Posts tonen met het label privacy. Alle posts tonen
Posts tonen met het label privacy. Alle posts tonen

vrijdag 12 juni 2020

Internet voting

Gene Spafford is one of my old security heroes. As you may know, not having an ICT background I'm not an expert in technical IT security, but what I learned about Unix and Internet security, I learned from Simson and Spafford (great introduction into security, also for Windows users...).

And if he speaks, you need to listen. This time he spoke about Internet Voting. The occasion being the US presidential primary elections. There are lots of voices who claim that internet voting is essential for democracy. Spaf is cautious, and with lots of reason, because, as he shows, technology is not stable and secure enough to facilitate free elections, there are too many obstacles from a technology point of view. No, not even Blockchain will make it secure enough. Here's the link to the interview with Spaf. And to all politicians: this expert knows more about security than all of you combined.

Why this post if I can just point to the interview?
Well, first the aspect of Identity was not mentioned. And we should of course touch on that as well. And second: this topic is a global topic, not just covering the US primaries.

Even though elections are anonymous, anonymity only extends to
  • the knowledge of who voted for whom
  • the knowledge of who voted
Those are the only anonymity requirements. The latter may not even be required if voting is mandatory by law, but then again, even in that case privacy may be relevant amd anonimity may extend to that topic.

But just the possibility, the justification for voting does require knowledge of the voter:
  • you are only allowed to vote if according to legislation you are considered to be a voter
  • you can only vote once
  • unless you have a uniquely identified mandate from another voter
And this is where Internet Voting is hurt even more than just by the techology part.

In order to make Internet Voting possible, these requirements have to  be met:
  • you need to have a trusted identity
  • an identity that is recognized in a 'voter directory'
  • there must be a transaction log to prevent multiple voting by one identity
  • there must be a mandate register, to enable mandated unique votes
Just imagine the first requirement in relation to Internet Voting.

zaterdag 3 mei 2014

Why worry about Facebook Whatsapp - part 2

A few weeks back I commented on Facebook taking over Whatsapp. As you can see my concern was that only if Facebook knows your phone number, it can datamine on the combined databases. As long as Facebook doesn't know your Whatsapp ID, your phone number, it cannot correlate the events in both social networks.

But I was naive. Chances are that facebook knows your phone number. Just recently I had to use a Facebook account. I don't have one. A few years ago I had a Facebook account, but I had Facebook delete my account.

But I needed to have a Facebook account in order to get access to a free wifi spot, I had to logon using a Facebook account. So, I created an account. And at that moment I found out that I had to enter a phone number in order to receive an SMS authentication token. Without a phone number I could only register by sending a copy of an ID card to Facebook. No way, I was in a hurry.
All I could do was enter my own phone number, because I had no time to get a prepaid sim.

So Facebook now knows my phone number. But, I created a fake Facebook account, with lots of strange likes.

And behold: Facebook suggested I became friends with a lot of people I know in real life... What other information in my account other than my phone number related to these people. My phone number must already be there, hidden deep within Facebook's treasure chest. I can hardly imagine my friends posting my phone number on their accounts.

Facebook never deleted my phone number or my friends network. So, am I worried about that Facebook - Whatsapp deal? No. I just kill my Facebook account again. I don't want at. And if I need another Facebook account, I will make sure to have a prepaid sim to use.

dinsdag 8 april 2014

Don't stop using XP until...

There is a lot of misconception about the security of Windows XP. Microsoft extended support ends today, after publishing the final set of security patches for XP that were developed to tackle security issues that occurred in the last few months. Microsoft has a 1 month patch cyclus, every 2nd tuesday of a month patches are published.
What does ending extended support for us mean:

If Microsoft would still support XP, the next set of security patches would only be published on the 13th of may 2014. Any zero day vulnerability that was discovered today, could, in an ideal world, only be fixed on the 13th of may, thereby leaving your pc vulnerable until the 13th of may. But that is the case for all supported Microsoft operating systems. Your 7, Vista, or 8 system would also be vulnerable until the patches of may 13t. Only in a few instances has Microsoft been pushed to fix earlier, but they keep with their regular scheme.

What does this mean for poor XP?

A fully patched XP system will be no less secure than a fully patched Windows 7, Vista or Windows 8 pc! Only on the 13th of may 2014 will the security be affected negatively because no new patches will be published. Your system will be vulnerable for ever...

Should you migrate?
Yes by all means. You may not be an interesting target for a criminal (you are, but I can probably not convince you today), but your pc is. It will be used as a spambot platform, or for bitcoin mining for others, running porn hubs for criminals, whatever. So migrate: YES


Should we panic?

Yes of course. But not because of today. We should panic because there are still too many XP systems.
Most consumer systems will be fully patched, but I bet that most companies who still run XP have graver problems. Many systems will not even be fully patched. So, consumers, you have one month left to migrate to 7, 8, Apple or Linux. Should you? Yes by all means!
And companies? You are in big trouble. You should fire the responsible management for not preventing this event.


===Update===
Hans Bos from Microsoft Netherlands mentioned that a fully patched XP system is less secure than a fully patched 7/Vista/8 system. He is right of course. Just have a look at Internet Explorer.
But then again, this has always been the case, XP has always been in a minor security league than more current systems. The class difference stays the same...

donderdag 20 februari 2014

Facebook and Whatsapp, why worry?

The deal of the year, Facebook buys Whatsapp. And even before the dust settles, the privacy world is screaming murder. The privacy denying company buying a private messaging company spells doom for the privacy of hundreds of millions of users. You are warned to leave Whatsapp if you care for your privacy...

But is your privacy really at stake? Is the merger a new threat?

Facebook knows a lot about you. It knows your friends and relations, your likes, your updates, your whereabouts and it even knows what you would like to post but never really did. Facebook not only has access to your metadat, it has all content as well.
Whatsapp knows a lot about your telephone number. It knows the telephone numbers your phone number connects with and it has an enormous amount of metadata of all connections made.
And since both companies are American, you can bet that the NSA and it's friends have access to these (meta)data too.


But, and it's a big but, as long as a Facebook profile doesn't contain a telephone number, Facebook has no way to connect a profile with all Whatsapp metadata. There is no way to correlate a human profile with a phone profile.
It's a big but, but Facebook and Whatsapp live in different worlds en never the twain shall meet. So in my opinion there is no new privacy risk. If you really care for your privacy surely you would have left Facebook a long time ago?
So as far as I 'm concerned there is no need to dump Whatsapp. There are bigger threats to your privacy.



There's a second but, and that's a bit more tricky. A Facebook app and a Whatsapp app on a smartphone are different apps and they don't share between them, the operating system of the smartphone takes care of separation. Unless the operating system doesn't. I would say, stay away from any Facebook marketed phone...

So, until Facebook asks for your phone number, or you provide your phone number to Facebook, don't worry.

donderdag 14 november 2013

Adobe lesson learned: do not use complex passwords!


By now we all learned about yet another password leak, this time at Adobe. Not just some incident, no, it's a big one, with some 130 million passwords in the open. A big scandal too. And of course we are amazed at the large number of too obvious passwords chosen by the Adobe customers. Passwords like '123456' and 'secret' are amongst the most frequently chosen passwords. Are we really surprised? No of course not. We already knew that people are not very aware about the security risks involved.

Who are those customers? They are people like you and me, consuming services anywhere on the internet, Services like those offered by Adobe. And for most of those services the provider wants to know who you are by asking you to register an account. So, many of us did.

Accounts

Let me tell you about the way I create accounts. In order to protect my privacy I have to protect both my identity and my behavior. So I try to separate my digital life from my real life as much as possible. And I bet that I'm not alone in this. My preferred method is to create an account using an alias. And since providers want to reach my alias, I need to provide an email address. If possible I use a disposable, or a fake email address. Next I have to pick a password. '123456' will do just fine. Why?
This password is not there to authenticate, it's there because the provider wants me to provide a password to ensure my permission to use a service. But I didn't use a real digital identity, I just claimed some capacity to download whatever I want from the provider. I don't care about protecting it, because in real life it just doesn't exist, and in all fairness, it's worthless. In fact I may have created an Adobe account a long time ago, but I don’t even remember it. And if I don't care, it's just not relevant how secure it is or how complex the password is. The only thing that I need to take care of is to NOT use one of my regular identities and passwords.

That's my real protection. As long as a provider or a hacker for that matter, cannot link the non-existing identity with a real identity, there is no danger for my real privacy if the provider or hackers publish '123456'. I couldn't care less. So, lousy providers like Adobe are not really a risk for me. I was right in not trusting them.
A far better way for providers to connect to customers would be to let them use an external identity, that way you don't need to register an account with the provider and the provider doesn’t need to protect it, there is no password... If you are free to pick an external identity like facebook, Twitter or LinkedIn, then the risks of data leakage are far less. There's another privacy issue, because those identity providers know your interests because of the federation stuff. I will not elaborate on this issue, but if you have enough digital identities, every identity provider only knows part of your interests, part of your activities and thus part of your identity. Divide et Impera.

Threats

The Adobe leak led to a lot of noise in the security community. There were two main comments: Adobe is stupid by not enforcing better security, I agree. And: users are stupid for using simple passwords, well, I don't fully agree. And I will explain this:
Account and identity management is tricky. There are two risks:
1) Someone knows you and tries to steal your identity.
2) Someone knows your password and your login name and tries to find out your real identity and reuse that information

The first risk can be real, but it need not be that big, provided that you think about a few best practices. Protect your behavior. If someone doesn't know to relate your real identity to a digital identity, not a lot of harm can be done in the digital world, in Cyberspace.

As I mentioned, the second risk can be neglected as well, if you understand it and act upon it. I hope/believe that most of the Adobe top 20 passwords are used by people who knew this. In my opinion most of the accounts used are disposable accounts. And preferably accounts that cannot be linked to real identities.

Password complexity

Both reactions to the Adobe leak came down to one issue: password complexity. Fact was that Adobe didn't enforce password complexity, not in the user space, not by using good practices for cryptography. Second fact: lots of users didn't use complex passwords.

Password complexity is difficult. A password needs to be complex for a few reasons:
- You don't want it to be easily guessed by someone who knows your digital identity.
- You don't want it to be easily cracked by someone who has access to your encrypted password.
Yet at the same time you want it to be easily remembered, by yourself.

The first risk is in fact the risk that we need to manage to mitigate the threat of someone who knows you to steal your digital identity, that's the first identity risk. It's the risk of someone retrieving an identity => password combination based on known identity information.

The second risk is more difficult to manage. The enormous amounts of processing power makes this risk hard to mitigate, password cracking isn't that hard to do anymore. This risk works the other way around: someone tries to retrieve a password => account combination based on known password information. Encryption of the password in transit and in storage does help safeguarding the password information, but it will probably only help temporarily. So we are trying to use one measure, password complexity, to tackle different risks. This may seem efficient, but in fact it's not what we need to do.

In order to prevent identity => password retrieval, we need password complexity. No one should be able to retrieve a password based on identity knowledge alone.
One example is Phishing: an attacker tries to retrieve secret information from a known identity. That means that the real, or physical identity => digital identity => password trail needs to be protected. And since the password is the valuable item, the password needs to be secured. That means using complex passwords (and to fight phishing: educate users to not hand over secret information!).

To prevent retrieval of a valuable identity based on a found password, another mechanism is required. If someone retrieved a password, he may be able to retrieve the digital identity, but he should not be able to retrieve the real identity behind the digital identity. Why?
This might lead to misuse of the identity => password risk!

If the password => identity trail can be found, an attacker might gain knowledge to intercept other identity => password combinations. The identity is the valuable resource, so you need to protect your identity. And the best way is to use disposable identities or external identities in those cases that you have to trust providers.

This leads to an interesting conclusion


Adobe user accounts with complex passwords, may well be more at risk than accounts with easy to guess passwords: customers using a complex password may well have used a valuable identity, expecting the complex password to protect it. How about that?

In my next post I will introduce a real simple complex password method.

maandag 19 november 2012

I shared an email with you

Twitter introduced an interesting new feature, emailing a tweet that you think might be of interest to someone else. Twitter lets you send an email straight from the Twitter web interface. If you choose so, up pops a browser window that lets you enter the email address of the recipient and enter some text next to the tweet. Press a button and Twitter takes care of sending the tweet.

Why does this bother me?
Some time ago I wrote a blog entry about Behavior centric identity management. I said that my Identity is constructed using several components, one of which is my behavior. You may know my name, or my interests, my relations, my work, whatever, but the more aspects of me you know, the better you know the real me, the closer you come to the real me. In order to be in control of the real me, for me this means seperating these components as much as possible. That's why I use netvibes rss aggregator (that knows about my areas of interest) instead of iGoogle (that will disappear anyway).

My Twitter handle is one of my identity components, just like my email relations. And the tweeps I follow are not randomly chosen, no, they are part of my identity too. But Twitter is just an instrument for me to use and Twitter has got nothing to do with my other identity components.

But now that they started offering an email facility, they have to possibility to combine my separate identity components. They can combine my areas of interest (the tweet that I want to share) and my non-Twitter relations (this function is obviously meant to reach non.tweeps, otherwise a simple RT would do). It's an effective interest aggregator.  The email sent contains lots of information, but most important is that Twitter owns the mail server. And Twitter is the owner of the sent email message.

Twitter could of course offer the email button and start my email client, just as easy, and they would never know to whom I would like to send a tweet. But by implementing the email facility like they did, they are in the middle of my communication channel with a non-Tweep. They know that my Twitter ID is interested in informing a non Twitter identity about a certain subject.

Since Twitter is becoming the on-line memory for our thoughts, I don't think that Twitter will remove all emails and temp files, do you?

maandag 8 oktober 2012

Confirmation e-mail shows password vulnerability

This week it happened again: I received an e-mail with a confirmation of creating an account for a webshop. Yes, it is very comforting to know that you have an account. But apart from the fact that I created yet another account somewhere in the cloud, I noticed that the email showed my account credentials in full text. Reading my accountname was not that special, but seeing the password I entered on the site was less reassuring.
If the mailserver sends an email with a readable password it means that my password is accessible for the mailserver in a readable format. And that means that the password is unencrypted somewhere between the website and the mailserver. In most cases a content management system (with a user database) or a webshop system (with some kind of CRM database) are familiair with my account. And both these systems use the emailserver to inform me about all transactions. Including account creation. The same can happen if you click a link to the forgotten password function. Some systems resend you the password for your account. So they must be able to read the password from your account in the database.
For me this implies that the CMS and/or CRM system do not store the password in encrypted form, otherwise how can the mailserver get the content for the email? I don't suppose these systems use a brute-force attack to discover your password...

In this case I informed the webshop owner that I suspect that there is a vulnerability in the user management function. 

Best practices:
  • Use third party identities (Oauth, OpenID etc.) to create customer accounts, that way you don't store passwords;
  • Use a hashing function for passwords in the database (and please pick a secure algorithm);
  • If your CMS or CRM doesn't support encryption of passwords, change to a secure system.
And never ever send an email with the password in readable form. Better send an email with a link to the password reset function.

If you encounter sites that email your password (either at create time or at password reset), please inform the webmaster of this vulnerability.

donderdag 6 oktober 2011

Nymwars: converging two worlds

Today this announcement was made: Facebook SIM brings social network to dumb phones. And this may well be the first convergence of the first world and the second world, convergence of the real world and the digital social networking world. And as I predicted, Facebook is one of the parties involved. Google will follow soon, mark my words...
Facebook Real Name policy will of course have a major impact. Your fb account is connected to your phone, the device you carry with you. Your virtual identity is connected to your physical identity 24/7. And I suppose that Facebook Timelines will in no time show your whereabouts, no more need to check in, fb knows it all. Frightening...
#IleftFacebook

woensdag 21 september 2011

Me, a name I call myself

Recently a few service providers initiated their Real Name policy. They require their users to use their real name in order to be able to use the services. Google+ and Facebook prohibit the use of an alias as a name. One of the most famous victims is Identity Woman. The service providers claim that the use of the real name of users helps creating more trust on the Internet. There are several reasons why this reasoning looks invalid, it looks as if there's another agenda. I will get to that later on in this post.

Of course these service providers allow you to use services like email, chat, socializing and so on. And until a few months ago these features seem to work for the Internet community. I can chat with other people. And I connect with them based on the information from within my network (about the reputation of these new connections), or based on their previous work (that I found using other Internet services), or even based on me knowing the person in real life. In no way does the real name of Internet users in my network have anything to do with me trusting them, trust is based on other parameters, reputation and performance being the most important.

A bizarre phenomenon is that many years ago I could open a Gmail account, using any stupid account name that I could imagine. Never ever did Google ask me to prove my identity as a person, and never would they claim that my mail is reliable or trustworthy. Of course they can't, because they don't know me in person and because I never needed a trustworthy email account in the first place, I just wanted a free web based communication facility. And now that they added + to my mail, they claim that all my communication will be more trustworthy if I use a different, real name.

These service providers have a point in a way that they manage to position themselves not only as a service provider, but as an identity provider, one of the major parties in a trust framework. Their users can use these identities towards other service providers, using protocols like OpenID and OAuth. But here they fail to understand that a digital identity, such as a + name, is just one of the identities that I, as a natural person, have. I have plenty more. G+ is not my real identity and you should not trust it, since this identity provider doesn't know me.

But, that's not all true. Google does know me, in the digital world. They know my interests and behavior based on my digital history. They know what I'm looking for and what other identities I have relations with. And this knowledge is valuable in exploiting their core advertising business, this knowledge is their business model. I get to use their services for free and they get to know me in order to let their commercial partners contact me for relevant offers. A fair deal, but trust is in no way a concern. I create my own network and I use the services that I want.

But how can these Googles and Facebooks earn more money? When digital identities are connected to real life consumers, ad campaigns have a higher return, these campaigns can be more relevant. And so ads are more valuable, resulting in higher earnings. That's their new business case, their new hight profit business model: connecting digital identities to real life individuals.The providers claim to help create more trust. By now they should know better. Diginotar proves that trust is not a technical issue, It's a people thing. And requiring real names does not help. In fact it is a new threat to my freedom in choosing the services that I want to use, in connecting to whoever I like and to be on the Internet who and what I like to be. Sometimes anonymity is not bad and sometimes an unreal name is more secure.

donderdag 16 april 2009

myOneLogin ad

I just read one big ad (dressed as an article) for the myOneLogin service. It is some kind of identity broker, directed at enterprises and SMB's, facilitating single sign-on for cloud applications. It's a $3/month per user service that might replace the use of OpenID for enterprises users. It also addresses strong authentication needs and can cope with SAML.

Anyway: this has got nothing to do with identity 2.0. It's not the end user that is in control of his identity. This may be fine for enterprise use, but why would a company pay fot sso in the cloud? Enterprise sso (esso) may be considered a security measure (it makes sharing accounts by end users difficult). And if you employed esso, cloud apps should be handled as well.

I'm a little bit concerned about such developments. The problem with services like this (as wel as with OpenID) is that a central authority gets to know my whereabouts. Can these authorities be trusted? How about international regulations? Any clue? How do they handle logging and log analysis? Or log retention (I hope Not).

I'm happy with this kind of development, because it propagates the use of open standards like SAML.

Still, not for me, though. I prefer an internal esso and besides, the password store in firefox and ie is capable enough. It is great, however, that using sso you are into green computing, in pandemic planning and fuel conservation and thus protecting the environment. I don't know how, but it's in their About statement (at least in today's version) :)