7.6.18


VPNFilter update: More bad news for routers

New research into VPNFilter finds more devices hit by malware that’s nastier than first thought, making rebooting and remediating of routers more urgent.
At the bottom of this article is a revised list of routers believed to be at particular risk from the malicious code known as VPNFilter, according to ongoing research by Cisco’s Talos Intelligence Group. These latest findings underscore the importance of rebooting routers, as described at length in this WeLiveSecurity article.
With 56 additional models and five new vendors impacted, it is increasingly likely that even more will be identified. This reinforces previous advice: you should take action regardless of the make or model of router you are using (unless you have received solid assurances from your ISP or vendor that your specific router is not vulnerable).
What’s going on here?
Hundreds of thousands of routers in more than 50 countries have been compromised by malware dubbed VPNFilter. When placed on a router, this malicious code can spy on traffic passing through the router. The malware can also “brick” the device it runs on, rendering it inoperative.
Like a lot of malware, VPNFilter is modular and can communicate over the internet with a Command and Control (C2) system to download additional modules. Research into VPNFilter’s capabilities is ongoing.
Routers are specialized computing devices that direct traffic between networks, for example, between the network in your office and the global network known as the internet. Routers have three places to store code and information: regular memory, which is “volatile” and loses its contents when it loses power; non-volatile memory that retains its contents even when the power is turned off; and firmware, the contents of which are relatively difficult to change.
Much of VPNFilter’s code resides in volatile memory and is wiped out by a reboot or “cycling the power” (i.e. power it off – wait 30 seconds – then power it on again). That is why the security experts and the FBI recommend rebooting your router.
However, a reboot does not remove code that VPNFilter may have written to non-volatile memory. Clearing non-volatile memory requires a device reset, but you should NOT perform a reset unless you know what you are doing (see the instructions and advice in this related WeLiveSecurity article).
If your router is supplied by your ISP you should contact them for instructions if they have not already alerted you and advised you of the situation.
Other steps to consider are upgrading your router to the latest firmware, changing the default administration password, and disabling remote administration. Instructions to perform these functions can be found on the router maker’s website.
Yes, you probably do have a router
I am sure there will be more articles related to VPNFilter and router security on WeLiveSecurity in the coming days. We already get the sense, based on questions from readers so far, that knowledge of routers and how to secure them varies considerably within the population of router users.
One basic question – do I have a router? – is actually trickier to answer than you might think. Many homes and small offices have a variety of boxes that work together to deliver the internet to their computers, smartphones, tablets, smart TVs, clever thermostats, and so on.
Read the complete article on

30.5.18

UNICEF now using cryptocurrency mining for fundraising



So far in 2018, the NGO has launched two charity campaigns with the aim of raising funds through cryptocurrency mining.
Many cryptocurrencies have been associated with cybercrime, especially Monero, which has led to many people considering them unethical. And the fact that cryptocurrency miners are at the top of the worldwide ranking of threats only worsens their image.
A few months ago we tried to explain why mining scripts were being detected as “potentially unwanted applications”, since these scripts are not malicious by themselves, but when used without the required permission and in an unethical way they can be troublesome for users. No tool is good or bad —it all depends on who uses it and what they use it for.
And so this article explores a case in which cryptocurrency mining is being used for a noble act and a good cause. As is the case for UNICEF, which has discovered a pioneering new way of raising funds for its humanitarian causes. This year, the NGO launched two campaigns in which it does not ask for direct money donations, but rather computer resources and processing power for cryptocurrency mining.
The first campaign was launched in February, 2018 under the “Game Chaingers” program, and ran until March 31. It was an initiative of UNICEF France, and its aim was to raise funds for children in Syria who are severely affected by the humanitarian crisis and the war. This campaign ended on March 31.
The second campaign is currently active, and was launched by UNICEF Australia on April 29. A site called “TheHopePage” was created for this campaign, with the aim of raising funds for the approximately 340,000 Burmese children who are currently refugees in Bangladesh due to the violent crisis unleashed in their home country.
Each of these charity campaigns promoted by different UNICEF offices were explored in detail by the ESET Latin America Laboratory, with the aim of making users more aware of this matter by providing relevant information. Because behind the pioneering new concepts like these, malicious campaigns always crop up that take advantage of the novelty to deceive users.
Game Chaingers: UNICEF France Campaign to Mine Ethereum and Help Syrian Children
The name “Game Chaingers” was strategically chosen to include the word “chain”, which is a reference to the blockchain technology that supports cryptocurrencies like Ethereum (the one used in this program). This campaign can be viewed on the site chaingers.io, and is aimed at eSports players, gamers, designers, and other users who have powerful computers with high-performance graphics cards, since the Ethereum mining process requires a lot of processing power.
The process of mining Ethereum for the benefit of UNICEF is really simple, since the mining client (or miner) can be downloaded with UNICEF’s wallet data preconfigured and based on your graphics card model and operating system. Once the miner is downloaded, all you have to do is run it via a shortcut to start mining.

However, taking this past campaign as an example, there are some issues to be considered before you start donating your resources. The first is the electrical consumption that this generates. According to the UNICEF website, a computer with a standard graphics card mining Ethereum consumes around 0.16 kWh, which is similar to the consumption used when playing a high-quality video game. This consumption should not be a problem if you only plan to donate a couple of hours a day, but it is definitely something that must be calculated if you plan to leave the miner running 24 hours a day.
It is also a known fact that intensively using and overloading processors can eventually damage a computer or cause some of its circuits to burn out. For this reason, you should always consider the processing percentage and power that will be used for mining.
And while UNICEF has clarified that the amount of resources assigned can be configured to avoid overloads, the fact remains that, by default, the miner is configured to use 100% of the processing power.

Miner start-up script
This last image shows the values configured in the miner at 100%. The parameters GPU_MAX_ALLOC_PERCENT and GPU_SINGLE_ALLOC_PERCENT indicate the processing percentage of the graphics card to be used, while GPU_MAX_HEAP_SIZE indicates the amount of memory. And while these values can be edited within the script, changing them could be cumbersome for some users who want to just run the file without taking such precautions.
TheHopePage: UNICEF Australia’s Campaign to Mine Monero and Help Refugee Children in Bangladesh
This is the current campaign launched by UNICEF Australia, which aims to raise funds for Burmese children who are refugees in Bangladesh as a result of the crisis. This campaign is aimed at all users, since it uses Monero mining scripts through a browser.
To collaborate in this initiative, simply visit the site TheHopePage.org and click on the “Start Donating” button.
Read the complete article at:

26.5.18

Facebook refines 2FA setup, adds authenticator app support




Do try this at home! If you haven’t taken advantage of the extra protection that two-factor authentication offers, now is a great time to do so. And you don’t even need to hand over your phone number.
Facebook has eliminated the need for users to register a phone number in order to set up two-factor authentication (2FA) in a move intended to get more users to add in another layer of security, according to a press release by Facebook’s product manager Scott Dickens.
To authenticate logins, the social network now enables users to employ a third-party app such as Google Authenticator or Duo Security on both desktop and mobile. The company has also revamped its 2FA feature with a “streamlined setup flow that guides you through the process”.
“Two-factor authentication is an industry best practice for providing additional account security and we just made it easier to set up,” wrote Dickens.
Text messages are the most common second factor although, due to the vulnerability of text messages to a number of threats, security professionals have been advising against using SMS for verification for a long time. Facebook has been offering SMS-based 2FA for a while now and will continue to do so, but using other means such as a hardware device or an authenticator app is generally viewed as safer.
There is no word on how many Facebook users actually use 2FA. On Google accounts, for example, the data are rather grim, as fewer than one in ten Google account holders utilize 2FA.
What to do?
To enable two-factor authentication on your Facebook profile, navigate to “Settings”, then to “Security and Login”, and then to the “Use two-factor authentication” section, where you can choose and set up your 2FA method of choice. While you’re at it, you may also want to peruse your other privacy and security settings.
Many online services, including the biggest players, nowadays offer at least one of the 2FA methods. The availability of 2FA on various online services can be checked on this site.
While not a cure-all, the extra authentication factor offers a valuable additional layer of protection in exchange for very little effort. It is safe to say that 2FA would have prevented countless account break-ins over the years had the legitimate account holders turned it on.
That said, it should not detract from the importance of having a strong and unique password or, even better, passphrase.

25.5.18


Google déploie des domaines .app avec HTTPS intégré

Google a déployé .app, un nouveau domaine de premier niveau (ou TLD, pour top-level domain) qui est le premier à exiger des connexions HTTPS cryptées pour tous les sites Web.app, selon une annonce faite par Ben Fried, directeur des systèmes d’information (DSI) de l’entreprise. Le 1er mai dernier, la société a ouvert des domaines .app
Google a déployé .app, un nouveau domaine de premier niveau (ou TLD, pour top-level domain) qui est le premier à exiger des connexions HTTPS cryptées pour tous les sites Web.app, selon une annonce faite par Ben Fried, directeur des systèmes d’information (DSI) de l’entreprise.
Le 1er mai dernier, la société a ouvert des domaines .app pour l’enregistrement dans le cadre du Programme d’accès hâtif (Early Access Program) sur Google Registry. Les domaines seront accessibles au grand public par l’intermédiaire d’autres bureaux d’enregistrement à partir du 8 mai.
« L’un des principaux avantages du domaine .app est que la sécurité est intégrée pour vous et vos utilisateurs. La grande différence est que HTTPS est nécessaire pour se connecter à tous les sites Web .app, ce qui contribue à la protection contre les logiciels malveillants et l’injection de suivi par les FAI, en plus de la protection contre l’espionnage sur les réseaux WiFi ouverts », peut-on lire dans le communiqué de presse.
Le domaine s’adresse en particulier aux développeurs d’applications. Néanmoins, Domain Name Wire cite un représentant de Google, qui déclarait en mars que ce domaine ne leur était pas réservé exclusivement. Certains des premiers adoptants des domaines .app sont présentés sur get.app.
 « Même si vous passez vos journées de travail dans le monde des applications mobiles, vous pouvez toujours bénéficier d’un repère sur le Web. Avec un nom de domaine .app mémorable, il est facile pour les gens de trouver et d’en savoir plus sur votre application. Vous pouvez utiliser votre nouveau domaine comme page d’atterrissage pour partager des liens de téléchargement fiables, tenir les utilisateurs à jour et des liens profonds vers le contenu de l’application », selon l’annonce.
Google, qui a déboursé 25 millions de dollars pour .app en 2015, contrôle un total de 45 TLD, y compris .comment, .papa, .eat, .soya ou .google. Selon l’autorité mondiale en matière de noms de domaine ICANN, l’Internet comptait 1543 TLD au 4 mai.
Le changement participe à la vision HTTPS de Google : partout dans le monde pour l’Internet. En février, par exemple, la société a annoncé que Chrome 68, prévu pour juillet de cette année, marquera tous les sites Web HTTP comme étant « non sécurisés ».
Petite note en terminant : le HTTPS (ou Hypertext Transfer Protocol Secure) chiffre le trafic Web, en s’assurant que les données soumises sont à l’abri des regards indiscrets pendant la transmission. Il est donc important, lorsque nous soumettons des données sensibles sur un site Web, de vérifier la présence de HTTPS dans la barre d’adresse du navigateur. Cependant, la présence du protocole à elle seule ne garantit pas automatiquement la sécurité contre un certain nombre d’autres menaces. Même un site qui affiche le HTTPS peut être malveillant : les sites d’hameçonnage, par exemple, ont de plus en plus adopté HTTPS.

GDPR: One rule to rule them all – legally


It’s here but what are the legal ramifications of the new legislation for businesses
There is a certain similarity between J. R. R. Tolkien’s The Lord of the Rings trilogy and General Data Protection Regulation (GDPR) coming to force tomorrow, May 25 2018. As weird as it may sound, the regulation puts in place standards identical to those of the One Ring – GDPR is here to rule the world of data protection the same way the One Ring ruled the others.
In real life, this could be directly linked to unifying the different levels of the data protection legislation in each of the European Union (EU) countries. Except in this case, the One Ring is replaced by the single set of data protection rules across the EU. Thus, the regulation aims to protect any information that relates to “an identified or identifiable person” – addressing the export of personal data outside of Europe as well.
WeLiveSecurity spoke with Tomáš Mičo, ESET Data Protection Officer, to clarify the essentials the regulation brings to businesses. “In Slovakia, where the cybersecurity firm ESET is based, we’ve already had, by law the possibility to appoint a Data Protection Officer, so applying GDPR for businesses inside countries with similar requirements of legislation shouldn’t have any significant impediments,” he says.
According to Mičo, businesses have already invested significant time and energy into mapping all the processes and reviewing all the agreements as recommended by data protection professionals. “Moreover, as GDPR has so-called ‘downstream’ effect, businesses need to apply the same principles to all their arrangements including those with third-party processors and sub-contractors,” explains Mičo.
The main purpose of the new regulation is to minimize the unnecessary collection of personal data, including steps that prevent storing data that does not need to be stored, and securing the entire journey of the personal data in the company. However, the biggest challenges for businesses lie with the requirements for Privacy by Design, Privacy by Default, Right to Erasure, Right to be Forgotten and Breach Notification.
The computer security companies around the globe are rightfully using this opportunity, offering solutions to mitigate the main risks connected to the regulation – selling encryption, two-factor authentication and other solutions to close any possible path for cybercriminals to get to the personal data that must be protected under GDPR.
That’s not all. Although businesses are successfully deploying cybersecurity solutions to make sure personal data are properly processed and protected inside your company, there are other legal responsibilities that must be completed. One of them is to offer an easy-to-understand explanation of data processing, so customers are transparently informed about their rights resulting from this new regulation.
“Businesses have to make sure they have consent, contract or other legal basis for processing all of the personal data protected by the regulation, for all their end users. For a middle size business, it can as well mean spending countless hours retroactively contacting all of them if their legal basis is not GDPR valid – including end users that businesses gained through third parties or sub-contractors,” adds Mičo.
In addition, individuals have as well the right to request a detailed listing of all their personal data that is being processed, and request it from any vendor that works with the personal data of EU located customers, even if the company is not physically located in the EU. This is especially hard for all the e-commerce businesses and businesses that work with cloud services. And that is the reason why the majority of newsletters in last couple of weeks start with We have updated our privacy policy.
Moreover, businesses must have the information about the individual available at any time and keep it protected – encrypted – to be GDPR compliant. “This way the personal data, even when the company suffers a breach or is hacked, stay protected,” says Mičo. Perharps the greatest onus in the Breach Notification requirement, which forces businesses to have processes in place that will ensure the information about the data breach will make it to the appropriate data protection authority within 72 hour after it was discovered.
If nothing else, penalties for non-compliance are quite a bite to swallow – looking at 2% to 4% of the company’s global annual turnover, which is an expense no company can afford to take lightly. A recent survey by IDC, however, reveals that for noncompliance, “regulators are more likely to focus on progress toward the goal than penalizing those not quite finished with GDPR conformity”.
In time, we’ll see if the famous one rule to rule them all will find them all and and bind them as the legislators have predicted, or if everyone will meet in an unfulfilled GDPR Land of Mordor.
For more information on GDPR, ESET has a dedicated page to help ensure that you have all the information needed to cope with GDPR. To read more articles like this one, please follow WeLiveSecurity.

23.5.18

Amazon Rekognition a possible threat to the civil rights of citizens




Use of software by law enforcement as a surveillance tool is a real concern for groups
Amazon has come under fire from civil rights groups in the US that say their online service that identifies faces in images could be abused by law enforcement.
The American Civil Liberties Union (ACLU) released a statement on Tuesday asking the tech giant to refrain from selling Amazon Rekognition to law enforcement agencies as they fear it will be used to unfairly target protesters along with individuals that the police view as suspicious.
The ACLU is leading a group of more than two dozen other civil rights organizations that are worried that the product will be used by law enforcement as a surveillance tool.
This claim was reinforced on Tuesday when the ACLU released a collection of public records that detailed how Amazon has been selling the software to those law enforcement agencies.
The statement released on the ACLU website stressed how the software threatens the freedom of citizens to go about their daily lives, “People should be free to walk down the street without being watched by the government”.
“By automating mass surveillance, facial recognition systems like Rekognition threaten this freedom, posing a particular threat to communities already unjustly targeted in the current political climate. Once powerful surveillance systems like these are built and deployed, the harm will be extremely difficult to undo”.

In a letter addressed to Jeff Bezos, Amazon’s chief executive, the group outlined its fears about the misuse of the software and also their concern that “Amazon Rekognition is primed for abuse in the hands of governments”.
They also implored the company to move fast, stating, “Amazon must act swiftly to stand up for civil rights and civil liberties, including those of its own”.
Police in Orlando, Florida and in Oregon’s Washington County are currently using Rekognition.
A report by the The Washington Post has stated that the Washington County Sheriff department pays something in the range of $6 and $12 a month for the service.
Amazon spokeswoman Nina Lindsey did not directly address the concerns outlined by the civil rights groups stating that Amazon would require all customers to “comply with the law and be responsible when they use AWS services.”
She also said that the software could be used for many positive purposes, including finding abducted people and could also help locate children that become separated from their parents in crowded areas.
The product was introduced by Amazon as part of Amazon Web Services in late 2016 and claimed it “can process millions of photos per day”.
This concern by citizens over the use of Artificial Intelligence (AI) as a surveillance tool by government agencies was also highlighted recently when it was reported that thousands of Google employees signed an internal petition requesting that the company end its controversial contract with the Pentagon. A partnership with the US Department of Defense, named Project Maven, that promised to speed up the analysis of drone footage by assessing images for photos or objects.
Google were quick to downplay any fears of misuse, “the technology flags images for human review, and is for non-offensive uses only,” a Google spokeswoman said. “Military use of machine learning naturally raises valid concerns. We’re actively discussing this important topic internally and with others as we continue to develop policies and safeguards around the development and use of our machine learning technologies.”
https://www.welivesecurity.com/2018/05/23/amazon-rekognition-threat-civil-rights/?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+eset%2Fblog+%28ESET+Blog%3A+We+Live+Security%29


16.5.18

Researchers reveal flaws that may expose encrypted emails to prying eyes



A team of academics says that, if exploited, the vulnerabilities can reveal the plain text of encrypted emails, including those sent years ago
The widely-used OpenPGP and S/MIME email encryption protocols suffer from weaknesses that may ultimately expose the plain text of encrypted messages to attackers, according to a team of eight academics from German and Belgian universities, who have nicknamed the flaws “EFAIL”.
“In a nutshell, EFAIL abuses active content of HTML emails, for example externally loaded images or styles, to exfiltrate plain text through requested URLs,” the researchers wrote on efail.de, a newly-launched website dedicated to their findings. The vulnerabilities come in two flavors and are described in great detail in a technical paper entitled “Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels”.
In order to exploit the weaknesses, miscreants first need to access the end-to-end encrypted email message. This means intercepting it in transit or stealing it, for instance, from a compromised email account, client computer or backup system. Then, the attackers need to alter the email by adding custom HTML code to it, and send the manipulated email to the victim. The victim’s email client decrypts the email and, given its HTML-rendering capability, it is tricked by the malicious code into sending the full plain text of the emails to the attackers. Even messages sent years ago are vulnerable.
The team also said that their proof-of-concept exploit has been shown to be successful against 25 out of 35 tested S/MIME email clients and 10 out of 28 OpenPGP clients. The flaws affect email applications such as Apple Mail with the GPGTools encryption plug-in, Mozilla Thunderbird with the Enigmail plug-in, and Outlook with the Gpg4win encryption package. The academics said that, in keeping with the principles of responsible disclosure, they have reported their findings to email providers concerned.
They also averred that there are no reliable fixes for the vulnerability and recommended several short-, medium-, and long-term mitigation strategies. The short-term actions involve decrypting emails in a separate application rather than in the email client, together with disabling the rendering of remote content, such as HTML images or styles. As for medium- and long-term fixes, respectively, the academics said that software holes need to be patched and the standards need to be updated.
The Electronic Frontier Foundation (EFF), a US-based digital rights group, had reviewed the researchers’ findings before they were published. On Sunday, it released a series of tutorials in which it largely echoed the researchers’ advice – users should disable or uninstall PGP plugins in their email handlers until the vulnerabilities are patched. Since the same flaws affect S/MIME, which is common in enterprise email networks, EFF recommended that, “during this period of uncertainty”, users should switch to alternative methods of secure communication.
Broken encryption, broken embargo
The research attracted a great deal of publicity even before its results was published. This was after the researchers initially released a “teaser” to the effect that the flaws would be described in detail in a paper on Tuesday. However, the embargo was broken on Monday, prompting the researchers to go public with their findings ahead of schedule.
Meanwhile, the findings have stirred some controversy, in particular over how realistic the threat truly is. For example, Robert J. Hansen of Enigmail dismissed the alarm bells as “a tempest in a teapot”.
In a similar vein, Werner Koch, the man behind GNU Privacy Guard (GnuPG/GPG), which is an implementation of OpenPGP, called the warnings “overblown”.
In fact, according to GnuPG, the problem lies elsewhere. “They figured out mail clients which don’t properly check for decryption errors and also follow links in HTML mails. So the vulnerability is in the mail clients and not in the protocols. In fact OpenPGP is immune if used correctly while S/MIME has no deployed mitigation,” GnuPG tweeted.
ProtonMail said in a statement that its encrypted email service is not affected by the flaws and that, beyond “one minor exception”, the vulnerabilities are not, in fact, present in PGP itself. “What the authors of Efail did was catalogue a list of PGP clients that have errors in their PGP implementation,” reads the statement. With that in mind, the company recommended the use of secure PGP implementations.
Cryptographer and professor at Johns Hopkins University Matthew Green said of the exploit that “[i]t’s an extremely cool attack and kind of a masterpiece in exploiting bad crypto, combined with a whole lot of sloppiness on the part of mail client developers.”
Cryptography expert Bruce Schneier weighed in by saying that “[t]he vulnerability isn’t with PGP or S/MIME itself, but in the way they interact with modern e-mail programs.”