Security Bits – 21 Sep 2018
Followups
- Following on from Apple’s belated removal of Adware Doctor for steal users browser history, Apple have now booted three apps from TrendMicro for doing the same, specifically Dr. Cleaner, Dr. Antivirus, and Dr. Archiver. TrendMicro insist it was an innocent mistake due to code re-use, and not malicious or nefarious in any way — tidbits.com/… & arstechnica.com/…
- Following on from the two big recent UK hacks (Ticket Master & British Airways), the same criminal gang have struck again, this time breaching all credit card transactions on NewEgg for a month — www.macobserver.com/…
Security Medium 1 — A New Cold Boot Attack Against Almost All Laptops
Security researchers have discovered a new variant of the old so-called cold boot attack that affects most laptops. The attack exploits a flaw in how motherboards deal with reboots from devices that are asleep. Or, to be more specific, devices that are in the shallowest of the two sleep states, i.e. devices that are suspended. Devices that are in the deeper hibernation level of sleep are not vulnerable.
If an attacker can get physical access to a laptop that’s currently suspended they can force it to reboot into a special OS of their devising that prevents RAM being scrubbed on reboot, and then uses almost no memory itself, preserving the data from the previously running OS in memory, including the decryption key for full disk encryption. With that key the attacker can then decrypt the disk and help themselves to all the data on the disk.
There are two obvious silver linings, firstly, an attacker needs to physical access to the targeted device while it is in the less deep of the two sleep modes, and they need that access for some time. Secondly, this is not like some previous FireWire-based attacks that could steal memory in seconds simply by plugging a dongle into a laptop for a few seconds and then removing it. You’ve not going to be able to execute this attack while the victim turns their back for a few seconds to get something form a shelf!
The simplest way to protect yourself is not to let your laptop out of your sight while it’s suspended. OS vendors are working on work-arounds, but that may not be so straightforward since the problem is with the very design of the power management APIs used by motherboards.
Links
Security Medium 2 — Apple’s Trust Score Anti-Fraud Feature
Apple updated it’s privacy statement for iOS 12 to inform users that it now calculates something it calls a Trust Score to help battle fraud on their stores. This score is a single number that is calculated on-device, and then sent to Apple’s servers where it is kept for a limited amount of time.
Apple do not detail the exact algorithm they use to generate this score. There’s a very good reason for that, if they did then bad guys could easily fake ‘good’ behaviour and utterly defeat the whole purpose of the feature. While they don’t tell us everything that goes into the algorithm, let alone how all that information does get translated into the final score, they do tell us that the data used includes information about calls and emails. Apple stress that all calculation is done on-device, and only the final numeric score is ever sent to Apple. That score cannot be reverse-engineered to reveal call or email information, and is only kept for a short time.
This seems eminently sensible to me, and it seems to me that Apple have done this right — do it on the device, and only upload the final answer to the cloud. I think it’s significant that Apple were completely up-front about this, and laid out what they are trying to achieve, and what data they are using. We know about this because Apple told us, not because someone caught them doing something in secret, and I think that matters a lot in how I feel about it.
Links
Notable Security Updates
- Patch Tuesday has been and gone with important security updates form Microsoft Adobe including updates to Windows and Flash — krebsonsecurity.com/…
- The Windows patch includes a fix to a zero-day that is being actively exploited in the wild, so update promptly! — nakedsecurity.sophos.com/…
- Apple releases iOS 12, watchOS 5, tvOS 12 & Safari 12, all of which are security updates as well as feature updates — www.us-cert.gov/…
- Apple locks out Safari Extensions –– developer.apple.com/…
- Safari 12 includes improved tracking prevention — www.securityweek.com/… & www.macobserver.com/…
Notable News
- 🇺🇸 It is now free to freeze and un-freeze your credit file in all states in the US — krebsonsecurity.com/…
- 🇪🇺 The EU Parliament has approved a somewhat amended version of the controversial new EU-wide copyright act. At issue are articles 11 and 13 which require a so-called link tax, and upload filters — www.theverge.com/…
- 🇺🇸 New US defence policies allow the US military to defend forward and launch pre-emptive cyber attacks. (Editorial by Bart This is some impressive, in all the wrong ways, Orwellian newspeak!) — nakedsecurity.sophos.com/…
- Security researchers are warning of a subtle URL re-writing bug in Safari. TL;DR – don’t enter any information into a page of the loading bar has not completed, or if there is no padlock — nakedsecurity.sophos.com/…
- Unrelated to the above bug, another Safari bug has been found that allows some maliciously crafted HTML+CSS to crash iPhones & Macs — www.macobserver.com/…
- Google has added a built-in password generator and manager to Chrome — nakedsecurity.sophos.com/…
- Belgian security researchers have found a significant vulnerability in Tesla Key-fobs — nakedsecurity.sophos.com/…
- 🇺🇸 Four major US cell carriers (AT&T, Verizon, T-Mobile & Sprint) have gotten together and announced their plans to build an online identity system which they are calling Project Verify. Users will be able to use project verify either as an alternative to passwords, or as a second factor, on sites that choose to implement the technology — krebsonsecurity.com/… & nakedsecurity.sophos.com/…
- 🇺🇸 The CA state senate has passed a bill which makes a start at regulating the security of IoT devices. The bill is now awaiting the governor’s signature or veto — nakedsecurity.sophos.com/…
- Owners of WesternDigital MyCloud NAS drives beware, security researcher reveal that the company has failed to patch a serious vulnerability in these drives for over a year — nakedsecurity.sophos.com/…
Suggested Reading
- PSAs, Tips & Advice
- iOS: How to AirDrop Passwords Between Devices — www.macobserver.com/…
- The iOS 12 Security Guide is Out Now — www.macobserver.com/…
- iOS 12 is here: these are the security features you need to know about — nakedsecurity.sophos.com/…
- How to Enable AutoFill Passwords in iOS 12 — www.macobserver.com/…
- 🇺🇸 AMBER Alerts on your iPhone: What they are and how to manage them — www.imore.com/…
- 🇬🇧 In the UK, Action Fraud, a joint initiative between the London Met and the National Fraud Intelligence Bureau is warning of an on-going phishing attack targeting Netflix users. Be on the lookout, and don’t ever enter any passwords or other sensitive information into a page you opened by clicking a link in an email! — nakedsecurity.sophos.com/…
- Notable Breaches & Privacy Violations
- Veeam leaves MongoDB database wide open, exposes 445m records — nakedsecurity.sophos.com/…
- 🇺🇸 GovPayNow.com Leaks 14M+ Records — krebsonsecurity.com/…
- Years on, third party apps still exposing Grindr users’ locations — nakedsecurity.sophos.com/…
- A misconfigured MongoDB database exposed over 43GB of data on over 10m users. Its not clear who the database belonged to, but there is circumstantial evidence it was discount site SaverSpy — nakedsecurity.sophos.com/…
- News
- Election-related Security News:
- 🇺🇸 ‘Only paper ballots by 2020!’ call experts after election tampering — nakedsecurity.sophos.com/…
- 🇺🇸 Georgia says switching back to all-paper voting is logistically impossible — arstechnica.com
- 🇺🇸 Lawmaker: US Senate, staff targeted by state-backed hackers — apnews.com/…
- How Facebook wants to protect political campaigners from hacking — nakedsecurity.sophos.com/…
- Microsoft purges 3,000 tech support scams hiding on TechNet — nakedsecurity.sophos.com/…
- 🇺🇸 State Department scores an F on 2FA security — nakedsecurity.sophos.com/…
- 91 “child friendly” Android apps accused of exploitation — nakedsecurity.sophos.com/…
- Bitcoin flaw could have allowed dreaded 51% takeover — nakedsecurity.sophos.com/…
- Election-related Security News:
- Opinion & Analysis
- Propellor Beanie Territory
You never told that last joke/cartoon.
Yeah – it wasn’t that funny…