Posts

Showing posts with the label hacking

Live Ensure® launches latest product features into US Market

  Live Ensure ® the SAAS  multi-factor authentication solution has spent the last year and a half field trialing the mobile version of the product with a few select customers who have collectively made millions of authentications without a single breach or failure.  Feedback provided valuable input which allowed the product to be further refined and streamlined making the user experience even better while making the solution stronger.   Live Ensure ® is easily integrated into an existing log-in form including SSO solutions like Twitter and Facebook.   This means that sites which allow users to log in e.g. with Twitter can now include a strong authentication layer thereby thwarting ID theft hacks which have become ubiquitous.   Examples are too numerous to mention but the weakness of password log-ins to emails ( Bush Hack )  and social media products (Twitter and Facebook) and their consequent failure are well documented. ...

FIDO, the password and Live Ensure®

Image
FIDO or Fast Identity Online was launched last week by a couple of Internet big hitters most notably PayPal.   They clearly have a vested interest in ensuring that their transactions are secure.     FIDO aims to provide specifications or standards to the industry that embody  an approach to authentication which starts to move away from the ‘security by obscurity ‘  or user name/password paradigm prevalent today.   The main reason why the incidence of hacking is sky-rocketing.   [ Twitter Hacked ] FIDO aims to leverage hardware devices such as phones and tablets as well as fingerprint readers, webcams, TPM ( Trusted Platform Module)  chips and tokens into an open-standard whereby there will be inter-operability between different systems but which comply to the standard.   A client/server architecture in combination with some hardware fingerprint starts to approach a much more secure approach th...

Out with the Old and in with the New

I was asked today by a board member to respond to a question from a prospective investor who wanted to know how Live Ensure (our service) differed from two other – lets call them ….the more traditional solutions.  For the sake of this blog we will call them the Old and the New solutions.   Let me describe the Old Co solutions to you briefly.  They both embody technologies which are over a decade old ( think RSA ) such as tokens and servers ( both physical and virtual).  Their solutions rely on the user entering a PIN into a browser and thereby satisfying the ‘something you know ‘ part of strong authentication.   Here it is slightly edited. The biggest weakness of both Old Co solutions are the vulnerability to MITM and MITB attacks. Both require the user to enter a PIN ( something you know ) ie a second factor over and above the user name and password ( the single factor or weak authentication ). The user enters this PIN back into the browser which is...

Why most security fails and LiveEnsure® does not ?

Image
Mary Meeker informs us that there are now 1.1bn  Smartphones  (17% of all mobile phones) and these are driving Internet growth with a total of 2.4bn people now connected to the Internet. Mary Meeker Internet trends The universe for hackers just grows and grows.    One of the most lethal of these attacks is Zeus (ZITMO) – which is aimed squarely at Smartphones. The Zeus attack is an example of several attacks now being launched that are based wholly on anticipated behavior, especially as it relates to social media, single-sign-on and BYOD. A sophisticated Zeus campaign stole an estimated €36 million, or $47 million, from over 30,000 customers across more than 30 banks in Europe this summer. The Eurograbber campaign, as it has been named, used custom versions of Zeus and Zeus in the mobile (ZITMO) Trojans to bypass the two-factor authentication measures to compromise customer bank accounts, Darrell Burkey, director of IPS products at Check Point Software Te...

CYBER LESSONS FROM SANDY

Whether in the 'real' world or the Cyber world there are real threats and dangers and there are perceived threats and dangers.   Sandy has just taught us about the reality of the force of nature when an extreme event occurs.    Destruction has been wrought on an unprecedented scale.  While we know that physical harm can be effected through  cyber-terrorism/war such as Stuxnet – the reality is that the hype about Cyber war is just that – hype.   These events, like Sandy, are rare.   I contend that the sources of much of the scare-mongering  (about the ‘threat’ of Cyberwar )  are more often than not , entities/organizations/newspapers / journals that have a vested interest in the proliferation of FUD about the weakness of our Cyber defences.    Don’t get me wrong – I am just as concerned as the next guy about cyber security – all I am saying is – lets get some perspective on the matter.   The defences that were put up again...

NatWest mobile banking fail and why real innovation in security is needed

Not a good week for NatWest innovative banking services.  NatWest Get Cash fraud   ( Get Cash Pulled ) A combination of a simple phishing attack and a fundamentally insecure service led to many users of the Get Cash service ( a sub set of the NatWest mobile banking app – powered by Monitise) being defrauded of cash from their accounts.    The system allows users to get cash from an ATM by keying in a ‘secure cash code’ into the terminal.    The assumption is that once you have logged in to your app you are legit and so you ping the system for the code.   A user name and password level of security – that’s it!.   No better than 99% of all apps on the Net today.    Needless to say the service was shut down once the fraud started becoming rampant.    Does the drive for customer convenience completely outweigh basic security rules. ?   The problem with this kind of solution and others that rely on the presentation ...

SITES DONT GIVE A DAMN ABOUT YOUR SECURITY

The sheer volume of reportage on hacking is overwhelming.   The sites being hit are the ones that you and I use every day.   Some provide useful information, some, valuable services and others perhaps just news or trivia.   We use them multiple times a day – sometimes without even being fully aware that we are,  like DropBox.   We use these sites  to store personal and business information, to connect us with potential clients, employers and employees, to help us choose insurance providers, to send us our groceries and some, to just play on.   Dropbox allows us to seamlessly log in by re-referencing a cookie they have planted on our computer to ‘verify’ our identity.   LinkedIn also uses the same technique when we log in.    A user name and password.  How secure is that ?    Well,  not very,  given that both of these sites have been hacked and your and my perso...

DROPBOX DROP THE BALL ..

My last blog touched on the DropBox hack.   It seems that they have now decided to rectify the situation.  ( DropBox Fix security )  But many clients have been left wondering.  How at risk was I and now am I ?   I wonder how much it has impacted their reputation ?    Do you entrust your personal and/or corporate data to them or to any of the other Cloud services out there.  The better known ones are Google Drive,  Evernote, Box,  YouSendit, Sugarsync,  MS SkyDrive and Egnyte.   If so then you should be concerned.   Why?  Because all of these services rely on you proving who you are merely through the provision of a user name and password.    Why is that so bad?   Because nowadays you can get password breakers off the Internet that will crack most passwords in seconds. ( Password cracker ) .   New sites are being hacked every day with serious consequences for the them and their users (i....

WHY SECURITY MATTERS? (or LET’S START A ‘PASSWORD SPRING’ ! )

You would be forgiven for thinking that perhaps most people have become somewhat nonchalant about online security and that the prevalence of hacks has made most of us somewhat immune to the dangers.    Indeed I would say that some sites have become almost cavalier about their attitude to their member’s security.  The recent hacking of LinkedIn certainly did not elicit the kind of response I would have expected, indeed hoped for,  as a member.   I get the impression that it was something of an irritant that they hope won't come again – and are certainly not bothering with beefing up security.  Far too much hassle.   So is their reaction reflective of their members lack of interest – I think not,  as one of their members has tried to sue them for failing to provide adequate security.  ( http://articles.latimes.com/2012/jun/21/business/la-fi-tn-linkedin-5-million-hack-20120621 )   LinkedIn have said that they will salt their passwords...

TRUST

Trust /trəst/   :   Firm belief in the reliability, truth, ability, or strength of someone or something. The foundations of the working of human society are built on trust.  This has been so since the beginning of recorded history.   As our communities evolved from hunter gatherer groups into agricultural chiefdoms, and ultimately modern states their operation, increasing complexity and success relied not only upon our cultural evolution as posited by Robert Wright in Non-Zero ( Non Zero )  but also upon trust.   Trust is integral to our ‘culture.’  The birth of capitalism and the rapid economic and technological growth of the last five centuries began with the pooling of capital used by investors to underwrite a ships trading expedition called the ‘ contratto di commenda ’ .  Such ventures could not have happened without the inherent trust that the investors had - that the expedition’s captain would return the profits to the investors....

Time for a new Magic Quadrant

You have all heard of the Magic Quadrant.  An industry benchmark by which the, mostly, established players like to measure themselves against each other.    To quote Wikipedia (that repository of all Internet wisdom ;-)) “ the Magic Quadrant aims to provide a qualitative analysis into a market and its direction, maturity and participants, thus possibly enabling a company to be a stronger competitor for that market. ”   The axes of the ‘Quadrant’ are ‘ability to execute’ and ‘completeness of vision’ and the methodology used to apply the ranking remains a closely guarded secret (or mystery depending on how you look at it.)   The MQ applies to many niches in the tech sector.  I want to consider the  User Authentication MQ.  Notably because the space is getting much media attention these days.   Hackers !  Wikipedia says that the aim of the analysis it is to  “ . .enable a company to be a stronger competitor for that market “ ...

You need authentication

I am constantly amazed at the lassez faire attitude that the majority of businesses, large and small, have about their online security.  Those that require their users / members to log on will provide a user name and password log in to verify their identity – and that’s it.  I suppose that if the large players like Amazon and iTunes can get away with it then the smaller guys think that’s all they need to. The reality is that if the big boys get a hit – they have the firepower to deal with it.  But SME’s just need one bad hack and they are out of business.    2011 is going down as the year of the ‘Hack’ (  http://www.infosecurity-magazine.com/view/22481/year-of-the-hack-/?utm_source=twitterfeed&utm_medium=twitter)  with many high profile victims like SONY, RSA and Epsilon losing millions of their users personal information.    Despite this there seems to be the attitude that ‘ it cant happen to me’ .  ...

Authentication in ' context'

con·text /ˈkäntekst/ The circumstances that form the setting for an event, statement, or idea, and in terms of which it can be fully understood and assessed. authenticate [ɔːˈθɛntɪˌkeɪt] vb (tr)   to establish as genuine or valid What does context have to do with authentication? When you log on to a web site and enter your user name and password so as to ‘authenticate’ yourself all you are presenting are self reported credentials to the site.  If you present the correct credentials then the site accepts you as - who you say you are.   It takes you at face value.  It identifies you.  Liken it to a knight of old arriving at castle and announcing himself.   When you log on to a web site and it asks you to log in with a user name and password – you are in effect – announcing yourself – identifying yourself.   What happens if someone steals your password?   Then they can log on as you – the site is none the wiser – the thief has presente...

SIX MONTHS ON AND EPSILON STILL DONT SECURE THEIR USERS

In April this year,  Epsilon Data Management LLC  (one of the world's largest providers of marketing-email services) , a division of Alliance Data Systems Corp issued a statement, " On March 30th, an incident was detected where a subset of Epsilon clients' customer data were exposed by an unauthorized entry into Epsilon's email system. The information that was obtained was limited to email addresses and/or customer names only ." ( http://www.fastcompany.com/1744738/the-epsilon-breach-should-you-be-angry-worried-or-bored ) When it's all said and done, the Epsilon hack may be the largest name and email address breach in the history of the Internet.  Epsilon handles more than 40 billion emails annually and more than 2,200 global brands. If you are thinking you are safe because you opted-out of marketing emails, think again ( http://blogs.computerworld.com/18079/epsilon_breach_hack_of_the_century ) Epsilon required their customer...

HSBC EMBRACES OLD TECHNOLOGY IN ITS BATTLE AGAINST HACKERS

 If you live in the UK and are somehow involved in the business world and exposed to media you could not help but have noticed the extensive advertising campaign that HSBC has been running on its new (sic) ‘security device’ for online banking - Secure Key.    ( I was tempted to refer to them as  ‘ large UK bank’  - but it is so obvious who it is – no point in pretending. ) A lot of money has been thrown at this campaign – I would guess millions.  ( http://www.youtube.com/watch?v=Jx0Z5CiQMIw )   Full page spreads in large circulation newspapers cost big bucks not to mention prime time TV slots.   So here you have the worlds largest retail bank splashing millions on advertising and even more on a ‘cool’ little device that looks like a mini-calculator  - but basically a technology that has been around for about a decade.   This will be rolled out to 4m retail customers worldwide at a reported cost of up to £50 per pop!...

SECURITY SANS FRONTIERS

In many countries around the World, access to the Internet is seen as a basic right, and so it should be.    Those countries which have done so to date include :  Estonia, France,  Spain,  Greece  and Finland,  which was actually the first to do so in June 2010.  ( http://www.publicserviceeurope.com/article/642/internet-access-should-be-a-human-right)  I In fact the United Nations recently declared Internet access as a human right. ( http://www.itproportal.com/2011/06/04/un-declares-internet-access-as-a-human-right/ ) Obviously the next challenge is to build the infrastructure and provide the means of access.    But that is the subject of a separate discussion. So the “World”  has woken up to the importance of closing the digital divide and has also realized the importance of the Internet, and access to it,  to the functioning of society.   Amongst the many momentous events of the last twelve months ...

ANONYMOUS / LULZSEC /ANTI-SEC ARE DOING MORE GOOD THAN HARM !

I know,   I know – I hear the howls of protest even before finishing this first sentence.   “What about all the innocent lives exposed by the irresponsible publication of peoples names in positions of authority or in sensitive roles. ?”    But where does the fault lie ?  With those doing the breaking and entering?   Or those not providing adequate protection??  It is liked leaving your house locked without an alarm system, going on holiday, and coming back and finding it broken into.   Don’t be surprised.  You have no one to blame but yourself.  “ But these are criminals ! “  – I hear the sounds of self righteous chest thumping.    Maybe, but what they have done – I hope – is scare the s**t out of anyone who has anything (data) that is accessible via the Web  - and into ensuring that their ‘security’ ( if any ) - is rapidly upgraded.    This ranges from personal users who ...