Friday, September 12, 2014

Internet of Things to make CISOs redefine security efforts

Internet of Things to make CISOs redefine security efforts
Posted on 12 September 2014.
By year-end 2017, over 20 percent of enterprises will have digital security services devoted to protecting business initiatives using devices and services in the Internet of Things, according to Gartner, Inc. Business cases using Internet of Things (IoT) devices already exist and their role in business and industry will force enterprises to secure them.

“The power of an Internet of Things device to change the state of environments and of itself will cause CISOs to redefine the scope of their security efforts beyond present responsibilities,” said Earl Perkins, research vice president at Gartner.

“IoT security needs will be driven by specific business use cases that are resistant to categorization, compelling CISOs to prioritize initial implementations of IoT scenarios by tactical risk. The requirements for securing the IoT will be complex, forcing CISOs to use a blend of approaches from mobile and cloud architectures, combined with industrial control, automation and physical security,” Perkins added.

Gartner predicts that the installed base of "things," excluding PCs, tablets and smartphones, will grow to 26 billion units in 2020, which is almost a 30-fold increase from 0.9 billion units in 2009. The component cost of IoT-enabling consumer devices will approach $1, and "ghost" devices with unused connectivity will be common.

There will be a $309 billion incremental revenue opportunity in 2020 for IoT suppliers from delivering products and services. The total economic value-add from IoT across industries will reach $1.9 trillion worldwide in 2020 by which time more than 80 percent of the IoT supplier revenue will be derived from services. The industries likely to see the greatest value added from the IoT will initially be manufacturing, healthcare providers, insurance, and banking and securities. However, this growth will not be confined there but will expand across all industry sectors.

“In an IoT world, information is the ‘fuel’ that is used to change the physical state of environments through devices that are not general-purpose computers but, instead, devices and services that are designed for specific purposes,” said Mr. Perkins. “The IoT is a conspicuous inflection point for IT security — and the CISO will be on the front lines of its emerging and complex governance and management.”

Mr. Perkins said that the Nexus of Forces identified in Gartner research— cloud, social, mobile and information — is driving early-state opportunities in the IoT. The IoT already has a myriad of commercial and consumer technology use cases that range from connected homes and connected automobiles to wearable devices, from intelligent medical equipment to sensor systems for smart cities and facilities management.

The characteristics of intelligent, purpose-built devices that are networked to provide information and state changes for themselves or surrounding environments are increasingly used in OT systems, such as those found in industrial control and automation (sometimes referred to as the "industrial IoT"). However, securing the IoT represents new CISO challenges in terms of the type, scale and complexity of the technologies and services that are required.

“At this time, there is no "guide to securing IoT" available that provides CISOs with a framework for incorporating IoT principles across all industries and use cases. What constitutes an IoT device is still up for interpretation, so securing the IoT is a ‘moving target.’ However, it is possible for CISOs to establish an interim planning strategy, one that takes advantage of the ‘bottom up’ approach available today for securing the IoT,” said Mr. Perkins.

“Gartner advises security leaders against over thinking IoT security by attempting to draft a grand strategy that encompasses all IoT security needs to this point in time. Instead, they should lower the residual risk of the IoT by assessing whether the particular business use case provides better control and performance. Lessons from these initial use cases will serve as building blocks for a broader strategy for addressing the security of the IoT.”

Sunday, September 7, 2014

In the Big Picture, Jennifer Lawrence Has the Same Security Problem as Your Bank

                   
in Data Security   
 

In year with rampant security breaches, two of this past week’s revelations proved that we could still be shocked by the level of threats from exposed photos, business operations and personal info.
b2ap3_thumbnail_PappLosAngeles_smile_celebrity_security.jpg(Don’t) smile! Celebrities and financial systems seem to be making a similar strategic mistake. (Image: "PappLosAngeles" by Blackbow17 - Own work. Licensed under Creative Commons Attribution 3.0 via Wikimedia Commons.) Over the last week, we’ve seen a massive spill of private pics from celebrities like Jennifer Lawrence and Kirsten Dunst from what is believed to be lame passwords attached to email and personal cloud accounts. On the business side, major banks revealed gigabytes of customer checking, savings and other personal information may have been “siphoned” from a mix of complex data system intrusions and easily discovered loopholes from outdated computer software.
There is a nearly incomprehensible amount of information leaked out from these two very different data exposures. What strikes me most beyond the tawdry pics and gigabytes are the reasons these security problems are the same. This isn’t a loose attempt to lump together saucy celebrity pics and enterprise software woes. Rather, it’s to note that your information – personal, financial or otherwise – is under threat and at risk from a range of sources. Yet, too often we see acceptance of one method to protect information.
One layer of data security is not better than nothing. In light of today’s security threats, one layer is just as bad as none. Multiple methods of defense are the only way to safeguard ourselves, regardless of whether “we” are a Wall Street financial behemoth or selfie posing celeb. For certain, finding the right layers of defense is a more involved process than merely saying so. It starts with a change in mindset. Gone are the days of believing in one option or checkbox to keep our business or personal data safe. And there is no acceptance that we’re powerless to protect against these risks.
In the weeks ahead, we’ll share practical strategies on a defense-in-depth approach to protect from the three main sources of threats – what we like to call “snoops, thieves and idiots.” In the meantime, let us know which data protection problems are most challenging for you or most vexing to read about.

Google acceleration of SHA-1 deprecation draws resistance

              

Google acceleration of SHA-1 deprecation draws resistance


Security holes in nascent Google Chrome patched
Google said Chrome 39, to be released within 12 weeks, will treat some sites as untrusted, accelerating the transition and user woes.
After some pushback from the industry, Google has revised its timetable for deprecating support of SHA-1 crypto hash for issuing TLS/SSL digital certificates, but the new schedule still may be too aggressive and nearly impossible for many web operators to meet.
Noting for quite some time that SHA-1 no longer offers an acceptable level of security, Google has made it clear would compel users to update their security certificates, moving from SHA-1 to SHA-2 over the next two to three years. And Microsoft, too, said last fall it would start withdrawing its support from SHA-1 on January 1, 2016, with the transition complete by January 1, 2017.
But the Google's late August announcement that Chrome 39, due to be released within the next 12 weeks, will treat some sites as untrusted and that notifications would began appearing when users accessed those sites, took even advocates by surprise.
The accelerated schedule raised concerns that potentially hundreds of thousands of web operators may not be able to comply in the proposed timeframe and that users would find the notifications both confusing and alarming.
“It took everyone by surprise,” CA Security Council's (CASC) Jeremy Rowley, associate general counsel at DigiCert, Inc., told SCMagazine.com in a Wednesday interview.
While the CASC applauds Google's “endeavor” to strengthen browser security and supports the transition to SHA-2, he explained that a lot of companies are using SHA-1, particularly in China and the first notifications in Google's proposed schedule would hit during the holiday season, when companies can't have any interruptions. Even the adjusted deprecation schedule offers only a little wiggle room.
“It's a nice gesture,” said Rowley, but “accelerating a whole year really messes up the sales cycle.”
The number of organizations and users that the change will impact is currently unknown.
“Maybe Google has numbers on how many people it will impact but they haven't shared yet,” Rowley said. “We know a lot of people using SHA-1. Getting [SHA-2] installed on their systems in the next two months” before the warnings start popping up, might prove impossible.


The warnings might also “confuse the end users of websites,” CASC's Robin Alden, CTO at Comodo CA Ltd., told SCMagazine.com in an interview. “How are they going to understand what that means." 
In fact, the alerts may leave them questioning whether they can trust the internet.
Potentially, among the hardest hit be the will be small and medium-sized businesses, which often hire an outside consultant to set up their servers and security certificates then just let them ride for two to three years.
Switching certificates more frequently, unless there is a known compromise, may be cost-prohibitive. Larger organizations, like Google, for instance, change their certificates frequently and may be more current.
To ease the burden and smooth the transition, “we would like to work [Google, Microsoft and others] to get a timeline that works for everyone,” said Rowley. “We need to make sure everyone coordinates so users don't have to change certificates so often.”

The Police Tool That Pervs Use to Steal Nude Pics From Apple’s iCloud


       
icloud-hack-tools-inline
Then One/WIRED
As nude celebrity photos spilled onto the web over the weekend, blame for the scandal has rotated from the scumbag hackers who stole the images to a researcher who released a tool used to crack victims’ iCloud passwords to Apple, whose security flaws may have made that cracking exploit possible in the first place. But one step in the hackers’ sext-stealing playbook has been ignored—a piece of software designed to let cops and spies siphon data from iPhones, but is instead being used by pervy criminals themselves.
On the web forum Anon-IB, one of the most popular anonymous image boards for posting stolen nude selfies, hackers openly discuss using a piece of software called EPPB or Elcomsoft Phone Password Breaker to download their victims’ data from iCloud backups. That software is sold by Moscow-based forensics firm Elcomsoft and intended for government agency customers. In combination with iCloud credentials obtained with iBrute, the password-cracking software for iCloud released on Github over the weekend, EPPB lets anyone impersonate a victim’s iPhone and download its full backup rather than the more limited data accessible on iCloud.com. And as of Tuesday, it was still being used to steal revealing photos and post them on Anon-IB’s forum.
“Use the script to hack her passwd…use eppb to download the backup,” wrote one anonymous user on Anon-IB explaining the process to a less-experienced hacker. “Post your wins here ;-)”
Apple’s security nightmare began over the weekend, when hackers began leaking nude photos that included shots of Jennifer Lawrence, Kate Upton, and Kirsten Dunst. The security community quickly pointed fingers at the iBrute software, a tool released by security researcher Alexey Troshichev designed to take advantage of a flaw in Apple’s “Find My iPhone” feature to “brute-force” users’ iCloud passwords, cycling through thousands of guesses to crack the account.
If a hacker can obtain a user’s iCloud username and password with iBrute, he or she can log in to the victim’s iCloud.com account to steal photos. But if attackers instead impersonate the user’s device with Elcomsoft’s tool, the desktop application allows them to download the entire iPhone or iPad backup as a single folder, says Jonathan Zdziarski, a forensics consult and security researcher. That gives the intruders access to far more data, he says, including videos, application data, contacts, and text messages.
On Tuesday afternoon, Apple issued a statement calling the security debacle a “very targeted attack on user names, passwords and security questions.” It added that “none of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.”
But the conversations on Anon-IB make clear the photo-stealing attacks aren’t limited to a few celebrities. And Zdziarski argues that Apple may be defining a “breach” as not including a password-guessing attack like iBrute. Based on his analysis of the metadata from leaked photos of Kate Upton, he says he’s determined that the photos came from a downloaded backup that would be consistent with the use of iBrute and EPPB. If a full device backup was accessed, he believes the rest of the backup’s data may still be possessed by the hacker and could be used for blackmail or finding other targets. “You don’t get the same level of access by logging into someone’s [web] account as you can by emulating a phone that’s doing a restore from an iCloud backup,” says Zdziarski. “If we didn’t have this law enforcement tool, we might not have the leaks we had.”
Elcomsoft is just one of a number of forensics firms like Oxygen and Cellebrite that reverse engineer smartphone software to allow government investigators to dump the devices’ data. But Elcomsoft’s program seems to be the most popular among Anon-IB’s crowd, where it’s been used for months prior to the most current leaks, likely in cases where the hacker was able to obtain the target’s password through means other than iBrute. Many “rippers” on Anon-IB offer to pull nude photos on behalf of any other user who may know the target’s Apple ID and password. “Always free, fast and discreet. Will make it alot easier if you have the password,” writes one hacker with the email address eppbripper@hush.ai. “Willing to rip anything iclouds – gf/bf/mom/sister/classmate/etc!! Pics, texts, notes etc!”
One of Anon-IB’s rippers who uses the handle cloudprivates wrote in an email to WIRED that he or she doesn’t consider downloading files from an iCloud backup “hacking” if it’s done on behalf of another user who supplies a username and password. “Dunno about others but I am too lazy to look for accounts to hack. This way I just provide a service to someone that wants the data off the iCloud. For all I know they own the iCloud,” cloudprivates writes. “I am not hacking anything. I simply copy data from the iCloud using the user name and password that I am given. Software from elcomsoft does this.”
Elcomsoft’s program doesn’t require proof of law enforcement or other government credentials. It costs as much as $399, but bootleg copies are freely available on bittorrent sites. And the software’s marketing language sounds practically tailor-made for Anon-IB’s rippers.
“All that’s needed to access online backups stored in the cloud service are the original user’s credentials including Apple ID…accompanied with the corresponding password,” the company’s website reads. “Data can be accessed without the consent of knowledge of the device owner, making Elcomsoft Phone Password Breaker an ideal solution for law enforcement and intelligence organizations.”
Elcomsoft didn’t respond to a request for comment.
On Monday, iBrute creator Troshichev noted that Apple had released an update for Find My iPhone designed to fix the flaw exploited by iBrute. “The end of fun, Apple have just patched,” he wrote on Github. But Anon-IB users continued to discuss stealing data with iBrute in combination with EPPB on the forum Tuesday, suggesting that the fix has yet to be applied to all users, or that stolen credentials are still being used with Elcomsoft’s program to siphon new data. Apple didn’t immediately respond to WIRED’s request for further comment, though it says it’s still investigating the hack and working with law enforcement.
For Apple, the use of government forensic tools by criminal hackers raises questions about how cooperative it may be with Elcomsoft. The Russian company’s tool, as Zdziarski describes it, doesn’t depend on any “backdoor” agreement with Apple and instead required Elcomsoft to fully reverse engineer Apple’s protocol for communicating between iCloud and its iOS devices. But Zdziarski argues that Apple could still have done more to make that reverse engineering more difficult or impossible.
“When you have third parties masquerading as hardware. it really opens up a vulnerability in terms of allowing all of these different companies to continue to interface with your system,” he says. “Apple could take steps to close that off, and I think they should.”
The fact that Apple isn’t complicit in law enforcement’s use of Elcomsoft’s for surveillance doesn’t make the tool any less dangerous, argues Matt Blaze, a computer science professor at the University of Pennsylvania and frequent critic of government spying methods. “What this demonstrates is that even without explicit backdoors, law enforcement has powerful tools that might not always stay inside law enforcement,” he says. “You have to ask if you trust law enforcement. But even if you do trust law enforcement, you have to ask whether other people will get access to these tools, and how they’ll use them.”


http://www.wired.com/2014/09/eppb-icloud/?mbid=social_twitter

Monday, July 28, 2014

Security zou volledig over data moeten gaan

Security zou volledig over data moeten gaan

door
data, brei, bigdata
door
    
Achtergrond - Deelnemers aan een paneldiscussie die donderdag in Boston onder Dell securityexperts, partners, analisten en klanten werd gehouden, stelden dat ingebedde security in data niet alleen wenselijk is, maar op termijn zelfs noodzakelijk.
Tijdens het evenement, de Dell 1-5-10 Series, werd ingegaan op de vraag wat over 1, 5 en 10 jaar de risico's zijn op gebied van security en wat bedrijven daartegen kunnen doen.
Hoewel altijd lastig is iets binnen IT te voorspellen, waren de panelleden het met CTO Don Ferguson van de Dell Software Group eens dat het securitymodel voor applicaties, dat al decennia lang ongewijzigd is, in de toekomst niet langer houdbaar zal zijn.
Het huidige model, waarin het programma verantwoordelijk is voor de identificatie van de persoon en de omgang ermee, hoort in de prullenbak thuis, zegt Ferguson. "Data is overal. Op een apparaat, in de cloud, op netwerken. Je kunt niet alle plekken overal beveiligen, dus data moet zichzelf beveiligen. De huidige generatie applicaties is niet geprogrammeerd om daarmee om te kunnen gaan."

Data overal kunnen volgen

Dit model veranderen kan volgens directeur Patrick Sweeney van Dell SonicWALL het BYOD-probleem oplossen. In plaats van je te richten op een apparaat of gebruiker, zou het alleen moeten gaan om de data - niet om het device of het netwerk. "Je moet data kunnen beschermen, er eigenaar van kunnen zijn en het kunnen intrekken."
Om dit binnen een termijn van vijf jaar te bewerkstelligen, zijn er drie dingen nodig, zegt Sweeney. "Allereerst moet data via enterprise key management versleutelt gaan worden. Dat hoort eigenlijk in iedere BYOD-strategie thuis."
"Daarna moet de data staan in een virtuele container waarover ik controle heb, net als een ambassade die rekening houdt met mijn regels en mijn wetten. Iemand anders kan het niet een andere betekenis geven, het uitsturen via e-mail, of wat dan ook."
"Tot slot moet ik eigenaar zijn over de policies die controleren wie toegang heeft. Als ik de sleutel wil intrekken, moet ik op een rode knop kunnen drukken en de bytes op afstand onleesbaar kunnen maken", zegt hij. Sweeney haalt daarbij aan dat als de NSA zulke controle over zijn data had gehad, dan had dit Edward Snowden kunnen verhinderen data te verzamelen en te verspreiden aan journalisten.


Sweeney ziet het liefst dat het toegang hebben tot data hetzelfde gaat zijn als "het kijken van tv".
Fellow en directeur van de Dell Software Group Tim Brown zegt dat dit van de data vraagt dat het "zelf begrijpt wat de policy zou moeten zijn, hoe gevoelig het is en wat de regels moeten zijn voor toegang". Hij zegt: "Pas als we op dat punt geraken, dan pas kunnen we informatie meer vrijelijk laten rondstromen."


Zulke doorbraken in security zijn, hoe significant ze ook mogen zijn, nog niet de uiteindelijke oplossing. Een reden dat het risico toch groter zal worden, is de komst van het Internet of Things.
Fellow en CTO Jon Ramsey van Dell SecureWorks zegt dat de samenkomst van cyber en fysieke domeinen - smartphones, smart cars, smartgrid - zorgen baart. "Het geeft kansen aan criminelen in het fysieke domein die die kansen niet eerder hadden", zegt hij.
"Er worden dingen met elkaar verbonden die oorspronkelijk niet ontworpen zijn om in verbinding te staan, wat betekent dat we de risicoafweging sterk negatief beïnvloeden", aldus Ramsey.
Daarnaast is er nog de menselijke factor. Vice-president David P. Wrenn van Advanced Office Systems vraagt zich af hoe technologie "idioten als ikzelf gaat verhinderen op een kwaadaardige link te klikken. Dat vind ik één van de grootste uitdagingen die onze branche kent."

Gevaar zit in software development

Over het feit dat de menselijke factor in security nog steeds het belangrijkst is en ook zal blijven, waren de panelleden het eens. Wat daarbij volgens Ferguson niet helpt, is dat security nog steeds als een bijzaak wordt gezien in softwareontwikkeling. "Als civiele ingenieurs gebouwen zouden bouwen op de manier waarop programmeurs applicaties ontwikkelen, dan zouden spechten de beschaving ten gronde kunnen richten", zegt hij. "In die zin maakt het Internet of Things me bang."
Executive director Brett Hansen van Client Solutions Software is iets optimistischer ingesteld. Hij denkt dat security van IT naar de boardroom verplaatst. "Het zal een fundamentele businessdiscussie gaan worden waarin gezocht wordt naar een balans tussen productiviteit en veiligheid."


http://cio.nl/beveiliging/83347-security-zou-volledig-over-data-moeten-gaan?utm_source=+SIM&utm_medium=email&utm_campaign=20140728-15%3A10%3A02_webwereld_daily_cron&utm_content=&utm_term=_7815

Sunday, July 27, 2014

25.07.2014 Only 16% of fund managers believe AIFMD regulations have a positive impact

Only 16% of fund managers believe AIFMD regulations have a positive impact

A significant 47% of real assets fund managers believe the Directive will have a negative impact on the industry, and 37% believe it will have no noticeable impact
Only a small proportion of fund managers active in infrastructure and real estate think that AIFMD regulations will have a positive impact on their firm and industry, following a recent survey of over 140 managers active in the asset classes.
Nevertheless, almost half (49%) of infrastructure managers and 34% of real estate managers worldwide indicated to Preqin in June 2014 that they would be compliant by the AIFMD’s July 2014 deadline.
Other AIFMD Key Facts:
-          36% of real estate fund managers believe regulation in general is having a negative impact on their industry, compared to 16% of infrastructure managers.
-          Almost two-thirds (63%) of infrastructure managers felt the AIFMD will have a negative impact on the industry, with 41% of real estate managers feeling the same way.
-          A greater proportion of real estate managers will not market within the EU. 38% of real estate managers indicated they will not market their funds in the region, compared to 26% of infrastructure managers. This may present opportunities for other managers to secure capital from investors based in the EU, with over 2,000 European institutional investors investing in real estate or infrastructure.
JOBS Act Key Facts:
-          A notable proportion of real estate managers, 30%, believe the JOBS Act is having a positive impact on their firm and industry, although only 1% of managers surveyed have registered and will market under the Act.
-          18% of infrastructure managers believe the JOBS Act is having a positive impact, with 8% of respondents either already registered or planning on registering under the Act.
-          Over 70% of both infrastructure and real estate fund managers either will not market their funds under the JOBS Act, or do not plan to at the moment.
-          Increased scrutiny from the SEC was named by the greatest number of real estate managers (18%) as the main reason preventing them marketing under the JOBS Act.

“The recent implementation of various regulations on the alternative investment industry has received mixed reviews from fund managers, with many wary of the additional costs and administrative requirements associated with compliance. In particular, fund managers appear to have a negative outlook on the AIFMD, with many unhappy with the additional cost and administrative burden required in order to be compliant and to continue marketing their funds within the EU.
Regarding the JOBS Act, although this allows managers to market to a broader audience through registration under section 506©, very few intend to follow this route in the short term, with many firms concerned about increased scrutiny of regulators and the additional costs that advertising would bring, as well as the potential negative perception of wider marketing. Only time will tell whether managers will adapt to and take advantage of the new opportunities created by the JOBS Act.” - Andrew Moylan, Head of Real Assets Products


http://www.iss-mag.com/regulations-and-compliance/only-16-percent-of-fund-managers-believe-aifmd-
 

Friday, July 4, 2014

The Ultra-Simple App That Lets Anyone Encrypt Anything

The Ultra-Simple App That Lets Anyone Encrypt Anything

 By  
Original illustration: Getty
Original illustration: Getty

Encryption is hard. When NSA leaker Edward Snowden wanted to communicate with journalist Glenn Greenwald via encrypted email, Greenwald couldn’t figure out the venerable crypto program PGP even after Snowden made a 12-minute tutorial video.
Nadim Kobeissi wants to bulldoze that steep learning curve. At the HOPE hacker conference in New York later this month he’ll release a beta version of an all-purpose file encryption program called miniLock, a free and open-source browser plugin designed to let even Luddites encrypt and decrypt files with practically uncrackable cryptographic protection in seconds.
“The tagline is that this is file encryption that does more with less,” says Kobeissi, a 23-year old coder, activist and security consultant. “It’s super simple, approachable, and it’s almost impossible to be confused using it.”
A screenshot from an early demo of miniLock.
A screenshot from an early demo of miniLock.
Kobeissi’s creation, which he says is in an experimental phase and shouldn’t yet be used for high security files, may in fact be the easiest encryption software of its kind. In an early version of the Google Chrome plugin tested by WIRED, we were able to drag and drop a file into the program in seconds, scrambling the data such that no one but the intended recipient—in theory not even law enforcement or intelligence agencies—could unscramble and read it. MiniLock can be used to encrypt anything from video email attachments to photos stored on a USB drive, or to encrypt files for secure storage on Dropbox or Google Drive.
Like the older PGP, miniLock offers so-called “public key” encryption. In public key encryption systems, users have two cryptographic keys, a public key and a private one. They share the public key with anyone who wants to securely send them files; anything encrypted with that public key can only be decrypted with their private key, which the user guards closely.
Kobeissi’s version of public key encryption hides nearly all of that complexity. There’s no need to even register or log in—every time miniLock launches, the user enters only a passphrase, though miniLock requires a strong one with as many as 30 characters or a lot of symbols and numbers. From that passphrase, the program derives a public key, which it calls a miniLock ID, and a private key, which the user never sees and is erased when the program closes. Both are the same every time the user enters the  passphrase. That trick of generating the same keys again in every session means anyone can use the program on any computer without worrying about safely storing or moving a sensitive private key.
“No logins, and no private keys to manage. Both are eliminated. That’s what’s special,” says Kobeissi. “Users can have their identity for sending and receiving files on any computer that has miniLock installed, without needing to have an account like a web service does, and without needing to manage key files like PGP.”
In fact, miniLock uses a flavor of encryption that had barely been developed when PGP became popular in the 1990s: elliptic curve cryptography. Kobeissi says that crypto toolset allows for tricks that haven’t been possible before; PGP’s public keys, which users have to share with anyone who wants to send them encrypted files, often fill close to a page with random text. MiniLock IDs are only 44 characters, small enough that they can fit in a tweet with room to spare. And elliptic curve crypto makes possible miniLock’s feature of deriving the user’s keys from his or her passphrase every time it’s entered rather than storing them. Kobeissi says he’s saving the full technical explanation of miniLock’s elliptic curve feats for his HOPE conference talk.
Despite all those clever features, miniLock may not get a warm welcome from the crypto community. Kobeissi’s best-known previous creation is Cryptocat, a secure chat program that, like miniLock, made encryption so easy that a five-year-old could use it. But it also suffered from several serious security flaws that led many in the security community to dismiss it as useless or worse, a trap offering vulnerable users an illusion of privacy.
But the flaws that made Cryptocat into the security community’s whipping boy have been fixed, Kobeissi points out. Today the program been downloaded close to 750,000 times, and in a security ranking of chat programs by the German security firm PSW Group last month it tied for first place.
Despite Cryptocat’s early flaws, miniLock shouldn’t be dismissed, says Matthew Green, a cryptography professor at Johns Hopkins University who highlighted previous bugs in Cryptocat and has now also reviewed Kobeissi’s design spec for miniLock. “Nadim gets a lot of crap,” Green says. “But slighting him over things he did years ago is getting to be pretty unfair.”
Green is cautiously optimistic about miniLock’s security. “I wouldn’t go out and encrypt NSA documents with it right now,” he says. “But it has a nice and simple cryptographic design, with not a lot of places for it to go wrong…This is one that I actually think will take some review, but could be pretty secure.”
Kobeissi says he’s also learned lessons from Cryptocat’s failures: miniLock won’t initially be released in the Chrome Web Store. Instead, he’s making its code available on GitHub for review, and has taken special pains to document how it works in detail for any auditors. “This isn’t my first rodeo,” he says. “[MiniLock's] openness is designed to show sound programming practice, studied cryptographic design decisions, and to make it easy to evaluate miniLock for potential bugs.”
If miniLock becomes the first truly idiot-proof public key encryption program, it could bring sophisticated encryption to a broad new audience. “PGP sucks,” Johns Hopkins’ Green says. “The ability for regular people to encrypt files is actually a valuable thing…[Kobeissi] has stripped away the complexity and made this thing that does what we need it to do.”


http://www.wired.com/2014/07/minilock-simple-encryption/