Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Saturday, March 24, 2007

Trusted Comuting: a film to warn you

Do you know what "Trusted Computing” is question it is a new idea developed by some great names of computers, according to them to make our computers safer. The guiding principle is very simple, it consists in assigning a signature for each data-processing object (software, document, music), and delegating to a third party the task to check if the handled object is authorized with being used on the local system… Elegant you will say, at the end we will get rid of all theses viruses… But think just a little: who will be the third party, the confidence one? All the signatures will have to be checked by this third party, and thus each signature recorded in the big database of this new Big Brother evil what, in a Microsoft logic, for example, will mean paid a lot of money to record your signature (if you do not believe me, ask yourself this simple question: “How much would it cost me to have my certificate in Internet Explorer? ”). To explain hazards this concept, here a small film found on Zudeo:

TrustedComputing_LAFKON_HIGH


Once again the great computer makers groups or OS makers intend to play Big Brother with the world… But once again, I think that the free software, will be able to answer this threat… If the laws are not voted by and for the million of $ these large companies! evil

Sunday, January 28, 2007

Big Brother is getting bigger and bigger

Details of millions of English people could soon be shared by bureaucrats on a giant database. This database is said to improve public services but it will sweep away privacy protection laws too. A lot of civil liberties groups condemned the project as another step towards a Big Brother state! England is already leading the world in video surveillance with more than 4 million CCTV cameras in the country... and now Tony Blair unveils the Big Brother project... It is time that English people put a halt to this and take care about their privacy... English government has already proved its incapacity in big IT project (NHS, or register of criminals...) but when it is matter of money they are always ready for the worse... Let's see if English people will stand up for their privacy... Just a little quotation that everyone should keep in mind:
First they came for the hackers. But I never did anything illegal with my computer, so I didn't speak up. Then they came for the pornographers. But I thought there was too much smut on the Internet anyway, so I didn't speak up. Then they came for the anonymous remailers. But a lot of nasty stuff gets sent from anon.penet.fi, so I didn't speak up. Then they came for the encryption users. But I could never figure out how to work pgp5 anyway, so I didn't speak up. Then they came for me. And by that time there was no one left to speak up."
Alara Rogers (Aleph Press)

Tuesday, January 23, 2007

Big Brother Awards

Not! it is not a post aboout a stupid English program twisted and I will not speak either about Jade Goody… Big Brother is the “character” created by George Orwell in his book 1984 (if you have not yet read it: you should)… and became synonymous with monitoring, or breaking the private life… and in fact precisely the French personalities (especially politicians) having acted like BigBrother “were rewarded” on January 20… One can find Jacques Lebrot, Paul Anselin, Pascal ClĂ©ment… Nicolas Sarkozi being declared out of the competition evil. Follow the link it is realy amusing!

Saturday, January 20, 2007

How to remember several very very complicated passwords?

in fact you only need to remember one password lol

I have just discovered “Password Composer”: the principle is simple: when you install this Greasemonkey script, each time it discovers a password field, it colors this field with green… If you double-click on the fields… a new dialog box appears and asks you for your master password… Script add then this password with the address of the site (with a change or two) and hash the result (md5)… This gives you a quite complicated password lol Why not use the same password for all the Web sites, because if one of the Web sites is cracked (and that happens very often…) the hacker can retrieve your password with a “rainbow table” or by brute force… he will have both your login and your password… It then he uses Google to know where you connect also and then can access to quite all your accounts… It is then enough to use different passwords but the complicated passwords are difficult to remember…
The only disadvantage of this script is that you will not have any more access from anywhere on your account, you will always need this script to connect you lol if safety is at this price, it does not bother me twisted you can always take your key USB with firefox on it lol but you are likely to become as paranoiac as me and to crypt it twisted


Thursday, January 18, 2007

Benjamin Franklin and the security

Security is not only a problem of the 21st century...

Those who would give up essential liberty to purchase a little temporary safety, deserve neither liberty nor safety
Benjamin Franklin

This quotation is dedicated to all the people who think that the new biometric identity cards will prevent terrorism, but which often forget that nothing distinguishes a terrorist from an honest citizen and that consequently the only manner of fighting against this plague would be to read the most intimate thoughts of each one… I am sure that you are a little less enthusiastic now… If it is not the case, I advise you highly the reading of 1984 of George Orwell.

Sunday, January 07, 2007

Picasaweb and a pseudo security

I have just tested Picasaweb, I had not tested it yet for the simple reason which I have no desire for spreading out my private life on the Web… nevertheless to exchange pictures with somebody, it can not be too bad, therefore I the uploaded some pics in an unlisted album… Google explains you that this album will be accessible only to the people,who are invited by you. So why a research on Google of the type: “site: picasweb.google.com authkey” returns at least one result??? It is absolutely not a safe solution to share pictures. And I was thinking that Google was one of the champions of safety lol… No Sorry twisted So Be careful…sad

Sunday, December 10, 2006

Data leaks from the "Identity and Passport Service"

Thanks to Wendell, I have found another article (follow the link of the title). It seems that information already detained by the State is not secured... In the Identity and Passport Service, which is setting up the National Identity Register, some members of the staff "hacked" the system to access private data from citizens...
Personal information about every British passport holder - including their date of birth, mother's maiden name, address and photographs - is already held in the IPS computers.
Now, do you remember one of the most common question bank ask you when they try to retrieve information about you... Yes your mother's maiden name! But it is simple to use it on Google, Yahoo or MSN to access to the mailbox... because in this case too, the mother's maiden name is often one of the recovery question... So even with so few information, which could already lead to an identity theft... you can already do some very harmful things... The problem with the dream of the British Big Brother is that it seems that every one can look over its shoulder... So imagine what could happen in the future with biometric data (have a look to this cartoon thank you Anonymous ;-) ) That's why I think that we have to think very carefully to the information we let institutions to record... And how they do that! That was the principal reason of my previous post...


Wednesday, December 06, 2006

Heathrow becomes biometric

The Heathrow airport is beginning to test an iris scan biometric machine to identify passengers at customs. Big Brother is not yet here and biometric passport are not yet mandatory... In fact passengers at Heathrow airport are being invited to take part in a trial of tech biometric scanning equipment which aims to make the travelling process easier by getting people through identity checks faster than ever before... All iris scan are record in a database, which will permit later to speed up the check of passenger... But the problem is how to be sure that this database will be safe, that information will not leak... Some people already sell data about others like address, phone number, gender, bank account number... So imagine what might happen with your biometric characteristics... Have you ever seen "Minority Report" and "Gattaca"? In Minority Report, all the shops use your iris to display targeted advertising... In Gattaca, even if there are plenty of biometric detector, one guy is able to fool all of them... This technology can be very useful but data have to be recorded carefully, maybe by using a fuzzy system... This time you don't record the biometric characteristic but a key c and the distance between c and your biometric characteristic x, which is name d. Now we use a fuzzy hash function: minor error leads to the same result, medium error produces a different hash. So in your database you have:
(h(c),d)
when you present your biometric characteristic, you compute: h(d+x') which has to match h(c) to be accepted...

The result is that you can change the secret if the database is compromise... It is maybe not the best method, as it requests a good function h but it is probably better than let the data on an untrusted server... Live and learn to see how this system will be broken...


Tuesday, November 28, 2006

A search engine dedicated to Security

I have played a little with the Google's technology to develop a search engine dedicated to the Security (of Internet, Computer, Networks...)
The search engine can be found at this adress:

http://cosearch.googlepages.com/cosecurity.html

For the moment only those urls are recorded for researches:
http://www.sans.org

http://secunia.com/
http://www.securityfocus.com/
http://edition.cnn.com/2006/LAW/11/20/internet.libel.ap/index.html(Court OKs broad Web libel immunity)
http://edition.cnn.com/2006/LAW/11/20/internet.libel.ap/index.html(Hackers plant virus on Website of China's largest bankcard operator)
http://www.guardian.co.uk/frontpage/story/0,,1953213,00.html(GPs revolt over patient files privacy)
http://www.cylab.cmu.edu/(Carnegie Mellon CyLab)
http://news.netcraft.com/ (Netcraft)

In fact I use it at my office, but it seems that it is not yet enough mature for the moment only : there are not enough urls in its database... So if some people want to take part to the adventure or post some interesting url...



Saturday, November 11, 2006

Kapersky and the 20 viruses

Kaspersky has just published its list of the top 20 malwaress (Virus/Trojan/Worm/...) spreaded by mail. As a consequence, in the case you see those little creature: don't click on them, don't try to play with them...
  1. Email-Worm.Win32.NetSky.q
  2. Email-Worm.Win32.Warezov.dn
  3. Email-Worm.Win32.Bagle.gen
  4. Email-Worm.Win32.Scano.gen
  5. Email-Worm.Win32.Warezov.ev
  6. Email-Worm.Win32.Bagle.mail
  7. Email-Worm.Win32.Warezov.dc
  8. Email-Worm.Win32.Mydoom.l
  9. Email-Worm.Win32.Mydoom.m
  10. Email-Worm.Win32.Scano.e
  11. Email-Worm.Win32.Warezov.do
  12. Email-Worm.Win32.NetSky.aa
  13. Email-Worm.Win32.NetSky.b
  14. Net-Worm.Win32.Mytob.c
  15. Trojan-Spy.HTML.Bankfraud.od
  16. Email-Worm.Win32.Warezov.eu
  17. Email-Worm.Win32.Warezov.gen
  18. Email-Worm.Win32.Bagle.dx
  19. Email-Worm.Win32.Warezov.dh
  20. Email-Worm.Win32.Scano.aq
Some new players in the team: Warezov.dn, Warezov.ev, Warezov.dc, Warezov.do, Warezov.eu, Warezov.gen, Warezov.dh.
Some malwares which begin to extinguish: NetSky.b, Mytob.c, Bankfraud.od, Scano.aq. Unfortunately we can notice the return of: NetSky.q, Bagle.gen, Bagle.mail, Mydoom.l, Mydoom.m, Scano.e, NetSky.aa, Bagle.dx, this means that some people don't have an uptodate antivirus, as a consequence they are infected and spread the threat! So install an antivirus if you haven't one already and ensure that it is uptodate (not only Kapersky, but Norton too, or ClamWin...)

Monday, October 30, 2006

Monty Python

Did you know that the word SPAM comes from a Monty Python sketch? Yes SPAM: these mails that you receive everyday in your mail box, these mails which promize you a big cash prize in a lottery ( or a purchase for a lottery ticket) or those which ask you the detail of you bank account, or a big winning prize and at last but not the least, the man in some country, who asks you to give him money in order to save funds from some dictators... All this new threats (SCAM or SPAM) are now named according a sketch by Monty Python




Lottery Scam

Since I received this letter from Euromillones, I made some researches about scams... In fact it was my first but there is not only the Italian Lottery which is used: the british one too. It’s worth noting that there is really a UK national lottery. The National lottery does not run an email campaign at all. As usually in SCAM, you will be asked for a series of charges to get the prize in cash or details of your bank account and it will never arrive! This is a scam so ignore it. Here a copy of this mail:


The National Lottery,
P O Box 1010,
L70 1NL Liverpool,
UNITED KINGDOM
(Customer Services)

Batch: 074/05/ZY369
Ref: UK/9420X2/68





WINNING NOTIFICATION:
We happily announce to you the draw (#963) of the UK NATIONAL LOTTERY,online Sweepstakes International program held on the 21st July, 2006.
Your e-mail address attached to ticket number:56475600545 188 with Serial number 5368/02 drew the lucky numbers:12-18-22-24-32-33(bonus no.), which subsequently won you the lottery in the 2nd category i.ematch 5 plus bonus.You have therefore been approved to claim a total sum of £250,000 (Two hundred and fifty thousand pounds sterling) in cash credited to file KTU/9023118308/03.

This is from a total cash prize of £1,000,000 shared amongst the first four (4) lucky winners in this category i.e Match 5 plus bonus. All participants for the online version were selected randomly from World Wide Web sites through computer draw system and extracted from over 100,000 unions, associations, and corporate bodies that are listed online. This promotion takes place periodically.

Please note that your lucky winning number falls within our European booklet representative office in Europe as indicated in your play coupon.In view of this, your £250,000 (Two hundred and fifty thousand pounds sterling) would be released to you by any of our payment offices in Europe. Our European agent will immediately commence the process to facilitate the release of your funds as soon as you contact him.

For security reasons, you are advised to keep your winning information confidential till your claim is processed and your money remitted to you in whatever manner you deem fit to claim your prize. This is part of our precautionary measure to avoid double claiming and unwarranted abuse of this program. Please be warned.

The UK NATIONAL LOTTERY Awards is proudly sponsored by the Microsoft Corporation, the Intel Group, Toshiba, Dell computers, Mckintosh and a conglomeration of other international IT companies. The UK NATIONAL LOTTERY internet draw is held once in a year and is so organized to encourage the use of the internet and computers worldwide. We are proud to say that over 200 Million Pounds are won annually in more than 150 countries worldwide.

To file for your claim, please send your details; Age, Sex, Country, Amount Won, Phone Number and Fax to our fudiciary agent
Fudiciary Agent: Mr Jack Collins
Email: jackcollins0001@yahoo.co.uk
Goodluck from me and members of staff of the UK NATIONAL LOTTERY.




Yours faithfully,
Brian Hunt.
Online coordinator
UK NATIONAL LOTTERY,
Sweepstakes International Program.
Open 7 days 7am-7pm.


Saturday, October 28, 2006

Someone try to steal my bank account number...

This morning, I received a strange mail from the Euromillones lottery primitiva s.a. This is surprising because I never buy a ticket... Moreover this mail come from Spain... But what is very annoying is that the name on the letter, has the same error as the name I gave to BT! In fact, when I opened my BT line, they miswrite my name and this is exactly the same error which appears on the letter I received: this is probably not a coincidence! BT leaks information about its customers, which could give the possibility to someone to send me a letter or even try to steal my identity! In fact in the letter it is written (I will copy this letter, so you will be able to compare if you received the same) that I won 615 810 euros... but I must give them my bank account number so they will be able to transfer the money to my account: THIS IS PHISHING. Sorry man I am not dumb. I will probably try to contact BT and explain them the situation... For the moment I will copy the letter here, so you can compare, if you receive the same letter:

FROM: THE DESK OF THE VICE PRESIDENT
INTERNATIONAL PROMOTION/PRICE AWARD
ATTN:STAKE WINNER

RE: AWARD FINAL NOTIFICATION

This is to inform you on the release of the Euromillones loteria internaltional program held on the 23th DEC. 2005. Due to mix up of some numbers and names, the results were released on the 23th OCT. 2006. Your name attached to ticket number ...................... with serial number ......... drew the lucky numbers of ............... which consequently won the lottery in the 3rd category.

You have therefore been approved for a lump sum payout of 615,810.00 euros in cash credited to file with REF NO ....... This is from a total cash price of 5,600,000.00 euros. Shared among the twelve international winners in there respective categories. CONGRATULATIONS!!!
Your fund is now deposited with a security company and insured in your name. Due to mix up of some numbers and name, we ask that you keep this award from public notice until your claim has been processed and money remitted to your account as this part of our security protocol to avoid double claiming or unwarranted taking advantage of this program by participants.

All participants were selected through a computer ballot system drawn from 25,000 names from Asia, Australia, New Zealand, Europe, America and North America as part of our International promotions program which we conduct once every year. We hope your lucky name will draw a bigger cash prize in the next year's program.
To begin your lottery claim, please contact your claims agent DR. RAUL GOMEZ the Foreign operations manager of GROUPAMA SEGUROS S.A On Tel: 0034 658 520 602. Fax: 0034 911 814 182 for the processing and remittance of your winning prize money to a destignation of your choice.

Remember, all price money must be claimed not later than, 27th NOV 2006. After this date all funds will be returned to the MINISTERIO DE ECONOMICO Y HACIENDA as unclaimed. And also be informed that 10% of your lottery Winning belongs to GROUPAMA SEGUROS S.A. because they are your claims agent. This is 10% will be remitted after you have received your winnings because the money is insured in your name already.

.... bla bla.....

place of the letter now: bin