Security

Charges Dropped Against Pentesters Paid To Break Into Iowa Courthouse (arstechnica.com) 37

Prosecutors have dropped criminal charges against two security professionals who were arrested and jailed last September for breaking into an Iowa courthouse as part of a contract with Iowa's judicial arm. From a report: The dismissal, which was announced on Thursday, is a victory not only for Coalfire Labs, the security firm that employed the two penetration testers, but the security industry as a whole and the countless organizations that rely on it. Although employees Gary DeMercurio and Justin Wynn had written authorization to test the physical security of the Dallas County Courthouse in Iowa, the men spent more than 12 hours in jail on felony third-degree burglary charges. The charges were later lowered to misdemeanor trespass. The case cast a menacing cloud over an age-old practice that's crucial to securing buildings and the computers and networks inside of them. Penetration testers are hired to hack or break into sensitive systems or premises and then disclose the vulnerabilities and techniques that made the breaches possible. Owners and operators then use the information to improve security. "I'm very glad to hear this," said a professional pentester when I told him the charges were dropped (he prefers to use only his handle: Tink). "Clients and security firms have an obligation to protect their pentesters and consultants. Pentesters are not criminals. Pentesters help organizations protect against criminals."
United States

FBI Probes Use of Israeli Firm's Spyware In Personal and Government Hacks (reuters.com) 18

nickwinlund77 shares a report from Reuters: The FBI is investigating the role of Israeli spyware vendor NSO Group Technologies in possible hacks on American residents and companies as well as suspected intelligence gathering on governments, according to four people familiar with the inquiry. The probe was underway by 2017, when Federal Bureau of Investigation officials were trying to learn whether NSO obtained from American hackers any of the code it needed to infect smartphones, said one person interviewed by the FBI then and again last year.

The FBI conducted more interviews with technology industry experts after Facebook filed a lawsuit in October accusing NSO itself of exploiting a flaw in Facebook's WhatsApp messaging service to hack 1,400 users, according to two people who spoke with agents or Justice Department officials. Part of the FBI probe has been aimed at understanding NSO's business operations and the technical assistance it offers customers, according to two sources familiar with the inquiry. Suppliers of hacking tools could be prosecuted under the Computer Fraud and Abuse Act (CFAA) or the Wiretap Act, if they had enough knowledge of or involvement in improper use, said James Baker, general counsel at the FBI until January 2018. The CFAA criminalizes unauthorized access to a computer or computer network, and the Wiretap Act prohibits use of a tool to intercept calls, texts or emails. NSO is known in the cybersecurity world for its "Pegasus" software other tools that can be delivered in several ways. The software can capture everything on a phone, including the plain text of encrypted messages, and commandeer it to record audio."

E3

E3 Organizer Says It's Tightened Security After Accidentally Doxxing Thousands of Attendees (theverge.com) 8

The Electronic Software Association is introducing tighter security measures around press registration for E3, following an incident last year in which sensitive personal information belonging to thousands of journalists, YouTube creators, and Twitch streamers was made public. The Verge reports: A new blog post published today details updates to the conference and its "media registration process," which the company says "received a lot of attention this past summer." "Earning back your trust and support is our top priority," the post reads. "That's why we rebuilt the E3 website with enhanced and layered security measures developed by an outside cybersecurity firm. This included updating our data management processes, including the handling of personally identifiable information, and we will no longer store that data on our site."

Changes to the registration process will also occur this year. The ESA will "collect the minimum information necessary" for attendees registering. The post doesn't state what those specific changes are. Last year's leak, which involved an unprotected file uploaded online and available for anyone to download, led to personal information like home addresses and phone numbers appearing on hateful forums like Kiwi Farms. After data leaked, multiple journalists -- including staff members of The Verge -- received texts and phone calls from complete strangers.

Communications

Feds Order Massive Number Of Tech Giants To Help Hunt Down One WhatsApp Meth Dealer (forbes.com) 53

As it struggles to get content from encrypted messenger apps and smartphones, the U.S. government is getting creative in how it tracks down criminal WhatsApp users, according to a search warrant uncovered by Forbes. From the report: Aside from shedding light on police data-trawling operations, these new efforts are "problematic," legal experts tell Forbes. They show that investigators are willing to test the boundaries of legality by demanding content they may not legally be allowed to collect from WhatsApp. And they're then demanding data from a seemingly endless list of tech providers -- from Google to any telecom company imaginable -- that could feasibly help them catch a single WhatsApp user.

In a bid to find an alleged Mexican methamphetamine dealer, the government demanded that WhatsApp hand over basic subscriber details, according to a previously unreported government order filed in Colorado in October. They'd been tipped off that the dealer -- a fugitive on the DEA's most-wanted list -- was a frequent user of WhatsApp and had even used the app to talk with an undercover agent. That WhatsApp data would come from what's known as a "pen-trap." Think of these as tracking tools that collect limited metadata like user phone numbers, IP addresses and call duration, not the content of messages. Forbes has reported on these before and they're fairly common. So far, so normal.

Privacy

Breach at Indian Airline SpiceJet Affects 1.2 Million Passengers (techcrunch.com) 13

SpiceJet, one of India's largest privately owned airlines, suffered a data breach involving the details of more than a million of its passengers, a security researcher told TechCrunch. From the report: The security researcher, who described their actions as "ethical hacking" but whom we are not naming as they likely fell afoul of U.S. computer hacking laws, gained access to one of SpiceJet's systems by brute-forcing the system's easily guessable password. An unencrypted database backup file on that system contained private information of more than 1.2 million passengers of the budget-carrier last month, TechCrunch has learned. Each record included details such as name of the passenger, their phone number, email address and their date of birth, the researcher told TechCrunch. Some of these passengers were state officials, they said. The database included a rolling month's worth of flight information and details of each commuter, they said, adding that they believe that the database was easily accessible for anyone who knew where to look.
Security

Apple Wants To Standardize the Format of SMS OTPs (One-Time Passcodes) (zdnet.com) 125

Apple engineers have put forward a proposal today to standardize the format of the SMS messages containing one-time passcodes (OTP) that users receive during the two-factor authentication (2FA) login process. From a report: The proposal comes from Apple engineers working on WebKit, the core component of the Safari web browser. The proposal has two goals. The first is to introduce a way that OTP SMS messages can be associated with an URL. This is done by adding the login URL inside the SMS itself. The second goal is to standardize the format of 2FA/OTP SMS messages, so browsers and other mobile apps can easily detect the incoming SMS, recognize web domain inside the message, and then automatically extract the OTP code and complete the login operation without further user interaction. By doing this, the process of receiving and entering a one-time passcode could be automated, eliminating the risk of a user falling for a scam and entering an OTP code on a phishing site, with the wrong URL.
Security

New Web Service Can Notify Companies When Their Employees Get Phished (zdnet.com) 18

Starting today, companies across the world have a new free web service at their disposal that will automatically send out email notifications if one of their employees gets phished. From a report: The service is named "I Got Phished" and is managed by Abuse.ch, a non-profit organization known for its malware and cyber-crime tracking operations. Just like all other Abuse.ch services, I Got Phished will be free to use. Any company can sign-up via the I Got Phished website. Signing up only takes a few seconds. Subscribing for email notifications is done on a domain name basis, and companies don't have to expose a list of their employee email addresses to a third-party service. Once a company's security staff has subscribed to the service, I Got Phished will check its internal database for email addresses for the company's email domain. This database contains logs from phishing operations, with emails for phished victims.
Security

Avast Closes Jumpshot Over Data Privacy Backlash (venturebeat.com) 15

Antivirus software giant Avast has announced that it will wind down one of its subsidiary businesses just days after leaked documents revealed the extent to which the Czech company was selling users' browsing data to third parties. From a report: On Monday, Vice and PCMag published details about how Avast had been collating browsing data covering web properties such as Google Maps and Search, LinkedIn, and YouTube and then repackaging it for sale under a subsidiary called Jumpshot, which has claimed clients such as Google, Microsoft, Yelp, Pepsi, Home Depot, and Conde Nast. Although the data was not thought to contain any personally identifiable information, it is often possible to "de-anonymize" data by combining and aligning it with different data sets to unearth shared patterns. Jumpshot was founded back in 2010 but officially launched from a Kickstarter-funded project in 2012. In its original guise, Jumpshot offered a PC-based software that promised to rid machines of viruses, spyware, and the like, and the company was eventually bought by Avast.
Security

Department of Interior Grounds Its Drones Amid Cybersecurity Concerns (techcrunch.com) 29

An anonymous reader quotes a report from TechCrunch: The U.S. Department of the Interior has confirmed it has grounded its fleet of non-emergency drones amid concerns over cybersecurity. In a brief statement, the department said the move will help to ensure that "the technology used for these operations is such that it will not compromise our national security interests." Interior spokesperson Carol Danko said the department affirms with a formal order the "temporary cessation of non-emergency drones while we ensure that cybersecurity, technology and domestic production concerns are adequately addressed," months after the department said it was grounding its approximately 800 drones. But the drones will still be used for emergency purposes, such as search and rescue and assisting with natural disasters, the statement said.

The order did not specifically mention threats from China, but said that information collected during drone missions "has the potential to be valuable to foreign entities, organizations, and governments." Danko told TechCrunch that the department currently has 121 drones made by DJI and 665 drones that are Chinese-built but not made by DJI. She added that 24 drones are made in the U.S. but have Chinese components. "The review is to help us identify and assess any potential threats or risks," said Danko.

United Kingdom

Why the UK is Banning Default Passwords in IoT Devices (newstatesman.com) 74

Matt Warman, the minister for digital and broadband in the UK, writes: From washing machines and children's toys to personal assistants, we are increasingly seeing more of our daily lives connected to the internet. In fact, research suggests by 2025 there will be 75 billion internet connected devices in homes around the world. However, the current security standards of many of these devices are low and the security and privacy risks are too great. Last week, for example, the usernames and for more 500,000 devices including Internet of Things (IoT) products were made available online.

Our aim is to make the UK the world's leading digital economy. But if we are to achieve this ambition we need to make sure people trust technology. I believe we can do this through pro-innovation regulation. So today I've announced we are developing new legislation to hold firms manufacturing and stocking internet-connected devices to account to stop hackers threatening people's privacy and safety. These new laws will mean consumers are protected from devices which do not adhere to the three rigorous security requirements we've developed alongside a code of conduct. These measures will mean all the passwords pre-programmed in internet-connected devices must be unique and not resettable to any universal factory setting.

Privacy

Apple Has a Putin Problem (fastcompany.com) 162

harrymcc writes: New legislation in Russia -- known as the 'law against Apple' -- mandates that smartphone makers must preinstall government apps that will give authorities access to an array of information about the phone's user. Apple, not surprisingly, is trying to wriggle its way out of complying. But whatever happens, it's another case of an authoritarian government pushing around a U.S. tech company for very un-democratic reasons. Over at Fast Company, Josh Nadeau reports on the issue and why the stakes are so high.
Security

Leaked Report Shows United Nations Suffered Hack (seattletimes.com) 32

Sophisticated hackers infiltrated U.N. offices in Geneva and Vienna last year in an apparent espionage operation, and their identity and the extent of the data they obtained is unknown. From a report: An internal confidential document from the United Nations, leaked to The New Humanitarian and seen by The Associated Press, says dozens of servers were compromised including at the U.N. human rights office, which collects sensitive data and has often been a lightning rod of criticism from autocratic governments for exposing rights abuses. Asked about the report, one U.N. official told the AP that the hack appeared "sophisticated" and that the extent of the damage remained unclear, especially in terms of personal, secret or compromising information that may have been stolen. The official, who spoke only on condition of anonymity to speak freely about the episode, said systems have since been reinforced. The skill level was so high it is possible a state-backed actor might have been behind it, the official said.

"It's as if someone were walking in the sand, and swept up their tracks with a broom afterward," the official said. "There's not even a trace of a clean-up." The leaked Sept. 20 report says logs that would have betrayed the hackers' activities inside the U.N. networks -- what was accessed and what may have been siphoned out -- were "cleared." It also shows that among accounts known to have been accessed were those of domain administrators -- who by default have master access to all user accounts in their purview. "Sadly ... still counting our casualties," the report says.

Security

Google Has Paid Security Researchers Over $21 Million for Bug Bounties, $6.5 Million in 2019 Alone (venturebeat.com) 18

An anonymous reader shares a report: Google has paid out over $21 million since launching its bug bounty program in November 2010. In the past year alone, the company distributed $6.5 million to 461 different security researchers, almost double the previous record set in 2018: $3.4 million to 317 different security researchers. Bug bounty programs motivate individuals and hacker groups to not only find flaws but disclose them properly, instead of using them maliciously or selling them to parties that will. Rewarding security researchers with bounties costs peanuts compared to paying for a serious security snafu.
China

Germany Has Proof That Huawei Worked With Chinese Intelligence: Handelsblatt (reuters.com) 172

The German government is in possession of evidence that Huawei, the leading maker of telecoms network equipment, has collaborated with Chinese intelligence, the Handelsblatt daily reported on Wednesday. Reuters: "At the end of 2019, intelligence was passed to us by the U.S., according to which Huawei is proven to have been cooperating with China's security authorities," the newspaper quoted a confidential foreign ministry document as saying. Chancellor Angela Merkel's government and her conservative ruling party are split on whether Huawei's equipment poses a security threat to Europe's largest economy, where the three mobile network operators are all customers of the Chinese firm.
Security

7 Years Later, Emergency Alert Systems Still Unpatched, Vulnerable (securityledger.com) 24

chicksdaddy writes: The Security Ledger is reporting that more than 50 Emergency Alert System (EAS) devices made by Monroe Electronics (now Digital Alert Systems) are un-patched and accessible from the public Internet, seven years after security researchers alerted the public about security flaws in the devices. More than 50 EAS deployments across the United States still use a shared SSH key, a security vulnerability first discovered and reported by IOActive in 2013, according to a warning posted by the security researcher Shawn Merdinger on January 19, seven years after the initial vulnerability report was issued.

Security Ledger viewed the exposed web interfaces for Monroe/Digital Alerts Systems EAS hardware used by two FM broadcasters in Texas and an exposed EAS belonging to a broadband cable provider in North Carolina. Also publicly accessible: EAS systems for two stations (FM and AM) serving the Island of Hawaii. Residents there received a false EAS alert about an incoming ICBM in 2018. That incident was found to be the result of human error but prompted the FCC to issue new guidance about securing EAS systems. Digital Alert Systems said it is aware of the problem and is contacting the customers whose gear is exposed. However, a search using the Shodan search engine suggests that few have taken steps to remove their EAS systems from the public Internet in the past week. Security Ledger is withholding the names of the broadcasters whose EAS systems were exposed for security reasons. None of the stations contacted for the story was able to provide comment prior to publication.

Security

Wawa Breach May Have Compromised More Than 30 Million Payment Cards (krebsonsecurity.com) 20

An anonymous reader quotes a report from Krebs on Security: In late December 2019, fuel and convenience store chain Wawa said a nine-month-long breach of its payment card processing systems may have led to the theft of card data from customers who visited any of its 850 locations nationwide. Now, fraud experts say the first batch of card data stolen from Wawa customers is being sold at one of the underground's most popular crime shops, which claims to have 30 million records to peddle from a new nationwide breach.

On the evening of Monday, Jan. 27, a popular fraud bazaar known as Joker's Stash began selling card data from "a new huge nationwide breach" that purportedly includes more than 30 million card accounts issued by thousands of financial institutions across 40+ U.S. states. Two sources that work closely with financial institutions nationwide tell KrebsOnSecurity the new batch of cards that went on sale Monday evening -- dubbed "BIGBADABOOM-III" by Joker's Stash -- map squarely back to cardholder purchases at Wawa. A spokesperson for Wawa confirmed that the company today became aware of reports of criminal attempts to sell some customer payment card information potentially involved in the data security incident announced by Wawa on December 19, 2019.
"We have alerted our payment card processor, payment card brands, and card issuers to heighten fraud monitoring activities to help further protect any customer information," Wawa said in a statement released to KrebsOnSecurity. "We continue to work closely with federal law enforcement in connection with their ongoing investigation to determine the scope of the disclosure of Wawa-specific customer payment card data."

"We continue to encourage our customers to remain vigilant in reviewing charges on their payment card statements and to promptly report any unauthorized use to the bank or financial institution that issued their payment card by calling the number on the back of the card," the statement continues. "Under federal law and card company rules, customers who notify their payment card issuer in a timely manner of fraudulent charges will not be responsible for those charges. In the unlikely event any individual customer who has promptly notified their card issuer of fraudulent charges related to this incident is not reimbursed, Wawa will work with them to reimburse them for those charges."
Privacy

LabCorp Security Lapse Exposed Thousands of Medical Documents (techcrunch.com) 15

A security flaw in LabCorp's website exposed thousands of medical documents, like test results containing sensitive health data. From a report: It's the second incident in the past year after LabCorp said in June that 7.7 million patients had been affected by a credit card data breach of a third-party payments processor. The breach also hit several other laboratory testing companies, including Quest Diagnostics. This latest security lapse was caused by a vulnerability on a part of LabCorp's website, understood to host the company's internal customer relationship management system. Although the system appeared to be protected with a password, the part of the website designed to pull patient files from the back-end system was left exposed. That unprotected web address was visible to search engines and was later cached by Google, making it accessible to anyone who knew where to look. The cached search result only returned one document -- a document containing a patient's health information. But changing and incrementing the document number in the web address made it possible to access other documents. The bug is now fixed.
China

DEF CON China Conference Put on Hold Due To Coronavirus Outbreak (zdnet.com) 19

The organizers of the DEF CON cyber-security conference have announced today that they are putting this year's China edition "on hold" due to the ongoing Wuhan coronavirus (2019-nCoV) outbreak. From a report: "China has announced a six-month hold on events like ours as part of the effort to combat the coronavirus outbreak," the DEF CON team said in a forum post today. DEF CON is one of the Top 3 most prestigious cyber-security conferences today. The conference is held each year in Las Vegas, in the month of August. The Chinese edition of the DEF CON conference, which would have reached its second edition this year, was set to take place in Beijing between April 17 and April 19. Organizers said they are currently putting the DEF CON China 2.0 conference on hold, but have not officially canceled the event.
United Kingdom

Huawei Allowed Limited Access To UK's 5G Networks as Britain Defies US Pressure (cnbc.com) 86

Britain will allow Chinese telecommunications giant Huawei to play a limited role in its next generation 5G mobile networks. From a report: The U.K. government said that Huawei will be restricted from being involved in "sensitive functions" in a network of features labeled as "core." There is also a limit in place on how much equipment networks can buy from one "high risk vendor" for a particular part of the infrastructure known as the Radio Access Network (RAN.) This is essentially the part of the network that hooks up your devices with the actual 5G signal. That cap is set at 35%. "The cap at 35% ensures the U.K. will not become nationally dependent on a high risk vendor while retaining competition in the market and allowing operators to continue to use two Radio Access Network (RAN) vendors," the U.K.'s National Cyber Security Centre said in its review of the country's telecommunications supply chain on Tuesday.
Government

Maryland Bill Would Outlaw Ransomware, Keep Researchers From Reporting Bugs (arstechnica.com) 85

A proposed law introduced in Maryland's state senate last week would criminalize the possession of ransomware and other criminal activities with a computer. However, CEO of Luta Security Katie Moussouris warns that the current bill "would prohibit vulnerability disclosure unless the specific systems or data accessed by the helpful security researcher were explicitly authorized ahead of time and would prohibit public disclosure if the reports were ignored." Ars Technica reports: The bill, Senate Bill 3, covers a lot of ground already covered by U.S. Federal law. But it classifies the mere possession of ransomware as a misdemeanor punishable by up to 10 years of imprisonment and a fine of up to $10,000. The bill also states (in all capital letters in the draft) that "THIS PARAGRAPH DOES NOT APPLY TO THE USE OF RANSOMWARE FOR RESEARCH PURPOSES."

Additionally, the bill would outlaw unauthorized intentional access or attempts to access "all or part of a computer network, computer control language, computer, computer software, computer system, computer service, or computer database; or copy, attempt to copy, possess, or attempt to possess the contents of all or part of a computer database accessed." It also would criminalize under Maryland law any act intended to "cause the malfunction or interrupt the operation of all or any part" of a network, the computers on it, or their software and data, or "possess, identify, or attempt to identify a valid access code; or publicize or distribute a valid access code to an unauthorized person." There are no research exclusions in the bill for these provisions.
"While access or attempted access would be a misdemeanor (punishable by a fine of $1,000, three years of imprisonment, or both), breaching databases would be a felony if damages were determined to be greater than $10,000 -- punishable by a sentence of up to 10 years, a fine of $10,000, or both," the report adds. "The punishments go up if systems belonging to the state government, electric and gas utilities, or public utilities are involved, with up to 10 years of imprisonment and a $25,000 fine if more than $50,000 in damage is done."

Slashdot Top Deals