Security

Modern RAM Used For Computers, Smartphones Still Vulnerable To Rowhammer Attacks (zdnet.com) 32

An anonymous reader writes: According to new research published this week, modern RAM cards are still vulnerable to Rowhammer attacks despite extensive mitigations that have been deployed by manufacturers over the past six years. These mitigations, collectively referred to as Target Row Refresh (TRR), are a combination of software and hardware fixes that have been slowly added to the design of modern RAM cards after 2014 when academics disclosed the first-ever Rowhammer attack.

But in a new research paper titled today and titled "TRRespass: Exploiting the Many Sides of Target Row Refresh" a team of academics from universities in the Netherlands and Switzerland said they developed a generic tool named TRRespass that can be used to upgrade the old Rowhammer attacks to work on the new-and-improved TRR-protected RAM cards. The new upgraded attacks work on both DIMM and LPDDR4 memory types, and can be used to retrieve encryption keys from memory, or escalate an attacker's access right to sudo/SYSTEM-level.

Microsoft

Windows Has a New Wormable Vulnerability With No Patch Available (arstechnica.com) 68

A vulnerability in version 3.1.1 of the Server Message Block (SMB) -- the service that's used to share files, printers, and other resources on local networks and over the internet -- can allow attacks to execute code of their choice on both servers and end-user computers that use the vulnerable protocol, Microsoft said in an advisory. Ars Technica reports: The flaw, which is tracked as CVE-2020-0796, affects Windows 10, versions 1903 and 1909 and Windows Server versions 1903 and 1909, which are relatively new releases that Microsoft has invested huge amounts of resources hardening against precisely these types of attacks. Patches aren't available, and Tuesday's advisory gave no timeline for one being released. Asked if there was a timeline for releasing a fix, a Microsoft representative said, "Beyond the advisory you linked, nothing else to share from Microsoft at this time."

In the meantime, Microsoft said vulnerable servers can be protected by disabling compression to block unauthenticated attackers from exploiting the vulnerability against an SMBv3 server. Users can use the following PowerShell command to turn off compression without needing to reboot the machine: "Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force." That fix won't protect vulnerable client computers or servers if they connect to a malicious SMB service, but in that scenario, the attacks aren't wormable. Microsoft also recommended users block port 445, which is used to send SMB traffic between machines.

Encryption

Motherboard Built a Database of Over 500 iPhones Cops Have Tried To Unlock (vice.com) 16

"Motherboard built and analyzed a database of over 500 iPhones seized by law enforcement," writes Slashdot reader em1ly. "It's a deep dive into the ongoing "Going Dark" conversation." Here's an excerpt from the report: Most of all, the records compiled by Motherboard show that the capability to unlock iPhones is a fluid issue, with an ebb and flow of law enforcement sometimes being able to access devices and others not. The data solidifies that some law enforcement officials do have trouble accessing data stored on iPhones. But ultimately, our findings lead experts to circle back to the fundamental policy question: should law enforcement have guaranteed access to iPhones, with the trade-offs in iPhone security that come with that?

Out of 516 analyzed cases, 295 were marked as executed. Officials from the FBI, DEA, DHS, Homeland Security and Investigations, the Bureau of Alcohol, Tobacco, Firearms and Explosives were able to extract data from iPhones in investigations ranging from arson, to child exploitation, to drug trafficking. And investigators executed warrants against modern iPhones, not just older models. In some cases, investigators obtained photos, text messages, call records, browsing data, cookies, and location data from seized iPhones. Some executed search warrants explicitly mention the type of extraction performed, such as so-called "Logical" or "Advanced Logical" extraction. The latter is a term with a meaning that varies between different phone data extraction companies, but generally it relates to creating a device backup as iTunes does normally and obtaining some more data on top of that, Vladimir Katalov, the CEO of iOS forensics firm Elcomsoft, told Motherboard. Katalov said those backups can contain the sorts of pieces of data that investigators obtained, and is available to all models of iPhone.

Medicine

Engineer Who Attended RSA Cybersecurity Event Contracts Coronavirus (bloomberg.com) 62

An anonymous reader quotes a report from Bloomberg: Two cybersecurity company employees who attended an annual industry conference last month in San Francisco have tested positive for the coronavirus. At least one is seriously ill with respiratory issues. One of the workers at Exabeam Inc. is a 45-year-old engineer who began experiencing symptoms when he returned home to Connecticut from California on Feb. 28 after attending the RSA cybersecurity conference, his wife said in an email. His condition deteriorated the following week and he was hospitalized in respiratory distress on March 6, she said. The man was placed into a medically induced coma and is now on a ventilator in "guarded condition."

The individual is predisposed for pneumonia due to an underlying heart condition, his wife said. Bloomberg is withholding the man's name to protect his privacy. The second person, who is unidentified, also worked at Exabeam and attended RSA, the Foster City, California-based company said Tuesday in a statement. "While we cannot confirm whether they contracted COVID-19 prior to, at or after the conference, if you came into contact with our staff, please be vigilant in monitoring yourself for symptoms," Exabeam said. The company said it instituted a work-at-home policy for its offices in Foster City and Atlanta.

Google

Google Tells All North America Staff To Work From Home (bloomberg.com) 29

Alphabet's Google told its staff in North America to not go into their offices unless they have to, becoming one of the latest companies seeking to protect workers from the spreading coronavirus. From a report: The Mountain View, California-based tech giant is "recommending" workers stay home until at least April 10, according to an internal memo seen by Bloomberg. The company had already sent home its Seattle-area workers, where the virus has had the highest number of cases in the U.S.

The note also told contract workers, which make up as much as half of the company's overall workforce, to work from home if they were able. Google also said last week it would keep paying the thousands of hourly workers who do jobs such as serving food, cleaning offices and providing security, through the crisis.
Amazon, Twitter, Microsoft, and a slew of other major tech companies are also encouraging employees to work from home to prevent the spread of the virus.
Botnet

Microsoft Orchestrates Coordinated Takedown of Necurs Botnet (zdnet.com) 15

Microsoft announced today a coordinated takedown of Necurs, one of the largest spam and malware botnets known to date, believed to have infected more than nine million computers worldwide. From a report: The takedown effort came after Microsoft and industry partners broke the Necurs DGA -- the botnet's domain generation algorithm, the component that generates random domain names. Necurs authors register DHA-generated domains weeks or months in advance and host the botnet's command-and-control (C&C) servers, where bots (infected computers) connect to receive new commands. "We were then able to accurately predict over six million unique domains that would be created in the next 25 months," said Tom Burt, Microsoft Vice President for Customer Security & Trust. Breaking the DGA allowed Microsoft and its industry partners to create a comprehensive list of future Necurs C&C server domains that they can now block and prevent the Necurs team from registering.
Intel

Intel CPUs Vulnerable To New LVI Attacks (zdnet.com) 24

A team of academics from universities across the world, along with vulnerability researchers from Bitdefender, today disclosed a new security flaw in Intel processors. From a report: Named Load Value Injection, or LVI for short, this is a new class of theoretical attacks against Intel CPUs. While the attack has been deemed only a theoretical threat, Intel has released firmware patches to mitigate attacks against current CPUs, and fixes will be deployed at the hardware (silicon design) level in future generations.
Privacy

Spying Concerns Raised Over Iran's Official COVID-19 Detection App (zdnet.com) 8

Catalin Cimpanu, reporting for ZDNet: Google has removed an Android app from the official Play Store that was developed by the Iranian government to test and keep track of COVID-19 (coronavirus) infections. Before being removed from the Play Store, controversy surrounded the app, and several users accused the Iranian government of using the COVID-19 scare to trick citizens into installing the app and then collecting phone numbers and real-time geo-location data. In hindsight of accusations, ZDNet has asked Lukas Stefanko, an Android malware researcher at ESET, to review the app for any malicious or spyware-like behavior.

"Based on the analysis of the app's APK, the app is not a malicious Trojan or spyware," Stefanko told ZDNet earlier this week. A Google spokesperson did not respond to a request for comment on the reasons the app was removed; however, sources familiar with Play Store policies told ZDNet that the app was most likely taken down because of its misleading claims -- namely that it could detect COVID-19 infections, something that is impossible through an app.

Privacy

Popular VPN and Ad-Blocking Apps Are Secretly Harvesting User Data (buzzfeednews.com) 46

An anonymous reader quotes a report from BuzzFeed News: Sensor Tower, a popular analytics platform for tech developers and investors, has been secretly collecting data from millions of people who have installed popular VPN and ad-blocking apps for Android and iOS, a BuzzFeed News investigation has found. These apps, which don't disclose their connection to the company or reveal that they feed user data to Sensor Tower's products, have more than 35 million downloads. Since 2015, Sensor Tower has owned at least 20 Android and iOS apps. Four of these -- Free and Unlimited VPN, Luna VPN, Mobile Data, and Adblock Focus -- were recently available in the Google Play store. Adblock Focus and Luna VPN were in Apple's App Store. Apple removed Adblock Focus and Google removed Mobile Data after being contacted by BuzzFeed News. The companies said they continue to investigate.

Once installed, Sensor Tower's apps prompt users to install a root certificate, a small file that lets its issuer access all traffic and data passing through a phone. The company told BuzzFeed News it only collects anonymized usage and analytics data, which is integrated into its products. Sensor Tower's app intelligence platform is used by developers, venture capitalists, publishers, and others to track the popularity, usage trends, and revenue of apps.
Randy Nelson, Sensor Tower's head of mobile insights, said the company's apps do not collect sensitive data or personally identifiable information and that "the vast majority of these apps listed are now defunct (inactive) and a few are in the process of sunsetting." But, as BuzzFeed points out, most of the apps are no longer available "because they were removed due to policy violations."
Security

AMD Processors From 2011 To 2019 Vulnerable To Two New Attacks (zdnet.com) 71

An anonymous reader quotes a report from ZDNet: AMD processors manufactured between 2011 and 2019 (the time of testing) are vulnerable to two new attacks, research published this week has revealed (PDF). The two new attacks impact the security of the data processed inside the CPU and allow the theft of sensitive information or the downgrade of security features. The research team said it notified AMD of the two issues in August 2019, however, the company has not released microcode (CPU firmware) updates, claiming these "are not new speculation-based attacks," a statement that the research team disagrees with.

The two new attacks target a feature of AMD CPUs known as the L1D cache way predictor. Introduced in AMD processors in 2011 with the Bulldozer microarchitecture, the L1D cache way predictor is a performance-centric feature that reduces power consumption by improving the way the CPU handles cached data inside its memory. A high-level explanation is available below: "The predictor computes a uTag using an undocumented hash function on the virtual address. This uTag is used to look up the L1D cache way in a prediction table. Hence, the CPU has to compare the cache tag in only oneway instead of all possible ways, reducing the power consumption." The two new attacks were discovered after a team of six academics [...] reverse-engineered this "undocumented hashing function" that AMD processors were using to handle uTag entries inside the L1D cache way predictor mechanism. Knowing these functions, allowed the researchers to recreate a map of what was going on inside the L1D cache way predictor and probe if the mechanism was leaking data or clues about what that data may be.
While the attacks can be patched, AMD denies that these two new attacks are a concern, claiming they "are not new speculation-based attacks" and that they should be mitigated through previous patches for speculative execution side channel vulnerabilities.

The research team says AMD's response is "rather misleading," and that the attacks still work on fully-updated operating systems, firmware, and software even today.
Privacy

Brave Says it Will Generate Random Browser Fingerprints To Preserve User Privacy (zdnet.com) 38

The Brave browser is working on a feature that will randomize its "fingerprint" every time a user visits a website in an attempt to preserve the user's privacy. From a report: Brave's decision comes as online advertisers and analytics firms are moving away from tracking users via cookies to using fingerprints. [...] "The unfortunate truth about all these approaches is that, despite being well-intentioned, none of them are very effective in preventing fingerprinting," the Brave team said of other browser makers' approaches. "The enormous diversity of fingerprinting surface in modern browsers makes these 'block', 'lie' or 'permission' approaches somewhere between insufficient and useless, unfortunately," they added. "Brave's new approach aims to make every browser look completely unique, both between websites and between browsing sessions," Brave developers said.
Businesses

DuckDuckGo is Good Enough For Regular Use (bitlog.com) 79

Jake Voytko, who previously worked at Google, writing in a blog post: [...] Let's move away from Google's competitive advantages. How does DuckDuckGo perform for most of my search traffic? DuckDuckGo does a good job. I haven't found a reason to switch back to Google. I combed through my browser's history of DuckDuckGo searches. I compared it to my Google search history. When I fell back to Google, I often didn't find what I wanted on Google either. Most of my searches relate to my job, which means that most of my searches are technical queries. DuckDuckGo serves good results for my searches. I'll admit that I'm a paranoid searcher: I reformat error strings, remove identifiers that are unique to my code, and remove quotes before searching. I'm not sure how well DuckDuckGo would handle copy/pasted error strings with lots of quotes and unique identifiers. This means that I don't know if DuckDuckGo handles all technical searches well. But it does a good job for me.

There are many domains where Google outperforms DuckDuckGo. Product search and local search are some examples. I recently made a window plug. It was much easier to find which big-box hardware stores had the materials I need with Google. I also recently bought a pair of ANC headphones. I got much better comparison information starting at Google. Google also shines with sparse results like rare programming error messages. If you're a programmer, you know what I'm talking about: imagine a Google search page with three results. One is a page in Chinese that has the English error string, one is a forum post that gives you the first hint that you need to solve the problem, and one is the error string in the original source code in Github. DuckDuckGo often returns nothing for these kinds of searches. Even though Google is better for some specific domains, I am confident that DuckDuckGo can find what I need. When it doesn't, Google often doesn't help either.

Chrome

DoNotPay Now Lets You Share Online Subscriptions Without Divulging Your Password (venturebeat.com) 37

DoNotPay, the digital lawyer that shot to prominence for its bot that helps drivers appeal parking tickets, has launched a new product aimed at consumers. With the DoNotPay Subscription Sharing Chrome extension, anyone can share access to their online accounts -- like Spotify, Netflix, Disney+ -- without divulging their password. From a report: To use the service, you need to install the DoNotPay Chrome extension, after which you'll be prompted to verify yourself by entering your mobile number and submitting an access code that is sent by SMS. Then, whenever you're logged into a website that you would like to share, such as Netflix or Spotify, you can tap the little DoNotPay icon at the top of the browser and then hit Generate Link. You'll be able to copy a link to share or enter a recipient's email address and push the Send Invite button. The recipient also needs to install the Chrome extension and verify themselves through DoNotPay, as this enables the sender to maintain control over who has access.

The account owner is able to revoke access at any time Joshua Browder, founder of DoNotPay, said there are no hard limits in terms of how many people you can share a link with. However, it's worth noting that many services automatically restrict the number of devices that can stream content simultaneously. [...] In terms of the underlying technology, DoNotPay effectively enables the secure transfer of a logged-in session by encrypting cookies for the website that is being shared.

IT

Are Virtual Conferences Better Than Real-World Conferences? (fastcompany.com) 44

Fast Company's Mark Sullivan argues that cancelling this year's tech conferences could have a silver lining -- by encouraging a movement toward virtual conferences: There are developers across the U.S. and around the world who get shut out when the conferences get sold out. Even more of them simply can't afford the admission fee (last year's WWDC was $1599) and travel expenses required to spend time in the Bay Area or Seattle. Apple uses a lottery system to pick registered developers at random, who then get the opportunity to buy a ticket for the event. "Not having a set of 5,000 people who paid to be there, and potentially millions of other people who don't get access to things exclusive to those attending, such as labs and all of the networking, but instead having everyone on the same level can be a good thing," says iOS developer Guilherme Rambo.

Even before the coronavirus came along, the major developer conferences were developing more robust online elements. Far more people stream the keynotes than watch them in person. Many conference now stream the developer sessions as well. And an increasing body of sessions from the events is archived online... With all the cancellations this year, big tech companies like Apple may get some time to really think about the value of big events in the age of live streaming. Apple, for one, might think about ways of further virtualizing WWDC.

Google

Google Could Have Fixed 2FA Code-Stealing Flaw in Authenticator App Years Ago (zdnet.com) 30

An anonymous reader shares a report: Last month, a cybersecurity firm discovered the first-ever Android malware that came with the capability to steal the 2FA (two-factor authentication) codes generated by the Google Authenticator app. The malware, discovered by researchers from ThreatFabric, was named Cerberus, and its 2FA OTP code-stealing feature was still under development, yet to have been detected in a real-world attack. According to researchers, the malware was a hybrid between a banking trojan and a remote access trojan (RAT).

Once an Android user got infected, the hacker would use the malware's banking trojan features to steal credentials for mobile banking apps. If an account was protected by 2FA, and namely by the Google Authenticator app, the malware was designed to allow the Cerberus gang to connect to a user's device manually, via its RAT features. Hackers would then open the Authenticator app, generate one-time passcodes, take a screenshot of the codes, and then access the user's account. [...] Nightwatch researchers said that Google could have fixed this issue as early as October 2014, when this misconfiguration was first brought to its attention by someone on GitHub.

Security

99.9% of Compromised Accounts Did Not Use Multi-Factor Authentication, Says Microsoft (zdnet.com) 30

Speaking at the RSA security conference last week, Microsoft engineers said that 99.9% of the compromised accounts they track every month don't use multi-factor authentication, a solution that stops most automated account attacks. From a report: The cloud giant said it tracks more than 30 billion login events per day and more than one billion monthly active users. Microsoft said that, on average, around 0.5% of all accounts get compromised each month, a number that in January 2020 was about 1.2 million. While all account hacks are bad, they are worse when the account is for enterprise use. Of these highly-sensitive accounts, only 11% had a multi-factor authentication (MFA) solution enabled, as of January 2020, Microsoft said. In most cases, the account hacks happen after rather simplistic attacks. The primary sources of most hacks of Microsoft accounts was password spraying, a technique during which an attacker picks a common and easy-to-guess password, and goes through a long list of usernames until they get a hit and can access an account using said password.
Android

Hack Turns Apple's iPhone Into An Android (forbes.com) 99

Ten years ago, David Wang pulled off a remarkable trick, installing Android on the first-generation iPhone. Now Wang and his colleagues at cybersecurity startup Corellium are doing it again with the ostentatiously titled Project Sandcastle. From a report: And Forbes got an exclusive hands-on look at their Android for iPhone product ahead of its public release scheduled for later this Wednesday. The timing is sure to have Apple fanboys rubbernecking: Corellium is in the middle of being sued by Apple. As previously reported by Forbes, in August last year, Corellium was taken to court over Apple claims the startup breached copyright laws by creating software versions of the iPhone for security and testing. The case took a surprise turn late last month when Apple subpoenaed Spanish banking giant Santander and the $50 billion U.S. military and intelligence contractor L3Harris.

But Corellium has lofty ambitions for Project Sandcastle, saying that it'll actually show how Apple's walled garden, which it has fiercely protected since launching its flagship phone in 2007, can be deconstructed and taken over by others' software. "Project Sandcastle is about having fun building something new from the sand -- from the literal silicon of the hardware," said Corellium CEO Amanda Gorton, in a statement sent to Forbes. "Apple restricts iPhone users to operate inside a sandbox, but users own that hardware, and they should be able to use that hardware the way they want. So where sandboxes create limits and boundaries on the hardware that users own, sandcastles provide an opportunity to create something new and wonderful from the limitless bounds of your imagination."

Encryption

The EARN IT Act is an Attack on Encryption (cryptographyengineering.com) 176

A bipartisan pair of US senators on Thursday introduced long-rumored legislation known as the EARN IT Act. The bill is meant to combat child sexual exploitation online, but if passed, it could hurt encryption as we know it. Matthew Green, a cryptographer and professor at Johns Hopkins University, writes: Because the Department of Justice has largely failed in its mission to convince the public that tech firms should stop using end-to-end encryption, it's decided to try a different tack. Instead of demanding that tech firms provide access to messages only in serious criminal circumstances and with a warrant, the DoJ and backers in Congress have decided to leverage concern around the distribution of child pornography, also known as child sexual abuse material, or CSAM. [...] End-to-end encryption systems make CSAM scanning more challenging: this is because photo scanning systems are essentially a form of mass surveillance -- one that's deployed for a good cause -- and end-to-end encryption is explicitly designed to prevent mass surveillance. So photo scanning while also allowing encryption is a fundamentally hard problem, one that providers don't yet know how to solve.

All of this brings us to EARN IT. The new bill, out of Lindsey Graham's Judiciary committee, is designed to force providers to either solve the encryption-while-scanning problem, or stop using encryption entirely. And given that we don't yet know how to solve the problem -- and the techniques to do it are basically at the research stage of R&D -- it's likely that "stop using encryption" is really the preferred goal. EARN IT works by revoking a type of liability called Section 230 that makes it possible for providers to operate on the Internet, by preventing the provider for being held responsible for what their customers do on a platform like Facebook. The new bill would make it financially impossible for providers like WhatsApp and Apple to operate services unless they conduct "best practices" for scanning their systems for CSAM. Since there are no "best practices" in existence, and the techniques for doing this while preserving privacy are completely unknown, the bill creates a government-appointed committee that will tell technology providers what technology they have to use. The specific nature of the committee is byzantine and described within the bill itself. Needless to say, the makeup of the committee, which can include as few as zero data security experts, ensures that end-to-end encryption will almost certainly not be considered a best practice.

AI

Before Clearview Became a Police Tool, It Was a Secret Plaything of the Rich (nytimes.com) 66

Investors and clients of the facial recognition start-up freely used the app on dates and at parties -- and to spy on the public. From a report: One Tuesday night in October 2018, John Catsimatidis, the billionaire owner of the Gristedes grocery store chain, was having dinner at Cipriani, an upscale Italian restaurant in Manhattan's SoHo neighborhood, when his daughter, Andrea, walked in. She was on a date with a man Mr. Catsimatidis didn't recognize. After the couple sat down at another table, Mr. Catsimatidis asked a waiter to go over and take a photo. Mr. Catsimatidis then uploaded the picture to a facial recognition app, Clearview AI, on his phone. The start-up behind the app has a database of billions of photos, scraped from sites such as Facebook, Twitter and LinkedIn. Within seconds, Mr. Catsimatidis was viewing a collection of photos of the mystery man, along with the web addresses where they appeared: His daughter's date was a venture capitalist from San Francisco.. Ms. Catsimatidis said she and her date had no idea how her father had identified him so quickly.

Clearview was unknown to the general public until this January, when The New York Times reported that the secretive start-up had developed a breakthrough facial recognition system that was in use by hundreds of law enforcement agencies. The company quickly faced a backlash on multiple fronts. Facebook, Google and other tech giants sent cease-and-desist letters. Lawsuits were filed in Illinois and Virginia, and the attorney general of New Jersey issued a moratorium against the app in that state. [...] The Times, however, has identified multiple individuals with active access to Clearview's technology who are not law enforcement officials. And for more than a year before the company became the subject of public scrutiny, the app had been freely used in the wild by the company's investors, clients and friends.

Slashdot Top Deals