<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Musings &#187; data protection</title>
	<atom:link href="http://securitymusings.com/article/category/data-protection/feed" rel="self" type="application/rss+xml" />
	<link>http://securitymusings.com</link>
	<description>Rants and raves from information security professionals</description>
	<lastBuildDate>Mon, 07 May 2012 21:31:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>There&#8217;s a reason to check security during development</title>
		<link>http://securitymusings.com/article/3215/theres-a-reason-to-check-security-during-development</link>
		<comments>http://securitymusings.com/article/3215/theres-a-reason-to-check-security-during-development#comments</comments>
		<pubDate>Mon, 07 May 2012 21:17:55 +0000</pubDate>
		<dc:creator>Benjamin Hartley</dc:creator>
				<category><![CDATA[data protection]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=3215</guid>
		<description><![CDATA[During security assessments, I always make sure they&#8217;re performing security testing as part of their development process. This is why: &#8220;Apple security blunder exposes Lion login passwords in clear text&#8221; No need to go into details as to what happened here; it&#8217;s well-researched in the linked article. However, this is exactly the scenario that development [...]]]></description>
			<content:encoded><![CDATA[<p>During security assessments, I always make sure they&#8217;re performing security testing as part of their development process.</p>
<p><a href="http://www.zdnet.com/blog/security/apple-security-blunder-exposes-lion-login-passwords-in-clear-text/11963" title="This is why.">This is why: &#8220;Apple security blunder exposes Lion login passwords in clear text&#8221;</a></p>
<p>No need to go into details as to what happened here; it&#8217;s well-researched in the linked article. However, this is exactly the scenario that development security testing is meant to avoid. A seemingly innocent patch disables or circumvents an important security feature. The results are predictable.</p>
<p>It could be worse, though. Here&#8217;s the worst case: the problem isn&#8217;t detected. Because the security was included in the original version, and because nobody checked, it is assumed that the security is in place, and successive updates are made, with the security feature in question not working, but everyone assuming it does. And successive patches are built upon the circumvented security. by the time the bug is discovered, fixing it is a gargantuan task.</p>
<p>So, it&#8217;s not <i>that</i> bad. It&#8217;s still a major breach, though. So if you ever wonder if that testing is really necessary during development, you can point to this incident and confidently say &#8220;Yes.&#8221;</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=There%E2%80%99s+a+reason+to+check+security+during+development+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D3215" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/3215/theres-a-reason-to-check-security-during-development&amp;t=There%E2%80%99s+a+reason+to+check+security+during+development" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/3215/theres-a-reason-to-check-security-during-development/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>On the importance of a Safe Harbor</title>
		<link>http://securitymusings.com/article/3208/on-the-importance-of-a-safe-harbor</link>
		<comments>http://securitymusings.com/article/3208/on-the-importance-of-a-safe-harbor#comments</comments>
		<pubDate>Thu, 12 Apr 2012 21:40:13 +0000</pubDate>
		<dc:creator>Benjamin Hartley</dc:creator>
				<category><![CDATA[data protection]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[regulations]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[vendors]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=3208</guid>
		<description><![CDATA[A service provider shall not be liable for monetary relief, or, except as provided in subsection (j), for injunctive or other equitable relief, for infringement of copyright by reason of the provider’s transmitting, routing, or providing connections for, material through a system or network controlled or operated by or for the service provider, or by [...]]]></description>
			<content:encoded><![CDATA[<p><em>A service provider shall not be liable for monetary relief, or, except as provided in subsection (j), for injunctive or other equitable relief, for infringement of copyright by reason of the provider’s transmitting, routing, or providing connections for, material through a system or network controlled or operated by or for the service provider, or by reason of the intermediate and transient storage of that material in the course of such transmitting, routing, or providing connections</em> &#8211; 17 USC § 512, from the Cornell University Law School</p>
<p>No business is an island. There&#8217;s no company that does not, to some extent, rely on other businesses. Business models assume that vendors will be able to assure a steady flow of goods, that retailers will sell goods and pay as contractually bound, that shippers will actually ship goods, etc. Our legal system is filled with assurances to that effect. And this is important, because it gives companies confidence to make such agreements. Knowing that business partners can in fact be bound and trusted to perform their duties, companies can more readily act to grow and increase their revenues. The key component here is confidence &#8211; a certainty that once a contract is signed, it will be followed.</p>
<p>That&#8217;s what makes the MegaUpload case rather disturbing. There&#8217;s no doubt that MegaUpload was hosting infringing content. However, the content was not <em>all</em> infringing &#8211; but all of it was taken down. Right now there is a case <a href="https://www.eff.org/press/releases/megaupload-user-asks-court-return-his-video-files" title="a case seeking return of files"></a> and the hosting company, Carpathia, is seeking court action which would allow it to release the existing data back to MegaUpload users.</p>
<p>However, in a way, the damage has already been done. Whatever the outcome of the case itself, one message has been sent clearly: your data can be held hostage by others&#8217; data. That&#8217;s sure to have a chilling effect on the hosting industry for years to come.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=On+the+importance+of+a+Safe+Harbor+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D3208" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/3208/on-the-importance-of-a-safe-harbor&amp;t=On+the+importance+of+a+Safe+Harbor" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/3208/on-the-importance-of-a-safe-harbor/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How *not* to secure your mobile phone.</title>
		<link>http://securitymusings.com/article/3184/how-not-to-secure-your-mobile-phone</link>
		<comments>http://securitymusings.com/article/3184/how-not-to-secure-your-mobile-phone#comments</comments>
		<pubDate>Thu, 22 Mar 2012 20:22:51 +0000</pubDate>
		<dc:creator>Tim Donaworth</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[rants]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=3184</guid>
		<description><![CDATA[The following events are based on actual facts and actual events. Names have been changed to protect the oblivious. I would like to start off by stating that I take no pity on the individual this story is about. I refer to them as oblivious because to do what they did simply can&#8217;t be categorized [...]]]></description>
			<content:encoded><![CDATA[<p>The following events are based on actual facts and actual events. Names have been changed to protect the oblivious.</p>
<p>I would like to start off by stating that I take no pity on the individual this story is about. I refer to them as oblivious because to do what they did simply can&#8217;t be categorized in any other way.</p>
<p>Let&#8217;s back up a week. I&#8217;ve been in need of another Android device to do some tinkering with, have a backup for my daily driver, and to have something that my son can play with and not fear total destruction (again of the daily driver). After checking with friends and co-workers if they had any spares &#8211; they didn&#8217;t &#8211; I resorted to Ebay. Long story short, I found an LG Optimus S &#8211; a rather sturdy little phone for its age for $7 plus $4 shipping. The description said that it did not boot. Being the hacker that I am, I generally don&#8217;t let simple statements like that deter me.</p>
<p>A few days later I had the phone in my mailbox. It even included the battery, which I wasn&#8217;t expecting. I attempt to boot it up, and as described &#8211; it doesn&#8217;t boot. I plug it in to ensure it has a charge. It won&#8217;t charge. I pull out the voltmeter and quickly determine the battery is junk. Fast-forward two more days after a visit to Amazon (Prime). A new battery is awaiting me in my mailbox. Plug it in, viola, Android magic!</p>
<p><strong><span id="more-3184"></span></strong>Immediately after boot up I notice the first notification is a voice mail. Seems the user never did reset the device. Being nosey, I check the notification. Something about John borrowing the truck for an extra day. I hope Sam<sup>1</sup> didn&#8217;t miss that voice mail. I check the contacts, and once again, it is full of names and addresses of people I&#8217;ve never heard of. Popping into the app drawer, I notice that not only does all the user data remain, but so do the apps. At this point I&#8217;m ready to simply go ahead and do a hard reset as I have zero interest in any of the previous owner&#8217;s old apps or information. But then this catches my eye:</p>
<div class="wp-caption alignleft" style="width: 134px"><img title="Chase App" src="https://lh6.ggpht.com/QComgTo47h1orWbQFpCJ6IYkmcC-MAlMZ_IeaC2ePJ4wF5DOPoJEeiXGnTPR4EZ21Rk=w124" alt="Chase App Icon" width="124" height="124" /><p class="wp-caption-text">Chase Android App</p></div>
<p>That’s right, the Chase Banking app. Immediately, my heart sinks. I already start to dread what I presume I&#8217;m going to find. I open the app, click the login button, and literally face-palm. Username jxxxxx, Password ********. The user’s login details were saved in the application. I&#8217;m now one click away from being in someone else&#8217;s bank account. At this point I&#8217;m feeling extremely paranoid, and my white-hat mindset kicks in. I pull the battery, put it back in, and proceed to hold the home key, volume down key, and power it into the recovery screen. A couple more volume clicks later, and the device is completely formatted and returned to its factory settings. The old data is wiped.</p>
<p>As I mentioned, I was already fairly certain as to what I was going to find before ever even entering into that Chase app. Why? Most people do not understand the consequences of their actions, especially when it comes to security. Nor do they even consider it when dealing with the majority of technical things they do on a day-to-day basis.</p>
<p>So for those of you wondering, let&#8217;s review some of the steps that Sam<sup>1 </sup>should have taken.</p>
<ol>
<li>Upon boot up, the device went straight to the launcher. No pin, password, or swipe gesture was required. You should always protect your devices with some sort of locking feature. This is especially true if you have sensitive data stored on your device. If you use your device to access your company email or remotely connect to your company network, this should definitely be part of the company policy. It&#8217;s easy to configure within Exchange as well.</li>
<li>The user stored sensitive credentials within apps. Storing your password for something like your gaming account is one thing. Even allowing Android to automatically log into your email is a little risky, but saving the username AND password to your banking application? That&#8217;s just asking for trouble. NEVER store credentials in any application that you wouldn&#8217;t want someone else having access to! End of story.</li>
<li>The user sold a device (knowingly) without performing a reset or wiping the data. This policy holds true for more than just cell phones. But let&#8217;s face it; we are all even more connected to our phones today than ever before. I&#8217;d go as far as to say some even use them more than their actual computers (for personal tasks). If/when you sell electronic devices, you should always perform a format, or wipe of all stored data, whether this is a factory reset of a phone, a format and reinstall of a laptop OS, or even a full DoD multiple pass wipe. Always destroy your data before releasing your devices to the public.</li>
<li>The fact that Sam<sup>1 </sup>even had his banking app on his phone can be viewed as a flaw &#8211; but I&#8217;ll let that one slide. I personally choose not to keep anything on my devices that can associate me to what my banking information may be. I go even as far as to ensure that any emails I get from my banks are sent to an email address that isn&#8217;t associated with my default Android account. Paranoid, perhaps. Secure, you bet!</li>
</ol>
<p>I will take a slight bit of leniency on Sam<sup>1 </sup>based solely on the fact that he thought the device was toast. But this is even more reason why you should take the steps necessary to ensure the device is wiped clean before getting rid of it. And for the average Joe (Sam) it&#8217;s not always obvious how to do these tasks. I had to look it up myself for this specific device (Android tends to vary the button combination per device). But in this case because the phone wouldn&#8217;t boot with the dead battery, Sam wouldn&#8217;t have even been able to perform the reset without some other form of digital magic.</p>
<p>Moral of the story: Wipe your devices, lock your devices, and don&#8217;t store credentials to sensitive information!</p>
<p><sup>1 </sup>Sam is a made up name, unless his name really was Sam, in which case it is purely coincidental.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=How+%2Anot%2A+to+secure+your+mobile+phone.+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D3184" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/3184/how-not-to-secure-your-mobile-phone&amp;t=How+%2Anot%2A+to+secure+your+mobile+phone." title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/3184/how-not-to-secure-your-mobile-phone/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Smart Phone Security Pointers</title>
		<link>http://securitymusings.com/article/3134/smart-phone-security-pointers</link>
		<comments>http://securitymusings.com/article/3134/smart-phone-security-pointers#comments</comments>
		<pubDate>Sat, 17 Dec 2011 02:35:50 +0000</pubDate>
		<dc:creator>Nick Staples</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[general]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=3134</guid>
		<description><![CDATA[Around this time of year, many people receive new devices and gadgets as gifts, and some of those gadgets turn out to be smart phones. But smart phone security is very tricky to pin down, as there are multiple vendors and platforms to take into consideration, not to mention the speed at which smart phone [...]]]></description>
			<content:encoded><![CDATA[<p>Around this time of year, many people receive new devices and gadgets as gifts, and some of those gadgets turn out to be smart phones. But smart phone security is very tricky to pin down, as there are multiple vendors and platforms to take into consideration, not to mention the speed at which smart phone technology is evolving. So when I came across this <a href="http://www.mcafee.com/us/resources/white-papers/foundstone/wp-top-10-iphone-security-tips.pdf">Top 10 iPhone Security Tips</a> whitepaper (pdf), I knew that it was probably a good thing that it attempts to target a specific platform. However, after reading through it, I think that many of the things McAfee points out can also apply to a Droid or BlackBerry. And so, by stripping away the platform-specific details, we arrive at a pretty decent list of things a new smart phone owner can do to achieve some basic smartphone security:</p>
<ul>
<li>Enable passcode/lock</li>
<p>Mobile phones have had passcode capabilities for a long time. Make sure you&#8217;re using it, since a passcode lock is often the first line of defense.</p>
<li>Erase all data before a return, repair, or resale</li>
<p>If you will no longer be the owner in possession of the device, it&#8217;s best to erase everything you can first. Everything. If you can do a factory reset, do so, because your phone constantly records information and there is always some data that isn&#8217;t easily found, let alone purged.</p>
<li>Regularly update firmware</li>
<p>I&#8217;m guilty of not doing this&#8211; sometimes the update notification will sit around for a week before I finally give it permission to run. But this is one of the easier things to do, since it&#8217;s mostly automatic.</p>
<li>Don&#8217;t run shady apps</li>
<p>Just like with a personal computer, if you run unknown or untrusted applications, you substantially increase your chances of getting <strong>got</strong>.  So if you don&#8217;t want to get got, be prudent about what apps you run on your device.</p>
<li>Take advantage of the web browser&#8217;s security</li>
<p>For smartphones with native web browser apps, be sure to use the security features to clear caches and stored passwords when it&#8217;s necessary. Just because a web browser is on a mobile device doesn&#8217;t mean it&#8217;s a security lightweight. Check out the &#8220;settings&#8221; or &#8220;options&#8221; to see just how much your mobile phone web browser can do to help you out.</p>
<li>If you&#8217;re not using it, disable it</li>
<p>I&#8217;m also guilty of leaving stuff running unnecessarily. Be careful about leaving debug mode enabled, Bluetooth and wifi on, etc.  Generally speaking, the more doors you leave unlocked, the lighter you sleep at night. Turning off unused services when they aren&#8217;t needed is a good habit to form, even outside the realm of security.</p>
<li>Secure that email</li>
<p>In addition to providing native web browser apps, many smartphones also come bundled with a native email app. Check the settings for these apps to take advantage of any security features they&#8217;re offering (such as SSL/TLS).</p>
<li>Use a phone tracker</li>
<p>The GPS can be bad for privacy if you are reckless with it. However, it can also be a powerful tool to help you recover a lost/stolen device. I believe the iPhone 4 has a built in device-finding service (complete with a remote wipe). But even if you have a different smartphone, there is almost certainly an app that provides some remote tracking for lost devices (i.e. <em>Where&#8217;s My Droid</em> app for Android).</ul>
<p>This certainly isn&#8217;t a comprehensive list, but it should be enough to get both new and old smartphone users thinking about general mobile device security in a healthy way.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Smart+Phone+Security+Pointers+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D3134" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/3134/smart-phone-security-pointers&amp;t=Smart+Phone+Security+Pointers" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/3134/smart-phone-security-pointers/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>&#8220;I think they already know about the mountains, sir.&#8221;</title>
		<link>http://securitymusings.com/article/3087/i-think-they-already-know-about-the-mountains-sir</link>
		<comments>http://securitymusings.com/article/3087/i-think-they-already-know-about-the-mountains-sir#comments</comments>
		<pubDate>Mon, 31 Oct 2011 21:13:50 +0000</pubDate>
		<dc:creator>Benjamin Hartley</dc:creator>
				<category><![CDATA[data protection]]></category>
		<category><![CDATA[general]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[risk management]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=3087</guid>
		<description><![CDATA[A few years ago, a friend of mine served in Afghanistan. It was, as he described it, a long and mostly dull duty. When not busy with soldierly duties, he wrote on his blog and took pictures, often of the rather picturesque – to those who didn’t have to traverse it – scenery. At one [...]]]></description>
			<content:encoded><![CDATA[<p>A few years ago, a friend of mine served in Afghanistan. It was, as he described it, a long and mostly dull duty. When not busy with soldierly duties, he wrote on his blog and took pictures, often of the rather picturesque – to those who didn’t have to traverse it – scenery. At one point, however, he was informed that these landscape pictures were, in fact, an operational security violation. Not the ones taken in-camp, but the gorgeous panoramas of Afghani mountains and valleys. The theory was that, using those pictures, insurgents could find their position. My friend’s response was succinct: “I think they already know about the mountains, sir.”</p>
<p>In a previous job, I was charged with creating the security documentation for a particular government system, including the disaster recovery plan. That plan necessarily had to include the power requirements for the system. However, with a certain amount of digging, I discovered that by the standards to which I would be held, the simple fact that the servers used either 110V or 220V power was considered “secure unclassified information” and my report would require rather cumbersome treatment. Mind, what put it over the top was not that the servers required 110V, or that the servers required 220V, but simply that the servers might require one or the other. Or, in other words, that the servers required electricity <em>in the same fashion as every other standard server</em>. The bleedingly, patently, absurdly obvious. But that fact was somehow important for security.</p>
<p>There is a certain tendency, with respect to security, to classify, render confidential, or otherwise obscure every piece of information. I cannot count how many times I have heard “we can’t tell you what kind of encryption we use &#8211; that would make it insecure!” or some other variant. Indeed, there is a certain value to hiding some seemingly obvious pieces of information – the number of servers, the ports being used, the location of a datacenter in a building. These are not without purpose. There is no sense in making an intruder’s job any easier, and great value in making it as trudgingly difficult and annoying for them as possible.</p>
<p>But this must be tempered with a modicum of sense. In risk assessment terms, this means examining a piece of information and determining what level of risk it exposes. There is no sense in restricting the fact that servers run off of electricity; an intruder knows that – it’s not something that takes much knowledge to figure out. There’s no sense in hiding the fact that a base which is in contact with the local population can see the mountains – the insurgents know that. These are obvious things.</p>
<p>And there’s an important psychological component there. By trying to secure patently obvious things, security by obscurity (already a bad idea) becomes security of absurdity. The very concept of security becomes eroded. Yes, it’s easier to treat all information as secure, but the end users won’t view it that way. What they’ll see – correctly – is a security posture which has gone amok and which is not connected to the reality of their work. And they’ll start ignoring it because it’s ridiculous. And then they’ll be ignoring actually sensible security; they’ve lost confidence in the directives and the purpose behind them. And then you have a problem.</p>
<p>The point is to maintain a real connection with the people who have to implement security directives. As I’ve <a href="http://securitymusings.com/article/2487/compromises-and-security">said before</a>, their job is not to keep your infrastructure secure – their job is, well, their job. To keep people following secure processes, they have to be invested. They have to be able to understand <em>why</em> they’re doing these things. You have to acknowledge that they know the mountains are there, and work within that reality.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=%E2%80%9CI+think+they+already+know+about+the+mountains%2C+sir.%E2%80%9D+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D3087" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/3087/i-think-they-already-know-about-the-mountains-sir&amp;t=%E2%80%9CI+think+they+already+know+about+the+mountains%2C+sir.%E2%80%9D" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/3087/i-think-they-already-know-about-the-mountains-sir/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The Digital Underground</title>
		<link>http://securitymusings.com/article/3052/the-digital-underground</link>
		<comments>http://securitymusings.com/article/3052/the-digital-underground#comments</comments>
		<pubDate>Sat, 08 Oct 2011 02:56:38 +0000</pubDate>
		<dc:creator>Nick Staples</dc:creator>
				<category><![CDATA[data protection]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[general]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=3052</guid>
		<description><![CDATA[A lot of what we security professionals do includes protecting information from being compromised (especially personal information). The shift towards more profit-driven computer crime has happened swiftly over the last decade, so it should come as no surprise that there is a booming underground market centered almost entirely around compromised financial and personal data. And, [...]]]></description>
			<content:encoded><![CDATA[<p>A lot of what we security professionals do includes protecting information from being compromised (especially personal information). The shift towards more profit-driven computer crime has happened swiftly over the last decade, so it should come as no surprise that there is a booming underground market centered almost entirely around compromised financial and personal data. And, on the other end of the spectrum, we have laws and regulations to help minimize the leakage of this data in the first place. Plenty of research and documentation exists for the many ways we try to protect information, but there isn&#8217;t much (public) info on the underground market populated by the attackers and their associates who trade in illegally-gotten information. So, how do someone&#8217;s bank account credentials grease the wheels of this unique ecosystem?</p>
<p>The Underground Economy: Priceless (<a href="http://www.usenix.org/publications/login/2006-12/openpdfs/cymru.pdf">pdf</a>) touches on the subject in a great amount of detail, even explaining the importance of reputation and the lengths people take to avoid prosecution.</p>
<p>Essentially, public and private servers host communities of individuals who offer their services for a fee. Maybe one person will help someone else cash out an entire bank account (for a 50% cut). And maybe another person will deliver ill-purchased goods to a safe location (for a 30% stake). In the mix are also those who initially did the work (or wrote the code) to capture the information, as well as people who specialize in forging IDs, curious researchers, law enforcement&#8230; the list goes on. Compromised financial data seems to lead to a very deep chain of events that attracts many people with varying skillsets, most of whom are simply offering to perform the same hustle(s) over and over. It is a system where both information and skills are bartered/exchanged and high risk is accepted for high returns on investment.</p>
<p>But not all participants are highly skilled&#8211; there should be some low-hanging fruit in there too, right? Surely, there are people who aren&#8217;t as cautious or who miscalculate their risk of exposure, yet we still have trouble keeping up with even a fraction of the online fraud. While I&#8217;m glad we are focusing efforts on preventing information from being compromised in the first place, I feel like there is a growing opportunity to focus a lot more research on thwarting these high-risk behaviors directly. Sometimes you have to treat both the symptom and the cause.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=The+Digital+Underground+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D3052" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/3052/the-digital-underground&amp;t=The+Digital+Underground" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/3052/the-digital-underground/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Removing Trusted Certificates from Android</title>
		<link>http://securitymusings.com/article/3001/removing-trusted-certificates-from-android</link>
		<comments>http://securitymusings.com/article/3001/removing-trusted-certificates-from-android#comments</comments>
		<pubDate>Thu, 15 Sep 2011 15:22:55 +0000</pubDate>
		<dc:creator>Tim Donaworth</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Android SDK]]></category>
		<category><![CDATA[BouncyCastle]]></category>
		<category><![CDATA[DigiNotar]]></category>
		<category><![CDATA[PKI]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[TLS]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=3001</guid>
		<description><![CDATA[In light of all the discussions about maintaining a secure posture on trusted certificates we often times forget about the little guys. In this case I'm talking about our mobile devices. We tend to forget that these devices are just as vulnerable as our desktop/laptops. Unfortunately it's not always easy to manage the certificates on these devices. But if you own an Android device and would like to take a little more control over what your device is trusting read on to find out how you can do it.]]></description>
			<content:encoded><![CDATA[<p>In light of all the <a title="CAs behaving badly" href="http://securitymusings.com/article/2969/certification-authorities-behaving-badly" target="_blank">discussions</a> about maintaining a secure posture on trusted certificates, we oftentimes forget about the little guys. In this case, I&#8217;m talking about our mobile devices. We tend to forget that these devices are just as vulnerable as our desktop/laptops. Unfortunately, it&#8217;s not always easy to manage the certificates on these devices. But if you own an Android device and would like to take a little more control over what your device is trusting, here&#8217;s how you can do it.</p>
<p><strong>Remove a CA Cert from Android System</strong><br />
The bouncycastle library will be required, you can grab it here:<br />
<a title="BouncyCastle Library" href="http://bouncycastle.org/download/bcprov-jdk16-141.jar" target="_blank"> BouncyCastle Library</a></p>
<p>You&#8217;ll need the Android-SDK as well in order to utilize ADB. It can be found here if you don&#8217;t already have it:<br />
<a title="Android SDK" href="http://developer.android.com/sdk/index.html" target="_blank"> Android SDK</a><br />
<strong><span id="more-3001"></span></strong>
<ol>
<li>Move the jar into the $JAVA_HOME%\lib\ext folder. It&#8217;s most likely in a place like this:<br />
&nbsp;</p>
<pre><span style="color: #333399;">C:\Program Files (x86)\Java\jre6\lib\ext\</span></pre>
<p>&nbsp;</li>
<li>Connect your USB cable to your phone and verify with adb that it is seen as attached.<em> [%android-sdk% is the location of the Android SDK installed on your system]</em><br />
&nbsp;</p>
<pre><span style="color: #333399;">%android-sdk%\tools&gt; adb devices</span></pre>
<p>&nbsp;</li>
<li>You&#8217;ll need to grab the cacerts.bks file from your phone using adb:<br />
&nbsp;</p>
<pre><span style="color: #333399;">%android-sdk%\tools&gt;adb pull /system/etc/security/</span></pre>
<pre><span style="color: #333399;">cacerts.bks cacerts.bks</span></pre>
<p>&nbsp;</li>
<li>Now let&#8217;s extract the cacerts.bks to a human readable format (there are other ways of reading bks files, but this is an easy route)</li>
<p>&nbsp;</p>
<pre><span style="color: #333399;">%android-sdk%\tools&gt;"%JAVA_HOME%\keytool.exe" -keystore</span></pre>
<pre><span style="color: #333399;">cacerts.bks -storetype BKS -provider org.bouncycastle.jce</span></pre>
<pre><span style="color: #333399;">.provider.BouncyCastleProvider -storepass changeit -v</span></pre>
<pre><span style="color: #333399;">-list &gt; calist.txt</span></pre>
<p>&nbsp;</p>
<li>Open the newly created calist.txt file and search for the desired CA Cert ( DigiNotar CA in our case). You&#8217;ll want to identify the alias name number. You&#8217;ll use this to identify the certificate so that you can remove it with keytool.exe:</li>
<p>&nbsp;</p>
<pre>*******************************************
<span style="color: #ff0000;">Alias name: 61</span></pre>
<pre>Creation date: Feb 8, 2011</pre>
<pre>Entry type: trustedCertEntry</pre>
<pre>Owner: C=NL,O=DigiNotar,CN=DigiNotar Root CA,E=info@diginotar.nl</pre>
<pre>Issuer: C=NL,O=DigiNotar,CN=DigiNotar Root CA,E=info@diginotar.nl</pre>
<pre>Serial number: c76da9c910c4e2c9efe15d058933c4c</pre>
<pre>Valid from: Wed May 16 17:19:36 UTC 2007</pre>
<pre>until: Mon Mar 31 18:19:21 UTC 2025</pre>
<pre>Certificate fingerprints:</pre>
<pre>MD5:  7A:79:54:4D:07:92:3B:5B:FF:41:F0:0E:C7:39:A2:98</pre>
<pre>SHA1: C0:60:ED:44:CB:D8:81:BD:0E:F8:6C:0B:A2:87:DD:CF:81:67:47:8C</pre>
<pre>Signature algorithm name: SHA1WithRSAEncryption</pre>
<pre>Version: 3
*******************************************</pre>
<p>&nbsp;</p>
<pre><span style="color: #333399;">%android-sdk%\tools&gt;"%JAVA_HOME%\bin\keytool.exe" -keystore</span></pre>
<pre><span style="color: #333399;">cacerts.bks -storetype BKS -provider org.bouncycastle.jce.</span></pre>
<pre><span style="color: #333399;">provider.BouncyCastleProvider -storepass changeit -v -delete</span></pre>
<pre><span style="color: #333399;">-alias <span style="color: #ff0000;">&lt;alias name number&gt;</span></span></pre>
<p>&nbsp;</p>
<p>For example:</p>
<pre><span style="color: #333399;">%android-sdk%\tools&gt;"%JAVA_HOME%\bin\keytool.exe" -keystore</span></pre>
<pre><span style="color: #333399;">cacerts.bks -storetype BKS -provider org.bouncycastle.jce</span></pre>
<pre><span style="color: #333399;">.provider.BouncyCastleProvider -storepass changeit -v</span></pre>
<pre><span style="color: #333399;">-delete -alias <span style="color: #ff0000;">61</span></span></pre>
<p>&nbsp;</p>
<p>You&#8217;ll probably want to repeat this process for the Comodo certificates as well if you&#8217;re really security minded (of course you are).</p>
<li>Once you&#8217;ve removed the certificate you can push the cacerts.bks back to your phone for usage:</li>
<p>&nbsp;</p>
<pre><span style="color: #333399;">%android-sdk%\tools&gt;adb remount</span></pre>
<p>&nbsp;</p>
<pre><span style="color: #333399;">%android-sdk%\tools&gt;adb push cacert.bks /system/etc/security/</span></pre>
<p>&nbsp;</p>
<li>The final step will require you to reboot your phone so that Android can reload the cacerts.bks.</li>
<li>Enjoy!</li>
</ol>
<p>&nbsp;</p>
<p>If you have root access and don&#8217;t feel like going through ADB and all the SDK installation, the GuardianProject has created an Android app (<a title="Android Market - CACertMan" href="https://market.android.com/details?id=info.guardianproject.cacert">CACertMan</a>) that is targeted at doing the above for you and letting you manage your certs yourself. You can check it out <a title="GuardianProject CACertMan" href="https://guardianproject.info/2011/09/05/cacertman-app-to-address-diginotar-other-bad-cas/">here</a>. It is still in beta and isn&#8217;t 100% compatible yet, hence the manual instructions above.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Removing+Trusted+Certificates+from+Android+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D3001" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/3001/removing-trusted-certificates-from-android&amp;t=Removing+Trusted+Certificates+from+Android" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/3001/removing-trusted-certificates-from-android/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Certification Authorities Behaving Badly</title>
		<link>http://securitymusings.com/article/2969/certification-authorities-behaving-badly</link>
		<comments>http://securitymusings.com/article/2969/certification-authorities-behaving-badly#comments</comments>
		<pubDate>Tue, 30 Aug 2011 14:59:06 +0000</pubDate>
		<dc:creator>Peter Hesse</dc:creator>
				<category><![CDATA[data protection]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[DigiNotar]]></category>
		<category><![CDATA[PKI]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[TLS]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=2969</guid>
		<description><![CDATA[edited September 2 with an update on Apple/Safari. Another case of a certification authority (CA) issuing a certificate they never should have has surfaced. You may remember when we discussed the Comodo incident earlier this year. Now, a certificate issued by DigiNotar has surfaced in the wild, being valid for *.google.com &#8211; meaning it could [...]]]></description>
			<content:encoded><![CDATA[<p><em>edited September 2 with an update on Apple/Safari.</em></p>
<p>Another case of a certification authority (CA) issuing a certificate they never should have has surfaced. You may remember when we discussed the <a href="http://securitymusings.com/article/2639/did-comodo-violate-its-own-practices">Comodo incident</a> earlier this year. Now, a certificate issued by <a href="http://www.diginotar.com">DigiNotar</a> has surfaced in the wild, being valid for *.google.com &#8211; meaning it could be used to secure any transaction with any Google web property, including <a href="http://www.gmail.com">GMail</a>. According to <a href="http://pastebin.com/SwCZqskV">this pastebin post</a>, this certificate &#8220;is being used in the wild against real people in Iran *right* now.&#8221; DigiNotar has <a href="http://www.vasco.com/company/press_room/news_archive/2011/news_diginotar_reports_security_incident.aspx">issued a statement</a>. Here is some information about why this is bad, and what steps you should take to remove this issuer from your trust lists.<span id="more-2969"></span></p>
<p><strong>What does this mean?</strong></p>
<p>SSL, or TLS, is used to perform two things. First, it provides authentication of the web server to the web browser. (It can optionally provide authentication of the browser to the server, too, but that&#8217;s less common.) This means that the web browser knows that it is talking to a trusted web server and can share sensitive information with it. Second, it provides transport-layer encryption, so that the communications between the web browser and the web server are encrypted. This means that other parties cannot read what is being sent between the server and browser. This is widely used for most logins, because you don&#8217;t want your username and password being sent to the server &#8220;in the clear&#8221;. Anything sent &#8220;in the clear&#8221; can be read by anyone else on your network (or within range of your wireless network), or by anyone on any network that your traffic is routed through between you and the server.</p>
<p>In this case, a fraudulent certificate has been issued for *.google.com by a certification authority which is completely trusted by most modern web browsers. This means that the web browser will see this certificate, consider it valid for all traffic with Google (and GMail), and go ahead and create that little lock icon everyone has been trained to look for, which indicates your communication is secure.</p>
<p>Except, it&#8217;s not.</p>
<p>Google does not own this certificate. Google did not pay for this certificate. Therefore, when you communicate using this certificate, it&#8217;s not with Google. It&#8217;s with whoever managed to get that certificate issued, which according to the pastebin, is by groups wishing to do harm to individuals in Iran.</p>
<p>Personally, I don&#8217;t want to take a chance on whether it might be used against me, as well.</p>
<p><strong>What should I do about it?</strong></p>
<p>It is my opinion that issuance of a certificate such as this is an unforgivable sin.  Certification authorities must have the appropriate technical controls, and checks and balances, to prevent this from <strong>ever</strong> happening. There are plenty of certification authorities out there, and it is time to remove this one from my system and all systems I manage.</p>
<p>The good news is that the browser manufacturers also think this is a bad thing and are rushing to put together information on how to ensure you won&#8217;t trust this certificate.</p>
<ul>
<li><a href="http://blog.mozilla.com/security/2011/08/29/fraudulent-google-com-certificate/">Mozilla is updating Firefox, Seamonkey, Thunderbird, and others to remove this</a>; they also provide a <a href="http://support.mozilla.com/en-US/kb/deleting-diginotar-ca-cert">link for manual removal</a>.</li>
<li>Apple hasn&#8217;t stepped up with information about it yet that I can find. If you&#8217;re running a Mac OSX machine, you should set your system to never trust the Diginotar certificate. Run <strong>Keychain Access</strong>, and on the left choose your &#8220;login&#8221; keychain. Down below, choose &#8220;All Items&#8221;. Then in the search box, search for DigiNotar. You should see one or two results for DigiNotar Root CA. Double-click it. Expand the <strong>Trust</strong> arrow, and where it says &#8220;When using this certificate:&#8221; choose <strong>Never Trust</strong>. Close the window and you will likely be prompted to enter your password to update the login keychain. Repeat for all occurrences of DigiNotar certificates. <strong><span style="color: #ff0000;">Update: It&#8217;s worse than I thought. This method does not work for EVSSL certificates in Safari. See </span><span style="color: #ff0000;"><a href="http://news.techworld.com/security/3300602/apple-mac-os-x-unable-to-revoke-ssl-certificates-properly/">this link</a> for more information</span><span style="color: #ff0000;">. Stay tuned for any updates Apple might make about this, a patch to Safari is probably necessary.</span></strong></li>
<li><a href="http://www.microsoft.com/technet/security/advisory/2607712.mspx">Microsoft tells you you&#8217;re protected</a> if you&#8217;re running Vista or later. If you&#8217;re not and still running XP or Windows 2000/2003, you should remove the certificate manually. The easiest way to do this is to launch Internet Explorer, and choose Tools-&gt;Internet Options. (Or just launch &#8220;Internet Options&#8221; from your control panel.) Go to the Content tab and click the Certificates button. Click the Trusted Root Certification Authorities tab. Find the DigiNotar Root CA and double-click it. (If it&#8217;s not there, you&#8217;re safe!) Click the Details tab and click the Edit Properties&#8230; button. Choose <strong>Disable all purposes for this certificate</strong> and click OK.</li>
<li>Google Chrome users, you will benefit from the rapid updates to Chrome which will <a href="http://codereview.chromium.org/7795014">mark DigiNotar as untrusted</a>. You can (should?) also take the Apple or Microsoft manual removal steps above to be sure you&#8217;re safe.</li>
</ul>
<p>Additional good commentary (as always) from <a href="http://twitter.com/moxie__">Moxie Marlinspike</a> and <a href="http://twitter.com/ioerror">Jacob Appelbaum</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Certification+Authorities+Behaving+Badly+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D2969" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/2969/certification-authorities-behaving-badly&amp;t=Certification+Authorities+Behaving+Badly" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/2969/certification-authorities-behaving-badly/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Apricorn Aegis Padlock Review</title>
		<link>http://securitymusings.com/article/2937/apricorn-aegis-padlock-review</link>
		<comments>http://securitymusings.com/article/2937/apricorn-aegis-padlock-review#comments</comments>
		<pubDate>Mon, 15 Aug 2011 12:46:48 +0000</pubDate>
		<dc:creator>Laura Raderman</dc:creator>
				<category><![CDATA[cool]]></category>
		<category><![CDATA[data protection]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=2937</guid>
		<description><![CDATA[Disclaimer: I requested and received an evaluation version of the Apricorn Aegis Padlock. I was sent the 250GB AES-256 version, and I need to return it to the company in 30 days. This is a pretty sweet hard drive, but there are a few annoyances that I think can be improved upon. I was unable [...]]]></description>
			<content:encoded><![CDATA[<p>Disclaimer: I requested and received an evaluation version of the <a href="http://www.apricorn.com/products/hardware-encrypted-drives/apricorn-padlock-256-bit-aes-encrypted-usb-drive.html">Apricorn Aegis Padlock</a>. I was sent the 250GB AES-256 version, and I need to return it to the company in 30 days.</p>
<p>This is a pretty sweet hard drive, but there are a few annoyances that I think can be improved upon. I was unable to test a few things just due to the time I could devote to this, the fact that I need to return the drive in working condition, and that I don&#8217;t have access to some specialized hardware to test timing attacks.</p>
<p>The drive is FIPS 197 validated &#8211; aka, uses AES according to NIST.</p>
<p>You can check out Apricorn&#8217;s site for the specs and details, but what you see on the product site is pretty much what you get. The drive draws power from your USB port, so you&#8217;ll need a powered port. The drive came with an adapter (1 USB to 2 USB) if one of your USB ports doesn&#8217;t provide enough power. I had no issues with power on my MacBook Air, but I did on my office desktop since all USB ports were already taken &#8211; easily solved with a powered USB hub.</p>
<p><strong><span id="more-2937"></span></strong>The drive comes formatted for Windows, but my mac helpfully formatted it for me once I said &#8220;yes&#8221; to &#8220;Use this as a Time Machine drive?&#8221; The quick start sheet in the box also provides Mac formatting instructions. The actual manual is already on the drive, and my mac helpfully erased it for me during formatting. However, the &#8220;Support&#8221; section of the website has the full manual available for download. At first, you really want to have the full manual available (and not on the drive).</p>
<p>The drive has the capability to have an administrator PIN and up to 9 &#8220;user&#8221; PINs. Knowledge of the admin PIN can wipe the user PINs, but not change them &#8211; only users can change their PINs. The different PINs do not allow access to different parts of the drive. All PINs have access to the entire drive. PINs can be anywhere between 6 and 16 digits, the default admin PIN is 123456 and there are no user PINs. There is &#8220;drive wipe&#8221; protection, but it&#8217;s pretty lame, and wouldn&#8217;t meet most corporate policies (complaint #1). After 6 invalid PIN attempts, the drive needs to be unplugged before you can try 6 more attempts. Once you&#8217;ve gotten to 50 attempts, you have to type in a (hardcoded) PIN to try 50 more times (you still have to unplug every 6 tries). Only after 100 total attempts will the drive &#8220;wipe&#8221; itself. Given how long the wipe took during this testing, it&#8217;s probably only wiping the keys, not the whole drive (but the manual doesn&#8217;t say this is the case). While annoying, certainly not insurmountable for someone who&#8217;s really determined, but a brute force for a 6 digit PIN (the minimum) is 10^6 &#8211; well over 100, so unless the attacker has some prior knowledge, the drive will likely wipe first.</p>
<p>Basic operation is plug in drive, enter a valid PIN (user or admin) and the drive mounts &#8211; decrypted. When you&#8217;re done, unmount the drive from your OS, and unplug the drive. Until you unplug the drive, the data is still decrypted (complaint #2).</p>
<p>The administrative &#8220;interface&#8221; works, but it&#8217;s pretty complicated &#8211; hence my suggestion to keep the manual handy until you&#8217;ve got the hang of it. All commands are sent using a keypress combination or sequence. Granted, the primary interface is a keypad with a &#8220;cancel&#8221; and a lock icon in addition to the 10 digits, and you&#8217;re limited a bit. I had some trouble creating user PINs, but it seemed intermittent, so I blame it on user error instead of anything the drive did (or didn&#8217;t do).</p>
<p>If you forget your PINs, you&#8217;re SOL (which is as it should be &#8211; in most cases). You can reset the drive back to factory settings &#8211; again, the &#8220;wipe&#8221; is just a wipe of the keys and partition table based on the time it took. This is great for most uses, but I can see corporate folks leery about this because if a user forgets their PIN (or tries to reset their drive themselves), the company&#8217;s just lost a lot of data. The admin PIN is supposed to protect against that and as long as help desk/etc. keep that PIN, they&#8217;re safe from all but others resetting the drive.</p>
<p>The keypad is supposed to be wear resistant &#8211; but in the two weeks I had the drive, I can&#8217;t test that, but it feels sturdy, and the digits seem to be embedded in the rubbery keys.</p>
<p>The casing appears sturdy and no obvious screws (they&#8217;re probably under the rubber feet), but since I have to return it in working condition, I didn&#8217;t try too hard to break the case. There is no special padding or ruggedness to the case that you wouldn&#8217;t see in an unencrypted external drive case. However, the product page claims some protection from drops (I&#8217;ve found that most external drives can handle a small drop).</p>
<p>There&#8217;s also VTC (Variable Time Circuit) technology, which I&#8217;ve never heard of, but apparently helps to thwart timing attacks &#8211; again, not something I can test, because I don&#8217;t have the equipment (or time).</p>
<p>It&#8217;s pretty easy to use, and I used it almost daily for two weeks &#8211; mostly for play, since I don&#8217;t have a real need for external drives (except Time Machine). The drive is on my wish list, but until I get my house sold, we&#8217;re on a spending moratorium at home. It&#8217;s really not that expensive relative to unencrypted drives &#8211; the AES-256 250GB drive is listed at $109. There&#8217;s a 3 year warranty on the drive, which covers the drive and the casing.</p>
<p>The drive&#8217;s a bit slower than your typical external drive, but I expected that. An initial Time Machine backup of 198GB took 4.5 hours. I was using the computer while it was backing up, so that could have impacted the performance. For most uses, you won&#8217;t notice much of a difference &#8211; unless you&#8217;re moving a *lot* of data that has to be encrypted on the drive.</p>
<p>There are a few annoyances, but they&#8217;re really just annoyances.</p>
<p>1: Having to unplug the drive to lock it. There&#8217;s already a cancel button, why not use that for a &#8220;lock&#8221; button. As long as the drive is receiving power &#8211; say, while the computer has the screensaver turned on, the drive remains decrypted. Now, someone can&#8217;t easily read the drive if the screen is locked, but if someone doesn&#8217;t lock their screen? It&#8217;s available. There&#8217;s also no &#8220;timeout&#8221;. I can see why &#8211; as long as the OS has the drive mounted, it could be in use. I wonder if it&#8217;s possible for the drive to detect that it&#8217;s been unmounted and lock itself after a pre-determined time.</p>
<p>2: It&#8217;d be nice to have a configurable wipe after X attempts capability &#8211; or at least wipe after 10-15 attempts, which would cover most corporate policies.</p>
<p>3: I would love to see a Kensington style laptop lock on the drive case. The data may be protected if someone steals the drive, but it&#8217;s annoying. As I can see this drive going along to the library/coffee shop/etc. with the laptop, it&#8217;d be nice if there were some physical way to lock the drive either to the table or to the laptop. You should never leave your laptop/data/&#8221;stuff&#8221; unattended in public places, but a lot of people do it.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Apricorn+Aegis+Padlock+Review+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D2937" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/2937/apricorn-aegis-padlock-review&amp;t=Apricorn+Aegis+Padlock+Review" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/2937/apricorn-aegis-padlock-review/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Encrypt your portable devices</title>
		<link>http://securitymusings.com/article/2924/encrypt-your-portable-devices</link>
		<comments>http://securitymusings.com/article/2924/encrypt-your-portable-devices#comments</comments>
		<pubDate>Thu, 04 Aug 2011 20:45:47 +0000</pubDate>
		<dc:creator>Benjamin Hartley</dc:creator>
				<category><![CDATA[data protection]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[Technology & Tool Thursday]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=2924</guid>
		<description><![CDATA[I just recently bought a new netbook. Now, I know that netbooks are supposedly on the way out, but I love the low price, long battery life, and massive portability. But there’s a problem with netbooks and security. They’re massively portable – whether the person doing the porting is me or a thief. I do [...]]]></description>
			<content:encoded><![CDATA[<p>I just recently bought a new netbook. Now, I know that netbooks are supposedly on the way out, but I love the low price, long battery life, and massive portability. But there’s a problem with netbooks and security. They’re massively portable – whether the person doing the porting is me or a thief. I do my best to keep my netbook safe, but being realistic I’ll admit that it could happen.</p>
<p>Now, the biggest loss from someone stealing my netbook is in data; the hardware really isn’t all that expensive. My netbook doesn’t just contain personal information; it’s also full of important business data. I can and do perform regular backups to make sure I don’t lose any of the data, but I don’t want anyone else reading what I’ve got, either.</p>
<p>That’s where file encryption comes in. If properly encrypted, my data won’t be accessible even if someone has the hard drive. So, with that in mind, I’m looking at three different utilities for encrypting my drive:</p>
<p><a href=http://www.truecrypt.org/>TrueCrypt</a> – TrueCrypt is kind of the grand-daddy of Whole Disk Encryption; it&#8217;s currently on release 7. Being free for download, it’s rather popular. It offers a range of features, including the ability to perform whole disk encryption, and the ability to create hidden volumes and hidden operating systems, meaning that even if you’re compelled to divulge passwords, your attacker won’t know about these volumes and thus won’t know to get access to them.  In addition, TrueCrypt comes with a pretty impressive set of encryption algorithms, including AES-256.</p>
<p><a href=http://www.axantum.com/axcrypt/>AxCrypt</a> – Another piece of freeware, AxCrypt doesn’t offer quite as much as TrueCrypt. Unlike TrueCrypt, AxCrypt exists for encrypting files and doesn’t have a whole disk option. Also, it’s limited to AES-128 which is not bad but certainly not as secure as 256. It seems to have a bit more open UI, however, letting users execute scripts on it. It’s also more oriented toward online shares and network storage – so if you want to put encrypted files on online repositories, AxCrypt may be the one for you.</p>
<p><a href=http://www.symantec.com/business/whole-disk-encryption>PGP</a> – The third tool I’ve been looking at is Symantec’s PGP. Unlike the other two, PGP costs – roughly 90USD per license. What do you get for $90? Well, it looks like it’s not a bad piece of software. As with TrueCrypt, Whole Disk Encryption is an option. It also has centralized management options, so it seems the best of the three for large-scale implementations. In addition, it has a host of certifications, notably FIPS 140-2 compliance. If you’re in an environment where that’s required, this is likely the way to go.  While the online information is not immediately forthcoming on encryption algorithms, FIPS-140-2 compliance means that at minimum it offers AES-128.</p>
<p>For my purposes, I’m likely going to use TrueCrypt. AxCrypt and PGP both have their place. But the most important thing? Implement something. It’s easy to put off such a step, but you never know when your mobile device might be lost or stolen.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Encrypt+your+portable+devices+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D2924" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/2924/encrypt-your-portable-devices&amp;t=Encrypt+your+portable+devices" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/2924/encrypt-your-portable-devices/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

