Cyberwarfare

Cyberwarfare raises issues of growing national interest and concern.

Cyberwarfare can be used to describe various aspects of defending and attacking information and computer networks in cyberspace, as well as denying an adversary’s ability to do the same. Some major problems encountered with cyber attacks, in particular, are the difficulty in determining the origin and nature of the attack and in assessing the damage incurred.

A number of nations are incorporating cyberwarfare as a new part of their military doctrine. Some that have discussed the subject more openly include the United Kingdom, France, Germany, Russia, and China. Many of these are developing views toward the use of cyberwarfare that differ from those of the United States, and in some cases might represent national security threats.

Cyberterrorism is also an issue of growing national interest. Many believe terrorists plan to disrupt the Internet or critical infrastructures such as transportation, communications, or banking and finance. It does seem clear that terrorists use the Internet to conduct the business of terrorism, but on closer inspection, however, it is not clear how or whether terrorists could use violence through the Internet to achieve political objectives.

Although the U.S. government is striving to consolidate responsibility for and focus more attention on cyberwarfare issues, it is not clear how successful those efforts will be. Congress may choose to examine critically the policies, organization, and legal framework that guides executive ranch decisionmaking on issues of cyberwarfare.
Showing posts with label password. Show all posts
Showing posts with label password. Show all posts

Tuesday, April 20, 2010

Google Hackers Stole Global Password System

Report: Google Hackers Stole Source Code of Global Password System

By Kim Zetter

The hackers who breached Google’s network last year were able to nab the source code for the company’s global password system, according to The New York Times.

The single sign-on password system, which Google referred to internally as “Gaia,” allows users to log into a constellation of services the company offers — Gmail, search, business applications and others — using one password.

The hackers, who are still unknown, were able to steal the code after gaining access to the company’s software repository, which stores the crown jewels for its search engine and other programs.

Because the hackers grabbed the software, and do not appear to have grabbed customer passwords, users aren’t directly affected by the theft. But the hackers could study the software for security vulnerabilities to devise ways to breach the system that could later affect users.

Google announced in January that it and numerous other companies had been hacked in a sophisticated attack. The hackers had targeted source code repositories at many of the companies, including Google.

According to the Times, the theft began when an instant message was sent to a Google employee in China who was using Windows Messenger. The message included a link to a malicious website. Once the employee clicked on the link, the intruders were able to gain access to the employee’s computer and from there to computers used by software developers at Google’s headquarters in California.

The intruders seemed to know the names of the Gaia software developers, according to the Times. The intruders had access to an internal Google corporate directory known as Moma, which lists the work activities of every Google employee.

They initially tried to access the programmer’s work computers and “then used a set of sophisticated techniques to gain access to the repositories where the source code for the program was stored.”

The Times doesn’t elaborate on the set of sophisticated techniques the hackers used to access the source code, but in March, security firm McAfee released a white paper in relation to the Google hack that describes serious security vulnerabilities it found in software configuration management systems (SCMs) used by companies that were targeted in the hacks.

“[The SCMs] were wide open,” Dmitri Alperovitch, McAfee’s vice president for threat research told Threat Level at the time. “No one ever thought about securing them, yet these were the crown jewels of most of these companies in many ways — much more valuable than any financial or personally identifiable data that they may have and spend so much time and effort protecting.”

Many of the companies that were attacked used the same source-code management system made by Perforce, a California-based company, according to McAfee. The paper didn’t indicate, however, whether Google used Perforce or had another system in place with vulnerabilities.

According to McAfee’s earlier report, the malicious website the hackers used in the Google hack was hosted in Taiwan. Once the victim clicked on a link to the site, the site downloaded and executed a malicious JavaScript, with a zero-day exploit that attacked a vulnerability in the user’s Internet Explorer browser.

A binary disguised as a JPEG file then downloaded to the user’s system and opened a backdoor onto the computer and set up a connection to the attackers’ command-and-control servers, also hosted in Taiwan.

From that initial access point, the attackers obtained access to the source-code management system or burrowed deeper into the corporate network to gain a persistent hold.

According to the paper, the hackers were successful at accessing source code because many SCMs are not secured out of the box and do not maintain sufficient logs to help forensic investigators examining an attack.

“Additionally, due to the open nature of most SCM systems today, much of the source code it is built to protect can be copied and managed on the endpoint developer system,” the white paper states. “It is quite common to have developers copy source code files to their local systems, edit them locally, and then check them back into the source code tree…. As a result, attackers often don’t even need to target and hack the backend SCM systems; they can simply target the individual developer systems to harvest large amounts of source code rather quickly.”

Alperovitch told Threat Level his company had seen no evidence to indicate that source code at any of the hacked companies had been altered.


Google password system was target of Chinese hackers

Charles Arthur

Web giant quit Chinese mainland after attack on internal system allowing people to use single password to access its services

Google's internal system which lets people access its services via a single password was the target of the Chinese hacking attack last December that led the company to withdraw from the mainland, according to the New York Times.

The system, known internally as "Gaia" – after the overarching planetary consciousness posited by James Lovelock – is behind the interface which lets not just users but also Google developers to log in and gain access to the company's resources. Millions of people use that interface to access documents and email from anywhere in the world using Google's "cloud" services. However, users' passwords have not been compromised: Google is understood to follow standard security practice, by which passwords are only stored in encrypted form known as a "hash". When a user logs in, the password they supply is encrypted using the same method and compared to the hash. If the two match, access is allowed. Reversing the process is computationally unfeasible.

But if the hackers could gain uncontrolled access to Gaia, they might be able to change the emails to which password resets are sent (for instance when people forget their original one), and then trigger a password reset – effectively capturing the account. They might also be able to limit or expand what an account was allowed to access.

The hacking was a two-stage process. First the hackers gained access to an internal Google system called Moma, which holds information about the work activities of each Google employee: the hackers may have used that to find specific employees. Then a China-based member of Google's staff was sent a link via Microsoft's instant messenger system to a website which infected their computer and gave the hackers access to the company's internal network.

The New York Times said that a person with "direct knowledge of the investigation" had provided the details of the hack, which it said lasted less than 48 hours. Google had no comment today, referring enquiries to its original blogpost from 12 January in which it revealed that it had been attacked, when it called the hack "a highly sophisticated and targeted attack on our corporate infrastructure originating from China that resulted in the theft of intellectual property from Google."

It also said then that "we have evidence to suggest that a primary goal of the attackers was accessing the Gmail accounts of Chinese human rights activists".

Google began making "significant" changes to its internal systems as soon as it discovered the attack. But the hackers seem to have had access to the actual program code that is used to run Gaia – which security experts said could, in theory, lead them to weaknesses in it that they could exploit which Google would not be able to detect.

The attack on Google was not an isolated incident: the company said at the time that it had evidence that "at least 20" other US companies in internet, finance, technology, media and the chemical sectors had also been infiltrated and their intellectual property stolen. The attack was dubbed "Aurora" by the internet security company McAfee, which said that it had been done through a weakness in Microsoft's Internet Explorer browser.

Observers have suggested that the Chinese government was behind the attacks because of the profile of the companies and the information that was targeted. While Google has never publicly backed this view, its decision upon discovering the attack to cease censoring its search results in China – and withdraw its operations from the Chinese mainland to Hong Kong – suggest it thinks the attacks were done on the orders of government.

The latest details may make some businesses wary of using so-called "cloud" computing, where high-value data or important personal information is stored online rather than on individual computers under the owner's control. But the fact that it was not just Google that was affected, but internet-connected machines in other companies too, suggests that organisations will need to reconsider the threat from government-inspired hackers.

Wednesday, January 20, 2010

Popular account password Hack Me Please

If Your Password Is 123456, Just Make It HackMe

Published: January 20, 2010

Back at the dawn of the Web, the most popular account password was “12345.”


Today, it’s one digit longer but hardly safer: “123456.”

Despite all the reports of Internet security breaches over the years, including the recent attacks on Google’s e-mail service, many people have reacted to the break-ins with a shrug.

According to a new analysis, one out of five Web users still decides to leave the digital equivalent of a key under the doormat: they choose a simple, easily guessed password like “abc123,” “iloveyou” or even “password” to protect their data.

“I guess it’s just a genetic flaw in humans,” said Amichai Shulman, the chief technology officer at Imperva, which makes software for blocking hackers. “We’ve been following the same patterns since the 1990s.”

Mr. Shulman and his company examined a list of 32 million passwords that an unknown hacker stole last month from RockYou, a company that makes software for users of social networking sites like Facebook and MySpace. The list was briefly posted on the Web, and hackers and security researchers downloaded it. (RockYou, which had already been widely criticized for lax privacy practices, has advised its customers to change their passwords, as the hacker gained information about their e-mail accounts as well.)

The trove provided an unusually detailed window into computer users’ password habits. Typically, only government agencies like the F.B.I. or the National Security Agency have had access to such a large password list.

“This was the mother lode,” said Matt Weir, a doctoral candidate in the e-crimes and investigation technology lab at Florida State University, where researchers are also examining the data.

Imperva found that nearly 1 percent of the 32 million people it studied had used “123456” as a password. The second-most-popular password was “12345.” Others in the top 20 included “qwerty,” “abc123” and “princess.”

More disturbing, said Mr. Shulman, was that about 20 percent of people on the RockYou list picked from the same, relatively small pool of 5,000 passwords.

That suggests that hackers could easily break into many accounts just by trying the most common passwords. Because of the prevalence of fast computers and speedy networks, hackers can fire off thousands of password guesses per minute.

“We tend to think of password guessing as a very time-consuming attack in which I take each account and try a large number of name-and-password combinations,” Mr. Shulman said. “The reality is that you can be very effective by choosing a small number of common passwords.”

Some Web sites try to thwart the attackers by freezing an account for a certain period of time if too many incorrect passwords are typed. But experts say that the hackers simply learn to trick the system, by making guesses at an acceptable rate, for instance.

To improve security, some Web sites are forcing users to mix letters, numbers and even symbols in their passwords. Others, like Twitter, prevent people from picking common passwords.

Still, researchers say, social networking and entertainment Web sites often try to make life simpler for their users and are reluctant to put too many controls in place.

Even commercial sites like eBay must weigh the consequences of freezing accounts, since a hacker could, say, try to win an auction by freezing the accounts of other bidders.

Overusing simple passwords is not a new phenomenon. A similar survey examined computer passwords used in the mid-1990s and found that the most popular ones at that time were “12345,” “abc123” and “password.”

Why do so many people continue to choose easy-to-guess passwords, despite so many warnings about the risks?

Security experts suggest that we are simply overwhelmed by the sheer number of things we have to remember in this digital age.

“Nowadays, we have to keep probably 10 times as many passwords in our head as we did 10 years ago,” said Jeff Moss, who founded a popular hacking conference and is now on the Homeland Security Advisory Council. “Voice mail passwords, A.T.M. PINs and Internet passwords — it’s so hard to keep track of.”

In the idealized world championed by security specialists, people would have different passwords for every Web site they visit and store them in their head or, if absolutely necessary, on a piece of paper.

But bowing to the reality of our overcrowded brains, the experts suggest that everyone choose at least two different passwords — a complex one for Web sites were security is vital, such as banks and e-mail, and a simpler one for places where the stakes are lower, such as social networking and entertainment sites.

Mr. Moss relies on passwords at least 12 characters long, figuring that those make him a more difficult target than the millions of people who choose five- and six-character passwords.

“It’s like the joke where the hikers run into a bear in the forest, and the hiker that survives is the one who outruns his buddy,” Mr. Moss said. “You just want to run that bit faster.”