[+] Wayc0de's Blog[+]

03/09/11

Class Action Lawsuit Accuses Microsoft of Illegal Geotagging

UPDATE: A class action lawsuit filed in U.S. District Court in Seattle, Washington, accuses Microsoft Corp. of collecting geolocation information from photos taken with phones running its Windows Phone 7 operating system, even without the user's consent.

The suit, filed by one Rebecca Cousineau, on behalf of other Windows Phone 7 users, accuses Microsoft of violating federal laws and of submitting false testimony to the U.S. Congress about its activities. The suit, is just the latest to raise questions about mobile phone companies' data collection practices.

In April, a similar class action suit was filed on behalf of iPhone users over privacy violations. That after security researchers presented a paper at the Where 2.0 Conference in San Francisco that detailed an iPhone feature that secretly tracks and saves the movements and locations of iPhone users. Faced with scrutiny, Apple maintained that the tracking feature is used to assemble a map of cell phone tower locations, not user movements. The goal, the company said, is to improve iPhone users connectivity by noting the location of cell phone towers and wifi hotspots.

Like Apple, Microsoft also uses its mobile phone user population to help it assemble an accurate map of cell phone towers and WiFi hotspots. Accurate maps allow the phone to connect to nearby resources more quickly, and can be used to calculate the user's exact location without the need to query GPS satellites.

The Windows Phone 7 suit hinges on research by Samy Kamkar, who is noted for his creation of the MySpace worm, as well as "evercookie" - a persistent tracking cookie. Kamkar's research found that Windows Phone 7's prepackaged camera application periodically transmits information from wifi networks and cell towers to a host system owned by Microsoft Corp. even in cases where the user elected not to share his or her location data. The data sent includes the longitude and latitude of the cell tower the phone had connected to, as well as unique identifiers corresponding to the phone and the application(s) running on it.

Kamkar tested the behavior on Samsung Omnia 7 phones running Windows Phone 7.0.7004 and 7.0.7392.
In an e-mail statement, a Microsoft spokesperson said that it is investigating the claims raised in the complaint.

“We take consumer privacy issues very seriously. Our objective was – and remains – to provide consumers with control over whether and how data used to determine the location of their devices are used, and we designed the Windows Phone operating system with this in mind."

The company also said that it does not store unique identifiers with any data transmitted to its location service - an assertion that seems to run contrary to what Kamkar's research showed.

"The data captured and stored on our location database cannot be correlated to a specific device or user. Any transmission of location data by the Windows Phone camera would not enable Microsoft to identify an individual or 'track' his or her movements,” the spokesperson said.

In her suit, Cousineau is asking for Microsoft to pay $1,000 per violation of the applicable federal laws. Those penalties would be due to herself and others included in the class, assuming the suit is granted "class" status.

Read More...

Comodo, DigiNotar Attacks Expose Crumbling Foundation of CA System

There are a lot of things in the security world that are broken and there isn't room to list them all, even on the Internet. But if the events of the last few days have shown us anything, it's that the certificate authority infrastructure is beyond broken and there's no quick fix looming on the horizon. In fact, the way things look now, there may not be any practical solution to the problem at all.

The details of the attack on DigiNotar that began to leak out on Monday have gotten uglier by the day as more and more researchers have looked into the compromise and the depth of the problem became clear. At the beginning, the attack looked to be quite similar to the March compromise of Comodo. In both cases, attackers were able to find a way into the CA's infrastructure and issue themselves valid SSL certificates for a series of high-value domains that they didn't control. Many of the targeted domains--Google, Yahoo, Mozilla--are the same in both cases and the ultimate goal likely was the same, as well: impersonating trusted sites in order to capture sensitive user data.

But, as bad as the Comodo attack was, it is beginning to pale in comparison to the mess that's emerging from DigiNotar's servers right now. Not only did the company issue SSL certificates for Google, Tor, Yahoo and others to some unknown third parties who may have been using them to intercept traffic from users in Iran, but DigiNotar may have been completely compromised for some time. The company revoked some still-unknown number of fraudulent certificates several weeks ago when it discovered signs of the attack, but it somehow missed the Google wildcard certificate, which is the one that brought all of this to light. What's even more worrisome is that the company not only issues commercial SSL certs, but also is the provider for the Dutch government's PKI program.

Those are the problems that we know about. Raise your hand if you think there aren't six or eight or a dozen other CAs that are similarly compromised and just don't know it yet. Right. Any CA that isn't doing a complete security audit of its infrastructure right now is either totally overconfident or delusional.

In some ways, the attackers who have owned Comodo, DigiNotar and other CAs have done us all a favor. They've exposed the cracked footings and crumbling foundation that underpins the entire SSL and CA infrastructure. Matt Blaze, a cryptographer and associate professor at Penn, put as succinctly as anyone when he said years ago: "Certificate authorities protect you from anyone from whom they're unwilling to take money."

It's a system that's long overdue for a major overhaul, but is so intertwined in the inner workings of the Internet that there's almost no practical way to get it done at this point. Jacob Appelbaum of The Tor Project, who was the first one to publicly detail the Comodo attack and has been researching the DigiNotar attack as well, said as much in his analysis of the DigiNotar situation.

"The Certificate Authority system as it stands today is a house of cards and we're witnessing in public what many have known for years in private. The entire system is soaked in petrol and waiting for a light," Appelbaum wrote.

That spark needed to burn the whole system down started with the Comodo compromise and may have caught for good now with the DigiNotar attack. But even if everyone spontaneously abandoned the CA system tomorrow, the underlying problem that it was designed to solve will still be there. In order for security and privacy to exist online, users need to be able to trust someone or something. Right now that thing is the browser, which in turn places its trust in the certificates that sites present to it. And those certificates are issued by...CAs such as Comodo and DigiNotar.

Which part of that seems like it's working well?
There's fairly broad agreement in the security industry that something needs to be done about this state of affairs, but there's not much in the way of consensus on what to do. Trust is a difficult concept to implement in real life and it's turned out to be far harder to implement online.

There's an old axiom in the security community that says you should always operate with the assumption that your network has been owned. But how are we supposed to operate when it's the CAs that are owned?
Read More...

Anonymous claims hack of Texas police website

The group has released controversial email said to have been sent by Texas police officers

Anonymous has attacked the website of the Texas Police Chiefs Association, in retaliation for the arrests of alleged members of the hacker group.

It said Thursday it had defaced the website, and leaked information that was classified as "law enforcement sensitive" and "for official use only". Among the leaked documents were also said to be some private emails from police officers, that had racist and sexist content.

[ Anonymous hackers also breached San Francisco's public transport site. | Master your security with InfoWorld's interactive Security iGuide. | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]

Anonymous also claimed in a message on Twitter that it had brought down the police website for over three hours. The site which was subsequently restored, and the defacement removed, was however defaced again late Thursday. "It seems they restored the website somehow without removing the backdoors," Anonymous said in a Twitter message.

The Texas Police Chiefs Association did not respond to a request by email for comment.

Separately, Anonymous claimed it had taken down the website of the United States Courts for the Ninth Circuit on Thursday, as justice argues that "civil disobedience is cyber-terrorism".

The Antisec operation by the hacker group and affiliates is protesting the arrest of people suspected to be its members, including Topiary, the person regarded as the spokesman of Anonymous and another group called LulzSec. Jake Davis, the person suspected to be Topiary, was arrested in July in the U.K. and charged with conspiring with others to conduct DDOS (distributed denial-of-service) attacks against the website of the Serious Organised Crime Agency (SOCA), a British law enforcement institution.

Police in the U.K. said Thursday they had charged two more persons in connection with investigations into online attacks, according to reports. Two others were also charged earlier this week, according to the Metropolitan Police.

Anonymous has been involved in a number of attacks on the websites of U.S. law enforcement agencies and defense contractors, and also government websites in Malaysia, Turkey, and Brazil. Its Antisec program targets governments, law enforcement, and corporations.

 

Read More...

Hackers break into Linux source code site

But Linux geeks say that the kernel source code is secure

As Linux fans know, there are two kinds of hackers: the good guys who develop free software, such as the Linux kernel, and the bad guys who break into computers.

The bad guys paid the good guys an unwelcome visit earlier this month, breaking into the Kernel.org website that is home to the Linux project. They gained root access to a server known as Hera and ultimately compromised "a number of servers in the kernel.org infrastructure," according to a note on the kernel.org website Wednesday.

[ Track the latest trends in open source with InfoWorld's Open Sources blog and Technology: Open Source newsletter. ]

Administrators of the website learned of the problem Sunday and soon discovered a number of bad things were happening on their servers. Files were modified, a malicious program was added to the server's startup scripts and some user data was logged.

Kernel.org's owners have contacted law enforcement in the U.S. and Europe and are in the process of reinstalling the site's infrastructure and figuring out what happened.

They think that the hackers may have stolen a user's login credentials to break into the system, and the site is making each of its 448 users change their passwords and SSH (Secure Shell) keys.

The hack is worrying because Kernel.org is the place where Linux distributors download the source code for the widely used operating system's kernel. But Kernel.org's note says that, even with root access, it would be difficult for a hacker to slip malicious source code into the Linux kernel without it being noticed. That's because Linux's change-tracking system takes a cryptographic hash of each file at the time it is published.
So once a component of the Linux kernel has been written and published to Kernel.org, "it is not possible to change the old versions without it being noticed," the Kernel.org note said.

This kind of compromise has become disturbingly common. In January, servers used by the Fedora project -- the community version of Red Hat Enterprise Linux -- were hacked. And around the same time another open-source software development site called SourceForge was also broken into.

 

Read More...

LulzSec and Anonymous police and FBI investigation sees two more arrested

The LulzSec logo
LulzSec, which uses this logo, and Anonymous are being investigated by UK police and the FBI over claims the online groups hacked websites.
 
Two men have been arrested in connection with online attacks by hacking gangs Anonymous and LulzSec, Scotland Yard said.

The men, aged 24 and 20, were arrested on Thursday in Mexborough, near Doncaster, South Yorkshire, and Warminster, Wiltshire, for conspiring to commit offences under the Computer Misuse Act 1990.

Scotland Yard said the arrests were part of a continuing investigation in collaboration with the FBI, South Yorkshire Police and other law enforcement bodies, into activities of Anonymous and LulzSec, especially in connection with suspected offences under the cover of online identity "Kayla".

A spokesman said the men were arrested separately. He said the Doncaster address was searched by police and computer equipment was removed for forensic examination.

Detective Inspector Mark Raymond from the Metropolitan Police's Central e-Crime Unit (PCeU), said: "The arrests relate to our inquiries into a series of serious computer intrusions and online denial-of-service attacks recently suffered by a number of multi-national companies, public institutions and gPressovernment and law enforcement agencies in Great Britain and the US.

"We are working to detect and bring before the courts those responsible for these offences, to disrupt such groups, and to deter others thinking of participating in this type of criminal activity."

In a separate investigation two men were charged on Thursday over online attacks by Anonymous, Scotland Yard said.

Christopher Weatherhead, 20, from Northampton, and Ashley Rhodes, 26, from Kennington, south London, have been charged with conspiracy to carry out an unauthorised act in relation to a computer.

Police had already charged a youth from Chester aged 17 and student Peter David Gibson, 22, from Hartlepool, in relation to the same offences.

All four will appear on bail at City of Westminster Magistrates Court on September 7.
Read More...