Bits from Bill

Technology thoughts leaking from the brain of "Bill Pytlovany"

Tuesday, April 29, 2014

Computer Security Will Never Be the Same

This has been a remarkable month and the impact on how I view computer security will never be the same. The last time anything like this occurred was in the 90’s when I was infected with a complex worm looking to steal AOL passwords. When customer support told me to format my hard drive it encouraged me to create WinPatrol. The concept used in WinPatrol had never been done before but since my programming skills were busy on other projects it remained just a side project.

aprilI started April 2014 making it clear what Microsoft’s lack of support for Windows XP would really mean. By the end of the month the worse case prediction appears to be coming true. Microsoft received details of an active zero-Day vulnerability from security platform developer,
FireEye.  Not only does this threat affect nearly all versions of Internet Explorer and Windows,  attacks using this vulnerability are currently being reported. 

The software  already “in the wild” uses a Flash(.swf) file to call JavaScript in Internet Explorer eventually accessing protected memory that had been randomized as a form of protection. The entry method has been a known flaw since last October but until now wasn’t found to trigger this kind of attack. Microsoft has posted a new security advisory at https://technet.microsoft.com/en-US/library/security/2963983. The Microsoft Security Response Center has been working through the weekend  testing a solution they hope to release soon.  Even though the flaw is in Internet Explorer if you’re using Windows XP you won’t receive an update. No matter how much you’re tempted to view a video you hear about on Facebook, Twitter or in your Email, don’t do it.

tvbleed

The other major concern in April was called Heartbleed.  While the media coverage was over the top, few really understood what this software failure meant.  You may have heard that 66% of the worlds web servers were affected. In fact, less than 7% were actually running a version of the program OpenSSL that allowed access to 64kb chucks of data belonging to others.  Even with this seemingly low number, Heartbleed opens up a couple of troubling issues. Problem #1: Data exposed by this flaw was raw and unencrypted. It was available to anyone no matter how secure you made your computer or how sophisticated the attack. The attacker didn’t need to know you to access your data.  Problem #2: This event demonstrated how defenseless we all are any time we use the Internet. This was the result of a programmer and reviewers missing a simple error. I can only imagine how much of the Internet uses software with existing backdoors created by design.

This year I’ve done a lot to make WinPatrol easier and useful to a wider audience. Given these serious threats my motivation hasn’t diminished.fontalert The basic concept of WinPatrol detecting changes continues to be a model that make sense. While some attacks may require the PLUS version we have one advantage. Ironically, WinPatrol isn’t always taken seriously so it continues to notify users while many popular Anti-Virus programs are disabled.

.

 

UPDATE 5/2/2014
Microsoft has released a security update on May 1st.  This update will repair the failure found in Microsoft Internet Explorer.
Security Garden: Out of Band Security Update for IE Zero-Day Vulnerability
The patch is available as a Windows Auto Update.   Microsoft surprised many by making this available on machines running Windows XP.
WinBeta: I’m sorry Windows XP users, but Microsoft shouldn’t have patched your OS

Labels: , , , , , , , , , , ,

Share on Facebook


Saturday, December 05, 2009

Who Gets Your Personal Information on Facebook?


Are you one of the 350 million Facebook users? I’m a big fan of Facebook and like many I connect daily to see what my friends are doing and to share photos. As a security professional I am very careful about what I post and what information I allow to be shared. In that respect I’m unique. It surprises me how many of my friends will refuse to allow companies to share their information but eagerly give away their personal information to application developers on Facebook.

allowaccess

My friend Diana sent me some Christmas cheer. How could that be a bad thing right? Well, if I accept her cheer I’m sharing my personal information and all my friends with a company called Mob Science who has no physical address or privacy policy posted on their website.

Who are these application developers you’re giving your personal information too. One of the most popular developers is San Francisco based Zynga. They’re responsible for the games Farmville, YoVille, Mafia Wars, RollerCoaster Kingdom, Scrabble and dozens more. You’ll never be offered a chance to read Zynga’s privacy policy but the information is typical. They say only your name, address and gender are collected. As in most privacy policies they protect themselves with vague statements like “we don't generally collect any “Personally Identifying Informationabout our users”.

I’m not saying the folks at Zynga are evil or have bad intent but I doubt most users realize they’re providing information to this or other little known companies. Most people mistakenly believe it’s just all part of the Facebook experience.

It’s not just the games. When you take a quiz, or even donate to “Causes” you’re providing access your personal information. When you create or join a “Cause” you’re registering your personal information with Berkeley based Philotic Inc, started by Sean Parker, one of the brilliant co-founders of Napster.


If you’re a fan of Farm Town, you’ve registered with Florida based SlashKey. Popular game provider MindJolt.com is another one that doesn’t include any physical address or privacy policy on their website. The number two Facebook developer Playfish acknowledges “We collect the following personal data from you … : your date of birth, gender and your contact details including the country where you live and any phone number(s) or email address(es) that you provide.” In addition, “We may use a third party to serve advertisements on our site. Cookies may be associated with these advertisements … We do not have access to or control of cookies placed by third parties.

In the grand scheme of things the dangers from sharing your information with these companies may still be minor compared to other risks. I wanted to focus on 3rd party Facebook Applications because most people don’t understand why their Email Spam seems to know specific personal details.

Facebook Applications can access this info
Did you know when your friend allows an application, they give away all your information too?

When you sign up for Facebook all these boxes are checked as the default setting. That means if your friend allows an application, all the information you may have set to "Friends Only" is made available. Click Here to change your settings. (Update 12/9: Facebook has made some changes do don't be surprised if this page looks a little different)

Facebook has been slow to react to customer concerns but recently announced new privacy options. It’s still up to the individual user to check out their rights and options to protect themselves. If you’re a Facebook user please click here to read how you can update your privacy settings.

Updated 12/9
Facebook has updated their privacy options. Here's the replacement for the screen allowing you to restrict information shared by your friends.



Updated Facebook privacy



Facebook Simplifies Sharing your Personal Info

Labels: ,

Share on Facebook


Wednesday, February 13, 2008

Opt Out to Protect Your Privacy and Identity

The World Privacy Forum has posted their Top Ten Opt Outs which I recommend you all review. If you think the Do Not Call Registry is a great idea you’ll be excited to learn what else is available.

I know many of you are concerned about using your credit card online but you might also want to protect what information the credit card company shares(sells) about you.

According to the FDIC:

Unless you opt out, your financial company can provide your personal financial information (for example, information on the kinds of stores you shop at, how much you borrow, your account balances, or the dollar value of your assets) to non-affiliates for marketing and other purposes.
Contact your credit card company to opt-out(4)

Top Ten Opt Outs

  • 1. National Do Not Call Registry

  • 2. Prescreened offers of credit and insurance

  • 3. DMA opt outs

  • 4. Financial institution opt outs

  • 5. CAN SPAM

  • 6. Credit freeze

  • 7. FERPA
    The FERPA opt out stops schools from releasing student directory information (Name, home address, date of birth, and other information) without consent, with some limitations.

  • 8. Data broker opt outs

  • 9. Internet portal opt outs

  • 10. NAI opt out

Labels: , ,

Share on Facebook


Friday, January 04, 2008

Your Sears Purchase Details Available to World

When I first heard about this from Ben Edelman I couldn’t believe it. Unfortunately, this isn’t an urban legend you’ll find a Snopes or PhoneyMail.com. Sears has made it extremely easy for you to review the details of your purchase history. You’ll find your model number, download manuals and you can even purchase extended warranties. The only problem is you’re not the only one who can access this information.

Want to see what items your friends, family, and neighbors have purchased? Just set up a Sears “Manage My Home” account. It’s easy at http://www.managemyhome.com/. All you need is an Email address. Once you have an account just go to your home profile and click on “Find your products” under “Sears Purchase History”.

All you need now is a name and address. It doesn’t need to be your name and even the phone number you enter won’t matter. I found some purchase histories going back to 1982 and hey, I didn’t know my daughter bought a Freezer last October.

Why can I access this private purchase information?

Easy to access purchase information

Apparently the “softer side of Sears” refers to the brains of the people at the Sears Holding Corporation. If so called reputable companies are this ignorant, can you imagine what lack of privacy we all have with other companies. Anyone looking to start a class action lawsuit, let me know. I’ll be the first to sign up.

If you feel guilty looking up up someone’s information (as you should ) my address can be found by clicking here. You can see the eight items I’ve purchased at Sears in the last five years. (I actually don’t recommend the Galaxy Refrigerator which was returned.)

Update: Sears has fixed this particular stupidity due to obvious criticism.

Labels: , ,

Share on Facebook


Friday, December 14, 2007

Malware is FREE on Wireless Networks

I love that when I travel I can get online from just about anywhere. High speed WiFi networks are now available in most hotels and airports of the world. This is a big change from when I used to bring wire strippers, electrical tape and a screw driver when traveling. In my old Q-Link days hotels didn’t even have modular jacks so I used to unscrew the phone jack to wire up my 300 baud modem.

Unfortunately, WiFi public networks can be a real danger to your privacy and the security of your computer. If you’re connecting to an unsecured WiFi network your data is up for grabs to anyone with the right tools. Keystrokes, Emails and passwords on unsecure web pages can be grabbed out of the air.

What you also need to watch for is bogus WiFi networks that phish for your connection. One of the guys at VirusList.com recently blogged, while sitting at Schiphol Airport in Amsterdam, that his computer found suspicious networks with names like “Free Public WiFi” and “US Airways Free WiFi”.


Beware of free Wireless Networks

Just driving around my neighborhood I was able to find a number of wireless networks open to the public. At a hotel or airport you’ll see many others including some with the word “FREE” in their name. Beware!

According to VirusList.com

“It's easy to spot rogue WiFi links - you just need to look for the following signs:

- an enticing name like 'Free Wifi' or 'Free Internet'
- an AD-Hoc type connection, rather than an access point”

If it’s an AD-Hoc network you should see the words, “Computer-to-Computer” under the network name. The ones shown in my example are Access Point networks.

They also recommend the following…

“- use a VPN link over any public WiFi internet access link to dial back home and access the internet using a secure proxy over the VPN link
- use only encrypted IMAP e-mail connections to read mail, TLS or SSL
- beware of fake certificates
- use a firewall and IPS or a combined security solution such as KIS7”

Most of you don’t have or probably don’t know what a VPN is so I’ll offer you an alternative. I use a service from GoToMyPC.com.

Using GoToMyPC when I travel, I connect to my home/office PC. I open up my Outlook Email as if I was sitting in my chair at home. It also means I don’t have to sync up stuff I’m working on when I leave and return. I even sign on AOL from that computer via GoToMyPC. Essentially my laptop acts as a dump terminal and the entire session is done using 128–bit AES encryption. The service is $20 a month but you can click here for a free trial.

If you’re a regular reader you’ll remember I recently changed from Time Warner Road Runner to Verizon FIOS which provides much greater upload speed. Many broadband providers give you lots of download bandwidth but a small slice for upload. Having more bandwidth allocated to upload is especially helpful for using GoToMyPC.

Labels: , , ,

Share on Facebook