EPIC.org has an interesting post on their blog that I hadn't seen before on the Vulnerabilities Equities Process
It's particularly timely with the recent "Wannacry" ransomware that appeared to use government leaked code that may not have been reported to the Microsoft
Question from the VEP - Is it the job of the intelligence community to find and report bugs? Are the bug hunters at the IC that much better at programming than Microsoft? Maybe the IC should share their bug hunting techniques? How about people not buying buggy software?
Wednesday, May 31, 2017
Google Chrome "feature" allows recording audio and video without indicator
Slashdot writes about it here - Google Chrome Bug Lets Sites Record Audio and Video Without a Visual Indicator
"Ran Bar-Zik, a web developer at AOL, has discovered and reported a bug in Google Chrome that allows websites to record audio and video without showing a visual indicator," reports BleepingComputer. "The bug is not as bad as it sounds, as the malicious website still needs to get the user's permission to access audio and video components, but there are various ways in which this issue could be weaponized to record audio or video without the user's knowledge. The bug's central element is a 'red circle and dot' icon that Chrome usually shows when recording audio or video streams." Bar-Zik discovered that if the JavaScript code that does the actual audio and video recording is launched inside a small popup, the icon is not shown anymore. This opens the door for various types of scenarios, where an attacker that has tricked a user into granting him permission to record audio and video records user data but when the user doesn't expect this (no visual indicator). For example, an attacker could disguise audio/video recording code inside popup ads. If the user doesn't close the popup, the popup continues to stream audio and video from the victim's house. Google declined to consider this a security bug.
Google bug site at first treats it as a feature not a bug,
Comment 1 by dominickn@chromium.org, Apr 10
Components: UI>Browser>Permissions>Indicators Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Team-Security-UX OS-Chrome OS-Linux OS-Mac OS-Windows Type-Bug Status: Available Thanks for the report. This isn't really a security vulnerability - for example,
WebRTC on a mobile device shows no indicator at all in the browser.
but I expect they'll come around quicklyThe dot is a best-first effort that only works on desktop when we have chrome UI space available. That being said, we are looking at ways to improve this situation. I'll put this in our general permissions indicator pool.
Tuesday, April 18, 2017
El Reg: Researchers steal data from CPU cache shared by two VMs
Researchers steal data from CPU cache shared by two VMs
A group of researchers say they can extract information from an Amazon Web Services virtual machine by probing the cache of a CPU it shares with other cloudy VMs.
A paper titled Hello from the Other Side: SSH over Robust Cache Covert Channels in the Cloud (PDF) explains the challenges of extracting data from CPU cache, a very contested resource in which the OS, the hypervisor and applications all conduct frequent operations. All that activity makes a lot of noise, defying attempts to create a persistent communications channel.
Until now, as the researchers claim they've built “a high-throughput covert channel [that] can sustain transmission rates of more than 45 KBps on Amazon EC2”. They've even encrypted it: the technique establishes a TCP network within the cache and transmits data using SSH.
The results sound scarily impressive: a Black Hat Asia session detailing their work promised to peer into a host's cache and stream video from VM to VM.
The paper explains that this stuff is not entirely new, but has hitherto also not been entirely successful because it's been assumed that “error-correcting code can be directly applied, and the assumption that noise effectively eliminates covert channels.”
The authors knock both of those arguments over, the first by figuring out a way to handle errors and the second with a method of scheduling communication between two VMs.
The paper details those efforts extensively, names them a “Cache-based Jamming Agreement” and offer you working code on GitHub so you can build your own all-in-cache covert channel, either on-premises or in the cloud.
A group of researchers say they can extract information from an Amazon Web Services virtual machine by probing the cache of a CPU it shares with other cloudy VMs.
A paper titled Hello from the Other Side: SSH over Robust Cache Covert Channels in the Cloud (PDF) explains the challenges of extracting data from CPU cache, a very contested resource in which the OS, the hypervisor and applications all conduct frequent operations. All that activity makes a lot of noise, defying attempts to create a persistent communications channel.
Until now, as the researchers claim they've built “a high-throughput covert channel [that] can sustain transmission rates of more than 45 KBps on Amazon EC2”. They've even encrypted it: the technique establishes a TCP network within the cache and transmits data using SSH.
The results sound scarily impressive: a Black Hat Asia session detailing their work promised to peer into a host's cache and stream video from VM to VM.
The paper explains that this stuff is not entirely new, but has hitherto also not been entirely successful because it's been assumed that “error-correcting code can be directly applied, and the assumption that noise effectively eliminates covert channels.”
The authors knock both of those arguments over, the first by figuring out a way to handle errors and the second with a method of scheduling communication between two VMs.
The paper details those efforts extensively, names them a “Cache-based Jamming Agreement” and offer you working code on GitHub so you can build your own all-in-cache covert channel, either on-premises or in the cloud.
Friday, April 14, 2017
Don't expect the FTC to help with Net Neutrality, Privacy, or anything else related to Telecom
In a nutshell:
1. FTC is really really busy
2. They don't know anything about network
4. Oh the courts told them THEY CAN'T
Don't expect Google to herlp either - Techdirt has a really good article about it,
Wednesday, September 28, 2016
Yet another reason Verizon...
From Ars Technica...
Employee breached customer trust, profited from private phone data for years.
An Alabama man who worked as a Verizon Wireless technician has agreed to
plead guilty to a federal hacking charge in connection to his illegal
use of the company's computers to acquire customer calling and
location data. The man, Daniel Eugene Traeger, faces a maximum five
years in prison next month. He admitted Thursday that he sold customer
data—from 2009 to 2014—to a private investigator whom the authorities
have not named.
Great!
Tuesday, August 30, 2016
Was Hillary's server used for State Dept Business? While it was infected? It just keeps getting worse...
Oh I don't know - how did the State Department treat it? As a priority? Then maybe...
WASHINGTON (AP) — State Department staffers wrestled for weeks in December 2010 over a serious technical problem that affected emails from then-Secretary Hillary Clinton's home email server, causing them to temporarily disable security features on the government's own systems, according to emails released Wednesday.Techdirt calls it more frankly -
The emails were released under court order Wednesday to the conservative legal advocacy group Judicial Watch, which has sued the State Department over access to public records related to the presumptive Democratic presidential nominee's service as the nation's top diplomat between 2009 and 2013.
The emails, reviewed by The Associated Press, show that State Department technical staff disabled software on their systems intended to block phishing emails that could deliver dangerous viruses. They were trying urgently to resolve delivery problems with emails sent from Clinton's private server.
"This should trump all other activities," a senior technical official, Ken LaVolpe, told IT employees in a Dec. 17, 2010, email. Another senior State Department official, Thomas W. Lawrence, wrote days later in an email that deputy chief of staff Huma Abedin personally was asking for an update about the repairs. Abedin and Clinton, who both used Clinton's private server, had complained that emails each sent to State Department employees were not being reliably received.
After technical staffers turned off some security features, Lawrence cautioned in an email, "We view this as a Band-Aid and fear it's not 100 percent fully effective."
Emails Show Hillary Clinton's Email Server Was A Massive Security Headache, Set Up To Route Around FOIA Requests
from the breaking-badly dept
More bad news for Hillary Clinton and her ill-advised personal email server. Another set of emails released by the State Department shows the government agency had to disable several security processes just to get its server to accept email from Clinton's private email address.
Tuesday, August 9, 2016
Are the Democrats *REALLY* accusing Wikileaks?! Bernie?! and Trump?!?! of being RUSSIAN SPIES!?
From the Intercept
Is Hillary getting worried?
From Drudge
OTOH, the New York Times, has an interesting article..
Cash Flowed to Clinton Foundation Amid Russian Uranium Deal
...
Beyond mines in Kazakhstan that are among the most lucrative in the world, the sale gave the Russians control of one-fifth of all uranium production capacity in the United States. Since uranium is considered a strategic asset, with implications for national security, the deal had to be approved by a committee composed of representatives from a number of United States government agencies. Among the agencies that eventually signed off was the State Department, then headed by Mr. Clinton’s wife, Hillary Rodham Clinton.
Subscribe to:
Posts (Atom)
