Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Tuesday, May 06, 2014

Hiawatha Bray on Computer Security in the Wake of Heartbleed


I keep meaning to post about an excellent column by the Boston Globe technology columnist, Hiawatha Bray on May 1. "After Heartbleed, Change the Locks," is partly a sympathetic note to all of us who are tearing our hair out, or maybe just apathetically groaning, at the news that we must change all of our passwords because of this new security breach!! But it also is a much more useful, step-by-step explanation of different levels of security. In part, Bray discusses why passwords are just NOT doing it for us as security.

But passwords are pretty much what most of us are stuck with. Most of us don't yet have fingerprint or iris scan technology. So,... Bray explains that the best way to deal with passwords is two-factor authentication. Actually, Bray's explanation is not the clearest. What his column does very nicely is scan the current state of security options, and review them. Very nice and handy!

Two-factor authentication typically requires something you know (i.e., a password) PLUS something you own (for instance an ATM card or cell phone. That way, even if a clever hacker figures out or steals your password, it is exceedingly unlikely that they will also have your cell phone or ATM card. (Here is a link to Google's set up two-step authentication link for Android Phones, as an example) and a general Google Two-Step explanation. This Lifehacker post includes a long list of links for a number of social networks and other services that now offer two-factor authentication.

Two-step can work with another combination, as well, such as a printed list of codes. You use each code once, and mark it off each time you use it. Those codes are used in combination with your password, so again, it is a combination of something you KNOW and something you HAVE. So long as you keep the thing you KNOW (password, computer with passwords saved as cookies, or PIN) separate from the thing you HAVE (phone, ATM card, list of codes), this is a very secure way to access online data. So, for instance, don't copy your PIN number on your ATM card!

I previously posted about two-step authentication here before. See....

Wednesday, February 06, 2013

P.S., Aaron Swartz

Readers will recall Aaron Swartz's suicide, in apparent reaction to his ongoing prosecution for downloading huge numbers of files from JStor illegally at MIT.  Swartz was an Internet activist who downloaded the files, not for personal gain, but as a stunt to draw attention to his argument that the articles and materials in the files had already been paid for by the universities, in that their faculty created the materials.  He felt that the materials should not be behind pay walls.  But after the prosecution began, Swartz returned the files and JStor dropped civil charges.  MIT to ask the prosecutors to press criminal charges, and the federal prosecutors in Boston did so with great creativity and effort.  Swartz originally faced 4 charges, but finally had 13 felony charges against him, up to 35 years in prison and a million dollars in fines.  The extra charges were derived by creating a separate charge for each date.  Many of the charges were not simply based on violation of copyright, but were under the Computer Fraud and Abuse Act, 18 USC § 1030 (CFAA).

The CFAA is extremely broad, and allows great latitude to prosecutors. Through the original law and amendments since, it essentially prohibits both the acts and attempts of seven offenses:


1. obtaining national security information,

2. compromising confidentiality,

3. trespassing in a government computer,

4. accessing to defraud and obtain value,

5. damaging a computer or information,

6. trafficking in passwords, and

7. threatening to damage a computer.


The House Committee on Oversight and Government Reform is holding a hearing, asking the prosecutors for more information on this prosecution. Here is a link to the letter the Committee has sent to Attorney General Eric Holder requesting more information on the decisions made by the prosecutors in the case. Among other questions, the Committee asks why they made a superseding indictment adding the extra felony counts. The Committee asks whether Swartz's opposition to SOPA or other activism was a factor in the decisions in the case.

Shortly before the Committee issued this request, a Boston Globe columnist, Kevin Cullen, wrote a column about a similar case in Boston 19 years ago, where the same prosecutor, Steve Heymann, brought charges against an MIT student, David LaMacchia, for similar computer hacking. LaMacchia had downloaded $1 million worth of software which he posted to a bulletinboard for anyone to download and use. In that case, however, federal District Judge Richard Stearns dismissed the case just before it went to trial. Judge Stearns ruled: "One might at best describe his actions as heedlessly irresponsible, and at worst as nihilistic, self-indulgent, and lacking in any fundamental sense of values." With that stern dressing-down, the judge sent the sophomore LaMacchia back to his dorm, probably embarrassed, but with his life and future intact. The Globe columnist tells his readers that LaMacchia had contacted Aaron Swartz with an offer to talk when he heard about the prosecution. Swartz never called him back.

It is sad that the judge in Swartz's case did not feel he or she could dismiss the matter. It is also sad that Swartz did not, for whatever reason, feel he could or wanted to, reach out to LaMacchia. I am very grateful that the House Committee is asking some hard questions about the prosecutors' decisions in the Swartz case. And I am also glad that the community is continuing to pressure all those who felt that this case needed to be made into an example. It has been appalling to watch the copyright-holding community make examples of little people time and again in their efforts to secure rights that they feel slipping in an electronic world. We need to keep some sense of proportion, and perhaps this case is the one that will be a wake up call. How sad.

The image is an often-reproduced photo of Aaron Swartz that appeared in the Globe.

Monday, December 20, 2010

Defending Against Hacker Attacks


Another interesting article in the Boston Globe, by the wonderful Hiawatha Bray, about companies whose business is defending against distributed denial of service attacks, as well as other internet attacks. Denial of Service attacks (DDS attacks) essentially seek to overwhelm the victim's resources by sending so many requests simultaneously that the victim's computers cannot respond to legitimate requests, and crash, or simply slow too much to be useful. The attacker assembles a zombie like army called a botnet by sending a code to random computers via e-mail attachments or a computer worm. The botnet computers then work together to send out the DDS attack in a coordinated way. The owners of the botnet computers may never know their computers were involved. OOTJ readers probably remember when Google publicized its attack by hackers from the People's Republic of China. Twitter and Facebook have also been attacked, and as former supporters of Wikileaks have withdrawn financial support, they are facing similar attacks from outraged Wikileak friends.

The article in the Globe seriously (and perhaps intentionally) oversimplifies the matter of defending against DDOS attacks. The primary defense appears to be providing a large enough number of alternative servers to soak up the attacks. Quoting from the article:

Akamai relied on the simplest defense: a network of servers and data lines with such huge capacity that it can’t be overwhelmed by such an attack.

“If your pipe is bigger than their pipe, you win,’’ said Bruce Schneier, chief security technology officer at the British telecom giant BT Group.

The biggest DDOS attack ever to hit an Akamai customer occurred on July 4, 2009, when several US government sites were attacked by a botnet based in South Korea. But that attack generated a stream of data equal to just 4 percent of Akamai’s average daily traffic load, and was easily absorbed.

The data traffic aimed at the five Internet retailers equaled less than half of 1 percent of Akamai’s daily load and was barely noticed.

Akamai’s robust network may have also helped protect Internet retailer Amazon.com from online vandalism.

A group calling itself Anonymous posted Twitter messages that took credit for bringing down the Visa and MasterCard sites, saying the attacks were revenge for the credit card companies’ refusal to do business with the website WikiLeaks, which had published secret US government documents.

Anonymous said that Amazon, which had also cut ties to WikiLeaks, would be the next target. But within hours, Anonymous dropped the idea, posting that “The Hive isn’t big enough to attack Amazon.’’
It could be that this is the current state of the art. Just six years ago, a lengthy article by Cisco presented the difficulties in defending against DDOS attacks in 7 Internet Protocol Journal 4 with many more defense options. But six years is an eon in this field. Akamai's website does actually talk about more than offering a wider pipe. And other DDoS protection firms detail other security measures they offer as well: BlockDOS mentions adaptive filtering, deep packet inspection and flexible content filtering among several other types of filtering as methods of protecting clients servers from attack. Arbor Networks, another DDoS protection firm mentioned in the Globe article also lists a variety of security services beyond enlarging the "pipe:" protecting DNS architecture (I wish Comcast would sign up with them!), leverage IP flow for peak network visibility (I think they mean making the most of the available hardware), and more.

It's becoming a new industry to protect against the attacks. We already have security services for our computers like anti-virus providers McAfee or Symantec and hosts of others. Now there is a burgeoning industry for professional protection against DDoS attacks and more -- theft of information from the databanks, for instance, and other nightmares. It won't be long before universities become clients of these firms. The interesting thing is that the folks who developed the protections often haled originally from the ranks of the hackers who developed the problems. It takes a hacker to catch a hacker. Though hacker is a mutable term -- ignorant outsiders often misunderstand the term. Hackers are not necessarily troublemakers. Black hats and white hats are better distinguishing terms. Which is why I am decorating this post with those images.