Showing posts with label Mac OS. Show all posts
Showing posts with label Mac OS. Show all posts

Saturday, February 2, 2013

Pen Testing & Hardware Hacking: Hacking Laptop Docking Station

http://www.darkreading.com/mobile-security/167901113/security/client-security/240147566/hacking-the-laptop-docking-station.html

Very slick idea, by NCC Group's Research Director Andy Davis.

NCC link http://www.nccgroup.com/en/our-services/security-testing-audit-compliance/

I suspect Andy Davis prefers to exploit Hardware vulnerabilities, also found this notice about USB Mac Lion exploit discovered by him http://www.securityfocus.com/archive/1/524248/30/0/threaded

It is an "Arbitrary Code Execution (bug triggered by USB device insertion)."


I think (my opinion, no hard data to support) that providing security from Hardware Hacks like this, is a lot harder than defending against more common Computer threats like Phishing, Java exploits, weak passwords, etc.

Not objectively harder, but practically harder, because providing good security form Hardware Hacks requires people with skills from both Physical Security and Computer Security.

As well as budget support from upper management, the hardest type of support to secure.

The budget support is for good vetting and retention of cleaning personnel, I have mentioned this before in relation to hardware attacks,

It is difficult to convince higher management of the Security need to pay 3-5 times more than a business is used to for custodians.

Think Social Engineering attacks, or working as part of cleaning crew, would allow easy placement of device like this.

How many companies care enough about security to pay good wages to keep good, vetted, in house Custodians vs using a Contractor provided Cleaning Crew?

Those cleaning crews tend to have high turn over, additionally, because of the high turnover, they tend to have low standards for hiring.

They need to keep hiring people that won't be paid much or be treated with much respect, so they tend to hire many people that have problems (criminal records, drug/alcohol, etc).

Even if they use in house custodians, still tends to be a low pay, low status job, with a lot of turnover, and generally low standards for hire.

Remember, Custodians or Cleaning Crews tend to have physical access to entire company, heck they are normally given keys.

It is trivially easy for someone on Cleaning Crew to swap out a hacked dock with existing one, or install hardware keyloggers.










Tuesday, August 21, 2012

Nerd News: "McAfee update chaos sparks user fury"

See story at SC Magazine's site http://www.scmagazine.com.au/News/312625,mcafee-update-chaos-sparks-user-fury.aspx

Personally I don't use McAfee's AV anymore, I think they have skills & talent to make decent AV software, but how they view and treat customers just doesn't make me feel like giving them my money.

I prefer Microsoft Security Essentials for Windows AV software (talking home & small business use, a business with some real money to throw at software could be different).

For Mac OS not sure yet, currently using and testing Sophos Free Mac AV.

So far for free AV it seems good, small bug issues couple of times, fixed with next patch, but other than that no complaints so far.