Awareness and Knowledge means security.
Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts
Monday, January 13, 2014
Saturday, December 7, 2013
Microsoft Beefs Up Encryption After NSA Spying Reports
- In response to reports that the feds are spying on tech firms' data as it moves between servers, Microsoft today pledged to step up encryption across its services.
- If true, NSA spying could "seriously undermine confidence in the security and privacy of online communications," Microsoft's general counsel, Brad Smith, said in a blog post.
- Smith said Office 365 and Outlook.com customer content is already encrypted when traveling between customers and Microsoft, while most Office 365 workloads as well as Windows Azure storage are now encrypted in transit between data centers.
- The NSA denied those allegations. "NSA is a foreign intelligence agency. And we're focused on discovering and developing intelligence about valid foreign intelligence targets only."
- Read more at ..http://www.pcmag.com/article2/0,2817,2427962,00.asp?mailingID=4A8C526FE94DD7A9EACC9565528CC0A8
Thursday, November 21, 2013
Snowden Likely Used SSH Keys to Access Classified NSA Data
Using public statements from Edward Snowden and NSA officials, digital-certificate firm Venafi pieces together a likely scenario for how the former contractor accessed classified documents.
Edward Snowden has not publicly stated how he leveraged his privileged access to certain servers and top-secret information at the National Security Agency into a wider fishing expedition, netting classified secrets that he had no clearance to access. The NSA hasn't provided much insight either.This week, however, security researchers at certificate-management firm Venafi threw their collective hat into the ring, posting an analysis stating that Snowden likely used authentication keys to give his account privileged access to other servers in the network. Secure shell (SSH) keys are frequently used by system administrators to log into remote computers without a password, and Snowden likely gained access to others' keys or to privileged accounts and inserted his own keys, the company said.
The most significant clue is General Keith Alexander's testimony in which the NSA chief reportedly stated that Snowden "fabricated digital keys" to gain access to classified systems, Jeff Hudson, CEO of Venafi, told eWEEK.
"It all comes back to one thing: 'He fabricated the SSH keys,'" he said. "What he did was he allowed himself access to other systems and in the process he elevated his privilege."
More news at http://www.eweek.com/security/snowden-likely-used-ssh-keys-to-access-classified-nsa-data-venafi.html
Sunday, October 20, 2013
Tor Stands Tall Against the NSA
The National Security Agency tried to crack the encryption protecting the Tor network -- known as a bulletproof vehicle for anonymous communication -- but was unable to do so, according to news reports based on revelations provided by former NSA systems administrator Edward Snowden.
Source Tech newsIt seems fairly clear that the U.S. security agency has been trying to hack into Tor for some time. "The real question here concerns who the exploit was targeting," suggested Ken Westin, founder of mobileprivacy.org. "Was is it people law enforcement had probable cause to monitor, or was it a blanket exploit that targeted all users of Tor?" It's pretty reasonable to assume the latter, Westin opined.
Follow it here on http://www.technewsworld.com/story/79133.html
Wednesday, October 16, 2013
Whats App is not secure due to weak encryption policies
A serious vulnerability in WhatsApp allows anyone who is able to eavesdrop on WhatsApp connection to decrypt users' messages.
Whatsapp, the mobile application for instant messaging platform has become one of the main communication tools of the present day and its popularity makes it attractive for security researchers and hackers.
This time it is debated in the protection of the messages exchanged through the application, thanks to a vulnerability in the crypto implementation they can be intercepted by an attacker.
Thijs Alkemade is a computer science student at Utrecht University in The Netherlands who works on the open source Adium instant messaging project, during its research activity he disclosed a serious issue in the encryption used to secure WhatsApp messages.
In the post titled "Piercing Through WhatsApp’s Encryption" Alkemade remarked that Whatsapp has been plagued by numerous security issues recently, easily stolen passwords, unencrypted messages and even a website that can change anyone’s status.
"You should assume that anyone who is able to eavesdrop on your WhatsApp connection is capable of decrypting your messages, given enough effort. You should consider all your previous WhatsApp conversations compromised. There is nothing a WhatsApp user can do about this but expect to stop using it until the developers can update it." states the researcher.
An attacker sniffing a WhatsApp conversation is able to recover most of the plaintext bytes sent, WhatsApp uses RC4 software stream cipher to generate a stream of bytes that are encrypted with the XOR additive cipher.
The mistakes are:
- The same encryption key in both directions
- The same HMAC key in both directions
Below the trick used by the researcher to reveal the messages sent with WhatsApp exploiting first issue:
WhatsApp adopts the same key for the incoming and the outgoing RC4 stream, "we know that ciphertext byte i on the incoming stream xored with ciphertext byte i on the outgoing stream will be equal to xoring plaintext byte i on the incoming stream with plaintext byte i of the outgoing stream. By xoring this with either of the plaintext bytes, we can uncover the other byte."
The technique doesn't directly reveal all bytes but works in many cases, another element that advantage the attacker is that messages follow the same structure and are easy to predict starting from the portion of plaintext that is disclosed.
The second issue related to the HMAC id more difficult to exploit, Alkemade said WhatsApp also uses the same HMAC key in both directions, another implementation error that puts messages at risk, but is more difficult to exploit.
The MAC is used to detect data alteration but it is not enough to detect all forms of tampering, the attacker potentially could manipulate any message.
"TLS counters this by including a sequence number in the plaintext of every message and by using a different key for the HMAC for messages from the server to the client and for messages from the client to the server. WhatsApp does not use such a sequence counter and it reuses the key used for RC4 for the HMAC."
Alkemade is very critical to the development team of the popular platform:
“There are many pitfalls when developing a streaming encryption protocol. Considering they don’t know how to use a xor correctly, maybe the WhatsApp developers should stop trying to do this themselves and accept the solution that has been reviewed, updated and fixed for more than 15 years, like TLS,” he said.
I agree with the thinking of the researcher, security for applications such as WhatsApp is crucial given its level of penetration, it is true that the interest of the scientific community and cybercrime will surely lead them to discover new vulnerabilities to which WhatsApp have to provide a quick solution.
Alkemade confirmed that there is no remediation for the flaw in this moment, that's why he suggest to stop using WhatsApp until developers produce a patch.
Read more: http://thehackernews.com/2013/10/vulnerability-in-whatsapp-allows.html#ixzz2hsut182j
Follow us: @TheHackersNews on Twitter | TheHackerNews on Facebook
Subscribe to:
Posts (Atom)

