Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, 27 September 2013

iPhone 5s fingerprint scanner could be mobile security game changer

On Friday the iPhone 5s will be out on the street, and with it, Apple’s fingerprint scanning technology. There are still some concerns about how Apple is implementing and managing fingerprint authentication, but as long as the iPhone 5s doesn’t fumble completely, the new smartphone could finally spur mainstream adoption of the technology.

As Apple revealed a couple of weeks ago, the home button on the new iPhone 5s is also a fingerprint scanner. Rather than using a passcode, you can now unlock the device just by holding your finger on the home button.

Touch IDThe iPhone 5s includes a capacitive fingerprint scanner.

The iPhone 5s isn’t the first mobile device with a fingerprint scanner. The Motorola Atrix included fingerprint authentication back in 2011. Apparently, even Motorola forgot about the Atrix, though, because it had the audacity to send out a tweet slamming the idea of using a fingerprint with a mobile device.

Paul Henry, security and forensic analyst at Lumension believes that the iPhone 5s fingerprint authentication could prove to be a game changer. “There are two factors that will determine the real success of this new feature, which has undeniable potential,” he says. “First, reliability and second, security—though as a security researcher, I have to say it should really be security first.”

There are questions about how Apple is scanning and storing the fingerprint data. If someone guesses or compromises your passcode, you can just change it to a new one. But, you can’t change your fingerprints. Some worry that a thief can simply use an image or picture of your fingerprint gain access to a user’s iPhone, the same way Android’s facial recognition authentication can be fooled with a picture of the device owner. It wouldn’t be hard to get your fingerprint—your iPhone will likely be covered with dozens of samples.

Macworld contributor Rich Mogull does an excellent job explaining why that probably isn’t an issue. In a nutshell, Apple is using capacitive scanning that looks at more than just the image of your fingerprint, and it’s most likely not storing the actual fingerprint anywhere on the iPhone where it might be compromised.

Mogull hypothesizes that Apple is probably analyzing the fingerprint and using unique data from it to generate a mathematical representation or template. By this logic, when you touch the home button, your fingerprint is run through the algorithm again, and the results are compared to the template to ensure they match. These are educated guesses, though, and the actual implementation may work differently.

Touch IDApple revealed the details of the fingerprint scanner at the iPhone 5s launch event.

“What we need to know is how good a job did Apple actually do securing the biometric data,” Henry says. “They say it’s encrypted and not shared with other applications, but we’ll have to wait and see how it works in practice.”

Henry also has some concerns about just how much access someone gets if the fingerprint authentication is bypassed or compromised. “If a single fingerprint grants access to other services (particularly iCloud), that’s a frightening prospect if Apple hasn’t done a truly expert job at securing that local credential,” he says.

Dwayne Melancon, CTO for Tripwire, says, “In general, multifactor authentication is a good idea and biometrics, in particular, are good as long as they work properly. Early reports of Apple’s biometric implementation are promising, and even if there is some rate of false identification, this approach is still more secure than a four-digit PIN.”

One crucial thing for IT admins to understand is how device access works in the event that the fingerprint scanner is not an option. What if a user breaks their finger and it’s in a cast, or the home button fingerprint sensor malfunctions?

“From an enterprise perspective, I would wait until the security of this implementation of fingerprint scanning has been tested ‘in real life’ before adopting it broadly,” Melancon cautions.

Biometric security is nothing new, but it has yet to really catch on as a mainstream method of authentication. The password or passcode remains king. Apple has a huge market presence, though, and the iOS ecosystem commands a great deal of respect. If the iPhone 5s fingerprint scanner lives up to expectations, this could be the tipping point that turns it into the new default standard.

If Apple stumbles or falls on its face, though, it could set biometric security back a few years. If there are too many false negatives or false positives, or it turns out that the fingerprint data isn’t stored as securely as it should be, or there are other problems with the fingerprint scanner, it will tarnish the reputation of biometrics with average users, and it will take a long time to recover.

Tony is principal analyst with the Bradley Strategy Group, providing analysis and insight on tech trends. He is a prolific writer on a range of technology topics, has authored a number of books, and is a frequent speaker at industry events.
More by Tony Bradley


View the original article here

Tuesday, 24 September 2013

Old tricks help German hackers bypass iPhone 5s Touch ID security

Apple's Touch ID authentication system can be defeated using a well-honed technique for creating a latex copy of someone's fingerprint, according to a German hacking group.

The Chaos Computer Club (CCC), which hosts an annual hacking conference and publishes computer security research, wrote on its blog that their experiment shows that fingerprint authentication "should be avoided."

Apple introduced Touch ID with its latest high-end iPhone 5S on Sept. 10. A person's "fingerprint is one of the best passcodes in the world. It's always with you, and no two are exactly alike," according to the company's website.

A hacker who goes by the name Starbug found that while Touch ID scans at a higher resolution, it can be beaten by increasing the resolution of the victim's fingerprint.

The CCC posted a video of what it wrote is a successful attack. Faking the print involves photographing the victim's fingerprint at 2400 DPI. The image is inverted and laser printed at 1200 DPI onto a transparent sheet using a "thick toner setting," according to the CCC.

Pink latex milk or white wood glue is smeared into the pattern created the toner. After it cures, a sliver of latex is lifted from the sheet, and blowing on it gives a bit of moisture like that on a human finger. It then can be placed on the iPhone's fingerprint sensor, the CCC wrote.

The technique is not new. "This process has been used with minor refinements and variations against the vast majority of fingerprint sensors on the market," the CCC wrote. Apple officials did not have an immediate comment on the CCC's findings.

Security experts have long warned that fingerprint authentication should not be solely relied upon, but rather used in concert with other technologies. Photos of fingerprints and molds have successfully bypassed fingerprint checks.

Touch ID is intended to reduce the number of times a person must enter a passcode, but Apple still requires a passcode in some circumstances, such as restarting the phone and if the devices hasn't been unlocked in two days.

Changes to the fingerprint settings also require a passcode, which can be configured to be longer and more complex than four digits.


View the original article here

PC security, NSA-style: 7 tips from the spymasters

Was it really just a few months ago that your biggest computer-privacy concern was making sure your employer didn’t find the college photo of you sucking on a beer bong on your Facebook page? That seems cute now. With the recent revelations that the National Security Agency may have been involved in everything from spying on U.S. residents to cracking online encryption to collecting global financial data, computer privacy has taken on all the cloak-and-dagger intrigue of a John le CarrĂ© novel.

If you’re like most users, you take your privacy seriously. So we went right to the experts—the NSA itself—and pored over the agency’s security tips and recommendations for its Department of Defense and intelligence-community customers. From there, we identified seven measures that both consumers and small businesses can easily implement to protect themselves from hackers and cybercriminals—and perhaps even from the NSA.

It isn’t the coolest counterintelligence technique, but good security starts with the basics, and nothing is more basic than making sure that your operating system is up-to-date. So it’s no surprise that the NSA recommends enabling automatic updates in Windows.

Doing so is easy enough: First, simply navigate to System and Security from the Windows Control Panel. Click Turn automatic update on and off, and select Install updates automatically.

Recommended in the NSA’s rundown of security highlights in Windows 7 (PDF), BitLocker encryption is built into the Enterprise and Ultimate versions of Windows 7, as well as the Pro and Enterprise versions of Windows 8. When enabled, BitLocker encrypts all of the data kept on a storage volume, and it continues working in the background to protect the contents of a Windows PC from unauthorized access.

BitLocker is an excellent first line of defense that takes just a few clicks to enable. However, if you’re concerned that the full-disk encryption technology may have been compromised by a backdoor deal with the NSA (there is no evidence of that, so far), you can find plenty of alternative methods to encrypt your data.

Integrated webcams are great for video chats, but they’re also excellent tools for hackers to spy on users. And you would never know that you were being watched: Although the webcam indicator light is supposed to switch on when the camera activates, hackers have found ways to disable the light in certain laptop models.

According to the NSA, a simple, low-tech solution is to tape over your webcam—with black tape, naturally. If you’re worried that the sticky residue might damage the webcam, use tape to secure a small piece of paper over the lens.

SoundDisable your laptop’s built-in microphone to ensure that your private conversations stay private.

Just as your machine’s webcam can give hackers a window into your private world, your laptop’s built-in microphone—typically enabled by default—can fall prey to remote hijacking and allow snoops to eavesdrop on all conversations in its vicinity.

To ensure that no one can listen in on your home or office, launch the Sound applet from the Control Panel. Click the Recording tab, select your laptop’s built-in microphone, and disable it.

Of course, taking this step doesn’t prevent a malicious hacker who has already compromised your laptop from reenabling it. If you’re really paranoid, you can disable the built-in microphone permanently simply by poking it with the business end of a needle or paper clip. The espionage game has its casualties.

Although it’s impossible to lock out hackers completely, you don’t have to make their task any easier. Start by disabling network-related protocols and services that you don’t use, as attackers and snoops could exploit them to access your files and devices. For small businesses, such services will likely include IPv6, Bluetooth wireless, or even Wi-Fi, if you’re primarily using deskbound laptops connected via ethernet. And if you don’t share file and printer resources on your PC, be sure to disable sharing for additional security—a step that Microsoft recommends, as well.

Spend a few minutes tweaking your Windows account settings. Few security measures offer so much protection for so little effort. A good first step is to disable any guest accounts that are present, ensuring that a password is set for each account, and disabling automatic login.

If you use sleep mode, adjust your PC’s settings to require a password on waking up.

Next, enable a screensaver and set it to start with a reasonably short inactivity timeout of between 1 and 5 minutes. To do so, right-click the desktop, select Personalize from the menu, and click Screen Saver. Make sure to select the On resume, display logon screen checkbox. Obviously, you will need to have a password configured first for this step to work.

Finally, require that users reenter their system password if the PC has been inactive. Configure this option by clicking Power Options in the Control Panel and selecting Require a password on wakeup in the left column.

Web surfing on a user account with administrative rights is kind of like walking through a bad neighborhood with your house keys in one hand, your Social Security card in the other, and your ATM PIN written on your forehead. You’re offering up all kinds of sensitive personal information to eager takers.

Because of that risk, the usual advice is to avoid surfing the Web on an admin account to limit the damage if a zero-day exploit happens to compromise your account. Given the growing number of attacks launched via email messages, it’s a good idea to extend this precaution to your inbox by reading new email messages only on a nonadministrator account. This practice won’t protect you from phishing attempts that try to trick you into giving up your password, though, so be sure to stay on your guard against fake email messages, too.

While adhering to these tips will go a long way toward shielding you and your data from prying eyes, to secure your PC further be sure to check out our tips to avoid the most devious security traps, Prism surveillance, and watchers on the Web. We can’t promise that following these measures will make you spyproof, but you will certainly sleep better. Just remember to keep one eye open.

Paul has a lifelong affinity for checking out all sorts of tech gadgets, enterprise gear, and everything in between. With half a decade in the IT industry under his belt, He is especially interested in how technology can be practically leveraged to help businesses do more.
More by Paul Mah


View the original article here

Thursday, 12 September 2013

Lawmakers question security of health insurance hub days from launch

Less than three weeks before a massive U.S. government health information database is scheduled to go live, some lawmakers have significant concerns about the ability of the system to protect personal health records and other private information.

It’s unclear if security measures are in place at the U.S. Department of Health and Human Services’ health exchange data hub, a huge IT system that will process uninsured U.S. residents’ applications for health insurance, said Representative Patrick Meehan, a Pennsylvania Republican.

“I have grave concerns from a cybersecurity standpoint,” Meehan said on Wednesday during a hearing of the cybersecurity subcommittee of the U.S. House of Representatives Homeland Security Committee.

The data hub, scheduled to go live Oct. 1, will process names, dates of birth, Social Security numbers, health conditions, and several other pieces of personal information, Meehan said.

Other lawmakers raised similar fears about the hub, a key piece of the Affordable Care Act, often called Obamacare, passed by Congress in 2010. “The issue is not if but when we’re going to have a breach of the data hub,” said Representative Mike Rogers, an Alabama Republican.

But subcommittee Democrats noted that earlier this month the HHS Centers for Medicare and Medicaid Services (CMS) completed testing of the hub and received security authorization for the system. The security testing was established by the U.S. National Institute of Standards and Technology, according to CMS.

Representative Yvette Clarke, a New York Democrat, praised CMS for focusing on U.S. residents’ privacy. State-operated health care exchanges, allowing uninsured people to shop for insurance, “will function only if people are certain that their private information—medical and financial—will be protected,” she said.

Meehan questioned how CMS completed its security assessment nearly a month ahead of schedule after the agency had “for three years failed to meet a single deadline.”

Critics have long raised concerns that the hub will collect large amounts of health and other personal information, and a breach could cause significant problems for users. Officials with President Barack Obama’s administration have said the hub will store little information, instead accessing information in other databases as needed.

Data breaches at the hub would do “irreparable harm” to users, said Stephen Parente, director of the Medical Industry Leadership Institute at University of Minnesota. There hasn’t been enough security testing on the hub, which is a “massive IT project with literally no technical precedent,” he added.

Meehan on Wednesday repeated his concerns that the hub would make an attractive target for hackers. “We face a time in which we have very sophisticated adversaries ... who may wish to do us harm,” he said.

But Matt Salo, executive director of the National Association of Medicaid Directors, said directors of state Medicaid programs have been working to ensure that the hub will be secure as their systems exchange data with it.

Salo predicted the hub—which he called the Travelocity of health care insurance—will likely have a “turbulent” launch because of its size, but most of the problems will be related to its interface, not security. “The consumer experience will not be a smooth and seamless Travelocity,” he said. “We do not think security is going to be a primary concern on day one.”

Lawmakers should give the hub time to “work out the kinks,” Clarke added.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service.
More by Grant Gross, IDG News Service


View the original article here

Monday, 9 September 2013

IFA security stops man accused of stealing from trade show

Sorry, I could not read the content fromt this page.

View the original article here

McAfee unveils 2014 versions of Antivirus Plus, Internet Security, and Total Protection

McAfee announced Monday its 2014 product line of consumer antivirus and security products for the PC platform. All are available for download or retail purchase starting today.

McAfee AntiVirus Plus 2014 is priced at $34.99 for one year of protection for one PC. McAfee Internet Security 2014 costs $55.99 for use on up to three computers, and McAfee Total Protection 2014 costs $89.99 for use on up to three computers. McAfee is also updating the LiveSafe cross-platform security product it announced in the spring.

All of the upgraded products provide some basic protections. They all use McAfee's AM Core scanning engine to detect viruses, malware, Trojan horses, and their nefarious ilk in real time. McAfee claims to have faster scanning performance in AM Core as well, so it doesn’t hold up your computer's other operations. The new products also include McAfee Vulnerability Scanner to look for patches or updates to your installed programs.

McAfee Shredder comes with all three products, supplying a tool that completely deletes files and makes them unrecoverable. To prevent hackers and other unwanted intrusions, the products include a two-way firewall and network security, plus a My Home Network viewer to check for freeloaders on your connection. McAfee SiteAdvisor also comes with all three, and tells you whether a site you’re about to visit is known to be safe, suspicious, or downright dangerous.

Internet Security 2014 and Total Protection 2014 add parental controls including a usage report, activity monitoring, and site blocking. Both products also offer spam filtering.

Total Protection 2014 adds file encryption and wireless network security. The latter can protect your passwords and data even if you’re using an open, public network.

McAfee has long been a leader in antivirus and security software. Nevertheless, competition abounds, including capable freeware. The company says its AM Core malware scanning engine, introduced earlier this year, offers a competitive advantage because it can dynamically detect and fend off hostile software. Even simpler features like the McAfee Shredder seem like they'd be handy tools for routine PC housecleaning. We'll know more in a few months, when we embark upon our annual roundup of antivirus software.

The daughter of a mechanical engineer, Melissa grew up playing with machine parts and still loves getting into the nuts and bolts of how things work. She is never happier than when she is on a factory tour.
More by Melissa Riofrio


View the original article here

Saturday, 31 August 2013

Salesforce.com mobile app developers gain security tools

Good Technology has integrated its Dynamics Secure Mobility Platform with Salesforce.com's Mobile SDK to help developers build mobile applications that are more secure and easily managed.

The growing popularity of smartphones and tablets combined with the BYOD (bring-your-own-device) trend presents several challenges to IT departments, including developing mobile applications and then efficiently managing and protecting them. Salesforce.com's Mobile SDK (software development kit) helps with the former and Good's Secure Mobility Platform offers the latter.

[ Learn how to work smarter, not harder with InfoWorld's roundup of all the tips and trends programmers need to know in the Developers' Survival Guide. Download the PDF today! | Keep up with the latest developer news with InfoWorld's Developer World newsletter. ]

The goal with the integration is to make it easier for Salesforce.com developers to build apps compatible with Good's containerization technology, which offers features such as app-level encryption as well as compliance and jailbreak detection. Enterprises can also put in place data loss prevention and automated actions that lock and wipe applications without impacting a user's device or personal data, according to Good.

The Mobile SDK, which is available for Android and iOS, is a key part of Salesforce.com's accelerating mobile push. It lets developers choose between building applications directly for Apple and Google's OSes, web applications or so-called hydrid applications -- which make it possible to embed HTML5 apps inside a native container.

Recently, Salesforce.com announced version 2.0 of the SDK, which added the SmartSync data framework allowing developers to create applications that work with data both off and online.

Good isn't the only mobile management tool vendor that's working with Salesforce. On Tuesday, competitor MobileIron announced Anyware. The hosted enterprise mobility management service lets administrators distribute mobile apps to employees as well as manage their devices from the Salesforce administration console, MobileIron said.

Send news tips and comments to mikael_ricknas@idg.com.


View the original article here

Salesforce.com mobile app developers gain security tools

IDG News Service - Good Technology has integrated its Dynamics Secure Mobility Platform with Salesforce.com's Mobile SDK to help developers build mobile applications that are more secure and easily managed.

The growing popularity of smartphones and tablets combined with the BYOD (bring-your-own-device) trend presents several challenges to IT departments, including developing mobile applications and then efficiently managing and protecting them. Salesforce.com's Mobile SDK (software development kit) helps with the former and Good's Secure Mobility Platform offers the latter.

The goal with the integration is to make it easier for Salesforce.com developers to build apps compatible with Good's containerization technology, which offers features such as app-level encryption as well as compliance and jailbreak detection. Enterprises can also put in place data loss prevention and automated actions that lock and wipe applications without impacting a user's device or personal data, according to Good.

The Mobile SDK, which is available for Android and iOS, is a key part of Salesforce.com's accelerating mobile push. It lets developers choose between building applications directly for Apple and Google's OSes, web applications or so-called hydrid applications -- which make it possible to embed HTML5 apps inside a native container.

Recently, Salesforce.com announced version 2.0 of the SDK, which added the SmartSync data framework allowing developers to create applications that work with data both off and online.

Good isn't the only mobile management tool vendor that's working with Salesforce. On Tuesday, competitor MobileIron announced Anyware. The hosted enterprise mobility management service lets administrators distribute mobile apps to employees as well as manage their devices from the Salesforce administration console, MobileIron said.

Send news tips and comments to mikael_ricknas@idg.com

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Salesforce.com mobile app developers gain security tools

Sorry, I could not read the content fromt this page.

View the original article here

Lookout Antivirus & Security review: Basic protection for your Android phone

Lookout Security & Antivirus Free Lookout Security & Antivirus is a solid choice for families serious about mobile security, but you'll need to pay for a premium account in order to get the most out of the app.

Smartphones are a treasure trove of personal information and it doesn't take much for people who would mean you harm to get at all that sensitive data. While putting a PIN lock on your phone helps deter physical threats, you still have to keep an eye out for sneaky apps that want your private info. Lookout Security & Antivirus is a security app that helps defend your phone against all kinds of evildoers, but you'll have to pay if you want comprehensive protection.

Lookout is available for free from the Google Play Store and offers both free and premium account levels. Signing up for a free account gives you access to all the basic tools, like a virus scanner and the ability to locate your phone remotely.

Lookout's privacy advisor gives you an at a glance look at which apps are accessing your information.

If you decide to pay $3 a month, you'll get access to a privacy advisor that breaks down what information each app has access to. It's basically a simplified version of Google's permissions warning that pops up whenever you install an app, but Lookout presents the information in a way that's easier to digest. Lookout Premium also gives you a safe browsing tool that warns you if you're going to a known malicious website in your phone's browser.

Lookout's virus scanner automatically runs whenever you install a new app, and you can set it to scan your entire phone during certain times or initiate scans manually. According to data provided by AV-Test, a well-respected antivirus testing outfit, Lookout has a malware detection rate of 99 percent. The app compares favorably to other Android security apps and is ranked as the fourth best security app by AV-Test. In all the years I've used Lookout, I've never actually had the app alert me that it had detected malware, though—you're more likely to find a legit app that violates your privacy instead of one that carries a trojan.

A major downside to having Lookout run whenever you install an app is that it can slow down your phone—especially if you are installing multiple apps at once and aren't using a high-end phone like the HTC One or Samsung Galaxy S4. Having the virus scanner run in the background doesn't seem to adversely affect battery life, but if you're really worried about it you can set it so it doesn't activate each and every time you download an app.

Even if you don't decide to sign-up for Lookout Premium, the app is worth installing for its ability to remotely locate your phone. By logging into Lookout.com, you can see your phone's location on a map and even make it "scream" to make it easier to locate. The scream is helpful if you misplaced your phone at home, but it's disappointing that the two more useful options (remote lock and remote wipe) require you to have a premium account. The app can also send up a "flare" and email you its last registered location if the battery is starting to run low or the phone dies. Again, it's a helpful tool if your sofa ate your phone, but it isn't much use if some thief snatched it from your hands.

The remote wipe and remote lock options are sadly only available for paying customers.

The free version of Lookout only offers basic protection, but it's a solid app that provide some piece of mind as you navigate the murky waters of the Google Play Store. Other security apps like TrustGo Mobile Security offer many of the same features that Lookout locks behind its premium service for free, making them better for individual users worried about their phone's safety. Lookout is a better choice for families, however, as you can use a single Lookout account to manage and track multiple devices at once. Just make sure to put a PIN lock on your phone if you choose against paying for a subscription.


View the original article here

Friday, 30 August 2013

Java security will be in the spotlight at JavaOne

Java security will be in the spotlight at JavaOne

If Oracle's JavaOne show plans are any indication, the company is very serious about educating developers on how to make their Java applications secure.

Sessions planned for next month's annual Java technical conference include "Dissecting Java Malware," "The State of Java Web Container Security," and "One Year of Security Enhancements in the JRE (Java Runtime Environment)." One session description, for a talk entitled, "Java Security: Bringing Trust to Your Java Application," flat out acknowledges the bad press Java has been receiving lately. "Recently there has been a lot of press about Java vulnerabilities and security -- giving Java a bad rap," the description reads. "The reality is that the Java platform and language were built with security in mind." This session is to be conducted by a VeriSign employee.

Java's security maladies have included zero-day vulnerabilities, such as arbitrary, unsecure class loading in Java SE (Standard Edition). Some experts advised uninstalling Java plug-ins in browsers to boost security. Java's travails even prompted a bulletin from the US Department of Homeland Security earlier this year. JavaOne actually features a session entitled "Anatomy of a Java Zero-Day Exploit," to be conducted by an engineer from Carnegie-Mellon.

Oracle, for its part, has been quick to issue security patches for Java and has advised users to upgrade to the latest Java versions. Oracle, which inherited the stewardship of Java when the company acquired Sun Microsystems early in 2010, will continue Java security damage control at JavaOne. The conference is being held in San Francisco from Sept. 22-26, concurrent with the Oracle OpenWorld conference.

Besides security, other JavaOne highlights scheduled include a focus on developing Java applications for the Microsoft Windows Azure cloud, with a Microsoft official conducting a session on it. Coding for desktop and mobile via HTML5 and Java EE 7 also will be covered, as will JavaScript on the JVM (Java Virtual Machine) via the Nashorn project, and developing with Java for Apple iOS and Google Android via Oracle ADF (Application Development Framework).

Attendees also will have the opportunity to meet Oracle's Java language team and look into the "JVM Crystal ball," as one session description puts it. NoSQL database technology will be examined at the conference, along with other JVM languages, such as Groovy and Scala. Red Hat and Oracle officials will conduct a session on interoperability in Java EE 7.

This story, "Java security will be in the spotlight at JavaOne," was originally published at InfoWorld.com. Get the first word on what the important tech news really means with the InfoWorld Tech Watch blog. For the latest developments in business technology news, follow InfoWorld.com on Twitter.


View the original article here

Wednesday, 28 August 2013

HyTrust enforces two-person approval for VMware security

Following up on customer feedback from U.S. intelligence agencies, VMware security systems provider HyTrust has updated its virtual security appliance so actions taken by administrators can be delayed until external approval for that action is granted.

Such precautions are increasingly necessary because today's virtual environments pose "a concentration of risk," said Eric Chiu, president and cofounder of HyTrust.

[ Security expert Roger A. Grimes offers a guided tour of the latest threats and explains what you can do to stop them in "Fight Today's Malware," InfoWorld's Shop Talk video. | Keep up with key security issues with InfoWorld's Security Adviser blog and Security Central newsletter. ]

"Servers, networking, storage used to be separate physical systems and they all had their separate configurations and experts to manage them. That has all been collapsed to a single software layer, with a single management console where any administrator can access any resource," Chiu said. "Ultimately, that creates security and compliance issues."

HyTrust announced the update to its flagship HyTrust Appliance at VMware's VMworld conference, being held this week in San Francisco. At this conference, VMware will detail its roadmap for the software defined data center (SDDC) architecture, in which servers, networking and storage can be virtualized and run in a coordinated fashion.

The HyTrust Appliance monitors and controls the employee use of virtual machines (VMs) that run on VMware's ESX and ESXi hypervisors, as well as oversees administrative use of the VMware vSphere management console. It monitors every administrative action taken on a VM, based on the roles that are assigned to each user. The appliance can block inappropriate actions, and log all user actions.

The software can be valuable in preventing the theft of a VM that contains confidential information, the willful destruction of an entire virtual data center, or the misconfiguring of a VM tenant.

The new version of the virtual appliance includes the ability to block any administrative action until approval from an outside party is granted.

One customer, a U.S. intelligence agency, had requested this feature, Chiu said. It mimics the procedures the U.S. Air Force called the two person concept, in which two managers would be required to complete an action (in the Air Force's case, to launch a nuclear strike).

With the HyTrust software, certain actions, such as deleting a VM, can be put on hold until it is approved by a second party, such as a manager or higher-ranking administrator.

HyTrust offered a limited version of this capability in prior versions, but this release offers a full range of capabilities around the process, Chiu said. It now meets the U.S. National Security Agency's requirements for implementing secondary approval. New features include a timer that could be put in place on any action, so a person can only execute an approved action within a certain period of time, such as a nightly maintenance window, Chiu said.

HyTrust Appliance 3.5 also includes a new monitoring mode, which allows an administrator to log how VMs are used before applying policies to their use. The appliance logs all activity, without enforcing any rules. The monitor-only mode can be useful for allowing an administrator to observe routine behavior, which would provide a baseline for building a set of rules to enforce proper use.


View the original article here

Monday, 26 August 2013

Mobile users rely on simple security methods, report says

Nearly 80 percent of smartphone and tablet users choose simple pass codes to protect their devices from unauthorized use, according to an analysis released recently by a maker of mobile device management solutions.

While 85 percent of some 200,000 mobile devices analyzed by Fiberlink had their pass code feature turned on as required by company policy, most of those devices (93 percent) were using simple pass codes to protect the devices.

Fiberlink defined a simple pass code or PIN as a password made up of all numbers or all letters. Of the mobile devices using simple pass codes, almost three quarters (73 percent) had one with a length of four to five characters.

Only 7 percent of the devices analyzed by the company had a complex or alphanumeric pass code. Fiberlink defines a complex password as one made up of letters, numbers and special characters.

"IT is saying it doesn't have the desire to enforce complex passwords on a device that's so heavily balanced between personal use and corporate use," Jonathan Dale, product marketing manager for Fiberlink, said in an interview.

The devices themselves may be contributing to the use of simple pass codes. "It's a usability thing more than anything," said Jamie Cowper, a senior director for Nok Nok Labs.

"The temptation is to go as simple as you can, because long, complex passwords are next to impossible on a small screen in a timely correct fashion," Cowper told CSOonline.

"The balance between security and ease of use has shifted a bit in the mobile space," he said. "You can't ask the same things of a mobile user that you might have done at a desktop machine."

Bill Carey, vice president of Siber Systems, a maker of a password management software, said that ease of typing definitely influenced password choice. "If you're at your computer, you're more inclined to use a more difficult password—something with capital letters and numbers," Carey said in an interview. "But on mobile devices, people don't like typing on those so they're more likely to keep their passwords short."

On the other hand, smartphones have standard features that can be used to authenticate a user that desktop and laptop systems may not have. "Location-based services can be used and biometric information—voice and face—as well," Nok Nok's Cowper said.

"Fingerprint sensors will be on these devices in the near future, possibly next month with Apple's iPhone announcement," he said.

Fiberlink also discovered that the industry which had the highest percentage of devices required to have their pass code feature activated was health care (97 percent), followed by professional services (87 percent), public sector (85 percent), consumer-retail (81 percent), financial services (79 percent), manufacturing (78 percent) and education (41 percent).

However, health care is in the middle of the pack when it comes to the number of devices that have alphanumeric or complex pass codes on them (4 percent). The public sector had the highest number of mobile devices with alphanumeric or complex passwords (18 percent) and education the lowest (1 percent).

Fiberlink's Dale said he was surprised that financial services ranked near the bottom of the table of industries that required its mobile devices to use pass codes. A trend in the industry may have affected that number, he hypothesized.

"Organizations are starting to enforce pass codes only for corporate data and not device data," Dale said. "Companies are putting more restrictive pass codes and permissions around the corporate data on a device and not caring about the pass codes on the device level."

"Let's face it, IT doesn't care about you getting into your phone to text and tweet," he said. "Since our analysis only looked at pass codes used to access a device, that trend wouldn't show up in our data."

With all the flack passwords have received as an authentication method, some commentators have predicted their demise.

Silber's Carey isn't one of those doomsayers. "I'm not sure that anytime soon there's going to be a complete alternative to passwords," he said. "There might some complements to passwords but not necessarily alternatives."

"There have been alternatives for awhile," Carey said. "But none of them seems to have caught on. I think there is a need for passwords and there will always be a need for passwords."

Follow TechHive on Tumblr today.

John Mello writes on technology and cyber security for a number of online publications and is former managing editor of the Boston Business Journal and Boston Phoenix.
More by John P. Mello Jr


View the original article here

HyTrust enforces two-person approval for VMware security

Following up on customer feedback from U.S. intelligence agencies, VMware security systems provider HyTrust has updated its virtual security appliance so actions taken by administrators can be delayed until external approval for that action is granted.

Such precautions are increasingly necessary because today's virtual environments pose "a concentration of risk," said Eric Chiu, president and cofounder of HyTrust.

"Servers, networking, storage used to be separate physical systems and they all had their separate configurations and experts to manage them. That has all been collapsed to a single software layer, with a single management console where any administrator can access any resource," Chiu said. "Ultimately, that creates security and compliance issues."

HyTrust announced the update to its flagship HyTrust Appliance at VMware's VMworld conference, being held this week in San Francisco. At this conference, VMware will detail its roadmap for the software defined data center (SDDC) architecture, in which servers, networking and storage can be virtualized and run in a coordinated fashion.

The HyTrust Appliance monitors and controls the employee use of virtual machines (VMs) that run on VMware's ESX and ESXi hypervisors, as well as oversees administrative use of the VMware vSphere management console. It monitors every administrative action taken on a VM, based on the roles that are assigned to each user. The appliance can block inappropriate actions, and log all user actions.

The software can be valuable in preventing the theft of a VM that contains confidential information, the willful destruction of an entire virtual data center, or the misconfiguring of a VM tenant.

The new version of the virtual appliance includes the ability to block any administrative action until approval from an outside party is granted.

One customer, a U.S. intelligence agency, had requested this feature, Chiu said. It mimics the procedures the U.S. Air Force called the two person concept, in which two managers would be required to complete an action (in the Air Force's case, to launch a nuclear strike).

With the HyTrust software, certain actions, such as deleting a VM, can be put on hold until it is approved by a second party, such as a manager or higher-ranking administrator.

HyTrust offered a limited version of this capability in prior versions, but this release offers a full range of capabilities around the process, Chiu said. It now meets the U.S. National Security Agency's requirements for implementing secondary approval. New features include a timer that could be put in place on any action, so a person can only execute an approved action within a certain period of time, such as a nightly maintenance window, Chiu said.

HyTrust Appliance 3.5 also includes a new monitoring mode, which allows an administrator to log how VMs are used before applying policies to their use. The appliance logs all activity, without enforcing any rules. The monitor-only mode can be useful for allowing an administrator to observe routine behavior, which would provide a baseline for building a set of rules to enforce proper use.

The new software can also send out e-mail alerts whenever some unwanted activity takes place."You can specify any kind of alert you care about," Chiu said. For instance, an administrator can set up an alert for whenever anyone deletes more than 10 VMs.

Typically, administrators rely on SIEM (Security Information Event Management) systems for getting such system alerts, but that software tends not to work well for virtualized environments, Chiu said.

"Trying to configure a SIEM to report on what is happening in a virtual environment is difficult. Our customers told us 'We want that to come from you'," Chiu said.

Drawing from a new security hardening guide for vSphere released by VMware, HyTrust Appliance now has three times as many server configuration security checks and remediation operations than it had before. It can also now work with Intel's Intel Trusted Execution Technology (Intel TXT), so "you can determine whether your hardware platform is trusted, before you move your workload into that environment," Chiu said.

HyTrust Appliance 3.5 is now available. The HyTrust Appliance Enterprise Edition costs US$1,050 per CPU socket for each ESX or EXSi host, as well per $30,000 per appliance. The company also offers a downloadable community edition for no cost, which manages up to three hosts.

Joab Jackson covers enterprise software and general technology breaking news for The IDG News Service. Follow Joab on Twitter at @Joab_Jackson. Joab's e-mail address is Joab_Jackson@idg.com

Joab Jackson covers enterprise software and general technology breaking news for the IDG News Service.
More by Joab Jackson


View the original article here

Social network use offers clues for security, Gartner says

Keeping people from social media is like keeping people from breathing, according to Gartner research director, Rob McMillan.

McMillan made the comparison at the Gartner Security Summit in Sydney, Australia recently, where he highlighted the importance of embracing social media from a security perspective instead of shying away from it or even trying to prohibit its use.

social network

"Social is the most popular form of Cloud service on the planet," he said. "Blocking access just encourages people to overcome security controls."

By opening up to social media, McMillan said it helps companies "learn new tricks."

"We have to understand how social works and develop capabilities in monitoring, data analysis, mitigation and remediation," he said.

Another useful outcome from embracing social media is that it forces IT professionals to consider employees and customers as part of the broad security team.

However, McMillan warns that all of this cannot be managed "just by buying more technology."

"The social risk is not just about social media, and we've already seen many companies affected by social risk events," he said.

Beyond the social media discussion is big data, which McMillan said can enable true context aware security risk management.

While there are numerous tools that can help a business to take advantage of big data, he warns that the work does not stop there.

"All of the data and analysis in the world won't help if you do not know how to use the results to identify flaws in emerging risks," he said.


View the original article here

Saturday, 24 August 2013

Mozilla 'Plug-n-Hack' project wants browsers to play nice with security software

Mozilla is developing a protocol that aims to let security tools and Web browsers work better together.

Configuring a web browser to work with a security tool involves writing platform and browser-specific extensions, a non-trivial process that discourages people with less experience, wrote Simon Bennetts, a security automation engineer with Mozilla, on Thursday.

The proposed standard, called "Plug-n-Hack," will define how security extensions can work with a browser in a more usable way, Bennetts wrote. PnH will allow the security tool to "declare the functionality that they support which is suitable for invoking directly from the browser."

Under the current arrangement, if a user wants to, for example, intercept HTTPS traffic, a user must configure proxy connections through the tool and browser correctly and import the tool's SSL (Secure Sockets Layer) certificate, Bennetts wrote.

"If any of these steps are carried out incorrectly then the browser will typically fail to connect to any website—debugging such problems can be frustrating and time-consuming," Bennetts wrote.

Users may also have to switch often between the tool and their browser to intercept an HTTPS request.

"PnH allows security tools to declare the functionality that they support which is suitable for invoking directly from the browser," Bennets wrote. "A browser that supports PnH can then allow the user to invoke such functionality without having to switch to and from the tool."

The PnH protocol is being designed to be browser and tool independent. The implementation for Firefox has been released under the Mozilla Public License 2.0 and can be incorporated into commercial products for free, Bennetts wrote.

The next phase of the project is being planned, but it is expected it will allow browsers to "advertise their capabilities to security tools," he wrote.

"This will allow the tools to obtain information directly from the browser, and even use the browser as an extension of the tool," Bennetts wrote.


View the original article here

Mozilla 'Plug-n-Hack' project wants browsers to play nice with security software

Mozilla is developing a protocol that aims to let security tools and Web browsers work better together.

Configuring a web browser to work with a security tool involves writing platform and browser-specific extensions, a non-trivial process that discourages people with less experience, wrote Simon Bennetts, a security automation engineer with Mozilla, on Thursday.

The proposed standard, called "Plug-n-Hack," will define how security extensions can work with a browser in a more usable way, Bennetts wrote. PnH will allow the security tool to "declare the functionality that they support which is suitable for invoking directly from the browser."

Under the current arrangement, if a user wants to, for example, intercept HTTPS traffic, a user must configure proxy connections through the tool and browser correctly and import the tool's SSL (Secure Sockets Layer) certificate, Bennetts wrote.

"If any of these steps are carried out incorrectly then the browser will typically fail to connect to any website—debugging such problems can be frustrating and time-consuming," Bennetts wrote.

Users may also have to switch often between the tool and their browser to intercept an HTTPS request.

"PnH allows security tools to declare the functionality that they support which is suitable for invoking directly from the browser," Bennets wrote. "A browser that supports PnH can then allow the user to invoke such functionality without having to switch to and from the tool."

The PnH protocol is being designed to be browser and tool independent. The implementation for Firefox has been released under the Mozilla Public License 2.0 and can be incorporated into commercial products for free, Bennetts wrote.

The next phase of the project is being planned, but it is expected it will allow browsers to "advertise their capabilities to security tools," he wrote.

"This will allow the tools to obtain information directly from the browser, and even use the browser as an extension of the tool," Bennetts wrote.


View the original article here

Thursday, 22 August 2013

Despite recent cloud service outages, security a bigger concern than availability

Wow. No sooner did I finish writing about how the Google and Microsoft outages were not a reason to lose confidence in the cloud, than Amazon went down. The online retail site—and its associated cloud services—were down for just under half an hour Monday afternoon. I stand by my assertion that the sky is not falling, but there’s more to using the cloud than just availability.

Amazon.com was the third major cloud service to suffer an outage in the last week.


Over on WindowsITPro.com, Paul Thurrott summed up the hysteria over cloud outages nicely. “And of course, the cloud computing doubters—who, like global warming doubters are increasingly at odds with reality—will argue that such outages prove that our move away from on-premises hardware and local storage is nothing but a temporary trend.”Let’s start with some perspective, breaking down the math like I did yesterday for Google and Microsoft. Amazon was down for about 25 minutes (although I’ve seen reports from 15 minutes to 40 minutes). In the grand scheme of things, Amazon was down for an infinitesimally small period of time. Depending on the estimate you go with, Amazon lost about $5 million in retail commerce during that timeframe—or about two percent of what it cost Amazon CEO Jeff Bezos to buy the Washington Post, or about two thousandths of a percent of his net worth.

Thurrott also pointed out the irony of how many users turn to Internet-based services like Facebook or Twitter to complain about cloud outages and declare the impending death of this cloud fad.

The debate over cloud availability is silly. As I pointed out my post about the Google and Microsoft outages, local networks and servers are not impervious to outages, so the risk is essentially the same as it pertains to availability.

privacySecurity and privacy are more relevant cloud concerns than availability.

There are, however, other concerns that offer a much more valid argument against cloud services for some businesses. Chief among them is security and privacy.

The convenience of outsourcing the IT infrastructure to a cloud-based third-party comes with increased risk that your network traffic or stored data could be compromised in some way, either directly by the IT support personnel charged with maintaining your services, or inadvertently by exposing it to increased risk on Internet-based servers.

It doesn’t have to be that way, though. You can enjoy some of the benefits of cloud servers and storage without sacrificing control, or putting the data at increased risk by hosting your own private cloud, or using a hybrid approach that includes on-premise and cloud-based services.

For example, you could store your data locally in an appliance like the ioSafe N2. The NAS (network attached storage) device can hold terabytes of data in a redundant configuration inside a fire proof, flood proof enclosure. Best of all, the N2 connects to the network and to the Internet, and it makes the data available from virtually anywhere, and from any computer or mobile device.

Another option is to choose a hybrid cloud solution like Egnyte. Egnyte does provide cloud file storage, but it can also connect and sync with local storage platforms.

Just keep in mind that this approach has tradeoffs. In order to gain greater security and privacy, you have to take responsibility for managing and maintaining the servers and data, which is arguably one of the biggest benefits of cloud services for small businesses. Also consider the fact that the third-party cloud support personnel might know more than you do about security and privacy, so managing it yourself may give you an illusion of greater security and privacy, while actually putting your servers and data at greater risk.

Tony is principal analyst with the Bradley Strategy Group, providing analysis and insight on tech trends. He is a prolific writer on a range of technology topics, has authored a number of books, and is a frequent speaker at industry events.
More by Tony Bradley


View the original article here

Monday, 19 August 2013

Tech shops worry that younger workers brush off security

The generation gap has existed for—well —generations. But the current divide between twentysomethings and their elders in the information technology workforce, at least according to some experts, goes beyond the older cohort simply shaking their heads and muttering, "Kids these days." There is, they say, a security divide.

Andrew Avanessian, vice president of Global Professional Services at Avecto, writing for USA Today's CyberTruth, called Millennials, also labeled Generation Y, "a new attack vector that is emanating from the inside."

Avanessian cited a Cisco's 2013 Annual Security Report that said while Gen Y workers bring enormous expertise and technical understanding to their jobs, they also tend to ignore IT policies, demand freedom of access, shrug off a lack of privacy, and are used to mixing their personal and professional lives, all of which can lead to cyber intrusions.

As Cisco put it, "Security risks rise in businesses because many employees adopt 'my way' work lifestyles in which their devices, work and online behavior mix with their personal lives virtually anywhere—in the office, at home and everywhere in between."

Christopher Ellingwood, writing at Berry Dunn, cited a survey by RSA, Inc. that found that more than 70 percent of Generation Y workers, "admitted to conducting 'risky' behavior over the Internet such as posting too much personal and company information on social media sites."

"This generation, also known as the 'click-through' generation, expects information to be readily available and will download content, visit websites, and offer personal information in order to obtain information they seek. Many sites that are visited and files that are downloaded require an acceptance of the terms and conditions which the Generation Y user is highly likely to accept without reading," Ellingwood wrote.

It is not, for the most part, because workers are visiting shady sites. Cisco found that, "the highest concentration of online security threats do not target pornography, pharmaceutical or gambling sites as much as they do legitimate destinations visited by mass audiences, such as major search engines, retail sites and social media outlets."

Regarding privacy, Cisco found that, "most Generation Y employees believe the age of privacy is over (91 percent) & (and) are willing to sacrifice personal information for socialization online."

"In fact, more Generation Y workers globally said they feel more comfortable sharing personal information with retail sites than with their own employers' IT departments—departments that are paid to protect employee identities and devices."

Avanessian said in many cases those workers need added privileges to do their jobs.

"Restrictive policies that only allow them to do A, B and C actually hinder their workflow, slowing them down and potentially costing the organization in terms of efficiency and resources," he wrote, but added that the "inherent danger" is that even application controls don't stop those workers from opening up the system.

"When you couple administrative rights with the skills and expertise of today's savvy employees, antivirus and application controls can be disabled in seconds," he wrote.

Bogdan Botezatu, senior e-threat analyst at Bitdefender, said direct observation shows that, "Millennials are more likely to open the door to security threats in corporate environments. Since they are basically more interconnected than other demographic categories, they tend to expose more information about themselves."

Not everybody agrees. Guy Helmer, assistant vice president of data loss prevention at Absolute Software, said he doesn't think any specific generation is a new attack vector.

"As technology is embraced by all generations, it is natural for tech-savvy employees to want to have the same network and app access at work as at home," he said. "Gen Y employees are continuing the democratization of the data that started 30 years ago in the days of the personal computer."

Kevin Bocek, vice president of product marketing at Venafi, agrees that "Gen Y trusts technology to an extent that other generations have not—their rush to use social media and anything mobile are just some examples of trusting and embracing technology."

But, he says, they are simply the newest part of the most common attack vector.

"People have been known by cybercriminals to be the weakest link, and spawned the use of phishing, spear phishing, water hole attacks and more for years."

Mike Tierney, vice president of operations at SpectorSoft, agreed.

"Access and availability have always been at odds with security and privacy," he said.

Still, even some in the Gen Y age range acknowledge that the problem is at a new level with their age group. Reem Ateyeh, an account executive at HORN, is one.

Ateyeh said the "new attack vector" label is, "absolutely fair. Many Gen Y employees are tech-savvy, but not as security savvy as they ought to be. Often times, we do not realize the risk that our online activities can pose for our employers," she said, adding that even though she has become very security conscious through her work with IT professionals, "it is difficult to be cautious simply due to the vast number of tools available to share data and information."

security

But, she adds that older generations may become more of a risk factor as they also become more socially connected.

"Whether or not Gen Xers are more security-savvy is an unknown, but they are by no means in the clear when it comes to enterprise security," she said.

What should enterprises do about it? While education about security is important for employees of every age, most experts say this is not something that companies can "train" their way out of. It is also not something the Gen Y cohort will outgrow.

"This is not a phase that a generation will grow out of," said Kevin Bocek. "This is an evolution in the way business is architected and run. Gartner refers to this change brought on in part by Gen Y and by social, mobile, and cloud as 'The Nexus of Forces.' These are unstoppable forces that are changing IT forever."

Guy Helmer's advice is to work with it, rather than try to stop it.

"In many instances, security incidents have occurred because tech-savvy employees find a work-around that will enable them to do their work," he said. "A good example is an employee using a cloud-based service like DropBox to share large files that are difficult to email or access on the network remotely. IT needs to approach the situation as an enabler, not an enforcer."

SpectorSoft's Mike Tierney said companies need to, "establish what is, and isn't, acceptable when it comes to data security," and communicate that clearly to their employees.

"There's an adage I read a few weeks back that puts it in context: 'What you allow, will continue,'" he said.

That, he said, leads to two options: "One is to lock it down—companies will have to choose security over productivity and keep employees actions within the confines of security policy. The other is to allow a more open environment, but only on devices where the company can monitor usage and be notified when someone goes outside the boundaries of what's acceptable," he said.

"In either case, the onus is on the company to do all the work," he added.

Kyrk Storer, an account supervisor at HORN and also part of Gen Y, said clarity from employers would help. Since technology is an everyday thing and security risks "rarely cross our mind," it would help to have, "clear explanation on the part of the employer when we start our careers," about security policy.

Mike Denning, senior vice president and general manager of the Security business at CA Technologies, says being tech-savvy can be a security asset.

"From growing up in a world full of cyber-security risks, they often have a better intuitive sense of which actions are risky and which are not. For them, it has become second nature to not open email attachments from untrusted sources or to download risky applications."

But, he adds, "BYOD—the blending of work and personal on the same device, and being active on social networks—is a way of life. You don't grow out of it, nor should you, but you do need to protect and manage and operate smartly.


View the original article here