Last week I avoided talking about Prism, the supposed NSA wiretapping issue that has been all over the news.
However, in the past week I've read or heard 3 different highly insightful analyses and I'd like to comment on them.
First, on the possible techniques used. Major data collection organizations including Facebook and Google have denied providing any information to the US Feds as has been alleged. But the NSA is getting information.
A place to talk about information security, Internet safety and, of course... coffee!
Thoughtful, sometimes controversial, but not following the crowd unless I'm in line at the coffee shop.
Tuesday, June 18, 2013
Tuesday, June 11, 2013
Light and Sound - the next mobile malware vector?
With all the talk about Prism in the security news, we didn't hear about much else.
But here's an interesting story... Researchers at University of Alabama, Birmingham verified that malware, or other actions, can be triggered on a mobile device by sounds, music or light!
From the article:
"In one instance, the researchers used music in a crowded hallway to launch an attack on an off-the-shelf Android phone. In others, the malicious code was activated by a song with a particular pattern or the ambient light from a TV, computer monitor or overhead light bulb."
For most of their experiments, the source of the sound or light needed be very close to the target device.
Right now this is only experimental. However, we know that well over 50% of mobile phone users in the US have smartphones. And these phones have input sensors for light, sound and motion. Essentially, we are all carrying devices that not only track our location and movements, but can record, and be influenced by, the environment around us.
It will be interesting to track this research and see the ongoing new ways in which these ubiquitous devices can be exploited.
But here's an interesting story... Researchers at University of Alabama, Birmingham verified that malware, or other actions, can be triggered on a mobile device by sounds, music or light!
From the article:
"In one instance, the researchers used music in a crowded hallway to launch an attack on an off-the-shelf Android phone. In others, the malicious code was activated by a song with a particular pattern or the ambient light from a TV, computer monitor or overhead light bulb."
For most of their experiments, the source of the sound or light needed be very close to the target device.
Right now this is only experimental. However, we know that well over 50% of mobile phone users in the US have smartphones. And these phones have input sensors for light, sound and motion. Essentially, we are all carrying devices that not only track our location and movements, but can record, and be influenced by, the environment around us.
It will be interesting to track this research and see the ongoing new ways in which these ubiquitous devices can be exploited.
Tuesday, June 4, 2013
How crackers ransack passwords - Sort of...
I am not trying to make this the password rant blog. But we just can't go a full week without more news about password problems!
Last week the excellent tech new site, Ars Technica, did a feature article in which they had first a journalist, then three different password hacking experts, try to decrypt passwords from an encrypted password file. They were all quite successful... frighteningly so.
Steve Gibson discussed this for a bit in Security Now episode 406.
But, I think there were some critical flaws in the test. And there were also some excellent lessons.
I'll comment on the article using the sandwich method, starting with what was good...
Last week the excellent tech new site, Ars Technica, did a feature article in which they had first a journalist, then three different password hacking experts, try to decrypt passwords from an encrypted password file. They were all quite successful... frighteningly so.
Steve Gibson discussed this for a bit in Security Now episode 406.
But, I think there were some critical flaws in the test. And there were also some excellent lessons.
I'll comment on the article using the sandwich method, starting with what was good...
Tuesday, May 28, 2013
Twitter 1-and-a-half Factor Authentication
As you may have read, and hopefully enabled, Twitter added a 2-factor authentication capability last week.
If you haven't yet turned this on, here's how. Log in to Twitter; select Settings; select Mobile; add and activate your phone. Here are the detailed instructions for adding your phone number. To enable 2-factor authentication, select Account, then check the box labeled: Account security
Here's the good news... as I've discussed in the past, I am a fan of using some kind of 2-factor auth for website authentication. I also like the use of a smartphone for delivering that one-time-use PIN or code. While we still have a digital divide in the US, most people do have a cell phone, and most of those have a smartphone.
But there are some issues.
If you haven't yet turned this on, here's how. Log in to Twitter; select Settings; select Mobile; add and activate your phone. Here are the detailed instructions for adding your phone number. To enable 2-factor authentication, select Account, then check the box labeled: Account security
Here's the good news... as I've discussed in the past, I am a fan of using some kind of 2-factor auth for website authentication. I also like the use of a smartphone for delivering that one-time-use PIN or code. While we still have a digital divide in the US, most people do have a cell phone, and most of those have a smartphone.
But there are some issues.
Tuesday, May 21, 2013
The Business (not Blind) Side
A Doctor, Lawyer, Salesperson and Systems Adminstrator walk into a bar...
As I mentioned last week, the Secure360 conference was in town. And as always, it was a great show. I was pretty busy and had 3 different talks. The first was a 4 hour pre-conference session on BYOD. (slides here)
After talking about the history of portable devices and framing the issues with which organizations struggle, we did something a bit different.
As I mentioned last week, the Secure360 conference was in town. And as always, it was a great show. I was pretty busy and had 3 different talks. The first was a 4 hour pre-conference session on BYOD. (slides here)
After talking about the history of portable devices and framing the issues with which organizations struggle, we did something a bit different.
Labels:
business,
BYOD,
conference,
consumer,
customer,
devices,
IT,
portable,
security,
technology
Tuesday, May 14, 2013
One Size Does Not Fit All
The annual Secure360 conference kicked off yesterday in St. Paul with pre-conference sessions. Secure360 is the major upper Midwest security conference and has become a US national event, now in its 11th year (I think!).
I'll be pretty busy at this year's conference. I've actually spoken at every Secure360, but this year I did a half-day seminar yesterday on BYOD, and tomorrow I've got back-to-back talks - one on the Insider Threat I call "The Accidental Insider" (blog post), and one on authentication "3 Factors of Fail" (blog series starts here). Slides for all are on my slideshare site.
I've got a wide variety of topics to cover!
And that's what is so cool, and critical, about conferences.
Tuesday, May 7, 2013
So Long and Thanks for All the Passwords!
If you've been following any online news lately you read about the recent Living Social breach. They reported "unauthorized access" of their systems resulting in a download of customer data including name, email address and encrypted passwords.We have heard of many similar instances over the past few years. I've written about this in previous posts and will be giving a talk at Secure360 in St. Paul, MN in a couple of weeks talking about authentication and passwords.
In their defense, Living Social did do a couple of things well. First of all, fortunately, they did store only encrypted passwords. Unfortunately many organizations don't. Unfortunately they used an older, weaker encryption algorithm. And, of course, unfortunately they got breached and had the file downloaded.
Subscribe to:
Posts (Atom)

