Phishing Has Gotten Very Good
schneier.com
schneier.com
The turn around time was crazy - on at least two occasions the workflow went:
recent victim gets first/early copy of policy paper written that day --> document is taken, translated to a different format and has 0 day inserted --> emails with exploit are sent to no more than 10-15 people the victim frequently discusses the topics covered in the paper with. --> Many include personalized notes that include observations the victim had sent to the author --> Time from initial email receipt to exploits all mailed: around 3 hours
Now that's how you get a 95% open rate.
related: http://contagiodump.blogspot.com/search/label/CVE-2011-0611
Anyone who could profit is our starting set. And the budget for the federal government funds massive amounts of private entities that have a vested interest in finding out ahead of time what their and their competitors funding will be.
Notably, hedging their bets on an exchange.
And, maybe obviously, some of these private entities are the very entities that are consulted for the federal government's email and computer security policy.
Schneier stated this explicitly: "Amateurs target systems, professionals target people." It doesn't matter if your money is behind a five-foot-thick reinforced-concrete safe if the banker can be convinced to open it for an attacker.
So we should use thinner walls or none at all?
Don't be obtuse.
We talk about the walls, because stronger walls reduce the chances of a break-in.
This is the textbook definition of a strawman.
What I am pointing out is that nobody is discussing how to train/educate humans to be more resistant to social engineering attacks. Instead there seems to be an echo chamber of "X system is so much secure than Y system!" which is really banal.
o Windows o Internet Explorer o Java o Flash o Office
People can whine all they want about Chromebooks not running non-cloud stuff, but IMHO, diplomats, executives, et al should be required to use locked down machines for communications, and training to educate people about opening email links should be widespread.
I get emails all the time from my bank and credit card companies, but even if I visually inspect the link targets, I don't trust them, I always type in the location myself if it is a site that I know I'm going to enter important credentials into.
Assuming the service is storing unsalted password hashes that can be cracked using a rainbow table, or (god forbid) plaintext passwords, right?
If one can add a <script> tag to arbitrary webpages via a malicious extension,XSS or whatever other method then that's probably as good as/better than root.
You are still not magically immune from buffer overflow, heap overflows or any of the other bread and butter stuff either.
Or "Check out my blog... (I specialise in Javascript so please turn NoScript off.)" The possibilities of social engineering are scary.
What's surprising is that I gave a talk twice for Schneier's company Counterpane on tour with him in Texas, to a small room of people, including Bruce, covering exactly this topic, around that time.
Disclaimer: I no longer work there but I created their anti-spam software.
When I click on a link, I want a remote text and image viewer. Sometimes I'll allow certain sites like youtube to run flash, even automatically. This computer is my tool, not someone else's, and in 2013 clicking on a link shouldn't be a wildly uncontrolled and dangerous experience.
I've been on the internet for a few years, as a kid, and never got into phishing trouble. Now, as an adult, I've seen phishing forgeries so incredibly detailed that I had to check a lot of factors to finally conclude that it's phishing. And I'm an adult computer scientist who programs web pages!
Just think about any other intelligent adult but without the technical knowledge to detect forgeries. It's turning to be really scary.
Maybe switch to gopher?
How about running the browser in a sandbox that resets all changes on exit? I've actually set up Firefox (hardened) + Sandboxie on Win7 but exactly how good is this setup?
a) disable flash
b) disable java
c) disable any plugins really.
d) use chrome (at least)
e) do not allow downloading of any file. Instead use chrome's plugin to open any word/etc files in google docs.
f) Use a chromebook. Chromebooks can't really execute programs like windows machines can, so it's fairly safe. And worst case is you expose a sandbox machine with no private data other than caches, that can be set to be cleared on sleep or whatever. Bonus security points:
- if a chromebook is hijacked, it will only be hijacked until a reboot during which time the chromebook does a sanity check ensuring the OS is exactly intact. If it is not it just reinstalls the OS from ROM. Basically no long-term compromised machines.
- The only time chrome's sandbox was ever completely bypassed allowing arbitrary code execution was using a combination of multiple chrome exploits (now closed) and a windows data execution prevention bug. That can't happen on linux (and the chrome team works to further solidify that sandbox). Pretty much almost impossible. And if it is quickly patched and vuala.
g) browse in private browsing mode only
h) When visiting links (like facebook) manually type in the url to ensure nothing is spoofed.
I think you will be fairly safe. However... I doubt most people will go that far.
So to avoid leaking any private data to third parties, I should send all my private data to a third party using a proprietary protocol?
Also, I 'd recommend using noscript, with no plugins. Don't bother opening word files, get them to send it to you in plain text. Or run around with usb drives (no one ever said it would be easy).
If an attacker can gain access to your network (splicing a network cable somewhere, long term hacks against wifi keys, etc) then they can run DNS or arp poisoning, and redirect all of your traffic through a transparent proxy that can strip off HTTPS and log all cookies and form submission.
Many people will then type in 'www.facebook.com' into the address bar, and will see facebook as normal (minus the padlock, which most people wouldn't notice is missing).
So: don't just type in 'www.facebook.com' ALWAYS type in 'https://www.facebook.com manually, or make a habbit of checking the padlock on every page view (perhaps there is a chrome addon for this?)
EDIT: and if you're being spoofed by a government or syndicate who has the ability to sign global certificates, then there is probably not much you can do.
embarrasing to admit, but I've always wanted to believe one could at least trust plugins like Adblock Plus or Ghostery to protect ones mind and privacy a little.. now, reading Hacker News almost every day, I'm getting paranoid. is it a vulnerability to even use them?
Let's say you trust Chrome, you can't trust AdBlock just because you trust Chrome. The install on the Chrome store could get compromised, somehow.
In this specific case though, you also have to weigh the risk of an attack being delivered from an ad. What's more likely? One of the thousands of ads you view a day launches an attack, or installing a Chrome extension does? Which would be more damaging?
Security is not an exact science. It's all about weighing options and making informed decisions.
Addons is more generic term, it includes extensions, plugins and themes.
I'm interested to know how google's cloud is going to implement my updated video card drivers.
Yeah. Technology to hack someone is getting better by the minute.
eg, here's the DoD global phone book (in case I want to email somebody). Server requires CAC token from the client, but the client's browser doesn't trust the server!
https://dod411.chamb.disa.mil/
I don't even know what to call this level of broken, Chomsky-esque?
I've used approximately zero DoD computers since 2005 that had the SSL CA chain misconfigured for use on DoD websites. It's really not that hard, even my Linux box here works fine.
In my humble experience, installing DoD roots is a journey: there are at least a few dozen and they are constantly being retired and superseded. Meanwhile, to get the DoD root certs, one has to trust A) DNS B) whomever is in charge of access control to the cert servers. Clearly, access control is a major problem for the DoD, that's the whole problem to begin with.
But like I said, it works on my home computer too. Google for DISA InstallRoot (or try going here and running through the steps http://iase.disa.mil/pki-pke/getting_started/index.html)
It is true that they go through the intermediate CAs fairly quickly, but the actual root is still at CA-2 from what I can tell.
DNS security is certainly a concern, but not the kind of concern that leads to SSL warning popups unless there's something else screwy going on. But then maybe Chrome is seeing screwy stuff that MSIE doesn't know to check for...
However this is a policy which is not computer-enforced, which means of course that it's fairly useless in practice.
See, for example, https://www.authentic8.com
Chrome OS is probably the only commercial platform that is designed with this era of threats in mind. It's at least a generation ahead of everybody else. They're actually building their own embedded controller (controls the fans, battery etc.) to go along with their open source firmware so they can worry less about bad guys in the supply chain.
The problem with this sort of approach is that it is slow on most office machines. A lot of companies are still running XP desktops with 1GB RAM.
Sandbox all the things.
What would make me even happier is a way for me to read the writings of my favorite authors without relying on many millions of lines of source code (i.e., a "modern" browser) and the inevitable security holes in those millions of lines.
Bruce's site is hacked.
Clever self-referential hackers. We're all done for.