Education

How Should Students Respond To Their School's Surveillance Systems? (gizmodo.com.au) 138

Hundreds of thousands of American students are being tracked by their colleges to monitor attendance, analyze behavior and assess their mental health, the Washington Post reported this week. That article has now provoked some responses...

Jay Balan, chief security researcher at Bitdefender, told Gizmodo that the makers of the student-tracking apps should at least offer bug bounties and disclose their source code -- while rattling off easily foreseeable scenarios like the stalking of students. Gizmodo notes one app's privacy policy actually allows them to "collect or infer" students' approximate location -- even when students have turned off location tracking -- and allows third parties to "set and access their own tracking technologies on your devices."

And cypherpunk Lance R. Vick tweeted in response to the article, "If you are at one of these schools asking you to install apps on your phone to track you, hit me up for some totally hypothetical academic ideas..."

Gizmodo took him up on his offer -- and here's a bit of what he said: Students could reverse engineer the app to develop their own app beacon emulators to tell the tracking beacons that all students are present all the time. They could also perhaps deploy their own rogue tracking beacons to publish the anonymised attendance data for all students to show which teachers are the most boring as evidenced by lack of attendance. If one was hypothetically in an area without laws against harmful radio interference (like outside the U.S.) they could use one of many devices on the market to disrupt all Bluetooth communications in a target area so no one gets tracked... If nothing else, you could potentially just find a call in the API that takes a bit longer to come back than the rest. This tells you it takes some amount of processing on their side. What happens if you run that call a thousand times a second? Or only call it partway over and over again? This often brings poorly designed web services to a halt very quickly...

Assuming explorations on the endpoints like the phone app or beacon firmware fail you could still potentially learn useful information exploring the wireless traffic itself using popular SDR tools like a HackRF, Ubertooth, BladeRF. Here you potentially see how often they transmit, what lives in each packet, and how you might convert your own devices, perhaps a Raspberry Pi with a USB Bluetooth dongle, to be a beacon of your own.

Anyone doing this sort of thing should check their local and federal laws and approach it with caution. But these exact sorts of situations can, for some, be the start of a different type of education path -- a path into security research. Bypassing annoying digital restrictions at colleges was a part of how I got my start, so maybe a new generation can do similar. :)

Gizmodo calls his remarks "hypothetical hacking that you (a student with a bright future who doesn't want any trouble) should probably not do because you might be breaking the law."

But then how should students respond to their school's surveillance systems?
The Courts

Amazon, Ring Face Class-Action Lawsuit Over Alleged Security Camera Hacks 35

Alabama resident John Orange has filed a class-action lawsuit accusing Amazon and Ring of failing to do enough to secure their security systems against hacks, including Orange's. Engadget reports: He alleged that a stranger compromised his Ring outdoor camera and spooked his kids as a "direct and proximate" result of the company's inability to protect its devices "against cyber-attack." He pointed to other incidents to support the argument for a class action, including a highly publicized event in December where a remote intruder harassed a Mississippi girl.

Orange also claimed that Ring's response was evidence of the company blaming customers. It told Orange that there was "no evidence" someone had hacked the firm's infrastructure, and that his incident may be the result of a breach at a "non-Ring service" where the perpetrators reused info to sign into Ring accounts. In other words, Ring couldn't help it if people reused passwords with sites and services it can't control. The suit formally levels accusations of breach of contract, invasion of privacy, negligence, unjust enrichment and violating California's Unfair Competition Law (through misleading representations of security). If it achieves class action status, it would ask Amazon and Ring to compensate victims and implement "improved security procedures and measures."
Science

Information Teleported Between Two Computer Chips For the First Time (newatlas.com) 185

Michael Irving, writing for New Atlas: Scientists at the University of Bristol and the Technical University of Denmark have achieved quantum teleportation between two computer chips for the first time. The team managed to send information from one chip to another instantly without them being physically or electronically connected, in a feat that opens the door for quantum computers and quantum internet. This kind of teleportation is made possible by a phenomenon called quantum entanglement, where two particles become so entwined with each other that they can "communicate" over long distances. Changing the properties of one particle will cause the other to instantly change too, no matter how much space separates the two of them. In essence, information is being teleported between them.

Hypothetically, there's no limit to the distance over which quantum teleportation can operate -- and that raises some strange implications that puzzled even Einstein himself. Our current understanding of physics says that nothing can travel faster than the speed of light, and yet, with quantum teleportation, information appears to break that speed limit. Einstein dubbed it "spooky action at a distance." Harnessing this phenomenon could clearly be beneficial, and the new study helps bring that closer to reality. The team generated pairs of entangled photons on the chips, and then made a quantum measurement of one. This observation changes the state of the photon, and those changes are then instantly applied to the partner photon in the other chip.

Transportation

Mazda3 Bug Activates Emergency Brake System For No Reason (engadget.com) 55

Mazda says "incorrect programming" in its Smart Braking System (SBS) can make fourth-generation Mazda 3 vehicles falsely detect on object in their path while driving and automatically apply the brakes while driving. "The problem affects 35,390 2019 and 2020 model year cars in the U.S., but Mazda says it is not aware of any injuries or deaths as a result of the defect," reports Engadget. From the report: If the issue occurs, the driver will notice because their car has suddenly stopped, and also as an alarm sounds and a message is displayed on the in-car warning screen. Some Reddit posters report experiencing situations of the system activating while driving with nothing around, and note that while the system can be disabled, it appears to re-enable itself every time the car starts.

Autoblog reports that while some vehicles will simply need to have the system updated or reprogrammed, certain cars with early build dates might need to have their entire instrument cluster replaced or reprogrammed. It's a scary issue, but we've seen Mazda update its cars software to deal with real-life bugs, and the newly-redesigned Mazda3 has already seen a recall to make sure its wheels don't fall off.

Privacy

Ring's Security Woes Cause Some Tech Review Sites To Rethink Glowing Endorsements (gizmodo.com) 38

At least two tech review sites are discussing whether to rescind their positive recommendations of Ring's home surveillance cameras, a leading digital-rights organization announced this week. From a report: In the wake of reporting by Gizmodo and other outlets this year concerning Ring's troubled security and privacy practices, Fight for the Future has launched a campaign calling on tech review sites, such as Consumer Reports and PC Magazine, to suspend recommending Ring products. "Tech reviews and guides play an important role in people deciding which devices to buy," said Evan Greer, deputy director of Fight for the Future. [...] Last week, the tech review site Wirecutter announced it was suspending its recommendation of Ring products citing a report about a data leak by BuzzFeed's Caroline Haskins. This prompted Fight for the Future to contact other review sites and ask them to rescind their recommendations as well.
Chrome

Google Chrome Impacted By New Magellan 2.0 Vulnerabilities (zdnet.com) 25

An anonymous reader quotes a report from ZDNet: A new set of SQLite vulnerabilities can allow attackers to remotely run malicious code inside Google Chrome, the world's most popular web browser. The vulnerabilities, five, in total, are named "Magellan 2.0," and were disclosed today by the Tencent Blade security team. All apps that use an SQLite database are vulnerable to Magellan 2.0; however, the danger of "remote exploitation" is smaller than the one in Chrome, where a feature called the WebSQL API exposes Chrome users to remote attacks, by default.

Just like the original Magellan vulnerabilities, these new variations are caused by improper input validation in SQL commands the SQLite database receives from a third-party. An attacker can craft an SQL operation that contains malicious code. When the SQLite database engine reads this SQLite operation, it can perform commands on behalf of the attacker. In a security advisory published today, the Tencent Blade team says the Magellan 2.0 flaws can lead to "remote code execution, leaking program memory or causing program crashes." All apps that use an SQLite database to store data are vulnerable, although, the vector for "remote attacks over the internet" is not exploitable by default. To be exploitable, the app must allow direct input of raw SQL commands, something that very few apps allow.
Thankfully, Google patched all five Magellan 2.0 vulnerabilities in Google Chrome 79.0.3945.79, released two weeks ago.

The SQLite project also fixed the bugs in a series of patches on December 13, 2019; however, these fixes have not been included in a stable SQLite branch -- which remains v3.30.1, released on December 10.
Bug

A Twitter App Bug Was Used To Match 17 Million Phone Numbers To User Accounts (techcrunch.com) 5

Security researcher Ibrahim Balic said he has matched 17 million phone numbers to Twitter user accounts by exploiting a flaw in Twitter's Android app. TechCrunch reports: Ibrahim Balic found that it was possible to upload entire lists of generated phone numbers through Twitter's contacts upload feature. "If you upload your phone number, it fetches user data in return," he told TechCrunch. He said Twitter's contact upload feature doesn't accept lists of phone numbers in sequential format -- likely as a way to prevent this kind of matching. Instead, he generated more than two billion phone numbers, one after the other, then randomized the numbers, and uploaded them to Twitter through the Android app. (Balic said the bug did not exist in the web-based upload feature.)

Over a two-month period, Balic said he matched records from users in Israel, Turkey, Iran, Greece, Armenia, France and Germany, he said, but stopped after Twitter blocked the effort on December 20. Balic provided TechCrunch with a sample of the phone numbers he matched. Using the site's password reset feature, we verified his findings by comparing a random selection of usernames with the phone numbers that were provided. While he did not alert Twitter to the vulnerability, he took many of the phone numbers of high-profile Twitter users -- including politicians and officials -- to a WhatsApp group in an effort to warn users directly.
A Twitter spokesperson told TechCrunch the company was working to "ensure this bug cannot be exploited again."

"Upon learning of this bug, we suspended the accounts used to inappropriately access people's personal information. Protecting the privacy and safety of the people who use Twitter is our number one priority and we remain focused on rapidly stopping spam and abuse originating from use of Twitter's APIs," the spokesperson said.
Crime

IT Worker With Grudge Jailed (bbc.com) 31

A former Jet2 IT contractor with a grudge has been jailed for a cyber-attack on the company. From a report: Scott Burns, 27, of Queen Street in Morley, Leeds, was jailed for 10 months for his actions, which cost the company $214,000. The attack shut down Jet2's computer network for 12 hours in January 2018. Burns wanted revenge for the firm's treatment of him following an incident at a 2017 "Benidorm roadshow," Leeds Crown Court heard. Details about happened at the event in Benidorm were not outlined in court. The court heard only fast-thinking by one employee at the Leeds-based airline stopped Burns' actions being a "complete disaster" for Jet2. Burns pleaded guilty to eight counts under the Computer Misuse Act at a previous hearing. Judge Andrew Stubbs QC told Burns: "You intended to cause as much damage to Jet2's computer system as you could. "This went far beyond being mischievous. This was a revenge attack for a perceived slight you had suffered."
Security

No, Spotify, You Shouldn't Have Sent Mysterious USB Drives To Journalists (techcrunch.com) 53

Zack Whittaker, writing for TechCrunch: Last week, Spotify sent a number of USB drives to reporters with a note: "Play me." It's not uncommon for reporters to receive USB drives in the post. Companies distribute USB drives all the time, including at tech conferences, often containing promotional materials or large files, such as videos that would otherwise be difficult to get into as many hands as possible. But anyone with basic security training under their hat will know to never plug in a USB drive without taking some precautions first.

Concerned but undeterred, we safely examined the contents of the drive using a disposable version of Ubuntu Linux (using a live CD) on a spare computer. We examined the drive and found it was benign. On the drive was a single audio file. "This is Alex Goldman, and you've just been hacked," the file played. The drive was just a promotion for a new Spotify podcast. Because of course it was. Jake Williams, a former NSA hacker and founder of Rendition Infosec, called the move "amazingly tone deaf" to encourage reporters into plugging in the drives to their computers.

China

Chinese Hacker Group Caught Bypassing 2FA (zdnet.com) 27

Security researchers say they found evidence that a Chinese government-linked hacking group has been bypassing two-factor authentication (2FA) in a recent wave of attacks. From a report: The attacks have been attributed to a group the cyber-security industry is tracking as APT20, believed to operate on the behest of the Beijing government, Dutch cyber-security firm Fox-IT said in a report published last week. The group's primary targets were government entities and managed service providers (MSPs). The government entities and MSPs were active in fields like aviation, healthcare, finance, insurance, energy, and even something as niche as gambling and physical locks.

The Fox-IT report comes to fill in a gap in the group's history. APT20's hacking goes back to 2011, but researchers lost track of the group's operations in 2016-2017, when they changed their mode of operation. Fox-IT's report documents what the group has been doing over the past two years and how they've been doing it. According to researchers, the hackers used web servers as the initial point of entry into a target's systems, with a particular focus on JBoss, an enterprise application platform often found in large corporate and government networks.

The Internet

DNS Over HTTPS: Not As Private As Some Think? (sans.edu) 83

Long-time Slashdot reader UnderAttack writes: DNS over HTTPS has been hailed as part of a "poor mans VPN". Its use of HTTPS to send DNS queries makes it much more difficult to detect and block the use of the protocol.

But there are some kinks in the armor. Current clients, and most current DoH services, do not implement the optional passing option, which is necessary to obscure the length of the requested hostname. The length of the hostname can also be used to restrict which site a user may have access [to].

The Internet Storm Center is offering some data to show how this can be done.

Their article is by Johannes B. Ullrich, Ph.D. and Dean of Research at the SANS Technology Institute.

It notes that Firefox "seems to be the most solid DoH implementation. Firefox DoH queries look like any other Firefox HTTP2 connection except for the packet size I observed." And an open Firefox bug already notes that "With the availability of encrypted DNS transports in Firefox traffic analysis mitigations like padding are becoming relevant."
Security

'We Tested Ring's Security. It's Awful' (vice.com) 48

"Ring lacks basic security features, making it easy for hackers to turn the company's cameras against its customers," reports Motherboard: Ring is not offering basic security precautions, such as double-checking whether someone logging in from an unknown IP address is the legitimate user, or providing a way to see how many users are currently logged in -- entirely common security measures across a wealth of online services... Ring doesn't appear to check a user's chosen password against known compromised user credentials. Although not a widespread practice, more online services are starting to include features that will alert a user if they're using an already compromised password....

Motherboard deliberately entered the wrong password to our account on the login portal while connecting from the Tor anonymity network dozens of times in quick succession. At no point did Ring try to limit our login attempts or present a captcha....

Ring does offer two-factor authentication, where a user is required to enter a second code sent to them as well as their password, but Ring does not force customers to use it. Motherboard verified that Ring's two-factor authentication does work as advertised, but multiple people who were logged into the app didn't have to log back in after it was enabled -- Ring didn't eject them nor ask them to enter a two-factor token...

From a smartphone app, someone who is logged in can watch live and historical footage, listen through the camera's microphone, speak through the camera's speaker, play an alarm, see the name of the specific Wi-Fi network the camera is connected to, see the address the user originally registered the Ring camera with, see the phone number a user has entered into the app, and see nearby crime "incidents." This shows the specific, user-selected home address plotted on a map. Ring requires that a user input a home address to set up the camera.

Privacy

Wawa Announces Data Breach Potentially Affecting More Than 850 Stores (6abc.com) 30

Wawa, a convenience store and gas station chain, notified customers Thursday of a data breach (Warning: source may be paywalled; alternative source) that collected debit and credit card information at potentially all of its more than 850 locations along the East Coast. It is now offering free credit monitoring and identity theft protection to those affected. The New York Times reports: Malware was discovered on Wawa payment processing servers on Dec. 10; it was blocked and contained by Dec. 12, the company said, adding that the malware no longer posed a risk to customers using cards to pay. Customer information including credit and debit card numbers, expiration dates and cardholder names on payment cards used in store and at fuel pumps was being collected as early as March 4, the company said. A.T.M.s inside stores were not affected. Debit card PINs, credit card security code numbers and driver's license information were also not part of the breach, the company said, adding that it was not aware of any unauthorized use of any payment card information because of the breach. After learning of the breach, Wawa initiated an investigation, notified law enforcement and payment card companies, the company said, adding that it had brought on board an external forensics firm for support. The company, which is based in Pennsylvania, established a dedicated call center to answer questions. "Today, I am very sorry to share with you that Wawa has experienced a data security incident," Chris Gheysens, Wawa's chief executive, said in a letter. Customers will not be responsible for any fraudulent charges on cards related to the data breach, he said. "I apologize deeply to all of you, our friends and neighbors, for this incident. You are my top priority and are critically important to all of the nearly 37,000 associates at Wawa."
Security

Over 267 Million Facebook Users Reportedly Had Data Exposed Online (engadget.com) 17

More than 267 million Facebook users allegedly had their user IDs, phone numbers and names exposed online, according to a report from Comparitech and security researcher Bob Diachenko. From a report: That info was found in a database that could be accessed without a password or any other authentication, and the researchers believe it was gathered as part of an illegal scraping operation or Facebook API abuse. Dianchenko says he reported the database to the service provider managing the IP address of the server, but the database was exposed for nearly two weeks. In the meantime, he says, the data was posted as a download in a hacker forum. That's a lot of personal data to be floating around in the wild, and as Comparitech notes, it could be used to carry out phishing scams and other foul play.
Bug

Apple Opens Public Bug Bounty Program, Publishes Official Rules (zdnet.com) 10

Apple has formally opened its bug bounty program today to all security researchers, after announcing the move earlier this year in August at the Black Hat security conference in Las Vegas. From a report: Until today, Apple ran an invitation-based bug bounty program for selected security researchers only and was accepting only iOS security bugs. Starting today, the company will accept vulnerability reports for a much wider spectrum of products that also includes as iPadOS, macOS, tvOS, watchOS, and iCloud. In addition, the company has also increased its maximum bug bounty reward from $200,000 to $1,500,000, depending on the exploit chain's complexity and severity.
The Courts

Contractor Admits Planting Logic Bombs In His Software To Ensure He'd Get New Work (arstechnica.com) 117

An anonymous reader quotes a report from Ars Technica: Many IT workers worry their positions will become obsolete as changes in hardware, software, and computing tasks outstrip their skills. A former contractor for Siemens concocted a remedy for that -- plant logic bombs in projects he designed that caused them to periodically malfunction. Then wait for a call to come fix things. On Monday, David A. Tinley, a 62-year-old from Harrison City, Pennsylvania, was sentenced to six months in prison and a fine of $7,500 in the scheme. The sentence came five months after he pleaded guilty to a charge of intentional damage to a protected computer. Tinley was a contract employee for Siemens Corporation at its Monroeville, Pennsylvania, location.

According to a charging document filed in U.S. District Court for the Western District of Pennsylvania, the logic bombs Tinley surreptitiously planted into his projects caused them to malfunction after a certain preset amount of time. Because Siemens managers were unaware of the logic bombs and didn't know the cause of the malfunctions, they would call Tinley and ask him to fix the misbehaving projects. The scheme ran from 2014 to 2016. Tinley will be under supervised release for two years following his prison term. He will also pay restitution. The parties in the case stipulated a total loss amount of $42,262.50. Tinley faced as much as 10 years in prison and a $250,000 fine.

Security

A Data Leak Exposed the Personal Info of Over 3,000 Ring Users (buzzfeednews.com) 40

The log-in credentials for 3,672 Ring camera owners were compromised this week, exposing log-in emails, passwords, time zones, and the names people give to specific Ring cameras, which are often the same as camera locations, such as "bedroom" or "front door." BuzzFeed News reports: Using the log-in email and password, an intruder could access a Ring customer's home address, telephone number, and payment information, including the kind of card they have, and its last four digits and security code. An intruder could also access live camera footage from all active Ring cameras associated with an account, as well as a 30- to 60-day video history, depending on the user's cloud storage plan. We don't know how this tranche of customer information was leaked. Ring denies any claims that the data was compromised as a part of a breach of Ring's systems. A Ring spokesperson declined to tell BuzzFeed News when it became aware of the leak or whether it affected a third party that Ring uses to provide its services.

Security experts told BuzzFeed News that the format of the leaked data -- which includes username, password, camera name, and time zone in a standardized format -- suggests it was taken from a company database. They said data obtained via credential stuffing -- when previously-compromised emails and passwords are used to get access to other accounts -- would likely not display Ring-specific data like camera names or time zone. BuzzFeed News was alerted to the leak by a security researcher, who claimed he used a web crawler to search the internet for any data leaks pertaining to Ring accounts. The security researcher found the list of compromised credentials posted anonymously on a text storage site.
"Ring has not had a data breach. Our security team has investigated these incidents and we have no evidence of an unauthorized intrusion or compromise of Ring's systems or network," a Ring spokesperson said. "It is not uncommon for bad actors to harvest data from other company's data breaches and create lists like this so that other bad actors can attempt to gain access to other services."
Facebook

Facebook Won't Use 2FA Numbers To Suggest Friends Anymore (inputmag.com) 20

Facebook won't use the phone numbers some users give it for two-factor authentication for its "people you may know" feature. From a report: The social network says the move is "part of a wide-ranging overhaul of its privacy practices." It previously used phone numbers to serve ads too but says it stopped doing that in June. Two-factor authentication is a great way to reduce the risk of accounts being compromised, so giving users reasons to avoid using it is vile, even by Facebook's admittedly low standards. When news broke last year that Facebook was misusing phone numbers in that way it was met with appropriate opprobrium from the media and privacy advocates.
Books

Judge Rules Edward Snowden Can't Profit From His Book (gizmodo.com) 104

A federal judge in Virginia ruled Tuesday that whistleblower Edward Snowden will not be allowed to profit from sales of his memoir Permanent Record. The reason? He didn't receive approval from the CIA and NSA. Gizmodo reports: Permanent Record, which was released in September, tells the story of Snowden's decision to become a whistleblower and expose the ways that the U.S. government was spying on Americans in the late 2000s and early 2010s. Snowden fled the U.S. in 2013 after several new stories were written based on documents he leaked and now lives in Moscow, Russia.

Snowden didn't seek approval from the national security agencies where he had signed secrecy agreements before publication, and while the government didn't move to stop the book from being published, it does want any money he makes from the endeavor. Snowden's U.S.-based publishers, MacMillan and Holtzbrinck, are also named in the lawsuit. "Snowden's publication of Permanent Record without prior submission for prepublication review breached the CIA and NSA Secrecy agreement and the attendant fiduciary duties set forth in those agreements," federal judge Liam O'Grady wrote in his 14-page decision. "According to government filings, Snowden signed three Secrecy Agreements with the CIA in November of 2005, August of 2006, and April of 2009. He also signed three NSA Secrecy Agreements in July of 2005, May of 2009, and March of 2013. All of those agreements were unambiguous, according to the judge, and required Snowden to get a prepublication review before the book came out.
"During each of [Snowden's public talks via video link at a TED conference and various universities], Snowden caused to be displayed and discussed, among other things, at least one slide which was marked classified at the Top Secret level, and other intelligence-related activities of the CIA and NSA," the judge wrote. "He never submitted any materials or slides to the CIA or NSA for prepublication review, and never received written authority to make his public remarks or publish his slides."

It's unclear if Snowden will appeal the ruling.
It's funny.  Laugh.

More than 38,000 People Will Stand in Line this Week To Get a New Password (zdnet.com) 46

A non-standard and somewhat weird password reset operation is currently underway at a German university, where more than 38,000 students and staff were asked this week to stand in line with their ID card and a piece of paper to receive new passwords for their email accounts. From a report: All of this is going on at the Justus Liebig University (JLU) in Gieben, a town north of Frankfurt, Germany. The university suffered a malware infection last week. While the name or the nature of the malware strain was not disclosed, the university's IT staff considered the infection severe enough to take down its entire IT and server infrastructure. The university's network has been down since December 8, and all computers have been isolated and disconnected from each other. For the past days, IT staff have used antivirus scanners loaded on more than 1,200 USB flash drives to scan each JLU computer for malware.

Slashdot Top Deals