900 social insurance numbers stolen from Revenue Canada via Heartbleed
cbc.ca
cbc.ca
Even at a previous job back in the late 90's we were doing full pcap of our gov't department's T1 to the internet.
Products from companies like Netscout and VSS make this pretty straightforward.
I imagine a government agency, particularly dealing with revenue, might be a primary user of such a tool, though.
Worst case scenario they are looking into streams of suspicious behavior, like Russian IPs attempting to validate the SINs somewhere else, like at a bank.
"It is irrelevant whether your system can even support some of the cipher suites in the list, because the Heartbeat request that triggers the vulnerability is sent before any encryption takes place."
http://www.hut3.net/blog/cns---networks-security/2014/04/14/...
I was specifically wondering if a) the heartbeat messages which leak data (keys or whatever) are encrypted or not, and b) if they are, and PFS was used, is it even possible for someone to audit a full packet capture for heartbeat attacks.
So I called them up, waited on hold for 5 minutes. I spoke with a CRA rep who said "Yup, we screwed up. Fixed". And it was fixed. Total time to fix an $11K screw up? 15 minutes. Try that with any other organization.
Every single interaction with them and every single person I know that has to deal with them has been nothing but mindblowingly professional. Even on the phone, they are exceptionally good at getting to the point IMMEDIATELY but without the normal "this isn't the right department" BS that every other Canadian government agency has.
It's hard to even think of a number two. The Supreme Court maybe? Elections Canada? Ellis Don?
Anyway, I call, and it was the closest thing to magic I've ever seen. I give reception my SIN, and ask for the woman that signed the letter I received. I'm on hold for only 10 or 20 seconds, the woman answers, and greets me with my name. I didn't say more than a couple of sentences explaining the issue, and she says she'll check her computer, taps a button and poof she knows everything. Literally a few more seconds, and everything is sorted, and a cheque is being mailed.
I was almost speechless, I was expecting a 30 minute call between departments, explaining numbers, CRA scratching their heads since this was taking place across multiple provinces, and then me having to physically mail in a variety of personal information. Instead, it was a 1 or 2 minute call with an incredibly friendly woman, and she was so organized, it's like she spent the day preparing for me to call in advance. And, to reiterate, this was the woman that signed the original letter I received, not someone from support or customer service.
Now, the CRA website is a nightmare, but talking to them on the phone was the most impressive service I've ever encountered.
For instance, one guy looked up the information attached to his SIN. Something like an hour later RCMP showed up, and escorted the fellow out of the building.
And you don't really expect them to blindly patch things right away do you?
Maybe the Canadian government should walk down to the CSEC offices and ask them hey can you guys stop conspiring with the rest of the 5 Eyes Alliance to sabotage IETF standards
Vulnerability was disclosed on Monday, April 7th. CRA website was shutdown on Wednesday, April 9th. Didn't take long for the baddies to take PoCs and point them at vulnerable sites.
Any other high-value sites that took more than a day to patch should take this as a warning.
On the other side of it, I think it's really great that they've been able to determine exactly what was stolen from this so that they can attempt to repair any damages.
If so, is it safe to say that this crisis was dealt with rather well? Or is it just too early to know how many sites were actually attacked?
Here's a number: 147334572. Have I stolen it?
This is yet another alarming signal that the whole idea that your SSN/SIN or credit card number is somehow secret and can be used for authentication is flawed. We need to work on fixing this. At the very least, we should stop talking about "stolen numbers". And even if the breach in question resulted in attackers gaining access to names + numbers (unclear from the article), it should not cause any serious consequences.
The same way someone might "steal" your password. All data can be encoded as a number.
> the whole idea that your SSN/SIN or credit card number is somehow secret and can be used for authentication is flawed.
I don't disagree, but "how can you steal a number?" isn't a valid argument for your assertion.
Secret information is required for practical authentication. Some examples:
Private keys (ssh, gpg, SSL/TLS certs, bitcoin wallets)
passwords
session ids
api secrets
auth tokens
As a comparison, your SSN is used all over the place, you will need to disclose it regularly (rent an apartment and your landlord is likely to request a credit check, you'll give him your SSN). A number of people and institutions will have access to it. It is not a secret. It should not be used for authentication and no one should assume it somehow secret, because it is not.
However, even if we all had a unique 4096 bit private key with which we identified ourselves, it would still essentially be a number and it would certainly be able to be stolen. Stealing a number is more or less the same as stealing a private key or stealing a classified electronic document - it's the unauthorised access and copying of information. Society has broadly come to accept that this is considered stealing.
People use all sorts of zany things to try to prove identity. I think public education is the first line of defence against the misuse of things like SSN/SIN.
For most other things though you can refuse to disclose it (i.e. telecom providers, debt-only financial institutions like credit card providers)
Here's a name: jwr. Have I stolen it?
This is yet another alarming signal that the whole idea that your colloquial identifying information (name, phone, SSN/SIN, credit card number) is somehow a natural resource that anyone can use as they like. We need to work on fixing this. At the very least, we should stop pretending that identifiers are just tags that anyone can use without consequence. And even if the breach in question resulted in no harm done (those associated with the identifiers suffer no direct liabilities), it should not be treated lightly.
Possession of particular identifiers cannot be brushed off as "it's just a number" et al. You picked 14334572 precisely because it is not meaningful to anyone; short of such particular & peculiar use, we don't pick and retain numbers (or other identifiers) for no good reason. Out of a given range, the odds of picking 14334572 is very very small...if it happens to have a particular social meaning, and you possess it along with other information which likewise has an odd lack of meaninglessness, then you have malicious intent constituting "stolen numbers".
Don't pretend information is meaningless. We're not dealing with the Library Of Babel here.
You having a 'jwr' string does not enable you to do much — you can't use it to gain access to anything, no one will ask you for this string to authenticate you, you can't use it to pay for services. So if you "stole" it (or produced it out of thin air), it would not be a problem.
Now, I picked 14334572 specifically because it looks like a social security number (and might, for all I know, actually correspond to one). The point here was that you can't 'possess' a number, and you can't 'steal' one. You can steal complete personal information (that includes the number), but that is not what the original article was about.
My main point was that the real problem is with the whole idea of social security numbers (and credit card numbers) being both public identifiers (which is fine) and authentication tokens (which is not). If they were just public identifiers, then "stealing" a list of such numbers would not be a problem for anyone. It is the embedded trust we place in those numbers that causes us problems. SSNs are not secret key material, and treating them as such causes all kinds of issues.
As a side note: looking at the downvotes, I am increasingly worried about knee-jerk reactions here. I am finding that unless I craft my comment carefully and surround it with disclaimers, it will get misread. This is worrying, because it leads to watered-down and needlessly verbose discourse, words playing the role of guards against all the detail-pickers out there.
I might not be able to do much with "jwr", but I could build an entire profitable identity around your SSN.
Your real concern is that identifiers and authentication must be separate and treated as such, while in practice one number/string is used for both purposes - hence the concern of "stealing numbers", as having the identifier means having the authentication. Insofar as there may be a separate authenticating token, all too often it is so weak that the identifier is used as part of the authentication; having the identifier may be enough for access, or enough that deducing the remaining authentication token may be fairly trivial (say, a 4-digit PIN); this being tax day in the USA, we're quite aware that many tax returns will be fraudulent, requesting large refunds based on mere possession of a SSN identifier and a smattering of other public data. We should be using real cryptographic private keys of substantial length for authentication, leaving the public identifier public so that having one (or a slew) gets one nowhere without the hard-to-obtain authentication tokens.
As for the downvotes and the need to craft comments carefully: yes, the need for careful wording is the norm. We're trying to cram a lot of information and opinion into a very small space, which will be read very quickly by a great many people of wildly varying perspectives interpreting the post, making it very easy to misinterpret intent (doesn't help that there are a lot of dumb & ill-advised posts, setting expectations quite low). The greatest problem is refining short easily-read posts to withstand accusations which demand encyclopedic thoroughness. One of my motivations for prolific posting around the 'net is precisely to exercise & refine my ability to post views in a concise & persuasive manner (and if that gets bizarrely construed as "he must have multiple accounts, know a lot of people, and persuades others to downvote opposing views" then I must be getting somewhere with that ability).
Hilariously enough, if you call them, you can change the address on file if you have SIN + DOB, making the "PIN" pointless (and irritating, since you have to wait several weeks)
Still a pain to get it setup, but once you are setup it is much better now.
That said, the SIN in Canada is actually meant to be kept secret between you, your employer(s), the CRA, and a few other situations[1]. You should never give it to anyone else, write it down anywhere, etc. I memorized mine long ago and keep the actual card locked in a box somewhere, and I never give it out except to the government or new employers.
[1] http://www.servicecanada.gc.ca/eng/sin/protect/provide.shtml