Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, April 19, 2013

Plane hacking or not?


Article about the security presentation 
http://www.net-security.org/secworld.php?id=14733

The denial from the Aviation Authorities
http://www.net-security.org/secworld.php?id=14749

Well meaning clarification from pilot
http://www.askthepilot.com/hijacking-via-android/


This is both a fascinating research paper and a social comedy.

The researcher has demonstrated an interesting exploit against aircraft.  Ok, yet another insecure system. Interesting but only comment worthy for the novelty of the target.

The clearly bullshit ridden  denial from the Aviation Authorities is a nice attempt to damp down the expected alarmist crap from the usual suspects in the media.  However, the denial smells exactly like a denial.  There is really nothing that the FAA etc could say that would be beleived either by the ignorant masses, the ignorant media or technical experts. But its nice that they cared enough to make a statement. 

Finally, the well meaning clarification by the pilot.  Hmmm what can we say here?  Apart from pointing out how well meaning he is.  To put it simply, the guy is an egotistical fucking imbecile.  The whole point of hacking is to take command of a system.  This guy has not understood that pilots are part of a system.  He is arrogant enough to think that pilots are some how "above" it all.  They are uncorruptable, omnipotent and benevolent.  And like all generalisations... this one too is crap.

The evidence is easy to find. Start watching "Air Crash Investigators" or any similar program.  Pilots are human just like everyone else.  Air crews make catastrophic mistakes every day.  Sometimes they survive and sometimes they dont.  The point is that they respond with training and skill, under pressures, time limits and equipment limits.  They trust all sorts of automated systems, instruments and processes.  The point that this research has shown is that some of these automated systems may no longer be as trustworthy as the suppliers and the FAA would want the traveling public to think.

The fact that any system is hackable (read corruptable) is always simply a matter of time and resources.  Every system has weaknesses.  Most people do not have the resources to corrupt the systems around them.  Most of the time the users of those systems "trust" them.  However, the more these systems are revealed as being potentially untrustworthy, the more people are forced to consider what the systems tell them, to pay attention to inconsistencies and be aware of the big picture.  In the case of pilots, it will hopefully make them a little more aware of where the manual controls and old school instruments are located.  It may make them a little more dilligent in keeping their hand-fly skills polished.

Trust in automated systems should have limits.  Robots are only going to take over the world when we let them.  Once humans are totally redundant and a completely automated system that everyone trusts is availible, the human will be fired.  Look at the manufacturing industry.  Look at any industry where data processing has replaced people.  Once we take humans out of the loop and trust the machines there will be a much longer unemployment line.

Its disturbing to see just how many people are no longer needed to keep many large organisations opperating.  Look at all the industries that are down-sizing across the US.  White collar workers are the current ones who are being made redundant simply because knowledge can be managed by software robots. 

Showing this kind of exploit will sharpen a couple of pilots up and perhaps make them a little more paranoid for a while.  It will force the FAA etc to consider the possibility that there are exploitable systems on planes... but the other side of the arms race, the component manufacturers will work hard to rebuild that trust and show that their systems are bullet proof. Eventually everyone will trust them enough to take the humans out of the loop and planes will be completely flown by automated system.  I am suprised that commercial drones have not been trialed yet.  Certainly for freight but I expect eventually for passengers.  The final step will be fully automatic (with a remote manual override for a while).  But human trust will take the humans out of the loop eventually.

Monday, November 12, 2012

Paranoia on the Security Frontier


Just read this article on the issues the American's brains trust are having with suppliers of major network infrastructure components.  The point of view expressed and the stunning hubris... is just so... sad. Basically the article says that the US gov is paranoid about the Chinese gov being able to pop some malware on some backbone switches at some point in the future.... maybe...

Firstly, this article is yet more China bashing.  Although to be fair there is a little bit of acknowledgment that there are other players in the game but none are named or particularly have the finger pointed at...

Secondly,  the fact that American manufacturers are simply assumed to be free of any government influence is just a tad ideologically blind.  Everyone outside the US is paranoid about the US spy services and what they might be inserting into the Internet infrastructure... but that goes without comment.  LOL. 

The silliest bit of all this is the naive assumption that the US spy services are somehow automagically on the side of the average US citizen... hmmmm?? Said who? Is there any evidence to support that point of absolute belief? Hmmm... could be some evidence for both sides of that argument.

Anyway,  as a third party country who gets to buy from both suppliers... we're just a little bit paranoid about both of them. As mentioned in the article.  At the end of the day... there's nothing for it except to do some independant verification of all significant network infrastructure and design networks to be able to identify and withstand the effect of compromised equipment. 

In any case, its often not the designed in back doors that prove the biggest problem, its the exploits that appear from independ players and the side effects of poor network planning that have the biggest problems.  The other problem with backdoors is that you never know who else knows about them.  Since you can bet that the US spy guys will have purchased a couple of these routers and they do have the resources to take them apart and find any useful compromises... that any backdoor that is inplace or could be inserted via patches is able to be compromised by US players just as easily.  Also by every other 3 letter agency in the world... it would then be a fairly simple activity to block each other from using the backdoors while still being able to use them themselves... unless they wanted to let the others think that they did not know about it but still wanted to be able to block them...


I'm sure that in the minds of the politicians it's all scary to think that someone else can reach out and switch off your backbone routers or do bad things with them... but a simple firewall and some physical seperation should prevent that kind of scenario.  Getting some kind of command and control interface to a backbone router should be incredibly difficult via the actual feed line.  They should be controlled via a complely different internal network that is not carried on the public feed.  This provides both physical and logical security. 

This would prevent them being compromised by either some "foreign government types" or by criminal, hacktivists, rogue spy types or other trouble makers.  But like always, it does not prevent them being compromised by the staff of the backbone provider.  As always, people are the weakest link... not the machines. All a spy agency needs to do is compromise one employee and the whole system fails.... but then again, thats what spy agencies have been doing since year 1.

Must be nice to live in a world where all you need to be afraid of is some malware built into a backbone router.  Do you think the US and Chinese spy kids are trying to rev up yet another cold war to keep their budgets?  Most of us are actually worried about non-state players taking down the networks rather than state backed players.  They have much more interest in taping the flow of information than simply trashing the place. 

There are just so many old-school points of view that underpin this whole debate that are no longer relevant.  I have no doubt that every spy agency in the world wants to pwn every backbone switch they can.  They all want unfetted access to every data centre in the world and everyones email, game sessions, chat boards, porn habits, online bank accounts, bot nets..blah blah blah... but the point is that this is a massive fire-hose of data that is simply a monster to try to do anything comprehensive with.  Very few of them have the sort of infrastructure to store, process or make sense of this in a wholistic way, so mostly they will continue to just dip their toes in while they play paranoia games.  The second one or the other gets enough capacity to be able to control a substantial slice of all this action, the whole concept of cyberwar will be declared "won".  Cause just having the ability to "switch off" someone else's network can be implemented much more cheaply than putting some bad malware in everyone elses routers.  This is why the spy agencies still exist and are still able to out-muscle all the small outfists like the hacktivists and criminals, is because they can still mobalise a set of trained and motivated people on the ground to go and "act" upon a foreign govenments network infrastructure if they so wished. All the wanna-be organisations simply do not have the resources to reach out and touch someone in a systematic way.  Just to make it even more difficult, all the backbone providers spend every day attempting to armour and fortifiy their infrastructure against everything the hacker/criminal/vandal set can think of to stuff things up.  Think of this as crowdsourced penetration testing.  The idea that some backdoor could exist that would be exploitable by a foreign government that could withstand this kind of probing is possible... but not probable.

It reads like some sort of bad plot from a really cheesy cold-war thriller... as I ranted somewhere above... its just a bit sad.

 





Thursday, September 6, 2012

How to avoid malware (abit...)

I was asked how to get an offline copy of a video from a popular online video site. 

The solutions that used to work no longer do as the sites are using multiple flash wrappers to try to obfuscate the video stream and prevent all the usual tricks from working. 

I had a troll of some of the online services that used to do the trick using some fairly straighforward javascript. They used to be ad-supported.  Now they have much fewer ad's and they all require Java for their functionality.... hello?

Could there be a correllation with the number of exploits recently found in Java?  Could it be possible?

Anyway, since I did not have time to fiddle... the solution is to create a clean vritual machine using your favorite VM base OS.  (Something XP or Ubuntu should do the trick) make sure you enable Undo disks. Create a shared folder for passing back and forth to the VM.

Then boot up the VM, pass your YouTube links to the VM via a shared folder in a text file. 

Inside the VM, open a browser, go to your favorite video file scamming website and download the files to the shared folder. (Install Java if required)

Shut down the VM and do not commit the changes to the VM. 

Tada.  Ofline copy saved, Malware deleted, problem solved. 

Now explain that to your grandma....

Hmmm strategy...



http://www.technologyreview.com/news/428649/hey-hackers-defense-is-sexy-too/




The title of the above post caught my fancy.  The content is pretty small but the idea is funny.

This is just stupid.  Its the most poorly thought out marketing attempt... well not "ever"... but its still pretty weak.

Attack is always easy.  Defense is always hard.  But now it's sexy....lol. That should convert the masses.

Attacking a stationary/static target is simply a matter of trial and error.  Success is a factor of time, effort and a bit of cunning. Hence its popularity with "security researchers". 

Defending a stationary target is an exercise in "preventing the unknown".  You have no capacity to prevent whats going to happen if its a simple attack-defend scenario, unless you can brute force "prevent" the attackers vector from functioning.  But to do this you either need to know what the vectors are before hand, prevent all possible vectors or ..."other".
The first is essentially the "attack" strategy just going in the opposite direction.  (See all current signature based mechanims)
The second is theoretically impossible but heuristics offer partial solutions. (Mechanisms such as DEP, Mutable loading, calling etc, behaviour monitoring mechanisms, white lists)
The third is.... "unknown".

But now its sexy!

Its also going to be damn hard to "show" in the way exploits have traditionally been demonstrated at the various conrferences.  An exploit either works or fails.  Defending against an unknown and possibly non-existant attack is ... harder to demonstrate.

"Evidence of  defence against non-existant threat may have been successfully demonstrated... audience baffled and bored!"

At least if you find an exploit and then demonstrate a fix, people "get it".  Doing this for broad classes of attack strategies may be harder, simply becasue doing so just moves the goalposts for the attackers. It does not eliminate goalposts, although it may in the mind of the purchaser.

I think being under a state of constant attack, forces people to adopt a conservative approch to their computing activities.  Purchasing a "solution" simply promotes a false sense of security. 

But I ramble...




Wednesday, June 13, 2012

Linkedin Cracking strategies

https://community.qualys.com/blogs/securitylabs/2012/06/08/lessons-learned-from-cracking-2-million-linkedin-passwords

This article contains some interesting hints about discovering rules using iterative search techniques. Reading it spured some ideas about discovering social and group rules tha tcould be useful for heuristic based systems.

Friday, June 1, 2012

Kicking Sand out of the box....Shiny.

http://arstechnica.com/security/2012/05/anatomy-of-a-hack-6-separate-bugs-needed-to-bring-down-google-browser/?comments=1#comments-bar

This is a nice overview of a successful prize from Google for breaking the sandbox on Chrome.  Very nice work, especially the illustration.

Monday, November 7, 2011

Adware strategies

http://philosecurity.org/2009/01/12/interview-with-an-adware-author

There are some ethical issues here, strategy information and some interesting comments.  Your opinion of the subject of the post may range from repulsion to disgust to acceptance.  My firstly thought is... realist meets ambiguous opportunity...

Wednesday, September 28, 2011

Data Recovery Event...

http://www.datarecovery.com.au/html/Contact.html

Service I'm using in anger.  Bad things happen to people who don't back up... and get distracted by work and stuff....

Yah Fear me. I am geek and know all... who am I kidding? Current generation hard drives are way beyond my capability to recover.... I bow to the professionals and suck up the cost as a learning experience. Long story... don't ask.

Good security blog

http://krebsonsecurity.com/

Having read posts on this security blog accidentally for a few years, I'm really enjoying the quality of the writing and work. Good depth, fairly thought and some interesting lateral investigation. This is what journalism used to be. 

Contrast that with the embarrassing episode of "Insight" that Jenny Brokey hosted the night before last on SBS on the topic of Hacktivism.  It was the usual arguments about semantics, generalisations and conflicts of values.  Mix in a bit of inarticulate rambling and you get.... rubbish. Some of the guests were just childish. 

Personal Data Stores

Found an interesting list of projects in the personal data store/identity space.

http://owncloud.org/

http://unhosted.org/

http://lockerproject.org/


http://projectdanube.org/
Lots of good ideas here. Well written docs.

https://joindiaspora.com/
This one looks a little raw at the moment but the idea is good.

http://personaldataecosystem.org/
Kind of overview organisation. In a decentralized, disorganized ecosystem...

http://www.idcommons.net/
Interesting group....

http://cyber.law.harvard.edu/research/projectvrm
Project VRM.  Another interesting idea....


Thursday, May 26, 2011

Fun with Botnets

http://www.abuse.ch/?p=3294


This is an analysis on botnet size captured using a technique called sinkholeing. Looks like an effective method for trashing botnets if it was used effectively.   The article also points out the obvious that the botnets and the malware are no longer that important.  Its other links in the value chain that are more critical to extracting usable value from the exercise.  Essentially a botnet is just illegal infrastructure for a business.  Anything like this needs a whole ecosystem around it to form an economic activity.

I would expect that at some point, some of the botnet systems will ( as suggested in the comments on the article) turn into a cloud service and at some future point, they will start to turn legit by paying the drone computers and selling the service to the highest bidder.  This legitimise the botnet part of the system and push the criminal/illegal parts to a smaller section of the value chain. Eventually the criminal element will be just a contractor and eventually they will move somewhere else and try to exploit a different niche.

The biggest losers from such a transformation will be the ecosystem of security companies that have fed off the fear and uncertainty that the botnets/maleware/virus ecosystem has created.  They were an opportunistic business model at the best of times.  They will transform into a much more specific security service for clients and provide targeted security around assets, probably information assets.  I fully expect to see infosec turn into some sort of cloud service where you check your information in and have a guaranteed access to it anywhere, anytime under a certain level of security.  People like guarantees.

Wednesday, May 25, 2011

Tracking Online Transactions

http://www.technologyreview.com/blog/editors/26785/

This is an interesting little snipit about the transactions involved behind a spam advertised product.  The thought that comes to mind is the similarity to the drop-shipping model that has proliferated on ebay and other online auction sites.  The funniest thing is that every time some politician smiles brightly and talks about the wonders of free trade and the global ecconomy... this is actually what it means.  Not that I am being critical. This is a healthy thing.  It's the organisational structures that are not yet in place to regulate this sort of thing.

Its actually even funnier when you read about all the arguments and counter arguments about online music piracy and the arguments about how the old economic model is dead and how the music companies need to evolve etc etc. The thing that everyone forgets is that every economic transaction will evolve in a similar way.  EVERYTHING!  Any product our grandparents could purchase from a shop can now be delivered across the internet.  Very soon any service short of those requiring specialist equipment or personal contact will be able to be partially or completely delivered via the internet.

If you think the flight of jobs to cheap labor sources has been rapid up till now... just you wait.  For every new country that gets good, universal connection to the internet, we will have another round of movement of jobs and infrastructure in to exploit the unemployed for cheap labour and the wealthy for customers.

The long game in all this is that the internet will provide a degree of leveling, in that wealth and employment will flow to countries with cheap labor and low employment conditions while wealthy countries where labor costs are high will be drained of both employment and capital. 

This has been happening for the past few decades, so this is not exactly rocket science.  The point that I find eternally amusing is how little the political machinery wants to accept this reality.  Politicians are the last to change.  The absolute last to accept that that status quo in not maintainable.  Simply because they are only in their position by promosing to maintain the status quo ( or return to a previous idyllic status quo that the population of voters remembers fondly ( see Russia for an example of that particular issue))  But as much as I can point at Russia... I think they are just the leading edge. Half of western Europe is going through economic collapse at the moment, so they should probably be looking at Russia for guidance rather than treating Russia as some kind of "never happen here" case.
But politicians being politicians, they all want to pretend that some how they can roll back to a better time.  Just like the climate debate, "we can undo the damage" just tax carbon etc etc.  Bullshit.  There is no going back.   We can certainly tax carbon but that will just create a carbon market. If it has an incidental effect on the amount of greenhouse gas... well that's nice too.

The point is that the Internet is a transformative technology for everything, wealth, culture, community, politics, technology etc. simply because it has expanded everyones ability to access all of the above.

Are there down sides... you betcha.

Tuesday, November 9, 2010

Firesheep plugin

http://codebutler.com/firesheep

This is a little old but still funny. I'm interested in this from a security point of view but also from seeing what the reaction to it is. Its one of those things that could catch fire and take off or disappear into the background noise. Its an interesting experiment on public scrutiny and security by obscurity.  The techniques to exploit this hole have been around since cookies were invented and abused for session management over insecure networks... so far its passed about 1.4 million search results on google using "firesheep -sheep". The top ten pages are all 100% articles on Firesheep so I figure the rest of the results are probably pretty good.  LOL.  Way to shine a light on the issue. Lets see if anything happens.

Edit
The general reaction has been two fold. Firstly all the tech press is generally cheering the political objectives while recommending countermeasures. Secondly the hysterical non technical press is decrying the existance of such a terrible weapon... blah blah blah.

Another interesting aspect is the ecosystem of countermeasure tools that are popping up. BlackSheep and FireShepard are the two that have sprung fully formed to offer a solution for the ignorant. Does that not strike you as suspicious?  I have read that BlackSheep is actually a DDOS attack client which I find much more credible than that it magically has some capacity to reach out and touch a passive sniffer application. The description of how it works is kinda credible but not if you know much about DNS and how FireSheep actually works. Even if its exploiting a weakness in FireSheep, its not actually dealing with the underlying issue that is being highlighted. It would be trivial to rework FireSheep to be impervious to BlackSheep's supposed technique.

As for FireShepard:

http://blogs.forbes.com/andygreenberg/2010/10/28/how-to-screw-with-firesheep-snoops-try-fireshepherd/

This page has a lightweight description of how it claims to work. Again its basically trying to attack a weakness in the Firesheep tool rather than patch the problem that FireSheep is highlighting.  Also FireShepard would probably breach the terms of service of any reasonable network because it works by intermittently flooding the network with rubbish packets. This sort of activity would probably set off all sorts of DOS attack detectors, Intrusion systems and just generally piss off any network admins who caught you using it.  Its the equivalent of turning on the sprinkler system in a whole building to put out a single candle (that may or may not be there). And just consider the chaos if one paranoid user on the network starts talking about it to their co-workers and encourages them to also install it.  You then have multiple people intermittently DOS'ing the network segment. Genius.... (Sarcasm)
The first tool sounds like its a tiny step from being outright scamware if its not already malware. The second sounds like a poorly thought out tool with marginal hope of fixing the problem but much larger potential for getting the user banned or prosecuted.

Nothing has turned up about dealing with false positives or the social consequences of detecting an attacker and how to deal with it ethically or safely has shown up yet.  I would assume that the common witch hunt rules would apply. If you think someone is running a sniffer on the network, you can unilaterally employ the "strike first" approach and burn them publicly so you feel all safe again.  Since there is no actual evidence (unless your facebook profile has been hijacked by a completely incompetent person who signs all their fake posts with their real name... but then how would you even prove that that was their real name?  Endless fun with digital forensics.

So we have a scary mix of paranoia, uncertainty, ignorance, exploitative tool developers, no useful solutions from most of the affected sites and a bubbling pool of anger, distrust and the usual illusion of invulnerability that internet users get when they feel safe and anonymous. Nothing bad could happen here...