Showing posts with label Apple. Show all posts
Showing posts with label Apple. Show all posts

Tuesday, February 23, 2016

Hospital Held Hostage, FBiOS and CEO Phishing

   I usually don't do "news of the week" commentary posts, but too much has happened this past week and we need to discuss it!

Hospital Held Hostage.

   I'm sure by now you've seen some info on what happened at Hollywood Presbyterian Medical Center in California.  Just in case you were on a desert island... on Feb. 5 HPMC experienced a cryptoware attack.  We've talked about those before... it's malicious software that encrypts files so that only the attacker can read them... the people who need to can't.  The story broke about 10 days later.

   Cryptoware becomes ransomware when the attackers offer to fix the problem - decrypt the files - for a "small consulting fee", usually not small and paid in bitcoin, an untraceable online currency.

   The situation itself is, unfortunately, not unique.  These kinds of attacks have been happening everywhere for years.  But there are two things that happened in this case that are unique.  First, the cryptoware completely shut down all the computerized systems in the hospital.  That means no electronic medical records, radiology, anesthesiology... just about any -ology and most hospital functions are computerized.  The hospital reverted to paper and had to turn away surgery patients or those needing more complex diagnosis, tests or procedures.  

   Second, the hospital paid the ransom.  This is the first publicized case of both a hospital shut down in this way and paying the ransom to restore their files.

   Most hospitals have procedures, called "down time procedures" for operating without some computerized resources.  And there is an incident handling process called HICS - Hospital Incident Command System - based on US FEMA (Federal Emergency Management Agency) NIMS (National Incident Management System).  But there are still medical procedures that can't be done with out access to the electronic data or computer-controlled systems.

   This attack is not OK.  Stealing people's data is bad enough.  But this affects lives.

FAQ:
   Can this happen here (wherever "here" is)?  It can, it has, it does and it will.  All industries and even home systems have been hit.  It's not "if", but "when".

   Can't we prevent it?  Yes!

   Wait.  What?  There's more to that story.  An attack like this can be prevented, but systems would have to be locked down so tight that they might not be usable.  And that's not a solution.  But there are some proactive things that can be done:
  • Don't click!  Most of these kinds of attacks start with the click of a link on a website or in an email, or opening an email attachment.  We've discussed this many times before... if you're not expecting it, if it doesn't look right, if it's not consistent... don't click!
  • Endpoint controls.  These are controls on your desktop or laptop computer including old-school anti-virus, application whitelisting, and execution controls; operational procedures like having a standard workstation configuration and regular patching.
  • Network/System controls.  Like monitoring and keeping all applications up to date with the latest versions and patches, and reliable and tested offline backups.
  • Internet controls.  Like web site filtering and email controls.
   So why did they pay?  Isn't that bad?  In some cases, if the cryptoware infection gets so bad that the organization cannot recover, there may be no other choice then to pay.  And even that's no guarantee that the attackers will or can give you the key to decrypt the files.  In some attacks, if the victim doesn't pay in time, the key is deleted and the files could be unrecoverable.  It's obviously better not to pay (or not to have to pay!), but the organization might not have a choice.

   CSI:Cyber did an episode on a hospital malware attack in Nov. 2015.  I wrote about that here.

   Just a quick commentary on the other two issues.

CEO Phishing.

   Or perhaps more correctly... phishing from your CEO!  In this phishing attack variant, an email comes from "the CEO" (or other highly placed official) demanding some kind of immediate action, typically involving wiring money.  All too often, the recipient does what they're told and sends the funds.

   Recent issues in the US and in France have kept this in the news.  Now Microsoft is getting in on the act, trying to make improvements to Outlook to help with this problem.

   As we've discussed in the past, if something on a web page or email doesn't look right, it probably isn't.  Don't click; Report it!  And even if you did click, report it!

FBiOS.

   After the San Bernadino, California terrorist shooting last December, Federal authorities captured one of the attacker's cell phone.  It is an Apple 5C.  Because of the way Apple encrypts its phones, law enforcement has been unable to view the contents of the phone.

   This week a federal judge ordered Apple to help unlock the phone.  The order is based upon the 1789 law called the All Writs Act.  Apple has chosen not to comply and that has led to plenty of discussion on both sides of the issue.  Apple says helping would set a bad precedent and weaken their phones' protections.  The FBI says it's Apple's duty to help with this criminal investigation.

   As is so often the case, there is no perfect answer.

   As Benjamin Franklin famously did not say, "Those who give up liberty for security deserve neither".  The reality for encryption is, if we make technology that law enforcement can crack, then anyone can crack it.  This is true because of the law no one can break - the law of mathematics!

   However, the Apple 5C uses an older encryption method than their newer phone.  So in this case, Apple could help without compromising everyone else's security and privacy.

   There's some great in-depth discussion of this issue on the TWIT podcast this week.

   Here are some good articles with more details.  We'll watch to see how this plays out.

Tuesday, March 10, 2015

Chip & Pin & a Tin Foil Wallet

   I've been talking a lot about ID Fraud lately and was recently asked this question:
"A question came up at home – and that is about use of credit card wallets that protect from rogue scanners. Are they necessary? Will they be more or less necessary when newer cards with embedded microchips are more prevalent?

I thought this might be an interesting topic for your blog."
   Thanks for the great question and idea to put this in a blog post!

   So, by credit card wallet I’m assuming that you mean some kind faraday cage or lead lined case that blocks electronic signals, as opposed to a credit card wallet like Google Wallet, Apple Pay or SoftCard.

   When it comes to old-school mag stripe cards… have you noticed how you sometimes have to reinsert or re-swipe the card in the reader, and even then it doesn’t always read?  Mag stripe is definitely a direct-physical-contact medium.  Other than vendor breaches or stolen (physical) wallets, the typical way someone can steal your mag-stripe card data is via some kind of skimmer.  There are very low profile skimmers that can be inserted into ATMs or gas pumps to grab your card data while you’re trying to do a legit transaction.  There are also hand-held or desktop units that an “evil waiter” can use to grab your card data when they take your card at a restaurant.  There are no reliable remote ways to read magnetic data off a card.  So, a lead wallet won’t help here at all.  It’s the same way you can’t read the contents of a hard drive just by being near it.

   Next is RFIDs.  That stands for Radio Frequency IDentification and, as the name implies, they do transmit data.  These are the chips in the tap & pay cards.  There are transmission-blocking wallets for RFID passports and things like that which transmit data.  So anything with RFID or a transmitter can be remotely read (at various distances).

   The new cards coming out will be chip & "something".  Currently in Europe they use chip & pin.  This is expensive to implement and requires replacing all the mag stripe readers with much costlier readers.  The chip is a microchip that computes a value and provides a 1-time-use code for a transaction.  Note that it does not use your credit card number.  In addition to that single use code, the person also needs to put in their numerical PIN.  So, even if the card was stolen, or the code could be remotely read, it couldn’t be used for a transaction without the PIN, and the code couldn't be reused.

   The US is actually considering chip & signature.  Among the reasons is that the cost will be lower even though the readers still need to be replaced.  (though, because of the marketing power of Apple and Apple Pay, many merchants have already upgraded readers).  The chip works the same way, but the 2nd part of the verification is the physical signature.  Not particularly strong but better than nothing.

   Now… neither of these new card types solves a particularly important case… Card Not Present.  This is when you buy something over the phone or internet.  So there’s no card reader nor person to look at your signature, and you don’t want to give some random merchant your PIN.

   There are a number of potential solutions in the works.  Verified-By-VISA or MasterCard SecureCode are examples of tools available now, even for mag stripe cards.  Basically, you choose one of these at online checkout; then you’re transferred to the VISA or MasterCard site; you authenticate there; the VISA or MasterCard site generates an acceptance code that get sent back to the merchant and you’re all set.

   So, chip & signature cards and readers will help deal with some of the credit card fraud we have, but we still need a standardized solution for Card Not Present (CNP).

   Now with that background, back to your initial question… remote reading of a magnetic stripe, chip & PIN or chip & signature card is not a major threat.  However, cards that use RFID, or any tap and pay technology, could be read remotely.

   You'd be far better off taking the precautions I listed in my previous ID Fraud articles including:

  • regularly viewing your credit report
  • watching your bills
  • shredding unneeded documents that have personal info
  • carrying only the minimum cards you need
  • using care online

   Thanks again for the great question!  If anyone has questions or ideas for things I should write about in the future, please let me know.