Showing posts with label Bruce Schneier. Show all posts
Showing posts with label Bruce Schneier. Show all posts

Wednesday, October 9, 2013

PSA TrueCrypt Audit project

What an interesting day!

Started with comments about Bruce Schneier's article at Wired http://www.wired.com/opinion/2013/10/149481/ where he mentions some concerns about TrueCrypt:
No, I don’t have any inside knowledge about TrueCrypt, and there’s a lot about it that makes me suspicious. But for Windows full-disk encryption it’s that, Microsoft’s BitLocker, or Symantec’s PGPDisk — and I am more worried about large U.S. corporations being pressured by the NSA than I am about TrueCrypt.

Eventually Matthew Green made the following tweet:
. and I are working on a 'Kickstarter' for a proper review of Truecrypt. The terms are a work in progress.

Fundfill link from Tweet above http://www.fundfill.com/fund/4-spzFJdDQk211KJDAUfcOw==#

Draft at http://istruecryptauditedyet.com/

You can follow Kenn White & Matthew Green on Twitter:

I am still very much a noob when it comes to Crypto, but Matthew Green is one of the people I follow to learn.

If your not into Crypto you probably haven't heard of him, this Ars article would be one place to start http://arstechnica.com/security/2013/09/crypto-prof-asked-to-remove-nsa-related-blog-post/

I am sorry to say I don't know much about Kenn White currently, I'd welcome comments or links that correct my ignorance.

Friday, January 18, 2013

Security & Hacking: Malware 2 Years ago USB Battery Charger Backdoor

Energizer Battery Charger Software Included Backdoor http://krebsonsecurity.com/2010/03/energizer-battery-charger-software-included-backdoor/

Energizer DUO USB battery charger software allows unauthorized remote system access http://www.kb.cert.org/vuls/id/154421

This is from 2010, so certainly not new concept, I hadn't heard of this specific hack before though, & to be honest, don't think I would have expected this, before reading Brian Kreb's article on it.

Though I was aware of the Vodafone issue that some of the Energizer Duo articles/comments mentioned http://research.pandasecurity.com/vodafone-distributes-mariposa/

To be clear, there wasn't Malware on the USB device itself, but in the software you could download from Energizer to monitor the device.

I didn't find any articles explaining how the Malware got inserted into the Energizer software, but some stories suggested it might have been in place for ~3 years.

If anyone has any more detail on this I would be interested in learning it.

Schneier also posted about it http://www.schneier.com/blog/archives/2010/03/back_door_in_ba.html


Tuesday, November 6, 2012

Nerd News: TSA Smackdown! Or "You Thought THAT was a Patdown?!?

[Edited to Clarify:  Since this happened in UK, it wasn't TSA, but that is name of the equivalent organization here in US so the name I used for convenience sake.]

Via Bruce Schneier, who is a well known critic of what he calls "security theatre", http://www.schneier.com/blog/archives/2012/11/on_the_ineffect_1.html

He links to this AWESOME story http://www.gizmodo.co.uk/2012/10/search-me/

Here is a snippet teaser, trust me, I didn't snip the best part, so go read whole article:
“That search was absolutely useless.” I said. “And just shows how much of all of this is security theatre. You guys are just feeling up passengers for no good effect, which means that you get all the downsides of a search – such as annoyed travellers who feel like they have had their privacy violated – without any of the benefits. I could have hidden half a dozen items on my person that you wouldn’t have had a snowball’s chance in a supernova of finding. That’s what I meant.”

That Gizmodo article was written by Matt Delito, "a police officer in London’s Metropolitan police force."

He blogs about his work and more at http://mattdelito.wordpress.com/


I immediately followed his RSS feed  http://mattdelito.wordpress.com/feed/
after reading his story.

Great Snark!

Also very true!!

Thursday, October 25, 2012

Security & Hacking "Backdoor in computer controls opens critical infrastructure to hackers"

http://arstechnica.com/security/2012/10/backdoor-in-computer-controls-opens-critical-infrastructure-to-hackers/

Things are just peachy with infrastructure security, this quote sums it up, "The CoDeSys tool will grant a command shell to anyone who knows the proper command syntax and inner workings, leaving systems that are connected to the public Internet open to malicious tampering."

This involves power plants and other infrastructure in the US and other parts of the world.

Not only is it frightening, it is really sad, just how big a vulnerability this single issue causes.

Not really even hacking, more like no security at all.

There are more infrastructure security issues out there.

There is a ridiculously bad category called Forever Day Bugs, also know as iDays, or Infinite Days.

Name is similar to Zero Day, only Forever Day/iDays vulnerabilities remain for years even after they are disclosed.

For various reasons iDays don't get patched or fixed.

Bruce Schneier has talked about Forever Day Bugs (vulnerabilities) http://www.schneier.com/blog/archives/2012/04/forever-day_bug.html

Ars has also covered them http://arstechnica.com/business/2012/04/rise-of-ics-forever-day-vulnerabiliities-threaten-critical-infrastructure/

ICS=Industrial Control Systems, not Ice Cream Sandwich, in this context.

Thursday, October 4, 2012

Security & Hacking: Keccak is chosen to be SHA-3

Official NIST announcement http://csrc.nist.gov/groups/ST/hash/sha-3/winner_sha-3.html
detailed PDF announcement from NIST http://csrc.nist.gov/groups/ST/hash/sha-3/sha-3_selection_announcement.pdf

Bruce's comments and thoughts http://www.schneier.com/blog/archives/2012/10/keccak_is_sha-3.html Bruce made it to the final round with his entry.

Keccak website http://keccak.noekeon.org/

Interesting times, hat tip to NIST for picking a good replacement before we need one!

I wish more banks and other institutions would follow that lead, instead of general trend of not updating security and crypto until long after vulnerabilities have been exploited.

Monday, October 1, 2012

Security & Hacking: PlaceRaider Android App Spies on You

http://www.technologyreview.com/view/429394/placeraider-the-military-smartphone-malware/
via Bruce Schneier's Blog http://www.schneier.com/blog/archives/2012/10/scary_iphone_ma.html

[Bruce labeled it iPhone by accident when first posting it, URL's are forever with blogs, has happened to me T_T ]

According to Technology Review the "app [is] capable of running in the background of any smartphone using the Android 2.3 operating system".

So newer versions of Android might be safe from this particular app?

Basically this Malware App silently takes pictures, while geo and orientation tagging them, filters out blurred and dark images, then send the rest to a server.

Interesting app.


Sunday, September 23, 2012

Cool, pretty, Sad

http://findlaydonnan.wordpress.com/2012/04/08/glowing-firefly-squid-beached-along-the-japanese-coast/

Via Schneier's Blog http://www.schneier.com/blog/archives/2012/09/friday_squid_bl_344.html

If your not familiar with Bruce Schneier's blog you should check it out, he is a gosu Security & Crypto person, your probably familiar with Truecrypt that he, and others, have worked on.

Sunday, July 29, 2012

Security & Hacking: "Stop using PPTP and switch to other technologies like IPsec or OpenVPN"

Article on Computerworld, about tools released at "Defcon security conference that can be used to crack the encryption of any PPTP (Point-to-Point Tunneling Protocol) and WPA2-Enterprise (Wireless Protected Access) sessions that use MS-CHAPv2 for authentication."

Bruce Schneir has written about problems with MS_CHAPv2 see http://www.schneier.com/pptp.html or full paper at http://www.schneier.com/paper-pptpv2.html

Wednesday, June 13, 2012

Bruce Schneier: Teaching the Security Mindset (Teach people to Cheat)

Bruce Schneier is an interesting person, for those of you that don't know who he is, he has worked with Truecrypt, and is considered a crypto and computer security expert.

I have been following him for a while now, very educational and useful IMO even if your not a computer geek. 


Today, he has a great post that covers Security Mindset, and points to a great paper "Embracing the Kobayashi Maru: Why You Should Teach Your Students to Cheat" by Gregory Conti and James Caroland.

Just wish I would have had a class like that when I was in college!