Wednesday, 3 June 2015

Ransomware Decryption Keys

An individual claiming to be the developer of the crypto ransomware known as Locker has published the private keys needed to recover the files taken hostage by the threat.

`I am the author of the Locker ransomware and I`m very sorry about that has happened. It was never my intention to release this,` reads a Pastebin post signed by `Poka BrightMinds.`

A CSV file containing Bitcoin addresses and RSA keys has been made available, along with information on the structure of the encrypted files. The alleged author claims that files will also be automatically decrypted starting June 2 at midnight.

The database file contains over 62,000 rows, but most of the keys have not been used, according to the alleged Locker developer.

Several users have confirmed on the Bleeping Computer forum that the published decryption keys are valid. Malware analyst and ransomware expert Nathan Scott has developed Locker Unlocker, a simple tool that allows victims to recover their files.

Locker demands the payment of 0.1 Bitcoin for the decryption key. If the ransom is not paid within 72 hours, the amount increases to 1 Bitcoin.

The threat has been distributed with the aid of a Trojan downloader, which received a command instructing it to install Locker on infected systems on May 25.

Many users have been skeptical about the alleged author's good intentions, and some have pointed out that he should return the Bitcoins paid by victims if he is truly sorry for his actions. While some have speculated that the individual who released the decryption keys might be a programmer hired to create Locker or that his work has been stolen and abused, many people don't think he is innocent.

Another piece of ransomware that has made numerous headlines over the past weeks is TeslaCrypt. In April, Cisco released a tool that recovers the master encryption key used by TeslaCrypt and restores the content of encrypted files.

Read original article

Windows 10 Security

Microsoft Windows 10: Three Security Features To Know About

Microsoft`s next-generation operating system Windows 10 will be available as a free upgrade to Windows 7 and 8.1 users on July 29. But Windows Enterprise version customers will have to wait until later this year.

Application-vetting and biometric authentication headline the new main security features in Microsoft`s new Windows 10 operating system, which the company today said will begin shipping for free on July 29 to users of Windows 7 and 8.

Windows 10`s arrival can`t come too soon amid doom-and-gloom predictions of the demise of Windows after Microsoft`s failed makeover of Windows with the tile interface-heavy and startup menu-missing Windows 8. Aside from the return of the beloved startup menu, a personal assistant called Cortana and a new faster and more personalized browser called Edge, Microsoft also is launching some significant new security features in Windows 10, most of which are available in the first release.

Windows security expert Marc Maiffret says with the new Windows 10 security features combined with the new Windows Store for authorized and vetted applications, Microsoft is making the desktop ecosystem look a lot more like the smartphone -- which is good news for security. `There are interesting security implications to that: part of what all of us are fighting is how to better control apps and code in environments,` he says.

1. Device Guard

Microsoft`s new Device Guard is aimed at blocking zero-day attacks by vetting applications that try to access a Windows 10 machine and its network. It basically blocks any applications that are not signed by specific software vendors, the Windows app store, and an enterprise itself.

Acer, Fujitsu, HP, NCR, Lenovo, Par, and Toshiba, have teamed up with Microsoft to use Device Guard on their Windows-based devices. It supports point-of-sale systems, ATM machines, and other Internet of Things-type devices running Windows.

`To help protect users from malware, when an app is executed, Windows makes a determination on whether that app is trustworthy, and notifies the user if it is not. Device Guard can use hardware technology and virtualization to isolate that decision-making function from the rest of the Windows operating system, which helps provide protection from attackers or malware that have managed to gain full system privilege,` blogged Microsoft`s Chris Hallum recently on the new Windows app feature.

Microsoft`s Hallum argues that Device Guard, unlike antivirus and whitelisting software, isn`t an susceptible to insider tampering or credential hijacking or unknown malware sneaking past, but the feature likely will work in concert with AV and whitelisting or other app-control products.

`Traditional AV solutions and app control technologies will be able to depend on Device Guard to help block executable and script based malware while AV will continue to cover areas that Device Guard doesn't such as JIT based apps (e.g.: Java) and macros within documents,` Hallum said.

Interestingly, Device Guard also operates virtually so that if the Windows kernel is compromised, Device Guard is not, according to Microsoft. It requires policy provision software.

2. Windows Hello

Windows Hello has been touted by Microsoft as a password-killer feature that uses biometrics -- your face, iris, or your fingerprint -- to launch Windows 10 devices rather than those pesky and vulnerable passwords.

Joe Belfiore, corporate vice president of Microsoft`s operating systems group, says Hello is more secure because it allows you to authenticate applications, enterprise content, and online experiences without storing a password on the user device or on a network server.

The catch is you need a machine with a fingerprint reader and scanning software and hardware for the infrared technology to identify a user by his face or iris. And the devices require Windows Biometric Framework support.

`We`re working closely with our hardware partners to deliver Windows Hello capable devices that will ship with Windows 10 and we are excited to announce that all OEM systems incorporating the Intel RealSense 3D Camera (F200) will support the facial unlock features of Windows Hello, including automatic sign-in to Windows, and support to unlock `Passport` without the need for a PIN,` Belfiore said in a post about Windows 10 today.

Maiffret says Microsoft appears to have developed Hello as a viable form of authentication for the enterprise as well. `They`ve gone the lengths to make this secure from a crypto perspective, so it can be ... accepted as a real form of authentication in the enterprise,` he says.

3. Passport

Also in sync with the theme of password liberation is Windows 10`s new Passport feature that lets users authenticate to applications, websites, and networks sans passwords.

`Windows 10 will ask you to verify that you have possession of your device before it authenticates on your behalf, with a PIN or Windows Hello on devices with biometric sensors. Once authenticated with `Passport`, you will be able to instantly access a growing set of websites and services … favorite commerce sites, email and social networking services, financial institutions, business networks` and others, according to Microsoft.

Passport will work with Microsoft`s Azure Active Directory Services, according to Microsoft, and the user`s biometric `signature` is secured and stored locally on the user device and used only to unlock it and for Passport; it`s not used to authenticate via the network.

Microsoft isn`t dictating the death of passwords, however, although now as part of the FIDO Alliance it`s working to help replace passwords in the future. So users or organizations who can`t bear to part with their passwords and password management don`t have to deploy Windows Hello and Passport in Windows 10 at all.

Meanwhile, Microsoft also has made some subtle but key changes in Windows 10 `under the hood` using containers and virtualized sandboxes to better secure desktops, Maiffret says. `But I`m sure at Black Hat or next year someone will do a talk on how to break out of the Windows 10 sandbox. that`s inevitable.`

Even so, Microsoft`s taking that approach with Windows is a game changer for the OS, he says.

Read original article

Google Centralizes Security

Google`s new account hub, for users of its Web services and Android smartphones, gives IT organizations a new tool to improve employee awareness of security and privacy.

Following its developer conference last week, on Monday Google enhanced its security and privacy offerings with a unified security page and a Web resource for those with privacy questions.

For IT organizations that have to deal with the intricacies of employee devices in the workplace and shadow IT, Google`s effort to educate users about security and privacy provide a potential opportunity to raise awareness of issues that confront every company.

In a blog post, Google product manager Guemmy Kim said the company wants to change the perception that people are unable to control their personal information.

`Privacy and security are two sides of the same coin: If your information isn`t secure, it certainly can`t be private,` said Kim.

According to a Pew Research study published last month and cited in Kim`s blog, only 9% of the 498 survey respondents polled in fall 2014 expressed confidence that they have `a lot` of control over the information collected about them. Pew`s researchers explain the evident doubt by noting that Edward Snowden`s 2013 revelations about NSA data gathering `have contributed to a cloud of personal `data insecurity` that now looms over many Americans` daily decisions and activities.`

This cloud over cloud computing affects companies beyond Google.

Facebook`s decision on Monday to support OpenPGP public keys in user profiles comes from the same need to help consumers feel comfortable amid the largely unchecked data gathering practiced by advertisers, information brokers, and intelligence agencies.

The political tempest in Washington over the Patriot Act and the USA Freedom Act also flows from the same weather system

Google`s revised My Account page puts security and privacy controls in one place. It provides access to sign-in and security settings, personal information and privacy settings, and account preferences. It also includes Security Checkup and Privacy Checkup guides, which take users through a step-by-step review of important security and privacy settings.

The Security Checkup covers: account recovery information, connected devices, account permissions, app passwords, Gmail settings, and 2-step authentication settings.

The Privacy Checkup covers: Google+ profile information, phone number visibility for users of other Google services, settings that affect personalization in Google services, and ad relevance settings.

The My Account page also includes a link to Google`s new privacy and security answers resource. It amounts to a list of frequently asked questions (FAQs), though Google, shunning Internet vernacular, refers to them as common questions.

The questions include:
•`What data does Google collect?`
•`What does Google do with the data it collects?`
•`Does Google sell my personal information?`

To find out how Google answers these questions, visit privacy.google.com.

Read original article

Facebook supports OpenPGP

Facebook has announced that its users can add an OpenPGP public key to their profile. This will allow Facebook to encrypt notification e-mails, and for others to use the public keys for encrypted communications. Facebook is `gradually rolling out` this experimental feature, which will be available from your account`s Contact and Basic Info page.

Facebook says it has chosen to use GNU Privacy Guard (GPG) for its implementation. Back in February, the company stepped in with a $50,000 donation when the GPG project was struggling to raise funds to secure its future. As far as the detailed implementation is concerned, Facebook`s notifications will be encrypted using the RSA or ElGamal algorithms, and the company is `investigating the addition of support for GPG`s newer elliptic curve algorithms in the near future.` Facebook is also looking at ways of offering public key management on mobile devices, not currently supported.

When encrypted notifications are enabled on an account, Facebook will sign outbound messages using its own private key to provide greater assurance that the contents of inbound e-mails are genuine—one of the chief benefits of the new feature. It means, for example, that users can be sure that password reset messages do indeed come from Facebook rather than someone masquerading as the company.

Although limited in its impact, the move is a step beyond HTTPS by default, which the company rolled out two years ago. Facebook`s example may encourage other online services to follow suit, and could also help to raise awareness of the general idea of end-to-end encryption for email.

Read original article

Tuesday, 2 June 2015

DDoS attacks spread

A total of 23,095 DDoS attacks were carried out on web resources located in 76 countries in the first quarter of 2015, up 15 percent from the 66 countries affected in the final quarter of last year.

This is one of the findings of a new study by cyber security firm Kaspersky Lab into the botnet-assisted DDoS attack landscape. But although the geography is expanding the overall number of botnet-assisted attacks is down by 11 percent and the number of unique victims down by eight percent.

Servers in the US, Canada and China are targeted most frequently. The study also finds that the greatest number of attacks on a single web resource in Q1 2015 was 21, compared to 16 in Q4 2014, and the most prolonged botnet attack occurred for almost six days.

`A DDoS attack is often a cross-border effort; the customer is located in one country, the executor in another, the C&C servers are hosted in a third country, and the bots involved in the DDoS attack are scattered across the world,` says Evgeny Vigovsky, Head of DDoS Protection at Kaspersky Lab. `This often makes it more complicated to investigate attacks, take down botnets and catch those responsible. Although cybercriminals do not limit their DDoS toolkits to botnets alone, this is still a widespread and dangerous tool, and it demands preventive protection measures from potential targets, i.e. web resources`.

The fact that China and the US for most frequently attacked countries and highest numbers of victims is, says Kaspersky Lab, down to low hosting prices that encourage many companies to have their sites located in those countries.

The most attacks on a single resource were against a Russian language website belonging to an investment group. A Vietnamese wedding services site was second most attacked, and a US hosting provider third.

Only three sites suffered attacks of more than 100 hours, down significantly from 13 in the final quarter of 2014. However, as the report points out even a short, one-off attack can make a site inoperable and cost the victim both financially and in damage to reputation.

The full report with much more detail is available from the Kaspersky Lab site.

Read original article

StuxNet Malware

The United States tried and failed to use the infamous Stuxnet worm to disrupt North Korea's nuclear facilities, according to several intelligence sources.

The unnamed `people familiar with the covert campaign` told Reuters that US spies developed a related piece of malware which would activate when it encountered the Korean language on an infected machine.

The plan, which was hatched at the same time as the Stuxnet campaign against Iran's nuclear program, failed because NSA operatives couldn't get it onto targeted systems.

North Korea, and its ICT systems, are among the most isolated in the world.

Only a tiny fraction of the country's population are even allowed on the world wide web, and anyone wanting to own a PC must apply for a license – meaning there were relatively few options available to US spies.

Iran is relatively open by contrast, with citizens able to browse the global internet.

Experts spoken to by the newswire claimed that US spooks had probably tried to get the malware onto core target systems in North Korea via equipment imported from Iran, Pakistan or China.

It's thought that Pyongyang's nuclear program uses similar hardware and software to that of Iran, so the tweaks needed to make Stuxnet work in the hermit nation would not have required much time or money.

Iran and North Korea signed a deal back in 2012 to co-operate more closely in areas such as IT, biotech and renewable energy, including joint R&D projects.

Stuxnet first leapt to fame in 2009 when it emerged that the worm – which featured an unheard of four zero-day exploits – had been used to disrupt Iran's nuclear program.

It was designed to infect Siemens industrial control software, damaging the centrifuges that play a key role in the uranium enrichment process.

Operation Olympic Games, as it was called, is thought to have been a joint NSA/Israeli project to disrupt the nuclear research and development work undertaken at Iran's Natanz facility.

Read original article

Strong EncryptionNeeded

The United Nations has defended the use of strong encryption software as vital to protecting free speech around the globe, in a new report which clashes with recent statements from London and Washington.

The report was compiled by David Kaye, UN special rapporteur on the promotion and protection of the right to freedom of opinion and expression.

It argues that many journalists, activists, artists and regular citizens today use encryption and anonymity tools to protect their privacy; to empower them to browse, develop and share opinions without interference; and to otherwise exercise their right to freedom of opinion and expression.

However, financial crime, bullying, illegal drug dealing, child porn, terrorism and more are also made possible via these tools.

As a result, the report attempts to examine to what extent governments can restrict anonymity and encryption.

It explains that any restrictions placed on these concepts should be `strictly limited according to principles of legality, necessity, proportionality and legitimacy in objective.`

It concludes:

`States should promote strong encryption and anonymity. National laws should recognize that individuals are free to protect the privacy of their digital communications by using encryption technology and tools that allow anonymity online. Legislation and regulations protecting human rights defenders and journalists should also include provisions enabling access and providing support to use the technologies to secure their communications.`

The authorities in member countries should `avoid all measures that weaken the security that individuals may enjoy online, such as backdoors, weak encryption standards and key escrows,` the report argues.

However, the UN does admit that in some circumstances law enforcement should be able to `restrict` anonymity and encryption, but only on a case-by-case basis.

Each of these cases must `meet the requirements of legality, necessity, proportionality and legitimacy in objective, require court orders for any specific limitation, and promote security and privacy online through public education.`

The report is somewhat at odds with recent remarks made by senior officials on both sides of the Atlantic.

US attorney general, Eric Holder, FBI director, James Comey, and Homeland Security (DHS) secretary Jeh Johnson have all argued for greater restrictions on encryption, claiming that it helps hide criminal activity from law enforcers.

UK prime minister, David Cameron, went even further, arguing that in extremis, it should be possible for law enforcers to access and read strongly encrypted communications.

His remarks have been widely criticized by cybersecurity experts, with many claiming that this would basically require backdoors to be inserted by vendors like Apple and Google into their products.

If this were to happen, cyber-criminals would eventually manage to get hold of the same backdoors, dealing a blow to corporate security efforts by effectively exposing all users to snooping.

Read original article