{"id":11231,"date":"2016-03-05T15:29:29","date_gmt":"2016-03-05T23:29:29","guid":{"rendered":"http:\/\/cahighways.org\/wordpress\/?p=11231"},"modified":"2016-03-05T15:29:29","modified_gmt":"2016-03-05T23:29:29","slug":"security-news-chum-browsers-berkeley-ransom-and-requests","status":"publish","type":"post","link":"https:\/\/cahighways.org\/wordpress\/?p=11231","title":{"rendered":"Security News Chum: Browsers, Berkeley, Ransom and Requests"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full wp-image-8188\" style=\"float: right; margin: 5px;\" src=\"https:\/\/cahighways.org\/wordpress\/wp-content\/uploads\/2013\/07\/cardboard-safe.jpg\" alt=\"userpic=cardboard-safe\" width=\"100\" height=\"86\" \/>Ready for the third course of news chum? This part of the meal is a collection of articles related to cybersecurity:<\/p>\n<ul>\n<li><strong>Help! I&#8217;m DROWNing<\/strong>. This week, researchers <a href=\"http:\/\/arstechnica.com\/security\/2016\/03\/more-than-13-million-https-websites-imperiled-by-new-decryption-attack\/\">announced yet another attack against TLS<\/a>, the protocols used to secure the traffic that you see as HTTPS:\/\/. More than 11 million websites and e-mail services protected by the TLS protocol\u00a0are vulnerable to this low-cost attack that decrypts sensitive communications in a matter of hours and in some cases almost immediately. The attack works against TLS-protected communications that rely on the RSA cryptosystem when the key is exposed even indirectly through SSLv2, a TLS precursor that was retired almost two decades ago because of crippling weaknesses. The vulnerability allows an attacker to decrypt an intercepted TLS connection by repeatedly using SSLv2 to make connections to a server. In the process, the attacker learns a few bits of information about the encryption key each time. While many security experts believed the removal of SSLv2 support from browser and e-mail clients prevented abuse of the legacy protocol, some misconfigured TLS implementations still tacitly support the legacy protocol when an end-user computer specifically requests its use. The most notable implementation subject to such fatal misconfigurations is the OpenSSL cryptographic library.<\/li>\n<li><strong>More Exposure at Berkeley<\/strong>. No, I&#8217;m not talking <a href=\"http:\/\/www.dailycal.org\/2015\/12\/07\/the-naked-truth-about-the-naked-run\/\">exposure of a student body<\/a>, but exposure of <em>the <\/em>student body. The <a href=\"http:\/\/www.zdnet.com\/article\/university-of-california-berkeley-once-again-becomes-victim-of-cyberattack\/#ftag=RSSbaffb68\">University of California, Berkeley, has admitted to a second data breach which may have exposed the data of 80,000 people to misuse<\/a>. Current and former students, faculty members and vendors linked to the university are among those who have been warned about the incident, which took place through financial management software which contained a security flaw, allowing an attacker &#8212; or group &#8212; to access internal services. In total, 57,000 current and former students, including student workers, 10,300 vendors and others &#8212; at a ratio of roughly 50 percent of current students and 65 percent of active employees &#8212; could have had their information taken.<\/li>\n<li><strong>Dealing with Ransomware<\/strong>. Our biggest worry used to be viruses. Those were the days. Today, the big fear is ransomware &#8212; malware you get by a drive-by-download or clicking on a bad link in an email. These attacks encrypt the data on your computer and require you to pay a ransom if you want to have any hope of decrypting it. Here&#8217;s <a href=\"http:\/\/www.pcworld.com\/article\/3041001\/security\/five-things-you-need-to-know-about-ransomware.html#tk.rss_all\">a reasonably good PCWORLD article with somethings you can do to prevent attacks<\/a>. As usual, it boils down to the 4 &#8220;E&#8221;s: Use the\u00a0<strong>engineering<\/strong> in your system to stop attacks by having a good always-on malware and dangerous site scanner;\u00a0have usage policies and\u00a0<strong>enforce\u00a0<\/strong>them about not clicking on links, using non administrative accounts, etc.;\u00a0<strong>educate\u00a0<\/strong>your users on what to look for, and what not to do; and\u00a0plan for\u00a0<strong>emergency services<\/strong> by having a external disk backup that is not always connected using a reliable back tool.<\/li>\n<li><strong>Dealing with Requests<\/strong>. <a href=\"http:\/\/www.computerworld.com\/article\/3040356\/apple-ios\/aclu-you-can-kiss-trust-in-software-updates-goodbye-if-apples-forced-to-help-the-fbi.html\">This article from ComputerWorld explains what really is at risk in the Apple vs FBI fight<\/a>. The issue is <em>not <\/em>encryption or encryption backdoors. The FBI is not trying to break the encryption on the phone. They are trying to unlock the phone, which will decrypt it. To find that key they need to do a brute force attack; to do that attack, they can&#8217;t have the system wipe the phone after 10 failures. So what they want Apple to do is put up a special signed software update that the phone will automatically install that will remove the limit. In other words, this request is to force Apple to put up an untrustworthy software update that weakens the phone. <em>That&#8217;s the precedent that Apple does not want to set<\/em>. In particular, such an update can&#8217;t be limited to just one phone, and if a faked update can get out, then the entire spider-web of automatic software updates becomes untrustworthy. If it becomes untrustworthy, people won&#8217;t automatically install updates, and that will result in known holes being unpatched, which means weaker systems.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ready for the third course of news chum? This part of the meal is a collection of articles related to cybersecurity: Help! I&#8217;m DROWNing. This week, researchers announced yet another attack against TLS, the protocols used to secure the traffic that you see as HTTPS:\/\/. More than 11 million websites and e-mail services protected by <a class=\"more-link\" href=\"https:\/\/cahighways.org\/wordpress\/?p=11231\">Read More &#8230;<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56,98],"tags":[],"class_list":["post-11231","post","type-post","status-publish","format-standard","hentry","category-news-chum","category-security"],"_links":{"self":[{"href":"https:\/\/cahighways.org\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/11231","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cahighways.org\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cahighways.org\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cahighways.org\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cahighways.org\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11231"}],"version-history":[{"count":1,"href":"https:\/\/cahighways.org\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/11231\/revisions"}],"predecessor-version":[{"id":11232,"href":"https:\/\/cahighways.org\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/11231\/revisions\/11232"}],"wp:attachment":[{"href":"https:\/\/cahighways.org\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11231"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cahighways.org\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11231"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cahighways.org\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11231"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}