WISH YOU A HAPPY AND SECURE YEAR 2009

Friday, May 23, 2008

Quote of the day

Quote of the day

Adversity cause some men to break; others to break records.

William A. Ward

New IT Term of the day

New IT Term of the day


passive impostor acceptance


In a biometric security system, when an impostor intentionally submits his own biometric sample and claims the identity of another enrollee (either intentionally or unintentionally) with the purpose of gaining access to a system. Passive impostor acceptance implies that the impostor successfully gains entrance into the system using the verified identity.

OpenSSL worked on Easily Guessable Key

BIG BUG : OpenSSL worked on Easily Guessable Key

After Debian's epic SSL blunder, a world of hurt for security pros

By Dan Goodin in San Francisco

21st May 2008

http://www.theregister.co.uk/2008/05/21/massive_debian_openssl_hangover/

It's been more than a week since Debian patched a massive security hole in the library the operating system uses to create cryptographic keys for securing email, websites and administrative servers. Now the hard work begins, as legions of admins are saddled with the odious task of regenerating keys too numerous for anyone to estimate.

The flaw in Debian's random number generator means that OpenSSL keys generated over the past 20 months are so predictable that an attacker can correctly guess them in a matter of hours. Not exactly a comforting thought when considering the keys in many cases are the only thing guarding an organization's most precious assets. Obtain the key and you gain instant access to trusted administrative accounts and the ability to spoof or spy on sensitive email and web servers.

Security pros have rightfully reacted swiftly to word of Debian debacle. But if you think last week's patch is like most other security fixes, you're dead wrong. Installing it is probably the easiest part of mopping up the resulting mess. Once it's installed, admins will be forced to search sometimes sprawling systems for every key that's ever interacted with the buggy version of Debian and a host of other OSes and applications that relied on it.

Certificates for defective keys will have to be revoked, new keys will have to be generated and, in the case of SSL certificates, registered with VeriSign or another certificate authority. No one knows how many keys need to be replaced, but it could number in the hundreds of thousands or millions. The keys are used for Secure Sockets Layer (SSL) transactions, which authenticate servers handling trusted websites and email, and to authenticate Secure Shell (SSH), which provides encrypted channels between sensitive computers.

The heft and tedium of tracking down, testing and regenerating so many keys, and the cost of paying certificate authorities to register them, has left some people feeling pessimistic about the prospects the problem will be fixed anytime soon.

"There's the pain-in-the-ass factor and then there's the cost factor," says Jacob Appelbaum, an independent security researcher, as he ticks off the reasons he believes organizations will be slow to tackle the problem. Sure, some will make an earnest effort, but "even those people are going to be overwhelmed and patch a lot of their systems but not all of them," he adds.

Weakened White House

Among the weak SSL certificates at time of publication is this one belonging to Whitehouse.gov. It's of little consequence, since the site doesn't conduct secure transactions, but it does show the ubiquity of the problem. The key is owned by content delivery provider Akamai Technologies and is used by about 20,000 websites. Akamai is in the process of replacing it.

Akamai has escaped relatively unscathed. All its keys involved in sensitive transactions are generated using a highly customized Debian derivative that didn't include the buggy random number generator. The single key used by Whitehouse.gov and the other Akamai customers, which was generated using a separate system running on standard Debian is the only one affected, says Andy Ellis, Akamai's senior director of information security.

"I can't imagine how painful this will be for people who are using large data centers with hundreds of certificates," Ellis said.

The unwieldy cleanup effort is akin to the aftermath of a serious Flash vulnerability found in December to be plaguing tens of thousands of websites. Three months after a patch was released, the sites - many carrying out banks financial and other sensitive transactions - remained vulnerable because they had yet to remove and regenerate an estimated 500,000 buggy flash applets. Both the Debian and Flash vulnerabilities are unusual, because applying the patch represents only the beginning of the healing process.

The Debian bug was introduced in September 2006. It vastly reduces the amount of entropy used when programs like the Apache webserver, Sendmail, Exim and some implementations of Kerberos use OpenSSL to perform basic cryptographic functions. As a result, attackers can crack SSL keys, x.509 certificate keys, SSH keys, and digital signatures in fewer than 33,000 guesses, rather than the seemingly-infinite number of tries that would normally be required.

Tools available from Ubuntu and Metasploit author HD Moore are designed to aid in the process of detecting weak keys, but Appelbaum, the independent researcher, says certain conditions will prevent even diligent searches from finding everything. For example, keys with nonstandard sizes may not be flagged even though they're vulnerable.

"What that means is you have tools that may cover large swaths of the key space, but they won't cover all of the key space," he says.

So if your organization hasn't begun a thorough audit of all the keys in its portfolio, now is the time to get to it. Like an outbreak of lice at the children's grade school, its an unpleasant task eradicating the pests, but it's got to be done.

"This is a bit of a nightmare for anybody who used Debian" or programs that relied on its OpenSSL library, says Vincent Danen, the security team manager for Mandriva, a Linux distribution that was not affected by the bug. "If you're running a Debian shop and you have 100 certificates, depending on who you've got as a certificate authority, you could be looking at big bucks to regenerate your keys and get them re-signed. It could take months or even years for all the keys to get weeded out."

UK Government Considering Database of all Phone calls

BIG BROTHER : UK Government Considering Database of all Phone calls

BBC NEWS

2008/05/20

http://news.bbc.co.uk/go/pr/fr/-/2/hi/uk_news/7409593.stm

Ministers are to consider plans for a database of electronic information holding details of every phone call and e-mail sent in the UK, it has emerged.

The plans, reported in the Times, are at an early stage and may be included in the draft Communications Bill later this year, the Home Office confirmed.

A Home Office spokesman said the data was a "crucial tool" for protecting national security and preventing crime.

Ministers have not seen the plans which were drawn up by Home Office officials.

A Home Office spokesman said: "The Communications Data Bill will help ensure that crucial capabilities in the use of communications data for counter-terrorism and investigation of crime continue to be available.

"These powers will continue to be subject to strict safeguards to ensure the right balance between privacy and protecting the public."

The spokesman said changes need to be made to the Regulation of Investigatory Powers Act 2000 "to ensure that public authorities can continue to obtain and have access to communications data essential for counter-terrorism and investigation of crime purposes".

But the Information Commission, an independent authority set up to protect personal information, said the database "may well be a step too far" and highlighted the risk of data being lost, traded or stolen.

Assistant information commissioner Jonathan Bamford said: "We are not aware of any justification for the state to hold every UK citizen's phone and internet records. We have real doubts that such a measure can be justified, or is proportionate or desirable.

"Defeating crime and terrorism is of the utmost importance, but we are not aware of any pressing need to justify the government itself holding this sort of data."

'Appalling record'

A number of data protection failures in recent months, including the loss of a CD carrying the personal details of every child benefit claimant, have embarrassed the government.

The plans also prompted concern from political groups.

The shadow home secretary, David Davis, said: "Given [ministers'] appalling record at maintaining the integrity of databases holding people's sensitive data, this could well be more of a threat to our security than a support."

Liberal Democrat home affairs spokesman Chris Huhne called the proposals "an Orwellian step too far".

He said ministers had "taken leave of their senses if they think that this proposal is compatible with a free country and a free people".

"Given the appalling track record of data loss, this state is simply not to be trusted with such private information," said Mr Huhne.

Cyber Threats to US Electrical Grid

THREAT : Cyber Threats to US Electrical Grid

Grant Gross

IDG News Service

May 21, 2008

http://www.pcworld.com/businesscenter/article/146153/lawmakers_see_cyber_threats_to_electrical_grid.html

The U.S. electrical grid remains vulnerable to cyber attacks that could cripple the economy, and the organization responsible for regulating electrical suppliers doesn't appear to be serious about fixing the problems, some U.S. lawmakers said Wednesday.

U.S. Representative James Langevin and other members of the House of Representatives Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology questioned whether the North American Electric Reliability Corp. (NERC), an electric industry group tasked with ensuring electric reliability, is doing its job.

NERC officials last October painted a "misleading" and rosy picture of the U.S. electric system's readiness for cyber attacks, said Langevin, a Rhode Island Democrat and chairman of the subcommittee. But Langevin has "little confidence" that the U.S. electrical grid has fully addressed the so-called Aurora vulnerability, a cyber attack aimed at shutting down electric utilities' generators or other equipment, he said.

"I still do not get the sense that we are addressing cybersecurity with the seriousness that it deserves," Langevin added. "I think we could search far and wide and not find a more disorganized, ineffective response to an issue of national security of this import. If NERC doesn't start getting serious about national security, it may be time to find a new electric reliability organization."

The U.S. and Canadian governments have given NERC authority to ensure the reliability of the electric grid. Last October, a NERC official told Congress that utilities covering 75 percent of the U.S. power grid were taking actions to fix Aurora vulnerabilities first identified by the U.S. Department of Homeland Security in 2006.

But the U.S. Government Accountability Office (GAO) released a report on Wednesday identifying numerous cyber vulnerabilities at the Tennessee Valley Authority (TVA), the nation's largest public power company. The GAO issued 92 recommendations to the TVA, which supplies power to 8.7 million U.S. residents in Tennessee and parts of six other states.

"The corporate network was interconnected with control systems networks GAO reviewed, thereby increasing the risk that security weaknesses on the corporate network could affect those control systems networks," the GAO report said.

On the TVA's control systems networks, firewalls were inadequately configured or bypassed, passwords were ineffectively implemented, and servers and workstations lacked key patches and effective virus protection, said Greg Wilshusen, director of information security issues at the GAO. "Until TVA fully implements these security program activities, it risks a disruption of its operations as the result of a cyber incident," Wilshusen said.

TVA's corporate network had some of the same vulnerabilities, including a lack of key software patches, limited security configurations and an intrusion-detection system with "significant limitations," the report said.

The TVA had already been working to fix the problems when the GAO investigation happened, said William McCollum Jr., chief operating officer of the TVA. The power supplier has addressed several of the issues identified by the GAO, McCollum said, and the TVA would address most of the problems by the end of the year. But McCollum could not give lawmakers a definite date when all the issues would be fixed.

NERC, with help from the Federal Energy Regulatory Commission, is implementing cybersecurity requirements that come online in July, instead of the advisories it had authority to issue in the past, said Richard Sergel, NERC's president and CEO.

Sergel pledged to push cybersecurity issues with electric utilities and paint a clearer picture of problems before Congress. "The responsibility to be clear [about problems] is ours," he said.

Phishers turn to legit sites to steal information

TOM & JERRY : Phishers turn to legit sites to steal information

Dan Kaplan

May 21 2008

http://www.scmagazineus.com/Phishers-turn-to-legit-sites-to-steal-information/article/110388/

Phishers have discovered a new way in which to launch phishing attacks that will allow the assaults to persist for much longer than usual.

They are turning to infiltrating legitimate websites on which to host their attacks -- a technique known as "hack-and-pier," according to Finnish anti-virus firm F-Secure.

Normally, internet service providers take down fraudulent websites within 24 hours, according to research, but when an authentic site is the culprit, much more work is involved.

"The site cannot simply be pulled offline without collateral damage to the legitimate business," Sean Sullivan, a technical specialist at F-Secure, said Wednesday on the company's blog. "So the website's administrator must be contacted to repair the damage."

Sullivan mentioned B.B.C. Sales & Service, a Canada-based beverage equipment provider, as one of a number of legitimate websites that has been exploited to host phishing scams. A company spokeswoman did not immediately respond to a request for comment Wednesday.

Sullivan said that until websites repair vulnerabilities that permit hackers access, this new style of attack will continue.

This Day in History

Thanks for your Visit