Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Wednesday, October 19, 2011

Computer Security Education

Whether I am teaching a Computer Concepts course or a course in the Information Technology major, the topic of computer security will usually come up. At some point during the discussion, someone will usually ask "should you really be showing us this?" or something of that nature. I suppose that sort of issue exists in many areas. If you teach someone karate, who is to say they won't use those skills to hurt someone? If you teach someone how to shoot a gun, how do you know they won't shoot a person? Of course, causing physical damage is a little different than computer security. How about this: if you teach someone computer programming, how do you know they won't use it to create a virus? The short answer is that you don't.

We have a few courses that involve computer security at PCCC. I know Bergen also has a course that involves computer security. As a matter of fact, ABET (an accrediting board) includes data security and privacy as a "core" topic in Information Technology. In other words, it is a critical piece of any IT program. You can't send entry-level computer professionals out without some sort of background in this area. Even someone who is going to be employed in a career that involves computers (most college students, I would assume) need some background. Often, the weakest link in computer security is not your firewall, or your antivirus, or your VPN software, it is your users. I think we have a responsibility as educators to raise the awareness level of all students.

Wednesday, June 15, 2011

Google Image Stalking

So, Google is introducing a few new features, and as always, the applications can be used for evil.

One of the features aims to allow users to ask questions through their microphone, and have Google search for the words you speak rather than requiring you to type them in. It will recognize your voice and send the words to the search engine.

Another new search is the Google Search By Image. This feature claims that it will let you upload a picture and find information about that picture. For example, if I have a picture of me in front of a building, Google Search By Image would attempt to identify that building. That seems really interesting.

I decided to test it out with some pictures of a trip I took. I went to the Google image search, and downloaded the Firefox extension which allows you to right click on any image in your Web browser and search the Google Search By Image tool for it. However, it doesn't work with Firefox 4.0 yet, so I decided to try it in Google Chrome. I then dragged a few images in to the browser.

I had some pictures of a cruise I took last summer, so I decided to try those.

First, I tried a picture of a lighthouse I saw in Canada. It came up with some pictures that were very similar, but they were the lighthouse in Cape May, NJ.

I decided to try something easier, and I dragged a photo of the Statue of Liberty there. Google Search by Image correctly identified it and returned other images of it and a link to the Wikipedia article.

I tried a picture of a random chunk of the NYC skyline, taken from sea, and that also did not return anything useful.

I tried a picture of a pretty distinctive tour bus from St. John's, Canada, and it wasn't able to match that either.

Verdict on the image locator: weak so far.

Google also claimed it could locate an image that is on the Web. I dragged an image of something I am selling on Craigslist, and it was able to immediately find and display that for me. I dragged another image of something I am selling on eBay, and it was able to find that. Finally, I tried an image I downloaded randomly, and it was able to show me where that image came from. I would say this is a success.

Verdict: This could also be pretty powerful if you are checking to find where an image came from, in case you want to use legally it in a publication, but isn't going to be able to determine where a vacation photo was taken unless it has a pretty obvious or distinctive monument in it.

Google does claim there is no facial recognition that will be available. Color me suspicious.

For a number of years, Google had a free 411 service called Google 411. Many people felt like the reason Google was doing this was to allow testing of their voice-recognition algorithm. All of a sudden, they have Google voice search. I would assume they tested and improved their algorithms in part with their free 411 service.

Now, Google is going to claim there is no facial recognition that is available. However, they will be amassing a powerful database of photographs. The Google privacy statement seems to allow them to keep Web requests, and my interpretation of an image is that it is a Web request.  Given what they did with Google 411, I would suspect that they will save the images you upload for their own testing purposes. Could facial recognition be something they are testing?  Who knows.

I tend to trust Google more than some of the other big name companies, but just because they aren't making facial recognition available to the public, doesn't mean they aren't gathering our uploaded photos to test their software.

I also have some concerns about how, if this technology develops, people might use this to stalk or harass other people. For example, let's say someone uploads a few pictures to their Facebook, or hacks their phone, or steals their digital camera. If someone is trying to hide from someone, those pictures may be searchable and usable. In addition, let's say a criminal finds a digital camera and notices people wearing nice jewelry in it. Could the pictures possibly lead them to a person's residence? As I said before, this does not seem to be at that point yet, but always something to think about.

Monday, June 06, 2011

One in Every 14 programs downloaded is malware?

A few weeks ago, Microsoft blogged about Internet Explorer 9's new "SmartScreen Application Reputation" feature. Microsoft quotes a statistic that 1 in every 14 programs downloaded (on the Microsoft platform) is confirmed to be malware. Of course, statistics can be twisted, so I am not sure what Microsoft defines as "malware". I also assume they are talking about files downloaded through Web browsers, and not files downloaded from the Internet.

From my experience, the riskier the behavior the user engages in, the more likely it is they are going to have a problem. When a friend has a computer crash, it generally has something to do with the activities they engage in on the computer. For example, if people visit shady sites to download videos or music, they risk running in to problems. Making things even riskier (though not affected by this study, I assume) are the file sharing networks.

Even if you have an updated antivirus program, and antispyware, and a firewall, you still risk running in to problems. A virus released today may not end up being blocked by antivirus tools for a few weeks. First, the virus has to come to the antivirus company's attention, and then they must figure what it does and how it does it, and then program a fix, test the fix, and make it available for updates. Then, the user's home machine needs to download the update and apply it.

These viruses are called zero-day viruses, and it isn't unreasonable for it to take weeks for a low-priority virus to get blocked. Further complicating matters is that many home users do not always pay for updates to the antivirus tool. It's generally better to have a free, up-to-date antivirus tool than an outdated commercial one, because new viruses are written all the time. I have in the past personally used the free AVG antivirus, and there is also a free version of avast! antivirus available.

Of course, Linux and Macintosh computers deal with less viruses, not because they can't be written for those operating systems, but because Windows has the largest market share and generally has more inexperienced users. If Macintosh ever became more popular than Windows, hackers would certainly work to find exploits for that operating system too.

So, Microsoft will claim IE9 is safer than Firefox, and Firefox will claim they are safer than IE9. If nothing else, turn a critical eye to both claims. And, if you want to be safe, stop doing risky things. They say the safest sex is abstinence, after all, and the same concept applies to computer activity.


Link to Network World article

Thursday, April 14, 2011

My Bookshelf

I am in the process of doing some updates to my place of residence. As part of it, I ended up cleaning out my bookcase and reminiscing about some of the books I found there. It seemed like a cool idea to mention what's on my bookcase and why.

Google Hacks (2005): This book was a pretty cool book for the time, teaching you how to use many of the Google services more efficiently. This book is how I learned about some of the special Google commands (as basic as using the title command or as in depth as using commands like inurl). It also gave a bunch of Perl scripts you could use to do all sorts of cool stuff, effectively combining a Perl script and Google to give you the power to automatically perform and parse searches. This book doesn't seem to have continued past the third edition (I have the second), but it is a cool read, especially for those of you with knowledge of programming.


Fire in the Valley (2000): This book details the history of the personal computer, going back to the days when people ordered the parts and put them together themselves. The central part of the book details the battle between Apple and Microsoft, made more famous by the movie Pirates of Silicon Valley. I found it fascinating, though a little dry at times.

The Art of Intrusion (2005) / The Art of Deception (2003): Two books by Kevin Mitnick detailing some hacking and social engineering topics. It is fascinating how social engineers can manipulate a person to the point where you are thanking them as they steal your information. These books taught me about things like SQL injection attacks (which we just talked about in my 163 course - see page 175 of the Art of Intrusion). I asked the librarians at both PCCC and BCC to get these books to have on hand, they are definitely worth checking out.

Cryptonomicon (2002): This is a tough read, but it's an excellent fictional novel. It has two main storylines. The first has to deal with a group of people in World War II who have broken the German's secret code (Enigma). This was early cryptography, and it was interesting to see the characters intercept messages but not actually warn troops sometimes, because they also did not want the Germans to know they had broken the code. The second storyline has to do with a group of more contemporary individuals trying to create a secure digital cash system, using cryptographic methods.

And, just to show I have more than computer books on the shelf...

The Butterfly Revolution (1961): I actually had to read this for a freshman class in high school, and my teacher gave me one of the books since I liked it so much. It has to do with a socially awkward teenager who goes to a summer camp, where he ends up involved in a takeover of the camp. Chaos ensues. Picture "Lord of the Flies" in a summer camp.

The Machine (2009): A book about the 1975 Cincinnati Reds. Even as a child, I read a lot of books about baseball. I remember in high school having to write a persuasive essay, and I wrote one arguing that Pete Rose (featured in this book) was innocent of gambling charges. Of course, he later admitted this so I was wrong, but as a fan, I guess I was blinded. So, the book involved one of my favorite players, and had the extra bonus of being authored by my favorite sports blogger, Joe Posnanski. I've been reading his stuff for years, and it was cool to see him go from a small writer for a Kansas City newspaper to someone who writes for Sports Illustrated. Behold, the power of the Internet!

The New New Thing (2000) / Moneyball (2004) / The Blind Side (2008): All these books are written by Michael Lewis. I was first introduced to him through the first book listed, which was about Dr. Jim Clark, founder of Netscape and Silicon Graphics, and how it was fascinating for him to take chances on new technologies and stay at the forefront (and find the new "new thing"). The book detailed a company called Healtheon, which later merged with WebMD. The Blind Side and Moneyball were both excellent sports books which had movies made from them.


The Closing of the American Mind (1988): This book was recommended to me a few years ago by a colleague from PCCC, Dr. Ida Greidanus. The author feels as if modern colleges and universities are failing students, and that America is in a crisis regarding higher education. I think this book made some excellent points which got me thinking about my teaching in a different way.

The Dark Half (1989): The first Stephen King book I ever read.


There are many more books on the bookcase, but I think that's a good enough sample for today!

Saturday, April 02, 2011

Spyware

Spyware is a topic I don't feel like many of my students really see the risk in. I figured I would put up some information about it since I am going to be talking about it in class soon.



Not THAT type of spyware (Image from icanhascheezburger.com)

Spyware isn't the same thing as a virus, and this was a problem at first. Programs started appearing that would monitor what a user was doing and possibly transmit the results elsewhere, and antivirus software programs did not block them, because were not a traditional virus (especially in that they did not replicate/copy themselves to another machine).


Some examples are keyloggers, advertising software ("adware"), and tracking cookies,

Keyloggers keep track of the keystrokes entered on a computer. They can be either hardware or software based. A hardware based keylogger would simply plug in between the keyboard and the system unit. Since most people don't regularly examine their computers, this is a good way to spy on someone. It is generally a little more difficult to detect since the operating system may not even detect it, but it has the drawback that you need physical access to the machine. Software keyloggers are a little safer, but also more likely to be caught by anti-spyware tools. Some of them can record the keys you hit and even email or upload the log file to someone.

Adware keeps track of a user's browsing habits and pops up ads. The adware tends to be a little more aggressive than your standard pop-up ads. Certain adware will attempt to scare you in to buying things like antivirus software. The reason this can be more malicious and dangerous is because once it is installed on your machine, it has more permission to do things (like pop up windows or change system settings) than a regular Web site does.


Tracking cookies also present a threat, though they are less scary than the other things mentioned. These keep track of your viewing habits and store information on your computer. These may be used to, say, display more ads about cars and less about baby clothes if you often click on car ads and never click on baby clothing ads.


The main thing that distinguishes tracking cookies and adware is the way they are used. Adware is usually installed versus the tracking cookies just being left by a Web site.

Either way, you should have some sort of anti-spyware protection on the computer. Most antivirus tools come with some sort of anti-spyware at this point, though if you are looking for extra protection, tools such as Lavasoft Ad-Aware and Spybot Search and Destroy do have free versions.

Thursday, March 10, 2011

No, your operating isn't perfect either

When I was in college, I gave up on Microsoft's operating systems (I got tired of Windows freezing on me) and ran a distribution of Linux called Debian for a few years. For my needs, it worked well, probably even better than a Windows system did. I did a lot of programming, and the Linux operating system was very similar to the Unix (Solaris) operating system that our assignments ran on.

When I teach introductory classes, I have students who have Macintosh computers at home or people running Linux. When we come to computer security, I will generally mention the idea of antiviruses. I generally will have some student say "I don't need one because I am not running Windows". Sometimes, I even get "you can't get a virus on a Mac (or Linux) system".

This is factually incorrect. In security, there are no absolutes. There are viruses, malware, and other programs which end up out there for both operating systems. This doesn't mean the Macintosh and Linux operating systems aren't inherently safer, however.

If I am a hacker, I have to determine my audience (much like a research paper). Who am I hacking? The answer is probably something like "new computer users". Most new computer users are not running Linux, and therefore, if you are writing an exploit, you want to target non-Linux users. Similarly, if you are writing an exploit through the Web, you want to target your biggest audience, and that would be Windows operating system users running the default browser (Internet Explorer). Of course there are other reasons you might target the Windows/IE combination (such as Active-X controls).

The reason this is on my mind...out at the Pwn2Own hacker challenge, some folks from a French penetration testing company hacked a fully patched Mac. They did it using an exploit in the Safari browser.

Link to story

Teams will also compete to create more exploits for a number of different browser/OS/plug-in today and tomorrow.

Saturday, February 26, 2011

Stalking? There's an app for that.

A large part of Facebook's appeal is the ability to add apps to your account. Games (such as Farmville or Vampire Wars), social apps (like Yelp or horoscope apps), self improvement apps (dieting apps, investing tips) and many more can be found on the site, many of which are free.

There are times where Facebook will determine that certain apps violate their terms. For example, in early 2009, Burger King created an app that, if you dumped 10 friends, would give you a free Whopper. Really. Facebook's rationale was that apps are not allowed to tell people if you've dumped them as friends, and this app did.

Facebook just pulled the plug on an app that many contended was a stalking app. Breakup Notifier was an app released recently. The whole purpose of the app was to let you know if someone's Facebook relationship status changed. For example, if someone was listed "in a relationship" and changed their status to "single", you would be alerted.

Many people view this as a stalking app, but in my opinion, if someone puts this information out there publicly, there really isn't anything wrong with it. I could just as easily bookmark a profile and revisit it to see if someone changed their profile status, and I would also be able to see it through my News Feed. This app would just monitor it for you and send you a response via e-mail when that status changed, providing you with real time information.

Facebook has apparently permanently disabled the app, citing some reason or another. Was it the 3.6 million users it amassed in a week (and the strain it added to their servers), was it complaints, or was it something else? I would guess complaints. I am assuming that the same people who post their relationship status publicly are the same people who wrote to Facebook to complain.

Undeterred, the creator of the Breakup Notifier has created another app, Crush Notifier. This works very much like speed dating. Let's say Sally has a crush on Tim. She would mark that she has a crush on him, using this app. Tim would not receive notification of Sally's crush, so Sally does not risk rejection or awkwardness. However, if Tim marks through the app he has a crush on Sally, they would both receive e-mail notifications that they like each other. Crush Notifier even has a business model, where you get two uses for free, and would need to use Facebook credits to receive any further e-mails.

Amazing how social media continues to change society, huh? Well, as Ricky Bobby said, "Does that blow your mind? That just happened!"

Saturday, February 12, 2011

Spy vs. Spy

A few years back, I attended a workshop hosted by NJ Infragard. It's a group that puts on workshops related to security, specifically computer security.

(Amusingly enough, every time I mention Infragard, I get an email from someone telling me how "bad" they are. I also get a comment every time I post anything remotely related to Web design, from someone who hates a stock photo company called Getty Images. Always interesting to see what brings out the commenters and emailers!)

Anyway, that said, one meeting had the key speaker being Kevin Murray, of Murray Associates. His company is one that is part of an industry I didn't even realize exists. His company will come in and sweep your company for wiretaps, listening devices, and the like. It was quite educational for me. He told some crazy stories about how far people go to spy, in politics, and in private industries like pharmaceuticals.

Anyway, the company maintains a blog with tons of news involving espionage, privacy, and security. This site is definitely one I check out from time to time. I enjoy computer security, but I am not actively involved in it on a day-to-day basis. Reading the perspective of someone who is out there in the field is entertaining and educational for me.

Link to Kevin's Security Scrapbook

Tuesday, January 18, 2011

Metadata and You

I first encountered the word metadata back when I started creating Web pages in the mid 1990's. Programs called "search engines", like Webcrawler and Altavista, would automatically find your page and make it available for the world to find. They did have issues adequately describing your page, so as a Web developer adding "meta tags" was critical. It was a way of adding text that did not show up in the Web browser, but allowed search engines to find information about your site.

Metadata is something that is used today in many areas, from computer forensics to corporate espionage. I will give you a regular example first. As a professor, there are times when I think something might be an exact copy of someone else's file. The first thing I will do is take a look at the file properties. In Office 2010, I would go to the File tab and select "Info". On the right side are properties. I can see very easily the name of the person who created the file. In a computer lab, most people probably have the same user name, so that may not tell me anything. However, if you created it at home and gave it to a friend, there is pretty damning evidence since your friend has handed in a file with your name in it. Other ways include "date created" - this tells me the day and time the file was created. I am of course not opening up my whole bag of tricks here, but these are two ways to investigate a file further.

In terms of corporate espionage and hacking...many times, the metadata in programs such as Word (and most of the rest of Office) includes data like username, company name and a file path. If this file was created on a network drive, I now know the name of one of your company's internal servers and possibly your username. This information is valuable for hackers!

If you are distributing a file from Office, also be aware if your company uses tracking changes, revisions, comments, or hidden text, that information can be included in a file you distribute. If a member of a company's staff left a comment in the file, there is a good chance it could be found. You can use the Office 2010 Prepare for Sharing options to minimize this risk, though once again, most people do not realize this.

Even programs like Photoshop can cause metadata issues. Let's say you have an image, and you choose to blur out bits of it. Photoshop will save a thumbnail as part of the file, to make it quicker for the operating system to give users a preview. Therefore, a smart hacker may be able to see your original image using some advanced techniques. Programs such as jStrip will help minimize this risk, but many people don't realize it is a risk.

Like many other technology issues, the only way people know about this generally seems to be if they are burned by it.

Friday, December 17, 2010

Java up, Adobe down

...in terms of exploits, anyway. Looks like Java exploits are gaining favor with hackers again lately, according to this CNN article.

One of the problems with the Internet and specifically the World Wide Web is there are so many moving parts. Many novice users do not seem to realize the complexity of it all. Any application software (including Web browsers) present security risks, and when you add in the various plug-ins (such as Adobe Flash Player, Javascript, Microsoft Silverlight, etc.), you have a hacker's paradise. In the typical interaction, you have three points where security breaches can happen:
1) The browser
2) The plug-in
3) When the browser and plug-in interact

A perfect secure world would have no plug-ins at all, but that is not realistic. We are left as end users to hope the developers of the plug-ins secure their products.

Adobe has come under fire a bit for some of their exploits, but it seems as if they have done a good job (albeit, a reactive job) of plugging up some of their security holes. The report linked above shows that the number of Adobe exploits recorded has gone down, while Java exploits have gone up. Does that mean that Adobe has fixed their problems, or does it mean that Java problems are easier to exploit? That I can not tell you.

Friday, December 03, 2010

Bring out the Dancing Pigs!

"Given a choice between dancing pigs and security, users will pick dancing pigs every time."

Once someone explained that line to me, I loved it. Basically, Bruce Schneier (a US computer security consultant and cryptographer) explained, "If the computer prompts him with a warning screen like: "The applet DANCING PIGS could contain malicious code that might do permanent damage to your computer, steal your life's savings, and impair your ability to have children," he'll click OK without even reading it. Thirty seconds later he won't even remember that the warning screen even existed."

That basically seems to summarize computer security these days. Users often get taken in by phishing schemes, download viruses, give out personal information, and do other things that compromise security...for the promise of dancing pigs. Smart hackers do this and create attractive links that people will click on.

As you can see, there are tutorials taking potential phishers through the process of stealing information. Stopping sites posting information like that is like playing Whac-A-Mole.


Congrats, you shut down a phishing site! Put down the hammer, I don't think others will pop up!

I do not know that most Americans are adequately prepared to figure out what sites are legitimate and which ones are not (and to read warnings). Sadly, people seem to learn by making mistakes and losing their personal information or getting hacked.

Tuesday, November 30, 2010

Proper Hardware Disposal

In one of my classes last week, we discussed the proper way to get rid of old computer hardware, to avoid privacy issues.

I've gotten rid of old computers, but I generally either keep the hard drives (to destroy) or use software to do a thorough wipe of the drive's data When I say "thorough wipe", I am not talking about deleting files, because data can easily be recovered from a hard drive, EVEN AFTER YOU DELETE IT. Really. As a matter of fact, Microsoft's pre-Windows operating system, DOS, used to include an undelete tool which could recover deleted files easily.

eBay is one place people can purchase used hard drives, and they even provide information on why you need to thoroughly wipe a hard drive before you sell it. You can see that the site shows that social security numbers, credit card numbers, and all sorts of stuff can be found on these hard drives. This means your identity can be stolen even if you do nothing wrong, if a company you have purchased from does not follow good procedures for hard drive disposal. Aside from eBay, there are sites like Craigslist where people get rid of old hardware, and there are always garage sales. In the corporate environment, many colleges and companies pay companies to dispose of old hardware (such as eRevival locally). If you go with a cut-rate company, you may find that though they promise to clean hard drives, they may not do so thoroughly. Any of these are ways that data can be leaked if the hard drives are not wiped.

One way you can provide a level of security is to physically destroy the hard drive, though someone could pick it out of the trash and recover something. The best way is to do a full wipe of the hard drive, or what we used to call a "zeroize" at the company I used to work for. We were putting defense systems in military crafts, and one of the requirements was that the pilot needed to have a button to wipe all the data in the system, to prevent classified data from falling in to the enemy's hands. (Yes, that information is public.)

The Department of Defense has pretty high standards for data wiping, and there are a number of tools that meet their standards. The problem is most of these tools cost money. The one that I recommend is a free tool called Darik's Boot and Nuke (available for download at www.dban.org). Despite the informal name, it is a legitimate program (referenced by CNN and the BBC). There are commercial tools that do this sort of thing as well, but the major difference is not function, it is speed (DBAN has a reputation for being slow - the BBC article says it took two hours for an 80GB drive). DBAN is cool because it gives you a CD to boot off of, and you select the depth of the wipe you want. The more depth you want, the longer it will take to run. If you are going to do this, I would recommend choosing the most in-depth wipe, doing it before you go to bed (as a home user) or before you leave work in the evening (at work), and just letting it run overnight. That way, there is no time wasted waiting for wipe to be completed. In a professional environment, having a DBAN CD around is not a bad thing, especially so your company does not end up in violation with the standards that govern your industry (Sarbanes-Oxley, HIPAA, FACTA, etc.).

A larger company may want to invest in faster, packaged software for this, or a hard drive sanitizer (such as this one - though I am certain their claim of 7 minutes per drive is for the simple wipe and not the seven-pass version).

Any of these options are better than the ol' sledgehammer method, because who wants to clean up that mess?

Friday, October 15, 2010

Stalking a criminal

The Internet has obviously changed many things. One thing it has changed is crime. Criminals are known to use sites like Craigslist and eBay to sell stolen goods.

It's interesting how people have also used this in the investigation of crimes. For example, a woman recently had a GPS stolen, and used Craigslist to get in touch with someone who was selling a GPS of the same brand the next day. She contacted the guy, got his email address, used that to find his profile on an online dating site, used that information to find him on Myspace....

The police were able to get video footage from a McDonald's where he used her card, and the Myspace profile matched the face of the person on the video.

It's a lesson that (as she says) you never know who you are robbing.

Link to story

Thursday, September 09, 2010

Zero-Day exploits

I have pretty tight security on my home system. I have my anti-virus, my anti-spyware, and router with built in firewall. I keep my operating system and anti-virus up-to-date. I feel pretty safe on a day-to-day basis. I sometimes forget that this is not true. We are all vulnerable to "zero-day exploits". These are basically newly discovered ways for you to get a virus (or get hacked, etc) even if your virus scanner and operating system are 100% up-to-date. This is the part of computer security that people don't always understand. Anti-virus programs, anti-spyware programs, the operating system, and things like that all get updated AFTER problems happen, so someone needs to be the first group of people to get this virus. Unfortunately, fixes are often reactive (oh, no, we didn't think of that!) rather than proactive (hmm, how would I exploit this system if I were a hacker?).

Yesterday, Adobe (the company that makes Acrobat and Flash, among other tools) released a statement saying there was a vulnerability in even the latest version of Adobe Reader. This is a free tool most people have installed that reads read-only versions of documents. Sounds pretty innocuous, right? Well, there is an exploit that allows this to beat security. If I were to download a file, my firewall, anti-virus, anti-spyware, and operating system would all be beaten by this exploit.

What helps is avoiding high-risk activities online. File sharing networks and torrents obviously present advantages in the form of free stuff, but even if you have all the protection I mentioned before, you are subject to zero-day exploits. This one is an exploit with Adobe Reader, but it could happen in iTunes, or in Windows Media Player, or Internet Explorer, or Firefox, or any other software package. It can also happen when people download software through these networks and actually run a program on their machine. Just remember that despite the updated anti-virus, you are vulnerable. This doesn't even take in to account the folks who have anti-virus software that they don't subscribe to and don't receive updates to.

(For those of you who understand digital signatures, this is a very clever exploit that seems to take advantage of stolen certificates. Who knows, maybe the hackers used a zero-day exploit to steal the certificates!)

Wednesday, August 25, 2010

The Weakest Link: Password Reminders

Security vs. Ease of Use...always is a tradeoff.

I always use an example of a car security system in class. If I could GUARANTEE that no one could steal your car, and it wouldn't be expensive to install, you'd probably go for it, right?

What if I then told you it would take 90 minutes to get in to the car? At that point, the security isn't worth it.

Generally, when you sign up for accounts, you are given very few choices for password hints. For example, what is your mother's maiden name? Or, where were you born?

The problem is that some of these things can be found out from social networking sites or even from personal knowledge. For example, if you friend your mother, everyone who is a friend of yours now knows the answer to that security question, especially if you use the Facebook "related to" option to show she is your mother. Where were you born can be guessed many times as well, even without Facebook. Where I went to high school, I would guess that most of the students were born in the same hospital. In more rural areas, that isn't as tough of a question as you might think. A good private investigator might chat you up in a bar to find out the answer to the question "what was the name of your first pet", if the answer to that question is valuable enough. In divorce cases, this sort of information can be a gold mine. If you are going through a divorce, remember that things like birthdays and anniversaries are things your future ex may know, and they can circumvent your password that way. Even things like "what is your blood type" aren't great, because how many possible choices are there? (A, B, AB, and O, I think). Even questions like "who is your favorite actor/actress" is tough, because answers change.

On the other hand, no one wants the question to be "pick your favorite number between 122 and 488".

Some sites will let you create your own questions, which present their own problems. People may tend to make even easier questions ("what is your middle name"), or really poor questions ("what color shirt are you wearing"). Yes, I've seen questions like this when helping people.

One of the better questions I have seen is "what is your father's middle name". I couldn't tell you the middle name of my friend's fathers, so this would require a little more work. Other good questions might be "what was the first bone you ever broke" - certainly something you would remember, but still vague.

Another clever idea that hasn't taken off is "Passfaces", where people use visual reminders as a password. Clever idea either as a replacement for a password or as something to augment password reminder security, but not mainsteam yet.

The best defense is to pair sets of questions together, asking people to answer multiple questions to get access. Another way would be to give people a checklist, for example, ask "which of the following statements are true about you", give a list of 15 things, and have the person check off which they have done. For example, give statements like:
I have shoplifted something worth more than $10.
I have been to Cincinnati.
My first car was white, yellow, brown, or green.

Have the person check off yes or no for each, and they are only granted access if all 15 questions are correct. Even if someone tries to guess their way through that, that is hundreds of possible responses. The problem here is that the best questions are the deeply personal ones that no one else knows the answer to. These are also the questions people might be shy about answering honestly. For example, the "shoplifted" question is good, but would I really check off "Yes" if this were a password reminder for a company I work for?

Or, you can do what I do, and give fake answers to the questions in a way that you will still remember it. Or, just use your mother's maiden name everywhere and wonder how all your accounts got hacked on the same day.

Sunday, June 13, 2010

Times Square Bomber and Computer Forensics

Most people think just because it is a free email address with no billing address, they are safe, but there are many ways they can be tracked.  Take for example the suspect in the Times Square bombing.  Technology helped lead to his arrest.   The car that was used was apparently purchased in cash after an ad on Craigslist. The guy was apparently somewhat clever in covering his tracks, according to reports. He switched license plates at a place where it was unlikely to be noticed (a garage - when was the last time you checked to see if your license plates are really yours anyway?).  He also attempted to remove the vehicle identification number.  Unfortunately, it is found in a number of places in most vehicles, and the suspect missed a few locations.

So, how did Craigslist play a role? The seller apparently got an email from the buyer, who paid in cash. With that email, authorities can determine what IP address that email was sent from.  With that IP address, it's an easy matter to determine who the Internet Service Provider of the sender was, and you can subpoena that ISP to get the name of the customer.

If that was a dead end, they could also trace the email address.  Let's say the guy signed up for a free Hotmail account.  He signed up from some computer somewhere, so law enforcement could subpoena Hotmail to find out what computers accessed that email account, and follow the trail as mentioned above.

Now, this guy was either sloppy or just did not think they would catch up to him quick enough for things to matter, because there were a number of ways he could have obscured his identity better.

First of all, he should have created this email address from a public computer, and only accessed it from a public computer.  Either that, or he should have "borrowed" someone's wireless Internet connection, because then the trail would lead back to them.  He could have driven around and found one easily (and this is part of the reason not setting up security on your wireless Internet can be a very bad thing).

Secondly, he should have made sure there were no cameras that could help aid in his identification, regardless of the method.  A nice, unsecured location could be helpful, and scouting is important.

Thirdly, he should have made sure to pay in cash (if this were a cybercafe), use a fake ID (in a library), or used a program to try to hide his computer's network card address (if he used someone else's Internet connection).  Each network card manufactured has a unique identifier, so if he connected to my router, I could browse my logs and find out the network card address (known as a MAC address).  Law enforcement could subpoena the manufacturer to get the name of the buyer.  If he was smart, he would have paid cash for a cheap network card (and bypassed the built-in wireless found in most laptops) and used a throwaway one.  Again, if it was purchased recently, store cameras could be used to track suspects.

Finally, he should have used some program to anonymize his Internet usage and/or mask his IP address.

I do not know the specifics of what he did or did not do right, but electronic communication is not difficult to track with a little technical knowledge and the power of a court order.

Link to Story

Tuesday, May 18, 2010

Cyber Crooks and Disasters

As always, criminals are clever. 

When disasters or other newsworthy events happen, they rush to get information out there.  The goal is to get people to visit their sites, and if they can be the first results on Google after an incident, they can often infect people before Google has a chance to filter out the results.

For example, when the recent Icelandic volcano eruption happened, the scammers were smart enough to realize people were not going to search for the actual name of the volcano (Eyjafjall), because who is going to remember that spelling?  Instead, they had results up quickly for the search terms people would likely use - things like Icelandic volcano eruption.  By getting their results on to Google quickly, they had the chance to infect people's PCs.

Interestingly enough, newspapers want to be the first people to report news to gain prestige.  They are now competing with hackers.

http://pandalabs.pandasecurity.com/volcanos-ashes-and-malware/

Monday, April 12, 2010

Hacking Facial Recognition Software

One thing that I see often in TV is facial recognition software.  For example, in the current season of "24", Chloe O'Brien is able to very easily figure out who someone in based on the digital image of their face.  The way these software programs work is similar (though not as advanced as in "24").  They take a facial image and scan it to determine what the features of the person are, and then compare that to a database of people's characteristics.

Of course, the easy way to beat this would be to wear a ski mask or something, but it would be way too obvious if you were walking around in public with one on.  I often wondered if some sort of plastic surgery would make you harder or impossible to detect, and that certainly is an option.

However, a computer programmer was able to reverse engineer this software to find ways to beat it, in theory by using makeup patterns.  He had three sets of images.  The first set were basic images with no makeup, the second set was images with random patterns, and the third set were images that exploited what he considered potential weaknesses in the facial recognition software.  His conclusions?  The patterns he created all fooled the system, while the random patterns and the blank patterns did not fool the system.

His conclusion?  The images represent potential anti-surveillance makeup.

Now, if someone was walking around with the makeup you see in the images, it might look weird still...but the potential is there.  If someone can wear a weird makeup pattern and throw off these systems - well, these systems need to be more mature and figure these things out.  I am sure the companies will say "well, no one is going to walk around with that makeup" publicly, while privately scrambling to find a fix.

Needless to say, if a graduate student came up with an idea like this...imagine what terrorists who do not want to be found will come up with.


http://ahprojects.com/c/itp/thesis

Saturday, December 26, 2009

CNN Tech: The Top 10 Technology Fails of 2009

It has been an interesting year for technology failures, and part of the reason (I believe, anyway) is that technology is now considered important enough to get the media coverage to make it news.  Five years ago, it was not something that was noticed, and now it is.

It's always interesting for me to go back and see what sort of things happened this year, and see what sort of stories were big.  For example, you may have heard a lot of hype about a virus called Conficker (around April Fool's Day 2009).  This was supposed to be a big virus, but no major destruction and doom ever materialized.

Also, who can forget the Sidekick crash in October, where many users lost personal data - ALL of it.  Some users were able to recover it, but many were not.  This was one of those things that I don't understand.  This is why backups are so important, and I don't see how companies lose data these days.

Anyway, here's the article from CNN:
Link to Article

Sunday, December 20, 2009

Facebook group hacking

I always love it when the words "hacking" and "protest" show up in the same article.

Recently, people on Facebook were annoyed with a feature of the Facebook "groups".  Basically, this feature said that if someone who had created a group left it, and there was no longer an administrator, ANYONE in the group could take the group over.  You can see why this was put in place - you wouldn't want someone to abandon a group and have it just disappear, after all.  However, you can also see the potential problem.  Anyone can take over a group!

In protest, a group of people "hijacked" administrator privileges in around 300 groups in November, just to show that Facebook has a major issue with security.

Link to article