Showing posts with label CyberSecurity. Show all posts
Showing posts with label CyberSecurity. Show all posts

Saturday, November 28, 2015

The Paranoid's survival guide: Protect your privacy on social, mobile and more


The paranopid's survival guide, part 2: Protect your privacy on social, mobile and more

by ROBERT L. MITCHELL | 

Is privacy dead? Not by a long shot. While you can't control everything that's out there about you, there's quite a bit you can do to reduce your data footprint -- or at least avoid adding to it. For this series, Computerworld asked nine privacy experts for tips and tricks they use for keeping their own personal data profiles on the down low.

Whether your goal is avoiding tracking by marketers, ensuring your personal safety or protecting yourself from government surveillance, there are steps you can take to minimize your exposure both online and off, these professionals say.

Part 1 of this series covered how to maintain your online privacy and surf the Web without leaving a data trail. Here, in part 2, we offer advice on how to approach social media, messaging and some general rules you should follow when using mobile apps. Part 3 covers how to minimize your offline data footprint, and where to go to opt out. (For more tips, also see our "60-minute security makeover: Prevent your own epic hack.")

3 ways to shape up your social media

Don't sign up for a new service using Facebook or another social networking account

When a website tells you it's easier to register for its service using your Facebook account, what they really mean is that it's easier for them to pull all available information about you from that site and use it to build a profile on you, says Rob Shavell, co-founder and CEO at privacy software vendor Abine. Always choose the "sign up with email" option, and don't use the same email address you use for Facebook or other social media accounts.

Lock down those social network privacy settings

Review and set the privacy settings for every online service you use, and revisit those policies regularly to update them, as the services tend to change their policies frequently, says Jules Polonetsky, executive director of the Future of Privacy Forum. "Make sure you lock down the settings in every social media profile, and test it to see what others can see about you," he suggests.

Think before you post

On social networks nothing is truly private. "Be aware when you post with whom you are sharing," says Sid Stamm, senior engineering manager for security and privacy at Mozilla. What you post can be used against you, either now or in the future -- by snooping government agencies, political operatives, potential employers or online marketers that want to serve up interest-based advertising.

Even when you delete a post it's likely to persist. Your "friends" can copy/paste anything visible to them into other sites or email messages. And with Twitter your posts are part of the public data feed that's routinely captured by data brokers and others interested in analyzing that data. "The act of deleting just means removing the visibility on Twitter," says Robert Hansen, a security researcher and director of product management at the website-security vendor WhiteHat Security. But every data broker or other organization that has consumed your Twitter feed between the time you posted and the time you deleted the message still has the data.

Don't post photos of your kids, your interests or when you'll be going on vacation, he adds. "If it's something I even briefly pause about, I don't put it on social networks. Treat everything in social networks as adversarial, and then you don't have to worry about it."

Online job sites and online dating sites are the two areas where people give up way too much information about themselves, says Casey Oppenheim, co-CEO at anti-tracking software vendor Disconnect. "Your name, address, where you went to school -- all of that information about you can be used to answer challenge questions," he says. Online dating sites may use questionnaires to collect extensive psychological and demographic data in an effort to build very detailed profiles that may be retained even after you close your account.

Page 2 of 3

Manage your messaging

Secure your email

Be sure to enable HTTPS encryption for all email communications in transit. As for email data in your inbox, a hosted private email service that you pay for, from a company such as Rackspace, offers more privacy than does a free, public Webmail service such as Gmail, while hosting your own email server on premises offers the most privacy of all.

There are many exploits out there for compromising Webmail services, says Hansen. What's more, the content of email hosted on free Webmail services may be used to allow advertisers to send interest-based advertising. Also, government agencies can access your data on Webmail or hosted email systems at any time by simply presenting a subpoena -- and the provider may be prohibited from telling you about it. With an internally hosted server, a search warrant would be required, and you would be aware of the action.

Use a privacy-oriented email service

Popular Webmail services such as Gmail and Yahoo Mail offer a free account in exchange for collecting data about you and analyzing your email activity for marketing purposes. If that bothers you, consider a free service not supported by advertising, such as Zoho Mail, or use an email account provided by your ISP.

For even greater protection, use a secure email service that's dedicated to protecting your privacy, such as Riseup or MyKolab. Services like MyKolab, which hosts your email data offshore and out of reach of the Patriot Act, may make your data less prone to U.S. government snooping.

Use a self-destructing text/chat service

Instant messaging/texting services that encrypt your communications and don't retain your chat history have gained critical mass among young people, and for good reason, says Polonestky. "No one records [verbal] chit-chat, but when I have that conversation online it's somehow part of the national archives. It shouldn't be. It's the kind of communication that should work as a shout out and be fleeting," he says.

Polonestky uses Frankly Chat, which he calls "Snapchat for adults," but says other popular services including Snapchat itself or Whisper also work well. Whisper is an anonymous social network, and Snapchat allows users to set time limits for how long their posts will appear.

Oppenheim recommends Silent Text and TextSecure. The downside of these services is that the person you want to message must have the same app installed and running before you can connect. So, depending on which service your friends use, you might need to keep more than one app running.

Mobile protections

Limit tracking on your mobile phone

Mobile phones offer more limited options for minimizing your online footprint, says Justin Brookman, director, consumer privacy at the Center for Democracy & Technology. Your carrier knows your location, the calls you make, the sites you visit, the texts you've sent and received and the apps you use. Unless you turn off your phone, your carrier will always know where you are, he says. And while you can't opt of out all data collection, your carrier may offer options that let you limit how it uses and shares that data.

Password-protect your smartphonestablets and other personal computing devices, and configure the "find me" feature or app for mobile devices. "The first thing to do is to make sure that if you ever lost the device you can get it back and lock it down. This is half security, half privacy," says Chris Babel, CEO at security vendor Truste.

Page 3 of 3

Use a password manager and two-factor authentication

Password managers not only keep track of your online user names and passwords and generate strong passwords, Babel says, but most also have an auto-fill feature that protects your account credentials from key logger malware that may be watching you. (It's especially important to use a strong password for your email account, since it contains a trove of personal information about you, and most online accounts use your email address to allow you to reset forgotten passwords.)

If you already use a password manager -- either on your desktop as a standalone app or in your browser -- check to see if it has a mobile component. Many do.

For additional protection, consider a password manager such as LastPass that supports two-factor authentication. Even if someone guesses your master password they still won't be able to get at your password database without physical access to your device.

Don't share your location information

"You can control who you give location permission to on most mobile devices, but you can't control" with which other apps are given that data. "So choose carefully," says Brookman. Social media updates that include location data also tell people where you are -- and where you aren't. Do you really want everyone on Twitter, or all of your Facebook friends -- and friends of friends -- to know? "Don't turn on location services unless you really need it," says Oppenheim. And turn it off when you're done.

Turn off your Wi-Fi and Bluetooth to avoid retail tracking

Today you walk into a store and the retailer doesn't know much about you. "But stores are installing listening devices to detect mobile phones with Wi-Fi turned on that are actively looking for access points," says Brookman. Before long, it won't just be your mobile carrier and mobile apps that know where you are at all times. Retailers and other businesses want to use the combination of Bluetooth and Wi-Fi signals emanating from your smartphone to track you when you enter a store or other place of business.

"When I walk into the mall they will know I've entered because my device is pinging Wi-Fi. And with Bluetooth they can track me within 30 to 50 feet. They know where I'm walking," says Babel. When your phone queries the store's wireless router to search for connectivity option, the business captures the unique MAC address associated with your phone's Wi-Fi hardware. If you then make a purchase, your MAC address can be combined with other information the store has to identify you. Some consumers might want to announce themselves, Babel says, because they're hoping to receive special offers on their smartphones. But if you're paranoid, says Brookman, turning off Wi-Fi and Bluetooth solves the problem.

If you can't be bothered to toggle those services off every time you leave your home or office, anti-virus software vendor AVG recently rolled out a service called PrivacyFix that automatically turns off your mobile Wi-Fi if the network you're passing by isn't on your whitelist. Mobile apps like Tasker for Android can be configured to use a technique called "geofencing" to turn off Wi-Fi when you leave your home or office and turn it back on when you return.

Soon you may have another option: The Future of Privacy Forum is in the process of creating a service called Do Not Track My Mac -- to be hosted at smartstoreprivacy.org -- that will let users opt out of tracking by retailers that want to capture your smartphone's Ethernet MAC address.

The companies agree not to capture your name or link your information to your MAC address unless you opt in, says Polonetsky. However, they can still track your MAC address anonymously unless you opt out. The data is used for general analysis purposes, such as to determine the average wait time in cashier lines, for example, or to study how traffic moves through the store. So far, 10 companies have signed on, Polonetsky says.

Next: How to minimize your offline data footprint, and where to go to opt out.

This article, The paranoid's online survival guide, part 2: How to protect your personal data, was originally published at Computerworld.com.


^ed 
Sent via iPhone

Friday, November 27, 2015

You're not as anonymous as you think!

The following information is associated with each type of browsing data and applies to Google Chrome on Windows, Mac, Linux, and Chrome OS.

  • Browsing history: Clearing your browsing history specifically deletes the following:
    • Web addresses you've visited from the History page
    • Cached text of those pages
    • Snapshots of those pages for images that appear on the New Tab page
    • Any IP addresses pre-fetched from those pages
  • Download history: The list of files you've downloaded using Google Chrome is cleared, but the actual files are not removed from your computer.
  • Cookies, site, and plug-in data:
  • Cache: Text of webpages you've visited in Google Chrome is removed from your computer. Browsers store elements of webpages to speed up the loading of the webpage during your next visit.
  • Passwords: Records of usernames and passwords are deleted. If you're using a Mac, your password records are deleted from Keychain Access.
  • Form data: All your Autofill entries and records of text you've entered on web forms are deleted.
  • Clear data from hosted apps: Data from the apps you’ve added to Chrome from the Chrome Web Store will be erased, such as the local storage used by Gmail Offline.
  • Deauthorize content licenses: This will prevent Flash Player from playing any previously viewed protected content, such as movies or music that you’ve purchased. It’s recommended to deauthorize content licenses before selling or donating your computer.

Wednesday, October 28, 2015

Back in Pastebin October 29, 2015

I started this private site after my name, ID, medical and financial info was stolen, made public in Pastebin, and sold on T-shirts at the DefCon hackers conference. I never got one penny for the T-shirts and apparel sold and was never reimbursed for the damage done to my computer equipment and mobile devices as a result of HARD CORE hackers. I was promised the T-shirts and promo ads would be pulled from the event and the black hat hackers known as Lulz, AntiSec, (Sabu and Co.) would take them down and refrain from using my likeness for promotional purposes. They were not. They used my name, my likeness, my photos, my social security number, my ID, my address and more to create a slew of fake social media accounts to post insane bullshit across a variety of platforms. They even socially engineered my closest friends and family members in various forums to reinforce the charade. They claimed the T-shirts were for charity and that $1.00 would be donated for every ELyssaD garment sold. Not only did I not receive any such monies, I am quite certain these wits have no idea how serious it is to impersonate a 501(c)3. So not only did they make a profit from exploiting every aspect of my life, they harassed my friends, impersonated an ex-cop who has been one of most trusted allies and confidant; threatened friends who dare to speak up on my behalf by calling them on the phone and identifying themselves as law enforcement. ANOTHER felony. They made a profit. They offered a reward for tittie pics, had podcasts, comic books and sold a line of women's apparel to promote their podcasts, show and of course, make money. They created multiple fake identities on various social media platforms. They pwned my website, social media accounts, linked in, private forums, etc... harassed my friends and posted my fathers home address on the internet. They altered personal documents they stole from my private files, altered them, and had the nerve to put the FAKE documents back in to my web albums and made them public. ONE LOGIN = ONE FELONY Destruction of evidence (especially records that pertain to employee benefits is a whole other class of crimes) These individuals are clearly guilty, and have no problem advertising their skills across the hacker community. They destroyed my professional credibility with disinformation writing posting ridiculous website entries that present my professional certifications as a practicing therapist to make them appear as if I was the patient not the provider. 65 "people" impersonating me on social media platforms? My friends, sister, brothers, my mother, and even "Agent Daddy" became targets as well. I started this site hoping for a do-over. My name is ELyssa. ELyssaD and, for he record I've never done midget porn!

image1.PNG


image2.PNG

image3.PNG




I didn't see this one coming. 




^ed 
Sent via iPhone

Monday, November 10, 2014

17 Arrested, 400 Tor sites seized

17 arrested, 400 Tor sites seized in operation targeting ‘darknet markets’


November 7 

THE HAGUE, NETHERLANDS (BNO NEWS) — Authorities in Europe and the United States have arrested 17 people and seized more than 400 sites in a coordinated action against markets offering weapons and drugs through anonymity network Tor, officials announced on Friday, just a day after a major drugs market was taken down.

The latest operation took place on Thursday when authorities in the United States and more than a dozen European countries executed 13 search warrants and arrested 17 people after an investigation into darknet marketplaces. On these marketplaces, which can only be accessed through Tor, people can purchase weapons, drugs and even contract killers.

Ulf Bergström, a spokesman for Eurojust, the European Union’s judicial cooperation unit, said 414 hidden sites were seized during Thursday’s operation, which was dubbed Operation Onymous. Also seized was hardware, digital media, drugs, gold, silver, 180,000 euros ($223,500) in cash, and Bitcoins worth approximately 1 million U.S. dollars.

“Users, vendors and those hosting these hidden services were – until now – believed to be relatively safe from prosecution. This action will shake that belief,” Bergström said. He said several vendors and administrators were arrested during the operation, but there was no immediate word on whether any users of Tor sites had been identified.

Sites seized during the operation include “Pandora,” “Blue Sky,” “Hydra,” and “Cloud Nine,” all of which offered an extensive range of illegal goods and services for sale, including drugs, stolen credit card data, counterfeit currency, and fake identity documents. Also seized was “Executive Outcomes,” which specialized in firearm trafficking, and “Super Notes Counter,” which offered to sell counterfeit euros and U.S. dollars in exchange for Bitcoin.

Countries involved in ‘Operation Onymous’ include Bulgaria, the Czech Republic, Finland, France, Germany, Hungary, Ireland, Latvia, Lithuania, Luxembourg, the Netherlands, Romania, Spain, Sweden, Switzerland, the United Kingdom, and the United States.

Thursday’s operation came just a day after 26-year-old Blake Benthall, who is known as ‘Defcon’ online, was arrested in San Fransisco for allegedly running the hidden site ‘Silk Road 2.0,’ which was launched in November 2013 after its predecessor was shut down by law enforcement. Benthall’s site is alleged to have enabled more than 100,000 people to buy and sell illegal drugs.

“Underground websites such as Silk Road and Silk Road 2 are like the Wild West of the Internet, where criminals can anonymously buy and sell all things illegal,” said Peter Edge, of Homeland Security Investigations (HSI) at the U.S. Immigration and Customs Enforcement (ICE). “We will continue to use all of our resources and work closely with our U.S. and international law enforcement partners to shut down these hidden black market sites, and hold criminals accountable who use anonymous Internet software to peddle their illegal activities.”

Tor, which is an acronym for the Onion Router, is a network designed to hide users’ real IP address by routing all traffic through the many servers of the Tor network, making it practically impossible to physically locate the computers hosting or accessing the sites. Although Tor is also used for legitimate purposes, criminals take advantage of Tor for a range of illicit purposes, including drugs, weapons, money laundering, and child pornography.

Friday, July 4, 2014

Anonymous, Lulz, and the Politics of Hacktivism

Why am I writing about th3j35t3r in a blog which focuses on cyberharassment and cyberbullies?

I’ve been monitoring his Twitter feed for a long time now and frankly I can’t think of anyone online right now that is more targeted by Tards than this guy/gal/group.

The biggest irony of all is that the people who are targeting him/her/them most frequently call themselves Anonymous.

Now I’m not going to get into the whole issue of who is or isn’t a ‘real Anon’ or who does or doesn’t reflect the concept, etc. It just gets complicated because pretty much anyone can declare themselves Anonymous irrespective of the core ideal which Anonymous represents and irrespective of whether they actually follow that core ideal or not. Although they all claim to and no doubt genuinely believe that they do follow it.

Either that or I’m sadly mistaken about what the core ideal is. No doubt that is possible and if I am I’d like to be corrected because that means that I should reconsider my support.

Based on what I believe the core ideals of Anonymous are, there is no-one who represents the Anonymous ideal more than th3j35t3r including those Tards who keep targeting him with their numerous and ongoing FailDoxes and cyberharassment campaigns.

The exception to that would be those real hacking groups (not the skids who all claim to be hackers and create their little drama whore ‘sects’) which have managed to maintain complete secrecy and are generally unknown. The other exception to that are those groups that are open and known but manage to maintain complete secrecy about what it is they actually do. 

I’m not going to draw attention to them by naming them and anyone who is serious or interested knows who the real ones are with the really serious people who are really good at what they do, anyway.

So, to me, and of course, this is just my personal opinion, they and th3j35t3r represent the real Anonymous not a bunch of loud mouthed egofag skids and n00bs who run around doxing people like th3j35t3r and other legitimate social activists/hacktivists, for no reason, or for completely idiotic reasons that they, more often than not, just fabricate, or by taking a minor ‘transgression’ and exaggerating the issue beyond recognition to rationalize their behavior.

That said, it’s important to note that I’m not a member of the Anonymous Collective, have never been and am speaking as an outsider. So, my opinion on this has as much value as those who read this choose to give it and no more.

I do, however, openly and publicly support what Anonymous does by writing about the Ops I support on my main blog and promoting the videos that I agree with. That is my contribution to the cause and I believe that it’s just as important as the actions that the hacktivists and social activists engage in because if people don’t know what they’re doing because people like me aren’t promoting their causes and advocating on their behalf, all their actions don’t mean very much. You need both. It isn’t a case of one vs the other.

Now, let’s look at the facts and from this point on I’m going to refer to th3j35t3r as a ‘he’ simply out of convenience. I have no idea who he/she/they are nor do I want to know and if I did ever stumble across that information I wouldn’t share it. You’d have to waterboard me to get it out of me.

Th3J35t3r Facts:

He has been online for 5 years now or is beginning his 5th year as of November 9th, 2013 when he celebrated his anniversary.

During this time, he has managed to remain completely anonymous despite:

1. Thousands of attempts to dox him.

2. At least some of the attempts were made by people who claim to have expertise in the InfoSec field.

3. Numerous people have attempted to befriend him and women have attempted to seduce him in order to extract personal identifying information from him. Some self-identified as social engineers.

All without success.

So I have to wonder why there is such an obsession with doxing th3j35t3r and why is it coming mostly from people who claim to be Anonymous?

Well, first of all, the only elements of Anonymous who appear to be obsessed with th3j35t3r are the skids and the n00bs. The serious Anon hacktivists and social activists don’t appear to be concerned about him at all.

In my opinion, the skids and n00bs do it because of:

1. Their own egofaggotry, that is, they think they know-it-all, they think they’re the best, and they want to prove it by taking on the ‘fastest gun in the west’ much like the gun slingers in those old westerns who couldn’t get out of town without having a shoot out because someone wanted to prove they were faster on the draw.

2. This delusion they hold about themselves is an indication of their own anti-social personality disorders and need to cyberharass people.

3.  They may or may not also engage in the odd bit of social activism or at least try to present themselves in that light in order to establish some credibility for themselves before starting a cyberharassment campaign against someone. Now, it’s always possible that the intent was genuine but their personality disorder just took hold. Either way the end result is the same and the cause is the same. That said, most of those with anti-social personality disorders simply use things like social activism both as a means of covering up their anti-social personality disorder by making themselves appear to be caring people as well as a means to their end of rationalizing cyberharassment against people.

That is, those same people who want to be ‘epic’ and take on th3j35t3r will also likely be the same ones on Facebook and other sites, leading theRIP Tards and other Tards in various cyberharassment campaigns.

Their psychology is really no different. As I pointed out in one of my previous blog posts, normal, sane, rational people don’t go around destroying other people without serious cause. These habitual doxers usually make it crystal clear that their intent is to destroy the person and there is usually little or no real cause for them to do so.

I can perfectly understand and sympathize with the person who kills the pedophile who raped their child. It may not be the right thing to do but it’s understandable and I may or may not be above such an act myself.

I don’t understand or sympathize with those who want to destroy a person because they don’t agree with them on some issue or because they say something they don’t like or do something they don’t like or associate with someone they don’t like.

It’s called Freedom of Speech and Freedom of Association and both are constitutionally protected civil rights. Cyberharassing people on any of those grounds means that the Tards are violating their targets civil rights.

Civil Rights are something which I thought was supposed to be a core ideal of Anonymous. So, frankly, who do these Tards think they are when they attack th3j35t3r or those who associate with him because they don’t like his opinion on something or the fact that some support him?

Isn’t Anonymous all about Civil Rights? Am I wrong?

That’s not to say there isn’t some actual social activist opposition to th3j35t3r. There is no doubt that there is. He makes no secret out of the fact that he doesn’t agree with WikiLeaks and brought their site down and he’s not shy about expressing his political opinion where Assange is concerned.

Is this personal? Is he threatening to ‘destroy Assange and his family’? No. I’ve never seen him take that approach.

He keeps it all in the political domain and he has a right to do that.

disagree with him and support both Assange and WikiLeaks and consider what they do extremely important. So what? We disagree on something. That’s no reason to hate him.

I respect him for the things he does that I agree with just like I support the Anon Ops that I agree with and ignore the one’s that I don’t agree with.

However, the self-righteous Tards who hate him because he doesn’t agree with them on some issue seem to think they have the right to impose their views on everyone and no-one can possibly be moral or ethical unless they follow their deemed politically correct party line. 

They also seem to think they have the right to destroy anyone’s life who dares to disagree with them or associates with those who disagree with them.

Freedom of speech gives th3j35t3r just as much right to his opinion as it does you or I. I agree with some things he does and disagree with some things. 

I see no reason to hate him or anyone else because he or they don’t agree with me on everything or something. It’s a good reason to get into an interesting discussion if both parties can handle that or simply to agree to disagree.

One of the actions on Twitter that brought a smile to my face was when th3j35t3r decided to throw down the gauntlet to Kevin Mitnick because of his position supporting Snowden. 

He was going to protest Mitnick’s support by having a political virtual sit-in by dDosing and bringing down Mitnicks web site. 

He initiated things like a gentleman with Mitnick by letting him know that he was going to target his site and why. 

Although I don’t think he gave him the technical details of what he was planning. The irony was perfect. He used an Android to bring down Mitnick’s security business site. How did Mitnick react? Like a true gentleman in return. They shook hands and moved on. It was a pleasure to behold.

That is how normal, sane, rational people who don’t have anti-social personality disorders handle these things.

When it comes to the 99%, the reality is that we are NOT going to agree on MOST things. Everyone comes from different ideologies and backgrounds and represents different social and political views.

I’m a Freethinker and don’t accept any ideology. I determine my position on issues based on logic, reason and empirical evidence.

However, we can ALL agree on SOME things like the importance of protecting our Civil Rights. And even on that issue some might not believe that our Civil Rights are in danger. They would wrong in my opinion but they’re allowed to hold that belief whether I agree with it or not.

In the end, Anonymous and Occupy can only be successful if they recognize that fact, don’t try to push sectarian positions and stick to the general issues that matter to most of us irrespective of whether we agree with any particular ideology or not.

The Tards are incapable of recognizing this or the importance of this concept so we will likely forever be dealing with their Tard ways. 

Since they’re now getting together in Tard groups to do Tard things en masse we all need to be aware of this phenomenon that’s occurring and have good strategies to deal with it.

From what I’ve seen, th3j35t3r handles all of this quite well. He will only retaliate to the degree necessary to get them off his back which is exactly what needs to be done.

Unfortunately for the Tards and because of their own stupidity, it sometimes means that you have to do quite a lot of damage before they’ll move on. 

The benefit of that is that since they tend to be cowards as well, it makes them think twice before they’ll do it again. 

They might try to repeat the behavior using other strategies but they’ll always find themselves in the same position again if enough people continue to stand up to them.

Th3j35t3r, on the other hand, and those following him, might miss it if all the drama stopped completely. It’s almost always entertaining to watch these Tards make fools of themselves over and over again. 

They may be doing it for the lulz but the one’s that are actually having the lulz are those of us watching th3j35t3r’s feed and watching him pwn them over and over again.

If anyone were to actually dox th3j35t3r, given the support he has on Twitter, that someone could find themselves in more trouble than they can handle. I’m pretty sure I won’t be only one ticked off if that were to happen. Just saying….

I think that every person who has been doxed by these Tards as th3j35t3r should automatically get a free J T-Shirt which says th3j35t3r-2, the3j35t3r-3, etc. on it and a membership card to a club called ‘Doxed as th3j35t3r’.


I’d dox myself as th3j35t3r for that :-D.

Stay Frosty ;-D

Saturday, December 21, 2013

SIM Crypto Hijack Threatens Millions

Mobe SIM crypto hijack threatens millions: Here's HOW IT WORKS

July 22nd 2013

You'll kick yourself when you know how

Analysis A German researcher reckons he can take control of your phone's SIM card and hijack the handset by cracking the encryption on the device.

But he's not alone: network operators have long been able to do just that, and a careful look at how that's possible makes the long-standing security of GSM phone networks all the more remarkable.

GSM networks are secured by shared secrets. A unique cryptographic key is issued to each subscriber and embedded in their phone's SIM card; a copy of that key is held by the network allowing mutual authentication by symmetric encryption (the same key is used at both ends).

Despite successful assaults on other parts of the GSM infrastructure those private keys have remained beyond the grasp of hackers, at least until now.

Pedigree security researcher Karsten Nohl has apparently discovered two unrelated flaws in implementations of the GSM standard that (when combined) could leave millions of SIM cards vulnerable to attack. Such attacks could permit call interception, and threaten the security of NFC applications (such as pay by wave) just as the tech is on the cusp of going mainstream.

Getting the secret key off a SIM isn't easy - but increases in computing power have combined with poor implementations to create the first flaw exploited by Nohl, which reveals the secret key that should be known only to the network operator and the SIM.

Nohl's crack uses an SMS message addressed to the SIM, and unseen by the user. This is normal enough; these messages come in four classes (0-3) addressed to the user, the handset, the SIM, and a tethered device respectively. Class 0 is the one we all know and love, but Class 2 (addressed to the SIM) remains surprisingly popular even if the other classes are all but forgotten.

The most common Class 2 message contains changes to the list of preferred roaming partners, to reflect new deals between operators, but the Global Platform standard permits anything, even the entire operating system, to be changed using signed Class 2 messages.

Such radical updates are rare, but they have happened and are secured using that shared secret, so knowledge of the key confers significant power.

This should already be setting off alarm bells

Nohl's crack starts with a malformed Class 2 message. Anyone can send such a message using a software SMS Centre (SMSC), or even an old handset as some permitted a user-selected class. That message is rejected by the receiving SIM as it's not signed, usually the message is just discarded but some SIMs apparently respond with a digitally signed error message that can be used to reveal their secret key.

Digital signatures shouldn't reveal the keys used to sign them; that would defeat the object, but in this case it seems that some do.

The digital signature sent over with the error message is a one-way hash: a fixed-length summary of the message that is generated by the phone using the secret key.

This allows the receiver of the message to verify it is genuine and trustworthy: the receiver calculates a hash value using its copy of the secret key and the received message data. If that calculated value matches the hash included with the message then all is well - the secret keys at both ends must match.

But Nohl's team has a rainbow table to deduce the secret key from the signature.

The error message is a standard one - it doesn't change between handsets - so by generating a list of every possible key value, a rainbow table of every possible hash value can be calculated for this one particular message. So an attacker simply takes the signature from the phone and looks it up in the rainbow to discover the secret key.

Every bit of a key doubles the size of the rainbow table, and such techniques rapidly become impractical as keys get bigger, but some older SIMs are using 56-bit keys and old-style DES encryption which combines to make the rainbow technique viable, and where that happens the secret key can be quickly discovered.

Once you have the key, you can start signing your own command SMS messages to control a targeted mobile.

What can be done?

Operators can change the SIMs, and update the encryption, but users are surprisingly reluctant to slot a new SIM into their handsets - they become quite emotional about it, proud to be using decades-old chippery, which stalls upgrade programmes. It's also expensive - adding a dollar to the cost of the SIM may seem like a small deal, but when a network has 10 million customers it becomes a significant expense.

Quite how many SIMs are using 56DES we don't know; Kohl reckons to have tried a thousand over the last year or two and discovered a quarter are vulnerable. There's no easy way to discover if a specific SIM is using 56DES, the operators store the information along with the keys, but the SIM won't talk about the subject.

Armed with a key our miscreant can reprogram the SIM to do just about anything - redirect SMS messages, change the preferred network operator, run up enormous bills to premium-rate numbers and authenticate payments through services such as PayForIt. Modern SIMs can request an internet connection, furnished by the handset and generally without user interaction, through which our attacker can cause all sorts of mischief - though to get at the users' bank details he'll need Nohl's second flaw.

Almost all SIMs (and credit cards) use JavaCard, a relation of Java still owned by Oracle, but having little in common with the cross-platform interpreted language beyond a bit of syntax. JavaCard is an operating system, not a language, and one which keeps applications (Cardlets, in the parlance) separated so they can't talk to each other.

Nohl claims to have found a flaw in that separation, though he won't be making the details public until next month's Black Hat conference. Combining that flaw with possession of the secret key makes for a potent combination - pay-by-bonk applications, such as the one being launched by EE later this year, rely on the hitherto sacrosanct separation of JavaCard apps, so they'll be a good deal of interest in Nohl's talk from hat wearers of all colours.

GSM authentication, as opposed to encryption, has proved amazing resilient over the years. A fix for this problem will likely turn up pretty quickly with the ITU and GSMA falling over themselves to be associated with the solution, but if it needs replacement SIMs then that will be a longer process.

Operators should be quick to send out new SIM cards to customers still using 56DES, but the JavaCard vulnerability may prove harder to patch and we'll get you details of that just as soon as we can. ®

Saturday, November 30, 2013

Hackers Courted by Government for Cyber Security Jobs

Hackers Courted by Government for Cyber Security Jobs - Rolling Stone

Inside a darkened conference room in the Miami Beach Holiday Inn, America’s most badass hackers are going to war – working their laptops between swigs of Bawls energy drink as Bassnectar booms in the background. A black guy with a soul patch crashes a power grid in North Korea. A stocky jock beside him storms a database of stolen credit cards in Russia. And a gangly geek in a black T-shirt busts into the Chinese Ministry of Information, represented by a glowing red star on his laptop screen. “Is the data secured?” his buddy asks him. “No,” he replies with a grin. They’re in.

Fortunately for the enemies, however, the attacks aren’t real. They’re part of a war game at HackMiami, a weekend gathering of underground hackers in South Beach. While meatheads and models jog obliviously outside, 150 code warriors hunker inside the hotel for a three-day bender of booze, break-ins and brainstorming. Some are felons. Some are con artists. But they’re all here for the same mission: to show off their skills and perhaps attract the attention of government and corporate recruiters. Scouts are here looking for a new breed of soldier to win the war raging in the online shadows. This explains the balding guy prowling the room with an “I’m Hiring Security Engineers. Interested?” button pinned to his polo shirt.

Hackers like these aren’t the outlaws of the Internet anymore. A 29-year-old who goes by the name th3_e5c@p15t says he’s ready to fight the good fight against the real-life bad guys. “If they topple our government, it could have disastrous results,” he says. “We’d be the front line, and the future of warfare would be us.”

Related: Sex, Drugs and the Biggest Cybercrime of All Time

After decades of seeming like a sci-fi fantasy, the cyberwar is on. China, Iran and other countries reportedly have armies of state-sponsored hackers infiltrating our critical infrastructure. The threats are the stuff of a Michael Bay blockbuster: downed power grids, derailed trains, nuclear meltdowns. Or, as then-Defense Secretary Leon Panetta put it last year, a “cyber-Pearl Harbor... an attack that would cause physical destruction and the loss of life, paralyze and shock the nation and create a profound new sense of vulnerability.” In his 2013 State of the Union address, President Obama said that “America must also face the rapidly growing threat from cyberattacks.…We cannot look back years from now and wonder why we did nothing in the face of real threats to our security and our economy.”

The pixelated mushroom cloud first materialized in 2010 with the discovery of Stuxnet, a computer worm said to be designed by the Israeli and U.S. governments, which targeted uranium-enrichment facilities in Iran. Last fall, Iranian hackers reportedly erased 30,000 computers at a Middle Eastern oil company. In February, security researchers released a report that traced what was estimated to be hundreds of terabytes of stolen data from Fortune 500 companies and others by hackers in Shanghai. A leaked report from the Department of Homeland Security in May found “increasing hostility” aimed online against “U.S. critical infrastructure organizations” – power grids, water supplies, banks and so on.

Dave Marcus, director of threat intelligence and advance research at McAfee Federal Advanced Programs Groups, part of McAfee Labs, a leading computer-security firm, says the effects would be devastating. “If you shut off large portions of power, you’re not bringing people back to 1960, you’re bringing them back to 1860,” he says. “Shut off an interconnected society’s power for three weeks in this country, you will have chaos.”

Related: Meet the Legendary Hacker the Government Set Out to Destroy

Hence, events like HackMiami, where the competition to hire cyberwarriors is increasingly intense. “There’s too much demand and not enough talent,” says Jeff “The Dark Tangent” Moss, founder of the largest hacker convention, DefCon, held annually in Las Vegas. Despite the threats, a report by the Commission on the Theft of American Intellectual Property, a group comprised of former U.S. government, corporate and academic officials, recently concluded that so far the feds have been “utterly inadequate [in dealing] with the problem.” While Uncle Sam is jockeying for the Internet’s best troops, private security firms are offering way more pay and way less hassle. Charlie Miller, a famous hacker who exposed vulnerabilities in the MacBook Air and iPhone, spent five years with the National Security Agency before joining Twitter’s security team. Earlier this year, the DHS lost four top cybersecurity officials. In April, Peiter “Mudge” Zatko, a renowned member of the pioneering hacker collective Cult of the Dead Cow who was working at the DOD’s Defense Advanced Research Projects Agency, split for Silicon Valley to join his former DARPA boss, Regina Dugan. “Goodbye DARPA,” he tweeted. “Hello Google!”

As a result, there’s a metawar taking place: one between government and industry to score the country’s toughest geeks – like the ones here this weekend – to join their front lines before it’s too late. “We need hackers,” Janet Napolitano, secretary of the Department of Homeland Security, toldRolling Stone in June, “because this is the fastest-growing and fastest-changing area of threat that we’re confronting.” A month later, however, she announced that she was leaving DHS too – stepping down from her post to head the University of California system.