Monday, 25 May 2015

Bellevue Hospital Breach

Bellevue Hospital Center operator New York City Health and Hospitals Corporation (HHC) is notifying roughly 3,300 patients that their personal information was included in a spreadsheet that was improperly emailed to an unauthorized recipient.

How many victims? About 3,300.

What type of personal information? Names, telephone numbers, medical record numbers, email addresses, insurance carrier information and limited sensitive health information.

What happened? A Bellevue employee improperly emailed a spreadsheet containing the personal information to an unauthorized recipient, who was her relative.

What was the response? The Bellevue employee and her relative were interviewed, and it was confirmed that the spreadsheet was not sent to any other individuals and was deleted by the relative. Additional training is being planned for staff, and an automatic blocking system is being implemented to prevent email communications containing personal and other confidential information from being sent from HHC`s systems to outside systems, unless for legitimate purposes. The employee is facing disciplinary action. All potentially impacted individuals are being notified.

Details: The email was sent on Jan. 15 and the incident was discovered on Feb. 27. The employee indicated that she sent the spreadsheet to the relative for technical assistance in manipulating the spreadsheet data for work purposes.

Quote: `There is no evidence to suggest that the spreadsheet was received or viewed by anyone other than the single unauthorized recipient, and there is no evidence to suggest that the PHI contained in the spreadsheet was misused or further disclosed in any manner,` according to a notification posted to the website.

Read original article

MasterCards breach settlement

MasterCard`s $19 million breach-expense settlement with Target on behalf of its card issuers has been derailed after an insufficient number of banking institutions chose to accept the terms of the deal.

But what will happen next, now that the issuers have walked away from a deal they viewed as offering inadequate reimbursement for their breach expenses?

One payments security expert says MasterCard will likely renegotiate its settlement to avoid lengthy litigation. Meanwhile, an attorney representing banks and credit unions involved in a class-action lawsuit against Target, which seeks to recoup breach-related expenses, says the suit will push forward.

John Buzzard, who heads up FICO`s Card Alert Service, says MasterCard is likely to offer a new settlement that better meets the expectations of issuers.

`I`m surprised the settlement didn`t pass, and at the same time, I can totally understand why there is reluctance to accept a number that seems small to many issuers,` he says. `I would imagine that renegotiation could be on the table again. A lengthy court battle and the complexities involved in a class action lawsuit could be mired in red tape for years.`

Charles Zimmerman, co-lead counsel for the banking institution plaintiffs in the class-action suit against Target, says banks and credit unions agreed the settlement was unfair and decided they would rather push forward with their class-action suit, rather than agree to a settlement that provides inadequate reimbursement for their substantial breach-related expenses.

`We are pleased that financial institutions have resoundingly rejected Target and MasterCard`s attempt to avoid fully reimbursing the losses suffered during one of the largest data breaches in U.S. history,` Zimmerman said in a statement provided to ISMG. `Financial institutions clearly saw through Target`s misleading statements and efforts to extinguish pending legal claims for pennies-on-the-dollar. We will continue working to hold Target accountable and ensure that all affected financial institutions receive proper compensation for losses resulting from this data breach.`

MasterCard did not respond to ISMG`s request for comment. But the Star Tribune in Minneapolis, where Target is based, reports that MasterCard says it`s `working to resolve the matter.`

Settlement Voided

Target spokeswoman Molly Snyder confirms MasterCard failed to get enough banks and credit unions to agree to the settlement`s terms by the May 20 deadline.

`The April 16 settlement agreement between MasterCard International Inc. and Target was to become effective if eligible issuers of at least 90 percent of all qualified accounts opted in to the settlement by May 20, 2015,` Snyder tells Information Security Media Group. `MasterCard has informed Target that the 90 percent threshold was not reached by the May 20 deadline. Target has nothing further to share at this time.`

Visa is working with Target and banking institutions to come up with a viable breach-expense recovery strategy, a Visa spokeswoman tells ISMG.

`Visa continues to work with Target and its acquiring financial institutions regarding any potential liability under Visa`s Global Compromised Account Recovery program,` the spokeswoman says.

Setting a Precedent?

Attorney Chris Pierson, chief security officer at invoicing and payments provider Viewpost, says banks` and credit unions` reluctance to agree to the terms of MasterCard`s settlement with Target should serve as a wake-up call to the card brands.

`The failure of this settlement to pass is new ground that the card associations will need to consider and grapple with in this specific matter, and going forward with other notable breaches,` he says. `The change in behavior may underscore the underlying frustration of fraud fallout from card-centric breaches.`

Read original article

Sunday, 24 May 2015

What is encryption

There's been a lot of talk about encryption in the media lately.

You hear about who uses encryption, and who doesn't (lots of companies don't, to their own detriment).

And you hear about who wants to be able to bypass encryption (some law enforcement and national security agencies), and who doesn't (Google, Apple, privacy advocates, etc.).

The encryption debate is important, but unfortunately, encryption is complex and the discussion can be hard to follow for people outside of the security community.

Businesses often don`t realise why encryption is important, and how they can use it to protect their data.

In this article I will seek to answer some common questions about encryption by covering two areas: 1) a very brief explanation of encryption, and 2) a couple of the most common use-cases which business needs to be aware of.

What is encryption?

Encryption is a method of scrambling messages in a format that is unreadable by unauthorised users - it is, simply put, the best way to keep data secure from spies, thieves or accidental exposure. (Not to be confused with steganography, which is all about hiding messages, rather than making them unreadable).

Cryptography - the art and science behind encryption - uses algorithms to turn readable data (plaintext) into unreadable format (ciphertext).

Without getting too deep into the details, it`s helpful to think about it like this: when you encrypt data you are storing it like you would money in a safe - you need a key to unlock the safe to get the money out (my apologies to any cryptographers reading this for the gross over-simplification!).

(If you want to learn more, I recommend my fellow Naked Security writer Paul Ducklin`s great explanation of public-private key encryption.)

There are loads of ways to use encryption, but for organisations concerned about data loss, two very important areas to understand are full-disk encryption and file-level encryption.

Full-disk encryption vs. file-level encryption

Encryption can be used in many different ways.

Say your employee accidentally loses a USB drive with valuable data on a train, or their laptop gets stolen when they leave it alone in a coffee shop while they go to the bathroom (it happens).

The physical kit can be replaced, but the data on them could end up in the wrong hands and cause considerable harm - you might face financial penalties (depending on your local laws and industry regulations).

Or you might lose customers when word gets out that their personal data was leaked. You may very well be legally obliged to tell them. Of course, morally, telling them is always the right thing to do, regardless of legality.

However, if the laptop or USB drive was strongly encrypted, the data is unreadable to someone without they key and you likely won't have legal issues to worry about.

Laptops, USB drives, and even smartphones can be encrypted using what is known as full-disk encryption. That means the entire hard drive of the device and everything on it is protected by encryption - from the operating system to program files all the way down to temporary files.

Full-disk encryption is also relatively simple to implement - laptops and smartphones now come with the capability built in, what's called native encryption.

However, full-disk encryption can only keep your stuff secure when it`s on the device. The second anything leaves the encrypted device, it is `magically` decrypted and readable by all. This has important implications for your backups or files you`ve uploaded to a cloud service or attached to an email.

If you think about the analogy of money in a safe, the encrypted disk is the safe, and the money is your data. Once you take your money out of the safe it is no longer protected.

Conversely, if you have file-level encryption, every file has a `padlock.`

With file-level encryption, your data is protected when it is in transit, or stored somewhere in the cloud.

But there is a downside - file-level encryption is harder to manage than full-disk encryption, because whenever you want to access the data, you need the key. As you may want access from many devices and many places, this requires careful key management.

When and how should you use encryption?

Full-disk encryption barely affects system performance at all, but if you try to encrypt everything at the file level, it will quickly become unmanageable.

You need to think a bit more about what data you want to encrypt and why. You`ll likely want to focus on file-level encryption for sensitive data and/or data that you copy to other places - for example, documents you want to access on your phone as well as your desktop, or from a service like Dropbox.

It`s important to understand that file-level encryption doesn`t replace full-disk encryption. They complement each other. If you only encrypt your own files and not the full disk then it`s very easy to miss something. Chances are your computer stores copies of your data in all sorts of places you didn`t think about.

Most companies will also want the IT department to carefully manage the encryption keys across various devices. Without this central management, data could easily be lost if a person leaves the company or loses their decryption password. Unlike passwords used for access, passwords used for encryption can`t simply be reset by a sysadmin if they`re forgotten.

A smart company will make sure the master decryption keys are very well protected. Even smarter companies will ensure that no single person has full access to the powerful key. One way of doing this is designing a system such that two or more people need to contribute towards the decryption process (segregation of duties).

Good encryption software will have capabilities to make key management and segregation of duties relatively simple.

Read original article

Apple Fixes Security Bugs

Apple released on Tuesday its first update for Watch OS, the iOS-based operating system that runs on the Apple Watch.

Watch OS 1.0.1 patches a total of 13 vulnerabilities affecting components such as the kernel, Secure Transport, FontParser, the Foundation framework, IOHIDFamily, and IOAcceleratorFamily.

The FontParser issue exists due to the way font files are processed. An attacker can exploit this vulnerability (CVE-2015-1093) to execute arbitrary code by getting a user to process a maliciously crafted font.

The Foundation framework in the first version of Watch OS is plagued by an XML External Entity (XXE) vulnerability caused by the way the NSXMLParser handles XML files (CVE-2015-1092). This allows an application using the NSXMLParser to disclose information, Apple said in its advisory.

The flaws affecting IOHIDFamily and IOAcceleratorFamily could allow malicious applications to determine kernel memory layout.

The following vulnerabilities have been identified in the kernel:
CVE-2015-1099: race condition in the setreuid system call could allow malicious apps to cause a denial-of-service (DoS) condition on the system;
CVE-2015-1103: ICMP redirects enabled by default allow a man-in-the-middle (MitM) attacker to redirect users' traffic to arbitrary hosts;
CVE-2015-1105: state inconsistency issue in handling of TCP out-of-band data allows a remote attacker to cause a DoS condition;
CVE-2015-1117: setreuid and setregid system calls fail to drop privileges permanently, allowing malicious applications to escalate privileges using a compromised service that should run with limited permissions;
CVE-2015-1104: system treats some IPv6 packets from remote network interfaces as local packets, enabling remote attackers to bypass network filters;
CVE-2015-1102: inconsistency in the processing of TCP headers allows an MitM attacker to cause a DoS condition;
CVE-2015-1100: out-of-bounds memory access flaw in the kernel allows malicious apps to cause the system to crash or read kernel memory;
CVE-2015-1101: memory corruption vulnerability allows malicious applications to execute arbitrary code with system privileges.

The list of people and organizations credited for finding these vulnerabilities includes Marc Schoenefeld, Ikuya Fukumoto, Ilja van Sprundel of IOActive, Cererdlong of the Alibaba Mobile Security Team, Mark Mentovai of Google, Zimperium Mobile Security Labs, Kenton Varda of Sandstorm.io, Stephen Roettger of Google, Andrey Khudyakov and Maxim Zhuravlev of Kaspersky Lab, Maxime Villard of m00nbsd, and lokihardt@ASRT.

Watch OS 1.0.1 also addresses the FREAK vulnerability, which allows an MitM attacker to access encrypted data by downgrading the connection.

In addition to addressing these security bugs, Apple has updated the certificate trust policy, which includes a list of trusted, untrusted but not blocked, and blocked certificates in Watch OS.

The update is available for Apple Watch, Apple Watch Sport, and Apple Watch Edition.

Read original article

Brazil Ground Zero

Brazil, one of the most populated countries in the world, also has one of the highest percentages of internet users using online banking: more than half of the population uses it. As a consequence, banking trojans are the No. 1 cybersecurity threat in that Latin America powerhouse. And they're being unleashed on the country in a homegrown malware phenomenon that's specific to the region.

That's according to ESET, which has identified control panel application (CPL) malware flowing at an increasing rate through its Latin American Research Lab, 90% of which came from Brazil. CPL files are a type of library file that, once clicked, will trigger the automatic execution of the code contained in the file. If that code is malicious code, the user is infected as a matter of course. It's a very specific type of code approach that's quite uncommon in the larger malware picture.

Of those malicious CPL files observed by ESET, 82% of them deliver some variant of Win32/TrojanDownloader.Banload family; which has as its main goal the download and installation of banking trojans.

To persuade their victims to execute the malicious CPL files and become infected, cyber-criminals send fake emails that make good use of social engineering techniques. The most used types of bait messages include documents with a price quote, invoice or receipt; a document with information on a debt or banking situation; specific digital payment instruments only used in Brazil, such as the Boleto Bancário or the Nota Fiscal Eletrônica; and files passed off as photographs, videos or other kinds of media files.

The Brazil-specific payment instruments may be the most ingenious, and again, point to the homegrown nature of the campaign. Matías Porolli, researcher at ESET, explained in a whitepaper that the Boleto Bancário is digitally issued and supported by a banking institution, which contains a bar code and allows anyone to pay a receiving party, usually by printing the document and paying at one of the places specially authorized for that purpose. Likewise, the Brazilian electronic invoice called Nota Fiscal Eletrônica is another digital document that makes it easier to purchase goods from a supplier, relying on the digital signature of the issuer and the receiver. It requires validation from a Brazilian public organization.

CPL malware is on the rise—and significantly so. At the beginning of 2012, only 5% of the files sent by users to the ESET LATAM Lab corresponded to CPL malware. However, in 2013 this figure increased to 20%, quadrupling its number as compared with the previous year. Throughout 2014 and early 2015, the percentage of samples the users received increased by 50%.

By the first quarter of 2015, three out of every 10 samples that users sent to the ESET LATAM Lab were CPL files, with Brazil disproportionately affected: 76% of ESET detections last year came from the country.

`This very clearly demonstrates that this malware family is specifically targeting users in that country—the second place, occupied by Spain, has almost 11 times fewer detections, and the gap extends further with other countries like Argentina, Colombia and even Portugal,` said Porolli.

Most of the samples use Delphi as the programming language, use the same CPL-specific encryption algorithm, and use the same propagation campaigns.

`All these similarities tell us that these attacks are being carried out by the same cyber-criminal group or by many groups that are in contact with each other and who share information,` Porolli said. `Many of the elements present in the current campaign were made in Brazil. Due to the strings in Portuguese present in the executables, as well as the consistent use of the Delphi language, it is reasonable to believe that quite a lot of local work went into developing the threats, rather than merely adapting those that already exist.`

Read original article

ULCC cyber attack

The University of London Computer Centre (ULCC) has been hit by a major cyber-attack, knocking out open source learning platform Moodle and numerous university websites for several hours.

The attack is thoughts to have struck at 7.30 on Thursday morning, local time, and continued till around midday.

Initial status updates from ULCC claimed that `an issue with our firewall` was the cause of the outage.

However, a final update at midday told a different story:

`All our services are now up and running again! The networking issue was caused by a cyber attack. We have taken action to block the source. An incident report will be produced and shared in due course. We appreciate your patience, understanding and words of support on social media.`

There's no further information on the attack – whether it was a straightforward DDoS or something more sinister – but it's thought to have originated in the UK, according to Russia Today.

Back in February, the ULCC suffered a denial of service attack lasting a couple of hours.

Despite the name, the ULCC is actually an IT services non-profit which supports over 300 UK educational institutions including the University of York, the European Library, and the American College of Beirut.

It's also responsible for hosting Moodle, marketed as `the world's open source learning platform`, which is used by over two million students.

Unsurprisingly, many students took to Twitter to vent their anger over the outage, which came on the eve of important exams for some.

Rob Lay, enterprise and cybersecurity solutions architect at Fujitsu, argued that all organizations are a target for cyber-criminals today.

`Organizations can no longer afford to make mistakes in security. By communicating from the top down what cybersecurity means to its business, organizations can help all staff recognize their responsibility in ensuring the company is adequately prepared to manage threats,` he added.

`Security impacts everyone, including students, and being prepared to respond quickly to incidents will help to reduce that impact.`

Webroot director, George Anderson, added that four hours of `complete shutdown` would be unacceptable for most businesses.

`Hopefully this case will serve as a warning to other organizations, encouraging them to ensure that they have an effective strategy in place to make sure user experience is impacted as little as possible,` he argued.

Read original article

Verizon Security Flaw

With its $4.4 billion purchase yesterday of AOL, the telecom giant Verizon gained millions of new home internet customers. But a glaring security flaw suggests they may have put millions of their existing internet customers at risk.

BuzzFeed News has learned of a vulnerability in Verizon's service that could have allowed anyone to view the personal information of any of its 9 million home internet customers simply by visiting its website with a spoofed IP address — the very same personal information that can be used to obtain password resets and gain full control over those home accounts.

Verizon fixed the security loophole after being notified of it by BuzzFeed News.

BuzzFeed News was able to verify this vulnerability multiple times, on multiple accounts, with the explicit and repeated permission of the account holders.

Your IP address is a unique number assigned to your internet-connected devices that lets other computers identify you. It's in the header of emails you send, and can be easily sussed out by savvy hackers if you, say, make a Skype call, play games online with Xbox, or click on the wrong link in an email. But it wouldn't have taken a savvy hacker to pull off this Verizon exploit. In fact, all you need is a Firefox plug-in — one of hundreds of browser-specific programs that people use to do things like block display ads or sync their bookmarks between browsers.

Last week, BuzzFeed News received a tip from Eric Taylor — now the chief information security officer of a company called Cinder, but probably better known by his former hacking alias, Cosmo the God. Taylor and Blake Welsh, a student at Anne Arundel Community College in Maryland, had found a way to easily access Verizon user information by spoofing IP data. They passed along the information to BuzzFeed News on the condition that we would report it to Verizon before publishing — which we did.

The vulnerability existed because Verizon's customer support website identifies you through your computer's IP address. Since this address is generated by your internet service provider, what it's really looking for is if you're hitting its page with an IP address that Verizon recognizes. Because those IP addresses are unique to each home internet customer, when it sees one it recognizes, it assumes it knows who you are, and until we informed Verizon of the flaw, it automatically displayed things like your location, your name, your phone number, and your email address. And that's really all you need to take control of a Verizon account.

Within a few hours of the tip, and despite having no technical background, with the explicit permission of several Verizon account holders, I was able to convince Verizon customer service to reset an account password, giving me total control of a Verizon account. It was surprisingly easily done.

It took me only two downloads, copy and pasting some information from an email, and a few interactions with Verizon customer support. It was just a matter of following step-by-step instructions. In other words, if you can follow a recipe, you could have probably gotten a Verizon password reset.

First, I downloaded a particular old version of Firefox (20, in case you were wondering). Then I downloaded `X-Forwarded-For Header,` a simple Firefox extension that lets your browser impersonate an IP address of your choosing. I popped a Verizon user's IP address — which I gleaned from the header of an email sent to me by one of the volunteers who had given me permission to gain control of his account — into the extension.

I then navigated to the Verizon customer support page, which showed my location in another state — the state of the accounts I was using (with permission) to test this method. Although I work in New York, the page displayed my location as D.C. It also greeted me by name — but not my name, the name on the account.

Read original article