<?xml version="1.0"?>
<rss version="2.0"><channel><title><![CDATA[News: Security & Privacy News]]></title><link>https://nsaneforums.com/news/security-privacy-news/page/40/?d=2</link><description><![CDATA[News: Security & Privacy News]]></description><language>en</language><item><title>Man Puzzled When Meta's AI Keeps Giving Out His Phone Number to Strangers</title><link>https://nsaneforums.com/news/security-privacy-news/man-puzzled-when-metas-ai-keeps-giving-out-his-phone-number-to-strangers-r24808/</link><description><![CDATA[<p>
	Meta's AI chatbot kept giving strangers a man's phone number, and it remains unclear how or why it happened.
</p>

<p>
	 
</p>

<p>
	As Business Insider's Rob Price reports, the debacle began when he was added to a random WhatsApp group chat filled with people from multiple countries who began asking him random questions in Spanish.
</p>

<p>
	 
</p>

<p>
	The people in the chat seemed bemused when the senior Silicon Valley correspondent asked them why he'd been added to the group chat and why they were asking him questions. Eventually, someone posted a screenshot and Price noticed that his number was saved under the name "Meta AI."
</p>

<p>
	 
</p>

<p>
	After more back-and-forth, someone eventually shared another screenshot that included a one-on-one exchange with Meta AI, the company's cross-platform chatbot, explaining that Price's phone number could be used to add it to group chats.
</p>

<p>
	 
</p>

<p>
	"You can add me to a WhatsApp group as if I were just another contact," the chatbot told the user in a translation of the original Spanish exchange. "You only need to save my phone number."
</p>

<p>
	 
</p>

<p>
	After that first bizarre instance, people from various countries in South America kept contacting the reporter thinking he was Meta AI, spitting out Price's work number each time when users asked the chatbot for its phone number.
</p>

<p>
	<br />
	<span style="font-size:20px;"><strong>Working Theory</strong></span>
</p>

<p>
	 
</p>

<p>
	As a journalist, Price was accustomed to being contacted by random people, but this was substantially different. Generally speaking, being accused of being a bot only happens during particularly intense political debates between humans on social media — and this was nothing of the sort.
</p>

<p>
	 
</p>

<p>
	Ultimately, the reporter concluded that when training the large language model (LLM) undergirding the Meta AI chatbot, the company had likely scraped his publicly-available phone number, too.
</p>

<p>
	 
</p>

<p>
	Having written roughly 300 stories mentioning Facebook that included his phone number — which was shared, as is common practice, to solicit tips — Price reckons that the number may have been "scooped up" into Meta's training data. During the mysterious "black box" sausage-making process that results in AI, the LLM may then have made some "misguided causal connection" that resulted in his number being spat out when users asked Meta for its phone number.
</p>

<p>
	 
</p>

<p>
	In a statement to BI, a company spokesperson seemed to co-sign this theory, telling Price that because Meta AI "was trained on publicly available information online," his number may have ended up in the secret sauce.
</p>

<p>
	 
</p>

<p>
	The only problem? Axel Springer, Business Insider's parent company, doesn't have any deal in place to allow Meta to train its AI on its content (though it does have one with OpenAI).
</p>

<p>
	 
</p>

<p>
	Price noted that after he'd contacted Meta about the bizarre occurrences, people stopped randomly messaging him thinking he was a chatbot — and that he'd never been able to replicate the fluke for himself, either.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://futurism.com/the-byte/meta-ai-gives-phone-number" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24808</guid><pubDate>Thu, 08 Aug 2024 14:38:48 +0000</pubDate></item><item><title>Watch How a Hacker&#x2019;s Infrared Laser Can Spy on Your Laptop&#x2019;s Keystrokes</title><link>https://nsaneforums.com/news/security-privacy-news/watch-how-a-hacker%E2%80%99s-infrared-laser-can-spy-on-your-laptop%E2%80%99s-keystrokes-r24804/</link><description><![CDATA[<p>
	<span style="font-size:18px;"><strong>Hacker Samy Kamkar is debuting his own open source version of a laser microphone—a spy tool that can invisibly pick up the sounds inside your home through a window, and even the text you’re typing.</strong></span>
</p>

<p>
	 
</p>

<p>
	In a famous scene from the 1992 movie Sneakers, a hacker classic, the main characters park a surveillance van across the street from their target's office and point a telephoto lens through his window—only to find that their view of his computer keyboard is blocked by the surprise entrance of his love interest at the precise moment when he types his password. The surveillance team ends up watching and rewatching their partially obstructed VHS video of his keystrokes, bickering comically about the layout of a QWERTY keyboard.
</p>

<p>
	 
</p>

<p>
	Today, with a few decades of surveillance tech advancements and some clever feats of physics, all it would take to grab that password—as well as anything typed on the computer, or, for that matter, every word spoken in the room—would be a well-aimed infrared laser.
</p>

<p>
	 
</p>

<p>
	At the Defcon security conference this weekend in Las Vegas, renowned hacker Samy Kamkar plans to debut his own DIY advances in a form of laser-based surveillance, demonstrating that he can point a laser that's invisible to the human eye at a faraway laptop, through a window, and detect the computer's vibrations to reconstruct virtually every character typed on it. The trick, which takes advantage of the subtle acoustics created by tapping different keys on a computer, works even without a view of the computer's keyboard, so long as the hacker has a line-of-sight view of any relatively reflective portion of the target laptop.
</p>

<p>
	 
</p>

<p>
	In the process of perfecting that light-based keystroke eavesdropping technique, Kamkar says he's also created what may well be one of the world's most high-fidelity implementations of a laser microphone—a tool that bounces a laser off a room's window to detect its vibrations and record all the sounds inside—or at least, one of the most advanced such laser microphones whose technical details have been publicly released. (Kamkar plans to publish the full schematics on his website and GitHub.) The result is an open-source spying setup that can, in various forms, potentially pick up virtually everything either typed or spoken aloud in a surveillance target's room.
</p>

<p>
	 
</p>

<p>
	Kamkar says he's been determined to build his own laser-based spy setup since he watched a Defcon talk 15 years ago, in which a pair of hackers demonstrated some rudimentary detection of keystrokes with a laser pointed at a laptop from across a room. “It blew my mind. ‘I want to do this,’” Kamkar says he remembers thinking. “But I also wanted to improve the attack. Can I make it work from outside, from far away? Can I do it with an infrared laser so the target can't see it? And can I also hear what's happening in the room, such as by bouncing the laser off a window?”
</p>

<p>
	 
</p>

<p>
	The answers: Yes to all the above. The video below shows an example of Kamkar's prototype setup–he tested it through different windows of his house with varying results—with his infrared laser outside pointed at his Macbook inside, where he's typing and listening to music.
</p>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" src="https://www.youtube-nocookie.com/embed/fqZZTkxa7bI?feature=oembed" title="laser mic setup" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	Here's a sample of text he was able to recover in one case from his own typing, compared to the original:
</p>

<p>
	 
</p>

<p>
	<img alt="SamyKamkar_Security_textsample.png" class="ipsImage" data-ratio="66.81" height="216" width="720" src="https://media.wired.com/photos/66b3f39bc383e8e7b96bbeca/master/w_1600,c_limit/SamyKamkar_Security_textsample.png" />
</p>

<p>
	 
</p>

<p>
	Kamkar says that his keystroke spying trick works best when he can aim his laser at a spot on a laptop that reflects light—ideally a shiny metal or plastic spot on the laptop's case, such as a logo. “The Apple logo is nearly a mirror,” he says. “So that's a really good reflective surface.” The video clip below, captured with an infrared camera and steam to make the laser's path visible, shows Kamkar's infrared laser bouncing off that shiny Apple logo.
</p>

<p>
	 
</p>

<div class="ipsEmbeddedVideo" contenteditable="false">
	<div>
		<iframe allowfullscreen="" frameborder="0" height="113" src="https://www.youtube-nocookie.com/embed/H3y1f7HrD0Y?feature=oembed" title="infrared laser beam" width="200"></iframe>
	</div>
</div>

<p>
	 
</p>

<p>
	When it came to recording sounds inside a room, Kamkar was in some cases able to pick up music clearly, as in the first two samples below—though he found that double-paned glass produced far more muffled results, which you can hear in the third audio sample.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	&lt; Listen to the audio samples at the <a href="https://www.wired.com/story/infrared-laser-microphone-keystroke-surveillance/" rel="external nofollow">source page</a>. &gt;
</p>

<p style="text-align:center;">
	 
</p>

<p>
	Neither of Kamkar's two laser-spying techniques are entirely new concepts: Both the keystroke-surveillance technique and the laser-based audio eavesdropping trick are essentially his own versions of a tool known as a laser microphone, a decades-old invention that bounces a laser off a surface and measures the reflected light to detect the target's vibrations—such as those caused by either key presses on a laptop's keyboard or someone's nearby voice.
</p>

<p>
	 
</p>

<p>
	For both of his laser-based techniques, however, Kamkar used his own engineering tricks and a few thousand dollars in hardware to significantly advance the fidelity of his optical eavesdropping. To reduce the noise created by ambient light when attempting to detect vibrations in his reflected infrared laser, for instance, he designed his laser microphone system to strobe on and off 400,000 times per second, picking up the reflected light through a lens so that the light hits a photo diode—or doesn't—depending on the target's vibrations.
</p>

<p>
	 
</p>

<p>
	By using that 400-kilohertz frequency and measuring variances in the signal's amplitude just as an amplitude-modulated, or AM, radio does, Kamkar was able to later filter out everything other than that frequency to vastly reduce noise. He then amplified that signal and used a piece of hardware known as an upconverter to shift that AM radio signal to a higher frequency, so that it could be fed it into a software-defined radio—a digital, programmable radio capable of handling a far larger range of frequencies than a typical radio—to analyze it.
</p>

<p>
	 
</p>

<p>
	“I think I've created the first laser microphone that's actually modulated in the radio frequency domain,” Kamkar says. “Once I have a radio signal, I can treat it like radio, and I can take advantage of all the tools that exist for radio communication.” In other words, Kamkar converted sound into light into radio—and then back again into sound.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="20240804_Wired_Defcon_SamyKamkar_003.jpg" class="ipsImage" data-ratio="75.10" height="480" width="720" src="https://media.wired.com/photos/66b3ef6bed705b9278666827/master/w_1600,c_limit/20240804_Wired_Defcon_SamyKamkar_003.jpg" />
</p>

<p style="text-align:center;">
	<span style="font-size:12px;"><em>Samy Kamkar at his home workstation.Photograph: Roger Kisby</em></span>
</p>

<p style="text-align:center;">
	 
</p>

<p>
	For his keystroke detection technique, Kamkar then fed the output of his laser microphone into an audio program called iZotopeRX to further remove noise and then an open source piece of software called Keytap3 that can convert the sound of keystrokes into legible text. In fact, security researchers have demonstrated for years that keystroke audio, recorded from a nearby microphone, can be analyzed and deciphered into the text that a surveillance target is typing by distinguishing tiny acoustic differences in various keys. One group of researchers has shown that relatively precise text can even be derived from the sounds of keystrokes recorded over a Zoom call.
</p>

<p>
	 
</p>

<p>
	Kamkar, however, was more interested in the 2009 Defcon demonstration in which security researchers Andrea Barisani and Daniele Bianco showed that they could use a simple laser microphone to roughly detect words typed on a keyboard, a trick that would allow long-distance line-of-sight spying. In that demo, the two Italian hackers only got as far as testing out their laser spying technique across the room from a laptop and generating a list of possible word pairs that matched the vibration signature they recorded.
</p>

<p>
	 
</p>

<p>
	Speaking to WIRED, Barisani says their experiment was only a “quick and dirty” proof of concept compared to Kamkar's more polished prototype. “Samy is brilliant, and there was a lot of room for improvement,” Barisani says. “I'm 100 percent sure that he was able to improve our attack both in the hardware setup and the signal processing.”
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="20240804_Wired_Defcon_SamyKamkar_006.jpg" class="ipsImage" data-ratio="75.10" height="540" width="405" src="https://media.wired.com/photos/66b3ef6c029c500caa827e35/3:4/w_1600,c_limit/20240804_Wired_Defcon_SamyKamkar_006.jpg" />
</p>

<p style="text-align:center;">
	<span style="font-size:12px;"><em>Kamkar’s laser spying kit: An infrared laser…Photograph: Roger Kisby</em></span>
</p>

<p style="text-align:center;">
	 
</p>

<p style="text-align:center;">
	<img alt="20240804_Wired_Defcon_SamyKamkar_005.jpg" class="ipsImage" data-ratio="75.10" height="540" width="405" src="https://media.wired.com/photos/66b3ef6b042186bb6e24b38b/3:4/w_1600,c_limit/20240804_Wired_Defcon_SamyKamkar_005.jpg" />
</p>

<p style="text-align:center;">
	<span style="font-size:12px;"><em>…attached to an oscilloscope’s signal generator, current controller, temperature controller, and amplifier power supply.Photograph: Roger Kisby</em></span>
</p>

<p style="text-align:center;">
	 
</p>

<p>
	Kamkar's results do appear to be dramatically better: Some samples of text he recovered from typing with his laser mic setup and shared with WIRED were almost entirely legible, with only a missed letter every word or two; others showed somewhat spottier results. Kamkar's laser microphone worked well enough for detecting keystrokes, in fact, that he also tested using it to record audio in a room more generally, by bouncing his infrared laser off a window. It produced remarkably clear sound, noticeably better than other samples of laser microphone audio released online—at least among those recorded stealthily from a window's vibrations.
</p>

<p>
	 
</p>

<p>
	Of course, given that laser microphones have existed for decades, Kamkar admits he doesn't know what advancements the technology may have made in commercial implementations available to governments or law enforcement, not to mention even more secret, custom-built technologies potentially created or used by intelligence agencies. “I would assume they're doing this or something like it,” Kamkar says.
</p>

<p>
	 
</p>

<p>
	Unlike the creators of those professional spy tools, though, Kamkar is publishing the full schematics of his DIY laser microphone spy kit. “Ideally, I want the public to know everything that intelligence agencies are doing, and the next thing, too," Kamkar says. “If you don't know something is possible, you're probably not going to protect against it.”
</p>

<p>
	 
	</p><p>
		Even knowing that Kamkar's silent, invisible, long-distance laser spy trick exists, how does anyone hide their secrets from it? He suggests that companies install double-paned or reflective glass. Some security device companies also sell protection devices that affix to windows and vibrate them to prevent laser microphone spying, and Kamkar concedes he hasn't tested his attack against those. But he also suggests a safer countermeasure: “Don't work on computers visible from a window,” he says. “Or just have dirty windows.”
	</p>


<p>
	 
</p>

<p>
	Kamkar admits that beyond any idea of enabling or defeating surveillance, he was driven to develop his laser spying tricks mostly to test what was possible in the realm of physics-based hacking. More than a warning about any particular spy trick, he hopes his Defcon talk will inspire the conference's hacker audience to think more broadly about how information resonates through the real world in unexpected and exploitable ways, defying any simple model of computer security.
</p>

<p>
	 
</p>

<p>
	“You hit a key, it produces a sound that emanates in all directions. All the light hitting the laptop also vibrates at that frequency. The key then closes a circuit on the keyboard that generates electromagnetism and emits radio frequency in all directions,” Kamkar says. “The physical world screams secrets, and we have the ability to listen.” And if you don't, whoever's watching outside your window just might.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.wired.com/story/infrared-laser-microphone-keystroke-surveillance/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24804</guid><pubDate>Thu, 08 Aug 2024 14:08:00 +0000</pubDate></item><item><title>Inside the Dark World of Doxing for Profit</title><link>https://nsaneforums.com/news/security-privacy-news/inside-the-dark-world-of-doxing-for-profit-r24803/</link><description><![CDATA[<p>
	<span style="font-size:18px;"><strong>From tricking companies into handing over victims’ personal data to offering violence as a service, the online doxing ecosystem is not just still a problem—it’s getting more extreme.</strong></span>
</p>

<p>
	 
</p>

<p>
	Since the early 1990s, people have used doxing as a toxic way to strike digital revenge—stripping away someone’s anonymity by unmasking their identity online. But in recent years, the poisonous practice has taken on new life, with people being doxed and extorted for cryptocurrency and, in the most extreme cases, potentially facing physical violence.
</p>

<p>
	 
</p>

<p>
	For the past year, security researcher Jacob Larsen—who was a victim of doxing around a decade ago when someone tried to extort him for a gaming account—has been monitoring doxing groups, observing the techniques used to unmask people, and interviewing prominent members of the doxing community. Doxing actions have led to incomes of “well over six figures annually,” and methods include making fake law enforcement requests to get people’s data, according to Larsen’s interviews.
</p>

<p>
	 
</p>

<p>
	“The primary target of doxing, particularly when it involves a physical extortion component, is for finance,” says Larsen, who leads an offensive security team at cybersecurity company CyberCX but conducted the doxing research in a personal capacity with the support of the company.
</p>

<p>
	 
</p>

<p>
	Over several online chat sessions last August and September, Larsen interviewed two members of the doxing community: “Ego” and “Reiko.” While neither of their offline identities is publicly known, Ego is believed to have been a member of the five-person doxing group known as ViLe, and Reiko last year acted as an administrator of the biggest public doxing website, Doxbin, as well as being involved in other groups. (Two other ViLe members pleaded guilty to hacking and identity theft in June.) Larsen says both Ego and Reiko deleted their social media accounts since speaking with him, making it impossible for WIRED to speak with them independently.
</p>

<p>
	 
</p>

<p>
	People can be doxed for a full range of reasons—from harassment in online gaming, to inciting political violence. Doxing can “humiliate, harm, and reduce the informational autonomy” of targeted individuals, says Bree Anderson, a digital criminologist at Deakin University in Australia who has researched the subject with colleagues. There are direct “first-order” harms, such as risks to personal safety, and longer-term “second-order harms,” including anxiety around future disclosures of information, Anderson says.
</p>

<p>
	 
</p>

<p>
	Larsen’s research mostly focused on those doxing for profit. Doxbin is central to many doxing efforts, with the website hosting more than 176,000 public and private doxes, which can contain names, social media details, Social Security numbers, home addresses, places of work, and similar details belonging to people’s family members. Larsen says he believes most of the doxing on Doxbin is driven by extortion activities, although there can be other motivations and doxing for notoriety. Once information is uploaded, Doxbin will not remove it unless it breaks the website’s terms of service.
</p>

<p>
	 
</p>

<p>
	“It is your responsibility to uphold your privacy on the internet,” Reiko said in one of the conversations with Larsen, who has published the transcripts. Ego added: “It’s on the users to keep their online security tight, but let’s be real, no matter how careful you are, someone might still track you down.”
</p>

<p>
	<br />
	<span style="font-size:24px;"><strong>Impersonating Police, Violence as a Service</strong></span>
</p>

<p>
	 
</p>

<p>
	Being entirely anonymous online is almost impossible—and many people don’t try, often using their real names and personal details in online accounts and sharing information on social media. Doxing tactics to gather people’s details, some of which were detailed in charges against ViLe members, can include reusing common passwords to access accounts, accessing public and private databases, and social engineering to launch SIM swapping attacks. There are also more nefarious methods.
</p>

<p>
	 
</p>

<p>
	Emergency data requests (EDR) can also be abused, Larsen says. EDRs allow law enforcement officials to ask tech companies for people’s names and contact details without any court orders as they believe there may be danger or risks to people’s lives. These requests are made directly to tech platforms, often through specific online portals, and broadly need to come from official law enforcement or government email addresses.
</p>

<p>
	 
</p>

<p>
	“If a threat actor can intercept that process, it’s the fastest way for them to get highly accurate sensitive data on the victim,” Larsen explains. “They’re really stepping up and using that as their primary method for doxing victims.” This kind of request has previously been used to harass women and children, as well as weaponized against security researchers.
</p>

<p>
	 
</p>

<p>
	During his research, Larsen says he infiltrated various Telegram groups where people were selling access to systems to make EDRs and government emails needed to make requests. One individual, according to screenshots shared by Larsen, claimed to be selling access to TikTok’s law enforcement platform using a US Department of Justice email address, and claimed they had an FBI email address too.
</p>

<p>
	 
</p>

<p>
	Another claimed they would make government emails addresses from Mozambique, the Philippines, Pakistan, and Brazil for $125 each.
</p>

<p>
	Larsen says he reported the details to law enforcement agencies. The FBI declined to comment about false EDRs to WIRED, while a TikTok spokesperson pointed toward its public policies on emergency data requests and the ways it tries to ensure they are valid. The US Cybersecurity and Infrastructure Security Agency did not respond to a request for comment.
</p>

<p>
	 
</p>

<p>
	“Violence as a service” groups have appeared from SIM swapping communities in recent years as well, allowing people to pay for violent acts to be carried out. Digital extortion can lead to physical extortion, Larsen says, adding that Doxbin doesn’t allow threats or discussions of violence to be posted on its platform. “I’ve seen people get doxed and that ends up in them being bricked, getting their house shot up, getting a Molotov thrown through their windows, gang stalked, all in an attempt to extort them for money,” Ego said in a conversation with Larsen. Videos of attacks are sometimes posted online. “Things get pretty wicked online, much more than people realize,” Ego said.
</p>

<p>
	 
</p>

<p>
	These incidents can involve people trying to extort cryptocurrency from people with large stashes—although some violence services have been used by feuding online groups. “Unless these platforms get taken down, or more actors get punished, both in the US and abroad, it's just going to continue to rise,” Larsen says. “Particularly as cryptocurrency becomes more adopted by more people.”
</p>

<p>
	<br />
	<span style="font-size:24px;"><strong>Few Doxing Protections</strong></span>
</p>

<p>
	 
</p>

<p>
	Globally, few legal protections against doxing exist—although elements may fall under stalking, harassment, or data protection legislation. “Laws worldwide are simply not fit to provide protection,” says Amanda Manyame, digital rights adviser at Equality Now, a feminist human rights NGO. “Victims have no way to swiftly regain control of information that has been published with the intent to harass, intimidate, and/or harm them.”
</p>

<p>
	 
</p>

<p>
	“The prompt takedown of doxing-related content is very important for victims, and governments need to enact laws that mandate the removal of such content within 24 hours,” Manyame says, with Equality Now’s research stating that doxing can “disproportionately” impact women and girls.
</p>

<p>
	 
</p>

<p>
	Indicating the challenges of getting information removed, Doxbin publishes a transparency report—mimicking the practices of Big Tech platforms—listing the number of removal requests it receives. Around 160 requests from lawyers and local and national law enforcement bodies are listed from 27 countries, Larsen says, with the majority being denied as they don’t break Doxbin’s limited terms of service.
</p>

<p>
	 
</p>

<p>
	While legal routes to getting data removed are slim, there are steps people can take to limit some of the impacts linked to doxing and wider online privacy abuses. At an individual level, Larsen says, common cybersecurity measures can help, including not reusing passwords across apps and websites, locking down social media accounts and not posting photos and personal information, and turning on multifactor authentication for as many accounts as possible. For people wanting to go further, using usernames and emails not linked to the same email address or online handle is a potential first step.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.wired.com/story/doxing-extortion-violence-as-service/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24803</guid><pubDate>Thu, 08 Aug 2024 13:59:03 +0000</pubDate></item><item><title>This cyberattack downgrades your version of Windows to one unprotected against attacks</title><link>https://nsaneforums.com/news/security-privacy-news/this-cyberattack-downgrades-your-version-of-windows-to-one-unprotected-against-attacks-r24802/</link><description><![CDATA[<p>
	<span style="font-size:20px;">Your Windows device could be downgraded by this attack</span>
</p>

<p>
	 
</p>

<p>
	A version-rollback vulnerability has been discovered by a cybersecurity researcher that allows a fully patched Windows machine to be downgraded to older version, allowing the exploitation of previously patched zero-days and vulnerabilities.
</p>

<p>
	 
</p>

<p>
	Alon Leviev unveiled his findings at Black Hat USA 2024 and DEF CON 32 (2024) as a tool named Windows Downdate.
</p>

<p>
	 
</p>

<p>
	Leviev says the tool can be used to make “the term “fully patched” meaningless on any Windows machine in the world.”
</p>

<p>
	<br />
	<span style="font-size:22px;"><strong>Windows Downdate</strong></span>
</p>

<p>
	 
</p>

<p>
	Leviev started their journey with the aim of discovering a version-rollback exploit using Windows Update as a starting point. It turned out Windows Update had a significant flaw that allowed for a full takeover of the update process, including downgrading Windows versions.
</p>

<p>
	 
</p>

<p>
	By also exploiting access to critical OS components, including dynamic link libraries (DLLs), drivers, and NT kernel, Leviev was able to have the Windows machine report  it was fully updated and unable to download any updates without having recovery and scanning tools detect anything out of the ordinary.
</p>

<p>
	 
</p>

<p>
	Leviev then also discovered the virtualization stack could be tampered with as well, allowing a number of previously secure applications to be exposed to previously patched privilege escalation vulnerabilities, with Credential Guard’s Isolated User Mode Process, Secure Kernel, and Hyper-V’s hypervisor all being suceptible.
</p>

<p>
	 
</p>

<p>
	Finally, Windows virtualization-based security was also disabled even when secured by UEFI locks. This allowed Leviev to also disable security features such as Credential Guard and Hypervisor-Protected Code integrity. According to Leviev’s knowledge, “this is the first time VBS’s UEFI locks have been bypassed without physical access.”
</p>

<p>
	 
</p>

<p>
	Leviev offers a number of suggestions to make operating systems less vulnerable to downgrade attacks, including:
</p>

<p>
	 
</p>

<ul>
	<li>
		    Researching and implementing security measures that check for and prevent the downgrade of critical OS components.
	</li>
	<li>
		    Reviewing all design features as an attack surface, even old ones.
	</li>
	<li>
		    Research in-the-wild-attacks to evaluate whether other components or areas are vulnerable to attack.
	</li>
	<li>
		    These are the best firewalls around today
	</li>
	<li>
		    Check that email carefully — experts warn anti-phishing tools in Microsoft 365 can be easily bypassed
	</li>
	<li>
		    Take a look at the best VPN with antivirus
	</li>
</ul>

<p>
	 
</p>

<p>
	<strong><a href="https://www.techradar.com/pro/this-cyberattack-downgrades-your-version-of-windows-to-one-unprotected-against-attacks" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24802</guid><pubDate>Thu, 08 Aug 2024 13:54:47 +0000</pubDate></item><item><title>0.0.0.0 Day: 18-Year-Old Browser Vulnerability Impacts MacOS and Linux Devices</title><link>https://nsaneforums.com/news/security-privacy-news/0000-day-18-year-old-browser-vulnerability-impacts-macos-and-linux-devices-r24801/</link><description><![CDATA[<p>
	Cybersecurity researchers have discovered a new "0.0.0.0 Day" impacting all major web browsers that malicious websites could take advantage of to breach local networks.
</p>

<p>
	 
</p>

<p>
	The critical vulnerability "exposes a fundamental flaw in how browsers handle network requests, potentially granting malicious actors access to sensitive services running on local devices," Oligo Security researcher Avi Lumelsky said.
</p>

<p>
	 
</p>

<p>
	The Israeli application security company said the implications of the vulnerability are far-reaching, and that it stems from the inconsistent implementation of security mechanisms and a lack of standardization across different browsers.
</p>

<p>
	 
</p>

<p>
	As a result, a seemingly harmless IP address such as 0.0.0.0 could be weaponized to exploit local services, resulting in unauthorized access and remote code execution by attackers outside the network. The loophole is said to have been around since 2006.
</p>

<p>
	 
</p>

<p>
	0.0.0.0 Day impacts Google Chrome/Chromium, Mozilla Firefox, and Apple Safari that enables external websites to communicate with software that runs locally on MacOS and Linux. It does not affect Windows devices as Microsoft blocks the IP address at the operating system level.
</p>

<p>
	 
</p>

<p>
	Particularly, Oligo Security found that public websites using domains ending in ".com" are able to communicate with services running on the local network and execute arbitrary code on the visitor's host by using the address 0.0.0.0 as opposed to localhost/127.0.0.1.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="demo.gif" class="ipsImage" data-ratio="55.56" height="395" width="720" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgEaU93mQqxwLUX73w-P5kSrxL3gnxOc2N6sgjaRy24qYXqNCWLZnAx4gIOQpwtL0njA_bFlVG1YqIVGNif5UJNLgjJKZhH1aaFmpJpzxK0Dd2XjxinuRPH_L6GuCSkR1eOndbp4Wp9O7X67tWKwftaFjdGGx1b4bPeu1Z6ecipiOawWtqLNMpAlDA3koDo/s728-rw-e365/demo.gif" />
</p>

<p style="text-align:center;">
	 
</p>

<p>
	It's also a bypass of Private Network Access (PNA), which is designed to prohibit public websites from directly accessing endpoints located within private networks.
</p>

<p>
	 
</p>

<p>
	Any application that runs on localhost and can be reached via 0.0.0.0 is likely susceptible to remote code execution, including local Selenium Grid instances by dispatching a POST request to 0.0.0[.]0:4444 with a crafted payload.
</p>

<p>
	 
</p>

<p>
	In response to the findings in April 2024, web browsers are expected to block access to 0.0.0.0 completely, thereby deprecating direct access to private network endpoints from public websites.
</p>

<p>
	 
</p>

<p>
	"When services use localhost, they assume a constrained environment," Lumelsky said. "This assumption, which can (as in the case of this vulnerability) be faulty, results in insecure server implementations."
</p>

<p>
	 
</p>

<p>
	"By using 0.0.0.0 together with mode 'no-cors,' attackers can use public domains to attack services running on localhost and even gain arbitrary code execution (RCE), all using a single HTTP request."
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://thehackernews.com/2024/08/0000-day-18-year-old-browser.html" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24801</guid><pubDate>Thu, 08 Aug 2024 13:34:09 +0000</pubDate></item><item><title>This Attack Pushes Windows Update to the Dark Side</title><link>https://nsaneforums.com/news/security-privacy-news/this-attack-pushes-windows-update-to-the-dark-side-r24795/</link><description><![CDATA[<p>
	<span style="font-size:16px;">Every month, you trust Windows Update to improve and secure your operating system. At Black Hat, we got a peek at what happens when malefactors twist it to downgrade security instead.</span>
</p>

<p>
	 
</p>

<p>
	LAS VEGAS—If a powerful program reached into your Windows operating system and made fundamental changes to its functionality, including changes to security, you might consider it a dangerous attack on system integrity. But when that powerful program is Windows Update, well, it’s just fine. Every month, sometimes more often, Windows Update does its thing. Alon Leviev, Security Researcher at SafeBreach, scrutinized the process for ways malware coders might misuse it. At the Black Hat conference here, he revealed multiple techniques that force Windows Update to downgrade system security.
</p>

<p>
	<br />
	<span style="font-size:22px;"><strong>Inspired by Black Lotus Attack</strong></span>
</p>

<p>
	 
</p>

<p>
	Leviev led off with his inspiration—the downgrade attack called Black Lotus, which managed to defeat the touted Secure Boot system that’s the core of Windows 11 security. With Secure Boot, five distinct Windows components participate, each vetting the next. Black Lotus worked by replacing one of those components with an earlier vulnerable version. And Microsoft foiled it by banning old, revoked components from the process.
</p>

<p>
	 
</p>

<p>
	“Are there any other components that may be vulnerable to downgrade attacks?” mused Leviev. “My research was to find out.”
</p>

<p>
	 
</p>

<p>
	What makes a complete and perfect downgrade attack? Leviev broke it down into four criteria: it should be undetectable, invisible, persistent, and irreversible. Undetectable goes without saying, as built-in security would fend off any overt attack. Likewise, it must be invisible to active defenses. There’s no point in forcing a downgrade if a regular Windows Update will undo your work, so it needs to be persistent. For that matter, why not make it impossible to reverse the attack?
</p>

<p>
	<br />
	<span style="font-size:22px;"><strong>The Weakest Link</strong></span>
</p>

<p>
	 
</p>

<p>
	On the face of it, Windows Update seems well-protected. Your PC submits a folder of files for update, but after that, a hardened Trusted Installer owns the show. It performs upgrades, catalogs what it did, digitally signs its activities, and makes everything ready to install the upgraded files at the next update.
</p>

<p>
	 
</p>

<p>
	Leviev noted several blind alleys that didn’t play out. Not until he looked at the list of actions that must be performed during that reboot. “Maybe I could compromise the action list? Where does it save its state between reboots?” he wondered.
</p>

<p>
	 
</p>

<p>
	Indeed, that proved to be the weak link. By controlling the action list, he could make changes to the system with the full power of Windows Update. To prevent the reversal of the changes, he compromised the component that parses the action list. He patched the System Integrity Checker so it wouldn’t flag his changes as illegitimate. When the fully fleshed-out attack finished, he could downgrade any part of Windows to a version subject to exploitation. “It makes the term 'fully patched' meaningless across any Windows machine worldwide,” concluded Leviev.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>Worthy of Applause</strong></span>
</p>

<p>
	 
</p>

<p>
	The presentation didn’t end there. Leviev went on to display more arcane abilities granted by his downgrade attack, up to and including compromising the Windows kernel and the Hypervisor system. With all the pieces in place, he performed a live demo that started with a safe Windows 11 installation and proceeded to disable Credential Guard and replace other important components, resulting in the ability to read out all the system passwords and other secrets. The audience didn’t quite go for a standing ovation, but they applauded with enthusiasm.
</p>

<p>
	 
</p>

<p>
	As far as I can tell, this attack remains valid. You’re not likely to see the effects on your own computer, but it could power a formidable targeted attack. Perhaps at the next Black Hat conference, we’ll enjoy a presentation from Microsoft’s designers on how they hardened Windows against this downdate attack.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.pcmag.com/news/this-attack-pushes-windows-update-to-the-dark-side" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24795</guid><pubDate>Thu, 08 Aug 2024 00:05:15 +0000</pubDate></item><item><title>A Flaw in Windows Update Opens the Door to Zombie Exploits</title><link>https://nsaneforums.com/news/security-privacy-news/a-flaw-in-windows-update-opens-the-door-to-zombie-exploits-r24781/</link><description><![CDATA[<h3>
	A researcher found a vulnerability that would let hackers strategically downgrade a target’s Windows version to reexpose patched vulnerabilities. Microsoft is working on fixes for the issue.
</h3>

<p>
	New research being presented at the <a href="https://www.wired.com/tag/black-hat/" rel="external nofollow">Black Hat</a> security conference in Las Vegas today shows that a vulnerability in Windows Update could be exploited to downgrade Windows to older versions, exposing a slew of historical vulnerabilities that then can be exploited to gain full control of a system. Microsoft says that it is working on a complex process to carefully patch the issue, dubbed “Downdate.”
</p>

<p>
	 
</p>

<p>
	Alon Leviev, the SafeBreach Labs researcher who discovered the flaw, says he started looking for possible downgrade attack methods after seeing that a startling hacking campaign from last year <a href="https://arstechnica.com/information-technology/2023/03/unkillable-uefi-malware-bypassing-secure-boot-enabled-by-unpatchable-windows-flaw/2/" rel="external nofollow">was using a type of malware</a> (known as the “BlackLotus UEFI bootkit”) that relied on downgrading the Windows boot manager to an old, vulnerable version. After probing the Windows Update flow, Leviev discovered a path to strategically downgrading Windows—either the entire operating system or just specifically chosen components. From there, he developed a proof-of-concept attack that utilized this access to disable the Windows protection known as Virtualization-Based Security (VBS) and ultimately target highly privileged code running in the computer's core “kernel.”
</p>

<p>
	 
</p>

<p>
	“I found a downgrade exploit that is fully undetectable because it is performed by using Windows Update itself,” which the system trusts, Leviev told WIRED ahead of his conference talk. “In terms of invisibility, I didn't uninstall any update—I basically updated the system even though under the hood it was downgraded. So the system is not aware of the downgrade and still appears up-to-date.”
</p>

<p>
	 
</p>

<p>
	Leviev's downgrade capability comes from a flaw in the components of the Windows Update process. To perform an upgrade, your PC places what is essentially a request to update in a special update folder. It then presents this folder to the Microsoft update server, which checks and confirms its integrity. Next, the server creates an additional update folder for you that only it can control, where it places and finalizes the update and also stores an action list—called “pending.xml”—that includes the steps of the update plan, such as which files will be updated and where the new code will be stored on your computer. When you reboot your PC, it takes the actions from the list and updates the software.
</p>

<p>
	 
</p>

<p>
	The idea is that even if your computer, including your update folder, is compromised, a bad actor can't hijack the update process because the crucial parts of it happen in the server-controlled update folder. Leviev looked closely at the different files in both the user's update folder and the server's update folder, though, and he eventually found that while he couldn't modify the action list in the server's update folder directly, one of the keys controlling it—called “PoqexecCmdline”—was not locked. This gave Leviev a way to manipulate the action list, and with it the entire update process, without the system realizing that anything was amiss.
</p>

<p>
	 
</p>

<div>
	<div aria-hidden="true" class="ConsumerMarketingUnitThemedWrapper-iUTMTf jssHut consumer-marketing-unit consumer-marketing-unit--article-mid-content" role="presentation">
		<div class="consumer-marketing-unit__slot consumer-marketing-unit__slot--article-mid-content consumer-marketing-unit__slot--in-content">
			 
		</div>

		<div class="journey-unit">
			 
		</div>
	</div>
</div>

<p>
	With this control, Leviev then found strategies to downgrade multiple key components of Windows, including drivers, which coordinate with hardware peripherals; dynamic link libraries, which contain system programs and data; and, crucially, the NT kernel, which contains the most core instructions for a computer to run. All of these could be downgraded to older versions that contain known, patched vulnerabilities. And Leviev even cast a wider net from there, to find strategies for downgrading Windows security components including the Windows Secure Kernel; the Windows password and storage component Credential Guard; the hypervisor, which creates and oversees virtual machines on a system; and VBS, the Windows virtualization security mechanism.
</p>

<p>
	 
</p>

<div class="AdWrapper-dQtivb fZrssQ ad ad--in-content">
	<div class="ad__slot ad__slot--in-content" data-node-id="vkyzoc">
		 
	</div>
</div>

<p>
	The technique does not include a way to first gain remote access to a victim device, but for an attacker who already has initial access, it could enable a true rampage, because Windows Update is such a trusted mechanism and can reintroduce a vast array of dangerous vulnerabilities that have been fixed by Microsoft over the years. Microsoft says that it has not seen any attempts to exploit the technique.
</p>

<p>
	 
</p>

<p>
	“We are actively developing mitigations to protect against these risks while following an extensive process involving a thorough investigation, update development across all affected versions, and compatibility testing, to ensure maximized customer protection with minimized operational disruption,” a Microsoft spokesperson told WIRED in a statement.
</p>

<p>
	 
</p>

<p>
	Part of the company's fix involves revoking vulnerable VBS system files, which must be done carefully and gradually, because it could cause integration issues or reintroduce other, unrelated problems that were previously addressed by those same system files.
</p>

<p>
	 
</p>

<p>
	Leviev emphasizes that downgrade attacks are an important threat for the developer community to consider as hackers endlessly seek paths into target systems that are stealthy and difficult to detect.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.wired.com/story/windows-update-downdate-exploit/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every single day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of July): 3,313 news posts</em></span>
</p>
]]></description><guid isPermaLink="false">24781</guid><pubDate>Wed, 07 Aug 2024 17:53:50 +0000</pubDate></item><item><title>This Caller Does Not Exist: Using AI to Conduct Vishing Attacks</title><link>https://nsaneforums.com/news/security-privacy-news/this-caller-does-not-exist-using-ai-to-conduct-vishing-attacks-r24771/</link><description><![CDATA[<p>
	 
</p>

<p>
	As technology advances, threat actors increasingly leverage these innovations to conduct social engineering attacks including vishing, targeting the human element that technical controls often cannot fully safeguard.
</p>

<p>
	<br />
	<span style="font-size:22px;"><strong>What is Vishing?</strong></span>
</p>

<p>
	 
</p>

<p>
	Voice phishing, also known as Vishing, is a type of social engineering attack that uses phone calls or audio messages as a delivery method. These calls deceive people into divulging personal, financial or sensitive information. Vishing calls can also be used to convince people to carry out a malicious action such as resetting the password of a user account or transferring money to a threat actor’s bank account.
</p>

<p>
	 
</p>

<p>
	Social engineering attacks are increasing year-over-year in complexity, sophistication, and frequency.  Threat actors are looking for alternative attack paths as defensive technologies improve at detecting, mitigating and stopping cyberattacks. These technological advancements are apparent in the prolific use of artificial intelligence and machine learning in defensive operations. However, AI is also being used in offensive operations as well. In this blog post, GuidePoint’s Threat and Attack Simulation Team (TAS) will explore how threat actors can leverage AI-generated voices to social engineer their targets and provide guidance on how to protect you and your organization.
</p>

<p>
	 
</p>

<p>
	The following is a quick reference on the tools and platforms used in this post:
</p>

<p>
	 
</p>

<ul>
	<li>
		<span style="color:#2980b9;"><strong>ElevenLabs</strong></span> – Used to create AI-generated voices using text-to-speech or speech-to-speech capabilities. Voices can also be cloned by uploading a one-minute video or soundbite.
	</li>
	<li>
		<span style="color:#2980b9;"><strong>Soundux</strong> </span>– A free and open-source soundboard that can be used to play AI-generated speech during a phone call.
	</li>
	<li>
		<span style="color:#2980b9;"><strong>Voicemeeter</strong></span> – An audio mixer application that can create virtual sound cards and allow Soundux audio to be used in voice-over-internet protocol (VoIP) calls or virtual meetings. Background sounds can also be introduced to add legitimacy to these attacks.
	</li>
	<li>
		<span style="color:#2980b9;"><strong>Google Voice</strong> </span>– A VoIP provider that can place phone calls from a computer.
	</li>
</ul>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>Use Cases and Scenarios</strong></span>
</p>

<p>
	 
</p>

<p>
	Threat actors routinely use social engineering attacks to go after “high-value” targets. What makes a person a “high-value” target? It depends on the threat actor, but typically an attacker is going to target someone who has access to:
</p>

<p>
	 
</p>

<ul>
	<li>
		    Sensitive financial information.
	</li>
	<li>
		    Intellectual property.
	</li>
	<li>
		    Internal servers or data centers.
	</li>
</ul>

<p>
	 
</p>

<p>
	No matter what job role a person has, they have access to information that threat actors want. This means that everyone is a potential target for social engineering attacks. The following scenarios are real-world examples of social engineering attacks where a threat actor uses AI-generated voices.
</p>

<p>
	 
</p>

<ul>
	<li>
		A threat actor discovers an interview featuring the CEO of a company. Using this audio, the CEO’s voice is cloned using AI. The threat actor then calls a subsidiary company to request a wire transfer and receives $243,000. (<span style="color:#2980b9;">Source: Forbes</span>)
	</li>
	<li>
		A threat actor discovers valid credentials in a data breach. They clone the voice of an employee using AI and contact the company’s IT help desk. The threat actor convinces the IT help desk to reset the user’s multi-factor authentication profile. After gaining access to the internal network, the threat actor deploys ransomware causing nearly $100,000,000 in damages. (<span style="color:#2980b9;">Source: CyberArk</span>)
	</li>
</ul>

<p>
	 
</p>

<p>
	The best way to defend against these attacks is by educating ourselves on how threat actors operate, and to become familiar with the tools, techniques and procedures used to carry out these attacks.
</p>

<p>
	<br />
	<span style="font-size:22px;"><strong>Why Use Text-To-Speech?</strong></span>
</p>

<p>
	 
</p>

<p>
	Real-time voice changing using AI-generated voice files can be challenging and it isn’t as realistic as text-to-speech. The current technology for real-time voice changing isn’t convincing enough. However, with the current speed of innovation regarding AI voice technology, that may change very soon!
</p>

<p>
	<br />
	<span style="font-size:22px;"><strong>Generating AI Voices</strong></span>
</p>

<p>
	 
</p>

<p>
	<span style="color:#2980b9;">ElevenLabs</span> offers free and paid subscription plans to create AI-generated audio. While the default voices provided by ElevenLabs work well, they sound more like a voiceover for a commercial than a user calling to reset their password.
</p>

<p>
	 
</p>

<p>
	ElevenLabs has a voice library that includes various voice models that can better handle natural speech. This can be accessed by navigating to the “Voices” tab, then to “Voice Library”.
</p>

<p>
	 
</p>

<p>
	Advanced filters can be applied to determine the type of voice, age, language, and accent used by clicking the filter button on the right side of the filter bar.
</p>

<p>
	 
</p>

<p>
	The voice you pick will be added under your “Voices” tab where you can generate audio from text.
</p>

<p>
	 
</p>

<p>
	Each voice can be modified to change the tone and overall sound of the generated audio. This is also where you can clone a voice using existing audio or video. This is a premium feature and requires a paid subscription, but any custom voices will be saved within the “VoiceLab” tab.
</p>

<p>
	 
</p>

<p>
	Using the Multilingual model, audio can be produced in multiple languages depending on the prompt. Various modifications can be made to change how the AI voice sounds.
</p>

<p>
	 
</p>

<ul>
	<li>
		Stability will determine how “natural” the voice sounds. A more variable setting percentage will add intonation, inflection, and tone to different areas of the prompt.
	</li>
	<li>
		A higher similarity will make the AI voice sound more robotic. Each voice model is unique, and some may require changes to the similarity setting percentage to sound more “natural”.
	</li>
	<li>
		Some voice models will allow you to change the style exaggeration percentage. Think of this as increasing the emotions in a message.
	</li>
</ul>

<p>
	 
</p>

<p>
	These can sometimes sound jarring, and with each model being unique, there will need to be minor changes to get the audio to sound perfect.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>Adding Pauses, Stammering and Filler Words</strong></span>
</p>

<p>
	 
</p>

<p>
	To better mirror natural speaking, you can add special tags within the prompt that will make the AI voice pause or throw in some “uhhs” or “ahhs” between words.
</p>

<p>
	 
</p>

<p>
	Adding a break tag will make the voice pause. Keep in mind that the maximum pause is three seconds.
</p>

<p style="margin-left:40px;">
	<br />
	“This is an example of what my AI voice will say” &lt;break time=”2.5s” /&gt; “After a short break I am back!”
</p>

<p>
	 
</p>

<p>
	Additional stammering or filler phrases can be added by using an ellipsis (…) between words.
</p>

<p style="margin-left:40px;">
	<br />
	… This is an example of what my AI voice will say … Let’s get to hacking!
</p>

<p style="margin-left:40px;">
	 
</p>

<p>
	Sometimes the audio might be too rushed, or there might be a pause in the wrong place. You can regenerate the speech and get a new audio file.
</p>

<p>
	 
</p>

<p>
	These audio files can also be slowed down using free audio editing software such as Audacity. After installing Audacity and opening the audio file, the sound clip can be slowed down without changing the pitch by first selecting the clip, then by clicking the “Effect” tab. Next, expand the “Pitch and Tempo” submenu, and select “Change Speed and Pitch”.
</p>

<p>
	 
</p>

<p>
	Save the generated or edited files locally in a new project folder. This project folder will be used later by Soundux to play the AI-generated audio through a phone call. Name the file after your prompt, this will make it easier to find the sentence you want to play on the call.
</p>

<p>
	<br />
	<span style="font-size:22px;"><strong>Creating Prompts</strong></span>
</p>

<p>
	 
</p>

<p>
	Good storytellers have captivated people for millennia. Social engineering attacks are like stories, threat actors impersonate the reality we see around us to deceive and trick people into acting. Threat actors can be thought of as theatrical actors in the sense that developing a realistic attack scenario or pretext requires a sense of acting.
</p>

<p>
	 
</p>

<p>
	Have you ever called an IT help desk or technical support about an annoying issue? Social engineering attacks follow the same conventions and conversational flow.
</p>

<p>
	 
</p>

<p>
	“Thank you for calling the Acme co-helpdesk, this is Adam speaking.”
</p>

<p>
	 
</p>

<p>
	“Hey there Adam, this is James Doe. I’m hoping you can help me out here, I tried changing my password on my own and it didn’t work. Can you give me a temporary password so I can get back to work?”
</p>

<p>
	 
</p>

<p>
	These conversational flows can be pre-scripted, writing out a response to any possible questions or reactions will allow a threat actor to have an AI-generated response for any situation.
</p>

<p>
	<br />
	<span style="font-size:22px;"><strong>Creating a Sound Board</strong></span>
</p>

<p>
	 
</p>

<p>
	Once the voice files are saved, they will be played using Soundux, a free and open-source soundboard project. A Soundux installer <span style="color:#2980b9;">can be found here</span>, or the executable can be compiled from the source code from the project’s <span style="color:#2980b9;">GitHub</span> <span style="color:#2980b9;">repository.</span>
</p>

<p>
	 
</p>

<p>
	Soundux may produce an error about the audio output. Because we are using a custom audio engine, this error can be ignored.
</p>

<p>
	 
</p>

<p>
	After installing the software, configure Soundux to use the audio project folder that was created earlier by clicking “Add Tab”. This will import the audio files and allow them to be played.
</p>

<p>
	 
</p>

<p>
	Afterward, click “Reload” to import the audio files. Click on the title of the file and it will play it using your assigned output device.
</p>

<p>
	<br />
	<span style="font-size:22px;"><strong>Installing and Configuring the Audio Engine</strong></span>
</p>

<p>
	 
</p>

<p>
	Voicemeeter offers a free audio mixing engine that can create virtual sound ports on your machine. This means that you can route audio from a program like Soundux and use that audio as input to another program such as Google Voice or any other VoIP provider.
</p>

<p>
	 
</p>

<p>
	Voicemeeter Banana can be downloaded <span style="color:#2980b9;">here</span>.
</p>

<p>
	 
</p>

<p>
	Next, Voicemeeter and Soundux will be configured to work together. Within Soundux, change the “Output Device” to “Voicemeeter Input”.
</p>

<p>
	 
</p>

<p>
	This will force Soundux to output the AI-generated audio to Voicemeeter. The “Voicemeeter Input” value is enabled by default. To hear the AI-generated audio, “A1” must be enabled for the “Voicemeeter Input” column. Enabling “B1” will allow the audio to be played in a virtual port and used by other programs like a microphone. The following image explains each function within Voicemeeter.
</p>

<p>
	 
</p>

<p>
	Additional adjustments can be made such as increasing the bass of the audio by enabling the “EQ” in the virtual audio out column. The volume of the AI-generated voice can be lowered if needed using the fader gain slider in the same column.
</p>

<p>
	 
</p>

<p>
	Soundux should now output sound using Voicemeeter as an audio engine. The sound can be tuned and modified depending on the audio samples.
</p>

<p>
	<br />
	<span style="font-size:22px;"><strong>Conducting the Vishing Attack</strong></span>
</p>

<p>
	 
</p>

<p>
	VoIP providers such as Google Voice, Twilio, or Vonage can be used to make phone calls using a desktop computer. These aren’t the only platforms that can be used to carry out vishing attacks. Software such as Microsoft Teams, Zoom, or Cisco WebEx can be used to start audio calls. For example, a threat actor can impersonate an internal user, clone their voice, or create a voice within their demographic, and invite another person to an audio-only meeting.
</p>

<p>
	 
</p>

<p>
	For this example, Google Voice will be used to make phone calls.
</p>

<p>
	 
</p>

<p>
	After configuring a free phone number or transferring an existing phone number, Google Voice will need to be configured to use the virtual output of Voicemeeter as the microphone. These settings can be accessed by clicking the headset button shown below.
</p>

<p>
	 
</p>

<p>
	Configure the microphone within Google Voice and select “Voicemeeter Out B1”. Ensure “B1” is enabled under the “Voicemeeter Input” column. Next, set the ringing and speaker settings to “Voicemeeter AUX Input”.  The following image highlights the associated areas in their respective colors.
</p>

<p>
	 
</p>

<p>
	Make a test call using <span style="color:#2980b9;">Google Voice</span> to test the attack and adjust the output of the AI-generated voice as needed. To adjust the volume of the AI voice, lower the fader gain in the first virtual output column as seen below.
</p>

<p>
	 
</p>

<p>
	Click each audio clip within Soundux that your AI voice will say during the conversation. The audio of the person who called will be outputted to your headphones or speakers, allowing you to quickly reply as if you were talking on the phone.
</p>

<p>
	<br />
	<span style="font-size:22px;"><strong>Defending Against AI Vishing Attacks</strong></span>
</p>

<p>
	 
</p>

<p>
	As the use of AI increases, so will the abuse of AI. Threat actors will always update their tactics to match the latest advances in technology. There are some ways to protect your organization and protect yourself. The term “trust but verify” is at the core of defending against vishing attacks.
</p>

<p>
	 
</p>

<ul>
	<li>
		Educate users on the rise of AI-based social engineering attacks. Users not only need to closely monitor emails but phone calls and meetings as well. Implement this education within your security awareness training.
	</li>
	<li>
		Implement strong identity verification steps across help desks and support groups. Ensure that phone calls are verified with a form of multi-factor authentication (MFA).
	</li>
</ul>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>What Does Strong Identity Verification Look Like?</strong></span>
</p>

<p>
	 
</p>

<p>
	The first step would be to move away from only requiring personal information as a verification measure. Threat actors often conduct reconnaissance on their victims ahead of an attack, looking for birthdates, addresses, pets, or the names of people’s children. All this information can be found on social media, public records, or public data leaks.
</p>

<p>
	 
</p>

<p>
	If a user calls the help desk requesting any activity that could change the details of an account such as a password, or a multi-factor authentication token, the term “trust but verify” should come into effect. One way to stop vishing attacks is to require a physical method to verify their identity.
</p>

<p>
	 
</p>

<p>
	If a user requests a password reset, the help desk can send a push notification or request a verification code from their device that handles multi-factor authentication. A remote threat actor would need to have physical access to the legitimate user’s device or carry out extensive attacks to gain access to their phone or physical authentication device.
</p>

<p>
	 
</p>

<p>
	“Trust but verify” can also apply to your personal life as well. Threat actors don’t only target organizations and governments but increasingly target everyday people directly.
</p>

<p>
	 
</p>

<p>
	We all get phone calls from trusted sources, some of which may require sensitive information. A good measure is to call them back directly and request some form of authentication. This will rule out caller ID spoofing and get you one step closer to verifying the call. Perhaps they could send a push notification to your phone or send you an email to verify the call.
</p>

<p>
	 
</p>

<p>
	No matter what, properly verifying communications can mitigate the risk of a successful social engineering attack. As the threat landscape changes and technology progresses, we all must have a sense of caution and “trust but verify” as a standard moving forward.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://securityboulevard.com/2024/08/this-caller-does-not-exist-using-ai-to-conduct-vishing-attacks/" rel="external nofollow">Source</a></strong>
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">24771</guid><pubDate>Wed, 07 Aug 2024 14:53:53 +0000</pubDate></item><item><title>New Linux kernel attack slips past modern defenses &#x2014; SLUBStick boasts a 99% success rate</title><link>https://nsaneforums.com/news/security-privacy-news/new-linux-kernel-attack-slips-past-modern-defenses-%E2%80%94-slubstick-boasts-a-99-success-rate-r24770/</link><description><![CDATA[<p>
	<span style="font-size:20px;">Attack vector boasts 99% success rate under many conditions</span>
</p>

<p>
	 
</p>

<p>
	Researchers at the Graz University of Technology in Austria have found a new cross-cache attack (PDF) that can bypass modern kernel defenses and provide arbitrary read and write access. The exploits involved affect Linux kernel versions 5.19 and 6.2.
</p>

<p>
	 
</p>

<p>
	The team has dubbed the attack technique SLUBStick. This attack vector takes advantage of memory reuse of the kernel allocator in a novel way, making it more reliable than most other cross-cache attacks. Whereas most cross-cache attacks have a success rate of just 40%, the researchers pushed SLUBStick to a 99% success rate for frequently used generic caches.
</p>

<p>
	 
</p>

<p>
	This success rate comes despite the modern security protections available for the Linux kernel. Recognizing the susceptibility of the Linux kernel to memory safety vulnerabilities, researchers and kernel developers have included defenses to inhibit the success of cross-cache attacks.
</p>

<p>
	 
</p>

<p>
	SLUBStick, however, is capable of bypassing Supervisor Mode Execution Prevention (SMEP), Supervisor Mode Access Prevention (SMAP), and Kernel Address Space Layout Randomization (KASLR). The researchers note that existing kernel defenses promise to reduce SLUBStick’s threat, but none currently provide comprehensive protection. Therefore, the danger of exploitation via SLUBStick is still natural, even with kernel defenses in use.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>CVEs tested using SLUBStick attack vector</strong></span>
</p>

<p>
	 
</p>

<table>
	<thead>
		<tr>
			<th colspan="1" style="text-align:left;">
				CVE
			</th>
			<th colspan="1" style="text-align:left;">
				Capability
			</th>
			<th colspan="1" style="text-align:left;">
				Cache
			</th>
		</tr>
	</thead>
	<tbody>
		<tr>
			<td colspan="1" style="text-align:left;">
				CVE-2023-21400
			</td>
			<td colspan="1" style="text-align:left;">
				Double Free
			</td>
			<td colspan="1" style="text-align:left;">
				kmalloc-32
			</td>
		</tr>
		<tr>
			<td colspan="1" style="text-align:left;">
				CVE-2023-3609
			</td>
			<td colspan="1" style="text-align:left;">
				Use After Free
			</td>
			<td colspan="1" style="text-align:left;">
				kmalloc-96
			</td>
		</tr>
		<tr>
			<td colspan="1" style="text-align:left;">
				CVE-2022-32250
			</td>
			<td colspan="1" style="text-align:left;">
				Use After Free
			</td>
			<td colspan="1" style="text-align:left;">
				kmalloc-64
			</td>
		</tr>
		<tr>
			<td colspan="1" style="text-align:left;">
				CVE-2022-29582
			</td>
			<td colspan="1" style="text-align:left;">
				Use After Free
			</td>
			<td colspan="1" style="text-align:left;">
				files_cachep
			</td>
		</tr>
		<tr>
			<td colspan="1" style="text-align:left;">
				CVE-2022-27666
			</td>
			<td colspan="1" style="text-align:left;">
				Out Of Bounds
			</td>
			<td colspan="1" style="text-align:left;">
				kmalloc-4096
			</td>
		</tr>
		<tr>
			<td colspan="1" style="text-align:left;">
				CVE-2022-2588
			</td>
			<td colspan="1" style="text-align:left;">
				Double Free
			</td>
			<td colspan="1" style="text-align:left;">
				kmalloc-192
			</td>
		</tr>
		<tr>
			<td colspan="1" style="text-align:left;">
				CVE-2022-0995
			</td>
			<td colspan="1" style="text-align:left;">
				Out Of Bounds
			</td>
			<td colspan="1" style="text-align:left;">
				kmalloc-96
			</td>
		</tr>
		<tr>
			<td colspan="1" style="text-align:left;">
				CVE-2021-4157
			</td>
			<td colspan="1" style="text-align:left;">
				Out Of Bounds
			</td>
			<td colspan="1" style="text-align:left;">
				kmalloc-64
			</td>
		</tr>
		<tr>
			<td colspan="1" style="text-align:left;">
				CVE-2021-3492
			</td>
			<td colspan="1" style="text-align:left;">
				Double Free
			</td>
			<td colspan="1" style="text-align:left;">
				kmalloc-4096
			</td>
		</tr>
	</tbody>
</table>

<p>
	 
</p>

<p>
	SLUBStick takes advantage of a heap vulnerability in Linux’s memory management to gain elevated privileges, break out of sandbox environments in virtual machines, and gain root access to the host system. Even worse, the technique uses a side-channel exploit to observe memory usage and determine the exact moment of whether or not to reallocate a memory hash. This means that SLUBStick can predict and control memory reuse to increase its success rate.
</p>

<p>
	 
</p>

<p>
	For SLUBStick to work, attackers need local access to the attacked Linux system. The attack also requires the presence of a heap vulnerability in the Linux kernel, which has been found in both the 5.19 Linux kernel and the 6.2 kernel.
</p>

<p>
	 
</p>

<p>
	The researchers systematically analyzed the attack on the two Linux kernel versions, finding that SLUBStick was effective at executing on generic cache from kmalloc-08 through kmalloc-4096. Using a synthetic vulnerability and nine real-world CVEs, they tested the attack method to escalate privileges and gain root access.
</p>

<p>
	 
</p>

<p>
	SLUBStick was tested on both x86 and aarch64 virtual machines, and it is equally effective on Intel—and AMD-based processors and Arm CPUs. The team notes that the attack technique afforded by SLUBStick “greatly enhances the reliability of cross-cache attacks from generic caches and makes them practical for exploitation.” In other words, SLUBStick can make other attacks more successful and effective.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.tomshardware.com/tech-industry/cyber-security/new-linux-kernel-attack-slips-past-modern-defenses" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24770</guid><pubDate>Wed, 07 Aug 2024 14:37:33 +0000</pubDate></item><item><title>'Criminals are preying on Windows users': Software subject of CISA, cybersecurity warnings</title><link>https://nsaneforums.com/news/security-privacy-news/criminals-are-preying-on-windows-users-software-subject-of-cisa-cybersecurity-warnings-r24757/</link><description><![CDATA[<p>
	The U.S. Cybersecurity and Infrastructure Security Agency added a vulnerability in Microsoft's Windows 10 software to a list of exploited security weak spots.
</p>

<p>
	 
</p>

<p>
	CISA said that "Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution," in a listing added to the agency's Known Exploited Vulnerability Catalog Monday.
</p>

<p>
	 
</p>

<p>
	The listing advised users to stop using software or utilize a patch through Windows.
</p>

<p>
	 
</p>

<p>
	CISA said that it did not know if the vulnerability, titled CVE-2018-0824, had been used in a ransomware campaign but a CISCO Talos report released Thursday said that a Chinese hacking group utilized the vulnerability in an attack on a Taiwanese government research center. The report said the center was, "likely compromised."
</p>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>Second organization issues Windows warning</strong></span>
</p>

<p>
	 
</p>

<p>
	CISA was not the only organization to issue a warning to Windows users Monday.
</p>

<p>
	 
</p>

<p>
	"Criminals are preying on Windows users yet again, this time in an effort to hit them with a keylogger that can also steal credentials and take screenshots," enterprise technology news site the Register reported Monday.
</p>

<p>
	 
</p>

<p>
	The outlet reported that FortiGuard Labs, a threat intelligence agency, found an uptick in malware attacks with SnakeKeylogger. The malware is known to steal credentials and record keystrokes in infected machines.
</p>

<p>
	 
</p>

<p>
	It was originally sold on a subscription basis on Russian crime forums and became a major threat in 2020, according to the Register.
</p>

<p>
	 
</p>

<p>
	In 2022 Check Point Research, a cyber security firm, warned that the malware, "is usually spread through emails that include docx or xlsx attachments with malicious macros," and through PDF files.
</p>

<p>
	 
</p>

<p>
	The warnings come on the heels of the "Crowdstrike outage" in July, where a defective software update rendered devices using Windows software useless for hours.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.usatoday.com/story/tech/news/2024/08/06/windows-vunerabilities-hackers/74694219007/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24757</guid><pubDate>Wed, 07 Aug 2024 00:38:26 +0000</pubDate></item><item><title>INTERPOL Recovers $41 Million in Largest Ever BEC Scam in Singapore</title><link>https://nsaneforums.com/news/security-privacy-news/interpol-recovers-41-million-in-largest-ever-bec-scam-in-singapore-r24756/</link><description><![CDATA[<p>
	INTERPOL said it devised a "global stop-payment mechanism" that helped facilitate the largest-ever recovery of funds defrauded in a business email compromise (BEC) scam.
</p>

<p>
	 
</p>

<p>
	The development comes after an unnamed commodity firm based in Singapore fell victim to a BEC scam in mid-July 2024. It refers to a type of cybercrime where a malicious actor poses as a trusted figure and uses email to trick targets into sending money or divulging confidential company information.
</p>

<p>
	 
</p>

<p>
	Such attacks can take place in myriad ways, including gaining unauthorized access to a finance employee or a law firm's email account to send fake invoices or impersonating a third-party vendor to email a phony bill.
</p>

<p>
	 
</p>

<p>
	"On 15 July, the firm had received an email from a supplier requesting that a pending payment be sent to a new bank account based in Timor-Leste," INTERPOL said in a press statement. "The email, however, came from a fraudulent account spelled slightly different to the supplier's official email address."
</p>

<p>
	 
</p>

<p>
	The Singaporean company is said to have transferred $42.3 million to the non-existent supplier on July 19, only for it to realize the blunder on July 23 after the actual supplier said it had not been compensated.
</p>

<p>
	 
</p>

<p>
	However, by taking advantage of INTERPOL's Global Rapid Intervention of Payments (I-GRIP) mechanism, authorities in Singapore managed to detect $39 million and froze the counterfeit bank account a day later.
</p>

<p>
	 
</p>

<p>
	Separately, seven suspects have been arrested in the Southeast Asian nation in connection with the scam, leading to the further recovery of $2 million.
</p>

<p>
	 
</p>

<p>
	Back in June, I-GRIP was used to trace and intercept the illicit proceeds stemming from fiat and cryptocurrency crime, successfully recovering millions and intercepting hundreds of thousands of BEC accounts as part of a global police operation named First Light.
</p>

<p>
	 
</p>

<p>
	"Since its launch in 2022, INTERPOL's I-GRIP mechanism has helped law enforcement intercept hundreds of millions of dollars in illicit funds," the agency said.
</p>

<p>
	 
</p>

<p>
	"INTERPOL is encouraging businesses and individuals to take preventative steps to avoid falling victim to business email compromise and other social engineering scams."
</p>

<p>
	 
</p>

<p>
	The disclosure follows the law enforcement seizure of an online digital wallet and cryptocurrency exchange known as Cryptonator for allegedly receiving criminal proceeds of computer intrusions and hacking incidents, ransomware scams, various fraud markets, and identity theft schemes.
</p>

<p>
	 
</p>

<p>
	Cryptonator, launched in December 2013 by Roman Boss, has also been accused of failing to institute appropriate anti-money laundering controls in place. The U.S. Justice Department indicted Boss for founding and operating the service.
</p>

<p>
	 
</p>

<p>
	Blockchain intelligence firm TRM Labs said the platform facilitated more than 4 million transactions worth a total of $1.4 billion, with Boss taking a small cut from each transaction. This comprised money exchanged with darknet markets, scam wallet addresses, high-risk exchanges, ransomware groups, crypto theft operations, mixers, and sanctioned addresses.
</p>

<p>
	 
</p>

<p>
	Specifically, cryptocurrency addresses controlled by Cryptonator transacted with darknet markets, virtual exchanges, and criminal marketplaces like Bitzlato, Blender, Finiko, Garantex, Hydra, Nobitex, and an unnamed terrorist entity.
</p>

<p>
	 
</p>

<p>
	"Hackers, darknet market operators, ransomware groups, sanctions evaders and others threat actors gravitated to the platform to exchange cryptocurrencies as well as cash out crypto into fiat currency," TRM Labs noted.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="crypto.png" class="ipsImage" data-ratio="75.10" height="540" width="685" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjDWhzJ0ZNQe34yloIe0zEa7LyoVFrCaP7Dw4JnrmySI26bpz2qkRyjB9WAc1qtyntK3_Z5EO3Erovsboal-6Jdp_TVHwJnBqBg7Y0edYiBdZECyq1g2wWhcca3HLxrTKohemjWvugm8Lp0ASS_dT4D2d9OYMcrffCuKvZrK3nAatLBF1EcVGXrp8B3JJEf/s728-rw-e365/crypto.png" />
</p>

<p style="text-align:center;">
	 
</p>

<p>
	The popularity of cryptocurrency has created plenty of opportunities for fraud, with threat actors constantly devising new ways to drain victims' wallets over the years.
</p>

<p>
	 
</p>

<p>
	Indeed, a recent report from Check Point found that fraudsters are abusing legitimate blockchain protocols like Uniswap and Safe.global to conceal their malicious activities and siphon funds from cryptocurrency wallets.
</p>

<p>
	 
</p>

<p>
	"Attackers leverage the Uniswap Multicall contract to orchestrate fund transfers from victims' wallets to their own," researchers said.
</p>

<p>
	 
</p>

<p>
	"Attackers have been known to use the Gnosis Safe contracts and framework, coaxing unsuspecting victims into signing off on fraudulent transactions."
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://thehackernews.com/2024/08/interpol-recovers-41-million-in-largest.html" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24756</guid><pubDate>Wed, 07 Aug 2024 00:33:17 +0000</pubDate></item><item><title>A New Plan to Break the Cycle of Destructive Critical Infrastructure Hacks</title><link>https://nsaneforums.com/news/security-privacy-news/a-new-plan-to-break-the-cycle-of-destructive-critical-infrastructure-hacks-r24752/</link><description><![CDATA[<p>
	<span style="font-size:18px;"><strong>As digital threats against US water, food, health care, and other vital sectors loom large, a new project called UnDisruptable27 aims to help fix cybersecurity weaknesses where other efforts have failed.</strong></span>
</p>

<p>
	 
</p>

<p>
	An endless parade of data breaches, brutally disruptive ransomware attacks, and crippling IT outages has somehow become the norm around the world. And in spite of escalating impacts to critical infrastructure and daily life, progress has been intermittent and often fleeting. Something's gotta give—and at the BSides Las Vegas security conference this week, a longtime critical-infrastructure security researcher is launching a project to communicate with utility operators, municipalities, and regular people in creative ways about both urgency and optimism around protecting critical infrastructure now.
</p>

<p>
	 
</p>

<p>
	Dubbed UnDisruptable27, the project will start as a pilot with a $700,000 grant for the first year through Craig Newmark Philanthropies' Cyber Civil Defense coalition. Led by Josh Corman, who was chief strategist for the US Cybersecurity and Infrastructure Security Agency's Covid Task Force, in collaboration with the Institute for Security and Technology (IST), the project will focus on the critical interdependence of water, food, emergency medical care, and power as the backbone of human safety. Corman says that the key goal is to foster new discourse about these challenges inspired by the disaster management tenets “inform, influence, inspire.” In other words, people need to understand the risks and feel empowered that they can take action.
</p>

<p>
	 
</p>

<p>
	“We are overdependent on undependable things. No one should feel comfortable with the potential for harm here with our current state of defense,” Corman told WIRED ahead of the announcement. “Our dependence on connected tech has grown faster than our ability to secure it. People have been doing good things, but public policy takes time, and I think this year we need to cross certain thresholds on the sense of urgency.”
</p>

<p>
	 
</p>

<p>
	One of Corman's main motivations to launch the effort as quickly as possible came from comments made during a January congressional hearing about the cybersecurity threat China poses to the US. In the hearing, then Cyber Command head and NSA director Paul Nakasone, Cybersecurity and Infrastructure Security Agency director Jen Easterly, FBI director Christopher Wray, and head of the Office of the National Cyber Director Harry Coker Jr. testified about pressing threats to US critical infrastructure, including specific campaigns the Chinese hacking group known as Volt Typhoon has been conducting to pre-position itself in US water infrastructure. The goal of this targeting is apparently to create leverage and a credible threat against the US as part of a Chinese plan to invade Taiwan, potentially in 2027.
</p>

<p>
	 
</p>

<p>
	“The budgets that emerge from discussions underway now will dictate what kind of resources we have ready in 2027, a year that, as this committee knows all too well, the CCP has circled on its calendar,” Wray told the US House of Representatives committee in January. “And that year will be on us before you know it. As I've described, the PRC is already today putting their pieces in place. I do not want those watching today to think we can't protect ourselves, but I do want the American people to know that we cannot afford to sleep on this danger.”
</p>

<p>
	 
</p>

<p>
	Having worked on embedded device security and critical infrastructure defense for years, including through the decade-old grassroots computer security and human safety initiative he founded known as I Am the Cavalry, Corman says that it felt significant that some of the nation's top intelligence officials were warning Congress of such specific threats to US infrastructure in an unclassified setting.
</p>

<p>
	 
</p>

<p>
	“It’s not just that the water goes out, it’s that when the sole wastewater facility in your community is down really bad things start to happen. For example, no water means no hospital,” he says. “I really encountered a lot of this during my leadership of the Covid Task Force. There is such interdependence across the basic functions of society.”
</p>

<p>
	 
</p>

<p>
	UnDisruptable27 will focus on interacting with communities who aren't reached by Washington, DC-based policy discussions or Information Sharing and Analysis Centers (ISACs), which are meant to represent each infrastructure sector of the US. The project aims to communicate directly with people who actually work on the ground in US critical infrastructure, and grapple together with the reality that cybersecurity-related disasters could impact their daily work.
</p>

<p>
	 
</p>

<p>
	“There’s a data breach, you get whatever services like identity protection for some period of time, and life carries on, and people think that there’s no long-term impact," says Megan Stifel, IST's chief strategy officer. “There’s this expectation that it’s fine, things will just continue. So we’re very interested in getting after this issue and thinking about how do we tackle critical infrastructure security with perhaps a new approach.”
</p>

<p>
	 
</p>

<p>
	Corman notes that even though cybersecurity incidents have become a well-known fact of life, business owners and infrastructure operators are often shaken and caught off guard when a cybersecurity incident actually affects them. Meanwhile, when government entities try to impose cybersecurity standards or become a partner on defense initiatives, communities often balk at the intrusion and perceived overreach. Last year, for example, the US Environmental Protection Agency was forced to rescind new cybersecurity guidelines for water systems after water companies and Republicans in Congress filed a lawsuit over the initiative.
</p>

<p>
	 
</p>

<p>
	“Time and time again, trade associations or lobbyists or owners and operators have an allergic reaction to oversight and say, ‘We prefer voluntary, we’re doing fine on our own,’” Corman says. “And they really are trying to do the right thing. But then also time and time again, people are just shocked that disruption could happen and feel very blindsided. So you can only conclude that the people who feel the pain of our failures are not included in the conversation. They deserve to understand the risks inherent in this level of connectivity. We’ve tried a lot of things, but we have not tried just leveling with people.”
</p>

<p>
	 
</p>

<p>
	UnDisruptable27 is launching this week for visibility among attendees at BSides as well as the other conferences, Black Hat and Defcon, that will run through Sunday in Las Vegas. Corman says that the goal is to combine the hacker mentality and, essentially, a call for volunteers with plans to work with creative collaborators on producing engaging content to fuel discourse and understanding. Information campaigns using memes and social media posts or moonshots like narrative podcasts and even reality TV are all on the table.
</p>

<p>
	 
</p>

<p>
	“We must prioritize the security, safety, and resilience of critical infrastructure—including water, health care facilities, and utilities," Craig Newmark, the Craigslist founder whose philanthropy is funding UnDisruptable27, told WIRED. "The urgency of this issue requires affecting human behavior through storytelling.”
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.wired.com/story/undisruptable27-us-critical-infrastructure-cybersecurity/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24752</guid><pubDate>Tue, 06 Aug 2024 22:20:43 +0000</pubDate></item><item><title>Defeat censorship with Stealth, our new VPN protocol</title><link>https://nsaneforums.com/news/security-privacy-news/defeat-censorship-with-stealth-our-new-vpn-protocol-r24738/</link><description><![CDATA[<p>
	We’ve developed a new VPN protocol, Stealth, that can avoid detection and let you bypass internet censorship and VPN blocks.
</p>

<p>
	 
</p>

<p>
	We’re pleased to announce Stealth, a new, undetectable VPN protocol that can bypass most firewalls and VPN blocking methods. You’ll be able to bypass advanced VPN blocks, access censored sites, and communicate with people on social media, even if your government is trying to restrict access.
</p>

<p>
	<br />
	<span style="font-size:20px;"><strong>Why is Stealth needed?</strong></span>
</p>

<p>
	 
</p>

<p>
	In 2017, we launched Proton VPN because there was no trustworthy, reliable, and freely available VPN service. Our motivation was simple.
</p>

<p>
	 
</p>

<p>
	Because our services, such as Proton Mail, play a crucial role in ensuring freedom and privacy worldwide, we knew authoritarian governments would eventually try to block them.
</p>

<p>
	 
</p>

<p>
	But with Proton VPN, people can bypass those blocks and continue using Proton Mail. Over the past few years, Proton VPN has become an essential tool, helping ensure the free flow of information for tens of millions of people during crises and wars around the world.
</p>

<p>
	 
</p>

<p>
	Since we launched Proton VPN, we’ve continuously worked on technology to bypass surveillance and censorship. For example, in 2017, we launched Secure Core VPN, which provides greater privacy than typical VPN services.
</p>

<p>
	 
</p>

<p>
	In 2020, we launched alternative routing(new window), which bypasses VPN blocks by re-routing our connections over other hard-to-trace paths. Finally, in 2021, we released VPN Accelerator, a unique technology that provides connection speeds that are up to 400% faster, which is critically important for users in far-flung regions with slower internet.
</p>

<p>
	 
</p>

<p>
	As we have stepped up our efforts to build a more censorship-resistant VPN, authoritarian governments have also stepped up their efforts to block VPNs. Traditional VPN protocols (such as OpenVPN, IKEv2, and WireGuard) are relatively easy to recognize on a network. And as deep packet inspection (DPI) technology becomes more widespread, it will be easier and easier for authoritarian governments to detect and block VPNs using these protocols.
</p>

<p>
	 
</p>

<p>
	For years there have been various projects to try to obfuscate existing VPN protocols, but many of them are hacks on top of existing protocols that unfortunately no longer work very well.
</p>

<p>
	 
</p>

<p>
	We designed our Stealth protocol from the ground up to not have these issues. With Stealth enabled, your Proton VPN connection will be almost completely undetectable.
</p>

<p>
	 
</p>

<p>
	Stealth is available on all Proton VPN plans, including our Free plan, because everyone deserves online freedom. For now, you can use Stealth on our Android, Windows, macOS, and iOS apps.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://protonvpn.com/blog/stealth-vpn-protocol" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24738</guid><pubDate>Tue, 06 Aug 2024 18:20:37 +0000</pubDate></item><item><title>Proton VPN Rolls Out Three Important Anti-Censorship Updates</title><link>https://nsaneforums.com/news/security-privacy-news/proton-vpn-rolls-out-three-important-anti-censorship-updates-r24732/</link><description><![CDATA[<p>
	<span style="font-size:20px;">Proton continues to fight for basic free speech</span>
</p>

<p>
	 
</p>

<p style="margin-left:40px;">
	<strong><span style="font-size:20px;">Why this matters</span></strong>
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	These updates make it easier to bypass internet censorship, and it's as easy as just switching on the VPN.
</p>

<p>
	 
</p>

<p>
	Proton is a Swiss-based VPN provider known for its commitment to privacy. Just last month, the company made it safer to share sensitive information via their password manager. And now, they've introduced a few changes intended to combat censorship.
</p>

<p>
	 
</p>

<p>
	In a press release sent to Lifewire, the company detailed the changes which include new servers for countries most at risk of censorship, an anti-censorship protocol for the Windows app, and a new way for Android users to hide the VPN app on their devices.
</p>

<p>
	 
</p>

<p>
	Proton has added local VPN servers in 12 countries. Chosen based on threats like authoritarian rule and decreasing civil liberties, they include Afghanistan, Bahrain, Eritrea, Ethiopia, Iraq, Kuwait, Libya, Saudi Arabia, Sudan, Tajikistan, Turkmenistan, and Yemen. These new servers let people in those areas access the internet freely.
</p>

<p>
	 
</p>

<p>
	Additionally, Windows users can now use the company's exclusive Stealth protocol for increased protection. Proton calls it an "undetectable" protocol designed to make it harder for governments and ISPs to see that a VPN is being used, thus lowering the odds that the traffic will be blocked. The Stealth protocol is also available on other platforms.
</p>

<p>
	 
</p>

<p>
	Proton VPN is also available on Android. Today's update includes a small but helpful change where users can swap out the app icon for something less conspicuous. Helpful in regions where police might randomly inspect the phone, users can change out the standard Proton VPN logo for something more generic. Options include a weather app, a to-do list, and a few others.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.lifewire.com/proton-vpn-censorship-updates-8690780" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24732</guid><pubDate>Tue, 06 Aug 2024 14:55:01 +0000</pubDate></item><item><title>Why CERT-In is asking iPhone, iPad and Mac users in India to immediately update their devices</title><link>https://nsaneforums.com/news/security-privacy-news/why-cert-in-is-asking-iphone-ipad-and-mac-users-in-india-to-immediately-update-their-devices-r24729/</link><description><![CDATA[<p>
	<span style="font-size:18px;">If you are already on the latest version of the software for these devices, you are safe as Apple has patched vulnerabilities with the latest security update.</span>
</p>

<p>
	 
</p>

<p>
	The Indian Computer Emergency Response Team (CERT-In) has issued a “high” severity warning for Apple product users in India about software vulnerabilities on iPhones, iPads, and Macs. According to CERT-In, which is part of the Ministry of Electronics and Information Technology, these vulnerabilities could allow hackers to easily attack these devices and steal sensitive information.
</p>

<p>
	 
</p>

<p>
	CERT-In recommends users update their Apple products to the latest available version to secure their devices. The list of affected devices includes:
</p>

<p>
	 
</p>

<p>
	iOS and iPadOS versions prior to 17.6 and 16.7.9 (iPhones and iPads)<br />
	macOS Sonoma versions prior to 14.6 (Macs)<br />
	macOS Ventura versions prior to 13.6.8 (Macs)<br />
	macOS Monterey versions prior to 12.7.6 (Macs)<br />
	watchOS versions prior to 10.6 (Apple Watch)<br />
	tvOS versions prior to 17.6 (Apple TV)<br />
	visionOS versions prior to 1.3 (Vision Pro)<br />
	Safari versions prior to 17.6 (iPhone, iPad, Mac, Vision Pro)
</p>

<p>
	 
</p>

<div class="ipsEmbeddedOther" contenteditable="false">
	<iframe allowfullscreen="" data-controller="core.front.core.autosizeiframe" data-embedid="embed5161407219" src="https://nsaneforums.com/index.php?app=core&amp;module=system&amp;controller=embed&amp;url=https://twitter.com/IndianCERT/status/1820326964344782959?ref_src=twsrc%255Etfw%257Ctwcamp%255Etweetembed%257Ctwterm%255E1820326964344782959%257Ctwgr%255Eea95886e3dfa9e26a61939a1237412cd29c6427c%257Ctwcon%255Es1_%26ref_url=https://indianexpress.com/article/technology/tech-news-technology/why-cert-in-is-asking-iphone-ipad-and-mac-users-in-india-to-immediately-update-their-devices-9495703/" style="height:879px;"></iframe>
</div>

<p>
	Due to the high severity rating of these vulnerabilities, users may experience issues such as sensitive information disclosure, denial of service, security bypass, spoofing attacks, arbitrary code execution, and cross-site scripting-related problems.
</p>

<p>
	 
</p>

<p>
	If you are already using the latest software for these devices, this will not be an issue, as Apple has patched these vulnerabilities with the latest security update. However, if you have not yet installed the latest version, it is recommended that you do so to secure your Apple device.
</p>

<p>
	 
</p>

<p>
	Apple has also been sending alerts about “mercenary spyware attacks” to high-profile individuals, including politicians, journalists, and government officials, in over 150 countries, including India. If Apple believes a device is compromised, the user will be notified and can engage the device in lockdown mode to prevent data and device cyber attacks.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://indianexpress.com/article/technology/tech-news-technology/why-cert-in-is-asking-iphone-ipad-and-mac-users-in-india-to-immediately-update-their-devices-9495703/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24729</guid><pubDate>Tue, 06 Aug 2024 11:55:35 +0000</pubDate></item><item><title>Internal memo: Microsoft makes security a &#x2018;core priority&#x2019; for employee review process</title><link>https://nsaneforums.com/news/security-privacy-news/internal-memo-microsoft-makes-security-a-%E2%80%98core-priority%E2%80%99-for-employee-review-process-r24722/</link><description><![CDATA[<p>
	Microsoft will elevate security to the status of “core priority” for all employees as part of the process of focusing their work and reviewing performance, according to an internal email Monday morning.
</p>

<p>
	 
</p>

<p>
	This is the latest step by the company to implement what it calls a security-first mindset. It follows a series of high-profile breaches that have raised concerns among regulators and legislators, and resurfaced longstanding questions about the widespread reliance on Microsoft’s technology by major customers.
</p>

<p>
	 
</p>

<p>
	The change will be implemented for all employees when setting priorities and reviewing performance, known internally as “Connect,” according to the email Monday from Kathleen Hogan, Microsoft’s chief people officer.
</p>

<p>
	 
</p>

<p>
	“The Security Core Priority is not a check-the-box compliance exercise; it is a way for every employee and manager to commit to — and be accountable for — prioritizing security, and a way for us to codify your contributions and to recognize you for your impact,” Hogan wrote. “We all must act with a security-first mindset, speak up, and proactively look for opportunities to ensure security in everything we do.”
</p>

<p>
	 
</p>

<p>
	With the move, security joins two existing core priorities as part of the Connect process, focused on diversity and inclusion, and Microsoft’s expectations and principles for managers.
</p>

<p>
	 
</p>

<p>
	Priorities and performance reviews are factors in employee bonuses, but the company did not provide specifics on the degree to which the change could impact employee compensation.
</p>

<p>
	 
</p>

<p>
	The timing for the Connect process varies, generally occurring two to three times a year. Microsoft is calling on employees to implement the new core priority starting with their first “Connect” of the fiscal year, which started July 1.
</p>

<p>
	 
</p>

<p>
	Separately, Microsoft said last week that it will provide employees with a special one-time cash award amounting to an additional 10% to 25% of the value of their annual bonuses for the company’s recently completed fiscal year.
</p>

<p>
	 
</p>

<p>
	The security changes build on Microsoft’s Secure Future Initiative (SFI), introduced last fall. It’s Microsoft’s latest attempt to prioritize security, dating back the “Trustworthy Computing” initiative that Bill Gates instituted in 2002.
</p>

<p>
	 
</p>

<p>
	Microsoft said in May that it would base a portion of senior executive compensation on progress toward security priorities, place deputy chief information security officers (CISOs) in each product group, and bring together teams from its major platforms and product teams in “engineering waves” to overhaul security.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="nadella-security-768x549.jpg" class="ipsImage" data-ratio="75.10" height="514" width="720" src="https://cdn.geekwire.com/wp-content/uploads/2020/03/nadella-security-768x549.jpg" />
</p>

<p style="text-align:center;">
	<span style="font-size:12px;"><em>Microsoft CEO Satya Nadella. (GeekWire File Photo)</em></span>
</p>

<p style="text-align:center;">
	 
</p>

<p>
	In an internal memo at the time, Microsoft CEO Satya Nadella called on employees to make security their top priority, even if that means making difficult choices in the interest of greater security.
</p>

<p>
	 
</p>

<p>
	“If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” the Microsoft CEO told employees. “In some cases, this will mean prioritizing security above other things we do, such as releasing new features or providing ongoing support for legacy systems.”
</p>

<p>
	 
</p>

<p>
	A critical report by the Cyber Safety Review Board (CSRB) in April described Microsoft’s security culture as “inadequate.” The report called for security initiatives to be “overseen directly and closely” by Microsoft’s CEO and board, and said “all senior leaders should be held accountable for implementing all necessary changes with utmost urgency.”
</p>

<p>
	 
</p>

<p>
	The CSRB report focused on a high-profile incident in May and June 2023, in which a Chinese hacking group known as Storm-0558 is believed to have compromised the Microsoft Exchange Online mailboxes of more than 500 people and 22 organizations worldwide, including senior U.S. government officials.
</p>

<p>
	 
</p>

<p>
	Microsoft revealed in January that a Russian state-sponsored actor known as Nobelium or Midnight Blizzard accessed its internal systems and executive email accounts. Subsequently, the company said the same attackers were able to access some of its source code repositories and internal systems.
</p>

<p>
	 
</p>

<p>
	Testifying before the U.S. House Committee on Homeland Security in June, Microsoft President Brad Smith said the company took responsibility for the issues cited by the CSRB, and reiterated the commitment to prioritizing security.
</p>

<p>
	 
</p>

<p>
	Here’s the full text of Hogan’s memo to employees Monday morning.
</p>

<p>
	 
</p>

<p style="margin-left:40px;">
	Date: August 5, 2024
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	Subject: Introducing our Company-wide Security Core Priority
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	At Microsoft, we deliver mission-critical infrastructure that the world depends on to achieve more. With that trust in us comes a great responsibility: to protect our customers, our company, and our world from cyber threats. As Microsoft employees, we all have a role in that responsibility.
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	As Satya referenced in his May 3 email and again during his FY25 kick off on July 9, security is our number-one priority, and everyone at Microsoft will have security as a Core Priority. When faced with a tradeoff, the answer is clear and simple: security above all else.
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	Our commitment to security is enduring. New and novel attacks will require us to continue to learn, innovate, and defend. Yet working together, we will make nonlinear improvements, stay alert, and meet the expectations of our customers. They are counting on us, and our future depends on their trust.
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	Our new Security Core Priority reinforces our commitment to security and holds us accountable for building secure products and services. It is now available in the Connect tool for most employees, and we are partnering with geo HR teams to expand access to all employees globally. The Security Core Priority is not a check-the-box compliance exercise; it is a way for every employee and manager to commit to — and be accountable for — prioritizing security, and a way for us to codify your contributions and to recognize you for your impact. We all must act with a security-first mindset, speak up, and proactively look for opportunities to ensure security in everything we do.
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	The core priority will have two parts:
</p>

<p style="margin-left:40px;">
	 
</p>

<ul>
	<li>
		<p style="margin-left:40px;">
			Core and common elements that apply to all employees
		</p>
	</li>
</ul>

<p style="margin-left:40px;">
	 
</p>

<ul>
	<li>
		<p style="margin-left:40px;">
			An optional section for employees to further specify how they will activate the Security Core Priority based on their role, team, org, etc.
		</p>
	</li>
</ul>

<p style="margin-left:40px;">
	<br />
	All employees will set their Security Core Priority as part their first FY25 Connect, with the intent that during regular Connect conversations, you and your manager will discuss your Security Core Priority progress and impact. This process will follow the same approach as our other company-wide core priorities for Diversity &amp; Inclusion and Managers. …
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	As we kick off our 50th year as a company, I know we all feel honored and humbled that we are still here — as a relevant and consequential company — pursuing our mission together. When we empower every person and organization on the planet to achieve more, we take on society’s biggest challenges and empower the world. What a big, bold, and meaningful mission we have, and yet none of us can take this for granted. We are here because our customers trust us, and we must continue to earn their trust every day.
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	Thank you for your commitment to our Security Core Priority that will help protect Microsoft, our customers, and our partners.
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	Kathleen
</p>

<p style="margin-left:40px;">
	 
</p>

<p>
	The changes follow the end of Microsoft’s 2024 fiscal year on June 30. Microsoft reported fiscal fourth quarter earnings of $64.7 billion, up 15%, and profits of $22 billion, up 10%, surpassing Wall Street’s expectations, even as some analysts were disappointed by its cloud growth and the timeline for seeing a larger payoff from AI investments.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.geekwire.com/2024/internal-memo-microsoft-makes-security-a-core-priority-for-employee-reviews/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24722</guid><pubDate>Tue, 06 Aug 2024 01:59:59 +0000</pubDate></item><item><title>Safari&#x2019;s new &#x2018;Distraction Control&#x2019; feature lets you hide annoying cookie pop-ups</title><link>https://nsaneforums.com/news/security-privacy-news/safari%E2%80%99s-new-%E2%80%98distraction-control%E2%80%99-feature-lets-you-hide-annoying-cookie-pop-ups-r24716/</link><description><![CDATA[<h3>
	You’ll be able to tap parts of a website that you want to remove. The feature is available in the newest iOS 18, iPadOS 18, and macOS Sequoia developer betas.
</h3>

<div>
	<div>
		<div>
			<div>
				<p>
					Apple is adding a new feature to Safari called “Distraction Control” that lets you remove distracting things like cookie preference pop-ups while you’re browsing, <a href="https://www.macrumors.com/2024/08/05/ios-18-safari-distraction-control/" rel="external nofollow"><em>MacRumors</em> reports</a>. The new feature is available with the fifth iOS 18, iPadOS 18, and macOS Sequoia developer betas that launched on Monday.
				</p>

				<p>
					 
				</p>
			</div>

			<div>
				<p>
					You can get an idea of how Distraction Control works thanks to <a href="https://go.skimresources.com/?id=1025X1701640&amp;xs=1&amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DFzBa6Tc-JeE%26t%3D1s&amp;xcust=___vg__p_23977940__t_w__d_D" rel="external nofollow" target="_blank">a video from <em>MacRumors</em></a>. From a menu, you can choose an option to “Hide Distracting Items” and then select items you want to hide from the page you’re looking at. When items are hidden, they dissipate away with a very slick animation.
				</p>

				<p>
					 
				</p>

				<div class="ipsEmbeddedVideo" contenteditable="false">
					<div>
						<iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen="" frameborder="0" height="113" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube-nocookie.com/embed/FzBa6Tc-JeE?feature=oembed" title="iOS 18 Beta 5: New Distraction Control Feature is AMAZING!" width="200"></iframe>
					</div>
				</div>

				<p>
					 
				</p>
			</div>

			<div>
				<p>
					In a pop-up shown in the video, Apple notes that “hiding distracting items will not permanently remove ads and other content that updates frequently,” so you won’t be able to use this feature to hide every ad you see for good. Parts of a website that you hide also don’t sync across your devices, <em>MacRumors </em>says.
				</p>

				<p>
					 
				</p>
			</div>

			<div>
				<p>
					The new iOS 18 beta also brings changes to the redesigned Photos app, including <a href="https://www.macrumors.com/2024/08/05/ios-18-beta-5-photos-app/" rel="external nofollow">removing the new carousel view feature</a>.
				</p>

				<p>
					 
				</p>
			</div>
		</div>
	</div>
</div>

<p>
	<a href="https://www.theverge.com/2024/8/5/24213899/apple-safari-distraction-control-hide" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every single day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of July): 3,313 news posts</em></span>
</p>
]]></description><guid isPermaLink="false">24716</guid><pubDate>Tue, 06 Aug 2024 01:43:28 +0000</pubDate></item><item><title>Apple introduces built-in content blocker for Safari called 'Distraction Control'</title><link>https://nsaneforums.com/news/security-privacy-news/apple-introduces-built-in-content-blocker-for-safari-called-distraction-control-r24715/</link><description><![CDATA[<p>
	Apple today released the latest preview versions of its operating systems, and one of the most interesting changes arrived for Safari, Apple's default web browser. It now has a built-in content blocker called "Distraction Control."
</p>

<p>
	 
</p>

<p>
	Unlike traditional content blockers that remove ads, Apple's approach is more careful. As the name implies, the feature tries to eliminate various web annoyances, such as newsletter signups (that thing that dims the entire screen and begs for your email two and a half seconds after you load the website), cookie prompts, autoplaying videos, and other irritations.
</p>

<p>
	 
</p>

<p>
	Although you can use Distraction Control to block ads, they return once you refresh the page, clearly indicating that Apple is not trying to substitute third-party ad blockers. Safari will even warn you that Distraction Control cannot permanently remove ads.
</p>

<p>
	 
</p>

<p>
	In a nutshell, Apple is giving iOS, iPadOS, and macOS users a quick and easy tool to hide distracting elements when visiting websites. Another important aspect is that hiding certain parts of a website requires action from the end user, so the process is not automatic, and it won't sync across devices. You have to invoke the feature from the menu and manually select the element you want to remove.
</p>

<p>
	 
</p>

<p>
	If that sounds like too much work, Apple users can always get a third-party ad blocker that would automate the process.
</p>

<p>
	 
</p>

<p>
	Distraction Control is now available in the latest iOS 18, iPadOS 18, and macOS Sequoia developer betas. It is expected to arrive in the next public beta and land alongside the stable releases in the next month or two.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/apple-introduces-built-in-content-blocker-for-safari-called-distraction-control/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every single day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of July): 3,313 news posts</em></span>
</p>
]]></description><guid isPermaLink="false">24715</guid><pubDate>Tue, 06 Aug 2024 01:42:11 +0000</pubDate></item><item><title>Mac and Windows users infected by software updates delivered over hacked ISP</title><link>https://nsaneforums.com/news/security-privacy-news/mac-and-windows-users-infected-by-software-updates-delivered-over-hacked-isp-r24713/</link><description><![CDATA[<p>
	<span style="font-size:16px;">DNS poisoning attack worked even when targets used DNS from Google and Cloudflare.</span>
</p>

<p>
	 
</p>

<p>
	Hackers delivered malware to Windows and Mac users by compromising their Internet service provider and then tampering with software updates delivered over unsecure connections, researchers said.
</p>

<p>
	 
</p>

<p>
	The attack, researchers from security firm Volexity said, worked by hacking routers or similar types of device infrastructure of an unnamed ISP. The attackers then used their control of the devices to poison domain name system responses for legitimate hostnames providing updates for at least six different apps written for Windows or macOS. The apps affected were the 5KPlayer, Quick Heal, Rainmeter, Partition Wizard, and those from Corel and Sogou.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:20px;"><strong>These aren’t the update servers you’re looking for</strong></span>
</p>

<p>
	<br />
	Because the update mechanisms didn’t use TLS or cryptographic signatures to authenticate the connections or downloaded software, the threat actors were able to use their control of the ISP infrastructure to successfully perform machine-in-the-middle (MitM) attacks that directed targeted users to hostile servers rather than the ones operated by the affected software makers. These redirections worked even when users employed non-encrypted public DNS services such as Google’s 8.8.8.8 or Cloudflare’s 1.1.1.1 rather than the authoritative DNS server provided by the ISP.
</p>

<p>
	 
</p>

<p>
	“That is the fun/scary part—this was not the hack of the ISPs DNS servers,” Volexity CEO Steven Adair wrote in an online interview.
</p>

<p>
	 
</p>

<p>
	“This was a compromise of network infrastructure for Internet traffic. The DNS queries, for example, would go to Google’s DNS servers destined for 8.8.8.8. The traffic was being intercepted to respond to the DNS queries with the IP address of the attacker’s servers.”
</p>

<p>
	 
</p>

<p>
	In other words, the DNS responses returned by any DNS server would be changed once it reached the infrastructure of the hacked ISP. The only way an end user could have thwarted the attack was to use DNS over HTTPS or DNS over TLS to ensure lookup results haven’t been tampered with or to avoid all use of apps that deliver unsigned updates over unencrypted connections.
</p>

<p>
	 
</p>

<p>
	Volexity provided the following diagram illustrating the flow of the attack:
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="stormbamboo-dns-poisoning-flow-640x339.p" class="ipsImage" data-ratio="52.97" height="339" width="640" src="https://cdn.arstechnica.net/wp-content/uploads/2024/08/stormbamboo-dns-poisoning-flow-640x339.png" />
</p>

<p>
	 
</p>

<p>
	As an example, the 5KPlayer app uses an unsecure HTTP connection rather than an encrypted HTTPS one to check if an update is available and, if so, to download a configuration file named Youtube.config. StormBamboo, the name used in the industry to track the hacking group responsible, used DNS poisoning to deliver a malicious version of the Youtube.config file from a malicious server. This file, in turn, downloaded a next-stage payload that was disguised as a PNG image. In fact, it was an executable file that installed malware tracked under the names MACMA for macOS devices or POCOSTICK for Windows devices.
</p>

<p>
	 
</p>

<p>
	MACMA first came to light in 2021 post published by Google’s Threat Analysis Group, a team that tracks malware and cyberattacks backed by nation-states. The backdoor was written for macOS and iOS devices and provided a full suite of capabilities including device fingerprinting, screen capture, file downloading and uploading, execution of terminal commands, audio recording, and keylogging.
</p>

<p>
	 
</p>

<p>
	POCOSTICK, meanwhile, has been in use since at least 2014. Last year, security firm ESET said the malware, which it tracked under the name MGBot, was used exclusively by a Chinese-speaking threat group tracked as Evasive Panda.
</p>

<p>
	 
</p>

<p>
	ESET researchers determined that the malware was installed through legitimate updates of benign software, but they weren’t sure how that happened. One possibility, the researchers said at the time, was through a supply-chain attack that replaced the legitimate updates with malicious ones at the very source. The other possible scenario was through a MitM attack on the servers delivering the updates. Volexity’s findings now confirm that the latter explanation is the correct one.
</p>

<p>
	 
</p>

<p>
	In at least one case in the most recent attacks, StormBamboo forced a macOS device to install a browser plugin Volexity tracks under the name RELOADEXT. The extension masquerades as one that loads webpages to be compatible with Internet Explorer. In fact, Volexity said, it copies browser cookies and sends them to a Google Drive account controlled by the attackers. The data was base64 encoded and encrypted using the Advanced Encryption Standard. Despite the care taken by the hackers, they nonetheless exposed the client_id, client_secret, and refresh_token in the malicious extension.
</p>

<p>
	 
</p>

<p>
	One other technique Volexity observed was StormBamboo’s use of DNS poisoning to hijack www.msftconnecttest.com , a domain Microsoft uses to determine if Windows devices are actively connected to the Internet. By replacing the legitimate DNS resolution with an IP address pointing to a malicious site operated by the threat actors, they could intercept HTTP requests destined for any host.
</p>

<p>
	Adair declined to identify the hacked ISP other than to say it’s “not a big huge one or one you’d likely know.”
</p>

<p>
	 
</p>

<p>
	“In our case the incident is contained but we see other servers that are actively serving malicious updates but we do not know where they are being served from,” he said. “We suspect there are other active attacks around the world we do not have purview into. This could be from an ISP compromise or a localized compromise to an organization such as on their firewall.”
</p>

<p>
	 
</p>

<p>
	As noted earlier, there are many options for preventing these sorts of attacks beyond (1) eschewing all software that updates unsecurely or (2) using DNS over HTTPS or DNS over TPS. The first method is likely the best, although it likely means having to stop using a preferred app in at least some cases. The alternative DNS configurations are viable, but at the moment are offered by only a handful of DNS providers, with 8.8.8.8 and 1.1.1.1 being the best known.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://arstechnica.com/security/2024/08/hacked-isp-infects-users-receiving-unsecure-software-updates/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24713</guid><pubDate>Tue, 06 Aug 2024 01:36:24 +0000</pubDate></item><item><title>Chrome&#x2019;s Manifest V3, and its changes for ad blocking, are coming real soon</title><link>https://nsaneforums.com/news/security-privacy-news/chrome%E2%80%99s-manifest-v3-and-its-changes-for-ad-blocking-are-coming-real-soon-r24702/</link><description><![CDATA[<h3>
	Chrome is warning users that their extension makers need to update soon.
</h3>

<div class="article-content post-page" itemprop="articleBody">
	
	<p>
		Google Chrome's long, long project to implement a new browser extension platform is seemingly going to happen, for real, after six years of cautious movement.
	</p>

	<p>
		 
	</p>

	<p>
		One of the first ways people are seeing this is if they use uBlock Origin, a popular ad-blocking extension, <a href="https://www.bleepingcomputer.com/news/google/google-chrome-warns-ublock-origin-may-soon-be-disabled/" rel="external nofollow">as noted by Bleeping Computer</a>. Recently, Chrome users have seen warnings pop up that "This extension may soon no longer be supported," with links asking the user to "Remove or replace it with similar extensions" from Chrome's Web Store. You might see a similar warning on some extensions if you head to Chrome's Extensions page (chrome://extensions).
	</p>

	<p>
		 
	</p>
	What's happening is Chrome preparing to make Manifest V3 required for extensions that want to run on its platform. <a href="https://blog.chromium.org/2018/10/trustworthy-chrome-extensions-by-default.html" rel="external nofollow">First announced in 2018</a>, the <a href="https://arstechnica.com/gadgets/2024/05/google-starts-deprecating-older-more-capable-chrome-extensions-next-week/" rel="external nofollow">last word</a> on Manifest V3 was that V2 extensions would start being nudged out in early June on the Beta, Dev, and Canary update channels. Users will be able to manually re-enable V2 extensions "for a short time," <a href="https://developer.chrome.com/docs/extensions/develop/migrate/mv2-deprecation-timeline" rel="external nofollow">Google has said</a>, "but over time, this toggle will go away as well." The shift for enterprise Chrome deployments is expected to be put off until June 2025.

	<p>
		 
	</p>

	<p>
		Google has said that its new extension platform was built for "improving the security, privacy, performance, and trustworthiness of the extension ecosystem." The Electronic Frontier Foundation (EFF) <a href="https://www.eff.org/deeplinks/2019/07/googles-plans-chrome-extensions-wont-really-help-security" rel="external nofollow">disagrees most strongly with the security aspect</a>, and Firefox-maker Mozilla, while intending to support V3 extensions for cross-browser compatibility, has <a href="https://blog.mozilla.org/addons/2024/03/13/manifest-v3-manifest-v2-march-2024-update/" rel="external nofollow">no plans to cut off support for V2 extensions</a>, signaling that it doesn't see the big improvement.
	</p>

	<p>
		 
	</p>

	<p>
		Perhaps the biggest point of friction is with ad blockers. Google has said it "isn't killing ad blockers" but "making them safer," in <a href="https://security.googleblog.com/2019/06/improving-security-and-privacy-for.html#:~:text=To%20help%20with,over%20Web%20Request." rel="external nofollow">an explanatory blog post</a>. Google noted in November 2023 that Manifest V3 allowed for a greater number, and more dynamic updating, of content-blocking rules in extensions, <a href="https://developer.chrome.com/blog/improvements-to-content-filtering-in-manifest-v3/" rel="external nofollow">specifically ad blockers</a>.
	</p>

	<p>
		 
	</p>

	<p>
		But one of the biggest changes is in disallowing "remotely hosted code," which includes the filtering lists that ad blockers keep regularly updated. Ad blockers that want to update their filtering lists, perhaps in response to pivots by platforms like Google's YouTube and ad servers, will have to do so through the Chrome Web Store's review process. Ad-blocking coders see it as <a href="https://arstechnica.com/google/2023/12/chromes-next-weapon-in-the-war-on-ad-blockers-slower-extension-updates/" rel="external nofollow">an intentional gatekeeping and slowing</a>.
	</p>

	<p>
		 
	</p>

	<p>
		Google said before the initial May push toward V3 that 85 percent of actively maintained extensions in its store had Manifest V3 versions ready. Raymond Hill wrote <a href="https://github.com/uBlockOrigin/uBlock-issues/wiki/About-Google-Chrome's-%22This-extension-may-soon-no-longer-be-supported%22" rel="external nofollow">on uBlock Origin's GitHub page Friday</a> that there will not be a full version of uBlock Origin that works with Manifest V3, but instead <a href="https://chromewebstore.google.com/detail/ublock-origin-lite/ddkjiahejlhfcafbddmgiahcphecmpfh" rel="external nofollow">a "Lite" version</a> that is "a pared-down version of uBO with a best effort at converting filter lists used by uBO into a Manifest V3-compliant approach."
	</p>
</div>

<p>
	 
</p>

<p>
	<a href="https://arstechnica.com/gadgets/2024/08/chromes-manifest-v3-and-its-changes-for-ad-blocking-are-coming-real-soon/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every single day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of July): 3,313 news posts</em></span>
</p>
]]></description><guid isPermaLink="false">24702</guid><pubDate>Mon, 05 Aug 2024 18:39:34 +0000</pubDate></item><item><title>Home users increasingly targeted by global Magniber ransomware campaign</title><link>https://nsaneforums.com/news/security-privacy-news/home-users-increasingly-targeted-by-global-magniber-ransomware-campaign-r24695/</link><description><![CDATA[<p>
	Mounting attacks have been deployed by the Magniber ransomware operation against home users' devices around the world since late July, BleepingComputer reports.
</p>

<p>
	 
</p>

<p>
	Intrusions, which were noted by BleepingComputer and ID-Ransomware to have increased in prevalence since July 20, were reported by some victims to have resulted in device encryption following the execution of cracked software and key generators. Aside from appending random extensions to encrypted files, Magniber also created a ransom note including a link to the ransomware gang's Tor site. While Magniber initially demands a $1,000 ransom from its victims, it later seeks $5,000 should they fail to provide payment within three days. Such findings come seven years after Magniber emerged as Cerber ransomware's successor and while a decryptor for the ransomware was unveiled just a year after its launch, such a tool is no longer functional after attackers addressed the payload's free file decryption bug. Organizations have been urged to avoid key generators and cracked software to avoid potential compromise.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.scmagazine.com/brief/home-users-increasingly-targeted-by-global-magniber-ransomware-campaign" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24695</guid><pubDate>Mon, 05 Aug 2024 15:26:17 +0000</pubDate></item><item><title>Ongoing Iranian internet outage claimed by Israeli hacktivists</title><link>https://nsaneforums.com/news/security-privacy-news/ongoing-iranian-internet-outage-claimed-by-israeli-hacktivists-r24694/</link><description><![CDATA[<p>
	Iran had its internet services claimed to be disrupted by Israeli hacktivist operation WeRedEvils, reports The Register.
</p>

<p>
	 
</p>

<p>
	Aside from conducting the ongoing internet outage, which was proven by showing the takedown of most Iranian ministry websites, WeRedEvils also purported exfiltrating data from the impacted computer systems, which has already been given to the Israeli government.
</p>

<p>
	 
</p>

<p>
	"Stop raising red flags and start raising a white flag. The folly will take you all to the dustbin of history. Iran will burn – Israel will win," said WeRedEvils in a translated Telegram message, which also noted their desire to personally communicate with supporters of Iran's Revolutionary Guards. WeRedEvils' alleged compromise of Iran's internet comes nearly a year after claiming to disrupt Iran's electric grid in what is believed to be the hacktivist group's initial attack. Numerous WeRedEvils members were also noted to have been apprehended by the Israeli government for espionage in June.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.scmagazine.com/brief/ongoing-iranian-internet-outage-claimed-by-israeli-hacktivists" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24694</guid><pubDate>Mon, 05 Aug 2024 15:24:59 +0000</pubDate></item><item><title>Chinese Hackers Deliver Malware via ISP-Level DNS Poisoning</title><link>https://nsaneforums.com/news/security-privacy-news/chinese-hackers-deliver-malware-via-isp-level-dns-poisoning-r24692/</link><description><![CDATA[<p>
	<span style="font-size:16px;">Chinese group StormBamboo spotted delivering Windows and macOS malware by compromising an ISP and using DNS poisoning.</span>
</p>

<p>
	 
</p>

<p>
	Threat intelligence and incident response firm Volexity has shared details on attacks in which a threat actor linked to China used ISP-level DNS poisoning in order to deliver malware to targets.
</p>

<p>
	 
</p>

<p>
	The operation was conducted by an APT tracked as StormBamboo, Evasive Panda, and StormCloud.
</p>

<p>
	 
</p>

<p>
	Volexity has not shared any information on the targeted entities, but the threat actor is known for cyberespionage operations aimed at organizations in Asia.
</p>

<p>
	 
</p>

<p>
	According to the cybersecurity firm, which started investigating the attacks in mid-2023, the attackers compromised an internet provider’s systems and performed DNS poisoning in order to deliver Windows and macOS malware through insecure automatic software update mechanisms.
</p>

<p>
	 
</p>

<p>
	“Volexity determined that StormBamboo was altering DNS query responses for specific domains tied to automatic software update mechanisms. StormBamboo appeared to target software that used insecure update mechanisms, such as HTTP, and did not properly validate digital signatures of installers. Therefore, when these applications went to retrieve their updates, instead of installing the intended update, they would install malware,” the security firm explained.
</p>

<p>
	 
</p>

<p>
	Volexity worked with the targeted ISP to respond to the incident.
</p>

<p>
	 
</p>

<p>
	“As the ISP rebooted and took various components of the network offline, the DNS poisoning immediately stopped. During this time, it was not possible to pinpoint a specific device that was compromised, but various components of the infrastructure were updated or left offline and the activity ceased,” Volexity said.
</p>

<p>
	 
</p>

<p>
	The company saw StormBamboo delivering malware such as MacMa (CDDS), a macOS threat first spotted by Google in 2021. At the time it had been delivered to users in Hong Kong via watering hole attacks and a macOS zero-day vulnerability.
</p>

<p>
	 
</p>

<p>
	In another case, Volexity saw StormBamboo deploying a malicious Chrome extension named Reloadext, which enables the exfiltration of email data.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.securityweek.com/chinese-hackers-deliver-malware-via-isp-level-dns-poisoning/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24692</guid><pubDate>Mon, 05 Aug 2024 15:20:58 +0000</pubDate></item><item><title>Researchers Uncover Flaws in Windows Smart App Control and SmartScreen</title><link>https://nsaneforums.com/news/security-privacy-news/researchers-uncover-flaws-in-windows-smart-app-control-and-smartscreen-r24685/</link><description><![CDATA[<p>
	Cybersecurity researchers have uncovered design weaknesses in Microsoft's Windows Smart App Control and SmartScreen that could enable threat actors to gain initial access to target environments without raising any warnings.
</p>

<p>
	 
</p>

<p>
	Smart App Control (SAC) is a cloud-powered security feature introduced by Microsoft in Windows 11 to block malicious, untrusted, and potentially unwanted apps from being run on the system. In cases where the service is unable to make a prediction about the app, it checks if it's signed or has a valid signature so as to be executed.
</p>

<p>
	 
</p>

<p>
	SmartScreen, which was released alongside Windows 10, is a similar security feature that determines whether a site or a downloaded app is potentially malicious. It also leverages a reputation-based approach for URL and app protection.
</p>

<p>
	 
</p>

<p>
	"Microsoft Defender SmartScreen evaluates a website's URLs to determine if they're known to distribute or host unsafe content," Redmond notes in its documentation.
</p>

<p>
	 
</p>

<p>
	"It also provides reputation checks for apps, checking downloaded programs and the digital signature used to sign a file. If a URL, a file, an app, or a certificate has an established reputation, users don't see any warnings. If there's no reputation, the item is marked as a higher risk and presents a warning to the user."
</p>

<p>
	 
</p>

<p>
	It's also worth mentioning that when SAC is enabled, it replaces and disables Defender SmartScreen.
</p>

<p>
	 
</p>

<p>
	"Smart App Control and SmartScreen have a number of fundamental design weaknesses that can allow for initial access with no security warnings and minimal user interaction," Elastic Security Labs said in a report shared with The Hacker News.
</p>

<p>
	 
</p>

<p>
	One of the easiest ways to bypass these protections is get the app signed with a legitimate Extended Validation (EV) certificate, a technique already exploited by malicious actors to distribute malware, as recently evidenced in the case of HotPage.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="demo.gif" class="ipsImage" data-ratio="56.67" height="403" width="720" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0GiVpNbi0_Fzv8fv5ugFm824cfmHBnnDVFgkm8g4WDJepJS5vVLhVocZ4ce6oeZImMqiWgXF5w5LV-O60TtaJGQj4PUJJmWNYc6b1Ojatyp500tLKL-ktKiK-P7WAieYcAYs0mdnQ_i3PXsSpuwXAo-V90ID20FsMBEpUgRSZhYPOmonAtWPXW0fdzKTt/s728-rw-e365/demo.gif" />
</p>

<p style="text-align:center;">
	 
</p>

<p>
	Some of the other methods that can be used for detection evasion are listed below -
</p>

<p>
	 
</p>

<ul>
	<li>
		Reputation Hijacking, which involves identifying and repurposing apps with a good reputation to bypass the system (e.g., JamPlus or a known AutoHotkey interpreter)
	</li>
</ul>

<p>
	 
</p>

<ul>
	<li>
		Reputation Seeding, which involves using an seemingly-innocuous attacker-controlled binary to trigger the malicious behavior due to a vulnerability in an application, or after a certain time has elapsed.
	</li>
</ul>

<p>
	 
</p>

<ul>
	<li>
		Reputation Tampering, which involves altering certain sections of a legitimate binary (e.g., calculator) to inject shellcode without losing its overall reputation
	</li>
</ul>

<p>
	 
</p>

<ul>
	<li>
		LNK Stomping, which involves exploiting a bug in the way Windows shortcut (LNK) files are handled to remove the mark-of-the-web (MotW) tag and get around SAC protections owing to the fact that SAC blocks files with the label.
	</li>
</ul>

<p>
	<br />
	"It involves crafting LNK files that have non-standard target paths or internal structures," the researchers said. "When clicked, these LNK files are modified by explorer.exe with the canonical formatting. This modification leads to removal of the MotW label before security checks are performed."
</p>

<p>
	 
</p>

<p>
	"Reputation-based protection systems are a powerful layer for blocking commodity malware," the company said.
</p>

<p>
	 
</p>

<p>
	"However, like any protection technique, they have weaknesses that can be bypassed with some care. Security teams should scrutinize downloads carefully in their detection stack and not rely solely on OS-native security features for protection in this area."
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://thehackernews.com/2024/08/researchers-uncover-flaws-in-windows.html" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24685</guid><pubDate>Mon, 05 Aug 2024 14:26:04 +0000</pubDate></item><item><title>Computer security is a political struggle</title><link>https://nsaneforums.com/news/security-privacy-news/computer-security-is-a-political-struggle-r24684/</link><description><![CDATA[<p>
	<span style="font-size:22px;"><strong>Cold cyberwar</strong></span>
</p>

<p>
	 
</p>

<p>
	We are in a new cold war. That sounds like it's not news. However, it is not the bordered cyber-war between nation states involving armies of hackers, but more akin to a quiet civil conflict between ordinary people - who use and depend on technology - and the… well to quote Bill Hicks "demons that run amok amongst us".
</p>

<p>
	 
</p>

<p>
	It's a political and psychological battle for culture and is the old battle for the dividends of technology. Who gets to use the fruits of science and to what end? As technologists it behoves us to take stock of this landscape, if not to pick a side then to plan our own way between the falling shells.
</p>

<p>
	 
</p>

<p>
	Recent events demonstrate clearly that our technology is unsafe. We're in an accelerating situation of acute failures that shut down businesses, sometimes for days or weeks. Large one-off losses from fraud, such as ransomware or AI assisted social engineering, keep growing. At a deeper level there are systemic failures because the goods and services we rely on are not fit for purpose, and those responsible for supplying and maintaining services are unable to discharge their duty.
</p>

<p>
	 
</p>

<p>
	And at the highest level there is a political failure to confront the real causes. The UK Horizon Post-Office scandal laid bare the complicity of authority in burying inconvenient truths, making scape-goats and disseminating official lies to cover up problems with civic technology.
</p>

<p>
	 
</p>

<p>
	We find that our major concerns in cybersecurity are not really technical at all. They are political. But they are largely beyond tha capacity of our current political thinkers to solve. Instead, politicians bat the problem back into the technical court. We add or remove a layer of encryption, change a key protocol, deploy "intrusion detection" or "malware filtering"… and within a week the same problem is back, metamorphosed into something new. This will continue ad nauseum until there is political change.
</p>

<p>
	 
</p>

<p>
	The digital version is more subtle and damaging than kinetic wars in a civil space. We can't look to history for guidance. Conjure up mental images of ruined cities, food shortages, civil unrest, exploding power plants, disabled hospitals and broken transport systems. Worst case cyber-war is what Hollywood disaster movies have equipped us to anticipate. In the drama of a post-apocalyptic Mad Max fantasy world we can see ourselves playing unlikely solar-punk survivors living off-grid.
</p>

<p>
	 
</p>

<p>
	But that's just a story, at least so far. How do we recognise the effects of the different kind of war? What does a "worst case" look like if limited to infowars in cyberspace?
</p>

<p>
	 
</p>

<p>
	In Hollywood movies, the {terrorists, evil maniacs, rogue states} take over cyberspace and then use it to {hijack planes, melt down reactors, assassinate presidents}, or whatever. They are doing one thing, which is taking power.
</p>

<p>
	 
</p>

<p>
	Power, or "control" is one of the primary functions of digital systems - the others are computation, storage and communication. Control systems, which permit action at a distance, almost always involve communication along with telemetry as feedback. They close a loop. If you can mess with that loop you can exercise control.
</p>

<p>
	 
</p>

<p>
	That's why the integrity of communications systems is important. If the bad guys get control of the communications they win, and Hollywood events ensue. In reality, power seekers can act to manipulate events. That's the hard way. In cyberspace, you don't have to leave your seat to just manipulate the capture, transformation and transmission of signals that represent events. The media have done this for decades. Going further, if you can manipulate the perception and discussion of ideas that's even more powerful, especially if you already more or less own the means of communication.
</p>

<p>
	 
</p>

<p>
	That's why the Great Maker created the Internet first, as a little patch of level playing-field (or garden if you like) to see what we'd make of it. Not much, it turned out. We preferred to let developers pave it over and build us a residential amusement park. And of course, amusement parks always turn spooky and fill up with murderous robots and killer clowns.
</p>

<p>
	An Internet is a jolly useful and powerful thing, if you can keep it, and the trick is to ensure that power remains spread out and not let one group of people suddenly have it all, like terrorists in the films.
</p>

<p>
	 
</p>

<p>
	But as Bruce Schniere puts it best, Terrorists Don't Do Movie Plots. In number theory there's an idea for that, it's called Cantor's Diagonal or otherwise Russell's paradox if you prefer to think of sets, but either way the insight is that "there's always one more…", one more bug, one more escape sequence, and so on, which entreats us to abandon the folly of totalitarianism and chasing "perfect systems". Concern with risk then is really about emerging threats rather than known ones against which we can pit our security.
</p>

<p>
	 
</p>

<p>
	For any system there are a couple of places from which threats can come. From the outside or from the inside. Inside threats may come from defective people, but more likely from failures of the system itself. Poor maintenance is a rather mundane and preventable cause. Through the distracted happy apathy of our amusement park days we forgot to oil the works and kick the tyres.
</p>

<p>
	 
</p>

<p>
	Our Internet has slowly rusted. The repair bill is high and the effects already showing are not good. We've undergone a slow descent into digital serfdom, meaningless pseudo-employment, apathy, anomie, a permanent state of endemic economic, spiritual depression and frustration. Like all realities it emerges day by day without fanfare.
</p>

<p>
	 
</p>

<p>
	We don't feel it creeping up on us. We don't notice the walls of social media echo-chambers closing in on us… our horizons narrowing, hope evaporating. We don't feel the steady increase of pressure and anxiety from constant hostile surveillance, being tricked, gaslighted, lied to and manipulated. Yet the present, evident cultural effects are on everybody's lips. Every day we read and talk about the negative effects of news and communication technology.
</p>

<p>
	 
</p>

<p>
	The technology itself seems so "successful". Is it? We've always celebrated technology that's good for us, whether it's steam engines or rockets, and even the stuff that we didn't know was so bad for us, like our cars.
</p>

<p>
	 
</p>

<p>
	But the idea of tech which is just bad for everyone and we all know it is something new. It hadn't taken hold until this century. At least here in the West beyond a context of warfare far away, our weapons were always aimed "at them". But remember that the Internet started in an "Advanced Research Projects" defence laboratory. It's a weapon. We were so excited to unbox it nobody read the manual and the warning about the "sharp end" and which way to point it.
</p>

<p>
	 
</p>

<p>
	Like bad food or environmental pollutants, the effects of bad technologies take time to come on, and then get us talking about "what to do?" Surely we are prepared, because there are so many amazing books and films about dystopias and failed social experiments, served as cautionary signposts for what not to do (again, elsewhere or just…ever!). Orwell, Solzhenitsyn, Kafka Huxley and Gibson all described states we do not want to build.
</p>

<p>
	 
</p>

<p>
	But for some people these warnings became blueprints. They set us off on a slow death-march; a slow maddening of humanity. These are our times. Soviet style conditions of hostile, intrusive and abusive corporate plutocracy… the various ideologies of consumer communism, surveillance capitalism, advertising madmen, blood-thirsty tech visionaries with shark-lasers… meanwhile most of our stuff, like the trains and planes and banks just don't work the way we want.
</p>

<p>
	 
</p>

<p>
	It is this sad carnival of clowns that we are at war against. It is a war on cheap, greedy incompetence, on reckless engineering, on sleazy opportunists, on crony contractors and corrupt IT back-room deals. It is a war against those who have their hands on the levers of technology, but are a dangerous lot who do not deserve to. It is a war for functional civic technology that the people own and control.
</p>

<p>
	 
</p>

<p>
	As defenders we are called to arms because real cybersecurity has to consider not just where technology fails, but where it succeeds - for some strange paperclip-maximised value of "success".
</p>

<p>
	 
</p>

<p>
	Technology is not neutral. It carries values. Often, bad technology is just ordinary, but designed and deployed by those with wicked agendas. Where technology grows too thickly or in the wrong place it is a weed and a poison. Like any garden or ecosystem the Internet can decline, as it has, into a form of wholly inadequate but irreversible social control. For example, "social media" is the obliteration of the social.
</p>

<p>
	 
</p>

<p>
	But what do you call a struggle like this? Fifty years ago radical Marxists might have called it a "class war", if you substitute ownership of means of production for control of the means to social life. Yet it seems an entirely different sort of conflict that transcends class, wealth, pedigree and political belief.
</p>

<p>
	 
</p>

<p>
	In all conflicts people use mental defences to say "it can't happen here", until it does. Digital war is a great leveller.
</p>

<p>
	 
</p>

<p>
	Whatever walk of life you come from it affects you. You are no less at risk from an enemy of sorts that does not recognise power or privilege, laws, station or legitimacy.
</p>

<p>
	 
</p>

<p>
	If we split the world of digital threats up into a few broad kinds we might call them advanced persistent threats (APT), which are specific and even localised, transient situational threats like Y2K or solar storms which came and went, and ambient or nebulous effects, which are already inside our system or all around us. Here let's consider the last of these. What are we to do about ambient threats that are within the very systems we use to naviagate life?
</p>

<p>
	 
</p>

<p>
	<strong><span style="font-size:22px;">Self devouring</span></strong>
</p>

<p>
	<br />
	Most of Western society now depends on digital technology. Yet we have a technology industry that is at war with its own customers. Much of our technology is broken, and it is broken by design. because this is profitable and brings power to its creators. Technologically, our civilisation is suffering from a lack of self-care. We are struggling with a broken model of "security" and the emergence of a global insecurity industry. This self-devouring and abandonment of our own values is what Solzhenitsyn warned us against in his Warning to the West.
</p>

<p>
	 
</p>

<p>
	We are now taking an unprecedented direction in political history having slept-walked into a territory where the monopoly companies we allowed quasi-governmental status through delegation (dereliction) of power in the late 20th century cannot be coerced, regulated, fined or even taken over and "nationalised" as a remedy. So far politicians have underestimated and misunderstood the power struggle with technology that is afoot.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>Money, money, money</strong></span>
</p>

<p>
	<br />
	Let's take a simple, modest example from your everyday life; If you have an Android type phone spend a moment researching how to stop Google from spying on your location. Simple enough, no?
</p>

<p>
	 
</p>

<p>
	Google are a 'legitimate company', are they not? But despite all the protections your laws afford you, despite still more tough-talk from Europe about our privacy rights, the realpolitik is quite different. In fact it's more or less impossible to get Google to stop spying on you.
</p>

<p>
	 
</p>

<p>
	First let's acknowledge the motives: US American BigTech companies primarily make money by selling your private data to co-parasitical advertising and security industries. Commercially they discriminate to distribute digital goods preferentially by location, social strata or even as personally targeted campaigns.
</p>

<p>
	 
</p>

<p>
	Increasingly for political reasons, service access is only available in certain countries or by certain groups. The Internet has become the The Splinternet, a tool for division. Conflict makes clicks.
</p>

<p>
	 
</p>

<p>
	Of course this disadvantages anyone who moves between spheres, is travelling or relocated for work, or has family in other countries. It "locks things down", and simply goes against the basic principles of "The Internet" as a global, universal system (which it hasn't been for almost 10 years now). But, "so what?" you may say. These are "first world problems", surely? Minor inconvenience at most?
</p>

<p>
	 
</p>

<p>
	Look again. Tech corporations have insinuated themselves into almost all aspects of life. For too many people companies like Microsoft act as their identity. Companies like Amazon control everything they buy, sell, read, own or even think about. Google know every thought they've had since 1998.
</p>

<p>
	 
</p>

<p>
	Governments and bodies for trade, development and intellectual property (WIPO, WEF, WTO), have been derelict and allowed BigTech to carve up the global economy into new digital fiefdoms. Through negligence, through weakness, through our own deliberate fault, we've enabled the rise of digital colonialism, new forms of slavery and neo-feudalism. We've failed "consumers" as people, and all of us as citizens.
</p>

<p>
	 
</p>

<p>
	Of course it is still possible to live, and live well, without invasive low-life-quality technology. Millions of us do. Smart kids don't have smart phones. For the adults, Microsoft's operating system is now an advert-infested disaster-area teetering on unusable, with droves abandoning it. As is Google's derelict search engine. Social media is a misery pit of teen anxiety, disinformation and hate-spreading.
</p>

<p>
	 
</p>

<p>
	But the aim was never to live without technology, just to have good, simple, humane, flexible, durable tools that make life a little easier and bring some fun. We long ago surpassed that need. People are turning away from tech, or at least pinning their anger and fear upon it, because of the effects of how it's used now, not what it essentially is.
</p>

<p>
	 
</p>

<p>
	With pomp, bluster and glory the big technology companies bask in the glow of "freedom". They supply us all with the mind-numbing cargo-cult of games, media and applications we can give our attention to.
</p>

<p>
	 
</p>

<p>
	They present themselves as "progressive" and there is always the breathless cry… "Follow us follow us! Don't be left behind" But surely we must start to see them for what they really are. The Pied Piper is fundamentally anti-progressive because he leads in a circle. Other writers have described it as the problem of the modern East India Tea Company, as throwbacks to the unfettered laissez-faire capitalism of the era before the Great War, and consequent global crash of the 30s and World War 2. We've already learned these lessons from history, so why are we going for a replay?
</p>

<p>
	 
</p>

<p>
	As a British person I can really relate to companies like Google, Microsoft and Meta… dinosaurs, still trading on the myths of their once glorious past empires, standing uncomfortably too long on the stage, missing all the cues for a graceful exit and having to be hauled off with a shepherds crook. They have been holding back technology for decades.
</p>

<p>
	 
</p>

<p>
	They are first and foremost companies who cannot allow actual progress to come before profit. Sure they came out of the garages of suburbia, as the cool new rockers. But if Bigtech were bands they'd be the kind on 12 inch vinyl in your mum's record box, who now wear gold watches, own organic fish-farms and were at least accused of touching their groupies inappropriately in the 1970s.
</p>

<p>
	 
</p>

<p>
	Dig into the reality behind Google and you'll discover a company that, apart from having a defunct "search engine" on which it built its initial reputation, also abandoned almost every other product it ever touched. It adds up to a gargantuan bonfire of wealth and lost opportunity imposed on the rest of Western society. Likewise, Microsoft's death-grip of insecurity on computing by acquisitions, smothering or outspending competition, has done for the progress of computer security what Julius Caesar did at Library of Alexandria in 48 BC.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>Is anyone still fooled?</strong></span>
</p>

<p>
	 
</p>

<p>
	Apparently, at long last, the U.S. government is losing trust in Microsoft. In recent years it has stood up against powerful foreign technology actors like Huawei and TikTok. Even in Britain we had to acknowledge the security catastophe of Hikvision cameras and our government finally banned them. But these are the tip of the iceberg of toxic tech. It is easy to pick on Chinese or Russian companies precisely because we don't trust their regimes. But most dangerous of all are the companies we suppose we can trust, like Meta, Google, Amazon, and Apple.
</p>

<p>
	 
</p>

<p>
	Trust is the ability to do harm.
</p>

<p>
	 
</p>

<p>
	The political fault-lines lie in this misplaced trust, "special relations" and trade agreements that place U.S. technology suppliers beyond question.
</p>

<p>
	 
</p>

<p>
	Yet we continue to lionise these lumbering monsters. Their bright coloured logos, sit behind the strutting stars of TED talks in their brown leather brogues, turtle-necks and jeans. Their hipster language still dazzles us. In our minds they are youthful, vibrant and privy to secrets about the future.
</p>

<p>
	 
</p>

<p>
	Reality check; They are already the next iteration of tired old power, replete with red mid-life-crisis-mobiles on the drive. Our "tech leaders" are now the generation of fossilised cranky and emotionally challenged old men. Same as the ones that ran Exxon Mobil while the planet was heating up in the 1950s.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>The limits of industry</strong></span>
</p>

<p>
	<br />
	In academic writing and political talk we often see "Industry" used as a notional symbol, It stands, not in a harmony but alongside "Government" and "Academia", as a timeless imaginary power grouping. It requests a deflationary logic that "industry" is synonymous with "the economy" which is in turn synonymous with "happiness and quality of life".
</p>

<p>
	 
</p>

<p>
	It is a peculiarly post-Thatcher/Reagan take, a neo-liberalist ideal of "private industry" taking the place of government. But if Thatcher was ever to be taken seriously on a single word she said, what we have today is an abomination of her values. "Private enterprise" was another way of talking about the ordinary people, but through an economic lens. If you cut someones hair or carried your own groceries to the car today you're involved in "industry". We have a music industry a culture industry, an education industry… what has not been industrialised? So what does that leave that isn't an "industry"?
</p>

<p>
	Of course what politicians really mean by "industry" today is the one percent of rich and powerful owners.
</p>

<p>
	 
</p>

<p>
	Perhaps we misunderstand industry as "engines of progress" because of the persistent mythology of our own bygone industrial revolution; greats like Brunel, Stephenson and Telford. We still see ourselves on the frontier, paving roads to infinity. But industry has other forms, especially in mature civilisations. It is sustaining, home-building, frugal, refining.
</p>

<p>
	 
</p>

<p>
	The old mythology is still recycled in the stories and pseudo-philosophies of Ayn Rand, and now Elon Musk, Peter Thiel and company. Modern heroes? Noble strugglers against "Old power"? Or perhaps, misogynistic, grandiose, psychopathic Silicon Valley "bros" who are not ashamed to hide their naked contempt for the poor, for education, mobility, for women, blacks or anyone else who refuses to "get with their programme" of social immobility. Silicon Valley increasingly has the stench of some alt-right faction, throwbacks to violence - so long as it is cowardly, technologically mediated violence.
</p>

<p>
	 
</p>

<p>
	In it's disdain for women it's starting to look more like a backward religious sect. The irony is that tech is an industry that doesn't really produce anything. Software is mostly like music, in that you sell the same thing again and again.
</p>

<p>
	 
</p>

<p>
	It recycles old ideas and repackages software sponged from a global network of volunteer "free software" writers, sticks that on some chips imported from China, and uses that as bait to attract victims for data harvesting. It's a tasty racket if ever there was.
</p>

<p>
	 
</p>

<p>
	Of course real industry is very important, and it is part of human progress. Steel and concrete must come from somewhere. But we've long passed time to put the tech industry alongside the old oil and pharmaceuticals. It is no "disruptive" challenger to the status quo. What it perpetuates is more of itself, more control. It might not be a paperclip-maximiser yet, for now it's just a tech-industry maximiser.
</p>

<p>
	 
</p>

<p>
	It is the status-quo.
</p>

<p>
	 
</p>

<p>
	So it needs disrupting. Real progress is complex. It's not just this or that breakthrough… Penicillin. Electric lights. Steam engines. It isn't just spotting opportunities to monetise this or that idea. It's a balance of the intellectual, social, political, artistic, as well as industrial faculties. Yet we have bowed down before just a few industrial totems. This one-sided cult-like obsession with technology must be overcome and balance restored to the political and humanistic classes if we are to survive.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:24px;"><strong>The Cost</strong></span>
</p>

<p>
	<br />
	AI is consuming electricity equal to the supply for Netherlands. Crypto block-chains twice as much again. Every new phone manufactured uses the daily water supply of 10,000 people. Survival of the planet was simply not on the profit road-map for the oil companies, and likewise neither will human survival be a priority for tech. Stubborn refusal to pause AI despite low value-yields and skyrocketing risk is the giveaway.
</p>

<p>
	 
</p>

<p>
	Your security and privacy means nothing for the technology companies. Until we internalise a new reality; that our quest for technology run by people, that our quest for a sustainable, reliable, private, and secure world is not a technical problem but a political struggle, we will make no progress toward it.
</p>

<p>
	 
</p>

<p>
	Look out of your window at the floods, wildfires, hurricanes, and streets lined with stationary automobiles, then do some research on the systematic suppression of electric vehicle technology. We could have begun a serious counter to climate change over 60 years ago when it would have made a difference. The computer security problem today is eerily similar. It is stuck in political stasis, but presented as a technical problem.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:24px;"><strong>Taking back tech</strong></span>
</p>

<p>
	<br />
	Technology has one purpose; to serve humanity.
</p>

<p>
	 
</p>

<p>
	Here, today… on every smartphone there should be a single, reliable button to switch off spying once and for all. But there isn't. Why not? Because it's not profitable for you to have privacy. That's all there is to it. There's no technical challenge.
</p>

<p>
	 
</p>

<p>
	But, you say, those with political power can simply order these mischievous tech companies to behave. Sadly, no.
</p>

<p>
	 
</p>

<p>
	Foremost our politicians lack the courage, knowledge and fluency. But behind that is a Faustian bargain by which they hope to benefit from a surveillance pact. They imagine themselves "sharing" power with the tech oligarchs. They will not. Like Yeltsin, post-1991 Minsk Agreement they will become puppets and vassals to those who control their means of communication. There will be nothing left but for a "strong man" to come to the rescue of the people. And nothing good will come of that.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>Who dares?</strong></span>
</p>

<p>
	<br />
	It seems that, to get the things we want and need from technology today we must all become active. We must become hackers and combatants in a theatre of digital political warfare - fighting for security. For civic cybersecurity.
</p>

<p>
	 
</p>

<p>
	Security, privacy and self-determination in tech is what you take, not what is given to you out of kind-heartedness. What we need will not be obtained because corporations adhere to the rule of law. Nor by market forces. There is certainly nothing you can buy from people who want to rob you of it.
</p>

<p>
	 
</p>

<p>
	Big tech companies scoff at the law. They think it old-fashioned. Enormous fines are simply factored into their budgets. They have more money and influence than the political blocs that hope to regulate them. Neither can we rely on our political representatives to put up resistance, because they are poorly educated in technical matters and easily bought or misinformed.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:24px;"><strong>No escape?</strong></span>
</p>

<p>
	<br />
	Now, suppose you are active and skilled enough to do things like root a phone, disable, spoof or jam GPS, remove the SIM, connect by wifi via a VPN endpoint hosted in another country, and use a payment service located in that country… then you may briefly be able to trick companies like Google or Meta to give you what you need. But no matter what apps you install on an Android smartphone, the operating system itself is written by Google, and is therefore untrustworthy.
</p>

<p>
	 
</p>

<p>
	In all such software, privacy settings default to unsafe or revert to unsafe settings following a forced update. Some location-tracking even works when your phone is supposedly "switched off". Although their Play Store contains hundreds of apps for masking or spoofing location, few of these really work because the company is locked in an endless cat and mouse game to defeat suppliers of those products. They kill products that meet a manifestly enormous market-demand. They pretend this is motivated by "business", not ideology.
</p>

<p>
	 
</p>

<p>
	Like the British Tory party who sabotaged hospitals so that they could deem them "failing" and ripe for privatisation, BigTech firms vandalise the privacy landscape in order to declare that "there is no demand for privacy". This disinformation trick can be seen on social media forums and Internet discussion boards everywhere tech industry shills operate.
</p>

<p>
	 
</p>

<p>
	The big players dislike any independent suppliers of security products, because they conflict with their thirst for profit and power. By empowering users, small companies become the enemies of BigTech, tolerated briefly in their "App Stores" before being arbitrarily ejected. Hacker forums are filled with stories of upstart developers trying to build a company, but being turfed off BigTech land by capricious diktats. Github, a common developer platform run by Microsoft is notorious for political beheadings of dissident projects.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:24px;"><strong>False security</strong></span>
</p>

<p>
	<br />
	Maybe more damaging is that BigTech misuses people's desire for security, and misuses the language of security, to misdirect users into less beneficial or safe situations. For example, printer companies sabotage third party ink refils with malicious updates pitched as "necessary for security". This undermines any real project of cybersecurity. Users begin to mistrust updates of any kind when companies use them as vehicles for malware and undocumented suprises.
</p>

<p>
	 
</p>

<p>
	Companies muddy the waters around "security" by conflating "your security" with "our security". They then use the word "securty" as an abstract noun to imply users are getting something that benefits them but in reality benefits the vendor.
</p>

<p>
	 
</p>

<p>
	They get security from the user. Even the word itself has become a kind of token, a false "moral high ground" from which wannabe tyrants can denounce their enemies. This is a sort of cyber-washing, to use fake cybersecurity for virtue signalling and concern trolling.
</p>

<p>
	 
</p>

<p>
	Once we see that this sort of security is a fixed-sum game then it's clear that anything that improves the end-user's security actually subtracts from that of the platform suppliers who benefit from a user's vulnerability. So the main vendors smear the sellers of things that compete with their "insecurity model". They attack Libre Open Source software written by regular citizens as "insecure" and "risky" - while secretly it's the same software they take for their own products, without paying for it.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>Rebuilding public trust</strong></span>
</p>

<p>
	<br />
	Thankfully the political systems of Europe have started to wise-up and stand-up to US BigTech hostility and have mandated that all software used for public services, government and state apparatus must be Libre open source code that is auditable, verifiable and under control of the people. We want to see the same for schools, hospitals, railways and every other facet of public life and governance in the UK. Digital sovereignty is a big issue today.
</p>

<p>
	 
</p>

<p>
	Meanwhile practically, all of the "official" methods given by BigTech for obtaining privacy are no good. Play with your "preferences or choices" but regardless the platforms are still quite able to extract personal information from wifi networks and Bluetooth points in range of your devices, metadata in photos you share online, financial transactions, IP addresses of anything that touches a computer run by AWS, Meta, Azure or Google Cloud (even just to download a font or style-sheet). Any information passing through Gmail, Hotmail or Google Drive is subject to their prying if you are still unaware not to use such things.
</p>

<p>
	 
</p>

<p>
	Remarkably, some government offices still use these systems, and everything from doctors to parts of the British defence industry are entangled with Gmail, Amazon cloud, and even Whatsapp, despite warnings from the intelligence services that this isn't a good idea. Hypocritically, even GCHQ buy-in services from Amazon. If organisations that absolutely should avoid these security risks cannot resist the economic lure, who can?
</p>

<p>
	 
</p>

<p>
	There is a clear conflict of interests that companies that supply the systems for private and secure communication also profit from violating privacy and security. Surveillance is Google and Facebook's core business model. The only reliable way to defeat them and their type is not to use their products, or at least to fully root an "Android" smartphone and replace the operating system with something safer like F-Droid and with alternative social media platforms.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:24px;"><strong>A boot stamping…</strong></span>
</p>

<p>
	<br />
	But ubiquitous location spying is just one random example of the spectacular mess of consumer computing. Let's now talk about "Secure Boot", which is in the news this week as the latest massive tech SNAFU.
</p>

<p>
	 
</p>

<p>
	"Secure boot" is a ploy by (mainly) Microsoft to ensure that every computer on Earth must run exploitable software. You'll hear other explanations for "secure boot" - such as the ability to stop malware writing to the BIOS. That's handy, In reality though, that problem is solved by a "jumper", a small wire or component costing fractions of a penny. Instead the "industry" invested billions of dollars in an arcane, elaborate scheme of "trusted computing" based on suspect cryptography, to replace a wire that costs a penny. Why would they do that?
</p>

<p>
	 
</p>

<p>
	Well, it's also a way for "anti-cheat" and digital restrictions code to run on your computer, whether you want it to or not. And to stop you copying what you see on your computer screen. These don't sound like features you requested, am I right? That's because they're feature requests from tech's neighboring trillion dollar industry - arts and entertainments.
</p>

<p>
	Anyone in physical possession of computer hardware can subvert it. End of. Secure boot is a fine idea in some very limited use cases, but as a general principle to replicate into all consumer technologies it's an industry con, what we call a "Fritz Chip" that cedes power to the commercial OS vendors and software-as-service industry.
</p>

<p>
	 
</p>

<p>
	It puts your computer completely under the control of a remote and hostile company. It provides "trusted computing" for them and does not, unless you have a side business deploying remote servers in hostile locations, serve you (as a regular dude/dudette), and importantly the ostensible owner of the computer.
</p>

<p>
	 
</p>

<p>
	Last week Bruce Schneier reported on research from a group called Binerly that "secure boot" is completely compromised on almost all systems. In response, the comments were mostly "Good! We own our own computers!". Go away secure boot!
</p>

<p>
	 
</p>

<p>
	Secure-boot is a solutionist reaction to fixing a security problem that should never be there in the first place. It caters to conditions of extreme mistrust and therefore cultivates mistrust where deployed. This is a perfect example of the "insecurity industry". It is an undesirable computing concept because it brings more security to the powerful while removing security for the less powerful.
</p>

<p>
	 
</p>

<p>
	Besides, another problem is that computer main-boards even still have BIOS/EFI, now a silly and unnecessary mistake prolonged by industry inertia. People who've built and maintained computers for decades know that the more minimal the loader and the less the BIOS needs to do the better.
</p>

<p>
	 
</p>

<p>
	Computer scientists and electronics engineers get to build some quite challenging things as rites of passage. In my youth I wired together my own microprocessor (4 bit ALU with three registers and 12 bit address using TTL logic) and a full microprocessor system or "computer" (68000 based board roughly equal to an Apple Lisa - along with a simple operating system and loader for it). Having built, and in the process properly understood such technology, it's my humble opinion that since it worked in the past without any opaque magic, it can work in the future without opaque magic. The inconvenient theory that, anything that has happened can happen, leaves little space for a logical comeback.
</p>

<p>
	 
</p>

<p>
	Board-level OS is one of those ritual grooves that we are stuck doing because we always have. The root of it is disorder in the hardware industry and betrayal of standards. Egged on by the likes of Microsoft to add "trusted computing" hardware, the PC "mainboard" industry lacks a creative escape plan. In practice many simpler but very powerful "single board computers" (SBCs) completely do without this nonsense and there are hundreds of brands of main-boards that don't have encumbering and trecherous technologies embedded. Nonetheless we are attempting to normalise dangerous ideas, wandering into territory that's hostile to user security in the name of making big business more secure against them.
</p>

<p>
	 
</p>

<p>
	Perhaps the spectacular failure of Microsoft as a company is the best thing that has happened to cyberscurity for years.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>Why are we stuck?</strong></span>
</p>

<p>
	<br />
	So why do we accept this dynamic? As regular citizens, mostly because we don't know much about it. As engineers, because we get confused about whose control we are supposed to be protecting. As governments, probably because the power seems seductive but there's a lack of education in the political science of why that would be a bad thing.
</p>

<p>
	 
</p>

<p>
	In part it's also down to a dearth of technical education and the power of dishonest marketing. Technnology is always a market where people will buy things they have no need or use for, no understanding of, but hope might bring empowering magic. That is the push-power of an industry that does not answer to demand. It is also a failure of our legal and political systems to challenge predatory business, dishonest advertising and monopoly.
</p>

<p>
	 
</p>

<p>
	However, in the name of innovation, we have always taken a hands-off approach to tech, with minimal regulation. That's led to a slowly growing abusive culture. There's a toxic relationship that's grown through habit of non-challenging and taking-for-granted. We now have an industry that feels itself above and beyond the law. We have "consumers" who dwell in learned-helplessness without the courage, knowledge or political voice to fight back.
</p>

<p>
	 
</p>

<p>
	But the horror show is getting a lot more light shone on it and cracks are now visible due to a slew, indeed an inexorable tide, of spectacular technology failures that now threaten individual lives, small and medium sized businesses and government too.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>Digital lemons</strong></span>
</p>

<p>
	<br />
	It's also because the quality and provenance of software is hard to evaluate. Experts are as pressed as an average person to tell whether software is genius or junk. We don't know what value it will really bring. We don't know where the bugs are. Software quality metrics are as much a black-art as 40 years ago. We are kept on the path of cavalier engineering, to "move fast and break stuff" by the ever-present promise of medical and other scientific breakthroughs that can help humanity.
</p>

<p>
	 
</p>

<p>
	But have we factored political turmoil and social disintegration into our risk equations as a likely price to pay? Technology is risky ground and you need to look whare you are going. I think we are rather lost in fact. We seem at the mercy of tech hype cycles - blockchains, AI, virtual reality, consuming trillions of dollars and thousands of terawatt hours of energy. Where is the practical upshot? We get unemployment, pornography, and scorching the planet, so that going outside is unbearable; which may all at least cancel each other out if we can build enough homes for people to hide in and masturbate.
</p>

<p>
	 
</p>

<p>
	In truth, nobody is really sure what they are doing, and so we avoid long term discussion and decisions by deferring everything and moving agency to a future "long-tail" or maintenance phase of hardware and software. The core idea at the heart of so much bad cybersecurity is:
</p>

<p>
	 
</p>

<p>
	"Someone else will sort that out later"
</p>

<p>
	<br />
	The trick is to push the security onus and cost onto the end consumer in the form of so-called "updates". Like with climate, it pushes the risks and costs on to future generations… those that will have to clear up the mess caused by short-term profit. Unfortunately there's no "update" for a ruined planet in civil turmoil.
</p>

<p>
	 
</p>

<p>
	Digital technology is an industry that gets away with a fundamental violation of basic expectations of quality and fitness for purpose more than any other. We call this "software exceptionalism". The technology industry is run by people who think what they do is special - in an almost religiously sincere way. But most are not special. They are ordinary irresponsible people/ hoping to make a buck quick and get out before the fall.
</p>

<p>
	 
</p>

<p>
	With so many con-artists around, this means tech is a market for lemons in which the base price of all products is basically zero. Because that's the real level of confidence people have in gratuitous tech, despite all they might say. Therefore all profit made is by grift, encumbrances, rents, liens and deceptions laid on top of ostensibly "free" software services. It is not even really a "market" at all.
</p>

<p>
	 
</p>

<p>
	For about 30 years that didn't matter. People and businesses did not rely on computer software as we do today. In the 70s, 80' and 90s consumer tech products were seen as toys, fads, passing fun and frivolity. Now we put the same quality of software into Boeing airliners that fall out of the sky when it fails.
</p>

<p>
	 
</p>

<p>
	The tragedy is that we've plenty of smart people around who've devoted their lives to software engineering, quality, formal methods, and digital security. But their professionalism is made a mockery of by greedy corporations, our lack of investment in smaller, local tech, and missing political will to redistribute power on the Internet.
</p>

<p>
	 
</p>

<p>
	Anyone who looks at the emerging failures in digital tech is bewildered. Not just journalists and politicians, but the experts and programmers as well. The failures behind events like "Solar Winds", "Crowdstrike" and the latest "Secure Boot" issues are beyond belief - in their fundamental stupidity. They prove that we can assemble thousands of the worlds smartest people, but if we give them perverse motives - like putting money ahead of human life - they will fare worse than as many halfwits.
</p>

<p>
	 
</p>

<p>
	This avoidance of real thinking and engagement can be seen in events like the sham Bletchley Declaration, signed by 28 nations to agree to… "think carefully and have more talks"… about a threat considered by many leading scientists to be more serious than nuclear war.
</p>

<p>
	 
</p>

<p>
	I am in agreement with Carissa Véliz of Oxford who thinks the summit was an ethical dodge. It sullied the name of Bletchley Park (now within the grubby paws of Facebook after a £1 million "donation") by assembling political opportunists alongside carefully selected experts to give an appearance that governments are in control of the tech industry and not the other way around.
</p>

<p>
	 
</p>

<p>
	What we saw with Crowdstrike was a fundamental misunderstanding of the concept of ownership. The US National Security Agency have described anti-virus software as indistinguishable from a "rootkit" (the very worst kind of malware). Indeed that's what it is. It's just very dangerous software you allow someone else - who you believe you trust - to install on your computer. Anti-virus and "managed endpoint security" are medicines far worse than the diseases they claim to cure. Sadly we have silently slipped into an age where nobody questions this any longer, but we must challenge and remedy this dangerous mindset.
</p>

<p>
	 
</p>

<p>
	Solutionism is where we start with a small mistake and build bigger ones in response to it. In drama, that's called farce. The cascade effects in commercial tech have become a kind of farcical "Where's my trousers?" British sitcom. With secure boot what we see is mistakes bolted on top of mistakes in an orgy of solutionism. Layer upon layer of cryptographic staging and signing, and every new link in the chain is a weakness. Most of the motives are unclear. Whose computer is it?
</p>

<p>
	 
</p>

<p>
	Whose property is being "protected"?
</p>

<p>
	 
</p>

<p>
	It has every hallmark of how security goes bad - because it is unclear - and I believe deliberately so - who the security is for, what it is security from, and what end it serves! A general consensus in the technology world is that it primarily serves the interests of publishers - the movie and recording industry, Sony, Disney, the RIAA and MPAA in the US who represent these powers and dictate to other tech companies.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>Calling it out</strong></span>
</p>

<p>
	<br />
	As I've witnessed it unfold over 50 years this whole sorry saga reminds me of some cautionary tale about a tangled web woven by the boy who first told a little white lie, but then had to tell another to support it, and a bigger lie, and then a bigger one still, until he and everyone else had forgotten what was true and what was false.
</p>

<p>
	 
</p>

<p>
	That's computing today. Our industry is dominated by greedy and dishonest motives, so;
</p>

<p>
	 
</p>

<ul>
	<li>
		we're not getting the technology we really need to face the existential and economic challenges of our age
	</li>
	<li>
		we are facing a catastrophic complexity collapse
	</li>
	<li>
		we endure nebulous societal harms like damaged mental health, ruined education, widespread depression and disaffection with politics
	</li>
	<li>
		we risk a major takeover/power-shift away from democacy
	</li>
</ul>

<p>
	<br />
	If human political pride is stopping us from preventing a much worse outcome that's no failure of science, technology and engineering, but a long overdue moral reckoning. The answers here are not technical but moral, and therefore political.
</p>

<p>
	 
</p>

<p>
	Whatever names we know each weekly tech disaster by… Crowdstrike, Meltdown, Solarwinds, Horizon… as we name hurricanes… they'll still keep coming and keep getting worse.
</p>

<p>
	 
</p>

<p>
	As with climate, to fix things we must look for the root causes. The sooner we stop pretending these are technical problems and start speaking the truth about the fundamental political problems in cybersecurity, and the issues we have with our consumer computing industry in general, the sooner we can have security for all computer users again, not just the already rich and powerful ones.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://cybershow.uk/blog/posts/computer-security-is-a-political-struggle/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24684</guid><pubDate>Mon, 05 Aug 2024 14:17:03 +0000</pubDate></item></channel></rss>
