1.2.19

Four new caches of stolen logins put Collection #1 in the shade



The recently discovered tranches of stolen login credentials freely floating around the internet total 2.2 billion records
Two weeks ago, reports that a vast compilation of stolen access credentials was being widely circulated, not only in the internet’s dark recesses, made the headlines. Before long, additional reports began to pour in that this trove of data, dubbed Collection #1, was far from the only massive and readily available aggregation of stolen logins.
Security journalist Brian Krebs, for one, wrote that Collection #1, which comprises 773 million login names and associated passwords, was just a portion of a far larger stash of stolen or leaked credentials that was circulating on hacking forums and via torrents. Besides, by some accounts at least a portion of the latter caches contains more recent data, thus potentially posing greater risks for users. Enter Collections #2 through #5, so nicknamed by their creator(s).
Research by Germany’s Hasso Plattner Institute (HPB) has shed some more light on the data sets. HBP found that the number of purloined login credentials that have been cobbled together into the five tranches totals 2.2 billion, reads the HBP’s press release (in German).
Importantly, the institute operates a service that is similar to Troy Hunt’s Have I Been Pwned (HIBP) site. Unlike HIBP (as of the day of writing, anyway), the Identity Leak Checker includes data from all five caches in their entirety, and then some – 8.16 billion data records.
You can use the tool to check if any of your email accounts, or an online account associated with your email account(s), may have been impacted by a known leak. In addition to login names and passwords, the tool can also show some other sensitive information of yours that may have also been exposed.
Databases of stolen login data can have far-reaching implications particularly because of the rampant practice of many netizens to reuse their passwords across multiple services. Attackers can exploit this with an automated technique known as ‘credential stuffing’ that can give them access to other and possibly higher-value online accounts where the victim uses the same access credentials.
Beyond using a unique and strong password for each account, it’s also worth setting up two-factor authentication (2FA) wherever possible. That extra factor is a simple measure that is very likely to help thwart account-takeover attempts.

29.1.19

Hear me out! Thousands tell UK taxman to wipe their voice IDs




Even so, the database has grown to seven million voiceprints amid a controversy that puts the spotlight on the privacy implications of the collection of biometric information
In June 2018, a British privacy campaign group called Big Brother Watch accused the country’s tax authority of amassing the voiceprints of millions of people without asking for their explicit consent.
Within six months, more than 162,000 people would opt out of the voice ID scheme of Her Majesty’s Revenue and Customs (HMRC) and would have their biometric data deleted. While the thousands exercised their right to be forgotten as enshrined in the European Union’s General Data Protection Regulation (GDPR), another 2.1 million people joined the scheme between June and December 2018, bringing the number of people with voiceprints on file to around 7 million.
These developments come on the heels of a controversy that came to a head last summer when Big Brother Watch accused HMRC of “creating biometric ID cards by the back door” for 5.1 million taxpayers. The campaigners alleged that “HRMC has in fact railroaded taxpayers into this unprecedented ID scheme”, without providing a straightforward opt-out method. HMRC introduced the voice recognition system in January 2017.
Although there was a way to say ‘no’ to the scheme – it required saying ‘no’ to automated requests three times in a row – the opt-out route was not, in fact, immediately obvious (as detailed here). Instead, HMRC’s automated helpline instructed millions of callers to repeat the phrase “My voice is my password” up to five times in order to create a unique voiceprint for each of them and use it to verify the caller’s identity in the future.
The issue has also prompted the privacy campaigners to file a complaint with the Information Commissioner’s Office (ICO). The UK’s data protection watchdog has yet to decide on whether HMRC has been seeking user consent that is “freely given, specific, informed and unambiguous”, another requirement set out in the GDPR.
Either way, HMRC revamped the recording in July, introducing a clear option for callers to turn down the voice ID, as well as delete their existing voiceprints. By the taxman’s own admission, this option had not been stated explicitly before. As noted in HMRC’s Voice ID privacy notice, callers who reject the biometric option can continue to answer security questions to access their HMRC accounts.
ESET UK cybersecurity specialist Jake Moore views the news as a positive, but also sounded a warning: “It’s very promising that people can now delete their biometric voice data if they choose to. However, if HMRC took such data without consent then this is a different story. People should be given the option from the start whether to have their biometric data stored by the provider or not. Usually, people will assume this data will also be encrypted and kept highly secure, too”.
Meanwhile, the tax agency has also had to respond to concerns about the security of the collected data, not least because of the size of its database. HMRC has said that the data is encrypted, stored in a data center in the UK, and is never shared with anyone outside the agency.
HMRC is no stranger to biometrics, having also embraced the technology on its mobile app both for Android and iPhones. Besides authentication relying on a PIN code, people can also prove their identity using face recognition and fingerprint scanning.

27.1.19

Le Forum International de la Cybersécurité 2019 : la connaissance comme première ligne de défense



L’importance de la transmission des connaissances marque la 11e édition du FIC, espace de réflexion sur la vision et les enjeux européens en matière de cybersécurité.
L’année 2019 s’amorce à peine et est déjà marquée par une brèche de sécurité d’envergure gargantuesque, ainsi que la publication d’informations confidentielles touchant des personnalités politiques allemande de premier plan. De nombreux incidents ont déjà marqué cette année et rappellent à tous le rôle prépondérant des questions de sécurité numérique, tant pour les utilisateurs que pour les organisations privées et même, les gouvernements et États. C’est dans ce contexte que se clôture la 11e édition du Forum International de la Cybersécurité (FIC) 2019, à Lille, en France. Cet événement annuel regroupe tant les experts et les représentants de l’industrie que les gouvernements au sein d’un espace d’échanges et de réflexion sur les enjeux et la vision de l’Europe en matière de cybersécurité.
Dès le départ, le ton était donné : les participants ont pleinement conscience de l’importance des enjeux actuels; qu’on parle par exemple de la privacy by design ou du RGPD, sans oublier la cyberdéfense au niveau national. Ainsi, Laurent Nuñez, Secrétaire d’État auprès du ministre de l’Intérieur français, soulignais l’importance majeure des questions de sécurité numérique, dès l’ouverture du FIC 2019. Son propos était sans équivoque: « Pour le gouvernement et le ministère de l’Intérieur, 2019 sera une année décisive en matière de cybersécurité. »
La tenue du FIC 2019 coïncidait d’ailleurs avec le premier bilan annuel de la plateforme cybermalveillance.gouv.fr, programme lancé à l’automne 2017 par le gouvernement français, afin de contribuer à la sensibilisation, à la prévention et au soutien en matière de sécurité numérique à travers la France.
Ce premier bilan annuel montre bien l’importance que revêt la mission de la plateforme. En effet, soulignons notamment que pour 2018, « 28 855 victimes sont venues chercher de l’assistance sur la plateforme en 2018 dont 24 574 particuliers, 3 650 entreprises et 631 collectivités. » La notoriété et la popularité de la plateforme est d’ailleurs en augmentation.  En effet, celle-ci a connu une croissance de « +500% de personnes » des personnes la consultant entre le début et la fin de 2018. Depuis le lancement du 1er volet du kit de sensibilisation, en juin 2018, celui-ci a été téléchargé plus de 21 000 fois.
Parmi les tendances observées, les principales menaces soulevées dans ce bilan comprennent les tentatives d’hameçonnage, le piratage de compte, l’envoi de spam (ou pourriel) et les virus, notamment les rançongiciels.
Vu la place de plus en plus prépondérante et menaçante de plusieurs menaces, il va de soi que la préparation en amont est essentielle. L’un des thèmes marquants du FIC 2019 était d’ailleurs le privacy by design. Alors que de plus en plus d’objets connectés nous entourent et modifient nos façons de faire, il est de plus en plus fondamental que la cybersécurité soit au cœur de l’ensemble du processus de conception de ces appareils, afin d’a sécurité et la vie privé des usagers.
Alors que les plusieurs cybermenaces se complexifient, une chose demeure. Plusieurs présentateurs ont souligné, à juste titre, qu’aucune couche de protection technologique ne peut se substituer à la formation et vigilance de chaque utilisateur. Il suffit en effet d’observer du côté des attaques de rançongiciel ou de cyberpiratage pour constater que l’ingénierie sociale vit toujours de beaux moments. Mais il n’en tient qu’à chaque individu, et à chaque organisation, de se préparer adéquatement pour éviter de devenir malencontreusement son propre adversaire.



25.1.19

Le baromètre de la cybersécurité: l’étude démontre l'impact de la cybercriminalité sur la vie privée et la sécurité



Septante pourcent des américains interrogés par ESET s'inquiètent de l'utilisation abusive des informations personnelles fournies aux sites Web lors de leurs transactions bancaires ou de leurs achats en ligne. Aujourd’hui, une écrasante majorité d'américains considèrent la cybercriminalité comme une menace pour leur pays, et cette menace ne fait que croître. Il ne s’agit que de quelques-unes des principales conclusions du baromètre de la cybersécurité d’ESET, une enquête faite auprès de 3.500 adultes en Amérique du Nord (2.500 aux États-Unis et 1.000 au Canada).
En tant que chercheur qui, depuis des années, analyse les enquêtes concernant la cybersécurité, Stephen Cobb , chercheur senior chez ESET, ai constaté la préoccupation croissante du public pour la cybercriminalité. Cependant, il a été choqué de voir les résultats : neuf sur dix des américains interrogés déclarent que la cybercriminalité constitue "un défi majeur pour la sécurité intérieure des États-Unis".

En tant que criminologue, il a été tout aussi choqué de constater que les personnes interrogées considéraient la cybercriminalité comme un défi plus important que le trafic de drogue ou le blanchiment d'argent. Constater que moins de la moitié des participants pensent que le gouvernement et les forces de l'ordre en font assez pour lutter contre la cybercriminalité, a été tout aussi inquiétant.

De quel type de baromètre s’agit-il ?
Le baromètre de la cybersécurité d’ESET est une enquête qui évalue les attitudes et les expériences du public en matière de cybercriminalité, de cybersécurité et de confidentialité des données. Ce qui fait la différence avec d’autres enquêtes – comme celles des entreprises qui vendent des produits et services de sécurité – c’est que ce baromètre a été conçu par des décideurs gouvernementaux. L'enquête se compose d’une série de questions similaires à celles utilisées pour des études menées dans l'UE pour la Commission européenne. Le but est de récolter des données qui peuvent être utilisées en confiance par les responsables politiques et les décideurs. Les résultats obtenus doivent résister à d’éventuelles accusations de partialité lors de la conception de cette enquête et permettre les comparaisons.
Ce lien permet de télécharger un PDF du rapport ESET Cybersecurity Barometer USA report 
Le rapport concernant le Canada se trouve sur: ESET Cybersecurity Barometer Canada.

Quelles sont les spécificités de l’enquête ?
Dans cette enquête, ce qui frappe, ce sont les préoccupations exprimées par les personnes interrogées au sujet des menaces causées par la cybercriminalité ainsi que le manque de confiance dans la possibilité d’une amélioration rapide. Près de 87% des participants s’attendent à ce que le risque d’être une victime de la cybercriminalité augmente.
D’autres éléments importants sont la manière dont les Américains réagissent à la cybercriminalité, y compris un pourcentage inquiétant de personnes interrogées qui affirment être moins enclins à faire des achats ou des opérations bancaires en ligne à cause des problèmes de sécurité et de confidentialité (respectivement 19 et 20%).  Ces résultats démontrent clairement les opportunités manquées par la distribution et le secteur bancaire. Les spécialistes du marketing numérique doivent tenir compte que pour 44% des participants, les problèmes de sécurité et de confidentialité ont eu comme résultat qu’ils fournissent moins d’informations personnelles sur les sites. Le rapport souligne aussi la relation entre les préoccupations au sujet de la cybercriminalité et le taux de récidive. Près de 70% des américains adultes interrogés signalent avoir reçu des mails ou coups de fil frauduleux leur demandant leurs données personnelles. Le même pourcentage a exprimé ses préoccupations à ce sujet.
Un nombre bien plus important (86%) est préoccupé par le fait qu’ils pourraient être la victime d’un vol d’identité alors que seulement 30% - donc moins de la moitié - avait fait une déclaration de vol. C’est donc particulièrement choquant de voir que trois américains sur dix ont déjà été victime d’un tel vol. Mais, comme le rapport le mentionne, ce niveau élevé de préoccupation nous permet d’apprendre beaucoup de choses très intéressantes.

Pourquoi une telle enquête ?
Comme les lecteurs réguliers de WeLiveSecurity.com le savent, Cobb a déjà expliqué pourquoi il faut évaluer l’opinion publique en matière de cybersécurité et de protection. Cela se trouve dans: Why ask the public about cybercrime and cybersecurity?
D’après lui, les gens choisissent leur gouvernement et aident ainsi à déterminer la politique en matière de cybercriminalité. Par leurs impôts les citoyens payent une grande partie des efforts gouvernementaux visant à réduire la cybercriminalité.  Dès lors, savoir ce que pense le public de la cybercriminalité, de la cybersécurité et de la confidentialité des données est essentiel pour le développement réussi d’une politique contre la cybercriminalité et d’importance capitale en ce qui concerne les efforts de la société dans le domaine de la cybersécurité.
Les résultats de cette enquête constituent jusqu’à présent la plus forte indication de la rapidité avec laquelle les systèmes et les données sont utilisés abusivement. Ainsi, la confiance du public dans la technologie sera encore affaiblie, à moins que la cybersécurité et la dissuasion de la cybercriminalité ne soient traitées avec une plus haute priorité par les gouvernements et les entreprises. Comme indiqué dans le rapport, maintenir et développer cette confiance est d’une importance capitale pour le bien-être économique de l’Amérique, maintenant et à l’avenir.

A propos d’ESET
Depuis 30 ans, ESET® développe des logiciels et des services de sécurité IT de pointe destinés aux entreprises et aux consommateurs, partout dans le monde. Avec des solutions allant de la sécurité des terminaux et des mobiles jusqu’à des solutions de chiffrement et d’authentification à deux facteurs, les produits conviviaux et hautement performants d’ESET confère aux consommateurs et aux entreprises la tranquillité d’esprit nécessaire pour pleinement tirer parti des potentiels de leurs technologies. ESET assure une protection et une surveillance discrète 24 h sur 24, mettant les solutions de protection à jour en temps réel afin de garantir la sécurité des utilisateurs et les activités des entreprises, sans la moindre interruption. Les menaces en constante évolution requièrent une société spécialisée en sécurité IT qui soit elle-même évolutive. S’appuyant sur ses divers centres R&D de par le monde, ESET est la première société de sécurité IT à avoir décroché 100 récompenses Virus Bulletin VB100 et ayant identifié, sans exception, tous les malwares en circulation et ce, sans interruption depuis 2003. Pour toute information complémentaire, consultez le site www.eset.com ou suivez-nous sur LinkedInFacebook et Twitter.

24.1.19

Can you spot the phish? Take Google’s test



Everybody loves quizzes. So why not take this one and hone your phish-spotting prowess?
Google’s technology incubator Jigsaw has revealed a quiz that tests users’ abilities to identify phishing attacks. In asking you to distinguish legitimate emails from phishing scams, the test reveals some of the most common scenarios that fraudsters use with a view to stealing your finances, data or identity. It comes complete with to-the-point explanations as to why this or that message is, or is not, a phishing attack.
According to Jigsaw’s blog post, the test is based on the company’s security trainings with “nearly 10,000 journalists, activists, and political leaders around the world from Ukraine to Syria to Ecuador”.
All eight scenarios draw on real-life techniques deployed by scammers. The examples vary and include files shared via Google Drive, email security alerts, Dropbox notifications and, of course, attachments that ask for your immediate attention but are, instead, intended to download information-stealing malware onto your machine.
Phishing remains the most pervasive of online cons and has for long been a highly effective method for fraudsters to steal people’s sensitive data. “One percent of emails sent today are phishing attempts,” according to Jigsaw’s figures.
Indeed, many security incidents begin with a user simply clicking on a malicious link or opening a dangerous attachment that is most commonly delivered via email or social media. Even though email filters do a good job of winnowing out many such scam attempts, some fraudulent emails will still slip through. Which is where phish-spotting skills can be critical, as can anti-phishing protection that is commonly part of reputable security software.
And, as Jigsaw itself recommends, you should enable two-factor authentication (2FA) wherever possible, if you haven’t done so already. The extra factor offers a valuable additional layer of protection in return for very little effort. It is best implemented via a dedicated hardware device or delivered through an authenticator app, rather than via text messages (although SMS is still better than nothing). The availability of various 2FA methods on various online services can be checked on this site.
Back to the testing, however: If you got all the answers right, congratulations! That said, it’s probably better not to be lulled into a sense of complacency. Many scams can be even more devious and are, indeed, “difficult to spot even for a trained eye”.
Did you fall for any of the eight examples? There’s no need to feel ashamed. At least you should have a better understanding of the threat, making you better equipped to protect yourself from actual phishing attacks.
If you’re up for some more testing, you may also want to head over to this questionnaire devised by researchers at the Universities of Cambridge and Helsinki. The test, which we wrote about last year, will gauge your susceptibility to falling for online scams and other types of internet crime.
The complete article on:

22.1.19

Email Security does not end with your password



Email is a crucial part of most people’s daily lives, but few people consider how it’s secured, apart from entering a password to access our accounts. What options are available or even advisable to use for securing email?

What is email security?
For the purposes of this post, I’ll define email security as pertaining to both the content of messages, as well as the accounts people use to access their emails.
Email security does not end with authentication for accessing our accounts: message content can be validated and secured, sender identity can be authenticated, authorization of email senders can be maintained, and the integrity and functionality of the email app itself can be better secured. 
If you’re the administrator of your email account, you’ll naturally have a different subset of options than if your account is being administered by someone else. Depending on your threat model, which options are needed may vary somewhat, but most of us could benefit from adding more methods to our repertoires.

Securing message content
Few people seem to be aware that sending an email can be as open to eavesdropping as sending a message on a postcard. Fortunately, there are a variety of ways to add layers of security to the process of sending a message. One method is akin to putting a message in an envelope; people can still see where the message came from, and where it was sent to, as well as the content of the message if an eavesdropper is able to intercept it at some point in the process (especially after the envelope is opened). This type of protection is considered “transport-level”, as it helps protect the message in transit across the internet.
It’s also possible to secure the message from “end to end”, meaning the message is encrypted at the source before it ever hits the network, and then decrypted by the recipient. This shortens the time that a message might be read even by an eavesdropper, as it can’t be read when it’s in transit or until its contents are decrypted. The eavesdropper would also need to have the decryption key as well as the email to access the data within an intercepted message.
Administrators often choose to implement transport-level protection, as it’s the type that’s most transparent to users and because it usually doesn’t require their direct interaction. If end-to-end encryption is needed, it’s a good idea to choose technologies that make this process simple, and to create policies that dictate when this type of encryption must be used.

Ensuring valid, appropriate content
It’s a fact of modern life that much of what arrives in our inbox is not anything we want to receive. When you add up the amount of spam, scams, phishing and malware that’s being sent, there’s a lot of traffic that is wholly unwelcome. Most organizations and email service providers have some manner of filtering for this sort of detritus in place already, to help stem the flow. Depending on our own levels of risk tolerance, there are a variety of ways that this can be done.
Most email providers operate a simple blacklist of known spam, phishing and malware to decrease the amount of unwanted and malicious email that reaches their customers. But many organizations would be wise to be more proactive with their filtering. You could also limit messages by attachment type; either allowing only those files from an approved list of safer or more common file types or excluding unusual or more-risky file types.
Keep in mind that while many popular file types may seem safer, they can still include powerful macro code or malicious, embedded files. No file type should be considered completely safe. It may be more helpful to view file types less in terms of their potential danger, and more in terms of their level of risk versus potential impact on workflow. While many people send things like documents, spreadsheets, or presentations, very few people have valid work-appropriate reasons to send or receive executable file types via email, so these can be excluded in most organizations with a minimum of hassle.
Some organizations also choose to screen emails before they’re sent out from their network too, for malware and/or confidential company data. Most companies maintain some sort of sensitive files or information such as payment or ID card details, healthcare information, or confidential company data and would do well to log its whereabouts. It can be useful to set gateway anti-malware scanners to more “paranoid” settings, as a potentially slower scan of files going through email will be less noticeable or disruptive.

Email authorization and authentication
Spoofing email is trivially easy for miscreants, and while there are ways to limit this, the available options are not yet widely used. These techniques help authenticate message content, indicate which users and accounts are authorized to send from your domain, and can help verify that email headers are internally consistent.
Because these authorization and authentication techniques are not commonly implemented, the best-use case for most companies is to deploy these methods to help protect your brand integrity or prevent certain types of Business Email Compromise (BEC). You can also use them to log emails that fail to authenticate properly, for forensic purposes.
Use of email authentication and authorization should be considered part of good administration hygiene, like promptly removing (or at least changing the passwords of) accounts that are no longer in use (such as those formerly belonging to employees who are no longer with the company).

Account protection
Most of us are aware of authentication for our email accounts, as this is the type of email security most of us have. Several of the other types of email security we’ve discussed in the previous paragraphs exist in part to help mitigate the damage caused by stolen login credentials, which is to say it’s a huge problem that causes a cascade of other woes. But multi-factor authentication is another very effective level of protection for access to our email accounts.
Rather than just providing a username and password, which is one single “factor” of verifying that you are who you say you are, multi-factor authentication combines these credentials with another method. The most common example of a second method is a one-time key – often sent by email or SMS, or created by an app or dongle – that is input after you’ve successfully entered your username and password. Multi-factor authentication can either be tied directly to the login process for an email app, or to a network login process, depending on your specific needs and threats.

Software protection
Last but not least, it’s also important to protect your email by regularly updating the software you use, including your operating system and the app or browser you use to access email. This will help address vulnerabilities that could allow attackers to access your emails. You may wish to do this with automatic update capabilities in the software itself or in your operating system, or by going directly to the vendor’s website for downloads.

Final Thoughts
Whatever methods you choose to incorporate – be it for email or computer security in general – it’s important that they be things people in your organization can and will use. This means observing the workflow of the people who will be using these technologies, choosing options that are either applied automatically or are easy to use, and then training users about how and when to use protection methods.

CES: Smart cities and the challenge of securing the neighborhood

Cameron Camp
In our final report from CES we take a look at smart city initiatives
This year at CES there was an entire section devoted to smart city initiatives municipalities are rolling out in many cities around the world, or planning to. As we noted in our look at automotive security and IoT security previously, the technologies surrounding transportation are converging; so too are the technologies that make cities work. From automated street lights that change color to alert you of a hazard, to centrally-planned dynamic traffic flows and car-to-car communication, cities will change rapidly. But how they will manage these changes is another story.
Stage one is the deployment of sensors that passively assess traffic flows, pedestrian traffic and potential hazards. Shortly thereafter, cities will deploy more active measures, such as controlling traffic lights and entire systems based on holistic input from the swarms of sensors.
One of the hotspots (literally) will be city lamp posts, especially if they are connected electrically. This will be the focus of considerable attention, as they are a perfect platform for Wi-Fi, temperature and other ambient condition sensors, and hence, potential hosts for super-high-speed, ubiquitous, wireless connectivity. Want to get a feel for what’s happening across the whole landscape? Fire up a mesh of a bazillion sensors on the lamp posts and start getting a better picture. All this without significant development and acquisition of land.
Next will be law enforcement, or more specifically, rolling out these new rafts of collected data (after being sifted and enriched) to provide real-time data as they drive, walk, or ride around the city.
So the swarms of sensors will feed the central offices, which will then feed data back out to the swarms of consumers . . . after being digested and enriched.
The problem is that cities are extremely ill-prepared to staff and manage all the complexity, let alone secure it all. If, for example, attackers are able to gain access to one part of the sensor network, it becomes potentially easier to use as a potential onramp to escalate to more privileged access and hop back to the critical data stores and exploit them as well.
This dynamic would be much easier to manage if cities had vast budgets to hire the best cybersavvy technicians and specialists, but it is important as it is paradoxically rare. Here, “fire and forget” just doesn’t work well. We’ve seen breach after breach where organizations had the right technology deployed, but failed on implementation or triage and escalation of potential breach incidents.
For cities that try to outsource their needs, concerns such as data leakage and misuse come to the fore. In light of the raft of legislation for protecting personally identifying data, the potential blowback from leaking security information for example, would make for some rough public relations for the mayor of a city, who’s staff might not be digital experts at all.
Most cities are primarily concerned with keeping the lights on, the water flowing, the streets open, the trains running and so on. The politicians and critical infrastructure managers are far more concerned with high availability than high security – or indeed, any security at all. Year after year at the Black Hat conferences we see examples of city systems trivially exploited. Yet, with the increasing interconnectivity of their systems, smart cities will soon be saddled with understanding and implementing cybersecurity well.
Oh, and without significant budget increases!