What do hackers look like?
Boingboing's Rob Beschizza surveyed stock photos of hackers from Shutterstock and Reuters - the writeup should make security professionals and hackers laugh...and wince.
Boingboing's Rob Beschizza surveyed stock photos of hackers from Shutterstock and Reuters - the writeup should make security professionals and hackers laugh...and wince.
Posted by
David
at
9:17 PM
0
comments
Labels: security humor
Most people in the security world - and many Internet users - have read over the past two weeks about the possible exposure of LastPass's password database. Since LastPass (which I've written about before) is a cloud password management tool, this was a major cause for concern, despite the fact that the passwords were salted - which would make them harder to figure out - many users still use poor passwords which could be easily retrieved.
The good news is that LastPass did a lot of things right, starting with their first blog post: "We noticed an issue yesterday and wanted to alert you to it. As a precaution, we're also forcing you to change your master password." They went on to explain why they were worried "we saw a network traffic anomaly for a few minutes from one of our non-critical machines" and "we found a similar but smaller matching traffic anomaly from one of our databases in the opposite direction (more traffic was sent from the database compared to what was received on the server)".
They explained what this might mean: "We know roughly the amount of data transfered and that it's big enough to have transfered people's email addresses, the server salt and their salted password hashes from the database. We also know that the amount of data taken isn't remotely enough to have pulled many users encrypted data blobs."
Best of all, they then explained who might be in danger: "If you have a strong, non-dictionary based password or pass phrase, this shouldn't impact you - the potential threat here is brute forcing your master password using dictionary words, then going to LastPass with that password to get your data. Unfortunately not everyone picks a master password that's immune to brute forcing."
They even note that they're not sure that the whole thing is an actual issue - but that they want to do the right thing: "We realize this may be an overreaction and we apologize for the disruption this will cause, but we'd rather be paranoid and slightly inconvenience you than to be even more sorry later."
Since then, LastPass has done a lot more things right and they've described it on their blog. They've done everything from providing frequent updates to trying to make sure that any future issues are handled properly. They've analyzed the mistakes they've made, and have acted to correct them, and have implemented a number of improvements to their infrastructure, design, and their overall processes.
Some of the things that I'm happiest to see are:
Posted by
David
at
8:29 PM
0
comments
The AP and other news sources are reporting that BP lost a laptop containing the personal information of 13,000 people who applied for compensation for damages. The laptop was unencrypted, but was password protected. BP has sent notification letters to those effected.
This is just another reminder that laptop encryption makes life easier...and may even cost less than notification letters!
Posted by
David
at
5:15 PM
0
comments
Labels: BP, laptop encryption, ssn exposure
The purported Comodo hacker has posted a number of documents on pastebin. The hacker claims to have used API access to generate the certificates mentioned in
Comodo has also recently announced that two additional resellers were also breached.
The documents are well worth a read to understand how web based infrastructure services might be breached, and where we might expect to see attacks in the future. API accessibility and vulnerable servers make for a nasty combination when a trust based infrastructure is in play.
Posted by
David
at
9:11 PM
0
comments
Labels: Comodo hack
Forensic Psychology's "How To Spot A Liar" infographic is a great overview of what research shows liars do - and don't when asked questions.
Posted by
David
at
5:15 PM
0
comments
Labels: how to spot a liar, psychology of security
Here's a recent example of a secret shopper scam. Like many scams, this one attempts to lure people who think that accidentally receiving a secret shopper invitation is a way to free money. In the end, it is merely an attempt at identity theft - though it may also involve a fee scam as well!
If the recipient bothers to check who it is from, it purports to come from Dow Chemical, with an email address that is recruit@hsbrv.net, with a cc to david212@blumail.org. The hsbrv.net domain points back to a Betty Prevo, with an email address listing mark212@blumail.org. That sounds suspiciously like our david212 address as well. The whois results are below:
Administrative Contact:For those who are interested, that address points to an apartment building in Chicago. Interestingly, Betty Prevo apparently exists and does live in that area in Chicago, but she'd probably be interested to find out that she's running various domains.
Prevo, Betty mark212@blumail.org
1368 X W. Estes Ave
Chicago, Illinois 60626
United States
Hello there,Note that the name actually somewhat matches the email address - that's often a missed detail for our scammers.
My Name is David Anderson and I am your group regional Instructor from within the USA.Henceforth you will be working with me on the completion of your Mystery Shopper's Position application. Like you already know, your weekly per assignment is $300:00 Flat for working with us and will come in payments of $300 each per assignment you complete for the company.
PAYMENT TERMS:Free money, and what sounds like a somewhat reasonable reason why the company would want you to do this. The grammar is even better than most letters of this type.
Your payment would be sent ($300) per assignment , Also the company is in charge of providing you with all expense money for the shopping and other expenses incurred during the course of your assignment.All the tools you will needing would be provided to you with details every week you have an assignment.
JOB Description :
1} When an assignment is given to you,You would be provided with details to execute the assignment and in a timely fashion.
2} You would be asked to visit a company or store in your area and they are mostly our competitors as a secret shopper and shop with them to know more about their sales and stock , cost sales and more details as provided by the company then report back to us with details of whatever transpired a the store. But anything you buy at the shop belongs to you,all we want is an effective/quick job and reports.
ASSIGNMENT PACKET :It starts to fall apart here with lines like "Then we would be providing you details on here".
Before any assignment we would provide you with the resources needed {cash}Mostly our company would send you a check which you can cash and use for the assignment. Included to the check would be your assignment packet .Then we would be providing you details on here. But you follow every single information given to you as a secret shopper .
KINDLY RECONFIRM YOUR INFORMATION BELOW TO PROCEED ON FIRST ASSIGNMENT:And that's the anatomy of a secret shopper scam. A simple way to hook the gullible into providing details for identity theft.
Full Legal Name :
Full Physical Address :
City :
State :
Zip code :
Age:
Nationality :
Home and Cell # :
Present Occupation:
Email:
Thank you for reading.
Yours sincerely.
Contact Person: David Anderson
Time: 24 Hours daily by e-mail
Posted by
David
at
11:49 AM
0
comments
Labels: identity theft, secret shopper scams
EMC's RSA division announced that they had been hacked and it appears that they're doing the right thing for their customers by telling them. From their announcement:
"Our investigation also revealed that the attack resulted in certain information being extracted from RSA's systems. Some of that information is specifically related to RSA's SecurID two-factor authentication products. While at this time we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers, this information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack."If you're a current SecurID customer, you'll likely want to keep track of this as further detail is released. RSA notes that they expect to release details to the community -
"As appropriate, we will share our experiences from these attacks with our customers, partners and the rest of the security vendor ecosystem and work in concert with these organizations to develop means to better protect all of us from these growing and ever more sophisticated forms of cyber security threat."I'll post further detail as it becomes available.
Posted by
David
at
12:30 PM
0
comments
Labels: advanced persistent threat, RSA, SecurID