Security

Tor Project To Fix Bug Used For DDoS Attacks On Onion Sites For Years (zdnet.com) 30

An anonymous reader writes: "The Tor Project is preparing a fix for a bug that has been abused for the past years to launch DDoS attacks against dark web (.onion) websites," reports ZDNet. "Barring any unforeseen problems, the fix is scheduled for the upcoming Tor protocol 0.4.2 release." The bug has been known to Tor developers for years, and has been used to launch Slow Loris-like attacks on the web servers that run the Tor service supporting an .onion site. It works by opening many connections to the server and maxing out the CPU. Since Tor connections are CPU intensive because of the cryptography involved to support the privacy and anonymity of the network, even a a few hundreds connections are enough to bring down dark web portals. A tool to exploit the bug and to automate DDoS attacks has been around for four years, and has been used by hackers to extort dark web marketplaces all spring. At least two markets selling illegal products have shut down after refusing to pay attackers. To get the bug fixed, members of a dark web forum banded together and donated to the Tor Project to sponsor the bug's patch.
Businesses

Need Customer Service For an App? Prepare To Lose Your Mind (wsj.com) 145

App-based services have made our lives easier in so many ways. But when things go awry, they offer few paths to real assistance [Editor's note: the link may be paywalled]. From a report: There's a trade-off between the speed of apps and their ability to provide timely help. Customer service isn't dead, it's just hiding very well, often under a maze of preset menu options that seem designed to make you want to chuck your phone out the window. I recently ordered a Lyft ride from the airport. As the driver loaded my bag into the trunk -- something he didn't seem happy about -- he started talking under his breath. I asked if he was talking to me. His eyes got wide, and he said no, he wasn't. Then he removed my bag and told me I had the wrong car. His license plate matched my app, but he said, "I'm not your ride, baby," before driving off.

Part of me was relieved. But to let Lyft know, I had to spend probably 20 minutes going through endless options for pre-written problems I didn't have. "Something happened during my ride" got me a drop-down menu with a bunch of inapt scenarios: "Demanding cash?" Nope. "Refusing my service animal?" Also no. Lyft can foresee these issues, but not "Acting unprofessional"? [...] Except for safety issues, there's no helpline to get a live person with Uber or Lyft. Ditto Spotify, Instagram and many other apps. Airbnb customer support has a phone number where actual humans answer. Instacart's app has an email address with a field to include details about your problem. It's also got a number you can ring 24/7.

Mozilla

Mozilla Set To Offer Ad-Free News Consumption Capability on Firefox For $5 Per Month (betanews.com) 94

As previously announced, Mozilla has started to tease the launch of a new $5 monthly subscription to a variety of online news publishers that involves no ads. The idea is that a single, low subscription fee gives you access to a number of sites with the ads removed. From a report: You pay a monthly fee to Mozilla, and this money is shared with its partners to help fund an ad-free internet experience. More than this, Mozilla says that the subscription fee will also grant access to audio versions of articles, article synchronization and more. In a page which promises people the chance to "support the sites you love, avoid the ads you hate", Mozilla says: "We've partnered with some of the world's greatest publishers to bring you a better journalism experience. We share your payment directly with the sites you read. They make more money which means they can bring you great content without needing to distract you with ads just to keep the lights on.
Android

Fake Samsung Firmware Update App Tricks More Than 10 Million Android Users (zdnet.com) 61

Over ten million users have been duped in installing a fake Samsung app named "Updates for Samsung" that promises firmware updates, but, in reality, redirects users to an ad-filled website and charges for firmware downloads. From a report: "I have contacted the Google Play Store and asked them to consider removing this app," Aleksejs Kuprins, malware analyst at the CSIS Security Group, told ZDNet this week in an interview, after publishing a report on the app's shady behavior earlier today. The app takes advantage of the difficulty in getting firmware and operating system updates for Samsung phones, hence the high number of users who have installed it. "It would be wrong to judge people for mistakenly going to the official application store for the firmware updates after buying a new Android device," the security researcher said. "Vendors frequently bundle their Android OS builds with an intimidating number of software, and it can easily get confusing."
Security

7-Eleven Japanese Customers Lose $500,000 Due To Mobile App Flaw (zdnet.com) 67

Approximately 900 customers of 7-Eleven Japan have lost a collective of $510,000 after hackers hijacked their 7pay app accounts and made illegal charges in their names. From a report: The incident was caused by an appalling security lapse in the design of the company's 7pay mobile payment app, which 7-Eleven Japan launched in the country on Monday, July 1. The 7pay mobile app was designed to show a barcode on the phone's screen when customers reach the 7-Eleven cashier counters. The cashier scans the barcode, and the bought goods are charged to the user's 7pay app and the customer's credit or debit cards that have been saved in the account. However, in a mind-boggling turn of events, the app contained a password reset function that was incredibly poorly designed. It allowed anyone to request a password reset for other people's accounts, but have the password reset link sent to their email address, instead of the legitimate account owner.
Security

OpenID Foundation Says 'Sign In with Apple' is Not Secure Enough (zdnet.com) 39

The OpenID Foundation, the organization behind the OpenID open standard and decentralized authentication protocol, has penned an open letter to Apple in regards to the company's recently announced "Sign In with Apple" feature. From a report: In its letter, the organization said that Apple has built Sign In with Apple on top of the OpenID Connect platform, but the Cupertino company's implementation is not fully compliant with the OpenID standard, and as a result "exposes users to greater security and privacy risks." "The current set of differences between OpenID Connect and Sign In with Apple reduces the places where users can use Sign In with Apple and exposes them to greater security and privacy risks," said Nat Sakimura, OpenID Foundation Chairman.

The OpenID Foundation published a list of differences between Sign In with Apple and the OpenID Connect platform, which Sakimura urged Apple to address. The OpenID exec said these differences place an unnecessary burden on developers working with both OpenID Connect and Sign In with Apple, who now have to support two different authentication standards and deal with each one's quirks. "By closing the current gaps, Apple would be interoperable with widely-available OpenID Connect Relying Party software," Sakimura said.

Crime

Hacker Who Launched DDoS Attacks on Sony, EA, and Steam Gets 27 Months in Prison (zdnet.com) 76

An anonymous reader shares a report: A 23-year-old man from Utah was sentenced this week to 27 months in prison for a series of DDoS attacks that took down online gaming service providers like Sony's PlayStation Network, Valve's Steam, Microsoft's Xbox, EA, Riot Games, Nintendo, Quake Live, DOTA2, and League of Legends servers, along with many others. Named Austin Thompson, but known online as DerpTrolling, the man is the first hacker who started a trend among other hackers and hacking crews -- namely of launching DDoS attacks against gaming providers during Christmas, which they later justified using ridiculous reasons such as "to spoil everyone's holiday," "to make people spend time with their families," or "for the lulz." The hacker's DDoS attacks were extremely successful at the time, in 2013, in a time when most companies didn't use strong DDoS mitigation services.
Businesses

Broadcom Said To Be In Talks To Buy Symantec, the Security Software Maker (nytimes.com) 39

An anonymous reader quotes a report from Bloomberg: Broadcom is in advanced talks to buy cybersecurity firm Symantec, according to people familiar with the matter, seeking a further expansion into the more profitable software business. Broadcom could reach an agreement to buy the Mountain View, California-based company within weeks, said the people, who asked to not be identified because the matter isn't public. No deal has been finalized and the talks could fall through, the people said. "Broadcom's potential purchase of another asset with $4+ billion in software sales is likely its most ambitious deal yet -- leaderless Symantec has been losing share, even in its core segments," says Bloomberg's technology analyst Anand Srinivasan. "Broadcom CEO Hock Tan will likely need to aggressively cut Symantec costs while keeping sales stable."

The report also adds that if this deal does happen, it "would mark Broadcom's second big bet in software, following its $18 billion takeover last year of CA Technologies."
Youtube

YouTube Bans Content 'Showing Users How To Bypass Secure Computer Systems' 128

Kody Kinzie from the Null Byte YouTube channel on Tuesday said YouTube banned a video he made about launching fireworks over Wi-Fi for the 4th of July. According to YouTube's Community Guidelines, you are not allowed to post content "showing users how to bypass secure computer systems or steal user credentials and personal data." Doing so will apparently result in a strike. The Register notes that this written policy "first appears in the Internet Wayback Machine's archive of web history in an April 5, 2019 snapshot."

"I'm worried for everyone that teaches about infosec and tries to fill in the gaps for people who are learning," Kinzie said on Twitter. "It is hard, often boring, and expensive to learn cybersecurity." Security professionals like Tim Erlin, VP of product management and strategy at cybersecurity biz Tripwire, also finds the policy questionable. "Google's intention here might be laudable, but the result is likely to stifle valuable information sharing in the information security community," he said. "In cybersecurity, we improve our defenses by understanding how attacks actually work. Theoretical explanations are often not the most effective tools, and forcing content creators onto platforms restricted in distribution, like a paid training course, simply creates roadblocks to the industry. Sharing real world examples brings more people to the industry, rather than creating more criminals."
Encryption

Someone Is Spamming and Breaking a Core Component of PGP's Ecosystem (vice.com) 88

A new wave of spamming attacks on a core component of PGP's ecosystem has highlighted a fundamental weakness in the whole ecosystem. From a report: Unknown attackers are spamming a core component of the ecosystem of the well-known encryption software PGP, breaking users' PGP installations and clients. What's worse, there may be no way to stop them. Last week, contributors to the PGP protocol GnuPG noticed that someone was "poisoning" or "flooding" their certificates. In this case, poisoning refers to an attack where someone spams a certificate with a large number of signatures or certifications. This makes it impossible for the the PGP software that people use to verify its authenticity, which can make the software unusable or break. In practice, according to one of the GnuPG developers targeted by this attack, the hackers could make it impossible for people using Linux to download updates, which are verified via PGP.
Security

File-Storage App 4shared Caught Serving Invisible Ads and Making Purchases Without Consent (techcrunch.com) 64

With more than 100 million installs, file-sharing service 4shared is one of the most popular apps in the Android app store. But security researchers say the app is secretly displaying invisible ads and subscribes users to paid services, racking up charges without the user's knowledge -- or their permission -- collectively costing millions of dollars. From a report: "It all happens in the background... nothing appears on the screen," said Guy Krief, chief executive of London-based Upstream, which shared its research exclusively with TechCrunch. The researchers say the app contains suspicious third-party code that allowed the app to automate clicks and make fraudulent purchases. They said the component, built by Hong Kong-based Elephant Data, downloads code which is "directly responsible" for generating the automated clicks without the user's knowledge. The code also sets a cookie to determine if a device has previously been used to make a purchase, likely as a way to hide the activity.
Security

Security Flaws In a Popular Smart Home Hub Let Hackers Unlock Front Doors (techcrunch.com) 98

In new research published Tuesday, security researchers Chase Dardaman and Jason Wheeler found three security flaws which, when chained together, could be abused to open a front door with a smart lock. TechCrunch reports: Dardaman and Wheeler began looking into the ZipaMicro, a popular smart home hub developed by Croatian firm Zipato, some months ago, but only released their findings once the flaws had been fixed. The researchers found they could extract the hub's private SSH key for "root" -- the user account with the highest level of access -- from the memory card on the device. Anyone with the private key could access a device without needing a password, said Wheeler. They later discovered that the private SSH key was hardcoded in every hub sold to customers -- putting at risk every home with the same hub installed.

Using that private key, the researchers downloaded a file from the device containing scrambled passwords used to access the hub. They found that the smart hub uses a "pass-the-hash" authentication system, which doesn't require knowing the user's plaintext password, only the scrambled version. By taking the scrambled password and passing it to the smart hub, the researchers could trick the device into thinking they were the homeowner. All an attacker had to do was send a command to tell the lock to open or close. With just a few lines of code, the researchers built a script that locked and unlocked a smart lock connected to a vulnerable smart hub.

Security

Choice To Pay Ransomware Might Be Simpler Than You'd Think (axios.com) 217

The conventional wisdom about ransomware is that when local governments pay the ransom, it encourages more criminals to launch more attacks. But that's not necessarily the case, experts say. From a report:The costs of recovering from a ransomware attack are often greater than the cost of the ransom. The victims of ransomware attacks are typically targets of opportunity, and cities generally aren't the primary targets. Corporations are -- and they often pay up. "The fact is, paying a ransom does not create a market," said Forrester Research's Josh Zelonis. "There already is a market." Riviera Beach and Lake City, Florida, paid a combined $1.1 million in ransom over about a week in June. Meanwhile, Atlanta spent $17 million restoring systems rather than pay a $50,000 ransom last year. Baltimore is likely to spend $10 million restoring its own systems refusing to pay a $75,000 ransom this year. The disruption to its city services may cost another $8 million.

For some cities, the best response might be to pay the ransom, then use the millions of dollars that would have been spent on recovery to strengthen cyber defenses before the next attack. "If you don't learn from the past, you will end up being ransomed again," said Deborah Golden, the new head of Deloitte's cyber consultancy. Whether a city pays, doesn't pay, or has yet to be attacked, prevention will often save money.

The Almighty Buck

Would You Pay $30 a Month To Check Your Email? (nytimes.com) 219

The year is 2019, and the brainy engineers of Silicon Valley are hunkered down, working on transformative, next-generation technologies like self-driving cars, digital currencies and quantum computing. Meanwhile, the buzziest start-up in San Francisco is ... an expensive email app? From a report: A few months ago, I started hearing about something called Superhuman. It's an invitation-only service that costs $30 a month and promises "the fastest email experience ever made." Marc Andreessen, the influential venture capitalist, reportedly swore by it, as did tech bigwigs like Patrick and John Collison, the founders of Stripe. The app was rumored to have a waiting list of more than 100,000 people. "We have the who's who of Silicon Valley at this point," Superhuman's founder, Rahul Vohra, told me in an interview. The waiting list is actually 180,000 people long, he said, and some people are getting desperate. He showed me a photo of a gluten-free cake sent to Superhuman's office by a person who was hoping to score an invitation. "We have insane levels of virality that haven't been seen since Dropbox or Slack," Mr. Vohra added.

Last month, Superhuman raised a $33 million investment round, led by Mr. Andreessen's firm, Andreessen Horowitz. That valued the company at roughly $260 million -- a steep valuation for an app with fewer than 15,000 customers, but one apparently justified by the company's trajectory and its support among fans, which borders on evangelical. [...] Signing up for Superhuman is not easy. First, you fill out a long questionnaire about your email habits and work flow. Then, if you're approved for access, there's a mandatory session in which a representative gives you a videoconference tutorial. In my case, Mr. Vohra spent a full hour teaching me how to use the app's features. Superhuman, which plugs into your existing email account, works with only Gmail and Google G Suite addresses for now, but the company plans to expand to other providers soon. Some of the app's features -- such as ones that let users undo sending, track when their emails are opened and automatically pull up a contact's LinkedIn profile -- are available in other third-party email plug-ins. But there are bells and whistles that I hadn't seen before.

Like "instant intro," which moves the sender of an introductory email to bcc, saving you from having to manually re-enter that person's address. Or the scheduling feature, which sees that you're typing "next Tuesday" and automatically pulls up your calendar for that day. Superhuman promises to help V.I.P.s get through their inboxes twice as fast. Partly, that's because every command has a keyboard shortcut, so a busy power broker never has to waste precious seconds reaching for the mouse. And partly it's because the app itself is built for speed -- it stores information locally in a user's browser rather than retrieving it from Google's servers, which cuts down on the time required to surf between emails.
Further reading: Superhuman is Spying on You.
China

China Is Forcing Tourists To Install Text-Stealing Malware at its Border (vice.com) 230

Foreigners crossing certain Chinese borders into the Xinjiang region, where authorities are conducting a massive campaign of surveillance and oppression against the local Muslim population, are being forced to install a piece of malware on their phones that gives all of their text messages as well as other pieces of data to the authorities, a collaboration by Motherboard, Suddeutsche Zeitung, the Guardian, the New York Times, and the German public broadcaster NDR has found. From the report: The Android malware, which is installed by a border guard when they physically seize the phone, also scans the tourist or traveller's device for a specific set of files, according to multiple expert analyses of the software. The files authorities are looking for include Islamic extremist content, but also innocuous Islamic material, academic books on Islam by leading researchers, and even music from a Japanese metal band. In no way is the downloading of tourists' text messages and other mobile phone data comparable to the treatment of the Uighur population in Xinjiang, who live under the constant gaze of facial recognition systems, CCTV, and physical searches. [...] The malware news shows that the Chinese government's aggressive style of policing and surveillance in the Xinjiang region has extended to foreigners, too.

"[This app] provides yet another source of evidence showing how pervasive mass surveillance is being carried out in Xinjiang. We already know that Xinjiang residents -- particularly Turkic Muslims -- are subjected to round-the-clock and multidimensional surveillance in the region," Maya Wang, China senior researcher at Human Rights Watch, said. "What you've found goes beyond that: it suggests that even foreigners are subjected to such mass, and unlawful surveillance."

Government

Senate Passes Cybersecurity Bill To Decrease Grid Digitization, Move Toward Manual Control (utilitydive.com) 140

On June 27, the U.S. Senate passed a bipartisan cybersecurity bill that will study ways to replace automated systems with low-tech redundancies to protect the country's electric grid from hackers. Called The Securing Energy Infrastructure Act (SEIA), the bill establishes a two-year pilot program identifying new security vulnerabilities and researching and testing solutions, including "analog and nondigital control systems." The U.S Department of Energy would be required to report back to Congress on its findings. Utility Drive reports: The increase in distributed energy resources can serve load more efficiently, but also offers potential attackers more potential entry points. "Our connectivity is a strength that, if left unprotected, can be exploited as a weakness," Sen. Angus King, I-Maine, who sponsored the bill with Sen. Jim Risch, R-Idaho, said in a statement. Sens. Susan Collins, R-Maine, Martin Heinrich, D-N.M., and Mike Crapo, R-Idaho cosponsored the bill. The House measure is being introduced by Reps. Dutch Ruppersberger, D-Md., and John Carter, R-Texas.
Security

Florida City Fires IT Employee After Paying Ransom Demand Last Week (zdnet.com) 326

Officials from Lake City, Florida, have fired an IT employee last week after the city was forced to approve a gigantic ransomware payment of nearly $500,000 last Monday. The employee, whose name was not released, was fired on Friday, according to local media reports, who cited the Lake City mayor. ZDNet reports: Lake City's IT network was infected with malware on June 10. The city described the incident as a "triple threat." In reality, an employee opened a document they received via email, which infected the city's network with the Emotet trojan, which later downloaded the TrickBot trojan, and later, the Ryuk ransomware. The latter spread to the city's entire IT network and encrypted files. Hackers eventually demanded a ransom to let the city regain access to its systems. The city's leadership approved a ransom payment last Monday, which was paid the next day, on Tuesday. The city's IT staff started decrypting files on the same day.
Security

Germany To Publish Standard on Modern Secure Browsers (zdnet.com) 61

Germany's cyber-security agency is working on a set of minimum rules that modern web browsers must comply with in order to be considered secure. From a report: The new guidelines are currently being drafted by the German Federal Office for Information Security (or the Bundesamt fur Sicherheit in der Informationstechnik -- BSI), and they'll be used to advise government agencies and companies from the private sector on what browsers are safe to use. A first version of this guideline was published in 2017, but a new standard is being put together to account for improved security measures added to modern browsers, such as HSTS, SRI, CSP 2.0, telemetry handling, and improved certificate handling mechanisms -- all mentioned in a new draft released for public debate last week. According to the BSI's new draft, to be considered "secure," a modern browser must follow the following requirements, among others: Must support TLS, must have a list of trusted certificates, must support extended validation (EV) certificates, must verify loaded certificates against a Certification Revocation List (CRL) or an Online Certificate Status Protocol (OCSP); the browser must use icons or color highlights to show when communications to a remote server is encrypted or in plaintext, connections to remote websites running on expired certificates must be allowed only after specific user approval; must support HTTP Strict Transport Security (HSTS) (RFC 6797). Further reading: Germany and the Netherlands To Build the First Ever Joint Military Internet.
Open Source

Linus Torvalds Sees Lots of Hardware Headaches Ahead (devops.com) 205

Linux founder Linus Torvalds "warns that managing software is about to become a lot more challenging, largely because of two hardware issues that are beyond the control of DevOps teams," reports DevOps.com.

An anonymous reader shares their report about Torvalds remarks at the KubeCon + CloudNative + Open Source Summit China conference: The first, Torvalds said, is the steady stream of patches being generated for new cybersecurity issues related to the speculative execution model that Intel and other processor vendors rely on to accelerate performance... Each of those bugs requires another patch to the Linux kernel that, depending on when they arrive, can require painful updates to the kernel, Torvalds told conference attendees. Short of disabling hyperthreading altogether to eliminate reliance on speculative execution, each patch requires organizations to update both the Linux kernel and the BIOS to ensure security. Turning off hyperthreading eliminates the patch management issue, but also reduces application performance by about 15 percent.

The second major issue hardware issue looms a little further over the horizon, Torvalds said. Moore's Law has guaranteed a doubling of hardware performance every 18 months for decades. But as processor vendors approach the limits of Moore's Law, many developers will need to reoptimize their code to continue achieving increased performance. In many cases, that requirement will be a shock to many development teams that have counted on those performance improvements to make up for inefficient coding processes, he said.

Crime

Sting Finds Ransomware Data Recovery Firms Are Just Paying The Ransom (propublica.org) 148

"ProPublica recently reported that two U.S. firms, which professed to use their own data recovery methods to help ransomware victims regain access to infected files, instead paid the hackers. Now there's new evidence that a U.K. firm takes a similar approach."

An anonymous reader quotes their report: Fabian Wosar, a cyber security researcher, told ProPublica this month that, in a sting operation he conducted in April, Scotland-based Red Mosquito Data Recovery said it was "running tests" to unlock files while actually negotiating a ransom payment. Wosar, the head of research at anti-virus provider Emsisoft, said he posed as both hacker and victim so he could review the company's communications to both sides. Red Mosquito Data Recovery "made no effort to not pay the ransom" and instead went "straight to the ransomware author literally within minutes," Wosar said. "Behavior like this is what keeps ransomware running."

Since 2016, more than 4,000 ransomware attacks have taken place daily, or about 1.5 million per year, according to statistics posted by the U.S. Department of Homeland Security. Law enforcement has failed to stem ransomware's spread, and culprits are rarely caught... But clients who don't want to give in to extortion are susceptible to firms that claim to have their own methods of decrypting files. Often, victims are willing to pay more than the ransom amount to regain access to their files if they believe the money is going to a data recovery firm rather than a hacker, Wosar said.

Red Mosquito charged their client four times the actual ransom amount, according to the report -- though after ProPublica followed up, the company "did not respond to emailed questions, and hung up when we called the number listed on its website."

The company then also "removed the statement from its website that it provides an alternative to paying hackers. It also changed 'honest, free advice' to 'simple free advice,' and the 'hundreds' of ransomware cases it has handled to 'many.'"

Slashdot Top Deals