Pages

Wednesday, July 22, 2015

The Ashley Madison hack is a goldmine for criminals

There have been hundreds of articles written on the Ashley Madison hack this week, as I'm sure you've probably seen. If for some reason you haven't, this site offers users the opportunity to setup sexual affairs with other registered users in secret. The personal messages, profiles, email addresses and credit card numbers have been stolen and are being held for ransom, which is truly sensitive information if you're one of the millions of users, 37 million to be exact, that's looking to have an affair on line and using their services to assist with cheating. The group that stole the information is requesting that the site and their affiliates be taken down or they'll release the cache of info.

No matter how you feel about the site itself, I personally think it's a despicable way to make money, there are some major ramifications at play here that aren't part of a normal data breach. The people that are responsible aren't using the credit cards or selling them, that we know of, and are requesting that the site be taken down. This is a different response from what we normally see when large eCommerce sites have been compromised. At this point the attackers don't seem to be financially motivated, which makes them even more unpredictable.

There's also the aspect of having very personal data potentially being spewed across the internet showing these users infidelity in very public ways. Once this happens there are a few things I can forsee happening:
  • Privacy lawsuits against Ashely Madison for the users that were told their personal information would be removed after their accounts were deleted. These records are going to show up in divorce courts now for the next couple years. This data was supposed to be private and has now been made public for the world to see. The divorce lawyers are going to love this. 
  • Once this list makes its way to the internet the first thing someone's going to do is create a searchable database with credit card, name, email address, etc. for people to search and see if their partners were cheating on them. This will surely happen and relationships will suffer due to this site. Not that these people wouldn't have had affairs without the site, but offering it as a service, while being hacked, is doubly wrong. 
  • Blackmail will happen at large levels. People will be found on the data dump and be told that they'll rat to their spouse unless they pay them. This is bound to happen and could be worse if criminals start using this data to spur cyber espionage (E.G Someone in a pharmacutcial firm is found to be on the list and cyber criminals offer to tell their spouse unless they start giving out trade secrets, etc, etc, etc).
This site was about being secret and fooling around behind your partners back. It turns out that's exactly what's happening to them now (oh the irony). It also shows that if you have something private, no matter what it is, you can't trust a third party to hold your secrets. If there's sensitive information being sent up to a site that you don't manage completely, assume that it will be lost or breached. Make your digital decisions based off this risk approach.


Thursday, July 16, 2015

Steve Jobs Thoughts on Flash


This morning I came across Steve Jobs thoughts on why he despised Adobe Flash, which is widely documented, but I thought due to all the Flash bashing that’s occurred over the past week it was worth sharing. The man was an absolute visionary and I wonder what thoughts he’d have towards Flash now since vendors are finally starting to take action on what he started five years ago. Unless I’m mistaken, Steve Jobs, and Apple, were the first to take a stand against Flash by not allowing it to run on their mobile devices. We need more people with the stubbornness and forward thinking of Steve Jobs to take stands, like Mozilla did earlier in the week, even when at  times it goes against a giant cooperation or flies in the face of what’s considered an industry standard. Many times change comes when one person takes a stand against a particular issue for the greater good. This is also commonly called leadership.

Here’s a snippet from Steve Jobs open letter about Adobe flash. This was written over five years ago and only now are people standing up to take action against Flash. In his open letter to Adobe he hits on six reasons why Apple won’t run Flash on mobile devices. His third reason for alienating Flash from Apple mobile devices is security, take a look at what he said: 

Third, there’s reliability, security and performance.

Symantec recently highlighted Flash for having one of the worst security records in 2009. We also know firsthand that Flash is the number one reason Macs crash. We have been working with Adobe to fix these problems, but they have persisted for several years now. We don’t want to reduce the reliability and security of our iPhones, iPods and iPads by adding Flash. 

With this open letter to Adobe, does it really take over five years for us to start acting? If you want to read the entire letter, and I recommended you do, you can find it here: https://www.apple.com/hotnews/thoughts-on-flash/

Wednesday, July 15, 2015

Opening Up Blog to Guest Posts

A few summers ago I opened up my blog to guest contributors and some great content, that might not have gone public, came to light under these guest blogs. With that being said, for the remainder of the summer, if you have a security article you'd like to post, research you'd like to share, news that you'd like to break, etc. please contact me at matthewpascucci@protonmail.ch and we can discuss the details.

Look forward to working with you!!

Building Security into DevOps


I really think this is a huge idea.  Anytime you can take collaboration from other groups and wrap security around it, security wins. It’s having a seat at the table that’s really what’s most important these days. There might not be a surge in productivity right away, but things like this take time to fester and before long you’re being asked if what’s being rolled out is secure. This will however bring many things past your desk that you wouldn’t have otherwise realized. Which is a good thing, right?

Take a look at the article I wrote for Algosec about the benefits security has while being inserted into the DevOps cycle. Also, if you haven’t read the book: “The Phoenix Project”, check it out.

Tuesday, June 16, 2015

Protonmail Open For All

I've been a huge fan of Protonmail since first reading about what they were trying to accomplish last year. In short, they're looking to create free, encrypted email that doesn't leave the encryption keys out of your control. So many encrypted email providers have been bullied by governments to give up their keys or shut down, but it's impossible for this to occur with Protonmail, because they don't keep both keys. Brilliant!!

The biggest problem with Protonmail was the enrollment process. Which took me multiple months to be assigned an account on their system. This was most likely due to limited resources and funds, so you can imagine my excitement when I received the below email from Protonmail. If you haven't already signed up for an account, what are you waiting for!! GO FOR IT!!

To celebrate our 1 year anniversary, we are upgrading all accounts created by June 17th, 2015 to 1GB of free storage! Many of you have also asked for a way to share ProtonMail with friends and family. To do that, we have created a special link that allows instant account creation: 
https://protonmail.ch/privacyforall 

You can send this link to friends and family and they will be able to get a ProtonMail account instantly. As our server capacity is still limited, we will only keep this link active until June 17th, 2015 (or until we hit capacity limit). Also after June 17th, all new accounts will default to 500MB of free storage. 

Over the past year, ProtonMail has proven to be reliable with less than 12 hours of total downtime (mostly scheduled maintenance), no incidents of permanent data loss, and no reports of user data compromise. Over that same period, the ProtonMail user community has grown from 10,000 to 500,000 people. 

As you know, we respect your privacy and do not track detailed user activity. Therefore, to continue to improve ProtonMail, we need to rely on direct feedback from you and would love to hear your suggestions or criticisms in the following survey: 
https://blog.protonmail.ch/feedback 

Many of the improvements mentioned in the survey will be coming soon. In the past few months alone, we have added new features like folders/labels, encrypted attachments, the protonmail.com domain, and more: https://blog.protonmail.ch/protonmails-new-features-guide 

We look forward to continuing this exciting journey with you! 

Best regards, 
The ProtonMail Team 

We believe privacy is a fundamental human right which is why we are supported by donations instead of advertisements. If you would like to support us, please visit:https://protonmail.ch/donate 


Tuesday, June 2, 2015

Ten Guaranteed Ways NOT to Think Securely


We've gone over this subject a few times, but not it great detail. It's for this reason I'm going to dedicate an entire article to the subject. If you're following compliance only, you're not doing your job. There you have it, I said it. This is a blunt way of saying, be security minded, before following compliance and just hoping for the best. Now I know there are many people out there who want to follow security first, but aren't allowed to. This article isn't for you. This is for the people that look at compliance as their only means of protection. There are plenty of businesses doing this now with security minded people grudgingly attempting to push them through the muck and mire of the compliance-only ideology. The next ten, tongue in cheek, warnings are for those who are stuck in a compliance-only frame of mind. So for those that don't want to move forward and understand that compliance will not protect you when the attackers come calling, here are ten ways to cement your position as a compliance-only, non-security minded practitioner.

  1. Don't ever look past the compliance standard – When you ask a question to an auditor about why something needs to be done a certain way, take their word for it. Never ask why, or if you can be creative about your architecture. Follow their every word and wait on them with baited breath. They’re professionals after all, and you're paying them good money. How could they be wrong?
  1. Believe you are secure with only compliance – Only malicious and nefarious attacks happen to large companies. You're not on their radar right now, so you'll most likely skate free without being noticed. What are the odds? These things only happen to ultra-large organizations anyway; you're safe to sleep well at night. 
  1. Never use compliance as a way to increase security awareness – Just because you have the ability use compliance to put your security program on the map, doesn't mean you should take advantage of this. Make sure no one outside your team is aware of what you are doing and keep these things to your self. 
  1. Make sure you select easy assessors – We know that not all assessors are created equal. Make sure you do your due diligence and select the vendor that's going to give you your corporate compliance the quickest. Don't have assessors come in that will challenge the status quo, which could push you into a security mindset. You wouldn't like that. And above all things make sure the assessor brings their rubber stamp. 
  1. Always use the same assessors every year – The best way to quickly pass compliance is to have the same set of eyes on your environment every year. This will increase the speed that you receive your precious compliance, since your habitual assessor has already beaten this path, and it will make the process ever so much easier.
  1. Be content with checking the boxes – Once you have every check box securely filled in, you can be almost absolutely sure that you're safe from attack. The assessors’ job is to make sure you're hacker proof and they're normal never wrong. Make sure you put full faith in the compliance standard, as well as the assessor in place to bring you into their compliant beliefs. 
  1. Don't worry about security unless an audit is underway – Security all year is hard. Make sure you only become interested in it while an assessment is underway. Since you're using the same assessor that was chosen for looseness, it shouldn't be hard to pass an assessment even while only being concerned for a few weeks out of the year. No one has time to be secure all year round, so don't be too hard on yourself. 
  1. Never include out-of-scope systems into your thinking – Make sure you're only concerned with systems that are being audited, because that's really all that matters. The systems that are out of scope are just that, out of scope. They're not important and even if an attacker somehow got through your assessor-approved bulletproof architecture, they wouldn't care anyway. All the juicy systems are in scope and those are the only one's that should be protected. The rest are just hangers-on and should be dealt with when you have time, but it's not urgent. 
  1. By all means, don't be proactive – Being proactive with your thinking will eventually bleed over to being secure, which after all, is what we're trying to avoid. Pushing for new technology and procedure could quickly get out of control. If you start being proactive it's going to affect all your systems; and we only want in-scope systems, remember? Do only as you're told and don't look for ways to improve.
  1. Make sure management knows compliance is most important – You're management is ultimately in control of what happens to your program, so don't bring up risks outside of those that might effect your ability to comply with the standard. They shouldn't be consulted or told about other risks to the environment. They're so very busy anyway, so why even bother them. Make sure that they are effectively lulled into a compliant mindset so that they're not awakened into worrying about security. This could ruin the compliant-only program you've worked so hard to achieve.

By following these ten sure-fire steps you'll become the best compliant-minded practitioner on the face of the planet. Follow them well and treat them like the compliance standard itself, but be very careful. If you feel yourself asking questions, or even having doubts about these ten steps, you're on your way towards being security minded. And for someone that's stuck in a compliance-only mindset this can be very dangerous. It will have you start thinking outside the box and worrying about the security of your entire infrastructure. Be careful, stay the course.