Security

Capital One's Breach Was Inevitable, Because We Did Nothing After Equifax (techcrunch.com) 165

An anonymous reader shares a report: Another day, another massive data breach. This time it's the financial giant and credit card issuer Capital One, which revealed on Monday a credit file breach affecting 100 million Americans and 6 million Canadians. Sound familiar? It should. Just last week, credit rating giant Equifax settled for more than $575 million over a date breach it had -- and hid from the public for several months -- two years prior. Why should we be surprised? Equifax faced zero fallout until its eventual fine. All talk, much bluster, but otherwise little action. Equifax's chief executive Richard Smith "retired" before he was fired, allowing him to keep his substantial pension packet. Lawmakers grilled the company but nothing happened.

An investigation launched by the former head of the Consumer Financial Protection Bureau, the governmental body responsible for protecting consumers from fraud, declined to pursue the company. The FTC took its sweet time to issue its fine -- which amounted to about 20% of the company's annual revenue for 2018. For one of the most damaging breaches to the U.S. population since the breach of classified vetting files at the Office of Personnel Management in 2015, Equifax got off lightly. Legislatively, nothing has changed. Equifax remains as much of a "victim" in the eyes of the law as it was before -- technically, but much to the ire of the millions affected who were forced to freeze their credit as a result.

Security

Amazon's Ring Reportedly Partners With 200 Law Enforcement Agencies (vice.com) 73

An anonymous reader quotes a report from Motherboard: At least 200 law enforcement agencies around the country have entered into partnerships with Amazon's home surveillance company Ring, according to an email obtained by Motherboard via public record request. Ring has never disclosed the exact number of partnerships that it maintains with law enforcement. However, the company has partnered with at least 200 law enforcement agencies, according to notes taken by a police officer during a Ring webinar, which he emailed to himself in April. It's possible that the number of partnerships has changed since the day the email was sent. The officer who sent the email told Motherboard that the email was a transcribed version of handwritten notes that he took during a team webinar with a Ring representative on April 9. Additional emails obtained by Motherboard indicate that this webinar trained officers on how to use the "Law Enforcement Neighborhood Portal." This portal allows local police to see a map with the approximate locations of all Ring cameras in a neighborhood, and request footage directly from camera owners. Owners need to consent, but police do not need a warrant to ask for footage. "This doesn't surprise me at all, and it's the perfect example of how corporate surveillance and government surveillance are inextricably linked," Evan Greer, deputy director of Fight for the Future, told Motherboard. "Amazon is building a for-profit surveillance dragnet and partnering with local law enforcement agencies in ways that avoid any form of oversight or accountability that police departments might normally be required to adhere to."

"It's time to come to grips with the fact that the 1984 dystopian future we all fear isn't something a future authoritarian government might impose," Greer told Motherboard, "it's something that's being built right now, in plain sight, through partnerships between private companies and government agencies."
Privacy

Capital One Says Hacker Breached Accounts of 100 Million People; Ex-Amazon Employee Arrested (forbes.com) 280

CaptainDork shares a report from Forbes: Capital One said Monday that sensitive financial information -- including social security and bank account numbers -- from over 100 million people were exposed in a massive data breach that led to the arrest of former Amazon employee Paige Thompson, a hacker who lives in Seattle. The information was taken from credit card applications submitted to the Virginia-based bank from 2005-2019. These included names, addresses, zip codes/postal codes, phone numbers, email addresses, dates of birth and self-reported income. Additionally, Capital One said that 140,000 Social Security and 80,000 linked bank account numbers were compromised as well as fragments of transaction data from a total of 23 days during 2016, 2017 and 2018. No credit card account numbers or log-in credentials were exposed. Individuals whose information was compromised in the breach will be notified by Capital One. According to court documents, Paige Thompson was arrested for hacking into cloud computer servers rented by Capital One. Investigators say Thompson previously worked at the cloud computing company whose servers were breached, but did not name the company.

"Thompson's resume, which is still online, and her LinkedIn profile indicate that she worked at Amazon, which operates the popular cloud computing business Amazon Web Services, from 2015-2016," reports Forbes. "Thompson allegedly posted the information from the hack on her Github profile, which included a link to her resume, leading the FBI to her. The hack occurred on March 22 or 23, the court documents say, but no one at Capital One knew the bank had been breached until four months later when an anonymous security researcher alerted them."
Android

The Google Pixel 4 Will Have Built-In Radar and Unlock With a Face Scan (theverge.com) 72

In a YouTube video and blog post, Google revealed that its upcoming Pixel 4 smartphone will feature face unlock technology and a feature called "Motion Sense," which confirms that it will have a Project Soli chip that uses radar to detect hand gestures near the phone. The Verge reports: Adding face unlock puts the Pixel 4 on par with modern iPhones for unlocking, and it's (at least in theory) more convenient than an in-screen fingerprint sensor. Google also confirmed that the Pixel 4 will use the face unlock feature for payments: "face unlock works in almost any orientation -- even if you're holding it upside down -- and you can use it for secure payments and app authentication too." As with the iPhone, Google says that biometric data will be stored locally in a secure chip and never share with other Google services. The Pixel 4's face unlock feature will use a variety of sensors to identify your face, including depth, infrared, and RGB. That should mean that it will work in a variety of lighting situations and also work with a diverse set of faces. Google has told me that it has done "field research" to ensure both of those things.

As for the "Motion Sense" feature, there's not a ton that we can glean from Google's article. Earlier rumors have pointed to it being related to Project Soli, which uses radar to detect tiny hand or finger movements above the device. For example, Google has demoed rubbing your thumb and index finger together to simulate turning a dial on a smartwatch. Some code found in the next version of Android has suggested it could be used for media controls at the very least. Google's post cites a possible use case where the Soli chip could detect your hand reaching for the phone, which would automatically turn on "the face unlock sensors." If it all works, the phone would automatically unlock itself and be ready by the time you're looking at it.

Security

200 Million Devices -- Some Mission-Critical -- Vulnerable To Remote Takeover (arstechnica.com) 46

An anonymous reader quotes a report from Ars Technica: About 200 million Internet-connected devices -- some that may be controlling elevators, medical equipment, and other mission-critical systems -- are vulnerable to attacks that give attackers complete control, researchers warned on Monday. In all, researchers with security firm Armis identified 11 vulnerabilities in various versions of VxWorks, a slimmed-down operating system that runs on more than 2 billion devices worldwide. Billed collectively as Urgent 11, the vulnerabilities consist of six remote code flaws and five less-severe issues that allow things like information leaks and denial-of-service attacks. None of the vulnerabilities affects the most recent version of VxWorks or any of the certified versions of the OS, including VxWorks 653 or VxWorks Cert Edition.

For the 200 million devices Armis estimated are running a version that's susceptible to a serious attack, however, the stakes may be high. Because many of the vulnerabilities reside in the networking stack known as IPnet, they can often be exploited by little more than boobytrapped packets sent from outside the Internet. Depending on the vulnerability, exploits may also be able to penetrate firewalls and other types of network defenses. The most dire scenarios are attacks that chain together multiple exploits that trigger the remote takeover of multiple devices. "Such vulnerabilities do not require any adaptations for the various devices using the network stack, making them exceptionally easy to spread," Armis researchers wrote in a technical overview. "In most operating systems, such fundamental vulnerabilities in the crucial networking stacks have become extinct, after years of scrutiny unravelled and mitigated such flaws."
VxWorks-maker Wind River says the latest release of VxWorks "is not affected by the vulnerability, nor are any of Wind Rivers' safety-critical products that are designed for safety certification, such as VxWorks 653 and VxWorks Cert Edition used in critical infrastructure."

Wind River issued patches last month and is in the process of notifying affected customers of the threat.
Privacy

DMARC's Abysmal Adoption Explains Why Email Spoofing is Still a Thing (zdnet.com) 113

Companies around the world are still failing to see the benefits of implementing DMARC, an email security protocol designed to prevent email spoofing, the primary trick used by cybercriminals to deliver phishing emails and BEC scams. From a report: Around 79.7% don't use DMARC, according to a report that surveyed the DMARC policies deployed with 21,075 business and government domains. The survey, carried out by email security and analytics firm 250ok, analyzed domains from sectors such as Fortune 500, US government (Executive, Legislative and Judicial), the China Hot 100, the top 100 law firms, international nonprofits, the SaaS 1000, education, e-commerce, financial services, and travel sectors. The survey looked specifically at DMARC adoption because of the protocol's importance.
EU

'No More Ransom' Decryption Tools Prevent $108M In Ransomware Payments (zdnet.com) 95

An anonymous reader quotes ZDNet: On the three-year anniversary of the No More Ransom project, Europol announced today that users who downloaded and decrypted files using free tools made available through the No More Ransom portal have prevented ransomware gangs from making profits estimated at at least $108 million... However, an Emsisoft spokesperson told ZDNet that the $108 million estimate that Europol shared today is "actually a huge underestimate. They're based on the number of successful decryptions confirmed by telemetry -- in other words, when the tools phone home to confirm they've done their job," Emsisoft told ZDNet... Just the free decryption tools for the GandCrab ransomware alone offered on the No More Ransom website have prevented ransom payments of nearly $50 million alone, Europol said.

The project, which launched in July 2016, now hosts 82 tools that can be used to decrypt 109 different types of ransomware. Most of these have been created and shared by antivirus makers like Emsisoft, Avast, and Bitdefender, and others; national police agencies; CERTs; or online communities like Bleeping Computer. By far the most proficient member has been antivirus maker Emsisoft, which released 32 decryption tools for 32 different ransomware strains... All in all, Europol said that more than three million users visited the site and more than 200,000 users downloaded tools from the No More Ransom portal since its launch.

One Emisoft researcher said they were "pretty proud" of their decryptor for MegaLocker, "as not only did it help thousands of victims, but it really riled up the malware author."
Encryption

Did Facebook End The Encryption Debate? (forbes.com) 163

Forbes contributor Kalev Leetaru argues that "the encryption debate is already over -- Facebook ended it earlier this year." The ability of encryption to shield a user's communications rests upon the assumption that the sender and recipient's devices are themselves secure, with the encrypted channel the only weak point... [But] Facebook announced earlier this year preliminary results from its efforts to move a global mass surveillance infrastructure directly onto users' devices where it can bypass the protections of end-to-end encryption. In Facebook's vision, the actual end-to-end encryption client itself such as WhatsApp will include embedded content moderation and blacklist filtering algorithms. These algorithms will be continually updated from a central cloud service, but will run locally on the user's device, scanning each cleartext message before it is sent and each encrypted message after it is decrypted. The company even noted that when it detects violations it will need to quietly stream a copy of the formerly encrypted content back to its central servers to analyze further, even if the user objects, acting as true wiretapping service...

If Facebook's model succeeds, it will only be a matter of time before device manufacturers and mobile operating system developers embed similar tools directly into devices themselves, making them impossible to escape... Governments would soon use lawful court orders to require companies to build in custom filters of content they are concerned about and automatically notify them of violations, including sending a copy of the offending content. Rather than grappling with how to defeat encryption, governments will simply be able to harness social media companies to perform their mass surveillance for them, sending them real-time alerts and copies of the decrypted content.

Putting this all together, the sad reality of the encryption debate is that after 30 years it is finally over: dead at the hands of Facebook. If the company's new on-device content moderation succeeds it will usher in the end of consumer end-to-end encryption and create a framework for governments to outsource their mass surveillance directly to social media companies, completely bypassing encryption.

In the end, encryption's days are numbered and the world has Facebook to thank.


UPDATE: 8/2/2019 Will Cathcart, WhatsApp's vice president of product management, took to the internet with this forceful response. "We haven't added a backdoor to WhatsApp. To be crystal clear, we have not done this, have zero plans to do so, and if we ever did, it would be quite obvious and detectable that we had done it. We understand the serious concerns this type of approach would raise, which is why we are opposed to it."
Programming

Is Hiring Broken? (rajivprab.com) 397

DevNull127 writes: Hiring is broken and yours is too," argues a New York-based software developer whose LinkedIn profile says he's worked at both Amazon and Google, as well as doing architecture verification work for both Oracle and Intel. Summarizing what he's read about hiring just this year in numerous online articles, he lists out the arguments against virtually every popular hiring metric, ultimately concluding that "Until and unless someone does a rigorous scientific study evaluating different interviewing techniques, preferably using a double-blind randomized trial, there's no point in beating this dead horse further. Everyone's hiring practices are broken, and yours aren't any better."

For example, as a Stanford graduate he nonetheless argues that "The skills required for getting into Stanford at 17 (extracurriculars, SAT prep etc) do not correlate to job success as a software developer. How good a student you were at 17, is not very relevant to who you are at 25." References are flawed because "People will only ever list references who will say good things about them," and they ultimately punish people who've had bad managers. But asking for source code from past sides projects penalizes people with other interests or family, while "most work product is confidential."

Brain teasers "rely on you being lucky enough to get a flash of inspiration, or you having heard it before," and are "not directly related to programming. Even Google says it is useless." And live-coding exercises are "artificial and contrived," and "not reflective of practical coding," while pair programming is unrealistic, with the difficulty of the tasks varying from day to day.

He ultimately criticizes the ongoing discussion for publicizing the problems but not the solutions. "How exactly should we weigh the various pros and cons against each other and actually pick a solution? Maybe we could maybe try something novel like data crunch the effectiveness of each technique, or do some randomized experiments to measure the efficacy of each approach? Lol, j/k. Ain't nobody got time for that!"

Windows

Penetration Testing Toolkit Includes Exploit For 'Incredibly Dangerous' Bluekeep Vulnerability (vice.com) 67

An anonymous reader quotes Vice: In May, Microsoft released a patch for a bug in several versions of Windows that is so bad that the company felt it even had to release a fix for Windows XP, an operating system that (has been unsupported) for five years. That vulnerability is known as BlueKeep, and it has kept a lot of security researchers up at night. They are worried that someone could write an exploit for it and make a worm that could wreak havoc the way WannaCry or NotPetya -- two viruses that spread almost uncontrollably all over the world locking thousands of computers -- did.... Researchers were so worried about this vulnerability that for months, no one has published the code for a proof-of-concept exploit. In other words, no one wanted to be the guy to even prove that this type of malware was even possible to write.

Until now.

On Tuesday, Immunity, a long time US government contractor, announced that it had developed an exploit for BlueKeep and included it into its penetration testing toolkit Canvas, which is available only to paying subscribers. Canvas customers, can now exploit this bug using Immunity's own code.

ZDNet notes that Canvas licenses "cost between thousands and tens of thousands of US dollars," but also adds that "hackers have been known to pirate or legitimately buy penetration testing tools."
Crime

Marcus 'MalwareTech' Hutchins Gets No Prison Time, One Year Supervised Release (zdnet.com) 45

An anonymous reader writes: Marcus 'MalwareTech' Hutchins, the security researcher who helped stop the WannaCry ransomware outbreak, was sentenced today in the US to time served and one year of supervised release. The UK-born malware analyst avoided the prison time in the case as the judge described "too many positives on other side of ledger" -- referring to Hutchins' role in the WannaCry ransomware outbreak and his work as a malware analyst. Judge J. P. Stadmueller had a difficult decision on his hand, and would have considered a pardon. However, courts have no such power, and deferred to the executive branch. In court, Hutchins apologized, again, to victims, family, and friends. The judge waived any fines. The sentence comes after Hutchins pleaded guilty this April on two charges of entering a conspiracy to create and distribute malware, and in aiding and abetting its distribution.
Mozilla

Mozilla Debuts Implementation of WebThings Gateway Open Source Router Firmware (venturebeat.com) 57

An anonymous reader shares a report: For the better part of two years, the folks at Mozilla have been diligently chipping away at Mozilla WebThings, an open implementation of the World Wide Web Consortium's (W3C) Web of Things standard for monitoring and controlling connected devices. In April, it gained a number of powerful logging, alarm, and networking features, and this week, a revamped component of WebThings -- WebThings Gateway, a privacy- and security-focused software distribution for smart home gateways -- formally debuted. Experimental builds of WebThings Gateway 0.9 are available on GitHub for the Turris Omnia router, with expanded support for routers and developer boards to come down the line. (Separately, there's a new build compatible with the recently announced Raspberry Pi 4.) Mozilla notes that it currently only offers "extremely basic" router configuration and cautions against replacing existing firmware, but the company says that it's a noteworthy milestone in its path to creating a full software distribution for wireless routers.
The Almighty Buck

The FBI Is Investigating Long Island Iced Tea's BlockChain Pivot (futurism.com) 48

Beverage firm Long Island Iced Tea -- now known as Long Blockchain -- is being investigated by the U.S. Federal Bureau of Investigation for insider trading and securities fraud. From a report: Court records show that the FBI is investigating suspicious dealings that date back to December 2017 -- around the time when the beverage company changed its name and shifted its "primary corporate focus" from selling sweetened iced tea to blockchain. The company's stock shot up by almost 300 percent after it announced the pivot in late 2017. The FBI is focusing in on secretive phone message conversations about Long Island Iced Tea between two men, Oliver Lindsay and Gannon Giguiere, who were previously arrested for securities fraud related to a different company.
Security

Russian Hack of Elections System Was Far-Reaching, Senate Intel Committee Report Finds (npr.org) 365

An anonymous reader quotes a report from The New York Times: The Senate Intelligence Committee concluded Thursday that election systems in all 50 states were targeted by Russia in 2016 (Warning: source may be paywalled; alternative source), largely undetected by the states and federal officials at the time, but at the demand of American intelligence agencies the committee was forced to redact its findings so heavily that key lessons for the 2020 election are blacked out. Even key findings at the beginning of the report were heavily redacted. It concluded that while there is no evidence that any votes were changed in actual voting machines, "Russian cyberactors were in a position to delete or change voter data" in the Illinois voter database. The committee found no evidence that they did so. While the report is not directly critical of either American intelligence agencies or the states, it described what amounted to a cascading intelligence failure, in which the scope of the Russian effort was underestimated, warnings to the states were too muted, and state officials either underreacted or, in some cases, resisted federal efforts to offer help.
Security

Louisiana Governor Declares State Emergency After Local Ransomware Outbreak (zdnet.com) 141

Louisiana Governor John Bel Edwards has activated a state-wide state of emergency in response to a wave of ransomware infections that have hit multiple school districts. ZDNet reports: The ransomware infections took place this week and have impacted the school districts of three North Louisiana parishes -- Sabine, Morehouse, and Ouachita. IT networks are down at all three school districts, and files have been encrypted and are inaccessible, local media outlets are reporting. By signing the Emergency Declaration, the Louisiana governor is making available state resources to impacted schools. This includes assistance from cybersecurity experts from the Louisiana National Guard, Louisiana State Police, the Office of Technology Services, the Governor's Office of Homeland Security and Emergency Preparedness (GOHSEP), and others. State officials hope that additional IT expertise will speed up the recovery process so schools can resume their activity and preparations for the upcoming school year. Earlier today, some residents of Johannesburg have been left without electricity after a ransomware infection.
Bug

Airbus A350 Software Bug Forces Airlines To Turn Planes Off and On Every 149 Hours (theregister.co.uk) 131

An anonymous reader quotes a report from The Register: Some models of Airbus A350 airliners still need to be hard rebooted after exactly 149 hours, despite warnings from the EU Aviation Safety Agency (EASA) first issued two years ago. In a mandatory airworthiness directive (AD) reissued earlier this week, EASA urged operators to turn their A350s off and on again to prevent "partial or total loss of some avionics systems or functions." The revised AD, effective from tomorrow (26 July), exempts only those new A350-941s which have had modified software pre-loaded on the production line. For all other A350-941s, operators need to completely power the airliner down before it reaches 149 hours of continuous power-on time.

Concerningly, the original 2017 AD was brought about by "in-service events where a loss of communication occurred between some avionics systems and avionics network" (sic). The impact of the failures ranged from "redundancy loss" to "complete loss on a specific function hosted on common remote data concentrator and core processing input/output modules." In layman's English, this means that prior to 2017, at least some A350s flying passengers were suffering unexplained failures of potentially flight-critical digital systems.

Security

Stock Trading Service Robinhood Admits To Storing Some Passwords in Cleartext (zdnet.com) 30

Stock trading service Robinhood has admitted this week to storing some customers' passwords in cleartext, according to emails the company has been sending to impacted customers. From a report: "On Monday night, we discovered that some user credentials were stored in a readable format within our internal system," the company said. "We resolved the issue, and after thorough review, found no evidence that this information was accessed by anyone outside our response team." Robinhood is now resetting passwords out of an abundance of caution, despite not finding any evidence of abuse. A company spokesperson told ZDNet via phone call that not all Robinhood users were impacted, but could not reveal the exact number.
Transportation

Atlanta Pauses Scooter Permits After Deaths (nbcnews.com) 143

Atlanta's mayor put a pause on the city's issuance of permits for smartphone-based electric scooter rentals Thursday following two recent deaths. From a report: The city had come under pressure from activists in recent days who had protested on Atlanta's streets after a man riding a scooter was run over by a city transit bus. The executive order from Mayor Keisha Lance Bottoms stops short of removing scooters from the city's streets.

"Across the nation, municipalities are dealing with the sudden and unforeseen impact these devices have had on our communities," Bottoms said in a press release. "While some municipalities have banned the devices altogether, the City of Atlanta acted in good faith to work with the private sector to explore innovative solutions to ease existing commuting strains," said Bottoms. "However, as Atlanta has seen two scooter related deaths, this complex issue requires a more thorough and robust dialogue."

IT

Ransomware Incident Leaves Some Johannesburg Residents Without Electricity (zdnet.com) 67

A ransomware infection at an electricity provider in the city of Johannesburg, South Africa's biggest city and financial capital, has left some of its residents without power. From a report: The ransomware infection impacted City Power -- a provider of pre-paid electric power for Johannesburg residents and local companies. The malware encrypted the company's database, internal network, web apps, and official website.
Bug

VLC Developer Debunks Reports of 'Critical Security Issue' In Open Source Media Player (portswigger.net) 80

New submitter Grindop53 shares a report: Widespread reports of a "critical security issue" that supposedly impacted users of VLC media player have been debunked as "completely bogus" by developers. Earlier this week, German computer emergency response team CERT-Bund -- part of the Federal Office for Information Security (BSI) -- pushed out an advisory warning network administrators and other users of a high-impact vulnerability in VLC. It seems that this advisory can be traced back to a ticket that was opened on VLC owner VideoLAN's public bug tracker more than four weeks ago. The alleged heap-based buffer overflow flaw was disclosed by a user named "topsec(zhangwy)," who stated that a malicious .mp4 file could be leveraged by an attacker to take control of VLC media player users' devices. The issue was flagged as high-risk on the CERT-Bund site, and the vulnerability was assigned a CVE entry (CVE-2019-13615).

However, according to VideoLAN president Jean-Baptiste Kempf, the exploit does not work on the latest VLC build. In fact, any potential issues relating to the vulnerability were patched more than a year ago. "There is no security issue in VLC," Kempf told The Daily Swig in a phone conversation this morning. "There is a security issue in a third-party library, and a fix was pushed [out] 18 months ago." When asked how or why this oversight generated so much attention, Kempf noted that the reporter of the supposed vulnerability did not approach VideoLAN through its security reporting email address. "The guy never contacted us," said Kempf, who remains a lead developer at the VLC project. "This is why you don't report security issues on a public bug tracker."
Kempf and his team were unable to replicate the issue in the latest version of VLC, leading many to believe that the bug reporter was working on a computer running an outdated version of Ubuntu. "If you report a security issue, at least update your Linux distribution," Kempf said.

Slashdot Top Deals