Pages

Friday, July 24, 2015

Urgent Wordpress vulnerability....again.

Honestly, I've considered moving this blog away from Blogger many times, which it's hosted on, but it's constant Wordpress vulnerabilities, like these, that always dissuades me from moving forward.

Maybe one day.

The Salvation of Incident Response


Wednesday, July 22, 2015

The Ashley Madison hack is a goldmine for criminals

There have been hundreds of articles written on the Ashley Madison hack this week, as I'm sure you've probably seen. If for some reason you haven't, this site offers users the opportunity to setup sexual affairs with other registered users in secret. The personal messages, profiles, email addresses and credit card numbers have been stolen and are being held for ransom, which is truly sensitive information if you're one of the millions of users, 37 million to be exact, that's looking to have an affair on line and using their services to assist with cheating. The group that stole the information is requesting that the site and their affiliates be taken down or they'll release the cache of info.

No matter how you feel about the site itself, I personally think it's a despicable way to make money, there are some major ramifications at play here that aren't part of a normal data breach. The people that are responsible aren't using the credit cards or selling them, that we know of, and are requesting that the site be taken down. This is a different response from what we normally see when large eCommerce sites have been compromised. At this point the attackers don't seem to be financially motivated, which makes them even more unpredictable.

There's also the aspect of having very personal data potentially being spewed across the internet showing these users infidelity in very public ways. Once this happens there are a few things I can forsee happening:
  • Privacy lawsuits against Ashely Madison for the users that were told their personal information would be removed after their accounts were deleted. These records are going to show up in divorce courts now for the next couple years. This data was supposed to be private and has now been made public for the world to see. The divorce lawyers are going to love this. 
  • Once this list makes its way to the internet the first thing someone's going to do is create a searchable database with credit card, name, email address, etc. for people to search and see if their partners were cheating on them. This will surely happen and relationships will suffer due to this site. Not that these people wouldn't have had affairs without the site, but offering it as a service, while being hacked, is doubly wrong. 
  • Blackmail will happen at large levels. People will be found on the data dump and be told that they'll rat to their spouse unless they pay them. This is bound to happen and could be worse if criminals start using this data to spur cyber espionage (E.G Someone in a pharmacutcial firm is found to be on the list and cyber criminals offer to tell their spouse unless they start giving out trade secrets, etc, etc, etc).
This site was about being secret and fooling around behind your partners back. It turns out that's exactly what's happening to them now (oh the irony). It also shows that if you have something private, no matter what it is, you can't trust a third party to hold your secrets. If there's sensitive information being sent up to a site that you don't manage completely, assume that it will be lost or breached. Make your digital decisions based off this risk approach.


Thursday, July 16, 2015

Steve Jobs Thoughts on Flash


This morning I came across Steve Jobs thoughts on why he despised Adobe Flash, which is widely documented, but I thought due to all the Flash bashing that’s occurred over the past week it was worth sharing. The man was an absolute visionary and I wonder what thoughts he’d have towards Flash now since vendors are finally starting to take action on what he started five years ago. Unless I’m mistaken, Steve Jobs, and Apple, were the first to take a stand against Flash by not allowing it to run on their mobile devices. We need more people with the stubbornness and forward thinking of Steve Jobs to take stands, like Mozilla did earlier in the week, even when at  times it goes against a giant cooperation or flies in the face of what’s considered an industry standard. Many times change comes when one person takes a stand against a particular issue for the greater good. This is also commonly called leadership.

Here’s a snippet from Steve Jobs open letter about Adobe flash. This was written over five years ago and only now are people standing up to take action against Flash. In his open letter to Adobe he hits on six reasons why Apple won’t run Flash on mobile devices. His third reason for alienating Flash from Apple mobile devices is security, take a look at what he said: 

Third, there’s reliability, security and performance.

Symantec recently highlighted Flash for having one of the worst security records in 2009. We also know firsthand that Flash is the number one reason Macs crash. We have been working with Adobe to fix these problems, but they have persisted for several years now. We don’t want to reduce the reliability and security of our iPhones, iPods and iPads by adding Flash. 

With this open letter to Adobe, does it really take over five years for us to start acting? If you want to read the entire letter, and I recommended you do, you can find it here: https://www.apple.com/hotnews/thoughts-on-flash/

Wednesday, July 15, 2015

Opening Up Blog to Guest Posts

A few summers ago I opened up my blog to guest contributors and some great content, that might not have gone public, came to light under these guest blogs. With that being said, for the remainder of the summer, if you have a security article you'd like to post, research you'd like to share, news that you'd like to break, etc. please contact me at matthewpascucci@protonmail.ch and we can discuss the details.

Look forward to working with you!!

Building Security into DevOps


I really think this is a huge idea.  Anytime you can take collaboration from other groups and wrap security around it, security wins. It’s having a seat at the table that’s really what’s most important these days. There might not be a surge in productivity right away, but things like this take time to fester and before long you’re being asked if what’s being rolled out is secure. This will however bring many things past your desk that you wouldn’t have otherwise realized. Which is a good thing, right?

Take a look at the article I wrote for Algosec about the benefits security has while being inserted into the DevOps cycle. Also, if you haven’t read the book: “The Phoenix Project”, check it out.