Showing posts with label Wi-Fi. Show all posts
Showing posts with label Wi-Fi. Show all posts

Thursday, January 27, 2011

Sophos Top tips for Mac OS X security - Part 1
And my commentary

--
While I polish up Parts II and III of my 2010 Mac security summary, here is an article Sophos posted on Christmas day. It is the first in a series of articles to help Mac users secure their Macs. For advanced users, this is old news.

Top tips for Mac OS X security - Part 1

For users new to the concepts in this article, it is important to note that each added layer of security typically adds a layer of difficulty for the user. Using the points from this article, here are some useful examples:

1) Disable Automatic Login: This is absolutely critical. But it means there is not automatic logging in and booting of your user account ever again. That is a GREAT thing for security. But there are always newbies who complain. I say tough. But I'm a grizzly old meanie when it comes to personal responsibility. If you are of a more personable personality, talk over with your users exactly what happens when a hacker accesses their computer: Everything of yours is now their's. Everything. Once people think about that, they tend to want to protect their computer.

2) Set a Firmware Password: This is incredibly brilliant for stopping that big, Huge GAPING SECURITY HOLE in Mac OS X: Booting onto anyone's Mac via any compatible Mac OS X installation disc. Once booted from these discs, it is dirt easy to remove and change the Administrator account password. Once changed, that Mac is PWNED! Setting a firmware password stops that DEAD. However! There are other results as well. These include losing the ability to easily change your Startup Disc. You can't boot with the Option key down to change startup discs. You can't simply click on a new volume in the Startup Disc preference pane. The result can be quite annoying if you frequently change them, for example to use another volume on your Mac for repairing your main boot volume, which I do regularly.

3) Encryption is a good idea:

--3A) Boot Drives:

On Mac OS X you are allowed to use FileVault (found in the Security preference pane) to encrypt your User accounts. If you have critical data that should NEVER fall into other people's hands, this encryption is CRITICAL! Do it. However! You've got to consider some consequences:  

First, you can no longer access that volume from another boot volume. No more repairing it from elsewhere.

Second, you MUST keep all your critical data specifically in your User account and NOT anywhere else on your boot volume. Again, only the contents of your user account Home folder is encrypted.

Third, updating Mac OS X to a new version is a bit more of a PITA if items in your Home folder have to be updated.

Fourth, there is a minor slowdown of your machine due to the constant decryption of your data then reencryption of new data.

And you'll find other minor annoyances.

If you have a critical machine, all of three of these steps are important. Think of the added user annoyances as added 'Cost Of Doing Business' that you cannot do without. Live with them and appreciate that they provide you with solid and important security.

Question: Is it important to encrypt your entire hard drive?

Answer: NO, not if you keep ALL your critical data inside your Home folder. Everything else on your hard drive should not be of any consequence. All of it should be files and folders and apps that anyone could obtain any day of the week. Therefore, getting them off your computer is trivial. What you must protect is UNIQUE data that only you and trusted colleagues should ever see.

Question: But, but, but, some security expert firm says blahblahblah!!!

Answer: They are either being extremists or they want to sell you something. For example, Sophos use their article to try to sell you their 'SafeGuard Disk Encryption for Mac' that encrypts absolutely everything on your Mac. If you see a point in further slowing down your Mac and keeping publicly accessible System files away from bad guys, fine. Go buy it. I personally see no reason for it.

The only possible exceptions I can imagine are if you are a developer or software tester who has something unique installed into their system, such as a custom .KEXT extension file, that there is no way on Earth you want anyone to obtain. Then I'd encrypt everything.

--3B) External Drives:

YES! Encrypt them! They have your data on them. This includes everything from CDs you burn to DVDs to Flash drives to attached hard drives. ENCRYPT THEM ALL!

There are lots of great programs to accomplish this for you, many of which are simple Drag And Drop apps that encrypt then put the encrypted file onto your external drive for you. Some of them will alert you if you attempt to put anything unencrypted onto a drive, 'user-minder' apps if you will. These are great to have.

--3C) Wi-Fi Encryption:

YES OF COURSE! It is so easy to forget that free Wi-Fi spots continue to provide ZERO PRIVACY. If you don't have to sign in to a Wi-Fi spot, your data and/or your cookies to websites are IN THE CLEAR, meaning you can expect them to be stolen by anyone else also connected to that router. This is why the Firesheep hacking tool was made public: To force people, Wi-Fi spot owners and website owners to WAKE UP and force encryption or account privacy at all times. Very very slowly the world is catching on. But I fully expect encryption/privacy cluelessness to last well on into the very distant future. Some people are never going to understand. That includes members of my own family! Be nice to them and if need be, set up encryption and privacy on their routers for them.

As Sophos publish further Mac OS X security tips I will provide further links and further commentary.

Share and Enjoy!
--

Wednesday, November 10, 2010

Firesheep Wi-Fi Warz

--
The Sheeple Are Burning

October 25 a hackertool was released for Firefox in the form of an add-on called Firesheep. It is extremely easy to install and use on Mac, Linux and Windows versions of Firefox. (I will not provide the link. Sorry.) It provides casual Firefox web browser users to spy on and doppelganger anyone who is connected to the Internet via a shared, open Wi-Fi connection. Simply connect your computer to the same open Wi-Fi connection and commence surveillance and identity theft.

It performs its dirty deeds by way of coopting the cookies being sent in the clear from any victim's computer. It is not a thorough form of identity theft, but it adequate while the hacker's computer remains within that open WiFi connection. IDs and passwords are typically not sent in the clear. However, the Firesheep add-on is able copy out of the air the cookies any user is sending to any website. The contents of the cookies may remain completely incomprehensible to the hacker. All that is required is the contents of that cookie to literally "BE" the intercepted victim. This means the hacker can access any active website connections and fake being that person through the use of their intercepted cookies. The hacker can do ANYTHING on those websites AS the victim. If at any point the website asks for password verification, such as when buying items from Amazon.com, the hacker is thwarted. Their identity theft stops dead at that point. However, anything else goes. This can create incredible havoc on the Internet.

At the point in time of this article being posted, well over HALF A MILLION PEOPLE have downloaded Firesheep. That essentially says it is becoming universal, endangering ALL unencrypted Wi-Fi connections to the Internet. And that was the purpose of creating and providing this add-on to the entire computer community.

The creator of this hacker tool is a Black Hat, which is to say that he bulldozes improvements in computer security by providing the means of exploiting a security hole to the world at large without any prior warning to anyone. To use a very mild metaphor, it is the equivalent of 'Tough Love' for computer users and software developers. In this case the desired effect is to lock up ALL Wi-Fi connections via encryption, ending forever open Wi-Fi connections.

There are two cures for this dilemma:

1) All websites must provide SSL encrypted connections at all times, not simply when a user logs in. This means that all websites would stop using merely HTTP connections and instead use only HTTPS connections between themselves and their users. This adds some minor overhead burdens but is entirely feasible. How long it will take the entire World Wide Web to catch up is the big question. The hope is that it will be immediate. But we're dealing with humanity here, therefore...

2) All Wi-Fi connections must require WPA account encryption. This means that all users of an 'open' Wi-Fi connection site must have and use a password in order to access the Wi-Fi hub. Surprisingly, this is an incredibly simple thing to do with nearly all modern routers. (Older routers that only use WEP encryption are SOL). Everyone making a connection to the router can use the exact same password! Routers know the MAC address of every device that connects to them. This allows them to keep each and every connection entirely separate. The fact that each connection uses the same password provides almost perfect separation of users while providing unbreakable (at this time anyway) encryption.

Here's how #2 cure would work at Starbucks: A simple sign is provided at the counter that says something to the effect of "To access Starbucks' Wi-Fi connection, please use the password 'starbucks'." That's it! Simple.

Since Firesheep was let loose for the average computer user, there have been plenty of happy stories of users speaking to the manager of shops that provide free Wi-Fi and asking them to turn on WPA account encryption. For anyone familiar with setting up Wi-Fi routers, turning on WPA is trivial. The shop managers have been happily changing their router setup and killing off the Firesheep threat. I strongly suggest that you do the same EVERYWHERE you go with your Wi-Fi device.

WEP encryption, unfortunately, was created in haste and provides NO SECURITY. It is trivial for hackers to obtain tools that can break into WEP encryption within less than a minute. It is expected, in fact, that future versions of Firesheep or similar hacker tools will include a WEP cracking tool.


The Next Best Thing To A Cure


I knew further shoes were going to drop regarding this subject. I just found out this evening that a helper tool has been provided by Zscaler that can warn you when there are Firesheep prowling around in an open Wi-Fi connection. Once again it is a Firefox add-on. Its name is Blacksheep. (Why black? Read back in the article about Black Hat hackers.)

Below is a quote from our pals at the SANS Institute from SANS NewsBites Vol. 12 Num. 89:
--Firefox Extension Warns users When Others are Using FireSheep (November 8, 2010)
Researchers have released an extension for Firefox that detects when computers on a local area network are using FireSheep, a tool that steals unencrypted cookies from websites. Called BlackSheep, the extension alerts users by displaying a message telling them that someone is using FireSheep and providing the LAN IP address of the FireSheep user. FireSheep was created and released to draw attention to the lack of encryption for session cookies on many popular websites.
http://www.theregister.co.uk/2010/11/08/firesheep_detection_tool/
[Editor's Note (Northcutt): Interesting, dueling plug-ins. For the moment this is quite limited as you can install FireSheep and BlackSheep on the same computer only if you use different Firefox profiles. The duel would be over unencrypted LANs:
http://www.zscaler.com/blacksheep.html ]
The Blacksheep add-on page provides instructions and a video showing it in action.

Also of interest: Microsoft, Intego and other anti-malware providers have added Firesheep to their list of detected 'malware'. This is IMHO a weak move as Firesheep is NOT malware. It is a hacker tool that requires deliberate installation by the hacker and has no user-based malware behavior whatsoever. However, parents or employers would be interested to know about the hacker behavior of their children or employees.

Do NOT consider Blacksheep to be any kind of cure! It is merely a defensive tool when you're STUCK at an unencrypted Wi-Fi spot, such as the Airport or wherever they are too clueless to turn on WPA encryption, or they don't know how, or they're stuck with worthless WEP encryption on their router. Do NOT consider Blacksheep to be thorough defense! It is not. I personally would only use it out of desperation.

The single best defenses against having your cookies stolen and your ID doppelgangered when you're STUCK in an open Wi-Fi spot are to:

1) Never log into anywhere that does not provide end-to-end HTTPS/SSL encryption. An example would be Google's GMail. You can't turn off HTTPS at the GMail site if you try! That's the way it should be everywhere.

2) Remember that eMail provides NO SECURITY apart from possibly an SSL connection to and from your eMail server. Otherwise, everything you email is in the clear for anyone to read. These days I think of some dorky, bored CIA/NEA/FBI human intercepting everything I email and reading it. I even write them little notes from time to time to set off their keyword alarms just to wake them up. Unconstitutional as it is to invade any US citizen's privacy, the Bush League set the precedence for breaking the law anyway, and sadly the Obama administration is goose stepping right along to the same deranged tune. I have further rants on such subjects at my zunipus blog.

The safest thing to do when you're STUCK at an open Wi-Fi spot is to merely browse happy, smiley, shiny websites for fun, not for work, not for financial interactions, not anywhere a hacker could steal your identity. With Firesheep they are you anywhere you go on the web.

Stay safe kids! And watch out for sheep.

;-Derek
--