Showing posts with label Passwords. Show all posts
Showing posts with label Passwords. Show all posts

Sunday, April 13, 2014

Report: NSA Exploited Heartbleed to Siphon Passwords for Two Years

Image: Codenomicon

Image: Codenomicon

The NSA knew about and exploited the Heartbleed vulnerability for two years before it was publicly exposed this week, and used it to steal account passwords and other data, according to a news report.

Speculation had been rampant this week that the spy agency might have known about the critical flaw in OpenSSL that would allow hackers to siphon passwords, email content and other data from the memory of vulnerable web servers and other systems using the important encryption protocol.

That speculation appears to be confirmed by two unnamed sources who told Bloomberg that the NSA discovered the flaw shortly after it was accidentally introduced into OpenSSl in 2012 by a programmer.

The flaw “became a basic part of the agency’s toolkit for stealing account passwords and other common tasks,” the publication reports. [See NSA response below]

OpenSSL is used by many websites and systems to encrypt traffic. The vulnerability doesn’t lie in the encryption itself, but in how the encrypted connection between a website and your computer is handled. On a scale of one to 10, cryptographer Bruce Schneier ranks the flaw an 11.

The flaw is critical because it’s at the core of SSL, the encryption protocol so many have trusted to protect their data, and can be used by hackers to steal usernames and passwords — for sensitive services like banking, ecommerce, and web-based email.

There are also concerns that the flaw can be used to steal the private keys that vulnerable web sites use to encrypt traffic to them, which would make it possible for the NSA or other spy agencies to decipher encrypted data in some cases and to impersonate legitimate web sites in order to conduct a man-in-the-middle attack and trick users into revealing passwords and other sensitive data to fake web sites they control.

Heartbleed allows an attacker to craft a query to vulnerable web sites that tricks the web server into leaking up to 64kb of data from the system’s memory. The data that’s returned is random — whatever is in the memory at the time — and requires an attacker to query multiple times to collect a lot of data. But this means that any passwords, spreadsheets, email, credit card numbers or other data that’s in the memory at the time of the query could be siphoned. Although the amount of data that can be siphoned in one query is small, there’s no limit to the number of queries an attacker can make, allowing them to collect a lot of data over time.

Although some researchers have reported on Twitter and in online forums that they were able to siphon the private keys in some cases from servers that were vulnerable to the flaw, the security firm CloudFlare announced today in a blog post that it was unable to siphon a private key after multiple days of testing the flaw.

Cracking SSL to decrypt internet traffic has long been on the NSA’s wish list. Last September, the Guardian reported that the NSA and Britain’s GCHQ had been working to develop ways into the encrypted traffic of Google, Yahoo, Facebook, and Hotmail to decrypt the data in near-real time, and there were suggestions that they might have succeeded.

According to documents that Edward Snowden provided the paper, the spy agencies have used a number of methods under a program codenamed “Project BULLRUN” to undermine encryption or do end-runs around it — including efforts to compromise encryption standards and work with companies to install backdoors in their products. But at least one part of the program focused on undermining SSL. Under BULLRUN, the Guardian noted, the NSA “has capabilities against widely used online protocols, such as HTTPS, voice-over-IP and Secure Sockets Layer (SSL), used to protect online shopping and banking.”

Bloomberg does not say if the NSA or its counterparts succeeded in siphoning private keys using the Heartbleed vulnerability. The paper only mentions using it to steal passwords and “critical intelligence.”

Update: The NSA has issued a statement denying any knowledge of Heartbleed prior to its public disclosure this week. “NSA was not aware of the recently identified vulnerability in OpenSSL, the so-called Heartbleed vulnerability, until it was made public in a private-sector cybersecurity report,” an NSA spokesperson wrote in a statement. “Reports that say otherwise are wrong.”

The White House National Security Council spokesperson Caitlin Hayden also denied that federal agencies knew about the bug. “If the Federal government, including the intelligence community, had discovered this vulnerability prior to last week, it would have been disclosed to the community responsible for OpenSSL,” Caitlin Hayden said in a statement.

This entry passed through the Full-Text RSS service — if this is your content and you're reading it on someone else's site, please read the FAQ at fivefilters.org/content-only/faq.php#publishers.


View the original article here

Friday, April 11, 2014

Passwords vulnerable after security flaw found - Washington Post

By Associated Press,

NEW YORK — Passwords, credit cards and other sensitive data are at risk after security researchers discovered a problem with an encryption technology used to securely transmit email, e-commerce transactions, social networking posts and other Web traffic.

Security researchers say the threat, known as Heartbleed, is serious, partly because it remained undiscovered for more two years. Attackers can exploit the vulnerability without leaving any trace, so anything sent during that time has potentially been compromised. It’s not known, though, whether anyone has actually used it to conduct an attack.

Researchers are advising people to change all of their passwords.

The flaw was discovered independently in recent days by researchers at Google Inc. and the Finnish security firm Codenomicon.

The breach involves SSL/TLS, an encryption technology marked by the small, closed padlock and “https:” on Web browsers to signify that traffic is secure. With the Heartbleed flaw, traffic was subject to snooping even if the padlock had been closed.

The problem affects only the variant of SSL/TLS known as OpenSSL, but that happens to be one of the most common on the Internet.

Researchers at Codenomicon say that OpenSSL is used by two of the most widely used Web server software, Apache and nginx. That means many websites potentially have this security flaw. OpenSSL is also used to secure email, chats and virtual private networks, which are used by employees to connect securely with corporate networks.

Despite the worries, Codenomicon said many large consumer sites don’t have the problem because of their “conservative choice” of equipment and software. “Ironically smaller and more progressive services or those who have upgraded to (the) latest and best encryption will be affected most,” the security firm added.

A fix came out Monday, but affected websites and service providers must install the update.

Yahoo’s Tumblr blogging service uses OpenSSL. In a blog post Tuesday, officials at the service said they had no evidence of any breach and had immediately implemented the fix.

“But this still means that the little lock icon (HTTPS) we all trusted to keep our passwords, personal emails, and credit cards safe, was actually making all that private information accessible to anyone who knew about the exploit,” Tumblr’s blog post read. “This might be a good day to call in sick and take some time to change your passwords everywhere — especially your high-security services like email, file storage, and banking, which may have been compromised by this bug.”

Yahoo Inc. said its other services, including email, Flickr and search, also have the vulnerability. The company said some of the systems have already been fixed, while work is being done on the rest of Yahoo’s websites.

The company reiterated its standard recommendation for people to change passwords regularly and to add a backup mobile number to the account. That number can be used to verify a user’s identity if there are problems accessing the account because of hacking.

___

AP Technology Writer Michael Liedtke in San Francisco contributed to this report.

___

Online:

http://heartbleed.com

http://www.kb.cert.org/vuls/id/720951

Copyright 2014 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

This entry passed through the Full-Text RSS service — if this is your content and you're reading it on someone else's site, please read the FAQ at fivefilters.org/content-only/faq.php#publishers.


View the original article here

Blogger Widgets

Categories

Aarons (1) About (1) ADDitude (5) Adorable (1) afraid (1) after (4) aftermath (2) Airline (1) Airlines (2) Airport (1) Amazon (1) America (2) Americas (1) Amount (2) Angeles (6) anguish (2) Answered (1) Antidote (1) Anything (1) April (1) Arcade (1) Argue (1) Article (1) Aspirin (1) Astronauts (1) Atheist (1) Attacks (1) attendant (1) Attraction (1) backfire (1) basketball (2) Beard (1) Believe (1) Bergen (1) Between (1) Beyond (2) Bikes (1) Bizzaro (1) Blakelock (1) blogger (1) Bloomberg (1) Blowhard (1) blurry (1) Bombing (1) Bonding (1) Bonobos (1) Boston (1) Bottle (1) Boxer (1) Brain (2) Bright (1) Bring (1) brothers (1) Build (1) buildings (1) Businessweek (1) Canada (1) cannibalism (1) Captain (1) Captains (1) Cares (3) Cartels (1) Carter (1) center (1) centers (1) Challenging (1) Chances (1) Change (1) Changed (1) Check (1) Chevy (1) Chicago (1) Chief (1) Child (1) Chiropractic (1) Chris (1) Christian (1) Chunk (1) Church (1) Clamps (1) cleared (1) Clinton (2) coast (1) Coding (1) Coffee (1) Colbert (3) college (1) Colorful (1) ComcastTime (2) Comic (1) Comics (1) commentaires (1) Comments (2) Common (1) Community (1) completes (1) Computers (1) Confessions (1) congressman (2) Connecticut (1) Convictions (1) CoOperative (1) could (1) Could (3) crash (3) Create (1) created (1) Creativity (1) cried (1) crisis (2) Damage (1) Dangers (1) debate (1) Decreasing (1) defends (1) defiance (1) Delivery (1) Depends (3) deportations (1) Describe (1) DeStress (1) Difference (1) disability (1) disaster (1) Disney (1) disorder (1) Divine (1) Doing (1) draws (1) Dream (1) drives (1) Drones (1) During (2) early (2) Earths (1) Eating (2) Email (1) Encouraging (1) Energy (1) Episode (1) equal (3) erase (1) Escape (1) Everything (1) Evoking (1) Exercise (1) Experience (2) Exploited (1) Failure (1) Faith (1) Falcon (1) Family (3) Fandom (1) Farley (1) Feels (1) ferry (1) fiery (1) Filled (1) films (1) final (1) first (3) Fitness (1) flawed (1) Flight (4) Footage (1) football (1) force (2) Forget (1) forgive (1) forward (1) found (3) Freedom (1) galaxy (1) GameLife (1) Games (1) George (1) Getting (1) Gingrich (1) Glass (1) Glorious (1) Google (1) Goonies (1) Gorgeous (1) graduates (1) Gratefulness (1) Great (1) Greater (1) grooming (1) ground (1) Guess (1) handle (1) Happen (1) Happened (1) Happiness (1) Hated (1) Having (1) Healing (3) Health (6) Healthier (2) Heart (1) Heartbleed (2) Helicarriers (1) Highlights (1) Hillary (2) Himself (1) Hipsters (1) history (2) Holler (1) Hollywood (1) Horrifying (1) Hospital (1) Humans (1) Hurricane (1) hypocrite (1) Idahos (1) Importance (2) Improve (1) Increase (1) Infection (1) injures (1) Inside (1) Inspire (1) Internet (1) Interview (1) Introduce (2) Invade (1) Invention (1) iPhone (1) issues (1) Jewish (1) Judge (1) Kansas (1) Kathleen (1) keepers (1) keine (1) Kerry (1) Kharkiv (1) killed (1) Killers (1) killing (1) Kindness (1) Kissing (2) knives (1) Korean (1) Language (1) Learn (1) learning (1) learns (1) least (1) leave (1) LEGOThemed (1) Linked (2) Listen (3) Listens (1) Longer (1) Looks (1) machen (1) Magazine (5) Malaysia (2) Marathon (1) Marriage (1) Massive (1) McAllister (1) media (1) Medicine (1) Meditation (1) Meetings (1) meets (1) Merger (2) Microbes (1) Microsoft (1) MicrosoftPlan (1) Midriff (1) miles (1) military (2) Militias (1) Miller (1) MinorLeague (1) Minute (1) missed (1) missing (1) Mobile (1) Moments (1) Monitor (1) Mother (1) Motivated (1) moves (1) movie (2) Moving (1) Murder (1) nations (1) NBCNewscom (2) needs (1) Negative (1) Negativity (1) Nevada (1) NextLevel (1) ninth (1) Noise (1) nominee (1) Notes (1) Notre (1) Obama (3) Obamacare (1) ObamaCare (1) Obamas (2) Online (1) orders (1) Oscar (2) Others (1) Ourselves (1) Overly (1) oversaw (1) Overturned (1) Pacino (1) pangolin (1) Password (1) Passwords (2) Pennsylvania (1) people (1) People (1) perfect (1) Phillycom (1) photo (2) Physical (1) Pings (1) Pistorius (5) PizzaCutter (1) plane (1) plastic (1) Playing (2) Please (1) Podcast (1) Politico (1) Pollution (1) Potential (1) Power (1) pregancy (1) Pregnancy (1) Prevent (1) Prince (1) Probably (1) Profitable (1) Programs (1) promising (1) Prone (1) Proper (1) proRussians (2) Proud (1) Quantified (1) Questions (1) quits (1) rampant (1) ranchers (1) Reader (1) Really (1) record (1) Reeva (3) Reiki (1) Relax (1) Relaxation (1) Report (1) Reports (1) Republican (1) Resign (1) resigns (1) Resigns (1) Resolutions (1) Response (1) Restore (1) Restoring (1) retake (1) Reusable (1) Reuters (2) rhetoric (1) rigged (1) Risks (1) rollout (2) routs (1) royal (1) Rubin (1) Russia (2) Russias (1) sagit (1) SameSex (1) Scare (1) scene (1) schlechte (1) School (2) Schools (1) Science (1) Scientology (1) search (2) season (1) Sebelius (5) secretary (1) security (3) seeking (1) Selfie (2) Series (1) Sesame (1) Seven (1) Sexual (1) sharp (1) Shells (1) shoot (1) Shootings (1) Shops (1) Short (1) shouldnt (1) silent (1) Similarities (1) Simple (1) Simpsons (1) sinks (1) Siphon (1) Sketch (1) Sleep (2) Slowly (1) Slurpee (1) Smallest (1) Snail (1) social (1) South (1) SpaceXs (1) Speak (1) Speech (1) spoton (1) Spread (1) Sprinkle (1) Stabbing (1) standoff (1) stars (1) State (1) Staying (1) Steenkamp (1) Steps (2) Stores (1) Stress (2) Strikes (1) Student (2) students (1) Success (1) Successful (1) Sudden (1) Suicide (3) Superhero (1) surgery (1) surrounded (2) Survive (1) survivor (1) symptoms (1) Talent (1) Tattoos (1) Terrible (2) Terriers (1) Testimony (1) theyve (2) Thing (1) Think (4) Those (1) Thoughts (1) Thrashes (1) Through (1) thrown (1) Thrown (1) Tigers (1) timeline (1) Times (12) Tinder (1) title (1) TODAY (3) trade (1) Tradition (1) Transcending (1) transgression (1) Translation (1) trapped (1) trend (1) trends (1) Trial (1) Tribune (1) Troubles (1) Tumblr (1) Turkish (1) turning (1) TVSendungen (1) Twist (1) UConn (1) Ukraine (6) Ukraines (1) Ukrainian (2) Uncommon (1) Understanding (1) underwater (1) uninfected (1) Unrest (1) Valuable (1) Vance (1) Vegas (1) Victim (1) Video (1) Videos (1) voters (1) vulnerable (1) Waffles (1) Wallet (1) Wants (1) Warner (2) Warns (1) Washington (3) Wasnt (1) Watch (1) Wedding (1) Weight (3) Weird (1) Western (1) which (1) Whole (1) Whose (1) wielding (1) Windows (1) WIRED (2) women (1) Women (2) womens (2) Words (1) Workers (1) Working (1) World (1) Worst (1) Worth (3) wrong (1) Wrong (1) Yahoo (1) Years (2) Youre (4) Zizmor (1)

Disclaimer

All the information on this "Day's Top Stories" blog is solely published in good faith and for general informational purposes only. The owner of this blog makes no representations as to the accuracy or completeness of any information on this site or found by following any link on this site. From this site, you can visit other websites by following hyperlinks to such external sites.