cybercrime to authorities without being required to compensate or inform consumers.
    A civilian authority would end what Andersdotter calls the "conspiracy of database manufacturers and law enforcement agencies" by placing greater responsibility with industry.
    What most experts agree on is that European companies and consumers are vulnerable to cybersecurity threats, and that can have an impact on people's willingness to use online services.
    James Wootton, from British online security firm IRM, said the ENISA exercises are a step in the right direction, but are not enough.
    "The problem is nation states wanting to fight cybercrime individually, even when cybercrime does not attack at that level," Wootton says, arguing that national law enforcement agencies often lack the required resources.
    "So it is good to look at this at the European level, but what power does ENISA have? What can they force countries to do?"
    Eurostat figures show that, by January 2012, only 26 percent of EU enterprises had a formally defined information technology security plan in place.
    One industry insider said the view in Brussels is that EU cybersecurity was "like teenage sex: everyone says they are doing it but not that many actually are."


    http://news.yahoo.com/europes-cybersecurity-policy-settings-under-attack-042108714.html

    Wednesday, April 30, 2014

    63% of orgs believe they can’t stop data theft

    63% of orgs believe they can’t stop data theft

    Infosec 2014: Datacentre security key to cloud security, says Google


    Warwick Ashford

    Wednesday 30 April 2014 The security challenges of the cloud are fundamentally the same as those of any in-house datacentre, says Peter Dickman, engineering manager at Google.
    This means securing data in both can be tackled in the same way, he told attendees of Infosecurity Europe 2014 in London.

     “It is a question of adding as many layers of controls as possible without impairing usability,” said Dickman, which is the approach Google uses to continually evolve and improve security.
    Although cloud computing is at an unprecedented scale, he said there are really no new security challenges in the cloud.
    “Security is still about balancing controls with usability and, while it is not necessarily easy, it is also not impossible to achieve,” said Dickman.
    Security professionals know there is no such thing as perfect security, but he said there are many things that can be done to ensure data in the cloud is as secure as possible.
    Google, like most other cloud service providers, has had the advantage of building infrastructure with scalability and security in mind from the start.
    “We recognised that devices could be compromised, some applications could be malicious and that we could not assume that users were security savvy, so we planned accordingly,” said Dickman.
    First, this means that the computers in cloud datacentres are largely homogenous, making it quick and easy for service providers to update application software and security controls whenever needed.

    “This homogeneity enables us to treat each datacentre like a single computer, which makes it easier to do security and get it right,” said Dickman.

    Google uses a single, custom-built and security-hardened Linux-based software stack for all its servers in a single datacentre.
    The servers are designed so they do not include unnecessary hardware or software to reduce the number of potential vulnerabilities.
    This is important for cloud service providers, he said, as their business relies on preserving the trust placed in them as stewards of data belonging to hundreds of millions of users.
    Although cloud computing tends to raise concerns about data security, Dickman said this approach was developed in response to the demand for access to data everywhere.
    “People attempted to achieve this by making copies of data on portable media and mobile devices, but that was a security risk, and cloud computing essentially meets the need without the risk,” he said.
    The next step, said Dickman, is to ensure physical security at the cloud datacentres, using multiple layers of access control technologies and processes.
    “It is also important to build devices against possible malicious insiders, which is why our security teams build systems to check each other,” he said.
    Also within the datacentre, Dickman said it is important to follow the principles of isolation, segregation and sandboxing, and deploy encryption wherever, and whenever possible.
    “Encryption is no panacea, but it is worth the cost and Google is continually working to ensure our encryption algorithms are as fast and as secure as possible,” he said.
    Unfortunately, many organisations still fail to keep things separate, said Dickman. “This is not rocket science, just tricky engineering,” he said.
    Availability is another important component of security he said, but because cloud service providers take security seriously, they tend to build their datacentres to be fault tolerant.
    “We test our fault tolerance by turning things off, which should work if systems have been designed and implemented correctly,” said Dickman.
    Google has robust disaster recovery measures in place due to its ability to shift data access to other datacentres in various parts of the world, selected for their relatively high political stability.
    Google does not store each user's data on a single machine or set of machines. Instead, the company distributes all data, including its own, across many computers in different locations.
    The data is then split into chunks and replicated over multiple systems to avoid a single point of failure, and the data chunks are given random computer-readable only names as an extra measure of security.
    Google also rigorously tracks the location and status of each hard disk in its datacentres, and it destroys hard disks that have reached the end of their lives in a thorough, multi-step process.
    “No one knows yet how to build perfect security, but Google is continually working to make it better,” said Dickman.
    All companies are faced with the security challenge of finding the correct balance between what is needed and what can be afforded, he said.
    But Google, like most other cloud service providers, argues that because of the economies of scale, it is able to build and maintain security to a higher level than most companies could achieve on-premise.


    http://www.computerweekly.com/news/2240219821/Infosec-2014-Datacentre-security-key-to-cloud-security-says-Google?asrc=EM_EDA_28719943&utm_medium=EM&utm_source=EDA&utm_campaign=20140430_Infosec%202014:%20Datacentre%20security%20key%20to%20cloud%20security,%20says%20Google_

    Sunday, April 27, 2014

    Password Requirements Quick Guide


    Password Requirements Quick Guide
    Question: Which characters are required in my password?
    Answer: That depends on how long it is. The shorter it is, the more restrictions there are. Here are the specific requirements:
    Number of charactersRequirements
    8-11mixed case letters, numbers, and symbols
    12-15mixed case letters and numbers
    16-19mixed case letters
    20 or moreAny characters you like!
    Stanford recommends a password 16 or more characters long.
    Longer passwords are inherently more secure because it takes hackers longer to guess them when employing a brute force method. So make your password 16 characters or longer!
    Because they only require upper and lower case letters, passwords that are 16 characters or longer are much easier to type on a mobile device.
    You may be thinking “How on earth can I come up with a password that long?!” It’s easy! Just select 4 random words. For example: orange eagle key shoe. That’s 21 characters including the spaces.
    Now go forth and create your own awesome passwords and keep your account secure!