Oblivious DNS-over-HTTPS

This new protocol, called Oblivious DNS-over-HTTPS (ODoH), hides the websites you visit from your ISP.

Here’s how it works: ODoH wraps a layer of encryption around the DNS query and passes it through a proxy server, which acts as a go-between the internet user and the website they want to visit. Because the DNS query is encrypted, the proxy can’t see what’s inside, but acts as a shield to prevent the DNS resolver from seeing who sent the query to begin with.

IETF memo.

The paper:

Abstract: The Domain Name System (DNS) is the foundation of a human-usable Internet, responding to client queries for host-names with corresponding IP addresses and records. Traditional DNS is also unencrypted, and leaks user information to network operators. Recent efforts to secure DNS using DNS over TLS (DoT) and DNS over HTTPS (DoH) havebeen gaining traction, ostensibly protecting traffic and hiding content from on-lookers. However, one of the criticisms ofDoT and DoH is brought to bear by the small number of large-scale deployments (e.g., Comcast, Google, Cloudflare): DNS resolvers can associate query contents with client identities in the form of IP addresses. Oblivious DNS over HTTPS (ODoH) safeguards against this problem. In this paper we ask what it would take to make ODoH practical? We describe ODoH, a practical DNS protocol aimed at resolving this issue by both protecting the client’s content and identity. We implement and deploy the protocol, and perform measurements to show that ODoH has comparable performance to protocols like DoH and DoT which are gaining widespread adoption,while improving client privacy, making ODoH a practical privacy enhancing replacement for the usage of DNS.

Slashdot thread.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Patch Tuesday, Good Riddance 2020 Edition

Microsoft today issued its final batch of security updates for Windows PCs in 2020, ending the year with a relatively light patch load. Nine of the 58 security vulnerabilities addressed this month earned Microsoft’s most-dire “critical” label, meaning they can be abused by malware or miscreants to seize remote control over PCs without any help from users.

Mercifully, it does not appear that any of the flaws fixed this month are being actively exploited, nor have any them been detailed publicly prior to today.

The critical bits reside in updates for Microsoft Exchange Server, Sharepoint Server, and Windows 10 and Server 2016 systems. Additionally, Microsoft released an advisory on how to minimize the risk from a DNS spoofing weakness in Windows Server 2008 through 2019.

Some of the sub-critical “important” flaws addressed this month also probably deserve prompt patching in enterprise environments, including a trio of updates tackling security issues with Microsoft Office.

“Given the speed with which attackers often weaponize Microsoft Office vulnerabilities, these should be prioritized in patching,” said Allan Liska, senior security architect at Recorded Future. “The vulnerabilities, if exploited, would allow an attacker to execute arbitrary code on a victim’s machine. These vulnerabilities affect Microsoft Excel 2013 through 2019, Microsoft 365 32 and 64 bit versions, Microsoft Office 2019 32 and 64 bit versions, and Microsoft Excel for Mac 2019.”

We also learned this week that Redmond quietly addressed a scary “zero-click” vulnerability in its Microsoft Teams platform that would have let anyone execute code of their choosing just by sending the target a specially-crafted chat message to a Teams users. The bug was cross-platform, meaning it could also have been used to deliver malicious code to people using Teams on non-Windows devices.

Researcher Oskars Vegeris said in a proof-of-concept post to Github that he reported the flaw to Microsoft at the end of August, but that Microsoft didn’t assign the bug a Common Vulnerabilities and Exposure (CVE) rating because it has a policy of not doing so for bugs that can be fixed from Microsoft’s end without user interaction.

According to Vegeris, Microsoft addressed the Teams flaw at the end of October. But he said the bug they fixed was the first of five zero or one-click remote code execution flaws he has found and reported in Teams. Reached via LinkedIn, Vegeris declined to say whether Microsoft has yet addressed the remaining Teams issues.

Separately, Adobe issued security updates for its Prelude, Experience Manager and Lightroom software. There were no security updates for Adobe Flash Player, which is fitting considering Adobe is sunsetting the program at the end of the year. Microsoft is taking steps to remove Flash from its Windows browsers, and Google and Firefox already block Flash by default.

It’s a good idea for Windows users to get in the habit of updating at least once a month, but for regular users (read: not enterprises) it’s usually safe to wait a few days until after the patches are released, so that Microsoft has time to iron out any chinks in the new armor.

But before you update, please make sure you have backed up your system and/or important files. It’s not uncommon for a Windows update package to hose one’s system or prevent it from booting properly, and some updates have been known to erase or corrupt files.

So do yourself a favor and backup before installing any patches. Windows 10 even has some built-in tools to help you do that, either on a per-file/folder basis or by making a complete and bootable copy of your hard drive all at once.

And if you wish to ensure Windows has been set to pause updating so you can back up your files and/or system before the operating system decides to reboot and install patches on its own schedule, see this guide.

As always, if you experience glitches or problems installing any of these patches this month, please consider leaving a comment about it below; there’s a better-than-even chance other readers have experienced the same and may chime in here with some helpful tips.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Half of US Schools Skipped Remote Security Training

Half of US Schools Skipped Remote Security Training

A new report on the cybersecurity of the education sector has found that nearly half of the schools in the United States did not implement new training or tools to protect staff and students during the pandemic.

The CTNT report “Lessons learned: How education coped in the shift to distance learning” from Malwarebytes details data from 500 students and 75 IT decision makers at educational institutions.

Researchers found that while 70% of schools adopted new software such as Zoom, Remind, and Google Classroom to enable students to learn remotely, nearly half (46.7%) of IT decision makers said their schools developed “no additional requirements” for the students, faculty, or staff who connected to the school’s network.

Over half (50.7%) of IT decision makers said that no students, staff, or faculty were required to enroll in cybersecurity training before the new school year began.

Over a quarter of IT respondents (28%) said that their school did not have sufficient laptops, computers, or tablets to allow teachers, administrators, and staff members to work remotely. Providing all parents and students with devices was a problem for 40% of schools. 

Nearly half (45.3%) of schools were unable to provide every student with a device to use for distance learning, creating educational inequality. 

Inconsistencies in the perceived cybersecurity of the schools was found to exist between the students and the establishments’ IT departments. Just 2.7% of IT decision makers said that their schools suffered a cyber-attack; however, 46.2% of students said their schools had suffered a cyber-attack. 

Taking security precautions appeared to help schools fend off Zoom-bombing attacks. Overall, 29.3% of respondents suffered a Zoom-bombing attack, but the same fate befell just 18.2% of respondents who said they had engaged in cybersecurity best practices. 

“Students during the pandemic are struggling with digital access, engagement and a severe sense of isolation. Cybersecurity should be the least of their concerns, and yet, it’s concerning to find that nearly half of educational institutions show a lack of preparedness,” said Marcin Kleczynski, CEO of Malwarebytes. 

“It is essential that schools—and all organizations—stop viewing cybersecurity as an afterthought; protecting our students and their data online should be a top priority for educators.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NortonLifeLock to Acquire Avira

NortonLifeLock to Acquire Avira

Cyber-safety company NortonLifeLock today announced that it will acquire Avira from Investcorp Technology Partners

The all-cash transaction to acquire the company, whose roots go back to 1986, will see roughly $360m change hands. 

Avira is headquartered on the shores of Lake Constance, Germany. The company provides a consumer-focused portfolio of cybersecurity and privacy solutions for Windows and Mac computers, Android and iOS smartphones, home networks, and smart devices (IoT). 

The company, which employs roughly 500 people, describes itself as a pioneer of the freemium software business model.

“I am delighted to welcome Avira to the Norton family,” said Vincent Pilette, CEO, NortonLifeLock. “We strive to bring Cyber Safety to everyone, and acquiring Avira adds a growing business to our portfolio, accelerates our international growth and expands our go-to-market model with a leading freemium solution.”

Pilette added that the two companies are a great match culturally and “share a relentless focus on delivering innovative products to customers” as well as a customer-first attitude. 

Once the planned acquisition closes, Avira CEO Travis Witteveen and CTO Matthias Ollig will join the NortonLifeLock leadership team. 

“NortonLifeLock and Avira are fiercely dedicated to helping protect consumers’ digital lives,” said Witteveen. “We are thrilled to become part of NortonLifeLock—a company that is synonymous with trust and leadership in Cyber Safety. By leveraging the scale of NortonLifeLock, we can reach and protect more consumers around the globe.”

Among the strategic and financial benefits the companies expect to emerge from the deal are an acceleration of international growth in Europe and key emerging markets and the addition of the freemium business model and over 30 million active devices to the Norton family.

Gagan Singh, chief product officer, NortonLifeLock, said: “We were pioneers in delivering comprehensive Cyber Safety to consumers via our Norton 360 platform, and now with the addition of Avira’s product capabilities and solutions, we can better serve a broader set of consumers with our combined portfolio and a freemium business model.”

The acquisition is expected to close in the Fiscal 2021 fourth quarter, subject to regulatory and customary closing conditions, and is not expected to be material to Fiscal 2021 Q4 results.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cybercrime Costs World Economy over 1% of Global GDP

Cybercrime Costs World Economy over 1% of Global GDP

Global losses from cybercrime now total over $1tn, according to a new report released today by McAfee in partnership with the Center for Strategic and International Studies (CSIS).

The Hidden Costs of Cybercrime” concludes that cybercrime costs the world economy more than one percent of global GDP. A 2018 study put global losses more than 50% lower, at around $600bn. 

Independent technology market research specialist Vanson Bourne was commissioned by McAfee to undertake the research upon which the report is based. Between April and June 2020, researchers interviewed 1,500 IT and line-of-business decision makers. 

Respondents came from Australia (200), Canada (200), France (200), Germany (200), Japan (200), the UK (200), and the US (300).

The report focuses not just on the significant financial cost of cybercrime but also on its wider impact on things like company performance and brand reputation. Nearly all (92%) companies surveyed reported feeling effects from cybercrime that went beyond monetary losses. 

Over a third (33%) of survey respondents stated downtime caused by IT security incidents cost them between $100,000 and $500,000. The average cost to organizations from their longest amount of downtime in 2019 was $762,231. 

More than a quarter (26%) said that downtime caused by cybercrime had damaged their brand. Downtime also reduced efficiency, losing organizations on average nine working hours a week.

“The severity and frequency of cyber-attacks on businesses continues to rise as techniques evolve, new technologies broaden the threat surface, and the nature of work expands into home and remote environments,” said Steve Grobman, SVP and CTO at McAfee. 

“While industry and government are aware of the financial and national security implications of cyber-attacks, unplanned downtime, the cost of investigating breaches and disruption to productivity represent less appreciated high-impact costs.” 

Grobman identified a need for greater understanding of the comprehensive impact of cyber-risk and said that effective plans should be put in place to respond to and prevent cyber-incidents “given the hundreds of billions of dollars of global financial impact.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

HMRC Reported 11 “Serious” Personal Data Incidents to ICO this Financial Year

HMRC Reported 11 “Serious” Personal Data Incidents to ICO this Financial Year

HM Revenue and Customs (HMRC) has reported 11 “serious” personal data incidents to the Information Commissioner’s Office (ICO) in the most recent financial year, according to official figures.

As disclosed in its recent annual report, HMRC outlined that the incidents are estimated to have affected more than 23,000 people in total.

The most widespread and serious personal data incident recorded in the report occurred in May. In that instance, National Insurance number letters relating to 16-year-old children were sent out with incorrect details, impacting up to 18,864 members of the public.

The most severe incident occurred in February when a fraudulent attack resulted in 64 employees’ details being obtained from three PAYE schemes. Various personal info was leaked with 573 people said to have been impacted as a result.

Commenting on the report, HMRC said: “We deal with millions of customers every year and tens of millions of paper and electronic interactions. We take the issue of data security extremely seriously and continually look to improve the security of customer information. We investigate and analyses all security incidents to understand and reduce security and information risk. We actively learn and act on our incidents.”

Donal Blaney, principle at Griffin Law, added: “Taxpayers have a right to expect their sensitive personal data to be kept secure by the taxman. The Information Commissioner should immediately investigate HMRC for these breaches and hold the taxman to account for this breathtaking incompetence.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Egregor Ransomware Steals Data from Recruiter Randstad

Egregor Ransomware Steals Data from Recruiter Randstad

One of the world’s largest recruitment agencies has become the latest victim of a serious ransomware attack, after being hit by the Egregor variant.

Randstad claims to have 280,000 clients and operations in 38 countries. Its 38,000 employees helped to generate nearly €24bn ($29bn) in revenue last year.

However, the self-styled “number one recruitment agency in the world” revealed in a statement late last week that it “recently” became aware of malicious activity on the network.

It appears as if the firm manged to escape any major operational impact, but it has suffered a data breach.

“Prompt global action was taken to mitigate the incident while further protecting Randstad’s systems, operations and data. As a result, a limited number of servers were impacted. Our systems have continued running without interruption and there has not been any disruption to our operations,” it explained.

“To date, our investigation has revealed that the Egregor group obtained unauthorized and unlawful access to our global IT environment and to certain data, in particular related to our operations in the US, Poland, Italy and France. They have now published what is claimed to be a subset of that data.”

An investigation into exactly what has been accessed is currently underway, so that relevant parties can be notified. As a major recruiter, Randstad would have access to troves of personal data from job-hunters.

The firm said the relevant regulatory authorities and law enforcement agencies have been notified, and that it doesn’t appear as if any third-party systems were impacted by the attack.

Egregor first came to light in September, when the ransomware-as-a-service group appeared to rise from the ashes of the now-defunct Maze gang. Since then, it has quickly ramped up activity, with the number of victim organizations soaring 240% between September and October, according to Digital Shadows.

The ransomware itself was designed with code obfuscation and packed payloads, in a bid to deter analysis by researchers.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FBI: #COVID19 Recession Fuels Money Mule Activity

FBI: #COVID19 Recession Fuels Money Mule Activity

The FBI has warned that the economic recession caused by COVID-19 is creating the perfect conditions for a surge in money mule activity.

An alert sent out by the Baltimore Field Office on Friday was designed to alert potential recruits to the fact they may be unwittingly breaking the law by moving money about on behalf of others.

Due to surging unemployment in the US, many former workers are falling for “work from home” opportunities advertised online, including on legitimate job sites, the FBI noted.

“Once ‘hired’ for these jobs, you may first be asked to perform a few easy COVID-19 related tasks, such as researching the current price of various hand sanitizers. Eventually, the employer may ask you to accept a ‘donation’ of funds into your own bank account or to open a new bank account in the name of a company to accept a deposit of funds,” the notice explained.

“You are then asked to withdraw the funds in cash and deposit them into a Bitcoin ATM or ‘kiosk.’ The so-called ‘donation’ is money that has been stolen from others. Mules may also be asked to wire the deposited funds to another bank account or even to use the funds to purchase gift cards or other transferrable assets.”

Even before the pandemic struck, money mule activity had been surging as organized crime groups looked for new recruits to launder money obtained by fraud and other predicate offenses. From 2015-19, fraud losses reported to the FBI’s Internet Crime Complaint Center (IC3) more than tripled, from $1.1bn to $3.5bn.

It’s also rife in the UK: a Cifas report from June 2019 recorded a 26% increase in fraudulent use of bank accounts over the previous year.

The FBI urged job seekers to protect themselves from such scams by refusing job offers that request they use their bank accounts to transfer other people’s money, or employers that request they form a company to open a new bank account.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Europol: Beware Fake Dark Web #COVID19 Vaccines

Europol: Beware Fake Dark Web #COVID19 Vaccines

As the UK begins preparations to deploy a COVID-19 vaccine, law enforcers are warning of counterfeit versions circulating on the dark web.

After passing the UK’s strict regulatory approvals process in record time, the Pfizer/BioNTech vaccine will begin rolling out to vulnerable groups this week.

However, Europol warned on Friday that counterfeit versions are already starting to circulate on the dark web, as organized crime groups react to the surge in interest and demand from the public.

These will be “ineffective at best or toxic at worst” and could lead to outbreaks of the virus among communities assumed to have been vaccinated, the police agency warned.

“Counterfeit vaccines may circulate on illicit markets or be introduced to the legal market, as occurs regularly with other counterfeit pharmaceuticals. The expected high demand for COVID-19 vaccines will likely attract organized crime groups seeking to capitalize on the pandemic situation and subsequent vaccination campaigns,” it explained.

“For example, criminals may resort to illegally refilling empty vials. Therefore, procedures for the correct disposal of vials by grinding or incineration will have to be properly enforced.”

Criminals may also look to seize genuine vaccines from supply chain companies charged with delivering them, Europol warned.

“Genuine COVID-19 vaccines will be highly valuable commodities and their supply chains (storage, transportation and delivery) will be at risk of being targeted by criminals seeking to obtain these pharmaceutical products,” it said.

“Organized crime groups might target transit containing COVID-19 vaccines for hijacking and theft.”

These vaccines could also pose a risk to public health, as they are likely to have been stored in ways that could impair the product, said Europol.

Domain Tools senior security researcher, Chad Anderson, also urged the public to be patient and wait their turn for official COVID-19 jabs.

“There is absolutely no guarantee that what you purchase from a dark web marketplace is what you will receive,” he added. “Unvetted dark web marketplaces now proliferate and allow sellers to scam at will. As always, we encourage users to not purchase items from dark web marketplaces and fund this criminal economy.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk