Esports & Computer Security Blog. For SC2 tournaments see clocks immediately below. Starts with Korean time at upper left, moves west around the world till you end with PDT/PST clock for Anaheim USA. I earn a small referral fee if you click the occasional Amazon links and then purchase item. It does not affect the purchase price. For more information see "Amazon Associates" link below & left of clocks.
Monday, October 27, 2014
IEM 2014 San Jose: Catz vs Creature
Interesting series
Catz (Z) vs Creature (P)
Monday, October 6, 2014
Nerd News: "Silk Road Lawyers Poke Holes in FBI’s Story"
Brian Krebs has an interesting article up, http://krebsonsecurity.com/2014/10/silk-road-lawyers-poke-holes-in-fbis-story/, about the trial of alleged leader of Silk Road.
Short version, government's explanation for how they found the hidden servers appears to be BS.
This seems like they are hiding real way & means that they discovered the information.
Which, though IANAL, isn't legal as I understand it, in US Trials, there is a step called "Discovery" see http://www.americanbar.org/groups/public_education/resources/law_related_education_network/how_courts_work/discovery.html & http://en.wikipedia.org/wiki/Civil_discovery_under_United_States_federal_law.
So unlike TV or Movie Courtroom drama, there isn't surprise evidence introduced in the middle of the trial.
There are several reasons why information isn't supposed to be hidden during Discovery.
Discovery reduces wasting time, Judges generally have more cases than they can get to in any given time period, so as a practical matter, parties are encouraged to settle before Court date.
It also reduces some types of false testimony & evidence, or at least makes it easier to illuminate that it is occurring.
Short version, government's explanation for how they found the hidden servers appears to be BS.
This seems like they are hiding real way & means that they discovered the information.
Which, though IANAL, isn't legal as I understand it, in US Trials, there is a step called "Discovery" see http://www.americanbar.org/groups/public_education/resources/law_related_education_network/how_courts_work/discovery.html & http://en.wikipedia.org/wiki/Civil_discovery_under_United_States_federal_law.
So unlike TV or Movie Courtroom drama, there isn't surprise evidence introduced in the middle of the trial.
There are several reasons why information isn't supposed to be hidden during Discovery.
Discovery reduces wasting time, Judges generally have more cases than they can get to in any given time period, so as a practical matter, parties are encouraged to settle before Court date.
It also reduces some types of false testimony & evidence, or at least makes it easier to illuminate that it is occurring.
Friday, September 19, 2014
Security & Hacking: Apple iOS 8 & Data Extraction
People have been citing a statement on this page http://www.apple.com/privacy/government-information-requests/ as proof that with iOS 8 Apple can't extract data from devices secured with a passcode.
I don't think most people are reading Apple's statement with a critical enough mindset, here is last part of what Apple actually wrote about data extraction:
The key part is "extraction of this data from devices in their [government] possession running iOS 8." Note my bolded emphasis.
What Apple is really saying, I think, is just like iOS 7 Apple needs devices in their possession to extract data, they can't do it remotely and didn't provide government agencies with the tools to do so either.
Here is a snippet from Apple's page Legal Process Guidelines U.S. Law Enforcement. Important Note, the original link "https://www.apple.com/legal/more-resources/law-enforcement/" to this information at Apple gets redirected to "https://www.apple.com/privacy/government-information-requests/" now, so if you don't have a copy of original page you will need to find cached version to verify:
And from the FAQ section of that page:
I also haven't noticed any comments about data from the coprocessor that tracks movement and other data on iPhone 5S and newer, even when phone is sleeping.
Additional Links of Interests:
I don't think most people are reading Apple's statement with a critical enough mindset, here is last part of what Apple actually wrote about data extraction:
"So it's not technically feasible for us to respond to government warrants for the extraction of this data from devices in their possession running iOS 8."
The key part is "extraction of this data from devices in their [government] possession running iOS 8." Note my bolded emphasis.
What Apple is really saying, I think, is just like iOS 7 Apple needs devices in their possession to extract data, they can't do it remotely and didn't provide government agencies with the tools to do so either.
Here is a snippet from Apple's page Legal Process Guidelines U.S. Law Enforcement. Important Note, the original link "https://www.apple.com/legal/more-resources/law-enforcement/" to this information at Apple gets redirected to "https://www.apple.com/privacy/government-information-requests/" now, so if you don't have a copy of original page you will need to find cached version to verify:
" I. Extracting Data from Passcode Locked iOS Devices
Upon receipt of a valid search warrant, Apple can extract certain categories of active data from passcode locked iOS devices. Specifically, the user generated active files on an iOS device that are contained in Apple’s native apps and for which the data is not encrypted using the passcode (“user generated active files”), can be extracted and provided to law enforcement on external media. Apple can perform this data extraction process on iOS devices running iOS 4 or more recent versions of iOS. Please note the only categories of user generated active files that can be provided to law enforcement, pursuant to a valid search warrant, are: SMS, photos, videos, contacts, audio recording, and call history. Apple cannot provide: email, calendar entries, or any third-party App data."
And from the FAQ section of that page:
"Can Apple provide me with the passcode of an iOS device that is currently locked?
No, Apple does not have access to a user’s passcode but may be able to extract some data from a locked device with a valid search warrant as described in the Guidelines."So what it seems like to me, is that iOS 8 offers at best same protection as earlier versions, Apple can still extract data from from devices in their possession, though they worked hard to write a factually accurate statement that was misleading.
I also haven't noticed any comments about data from the coprocessor that tracks movement and other data on iPhone 5S and newer, even when phone is sleeping.
Additional Links of Interests:
- Apple's 2014 iOS Security Whitepaper http://images.apple.com/privacy/docs/iOS_Security_Guide_Sept_2014.pdf
- Apple iMessage encryption http://cliffsesportcorner.blogspot.com/2013/04/cnet-apples-imessage-encryption-trips.html
- iPhone 5S Good, Bad, & Big Brother http://cliffsesportcorner.blogspot.com/2013/09/nerd-news-iphone-5s-good-bad-big-brother.html
Thursday, September 11, 2014
DEFCON 22 Weaponizing Your Pets Gene Bransfield
Weaponizing Your Pets
Gene Bransfield Twitter @gbransfield
DEFCON 22: Dark Mail Ladar Levison and Stephen Watt
DEF CON 22 Darkmail
Ladar Levison & Stephan Watt
I also strongly recommend Leo Laporte's interview of Ladar Levison on Triangulation, its available as podcast on iTunes or as download at
http://twit.tv/show/triangulation/125
Nerd News: "U.S. threatened massive fine to force Yahoo to release data"
Washington Post article about how US Government forced Yahoo to hand over information & messages from its users.
And forced their participation in PRISM.
Washington Post article:
http://www.washingtonpost.com/business/technology/us-threatened-massive-fine-to-force-yahoo-to-release-data/2014/09/11/38a7f69e-39e8-11e4-9c9f-ebb47272e40e_story.html
Wikipedia PRISM:
http://en.wikipedia.org/wiki/PRISM_%28surveillance_program%29
And forced their participation in PRISM.
Washington Post article:
http://www.washingtonpost.com/business/technology/us-threatened-massive-fine-to-force-yahoo-to-release-data/2014/09/11/38a7f69e-39e8-11e4-9c9f-ebb47272e40e_story.html
Wikipedia PRISM:
http://en.wikipedia.org/wiki/PRISM_%28surveillance_program%29
Tuesday, August 12, 2014
Nerd News: LastPass Back Up
LastPass has been down for a while, but according to LastPass and
other reports it should be back up, though there may still be some
issues.
Sounds like they only use 2 datacenters, or maybe even only single primary one with a "backup".
Source https://lastpass.com/status.php
Also http://www.isitdownrightnow.com/lastpass.com.html
For LastPass users that want an offline solution to prevent this type of problem in future consider LastPass Pocket
This is LastPass link specifically about offline access https://helpdesk.lastpass.com/password-manager-basics/your-lastpass-vault/offline-access-to-your-lastpass-vault/
Sounds like they only use 2 datacenters, or maybe even only single primary one with a "backup".
"Update: 1:28 pm ESTSource http://blog.lastpass.com/
Though one of our data centers remains completely down, the service is generally stable and should be available to the majority of users (with the exception of login favicons). Some users may see connection errors but should still be able to access their data. We continue to work as quickly as possible to get the service back to 100%. "
"Aug 12, 2014 - One of LastPass' datacenters has been down since 3:57am EDT. The service is now running fully off one Herndon VA datacenter and we have been engaged with our provider all morning. Currently favicons/sprites are impacted. We are doing what we can to minimize the impact and apologize for the inconvenience. "
Source https://lastpass.com/status.php
Also http://www.isitdownrightnow.com/lastpass.com.html
For LastPass users that want an offline solution to prevent this type of problem in future consider LastPass Pocket
This is LastPass link specifically about offline access https://helpdesk.lastpass.com/password-manager-basics/your-lastpass-vault/offline-access-to-your-lastpass-vault/
Monday, August 11, 2014
Def Con 21: "Pentesting with an Army of Low-power Low-cost Devices"
Couldn't go to Def Con 22, waiting for vods to come out, so started watching some of the Def Con 21 Youtubes in the meanwhile.
I like this one about Pen Testing with cheap Arm devices by Dr. Philip Polstra aka Dr. Phil the Hacker his Twitter is ppolstra | https://twitter.com/ppolstra.
He uses the BeagleBoard Black as the starting point for his hardware.
Some useful links:
- Current version that's available BeagleBone Black Rev C - 4GB Flash - Pre-installed Debian https://www.adafruit.com/products/1876
- Jan Axelson was LVR.com now http://janaxelson.com/ ["The developer's resource for computer interfacing, especially USB, serial (COM) ports, mass storage, Ethernet and Internet for embedded systems, and the parallel port."]
- Xbee http://www.digi.com/xbee/
- The Deck [a full-featured penetration testing & forensics Linux distribution] for BeagleBone Black http://ppolstra.blogspot.com/2013/08/the-deck-for-beaglebone-black-has.html
- Installing Deck Youtube http://youtu.be/98kbOKuInv4?t=1m18s
- BeagleBoard site http://beagleboard.org/
- BeagleBoard Black site http://beagleboard.org/black
- Wikipedia on BeagleBoard http://en.wikipedia.org/wiki/BeagleBoard
- Wikipedia on Xbee http://en.wikipedia.org/wiki/XBee
These labels can be booked marked so you can just check topics your interested in, so for more posts like this you could click on:
Security & Hacking: The Matasano Crypto Challenges
Really cool the Matasano Crypto Challenges is "a collection of 48 exercises that demonstrate attacks on real-world crypto."
It's designed to teach real Crypto attacks by doing, great for improving the security of code you write, or to get an idea of what Pen Testing or malicious hacking involves.
Very good review, worth reading in it's own right here https://blog.pinboard.in/2013/04/the_matasano_crypto_challenges/
Note in the Pinboard review the original link for Matasano Crypto Challenges didn't update for server move, current working link (I have correct link at top of this blog post of mine as well) is http://web.archive.org/web/20140213141638/http://www.matasano.com/articles/crypto-challenges/
It's designed to teach real Crypto attacks by doing, great for improving the security of code you write, or to get an idea of what Pen Testing or malicious hacking involves.
Very good review, worth reading in it's own right here https://blog.pinboard.in/2013/04/the_matasano_crypto_challenges/
Note in the Pinboard review the original link for Matasano Crypto Challenges didn't update for server move, current working link (I have correct link at top of this blog post of mine as well) is http://web.archive.org/web/20140213141638/http://www.matasano.com/articles/crypto-challenges/
Saturday, August 2, 2014
SC2ITL: ROOT vs Grav
Stream: http://www.twitch.tv/fenn3r
SC2 Improve Team League: http://wiki.teamliquid.net/starcraft2/SC2Improve_Team_League
Root 4 Root!
SC2 Improve Team League: http://wiki.teamliquid.net/starcraft2/SC2Improve_Team_League
Root 4 Root!
Subscribe to:
Posts (Atom)