Showing posts with label Encryption. Show all posts
Showing posts with label Encryption. Show all posts

Monday, 23 October 2017

Google Play Protect Stops Less Malware Than Anti-Virus Apps


The security software that protects Google Android devices against malware performs worse than anti-virus apps, according to a test of the German test lab AV-Test. In July , Google launched " Play Protect", security software that checks apps that users want to download and install scans malware and periodically checks the device on malware. Play Protect is present on all Android devices with Google Play.

AV-Test has been comparing several mobile virus scanners for a long time, but also included Play Protect in the September test. For the test, 20 different Android virus scanners and Play Protect were tested with nearly 6000 infected apps. It involved detection of 3000 contaminated apps in real time and detection of 2900 infected Android apps found in the last four weeks of the test.

On average, the tested programs detect 95.7 percent and 98.4 percent of the infected apps. Antiy, Bitdefender, Cheetah Mobile, Sophos, Symantec and Trend Micro score 100 percent in both detection tests. Google Play Protect ends at the bottom. During the real-time detection of apps, Play Protect detected 65.8 percent of malicious apps. Of the malicious apps found in the four weeks before the test, Play Protect detected 79.2 percent.

In total, the virus scanners could collect 13 points. Six points were achieved for detecting malicious apps. The same number of points were divided for usability, such as battery usage, system load, high data traffic, and the unreasonable alert of Google Play clean apps and other official marketplaces. Finally, there was one point to earn for additional security measures, such as anti-theft, encryption and backup.

To achieve six points in detecting Android malware, it was not necessary to score 100 percent. Therefore, ultimately, AhnLab, Antiy, Bitdefender, Cheetah Mobile, G Data, Kaspersky Lab, McAfee Symantec, Tencent and Trend Micro can reach the maximum 13 points. Google Play Protect was evaluated only on malware detection. Due to the low detection score, the software receives zero points. Of the anti-virus applications tested on all components, NSHC and F-Secure end with 9 and 9.5 points, respectively, below.

Wednesday, 20 April 2016

Chat App Viber Also Adds End-To-End Encryption



The popular chat and VoIP app Viber, which has over 600 million users in their own words, will encrypt all calls through end-to-end encryption. It developers have announced today . Through Viber users can chat with each other and whistles.

By adding encryption have Viber users under the assurance that their messages are not intercepted, whether it's for group or one-on-one meetings and regardless of platform. All that users have to do is use the latest version of Viber. Then, the chat app will show if the call is encrypted.

Users will see a gray lock when the call is encrypted. It is also possible to authenticate contacts manually. In this case, the lock will be green. Rolling out the encryption will take place over the next two weeks. In addition to the announcement of encryption Viber also has "Hidden Chats" revealed. Through this option, users can hide certain conversations in the main window so that only the user knows that they exist.

Tuesday, 19 April 2016

BlackBerry CEO Cryptically On Assistance To Canadian Police



BlackBerry CEO John Chen has responded at a news that BlackBerry Canadian police would have the encryption key to the encrypted BlackBerry messages could decrypt. Chen does not want to confirm or deny the report.

Last week Vice Magazine came out with a report showing that Canadian police were able to decrypt encrypted BlackBerry messages. At that BlackBerry did not respond, but last night there appeared a blog posting by Chen . In it he argues that tech companies must meet reasonable court orders to give investigators access to data. He also repeated his earlier statement that it is objectionable as companies put their reputation over the public interest.

He then briefly discusses the case of the Canadian police, but would not say whether the Canadian police indeed received the encryption key. Chen said the only thing is that BlackBerry has held in this case to its own principles. "For BlackBerry, there is a balance of what is right, such as helping in the detection of criminals, and prevent government violate the privacy of citizens. We have found this balance, even though governments have pressured us to our ethical principles change."

Friday, 27 November 2015

EFF Wants Stronger Encryption Against Terrorists And Criminals



If the government were to ask people to remove the good locks on their doors and windows and replacing them worse so that government employees can penetrate more easily in case someone is a terrorist, no one would accept this because bad locks make everyone vulnerable.

Yet this is exactly what governments and law enforcement agencies in the case of encryption will, according to the American civil rights movement EFF. Regularly advocate agencies like the FBI to add backdoors in encryption, ensuring encrypted communication can still be tapped. This is similar to prevent people from getting access to good locks and locksmiths can produce good locks.

In this last example, most people would understand that this is not a wise idea, says Cindy Cohn of the EFF. However, when it comes to Internet and technology, such as the operation of encoding, which for many people is less clear. Parties such as the FBI and politicians would also have known better, says Cohn. "The answer to insecure networks and digital technologies must be correct in order to make them safer."

But that is not what is happening, so she continues. Policymakers are therefore urged to take this into account. "Ensuring that everyone's door is unlocked, is not the answer to crime or terrorism. That is the development and support of better security," Cohn decision.

Tuesday, 10 November 2015

Researchers Crack Linux Ransomware By Design Flaw


Researcher managed to crack the Linux.Encoder-ransomware for Linux so that victims without paying their files to recover. The ransomware was last week announced by the anti-virus company Doctor Web. At the time, it was unknown how the ransomware spreading.

It was known that it was mostly web servers that were infected. Now the Romanian anti-virus company said Bitdefender attackers use a vulnerability in the popular content management system magento to access servers. Then they install the ransomware, which looks a lot like Windows ransomware. Like Windows-based ransomware encrypts Linux.Encoder files with AES. The symmetric key is then encrypted with an asymmetric encryption algorithm (RSA).

When designing the ransomare the creators have made ​​a big mistake, allowing researchers Bitdefender can identify the AES key without that first with the RSA private key must be decrypted. The ransomware does not use any keys and initialisation vectors for encryption, but leads these two pieces of information on a specific feature in combination with the time of the encryption. This information is easily retrieved and, according to the researchers, a major design flaw. They now have a tool(zip) has been developed which automatically encrypted files can decrypt.

Friday, 30 October 2015

Tor Launches Chat Program Secure Chat


The creators of the Tor network have launched software that allows users of many different chat programs or channels through one simple encrypted chat program. Tor Messenger as the chat program is called, sends messages over the Tor network.

It thereby supports different transport networks like Jabber (XMPP), IRC, Google Talk, Facebook Chat, Twitter, Yahoo, and other networks. In addition, Off-the-Record (OTR) Messaging by default. This makes the messages are encrypted and users can check that the person with whom they chat actually the person he or she claims to be. Furthermore OTR also adds perfect forward secrecy, and "deniability" so that it can be denied that the user has sent an IM message.

Tor Messenger or uses existing networks so that users with existing contacts and without much adaptation can continue chatting. This approach means that metadata can be stored by the server of the chat network. However, the route to the server is hidden, as it runs over the Tor network. The version launched today is a test version and is available for Linux, Mac and Windows.

Wednesday, 21 October 2015

Google Requires Full Disk Encryption In Android 6.0


Manufacturers smartphones and tablets with Android 6.0 supply should ensure that full disk encryption is enabled by default, according to documents (pdf) which Android Police post. Initially, Google "encryption by default" is already available in Android 5.0 Lollipop.

Later, the Internet giant decided right there to see it from. Now Google has announced that for implementations that support full disk encryption and where cryptographic calculations using the Advanced Encryption Standard (AES) over 50 mebibyte per second come standard full disk encryption is enabled. Devices with an older version than Android 6.0 were launched outside of the new obligation, unless they full disk encryption already supported. That was only the Nexus Nexus 6 and 9.

However, Google does not oblige users to turn on the screen lock. For these users, there will be a default for the disk encryption are used. When the user eventually chooses to disable the screen lock the device does not need to be re-encrypted, which could take a long time.

Tuesday, 6 October 2015

Researchers Demonstrate Quantum Cryptography Over 100km



Researchers at Toshiba's Cambridge Research Lab have quantum cryptography secure data over a distance of 100 kilometers knowledge exchange, which is a new record. The exchange took place over a single cable with a speed of 200 gigabits per second.

Quantum cryptography is a technique in which the encryption of information is performed with the aid of light, or photons. A zero or one is represented by a single light particle. At the level of single particles governed by the laws of quantum mechanics. That means that if the encrypted message is tapped, the contents of the message changes automatically.

A problem with quantum cryptography is the so-called "cross-talk", which provides a signal on one channel for problems in a different channel. The normal encoded data bits are shown in quantum cryptography by millions of photons, while the bits of the quantum key are received through a single photon. Dispersion of light makes detecting these key photons difficult, says researcher Andrew Shields opposite Electronics Weekly.

Because of the light in certain ways to filter the researchers succeeded in order to identify the key. The next step in the research is to build a network in order to demonstrate end-to-end-quantum cryptography. Earlier this year, Toshiba already announced that it is in 2020 with a communication system is that makes use of quantum cryptography, and in theory, is not to eavesdrop.

Tuesday, 29 September 2015

Encryption Software Crypt Vera Patches TrueCrypt Leak


There is a new version of Vera Crypt appeared on the TrueCrypt software-based encryption. A researcher at Google had in TrueCrypt two leaks discovered which were also present in Vera Crypt.Through the leak could be a local attacker who already has access to the system to increase its rights.

TrueCrypt is no longer supported since last year, making the two vulnerabilities are not patched. Vera Crypt is based on the source code of TrueCrypt and is still actively maintained. Besides the two vulnerabilities are also fixed several other non-security related bugs. Users of Vera Crypt therefore be advised to version 1.15 upgrade.

James Forshaw, the Google researcher who vulnerabilities discovered, suggests that this is not about backdoors, but that they unwittingly came through the TrueCrypt audit. Last year it was TrueCrypt for the presence of back doors audited, whereby various problems were found. Backdoors were not found. A few weeks after the first part of the audit was completed decided to stop the TrueCrypt developers with the development of the software. The problems found were not patched as a result, which also applies to new vulnerabilities.

Monday, 14 September 2015

Users Ashley Madison Had Often Name As Password


Users of the Ashley Madison website often used their username and password, so researchers have discovered. The group of researchers called Cynosure Prime showed last week that by some programming errors crack the password hashes of Ashley Madison are simple. At the hack of the cheaters website approximately 36 million password hashes were stolen.

Hashes to ensure that the user passwords are not immediately visible to an attacker in case the website is hacked. Ashley Madison used before a strong hashing algorithm, but by various programming errors hashes prove yet easy to crack. The researchers have cracked 11.7 million password hashes.

It shows that mainly weak and insecure passwords were used. So there were three million passwords of six characters and there were slightly less than 3 million, which consisted of eight males kara. The shortest password was cracked one character long. Nearly 10 million passwords only consisted of small letters or lowercase letters and numbers.

User Name

The researchers were also curious how many users are using their username and password. A total of 630 000 passwords were found that matched the user name. The investigators noted that the actual number is higher as possible, since there are obvious only obvious mutations were used. If there was more combinations of uppercase and lowercase letters sought was the true number is likely higher. The researchers argue that these passwords could be cracked too easily without programming errors found.

Striking Passwords

Instead of publishing a list of the Top 10 most common passwords, the researchers decided to create a collection of distinctive passwords. It is about passwords as allthegoodpasswordshavegone ',' youwillneverfindout ',' everynameitriedwastaken ',' goodguydoingthewrongthing ',' thisisagoodpassword 'and' correct horse battery staple ", known from the xkcd strip.

Thursday, 10 September 2015

Researchers Crack 11 Million Passwords Ashley Madison


Researchers have managed to crack more than 11 million passwords of Ashley Madison users, as they have announced today. The group of researchers called himself the cynosure Prime and examined the data that was stolen by the cheaters website. Attackers managed to steal gigabytes of data at Ashley Madison, including hashed passwords of users.

It involves a total of 36 million password hashes. Ashley Madison had the passwords are not stored in plain text, but in hashed form. This makes them not directly readable, but they can be cracked. For hashing the password had Ashley Madison the bcrypt algorithm used, and there was also a "salt-made 'use. This makes it much more difficult to crack password hashes. In a weaker algorithm, such as MD5, it is possible to try millions of password combinations per second. In the case of the gesalte bcrypt hashes came another researcher with his computer not go beyond 156 hashes per second. This investigator knew in five days 4000 passwords to crack.

It was therefore argued that the cracking of all Ashley Madison password hashes would last for centuries. That now seems not to be so. The researchers from Cynosure Prime investigated namely the second amount of data that was recently put online. In it they found information that helps them with the bcrypt hashed passwords could crack much faster. "Instead of cracking the slow bcrypt hashes, which is currently a hot topic, we decided to choose a more efficient approach and attack the MD5 tokens," the researchers said in their explanation.

The cheaters website appears to have used for reasons still unknown MD5 tokens. These tokens can be cracked much simpler than the bcrypt hashes. The information from the cracked tokens could then be used to crack the hashes bcrypt, she discovered. Since the researchers two weeks ago with their research, they began now more than 11.2 million bcrypt hashes cracked. In total there were in the stolen data over 15 million tokens.

Friday, 28 August 2015

Large Illegal Marketplace Offline For Tor-Vulnerability


A large illegal market on the Tor network has decided to temporarily offline due to vulnerabilities in the Tor network, so have the managers through Pastebin announced. It is Agora, the largest illegal market on the Tor network.

Through the website is handled in narcotics. The Agora administrators point to recent studies showing that web servers can be identified on the Tor network. These so-called "Tor hidden services" are only accessible via the Tor network and should not be localized. Recently, researchers showed that they were able to identify 88% of the hidden services in a test set-up.

According to the Tor Project, the developers of the Tor software and the Tor network, the impact of the attack revealed that bad. Yet the reason for the administrators of the Agora marketplace to temporarily pull the plug on the website. In a statement they say that it is unsafe to allow visitors to the website, since they are at risk. It is now working on a solution, but it is unknown when they will appear.

Tuesday, 25 August 2015

Researcher Cracks 4000 Passwords Ashley Madison


A researcher has managed to crack 4000 passwords of users of Ashley Madison, which demonstrates how important it is to choose a strong password. Attackers managed last month to steal a large amount of data from Ashley Madison, the site for cheaters.

The data were published last week in part. Among the stolen data there were also 36 million password hashes. Ashley Madison had the passwords are not stored in plain text, but in hashed form. This makes them not directly readable, but they can be cracked. Dean Pierce, Linux security engineer at chip giant Intel, password hashes ended with his special "squat machine" to crack.

Computer Pierce consists of four R9 290 ATI video cards. For hashing the password had Ashley Madison the bcrypt algorithm used, and there was also a "salt-made 'use. This makes it much more difficult to crack password hashes. In a weaker algorithm, such as MD5, it is possible to try millions of password combinations per second. In the case of the make bcrypt hashes came Pierce with his computer not go beyond 156 hashes per second.

The experiments also revealed the extent of the number of password hashes problematic, so he could load 6 million of the 36 million password hashes. For cracking the hashes he used the RockYou dictionary. RockYou is a company developing widgets for social media. In 2009 it was hacked, giving attackers more than 32 million managed to steal passwords. These passwords were stored in plain text, and finally appeared on the Internet. Since then the passwords of RockYou be used by many researchers as the default password cracking.

Crack Time

Pierce had his machine power for five days, during which he finally managed to crack 4000 passwords. That equates to 32.6 cracked passwords per hour. It also showed that there were 1191 unique passwords between. The most common password is "123456", which occurred 202 times. It also showed that 105 users had chosen the password "password". Pierce made ​​a Top 20 of the most common passwords. The list is very similar to other password lists that are regularly published.

According to the researcher, it is probably impossible to crack each bcrypt password, but will in the case of Ashley Madison eventually many passwords are outdated anyway. It is in this case especially for weak passwords which are found in many dictionaries, or simply through brute force to retrieve his. Thus, on the list of passwords of the short Pierce especially less than eight characters.

Monday, 3 August 2015

Tor Project Not Worried About Another Attack On Hidden Services


Scientists have found two ways to hidden services on the Tor network and its users, identify, but according to the Tor Project is the impact of the attacks it. Hidden services include websites that can be hosted on the Tor network. The address of the website is generally known only to the administrator and the website itself can only be accessed through the Tor network.

The well-known marketplace Silk Road was an example of a hidden service. According to scientists from MIT and the Qatar Computing Research Institute (QCRI) there is a vulnerability ( pdf ) present in the design of Tor, which can be established that makes a Tor user of a hidden service use. Hidden services themselves could be identified with an accuracy of 88% and a comparable rate could be determined which sites a user has visited.
Tor network

The Tor-network consists of several nodes, also known as relays, on which the traffic runs. It is in this case for servers of the user's request, for example to ask a website via the Tor network to forward. For example, the first node is the "entry guard" that the request of the Tor-user to the "relay node" forward. Then it goes from this node to the "exit node", which sends the request to the Internet. An attacker or intelligence can add one or more servers in the Tor network. However, the attacker can not determine which node the user will use.

According to Tor developer Roger Dingledine consists attack the scientists of three phases, so he lets in a blog posting know. During the first phase, the attacker must have the luck that his server as entry guard is used by the user that he has in mind. During the second phase, the user loads a web site via the Tor network and investigators use a classifier to guess whether it is a web site on the Tor network or on the "ordinary" internet.

Next, a second classifier is used to determine which site-Tor was. According Dingledine is the extent to which the classifier used by the researchers to identify websites is accurate. The research was based on a thousand websites, but according to previous research would be millions of websites are hosted on the Tor network. In this case, the researchers would in most cases not been able to establish the identity of a web site.

In addition, there are also steps which may take the Tor network which make it more difficult for an attacker to determine or create a target site with a gate-connection or not. Altogether Dingledine is pleased with the study because it raises some interesting questions, however, the impact of the attacks described in the really easy.

Saturday, 27 June 2015

Cisco Fixes Problems Again With Standard SSH Keys


Cisco offers weather updates for different products released due to the use of standard SSH-keys. Using the default SSH keys, an attacker remotely without valid credentials on a login system with root privileges. The only thing that is required is that the attacker can connect to the platform.

According to Cisco, the problem is that all installations of the Web Security Virtual Appliance (WSAV), Email Security Virtual Appliance (Esau) and Content Security Management Virtual Appliance (SMAV) share the same authorized SSH key for the remote support functionality. Also, an attacker via the SSH host key can also all appliances is the same, and all communications between virtual appliances decrypt and mimic.

Cisco has released updates to fix the problems. Last October there appeared an update of a similar problem in the Cisco Unified Communications Manager Domain. The networking giant has announced that to their knowledge the newly discovered problems are not yet attacked or were previously known on the Internet.

Tuesday, 23 June 2015

Toshiba Promises Quantum Cryptography 2020


The Japanese electronics giant Toshiba says that in five years with a communication system is making use of quantum cryptography and in theory is not to eavesdrop. This was reported by the Asahi Shimbun . The testing of the quantum key distribution according to the company is located in the final stage. Earlier tests with long-distance communication would have been a success. In late August there will be a test of two years to test the resistance of the system before it goes to market.

At current encryption systems are working with secret keys. Once the key has been stolen, the data can be decrypted. Quantum Cryptography is a technique in which the encryption of information is performed with the aid of light, or photons. A zero or one is represented by a single light particle. At the level of single particles governed by the laws of quantum mechanics. That means that if the encrypted message is intercepted, the content of the message changes automatically.

The Toshiba system first sends the secret key and then the data. If it appears that the secret key is intercepted, the data will not be sent and intercepted key is turned off. Photons are, however, unstable and the development of a system to communicate over long distances has always been a major obstacle. Toshiba has improved the precision of the photo transmitter, where there is now photons over a distance of 45 kilometer may be sent. The test that begins shortly aims to solve the final obstacles so that the system, in practice, may be used.

Friday, 29 May 2015

"Dormant" Ransomware Makes Victims Worldwide


Main Locker Screen
This week, the world of computers with a new ransomware variant infected become infected systems which quietly and suddenly became active on 25 May. It is the locker-ransomware which like other kinds of ransomware specimens encrypts files on the system.

According Bleeping Computer is a large number of people worldwide affected by the malware. After the encryption users will see a notification that they have to pay 0.1 bitcoin. That comes with the current exchange rate equivalent to 22 euros. An amount that is one-tenth of what questions ransomware many other instances. In the warning that users get to see is further stated that they should not investigate Locker ransomware or remove, because the private key will be destroyed and the data is no longer decrypt.

Experts, however, that this is just a way to scare people so that they pay the amount requested. Besides the forum Bleeping Computer are also social news site Reddit been several reports of the victims appeared to have the amount paid. It is the low price of 22 euros given as a reason to watch or by paying the files are recoverable. Several victims have thereby know that after the pay could decrypt their files and so got back.

How Locker ransomware exactly spreads is not yet confirmed, but possibly it is a cracked version of Minecraft or sports streaming sites, although e-mail attachments and exploits are mentioned. The ransomware would just delete the Volume Shadow Copies on the C drive. This would be possible through the Volume Shadow Copies of other disks for files that have been encrypted there without paying retrieve .

Thursday, 21 May 2015

New Encryption Leak Threatens Web Servers And Mail Servers



A well-known cryptography professor has discovered a vulnerability in TLS encrypted connections allowing attackers to web and mail servers to attacks and eavesdropping. The vulnerability by Matthew Green " logjam "named and located in the Diffie-Hellman key exchange , a cryptographic algorithm that Internet protocols can establish an encrypted connection. It is essential for various protocols, including HTTPS, SSH, IPsec, SMTPS and protocols that rely on TLS.

Through the logjam attack attacker can, located between the victim and the Internet is vulnerable TLS connections to a 512-bit encryption downgrade. This allows an attacker to decrypt all the data on the encrypted connection and thus read and adjust. The vulnerability is similar to the FREAK-attack which was unveiled in March. Both vulnerabilities are caused by the US export policy in the early 1990s, making strong encryption could not be exported. Instead, if there is only "export-grade" encryption provided. The encryption keys were allowed in this case only 512 bits in size. However, the logjam-attack is focused on the exchange of keys via the Diffie-Hellman algorithm in place of the RSA-algorithm.

The attack affects all servers that Diffie-Hellman "export" encryption support. According to Green, all modern browsers and 8.4% of the 1 million most visited websites on the Internet vulnerable. The researchers experimented with attacking the most common primes 512-bit Diffie-Hellman used to exchange keys and were thus 80% of the servers with Diffie-Hellman "export" encryption downgrade. An intelligence could crack a 1024-bit prime and thus tapping 18% of encrypted connections from the 1 million most visited websites. Cracking a second prime number would make it possible to monitor 66% of VPN servers and 26% of the SSH servers.

Owners of a mail server or Web server are advised to disable the support of export encryption and generate a unique 2048-bit Diffie Hellman Group. Internet users should install the updates for their browsers as they become available. All suppliers are now working on an update. Finally get the advice to system administrators and developers to ensure that TLS libraries up-to-date and Diffie-Hellman Groups are refused less than 1024 bit.

Millions Of Routers Vulnerable To Criticism NetUSB Leak


A critical vulnerability in a component that "USB over IP" functionality to routers offers ensures that millions of routers at risk. Before warns security firm SEC Consult . The vulnerability is present in the NetUSB software of the Taiwanese Kcodes.

NetUSB via USB devices such as printers, external hard drives and USB sticks that are connected to a Linux-based embedded system, such as a router or access point, are accessible via the network. For this load a Linux kernel driver that starts a server on port 20005. Standard was the feature on all devices examined on SEC Consult.

Using the vulnerability, an unauthenticated attacker got on the local network to cause a buffer overflow resulting in a Denial of Service or in the worst case, the execution of arbitrary code. In some devices, it is also possible for a remote attacker to execute arbitrary code and thus take over the device.

The problem is a large number of manufacturers, including Netgear, TP-Link, Zyxel and D-Link and probably Western Digital, and Sitecom TRENDnet. The complete list of manufacturers in the advisory to find. Users are advised to install new firmware, if available. Other solutions are blocking port 20005, or disable "USB device sharing".

Friday, 1 May 2015

New Ransomware Avoids US Computers


Researchers have discovered a new ransomware variant that strikes because the US does not infect computers intentional. Crypt0L0cker such as ransomware called, according to researchers from Bleeping Computer a version of the famous Torrent Locker ransomware.

Crypt0L0cker appears to use the same communication methods as Torrent Locker and encrypts all kinds of files, which then users hundreds of dollars can be decrypt. If victims do not ransom doubling pay on time.

Why Crypt0L0cker US avoids computers is unknown. In the past happened that Russian cyber criminals infecting computers no Russian, so as not to attract the attention of the Russian authorities. The new ransomware is now in Europe, Asia and Australia surfaced and spreads via emails posing as traffic violations or government posts.