Wednesday, March 15, 2017

De top 5 IAM functionaliteiten die u niet mag missen

De top 5 IAM functionaliteiten die u niet mag missen

              
Identity & Access Management (IAM). Voor velen een onbekende term en een ver van je bed show. Voor anderen een dagelijkse bezigheid. Hoe dan ook een onderwerp binnen de IT waar u dagelijks mee te maken hebt en welke steeds belangrijker wordt. Belangrijker omdat bedrijfsdata steeds vaker open staat voor hackers. Maar ook omdat u vanuit de (nieuwe Europese) wetgeving allerlei verplichtingen hieromtrent hebt. In mei 2018 wordt de Europese wetgeving (de General Data Protection Regulation) doorgevoerd, vanaf dan bent u verplicht uw organisatie afdoende te beveiligen. Een ontoereikend beveiligingsbeleid kan u zomaar 4% van de totale internationale jaaromzet kosten.
IAM helpt organisaties om in controle te komen en blijven zodat gebruikers vanaf het juiste device, de juiste en veilige toegang krijgen tot beveiligde applicaties. Naast het tijdig en gestandaardiseerde beheer van gebruikersaccounts en toegangsrechten biedt het met bijvoorbeeld rapportage mogelijkheden ook ondersteuning bij het naleven van wet- en regelgeving.
Identity & Access Management is bedrijfsbreed. Elke medewerker en administrator heeft er mee te maken. Maar wat zijn nou de onderdelen die u absoluut zou moeten hebben als u aan de slag gaat met Identity & Access Management? Wij hebben een top vijf voor u opgesteld:
  1. Provisioning
  2. Data Access Governance
  3. Single Sign On
  4. Self Service
  5. Privileged Access Management
  1. Provisioning

Hier wordt het HR proces gedigitaliseerd. Het proces van in-, door- en uitstroming van medewerkers wordt op basis van business regels geautomatiseerd. Er is dus geen tussenkomst meer nodig van een IT-afdeling of applicatiebeheer om de benodigde accounts te beheren. Het IAM systeem kan gekoppeld worden aan uw HR systeem. Deze koppeling zorgt ervoor dat alle wijzigingen die HR maakt automatisch worden doorgevoerd. Een nieuwe medewerker komt binnen en krijgt direct een account met de juiste rechten. Een medewerker verandert van functie en zijn rechten worden direct aangepast. Een medewerker verlaat het bedrijf en zijn account wordt direct inactief gezet.
Het inregelen van provisioning op deze manier zorgt ervoor dat handmatige acties niet meer nodig zijn. Menselijke fouten van het verkeerd kopiëren van bijvoorbeeld de naam zijn uitgesloten. Naast veel tijd maakt het uw omgeving ook een stuk veiliger. De rechten van een medewerker worden direct goed gezet en bij het verlaten van het bedrijf zijn deze ook niet langer actief. Voor u geen verhalen meer zoals de ex-politieman die nog toegang had tot gevoelige informatie.
De voordelen op een rij:
  • Snellere doorlooptijd
  • Tijdsbesparing
  • Minder foutgevoelig
  • Betere beveiliging van data
  1. Data Access Governance

Data Access Governance is het beheren en onderhouden van toegangsrechten tot applicaties en van gebruikersrechten binnen applicaties. Gebruikerstoegang en -rechten van medewerkers worden via een uniform beheermodel uitgegeven, gewijzigd en ingetrokken. Medewerkers krijgen de juiste autorisaties zoals deze bij hun rol horen. Dit wordt ook wel Role Based Access Control (RBAC) genoemd. Op basis van de rol die de medewerker heeft wordt met een autorisatiematrix bepaald tot welke systemen en applicaties de medewerker toegang krijgt. Een andere variant hiervan is Attribute Based Access Control (ABAC). Het systeem registreert alle acties van gebruikers automatisch, net als de tijdstippen, hierdoor kunt u de benodigde rapporten maken voor de audit.
De voordelen op een rij:
  • Betere beveiliging van data
  • Tijdsbesparing
  • Meer inzicht door rapportage mogelijkheden
  1. Single Sign On

Een term die u ongetwijfeld kent. Met slechts één keer inloggen direct toegang tot meerdere applicaties op een veilige manier. Een veelgehoorde wens vanuit de medewerkers, eenvoudig in te regelen via een IAM systeem.
U koppelt applicaties aan het IAM systeem welke alle accounts en wachtwoorden beheert. Met bijvoorbeeld het Active Directory account welke ook gekoppeld is aan het IAM systeem kunnen gebruikers na eenmalig inloggen (bijvoorbeeld op de PC) vrij toegang krijgen tot alle gekoppelde applicaties.
Een koppeling met applicaties van externe organisaties of cloud applicaties is mogelijk met federatie service. Hierdoor kunnen gebruikers met hun eigen gegevens inloggen in applicaties van andere organisaties. Ook is het mogelijk om dan bijvoorbeeld MultiFactor Authentication (MFA) te implementeren. DigiD is hiervan een voorbeeld voor verschillende overheidsapplicaties.
De voordelen op een rij:
  • Gebruikersgemak
  • Tijdsbesparing
  • Meer veiligheid
  1. Self Service

Een helpdesk die een groot deel van zijn tijd kwijt is aan het resetten van wachtwoorden herkenbaar? Selfservice voor gebruikers maakt het mogelijk dat gebruikers zelf hun wachtwoord kunnen resetten op een beveiligde manier en hun persoonlijke informatie zelf kunnen onderhouden zonder tussenkomst van anderen. Maar ook kan er bijvoorbeeld Self service ingericht worden voor het aanvragen van toegang tot een applicatie, facilitaire services of het inzien van rapportages. Het goedkeuringsproces wordt vastgelegd in gestructureerde workflows. De manager kan de aanvraag direct goed- of afkeuren en laten doorvoeren via het IAM systeem. Tussenkomst van de IT afdeling is dan niet meer nodig.
De voordelen op een rij:
  • Gebruikersgemak
  • Tijdsbesparing
  1. Privileged Access Management

Diefstal van privileged logingegevens, zoals van uw beheerders, is een groot gevaar voor elke organisatie. Uw bedrijfskritische data inclusief persoonsgegevens wilt u tenslotte niet op straat hebben. Privileged Access Management (PAM) beschermt de privileged logingegevens en verdient een prioriteit. Geïntegreerd met het IAM systeem biedt het een solide uitgangspunt voor uw beveiliging. Het helpt u bevoorrechte toegangen binnen uw bestaande Active Directory Domain Server (ADDS) te beperken. Dit kunnen zowel interne als externe gebruikers zijn, denk maar eens aan de remote IT-support die uw organisatie wellicht inschakelt (zoals 92% van alle organisaties doet).
PAM monitort en logt het gebruik van privileged logingegevens en levert gedetailleerd inzicht in wie van uw beheerders wat en wanneer doet. Er wordt dus meer controle door monitoring en logging toegevoegd en u krijgt gedetailleerde rapportagemogelijkheden. Aanvallen zijn hierdoor vele malen sneller op te sporen. Bovendien kunt u zo ook beter aan de meldplicht datalekken voldoen.
De voordelen op een rij:
  • Voldoe aan compliance eisen en wetgeving
  • Meer inzicht door rapportages
  • Beter beveiliging van data
Naast deze vijf functionaliteiten is er nog veel meer mogelijk. Denk aan het beheren van mobiele devices. IAM wordt de spin in het web van uw IT organisatie. Of u nu de keuze maakt voor IAM on premise of in de cloud: met een goed ingericht IAM systeem bent u klaar voor de toekomst.


Georg Grabner is Managing Partner van IonIT. IonIT is gespecialiseerd in Identity & Access Management, Cloud Enablement en Enterprise Mobility. Als technologie onafhankelijke dienstverlener automatiseert IonIT IT-processen zodat gebruikers op tijd de juiste en veilige toegang krijgen tot de toepassingen en diensten die zij nodig hebben en bedrijven het inzicht en controle hierover krijgen.

Wednesday, March 8, 2017

What is the motivation behind data security?

What is the motivation behind data security?
With an increasing number of data breaches splashed across front page news, not only in the UK but also across the world, companies have good reason to take security seriously


What is the motivation behind data security?
Legislation should be regarded not as a stick to beat companies into compliance, but as a framework upon which to base a full data security strategy. So that when your company is targeted by fraudsters, as it almost inevitably will be, you have the processes in place to withstand it
The story of Tesco Bank suffering a data breach that exposed 20,000 of its customers’ accounts to theft is a perfect illustration of a headline grabbing crisis that can severely damage brand image, and probably comes close to being every CEO’s worst nightmare.
From such serious reputational damage to punitive fines, the pressure to protect customers is increasing from all sides.
Yet, some organisations are still resistant, whether through reluctance to invest in something that doesn’t directly generate revenue, or sometimes simply because of inertia. So, which are the factors that finally drive directors to take action?
>See also: Tesco Bank accounts have been compromised
If reputational damage doesn’t top the list, organisations could easily assume that financial losses might play the biggest part in a businesses decision to bolster data security.
A staggering £399.5 million was lost due to fraud in the first half of 2016 in relation to payment cards, remote banking and cheques. What’s more, this represented an increase of 25% from the same period in 2015, when the figure was £320.3 million.

It’s all about the rules

But according to a recent report, neither of these scenarios is the leading reason that drives organisations to invest in security measures.
A survey of 126 large companies (those with more than 2,000 employees) has shown that the number one motivator for the people in charge of protecting sensitive information is in fact regulatory compliance.
The study indicated, moreover, that the importance of regulations had increased nine-fold in just over two years.
The regulations that drive businesses to act cover a wide spectrum. From the Health Insurance Portability and Accountability Act (HIPAA) regulations in the US to the Financial Conduct Authority (FCA) in the UK or the Payment Card Industry Data Security Standard (PCI DSS) worldwide, every sector has its own regulator, with varying degrees of power.
One that every organisation should take heed of, however, is the European Union’s new General Data Protection Regulation (EU GDPR).

The EU GDPR is almost upon us

The biggest, and some would say most intimidating, regulation on the horizon is the EU GDPR. After four years of discussions and debates, the new legislation has been signed and sealed and will officially be delivered in 2018.
This regulation, which is unlikely to be toned down by Brexit, will issue severe penalties on organisations that fail to protect customer data. A breach could result in a fine of €20 million or 4% of annual turnover, whichever is highest.
>See also: What are US companies’ view on GDPR?
Similar fines will come into force for neglecting to report a data breach to the relevant Data Protection Authority (DPA) within 72 hours. An estimate of the aforementioned Tesco Bank breach suggests that it would have cost the company £1.94 billion in fines had the EU GDPR already come into effect today.
With this staggering figure out in the public domain, company boards would do well to take notice and start planning now for how they will adhere to the latest data regulation.
To further concentrate the minds of business leaders, the UK Information Commissioner’s Office recently recommended that company directors be held personally liable for data breaches.

Doing the right thing

In the world of global business, where short-term profit is highly valued, perhaps we should not be surprised that many organisations will not take action until they are forced to do so by regulators.
But common sense tells us that the more enlightened will be aware that there is a bigger picture. A financially-damaging, one-time penalty is a terrible thing, but long-term distrust and bad-will among your customer base could be fatal.
>See also: Change is coming: the GDPR storm
Legislation should be regarded not as a stick to beat companies into compliance, but as a framework upon which to base a full data security strategy. So that when your company is targeted by fraudsters, as it almost inevitably will be, you have the processes in place to withstand it.
Don’t wait until a new regulation forces you into action; sort out your security measures now. You owe it to your customers – and to your employees – to protect the data you handle.

Sourced by Tim Critchley, CEO, Semafone

Tuesday, January 10, 2017

Tackling #GDPR, #ISO27001 or #PCI compliance? Take a free toolkit trial & see how much time & money you could save https://www.itgovernance.co.uk/free_trial?utm_source=social&utm_medium=twitter …

Tackling , or compliance? Take a free toolkit trial & see how much time & money you could save

Product Demos

Product News RSS feed

EU GDPR Documentation Toolkit

The EU General Data Protection Regulation (GDPR) Documentation Toolkit contains a sample set of documentation templates that will help you meet stringent new data protection requirements from the EU.

ISO 27001 ISMS Documentation Toolkit

This toolkit provides you with a comprehensive set of pre-written ISMS documents compliant with the newly released ISO27001:2013 Standard.

The toolkit includes all the necessary policies, procedures, work instructions and records that will save you months of work as you get your information security system operational.

ISO 9001 QMS Documentation Toolkit

This ISO 9001:2015 QMS Documentation Toolkit Trial contains a sample set of documentation templates that will help you assess some of the templates we have in our full documentation toolkit.

PCI DSS Documentation Toolkit

This toolkit gives you all the policies and documentation that you need for compliance with the PCI DSS. It has been developed to integrate with an ISO27001 ISMS, and provides pre-written compliant documentation templates for all the mandatory PCI DSS policies, and easily customisable implementation guidelines. It will be particularly useful for level 2, 3 and 4 merchants.

ITSM, ITIL® ISO/IEC 20000 Implementation Toolkit

Developed by service management gurus Shirley Lacy and Jenny Dugmore, this toolkit helps organisations implement service management using ITIL® practices to prepare for successful ISO20000 certification. It is the perfect investment for organisations that want an optimal route to implementing service management best practice, to implementing ITIL and also to achieving ISO/IEC 20000 certification.

IT Governance Control Framework Implementation Toolkit

Each of the 37 COBIT®5 processes requires multiple documents, including charters, standing agendas, policies and procedures. The IT Governance Control Framework Implementation Toolkit simplifies the documentation part of the project. It is easy to use, easy to customise and requires all the policy and procedure documentation templates you will need.

ISO 14001 EMS Toolkit

The ISO 14001:2015 EMS Documentation Toolkit provides organisations with the necessary tools and resources to successfully implement the documentation required for compliance, helping organisations to control the environmental impact of their activities, products and services, while demonstrating continual improvements in their environmental performance.

ISO 22301 BCMS Implementation Toolkit

The ISO22301 BCMS Implementation Toolkit helps organisations implement a BCMS to ensure their survival following disaster. It contains all the document templates and tools a Business Continuity Manager needs to produce tailored versions of all the documents needed to implement a BCMS in line with ISO22301 quickly and effectively.

ISO 50001 Energy Management System Toolkit

The ISO50001 Energy Management System Documentation Toolkit contains pre-written documents and templates that meet requirements applicable to energy use and consumption. The toolkit can be applied to any organisation that wishes to ensure it conforms to ISO50001, the standard which helps organisations develop an energy policy.

ISO 38500 IT Governance Framework Toolkit

Compatible with ISO38500, this toolkit contains nearly 1600 pages of resources, comprising 98 different documents, including templates, guidelines, checklists, questionnaires, slide presentations, assessments and planning tools, to help you take the fast route to ISO38500 best practice.

Product Demos

Product News RSS feed

Data Protection Toolkit

This toolkit contains the essential document templates and tools for any UK organisation responsible for personal information to comply with the UK Data Protection Act (DPA) 1998. The DPA sets out eight principles for securely managing personal information, but offers no guidance on complying with them.

ISO 20000 Documentation Toolkit

This toolkit gives your organisation the documentation it needs to implement an IT service management system whilst meeting the basic documentation requirements of ISO/IEC 20000-1. This toolkit will be most valuable to those organisations that have already established significant IT Service Management documentation and those who are looking for the specific documents that will enable them to achieve ISO20000-1 certification.

OHSAS 18001 Occupational Health and Safety Toolkit

This toolkit contains over 40 separate documents that will help you accelerate the development of your organisation’s Occupational Health and Safety Management System (OHSMS).The documents in this toolkit have been specifically designed for use by organisations seeking to comply with the requirements of OHSAS18001. These policies and procedures are all compatible with ISO27001 and other toolkits within the IT Governance toolkit suite.

IG Toolkit: Business Partner Documentation Templates

This ITGP documentation toolkit contains all the documents that you need to complete and put into operation to meet the Business Partner requirements and achieve compliance with the IG Toolkit (v14). The toolkit also includes guidance on how to upload your ITGP toolkit to your SharePoint document management system.

IG Toolkit: Commercial Third Parties Documentation Templates

This ITGP documentation toolkit contains all the documents that you will need to complete and put into operation if you are to meet the Commercial Third Party requirements and achieve compliance with the IG Toolkit (v14). It also includes guidance on how to upload your ITGP toolkit to your SharePoint document management system.

ABMS Anti-Bribery Documentation Toolkit

UK organisations are legally obliged to take active steps to prevent bribery. The best way to do this is to implement an Anti-Bribery Management System with enforceable procedures. Our Anti-Bribery Management Documentation Toolkit will help you achieve compliance with BS10500, the British Standard for Anti-Bribery management, by giving you the templates and documents needed for compliance, and showing you how to integrate them with your existing management system, whether it is an ISMS or QMS.

Business Management Controls Toolkit

The Business Management Control Toolkit is aimed at managers, auditors and professionals who want to understand how the assets, transactions, operations, systems activities and investments of their organisation may be protected, controlled and improved more effectively and more efficiently.

Business Transformation Toolkit

The Business Transformation Toolkit provides organisations with a structured approach to managing change, and looks at different approaches that can be tailored to your organisation. This toolkit will enable you to plan and prepare for change, implement change, and embed the change, for the transition to appear seamless to the customer.

SharePoint Governance Toolkit

The ITG SharePoint Governance Toolkit contains a comprehensive suite of documents and templates that will help you implement and maintain an effective and secure SharePoint service in your organisation. This toolkit is applicable in all SharePoint environments (MOSS 2007, MOSS 2010) and draws on a wide range of established best practice, including Microsoft guidance.

Social Media Governance Toolkit

This toolkit helps organisations create an effective governance structure for social media activities. It contains documents for creating a social media policy, documents that help embed crucial controls around social media, including an acceptable use agreement, and best-practice policies for social media activity, including guidelines for blogging, Facebook, LinkedIn, Reddit, Twitter, YouTube, Instagram, Pinterest and Tumblr.

Thursday, December 29, 2016

How a 2011 Hack You’ve Never Heard of Changed the Internet’s Infrastructure

FROM SLATE, NEW AMERICA, AND ASU

How a 2011 Hack You’ve Never Heard of Changed the Internet’s Infrastructure

It all started with an internet user in Iran who couldn’t get into his Gmail account.

n Saturday, Aug. 27, 2011, an Iranian man who went by the online alias alibo tried to check his email—only to find he couldn’t connect to Gmail. Yet the problem disappeared when he connected to a virtual private network that disguised his location. Whatever was going on, it seemed to only affect computer users in Iran.
His first hunch was that the problem might be somehow tied to the Iranian government—which was known for interfering with online activity—or a problem with his local internet service provider. So alibo posted a question about the issue on the Gmail Help Forum. Two days later, Google responded to this apparently small problem in a big way: It issued a public statement about the incident, attributing the problem to security issues at a Dutch company called DigiNotar. Within a month, DigiNotar had been taken over by the Dutch government. Not long after that, it declared bankruptcy and dissolved.
Advertisement
Cybersecurity breaches don’t usually spell the end of companies, much less spur national governments to seize control of private firms. But the DigiNotar compromise was unusual in many ways. Usually, the cybersecurity incidents we read about involve a company failing to protect the information entrusted to it by users. DigiNotar was different: Its whole reason for existence was to tell internet users who and what they could trust—and in 2011, it failed spectacularly in that mission. In the process, it revealed the cracks in the largely hidden infrastructure that enables our computers to make decisions about which websites to load or which software updates to run. Those decisions may seem mundane, but they are critical to the safety and security of the internet.
Five years later, the story of DigiNotar’s demise is all but forgotten, eclipsed by a series of more recent, more easily understandable, and more exciting breaches directed at organizations like Target, Sony, Ashley Madison, and the Democratic National Committee. But DigiNotar’s case has had long-lasting impacts, motivating some much needed improvements in the security of our online trust infrastructure, including a set of new minimum security requirements for companies like DigiNotar that were announced earlier this month by the Certificate Authority Security Council. But even as announcements like those suggest that we’re moving, gradually, in the right direction, the DigiNotar breach—even five years later—still serves as an important reminder of the risks inherent to our often-confusing online ecosystem.
Understanding what happened to DigiNotar requires some understanding of how your computer decides who and what to trust. There are a lot of people in the world building websites and coding software, and at any given moment, at least a few of them are up to no good—designing webpages built to look exactly like your bank’s in order to steal your login credentials, for instance, or writing programs that will encrypt your hard drive and hold it for ransom.
Advertisement
So every time you try to visit a webpage, your browser checks to make sure that the site you’re loading is really the one you’re trying to access, not a malicious page some wily attacker is trying to redirect you to. Similarly, when you download a new piece of software, your operating system will often check to make sure it’s coming from a trustworthy vendor.
But browser and operating system companies don’t want to be responsible for screening every single website and software developer in the world. Instead, they rely on third parties to vouch for those sites and developers. The third parties do this by issuing what are called certificates.
Bear with me, because this gets a little complicated—but it’s worth it. Those certificates are the bedrock of much of the security we enjoy online. They’re the reason we can do online banking, the reason we can download and install software updates without fearing malware. The organizations that screen people and companies and issue them these certificates are called certificate authorities, or CAs, and they make money by vetting and selling certificates to website operators and software manufacturers. There are hundreds of certificate authorities around the world, but the major browser and operating systems list only a small number as authorities whose certificates they will automatically trust. These elite certificate authorities are called root CAs. And the root CAs can, in turn, grant that same authority to any other intermediate CA they choose to endorse.
For instance, in 2015, a root CA operated by the China Internet Network Information Center issued an intermediate certificate to one of its customers, which then used the certificate to perform man-in-the-middle attacks and potentially intercept traffic between users and websites.
Advertisement
Any of those trusted CAs, whether they are root CAs or intermediate CAs that have been endorsed, can then issue certificates for any website they choose—even websites that have chosen to buy certificates from different CAs. This complex and often opaque hierarchy of relationships is one reason why things can go so wrong.
Most of this happens behind the scenes. If you’re a normal internet user, you probably only encounter certificates when you get a warning from your browser about trying to visit a website whose certificate was issued by an untrusted CA. But of course, that’s often not a clear—or alarming—enough message to stop users from trusting those sites. Admit it: You’ve probably clicked through such a warning.
There are different kinds of certificates: Some just allow for encrypted communication between you and the website you’re visiting, while other “Extended Validation” certificates involve a more thorough vetting of the website operator and certify that the organization running that site really is who it claims to be. When you see a little lock next to a site’s URL in your browser window, that usually means there’s an encrypted connection; a green bar next to the URL usually indicates that the site has an EV certificate.
Got all that?
Advertisement
* * *
Now that the background is out of the way: DigiNotar was a certificate authority—a well-established and reputable one. It was one of the root CAs for all of the major web browsers and issued many of the digital certificates used by the Dutch government for its online services. That made it a tempting target for criminals: If they could control one of these root CAs and issue trusted certificates themselves, they could potentially lure victims to a phishing site or infect computers with malware, bypassing many operating system and browser protections.
Because CAs are prime targets, they have to—and tend to—take security very seriously. DigiNotar was no exception. Among other things, it had segmented its computer networks into several different isolated partitions to constrain access attempts and used an intrusion prevention system to monitor incoming traffic. Every request for a new certificate had to be vetted and approved by two DigiNotar employees. Then, to issue the certificate, an employee had to insert a physical key card into a computer kept in a heavily guarded room. According to a postmortem report on DigiNotar’s compromise by security firm Fox-IT:
This room could be entered only if authorized personnel used a biometric hand recognition device and entered the correct PIN code. This inner room was protected by an outer room connected by a set of doors that opened dependent on each other creating a sluice. These sluice doors had to be separately opened with an electronic door card that was operated using a separate system than for any other door. To gain access to the outer room from a publicly accessible zone, another electronic door had to be opened with an electronic card.
Advertisement
This mix of physical and virtual safeguards demonstrates that DigiNotar was not a company that had failed to think about or invest in security. It understood that its security was vital for its own reputation—and for the wider world of internet users who relied, often without even knowing it, on DigiNotar’s certificates to tell them whom to trust online.
But DigiNotar also made some serious mistakes during the summer of 2011. For one, it was running some unpatched software one its web servers, which allowed an intruder to begin burrowing into its maze of partitioned networks in June 2011. On July 10, the intruder successfully issued his first rogue certificate. All told, by the end of the summer, he would go on to issue 531 rogue certificates for domains ranging from aol.com and microsoft.com to mossad.gov.il and cia.gov. (Once you’ve got access to a CA server, issuing rogue certificates for high-value targets like the CIA is no harder than issuing them for sites like AOL.)
It’s still unclear how exactly the intruder managed to bypass all the physical security in place to protect the inner sanctum where certificates were generated, but the investigators’ best guess was that the keycards for a few computers were left permanently in place. If true, it would have largely defeated the purpose of requiring the keycard insertion—not to mention all those sluiced doors and biometrics and PIN codes—in the first place.
On July 19, a routine check by DigiNotar revealed that some of the certificates it had ostensibly signed were not listed in the company’s logs—indeed, DigiNotar had no records of ever issuing these certificates. They were promptly revoked, and DigiNotar launched an internal investigation that uncovered still more rogue certificates. But by the end of July, the company believed the problem had been dealt with.
Advertisement
So it came as a shock when the report from alibo, the Iranian user, surfaced on the Gmail Help Forum a month later, and Google, in turn, blamed an unauthorized google.com certificate issued by DigiNotar. Some of the rogue certificates, it seemed, had slipped through the cracks of DigiNotar’s internal audit. And they were being used to certify impostor websites.
Thousands of Iranians who tried to visit Google websites in August 2011 were apparently redirected to sites that looked like Google webpages and were also certified as belonging to Google according to certificates issued by DigiNotar. Users from 298,140 unique internet protocal addresses trying to access Google websites were affected, and 95 percent of those IP addresses originated in Iran.
Why bother redirecting hundreds of thousands of Iranian Google users to fraudulent websites? Probably in order to read their email. Only one thing stood in the way: Google Chrome.
Part of what makes changing and securing the certificate ecosystem so difficult is that there are a lot of different stakeholders involved. Besides the hundreds of CAs, there are five major browsers (Firefox, Chrome, Internet Explorer, Safari, Opera), and these two groups have slightly different agendas. The CAs make money by selling certificates, so they want to sell as many as possible without alienating any of the major browsers. The browsers, in turn, are competing with one another for users. They don’t want to constantly block people from visiting websites due to certificate problems that those users are unlikely to understand and very likely to blame on the browser.

Back in 2011, Google Chrome included DigiNotar on its list of trusted CAs and would have happily accepted the company’s certificates for any other domain. But Chrome had a special extra check for Google’s own certificates. Google knew exactly which certificates it had purchased to validate its own domains—and which CAs it had purchased those certificates from. So to make sure that no other certificates were being issued for its domain, Google “pinned” its own valid certificates to its browser, Chrome, and didn’t accept any others, even if they had been issued by trusted vendors like DigiNotar. So on Aug. 27, when alibo tried to log into his Gmail account through Chrome and was redirected to the site signed by the rogue certificate, his browser knew something was wrong. It blocked the webpage, prompting alibo’s post on the Gmail Help Forum and the unraveling of the entire incident—and DigiNotar itself.
No one has ever been caught or charged with the compromise, though many have speculated that Iran’s government was likely involved. The only clue left by the intruder—a message left behind on a DigiNotar server—offers little insight into the perpetrator’s mission or identity other than a profound sense of self-importance. “I know you are shocked of my skills, how I got access to your network,” the message begins. “THERE IS NO [sic] ANY HARDWARE OR SOFTWARE IN THIS WORLD EXISTS WHICH COULD STOP MY HEAVY ATTACKS MY BRAIN OR MY SKILLS OR MY WILL OR MY EXPERTISE.”
The discovery of the DigiNotar compromise left the browser and CA community—to say nothing of the Dutch government—reeling. Browser vendors rushed to revoke trust in DigiNotar certificates, but removing a root CA was not entirely straightforward. “We actually needed to push out an update to Firefox because the CA information was hard-coded to the browser,” Firefox security lead Richard Barnes said. Additionally, many legitimate websites (including some operated by the Dutch government) were still relying on DigiNotar certificates, so the browser vendors were forced to hold off on a blanket ban. Instead, Mozilla decided to block all DigiNotar certificates issued after July 1, 2011, but allowed users to decide whether they wanted to trust certificates issued by the company before that date. But giving users that autonomy over their online security only works if they understand what it is they’re choosing and the implications of that choice—a task that surely went beyond many Firefox users.
While the browsers scrambled to protect their users, the Dutch government took charge of DigiNotar and commissioned Fox-IT to investigate what had gone wrong. Hans Hoogstraaten, who led the investigation, said in an email, “What really shocked me was when I realized the impact it had for the people of Iran. In those days … people got killed for having a different opinion. The hackers (presumably the state) had access to over 300,000 Gmail accounts. The realization that the … security of a small company in Holland [may have] played a part in the killing or torture of people really shocked me.”
Both CAs and browsers have made significant changes to their security practices since 2011. “DigiNotar was a real wake-up call for the entire industry,” said Rick Andrews, senior technical director for website security at Symantec, one of the largest CAs in the world.
Certificate pinning—what Google did with its certificates in Chrome, which resulted in the DigiNotar compromise first being detected—has become more common and has spread beyond companies that manufacture their own browsers. Another initiative, called Certificate Transparency, aims to make sure logs of all valid certificates issued by CAs are publicly accessible. This makes it easier for individual domain owners to monitor whether any certificates have been issued for their domains without their knowledge. To incentivize CAs to log their certificates publicly, Google announced in December 2014 that, beginning in 2015, it would no longer display the green address bar in Chrome for certificates that belong to verified companies unless those certificates had also been logged. In the back and forth between CAs and browsers, the browsers wield much of the power since they ultimately decide which websites users can load and which of the subtle security signals—green bars, lock icons—are conveyed to those users.
Perhaps the most significant change in the certificate landscape is simply that there are now many more certificates than there were five years ago. This is part of a larger push for widespread online encryption spearheaded by the CA Let’s Encrypt, launched earlier this year, which provides free certificates to anyone who wants them. Let’s Encrypt doesn’t provide the Extended Validation certificates that involve verifying a website owner’s identity (the kind that most high-value targets generally get and that warrant a green box in many browsers) because that process cannot be automated. “There are hundreds of millions of websites and devices out there, and in the future there will be many billions. For every one to have a certificate we’ll need issuance systems that can be fully automated,” said Josh Aas, founder of the Internet Security Research Group, which established Let’s Encrypt. Issuing more certificates helps spread encryption, but it also raises the stakes for the security of CAs and the risks posed by incidents like the DigiNotar compromise because it means that an increasing amount of our online communication relies on the protection provided by digital certificates.
And problems with CAs have not gone away. On March 20, 2015, years after the collapse of DigiNotar, Google discovered another set of rogue certificates for Google domains. These certificates had been issued by an Egyptian company, MCS Holdings, which had, in turn, received its certificates from CNNIC, the CA operated by the China Internet Network Information Center, an agency in the Chinese government’s Ministry of Information Industry. Soon afterward, Firefox and Chrome both removed CNNIC from their root CA lists. Just this summer, Chinese CA WoSign was accused of issuing fake certificates for Github and Alibaba, and in October Mozilla announced that it would no longer trust WoSign certificates.
Thanks in no small part to the legacy of DigiNotar, browsers and CAs alike are better able to deal with problems like these than they were five years ago—they can revoke compromised certificates faster, check certificates against public logs, and restrict the use of rogue certificates with pinning. But in other, more fundamental ways, the system of relying on CAs to tell us who we can trust online remains inherently vulnerable—and, perhaps more importantly, largely invisible to most internet users. The complexity of the certificate infrastructure can make it difficult for the wider public—beyond the community of browsers and CAs who have long been attuned to the importance of the DigiNotar compromise—to understand the risks they face online, as well as the signals and warnings that their browsers provide.
“The folks who operate the CAs are really a very tempting point of attack,” said Daniel Kahn Gillmor, a senior staff technologist with the American Civil Liberties Union’s Speech, Privacy and Technology Project. “If I wanted to attack someone else I would be looking for a lever of control that they might not even know existed.” The more we gloss over the crucial components of the trust infrastructure underlying our online communications—an infrastructure that is every bit as relevant today as it was five years ago—the harder it becomes to grasp how deeply and fundamentally all of our security is predicated on the security of digital certificates and the companies that issue them.
This article is part of Future Tense, a collaboration among Arizona State University, New America, and Slate. Future Tense explores the ways emerging technologies affect society, policy, and culture. To read more, follow us on Twitter and sign up for our weekly newsletter.



Josephine Wolff is an assistant professor of public policy and computing security at Rochester Institute of Technology and a faculty associate at the Harvard Berkman Center for Internet and Society. Follow her on Twitter.


Wednesday, December 21, 2016

Mobile banking trojan now has encryption and is targeting over 2000 apps

December 20, 2016

Mobile banking trojan now has encryption and is targeting over 2000 apps

Kaspersky Lab claims that a mobile phone Trojan has gone truly international - with it being translated into 77 languages - and works by demanding admin control of the phone.
The app has gone international, with 77 different languages, is this the future of malware?
The app has gone international, with 77 different languages, is this the future of malware?
Security experts at Kaspersky Lab have discovered a modification of the mobile banking Trojan, Faketoken, which can encrypt user data. Kaspersky Lab has detected several thousand Faketoken installation packages capable of encrypting data, the earliest of which dates back to July 2016.  
Disguised as various programs and games, including Adobe Flash Player, the modified Trojan can also steal credentials from more than 2000 Android financial applications

Top 10 cyber crime stories of 2016

Here are Computer Weekly’s top 10 cyber crime stories of 2016:

http://www.computerweekly.com/news/450404344/Top-10-cyber-crime-stories-of-2016?utm_content=buffer13b00&utm_medium=social&utm_source=twitter.com&utm_campaign=buffer

Tuesday, November 29, 2016


Nov292016

Geert Vermeulen: With U.S. help, Dutch enforcement makes dramatic leap

For many years the Dutch government lagged behind countries like the United States, the UK and Germany enforcing anti-corruption laws. But that has recently changed in a dramatic way.
I wrote a post nearly two years ago for the FCPA Blog about Dutch enforcement actions against KPMG and the construction company Ballast Nedam.
Since then Dutch law was amended to raise jail sentences and maximum penalties for bribery (up to 10 percent of the revenue of a company). And Dutch authorities have been more actively prosecuting local and overseas bribery.
No wonder Transparency International raised the Netherlands from the "little or no enforcement category" to the "limited enforcement category."
Last month the Dutch Volkswagen/Audi distributor Pon settled a bribery case for €12 million (about $12.7 million) with Dutch prosecutors related to a tender for the procurement of cars by the Dutch police force and Ministry of Defense. Representatives of Pon allegedly provided exclusive gifts, discounts on cars and trips abroad.
Six policemen and civil servants are still being investigated by the authorities, as well as a former employee of Pon. Seven other former employees of Pon have already settled.
Last week, the Dutch business newspaper Het Financieele Dagblad said Rudy Stroink, a Dutch businessman who used to own the now defunct company Trammell-Crow Netherlands (TCN), was summoned to appear in court. Stroink allegedly paid €1.7 million through two third-party offshore companies to a representative of Google, Simon Tusha.
In exchange, Tusha allegedly decided that Google would use the data centers of TCN in The Netherlands.
Tusha, an American who lives in Maryland, pleaded guilty in U.S. federal court in May this year to a charge of conspiracy to defraud the United States.
He failed to report kickback or bribe payments from TCN and a UK company, Evolved IT. The Justice Department said from 2008 through 2010 Tusha received more than $2.7 million that he didn't report to the IRS. He hasn't been sentenced yet.
U.S. and Dutch authorities apparently cooperated two years ago when Netherlands-based SBM Offshore paid $240 million to resolve a Dutch enforcement action for overseas bribery, and the U.S. DOJ simultaneously gave SBM a declination.
Earlier this year, Amsterdam-based VimpelCom paid Dutch authorities $397.5 million and the U.S. DOJ and SEC $397.6 million to resolve bribery offenses related to Uzbekistan.
Last month, Swedish telcom TeliaSonera said it reserved $1.45 billion for a settlement of bribery charges also related to Uzbekistan, again with both Dutch and U.S. authorities.
The prosecution of Rudy Stroink seems to be the latest result of the increased cooperation between the U.S. and Dutch authorities.
____
Geert Vermeulen, pictured above, is the CEO of ECMC (Ethics & Compliance Management & Consulting). He is a teacher, consultant and interim/project manager in respect of Ethics & Compliance. He gained most of his experience in-house as Chief Compliance Officer in the insurance and the logistics industry. He is also a former Director of the Netherlands Compliance Institute and the former President of the Dutch Compliance Officer Association. He can be contacted here.
- See more at: http://www.fcpablog.com/blog/2016/11/29/geert-vermeulen-with-us-help-dutch-enforcement-makes-dramati.html#sthash.z49Defts.dpuf

http://www.fcpablog.com/blog/2016/11/29/geert-vermeulen-with-us-help-dutch-enforcement-makes-dramati.html