Tuesday, September 19, 2017

EQUIFAX - There should be a limit to just how deep you go.


Second opinion piece within one week on the same subject, must be that kind of week.

The type of week that makes it simply too overwhelming to keep my fingers off the keyboard.

As it stands now, it is no longer a big secret that Equifax was not doing what they should have been doing and they exposed a vast amount of extremely sensitive personal information.

LAWSUITS 

The FTC (Federal Trade Commission) in the US has officially commented that they are investigating.  Also of interest, in Atlanta, a lawsuit has been filed for  “gargantuan failures to secure and safeguard consumers’ personally identifiable information … and for failing to provide timely, accurate and adequate notice”  Add to that Massachusetts who just announced legal action for failing to protect its residents and maybe a landslide of lawsuits is just around the corner.

This is very interesting, and I certainly wish someone... anyone.... in Canada decided that these services put together by chimpanzees with duct tape should ALL be investigated and audited to ENSURE that a REASONABLE level of security is in place.  All we have so far... is a rather weak statement from the privacy commissioner. 

TOP QUALITY SECURITY PROFESSIONALS

Something even more fascinating came out, this was the fact that their CSO (Chief Security Officer) was paid a ridiculously large salary which didn't seem to help their security posture since issue after issue have been reported over the last few days. Including the services in one country being accessible with the ever so complexe and secure username ADMIN and password ADMIN.

Several video and audio interviews performed in the past by EQUIFAX's CSO have been pulled from Youtube and SoundCloud.  Luckily the Internet is responding by finding their own copies and reposting them

It seems that watching these videos and listening to the CSO's discussions gave you little doubt that this breach was going to happen.

Luckily they have all been pulled from the Internet, only a few transcripts remain at http://archive.is/6M8mg

Unlucky for us since we cannot view these gems and make our own opinion.

What has surfaced is that the CSO's formal training appears to be in Music (Music Major).  This got the entire Internet in an uproar, however on it's own, it really is meaningless as good security requires intelligence and common sense, and I know plenty of musicians that have both.

This does however become very pertinent when under every stone the Internet lifts up, fumes from a pile of shit seem to rise.

So Equifax in Canada appears to have announced that at least 100,000 Canadians have been exposed, that they are protecting these accounts with their protection services for free, and that the ongoing investigation should conclude within a few weeks when they can finally announce who got screwed.   Fascinating that they are stating that they are protecting the 100,000 people right now, as they publish this news, yet they do not know who they are, and will let them know when their investigation concludes.

So just to recap, so far we have:
1) Hidden the breach for something that appears to be 5 months or more

2) Inside trading as senior execs sold stock after the breach was known and prior to it being announced

3) Someone with intimate knowledge shorted the stock to the tune of 4 million

4) Several senior execs just decided to retire

5) The CSO has no formal training yet is paid a multimillion dollar salary and has also just retired

6) Equifax was reported as compliant to PCI, ISO, SOX II TYPE II, etc.

7) Their critical systems where not patched and up to date

8) At least one system had no valid password to protect the ADMIN account yielding access to all client data

9) Their response to the incident is clearly amateur.

10) Somehow they had unencrypted credit card numbers just sitting there, or their encryption architecture was so so weak... Yes... weak it is as the private keys are accessible in the web panel.

11) They put together a credit monitoring service that is also exposed

12) They put together a site to tell you if your data has been exposed that returns random results.

13) They are erasing any Video/Audio traces of their Musical CSO

14) .....   I could go on, and on and on, but I'm tired of going through tons of notes on the subject... you get the idea....

This folks is how to NOT run an incident response.

SETTING A GOOD EXAMPLE

This week, another significant security breach has surfaced.  CCleaner is a utility program used by millions and it got hacked and ended up deploying malicious code on it's users workstations.

Listen up to how they managed this crisis.

They came out and said the following: (reference article here)

a) We are sorry
b) We screwed up
c) This is exactly how it happened
d) This is exactly what we did to fix it
e) This is exactly what we are doing to address the root cause so this doesn't happen again

So what do you think is going to happen.

It's going to go away.  They took responsibility and didn't cover it up, came right out and came clean.  It's over, move on.

This is clearly not the angle that Equifax is taking.

COMPARING WITH A TARGET

A few years back a significant breach had taken place at a small retailer called TARGET.

They too took the glamorous path of lies and the strategy of downplaying.

Day 1: We may have had a breach
Day 2: Some client data might have been touched
Day 3: Only 10 million client records could have been affected
Day 4: Only 40 million client records might have been affected
Day 5: Only 70 million client records involved
Day 6: Oh to hell with it, all our client records have been hacked.

What happened, the media ate them alive.

At the exact same time, another retailed had had pretty much the exact same breach.

Neiman Marcus had been hacked using the same technic.  They came out day one and said, we are not sure exactly what happened, but it looks like all our customer data was stolen.

The media wrote about it once, moved on.   What else is there to say.  

The Target went on for more then a month because they kept trying to cover it up.


So here we stand, with Equifax doing such a swell job.

ABSENCE OF CANADIAN LEADERSHIP

Where EXACTLY is our Canadian privacy commissioner ??????

Since Equifax is run by big business for big business... is it untouchable in Canada ?
Since they have all of our data, and most people aren't even their client, nor do we really want them to have our data...... is there anything we can do ?

Why aren't our elected officials taking direct, public actions to investigate a company that CLEARLY needs to be verified.

Also in the news this week, JPMorgan CEO calls bitcoins a fraud and says he will fire anyone in his firm that invests in bitcoins....  bitcoins plunge and JPMorgan shorts it and makes millions.   Yet JPMorgan has been fined 13 billion for fraud in that last years...

Just how far in does the apparatus have to be inserted before someone yells "HEY !  That's deep enough!"

In closing, I recommend reading through this post from SPUZ.ME that highlights some of the exchanges with the hackers who broke into Equifax.  The screen shots kinda of give a big secret away.  Equifax has all your shit accessible from the Internet.  

http://spuz.me/blog/zine/3Qu1F4x.html

or visit the hackers current onion site at :  equihxbdrjn5czx2.onion



_______________________________________________

Eric Parent is a senior security expert, specialized in coaching senior executives.  He teaches CyberSecurity at l'Ecole Polytechnique and HEC Universities in Montreal, and is CEO of Logicnet/EVA-Technologies, one of Canada's oldest privately owned security companies.

Follow Eric on:
Twitter @ericparent
LinkedIn :  EVA-Technologies

www.eva-technologies.com




Saturday, September 9, 2017

Equifax is "SCREWING" their "customers".



This is an opinion piece... so grab a beer or a line of coke like the Equifax execs have been doing.






First they have repeated security issues, many reported to them and they do nothing.  And they have had breaches in the past (2 others in the last year or so).


Second they appear to be taking full advantage of this "breach" in a way that Donald Trump would appreciate.

Hey, business is business, not my fault you happened to be bent over while I was getting ready to...  All right, let's keep it clean.

Researchers (friendly hackers) noticed something really cool about the NEW service being offered by Equifax to check if your data is part of the breach.

Drum roll please.....

It doesn't really matter what you enter, the answers are random and they just want to push you to their TrustedID service.

Coincidentally subscribing to this service means you are agreeing with their terms and you give up your right to sue their sorry asses.

Take a look at this posting from Sarah Buhr at TechCrunch and your aggravation level is certain to rise unless your dead inside.   


PSA: no matter what, Equifax may tell you you’ve been impacted by the hack

A while back I wrote about the Ashley Madison "hack" and the fact that this company had self proclaimed themselves secure with a made up Security Award.  Well... seems they all went to the same business school as what Equifax is doing and how they are responding to this breach is inline with this type of business practice.

Combine all this with the fact that senior executives sold 2 million in stocks prior to the announcement, and then you add to that the unknown person or persons who shorted the stock and made another 4 million.... you have yourself a really nice picture generally called insider trading along with a few more terms not fit for small children.


Suspect trading in Equifax options before breach might have generated millions in profit



This all points to something missing in our wonderful world called PENALTIES.   Not penalties for the enterprise.  The executives do not care if the enterprise has to pay some penalties.  Penalities for the executives including jail time when their actions are criminal in nature.  

I'm not referencing the insider trading, which I hope is considered criminal.  I'm referencing the lack of respect for their customers data and willful blindness when serious security shortcomings are reported up the chain of command.

And by the way, why are we calling ourselves customers, when in fact we are their product, not their customers.  We are forced to deal with companies run by clowns, and the only time we are customers is if we subscribe to one of their shitty services to access our own damned data and make sure they are reporting accurately on our data !!!  What world are we allowing ourselves to live in.

I have to pay a monthly fee to access my data that I never wanted these idiots to have.  Why... because the banks "need" it the authorize my mortgage.  We certainly don't want the banks taking too much risk.  Wait... didn't they seriously screw up a few years back and lend billions of dollars that they shouldn't have and then the US government bailed them out and they all took in BONUSES !

If you want a really good laugh, take a look at Equifax's SOC 2 TYPE II attestation report.

https://www.equifax.com/assets/WFS/the_work_number_best_practices_in_data_security.pdf




Proof again, that traditional auditing mechanism are meaningless because people LIE. 

Listen up folks:  Companies on the stock market are filled with executives who have ONE priority, themselves.  Therefor they LIE, COVER UP, and IGNORE some pretty significant elements that lead to events like this.  Their bonuses are dependant on everything looking great.

So there you have it folks.  A great big company, audited by other great big companies, compromised at all levels including ethically and morally.

No wonder I prefer family run businesses.  My two most significant clients are family run (one is 500m revenue and the other is several billion) and surprise surprise, when something comes up as a security risk, the CIO brings to the the CEO and no one hides anything.   They just manage the risk, takes decisions, figure out how to be better and fix things.  

Wow.... that's revolutionary.


_______________________________________________

Eric Parent is a senior security expert, specialized in coaching senior executives.  He teaches CyberSecurity at l'Ecole Polytechnique and HEC Universities in Montreal, and is CEO of Logicnet/EVA-Technologies, one of Canada's oldest privately owned security companies.

Follow Eric on:
Twitter @ericparent
LinkedIn :  EVA-Technologies

www.eva-technologies.com







Friday, September 8, 2017

Slow News Week


The quality of journalism can certainly be challenged these days.   It seems that in order to keep your job, the title of every article must sound alarming and catastrophic in nature in order to "sell print".

Sad really, since we end up with a feeling of fake news, and many other side effects.

However, a significant mass of people will be reading these articles and believing the negative feelings being conveyed.  

This morning, in Montreal's very popular "Journal de Montreal", we find an article titled "He receives a strangers card" making reference to a medicare card.   Not a credit card, not a drivers license, but a medicare card.

Poor poor man.   How traumatizing to have received your own card along with a strangers.  How will you sleep through the night and get to work on Monday.

If you ordered underwear from Amazon and received someone else's order of socks would you call the newspaper or would you call Amazon to have the error corrected?

This is not the first time a shit article has been written on a shit subject.   Last year, someone received something from the government that was miss addressed and the newspaper did the same type of article.

Lets look at the risk.

The medicare card has only one piece of sensitive information, your birthdate.  Combined with your name, the person who erroneously received your card, now has a piece of plastic with physical countermeasures similar to a credit card, that has your picture, name and date of birth on it.

What is the risk here..... well....  if the person that received it is Frank Abagnale then maybe he can cannibalise the card, change the picture and used it to get free medical services.  Frank wouldn't have your address and know where you bank, so the damages to you are limited to say the least.

In order to sound like a journalist, let me say it this way..... 

"The statistics demonstrate that sending a random medicare card to a random individual will not result in that card being used maliciously"

Did I say statistics... sorry I meant common sense.

"A random citizen does not have access to the talent required to fraudulently use someone else's medicare card"

"A random citizen doesn't have access to the underground networks that use false medicare cards for profite"

Oh oh oh wait.... here is a good one...

"A random citizen can't do shit with your name and date of birth and your ugly mug shot".   Usually considered the same pairing of information that most idiots share with their 800 Facebook "friends".

As an other note.....  news is supposed to be pertinent (in my opinion).  These types of articles only make the security uneducated worry about something that is out of context and of no value.  The fact that a rubber bushing on an envelope stuffing machine felt fat one morning and spewed two cards into an envelope instead of just one is about as newsworthy as watching paint dry or linoleum curl under high humidity. 

Imagine your next family gathering where grandma wobbles over to her security expert grandson and asks "How bad is it dear, am I going to loose my medicare, I read that they sent out my card to the wrong address".

Charming.

I'm pretty convinced that there are large masses of worthy subjects to investigate and report on.   

This happens in security articles too

Take this example: 


Bug in Windows Kernel Could Prevent Security Software From Identifying Malware




According to Microsoft, this isn't a bug, it's a design feature.   Sure we can argue that Microsoft is covering their asses, but the article actually stipulates Microsofts response.   So in my opinion, the article title should have been "Windows Kernel Design makes security software creators work for their money".... but that is far less catchy!

_______________________________________________

Eric Parent is a senior security expert, specialized in coaching senior executives.  He teaches CyberSecurity at l'Ecole Polytechnique and HEC Universities in Montreal, and is CEO of Logicnet/EVA-Technologies, one of Canada's oldest privately owned security companies.

Follow Eric on:
Twitter @ericparent
LinkedIn :  EVA-Technologies

www.eva-technologies.com


Sunday, May 14, 2017

The dangers of centralized authentication




EXECUTIVE SUMMARY:  If your Enterprise has many several different systems controlled through a centralized authentication mechanism (a single username and password) and you do not have multi-factor authentication (receiving an SMS for example)... you are more then likely exposed far more then you think.

---

I didn't want to name any of the "cool" marketing terms we keep hearing, like SSO, and Federated Identity Management solution.  These concepts are all great and bring a lot of value.  What if parts of this introduced behaviour that was much riskier then we all think?

Having a single username and password to access everything is nothing new.

What if it was a terrible idea ?

What if this "idea" was meant to be used a certain way, and we all ain't doing it.

I know.... ain't ain't a word, so how can this be true....

Read on....  because a client asked my opinion on something and my answer simply wasn't... "go ahead.... it's fine".  It came to mind that a lot of Enterprises are faced with this issue.

Awhile back, I did an intrusion test on a large brokerage firm that I happened to be a client of.  The reason I tested it, was simple.... it smelt bad from the first welcome letter.

After compromising an administrator email account, I had access to everything.

When I contacted this company to explain to them that they had a major security flaw, the CEO and CIO did what they do best in traded companies... they ignored me.  

I had to light a few fires to get them to assign some poor soul to call me back.

NOTE:  Now lets be clear, I do not hack companies and then call them.  In this case, I was the client, and I suspected many things smelt bad so I did my due diligence and hired a professional to test them out.  The professional happened to be me.

When I finally talked to someone, they told me that under no circumstances had client data been exposed, that this was simply a breach of the company email system.

To this I replied as follows:

1) First off, your administrator had your websites new web certificate in his email including the private keys.  He must have emailed it to himself to then retrieve and install on your servers.  So you no longer have any security on your "transaction" servers which do host very sensitive information.

2) The administrator credentials I now have in my possession have the following characteristics which you might find of interest:


  • This is an Active Directory admin account
  • Your enterprise VPN is integrated into Active Directory
  • Your Citrix remote access which is Internet facing is integrated into Active Directory.
I then paused for effect and waited to see if the lights where on or if I was talking to myself.....  after a longer pause then I was willing to wait for I asked "do you understand what that means", then the reply was both funny and frightening at the same time.  "Why is that a big deal".

After a quick deep breath, I explained that since all their key technologies are plugged into A/D to validate usernames and passwords, that once an account is compromised on one application (in this case the email system), that the attacker can now use this account to access everything else that user has access to.....

So why does that effect most companies?

A simple list of reasons really.  Simplicity & ease of access.

Add to that lack of budget for good form.

Everyone wants easy access to email.

Your company probably has webmail services.

Or minimally you can access your emails from your smart phone or tablet.

This means that an employee can use an insecure device (such as their own virus infested home computer, or better yet, an Internet Cafe or Hotel computer) and access corporate email.

This means that this users username and password could be captured by someone with malicious intent through several of these opportunities.

The reflex is always to think that "It's only email". 

First off, after hundreds of investigations over the years, it is NEVER just emails.  Emails alone expose a list of concerns as long as the pills Donald Trump should be taking.

But in so many instances it exposes the rest of the company through remote access connections or even web based applications that are available from the Internet from anywhere in the world, perhaps using the same username and password because it is all integrated within a centralized authentication system. 

So we covered simplicity and ease of use.... what about budget?

The bottom line is that centralizing is indeed a good idea.  Since it allows you to have more control.

The problem is we are not putting in place "more" control to the level that we need.

Think back, hundreds of years ago.  You put your money at the bank because it was safer.  You put your houses deed in a safety deposit box, because anyone with the papers essentially owns your house.  You did this because the bank has controls that are safer then underneath your mattress.  A simple example:  safety deposit boxes require two keys and the role of the bank key is to vet that you are on the authorized access list.

So what about our username and password to access our sensitive corporate systems ?  Where is the added security as we centralize all our applications into one pot of gold ?

Two factor authentication (also called strong authentication) is the missing link.   Centralizing is fine IF you have strong authentication.

Without it, enterprises must realize that if they allow risky behaviour on some systems, this could allow access to more critical systems and assets... 

So to summarize, if you have multiple systems and applications pulling authentication from A/D and also have web based systems (such as email or business portals, etc.) and any of your staff can access this from anywhere in the world....  you should be greatly concerned because without two-factor authentication it is just a matter of time before this attack vector becomes your Saturday morning discussion.

---

Actually, now that I think about it, budget isn't really the issue.  I think senior managers might be.  I recall numerous times when senior management refused to do things the "secure way" because they find it unconformable.   I don't want my workstation to lock me out when I don't use it for hours, this irks me.  Fix it because I'm the boss.

This kind of attitude is what often bits companies in the ass.

Since when is letting someone decide who does not have the competence to make these decisions.   

Oh wait.... that happens a lot doesn't it.

Food for thought.


_______________________________________________

Eric Parent is a senior security expert, specialized in coaching senior executives.  He teaches CyberSecurity at l'Ecole Polytechnique and HEC University in Montreal, and is CEO of Logicnet/EVA-Technologies, one of Canada's oldest privately owned security companies.

Follow Eric on:
Twitter @ericparent
LinkedIn :  EVA-Technologies
www.eva-technologies.com


Tuesday, March 1, 2016

Are we sharing too much, and who is sharing it on our behalf !



If you haven't heard of TAKE THIS LOLLYPOP it is worth your time. A great educational experience.


http://www.takethislollipop.com



It is an interactive film which accesses the viewer's Facebook profile and locates the viewer's home from data in their profile. It depicts the dangers in posting too much personal information on the Internet. 

Information gathered is then deleted which makes the film different for each viewer.... and safe....

it is an eye opener for both techies and non techies and it is extremely well done.

Perhaps if everyone realized that not everyone on the Internet or in this case social media is your friend, information would be disclosed far less openly.

The more open and full your Facebook profile is, the more the film will hit home and make you think.

Come on Sandra you don't really have 1700 friends whom you trust with your personal information do you ?????
(reference to one of my Facebook friends, her name replaced to protect the innocent)

Now this applies to corporations also, after all, if your enterprises password retrieval security questions rely on voluntarily leaked information such as hometown, birthdate, or favourite sports team, then you're exposed and chances are.... you don't realize it.

That is the thing with security (or insecurity), a malicious person will take the time to navigate the search engines and find all sorts of tidbits of information that can be accumulated to perform more intrusive social engineering attacks.

As a manager or senior executive, shouldn't you KNOW what information can be gathered or derived from your employees ?   I certainly think so.

There are tools out there, like Harvester.py which is a simply python script to dig through Google, Bing, LinkedIn and gather email addresses that have been leaked (published voluntarily). 

Other interesting ones include:
PunkSpider which indexes web pages with identified vulnerabilities
Shodan.io which lists IoT (Internet of Things) devices found on the Internet
Censys.io which does something similar...

Are you listed in any of these ?   Is the information you uncover a surprise....

99.9% of enterprises have no idea what information about them is out there.  A determined attacker will find more then enough information then is required to breach your enterprise security.

A good example is this article about a journalist who challenged (as in asked for) a group of hackers to violate his digital world at Defcon23.  

This is him, amazed at what a social engineer is getting out of his own cell phone provider.  



A video and article worth taking a look at.

http://fusion.net/video/271750/real-future-episode-8-hack-attack/

There are privately developed tools that make use of multiple sources to look for meaning and collisions and help float to the top the most important elements.   My own company has a toolset that does just that, and so far, we have had a blast identifying leaks in seemingly prestigious and "secure" companies.


Now here is an idea.... we need an interactive TAKE THIS LOLLYPOP movie that targets enterprises.....  That sounds like a great summer time project.

Any takers ?

Call me !



_______________________________________________

Eric Parent is a senior security expert, specialized in coaching senior executives.  He teaches CyberSecurity at l'Ecole Polytechnique and HEC University in Montreal, and is CEO of Logicnet/EVA-Technologies, one of Canada's oldest privately owned security companies.

Follow Eric on:
Twitter @ericparent
LinkedIn :  EVA-Technologies
www.eva-technologies.com







Friday, February 19, 2016

How disconnected are the cerebellums of the CIA and FBI?

The last few weeks have been significantly active in the security world, constantly providing sitcom writers material to last a decade.  And.... I'm not even going to talk about Donald Trump.  

The FBI is sending out court orders to get Apple to put in back doors in an iPhone....

Hillary Clinton is being investigated by the FBI for her "sensitive email" issue....

And the FBI arrests a teenager for hacking into senior CIA & FBI officials emails....

Lets take a quick look at these events, and lets all realize how much we are being taken for fools.



First off, the FBI does not need Apple to get into the insides of an iPhone.  John McAffee is even offering to do it for free.  Thanks John.  In fact, I will offer to do it for free too, great publicity.  

No worries since the FBI will not let anyone try to get into that iPhone.  This case is about the government putting in place the mechanisms for killing privacy in general.  So don't be fooled by their request looking all normal because they need Apple to get into a terrorists phone.  Whatever Apple could do, the United States Government can do, or get done.

But lets take a look at the MAJOR security issue around the Hillary Clinton and CIA/FBI email scandal.

Certainly we should be concerned that a senior government official who is representing "the people" and is supposed to be smart would expose sensitive information on her personal email system.

However, something much worst is not being discussed by the media.

How can someone, anyone, take top secret documents from a high security ecosystem and bring it into a less secure ecosystem (like Hillary's email server).

Someone should be getting fired, and charged with some form of criminal negligence.

But WAIT !   It gets worst.

This week, HackerNews reported that a 16 year old hacker was arrested for breaking into emails of both the CIA and the FBI.

Take a look at these details (taken from the article):

What the hell is going on at the CIA and the FBI ????  Do they not have any security policies or "RULES" ?   Can anyone just do anything over there ?

Well, rest assured, if a normal person working at the CIA or FBI did anything this stupid, they would face the full power of the US government (sorry Snowden).  Yet in this case, just like Hillary, it will be a joke.

What am I referencing exactly...  Senior staff using PERSONAL EMAIL SYSTEMS (like AOL) to handle sensitive data.

These clowns are the real problem.   They knowingly allowed sensitive information to transit through insecure systems therefor violating the agencies CLEARLY DEFINED POLICIES.

Strangely, John Brennan, James Clapper and Mark Giuliano are not being charged, and have not been arrested...

Yet a 16 year old is being arrested.

Doing enterprise security assessments is often accompanied by attitudes that ressemble this.  

What people to not understand is that the security risk is coming from these individuals, not the 16 year old.

In fact, strange enough, the 16 year old exposed the issue, brought it to light, and showed no strategy for making use of the information collected aside from foolishly publishing it.

Who is to say that someone truly malicious had not been reading these imbeciles emails for months or years ?

The 16 year old went out and published what he found and got caught.

The spies who are taking actions on US soil do not publish their findings for the world to see.  They gather the intelligence and take well educated actions.

Like corporate America, these senior executives are the weakest link, and will significantly and negatively impact security.

So when the FBI is done roasting the 16 year old, I hope they get their heads out of their asses and have the common sense to take legal action against their own clowns.

In the security industry, we call that the ROOT CAUSE.

You can't fix stupid, but you can fire stupid.


_______________________________________________

Eric Parent is a senior security expert, specialized in coaching senior executives.  He teaches CyberSecurity at l'Ecole Polytechnique and HEC University in Montreal, and is CEO of Logicnet/EVA-Technologies, one of Canada's oldest privately owned security companies.

Follow Eric on:
Twitter @ericparent
LinkedIn :  EVA-Technologies

www.eva-technologies.com


What if the lowest bidder is always the most expensive option.

Reflection:   Perhaps we should start looking at the highest bidder and figure out what the lowest bidder isn't including.... In Quebec,...