Showing posts with label Security Articles. Show all posts
Showing posts with label Security Articles. Show all posts

Lessons Learnt fom Sony Flaw

As you all might notice, earlier 2011, Sony is again in the highlight of news for getting attack from various hackers, exploiting their PlayStation network (PSN) which has roughly 55 millions of users and the music streaming network, QrioCity.

During the attack, Sony PlayStation network has been shutdown, following the forensic security testing. It could be one of the largest case of data theft about 77 millions users. The details of how the attack has been occurred has not yet been published.

However, in Dec 2010, during the Hackers Chaos Communications Conference, the hacking team known as "FailOverflow" has revealed in their presentation that they are now able to decipher the private key used in Play Station 3. Having the private key will allow the users to run any application on the device just like the Sony manufacturer. Sony responded by suing the FailOverflow group, the firmware creator "GeoHot" and others for revealing the root key details and cracks for PS3. Another hacker known as Mathieu Hervais has also discovered the walkaround to the PS3 Firmware 3.56 and announced it in his twitter account. However, he was afraid of Sony legal team, therefore chose not to release the information.

I truly convinced that there is no such thing called "absolute security". Any network that are exposed to public are vulnerable to attack given the skills, resources and time. While feeling sorry for Sony, I am also disappointed that Sony has overlooked the basic security requirement of data.

For instance, Lutz security said that the data stolen from Sony are completed unencrypted. Although I do not know if this information is true, I would think that all the companies and websites that keep the user login, password and important information such as credit cards details must be stored in encrypted format. I realized some programmers simply store the information on their database in plaintext!!!

And the latest series of attacks are in SQL injection according to the AppleRiver. And if these claims were true, I simply think this is a total negligence of Sony for allowing such kind of attacks. This SQL injection should simply not happen.

From this episode, we must be aware that no network is totally secured. All the companies and websites must be proactive in securing their information. By losing to attackers out there, it is not only the unexpected shutdown and expensive forensic analysis but also lose the confidence of customers. While using legal team to contain the damage, you should not forget about the prevention if your business has the nature of online activities.

As for the users, it is very important that your information has been stolen. If your credit cards details are leaked, your card might be misused by someone out there. Most users has the habit of keeping the username and password similar across all kinds of websites, it is likely that once your email password are exposed, your social account such as fackbook and twitter might be stolen too. If you are the one of the stolen customers, you may check with your credit card company on how to control the damage if your card were stolen.

With this unpleasant occasion, Is it a time for the data security to pass to the central authority instead of allowing any individual to keep your valuable information? After all, it is about trust between the service providers and the people.

National Authentication Framework (NAF)

This article that I have just seen reminds me one of system securities core values - CIAA (confidentiality, Integrity, Availability and Authenticity). Singapore IDA formed an subsidiary called "Assurity Trusted Solutions Pte Ltd" to oversee & manage their vision called iN2015 master plan to provide secure & trusted party authorizing 2nd Factor Authentication (2FA).

Currently, Online Banking in Singapore is heavily using 2FA - if you are one of the online banking users, you might be holding a token or a cell phone that the authentication codes will be sent to you after you login. Singapore IDA is taking over this stuff to become in charge of this 2FA instead of individual banks. Its main purpose is to make a single authentication device instead of using multiples from various service providers. It also mentioned that business can enjoy cost saving since they do not need to implement it by themselves.

Please allow me to revisit what we learnt about authentication. It is about proving who you really are - that is authentication. There are 3 ways to verify someone - something you know (like your email password), or something you have (like your ID card) or something you are (like your fingerprint or voice). If we want to enforce the systems, it is easy - use more than one verification methods.

Overall, it seems it has benefits to many angles of life. But one thing that come across my mind is "responsibility". First, let's say you are logging into one of Singapore Local bank (says DBS). You got to login using your username and password that the database is maintained in the bank. After you have supplied the correct username and password before your maximum tries is over or before the session timeout has occurred, you will be asked to enter the 2nd authentication code.

If IDA is supplying the 2nd authentication code, that caused me a lot of wonder. First, who is now maintaining the username and password? IDA or individual banks? Moreover, some transactions are considered as sensitive transactions such as fund transfer or paying bills. Such transactions require the 2nd authentication code.

And in the case of online fraud or some undesired event happened, who is now answerable? Bank or 2nd Authentication Code Provider? This is very confusing indeed. When the 1st authentication and 2nd authentication verifiers are different, the arguments of holding the responsibility now fall in grey area.

To see full story about the NAF, read in Straits Times.

A Programmer's Life???

I just received an email from a friend and I think the image is quite true and hilarious. Programmers always require small things to be happy and also small problems to become frustrated. They live in a different world, a tiny one. They are fragile and often tortured by the managers. Here is a programmer’s life.


Enjoy~~~

How does the word "Hacking" appear?

Recently, I was asked by my close friend who had just started to learn computer and some basic programming. His question is "what is a hacker? What does hacking mean?" I think for long, but I do not have clear idea about it. I try to search all available information on internet. And i hope this could be an interesting for you. I am sorry that it is a bit wordy.

The word "HACKING", different people have different views on the hacking scene. There is no official definition of a hacker, rather a vague idea among the masses. The media loves to add false information to draw more attention for the sake of their revenue.

It began in 1960s at MIT, origin of the term "hacker", where extremely skilled individuals practiced hardcore programming in ColdFusion and other older languages. They are, by far, the most intelligent, individual and intellectually advanced people who happen to be the pioneers and forefathers of the talented individuals that are today the true hackers. In 1969, Bell Labs employee Ken Thompson invented UNIX and it permanently changed the future of computer industry. In 1970s, Dennis Ritchie invented programming language "C", which was invented specially for UNIX. Eventually, "C" creased the usage of assembler due to its portability.

The term HACKER was accepted as a positive label slapped onto computer guru who can push computer systems beyond their limits. A network known as ARPANET was found by Department of Defense in United State as a means to link government offices. In time, ARPANET evolved into something today known as the Internet.

In 1990s, Kevin Mitnick is arrested after being tracked down by Tsutomu Shimomura. Kevin is a computer security consultant and he committed computer and communicated-related crimes using social engineering. The trials of Kevin Mitnick were the most publicized hacker trials in hacker history.

Hackers have developed methods to exploit security holes in various computer systems. When hacking first originated, the motivation was based purely on "curiosity". They are curious what the system did, how the system could be used, how the system did, and why the system did that way.

Recently, the way and intention of hacking has been changed. They overload email servers by sending massive amount of email to one address causing to drain system memory resources. It also used as a tool as to hack into websites to send political message. In 1999, for example, NATO conflict in Yugoslavia, hackers attacked websites in NATO countries, including the United States, using virus-infected email and other techniques. It becomes weapons the times of war, where enemy country has highly depending on computer systems.

Hackers today are just like everyone, it might be black, white, asian, european, tall, short, socially active, cool, nerdy. Although there are people running around saying, "Look, I took down this website or this email address, I did it, and therefore I'm a hacker" doesn't mean they're a hacker. They are fakes and wannabes.

And finally, I would like to remind that if you naively believe that you have right to access information even harmless computer intrusions, it can trigger criminal sanctions. Simple advice is "do it for your innocent digital thrill seeking, but don't forget the law".