The Latest

Google security researcher Tavis Ormandy has unearthed a slew of critical vulnerabilities, including many remote code execution flaws, in Symantec and Norton enterprise and consumer AV products.

Symantec Norton AV flaws

The flaws affect the core engine deployed in the products and are, according to Ormandy, “as bad as it gets.”

“They don’t require any user interaction, they affect the default configuration, and the software runs at the highest privilege levels possible. In certain cases on Windows, vulnerable code is even loaded into the kernel, resulting in remote kernel memory corruption,” he noted.

The latter is possible because Symantec runs executable file unpackers directly in the kernel.

One of the vulnerabilities (CVE-2016-2208), a trivial buffer overflow, can lead to kernel memory corruption on Windows machines, and can be triggered by the victim simply receiving (and not opening) a specially crafted file or link via email.

“Because no interaction is necessary to exploit it, this is a wormable vulnerability with potentially devastating consequences to Norton and Symantec customers. An attacker could easily compromise an entire enterprise fleet using a vulnerability like this,” Ormandy pointed out.

“Network administrators should keep scenarios like this in mind when deciding to deploy Antivirus, it’s a significant tradeoff in terms of increasing attack surface.”

More details about the flaws can be found here and here, along with code for some of the exploits.

The vulnerabilities have been fixed by Symantec, and for some products will be implemented automatically, along with the latest definition updates. But for the rest, admins have to check for the updates, download them and install them manually (see Symantec’s security advisory for details).

Ormandy is known for his research into the security of security products, and has previously discovered critical flaws in solutions by many high-profile vendors such as Comodo, Trend Micro, Kaspersky and FireEye.


from Help Net Security http://ift.tt/29bmlsN

GuardKeyOver the years, we’ve covered many encrypted USB dongles on Help Net Security. All of them provide high security for your data, encrypted and stored on the dongle itself. Today I’m taking a look at GuardKey, which provides a different take on private data encryption.

Essentially, GuardKey is a digital key to your data. When you connect it to your computer, hidden data folders, dubbed safeboxes, will appear, and you can work with the files residing in them. Unplug the key, and the folders disappear. There are a couple of extra functions built in, and they will be covered in this review.

Digital safeboxes

When plugging this $59.99 (current price on Amazon.com) device for the first time, you set a master password and it’s ready for use. The USB stick itself has around 8GB of storage, so you can store data on it as well, but the main idea is to create safeboxes on the desktop computer.

GuardKey works on Microsoft Windows 7 and later, with OS X support announced for the near future. Its interface is simple and rudimentary, but works well for managing and accessing secure folders.

When creating new safeboxes, there is one simple rule – you can create one per partition. When a safebox is created, you can choose whether it will be automatically opened when GuardKey is plugged in, or whether you want to open in manually using the application.

While the data is encrypted using 256-bit AES, the hidden safebox folders will contain files with readable names by default. I advise going into setup mode and enabling the option to automaticaly encrypt the file names as well.

GuardKey

Even though you set up a master password, it is not needed in order to decrypt data. After plugging in the GuardKey into your computer, you will be automatically granted access to the files. You can manage this liability by going into the setup mode and manually enabling the option to make password input obligatory.

When I inquired about this, I was told that the idea behind Guardkey was to provide something like a physical door key – when the key is plugged in, the data is visible, and if its unplugged, the data is hidden.

But, when you think about it, the concept of a door key being the only mechanism for protecting your valuables inside a house is obsolete. Nowadays we use alarm systems, guard dogs, personal safe boxes, etc.

Password authentication should be a default option for a security product like GuardKey.

Besides on a couple of test computers, I’ve used GuardKey inside VirtualBox as well. Nothing special to add here, but I just wanted to mention that if you come across issues with initializing GuardKey in VirtualBox, you’ll probably fix the situation by installing the VM VirtualBox Extension Pack.

Secure cloud data

Creating and using a cloud safebox is practically the same as starting the regular safebox, the only difference is that the cloud one will be automatically synced to the service you use. The only prerequisite is that you have the cloud service software installed on your box. Currently GuardKey supports Dropbox, Google Drive, Microsoft OneDrive, ASUS WebStorage and SugarSync.

GuardKey

Pairing with a mobile device

By using a QR code, GuardKey can be paired with a Viewer app on a mobile device. This is needed for accessing encrypted cloud data from within the mobile application, but it is used for something else as well. You can use your mobile device as a backup variant (your personal backdoor?) to decrypt your private data on the desktop computer even when you misplace or lose the GuardKey dongle. This might seem like a good option from the usability perspective, but it’s a security issue. As its desktop version, opening the mobile GuardKey Viewer application doesn’t require a password, so anyone with brief access to your phone and computer could easily access your data.

GuardKey

GuardKey Viewer app

The GuardKey Viewer application is available for iOS, Android and Windows Mobile devices. As seen from the product homepage, marketing and tech documents, it is an equal part of the GuardKey experience extending the USB dongle’s functionality. The mobile application can be used for various actions, including being a backup option for opening desktop based safeboxes, acting as a reader of encrypted cloud based data, and uploading encrypted photos to the cloud.

I’ve used the latest iOS version of the software, published to the App Store in early February 2016. I needed to double check whether this was the latest version, as the application looked outdated. I don’t have a designer’ eye, but the issue with the GuardKey Viewer application is that it seems its GUI was optimized for the iPhones available back in December 2013 when the application first appeared in the App Store. The icons and the text are too large, and some graphical elements are missing. To make things worse, the problems with the mobile app extend to a myriad of spelling errors, but also to core functionality.

GuardKey

For the purporse of this review I was using the Box cloud service. After installing it on my iPhone, I made sure it was GuardKey ready – I created a cloud Safebox via the desktop computer. When I tried uploading photos to it, the Photos screen inside GuardKey Viewer stated just the following – Uaauthorized (Dropbox). I’ve gone through all the settings, to see whether Dropbox is labeled as the default location for photo uploads, but this wasn’t the case. I don’t even use Dropbox and therefore couldn’t even connect it with GuardKey. I was curious, so I opened a Dropbox account and when I gave access to it through GuardKey Viewer, the photo upload worked. So, it’s safe to assume that, in reality, the mobile application doesn’t work with all the cloud storage services GuardKey supports.

Through the desktop computer I’ve synced several files that were automatically encrypted and tried to open them in the Box iOS app. Naturally, the app couldn’t open them, but when I clicked on the “Open in” button, GuardKey Viewer was presented as an option, and it worked. FYI, the actual file you’re accessing is copied into a temporary folder inside GuardKey Viewer from which it can be opened.

Documentation

The GuardKey homepage provides a 44 page manual in which you’ll find practically all of the information you’ll need on using the product. There are also videos on GuardKey usage uploaded to YouTube and embedded on the product homepage, so check them out if you want to see the product in action. The web site also has an F&Q section, which I presume is misspelled combination of Q&A and FAQ. This section is empty and doesn’t provide any information. The cloud storage part of the GuardKey Viewer mobile app contains some helpful tips on using each of the supported cloud service providers in conjunction with GuardKey.

Closing remarks

While trying to toe the fine line between mainstream usability and a decent level of security, GuardKey presents some hits and misses. The product offers some interesting functionality such as encrypted cloud data and hidden private safeboxes, but fails with a sub par iOS application that looks unprofessional, and provides only borderline usability. GuardKey has good technology under the hood, but the developers have to work on polishing the presentation and the focus of the product.


from Help Net Security http://ift.tt/29nyhn5

Ecommerce sites are reselling used electronics without permanently erasing data from them.

Based on an analysis of 200 second-hand hard disk drives and solid state drives purchased from eBay and Craigslist in the first quarter of 2016, Blancco Technology Group found that 67 percent of the used drives contained personally identifiable information and 11 percent held sensitive corporate data, including company emails, CRM records and spreadsheets containing sales projections and product inventories.

used drives personal information

Whether the business is a traditional brick-and-mortar retailer, an ecommerce site, an electronics manufacturer or an enterprise business, failing to wipe drives clean before they are resold, repurposed or recycled can cause irreparable damage to customer loyalty, brand reputation and sales, both near-term and long-term.

Recent examples of data breaches and backlash resulting from this mistake reiterate how important it is to improve this area of data security. As Paul Henry, IT Security Consultant for Blancco Technology Group, explains, “With the Ashley Madison hack, in particular, users who wanted to make sure all of their data was erased from the dating site put all of their trust into the site’s $20 ‘Full Delete’ program. Even though the obvious identifiers had been removed, enough information was left to expose the site’s users. The big lesson for Ashley Madison – and any other type of business – should be to test that your deletion methods are adequate and to not blindly trust that simply ‘deleting’ data will truly get rid of all of it for good. Remaining data can still be accessed and recovered unless the data is securely and permanently erased.”

Key findings

  • Company emails, CRM records and spreadsheets are highly susceptible to leaks. Our digital forensics experts found company emails on 9 percent of the drives, followed by spreadsheets containing sales projections and product inventories (5 percent) and CRM records (1 percent).
  • Delete doesn’t always mean delete. On 36 percent of the used HDDs/SSDs containing residual data, users previously attempted to wipe the drives clean by dragging files to the ‘Recycle Bin’ or using the ‘delete’ button.
  • Quick formatted data can still be recoverable. A quick format was performed on nearly half (40 percent) of the used drives with lingering data found on them.
  • Despite proven capabilities, data erasure is still the lesser-known unicorn. Out of the 200 used HDDs and SSDs, only 10 percent had a secure data erasure method performed on them.

used drives personal information

“In even the most technology-inclined companies today, IT executives and CIOs often put most of their attention, resources and budgets towards tackling ‘scary’ data security threats, such as backdoor attacks, extortion hacks, malicious insider intrusions and malware. So investing in tools and methods to erase data from IT assets tends to sit low on their organization’s list of IT security priorities. But as our study shows, the dangers are just as precarious when data isn’t securely and completely erased,” said Pat Clawson, CEO at Blancco Technology Group.


from Help Net Security http://ift.tt/29eaya5
With the prevalence of DDoS attacks, good preparation and planning can go a long way toward making the DDoS response process as manageable, painless, and inexpensive as possible. The Network Ops DDoS Playbook is a guide focused on how to prepare yourself against a DDoS attack on your business and what to do if you are under attack. You’ll find practical tips, best practices and an overview of the cyber security technologies available to protect … More →
from Help Net Security http://ift.tt/291UiGG

Organizations are failing to appreciate the growing challenges of protecting their data and, as a result, are experiencing the economic impact of data loss, according to EMC.

emerging threats

A new study of enterprise backup in 18 countries around the world, revealed that, while businesses have been successful in reducing the impact of the four biggest traditional data loss risks, they are unprepared for new, emerging threats, which are taking their toll instead.

Threats to protection data

Nearly a quarter (23%) of businesses surveyed had experienced data loss or unplanned systems disruption due to an external security breach and that number increased to over one third (36%) when taking internal breaches into account. Businesses are increasingly facing threats not just to their primary data, but also to their backup and protection data.

Whether combating cyber extortionists demanding cash to unlock data encrypted by ransomware, or other risks posed to backup and protection data, businesses need to find solutions that put their ‘data of last resort’ beyond harm’s reach.

Threats to data in the cloud

More than 80% of survey respondents indicated that their organizations will run at least part of eight key business applications2 in the public cloud in the next two years; yet less than half said they protect cloud data against corruption and less than half against deletion. More than half said they already run their email solution in the public cloud. And, overall, respondents already had, on average 30% of their IT environments based in the public cloud.

Because SaaS application providers often won’t protect against accidental loss or deletion by an employee, EMC believes it is critical for organizations to include cloud applications in their overall data protection strategies.

emerging threats

Evolving protection needs

More than 70% of organizations surveyed are not very confident they could fully recover their systems or data in the event of data loss or unexpected systems downtime. And confidence also suffers when it comes to data center performance, with 73% declaring they are not very confident their solutions will be able to keep pace with the faster performance and new capabilities of flash storage.

“Our customers are facing a rapidly evolving data protection landscape on a number of fronts, whether it’s to protect modern cloud computing environments or to shield against devastating cyber attacks. Our research shows that many businesses are unaware of the potential impact and are failing to plan for them, which is a threat in itself,” said David Goulden, CEO, EMC Information Infrastructure.


from Help Net Security http://ift.tt/293ryzD

The artificial intelligence market in the US is projected to grow at a CAGR of 75% until 2021 on account of increasing AI technology adoption, according to TechSci Research.

artificial intelligence market

Major consumer electronic device manufacturers and platform providers such as Apple, Microsoft and Google are increasingly offering these solutions in smartphones, tablets and smart wearables.

“It’s no surprise AI and machine learning are growing at a CAGR of 75%. When looking at the cyber security segment, it’s a painfully obvious need. Truth is we are short over 1,000,000 cyber security specialists globally this year. The way the industry previously handled cyber security analysis, incident response, threat detection and remediation will simply not scale going forward. Today, firms have Managed Security Service Providers that have armies of analysts with ‘eyes on glass’ and that approach is worse than reactive, it’s simply broken,” Yuri Frayman, CEO of ZENEDGE, told Help Net Security.

Venture capital investments in this sector are in full swing. The major applications in the artificial intelligence market include speech and image recognition, natural language processing, gesture control, and cyber security.

The only way forward is to replicate what the security analyst is able to achieve through data analysis but at the scale of machine learning / AI, according to Frayman.

“At the core AI is a sophisticated, non-linear pattern matching and classification technology. We need to apply that discipline to a growing number of real world applications within cyber security. As an industry we must think out of the box and apply both supervised and unsupervised machine learning in creative ways to lower our reliance on human analysis,” the ZENEDGE CEO concluded.


from Help Net Security http://ift.tt/2941R1f