Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Saturday, April 27, 2013

Living Social Hack and AP Twitter Account Hacked


The website, LivingSocial, a daily deals site, was hacked late yesterday.  The original report came from AllThingsD.com, and includes the text of an e-mail the CEO sent to staff and now the public. No credit card data or merchant financial information was accessed, which must mean that they stored them on a separate server.  The cyberattack affected 50 million users (all users except those in Korea, Thailand, Indonesia and the Phillipines, which use different services with separate servers).  The attackers netted millions of user names, birthdates, e-mail and passwords.

The website now greets users with an announcement of the attack, and recommendation that users change their passwords.  The announcement notes that passwords are coded, and the CEO's e-mail says they have been "hashed and salted."  This mean they use an algorithm to code, or "hash" the passwords. Salting means that each user who uses the same password would have their password "hashed" into a different coded version.  However, those with passwords which are too easy may make it easy for the hackers to guess, since the hashing algorithm is known.  Hackers can use an online dictionary and a computer to try to guess multiple passwords in just a few seconds.  But because multiple passwords set to "password" would each have a different hashed version, the hackers will have to devote considerably more time to cracking passwords.

CNN Money Tech reports that a different cyberattack on the Twitter account of the Associated Press.  The hackers in that case planted a false report that President Obama had been injured in two explosions at the White House.   AP suspended their Twitter account, with an announcement that the report was false. However, the attack shows up security weaknesses with Twitter, which had been discussed for some time by security analysts with concern.  Apparently, unlike Facebook and Dropbox, among other sites which offer the option, Twitter does not yet require a "two-step authentication" process.

A two-step authentication, done properly, requires a combination of two out of three types of information:
1.  Who you are (physical ID for instance, or fingerprint scan or facial recognition now on many laptops)
2. What you have (a gadget that generates a code, or a one-time password provided in a list by the website for users, for instance),
3.  What you know (passwords, mother's maiden name for a security question, for example)

For instance, a good two-step authentication procedure might require not only your password, but also an individually created key, which might be stored only on a user's phone. The user sends the secret key along with their password.  A lower tech alternative to the gadget code is the list of passwords provided separately to users. A user would input one of the codes and mark it off the list.  When a user runs low on the number of provided by the website, they request a new list.  As long as the two items are received within a short time (approximately 30 seconds), the system will accept the combination log-in.  The CNN article notes that Twitter had advertised for engineers to develop a two-step security process, but apparently this has not yet been implemented.

Another hack previously compromised Fox News' Twitter account. In that case, the hacked tweet was that President Obama had been assassinated. The recent fake tweet actually caused a brief downturn in the stockmarket. According to the CNN report,  Twitter's response to these and various other hacks on corporate Twitter accounts has been to urge more care.  What they need is to implement better security.

The decoration for this post is from Wikipedia, which notes it was designed in the late 1990's by Dagmar D'Surreal, as a logo for the PhreakNIC annual conference in Nashville, Tennessee. Many thanks to my son, Joe McKenzie, for technical explanations made easy.

Wednesday, July 13, 2011

Could Your Cellphone Voice Mail be Hacked?


We are all watching the scandal about the British tabloid News of the World whose reporter hacked into the cellphone voice mail of a missing girl and deleted some of the messages while police were searching for the child. But have you considered the implications of hacking voice mail in cellphones? It means that it's dead easy to get into anybody's voice mail – unless they take a few precautions.

The Boston Globe has an article in today's paper by Hiawatha Bray, one of my tech heroes. The hack is done with a service anybody can find, called ID spoofing. Google it. It works like a pre-paid calling card or sometimes through a Web interface. You pay for a certain amount of time to have a PIN that represents to the telephone you are calling that you are calling from a different telephone number.

Spoofing can be used for legitimate purposes, as law enforcement sometimes uses it, or women fleeing from abusive situations have used this to conceal their location and phone number. But mostly, it is considered a malicious act, and bills have been introduced several times to outlaw the practice, beginning in 2006. Finally, in December, 2010, the Truth in Calling Actpassed Congress and was signed into law by President Obama, prohibiting spoofing “with the intent to defraud, cause harm, or wrongfully obtain anything of value...” Law enforcement is specifically exempted. The penalties are fines, and enforcement is under state jurisdiction.

But the important part of the Globe article is to explain how to protect yourself from having your voice mail hacked. Here is the information: Protect your voice mail

The image is courtesy of Entrepreneur website, which actually has a very helpful post about protecting your cellphone, adding a paragraph about the viruses that are becoming so rampant in a lot of the apps that people are adding outside of the official sites. See http://www.entrepreneur.com/blog/219961

Monday, December 20, 2010

Defending Against Hacker Attacks


Another interesting article in the Boston Globe, by the wonderful Hiawatha Bray, about companies whose business is defending against distributed denial of service attacks, as well as other internet attacks. Denial of Service attacks (DDS attacks) essentially seek to overwhelm the victim's resources by sending so many requests simultaneously that the victim's computers cannot respond to legitimate requests, and crash, or simply slow too much to be useful. The attacker assembles a zombie like army called a botnet by sending a code to random computers via e-mail attachments or a computer worm. The botnet computers then work together to send out the DDS attack in a coordinated way. The owners of the botnet computers may never know their computers were involved. OOTJ readers probably remember when Google publicized its attack by hackers from the People's Republic of China. Twitter and Facebook have also been attacked, and as former supporters of Wikileaks have withdrawn financial support, they are facing similar attacks from outraged Wikileak friends.

The article in the Globe seriously (and perhaps intentionally) oversimplifies the matter of defending against DDOS attacks. The primary defense appears to be providing a large enough number of alternative servers to soak up the attacks. Quoting from the article:

Akamai relied on the simplest defense: a network of servers and data lines with such huge capacity that it can’t be overwhelmed by such an attack.

“If your pipe is bigger than their pipe, you win,’’ said Bruce Schneier, chief security technology officer at the British telecom giant BT Group.

The biggest DDOS attack ever to hit an Akamai customer occurred on July 4, 2009, when several US government sites were attacked by a botnet based in South Korea. But that attack generated a stream of data equal to just 4 percent of Akamai’s average daily traffic load, and was easily absorbed.

The data traffic aimed at the five Internet retailers equaled less than half of 1 percent of Akamai’s daily load and was barely noticed.

Akamai’s robust network may have also helped protect Internet retailer Amazon.com from online vandalism.

A group calling itself Anonymous posted Twitter messages that took credit for bringing down the Visa and MasterCard sites, saying the attacks were revenge for the credit card companies’ refusal to do business with the website WikiLeaks, which had published secret US government documents.

Anonymous said that Amazon, which had also cut ties to WikiLeaks, would be the next target. But within hours, Anonymous dropped the idea, posting that “The Hive isn’t big enough to attack Amazon.’’
It could be that this is the current state of the art. Just six years ago, a lengthy article by Cisco presented the difficulties in defending against DDOS attacks in 7 Internet Protocol Journal 4 with many more defense options. But six years is an eon in this field. Akamai's website does actually talk about more than offering a wider pipe. And other DDoS protection firms detail other security measures they offer as well: BlockDOS mentions adaptive filtering, deep packet inspection and flexible content filtering among several other types of filtering as methods of protecting clients servers from attack. Arbor Networks, another DDoS protection firm mentioned in the Globe article also lists a variety of security services beyond enlarging the "pipe:" protecting DNS architecture (I wish Comcast would sign up with them!), leverage IP flow for peak network visibility (I think they mean making the most of the available hardware), and more.

It's becoming a new industry to protect against the attacks. We already have security services for our computers like anti-virus providers McAfee or Symantec and hosts of others. Now there is a burgeoning industry for professional protection against DDoS attacks and more -- theft of information from the databanks, for instance, and other nightmares. It won't be long before universities become clients of these firms. The interesting thing is that the folks who developed the protections often haled originally from the ranks of the hackers who developed the problems. It takes a hacker to catch a hacker. Though hacker is a mutable term -- ignorant outsiders often misunderstand the term. Hackers are not necessarily troublemakers. Black hats and white hats are better distinguishing terms. Which is why I am decorating this post with those images.