Millions of accounts from various websites have been exfiltrated and shared online.
Some of the largest compromises of personal accounts, include 359 million MySpace accounts, 164 million LinkedIn accounts, 152 million Adobe accounts, 65 million tumblr accounts, but the list goes on.
Despite all these high profile comprises being reported in the news; have you ever wondered if any of these compromised accounts were yours?
You can check here: https://haveibeenpwned.com/
This is a website created by Troy Hunt, a Regional Director at Microsoft and more information about him can be found here.
Showing posts with label Data Privacy. Show all posts
Showing posts with label Data Privacy. Show all posts
Wednesday, 1 June 2016
Tuesday, 19 April 2016
Apple vs FBI: End of the battle, not the war [Link - CRN]
An article I wrote around the FBI trying to break into an Apple iPhone was published on CRN: http://www.channelweb.co.uk/crn-uk/opinion/2454969/apple-vs-fbi-end-of-the-battle-not-the-war
===================
The biggest story coming out of Silicon Valley over last few months has been Apple's battle with the FBI over a federal order to unlock the iPhone of the San Bernardino shooter. The recent news that the FBI has found a way to break into the phone without Apple's help brings no resolution to the issue of how far governments can go to examine private communications data such as messages and photos.
Apple's refusal to help the FBI has set in motion a wider debate about privacy and security in the digital age. Supporters of the government say that Apple has a duty to support crime fighting agencies and that Apple has cooperated in the past to unlock phones.
The issue, however, is about more than unlocking a phone. It's about ordering Apple to create a new software tool to eliminate the software it specifically created in 2014 to protect customer data. This has huge implications for the future of privacy.
Tech companies say they turn over the customer data they have when legally required to do so. But digital companies are determined to protect customers' privacy against unwarranted intrusion and many are increasingly using encryption and other safeguards that put customer data out of their reach.
Unanswered questions
Heightened terrorist threats have led to governments around the world looking at how they can renew their assault on digital encryption, and revive efforts to force companies to install backdoors in secure products.
However, digital companies are showing a steely resolve. This is a core issue that's incredibly important for customers who value privacy and the tech industry are determined to protect it.
In the latest move, many privacy advocates will have welcomed the news that Whatsapp has announced encryption by default on its messaging platform. The Facebook-owned company, which is used by over a billion people worldwide, added end-to-end encryption to its chat and call functionality, which means that messages can only be read by the intended recipients.
It is difficult to overstate the importance of this move for the security and privacy of ordinary users. In one swoop, there are now hundreds of millions of users communicating with each other using end-to-end encryption for the very first time.
Finding the right balance
For governments and law enforcement, the issue centers around this: what do you do when a company creates an encryption system that makes it impossible for court-authorised search warrants to be executed? And what is the reasonable level of assistance you should ask from that company?
Governments need to be careful that they are not being seen as attempting to collect as much data on every citizen as possible. At the height of the FBI dispute, Apple's Tim Cook talked about the possibility of a shocking future in which the company is forced to write and install a program on a suspect's phone that would help police turn on the iPhone's video camera.
It's a dangerous situation and one that not only potentially undermines consumers' trust, but also the entire tech industry and the democratic freedom we are entitled to.
What's next?
After finding its own way to access files on the San Bernardino iPhone, the US Justice Department said it no longer needs a court order to force Apple to remove safeguards against guessing that iPhone's passcode. It has become clear that this only serves to prolong the issue because we've lost the opportunity to have the courts resolve the issue of online privacy once and for all.
No-one has really won from this dispute. For Apple, the fact that the FBI actually hacked the iPhone doesn't sound good for its security credentials. For the FBI, it has lost credibility because no-one really bought the idea that it was only about one phone, and there's a feeling that it's been less than straightforward about its motivations for taking Apple to court.
The battle over encryption goes back decades and is sure to go on. There are concerns that authorities may now go after a smaller company, without the high profile and financial resources of Apple, to win a legal precedent that would bind the whole industry.
Whatever comes next, the tech industry must stand together to safeguard privacy and security in the digital age.
===================
The biggest story coming out of Silicon Valley over last few months has been Apple's battle with the FBI over a federal order to unlock the iPhone of the San Bernardino shooter. The recent news that the FBI has found a way to break into the phone without Apple's help brings no resolution to the issue of how far governments can go to examine private communications data such as messages and photos.
Apple's refusal to help the FBI has set in motion a wider debate about privacy and security in the digital age. Supporters of the government say that Apple has a duty to support crime fighting agencies and that Apple has cooperated in the past to unlock phones.
The issue, however, is about more than unlocking a phone. It's about ordering Apple to create a new software tool to eliminate the software it specifically created in 2014 to protect customer data. This has huge implications for the future of privacy.
Tech companies say they turn over the customer data they have when legally required to do so. But digital companies are determined to protect customers' privacy against unwarranted intrusion and many are increasingly using encryption and other safeguards that put customer data out of their reach.
Unanswered questions
Heightened terrorist threats have led to governments around the world looking at how they can renew their assault on digital encryption, and revive efforts to force companies to install backdoors in secure products.
However, digital companies are showing a steely resolve. This is a core issue that's incredibly important for customers who value privacy and the tech industry are determined to protect it.
In the latest move, many privacy advocates will have welcomed the news that Whatsapp has announced encryption by default on its messaging platform. The Facebook-owned company, which is used by over a billion people worldwide, added end-to-end encryption to its chat and call functionality, which means that messages can only be read by the intended recipients.
It is difficult to overstate the importance of this move for the security and privacy of ordinary users. In one swoop, there are now hundreds of millions of users communicating with each other using end-to-end encryption for the very first time.
Finding the right balance
For governments and law enforcement, the issue centers around this: what do you do when a company creates an encryption system that makes it impossible for court-authorised search warrants to be executed? And what is the reasonable level of assistance you should ask from that company?
Governments need to be careful that they are not being seen as attempting to collect as much data on every citizen as possible. At the height of the FBI dispute, Apple's Tim Cook talked about the possibility of a shocking future in which the company is forced to write and install a program on a suspect's phone that would help police turn on the iPhone's video camera.
It's a dangerous situation and one that not only potentially undermines consumers' trust, but also the entire tech industry and the democratic freedom we are entitled to.
What's next?
After finding its own way to access files on the San Bernardino iPhone, the US Justice Department said it no longer needs a court order to force Apple to remove safeguards against guessing that iPhone's passcode. It has become clear that this only serves to prolong the issue because we've lost the opportunity to have the courts resolve the issue of online privacy once and for all.
No-one has really won from this dispute. For Apple, the fact that the FBI actually hacked the iPhone doesn't sound good for its security credentials. For the FBI, it has lost credibility because no-one really bought the idea that it was only about one phone, and there's a feeling that it's been less than straightforward about its motivations for taking Apple to court.
The battle over encryption goes back decades and is sure to go on. There are concerns that authorities may now go after a smaller company, without the high profile and financial resources of Apple, to win a legal precedent that would bind the whole industry.
Whatever comes next, the tech industry must stand together to safeguard privacy and security in the digital age.
Thursday, 24 March 2016
A matter of privacy [Link - ITProPortal]
An article I wrote around the FBI trying to break into an Apple iPhone was published on ITProPortal: http://www.itproportal.com/2016/03/24/a-matter-of-privacy/
============================
============================
When Apple recently refused to comply with a federal court order issued by the FBI to help it break into an iPhone 5c, belonging to one of the shooters in the San Bernardino incident, a US House Judiciary Committee hearing was held.
If a ruling is made in favour of the FBI, Apple will have to weaken the encryption of its iPhone operating system, allowing the FBI to gain access to data on any iPhone. Apple’s chief executive, Tim Cook described this as the “software equivalent of cancer.”
Detrimental to future security
Apple’s argument is that if it is forced to write such software, it would open the floodgates to constantly writing spy tools for law enforcement. Cook gave the example of being forced to write and install a program on a suspect’s phone that would help police turn on the iPhone’s video camera. It would also seriously undermine Apple’s business, which has been partly built on the security of its proprietary software.
Inevitably, the iPhone would be weakened, leading to an operating system that could be carved open by those with the means and the will. It would open the sluice gate for other parties to break into iPhones and we’re not just talking hackers and online crime outfits, but also foreign intelligence agencies.
Widespread support
In a measure of just how serious the issue is, over 40 organisations are backing Apple’s case, including many tech companies. In short, Silicon Valley is on Apple’s side. There are also many tech companies who are not throwing their weight into the case but are quietly in support of Apple.
Microsoft, Facebook, Google, Dropbox and Snapchat are expected to sign on to briefs in the case, in support of Apple. Although not directly involved in the case, concerned parties can add additional weight, context, and information to an argument via a legal vehicle known as an amicus brief. Even the United Nations High Commissioner for Human Rights, Zeid Ra’ad Al Hussein has weighed in on the side of Apple.
Generally, there is a widespread feeling that if the FBI won it would be disastrous for the tech industry and the overall freedom of citizens. In the wake of the Edward Snowden revelations, there is an informed and widespread understanding that this case isn’t about a single iPhone; it’s about the future and the protection of safety and privacy.
Of course, the Apple FBI case also foreshadows what could happen in the UK, should the draft Investigatory Powers Bill be approved in its current form. This bill also wants to compel technology companies to produce products that are capable of having their encryption bypassed.
Draconian powers
In the UK, like in the US, it’s not only civil rights groups who are concerned, it’s the tech community too. As it stands, if the bill is passed, it would mean that the UK has one of the most draconian surveillance laws of any democracy, via mass surveillance powers to monitor every citizen’s browsing history.
The government seems intent on rushing the bill through with home secretary Theresa May wanting the bill on the statute books by December 2016. Three parliamentary committees have already made many criticisms about the draft bill suggesting a large number of recommendations are required to safeguard privacy. The government responded by adding ‘privacy’ into the title of the first chapter and apparently leaving the text virtually unchanged.
Impossible data searches
There are also questions as to whether the bill in its current state is actually possible to implement. Part of the bill legally requires ISPs to archive connections a device makes to the Internet and hold that data for a minimum of a year. Nobody for certain can say how much data that is but one thing is for certain, it is an enormous amount. Just think of one single video on YouTube that gets 10 million hits in the UK. That’s just one Internet link.
How much untargeted data would be collected and how do you decide what is useful and not useful?
Undermining foundations
It seems that as dust of outrage settles post-Snowden, governments and law enforcement on both sides of the Atlantic are ramping up their ambition to collect as much data on every citizen as possible, without thinking through the implications.
It’s a dangerous situation and one that, not only potentially undermines consumer’s trust, but also the entire tech industry and the democratic freedom we are entitled to. Security agencies can still do their job without resorting to mass surveillance just as the FBI could access the data in the San Bernardino iPhone should it wish to do so.
Freedom of speech is a fundamental right in Western democracies, as well as privacy, but the desire to weaken encryption actually weakens the foundations on which our societies are built.
Thursday, 7 January 2016
The dark web & business report: A seedy Dickensian underworld online [Link - IDG Connect]
I was asked to comment how the dark web could impact on businesses, and was fortunate enough to have them published in an IDG Connect artcle.
http://www.idgconnect.com/abstract/11383/the-dark-web-business-report-a-seedy-dickensian-underworld-online
==============
It is obviously imperative that businesses can secure themselves against any threat. And as the latest wave of breaches have proved, whilst most organisations spend money on traditional perimeter security, many fail to properly protect their biggest asset, their data.
“Personal Identifiable Information (PII) should be encrypted,” says Andrew Tang, Service Director, of Security at MTI Technology. This would make any information unreadable to the perpetrator.
“Many of the recent attacks, which have allowed thousands of records to be stolen have been achieved by using SQL Injection attacks,” he adds. “If information needs to be accessible to the internet, ensure OWASP standards are followed, the website is tested by a penetration testing organisation and critical data is encrypted.”
http://www.idgconnect.com/abstract/11383/the-dark-web-business-report-a-seedy-dickensian-underworld-online
==============
It is obviously imperative that businesses can secure themselves against any threat. And as the latest wave of breaches have proved, whilst most organisations spend money on traditional perimeter security, many fail to properly protect their biggest asset, their data.
“Personal Identifiable Information (PII) should be encrypted,” says Andrew Tang, Service Director, of Security at MTI Technology. This would make any information unreadable to the perpetrator.
“Many of the recent attacks, which have allowed thousands of records to be stolen have been achieved by using SQL Injection attacks,” he adds. “If information needs to be accessible to the internet, ensure OWASP standards are followed, the website is tested by a penetration testing organisation and critical data is encrypted.”
Tuesday, 20 October 2015
"Hunted" - Technology View [Link - MTI Bytes]
A piece I wrote has been edited and used on the work blog: http://www.mtibytes.com/post/Hunted-A-technology-view
===================================
Channel 4’s new reality show Hunted has gripped my attention since the first episode launched 6 weeks ago. I'm particularly surprised by the amount of surveillance there is in the UK, allowing people to be traced or ‘hunted’ using data from mobile phone and ATM usage, number plate recognition, and CCTV footage. What I've found more concerning however, is the oblivious nature of the contestants to the digital footprint they are leaving, not dissimilar to the naivety of employees when it comes to safeguarding corporate data.
So, in a world driven by technology, how do you protect your personal and corporate digital footprint?
1. Manage your devices
Gone are the days of owning one mobile device, we live in a society where people juggle a plethora of devices at any given time. The mobile phone in particular has become the hub of many people’s lives; 66 per cent of people now own a smartphone. In a short period of time the mobile phone has evolved to support all work and personal activity from sharing files to tracking fitness goals, as well as still holding its primary function of making calls.
Ensuring your device is backed up regularly, is one way to manage its contents and protects it against damage or thief. Backing up the device’s applications and data to a public cloud service safeguards contents but also adds an additional layer of security to your data.
2. Password protect
Irrespective of the abundance of recent security hacks, the show brings attention to the amount of people that still don’t have any security on their devices. Without any security measures, others can immediately access the device as well as personal and corporate data. Securing accounts with a password is an essential step to protecting data.
Using complex and different passwords across various accounts and devices also tightens security. Where possible, a two-step verification or authentication is preferable.
Applications such as KeePass can help remember any complex passwords you have.
3. Control browser history
If Internet anonymity is important, tools like the TOR network provide users with ability to hide identity and usage. Internet performance and connectivity can be affected by products such as TOR, therefore consider if the perceived cost of your history is worth it.
Browsers can also be set to delete search either automatically or manually, as the search history is automatically cached. Most browsers have a secret search feature, whereby the history is not stored and neither are cookies. The issue with cookies is that the information is read by other services, often to advertise to. Remember, Internet history will never truly be private, as ISP will track sites visited.
4. Information control
The revelation of social media is leading to a generation of over-sharers. Think about the information you want on the Internet. Imagine what could happen if an unscrupulous person had access to your private information and what they could do with that information? Sharing information you may use for added security protection such as pet names etc. invites security threat.
It is essential to have prevention tools in place to control your digital footprint and to stop yourself from being ‘hunted’.
===================================
Channel 4’s new reality show Hunted has gripped my attention since the first episode launched 6 weeks ago. I'm particularly surprised by the amount of surveillance there is in the UK, allowing people to be traced or ‘hunted’ using data from mobile phone and ATM usage, number plate recognition, and CCTV footage. What I've found more concerning however, is the oblivious nature of the contestants to the digital footprint they are leaving, not dissimilar to the naivety of employees when it comes to safeguarding corporate data.
So, in a world driven by technology, how do you protect your personal and corporate digital footprint?
1. Manage your devices
Gone are the days of owning one mobile device, we live in a society where people juggle a plethora of devices at any given time. The mobile phone in particular has become the hub of many people’s lives; 66 per cent of people now own a smartphone. In a short period of time the mobile phone has evolved to support all work and personal activity from sharing files to tracking fitness goals, as well as still holding its primary function of making calls.
Ensuring your device is backed up regularly, is one way to manage its contents and protects it against damage or thief. Backing up the device’s applications and data to a public cloud service safeguards contents but also adds an additional layer of security to your data.
2. Password protect
Irrespective of the abundance of recent security hacks, the show brings attention to the amount of people that still don’t have any security on their devices. Without any security measures, others can immediately access the device as well as personal and corporate data. Securing accounts with a password is an essential step to protecting data.
Using complex and different passwords across various accounts and devices also tightens security. Where possible, a two-step verification or authentication is preferable.
Applications such as KeePass can help remember any complex passwords you have.
3. Control browser history
If Internet anonymity is important, tools like the TOR network provide users with ability to hide identity and usage. Internet performance and connectivity can be affected by products such as TOR, therefore consider if the perceived cost of your history is worth it.
Browsers can also be set to delete search either automatically or manually, as the search history is automatically cached. Most browsers have a secret search feature, whereby the history is not stored and neither are cookies. The issue with cookies is that the information is read by other services, often to advertise to. Remember, Internet history will never truly be private, as ISP will track sites visited.
4. Information control
The revelation of social media is leading to a generation of over-sharers. Think about the information you want on the Internet. Imagine what could happen if an unscrupulous person had access to your private information and what they could do with that information? Sharing information you may use for added security protection such as pet names etc. invites security threat.
It is essential to have prevention tools in place to control your digital footprint and to stop yourself from being ‘hunted’.
Wednesday, 30 September 2015
“Hunted” - A technology view
How many of you have been watching Hunted on Channel 4? I have been an avid viewer since the first episode and have to say it was an eye opener. I was surprised how much surveillance there is in the UK, allowing people to be traced by mobile phone and ATM usage, number plate recognition, CCTV footage, but more concerning the digital footprint people were leaving, where every step could be traced.
Mobile
The mobile phone has become the hub of many people’s lives, in a short period of time of being a device to make calls, it could then send text messages and play Snake, to being the hub of all communications, such as work email, personal email, social media, text and picture messages, video calls, tracking our movements for fitness, our music, video and photograph repositories, and we sometimes even use them for telephone calls!
I know that if I misplace my mobile phone, I’m at a loss, but that’s probably the subject of another blog post. In the show, they talk about phone tapping and triangulation, but more concerning was how people didn’t have any security on their devices, allowing access immediately onto the device.
Smartphones are lost or damaged on a seemingly regular basis, but thankfully there is the option to back up the device’s applications and data to a public cloud service. This functionality is offered by the main operating system providers, such as Google, Apple and Microsoft, as well as manufacturers such as HTC. This can only be a good thing, except if someone has access to your password, where the backup can be restored. This would give access to text messages, browser history, and other private and sensitive information.
Email
Unless you are paranoid or technical, you probably have a web based email account provided by Google, Microsoft, Yahoo, etc, as the convenience of a web based email account outweigh any benefits of running your own mail server for your own domain.
Internet based services are easy to reach offering convenience, but also means that you are open to have your account compromised by a hacker. On the show, one email account where access was gained immediately as the password was saved by the browser.
A recent episode showed the use of a phishing attack, where a seemingly legitimate email was sent with a link, which led to a website asking for a password. As most people use the same password for multiple websites, having one password can open access to many online accounts.
Google searches
In the show, internet searches were used to discover what the user was researching prior to being hunted.
I’ve never been worried about what I’ve been searching for on the internet, but if you are, there are privacy services offered by the major browsers. Although it will mean that your searches are not cached and no cookies will be stored, the provider and the ISP (Internet Service Provider) you’re using will know, as they have to deliver this service.
If Internet anonymity is important, the using tools like the TOR network, utilising their software and thousands of routers, there is the ability to hide identity and usage. This can be great for privacy, but can be a threat to national security.
Social media
The internet revelation of social media allowed to find our friends and share information. For people to find you, you have to place a certain amount of information on the internet, but many people over share, leaving a lot of information about themselves on the internet.
The researchers on the show used internet searches to see what they could find about the subject. When that wasn't enough they also used the users devices for access to social media accounts, where again passwords were either saved by the browser or written down on a piece of paper nearby.
Location Services
The ability for your apps to have location information improves the app experience. One of the primary uses is for mapping, allowing the device to be located on a map. It’s not commonly know that location services are typically switched on for a mobile phone camera. This has a use if you are taking a photograph to share on social media, telling everyone where the photograph was taken. The downside, the properties of the photograph shows the location, which many not be useful if you don’t want people knowing where the photograph was taken.
I haven’t seen this used on the show, but would have been useful in locating people beyond the mobile phone triangulation and number plate recognition.
Protecting Mobile Devices
Smartphones are ubiquitous, but are incredibly powerful devices we have in our pockets. I met someone recently who didn't trust smartphones so has a non-smart mobile phone. There are some simple measures that can be used to protect the device.
Create a PIN or password for the device. Yes, it can be a pain to have that, but it’s protecting the device and the contents. You will be able to set the device to wipe itself if the incorrect PIN/password is entered incorrectly a number of times.
Ensure your device is backed up regularly, so even if the device is lost or stolen, the data won’t be. The password for this cloud storage and cloud backup account must have a strong password, and there is often the option to use two-step verification where a code is sent via SMS to the registered mobile device. If it’s too easy for you to access the account, it’s too easy for a hack to access it as well.
Protecting Email
Sounds like simple advice, but harder to execute. Use different complex passwords for each of your online accounts, don’t allow your browser to remember the passwords, and switch on two step or two factor authentication where possible.
There are applications to help remember the complex passwords, but a popular one, KeePass was recently discovered to have a security flaw. Just don't write down your passwords and certainly don't keep them next to your computer or tablet!
As ever, ensure the sites asking for your passwords are legitimate sites, and simply delete anything that looks “fishy”!
Protecting Browser History
Browsers can be set to delete search either automatically or manually, as the search history is automatically cached. Most browsers will have a secret search feature, where the history is not stored and neither are cookies, typically created when visiting a website. The issue with cookies, is that they can be read by other services. For example if you search for a computer game, you will see on subsequent websites advertisements for that game. This information is stored on a cookie and being read by advertising services. Keep in mind that sites visited will be tracked by ISP delivering the content, so the Internet history will never truly be private.
TOR can provide anonymity to the user, but the traffic and content can be seen on the exit node and performance can be poor, due to the bandwidth available. It certainly won't offer the media and feature rich Internet experience we've come to expect. If you have something to hide TOR maybe the way forward, but the sacrifice may not be worth it.
Protecting Social Media
Think about what information you want about your out on the internet. Imagine if anyone could have full access to your profile, what could an unscrupulous person do with that information? Is your password made up of your favourite team, band, child’s name, mother’s maiden name, pet’s name, etc? Then think if that information is on your public profile? Set privacy settings to ensure on the people you want can see the information you want them to.
Protecting Location Information
If you need to hide your location, but want to use Social Media? Check the location services and whether they are enabled on your applications, especially your mobile/tablet apps. Check the settings for your camera as well. Even if location services are stopped on Social Media, the properties of the photograph can still have the location of where it was taken, if the feature has not been disabled on the camera.
Hunted?
If you are really being hunted, then this is only basic advice, but much like the IT security adage, “It’s not if, but when you’re hacked”, it may well be; it’s not if they find you, but when!
Mobile
The mobile phone has become the hub of many people’s lives, in a short period of time of being a device to make calls, it could then send text messages and play Snake, to being the hub of all communications, such as work email, personal email, social media, text and picture messages, video calls, tracking our movements for fitness, our music, video and photograph repositories, and we sometimes even use them for telephone calls!
I know that if I misplace my mobile phone, I’m at a loss, but that’s probably the subject of another blog post. In the show, they talk about phone tapping and triangulation, but more concerning was how people didn’t have any security on their devices, allowing access immediately onto the device.
Smartphones are lost or damaged on a seemingly regular basis, but thankfully there is the option to back up the device’s applications and data to a public cloud service. This functionality is offered by the main operating system providers, such as Google, Apple and Microsoft, as well as manufacturers such as HTC. This can only be a good thing, except if someone has access to your password, where the backup can be restored. This would give access to text messages, browser history, and other private and sensitive information.
Unless you are paranoid or technical, you probably have a web based email account provided by Google, Microsoft, Yahoo, etc, as the convenience of a web based email account outweigh any benefits of running your own mail server for your own domain.
Internet based services are easy to reach offering convenience, but also means that you are open to have your account compromised by a hacker. On the show, one email account where access was gained immediately as the password was saved by the browser.
A recent episode showed the use of a phishing attack, where a seemingly legitimate email was sent with a link, which led to a website asking for a password. As most people use the same password for multiple websites, having one password can open access to many online accounts.
Google searches
In the show, internet searches were used to discover what the user was researching prior to being hunted.
I’ve never been worried about what I’ve been searching for on the internet, but if you are, there are privacy services offered by the major browsers. Although it will mean that your searches are not cached and no cookies will be stored, the provider and the ISP (Internet Service Provider) you’re using will know, as they have to deliver this service.
If Internet anonymity is important, the using tools like the TOR network, utilising their software and thousands of routers, there is the ability to hide identity and usage. This can be great for privacy, but can be a threat to national security.
Social media
The internet revelation of social media allowed to find our friends and share information. For people to find you, you have to place a certain amount of information on the internet, but many people over share, leaving a lot of information about themselves on the internet.
The researchers on the show used internet searches to see what they could find about the subject. When that wasn't enough they also used the users devices for access to social media accounts, where again passwords were either saved by the browser or written down on a piece of paper nearby.
Location Services
The ability for your apps to have location information improves the app experience. One of the primary uses is for mapping, allowing the device to be located on a map. It’s not commonly know that location services are typically switched on for a mobile phone camera. This has a use if you are taking a photograph to share on social media, telling everyone where the photograph was taken. The downside, the properties of the photograph shows the location, which many not be useful if you don’t want people knowing where the photograph was taken.
I haven’t seen this used on the show, but would have been useful in locating people beyond the mobile phone triangulation and number plate recognition.
Protecting Mobile Devices
Smartphones are ubiquitous, but are incredibly powerful devices we have in our pockets. I met someone recently who didn't trust smartphones so has a non-smart mobile phone. There are some simple measures that can be used to protect the device.
Create a PIN or password for the device. Yes, it can be a pain to have that, but it’s protecting the device and the contents. You will be able to set the device to wipe itself if the incorrect PIN/password is entered incorrectly a number of times.
Ensure your device is backed up regularly, so even if the device is lost or stolen, the data won’t be. The password for this cloud storage and cloud backup account must have a strong password, and there is often the option to use two-step verification where a code is sent via SMS to the registered mobile device. If it’s too easy for you to access the account, it’s too easy for a hack to access it as well.
Protecting Email
Sounds like simple advice, but harder to execute. Use different complex passwords for each of your online accounts, don’t allow your browser to remember the passwords, and switch on two step or two factor authentication where possible.
There are applications to help remember the complex passwords, but a popular one, KeePass was recently discovered to have a security flaw. Just don't write down your passwords and certainly don't keep them next to your computer or tablet!
As ever, ensure the sites asking for your passwords are legitimate sites, and simply delete anything that looks “fishy”!
Protecting Browser History
Browsers can be set to delete search either automatically or manually, as the search history is automatically cached. Most browsers will have a secret search feature, where the history is not stored and neither are cookies, typically created when visiting a website. The issue with cookies, is that they can be read by other services. For example if you search for a computer game, you will see on subsequent websites advertisements for that game. This information is stored on a cookie and being read by advertising services. Keep in mind that sites visited will be tracked by ISP delivering the content, so the Internet history will never truly be private.
TOR can provide anonymity to the user, but the traffic and content can be seen on the exit node and performance can be poor, due to the bandwidth available. It certainly won't offer the media and feature rich Internet experience we've come to expect. If you have something to hide TOR maybe the way forward, but the sacrifice may not be worth it.
Protecting Social Media
Think about what information you want about your out on the internet. Imagine if anyone could have full access to your profile, what could an unscrupulous person do with that information? Is your password made up of your favourite team, band, child’s name, mother’s maiden name, pet’s name, etc? Then think if that information is on your public profile? Set privacy settings to ensure on the people you want can see the information you want them to.
Protecting Location Information
If you need to hide your location, but want to use Social Media? Check the location services and whether they are enabled on your applications, especially your mobile/tablet apps. Check the settings for your camera as well. Even if location services are stopped on Social Media, the properties of the photograph can still have the location of where it was taken, if the feature has not been disabled on the camera.
Hunted?
If you are really being hunted, then this is only basic advice, but much like the IT security adage, “It’s not if, but when you’re hacked”, it may well be; it’s not if they find you, but when!
Tuesday, 10 February 2015
Sweating Like a Moonpig and Other Data Security Lessons
Here is an article I was asked to write for a magazine regarding the Moonpig incident, which was republished on the work blog here: http://www.mtibytes.com/post/Sweating-Like-a-Moonpig-and-Other-Data-Security-Lessons
=============
It has now been widely publicised that Moonpig, one of the UK’s largest personalised greeting card companies, had a major security vulnerability in its website, which remained unfixed for 17 months. Despite being notified, the company chose not to act for the better part of 2014, leaving the personal data of 3 million customers (including partial credit card details) exposed to the public.
The vulnerability in question is fairly basic and relates to the way individual users are authenticated. For months, the lack of authentication in place allowed access to any users’ accounts by connecting with the Moonpig servers via the API and simply tweaking the customer ID numbers sent in API requests. Without any further authentication, this tactic could have been replicated by hackers 3 million times with a simple piece of software in order to steal personal data, including names, addresses, and credit card details.
Widespread consequences
One critical lesson from Moonpig’s vulnerability is that data security does not end when the user logs off. Often all that is needed to take control of someone’s entire digital life is a billing address and the last four digits of an associated credit card number. Once a threat is identified, inaction on the part of the service provider can prove just as devastating as causing a security hole in the first place. Moonpig may not have directly leaked their customers’ data, however they made that data directly accessible to any eager parties, capable of writing some simple code.
The ramifications aside, Moonpig severely jeopardised its customers’ trust. As custodians of customer data, companies that process payments have an ethical obligation to fix basic security issues within a reasonable timeframe. Moreover, they have a legal obligation to protect that data. In the case of Moonpig, Price should have contacted an enforcement authority like the Information Commissioner instead of going public with the vulnerability.
Next steps
Moonpig’s API vulnerability highlights an area that is poorly documented and routinely overlooked in security testing, but there are easy steps that can mitigate against this threat, such as patching operating systems, applications, and known vulnerabilities. When developing code, many organisations believe that a code review or penetration test is sufficient on application completion, however developed applications are often a work in progress, with many subsequent bug fixes, code changes, additional features, and functions added. It is thus necessary to have on-going code reviews during the development cycle, with a code review and penetration test on completion at each stage. In effect, the code review has to be as agile as the development itself.
Many threats and vulnerabilities reside within organisations for months or even years before discovery, and when they are revealed, it is often a third party that blows the whistle. Even after several warnings of the code vulnerability within its Android application, Moonpig seemingly chose to do nothing to resolve the issue. From banks to greeting card companies, when customers give out their data they trust that the vendor will take appropriate measures to encrypt and safeguard their personal information. As the threat landscape changes, many organisations do not seem to have the agility to uphold this implicit trust.
=============
It has now been widely publicised that Moonpig, one of the UK’s largest personalised greeting card companies, had a major security vulnerability in its website, which remained unfixed for 17 months. Despite being notified, the company chose not to act for the better part of 2014, leaving the personal data of 3 million customers (including partial credit card details) exposed to the public.
The vulnerability in question is fairly basic and relates to the way individual users are authenticated. For months, the lack of authentication in place allowed access to any users’ accounts by connecting with the Moonpig servers via the API and simply tweaking the customer ID numbers sent in API requests. Without any further authentication, this tactic could have been replicated by hackers 3 million times with a simple piece of software in order to steal personal data, including names, addresses, and credit card details.
Widespread consequences
One critical lesson from Moonpig’s vulnerability is that data security does not end when the user logs off. Often all that is needed to take control of someone’s entire digital life is a billing address and the last four digits of an associated credit card number. Once a threat is identified, inaction on the part of the service provider can prove just as devastating as causing a security hole in the first place. Moonpig may not have directly leaked their customers’ data, however they made that data directly accessible to any eager parties, capable of writing some simple code.
The ramifications aside, Moonpig severely jeopardised its customers’ trust. As custodians of customer data, companies that process payments have an ethical obligation to fix basic security issues within a reasonable timeframe. Moreover, they have a legal obligation to protect that data. In the case of Moonpig, Price should have contacted an enforcement authority like the Information Commissioner instead of going public with the vulnerability.
Next steps
Moonpig’s API vulnerability highlights an area that is poorly documented and routinely overlooked in security testing, but there are easy steps that can mitigate against this threat, such as patching operating systems, applications, and known vulnerabilities. When developing code, many organisations believe that a code review or penetration test is sufficient on application completion, however developed applications are often a work in progress, with many subsequent bug fixes, code changes, additional features, and functions added. It is thus necessary to have on-going code reviews during the development cycle, with a code review and penetration test on completion at each stage. In effect, the code review has to be as agile as the development itself.
Many threats and vulnerabilities reside within organisations for months or even years before discovery, and when they are revealed, it is often a third party that blows the whistle. Even after several warnings of the code vulnerability within its Android application, Moonpig seemingly chose to do nothing to resolve the issue. From banks to greeting card companies, when customers give out their data they trust that the vendor will take appropriate measures to encrypt and safeguard their personal information. As the threat landscape changes, many organisations do not seem to have the agility to uphold this implicit trust.
Thursday, 25 September 2014
Securing the virtual you
I blogged recently about the Cyber Kill Chain where I look at each of the steps. Many of the steps can be dealt with using technology, except one stage, the reconnaissance stage.
LinkedIn
Twitter
Facebook
Who's the target?
As the bad guys need to be more specific in targeting individuals, research is the key. Knowing who someone works for, who their friends are, their hobbies and pastimes, they all help construction a picture of the target. If you know your target, you can try to exploit it by sending emails with specific topics and links to lure your target to click on a link which can compromise their machine.Spear-Phishing
People who are normally target to a "spear-phishing" (if phishing is a wide indiscriminate attack to get users details, spear phishing is targeting a very group or an individual person) are people who will have more rights than a typical user. Why? Well I mentioned in previous posts that a compromise will involve administrative credentials 100% of the time. So the target will often be members of the executive team (who often have more rights than a user) or members of the IT team.Research/Googling?
How would I find out more about someone? Use Google (other internet search engines are available) and search for them. As an example, I'll use me and see what's available out there...
The second hit is for LinkedIn and most of the posts that follow are for a Singaporean racing driver (I'll give you a hint, I'm not a racing driver!). For those who are unfamiliar with LinkedIn, it's a social networking site for "professionals" effectively giving a CV online.
So following the link, it takes me to a number of people called Andrew or Andy Tang internationally, but LinkedIn handily gives a link at the top to refine this list to Andrew or Andy Tangs based in the United Kingdom.
So if you knew who I worked for (MTI by the way), then you'd know to click on the top link. If you didn't, then you probably won't target me! So now I can see a public profile of Andrew Tang, and even without a LinkedIn account I can gather a lot of information.
Now you know who I work for and have worked for, along with people who I must be linked with in some fashion, as people looking for my profile have also looked at these profiles. That already creates links with people or organisations I would potentially trust, or would not find odd if I received a communication from them. Additional information such as company websites and blogs may also be there and give more clues.
Google+/Blogger
Following out to the blog, it can be seen that the URL to my blog (that you're reading by the way, thank you) is http://blog.andytang.com which gives us similar information to the LinkedIn profile, as well as a link to my public LinkedIn profile. There is also a link to my Google+ profile as the blog use Blogger which is a Google company.
Information we already have like company and LinkedIn details. There is a link to Twitter, along with some people who have put me in their circles. Again, more people that I would not find odd if I received communications from them. Let's follow the link to Twitter...
No real insights here, except that I say I live in Surrey. That may have been assumed as current and previous employers are in Surrey as well.
WhoIs?
Maybe time to get a little cleverer! We know the domain I own andytang.com, so there must be some information around that domain. A WhoIs will find out who has registered this domain:
No real information here either!
I've tried looking for a Facebook page, but struggle to find myself, even if I spread the net wider with more information than can be found above. None of the profiles below are me, but then I have locked down my privacy settings.
I thought I'd try a different way to get to the profile. I know who Andrew Tang works for and I know they have a Facebook page. Having a quick look through would show up any posts Andrew Tang may have liked, and from there I can access the profile and gather more information:
This shows my Facebook privacy settings work!
Corporate Website
Most corporate websites have a who's who on it, but I'm not currently on it. Although if I were, it would probably show a photograph and a brief about me, which could uncover hobbies or pastimes.
So what?
A lot of information can be uncovered very quickly about people. If I were a target to an attack, I would hope that my privacy settings and IT awareness would help. If the communication was more targeted from people I know or around a hobby or pastime, I may well click on them.
Our virtual presence keeps growing, but do we keep tabs on what's out there. I did the above with no special access or logins. The only site that needed an account was Facebook, but the rest is there to be discovered.
Take the time to secure and protect your information, and make sure there's not too much out there.
Googling yourself is no longer about vanity, it's about security!
Thursday, 4 September 2014
iCloud Compromise...
The mainstream news has covered the compromise of iCloud, which led to a number of private photographs being exposed to the public. The first assumption was that iCloud was hacked or compromised, but Apple denies this.
Accounts Compromised...
Rather than iCloud in its entirety being compromised, the compromise was to individual accounts. It is assumed that the celebrity accounts were compromised with a brute force attack, allowing multiple tries of various passwords to each account. This meant with the right software toolset which could be acquired cheaply, numerous passwords could be tried against each account.
Simple Passwords...
It would seem that celebrities are very much like the general public when it comes to passwords. There are commonly used passwords, the top 25 of 2013 can be found here. From that article you see the commonly used passwords are "123456" and "password"! With relatively simple passwords or common words, they can easily be compromised using a dictionary attack.
Security (?) Questions...
There are many ways to recover a password. It may be requested a new password which the site or application will ask you to subsequently change. There may be a need to telephone a call centre and provide details over the telephone to reset your password. The least secure in my opinion, is the ability to answer security questions that the user has the answer.
This would seem like a secure way of resetting a password, as how many people would know your mother's maiden name, where you were born, what your favourite football team is, etc? The internet and social media has been great in many respects, but it exposes a lot of information about an individual out into the wild. Once it's out there, there is no way to control, edit or delete it. Bear this in mind if you have to use to methodology for any website or application.
It would seem that this current compromise a is new thing, but something very similar happened over nine years ago when Paris Hilton's mobile phone was hacked in 2005. How was this done? The T-Mobile Sidekick device had an internet facing dashboard. If you forgot your password, you could answer some security questions including date of birth and your pet's name. All the security questions could be answered with an internet search engine.
Complex Passwords, hard to remember?
As the levels of security have to rise, so this can only make it more difficult to use the services or applications. There is always a balance between usability and complexity. We can encourage people to use a mixture of upper and lower case, special characters and numbers, but will only mean more password resets these complex passwords will be forgotten more easily.
Also common advice is not to use the same password over multiple applications and services. This only increases the users capacity to forget a password!
Phishing...
News has come to light this morning that rather than a brute force attack, it may have been a phishing attack. We are reminded to check the legitimacy of an email before acting on it, and if it seems fishy (excuse the pun) to ignore it or delete it. Some celebrities may have fallen for one of the simplest tricks.
The bad guy sends out emails that looks like an email from Apple. It tells the user that there is some sort of issue with the account that requires a password reset/change/confirmation. The user will enter their password which is stored by the bad guy. The user will be presented with either a failed message screen, a confirmation all is OK and if they were clever, even synchronise the password with Apple, so all seems right for the user.
Two Factor Authentication...
I have written a few blog posts in the past regarding passwords and multi-factor authentication, but it's relevant to re-cap it. It we look at the different types of information that can be used to log a user in, we can take different types of information in order to increase security. So one form this can take is information the user knows, such as username, password, PINs and patterns. Another form this information can take is information a piece of technology gives the user, such as a passcode from a token, a passcode from a device such as a smartphone or computer, or a passcode set via SMS to a known mobile telephone number. If the known information and the provided information are different types of information, or factors, it becomes clear where the term two factor authentication comes from.
Free protection...
I've mentioned it before, but service providers such as Apple's iCloud, GMail, eBay and Facebook give the option to switch on two-step verification, where if you try to login from a new device, a new browser or a different country, the user will be prompted to enter a code that is sent to the registered mobile phone number. The security is there and it's free!
Increase your security posture
Be aware of the security questions you choose to to use. Are the answers to your security questions available from the likes of Facebook and Twitter?
Be aware of emails asking for password changes. Double check with the service provider.
If you want to use more complex passwords, but are worried about remembering them all, use a password vault to store these passwords securely.
Although two factor authentication may add a slight delay to using the service, it gives a level of protection that will make it a lot more difficult to compromise your personal information, your data and in this case, your personal photos.
Monday, 1 September 2014
Are you wearing a security risk?
Quantified Self
The "quantified self" is incorporating technology to capture data on various aspects of a person's life. This could be food and water intake, blood pressure, glucose levels, steps, movement, sleep patterns and such like. As these wearable monitoring solutions become increasing popular, there needs to be an understanding as to how some of the more mainstream technology works.Data Connectivity
Many of these wearable devices will collect data, and then synchronise to a computer or smart device using Bluetooth LE (low energy), sometimes known as Bluetooth 4.0. Data can be manually entered onto the computer or smart device. This data will then transferred to a cloud location giving a dashboard with history, via an internet connection whether that be cellular, wireless or cabled.FitBit & Security?
I recently purchased a FitBit Flex, which is a wearable band which monitors my steps, movement and sleep patterns. So I wanted to look at this example and if there were any security risks I should be aware of.Personal Information
First of all I needed to create an account on a web portal, which required either a login using Google or Facebook credentials or create a login with an email address. The portal uses SSL certificate, although there is no stipulation for a strong password.Personal information can be stored, but it's not mandatory. There is the ability to store your name, postal address, gender, date of birth, country, height and weight. The dashboard can create API links to Facebook, Twitter and WordPress.
The dashboard shows the number of steps taken, distance covered, and then give a calculation of calories burnt.
Bluetooth Wearable
The wearable is charged up and ready to go what next? It will start to collect data and that data will need to be transferred to a smart device or computer. The wearable will use Bluetooth LE, as this will have a minimal battery drain on the smart device. The wearable synchronises with the computer or smart device using the software or app installed. Although the wearable device is visible as a Bluetooth device, I was unable to connect to it.
I'm not suggesting that it's not possible, as Bluetooth hacking tools are quite inexpensive, but it certainly wasn't possible with a simple connection.
Dashboard Access
As mentioned before, the dashboard runs as a secure website using an SSL certificate to protect it. The credentials to log into that dashboard are either social media or an email address with password. No complexity was required on the password, despite the personal information that could be stored.
If someone had access to my email or my social media accounts, then access to the dashboard would be relatively straightforward. On my laptop with my profile, when I access the main website, it takes me straight into the dashboard.
Data Synchronisation
The data sent to the portal seems to be protected and not being transferred in clear text. There may be some concerns with the connection method used to transfer this data, so the normal rules would apply. If there is an open wireless connection, or a connection using WEP to protect it, the data can be gathered during the transfer. Whether the data would be of any use is a different matter.
If web proxy solution is being used, which is able to decrypt the traffic to websites, then some information could be gathered by these systems, where the systems administrator will have access.
I'm not too familiar with cellular data transfer, so I am unable to comment on how secure this data transfer method would be.
Data Privacy?
Another concern is whether my data privacy is being respected. Will FitBit sell my data to highest bidder? Who will have access to my data? How is it stored? How is it protected?Here is the privacy policy for UK users: https://www.fitbit.com/uk/privacy
Should I use my wearable?
As we have learnt from some very high profile breaches, no organisation or website is 100% secure. Be aware of what data you are putting on internet, but I will carry on using my FitBit Flex in the mean time.
Monday, 28 July 2014
Hacking humans...
There is undoubtedly more news coverage on security breaches
or hacks into some well-known companies.
When large retail chains like Target in the States, or
massive online websites like eBay get breached, the
concerns about losing data and the impact on the consumer is massive.
Technology will protect us…
There are many technical solutions that can protect organisations, from traditional security solutions such as anti-virus software, web filtering solutions, email filtering solutions, firewalls, intrusion detection and prevention, encryption, secure authentication and endpoint lockdown solutions. There are new technologies, which use sandboxing technologies, behavioural analytics, data analysis tools, and next generation technologies refining and enhancing the traditional security solutions.
With all these solutions in place, it would be difficult to
believe that organisations are still being breached, but yet most of these technologies are in and running in these organisations. These systems are not infallible as a number of technical solutions were subject to a major security flaw, when the Heartbleed bug was highlighted.
Legislation will protect us…
There are many legislations when looking at Information Security, but although many are there to protect information, such as the Data Protection Act, Freedom of Information Act, Privacy and Electronic Communications Regulations, Computer Misuse Act, Terrorism Act, Official Secrets Act, Malicious Communications Act and even the new Data Retention and Investigatory Powers Bill.
Although these acts look after the information of the individual, an organisation or what the people can see, these are not safeguards to protecting organisations. These legislations would have done little or nothing to prevent the breaches that typically occur.
ISO 27001 and ISO 9001 are framework standards which can help safeguard the data through good practices, as can the PCI standard, but again organisations can adhere to these standards and still face the organisation being compromised.
Our people will protect us…
It is commonly joked within IT departments that "the problem is between the chair and the keyboard", implying that users are the weakest links. It's not surprising as social engineering and more targeted attacks have the "look and feel" of legitimate communication. When a large security organisation like RSA is breached it brings into question the users education. In this situation, the spear phishing (specifically directed email) attack was launched and captured by the organisation's email SPAM filter. The technology had worked, but the release of an important looking email and clicking on it, gave way to a breach that reportedly cost RSA $66 Million.
It is also believed that only 11 malicious spear phishing emails were received, all of which were caught by the SPAM filter, but it only took one person to instigate this PR nightmare.
User Education
It is often said that all compromises have used elevated privileges, which means the threats are targeting individuals because they have specific administrative rights or access to specific system. Do not overlook the importance of user education and awareness.
The technology may to there capture some of the security threats, and legislations to help safeguard practices, but vigilant and well trained users will help organisations more.
Wednesday, 16 July 2014
Data, data, data...
There are many terms thrown around about data, such as big
data, data privacy, data protection, data compliancy and data security.
Generating more and more data
The volume of data gathered is ever increasing, whether it’s
in the commercial world or our personal world.
As ways of generating data increases thorough social networking, photos
get larger through greater megapixels, the number of internet connected devices
we carry increase from zero to three or more, as media such as books, magazines
and music become digital, we can readily see why there has been phenomenal
growth in data generation.
With the many streams of data we generate and have access to,
the challenges of collecting, manipulating, aggregating this data become all too
apparent, and these are the challenges of big data.
Keeping it private
With all this data, there should be concerns with who sees
it. Ensuring the necessary controls are
in place can be difficult, whether it’s who sees our photographs on a social
media site, or when data leaves a controlled environment and into uncontrolled
public cloud storage facilities.
Most people don’t want their personal information made
public. This may be home addresses,
email addresses, telephone numbers, passport numbers, etc. This is the sort of information most people would
like to keep private.
Keeping data where only the right people, can see the
right information, but ensuring the privacy of that data is maintained, are the
challenges of data privacy and data protection.
Law enforcement
There must be laws in place to protect information. There are a number of legislations
to protect us, along with industry bodies policing certain industry
verticals. If these legislations or compliance
bodies are ignored or contravened, then fines or dismissal can be the penalty.
Using the legal system or industry bodies to monitor and
police the data, could be considered data compliancy.
Technical Enforcement
There are many technical solutions that can help protect the
data, whether it’s by encryption, password protection, two factor authentication
access, VLANs, data segmentation, database security solutions, data leakage
prevention solutions, etc.
These solutions are just that. It is more important to understand the
challenges and issues, before jumping in with a technical solution.
CIA?
Working in Information Security, many people will refer to
the CIA triad. This is where Confidentiality, Integrity and Availability
are considered the cornerstones and core principles of Information Security.
The considerations will all data, are:
Confidentiality – Define and enforce the appropriate access
controls to the data
Integrity – Ensure the data has not been manipulated from
when it was captured
Availability – Ensure the data is accessible when it is
required
Emergency Data Laws in the UK
Currently in the UK, emergency data laws are being
rushed in. The reasons for needing
to capture this data is important for national security. The concerns are speed with which legislation
has been passed, as with many IT projects, when they are rushed, they either go
over budget, or elements are overlooked.
There is vast amount of data that will need to be collected,
aggregated, stored and interrogated. There
will also be a need to protect the various databases holding this data, and the
need to encrypt this data, so if it were to leave this environment, it would be
unusable.
This data will need to be made available, so there will be a
need to keep this data in multiple locations, but also ensuring the data that
has been captured has not been manipulated maintain the data integrity.
The biggest concern should be confidentially. There have been many reports of lost data,
inappropriate access to data, but the rise in the reports of hacking leading to
the exfiltration of data from government sources.
Data is important in
our lives, but let’s ensure that our data is protected correctly, whether it's held by a social networking site or by the government.
Wednesday, 21 May 2014
eBay compromised...
Today, eBay made the news as it was announced that their database had been compromised. Personal information had been stolen, including names, addresses, email address, phone numbers, date of birth and an encrypted copy of the users password. The breach was believed to have occurred between late February to early March.
If you have an eBay account, the first thing to is change your password.
Depending on the level of encryption, all that is needed to crack the password is time and processing power. Although the PayPal database is separate and has not been compromised, I would highly recommend changing that password, if it matches your eBay account.
Although my PayPal account rarely has much money left in it, it was only protected with a password. After today, this was changed to send me a code via SMS when I log in, so I require my password and my mobile phone to gain access to the account now. You can activate that on your account here,
How was eBay compromised? Some of the eBay user credentials were obtained and used to carry out the compromise.
We've yet to find out how, but I suspect that it was either someone aware of the eBay way of working, or it obtained via a spear-phishing attack. Spear-phishing is where specific people are targeted, where the people are either known, or information has been gathered from public sources, such as social media. Once aware of information relating to the user, they can be targeted by many means, including email. Typically when the user falls for the trap, software will be deployed onto their computer and the target monitored. Credentials can be gathered and then used against the organisation the hacker is targeting.
Lockheed Martin pioneered the Cyber Kill Chain where there are seven steps to the potential compromise, and the aim is to break the chain at any one of the seven points. The sooner, the better.
Another concern is that most organisations would require users to have privileged (such as system administrator) access to be able to access such information. There are solutions out that that can could have prevented this by managing the password on behalf of the user.
I'm sure more information regarding the compromise will come to light over next few weeks. It's surprising that more protection and prevention hasn't been deployed, but being a large organisation like eBay they will always be targeted.
Wednesday, 14 May 2014
Muting Social Media...
At the
beginning of this month, it was reported in the news that Twitter were trying
out a mute feature. This feature is
being made live this week over various platforms, but I'm surprised why you’d
follow someone who over-shares. Surely
the mute feature would be to unfollow them.
I'm on a
number of social media sites, including Twitter, Facebook and LinkedIn, and am
all too aware of people who over-share on social media. I'm sure you have the same with the people you are connected with on various social media sites.
In the last
year or so, I've noticed that it’s the same people who share a lot on my recent
news feeds, but have noticed many people have been sharing a lot less. In fact I'm guilty of this as my
regular blogging has slowed somewhat, and I'm
also using Twitter and Facebook less frequently. My LinkedIn is quite
active, which I suspect was due to my relatively recent new role with a new
organisation.
I believe this
could be attributed to the “Snowden Effect”, as more and more people hear about
and begin to understand about data privacy, they become more concerned with
what they are sharing and how it is so easily accessible with the aid of
everyone’s favourite search engine.
I find I'm a
lot more cautious when using social media now, as I don’t know who may read or
misread my comments at a later date. The
recent news about the “right
to be forgotten” in the EU court is interesting, as Google can on search on
publicly available data on the internet.
It still surprises me how many people believe that Google holds all this data,
although I appreciate Google does cache some information.
It’s
not just about data that can be used, there are also legal implications. We have seen a number of legal cases and
prosecutions around trolling,
but this does not seem to slow the flow of negative or inflammatory comments on
social media sites. Listening
to the news on the radio today it seems that the Crown Prosecution Service
(CPS) are issuing new guidelines
towards the elderly and teenagers receiving abuse, including via social media.
After the initial explosion and the subsequent growth of social media, it has meant the laws protecting the users have always lagged
behind. It’s great to be a part
of this pioneering time, but as with all pioneers, it’s difficult to protect
yourself from the unknown.
Wednesday, 19 February 2014
NHS database delayed
After my previous blog post, I have seen an increase in awareness and concerns around the NHS database rollout.
Yesterday, it was announced that the rollout has been delayed for six months, as the public were not appropriately made aware of what would be happening to their data.
BBC News: http://www.bbc.co.uk/news/health-26239532
As a side note, as I was passing my Doctor's surgery, I picked up an opt out form:
Yesterday, it was announced that the rollout has been delayed for six months, as the public were not appropriately made aware of what would be happening to their data.
BBC News: http://www.bbc.co.uk/news/health-26239532
As a side note, as I was passing my Doctor's surgery, I picked up an opt out form:
As you can see the data being moved from the GP surgery to the database is you NHS Number, Data of Birth, Post Code and Gender, along with your medical records. The data being used or sold will be age bands, area and gender, along with your medical records.
I have concerns around how the data will be transferred to the main NHS database, as well as the data itself. I appreciate that they will then modify the data before selling it, but I would then have concerns around how this data is stored, who will have access to it and what safeguards are in place to protect the original data, rather than the anonymised data. There is then the ethical questions around selling patient data to third parties.
It sounds extreme, but if a third party had access to your medical records and your postcode, it would take much to correlate this with information in the public domain to get your in address and/or telephone number. If you had a serious medical condition, would you want to be bombarded by calls and letters selling care homes or even funeral services!
I wait to see what happens in the next six months around this, but suspect I will still opt-out!
Monday, 3 February 2014
Data Privacy...
The Data Protection Act is there safeguard our personal information when being held by organisations. That in itself we hope would be good enough, but if it isn't it is policed by the Information Commissioner's Office (ICO) who are an independent authority.
The ICO have the ability to issue fines up to £500,000 where there are serious breaches to the Data Protection Act and Privacy and Electronic Communications Regulations. There have been some notable cases in the news, including:
As you can see, these data breaches whether intentional or not, happen a lot. It would want you to ensure the organisations who have your data have the necessary safeguards, but it's all to apparent that these are not in place, whether they are encryption solutions, firewalls, strong passwords, two factor authentication, data leakage prevention solutions, website firewalls, staff training, etc.
With all this in mind, did you know that the NHS have the right to share your personal information unless you opt-out of the scheme. I for one will be opt-ing out as soon as possible.
More information here:
http://www.nhs.uk/NHSEngland/thenhs/records/healthrecords/Documents/NHS_Door_drop_26-11-13.pdf
http://www.bbc.co.uk/news/health-25919399
The ICO have the ability to issue fines up to £500,000 where there are serious breaches to the Data Protection Act and Privacy and Electronic Communications Regulations. There have been some notable cases in the news, including:
- NHS Surrey, who lost sensitive information belonging to 3000 patients, which was left on a computer that was auctioned. The fine, £200,000 (Source: BBC News)
- Sony, whose Playstation database was hacked. The fine, £250,000 (Source: BBC News)
- Brighton and Sussex university Hospitals NHS Trust, who have hard drives stolen containing personal data, including medical records, National Insurance numbers, and staff home addresses. The fine, £325,000 (Source: BBC News)
- North East Lincolnshire Council, who lost sensitive information of hundreds of children on an unencrypted memory stick. The fine, £80,000 (Source: ICO)
- Ministry of Justice, who emailed the details of prisoners at HMP Cardiff to three of the inmates families. The fine, £140,000 (Source: ICO)
As you can see, these data breaches whether intentional or not, happen a lot. It would want you to ensure the organisations who have your data have the necessary safeguards, but it's all to apparent that these are not in place, whether they are encryption solutions, firewalls, strong passwords, two factor authentication, data leakage prevention solutions, website firewalls, staff training, etc.
With all this in mind, did you know that the NHS have the right to share your personal information unless you opt-out of the scheme. I for one will be opt-ing out as soon as possible.
More information here:
http://www.nhs.uk/NHSEngland/thenhs/records/healthrecords/Documents/NHS_Door_drop_26-11-13.pdf
http://www.bbc.co.uk/news/health-25919399
Subscribe to:
Posts (Atom)

