[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label encryption. Tampilkan semua postingan
Tampilkan postingan dengan label encryption. Tampilkan semua postingan

13/03/14

How to Use Edward Snowden’s Three Tips for Digital Privacy

Former NSA contractor Edward Snowden says he has been able to outfox U.S. officials using encryption. During a webcast on NSA leaks and data security at the South by Southwest conference in Austin, Texas, Snowden shared some privacy tips for the rest of us: Encrypt your hard drive, use plug-ins for your browser that prevent organizations or companies from tracking you online, and cover your tracks with Tor, an online network that promises anonymity.
These tips range from simple to complicated depending on your computer savvy, so we’ve collected some basic info and guides to help you get started:
Encrypt your hard drive
Encryption is the “Defense Against the Dark Arts” for the digital world, said Snowden, referencing the class Harry Potter took during his Hogwarts years.
Adding password protection to files on your computer is just the first step to personal file security. Encrypting the entire hard disk on your computer ensures personal information is secure, even if your device is stolen or seized.
Newer versions of Windows and Mac operating systems come with built-in disk encryption tools. BitLocker, which encrypts your entire hard drive, comes as part of Windows 7 Ultimate and Enterprise versions, and Windows 8.1 Pro and Enterprise editionsAppleoffer detailed tutorials online on how disk encryption services can be turned on. For those with older operating systems, TrueCrypt, there’s a free program for encrypting your drive. Here’s a guide on how to download and install it.
The Electronic Frontier Foundation, an organization that works on digital rights issues, has a guide to how encryption can help in different situations.
Use browser plug-ins to avoid being tracked onlineThe Wall Street Journal’s series ‘What They Know‘ showed companies are using digital tracking for online activities such as shopping, varying prices based on shopping patterns and location information. While that may seem harmless, it’s important to know that if retailers can see you, it’s likely that others can as well.
Slowly, companies such as Google have agreed to support a do-not-track button to be embedded in most Web browsers. Google’s Chrome browser has a setting that most users can turn on to send a do-not-track request, and so does Microsoft’s Internet Explorer 10. They won’t work with all websites, but it’s a good place to begin.
Plug-ins or small software extensions available for browsers are another way to go about it. Ghostery, a plug-in available for most popular browsers, when installed will show the number of trackers detected but not automatically block them. Users have the choice to individually or in bulk block these trackers.
You can also choose sites, such as the search engine DuckDuckGo, which do not record or share your searches.
Cover your tracks with Tor Over the last few months, Tor, a network that promises anonymity and privacy online has come under the spotlight. Tor hosts a network of websites, some of which have been under the scanner of law enforcement officials for illegal activities. Late last year, the Federal Bureau of Investigation shut down Silk Road, a marketplace available only through the Tor network, for the sale of illegal drugs.
Tor may be useful for criminals, but its cloak of anonymity is increasingly a comfort to anyone looking for privacy. Tor offers its own browser that can be used to connect to news sites or instant messaging services and chat rooms that can’t be easily tracked online.
To get started on the Tor network, take the advice of the ExtremeTech blog, and download the Tor Browser Bundle available for Windows, Mac and Linux. It’s similar to using the Firefox or Chrome browser but slower, because Internet traffic is routed through a series of proxies to mask its origin.
Other ways to lower your online profile include using encrypted chat services such as SilentCircle, and encrypted mail such as Hushmail. There are even smartphones coming out soon that will offer a suite of privacy features baked right in.

Read More...

29/10/11

Cisco rolls out router with military-strength encryption

Cisco's ISR G2 router allows point-to-point encryption of IP traffic based on algorithms designated for Department of Defense communications

Cisco has announced a hardware encryption module for its ISR G2 router that allows point-to-point encryption of IP traffic based on what's called "Suite B," the set of encryption algorithms designated by the National Security Agency for Department of Defense communications.

According to Sarah Vanier, security solutions marketing at Cisco, the VPN Internal Service Module for the Cisco ISR G2 router lets information technology managers select how to use any of the main encryption algorithms as well as the SHA-2 hash algorithm to protect sensitive information traveling between any two routing points equipped with the module.

[ Master your security with InfoWorld's interactive Security iGuide. | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]

MORE: Cisco ASA adds identity firewalling

"The module allows you to offload the encryption process on to the card," says Vanier, with the hardware doing the hard work of encryption and decryption of traffic at the beginning and terminating points.

The selection of encryption and hash algorithms in the Cisco card include the Advanced Encryption Standard, standards-based elliptic-curve cryptography or Triple-DES, to satisfy encryption requirements that might range from unclassified to Top Secret in military networks, she said.

The card, which is said to support up to 3,000 concurrent tunnels with throughput of up to 1.2Gbps, can make use of the SHA-2 hash algorithm to assure data integrity between the two router points.

Nelson Chao, Cisco product manager, said the Cisco encryption card does not currently support multi-cast encryption, but that is anticipated to be supported by Cisco in the future, perhaps late next year.

Cisco also points out that the encryption module is still undergoing official encryption testing to achieve the government's FIPS-level certification, but the module is shipping now.

The Cisco VPN Internal Service Module for the ISR G2 starts at $2,000.
Read More...

19/10/11

Phishers Promote Indonesian Rock Star

In the month of January 2011 Symantec reported adult scams that targeted Indonesian Facebook users. These scams claimed to have an application in which users could view adult videos of Indonesian celebrities, taken from hidden cameras.

It seems that phishers are now using specific celebrities as bait for their phishing sites. This is unlike the previous Indonesian adult scams whose phishing pages gave the impression that the adult video would be of a random celebrity. In October 2011 phishers continued their adult scams on Facebook, but this time they chose the Indonesian rock star Ahmad Dhani in particular. Dhani is the frontman of the rock bands “Dewa 19” and “Ahmad Band”. The phishing site contained a photograph of Ahmad Dhani and Indonesian singer Dewi Persik. The Indonesian caption of the photograph translated: “To view videos of Ahmad Dhani recorded from CCTV cameras, please login below”. After users entered their Facebook login credentials, the phishing page redirected to a pornographic website. Of course, if users gave away their login credentials to the phishing site, phishers would have successully stolen their information for identity theft. The phishing site was hosted on a free Web hosting site.



Celebrities have been a common target in phishing attacks. In the past, we have seen Aishwarya Rai and Katrina Kaif used as phishing bait. Phishers are choosing celebrities with a large fan following because they perceive a larger audience will mean more duped users.

Internet users are advised to follow best practices to avoid phishing attacks:

  • Do not click on suspicious links in email messages.
  • Avoid providing any personal information when answering an email.
  • Never enter personal information in a pop-up page or screen.
  • When entering personal or financial information, ensure the website is encrypted with an SSL certificate by looking for the padlock, ‘https’, or the green address bar.
  • Frequently update your security software, such as Norton Internet Security 2011, to protect you from online phishing.
Read More...

06/10/11

Amazon adds free encryption to storage service

Server Side Encryption protects data stored in Amazon's data center

Using Amazon Web Services' new Server Side Encryption feature, enterprises will at no extra cost be able to encrypt data stored on the company's Simple Storage Service (S3), Amazon said on Tuesday.

The Server Side Encryption feature has been added to simplify the process of protecting data stored on S3. Previously, enterprises had to choose an encryption algorithm, create and store keys, and adapt applications to ensure that all data was encrypted and decrypted for every operation. Now users can leave that to Amazon. The Server Side Encryption feature handles all encryption, decryption, and key management transparently, according to a blog post.

[ Master your security with InfoWorld's interactive Security iGuide. | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]

The data is encrypted when an extra header is added when writing an object to S3. Each object is encrypted with a unique key. As an additional safeguard, this key itself is encrypted with a regularly rotated master key. The encryption algorithm Amazon uses is AES-256, it said.

Enterprises can start to take advantage of Server Side Encryption using Amazon's Management Console and the S3 API.

That Amazon added encryption on its servers isn't terribly exciting, according to Swedish security expert Jakob Schlyter. The feature would help protect data if someone managed to break into one of Amazon's data centers, and steal a disk that stored company data. That has to be weighed against what would happen if something went wrong with Amazon's key management, and data was lost because of that, Schlyter said, and added that he would still use client-side encryption.

On Tuesday, Amazon also said that the number of objects stored on S3 increased to 566 billion during the third quarter of this year, after reaching 262 billion objects during the last quarter of 2010.

 

Read More...

29/09/11

Russian security company adds BlackBerry password cracker

Elcomsoft says its software can extract a master device password from an encrypted BlackBerry memory card

A Russian security company has upgraded a phone-password cracking suite with the ability to figure out the master device password for Research in Motion's BlackBerry devices.

Elcomsoft said on Thursday that before it developed the product, it was believed that there was no way to figure out a device password on a BlackBerry smartphone. BlackBerry smartphones are configured to wipe all data on the phone if a password is typed incorrectly 10 times in a row, the company said.

[ Learn how to manage iPhones, Androids, BlackBerrys, and other smartphones in InfoWorld's 20-page Mobile Management Deep Dive PDF special report. | Keep up on key mobile developments and insights via Twitter and with the Mobile Edge blog and Mobilize newsletter. ]

Elcomsoft said it figured a way around the problem using a BlackBerry's removable media card, but only if a user has configured their smartphone in a certain way. In order for Elcomsoft's software to be successful, a user must have enabled the feature to encrypt data on the media card.

The feature is disabled by default, but Elcomsoft said around 30 percent of BlackBerry users have it enabled for extra security.

The company's software can then analyze the encrypted media card and use a brute-force method to figure out a password, which involves trying millions of possible password combinations per second until one works.

Elcomsoft said it can recover a seven-character password in less than an hour if the password is all lower-case or all capital letters. The software does not need access to the actual BlackBerry device but just the encrypted media card.

The new feature is wrapped into Elcomsoft's Phone Password Breaker. It costs £79 ($123) for the home edition and £199 for the full-featured suite, which can also recover plain-text passwords used to access encrypted backup files for Apple's iPhone, iPad and iPod Touch devices. To crack those passwords, a user does need to have the Apple device in hand.

The BlackBerry password recovery feature is only available in the professional edition. Elcomsoft has published a chart comparing the two versions.
The backup files contain sensitive data including call logs, SMS archives, calendars, photos, email account settings, a person's Web browsing history and more.

Elcomsoft reserves some of its password-cracking software strictly to vetted law enforcement, such as its iOS Forensic Toolkit, which can extract passwords and decrypt a device's file system.

 

Read More...