IOS

Apple Adds 'BlastDoor' To Secure iOS From Zero-Click Attacks (securityweek.com) 17

wiredmikey shares a report from SecurityWeek.com: Apple has quietly added several anti-exploit mitigations into iOS in what appears to be a specific response to zero-click iMessage attacks observed in the wild. The new mitigations were discovered by Samuel Grob, a Google Project Zero security researcher, [with the first big addition being] a new, tightly sandboxed "BlastDoor" service that is now responsible for the parsing of untrusted data in iMessages.

With iOS 14, Grob discovered that Apple shipped a significant refactoring of iMessage processing, and made all four parts of an attack much harder to succeed. Apple added logic into iOS 14 to specifically detect [shared cache region] attacks and new techniques to limit an attacker's ability to retry exploits or brute force Address Space Layout Randomization (ASLR).
"Overall, these changes are probably very close to the best that could've been done given the need for backwards compatibility, and they should have a significant impact on the security of iMessage and the platform as a whole," the Google researcher added.
Encryption

ProtonMail, Threema, Tresorit and Tutanota Warn EU Lawmakers Over 'Anti-Encryption' Push (techcrunch.com) 46

Four European apps which secure user data via end-to-end encryption, ProtonMail, Threema, Tresorit and Tutanota, have issued a joint-statement warning over recent moves by EU institutions that they say are setting lawmakers on a dangerous path to backdooring encryption. From a report: Last month the EU Council passed a resolution on encryption that's riven with contradiction -- calling for "security through encryption and security despite encryption" -- which the four e2e app makers believe is a thinly veiled call to backdoor encryption. The European Commission has also talked about seeking "improved access" to encrypted information, writing in a wide-ranging counter-terrorism agenda also published in December that it will "work with Member States to identify possible legal, operational, and technical solutions for lawful access." Simultaneously, the Commission has said it will "promote an approach which both maintains the effectiveness of encryption in protecting privacy and security of communications, while providing an effective response to crime and terrorism." And it has made it clear there will be no 'one silver bullet' as regards the e2e encryption security 'challenge.' But such caveats are doing nothing to alleviate the concerns of e2e encrypted app makers -- who are convinced proposals from the Council of the EU, which is involved in adopting the bloc's laws (though the Commission usually drafts legislation), sums to an push toward backdoors.

"While it's not explicitly stated in the resolution, it's widely understood that the proposal seeks to allow law enforcement access to encrypted platforms via backdoors," the four app makers write, going on to warn that such a move would fatally underline the security EU institutions also claim to want to maintain. "The resolution makes a fundamental misunderstanding: Encryption is an absolute, data is either encrypted or it isn't, users have privacy or they don't," they go on. "The desire to give law enforcement more tools to fight crime is obviously understandable. But the proposals are the digital equivalent of giving law enforcement a key to every citizen's home and might begin a slippery slope towards greater violations of personal privacy."

Security

Authorities Plan To Mass-Uninstall Emotet From Infected Hosts on March 25 (zdnet.com) 26

Law enforcement officials in the Netherlands are in the process of delivering an Emotet update that will remove the malware from all infected computers on March 25, 2021, ZDNet has learned today. From a report: The update was made possible after law enforcement agencies from across eight countries orchestrated a coordinated takedown this week to seize servers and arrest individuals behind Emotet, considered today's largest malware botnet. While servers were located across multiple countries, Dutch officials said that two of three of Emotet's primary command and control (C&C) servers were located inside its borders. Dutch police officials said today they used their access to these two crucial servers to deploy a boobytrapped Emotet update to all infected hosts. According to public reports, also confirmed by ZDNet with two cyber-security firms that have historically tracked Emotet operations, this update contains a time-bomb-like code that will uninstall the Emotet malware on March 25, 2021, at 12:00, the local time of each computer.
Crime

Police Dismantle World's 'Most Dangerous' Criminal Hacking Network (reuters.com) 31

International law enforcement agencies said on Wednesday they had dismantled a criminal hacking scheme used to steal billions of dollars from businesses and private citizens worldwide. Reuters reports: Police in six European countries, as well as Canada and the United States, completed a joint operation to take control of Internet servers used to run and control a malware network known as "Emotet," authorities said in a statement. "Emotet is currently seen as the most dangerous malware globally," Germany's BKA federal police agency said in a statement. "The smashing of the Emotet infrastructure is a significant blow against international organized Internet crime."

German police said infections with Emotet had caused at least 14.5 million euros ($17.56 million) of damage in their country. Globally, Emotet-linked damages cost about $2.5 billion, Ukrainian authorities said. Ukraine's General Prosecutor said police had carried out raids in the eastern city of Kharkiv to seize computers used by the hackers. Authorities released photos showing piles of bank cards, cash and a room festooned with tangled computer equipment, but did not say if any arrests were made.

Windows

iCloud For Windows Gaining Support For iCloud Passwords Chrome Extension (macrumors.com) 6

Apple yesterday released a new version of iCloud for Windows 10, and based on multiple reports and the update's release notes, it appears Apple is introducing an iCloud Passwords extension designed for Chrome, which will allow "iCloud" Keychain passwords to be used on Windows machines. MacRumors reports: As noted by The 8-Bit and a few other sources, the update adds support for an "iCloud" Passwords Chrome extension." After installing version 12 of "iCloud" for Windows, there's a new "Passwords" section in the app with an "iCloud" Keychain logo. When attempting to use the feature, though, the "iCloud" app prompts users to download a Chrome extension, but the extension is broken and clicking to install leads to a broken web page.

This is likely a bug that will be addressed in the near future, and it sounds like when it is functional, Windows users will be able to access their "iCloud" Keychain passwords on their Windows machines through the Chrome browser. It's not clear if Apple will offer this extension for Mac machines in the future as well, and it appears to be limited to Windows at this time.

Security

10-year-old Sudo Bug Lets Linux Users Gain Root-Level Access (zdnet.com) 166

A major vulnerability impacting a large chunk of the Linux ecosystem has been patched today in Sudo, an app that allows admins to delegate limited root access to other users. From a report: The vulnerability, which received a CVE identifier of CVE-2021-3156, but is more commonly known as "Baron Samedit," was discovered by security auditing firm Qualys two weeks ago and was patched earlier today with the release of Sudo v1.9.5p2. In a simple explanation provided by the Sudo team today, the Baron Samedit bug can be exploited by an attacker who has gained access to a low-privileged account to gain root access, even if the account isn't listed in /etc/sudoers -- a config file that controls which users are allowed access to su or sudo commands in the first place.
Businesses

Just 1 In 10 Companies Expect All Employees To Return To the Office (nbcnews.com) 98

An anonymous reader writes: Only about 1 in 10 companies expect all employees to return to their pre-pandemic work arrangements, according to a new survey. The National Association for Business Economics found that just 11 percent of survey respondents expect all staff members at their companies to return eventually. Around 65 percent of companies have allowed "most" or "all" of their staff members to work from home during the pandemic, and about half of respondents said they plan to continue the policies until the second half of the year.

"For the most part, companies that are able to provide work-from-home are doing so and are continuing to do so," said Andrew Challenger, vice president of the executive outplacement and coaching firm Challenger, Gray & Christmas. Challenger said his conversations with human resources executives indicated a reluctance to mandate a return to the office while the virus is still circulating and parts of the country face surges. In some cases, local or state lockdowns, school and day care closings or restrictions on building capacities also limit employers' options.
According to another recent survey, 31% of professionals from 42 tech companies said they're only putting in between three and four hours a day. However, the survey did not ask the workers to self-report productivity.
Businesses

One-Third of Tech Workers Admit To Working Only 3 To 4 Hours a Day, Report Finds (fastcompany.com) 180

According to a survey by Blind, 31% of professionals from 42 tech companies said they're only putting in between three and four hours a day. Fast Company reports: Additionally, the survey found, 27% of tech professionals said they work five to six hours a day, and 11% reported only working one to two hours per day. In contrast, 30% said they work between seven and 10 hours per day. The survey did not ask the workers to self-report productivity, which we know is very different for everyone.

Although the responses within the companies surveyed were anecdotal, one Amazon employee commented, "Amazon requires at least 10 hours a day, with exceptions and maybe less work on Fridays or more work on weekends. I'm working way more during COVID-19, calendar's full back to back, leadership is asking for more." Meanwhile, a professional at Facebook reported, "If meetings count then 9-10. If they do not... [less than] 1," bearing out the fact that the pandemic has not impacted everyone equally.

Security

North Korean Hackers Have Targeted Security Researchers Via Social Media (zdnet.com) 15

Google said today that a North Korean government hacking group has targeted members of the cyber-security community engaging in vulnerability research. From a report: The attacks have been spotted by the Google Threat Analysis Group (TAG), a Google security team specialized in hunting advanced persistent threat (APT) groups. In a report published earlier today, Google said North Korean hackers used multiple profiles on various social networks, such as Twitter, LinkedIn, Telegram, Discord, and Keybase, to reach out to security researchers using fake personas. Email was also used in some instances, Google said. "After establishing initial communications, the actors would ask the targeted researcher if they wanted to collaborate on vulnerability research together, and then provide the researcher with a Visual Studio Project," said Adam Weidemann, a security researcher with Google TAG.
Firefox

Firefox 85 Hammers the Final Nail Into the Adobe Flash Coffin (cnet.com) 67

With Mozilla's release of Firefox 85 on Tuesday, Adobe's once ubiquitous Flash technology is really gone for good. The software had been widely used to expand gaming, video and animation on the web, though Adobe stopped supporting it at the end of 2020. Firefox was the last major browser to support Flash. From a report: Apple, whose late boss Steve Jobs helped sink Flash by banning it from iPhones and iPads, ditched Flash with Safari 14 in September 2020. Google Chrome, the most widely used browser, completely excised it on Jan. 19 with version 88. Microsoft's Edge 88 followed suit on Jan. 21. The schedule of removals shows just how hard it is to advance technology foundations as widely used as the web. Browser makers for years wanted to remove Flash, replacing it with more advanced standards built directly into the web. Jobs' "Thoughts on Flash" letter in 2010 solidified the opposition, and Adobe started recognizing the software's doom by scrapping the Android version of Flash in 2011. It's taken years of effort to drop Flash completely. Adobe took until 2017 to announce that Flash would be completely unsupported at the end of 2020, and still some are willing to jump through lots of hoops to keep Flash around a little longer.
Google

Google Says It May Have Found a Privacy-Friendly Substitute To Cookies (axios.com) 158

Google says its new machine learning algorithms could replace cookie-based ad targeting without invading your privacy. Axios reports: Google has been testing a new API (a software interface) called Federated Learning of Cohorts (FLoC) that acts as an effective replacement signal for third-party cookies. The API exists as a browser extension within Google Chrome. The company said Monday that tests of FLoC to reach audiences show that advertisers can expect to see at least 95% of the conversions per dollar spent on ads when compared to cookie-based advertising. FLoC uses machine learning algorithms to analyze user data and then create a group of thousands of people based off of the sites that an individual visits. The data gathered locally from the browser is never shared. Instead, the data from the much wider cohort of thousands of people is shared, and that is then used to target ads.

It's a big deal that Google says it's close to coming up with a technology that will replace cookies, because one of the toughest parts of phasing cookies out of internet ad-targeting is that there hasn't been a great solution for what to replace them with. [...] Google has other proposals to replace cookies in the works, so it's not guaranteed that FLoC will be the answer, but the company said it's highly encouraged by what it has seen so far.

Privacy

Hacker Leaks Data of 2.28 Million Dating Site Users 25

An anonymous reader quotes a report from ZDNet: A well-known hacker has leaked the details of more than 2.28 million users registered on MeetMindful.com, a dating website founded in 2014, ZDNet has learned this week from a security researcher. The dating site's data has been shared as a free download on a publicly accessible hacking forum known for its trade in hacked databases. The leaked data, a 1.2 GB file, appears to be a dump of the site's users database.

The content of this file includes a wealth of information that users provided when they set up profiles on the MeetMindful site and mobile apps. Some of the most sensitive data points included in the file include: Real names; Email addresses; City, state, and ZIP details; Body details; Dating preferences; Marital status; Birth dates; Latitude and longitude; IP addresses; Bcrypt-hashed account passwords; Facebook user IDs; and Facebook authentication tokens. Messages exchanged by users were not included in the leaked file; however, this does not make the entire incident less sensitive.
The data leak, which is still available for download, was released by a threat actor who goes by the name of ShinyHunters. They also were responsible for leaking the details of millions of users registered on Teespring.
IT

Browser Makers Launch New Project For Writing Documentation For Web APIs (zdnet.com) 13

A coalition of tech companies announced today the launch of Open Web Docs, a new initiative to help write documentation for Web APIs, JavaScript, and other web tooling and platforms. From a report: The new project does not view itself as a replacement for MDN Web Docs, a website hosted by Mozilla, where all browser makers agreed to move the official Web API documentation back in October 2017, and stop developing their own, often diverging, documentation sites. Instead, in a press release and FAQ today, the Open Web Docs team said their role is to fund, coordinate, and contribute to MDN Docs going forward. The new initiative comes after Mozilla laid off 250 employees last summer, including many of its MDN Web Docs staff. Open Web Docs comes to fill this void and provide the labor force needed to continue updating the MDN Web Docs portal.
Crime

Dutch COVID-19 Patient Data Sold on the Criminal Underground (zdnet.com) 9

Dutch police arrested two individuals late last week for allegedly selling data from the Dutch health ministry's COVID-19 systems on the criminal underground. From a report: The arrests came after an investigation by RTL Nieuws reporter Daniel Verlaan who discovered ads for Dutch citizen data online, advertised on instant messaging apps like Telegram, Snapchat, and Wickr. The ads consisted of photos of computer screens listing data of one or more Dutch citizens. The reporter said he tracked down the screengrabs to two IT systems used by the Dutch Municipal Health Service (GGD) -- namely CoronIT, which contains details about Dutch citizens who took a COVID-19 test, and HPzone Light, one of the DDG's contact-tracing systems. Verlaan said the data had been sold online for months for prices ranging from $36 to $60 per person. Buyers would receive details such as home addresses, emails, telephone numbers, dates of birth, and a person's BSN identifier (Dutch social security number).
United States

More Companies Are Joining 'Tech Exodus' From California (nbcnews.com) 258

This week Digital Reality data center services announced it was also relocating its headquarters from the San Francisco Bay Area to Texas, citing factors like a low cost of living and "supportive business climate". (Though it will still maintain a "significant" presence in the Bay Area.)

And Align Technology (makers of the Invisalign orthodontic dental aligners) also announced it had relocated its global corporate headquarters from San Jose, California to Tempe, Arizona, citing a "favorable corporate operating environment, low cost of living and overall quality of life."

NBC News writes that "while Silicon Valley is by no means ceasing to be the center of the technology industry," there's still an "undeniable migration" that's happening: Shervin Pishevar, a venture capitalist, bought a house in Miami Beach in 2018. In late 2020, Jonathan Oringer, who founded Shutterstock and became an investor, moved to Miami, as did other notable venture capitalists, including Keith Rabois and David Blumberg. It's not just Miami experiencing this migration. Last month, Oracle, the tech giant, announced it is moving its corporate headquarters from Redwood City, California, to Austin, Texas. Other such moves include Palantir, which decamped for Denver, while Elon Musk said last month he had moved himself to Austin. Hewlett Packard Enterprise also announced last month it was moving its headquarters from San Jose, California, in favor of a Houston suburb...

It's significant enough that while the San Francisco Bay Area continues to gain tech workers, the rate of increase is down by over 35 percent — the single largest drop of any tracked metropolitan area — according to self-reported data tracked by LinkedIn. Experts following this migration predict these numbers may grow. "There's a mini-exodus of tech companies leaving the Valley, and I think that's going to accelerate in 2021," said Dan Ives, a financial analyst with Wedbush Securities. But the reasons many businesses are moving are more complex than people may think. Tax experts say companies aren't moving their corporate headquarters necessarily for business tax incentives. Instead, it may be a long-term play to help them pay workers relatively less where the cost of living is lower... "You're going to always have the vast majority of tech companies coming out of the Valley, and you can't create that anywhere else," Ives said. "But when you look at an Austin: It's creating a mini Silicon Valley at half the cost for an average employee..."

Tax experts suspect Oracle and its peers may over time phase out higher-paid employees in California in favor of lower-paid employees in Texas. These companies can also ease off giving employees raises because they are living somewhere with a lower cost of living. "Even though a lot of companies are saying they can let people work from anywhere, most are saying we're not going to cut salary, but we're going to slow the rate of increase of salary," said Brian Kropp, an analyst with the IT service management company Gartner. Kropp said he spoke with high-level representatives from several "Fortune 200 type companies" who are exploring moving their corporate headquarters. In short, shifting employees from California to Texas could represent long-term corporate cost savings, which means larger payouts for these companies' top executives.

"The compounding effect translates to a 3 or 5 percent margin that moves straight to profit," Kropp said...

Kropp says some companies are also worried about the increase in state laws targeting businesses and executives. But there could be another culprit, argues Darien Shanske, a law professor at the University of California, Davis who NBC identiies as an expert on state and local taxation.

"California has blown it, but not because of tax policy — its decades-long problem of not producing enough housing," he said. "It's probably cheaper and easier to build that in Austin."
Government

Ransomware Attackers Try Publishing 4,000 Scottish Government Agency Files (threatpost.com) 34

Threatpost reports: On the heels of a ransomware attack against the Scottish Environmental Protection Agency (SEPA), attackers have now reportedly published more than 4,000 files stolen from the agency — including contracts and strategy documents.

After hitting SEPA on Christmas Eve with the attack, cybercriminals encrypted 1.2GB of information. The attack has affected SEPA's email systems, which remain offline as of Thursday, according to the agency. However, SEPA, which is Scotland's environmental regulator, stressed on Thursday that it will not "engage" with the cybercriminals. "We've been clear that we won't use public finance to pay serious and organized criminals intent on disrupting public services and extorting public funds," said SEPA chief executive Terry A'Hearn in a statement... SEPA's email and other systems remain down, and "what is now clear is that with infected systems isolated, recovery may take a significant period," according to the agency in its update. "A number of SEPA systems will remain badly affected for some time, with new systems required..."

The incident also points to ransomware actors evolving from previously destroying critical data or bringing companies' services and operations to a standstill, to now threatening to disclose sensitive data publicly, Joseph Carson, chief security scientist and Advisory CISO at Thycotic told Threatpost.

Security

How Law Enforcement Gets Around Your Smartphone's Encryption (arstechnica.com) 62

Long-time Slashdot reader SonicSpike shares a recent Wired.com article that purports to reveal "how law enforcement gets around your smartphone's encryption." Lawmakers and law enforcement agencies around the world, including in the United States, have increasingly called for backdoors in the encryption schemes that protect your data, arguing that national security is at stake. But new research indicates governments already have methods and tools that, for better or worse, let them access locked smartphones thanks to weaknesses in the security schemes of Android and iOS.

Cryptographers at Johns Hopkins University used publicly available documentation from Apple and Google as well as their own analysis to assess the robustness of Android and iOS encryption. They also studied more than a decade's worth of reports about which of these mobile security features law enforcement and criminals have previously bypassed, or can currently, using special hacking tools...

once you unlock your device the first time after reboot, lots of encryption keys start getting stored in quick access memory, even while the phone is locked. At this point an attacker could find and exploit certain types of security vulnerabilities in iOS to grab encryption keys that are accessible in memory and decrypt big chunks of data from the phone. Based on available reports about smartphone access tools, like those from the Israeli law enforcement contractor Cellebrite and US-based forensic access firm Grayshift, the researchers realized that this is how almost all smartphone access tools likely work right now. It's true that you need a specific type of operating system vulnerability to grab the keys — and both Apple and Google patch as many of those flaws as possible — but if you can find it, the keys are available, too...

Forensic tools exploiting the right vulnerability can grab even more decryption keys, and ultimately access even more data, on an Android phone.

The article notes the researchers shared their findings with the Android and iOS teams — who both pointed out the attacks require physical access to the target device (and that they're always patching vulnerabilities).
Bug

How DNSpooq Attacks Could Poison DNS Cache Records (zdnet.com) 9

Earlier this week security experts disclosed details on seven vulnerabilities impacting Dnsmasq, "a popular DNS software package that is commonly deployed in networking equipment, such as routers and access points," reports ZDNet. "The vulnerabilities tracked as DNSpooq, impact Dnsmasq, a DNS forwarding client for *NIX-based operating systems."

Slashdot reader Joe2020 shared Help Net Security's quote from Shlomi Oberman, CEO and researcher at JSOF. "Some of the bigger users of Dnsmasq are Android/Google, Comcast, Cisco, Red Hat, Netgear, and Ubiquiti, but there are many more. All major Linux distributions offer Dnsmasq as a package, but some use it more than others, e.g., in OpenWRT it is used a lot, Red Hat use it as part of their virtualization platforms, Google uses it for Android hotspots (and maybe other things), while, for example Ubuntu just has it as an optional package."

More from ZDNet: Dnsmasq is usually included inside the firmware of various networking devices to provide DNS forwarding capabilities by taking DNS requests made by local users, forwarding the request to an upstream DNS server, and then caching the results once they arrive, making the same results readily available for other clients without needing to make a new DNS query upstream. While their role seems banal and insignificant, they play a crucial role in accelerating internet speeds by avoiding recursive traffic...

Today, the DNSpooq software has made its way in millions of devices sold worldwide [including] all sorts of networking gear like routers, access points, firewalls, and VPNs from companies like ZTE, Aruba, Redhat, Belden, Ubiquiti, D-Link, Huawei, Linksys, Zyxel, Juniper, Netgear, HPE, IBM, Siemens, Xiaomi, and others. The DNSpooq vulnerabilities, disclosed today by security experts from JSOF, are dangerous because they can be combined to poison DNS cache entries recorded by Dnsmasq servers. Poisoning DNS cache records is a big problem for network administrators because it allows attackers to redirect users to clones of legitimate websites...

In total, seven DNSpooq vulnerabilities have been disclosed today. Four are buffer overflows in the Dnsmasq code that can lead to remote code execution scenarios, while the other three bugs allow DNS cache poisoning. On their own, the danger from each is limited, but researchers argue they can be combined to attack any device with older versions of the Dnsmasq software...

The JSOF exec told ZDNet that his company has worked with both the Dnsmasq project author and multiple industry partners to make sure patches were made available to device vendors by Tuesday's public disclosure.

Privacy

A Home Security Worker Hacked Into Surveillance Systems To Watch People Have Sex (gizmodo.com) 141

An anonymous reader quotes a report from Gizmodo: A former employee of prominent home security company ADT has admitted that he hacked into the surveillance feeds of dozens of customer homes, doing so primarily to spy on naked women or to leer at unsuspecting couples while they had sex. Telesforo Aviles, 35, pleaded guilty to a count of computer fraud in federal court this week, confessing that he inappropriately accessed the accounts of customers some 9,600 times over the course of several years. He is alleged to have done this to over 200 customers.

Authorities say that the IT technician "took note of which homes had attractive women, then repeatedly logged into these customers' accounts in order to view their footage for sexual gratification." He did this by adding his personal email address to customer accounts, which ultimately hooked him into "real-time access to the video feeds from their homes." Aviles, who now faces up to five years in prison, sometimes "claimed he needed to add himself temporarily in order to 'test' the system; in other instances, he added himself without their knowledge," officials said. "This defendant, entrusted with safeguarding customers' homes, instead intruded on their most intimate moments," acting U.S. Attorney Prerak Shah said in a statement. "We are glad to hold him accountable for this disgusting betrayal of trust."
The scandal has inspired multiple lawsuits -- three of which are ongoing. ADT tried using confidentiality agreements to keep some customers silent.

The company told BuzzFeed that it is "continuing to respond to the lawsuits and has resolved the concerns of most of the 220 impacted customers, including those who have retained attorneys to address the issue."
Bitcoin

As Bitcoin Price Surges, DDoS Extortion Gangs Return in Force (zdnet.com) 36

Extortion groups that send emails threatening companies with DDoS attacks unless paid a certain fee are making a comeback, security firm Radware warned today. From a report: In a security alert sent to its customers and shared with ZDNet this week, Radware said that during the last week of 2020 and the first week of 2021, its customers received a new wave of DDoS extortion emails. Extortionists threatened companies with crippling DDoS attacks unless they got paid between 5 and 10 bitcoins ($150,000 to $300,000).

Radware said that some of the emails it seen were sent by a group that was active over the 2020 summer when the extortionists targeted many financial organizations across the world. Companies that received this group's emails last summer also received new threats over the winter, Radware said. The security firm believes that the rise in the Bitcoin-to-USD price has led to some groups returning to or re-prioritizing DDoS extortion schemes.

Slashdot Top Deals