2.6.17

OneLogin data breach may have compromised encrypted information




OneLogin  has admitted that it cannot guarantee the security of encrypted data compromised by a cybercriminal on Wednesday (May 31st).
The firm has confirmed that a review is currently underway to investigate the data breach, which affected its “US data region”.
Unauthorized access has since been blocked and the incident has been reported to the authorities, with independent security firms also on board to help identify the extent of the incident.
OneLogin found that the cybercriminal had obtained access to a set of AWS keys, and had used them to access the AWS API from an intermediate host with another, smaller service provider in the US.
Affected customers have already been informed, with the company claiming that the attacker was able to access database tables containing various pieces of sensitive information about users, apps and various types of keys.
While insisting that much of its most sensitive data was encrypted, the company admitted that it cnn not guarantee that the cybercriminal has not managed to find a way to decrypt that data.
As a result, it has asked customers to remain vigilant, making several recommendations for action.
According to Bill Buchanan of Edinburgh Napier University, the incident has highlighted the risk of depending on cloud-based systems.
He told the BBC: “Increasingly they [companies] need to encrypt sensitive information before they put it within cloud systems, and watch that their encryption keys are not distributed to malicious agents.
“It is almost impossible to decrypt data that uses strong encryption, unless the encryption key has been generated from a simple password.”
The case once again highlights the importance of properly implementing an encryption solution, particularly for UK companies, which are still likely to remember the £150,000 fine dished out to insurance company Alliance and Leicester at the beginning of the year.
Whether OneLogin could have done more to protect their encrypted data is likely to become clearer in the next few weeks.

26.5.17

ICO urges businesses to focus on becoming GDPR compliant

The UK’s information commissioner Elizabeth Denham has urged businesses to be incentivized by the benefits of GDPR data security compliance, rather than the possible consequences.
In a video addressing boardrooms across the country, Denham stated that businesses should not waste any time in preparing for “the biggest change to data protection law for a generation”.
As a result, she urged companies to act swiftly in ensuring they are compliant with the upcoming GDPR regulations, which are due to come into force on May 25th, 2018.
But she insists that businesses should not be motivated by fears surrounding the consequences of non-compliance.
Instead they should look at the advantages of having a strong data protection system.
“If your organization can’t demonstrate that good data protection is a cornerstone of your business policy and practices, you’re leaving your organisation open to enforcement action that can damage both public reputation and bank balance,” Denham added.
“But there’s a carrot here as well as a stick: get data protection right, and you can see a real business benefit.”
Her comments may well fall on a few surprised ears over the coming weeks, with research from IDC earlier this month indicating that just one-quarter of companies claim to be aware of GDPR.
This comes despite new rules regarding consent, as well as broadened European privacy rights, fines for non-compliance that could go into millions of euros, as well as tightened procedures and public disclosure in cases of a data breach.
Additionally, 52% of companies said they were unsure of how GDPR would impact their organization.
The ICO is subsequently doing its best to raise awareness for UK companies, with an updated data protection toolkit for SMEs set to go live on its website, as well as an Information Rights Strategic Plan, which aims to increase public trust.
There will also be a relaunch of the ICO’s 12 steps to take to prepare for GDPR.

24.5.17

Is the world ready for GDPR? Privacy and cybersecurity impacts are far-reaching


On May 25th, in the year 2018, something called the General Data Protection Regulation (GDPR) will go into effect. That means your company, and every other company in the world, should already have a good answer to this question: “How will GDPR affect us?” In fact, I would argue that you are currently courting danger if your answer is either “I don’t know” or “it doesn’t affect us because we’re not a European company” or “GDPR is irrelevant to us because we are located in America/Australia/India/etc.”
The main danger that you are courting is a big fat fine for non-compliance with GDPR, a set of rules governing the privacy and security of personal data that is being implemented by the European Commission, but which DOES APPLY to some companies located outside the European Union (EU).
In this article I have outlined why GDPR could have serious implications for your organization, starting with a few words about the wide net that this law casts, far beyond the borders of the EU. I will end with links to resources that can help you prepare for GDPR.
Another fine mess EU’ve landed US in?
I know that I am badly misquoting Laurel and Hardy there, but hopefully you are now paying attention because this is very serious. GDPR applies to your organization, regardless of the country in which you are based or from which you operate, unless you do not collect or process personal data drawn from the European market.
“If in doubt about GDPR compliance, ask corporate counsel. If corporate counsel responds by saying “GDP what now?” consider retaining new counsel.”
In other words, you are only off the hook if you do not offer goods or services to, nor track or create profiles of, European citizens.
If you do engage in any of those activities then you most likely will have to comply with GDPR. If in doubt ask corporate counsel. If corporate counsel responds by saying “GDP what now?” consider retaining new counsel.
For the sake of clarity and emphasis, let me summarize. Your firm probably needs to comply with GDPR if:
·         You monitor the behavior of data subjects who are located within the EU, or
·         You’re based outside the EU but provide services or goods to the EU (including free services), or
·         You have an “establishment” in the EU, regardless of where you process personal data (e.g. cloud-based processing performed outside of the EU for an EU-based company is subject to the GDPR).
Clearly, this is a considerable expansion of the scope of data protections provided by previous European laws. And it encompasses all people living in the EU, not just EU citizens. In addition, GDPR expands liability beyond the current directive to include data processors as well as data controllers.
(Need a quick refresher on the language of European data protection? There are three key terms: data subjects, data controllers, and data processors. For example, a company is a data controller with respect to the customers or employees about whom it has personal information. The customers and employees are the data subjects in this context: natural persons whose personal data is being processed by the data controller. An example of a data processor would be a company to whom payroll operations are outsourced by the employer in its capacity as a data controller.)
11 key things that GDPR does
1.     Increases the individual’s expectation of data privacy and the organization’s obligation to follow established cybersecurity practices.
2.     Establishes hefty fines for non-compliance. An egregious violation of GDPR, such as poor data security leading to public exposure of sensitive personal information, could result in a fine in the millions or even billions of dollars (there are two tiers of violations and the higher tier is subject to fines of over 20 million euros or 4% of the company’s net income).
3.     Imposes detailed and demanding breach notification requirements. Both the authorities and affected customers need to be notified “without undue delay and, where feasible, not later than 72 hours after having become aware of [the breach]”. Affected companies in America that are accustomed to US state data breach reporting may need to adjust their breach notification policies and procedures to avoid violating GDPR.
4.     Requires many organizations to appoint a data protection officer (DPO). You will need to designate a DPO if your core activities, as either a data controller or data processor, involve “regular and systematic monitoring of data subjects on a large scale.” For firms who already have a chief privacy officer, making that person DPO would make sense, but if there is no CPO or similar position in the organization, then a DPO role will need to be created.
5.     Tightens the definition of consent. Data subjects must confirm their consent to your use of their personal data through a freely given, specific, informed, and unambiguous statement or a clear affirmative action. In other words: silence, pre-ticked boxes, or inactivity no longer constitute consent.
6.     Takes a broad view of what constitutes personal data, potentially encompassing cookies, IP addresses, and other tracking data.
7.     Codifies a right to be forgotten so individuals can ask your organization to delete their personal data. Organizations that do not yet have a process for accommodating such requests will need to work on that.
8.     Gives data subjects the right to receive data in a common format and to ask that their data be transferred to another controller. Organizations that do not yet have a process for accommodating such requests will need to work on that.
9.     Makes it clear that data controllers are liable for the actions of the data processors they choose. (The controller-processor relationship should be governed by a contract that details the type of data involved, its purpose, use, retention, disposal, and protective security measures. For US companies, think Covered Entities and Business Associates under HIPAA.)
10.   Increases parental consent requirements for children under 16.
11.   Enshrines “privacy-by-design” as a required standard practice for all activities involving protected personal data. For example, in the area of app development, GDPR implies that “security and privacy experts should sit with the marketing team to build the business requirements and development plan for any new app to make sure it complies with the new regulation”.
GDPR cost and timing
As you might expect, when it comes to getting ready for GDPR, some organizations are further along than others. In January of this year PwC surveyed 200 US companies with more than 500 employees and found that 92% considered compliance with GDPR a top priority on their data-privacy and security agenda in 2017. More than half said it was the top priority and 38% said it was among their top priorities. Of course, compliance will not come cheap and 77% of folks in the PwC study said their organization was planning to spend $1 million or more on GDPR.
“When it comes to getting ready for GDPR, some organizations are further along than others.”
While you might expect European companies to be on top of GDPR preparation, a recent IDC Research study conducted on behalf of ESET found that a quarter (25%) of the 700 European companies surveyed admitted they were not aware of GDPR. In addition, more than half (52%) of them were unsure what GDPR’s impact on their organizations would be (see this article on WeLiveSecurity).
Security and notification under GDPR
To drill a little further into GDPR’s implications for the security of personal data that your organization handles, I think it is worth citing the appropriate sections at length. In effect, these establish a baseline that companies which handle data about EU persons will need to meet in order to defend against claims that they are “processing in infringement of this Regulation” and thus potentially subject to fines.
In section 83 we read that “… the controller or processor should evaluate the risks inherent in the processing and implement measures to mitigate those risks, such as encryption. Those measures should ensure an appropriate level of security, including confidentiality, taking into account the state of the art and the costs of implementation in relation to the risks and the nature of the personal data to be protected.”
In other words, there are very few specifics about how you should approach securing data, aside from the encryption reference; but there’s a clear assertion that you must perform a risk assessment. (I would hope that by now every organization has done a cybersecurity risk assessment and is keeping it current, yet we still see HIPAA fines in the US due to failure to do so.)
Section 83 elaborates on the risks that need to be considered: “In assessing data security risk, consideration should be given to the risks that are presented by personal data processing, such as accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed which may in particular lead to physical, material or non-material damage.”
Section 84 goes on to discuss the security of “high risk” data, a distinction I will address in a separate article (there is an ongoing discussion about how that distinction will be made).
“Nothing sheds light on organizational cybersecurity posture like security breaches.”
Nothing sheds light on organizational cybersecurity posture like security breaches, and these are addressed in Section 85. This states that when the data controller “becomes aware that a personal data breach has occurred, the controller should notify the personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it.”
Interestingly, GDPR allows the data controller to avoid notifying authorities of a breach if it is “able to demonstrate, in accordance with the accountability principle that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons”.
GDPR specifies the terms of data breach notification in Section 86 which states that data controllers must “communicate to the data subject a personal data breach, without undue delay, where that personal data breach is likely to result in a high risk to the rights and freedoms of the natural person in order to allow him or her to take the necessary precautions.”Some of the specifics of the notification are spelled out, such as “describe the nature of the personal data breach as well as recommendations for the natural person concerned to mitigate potential adverse effects.” For a look at some of the implications of these notification rules, including a possible surge in notifications, read this
Some of the specifics of the notification are spelled out, such as “describe the nature of the personal data breach as well as recommendations for the natural person concerned to mitigate potential adverse effects.” For a look at some of the implications of these notification rules, including a possible surge in notifications, read this article on the IAPP blog.
More GDPR resources
Clearly, there is a lot to get ready for, especially if the idea of having to deal with European data protection law is new to you. Here are some additional resources:
·         ESET has several GDPR guides available for download from this page.
·         There is a growing collection of articles about different aspects of GDPR on WeLiveSecurity.
·         For privacy and security purists who want to read the GDPR for themselves (like I did) here is a link to the final version as a PDF, all 150 pages of it.
Finally, it should noted that I am not a lawyer and you should not rely on this or any other internet article for legal advice. You should consult suitably qualified legal counsel on matters relating to GDPR interpretation and compliance. However, I do have one pro legal tip: if you bring up  GDPR with your company’s counsel and they respond with something like “G-D-P-what?” then they are probably not yet suitably qualified (so tell them you know a good article they can check out to learn more).

23.5.17

Zomato working with ‘ethical hacker’ to improve security


Restaurant and food delivery app Zomato has confirmed that it has been communicating with the hacker responsible for stealing the data of around 17 million of its customers.
The company, which claims to boast over 120 million users, confirmed that information including email address and hashed passwords had been compromised, but insists data relating to payment information had been stored separately in a secured PCI Data Security Standard compliant vault and that no credit card data had been stolen.
Zomato’s reaction was to make a pledge at plugging potential gaps in its security of user information, while also adding a layer of authorization for internal teams to avoid the possibility of a human breach.
Hours after confirming the attack, Zomato released an update stating that it had opened “a line of communication with the hacker who had put the user data up for sale”.
It continued by stating that the hacker had been “very cooperative” and claimed he wanted the company to acknowledge security vulnerabilities in its system.
On request of the hacker, Zomato is set to run a bug bounty program on Hackerone, in a deal that will see all copies of stolen data destroyed and taken off the dark web marketplace.
It added: “This incident has made our team’s commitment to addressing all our security issues in a responsible and timely manner even stronger. We look forward to working more closely with the ethical hacker community, to make Zomato a safer place for our users.”
The emergence of an “ethical hacker” in the Zomato data breach is in stark contrast to that of other recent attacks across the world over recent weeks, although it does nevertheless further emphasise the importance of ensuring that software is kept up to date.
The failure to keep software updated has been cited as a root cause of several high-profile hacks, with some experts even labelling it as one of five “basic security mistakes”.


19.5.17

Ignoring software updates? You’re making one of five basic security mistakes



Cybercrime has quickly become a major problem for businesses, governments and citizens all over the globe.
While awareness of this multifaceted threat is increasing, we’re still making the same blunder when it comes to cybersecurity, as a recent study by the Pew Research Center alluded to.
Here are a few security mistakes to be aware of.
Email: This ruse is nothing new
Social engineering tactics are as old as the day is long, yet people keep falling for them. Today, phishing via email has become incredibly commonplace.
Although criminals are improving the ‘quality’ of these emails, with some targeted – known as spear phishing – emails looking incredibly authentic most do not (telltale signs include poor spelling, random email address and far-fetched claims that you’ve won millions).
Keep yourself safe by carefully checking the recipient, the request, and use some common sense – search via Google rather than using the enclosed website address. Also, be cautious of attachments, as they may be malware-infected. It’s important to check file extensions and to only open files deemed safe and from legitimate sources.
Social media: New hunting ground
Social media has become the go-to-market for cybercriminals eager to compromise people. It’s no surprise, as many users still fail to adequately look after their networks (for example, a 2016 survey showed that 58% of people do not know how to update their privacy settings).
As with email, and post too, always check the authenticity of the sender (do they look credible?), the message and the link (which will likely be shortened). Beware trending hashtags too, as many as now using these to catch out unsuspecting Twitter and Facebook users trying to catch-up with the latest breaking news.
Attitude: It won’t happen to me
Forget technology for a second, culture is arguably the biggest issue with security right now, and this has been the case for 20 years. CEOs think they won’t be targeted and citizens think much the same (i.e. it won’t happen to me).
This complacency is misguided, as everyone is a potential target. Accordingly, this attitude can often result in poor security habits, with individuals and organizations treating, for example, password and Wi-Fi security not as seriously as they should.
This is despite the fact that good cybersecurity can be achieved relatively easily, through good password hygiene, regular software updates, anti-virus and even password managers, VPNs and secure encrypted messaging apps.
Passwords: The easy way in
Generic, guessable passwords can be easily cracked, and they can open a can of worms if you use the same password across several accounts. Brute-forcing passwords is increasing fast and easy for criminals today equipped with either huge computing power, or access to buy such expertise on the dark web.
Weak passwords, such as 123456; password; 12345678; and qwerty remain commonplace, with many people failing to see how this ‘low-hanging fruit’ is an entry point for cybercriminals. According to Forrester, 80% of all attacks involve a weak or stolen password.
Fortunately, some web providers now forcing you to generate random passwords, or create complex ones. You may want to consider a password manager, as well as passphrases.
Software updates: A lack of
Whether on desktop, laptop or mobile, there’s always another software update for an app, our operating system or security solution. Interestingly, the constant pop-ups irritate us, with many people failing to understand just how important they are.
If we fail to update, we’re effectively leaving our software and devices vulnerable to attack, as cybercriminals look to exploit out-of-date flaws. Configuring automatic updates from trusted providers can make sure these are installed regularly.
https://www.welivesecurity.com/2017/05/19/ignoring-software-updates-youre-making-one-five-basic-security-mistakes/?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+eset%2Fblog+%28ESET+Blog%3A+We+Live+Security%29

WannaCryptor: Are governments and financial regulators to blame?

On Friday 12th May the world paused and drew breath as cybercriminals launched WannaCryptor (popularly known as WannaCry), a ransomware attack that dominated news and conversations around the globe. Companies shut down technology that they rely on to trade, to treat patients and to communicate with customers. The results for many of the affected companies and their customers were devastating.
Security experts everywhere were called into action to combat the ransomware that was unleashed as companies and organizations attempted to return to normal trading and practice. The vulnerability used as an entry point to infect machines was in Microsoft’s Windows. The National Security Agency apparently knew about it, then someone leaked the details and the cybercriminal took advantage of the situation.
“As with all new innovative technology, it takes time for regulators and governments to catch up.”
We may never know what motivated the cybercriminal to unleash WannaCryptor but we do know that there was financial gain. The ransomware encrypted files, with an offer to decrypt them of $300, payable by bitcoin.
I am sure many of you, like me, have watched crime dramas where the law enforcement dudes say ‘follow the money’ as the method to find the real criminal behind a crime. Can you follow the money flow for WannaCryptor? Apparently not.
If you’ve attempted to open a bank account or applied for a credit card then you know the financial services industry has strict regulations requiring the identification of the person opening the account. The regulations extend to businesses and staff opening accounts or applying for a credit card terminal; the people responsible go through a process of being identified so they can be held responsible. The regulations are there to combat fraud and money laundering — in other words, to stop crime in the financial system.
Why does the criminal behind WannaCryptor only accept payment with bitcoin?
Bitcoin’s message on their website states that “bitcoin is open-source; its design is public, nobody owns or controls bitcoin and everyone can take part” and goes on to state: “Bitcoin allows exciting uses that could not be covered by any previous payment system.”
The concept of a virtual currency is potentially a good one: exchange rate free and accepted globally — there would seem to be benefits for businesses and consumers. How do I join the bitcoin community and reap the benefits of this virtual currency? To start with, I need a wallet to hold my virtual cash.
There are several wallet vendors, just like the physical world. With some offering additional privacy by rotating addresses and others offering services that remove the need to validate payments.
Once I’ve selected my wallet I can generate an address, a virtual location to receive funds; the recommendation is a different address for every transaction to enhance my privacy. The messages of rotating addresses and using a new address for every transaction start to give me the confidence that I am going to be able to remain hidden, private and anonymous.
Ok, my wallet is full, how do I get the money?
My wallet, which is an account, is bursting at the seams and I want to withdraw my funds. There are two methods: register with an exchange, or in person. Registering with an exchange will require positive identification, uploading utility bills and stuff that we are used to doing at normal banks. Alternatively, you can trade directly with another person, meet them, exchange a QR code for cash and walk away.
The ‘in person’ method of cashing out means another unidentified person now holds the virtual money in his wallet and I remain completely anonymous. Needing to move the funds on may not be essential though — holding on to them as an investment or anonymously trading for services could be alternatives.
Bitcoin is often regarded as an anonymous currency because it is possible to send and receive bitcoins without giving any personal identifying information. True anonymity may be impossible, as the cashing out process could require a physical meeting, but it is probably reasonable to say it’s pseudonymous.
Financial institutions around the world have sophisticated systems to detect money laundering, such as large sums moving from account to account. If you have ever sold a property and had the funds deposited in an account, you may have had to go through the experience of explaining where the funds came from.
In the virtual currency world there seem to be no – or very limited – requirements to track the flow of money, making it an ideal solution for criminals, fraudsters and terrorists to use for storing and moving their funds. A secret currency.
“As with all new innovative technology, it takes time for regulators and governments to catch up.”
As with all new innovative technology, it takes time for regulators and governments to catch up. Now would seem an opportune moment, though, for the same requirements imposed on financial organizations to be migrated to the new world of virtual currency, making “follow the money” a reality again. Taking action now by cutting off the ability to have an anonymously traded currency could stop the next major cyberattack.


18.5.17

WannaCryptor: Are governments and financial regulators to blame?


On Friday 12th May the world paused and drew breath as cybercriminals launched WannaCryptor (popularly known as WannaCry), a ransomware attack that dominated news and conversations around the globe. Companies shut down technology that they rely on to trade, to treat patients and to communicate with customers. The results for many of the affected companies and their customers were devastating.
Security experts everywhere were called into action to combat the ransomware that was unleashed as companies and organizations attempted to return to normal trading and practice. The vulnerability used as an entry point to infect machines was in Microsoft’s Windows. The National Security Agency apparently knew about it, then someone leaked the details and the cybercriminal took advantage of the situation.
“As with all new innovative technology, it takes time for regulators and governments to catch up.”
We may never know what motivated the cybercriminal to unleash WannaCryptor but we do know that there was financial gain. The ransomware encrypted files, with an offer to decrypt them of $300, payable by bitcoin.
I am sure many of you, like me, have watched crime dramas where the law enforcement dudes say ‘follow the money’ as the method to find the real criminal behind a crime. Can you follow the money flow for WannaCryptor? Apparently not.
If you’ve attempted to open a bank account or applied for a credit card then you know the financial services industry has strict regulations requiring the identification of the person opening the account. The regulations extend to businesses and staff opening accounts or applying for a credit card terminal; the people responsible go through a process of being identified so they can be held responsible. The regulations are there to combat fraud and money laundering — in other words, to stop crime in the financial system.
Why does the criminal behind WannaCryptor only accept payment with bitcoin?
Bitcoin’s message on their website states that “bitcoin is open-source; its design is public, nobody owns or controls bitcoin and everyone can take part” and goes on to state: “Bitcoin allows exciting uses that could not be covered by any previous payment system.”
The concept of a virtual currency is potentially a good one: exchange rate free and accepted globally — there would seem to be benefits for businesses and consumers. How do I join the bitcoin community and reap the benefits of this virtual currency? To start with, I need a wallet to hold my virtual cash.
There are several wallet vendors, just like the physical world. With some offering additional privacy by rotating addresses and others offering services that remove the need to validate payments.
Once I’ve selected my wallet I can generate an address, a virtual location to receive funds; the recommendation is a different address for every transaction to enhance my privacy. The messages of rotating addresses and using a new address for every transaction start to give me the confidence that I am going to be able to remain hidden, private and anonymous.
Ok, my wallet is full, how do I get the money?
My wallet, which is an account, is bursting at the seams and I want to withdraw my funds. There are two methods: register with an exchange, or in person. Registering with an exchange will require positive identification, uploading utility bills and stuff that we are used to doing at normal banks. Alternatively, you can trade directly with another person, meet them, exchange a QR code for cash and walk away.
The ‘in person’ method of cashing out means another unidentified person now holds the virtual money in his wallet and I remain completely anonymous. Needing to move the funds on may not be essential though — holding on to them as an investment or anonymously trading for services could be alternatives.
Bitcoin is often regarded as an anonymous currency because it is possible to send and receive bitcoins without giving any personal identifying information. True anonymity may be impossible, as the cashing out process could require a physical meeting, but it is probably reasonable to say it’s pseudonymous.
Financial institutions around the world have sophisticated systems to detect money laundering, such as large sums moving from account to account. If you have ever sold a property and had the funds deposited in an account, you may have had to go through the experience of explaining where the funds came from.
In the virtual currency world there seem to be no – or very limited – requirements to track the flow of money, making it an ideal solution for criminals, fraudsters and terrorists to use for storing and moving their funds. A secret currency.
“As with all new innovative technology, it takes time for regulators and governments to catch up.”
As with all new innovative technology, it takes time for regulators and governments to catch up. Now would seem an opportune moment, though, for the same requirements imposed on financial organizations to be migrated to the new world of virtual currency, making “follow the money” a reality again. Taking action now by cutting off the ability to have an anonymously traded currency could stop the next major cyberattack.
For more on the WannaCryptor, aka WannaCry, ransomware attack, check out the following: