Thursday, 27 January 2011

But I'm Tryin', Ringo

The Path of the Righteous



Jules in Pulp Fiction is having a hard time interpreting Ezekiel 25:17, as three conflicting analyses compete for his approval. And this morning, one month after Microsoft's Cloud Data Breach, we find ourselves in a perfectly analogous quandary. How to interpret this Windows Azure spam promotional email from Reading?

Come in We're Still OPEN

At first I thought they were trying to reassure me, that despite the forementioned breach of customers' confidential data security, "We're still trading! Yes I know, it's incredible! We're still in business!"

Then, Colleague P suggested it might instead indicate the ongoing status of that breach: "Customer data still available! We're still w-i-d-e open!"

But that shit ain't the truth. The truth is - upon subsequent, more sober reflection - that the intended interpretation (becoming clear only after you read into it at least a little further) is just this: "We are open 24/7/365." Still open, in other words, during holidays.

Windows Azure: We're Still Open. What an odd email to receive, as Tweeter CloudClip-Azure muses. You can't help bracing yourself for the inevitable and apparently imminent follow-up promotion. Windows Azure: Closing Down Sale.

A famous advertising campaign in the mid-1980s, by the now defunct British Rail, and sporting the tag line We're Getting There, was universally ridiculed from its launch day. This Azure email campaign seems almost as easily avoidable a case of foot-in-mouth as that one.

Wednesday, 26 January 2011

Your Fave Browser

An Arresting Ambiguity

Today's "Technology" sidebar has a new number one, which caught my attention:
Parallel Programming with .NET
- Parallel Computing Virtual Labs on MSDN
Clicking through to Stephen Toub's introduction, I'm immediately whisked along by his infectious enthusiasm:
Interested in trying out the support for parallel computing in Visual Studio 2010 or .NET 4, but don’t have either installed? No problem. You can now use the MSDN Virtual Labs site to try these out from the comforts of your favorite browser.
All right! Actually I do have both installed, but no matter, this looks like fun. My favourite browser is currently Firefox, so I should be able to right-click, Open Link in New Tab, then launch one of the five parallel computing virtual labs on offer...


Okay, so I guess that answers that whole question about "how can they do that without ActiveX?" They can't. But the part I hadn't realised before, is that whenever a Microsoft guy says your favorite browser, he means IE6!

Tuesday, 25 January 2011

Security Digest #16

A Time Of Contrasts

The first story from January's Security and Privacy archives is reminiscent of a certain Wikileaks / Facebook platitude, recently memed via Saturday Night Live's Bill Hader, speaking in the persona of Julian Assange (emphasis mine):
I give you private information about corporations.
For free.
And I'm a villain.
Mark Zuckerberg gives your private information to corporations.
For money.
And he's Man of the Year.

Honour Among Hackers

All of which leads us to consider these several and various attitudes towards device jail breaking, as recently exhibited by Apple, Sony, and Microsoft.

Apple tried first in 2009 to have the jail breaking of the iPhone ruled illegal under America's Digital Millennium Copyright Act (DMCA). The land of the free disagreed, and in July 2010 went further by declaring there was "no basis for copyright law to assist Apple in protecting its restrictive business model." The iPhone was of course first hacked by George Hotz...

Next up came Sony, in the wake of the 27th Annual Chaos Communication Congress and the comprehensive obliteration of its PS3 security system, at the hands firstly of the fail0verflow group, and the subsequent samurai sword strike from the hand of... George Hotz. Sony's response, described by the Electronic Frontier Foundation as "sending a dangerous message to researchers and gamers", was to sue everyone involved. Not only with the DMCA hammer, but also with a highly creative slew of Computer Fraud and Abuse claims.

Finally, having already leaked details of their upcoming fix for the ChevronWP7 hack, Microsoft - predictably enough - reacted to a post by who-else-but George Hotz, threatening next to break Windows Phone 7 "in a way they won't like". The reaction of this particular giant multinational corporation was...

...to offer the hackers free T-shirts. And a free phone. Also, to offer a meeting, for the purpose of discussing how Microsoft might in future support “homebrew” apps, in a way that benefits all parties.

This just might turn out to be a very shrewd way to start building a much needed, fiercely loyal, customer base.

Photo source: istartedsomething.



The Hack List 2010


PCWorld Magazine's Business Center carries Tim Greene's report on the Top 10 Web Hacking Techniques of 2010, as voted by a panel of experts and open voting:
  1. Padding Oracle Crypto Attack
  2. Evercookie
  3. Hacking Autocomplete
  4. Cache Injection HTTPS Attack
  5. CSRF Bypass via ClickJacking / HTTP Parameter Pollution
  6. IE8's Universal XSS
  7. HTTP POST DoS
  8. JavaSnoop
  9. Firefox CSS History Grab
  10. Java Applet DNS Rebinding
#1 was covered previously in my Twenty Questions post. For useful details on the rest, see Tim's article. The list was sponsored by Black Hat, OWASP and White Hat Security, and will be the subject of a presentation at IT-Defense 2011 conference in Germany next month.


McCloud

M'learned colleague Scale This! draws attention to the ITProPortal story, Microsoft Suffers Cloud Data Breach, with the comment that it's really about web app security. Backtrack to PCWorld, where we find Microsoft Cloud Data Breach Heralds Things to Come.

The issue, it emerges, has nothing to do with hacking, legal or otherwise. It's been a simple matter of misconfiguration of BPOS. Nothing uniquely cloudy about that, aside from the prevailing weather conditions above the head of some poor IT guy somewhere.

It may indeed be a herald of things to come. Maybe in today's computer journalism, "The Cloud" is already interchangeable with "The Server"?


That's January's wrap.

Conficker: Mission Accomplished

"Complete Success" (Patient Dead)

Between 2008 and 2010 the Conficker Working Group (CWG), a heterogeneous association of researchers in computer security, studied and fought against the eponymous malicious software worm. When that process got under way, in 2009 the US Department of Homeland Security's Science and Technology Directorate set up and funded a project designed to preserve a permanent record of the "Lessons Learned" - the hope being that a template could be discerned for subsequent application in similar situations.

The Rendon Group conducted that research, working independently, interviewing members of the CWG and constructing the definitive account of their experience and findings. Yesterday they published their report (PDF).

Among the successes of the CWG, this document highlights the "unprecedented act of coordination and collaboration" between organizations and individuals around the world, in both the public and private sectors. Academic researchers, domain registry operators, AV vendors, ICANN, and the blue hats at Microsoft, joined in a "very successful" effort to pre-register and otherwise block domains from being used to update the malware. Essentially they cut off the worm's author from communicating with the botnet.

Remediation of infected computers is generally regarded as one of the most disappointing outcomes of the study, with millions of Conficker A and B infections still active.

Recommendations

The report's recommendations list the following urgent requirements "if the cyber security community is to stay ahead of impending threats":
  • private sector collaboration
  • public-private information sharing
  • support to law enforcement
  • resources
  • legislative reform
There is also much necessary detail on the thorny subject of how to manage such a group effort as it grows. What should the essential collaborative infrastructure look like? There appears to have been a consensus that "volunteers" should continue to do most of the work, with nobody wishing to exceed the figure of 4 or 5 paid, full time staff.

The report concludes that "The group as a whole saw little participation from the government. One person put it as zero involvement, zero activity, zero knowledge." Most tellingly, one interviewee remarked, "People put in hours of unpaid work on nights and weekends, often at the expense of their own free time or time with their family."

Today, at least eight working groups modelled on the CWG are busy tackling other threats. Some of these groups' efforts have already led to arrests. How long will commercial enterprise, banks, and credit card companies, continue to depend on such unpaid, idealistic armies of volunteers, to protect their profits from growing gangs of well-resourced and professionally organised thieves?

Sunday, 23 January 2011

Sunday Dinner

My Cod Here

This isn't just a sea food platter for two. This is Marks & Spencer citrus cured Loch Fyne gravadlax with honey and dill dressing, salmon flakes, dressed mozarella crab, prawns, spiced prawns, king prawns in seafood sauce, calamari, French stick, pinot noir, and champagne. The occasion? Well you see, it was a Sunday.

Oh and also, we had a day off work together (which hardly ever happens).

Photo by Linda. Click to embiggen its cromulent scrumptiousness.

Tuesday, 18 January 2011

Microsoft Security Essentials 2



It's been two or three weeks since Microsoft released, to no fanfare whatsoever, version 2 of Security Essentials (MSE), the beta (illustrated in the above video) having been available since July 2010. This is their free security solution for Vista and Windows 7. And yes, XP too. Although you won't find that fact advertised too prominently, there's a good argument saying that XP still represents the biggest nest of exploited vulnerabilities out there.

Superficially similar to its predecessor, September 2009's Morro (itself the successor to the subscription-based Windows Live OneCare), MSE2 offers real-time protection for "your home PC", guarding against malicious software such as viruses, worms, and various other malware / spyware. But in fact MSE2 offers quite a lot more in terms of integration, with for example IE, and Windows Firewall.

Network based exploits are defended against by the new Network Inspection System. Overall performance is improved, detection and cleanup capabilities enhanced. Then too, there's...
  • control of the maximum CPU usage during scheduled scans (default 50%);
  • automatic removal of quarantined files after a given time (disabled by default);
  • the option to opt out of Microsoft SpyNet (not recommended!);
  • fine grained control of real-time protection functionality.
OEMs may pre-install MSE2 on consumer-bound PCs, providing malware protection out of the box, at no cost. And needless to say, automatic updates are... erm, yes. Precisely.

Free download: http://www.microsoft.com/security_essentials/

Saturday, 1 January 2011

Tweets - December 2010