Indistinguishability Obfuscation

Quanta magazine recently published a breathless article on indistinguishability obfuscation — calling it the “‘crown jewel’ of cryptography” — and saying that it had finally been achieved, based on a recently published paper. I want to add some caveats to the discussion.

Basically, obfuscation makes a computer program “unintelligible” by performing its functionality. Indistinguishability obfuscation is more relaxed. It just means that two different programs that perform the same functionality can’t be distinguished from each other. A good definition is in this paper.

This is a pretty amazing theoretical result, and one to be excited about. We can now do obfuscation, and we can do it using assumptions that make real-world sense. The proofs are kind of ugly, but that’s okay — it’s a start. What it means in theory is that we have a fundamental theoretical result that we can use to derive a whole bunch of other cryptographic primitives.

But — and this is a big one — this result is not even remotely close to being practical. We’re talking multiple days to perform pretty simple calculations, using massively large blocks of computer code. And this is likely to remain true for a very long time. Unless researchers increase performance by many orders of magnitude, nothing in the real world will make use of this work anytime soon.

But but, consider fully homomorphic encryption. It, too, was initially theoretically interesting and completely impractical. And now, after decades of work, it seems to be almost just-barely maybe approaching practically useful. This could very well be on the same trajectory, and perhaps in twenty to thirty years we will be celebrating this early theoretical result as the beginning of a new theory of cryptography.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

More on the Security of the 2020 US Election

Last week I signed on to two joint letters about the security of the 2020 election. The first was as one of 59 election security experts, basically saying that while the election seems to have been both secure and accurate (voter suppression notwithstanding), we still need to work to secure our election systems:

We are aware of alarming assertions being made that the 2020 election was “rigged” by exploiting technical vulnerabilities. However, in every case of which we are aware, these claims either have been unsubstantiated or are technically incoherent. To our collective knowledge, no credible evidence has been put forth that supports a conclusion that the 2020 election outcome in any state has been altered through technical compromise.

That said, it is imperative that the US continue working to bolster the security of elections against sophisticated adversaries. At a minimum, all states should employ election security practices and mechanisms recommended by experts to increase assurance in election outcomes, such as post-election risk-limiting audits.

The New York Times wrote about the letter.

The second was a more general call for election security measures in the US:

Obviously elections themselves are partisan. But the machinery of them should not be. And the transparent assessment of potential problems or the assessment of allegations of security failure — even when they could affect the outcome of an election — must be free of partisan pressures. Bottom line: election security officials and computer security experts must be able to do their jobs without fear of retribution for finding and publicly stating the truth about the security and integrity of the election.

These pile on to the November 12 statement from Cybersecurity and Infrastructure Security Agency (CISA) and the other agencies of the Election Infrastructure Government Coordinating Council (GCC) Executive Committee. While I’m not sure how they have enough comparative data to claim that “the November 3rd election was the most secure in American history,” they are certainly credible in saying that “there is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised.”

We have a long way to go to secure our election systems from hacking. Details of what to do are known. Getting rid of touch-screen voting machines is important, but baseless claims of fraud don’t help.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

GoDaddy Employees Used in Attacks on Multiple Cryptocurrency Services

Fraudsters redirected email and web traffic destined for several cryptocurrency trading platforms over the past week. The attacks were facilitated by scams targeting employees at GoDaddy, the world’s largest domain name registrar, KrebsOnSecurity has learned.

The incident is the latest incursion at GoDaddy that relied on tricking employees into transferring ownership and/or control over targeted domains to fraudsters. In March, a voice phishing scam targeting GoDaddy support employees allowed attackers to assume control over at least a half-dozen domain names, including transaction brokering site escrow.com.

And in May of this year, GoDaddy disclosed that 28,000 of its customers’ web hosting accounts were compromised following a security incident in Oct. 2019 that wasn’t discovered until April 2020.

This latest campaign appears to have begun on or around Nov. 13, with an attack on cryptocurrency trading platform liquid.com.

“A domain hosting provider ‘GoDaddy’ that manages one of our core domain names incorrectly transferred control of the account and domain to a malicious actor,” Liquid CEO Mike Kayamori said in a blog post. “This gave the actor the ability to change DNS records and in turn, take control of a number of internal email accounts. In due course, the malicious actor was able to partially compromise our infrastructure, and gain access to document storage.”

In the early morning hours of Nov. 18 Central European Time (CET), cyptocurrency mining service NiceHash disccovered that some of the settings for its domain registration records at GoDaddy were changed without authorization, briefly redirecting email and web traffic for the site. NiceHash froze all customer funds for roughly 24 hours until it was able to verify that its domain settings had been changed back to their original settings.

“At this moment in time, it looks like no emails, passwords, or any personal data were accessed, but we do suggest resetting your password and activate 2FA security,” the company wrote in a blog post.

NiceHash founder Matjaz Skorjanc said the unauthorized changes were made from an Internet address at GoDaddy, and that the attackers tried to use their access to its incoming NiceHash emails to perform password resets on various third-party services, including Slack and Github. But he said GoDaddy was impossible to reach at the time because it was undergoing a widespread system outage in which phone and email systems were unresponsive.

“We detected this almost immediately [and] started to mitigate [the] attack,” Skorjanc said in an email to this author. “Luckily, we fought them off well and they did not gain access to any important service. Nothing was stolen.”

Skorjanc said NiceHash’s email service was redirected to privateemail.com, an email platform run by Namecheap Inc., another large domain name registrar. Using Farsight Security, a service which maps changes to domain name records over time, KrebsOnSecurity instructed the service to show all domains registered at GoDaddy that had alterations to their email records in the past week which pointed them to privateemail.com. Those results were then indexed against the top one million most popular websites according to Alexa.com.

The result shows that several other cryptocurrency platforms also may have been targeted by the same group, including Bibox.com, Celsius.network, and Wirex.app. None of these companies responded to requests for comment.

In response to questions from KrebsOnSecurity, GoDaddy acknowledged that “a small number” of customer domain names had been modified after a “limited” number of GoDaddy employees fell for a social engineering scam. GoDaddy said the outage between 7:00 p.m. and 11:00 p.m. PST on Nov. 17 was not related to a security incident, but rather a technical issue that materialized during planned network maintenance.

“Separately, and unrelated to the outage, a routine audit of account activity identified potential unauthorized changes to a small number of customer domains and/or account information,” GoDaddy spokesperson Dan Race said. “Our security team investigated and confirmed threat actor activity, including social engineering of a limited number of GoDaddy employees.

“We immediately locked down the accounts involved in this incident, reverted any changes that took place to accounts, and assisted affected customers with regaining access to their accounts,” GoDaddy’s statement continued. “As threat actors become increasingly sophisticated and aggressive in their attacks, we are constantly educating employees about new tactics that might be used against them and adopting new security measures to prevent future attacks.”

Race declined to specify how its employees were tricked into making the unauthorized changes, saying the matter was still under investigation. But in the attacks earlier this year that affected escrow.com and several other GoDaddy customer domains, the assailants targeted employees over the phone, and were able to read internal notes that GoDaddy employees had left on customer accounts.

What’s more, the attack on escrow.com redirected the site to an Internet address in Malaysia that hosted fewer than a dozen other domains, including the phishing website servicenow-godaddy.com. This suggests the attackers behind the March incident — and possibly this latest one — succeeded by calling GoDaddy employees and convincing them to use their employee credentials at a fraudulent GoDaddy login page.

In August 2020, KrebsOnSecurity warned about a marked increase in large corporations being targeted in sophisticated voice phishing or “vishing” scams. Experts say the success of these scams has been aided greatly by many employees working remotely thanks to the ongoing Coronavirus pandemic.

A typical vishing scam begins with a series of phone calls to employees working remotely at a targeted organization. The phishers often will explain that they’re calling from the employer’s IT department to help troubleshoot issues with the company’s email or virtual private networking (VPN) technology.

The goal is to convince the target either to divulge their credentials over the phone or to input them manually at a website set up by the attackers that mimics the organization’s corporate email or VPN portal.

On July 15, a number of high-profile Twitter accounts were used to tweet out a bitcoin scam that earned more than $100,000 in a few hours. According to Twitter, that attack succeeded because the perpetrators were able to social engineer several Twitter employees over the phone into giving away access to internal Twitter tools.

An alert issued jointly by the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) says the perpetrators of these vishing attacks compile dossiers on employees at their targeted companies using mass scraping of public profiles on social media platforms, recruiter and marketing tools, publicly available background check services, and open-source research.

The FBI/CISA advisory includes a number of suggestions that companies can implement to help mitigate the threat from vishing attacks, including:

• Restrict VPN connections to managed devices only, using mechanisms like hardware checks or installed certificates, so user input alone is not enough to access the corporate VPN.

• Restrict VPN access hours, where applicable, to mitigate access outside of allowed times.

• Employ domain monitoring to track the creation of, or changes to, corporate, brand-name domains.

• Actively scan and monitor web applications for unauthorized access, modification, and anomalous activities.

• Employ the principle of least privilege and implement software restriction policies or other controls; monitor authorized user accesses and usage.

• Consider using a formalized authentication process for employee-to-employee communications made over the public telephone network where a second factor is used to
authenticate the phone call before sensitive information can be discussed.

• Improve 2FA and OTP messaging to reduce confusion about employee authentication attempts.

• Verify web links do not have misspellings or contain the wrong domain.

• Bookmark the correct corporate VPN URL and do not visit alternative URLs on the sole basis of an inbound phone call.

• Be suspicious of unsolicited phone calls, visits, or email messages from unknown individuals claiming to be from a legitimate organization. Do not provide personal information or information about your organization, including its structure or networks, unless you are certain of a person’s authority to have the information. If possible, try to verify the caller’s identity directly with the company.

• If you receive a vishing call, document the phone number of the caller as well as the domain that the actor tried to send you to and relay this information to law enforcement.

• Limit the amount of personal information you post on social networking sites. The internet is a public resource; only post information you are comfortable with anyone seeing.

• Evaluate your settings: sites may change their options periodically, so review your security and privacy settings regularly to make sure that your choices are still appropriate.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Green Beret Passed Secrets to Russia

Green Beret Passed Secrets to Russia

A former Green Beret in the United States Army has admitted passing classified information to Russian intelligence agents.

Peter Rafael Dzibinski Debbins was arrested in August 2020 and charged with conspiring to provide United States national defense information to agents of a foreign government. On November 18, the 45-year-old Gainesville, Florida, resident pleaded guilty to the charge and now faces a maximum penalty of life in prison. 

“Despite being entrusted to protect his colleagues and US national security, he chose to abuse this trust by knowingly providing classified information to one of our most aggressive adversaries,” said Steven D’Antuono, assistant director in charge of the FBI’s Washington Field Office. 

According to court documents, Debbins conspired with agents of a Russian intelligence service from December 1996 to January 2011, periodically visiting Russia to meet with those agents in person. 

Debbins was assigned a code name by Russian intelligence agents in 1997 after signing a statement in which he pledged his allegiance to Russia. 

From 1998 to 2005, Debbins served on active duty as an officer in the US Army, working in chemical units before being selected to join the US Army Special Forces, where he served at the rank of captain.

Throughout the 13-year conspiracy, Debbins gave Russian intelligence agents information that he obtained as a US Army member, including data about his chemical and Special Forces units. 

In 2008, after leaving active duty service, Debbins disclosed to the Russian intelligence agents classified information about his previous activities while deployed with the Special Forces. 

Debbins also provided agents with the names of, and information about, his former Special Forces team members. Agents used this information to decide who to approach and sound out about the possibility of cooperating with the Russian intelligence service.

“President Kennedy called the Green Berets ‘a symbol of excellence, a badge of courage, a mark of distinction.’ Mr. Debbins’ actions were a symbol of betrayal, a badge of cowardice, and a mark of treachery,” said Alan Kohler, Jr., assistant director of the FBI’s Counterintelligence Division. 

“He pledged his allegiance to Russia, and in doing so, sold-out his country and fellow Green Berets.”

Debbins is scheduled to be sentenced on February 26, 2021.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Data Breach at Iowa Hospital

Data Breach at Iowa Hospital

A data breach at an Iowa hospital has exposed the Social Security numbers and private medical information of more than 60,000 patients. 

Mercy Iowa City began notifying patients on November 13 of a data breach that occurred in spring 2020 after an employee’s email account was accessed by a threat actor. 

The hospital detected the breach on June 24 when the targeted account began sending out phishing emails and spam. An investigation revealed that the hacked account had been compromised between May 15 and June 24.

Security experts brought in to scrutinize the incident confirmed in October that sensitive patient data could have been accessed by the attacker.

Data exposed may have included names, Social Security numbers, driver’s license numbers, and health insurance information.

Chicago-based Polsinelli law firm, representing the hospital, said that 60,473 Iowa residents may have been impacted by the security incident.

In a letter sent out to affected Iowa residents on the hospital’s behalf, Bruce Radke of Polsinelli stated: “Mercy is not aware of any fraud or identity theft to any individual as a result of this incident. Nevertheless, because there was an email account compromise, Mercy searched the impacted account to determine if it contained any personal information that may have been viewed by the third party.

“Mercy determined that the compromised account contained certain personal information, including, depending on the person, their name, Social Security number, driver’s license numbers, date of birth, medical treatment information, and health insurance information.”

Mercy Iowa City is offering one year of complimentary identity theft protection services to patients whose driver’s license numbers and Social Security numbers may have been compromised.

The hospital said that it is implementing a series of cybersecurity measures including multi-factor authentication to prevent any more breaches from happening. 

“We have taken steps to reduce the risk of the type of incident occurring in the future, including enhancing our technical security measures,” said Mercy’s privacy officer, Kelli Hale.

This latest data spill is the second and worst breach to occur at Mercy Iowa City. In 2016, the acute care hospital reported a security breach that may have exposed the information of 15,625 patients. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FireEye Acquires Respond Software

FireEye Acquires Respond Software

Intelligence-led security firm FireEye yesterday announced the acquisition of Respond Software, a company that uses automation to assist customers to comprehend and investigate security incidents.

The transaction closed on November 18, 2020, and is valued at approximately $186m in cash and stock. 

FireEye said that the acquisition of Respond Software will open new market opportunities to deliver eXtended Detection and Response (XDR) capabilities to a wide range of customers. Furthermore, the deal will enable Mandiant Solutions to scale its expertise and front-line intelligence as part of the Mandiant Advantage platform.

“Respond’s product dramatically reduces time spent investigating false positives as it connects the dots among siloed, multi-vendor security controls in an easy-to-deploy cloud-based package,” said Mike Armistead, Respond Software’s chief executive officer prior to the acquisition. 

“Now coupled with Mandiant’s world-class threat intelligence and incident response expertise feeding our models, customers can be confident the most up-to-date and relevant attack tactics and techniques are recognized and appropriately escalated.”  

California-based company Respond is creator of the Respond Analyst, an XDR engine that uses cloud-based data-science models to accelerate cyber-investigation and response. After ingesting data from a comprehensive set of security technologies, the engine automatically correlates multi-sourced attack evidence.

FireEye plans to make the XDR technology an integral part of the Mandiant Advantage platform, bringing vendor-agnostic XDR and investigation capable of integration with all customer environments. The company said the changes will quicken response times and provide better security outcomes for customers. 

“With Mandiant’s position on the front lines, we know what to look for in an attack, and Respond’s cloud-based machine learning productizes our expertise to deliver faster outcomes and protect more customers,” said Kevin Mandia, FireEye chief executive officer. 

“This creates a learning system with new capabilities that will enable us to expand our Mandiant portfolio and drive new XDR revenue through our Mandiant Advantage platform.”

Max Gazor from CRV, who led the Respond Software’s Series Seed round in 2016, commented: “Respond Software’s acquisition follows in the footsteps of other great CRV portfolio companies such as CloudGenix (acquired by Palo Alto Networks), Affirmed Networks (acquired by Microsoft), and Signal Sciences (acquired by Fastly) making it the fourth major acquisition in CRV’s portfolio this year.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#ISSE2020: Focus on 2020’s Crypto Successes Rather than Efforts to Break it

#ISSE2020: Focus on 2020’s Crypto Successes Rather than Efforts to Break it

Efforts to break encryption in new crypto wars are ongoing, but there are many successes to recount in the past year.

Speaking in the closing session the virtual ISSE Conference Professor Bart Preneel from the KU Leuven, where he heads the COSIC research group, said more and more research crypto has been published this year and he praised the work to enable contact tracing, but was critical of government and law enforcement’s efforts around end-to-end (E2E) encryption.

Saying the “crypto wars have come back again, something I’m doomed to live with for the rest of my life,” Preneel referred to the case in 1993 when AT&T introduced a secure phone with E2E-based on Triple DES, which the US government was not happy with “as it stopped them intercepting phone calls, especially outside US.” The clipper chip with key escrow project failed, and now the crypto wars have come back as cryptography has shifted from hardware to software.

He said there is a case for interception of those people communicating child abuse images, terrorist acts and kidnapping cases, and governments are unable to access encrypted communications, “so the government has no access.” Preneel also said some people use Facebook Messenger for those purposes, and it is possible at the moment as it is not E2E encrypted, but Facebook announced E2E for Messenger to stop that channel of access, “and the stupid people will not be able to escape.”

He said this proposal was met with criticism as most people are not happy with backdoors, and as a society, we can agree to filter for abuse messages and images, but it could also be used against the freedom of speech of people you don’t like, and for political purposes.

“It keeps coming in different forms and shapes, but the debate is essentially the same and the main complaint is police and intelligence services have lots of metadata, once they find one person they can use that infrastructure to find other people, once you have metadata you have access,” he said. “It is a one-sided debate as law enforcement does not show what they acquired in the last 20 years, so that is actually a debate that is happening, and it is difficult to debate with one side who doesn’t disclose.”

Among other cryptography highlights from 2020, Preneel cited the breaking of RSA 250, where the researchers found two prime factors. “It is important as a large part of digital infrastructure relies on RSA,” he said. “It was amazing as they used so little power, and more effort and money was put in.”

Speaking on quantum computing, he said despite Google, Intel and Microsoft building and spending in quantum computing research, there were no big examples of successes this year, even by companies “spending small fortunes.” He said in order to break RSA 2048 you will need something like 20 million qbits, and most companies were very far from that, so he predicted that we will be safe until 2035.

With regards to contact tracing, Preneel welcomed the work done to create apps that anonymized user details, and using decentralized proximity tracing (DP3T), he said there had been 57 million downloads of DP3T-based apps across 18 EU countries and Switzerland. He said: “There are still problems in integration in some national health systems, but it is a solution that seems to work. There are clear indications it works and people are being warned and it is cost effective. The solution was security and privacy friendly.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CybExer Tasked With Enhancing Luxembourg’s Cyber-Defense Capabilities

CybExer Tasked With Enhancing Luxembourg’s Cyber-Defense Capabilities

Cybersecurity firm CybExer Technologies has announced it has been tasked with building a cyber-range for the Luxembourg Directorate of Defense in order to grow the skills of its current and future cyber-personnel.

The cyber-range is essentially an IT-systems simulation environment that aims to improve organizations’ cyber-defense capabilities by conducting regular training and testing.

The company has been awarded a three-year contract by the NATO Support and Procurement Agency (NSPA) to deliver the range, which will utilize CybExer’s management tools and offer realistic and flexible training environments. The platform will primarily be used by the NSPA and Luxembourg Directorate of Defense, but may also be shared with allies and partners.

This follows the recent decision by the Directorate of Defense of the Grand Duchy of Luxembourg to develop its cyber-defense capabilities. In order to grow the skills of its security staff, the directorate is working with the NSPA to purchase new training capabilities.

As part of the agreement, CybExer will also provide a series of dedicated training sessions as well as have responsibility for the operation and maintenance of the range throughout the period of the contract.

Andrus Kivisaar, CEO of CybExer Technologies, commented: “We have been focusing on building and improving cyber-ranges for years and are glad that our dedication and expertise in the field has been recognized at NATO level. We see that the cybersecurity environment is getting more and more complex. It is good to work with a client who shares our vision and demands a sophisticated cyber-range solution.”

Ben Fetler, cybersecurity project manager at the Luxembourg Directorate of Defense, added: “Luxembourg has become a key ICT actor in the European Union. We have invested massively in connectivity and IT infrastructures over the last years, with the aim of becoming a ‘smart nation’ and one of the most dynamic digital economies in Europe. All of this requires protection and with our national cybersecurity strategy we are aiming, together with NSPA and CybExer, at building a highly capable training environment that can prepare our cybersecurity teams for the most advanced threats.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Faith App Pray.com Exposes Millions Through Cloud Misconfig

Faith App Pray.com Exposes Millions Through Cloud Misconfig

A popular Christian faith app has unwittingly exposed the personal data of up to 10 million users dating back several years, after misconfiguring its cloud infrastructure, researchers have warned.

Santa Monica-headquartered Pray.com claims to be the “#1 App for daily prayer and biblical audio content” and has been downloaded over a million times from the Play Store.

Researchers at vpnMentor discovered four misconfigured AWS S3 buckets belonging to the company.

Although it had made private around 80,000 files, it failed to replicate these security measures on its Cloudfront CDN, which also had access to the files. This means a hacker could have compromised personal information on as many as 10 million people, most of whom were not even Pray.com users.

“Cloudfront allows app developers to cache content on proxy servers hosted by AWS around the world – and closer to an app’s users – rather than load those files from the app’s servers. Doing so speeds up the app’s performance considerably,” vpnMentor explained.

“Pray.com seemingly overlooked installing proper security measures on its CloudFront account. As a result, any files on the S3 buckets could be indirectly viewed and accessed through the CDN, regardless of their individual security settings.”

After notifying the company repeatedly through early October, vpnMentor finally received a one-word response from Pray.com CEO, Steve Gatena: “Unsubscribe.”

While most of the misconfigured buckets’ 1.8 million files featured corporate content, those 80,000 exposed files represented a serious privacy and security risk.

They contained uploaded profile pics from app users, CSV files from churches using the app, with the names, home and email addresses, phone numbers and other info on churchgoers and PII of individuals donating to churches via the app.

Perhaps most damaging was a feature which uploads the entire phonebook of any user who gives the app permission to invite their friends to join. These “phonebooks” contained hundreds of contacts, with info including name, phone number, email, home and business address.

Many of the files also contained log-ins from private accounts, the report continued.

This data went all the way back to 2016.

The researchers warned that individuals caught up in the leak, some of whom had .gov and .mil email addresses, were at risk from follow-on phishing, identity fraud and account takeover.

The vpnMentor team noted that regulators for the CCPA and GDPR may want to investigate further. Five weeks after initial contact was made with Pray.com, the offending files were removed, although the S3 buckets apparently remain exposed.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Announces Pluton Processor for Better Hardware Security

Microsoft Announces Pluton Processor for Better Hardware Security

Microsoft has announced the launch of a security processor designed to provide stronger hardware and software integration for Windows PCs to remove entire vectors of attack. 

Named the Pluton and built in collaboration with AMD, Intel and Qualcomm, Microsoft claimed the processor will improve the ability to guard against physical and/or hardware attacks targeting identity and encryption keys to steal sensitive information, monitor firmware and verify the integrity of the system, and streamline firmware updates through the cloud (via Windows Update).

A “chip-to-cloud” security technology, this has been pioneered in Xbox and Azure Sphere. Microsoft said its vision for the future of Windows PCs is security at the core, built into the CPU, for a more integrated approach where the hardware and software are tightly integrated, ultimately removing entire vectors of attack.

Windows PCs using the Pluton architecture will first emulate a Trusted Platform Module (TPM), which works with the existing TPM specifications and APIs, allowing customers to immediately benefit from enhanced security for Windows features that rely on TPMs like BitLocker and System Guard.

The processor will protect credentials, user identities, encryption keys and personal data by storing sensitive data securely within the Pluton processor, which is isolated from the rest of the system

Pluton also provides the unique Secure Hardware Cryptography Key (SHACK) technology that helps ensure keys are never exposed outside of the protected hardware, even to the Pluton firmware itself, providing an unprecedented level of security for Windows customers.  

Also, Pluton will provide a flexible, updateable platform for running firmware that implements end-to-end security functionality that is authored, maintained and updated by Microsoft. Pluton for Windows computers will be integrated with the Windows Update process in the same way that the Azure Sphere Security Service connects to IoT devices.  

David Weston, director of enterprise and OS security at Microsoft, said: “We believe that processors with built-in security like Pluton are the future of computing hardware. With Pluton, our vision is to provide a more secure foundation for the intelligent edge and the intelligent cloud by extending this level of built-in trust to devices and things everywhere.  

“Our work with the community helps Microsoft continuously innovate and enhance security at every layer. We’re excited to make this revolutionary security design a reality with the biggest names in the silicon industry as we continuously work to enhance security for all.” 

Asaf Shen, senior director of product management at Qualcomm Technologies, said: “Qualcomm Technologies is pleased to continue its work with Microsoft to help make a slew of devices and use cases more secure. We believe an on-die, hardware-based Root-of-Trust like the Microsoft Pluton is an important component in securing multiple use cases and the devices enabling them.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk