CRYPTO-GRAM
November 15, 2011
by Bruce Schneier
Chief Security Technology Officer, BT
[email protected]
http://www.schneier.com
A free monthly newsletter providing summaries, analyses, insights, and
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at
<http://www.schneier.com/crypto-gram-1111.html>. These same essays and
news items appear in the "Schneier on Security" blog at
<http://www.schneier.com/blog>, along with a lively comment section. An
RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
Advanced Persistent Threat (APT)
News
Another ATM Theft Tactic
Remotely Opening Prison Doors
Schneier News
Fake Documents that Alarm if Opened
** *** ***** ******* *********** *************
Advanced Persistent Threat (APT)
It's taken me a few years, but I've come around to this buzzword. It
highlights an important characteristic of a particular sort of Internet
attacker.
A conventional hacker or criminal isn't interested in any particular
target. He wants a thousand credit card numbers for fraud, or to break
into an account and turn it into a zombie, or whatever. Security
against this sort of attacker is relative; as long as you're more secure
than almost everyone else, the attackers will go after other people, not
you. An APT is different; it's an attacker who -- for whatever reason
-- wants to attack you. Against this sort of attacker, the absolute
level of your security is what's important. It doesn't matter how
secure you are compared to your peers; all that matters is whether
you're secure enough to keep him out.
APT attackers are more highly motivated. They're likely to be better
skilled, better funded, and more patient. They're likely to try several
different avenues of attack. And they're much more likely to succeed.
This is why APT is a useful buzzword.
** *** ***** ******* *********** *************
News
Interesting article on the criminal use of crowdsourcing.
http://www.forbes.com/sites/oreillymedia/2011/10/03/the-rise-of-crime-sourcing/
or http://tinyurl.com/3vjrola
Discovering what Facebook knows about you: interesting developments from
Europe.
http://www.identityblog.com/?p=1201
http://europe-v-facebook.org/DE/Anzeigen/anzeigen.html
A newly discovered piece of malware, Duqu, seems to be a precursor to
the next Stuxnet-like worm and uses some of the same techniques as the
original.
http://www.wired.com/threatlevel/2011/10/son-of-stuxnet-in-the-wild/
http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet
http://www.f-secure.com/weblog/archives/00002255.html
A contrary view:
http://krypt3ia.wordpress.com/2011/10/19/the-son-of-stuxnet-methinks-the-cart-be-before-ye-horse/
or http://tinyurl.com/5t6ntjx
Interesting analysis of random passwords in the wild.
http://www.lightbluetouchpaper.org/2011/08/24/randomly-generated-passwords-at-mybart/
or http://tinyurl.com/3zxkwv7
It turns out that "2bon2btitq" is not a strong password.
http://www.lightbluetouchpaper.org/2011/11/08/want-to-create-a-really-strong-password-dont-ask-google/
or http://tinyurl.com/cnnh7sz
Google enables SSL by default for search. This is a good thing.
http://www.theregister.co.uk/2011/10/19/google_default_ssl/
http://m.wired.com/threatlevel/2011/10/google-search-https/
There's a patent application from Facebook that seems to cover tracking
people even when they're not logged in to Facebook.
http://www.schneier.com/blog/archives/2011/10/facebook_patent.html
Blue Coat products enable web censorship in Syria. It's illegal for
Blue Coat to sell its technology for this purpose, but there are lots of
third parties who are willing to act as middlemen. Bet you anything
that the Syrian Blue Coat products are registered, and that they receive
all the normal code and filter updates.
http://www.thebureauinvestigates.com/2011/10/23/us-technology-used-to-censor-the-internet-in-syria/
or http://tinyurl.com/3gcu8cu
The Wall Street Journal confirms it: "The appliances do have Blue Coat
service and support contracts. The company says it has now cut off
contracts for the devices."
http://online.wsj.com/article/SB10001424052970203687504577001911398596328.html
The second document in this file is the recently unclassified "Guide to
Historical Cryptologic Acronyms and Abbreviations, 1940-1980," from the
NSA. Note that there are still some redactions.
http://www.governmentattic.org/5docs/3-NSA-HistRecords_2002-2010.pdf
The Twofish encryption algorithm is mentioned in the book "Abuse of Power."
http://www.schneier.com/blog/archives/2011/10/twofish_mention.html
Google releases statistics on law-enforcement demands for Google's data.
I'm sure they have an office full of attorneys versed in the laws of
various countries.
http://pda.physorg.com/news/2011-10-google-demands-info.html
http://m.wired.com/threatlevel/2011/10/google-data-requests/
I don't follow historical cryptography, so all of this comes as a
surprise to me. But something called the Copiale Cipher from the 18th
Century has been cracked.
http://www.nytimes.com/2011/10/25/science/25code.html
http://stp.lingfil.uu.se/~bea/copiale/
EFF reports on the security of SSL:
https://www.eff.org/deeplinks/2011/10/how-secure-https-today
Secret codes in bacteria.
http://news.sciencemag.org/sciencenow/2011/09/a-different-kind-of-secret-code.html
or http://tinyurl.com/3zueypc
This XKCD is a good one. Be sure to read the hover-over text.
http://xkcd.com/970/
Brian Krebs has done some analysis on the attack that compromised RSA in
March; it's something like 760 companies that were compromised.
http://krebsonsecurity.com/2011/10/who-else-was-hit-by-the-rsa-attackers/ or
http://tinyurl.com/67ldcwk
http://money.cnn.com/2011/10/27/technology/rsa_hack_widespread/
I was not surprised that police forces are buying this cell phone
surveillance system, but at its capabilities.
http://www.guardian.co.uk/uk/2011/oct/30/metropolitan-police-mobile-phone-surveillance
or http://tinyurl.com/6jgjjlr
Company website:
http://www.datong.co.uk/
Two articles from The Economist on lying:
http://www.economist.com/node/21534748
http://www.economist.com/node/21534780
And this is the cited work:
http://medicalxpress.com/news/2011-10-brain-imaging-true.html
http://gallantlab.org/
http://www.princeton.edu/~fpereira/research.shtml
I note that the three "industry leaders" speaking at the DARPA Cyber
Colloquium next week have about 75 years of government experience among
them.
https://www.signup4.net/Public/ap.aspx?EID=DARP102E
Interesting research on how parents help their children lie about their
age to get onto Facebook.
http://www.zephoria.org/thoughts/archives/2011/11/01/parents-survey-coppa.html
or http://tinyurl.com/42at3kr
http://www.uic.edu/htbin/cgiwrap/bin/ojs/index.php/fm/article/view/3850/3075
or http://tinyurl.com/3wyungm
Media coverage:
http://huff.to/rVocz5
http://cnet.co/tnNPw1
>From the "Journal of Strategic Studies": "Cyber War Will Not Take Place":
http://www.tandfonline.com/doi/abs/10.1080/01402390.2011.608939
Here's another article: "The Non-Existent 'Cyber War' Is Nothing More
Than A Push For More Government Control."
http://www.techdirt.com/articles/20111023/02413916479/non-existent-cyber-war-is-nothing-more-than-push-more-government-control.shtml
or http://tinyurl.com/3v59t2g
Weaponized UAV drones in the hands of local police:
http://www.schneier.com/blog/archives/2011/11/weaponized_uav.html
Cutting wallets out of drunks' pockets on New York City subways: it's a
crime with finesse.
http://www.nytimes.com/2011/11/05/nyregion/lush-workers-cut-wallets-from-pockets-of-drunk-train-riders.html
or http://tinyurl.com/6mmpm3s
Pickpockets of all kinds may be a dying breed in New York.
http://www.slate.com/articles/arts/culturebox/2011/02/the_lost_art_of_pickpocketing.html
or http://tinyurl.com/3jc48zf
Unlocking any iPad2 using a Smart Cover.
http://gizmodo.com/5852036/how-to-break-into-any-ipad-2-with-just-a-smart-cover
or http://tinyurl.com/3deqtxq
The bug has been patched.
More SSL woes from Mikko Hypponen: "We found a malware sample. Which was
signed. With a valid certificate. Belonging to the Government of Malaysia."
https://twitter.com/#!/mikko/status/136090183857745920
http://www.f-secure.com/weblog/archives/00002269.html
There's a group who charges to make social engineering calls to obtain
missing personal information for identity theft. This doesn't surprise
me at all. Fraud is a business, too.
http://www.itbusiness.ca/it/client/en/home/News.asp?id=64887
** *** ***** ******* *********** *************
Another ATM Theft Tactic
This brazen tactic is from Malaysia. Robbers sabotage the machines, and
then report the damage to the bank. When the banks send repair
technicians to open and repair the machines, the robbers take the money
at gunpoint.
It's hardly a technology-related attack. But from what I know about
ATMs, the security of the money safe inside the machine is separate from
the security of the rest of the machine. So it seems that the repair
technicians might be given access to only the machine but not the safe
inside.
http://thestar.com.my/news/story.asp?file=/2011/10/6/nation/9638034&sec=nation
or http://tinyurl.com/3ea6dwh
** *** ***** ******* *********** *************
Remotely Opening Prison Doors
Researchers have found a vulnerability in computer-controlled
prison-door systems that allows them to be remotely opened over the
Internet. This assumes that they're connected to the Internet in the
first place, which some of them are.
The weirdest part of the article was this last paragraph.
"You could open every cell door, and the system would be telling
the control room they are all closed," Strauchs, a former CIA
operations officer, told the Times. He said that he thought
the greatest threat was that the system would be used to create
the conditions needed for the assassination of a target prisoner.
I guess that's a threat. But the *greatest* threat?
http://arstechnica.com/business/news/2011/11/vulnerabilities-give-hackers-ability-to-open-prison-cells-from-afar.ars
or http://tinyurl.com/7533eze
The original paper:
http://www.google.co.uk/url?sa=t&rct=j&q=tiffany%20rad%2C%20teague%20newman%2C%20and%20john%20strauchs&source=web&cd=2&ved=0CCMQFjAB&url=http%3A%2F%2Fwww.exploit-db.com%2Fdownload_pdf%2F17979%2F&ei=iznBTtzMLsew8gPLxNSfBA&usg=AFQjCNFwfgrkcWZC2Cg5R2FgNpSLd24orQ&sig2=Oz90YVa4SCdCeErXfKc_EQ
or http://tinyurl.com/ccvjl7q
** *** ***** ******* *********** *************
Schneier News
I'm speaking at Internetdagarna in Stockholm on November 21.
http://www.internetdagarna.se/ind10/english
I'm speaking at The Register and Intel Live in London on November 22.
http://forms.theregister.co.uk/misc/live11/
And I'm speaking at the CISO Executive Summit in Chicago on December 1.
http://www.evanta.com/events/245/agenda
** *** ***** ******* *********** *************
Fake Documents that Alarm if Opened
Creating fake documents that alarm if opened seems like a decent
approach to the problem of insider information theft, but it has a lot
of practical problems.
In the wake of Wikileaks, the Department of Defense has stepped up
its game to stop leaked documents from making their way into the
hands of undesirables -- be they enemy forces or concerned
citizens. A new piece of software has created a way to do this by
generating realistic, fake documents that phone home when they're
accessed, serving the dual purpose of providing false intelligence
and helping identify the culprit.
Details aside, this kind of thing falls into the general category of
data tracking. It doesn't even have to be fake documents; you could
imagine some sort of macro embedded into Word or pdf documents that
phones home when the document is opened. (I have no idea if you
actually can do it with those formats, but the concept is plausible.)
This allows the owner of a document to track when, and possibly by what
computer, a document is opened.
But by far the biggest drawback from this tech is the possibility
of false positives. If you seed a folder full of documents with a
large number of fakes, how often do you think an authorized user
will accidentally double click on the wrong file? And what if they
act on the false information? Sure, this will prevent hackers from
blindly trusting that every document on a server is correct, but
we bet it won't take much to look into the code of a document and
spot the fake, either.
I'm less worried about false positives, and more concerned by how easy
it is to get around this sort of thing. Detach your computer from the
Internet, and the document no longer phones home. A fix is to combine
the system with an encryption scheme that requires a remote key. Now
the document *has* to phone home before it can be viewed. Of course,
once someone is authorized to view the document, it would be easy to
create an unprotected copy -- screen captures, if nothing else -- to
forward along,
While potentially interesting, this sort of technology is not going to
prevent large data leaks. But it's good to see research.
http://www.theverge.com/2011/11/4/2537647/darpa-fake-documents-security-wikileaks
** *** ***** ******* *********** *************
Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing
summaries, analyses, insights, and commentaries on security: computer
and otherwise. You can subscribe, unsubscribe, or change your address
on the Web at <http://www.schneier.com/crypto-gram.html>. Back issues
are also available at that URL.
Please feel free to forward CRYPTO-GRAM, in whole or in part, to
colleagues and friends who will find it valuable. Permission is also
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entirety.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of the
best sellers "Schneier on Security," "Beyond Fear," "Secrets and Lies,"
and "Applied Cryptography," and an inventor of the Blowfish, Twofish,
Threefish, Helix, Phelix, and Skein algorithms. He is the Chief
Security Technology Officer of BT BCSG, and is on the Board of Directors
of the Electronic Privacy Information Center (EPIC). He is a frequent
writer and lecturer on security topics. See <http://www.schneier.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not
necessarily those of BT.
Copyright (c) 2011 by Bruce Schneier.
** *** ***** ******* *********** *************
To unsubscribe, click this link:
http://listserv.modwest.com/cgi-bin/wa?TICKET=NzM0NDg2IGFyY2hpdmVATUFJTC1BUkNISVZFLkNPTSBDUllQVE8tR1JBTS1MSVNUIO9AKJz4Tf+O&c=SIGNOFF