http://www.darkreading.com/mobile-security/167901113/security/client-security/240147566/hacking-the-laptop-docking-station.html
Very slick idea, by NCC Group's Research Director Andy Davis.
NCC link http://www.nccgroup.com/en/our-services/security-testing-audit-compliance/
I suspect Andy Davis prefers to exploit Hardware vulnerabilities, also found this notice about USB Mac Lion exploit discovered by him http://www.securityfocus.com/archive/1/524248/30/0/threaded
It is an "Arbitrary Code Execution (bug triggered by USB device insertion)."
I think (my opinion, no hard data to support) that providing security from Hardware Hacks like this, is a lot harder than defending against more common Computer threats like Phishing, Java exploits, weak passwords, etc.
Not objectively harder, but practically harder, because providing good security form Hardware Hacks requires people with skills from both Physical Security and Computer Security.
As well as budget support from upper management, the hardest type of support to secure.
The budget support is for good vetting and retention of cleaning personnel, I have mentioned this before in relation to hardware attacks,
It is difficult to convince higher management of the Security need to pay 3-5 times more than a business is used to for custodians.
Think Social Engineering attacks, or working as part of cleaning crew, would allow easy placement of device like this.
How many companies care enough
about security to pay good wages to keep good, vetted, in house Custodians vs using a Contractor provided Cleaning Crew?
Those cleaning crews tend to have high turn over, additionally, because of the high turnover, they tend to have low standards for hiring.
They need to keep hiring people that won't be paid much or be treated with much respect, so they tend to hire many people that have problems (criminal records, drug/alcohol, etc).
Even if they use in house custodians, still tends to be a low pay,
low status job, with a lot of turnover, and generally low standards for
hire.
Remember, Custodians or Cleaning Crews tend to have physical access to entire company, heck they are normally given keys.
It is trivially easy for someone on Cleaning Crew to swap out a hacked dock with existing one, or install hardware keyloggers.
Esports & Computer Security Blog. For SC2 tournaments see clocks immediately below. Starts with Korean time at upper left, moves west around the world till you end with PDT/PST clock for Anaheim USA. I earn a small referral fee if you click the occasional Amazon links and then purchase item. It does not affect the purchase price. For more information see "Amazon Associates" link below & left of clocks.
Showing posts with label Mac OS. Show all posts
Showing posts with label Mac OS. Show all posts
Saturday, February 2, 2013
Tuesday, August 21, 2012
Nerd News: "McAfee update chaos sparks user fury"
See story at SC Magazine's site http://www.scmagazine.com.au/News/312625,mcafee-update-chaos-sparks-user-fury.aspx
Personally I don't use McAfee's AV anymore, I think they have skills & talent to make decent AV software, but how they view and treat customers just doesn't make me feel like giving them my money.
I prefer Microsoft Security Essentials for Windows AV software (talking home & small business use, a business with some real money to throw at software could be different).
For Mac OS not sure yet, currently using and testing Sophos Free Mac AV.
So far for free AV it seems good, small bug issues couple of times, fixed with next patch, but other than that no complaints so far.
Personally I don't use McAfee's AV anymore, I think they have skills & talent to make decent AV software, but how they view and treat customers just doesn't make me feel like giving them my money.
I prefer Microsoft Security Essentials for Windows AV software (talking home & small business use, a business with some real money to throw at software could be different).
For Mac OS not sure yet, currently using and testing Sophos Free Mac AV.
So far for free AV it seems good, small bug issues couple of times, fixed with next patch, but other than that no complaints so far.
Subscribe to:
Posts (Atom)