This Week’s [in]Security – Issue 16
17 Jul 2017.
Welcome to This Week’s [in]Security. We’ve collected and grouped together a selection of this week’s news, opinions, and research. Quickly skim these annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.
PCI Compliance and Payments
- PCI Council now looking at software based standards for mobile PIN entry with solutions like Square, may signal a change of position with implications to other standards https://blog.pcisecuritystandards.org/mobile-payment-acceptance-a-look-at-pcis-new-software-based-pin-entry-initiative
- Official PCI SSC article on Demystifying NESA https://blog.pcisecuritystandards.org/demystifying-the-nesa ( See also our previous article on P2PE, NESA, and E2EE https://controlgap.com/blog/understanding-encryption-and-pci-compliance/)
- NIST announces plans to deprecate TDEA (3DES) https://beta.csrc.nist.gov/News/2017/Update-to-Current-Use-and-Deprecation-of-TDEA
- UK payments survey http://www.pymnts.com/news/regulation/2017/psr-offers-up-annual-report-and-regulatory-roadmap/
- Experiments in offline-mobile payments https://www.lightbluetouchpaper.org/2017/07/12/testing-the-usability-of-offline-mobile-payments/
- Deep insert skimmers using infrared https://krebsonsecurity.com/2017/07/thieves-used-infrared-to-pull-data-from-atm-insert-skimmers/
Breaches / Leaks
- UK's AA leaks partial credit card (i.e. last 4, expiry) info but PR side of incident response less than satisfying https://www.theregister.co.uk/2017/07/10/aa_breach_analysis/
- Possible breach of 100M records from Indian telco https://www.theregister.co.uk/2017/07/11/indian_telco_reliance_jio_denies_alleged_customer_data_breach/
- Analysis (long) of the affect of breaches on share prices shows variations such as due to time period and asset sensitivity https://www.comparitech.com/blog/information-security/data-breach-share-price/
- 3rd card breach for Trump Hotels due to Sabre breach https://www.theregister.co.uk/2017/07/11/trump_hotels_sabre_synxis_victim/ and http://www.databreachtoday.com/trump-hotels-suffers-another-payment-card-breach-a-10101
- Verizon 3rd party leaks 14M customer records through insecure AWS S3 bucket https://threatpost.com/third-party-exposes-14-million-verizon-customer-records/126798/
- S3 leaks are happening way too often https://threatpost.com/experts-warn-too-often-aws-s3-buckets-are-misconfigured-leak-data/126826/
Lawful Access / Back-doors / Laws & Regulations
- ex-GCHQ director backs end to end encryption https://www.theregister.co.uk/2017/07/10/former_gchq_wades_into_encryption_debate/
- China and Russia pass anti-privacy laws https://www.theregister.co.uk/2017/07/11/russia_china_vpns_tor_browser/
- US restricts use of Kaspersky http://www.databreachtoday.com/trump-administration-restricts-kaspersky-lab-product-use-a-10105
Bugs
- Mitre is having trouble keeping up with CVE's http://www.csoonline.com/article/3204568/application-security/closing-the-cve-gap-is-mitre-up-to-it.html
- Rare HP Non-Stop vulnerability and it's, you guessed it, Samba https://www.theregister.co.uk/2017/07/11/hpe_stops_nonstop_server_samba_bugs/
- Recent penetration test report on RDP showing significant systematic weaknesses and challenges to achieving secure configurations https://www.exploit-db.com/docs/41621.pdf (Note: the attack uses arp spoofing but could easily be implemented using wide area techniques like DNS compromise)
Privacy
- EFF's 7th annual report "Who Has Your Back? Government Data Requests" https://www.eff.org/who-has-your-back-2017
- "Black Code" documentary available for streaming https://citizenlab.ca/2017/07/black-code-available-streaming/
Hacking / Malware / Cybercrime
- New POS malware, old botnet https://threatpost.com/new-point-of-sale-malware-lockpos-hitches-ride-with-flokibot/126795/
- Example of disgruntled employee revenge http://www.csoonline.com/article/3206626/security/insider-wreaks-havoc-on-companyafter-he-resigns.html
- Going to DefCon, consider a burner laptop http://blog.erratasec.com/2017/07/burner-laptops-for-def-con.html
- SMS based MFA, no problem just social engineer the phone https://www.theregister.co.uk/2017/07/10/att_falls_for_hacker_tricks/
- Remember the Mt Gox Bitcoin hack, former CEO now on trial for embezzlement https://www.theguardian.com/technology/2017/jul/11/gox-bitcoin-exchange-mark-karpeles-on-trial-japan-embezzlement-loss-of-millions
Other Security / Risk
- Smart home assistant device calls cops http://www.csoonline.com/article/3205897/security/smart-home-device-calls-cops-during-domestic-dispute.html
- Implications for DRM, study shows interoperability features command a premium https://www.eff.org/deeplinks/2017/07/new-research-estimates-value-removing-drm-locks
- The future of multi-media forgeries https://www.schneier.com/blog/archives/2017/07/the_future_of_f_1.html
- TLD name server domains for British Indian Ocean Territory (.io) left open for renewal and hijacking https://www.theregister.co.uk/2017/07/10/io_hijacking_in_transition_cockup/
- No fly zone? No problem. Bad source code security opens drone software up for tinkering https://www.theregister.co.uk/2017/07/11/dji_drones_app_sec/
- EFF appeals W3C's EME DRM decision https://www.eff.org/deeplinks/2017/07/notice-w3c-effs-appeal-directors-decision-eme
- The dangers of home-grown single sign-on https://threatpost.com/uber-patches-authentication-bypass-vulnerability-on-custom-sso-solution/126791/
- Smartphone based SQL injection tool https://www.darkreading.com/application-security/new-sql-injection-tool-makes-attacks-possible-from-a-smartphone/d/d-id/1329334
Off-Topic
- The quantum internet just got 1 photon closer https://www.sciencealert.com/scientists-just-teleported-a-photon-from-earth-to-orbit-for-the-first-time
- Best images ever of Jupiter's Great Red Spot http://www.syfy.com/syfywire/the-great-red-spot
- Hubble makes lucky find and images a star 9-billion light years away http://www.syfy.com/syfywire/the-farthest-star
- Delaware+ sized iceberg breaks off Antarctica http://www.bbc.co.uk/news/science-environment-40321674