Thursday, February 21, 2013

iPhone Forensics: iPhone and iPad Forensics in a BYOD Enterprise Environment / Mac, iPad, and iPhone Forensics and eDiscovery Experts | BlackBag Technologies

Posted on February 23, 2012 by BlackBag Training Team There have been 1 comment(s)

The personal use of iPhone and iPad devices among consumers has become quite widespread. But, until now, deployment of these devices in the enterprise environment has generally occurred less frequently. However, according to a ZDNet report (King 2011) published in October of last year, due to the popularity of Apple’s iPad 2 and iPhone 4 devices, this is rapidly changing, especially among entities within the Financial Services sector. Some public and private sector organizations are purchasing mobile devices for use within the organization; however, others are adopting “Bring Your Own Device” (BYOD) policies and practices.

 

While BYOD strategies are both convenient for individual workers and potentially more cost effective than corporate-sponsored widespread mobile device deployment, BYOD practices present concerns and challenges to management, IT and human resources professionals, and individuals themselves. Because BYOD iPhones and iPads contain both personal and corporate data, several security issues such as WiFi security, device authentication, malware protection, and data access control, as well as digital forensics, eDiscovery, privacy, and regulation compliance issues must be addressed.

 

To mitigate some of these risks and concerns, business entities are implementing various “Mobile Device Management” techniques, policies, and controls. In October 2011, Apple introduced the iOS5 platform, which includes features such as over-the-air configuration and control. Apple developed these features to specifically address and support Mobile Device Management in the enterprise environment. (Apple Computer, Inc. 2011)

 

Mac and iOS forensic examiners need to be aware of the differences they may encounter when examining a device used in a BYOD enterprise environment versus a device that is configured for personal use only. The settings and configurations an IT administrator applies to an iPhone or iPad device when integrating the device into an enterprise environment may change the way a user interacts with the device, and may drastically alter the way the iOS device appears upon examination.

 

Below are several key areas that a Mac and iOS forensic examiner must consider when seizing and analyzing a BYOD iPhone or iPad device.

 

Application Installations

Apple factory-installed applications on an iOS device used for personal purposes may or may not be visible on a BYOD device.  This does not necessarily mean that that an application has been removed or that the tasks these applications normally execute are not executing on the iPhone or iPad. Rather, the application may be hidden, disabled, or substituted with a proprietary enterprise application and/or configuration that is undertaking, limiting, or hiding an iOS factory installed application, service, or task. A Mac and iOS forensic examiner must also understand that IT administrators can install and provision custom enterprise applications without accessing the iTunes App Store.

 

WiFi Data Syncing and Backups

iPhone and iPad devices in a BYOD environment may not be set to sync exclusively to a particular computer or iTunes account as they might on a personal device. IT administrators can provision and activate an iOS device via a WiFi connection. Therefore, a Mac and iOS forensic examiner must determine whether backups are residing on a corporate server and/or one of Apple’s iCloud servers, and determine which data is corporate and which is personal. Information contained in device configuration files may help a forensic examiner make this determination.

 

User Data and Artifacts

A forensic examiner may fail to find history data for applications such as YouTube, Maps, App Store, and even Safari on a device used in a BYOD environment. This may suggest the presence of an enterprise configuration profile deployment that limits the use of these applications. The iMessage application is another iOS5 application that a Mac and iOS examiner must carefully understand. Using iMessage, a user may initiate a secure chat session on one device, and seamlessly transition a text-based conversation, or transfer audio, video and pictures to another device, even if the second device does not have standard SMS capabilities. An examiner must be aware that data from a single communication session may be found on more than one device, and communications may have taken place on or with devices that one would not expect to find SMS communications.

 

Data Authentication

iOS5 devices support wireless Windows Exchange Tasks syncing and Active Sync. Notifications, applications, updates, events, emails, etc. may be pushed to the iOS device. A forensic examiner must carefully determine and thoroughly understand the device’s settings, especially when illegal, illicit, and/or misappropriated material is discover in order to accurately report and defend examination findings. iPhone and iPad devices support S/Mime email encryption and SecureID two-factor authentication. An examiner must be familiar with both the strengths and vulnerabilities of these technologies in order to address evidence authenticity inquiries.

 

Data Preservation

A user or IT administrator may remotely wipe data from an iPhone or iPad device using more than one method in a BYOD environment that has deployed these iOS devices. A user can wipe the device using the ‘Find My iPhone’ feature on the device and the iCloud or MobileMe web application.  Alternatively, the user or an IT administrator can wipe the device using Microsoft Exchange Server.  Therefore, if the ‘Find My iPhone’ feature is inactive, removed, or hidden, it does not mean that the device cannot be remotely wiped.

 

More on Remote Data Wiping

A Mac and iOS forensic examiner should also be familiar with the remote data wipe procedure and process differences on a BYOD versus personal-use device.  The methods used to wipe the device may impact the time it takes to remotely wipe a device.  To enable the remote wiping feature on an iPhone or iPad device, a user must first set the Find My iPhone setting to the On position in the iCloud or MobileMe account device settings via Settings > Mail, Contacts, Calendars > MobileMe account settings.

 

 

To send a remote wipe signal to an iOS device, the user must sign into their iCloud.com or MobileMe account, or use Apple’s FindMyiPhone application from another iOS device. The target device must be also be on and connected to either a cell phone tower or a WiFi network.

 

To initiate an iOS device remote wipe from a Microsoft Exchange Server 2003 machine, a user or IT administrator uses the Exchange ActiveSync Mobile Administration Web Tool. A user or IT administrator may use the Exchange Management Console, Outlook Web Access application, or the Exchange ActiveSync Mobile Administration Web Tool to initiate a remote wipe from an Exchange Server 2007 machine. Again, the target device must be turned on and connected to either a cell phone tower or a WiFi network for the remote wipe to execute successfully.

 

A Mac or iOS forensic examiner must consider remote wipe execution times so they can properly protect data on these devices from destruction. When a user executes a data wipe on an original iPhone or iPhone 3G device, the data on the device is overwritten. Conversely and most importantly, when a user or IT administrator executes a data wipe on a BYOD-configured iPhone 4, iPhone 4S, or iPad, the “wipe” executes immediately via a data encryption key removal.  In both cases, when a remote wipe is instigated, Apple sends a confirmation email to the user’s primary Apple ID email address.

 

 

iPhone Configuration Utility

Extensive information about iOS Enterprise Deployment can be found on Apple’s website. (Apple Computer, Inc. 2011)  An examiner can also look to Apple’s iPhone Configuration Utility to further understand important custom iPhone and iPad BYOD configuration settings. The iPhone Configuration Utility for Mac OS X  and for Windows is available free of charge on Apple’s website.

 

Using the iPhone Configuration Utility, enterprise IT administrators can set policy and control iOS behavior via configuration profiles.  These configuration profiles are certificates that administrators download and install on the BYOD iPhone or iPad device. IT administrators can install configuration profiles in a way that makes it nearly impossible for a user to remove the profile from the iOS device.

 

Customizable settings and controls include:

• Passcode policy enforcement such as passcode strength, length, expiry, complexity (pin code vs. passcode), and history

•  Remote data wiping settings.

•  Acceptable YouTube, Safari, Mail, the App Store app, and iTunes application use.  As previously mentioned, IT administrators can limit these applications and even hide them from the user’s view. Again, just because an application is not visible, does not mean that it is not present on the device.

•  VPN configuration and network access controls.

•  Calendar subscriptions and access.

•  Custom enterprise application installation and provisioning profiles.

•  Push notification settings and controls.

 

 

Configuration Profile Location

iPhone Configuration Utility configuration profiles are contained in the Configuration Profiles folder here:

 

/mobile/Library/Configuration Profiles

 

iPhone Configuration Utility profile files have a *.stub extension.  An examiner can openthese binary .xml files from within the BlackLight forensic software or with any .plist viewing tool. The Configuration Profiles folder may contain a few or many configuration profile files depending on how extensively a user or IT administrator customized the iOS device settings.  Configuration profiles may include Trust Certificates that correspond to encryption-based tasks such as email encryption.  A forensic examiner  can open and examine these certificates in the same manner as they would the configuration profiles themselves.

 

If an enterprise has designed and installed a proprietary application, a Provisioning Profile file is present. A Provisioning Profile file contains an Apple Developer ID, which may be registered to the enterprise that created the custom enterprise application.

 

Conclusion

As enterprises increasingly deploy BYOD configured iPhone and iPad devices within their organizations, Mac and iOS forensic examiners are likely to encounter these devices more frequently. Additionally, as iPhone, iPad, and proprietary App Store application capabilities become more sophisticated, the level of customization and control that an enterprise can apply to these devices will evolve.  A Mac and iOS forensic examiner’s best ally is continued awareness of what enterprises can control on iPhone and iPad BYOD devices, and how these controls affect the iOS device usage.

 

References

Apple, Inc. Enterprise. 2012. http://www.apple.com/support/iphone/enterprise/ (accessed February 21, 2012).

—. Mobile Device Management in iOS. October 2011. http://www.apple.com/iphone/business/integration/mdm/ (accessed February 21, 2012).

King, Rachael. Between the Lines - ZDNet. October 20, 2011. http://www.zdnet.com/blog/btl/ipad-driving-massive-growth-for-ios-in-enterprise-survey/61229 (accessed February 21, 2012).

Posted from DailyDDoSe

Wednesday, February 20, 2013

What’s Your Story? | Self Evident Truths

What’s Your Story?

 

Did you have an intense coming out experience? Were you raised in a religious environment? Were your friends supportive of your coming out? How did your loved ones treat you during that time? Have your parents been more supportive than you ever dreamed? Have you suffered discrimination? Was it not a big deal for you at all? What has your experience of sexuality been??
Send us your story so that we can share it with the community, through our blogs and this page. Fill out the form below or email SelfEvident2011@gmail.com.

→ Read, watch and listen to some inspiring and courageous stories we have collected from incredible people across the country in SELF EVIDENT TRUTHS MAGAZINE

Posted from DailyDDoSe

One Site May Be Responsible for Recent Hacks - Mike Isaac - Social - AllThingsD

Youve_Been_Hacked1Apple, Facebook, Twitter — all hacked. And there’s probably more to come.

In the spate of large companies hacked in recent weeks, it seems that many of them have one thing in common. Many have visited one compromised website specifically devoted to sharing information related to mobile development — and it’s not just tech companies visiting the site.

The site is called iPhoneDevSDK, according to sources close to the Facebook hacking investigation. It’s a hub for many companies concentrated on the mobile space.

After Facebook employees visited the mobile development site in recent weeks, malicious code injected into the HTML of the site used an exploit in Oracle’s Java plug-in to infect employee laptops, as the company divulged last Friday.

When asked for comment on the site in question, Facebook referred us back to the company’s blog post from last week, without going into further detail.

Of note: Do not visit this site, as it may continue to be compromised. While it’s potentially risky to publicize the website, AllThingsD is providing the name to inform readers, developers and organizations interested in mobile development in order to keep them from becoming infected.

Update 4:22 pm PT: Ian Sefferman, owner and operator of the site iPhoneDevSDK, has reached out to AllThingsD and provided the following statement:

“We’re investigating Facebook’s reports that iPhoneDevSDK was hosting an exploit targeted at Facebook employees. We’re actively ensuring that is not the case. Facebook originally noted that they immediately reached out to other affected companies, but we were never contacted by Facebook, any other company, or law enforcement. Our users’ security is incredibly important to us and we’ll be sure to follow the investigation through to completion.”

When asked for a response to Sefferman’s statement, Facebook declined to comment on an ongoing investigation.

This is likely also the website responsible for the recent hack of Apple employee laptops, as the company announced on Tuesday. “Apple has identified malware which infected a limited number of Mac systems through a vulnerability in the Java plug-in for browsers,” the company said in a statement to AllThingsD provided earlier this morning.

Apple did not immediately respond to a request for comment on whether or not the iPhoneDevSDK site was involved in its hack.

The site could also be the common thread behind the recent Twitter hack, which potentially compromised the accounts of 250,000 Twitter users. In the language of Twitter’s blog post, head of information security Bob Lord reminded users to disable Java inside of their browsers, a hint that this could be related to the Facebook and Apple hacks.

Apple also released a security update software patch to users on Tuesday which addresses the Java exploit, another indication that the iPhoneDevSDK site is responsible for the company’s hack.

Twitter did not respond to a request for comment.

The hack is different from many familiar modes of attacking individual users and companies. It’s called a “watering hole” attack, in that it’s launched from a centralized, popular location that many people visit across multiple industries.

“Everyone knows about spearphishing now,” said Joe Sullivan, Facebook’s chief security officer, in an interview last week with AllThingsD. “But being able to target a site on the Internet — it’s a really interesting idea that you could target people from there. You don’t have to get someone to open the email or click on the link.”

Or as independent security researcher Ashkan Soltani told us last week: “Rather than attack individual developers, they’ve poisoned the well.”

This type of attack has been used in other recent high-profile hacks. In December of last year, a watering-hole hack was discovered on the website of the Council of Foreign Relations, a Washington, D.C.-based think tank whose influence is widespread in “journalist, business and education circles.”

But the attack on mobile developers is potentially even more worrisome: The iPhoneDevSDK website isn’t just for tech-focused companies working on mobile apps. It’s an iPhone-specific site that any organization interested in mobile could benefit from visiting. And as Facebook said in its recent blog post, “Facebook was not alone in this attack. It is clear that others were attacked and infiltrated recently as well.”

The implications loom large. As the tide has shifted over the past few years and more people have moved to using smartphones and tablets for their computing needs, countless numbers of major companies and organizations have invested heavily in mobile application development. Imagine how many visited the site and could unknowingly be affected.

“It’s the type of forum that anyone who was building apps for mobile devices would visit,” Facebook’s Sullivan told AllThingsD. “It’s pretty popular for sharing tips, tricks, etc.”

So going forward, the question now isn’t which company is next, but rather which one is willing to admit it next.

“I truly believe we’re going to see quite a bit more of these announcements as companies start to get smarter and look more closely at their systems,” Soltani told AllThingsD in a previous interview.

Now, “it’s not a matter of whether or not you’ve been compromised,” Soltani said. “It’s whether you have the expertise to tell.”

Posted from DailyDDoSe

Apple's 128GB iPad Launches Next Week - John Paczkowski - Mobile - AllThingsD

The rumors were true. Apple will soon add another iPad model to its tablet portfolio, this one at the high end of the line. The company said this morning that come Feb. 5 it will begin offering a 128 gigabyte version of the fourth-generation Retina display iPad it announced last fall.

The new device boasts double the storage capacity of the top-of-the-line iPad that preceded it, and a price to match. The 128GB Wi-Fi-only iPad will set you back $799, while a cellular version creeps up on four figures at $929.

That’s a heady price, but one that’s likely not at all off-putting to the markets for which Apple’s latest iPad is intended: Enterprise, medicine and photography. Apple specifically called out those segments in its press release this morning, noting as well that the iPad is being used in “virtually all” Fortune 500 companies, and in more than 85 percent of Global 500 companies. Is it coincidence that the 128GB iPad arrives at market about the same time that Microsoft begins shipping its Surface Pro, which starts out at $899 for 64 GB model? Doubtful.

Today’s 128GB iPad announcement represents another marked shift from Apple’s typical iPad release cycle. Rather than rolling out one big update to the device annually, the company is now making incremental updates to it as it sees fit — just as it would to its Mac line. On that note, the largest iPad now has the same storage as the base model 13-inch MacBook Air …

Posted from DailyDDoSe

Pocket : Apple and world HACKED by Facebook plunderers

Apple and world HACKED by Facebook plunderers

Apple, Facebook and "hundreds of other companies" have had their Mac computers hacked in a sophisticated campaign mounted by an unknown adversary.

Attackers were able to infect Apple, along with other businesses around the world with Mac malware delivered via a Java zero-day vulnerability, Reuters reported on Tuesday, after receiving information from a source at Apple.

The hack used the same Java zero-day and associated Mac malware as the one which Facebook disclosed last week, the Apple source indicated.

Hundreds of companies, including defense contractors, have been infected with the same malicious software, the source said.

"This is the first really big attack on Macs," Reuters's source said, "Apple has more on its hands than the attack on itself."

Apple plans to release a software tool to detect and remove the Java-related malware, the company said in a statement to AllThingsD. Java has not shipped with Macs since the release of OS X Lion.

The Mac malware could have been used to deliver a backdoor onto the computers via the installation of an SSH Daemon, allowing hackers to remotely control parts of the affected system, Finnish virus experts F-Secure indicated in a blog post on Monday.

At the time, they classed the Facebook hack as a "watering hole" attack, which sought to target Facebook users by infecting the company behind the social network.

With the revelations from Apple, it appears the attack could have been part of a widespread hacking campaign against various companies including Facebook and Twitter as well.

At the time of writing Google had not responded to queries about whether it had also been targeted, and Microsoft declined to comment.

The news comes alongside the release of a report on Tuesday that linked the Chinese People's Liberation Army to hackers that have been mounting a "Cold War" style campaign against Western companies.

The report implicated the PLA in a variety of major hacking campaigns that have occurred over the past few years, including 2011's RSA hack that compromised SecurID encryption tokens. ®

Posted from DailyDDoSe

Security flaw allows snoopers to access locked iPhones - CNN.com

Security flaw allows snoopers to access locked iPhones

Doug Gross, CNN

In a YouTube video, a user shows how a nearby phone can be used to bypass an iPhone password to access limited functions.
In a YouTube video, a user shows how a nearby phone can be used to bypass an iPhone password to access limited functions.
STORY HIGHLIGHTS
  • YouTube video appears to show a way to bypass an iPhone password lock
  • The hack lets someone access your phone, contacts list and listen to messages
  • NEW: Apple says it's aware of the problem and a fix is coming

(CNN) -- The passwords on iPhones can be hacked, giving someone the ability to make calls, listen to your recent messages and tinker with your contact list, according to a new video posted to YouTube.

The apparent security flaw is shown on an iPhone 5 and can be exploited on phones running Apple's iOS 6.1, the most recent version of its mobile operating system, and some earlier versions.

The technique was posted by a Spanish-speaking user with the account name "videosdebarraquito," who has posted other videos that show what appear to be ways to tweak settings on the iPhone. CNN is not linking to the video, which was published January 31 but recently discovered by tech bloggers.

It involves using another phone placed nearby to make a call to the phone, canceling it, then answering with the targeted phone and fiddling with the power button.

Apple CEO remains confident with company

Obama: Apple will make Macs in the U.S.

Mark Cuban not bullish on Apple

According to the user who posted the video, it can't be used to access other parts of the phone. And he urged anyone who used it to play nice.

Use the bypass "to joke with your friends. To do a magic show. To win a harmless bet among friends in a PUB. Perhaps, to retrieve a phone number in case you don't remember the password, or just to be warned that exists," the user wrote.

"Use it as you want, at your own risk, but... please... use responsibly, do not use this trick to do evil !!!"

The company said Thursday that it's at work on the problem.

"Apple takes user security very seriously," said spokeswoman Trudy Muller. "We are aware of this issue, and will deliver a fix in a future software update."

The folks at tech blog The Verge tried out the technique, and said they were also able to access photos on the phone by attempting to add a photo to a contact. They were able to access an iPhone 5 that was running iOS 6.1 in the UK, they said.

Similar bugs have been pointed out in previous versions of Apple's mobile operating system. Usually, the company issues a quick update to fix the problem.

Posted from DailyDDoSe

Facebook hacked, says no user data compromised - CNN.com

Facebook hacked, says no user data compromised

Heather Kelly, CNN

Facebook says it has found no evidence that any user information was compromised in a hack last month.
Facebook says it has found no evidence that any user information was compromised in a hack last month.
STORY HIGHLIGHTS
  • Facebook says it was hacked in January when employees visited a compromised website
  • The social network has found no evidence that any user data was obtained by the hackers
  • This is latest in a string of high-profile hacks this year

(CNN) -- Facebook says it was recently hacked, though it says no data about its more than a billion users was compromised.

The company described the "sophisticated attack" in a blog post on Friday, saying it took place in January when a small number of employees visited a compromised website that installed malware on their machines.

"As soon as we discovered the presence of the malware, we remediated all infected machines, informed law enforcement and began a significant investigation that continues to this day," Facebook Security said in the post.

Facebook, the largest social network in the world, is the latest high-profile site to be hacked this year. Twitter announced a similar intrusion earlier this month, and major news organizations including The New York Times, Wall Street Journal and Washington Post have also admitted to being hacked.

The news sites attributed the breaches to hackers working for the Chinese government, but neither Facebook nor Twitter mention China when describing their attacks.

"Facebook was not alone in this attack. It is clear that others were attacked and infiltrated recently as well," said the blog post. "As one of the first companies to discover this malware, we immediately took steps to start sharing details about the infiltration with the other companies and entities that were affected. "

Unlike Twitter, Facebook said it has found no evidence that any user information was compromised. Twitter said that user names, encrypted passwords and e-mail addresses for as many as 250,000 users were potentially grabbed by the hackers. It reset passwords for all affected accounts.

The string of hacks have primarily exploited vulnerabilities in the programming language Java, which is installed on most computers by default. Facebook said the site responsible for its attack took advantage of a previously unknown Java vulnerability, which Oracle patched on February 1.

In January, the Department of Homeland Security issued an alert about the security-challenged software and recommended people turn it off on their computers. Apple turned off Java by default for its OS X users as a precaution. Full instructions on how to disable Java on any computer can be found on Oracle's website. If you must use Java, make sure that you have downloaded the latest updates, which include key security patches.

Facebook said it will continue to work with law enforcement and others in the industry to prevent future attacks.

Posted from DailyDDoSe

Apple: We were hacked, too - CNN.com

(CNN) -- Apple said Tuesday that a small amount of its employees' computers had been hacked, but that no data were exposed.

The company said the breach occurred when some employees visited a developer website that exploited a vulnerability in the Java browser plug-in, installing malware on their Mac computers.

"We identified a small number of systems within Apple that were infected and isolated them from our network. There is no evidence that any data left Apple," the company said in a statement.

Apple did not specify when the hack occurred. The company released a Java patch for OS X users that can be installed from Software Update, and said it's planning on releasing a tool Tuesday that will sweep Mac computers for any Java malware and remove the offending software. Reuters first reported the breach early Tuesday.

The security breach appears to mirror a similar hack at Facebook in January. On Friday, the social network announced it had been the victim of an intrusion after a handful of employees visited a compromised developer site.

Mandiant standing by hacking accusations

Firm: Many hackers attacking from China

New York Times: We were hacked

Apple is the latest high-profile American entity to say it was the victim of a recent cyberattack, following similar admissions by Twitter, The New York Times, The Wall Street Journal, The Washington Post and the U.S. Department of Energy. While the news organizations said they believed hackers in China were responsible for their intrusions, Facebook, Twitter and Apple have not mentioned China by name.

Security company Mandiant published a 60-page report Tuesday linking groups of hackers in China to the Chinese government. The cybersecurity company tracked the attacks to specific networks in Shanghai and some to the headquarters of one of China's secret military groups.

Security holes in Oracle's Java have been responsible for a number of the recent attacks. The Department of Homeland Security released a warning about the software in January.

Apple pointed out in its statement that Macs running the most recent operating system, OS X Lion, have not come with Java pre-installed and that the computers automatically disable the plug-in after 35-days of inactivity.

Posted from DailyDDoSe

Report: Eastern European gang hacked Apple, Facebook, Twitter - CNN.com

Report: Eastern European gang hacked Apple, Facebook, Twitter

Doug Gross, CNN

The hackers appear bent on stealing company secrets to sell on the underground market, according to reports.
The hackers appear bent on stealing company secrets to sell on the underground market, according to reports.
STORY HIGHLIGHTS
  • Cybersecurity expert says most savvy Web crime originates in Eastern Europe
  • Apple, Facebook, Twitter attacks came from Eastern European gang, report says
  • "Water hole" attack apparently used a site for developers on Apple's mobile system
  • Apple said this week that some employees' computers had been compromised

(CNN) -- An Eastern European gang of hackers bent on stealing company secrets was responsible for recent attacks on Apple, Facebook and Twitter as well as dozens of other less-publicized hacks, according to new reports.

Two unnamed "people familiar with the matter" told Bloomberg that the hackers appeared to be looking for research, intellectual property or other private information that they can sell on the underground market.

Apple confirmed Tuesday that some of its employees' computers had been compromised after they visited a hacked website for iPhone developers. That site exploited a vulnerability in the Java browser plug-in.

Weeks earlier, Facebook said that some of its computers were also compromised after employees visited a developer site.

Both Facebook and Apple said no user data were accessed in the attacks.

Earlier in January, Twitter said it, too, was attacked and that about 250,000 user accounts may have been compromised, with names and e-mails possibly being uncovered.

As news of the intrusions spread, suspicions turned toward hackers in China. The nation's government denies it supports hacking.

But experts said it wouldn't be surprising if the attacks originated in Eastern Europe instead.

"We've all been watching China, but they're not the most advanced cybercriminals," said Tom Kellermann, the former commissioner of President Barack Obama's cybersecurity council and head of security at Trend Micro. "The most advanced are from the Eastern Bloc and Russia."

Kellermann said that a "giant arms bazaar" has developed in Eastern Europe by which criminals sell cybertools to others. That way, he said, organized crime elements and even terror groups end up with the same kind of advanced tools some governments possess.

"That's what I'm most worried about," Kellermann said. "I wish this stuff were just nation-state on nation-state, so then we could crank up our diplomacy. But regimes don't have a monopoly on Big Brother, and they don't have a monopoly on cyber capabilities."

The recent hacks appear to have used what cybersecurity experts call a "water hole" attack. Like a lion waiting for those speedy gazelles to slow down and have a drink, criminals hack and load viruses onto sites they suspect attractive targets will visit, then wait.

They don't know exactly who their victims will be. But once the victims are infected, the hackers can follow them back to their own businesses' networks to snoop around.

One site used in the attacks appears to be called iPhone Dev SDK, a forum for developers who work with Apple's mobile operating system.

"iPhoneDevSDK has learned it was used as part of an attack whose victims included large Internet companies," read a message at the top of the site's home page Wednesday. "We have no reason to believe user data (were) compromised, but to be safe, we've reset all user passwords."

Security holes in Oracle's Java programming language have been responsible for a number of the recent attacks. The Department of Homeland Security released a warning about the software in January.

Apple pointed out in its statement that Macs running the most recent operating system, OS X Lion, have not come with Java pre-installed and that the computers automatically disable the plug-in after 35 days of inactivity.

CNNMoney's David Goldman contributed to this report.

Posted from DailyDDoSe

Tuesday, February 19, 2013

A Letter to my Former Therapist by ELyssa Durant, Ed.M. || New York Voice © 2007-2013

A Letter To My Former Therapist
Elyssa D. Durant, Ed.M.
« Article 1 of 29 »

Hi Elyssa,

It's nice to hear from you, I had just been thinking of you. Is there a reason why you sent me two copies? Talk to you soon—Elyssa's Former Therapist

Now how can you call yourself a qualified therapist and ask me such a stupid question? I have at least two of everything!

So my alter-ego as a "cyberwhore" is no longer a secret! I always send duplicate copies of every outgoing e-mail to myself to a number of free-mail accounts. Most have probably expired and I can't even remember most of the passwords to access them, which leads me to wonder what happens to my written works that I have so carefully created? Do they just float around in cyberspace forever? Are my words now immortal? Does that make me grandiose or paranoid?

I had my first appointment with my new psychiatrist on Wednesday and he seems very "eager" to help. He is a very young resident, and I think he is kind of psyched that he got placed at Vanderbilt in Nashville rather than some community mental health center in rural Tennessee. For his training, he needs a number of hours conducting therapy—so I graciously agreed to be one of his guinea pigs. I negotiated a one-hour session every other week.

I hate therapy. It seems so staged and rehearsed. I actually spend hours before a session trying to think of what I should say.

That never seemed to work with you. That kind of annoyed me, because I wanted you to play the game with me. This is the way it is supposed to work: I'll tell you what happened as a child, and you tell me the source of my insanity.

I would try to remember the random things that happen each day and let you know that I was telling you the truth about my life, my world, and my family. On many occasions, I would forget my zinger, my "punch-line" if you will, and I would be so disappointed in myself. I would drop these little tidbits of information hoping you would recognize that I was not completely beyond help, and you might understand the method to my madness. Would that make it okay to be so fucked up? Loony. Crazy. Nuts.

You never once said, "Aha!" Instead, you would listen impatiently as I reflected on childhood traumas. Even the most elaborate reports of my childhood experience did not make you flinch—well, maybe a few times! At what point did you realize that there was some truth in what I was telling you? I would say the same thing over and over because I knew it to be true, to be fact, to be far more cruel and evil than anything I could I make believe as a child. I want to stop playing those games. I am ready to be a person. I am ready to love. I am ready to be "normal."

As I grow, I would like to become more direct, more assertive, and more sure of what I am saying and how it is being received. In the past, I would sit with silence and ambivalence and just fall into situations by default. I don't want complacency to guide me through life. I am not incapable of protecting myself anymore. I hated being such a passive participant in my own life not knowing where I would be living, with whom, and for how long. Learned helplessness. I wonder how things might have been different...if only.

I will never know how events shaped my life and broke my mind. What caused my mind to break? Was I too weak? Was there some point where I should have thrown in the towel and taken my own life? Was there anything, anything I could have done differently to survive? Is there a "normal" breaking point? Did I put up a good fight? Did I do okay?

I want to act with purpose, speak with conviction, and be confident in my decisions. I want to choose action rather than inaction and feel comfortable with the choices I have made. No more ruminating over what I should have, might have, or almost done.

How did you manage to put my mind back together again without knowing what went wrong? Is my head okay? Can I have children?

You were a good therapist, you are a great therapist-- the best!

Posted from DailyDDoSe

Cloud Storage Is Expensive - Erik Caso - Voices - AllThingsD

The cloud has a dirty little secret: It is expensive.

These days, it seems as soon as some new technology begins to gain traction, VCs and journalists herald the arrival of a new technological order. While these predictions often end up being true eventually, many of us are left aggravated that the status quo sticks around for so long. Perhaps no such case is as true as with the cloud. The cloud has, without question, resulted in truly revolutionary benefits to enterprises and consumers, but it always seems to be presented in a very autocratic way: Stop what you are doing, and do things a new way.

Enterprises are obviously the first to accept such requirements. As long as this new solution offers a material benefit to their business, the smart companies will rapidly adopt it and put it to work. Conveniently, they are also quite willing to pay for such benefit, should it be real. This is critical, because consumers hate paying for things, so someone has to underwrite the commoditization of new technology. This is essential to understand because, contrary to what is marketed to consumers, the cloud is expensive.

People are buying and creating unbelievable amounts of content daily, driven by photos, personal videos, music and movie purchases. Movies and personal video have gone from standard definition to high definition — potentially going to ultra-high definition, if CES is any indication — and the trend is clearly moving more toward online purchasing. Music downloads surpassed CD sales two years ago and, even in light of successful streaming services; online music sales continue to grow year over year. Digital photography and videography have also surpassed their physical counterparts. Indeed, photos and videos are no longer things you take only on vacation or on special occasions. Smartphones have enabled us all to shoot photos and video all day long, for even the most mundane reasons. All these devices are continuously increasing resolution, and thus file size.

Gartner estimates that the average household had roughly one terabyte of files by the end of 2012, with that forecast to grow to approximately 3.3TB by 2016. At the same time, it is estimated that people will have, on average, 5.8 Internet-connected devices per person by 2015. There’s no doubt that people will continue to spread more and more data across more and more devices, based on these trends. If these predications are even somewhat accurate, the assumption that the cloud will be able to affordably accommodate all consumer data is difficult to accept.

Cloud storage is not built from hard drives bought off Amazon.com on the cheap. Indeed, whether it is the consumer cloud or the enterprise cloud, cloud storage services are enterprise-grade through and through. “Enterprise-grade” might as well be synonymous with “expensive.” That pricey storage is made up of enterprise-grade hardware, and kept in an enterprise-grade data center. Every step of the way, it is managed by an army of smart people, who are generally well paid. Let’s not forget local and geographic redundancy. The result is that while cloud storage is able to reduce its price slowly over time, consumers are increasing their storage demands on a near-geometric scale. Thus, while consumer cloud services may have a free tier to give consumers a taste of the benefits, virtually none of them offer enough storage to accommodate all the average person’s data. If some company were to cobble together all the necessary Web services to offer this, perhaps built off of Amazon Web Services or Microsoft Azure or something similar, it would cost nearly $1,000 per year in storage alone, and, of course, there is much more to all this than just storage.

The result is “cloud fragmentation” — users are putting subsets of their files into a litany of separate cloud services. Sometimes this is driven by the amount of free storage, and other times this is driven by an optimization of media type (e.g., documents versus videos). This fragmentation, however, increases complexity and becomes a burden to manage. I often have to think about whether a given document is in Dropbox, Google Drive or SkyDrive. My photos are spread across Flickr, Facebook and Instagram. Some videos are on Vimeo and others on YouTube. Of course, these are only a very tiny fraction of my more than 900 gigabytes of files. This complexity is something I refer to as “cloud overload,” where the number of cloud solutions I have has me scratching my head to remember which one I use for what, or to share with whom.

Why would consumers choose to do this? Price. The free tiers of most cloud services are indeed quite alluring. The marketing is great. The benefits are clear. It is the price that’s unacceptable. To mitigate that, consumers do all they can to extract benefit from the free tiers.

This is a clear divergence between consumer demand and technological reality. Cloud storage is too expensive for consumers to purchase for all their data, so they don’t. The result is user data getting spread across an array of primarily free solutions that fragment features by media type or value proposition (e.g., sharing, backup, etc.).

Occasionally, we see enterprises underwriting technological development that does not lead to the technological maturity and commoditization consumers require, at least not very quickly. This is, without exception, the case with the “consumer cloud.” Consumers require simplicity, convenience and affordability. The consumer cloud is built from services, including storage, sharing and device/platform interconnectivity. We’ve seen many companies emerge as tremendous successes; however, the products that define this space are themselves defined by their compromise in regard to consumer demand and expectations. Changes in user behavior (e.g., stop doing what you normally do, and do it a new way) are the friction that slows ubiquitous adoption. Furthermore, high cost ultimately makes such products, even when widely adopted, niche solutions.

Still, cloud services offer such unbelievable benefit that no one would argue that there is not demand. The question is less about what benefit can be derived from the consumer cloud; rather, it is how it should be delivered.

So, what solution have savvy startups begun to offer? It’s what is increasingly known as the “personal cloud”: A way for users to access all their files, on all their devices, all the time. And best of all, it’s affordable.

Personal cloud services for consumers give users the ability to have all their data on all their devices. While not a consumer platform, Amazon Web Services (AWS) provides a good model, since it delivers truly groundbreaking cloud services within a fairly simple service approach. Personal clouds are somewhat analogous to AWS on a consumer level. New personal cloud services have started to build inter-device connectivity into the operating system of your devices, which is conceptually similar to AWS-like services being built into your own computing devices. The result is that instead of users conforming to some new product’s requirements for you to get value, it conforms to the user’s own behavior.

Products like this are technically challenging to build, because they must integrate deeply into some other platform/device; in fact, they often augment it so that the device or operating system itself works in a new way (e.g., as a part of a personal device ecosystem). The result, however, is that consumers are offered a solution that accommodates their demands — one that is simple, convenient and affordable. These services can be cheap or free for any amount of data, whether you have 2GB, 2TB or 2PB, because they are leveraging your own devices to create your cloud and not hardware located in and across multiple data centers.

We all can be overzealous about predicting the future at times, so it is important to take stock of the present. The cloud is producing some of the biggest benefits to enterprises and consumers since the inception of the Internet itself. It is shepherding a variety of services and products that enable content sharing, distribution and access. While enterprises may reap the most advanced benefits of this now, it is obvious that the consumer versions of these technologies are compelling and exciting. The opportunity for companies to innovate is often not measured in features, as much as user experience. This is the unrealized opportunity within the consumer cloud, and the direction so many companies are taking to build the next set of products to affect our lives.

Posted from DailyDDoSe

Facebook Hacked, Claims "No Evidence of User Data Compromised" - Mike Isaac - Social - AllThingsD

Facebook announced on Friday that it had been the target of a series of attacks from an unidentified hacker group, which resulted in the installation of malicious software onto Facebook employee laptops.

“Last month, Facebook security discovered that our systems had been targeted in a sophisticated attack,” the company said in a blog post. “The attack occurred when a handful of employees visited a mobile developer website that was compromised.”

Facebook said that these employees then had malware installed on their laptops as a result of their visiting the website. The hack used what is called a “zero-day Java exploit,” a known vulnerability in Oracle’s software which has gained much attention in recent months. Essentially, anyone visiting a website using this attack who also has Oracle’s Java enabled in their browser was vulnerable. As a result, hackers inserted malware onto the laptops of multiple Facebook employees.

“As soon as we discovered the presence of malware, we remediated all infected machines, informed law enforcement, and began a significant investigation that continues to this day,” the post read.

In the company’s post, Facebook notes that it had “found no evidence that Facebook user data was compromised.”

Facebook did not say what the hackers did have access to, however, after the installation of said malware.

Facebook’s announcement comes on the heels of a string of recent attacks on other major websites. Twitter, the microblogging social network that hosts more than 200 million active users on its service, announced it had been hacked two weeks ago, and that upward of 250,000 user accounts may have been compromised as a result.

facebook-haloOther targets have included the Washington Post, the New York Times and The Wall Street Journal, all of which have said they believe that the Chinese government was somehow involved in their system infiltration.

But both Facebook and Twitter, in their respective blog posts, made no accusation or direct comparison to the hacks made on the Times, the Journal or the Post.

Facebook declined to comment when asked if the company suspected the Chinese government was involved.

Something to note, however: Facebook directly points to the zero-day exploit, which takes advantage of Oracle’s Java vulnerability, as the root cause of the attack. While Twitter did not detail the exact methods of how its systems were infiltrated, Twitter director of information security Bob Lord reminded users that security experts strongly recommend turning off the problematic Java inside of their browsers.

That could suggest that the two attacks were connected, though neither company says as much outright. But both Facebook and Twitter included language in their posts that their respective companies were part of a larger series of attacks on multiple companies over the past few months.

“Facebook was not alone in the attack. It is clear that others were attacked and infiltrated recently as well,” the company’s post says.

Twitter did not immediately respond to a request for comment.

The string of hacks also come as U.S. President Barack Obama recently released an executive cybersecurity order during his State of the Union address earlier this week, which would better allow government agencies to share information related to cyber-espionage and attacks within the private sector, while avoiding many of the unpopular concessions that the previously proposed CISPA made.

For now, however, Facebook will continue its investigation with law enforcement, as well as pursue its own “informal” cooperative investigation with others in the space.

“As one of the first companies to discover this malware, we immediately took steps to start sharing details about the infiltration with the other companies and entities that were affected. We plan to continue collaborating on this incident through an informal working group and other means.”

Posted from DailyDDoSe

Apple Says It, Too, Was Attacked by Hackers - Ina Fried - News - AllThingsD

Apple said Tuesday that a small number of its employees’ computers were hacked through a vulnerability in the Java browser plug-in, but said none of its internal data was compromised.

The flaw was also used to compromise Macs at other companies, including a recently disclosed attack at Facebook.

“Apple has identified malware which infected a limited number of Mac systems through a vulnerability in the Java plugin for browsers,” the company said in a statement to AllThingsD. “The malware was employed in an attack against Apple and other companies, and was spread through a website for software developers. We identified a small number of systems within Apple that were infected and isolated them from our network. There is no evidence that any data left Apple. We are working closely with law enforcement to find the source of the malware.”

The company noted that it has been shipping Macs without Java since the release of Mac OS X Lion, and that it also has a software mechanism that disables Java if it goes unused for 35 days. Apple is also releasing an updated software tool to detect and remove Java-related malware.

On Friday, Facebook confirmed that it was a victim of a targeted attack last month.

Such attacks have been on the rise, with many government agencies and companies saying that they have been targeted.

The attack on Apple employee computers was reported earlier on Tuesday by Reuters.

Posted from DailyDDoSe

FBI May Be Collaborating With Facebook Following Hack | Fast Company

FBI May Be Collaborating With Facebook Following Hack

The governmental crime fighters have been called in over reports that user data may have been compromised.

About This Series

Reuters is reporting that the FBI has been called in following last week's hacking of Facebook. Although the firm hasn't confirmed it itself--the social media giant claims that there is no evidence that user data has been compromised--anonymous sources are saying that the feds have been brought in for further digging.

The social media giant didn't release the news until late Friday evening, saying that they had fallen victim to a "sophisticated" attack. It is thought that the malware originated from a suspicious website visited by a Facebook employee, but was only discovered after the URL was flagged as suspicious. The news comes just weeks after a quarter of a million Twitter accounts were hacked, and both the New York Times and Wall Street Journal revealed that their computer systems were constantly being attacked by Chinese hackers.

[Image by Flickr user Tom in NYC]

Posted from DailyDDoSe

Facebook Says It Was The Target Of A "Sophisticated" Attack | Fast Company

Facebook Says It Was The Target Of A "Sophisticated" Attack

Though an investigation is still ongoing, the company says there is no evidence to suggest its user data was compromised as a result of the attack.

About This Series

Facebook has just announced it was "targeted in a sophisticated attack" in January. The company says there is currently no evidence to suggest that Facebook's user data was compromised.

The social giant says the attack occurred after several Facebook employees visited a compromised website that allowed malware to install itself on those employee laptops.

Facebook is the latest in a string of high-profile companies that have recently reported themselves as victims of cyber attacks, including Twitter, the New York Times, and the Wall Street Journal.

Facebook says it is currently working with internal and external security teams and law enforcement authorities in an ongoing investigation.

[Image: Flickr user Danny Sullivan]

Posted from DailyDDoSe

Apple Suffers Major Security Breach | Fast Company

Apple Suffers Major Security Breach

The same hackers behind an attack on Facebook last week infected an unknown amount of Apple Inc.'s corporate computers.

About This Series

Apple suffered a major security breach last week when China-linked hackers infiltrated an unknown number of corporate computers. In a short statement given to Reuters' Jim Finkle and Joseph Menn, Apple representatives said that an unknown number of employee Macs had been breached but that “there was no evidence any data left Apple.” According to Reuters, Apple was attacked by the same hackers who attacked Facebook, who were later linked to China. There are unconfirmed rumors that the FBI is helping Facebook investigate their own hack.

What could be more alarming to many is there is evidence that the hackers who attacked Apple exploited a security breach in iOS and Mac OS. Apple said they are releasing a patch on Tuesday that will protect customers against the worm used in the attack. On late Monday night, the New York Times] announced that they tracked the source of a recent hacker attack to the People's Liberation Army.

[Image: Wikimedia user Denis Pl]

Posted from DailyDDoSe

Like Facebook, Apple Says It Was Attacked By Hackers : The Two-Way : NPR

People walk past the Apple logo at the Apple Store at Grand Central Terminal in New York.

Timothy A. Clary /AFP/Getty Images
People walk past the Apple logo at the Apple Store at Grand Central Terminal in New York.

People walk past the Apple logo at the Apple Store at Grand Central Terminal in New York.

Timothy A. Clary /AFP/Getty Images

Apple said today that the computers of some of its employees were attacked by hackers, who used the same vulnerability to access computers at Facebook.

All Things D reports:

"'Apple has identified malware which infected a limited number of Mac systems through a vulnerability in the Java plugin for browsers,' the company said in a statement to AllThingsD. 'The malware was employed in an attack against Apple and other companies, and was spread through a website for software developers. We identified a small number of systems within Apple that were infected and isolated them from our network. There is no evidence that any data left Apple. We are working closely with law enforcement to find the source of the malware.'

"The company noted that it has been shipping Macs without Java since the release of Mac OS X Lion, and that it also has a software mechanism that disables Java if it goes unused for 35 days. Apple is also releasing an updated software tool to detect and remove Java-related malware."

Last week, Facebook said their systems had been breached in January. Both companies said that no user data had been compromised.

Reuters points out one of the interesting quirks of this hack: This is the "highest-profile cyber" attack to target Mac computers.

"Hackers have traditionally focused on attacking machines running the Windows operating system, though they have gradually turned their attention to Apple products over the past couple of years as the company gained market share over Microsoft Corp.," Reuters reports.

This news comes the same day that an American security company revealed it had connected hacks targeting 141 American companies to the Chinese government.

Posted from DailyDDoSe

Apple and world HACKED by Facebook plunderers

Use a Mac? Have Java? You might have been pwned

Free whitepaper – IDC Report: Lost in the Cloud? Automate with Cisco

Apple, Facebook and "hundreds of other companies" have had their Mac computers hacked in a sophisticated campaign mounted by an unknown adversary.

Attackers were able to infect Apple, along with other businesses around the world with Mac malware delivered via a Java zero-day vulnerability, Reuters reported on Tuesday, after receiving information from a source at Apple.

The hack used the same Java zero-day and associated Mac malware as the one which Facebook disclosed last week, the Apple source indicated.

Hundreds of companies, including defense contractors, have been infected with the same malicious software, the source said.

"This is the first really big attack on Macs," Reuters's source said, "Apple has more on its hands than the attack on itself."

Apple plans to release a software tool to detect and remove the Java-related malware, the company said in a statement to AllThingsD. Java has not shipped with Macs since the release of OS X Lion.

The Mac malware could have been used to deliver a backdoor onto the computers via the installation of an SSH Daemon, allowing hackers to remotely control parts of the affected system, Finnish virus experts F-Secure indicated in a blog post on Monday.

At the time, they classed the Facebook hack as a "watering hole" attack, which sought to target Facebook users by infecting the company behind the social network.

With the revelations from Apple, it appears the attack could have been part of a widespread hacking campaign against various companies including Facebook and Twitter as well.

At the time of writing Google had not responded to queries about whether it had also been targeted, and Microsoft declined to comment.

The news comes alongside the release of a report on Tuesday that linked the Chinese People's Liberation Army to hackers that have been mounting a "Cold War" style campaign against Western companies.

The report implicated the PLA in a variety of major hacking campaigns that have occurred over the past few years, including 2011's RSA hack that compromised SecurID encryption tokens. ®

Free whitepaper – IDC Report: Lost in the Cloud? Automate with Cisco

Posted from DailyDDoSe