Google Trumpets New Mobile App Security Standard

Google Trumpets New Mobile App Security Standard

Google is shouting about a new standard designed to enhance baseline security across mobile applications.

The Mobile Application Profile is the work of the Internet of Secure Things Alliance (ioXt), a consortium of over 300 members including Google, Facebook, T-Mobile, Zigbee Alliance, Schneider Electric and many others.

“With so many companies involved, ioXt covers a wide range of device types, including smart lighting, smart speakers, and webcams, and since most smart devices are managed through apps, they have expanded coverage to include mobile apps with the launch of this profile,” explained Brooke Davis and Eugene Liderman of the Android Security and Privacy Team.

“The ioXt Mobile Application Profile provides a minimum set of commercial best practices for all cloud connected apps running on mobile devices. This security baseline helps mitigate against common threats and reduces the probability of significant vulnerabilities.”

According to the document itself, the Profile covers passwords, interfaces, cryptography, software updates, vulnerability reporting and security-by-default.

It was produced by ioXt in collaboration with over 20 industry players including Google and Amazon, labs such as NCC Group and Dekra, and automated mobile app security testing vendors like NowSecure.

It’s also based on existing frameworks like OWASP MASVS and the VPN Trust Initiative. Although mobile apps only need to be certified under the Mobile Application Profile, VPN apps must also comply with a specialized VPN extension.

“Certification allows developers to demonstrate product safety and we’re excited about the opportunity for this standard to push the industry forward,” noted Davis and Liderman.

“We observed that app developers were very quick to resolve any issues that were identified during their black box evaluations against this new standard, oftentimes with turnarounds in a matter of days.”

The duo encouraged more developers to get involved in the project and said it would help act as a “guiding light” to inspire more of the community to invest in mobile app security.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FIN7 Sysadmin Gets 10 Years Behind Bars

FIN7 Sysadmin Gets 10 Years Behind Bars

The systems administrator for a notorious organized cybercrime group has been handed a 10-year jail sentence for his part in financial crimes that cost firms and consumers billions.

Ukrainian national Fedir Hladyr, 35, was manager and sysadmin for FIN7 (aka Carbanak), which is believed to have made a fortune from targeting banks, restaurants, gambling and hospitality firms.

The campaign which Hladyr has been linked to involved the compromise of thousands of computer systems internationally, including all 50 US states and the District of Columbia.

According to court documents, the gang stole 20 million customer card records from over 6,500 individual point-of-sale (PoS) terminals at more than 3,600 separate business locations, causing billions in damages at firms including Chipotle Mexican Grill, Chili’s, Arby’s, Red Robin, and Jason’s Deli.

Hladyr is said to have originally joined FIN7 via a front cybersecurity company known as Combi Security. Despite realizing early on it was a fake business, he continued to work for the gang, aggregating stolen payment card information, supervising FIN7 hackers, maintaining its command-and-control servers, and managing its encrypted communications.

Operating since at least 2015, the group itself is said to number around 70 individuals, highly organized into separate business units and teams, some developing malware and others engaged in hands-on hacking.

Initial compromise of those thousands of victim systems appears to have been via phishing emails and scam calls.

Hladyr was arrested in the German city of Dresden in 2018 and extradited to the US, where he pleaded guilty in 2019 to one count of conspiracy to commit wire fraud and one count of conspiracy to commit computer hacking.

“The defendant and his conspirators compromised millions of financial accounts and caused over a billion dollars in losses to Americans and costs to the US economy,” said acting assistant attorney general Nicholas McQuaid of the Justice Department’s Criminal Division.

“Protecting businesses — both large and small — online is a top priority for the Department of Justice. The department is committed to working with our international partners to hold such cyber-criminals accountable, no matter where they reside or how anonymous they think they are.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

ICO Issued Over £42 Million in Fines Last Year

ICO Issued Over £42 Million in Fines Last Year

The UK’s privacy regulator issued over £42 million in fines last year, although the vast majority of the money relates to two major GDPR penalties, according to new data.

Flagged by think tank Parliament Street, the Information Commissioner’s Office (ICO) “work to recover fines” report revealed that 17 financial penalties had been levied in 2020, amounting to more than £42.4 million.

Most can be attributed to the vastly reduced and much-delayed fines finally imposed on Marriott International (£18.4 million) and British Airways (£20 million) for major data breaches. Ticketmaster’s (£1.25 million) was the next-biggest fine, with the remaining 14 standing at £500,000 or less.

Three court orders were issued to wind-up erring firms last year, while eight company directors were disqualified following ICO enforcement action.

The latter action is meant to help prevent tactics known as “phoenixing,” where company owners who have allowed illegal practices such as cold calling simply declare bankruptcy after an ICO investigation and start a new company, avoiding any fines.

Thanks to changes in the law, directors could now not only face disqualification, but are also responsible for paying the fines, under either the Data Protection Act 2018, the UK’s version of the GDPR, or the Privacy and Electronic Communications Regulations (PECR), which govern nuisance calls.

ICO group manager for investigations, Natasha Longson, said awareness of these penalties has grown among directors.

“In most cases where a fine has not been paid, we work closely with the Insolvency Service. This has been a very successful collaboration and, last year, saw eight directors disqualified. Recovering fines from insolvent companies has been slower than usual due to the pandemic’s impact on the courts,” she added.

“We take a pragmatic approach to recovery and we support companies and directors in genuine financial hardship, for example agreeing payment plans where appropriate.”

However, some reports suggest the ICO’s strategy for fines is problematic. The original intent was to fine BA £183 million, for example.

What’s more, the regulator has been unable to collect around two-fifths (39%) of the fines issued from 2015-19, according to a report issued last October. In addition, 68% of fines issued since then are outstanding, the report claimed.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Details on the Unlocking of the San Bernardino Terrorist’s iPhone

The Washington Post has published a long story on the unlocking of the San Bernardino Terrorist’s iPhone 5C in 2016. We all thought it was an Israeli company called Cellebrite. It was actually an Australian company called Azimuth Security.

Azimuth specialized in finding significant vulnerabilities. Dowd, a former IBM X-Force researcher whom one peer called “the Mozart of exploit design,” had found one in open-source code from Mozilla that Apple used to permit accessories to be plugged into an iPhone’s lightning port, according to the person.

[…]

Using the flaw Dowd found, Wang, based in Portland, Ore., created an exploit that enabled initial access to the phone ­ a foot in the door. Then he hitched it to another exploit that permitted greater maneuverability, according to the people. And then he linked that to a final exploit that another Azimuth researcher had already created for iPhones, giving him full control over the phone’s core processor ­ the brains of the device. From there, he wrote software that rapidly tried all combinations of the passcode, bypassing other features, such as the one that erased data after 10 incorrect tries.

Apple is suing various companies over this sort of thing. The article goes into the details.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

SOCwise Series: A Tale of Two SOCs with Chris Crowley

In a recent episode of McAfee’s SOCwise Series, guest security expert Chris Crowley revealed findings of his recent survey of security efforts within SOCs. His questions were designed to gain insight into all things SOC, including how SOCs can accomplish their full potential and how they assess their ability to keep up with security technology. 

Hosts Ismael Valenzuela and Michael Leland tapped into Chris’ security operations expertise as he told “A Tale of Two SOCs. 

“Chris has a tremendous experience in security operations,” Ismael said. “I always like people who have experience both in the offensive side and the defensive side. Think red, act blue, right? . . . but I think that’s very important for SOCs. Where does ‘A Tale of Two SOCs’ come from?”  

In reference to the Charles Dickens’ classic, Chris explained how survey responses fell into two categories: SOCs that had management support or those that did not. 

“It’s not just this idea of does management support us. It’s are we effectively aligned with the organization?” Chris said. And I think that is manifest in the perception of management support of not management support, right? So, I think when people working in a SOC have the sense that they’re doing good things for the organization, their perceptions is that the management is supporting them.” 

In this case, Chris explains “A Tale of Two SOCs” also relates to the compliance SOC versus the real security SOC. 

“A lot of it has to do with what are the goals when management set up to fund the SOC, right? Maybe the compliance SOC versus the SOC that’s focused on the security outcomes on defending, right?There are some organizations that are funding for basic compliance,” Chris said. [If the] law says we have to do this, we’re doing that. We’re not really going to invest in your training and your understanding and your comprehension. We’re not going to hire really great analysts. We’re just going to buy the tools that we need to buy. We’re going to buy some people to look at monitors and that’s kind of the end of it. 

One of the easiest and telling methods of assessing where an SOC sees itself in this tale is having conversations with staff. Chris recommends asking staff if they feel aligned with management and do they feel empowered? 

“If you feel like you’re being turned into a robot and you pick stuff from here and drop it over there, you’re probably in a place where management doesn’t really support you. Because they’re not using the human being’s capability of synthesis of information and that notion of driving consensus and making things work,” Chris said. “They’re looking more for people who are replaceable to put the bits in the bucket and move through.” 

Chris shared other survey takeaways including how SOCs gauge their value, metrics and tools. 

SOC INDICATORS AND PERCEIVED VALUE 

The survey included hypotheses designed to measure how organizations classify the value of a SOC: 

  • Budget – The majority of respondents did not list budget as a sign of how their organization value them 
  • Skilled Staff  Many valued the hiring of skilled workers as a sign of support for their SOC. 
  • Automation and Orchestration – The SOC teams that believed their organizations already supported through the hiring skilled staff reported their biggest challenge was implementing the automation and orchestration. 

“This showed that as SOC teams met the challenge of skilled staffing, they moved on to their next order of task: Let’s make the computers compute well,” Chris said. 

SOC METRICS 

Ismael asked about the tendency for some SOC management not to report any metrics, and those that simply reported number of incidents not reporting the right metrics. Chris reported that most people said they do provide metrics, but a stillsurprising number of people said that they don’t provide metrics at all. 

Here’s the breakdown of how respondents answered, “Do you provide metrics to your management?” 

  • Yes  69 
  • No  24 
  • We don’t know – 6 

 That roughly a third of respondents either do not report metrics or don’t know if they report metrics was telling to the survey’s author. 

In which case [metrics] obviously don’t have a central place of importance for your SOC,” Chris said. 

Regarding the most frequently used metric – number of incidents – Chris speculated that several SOCs he surveyed are attempting to meet a metric goal of zero incidents, even if it means they’re likely not getting a true reading of their cyber security effectiveness.  

You’re allowed to have zero incidents in the environment. And if you consistently meet that then you’re consistently doing a great job,” Chris said. Which is insane to me, right? Because we want to have the right number of incidents. If youactually have a cyber security problem … you should want to know about it, okay? 

Among the group of respondents who said their most common metric is informational, the desired information from their “zero incidents” metrics doesn’t actually have much bearing on the performance or the value of what the SOC is doing.

“The metrics tend to be focused on what can we easily show as opposed to what truly depicts the value that the SOC has been providing for the org,” Chris said. And at that point you have something you can show to get more funding and more support right over time. 

Chris suggests better use of metrics can truly depict the value that the SOC is providing the organization and justify the desired support it seeks. 

One which I like, which is not an easy metric to develop is actually loss prevention. If I can actually depict quantitatively, which it will not be precise, there will be some speculation in that,” Chris said. “But if I can depict quantitatively what the SOC did this month, or quarter where our efforts actually prevented or intervened in things which were going wrong and we stopped damage that’s loss prevention, right? That’s what the SOC is there for, right? If I just report, we had 13 incidents there’s not a lot of demonstration of value in that. And so always the metrics tend to be focused on what can we easily show as opposed to what truly depicts the value that the SOC has been providing for the org. “ 

SOC TOOLS 

Michael steered the discussion to the value discussion around incident metrics and their relationship with SOC capacityHow many incidents can you handle? Is it a tools issue or a people issue or a combination of both? Chris’ study also revealed subset of tools that respondents more frequently leveraged and added value to delivery of higher capacity of incident closure. 

One question on the survey asked“Do you use it? 

 “Not whether you like it or not, but do you use it? And do you use it in a way where you have full coverage or partial coverage? Because another thing about technology, and this is kind of a dirty secret in technology applications, is a lot of people buy it but actually never get it deployed fully,” Chris said. 

His survey allowed respondents to reveal their most-used technologies and to grade tools. 

The most common used technologies reported in the survey were: 

  1. SIEM 
  2. Malware Protection Systems 
  3. Next-gen Firewall 
  4. VPN 
  5. Log management  

Tools receiving the most A grades: 

  • EDR 
  • VPN 
  • Host-based Malware Protection 
  • SIEM 
  • Network Distributed Denial of Service 

Tools receiving the most F grades: 

  • Full Peak App 
  • Network-Based Application Control 
  • Artificial Intelligence 
  • TLS Intercept 

Chris pointed out that the reasoning behind the F grades may be less a case of failing and more a case of not meeting their full potential. 

“Some of these are newer in this space and some of them just feel like they’re failures for people” Chris said. Now, whether they’re technology failures or not this is what people are reporting that they don’t like in terms of the tech.  

For more findings read or download Chris Crowley’s 2020 survey here. 

Watch this entire episode of SOCwise below.

 

The post SOCwise Series: A Tale of Two SOCs with Chris Crowley appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk