Security

Popular VPN Service NordVPN Says it Was Hacked 44

NordVPN, a virtual private network provider that promises to "protect your privacy online," has confirmed it was hacked. From a report: The admission comes following rumors that the company had been breached. It first emerged that NordVPN had an expired internal private keys exposed, potentially allowing anyone to spin out their own servers imitating NordVPN. For its part, NordVPN has claimed a "zero logs" policy. "We don't track, collect, or share your private data," the company says. But the breach is likely to cause alarm that hackers may have been in a position to access some user data. NordVPN told TechCrunch that one of its datacenters was accessed in March 2018. "One of the datacenters in Finland we are renting our servers from was accessed with no authorization," said NordVPN spokesperson Laura Tyrell. The attacker gained access to the server -- which had been active for about a month -- by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed.
Privacy

Researchers Tricked Google Home and Alexa Into Eavesdropping and Password Phishing (arstechnica.com) 34

What if Google and Amazon employees weren't the only ones who'd listened through your voice assistant? Ars Technica reports: The threat isn't just theoretical. Whitehat hackers at Germany's Security Research Labs developed eight apps -- four Alexa "skills" and four Google Home "actions" -- that all passed Amazon or Google security-vetting processes. The skills or actions posed as simple apps for checking horoscopes, with the exception of one, which masqueraded as a random-number generator. Behind the scenes, these "smart spies," as the researchers call them, surreptitiously eavesdropped on users and phished for their passwords...

The apps gave the impression they were no longer running when they, in fact, silently waited for the next phase of the attack.... The apps quietly logged all conversations within earshot of the device and sent a copy to a developer-designated server. The phishing apps follow a slightly different path by responding with an error message that claims the skill or action isn't available in that user's country. They then go silent to give the impression the app is no longer running. After about a minute, the apps use a voice that mimics the ones used by Alexa and Google home to falsely claim a device update is available and prompts the user for a password for it to be installed....

In response, both companies removed the apps and said they are changing their approval processes to prevent skills and actions from having similar capabilities in the future.

Security

WAV Audio Files Are Now Being Used To Hide Malicious Code (zdnet.com) 16

JustAnotherOldGuy quotes ZDNet: Two reports published in the last few months show that malware operators are experimenting with using WAV audio files to hide malicious code.

The first of these new malware campaigns abusing WAV files was reported back in June by Symantec security researchers who said they spotted a Russian cyber-espionage group known as Waterbug (or Turla) using WAV files to hide and transfer malicious code from their server to already-infected victims. The second malware campaign was spotted this month by BlackBerry Cylance. In a report published today and shared with ZDNet last week, Cylance said it saw something similar to what Symantec saw a few months before. But while the Symantec report described a nation-state cyber-espionage operation, Cylance said they saw the WAV steganography technique being abused in a run-of-the-mill crypto-mining malware operation.

Google

Google Criticized After Voice From 'Nest' Camera Threatens to Steal Baby (siliconvalley.com) 125

Jack Newcombe, the Chief Operating Officer of a syndication company with 44 million daily readers, describes the strange voice he heard talking to his 18-month old son: She says we have a nice house and encourages the nanny to respond. She does not. The voice even jokes that she hopes we don't change our password. I am sick to my stomach. After about five minutes of verbal "joy riding," the voice starts to get agitated at the nanny's lack of response and then snaps, in a very threatening voice: "I'm coming for the baby if you don't answer me...." We unplug the cameras and change all passwords...

Still helpless, I started doing the only thing I could do -- Googling. I typed "Nest + camera + hacked" and found out that this happens frequently. Parent after parent relayed stories similar to mine -- threatening to steal a baby is shockingly common -- and some much worse, such as playing pornography over the microphone to a 3-year-old... What is worse is that anyone could have been watching us at any time for as long as we have had the cameras up. This person just happened to use the microphone. Countless voyeurs could have been silently watching (or worse) for months.

However, what makes this issue even more terrifying is a corporate giant's complete and utter lack of response. Nest is owned by Google, and, based on my experience and their public response, Google does not seem to care about this issue. They acknowledge it as a problem, shrug their shoulders and point their fingers at the users. Their party line is to remind people that the hardware was not hacked; it was the user's fault for using a compromised password and not implementing two-step authentication, in which users receive a special code via text to sign on. That night, on my way home from work, I called Nest support and was on hold for an hour and eight minutes. I followed all directions and have subsequently received form emails in broken English. Nobody from Google has acknowledged the incident or responded with any semblance of empathy. In every email, they remind me of two-step authentication.

They act as if I am going to continue to use Nest cameras.

Government

Russian Cyber-Espionage Group Controlled Its Malware Partly Through Reddit Posts (bleepingcomputer.com) 18

"Cyber-espionage operations from Cozy Bear, a threat actor believed to work for the Russian government, continued undetected for the past years by using malware families previously unknown to security researchers," reports BleepingComputer -- citing a surprisingly detailed report: Relying on stealthy communication techniques between infected systems and the command and control servers, the group managed to keep their activity under the radar for a long time. Cyber-espionage campaigns that likely started in 2013, collectively named "Operation Ghost," have been attributed to this group, and continued through 2019...

Researchers at ESET tracking this threat actor found at least three victims of Operation Ghost, all being European Ministries of Foreign Affairs including the Washington DC embassy of a European Union country. The victim count is likely larger but identifying them is difficult because the threat actor uses unique command and control infrastructure for each target.

The report notes the group used sites like Reddit, Twitter, and Imgur to deliver the URLs for some command-and-control servers, along with information hidden in images. And another stage of its malware platform used an even more robust site for its command-and-control server: Dropbox.
Cloud

Would You Trust Amazon To Run Free and Fair Elections? (reuters.com) 80

More than 40 of America's 50 states now use Amazon's technology infrastructure for their elections, according to this Reuters article shared by joeblog. And so do both of America's political parties:

While it does not handle voting on election day, AWS -- along with a broad network of partners -- now runs state and county election websites, stores voter registration rolls and ballot data, facilitates overseas voting by military personnel and helps provide live election-night results, according to company documents and interviews... Amazon pitches itself as a low-cost provider of secure election technology at a time when local officials and political campaigns are under intense pressure to prevent a repeat of 2016 presidential elections, which saw cyber-attacks on voting systems and election infrastructure....

Most security experts Reuters spoke to said that while Amazon's cloud is likely much harder to hack than systems it is replacing, putting data from many jurisdictions on a single system raises the prospect that a single major breach could prove damaging. "It makes Amazon a bigger target" for hackers, "and also increases the challenge of dealing with an insider attack," said Chris Vickery, director of cyber risk research at cybersecurity startup Upguard. A recent hack into Capital One Financial Corp's data stored on Amazon's cloud service was perpetrated by a former Amazon employee. The breach affected more than 100 million customers, underscoring how rogue employees or untrained workers can create security risks even if the underlying systems are secure...

Vickery uncovered at least three instances where voter data on Amazon's cloud servers was exposed to the internet, which have been reported previously. For example, in 2017, he found a Republican contractor's database for nearly every registered American voter hosted on AWS exposed on the internet for 12 days. In 2016, he found Mexico's entire voter database on AWS servers was leaked. Amazon said the breaches were caused by customer errors, adding that while AWS secures the cloud infrastructure, customers are responsible for security of what goes in the cloud.

Bug

Unpatched Linux Bug May Open Devices To Serious Attacks Over Wi-Fi (arstechnica.com) 21

Long-time Slashdot reader Kekke shared this article from Ars Technica: A potentially serious vulnerability in Linux may make it possible for nearby devices to use Wi-Fi signals to crash or fully compromise vulnerable machines, a security researcher said.

The flaw is located in the RTLWIFI driver, which is used to support Realtek Wi-Fi chips in Linux devices. The vulnerability triggers a buffer overflow in the Linux kernel when a machine with a Realtek Wi-Fi chip is within radio range of a malicious device. At a minimum, exploits would cause an operating-system crash and could possibly allow a hacker to gain complete control of the computer. The flaw dates back to version 3.10.1 of the Linux kernel released in 2013...

The vulnerability is tracked as CVE-2019-17666. Linux developers proposed a fix on Wednesday that will likely be incorporated into the OS kernel in the coming days or weeks. Only after that will the fix make its way into various Linux distributions.

Nico Waisman, who is a principal security engineer at Github [and discovered the bug] said he has not yet devised a proof-of-concept attack that exploits the vulnerability in a way that can execute malicious code on a vulnerable machine. "I'm still working on exploitation, and it will definitely... take some time (of course, it might not be possible)," he wrote in a direct message. "On paper, [this] is an overflow that should be exploitable. Worst-case scenario, [this] is a denial of service; best scenario, you get a shell."

The article notes that the flaw "can't be triggered if Wi-Fi is turned off or if the device uses a Wi-Fi chip from a different manufacturer."
Bug

Apple Hid a Lightning Connector For Debugging In the Apple TV 4K's Ethernet Port (9to5mac.com) 60

Twitter user Kevin Bradley discovered a Lightning port hidden in the Apple TV 4K's ethernet port. There's a number of theories for why the port exists, but one of the more logical explanations is that it's simply there for Apple to use for debugging. 9to5Mac reports: While earlier Apple TV models had Micro USB and USB-C, the Apple TV 4K dropped all outwardly-facing ports other than Ethernet and HDMI. Under the hood, however, there's a hidden Lightning port, as Bradley discovered. The Lightning port is hidden in the ethernet connector on the Apple TV 4K. Bradley teased on Twitter: "None of us looked THAT closely to the hardware of the AppleTV 4K and the magic locked in the ethernet port until fairly recently."

As for getting the Lightning port itself to work, Steven Barker said in a tweet that this is proving to be "difficult." The Lightning port is stuck at the very back of the ethernet port. Ultimately, it's not really clear what the Lightning port discovery could mean. One thing it could lead towards is the expansion of jailbreak capabilities for the Apple TV 4K, though Bradley cautions: "Just because we know it's lightning doesn't mean anything past that. Just because we find a way in doesn't mean anything will DEFINITELY be released due to what we discover. The barrier for entry might be way too high."

The Military

Air Force Finally Retires 8-Inch Floppies From Missile Launch Control System (arstechnica.com) 77

Five years after CBS publicized the fact that the Air Force still used eight-inch floppy disks to store data critical to operating the Air Force's intercontinental ballistic missile command, the aerial and space warfare service branch decided it was time to officially retire them. Ars Technica reports: The system, once called the Strategic Air Command Digital Network (SACDIN), relied on IBM Series/1 computers installed by the Air Force at Minuteman II missile sites in the 1960s and 1970s. Despite the contention by the Air Force at the time of the 60 Minutes report that the archaic hardware offered a cybersecurity advantage, the service has completed an upgrade to what is now known as the Strategic Automated Command and Control System (SACCS), as Defense News reports. SAACS is an upgrade that swaps the floppy disk system for what Lt. Col. Jason Rossi, commander of the Air Force's 595th Strategic Communications Squadron, described as a "highly secure solid state digital storage solution." The floppy drives were fully retired in June.

But the IBM Series/1 computers remain, in part because of their reliability and security. And it's not clear whether other upgrades to "modernize" the system have been completed. Air Force officials have acknowledged network upgrades that have enhanced the speed and capacity of SACCS' communications systems, and a Government Accountability Office report in 2016 noted that the Air Force planned to "update its data storage solutions, port expansion processors, portable terminals, and desktop terminals by the end of fiscal year 2017." But it's not clear how much of that has been completed.

The Internet

Banning Out-of-Hours Email 'Could Harm Employee Wellbeing' (bbc.com) 118

Banning staff from accessing their work emails outside office hours could do more harm than good to employee wellbeing, a study suggests. From a report: University of Sussex researchers found while a ban could help some staff switch off, it could also stop people achieving work goals, causing stress. Companies are increasingly curbing email use to tackle burnout. France has even legislated on the issue. But human resources body CIPD said it agreed with the university's findings. According to the research, strict policies on email use could be harmful to employees with "high levels of anxiety and neuroticism."

That was because such employees needed to feel free to respond to a "growing accumulation of emails", or they could end up feeling even more stressed and overloaded, the researchers said. Dr Emma Russell, a senior lecturer in management at the University of Sussex Business School, said despite the best intentions of policies limiting email use, a one-size-fits-all approach should be avoided. "[Blanket bans] would be unlikely to be welcomed by employees who prioritise work performance goals and who would prefer to attend to work outside of hours if it helps them get their tasks completed. People need to deal with email in the way that suits their personality and their goal priorities in order to feel like they are adequately managing their workload."

Microsoft

Multifactor Authentication Issue Hitting North American Azure, Office 365 Users (zdnet.com) 40

A widespread multifactor authentication (MFA) issue is hitting a number of Microsoft customers in North America this morning. From a report: The exact cause of the problem is not clear at the moment, but Microsoft's engineering team says it is working on it. "Customers in North America are experiencing issues with Sign-in when Multi-Factor Authentication is enabled. Engineering team is currently investigating the issue and will send out an update as soon as possible." The Microsoft 365 Status twitter account, as of 10:45 a.m. ET, said: "We're investigating issues where users may be unable to access the admin center when using MFA. We'll provide an update shortly." I've asked Microsoft for an update. No word back so far. Users are reporting they cannot sign into Office 365 or access any of their Office 365 apps and services. Office 365 uses Azure Active Directory for authentication.
Firefox

Germany's Cybersecurity Agency Recommends Firefox As Most Secure Browser (arstechnica.com) 52

An anonymous reader quotes a report from ZDNet: Firefox is the only browser that received top marks in a recent audit carried out by Germany's cyber-security agency -- the German Federal Office for Information Security (or the Bundesamt fur Sicherheit in der Informationstechnik -- BSI). The BSI tested Mozilla Firefox 68 (ESR), Google Chrome 76, Microsoft Internet Explorer 11, and Microsoft Edge 44. The tests did not include other browsers like Safari, Brave, Opera, or Vivaldi. The audit was carried out using rules detailed in a guideline for "modern secure browsers" that the BSI published last month, in September 2019. The BSI normally uses this guide to advise government agencies and companies from the private sector on what browsers are safe to use. The article includes a list of all the minimum requirements required for the BSI to consider a browser "secure." It also lists the areas where the other browsers failed, such as: Lack of support for a master password mechanism (Chrome, IE, Edge); No built-in update mechanism (IE), and No option to block telemetry collection (Chrome, IE, Edge).
Security

Malware That Spits Cash Out of ATMs Has Spread Across the World (vice.com) 47

A joint investigation between Motherboard and the German broadcaster Bayerischer Rundfunk (BR) has uncovered new details about a spate of so-called "jackpotting" attacks. From a report: A joint investigation between Motherboard and the German broadcaster Bayerischer Rundfunk (BR) has uncovered new details about a spate of so-called "jackpotting" attacks on ATMs in Germany in 2017 that saw thieves make off with more than a million Euros. Jackpotting is a technique where cybercriminals use malware or a piece of hardware to trick an ATM into ejecting all of its cash, no stolen credit card required. Hackers typically install the malware onto an ATM by physically opening a panel on the machine to reveal a USB port. In some cases, we have identified the specific bank and ATM manufacturer affected. Although a European non-profit said jackpotting attacks have decreased in the region in the first half of this year, multiple sources said the number of attacks in other parts of the world has gone up. Attacked regions include the U.S., Latin America, and Southeast Asia, and the issue impacts banks and ATM manufacturers across the financial industry. "The U.S. is quite popular," a source familiar with ATM attacks said. Motherboard and BR granted multiple sources, including law enforcement officials, anonymity to speak more candidly about sensitive hacking incidents.
Chrome

Google Expands Chrome's Site Isolation Feature To Android Users (zdnet.com) 6

If Chrome for Android users visit a site where they enter passwords, Chrome will isolate that site from all the other tabs in a separate Android process, keeping the user's data safe from Spectre-like attacks, Google said today. From a report: Furthermore, Site Isolation, which has been available for desktop users since July 2018, has also been expanded for Windows, Mac, Linux, and Chrome OS users, which now receive protection against more attacks than the original Meltdown and Spectre vulnerabilities. Site Isolation is a Chrome security feature that Google started developing as a way to isolate each website from one another, so malicious code running on one site/tab couldn't steal data from other websites/tabs. Site Isolation was developed to act as a second layer of protection on top of Same Origin Policy (SOP), a browser feature that prevents websites from accessing each other's data. Google developed Site Isolation because browser bugs often allowed sites to jump the SOP barrier and steal user data stored in the browser, created by other sites.
Android

Samsung Says Anyone's Thumbprint Can Unlock $900 Galaxy S10 Smartphone (bbc.com) 40

A flaw that means any fingerprint can unlock a Galaxy S10 phone has been acknowledged by Samsung. From a report: It promised a software patch that would fix the problem. The issue was spotted by a British woman whose husband was able to unlock her phone with his thumbprint just by adding a cheap screen protector. When the S10 was launched, in March, Samsung described the fingerprint authentication system as "revolutionary." The scanner sends ultrasounds to detect 3D ridges of fingerprints in order to recognize users. Samsung said it was "aware of the case of S10's malfunctioning fingerprint recognition and will soon issue a software patch."
United States

US Carried Out Secret Cyber Strike on Iran in Wake of Saudi Oil Attack (reuters.com) 85

The United States carried out a secret cyber operation against Iran in the wake of the Sept. 14 attacks on Saudi Arabia's oil facilities, which Washington and Riyadh blame on Tehran, two U.S. officials have told Reuters. From the report: The officials, who spoke on condition of anonymity, said the operation took place in late September and took aim at Tehran's ability to spread "propaganda." One of the officials said the strike affected physical hardware, but did not provide further details. The attack highlights how President Donald Trump's administration has been trying to counter what it sees as Iranian aggression without spiraling into a broader conflict.

Asked about Reuters reporting on Wednesday, Iran's Minister of Communications and Information Technology Mohammad Javad Azari-Jahromi said: "They must have dreamt it," Fars news agency reported. The U.S. strike appears more limited than other such operations against Iran this year after the downing of an American drone in June and an alleged attack by Iran's Revolutionary Guards on oil tankers in the Gulf in May. The United States, Saudi Arabia, Britain, France and Germany have publicly blamed the Sept. 14 attack on Iran, which denied involvement in the strike. The Iran-aligned Houthi militant group in Yemen claimed responsibility. Publicly, the Pentagon has responded by sending thousands of additional troops and equipment to bolster Saudi defenses -- the latest U.S. deployment to the region this year.

Security

Argentinian Security Researcher Arrested After Tweeting About Government Hack (zdnet.com) 48

Argentinian police briefly detained and raided the home of a well-known security researcher last week on suspicion of hacking and leaking data from government systems. From a report: Following his release, Javier Smaldone, the security researcher, obtained and published court documents pertaining to his arrest on Twitter. The documents showed that authorities arrested and raided the security expert just for tweeting about a recent government hack, with no tangible evidence that he was involved. Smaldone claimed the entire affair was a witch-hunt, describing his arrest and raid as "political persecution." The researcher is a well-known cyber-security activist, previously testified in front of the Argentinian Senate against the use of electronic voting machines, and regularly publishes blog posts criticizing the government's plans to use such devices. Smaldone believes this is the government's revenge for past criticism.
Encryption

Edward Snowden: 'Without Encryption, We Will Lose All Privacy. This is Our New Battleground' (theguardian.com) 135

Edward Snowden: In the midst of the greatest computer security crisis in history, the US government, along with the governments of the UK and Australia, is attempting to undermine the only method that currently exists for reliably protecting the world's information: encryption. Should they succeed in their quest to undermine encryption, our public infrastructure and private lives will be rendered permanently unsafe. [...] Earlier this month the US, alongside the UK and Australia, called on Facebook to create a "backdoor," or fatal flaw, into its encrypted messaging apps, which would allow anyone with the key to that backdoor unlimited access to private communications. So far, Facebook has resisted this.

Donald Trump's attorney general, William Barr, who authorised one of the earliest mass surveillance programmes without reviewing whether it was legal, is now signalling an intention to halt -- or even roll back -- the progress of the last six years. WhatsApp, the messaging service owned by Facebook, already uses end-to-end encryption (E2EE): in March the company announced its intention to incorporate E2EE into its other messaging apps -- Facebook Messenger and Instagram -- as well. Now Barr is launching a public campaign to prevent Facebook from climbing this next rung on the ladder of digital security. This began with an open letter co-signed by Barr, UK home secretary Priti Patel, Australia's minister for home affairs and the US secretary of homeland security, demanding Facebook abandon its encryption proposals.

If Barr's campaign is successful, the communications of billions will remain frozen in a state of permanent insecurity: users will be vulnerable by design. And those communications will be vulnerable not only to investigators in the US, UK and Australia, but also to the intelligence agencies of China, Russia and Saudi Arabia -- not to mention hackers around the world. End-to-end encrypted communication systems are designed so that messages can be read only by the sender and their intended recipients, even if the encrypted -- meaning locked -- messages themselves are stored by an untrusted third party, for example, a social media company such as Facebook.

Security

China Has Gained the Ability To Spy On More Than 100 Million Citizens Via a Heavily Promoted Official App, Report Suggests (bbc.com) 47

Security researchers believe the Chinese Communist Party's official "Study the Great Nation" app has a backdoor that could help monitor use and copy data from those who have it installed on their devices. The BBC reports: Released in February, Study the Great Nation has become the most downloaded free program in China, thanks to persuasive demands by Chinese authorities that citizens download and install it. The app pushes out official news and images and encourages people to earn points by reading articles, commenting on them and playing quizzes about China and its leader, Xi Jinping. Use of the app is mandatory among party officials and civil servants and it is tied to wages in some workplaces.

Starting this month, native journalists must pass a test on the life of President Xi, delivered via the app, in order to obtain a press card which enables them to do their jobs. On behalf of the Open Technology Fund, which campaigns on human rights issues, Germany cyber-security firm Cure 53 took apart the Android version of the app and said it found many undocumented and hidden features. In its lengthy report, Cure 53 said Study the Great Nation had "extensive logging" abilities and seemed to try to build up a list of the popular apps an individual had installed on their phone. It was "evident and undeniable that the examined application is capable of collecting and managing vast amounts of very specific data," said the report. The app also weakened encryption used to scramble data and messages, making it easy for a government to crack security.
Adam Lynn, research director at the Open Technology Fund, told the Washington Post, which broke the story: "It's very, very uncommon for an application to require that level of access to the device, and there's no reason to have these privileges unless you're doing something you're not supposed to be."

The security company didn't find evidence that this high-level access was being used, but said it's not clear why an educational app would need such access to a phone.
Open Source

Flaw In Sudo Enables Non-Privileged Users To Run Commands As Root (thehackernews.com) 139

exomondo shares a report from The Hacker News: A vulnerability has been discovered in Sudo -- one of the most important, powerful, and commonly used utilities that comes as a core command installed on almost every UNIX and Linux-based operating system. The vulnerability in question is a sudo security policy bypass issue that could allow a malicious user or a program to execute arbitrary commands as root on a targeted Linux system even when the "sudoers configuration" explicitly disallows the root access. Sudo, stands for "superuser do," is a system command that allows a user to run applications or commands with the privileges of a different user without switching environments -- most often, for running commands as the root user.

The vulnerability, tracked as CVE-2019-14287 and discovered by Joe Vennix of Apple Information Security, is more concerning because the sudo utility has been designed to let users use their own login password to execute commands as a different user without requiring their password. What's more interesting is that this flaw can be exploited by an attacker to run commands as root just by specifying the user ID "-1" or "4294967295." That's because the function which converts user id into its username incorrectly treats -1, or its unsigned equivalent 4294967295, as 0, which is always the user ID of root user. The vulnerability affects all Sudo versions prior to the latest released version 1.8.28, which has been released today.

Slashdot Top Deals