Friday, August 1, 2014

The NSA's Patents

Here are all the NSA's patents, in one searchable database.
If you find something good, tell us all in the comments.

The Fundamental Flaw of USB

This is pretty impressive:
Most of us learned long ago not to run executable files from sketchy USB sticks. But old-fashioned USB hygiene can't stop this newer flavor of infection: Even if users are aware of the potential for attacks, ensuring that their USB's firmware hasn't been tampered with is nearly impossible. The devices don't have a restriction known as "code-signing," a countermeasure that would make sure any new code added to the device has the unforgeable cryptographic signature of its manufacturer. There's not even any trusted USB firmware to compare the code against.
The element of Nohl and Lell's research that elevates it above the average theoretical threat is the notion that the infection can travel both from computer to USB and vice versa. Any time a USB stick is plugged into a computer, its firmware could be reprogrammed by malware on that PC, with no easy way for the USB device's owner to detect it. And likewise, any USB device could silently infect a user's computer.
These are exactly the sorts of attacks the NSA favors.

Debit Card Overcome Hack


Parrish allegedly visited Apple Stores and tried to buy products with four different debit cards, which were all closed by his respective financial institutions. When his debit card was inevitably declined by the Apple Store, he would protest and offer to call his bank -- except, he wasn’t really calling his bank.
So, the complaint says, he would offer the Apple Store employees a fake authorization code with a certain number of digits, which is normally provided by credit card issuers to create a record of the credit or debit override.
Now that this trick is public, how long before stores stop accepting these authorization codes altogether? I'll be that fixing the infrastructure will be expensive.

Clever:

Thursday, July 31, 2014

Pretty good news for privacy-oriented people! BitTorrent unwraps its new instant messaging program that doesn’t store your metadata and helps you with encrypted communication to keep your online conversations private, whether its voice or text communications.
BitTorrent named its Online chat service as "Bleep", a decentralised peer-to-peer voice and text communications platform that offers end-to-end encryption, therefore is completely safe from the prying eyes. In order to spread users’ voice and text conversations, Bleep make use of the BitTorrent distributed network rather than a centralised server.
Unlike Skype or Google Hangouts, Bleep comes with with a completely decentralized design, giving you extremely strong anonymity.
WHY BLEEP?
"We never see your messages or metadata," said Jaehee Lee, the senior product manager for Bleep, in a blog post announcing the new app on Wednesday. "As far as we're concerned, anything you say is 'bleep' to us."
Bleep chat application promises security and privacy of your conversations that go through different nodes of encrypting instant message traffic by using the same decentralized approach which is behind torrents.

For now, the company has released Bleep invite-only pre-alpha for Windows 7 and Windows 8 users, so you can sign up now.
According to the Bleep project head Farid Fadaie, there are two main components to its architecture:
The new peer-to-peer communication platform, which was built on a fully distributed Session Initiation Protocol (SIP) server engine.
The User Interface, a chat-and-voice-enhanced application that will be continuously updated over time to provide a great messaging experience.
"BitTorrent does not track or store information on who is communicating with whom, or when communications happen," Fade said in a post. "We are not even storing data temporarily on servers and then deleting it. We never have the meta data in the first place. Person A finds Person B through other nodes in the network. We never track or store who is looking for whom."
Till now, there is no possible security or privacy weaknesses listed by the company, but if attackers could succeeded in spoofing nodes of the BitTorrent traffic, they would intercept or redirect communications.
BitTorrent chat app uses secure encryption protocols such as curve25519, ed25519 , salsa20, poly1305, and others for end to end encryption of whole communications, which according to him, "should be the new normal in the post-Snowden era".
It is very simple to use. You can sign up now with an email address, phone number, or even as unlisted so that you don't have to provide any personal identifiable information. After that you can invite your friends and can also import your Google address book.

OTHER ENCRYPTED CHAT PLATFORMS
Instant messaging apps that offers end-to-end encryption have surfaced fast in the wake of NSA revelations made by global surveillance whistleblower Edward Snowden.
One such promising service is Invisible.IM chat service, an anonymous Instant Messenger (IM) that leaves no trace as it is supposed to use the Tor anonymizing network to distribute chatter wrapped in OTR encryption.
Also Tor Browser Bundle is currently working on a new Privacy tool called 'Tor Instant Messaging Bundle' (TIMB), that will help you with encrypted communication to keep your online conversations private.

India’s security market to hit $1.06 billion by 2015

Security market in India is expected to touch $ 1.06 billion by 2015 as an increasing number of enterprises invest in these solutions to protect their business especially in the digital world, research firm Gartner today said.

According to Gartner, security vendor revenue (hardware, software and services) in India will grow from $ 882 million in 2013 to $ 953 million in 2014. This is forecast to reach USD 1.06 billion in 2015, it added.

“Organisations are today increasingly more aware of security considerations in India, driven by factors like highly visible security incidents, increasing financially (corporate espionage, underground economy) and politically (hacktivists and nation states) motivated advanced targeted attacks and renewed regulatory focus on security and privacy,” Gartner said.

Of the total market, security services (consulting, implementation, support and managed security services) accounted for more than 55 per cent and this trend is expected to continue into the foreseeable future.

“Enterprises in India that traditionally did not focus on, or invest in, a lot of security technologies are now beginning to realise the implications that a weak security and risk posture can have on their business,” Gartner Principal Research Analyst Sid Deshpande said.

Verticals like banking and financial services, that have had a strong focus on security, are now preparing themselves for IT digitalisation.

They are investing in technology approaches that can enable them to grow their business securely while embracing digital business models, he said.

Though this heightened awareness is creating increased budget allocations for security, there is a skills deficit in the security space in India (relative to the demand), which is a challenge.

Gartner said though security awareness is increasing steadily among enterprises, consumer security sub-segment will display modest growth.

“The importance of data privacy and security is not well understood by consumers in India and this situation is likely to continue to affect market growth in the consumer security space,” Gartner said.

 

Russia demands apple to submit the source code

Just few days after the announcement that Russian government will pay almost 4 million ruble (approximately equal to $111,000) to the one who can devise a reliable technology to decrypt data sent over the Tor, now the government wants something which is really tough.

APPLE & SAP, HAND OVER YOUR SOURCE CODES
Russian government has asked Apple to provide the access to the company’s source code in an effort to assure its iOS devices and Macintoshes aren’t vulnerable to spying. Not just this, the government has demanded the same from SAP as well, which is an enterprise software that manages business operations and customer relationships.
Russia proposed this idea last Tuesday when Communications Minister Nikolai Nikiforov met SAP’s Russian managing director Vyacheslav Orekhov, and Apple’s Russian general manager Peter Engrob Nielsen, and suggested that both the companies give Russian government access to their source code.
Russia has put out a tender on its official government procurement website for anyone who can identify Tor users. The reward of $114,000 seems pretty cheap for this capability. And we now get to debate whether 1) Russia cannot currently deaonymize Tor users, or 2) Russia can, and this is a ruse to make us think they can't.

Conference on Deception

There was a conference on deception earlier this month. Sophie Van Der Zee has a summary of the sessions.