Friday, 3 April 2015

Researchers Found No Backdoor In TrueCrypt


Researchers have completed the investigation into the cryptographic functionality of TrueCrypt and found no backdoors or other intentional introduced vulnerabilities in the encryption software. However, the software is not perfect and contains some errors. TrueCrypt is a popular program for encrypting files and computers. Despite the popularity of the source code and cryptographic functionality of the software has never been audited.

Several experts therefore decided to raise money through crowdfunding for an audit. Last January, the TrueCrypt boot loader and Windows kernel driver audited, with the audit report was presented in April of the same year. There were no backdoors to be present in the software. The second part of the audit would focus on the cryptographic operation of the encryption program.

End of May 2014 decided the TrueCrypt developers suddenly stop the development of the software and advised users to stop using. This ensured that the audit of the cryptographic operation was delayed, but early this year was yet started. The results have just been published ( pdf ) showing that TrueCrypt is a well-designed encryption program.

There were no intentional backdoors or other serious design errors encountered that would infest the software. However, the software is not perfect, says cryptography professor Matthew Green . The auditors discovered "Programming imprudent" several errors and that in some cases can lead to problems that TrueCrypt guarantee less than desirable.

Biggest problem

The biggest problem was found for the "random number generator" (RNG) of the Windows version. TrueCrypt used to generate the keys that TrueCrypt volumes are encrypted. An important part, because if the RNG is predictable, this may undermine the security of the system. The RNG in TrueCrypt is based on a design from 1998 by Peter Guttman. This RNG is trying "unpredictable" values ​​from disconnecting it and used here include the Windows Crypto API.

In very special cases, the Crypto API could not be initialized. If this happens TrueCrypt would have to stop and give a warning, but the program seems to accept this quietly and continues to generate keys. According to Green, this is not the end of the world, because the probability of this happening is very small. Addition, it would TrueCrypt, in addition to the Crypto API, also retrieve values ​​from other parts of the system, such as mouse movements. This is probably good enough to protect users, notes the professor. "But it is a bad design and should definitely be resolved in divestitures of TrueCrypt."

Sleepless Nights After Infection By Ransomware


An Irish businesswoman was strange to watch when she was a seemingly innocent YouTube link on Facebook and clicked her computer suddenly was infected with ransomware. All files, both business and private, were encrypted. To access they had to pay two bitcoins, which corresponds to 450 euros. She saw eventually forced to purchase the bitcoins and to pay the ransom.

The whole process took two days and gave her sleepless nights, she leaves in front of the Belfast Telegraph know. "It was just a link on Facebook, and it seemed to me it on a YouTube video. I thought it was safe and had no doubts." The woman was especially afraid of losing her private pictures. In addition, the computer also contained all kinds of business data of its business.

Paying the bitcoins was no easy task, so let them know. "The person I bought them wanted to validate me. They had to show a photo ID and ID card. They had to know that I was a real person." After she had paid her files were decrypted after half an hour. It took more than a day before it was operational again. The woman describe the whole event as a very stressful situation. From examination of Threat Track among 250 US IT professionals of medium-sized companies shows that 30% are willing to pay in the event of ransomware.

Tool Protects WiFi Networks Against Malicious Access Points


To prevent employees and other Wi-Fi users with hostile access points to connect to a programmer has developed a tool that offers protection against this. Through EvilAP_Defender like tool called Mohamed Idris, network administrators can discover so-called evil or rogue access points and prevent them from WiFi users attacks. A rogue access point is a Wi-Fi network as another Wi-Fi network to make do with the ultimate goal that employees through this network connection. Then the attacker could intercept and perform other attacks.

Once active EvilAP_Defender can send an e-mail to the administrator when a rogue access point detected. Soon there will also appear for SMS support. The tool can also be set to perform a Denial of Service attack on the rogue access point, so that the network administrator has time to take action.

The tool will only perform against rogue access points with the same network name the DoS attack, but a different BSSID (the MAC address of an access point), or if they are running on a different channel. This should prevent a DoS attack is performed on the legitimate network. On Reddit , where Idris tool announced yesterday, let him know that there is also a control signal. He also has plans to later develop a client-server version in which there are arranged at various places sensors that look for rogue access points.

WordPress Sites Lead To Infectious Pirate Bay Clone


Researchers at Malwarebytes have different hacked WordPress sites discovered that send visitors unnoticed into a clone of the popular torrent site The Pirate Bay. Since then attempts to spread malware in Adobe Flash Player through a recently patched leak.

The website has been set up through "The Open Bay Project", an initiative that allows anyone with minimal technical knowledge can make a "copy" of the Pirate Bay online. The website features the Nuclear-exploitkit. This exploitkit abuse of a vulnerability in Flash Player that Adobe was patched by the end of January. In the case of visitors to the WordPress sites miss this update, they can become infected by a banking Trojan.

This is a Trojan horse that attempts to steal money from online bank accounts. WordPress sites are also not up-to-date and prove an outdated version of the rotating RevSlider plugin. Recently it was announced that there are thousands of WordPress sites using a vulnerable version of this plug-in have been hacked.

Thursday, 2 April 2015

Critical Vulnerability In Google Chrome Patched


Google has released a new version of Google Chrome released that fixes four vulnerabilities, including a critical vulnerability that the underlying operating system in the worst case could be full. Visiting a malicious or hacked website or see getting an infected ad would have been sufficient in this case.

This kind of critical vulnerabilities are rare in Google Chrome. Last year there were only three of these types of leaks reported in Chrome. Critical vulnerabilities allow an attacker to run arbitrary code on the computer can perform, such as installing malware, come because of the sandbox security in the browser rare. In addition to a leak in the browser must also be a leak in the sandbox are found to execute code on the underlying system.

The vulnerability, which consists of various bugs, was reported by an anonymous security researcher. Google rewarded the researcher before with a total of almost $ 30,000. Besides this leak is also a vulnerability patched during the Pwn2Own contest was demonstrated. Researcher Jung Hoon Lee aka "lokihardt" succeeded during the event in order to execute arbitrary code via various vulnerabilities. Update to Chrome 41.0.2272.118 will happen automatically in most cases.

Google Says Trust Certificates In Chinese CNNIC CA


Due to a recent incident with wrongly issued SSL certificates for Google sites Google has confidence in the Chinese certificate authority (CA) CNNIC terminated, which Google products such as Chrome will no longer recognize the certificates of CNNIC. Something that will be implemented through a future update for Chrome. Since this is very big impact, particularly Chinese Chrome users will have Google has decided to permit temporarily issued SSL certificates under CNNIC even by placing them on a public whitelist.

The reason for the measure is the recent discovery of rogue SSL certificates for various Google domains that were created by the Egyptian company MCS Holding. The company had been given the opportunity of CNNIC, which is a root CA. As root CA is CNNIC trusted by all major browsers. CNNIC had spent an intermediate certificate for MCS Holding, which the company for arbitrary domains could create SSL certificates. Because the intermediate certificate of CNNIC came, they were created SSL certificates also trusted by browsers.

According MCS Holding made ​​a human error sure that the existence of the rogue Google certificate was discovered. Google, Microsoft and Mozilla therefore decided to block these certificates. In addition, the CNNIC was heavily charged that MCS Holding gave an intermedia certificate, which the Chinese company had violated all sorts of rules. After further investigation, Google has now decided to tell all the confidence in CNNIC.
Certificate Transparency

Google argues in a statement that it believes that no other unauthorized SSL certificates have been issued or that the rogue Google certificates are used outside the test environment of MCS Holding. Regarding the Chinese certificate authority that Google must "Certificate Transparency" before implementing any request about the renewed confidence of CNNIC is considered.

Certificate Transparency is a technology developed by Google and is intended to address several structural flaws in the SSL certificate system. Thereby to unjustifiably spent and rogue SSL certificates are detected earlier. Mozilla has also decided to Certificate Transparency support .
Update

CNNIC called Google's decision unacceptable and unwise. The Chinese CA Google also calls to take the interests and rights of users into consideration. CNNIC let customers know their rights and interests will not be compromised.

Researcher Could Remove Any YouTube Video


A security researcher has discovered a vulnerability in YouTube so he could remove any video on the popular video site. Kamil Hismatullin Google had received a "fair" to search for vulnerabilities in certain Google services. In late January, Google announced a new experimental program for security researcher. Researchers previously already received a financial reward to investigate vulnerabilities.

Hismatullin focused on YouTube Creator Studio, an app that allows users to manage their YouTube channel and statistics to retrieve. Looking for different vulnerabilities ran the researcher at a logic bug, so he could remove any video via a single request. Specifying a video ID with its own session token proved to be enough. Hismatullin reported the problem on a Saturday morning. Yet it quickly by Google was picked up and corrected within a few hours. For his bugmelding received the investigator $ 5,000. As proof, he made demonstration video below.

Tor-Flyer For Police And Citizens On The Internet Anonymously


Every day, hundreds of thousands of people using the Tor network to protect their online identity and privacy. Yet there is still much confusion about how the Tor network and the importance of online anonymity. Therefore, the Tor Project has several informative flyers ( pdf ) made ​​for police and citizens explaining the operation of the Tor network and the importance of anonymous internet.

Through the Tor network users can hide their IP address such as "hidden" visit websites that are only accessible through the Tor network. In recent months, several of these sites by the authorities off the air. The most Tor users are ordinary citizens who want to keep control over their privacy, so the Tor Project has announced in the flyer for police and investigative services.

The network is also used by journalists, activists and people in countries with totalitarian regimes or internet censorship. It is also handy for police and undercover operations. So use investigative services also the Tor network for their research."Because of the identity and location of hiding researchers Tor can be a valuable tool for successful online undercover operations," so let the flyer.

There is created a flyer for citizens showing the importance of anonymous Internet and online freedom is explained. According to the Tor Project is anonymity under fire as never before, allowing the ability to share free information on the Internet is undermined. "Countries monitors on each other and their citizens, block websites, watching the contents of traffic and reduce important world news." Organizations that deal with internet freedom can also order the flyers.

Wednesday, 1 April 2015

Five Percent Google Visitors Infected With Adware


More than five percent of all people who visit websites from Google is infected with adware and within this group has at least half two or more "ad injectors" installed. This involves software that injects or replace ads on websites. According to research from the University of California that will be published on May 1, but the most important details of which Google has already put online.

According to the Internet giant ad injectors are a big problem. It is about users of both Windows and Mac, with Internet Explorer, Firefox or Chrome works. The adware is often bundled with other programs or via advertisements. Google received since January this year more than 100,000 complaints of Chrome users on ads that were injected. This makes it the most common problem that users complain about.

The researchers discovered further 192 misleading Chrome extension where 14 million people were victims become.Furthermore, it appears that 34% of the Chrome extension that injects ads as malware is to classify. For Internet users from adware and other unwanted software to protect warns Google Chrome users since late February for websites where these programs are offered. Last week, Google made ​​this opportunity available for Mozilla, Apple and other parties.

On Lockable Pop-up Problem For iPad Users


Internet users in recent months with persistent pop-ups face that warn of known problems and very difficult to conclude. In case the pop-ups appear on iPads users have no choice but to turn off the tablet, restart and clear the history and institutions. That leaves Gary Warner of Malcovery know.

The pop-ups are scattered through various websites. There is a version that resembles a message from Norton and then displays a pop-up that a certain number of a help desk to be called. Each time the pop-up plays back the sound of a phone.The scammers behind the popup use all sorts of tricks to prevent users who can connect. For example, the right-turn off and sets the pop-up is always located in the center of the screen.

Warner recently discovered a variant on the iPad. "Because a mouse and keyboard on the iPad missing, this version of the browser pop up very annoying." The pop-up ensured that could not close the researcher Safari. Eventually he had to turn off his iPad and then delete its settings and history. Standard Safari charges the last open site, which in this case is the pop-up.On the forum of Apple are also many posts to find users who complain about the problem.

The pop-ups are focused on both Windows and Apple users and people try to make a phone call. This help desk tells people that the computer is full of malware or other problems. To solve this "trouble", the user must pay for hundreds of dollars."Anyone who has seen these pop-ups get where it is recommended to create a support telephone number to call is a crook and should immediately close the session," said Warner.

Tor Is Promoting Use Of Hidden Websites


The Tor network not only provides users the ability to hide their IP address, even turning and visiting hidden sites and services is possible. And it is this feature of Tor developers who now want to bring wider attention.

Through the hidden sites and services, on the Tor network if hidden services identified, people can share information anonymously and safely. So bloggers, activists, journalists and organizations under other totalitarian regimes use it.Newspapers like the Washington Post and Human Rights organizations like Amnesty International use them again to receive leaked information. "The potential of hidden services is huge and much still needs to be explored there," said Tor developers.They want to make the technology therefore accessible to a larger audience.

The Tor developers look for hidden services namely an important role when it comes to the future of secure communication.To realize this, the uses of hidden services will have to be increased, there must be mobile support for mobile applications and will eventually also the number of people that have to grow hidden services used. At this time, approximately 4% of the Tor-traffic originating from hidden services. To determine where the emphasis will be launched a crowd funding campaign on.

While looking for the Tor Project ideas for hidden services to crowd funded. Meanwhile, there are three ideas conceived, including an information for administrators of hidden services and hidden services where anonymity is paramount but speed.In this case, the hidden service will not care about their own anonymity, but that visitors anonymously and securely connect through the Tor network. It involves, for example initiatives of Facebook and Reddit to also be active in the Tor network.Other ideas via this page to reach out to.

American Ex-Officers Indicted For Theft Bitcoins


Two former US agents are charged with the theft of bitcoins that were used during the investigation into the online drug marketplace Silk Road and seized. It is an agent of the Drug Enforcement Administration (DEA) and an agent of the Secret Service.

The two officers were part of the Baltimore Silk Road Task Force, which investigated the illegal activities of the Silk Road.Through the Silk Road were all kinds of drugs marketed. The administrator of the marketplace in late 2013 arrested and sentenced early this year. The DEA agent operated as an undercover agent and made ​​contact with the administrator of the drug market. However, the agent would without permission different online identities have used that were involved in criminal activities, including the steal of bitcoins from the US government and the defendants that he had to investigate.

He asked as part of the research for bitcoins and got it from the government. However, he did not indicate that he had received the digital currency and made the money to his own private-account. He would also information about the government investigation of the Silk Road have passed on to the administrator of the marketplace. Furthermore, the agent while he was still working for the DEA worked at a bitcoin scholarship.

There he forced the company to freeze the account of a customer and to make money from this customer to his own account. According to the FBI, the man would further unauthorized summons from the Department of Justice sent to an online payment service, which was set to release his private-account again.

Secret Service of the agent would be more than $ 800,000 in bitcoins, where he was given control over the course of the investigation to the Silk Road, to his own account at the now bankrupt Japanese bitcoin scholarship Mt. Gox have made. He then transfer the money to his personal investment account in the United States. A few days later he was for an amount $ 2.1 million in accounts of Mt. Gox studded show place. The DEA agent was arrested on March 27, while the agent of the Secret Service itself indicated yesterday.