Thursday, July 29, 2010

Blackhat, ATMs, and Money Fountains, Oh My!

Security blogs and websites are all buzzing with the news of Barnaby Jack's Blackhat demonstration of ATM insecurity. Wired has coverage, our favorite security monkey has a video, and others including Tony Bradley from PC World covers the important lessons from the talk.

So does the hack tell us something truly new? I don't really think so. For years, many ATMs have been poorly embedded systems, often running commodity operating systems that rely more on physical security provided by locked boxes than on heavily secured operating systems with appropriate security controls. I've written about the insecurity of some ATM uplinks before, and accessing their network connection is often very simple in public locations.

What the exploit does do is serve to point out vulnerabilities in the specific ATMs, both of which were running Windows CE. It also serves as a reminder that any operating system that can be remotely accessed, or that allows its filesystem to be written, or to mount USB devices is vulnerable. Since many ATMs run Windows XP, or even Windows NT, they make attractive targets to those who have pre-written malware that works on Windows systems.

It should also remind us to review what devices we rely on that have embedded PC platforms in them. Windows CE, NT, XP, and various flavors of Linux appear throughout our IT infrastructure, and while we're used to locking down network access, often embedded devices don't provide strong local security. I've run into everything from AV controllers and music players to embedded systems running animal feeding systems for research. Most of the time, my only ability to secure them is to lock them away, limit access to the room they live in, and to ensure that they're on a secured network.

How do you secure your embedded systems? Have you gone so far as to modify appliances that manufacturers don't want changed?

Friday, May 21, 2010

O'Reilly Book Deal - Get Security and Other Ebooks Cheap Today

O'Reilly has a coupon available for today only that makes any one ebook in their store $10. If you're like me and like to have an electronic edition handy, this is a great deal for books that are updated and searchable. Their security books can be found here. You'll want to use coupon code "FAVFA".

Tuesday, May 18, 2010

Check Facebook Privacy Settings with ReclaimPrivacyRights.org's Scanner Bookmarklet


ReclaimPrivacyRights.org provides a simple bookmarklet that works simply by loading it when you visit your Privacy settings page on Facebook. Simple, neat, and it appears to be a neat way to get a basic checkup. Better, the source code is available for review.

Thursday, May 13, 2010

Facebook Friend Suggestions - Not a Virus!

Facebook status updates are quickly being populated with warnings that the suggest a friend notes that are appearing in users inboxes are virus driven. They're not - in fact, Facebook has released a notice that AllFacebook.com posted stating

"This is neither a bug nor a virus, and the “Virus Alert” status update is incorrect. Friend suggestions are now mutual and will appear for both users involved. That is, if I suggest that one person become friends with another, both the person I suggested and the person to whom I sent the suggestion will receive the notification."
The fact that the Facebook populace quickly communicates about a potential issue is good - the fact that false information is spreading quickly is not as good - but I'd rather my users avoid a fake virus than not avoid a real one.

Sunday, May 9, 2010

Experiments in Security: Magstripe Reading Using Rust Particles

Tetherdcow via BoingBoing has a great science experiment to try with magstripes on credit cards and other ID cards: using rust particles to read the magstripe. This looks like a great hands on and visible way to talk about how data is encoded when teaching students.

Tuesday, May 4, 2010

Opting out of Facebook's Instant Personalization



The EFF as a quick look at how to opt out of Facebook's new Instant Personalization capabilities. Of note, you must block ALL of the Instant Personalization websites if you use them, rather than just setting one master setting. They provide both written steps and a video, as well as a suggestion on how to make your voice heard about this new "feature".

Monday, May 3, 2010

Security Humor: McAfee's...Quicktart?

A search for McAfee's QuickStart HealthCheck service today resulted in the following listing:


Yes, that says Quicktart. I'll avoid McAfee QA jokes, but the actual page title does currently list their Quicktart service!

No news on whether other fast pastries will be in their continued product offerings...