<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title>Happy Valentine s DayStay  Happy </title><description>2010-02-14 15:41:31 - Roer.com   Information Security blog   The Roer Group Information Security Blog :     IMAGE  Valentine s Day is back and so are the malwares and viruses  Attackers would have tried by now to add you as friends on Facebook and other social networking sites and would have obtained your email addresses from there  if you add just about anyone on such sites without thinking twice  Once they get your email id they would sent you a cute card laced with virus Once you open the card mail you get infected instead of love  No doubt you will receive many emails today expressing love for you today but be cautious of viruses around A few tips that may help    Keep your security software  antivirus, anti-spyware  updated   DO NOT click on mails which are too good to be true   DO NOT open a greeting asking you to install software to view it   DO NOT click on links in emails, rather copy the link and paste it in the browser   DO NOT open attachments which ask you to RUN them   DO NOT use cyber cafes for Internet Banking   Keep strong passwords and change them quite often   DO NOT add friends on social networking sites unless you know them  well the point is keep your information secure and away from attackers  Stay safe and spread Love  D </description><link>http://www.secuobs.com/revue/news/191786.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/191786.shtml</guid></item>
<item><title>News  768 bit RSA bites the dust What next </title><description>Secuobs.com : 2010-02-14 13:36:28 - Roer.com   Information Security blog   The Roer Group Information Security Blog -     IMAGE  As computing becomes more and more fast, the encryption speed is increasing and the RSA keys are being broken Modern cryptography or rather RSA relies on the fact that it is highly improbable to factorise a product of two large prime numbers The entire strength of the system relies on these two primes, if someone comes up with a way to factorise these numbers, RSA will be redundant forever  An academic research team has announced that the 768 bit RSA has been broken way back in December 2009 The team also stressed on the fact the effort involved was relatively low   that the 1024 bit RSA key even though being 1000 times stronger should be phased out in next 2-3 years Also, it has been said that 768 bit RSA should no longer be used Summing it up,  The overall effort is sufficiently low that even for short-term protection of data of little value, 768-bit RSA moduli can no longer be recommended  It is only a matter of time that 1024 bit key will be broken All one can say is that Cryptography Encryption is not the antidote to every security problem in the world With an organization being able to hire Cloud services, if such computing power is directed at breaking key s I wonder what will be secure ever  Unless encryption techniques are supplemented by other security services we can never have a sense of security for ourselves To read the paper go here To read more Click  img  wwwnotcotcom  </description><link>http://www.secuobs.com/revue/news/191775.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/191775.shtml</guid></item>
<item><title>Google Espionage  Same Egg s in a New Basket</title><description>Secuobs.com : 2010-02-06 19:32:19 - Roer.com   Information Security blog   The Roer Group Information Security Blog -     IMAGE  The recent incident at Google shook the entire world, but was it merely a one-off incident or a wake-up call  Did the event gather importance just because Google threatened to pull out of China or stop the so called censorship or was there something more sinister  I tried to explore a little Speaking of corporate espionage, it s nothing new to the developed world Nokia s so-called attempts to monitor its employees, Porche   VW case are not unknown in the 21st century There was another interesting case in 2005 where an employee allegedly transferred product information before he was supposed to switch to that start-up venture In 2007 Oracle suspected that SAP had been hacking and stealing secrets from its computer systems Oracle went to court with the case  In recent years the focus has shifted with countries realizing the power of internet It is alleged that corporate espionage has taken a step further with certain developing countries taking the short way out to success in trying to steal the important research papers, innovations, designs etc By any means investing a few millions on high-tech thieves is cheaper than investing billions in doing R D and not getting desired results  I guess this is what some countries think nowadays  As per FBI even though 75pourcents of cases of data theft involve an insider, as we all know our security is only as strong as our weakest link  Still the 25pourcents cases are not a small number to forget about It is in these 25pourcents cases do countries who want to spy, invest millions to find loopholes   steal data remotely Firstly it is safer to deny such an act and secondly it s much harder to prove such a crime s origin, if the attacker is sophisticated  cautious enough Yes Google did get hacked due to a flaw in the browser one of its biggest current competitors failed to fix since ages, but does Google end its responsibility here If my email gets hacked and all my bank account details get stolen, does all my responsibility go away  In my opinion NO, I am responsible for all my activities- from setting a password to saving important details on my mail In case of a breach, no doubt I should take legal recourse, but it should not be my primary objective Google should have detected such a breach as soon as it had occurred No one knows the exact monetary estimate of the hack   what all data was lost I think there is another side of the coin as well, than just Google crying foul over being broken into After all Google always knew beforehand what it was treading into once it accepted all regulations that Chinese government asked it for It chose a little compromise to enter the world s 3rd biggest economy   now it s alleging that it s been compromised  Strange  Corporate espionage isn t new, what is new is the method   motivation After all, we must be prepared with better security than asking people to stop hacking us   crying foul  Risk management is a key business area   Google would have accounted for such risks long ago  kakroo img  datmoneycom </description><link>http://www.secuobs.com/revue/news/189285.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/189285.shtml</guid></item>
<item><title>How  secure  is the  common man </title><description>Secuobs.com : 2010-01-21 23:51:02 - Roer.com   Information Security blog   The Roer Group Information Security Blog -     IMAGE  It was a nice day as every other day The only thing troubling me was I had to make some urgent calls and my balance ran out As expected I rushed to the nearest top-up vending machine A note posted outside said  out-of-service  Well to give you a brief about the place I live in a small town  if I can call it that  near London where one has to literally  work  to get even his her daily needs stuff As it happens I stay in the campus and there is just one top-up vending machine which was  broke  as of now The nearest cash top-up is around 2-3 miles down to the town centre Walking 5 miles to get a top-up would have been the last thing I could have imagined I called up customer care   they registered me for the web services As I reached my room, my ever so helpful neighbour said  try the online top-up  I wasn t keen on using internet for a five pound top up but I did proceed anyway I opened the nice looking  3  website   proceeded straightaway to the  My 3  account As I tried to log in, the website displayed  username   password details incorrect , I tried again   again   again but the password just didn t seem to work  Just bear in mind the password was generated within last 30 minutes  I was exhausted trying   re-trying but no success I called  3  and told them about the event The gentleman on the phone said  the site has been experiencing issues for the past few days weeks   you won t be able to access the  My3  account   WTF, I just got the password 30 min back , I asked him the solution He said he would register the credentials for me I was happy   confused by what he meant The guy asked all my security passwords   digits of my SIM,  My3  access password, date of birth etc I was getting clumsy to give him all those details but having taken the plunge I had no other option   it was supposed to be a  safe  way  after all 3 is a renown mobile operator  Everything was OK till the time he said,  Sir, please give me your Debit Credit card details  I was just numb for a moment, yes the guy was being helpful but should I trust anyone with such details  I was in two minds, I wanted to put down the phone saying  Thank You  but I wanted the top-up   walking 5 miles in such a snowy weather just didn t seem fine I knew before proceeding that I will never be able to  trust  this particular card again but I did go ahead anyway I was asked for the card details, expiry date   security number By the time I had given all these details I was 100pourcents sure- I will never ever use this card to keep my money in anymore Yes  I did get the top up within 2 hours   I also got twice the number of free texts, as promised But I was left with questions running in my mind   IMAGE    Why did  3  mobile not have it is website in place  Even the  not-so-good  mobile companies have  working  websites   What security controls has  3  in place so that  card details  aren t misplaced from the agents end    What if my card details are used for scrupulous activities  Who should I blame    Yes, I won t use that card anymore  it s a debit card so I know what is in out anyway  but what about the customers who give away their credit card details    Should I give away my card details to anyone at all over the phone or website  I thought about the whole scenario   came to the conclusion that   IMAGE    Only if I had put in a little effort   went to the shop, I wouldn t have to bother so much   Card details should never be disclosed to anyone While in hotels, swipe the card on your own Do not let anyone watch you while entering your pin   In today s world money is plastic cash I suggest you keep a separate account with no internet banking or debit card Keep most of your cash in it   Keep a tab on your credit limit in case of credit card Do you really need a limit of 100,000 on your card  Moreover activate Mobile Alerts for every transaction that is done on your card   Always read your card bill   pay later Direct debit is not always helpful   Lastly, never become dependent on technology Use it to make your life a little easier  do not let it guide your life Have a safe day ahead  -Anupam img courtsey  elementautocom, cardsmartcouk, horstmanncom  IMAGE   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE IMAGE  </description><link>http://www.secuobs.com/revue/news/184227.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/184227.shtml</guid></item>
<item><title>Guest Post  Is Bitlocker really that  fail everyone claims </title><description>Secuobs.com : 2010-01-12 13:33:35 - Roer.com   Information Security blog   The Roer Group Information Security Blog -    Per ThorsheimIn December 2009, researchers at the security lab of Fraunhofer SIT announced a new way of circumventing the drive encryption technology provided by Microsoft Bitlocker  found in versions of Vista, Windows 7 and Server 2008  In addition to previous announcements from other researchers on the same topic, Fraunhofer were able to bypass this security even when used in conjunction with a Trusted Platform Module  TPM  The announcement created a buzz on the Internet, as usual with lots of people claiming the end of the world, pointing fingers at Microsoft and twittering their opinions on  fail and  failure Well All you can do is manage risk Bitlocker works It provides good security, when implemented properly  now that's possibly the hard part, as it involves humans  Take a look at the wikipedia entry on Bitlocker, it describes how Bitlocker has three authentication mechanisms, and how they may be attacked  or circumvented  by using  cold boot attacks  or  bootkit attacks  These are physical attacks, they need physical access to your computer There's a smaller chance of that happening compared to getting  hijacked  by malware on some random website you're visiting Even if somebody deliberately wanted to attack you, there's a higher probability of that happening using software and websurfing than against your physical computer There are hundreds - thousands - of people that can access your computer rather easily, without putting much effort or expense into it Compare that to the millions  or billions  that can attack you through the Internet Well, you get the idea But that's a diversion, lets get back to Bitlocker There are other solutions on the market that can provide full-disk encryption as well, Safeguard Easy from Sophos and Check Point Full Disk Encryption are 2 commercial alternatives TrueCrypt is maybe one of the best known free and open-source solutions  Comparison of many solutions can be found here  Not going into the details here, there are pros and cons with all of them, and they will all be susceptible to either cold boot or bootkit attacks in some form anyway What i find amazing about all the fuzz and buzz about the apparent failure of Bitlocker is that people are criticizing advanced technology and cryptographic solutions, talking about advanced attack methods which require rather advanced tools and techniques Security is 80pourcents about people, the remaining 20pourcents is everything else PROPERLY implementing the technology is the key here Many people doesn't do things properly, at least not on their first attempt  or do you always read the manual first  I'm interested in passw ords Not by passwords themselves, but how they protect, or fail to protect information and assets that represent value in some form to people, organizations and our society in a variety of waysThe failure is always on the human side, as we fail to design, implement and maintain it properly Many people ask me  What about 2-factor authentication then  I usually reply with  Oh, you're thinking about those cute little dongles which people lose all the time, protected only by 4 static digits, most probably written on the backside of the dongle  PIN equals PASSWORD  You may use AES-256 as your encryption of choice, but if your password is password Well, that's not good And it doesn't matter if you're using Bitlocker, Truecrypt, Sophos or Check Point All software solutions, which may interact with, or require hardware tokens as well Of course you could buy yourself some of the hard drives that features on-board hardware encryption like the Momentus drives from Seagate, but still there will probably be a need of a user supplying some sort of credentials in order to access the encrypted data Which will be susceptible to cold boot or bootkit attacks as well Now here's a failure from my point of view  if not implemented properly, they will allow the user to use very short and easy-to-guess passwords Believe me  if people are allowed to use very easy passwords and never change them, they will do exactly that  I've got many years of personal research to support that allegation  To make things worse  if any unauthorized individuals can get access to your unencrypted data they will also get access to any passwords stored on the computer Even if you change it after momentarily after discovering your computer is gone, the probability of most users changing their password from password10 to password11 is rather high  got statistics there as well  Once they're in, it is really hard to get them out An attacker only needs to succeed once, you can never fail The FUD concerning Bitlocker  failure published some places are just FUD There's a rather big gap between the academical research ending up in advanced attack scenarios and the simple reality as illustrated in this xkcd comic   IMAGE  Bottom line  Do your own evaluation of the solutions available, and choose the one that fulfills your needs, satisfies your risk analysis and conforms to your budget Bitlocker may very well be fulfilling all those criteria Personally i recommend using full-disk encryption for most environments, but you also need to harden and patch your operating system and all applications continuously That is a long list of work to do, believe me This blogpost is the personal opinions of Per Thorsheim, and does not necessarily reflect the opinion of his employer Per Thorsheim is working full-time with security, based in Bergen, Norway During his spare time he does research into various security topics and is a very active participant in the security community He is currently certified CISA and CISM from ISACA, and CISSP-ISSAP from ISC 2  You can read his blog at securitynirvanablogspotcom, and contact him at per-AT-thorsheimnet He is very interested in public speaking engagements </description><link>http://www.secuobs.com/revue/news/180631.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/180631.shtml</guid></item>
<item><title>News  How Pentagon fights cyber spies</title><description>Secuobs.com : 2010-01-09 11:00:08 - Roer.com   Information Security blog   The Roer Group Information Security Blog -    Pentagon fighting cyber spiesPentagon released a report about how e-spies, software that download information or worse alter information, is their greatest threat in cyber warfare Of course, all even remotely associated with infosec could have told them this decades ago, and of course, Pentagon has known all the time Todays challenge is the way social networks are used as a transport means to infect computers, and systems, inside the military After all, the operators are simply humans, and humans can so easily be dubbed into clicking on the link stating  Is that really YOU in this video  As stated  What s particularly vexing about these intrusions is that sophisticated methods weren t necessarily required to get inside the networks In 2007, detailed schematics of Bagram Air Base in Afghanistan and the Camp Bucca detention facility in Iraq were downloaded by reporters from file transfer protocol servers with easy-to-find passwords or no protection at all The malware that spread via thumb drive across the military in 2008 had been around, in one form or another, since the early  90s In 2009, troops were so susceptible to virus- or Trojan-laden messages   supposedly sent from friends on Facebook and Twitter   that US Strategic Command network security officers wanted to ban access to the social networks altogether You can download the full report here  And the introduction, or overview is found here Go on, it is well worth a look   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE IMAGE  </description><link>http://www.secuobs.com/revue/news/179862.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/179862.shtml</guid></item>
<item><title>Free Porn to you - No upfront payment </title><description>Secuobs.com : 2010-01-08 14:56:26 - Roer.com   Information Security blog   The Roer Group Information Security Blog -    If you are like, well me, then you watch porn On the Internet But unlike me, you may not know how to avoid all the creepy and itchy stuff that may arrive after having un-safe sex This movie clip shows how free porn  or even paid-for porn  may force you to download rouge video players that is used to infect your computer Clearly showing the need of a  Condom for your computer  is great Using helper software like internet security suits are a great way to help avoid rouge downloads and rouge websites If you are using FireFox, you may already be familiar with the plug-in WOT - Safe Browsing Tool This tool helps increase the safety of your computer by color coding links - green  safe  yellow  uncertain  Red  unsafe Simple and efficient Just like with safe sex, the next time you feel the urge, take precautions And as in life in general - there is no free porn You just get the bill later  </description><link>http://www.secuobs.com/revue/news/179595.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/179595.shtml</guid></item>
<item><title>The reasons why I like the Data Retention Directive  Directive 2006 24 EC </title><description>Secuobs.com : 2010-01-08 13:09:22 - Roer.com   Information Security blog   The Roer Group Information Security Blog -    Data retention DirectiveThe Data Retention Directive, more formally  Directive 2006 24 EC of the European Parliament and of the Council of 15 March 2006 on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks and amending Directive 2002 58 EC  has caused a large amount of debate the past years It is argued that you would loose your privacy, that the directive will mean that all your data traffic and phone data is stored way too long, and that the directive is a huge threat to the society as we know it I disagree To begin with the end The society as we know it has never been, and will never be The society we live in is a society of constant change  some may call it evolving  New technology rises every single day New threats arrive by the hour And opportunists are readily available to exploit the technology and the threats to their own winning only The challenge in such a society is not a new directive which aims to make a standard rule of what information to collect, and how long to store it The challenge is that we, the people, the society, do not have the fantasy, competence, time nor tools to avoid the threats and the bad-asses who exploits every opportunity Even the technology vendors themselves are not able to see all the challenges their new technology brings to the market With each new product, comes a bundle of new possible exploits And the exploits are only discovered later, when the product is well in place, and used In todays society, black-hat hackers  the wizards of computers, working for the dark side, you know, those who love Dart Vader , find and exploit those wholes in technology They have great success And the smartest of those black-hats know that the best thing is not to leave a trace when they do their job So they will use any means they know to evade being caught on the system They still need to use the lines to connect, though And by storing the connection data, there is a potential  albeit small  to actually find some of those crooks after their criminal acts has been discovered What is more, when one trace has been discovered, the Directive ensures that trails are kept in other networks around Europe, which makes it easier to remodel the attack in the first place I also strongly believe that one shall not forget about Cyber war in this context It is a real threat, it is a game played by all major nations, and it is one game that aims at intelligence collection and the mapping of potential targets, including finding their weak spots, testing their defenses and understanding their meaning as part of the infrastructure The Directive may prove a valuable insight on how friend and foe analyses European networks, their content and their weak spots The storing of telco and ISP data is not something new In Norway, we have a strong idea that these types of logs are private, and should only be stored by the ISP Telco for a short period of time, and only to help the analysis to improve the network Well, that and to give the available data to the police in case of an investigation On a side note - the data the police is getting today, is delivered as an Excel file I hope I do not need to explain the security issues with relying your evidence on a non-traceable Excel file that anyone can tamper with  In other countries, Telcos and ISPs may not have the same image of privacy as here in Norway Perhaps they are storing the data, and do not delete it at all  What if every employee have access to that data  Or what if some black-hat hacker gets access to the logs  What will they discover  They will find the following for most of us  we send and receive e-mails, most of it spam We watch porn online No news there We interact in social networks Where we happily share our own images, of half-dressed  or half-nude if you prefer , drunken sailors and maidens in awkward positions And some of us even feel proud of sharing these, quite private moments Yes, we do this by our own free will No, we have no warrant that this kind of data will be deleted some times in the future, if we so request And no, we have no way of telling how this information may or may not used, for or against us in the future Be it in life, or in court The Directive may actually turn out to be your friend at some point, as with it, you know that there is a track record of your actions - or at least meta-data from those actions - and you could request this data if you where in a squeeze, say in court And use it to prove your innocence For example to show that the images found on your computer never was downloaded by yourself, it had to be someone something else that did it I believe it is time to wake up We have long lost, and forgotten about what privacy is We have accepted video surveillance to such a degree the past 30 years that you can hardly walk down the street and fart without  Big Brother  noticing Adding to video cameras are automatic face body recognition, movement detectors, heat cold detectors, weapon metal bomb detectors You light up like a cigarette in the dark walking down the street And you have no idea who monitors you Even though video surveillance is strongly regulated by laws in Europe, most private cameras are illegally used And those controlled by the government, well, they are networked, and used to follow you home, so to speak Another example where logs are used to safeguard your history is that of credit card transactions Using your credit card, as we use all the time in Norway, leaves a glowing trail that not only allows the government  and others who have access to the data  the possibility to track you down by the minute, and as done by the companies specializing in giving you 2pourcents rebate on  everything you buy , the data is great to build a complete profile of who you are, what you like, where you shop and how you spend your cash And you accept that just because 1 you feel your money is safer, and 2 you gain some coins by rebates It is my sincere opinion that if the Directive 2006 24 EC had offered you a cheaper phone bill, or perhaps a new, cheap phone, you would not object to it at all As a matter of fact, I believe that if such an offer would be added, you would jump on board and say   Hell yea, I like this new directive  Who cares about the data anyway  It is also important to understand what is to be stored It is not the full e-mail, only who sent it  who got it  the subject line  and at what time it was sent and received So what  The same goes for the internet access of yours Only meta data is saved, not the content Yes, they will see that you visit a porn site But we all know that already Besides, if your neighbor decides to use your wireless network to interact with terrorists, it would be a great help for you to have those logs available - as they may show what traffic origins from your computer, and what comes from the bad ass And the phone Unless you call Al Qaida or other terrorists, who really cares  Your phone company already have a pretty clear view of who you are already, if you trust them, a capitalist organization with their own agenda, with that data, why don t you trust your own government  If it really matters that much to you, disconnect Crawl back into the cave and live in the past Others have done that before you, just look at the Amish Don t be such a hypocrite, we all love the technology and the possibilities it gives us And the new technology need us to be responsible - as individuals, as societies and as governments The technology itself opens doors, and it is our responsibility to guard those doors Sometimes we do it ourself - by adapting our actions, other times we use technology - like firewalls  and other times we need regulations These elements walks hand in hand And they must adapt, adopt and evolve with the new technology Simple as that So I welcome the Directive 2006 24 EC as one means of taking control over the technology and the potential challenges technology impose on us At least I prefer that the capitalist organizations are regulated when it comes to their potential surveillance And I prefer that the government, a government that I elect, and thus to some extent control, are the ones to control this data </description><link>http://www.secuobs.com/revue/news/179570.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/179570.shtml</guid></item>
<item><title>Lenovo IdeaPad U1 Hybrid to beat Apples iSlate tablet </title><description>Secuobs.com : 2010-01-07 16:22:05 - Roer.com   Information Security blog   The Roer Group Information Security Blog -    This cool device was showcased this week at the CES2010 At first glance, I lik e it But at closer inspection, I dub it a geeks toy Who would really want a table to run two different OS depending on whether you use it as a tablet  disconnected , or as a laptop  connected  To me, this tool looks like a laptop you can disconnect the screen so you can scribble on it, but to make it useful, I would require full OS operation, using the same OS both when used as a tablet, and when used as a laptop The way the U1 is made makes no sense to me at all It does look cool though, but again the PC manufacturers shows how Apple, with its complete control of both hardware and software, will beat them to it again And again Nice try Lenovo, but not good enough  IMAGE   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE IMAGE  </description><link>http://www.secuobs.com/revue/news/179195.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/179195.shtml</guid></item>
<item><title>Guest post  Challenging corporate thinking on implementing IAM solutions</title><description>Secuobs.com : 2010-01-07 13:08:17 - Roer.com   Information Security blog   The Roer Group Information Security Blog -    Tony BallGuest post by  Tony Ball, Senior VP, Identity and Access Management  IAM , HID Global Organisations around the world are facing more security threats to their business than ever before Breaches of confidentiality, crippling cyber attacks and data theft by their own employees are just some of the issues that companies now have to contend with and plan for These security threats can also necessitate taking a more tangible a pproach to security where controlling physical access to premises is high on the agenda for many companies As soon as lurking security risks are exposed, they can exact a costly penalty in terms of reputational damage, eroding the confidence of investors and the market This can be disruptive to a company s operations and can even have a knock-on impact on customer service At the same time, companies are also wrestling with swathes of regulations like Sarbanes-Oxley, ISO9000 and Basel II that require them to take a more consistent and comprehensive approach to risk management, corporate governance and compliance in their day-to-day operations Successfully managing physical and logical access to high-value resources or sensitive data is one of the most effective ways for companies to protect themselves against the barrage of threats they now face Driven by these corporate imperatives, identity and access management  IAM  is fast securing its position as a cornerstone of information security, with a growing number of organisations recognising the potential benefits of an effective IAM programme in terms of cost savings, better service levels, tighter IT governance and improved regulatory compliance A survey carried out by technology and market research firm Forrester found that over 75 per cent of enterprise IT security professionals in the UK, France and Germany feel that governance, risk and compliance are motivating them to consider IAM solutions for their organisation So if the majority of IT professionals recognise the need to implement IAM, why has this so far failed to translate into wide-scale adoption  One of the foremost barriers to adoption cited by companies that have considered   but reluctantly decided against   IAM is the cost issue The ravages of the recession have blown a sizeable hole in the IT budgets of many organisations, with other corporate issues sometimes prioritised over IT security However, when a company slashes its IT budget, it can leave itself dangerously exposed to security and financial risks Where the money saved by reducing budgets can soon be more than swallowed up by the costs of security breaches While it is impossible to wholly quantify the financial impact of security incidents, the Ponemon Institute estimates that data breaches cost around  60 per compromised record Furthermore and according to a survey by Datamonitor, smart card security solutions can actually result in a savings of more than  2 million for every 2,000 employees A further reason why IAM has not yet been broadly taken up by organisations is because it is still viewed in some quarters as a tactical rather than a strategic implementation Too many companies still treat IAM as a series of ad hoc projects instead a process that is as dynamic as their company itself But adopting a scattergun approach to IAM across an organisation can be counterproductive to say the least Juggling multiple, mutually exclusive systems is doomed to failure Not only is this an expensive and resource-intensive way to approach IAM, but the lack of integration or coordination between these systems generates substantial   and unnecessary   complexity This often leads to a lack of buy-in from senior management and thus a lack of engagement amongst employees themselves IAM can seem like a bit of a minefield for companies that know they need to implement it, but don t know where to start For many businesses, the obvious place to begin is with smart cards Let s call out one of the biggest bugbears for corporate IT departments  managing identities is inherently difficult at the best of times, but the existence of multiple, disparate identities for each user within the companies is nothing short of a nightmare for IT managers If users are utilizing several identities to access information stored in multiple locations, it can be very complicated to bring this information together into a single format when systems are combined A recent survey by IT security firm Sophos revealed that a third of respondents use one password across multiple sites This means that if one account is compromised, all accounts are vulnerable A username password combination is still the most popular method of accessing IT systems, but its shortcomings are well documented Companies at the cutting edge of secure corporate ID cards have developed a novel two-factor authentication approach to managing and protecting access control within their organisations The user has to provide a hardware token  corporate identification card  in addition to a secret PIN number to strengthen the overall security of a desktop log-on Even better, the very same smart card can be used to control physical access to the company s premises, making this kind of solution one of the most effective, cost-saving methods to protect workplace and data security Smart card technology is becoming increasingly advanced  cards can now offer three levels of security  single, dual or three-factor authentication With single-factor authentication, using the card on its own will grant access to a system or open a door Dual-factor authentication adds an extra level of security in the form of a PIN number Three-factor authentication goes a step further, using a PIN number and an extra security measure such as a biometric scan Smart cards are also finding effective applications outside the corporate world Smart card technology is now helping to solve some longstanding thorny issues in the healthcare sector, such as safeguarding patients and staff while protecting confidential patient information In the UK, for example, many hospitals are now waking up to the benefits of using smart cards to control physical access to their buildings and add logical security to the IT networks that house confidential patient data In the past, it was relatively easy for an intruder to walk unchallenged around a hospital, accessing areas meant only for authorised staff In rare cases, this led to security breaches where babies were removed from paediatric wards Smart cards are addressing this physical access problem by using encryption to offer differing levels of building access to certain staff Medical professionals are also using their smart card to quickly access sensitive patient data on a network So in addition to safeguarding the security of patients  personal information, using a smart card for logical security can also create efficiencies in terms of time Properly implemented, identity and access management solutions can help companies by fortifying the security of their data and their business while making it far easier for users to access the information they need In simple terms, the challenge for any organisation implementing an IAM system is to bring together physical access control and logical security to establish how they can work better for their customers In today s increasingly risk-conscious environment, IAM is fast becoming a basic, non-negotiable part of corporate IT infrastructure - although IAM is designed to deal with some big security challenges, it does so with a straightforward, common sense approach Portable and secure, smart cards are becoming an increasingly valuable tool for safeguarding physical security and guaranteeing the privacy of sensitive electronic information across corporations, hospitals, government agencies and any organisation seeking heightened security solutions When you weigh up the benefits of identity and access management solutions against the costs of reputational damage, security breaches and non-compliance, IAM can offer outstanding value by saving time and money while protecting an organisation s assets HID Global is exhibiting at Infosecurity Europe 2010, the No 1 industry event in Europe held on 27th   29th April in its new venue Earl s Court, London The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise For further information please visit wwwinfoseccouk </description><link>http://www.secuobs.com/revue/news/179140.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/179140.shtml</guid></item>
<item><title>Authentication   Passwords  Staying Safe Online</title><description>Secuobs.com : 2010-01-05 17:24:11 - Roer.com   Information Security blog   The Roer Group Information Security Blog -     IMAGE  Img  thespinningbeachballcom Authentication is a process that verifies the credentials of a user The verification may be carried out on basis of previously stored information within the system in the form of passwords, biometrics or challenge response mechanisms A user here implies someone whose record is already created in the SAI  stored authentication information  The user presents information to the system for comparison and such information is called comparison information authentication  CAI  In a password based system the password that the user inputs is served to some cryptographic function which processes it to produce the SAI In a typical application that requires authentication say an email client, a user has to enter his email id   password to login   check his her mail The email server attempts to match the username with a registered user In case of a successful response, the server then checks password supplied with the one in SAI If it matches the user is authenticated   viola he she can check the mails  As you can see the basic flaw, anyone having such information about anyone can login   check the mails There is no physical check to cross check if the person entering the details is the registered user Having explained the basic flaw, let us find what we can do to make ourselves more secure online In case you use email, you would in any case give everyone your user-id so that they can contact you Also, you would send across mails   junk mails to people you know personally So securing user-id is of no use as anyone can find that out in most circumstances The real security that you can use is your  PASSWORD  So what is a password  Well, a password is a string of characters that you can choose while registering or once you have logged-in using one time passwords  eg On-line banking  Ideally, you think let me choose something I can remember like my mother s name, date of birth, car registration details or something EASY  Just think if you choose such passwords, how many people who are around you may know your password   how easy will it be for someone following you on Facebook, Twitter, Orkut etc to guess them  Virtually by choosing such passwords you have given it away to hundreds   thousands of people, the thing is no-one has tried to break-in yet  Once a user enters his her password the same is used to derive some function that is compared to the SAI Generally, the log-in function computes some cryptographic function using the CAI and compares the result with the SAI The authentication server never tells a user what went wrong if the user-id or password or both are wrong Thus it is the responsibility on part of the user to keep his credentials safe at all times Password Vulnerability The easiest way one can compromise such a authentication mechanism is by giving away his her password Not many of us realise that writing down passwords   sticking them to out screen or hiding them under or keyboard, are the worst things we can do It is also surprising that users can give away their passwords to others In a survey conducted at InfoSecurity 2003 conference in London 90pourcents people revealed their passwords for a cheap pen   IMAGE  Img  msterminalservicesorg You might have heard about Brute-Force attacks In such an attack an intruder can try all possible combinations and thus find out the correct one She he doesn t need any information from you about the process Say there is a door lock which has a 4 digit combination  unless you have the correct combination you can t enter inside It would take a burglar, patience   10000 combinations at max before detecting the correct one  Thus he enters all possible combinations before finding the right one  this is what a brute-force attack is Using such attacks on-line isn t a right way for an intruder because they are time-consuming   also that there is a limit on how many times you can enter a password incorrectly nowadays Hence nowadays the attacker would perform off-line attacks before trying to cr ck an account He may obtain the SAI file or encrypted passwords from network traffic, then automate his process to deduce the password Assume that a password is built from a set of 70 characters  upper case   lower case alphabets  digits 0-9  common symbols  There are around 24 million possible passwords of length 4   576,480,100,000,000 passwords of length 8 If an attacker can encrypt   compare 10,000 password sec with the SAI, he can check every possible password in 4 minutes It would however take him 183 years to check every possible password of length 8   IMAGE  Img  deblaze-toolappspotcom We talked earlier about users choosing password which may be their mother s name, their name, date of birth etc Such passwords can easily be broken by an attacker using dictionary attacks As I said previously, brute force attack as a very lengthy process to perform for attacks However, there are no more than 80,000 and names in common use   an encrypted process can check encrypted forms of these in no time  Even if users try to be a little smart using  JaMe5  instead of  JAMES  such modification is being  taken care of  by the new tools that the attackers use nowadays There are many more sophisticated attacks being used to decode passwords   I won t delve into each of them as they are highly complex Being Safe  IMAGE  Img  reputationdefenderblogcom Why do most of authentication systems use passwords based mechanism then  I would say it is because it is more simple   easy Having seen the vulnerabilities above it is important to take steps to limit the extent of such vulnerabilities Brute-force attack will fail if the password chosen is sufficiently long   the characters entered are a mix of upper-case, lower-case, digits, special characters They should be at least eight characters long A dictionary attack will fail if the password is not easy to guess Never use dictionary words, names or simple number digit substitution to hide recognizable words A strong password is one that is long enough   not consisting of easily recognizable words Yes they will be a little hard to remember, but  DO NOT  write it down as that would rather increase the vulnerability What can be done is rather generate passwords from last letters of  recognizable catchphrases  or think of a sentence eg  I was supposed to be going to Switzerland on a vacation Mix and match the words with digits   special characters to build a strong password Just to add, never repeat the alphabets or digits in a password, avoid using names, familiar words, dictionary words  do not use same password for all your accounts Lastly, do not store passwords in mail or anywhere online Check here  http bitly x4NgZ  if the chosen password is OK You all will hopefully have got a basic knowledge of working of the password based authentication mechanism You ve also seen how passwords can be attacked   broken I am sure after reading this most of you will re-evaluate the strength of your passwords   be safer </description><link>http://www.secuobs.com/revue/news/178387.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/178387.shtml</guid></item>
<item><title>Internet Piracy  A Long Drawn Battle </title><description>Secuobs.com : 2010-01-04 22:54:40 - Roer.com   Information Security blog   The Roer Group Information Security Blog -     IMAGE  Music download   piracy have been in the sphere for quite some time now It causes lots of people to get what they want  easily    music for free thus making it impossible for music companies to  supposedly  make the amount of cash they want to The piracy has been supported by a lot of people who think that the  manufactured  pop stars who have the blessings of the big labels   who churn the music that may be not of taste to everyone are not worth downloading Also, that there are many more bands that live in remote parts of the world   without internet they can t get the audience that they should have More so such supporters want the power of choosing music in the hands of the listener   not with the advertiser record company Then there are people like Bono   Metallica who simply hate the idea of such downloads To them it is the amount of money they are loosing on every label that gets downloaded without payment Recently Bono has made a statement that he embraces the concept of monitoring the data by Government organizations which makes it possible to stop such downloads altogether I personally feel that the Government should implement a lot of controls to first prevent the attacks   breaches it faces everyday on its sites We all know that the UK Financial Investments was hacked yesterday, how can we expect the Govt to enact such regulations when they can t even keep themselves safe on the net  It isn t realistic to think that such amount of control can be exercised by anyone over the internet Even the music industry has tried now   then introducing mechanisms like Anti-PC technology, CD s which last 24 48 hours, copy-protected discs but has it really stopped the piracy I think user s have got around such technology   downloading happily again Well I believe even though the crusade against piracy is drawn for a lengthy battle ahead, the mere idea of downloading music for free is not justifiable After all, these musicians make their living out of it   numerous people working in the media organizations have their livelihood dependent on the sales Maybe the media agencies charge a lot but it doesn t give us a right to steal someone s work without purchasing a license for it I know that both parties have their own theories which justify their actions but strictly speaking it is not a legal practice to indulge in such downloads I however cannot buy the argument of recording agencies that they are loosing millions as a result of such downloads Who says that if I download 100 songs online, I would have bought them if I hadn t downloaded  There are surveys that indicate in the past that most people who download music are the ones that buy as well  The industry has started to realize the shutting down such servers   suing them won t do them much good in terms of generating revenue They have started offering song download at a price and that seems to be a step in the right direction img  indabamusiccom  IMAGE   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE IMAGE  </description><link>http://www.secuobs.com/revue/news/178072.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/178072.shtml</guid></item>
<item><title>10 security predictions for 2010</title><description>Secuobs.com : 2009-12-31 16:01:06 - Roer.com   Information Security blog   The Roer Group Information Security Blog -    Roer predicts 2010 This is Roer s take on security 2010  Please share your comments and your own visions in the comments below  1 Cloud security Roer believes that cloud security would be of paramount importance in the New Year As more and more customers get accustomed with the cloud services   their benefits they would at the same time be apprehensive of the security behind the service CSP s have started to realize that Trust is the key to bring in more clients Many organizations have adopted various authentication   identity management software s Still a lot needs to be done to build the confidence among clients We believe that the factors of authentication would increase Also, the attackers would get evolved   will adapt to bring down the cloud A single cloud carries data of millions of customers so it would be all the more attractive for an attacker to launch an attack on cloud CSP will have to implement security mechanisms to keep such attacks in mind Security is the make or break point for a cloud service, 2010 will see a lot of advancements in this sphere 2 Goodbye logons All of us  at least those of us using computers  have a plentitude of log on credentials, to a large amount of websites and social media sites The more sites, the more passwords to remember Right  We believe that logon solutions like the OpenID project will take over many sites in 2010 We are actually considering implementing third-party authentication services on this blog too, in order to make it easier for you to comment and share Mind you, OpenID is only one such tool we all know Facebook, Microsoft and Google, and they all offer third-party authentication 3 Targeted attacks Targeted attacks are attacks that are targeting a specific computer, company or network Obviously The challenge with such attacks is that they are not showing up on the security vendors radar - so there are no signature file to protect you Many types of targeted attacks exists today - from hijacking a corporate data center, to DDoS, and all the way down to malware designed solely to leave incriminating materials on your PC, leaving no trace of itself, and making the forensics experts believing you where the one to download that child porn Most of these malware are still held within a very small group of hackers, but give some time and some money, and you will be able to buy such tools over the counter just like you can buy a bot-net today Another subset of attack will be those targeting small or specialized software vendors like industry developed software These tools are usually business critical, and developed by software developers who deem security to be  a pain in the place where the sun never shines , and thus focus more on function and less on security 4 Cyberwar act 2 We believe that Cyberwar as we have seen it so far is only the tip of the Iceberg Most modern countries today use computer technology and networks actively in their defense strategy, and many actively use it in their attack strategies too Roer believe that computer technology will be used in new manners to gather intelligence about individuals, societies, groups, companies and countries Social media and networks are amazing at it s willingness to share political views, religion, sexual orientation, social status, economy, activities and interests All information that is vital when identifying friends and foes The public have seen nothing yet when it comes cyber warfare 5 More hype and FUD We do not like FUD  Fear, Uncertainty and Doubt - a sales strategy from Security vendors  at Roer We love hype, though Unfortunately, we will see both rise in 2010 Hype is good as long as it is relevant FUD is nothing but waste of energy As the economy will continue to jump up and down, the security vendors who are not able to fit their product with a client pain will continue to scare clients to buy their stuff - even if the client have no use for the product We suggest using a vendor independent consultant when investing in new technology, a consultant that will align the technology need to your business need 6 Compliance comes alive Compliance will continue to grow in 2010 However, companies will start to care more, understand more about how being compliant can be a business driver, and that compliance as such do not make the company any more secure In order gain a higher level of security, companies will implement better internal controls, and use the internal control systems to handle issues as they rise 7 Adobe in the action Hackers and malware authors have discovered a new  not really  target for their attacks They no longer only focus on OS  Windows , they are increasing their focus on client software, like the Adobe family products The reason is simple - client software with high volume distribution means a large enough target base, while the security of such software usually is lower than those of todays OS  Roer believe that Adobe, as well as other large software vendors will be targeted more in 2010 8 Mobile fun As smartphones continue to grow their market shares, they attract interest from hackers and vandals Many carry around corporate information, and most devices are connected to the cloud and to the enterprise data centers Roer predicts a growth in attacks on mobile devices, and a growth in security systems for mobile devices Most importantly, we predict that mobile users and enterprises will become much more aware, and thus more willing to invest in securing their devices 9 ID-theft Roer believe that ID-theft will continue to rise in 2010 The more social networks you are on, the higher the risk of getting attacked The increase of logon systems under point two in our list also means a higher risk of loosing all your personal information We also expect to see more scavenging of personal data, to construct detailed profiles of individuals These profiles may be used by criminals to identify targets, for corporations to streamline their product offerings, and for foreign governments to identify possible friends and foes As for the internal government, see the next point  10 Monitoring In Europe we had large discussion about the new data directive, commanding ISPs and Telcos to save a minimum set of information about phone calls and e-mails The purpose is to give the governments a better tool to conquer criminal activity and terrorism From a privacy point of view, some have argued against this new practice The interesting point is that these new laws now make it very explicit what to store, and for how long Earlier, this would be up to each country, company or ISP Telco In the UK, 2010 will also be the year when people who download illegal materials from the Internet get s monitored And a large number of companies will increase their social media monitoring, coupled with better policies for social media like Twitter and Facebook This post was made by Kai   Kakroo Please share your own visions and comments below  </description><link>http://www.secuobs.com/revue/news/177097.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/177097.shtml</guid></item>
<item><title>Under Siege - Amazon get s the better deal again</title><description>Secuobs.com : 2009-12-31 15:12:05 - Roer.com   Information Security blog   The Roer Group Information Security Blog -     IMAGE  Recently a DDoS attack hit various services provided by Amazon which left many users wanting to access its various web based services Amazon being one of the biggest e-commerce vendors does have a huge customer base, any attack which renders it inactive for any amount of time affects its business by thousands if not millions of dollars Even though the attack lasted a few minutes, the entire situation was brought under control within an hour The attack was limited to Northern California in the USA Due to the attack on Amazon, several of its services like S3, EC2 were affected which in turn rendered loads of websites offline If sites like Amazon can be hit by such attacks then what about smaller sites with limited resources available  Are we fully prepared to adapt to keeping our data on the cloud when such an attack can render our data inaccessible to us  Wouldn t keeping all the data at a big storage make it vulnerable to attacks  If an attacker wants to attack a particular client hosted on a server like S3, wouldn t such an attack render every other client hosted on the server inaccessible  Who is accountable for loss occurring to a client because of such an attack  My perspective is that we should never trust anyone with our data If the data is of paramount importance keep it with you rather than keeping it with a storage provider Keep a backup of everything of importance to you, in case you do go ahead with using such a service Check the security services that you are provided by the data hosting site Always read the fine print of a contract before signing on one  Read more HERE </description><link>http://www.secuobs.com/revue/news/177089.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/177089.shtml</guid></item>
<item><title>Tutorial  Jail breaking your iPhone</title><description>Secuobs.com : 2009-12-31 00:52:59 - Roer.com   Information Security blog   The Roer Group Information Security Blog -     IMAGE If you have an iPhone, you own one of the most useful communication devices anno 2009 When it first arrived, it revolutionized the mobile industry Finally, there was a successful combination of a PDA and a telephone When I got my hands on the iPhone, I had spent more than a decade to find a tool that would give me all I wanted Back in the 1990s, I used a Palm Pilot, traded it up to the Palm m505 with color screen, and loved the ease of use I did hate two things - it s lack of a phone meant I had to carry with me two devices, and no WIFI Internet meant I had to couple it with my computer to sync it Later came the Nokia, and the Sony Ericsson mobile phones with PDA and e-mail built in These devices sucked as phones, and was truly bad as PDA s I loathed them The only good thing was I could now - when I was lucky - sync over the GSM network I soon ended up using them as phones only I never tried the Blackberry, as it was not available in Norway until too late Perhaps that one would have convinced me Today, there is but one alternative That is the iPhone It is so amazingly easy to connect it to whatever tool I need - including gmail, my calendars, CRM, GeoCaching  a fun localization game , Facebook, Twitter and LinkedIn What is more, when I need something, the chance of finding it in the App store is pretty huge I use traveling tools from Lonely planet, I use Flight Track Pro, and I use the CIA World Fact book And a bunch of other apps too But Even the iPhone comes with limitations One of those is that it usually comes locked to your carrier This is fine if you do not travel to foreign countries a lot, and if you do travel, avoid using the GSM network to download your mail and other data My challenge is that I do travel much, and I do use the GSM network locally to download maps, information, mail and whatever This quickly becomes very expensive since Data roaming is not regulated yet My solution is to use local prepaid cards for my iPhone And this in turn requires me to unlock it Another limitation is Apples decision to control everything that I should be able to install on my iPhone Yes, most tools are now available in the Appstore But not everything And to get access to these not-approved apps, you need to jail breake your phone Doing so gives you more control over your iPhone, including setting themes, turning on or off services that you do not like, avoid sending privacy information to the application developers and much more A very nice tutorial on how to jailbreak, and how to unlock your iPhone here   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE   IMAGE IMAGE  </description><link>http://www.secuobs.com/revue/news/176902.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/176902.shtml</guid></item>
</channel>
</rss>
 
