IMSI-Catchers from Canada

Gizmodo is reporting that Harris Corp. is no longer selling Stingray IMSI-catchers (and, presumably, its follow-on models Hailstorm and Crossbow) to local governments:

L3Harris Technologies, formerly known as the Harris Corporation, notified police agencies last year that it planned to discontinue sales of its surveillance boxes at the local level, according to government records. Additionally, the company would no longer offer access to software upgrades or replacement parts, effectively slapping an expiration date on boxes currently in use. Any advancements in cellular technology, such as the rollout of 5G networks in most major U.S. cities, would render them obsolete.

The article goes on to talk about replacement surveillance systems from the Canadian company Octasic.

Octasic’s Nyxcell V800 can target most modern phones while maintaining the ability to capture older GSM devices. Florida’s state police agency described the device, made for in-vehicle use, as capable of targeting eight frequency bands including GSM (2G), CDMA2000 (3G), and LTE (4G).

[…]

A 2018 patent assigned to Octasic claims that Nyxcell forces a connection with nearby mobile devices when its signal is stronger than the nearest legitimate cellular tower. Once connected, Nyxcell prompts devices to divulge information about its signal strength relative to nearby cell towers. These reported signal strengths (intra-frequency measurement reports) are then used to triangulate the position of a phone.

Octasic appears to lean heavily on the work of Indian engineers and scientists overseas. A self-published biography of the company notes that while the company is headquartered in Montreal, it has “R&D facilities in India,” as well as a “worldwide sales support network.” Nyxcell’s website, which is only a single page requesting contact information, does not mention Octasic by name. Gizmodo was, however, able to recover domain records identifying Octasic as the owner.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Google Mending Another Crack in Widevine

For the second time in as many years, Google is working to fix a weakness in its Widevine digital rights management (DRM) technology used by online streaming sites like Disney, Hulu and Netflix to prevent their content from being pirated.

The latest cracks in Widevine concern the encryption technology’s protection for L3 streams, which is used for low-quality video and audio streams only. Google says the weakness does not affect L1 and L2 streams, which encompass more high-definition video and audio content.

“As code protection is always evolving to address new threats, we are currently working to update our Widevine software DRM with the latest advancements in code protection to address this issue,” Google said in a written statement provided to KrebsOnSecurity.

In January 2019, researcher David Buchanan tweeted about the L3 weakness he found, but didn’t release any proof-of-concept code that others could use to exploit it before Google fixed the problem.

This latest Widevine hack, however, has been made into an extension for Microsoft Windows users of the Google Chrome web browser and posted for download on the software development platform Github.

Tomer Hadad, the researcher who developed the browser extension, said his proof-of-concept code “was done to further show that code obfuscation, anti-debugging tricks, whitebox cryptography algorithms and other methods of security-by-obscurity will eventually by defeated anyway, and are, in a way, pointless.”

Google called the weakness a circumvention that would be fixed. But Hadad took issue with that characterization.

“It’s not a bug but an inevitable flaw because of the use of software, which is also why L3 does not offer the best quality,” Hadad wrote in an email. “L3 is usually used on desktops because of the lack of hardware trusted zones.”

Media companies that stream video online using Widevine can select different levels of protection for delivering their content, depending on the capabilities of the device requesting access. Most modern smartphones and mobile devices support much more robust L1 and L2 Widevine protections that do not rely on L3.

Further reading: Breaking Content Protection on Streaming Websites

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Army Base’s Twitter Account Hacked

US Army Base’s Twitter Account Hacked

A malicious hacker has been blamed for a series of lewd messages that emanated from the social media account of a US military base on Wednesday.

Followers of Fort Bragg’s official Twitter account were surprised by the sexual content of a number of tweets that began to appear at around 4:30pm ET. 

The tweets were posted in response to messages featuring adult content that were shared by another Twitter user. 

When @Quinnfinite10 posted a tweet about someone who had complained about the display of pubic hair on her OnlyFans page, Fort Bragg’s account replied to her post with a message in support of the user and her decision to show her body hair.

Referencing the individual who wasn’t in favor of the image, Fort Bragg’s alleged hacker stated: “He’s lost and doesn’t know a good thing when it’s staring him in the eyes or tickling his nose in this case.”

Other messages shared by the North Carolina army base’s Twitter account included a sexually explicit comment on a topless photo that had been shared on the Twitter page of @Quinnfinite10. 

The comment posted from @FtBraggNC read: “My face’s, then my boner’s and then my face’s again before I come up to give you a deep long kiss.”

Responding to the base’s racy messages, one Twitter user said: “Doesn’t surprise me that military bases out here advocating for pro Bush stances.”

Shortly after the lewd tweets were posted, the army base’s account appeared to be deleted.

The 18th Airborne Corps, whose commander commands Fort Bragg, then tweeted: “As many of you may know, there were a string of explicit Tweets from our account this afternoon. This was not the work of our admins. Our account was hacked.”

“We apologize to our followers. We have secured our account and [sic] looking into the matter.”

Fort Bragg spokesperson Tom McCollum told the Fayetteville Observer that the base’s account had been hacked and that an investigation into the security incident had been launched by the Army Criminal Investigation Division.

“We’ve deleted those images, reset our password and reset the two-cycle authentication process,” said McCollum. “We apologize to anyone who follows us on Twitter and don’t know how this happened.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Systems Admin Arrested for Hacking Former Employer

Systems Admin Arrested for Hacking Former Employer

The former systems administrator of an American department store has been arrested after allegedly hacking into his ex-employer’s private network to give his former colleagues paid holidays. 

New Yorker Hector Navarro is accused of creating a “superuser” account that allowed him to access a computer system of Century 21 after he resigned from his position at the company.

Navarro worked as a human resources systems administrator at the Manhattan branch of the department store from 2012 to October 2019. Through his role, the defendant had access to the company’s data management and timekeeping system. 

The 30-year-old is accused of accessing a network of his former employer from his Brooklyn apartment to tamper with data. It is further alleged that Navarro deleted data to prevent consultants hired to replace him from accessing Century 21’s computer network.

The Manhattan District Attorney’s Office stated: “Prior to his last day, he stole employee data from the company and created an unauthorized ‘superuser’ account on the company’s network—which allowed him access to the network after his resignation.” 

The department store discovered the security breach after Navarro’s replacements were unable to get into the system. An investigation by the company determined that changes had been made to Century 21’s holiday payroll policy.

As a result of the changes, certain employees would have been paid for holidays even if they had not worked on those particular dates. Century 21 spent thousands of dollars to correct the changes and deletions allegedly made by Navarro. 

“If left undetected, this former employee’s alleged tampering could have cost Century 21 more than $50,000,” said District Attorney Cy Vance.

“Unauthorized access to computer networks and the theft of valuable proprietary data are serious threats to the Manhattan business community.”

A New York Supreme Court indictment has charged Navarro with attempted grand larceny in the second degree, criminal mischief in the second degree, computer tampering in the third degree, computer trespass, petit larceny, and the criminal possession of stolen property.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Judge Signs Off on $7.75m Equifax Settlement

Judge Signs Off on $7.75m Equifax Settlement

A federal judge has approved a multi-million-dollar settlement to resolve claims made by financial institutions against Equifax following a data breach three years ago. 

Between May and June 2017, cyber-criminals gained access to around 150 million records of Atlanta-based credit monitoring service Equifax by exploiting an unpatched Apache Struts vulnerability. 

The breach impacted roughly 56% of America’s population and millions of consumers in the UK, costing Equifax over $1.35bn in losses.

Information exposed included names, Social Security numbers, dates of birth, addresses, and in some cases, driver license numbers.

A suit brought against Equifax by financial institutions after they were forced to absorb the expense of the breach has now been settled. 

Chief Judge Thomas Thrash of the Northern District of Georgia gave final approval to the $7.75m settlement yesterday during a hearing held via Zoom. Legal fees of $2m were included in the resolution. 

As part of the agreement, Equifax has committed to investing an additional $25m to enhance data security measures tailored to financial institutions. The investment is scheduled to occur over the next two years. 

Thrash described the settlement as “an excellent one” and said that the class lawyers’ request for $2m in legal fees was “appropriate.”

“The fact there were no objections from class members weighs in favor of approving the settlement,” stated Thrash.

Equifax has ring-fenced $5.5m to pay up to $5,000 to each financial institution for costs associated with the theft of customers’ personal information or fraud losses. 

Each of the 21 financial institutions listed as plaintiffs in the multi-district litigation will be paid $1,500 from the fund.

The settlement with the financial institutions is separate from a $1.4bn settlement reached by Equifax in December 2019 with legal representatives of roughly 147 million consumers whose data was exposed in the 2017 breach. Included in that settlement was $77.5m in legal fees and over $1.4m in expenses for class-action lawyers.

In April this year, Equifax agreed to pay $19.5m to settle a separate class-action lawsuit brought by the State of Indiana over the 2017 data breach. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#SecTorCa: How One Malicious Message Could Exploit an Enterprise

#SecTorCa: How One Malicious Message Could Exploit an Enterprise

Following the global transition to remote working that began in March of this year due to the COVID-19 pandemic, Omer Tsarfati, cybersecurity researcher at CyberArk Labs, found himself using Microsoft Teams more than ever before.

Being a security researcher, Tsarfati wanted to make sure the software he was using was actually secure – which it wasn’t. In fact, he and his teams discovered a critical flaw that could have potentially enabled an attacker to intercept messages across a company and possibly even launch broader attacks. The flaw was patched by Microsoft in April with few concrete details, however, Tsarfati explained the whole incident with new information in a session at the SecTor security conference.

Tsarfati explained that Microsoft Teams is a deeply integrated technology that connects with both Microsoft and non-Microsoft technologies. The integration with different technologies includes the use of access credentials known as OAuth tokens that authenticate the user with the given technology.

What Tsarfati and his team were able to discover was that Microsoft was using an authentication configuration approach that created a source of vulnerability, such that one malicious message could enable an attacker to gain access to multiple systems and user information.

How the Exploit Works

Tsarfati explained that one way to trigger the exploit would be to send a victim an email with a malicious link, which would then drop a cookie on the user’s system. That cookie could then read improperly configured information in Microsoft Teams to gain access to connected systems, including Outlook and Sharepoint.

He noted that organizations train employees not to click on links, as phishing is a known risk, so instead his team came up with a non-invasive approach to get the malicious cookie onto a victim’s system. That’s part of what was disclosed in Apri; a malicious GIF image that could be used to exploit Microsoft Teams.

Tsarfati said that simply by visiting a page in a web browser that has a malicious GIF image embedded in it, an attacker could pass the bad cookies to an endpoint and gain unauthorized access to other services. Adding further insult to injury, he noted that an attacker could also then further weaponize the vulnerability by spreading it to other users and across an organization’s network.

While Microsoft has patched the issue, Tsarfati was asked if other collaboration tools beyond Teams might have similar risks. He noted that it’s highly likely that is possible, if researchers take the time to look.

Though Microsoft has patched the issue, Tsarfati recommended that users remain vigilant. When sharing any confidential information, he suggested not sharing in the open in an email or in a document. According to Tsarfati, any sensitive and confidential information should always be encrypted to help prevent unauthorized access and limit risk.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#SecTorCa: Tech for Good, and Bad

#SecTorCa: Tech for Good, and Bad

According to Tracy Ann Kosa, staff privacy engineer at Google, all technology comes with both promises and un-intended consequences.

Kosa detailed the challenges and opportunities that technology can bring to society at large during a keynote session at the virtual SecTor security conference. She added that the notion that technology always helps to improve human life is slowly beginning to fade away.

“Social media was supposed to bring us all together and it definitely has, but we see positive and negative consequences of that,” she said.

Where Tech Excels and Where it Fails

Kosa noted that computers are exceptionally good at well-defined tasks with accurately and well-labeled data. Technology is also powerful for image recognition at a level that, in some cases, surpasses human abilities, but there are limitations.

In her view, computing systems still struggle with the physical world and lack common sense. When it comes to machine learning and automation, there are some particular risks as systems that are based on data that lacks diversity, both in terms of source and participation, lead to inaccurate outcomes.

 

Whenever a new technology is introduced, there is a cycle of panic that tends to follow, Kosa said. For example, she noted that there was a significant decline in youth mental health in the United States in 2010 that was rather compellingly blamed on smartphone usage.

“That kind of panic becomes a widespread popular moral panic, and we see questions such as: what does it mean to be human and how is this technology changing that for humanity?” she said.

What tends to follow the initial moral panic are politicians that will issue public declarations against a certain emerging technology. The next phase in the cycle of panic is some form of reinvention where the issues that caused the panic are somehow addressed. In some cases, no real progress happens and the panic about the technology continues.

Technology Ethics

Kosa said that there are increasing calls today to have ethics integrated into technology services so they can be more beneficial to human society.

“What does that mean, do we want our engineers to become philosophers, or do we want our philosophers to become engineers?” Kosa asked.

In answering her own question, Kosa emphasized that individuals make ethical decisions all the time and most people don’t need special training to become ethical. That said, for software developers and technology engineers, it can be useful to have a framework within which to consider the ethical implications of a given technology.

One such approach to considering the impact of technology is the reasonable person test that emerged out of a Supreme Court decision in Canada. Kasa explained that the reasonable person model for technology ethics is to consider how an average layperson expects technology to work and what kind of information is required by the service in order to work as expected.

Technology for Good

While much of Kasa’s keynote addressed the negative impacts of technology, she was careful to also note that technology has many positive impacts as well. Contact tracing efforts, which are critical during the COVID-19 pandemic, are one such example of helpful technology she cited.

Kasa also noted that financial services technology has been a major benefit for good in recent years, with online mortgage platforms helping to enable more people from diverse communities to get a loan and own a home.

“Reducing and, in some cases, removing entirely human brokers from the mortgage underwriting process does in fact seem to be democratizing the industry,” she said.

There is more that can be done to enable technology for good and to that end Kasa concluded her keynote with a call to action for developers and technology builders. Every time there is a new release of software, service or hardware, she wants there to be a consideration about three key questions: who is in the story, who is not in the story and who benefits?

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#SecTorCa: The Paramedic’s Guide to Surviving Cybersecurity

#SecTorCa: The Paramedic’s Guide to Surviving Cybersecurity

As a trained paramedic, Rich Mogull has helped to save lives. Mogull is also a cybersecurity professional and he sees a number of parallels between his two professions.

Mogull is the CEO of security analyst firm Securosis and provided his insights in a session at the virtual SecTor security conference. Mogull noted that he’s led parallel lives, one in emergency services and the other in cybersecurity and the lessons he has learned from one profession have helped in the other. In particular, he noted that there are many similarities between the two professions in terms of burnout and mental health challenges.

“I think the reason these two fields are so similar is that they share one really core aspect – the job is never done,” Mogull said. “We are pushing the rock uphill; we’re always treating the next patient, solving the next incident or securing the next technology.”

Both Professions Start with Enthusiasm

The initial phase in both emergency services and cybersecurity is a period where individuals are enthusiastic about the job. People are eager and excited to learn new skills, typically have a flexible mindset and are task-focused.

The big challenge during the initial enthusiasm phase is that individuals often learn skills without context. There are new tools that both professions get to use and new entrants into the profession are eager to use those tools.

“When I got out of paramedic school I couldn’t wait to start IVs (intravenous drip feeds) and when you come out of security training you can’t wait to use those latest tools and run a penetration test against your organization,” he said.

The other challenge during the enthusiasm phase is that people tend to pick the wrong role models to emulate and that can lead to bad outcomes in the future.

“People who are burnt out and cynical, they have a particular magnetism to them,” Mogull explained. “They come across as the old crusty seen it all, done it all, they are the Han Solo characters that we try to emulate.”

When Burnout Sets In

Mogull said that it typically takes three to five years to mature as a paramedic and then burnout will often set in during the five to seven year period. The burnout happens for a number of reasons in both professions, including the fact that the same types of incidents keep recurring time after time.

“You’re just caught in this endless cycle, seeing the same things over and over and responding the same way,” he added.

Avoiding the risk of burnout requires a combination of mindset and process, Mogull continued. There is a need to eat healthy, exercise and sleep. There is also a need for peer support, so colleagues help each other out. Having the right peers is critical for that process to work.

“If you hang out with the cynical and burned out crowd, you’re going to be cynical and burnt out,” he said.

Towards a Just Culture

There is also a need to compartmentalize the different aspects of life to enable some form of work-life balance. Having the ability to do context shifting to keep work at work is how Mogull said he’s able to have some balance.

Beyond just having a life outside of work, it’s important to have a positive environment, that Mogull referred to as a Just Culture. He explained that Just Culture is the opposite of blame culture and it’s important for both emergency services and cybersecurity. Rather than looking for someone to blame for a given issue, the basic idea behind Just Culture is to figure out how to improve the system and not necessarily to always be looking for someone to blame.

“If you use the term shadow IT, you don’t have a Just Culture, you’re blaming users for using technologies they think they need to get their job done,” Mogull argued. “In some cases it could be recklessness, but in other cases maybe we’re just not giving them the right tools or understanding their needs.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US and UK Issue Sanctions to Iran and Russia

US and UK Issue Sanctions to Iran and Russia

The US and UK governments have both issues sanctions in response to recent cyber-attacks.

Yesterday, the Department of the Treasury’s Office of Foreign Assets Control (OFAC) announced that five Iranian entities have been “designated” for attempting to influence elections in the United States. The OFAC said the Iranian regime “has targeted the United States’ electoral process with brazen attempts to sow discord among the voting populace by spreading disinformation online and executing malign influence operations aimed at misleading US voters.”

This involved components of the government of Iran, including the Islamic Revolutionary Guard Corps (IRGC), the IRGC-Qods Force (IRGC-QF) and Bayan Rasaneh Gostar Institute (Bayan Gostar), disguising itself as news organizations or media outlets in order to subvert US democratic processes. Also, the Iranian Islamic Radio and Television Union (IRTVU) and International Union of Virtual Media (IUVM) were designated as being owned or controlled by the IRGC-QF.

The disinformation campaigns “focus on sowing discord among readers via social media platforms and messaging applications, and frequently involve mischaracterizing information” it claimed. This included influencing the election by exploiting social issues within the United States, including the COVID-19 pandemic and denigrating US political figures.

As recently as summer 2020, Bayan Gostar was prepared to execute a series of influence operations directed at the US populace ahead of the presidential election.

Also, IRTVU, said to be a propaganda arm of the IRGC-QF, and IUVM, aided Bayan Gostar in efforts to reach US audiences by amplifying false narratives in English, and posting disparaging propaganda articles and other US-oriented content, with the intent to sow discord among US audiences. IUVM is also alleged to have posted conspiracy theories and disinformation related to the COVID-19 pandemic.

The statement came in the same week as the UK enforced new sanctions against Russia after a cyber-attack hit the German parliament in 2015. The UK said it will enforce asset freezes and travel bans against two Russian GRU officers and the GRU’s military intelligence unit 26165 – codenamed APT28 and Fancy Bear – which it said were responsible for the attacks.

In the attack, it is alleged unit 26165 targeted information systems, stole significant amounts of data and affected email accounts belonging to German MPs and the vice-chancellor.

The National Cyber Security Centre (NCSC) supported the attribution of the attack to Russia, and welcomed the sanctions and the multi-national and joint approach being taken with allies standing in solidarity against the attacks.

Paul Chichester, director of operations at the NCSC, said: “We fully support these sanctions, which send a strong message that that there will be consequences for those who target us or our allies in cyberspace. We will continue to work closely with our allies to counter malicious cyber-activity from the GRU and others who would seek to do us harm.”

Commenting, Ben Read, senior manager of analysis at Mandiant Threat Intelligence, said the EU and UK sanctions demonstrate the increased international willingness to hold countries accountable for the cyber-intrusions carried out by their security services. “The GRU (which we believe is linked to the threat group APT28) has compromised European governments including Germany for years, and shows no sign of slowing down,” he said. “While the technical features of its operations will continue to evolve, the strategic goal of gathering information for the Russian Government and projecting Russian power have remained consistent.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Infected IoT Device Numbers Surge 100% in a Year

Infected IoT Device Numbers Surge 100% in a Year

The volume of infected Internet of Things (IoT) devices globally has soared by 100% over the past year, according to new data from Nokia.

The telecoms equipment maker’s Threat Intelligence Report 2020 is compiled from data processed by service providers using its NetGuard Endpoint Security tool.

It revealed that infected IoT devices now comprise nearly a third (32.7%) of the total, up from 16.2% in the 2019 report.

Nokia argued that infection rates for connected devices depend dramatically upon the visibility of the devices on the internet.

“In networks where devices are routinely assigned public facing internet IP addresses, we find a high IoT infection rate. In networks where carrier grade NAT is used, the infection rate is considerably reduced, because the vulnerable devices are not visible to network scanning,” it explained.

“With the introduction of 5G well underway, it is expected that not only the number of IoT devices will increase dramatically, but also the share of IoT devices accessible directly from the internet will increase as well.”

Nokia warned that other aspects of 5G will also present major new security challenges to telcos: specifically Network Function Virtualization (NFV) and Software-defined Networking (SDN).

“For CSPs, it is a major challenge to provide a fully dependable, secure NFV environment. SDN bears the threat that control applications may wreak havoc on a large scale by erroneously or maliciously interacting with a central network controller,” the report explained.

“The network infrastructure of CSPs becomes more accessible to the attackers, so CSPs are increasingly targeted by sophisticated malicious actors.”

New use cases from the 5G subscriber side will also expand the potential attack surface for cyber-criminals, Nokia warned.

Security must therefore be baked into networks from the start, spanning all components of the ecosystem but managed from a central point of control. Automated orchestration and management and predictive security controls will also be key, Nokia said.

The firm will be hoping to differentiate on security as it competes for contracts formerly held by Chinese giant Huawei, which many governments are forcing CSPs to replace.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk