Pages

Showing posts with label Heartbleed. Show all posts
Showing posts with label Heartbleed. Show all posts

Thursday, 24 April 2014

Tech titans join forces to stop the next Heartbleed

heartbleed-open-ssl-8447.jpg
A Heartbleed T-shirt show just how effective the Heartbleed campaign has been.Martin Mulazzani
In between hurriedly snapping 1,250 pieces of a Lego Millenium Falcon set together in time for his daughter's sixth birthday last Sunday, Jim Zemlin, executive director of the Linux Foundation, was just as frantically making calls to tech's biggest firms. The future of Internet security could be at stake.
Google, which he called first, said yes. Facebook said yes. Intel said yes. And by 11 p.m. in New York City last night, with Amazon Web Services and Rackspace on board, Zemlin had lined up a dozen companies and millions of dollars to support his latest project, the Core Infrastructure Initiative.
A new open source security evaluation group that the Linux Foundation announced on Thursday morning, the Initiative's founding members stretch from Silicon Valley around the world. In addition to the aforementioned companies, Microsoft, Cisco, Dell, Fujitsu, IBM, NetApp, and VMware have all signed on, and each will contribute $100,000 a year over the next three years to support the project and sit on its guiding board, although anyone can donate.
"I thought, Where did we go wrong?" Zemlin told CNET when asked to describe the origins of the Initiative. "There are numerous open source projects that are not in line with the same kind of support that supports Linux."Conceived of by Zemlin just over a week ago, the group is tasked with building a framework to permanently support the myriad of critical yet often under-funded open source projects that most of the Internet has come to rely on.
The first project that will receive funds from the Core Infrastructure Initiative is OpenSSL, which has dominated recent news because of its critical Heartbleed vulnerability.
OpenSSL is used by so many website owners and hardware makers that it has become the de facto spine of Internet encryption. Announced two weeks ago with a coordinated campaign to educate Internet users and tech firms about its severity, Heartbleed allowed an attacker to pluck critical personal data such as usernames, passwords, and credit card numbers out of ostensibly secure transmissions. Many but not all of the servers that deliver the most popular sites on the Web have been patched, but that doesn't include Internet-connected devices that use OpenSSL that could still be exposed.
Zemlin said that he expects the Core Infrastructure Initiative to financially support cryptographic experts who devote their time to open source code, the same way that the Linux Foundation was created to support Linux's creator Linus Torvalds so that he could work solely on the open source operating system.
The concept that 'more eyeballs make bugs more shallow' I don't think is wrong. The idea is that we want to facilitate faster idea sharing.
Jim Zemlin, director, Linux Foundation
That may not be the best analogy, as there have been kernel bugs in Linux for 20 years. Still, Zemlin was enthusiastic.
"The concept that 'more eyeballs make bugs more shallow' I don't think is wrong. The idea is that we want to facilitate faster idea sharing," he said, "This has been somewhat proven by the Linux model."
Professor Eben Moglen of Columbia Law School said in a statement that "[m]aintaining the health of the community projects that produce software critical to the security and safety of Internet commerce is in everyone's interest."
The founding director of the Software Freedom Law Center, Moglen said that the companies involved are ensuring that the Internet will "work safely for us all."
Chris DiBona, Google's director of engineering for open source and Zemlin's first contact for the project, said that once Zemlin contacted him, the only issue was figuring out whether DiBona or his boss, Google's vice president of security Eric Gross, would take ownership of Google's responsibilities. Where the $100,000 annual contribution would come from was almost an afterthought.
"It's slightly less than the cost of hiring an engineer ourselves," he said. Google's managing board didn't have to be consulted.
While a $1.2 million operating budget may not sound like much, and is tantamount to what one of the Initiative's founding companies might consider pocket change, Zemlin said that the point of the new group goes beyond dollars.
heartbleed-over-web-address-770w.png
CNET
"At least equally important, and I would posit more important, is that this forum will now exist," he said. "This is not a panacea, this will happen again," but despite the odds that there will be another bug as bad as or worse than Heartbleed, Zemlin hopes that the framework created by Initiative will lessen the risk.
"The initial, first baby steps [of the Initiative] is that it will find the people working on [Open]SSL who aren't spending their whole time on it, and get them to spend their whole time on it," DiBona said.
Once the framework in place and work on OpenSSL has begun, DiBona said that he'd like to see the organization tackle security in the "most popular and least developed" open source projects, including core system libraries and cryptography analysis tools. The project's advisory board, on which each contributing company gets a seat, will identify not only what to tackle next, but how to go about building the group in the first place. The organization is so new that it hasn't even met yet.
Zemlin said that none of the companies he contacted balked at participating, and that he expects the group to grow rapidly as word spreads. Firms like Apple and Adobe were missing from the list of founders, he said, for two reasons: He didn't know anybody to reach out to at those companies, and he had to juggle making the phone calls with his daughter's birthday.
A fear of this initiative is that sometimes the presence of any solution will take the heat off, that it could remove some urgency simply because it's something that needs to be done.
Josh Corman, chief technology officer, Sonatype
Josh Corman, the former director of security intelligence at Akamai and current chief technology officer at security firm Sonatype, applauded the creation of the Initiative but said that some parts of it concerned him.
"A fear of this initiative is that sometimes the presence of any solution will take the heat off, that it could remove some urgency simply because it's something that needs to be done," as opposed to being the best solution, he said. "But if it creates some adult recognition of our dependence on open source, that could be great."
Also of concern, he said, is the as-yet unknown methodology by which the group's board chooses which projects to prioritize, and how to address the thornier problems facing open source security, such as updating Internet-connected devices.
DiBona conceded that it's impossible to patch all the vulnerable devices and websites running OpenSSL.
"There's always going to be some level of vulnerable device out there," he said. "I'm not as worried about it, because manufacturers shut off features they don't actually use to save space [memory.] The hope would be that devices that don't get patched get retired by their owners."
Zemlin acknowledged that the unsettled nature of the project is also likely to early cause concern among security experts.
The mechanisms by which the group makes decisions "should be able to have management meet the hackers, and help the hackers on the hackers terms," Zemlin said. "That's meaningful, that's a change. We'd like to help."
While the Core Infrastructure Initiative is barely out of the womb, Zemlin has high hopes for its impact during its first year.
"It's not a panacea, not going to prevent all problems, but it's going to play an important role in preventing essentially a market failure. If we could play a small role in solving that problem, I'd be incredibly gratified," he said.

Thursday, 17 April 2014

First Heartbleed attack reported; taxpayer data stolen

large-hero-heartbleed.jpg
Codenomicon/CNET
The Heartbleed bug has caused widespread anxiety, sent engineers scrambling into patch-mode, and likely prompted millions of users to re-invent their passwords, but so far there have been no accounts of attacks leveraging the bug... until now.
In the first known report of an attack using the security flaw, Canadian police have arrested a man who allegedly used Heartbleed to steal user data from the government's tax Web site, according to Reuters.
Authorities discovered earlier this week that the Canada Revenue Agency (CRA) site was hacked into over a six-hour period and the Heartbleed vulnerability was exploited to nab roughly 900 social insurance numbers and possibly other information from Canadian taxpayers.
"The CRA worked around the clock to implement a 'patch' for the bug, vigorously test all systems to ensure they were safe and secure, and re-launch our online services," said CRA commissioner Andrew Treusch in a statement. "The CRA is one of many organizations that was vulnerable to Heartbleed, despite our robust controls."

Police arrested Stephen Solis-Reyes, 19, in London, Ontario, on Wednesday and seized his computer equipment. He is allegedly associated with the attack, according to Reuters, and faces criminal charges of unauthorized use of computer and mischief in relation to data.

"It is believed that Solis-Reyes was able to extract private information held by CRA by exploiting the vulnerability known as the Heartbleed bug," the Royal Canadian Mounted Police said, according to Reuters.
News of the massive Heartbleed bug reverberated across the Internet last week showing how easily people's online data could be accessed. This particularly nasty vulnerability -- which has the capability to potentially extract people's usernames, passwords, and credit card information -- is said to have affected up to 500,000 Web sites, including Google, Facebook, Yahoo, and many more.
While the hack into the CRA appears to be the first reported attack with Heartbleed, it likely won't be the last.
Solis-Reyes is scheduled to appear in court on July 17.

Wednesday, 16 April 2014

Beyond Heartbleed: Why you need a password manager

roboform-toolbar.jpg
The RoboForm toolbar.Screenshot by Lance Whitney/CNET
RoboForm, LastPass, and other password managers would not have defended your individual passwords from the Heartbleed bug. But they make the cleanup process a whole lot easier.
Revealed last week, Heartbleed is a flaw discovered in certain versions of OpenSSL, open-source software that uses SSL (Secure Sockets Layers) to encrypt and protect your private information as it connects from one place to another across the Internet. CNET offers an FAQ with more details about the Heartbleed flaw and advice on how to protect yourself from the bug.
How do you know if one of your password-protected sites is vulnerable? Heartbleed checkers fromLastPass and Qualys let you type a specific Web site to see if it is currently affected by the bug. CNET also compiled a list of top sites across the Web and checked to see if the Heartbleed bug was patched. Many Web sites, even those that have patched the hole, have urged their users to change their passwords, at least to be on the safe side.
But assuming you have accounts at multiple Web sites potentially affected by the flaw, is there an easy way to change them all? Well, that's where a password manager would come in handy.
No, password managers by themselves would not have protected your passwords from Heartbleed. But they can take you exactly where you need to go to change those passwords.OK, what exactly is a password manager? Programs likeRoboForm and LastPass perform a few tasks to take the pain out of juggling all of your passwords. They can generate complex passwords that are hard to crack. They can automatically fill in those passwords at all your Web sites so you don't have to remember or write them down. And they maintain a list of all your password-protected Web sites.
I'm now changing passwords on several Web sites with help from RoboForm. To do that, I simply open RoboForm's list of my accounts and aim it toward a particular Web site. RoboForms automatically logs me in by entering my current username and password. I then use the site's own process to change my password. After changing the password, RoboForm automatically stores the new password.
Without RoboForm, the job of tracking down all of my Web site accounts and passwords would be a major headache and even more of a time suck.
Okay, but password managers typically store your log-in information online. Isn't that risky? And weren't their own sites vulnerable to Heartbleed?
In a blog written last week, RoboForm said that its site was not affected by the Heartbleed flaw as it used a different version of SSL than the one susceptible to the bug. Bill Carey, marketing vice president for Siber Systems, which sells RoboForm, told CNET that the site has since updated its OpenSSL software to version 1.0.1g, which rolled out last week with a fix for the Heartbleed bug.
In its own blog, LastPass acknowledged that it was "vulnerable" to Heartbleed since it ran the affected version of OpenSSL. But it said that it employs extra layers of security to encrypt data before that data is even transmitted using SSL. LastPass also uses a feature known as "perfect forward secrecy," which changes security keys so that past and future traffic can't be decrypted even if a particular security key is obtained.
password.jpg
CNET
Aside from Heartbleed, should users of password managers be concerned about entrusting all of their log-in information to one single product?
"I think it's a 100 percent valid concern," Carey said, "and quite frankly if I didn't work here, I'd have the same concerns. It's valid for that to be everyone's No. 1 concern because you're giving up a lot of personal information that, if misused, potentially could be dangerous to people."
In response, Carey outlined two measures that RoboForm takes to secure your data.
First, any data stored and transmitted online is encrypted. The information is also housed on servers protected by passwords and firewalls.
Second, products such as RoboForm and LastPass urge users to create a master password to encrypt and protect all of their log-in information. That master password is stored locally and is known only to you. Even if your log-in data were compromised over the Internet, no one should be able to uncover your actual credentials without that master password.
Of course, users need to ensure that the master password itself is complex enough to resist hacking. But remembering one complex password is certainly easier than trying to remember dozens of them.
RoboForm also offers a Desktop version of its software that does not store your log-in credentials online and keeps them local to your computer.
In an online world where we juggle numerous Web site accounts in the face of security hazards, there is no perfect way to manage your security. But password managers can make the process a lot easier, especially in the wake of a major security bug like Heartbleed.

Friday, 11 April 2014

Heartbleed coder admits 'oversight' but backs open source

large-hero-heartbleed.jpg
Heartbleed is a major vulnerability across the Internet.Codenomicon
We've all woken up on New Year's Day regretting what happened the night before, but this puts things in perspective: the man who accidentally introduced the Heartbleed bug to the Web did so on New Year's Eve.
Heartbleed is the name given to a vulnerability in the OpenSSL underpinning large sections of the Web, which potentially exposes passwords and other data from various sites. The code that contains the bug was written by programmer Robin Seggelmann, who admits he "missed the necessary validation by an oversight."
The problem is that hackers can tell their computer to lie about how much data is in the original packet, which causes the server to pad out the packet with data pulled from its memory before sending it back.
Seggelmann submitted the code at 11:59pm on New Year's Eve 2011, but claims the timing had nothing to do with the mistake. Although the bug was also missed by the review process for OpenSSL, an open source project written and reviewed by volunteers, Seggelmann told British newspaper The Guardianthat the bug's eventual discovery shows the value of publically available open source code.
The vulnerability was spotted this week by researchers at Google and Codenomicon, and has seen tech companies and websites scrambling to close the loophole before anything bad happens -- find out here which sites have protected themselves against Heartbleed.

Thursday, 10 April 2014

The Heartbleed Hit List: The Passwords You Need to Change Right Now


A look at which companies have issued a security patch to fix the Heartbleed bug.
http://mashable.com/2014/04/09/heartbleed-bug-websites-affected/?utm_cid=mash-com-g+-main-link