Showing posts with label against. Show all posts
Showing posts with label against. Show all posts

Sunday, 8 September 2013

How to secure your company against NSA-inspired hacking

How to secure your company against NSA-inspired hacking
Credit: Reuters/Jason Lee

News that the NSA has effectively negated security on the Internet is bleak -- even dire. It should also leave you and your company concerned that the same techniques might one day be used by other individuals and organizations. If you weren't wearing a tinfoil hat yesterday, you may well consider donning new headgear today.

While it's become increasingly clear the NSA can get its eyes onto anything it likes, there's also a great deal of concern that its dirty tricks may have opened the door for other groups to snoop. The revelations that NSA-derived intelligence was (is!) being leaked to the DEA, for example, certainly can't inspire much confidence that NSA is keeping mum on "Bullrun" secrets, as originally covererd in The Guardian and the New York Times.

The Guardian's report on this latest brouhaha quotes Christopher Sohoian, senior policy analyst at the ACLU, as saying:

Backdoors expose all users of a backdoored system, not just intelligence agency targets, to heightened risk of data compromise. This is because the insertion of backdoors in a software product, particularly those that can be used to obtain unencrypted user communications or data, significantly increases the difficulty of designing a secure product.

In the same report, former U.S. Department of Justice prosecutor Stephanie Pell is quoted as saying:

[An] encrypted communications system with a lawful interception back door is far more likely to result in the catastrophic loss of communications confidentiality than a system that never has access to the unencrypted communications of its users.

So humor me for a moment, strap on your tinfoil hats, and let's take a look at simple steps your company can take to minimize the chances of getting hacked -- not just by the NSA, but by other organizations with the wherewithal to unwind NSA's Gordian knots. (I hesitate to point to Russian TV-Novosti's coverage of the Parabon Leaks, which may be woven entirely from tinfoil.)

The fundamental point, according to security guru Bruce Schneier, goes like this: "The math is good, but math has no agency. Code has agency, and the code has been subverted."

Schneier has been working with The Guardian, going through "hundreds of top-secret NSA documents provided by whistleblower Edward Snowden." In The Guardian he explains how to remain secure against NSA surveillance. His recommendations include:

Hide in the network by using Tor.Encrypt communication with TLS or IPsec.Don't use encryption software from major vendors; instead, use public-domain encryption that's compatible with other public-domain encryption packages.

Schneier specifically mentions TrueCrypt, GnuPG, Silent Circle (which recently shut down its Silent Mail email service and released a secure messaging app for Android devices), Tails, CypherPunk's OTR and BleachBit for file wiping.

We don't specifically know if NSA has figured out how to bypass SSL or AES, although Snowden's comment two months ago offers some hope:

Encryption works. Properly implemented strong crypto systems are one of the few things that you can rely on. Unfortunately, endpoint security is so terrifically weak that NSA can frequently find ways around it.

While Snowden doesn't specifically recommend any product, his statement sounds to me like an endorsement for TrueCrypt's AES-256 encryption and GPG.

Using products with "properly implemented strong crypto" tosses the hot potato to the endpoints. It would be wise to assume that some major online email providers have been compromised -- perhaps by devious means, including NSA moles in key positions. It would also be wise to assume that online storage and hosting companies are vulnerable, but we already knew that was the case with the PRISM revelations. It's also fair to assume that your company's virtual private network isn't so private after all. And the SSL "lock" you've been teaching users to check may not be as locked as it once appeared.

The warning issued by Ladar Levison, who shut down his Lavabit email service last month, still rings in my ears:

I have been forced to make a difficult decision: to become complicit in crimes against the American people or walk away from nearly ten years of hard work by shutting down Lavabit... This experience has taught me one very important lesson: without congressional action or a strong judicial precedent, I would _strongly_ recommend against anyone trusting their private data to a company with physical ties to the United States.

It's advice that every company -- inside or outside the United States -- should take to heart. The crushing corollary is that even companies without physical ties to the United States may be compromised, too.

Tip o' the hat to JustinL.

This story, "How to secure your company against NSA-inspired hacking," was originally published at InfoWorld.com. Get the first word on what the important tech news really means with the InfoWorld Tech Watch blog. For the latest developments in business technology news, follow InfoWorld.com on Twitter.


View the original article here

Saturday, 7 September 2013

Apple faces threat from China, bellwether in battle against Android

Computerworld - Apple faces a threat from an unexpected quarter: Chinese developers crafting Android apps, an analytics firm said today.

Chinese developers build nearly two-thirds of the mobile apps used by Chinese consumers -- an even higher percentage than U.S. developers contribute to U.S. consumers' app usage patterns -- illustrating not only the difficulty outsiders face in breaking into the massive market, but reinforcing one analyst's claim that Apple will face a crisis next year if it continues to shed smartphone share.

According to Flurry, a U.S.-based mobile analytics firm, U.S. developers are losing their grip on the mobile app ecosystem, and have accounted for just 36% of all smartphone and tablet apps published so far this year. That's down from 45% over the last two years.

The U.S.'s contribution to the overall app market -- Android and iOS -- looked better when Flurry weighted the data by time spent with apps: There, U.S. developers accounted for 70%. But that, too, was smaller than in years prior, when U.S. programmers held app usage shares of 75% and 76% in 2011 and 2012, respectively.

While Flurry's data was meant to push U.S. developers to think globally -- something they've not done nearly as successfully as those in other countries -- it also revealed an interesting trend in China.

China, said Simon Khalaf, president and CEO of Flurry, is not a big software exporter at the moment. But that will change.

"The software export market [for China] is nascent now, it doesn't look like a big software exporter yet," said Khalaf in an interview. "But Chinese developers are starting to see some adoption in Japan and Korea. That's their focus now: CJK [China, Japan and Korea]."

And Chinese apps, localized for export, will continue to grab global share by expanding into other neighboring markets, including Southeast Asia, India and Indonesia. "The sheer numbers in India ... that's a lot of market [for Chinese apps]," said Khalaf.

The Chinese maneuver may seem inconsequential to Apple at first glance, but Khalaf begged to differ.

That's because Chinese consumers are more likely to be using an Android-based smartphone, one tied to the Android ecosystem, than they are to own an iPhone and rely on Apple's app market. In earlier studies by Flurry, the firm pegged the Android-iOS split in China at about 2 to 1, with Apple's installed base accounting for just 35% of the country's total. The remaining was all Android.

And Chinese developers, like all developers, follow the money. If Android dominates the installed base, Android is what developers will write for.

"When you look at the apps being submitted to Flurry, you do see an interesting shift happening, with Chinese developers releasing Android and iOS apps at the same time," said Khalaf. "But an 'Android-first' release could be the next shift down the road."

And that's where things start to get ugly for Apple. Or so Benedict Evans, an analyst with U.K.-based Enders Analysis, has argued.

In a report published in early August, Evans maintained that without a low-priced iPhone in its portfolio -- and by low, he meant as low as $200 to $300 -- Apple risked losing mind share among developers. In other words, Apple needs market share as much as profit margin for the iPhone to continue being a credible smartphone brand.

Like Khalaf, Evans saw the danger stemming from developers' decisions.

"Developers are starting to move from creating new products on the basis 'iPhone, then maybe Android' to 'iPhone and then Android' or even 'iPhone and Android at the same time,'" Evans said in his report. "We do not see Android becoming a first choice this year, but it is no longer optional for any publisher seeking real reach. If total Android engagement moves decisively above iOS, the fact that iOS will remain big will be beside the point -- it will move from first to first-equal and then perhaps second place on the roadmap."

If that happens, Apple is in a world of hurt.

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here

Wednesday, 28 August 2013

Spear phishing led to DNS attack against the New York Times, others

IDG News Service - The cyberattack that resulted in nytimes.com and some other high-profile websites being inaccessible to a large number of users Tuesday started with a targeted phishing attack against a reseller for Melbourne IT, an Australian domain registrar and IT services company.

The attack resulted in hackers changing the DNS (Domain Name System) records for several domain names including nytimes.com, sharethis.com, huffingtonpost.co.uk, twitter.co.uk and twimg.com -- a domain owned by Twitter -- Jaime Blasco, director of the research lab at security firm AlienVault, said Tuesday in a blog post.

This resulted in traffic to those websites being temporarily redirected to a server under the attackers' control.

Hackers also made changes to the registration information for some of the targeted domains, including Twitter.com. However, Twitter.com itself was not impacted by the DNS hijacking attack.

A hacker group called the Syrian Electronic Army (SEA) that publicly supports Syrian President Bashar al-Assad and his government took credit for the attack via Twitter. During the past several months the group broke into the websites or Twitter accounts of several media organizations including the Financial Times, the Associated Press, The Guardian, BBC and Al Jazeera.

Initial information suggested that the systems of Melbourne IT, the company through which all of the affected domain names were registered and administered, might have been hacked. However, the company later revealed that it was one of its resellers whose account was actually compromised.

"The credentials of a Melbourne IT reseller (username and password) were used to access a reseller account on Melbourne IT's systems," Tony Smith, general manager of corporate communications at Melbourne IT, said Wednesday via email. "The DNS records of several domain names on that reseller account were changed, including nytimes.com."

The name of the reseller was not disclosed.

According to Smith, the affected DNS records have been reverted back to their original values and have been locked from further modification at the .com registry level. The .com registry and DNS zone are operated by VeriSign.

In a subsequent statement sent via email, Bruce Tonkin, the chief technology officer of Melbourne IT, revealed that the compromise was the result of a targeted phishing attack that might have affected multiple accounts.

"We have obtained a copy of the phishing email and have notified the recipients of the phishing email to update their passwords," Tonkin said Tuesday via email. "We have also temporarily suspended access to affected user accounts until passwords have been changed."

Some users likely remained affected by the attack even after the DNS records were corrected by Melbourne IT in its system, as the recursive DNS servers of their ISPs continued to serve the compromised records from cache until their time-to-live (TTL) value expired. Because of caching, DNS record changes can take up to 24 hours to propagate through the entire Internet.

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here