Tuesday, February 19, 2019

Patch Tuesday Feb 2019

Microsoft on Tuesday issued numerous patches to correct at least 70 distinct security vulnerabilities in Windows and software designed to interact with various flavors of the operating system. This month’s patch batch tackles some notable threats to enterprises — including multiple flaws that were publicly disclosed prior to Patch Tuesday. It also bundles fixes to quash threats relevant to end users, including critical updates for Adobe Flash Player and Microsoft Office, as well as a zero-day bug in Internet Explorer.
Some 20 of the flaws addressed in February’s update bundle are weaknesses labeled “critical,” meaning Microsoft believes that attackers or malware could exploit them to fully compromise systems through little or no help from users — save from convincing a user to visit a malicious or hacked Web site.
Microsoft patched a bug in Internet Explorer (CVE-2019-0676) discovered by Google that attackers already are using to target vulnerable systems. This flaw could allow malware or miscreants to check for the presence of specific files on the target’s hard drive.
Another critical vulnerability that impacts both end users and enterprises is a weakness in the Windows component responsible for assigning Internet addresses to host computers (a.k.a. “Windows DHCP client”). That flaw, CVE-2019-0626, could let an attacker execute malcode of his choice just by sending the target a specially crafted DHCP request.
At the top of the list of patch concerns mainly for companies is a publicly disclosed issue with Microsoft Exchange services (CVE-2019-0686) that could allow an attacker on the same network as the target to access the inbox of other users. Microsoft said it has not seen active exploitation of this bug yet, but considers it likely to be exploited soon.
Security experts are fond of saying “patch now!” when it comes to Windows bugs, but in general it can’t hurt for regular users to wait a day or two after Microsoft releases monthly security updates before installing the fixes. That’s because occasionally buggy patches can cause serious headaches for users who install them before all the kinks are worked out.
Just don’t put off the task too long. And bear in mind it’s a good idea to get in the habit of backing up your data before installing Windows updates, to hedge against the odd case in which a wonky patch ends up rendering your system unusable until you can work out how to reverse the changes.
Windows 10 likes to install patches all in one go and reboot your computer on its own schedule. Microsoft doesn’t make it easy for Windows 10 users to change this setting, but it is possible. For all other Windows OS users, if you’d rather be alerted to new updates when they’re available so you can choose when to install them, there’s a setting for that in Windows Update.
Microsoft also included fixes to address a single vulnerability in Adobe Flash Player. Microsoft and Adobe disagree on the severity of this flaw, according to security firm Qualys. Adobe labels it an “important” bug, while Microsoft tags it with a far more severe “critical” label. Regardless, Flash flaws are favorite targets of attackers. If you browse the Web with IE or Edge, this month’s patch batch from Microsoft has you covered.
Fortunately, the most popular Web browser by a long shot — Google Chrome — auto-updates Flash but also is now making users explicitly enable Flash every time they want to use it (Microsoft also bundles Flash with IE/Edge and updates it whenever Windows systems install monthly updates). By the summer of 2019 Google will make Chrome users go into their settings to enable it every time they want to run it.
Firefox also forces users with the Flash add-on installed to click in order to play Flash content; instructions for disabling or removing Flash from Firefox are here. Adobe will stop supporting Flash at the end of 2020.
Adobe also released updates for Adobe Acrobat and Reader that plug at least 70 security holes in these applications, so if you have either installed please be sure to update those.
As always, if you experience any problems installing any of these patches this month, please feel free to leave a comment about it below; there’s a good chance other readers have experienced the same and may even chime in here with some helpful tips.

Monday, January 28, 2019

Microsoft to end support for Windows 7 in Jan 2019

A new reminder for those who are still holding on to the Windows 7 operating system you have less than one year left until Microsoft ends support for its 9-year-old operating system. So it's time for you to upgrade your OS and say goodbye to Windows 7, as its five years of extended support will end on January 14, 2020.


After that date, the tech giant will no longer release free security updates, bug fixes and new functionalities for the operating system that's still widely used by people, which could eventually leave a significant number of users more susceptible to malware attacks.

However, the end of free support doesn't end Windows 7 support for big business and enterprise customers. As always, Microsoft does make exceptions for certain companies that are willing to pay a lot of money to continue their support.

According to a 'Death of Windows 7' report from content delivery firm Kollective, as many as 43% of enterprises are still running the nine-year-old operating system, of which 17% didn't know when Microsoft's end of support deadline hit.

Millions of Users Are Still Using Windows 7
Want to know how popular Windows 7 is among users? Even after aggressively pushing Windows 10 installations since its release in 2015, its market share finally managed to overtake the user-favorite Windows 7 just by the end of last year.

Windows 7 was released in 2009 and, according to December 2018 stats from Netmarketshare, is currently running on about 37 percent of the world's PC fleet, which is far ahead of its radically redesigned successor Windows 8 and 8.1 combined.

Microsoft stopped the mainstream support for Windows 7 in January 2015, but Windows users have continued to receive security updates and patches for known security issues as part of the company's extended support, which runs for at least five years.

In March 2017, Microsoft also started blocking new security patches and updates for Windows 7 and Windows 8.1 users running the latest processors from Intel, AMD, Qualcomm, and others.

"For Windows 7 to run on any modern silicon, device drivers and firmware need to emulate Windows 7's expectations for interrupt processing, bus support, and power states- which is challenging for WiFi, graphics, security, and more," the company said.

"The lifecycle begins when a product is released and ends when it’s no longer supported. Knowing key dates in this lifecycle helps you make informed decisions about when to update, upgrade or make other changes to your software."

Besides ending support for Windows 7 next year, Microsoft will also end support for MS Office 2010, Windows Server 2008/2008 R2, SQL Server 2008/2008 R2, Exchange 2010 and Windows Embedded 7 in 2020.

As for Windows 8, the operating system's extended support is set to end on January 10, 2023.


Monday, January 21, 2019

Data Privacy Day

Nearly every day is some kind of holiday or special observance at the local, state or national level. Some days are assigned to multiple causes.
Feb. 2, for example is Groundhog Day and Feb. 3 is the Super Bowl, an undeclared national holiday that’s always on a Sunday.
Data Privacy Day, which is Jan. 28, comes a few days before. It’s a less heralded observance that has become increasingly relevant in the digital era. The international observance is designed to increase public awareness of the importance of respecting privacy, safeguarding data and enabling trust.
The special day, promoted by the National Cyber Security Alliance (NCSA) has been observed in Europe since 1981 and in the United States since 2008. In 2014, Congress adopted a nonbinding resolution that expressed support for the observance.
Advances in high-tech fields such as automation and artificial intelligence, as well as old-fashioned criminal greed, have made digital data difficult to protect.
Transparency can help a company build trust. But, of course, transparency isn’t enough. Responsible businesses also recognize that they have a strong obligation to protect information about their customers and employees.
Among the resources available to help businesses enhance the security of electronic information is the NCSA-powered website, StaySafeOnline.org. The NCSA also supports “Stop. Think. Connect.” That’s a global campaign whose supporters include businesses, law enforcement agencies and the federal government.
Free information on the StaySafeOnline site includes a two-page technology checklist designed to help small and medium-sized businesses. The checklist addresses several general areas of concern, including the use of Wi-Fi, mobile devices, email and other digital tools.
The section on websites, for example, offers the following advice:
  • Keep software up to date.
  • Require users to create strong passwords.
  • Prevent direct access for uploading files.
  • Use scanning tools to test a site’s security.
  • Register sites with spellings similar to your site.
  • Run the most current versions of content management systems or require web administrator/hosts to do so.
As StaySafeOnline noted in a recent news release, people are living in an unparalleled age of technological growth. By 2020, there is expected to be more than four connected devices for every person in the world.
“As businesses learn to extract value from and utilize data at a deeper level, it is essential for companies to be extremely conscientious about protecting personal information,” according to the group. “For any organization, respecting consumers’ privacy is a smart strategy for inspiring trust and enhancing reputation and growth.”
StaySafeOnline encourages organizations to create a culture that values privacy. It also offers three simple tips to help businesses build a high level of trust:
  • If your company collects data about consumers and employees, protect it.
  • Be open and honest about how information is collected, used and shared.
  • Do what you say you do.

Thursday, October 4, 2018

Recent Facebook Data Breach


With the recent data breach at Facebook, highlighting the importance of knowing how to minimize the risk of cyber threats and how to respond if your personal data may have been compromised is very important to everyone.
On Friday, it was reported that approximately 50 million user Facebook accounts were impacted by a data breach. Facebook did not indicate if any user information was accessed.
The Office of Consumer Protection recommends the following best practices for consumers who use social media:
§  Change your password regularly, and always use a strong password.
§  When available, use two-factor authentication for login.
§  Refrain from using any automatic sign-in functions/features of social media accounts and applications.
§  Monitor your privacy settings and adjust as needed.
§  Remove birth dates, addresses, and phone numbers from your account information.
§  Carefully consider the information you post, recognizing that in the event of a data breach, it could end up in the hands of people intent upon stealing your identity or conducting other malicious activities.

Scammers who obtain the personal information of others may try to open new accounts or extort money from their victims. According to the office of Consumer Protection, there are several options for people to monitor their credit and keep their identities safe, including:
§  Don’t pay a ransom. Paying a ransom is an ineffective way of handling the exposure of your personal information. It’s best to focus on proactively securing your identity.
§  Consider a free security freeze. A security freeze allows you to “lock up” your credit information so no one can access it without your permission. A freeze prevents a thief from taking out a new mortgage, applying for a credit card, or getting financing with your identity. When you “freeze” your credit, it stays frozen for as long as you’d like – until you can comfortably “thaw” it once again.
§  Place a fraud alert on your credit. Fraud alerts are a special message you can place on your credit report. The alert tells credit issuers there may be fraudulent activity on an account. Fraud alerts last for 90 days; although they won’t stop a scammer from being issued new credit, they can slow them down.
§  Request a free credit report annually.  Reviewing your credit report is a great way to check for unauthorized activity.  Visit www.annualcreditreport.com or call 1-877-322-8228 to request your free annual report.
§  Credit monitoring services offer additional protection.  Credit monitoring services track changes in your behavior and send you notifications about your credit score and potential fraud. These services typically cost between $10 — $30 per month.


Tuesday, March 13, 2018

Spectre & Meltdown - What you should know



Security researchers revealed two more major software vulnerabilities that, in one way or another, affect just about anything with a processor. The flaws, called “Spectre” and “Meltdown,” can potentially allow hackers to steal encrypted passwords as you type them in. If Spectre has you spooked, read on to learn more about these vulnerabilities and what’s being done to fix them.

What are Spectre and Meltdown?
Both Spectre and Meltdown refer to variants of the same vulnerabilities, all of which many researchers are considering catastrophic due to their widespread nature. And, they’ve been given names to match the extent of their impact. Spectre refers to a root cause, or to something that is difficult to fix (and will haunt us for years to come!). Meltdown is used to describe the “melting of the security boundaries” that is occurring, since the bugs make the usual protections from hardware unenforceable.

The vulnerability was originally thought to only impact Intel chipsets. However, it’s far more complex and widespread: nearly all systems are affected, from desktops and laptops to mobile devices, across Intel, AMD and ARM processors. All memory data from running apps is potentially vulnerable: password managers, photos, documents and more. As one researcher told ZDNet, “an attacker might be able to steal any data on the system.”
Essentially, each vulnerability is a security flaw in nearly every processor built in the last 20 years. This means a vast number of systems – all those built with Intel, ARM, or AMD processors – will require a security update. The bug itself is linked to how regular apps and programs “discover the contents of protect kernel memory areas.” In operating systems, kernels act as the core component; tying together applications and data processing, memory and hardware. The flaw in the affected processors may allow hackers to maneuver around the processor’s kernel access protections, making the contents of the kernel’s memory vulnerable.

Just how bad is it?
The initial focus of the patches has been on personal devices. Numerous patches are already available, but researchers are still investigating the effect Spectre may have on cloud services,
where several organizations are sharing the same resources. There’s been some speculation about data vulnerabilities—where one cloud tenant may be able to access the data of another.
Consider the impact, across the cloud, with privilege escalation. The reality is, data could be stolen in any instance where tenants share the same chip in services such as Amazon Web Services (AWS) or the Google Cloud. Small to mid-size organizations are especially vulnerable here, since so many of them run their entire businesses on shared cloud services.

Regarding your personal computer, this is when a hacker could leverage Spectre essentially take over your entire computer. But before you panic, remember, there are other ways a hacker could do this today (without these newly discovered vulnerabilities), so frankly, it’s up in the air as far as how much your risk has increased.

What’s being done about it?
Software patches have been released one after the other to help reduce the risk. Microsoft released an emergency patch January 3 and Intel is issuing updates for all types of processors, starting with those new in the last five years. Apple has released three updates to protect Safari and WebKit. And, cloud service providers, such as AWS and Microsoft Azure, are all deploying patches as well, while they wait for third-party patches to roll in to complement their efforts. But to truly reduce the risk, updates will need to be released across all vendors, from Intel and AMD to anti-malware vendors whose software needs to work appropriately with the new patches.

There’s been much discussion among IT professionals about the impact that these updates and patches could have on system performance. Some speculate it could cause systems to dramatically slow down, and others say that if Intel processors are using Skylake or more recent architecture, the impact will hardly be noticed. If organizations do experience a noticeable slowdown in performance, it’s likely they are using older processors.

What you can do about it
There’s a few things you can do now to mitigate your risk. The following steps will help shield you from the Meltdown variant:
• If you use Chrome or Firefox, update to the latest versions
• In the meantime, for Chrome users, here’s an easy workaround: copy and paste “chrome://flags/#enable-site-per-process” into your browser, and click “Enable.” Site Isolation loads each individual website as a separate process, preventing other remote connections from hijacking otherwise safe sites.
• Be diligent about your Windows updates. Make sure update KB4056892 is installed.
• Regularly check with your PC manufacturer’s website to see if they’ve released any news or firmware updates.
• Wait and install third-party updates as they become available.

Thursday, January 18, 2018

Rules for Securing Your IoT


Most people here have likely heard or read various prognostications about the impending doom from the proliferation of poorly-secured “Internet of Things” or IoT devices. Loosely defined as any gadget or gizmo that connects to the Internet but which most consumers probably wouldn’t begin to know how to secure, IoT encompasses everything from security cameras, routers and digital video recorders to printers, wearable devices and “smart” lightbulbs.

Throughout 2016 and 2017, attacks from massive botnets made up entirely of hacked IoT devices had many experts warning of a dire outlook for Internet security. But the future of IoT doesn’t have to be so bleak. Here are some basic rules for minimizing the chances that your IoT things become a security liability for you or for the Internet at large.

Avoid connecting your devices directly to the Internet — either without a firewall or in front it, by poking holes in your firewall so you can access them remotely. Putting your devices in front of your firewall is generally a bad idea because many IoT products were simply not designed with security in mind and making these things accessible over the public Internet could invite attackers into your network. If you have a router, chances are it also comes with a built-in firewall. Keep your IoT devices behind the firewall as best you can.

If you can, change the systems default credentials to a complex password that only you will know and can remember. And if you do happen to forget the password, it’s not the end of the world: Most devices have a recessed reset switch that can be used to restore to the thing to its factory-default settings (and credentials). Here’s some advice on picking better ones.

I say “if you can,” at the beginning of Rule #2 because very often IoT devices — particularly security cameras and DVRs — are so poorly designed from a security perspective that even changing the default password to the thing’s built-in Web interface does nothing to prevent the things from being reachable and vulnerable once connected to the Internet.

Also, many of these devices are found to have hidden, undocumented “backdoor” accounts that attackers can use to remotely control the devices. That’s why Rule #1 is so important.

Update the firmware. Hardware vendors sometimes make available security updates for the software that powers their consumer devices (known as “firmware). It’s a good idea to visit the vendor’s Web site and check for any firmware updates before putting your IoT things to use, and to check back periodically for any new updates.

Check the defaults, and make sure features you may not want or need like UPnP (Universal Plug and Play — which can easily poke holes in your firewall without you knowing it) — are disabled.
Want to know if something has poked a hole in your router’s firewall? Censys has a decent scanner that may give you clues about any cracks in your firewall. Browse to whatismyipaddress.com, then cut and paste the resulting address into the text box at Censys.io, select “IPv4 hosts” from the drop-down menu, and hit “search.” If that sounds too complicated (or if your ISP’s addresses are on Censys’s blacklist) check out Steve Gibson‘s Shield’s Up page, which features a point-and-click tool that can give you information about which network doorways or “ports” may be open or exposed on your network. A quick Internet search on exposed port number(s) can often yield useful results indicating which of your devices may have poked a hole.

If you run antivirus software on your computer, consider upgrading to a “network security” or “Internet security” version of these products, which ship with more full-featured software firewalls that can make it easier to block traffic going into and out of specific ports.
Alternatively, Glasswire is a useful tool that offers a full-featured firewall as well as the ability to tell which of your applications and devices are using the most bandwidth on your network. Glasswire recently came in handy to help me determine which application was using gigabytes worth of bandwidth each day (it turned out to be a version of Amazon Music’s software client that had a glitchy updater).

Avoid IoT devices that advertise Peer-to-Peer (P2P) capabilities built-in. P2P IoT devices are notoriously difficult to secure, and research has repeatedly shown that they can be reachable even through a firewall remotely over the Internet because they’re configured to continuously find ways to connect to a global, shared network so that people can access them remotely. For examples of this, see previous stories here, including This is Why People Fear the Internet of Things, and Researchers Find Fresh Fodder for IoT Attack Cannons.

Consider the cost. Bear in mind that when it comes to IoT devices, cheaper usually is not better. There is no direct correlation between price and security, but history has shown the devices that tend to be toward the lower end of the price ranges for their class tend to have the most vulnerabilities and backdoors, with the least amount of vendor upkeep or support.

One final note: I realize that the people who probably need to be reading these tips the most likely won’t ever know they need to care enough to act on them. But at least by taking proactive steps, you can reduce the likelihood that your IoT things will contribute to the global IoT security problem.

Wednesday, September 27, 2017

How to Get Your Employees Thinking about Cyber Security


Large scale cyber-attacks are, it seems, never far from the headlines these days and each event ought to serve as a warning to businesses alike. In September alone we have had four examples where we have been impacted by a data breach. Deloitte, SEC, Equifax, and Sonic among the organizations breached.

But, it isn’t just the big boys who are suffering at the hands of hackers. It’s said that 14 million small businesses in the US were hacked in the last year – which is about half of the total.

It’s a big threat for businesses, and that means you have to think about how these businesses can protect themselves. One of the most important things to remember is that security is a team effort. Your business won’t be secure if everyone doesn’t know how they can play their part. If you can get everyone thinking about cyber security—and appreciating the role that they can play—then that’s half of the battle overcome.

So, how can we get there?

Introduce processes
You need to introduce processes in your business that put cyber security at the forefront. Whether it’s the way you manage the passwords used to access your systems, the way in which you handle your paperwork to keep confidential data secure, or the way in which you deploy antivirus software and encryption to protect your systems and the data held within them, it all needs solidifying. Crucially, you also need to ensure that your processes are effectively communicated to every member of your staff and that there’s a clear structure in place for anyone to raise queries, report issues or suggest gaps in your defenses that need to be addressed.

Nominate people with responsibility
With that in mind, your processes will be most effective if they are introduced alongside a structure. This might mean nominating one person to take the lead on cyber security within your organization or, if you’re big enough, it might mean appointing a team of people. These people can monitor and review your processes, ensure they are implemented and be at the center of an effective communication strategy. By making responsibility clear, it helps to avoid a situation where employees all presume that it’s someone else’s job.

Training sessions
Once you have your structure in place and your process mapped out, it’s time to think about training. Every member of your staff should be clear on your cyber security strategy—but should also receive training on the nature of the threat posed by hackers online. It’s important that you know what you’re up against—and that the potential danger is spelled out so that people know that all of this isn’t being done for nothing. Effective training will definitely get your employees thinking and, hopefully, talking about cyber security.


Training, structure and process are the three main pillars required to get your employees thinking about cyber security. Together, they form the foundation of a business equipped to cope with the threats now faced online. So, implement this advice and see if your business is safer as a result.

Thursday, September 14, 2017

Steps to Staying Secure


As technology continues to gain a more important role in our lives, it also grows in complexity. Given how quickly technology changes, keeping up with security advice can be confusing. It seems like there is always new guidance on what you should or should not be doing. However, while the details of how to stay secure may change over time, there are fundamental things you can always do to protect yourself. Regardless of what technology you are using or where you are using it, we recommend the following steps to stay safe.

First and foremost, keep in mind that technology alone will never be able to fully protect you. Attackers have learned that the easiest way to bypass even the most advanced security technology is by attacking you. If they want your password, credit card, or personal data, the easiest thing for them to do is to trick you into giving them this information. For example, they can call you pretending to be Microsoft tech support and claim that your computer is infected, when in reality they are just cyber criminals that want you to give them access to your computer. Or perhaps they will send you an email explaining that your package could not be delivered and ask you to click on a link to confirm your mailing address, when in reality they are tricking you into visiting a malicious website that will hack into your computer. This is how attacks such as Ransomware or CEO Fraud start. Ultimately, the greatest defense against attackers is you. Be suspicious. By using common sense, you can spot and stop most attacks.


Passwords: The next step to protecting yourself involves using a strong, unique password for each of your devices and online account. The key words here are strong and unique. A strong password means one that cannot be easily guessed by hackers or by their automated programs. Tired of complex passwords that are hard to remember and difficult to type? Try using a passphrase instead. Instead of a single word, use a series of words that is easy to remember, such as “Where is my coffee?” The longer your passphrase is, the stronger. A unique password means using a different password for each device and online account. This way, if one password is compromised, all of your other accounts and devices are still safe. Can’t remember all those strong, unique passwords? Don’t worry, neither can we. That is why we recommend using a password manager, which is a specialized application for your smartphone or computer that securely stores all of your passwords in an encrypted format.  

Finally, one of the most important steps you can take to protect any account is enable two-factor authentication. Passwords alone are no longer enough to protect accounts; we all need something stronger. Two-step authentication is much stronger. It uses your password, but also adds a second step, either something you are (biometrics) or something you have (such as a code sent to your smartphone or an app on your smartphone that generates the code for you). Enable this option on every account you can, including your password manager, if possible. Two-step verification is probably the single most important step you can take to protect yourself, and it’s much easier than you think.

Updating: Make sure your computers, mobile devices, applications, and anything else connected to the Internet are running the latest software versions. Cyber criminals are constantly looking for new vulnerabilities in the software your devices use. When they discover vulnerabilities, they use special programs to exploit them and hack into the devices you are using. Meanwhile, the companies that created the software for these devices are hard at work fixing them by releasing updates. By ensuring your computers and mobile devices install these updates,


Backups: Sometimes, no matter how careful you are, you may be hacked. If that is the case, often your only option to ensure your computer or mobile device is free of malware is to fully wipe it and rebuild it from scratch. The attacker might even prevent you from accessing your personal files, photos, and other information stored on the hacked system. Often the only way to restore all of your personal information is from backup. Make sure you are doing regular backups of any important information and verify that you can restore from them. Most operating systems and mobile devices support automatic backups. In addition, we recommend you store your backups in either the Cloud or on an external device offline to protect them against cyber attackers.


By following the steps above, you will go a long way to protecting yourself while leveraging the latest technology.  You will make it much harder for someone to hack you.            

Thursday, January 19, 2017

Why Are We So Stupid About Passwords?


Yet another study has revealed that people are picking millions of weak passwords. Password management software vendor Keeper Security reviewed 10 million passwords that came to light in 2016 via data breaches and found that nearly one in six were "123456."
"If the media stopped saying 'hacking' and instead said 'figured out their password,' people would take password security more seriously." 
Keeper Security published a list of the top 25 most commonly used passwords, reporting that they account for more than half of the 10 million passwords it analyzed. How many countless hours have been lost by security experts attempting to share with friends and loved ones the optimal secrets for picking passwords or helping to set up password management software to ensure they never reuse the same password across multiple sites?


The latest analysis of leaked passwords shows that in recent years, unfortunately, little has changed when it comes to how most people pick their passwords (see Why Are We So Stupid About Passwords?). Part of the problem is perception, according to Khalil Sehnaoui, managing partner of information security firm Krypton. He says that the majority of what gets referred to today as "hacking" is really just attackers guessing passwords.


Not So Secret: '18atcskd2w'

One interesting finding from the Keeper Security study is that across 10 million leaked passwords, the 15th most used one was "18atcskd2w." In a list populated by numeric sequences, "qwerty," "passwords" and "google," that's an obvious anomaly. The prevalence of "18atcskd2w" was seen last year as well, after paid breach-reporting service LeakedSource in April detailed a February breach of Verticalscope.com that resulted in a dump of 45 million records relating to more than 1,100 websites and communities that the site runs, ranging from Techsupportforum.com and MobileCampsites.com to Pbnation.com and Motorcycle.com.


In the Verticalscope.com breach, 18atcskd2w was the second most common password used on the site. "What I believe happened is that these accounts were created by bots, perhaps with the intention of posting spam onto the forums," security expert Graham Cluley wrote in a blog post at the time.
Verticalscope.com subsequently confirmed the data breach, but it has yet to reveal the cause. Still, the organization reset all passwords and said that while it was "already using encrypted passwords and salted hashes to store passwords," it would also require users to follow stronger password rules, saying that "passwords now require a minimum of 10+ characters and a mixture of upper- and lower-case letters, numbers and symbols."

Stop Expiring Passwords

The service said it would also automatically expire passwords "to encourage more frequent password changes," but many security experts now say that forced password expiration puts users at greater risk. Indeed, last year, the U.K. government's National Technical Authority for Information Assurance, now the National Cyber Security Center, warned in its guidance: "It's one of those counter-intuitive security scenarios; the more often users are forced to change passwords, the greater the overall vulnerability to attack." It notes that related risks include users being more inclined to reuse passwords, write them down, base new passwords on old ones or to choose weaker, easier-to-remember passwords.


As a result, the NCSC noted it "now recommends organizations do not force regular password expiry. We believe this reduces the vulnerabilities associated with regularly expiring passwords ... while doing little to increase the risk of long-term password exploitation."

Spear-Phishing Success Continues

Training users to expect that their passwords will need resetting puts them at greater risk from spear-phishing attacks, which remain highly effective and low-cost ways for sidestepping both sites that secure passwords well and users who pick strong passwords. Take the Democratic National Committee, which was allegedly targeted by hacking teams sponsored by the Russian government that are often referred to as Cozy Bear and Fancy Bear. Thomas Rid, a professor of security studies at King's College London, noted in an October 2016 feature for Esquire that Fancy Bear targeted Gmail-using victims via spear-phishing emails that contained links shortened with the Bitly service that led to phishing sites designed to trick Gmail users into changing their password. In reality, however, the fake password-reset site was harvesting their passwords so attackers could use them to access their Gmail accounts.


Between October 2016 and May 2016 these attacks targeted 4,000 accounts and were wildly successful, with one in seven victims ultimately revealing their passwords, Rid writes. "Among the group's recent breaches were the German parliament, the Italian military, the Saudi foreign ministry, the email accounts of Philip Breedlove, Colin Powell and John Podesta - Hillary Clinton's campaign chairman - and, of course, the DNC."

Tuesday, January 17, 2017

The New PCI Data Security Standard 3.2 Refresher

The new and always evolving requirements make up the greatest changes – most of which do not go into effect until February 1, 2018:

  • Section 3.3 is an updated requirement that clarifies that any displays of a primary account number (PAN) greater than the first six/last four digits of the PAN requires a legitimate business need.
  • Section 3.5.1 is a new requirement for service providers only to maintain a documented description of the cryptographic architecture (algorithms, protocols, and keys) involved in their cardholder data environment (CDE).
  • Section 6.4.6 is a new requirement for change control processes to incorporate verification of other PCI DSS requirements that are impacted by a change such as network diagrams, endpoint controls, and the inclusion of new systems into the quarterly vulnerability scan process.
  • Section 8.3 has been expanded into sub-requirements to require multi-factor authentication for all personnel with non-console administrative access and all personnel with remote access to the CDE. This includes a new requirement, 3.2, that addresses multi-factor authentication for all personnel with remote access to the CDE and a new requirement 8.3.1 that addresses multi-factor authentication for all personnel with non-console administrative access to the CDE. In other words, we're going to start seeing a lot more multi-factor authentication.
  • Sections 10.8 & 10.8.1 are new requirements for service providers to detect and report on failures of critical security control systems such as firewalls, anti-virus, and audit logging mechanisms.
  • Section 11.3.4.1 is a new requirement for service providers to perform penetration testing on segmentation controls at least every six months.
  • Section 12.4.1 is a new requirement for service providers whereby executive management must establish responsibility for the protection of cardholder data and a PCI DSS compliance program to include accountability and a charter to ensure the program is communicated to management.
  • Sections 12.11 & 12.11.1 are new requirement for service providers to perform quarterly security program reviews and maintaining documentation and sign-off of those reviews.
  • New Appendix A2 that outlines additional requirements for SSL/TLS, namely:
    • After June 30, 2018, stop using SSL/early TLS as a security control and use only secure versions of the protocol (i.e. TLS v1.2).
    • Prior to June 30, 2018, existing implementations that use SSL and/or TLS 1.0 and 1.1 must have a formal Risk Mitigation and Migration Plan in place.
There's also additional clarification in PCI DSS version 3.2 that directly impacts application security programs such as:
  • Backup/recovery sites need to be considered when confirming PCI DSS scope.
  • Added Testing Procedure (11.3.4.c) to confirm penetration test is performed by a qualified internal resource or qualified external third party.
  • Training for developers must be up to date and occur at least annually.
A complete summary of all changes can be found in the document Summary of Changes from PCI DSS Version 3.1 to 3.2.

Tuesday, November 8, 2016

10 Things Security Experts Wish End Users Knew

Introduction
Security is an essential business operation more than ever before. However, without end users improving their knowledge base and behaviors, the technology that an organization deploys is insufficient. In this white paper, I would like to discuss ten things that security experts wish end users knew. The more users understand about risk and consequence, the more likely they will adjust their behavior and assist with supporting security. These concepts are concerns that security experts want you to know. We all know that users are the weakest link. Please review and provide your thoughts in the comments.

Software Updates Should Be Installed Promptly
Security experts want you to know that software updates should be installed promptly, but not blindly. Just because a vendor has released an update does not mean it should be taken as a sign to install the update instantaneously. The new code you would be adding to your system could be flawed or could cause unexpected results in your system that the vendor did not predict. Thus, under no circumstances should you install new updates before testing them and learning from others.

Always test new updates on dedicated test systems. Then, work through all major work tasks to ensure that the changes to the lab systems do not interfere. Next, review any comments, reviews, or feedback available about the update from others. You are unlikely the first person to consider installing a new update. Thus, learning from the experiences of others can save you from downtime and repair headaches. Once you are satisfied that an update is reasonably safe and appropriate to install, take one more precaution: back up your target systems. With a system backup, if the worst happens and the update process fails, the update corrupts your system, or new unforeseen consequences arise, you have a path to restore your environment back to a functional state.

To be even clearer, software updates should be installed promptly without skipping testing. In most cases, running the most current and complete set of code available will provide you with the most security form of the product. When updates are delayed or skipped, flaws will remain in your environment, which can be discovered and exploited by attackers.

Account Authentication Strength
A regular occurrence in technology news is a story about yet another person’s account being hacked through the use of a password compromise attack. What is so frustrating about many of these stories is when the victim’s password is revealed to be something short, simple, and easy to remember. What security experts want you to know is that a password can be made securer with just a few basic steps:

1. Make your password longer. Twelve characters is a reasonably secure length, assuming you follow other good password practices.

2. Use complexity. Use three or four character types: uppercase, lowercase, numbers, and when possible, symbols.

3. Do not reuse the same or a variation of a password. Ever. Not on the same site and not on different sites.

You can further improve your online password security through the use of a credential manager, such as LastPass, KeePass, or Dashlane. These will enable you to generate random passwords with the maximum length allowed on each and every site, while securely storing those passwords for you.

It is also important to use the two-step or two-factor authentication offerings from an online site. A growing number of websites now support multi-step authentication. You should enable this feature. While it initially will be cumbersome, once you become familiar with the process, it will make your online account significantly securer. Once you have secured your online accounts to stronger passwords and/or multi-factor authentication (where available), you can rest easier knowing that the media haranguing about another account compromise will be even less likely to actually affect you.

All Software Has Flaws
In the highly competitive marketplace of computer software and related technologies, you often hear marketing and advertising messages claiming their product is secure or at least securer than some other product. Often these product slingers want you to believe that, just by installing their solution, all your security worries will disappear. What security experts want you to know is that there are no perfectly secure systems and all software has flaws.

Software is written by humans (at least for the most part). Humans are imperfect and they regularly make mistakes. When those humans are writing software code, they are inevitably going to make mistakes as they type the code. Some of those mistakes will be typos, others will be logical flaws, while still others will be errors of omission or oversight (such as failing to prevent an unwanted event rather than just planning for only expected ones). As a software product grows larger and as more programmers are involved in its development, the likelihood of errors making their way into the final version is almost guaranteed.

A modern server operating system can include over one hundred million lines of code written by hundreds of programmers. While testing, auditing, and reviewing are often performed, it is just not feasible to track down and correct every single issue. For a software product to be perfectly secure, all errors and logic flaws need to be discovered and removed. For a software product to be vulnerable, only a single error or oversight needs to be left in the code. Attackers only need a single vulnerability to exploit a system. At some point, the process of debugging code becomes too expensive. Once a vendor decides they have reached the point of exhausting the cost-effectiveness of their debugging process, they hope that they have discovered and resolved the easy-to-exploit issues and left behind only those that are difficult to detect and exploit. However, we, as the software-using public, know this process is not perfect as we are constantly installing updates and still experiencing breaches.

An important takeaway from this issue that all software has flaws is to use a multi-layered defense strategy. Rather than using a single product or even multiple products from the same vendor, we should use multiple products from multiple vendors to have overlapping security protections. This defense-in-depth approach will minimize the chance that a single flaw in a single product will result in the compromise of the entire organization. Instead, the attackers will need to find a complex gauntlet of flaws, which in turn makes it more likely their attack efforts will be detected and thwarted long before they are ultimately successful.

Every Internet Interaction Should Be Encrypted
In a world where you now know that the NSA and other international government entities are actively monitoring Internet activity, and where criminal organizations are lurking to find new victims, the fact that we will perform most of our online activity in clear view form is absurd. Security experts want you to know that you need every Internet interaction to be encrypted. The only way to combat Internet eavesdropping is to encrypt your packets.

Having every communication over the Internet be encrypted is not automatic or guaranteed. But with a few simple steps, you can encrypt a majority of your online communications. First, start using Chrome, Firefox, or Opera as your Web browser with the plugin from Electronic Frontier Foundation’s (EFF) HTTPS Everywhere (https://www.eff.org/Https-Everywhere). This browser extension converts every URL you click or type from a plain-text HTTP link into one requesting the TLS secured HTTPS version. Only if the server is unable to offer an HTTPS response will you fail back to standard plain-text HTTP.

Second, for every other service you use, such as email, file transfer, or even newsgroups (USENET), use the TLS encrypted connection option provided by the server. This usually requires that you have a software client on your system rather than using the web interface for these other forms of online communication. When a service offers secured connection options, they typically include a how-to guide that helps you through the configuration process.

Third, use a VPN. There are a wide range of free and paid VPN services online these days. Find one you like and use it. Especially, when using wireless connections outside of your own home or office. That includes Wi-Fi networks as well as mobile network operator networks. Setup the VPN to operate on your home systems, your notebook/laptop, tablet, and smart phone. Use it always.

The Cloud Is Not a Security Silver Bullet
Cloud services are the new technology addiction for companies small to large. Almost every major product vendor is offering cloud services or cloud extensions or cloud access or cloud enhancements. Security experts want you to know that the cloud is not a security silver bullet. Having another organization perform a service for you or offer a product to you that you could do yourself internally might be a good idea. Other organizations may be better at offering technical support, running websites, or performing accounting. Leveraging the skills and expertise of others is an important part of the business world today. It can be cost-effective and efficient. But it is not necessarily securer.

It is important to keep in mind the truth behind the marketing phrase "the cloud" or "cloud services." There is no cloud. There is no floating collection of magical Internet architecture hanging majestically in the stratosphere just waiting to offer you newfangled capabilities and throughput. Instead, the cloud is just remote virtualization. In other words, the cloud is a collection of computer systems located in some warehouse which run virtualization solutions in order to host numerous operating systems and relevant software products. The resources and capabilities these warehoused computers support are then sold off to customers in a remote-access / remote-use concept under the label of "cloud services."

Thus, being a cloud solution does not automatically make it a securer option than what you could have created inside your own building. You are dependent upon the cloud vendors’ security design, expertise, and experience. If they did a poor job of implementing logical and physical security, then that can directly and negatively affect your data and communications hosted on their systems. Always thoroughly investigate a cloud provider’s track record and security policy before placing the core of your organization at risk.  

A Hacker Is Not a Criminal, Criminals Are Criminals
It has become a standard and regularly occurring news story to discuss attacks and security breaches of both individuals and organizations that are attributed to hackers. Security experts want you to know that a hacker is not a criminal—criminals are criminals.

A hacker is anyone who invests time and effort into thoroughly understanding a system, solution, or device. A hacker often disassembles and reassembles, while making adjustments and modifications to learn how the system reacts or changes based on those changes. A hacker can be thought of as an enthusiast. A hacker might focus on learning and understanding, improving and adjusting, or finding flaws and holes that need addressing.

The problem is when someone uses the term hacker to always mean a criminal or malicious hacker. Without proper context and explanation, the term hacker can cause confusion as well as place blame on those who are innocent. With the terms criminal and attacker, it is direct and obvious that the individual being referred to is violating a company policy and/or a law. But with hacker, that is not necessarily obvious. If people who consider themselves hackers violate polices and the law, then they have become a criminal. However, if they stay within the confines of company policy and legal restrictions, then they are still just hackers. It is good practice to use a distinct qualifier when intending to use the term hacker for the purposes of referring to a criminal, for example an unauthorized hacker, unethical hacker, malicious hacker, or criminal hacker.

Ultimately, hackers—especially the ethical ones, not just the criminal ones—help make technology securer. Just because hackers know how to bypass security or break a system does not mean they intend to do so nor that they have the intention of causing harm. Many security researchers are effectively hackers. Most product vendors have code reviewers, auditors, and internal testers, all of which are a form of hackers. By discovering and understanding the flaws and mistakes in technology, those concerns can be patched or otherwise addressed. Hackers have the ability to think in odd and unexpected ways: they don’t have to follow the logic of the computer program; they can make unexpected assumptions or take unpredictable actions. This freedom to examine technology without being forced to abide by its rules helps hackers understand and ultimately improve that technology.

New Is Not Necessarily Secure
New software solutions and hardware products are announced at an ever more fervent pace than before. Many tout their improved reliability, efficiency, and security. But before you spend your money or place your trust in some cutting-edge technology, security experts want you to know that new is not necessarily secure.

The primary issue or concern with new products is that they have not had sufficient testing performed against them. Products that have been in the marketplace for years have had more time to be improved and matured. The new product may have modern features and faster performance, but until the world community has had the opportunity to use, abuse, and hack it, the measure of its security has yet to be taken.

Another aspect of the new is not necessarily secure thinking is that many new products may come pre-infected with malware or have known security holes. For example, in early 2015 it was revealed that a wide range of Lenovo laptop models were "pre-installed" with Superfish (a vulnerable adware product). It is not the case that computer technology becomes less secure over time. Instead, most technologies become securer over time as flaws are discovered and patched. However, once the vendor ends support for a product, it then begins to revert back into a less secure product. For example, public support for Windows XP ended on April 8, 2014, and as new flaws were discovered and exploits created for that OS, the security that Microsoft had integrated into one of its most popular OSes has been degrading ever since that date.

Another nuance in this area relates to the updates to your operating systems, updates for installed applications, and firmware updates for hardware products. In most cases, installing updates promptly is a good security practice. But what often is overlooked is the essential need to test and evaluate those updates before blindly installing them into a production system. Just because new code is released from a vendor does not guarantee that it will prevent it from introducing new problems to your systems. These problems could interrupt mission critical business tasks or otherwise make your system unusable. Always test new updates on lab systems before installing them onto production equipment.

Computer Attacks Are Rare But Overly Emphasized by the Media
It is easy to be worried and frightened by the worst computer-based criminal attacks, but these attacks are rare. But due to our fight-or-flight-tuned brain, we often over emphasize the unlikely threats and under appreciate the more likely ones. Security experts want you to know that serious computer attacks are rare, but they are over emphasized by the media. Large-scale, massively damaging cybercrimes make for great headlines and attention-grabbing thriller plot lines, but they are very rare in comparison to more mundane exploits.

Most of the issues we should be concerned about are using poor passwords, sharing too openly on social networks, and using plain-text Internet communications. The chance that an attacker will figure out your password, attempt to scam you through email, or eavesdrop on your Internet activities is much more common than having your identity stolen, your retirement accounts being emptied, or your car remotely controlled by an attacker. Plus, with just a few simple actions on your part, you can reduce these common threats. Making stronger passwords and encrypting your Internet connections were covered earlier in this paper. How to be securer online in general online, especially with social networks, is detailed in my white paper "How to Secure Online Activities."

Take steps to reduce your risks on the more common but less dramatic concerns. Then, calm you fears over the massive cyber terrorism plots you hear about from TV, movies, or the media. They are much rarer than you are assuming, and you are an unlikely target. Sorry, but unless you are Warren Buffet, Elon Musk, or Richard Branson, you are just not worth the effort.
There Is More to the Internet than What Google Can Search
Most of us experience the world through a social network and Google. We think that we can learn anything or locate something just by typing in a few keywords for a search. Well, think again. Security experts want you to know that there is more to the Internet that what Google can search.

Google and other search engines use automated spiders or robot website crawlers (both a form of web browsing software) to retrieve information about websites. This information is then stored and indexed in their massive databases. When you perform a search, your keywords are used against this collected dataset to produce the results from which you select and click to traverse to the original source. However, due to website design, authentication requirements, or web crawler restrictions (such as robots.txt), search engines are not able to travel to all possible web pages.

There is also a plethora of other content that is not web based and thus is not able to be indexed by a web-focused site crawler. This non-searchable content is known as the Deep Web. This can include file stores; older Internet communication concepts, such as gopher and USENET; as well as custom content and temporary/temporal content.

While most of what we search for is part of the surface web (i.e., the part of the web that is search engine indexed), often once we click on a search result and dive deeper into the visited site, we may be encountering a part of the Deep Web (i.e., content that is not searchable). To learn more about the Deep Web, a quick surface web search will lead you to numerous articles and how-to guides if you want to go Internet spelunking.

Keep in mind that the Deep Web is a separate concept from that of the Darknet. The Darknet is the collection of computers and services that cannot be accessed (at least not directly) from the Internet as any standard website or service can. Instead, special VPN or anonymization services must be used to gain access. Examples of Darknet Services have included Silkroad and Agora Marketplace. Often these Darknet Services are by invitation only or are exceedingly challenging to locate. One popular access portal to some Darknet Services is Tor (https://www.torproject.org/). However, this does not mean Tor is only used for Darknet access or only questionable purposes—it is just a tool.

Social Engineering Protection and Physical Security Are Just As Important As IT Security
Security is an essential business task. But it also an essential concern for individuals. It should be a company policy, and it also should be a personal lifestyle. Security experts want you to know that social engineering protection and physical security are just as important as IT security. IT security, a.k.a. technical and logical security, are all of the computer hardware and software components that we commonly associate with improving online security, such as encryption, firewalls, authentication, logging, intrusion detection systems, and deep content inspection. However, IT security is just one aspect of organizational and personal security. It is essential not to overlook social engineering protection and physical security. Without all three of these security efforts, your protection infrastructure is incomplete.

Social engineering protection is the attempt to limit or restrict the ease by which an attacker can take advantage of you through cons, scams, or hoaxes. Social engineering attacks can occur in a face-to-face encounter, over the phone, through email, or through text messages. Being aware that such attacks are possible and being on guard against them is the first step to being securer. You need to avoid the trap of automatically trusting everything that is online or electronically delivered to you. All communications can be falsified or spoofed. So, take the effort to verify identity before you depend upon your assumptions.

Physical security is also important. Even with the best IT security money can buy, if your equipment is damaged by a flood or fire or stolen during a facility break-in, your data is still in the hands of attackers. Keeping doors locked, using locked containers or tethers, tracking visitors, and using video recording systems will help improve physical security.

Paying attention to security means sufficiently addressing logical, social, and physical security concerns. Only through a well-designed and balanced effort will a security infrastructure withstand a multitude of attack attempts.

 Conclusion

Security is complicated. This has led to the many misconceptions and misunderstandings about security. By paying attention to these ten concerns that security experts want you to know, you can gain knowledge and understanding about security and be securer both at work and in your personal life.

 

 

Protecting Your Business From Your Remote Employees

A significant portion of your workforce is currently moving to perform full- or part-time remote work as a result of COVID-19.  As you modif...