Showing posts with label Data Protection. Show all posts
Showing posts with label Data Protection. Show all posts

Saturday, 13 May 2017

The Anatomy of Ransomware - and How to Prevent from Impacting You

After the global cyber attack with ransomware, there is much advice out there suggesting the problem would have been prevented with point products, training or procedures.  I'm going to outline a generic ransomware attack below, so that the defences can be understood.  I'm going to outline what you can do as a home user, corporate user, or corporate IT team.


Delivery of Ransomware


Depending on the research you read, you can see that 93-98% of ransomware is delivered by email.  The remaining delivery methods can be via websites, whether a drive by download, malvertising or malicious website; or via removable media.

As a home user, a good quality endpoint protection solution would be recommended.  Try not to click on email attachments, dubious weblinks or using removable media you are unsure about.  Look to only have standard user profiles and not administrator rights on your everyday profile, and enter the admin credentials when needed.

As a corporate user, the advice is similar to a home user, try not to click on email attachments, dubious weblinks or using removable media you are unsure about.

As a corporate IT team, email and web gateway solutions should be protecting the email and web traffic.  The endpoint should have good quality multi layered protection.  Ensure that users do not have local administrator rights.  Sandboxing solutions on the network would analysis the unknown traffic coming into the network and ensure the email, web and endpoint vectors are covered.  Consider device control solutions if removable media is a big entry point into the network.  User education can help, but it needs to short and regular, and not many hours once a year.

Exploit the Endpoint


The ransomware's next task is to find a vulnerability on the endpoint, in order to exploit it and install the ransomware.  This is when the advice is to patch your operating system, or check and install the updates to your machine.  It's lesser known that the other software on your machine also has vulnerabilities, such as the third party software, like Java, Adobe Reader, etc, as well as the internet browsers and add-ons.

As a home user, change the settings on the operating system and software to automatically check and install the updates. Consider removing applications that are rarely used, as some may not check for updates until they are used.

As a corporate user there is typically little you can do, as this should be controlled by the administrators.  If you are able to run the updates, check regularly.  If you are able to install applications, consider what you are installing and switching on auto updating.

As a corporate IT team, ensure there is a robust patching regime.  Ensure patches are deployed to Microsoft operating systems as close to "Patch Tuesday" as possible, to prevent there being a "Hack Wednesday".  Ensure the patching regime goes beyond operating systems, covering off the third party applications, browsers and add-ons.  Consider Application Control solutions to limit the applications on the endpoints.  With the server environment, consider using IDS/IPS or "Virtual Patching" solutions in order to protect the servers until patch remediation can be carried out in a scheduled maintenance windows, allowing for testing of patches prior to deployment.


Installation of Ransomware


The installation of the ransomware will typically be disguised as a system process, so can go undetected by traditional or single layers of defence.

As a home user with the administrator rights removed as mentioned before, the software may not be able to install.  Again a good quality anti-malware solution may help prevent the ransomware from being installed.

As a corporate user there is typically little you can do, as this should be controlled by the administrators.

As a corporate IT team, look to Application Whitelisting, so unknown applications can't be installed.  Also giving the known good software will check fingerprints of applications, so even if the ransomware is masquerading as a system process, it will not be allowed to execute.  Again good multi layered anti-malware protection and limited local admin rights will help.  Sandboxing solutions should detect this traffic, and consider tools that can monitor file integrity, analyses the memory or offers memory injection protection.

Command and Control


Once installed, the ransomware will typically talk back to the "Command and Control" servers, communicate with the ransomware and customise what the machine will do, such as detect language settings of the computer and then get the correct interface installed in the matching language.  A Chinese demand for a ransom would not be very effective to a machine using Russian language.  There can be communication of the unique encryption key as well.

As a home user, beside the reliance on the endpoint protection having a good malware detection and possibly a host based firewall, there is very little that can be done at this point.

As a corporate user, the situation is much the same as the home user, as there is little that can be done.

As a corporate IT team, the use of Next Generation Firewalls and/or web gateway solutions should be able to see this traffic travelling to and from the network, and prevent the communication.  Logging or SIEM solutions should be able to take the feeds from various point throughout the network to detect this activity.


Data Encryption


The ransomware will now start to encrypt a portion of each of the files, allowing it to work quickly through all the files.  It will check for connected devices, so it will be able to encrypt network file shares and removable media connected to the machine.  It also knows to leave the operating system files, so the machine is still able to run and demand the ransom.

As a home user, beside the reliance on the endpoint protection having a good malware detection and possibly a host based firewall, there is very little that can be done at this point, aside from ensuring that there are system backups.

As a corporate user, the situation is much the same as the home user, as there is little that can be done.

As a corporate IT Team, the anti-malware solution may be able to detect this and stop it from running, or the use of application control could have prevent the application from executing as mentioned before.  Beyond that the the dependence will be on having system backups.


Ransom Demand


At this point, whoever you are, all is lost with out system/data backups.

The advice is not to pay as research currently shows that the payment of the ransom will to the decryption of the data around two thirds of the time, and increases your possibility of being targets again.


The Advice

As a home user, don't click on links without validating if they are legitimate, get a good quality endpoint protection solution and patch your computer regularly.  Remember to backup your data, whether to the cloud, portable hard drives or USB devices, and try not to physical devices connected when not in use.  Make your account a standard user, so the administrator password is required for tasks that are altering the configuration of your computer.

As a corporate user, don't click on links without validating if they are legitimate, but work with IT, if you think you have.

As a corporate IT Team, ensure the endpoints have good quality malware protection that can be centrally managed and centrally logs information.  Ensure there web and email gateways installed and configured.  If you don't have a NGFW, consider getting one and using the features available.  Patch the operating systems, applications and browsers on endpoints and servers.  Consider investing in Device and Application Control solutions, if you don't already have them.  Sandboxing solutions will help deal with the unknown and new threats, so are well worth the investment.  Review the rights the users have on their devices, as they typically don't need to be local administrations.  SIEM solutions with security features will help detect this early on.  End user training is important, but keep it short and regular for it to be effective.


Conclusion


Ransomware attacks will continue to happen, but stopping the chain of events as soon and as quickly as possible will minimise the damage.

I hope this guide has been useful in helping understand how ransomware works, and the measures that can be taken to prevent if from impacting you.  If you have any questions, please feel free to email me: blog@andytang.com

Thursday, 15 September 2016

Managing the keys to the kingdom [Link - Professional Security Magazine Online]

After the recent breach at Sage, I was asked to write a piece about insider threat for Professional Security Magazine Online: http://www.professionalsecurity.co.uk/products/cyber/managing-the-keys-to-the-kingdom/

==================================

The recent data breach at Sage, in which sensitive customer data was accessed internally, raises a wider question on whether UK companies are doing enough to defend against hacks, writes Andrew Tang, Service Security Director, MTI Technology, pictured.


After all, data breaches have become so commonplace that the widely accepted maxim of ‘Not if, but when’ stands true for most companies. The implication is that every major company is going to be hacked at some point. Of course, some keep it quiet and do their best to roll down the blinds so it stays in-house, while others have no choice but to come clean, usually when the breach is made public. The irony is that it doesn’t have to be like this. Attacks can be defended against. Internal breaches can be stopped. Data can be protected. It’s just a question of refocusing and committing to security as a business priority, rather than an IT need. The problem with internal attacks is that they undermine trust; a finger of doubt is pointed at all employees. People who were once held in high regard are now viewed with narrow-eyed suspicion. Paranoia rules.

In with the new

Traditional security has focused on building the castle, digging a moat and raising a drawbridge. Or in other words, putting in place rigorous and robust network defences that keep hackers out. But today we need a zero-trust model, one in which the enterprise is viewed as a hotel. Access to rooms, for example, are restricted to certain people. You can’t just walk through the front door and roam around unchallenged. You can only gain access to certain rooms according to the authorisations you have been given.

At the technology level it’s about introducing internal controls such as micro segmentation of the network, access controls and reducing administrators’ rights. Admin rights are often available to a wide number of people in any given organisation, but it’s a fact that between 80 and 100 per cent of system compromises have been carried out using admin credentials. For someone who knows what they are doing, and it doesn’t require a lot of technical knowledge, admin rights can be used to erase firewall logs, scrub back-ups, disable antivirus software and even erase CCTV footage if cameras are digitally connected to the network.

Only the few

Securing an organisation internally is about introducing privileged access, so only a small number of people who have the need can move through a company’s systems. It’s about recording these sessions so there is an audit trail and it’s easy to see who has gone where and when. It’s about introducing two factor authentications for internal access so people can’t just roam through the network at will.

In small organisations it’s relatively easy to introduce these controls precisely because the operations are small. As you step up in size, however, analytics engines need to be introduced so you can see what is going on internally and also set rules. Is someone, for example, trying to access Dropbox and have they just visited a corporate database that holds customer payment details? Of course, if this is the case the klaxons should be blaring loudly. While this is an obvious example, it illustrates how with the right technology you can see and stop potentially deviant behaviour and in fact can block it before it happens. For instance, you might want to stop all access to cloud-based storage for some employees while allowing it for others, depending on role-based needs. Data loss prevention (DLP) technologies have been around a while and are a powerful tool for identifying sensitive data and raising alerts if sensitive data suddenly starts moving across the network when it shouldn’t.

Transformation

This approach to security is transformative for the business because it introduces fundamental changes to the way people work, limiting their ability to roam around networks at will, pick up information from databases, or probe internal servers. But internal security is not just about getting the right technologies in place; it’s about a different mindset. It’s about looking at IT spend through the eyes of a realised IT soul. Do you really need an all singing and all dancing firewall or would a next generation firewall suit you better? Do you want to keep spending on the same technology or should you be looking at two factor authentication? Do you want to put 80 per cent of your budget into traditional security or would an investment in proactive analytics and DLP serve you better?

Ironically, this zero-trust approach engenders greater trust. You know who is doing what, and if someone does try to walk off with a rake of customer credit cards numbers, they will be stopped in their tracks.

Friday, 19 August 2016

The General Data Protection Regulation - A post Brexit positive for British enterprise [Link - SC Magazine]

Another proud moment for me, as I have another article published in SC Magazine about the General Data Protection Regulation (GDPR): http://www.scmagazineuk.com/the-general-data-protection-regulation--a-post-brexit-positive-for-british-enterprise/article/514976/

=======================

A month before the UK chose to leave the EU, The European Union's General Data Protection Regulation (GDPR) was signed into law. The act is designed to change the way businesses approach data protection from its 2018 enforcement date.

Replacing the EU Data Protection Directive, it has considerable scope in standardising and unifying data privacy requirements across member states and any business that markets to EU data subjects.

With strict guidelines around obtaining consent for data collection and individual profiling, alongside far more comprehensive definitions of data, non-compliance will trigger heavy fines - either €20 million (£17 million) or four percent of global turnover, whichever is greater.

Off the hook


If we exit the EU before the GDPR is enforced in 2018, technically the legislation won't apply. In practice, however, the international trading implications of the GDPR means the UK will need to broadly align its laws around handling EU citizens' personal information to maintain a close trading partnership with the EU member states.

So while those IT departments who believe GDPR stipulations impose a heavy burden might consider Brexit a handy escape route, the reality is this: Brexit aside, to continue as trading partners with the EU and remain in the European Economic Area, UK businesses will need to adopt a broadly similar framework of standards to protect EU citizens' information.

This is a positive thing, holding huge opportunity for UK business. The regulation's objectives and framework are vitally important in today's global digital economy. Meeting the new requirements will help protect UK businesses and citizens from much of the catastrophic damage caused from major cyber-attacks and mitigate many of the threats before they occur.

With only two years to meet compliance requirements and implement the changes to business systems and operations, now is the time to start the process of transforming the way businesses collect and use personal information and data.

Key considerations


Firstly, it's important to remember that the GDPR is a set of rules governing the security and management of any data that could be used to identify someone. Companies will have to immediately notify the authorities within 72 hours of any breach of an EU national's data to avoid a fine.

There's currently no UK requirement to do this and many don't due to the potential reputational impact. Recent examples, including TalkTalk's experience, demonstrate the potential damage to profit and trust following public data leaks.

To meet this requirement, businesses will need to deliver huge overhauls of their current systems to ensure breach protocols are compliant. The final draft won't be ready for some time, but companies should closely examine the current version to get up to speed.

From a technical perspective, the GDPR separates responsibilities and duties for both data controllers and processors. Controllers will only be able to engage processors that provide sufficient guarantees to meet the GDPR's standards of protecting data subjects' rights. For example.

Article 32 of the GDPR already outlines these responsibilities and provides specific suggestions for the type of security activities which might be ‘appropriate to the risk'.

Above all, it's worth remembering that from encryption of data to testing and assessing security systems – everything needs to be compliant with the GDPR's new code of conduct.

GDPR readiness


With just two budget cycles remaining until the act becomes law, it seems GDPR readiness is not a priority amongst European IT professionals – and there's a lot to be done.

As an immediate priority, a UK enterprise should start to get its systems ready and implement upgraded breach notification policies. To deliver this effectively, IT must start working with legal teams and other key departments to avoid the potential for heavy fines and get their operations data fit for a new era of global digital trade.

Wednesday, 20 July 2016

Gemalto hunts for partners for its encryption solutions as GDPR approaches [Link - CRN Magazine]

I was asked to give my opinion on our working relationship with Gemalto and GDPR by CRN and may comments were published: http://www.channelweb.co.uk/crn-uk/news/2465454/gemalto-hunts-for-partners-for-its-encryption-solutions-as-gdpr-approaches 

============================

MTI has been a partner with Gemalto for around eight years, and its services director Andrew Tang said that he has noticed the increased demand for the encryption products Gemalto provides in the run-up to GDPR.

"We have had a couple of organisations in the finance industry that have started asking us about how we can help them with their GDPR strategy. There are organisations out there that are on the ball, but more companies were in limbo because of the referendum," he said.

"People forget that when you look at all the different options, whether it's the Norway, Switzerland, Canada or Turkey models, they all have to adhere to EU regulation, which means GDPR in some fashion or another. It is still about education and evangelisation at the minute."



Monday, 11 July 2016

EU General Data Protection Regulation (GDPR)

Before I start on this blog piece, I have to make it clear that I'm not a lawyer and I have no legal training.  The blog piece below does not constitute as law, but these are areas I have researched and may make some assumptions along the way, especially with the uncertainty in the UK and it's relationship with the EU.


Data Protection Directive

The EU Commision were looking at replacing the Data Protection Directive.  So we are clear, an EU directive is a goal that the EU must achieve, but it's up to the individual countries to devise their own laws on how to reach the goal.

In January 2016, a draft form of the EU General Data Protection Regulation was released.  The difference between a directive and a regulation, is that an EU regulation is a binding act, that is applied in its entirety across the EU.

Why GDPR important?

GDPR is there to strengthen and unify data protection for individuals in the EU.  It addresses the export of personal data outside of the EU.

When will GDPR happen?

The regulation has now been released and enters into force on 25th May 2018


What is the impact of GDPR?

  • A Data Protection Officer is needed if an organisation processes 5000+ EU data subjects; or employs more 250+ employees
  • Mandatory disclosure of incidents within 72 hours to the national authority
  • Maximum fines of up to €20 million or 4% of worldwide revenue
  • “Right to be forgotten”: The data subject will have the right to retract consent, request data erasure or portability
  • EU Referendum has no impact to organisations – If you hold personal data on an EU citizen, GDPR still applies
  • Live May 2018 – Two budget cycles left

The Data Protection Officer

If the core activities of an organisation involves “systematic monitoring of data subjects on a larger scale”, or large scale processing of "special categories", such as racial/ethnic origin, political opinions, religious/philosophical beliefs, biometric data, heath/sex life or sexual orientation, then a Data Protection Officer is required.

The function is also there to advise on, and the monitoring of GDPR compliance, as well as representing the organisation when contacting supervising authorities.

Disclosure and Notification

The controllers are required to notify the appropriate supervisory authority of a personal data breach within 72 hours (at the latest) on learning about the exposure if it results in risk to the consumer. But even if the exposure is not serious, the company still has to keep the records internally.

According to the GDPR, accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data, the EU’s term for PII is considered a breach.

The GDRP notification is more than just reporting an incident, there is a need to include categories of data, records touched, and approximate number of data subjects affected. This will require detailed intelligence on what the hackers and insider were doing.

There is a term known as "Dwell time", which is the period of time that someone malicious is on your network and systems undiscovered.  Most people are shocked to learn that this on average is 206 days (from Cost of a Data Breach Study: Global Analysis, Ponemon Institute, 2015)

Fines

The GDPR has a tiered fine structure, so a company can be fined up to 2% for not having their records in order, not notifying the supervising authority and data subject about a breach or not conducting impact assessments, while more serious infringements merit a 4% fine. This includes violation of basic principles related to data security and conditions for consumer consent. 

The EU GDPR rules apply to both controllers and processors that are in “the cloud”. So cloud providers are not off the hook when it comes to GDPR enforcement.

"Right to be Forgotten"

Individuals can request the erasure of their personal data without undue delay by the data controller in certain situations. 

Consent can be withdrawn and no other legal ground for processing applies. This topic has attracted a huge amount of interest, particularly following the CJEU decision in the Google vs. Spain case.

Alongside this obligation is one to take reasonable steps to inform third parties that the data subject has requested the erasure of any links to, or copies of, that data.

Outside of the EU

The law applies to your company, even if it markets goods or services in the EU zone.  If you don’t have a formal presence in the EU zone but collect and store the personal data of EU citizens, GDPR still applies and the extra-territoriality requirement is especially relevant to ecommerce companies.

Is GDPR still required now that Brexit may happen?

If Article 50 is initiated in July 2016 & UK exits July 2018; GDPR will apply from May 2018. Also the UK were instrumental to writing and strengthening the GDPR.  Receiving personal data from EU member states would need to demonstrate to the European Commission that the law provides an adequate level of protection through its domestic laws or international commitments.

Source: Absolute Strategy Research Ltd

As you can see from the chart above, with many of the options open to the UK, compliance with EU regulation is required in order to trade with Europe.  In my opinion, GDPR will be relevant to the UK, and will need to be in place with UK organisations holding data of EU citizens.

Adopting GDPR

I believe there are some steps that will need to be taken with all organisations that wish to comply with GDRP:
  • Locate the critical data for GDPR
  • Protect the data (and the applications that access it) through segmentation and/or encryption
    • If encryption is used, ensure the encryption keys are secured
  • Use strong Access Controls to servers holding the data, such as two factor authentication
  • Use DLP/Insider Threat technology to prevent data exfiltration
  • Monitor all exfiltration data channels, including web and email
  • Collate logs from the network, so they can be analysed
  • Secure domain and local administrator accounts
  • Penetration test the environment

Final Thoughts

GDPR goes live in May 2018, which means there are two budget cycles left to get the education, processes, workflow and technology in place.  One of those budget cycles are underway already, so if GDPR planning hasn't begun, start it now, so you'll be ready for next years budget.

Friday, 1 July 2016

General Data Protection Regulation – what you need to know [Link - MTI Bytes]

This is a blog piece for the company blog site around the new General Data Protection Regulation: http://blogs.mti.com/blog/general-data-protection-regulation-what-you-need-to-know

===============================================

Signed into law in May 2016, the European Union’s General Data Protection Regulation (GDPR) act will force change in the way businesses approach data protection when it is enforced in two years’ time.

The scope of the act, which replaces the EU Data Protection Directive, will increase significantly as it standardises and unifies data privacy requirements not just across member states, but for any businesses that markets to EU data subjects.

Carrying heavy fines for non-compliance, either €20 million or 4 per cent of global turnover, whichever is greater, the GDPR enacts stricter guidelines for getting consent for data collection, individual profiling and also contains more comprehensive definitions of data.

GDPR also enhances the current legislature around data security and breach notification standards, so it is imperative the compliance teams, CIOs and data protection officers take notice of these changes.

Breach notification

As part of the new rules set by the EU, companies must alert the authorities without undue delay and have up to 72 hours – where feasible – to provide notification of a breach of EU national’s data, or risk a fine for non-compliance.

Currently, UK firms are not under any such requirement to announce a data breach, with many choosing not to as the cost of doing so for a business can be enormous. For example TalkTalk and Carphone Warehouse saw their profits and trust in their brands fall dramatically following public data leaks.

This will be a significant change for many businesses, and will see current systems overhauled in order to ensure breach protocols are compliant with the new legislation. It will also apply to all UK firms trading in Europe, as any company that holds the personal details of an EU ‘data subject’ will have to comply.

The devil is in the detail and the final text of the new directive needs to be closely studied.

Getting technical

The GDPR also separates responsibilities and duties for both data controllers and processors – requiring controllers to only engage processors that provide sufficient guarantees to meet the GDPR’s standards of protecting data subjects’ rights.

Article 32 of the GDPR outlines these responsibilities. While it is similar to the Directive’s Article 17, the GDPR expands this by providing specific suggestions for the type of security activities which might be ‘appropriate to the risk’.

From encryption of data to testing and assessing security systems – everything needs to be compliant with the GDPR’s new code of conduct.

Looking forward

There are just under two years and in turn two budget cycles remaining until the law enforces the act, yet GDPR readiness is not a priority amongst IT professionals in Europe.

There is a lot to assess in that time, especially in terms of the security aspects of GDPR, so now is the time to be getting systems ready for compliance and for implementing new breach notification policies.

This will require working with legal teams and other branches of the business to ensure compliance is watertight to prevent heavy fines for businesses.

Wednesday, 1 June 2016

Have your online accounts been compromised?

Millions of accounts from various websites have been exfiltrated and shared online.

Some of the largest compromises of personal accounts, include 359 million MySpace accounts, 164 million LinkedIn accounts, 152 million Adobe accounts, 65 million tumblr accounts, but the list goes on.

Despite all these high profile comprises being reported in the news; have you ever wondered if any of these compromised accounts were yours?

You can check here: https://haveibeenpwned.com/ 

This is a website created by Troy Hunt, a Regional Director at Microsoft and more information about him can be found here.

Tuesday, 12 January 2016

Biggest security fails of 2015 and a look ahead to emerging threats in 2016 [Link - MTI Bytes]

A blog piece I wrote for the company website: http://mtibytes.com/post/Biggest-security-fails-of-2015-and-a-look-ahead-to-emerging-threats-in-2016

===========

The last year has seen IT security at the forefront of the news agenda for all the wrong reasons. Various breaches and hackings, such as those on TalkTalk, Carphone Warehouse and Ashley Madison, have heightened discussion around IT security and the protection required to counter virtual incursions.

Yet, many of the attacks over the course of the year were avoidable. Had the companies in question been more diligent over their testing and security protocols, some of the breaches would not have been as successful.

Security fails of 2015
The biggest security failing of 2015 is arguably the vulnerability of companies to simple web application attacks. Organisations with large volumes of online customer interactions were targets for web application attacks, where cyber-criminals gain access to sensitive customer data. Techniques such as SQL injection and brute force attacks accessed valuable data for fraud or resale to third-parties

The other security failing this year has been phishing attacks, a method that can result in malware entering a network, leading to data theft. Phishing attacks can come in the form of a legitimate email from a company that redirects the user to a fake external site. Personal information is then requested and captured for future brute force attacks.

Prevention is simple
Following simple guidelines like OWASP is the first step to prevention. Regular testing of web facing applications before publishing them can also help avoid attacks.

Education within the company and targeted solutions aimed at monitoring data exfiltration should be a priority. A company’s security cannot be reliant on only using their security solutions as a shield – their workforce can and often will be a weak spot in their armour. Employee education on data governance, access and removal of data should be at the top of a company’s IT security resolutions for 2016.

Emerging security threats in 2016
The frequency and level of sophistication of ransomware threats looks set to increase in 2016, as the attacks are so effective. This is especially the case, as corrective measures to protect from attacks are rarely in place.

In addition, DDoS (distributed denial-of-service) attacks aimed at extracting data have been getting stronger and harder to defend against, as shown by the high profile TalkTalk and Carphone Warehouse breaches.

There have also been a growing number of blackmail attempts, threatening a company’s resources with DDoS attacks, unless they receive a sum of money.

What is interesting is that these two techniques do not demand high levels of technical ability, but the rewards can be great. Many companies cannot afford lengthy downtimes on their servers and will pay the sum demanded, even without any guarantee that the same attackers will not return.

Who will they affect the most?
Ransomware can affect a majority of computer users.  Assuming you will not be a victim of a cyber-attack is a major mistake and the risk of such an attack should be taken seriously.

Blackmail attacks/DDoS attacks on the other hand, will be targeting medium to large sized companies, who have the budget to pay the ransom money.

Invaluable security solutions for businesses in 2016
As ransomware is predominately distributed via email and Internet, a sandboxing solution is essential. The relevant solution has to be able to scan emails and Internet traffic delivered to computers on the network, remote workers using a VPN or BYOD users, who use wireless or mobile connections.

An attacker using ransomware infiltration techniques will execute with the user-credentials of the user who opens it, so there is a need to look at controlling administrative credentials of all computers, whether they are servers, workstations or laptops.

Thursday, 7 January 2016

The dark web & business report: A seedy Dickensian underworld online [Link - IDG Connect]

I was asked to comment how the dark web could impact on businesses, and was fortunate enough to have them published in an IDG Connect artcle.

http://www.idgconnect.com/abstract/11383/the-dark-web-business-report-a-seedy-dickensian-underworld-online

==============

It is obviously imperative that businesses can secure themselves against any threat. And as the latest wave of breaches have proved, whilst most organisations spend money on traditional perimeter security, many fail to properly protect their biggest asset, their data.

“Personal Identifiable Information (PII) should be encrypted,” says Andrew Tang, Service Director, of Security at MTI Technology. This would make any information unreadable to the perpetrator.

“Many of the recent attacks, which have allowed thousands of records to be stolen have been achieved by using SQL Injection attacks,” he adds. “If information needs to be accessible to the internet, ensure OWASP standards are followed, the website is tested by a penetration testing organisation and critical data is encrypted.”

Wednesday, 2 December 2015

Questions about the Dark Web

What do large organisations need to understand about the dark web?

The term Dark Web has many sinister undertones, and can be use used for illegal activities.  The World Wide Web  that we know and use, is accessible by a browser and is indexed using software called crawlers.  Crawlers allow the sites such as Google to know where websites are and the sort of content they contain.  There are elements that can not be indexed such a dynamic content, which generates the content on the fly, which is often referred to as the Deep Web.

What do many fail to grasp at the moment?

The Dark Web contains sites that require specific software to access it, and the network is encrypted to conceal the activity whether through privacy concerns or to cover illegal activities.  It should also be considered that the Dark Web is tiny compared to the World Wide Web.  A recent article believed there are between 7,000 to 30,000 hidden sites on the Dark Web, equating to around 0.03% of the Web.

How can understanding this space help them stay secure? 


The Dark Web is often referenced as the location of where stolen credentials are sold.  Rather than monitor or access the Dark Web, it is more important to protect the data in the first place.  Personal Identifiable Information (PII) should be encrypted, so it would render the information to being gibberish to the perpetrator.  Many of the recent attacks, which have allowed thousands of records to be stolen have been achieved by using SQL Injection attacks.  If information needs to be accessible to the internet, ensure OWASP standards are followed, ensure the website is tested by a penetration testing organisation and ensure critical data is encrypted.

Monday, 26 October 2015

TalkTalk Breach

On Friday 23rd October 2015, it came to light that TalkTalk, the telecommunications and internet provider was subject to a significant cyber-attack.

Some facts have come to light since the disclosure of the attack:

Third time’s a charm
The latest attack was the third cyber-attack in the past 12 months.  It is believe that that this attack has allowed the attacker to steal four million records.  It may also have been up to ten weeks, since the cyber-attack had occurred. 

DDoS as a cover
A DDoS (Distributed Denial of Service) attack was used to overwhelm the existing perimeter solutions.  The large volume of traffic will overwhelm perimeter solutions such as firewalls and IDS/IPS solutions which are there to scan and protect an organisation from malicious traffic.  It seems there was either no or an inappropriate/inadequate DDoS mitigation solution in place.  DDoS attacks are often used as a subterfuge to mask the real nature of the attack.  In this case, it looks like the attacker is flooding a website, whereas the underlying attack is to exfiltrate customer data.

SQL Injection?
It is widely believed that the attack was on the application available on the internet, and using web application testing tools, such as a form of SQL injection attack, were able to access the data.

SQL is a database application, and an SQL injection is the ability to run a query on a database.  Although very useful for database administrator, it gives malicious attackers the ability to query and export a whole database.  The ability to run SQL injection attacks, are typically due to bad administration practices and not properly protecting the database.

Comprehensive data on people
The customer data lost is incredibly comprehensive.  The list below shows the data the attacker was able to obtain.
  • Name
  • Address
  • Email Address
  • Telephone Number(s)
  • TalkTalk Account Number
  • TalkTalk Password
  • Bank Details
  • Partial Credit Card Details

Encryption?
The TalkTalk data wasn't encrypted, meaning the attacker was able to read all the above information.  The data was in clear text, offering no protection to the customer.

Aftermath
It is believed that the Police and BAE Systems are carrying out a forensic investigation on the attack, but this relies on how much of a digital footprint was left during the attack and whether it was recorded at the time.

BEFORE THE ATTACK
As an organisation handling customer information, there are many actions that would help prior to an attack:

Identification of Data
With numerous databases, server shares, cloud storage solutions and user created data; identifying important information, such as customer’s PII (Personal Identifiable Information) and financial information is paramount.

Protection of Data
Once the important information has been identified, methods of protecting the data should be used.  Encryption of data, where the data is encoded using a unique key and can only be decoded with this key, makes the data useless without it.

Testing of Systems
As applications are exposed the internet, such as customer portals, these need to be tested by a third party organisation with little or no knowledge of the application.  A Web Application Penetration Test could have highlighted some of the shortcomings of the web facing applications, including testing for SQL injections.

DURING THE ATTACK
When an organisation is under attack, a number of solutions could have prevented an attack similar to TalkTalk’s. 

Administrative Rights
It is often said that 100% of attacks have used administrative rights.  There are Privileged Access Management solutions, which will safeguard the administrative accounts, and will offer full traceability of which administrator has done what.  A typical attack will either use administrative credentials they have gained, or to elevate the administrative privileges of a normal user.

Protection from DDoS
A DDoS (Distributed Denial of Service) is normally used by a malicious attacker to take a web presence offline, making a web service inaccessible.  In the case of TalkTalk’s attack, it was use to cloak the underlying attack.  A hybrid DDoS mitigation solution could have prevented such an attack.

Intrusion Detection
There are Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) which is used to detect and identify malicious activity on the network, then try to block or stop that traffic, and report back.  These are available as standalone solutions or as part of a UTM (Unified Threat Management) or Next-Generation Firewall solution.  Sometimes the early warning of an attack can help prevent the loss from being so great.

Data Exfiltration
The data will need to be taken for a breach to have occurred, so a DLP (Data Loss Prevention) solution will monitor the vectors from which data can leave, such as web, email, USB, screenshots, printers, etc and if the monitored data leaves in an atypical fashion, it will be quarantined and administrators alerted.  

AFTER THE ATTACK
After the compromise, what options are available?

Logs & Forensics
Post attack, it’s important to know what has been lost and preventing it from happening again.  A SIEM (Security Information & Event Management) solution would be able to aggregate the logs from the various components of the network, and apply a level of intelligence to the data.  Some will be able to carry out a forensic analysis on the logs.

Understanding the attack will allow a more effective remediation plan to be created.

What now TalkTalk?
Reading the press following the TalkTalk attack, there is no understanding to the significance of the data loss.  Although there is no demand to encrypt the data, it doesn't mean that the information of your customers should not have been encrypted.

As a minimum, by pentesting the application to prevent the vulnerability, and encrypting the data so it's useless to the attacker, would have prevented TalkTalk from the media attention. 

There is a call for the government to do more to prevent the cyber-attacks, but as highlighted here the technologies are available to help prevent, gain visibility or slow down the attack.  The onus should not be on governments to protect the customer’s data, it should be the service provider.

Tuesday, 20 October 2015

"Hunted" - Technology View [Link - MTI Bytes]

A piece I wrote has been edited and used on the work blog: http://www.mtibytes.com/post/Hunted-A-technology-view

===================================

Channel 4’s new reality show Hunted has gripped my attention since the first episode launched 6 weeks ago.  I'm particularly surprised by the amount of surveillance there is in the UK, allowing people to be traced or ‘hunted’ using data from mobile phone and ATM usage, number plate recognition, and CCTV footage. What I've found more concerning however, is the oblivious nature of the contestants to the digital footprint they are leaving, not dissimilar to the naivety of employees when it comes to safeguarding corporate data.

So, in a world driven by technology, how do you protect your personal and corporate digital footprint?

1. Manage your devices
Gone are the days of owning one mobile device, we live in a society where people juggle a plethora of devices at any given time. The mobile phone in particular has become the hub of many people’s lives; 66 per cent of people now own a smartphone. In a short period of time the mobile phone has evolved to support all work and personal activity from sharing files to tracking fitness goals, as well as still holding its primary function of making calls.

Ensuring your device is backed up regularly, is one way to manage its contents and protects it against damage or thief. Backing up the device’s applications and data to a public cloud service safeguards contents but also adds an additional layer of security to your data.

2. Password protect
Irrespective of the abundance of recent security hacks, the show brings attention to the amount of people that still don’t have any security on their devices. Without any security measures, others can immediately access the device as well as personal and corporate data. Securing accounts with a password is an essential step to protecting data.

Using complex and different passwords across various accounts and devices also tightens security. Where possible, a two-step verification or authentication is preferable.

Applications such as KeePass can help remember any complex passwords you have.

3. Control browser history
If Internet anonymity is important, tools like the TOR network provide users with ability to hide identity and usage. Internet performance and connectivity can be affected by products such as TOR, therefore consider if the perceived cost of your history is worth it.

Browsers can also be set to delete search either automatically or manually, as the search history is automatically cached.  Most browsers have a secret search feature, whereby the history is not stored and neither are cookies. The issue with cookies is that the information is read by other services, often to advertise to. Remember, Internet history will never truly be private, as ISP will track sites visited.

4. Information control
The revelation of social media is leading to a generation of over-sharers. Think about the information you want on the Internet. Imagine what could happen if an unscrupulous person had access to your private information and what they could do with that information? Sharing information you may use for added security protection such as pet names etc. invites security threat.

It is essential to have prevention tools in place to control your digital footprint and to stop yourself from being ‘hunted’.

Thursday, 15 October 2015

Another week, another data leak [Link - MTI Bytes]

Another piece I wrote for the work blog: http://www.mtibytes.com/post/Another-week-another-data-leak

==================
San Francisco-based crowdfunding platform, Patreon, is the latest casualty in a series of recent data breaches. The incident has seen hackers download and leak a 15GB user database containing names, addresses, email addresses and donation information. So far, the hack has exposed 2.3 million users and their personal data, with the exception of credit card details, passwords, social security numbers and tax information.

In response to the hack, Patreon Founder Jack Conte wrote:

“There was unauthorised access to registered names, email addresses, posts, and some shipping addresses. Additionally, some billing addresses that were added prior to 2014 were also accessed. We do not store full credit card numbers on our servers and no credit card numbers were compromised. Although accessed, all passwords, social security numbers and tax form information remain safely encrypted with a 2048-bit RSA key.”

The question arises: how can you protect certain data?

Importance of encryption

Due to Patreon safely encrypting the information using a 2048-bit RSA key, hackers have been unable to access or leak users’ passwords, social security numbers and tax information.

In other words, Patreon protect key information via a multi-level password scheme called ‘bcrypt’.  The key benefit of ‘bcrypt’ is that it is irreversible, which means it cannot be “decrypted”. In Patreon’s case, the failure of the company to store plaintext passwords explains why the hackers could access only certain types of information.

As a result of Patreon using ‘bcyrpt’, an added layer of security protects the information, enabling passwords and credit card details to remain safe despite the hack. This additional security minimises the damage of the hack by securely protecting the most valuable information – the credit card details of millions of users.

Protect the test environment

The belief is that a publicly available debug version of the Patreon website led to the Patreon hack. Essentially, some of the site remained open, as part of a test environment, rather than behind a firewall.

Patreon’s data compromise highlights that test environments exposed to the Internet are just as important as their live counterparts. Security therefore needs to be tight, even on test sites. Web application firewalls and Data Loss Protection (DLP) solutions can help prevent data from leaving the site, ensuring that it is kept secure and is often the first line of defense for any company.

While the Patreon hack is undeniably a terrible breach of security, the company’s use of ‘bcrypt’ is helping to contain the damage, and highlights to other businesses the importance of good security practice.

Wednesday, 30 September 2015

“Hunted” - A technology view

How many of you have been watching Hunted on Channel 4?  I have been an avid viewer since the first episode and have to say it was an eye opener.  I was surprised how much surveillance there is in the UK, allowing people to be traced by mobile phone and ATM usage, number plate recognition, CCTV footage, but more concerning the digital footprint people were leaving, where every step could be traced.

Mobile 
The mobile phone has become the hub of many people’s lives, in a short period of time of being a device to make calls, it could then send text messages and play Snake, to being the hub of all communications, such as work email, personal email, social media, text and picture messages, video calls, tracking our movements for fitness, our music, video and photograph repositories, and we sometimes even use them for telephone calls!

I know that if I misplace my mobile phone, I’m at a loss, but that’s probably the subject of another blog post.  In the show, they talk about phone tapping and triangulation, but more concerning was how people didn’t have any security on their devices, allowing access immediately onto the device.

Smartphones are lost or damaged on a seemingly regular basis, but thankfully there is the option to back up the device’s applications and data to a public cloud service.  This functionality is offered by the main operating system providers, such as Google, Apple and Microsoft, as well as manufacturers such as HTC.  This can only be a good thing, except if someone has access to your password, where the backup can be restored.  This would give access to text messages, browser history, and other private and sensitive information.

Email
Unless you are paranoid or technical, you probably have a web based email account provided by Google, Microsoft, Yahoo, etc, as the convenience of a web based email account outweigh any benefits of running your own mail server for your own domain.

Internet based services are easy to reach offering convenience, but also means that you are open to have your account compromised by a hacker.  On the show, one email account where access was gained immediately as the password was saved by the browser.  

A recent episode showed the use of a phishing attack, where a seemingly legitimate email was sent with a link, which led to a website asking for a password.  As most people use the same password for multiple websites, having one password can open access to many online accounts.

Google searches
In the show, internet searches were used to discover what the user was researching prior to being hunted.

I’ve never been worried about what I’ve been searching for on the internet, but if you are, there are privacy services offered by the major browsers.  Although it will mean that your searches are not cached and no cookies will be stored, the provider and the ISP (Internet Service Provider) you’re using will know, as they have to deliver this service.  

If Internet anonymity is important, the using tools like the TOR network, utilising their software and thousands of routers, there is the ability to hide identity and usage.  This can be great for privacy, but can be a threat to national security. 

Social media
The internet revelation of social media allowed to find our friends and share information.  For people to find you, you have to place a certain amount of information on the internet, but many people over share, leaving a lot of information about themselves on the internet.   

The researchers on the show used internet searches to see what they could find about the subject.  When that wasn't enough they also used the users devices for access to social media accounts, where again passwords were either saved by the browser or written down on a piece of paper nearby.

Location Services
The ability for your apps to have location information improves the app experience.  One of the primary uses is for mapping, allowing the device to be located on a map.  It’s not commonly know that location services are typically switched on for a mobile phone camera.  This has a use if you are taking a photograph to share on social media, telling everyone where the photograph was taken.  The downside, the properties of the photograph shows the location, which many not be useful if you don’t want people knowing where the photograph was taken.

I haven’t seen this used on the show, but would have been useful in locating people beyond the mobile phone triangulation and number plate recognition.

Protecting Mobile Devices 
Smartphones are ubiquitous, but are incredibly powerful devices we have in our pockets.  I met someone recently who didn't trust smartphones so has a non-smart mobile phone.  There are some simple measures that can be used to protect the device.  

Create a PIN or password for the device.  Yes, it can be a pain to have that, but it’s protecting the device and the contents.  You will be able to set the device to wipe itself if the incorrect PIN/password is entered incorrectly a number of times.

Ensure your device is backed up regularly, so even if the device is lost or stolen, the data won’t be.  The password for this cloud storage and cloud backup account must have a strong password, and there is often the option to use two-step verification where a code is sent via SMS to the registered mobile device.  If it’s too easy for you to access the account, it’s too easy for a hack to access it as well.

Protecting Email 
Sounds like simple advice, but harder to execute.  Use different complex passwords for each of your online accounts, don’t allow your browser to remember the passwords, and switch on two step or two factor authentication where possible.  

There are applications to help remember the complex passwords, but a popular one, KeePass was recently discovered to have a security flaw.  Just don't write down your passwords and certainly don't keep them next to your computer or tablet!

As ever, ensure the sites asking for your passwords are legitimate sites, and simply delete anything that looks “fishy”!

Protecting Browser History 
Browsers can be set to delete search either automatically or manually, as the search history is automatically cached.  Most browsers will have a secret search feature, where the history is not stored and neither are cookies, typically created when visiting a website.  The issue with cookies, is that they can be read by other services.  For example if you search for a computer game, you will see on subsequent websites advertisements for that game.  This information is stored on a cookie and being read by advertising services.  Keep in mind that sites visited will be tracked by ISP delivering the content, so the Internet history will never truly be private.

TOR can provide anonymity to the user, but the traffic and content can be seen on the exit node and performance can be poor, due to the bandwidth available.  It certainly won't offer the media and feature rich Internet experience we've come to expect.  If you have something to hide TOR maybe the way forward, but the sacrifice may not be worth it.

Protecting Social Media
Think about what information you want about your out on the internet.  Imagine if anyone could have full access to your profile, what could an unscrupulous person do with that information?  Is your password made up of your favourite team, band, child’s name, mother’s maiden name, pet’s name, etc?  Then think if that information is on your public profile?  Set privacy settings to ensure on the people you want can see the information you want them to.

Protecting Location Information
If you need to hide your location, but want to use Social Media?  Check the location services and whether they are enabled on your applications, especially your mobile/tablet apps.  Check the settings for your camera as well. Even if location services are stopped on Social Media, the properties of the photograph can still have the location of where it was taken, if the feature has not been disabled on the camera.

Hunted?
If you are really being hunted, then this is only basic advice, but much like the IT security adage, “It’s not if, but when you’re hacked”, it may well be; it’s not if they find you, but when!

Tuesday, 10 February 2015

Sweating Like a Moonpig and Other Data Security Lessons

Here is an article I was asked to write for a magazine regarding the Moonpig incident, which was republished on the work blog here: http://www.mtibytes.com/post/Sweating-Like-a-Moonpig-and-Other-Data-Security-Lessons

=============
It has now been widely publicised that Moonpig, one of the UK’s largest personalised greeting card companies, had a major security vulnerability in its website, which remained unfixed for 17 months. Despite being notified, the company chose not to act for the better part of 2014, leaving the personal data of 3 million customers (including partial credit card details) exposed to the public.

The vulnerability in question is fairly basic and relates to the way individual users are authenticated. For months, the lack of authentication in place allowed access to any users’ accounts by connecting with the Moonpig servers via the API and simply tweaking the customer ID numbers sent in API requests. Without any further authentication, this tactic could have been replicated by hackers 3 million times with a simple piece of software in order to steal personal data, including names, addresses, and credit card details.

Widespread consequences
One critical lesson from Moonpig’s vulnerability is that data security does not end when the user logs off. Often all that is needed to take control of someone’s entire digital life is a billing address and the last four digits of an associated credit card number. Once a threat is identified, inaction on the part of the service provider can prove just as devastating as causing a security hole in the first place. Moonpig may not have directly leaked their customers’ data, however they made that data directly accessible to any eager parties, capable of writing some simple code.

The ramifications aside, Moonpig severely jeopardised its customers’ trust. As custodians of customer data, companies that process payments have an ethical obligation to fix basic security issues within a reasonable timeframe. Moreover, they have a legal obligation to protect that data. In the case of Moonpig, Price should have contacted an enforcement authority like the Information Commissioner instead of going public with the vulnerability.

Next steps
Moonpig’s API vulnerability highlights an area that is poorly documented and routinely overlooked in security testing, but there are easy steps that can mitigate against this threat, such as patching operating systems, applications, and known vulnerabilities. When developing code, many organisations believe that a code review or penetration test is sufficient on application completion, however developed applications are often a work in progress, with many subsequent bug fixes, code changes, additional features, and functions added. It is thus necessary to have on-going code reviews during the development cycle, with a code review and penetration test on completion at each stage. In effect, the code review has to be as agile as the development itself.

Many threats and vulnerabilities reside within organisations for months or even years before discovery, and when they are revealed, it is often a third party that blows the whistle. Even after several warnings of the code vulnerability within its Android application, Moonpig seemingly chose to do nothing to resolve the issue. From banks to greeting card companies, when customers give out their data they trust that the vendor will take appropriate measures to encrypt and safeguard their personal information. As the threat landscape changes, many organisations do not seem to have the agility to uphold this implicit trust.

Thursday, 25 September 2014

Securing the virtual you

I blogged recently about the Cyber Kill Chain where I look at each of the steps.  Many of the steps can be dealt with using technology, except one stage, the reconnaissance stage.

Who's the target?

As the bad guys need to be more specific in targeting individuals, research is the key.  Knowing who someone works for, who their friends are, their hobbies and pastimes, they all help construction a picture of the target.  If you know your target, you can try to exploit it by sending emails with specific topics and links to lure your target to click on a link which can compromise their machine.

Spear-Phishing

People who are normally target to a "spear-phishing" (if phishing is a wide indiscriminate attack to get users details, spear phishing is targeting a very group or an individual person) are people who will have more rights than a typical user.  Why?  Well I mentioned in previous posts that a compromise will involve administrative credentials 100% of the time.  So the target will often be members of the executive team (who often have more rights than a user) or members of the IT team.

Research/Googling?

How would I find out more about someone?  Use Google (other internet search engines are available) and search for them.  As an example, I'll use me and see what's available out there...


LinkedIn

The second hit is for LinkedIn and most of the posts that follow are for a Singaporean racing driver (I'll give you a hint, I'm not a racing driver!).  For those who are unfamiliar with LinkedIn, it's a social networking site for "professionals" effectively giving a CV online.

So following the link, it takes me to a number of people called Andrew or Andy Tang internationally, but LinkedIn handily gives a link at the top to refine this list to Andrew or Andy Tangs based in the United Kingdom.  



So if you knew who I worked for (MTI by the way), then you'd know to click on the top link.  If you didn't, then you probably won't target me!  So now I can see a public profile of Andrew Tang, and even without a LinkedIn account I can gather a lot of information.



Now you know who I work for and have worked for, along with people who I must be linked with in some fashion, as people looking for my profile have also looked at these profiles.  That already creates links with people or organisations I would potentially trust, or would not find odd if I received a communication from them.  Additional information such as company websites and blogs may also be there and give more clues.

Google+/Blogger

Following out to the blog, it can be seen that the URL to my blog (that you're reading by the way, thank you) is http://blog.andytang.com which gives us similar information to the LinkedIn profile, as well as a link to my public LinkedIn profile.  There is also a link to my Google+ profile as the blog use Blogger which is a Google company.  

Twitter

Information we already have like company and LinkedIn details.  There is a link to Twitter, along with some people who have put me in their circles.  Again, more people that I would not find odd if I received communications from them.  Let's follow the link to Twitter...


No real insights here, except that I say I live in Surrey.  That may have been assumed as current and previous employers are in Surrey as well.  

WhoIs?

Maybe time to get a little cleverer!  We know the domain I own andytang.com, so there must be some information around that domain.  A WhoIs will find out who has registered this domain:


No real information here either!  

Facebook

I've tried looking for a Facebook page, but struggle to find myself, even if I spread the net wider with more information than can be found above.  None of the profiles below are me, but then I have locked down my privacy settings.


I thought I'd try a different way to get to the profile.  I know who Andrew Tang works for and I know they have a Facebook page.  Having a quick look through would show up any posts Andrew Tang may have liked, and from there I can access the profile and gather more information:


This shows my Facebook privacy settings work!

Corporate Website

Most corporate websites have a who's who on it, but I'm not currently on it.  Although if I were, it would probably show a photograph and a brief about me, which  could uncover hobbies or pastimes.

So what?

A lot of information can be uncovered very quickly about people.  If I were a target to an attack, I would hope that my privacy settings and IT awareness would help.  If the communication was more targeted from people I know or around a hobby or pastime, I may well click on them.

Our virtual presence keeps growing, but do we keep tabs on what's out there.  I did the above with no special access or logins.  The only site that needed an account was Facebook, but the rest is there to be discovered.

Take the time to secure and protect your information, and make sure there's not too much out there.

Googling yourself is no longer about vanity, it's about security!

Monday, 1 September 2014

Are you wearing a security risk?

Quantified Self

The "quantified self" is incorporating technology to capture data on various aspects of a person's life.  This could be food and water intake, blood pressure, glucose levels, steps, movement, sleep patterns and such like.  As these wearable monitoring solutions become increasing popular, there needs to be an understanding as to how some of the more mainstream technology works.

Data Connectivity

Many of these wearable devices will collect data, and then synchronise to a computer or smart device using Bluetooth LE (low energy), sometimes known as Bluetooth 4.0.  Data can be manually entered onto the computer or smart device.  This data will then transferred to a cloud location giving a dashboard with history, via an internet connection whether that be cellular, wireless or cabled.

FitBit & Security?

I recently purchased a FitBit Flex, which is a wearable band which monitors my steps, movement and sleep patterns.  So I wanted to look at this example and if there were any security risks I should be aware of.

Personal Information

First of all I needed to create an account on a web portal, which required either a login using Google or Facebook credentials or create a  login with an email address.  The portal uses SSL certificate, although there is no stipulation for a strong password.

Personal information can be stored, but it's not mandatory.  There is the ability to store your name, postal address, gender, date of birth, country, height and weight.  The dashboard can create API links to Facebook, Twitter and WordPress.

The dashboard shows the number of steps taken, distance covered, and then give a calculation of calories burnt.

Bluetooth Wearable

The wearable is charged up and ready to go what next?  It will start to collect data and that data will need to be transferred to a smart device or computer.  The wearable will use Bluetooth LE, as this will have a minimal battery drain on the smart device.  The wearable synchronises with the computer or smart device using the software or app installed.  Although the wearable device is visible as a Bluetooth device, I was unable to connect to it.  

I'm not suggesting that it's not possible, as Bluetooth hacking tools are quite inexpensive, but it certainly wasn't possible with a simple connection.

Dashboard Access

As mentioned before, the dashboard runs as a secure website using an SSL certificate to protect it.  The credentials to log into that dashboard are either social media or an email address with password.  No complexity was required on the password, despite the personal information that could be stored.

If someone had access to my email or my social media accounts, then access to the dashboard would be relatively straightforward.  On my laptop with my profile, when I access the main website, it takes me straight into the dashboard.

Data Synchronisation

The data sent to the portal seems to be protected and not being transferred in clear text.  There may be some concerns with the connection method used to transfer this data, so the normal rules would apply.  If there is an open wireless connection, or a connection using WEP to protect it, the data can be gathered during the transfer.  Whether the data would be of any use is a different matter.

If web proxy solution is being used, which is able to decrypt the traffic to websites, then some information could be gathered by these systems, where the systems administrator will have access.

I'm not too familiar with cellular data transfer, so I am unable to comment on how secure this data transfer method would be.

Data Privacy?

Another concern is whether my data privacy is being respected.  Will FitBit sell my data to highest bidder?  Who will have access to my data?  How is it stored?  How is it protected?

Here is the privacy policy for UK users: https://www.fitbit.com/uk/privacy

Should I use my wearable?

As we have learnt from some very high profile breaches, no organisation or website is 100% secure.  Be aware of what data you are putting on internet, but I will carry on using my FitBit Flex in the mean time.