This past week at Defcon the social engineering capture the flag competition was hotter and more controversial than ever. Contestants were given their target company two weeks in advance for research purposes. During the actual competition contestants called employees at the target companies to gain sensitive information. The overall result: A big fat fail for the human element. As more companies begin to take security seriously budgeting for pen tests, equipment, etc. often the human element of security falls through the cracks. As shown at the Defcon competition, all the locks, both physical and network based, can’t stop an attacker if an employee ushers her through the door. The Social Engineering Competition was put on by Social-Engineer.org which is an[…]

Every year during the Black Hat conference, something crazy happens that makes me paranoid about things I use during my everyday life without really thinking too much about it.  Last year, it was the MD5 Collision Attack that allowed the attackers to create a rogue Certification Authority. This year, it’s ATMs.  A researcher by the name of Barnaby Jack developed his own custom rootkit for ATM machines that could be installed by dialing into the devices and exploiting the remote management software.  This rootkit allowed him to make the machines dispense money on command, which, I’m reasonably sure, is not how they are intended to function.  Lest you think this only allows the attacker to steal from the device and[…]

A colleague lent me his most recent copy of IEEE’s Computer magazine.  Inside was an article entitled A Web 2.0 Model for Patient-Centered Health Informatics Applications (IEEE membership required to read).  Some possible benefits of their proposed approach were listed, including: Run deeper analytics across physicians groups and facilities, which can include relevant patient data… Provide a wide community of health professionals with feedback on the use and effectiveness of protocols… Share similar and alternative protocols and their analyses across many medical facilities and individual providers… Anyone want to guess what’s completely missing from their approach?  You guessed it, any mention of security.  The commonly misunderstood (and frequently misspelled) HIPAA makes it pretty clear that the privacy and confidentiality of personal[…]

People are relieved. In what has quickly become one of the mainstream tech media’s darling stories of the day, the U.S. Library of Congress has apparently woken up to find itself a decade into the 21st century and has released an updated list of allowed circumventions that do not qualify for punishment under the Digital Millennium Copyright Act’s (DMCA) anti-circumvention clause. In a nutshell, you can rip (DeCSS) movie clips for fair use, you can jailbreak your iPhone (whether it be to install software or to hop providers), you can hack video games (for “good faith” security purposes, mind you, and consoles seem to be excluded), you can bypass hardware dongles that have become obsolete (fairly narrow ruling here), and[…]

Due to the way Android requires SD cards to be formatted in VFAT, it leaves a bit of a hole when it comes to security for files stored here. VFAT is an old standard that doesn’t support the access controls of Linux, so data stored here is unprotected.  Because of this, all storage here is shared with all programs on the device.  So storing sensitive information here isn’t going to be the best thing to do. With some devices having limited internal storage though, this might be your only option, or depending on what the data is, you may require large amounts of storage space. One way around this is to simply encrypt the data from within your application. This[…]