Security

New Flaws In 4G, 5G Allow Attackers To Intercept Calls and Track Phone Locations (techcrunch.com) 46

An anonymous reader quotes a report from TechCrunch: A group of academics have found three new security flaws in 4G and 5G, which they say can be used to intercept phone calls and track the locations of cell phone users. The findings are said to be the first time vulnerabilities have affected both 4G and the incoming 5G standard, which promises faster speeds and better security, particularly against law enforcement use of cell site simulators, known as "stingrays." But the researchers say that their new attacks can defeat newer protections that were believed to make it more difficult to snoop on phone users. [Rafiul Hussain, one of the co-authors of the paper, along with Ninghui Li and Elisa Bertino at Purdue University, and Mitziu Echeverria and Omar Chowdhury at the University of Iowa are set to reveal their findings at the Network and Distributed System Security Symposium in San Diego on Tuesday.

The paper, seen by TechCrunch prior to the talk, details the attacks: the first is Torpedo, which exploits a weakness in the paging protocol that carriers use to notify a phone before a call or text message comes through. The researchers found that several phone calls placed and cancelled in a short period can trigger a paging message without alerting the target device to an incoming call, which an attacker can use to track a victim's location. Knowing the victim's paging occasion also lets an attacker hijack the paging channel and inject or deny paging messages, by spoofing messages like Amber alerts or blocking messages altogether, the researchers say. Torpedo opens the door to two other attacks: Piercer, which the researchers say allows an attacker to determine an international mobile subscriber identity (IMSI) on the 4G network; and the aptly named IMSI-Cracking attack, which can brute force an IMSI number in both 4G and 5G networks, where IMSI numbers are encrypted.
AT&T, Verizon, Sprint and T-Mobile are all affected by Torpedo, "and the attacks can be carried out with radio equipment costing as little as $200," the report adds. One U.S. network is reportedly vulnerable to the Piercer attack, but the researcher wouldn't name which one.
Australia

Australian Email Service FastMail Says It is Losing Customers and Facing Calls To Move Operations Outside of the Country Over Local Anti-Encryption Laws (itnews.com.au) 65

An anonymous reader shares a report: Email provider FastMail says it has lost customers and faces "regular" requests to shift its operations outside Australia following the passage of anti-encryption laws. The Victorian company, which offers ad-free email services to users in 150 countries, told a senate committee that the now-passed laws were starting to bite.

"The way in which [the laws] were introduced, debated, and ultimately passed ... creates a perception that Australia has changed - that we are no longer a country which respects the right to privacy," FastMail CEO Bron Gondwana said. "We have already seen an impact on our business caused by this perception. Our particular service is not materially affected as we already respond to warrants under the Telecommunications Act." "Still, we have seen existing customers leave, and potential customers go elsewhere, citing this bill as the reason for their choice. We are [also] regularly being asked by customers if we plan to move."

Android

Android Is Helping Kill Passwords on a Billion Devices (wired.com) 123

The FIDO Alliance -- a consortium that develops open source authentication standards -- has been pushing to expand its secure login protocols to make seamless logins a reality for several years. Today, it has hit the jackpot: Google. From a report: On Monday, Google and the FIDO Alliance announced that Android has added certified support for the FIDO2 standard, meaning that the vast majority of devices running Android 7 or later will now be able to handle password-less logins in mobile browsers like Chrome. Android already offered secure FIDO login options for mobile apps, where you authenticate using a phone's fingerprint scanner or with a hardware dongle like a YubiKey. But FIDO2 support will make it possible to use these easy authentication steps for web services in a mobile browser instead of laboriously typing in your password every time you want to log in. Web developers can now design their sites to interact with Android's FIDO2 management infrastructure.
Network

ICANN Warns of 'Ongoing and Significant' Attacks Against Internet's DNS Infrastructure (techcrunch.com) 94

The internet's address book keeper has warned of an "ongoing and significant risk" to key parts of the domain name system infrastructure, following months of increased attacks. From a report: The Internet Corporation for Assigned Names and Numbers, or ICANN, issued the notice late Friday, saying DNS, which converts numerical internet addresses to domain names, has been the victim of "multifaceted attacks utilizing different methodologies." It follows similar warnings from security companies and the federal government in the wake of attacks believe to be orchestrated by nation state hackers.

[...] ICANN's chief technology officer David Conrad told the AFP news agency that the hackers are "going after the Internet infrastructure itself." The internet organization's solution is calling on domain owners to deploy DNSSEC, a more secure version of DNS that's more difficult to manipulate. DNSSEC cryptographically signs data to make it more difficult -- though not impossible -- to spoof.

Verizon

Verizon Asks FCC To Let It Lock New Smartphones For 60 Days (theverge.com) 81

Verizon is asking the FCC to let it keep new smartphones locked to its network for 60 days, as part of an initiative to prevent identify theft and fraud. "After the 60-day period, the phones would unlock automatically, the telecom says in a note published to its website and authored by Ronan Dunne, Verizon's executive vice president," reports The Verge. "Verizon says it should have the authority to do this under the so-called 'C-block rules' put in place following the FCC's 2008 wireless spectrum auction." From the report: "We believe this temporary lock on new phones will protect our customers by limiting the incentive for identity theft. At the same time, a temporary lock will have virtually no impact on our legitimate customers' ability to use their devices," Dunne writes. "Almost none of our customers switch to another carrier within the first 60 days. Even with this limited fraud safety check, Verizon will still have the most consumer-friendly unlocking policy in the industry. All of our main competitors lock their customers' new devices for a period of time and require that they are fully paid off before unlocking."

Verizon is just putting itself in line with the rest of the industry here. AT&T already requires your phone be activated for 60 days for you to unlock it, and the company even requires you to wait two weeks to unlock your old phone if you're upgrading to a new one. T-Mobile requires you wait 40 days, and also limits users to two unlocks per year per line. Sprint has a 50-day limit, and only unlocks devices from the onset if the phones are prepaid.

Medicine

Scientists Release Controversial Genetically Modified Mosquitoes In High-Security Lab (npr.org) 184

An anonymous reader quotes a report from NPR: Scientists have launched a major new phase in the testing of a controversial genetically modified organism: a mosquito designed to quickly spread a genetic mutation lethal to its own species, NPR has learned. For the first time, researchers have begun large-scale releases of the engineered insects, into a high-security laboratory in Terni, Italy. The goal is to see if the mosquitoes could eventually provide a powerful new weapon to help eradicate malaria in Africa, where most cases occur. The lab was specially built to evaluate the modified insects in as close to a natural environment as possible without the risk of releasing them into the wild, about which there are deep concerns regarding unforeseen effects on the environment.

To prevent any unforeseen effects on the environment, scientists have always tried to keep genetically engineered organisms from spreading their mutations. But in this case, researchers want the modification to spread. So they engineered mosquitoes with a "gene drive." A gene drive is like a "selfish gene," says entomologist Ruth Mueller, because it doesn't follow the normal rules of genetics. Normally, traits are passed to only half of all offspring. With the gene drive, nearly all the progeny inherit the modification. Researchers created the mosquitoes by using the powerful new gene-editing technique known as CRISPR, which Mueller likens to a "molecular scissor which can cut at a specific site in the DNA." The cut altered a gene known as "doublesex," which is involved in the sexual development of the mosquitoes. While genetically female, the transformed insects have mouths that resemble male mosquito mouths. That means they can't bite and so can't spread the malaria parasite. In addition, the insects' reproductive organs are deformed, which means they can't lay eggs. As more and more female mosquitoes inherit two copies of the modification, more and more become sterile.
Critics fear that these gene-drive mosquitoes could run amok and wreak havoc in the wild. Not only could the insects cause a negative effect on crops by eliminating important pollinators, but the insects' population crash could also lead to other mosquitos coming with other diseases.

Mueller assures NPR's Rob Stein that the lab the mosquitos are in is very secure, adding that even if the mosquitos did escape they would not be able to survive Italy's climate. "To enter the most secure part of the facility, Mueller punches a security code into a keypad to open a sliding glass door," reports NPR. "As the door seals, a powerful blower makes sure none of the genetically modified mosquitoes inside escape. Anyone entering must don white lab coats to make it easier to spot any mosquitoes that might try to hitch a ride out of the lab and must pass through a second sealed door and blower."
Privacy

2.7 Million Patient Phone Call Recordings Left Exposed Online (thenextweb.com) 45

Slashdot reader krenaud tipped us off to this story from The Next Web: The audio recordings of 2.7 millions calls made to 1177 Vardguiden -- Sweden's healthcare hotline -- were left exposed to anyone online, according to Swedish tech publication Computer Sweden. The 170,000 hours of incredibly sensitive calls were stored on an open web server without any encryption or authentication, leaving personal information completely exposed for anyone with a web browser....

The calls included sensitive information about patients' diseases and ailments, medication, and medical history. Some examples had people describing their children's symptoms and giving their social security numbers. Some of the files include the phone numbers the calls were made from. Around 57,000 numbers appear in the database and many of those are the callers' personal numbers, making it easy to match information with a particular person.

When reached for comment, the CEO of the subcontractor receiving the calls "denied it happened."
Bitcoin

Once Hailed As Unhackable, Blockchains Are Now Getting Hacked (technologyreview.com) 90

schwit1 shares a report from MIT Technology Review: Early last month, the security team at Coinbase noticed something strange going on in Ethereum Classic, one of the cryptocurrencies people can buy and sell using Coinbase's popular exchange platform. Its blockchain, the history of all its transactions, was under attack. An attacker had somehow gained control of more than half of the network's computing power and was using it to rewrite the transaction history. That made it possible to spend the same cryptocurrency more than once -- known as "double spends." The attacker was spotted pulling this off to the tune of $1.1 million. Coinbase claims that no currency was actually stolen from any of its accounts. But a second popular exchange, Gate.io, has admitted it wasn't so lucky, losing around $200,000 to the attacker (who, strangely, returned half of it days later).

Just a year ago, this nightmare scenario was mostly theoretical. But the so-called 51% attack against Ethereum Classic was just the latest in a series of recent attacks on blockchains that have heightened the stakes for the nascent industry. [...] In short, while blockchain technology has been long touted for its security, under certain conditions it can be quite vulnerable. Sometimes shoddy execution can be blamed, or unintentional software bugs. Other times it's more of a gray area -- the complicated result of interactions between the code, the economics of the blockchain, and human greed. That's been known in theory since the technology's beginning. Now that so many blockchains are out in the world, we are learning what it actually means -- often the hard way.

Android

Facebook Will Shut Down Its Spyware VPN App Onavo (techcrunch.com) 27

An anonymous reader quotes a report from TechCrunch: Facebook will end its unpaid market research programs and proactively take its Onavo VPN app off the Google Play store in the wake of backlash following TechCrunch's investigation about Onavo code being used in a Facebook Research app the sucked up data about teens. The Onavo Protect app will eventually shut down, and will immediately cease pulling in data from users for market research though it will continue operating as a Virtual Private Network in the short-term to allow users to find a replacement. Facebook has also ceased to recruit new users for the Facebook Research app that still runs on Android but was forced off of iOS by Apple after we reported on how it violated Apple's Enterprise Certificate program for employee-only apps. Existing Facebook Research app studies will continue to run, though. Onavo billed itself as a way to "limit apps from using background data and use a secure VPN network for your personal info" but also noted it would collect the "Time you spend using apps, mobile and Wi-Fi data you use per app, the websites you visit, and your country, device and network type." A Facebook spokesperson confirmed the change and provided this statement: "Market research helps companies build better products for people. We are shifting our focus to reward-based market research which means we're going to end the Onavo program."
Programming

Experts Find Serious Problems With Switzerland's Online Voting System (vice.com) 63

An anonymous reader quotes a report from Motherboard: Switzerland made headlines this month for the transparency of its internet voting system when it launched a public penetration test and bug bounty program to test the resiliency of the system to attack. But after source code for the software and technical documentation describing its architecture were leaked online last week, critics are already expressing concern about the system's design and about the transparency around the public test. Cryptography experts who spent just a few hours examining the leaked code say the system is a poorly constructed and convoluted maze that makes it difficult to follow what's going on and effectively evaluate whether the cryptography and other security measures deployed in the system are done properly.

"Most of the system is split across hundreds of different files, each configured at various levels," Sarah Jamie Lewis, a former security engineer for Amazon as well as a former computer scientist for England's GCHQ intelligence agency, told Motherboard. "I'm used to dealing with Java code that runs across different packages and different teams, and this code somewhat defeats even my understanding." She said the system uses cryptographic solutions that are fairly new to the field and that have to be implemented in very specific ways to make the system auditable, but the design the programmers chose thwarts this. "It is simply not the standard we would expect," she told Motherboard. [...] It isn't just outside attackers that are a concern; the system raises the possibility for an insider to intentionally misconfigure the system to make it easier to manipulate, while maintaining plausible deniability that the misconfiguration was unintentional.
"Someone could wire the thing in the wrong place and suddenly the system is compromised," said Lewis, who is currently executive director of the Open Privacy Research Society, a Canadian nonprofit that develops secure and privacy-enhancing software for marginalized communities. "And when you're talking about code that is supposed to be protecting a national election, that is not a statement someone should be able to make." "You expect secure code to be defensively written that would prevent the implementers of the code from wiring it up incorrectly," Lewis told Motherboard. But instead of building a system that doesn't allow for this, the programmers simply added a comment to their source code telling anyone who compiles and implements it to take care to configure it properly, she said.

The online voting system was developed by Swiss Post, the country's national postal service, and the Barcelona-based company Scytl. "Scytl claims the system uses end-to-end encryption that only the Swiss Electoral Board would be able to decrypt," reports Motherboard. "But there are reasons to be concerned about such claims."
Bug

Google Researchers Say Software Alone Can't Mitigate Spectre Chip Flaws (siliconrepublic.com) 98

A group of researchers say that it will be difficult to avoid Spectre bugs in the future unless CPUs are dramatically overhauled. From a report: Google researchers say that software alone is not enough to prevent the exploitation of the Spectre flaws present in a variety of CPUs. The team of researchers -- including Ross McIlroy, Jaroslav Sevcik, Tobias Tebbi, Ben L Titzer and Toon Verwaest -- work on Chrome's V8 JavaScript engine. The researchers presented their findings in a paper distributed through ArXiv and came to the conclusion that all processors that perform speculative execution will always remain susceptible to various side-channel attacks, despite mitigations that may be discovered in future.
Security

Linux Foundation Launches ELISA, an Open Source Project For Building Safety-Critical Systems (venturebeat.com) 36

The Linux Foundation today launched Enabling Linux in Safety Applications (ELISA), an open source project comprising tools intended to help companies build and certify Linux-based systems whose failure could result in loss of human life, significant property damage, or environmental damage. From a report: In partnership with British chip designer Arm, BMW, autonomous platforms company Kuka, Linutronix, and Toyota, ELISA will work with certification and standardization bodies in "multiple industries" to establish ways Linux can form the foundation of safety-critical systems across industries.
Security

Severe Vulnerabilities Uncovered In Popular Password Managers (zdnet.com) 122

chiefcrash shares a report from ZDNet: Independent Security Evaluators (ISE) published an assessment on Tuesday with the results of testing with several popular password managers, including LastPass and KeePass. The team said that each password management solution "failed to provide the security to safeguard a user's passwords as advertised" and "fundamental flaws" were found that "exposed the data they are designed to protect."

The vulnerabilities were found in software operating on Windows 10 systems. In one example, the master password which users need to use to access their cache of credentials was stored in PC RAM in a plaintext, readable format. ISE was able to extract these passwords and other login credentials from memory while the password manager in question was locked. It may be possible that malicious programs downloaded to the same machine by threat actors could do the same.
The report has summarized the main findings based on each password management solution. Here's what ISE had to say about LastPass and KeePass -- two of the most popular password managers available:

"LastPass obfuscates the master password while users are typing in the entry, and when the password manager enters an unlocked state, database entries are only decrypted into memory when there is user interaction. However, ISE reported that these entries persist in memory after the software enters a locked state. It was also possible for the researchers to extract the master password and interacted-with password entries due to a memory leak."

"KeePass scrubs the master password from memory and is not recoverable. However, errors in workflows permitted the researchers from extracting credential entries which have been interacted with. In the case of Windows APIs, sometimes, various memory buffers which contain decrypted entries may not be scrubbed correctly."
Privacy

Cybersecurity Expert Questions Existence of Embedded Camera On SIA's Inflight Entertainment Systems (yahoo.com) 81

Vitaly Kamluk, an information security expert and a high-ranking executive of cybersecurity company Kaspersky Lab, went on Twitter with concerns about an embedded camera in Singapore Airlines' (SIA) inflight entertainment systems. He tagged SIA in his post on Sunday, asking the airline to clarify how the camera is being used. Yahoo News reports: SIA quickly allayed his fears of unwanted surveillance by assuring Kamluk that the cameras have been disabled, with no plans to use them in the future. Not all of their devices sport the camera, though -- SIA explained that only some of its newer inflight entertainment systems come with cameras embedded in the hardware. In another tweet, SIA affirmed that the cameras were already built in by the original equipment manufacturers in newer inflight entertainment systems. Kamluk recommended that it's best to disable the cameras physically -- with stickers, for example -- to provide better peace of mind. In 2017, entertainment device developer Panasonic Avionics said it was studying how eye tracking can be used for a better passenger experience. As the report mentions, "Cameras can be used for identity recognition on planes, which in turn, would allow for in-flight biometric payment (much like Face ID on Apple devices) and personalized services."
United Kingdom

Britain and Germany Will Not Ban Huawei, Citing Lack of Spying Evidence (reuters.com) 240

An anonymous Slashdot reader writes from a report via Reuters: Despite persistent U.S. allegations of Chinese state spying, Britain said it is able to manage the security risks of using Huawei telecom equipments and has not seen any evidence of malicious activity by the company, a senior official said on Wednesday. Asked later whether Washington had presented Britain with any evidence to support its allegations, he told reporters: "I would be obliged to report if there was evidence of malevolence [...] by Huawei. And we're yet to have to do that. So I hope that covers it."

At the same time, German officials have told The Wall Street Journal that the country has made a "preliminary decision" to allow Huawei to bid on contracts for 5G networking. Catering to the surging populism, the U.S. has accused Huawei and other Chinese telecom equipments, along with European cars, as national security risks, even though the National Security Agency, American's cyber spying agency, was found to have wiretapped German Chancellor Angela Merkel, conducted economic espionage against France, and hacked into Chinese networks. Earlier this week, beleaguered Huawei founder Ren Zhengfei described the continued investigations by the U.S. into the Chinese firm -- including the arrest of his daughter and company CFO, Meng Wanzhou -- as politically motivated.

Facebook

Microsoft Edge Lets Facebook Run Flash Code Behind Users' Backs (zdnet.com) 127

An anonymous reader writes: Microsoft's Edge browser contains a secret whitelist that lets Facebook run Adobe Flash code behind users' backs. The whitelist allows Facebook's Flash content to bypass Edge security features such as the click-to-play policy that normally prevents websites from running Flash code without user approval beforehand.

The whitelist isn't new. It existed in Edge before, and prior to February 2018, it included 58 entries, including domains and subdomains for Microsoft's main site, the MSN portal, music streaming service Deezer, Yahoo, and Chinese social network QQ. The list was narrowed down to only two Facebook domains (facebook.com and apps.facebook.com) after a Google security researcher found that the whitelist mechanism had some security issues. The bug report also contains the original version of the whitelist, with all the 58 domains.

Microsoft

Microsoft Says Discovers Hacking Targeting Democratic Institutions in Europe (reuters.com) 71

Microsoft said today it had discovered hacking targeting democratic institutions, think tanks and non-profit organizations in Europe and plans to offer a cyber security service to several countries to close security gaps. From a report: The hacks occurred between September and December 2018, targeting employees of the German Council on Foreign Relations and European offices of The Aspen Institute and The German Marshall Fund, the company said. Microsoft said it found out about the hacks through the company's Threat Intelligence Center and Digital Crimes Unit, and the hacks targeted 104 employee accounts in Belgium, France, Germany, Poland, Romania, and Serbia. Hackers in most cases create malicious weblinks and spoofed email addresses that look legitimate, aiming to gain access to employee credentials and deliver malware, the company said.
Security

China Has Abandoned a Cybersecurity Truce With the US, Report Says (bloomberg.com) 114

Cybersecurity firm Crowdstrike says China has largely abandoned a hacking truce negotiated by Barack Obama as President Trump embarked on a trade war with Beijing last year. "A slowdown in Chinese hacking following the cybersecurity agreement Obama's administration secured in 2015 appears to have been reversed, the firm said in a report released Tuesday that reviewed cyber activity by U.S. adversaries in 2018," reports Bloomberg. From the report: The report comes as the Trump administration seeks to reach a trade deal with China, including provisions on intellectual property theft, ahead of a March 1 deadline. Trump has said he may extend that deadline and hold off on increasing tariffs on Chinese imports if there's progress in the talks. China's hacking targets in 2018 included telecommunications systems in the U.S. and Asia, according to Crowdstrike. Groups linked to Iran and Russia also appeared to target telecommunications, a sector that yields "the most bang for your buck" for hackers due to the large number of users that can be accessed after breaching a single network, Meyers said.

The findings align with concern in the U.S. about telecommunications security as the country transitions to the next generation of mobile networks and the Trump administration seeks to secure so-called 5G technology from foreign intelligence gathering. The administration has expressed particular concern about the spread of products made by the Chinese firm Huawei Technologies Co.
The report also mentions the increased cyber activity in other parts of the world. "Iran focused much of its cyber activity on Middle Eastern and North African countries while Russia engaged in intelligence collection and information operations worldwide," the report says. "North Korea deployed hackers for financial gain and intelligence collection, while China targeted sectors including technology, manufacturing and hospitality."
Windows

Linux Subsystem Files To Become Accessible via Windows File Explorer (zdnet.com) 123

One of Windows Subsystem for Linux's more annoying tricks is it's hard to get at your Linux files from Windows. From a report: Oh, you can do it, but you take a real chance of ruining the files. To quote Microsoft, "DO NOT, under ANY circumstances, access, create, and/or modify files in your distro's filesystem using Windows apps, tools, scripts, consoles, etc." In the forthcoming Windows 10 April 2019 Update, aka Windows 10 19H1, this Linux file problem will finally be fixed. According to Craig Loewen, a Microsoft programming manger working on Windows Subsystem for Linux (WSL), "The next Windows update is coming soon and we're bringing exciting new updates to WSL with it! These include accessing the Linux file system from Windows, and improvements to how you manage and configure your distros in the command line."
Microsoft

Microsoft Releases Windows 10 Timeline Extension For Google Chrome (windowscentral.com) 39

Microsoft has released an official Timeline extension for Google Chrome called "Web Activities" that brings Timeline integration to Google's web browser. From a report: Just like with Microsoft Edge, this new extension syncs web browsing activities with the Timeline feature on Windows 10, making it easier to pick up old activities and search through webpages you've visited recently. The extension is available now in the Chrome Web Store, and ties with your Microsoft Account.

Slashdot Top Deals