Sunday, August 18, 2013

LastPass password manager gets security patch against password leakage bug

LastPass password manager gets security patch against password leakage bug

Sorry, something happened and we couldn't sign you up. Please come back later and try again.
Congratulations, you've successfully signed up for our daily news! Check your inbox soon, we've sent you an email.
Sorry, we won't accept that email address. Please try a different address.
We're adding your address to our list...
Join thousands of others, and sign up for Naked Security's newsletter

Filed Under: Data loss, Featured, Privacy, Vulnerability

When there's a database breach involving passwords, which seems to be disappointingly often these days, we usually end up advising you to change your passwords, just in case.
Stolen passwords of this sort are supposed to be salted-and-hashed, so that the actual password you chose isn't directly available to the cybercrooks.
Nevertheless, with the hashes in their possession, they're one step closer to guessing correctly.
→ Password databases shouldn't uses hashes as an excuse for poor security. That's because someone with the database can try out passwords, typically by the bazillion, and use the hashes to find out when they've guessed correctly. Password hashes are an important layer of defence, but they're only one of many layers that should be in place. Password databases shouldn't get stolen in the first place. Just to be clear.
While we're about it, we usually take the opportunity to suggest that you make your passwords reasonably complex, for example: a 14-character mix of UPPERS, lowers, d1g1t5 and \/\/@ckies (punctuation marks).

And we urge you not to choose the same password for more than one site, so that attackers don't end up with a skeleton key to all your online accounts if they manage to breach any one of them.
This advice, of course, means you might end up with a list of passwords that becomes decreasingly easy to remember, like this:
Facebook:     S01?wouldE=myP
Twitter:      Ft1,IdtutGC'sA
Webmail:      aPWDmw1oft(CA)
Cartoon site: incorrectdonkeyaccumulatorclip
As a result, we often also suggest using a password manager that can generate hard-to-guess passwords for you, and then keep them locked up with one very-well-chosen master password.
Of course, this always begs the question, "What if the password manager gets breached?"
That is a very good question, and we don't have an easy answer, because there isn't one.
(Useful ways to mitigate that risk include: don't save your really important passwords, such as those for banking and taxation, along with the rest; and insist on two-factor authentication wherever you can.)
Well worth a listen while you're here
Sophos Techknow Podcast: Two-factor Authentication Explained

(15 April 2013, duration 16'25", size 9.9MBytes)
We've invariably avoided taking sides by not explicitly recommending any particular product, but LastPass is one that regularly appears in our articles.
And, wouldn't you know it, LastPass just pushed out a update that fixes, amongst other things, a security hole that could leak your precious password secrets.
We urge you to grab that update, which came out two days ago, on the grounds that a security hole patched is, simply put, no longer a security hole.
But don't panic, as there are some palliative factors:
  • The bug affects Internet Explorer users on Windows only.
  • The bug requires an attacker to perform a memory dump of Internet Explorer.
A memory dump is where you connect from one process to another, and suck out the contents of the system memory it's using.
Apparently, until the 16 August 2013 update, a LastPass memory dump might well be found to contain unencrypted pasword strings.
This is the same sort of attack that we have written about frequently in the context of banking malware.
Stymied by data protection regulations that force financial institutions to encrypt credit card data when it is saved to disk, the crooks have taken to riffling through memory instead.
They hope to find the raw data from your card's magnetic stripe as it passes through memory on its way from the card reader onto the disk or network.
Generally, though admittedly not always, that means you need access to the victim's computer, and perhaps even administrator-level powers, which usually means getting malware onto the computer first.
And if you can do that, then most, though not necessarily all, security bets are off anyway.
So if you are confident you haven't been infected with malware since you last changed your passwords, then you're probably OK just grabbing the LastPass update and installing it as soon as you can.
On the other hand, since in cases like this we usually advise you to change your passwords anyway, just in case...
...you may want to change your passwords anyway, just in case.

Google To Auto-Encrypt Users’ Cloud Data For Free

Google To Auto-Encrypt Users’ Cloud Data For Free

August 16, 2013

 
Image Credit: alexyndr / Shutterstock
Michael Harper for redOrbit.com – Your Universe Online
Google has improved their cloud storage security by automatically encrypting all data stored there by customers for free. Now, any new data pushed to Cloud Storage will be encrypted as it’s being uploaded and before it’s written to a physical drive. Google will hold the cryptographic keys by default and notes all files can be encrypted before they’re sent to the cloud, thereby giving users access to their own keys.
Any existing data already in the cloud will be encrypted in the same way in the coming months, according to Dave Barth, Google product manager. He also promises regular users won’t notice any difference when using the service. The tech world is still abuzz over the unfolding story of the NSA and its surveillance programs. Tech companies like Google, Apple, Facebook and Microsoft are all taking part in the programs, although the extent to which they’re aiding the NSA remains unknown.
“If you require encryption for your data, this functionality frees you from the hassle and risk of managing your own encryption and decryption keys,” explains Barth in a Cloud Platform Blog.
“We manage the cryptographic keys on your behalf using the same hardened key management systems that Google uses for our own encrypted data, including strict key access controls and auditing.”
When a user wants to access this data, their login and password will act as keys and decrypt the files before viewing. When the user logs out of their account, the files are locked again.
Discussing the specifics, Barth says each file and its associated metadata in Cloud Storage is encrypted with its own unique key under the 128-bit Advanced Encryption Standard, or AES-128. Another key is used to access each file; this key is also encrypted and protected with the owner’s password. Going further, each of these keys are themselves encrypted by a set of master keys which are regularly rotated to avoid being cracked by hackers.
Users wanting even more protection in Google’s cloud can encrypt the files themselves before uploading. This means even if a hacker manages to crack each of Google’s keys, they will still have to crack the key used to encrypt the files before they were uploaded.
This may be an attractive option to those spooked by Google and others’ participation in the NSAs surveillance programs. Programs such as Prism and Xkeyscore allow the government to work with tech companies to obtain information about their users. Though the NSA claims this information is only used in the name of national security and only accessed when they perceive a threat, these parameters have yet to be concretely defined.
For their part, the companies are allowed to give their users only a vague idea of how many times the government has asked for this information. But even this didn’t come without a fight.
When CNet asked how Google will handle all this newly encrypted data when the feds comes asking for it, the search company simply replied “in accordance with the law.”.
“We don’t provide our encryption keys to any government. We believe we’re an industry leader in providing strong encryption, along with other security safeguards and tools.”


Source: Michael Harper for redOrbit.com - Your Universe Online


Saturday, August 17, 2013

Google Offers Automatic Cloud Storage Data Encryption, But Is Data Safer On Premises?


google, cloud computing, cloud storage, eim, information managementGoogle continues to add to the appeal of its cloud storage capabilities, this time with the announcement that users’ data that is placed in its Cloud Storage system will be encrypted by default.

Google Cloud Storage Encryption

In a Google blog post, Dave Barth, Product Manager with Google Cloud Storage, says that the new encryption abilities need no setup or configuration, require no alterations to the way users access the service and — even better — it is offered as a free service once you have subscribed to Cloud Storage.
Cloud Storage is Google’s service for those wishing to store data to the cloud, be they individuals or business users. It also integrates with Google analytics.

If you find the idea of encryption off-putting, this is probably something that you’re really going to like in that Google does all the encryption and securing for you.
According to the post, it manages the encryption keys using the same kind of technology that it uses for its own data — and you know how cagey Google is about its own data — including rigorous controls around key access and auditing.
However, Google not only encrypts the data, it also encrypts the files’ metadata using 128-bit Advanced Encryption Standard (AES-128), while the per-object key itself is also encrypted with a key that is unique to the owner of the data. That key is also encrypted with a set of encryption keys that are regularly rotated.
Users can also managed their own keys if they want. The result is a system that encrypts to about five different levels, so it may be difficult for those that don’t manage this kind of technology already.
These encryption abilities have been applied server-side already so that any new data entering Cloud Storage will be encrypted automatically. However, Google said that it will also encrypt the data that is in its cloud already in the coming months.

Google Trust Deficit?

There are two obvious problems with all this, and both relate to issues that have been highlighted in recent weeks with the Edward Snowden controversy.
The first issue is this: Earlier in the week it emerged that Google doesn’t appear to believe that Gmail users should expect their emails to be private and that it was scanning them on a mind-boggling rate for the purposes of placing adverts. Who is to say that it won’t apply the same standards to enterprise data that it is storing?
The second issue is clear from the thread of comments on Dave Barth’s blog post and goes like this: Even if your data is encrypted, what is to stop government agencies from simply requesting the encryption keys? The Snowden data would seem to indicate that some of the major web companies have few qualms about offering data access to these agencies.
This in turn puts the whole cloud versus on premises debate back to where it started originally. If enterprises really want to secure their data, do they ultimately have to keep it on premises? While there is still no definitive answer to this, the scales are weighing firmly on the side of on premises at the moment. Whether any company can offer enough guarantees to counter-balance that remains to be seen.

Thursday, August 15, 2013

Nine out of 10 senior staffers have BYOD access to corporate data

Nine out of 10 senior staffers have BYOD access to corporate data

Summary: We asked ZDNet readers how much free reign their businesses allow their employees, and the results found that not only do senior staffers generally have access to whatever corporate data they like while on the go, there isn't a security policy in place half the time.
Almost nine out of 10 senior staff members from Australian organisations have access to corporate data on their personal mobile phones.
A recent ZDNet survey of IT decision makers within Australian organisations has found that 89 percent of businesses permit some members of their senior leadership team to access corporate data from their own mobile devices.
Breaking this figure down further, over half of all respondents (57 percent) indicated that of their senior leadership team, all or almost all (81 percent to 100 percent) possess this level of access.
access-on-byod
Staff members that are allowed access to data. Click to enlarge.
(Image: CBS Interactive)
When it came to "less trusted" staff members, the level of access dropped, with 77 percent of respondents indicating that members of middle management have access. This figure again drops, to 64 percent, for all other staff.
The kind of data that was accessed by staff members is more restricted for financial data, with the company's financial data completely off limits 57 percent of the time, but these restraints are lower for customer and supplier data, at 44 percent and 43 percent, respectively.
access-to-specific-info
The type of information that staff members have access to. Click to enlarge.
(Image: CBS Interactive)
Despite the high penetration of BYOD, the security precautions taken by respondents' organisations is lacking. About half of all respondents said that their business does not have a formal, documented security policy at all. When examining better practices, only 17 percent of all respondents said that they are certified to ISO 27001 standards. An additional 11 percent were undergoing certification at the time of the survey, but the remainder had not considered it.
Despite only half of the organisations having a security policy, it was billed by respondents as one of the top methods for controlling access; 77 percent of respondents said they use an "acceptable use" policy to outline what employees can and cannot do on their mobile devices.
The other top security measure was requiring passwords on mobile devices that connect to the network. Again, 77 percent of respondents use this to reduce risk.
which-of-the-following-security-approaches-have-you-implemented-v1
Security measures that respondents have in place. Click to enlarge.
(Image: CBS Interactive)
Despite their seemingly growing popularity, the use of secure containers is one of the lowest adopted measures (28 percent) among respondents. For all of its benefits, the use of data encryption on mobile devices is also quite low (43 percent), and organisations use a mobile device management suite almost half of the time (46 percent).
The survey was conducted by CBS Interactive's insights and analytics division, and looked at the responses of over 100 IT decision makers.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Top 10 information security blogs 'By 'Dejan Kosutic on May 07, 2012'

'By 'Dejan Kosutic on May 07, 2012

 
There is a huge amount of information about information security on the Internet, so it is really difficult to stay informed about really relevant stuff. This is why I made this list – I wanted to offer a list of independent, expertly written and up-to-date blogs that will keep you right on track.
The blogs are listed alphabetically:
Information Security Blog by Anton Chuvakin
Security topics including SIEM, log management, compliance, vulnerability management and cloud security.
IT Security Blog by Mark Brooks
This blog focuses on strategies and information security programs that protect high value information assets such as intellectual property, trade secrets, and privacy data.
Krebs on Security by Brian Krebs
This blog features posts on a number of recurring themes, including online crime investigations, latest threats, security updates, data breaches, and cyber justice.
Lenny Zeltser on Information Security
Presents a unique perspective on information security, based on  the author’s broad experience in IT, business and malware combat. The blog presents several infosec topics, including incident response, malicious software and risk management.
Mind Streams of Information Security Knowledge by Dancho Danchev
This blog covers trends and fads, tactics and strategies, intersecting with third-party research, speculations and real-time CYBERINT assessments, all packed with sarcastic attitude. The blog offers access to timely, insightful and independent open-source intelligence (OSINT) analyses for maintaining the necessary situational awareness to stay on top of emerging security threats.
Network Security Blog by Martin McKeay
Views on security, privacy and anything else that catches author’s attention.
Privacy and Information Security Law Blog
This blog covers important aspects of information security rarely covered in other blogs – privacy and information security law updates and analysis.
Schneier on Security by Bruce Schneier
A blog covering security and security technology – the author explains, debunks, and draws lessons from security stories that make the news.
Security Affairs by Pierluigi Paganini
This daily updated blog is focused on all the areas in the security sphere. Its target is to make security a theme accessible to professionals and laymen alike, with an objective judgment on the main security events with specific attention to the subjects of cyber warfare, cyber crime and hacking.
TaoSecurity by Richard Bejtlich
TaoSecurity blog is one of the original security blogs – it will soon be ten years old. It focuses on incident detection and response for targeted threats, with emphasis on Chinese intruders.
And by the way, Security Bloggers Network offers links to over 100 various information security blogs.

Thursday, August 8, 2013

Informatiebeveiliging bij DUO loopt 'voortdurend risico'

 

Bewerkt door: Redactie
8-8-13 - 12:09  bron: ANP
Eerstejaarsstudenten zoeken naar hun mentor in het Wilhelminapark op de eerste dag van de Utrechtse Introductie Tijd (UIT) vorig jaar. © anp.
De persoonlijke en financiële gegevens van meer dan 600.000 studenten lopen gevaar. De informatiebeveiliging van de Dienst Uitvoering Onderwijs (DUO), de instantie die onder meer verantwoordelijk is voor de studiefinanciering, loopt 'voortdurend risico''.
Dat staat in een rapport van het Ministerie van Onderwijs, dat onlangs via een WOB-verzoek naar buiten werd gebracht en waar ScienceGuide donderdag over bericht. De risico's zijn al langer bekend, maar er is nog onvoldoende vooruitgang geboekt. 'Geen gewenste situatie'', staat in het 'Samenvattend Auditrapport 2012' van het ministerie.

Tuesday, August 6, 2013

Gegevensuitwisseling voor veiligheid - de kracht van koppelen

Gegevensuitwisseling voor veiligheid


De kracht

van koppelen


De dertien basisregistraties in Nederland bevatten een keur

aan gegevens.Gegevens uitwisseling biedt kansen voor

keten samenwerking binnen de veiligheidspraktijk. Maar



vanwege de foutenmarges is zorgvuldigheid daarbij geboden,

schrijven Wimfred Grashoff en Mireille Reijs.

Professionals in het veld van handhaving en



criminaliteitsbestrijding zijn gebaat bij

goede informatie-uitwisseling. Daarbij gaat

het maar ten dele om de techniek van de

informatiesystemen. Net zo belangrijk zijn de wettelijke

kaders die gegevensuitwisseling mogelijk

maken, en (bestuurlijke) afspraken tussen organisaties

over hoe gegevens worden vastgelegd. Over dat

laatste gaat dit artikel. Want als partijen dezelfde

dingen – bedrijven, gebouwen of mensen – verschillend

noemen of indelen, dan is het lastig om gegevens

uit te wisselen. De basisregistraties van de

overheid kunnen een belangrijke bijdrage leveren

aan de oplossing.

door Wimfred Grashoff en Mireille reijs

Wimfred Grashoff is implementatieadviseur bij

de stichting ICTU, Mireille Reijs is tekstschrijver bij

communicatiebureau Nawwara.

In opkoMst

Het zogenoemde stelsel van Basisregistraties van de

Nederlandse overheid bestaat uit dertien registraties.

Elke registratie bevat authentieke gegevens die door

alle overheidsinstellingen verplicht en zonder nader

onderzoek worden gebruikt bij de uitvoering van hun

publiekrechtelijke taken. De registraties bevatten niet

alleen gegevens van personen en adressen, maar ook

bijvoorbeeld bedrijfsnamen, WOZ-waarden en voertuiggegevens.

Een aantal registraties bevat ook geografische

informatie, zoals coördinaten en kaarten.

Sommige basisregistraties worden al veel gebruikt,

zoals de Gemeentelijke Basisadministratie Personen

(GBA). Bij andere, zoals het Handelsregister en de

Basisregistraties Adressen en Gebouwen (BAG) is

het gebruik in opkomst. En registraties zoals de

Basisregistratie Ondergrond zijn nog in ontwikkeling.

De dertien Nederlandse basisregistraties

vormen in toenemende mate een samenhangend

56 secondant #3/4 | juli-augustus 2013



>>

geheel, doordat ze worden gekoppeld. Bijvoorbeeld:

in het Kadaster wordt verwezen naar personen uit

de GBA en naar bedrijven uit het Handelsregister.

En de GBA gebruikt adressen uit de BAG.

GeGevensWoorDenboek

Wat betekenen de basisregistraties voor de veiligheidspraktijk?

Er zijn al sprekende voorbeelden te

vinden in andere sectoren. Neem de vooringevulde

elektronische aangifte, waarmee belastingplichtigen

in Nederland de laatste jaren kennis hebben gemaakt.

De Belastingdienst vult daarbij al een aantal gegevens,

zoals het loon en de WOZ-waarden – van tevoren

in. Dat kan doordat de Belastingdienst gegevens

koppelt aan een uniek persoonsgebonden nummer,

het burgerservicenummer (BSN), en controles uitvoert

via een koppeling met de GBA.

Frauderen met

uitkeringen is

een stuk lastiger

geworden


Ook voor overheidsorganisaties die zich bezighouden

met werk en inkomen, zoals de Sociale Verzekeringsbank,

het UWV en de sociale diensten, is het BSN een

belangrijke sleutel tot het delen en uitwisselen van

gegevens. Cruciaal in deze keten is een digitaal netwerk

waarin de ketenpartners hun gegevens delen,

het Suwinet. Daarmee kunnen zij eenvoudig elkaars

gegevens raadplegen. Dat kan omdat alle partijen die

deelnemen aan het Suwinet de eigen gegevens koppelen

aan het BSN. De samenwerking wordt verder

ondersteund door een ‘gegevens woordenboek’ met

definities en afspraken over gegevens(vastlegging).

Doordat de ketenpartners in werk en inkomen afspreken

hoe gegevens worden vastgelegd en die gegevens

ook daadwerkelijk delen, is frauderen met uitkeringen

een stuk lastiger geworden.

Een goed voorbeeld in het domein van handhaving

en criminaliteitsbestrijding is het risicogericht

inspecteren. Dat betekent dat toezichthouders

meer controleren bij risicobedrijven en minder bij

bedrijven die zich aan de regels houden. De rijksinspecties

en inspectie- en opsporingsdiensten

gebruiken hiervoor het zogenoemde Inspectieview.

Via dit virtuele dossier kijken inspecties als het ware

even mee in de administraties van collega’s. De

gebruiker krijgt bij een zoekopdracht met een

bedrijfsnaam een actueel overzicht van alle inspectiegegevens

die bij het betreffende bedrijf horen.

basisregistraties

kunnen vastgoedcriminaliteit

helpen

opsporen


Een knelpunt bij Inspectieview heeft te maken met

eenduidige registraties. Als de ene inspectie een

bedrijf onder de naam ‘Van der Poel en zonen’ registreert,

en de andere onder ‘Handelsmaatschappij

v.d. Poel’, dan is de kans groot dat er geen relevante

bevindingen worden getoond. Dit effect blijkt nog

sterker wanneer inspecties grote bestanden analyseren

en vergelijken. Het gebruik van basisregistraties

voorkomt dit soort problemen. Want als alle

aangesloten inspecties in hun registraties de

bedrijfsnaam en het nummer van de Kamer van

Koophandel (uit het Handelsregister) zouden

overnemen, dan is de trefkans aanzienlijk groter.

verDachte constructIes

De basisregistraties kunnen ook vastgoedcriminaliteit

helpen opsporen. Neem de infobox Crimineel en

Onverklaarbaar Vermogen (iCOV) van de Belastingdienst,

de Fiscale Inlichtingen- en Opsporingsdienst,

het Openbaar Ministerie, de politie en de

Financial Intelligence Unit. De iCOV koppelt gegesecondant